MS-500 Technology & Digital Applications 2 — Questions and Answers
Question 1: Which Microsoft 365 feature allows administrators to restrict external sharing of SharePoint content to only specific domains?
- Sensitivity labels
- SharePoint domain allow/block lists (Correct answer)
- Conditional Access policies
- Microsoft Defender for Cloud Apps
Correct answer: SharePoint domain allow/block lists
SharePoint domain allow/block lists let admins restrict external sharing to or from specific domains.
Question 2: An organization wants to prevent users from forwarding emails to external addresses automatically. Which Microsoft 365 tool should be configured?
- Exchange mail flow rules (transport rules) (Correct answer)
- Microsoft Purview DLP
- Safe Attachments policy
- Azure AD Identity Protection
Correct answer: Exchange mail flow rules (transport rules)
Exchange transport rules can block automatic email forwarding to external recipients at the mail flow level.
Question 3: What is the primary purpose of Microsoft Secure Score?
- To measure network bandwidth utilization
- To provide a quantified security posture rating with recommended improvement actions (Correct answer)
- To track user productivity metrics
- To audit Azure resource costs
Correct answer: To provide a quantified security posture rating with recommended improvement actions
Microsoft Secure Score quantifies an organization's security posture and suggests prioritized actions to improve it.
Question 4: A user reports they cannot access a Teams channel after a sensitivity label was applied to a team. What is the most likely cause?
- The label revoked the user's Azure AD license
- The label's access control settings restricted membership or guest access (Correct answer)
- Teams service is experiencing an outage
- The user's MFA device is unregistered
Correct answer: The label's access control settings restricted membership or guest access
Sensitivity labels on Teams can enforce privacy settings and guest access restrictions that may block certain users.
Question 5: Which role in Microsoft 365 has the least privilege needed to manage Microsoft Defender for Office 365 policies without accessing user mailboxes?
- Global Administrator
- Security Administrator (Correct answer)
- Exchange Administrator
- Compliance Administrator
Correct answer: Security Administrator
Security Administrator can configure Defender for Office 365 policies without having access to individual mailbox content.
Question 6: What does enabling 'Attack Simulation Training' in Microsoft Defender for Office 365 allow an organization to do?
- Block all phishing emails automatically
- Run simulated phishing campaigns to measure and train user awareness (Correct answer)
- Encrypt outbound emails to external recipients
- Apply DMARC records to the email domain
Correct answer: Run simulated phishing campaigns to measure and train user awareness
Attack Simulation Training sends controlled, simulated phishing emails to employees to identify and reduce susceptibility.
Question 7: An administrator needs to ensure that documents labeled 'Highly Confidential' cannot be opened on unmanaged devices. Which technology enforces this?
- Azure AD Password Protection
- Sensitivity label with encryption and access control settings (Correct answer)
- Microsoft Intune device compliance policy
- Microsoft Purview audit log
Correct answer: Sensitivity label with encryption and access control settings
Sensitivity labels with encryption bind access rights to the label, preventing unmanaged or unauthorized devices from decrypting the content.
Which Microsoft 365 feature allows administrators to restrict external sharing of SharePoint content to only specific domains?