MS-500 Sample Questions

MS-500 Sample Questions & Answers

Threat protection through Defender for Identity and Endpoint carries the most weight, alongside identity and access for hybrid environments, information protection and data loss prevention, and compliance work like eDiscovery.

Launch the full MS-500 simulator →

Showing 10 of 20 free samples.

  1. Question 1

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

    You have created a new user via the Microsoft 365 admin center.

    The new user will be assigned the Reports reader role. You want to view the permissions of the Reports reader role before assigning it to the new user.

    Solution: You make use of the Azure Active Directory admin center.

    Does the solution meet the goal?

    Show answer & explanation

    Correct answer: A

    A

  2. Question 2

    The My Library feature of the service trust portal lets you save your own documents so that you can quickly access them on your My Library page.

    Show answer & explanation
  3. Question 3

    Which of these measures would lower the risk of having too many user accounts with the security administrator role in Azure AD?

    Show answer & explanation

    Correct answer: D

    Explanation: SSO will not reduce risk - this is a productivity enhancer

    Intune, conditional access and identity protection will reduce risk, but it is not specific to privileged administrator accounts

    A PIM access review would also reduce the risk, especially if configured to remove access if no longer needed thereby effectively reducing the number of privileged accounts. -- Reference: https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure

  4. Question 4

    You need to consider the underlined segment to establish whether it is accurate.

    You want to make sure that a user can assign Compliance Manager roles to users using only the minimum permissions required.

    You assign the user the Portal Admin role.

    Select “No adjustment required? if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.

    Show answer & explanation
  5. Question 5Select 3

    Your company subscribes to a n E5 version of Microsoft 365.

    You have recently created a security group via Microsoft Azure Active Directory (Azure AD), and added a number of users to it. You want to make sure that app enforced restrictions are applied to the group members when they access Microsoft Exchange Online from non-compliant devices. Where they are physically located should not matter.

    You have accessed the Azure portal to create a conditional access policy.

    Which of the following settings should you configure as part of the process? (Choose all that apply.)

    Show answer & explanation
  6. Question 6

    How do you require MFA for all users while keeping productivity disruptions to a minimum?

    Show answer & explanation

    Correct answer: B

    Explanation: Enabling MFA for all users using the MFA console will certainly cause all users to be challenged for MFA, but they will have to supply MFA for every authentication. Conditional access allows us to only challenge for MFA under certain conditions, thereby minimizing productivity impact, while maintaining a high level of security. -- Reference: https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/overview

  7. Question 7

    You need to consider the underlined segment to establish whether it is accurate.

    You have installed and initiated Azure AD Connect on a server running Windows Server in your company’s on-premises Active Directory domain.

    To view Azure AD Connect events, you should make use of the System event log on the Windows Server.

    Select “No adjustment required' if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.

    Show answer & explanation
  8. Question 8

    You create a new user using the M365 admin center. You plan to a ssign the new user the Security Reader role, but you first want to confirm what permissions will be made available to the user if you do so.

    Which interface will you use to a ccomplish your task?

    Show answer & explanation

    Correct answer: C

    Explanation: AAD Roles and administrators is the only one of the interfaces listed that enumerates the permissions of roles. -- Reference: httos://docs. microsoft.com/en-us/azure/active-directory/users-groups-roles/roles-create-custom

  9. Question 9

    NOTE: This question is a part of a series of questions that present the same scenario. For each of the following statements, select the best response(s) to the question or statement below. Each answer is worth one point.

    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

    You are a junior security administrator for your organization’s M365 implementation. All users are assigned a M365-E5 license and your senior colleagues have deployed full-stack ATP. You are requested to present a report on malware detected in email every Monday at your company's internal security meeting. Your current role does not afford you global administrator privileges and your organization has a strict least privilege policy.

    In the Security and Compliance Center, you navigate to the appropriate screen and choose + Create schedule

    NOTE: Change (or not) the highlighted section of the following statement to make it true.

    Show answer & explanation
  10. Question 10

    Your company has a M365 subscription and is using Intune to manage endpoints and mobile devices. Your company, however, does not allow the enrolment of personally owned devices in MDM, but allows the use of these devices to a ccess corporate data. The policy further states that all devices, whether personally owned or corporate owned must be prevented from accessing corporate data if the device is jailbroken or rooted.

    Which of the following would you deploy to a chieve your goal?

    Show answer & explanation

    Correct answer: E

    Explanation: Conditional access with device access control or condition will block access from non-compliant devices, but requires device enrolment in MDM. Device compliance policy will check (and block) jailbreak, but requires MDM.A device configuration profile requires MDM and also cannot check for jailbreak.

    App protection policy can check for jailbreak and doesn't require MDM. -- Reference: https://docs.microsoft.com/en-us/mem/intune/ai3iDs/app-protection-policy

Ready for the real thing?

The full MS-500 simulator has every exam-style question, timed mode, and instant scoring.

Go to the MS-500 simulator →