Download Microsoft.AZ-500.NewDumps.2021-07-08.238q.vcex

Download Exam

File Info

Exam Microsoft Azure Security Technologies
Number AZ-500
File Name Microsoft.AZ-500.NewDumps.2021-07-08.238q.vcex
Size 29 MB
Posted Jul 08, 2021
Download Microsoft.AZ-500.NewDumps.2021-07-08.238q.vcex

How to open VCEX & EXAM Files?

Files with VCEX & EXAM extensions can be opened by ProfExam Simulator.

Purchase

Coupon: MASTEREXAM
With discount: 20%






Demo Questions

Question 1

You need to meet the identity and access requirements for Group1. 
What should you do? 
 


  1. Add a membership rule to Group1.
  2. Delete Group1. Create a new group named Group1 that has a group type of Office 365. Add users and devices to the group.
  3. Modify the membership rule of Group1.
  4. Change the membership type of Group1 to Assigned. Create two groups that have dynamic memberships. Add the new groups to Group1.
Correct answer: B
Explanation:
Incorrect Answers:A, C: You can create a dynamic group for devices or for users, but you can't create a rule that contains both users and devices. D: For assigned group you can only add individual members.Scenario: Litware identifies the following identity and access requirements: All San Francisco users and their devices must be members of Group1. The tenant currently contain this group:      References: https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/groups-dynamic-membership https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-groups-create-azure-portal
Incorrect Answers:
A, C: You can create a dynamic group for devices or for users, but you can't create a rule that contains both users and devices. 
D: For assigned group you can only add individual members.
Scenario: 
Litware identifies the following identity and access requirements: All San Francisco users and their devices must be members of Group1. The tenant currently contain this group:
    
References: 
https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/groups-dynamic-membership 
https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-groups-create-azure-portal



Question 2

You need to ensure that the Azure AD application registration and consent configurations meet the identity and access requirements. 
What should you use in the Azure portal? To answer, select the appropriate options in the answer area. 
NOTE: Each correct selection is worth one point.
 


Correct answer: To work with this question, an Exam Simulator is required.
Explanation:
Reference:https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/configure-user-consent
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/configure-user-consent



Question 3

You need to ensure that users can access VM0. The solution must meet the platform protection requirements. 
What should you do? 


  1. Move VM0 to Subnet1.
  2. On Firewall, configure a network traffic filtering rule.
  3. Assign RT1 to AzureFirewallSubnet.
  4. On Firewall, configure a DNAT rule.
Correct answer: A
Explanation:
Azure Firewall has the following known issue:Conflict with Azure Security Center (ASC) Just-in-Time (JIT) feature. If a virtual machine is accessed using JIT, and is in a subnet with a user-defined route that points to Azure Firewall as a default gateway, ASC JIT doesn’t work. This is a result of asymmetric routing – a packet comes in via the virtual machine public IP (JIT opened the access), but the return path is via the firewall, which drops the packet because there is no established session on the firewall. Solution: To work around this issue, place the JIT virtual machines on a separate subnet that doesn’t have a user-defined route to the firewall. Scenario:       Following the implementation of the planned changes, the IT team must be able to connect to VM0 by using JIT VM access.       References: https://docs.microsoft.com/en-us/azure/firewall/overview
Azure Firewall has the following known issue:
Conflict with Azure Security Center (ASC) Just-in-Time (JIT) feature. 
If a virtual machine is accessed using JIT, and is in a subnet with a user-defined route that points to Azure Firewall as a default gateway, ASC JIT doesn’t work. This is a result of asymmetric routing – a packet comes in via the virtual machine public IP (JIT opened the access), but the return path is via the firewall, which drops the packet because there is no established session on the firewall. 
Solution: To work around this issue, place the JIT virtual machines on a separate subnet that doesn’t have a user-defined route to the firewall. 
Scenario: 
    
Following the implementation of the planned changes, the IT team must be able to connect to VM0 by using JIT VM access. 
    
References: https://docs.microsoft.com/en-us/azure/firewall/overview



Question 4

You need to deploy AKS1 to meet the platform protection requirements. 
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. 
NOTE: More than one order of answer choices is correct. You will receive credit for any of the correct orders you select. 


