Free AZ-500 Exam Braindumps (page: 54)

Page 53 of 128

You have an Azure Active Directory (Azure AD) tenant and a root management group.
You create 10 Azure subscriptions and add the subscriptions to the root management group.
You need to create an Azure Blueprints definition that will be stored in the root management group.
What should you do first?

  1. Modify the role-based access control (RBAC) role assignments for the root management group.
  2. Add an Azure Policy definition to the root management group.
  3. Create a user-assigned identity.
  4. Create a service principal.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin



HOTSPOT (Drag and Drop is not supported) (Drag and Drop is not supported)
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.
Contoso.com contains a group naming policy. The policy has a custom blocked word list rule that includes the word Contoso.
Which users can create a group named Contoso Sales in contoso.com? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/enterprise-users/groups-naming-policy



DRAG DROP (Drag and Drop is not supported) (Drag and Drop is not supported)
You have five Azure subscriptions linked to a single Azure Active Directory (Azure AD) tenant.
You create an Azure Policy initiative named SecurityPolicyInitiative1.
You identify which standard role assignments must be configured on all new resource groups.
You need to enforce SecurityPolicyInitiative1 and the role assignments when a new resource group is created.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/governance/blueprints/create-blueprint-portal https://docs.microsoft.com/en-us/azure/azure-australia/azure-policy



You have three on-premises servers named Server1, Server2, and Server3 that run Windows Server 2019. Server1 and Server2 are located on the internal network. Server3 is located on the perimeter network. All servers have access to Azure.
From Azure Sentinel, you install a Windows firewall data connector.
You need to collect Microsoft Defender Firewall data from the servers for Azure Sentinel.
What should you do?

  1. Create an event subscription from Server1, Server2, and Server3.
  2. Install the On-premises data gateway on each server.
  3. Install the Microsoft Monitoring Agent on each server.
  4. Install the Microsoft Monitoring Agent on Server1 and Server2. Install the On-premises data gateway on Server3.

Answer(s): C

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/sentinel/connect-windows-firewall






Post your Comments and Discuss Microsoft AZ-500 exam with other Community members:

AZ-500 Exam Discussions & Posts