exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 4 question 48 discussion

Actual exam question from Microsoft's MS-500
Question #: 48
Topic #: 4
[All MS-500 Questions]

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 subscription that contains the users shown in the following table.

You discover that all the users in the subscription can access Compliance Manager reports.
The Compliance Manager Reader role is not assigned to any users.
You need to recommend a solution to prevent a user named User5 from accessing the Compliance Manager reports.
Solution: You recommend assigning the Compliance Manager Reader role to User1.
Does this meet the goal?

  • A. Yes
  • B. No
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Rockalm
Highly Voted 4 years ago
Why should editing user1 have any impact on user5's access?
upvoted 21 times
Turdie
3 years, 6 months ago
I.e if *no* assignment for the role...All users can access. If assignment *is* granted to a user account. All user no longer can access (except the one(s) granted the assignment)
upvoted 6 times
...
...
Blue
Highly Voted 4 years, 8 months ago
I tried to replicate this is my environment. But in the newest version of Compliance manager "there is no longer a default Guest access role." Which I Believe this question is refering to. "Now each user must be assigned a role in order to access and work within Compliance Manager." So logic says this series of questions is based off the older set up that allowed all users with an Azure AD account to access Compliance manager as a guest. To me it does not make sense to apply lower permissions to another user to counteract no/derfault permissions because user1 already has contributor access and by default reader access so no changes would be made if you added this permission to this user. Same with adding reader access to User5 themselves either way you either made no change at all or the opposite of what you wanted to achieve. With that logic in mind I would say the both this answer and the following is No. I would love to know what Microsoft believe the correct answer to be on this question as I would love to know. https://docs.microsoft.com/en-us/microsoft-365/compliance/compliance-manager-overview?view=o365-worldwide
upvoted 9 times
VTHAR
4 years, 7 months ago
With this changes, this question series no longer make any sense and thus seem invalid in future exam.
upvoted 5 times
...
...
EM1234
Most Recent 2 years, 2 months ago
Selected Answer: B
Compliance Manager uses a role-based access control (RBAC) permission model. Only users who are assigned a role may access Compliance Manager, and the actions allowed by each user are restricted by role type. https://learn.microsoft.com/en-us/microsoft-365/compliance/compliance-manager-setup?view=o365-worldwide#set-user-permissions-and-assign-roles I cannot find anything showing that setting a role for user1 will disallow user5. I have looked at all the comments and links provided here to support choosing A and none of it really shows documentation for that answer. I am going with B.
upvoted 1 times
...
Dzuljzebari
2 years, 3 months ago
Selected Answer: B
User 5 access is independent from user 1
upvoted 1 times
...
mkoprivnj
3 years, 5 months ago
Selected Answer: B
B --??
upvoted 2 times
...
prats005
4 years, 1 month ago
Role types The table below shows the functions allowed by each role in Compliance Manager. The table also shows how each Azure AD role maps to Compliance Manager roles. Users will need at least the Compliance Manager reader role, or Azure AD global reader role, to access Compliance Manager. ROLE TYPES User can: Compliance Manager role Azure AD role Read but not edit data Compliance Manager Reader Azure AD Global reader, Security reader Edit data Compliance Manager Contribution Compliance Administrator Edit test results Compliance Manager Assessor Compliance Administrator Manage assessments, and template and tenant data Compliance Manager Administration Compliance Administrator, Compliance Data Administrator, Security Administrator Assign users Global Administrator Global Administrator
upvoted 1 times
...
Gamer50
4 years, 3 months ago
The Compliance Manager Contributor, Compliance Manager Assessor, Compliance Manager Administrator all have the Compliance Manager Reader sub role defined under each assignment. Reference : https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/permissions-in-the-security-and-compliance-center?view=o365-worldwide
upvoted 1 times
...
LuisLfr
4 years, 3 months ago
The correct answer is b, because the user 1 assigment It has nothing to do with user 5 assigment
upvoted 3 times
...
Atanas
4 years, 3 months ago
Compliance Manager Reader can read but not edit data. But "read" means "access" as well in my opinion. Most of the questions and answers here are unclear.
upvoted 1 times
...
PattiD
4 years, 4 months ago
https://docs.microsoft.com/en-us/microsoft-365/compliance/meet-data-protection-and-regulatory-reqs-using-microsoft-cloud?view=o365-worldwide
upvoted 1 times
...
Learner7
4 years, 7 months ago