Correct answer: To work with this question, an Exam Simulator is required.
Explanation:
Scenario: Azure AD users must be able to authenticate to AKS1 by using their Azure AD credentials.Litware plans to deploy AKS1, which is a managed AKS (Azure Kubernetes Services) cluster. Step 1: Create a server applicationTo provide Azure AD authentication for an AKS cluster, two Azure AD applications are created. The first application is a server component that provides user authentication. Step 2: Create a client applicationThe second application is a client component that's used when you're prompted by the CLI for authentication. This client application uses the server application for the actual authentication of the credentials provided by the client. Step 3: Deploy an AKS cluster.Use the az group create command to create a resource group for the AKS cluster.  Use the az aks create command to deploy the AKS cluster. Step 4: Create an RBAC binding.Before you use an Azure Active Directory account with an AKS cluster, you must create role-binding or cluster role-binding. Roles define the permissions to grant, and bindings apply them to desired users. These assignments can be applied to a given namespace, or across the entire cluster. Reference:https://docs.microsoft.com/en-us/azure/aks/azure-ad-integration
Scenario: Azure AD users must be able to authenticate to AKS1 by using their Azure AD credentials.
Litware plans to deploy AKS1, which is a managed AKS (Azure Kubernetes Services) cluster. 
Step 1: Create a server application
To provide Azure AD authentication for an AKS cluster, two Azure AD applications are created. The first application is a server component that provides user authentication. 
Step 2: Create a client application
The second application is a client component that's used when you're prompted by the CLI for authentication. This client application uses the server application for the actual authentication of the credentials provided by the client. 
Step 3: Deploy an AKS cluster.
Use the az group create command to create a resource group for the AKS cluster.  
Use the az aks create command to deploy the AKS cluster. 
Step 4: Create an RBAC binding.
Before you use an Azure Active Directory account with an AKS cluster, you must create role-binding or cluster role-binding. Roles define the permissions to grant, and bindings apply them to desired users. 
These assignments can be applied to a given namespace, or across the entire cluster. 
Reference:
https://docs.microsoft.com/en-us/azure/aks/azure-ad-integration



Question 5

You need to deploy Microsoft Antimalware to meet the platform protection requirements. 
What should you do? To answer, select the appropriate options in the answer area. 
NOTE: Each correct selection is worth one point.
 


Correct answer: To work with this question, an Exam Simulator is required.
Explanation:
Scenario: Microsoft Antimalware must be installed on the virtual machines in RG1.RG1 is a resource group that contains Vnet1, VM0, and VM1. Box 1: DeployIfNotExistsDeployIfNotExists executes a template deployment when the condition is met. Azure policy definition Antimalware Incorrect Answers:Append:Append is used to add additional fields to the requested resource during creation or update. A common example is adding tags on resources such as costCenter or specifying allowed IPs for a storage resource. Deny:Deny is used to prevent a resource request that doesn't match defined standards through a policy definition and fails the request. Box 2: The Create a Managed Identity settingWhen Azure Policy runs the template in the deployIfNotExists policy definition, it does so using a managed identity. Azure Policy creates a managed identity for each assignment, but must have details about what roles to grant the managed identity. Reference:https://docs.microsoft.com/en-us/azure/governance/policy/concepts/effects
Scenario: Microsoft Antimalware must be installed on the virtual machines in RG1.
RG1 is a resource group that contains Vnet1, VM0, and VM1. 
Box 1: DeployIfNotExists
DeployIfNotExists executes a template deployment when the condition is met. 
Azure policy definition Antimalware 
Incorrect Answers:
Append:
Append is used to add additional fields to the requested resource during creation or update. A common example is adding tags on resources such as costCenter or specifying allowed IPs for a storage resource. 
Deny:
Deny is used to prevent a resource request that doesn't match defined standards through a policy definition and fails the request. 
Box 2: The Create a Managed Identity setting
When Azure Policy runs the template in the deployIfNotExists policy definition, it does so using a managed identity. Azure Policy creates a managed identity for each assignment, but must have details about what roles to grant the managed identity. 
Reference:
https://docs.microsoft.com/en-us/azure/governance/policy/concepts/effects



Question 6

You need to meet the technical requirements for VNetwork1. 
What should you do first?


  1. Create a new subnet on VNetwork1.
  2. Remove the NSGs from Subnet11 and Subnet13.
  3. Associate an NSG to Subnet12.
  4. Configure DDoS protection for VNetwork1.
Correct answer: A
Explanation:
From scenario: Deploy Azure Firewall to VNetwork1 in Sub2.Azure firewall needs a dedicated subnet named AzureFirewallSubnet. References:https://docs.microsoft.com/en-us/azure/firewall/tutorial-firewall-deploy-portal
From scenario: Deploy Azure Firewall to VNetwork1 in Sub2.
Azure firewall needs a dedicated subnet named AzureFirewallSubnet. 
References:
https://docs.microsoft.com/en-us/azure/firewall/tutorial-firewall-deploy-portal



Question 7

What is the membership of Group1 and Group2? To answer, select the appropriate options in the answer area. 
NOTE: Each correct selection is worth one point.
 


