View Full Microsoft SC-500 Exam Dumps and Practice Test Dumps
Question 321. Which Microsoft Entra feature can be used to periodically verify whether users still need access to a group or application?
- Access reviews
- Sign-in logs
- Authentication strengths
- Security defaults
Correct Answer: 1. Access reviews
Explanation:
Microsoft Entra access reviews help organizations regularly verify whether users, groups, or applications still require access to protected resources. Reviewers can evaluate membership and remove access that is no longer necessary. This supports the Zero Trust principle of continuously verifying access rather than assuming that previously granted permissions should remain valid indefinitely. Access reviews are especially useful for guest users, privileged groups, and sensitive applications where unnecessary access can increase security risk. Sign-in logs provide activity information, while authentication strengths control authentication methods. Security defaults provide baseline protections but do not perform periodic entitlement reviews. Therefore, access reviews are the appropriate feature for recurring access validation.
Question 322. Which Microsoft security solution is designed to detect suspicious activities involving on-premises Active Directory identities?
- Microsoft Purview
- Microsoft Defender for Identity
- Microsoft Intune
- Microsoft Secure Score
Correct Answer: 2. Microsoft Defender for Identity
Explanation:
Microsoft Defender for Identity is designed to monitor and analyze signals from on-premises Active Directory environments to identify suspicious identity-related activities. It can detect behaviors associated with compromised accounts, reconnaissance, credential theft, lateral movement, and other threats involving domain identities. The service uses information collected from domain controllers and integrates identity signals with broader Microsoft security capabilities. Microsoft Purview focuses on data governance, compliance, and information protection, while Intune manages devices and application policies. Secure Score provides recommendations for improving an organization’s security posture. Defender for Identity therefore provides the most appropriate capability when the primary requirement is detecting threats against on-premises Active Directory identities.
Question 323. An organization wants Conditional Access to allow access only when a device satisfies required security conditions. Which Microsoft Entra capability should be used?
- Access reviews
- Lifecycle Workflows
- Device-based Conditional Access with Intune compliance
- Sentinel workbooks
Correct Answer: 3. Device-based Conditional Access with Intune compliance
Explanation:
Microsoft Entra Conditional Access can use device compliance information from Microsoft Intune to control access to organizational resources. An administrator can create a policy requiring a device to be marked compliant before access is permitted. Intune evaluates device conditions such as encryption, operating system requirements, security configuration, and other organizational compliance rules. Conditional Access then uses that compliance signal as part of its access decision. This approach supports Zero Trust by considering device state rather than trusting a user or device simply because it is known. Access reviews and Lifecycle Workflows address identity governance, while Sentinel workbooks are used for security monitoring and visualization.
Question 324. Which authentication approach provides stronger protection against phishing than traditional password-based authentication?
- Password-only authentication
- Security questions
- Email-based verification
- Phishing-resistant authentication using FIDO2 security keys
Correct Answer: 4. Phishing-resistant authentication using FIDO2 security keys
Explanation:
Phishing-resistant authentication is designed to prevent attackers from successfully replaying stolen credentials through fraudulent websites or social engineering techniques. FIDO2 security keys use public-key cryptography and are bound to the legitimate authentication context, making them substantially more resistant to credential phishing than passwords or many traditional verification methods. Microsoft Entra supports strong authentication methods that can be used with Conditional Access authentication strengths. Password-only authentication is particularly vulnerable to credential theft, while security questions and email verification can often be targeted through social engineering or account compromise. For sensitive administrative access, phishing-resistant authentication provides an important layer of identity protection.
Question 325. Which Microsoft Purview capability helps organizations apply classification and protection settings to sensitive documents and emails?
- Sensitivity labels
- Sentinel analytics rules
- Defender vulnerability assessments
- Entra access reviews
Correct Answer: 1. Sensitivity labels
Explanation:
Microsoft Purview sensitivity labels allow organizations to classify and protect documents, emails, and other supported content based on information sensitivity. Labels can be configured to apply protection controls such as encryption, access restrictions, visual markings, or other organizational requirements. They help users and administrators consistently identify and protect sensitive information throughout its lifecycle. Sentinel analytics rules are designed for detecting security events, while Defender vulnerability capabilities focus on identifying weaknesses in devices and applications. Entra access reviews are used to evaluate user access. Sensitivity labels therefore provide the appropriate mechanism when the objective is to classify information and apply corresponding protection policies.
