Use AZ-500 Exam Dumps (2022 PDF Dumps) To Have Reliable AZ-500 Test Engine [Q11-Q28]

Share

Use AZ-500 Exam Dumps (2022 PDF Dumps) To Have Reliable AZ-500 Test Engine

AZ-500 PDF Recently Updated Questions Dumps to Improve Exam Score


What Is Your Career Path after AZ-500?

After receiving the aforementioned associate-level certificate, you can also decide to enhance your skills further and bag another certification. There are certifications at the expert-level which are best for anyone seeking to have more say in their career. They include:

  • The Microsoft Certified: DevOps Engineer Expert;
  • The Microsoft Certified: Azure Solutions Architect Expert.

The first certificate for developers requires passing one test while the latter for solutions architect demands acing two tests. Earning any of them makes you an expert who can command a more advanced role and even a better salary.


There are various topics included in Microsoft AZ-500 that you should master during your preparation time. They are as follows:

  • Implement Platform Protection.
  • Manage Identity and Access;
  • Manage Security Operations;
  • Secure Data and Applications;

All of these domains are separated into different sections and each has its own percentage rate of occurring during your test. Therefore, we recommend that you check the official certification page to know the additional details that will help you during your preparation.

 

NEW QUESTION 11
You are troubleshooting a security issue for an Azure Storage account.
You enable the diagnostic logs for the storage account.
What should you use to retrieve the diagnostics logs?

  • A. File Explorer in Windows
  • B. SQL query editor in Azure
  • C. AzCopy
  • D. the Security & Compliance admin center

Answer: C

Explanation:
Explanation/Reference:
References:
https://docs.microsoft.com/en-us/azure/storage/common/storage-analytics-logging?toc=%2fazure%2fstorage%
2fblobs%2ftoc.json

 

NEW QUESTION 12
You have a hybrid configuration of Azure Active Directory (Azure AD).
All users have computers that run Windows 10 and are hybrid Azure AD joined.
You have an Azure SQL database that is configured to support Azure AD authentication.
Database developers must connect to the SQL database by using Microsoft SQL Server Management Studio (SSMS) and authenticate by using their on-premises Active Directory account.
You need to tell the developers which authentication method to use to connect to the SQL database from SSMS. The solution must minimize authentication prompts.
Which authentication method should you instruct the developers to use?

  • A. Active Directory - Integrated
  • B. Active Directory - Universal with MFA support
  • C. SQL Login
  • D. Active Directory - Password

Answer: A

Explanation:
Explanation
Azure AD can be the initial Azure AD managed domain. Azure AD can also be an on-premises Active Directory Domain Services that is federated with the Azure AD.
Using an Azure AD identity to connect using SSMS or SSDT
The following procedures show you how to connect to a SQL database with an Azure AD identity using SQL Server Management Studio or SQL Server Database Tools.
Active Directory integrated authentication
Use this method if you are logged in to Windows using your Azure Active Directory credentials from a federated domain.
1. Start Management Studio or Data Tools and in the Connect to Server (or Connect to Database Engine) dialog box, in the Authentication box, select Active Directory - Integrated. No password is needed or can be entered because your existing credentials will be presented for the connection.

2. Select the Options button, and on the Connection Properties page, in the Connect to database box, type the name of the user database you want to connect to. (The AD domain name or tenant ID" option is only supported for Universal with MFA connection options, otherwise it is greyed out.) References:
https://github.com/MicrosoftDocs/azure-docs/blob/master/articles/sql-database/sql-database-aad-authentication

 

NEW QUESTION 13
You have an Azure Active Directory (Azure AD) tenant named Contoso.com and an Azure Service (AKS) cluster AKS1.
You discover that AKS1 cannot be accessed by using accounts from Contoso.com You need to ensure AKS1 can be accessed by using accounts from Contoso.com The solution must minimize administrative effort.
What should you do first?

  • A. From Azure AD, configure the User settings
  • B. From AKS1, upgrade the version of Kubermetes.
  • C. From Azure recreate AKS1,
  • D. From Azure AD, implement Azure AD Premium.

