Microsoft SC-500 Practice Test Questions and Exam Dumps Part19 Q361-380

View Full Microsoft SC-500 Exam Dumps and Practice Test Dumps

 

Question 361. Which Microsoft Entra capability can require multifactor authentication when a user activates an eligible privileged role?

  1. Microsoft Entra Privileged Identity Management
  2. Microsoft Purview retention policies
  3. Microsoft Sentinel workbooks
  4. Microsoft Intune compliance policies

Correct Answer: 1. Microsoft Entra Privileged Identity Management

Explanation:

Microsoft Entra Privileged Identity Management (PIM) supports controls that can require multifactor authentication when users activate eligible privileged roles. This helps ensure that elevated permissions require stronger verification at the time they are needed. PIM can also support approval workflows, activation time limits, justification, and other controls that reduce standing administrative privileges. Retention policies manage information lifecycle requirements, Sentinel workbooks provide security visualization, and Intune compliance policies evaluate device conditions. Requiring multifactor authentication during privileged role activation adds an important layer of protection because possession of a user’s ordinary credentials alone may not be sufficient to obtain elevated access.

Question 362. Which Microsoft Defender capability can provide recommendations to reduce an organization’s attack surface by addressing vulnerabilities and security weaknesses?

  1. Defender for Office 365
  2. Defender Vulnerability Management
  3. Defender for Identity
  4. Defender for Cloud Apps

Correct Answer: 2. Defender Vulnerability Management

Explanation:

Microsoft Defender Vulnerability Management helps organizations discover and prioritize vulnerabilities and security weaknesses across supported devices and software. It can provide security recommendations that help administrators understand which weaknesses should be addressed and what remediation actions can reduce exposure. This supports attack-surface reduction by identifying vulnerable software, insecure configurations, and other conditions that may increase the likelihood of compromise. Defender for Office 365 focuses on email and collaboration threats, Defender for Identity focuses on identity threats involving Active Directory, and Defender for Cloud Apps focuses on cloud application security. Therefore, Defender Vulnerability Management is the most appropriate capability for vulnerability-focused security recommendations.

Question 363. Which Microsoft Sentinel capability allows an analyst to execute a response workflow after an incident is identified?

  1. Access reviews
  2. Sensitivity labels
  3. Playbooks
  4. Authentication strengths

Correct Answer: 3. Playbooks

Explanation:

Microsoft Sentinel playbooks are automated workflows that can be triggered from security incidents or other Sentinel events. They are commonly implemented using Azure Logic Apps and can perform actions such as sending notifications, enriching incident information, interacting with other services, or initiating response procedures. Playbooks help security teams automate repetitive response tasks and provide consistent handling of common incident scenarios. Access reviews are used for identity governance, sensitivity labels classify and protect information, and authentication strengths control acceptable authentication methods. Therefore, when an analyst needs to execute an automated response workflow following an incident, a Sentinel playbook is the appropriate capability.

Question 364. Which Microsoft Entra feature provides information about successful and failed authentication attempts?

  1. Sign-in logs
  2. Access reviews
  3. Lifecycle Workflows
  4. PIM activation history

Correct Answer: 1. Sign-in logs

Explanation:

Microsoft Entra sign-in logs provide detailed information about authentication activity, including successful and failed sign-in attempts. Security administrators can use these logs to investigate unusual authentication behavior, identify repeated failures, review Conditional Access results, examine authentication methods, and investigate potentially compromised accounts. Sign-in data is an important source for identity monitoring because it provides visibility into how users are accessing organizational resources. Access reviews evaluate whether users should retain access, Lifecycle Workflows automate identity lifecycle tasks, and PIM activation information is focused specifically on privileged role activation. Therefore, sign-in logs are the primary Microsoft Entra source for reviewing authentication attempts.

Question 365. Which Microsoft Purview feature can classify documents and emails according to their sensitivity level?

  1. Retention policies
  2. Sensitivity labels
  3. Sentinel analytics rules
  4. Entra audit logs

Correct Answer: 2. Sensitivity labels

Explanation:

Microsoft Purview sensitivity labels allow organizations to classify documents, emails, and other supported content according to information sensitivity. Labels can be configured with protection settings such as encryption, access restrictions, markings, or other controls appropriate to the organization’s requirements. Classification helps users and administrators understand how information should be handled and enables consistent protection across supported Microsoft 365 workloads. Retention policies address how long content should be retained, while Sentinel analytics rules detect security events and Entra audit logs record directory activities. Therefore, sensitivity labels are the appropriate Purview capability when the objective is to classify information based on its sensitivity.

