Free MS-500 Exam Braindumps

Pass your Microsoft 365 Security Administrator exam with these free Questions and Answers

Page 18 of 65
QUESTION 81

- (Exam Topic 4)
An administrator plans to deploy several Azure Advanced Threat Protection (ATP) sensors.
You need to provide the administrator with the Azure information required to deploy the sensors. What information should you provide?

  1. A. an Azure Active Directory Authentication Library (ADAL) token
  2. B. the public key
  3. C. the access key
  4. D. the URL of the Azure ATP admin center

Correct Answer: D
https://docs.microsoft.com/en-us/azure-advanced-threat-protection/workspace-portal

QUESTION 82

- (Exam Topic 4)
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some questions sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an on-premises Active Directory domain named contoso.com.
You install and run Azure AD Connect on a server named Server1 that runs Windows Server. You need to view Azure AD Connect events.
You use the System event log on Server1. Does that meet the goal?

  1. A. Yes
  2. B. No

Correct Answer: B
References:
https://support.pingidentity.com/s/article/PingOne-How-to-troubleshoot-an-AD-Connect-Instance

QUESTION 83

- (Exam Topic 4)
You have a Microsoft 365 E5 subscription that contains 500 Windows 10 devices The subscription uses Microsoft Defender for Endpoint and is integrated with Microsoft Endpoint Manager. AJI the devices have Defender for Endpoint deployed.
You create a Conditional Access policy as shown in the following table.
MS-500 dumps exhibit
You need to ensure that devices that have a machine risk score of high are blocked. What should you do in Microsoft Endpoint Manager?

  1. A. Apply a security baseline to all the devices.
  2. B. Apply an endpoint detection and response policy to the subscription.
  3. C. Configure the Compliance policy settings.
  4. D. Apply a compliance policy to all the devices.

Correct Answer: B

QUESTION 84

- (Exam Topic 4)
You have a Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) deployment that has the custom network indicators turned on. Microsoft Defender ATP protects two computers that run Windows 10 as shown in the following table.
MS-500 dumps exhibit
Microsoft Defender ATP has the machine groups shown in the following table.
MS-500 dumps exhibit
From Microsoft Defender Security Center, you create the URLs/Domains indicators shown in the following table.
MS-500 dumps exhibit
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
MS-500 dumps exhibit
Solution:
MS-500 dumps exhibit

Does this meet the goal?

  1. A. Yes
  2. B. No

Correct Answer: A

QUESTION 85

- (Exam Topic 4)
You have a Microsoft 365 alert named Alert?
as shown in the following exhibit.
MS-500 dumps exhibit
You need to manage the status of Alert2. To which status can you change Alert2?

  1. A. The status cannot be changed.
  2. B. investigating only
  3. C. Active or investigating only
  4. D. Investigating, Active, or Dismissed
  5. E. Dismissed only

Correct Answer: D

Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/dlp-configure-view-alerts-policies?view=o365-worl

Page 18 of 65

Post your Comments and Discuss Microsoft MS-500 exam with other Community members: