The Secret Of Microsoft Az-500 Free Practice Exam

Passleader offers free demo for az-500 exam. "Microsoft Azure Security Technologies", also known as az-500 exam, is a Microsoft Certification. This set of posts, Passing the Microsoft az-500 exam, will help you answer those questions. The az-500 Questions & Answers covers all the knowledge points of the real exam. 100% real Microsoft az-500 exams and revised by experts!

Free demo questions for Microsoft az-500 Exam Dumps Below:

NEW QUESTION 1

You company has an Azure Active Directory (Azure AD) tenant named contoso.com. You plan to create several security alerts by using Azure Monitor.
You need to prepare the Azure subscription for the alerts. What should you create first?

  • A. An Azure Storage account
  • B. an Azure Log Analytics workspace
  • C. an Azure event hub
  • D. an Azure Automation account

Answer: B

Explanation:
https://docs.microsoft.com/en-us/azure/azure-monitor/learn/quick-create-workspace

NEW QUESTION 2

You have five Azure subscriptions linked to a single Azure Active Directory (Azure AD) tenant. You create an Azure Policy initiative named SecurityPolicyInitiative1.
You identify which standard role assignments must be configured on all new resource groups.
You need to enforce SecurityPolicyInitiative1 and the role assignments when a new resource group is created. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
AZ-500 dumps exhibit


Solution:
Reference:
https://docs.microsoft.com/en-us/azure/governance/blueprints/create-blueprint-portal https://docs.microsoft.com/en-us/azure/azure-australia/azure-policy

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 3

You plan to deploy a custom policy initiative for Microsoft Defender for Cloud. You need to identify all the resource groups that have a Delete lock.
How should you complete the policy definition? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
AZ-500 dumps exhibit


Solution:
AZ-500 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 4

Lab Task
Task 6
You need to configure a Microsoft SQL server named Web3l 330471 only to accept connections from the Subnet0 subnet on the VNET01 virtual network.


Solution:
Configure the firewall settings for the SQL server. You can use the Azure portal, Azure PowerShell, or the Azure CLI to do this. You need to add a firewall rule that allows inbound traffic from the IP address range of the Subnet0 subnet. You also need to disable the option to allow Azure services and resources to access this server.
Configure the network settings for the SQL server. You can use the Azure portal, Azure PowerShell, or the Azure CLI to do this. You need to enable service endpoints for SQL Server on the Subnet0 subnet. You also need to add a virtual network rule that links the SQL server to the Subnet0 subnet.
Configure the connection settings for the SQL server. You can use SQL Server Management Studio or Transact-SQL to do this. You need to enable remote server connections and specify a TCP port for listening. You also need to configure SQL Server Authentication or Azure Active Directory Authentication for connecting to the SQL server.

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 5

You have the Azure key vaults shown in the following table.
AZ-500 dumps exhibit
KV1 stores a secret named Secret1 and a key for a managed storage account named Key1. You back up Secret1 and Key1.
To which key vaults can you restore each backup? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
AZ-500 dumps exhibit


Solution:
The backups can only be restored to key vaults in the same subscription and same geography. You can restore to a different region in the same geography.
https://docs.microsoft.com/en-us/azure/key-vault/general/backup?tabs=azure-cli

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 6

You have 15 Azure virtual machines in a resource group named RG1. All virtual machines run identical applications.
You need to prevent unauthorized applications and malware from running on the virtual machines. What should you do?

  • A. Apply an Azure policy to RG1.
  • B. From Azure Security Center, configure adaptive application controls.
  • C. Configure Azure Active Directory (Azure AD) Identity Protection.
  • D. Apply a resource lock to RG1.

Answer: B

Explanation:
Adaptive application control is an intelligent, automated end-to-end application whitelisting solution from Azure Security Center. It helps you control which applications can run on your Azure and non-Azure VMs (Windows and Linux), which, among other benefits, helps harden your VMs against malware. Security Center uses machine learning to analyze the applications running on your VMs and helps you apply the specific whitelisting rules using this intelligence.
Reference:
https://docs.microsoft.com/en-us/azure/security-center/security-center-adaptive-application

NEW QUESTION 7

You plan to create an Azure Kubernetes Service (AKS) cluster in an Azure subscription. The manifest of the registered server application is shown in the following exhibit.
AZ-500 dumps exhibit
You need to ensure that the AKS cluster and Azure Active Directory (Azure AD) are integrated. Which property should you modify in the manifest?

