Pass Your Microsoft 365 MS-500 Exam on Apr 11, 2024 with 329 Questions
MS-500 Free Exam Study Guide! (Updated 329 Questions)
What Are MS-500 Primary Domains and Skills Tested?
The course outline of the Microsoft MS-500 exam, including the detailed subtopics is presented below:
- Implementing and managing identity and access (30-35%)
The first domain covers the following subtopics: Microsoft 365 hybrid environments' security, securing identities, implementing various methods of authentication, conditional access, role-based access control, working with Identity protection of Azure AD, and performing the Azure AD PIM (privileged identity management). These require one to have knowledge about authentication and synchronization options, Azure AD Connect, password management, planning for sign-on security, monitoring of MFA, working with Windows Hello, configuring device compliance, auditing roles, implementing various risk policies, and configuring Identity Protection alerts, among the rest.
- Implementation and management of threat protection (20-25%)
This section mainly focuses on solutions for enterprise hybrid threat protection, implementation of device protection, administering the application protection, management of office 365 ATP, and utilizing Azure Sentinel for security monitoring. The skills and knowledge involved are as follows: the ability to provide different operations with Azure ATP such as installation, monitoring, management, and configuration; planning for Microsoft Defender ATP as well as its implementation; working with Secure Boot; managing Windows and non-Windows device encryption; configuring and monitoring Office 365 ATP; performing operations related to Azure Sentinel and responding to threats in it.
- Administering protection of information (15-20%)
The third domain of MS-500 exam covers securing data access when it comes to Office 365 solutions, management of sensitivity labels as well as Data Loss Prevention, and implementation of Microsoft Cloud App Security. To handle all the associated tasks in the test, one should have the following skills: working with Customer Lockbox and B2B sharing for external users, configuring sensitivity labels as well as policies, planning for DLP solutions, monitoring DLP reports and administering notifications, planning for the implementation of Cloud App Security, managing cloud app discovery, configuring Oauth applications, working with policies and templates, and interpreting as well as responding to alerts of Cloud App Security.
- Administering of Microsoft 365 governance and compliance (20-25%)
The last section of MS-500 is dedicated to the following areas: analyzing security reporting and configuring it, analyzing and managing audit logs, administering data governance, performing management of search and investigation, and working with data privacy regulation compliance. To succeed in the tasks under this domain, one should be proficient in utilizing Microsoft Endpoint Manager Admin Center, providing audit log search, configuring retention policies, recovering deleted Office 365 data, working with data archiving, planning for eDiscovery and content search, administering Compliance Manager as well as reviewing its reports, etc.
NEW QUESTION # 58
Your network contains an Active Directory domain named contoso.com. The domain contains a VPN server named VPN1 that runs Windows Server 2016 and has the Remote Access server role installed.
You have a Microsoft Azure subscription.
You are deploying Azure Advanced Threat Protection (ATP)
You install an Azure ATP standalone sensor on a server named Server1 that runs Windows Server 2016.
You need to integrate the VPN and Azure ATP.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/azure-advanced-threat-protection/install-atp-step6-vpn
NEW QUESTION # 59
Please wait while the virtual machine loads. Once loaded, you may proceed to the lab section. This may take a few minutes, and the wait time will not be deducted from your overall test time.
When the Next button is available, click it to access the lab section. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design.
Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn't matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
Labs are not timed separately, and this exam may more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
Username and password
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Microsoft 365 Username:
admin@[email protected]
Microsoft 365 Password: #HSP.ug?$p6un
If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support only:
Lab instance: 11122308








You need to prevent any email messages that contain data covered by the U.K. Data Protection Act from being sent to recipients outside of your organization, unless the messages are sent to an external domain named adatum.com.
To complete this task, sign in to the Microsoft 365 admin center.
Answer:
Explanation:
See explanation below.
Explanation
1. After signing into the Microsoft 365 admin center, navigate to Compliance Management in the Exchange Admin center.
2. Click on "Data Loss Prevention" option.
3. To add a new custom DLP policy, Click on (+) plus button to get the context menu
4. Click on "New Custom DLP policy" option, a new window appears where you have to enter policy name, description, state and mode of the requirement details. Click on save button to create policy and continue...
5. You will be back to the "Data Loss Prevention" screen with newly added policy information.
6. Double click on the added row to open the policy details, click on rules option in left part of the screen as depicted
7. Click on (+) plus button to add a new rule. Select the "Block messages with sensitive information" rule.
8. On the following screen, we can add condition, action, exceptions, rule activation and deactivation dates
9. Click on "Select Sensitive information Types" to specify the sensitive information details.
10. Click on (+) plus button and add the following Sensitive information Types:
* U.K. National Insurance Number (NINO
* U.S. / U.K. Passport Number
* SWIFT Code
11. Click on Ok
12. Add an exception for recipients in the adatum.com domain
13. Add recipients for incident reports and click ok
14. Click save
15. Click save
Reference:
https://events.collab365.community/configure-data-loss-prevention-policies-in-exchange-online-in-office-365/
NEW QUESTION # 60
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some questions sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an on-premises Active Directory domain named contoso.com.
