exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 2 question 20 discussion

Actual exam question from Microsoft's MS-500
Question #: 20
Topic #: 2
[All MS-500 Questions]

You have a hybrid deployment of Microsoft 365 that contains the users shown in the following table.

You plan to use Microsoft 365 Attack Simulator.
You need to identify the users against which you can use Attack Simulator.
Which users should you identify?

  • A. User3 only
  • B. User1, User2, User3, and User4
  • C. User3 and User4 only
  • D. User1 and User3 only
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kiketxu
Highly Voted 4 years, 1 month ago
C for sure. Only supported on EXO. Btw, MFA is to create and manage campaings.
upvoted 30 times
ffffffffdeeeeeeeeeeee
3 years, 10 months ago
ANS: A Attack Simulator only works on cloud-based mailboxes and with MFA enabled.
upvoted 9 times
WMG
3 years, 8 months ago
No, answer is C. MFa is only required for the admins. Try it out. The targeted mailboxes need to be cloud mailboxes, not on-premise. The MFA status of the user who has full access and owner of a mailbox object is not relevant.
upvoted 6 times
Dhamus
1 year, 11 months ago
You are right.
upvoted 1 times
...
...
...
...
belyo
Highly Voted 4 years, 1 month ago
A for sure *Your account needs to be configured for multi-factor authentication (MFA) to create and manage campaigns in Attack Simulator. For instructions, see Set up multi-factor authentication. *Attack Simulator only works on cloud-based mailboxes.
upvoted 12 times
kiketxu
4 years, 1 month ago
MFA is to create and manage campaings. In the statements says "against"
upvoted 11 times
chaoscreater
3 years, 10 months ago
You're overcomplicating the english. If the sentence were to say - "you need to identify the users which you can use Attack Simulator against", then it means you want to use it on them. "Against" is to use it ON something, not necessarily PREVENT from using it on them. Question here is talking about using it on someone. Answer A is correct.
upvoted 1 times
WMG
3 years, 8 months ago
A user with a mailbox does not need MFA in order to be targeted by attack simulator. The user mailbox must however be in the cloud. so User 3 and User 4 fulfil that requirement. This you can verify by just testing it in your lab environment. In no way does any documentation state that you need MFA for users, because it is not needed when you configure an attack simulation.
upvoted 4 times
...
...
...
...
Okadorium
Most Recent 1 year, 10 months ago
MFA (Multi-Factor Authentication) is not a requirement to use Attack Simulator in Microsoft Defender for Office 365. Attack Simulator can be used to simulate phishing and spear-phishing attacks regardless of whether MFA is enabled or disabled for user accounts. Thus, the Answer is C.
upvoted 2 times
...
Maxx4
1 year, 10 months ago
Selected Answer: A
A. User3 only. Microsoft 365 Attack Simulator can be used to simulate phishing and other attacks against users in order to assess their security awareness and resilience. However, Attack Simulator requires certain prerequisites to be met, specifically the availability of Exchange Online mailboxes and the user's MFA status. In this scenario, User3 is the only user who meets both prerequisites. User3 has a mailbox in Microsoft Exchange Online, and MFA is enabled for this user. Therefore, you can use Attack Simulator against User3 to assess their response to simulated attacks. User1 is an on-premises Exchange Server user with MFA enabled, which does not meet the requirement of having a mailbox in Exchange Online. User2 is an on-premises Exchange Server user with MFA disabled, which does not meet the requirement of having MFA enabled. User4 is a Microsoft Exchange Online user, but MFA is disabled for this user, which does not meet the requirement of having MFA enabled.
upvoted 1 times
...
clazmaz
1 year, 11 months ago
Selected Answer: B
It could be B, as per documentation: "Attack simulation training supports on-premises mailboxes, but with reduced reporting functionality. " -> https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/attack-simulation-training-get-started?view=o365-worldwide#what-do-you-need-to-know-before-you-begin
upvoted 2 times
...
TheABC
2 years, 8 months ago
The links posted don't give any requirements, I thought MFA was a requirement and only that, mailbox AI is online only, for me even B woudl be correct, as it seems to not mention MFA/Mailbox type online anywhere!
upvoted 1 times
...
[Removed]
2 years, 11 months ago
Selected Answer: A
I thought it was A but after some research C is correct. It used to be A.
upvoted 1 times
...
arska
3 years ago
Selected Answer: C
Attack Simulator requires Exchange Online. It doesn't require MFA for the users.
upvoted 2 times
...
JCast20
3 years, 3 months ago
Requirements for Attack simulator Your organization has Office 365 Threat Intelligence, with Attack simulator visible in the Security & Compliance Center (go to Threat management > Attack simulator) Your organization's email is hosted in Exchange Online. (Attack simulator is not available for on-premises email servers.) You are an Office 365 global administrator Your organization is using Multi-factor authentication for Office 365 users ANS:A
upvoted 3 times
...
mkoprivnj
3 years, 4 months ago
Selected Answer: C
C is correct!
upvoted 3 times
...
Rstilekar
3 years, 5 months ago
Only supported on EXO. MFA is to create and manage attack campaings.
upvoted 1 times
...
jaketeek
3 years, 7 months ago
It's most definitely C.
upvoted 2 times
...
Nail
3 years, 8 months ago
Definitely C. It is not asking about who is running Attack Simulator but who that admin is running it AGAINST. Those users need EXO.
upvoted 2 times
...
MikeMatt2020
3 years, 8 months ago
ANSWER IS C 1) "MFA is only required for the admin who initiates the Attack Simulator" 2) "Attack Simulator only works on CLOUD-BASED mailboxes" The question clearly asks us to "identify the users against which you can use Attack Simulator". Hate the phrashing but they're asking who are our targeted users? Who are our victims? To be our test dummies, the user mailboxes MUST be cloud based. Regarding MFA, this is only relevant to the admins who CREATE/MANAGE the simulations. https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/attack-simulator?view=o365-worldwide
upvoted 4 times
...
Joshing
3 years, 9 months ago
I don't get the confusion on this one. C is the definitely the correct answer. If it were asking who could manage the Attack Simulation campaign why would it include the mailbox type being on-prem or EXO? As an admin your only requirement to manage the campaigns is to have MFA on your account. You don't need any mailbox what so ever. The question is clearly asking what users you can run the campaign against. As in who will be targeted. In this case it will be C. As the requirement to run the campaign is just to have EXO. MFA is only required on the Admin running the campaign. https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/attack-simulator?view=o365-worldwide#what-do-you-need-to-know-before-you-begin
upvoted 5 times
Joshing
3 years, 9 months ago
Clarity: The requirement is EXO to be targeted for the campaign. MFA is not required.
upvoted 1 times
...
...
ViniciusVidal
4 years ago
For me A is correct (User 3 only), because Attack Simulator only works on cloud-based mailboxes and with MFA enabled.
upvoted 6 times
arunjana
3 years, 11 months ago
C is correct. MFA is only required for the admin who initiates the 'Attack Simulator'
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago