AZ-500 Exam Question 86

You have a Azure subscription.
You enable Azure Active Directory (Azure AD) Privileged identify (PIM).
Your company's security policy for administrator accounts has the following conditions:
* The accounts must use multi-factor authentication (MFA).
* The account must use 20-character complex passwords.
* The passwords must be changed every 180 days.
* The account must be managed by using PIM.
You receive alerts about administrator who have not changed their password during the last 90 days.
You need to minimize the number of generated alerts.
Which PIM alert should you modify?
  • AZ-500 Exam Question 87

    You have an Azure subscription that contains an Azure Active Directory (Azure AD) tenant.
    When a developer attempts to register an app named App1 in the tenant, the developer receives the error message shown in the following exhibit.

    You need to ensure that the developer can register App1 in the tenant.
    What should you do for the tenant?
  • AZ-500 Exam Question 88

    You are testing an Azure Kubernetes Service (AKS) cluster. The cluster is configured as shown in the exhibit. (Click the Exhibit tab.)

    You plan to deploy the cluster to production. You disable HTTP application routing.
    You need to implement application routing that will provide reverse proxy and TLS termination for AKS services by using a single IP address.
    What should you do?
  • AZ-500 Exam Question 89

    You have an Azure subscription that contains an Azure Active Directory (Azure AD) tenant named contoso.com. The tenant contains the users shown in the following table.

    You create a resource group named RG1.
    Which users can modify the permissions for RG1 and which users can create virtual networks in RG1? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    AZ-500 Exam Question 90

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You have an Azure Subscription named Sub1.
    You have an Azure Storage account named Sa1 in a resource group named RG1.
    Users and applications access the blob service and the file service in Sa1 by using several shared access signatures (SASs) and stored access policies.
    You discover that unauthorized users accessed both the file service and the blob service.
    You need to revoke all access to Sa1.
    Solution: You create a new stored access policy.
    Does this meet the goal?