Free AZ-500 Exam Braindumps (page: 64)

Page 63 of 128

HOTSPOT (Drag and Drop is not supported) (Drag and Drop is not supported)
You have an Azure Sentinel workspace that has the following data connectors:
-Azure Active Directory Identity Protection
-Common Event Format (CEF)
Azure Firewall
You need to ensure that data is being ingested from each connector.
From the Logs query window, which table should you query for each connector? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/sentinel/connect-azure-ad-identity-protection https://docs.microsoft.com/en-us/azure/sentinel/connect-azure-firewall https://docs.microsoft.com/en-us/azure/sentinel/connect-data-sources



You have 10 on-premises servers that run Windows Server 2019.
You plan to implement Azure Security Center vulnerability scanning for the servers.
What should you install on the servers first?

  1. the Azure Arc enabled servers Connected Machine agent
  2. the Microsoft Defender for Endpoint agent
  3. the Security Events data connector in Azure Sentinel
  4. the Microsoft Endpoint Configuration Manager client

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/azure-arc/servers/agent-overview https://docs.microsoft.com/en-us/azure/security-center/deploy-vulnerability-assessment-vm



HOTSPOT (Drag and Drop is not supported) (Drag and Drop is not supported)
You have an Azure subscription that contains three storage accounts, an Azure SQL managed instance named SQL1, and three Azure SQL databases.
The storage accounts are configured as shown in the following table.
SQL1 has the following settings:
-Auditing: On
-Audit log destination: storage1
The Azure SQL databases are configured as shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:


  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/azure-sql/managed-instance/auditing-configure https://docs.microsoft.com/en-us/azure/azure-sql/database/auditing-overview



You have an Azure subscription name Sub1 that contains an Azure Policy definition named Policy1. Policy1 has the following settings:
-Definition location: Tenant Root Group
-Category: Monitoring
You need to ensure that resources that are noncompliant with Policy1 are listed in the Azure Security Center dashboard.
What should you do first?

  1. Change the Category of Policy1 to Security Center.
  2. Add Policy1 to a custom initiative.
  3. Change the Definition location of Policy1 to Sub1.
  4. Assign Policy1 to Sub1.

Answer(s): B

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/governance/policy/overview






Post your Comments and Discuss Microsoft AZ-500 exam with other Community members:

AZ-500 Exam Discussions & Posts