{"id":16880,"date":"2026-09-19T11:43:20","date_gmt":"2026-09-19T11:43:20","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=16880"},"modified":"2026-09-19T11:43:20","modified_gmt":"2026-09-19T11:43:20","slug":"microsoft-sc-500-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-sc-500-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"Microsoft SC-500 Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/sc-500-exam-dumps\"><b>Microsoft SC-500 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<p><b>Question 141. Which Microsoft Entra capability can require administrator approval before a privileged role becomes active?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra access reviews<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Privileged Identity Management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra Connect<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra Application Proxy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Privileged Identity Management<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management, or PIM, can require approval before an eligible user activates a privileged role. This provides an additional control over administrative access by ensuring that elevation does not automatically occur simply because a user is eligible for the role. Organizations can configure activation requirements such as approval, multifactor authentication, justification, and time limits. This approach supports Just-In-Time administration and reduces the amount of time that privileged permissions remain active. Approval workflows are particularly useful for highly sensitive roles because another authorized person can review the business justification before elevated permissions are granted.<\/span><\/p>\n<p><b>Question 142. Which Microsoft Defender capability helps detect malicious or suspicious email messages and collaboration content?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Office 365<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Identity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender Vulnerability Management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Cloud Apps<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Defender for Office 365<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Office 365 helps protect organizations against threats delivered through email and supported collaboration services. It provides capabilities for detecting and responding to threats such as phishing, malicious links, malicious attachments, and other harmful content. Security teams can investigate alerts and use threat intelligence and analysis capabilities to understand potentially dangerous messages. Defender for Office 365 is an important part of a broader Microsoft security architecture because email is frequently targeted by attackers attempting to obtain credentials or deliver malware. Its signals can also contribute to Microsoft Defender XDR investigations, allowing analysts to correlate email activity with identity and endpoint events.<\/span><\/p>\n<p><b>Question 143. Which Microsoft Purview feature is designed to apply persistent classification and protection to sensitive files and emails?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Retention policies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Audit search<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sensitivity labels<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> eDiscovery holds<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Sensitivity labels<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview sensitivity labels help organizations classify and protect sensitive content such as documents and emails. Depending on configuration, labels can apply protection settings such as encryption, access restrictions, visual markings, or other controls. Labels help users and administrators consistently identify the sensitivity of information and apply appropriate protection according to organizational policies. They can be used across supported Microsoft 365 workloads and can also support automated classification scenarios when properly configured. Sensitivity labels differ from retention policies because their primary purpose is information classification and protection rather than determining how long content should be retained or when it should be deleted.<\/span><\/p>\n<p><b>Question 144. Which Microsoft Entra log should an administrator examine to determine what changes were made to directory objects?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Audit logs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sign-in logs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risky users<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Authentication strengths<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Audit logs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra audit logs provide information about administrative and directory activities that result in changes to resources. Administrators can use audit logs to investigate activities such as creating or deleting users, modifying groups, changing role assignments, updating applications, and other directory operations. These records are valuable during security investigations because they can help establish who performed an action, what operation occurred, and when the activity took place. Sign-in logs are primarily focused on authentication events, whereas audit logs focus on changes and administrative activities. Monitoring audit logs can therefore help identify unauthorized modifications and support accountability for important identity-management operations.<\/span><\/p>\n<p><b>Question 145. Which Microsoft Sentinel capability provides interactive visualizations of security data and trends?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Playbooks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Workbooks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automation rules<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data connectors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Workbooks<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel workbooks provide interactive visualizations that help security teams understand and analyze collected security information. Workbooks can display charts, tables, metrics, and other visual representations based on queries and available data. Security teams can use them to monitor trends, investigate activity, track incidents, and present operational information in a more accessible format. For example, a workbook could display authentication trends, incident statistics, endpoint activity, or other security metrics. Workbooks are primarily designed for visualization and analysis rather than automatic response. Automation rules and playbooks serve different purposes by helping organizations initiate actions based on alerts or incidents.<\/span><\/p>\n<p><b>Question 146. Which access model is most appropriate for granting administrators elevated permissions only when required?