MS-500 Exam Question 16

Your network contains an on-premises Active Directory domain. The domain contains servers that run Windows Server and have advanced auditing enabled.
The security logs of the servers are collected by using a third-party SIEM solution.
You purchase a Microsoft 365 subscription and plan to deploy Azure Advanced Threat Protection (ATP) by using standalone sensors.
You need to ensure that you can detect when sensitive groups are modified and when malicious services are created.
What should you do?
  • MS-500 Exam Question 17

    You have a Microsoft 365 E5 subscription.
    You plan to implement retention policies. Which item types can be retained?
  • MS-500 Exam Question 18

    You haw a Microsoft 365 subscription that contains the users shown in the following table.

    You need to ensure that User1, User2 , and User3 can use self-service password reset (SSPR). The solution must not affect User 4.
    Solution: You enable SSPR for Group3.
    .
    Does this meet the goal?
  • MS-500 Exam Question 19

    You view Compliance Manager as shown in the following exhibit.

    Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
    NOTE: Each correct selection is worth one point.

    MS-500 Exam Question 20

    You have a Microsoft 365 E5 subscription that contains a user named User1 and the groups shown in the following table.

    You plan to create a communication compliance policy named Policy1.
    You need to identify whose communications can be monitored by Policy1, and who can be assigned the Reviewer role for Policy1.
    Who should you identify? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.