Based on Official Syllabus Topics of Actual Microsoft MS-500 Exam [Q190-Q211]

Share

Based on Official Syllabus Topics of Actual Microsoft MS-500 Exam

Free MS-500 Dumps are Available for Instant Access


Target Audience and Prerequisites

MS-500 exam is designed for both beginners and practitioners in the field who need more skills in the profession. The applicants should have background knowledge of data protection, identity protection, data loss prevention, system security management, and the governance of data in an organization. Also, familiarity with Microsoft 365 workloads is recommended.


What Are MS-500 Primary Domains and Skills Tested?

The course outline of the Microsoft MS-500 exam, including the detailed subtopics is presented below:

  1. Implementing and managing identity and access (30-35%)

The first domain covers the following subtopics: Microsoft 365 hybrid environments' security, securing identities, implementing various methods of authentication, conditional access, role-based access control, working with Identity protection of Azure AD, and performing the Azure AD PIM (privileged identity management). These require one to have knowledge about authentication and synchronization options, Azure AD Connect, password management, planning for sign-on security, monitoring of MFA, working with Windows Hello, configuring device compliance, auditing roles, implementing various risk policies, and configuring Identity Protection alerts, among the rest.

  1. Implementation and management of threat protection (20-25%)

This section mainly focuses on solutions for enterprise hybrid threat protection, implementation of device protection, administering the application protection, management of office 365 ATP, and utilizing Azure Sentinel for security monitoring. The skills and knowledge involved are as follows: the ability to provide different operations with Azure ATP such as installation, monitoring, management, and configuration; planning for Microsoft Defender ATP as well as its implementation; working with Secure Boot; managing Windows and non-Windows device encryption; configuring and monitoring Office 365 ATP; performing operations related to Azure Sentinel and responding to threats in it.

  1. Administering protection of information (15-20%)

The third domain of MS-500 exam covers securing data access when it comes to Office 365 solutions, management of sensitivity labels as well as Data Loss Prevention, and implementation of Microsoft Cloud App Security. To handle all the associated tasks in the test, one should have the following skills: working with Customer Lockbox and B2B sharing for external users, configuring sensitivity labels as well as policies, planning for DLP solutions, monitoring DLP reports and administering notifications, planning for the implementation of Cloud App Security, managing cloud app discovery, configuring Oauth applications, working with policies and templates, and interpreting as well as responding to alerts of Cloud App Security.

  1. Administering of Microsoft 365 governance and compliance (20-25%)

The last section of MS-500 is dedicated to the following areas: analyzing security reporting and configuring it, analyzing and managing audit logs, administering data governance, performing management of search and investigation, and working with data privacy regulation compliance. To succeed in the tasks under this domain, one should be proficient in utilizing Microsoft Endpoint Manager Admin Center, providing audit log search, configuring retention policies, recovering deleted Office 365 data, working with data archiving, planning for eDiscovery and content search, administering Compliance Manager as well as reviewing its reports, etc.

 

NEW QUESTION # 190
A user stores the following files in Microsoft OneDrive:
* File.docx
* ImportantFile.docx
* File_Important.docx
You create a Microsoft Cloud App Security file policy Policy1 that has the filter shown in the following exhibit.

To which files does Policy1 apply?

  • A. ImportantFile.docx only
  • B. File.docx and File_Important.docx only
  • C. File.docx, ImportantFile.docx, and File_Important.docx
  • D. File_Important.docx only
  • E. File.docx only

Answer: C

Explanation:
Reference:
https://docs.microsoft.com/en-us/cloud-app-security/file-filters


NEW QUESTION # 191
Please wait while the virtual machine loads. Once loaded, you may proceed to the lab section. This may take a few minutes, and the wait time will not be deducted from your overall test time.
When the Next button is available, click it to access the lab section. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design.
Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn't matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
Labs are not timed separately, and this exam may more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
Username and password

Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Microsoft 365 Username:
admin@[email protected]
Microsoft 365 Password: &=Q8v@2qGzYz
If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support only:
Lab instance: 11032396
You need to ensure that a global administrator is notified when a document that contains U.S. Health Insurance Portability and Accountability Act (HIPAA) data is identified in your Microsoft 365 tenant.
To complete this task, sign in to the Microsoft Office 365 admin center.

