Microsoft

MS-500 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 194-question bank.

Provider
Microsoft
Question bank
194
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for MS-500, a certification listed under Microsoft. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Microsoft. The certification credential is issued by Microsoft, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    You have several Conditional Access policies that block noncompliant devices from connecting to services. You need to identify which devices are blocked by which policies. What should you use?

    Choose one answer.

    • the Setting compliance report in the Microsoft Endpoint Manager admin center
    • Sign-ins in the Azure Active Directory admin center
    • Activity log in the Cloud App Security portal
    • Audit logs in the Azure Active Directory admin center
  2. Question 2 · 1

    Your company has a Microsoft 365 subscription. The company does not permit users to enroll personal devices in mobile device management (MDM). Users in the sales department have personal iOS devices. You need to ensure that the sales department users can use the Microsoft Power BI app from iOS devices to access the Power BI data in your tenant. The users must be prevented from backing up the app's data to iCloud. What should you create?

    Choose one answer.

    • a conditional access policy in Microsoft Azure Active Directory (Azure AD) that has a device state condition
    • an app protection policy in Microsoft Endpoint Manager
    • a conditional access policy in Microsoft Azure Active Directory (Azure AD) that has a client apps condition
    • a device compliance policy in Microsoft Endpoint Manager
  3. Question 3 · 1

    HOTSPOT - You have a Microsoft 365 E5 subscription. Users and device objects are added and removed daily. Users in the sales department frequently change their device. You need to create three following groups: The solution must minimize administrative effort. What is the minimum number of groups you should create for each type of membership? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Hot Area:

    Choose an option for each prompt.

    Question illustration 1
    Question illustration 2

    Groups that have assigned membership:

    • 0
    • 1
    • 2
    • 3

    Groups that have dynamic membership:

    • 0
    • 1
    • 2
    • 3
    Read explanation

    Group 1 has to be assigned because you can't create a device group based on the device owners' attributes. Group 2 can be dynamic because a user does have a department attribute. Group 3 can be dynamic because a device does have a deviceownership attribute.

  4. Question 4 · 1

    Your company has a main office and a Microsoft 365 subscription. You need to enforce Microsoft Azure Multi-Factor Authentication (MFA) by using conditional access for all users who are NOT physically present in the office. What should you include in the configuration?

    Choose one answer.

    • a user risk policy
    • a sign-in risk policy
    • a named location in Azure Active Directory (Azure AD)
    • an Azure MFA Server
  5. Question 5 · 1

    HOTSPOT - You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table. You create and enforce an Azure AD Identity Protection sign-in risk policy that has the following settings: ✑ Assignments: Include Group1, Exclude Group2 ✑ Conditions: Sign-in risk of Low and above ✑ Access: Allow access, Require multi-factor authentication You need to identify how the policy affects User1 and User2. What occurs when each user signs in from an anonymous IP address? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Hot Area:

    Choose an option for each prompt.

    Question illustration 1
    Question illustration 2

    User1:

    • Blocked
    • Can sign in without MFA
    • Prompted for MFA

    User2:

    • Blocked
    • Can sign in without MFA
    • Prompted for MFA
  6. Question 6 · 1

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an on-premises Active Directory domain named contoso.com. You install and run Azure AD Connect on a server named Server1 that runs Windows Server. You need to view Azure AD Connect events. Solution: You use the Application event log on Server1. Does that meet the goal?

    Choose one answer.

    • Yes
    • No
  7. Question 7 · 1

    HOTSPOT - You have a Microsoft 365 subscription that contains the users shown in the following table. You implement Azure Active Directory (Azure AD) Privileged Identity Management (PIM). From PIM, you review the Application Administrator role and discover the users shown in the following table. The Application Administrator role is configured to use the following settings in PIM: ✑ Activation maximum duration (hours): 1 hour ✑ Require justification on activation: No ✑ Require ticket information on activation: No ✑ On activation, require Azure MFA: No ✑ Require approval to activate: Yes ✑ Approvers: None For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Hot Area:

    Choose an option for each prompt.

    Question illustration 1
    Question illustration 2
    Question illustration 3

    If UserB requests the Application Administrator role, User1 can approve the request of UserB.

    • Yes
    • No

    If UserB requests the Application Administrator role, User2 can approve the request of UserB.

    • Yes
    • No

    If UserC requests the Application Administrator role, User3 can approve the request of UserC.

    • Yes
    • No
  8. Question 8 · 1

    You have a Microsoft 365 E5 subscription. Some users are required to use an authenticator app to access Microsoft SharePoint Online. You need to view which users have used an authenticator app to access SharePoint Online. The solution must minimize costs. What should you do?

    Choose one answer.

    • From the Azure Active Directory admin center, view the sign-ins.
    • From the Microsoft 365 Security admin center, download a report.
    • From the Enterprise applications blade of the Azure Active Directory admin center, view the audit logs.
    • From the Azure Active Directory admin center, view the authentication methods.
  9. Question 9 · 1

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 E5 subscription that is associated to a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com. You use Active Directory Federation Services (AD FS) to federate on-premises Active Directory and the tenant. Azure AD Connect has the following settings: ✑ Source Anchor: objectGUID ✑ Password Hash Synchronization: Disabled ✑ Password writeback: Disabled ✑ Directory extension attribute sync: Disabled ✑ Azure AD app and attribute filtering: Disabled ✑ Exchange hybrid deployment: Disabled ✑ User writeback: Disabled You need to ensure that you can use leaked credentials detection in Azure AD Identity Protection. Solution: You modify the Password Hash Synchronization settings. Does that meet the goal?

