Free AZ-500 Exam Braindumps (page: 12)

Page 11 of 128

You are in the process of configuring an Azure policy via the Azure portal.
Your policy will include an effect that will need a managed identity for it to be assigned.
Which of the following is the effect in question?

  1. AuditIfNotExist
  2. Disabled
  3. DeployIfNotExist
  4. EnforceOPAConstraint

Answer(s): C

Explanation:

When Azure Policy runs the template in the deployIfNotExists policy definition, it does so using a managed identity.


Reference:

https://docs.microsoft.com/bs-latn-ba/azure/governance/policy/how-to/remediate-resources



You have been tasked with creating an Azure key vault using PowerShell. You have been informed that objects deleted from the key vault must be kept for a set period of 90 days.
Which two of the following parameters must be used in conjunction to meet the requirement? (Choose two.)

  1. EnabledForDeployment
  2. EnablePurgeProtection
  3. EnabledForTemplateDeployment
  4. EnableSoftDelete

Answer(s): B,D

Explanation:


Reference:

https://docs.microsoft.com/en-us/powershell/module/azurerm.keyvault/new-azurermkeyvault https://docs.microsoft.com/en-us/azure/key-vault/key-vault-ovw-soft-delete



DRAG DROP (Drag and Drop is not supported) (Drag and Drop is not supported)
Your company has an Azure SQL database that has Always Encrypted enabled.
You are required to make the relevant information available to application developers to allow them to access data in the database.
Which two of the following options should be made available? Answer by dragging the correct options from the list to the answer area.
Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Always Encrypted uses two types of keys: column encryption keys and column master keys. A column encryption key is used to encrypt data in an encrypted column. A column master key is a key-protecting key that encrypts one or more column encryption keys.


Reference:

https://docs.microsoft.com/en-us/sql/relational-databases/security/encryption/always-encrypted-database-engine



View Related Case Study

You need to ensure that you can meet the security operations requirements. What should you do first?

  1. Turn on Auto Provisioning in Security Center.
  2. Integrate Security Center and Microsoft Cloud App Security.
  3. Upgrade the pricing tier of Security Center to Standard.
  4. Modify the Security Center workspace configuration.

Answer(s): C

Explanation:

The Standard tier extends the capabilities of the Free tier to workloads running in private and other public clouds, providing unified security management and threat protection across your hybrid cloud workloads. The Standard tier also adds advanced threat detection capabilities, which uses built-in behavioral analytics and machine learning to identify attacks and zero-days exploits, access and application controls to reduce exposure to network attacks and malware, and more.
Scenario: Security Operations Requirements
Litware must be able to customize the operating system security configurations in Azure Security Center.


Reference:

https://docs.microsoft.com/en-us/azure/security-center/security-center-pricing






Post your Comments and Discuss Microsoft AZ-500 exam with other Community members:

AZ-500 Discussions & Posts