Microsoft SC-500 Practice Test Questions and Exam Dumps Part12 Q221-240

View Full Microsoft SC-500 Exam Dumps and Practice Test Dumps

 

Question 221. Which Microsoft Entra feature helps administrators review whether users still need access to specific groups or applications?

  1. Microsoft Entra Connect
  2. Microsoft Entra access reviews
  3. Microsoft Entra Domain Services
  4. Microsoft Entra Cloud Sync

Correct Answer: 2. Microsoft Entra access reviews

Explanation:

Microsoft Entra access reviews help organizations regularly verify whether users, groups, guests, or applications should continue to have access to resources. Instead of allowing permissions to remain indefinitely, administrators can configure recurring reviews where designated reviewers confirm whether access is still appropriate. This is especially useful for guest accounts, privileged groups, and applications containing sensitive information. Access reviews support Zero Trust and least-privilege principles because permissions are periodically reassessed rather than assumed to remain valid forever. After a review, administrators can apply the resulting decisions to remove unnecessary access and reduce the risk associated with excessive or outdated permissions.

Question 222. Which Microsoft security solution is designed to detect and investigate identity-based attacks against on-premises Active Directory?

  1. Microsoft Defender for Identity
  2. Microsoft Defender for Cloud Apps
  3. Microsoft Purview
  4. Microsoft Intune

Correct Answer: 1. Microsoft Defender for Identity

Explanation:

Microsoft Defender for Identity monitors signals from on-premises Active Directory to identify suspicious identity-related activity. It can detect behaviors associated with techniques such as credential theft, lateral movement, reconnaissance, and attacks against domain controllers. The service helps security teams understand relationships between users, devices, and identities so that suspicious activity can be investigated in context. Defender for Identity is particularly valuable in hybrid environments where organizations maintain on-premises Active Directory alongside Microsoft Entra ID. By combining identity telemetry with other Microsoft Defender signals, security teams can investigate attacks that move between identities, endpoints, and other resources more effectively.

Question 223. An organization wants access to corporate applications to depend on whether a user’s device satisfies defined security requirements. Which Microsoft capability should be used?

  1. Microsoft Purview retention labels
  2. Microsoft Sentinel workbooks
  3. Microsoft Entra Conditional Access with device compliance
  4. Microsoft Defender for Identity sensors

Correct Answer: 3. Microsoft Entra Conditional Access with device compliance

Explanation:

Microsoft Entra Conditional Access can use device compliance information from Microsoft Intune when determining whether access should be granted. An organization can define compliance requirements such as encryption, password configuration, operating system versions, or security settings. Conditional Access can then require a compliant device before allowing access to selected applications or services. This creates an important Zero Trust control because authentication alone does not automatically establish trust. The user’s identity and the security state of the device can both be evaluated before access is granted. Combining Intune compliance policies with Conditional Access therefore helps reduce the likelihood that compromised or poorly configured devices can reach sensitive resources.

Question 224. Which Microsoft Sentinel capability allows security analysts to search collected data interactively for suspicious activity that may not have triggered an alert?

  1. Workbooks
  2. Automation rules
  3. Data connectors
  4. Hunting queries

Correct Answer: 4. Hunting queries

Explanation:

Microsoft Sentinel hunting queries allow analysts to proactively search security data for suspicious patterns, behaviors, and indicators that might not have generated an existing alert. Analysts commonly use Kusto Query Language, or KQL, to examine log data and investigate hypotheses about potential threats. Threat hunting is different from simply waiting for analytics rules to generate incidents because analysts actively search for evidence of malicious behavior. Hunting queries can also help identify previously unknown activity, validate security assumptions, and support incident investigations. Once a useful hunting pattern is identified, it may also become the foundation for an analytics rule or other automated detection mechanism.

Question 225. Which Microsoft Purview capability can automatically identify sensitive information such as credit card numbers and help apply protection policies?

  1. Sensitivity labels
  2. Sensitive information types
  3. Retention policies
  4. Audit search

Correct Answer: 2. Sensitive information types

Explanation:

Microsoft Purview sensitive information types are patterns used to identify specific categories of sensitive information within organizational data. Examples can include credit card numbers, national identification numbers, financial information, and other regulated data patterns. These identifiers can be used by Microsoft Purview solutions such as Data Loss Prevention to detect sensitive content and apply appropriate controls. Sensitive information types are different from sensitivity labels because they focus on recognizing the nature of the data, while labels classify and protect content according to organizational requirements. Using sensitive information types helps security teams build policies that detect and control sensitive information consistently across supported Microsoft services.

