Free az-500 Exam Braindumps

Pass your Microsoft Azure Security Technologies exam with these free Questions and Answers

Page 8 of 76
QUESTION 31

- (Exam Topic 4)
You have Azure Resource Manager templates that you use to deploy Azure virtual machines.
You need to disable unused Windows features automatically as instances of the virtual machines are provisioned.
What should you use?

  1. A. device compliance policies in Microsoft Intune
  2. B. Azure Automation State Configuration
  3. C. application security groups
  4. D. Azure Advisor

Correct Answer: B
You can use Azure Automation State Configuration to manage Azure VMs (both Classic and Resource Manager), on-premises VMs, Linux machines, AWS VMs, and on-premises physical machines.
Note: Azure Automation State Configuration provides a DSC pull server similar to the Windows Feature DSCService so that target nodes automatically receive configurations, conform to the desired state, and report back on their compliance. The built-in pull server in Azure Automation eliminates the need to set up and maintain your own pull server. Azure Automation can target virtual or physical Windows or Linux machines, in the cloud or on-premises.
References:
https://docs.microsoft.com/en-us/azure/automation/automation-dsc-getting-started

QUESTION 32

- (Exam Topic 4)
You have an Azure subscription that contains an Azure Active Directory (Azure AD) tenant and a user named User1.
The App registrations settings for the tenant are configured as shown in the following exhibit.
AZ-500 dumps exhibit
You plan to deploy an app named App1.
You need to ensure that User1 can register App1 in Azure AD. The solution must use the principle of least privilege.
Which role should you assign to User1?

  1. A. App Configuration Data Owner for the subscription
  2. B. Managed Application Contributor for the subscription
  3. C. Cloud application administrator in Azure AD
  4. D. Application developer in Azure AD.

Correct Answer: D
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/roles/delegate-by-task

QUESTION 33

- (Exam Topic 4)
You have an Azure subscription that uses Azure Active Directory (Azure AD) Privileged Identity Management (PIM).
A PIM user that is assigned the User Access Administrator role reports receiving an authorization error when performing a role assignment or viewing the list of assignments.
You need to resolve the issue by ensuring that the PIM service principal has the correct permissions for the subscription. The solution must use the principle of least privilege.
Which role should you assign to the PIM service principle?

  1. A. Contributor
  2. B. User Access Administrator
  3. C. Managed Application Operator
  4. D. Resource Policy Contributor

Correct Answer: B

QUESTION 34

- (Exam Topic 4)
You have an Azure subscription that contains an Azure key vault. The role assignments for the key vault are shown in the following exhibit.
AZ-500 dumps exhibit
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.
AZ-500 dumps exhibit
Solution:
AZ-500 dumps exhibit

Does this meet the goal?

  1. A. Yes
  2. B. No

Correct Answer: A

QUESTION 35

- (Exam Topic 4)
You need to create a new Azure Active Directory (Azure AD) directory named 12345678.onmicrosoft.com. The new directory must contain a new user named user1@12345678.onmicrosoft.com.
To complete this task, sign in to the Azure portal.
Solution:
The first step is to create the Azure Active Directory tenant.
AZ-500 dumps exhibit Sign in to the Azure portal.
AZ-500 dumps exhibit From the Azure portal menu, select Azure Active Directory.
AZ-500 dumps exhibit On the overview page, select Manage tenants.
AZ-500 dumps exhibit Select +Create.
AZ-500 dumps exhibit On the Basics tab, select Azure Active Directory.
AZ-500 dumps exhibit Select Next: Configuration
to move on to thCe onfiguration tab.
AZ-500 dumps exhibit For Organization name, enter 12345678.
AZ-500 dumps exhibit For the Initial domain name, enter 12345678.
AZ-500 dumps exhibit Leave the Country/Region as the default.
The next step is to create the user.
AZ-500 dumps exhibit From the Azure portal menu, select Azure Active Directory.
AZ-500 dumps exhibit Select Users then select New user.
AZ-500 dumps exhibit Enter User1 in the User name and Name fields.
AZ-500 dumps exhibit Leave the default option of Auto-generate password.
AZ-500 dumps exhibit Click the Create button.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-access-create-new-tenant https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/add-users-azure-active-directory

Does this meet the goal?

  1. A. Yes
  2. B. No

Correct Answer: A

Page 8 of 76

Post your Comments and Discuss Microsoft az-500 exam with other Community members: