Download Microsoft.AZ-500.NewDumps.2022-10-04.203q.vcex

Download Exam

File Info

Exam Microsoft Azure Security Technologies
Number AZ-500
File Name Microsoft.AZ-500.NewDumps.2022-10-04.203q.vcex
Size 30 MB
Posted Oct 04, 2022
Download Microsoft.AZ-500.NewDumps.2022-10-04.203q.vcex

How to open VCEX & EXAM Files?

Files with VCEX & EXAM extensions can be opened by ProfExam Simulator.

Purchase

Coupon: MASTEREXAM
With discount: 20%






Demo Questions

Question 1

You need to meet the identity and access requirements for Group1.
What should you do?


  1. Add a membership rule to Group1.
  2. Delete Group1. Create a new group named Group1 that has a membership type of Office 365. Addusers and devices to the group.
  3. Modify the membership rule of Group1.
  4. Change the membership type of Group1 to Assigned. Create two groups that have dynamicmemberships. Add the new groups to Group1.
Correct answer: D
Explanation:
https://learnpros.net/Scenario:Litware identifies the following identity and access requirements: All San Francisco users and their devices must be members of Group1.The tenant currently contain this group:       References:https://learnpros.net/
https://learnpros.net/
Scenario:
Litware identifies the following identity and access requirements: All San Francisco users and their devices must be members of Group1.
The tenant currently contain this group:
       
References:
https://learnpros.net/



Question 2

You need to ensure that the Azure AD application registration and consent configurations meet the identity and access requirements.
What should you use in the Azure portal? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


Correct answer: To work with this question, an Exam Simulator is required.



Question 3

You need to deploy AKS1 to meet the platform protection requirements.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
NOTE: More than one order of answer choices is correct. You will receive credit for any of the correct orders you select.
   


Correct answer: To work with this question, an Exam Simulator is required.
Explanation:
Scenario: Azure AD users must be to authenticate to AKS1 by using their Azure AD credentials.Litewire plans to deploy AKS1, which is a managed AKS (Azure Kubernetes Services) cluster.Step 1: Create a server applicationTo provide Azure AD authentication for an AKS cluster, two Azure AD applications are created. The first application is a server component that provides user authentication.Step 2: Create a client applicationThe second application is a client component that's used when you're prompted by the CLI for authentication. This client application uses the server application for the actual authentication of the credentials provided by the client.Step 3: Deploy an AKS cluster.Use the az group create command to create a resource group for the AKS cluster.Use the az aks create command to deploy the AKS cluster.Step 4: Create an RBAC binding.Before you use an Azure Active Directory account with an AKS cluster, you must create role-binding or cluster role-binding. Roles define the permissions to grant, and bindings apply them to desired users. These assignments can be applied to a given namespace, or across the entire cluster.Reference:https://learnpros.net/
Scenario: Azure AD users must be to authenticate to AKS1 by using their Azure AD credentials.
Litewire plans to deploy AKS1, which is a managed AKS (Azure Kubernetes Services) cluster.
Step 1: Create a server application
To provide Azure AD authentication for an AKS cluster, two Azure AD applications are created. The first application is a server component that provides user authentication.
Step 2: Create a client application
The second application is a client component that's used when you're prompted by the CLI for authentication. This client application uses the server application for the actual authentication of the credentials provided by the client.
Step 3: Deploy an AKS cluster.
Use the az group create command to create a resource group for the AKS cluster.
Use the az aks create command to deploy the AKS cluster.
Step 4: Create an RBAC binding.
Before you use an Azure Active Directory account with an AKS cluster, you must create role-binding or cluster role-binding. Roles define the permissions to grant, and bindings apply them to desired users. These assignments can be applied to a given namespace, or across the entire cluster.
Reference:
https://learnpros.net/



Question 4

You need to deploy Microsoft Antimalware to meet the platform protection requirements.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
   


Correct answer: To work with this question, an Exam Simulator is required.
Explanation:
Scenario: Microsoft Antimalware must be installed on the virtual machines in RG1.RG1 is a resource group that contains Vnet1, VM0, and VM1.Box 1: DeployIfNotExistsDeployIfNotExists executes a template deployment when the condition is met.Azure policy definition AntimalwareIncorrect Answers:Append:Append is used to add additional fields to the requested resource during creation or update. A common example is adding tags on resources such as costCenter or specifying allowed IPs for a storage resource.Deny:Deny is used to prevent a resource request that doesn't match defined standards through a policy definition and fails the request.Box 2: The Create a Managed Identity settingWhen Azure Policy runs the template in the deployIfNotExists policy definition, it does so using a managed identity. Azure Policy creates a managed identity for each assignment, but must have details about what roles to grant the managed identity.Reference:https://learnpros.net/
Scenario: Microsoft Antimalware must be installed on the virtual machines in RG1.
RG1 is a resource group that contains Vnet1, VM0, and VM1.
Box 1: DeployIfNotExists
DeployIfNotExists executes a template deployment when the condition is met.
Azure policy definition Antimalware
Incorrect Answers:
Append:
Append is used to add additional fields to the requested resource during creation or update. A common example is adding tags on resources such as costCenter or specifying allowed IPs for a storage resource.
Deny:
Deny is used to prevent a resource request that doesn't match defined standards through a policy definition and fails the request.
Box 2: The Create a Managed Identity setting
When Azure Policy runs the template in the deployIfNotExists policy definition, it does so using a managed identity. Azure Policy creates a managed identity for each assignment, but must have details about what roles to grant the managed identity.
Reference:
https://learnpros.net/



Question 5

You need to configure SQLDB1 to meet the data and application requirements.
Which three actions should you recommend be performed in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.


