ExamGecko
Home / Microsoft / AZ-500 / List of questions
Ask Question

Microsoft AZ-500 Practice Test - Questions Answers, Page 24

List of questions

Question 231

Report
Export
Collapse

HOTSPOT

You have the hierarchy of Azure resources shown in the following exhibit.

Microsoft AZ-500 image Question 34 87422 10022024015441000000

You create the Azure Blueprints definitions shown in the following table.

Microsoft AZ-500 image Question 34 87422 10022024015441000000

To which objects can you assign Blueprint1 and Blueprint2? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft AZ-500 image Question 231 87422 10022024015441000
Correct answer: Microsoft AZ-500 image answer Question 231 87422 10022024015441000

Explanation:

Blueprints can only be assigned to subscriptions.

asked 02/10/2024
Fatawu Musah
31 questions

Question 232

Report
Export
Collapse

You have an Azure subscription that contains the Azure Log Analytics workspaces shown in the following table.

Microsoft AZ-500 image Question 35 87423 10022024015441000000

You create the virtual machines shown in the following table.

Microsoft AZ-500 image Question 35 87423 10022024015441000000

You plan to use Azure Sentinel to monitor Windows Defender Firewall on the virtual machines.

Which virtual machines you can connect to Azure Sentinel?

VM1 only
VM1 only
VM1 and VM3 only
VM1 and VM3 only
VM1, VM2, VM3, and VM4
VM1, VM2, VM3, and VM4
VM1 and VM2 only
VM1 and VM2 only
Suggested answer: C

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/connect-windows-firewall

asked 02/10/2024
Peter Avino
26 questions

Question 233

Report
Export
Collapse

HOTSPOT

You have an Azure subscription that contains a user named Admin1 and a resource group named RG1.

In Azure Monitor, you create the alert rules shown in the following table.

Microsoft AZ-500 image Question 36 87424 10022024015441000000

Admin1 performs the following actions on RG1:

Adds a virtual network named VNET1

Adds a Delete lock named Lock1

Which rules will trigger an alert as a result of the actions of Admin1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft AZ-500 image Question 233 87424 10022024015441000
Correct answer: Microsoft AZ-500 image answer Question 233 87424 10022024015441000
asked 02/10/2024
Omer Awad
29 questions

Question 234

Report
Export
Collapse

You have an Azure subscription that contains 100 virtual machines and has Azure Security Center Standard tier enabled.

You plan to perform a vulnerability scan of each virtual machine.

You need to deploy the vulnerability scanner extension to the virtual machines by using an Azure Resource Manager template.

Which two values should you specify in the code to automate the deployment of the extension to the virtual machines? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

the user-assigned managed identity
the user-assigned managed identity
the workspace ID
the workspace ID
the Azure Active Directory (Azure AD) ID
the Azure Active Directory (Azure AD) ID
the Key Vault managed storage account key
the Key Vault managed storage account key
the system-assigned managed identity
the system-assigned managed identity
the primary shared key
the primary shared key
Suggested answer: A, C
asked 02/10/2024
Aleksandar Jovasevic
45 questions

Question 235

Report
Export
Collapse

You have an Azure subscription that contains a user named Admin1 and a virtual machine named VM1. VM1 runs Windows Server 2019 and was deployed by using an Azure Resource Manager template. VM1 is the member of a backend pool of a public Azure Basic Load Balancer.

Admin1 reports that VM1 is listed as Unsupported on the Just in time VM access blade of Azure Security Center.

You need to ensure that Admin1 can enable just in time (JIT) VM access for VM1.

What should you do?

Create and configure a network security group (NSG).
Create and configure a network security group (NSG).
Create and configure an additional public IP address for VM1.
Create and configure an additional public IP address for VM1.
Replace the Basic Load Balancer with an Azure Standard Load Balancer.
Replace the Basic Load Balancer with an Azure Standard Load Balancer.
Assign an Azure Active Directory Premium Plan 1 license to Admin1.
Assign an Azure Active Directory Premium Plan 1 license to Admin1.
Suggested answer: A

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/security-center/security-center-just-in-time?tabs=jit-config-asc%2Cjit-request-asc

asked 02/10/2024
Venkata Nandyala
35 questions

Question 236

Report
Export
Collapse

HOTSPOT

You have an Azure Sentinel workspace that contains an Azure Active Directory (Azure AD) connector, an Azure Log Analytics query named Query1 and a playbook named Playbook1.

Query1 returns a subset of security events generated by Azure AD.

You plan to create an Azure Sentinel analytic rule based on Query1 that will trigger Playbook1.

You need to ensure that you can add Playbook1 to the new rule.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft AZ-500 image Question 236 87427 10022024015441000
Correct answer: Microsoft AZ-500 image answer Question 236 87427 10022024015441000

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom

https://docs.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook

asked 02/10/2024
Rajeev Parameswaran
38 questions

Question 237

Report
Export
Collapse

HOTSPOT

You have an Azure subscription that contains the resources shown in the following table.

Microsoft AZ-500 image Question 40 87428 10022024015441000000

An IP address of 10.1.0.4 is assigned to VM5. VM5 does not have a public IP address.

VM5 has just in time (JIT) VM access configured as shown in the following exhibit.

Microsoft AZ-500 image Question 40 87428 10022024015441000000

You enable JIT VM access for VM5.

NSG1 has the inbound rules shown in the following exhibit.

Microsoft AZ-500 image Question 40 87428 10022024015441000000

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.


Microsoft AZ-500 image Question 237 87428 10022024015441000
Correct answer: Microsoft AZ-500 image answer Question 237 87428 10022024015441000
asked 02/10/2024
Akshi Raj
42 questions

Question 238

Report
Export
Collapse

You have an Azure Active Directory (Azure AD) tenant and a root management group.

You create 10 Azure subscriptions and add the subscriptions to the root management group.

You need to create an Azure Blueprints definition that will be stored in the root management group.

What should you do first?

Modify the role-based access control (RBAC) role assignments for the root management group.
Modify the role-based access control (RBAC) role assignments for the root management group.
Add an Azure Policy definition to the root management group.
Add an Azure Policy definition to the root management group.
Create a user assigned identity.
Create a user assigned identity.
Create a service principal.
Create a service principal.
Suggested answer: A

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin

asked 02/10/2024
Ruben Munilla Hernandez
42 questions

Question 239

Report
Export
Collapse

HOTSPOT

You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.

Microsoft AZ-500 image Question 42 87430 10022024015441000000

Contoso.com contains a group naming policy. The policy has a custom blocked word list rule that includes the word Contoso.

Which users can create a group named Contoso Sales in contoso.com? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft AZ-500 image Question 239 87430 10022024015441000
Correct answer: Microsoft AZ-500 image answer Question 239 87430 10022024015441000

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/enterprise-users/groups-naming-policy

asked 02/10/2024
Pranoy Bej
33 questions

Question 240

Report
Export
Collapse

DRAG DROP

You have five Azure subscriptions linked to a single Azure Active Directory (Azure AD) tenant.

You create an Azure Policy initiative named SecurityPolicyInitiative1.

You identify which standard role assignments must be configured on all new resource groups.

You need to enforce SecurityPolicyInitiative1 and the role assignments when a new resource group is created.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.


Microsoft AZ-500 image Question 240 87431 10022024015441000
Correct answer: Microsoft AZ-500 image answer Question 240 87431 10022024015441000

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/governance/blueprints/create-blueprint-portal

https://docs.microsoft.com/en-us/azure/azure-australia/azure-policy

asked 02/10/2024
Sai Janani Ravishankar
35 questions
Total 442 questions
Go to page: of 45
Search

Related questions