2023 New Training Course AZ-500 Tutorial Preparation Guide [Q193-Q212]

Share

2023 New Training Course AZ-500 Tutorial Preparation Guide

Dumps of AZ-500 Cover all the requirements of the Real Exam


Microsoft AZ-500 is a certification exam that focuses on testing the skills and knowledge of individuals in the field of Microsoft Azure security technologies. This exam is designed for professionals who are interested in proving their skills and knowledge in securing Microsoft Azure workloads and data services. The exam tests various aspects of Azure security, including identity and access management, platform protection, data and application protection, and infrastructure security. It assesses an individual's ability to implement security controls, manage identity and access policies, monitor security incidents, and respond to security threats.


Microsoft AZ-500 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Install and Configure Microsoft Azure AD Connect
  • Authentication Methods
Topic 2
  • Implement Conditional Access Policies
  • Identity Protection
Topic 3
  • Configure Microsoft Azure AD Privileged Identity Management
  • Monitor Privileged Access
Topic 4
  • Manage Identity and Access
  • Configure Microsoft Azure Active Directory for Workloads
Topic 5
  • Manage App Registration Permission Consent
  • Configure Multi Factors
Topic 6
  • Manage API Access to Microsoft Azure Subscriptions and Resources
Topic 7
  • Activate Privileged Identity Management
Topic 8
  • Creation and Configuration App Registration Permission Scopes
Topic 9
  • Manage Microsoft Azure Directory Groups
  • Users

 

NEW QUESTION # 193
You have the Azure virtual machines shown in the following table.

Each virtual machine has a single network interface.
You add the network interface of VM1 to an application security group named ASG1.
You need to identify the network interfaces of which virtual machines you can add to ASG1.
What should you identify?

  • A. VM2 and VM3 only
    https://www.fast2test.com/AZ-500-practice-test.html 24
    Valid Fast2test AZ-500 Exam PDF Dumps - New AZ-500 Real Exam Questions
  • B. VM2, VM3, and VM5 only
  • C. VM2 only
  • D. VM2, VM3, VM4, and VM5

Answer: A

Explanation:
Explanation/Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/application-security-groups


NEW QUESTION # 194
You need to create a new Azure Active Directory (Azure AD) directory named 12345678.onmicrosoft.com. The new directory must contain a new user named [email protected].
To complete this task, sign in to the Azure portal.

Answer:

Explanation:
The first step is to create the Azure Active Directory tenant.
Sign in to the Azure portal.
From the Azure portal menu, select Azure Active Directory.
On the overview page, select Manage tenants.
Select +Create.
On the Basics tab, select Azure Active Directory.
Select Next: Configuration to move on to the Configuration tab.
For Organization name, enter 12345678.
For the Initial domain name, enter 12345678.
Leave the Country/Region as the default.
The next step is to create the user.
From the Azure portal menu, select Azure Active Directory.
Select Users then select New user.
Enter User1 in the User name and Name fields.
Leave the default option of Auto-generate password.
Click the Create button.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-access-create-new-tenant
https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/add-users-azure-active-directory


NEW QUESTION # 195
Your company has two offices in Seattle and New York. Each office connects to the Internet by using a NAT device. The offices use the IP addresses shown in the following table.

The company has an Azure Active Directory (Azure AD) tenant named contoso.com. The tenant contains the users shown in the following table.

The MFA service settings are configured as shown in the exhibit. (Click the Exhibit tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://www.cayosoft.com/difference-enabling-enforcing-mfa/


NEW QUESTION # 196
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription named Sub1.
You have an Azure Storage account named Sa1 in a resource group named RG1.
Users and applications access the blob service and the file service in Sa1 by using several shared access signatures (SASs) and stored access policies.
You discover that unauthorized users accessed both the file service and the blob service.
You need to revoke all access to Sa1.
Solution: You create a lock on Sa1.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

Explanation:
To revoke a stored access policy, you can either delete it, or rename it by changing the signed identifier. Changing the signed identifier breaks the associations between any existing signatures and the stored access policy. Deleting or renaming the stored access policy immediately affects all of the shared access signatures associated with it.
References:
https://docs.microsoft.com/en-us/rest/api/storageservices/Establishing-a-Stored-Access-Policy


NEW QUESTION # 197
You have an Azure Sentinel workspace that has the following data connectors:
Azure Active Directory Identity Protection
Common Event Format (CEF)
Azure Firewall
You need to ensure that data is being ingested from each connector.
From the Logs query window, which table should you query for each connector? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 198
You have an Azure Active Directory (Azure AD) tenant that contains the resources shown in the following table.

User2 is the owner of Group2.
The user and group settings for App1 are configured as shown in the following exhibit.

You enable self-service application access for App1 as shown in the following exhibit.

User3 is configured to approve access to Appl.
You need to identify the owners of Group2 and the users of Appl.
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/manage-self-service-access


NEW QUESTION # 199
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You use Azure Security Center for the centralized policy management of three Azure subscriptions.
You use several policy definitions to manage the security of the subscriptions.
You need to deploy the policy definitions as a group to all three subscriptions.
Solution: You create an initiative and an assignment that is scoped to the Tenant Root Group management group.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: A

Explanation:
Explanation/Reference:
https://docs.microsoft.com/en-us/azure/governance/policy/overview
https://4sysops.com/archives/apply-governance-policy-to-multiple-azure-subscriptions-with-management- groups/


NEW QUESTION # 200
You have an Azure subscription named Subscription1 that contains a resource group named RG1 and a user named User1. User1 is assigned the Owner role for RG1.
You create an Azure Blueprints definition named Blueprint1 that includes a resource group named RG2 as shown in the following exhibit.