Correct answer: To work with this question, an Exam Simulator is required.
Explanation:
Box 1: User1, User2, User3, User4Contains "ON" is true for Montreal (User1), MONTREAL (User2), London (User 3), and Ontario (User4) as string and regex operations are not case sensitive. Box 2: Only User3Match "*on" is only true for London (User3) as ‘London’ is the only word that ends with ‘on’. Scenario:Contoso.com contains the users shown in the following table.               Contoso.com contains the security groups shown in the following table.               References:https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/groups-dynamic-membership
Box 1: User1, User2, User3, User4
Contains "ON" is true for Montreal (User1), MONTREAL (User2), London (User 3), and Ontario (User4) as string and regex operations are not case sensitive. 
Box 2: Only User3
Match "*on" is only true for London (User3) as ‘London’ is the only word that ends with ‘on’. 
Scenario:
Contoso.com contains the users shown in the following table. 
            
Contoso.com contains the security groups shown in the following table. 
            
References:
https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/groups-dynamic-membership



Question 8

You are evaluating the security of the network communication between the virtual machines in Sub2. 
For each of the following statements, select Yes if the statement is true. Otherwise, select No. 
NOTE: Each correct selection is worth one point.
 


Correct answer: To work with this question, an Exam Simulator is required.
Explanation:
Box 1: Yes. All traffic is allowed out to the Internet so you can ping the public IP.NSG1, NSG2, NSG3, and NSG4 have the outbound security rules shown in the following table.               Box 2: Yes. VM3 is on Subnet12. There is no NSG attached to Subnet12 so the traffic will be allowed by default.                            Box 3: No (because VM5 is in a separate VNet).Note: Sub2 contains the virtual machines shown in the following table.                          
Box 1: Yes. All traffic is allowed out to the Internet so you can ping the public IP.
NSG1, NSG2, NSG3, and NSG4 have the outbound security rules shown in the following table. 
            
Box 2: Yes. VM3 is on Subnet12. There is no NSG attached to Subnet12 so the traffic will be allowed by default. 
            
            
Box 3: No (because VM5 is in a separate VNet).
Note: Sub2 contains the virtual machines shown in the following table.
            
            



Question 9

You are evaluating the security of VM1, VM2, and VM3 in Sub2.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.


Correct answer: To work with this question, an Exam Simulator is required.
Explanation:
VM1: Yes. NSG2 applies to VM1 and this allows inbound traffic on port 80.VM2: No. NSG2 and NSG1 apply to VM2.  NSG2 allows the inbound traffic on port 80 but NSG1 does not allow it. VM3: Yes.  There are no NSGs applying to VM3 so all ports will be open. VM3: Yes.  
VM1: Yes. NSG2 applies to VM1 and this allows inbound traffic on port 80.
VM2: No. NSG2 and NSG1 apply to VM2.  NSG2 allows the inbound traffic on port 80 but NSG1 does not allow it. 
VM3: Yes.  There are no NSGs applying to VM3 so all ports will be open. VM3: Yes.  



Question 10

You assign User8 the Owner role for RG4, RG5, and RG6. 
In which resource groups can User8 create virtual networks and NSGs? To answer, select the appropriate options in the answer area. 
NOTE: Each correct selection is worth one point.
 


Correct answer: To work with this question, an Exam Simulator is required.
Explanation:
Box 1: RG4 onlyThe policy does not allow the creation of virtual networks in RG5 or RG6. Box 2: The policy does not allow the creation of NSGs in RG5.       References: https://docs.microsoft.com/en-us/azure/governance/policy/overview
Box 1: RG4 only
The policy does not allow the creation of virtual networks in RG5 or RG6. Box 2: The policy does not allow the creation of NSGs in RG5. 
    
References: https://docs.microsoft.com/en-us/azure/governance/policy/overview









CONNECT US

Facebook

Twitter

PROFEXAM WITH A 20% DISCOUNT

You can buy ProfExam with a 20% discount!



HOW TO OPEN VCEX FILES

Use ProfExam Simulator to open VCEX files