ExamGecko
Home Home / Microsoft / AZ-500

Microsoft AZ-500 Practice Test - Questions Answers, Page 39

Question list
Search
Search

List of questions

Search

Related questions











You have an Azure subscription that uses Microsoft Defender for Cloud.

You have an Amazon Web Service (AWS) account named AWS1 that is connected to defender for Cloud.

You need to ensure that AWS foundational Security Best Practices. The solution must minimize administrate effort.

What should do you in Defender for Cloud?

A.
Create a new customer assessment.
A.
Create a new customer assessment.
Answers
B.
Assign a built-in assessment.
B.
Assign a built-in assessment.
Answers
C.
Assign a built-in compliance standard.
C.
Assign a built-in compliance standard.
Answers
D.
Create a new custom standard.
D.
Create a new custom standard.
Answers
Suggested answer: C

You have an Azure subscription that contains an Azure Blob storage account bolb1.

You need to configure attribute-based access control (ABAC) for blob1.

Which attributes can you use in access conditions?

A.
blob index tags only
A.
blob index tags only
Answers
B.
blob index tags and container names only
B.
blob index tags and container names only
Answers
C.
file extensions and container names only
C.
file extensions and container names only
Answers
D.
blob index tags, file extensions, and container names
D.
blob index tags, file extensions, and container names
Answers
Suggested answer: A

You have an Azure subscription that contains the resources show in the following table.

Both VM1 and VM2 connect to VNET1 and are configured to use NSG1.

You need to ensure that only VM1 and VM2 can access DB1.

What should you do?

A.
Add the IP address range of VNET1 to the Firewall setting of DB1.
A.
Add the IP address range of VNET1 to the Firewall setting of DB1.
Answers
B.
For NSG1, configure a rule that has a service tag.
B.
For NSG1, configure a rule that has a service tag.
Answers
C.
Create an application security group.
C.
Create an application security group.
Answers
D.
Configure DB1 to allow access from only VNET1.
D.
Configure DB1 to allow access from only VNET1.
Answers
Suggested answer: B

DRAG DROP

You have an Azure subscription.

You plan to implement Azure DDoS Protection. The solution must meet the following requirement:

* Provide access to DDoS rapid response support during active attacks.

* Project Basic SKU public IP addresses.

You need to recommend which type of DDoS projection to use for each requirement.

What should you recommend? To answer, drag the appropriate DDoS projection types to the correct

requirements. Each DDoS Projection type may be used once, or not at all. You may need to drag the

split bar between panes or scroll to view connect.

NOTE: Each correct selection is worth one point.

Answer:

Question 384
Correct answer: Question 384

HOTSPOT

You have an Azure subscription that contains a user named User1. User1 is assigned the Reader role for the subscription.

You plan to create a custom role named Role1 and assign Role1 to User1.

You need to ensure that User1 can create and manage application security groups by using the Azure portal.

Which two permissions should you add to Role1? To answer, select the appropriate permission in the answer area.

NOTE: Each correct selection is worth one point.


Question 385
Correct answer: Question 385

Explanation:

1. Microsoft Portal

2. Microsoft Network https://learn.microsoft.com/en-us/azure/azure-resourcemanager/management/azure-services-resource-providers

You have an Azure subscription that contains an Azure web app named 1 and a virtual machine named VM1. VM1 runs Microsoft SQL Server and is connected to a virtual network named VNet1.

App1, VM1, and Vent are in the US Central Azure region.

You need to ensure that App1 can connect to VM1. The solution must minimize costs.

A.
NAT gateway integration
A.
NAT gateway integration
Answers
B.
Azure Front Door
B.
Azure Front Door
Answers
C.
regional virtual network integration
C.
regional virtual network integration
Answers
D.
gateway-required virtual network integration
D.
gateway-required virtual network integration
Answers
E.
Azure Application Gateway integration
E.
Azure Application Gateway integration
Answers
Suggested answer: C

You have an Azure subscription that contains a storage account and an Azure web app named App1.

App1 connects to an Azure Cosmos DB database named Cosmos1 that uses a private endpoint named Endpoint1. Endpoint1 has the default settings.

You need to validate the name resolution to Cosmos1.

Which DNS zone should you use?

A.
Endpoint1. Privatelink,blob,core,windows,net
A.
Endpoint1. Privatelink,blob,core,windows,net
Answers
B.
Endpoint1. Privatelink,database,azure,com
B.
Endpoint1. Privatelink,database,azure,com
Answers
C.
Endpoint1. Privatelink,azurewebsites,net
C.
Endpoint1. Privatelink,azurewebsites,net
Answers
D.
Endpoint1. Privatelink,documents,azure,com
D.
Endpoint1. Privatelink,documents,azure,com
Answers
Suggested answer: D

You have an Azure subscription that contains the subnets shown in the following table.

The subscription contains Azure web app named WebApp1 that has the following configurations.

* Region West Us

* Virtual network VNet1

* VNet integration on: Enabled

* Outbound subnet: Subnet11

* Windows plan (West US): ASP1

You plan to deploy an Azure web app named WebApp2 that will have the following settings:

* Region: West US

* VNet integration on-Enabled

* Windows plan (West UAS): WebApp2?

To which subnets can you integrate WebApp2?

A.
Subnet11 only
A.
Subnet11 only
Answers
B.
Subnet2 only
B.
Subnet2 only
Answers
C.
Subnet11 or subnet12 only
C.
Subnet11 or subnet12 only
Answers
D.
Subnet2 or Subnet21 only
D.
Subnet2 or Subnet21 only
Answers
E.
Subnet11, subnet2, or Subnet21
E.
Subnet11, subnet2, or Subnet21
Answers
Suggested answer: C

You have an Azure AD turned that contains a user named User1.

You purchase an App named App1.

User1 needs to publish App1 by using Azure AD Application Proxy.

Which role should you assign to User1?

A.
Hybrid identity Administrator
A.
Hybrid identity Administrator
Answers
B.
Cloud App Security Administrator
B.
Cloud App Security Administrator
Answers
C.
Application Administrator
C.
Application Administrator
Answers
D.
Cloud Application Administrate
D.
Cloud Application Administrate
Answers
Suggested answer: C

DRAG DROP

You have an Azure subscription named Sub1 that contains the storage accounts shown in the following table

The storage3 storage account is encrypted by using customer-managed keys.

YOU need to enable Microsoft Defender for storage to meet the following requirements.

* The storage1 and storage2 account must be include in the defender for storage requirement.

* The storage3 account must be exclude from the Defender for Storage protections.

Which three actions should you perform in sequence? To answer, move the appropriate actions from

the list of actions to the answer area and them in the correct order.

Question 390
Correct answer: Question 390
Total 439 questions
Go to page: of 44