AZ-500 Exam Question 81

You have an Azure subscription that contains the resources shown in the following table.

You plan to deploy the virtual machines shown in the following table.

You need to assign managed identities to the virtual machines. The solution must meet the following requirements:
Assign each virtual machine the required roles.
Use the principle of least privilege.
What is the minimum number of managed identities required?
  • AZ-500 Exam Question 82

    You have an Azure Kubernetes Service (AKS) cluster that will connect to an Azure Container Registry.
    You need to use automatically generated service principal for the AKS cluster to authenticate to the Azure Container Registry.
    What should you create?
  • AZ-500 Exam Question 83

    You have an Azure subscription that contains a resource group named RG1. RG1 contains a virtual machine named VM1 that uses Azure Active Directory (Azure AD) authentication.
    You have two custom Azure roles named Role1 and Role2 that are scoped to RG1.
    The permissions for Role1 are shown in the following JSON code.

    The permissions for Role2 are shown in the following JSON code.

    You assign the roles to the users shown in the following table.

    For each of the following statements, select Yes if the statement is true. Otherwise, select No.
    NOTE: Each correct selection is worth one point.

    AZ-500 Exam Question 84

    You have an Azure Active Directory (Azure AD) tenant named Contoso.com and an Azure Service (AKS) cluster AKS1.
    You discover that AKS1 cannot be accessed by using accounts from Contoso.com You need to ensure AKS1 can be accessed by using accounts from Contoso.com The solution must minimize administrative effort.
    What should you do first?
  • AZ-500 Exam Question 85

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You use Azure Security Center for the centralized policy management of three Azure subscriptions.
    You use several policy definitions to manage the security of the subscriptions.
    You need to deploy the policy definitions as a group to all three subscriptions.
    Solution: You create an initiative and an assignment that is scoped to the Tenant Root Group management group.
    Does this meet the goal?