AZ-500 Exam Question 1

You have an Azure subscription that contains the virtual networks shown in the following table.

The subscription contains the virtual machines shown in the following table.

On NIC1, you configure an application security group named ASG1.
On which other network interfaces can you configure ASG1?
  • AZ-500 Exam Question 2

    You have an Azure subscription that contains the following resources:
    A network virtual appliance (NVA) that runs non-Microsoft firewall software and routes all outbound traffic from the virtual machines to the internet An Azure function that contains a script to manage the firewall rules of the NVA Azure Security Center standard tier enabled for all virtual machines An Azure Sentinel workspace
    30 virtual machines
    You need to ensure that when a high-priority alert is generated in Security Center for a virtual machine, an incident is created in Azure Sentinel and then a script is initiated to configure a firewall rule for the NVA.
    How should you configure Azure Sentinel to meet the requirements? To answer, drag the appropriate components to the correct requirements. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
    NOTE: Each correct selection is worth one point.

    AZ-500 Exam Question 3

    You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.

    Azure AD Privileged Identity Management (PIM) is enabled for the tenant.
    In PIM, the Password Administrator role has the following settings:
    Maximum activation duration (hours): 2
    Send email notifying admins of activation: Disable
    Require incident/request ticket number during activation: Disable
    Require Azure Multi-Factor Authentication for activation: Enable
    Require approval to activate this role: Enable
    Selected approver: Group1
    You assign users the Password Administrator role as shown in the following table.

    For each of the following statements, select Yes if the statement is true. Otherwise, select No.
    NOTE: Each correct selection is worth one point.

    AZ-500 Exam Question 4

    You have the Azure virtual networks shown in the following table.

    You have the Azure virtual machines shown in the following table.

    The firewalls on all the virtual machines allow ping traffic.
    NSG1 is configured as shown in the following exhibit.
    Inbound security rules

    Outbound security rules

    For each of the following statements, select Yes if the statement is true. Otherwise, select No.
    NOTE: Each correct selection is worth one point.

    AZ-500 Exam Question 5

    Your network contains an Active Directory forest named contoso.com. The forest contains a single domain.
    You have an Azure subscription named Sub1 that is associated to an Azure Active Directory (Azure AD) tenant
    named contoso.com.
    You plan to deploy Azure AD Connect and to integrate Active Directory and the Azure AD tenant.
    You need to recommend an integration solution that meets the following requirements:
    * Ensures that password policies and user logon restrictions apply to user accounts that are synced to the
    tenant
    * Minimizes the number of servers required for the solution.
    Which authentication method should you include in the recommendation?