MS-500 Exam Question 41

You have a Microsoft 365 E5 subscription that uses Microsoft Endpoint Manager.
The Compliance policy settings are configured as shown in the following exhibit.

On February 25, 2020, you create the device compliance policies shown in the following table.

On March 1. 2020, users enroll Windows 10 devices in Microsoft Endpoint Manager as shown in the following table

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

MS-500 Exam Question 42

You have a Microsoft 365 E5 subscription that contains a user named User1.
The Azure Active Directory (Azure AD) Identity Protection risky users report identities User1.
For User1, you select Confirm user compromised.
User1 can still sign in.
You need to prevent User1 from signing in. The solution must minimize the impact on users at a lower risk level.
Solution: You configure the user risk policy to block access when the user risk level is high.
Does this meet the goal?
  • MS-500 Exam Question 43

    You create an Azure Sentinel workspace.
    You configure Azure Sentinel to ingest data from Azure Active Directory (Azure AD).
    In the Azure Active Directory admin center, you discover Azure AD Identity Protection alerts. The Azure Sentinel workspace shows the status as shown in the following exhibit.

    In Azure Log Analytics, you can see Azure AD data in the Azure Sentinel workspace.
    What should you configure in Azure Sentinel to ensure that incidents are created for detected threats?
  • MS-500 Exam Question 44

    Your on-premises network contains an Active Directory domain that syncs to Azure Active Directory (Azure AD) by using Azure AD Connect. The functional level of the domain. You need to deploy Windows Hello for Business. The solution must meet the following requirements:
    * Ensure that users can access Microsoft 365 services and on-premises resources.
    * Minimize administrative efforts
    How should you deploy Windows Hello for Business, and which type of trust should you use? To answer, select the appropriate options in the answer area.

    MS-500 Exam Question 45

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some questions sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You have an on-premises Active Directory domain named contoso.com.
    You install and run Azure AD Connect on a server named Server1 that runs Windows Server.
    You need to view Azure AD Connect events.
    You use the Security event log on Server1.
    Does that meet the goal?