MS500 Microsoft 365 Security Administration Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A financial services firm, \"Aethelred Capital,\" has detected anomalous activity within its Microsoft 365 tenant, suggesting a sophisticated phishing attack has successfully compromised several executive accounts. Initial alerts indicate unauthorized access to sensitive financial documents and potential data exfiltration. The Chief Information Security Officer (CISO) must immediately coordinate a response that addresses the technical breach, legal obligations, and stakeholder confidence. Considering the firm\'s commitment to maintaining regulatory compliance under frameworks like SOX and the need for swift, yet thorough, action, which of the following strategic approaches best embodies a mature incident response posture?

Initiate immediate system-wide account lockouts for all executive personnel, followed by a comprehensive forensic analysis of compromised mailboxes and cloud storage, while simultaneously engaging legal counsel to assess notification requirements under relevant financial regulations.
Deploy an organization-wide alert for all employees to be vigilant for suspicious communications and proceed with a phased rollback of recent system changes, deferring detailed forensic investigation until after the immediate threat appears to have subsided.
Focus solely on isolating the compromised accounts by disabling their access and resetting passwords, then wait for user reports of further anomalies before escalating to a full investigation, prioritizing minimal disruption to daily operations.
Immediately notify all employees and external stakeholders about the potential breach, then begin a broad review of all Microsoft 365 security configurations to identify any misconfigurations that might have contributed, without prioritizing specific compromised accounts initially.

About the MS500 Microsoft 365 Security Administration Certification

These free practice questions are designed to help you assess your readiness for the MS500 Microsoft 365 Security Administration exam by Other. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.