This question is on the default behaviour. See "By default, this role group may not appear to have any members. However, the Security Reader role from Azure Active Directory is assigned to this role group. Therefore, this role group inherits the capabilities and membership of the Security Reader role from Azure Active Directory. To manage permissions centrally, add and remove group members in the Azure Active Directory admin center. For more information, see Administrator role permissions in Azure Active Directory. If you edit this role group in the Security & Compliance Center (membership or roles), those changes apply only to the Security & Compliance Center and not to any other services." https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/permissions-in-the-security-and-compliance-center?view=o365-worldwide So, if no users are assigned with Compliance Manager Security Reader role, in fact by default, the Security Reader role from Azure Active Directory is used and User5 will have this role. If Compliance Manager Security Reader role is explicitly assigned to User1, all other users, including User5 will be spared this role.
upvoted 2 times
ExamStudy68
4 years, 6 months ago
I understand the Security Reader role default and then assigning it kills the default to everyone - where I get confused is it states "Compliance Manager Reader" NOT Security Reader role - are there two different roles are are those interchangeably the same?
upvoted 1 times
...
...
Matthias_privat
4 years, 10 months ago
Answer is No Typo in text: Solution: You recommend assigning the Compliance Manager Reader role to User5.
upvoted 2 times
mehnaz
4 years, 10 months ago
This will give USER5 explicit access to reports but the question is about preventing user5 from accessing the reports. So "assign compliance manager reader role to user1" is correct.
upvoted 2 times
...
SUBZER0
4 years, 8 months ago
And how that typo prevents user 5 from accessing to the reports that is the purpose of the question?
upvoted 1 times
...
Tayta
4 years, 10 months ago
It's not a typo. There is a question identical to this one (part of a series of questions) with the possible answer of "You recommend assigning the Compliance Manager Reader role to User5." And that answer is no. This answer suggesting if you add the role to User1, does that prevent User5 from accessing the reports, the answer is yes due to that fact that there is now a defined reader role assignment to another user account, this the default all user access allowance is now revoked and all users not granted this role can no longer access the reports.
upvoted 7 times
Tayta
4 years, 10 months ago
I.e if *no* assignment for the role...All users can access. If assignment *is* granted to a user account. All user no longer can access (except the one(s) granted the assignment)
upvoted 5 times
...
...
...
BobInTheMoon
5 years, 3 months ago
Answer should be = No. Typo in the question, the solution should be: "Solution: You recommend assigning the Compliance Manager Reader role to User5." This solution does not prevent User5 from accessing the Compliance Manager reports. Notice that the question says "The Compliance Manager Reader role is not assigned to any users." That must mean that all users are accessing the compliance manager reports because they have assigned the "Azure AD Global Reader" permission which also gives read permission to Compliance Manager. I believe the correct solution is the one that mention to remove User5 license.
upvoted 3 times
WoneSix
5 years, 3 months ago
There is no typo in the question. originally, if you had no one in the Compliance Manager Reader group, everyone had access. Adding a single person blocked everyone else.
upvoted 56 times
Fuji_56
5 years, 2 months ago
This makes sense.
upvoted 3 times
...
jwkin
4 years, 11 months ago
Do you have anything to back that up? I cannot find anything on what you just said.
upvoted 3 times
...
jack987
4 years, 11 months ago
I agree with WoneSix. Answer is correct. There is no typo.
upvoted 3 times
...
...
...
krrunal
5 years, 5 months ago
I think in the question where it says "Solution: You recommend assigning the Compliance Manager Reader role to User1." , its a typo.It should be User5 instead of User1 and thats why answer is YES.
upvoted 1 times
Sizz
5 years, 4 months ago
Would make sense; also here's the correct source reference: https://docs.microsoft.com/en-us/microsoft-365/compliance/meet-data-protection-and-regulatory-reqs-using-microsoft-cloud#permissions-and-role-based-access-control
upvoted 1 times
Sizz
5 years, 4 months ago
I expect the key part of the documentation is actually this: "Note that there is no longer a default Guest access role.". This change was made to the docs in October 2019 (from GitHub history for that article). It's also mentioned in a blog: "Once role-based access is enabled, all new users have guest access unless assigned more than that." (Source: https://www.agileit.com/news/understanding-microsoft-compliance-manager/)
upvoted 3 times
...
...
Wallace44
5 years, 3 months ago
I'm trying to prevent User5 from seeing reports. Assuming it is a typo, how does assigning USER5 the Reader Role prevent that? Is it not literally granting him read access?
upvoted 8 times
...
...
nitram
5 years, 6 months ago
The link points to a preview. Preview is not valid and the document does not answer the question. It must be the answer No
upvoted 3 times
...
ChrisBr
5 years, 6 months ago
This makes no sense... How can I prevent User 5 to see a report by changing the role assignment for User 1?
upvoted 3 times
Niro
5 years, 6 months ago
Read reference for explanation
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago