πŸ”

AZ-500 β€” questions

Page 5 of 14 Β· 269 total questions.

Topic 2 Β· Question 122

You have an Azure subscription that contains an Azure Files share named share1 and a user named User1. Identity-based authentication is configured for share1. User1 attempts to access share1 from a Windows 10 device by using SMB. Which type of token will Azure Files use to authorize the request?

  • AOAuth 2.0
  • BJSON Web Token (JWT)
  • CSAML
  • DKerberos (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Kerberos.

Topic 2 Β· Question 124

You have an Azure subscription linked to an Azure Active Directory Premium Plan 1 tenant. You plan to implement Azure Active Directory (Azure AD) Identity Protection. You need to ensure that you can configure a user risk policy and a sign-in risk policy. What should you do first?

  • APurchase Azure Active Directory Premium Plan 2 licenses for all users. (correct answer)
  • BRegister all users for Azure Multi-Factor Authentication (MFA).
  • CEnable security defaults for Azure Active Directory.
  • DEnable enhanced security features in Microsoft Defender for Cloud.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Purchase Azure Active Directory Premium Plan 2 licenses for all users.

Topic 2 Β· Question 127

You have an Azure subscription. You plan to deploy a new Conditional Access policy named CAPolicy1. You need to use the What if tool to evaluate how CAPolicy1 wall affect users. The solution must minimize the impact of CAPolicy1 on the users. To what should you set the Enable policy setting for CAPolicy1?

  • AOff
  • BOn
  • CReport only (correct answer)
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Report only.

Topic 2 Β· Question 128

You have an Azure Active Directory (Azure AD) tenant that contains 500 users and an administrative unit named AU1. From the Azure Active Directory admin center, you plan to add the users to AU1 by using Bulk add members. You need to create and upload a file for the bulk add. What should you include in the file?

  • Aonly the display name of each user
  • Bonly the user principal name (UPN) of each user (correct answer)
  • Conly the user principal name (UPN) and display name of each user
  • Donly the user principal name (UPN) and object identifier of each user
  • Eonly the object identifier of each user
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: only the user principal name (UPN) of each user.

Topic 2 Β· Question 130

You have an Azure subscription that contains a user named User1. You need to ensure that User1 can create managed identities. The solution must use the principle of least privilege. What should you do?

  • ACreate a management group and assign User1 the Hybrid Identity Administrator Azure Active Directory (Azure AD) role.
  • BCreate a management group and assign User1 the Managed Identity Operator role.
  • CCreate a resource group and assign User1 to the Managed Identity Contributor role. (correct answer)
  • DCreate an organizational unit (OU) and assign User1 the User administrator Azure Active Directory (Azure AD) role.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Create a resource group and assign User1 to the Managed Identity Contributor role.

Explanation

A Managed Identity lets Azure resources authenticate to services without storing credentials. A Resource Group is a logical container that groups related resources for shared lifecycle and access control.

Topic 2 Β· Question 133

You have an Azure AD tenant. The tenant contains users that are assigned Azure AD Premium P2 licenses. You have a partner company that has a domain named fabrikam.com. The fabrikam.com domain contains a user named User1. User1 has an email address of [email protected] You need to provide User1 with access to the resources in the tenant. The solution must meet the following requirements: β€’ User1 must be able to sign in by using the [email protected] credentials. β€’ You must be able to grant User1 access to the resources in the tenant. β€’ Administrative effort must be minimized. What should you do?

  • ACreate a user account for User1.
  • BTo the tenant, add fabrikam.com as a custom domain.
  • CCreate an invite for User1. (correct answer)
  • DSet Enable guest self-service sign up via user flows to Yes for the tenant.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Create an invite for User1.

Topic 2 Β· Question 134

You have an Azure AD tenant that contains the identities shown in the following table. You plan to implement Azure AD Identity Protection. What is the maximum number of user risk policies you can configure?

Exhibit 1 for question 134
  • A1 (correct answer)
  • B90
  • C200
  • D265
  • E1000
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: 1.

Topic 2 Β· Question 135

You have an Azure subscription that contains a resource group named RG1 and the identities shown in the following table. You assign Group4 the Contributor role for RG1. Which identities can you add to Group4 as members?

Exhibit 1 for question 135
  • AUser1 only (correct answer)
  • BUser1 and Group3 only
  • CUser1, Group1, and Group3 only
  • DUser1, Group2, and Group3 only
  • EUser1, Group1, Group2, and Group3
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: User1 only.

Topic 2 Β· Question 137

You have an Azure subscription that is linked to an Azure AD tenant and contains the resources shown in the following table. Which resources can be assigned the Contributor role for VM1?

Exhibit 1 for question 137
  • AManaged1 and App1 only (correct answer)
  • BGroup1 and Managed1 only
  • CGroup1, Managed1, and VM2 only
  • DGroup1, Managed1, VM1, and App1 only
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Managed1 and App1 only.

Topic 2 Β· Question 141 Β· Select all that apply

You have an Azure subscription that contains a web app named App1. Users must be able to select between a Google identity or a Microsoft identity when authenticating to App1. You need to add Google as an identity provider in Azure AD. Which two pieces of information should you configure? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • Aa client ID (correct answer)
  • Ba tenant name
  • Cthe endpoint URL of an application
  • Da tenant ID
  • Ea client secret (correct answer)
Reveal answer & explanation
Correct answer: A, E

The correct answer is A, E. Option A: a client ID Option E: a client secret.

Topic 2 Β· Question 142

You have an Azure subscription that contains a user named User1. You need to ensure that User1 can perform the following tasks: β€’ Create groups. β€’ Create access reviews for role-assignable groups. β€’ Assign Azure AD roles to groups. The solution must use the principle of least privilege. Which role should you assign to User1?

  • AGroups administrator
  • BAuthentication administrator
  • CIdentity Governance Administrator
  • DPrivileged role administrator (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Privileged role administrator.

Topic 2 Β· Question 146

You have an Azure subscription that uses Azure AD Privileged Identity Management (PIM). A user named User1 is eligible for the Billing administrator role. You need to ensure that the role can only be used for a maximum of two hours. What should you do?

  • ACreate a new access review.
  • BEdit the role assignment settings.
  • CUpdate the end date of the user assignment.
  • DEdit the role activation settings. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Edit the role activation settings.

Topic 2 Β· Question 148

You have an Azure subscription that contains a user named User1 and a storage account that hosts a blob container named blob1. You need to grant User1 access to blob1. The solution must ensure that the access expires after six days. What should you use?

  • Aa shared access signature (SAS) (correct answer)
  • Brole-based access control (RBAC)
  • Ca shared access policy
  • Da managed identity
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: a shared access signature (SAS).

Topic 2 Β· Question 149 Β· Select all that apply

You have an Azure subscription linked to an Azure AD tenant named contoso.com. Contoso.com contains a user named User1 and an Azure web app named App1. You plan to enable User1 to perform the following tasks: β€’ Configure contoso.com to use Microsoft Entra Verified ID. β€’ Register App1 in contoso.com. You need to identify which roles to assign to User1. The solution must use the principle of least privilege. Which two roles should you identify? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • AAuthentication Policy Administrator (correct answer)
  • BAuthentication Administrator
  • CCloud App Security Administrator
  • DApplication Administrator (correct answer)
  • EUser Administrator
Reveal answer & explanation
Correct answer: A, D

The correct answer is A, D. Option A: Authentication Policy Administrator Option D: Application Administrator.

Topic 2 Β· Question 150

You have an Azure AD tenant. You plan to implement an authentication solution to meet the following requirements: β€’ Require number matching. β€’ Display the geographical location when signing in. Which authentication method should you include in the solution?

  • AMicrosoft Authenticator (correct answer)
  • BFIDO2 security key
  • CSMS
  • DTemporary Access Pass
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Microsoft Authenticator.

Topic 2 Β· Question 151

Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant. You plan to implement single sign-on (SSO) for Azure AD resources. You need to configure an Intranet Zone setting for all users by using a Group Policy Object (GPO). Which setting should you configure?

  • ALogon options
  • BAllow updates to status bar via script (correct answer)
  • CAllow active scripting
  • DAccess data sources across domains
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Allow updates to status bar via script.

Topic 2 Β· Question 153

You have an Azure AD tenant. You need to ensure that users cannot create passwords containing a variation of the word contoso. What should you configure?

  • AMicrosoft Entra Verified ID
  • BMicrosoft Entra Identity Governance
  • CAzure AD Privileged Identity Management (PIM)
  • DAzure AD Password Protection (correct answer)
  • EAzure AD Identity Protection
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Azure AD Password Protection

Explanation

Azure Active Directory (Microsoft Entra ID) provides identity, single sign-on, and conditional access.

Topic 2 Β· Question 159

You have a Microsoft Entra tenant named contoso.com. You plan to collaborate with a partner organization that has a Microsoft Entra tenant named fabrikam.com. Fabrikam.com uses the following identity providers: β€’ Google Cloud Platform (GCP) β€’ Microsoft accounts β€’ Microsoft Entra ID You need to configure the Cross-tenant access settings for B2B collaboration. Which identity providers support cross-tenant access?

  • AMicrosoft Entra ID only (correct answer)
  • BGCP and Microsoft Entra ID only
  • CMicrosoft accounts and Microsoft Entra ID only
  • DGCP, Microsoft accounts, and Microsoft Entra ID
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Microsoft Entra ID only

Explanation

Microsoft Entra ID (formerly Azure AD) is the managed identity and access management service for authentication and authorization.

Topic 2 Β· Question 160

You have a Microsoft Entra tenant named contoso.com. You have a partner company that has a Microsoft Entra tenant named fabrikam.com. You need to ensure that when a user in fabrikam.com attempts to access the resources in contoso.com, the user only receives a single Microsoft Entra Multi-Factor Authentication (MFA) prompt. The solution must minimize administrative effort. What should you do?

  • AFrom the Azure portal of contoso.com, configure the inbound access default settings. (correct answer)
  • BFrom the Azure portal of contoso.com, configure the External collaboration settings.
  • CFrom the Azure portal of contoso.com, configure the outbound access default settings.
  • DFrom the Azure portal of fabrikam.com, configure the outbound access default settings.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: From the Azure portal of contoso.com, configure the inbound access default settings.

Topic 2 Β· Question 163

You have a Microsoft Entra tenant that uses Microsoft Entra Permissions Management and contains the accounts shown in the following table: Which accounts will be listed as assigned to highly privileged roles on the Azure AD insights tab in the Entra Permissions Management portal?

Exhibit 1 for question 163
  • AAdmin1 only
  • BAdmin2 and Admin3 only
  • CAdmin2 and Admin4 only
  • DAdmin1, Admin2, and Admin3 only (correct answer)
  • EAdmin2, Admin3, and Admin4 only
  • FAdmin1, Admin2, Admin3, and Admin4
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Admin1, Admin2, and Admin3 only.

Showing questions 81–100 of 269 Β· Page 5 of 14