Looking for more? Click here to get the full PDF with 152+ practice questions for $10 for offline study and deeper preparation.
Question 1
You recently created and published several label policies in a Microsoft 365 subscription. You need to view which labels were applied by users manually and which labels were applied automatically. What should you do from the Microsoft 365 Compliance center?
A. From Search & investigation, select Content search
B. From Alerts, select View alerts
C. From eDiscovery, view an eDiscovery case
D. From Reports, select Dashboard
Show Answer
Correct Answer:
D. From Reports, select Dashboard
Question 2
You configure several Advanced Threat Protection (ATP) policies in a Microsoft 365 subscription. You need to allow a user named User1 to view ATP reports in the Threat management dashboard. Which role provides User1 with the required role permissions?
A. Security administrators
B. Exchange administrator
C. Compliance administrator
D. Message center reader
Show Answer
Correct Answer:
A. Security administrators
Question 3
You need to enable and configure Microsoft Defender for Endpoint to meet the security requirements. What should you do?
A. Configure port mirroring
B. Create the ForceDefenderPassiveMode registry setting
C. Download and install the Microsoft Monitoring Agent
D. Run WindowsDefenderATPOnboardingScript.cmd
Show Answer
Correct Answer:
D. Run WindowsDefenderATPOnboardingScript.cmd
Question 4
Which IP address space should you include in the Trusted IP MFA configuration?
A. 131.107.83.0/28
B. 192.168.16.0/20
C. 172.16.0.0/24
D. 192.168.0.0/20
Show Answer
Correct Answer:
A. 131.107.83.0/28
Question 5
You have an Azure Active Directory (Azure AD) tenant that has a Microsoft 365 subscription. You recently configured the tenant to require multi-factor authentication (MFA) for risky sign-ins. You need to review the users who required MFA. What should you do?
A. From the Microsoft 365 admin center, review a Security & Compliance report
B. From the Microsoft 365 Compliance center, run an audit log search and download the results to a CSV file
C. From the Azure Active Directory admin center, review the Authentication methods activities
D. From the Azure Active Directory admin center, download the sign-ins to a CSV file
Show Answer
Correct Answer:
D. From the Azure Active Directory admin center, download the sign-ins to a CSV file
Question 6
You have a Microsoft 365 subscription. You have a team named Team1 in Microsoft Teams. You plan to place all the content in Team1 on hold. You need to identify which mailbox and which Microsoft SharePoint site collection are associated to Team1. Which cmdlet should you use?
A. Get-UnifiedGroup
B. Get-MailUser
C. Get-Team
D. Get-TeamChannel
Show Answer
Correct Answer:
A. Get-UnifiedGroup
Question 7
You configure several Microsoft Defender for Office 365 policies in a Microsoft 365 subscription. You need to allow a user named User1 to view Defender for Office 365 reports from the Threat management dashboard. Which role provides User1 with the required role permissions?
A. Reports reader
B. Exchange administrator
C. Security administrators
D. Compliance administrator
Show Answer
Correct Answer:
C. Security administrators
Question 8
Your company has 500 computers. You plan to protect the computers by using Microsoft Defender for Endpoint. Twenty of the computers belong to company executives. You need to recommend a remediation solution that meets the following requirements: ✑ Microsoft Defender for Endpoint administrators must manually approve all remediation for the executives ✑ Remediation must occur automatically for all other users What should you recommend doing from Microsoft 365 Defender portal?
A. Configure 20 system exclusions on automation allowed/block lists
B. Configure two alert notification rules
C. Download an offboarding package for the computers of the 20 executives
D. Create two device groups
Show Answer
Correct Answer:
D. Create two device groups
Question 9
You have a Microsoft 365 E5 subscription. You plan to implement retention policies for Microsoft Teams. Which item types can be retained?
A. voice memos from the Teams mobile client
B. code snippets
C. embedded images
Show Answer
Correct Answer:
C. embedded images
Question 10
You have a Microsoft 365 E5 subscription that uses Azure Active Directory (Azure AD) Privileged Identity Management (PIM). A user named User1 is eligible for the User Account Administrator role. You need User1 to request to activate the User Account Administrator role. From where should User1 request to activate the role?
A. the My Access portal
B. the Microsoft 365 Defender portal
C. the Microsoft 365 admin center
D. the Azure Active Directory admin center
Show Answer
Correct Answer:
D. the Azure Active Directory admin center
Question 11
You have a Microsoft 365 subscription. You have a Microsoft SharePoint Online site named Site1. You have a Data Subject Request (DSR) case named Case1 that searches Site1. You create a new sensitive information type. You need to ensure that Case1 returns all the documents that contain the new sensitive information type. What should you do?
