Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Microsoft Microsoft Certified: Information Security Administrator Associate SC-500 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

You have multiple Microsoft Security Copilot workspaces.

A user named User1 accesses Security Copilot by using the default workspace.

You create a new workspace named Workspace 1 and assign a capacity to Workspace1.

You plan to route Security Copilot agent traffic to Workspace1.

You need to ensure that User1 can use embedded experiences without errors.

What should you do before switching to Workspace1?

Options:

A.

Add User1 to Workspace1.


B.

Assign User1 the Security Operator role in Microsoft Entra.


C.

Disassociate the capacity from the default workspace.


D.

Create a new capacity for Workspace1.


Expert Solution
Questions # 2:

You have an Azure subscription named Sub1 that contains multiple virtual machines.

You have a Microsoft 365 E5 subscription that contains devices onboarded to Microsoft Defender for Endpoint.

You have an on-premises datacenter that contains multiple servers.

You plan to onboard all existing and future on-premises servers to Azure Arc.

You need to ensure that the Azure Arc-enabled servers are protected by using the same security features as the Microsoft 365 devices immediately after the servers are onboarded. The solution must minimize administrative effort.

What should you do?

Options:

A.

Onboard each server to Microsoft Defender for Endpoint by using Group Policy.


B.

Onboard each server to Microsoft Defender for Endpoint by using a local installation script.


C.

For Sub1, enable the Microsoft Defender for Servers plan in Microsoft Defender for Cloud.


D.

Configure an Azure Policy assignment.


Expert Solution
Questions # 3:

You have an Azure subscription named Sub1 that contains a virtual network named VNet1.

VNet1 contains multiple virtual machines, including two virtual machines named VM1 and VM2.

Sub1 is linked to a Microsoft Entra tenant named contoso.com.

A partner company has an Azure subscription named Sub2 that contains a virtual network named VNet2. VNet2 contains a virtual machine named VM3.

Sub2 is linked to a Microsoft Entra tenant named fabrikam.com.

VM1 and VM2 contain data used by an application that runs on VM3.

You need to ensure that VM3 can access VM1 and VM2. The solution must deny VM3 access to any other resources in Sub1.

What should you configure on each virtual network? To answer, drag the components to the correct virtual networks. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 3


Expert Solution
Questions # 4:

You have an Azure virtual network that contains 100 virtual machines and an Azure Firewall instance named FW1.

All the traffic from the virtual machines is routed through FW1.

You need to ensure that FW1 allows access to only a URL of updates contoso.com and blocks all other outbound traffic.

What should you use?

Options:

A.

An inbound NAT rule


B.

An application rule


C.

An outbound NAT rule


D.

A network rule


Expert Solution
Questions # 5:

You have a Microsoft Defender External Attack Surface Management (Defender EASM) resource for a company named Contoso. Ltd.

You need to update the Defender EASM workflow to meet the following requirements:

•Assets from a business domain that Contoso no longer owns must be removed from inventory.

•Findings that do NOT apply to confirmed inventory must NOT affect reported counts.

What should you do for each requirement? To answer, drag the appropriate actions to the correct requirements. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 5


Expert Solution
Questions # 6:

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an automation rule.

Does this meet the goal?

Options:

A.

Yes


B.

No


Expert Solution
Questions # 7:

For each of the following statements, select Yes if the statement is true Otherwise, select No.

Question # 7


Expert Solution
Questions # 8:

You have a Microsoft Copilot Studio agent.

A Microsoft Power Platform administrator configures external threat detection for the agent by using a Microsoft Entra application.

You need to ensure that real-time protection is enabled during agent runtime.

What should you do in the Microsoft Defender portal?

Options:

A.

Configure Microsoft Defender for Cloud Apps session policies.


B.

Connect the Microsoft 365 app connector.


C.

Enable Global Secure Access for Agents.


D.

From Microsoft Sentinel, configure the Microsoft Purview data connector.


Expert Solution
Questions # 9:

You have a Microsoft Defender XDR environment.

You have a Microsoft Power Platform environment where makers publish custom Microsoft Copilot Studio agents.

You need to enable real-time protection so that suspicious tool invocations are blocked before an agent runs actions, and related alerts appear in the Microsoft Defender portal.

What should you do? To answer, drag the appropriate actions to the correct services. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 9


Expert Solution
Questions # 10:

You have a Microsoft Entra tenant that has user consent for applications disabled.

You register an application named App1 that requests the following Microsoft Graph delegated permissions:

•user.Read

•Mail.Read

You need to configure tenant permissions to meet the following requirements:

•Enable users to grant consent for low-risk permissions without administrator interaction.

•Ensure that applications requesting higher-privilege permissions require administrator approval.

What should you do?

Options:

A.

Grant tenant-wide admin consent to App1.


B.

Configure application assignments for App1.


C.

Configure Privileged Identity Management (PIM) role assignments.


D.

Create an app consent policy.


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions