Download Microsoft Azure Security Technologies.CertKingdom.AZ-500.2022-11-23.5e.246q.vcex

Download Exam

File Info

Exam Microsoft Azure Security Technologies
Number AZ-500
File Name Microsoft Azure Security Technologies.CertKingdom.AZ-500.2022-11-23.5e.246q.vcex
Size 19.32 Mb
Posted November 23, 2022
Downloads 13
Download Microsoft Azure Security Technologies.CertKingdom.AZ-500.2022-11-23.5e.246q.vcex

How to open VCEX & EXAM Files?

Files with VCEX & EXAM extensions can be opened by ProfExam Simulator.

Purchase

Coupon: MASTEREXAM
With discount: 20%



 
 



Demo Questions

Question 1

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements. 
Your company has an Active Directory forest with a single domain, named weylandindustries.com. They also have an Azure Active Directory (Azure AD) tenant with the same name. 
You have been tasked with integrating Active Directory and the Azure AD tenant. You intend to deploy Azure AD Connect. 
Your strategy for the integration must make sure that password policies and user logon limitations affect user accounts that are synced to the Azure AD tenant, and that the amount of necessary servers are reduced. 
Solution: You recommend the use of pass-through authentication and seamless SSO with password hash synchronization. 
Does the solution meet the goal? 

  • A: Yes 
  • B: No 

Correct Answer: B

For pass-through authentication, you need one or more (we recommend three) lightweight agents installed on existing servers. These agents must have access to your on-premises Active Directory Domain Services, including your on-premises AD domain controllers. They need outbound access to the Internet and access to your domain controllers. For this reason, it's not supported to deploy the agents in a perimeter network. 
Reference: 
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta 




Question 2

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements. 
Your company has an Active Directory forest with a single domain, named weylandindustries.com. They also have an Azure Active Directory (Azure AD) tenant with the same name. 
You have been tasked with integrating Active Directory and the Azure AD tenant. You intend to deploy Azure AD Connect. 
Your strategy for the integration must make sure that password policies and user logon limitations affect user accounts that are synced to the Azure AD tenant, and that the amount of necessary servers are reduced. 
Solution: You recommend the use of federation with Active Directory Federation Services (AD FS). 
Does the solution meet the goal? 

  • A: Yes 
  • B: No 

Correct Answer: B

A federated authentication system relies on an external trusted system to authenticate users. Some companies want to reuse their existing federated system investment with their Azure AD hybrid identity solution. The maintenance and management of the federated system falls outside the control of Azure AD. It's up to the organization by using the federated system to make sure it's deployed securely and can handle the authentication load. 
Reference: 
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta  




Question 3

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements. 
Your company has an Active Directory forest with a single domain, named weylandindustries.com. They also have an Azure Active Directory (Azure AD) tenant with the same name. 
You have been tasked with integrating Active Directory and the Azure AD tenant. You intend to deploy Azure AD Connect. 
Your strategy for the integration must make sure that password policies and user logon limitations affect user accounts that are synced to the Azure AD tenant, and that the amount of necessary servers are reduced. 
Solution: You recommend the use of password hash synchronization and seamless SSO. 
Does the solution meet the goal? 

  • A: Yes 
  • B: No 

Correct Answer: A

Password hash synchronization requires the least effort regarding deployment, maintenance, and infrastructure. This level of effort typically applies to organizations that only need their users to sign in to Office 365, SaaS apps, and other Azure AD-based resources. When turned on, password hash synchronization is part of the Azure AD Connect sync process and runs every two minutes. 
Reference: 
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta  




Question 4

You have been tasked with applying conditional access policies for your company's current Azure Active Directory (Azure AD). 
The process involves assessing the risk events and risk levels. 
Which of the following is the risk level that should be configured for users that have leaked credentials? 

  • A: None 
  • B: Low 
  • C: Medium 
  • D: High 

Correct Answer: D

These six types of events are categorized in to 3 levels of risks - High, Medium & Low: 

      
 
Reference: 
http://www.rebeladmin.com/2018/09/step-step-guide-configure-risk-based-azure-conditional-access-policies/  




Question 5

You have been tasked with applying conditional access policies for your company's current Azure Active Directory (Azure AD). 
The process involves assessing the risk events and risk levels. 
Which of the following is the risk level that should be configured for sign ins that originate from IP addresses with dubious activity? 

  • A: None 
  • B: Low 
  • C: Medium 
  • D: High 

Correct Answer: C

Reference: 
http://www.rebeladmin.com/2018/09/step-step-guide-configure-risk-based-azure-conditional-access-policies/ 
 




Question 6

You have been tasked with configuring an access review, which you plan to assigned to a new collection of reviews. You also have to make sure that the reviews can be reviewed by resource owners. 
You start by creating an access review program and an access review control. 
You now need to configure the Reviewers. 
Which of the following should you set Reviewers to? 

  • A: Selected users. 
  • B: Members (Self). 
  • C: Group Owners. 
  • D: Anyone. 

Correct Answer: C

In the Reviewers section, select either one or more people to review all the users in scope. Or you can select to have the members review their own access. If the resource is a group, you can ask the group owners to review. 

      
 
Reference: 
https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review 
https://docs.microsoft.com/en-us/azure/active-directory/governance/manage-programs-controls  




Question 7

Your company recently created an Azure subscription. You have, subsequently, been tasked with making sure that you are able to secure Azure AD roles by making use of Azure Active Directory (Azure AD) Privileged Identity Management (PIM). 
Which of the following actions should you take FIRST? 

  • A: You should sign up Azure Active Directory (Azure AD) Privileged Identity Management (PIM) for Azure AD roles. 
  • B: You should consent to Azure Active Directory (Azure AD) Privileged Identity Management (PIM). 
  • C: You should discover privileged roles. 
  • D: You should discover resources. 

Correct Answer: B

Reference: 
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-getting-started 
 




Question 8

Your company has an Azure Container Registry. 
You have been tasked with assigning a user a role that allows for the uploading of images to the Azure Container Registry. The role assigned should not require more privileges than necessary. 
Which of the following is the role you should assign? 

  • A: Owner 
  • B: Contributor 
  • C: AcrPush 
  • D: AcrPull 

Correct Answer: C

Reference: 
https://docs.microsoft.com/bs-latn-ba/azure/container-registry/container-registry-roles 
 




Question 9

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements. 
Your Company's Azure subscription includes a virtual network that has a single subnet configured. 
You have created a service endpoint for the subnet, which includes an Azure virtual machine that has Ubuntu Server 18.04 installed. 
You are preparing to deploy Docker containers to the virtual machine. You need to make sure that the containers can access Azure Storage resources and Azure SQL databases via the service endpoint. 
You need to perform a task on the virtual machine prior to deploying containers. 
Solution: You create an application security group. 
Does the solution meet the goal? 

  • A: Yes 
  • B: No 

Correct Answer: B

 




Question 10

You make use of Azure Resource Manager templates to deploy Azure virtual machines. 
You have been tasked with making sure that Windows features that are not in use, are automatically inactivated when instances of the virtual machines are provisioned. 
Which of the following actions should you take? 

  • A: You should make use of Azure DevOps. 
  • B: You should make use of Azure Automation State Configuration. 
  • C: You should make use of network security groups (NSG). 
  • D: You should make use of Azure Blueprints. 

Correct Answer: B

You can use Azure Automation State Configuration to manage Azure VMs (both Classic and Resource Manager), on-premises VMs, Linux machines, AWS VMs, and on-premises physical machines. 
Note: Azure Automation State Configuration provides a DSC pull server similar to the Windows Feature DSCService so that target nodes automatically receive configurations, conform to the desired state, and report back on their compliance. The built-in pull server in Azure Automation eliminates the need to set up and maintain your own pull server. Azure Automation can target virtual or physical Windows or Linux machines, in the cloud or on-premises. 
Reference: 
https://docs.microsoft.com/en-us/azure/automation/automation-dsc-getting-started  










CONNECT US

Facebook

Twitter

PROFEXAM WITH A 20% DISCOUNT

You can buy ProfExam with a 20% discount!



HOW TO OPEN VCEX AND EXAM FILES

Use ProfExam Simulator to open VCEX and EXAM files