Microsoft

AZ-500 Free Practice Questions — Page 18

Question 181

SIMULATION - You need to ensure that User2-1234578 has all the key permissions for KeyVault1234578. To complete this task, sign in to the Azure portal and modify the Azure resources.

Show Answer
Correct Answer: Assign the **Key Vault Administrator** role to User2-1234578 on KeyVault1234578.
Explanation:
The Key Vault Administrator role grants full data-plane permissions on the key vault, including managing keys, secrets, and certificates. Roles like Key Vault Secrets Officer or Crypto Officer are limited to specific object types and do not provide all key permissions.

Question 182

DRAG DROP - You have an Azure subscription that contains an Azure SQL database named SQLDB1. SQLDB1 contains the columns shown in the following table. For the Email and Birthday columns, you implement dynamic data masking by using the default masking function. Which value will the users see in each column? To answer, drag the appropriate values to the correct columns. Each value may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point. Select and Place:

Illustration for AZ-500 question 182 Illustration for AZ-500 question 182
Show Answer
Correct Answer: Email: XXXX Birthday: 1900-01-01
Explanation:
Default dynamic data masking is applied. For varchar columns, default() masks the value as 'XXXX'. For date data types in Azure SQL Database, default() masks the value as 1900-01-01.

Question 183

HOTSPOT - You have an Azure subscription that is linked to an Azure Active Directory (Azure AD). The tenant contains the users shown in the following table. You have an Azure key vault named Vault1 that has Purge protection set to Disable. Vault1 contains the access policies shown in the following table. You create role assignments for Vault1 as shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Hot Area:

Illustration for AZ-500 question 183 Illustration for AZ-500 question 183 Illustration for AZ-500 question 183 Illustration for AZ-500 question 183
Show Answer
Correct Answer: User1: No User2: No User3: Yes
Explanation:
User1: Purge protection cannot be enabled after vault creation, and Security Administrator has no Key Vault management rights. User2: Network Contributor and Key Vault Reader cannot modify Key Vault firewall or virtual network settings. User3: Key Vault Contributor can manage Key Vault configuration, including adding access policies.

Question 184

HOTSPOT - You have an Azure subscription that contains a web app named App1 and an Azure key vault named Vault1. You need to configure App1 to store and access the secrets in Vault1. How should you configure App1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Hot Area:

Illustration for AZ-500 question 184
Show Answer
Correct Answer: Managed identity Application settings tab
Explanation:
Enable a managed identity on the web app so it can authenticate to Azure Key Vault without credentials. Configure Key Vault references by adding app settings that use the @Microsoft.KeyVault(...) syntax in the Application settings tab.

Question 185

You have an on-premises network and an Azure subscription. You have the Microsoft SQL Server instances shown in the following table. You plan to implement Microsoft Defender for SQL. Which SQL Server instances will be protected by Microsoft Defender for SQL?

A. sql1 and sql2 only
B. sql1, sql2, and sql3 only
C. sql1, sql2, and sql4 only
D. sql1, sql2, sql3, and sql4
Show Answer
Correct Answer: B
Explanation:
Microsoft Defender for SQL protects Azure SQL Database and SQL Server running on Windows, including SQL Server on Azure virtual machines and on‑premises Windows servers (with or without Azure Arc). It does not protect SQL Server running on Linux. Therefore, sql1, sql2, and sql3 are protected, but sql4 is not.

Question 186

From Microsoft Defender for Cloud, you need to deploy SecPol1. What should you do first?

A. Enable Microsoft Defender for Cloud.
B. Create an Azure Management group.
C. Create an initiative.
D. Configure continuous export.
Show Answer
Correct Answer: A
Explanation:
To deploy a security policy (SecPol1) from Microsoft Defender for Cloud, the service itself must first be enabled on the subscription or management group. Without enabling Microsoft Defender for Cloud, its security policies and initiatives are not available for deployment. Other actions, such as creating initiatives, are only applicable after Defender for Cloud is enabled.

Question 187

You are troubleshooting a security issue for an Azure Storage account. You enable Azure Storage Analytics logs and archive it to a storage account. What should you use to retrieve the diagnostics logs?

A. Azure Cosmos DB explorer
B. Azure Monitor
C. Microsoft Defender for Cloud
D. Azure Storage Explorer
Show Answer
Correct Answer: D
Explanation:
Azure Storage Analytics logs are written as log files (blobs) into a storage account. To retrieve and browse these archived diagnostics logs, you use Azure Storage Explorer, which provides direct access to blob containers and log files. Azure Monitor, Defender for Cloud, and Cosmos DB Explorer are not used to directly retrieve Storage Analytics log files from a storage account.

Question 188

SIMULATION - You need to ensure that the rg1lod1234578n1 Azure Storage account is encrypted by using a key stored in the KeyVault12345678 Azure key vault. To complete this task, sign in to the Azure portal.

Show Answer
Correct Answer: Azure portal → Storage accounts → rg1lod1234578n1 Settings → Encryption Select Customer-managed keys Select key from Key Vault Choose KeyVault12345678 and the required key Save
Explanation:
The storage account must be configured to use customer-managed keys instead of Microsoft-managed keys. This is done from the Encryption settings by selecting Customer-managed keys and associating an encryption key stored in the specified Azure Key Vault.

Question 189

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You use Microsoft Defender for Cloud for the centralized policy management of three Azure subscriptions. You use several policy definitions to manage the security of the subscriptions. You need to deploy the policy definitions as a group to all three subscriptions. Solution: You create a policy initiative and an assignment that is scoped to the Tenant Root Group management group. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: A
Explanation:
A policy initiative groups multiple policy definitions so they can be deployed together. Assigning that initiative at the Tenant Root Group management group scope applies it to all child management groups and subscriptions, including the three subscriptions in question. Therefore, this solution meets the goal.

Question 190

SIMULATION - You need to create a web app named Intranet12345678 and enable users to authenticate to the web app by using Azure Active Directory (Azure AD). To complete this task, sign in to the Azure portal.

Show Answer
Correct Answer: Create the web app: - Azure portal → Create a resource → Web App - Name: Intranet12345678 - Select subscription, resource group, runtime → Create Enable Azure AD authentication: - Open the web app → Authentication - Add identity provider → Microsoft - Use Azure Active Directory (create new app registration if prompted) - Require authentication → Save
Explanation:
The task requires creating an Azure App Service and enabling built‑in authentication using Azure Active Directory. This is done by first deploying a web app named Intranet12345678, then configuring the Authentication blade to use Microsoft (Azure AD) as the identity provider and requiring users to sign in.

$19

Get all 440 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.