A. From the Microsoft 365 Compliance center, create a new Search by ID List
B. From Site1, modify the search dictionary
C. From the Microsoft 365 Compliance center, create a new Content search
D. From Site1, initiate a re-indexing of Site1
Show Answer
Correct Answer:
C. From the Microsoft 365 Compliance center, create a new Content search
Question 12
You have a hybrid Azure Active Directory (Azure AD) tenant that has pass-through authentication enabled. You plan to implement Azure AD Identity Protection and enable the user risk policy. You need to configure the environment to support the user risk policy. What should you do first?
A. Enable the sign-in risk policy
B. Enforce the multi-factor authentication (MFA) registration policy
C. Configure a conditional access policy
D. Enable password hash synchronization
Show Answer
Correct Answer:
D. Enable password hash synchronization
Question 13
You have a Microsoft 365 E5 subscription that contains a user named User1. You need to ensure that User1 can configure an Azure Active Directory (Azure AD) Identity Protection user risk policy and receive Azure AD Identity Protection alerts. The solution must use the principle of least privilege. Which role should you assign to User1?
A. Security Operator
B. Identity Governance Administrator
C. Security Administrator
D. Security Reader
Show Answer
Correct Answer:
C. Security Administrator
Question 14
Your company has a Microsoft 365 subscription that includes a user named User1. You suspect that User1 sent email messages to a competitor detailing company secrets. You need to recommend a solution to ensure that in the future you can review any email messages sent by User1 to the competitor, including sent items that were deleted. What should you include in the recommendation?
A. Enable In-Place Archiving for the mailbox of User1
B. From the Microsoft 365 Compliance center, perform a content search of the mailbox of User1
C. Place a Litigation Hold on the mailbox of User1
D. Configure message delivery restrictions for the mailbox of User1
Show Answer
Correct Answer:
C. Place a Litigation Hold on the mailbox of User1
Question 15
You have a Microsoft 365 E5 subscription. You need to enable support for sensitivity labels in Microsoft SharePoint Online. What should you use?
A. the SharePoint admin center
B. the Microsoft 365 admin center
C. the Microsoft 365 Compliance center
D. the Azure Active Directory admin center
Show Answer
Correct Answer:
C. the Microsoft 365 Compliance center
Question 16
Your company has a Microsoft 365 E5 subscription that uses Microsoft Defender for identity. You plan to create a detection exclusion in Microsoft Defender for Identity. What should you use to create the detection exclusion?
A. Microsoft Defender for Identity portal
B. Microsoft 365 Compliance center
C. Microsoft Defender for Cloud Apps portal
D. Microsoft 365 Defender portal
Show Answer
Correct Answer:
D. Microsoft 365 Defender portal
Question 17
You have a Microsoft 365 E5 subscription. A user reports that changes were made to several files in Microsoft OneDrive. You need to identify which files were modified by which users in the user's OneDrive. What should you do?
A. From the Azure Active Directory admin center, open the audit log
B. From Microsoft 365 Compliance admin center, perform an eDiscovery search
C. From Microsoft Cloud App Security, open the activity log
D. From the SharePoint admin center, select Access control
Show Answer
Correct Answer:
C. From Microsoft Cloud App Security, open the activity log
Question 18
You have a Microsoft 365 subscription that contains 100 users and a Microsoft 365 group named Group1. All users have Windows 10 devices and use Microsoft SharePoint Online and Exchange Online. A sensitivity label named Label1 is published as the default label for Group1. You add two sublabels named Sublabel1 and Sublabel2 to Label1. You need to ensure that the settings in Sublabel1 are applied by default to Group1. What should you do?
A. Change the order of Sublabel1
B. Modify the policy of Label1
C. Duplicate all the settings from Sublabel1 to Label1
D. Delete the policy of Label1 and publish Sublabel1
Show Answer
Correct Answer:
D. Delete the policy of Label1 and publish Sublabel1
Question 19
You have a Microsoft 365 E5 subscription. You need to use Attack simulation training to launch a credential harvest simulation. For which Microsoft 365 workloads can you create a payload?
A. Microsoft Exchange Online only
B. Microsoft Teams, Exchange Online, SharePoint Online, and OneDrive
C. Microsoft Teams and Exchange Online only
D. Microsoft SharePoint Online and OneDrive only
Show Answer
Correct Answer:
A. Microsoft Exchange Online only
Question 20
Your company has a main office and a Microsoft 365 subscription. You need to enforce Microsoft Azure Multi-Factor Authentication (MFA) by using conditional access for all users who are NOT physically present in the office. What should you include in the configuration?
A. a user risk policy
B. a sign-in risk policy
C. a named location in Azure Active Directory (Azure AD)
D. an Azure MFA Server
Show Answer
Correct Answer:
C. a named location in Azure Active Directory (Azure AD)
Aced these? Get the Full Exam
Download the complete MS-500 study bundle with 152+ questions in a single printable PDF.