Weekend Sale Special Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: CFsave75

Pass the Microsoft Microsoft Certified: Information Security Administrator Associate SC-500 Questions and answers with CertsForce

Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
Questions # 11:

You have the Azure key vaults shown in the following table.

Question # 11

KV1 stores a secret named Secret1 and a key for a managed storage account named Key1.

You back up Secret1 and Key1.

To which key vaults can you restore each backup? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 11


Expert Solution
Questions # 12:

You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.

You need to configure a solution that automates the remediation of malware detected in storage1.

What should you include in the solution?

Options:

A.

Application Insights


B.

Azure Event Hubs


C.

Azure Event Grid


D.

Azure Policy


Expert Solution
Questions # 13:

You have an Azure subscription that contains a blob container named cont1. Con1 ' has the access policies shown in the following exhibit.

Question # 13

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Question # 13


Expert Solution
Questions # 14:

You have an Azure subscription named Sub1. Sub1 contains 20 virtual machines that run Windows Server.

Sub1 has the Microsoft Defender for Cloud Defender Cloud Security Posture Management (CSPM) plan enabled.

You need to ensure that all the virtual machines are scanned automatically for known security flaws and misconfigurations.

What should you use?

Options:

A.

Attack path analysis


B.

Microsoft Cloud Security Benchmark (MCSB)


C.

Cloud security explorer


D.

Just-in-time (JIT) VM access


E.

Vulnerability assessment on the virtual machines


Expert Solution
Questions # 15:

You have an Azure subscription that contains the following servers:

•200 virtual machines that run either Windows Server or Ubuntu Server

•50 Azure Arc enabled servers

You use Azure Policy to manage compliance across all the servers.

You need to enforce an organization-specific security baseline. The solution must meet the following requirements:

•Customize a built-in security baseline.

•Ensure that configuration changes to the servers are enforced automatically after the security baseline is deployed.

♦Minimize administrative effort.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 15


Expert Solution
Questions # 16:

User1 has requested to use the AI Administrator role.

Which approvers can approve the request, and how long will User1 be an AI administrator after the role is approved? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 16


Expert Solution
Questions # 17:

You need to implement the function apps to meet the technical requirements.

Which apps should you include in the implementation?

Options:

A.

Fa1 and Fa2 only


B.

Fa2 and Fa3 only


C.

Fa1 and Fa3 only


D.

Fa1, Fa2, and Fa3


Expert Solution
Questions # 18:

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an automation rule.

Does this meet the goal?

Options:

A.

Yes


B.

No


Expert Solution
Questions # 19:

You have an Azure subscription named Sub1 that contains multiple virtual machines. Sub1 has the Microsoft Defender Cloud Security Posture Management (CSPM) plan enabled.

You discover that Defender for Cloud fails to identify plaintext connection strings and SSH keys stored on the virtual machines.

You need to ensure that secrets can be identified on the virtual machines.

What should you do?

Options:

A.

Configure the Defender for Cloud data connector in Microsoft Sentinel.


B.

Enable agentless machine scanning.


C.

Deploy the Azure Monitor Agent to all the virtual machines.


D.

Enable Microsoft Defender for Key Vault.


Expert Solution
Questions # 20:

You have an Azure subscription named Sub1 that contains multiple virtual machines and an Azure key vault named KV1.

Each virtual machine has a system-assigned managed identity. Sub1 has Microsoft Defender for Servers enabled. Defender for Servers has agentless scanning enabled.

Some virtual machines use managed disks that are encrypted by using customer-managed keys stored in KV1.

You discover that the affected virtual machines fail to return agentless scanning results in Microsoft Defender for Cloud.

You need to ensure that agentless scanning can analyze the virtual machines.

What should you do?

Options:

A.

Assign each virtual machine managed identity the Key Vault Reader role for KV1.


B.

Assign the scanning service the Key Vault Secrets User role for KV1.


C.

Enable Microsoft Defender for Key Vault for Sub1.


D.

Enable just-in-time (JIT) VM access for the affected virtual machines.


E.

Assign the scanning service the Key Vault Crypto Service Encryption User role for KV1


Expert Solution
Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions