ExamGecko
Home Home / Microsoft / AZ-500

Microsoft AZ-500 Practice Test - Questions Answers, Page 25

Question list
Search
Search

List of questions

Search

Related questions











You have three on-premises servers named Server1, Server2, and Server3 that run Windows Server 2019. Server1 and Server2 and located on the Internal network. Server3 is located on the premises network. All servers have access to Azure.

From Azure Sentinel, you install a Windows firewall data connector.

You need to collect Microsoft Defender Firewall data from the servers for Azure Sentinel.

What should you do?

A.
Create an event subscription from Server1, Server2, and Server3.
A.
Create an event subscription from Server1, Server2, and Server3.
Answers
B.
Install the On-premises data gateway on each server.
B.
Install the On-premises data gateway on each server.
Answers
C.
Install the Microsoft Monitoring Agent on each server.
C.
Install the Microsoft Monitoring Agent on each server.
Answers
D.
Install the Microsoft Monitoring Agent on Server1 and Server2. Install the On-premises data gateway on Server3.
D.
Install the Microsoft Monitoring Agent on Server1 and Server2. Install the On-premises data gateway on Server3.
Answers
Suggested answer: C

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/connect-windows-firewall

You have an Azure subscription that contains several Azure SQL databases and an Azure Sentinel workspace.

You need to create a saved query in the workspace to find events reported by Azure Defender for SQL.

What should you do?

A.
From Azure CLI run the Get-AzOperationalInsightsworkspace cmdlet.
A.
From Azure CLI run the Get-AzOperationalInsightsworkspace cmdlet.
Answers
B.
From the Azure SQL Database query editor, create a Transact-SQL query.
B.
From the Azure SQL Database query editor, create a Transact-SQL query.
Answers
C.
From the Azure Sentinel workspace, create a Kusto Query Language query.
C.
From the Azure Sentinel workspace, create a Kusto Query Language query.
Answers
D.
From Microsoft SQL Server Management Studio (SSMS), create a Transact-SQL query.
D.
From Microsoft SQL Server Management Studio (SSMS), create a Transact-SQL query.
Answers
Suggested answer: C

HOTSPOT

You plan to use Azure Sentinel to create an analytic rule that will detect suspicious threats and automate responses.

Which components are required for the rule? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 243
Correct answer: Question 243

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom

https://docs.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook

You are collecting events from Azure virtual machines to an Azure Log Analytics workspace.

You plan to create alerts based on the collected events.

You need to identify which Azure services can be used to create the alerts.

Which two services should you identify? Each correct answer presents a complete solution

NOTE: Each correct selection is worth one point.

A.
Azure Monitor
A.
Azure Monitor
Answers
B.
Azure Security Center
B.
Azure Security Center
Answers
C.
Azure Analysis Services
C.
Azure Analysis Services
Answers
D.
Azure Sentinel
D.
Azure Sentinel
Answers
E.
Azure Advisor
E.
Azure Advisor
Answers
Suggested answer: A, D

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You use Azure Security Center for the centralized policy management of three Azure subscriptions.

You use several policy definitions to manage the security of the subscriptions.

You need to deploy the policy definitions as a group to all three subscriptions.

Solution: You create an initiative and an assignment that is scoped to a management group.

Does this meet the goal?

A.
Yes
A.
Yes
Answers
B.
No
B.
No
Answers
Suggested answer: A

Explanation:

References:

https://docs.microsoft.com/en-us/azure/governance/policy/overview

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You use Azure Security Center for the centralized policy management of three Azure subscriptions.

You use several policy definitions to manage the security of the subscriptions.

You need to deploy the policy definitions as a group to all three subscriptions.

Solution: You create a policy initiative and assignments that are scoped to resource groups.

Does this meet the goal?

A.
Yes
A.
Yes
Answers
B.
No
B.
No
Answers
Suggested answer: B

Explanation:

Instead use a management group.

Management groups in Microsoft Azure solve the problem of needing to impose governance policy on more than one Azure subscription simultaneously.

Reference:

https://4sysops.com/archives/apply-governance-policy-to-multiple-azure-subscriptions-with-management-groups/

Note: This question-is part of a series of questions that present the same scenario. Each question-in the series contains a unique solution that might meet the stated goals. Some question-sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question-in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You use Azure Security Center for the centralized policy management of three Azure subscriptions.

You use several policy definitions to manage the security of the subscriptions.

You need to deploy the policy definitions as a group to all three subscriptions.

Solution: You create a policy definition and assignments that are scoped to resource groups.

Does this meet the goal?

A.
Yes
A.
Yes
Answers
B.
No
B.
No
Answers
Suggested answer: B

Explanation:

References: https://4sysops.com/archives/apply-governance-policy-to-multiple-azure-subscriptions-with-management-groups/

Note: This question-is part of a series of questions that present the same scenario. Each question-in the series contains a unique solution that might meet the stated goals. Some question-sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question-in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You use Azure Security Center for the centralized policy management of three Azure subscriptions.

You use several policy definitions to manage the security of the subscriptions.

You need to deploy the policy definitions as a group to all three subscriptions.

Solution: You create a resource graph and an assignment that is scoped to a management group.

Does this meet the goal?

A.
Yes
A.
Yes
Answers
B.
No
B.
No
Answers
Suggested answer: B

Explanation:

Management groups in Microsoft Azure solve the problem of needing to impose governance policy on more than one Azure subscription simultaneously. However, you need to use an initiative, not a resource graph to bundle the policy definitions into a group that can be applied to the management group.

References:

https://4sysops.com/archives/apply-governance-policy-to-multiple-azure-subscriptions-with-management-groups/

HOTSPOT

You have an Azure subscription that contains an Azure Sentinel workspace.

Azure Sentinel is configured to ingest logs from several Azure workloads. A third-party service management platform is used to manage incidents.

You need to identify which Azure Sentinel components to configure to meet the following requirements:

When Azure Sentinel identifies a threat, an incident must be created.

A ticket must be logged in the service management platform when an incident is created in Azure Sentinel.

Which component should you identify for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 249
Correct answer: Question 249

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/create-incidents-from-alerts

https://docs.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook

HOTSPOT

You have an Azure subscription.

You need to create and deploy an Azure policy that meets the following requirements:

When a new virtual machine is deployed, automatically install a custom security extension.

Trigger an autogenerated remediation task for non-compliant virtual machines to install the extension. What should you include in the policy? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 250
Correct answer: Question 250

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/governance/policy/how-to/remediate-resources

Total 439 questions
Go to page: of 44