Answer:

Explanation:
1. In the Security & Compliance Center > left navigation > Data loss prevention > Policy > + Create a policy.
2. Choose the U.S. Health Insurance Portability and Accountability Act (HIPAA) template > Next.
3. Name the policy > Next.
4. Choose All locations in Office 365 > Next.
5. At the first Policy Settings step just accept the defaults,
6. After clicking Next, you'll be presented with an additional Policy Settings page
* Deselect the Show policy tips to users and send them an email notification option.
* Select the Detect when content that's being shared contains option, and decrease the number of instances to 1.
* Select the Send incident reports in email option.
7. > Next
8. Select the option to turn on the policy right away > Next.
9. Click Create to finish creating the policy.
References:
https://docs.microsoft.com/en-us/microsoft-365/compliance/create-test-tune-dlp-policy?view=o365-worldwide
https://docs.microsoft.com/en-us/microsoft-365/compliance/data-loss-prevention-policies?view=o365-worldwide
https://docs.microsoft.com/en-us/microsoft-365/compliance/what-the-dlp-policy-templates-include?view=o365-w


NEW QUESTION # 192
How should you configure Azure AD Connect? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation


NEW QUESTION # 193
You have a Microsoft 365 E5 subscription.
You implement Advanced Threat Protection (ATP) safe attachments policies for all users.
User reports that email messages containing attachments take longer than expected to be received.
You need to reduce the amount of time it takes to receive email messages that contain attachments. The solution must ensure that all attachments are scanned for malware. Attachments that have malware must be blocked.
What should you do from ATP?

  • A. Add an exception
  • B. Set the action to Block
  • C. Add a condition
  • D. Set the action to Dynamic Delivery

Answer: D

Explanation:
Explanation/Reference:
https://docs.microsoft.com/en-us/office365/securitycompliance/dynamic-delivery-and-previewing


NEW QUESTION # 194
Which policies apply to which devices? To answer, select the appropriate options inthe answer area.
NOTE:Each correct selection is worth one point.

Answer:

Explanation:

Explanation


NEW QUESTION # 195
You recently created and published several labels policies in a Microsoft 365 subscription.
You need to view which labels were applied by users manually and which labels were applied automatically.
What should you do from the Security & Compliance admin center?

  • A. From Search & investigation, select eDiscovery
  • B. From Data governance, select Events
  • C. From Search & investigation, select Content search
  • D. From Reports, select Dashboard

Answer: D

Explanation:
Explanation
https://docs.microsoft.com/en-us/microsoft-365/compliance/view-label-activity-for-documents


NEW QUESTION # 196
You have a Microsoft 365 E5 subscription that contains an Azure Active Directory (Azure AD) tenant named contoso.com.
Azure AD Identity Protection alerts for contoso.com are configured as shown in the following exhibit.

A user named User1 is configured to receive alerts from Azure AD Identity Protection.
You create users in contoso.com as shown in the following table.

The users perform the sign-ins shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection
https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure-risk-policies


NEW QUESTION # 197
You have a Microsoft 365 subscription that uses an Azure Active Directory (Azure AD) tenant named contoso.com. All the devices in the tenant are managed by using Microsoft Intune.
You purchase a cloud app named App1 that supports session controls.
You need to ensure that access to App can be reviewed in real time.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/cloud-app-security/access-policy-aad


NEW QUESTION # 198
You haw a Microsoft 365 subscription that contains the users shown in the following table.

You need to ensure that User1, User2 , and User3 can use self-service password reset (SSPR). The solution must not affect User 4.
Solution: You enable SSPR for Group1.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

Explanation:
Explanation
By default, self-service password reset is enabled for Directory writers and Security administrator but not for Azure Information Protection administrators and Cloud application administrators. Thus, we must enable SSPR for User3 by applying it to Group2.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-policy#administrator-reset-p


NEW QUESTION # 199
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
For contoso.com, you create a group naming policy that has the following configuration.
<Department> - <Group name>
You plan to create the groups shown in the following table.

Which users can be used to create each group? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://office365itpros.com/2020/01/22/using-groups-admin-role/
https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference


NEW QUESTION # 200
You haw a Microsoft 365 subscription.
You receive a General Data Protection Regulation (GOPR) request for the custom dictionary of a user From The Compliance admin center you need to create a content search, should you configure the content search?

  • A. Condition: Type Operator Equals any of Value Documents
  • B. .Condition; Type Operator Equals any of Value Office Roaming Service
  • C. Condition: We type Operator Equals any of Value dic
  • D. Condition: Title Operator Equals any of Value Normal. dot

Answer: A


NEW QUESTION # 201
You have a Microsoft 365 tenant.
You need to retain Azure Active Directory (Azure AD) audit logs for two years. Administrators must be able to query the audit log information by using the Azure Active Directory admin center.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Graphical user interface, text, application Description automatically generated

Reference:
https://docs.microsoft.com/en-gb/azure/active-directory/reports-monitoring/howto-analyze-activity-logs-log-anal


NEW QUESTION # 202
You view Compliance Manager as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/office365/securitycompliance/meet-data-protection-and-regulatory-reqs-using-microsoft-cloud


NEW QUESTION # 203
Microsoft 365 E5 licenses. You plan to implement an Advanced Threat Protection (ATP) anti-phishing policy. You need to enable mailbox intelligence for all users. What should you do first?

  • A. Purchase the ATP add-on.
  • B. Select Directory extension attribute sync in Microsoft Azure Active Directory Connect {Azure AD Connect).
  • C. Configure attribute filtering in Microsoft Azure Active Directory Connect (Azure AD Connect).
  • D. Migrate the on-premises mailboxes to Exchange Online.

