AZ-500 Exam Question 16

You have the hierarchy of Azure resources shown in the following exhibit.

RG1, RG2, and RG3 are resource groups.
RG2 contains a virtual machine named VM1.
You assign role-based access control (RBAC) roles to the users shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

AZ-500 Exam Question 17

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You use Azure Security Center for the centralized policy management of three Azure subscriptions.
You use several policy definitions to manage the security of the subscriptions.
You need to deploy the policy definitions as a group to all three subscriptions.
Solution: You create an initiative and an assignment that is scoped to the Tenant Root Group management group.
Does this meet the goal?
  • AZ-500 Exam Question 18

    You create an alert rule that has the following settings:
    * Resource: RG1
    * Condition: All Administrative operations
    * Actions: Action groups configured for this alert rule: ActionGroup1
    * Alert rule name: Alert1
    You create an action rule that has the following settings:
    * Scope: VM1
    * Filter criteria: Resource Type = "Virtual Machines"
    * Define on this scope: Suppression
    * Suppression config: From now (always)
    * Name: ActionRule1
    For each of the following statements, select Yes if the statement is true. Otherwise, select No.
    Note: Each correct selection is worth one point.

    AZ-500 Exam Question 19

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You have an Azure Subscription named Sub1.
    You have an Azure Storage account named Sa1 in a resource group named RG1.
    Users and applications access the blob service and the file service in Sa1 by using several shared access signatures (SASs) and stored access policies.
    You discover that unauthorized users accessed both the file service and the blob service.
    You need to revoke all access to Sa1.
    Solution: You generate new SASs.
    Does this meet the goal?
  • AZ-500 Exam Question 20

    You have five Azure subscriptions linked to a single Azure Active Directory (Azure AD) tenant.
    You create an Azure Policy initiative named securityPolicyinitive1
    You identify which standard role assignments must be configured on all new resource groups.
    You need to enforce SecurityPolicyinvitative1 and the role assignments when anew resource group is created Which three actions should you perform in sequence? To answer move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.