  • A. accessTokenAcceptedVersion
  • B. keyCredentials
  • C. groupMembershipClaims
  • D. acceptMappedClaims

Answer: C

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/aks/azure-ad-integration-cli https://www.codeproject.com/Articles/3211864/Operation-and-Maintenance-of-AKS-Applications

NEW QUESTION 8

You have the role assignments shown in the following exhibit.
AZ-500 dumps exhibit
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
AZ-500 dumps exhibit


Solution:
AZ-500 dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 9

You have an Azure Active Directory (Azure AD) tenant that contains a group named Group1 You need to ensure that the members of Group1 sign in by using passwordless authentication What should you do?

  • A. Configure the Microsoft Authenticator authentication method policy.
  • B. Configure the certificate-based authentication (CBA) policy.
  • C. Configure the sign-in risk policy.
  • D. Create a Conditional Access policy.

Answer: A

NEW QUESTION 10

You have an Azure subscription that contains the virtual machines shown in the following table.
AZ-500 dumps exhibit
You create the Azure policies shown in the following table.
AZ-500 dumps exhibit
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
AZ-500 dumps exhibit


Solution:
References:
https://docs.microsoft.com/en-us/azure/governance/blueprints/concepts/resource-locking

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 11

You have an Azure Kubernetes Service (AKS) cluster that will connect to an Azure Container Registry. You need to use automatically generated service principal for the AKS cluster to authenticate to the Azure
Container Registry.
What should you create?

  • A. a secret in Azure Key Vault
  • B. a role assignment
  • C. an Azure Active Directory (Azure AD) user
  • D. an Azure Active Directory (Azure AD) group

Answer: B

Explanation:
References:
https://docs.microsoft.com/en-us/azure/aks/kubernetes-service-principal

NEW QUESTION 12

You have an Azure subscription that contains the resources shown in the following table.
AZ-500 dumps exhibit
You plan to deploy the virtual machines shown in the following table.
AZ-500 dumps exhibit
You need to assign managed identities to the virtual machines. The solution must meet the following requirements:
AZ-500 dumps exhibit Assign each virtual machine the required roles.
AZ-500 dumps exhibit Use the principle of least privilege.
What is the minimum number of managed identities required?

  • A. 1
  • B. 2
  • C. 3
  • D. 4

Answer: B

Explanation:
We have two different sets of required permissions. VM1 and VM2 have the same permission requirements. VM3 and VM4 have the same permission requirements.
A user-assigned managed identity can be assigned to one or many resources. By using user-assigned managed identities, we can create just two managed identities: one with the permission requirements for VM1 and VM2 and the other with the permission requirements for VM3 and VM4.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/overview

NEW QUESTION 13

You are evaluating the security of the network communication between the virtual machines in Sub2. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
AZ-500 dumps exhibit


Solution:
Q1: No { and it should not be allowed as only TCP 80 is allowed from the "Internet" service tag
Q2: Yes {as it should be for VMs in the same local subnet pinging each other on private IP and no NSG configured}
Q3: Yes {VM5 is in subnet where 1st rule of NSG allows any traffic from any source to the destination}

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 14

You need to configure WebApp1 to meet the data and application requirements.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Upload a public certificate.
  • B. Turn on the HTTPS Only protocol setting.
  • C. Set the Minimum TLS Version protocol setting to 1.2.
  • D. Change the pricing tier of the App Service plan.
  • E. Turn on the Incoming client certificates protocol setting.

Answer: BE

Explanation:
Refer https://docs.microsoft.com/en-us/azure/app-service/app-service-web-configure-tls-mutual-auth

NEW QUESTION 15

Lab Task
use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password. place your cursor in the Enter password box and click on the password below. Azure Username: Userl -28681041@ExamUsers.com
Azure Password: GpOAe4@lDg
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only: Lab Instance: 28681041
Task 5
You need to ensure that only devices connected to a 131-107.0.0/16 subnet can access data in the rg1lod28681041 Azure Storage account.


Solution:
To ensure that only devices connected to a 131-107.0.0/16 subnet can access data in the rg1lod28681041 Azure Storage account, you can follow these steps:
AZ-500 dumps exhibit In the Azure portal, search for and select the storage account named rg1lod28681041.
AZ-500 dumps exhibit In the left pane, select Firewalls and virtual networks.
AZ-500 dumps exhibit In the Firewalls and virtual networks pane, select Selected networks.
AZ-500 dumps exhibit In the Selected networks pane, select Add existing virtual network.
AZ-500 dumps exhibit In the Add existing virtual network pane, select the virtual network that contains the 131-107.0.0/16 subnet.
AZ-500 dumps exhibit Select Add.
https://docs.microsoft.com/en-us/azure/storage/common/storage-network-security

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 16
......

P.S. Allfreedumps.com now are offering 100% pass ensure az-500 dumps! All az-500 exam questions have been updated with correct answers: https://www.allfreedumps.com/az-500-dumps.html (377 New Questions)