Question 366. An administrator wants to investigate changes made to Microsoft Entra groups and role assignments. Which log should be reviewed?

  1. Sign-in logs
  2. Audit logs
  3. Defender for Endpoint alerts
  4. Sentinel workbooks

Correct Answer: 2. Audit logs

Explanation:

Microsoft Entra audit logs record administrative and directory activities, including many changes involving users, groups, applications, and role assignments. Administrators can use these logs to determine what change occurred, when it occurred, and which identity performed the action. This makes audit logs valuable for investigating unauthorized or unexpected configuration changes. Sign-in logs are focused on authentication events rather than directory modifications. Defender for Endpoint alerts provide endpoint security detections, while Sentinel workbooks visualize security information collected from various sources. Therefore, when investigating changes to groups or role assignments in Microsoft Entra, administrators should review the audit logs.

Question 367. Which Microsoft security capability can help enforce access decisions based on whether a device is compliant?

  1. Microsoft Entra Conditional Access
  2. Microsoft Purview retention
  3. Microsoft Sentinel workbooks
  4. Defender for Identity

Correct Answer: 1. Microsoft Entra Conditional Access

Explanation:

Microsoft Entra Conditional Access can use device compliance information as a condition when determining whether access should be allowed. When integrated with Microsoft Intune, an organization can require a device to meet defined compliance policies before permitting access to protected applications or resources. This supports Zero Trust by considering device security state rather than automatically trusting a device based only on its network location or previous access. Purview retention manages information lifecycle, Sentinel workbooks provide visualization, and Defender for Identity focuses on identity threats involving Active Directory. Conditional Access therefore provides the access-decision mechanism that can enforce requirements based on device compliance.

Question 368. Which Microsoft security principle states that access should be granted according to the minimum permissions required to complete a task?

  1. Assume breach
  2. Verify explicitly
  3. Least privilege
  4. Continuous deployment

Correct Answer: 3. Least privilege

Explanation:

Least privilege is a core security principle requiring users, applications, and services to receive only the permissions necessary to perform their authorized tasks. Restricting permissions reduces the potential damage caused by compromised accounts, malicious insiders, accidental changes, or application vulnerabilities. Microsoft security technologies such as Entra PIM and role-based access control can help organizations implement least privilege by limiting standing administrative access and providing temporary elevation when necessary. Assume breach and verify explicitly are also important Zero Trust principles, but they address different security concepts. Therefore, least privilege directly describes the requirement to provide only the minimum permissions needed for a task.

Question 369. Which Microsoft Defender solution is designed to detect malicious links and attachments in email messages?

  1. Defender for Identity
  2. Defender for Office 365
  3. Defender Vulnerability Management
  4. Defender for Cloud Apps

Correct Answer: 2. Defender for Office 365

Explanation:

Microsoft Defender for Office 365 provides security capabilities for protecting email and collaboration workloads from threats such as phishing, malicious links, malicious attachments, and other message-based attacks. It helps organizations detect suspicious content and investigate potential threats affecting Microsoft 365 communication environments. Defender for Identity focuses on identity threats involving on-premises Active Directory, Defender Vulnerability Management identifies vulnerabilities and security weaknesses, and Defender for Cloud Apps provides visibility and control for cloud applications. Therefore, Defender for Office 365 is the most appropriate solution when the security requirement specifically involves detecting and protecting against malicious links and attachments in email.

Question 370. Which Microsoft Entra feature can automate actions when employees join, change roles, or leave an organization?

  1. Lifecycle Workflows
  2. Authentication strengths
  3. Sign-in logs
  4. Access reviews

Correct Answer: 1. Lifecycle Workflows

Explanation:

Microsoft Entra Lifecycle Workflows are designed to automate identity lifecycle processes associated with employee onboarding, changes, and offboarding. Automating these activities can help organizations apply consistent procedures when users join the organization, move into new roles, or leave. Workflows can support tasks related to account and access management, reducing repetitive manual administration and improving consistency. Authentication strengths control acceptable authentication methods, sign-in logs provide authentication activity information, and access reviews periodically evaluate whether existing access remains appropriate. Therefore, Lifecycle Workflows are the appropriate Microsoft Entra capability when the objective is to automate recurring identity lifecycle actions.

Question 371. Which Microsoft Sentinel feature can identify suspicious behavior by running queries against collected security data?