    Choose one answer.

    • Yes
    • No
  10. Question 10 · 1

    You have a Microsoft 365 subscription that contains a user named User1. You plan to use Compliance Manager. You need to ensure that User1 can assign Compliance Manager roles to users. The solution must use the principle of least privilege. Which role should you assign to User1?

    Choose one answer.

    • Compliance Manager Assessor
    • Global Administrator
    • Portal Admin
    • Compliance Manager Administrator
  11. Question 11 · 1

    You have a Microsoft 365 subscription linked to an Azure Active Directory (Azure AD) tenant that contains a user named User1. You have a Data Subject Request (DSR) case named Case1. You need to allow User1 to export the results of Case1. The solution must use the principle of least privilege. Which role should you assign to User1 for Case1?

    Choose one answer.

    • eDiscovery Manager
    • Security Operator
    • eDiscovery Administrator
    • Global Reader
  12. Question 12 · 1

    HOTSPOT - You have a Microsoft 365 subscription that contains the users shown in the following table. You create and enforce an Azure Active Directory (Azure AD) Identity Protection user risk policy that has the following settings: ✑ Assignments: Include Group1, Exclude Group2 ✑ User-risk: User risk level of Medium and above ✑ Access: Allow access, Require password change The users attempt to sign in. The risk level for each user is shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Hot Area:

    Choose an option for each prompt.

    Question illustration 1
    Question illustration 2
    Question illustration 3

    User1 must change his password.

    • Yes
    • No

    User2 must change his password.

    • Yes
    • No

    User3 must change his password.

    • Yes
    • No
    Read explanation

    Box 1: Yes. User1 is in Group1 which the policy applies to. Box 2: No - User2 is in Group2 which is excluded from the policy. Box 3: No - User3 is in Group1 which is included in the policy and Group2 which is excluded from the policy. In this case, the exclusion wins so the policy does not apply to User3.

  13. Question 13 · 1

    You configure several Advanced Threat Protection (ATP) policies in a Microsoft 365 subscription. You need to allow a user named User1 to view ATP reports from the Threat management dashboard. Which role provides User1 with the required role permissions?

    Choose one answer.

    • Compliance administrator
    • Security reader
    • Message center reader
    • Reports reader
  14. Question 14 · 1

    HOTSPOT - Your network contains an on-premises Active Directory domain that syncs to Azure Active Directory (Azure AD) as shown in the following exhibit. The synchronization schedule is configured as shown in the following exhibit. Use the drop-down menus to select the answer choice that answers each question based on the information presented in the graphic. NOTE: Each correct selection is worth one point. Hot Area:

    Choose an option for each prompt.

    Question illustration 1
    Question illustration 2
    Question illustration 3

    Which employees can authenticate by using Azure AD?

    • Only employees who have an Azure AD user account
    • Employees who have an Azure AD user account and a synced on-premises account
    • Only employees who have a synced on-premises account

    What should you do to remove the warning for pass-through authentication?

    • Fix the synchronization server and install Azure AD Connect in staging mode
    • Fix the synchronization server and install an additional authentication agent
    • Install an additional authentication agent and run the Start-ADSyncSyncCycle cmdlet
    • Install Azure AD Connect in staging mode and run the Start-ADSyncSyncCycle cmdlet
  15. Question 15 · 1

    HOTSPOT - You have a Microsoft 365 E5 subscription that uses Microsoft Endpoint Manager. The Compliance policy settings are configured as shown in the following exhibit. On February 25, 2020, you create the device compliance policies shown in the following table. On March 1. 2020, users enroll Windows 10 devices in Microsoft Endpoint Manager as shown in the following table For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Hot Area:

    Choose an option for each prompt.

    Question illustration 1
    Question illustration 2
    Question illustration 3
    Question illustration 4

    On March 2, 2020, Device2 is marked as compliant.

    • Yes
    • No

    On March 6, 2020, Device1 is marked as compliant.

    • Yes
    • No

    On March 12, 2020, Device1 is marked as compliant.

    • Yes
    • No
    Read explanation

    Box 1: Yes - Device2 is in Group2 so Policy2 applies. Device2 is not compliant with Policy2. However, the device won't be marked as non-compliant until 10 days after the device was enrolled. Box 2: Yes - Device1 is in Group1 and Group2 so both Policy1 and Policy2 apply. Device1 is compliant with Policy1 but non-compliant with Policy2. However, the device won't be marked as non-compliant until 10 days after the device was enrolled. Box 3: No - Device1 is in Group1 and Group2 so both Policy1 and Policy2 apply. Device1 is compliant with Policy1 but non-compliant with Policy2. th March 12 - is more than 10 days after the device was enrolled so it will now be marked as non-compliant by Policy2.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free