MS-500 Technology & Digital Applications 5 — Questions and Answers
Question 1: Which Microsoft Purview capability allows legal teams to search across Exchange, SharePoint, Teams, and OneDrive for litigation purposes?
- Content Search and eDiscovery (Correct answer)
- Microsoft Defender for Office 365 Threat Explorer
- Azure AD audit logs
- Microsoft Secure Score
Correct answer: Content Search and eDiscovery
Microsoft Purview Content Search and eDiscovery tools enable legal teams to locate and export content across multiple M365 workloads.
Question 2: An organization wants to block all OAuth app consent by end users and require admin approval. What setting must be configured in Azure AD?
- Enable Azure AD Smart Lockout
- Configure user consent settings to require admin consent for all apps (Correct answer)
- Enable Identity Protection risk-based Conditional Access
- Configure Microsoft Defender for Cloud Apps app governance
Correct answer: Configure user consent settings to require admin consent for all apps
Setting Azure AD user consent to require admin approval prevents users from granting OAuth permissions to third-party apps without oversight.
Question 3: What is the role of DKIM (DomainKeys Identified Mail) in Microsoft 365 email security?
- Encrypts the email body end-to-end
- Adds a cryptographic signature to outbound emails to verify the sending domain's authenticity (Correct answer)
- Blocks phishing emails based on sender reputation
- Enforces SPF record validation for inbound emails
Correct answer: Adds a cryptographic signature to outbound emails to verify the sending domain's authenticity
DKIM adds a digital signature to outgoing emails, allowing receiving servers to verify the message was sent from the legitimate domain.
Question 4: An admin needs to monitor when a user is assigned the Global Administrator role. Which tool provides real-time alerts for this?
- Microsoft Purview Audit (Standard)
- Azure AD Privileged Identity Management (PIM) alerts and Microsoft 365 Defender incidents (Correct answer)
- Microsoft Intune compliance reports
- Exchange admin center audit reports
Correct answer: Azure AD Privileged Identity Management (PIM) alerts and Microsoft 365 Defender incidents
PIM can send alerts when a user is assigned a privileged role permanently, and Defender incidents correlate identity changes with suspicious activity.
Question 5: Which policy type in Microsoft Endpoint Manager (Intune) enforces minimum OS version and password requirements before granting resource access?
- App protection policy
- Device compliance policy (Correct answer)
- Device configuration profile
- Enrollment restrictions
Correct answer: Device compliance policy
Device compliance policies define health requirements such as minimum OS version and PIN complexity that devices must meet.
Question 6: What is the key difference between Microsoft Purview Communication Compliance and Insider Risk Management?
- Communication Compliance focuses on policy violations in communications, while Insider Risk Management broadly monitors user activity for risky behavior patterns (Correct answer)
- Communication Compliance only monitors email, while Insider Risk Management monitors SharePoint only
- Communication Compliance requires an E3 license, while Insider Risk Management requires E1
- Insider Risk Management replaces Communication Compliance in all scenarios
Correct answer: Communication Compliance focuses on policy violations in communications, while Insider Risk Management broadly monitors user activity for risky behavior patterns
Communication Compliance targets specific policy violations in messages (harassment, regulatory), while Insider Risk Management analyzes behavior patterns across many activities.
Question 7: A company needs to ensure that emails sent outside the organization containing credit card numbers are automatically encrypted. Which solution accomplishes this?
- Safe Links policy
- Microsoft Purview DLP policy with an encrypt action for external email (Correct answer)
- Exchange transport rule blocking all outbound email
- Intune app protection policy
Correct answer: Microsoft Purview DLP policy with an encrypt action for external email
A Purview DLP policy can detect sensitive data like credit card numbers and automatically apply Office Message Encryption to outbound messages.
Which Microsoft Purview capability allows legal teams to search across Exchange, SharePoint, Teams, and OneDrive for litigation purposes?