  1. Analytics rules
  2. Access reviews
  3. Sensitivity labels
  4. Device compliance policies

Correct Answer: 1. Analytics rules

Explanation:

Microsoft Sentinel analytics rules are used to detect suspicious activity in security data collected from connected data sources. Rules can contain detection logic that evaluates events and telemetry and generates alerts or incidents when specified conditions are met. They can be created using built-in templates or customized to meet organizational detection requirements. Analysts can use analytics rules to identify authentication anomalies, suspicious processes, network activity, and other potential threats. Access reviews manage identity entitlement, sensitivity labels classify and protect information, and device compliance policies evaluate endpoint security conditions. Therefore, analytics rules are the appropriate Sentinel capability for automatically identifying suspicious behavior through queries and detection logic.

Question 372. Which Microsoft Defender service provides visibility into cloud application usage and can help identify shadow IT?

  1. Defender for Identity
  2. Defender for Endpoint
  3. Defender for Cloud Apps
  4. Defender for Office 365

Correct Answer: 3. Defender for Cloud Apps

Explanation:

Microsoft Defender for Cloud Apps provides visibility and security controls for cloud applications used by an organization. It can help security teams discover applications that employees are using, evaluate application risk, and identify unsanctioned services that may represent shadow IT. This visibility allows organizations to develop appropriate governance and security controls around cloud application usage. Defender for Identity focuses on identity threats involving Active Directory, Defender for Endpoint protects endpoint devices, and Defender for Office 365 protects email and collaboration workloads. Therefore, Defender for Cloud Apps is the most appropriate Microsoft security solution for discovering and managing cloud application usage and shadow IT.

Question 373. Which Microsoft Entra capability can temporarily elevate a user’s privileges while maintaining approval and activation controls?

  1. Microsoft Entra Privileged Identity Management
  2. Microsoft Purview DLP
  3. Microsoft Sentinel workbooks
  4. Microsoft Intune

Correct Answer: 1. Microsoft Entra Privileged Identity Management

Explanation:

Microsoft Entra Privileged Identity Management provides controls for managing privileged roles using just-in-time and eligible access concepts. Instead of permanently assigning elevated permissions, organizations can make users eligible for roles and require activation when administrative privileges are needed. PIM can support approval requirements, multifactor authentication, justification, activation duration, and other safeguards. These controls help reduce standing privilege and limit the period during which highly sensitive permissions are active. Purview DLP protects sensitive information, Sentinel workbooks visualize security information, and Intune manages devices. Therefore, PIM is the appropriate solution for temporarily elevating a user’s privileges while maintaining administrative controls.

Question 374. Which Microsoft Purview capability can detect sensitive information and help prevent users from sharing it through prohibited locations?

  1. Retention policies
  2. Data Loss Prevention
  3. Access reviews
  4. Sentinel playbooks

Correct Answer: 2. Data Loss Prevention

Explanation:

Microsoft Purview Data Loss Prevention policies can identify sensitive information and apply organizational rules when users attempt to perform activities that could expose or improperly share that information. DLP can use sensitive information types and other conditions to determine whether content or an action presents a policy concern. Depending on configuration, organizations can notify users, generate alerts, or restrict specific actions. Retention policies manage how long information is retained, access reviews evaluate identity permissions, and Sentinel playbooks automate security response workflows. Therefore, Purview Data Loss Prevention is the capability most directly suited to detecting sensitive information and preventing prohibited sharing activities.

Question 375. Which Microsoft Defender solution provides endpoint telemetry that can help investigators understand the sequence of activities during an attack?

  1. Defender for Cloud Apps
  2. Defender for Identity
  3. Defender for Endpoint
  4. Defender for Office 365

Correct Answer: 3. Defender for Endpoint

Explanation:

Microsoft Defender for Endpoint collects endpoint security telemetry that can help investigators understand processes, files, network activity, alerts, and other events associated with suspicious behavior. This information can help analysts reconstruct portions of an attack, identify affected devices, determine how malicious activity occurred, and support response actions. Endpoint telemetry is particularly useful during incident investigations because individual alerts can be placed into a broader sequence of events. Defender for Cloud Apps focuses on cloud applications, Defender for Identity focuses on identity threats, and Defender for Office 365 focuses on email and collaboration. Defender for Endpoint is therefore the appropriate solution for endpoint investigation and attack activity analysis.

