Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Microsoft Azure Security Engineer Associate AZ-500 Questions and answers with ValidTests

Exam AZ-500 All Questions
Exam AZ-500 Premium Access

View all detail and faqs for the AZ-500 exam

Viewing page 8 out of 11 pages
Viewing questions 106-120 out of questions
Questions # 106:

You have an Azure subscription named Sub1 that contains the resource groups shown in the following table.

Question # 106

You create the Azure Policy definition shown in the following exhibit.

Question # 106

You assign the policy to Sub1.

You plan to create the resources shown in the following table.

Question # 106

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 106

Options:

Expert Solution
Questions # 107:

You have a Microsoft Entra tenant that contains the users shown in the following table.

Question # 107

AII the users have devices that contain certificates issued by a certification authority (CA) named ContosoCA. You create a Conditional Access policy that has the following settings:

• Name: CAPoltcy1

• Assignments

o Users and groups: Group1

o Target resources

* Include: All cloud apps

o Access controls

* Grant access: Require multi-factor authentication

o Enable policy: On

You enable and target certificate-based authentication as shown in the Enable and Target exhibit. (Click the Enable and Target tab.)

Question # 107

You configure certificate-based authentication as shown in the Configure exhibit. (Click the Configure tab.)

Question # 107

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Question # 107

Options:

Expert Solution
Questions # 108:

You have an Azure subscription that contains the resources show in the following table.

Question # 108

Both VM1 and VM2 connect to VNET1 and are configured to use NSG1.

You need to ensure that only VM1 and VM2 can access DB1.

What should you do?

Options:

A.

Add the IP address range of VNET1 to the Firewall setting of DB1.

B.

For NSG1, configure a rule that has a service tag.

C.

Create an application security group.

D.

Configure DB1 to allow access from only VNET1.

Expert Solution
Questions # 109:

You have an Azure key vault named sk2311 configured as shown in the following exhibit.

Question # 109

Sk2311 contains the items shown in the following table.

Question # 109

In sk2311, the following events occur in sequence:

• Item1 is deleted.

• Item2 and Policy1 ate deleted.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 109

Options:

Expert Solution
Questions # 110:

You have an Azure Storage account named storage1 and an Azure virtual machine named VM1. VM1 has a premium SSD managed disk.

You need to enable Azure Disk Encryption for VM1.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange then in the correct order.

Question # 110

Options:

Expert Solution
Questions # 111:

You have an Azure subscription that uses Microsoft Defender.

You enable the CIS Microsoft Azure Foundations Benchmark v2.0.0 built-in to the subscription.

You need to ensure that when users attempt to assign custom role-based access control (RBAC) roles, they receive a custom error message that includes a link to an internal website. The solution must minimize the impact on other policies.

What should you configure?

Options:

A.

the effect of the policy

B.

the remediation task of the policy

C.

a policy-specific non-compliance message

D.

the default non-compliance message of the built-in

Expert Solution
Questions # 112:

You have an Azure subscription that contains the resources shown in the following table.

Question # 112

You need to ensure that ServerAdmins can perform the following tasks:

    Create virtual machines in RG1 only.

    Connect the virtual machines to the existing virtual networks in RG2 only.

The solution must use the principle of least privilege.

Which two role-based access control (RBAC) roles should you assign to ServerAdmins? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

a custom RBAC role for RG2

B.

the Network Contributor role for RG2

C.

the Contributor role for the subscription

D.

a custom RBAC role for the subscription

E.

the Network Contributor role for RG1

F.

the Virtual Machine Contributor role for RG1

Expert Solution
Questions # 113:

You create resources in an Azure subscription as shown in the following table.

Question # 113

VNET1 contains two subnets named Subnet1 and Subnet2. Subnet1 has a network ID of 10.0.0.0/24. Subnet2 has a network ID of 10.1.1.0/24.

Contoso1901 is configured as shown in the exhibit. (Click the Exhibit tab.)

Question # 113

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 113

Options:

Expert Solution
Questions # 114:

You have an Azure subscription that contains an Azure key vault named Vault1.

In Vault1, you create a secret named Secret1.

An application developer registers an application in Azure Active Directory (Azure AD).

You need to ensure that the application can use Secret1.

What should you do?

Options:

A.

In Azure AD, create a role.

B.

In Azure Key Vault, create a key.

C.

In Azure Key Vault, create an access policy.

D.

In Azure AD, enable Azure AD Application Proxy.

Expert Solution
Questions # 115:

You onboard Azure Sentinel. You connect Azure Sentinel to Azure Security Center.

You need to automate the mitigation of incidents in Azure Sentinel. The solution must minimize administrative effort.

What should you create?

Options:

A.

an alert rule

B.

a playbook

C.

a function app

D.

a runbook

Expert Solution
Questions # 116:

You have an Azure subscription that uses Microsoft Defender for Cloud.

You plan to use the Secure Score Over Time workbook.

You need to configure the Continuous export settings for the Defender for Cloud data.

Which two settings should you configure? To answer, select the appropriate settings in the answer area.

NOTE: Each correct selection is worth one point.

Question # 116

Options:

Expert Solution
Questions # 117:

You are configuring network connectivity for two Azure virtual networks named VNET1 and VNET2.

You need to implement VPN gateways for the virtual networks to meet the following requirements:

* VNET1 must have six site-to-site connections that use BGP.

* VNET2 must have 12 site-to-site connections that use BGP.

* Costs must be minimized.

Which VPN gateway SKI) should you use for each virtual network? To answer, drag the appropriate SKUs to the correct networks. Each SKU may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point

Question # 117

Options:

Expert Solution
Questions # 118:

You have an Azure Kubernetes Service (AKS) cluster that will connect to an Azure Container Registry.

You need to use the automatically generated service principal for the AKS cluster to authenticate to the Azure Container Registry.

What should you create?

Options:

A.

an Azure AD user

B.

a secret in Azure Key Vault

C.

an Azure AD group

D.

a role assignment

Expert Solution
Questions # 119:

You have an Azure subscription and the computers shown in the following table.

Question # 119

You need to perform a vulnerability scan of the computers by using Microsoft Defender for Cloud. Which computers can you scan?

Options:

A.

VM1 only

B.

VM1 and VM2 only

C.

Server1 and VMSS1.0 only

D.

VM1, VM2, and Server1 only

E.

VM1, VM2, Server1, and VMSS1.0

Expert Solution
Questions # 120:

You have an Azure Active Directory (Azure AD) tenant that contains a user named User1.

You need to ensure that User1 can create and manage administrative units. The solution must use the principle of least privilege.

Which role should you assign to User1?

Options:

A.

Privileged role administrator

B.

Helpdesk administrator

C.

Global administrator

D.

Security administrator

Expert Solution
Viewing page 8 out of 11 pages
Viewing questions 106-120 out of questions