MS-500 Exam Question 76

You have an Azure Active Directory (Azure AD) tenant named Contoso.com that contains the users shown in the following table.
The User Administrator role is configured in Azure AD Privileged Identity Management (PIM) as shown in the following exhibit.

You make User4 eligible for the User Administrator role.
For each of the following statements, Select Yes if the Statement is true. Otherwise, select No./ NOTE: Each correct selection is worth one point.

MS-500 Exam Question 77

You have an Azure Sentinel workspace.
You configure a rule to generate Azure Sentinel alerts when Azure Active Directory (Azure AD) Identity Protection detects risky sign-ins. You develop an Azure Logic Apps solution to contact users and verify whether reported risky sign-ins are legitimate.
You need to configure the workspace to meet the following requirements:
Call the Azure logic app when an alert is triggered for a risky sign-in.
To the Azure Sentinel portal, add a custom dashboard that displays statistics for risky sign-ins that are detected and resolved.
What should you configure in Azure Sentinel to meet each requirement? To answer, select the appropriate options in the answer are a.
NOTE: Each correct selection is worth one point.

MS-500 Exam Question 78

You have a Microsoft 365 subscription.
You need to ensure that users can manually designate which content will be subject to data loss prevention (DLP) policies.
What should you create first?
  • MS-500 Exam Question 79

    You have a Microsoft 365 subscription that contains an Azure Active Directory (Azure AD) tenant named contoso.com.
    You need to recommend an Azure AD Privileged Identity Management (PIM) solution that meets the following requirements:
    Administrators must be notified when the Security administrator role is activated.
    Users assigned the Security administrator role must be removed from the role automatically if they do not sign in for 30 days.
    Which Azure AD PIM setting should you recommend configuring for each requirement? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    MS-500 Exam Question 80

    You have a Microsoft 365 subscription that contains the users shown in the following table.

    You implement Azure Active Directory (Azure AD) Privileged Identity Management (PIM).
    From PIM, you review the Application Administrator role and discover the users shown in the following table.

    The Application Administrator role is configured to use the following settings in PIM:
    * Maximum activation duration: 1 hour
    * Notifications: Disable
    * Incident/Request ticket: Disable
    * Multi-Factor Authentication: Disable
    * Require approval: Enable
    * Selected approver: No results
    For each of the following statements, select Yes if the statement is true. Otherwise, select No.
    NOTE: Each correct selection is worth one point.