This page was exported from Braindump2go Free Exam Dumps with PDF and VCE Collection [ https://www.mcitpdump.com ] Export date:Sat Nov 23 10:00:08 2024 / +0000 GMT ___________________________________________________ Title: [September-2021]Free Braindump2go Latest AZ-500 VCE AZ-500 292Q Guarantee 100% Pass[Q281-Q287] --------------------------------------------------- September/2021 Latest Braindump2go AZ-500 Exam Dumps with PDF and VCE Free Updated Today! Following are some new AZ-500 Real Exam Questions!QUESTION 281Case Study 3 - Fabrikam, IncGeneral OverviewFabrikam, Inc. is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. Fabrikam has IT, human resources (HR), and finance departments.Existing Environment Network Environment Fabrikam has a Microsoft 365 subscription and an Azure subscription named subscription1. The network contains an on-premises Active Directory domain named Fabrikam.com. The domain contains two organizational units (OUs) named OU1 and OU2. Azure AD Connect cloud sync syncs only OU1. The Azure resources hierarchy is shown in the following exhibit. The Azure Active Directory (Azure AD) tenant contains the users shown in the following table. Azure AD contains the resources shown in the following table. Subscription1 ResourcesSubscription1 contains the virtual networks shown in the following table. Subscription1 contains the network security groups (NSGs) shown in the following table. Subscription1 contains the virtual machines shown in the following table. Subscription1 contains the Azure key vaults shown in the following table. Subscription1 contains a storage account named storage1 in the West US Azure region.Planned Changes and RequirementsPlanned ChangesFabrikam plans to implement the following changes: Create two application security groups as shown in the following table. Associate the network interface of VM1 to ASG1. Deploy SecPol1 by using Azure Security Center. Deploy a third-party app named App1. A version of App1 exists for all available operating systems. Create a resource group named RG2. Sync OU2 to Azure AD. Add User1 to Group1.Technical RequirementsFabrikam identifies the following technical requirements: The finance department users must reauthenticate after three hours when they access SharePoint Online. Storage1 must be encrypted by using customer-managed keys and automatic key rotation. From Sentinel1, you must ensure that the following notebooks can be launched: - Entity Explorer – Account - Entity Explorer – Windows Host - Guided Investigation Process Alerts VM1, VM2, and VM3 must be encrypted by using Azure Disk Encryption. Just in time (JIT) VM access for VM1, VM2, and VM3 must be enabled. App1 must use a secure connection string stored in KeyVault1. KeyVault1 traffic must NOT travel over the internet.You need to meet the technical requirements for the finance department users.Which CAPolicy1 settings should you modify?A. Cloud apps or actionsB. ConditionsC. GrantD. SessionAnswer: DExplanation:https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-session-lifetimeQUESTION 282Case Study 3 - Fabrikam, IncGeneral OverviewFabrikam, Inc. is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. Fabrikam has IT, human resources (HR), and finance departments.Existing Environment Network Environment Fabrikam has a Microsoft 365 subscription and an Azure subscription named subscription1. The network contains an on-premises Active Directory domain named Fabrikam.com. The domain contains two organizational units (OUs) named OU1 and OU2. Azure AD Connect cloud sync syncs only OU1. The Azure resources hierarchy is shown in the following exhibit. The Azure Active Directory (Azure AD) tenant contains the users shown in the following table. Azure AD contains the resources shown in the following table. Subscription1 ResourcesSubscription1 contains the virtual networks shown in the following table. Subscription1 contains the network security groups (NSGs) shown in the following table. Subscription1 contains the virtual machines shown in the following table. Subscription1 contains the Azure key vaults shown in the following table. Subscription1 contains a storage account named storage1 in the West US Azure region.Planned Changes and RequirementsPlanned ChangesFabrikam plans to implement the following changes: Create two application security groups as shown in the following table. Associate the network interface of VM1 to ASG1. Deploy SecPol1 by using Azure Security Center. Deploy a third-party app named App1. A version of App1 exists for all available operating systems. Create a resource group named RG2. Sync OU2 to Azure AD. Add User1 to Group1.Technical RequirementsFabrikam identifies the following technical requirements: The finance department users must reauthenticate after three hours when they access SharePoint Online. Storage1 must be encrypted by using customer-managed keys and automatic key rotation. From Sentinel1, you must ensure that the following notebooks can be launched: - Entity Explorer – Account - Entity Explorer – Windows Host - Guided Investigation Process Alerts VM1, VM2, and VM3 must be encrypted by using Azure Disk Encryption. Just in time (JIT) VM access for VM1, VM2, and VM3 must be enabled. App1 must use a secure connection string stored in KeyVault1. KeyVault1 traffic must NOT travel over the internet.Hotspot QuestionYou need to configure support for Azure Sentinel notebooks to meet the technical requirements.What is the minimum number of Azure container registries and Azure Machine Learning workspaces required? Answer: QUESTION 283Case Study 3 - Fabrikam, IncGeneral OverviewFabrikam, Inc. is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. Fabrikam has IT, human resources (HR), and finance departments.Existing Environment Network Environment Fabrikam has a Microsoft 