Pass the Microsoft Azure Security Engineer Associate AZ-500 Questions and answers with CertsForce

Viewing page 3 out of 6 pages
Viewing questions 21-30 out of questions
Questions # 21:

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these

questions will not appear in the review screen.

You have a hybrid configuration of Azure Active Directory (AzureAD).

You have an Azure HDInsight cluster on a virtual network.

You plan to allow users to authenticate to the cluster by using their on-premises Active Directory credentials.

You need to configure the environment to support the planned authentication.

Solution: You create a site-to-site VPN between the virtual network and the on-premises network.

Does this meet the goal?

Options:

A.

Yes


B.

No


Expert Solution
Questions # 22:

You have an Azure key vault named Vault1 that stores the resources shown in the following table.

Question # 22

Which resources support the creation of a rotation policy?

Options:

A.

Key 1 only


B.

Cert1 only


C.

Key1 and Secret1 only


D.

Key1 and Cert1 only


E.

Secret1 and Cert1 only


F.

Key1, Secret1, and Cert1


Expert Solution
Questions # 23:

You have an Azure subscription named Sub1 that contains the storage accounts shown in the following table

Question # 23

The storage3 storage account is encrypted by using customer-managed keys.

YOU need to enable Microsoft Defender for storage to meet the following requirements.

* The storage1 and storage2 account must be include in the defender for storage requirement.

* The storage3 account must be exclude from the Defender for Storage protections.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and them in the correct order.

Question # 23


Expert Solution
Questions # 24:

You have been tasked with configuring an access review, which you plan to assigned to a new collection of reviews. You also have to make sure that the reviews can be reviewed by resource owners.

You start by creating an access review program and an access review control.

You now need to configure the Reviewers.

Which of the following should you set Reviewers to?

Options:

A.

Selected users.


B.

Members (Self).


C.

Group Owners.


D.

Anyone.


Expert Solution
Questions # 25:

You have an Azure subscription.

You need to deploy an Azure virtual WAN to meet the following requirements:

• Create three secured virtual hubs located in the East US, West US, and North Europe Azure regions.

• Ensure that security rules sync between the regions.

What should you use?

Options:

A.

Azure Firewall Manager


B.

Azure Virtual Network Manager


C.

Azure Network Function Manager


D.

Azure Front Door


Expert Solution
Questions # 26:

You have an Azure Sentinel workspace that has the following data connectors:

    Azure Active Directory Identity Protection

    Common Event Format (CEF)

    Azure Firewall

You need to ensure that data is being ingested from each connector.

From the Logs query window, which table should you query for each connector? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 26


Expert Solution
Questions # 27:

You have an Azure Active Directory (Azure AD) tenant named contoso.com

You need to configure diagnostic settings for contoso.com. The solution must meet the following requirements:

• Retain loqs for two years.

• Query logs by using the Kusto query language

• Minimize administrative effort.

Where should you store the logs?

Options:

A.

an Azure Log Analytics workspace


B.

an Azure event hub


C.

an Azure Storage account


Expert Solution
Questions # 28:

Your company has an Azure subscription named Sub1 that is associated to an Azure Active Directory Azure (Azure AD) tenant named contoso.com.

The company develops a mobile application named App1. App1 uses the OAuth 2 implicit grant type to acquire Azure AD access tokens.

You need to register App1 in Azure AD.

What information should you obtain from the developer to register the application?

Options:

A.

a redirect URI


B.

a reply URL


C.

a key


D.

an application ID


Expert Solution
Questions # 29:

You company has an Azure subscription named Sub1. Sub1 contains an Azure web app named WebApp1 that uses Azure Application Insights. WebApp1 requires users to authenticate by using OAuth 2.0 client secrets.

Developers at the company plan to create a multi-step web test app that preforms synthetic transactions emulating user traffic to Web App1.

You need to ensure that web tests can run unattended.

What should you do first?

Options:

A.

In Microsoft Visual Studio, modify the .webtest file.


B.

Upload the .webtest file to Application Insights.


C.

Register the web test app in Azure AD.


D.

Add a plug-in to the web test app.


Expert Solution
Questions # 30:

You have an Azure Active Directory (Azure AD) tenant that contains two users named User1 and User2 and a registered app named App1.

You create an app-specific role named Role1.

You need to assign Role1 to User1 and enable User2 to request access to App1.

Which two settings should you modify? To answer select the appropriate settings in the answer area

NOTE: Each correct selection is worth one pant.

Question # 30


Expert Solution
Viewing page 3 out of 6 pages
Viewing questions 21-30 out of questions