Free AZ-500 Exam Braindumps (page: 69)

Page 68 of 128

You have an Azure subscription that contains a resource group named RG1 and the network security groups (NSGs) shown in the following table.
You create the Azure policy shown in the following exhibit.
You assign the policy to RG1.
What will occur if you assign the policy to NSG1 and NSG2?

  1. Flow logs will be enabled for NSG2 only.
  2. Flow logs will be disabled for NSG1 and NSG2.
  3. Flow logs will be enabled for NSG1 and NSG2.
  4. Flow logs will be enabled for NSG1 only.

Answer(s): B



HOTSPOT (Drag and Drop is not supported) (Drag and Drop is not supported)
You have an Azure Active Directory (Azure AD) tenant named contoso.com that has Azure Active Directory Premium Plan 1 licenses.
You need to create a group named Group1 that will be assigned the Global reader role.
Which portal should you use to create Group1, and which type of group should you create? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

  1. See Explanation section for answer.

Answer(s): A

Explanation:



HOTSPOT (Drag and Drop is not supported) (Drag and Drop is not supported)
You have a management group named MG1 that contains an Azure subscription and a resource group named RG1. RG1 contains a virtual machine named VM1.
You have the custom Azure roles shown in the following table.
The permissions for Role1 are shown in the following role definition file.
The permissions for Role2 are shown in the following role definition file.
You assign the roles to the users shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.




  1. See Explanation section for answer.

Answer(s): A

Explanation:



You have an Azure Active Directory (Azure AD) tenant.
You need to prevent nonprivileged Azure AD users from creating service principles in Azure AD.
What should you do in the Azure Active Directory admin center of the tenant?

  1. From the User settings blade, set Users can register applications to No.
  2. From the Properties blade, set Access management for Azure resources to No.
  3. From the User settings blade, set Restrict access to Azure AD administration portal to Yes.
  4. From the Properties blade, set Enable Security defaults to Yes.

Answer(s): A






Post your Comments and Discuss Microsoft AZ-500 exam with other Community members:

AZ-500 Exam Discussions & Posts