Answer: D

Explanation:
References:
https://docs.microsoft.com/en-us/office365/securitycompliance/set-up-anti-phishing-policies


NEW QUESTION # 204
Your network contains an on-premises Active Directory domain and a Microsoft 365 subscription.
You plan to deploy a hybrid Azure Active Directory (Azure AD) tenant that has Azure AD Identity Protection risk policies enabled.
You need to configure Azure AD Connect to support the planned deployment.
Which Azure AD Connect authentication method should you select?

  • A. Pass-through authentication
  • B. Federation with PingFederate
  • C. Password Hash Synchronization
  • D. Federation with AD FS

Answer: C


NEW QUESTION # 205
Your network contains an Active Directory domain named contoso.com. The domain contains a VPN server named VPN1 that runs Windows Server 2016 and has the Remote Access server role installed.
You have a Microsoft Azure subscription.
You are deploying Azure Advanced Threat Protection (ATP)
You install an Azure ATP standalone sensor on a server named Server1 that runs Windows Server 2016.
You need to integrate the VPN and Azure ATP.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

Reference:
https://docs.microsoft.com/en-us/azure-advanced-threat-protection/install-atp-step6-vpn


NEW QUESTION # 206
You have a Microsoft 365 subscription that uses an Azure Active Directory (Azure AD) tenant named contoso.com. OneDrive stores files that are shared with external users. The files are configured as shown in the following table.

You create a data loss prevention (DLP) policy that applies to the content stored in OneDrive accounts. The policy contains the following three rules:
* Rulel:
* Conditions: Label 1, Detect content that's shared with people outside my organization
* Actions: Restrict access to the content for external users
* User notifications: Notify the user who last modified the content
* User overrides: On
* Priority: 0
* Rule2:
* Conditions: Label 1 or Label2
* Actions: Restrict access to the content
* Priority: 1
* Rule3:
* Conditions: Label2, Detect content that's shared with people outside my organization
* Actions: Restrict access to the content for external users
* User notifications: Notify the user who last modified the content
* User overrides: On
* Priority: 2
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation


NEW QUESTION # 207
Your network contains an Active Directory domain named contoso.com. The domain contains a VPN server named VPN1 that runs Windows Server 2016 and has the Remote Access server role installed.
You have a Microsoft Azure subscription.
You are deploying Azure Advanced Threat Protection (ATP)
You install an Azure ATP standalone sensor on a server named Server1 that runs Windows Server 2016.
You need to integrate the VPN and Azure ATP.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

Reference:
https://docs.microsoft.com/en-us/azure-advanced-threat-protection/install-atp-step6-vpn


NEW QUESTION # 208
Note: This question is part of a series of questions thatpresent the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question inthis section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 subscription that contains the users shown in the following table.

You discover that all the users in the subscription can access Compliance Manager reports.
The Compliance Manager Reader role is not assigned to any users.
You need to recommend a solution to prevent a user named User5 from accessing the Compliance Manager reports.
Solution: You recommend assigning the Compliance Manager Reader role to User5.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: B


NEW QUESTION # 209
You have a Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) deployment that has the custom network indicators turned on. Microsoft Defender ATP protects two computers that run Windows
10 as shown in the following table.

Microsoft Defender ATP has the machine groups shown in the following table.

From Microsoft Defender Security Center, you create the URLs/Domains indicators shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation


NEW QUESTION # 210
You plan to add a file named ConfidentialHR.docx to a Microsoft SharePoint library.
You need to ensure that a user named Megan Bowen is notified when another user accesses ConfidentialHR.xlsx.
To complete this task, sign in to the Microsoft 365 portal.

Answer:

Explanation:
See explanation below.
Explanation
You need to configure an alert policy.
* Go to the Security & Compliance Admin Center.
* Navigate to Alerts > Alert Policies
* Click on + New alert policy
* Give the policy a name and select a severity level. For example: Medium.
* In the Category section, select Information Governance and click Next.
* In the Select an activity section, select Any file or folder activity.
* Click Add a condition and select File name.
* Type in the filename ConfidentialHR.xlsx and click Next.
* In the email recipients section, add Megan Bowen and click Next.
* Click Finish to create the alert policy.


NEW QUESTION # 211
......


Passing the Microsoft MS-500 exam is essential for professionals who want to demonstrate their expertise in Microsoft 365 security administration. Microsoft 365 Security Administration certification validates a candidate's skills in managing and monitoring security and compliance solutions for Microsoft 365 environments. It also demonstrates their ability to implement and manage Microsoft 365 security features and capabilities, such as identity and access management, threat protection, information protection, and security management.

 

The Most In-Demand MS-500 Pass Guaranteed Quiz : https://www.validvce.com/MS-500-exam-collection.html

View All MS-500 Actual Exam Questions Answers and Explanations for Free: https://drive.google.com/open?id=14wyCYdYyfUDVxX-sLN6FkcDsnRZqk_AR