πŸ”

AZ-500 β€” questions

Page 9 of 14 Β· 269 total questions.

Topic 4 Β· Question 273 Β· Select all that apply

You create a new Azure subscription. You need to ensure that you can create custom alert rules in Azure Security Center. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • AOnboard Azure Active Directory (Azure AD) Identity Protection.
  • BCreate an Azure Storage account.
  • CImplement Azure Advisor recommendations.
  • DCreate an Azure Log Analytics workspace. (correct answer)
  • EUpgrade the pricing tier of Security Center to Standard. (correct answer)
Reveal answer & explanation
Correct answer: D, E

The correct answer is D, E. Option D: Create an Azure Log Analytics workspace. Option E: Upgrade the pricing tier of Security Center to Standard.

Explanation

Log Analytics queries collected logs and metrics to investigate and alert on resource behavior.

Topic 4 Β· Question 274

You have an Azure subscription named Sub1 that contains an Azure Log Analytics workspace named LAW1. You have 100 on-premises servers that run Windows Server 2012 R2 and Windows Server 2016. The servers connect to LAW1. LAW1 is configured to collect security-related performance counters from the connected servers. You need to configure alerts based on the data collected by LAW1. The solution must meet the following requirements: β€’ Alert rules must support dimensions. β€’ The time it takes to generate an alert must be minimized. β€’ Alert notifications must be generated only once when the alert is generated and once when the alert is resolved. Which signal type should you use when you create the alert rules?

  • ALog
  • BLog (Saved Query)
  • CMetric (correct answer)
  • DActivity Log
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Metric.

Topic 4 Β· Question 277

You have an Azure subscription named Subscription1 that contains the resources shown in the following table. You need to identify which initiatives and policies you can add to Subscription1 by using Azure Security Center. What should you identify?

  • APolicy1 and Policy2 only
  • BInitiative1 only
  • CInitiative1 and Initiative2 only
  • DInitiative1, Initiative2, Policy1, and Policy2 (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Initiative1, Initiative2, Policy1, and Policy2.

Topic 4 Β· Question 278

You have an Azure resource group that contains 100 virtual machines. You have an initiative named Initiative1 that contains multiple policy definitions. Initiative1 is assigned to the resource group. You need to identify which resources do NOT match the policy definitions. What should you do?

  • AFrom Azure Security Center, view the Regulatory compliance assessment.
  • BFrom the Policy blade of the Azure Active Directory admin center, select Compliance. (correct answer)
  • CFrom Azure Security Center, view the Secure Score.
  • DFrom the Policy blade of the Azure Active Directory admin center, select Assignments.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: From the Policy blade of the Azure Active Directory admin center, select Compliance.

Topic 4 Β· Question 279

You have an Azure subscription named Subscription1. You need to view which security settings are assigned to Subscription1 by default. Which Azure policy or initiative definition should you review?

  • Athe Audit diagnostic setting policy definition
  • Bthe Enable Monitoring in Azure Security Center initiative definition (correct answer)
  • Cthe Enable Azure Monitor for VMs initiative definition
  • Dthe Azure Monitor solution 'Security and Audit' must be deployed policy definition
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: the Enable Monitoring in Azure Security Center initiative definition.

Topic 4 Β· Question 282

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You use Microsoft Defender for Cloud for the centralized policy management of three Azure subscriptions. You use several policy definitions to manage the security of the subscriptions. You need to deploy the policy definitions as a group to all three subscriptions. Solution: You create a policy initiative and an assignment that is scoped to the Tenant Root Group management group. Does this meet the goal?

  • AYes (correct answer)
  • BNo
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Yes.

Topic 4 Β· Question 283

You have an Azure environment. You need to identify any Azure configurations and workloads that are non-compliant with ISO 27001:2013 standards. What should you use?

  • AAzure Sentinel
  • BAzure Active Directory (Azure AD) Identity Protection
  • CMicrosoft Defender for Cloud (correct answer)
  • DMicrosoft Defender for Identity
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Microsoft Defender for Cloud

Explanation

Microsoft Defender for Cloud provides security posture management and threat protection across resources.

Topic 4 Β· Question 287

You have an Azure subscription named Sub1 that contains the virtual machines shown in the following table. You need to ensure that the virtual machines in RG1 have the Remote Desktop port closed until an authorized user requests access. What should you configure?

  • AAzure Active Directory (Azure AD) Privileged Identity Management (PIM)
  • Ban application security group
  • CAzure Active Directory (Azure AD) conditional access
  • Djust in time (JIT) VM access (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: just in time (JIT) VM access.

Topic 4 Β· Question 290

You are troubleshooting a security issue for an Azure Storage account. You enable the diagnostic logs for the storage account. What should you use to retrieve the diagnostics logs?

  • AAzure Security Center
  • BAzure Monitor (correct answer)
  • Cthe Security admin center
  • DAzure Storage Explorer
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Azure Monitor

Explanation

Azure Monitor collects metrics and logs across resources for observability and alerting.

Topic 4 Β· Question 291

You have an Azure subscription that contains the resources shown in the following table. You plan to enable Azure Defender for the subscription. Which resources can be protected by using Azure Defender?

  • AVM1, VNET1, storage1, and Vault1 (correct answer)
  • BVM1, VNET1, and storage1 only
  • CVM1, storage1, and Vault1 only
  • DVM1 and VNET1 only
  • EVM1 and storage1 only
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: VM1, VNET1, storage1, and Vault1.