Answer: C

 

NEW QUESTION 14
You have an Azure subscription that contains the alerts shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

References:
https://docs.microsoft.com/en-us/azure/azure-monitor/platform/alerts-overview

 

NEW QUESTION 15
You have an Azure subscription that contains the resources shown in the following table.

You need to ensure that ServerAdmins can perform the following tasks:
* Create virtual machines in RG1 only.
* Connect the virtual machines to the existing virtual networks in RG2 only.
The solution must use the principle of least privilege.
Which two role-based access control (RBAC) roles should you assign to ServerAdmins? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. the Virtual Machine Contributor role for RG1
  • B. a custom RBAC role for RG2
  • C. the Contributor role for the subscription
  • D. the Network Contributor role for RG2
  • E. the Network Contributor role for RG1
  • F. a custom RBAC role for the subscription

Answer: A,B

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles

 

NEW QUESTION 16
You have the hierarchy of Azure resources shown in the following exhibit.

RG1, RG2, and RG3 are resource groups.
RG2 contains a virtual machine named VM1.
You assign role-based access control (RBAC) roles to the users shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

 

NEW QUESTION 17
You have an Azure Sentinel workspace that has an Azure Active Directory (Azure AD) data connector.
You are threat hunting suspicious traffic from a specific IP address.
You need to annotate an intermediate event stored in the workspace and be able to reference the IP address when navigating through the investigation graph.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation

Reference:
https://docs.microsoft.com/en-us/azure/sentinel/bookmarks

 

NEW QUESTION 18
You have an Azure subscription that contains the virtual machines shown in the following table.

Subnet1 and Subnet2 have a Microsoft.Storage service endpoint configured.
You have an Azure Storage account named storageacc1 that is configured as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Answer:

Explanation:

Explanation

Box 1: Yes
The public IP of VM1 is allowed through the firewall.
Box 2: No
The allowed virtual network list is empty so VM2 cannot access storageacc1 directly. The public IP address of VM2 is not in the allowed IP list so VM2 cannot access storageacc1 over the Internet.
Box 3: No
The allowed virtual network list is empty so VM3 cannot access storageacc1 directly. VM3 does not have a public IP address so it cannot access storageacc1 over the Internet.
Reference:
https://docs.microsoft.com/en-gb/azure/storage/common/storage-network-security

 

NEW QUESTION 19
You are configuring just in time (JIT) VM access to a set of Azure virtual machines.
You need to grant users PowerShell access to the virtual machine by using JIT VM access.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

 

NEW QUESTION 20
SIMULATION
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Azure Username: [email protected]
Azure Password: Ag1Bh9!#Bd
The following information is for technical support purposes only:
Lab Instance: 10598168




You need to ensure that the rg1lod10598168n1 Azure Storage account is encrypted by using a key stored in the KeyVault10598168 Azure key vault.
To complete this task, sign in to the Azure portal.

  • A. Step 1: To enable customer-managed keys in the Azure portal, follow these steps:
    1. Navigate to your storage account rg1lod10598168n1
    2. On the Settings blade for the storage account, click Encryption. Select the Use your own key option, as shown in the following figure.

    Step 2: Specify a key from a key vault
    To specify a key from a key vault, first make sure that you have a key vault that contains a key. To specify a key from a key vault, follow these steps:
    4. Choose the Select from Key Vault option.
    5. Choose the key vault KeyVault10598168 containing the key you want to use.
    6. Choose the key from the key vault.
  • B. Step 1: To enable customer-managed keys in the Azure portal, follow these steps:
    1. Navigate to your storage account rg1lod10598168n1
    2. On the Settings blade for the storage account, click Encryption. Select the Use your own key option, as shown in the following figure.

    Step 2: Specify a key from a key vault
    To specify a key from a key vault, first make sure that you have a key vault that contains a key. To specify a key from a key vault, follow these steps:
    4. Choose the Select from Key Vault option.
    5. Choose the key vault KeyVault10598168 containing the key you want to use.
    6. Choose the key from the key vault.

Answer: A

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/storage/common/storage-encryption-keys-portal

 

NEW QUESTION 21
You need to ensure that User2-11641655 has all the key permissions for KeyVault11641655.
To complete this task, sign in to the Azure portal and modify the Azure resources.

