Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Microsoft Microsoft Certified: Information Security Administrator Associate SC-500 Questions and answers with CertsForce

Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions
Questions # 1:

You have a Microsoft Sentinel workspace named Workspace1

You have 100 on-premises servers that run Linux and have the Azure Monitor Agent installed.

You need to collect Syslog events from the Linux servers. The solution must meet the following requirements:

•Ensure that filtering occurs before data is written to Workspace1

•Reduce ingestion costs by excluding low value Syslog messages.

What should you include in the solution?

Options:

A.

An Advanced Security Information Model (ASIM) parser


B.

A data collection rule (DCR)


C.

An analytics rule


D.

A table-level filter and split transformation


Expert Solution
Questions # 2:

You have 15 Azure virtual machines in a resource group named RG1.

All the virtual machines run identical applications.

You need to prevent unauthorized applications and malware from funning on the virtual machines. Authorized applications must be able to run on the virtual machines.

What should you do?

Options:

A.

Apply a resource lock to RG1.


B.

From Microsoft Defender for Cloud, configure adaptive application controls.


C.

Configure Microsoft Entra ID Protection.


D.

Apply an Azure policy to RG1.


Expert Solution
Questions # 3:

An application run2 on VM1 and VM2. The application is being migrated from storage account key authentication to Microsoft Entra authentication.

You review the current configuration and identify the following:

• VM1 and VM2 each have a system-assigned managed identity.

• Each application instance requests tokens by using only the local system-assigned managed identity.

• Network access to storage 1 from VMI and VM2 is allowed.

• No Azure RBAC data roles are assigned to the managed identities on storage1.

You need to enable the application on VM1 and VM2 to read and write blob data in storage1 by using Microsoft Entra authentication without changing how the application requests tokens.

Solution: You create a private endpoint for the blob service of storage1.

Does this meet the goal?

Options:

A.

Yes


B.

No


Expert Solution
Questions # 4:

You have an Azure virtual network named VNet1 that contains a subnet named Subnet1.

You create a storage account named storage1.

You need to ensure that access to storage1 can be managed only by a network security group (NSG) linked to Subnet1.

What should you use?

Options:

A.

an Azure Private Link service


B.

a service endpoint


C.

a private endpoint


D.

a user-defined route (UDR)


Expert Solution
Questions # 5:

You have an Azure subscription that contains a user named User1 and an Azure Container Registry named ContReg1.

You enable content trust for ContReg1.

You need to ensure that User1 can create trusted images in ContReg1 The solution must use the principle of least privilege.

Which two roles should you assign to User1? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

AcrQuarantineWriter


B.

Contributor


C.

AcrQuarantineReader


D.

AcrPush


E.

AcrImageSigner


Expert Solution
Questions # 6:

You have a Microsoft 365 tenant that has Microsoft 365 Copilot enabled for a pilot group.

Users frequently generate responses based on Microsoft Teams chats and Microsoft SharePoint Online sites.

You use Microsoft Purview Data Security Posture Management (DSPM) to identify inversharing risks and create policies based on the recommendations.

You need to manage and edit the policies created by DSPM

Which Microsoft Purview solution should you use?

Options:

A.

Insider Risk Management


B.

Data Loss Prevention


C.

information Protection


D.

Communication Compliance


Expert Solution
Questions # 7:

You have an Azure environment.

You need to identity any Azure configurations and workloads that are non-compliant with ISO 27001:2013 standards. What should you use?

Options:

A.

Microsoft Defender for Cloud


B.

Microsoft Defender for Identity


C.

Microsoft Entra ID Protection


D.

Microsoft Sentinel


Expert Solution
Questions # 8:

You have an Azure subscription that has the Microsoft Defender for Cloud Foundational Cloud Security Posture Management (CSPM) plan enabled.

You have an Amazon Web Services (AWS) account connected to Defender for Cloud for posture management.

In Defender for Cloud, security recommendations for the resources in Azure and AWS have a risk level of Not evaluated.

You need to ensure that Defender for Cloud assigns a risk level to the recommendations.

What should you do?

Options:

A.

Onboard all the virtual machines in the AWS account to Azure Arc.


B.

Enable Microsoft Defender for Servers Plan 2.


C.

Assign the CIS AWS Foundations v3.0.0 standard to the AWS account.


D.

Enable the Defender CSPM plan.


Expert Solution
Questions # 9:

You have an Azure subscription named Sub1 that contains multiple virtual machines.

You have a Microsoft 365 E5 subscription that contains devices onboarded to Microsoft Defender for Endpoint.

You have an on-premises datacenter that contains multiple servers.

You plan to onboard all existing and future on-premises servers to Azure Arc.

You need to ensure that the Azure Arc-enabled servers are protected by using the same security features as the Microsoft 365 devices immediately after the servers are onboarded. The solution must minimize administrative effort.

What should you do?

Options:

A.

Onboard each server to Microsoft Defender for Endpoint by using Group Policy.


B.

Onboard each server to Microsoft Defender for Endpoint by using a local installation script.


C.

For Sub1, enable the Microsoft Defender for Servers plan in Microsoft Defender for Cloud.


D.

Configure an Azure Policy assignment.


Expert Solution
Questions # 10:

You plan to deploy Microsoft 365 Copilot

You discover that Copilot can access sensitive information in your Microsoft SharePoint Online libraries. You need to automatically identify which SharePoint Online content has be*»n shared between all internal users-What should you create?

Options:

A.

a Conditional Access policy that requires multifactor authentication (MFA) for SharePoint Online


B.

a Microsoft Purview Data Security Posture Management (DSPM) remediation action


C.

a Microsoft Purview data loss prevention IDLP) policy in audit mode for SharePoint Online


D.

a SharePoint Advanced Management (SAM) Data access governance report


Expert Solution
Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions