Free AZ-500 Exam Braindumps (page: 58)

Page 57 of 128

HOTSPOT (Drag and Drop is not supported) (Drag and Drop is not supported)
You have an Azure subscription.
You need to create and deploy an Azure policy that meets the following requirements:
-When a new virtual machine is deployed, automatically install a custom security extension.
-Trigger an autogenerated remediation task for non-compliant virtual machines to install the extension.
What should you include in the policy? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/governance/policy/how-to/remediate-resources



You have an Azure subscription named Subscription1 that contains the resources shown in the following table.
You need to identify which initiatives and policies you can add to Subscription1 by using Azure Security Center.
What should you identify?

  1. Policy1 and Policy2 only
  2. Initiative1 only
  3. Initiative1 and Initiative2 only
  4. Initiative1, Initiative2, Policy1, and Policy2

Answer(s): C

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/security-center/custom-security-policies



You have an Azure subscription that contains an Azure key vault.
You create a storage account named storage1.
You plan to store data in the following storage1 services:
• Azure Files
• Azure Blob storage
• Azure Table storage
• Azure Queue storage
For which two services can you configure data encryption by using the keys stored in the key vault? Each correct answer presents a complete solution,
NOTE: Each correct selection is worth one point.

  1. Blob storage
  2. Table storage
  3. Queue storage
  4. Azure Files

Answer(s): A,D



You have an Azure resource group that contains 100 virtual machines.
You have an initiative named Initiative1 that contains multiple policy definitions. Initiative1 is assigned to the resource group.
You need to identify which resources do NOT match the policy definitions.
What should you do?

  1. From Azure Security Center, view the Regulatory compliance assessment.
  2. From the Policy blade of the Azure Active Directory admin center, select Compliance.
  3. From Azure Security Center, view the Secure Score.
  4. From the Policy blade of the Azure Active Directory admin center, select Assignments.

Answer(s): B

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/governance/policy/how-to/get-compliance-data#portal






Post your Comments and Discuss Microsoft AZ-500 exam with other Community members:

AZ-500 Exam Discussions & Posts