exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 4 question 35 discussion

Actual exam question from Microsoft's MS-500
Question #: 35
Topic #: 4
[All MS-500 Questions]

HOTSPOT -
You have a Microsoft 365 subscription that includes three users named User1, User2, and User3.
A file named File1.docx is stored in Microsoft OneDrive. An automated process updates File1.docx every minute.
You create an alert policy named Policy1 as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://docs.microsoft.com/en-us/office365/securitycompliance/alert-policies

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jack987
Highly Voted 5 years ago
Answer: Policy1 will be triggered after 45 minutes Policy1 will be triggered within 45 minutes Explanation: 1 user -> 5 mins 60/5 = 12 10th copy, t=50 mins -------------------------------- 3 users -> 10 mins t=0 -> 3 activites t=10 -> 6 activites in total t=20 -> 9 activites in total t=30 -> 12 activites in total -> Alert is triggered
upvoted 63 times
...
DTz
Highly Voted 5 years ago
When you go to create an alert like this, you options say: More than or equal to # activities During the last # minutes The key being "during the last # minutes". So it is assessing the trailing 60 minutes (each minute perhaps). So this pretty much nullifies the given answers of 60 minutes. If it were a report, I could see it happening after 60 minutes, but that would make useless alert wouldn't it! The other thing is that the choices in the first question says will be triggered 'AFTER' # minutes. So clearly is has to be "Policy1 will be triggered after 45 minutes" On the second question, notice on the 20 and 45 it says will be triggered 'WITHIN' # minutes. The 60 says 'AFTER'. We know it could not be within 20 minutes. 10 activities would take 30 minutes, so therefore the answer has to be 'within 45 minutes'. Simple process of elimination.
upvoted 31 times
STFN2019
5 years ago
of course, 100%
upvoted 2 times
...
mehnaz
4 years, 11 months ago
This is perfect. The policy will wait max of 60 seconds(the windows) but if it reaches threshold before that, it will trigger.In both cases we have policy matching threshold before 60 seconds. So 45 seconds is the answer in both cases.
upvoted 3 times
...
...
Ahhallison
Most Recent 2 years, 2 months ago
At first i was on board with the after 45 min and within 45 min crowd, but after consulting with my friend chatGPT, i believe the given answers are correct. "theoretically, if the file is copied 7 times within the last 3 minutes of the first 60-minute window, and then 7 more times within the first 3 minutes of the next 60-minute window, the alert policy may not be triggered. This is because the policy counts the number of file copies made within a 60-minute window, and it may not detect that the threshold has been exceeded if the copies are made at the boundaries of the windows. To avoid this scenario, you may consider adjusting the window size or threshold to ensure that the alert policy covers the necessary timeframe and captures the appropriate number of file copies. You may also want to consider setting up multiple alert policies with different windows and thresholds to provide more granular coverage."
upvoted 1 times
...
Jon06
2 years, 2 months ago
After 45 Within 45 Alert policy settings An alert policy consists of a set of rules and conditions that define the user or admin activity that generates an alert, a list of users who trigger the alert if they perform the activity, and a threshold that defines how many times the activity has to occur before an alert is triggered.
upvoted 1 times
...
Lion007
2 years, 10 months ago
Given answers are correct. You guys are overthinking it, it is NOT a math exam to calculate how many 5mins in 1 hour! The question is testing your knowledge about the Window of 1 hour. Did you know that Alert Policies in Microsoft Purview can be "Scheduled in minutes" which can be set under "During the last X minutes"? In this question, this alert policy will be checked every 1 hour to see if the Threshold was met. If met (More than or equal to 10 activities), then the alert policy will be triggered. So the correct answers will be 60mins for both answers because the threshold was exceeded within the 1 hour. Done.
upvoted 10 times
Lion007
2 years, 10 months ago
This is also a repeated question (in a different style), check out Question #23Topic 5 and ExamTopics explained nicely why the answers given are correct: "The alert triggers AFTER (1) the threshold is met or exceeded and (2) the window has expired. View alerts shows how many times the conditions (filter) was met within the window period."
upvoted 4 times
...
AWpkl
2 years, 5 months ago
this seems convincing but is contrary to logic. If I have an alert threshold, it should count back in time from every new event to determine if a 'within the last x minutes' threshold is broken, then send the alert the moment the count is over the threshold. Aggregation will prevent alert spam at this point as new incidents of 'exceeding count threshold' alerts will be appended to this first one. What kind of sense does it make to run blocks of x minute timers and post an alert at the end of every block where the threshold was exceeded? If this is how it works it is extraordinarily poorly designed, as a burst of activity at the start of a timer block wouldn't produce an alert until the end of the timer, potentially far too late to be helpful.
upvoted 1 times
AWpkl
2 years, 5 months ago
also I can't find this documented anywhere and the correlary question sited as evidence is also gone from examtopics, very frustrating that this can't be confirmed at this point.
upvoted 1 times
...
...
...
mkoprivnj
3 years, 7 months ago
Policy1 will be triggered after 45 minutes Policy1 will be triggered within 45 minutes