Question 226. Which Microsoft Entra capability provides just-in-time activation of privileged roles instead of keeping administrators permanently active?

  1. Microsoft Entra Privileged Identity Management
  2. Microsoft Entra Connect
  3. Microsoft Entra Domain Services
  4. Microsoft Entra Verified ID

Correct Answer: 1. Microsoft Entra Privileged Identity Management

Explanation:

Microsoft Entra Privileged Identity Management, or PIM, helps organizations reduce the risks associated with permanent administrative privileges. Instead of leaving a privileged role continuously active, an eligible administrator can activate the role for a limited period when administrative work is required. Organizations can configure controls such as approval, multifactor authentication, justification, notifications, and activation duration. This just-in-time approach supports least privilege by limiting the amount of time elevated permissions are available. PIM also provides visibility into privileged-role assignments and activations, helping security teams monitor administrative access. It is especially useful for protecting highly sensitive Entra roles and reducing opportunities for attackers to exploit standing privileges.

Question 227. Which Microsoft Defender solution provides endpoint detection and response capabilities for investigating suspicious activity on devices?

  1. Microsoft Defender for Office 365
  2. Microsoft Defender for Cloud Apps
  3. Microsoft Defender for Endpoint
  4. Microsoft Defender for Identity

Correct Answer: 3. Microsoft Defender for Endpoint

Explanation:

Microsoft Defender for Endpoint provides endpoint security capabilities including endpoint detection and response, threat investigation, vulnerability information, and attack surface reduction. Security teams can use endpoint telemetry to investigate suspicious processes, files, network connections, and other activities occurring on devices. When an endpoint shows signs of compromise, analysts can investigate the associated alerts and understand the sequence of events involved. Defender for Endpoint also works with other Microsoft security products, allowing endpoint signals to contribute to broader incident investigations. This integrated approach is useful because many attacks involve multiple components, and endpoint evidence can provide important context about how an identity, application, or device was compromised.

Question 228. An organization wants to identify risky sign-ins and automatically require stronger controls when risk is detected. Which combination is most appropriate?

  1. Microsoft Purview and retention labels
  2. Microsoft Entra ID Protection and Conditional Access
  3. Microsoft Sentinel workbooks and data connectors
  4. Microsoft Intune and Defender Vulnerability Management only

Correct Answer: 2. Microsoft Entra ID Protection and Conditional Access

Explanation:

Microsoft Entra ID Protection evaluates identity-related signals to identify potentially risky users and sign-ins. These risk detections can be integrated with Conditional Access policies so that organizations can respond automatically when a sign-in presents elevated risk. Depending on the policy configuration, users may be required to complete multifactor authentication, have access blocked, or satisfy another defined control. This approach supports adaptive security because access decisions can consider current risk rather than relying only on static identity information. Combining ID Protection with Conditional Access is particularly useful for detecting suspicious authentication activity and applying stronger controls when the available signals indicate that an account or sign-in may be compromised.

Question 229. Which Microsoft Defender solution helps organizations discover and assess unsanctioned cloud applications?

  1. Microsoft Defender for Cloud Apps
  2. Microsoft Defender for Identity
  3. Microsoft Defender for Endpoint
  4. Microsoft Defender for Office 365

Correct Answer: 1. Microsoft Defender for Cloud Apps

Explanation:

Microsoft Defender for Cloud Apps provides visibility and security controls for cloud applications used within an organization. One important capability is discovering applications that employees may be using without formal approval, often referred to as shadow IT. Security teams can analyze cloud application usage and assess applications according to organizational risk requirements. This visibility can help organizations identify potentially risky services, understand how cloud resources are being used, and establish appropriate policies. Defender for Cloud Apps can also provide controls for governing cloud applications and protecting data. This is valuable in modern environments where users may access numerous external services outside traditional corporate infrastructure.

Question 230. Which Microsoft Sentinel component is primarily used to visualize security data through interactive dashboards and reports?

  1. Analytics rules
  2. Playbooks
  3. Workbooks
  4. Automation rules

Correct Answer: 3. Workbooks

Explanation:

Microsoft Sentinel workbooks provide interactive visualizations and dashboards that help security teams understand collected security data. They can display information such as incident trends, alert activity, authentication events, threat indicators, and other operational metrics. Workbooks can combine multiple data sources and present information through charts, tables, graphs, and other visual components. This makes them useful for security monitoring, reporting, investigation, and operational awareness. Workbooks are different from analytics rules, which are primarily responsible for detecting suspicious activity, and playbooks, which support automated response actions. By presenting security information visually, workbooks help analysts identify patterns and trends that may be difficult to recognize in raw log data.

