AZ-500 Exam Question 61

You have an Azure subscription that contains an Azure key vault.
You create a storage account named storage1.
You plan to store data in the following storage1 services:
* Azure Files
* Azure Blob storage
* Azure Table storage
* Azure Queue storage
For which two services can you configure data encryption by using the keys stored in the key vault? Each correct answer presents a complete solution.
NOTE Each correct selection is worth one point.
  • AZ-500 Exam Question 62

    You have an Azure subscription that contains a Microsoft Defender External Attack Surface Management (Defender EASM) resource named EASM1. EASM1 contains the inventory assets shown in the following table.

    Which assets are scanned daily, and which assets will display in the default dashboard charts? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    AZ-500 Exam Question 63

    You have an Azure subscription named Sub1.
    You have an Azure Active Directory (Azure AD) group named Group1 that contains all the members of your IT team.
    You need to ensure that the members of Group1 can stop, start, and restart the Azure virtual machines in Sub1. The solution must use the principle of least privilege.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    AZ-500 Exam Question 64

    You have 10 on-premises servers that run Windows Server.
    You plan to implement Microsoft Defender for Cloud vulnerability scanning for the servers. What should you install on the servers first?
  • AZ-500 Exam Question 65

    You have a Azure subscription.
    You enable Azure Active Directory (Azure AD) Privileged identify (PIM).
    Your company's security policy for administrator accounts has the following conditions:
    * The accounts must use multi-factor authentication (MFA).
    * The account must use 20-character complex passwords.
    * The passwords must be changed every 180 days.
    * The account must be managed by using PIM.
    You receive alerts about administrator who have not changed their password during the last 90 days.
    You need to minimize the number of generated alerts.
    Which PIM alert should you modify?