upvoted 3 times
...
Rstilekar
3 years, 7 months ago
Given answers are correct. Explanation: 1st 1 user -> 5 mins 60/5 = 12 10th copy, t=50 mins So threshold for policy is met at 50th minute -------------------------------- 2nd 3 users -> 10 mins t=0 -> 3 activites t=10 -> 6 activites in total t=20 -> 9 activites in total t=30 -> 12 activites in total -> Alert is triggered So threshold for policy is met at 30th minute But....The policy is set to trigger alert after 60 minutes if the threshold is met, even if the action does occur within the 60 minutes. This will limit the number of notifications to a reasonable number.
upvoted 3 times
...
The_Temp
3 years, 7 months ago
"Window" has been changed to "during the last", which I think is clearer. I understand that as the policy looks at the last 60 minutes and sees if the number of matched activities meets the threshold. https://docs.microsoft.com/en-us/microsoft-365/compliance/alert-policies?view=o365-worldwide Based on my understanding Policy1 is triggered in both cases after 60 minutes.
upvoted 2 times
...
TimurKazan
4 years, 2 months ago
I believe no policy will be trigered, because: File is not updated, it is copied, which will not trigger alert
upvoted 2 times
...
prats005
4 years, 3 months ago
Answer for question 1 is Policy will be triggered AFTER 45 min Logic: Answer 1 Answer 1 Time User 1 Total Activity 0:00 1 1 0:05 1 2 0:10 1 3 0:15 1 4 0:20 1 5 0:25 1 6 0:30 1 7 0:35 1 8 0:40 1 9 0:45 1 10 Answer for question 2 is Policy will be triggered WITHIN 45 min Logic: Answer 2 Time User 1 User 2 User 3 Total activitty 0:00 1 1 1 3 0:10 1 1 1 6 0:20 1 1 1 9 0:30 1 1 1 12
upvoted 10 times
hw121693
3 years, 11 months ago
Oh I think this answer gives a much clearer explanation than Jack. Simple and easy to understand!
upvoted 2 times
...
...
Sethoo
4 years, 3 months ago
Interesting discussion. To me, the given answers are right. Both will trigger after 60 minutes. The policy is set to trigger after 60 minutes if the threshold is met. In both cases, within the 60 minutes window, they exceeded the threshold and so the trigger will happen at then 60 minutes window. This is more of the time trigger than the number of activity trigger. The question is , within one the one hour has the copying met or exceeded the threshold, if yes, trigger. Otherwise, no trigger.
upvoted 6 times
mroczyslaw
4 years ago
You are wrong. When activity occurs, system check last 60 minutes and sum activites. So, when 10th activity begin, system check if last 60 minutes was 10 times. There was, but time from last (10) to first (1) was 45 minutes, not 60 minutes. So: answer 1: 45 minutes answer 2: within 45 minutes (on 30 minutes there will be 12 times activity)
upvoted 1 times
...
Cbruce
4 years ago
I also agree with the answers provided. It will trigger it after 60 minutes for both because it is setup to alert after 60 minutes if the action does occur within the 60 minutes. This will limit the number of notifications to a reasonable number.
upvoted 2 times
...
...
kiketxu
4 years, 3 months ago
Both answers are wrong to me too. As above folks did the maths.... Policy1 will be triggered after 45 minutes when 10th Policy1 will be triggered within 45 minutes (as there isn't after 30min)
upvoted 3 times
...
Arjanussie
4 years, 3 months ago
docs.microsoft When the alert is triggered - You can configure a setting that defines how often an activity can occur before an alert is triggered. This allows you to set up a policy to generate an alert every time an activity matches the policy conditions, when a certain threshold is exceeded, or when the occurrence of the activity the alert is tracking becomes unusual for your organization. https://docs.microsoft.com/en-us/microsoft-365/compliance/alert-policies?view=o365-worldwide#:~:text=How%20alert%20policies%20work,-Here%27s%20a%20quick&text=A%20user%20performs%20an%20activity,in%20the%20Security%20%26%20Compliance%20Center. so the answers should be wrong
upvoted 1 times
...
PeeyushS
4 years, 4 months ago
Based on the link the image given in Qaestion is "Window = 60 Mins" However once we read the link then it is "During the last 60 Mins" . Thus answer is right there is nothing like Window..this is to create a confusion.
upvoted 2 times
...
itstudy369
4 years, 5 months ago
Tested and both given answers are correct!
upvoted 5 times
...
DLM
4 years, 5 months ago
The key here is Aggregated. It's going to to wait 60 minutes then tell you how many times it hit with a Hit Count. "When events that match the same alert policy occur within the aggregation interval, details about the subsequent event are added to the original alert." https://docs.microsoft.com/en-us/microsoft-365/compliance/alert-policies?view=o365-worldwide
upvoted 4 times
B1G_B3N
4 years, 5 months ago
I agree with you DLM, to add to your thinking the link you supplied also states the following: " If the same event occurs within the aggregation interval, then Microsoft 365 adds details about the new event to the existing alert instead of triggering a new alert. The goal of alert aggregation is to help reduce alert "fatigue" and let you focus and take action on fewer alerts for the same event." From that I take that the trigger could activate multiple times within the alert window but to reduce 'alert fatigue' it will only display 1 alert.
upvoted 2 times
...
Martyvdb
4 years, 5 months ago
It is 45 minutes until the event is triggered based on the activity. Aggregation means that further triggers within the time frame will only be added as hits to the original trigger, and not create new alerts.
upvoted 4 times
...
...
Mary_Yvette
4 years, 6 months ago
Tested this the alert was created even before it hits the 60 minutes.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...