Microsoft SC-500 Practice Test Questions and Exam Dumps Part14 Q261-280

View Full Microsoft SC-500 Exam Dumps and Practice Test Dumps

 

Question 261. Which Microsoft Entra capability can require multifactor authentication when a sign-in is considered risky?

  1. Microsoft Entra ID Protection with Conditional Access
  2. Microsoft Entra Connect
  3. Microsoft Entra Domain Services
  4. Microsoft Entra Verified ID

Correct Answer: 1. Microsoft Entra ID Protection with Conditional Access

Explanation:

Microsoft Entra ID Protection identifies identity-related risks and can provide risk information that Conditional Access uses to make access decisions. An organization can configure a Conditional Access policy that responds to elevated sign-in risk by requiring multifactor authentication or another appropriate control. This provides adaptive protection because the authentication requirement can change according to the security context of the request. Instead of treating every sign-in identically, the organization can apply stronger controls when risk signals indicate suspicious activity. This approach supports Zero Trust by continuously evaluating access conditions. It can also help protect users when attackers attempt to authenticate using credentials obtained through phishing, credential theft, or other compromise techniques.

Question 262. Which Microsoft Sentinel feature is used to detect suspicious patterns automatically and generate security incidents?

  1. Workbooks
  2. Analytics rules
  3. Data connectors
  4. Access reviews

Correct Answer: 2. Analytics rules

Explanation:

Microsoft Sentinel analytics rules are used to identify suspicious activity in collected security data. Administrators can create rules that evaluate events and patterns using Kusto Query Language or built-in detection templates. When a configured rule identifies activity that meets its conditions, Sentinel can generate alerts and, depending on configuration, incidents for investigation. Analytics rules are therefore an important detection mechanism within Sentinel. They differ from hunting queries, which are generally used by analysts for proactive investigation, and workbooks, which focus on visualization. Well-designed analytics rules help security teams detect known attack behaviors consistently and provide structured information that can be investigated alongside other security signals.

Question 263. Which Microsoft Purview feature can apply encryption and usage restrictions to sensitive documents and emails?

  1. Retention policies
  2. Audit logs
  3. Sensitivity labels
  4. Data connectors

Correct Answer: 3. Sensitivity labels

Explanation:

Microsoft Purview sensitivity labels can classify content according to sensitivity and can be configured with protection controls such as encryption and usage restrictions. When appropriate, labels can help ensure that sensitive documents and emails receive protections that remain associated with the content. This provides more than simple classification because organizations can use labels to enforce handling requirements. Sensitivity labels are different from retention policies, which manage how long information should be retained or deleted. They are also different from DLP, which focuses on detecting and preventing inappropriate data movement. Using sensitivity labels consistently can help organizations establish clear information protection requirements across supported Microsoft 365 workloads.

Question 264. Which Microsoft security solution helps detect suspicious activity involving domain controllers and on-premises identities?

  1. Microsoft Defender for Identity
  2. Microsoft Defender for Cloud Apps
  3. Microsoft Defender for Office 365
  4. Microsoft Purview

Correct Answer: 1. Microsoft Defender for Identity

Explanation:

Microsoft Defender for Identity monitors signals from on-premises Active Directory environments and helps detect identity-based attacks. It can identify suspicious behaviors associated with techniques such as reconnaissance, credential theft, lateral movement, and attacks involving domain controllers. This visibility is particularly important in hybrid environments where on-premises Active Directory remains connected to cloud identity services. Security analysts can use Defender for Identity alerts and investigation information alongside Microsoft Defender XDR signals to understand broader attack activity. By monitoring identity behavior within the traditional directory environment, the solution helps organizations identify threats that may otherwise remain difficult to detect using endpoint or cloud-only security controls.

Question 265. Which Microsoft Intune feature should be used to determine whether managed devices satisfy organizational security requirements?

  1. Device configuration profiles
  2. Compliance policies
  3. Application protection policies only
  4. Microsoft Sentinel workbooks

Correct Answer: 2. Compliance policies

Explanation:

Microsoft Intune compliance policies evaluate whether managed devices meet defined organizational requirements. Policies can check conditions such as operating system versions, encryption status, password requirements, device security settings, and other supported criteria. The resulting compliance state can be used by Microsoft Entra Conditional Access when determining whether a device should be allowed to access organizational resources. Compliance policies differ from configuration profiles: configuration profiles apply or establish settings, while compliance policies assess whether the device meets required conditions. Combining both capabilities provides stronger device management because administrators can configure secure settings and then verify that devices continue to satisfy the organization’s security standards.

Question 266. Which Microsoft Entra capability provides temporary activation of privileged roles with controls such as approval and MFA?

  1. Microsoft Entra access reviews
  2. Microsoft Entra audit logs
  3. Microsoft Entra Privileged Identity Management
  4. Microsoft Entra Lifecycle Workflows

Correct Answer: 3. Microsoft Entra Privileged Identity Management

Explanation:

Microsoft Entra Privileged Identity Management helps organizations control privileged role assignments and activations. Instead of keeping administrators permanently active in sensitive roles, PIM can allow them to remain eligible and activate privileges only when needed. Organizations can configure requirements such as multifactor authentication, approval, justification, notifications, and limited activation duration. These controls reduce the exposure created by standing administrative privileges. PIM also provides information about role assignments and activation activity, helping security teams monitor privileged operations. This approach supports least privilege and Zero Trust because elevated permissions are treated as temporary and controlled access rather than as a permanent entitlement for administrators.

Question 267. Which Microsoft Defender solution can identify malicious URLs and attachments delivered through organizational email?

  1. Defender for Endpoint
  2. Defender for Identity
  3. Defender for Office 365
  4. Defender for Cloud Apps

Correct Answer: 3. Defender for Office 365

Explanation:

Microsoft Defender for Office 365 provides security capabilities for protecting email and collaboration workloads from threats such as phishing messages, malicious URLs, and harmful attachments. It can analyze incoming content and use threat intelligence and security signals to identify potentially dangerous messages. The service also provides investigation capabilities that help security teams understand detected threats and their impact. Email-based attacks frequently attempt to obtain credentials or deliver malware, making messaging security an important component of an organization’s overall security strategy. Defender for Office 365 complements endpoint, identity, and data security solutions so that threats can be addressed across multiple stages of an attack rather than relying on a single protective layer.

Question 268. Which Microsoft Sentinel capability allows analysts to investigate security data using Kusto Query Language?

  1. Threat hunting
  2. Retention policies
  3. Access reviews
  4. Device compliance

Correct Answer: 1. Threat hunting

Explanation:

Microsoft Sentinel threat hunting allows security analysts to proactively search collected security data for suspicious activity using Kusto Query Language. Analysts can create queries to investigate hypotheses, identify unusual patterns, search for indicators, and discover activity that may not have generated an existing alert. Hunting is valuable because it allows analysts to look beyond predefined detections and investigate behaviors based on emerging threats or specific concerns. Useful hunting queries can later be incorporated into analytics rules when an organization wants to detect the same behavior automatically. This makes threat hunting an important part of a mature security operation, particularly when analysts need to investigate activity proactively rather than simply responding to generated alerts.

Question 269. Which Zero Trust principle emphasizes making access decisions based on current identity, device, application, and risk information?

  1. Assume breach
  2. Verify explicitly
  3. Trust the internal network
  4. Maximize privileges

Correct Answer: 2. Verify explicitly

Explanation:

The Zero Trust principle “verify explicitly” requires organizations to evaluate relevant signals before granting access instead of automatically trusting a request. These signals can include user identity, device health, authentication strength, application, location, and detected risk. Microsoft Entra Conditional Access can bring many of these factors together to create policies that make access decisions based on current conditions. This approach is especially important because users and devices can become compromised after they have successfully authenticated. Explicit verification therefore supports continuous evaluation rather than relying on a single authentication event. It helps organizations establish access controls that respond to the actual security context of each request.

Question 270. Which Microsoft Defender capability provides a unified view of related security alerts across multiple Microsoft security products?

  1. Microsoft Defender XDR
  2. Microsoft Secure Score
  3. Microsoft Intune
  4. Microsoft Purview

Correct Answer: 1. Microsoft Defender XDR

Explanation:

Microsoft Defender XDR correlates security signals across supported Microsoft Defender products to provide a broader view of related attacks. Instead of investigating endpoint, identity, email, and other alerts independently, analysts can examine connected signals within a more unified incident context. This correlation can help identify relationships between events and provide a clearer understanding of an attack chain. For example, an email threat may be associated with endpoint activity and subsequent identity compromise. Defender XDR can help security teams investigate these relationships and determine the broader scope of an incident. This reduces alert fragmentation and provides analysts with more context when determining the appropriate response to a security event.

Question 271. Which Microsoft Purview capability helps prevent users from accidentally sending sensitive information to unauthorized destinations?

  1. Data Loss Prevention
  2. Retention labels
  3. Audit logs
  4. eDiscovery searches

Correct Answer: 1. Data Loss Prevention

Explanation:

Microsoft Purview Data Loss Prevention helps organizations identify and protect sensitive information when users perform activities that could result in inappropriate disclosure. DLP policies can detect sensitive information using configured conditions and then apply actions such as notifications, policy tips, auditing, or restrictions, depending on the supported workload and configuration. This allows organizations to reduce accidental data exposure while also establishing consistent handling requirements. DLP works alongside other Purview capabilities rather than replacing them. Sensitivity labels classify and protect content, while retention controls address information lifecycle requirements. Together, these capabilities help organizations maintain stronger governance over sensitive information and reduce the likelihood of unauthorized data sharing.

Question 272. Which Microsoft Entra capability helps organizations periodically confirm that users still require access to applications or groups?

  1. Conditional Access
  2. Access reviews
  3. Sign-in logs
  4. Authentication strengths

Correct Answer: 2. Access reviews

Explanation:

Microsoft Entra access reviews provide a structured way to periodically reassess whether users, groups, guests, or applications should continue to have access to organizational resources. This is important because permissions can become outdated as employees change roles, projects end, or external collaboration relationships expire. Access reviews allow designated reviewers to make decisions about continued access and can support remediation of permissions that are no longer justified. The capability directly supports least privilege and Zero Trust by treating access as something that should be regularly validated. Organizations can use recurring reviews for sensitive groups, privileged resources, and external users to reduce the accumulation of unnecessary permissions.

Question 273. Which Microsoft Defender capability helps identify software vulnerabilities and prioritize remediation actions on endpoints?

  1. Defender for Cloud Apps
  2. Defender for Office 365
  3. Defender Vulnerability Management
  4. Defender for Identity

Correct Answer: 3. Defender Vulnerability Management

Explanation:

Microsoft Defender Vulnerability Management provides visibility into vulnerabilities and security weaknesses affecting supported organizational endpoints and software. Security teams can use this information to understand exposure and prioritize remediation activities. Addressing vulnerabilities proactively is important because attackers can exploit known weaknesses to gain access or execute malicious actions. Defender Vulnerability Management complements Defender for Endpoint, which provides endpoint detection and response capabilities. While endpoint detection focuses on suspicious activity that may indicate an attack, vulnerability management focuses on reducing exploitable weaknesses before they are used. This combination supports a more complete endpoint security strategy by addressing both current threats and underlying security exposure.

Question 274. Which Microsoft Entra feature provides a record of directory changes such as modifications to groups, applications, and role assignments?

  1. Sign-in logs
  2. Audit logs
  3. Risk detections
  4. Conditional Access insights

Correct Answer: 2. Audit logs

Explanation:

Microsoft Entra audit logs record administrative and directory activities, including changes involving users, groups, applications, and role assignments. They are valuable when investigating unexpected configuration changes or determining which administrative operation occurred during a specific period. Security teams can use audit information to establish an activity timeline and correlate administrative actions with authentication and security events. Sign-in logs serve a different purpose because they primarily describe authentication attempts and related access information. Regular monitoring of audit logs can help organizations identify unexpected privilege changes, unauthorized configuration activity, or other events that require investigation. They are therefore an important source of evidence for identity security and governance.

Question 275. Which Microsoft security capability helps organizations evaluate and improve their overall security posture through recommended actions?

  1. Microsoft Secure Score
  2. Microsoft Sentinel playbooks
  3. Microsoft Entra Lifecycle Workflows
  4. Microsoft Purview eDiscovery

Correct Answer: 1. Microsoft Secure Score

Explanation:

Microsoft Secure Score provides organizations with visibility into security posture and recommendations that can help improve security configurations and practices. The recommendations can cover areas such as identity, devices, data, applications, and other Microsoft security controls. Security teams can use the information to identify potential improvement opportunities and track progress as changes are implemented. Secure Score is primarily a posture-management capability rather than an incident investigation platform. It does not replace Sentinel, Defender, or Purview security tools. Instead, it provides a broader view that can help organizations prioritize configuration improvements and continuously strengthen their security environment based on available Microsoft security recommendations.