You install and run Azure AD Connect on a server named Server1 that runs Windows Server.
You need to view Azure AD Connect events.
You use the Application event log on Server1.
Does that meet the goal?
- A. Yes
- B. No
Answer: A
Explanation:
Reference:
https://support.pingidentity.com/s/article/PingOne-How-to-troubleshoot-an-AD-Connect-Instance
NEW QUESTION # 61
Which users are members of ADGroup1 and ADGroup2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/groups-dynamic-membership#suppor
NEW QUESTION # 62
How should you configure Group3? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 63
You are evaluating which devices are compliant in Intune.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 64
You have a Microsoft 365 description that contains a user named User1.
You need to that User1 can review registration and usage activity reports for Azure Multi-Factor Authentication (Azure MFA) for the subscription. The solution must meet the following requirements:
* Minimize Costs
* use the principle Of least privilege
What should you assign to user1?
Answer:
Explanation:
NEW QUESTION # 65
Please wait while the virtual machine loads. Once loaded, you may proceed to the lab section. This may take a few minutes, and the wait time will not be deducted from your overall test time.
When the Next button is available, click it to access the lab section. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design.
Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn't matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
Labs are not timed separately, and this exam may more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
Username and password
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Microsoft 365 Username:
admin@[email protected]
Microsoft 365 Password: #HSP.ug?$p6un
If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support only:
Lab instance: 11122308








You need to ensure that a user named Allan Deyoung receives incident reports when email messages that contain data covered by the U.K. Data Protection Act are sent outside of your organization.
To complete this task, sign in to the Microsoft 365 admin center.
Answer:
Explanation:
1. In the Security & Compliance Center > left navigation > Data loss prevention > Policy > + Create a policy.
2. Choose the U.K. Data Protection Act template > Next.
3. Name the policy > Next.
4. Choose All locations in Office 365 > Next.
5. At the first Policy Settings step just accept the defaults,
6. After clicking Next, you'll be presented with an additional Policy Settings page Deselect the Show policy tips to users and send them an email notification option.
Select the Detect when content that's being shared contains option, and configure the number instances to be 10.
Select the Send incident reports in email option.
Select the Choose what to include in the report and who receives it link to add Allan Deyoung as a recipient.
7. > Next
8. Select the option to turn on the policy right away > Next.
9. Click Create to finish creating the policy.
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/create-test-tune-dlp-policy?view=o365-worldwide
https://docs.microsoft.com/en-us/microsoft-365/compliance/data-loss-prevention-policies?view=o365-worldwide
https://docs.microsoft.com/en-us/microsoft-365/compliance/what-the-dlp-policy-templates-include?view=o365-worldwide
NEW QUESTION # 66
You have a Microsoft 365 ES subscription linked to an Azure Active Directory (Azure AD) tenant The tenant contains a user named User1 and multiple Windows 10 devices. The deuces are Azure AD joined and protected by using BitLocker Drive Encryption (BitLocker).
You need to ensure that User1 can perform tip following actions:
View BitLocker recovery keys.
Configure the usage location for the users in tenant.
The solution must use the principle of least privilege.
Which two roles should you assign to User' in the Microsoft 365 admin center? To answer, select the appropriate roles in the answer are a.
Each correct selection is one point.
Answer:
Explanation:
NEW QUESTION # 67
You plan to configure an access review to meet the security requirements for the workload administrators. You create an access review policy and specify the scope and a group.
Which other settings should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
NEW QUESTION # 68
Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the groups shown in the following table.
The domain is synced to a Microsoft Azure Active Directory (Azure AD) tenant that contains the groups shown in the following table.
You create an Azure Information Protection policy named Policy1.
You need to apply Policy1.
To which groups can you apply Policy1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/azure/information-protection/prepare
NEW QUESTION # 69
You have a Microsoft 365 subscription.
All computers run Windows 10 Enterprise and are managed by using Microsoft Intune.
You plan to view only security-related Windows telemetry data.
You need to ensure that only Windows security data is sent to Microsoft.
What should you create from the Intune admin center?
- A. a device compliance policy that has the System Security settings configured
- B. a device configuration profile that has the Endpoint Protection settings configured
- C. a device configuration profile that has device restrictions configured
- D. a device compliance policy that has the Device Health settings configured
Answer: C
Explanation:
Explanation/Reference:
https://docs.microsoft.com/en-us/intune/device-restrictions-windows-10#reporting-and-telemetry
NEW QUESTION # 70
You need to recommend an email malware solution that meets the security requirements.