Question 376. Which Microsoft security capability can combine identity, endpoint, email, and application signals to provide a broader incident investigation view?

  1. Microsoft Defender XDR
  2. Microsoft Intune
  3. Microsoft Purview retention
  4. Microsoft Entra Lifecycle Workflows

Correct Answer: 1. Microsoft Defender XDR

Explanation:

Microsoft Defender XDR integrates security signals from multiple Microsoft Defender workloads to provide a broader view of incidents and attack activity. Correlation across identities, endpoints, email, and other supported security sources can help analysts understand how separate alerts may be connected to the same attack. This reduces the need to investigate every security signal independently and can provide more context during incident response. Intune primarily manages devices, Purview retention manages information lifecycle, and Lifecycle Workflows automate identity processes. Defender XDR is therefore the appropriate Microsoft security capability when investigators need a unified view that combines signals from multiple security domains.

Question 377. Which Microsoft Entra capability can use user and sign-in risk signals to help determine whether access should be allowed?

  1. Entra ID Protection with Conditional Access
  2. Lifecycle Workflows
  3. Access reviews
  4. Audit logs

Correct Answer: 1. Entra ID Protection with Conditional Access

Explanation:

Microsoft Entra ID Protection can identify identity and sign-in risk signals, while Conditional Access can use those risk signals when making access decisions. For example, an organization can configure policies that require additional authentication or block access when a sign-in is considered sufficiently risky. This creates a risk-based access model in which authentication decisions can respond dynamically to suspicious activity. Lifecycle Workflows automate identity lifecycle tasks, access reviews periodically evaluate existing permissions, and audit logs record directory changes. Combining Entra ID Protection with Conditional Access therefore provides a practical method for using identity risk information to strengthen access decisions.

Question 378. Which Microsoft security capability provides a centralized set of recommendations for improving identity, device, data, and security configurations?

  1. Microsoft Secure Score
  2. Microsoft Sentinel playbooks
  3. Microsoft Entra sign-in logs
  4. Microsoft Purview sensitivity labels

Correct Answer: 1. Microsoft Secure Score

Explanation:

Microsoft Secure Score provides organizations with security posture information and recommendations designed to help improve protection across supported Microsoft services. Administrators can use its recommendations to identify areas where security configurations or practices may be strengthened. These recommendations can involve identity protection, device security, data protection, and other security controls. Sentinel playbooks are designed for automated response workflows, Entra sign-in logs provide authentication activity, and Purview sensitivity labels classify and protect information. Secure Score therefore best matches a requirement for a centralized view of security improvement recommendations across multiple areas of the Microsoft security environment.

Question 379. Which Zero Trust principle emphasizes making access decisions using current identity, device, application, and risk information?

  1. Assume breach
  2. Verify explicitly
  3. Least privilege
  4. Permanent trust

Correct Answer: 2. Verify explicitly

Explanation:

The Zero Trust principle of verifying explicitly means that access decisions should be based on relevant signals rather than automatically trusting a request because of its location or previous authorization. Organizations can consider identity, device state, application context, location, authentication strength, and risk when evaluating access. Microsoft Entra Conditional Access is an important technology for implementing this principle because policies can combine multiple conditions before granting access. Least privilege limits permissions, while assume breach encourages organizations to operate with the expectation that compromise can occur. Permanent trust contradicts the Zero Trust model. Therefore, verify explicitly is the principle that most directly describes evaluating current access signals.

Question 380. Which combination provides layered protection for a highly privileged Microsoft Entra administrator account?

  1. Permanent Global Administrator access and password-only authentication
  2. Shared administrator credentials and unrestricted permissions
  3. Just-in-time PIM activation, strong authentication, least privilege, and monitoring
  4. Trusting access based only on corporate network location

Correct Answer: 3. Just-in-time PIM activation, strong authentication, least privilege, and monitoring

Explanation:

Highly privileged administrator accounts should be protected using multiple complementary security controls. Just-in-time access through Microsoft Entra PIM reduces standing privilege and limits the period during which elevated permissions are active. Strong authentication, including phishing-resistant methods where appropriate, reduces the risk of stolen credentials being sufficient for administrative access. Least privilege limits what the account can do, while monitoring provides visibility into administrative activity and potential compromise. Relying on permanent administrator permissions, shared credentials, passwords alone, or network location creates unnecessary exposure. A layered approach combining temporary privileged access, strong authentication, least privilege, and continuous monitoring therefore provides stronger protection for highly privileged accounts.