AZ-500 Exam Question 96

You plan to use Azure Log Analytics to collect logs from 200 servers that run Windows Server 2016.
You need to automate the deployment of the Microsoft Monitoring Agent to all the servers by using an Azure Resource Manager template.
How should you complete the template? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

AZ-500 Exam Question 97

You have an Azure subscription named Sub1 that contains an Azure Log Analytics workspace named LAW1.
You have 100 on-premises servers that run Windows Server 2012 R2 and Windows Server 2016. The servers connect to LAW1. LAW1 is configured to collect security-related performance counters from the connected servers.
You need to configure alerts based on the data collected by LAW1. The solution must meet the following requirements:
* Alert rules must support dimensions.
* The time it takes to generate an alert must be minimized.
* Alert notifications must be generated only once when the alert is generated and once when the alert is
* resolved.
Which signal type should you use when you create the alert rules?
  • AZ-500 Exam Question 98

    Your network contains an on-premises Active Directory domain named contoso.com. The domain contains a user named User1.
    You have an Azure subscription that is linked to an Azure Active Directory (Azure AD) tenant named contoso.com. The tenant contains an Azure Storage account named storage1. Storage1 contains an Azure file share named share1.
    Currently, the domain and the tenant are not integrated.
    You need to ensure that User1 can access share1 by using his domain credentials.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    AZ-500 Exam Question 99

    You have an Azure Sentinel workspace that has an Azure Active Directory (Azure AD) data connector.
    You are threat hunting suspicious traffic from a specific IP address.
    You need to annotate an intermediate event stored in the workspace and be able to reference the IP address when navigating through the investigation graph.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    AZ-500 Exam Question 100

    You need to delegate the creation of RG2 and the management of permissions for RG1. Which users can perform each task? To answer select the appropriate options in the answer are a. NOTE: Each correct selection is worth one point