Summer Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

AZ-500 Exam Dumps - Microsoft Azure Security Technologies

Go to page:
Question # 41

You have an Azure subscription named Sub1 that has Security defaults disabled. The subscription contains the following users:

• Five users that have owner permissions for Sub1.

• Ten users that have owner permissions for Azure resources.

None of the users have multi-factor authentication (MFA) enabled.

Sub1 has the secure score as shown in the Secure Score exhibit. (Click the Secure Score tab.)

You plan to enable MFA for the following users:

• Five users that have owner permissions for Sub1.

• Five users that have owner permissions for Azure resources.

By how many points will the secure score increase after you perform the planned changes?

A.

0

B.

5

C.

7.5

D.

10

E.

14

Full Access
Question # 42

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure subscription named Sub1.

You have an Azure Storage account named Sa1 in a resource group named RG1.

Users and applications access the blob service and the file service in Sa1 by using several shared access signatures (SASs) and stored access policies.

You discover that unauthorized users accessed both the file service and the blob service.

You need to revoke all access to Sa1.

Solution: You create a lock on Sa1.

Does this meet the goal?

A.

Yes

B.

No

Full Access
Question # 43

You have an Azure subscription named Subscription1.

You need to view which security settings are assigned to Subscription1 by default.

Which Azure policy or initiative definition should you review?

A.

the Audit diagnostic setting policy definition

B.

the Enable Monitoring in Azure Security Center initiative definition

C.

the Enable Azure Monitor for VMs initiative definition

D.

the Azure Monitor solution ‘Security and Audit’ must be deployed policy definition

Full Access
Question # 44

You are configuring network connectivity for two Azure virtual networks named VNET1 and VNET2.

You need to implement VPN gateways for the virtual networks to meet the following requirements:

* VNET1 must have six site-to-site connections that use BGP.

* VNET2 must have 12 site-to-site connections that use BGP.

* Costs must be minimized.

Which VPN gateway SKI) should you use for each virtual network? To answer, drag the appropriate SKUs to the correct networks. Each SKU may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point

Full Access
Question # 45

You have Azure virtual machines that have Update Management enabled. The virtual machines are configured as shown in the following table.

You schedule two update deployments named Update1 and Update2. Update1 updates VM3. Update2 updates VM6.

Which additional virtual machines can be updated by using Update1 and Update2? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Full Access
Question # 46

You have an Azure subscription that contains a user named UseR1. You need to ensure that UseR1 can perform the following tasks:

• Create groups.

• Create access reviews for role-assignable groups.

• Assign Azure AD roles to groups.

The solution must use the principle of least privilege. Which role should you assign to User1?

A.

Groups administrator

B.

Authentication administrator

C.

Identity Governance Administrator

D.

Privileged role administrator

Full Access
Question # 47

You have a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.

You add enterprise applications to contoso.com as shown in the following table.

You need to Identify which users can grant admin consent for App1 and App2.

Full Access
Question # 48

You are testing an Azure Kubernetes Service (AKS) cluster. The cluster is configured as shown in the exhibit. (Click the Exhibit tab.)

You plan to deploy the cluster to production. You disable HTTP application routing.

You need to implement application routing that will provide reverse proxy and TLS termination for AKS services by using a single IP address.

What should you do?

A.

Create an AKS Ingress controller.

B.

Install the container network interface (CNI) plug-in.

C.

Create an Azure Standard Load Balancer.

D.

Create an Azure Basic Load Balancer.

Full Access
Go to page: