exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 2 question 6 discussion

Actual exam question from Microsoft's MS-500
Question #: 6
Topic #: 2
[All MS-500 Questions]

You have a Microsoft 365 Enterprise E5 subscription.
You use Microsoft Defender for Endpoint.
You plan to use Microsoft 365 Attack simulator.
What is a prerequisite for running Attack simulator?

  • A. Enable multi-factor authentication (MFA).
  • B. Configure Microsoft Defender for Office 365.
  • C. Create a Conditional Access App Control policy for accessing Microsoft 365.
  • D. Integrate Microsoft 365 Threat Intelligence and Microsoft Defender for Endpoint.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
zerrowall
Highly Voted 2 years, 3 months ago
There are two different MS 365 Attack Simulators. The first one was retired. The new version is called "Defender for Office 365 Attack simulation training". Probably some questions are about the previous version and are not appropriate for the new version. For example, I didn't find the requirements for MFA for the new version.
upvoted 6 times
JoeP1
2 years, 1 month ago
I see a number of 2018 references to the attack simulator that list MFA as a requirement. I do not see any for the new version.
upvoted 1 times
...
...
Daniel830
Highly Voted 2 years, 7 months ago
Selected Answer: D
I think It's D. "If your organization has Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2, which includes Threat Investigation and Response capabilities, you can use Attack simulation training in the Microsoft 365 Defender portal" See reference link: https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/attack-simulation-training-get-started?view=o365-worldwide
upvoted 5 times
PhyMac
2 years, 4 months ago
I cannot find any mention of Defender for endpoint in the URL you indicated. Defender for office 365(B) is the correct answer.
upvoted 3 times
...
Tanasi
1 year, 11 months ago
I run this on a tenant and this integration was not done. So it's not D
upvoted 1 times
...
...
Maxx4
Most Recent 1 year, 10 months ago
Selected Answer: D
The correct answer is D. Integrate Microsoft 365 Threat Intelligence and Microsoft Defender for Endpoint. To run the Microsoft 365 Attack simulator, a prerequisite is to integrate Microsoft 365 Threat Intelligence and Microsoft Defender for Endpoint. Microsoft 365 Threat Intelligence provides insights into global attack trends and threat intelligence data, while Microsoft Defender for Endpoint offers endpoint protection and threat detection capabilities. By integrating these two services, you can enhance your security posture and leverage the full functionality of the Attack simulator. The Attack simulator allows you to simulate real-world attack scenarios to assess your organization's security defenses and identify potential vulnerabilities. It helps you evaluate the effectiveness of your security controls, educate users about potential threats, and improve your overall security readiness.
upvoted 1 times
Maxx4
1 year, 10 months ago
Enabling multi-factor authentication (MFA) (option A) is a recommended security practice but not a prerequisite specifically for running the Attack simulator. Configuring Microsoft Defender for Office 365 (option B) and creating a Conditional Access App Control policy for accessing Microsoft 365 (option C) are not prerequisites for running the Attack simulator. These are separate configurations related to securing Office 365 applications and implementing access controls. Therefore, the correct prerequisite for running the Microsoft 365 Attack simulator is option D, integrating Microsoft 365 Threat Intelligence and Microsoft Defender for Endpoint.
upvoted 1 times
...
...
RomanV
2 years ago
Enabling multi-factor authentication (MFA), configuring Microsoft Defender for Office 365, or creating a Conditional Access App Control policy for accessing Microsoft 365 are not prerequisites for running Attack simulator, although they may be important security measures to implement in your environment. Correct answer is D. Integrate Microsoft 365 Threat Intelligence and Microsoft Defender for Endpoint.
upvoted 3 times
Tanasi
1 year, 11 months ago
I was able to run the Attack simulator without the integration. I think the question is just outdated and it probably wanted option A.
upvoted 1 times
...
...
GatesBill
2 years ago
https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/attack-simulation-training-get-started?view=o365-worldwide#what-do-you-need-to-know-before-you-begin - MFA is not listed as a requirement as it was before - You'll use MDO for sure, but what do they mean by "Configuring"? - No policy or whatsoever is needed - Attack Simulation training falls under MDO and not MDE, so acquiring MDE licenses is not necessary at all So guessing "configure" just means utilizing it; the correct answer would be B for the newer version of Attack Simulation...
upvoted 1 times
...
chickenroaster
2 years, 1 month ago
Selected Answer: A
MFA is required.
upvoted 1 times
...
amymay101
2 years, 3 months ago
Selected Answer: B
pre-req should be to config this in Defender for Office 365. Can find any reference to MFA as a pre-req
upvoted 1 times
shouro88
2 years, 2 months ago
An attack simulation is platform independent. What you are saying does not make any sense, please do not guess.
upvoted 2 times
...
...
zerrowall
2 years, 3 months ago
Selected Answer: B
B I think Defender for office 365 is the correct answer
upvoted 1 times
...
Broesweelies
2 years, 6 months ago
Very strange question. It is correct that the admin account doing the simulation needs MFA enabled, but not the users who are targeted by the campaign. But anwer D can also be correct as you dont know which plan the company has. If they have E 5 licenses, then the correct answer is A, but if they have E3 for example, you need to include Threat Investigation and Response capabilities
upvoted 1 times
Acbrownit
2 years, 6 months ago
Question states it has e5 licenses, so that is a moot point.
upvoted 1 times
...
...
Anonymousse
2 years, 6 months ago
Selected Answer: A
https://connectioncloudsupport.zendesk.com/hc/en-us/articles/4403047001881-Introduction-to-Attack-Simulator-in-Microsoft-365. Read step 2!
upvoted 3 times
...
Errr
2 years, 6 months ago
Selected Answer: A
https://github.com/MicrosoftDocs/OfficeDocs-o365seccomp/issues/439
upvoted 2 times
...
Minminweng
2 years, 7 months ago
I ALSO THINK ITS d
upvoted 2 times
...
pete26
2 years, 7 months ago
Selected Answer: A
100% A.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago