MS-500 Technology & Digital Applications 3 — Questions and Answers
Question 1: Which Microsoft 365 Defender feature correlates alerts from endpoints, email, identity, and cloud apps into a single incident?
- Microsoft Sentinel SIEM
- Microsoft 365 Defender incident correlation (Correct answer)
- Azure Monitor Log Analytics
- Microsoft Purview eDiscovery
Correct answer: Microsoft 365 Defender incident correlation
Microsoft 365 Defender automatically correlates related alerts across workloads into unified incidents for faster investigation.
Question 2: What is the effect of setting a retention policy with 'Preserve and then delete' action in Microsoft Purview?
- Content is deleted immediately after the retention period
- Content is preserved for the retention period, then permanently deleted afterward (Correct answer)
- Content is moved to an archive mailbox
- Content is encrypted for the duration
Correct answer: Content is preserved for the retention period, then permanently deleted afterward
A 'Preserve and then delete' retention policy keeps content for the specified period and then permanently removes it.
Question 3: Which capability in Microsoft Defender for Identity detects lateral movement techniques such as Pass-the-Hash?
- Safe Links URL detonation
- Lateral movement path detection (Correct answer)
- Microsoft Purview Insider Risk Management
- Cloud App Security CASB
Correct answer: Lateral movement path detection
Defender for Identity's lateral movement path detection identifies attack paths that use credential theft techniques like Pass-the-Hash.
Question 4: An admin wants to allow only compliant devices to access Exchange Online. Which two technologies must be configured together?
- Conditional Access policy + Intune device compliance policy (Correct answer)
- Safe Attachments + Safe Links
- Microsoft Purview DLP + Sensitivity labels
- Azure AD SSPR + MFA
Correct answer: Conditional Access policy + Intune device compliance policy
Conditional Access evaluates the device compliance signal provided by Intune to grant or block access to Exchange Online.
Question 5: What is the purpose of the 'Tenant Allow/Block List' in Microsoft Defender for Office 365?
- To set Data Loss Prevention exceptions for trusted senders
- To manually allow or block specific senders, URLs, or file hashes in email filtering (Correct answer)
- To configure outbound spam filter policies
- To control SharePoint external sharing permissions
Correct answer: To manually allow or block specific senders, URLs, or file hashes in email filtering
The Tenant Allow/Block List lets admins override filtering verdicts for specific email senders, URLs, or attachments.
Question 6: Which Microsoft Purview solution helps organizations identify and remediate risks from disgruntled employees exfiltrating data?
- Communication Compliance
- Insider Risk Management (Correct answer)
- eDiscovery (Premium)
- Data Lifecycle Management
Correct answer: Insider Risk Management
Insider Risk Management uses signals and policies to detect, investigate, and act on risky user activities such as data exfiltration.
Question 7: When configuring Azure AD Identity Protection, what triggers a 'high-risk' user sign-in alert?
- A user signing in from a new browser
- Leaked credentials detected or anomalous activity consistent with account compromise (Correct answer)
- A user failing MFA once
- A new application consent granted by a user
Correct answer: Leaked credentials detected or anomalous activity consistent with account compromise
Identity Protection flags high-risk sign-ins when credentials appear in breach databases or behavioral anomalies strongly suggest compromise.
Which Microsoft 365 Defender feature correlates alerts from endpoints, email, identity, and cloud apps into a single incident?