You assign Blueprint1 to Subscription1 by using the following settings:
Lock assignment: Read Only
Managed Identity: System assigned
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/governance/blueprints/concepts/resource-locking


NEW QUESTION # 201
You have an Azure subscription that contains a web app named App1 and an Azure key vault named Vault1.
You need to configure App1 to store and access the secrets in Vault1.
How should you configure App1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/app-service/overview-managed-identity?tabs=dotnet


NEW QUESTION # 202
You have an Azure web app named WebApp1.
https://www.fast2test.com/AZ-500-practice-test.html 82
Valid Fast2test AZ-500 Exam PDF Dumps - New AZ-500 Real Exam Questions
You upload a certificate to WebApp1.
You need to make the certificate accessible to the app code of WebApp1.
What should you do?

  • A. Enable system-assigned managed identity for the WebApp1.
  • B. Add a user-assigned managed identity to WebApp1.
  • C. Configure the TLS/SSL binding for WebApp1.
  • D. Add an app setting to the WebApp1 configuration.

Answer: D

Explanation:
Explanation/Reference:
https://docs.microsoft.com/en-us/azure/app-service/configure-ssl-certificate-in-code


NEW QUESTION # 203
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.

The tenant contains the named locations shown in the following table.

You create the conditional access policies for a cloud app named App1 as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 204
You have Azure virtual machines that have Update Management enabled. The virtual machines are configured as shown in the following table.

You schedule two update deployments named Update1 and Update2. Update1 updates VM3. Update2 updates VM6.
Which additional virtual machines can be updated by using Update1 and Update2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Update1: VM1 and VM2 only
VM3: Windows Server 2016 West US RG2
Update2: VM4 and VM5 only
VM6: CentOS 7.5 East US RG1
For Linux, the machine must have access to an update repository. The update repository can be private or public.
References:
https://docs.microsoft.com/en-us/azure/automation/automation-update-management


NEW QUESTION # 205
From Azure Security, you create a custom alert rule.
You need to configure which users will receive an email message when the alert is triggered.
What should you do?

  • A. From Azure Monitor, create an action group.
  • B. From Security Center, modify the alert rule.
  • C. From Azure Active Directory (Azure AD). modify the members of the Security Reader role group.
  • D. From Security Center, modify the Security policy settings of the Azure subscription.

Answer: A

Explanation:
Explanation
References:
https://docs.microsoft.com/en-us/azure/azure-monitor/platform/action-groups


NEW QUESTION # 206
You have a network security group (NSG) bound to an Azure subnet.
You run Get-AzureRmNetworkSecurityRuleConfig and receive the output shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/manage-network-security-group


NEW QUESTION # 207
You have an Azure subscription that contains a resource group named RG1. RG1 contains a virtual machine named VM1 that uses Azure Active Directory (Azure AD) authentication.
You have two custom Azure roles named Role1 and Role2 that are scoped to RG1.
The permissions for Role1 are shown in the following JSON code.

The permissions for Role2 are shown in the following JSON code.

You assign the roles to the users shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 208
You suspect that users are attempting to sign in to resources to which they have no access.
You need to create an Azure Log Analytics query to identify failed user sign-in attempts from the last three days. The results must only show users who had more than five failed sign-in attempts.
How should you configure the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

The following example identifies user accounts that failed to log in more than five times in the last day, and when they last attempted to log in.
let timeframe = 1d;
SecurityEvent
| where TimeGenerated > ago(1d)
| where AccountType == 'User' and EventID == 4625 // 4625 - failed log in
| summarize failed_login_attempts=count(), latest_failed_login=arg_max(TimeGenerated, Account) by Account
| where failed_login_attempts > 5
| project-away Account1
References:
https://docs.microsoft.com/en-us/azure/azure-monitor/log-query/examples


NEW QUESTION # 209
You have an Azure subscription that contains the key vaults shown in the following table.

The subscription contains the users shown in the following table.

On June 1, you perform the following actions:
* Delete a key named key1 from KeyVault1.
* Delete a secret named secret 1 from KeyVault2.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Answer:

Explanation:


NEW QUESTION # 210
You have the hierarchy of Azure resources shown in the following exhibit.

RG1, RG2, and RG3 are resource groups.
RG2 contains a virtual machine named VM1.
You assign role-based access control (RBAC) roles to the users shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 211
You have an Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com.
The User administrator role is assigned to a user named Admin1.
An external partner has a Microsoft account that uses the [email protected] sign in.
Admin1 attempts to invite the external partner to sign in to the Azure AD tenant and receives the following
error message: "Unable to invite user [email protected] Generic authorization exception."
You need to ensure that Admin1 can invite the external partner to sign in to the Azure AD tenant.
What should you do?

  • A. From the Users blade, modify the External collaboration settings.
  • B. From the Roles and administrators blade, assign the Security administrator role to Admin1.
  • C. From the Custom domain names blade, add a custom domain.
  • D. From the Organizational relationships blade, add an identity provider.

Answer: A

Explanation:
You need to allow guest invitations in the External collaboration settings.


NEW QUESTION # 212
......

Sample Questions of AZ-500 Dumps With 100% Exam Passing Guarantee: https://www.testvalid.com/AZ-500-exam-collection.html

Correct Practice Tests of AZ-500 Dumps with Practice Exam: https://drive.google.com/open?id=1vO2BdLn82wkScbnAuewbnqZcF7NC67PX