ExamGecko
Home Home / Microsoft / AZ-500

Microsoft AZ-500 Practice Test - Questions Answers, Page 26

Question list
Search
Search

List of questions

Search

Related questions











You have an Azure subscription named Subscription1 that contains the resources shown in the following table.

You need to identify which initiatives and policies you can add to Subscription1 by using Azure Security Center.

What should you identify?

A.
Policy1 and Policy2 only
A.
Policy1 and Policy2 only
Answers
B.
Initiative1 only
B.
Initiative1 only
Answers
C.
Initiative1 and Initiative2 only
C.
Initiative1 and Initiative2 only
Answers
D.
Initiative1, Initiative2, Policy1, and Policy2
D.
Initiative1, Initiative2, Policy1, and Policy2
Answers
Suggested answer: D

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/security-center/custom-security-policies

You have an Azure subscription named Sub1.

In Azure Security Center, you have a workflow automation named WF1. WF1 is configured to send an email message to a user named User1.

You need to modify WF1 to send email messages to a distribution group named Alerts.

What should you use to modify WF1?

A.
Azure Application Insights
A.
Azure Application Insights
Answers
B.
Azure Monitor
B.
Azure Monitor
Answers
C.
Azure Logic Apps Designer
C.
Azure Logic Apps Designer
Answers
D.
Azure DevOps
D.
Azure DevOps
Answers
Suggested answer: C

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/security-center/workflow-automation

https://docs.microsoft.com/en-us/learn/modules/resolve-threats-with-azure-security-center/6-exercise-configure-playbook

You have an Azure resource group that contains 100 virtual machines.

You have an initiative named Initiative1 that contains multiple policy definitions. Initiative1 is assigned to the resource group.

You need to identify which resources do NOT match the policy definitions.

What should you do?

A.
From Azure Security Center, view the Regulatory compliance assessment.
A.
From Azure Security Center, view the Regulatory compliance assessment.
Answers
B.
From the Policy blade of the Azure Active Directory admin center, select Compliance.
B.
From the Policy blade of the Azure Active Directory admin center, select Compliance.
Answers
C.
From Azure Security Center, view the Secure Score.
C.
From Azure Security Center, view the Secure Score.
Answers
D.
From the Policy blade of the Azure Active Directory admin center, select Assignments.
D.
From the Policy blade of the Azure Active Directory admin center, select Assignments.
Answers
Suggested answer: A

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/governance/policy/how-to/get-compliance-data#portal

You have an Azure subscription named Subscription1.

You need to view which security settings are assigned to Subscription1 by default.

Which Azure policy or initiative definition should you review?

A.
the Audit diagnostic setting policy definition
A.
the Audit diagnostic setting policy definition
Answers
B.
the Enable Monitoring in Azure Security Center initiative definition
B.
the Enable Monitoring in Azure Security Center initiative definition
Answers
C.
the Enable Azure Monitor for VMs initiative definition
C.
the Enable Azure Monitor for VMs initiative definition
Answers
D.
the Azure Monitor solution ‘Security and Audit’ must be deployed policy definition
D.
the Azure Monitor solution ‘Security and Audit’ must be deployed policy definition
Answers
Suggested answer: B

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/security-center/tutorial-security-policy

https://docs.microsoft.com/en-us/azure/security-center/policy-reference

DRAG DROP

You have an Azure Sentinel workspace that has an Azure Active Directory (Azure AD) data connector.

You are threat hunting suspicious traffic from a specific IP address.

You need to annotate an intermediate event stored in the workspace and be able to reference the IP address when navigating through the investigation graph.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.


Question 255
Correct answer: Question 255

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/bookmarks

HOTSPOT

You have 20 Azure subscriptions and a security group named Group1. The subscriptions are children of the root management group.

Each subscription contains a resource group named RG1.

You need to ensure that for each subscription RG1 meets the following requirements:

The members of Group1 are assigned the Owner role.

The modification of permissions to RG1 is prevented.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 256
Correct answer: Question 256

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You use Azure Security Center for the centralized policy management of three Azure subscriptions.

You use several policy definitions to manage the security of the subscriptions.

You need to deploy the policy definitions as a group to all three subscriptions.

Solution: You create a policy initiative and an assignment that is scoped to the Tenant Root Group management group.

Does this meet the goal?

A.
Yes
A.
Yes
Answers
B.
No
B.
No
Answers
Suggested answer: A

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/governance/policy/overview

https://4sysops.com/archives/apply-governance-policy-to-multiple-azure-subscriptions-with-management-groups/

You have an Azure environment.

You need to identify any Azure configurations and workloads that are non-compliant with ISO 27001 standards.

What should you use?

A.
Azure Sentinel
A.
Azure Sentinel
Answers
B.
Azure Active Directory (Azure AD) Identity Protection
B.
Azure Active Directory (Azure AD) Identity Protection
Answers
C.
Azure Security Center
C.
Azure Security Center
Answers
D.
Azure Advanced Threat Protection (ATP)
D.
Azure Advanced Threat Protection (ATP)
Answers
Suggested answer: C

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/security-center/security-center-compliance-dashboard

HOTSPOT

On Monday, you configure an email notification in Azure Security Center to email notifications to [email protected].

On Tuesday, Security Center generates the security alerts shown in the following table.

How many email notifications will [email protected] receive on Tuesday? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 259
Correct answer: Question 259

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/security-center/security-center-provide-security-contact-details

You are troubleshooting a security issue for an Azure Storage account.

You enable Azure Storage Analytics logs and archive it to a storage account.

What should you use to retrieve the diagnostics logs?

A.
Azure Monitor
A.
Azure Monitor
Answers
B.
SQL query editor in Azure
B.
SQL query editor in Azure
Answers
C.
File Explorer in Windows
C.
File Explorer in Windows
Answers
D.
Azure Storage Explorer
D.
Azure Storage Explorer
Answers
Suggested answer: D

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/storage/blobs/monitor-blob-storage?tabs=azure-portal

Total 439 questions
Go to page: of 44