Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Microsoft Azure Security Engineer Associate AZ-500 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam AZ-500 Premium Access

View all detail and faqs for the AZ-500 exam


790 Students Passed

87% Average Score

92% Same Questions
Viewing page 2 out of 6 pages
Viewing questions 11-20 out of questions
Questions # 11:

You have an Azure subscription that uses Microsoft Defender for Cloud.

You have an Amazon Web Services (AWS) account.

You need to ensure that when you deploy a new AWS Elastic Compute Cloud (EC2) instance, the Microsoft Defender for Servers agent installs automatically.

What should you configure first?

Options:

A.

the log Analytics agent

B.

the Azure Monitor agent

C.

the native cloud connector

D.

the classic cloud connector

Questions # 12:

You have the Azure key vaults shown in the following table.

Question # 12

KV1 stores a secret named Secret1 and a key for a managed storage account named Key1.

You back up Secret1 and Key1.

To which key vaults can you restore each backup? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 12

Options:

Questions # 13:

You plan to use Azure Resource Manager templates to perform multiple deployments of identically configured Azure virtual machines. The password for the administrator account of each deployment is stored as a secret in different Azure key vaults.

You need to identify a method to dynamically construct a resource ID that will designate the key vault

containing the appropriate secret during each deployment. The name of the key vault and the name of the

secret will be provided as inline parameters.

What should you use to construct the resource ID?

Options:

A.

a key vault access policy

B.

a linked template

C.

a parameters file

D.

an automation account

Questions # 14:

You have been tasked with applying conditional access policies for your company’s current Azure Active Directory (Azure AD).

The process involves assessing the risk events and risk levels.

Which of the following is the risk level that should be configured for users that have leaked credentials?

Options:

A.

None

B.

Low

C.

Medium

D.

High

Questions # 15:

You have an Azure subscription named Sub1 that uses Microsoft Defender for Cloud. You have the management group hierarchy shown in the following exhibit.

Question # 15

You create the definitions shown in the following table.

Question # 15

You need to use Defender for Cloud to add a security policy. Which definitions can you use as a security policy?

Options:

A.

Policy1 only

B.

Policy1 and Initiative1 only

C.

Initiative1 and Initiative2 only

D.

Initiative1, Initiative2, and Initiatives only

E.

Policy1, Initiative1, Initiative2, and Initiative3

Questions # 16:

You have a Microsoft Entra tenant that contains the users shown in the following table.

Question # 16

AII the users have devices that contain certificates issued by a certification authority (CA) named ContosoCA. You create a Conditional Access policy that has the following settings:

• Name: CAPoltcy1

• Assignments

o Users and groups: Group1

o Target resources

* Include: All cloud apps

o Access controls

* Grant access: Require multi-factor authentication

o Enable policy: On

You enable and target certificate-based authentication as shown in the Enable and Target exhibit. (Click the Enable and Target tab.)

Question # 16

You configure certificate-based authentication as shown in the Configure exhibit. (Click the Configure tab.)

Question # 16

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Question # 16

Options:

Questions # 17:

Lab Task

Task 2

You need to ensure that the events in the NetworkSecurityGroupRuleCounter log of the VNETOI-Subnet0-NSG network security group (NSG) are stored in the Iogs31330471 Azure Storage account for 30 days.

Options:

Questions # 18:

You have an Azure subscription that contains a user named UseR1. You need to ensure that UseR1 can perform the following tasks:

• Create groups.

• Create access reviews for role-assignable groups.

• Assign Azure AD roles to groups.

The solution must use the principle of least privilege. Which role should you assign to User1?

Options:

A.

Groups administrator

B.

Authentication administrator

C.

Identity Governance Administrator

D.

Privileged role administrator

Questions # 19:

You have an Azure subscription that contains a resource group named RG1 and a security group named ServerAdmins. RG1 contains 10 virtual machines, a virtual network named VNET1, and a network security group JNSG) named NSG1. ServerAdmins can access the virtual machines by using RDP.

You need to ensure that NSG1 only allows RDP connections to the virtual machines for a maximum of 60 minutes when a member of ServerAdmins requests access.

What should you configure?

Options:

A.

an Azure policy assigned to RGl

B.

a just in time (JIT) VM access policy in Microsoft Defender for Cloud

C.

an Azure AD Privileged Identity Management (PiM) role assignment

D.

an Azure Bastion host on VNET1

Questions # 20:

You plan to use Azure Log Analytics to collect logs from 200 servers that run Windows Server 2016.

You need to automate the deployment of the Microsoft Monitoring Agent to all the servers by using an Azure Resource Manager template.

How should you complete the template? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 20

Options:

Viewing page 2 out of 6 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.