ExamGecko
Home Home / Microsoft / AZ-500

Microsoft AZ-500 Practice Test - Questions Answers, Page 27

Question list
Search
Search

List of questions

Search

Related questions











You have an Azure subscription that contains the resources shown in the following table.

You plan to enable Azure Defender for the subscription.

Which resources can be protected by using Azure Defender?

A.
VM1, VNET1, storage1, and Vault1
A.
VM1, VNET1, storage1, and Vault1
Answers
B.
VM1, VNET1, and storage1 only
B.
VM1, VNET1, and storage1 only
Answers
C.
VM1, storage1, and Vault1 only
C.
VM1, storage1, and Vault1 only
Answers
D.
VM1 and VNET1 only
D.
VM1 and VNET1 only
Answers
E.
VM1 and storage1 only
E.
VM1 and storage1 only
Answers
Suggested answer: A

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/security-center/azure-defender

DRAG DROP

You have an Azure subscription that contains the following resources:

A network virtual appliance (NVA) that runs non-Microsoft firewall software and routes all outbound traffic from the virtual machines to the internet An Azure function that contains a script to manage the firewall rules of the NVA

Azure Security Center standard tier enabled for all virtual machines

An Azure Sentinel workspace

30 virtual machines

You need to ensure that when a high-priority alert is generated in Security Center for a virtual machine, an incident is created in Azure Sentinel and then a script is initiated to configure a firewall rule for the NVA.

How should you configure Azure Sentinel to meet the requirements? To answer, drag the appropriate components to the correct requirements. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.


Question 262
Correct answer: Question 262

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/create-incidents-from-alerts

https://docs.microsoft.com/en-us/azure/sentinel/connect-azure-security-center

You have an Azure subscription that contains a resource group named RG1 and a security group named ServerAdmins. RG1 contains 10 virtual machines, a virtual network named VNET1, and a network security group (NSG) named NSG1. ServerAdmins can access the virtual machines by using RDP.

You need to ensure that NSG1 only allows RDP connections to the virtual machines for a maximum of 60 minutes when a member of ServerAdmins requests access.

What should you configure?

A.
an Azure policy assigned to RG1
A.
an Azure policy assigned to RG1
Answers
B.
a just in time (JIT) VM access policy in Azure Security Center
B.
a just in time (JIT) VM access policy in Azure Security Center
Answers
C.
an Azure Active Directory (Azure AD) Privileged Identity Management (PIM) role assignment
C.
an Azure Active Directory (Azure AD) Privileged Identity Management (PIM) role assignment
Answers
D.
an Azure Bastion host on VNET1
D.
an Azure Bastion host on VNET1
Answers
Suggested answer: B

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/security-center/just-in-time-explained

HOTSPOT

You have an Azure subscription named Subscription1 that contains the resources shown in the following table.

You have an Azure subscription named Subscription2 that contains the following resources:

An Azure Sentinel workspace

An Azure Event Grid instance

You need to ingest the CEF messages from the NVAs to Azure Sentinel.

What should you configure for each subscription? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 264
Correct answer: Question 264

HOTSPOT

You have an Azure subscription named Subscription1 that contains a resource group named RG1 and a user named User1. User1 is assigned the Owner role for RG1.

You create an Azure Blueprints definition named Blueprint1 that includes a resource group named RG2 as shown in the following exhibit.

You assign Blueprint1 to Subscription1 by using the following settings:

Lock assignment: Read Only

Managed Identity: System assigned

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.


Question 265
Correct answer: Question 265

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/governance/blueprints/concepts/resource-locking

You have an Azure Sentinel deployment.

You need to create a scheduled query rule named Rule1.

What should you use to define the query rule logic for Rule1?

A.
a Transact-SQL statement
A.
a Transact-SQL statement
Answers
B.
a JSON definition
B.
a JSON definition
Answers
C.
GraphQL
C.
GraphQL
Answers
D.
a Kusto query
D.
a Kusto query
Answers
Suggested answer: D

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-custom

You have an Azure subscription named Subscription1 that contains a resource group named RG1 and the users shown in the following table.

You perform the following tasks:

Assign User1 the Network Contributor role for Subscription1.

Assign User2 the Contributor role for RG1.

To Subscription1 and RG1, you assign the following policy definition: External accounts with write permissions should be removed from your subscription.

What is the Compliance State of the policy assignments?

A.
The Compliance State of both policy assignments is Non-compliant.
A.
The Compliance State of both policy assignments is Non-compliant.
Answers
B.
The Compliance State of the policy assignment to Subscription1 is Compliant, and the Compliance State of the policy assignment to RG1 is Non-compliant.
B.
The Compliance State of the policy assignment to Subscription1 is Compliant, and the Compliance State of the policy assignment to RG1 is Non-compliant.
Answers
C.
The Compliance State of the policy assignment to Subscription1 is Non-compliant, and the Compliance State of the policy assignment to RG1 is Compliant.
C.
The Compliance State of the policy assignment to Subscription1 is Non-compliant, and the Compliance State of the policy assignment to RG1 is Compliant.
Answers
D.
The Compliance State of both policy assignments is Compliant.
D.
The Compliance State of both policy assignments is Compliant.
Answers
Suggested answer: A

HOTSPOT

You have an Azure Sentinel workspace that has the following data connectors:

Azure Active Directory Identity Protection

Common Event Format (CEF)

Azure Firewall

You need to ensure that data is being ingested from each connector.

From the Logs query window, which table should you query for each connector? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 268
Correct answer: Question 268

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/connect-azure-ad-identity-protection

https://docs.microsoft.com/en-us/azure/sentinel/connect-azure-firewall

https://docs.microsoft.com/en-us/azure/sentinel/connect-data-sources

You have 10 on-premises servers that run Windows Server 2019.

You plan to implement Azure Security Center vulnerability scanning for the servers.

What should you install on the servers first?

A.
the Azure Arc enabled servers Connected Machine agent
A.
the Azure Arc enabled servers Connected Machine agent
Answers
B.
the Microsoft Defender for Endpoint agent
B.
the Microsoft Defender for Endpoint agent
Answers
C.
the Security Events data connector in Azure Sentinel
C.
the Security Events data connector in Azure Sentinel
Answers
D.
the Microsoft Endpoint Configuration Manager client
D.
the Microsoft Endpoint Configuration Manager client
Answers
Suggested answer: C

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/azure-arc/servers/agent-overview

https://docs.microsoft.com/en-us/azure/security-center/deploy-vulnerability-assessment-vm

HOTSPOT

You have an Azure subscription that contains three storage accounts, an Azure SQL managed instance named SQL1, and three Azure SQL databases.

The storage accounts are configured as shown in the following table.

SQL1 has the following settings:

Auditing: On

Audit log destination: storage1

The Azure SQL databases are configured as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.


Question 270
Correct answer: Question 270

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/azure-sql/managed-instance/auditing-configure

https://docs.microsoft.com/en-us/azure/azure-sql/database/auditing-overview

Total 439 questions
Go to page: of 44