az-500 Dumps

az-500 Free Practice Test

Microsoft az-500: Microsoft Azure Security Technologies

QUESTION 61

- (Exam Topic 4)
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.
AZ-500 dumps exhibit
You create and enforce an Azure AD Identity Protection user risk policy that has the following settings:
AZ-500 dumps exhibit Assignment: Include Group1, Exclude Group2
AZ-500 dumps exhibit Conditions: Sign-in risk of Medium and above
AZ-500 dumps exhibit Access: Allow access, Require password change
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
AZ-500 dumps exhibit
Solution:
Box 1: Yes
User1 is member of Group1. Sign in from unfamiliar location is risk level Medium. Box 2: Yes
User2 is member of Group1. Sign in from anonymous IP address is risk level Medium. Box 3: No
Sign-ins from IP addresses with suspicious activity is low. Note:
AZ-500 dumps exhibit
Azure AD Identity protection can detect six types of suspicious sign-in activities:
AZ-500 dumps exhibit Users with leaked credentials
AZ-500 dumps exhibit Sign-ins from anonymous IP addresses
AZ-500 dumps exhibit Impossible travel to atypical locations
AZ-500 dumps exhibit Sign-ins from infected devices
AZ-500 dumps exhibit Sign-ins from IP addresses with suspicious activity
AZ-500 dumps exhibit Sign-ins from unfamiliar locations
These six types of events are categorized in to 3 levels of risks – High, Medium & Low: References:
http://www.rebeladmin.com/2018/09/step-step-guide-configure-risk-based-azure-conditional-access-policies/

Does this meet the goal?

Correct Answer: A

QUESTION 62

- (Exam Topic 4)
You have an Azure subscription name Sub1 that contains an Azure Policy definition named Policy1. Policy1 has the following settings:
AZ-500 dumps exhibit Definition location: Tenant Root Group
AZ-500 dumps exhibit Category: Monitoring
You need to ensure that resources that are noncompliant with Policy1 are listed in the Azure Security Center dashboard.
What should you do first?

Correct Answer: D
Reference:
https://docs.microsoft.com/en-us/azure/governance/policy/overview

QUESTION 63

- (Exam Topic 4)
You have an Azure subscription that contains an Azure key vault named Vault1. On January 1, 2019, Vault1 stores the following secrets.
AZ-500 dumps exhibit
Which can each secret be used by an application? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
AZ-500 dumps exhibit
Solution:
Box 1: Never Password1 is disabled.
Box 2: Only between March 1, 2019 and May 1, Password2:
AZ-500 dumps exhibit
Reference:
https://docs.microsoft.com/en-us/powershell/module/azurerm.keyvault/set-azurekeyvaultsecretattribute

Does this meet the goal?

Correct Answer: A

QUESTION 64

- (Exam Topic 1)
You need to ensure that users can access VM0. The solution must meet the platform protection requirements. What should you do?

Correct Answer: D
https://docs.microsoft.com/en-us/azure/firewall/tutorial-firewall-dnat

QUESTION 65

- (Exam Topic 4)
You plan to deploy an app that will modify the properties of Azure Active Directory (Azure AD) users by using Microsoft Graph. You need to ensure that the app can access Azure AD. What should you configure first?

Correct Answer: D
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-how-applications-are-added