Question 231. Which security principle requires access permissions to be limited to only what a user or service needs to perform its assigned responsibilities?

  1. Defense in depth
  2. Least privilege
  3. High availability
  4. Data residency

Correct Answer: 2. Least privilege

Explanation:

The principle of least privilege requires users, applications, and services to receive only the permissions necessary to perform their legitimate tasks. Excessive permissions increase the potential impact of compromised accounts and can make unauthorized activity more difficult to contain. In Microsoft security environments, least privilege can be supported through technologies such as Microsoft Entra roles, Privileged Identity Management, access reviews, Conditional Access, and role-based access control. Permissions should also be reviewed periodically because job responsibilities change over time. Applying least privilege reduces unnecessary exposure and supports Zero Trust by preventing organizations from automatically trusting users or systems with broad access simply because they previously received it.

Question 232. Which Microsoft Purview capability is primarily used to control how long organizational data should be retained or when it should be deleted?

  1. Retention policies
  2. Sensitivity labels
  3. eDiscovery holds only
  4. Data connectors

Correct Answer: 1. Retention policies

Explanation:

Microsoft Purview retention policies help organizations manage how long certain content should be retained and, depending on configuration, when it should be deleted. Retention requirements can be important for regulatory obligations, business records, and organizational governance. A retention policy can apply to selected Microsoft 365 locations or types of content according to defined rules. Retention is different from sensitivity labeling, which focuses on classifying and protecting content based on its sensitivity. Retention policies help organizations establish consistent information lifecycle practices rather than relying on individual users to decide when information should remain available. Proper retention management can also reduce unnecessary data accumulation and support compliance requirements.

Question 233. Which Microsoft Entra feature records information about administrative activities such as changes to users, groups, and directory settings?

  1. Sign-in logs
  2. Audit logs
  3. Risk detections
  4. Authentication methods reports

Correct Answer: 2. Audit logs

Explanation:

Microsoft Entra audit logs provide information about changes and activities performed within the directory. They can help administrators investigate events such as user creation, group membership changes, application configuration updates, role assignments, and other directory operations. Audit logs are particularly valuable during security investigations because they provide evidence about what administrative actions occurred and when they occurred. Sign-in logs serve a different purpose by recording authentication activity and sign-in events. Security teams can use audit information alongside sign-in, risk, and other Microsoft security signals to build a broader understanding of suspicious activity. Reviewing administrative audit data can also help identify unauthorized or unexpected configuration changes.

Question 234. Which Microsoft security capability can automatically trigger response actions after a Microsoft Sentinel incident or alert meets defined conditions?

  1. Microsoft Purview retention
  2. Microsoft Entra access reviews
  3. Microsoft Sentinel playbooks
  4. Microsoft Secure Score

Correct Answer: 3. Microsoft Sentinel playbooks

Explanation:

Microsoft Sentinel playbooks provide automated response and orchestration capabilities based on Azure Logic Apps. They can perform actions such as sending notifications, enriching incident information, interacting with other security services, or initiating response workflows. Playbooks can be associated with automation rules or other Sentinel workflows so that repetitive response tasks can occur consistently without requiring an analyst to perform every action manually. Automation is especially useful for common security events where the response process is well understood. By reducing manual work, playbooks can help analysts focus on investigations that require human judgment while ensuring that standardized response actions are performed quickly and consistently.

Question 235. Which Microsoft Defender solution focuses specifically on protecting users from malicious email messages, links, and attachments?

  1. Microsoft Defender for Endpoint
  2. Microsoft Defender for Identity
  3. Microsoft Defender for Cloud Apps
  4. Microsoft Defender for Office 365

Correct Answer: 4. Microsoft Defender for Office 365

Explanation:

Microsoft Defender for Office 365 provides security capabilities designed to protect organizational email and collaboration workloads from threats such as phishing, malicious links, and harmful attachments. It can analyze messages and associated content to help identify potentially dangerous activity before it affects users. Security teams can also investigate detected threats and use Microsoft Defender capabilities to understand related incidents. Defender for Office 365 complements endpoint and identity security because email is often used as an initial access mechanism in attacks. Protecting the messaging environment therefore helps reduce the likelihood that users will interact with malicious content that could lead to credential theft, malware execution, or further compromise.

