exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 4 question 11 discussion

Actual exam question from Microsoft's MS-500
Question #: 11
Topic #: 4
[All MS-500 Questions]

HOTSPOT -
You view Compliance Manager as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: perform an assessment -
You can start working with assessments and taking improvement actions to implement controls and improve your compliance score.
Box 2: shows that actions are required to evaluate compliance
Your compliance score measures your progress in completing recommended actions that help reduce risks around data protection and regulatory standards. It does not express an absolute measure of organizational compliance with regard to a particular standard or regulation.
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/compliance-manager-quickstart?view=o365-worldwide https://docs.microsoft.com/en-us/microsoft-365/compliance/compliance-manager-faq?view=o365-worldwide

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
yaco33
Highly Voted 5 years, 2 months ago
Correction: Assign Action itemshttps://docs.microsoft.com/en-us/microsoft-365/compliance/meet-data-protection-and-regulatory-reqs-using-microsoft-cloud?view=o365-worldwide#assessments-in-compliance-manager -Shows that actions are required to evaluate compliance the compliance manager can't be used to determine if an org is "compliant or not." The Compliance Score does not express an absolute measure of organizational compliance with any particular standard or regulation. It expresses the extent to which you have adopted controls which can reduce the risks to personal data and individual privacy. No service can guarantee that you are compliant with a standard or regulation, and the Compliance Score should not be interpreted as a guarantee in any way.
upvoted 48 times
WMG
3 years, 10 months ago
This is not correct, at least not as of writing this answer. You perform an Assessment. Documentation states: " [your score] is the accumulation of points received for each control assessment that has been marked as Implemented and Tested in the Assessment." Second answer is correct, you bring in your external auditor to verify you are in compliance (=actions required to evaluate compliance) So the answers given are correct.
upvoted 4 times
...
jack987
5 years ago
I agree with Yaco33. Answer: Assign Action Shows that actions are required to evaluate compliance
upvoted 18 times
...
...
yaco33
Highly Voted 5 years, 2 months ago
I think it should be: - Review Actions -Shows that actions are required to evaluate compliance
upvoted 15 times
...
Jonclark
Most Recent 2 years, 4 months ago
The first section really should allow multiple selections, or better yet allow you to put choices in order. If you want to improve your GDPR compliance: 1. Start with your current assessment (that's available and showing in the portal). 2. Review the actions suggested. Is the assessment correct? Does something need to get fixed? 3. Assign the actions. Remediate the controls which did not pass and/or have gaps. *** at this point, your GDPR compliance has actually improved -- good job! *** 4. Run a new assessment. *** at this point, the compliance portal will show your improvement *** The question is about the score you see in the portal and making it higher, so if I can only pick one, I go with my step 4 above -- perform an assessment. If someone did steps 1-3, I expect the score will be higher. Regarding the second section: Tools are great, but auditors make the call on whether you are compliant with regulation. For several reasons, I would never deploy a tool that automatically leaves a discoverable record stating "compliant" or "not compliant" with GDPR.
upvoted 4 times
...
Whatsamattr81
2 years, 11 months ago
Its got to be perform an assessment... Just assigning action items wont improve your score... You have to complete the assessment against the standard you want.
upvoted 3 times
...
mkoprivnj
3 years, 6 months ago
3 & 3 is correct!
upvoted 3 times
...
Rstilekar
3 years, 7 months ago
I agree with Yaco33 and Joshing... Technically neither assigning or reviewing the Improvement Actions will increase the compliance score. It's only when you change the implementation and testing to passed will it improve the score but I guess by Microsoft's documentation you would in an ideal world assign the action for someone to implement. (( the score only changes if these action items are being handled. and you can assign individual items to users in orderfor them to cary out whatever is required for that action, being a simple review or something else. )) An assessment isn't required as the image shows there are already three assessments in progress for GDPR. It even shows they are on the assessments tab in Compliance Manager. GDPR wouldn't show up here if the assessment hadn't been created. So definitely not the correct answer. The second answer is correct though (actions are required to evaluate compliance)
upvoted 6 times
...
Joshing
3 years, 10 months ago
Technical neither assigning or reviewing the Improvement Actions will increase the compliance score. It's only when you change the implementation and testing to passed will it improve the score but I guess by Microsoft's documentation you would in an ideal world assign the action to someone to implement. An assessment isn't required as the image shows there are already three assessments in progress. It even shows they are on the assessments tab in Compliance Manager. GDPR wouldn't show up here if the assessment hadn't been created. So definitely not the correct answer. The second answer is correct though.
upvoted 5 times
...