Question 326. An administrator needs users to receive privileged Entra roles only temporarily when they actively require them. Which solution should be implemented?
- Permanent role assignments
- Microsoft Entra Privileged Identity Management
- Security defaults
- Purview retention policies
Correct Answer: 2. Microsoft Entra Privileged Identity Management
Explanation:
Microsoft Entra Privileged Identity Management, or PIM, supports just-in-time privileged access by allowing administrators to make eligible role assignments that users activate only when needed. Organizations can configure additional controls such as approval, multifactor authentication, activation duration, and justification. This reduces the amount of time that highly privileged permissions remain active and limits the potential impact of compromised administrative accounts. Permanent role assignments provide broader standing privileges and therefore increase exposure. Security defaults provide baseline identity protections, while Purview retention policies manage information retention rather than privileged access. PIM is therefore the appropriate solution for temporary administrative access based on operational need.
Question 327. Which Microsoft Defender capability provides endpoint detection and response capabilities for investigating suspicious activity on devices?
- Defender for Cloud Apps
- Defender for Identity
- Microsoft Defender for Endpoint
- Microsoft Purview
Correct Answer: 3. Microsoft Defender for Endpoint
Explanation:
Microsoft Defender for Endpoint provides endpoint detection and response capabilities that help security teams identify, investigate, and respond to suspicious activity on supported devices. It collects endpoint telemetry and security signals that can be used to investigate processes, files, alerts, vulnerabilities, and other indicators associated with potential attacks. Security teams can use this information to understand how an incident affected an endpoint and take appropriate response actions. Defender for Cloud Apps focuses on cloud application visibility and control, while Defender for Identity concentrates on identity threats involving Active Directory. Microsoft Purview focuses on data security and compliance. Therefore, Defender for Endpoint is the appropriate service for endpoint-focused detection and response.
Question 328. Which Microsoft Sentinel capability allows analysts to investigate security events by querying collected data for suspicious patterns?
- Sensitivity labels
- Lifecycle Workflows
- Access reviews
- KQL-based threat hunting
Correct Answer: 4. KQL-based threat hunting
Explanation:
Microsoft Sentinel provides threat hunting capabilities that allow analysts to proactively search collected security data for suspicious behaviors and potential threats. Kusto Query Language, or KQL, is commonly used to query logs and telemetry stored in Sentinel. Analysts can construct queries that identify unusual authentication patterns, suspicious network activity, repeated failures, abnormal account behavior, or other indicators that may not yet have generated an alert. This proactive approach complements automated analytics rules and incident detection. Sensitivity labels and access reviews address different security requirements, while Lifecycle Workflows manage identity lifecycle processes. KQL-based threat hunting is therefore the appropriate capability for investigating security data through targeted queries.
Question 329. An organization wants to identify and control unsanctioned cloud applications used by employees. Which Microsoft security solution is most appropriate?
- Microsoft Defender for Cloud Apps
- Microsoft Defender for Identity
- Microsoft Intune
- Microsoft Purview retention
Correct Answer: 1. Microsoft Defender for Cloud Apps
Explanation:
Microsoft Defender for Cloud Apps provides visibility and security controls for cloud applications used within an organization. It can help security teams discover cloud application usage, identify potentially risky or unsanctioned services, and apply governance controls based on organizational requirements. This capability is useful for addressing shadow IT, where employees may use cloud services without formal approval or security assessment. Defender for Identity focuses primarily on identity threats involving Active Directory, while Intune manages devices and application policies. Purview retention capabilities address how information is retained or disposed of. Defender for Cloud Apps therefore best matches the requirement to discover and control unsanctioned cloud application usage.
Question 330. Which Microsoft Sentinel feature can automatically initiate a response workflow when a security condition is detected?
- Sensitivity labels
- Automation rules and playbooks
- Access reviews
- Authentication strengths
Correct Answer: 2. Automation rules and playbooks
Explanation:
Microsoft Sentinel automation rules and playbooks can be used to automate security response activities after relevant events or incidents are identified. Automation rules can perform actions such as assigning incidents, changing incident status, or triggering appropriate workflows. Playbooks, commonly implemented with Azure Logic Apps, can perform more extensive automated response actions, such as notifying administrators, enriching alerts, or interacting with other security services. This reduces the amount of repetitive manual work required from security analysts and can improve response consistency. Sensitivity labels, access reviews, and authentication strengths address information protection, identity governance, and authentication controls respectively. Automation rules and playbooks therefore provide the required incident-response automation.
