MS-500 Technology & Digital Applications 4 — Questions and Answers
Question 1: What does the 'ZAP' (Zero-hour Auto Purge) feature do in Microsoft Defender for Office 365?
- Encrypts malicious attachments before delivery
- Retroactively removes malicious emails from user mailboxes after delivery (Correct answer)
- Blocks outbound spam before it leaves the tenant
- Scans URLs at time of click
Correct answer: Retroactively removes malicious emails from user mailboxes after delivery
ZAP retroactively moves emails that are later identified as malicious out of user inboxes after delivery.
Question 2: An organization must ensure that all Teams meetings are recorded and retained for 90 days for compliance. Which Microsoft 365 service should be configured?
- Microsoft Purview retention policy scoped to Teams meetings (Correct answer)
- Microsoft Defender for Cloud Apps session policy
- Intune app protection policy
- Azure AD Privileged Identity Management
Correct answer: Microsoft Purview retention policy scoped to Teams meetings
A Microsoft Purview retention policy targeting Teams meeting recordings ensures recordings are kept for the specified 90-day period.
Question 3: Which type of Conditional Access grant control requires users to register and use a specific hardware token?
- Require compliant device
- Require multifactor authentication with phishing-resistant methods (FIDO2 key) (Correct answer)
- Require approved client app
- Require hybrid Azure AD joined device
Correct answer: Require multifactor authentication with phishing-resistant methods (FIDO2 key)
Requiring phishing-resistant MFA in Conditional Access enforces hardware security key or passkey authentication.
Question 4: What is the primary function of Microsoft Defender for Cloud Apps (CASB)?
- Scanning email attachments for malware
- Providing visibility and control over third-party cloud applications used by employees (Correct answer)
- Managing endpoint antivirus definitions
- Enforcing on-premises firewall rules
Correct answer: Providing visibility and control over third-party cloud applications used by employees
Microsoft Defender for Cloud Apps is a CASB that discovers shadow IT, enforces policies, and protects data in third-party SaaS apps.
Question 5: An admin is reviewing the Microsoft 365 audit log and sees the operation 'Set-Mailbox -LitigationHoldEnabled $true'. What does this indicate?
- A mailbox was deleted
- A mailbox was placed on litigation hold to preserve all content (Correct answer)
- A user's password was reset
- An email forwarding rule was created
Correct answer: A mailbox was placed on litigation hold to preserve all content
The LitigationHoldEnabled parameter being set to true places a mailbox on litigation hold, preserving all content indefinitely.
Question 6: Which Microsoft 365 feature prevents accidental sharing of content marked as sensitive in Teams chats?
- Microsoft Purview DLP policies for Teams (Correct answer)
- Azure AD B2B collaboration
- Endpoint DLP
- Microsoft Defender for Identity
Correct answer: Microsoft Purview DLP policies for Teams
DLP policies scoped to Microsoft Teams detect and block sharing of sensitive information within Teams chats and channels.
Question 7: What does enabling 'Security Defaults' in Azure Active Directory provide?
- Advanced threat hunting capabilities
- A baseline set of security policies including MFA for all users and blocking legacy authentication (Correct answer)
- Full Privileged Identity Management activation
- Automatic device enrollment in Intune
Correct answer: A baseline set of security policies including MFA for all users and blocking legacy authentication
Security Defaults enforce a preconfigured baseline including MFA registration, MFA at sign-in, and blocking legacy auth protocols.
What does the 'ZAP' (Zero-hour Auto Purge) feature do in Microsoft Defender for Office 365?