365 subscription and an Azure subscription named subscription1. The network contains an on-premises Active Directory domain named Fabrikam.com. The domain contains two organizational units (OUs) named OU1 and OU2. Azure AD Connect cloud sync syncs only OU1. The Azure resources hierarchy is shown in the following exhibit. The Azure Active Directory (Azure AD) tenant contains the users shown in the following table. Azure AD contains the resources shown in the following table. Subscription1 ResourcesSubscription1 contains the virtual networks shown in the following table. Subscription1 contains the network security groups (NSGs) shown in the following table. Subscription1 contains the virtual machines shown in the following table. Subscription1 contains the Azure key vaults shown in the following table. Subscription1 contains a storage account named storage1 in the West US Azure region.Planned Changes and RequirementsPlanned ChangesFabrikam plans to implement the following changes: Create two application security groups as shown in the following table. Associate the network interface of VM1 to ASG1. Deploy SecPol1 by using Azure Security Center. Deploy a third-party app named App1. A version of App1 exists for all available operating systems. Create a resource group named RG2. Sync OU2 to Azure AD. Add User1 to Group1.Technical RequirementsFabrikam identifies the following technical requirements: The finance department users must reauthenticate after three hours when they access SharePoint Online. Storage1 must be encrypted by using customer-managed keys and automatic key rotation. From Sentinel1, you must ensure that the following notebooks can be launched: - Entity Explorer – Account - Entity Explorer – Windows Host - Guided Investigation Process Alerts VM1, VM2, and VM3 must be encrypted by using Azure Disk Encryption. Just in time (JIT) VM access for VM1, VM2, and VM3 must be enabled. App1 must use a secure connection string stored in KeyVault1. KeyVault1 traffic must NOT travel over the internet.Drag and Drop QuestionYou need to perform the planned changes for OU2 and User1.Which tools should you use? To answer, drag the appropriate tools to the correct resources. Each tool may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.NOTE: Each correct selection is worth one point. Answer: Explanation:https://docs.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-key-vault?tabs=powershellQUESTION 284You have an Azure subscription that contains the resources shown in the following table. You need to ensure that ServerAdmins can perform the following tasks:- Create virtual machines in RG1 only.- Connect the virtual machines to the existing virtual networks in RG2 only.The solution must use the principle of least privilege.Which two role-based access control (RBAC) roles should you assign to ServerAdmins? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.A. a custom RBAC role for RG2B. the Network Contributor role for RG2C. the Contributor role for the subscriptionD. a custom RBAC role for the subscriptionE. the Network Contributor role for RG1F. the Virtual Machine Contributor role for RG1Answer: AFExplanation:https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-rolesQUESTION 285You have an Azure Sentinel deployment.You need to create a scheduled query rule named Rule1.What should you use to define the query rule logic for Rule1?A. a Transact-SQL statementB. a JSON definitionC. GraphQLD. a Kusto queryAnswer: DExplanation:https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats-customQUESTION 286You have an Azure subscription named Subscription1 that contains a resource group named RG1 and the users shown in the following table. You perform the following tasks:- Assign User1 the Network Contributor role for Subscription1.- Assign User2 the Contributor role for RG1.To Subscription1 and RG1, you assign the following policy definition: External accounts with write permissions should be removed from your subscription.What is the Compliance State of the policy assignments?A. The Compliance State of both policy assignments is Non-compliant.B. The Compliance State of the policy assignment to Subscription1 is Compliant, and the Compliance State of the policy assignment to RG1 is Non-compliant.C. The Compliance State of the policy assignment to Subscription1 is Non-compliant, and the Compliance State of the policy assignment to RG1 is Compliant.D. The Compliance State of both policy assignments is Compliant.Answer: AQUESTION 287Hotspot QuestionYou have an Azure subscription that contains the Azure Active Directory (Azure AD) resources shown in the following table. You create the groups shown in the following table. Which resources can you add to Group5 and Group6? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point. Answer: Resources From:1.2021 Latest Braindump2go AZ-500 Exam Dumps (PDF & VCE) Free Share:https://www.braindump2go.com/az-500.html2.2021 Latest Braindump2go AZ-500 PDF and AZ-500 VCE Dumps Free Share:https://drive.google.com/drive/folders/1sQAsVdJ79oBKFiswxjUzGT6Gt6a6PYWl?usp=sharing3.2021 Free Braindump2go AZ-500 Exam Questions Download:https://www.braindump2go.com/free-online-pdf/AZ-500-PDF-Dumps(81-287).pdfFree Resources from Braindump2go,We Devoted to Helping You 100% Pass All Exams! --------------------------------------------------- Images: --------------------------------------------------- --------------------------------------------------- Post date: 2021-09-08 07:34:46 Post date GMT: 2021-09-08 07:34:46 Post modified date: 2021-09-08 07:34:46 Post modified date GMT: 2021-09-08 07:34:46 ____________________________________________________________________________________________ Export of Post and Page as text file has been powered by [ Universal Post Manager ] plugin from www.gconverters.com