Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Microsoft Azure Security Engineer Associate AZ-500 Questions and answers with ValidTests

Exam AZ-500 All Questions
Exam AZ-500 Premium Access

View all detail and faqs for the AZ-500 exam

Viewing page 9 out of 11 pages
Viewing questions 121-135 out of questions
Questions # 121:

You have Azure Resource Manager templates that you use to deploy Azure virtual machines.

You need to disable unused Windows features automatically as instances of the virtual machines are provisioned.

What should you use?

Options:

A.

security policies in Azure Security Center

B.

Azure Logic Apps

C.

an Azure Desired State Configuration (DSC) virtual machine extension

D.

Azure Advisor

Expert Solution
Questions # 122:

You have an Azure subscription.

You need to create and deploy an Azure policy that meets the following requirements:

    When a new virtual machine is deployed, automatically install a custom security extension.

    Trigger an autogenerated remediation task for non-compliant virtual machines to install the extension.

What should you include in the policy? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 122

Options:

Expert Solution
Questions # 123:

You have a network security group (NSG) bound to an Azure subnet.

You run Get-AzureRmNetworkSecurityRuleConfig and receive the output shown in the following exhibit.

Question # 123

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Question # 123

Options:

Expert Solution
Questions # 124:

You have an Azure Sentinel workspace that has the following data connectors:

    Azure Active Directory Identity Protection

    Common Event Format (CEF)

    Azure Firewall

You need to ensure that data is being ingested from each connector.

From the Logs query window, which table should you query for each connector? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 124

Options:

Expert Solution
Questions # 125:

You have an Azure subscription that contains the virtual machines shown in the following table.

Question # 125

You have an Azure Cosmos DB account named cosmos1 configured as shown in the following exhibit.

Question # 125

Question # 125

Options:

Expert Solution
Questions # 126:

You have an Azure Active Directory (Azure AD) tenant that contains a user named Admin1. Admin1 is assigned the Application developer role.

You purchase a cloud app named App1 and register App1 in Azure AD.

Admin1 reports that the option to enable token encryption for App1 is unavailable.

You need to ensure that Admin1 can enable token encryption for App1 in the Azure portal.

What should you do?

Options:

A.

Upload a certificate for App1.

B.

Modify the API permissions of App1.

C.

Add App1 as an enterprise application.

D.

Assign Admin1 the Cloud application administrator role.

Expert Solution
Questions # 127:

You have a Microsoft Entra tenant that contains a user named User1.

You plan to enable passwordless authentication for the tenant.

You need to ensure that User1 can enable the combined registration experience. The solution must use the principle of least privilege.

Which role should you assign to User1?

Options:

A.

Security Administrator

B.

Global Administrator

C.

Privileged Role Administrator

D.

Authentication Administrator

Expert Solution
Questions # 128:

You need to recommend an encryption solution for the planned ExpressRoute implementation. The solution must meet the technical requirements.

Which ExpressRoute circuit should you recommend for each type of encryption? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 128

Options:

Expert Solution
Questions # 129:

You need to implement the planned change for WAF1.

The solution must minimize administrative effort

What should you do?

Options:

A.

Create an Azure policy.

B.

Modify the Azure-managed DRS.

C.

Add a custom rule.

D.

Modify the Bot Manager 1.1 rule set.

Expert Solution
Questions # 130:

You need to implement the planned change for SQLdb1.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

Create a compliance policy.

B.

Configure Microsoft Entra authentication for SQLServer1.

C.

Create a Conditional Access policy.

D.

Configure a user-assigned managed identity for SQLdb1.

E.

Configure Federated client identity for SQLdb1.

Expert Solution
Questions # 131:

You need to configure the AKS1 and ID1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.

Which role should you assign to each identity? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 131

Options:

Expert Solution
Questions # 132:

You need to delegate a user to implement the planned change for Defender for Cloud.

The solution must follow the principle of least privilege.

Which user should you choose?

Options:

A.

Admin1

B.

Admin2

C.

Admin3

D.

Admin4

Expert Solution
Questions # 133:

You implement the planned changes for the key vaults.

To which key vaults can you restore AKV1 backups?

Options:

A.

AKV4only

B.

AKV3 and AKV4 only

C.

AKV4 and AKV5 only

D.

AKV2, AKV3, and AKV4 only

E.

AKV2, AKV3, AKV4, and AKV5

Expert Solution
Questions # 134:

You need to implement the planned change for VM1 to access storage1.

The solution must meet the technical requirements.

What should you do first?

Options:

A.

Configure a system-assigned managed identity on VM1.

B.

Configure federated identity credentials for ID1.

C.

Assign the Storage Blob Data Reader role to storage 1.

D.

Assign ID1 to VM1.

E.

Add a role assignment condition to storage1.

Expert Solution
Questions # 135:

You need to perform the planned changes for OU2 and User1.

Which tools should you use? To answer, drag the appropriate tools to the correct resources. Each tool may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 135

Options:

Expert Solution
Viewing page 9 out of 11 pages
Viewing questions 121-135 out of questions