Question 276. Which Microsoft Sentinel component can execute automated workflows such as sending notifications or enriching an incident?

  1. Workbooks
  2. Playbooks
  3. Analytics rules
  4. Data connectors

Correct Answer: 2. Playbooks

Explanation:

Microsoft Sentinel playbooks use automation capabilities to perform response and orchestration tasks. They can be used for actions such as sending notifications, enriching incident information, interacting with external services, or initiating predefined response workflows. Playbooks are particularly useful when security teams repeatedly perform the same response steps for similar incidents. Automating these actions can improve consistency and reduce the amount of manual work required from analysts. Playbooks can be triggered through Sentinel automation mechanisms and can work alongside analytics rules that detect suspicious activity. This combination allows organizations to connect detection with standardized response actions while preserving the ability for analysts to handle complex investigations manually.

Question 277. Which Microsoft Entra feature helps automate user lifecycle processes such as onboarding and offboarding?

  1. Lifecycle Workflows
  2. Sign-in logs
  3. Audit logs
  4. Access reviews

Correct Answer: 1. Lifecycle Workflows

Explanation:

Microsoft Entra Lifecycle Workflows help automate identity lifecycle tasks associated with events such as employee onboarding, role changes, and offboarding. Automating these processes can reduce manual administrative effort and help ensure that identity-related actions are performed consistently. Offboarding is particularly important because users who leave an organization should not retain unnecessary access to applications, groups, or resources. Lifecycle Workflows can support standardized processes that help reduce delays and overlooked actions. They complement access reviews and privileged access management by addressing identity lifecycle events more broadly. Automating routine identity processes can therefore improve governance, reduce operational errors, and support stronger access control throughout the user’s relationship with the organization.

Question 278. Which Microsoft Defender solution is specifically designed to provide visibility and security controls for cloud application usage?

  1. Defender for Identity
  2. Defender for Endpoint
  3. Defender for Cloud Apps
  4. Defender for Office 365

Correct Answer: 3. Defender for Cloud Apps

Explanation:

Microsoft Defender for Cloud Apps helps organizations discover, monitor, and govern cloud application usage. It can provide visibility into applications being accessed by users and help security teams identify applications that may present security or compliance concerns. This capability is useful for addressing shadow IT because employees may use cloud services that have not been formally reviewed or approved. Defender for Cloud Apps can help organizations evaluate application risk and establish appropriate controls for cloud usage. It complements identity and endpoint security by providing additional visibility at the cloud application layer. Managing cloud application activity is increasingly important because organizational data can move through many external services outside traditional network boundaries.

Question 279. Which access-control approach best supports the principle of least privilege for administrative roles?

  1. Assign every administrator permanent global permissions
  2. Use eligible roles with just-in-time activation
  3. Share one privileged account among administrators
  4. Allow administrators to bypass authentication

Correct Answer: 2. Use eligible roles with just-in-time activation

Explanation:

Eligible roles with just-in-time activation support least privilege by limiting when privileged permissions become active. Microsoft Entra Privileged Identity Management allows organizations to assign users as eligible for privileged roles rather than leaving those permissions permanently active. When administrative work is required, the user can activate the role for a controlled period and may be required to satisfy additional conditions such as multifactor authentication, approval, or justification. This reduces the time during which elevated privileges are available to an account. It also improves visibility into privileged activity because role activations can be monitored and reviewed. This model is generally more controlled than permanent privileged access.

Question 280. Which combination best represents a Zero Trust approach to protecting access to sensitive resources?

  1. Trust authenticated users permanently after the first login
  2. Allow unrestricted access from the corporate network
  3. Verify identity and device conditions, apply least privilege, and continuously evaluate risk
  4. Disable monitoring after successful authentication

Correct Answer: 3. Verify identity and device conditions, apply least privilege, and continuously evaluate risk

Explanation:

A Zero Trust approach does not assume that users, devices, or network locations are automatically trustworthy. Access decisions should consider relevant identity, device, application, authentication, and risk signals. Least privilege limits the permissions available after access is granted, while continuous evaluation and monitoring help organizations respond when conditions change. Microsoft technologies such as Entra Conditional Access, Intune compliance, Privileged Identity Management, Defender solutions, and Microsoft Sentinel can contribute to this model. The goal is not simply to authenticate a user once but to establish appropriate controls around every access request. This approach can reduce unnecessary exposure and limit the impact of compromised identities or devices.