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permanent access<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Shared account access<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Just-In-Time access<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Anonymous access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Just-In-Time access<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Just-In-Time access provides elevated permissions only for the period in which they are required. This reduces the exposure created by permanent administrative privileges. In Microsoft environments, Microsoft Entra Privileged Identity Management can support Just-In-Time role activation by allowing administrators to remain eligible for a role without continuously holding the active permissions. Activation can require additional safeguards such as multifactor authentication, approval, justification, and a defined duration. This model supports least privilege and helps limit the window in which a compromised privileged account could be abused. It is especially useful for administrative roles where elevated access is needed periodically rather than continuously.<\/span><\/p>\n<p><b>Question 147. Which Microsoft security service can help detect suspicious behavior involving users, computers, and domain controllers in an on-premises Active Directory environment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Identity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Office 365<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview DLP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Intune<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Defender for Identity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Identity monitors identity-related signals in on-premises Active Directory environments and helps identify suspicious behavior associated with accounts, computers, and domain infrastructure. It can detect indicators associated with reconnaissance, credential theft, lateral movement, privilege escalation, and other identity-based attack techniques. This visibility is especially important for organizations operating hybrid environments where cloud identities and on-premises Active Directory are interconnected. Defender for Identity can also contribute signals to broader Microsoft Defender XDR investigations, helping analysts correlate identity activity with endpoint and other security events. Monitoring identity behavior provides an additional layer of protection beyond traditional endpoint-focused security controls.<\/span><\/p>\n<p><b>Question 148. Which Conditional Access feature can restrict access based on the geographic network location from which a request originates?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Authentication strengths<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Named locations<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Session controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Access reviews<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Named locations<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Conditional Access named locations allow administrators to define trusted or specific network locations using criteria such as IP address ranges or supported geographic conditions. These locations can then be referenced in Conditional Access policies to apply different access requirements depending on where a sign-in originates. For example, an organization may require stronger controls when users connect from unfamiliar locations while applying different requirements to known corporate networks. Named locations should not be treated as a complete security boundary because trusted networks can also be compromised or misused. They are best used as one signal among several when developing risk-based and Zero Trust access policies.<\/span><\/p>\n<p><b>Question 149. Which Microsoft security principle recommends continuously evaluating access rather than assuming previously granted access remains trustworthy?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Zero Trust<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Perimeter-only security<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Implicit trust<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Shared administration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Zero Trust<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust is a security approach based on the principle that access should not be automatically trusted simply because a user or device was previously approved. Instead, organizations should continuously evaluate relevant signals such as identity, device state, application, location, and risk before granting or maintaining access. Microsoft security technologies such as Conditional Access, Microsoft Entra ID Protection, Intune compliance policies, Privileged Identity Management, and Defender solutions can support this model. Zero Trust also emphasizes least privilege and the assumption that a breach may occur. The goal is to reduce unnecessary trust and limit the potential impact of compromised identities, devices, or applications.<\/span><\/p>\n<p><b>Question 150. Which Microsoft Defender solution provides security recommendations related to endpoint vulnerabilities and configuration weaknesses?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Defender for Office 365<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Defender for Cloud Apps<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Defender Vulnerability Management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Defender for Identity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Defender Vulnerability Management<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender Vulnerability Management provides visibility into vulnerabilities and security weaknesses affecting supported devices and software. It can help security teams identify exposure, prioritize remediation, and understand recommendations for improving endpoint security posture. Rather than treating every vulnerability as equally urgent, organizations can use available risk information to focus attention on weaknesses that present greater exposure. The service complements endpoint detection and response by addressing weaknesses that attackers could potentially exploit before or during an attack. Regular vulnerability assessment is an important part of proactive security because preventing or reducing exploitable weaknesses can decrease the number of opportunities available to attackers.<\/span><\/p>\n<p><b>Question 151. Which Microsoft Entra feature helps organizations automate identity lifecycle tasks when employees join, change roles, or leave?