ExamGecko
Home / Microsoft / AZ-500 / List of questions
Ask Question

Microsoft AZ-500 Practice Test - Questions Answers

List of questions

Question 1

Report
Export
Collapse

HOTSPOT

You implement the planned changes for ASG1 and ASG2.

In which NSGs can you use ASG1, and the network interfaces of which virtual machines can you assign to ASG2?


Microsoft AZ-500 image Question 1 87311 10022024015440000
Correct answer: Microsoft AZ-500 image answer Question 1 87311 10022024015440000
asked 02/10/2024
Robert Petty
52 questions

Question 2

Report
Export
Collapse

You plan to implement JIT VM access.

Which virtual machines will be supported?

VM2, VM3, and VM4 only
VM2, VM3, and VM4 only
VM1, VM2, VM3, and VM4
VM1, VM2, VM3, and VM4
VM1 and VM3 only
VM1 and VM3 only
VM1 only
VM1 only
Suggested answer: C
asked 02/10/2024
Freddy Rojas
35 questions

Question 3

Report
Export
Collapse

You plan to configure Azure Disk Encryption for VM4.

Which key vault can you use to store the encryption key?

KeyVault1
KeyVault1
KeyVault2
KeyVault2
KeyVault3
KeyVault3
Suggested answer: A

Explanation:

The key vault needs to be in the same subscription and same region as the VM.

VM4 is in West US. KeyVault1 is the only key vault in the same region as the VM.

Reference: https://docs.microsoft.com/en-us/azure/virtual-machines/windows/disk-encryption-key-vault

asked 02/10/2024
Rafal Piasecki
40 questions

Question 4

Report
Export
Collapse

You need to encrypt storage1 to meet the technical requirements.

Which key vaults can you use?

KeyVault2 and KeyVault3 only
KeyVault2 and KeyVault3 only
KeyVault1 only
KeyVault1 only
KeyVault1 and KeyVault3 only
KeyVault1 and KeyVault3 only
KeyVault1, KeyVault2, and KeyVault3
KeyVault1, KeyVault2, and KeyVault3
Suggested answer: A

Explanation:

asked 02/10/2024
Abel Galleguillos
39 questions

Question 5

Report
Export
Collapse

You need to meet the identity and access requirements for Group1.

What should you do?

Add a membership rule to Group1.
Add a membership rule to Group1.
Delete Group1. Create a new group named Group1 that has a membership type of Microsoft 365. Add users and devices to the group.
Delete Group1. Create a new group named Group1 that has a membership type of Microsoft 365. Add users and devices to the group.
Modify the membership rule of Group1.
Modify the membership rule of Group1.
Change the membership type of Group1 to Assigned. Create two groups that have dynamic memberships. Add the new groups to Group1.
Change the membership type of Group1 to Assigned. Create two groups that have dynamic memberships. Add the new groups to Group1.
Suggested answer: D

Explanation:

When you create dynamic groups, they can either contain users or devices. Hence here we need to create two separate dynamic groups and assign those groups to an Assigned group. Incorrect Answers:

A, C: You can create a dynamic group for devices or for users, but you can't create a rule that contains both users and devices.

D: For assigned group you can only add individual members.

Scenario:

Litware identifies the following identity and access requirements: All San Francisco users and their devices must be members of Group1.

The tenant currently contain this group:

Microsoft AZ-500 image Question 1 explanation 87242 10022024015440000000

References:

https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/groups-dynamic-membership

https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-groups-create-azure-portal

asked 02/10/2024
Shaunt Khalatian
38 questions

Question 6

Report
Export
Collapse

HOTSPOT

You need to ensure that the Azure AD application registration and consent configurations meet the identity and access requirements. What should you use in the Azure portal? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Microsoft AZ-500 image Question 6 87243 10022024015440000
Correct answer: Microsoft AZ-500 image answer Question 6 87243 10022024015440000

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/configure-user-consent

asked 02/10/2024
William Macy
55 questions

Question 7

Report
Export
Collapse

HOTSPOT

You need to configure support for Azure Sentinel notebooks to meet the technical requirements.

What is the minimum number of Azure container registries and Azure Machine Learning workspaces required?


Microsoft AZ-500 image Question 7 87384 10022024015441000
Correct answer: Microsoft AZ-500 image answer Question 7 87384 10022024015441000

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/notebooks

asked 02/10/2024
Alemu, Fissha
38 questions

Question 8

Report
Export
Collapse

From Azure Security Center, you need to deploy SecPol1.

What should you do first?

Enable Azure Defender.
Enable Azure Defender.
Create an Azure Management group.
Create an Azure Management group.
Create an initiative.
Create an initiative.
Configure continuous export.
Configure continuous export.
Suggested answer: C

Explanation:

Reference:

https://github.com/MicrosoftDocs/azure-docs/blob/master/articles/security-center/custom-security-policies.md

https://zimmergren.net/create-custom-security-center-recommendation-with-azure-policy/

asked 02/10/2024
KENEILWE DITHLAGE
42 questions

Question 9

Report
Export
Collapse

You need to recommend which virtual machines to use to host App1. The solution must meet the technical requirements for KeyVault1.

Which virtual machines should you use?

VM1 only
VM1 only
VM1, VM2, VM3, and VM4
VM1, VM2, VM3, and VM4
VM1 and VM2 only
VM1 and VM2 only
VM1, VM2, and VM4 only
VM1, VM2, and VM4 only
Suggested answer: D

Explanation:

asked 02/10/2024
Tiro malope
40 questions

Question 10

Report
Export
Collapse

You need to ensure that users can access VM0. The solution must meet the platform protection requirements. What should you do?

Move VM0 to Subnet1.
Move VM0 to Subnet1.
On Firewall, configure a network traffic filtering rule.
On Firewall, configure a network traffic filtering rule.
Assign RT1 to AzureFirewallSubnet.
Assign RT1 to AzureFirewallSubnet.
On Firewall, configure a DNAT rule.
On Firewall, configure a DNAT rule.
Suggested answer: A

Explanation:

Azure Firewall has the following known issue:

Conflict with Azure Security Center (ASC) Just-in-Time (JIT) feature.

If a virtual machine is accessed using JIT, and is in a subnet with a user-defined route that points to Azure Firewall as a default gateway, ASC JIT doesn’t work. This is a result of asymmetric routing – a packet comes in via the virtual machine public IP (JIT opened the access), but the return path is via the firewall, which drops the packet because there is no established session on the firewall.

Solution: To work around this issue, place the JIT virtual machines on a separate subnet that doesn’t have a user-defined route to the firewall.

Scenario:

Microsoft AZ-500 image Question 1 explanation 87315 10022024015440000000

Following the implementation of the planned changes, the IT team must be able to connect to VM0 by using JIT VM access.

Microsoft AZ-500 image Question 1 explanation 87315 10022024015440000000

References:

https://docs.microsoft.com/en-us/azure/firewall/overview

asked 02/10/2024
Anu V
42 questions
Total 442 questions
Go to page: of 45

Related questions