Microsoft AZ-500 Übungsprüfungen
Zuletzt aktualisiert am 25.04.2025- Prüfungscode: AZ-500
- Prüfungsname: Microsoft Azure Security Technologies
- Zertifizierungsanbieter: Microsoft
- Zuletzt aktualisiert am: 25.04.2025
You have an Azure subscription name Sub1 that contains an Azure Policy definition named Policy1.
Policy1 has the following settings:
– Definition location: Tenant Root Group
– Category: Monitoring
You need to ensure that resources that are noncompliant with Policy1 are listed in the Azure Security Center dashboard.
What should you do first?
- A . Change the Category of Policy1 to Security Center.
- B . Add Policy1 to a custom initiative.
- C . Change the Definition location of Policy1 to Sub1.
- D . Assign Policy1 to Sub1.
You have an Azure subscription that contains a user named UseR1.
You need to ensure that UseR1 can perform the following tasks:
• Create groups.
• Create access reviews for role-assignable groups.
• Assign Azure AD roles to groups.
The solution must use the principle of least privilege.
Which role should you assign to User1?
- A . Groups administrator
- B . Authentication administrator
- C . Identity Governance Administrator
- D . Privileged role administrator
You have a Microsoft Entra tenant that contains a user named User1.
You plan to enable passwordless authentication for the tenant.
You need to ensure that User1 can enable the combined registration experience. The solution must use the principle of least privilege.
Which role should you assign to User1?
- A . Security Administrator
- B . Global Administrator
- C . Privileged Role Administrator
- D . Authentication Administrator
HOTSPOT
On Monday, you configure an email notification in Azure Security Center to notify user [email protected].
On Tuesday, Security Center generates the security alerts shown in the following table.
How many email notifications will [email protected] receive on Tuesday? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
HOTSPOT
You work at a company named Contoso, Ltd. that has the offices shown in the following table.
Contoso has an Azure Active Directory (Azure AD) tenant named contoso.com. All contoso.com users have Azure Multi-Factor Authentication (MFA) enabled.
The tenant contains the users shown in the following table.
The multi-factor settings for contoso.com are configured as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
HOTSPOT
You work at a company named Contoso, Ltd. that has the offices shown in the following table.
Contoso has an Azure Active Directory (Azure AD) tenant named contoso.com. All contoso.com users have Azure Multi-Factor Authentication (MFA) enabled.
The tenant contains the users shown in the following table.
The multi-factor settings for contoso.com are configured as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
You have an Azure subscription that contains the resources shown in the following table.
You plan to enable Azure Defender for the subscription.
Which resources can be protected by using Azure Defender?
- A . VM1, VNET1, storage1, and Vault1
- B . VM1, VNET1, and storage1 only
- C . VM1, storage1, and Vault1 only
- D . VM1 and VNET1 only
- E . VM1 and storage1 only
HOTSPOT
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.
Contoso.com contains a group naming policy. The policy has a custom blocked word list rule that includes the word Contoso.
Which users can create a group named Contoso Sales in contoso.com? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
You have a Microsoft Entra tenant that uses Microsoft Entra Permissions Management and contains the accounts shown in the following table:
Which accounts will be listed as assigned to highly privileged roles on the Azure AD insights tab in the Entra Permissions Management portal?
- A . Admin1 only
- B . Admin2 and Admin3 only
- C . Admin2 and Admin4 only
- D . Admin1. Admin2, and Admin3 only
- E . Admin2. Admin3, and Admin4 only
- F . Admin1. Admin2, Admin3. and Admin4
You have an Azure subscription that contains the resources show in the following table.
Both VM1 and VM2 connect to VNET1 and are configured to use NSG1.
You need to ensure that only VM1 and VM2 can access DB1.
What should you do?
- A . Add the IP address range of VNET1 to the Firewall setting of DB1.
- B . For NSG1, configure a rule that has a service tag.
- C . Create an application security group.
- D . Configure DB1 to allow access from only VNET1.