TimurKazan
4 years, 2 months ago
I would go with "perform an assessment" and "shows that actions are required to evaluate compliance "
upvoted 2 times
...
Sugar123
4 years, 3 months ago
Correct Answers are: Assign action items. See "Improvement actions" section : https://docs.microsoft.com/en-us/microsoft-365/compliance/compliance-manager?view=o365-worldwide Shows that actions are required to evaluate compliance. "If I have a high score, does it mean I’m fully compliant? No. Your compliance score measures your progress in completing recommended actions that help reduce risks around data protection and regulatory standards. It does not express an absolute measure of organizational compliance with regard to a particular standard or regulation. Compliance Manager, and your compliance score, should not be interpreted as a guarantee in any way." https://docs.microsoft.com/en-us/microsoft-365/compliance/compliance-manager-faq?view=o365-worldwide
upvoted 3 times
...
Martyvdb
4 years, 5 months ago
You are likely to find that many of the noted actions are already complete when you review them. You simply need to review them, set an implementation and test date, and earn the points. The noted score does not mean you are not compliant. It means you need to assess the recommended actions and confirm if you have them set or not.
upvoted 1 times
SSK500
4 years, 4 months ago
So the answer should be "perform an assessment"?
upvoted 2 times
...
...
BBR
4 years, 7 months ago
1. To increase the GDPR Compliance Score for Microsoft Office 365, you must: Perform an assessment. "Compliance Manager displays the total score for Office 365 ASSESSMENTS in the upper right-hand corner of the tile. This is the overall total Compliance Score for the Assessment and is the accumulation of points received for each control assessment..." From: https://docs.microsoft.com/en-us/microsoft-365/compliance/meet-data-protection-and-regulatory-reqs-using-microsoft-cloud?view=o365-worldwide#understanding-the-compliance-score
upvoted 8 times
TonySuccess
4 years, 6 months ago
Yep, looks to be another one of those things that has updated and changed recently. You need to 'Add Assessment' this then provides you with the improvement actions to increase the score. I can't even see assign action items or rewview actions anymore when in: https://compliance.microsoft.com/compliancemanager
upvoted 1 times
...
...
Dhanger
4 years, 8 months ago
Organization is non complaint: The Compliance Score is a core component of the way that Compliance Manager helps organizations understand and manage their compliance. The Compliance Score for an assessment is an expression of the company's compliance with a given standard or regulation as a number, where the higher the score (up to the maximum number of points allocated for the Assessment), the better the company's compliance posture. Understanding the compliance scoring methodology in which assessment controls are assigned risk severity values between 1- 10 (low to high), and how completed control assessments add to the total compliance score is crucial to organizations for prioritizing their actions. https://docs.microsoft.com/en-us/microsoft-365/compliance/meet-data-protection-and-regulatory-reqs-using-microsoft-cloud?view=o365-worldwide#understanding-the-compliance-score
upvoted 1 times
...
junkz
4 years, 11 months ago
the score is comprised by many improvement action. some actions require just to be read/reviewed, some require interactive approach and mitigation. but the score only changes if these action items are being handled. and you can assign individual items to users in orderfor them to cary out whatever is required for that action, being a simple review or something else. remember that IT dep is not going to be responsible for the way the data is clasified by business for example. so it cannot and should not even attempt to handle each of the improvement actions that are surfaced in the portal. So assigning items is the right answer here
upvoted 2 times
...
mehnaz
4 years, 11 months ago
How is the organization non-compliant? Do we need to complete certain percentage of "customer managed actions" for being compliant.
upvoted 2 times
mehnaz
4 years, 11 months ago
could be because only 7/63 customer managed actions completed.
upvoted 1 times
...
...
examuser123
5 years ago
This is a tricky one. Last one is correct (does not prove if compliant). Based on the wording it could either be review or perform an assessment. When clicking review for an action item it does give you the option to state it has been implemented which increases your score. Poor wording/answer selection as usual
upvoted 1 times
...
FableFa
5 years ago
Assigning or reviewing action doesn't increase the score ! You need to pass the assessment ... For me answer are : 1. Perform an assessment & 2. Show that actions are required to evaluate compliance.
upvoted 4 times
musiman
4 years, 7 months ago
You are right. You need to do an assessment: Each Assessment includes a total Compliance Score based on the shared responsibility model. Microsoft's implementation and testing of controls for Office 365 contributes a portion of the total possible points associated with a GDPR assessment. As the customer implements and tests each of the customer Actions, the Compliance Score for the Assessment will increase by the value assigned to the control.
upvoted 3 times
...
...
billy22
5 years ago
Yaco is right, check this link: https://docs.microsoft.com/en-us/microsoft-365/compliance/compliance-score-faq?view=o365-worldwide#if-i-have-a-high-score-does-it-mean-im-fully-compliant
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...