Correct answer: To work with this question, an Exam Simulator is required.
Explanation:
https://learnpros.net/
https://learnpros.net/



Question 6

You need to create Role1 to meet the platform protection requirements.
How should you complete the role definition of Role1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


Correct answer: To work with this question, an Exam Simulator is required.
Explanation:
A new custom RBAC role named Role1 must be used to delegate the administration of the managed disks in Resource Group1. Role1 must be available only for Resource Group1.
A new custom RBAC role named Role1 must be used to delegate the administration of the managed disks in Resource Group1. Role1 must be available only for Resource Group1.



Question 7

You need to configure WebApp1 to meet the data and application requirements.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.


  1. Upload a public certificate.
  2. Turn on the HTTPS Only protocol setting.
  3. Set the Minimum TLS Version protocol setting to 1.2.
  4. Change the pricing tier of the App Service plan.
  5. Turn on the Incoming client certificates protocol setting.
Correct answer: BE
Explanation:
Referhttps://learnpros.net/
Refer
https://learnpros.net/



Question 8

You need to ensure that you can meet the security operations requirements.
What should you do first?


  1. Turn on Auto Provisioning in Security Center.
  2. Integrate Security Center and Microsoft Cloud App Security.
  3. Upgrade the pricing tier of Security Center to Standard.
  4. Modify the Security Center workspace configuration.
Correct answer: C
Explanation:
The Standard tier extends the capabilities of the Free tier to workloads running in private and other public clouds, providing unified security management and threat protection across your hybrid cloud workloads. The Standard tier also adds advanced threat detection capabilities, which uses built-in behavioral analytics and machine learning to identify attacks and zero-day exploits, access and application controls to reduce exposure to network attacks and malware, and more.Scenario: Security Operations RequirementsLitware must be able to customize the operating system security configurations in Azure Security Center.References:https://learnpros.net/
The Standard tier extends the capabilities of the Free tier to workloads running in private and other public clouds, providing unified security management and threat protection across your hybrid cloud workloads. The Standard tier also adds advanced threat detection capabilities, which uses built-in behavioral analytics and machine learning to identify attacks and zero-day exploits, access and application controls to reduce exposure to network attacks and malware, and more.
Scenario: Security Operations Requirements
Litware must be able to customize the operating system security configurations in Azure Security Center.
References:
https://learnpros.net/



Question 9

You need to ensure that users can access VM0. The solution must meet the platform protection requirements.
What should you do?


  1. Move VM0 to Subnet1.
  2. On Firewall, configure a network traffic filtering rule.
  3. Assign RT1 to AzureFirewallSubnet.
  4. On Firewall, configure a DNAT rule.
Correct answer: A
Explanation:
Azure Firewall has the following known issue:Conflict with Azure Security Center (ASC) Just-in-Time (JIT) feature.If a virtual machine is accessed using JIT, and is in a subnet with a user-defined route that points to Azure Firewall as a default gateway, ASC JIT doesn't work. This is a result of asymmetric routing  a packet comes in via the virtual machine public IP (JIT opened the access), but the return path is via the firewall, which drops the packet because there is no established session on the firewall.Solution: To work around this issue, place the JIT virtual machines on a separate subnet that doesn't have a user-defined route to the firewall.Scenario:       Following the implementation of the planned changes, the IT team must be able to connect to VM0 by using JIT VM access.       References:https://learnpros.net/
Azure Firewall has the following known issue:
Conflict with Azure Security Center (ASC) Just-in-Time (JIT) feature.
If a virtual machine is accessed using JIT, and is in a subnet with a user-defined route that points to Azure Firewall as a default gateway, ASC JIT doesn't work. This is a result of asymmetric routing  a packet comes in via the virtual machine public IP (JIT opened the access), but the return path is via the firewall, which drops the packet because there is no established session on the firewall.
Solution: To work around this issue, place the JIT virtual machines on a separate subnet that doesn't have a user-defined route to the firewall.
Scenario:
       
Following the implementation of the planned changes, the IT team must be able to connect to VM0 by using JIT VM access.
       
References:
https://learnpros.net/



Question 10

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure Subscription named Sub1.
You have an Azure Storage account named Sa1 in a resource group named RG1.
Users and applications access the blob service and the file service in Sa1 by using several shared access
signatures (SASs) and stored access policies.
You discover that unauthorized users accessed both the file service and the blob service.
You need to revoke all access to Sa1.
Solution: You generate new SASs.
Does this meet the goal?


  1. Yes
  2. No
Correct answer: B
Explanation:
Instead you should create a new stored access policy.To revoke a stored access policy, you can either delete it, or rename it by changing the signed identifier.Changing the signed identifier breaks the associations between any existing signatures and the stored access policy. Deleting or renaming the stored access policy immediately affects all of the shared access signatures associated with it.References:https://learnpros.net/
Instead you should create a new stored access policy.
To revoke a stored access policy, you can either delete it, or rename it by changing the signed identifier.
Changing the signed identifier breaks the associations between any existing signatures and the stored access policy. Deleting or renaming the stored access policy immediately affects all of the shared access signatures associated with it.
References:
https://learnpros.net/









CONNECT US

Facebook

Twitter

PROFEXAM WITH A 20% DISCOUNT

You can buy ProfExam with a 20% discount!



HOW TO OPEN VCEX FILES

Use ProfExam Simulator to open VCEX files