Pass the Microsoft Azure Security Engineer Associate AZ-500 Questions and answers with CertsForce

Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions
Questions # 31:

You need to implement the planned change for WAF1.

The solution must minimize administrative effort

What should you do?

Options:

A.

Create an Azure policy.


B.

Modify the Azure-managed DRS.


C.

Add a custom rule.


D.

Modify the Bot Manager 1.1 rule set.


Expert Solution
Questions # 32:

You need to recommend an encryption solution for the planned ExpressRoute implementation. The solution must meet the technical requirements.

Which ExpressRoute circuit should you recommend for each type of encryption? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 32


Expert Solution
Questions # 33:

You need to implement the planned change for SQLdb1.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

Create a compliance policy.


B.

Configure Microsoft Entra authentication for SQLServer1.


C.

Create a Conditional Access policy.


D.

Configure a user-assigned managed identity for SQLdb1.


E.

Configure Federated client identity for SQLdb1.


Expert Solution
Questions # 34:

You need to delegate a user to implement the planned change for Defender for Cloud.

The solution must follow the principle of least privilege.

Which user should you choose?

Options:

A.

Admin1


B.

Admin2


C.

Admin3


D.

Admin4


Expert Solution
Questions # 35:

You need to implement the planned change for VM1 to access storage1.

The solution must meet the technical requirements.

What should you do first?

Options:

A.

Configure a system-assigned managed identity on VM1.


B.

Configure federated identity credentials for ID1.


C.

Assign the Storage Blob Data Reader role to storage 1.


D.

Assign ID1 to VM1.


E.

Add a role assignment condition to storage1.


Expert Solution
Questions # 36:

You implement the planned changes for the key vaults.

To which key vaults can you restore AKV1 backups?

Options:

A.

AKV4only


B.

AKV3 and AKV4 only


C.

AKV4 and AKV5 only


D.

AKV2, AKV3, and AKV4 only


E.

AKV2, AKV3, AKV4, and AKV5


Expert Solution
Questions # 37:

You need to configure the AKS1 and ID1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.

Which role should you assign to each identity? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 37


Expert Solution
Questions # 38:

You plan to configure Azure Disk Encryption for VM4. Which key vault can you use to store the encryption key?

Options:

A.

KeyVault1


B.

KeyVault3


C.

KeyVault2


Expert Solution
Questions # 39:

You need to delegate the creation of RG2 and the management of permissions for RG1. Which users can perform each task? To answer select the appropriate options in the answer area. NOTE: Each correct selection is worth one point

Question # 39


Expert Solution
Questions # 40:

You plan to implement JIT VM access. Which virtual machines will be supported?

Options:

A.

VM1 and VM3 only


B.

VM1. VM2. VM3, and VM4


C.

VM2, VM3, and VM4 only


D.

VM1 only


Expert Solution
Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions