Free AZ-500 Exam Braindumps (page: 47)

Page 46 of 128

HOTSPOT (Drag and Drop is not supported) (Drag and Drop is not supported)
You have an Azure subscription that contains the virtual networks shown in the following table.
NSG1 rules restrict access to the internet from Subnet3.
The subscription contains the function apps shown in the following table.
Virtual network integration has the default settings.
You need to configure network access for App1 and App2 to meet the following requirements:
• Deny inbound access to App1 from Subnet1 and allow inbound access from Subnet2.
• Deny outbound access from App2 to the internet.
What should you do for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


  1. See Explanation section for answer.

Answer(s): A

Explanation:



You have an Azure subscription that contains an Azure SQL database named SQL1 and an Azure key vault named KeyVault1. KeyVault1 stores the keys shown in the following table.
You need to configure Transparent Data Encryption (TDE). TDE will use a customer-managed key for SQL1.
Which keys can you use?

  1. Key2 only
  2. Key1 only
  3. Key2 and Key3 only
  4. Key1, Key2, Key3, and Key4
  5. Key1 and Key2 only

Answer(s): E

Explanation:

The key must be an asymmetric, RSA or RSA HSM key. The supported key lengths are 2048-bit and 3072-bit.


Reference:

https://docs.microsoft.com/en-us/azure/azure-sql/database/transparent-data-encryption-byok-overview



SIMULATION
You plan to use Azure Disk Encryption for several virtual machine disks.
You need to ensure that Azure Disk Encryption can retrieve secrets from the KeyVault12345678 Azure key vault.
To complete this task, sign in to the Azure portal and modify the Azure resources.

  1. See Explanation section for answer.

Answer(s): A

Explanation:

1. In the Azure portal, type Key Vaults in the search box, select Key Vaults from the search results then select KeyVault12345678. Alternatively, browse to Key
Vaults in the left navigation pane.
2. In the Key Vault properties, scroll down to the Settings section and select Access Policies.
3. Select the Azure Disk Encryption for volume encryption

4. Click Save to save the changes.



HOTSPOT (Drag and Drop is not supported) (Drag and Drop is not supported)
You have an Azure subscription that contains a web app named App1 and an Azure key vault named Vault1.
You need to configure App1 to store and access the secrets in Vault1.
How should you configure App1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/app-service/overview-managed-identity?tabs=dotnet






Post your Comments and Discuss Microsoft AZ-500 exam with other Community members:

AZ-500 Discussions & Posts