What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
NEW QUESTION # 71
Your network contains an Active Directory domain named contoso.com. The domain contains a VPN server named VPN1 that runs Windows Server 2016 and has the Remote Access server role installed.
You have a Microsoft Azure subscription.
You are deploying Azure Advanced Threat Protection (ATP)
You install an Azure ATP standalone sensor on a server named Server1 that runs Windows Server 2016.
You need to integrate the VPN and Azure ATP.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/azure-advanced-threat-protection/install-atp-step6-vpn
NEW QUESTION # 72
You have an on-premises Hyper-V infrastructure that contains the following:
* An Active Directory domain
* A domain controller named Server1
* A member server named Server2
A security policy specifies that Server1 cannot connect to the Internet. Server2 can connect to the Internet.
You need to implement Azure Advanced Threat Protection (ATP) to monitor the security of the domain.
What should you configure on each server? To answer, drag the appropriate components to the correct servers.
Each component may only be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
NEW QUESTION # 73
Please wait while the virtual machine loads. Once loaded, you may proceed to the lab section. This may take a few minutes, and the wait time will not be deducted from your overall test time.
When the Next button is available, click it to access the lab section. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design.
Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn't matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
Labs are not timed separately, and this exam may more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
Username and password
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Microsoft 365 Username:
admin@[email protected]
Microsoft 365 Password: &=Q8v@2qGzYz
If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support only:
Lab instance: 11032396
You need to ensure that a global administrator is notified when a document that contains U.S. Health Insurance Portability and Accountability Act (HIPAA) data is identified in your Microsoft 365 tenant.
To complete this task, sign in to the Microsoft Office 365 admin center.
Answer:
Explanation:
1. In the Security & Compliance Center > left navigation > Data loss prevention > Policy > + Create a policy.
2. Choose the U.S. Health Insurance Portability and Accountability Act (HIPAA) template > Next.
3. Name the policy > Next.
4. Choose All locations in Office 365 > Next.
5. At the first Policy Settings step just accept the defaults,
6. After clicking Next, you'll be presented with an additional Policy Settings page
* Deselect the Show policy tips to users and send them an email notification option.
* Select the Detect when content that's being shared contains option, and decrease the number of instances to 1.
* Select the Send incident reports in email option.
7. > Next
8. Select the option to turn on the policy right away > Next.
9. Click Create to finish creating the policy.
References:
https://docs.microsoft.com/en-us/microsoft-365/compliance/create-test-tune-dlp-policy?view=o365-worldwide
https://docs.microsoft.com/en-us/microsoft-365/compliance/data-loss-prevention-policies?view=o365-worldwide
https://docs.microsoft.com/en-us/microsoft-365/compliance/what-the-dlp-policy-templates-include?view=o365-w
NEW QUESTION # 74
......
Difficulty in writing the Microsoft MS-500 Exam:
Due to the fact the Microsoft certification exams are computer-based tests, candidates can find it extremely difficult to write, especially those candidates who have been out of the field for a long time or those with little or no knowledge of the subject they are about to be tested on. Outdated content may lead the candidate to take the test more than once. The individual needs to practice writing many sample questions, and they need to know how to answer software development questions that have been previously asked on the MS-500 Exam. Requirements may vary from one exam to another. The multiple-choice format of these exams is not easy for most candidates and can cause them mental stress and difficulty understanding the test objective and answering the question correctly. MS-500 Dumps are commonly used to assist candidates in their preparation for the certification exams. The Microsoft certification exams are not only updated every year, but they also change their format. Any threat to safety can result in a loss of focus and concentration. Many candidates fear that they will forget some questions, so they abridge their answers by omitting irrelevant information, but this will only result in wasting valuable time and money on rescheduling exams that do not allow abridging test questions. Most candidates who fail these exams do not get the opportunity to get their results. Data is updated every five minutes, which will allow the candidate to track their progress. Workers can withdraw from the certification exam when they want.
The MS-500 Exam covers a wide range of security topics related to Microsoft 365, including identity and access management, threat protection, information protection, security management, and compliance. Candidates who pass MS-500 exam demonstrate their ability to implement and manage security solutions that protect the organization's data and meet compliance requirements.
MS-500 Dumps for Microsoft 365 Certified Exam Questions and Answer: https://www.exam4free.com/MS-500-valid-dumps.html
Realistic Verified MS-500 exam dumps Q&As - MS-500 Free Update: https://drive.google.com/open?id=1w6z7rGUqRt2-Dc9tLBZdHgVd_Jyy795b