Question 331. Which security principle requires users to receive only the permissions necessary to perform their assigned responsibilities?
- Assume breach
- Verify explicitly
- Least privilege
- Password rotation
Correct Answer: 3. Least privilege
Explanation:
The principle of least privilege requires users, applications, and services to receive only the permissions necessary to perform their authorized tasks. Limiting permissions reduces the potential impact of compromised accounts, accidental misuse, and unauthorized activity. In Microsoft security environments, least privilege can be reinforced through tools such as Microsoft Entra PIM, access reviews, role-based access control, and Conditional Access. Instead of giving administrators permanent broad permissions, organizations can provide eligible or temporary access when elevated privileges are genuinely required. Assume breach and verify explicitly are also important Zero Trust principles, but they address different aspects of security. Therefore, least privilege directly describes limiting permissions to what is necessary.
Question 332. Which Microsoft Purview capability is primarily used to define how long organizational content should be retained or when it can be disposed of?
- Retention policies
- Authentication strengths
- Sentinel workbooks
- Device compliance policies
Correct Answer: 1. Retention policies
Explanation:
Microsoft Purview retention policies help organizations manage how long certain types of content should be retained and when information can be disposed of according to organizational or regulatory requirements. Retention can be applied across supported Microsoft 365 locations and can help organizations maintain information for an appropriate period without relying entirely on individual users to make retention decisions. Authentication strengths control sign-in requirements, Sentinel workbooks provide security visualization, and Intune compliance policies evaluate device security state. Retention policies are therefore the correct capability when the requirement is to establish organizational rules for keeping or disposing of content over time.
Question 333. Which Microsoft Entra log provides information about authentication attempts and sign-in activity?
- Provisioning logs
- Audit logs
- Sign-in logs
- Retention reports
Correct Answer: 3. Sign-in logs
Explanation:
Microsoft Entra sign-in logs provide information about authentication attempts and user sign-in activity. Security teams can use these logs to investigate successful and failed authentication, identify unusual locations, examine authentication methods, review Conditional Access results, and investigate potentially compromised accounts. Sign-in information can be especially useful when correlating identity activity with other Microsoft security signals. Audit logs serve a different purpose by recording administrative and directory-related changes, such as modifications to users, groups, applications, and settings. Retention reports do not provide the primary authentication activity record. Therefore, when an administrator needs to examine authentication attempts and sign-in behavior, Microsoft Entra sign-in logs are the appropriate source.
Question 334. Which Microsoft Defender capability helps identify vulnerabilities and security weaknesses across an organization’s devices?
- Defender for Office 365
- Defender Vulnerability Management
- Defender for Cloud Apps
- Defender for Identity
Correct Answer: 2. Defender Vulnerability Management
Explanation:
Microsoft Defender Vulnerability Management helps organizations discover, assess, prioritize, and remediate security vulnerabilities and weaknesses across devices. It can provide visibility into software vulnerabilities, security recommendations, device exposure, and remediation priorities. Security teams can use this information to understand which weaknesses require attention and to reduce the organization’s attack surface. Defender for Office 365 focuses on email and collaboration threats, Defender for Cloud Apps focuses on cloud application security, and Defender for Identity focuses on identity threats involving Active Directory. Vulnerability management therefore directly addresses the requirement to identify and prioritize weaknesses across organizational endpoints and other supported assets.
Question 335. Which Microsoft security service is specifically focused on protecting email and collaboration workloads from malicious links, attachments, and related threats?
- Microsoft Defender for Identity
- Microsoft Defender for Office 365
- Microsoft Intune
- Microsoft Entra PIM
Correct Answer: 2. Microsoft Defender for Office 365
Explanation:
Microsoft Defender for Office 365 provides security capabilities designed to protect email and collaboration workloads against threats such as malicious links, harmful attachments, phishing attempts, and other message-based attacks. It can use security intelligence and analysis to detect suspicious content and provide investigation and response capabilities. Defender for Identity is focused on identity threats involving Active Directory, while Intune manages devices and application policies. Microsoft Entra PIM controls privileged identity access. When an organization needs protection for Microsoft 365 email and collaboration services, Defender for Office 365 is the service most directly aligned with that requirement.
Question 336. Which Microsoft Entra capability helps automate identity-related tasks such as onboarding and offboarding users?
