MS-500 Exam Question 41

You have a Microsoft 365 E5 subscription and a hybrid Microsoft Exchange Server organization.
Each member of a group named Executive has an on-premises mailbox. Only the Executive group members have multi-factor authentication (MFA) enabled. Each member of a group named Research has a mailbox in Exchange Online.
You need to use Microsoft Office 365 Attack simulator to model a spear-phishing attack that targets the Research group members.
The email address that you intend to spoof belongs to the Executive group members.
What should you do first?
  • MS-500 Exam Question 42

    Several users in your Microsoft 365 subscription report that they received an email message without the attachment. You need to review the attachments that were removed from the messages. Which two tools can you use? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
  • MS-500 Exam Question 43

    You have a Microsoft 365 subscription that includes a user named User1.
    You have a conditional access policy that applies to Microsoft Exchange Online. The conditional access policy is configured to use Conditional Access App Control.
    You need to create a Microsoft Cloud App Security policy that blocks User1 from printing from Exchange Online.
    Which type of Cloud App Security policy should you create?
  • MS-500 Exam Question 44

    You have a Microsoft 365 subscription that uses an Azure Active Directory (Azure AD) tenant named contoso.com. All the devices in the tenant are managed by using Microsoft Intune.
    You purchase a cloud app named App1 that supports session controls.
    You need to ensure that access to App can be reviewed in real time.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    MS-500 Exam Question 45

    You have a Microsoft 365 subscription that contains 1,000 user mailboxes.
    An administrator named Admin1 must be able to search for the name of a competing company in the mailbox of a user named User5.
    You need to ensure that Admin1 can search the mailbox of User5 successfully. The solution must prevent Admin1 from sending User5.
    Solution: You start a message trace, and then create a Data Subject request (DSR) case.
    Does this meet the goal?