Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Microsoft Azure Security Engineer Associate AZ-500 Questions and answers with ValidTests

Exam AZ-500 All Questions
Exam AZ-500 Premium Access

View all detail and faqs for the AZ-500 exam

Viewing page 5 out of 11 pages
Viewing questions 61-75 out of questions
Questions # 61:

You are evaluating the effect of the application security groups on the network communication between the virtual machines in Sub2.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 61

Options:

Expert Solution
Questions # 62:

You are evaluating the security of VM1, VM2, and VM3 in Sub2.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 62

Options:

Expert Solution
Questions # 63:

You need to ensure that User2 can implement PIM.

What should you do first?

Options:

A.

Assign User2 the Global administrator role.

B.

Configure authentication methods for contoso.com.

C.

Configure the identity secure score for contoso.com.

D.

Enable multi-factor authentication (MFA) for User2.

Expert Solution
Questions # 64:

: 2 HOTSPOT

Which virtual networks in Sub1 can User2 modify and delete in their current state? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 64

Options:

Expert Solution
Questions # 65:

You have an Azure resource group that contains 100 virtual machines.

You have an initiative named Initiative1 that contains multiple policy definitions. Initiative1 is assigned to the resource group.

You need to identify which resources do NOT match the policy definitions.

What should you do?

Options:

A.

From Azure Security Center, view the Regulatory compliance assessment.

B.

From the Policy blade of the Azure Active Directory admin center, select Compliance.

C.

From Azure Security Center, view the Secure Score.

D.

From the Policy blade of the Azure Active Directory admin center, select Assignments.

Expert Solution
Questions # 66:

You have an Azure subscription that is linked to a Microsoft Entra tenant. The tenant uses Microsoft Entra ID Protection.

You have 2,000 users that are each assigned a Microsoft Entra ID P2 license.

You plan to use Azure Monitor to generate an alert when a workload identity that is using leaked credentials is detected.

You need to configure the Diagnostic setting to support the planned alert. The solution must minimize administrative effort.

Which log category should you collect, and to

which destination should you send the logs? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 66

Options:

Expert Solution
Questions # 67:

You plan to use Azure Sentinel to create an analytic rule that will detect suspicious threats and automate responses.

Which components are required for the rule? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 67

Options:

Expert Solution
Questions # 68:

You have an Azure subscription that contains the resources show in the following table.

Question # 68

Both VM1 and VM2 connect to VNET1 and are configured to use NSG1.

You need to ensure that only VM1 and VM2 can access DB1.

What should you do?

Options:

A.

Add the IP address range of VNET1 to the Firewall setting of DB1.

B.

For NSG1, configure a rule that has a service tag.

C.

Create an application security group.

D.

Configure DB1 to allow access from only VNET1.

Expert Solution
Questions # 69:

Your company plans to create separate subscriptions for each department. Each subscription will be

associated to the same Azure Active Directory (Azure AD) tenant.

You need to configure each subscription to have the same role assignments.

What should you use?

Options:

A.

Azure Security Center

B.

Azure Policy

C.

Azure AD Privileged Identity Management (PIM)

D.

Azure Blueprints

Expert Solution
Questions # 70:

You have an Azure subscription that uses Microsoft Defender for Cloud. The subscription contains the Azure Policy definitions shown in the following table.

Question # 70

Which definitions can be assigned as a security policy in Defender for Cloud?

Options:

A.

Policy1 and Policy2 only

B.

Initiative1 and Initiative2 only

C.

Policy1 and Initiative1 only

D.

Policy2 and Initiative2 only

E.

Policy1, Policy2, Initiative1, and Initiative2

Expert Solution
Questions # 71:

You have an Azure App Service web app named App1 as shown in the following exhibit.

Question # 71

Subnet 2 contains a virtual machine named VM1.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic

NOTE: Each correct selection is worth one point.

Question # 71

Options:

Expert Solution
Questions # 72:

You have an Azure subscription that uses Microsoft Defender for Cloud.

Defender for Cloud has the security alerts shown in the following exhibit.

Question # 72

Question # 72

Options:

Expert Solution
Questions # 73:

You have an Azure subscription that contains the resources shown in the following table.

Question # 73

SQL1 has the following configurations:

• Auditing: Enabled

• Audit log destination: storage1, Workspace1

DB1 has the following configurations:

• Auditing: Enabled

• Audit log destination: storage2

DB2 has auditing disabled.

Where are the audit logs for DB1 and DB2 stored? To answer, select the appropriate options in the answer area

NOTE: Each correct selection is worth one point.

Question # 73

Options:

Expert Solution
Questions # 74:

You have an Azure subscription named Sub1 that contains the Azure key vaults shown in the following table:

Question # 74

In Sub1, you create a virtual machine that has the following configurations:

    Name: VM1

    Size: DS2v2

    Resource group: RG1

    Region: West Europe

    Operating system: Windows Server 2022

You plan to enable Azure Disk Encryption on VM1.

In which key vaults can you store the encryption key for VM1?

Options:

A.

Vault1 or Vault3 only

B.

Vault1, Vault2, Vault3, or Vault4

C.

Vault1 only

D.

Vault1 or Vault2 only

Expert Solution
Questions # 75:

You have an Azure subscription that uses Microsoft Defender.

You enable the CIS Microsoft Azure Foundations Benchmark v2.0.0 built-in to the subscription.

You need to ensure that when users attempt to assign custom role-based access control (RBAC) roles, they receive a custom error message that includes a link to an internal website. The solution must minimize the impact on other policies.

What should you configure?

Options:

A.

the effect of the policy

B.

the remediation task of the policy

C.

a policy-specific non-compliance message

D.

the default non-compliance message of the built-in

Expert Solution
Viewing page 5 out of 11 pages
Viewing questions 61-75 out of questions