Question 236. Which Microsoft Intune capability evaluates whether a device meets organizational security requirements?

  1. Compliance policies
  2. Audit logs
  3. Analytics rules
  4. Access reviews

Correct Answer: 1. Compliance policies

Explanation:

Microsoft Intune compliance policies define requirements that devices must satisfy to be considered compliant. These requirements can include operating system versions, password settings, encryption, device security configurations, and other organizational controls. Compliance information can then be integrated with Microsoft Entra Conditional Access so that access to corporate resources can depend on the security state of the device. This provides an additional layer of protection because a valid username and password alone may not be enough to gain access. Device compliance is especially important in environments where users access organizational resources from laptops, mobile devices, or other endpoints that may operate outside traditional corporate network boundaries.

Question 237. Which Microsoft security capability provides recommendations for improving an organization’s security posture based on observed configurations and controls?

  1. Microsoft Sentinel hunting
  2. Microsoft Secure Score
  3. Microsoft Entra access reviews
  4. Microsoft Purview eDiscovery

Correct Answer: 2. Microsoft Secure Score

Explanation:

Microsoft Secure Score provides organizations with visibility into security posture and recommendations for improving security across Microsoft services. It evaluates relevant security controls and presents actions that can help strengthen the environment. Organizations can use the recommendations to identify areas where security configurations or practices may be improved and track progress over time. Secure Score is not intended to replace detailed security investigations or incident response tools. Instead, it provides a broader posture-management perspective that can help security teams prioritize configuration improvements. Reviewing Secure Score recommendations regularly can support continuous security improvement and help organizations identify gaps in areas such as identity, devices, applications, and data protection.

Question 238. Which Microsoft Entra capability can help automatically manage identity lifecycle tasks such as onboarding and offboarding users?

  1. Microsoft Entra Lifecycle Workflows
  2. Microsoft Entra sign-in logs
  3. Microsoft Entra audit logs
  4. Microsoft Entra Verified ID

Correct Answer: 1. Microsoft Entra Lifecycle Workflows

Explanation:

Microsoft Entra Lifecycle Workflows help automate identity lifecycle processes associated with events such as employee onboarding, role changes, and offboarding. Automating these processes can help ensure that accounts and access are handled consistently as users enter, change roles within, or leave an organization. For example, workflows can support tasks associated with removing access when a user’s employment ends. Manual identity lifecycle management can introduce delays and increase the possibility of overlooked permissions. Lifecycle Workflows therefore support security and governance by making identity-related processes more standardized and repeatable. They also complement access reviews and privileged access controls by addressing the broader lifecycle of user identities.

Question 239. Which Microsoft Defender capability helps identify security weaknesses and prioritize remediation across organizational endpoints?

  1. Defender for Office 365
  2. Defender for Identity
  3. Defender Vulnerability Management
  4. Defender for Cloud Apps

Correct Answer: 3. Defender Vulnerability Management

Explanation:

Microsoft Defender Vulnerability Management helps organizations identify, assess, prioritize, and remediate security weaknesses affecting endpoints and software environments. It provides visibility into vulnerabilities and can help security teams determine which issues require attention based on factors such as exposure and risk. Vulnerability management is different from endpoint detection and response because its primary focus is reducing weaknesses that attackers could exploit rather than investigating active suspicious behavior. Integrating vulnerability information with broader Microsoft security capabilities can help organizations understand where exposure exists and prioritize remediation efforts. Regular vulnerability assessment supports proactive security because organizations can address weaknesses before they become part of an active attack.

Question 240. Which Zero Trust principle requires organizations to evaluate access requests using available identity, device, application, and risk signals rather than automatically trusting a user because they are inside the corporate network?

  1. Verify explicitly
  2. Assume breach
  3. Minimize data retention
  4. Maximize network trust

Correct Answer: 1. Verify explicitly

Explanation:

The Zero Trust principle of “verify explicitly” means access decisions should be based on relevant available signals rather than automatically trusting a request. Microsoft security controls can evaluate factors such as user identity, device compliance, authentication strength, application, location, and detected risk. This approach recognizes that a user or device may become compromised even when operating from an apparently trusted environment. Conditional Access is one important mechanism for implementing these decisions because policies can require stronger authentication or impose other controls when conditions warrant them. Explicit verification helps organizations move away from implicit trust and toward dynamic access decisions that better reflect the current security context.