- Entra Lifecycle Workflows
- Sentinel workbooks
- Defender Vulnerability Management
- Purview DLP
Correct Answer: 1. Entra Lifecycle Workflows
Explanation:
Microsoft Entra Lifecycle Workflows are designed to automate identity lifecycle processes such as onboarding, employee movement, and offboarding. Automating these processes can help organizations apply consistent actions when users join, change roles, or leave the organization. For example, workflows can support tasks associated with account management and access changes, reducing the amount of manual administrative effort required. Sentinel workbooks are designed for security visualization, Defender Vulnerability Management focuses on identifying security weaknesses, and Purview DLP helps protect sensitive information from inappropriate sharing or transfer. Lifecycle Workflows therefore provide the capability most directly suited to automating recurring identity lifecycle tasks.
Question 337. Which Microsoft security capability provides a unified view of alerts and incidents across multiple Defender security products?
- Microsoft Defender XDR
- Microsoft Intune
- Microsoft Purview
- Microsoft Entra access reviews
Correct Answer: 1. Microsoft Defender XDR
Explanation:
Microsoft Defender XDR brings security signals from multiple Microsoft Defender products together to provide a more unified view of threats, alerts, incidents, and related entities. Correlating signals across endpoints, identities, email, and other workloads can help security teams understand broader attack activity instead of investigating every alert independently. This can reduce fragmented investigations and help analysts identify relationships between events occurring across different parts of the environment. Intune focuses on device management, Purview addresses data security and compliance, and access reviews address identity governance. Defender XDR therefore best matches the requirement for unified detection and investigation across Microsoft security workloads.
Question 338. Which Microsoft Entra capability can evaluate user risk and help apply additional access controls when suspicious sign-in behavior is detected?
- Lifecycle Workflows
- Entra ID Protection
- Access reviews
- Audit logs
Correct Answer: 2. Entra ID Protection
Explanation:
Microsoft Entra ID Protection provides identity risk detection capabilities that can identify potentially compromised users and risky sign-in activity. Risk information can be incorporated into Conditional Access policies so that organizations can require stronger authentication, block access, or apply other controls when appropriate. This supports a risk-based approach to identity security because access decisions can consider signals associated with potential compromise rather than relying only on static conditions. Lifecycle Workflows automate identity lifecycle tasks, access reviews periodically evaluate entitlement, and audit logs record directory changes. Entra ID Protection is therefore the capability most directly associated with detecting and responding to user and sign-in risk.
Question 339. Which Microsoft security capability can provide recommendations for improving an organization’s overall security posture?
- Microsoft Secure Score
- Microsoft Sentinel playbooks
- Microsoft Entra sign-in logs
- Purview sensitivity labels
Correct Answer: 1. Microsoft Secure Score
Explanation:
Microsoft Secure Score provides an assessment of an organization’s security posture and offers recommendations intended to help improve security configuration and protection. It can help administrators identify areas where security controls can be strengthened and track improvements over time. The recommendations may cover areas such as identity protection, device security, data protection, and other Microsoft security capabilities. Sentinel playbooks are designed for automated security workflows, Entra sign-in logs provide authentication activity information, and Purview sensitivity labels classify and protect information. Therefore, Microsoft Secure Score is the appropriate capability when the goal is to review security posture and receive actionable recommendations for improvement.
Question 340. An organization wants to protect privileged administrator accounts using temporary access, strong authentication, least privilege, and continuous monitoring. Which approach best supports this requirement?
- Permanent global administrator assignments
- Password-only authentication with broad permissions
- Just-in-time privileged access combined with strong authentication and monitoring
- Disabling all administrator accounts
Correct Answer: 3. Just-in-time privileged access combined with strong authentication and monitoring
Explanation:
Privileged administrator accounts require stronger controls because compromise of these accounts can have significant consequences across an organization. A security architecture should minimize standing privilege through just-in-time access, require strong or phishing-resistant authentication where appropriate, apply least-privilege role assignments, and continuously monitor administrative activity. Microsoft Entra PIM can support temporary privileged access and activation controls, while Conditional Access and authentication strengths can enforce stronger authentication requirements. Monitoring through Microsoft security services provides additional visibility into suspicious activity. Permanent broad administrator assignments and password-only authentication increase exposure, while disabling all administrator accounts is generally impractical. A layered privileged-access strategy therefore best supports the stated requirement.