Month End Sale Special Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = drift75

Pass the Microsoft Certified: Information Security Administrator Associate SC-500 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam SC-500 Premium Access

View all detail and faqs for the SC-500 exam


0 Students Passed

0% Average Score

0% Same Questions
Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
Questions # 21:

You have a Microsoft Entra tenant that contains a group named Group1.

You plan to target Group1 to use the Microsoft Authenticator authentication method.

You need to ensure that the members in Group1 can use the Authenticator app as their primary authentication method.

What should you do?

Options:

A.

Enable one-time passcodes in Authenticator for Group1.

B.

Revoke the sessions for the Group1 members.

C.

Enable Authenticator push authentication mode for Group1.

D.

Enable the Authenticator passwordless authentication method for Group1.

Questions # 22:

You have an Azure subscription that contains the custom roles shown in the following table.

Question # 22

In the Azure portal, you plan to create new custom roles by cloning existing roles Ihe new roles will be configured as shown in following table.

Question # 22

Options:

Questions # 23:

You have an Azure subscription that contains the following servers:

•200 virtual machines that run either Windows Server or Ubuntu Server

•50 Azure Arc enabled servers

You use Azure Policy to manage compliance across all the servers.

You need to enforce an organization-specific security baseline. The solution must meet the following requirements:

•Customize a built-in security baseline.

•Ensure that configuration changes to the servers are enforced automatically after the security baseline is deployed.

♦Minimize administrative effort.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 23

Options:

Questions # 24:

You have an Azure SQL Database logical server named Server1 that contains multiple databases.

The databases contain legacy SQL authentication logins that must no longer be usable for sign-in but must NOT be removed from the databases.

You need to ensure that SQL authentication is denied for connections.

What should you do?

Options:

A.

Run CREATE USER ... FROM EXTERNAL PROVIDER on each database.

B.

Create a Conditional Access policy.

C.

Enable Microsoft Entra-only authentication for Server1.

D.

Assign the SQL Server Contributor role to Server1.

Questions # 25:

You have an Azure virtual network named VNet1 that contains a subnet named Subnet1.

You create a storage account named storage1.

You need to ensure that access to storage1 can be managed only by a network security group (NSG) linked to Subnet1.

What should you use?

Options:

A.

an Azure Private Link service

B.

a service endpoint

C.

a private endpoint

D.

a user-defined route (UDR)

Questions # 26:

You have a Microsoft 365 subscription. All users have Microsoft Exchange Online mailboxes.

You use Microsoft Entra Agent ID to register and manage AI agents.

The developers at your company create the following two agents:

•Agent 1: An interactive agent that helps users summarize their own Exchange Online email

•Agent2: An autonomous agent that sends nightly updates to a Microsoft Teams channel

You need to grant each agent access to Microsoft Graph. The solution must minimize the access scope, while meeting each agent ' s operating model.

Which type of permission should you assign to each agent? To answer, drag the appropriate permission types to the correct agents. Each permission type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 26

Options:

Questions # 27:

You have an Azure subscription named Sub1. Sub1 contains 60 virtual machines that run either Window Server or Linux.

All the Windows Server virtual machines host line-of-business (LOB) applications and all the Linux virtual machines host backend databases.

You need to enable malware protection for the virtual machines.

Which Microsoft Defender for Cloud plan should you enable for each type of virtual machine? To answer, drag the appropriate plans to the correct virtual machine types. Each plan may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 27

Options:

Questions # 28:

You have an Azure virtual network named VNet1 that contains a subnet named Subnet! A network security group named NSG1 is associated with Subnet1.

Vou have a storage account named storage1.

You need to ensure that access from Subnet1 to storage! uses a private IP address in Subnet1 and ran be filtered by NSG1 Public network access to storage1 must be disabled.

What should you create?

Options:

A.

a user-defined route (UDR)

B.

a service endpoint

C.

a private endpoint

D.

an Azure Private link service

Questions # 29:

You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.

You need to configure a solution that automates the remediation of malware detected in storage1.

What should you include in the solution?

Options:

A.

Application Insights

B.

Azure Event Hubs

C.

Azure Event Grid

D.

Azure Policy

Questions # 30:

You have an Azure subscription named Sub1 that contains multiple virtual machines and an Azure key vault named KV1.

Each virtual machine has a system-assigned managed identity. Sub1 has Microsoft Defender for Servers enabled. Defender for Servers has agentless scanning enabled.

Some virtual machines use managed disks that are encrypted by using customer-managed keys stored in KV1.

You discover that the affected virtual machines fail to return agentless scanning results in Microsoft Defender for Cloud.

You need to ensure that agentless scanning can analyze the virtual machines.

What should you do?

Options:

A.

Assign each virtual machine managed identity the Key Vault Reader role for KV1.

B.

Assign the scanning service the Key Vault Secrets User role for KV1.

C.

Enable Microsoft Defender for Key Vault for Sub1.

D.

Enable just-in-time (JIT) VM access for the affected virtual machines.

E.

Assign the scanning service the Key Vault Crypto Service Encryption User role for KV1

Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.