Topic 4 Β· Question 293

You have an Azure subscription that contains a resource group named RG1 and a security group named ServerAdmins. RG1 contains 10 virtual machines, a virtual network named VNET1, and a network security group (NSG) named NSG1. ServerAdmins can access the virtual machines by using RDP. You need to ensure that NSG1 only allows RDP connections to the virtual machines for a maximum of 60 minutes when a member of ServerAdmins requests access. What should you configure?

  • Aan Azure policy assigned to RG1
  • Ba just in time (JIT) VM access policy in Microsoft Defender for Cloud (correct answer)
  • Can Azure Active Directory (Azure AD) Privileged Identity Management (PIM) role assignment
  • Dan Azure Bastion host on VNET1
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: a just in time (JIT) VM access policy in Microsoft Defender for Cloud

Explanation

Microsoft Defender for Cloud provides security posture management and threat protection across resources.

Topic 4 Β· Question 296

You have an Azure Sentinel deployment. You need to create a scheduled query rule named Rule1. What should you use to define the query rule logic for Rule1?

  • Aa Transact-SQL statement
  • Ba JSON definition
  • CGraphQL
  • Da Kusto query (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: a Kusto query.

Topic 4 Β· Question 297

You have an Azure subscription named Subscription1 that contains a resource group named RG1 and the users shown in the following table. You perform the following tasks: β€’ Assign User1 the Network Contributor role for Subscription1. β€’ Assign User2 the Contributor role for RG1. To Subscription1 and RG1, you assign the following policy definition: External accounts with write permissions should be removed from your subscription. What is the Compliance State of the policy assignments?

  • AThe Compliance State of both policy assignments is Non-compliant. (correct answer)
  • BThe Compliance State of the policy assignment to Subscription1 is Compliant, and the Compliance State of the policy assignment to RG1 is Non-compliant.
  • CThe Compliance State of the policy assignment to Subscription1 is Non-compliant, and the Compliance State of the policy assignment to RG1 is Compliant.
  • DThe Compliance State of both policy assignments is Compliant.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: The Compliance State of both policy assignments is Non-compliant.

Topic 4 Β· Question 299

You have 10 on-premises servers that run Windows Server 2019. You plan to implement Azure Security Center vulnerability scanning for the servers. What should you install on the servers first?

  • Athe Azure Arc enabled servers Connected Machine agent (correct answer)
  • Bthe Microsoft Defender for Endpoint agent
  • Cthe Security Events data connector in Azure Sentinel
  • Dthe Microsoft Endpoint Configuration Manager client
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: the Azure Arc enabled servers Connected Machine agent.

Topic 4 Β· Question 301

You have an Azure subscription name Sub1 that contains an Azure Policy definition named Policy1. Policy1 has the following settings: β€’ Definition location: Tenant Root Group β€’ Category: Monitoring You need to ensure that resources that are noncompliant with Policy1 are listed in the Azure Security Center dashboard. What should you do first?

  • AChange the Category of Policy1 to Security Center.
  • BAdd Policy1 to a custom initiative. (correct answer)
  • CChange the Definition location of Policy1 to Sub1.
  • DAssign Policy1 to Sub1.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Add Policy1 to a custom initiative.

Topic 4 Β· Question 302

You have an Azure subscription. You plan to create a workflow automation in Azure Security Center that will automatically remediate a security vulnerability. What should you create first?

  • Aan automation account
  • Ba managed identity
  • Can Azure logic app (correct answer)
  • Dan Azure function app
  • Ean alert rule
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: an Azure logic app.

Topic 4 Β· Question 309

You are troubleshooting a security issue for an Azure Storage account. You enable the diagnostic logs for the storage account. What should you use to retrieve the diagnostics logs?

  • AAzure Storage Explorer (correct answer)
  • BSQL query editor in Azure
  • CFile Explorer in Windows
  • DAzure Security Center
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Azure Storage Explorer.

Topic 4 Β· Question 310

You are troubleshooting a security issue for an Azure Storage account. You enable Azure Storage Analytics logs and archive it to a storage account. What should you use to retrieve the diagnostics logs?

  • AAzure Cosmos DB explorer
  • BSQL query editor in Azure
  • CAzCopy (correct answer)
  • Dthe Security admin center
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: AzCopy

Explanation

AzCopy is a command-line tool that efficiently copies data to and from Azure Storage.

Topic 4 Β· Question 311 Β· Select all that apply

You have an Azure Sentinel workspace. You need to create a playbook. Which two triggers will start the playbook? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

  • AAn Azure Sentinel scheduled query rule is executed.
  • BAn Azure Sentinel data connector is added.
  • CAn Azure Sentinel alert is generated. (correct answer)
  • DAn Azure Sentinel hunting query result is returned.
  • EAn Azure Sentinel incident is created. (correct answer)
Reveal answer & explanation
Correct answer: C, E

The correct answer is C, E. Option C: An Azure Sentinel alert is generated. Option E: An Azure Sentinel incident is created.

Topic 4 Β· Question 312

You are troubleshooting a security issue for an Azure Storage account. You enable Azure Storage Analytics logs and archive it to a storage account. What should you use to retrieve the diagnostics logs?

  • AAzure Monitor
  • BSQL query editor in Azure
  • CFile Explorer in Windows
  • DAzure Storage Explorer (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Azure Storage Explorer.

Showing questions 161–180 of 269 Β· Page 9 of 14