Answer:

Explanation:
You need to assign the user the Key Vault Secrets Officer role.
In the Azure portal, type Key Vaults in the search box, select Key Vaults from the search results then select KeyVault11641655. Alternatively, browse to Key Vaults in the left navigation pane.
In the key vault properties, select Access control (IAM).
In the Add a role assignment section, click the Add button.
In the Role box, select the Key Vault Secrets Officer role from the drop-down list.
In the Select box, start typing User2-11641655 and select User2-11641655 from the search results.
Click the Save button to save the changes.

 

NEW QUESTION 22
You have Azure virtual machines that have Update Management enabled. The virtual machines are configured as shown in the following table.

You schedule two update deployments named Update1 and Update2. Update1 updates VM3. Update2 updates VM6.
Which additional virtual machines can be updated by using Update1 and Update2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

Update1: VM1 and VM2 only
VM3: Windows Server 2016 West US RG2
Update2: VM4 and VM5 only
VM6: CentOS 7.5 East US RG1
For Linux, the machine must have access to an update repository. The update repository can be private or public.
References:
https://docs.microsoft.com/en-us/azure/automation/automation-update-management

 

NEW QUESTION 23
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.

From Azure AD Privileged Identity Management (PIM), you configure the settings for the Security Administrator role as shown in the following exhibit.

From PIM, you assign the Security Administrator role to the following groups:
* Group1: Active assignment type, permanently assigned
* Group2: Eligible assignment type, permanently eligible
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Yes
Eligible Type: A role assignment that requires a user to perform one or more actions to use the role. If a user has been made eligible for a role, that means they can activate the role when they need to perform privileged tasks. There's no difference in the access given to someone with a permanent versus an eligible role assignment. The only difference is that some people don't need that access all the time.
You can choose from two assignment duration options for each assignment type (eligible and active) when you configure settings for a role. These options become the default maximum duration when a user is assigned to the role in Privileged Identity Management.
Use the Activation maximum duration slider to set the maximum time, in hours, that a role stays active before it expires. This value can be from one to 24 hours.
Box 2: Yes
Active Type: A role assignment that doesn't require a user to perform any action to use the role. Users assigned as active have the privileges assigned to the role Box 3: Yes User3 is member of Group2.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure
https://docs.microsoft.com/bs-cyrl-ba/azure/active-directory/privileged-identity-management/pim-resource-roles-configure-role-settings

 

NEW QUESTION 24
All the virtual networks are peered.
You deploy Azure Bastion to VNET2.
Which virtual machines can be protected by the bastion host?

  • A. VM1, VM2, and VM3 only
  • B. VM1, VM2, VM3, and VM4
  • C. VM2 and VM4 only
  • D. VM2 only

Answer: B

Explanation:
https://docs.microsoft.com/en-us/azure/bastion/vnet-peering

 

NEW QUESTION 25
You have an Azure environment.
You need to identify any Azure configurations and workloads that are non-compliant with ISO 27001 standards.
What should you use?

  • A. Azure Sentinel
  • B. Azure Advanced Threat Protection (ATP)
  • C. Azure Security Center
  • D. Azure Active Directory (Azure AD) Identity Protection

Answer: C

Explanation:
Section: [none]
Explanation/Reference:
https://docs.microsoft.com/en-us/azure/security-center/security-center-compliance-dashboard

 

NEW QUESTION 26
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains three security groups named Group1, Group2, and Group3 and the users shown in the following table.

Group3 is a member of Group2.
In contoso.com, you register an enterprise application named App1 that has the following settings:
Owners: User1
Users and groups: Group2
You configure the properties of App1 as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select no.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/assign-user-or-group-access-portal

 

NEW QUESTION 27
You have an Azure subscription that contains the virtual machines shown in the following table.

You create the Azure policies shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

References:
https://docs.microsoft.com/en-us/azure/governance/blueprints/concepts/resource-locking

 

NEW QUESTION 28
......

AZ-500 Dumps Full Questions with Free PDF Questions to Pass: https://www.testpassed.com/AZ-500-still-valid-exam.html

Free Microsoft Azure Security Engineer Associate AZ-500 Official Cert Guide PDF Download: https://drive.google.com/open?id=1VTc6JOtqmGnC-9lI3aIk-LRN3LJh5MC3