MS-500 Exam Question 6
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some questions sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 subscription.
You have a user named User1. Several users have full access to the mailbox of User1.
Some email messages sent to User1 appear to have been read and deleted before the user viewed them.
When you search the audit log in Security & Compliance to identify who signed in to the mailbox of User1, the results are blank.
You need to ensure that you can view future sign-ins to the mailbox of User1.
You run the Set-AuditConfig -Workload Exchange command.
Does that meet the goal?
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 subscription.
You have a user named User1. Several users have full access to the mailbox of User1.
Some email messages sent to User1 appear to have been read and deleted before the user viewed them.
When you search the audit log in Security & Compliance to identify who signed in to the mailbox of User1, the results are blank.
You need to ensure that you can view future sign-ins to the mailbox of User1.
You run the Set-AuditConfig -Workload Exchange command.
Does that meet the goal?
MS-500 Exam Question 7
You have a Microsoft 365 subscription that uses a default domain name of fabrikam.com.
You create a safe links policy, as shown in the following exhibit.

Which URL can a user safely access from Microsoft Word Online?
You create a safe links policy, as shown in the following exhibit.

Which URL can a user safely access from Microsoft Word Online?
MS-500 Exam Question 8
Your network contains an on-premises Active Directory domain. The domain contains the servers shown in the following table.

You have a Microsoft 365 subscription.
You plan to deploy Microsoft Defender for Identity.
You need to deploy the Defender for Identity sensor. The solution must meet the following requirements:
* Support the collection of Event Tracing for Windows (ETW) log entries.
* Use the principle of least privilege.
* Maximize security.
On which servers can you install the sensor, and which type of credentials is required for the sensor? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


You have a Microsoft 365 subscription.
You plan to deploy Microsoft Defender for Identity.
You need to deploy the Defender for Identity sensor. The solution must meet the following requirements:
* Support the collection of Event Tracing for Windows (ETW) log entries.
* Use the principle of least privilege.
* Maximize security.
On which servers can you install the sensor, and which type of credentials is required for the sensor? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

MS-500 Exam Question 9
You have an Azure Sentinel workspace that has an Office 365 connector.
You are threat hunting events that have suspicious traffic from specific IP addresses.
You need to save the events and the relevant query results for future reference.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You are threat hunting events that have suspicious traffic from specific IP addresses.
You need to save the events and the relevant query results for future reference.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

MS-500 Exam Question 10
You have a Microsoft 365 tenant that has modern authentication enabled.
You have Windows 10, MacOS. Android, and iOS devices that are managed by using Microsoft Endpoint Manager. Some users have older email client applications that use Basic authentication to connect to Microsoft Exchange Online. You need to implement a solution to meet the following security requirements-
* Allow users to connect to Exchange Online only by using email client applications that support modern authentication protocols based on OAuth 2.0.
* Block connections to Exchange Online by any email client applications that do NOT support modern authentication.
What should you implement?
You have Windows 10, MacOS. Android, and iOS devices that are managed by using Microsoft Endpoint Manager. Some users have older email client applications that use Basic authentication to connect to Microsoft Exchange Online. You need to implement a solution to meet the following security requirements-
* Allow users to connect to Exchange Online only by using email client applications that support modern authentication protocols based on OAuth 2.0.
* Block connections to Exchange Online by any email client applications that do NOT support modern authentication.
What should you implement?