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Lifecycle Workflows<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sign-in logs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Named locations<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Authentication strengths<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Lifecycle Workflows<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Lifecycle Workflows help organizations automate identity lifecycle processes associated with events such as onboarding, role changes, and offboarding. Automation can reduce the amount of manual work required from administrators and help ensure that appropriate identity actions occur consistently. For example, workflows can support tasks associated with removing access when an employee leaves or preparing accounts and access-related processes when a new employee joins. Effective lifecycle management is important because stale accounts and unnecessary permissions can create security risks. Automating repeatable lifecycle tasks can improve consistency, reduce administrative errors, and help organizations maintain appropriate access throughout the identity lifecycle.<\/span><\/p>\n<p><b>Question 152. Which Microsoft Sentinel capability allows analysts to create reusable queries for proactive investigation of suspicious activity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Analytics rules<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hunting queries<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Workbooks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Incident queues<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Hunting queries<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel hunting queries allow security analysts to proactively search security data for suspicious activity. Analysts can create and save Kusto Query Language queries that investigate specific behaviors, indicators, or patterns across available data. Hunting is useful when analysts have a hypothesis about potential malicious activity or want to investigate threats that have not necessarily triggered an existing detection rule. Findings from hunting can also help security teams improve their detection strategy by identifying patterns that could later become analytics rules. This makes threat hunting an important proactive security activity rather than simply a method for responding to alerts that have already been generated.<\/span><\/p>\n<p><b>Question 153. Which Microsoft security control can help prevent users from accessing protected resources when their managed device does not meet required security conditions?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Conditional Access combined with device compliance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel workbooks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview eDiscovery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Defender for Identity sensors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Conditional Access combined with device compliance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Intune device compliance policies can evaluate whether managed devices meet defined security requirements, while Microsoft Entra Conditional Access can use that compliance state when making access decisions. This combination allows organizations to restrict access when a device does not meet required conditions. For example, policies may require encryption, an approved operating system version, or other security settings before access to sensitive resources is permitted. This supports Zero Trust because the organization does not automatically trust a device merely because it belongs to a known user. Device posture becomes an important factor in determining whether access should be granted under the organization&#8217;s security policies.<\/span><\/p>\n<p><b>Question 154. Which Microsoft Purview capability helps prevent sensitive information from being shared through unauthorized channels?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data Loss Prevention<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Audit logs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> eDiscovery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Retention labels<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Data Loss Prevention<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Purview Data Loss Prevention helps organizations detect and protect sensitive information across supported locations and communication channels. DLP policies can identify sensitive information types or other configured conditions and then apply actions intended to reduce inappropriate sharing or transmission. Depending on the workload and policy configuration, users may receive warnings, activities may be blocked, or events may be reported for investigation. DLP is particularly useful for reducing accidental data exposure because users may unintentionally share sensitive information with unauthorized recipients. Effective DLP policies should be designed around organizational requirements and tested carefully so that security controls provide protection without unnecessarily disrupting legitimate business activity.<\/span><\/p>\n<p><b>Question 155. Which Microsoft Defender XDR capability helps security analysts investigate related alerts as a single security incident?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Alert and incident correlation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Device enrollment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Retention management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Directory synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Alert and incident correlation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender XDR can correlate related security alerts across different Microsoft security products and present them within a more unified incident context. This helps analysts understand that several individual alerts may actually represent different stages or components of the same attack. Correlation can reduce unnecessary duplication and provide additional context about affected identities, devices, applications, email activity, and other resources. Instead of investigating every alert independently, analysts can examine the relationships among events and build a more complete picture of the attack. This approach can improve investigation efficiency and help security teams determine appropriate response actions based on the broader incident context.<\/span><\/p>\n<p><b>Question 156. Which Microsoft Entra capability allows organizations to periodically confirm whether users should retain access to groups or applications?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Access reviews<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sign-in risk<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application Proxy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Directory synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Access reviews<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra access reviews allow organizations to periodically verify whether users and other identities should continue to have access to resources such as groups, applications, or privileged assignments. Regular reviews are important because access requirements can change when employees change roles, projects end, contractors leave, or business responsibilities are modified. Without periodic review, unnecessary permissions can remain active for extended periods. Access reviews provide a structured process for reviewers to confirm or remove access. This supports least privilege and Zero Trust principles by treating access as something that should be continuously evaluated rather than as a permanent entitlement granted once and trusted indefinitely.<\/span><\/p>\n<p><b>Question 157. Which Microsoft security capability can require multifactor authentication when a user&#8217;s identity risk reaches a configured threshold?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Entra ID Protection with Conditional Access<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Sentinel Workbooks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Purview retention policies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender Vulnerability Management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Microsoft Entra ID Protection with Conditional Access<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID Protection can provide identity risk information that Conditional Access policies can use to enforce additional controls. Organizations can configure policies that respond when a user&#8217;s risk reaches a defined level and require actions such as multifactor authentication or other remediation. This creates a risk-based approach to identity security because authentication requirements can change according to the security signals associated with an identity. Instead of applying exactly the same controls to every situation, organizations can increase protection when evidence suggests greater risk. Administrators should carefully design these policies and consider legitimate user scenarios to ensure that security requirements remain effective and manageable.<\/span><\/p>\n<p><b>Question 158. Which Microsoft security solution provides visibility into cloud application usage and can help identify unsanctioned applications?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Identity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Cloud Apps<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Defender for Endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Microsoft Intune<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Microsoft Defender for Cloud Apps<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud Apps provides visibility into cloud application usage and can help organizations identify applications that are not formally approved or managed. This is useful for discovering shadow IT, where employees use cloud services outside established organizational controls. Security teams can assess applications based on factors such as security posture, compliance considerations, and organizational requirements. The resulting visibility can help administrators determine which applications should be sanctioned, monitored, restricted, or otherwise managed. Cloud application discovery is particularly important because users may introduce data exposure risks by transferring sensitive information to services that have not undergone organizational security review.<\/span><\/p>\n<p><b>Question 159. Which security practice reduces the risk created when a single administrator has unrestricted control over every security function?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Shared credentials<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Separation of duties<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permanent Global Administrator access<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Anonymous administration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Separation of duties<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties reduces security risk by distributing sensitive responsibilities among different roles or individuals instead of allowing one person to control every critical function. This can help prevent unauthorized changes, reduce opportunities for abuse, and provide additional oversight for high-impact administrative actions. In Microsoft environments, organizations can combine role-based access control, least privilege, Privileged Identity Management, approval workflows, and auditing to support this principle. Separation of duties does not mean that every task must require multiple people; rather, especially sensitive responsibilities should be structured so that excessive control is not concentrated in a single account or administrator.<\/span><\/p>\n<p><b>Question 160. Which Microsoft security strategy combines identity protection, device security, data protection, threat detection, and continuous verification?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Perimeter-only security<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password-only authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Zero Trust security architecture<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Shared-account administration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Zero Trust security architecture<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Zero Trust security architecture combines multiple security disciplines rather than relying on a single perimeter or control. Identity protection verifies users and evaluates risk, device security evaluates endpoint posture, data protection helps safeguard sensitive information, and threat detection identifies suspicious activity across the environment. Continuous verification helps ensure that access decisions can change as risk conditions change. Microsoft technologies such as Entra ID Protection, Conditional Access, Intune, Defender solutions, Microsoft Sentinel, and Microsoft Purview can support different parts of this architecture. The overall objective is to reduce implicit trust, enforce least privilege, assume that breaches can occur, and limit the potential impact of compromised identities, devices, or applications.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft SC-500 Exam Dumps and Practice Test Dumps &nbsp; Question 141. Which Microsoft Entra capability can require administrator approval before a privileged role becomes active? Microsoft Entra access reviews Privileged Identity Management Microsoft Entra Connect Microsoft Entra Application Proxy Correct Answer: 2. Privileged Identity Management Explanation: Microsoft Entra Privileged Identity Management, or PIM, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16880"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=16880"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16880\/revisions"}],"predecessor-version":[{"id":16909,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16880\/revisions\/16909"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=16880"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=16880"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=16880"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}