Microsoft

AZ-500 Free Practice Questions — Page 21

Question 213

You need to meet the technical requirements for the finance department users. Which CAPolicy1 settings should you modify?

A. Cloud apps or actions
B. Conditions
C. Grant
D. Session
Show Answer
Correct Answer: D
Explanation:
The finance department’s technical requirement is to control user sign-in behavior (such as enforcing periodic reauthentication or sign-in frequency). These controls are configured in the Conditional Access policy under **Session** settings, not Cloud apps, Conditions, or Grant. Session controls manage how long a session lasts and when users must reauthenticate.

Question 214

DRAG DROP - You need to perform the planned changes for OU2 and User1. Which tools should you use? To answer, drag the appropriate tools to the correct resources. Each tool may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point. Select and Place:

Illustration for AZ-500 question 214
Show Answer
Correct Answer: OU2: Azure AD Connect User1: The Azure portal
Explanation:
OU2 changes must be performed on-premises and synchronized to Azure AD, which is done using Azure AD Connect. User1 is associated with a cloud-only object (not synchronized from on-premises), so changes to User1 are managed directly in Azure AD through the Azure portal.

Question 215

HOTSPOT - You need to configure support for Microsoft Sentinel notebooks to meet the technical requirements. What is the minimum number of Azure container registries and Azure Machine Learning workspaces required? Hot Area:

Illustration for AZ-500 question 215
Show Answer
Correct Answer: Container registries: 0 Workspaces: 1
Explanation:
Microsoft Sentinel notebooks run on an Azure Machine Learning (AML) workspace. A single AML workspace is sufficient to host and execute notebooks. An Azure Container Registry is optional and only required for custom Docker images, so the minimum required is none.

Question 216

You plan to deploy Azure container instances. You have a containerized application that is comprised of two containers: an application container and a validation container. The application container is monitored by the validation container. The validation container performs security checks by making requests to the application container and waiting for responses after every transaction. You need to ensure that the application container and the validation container are scheduled to be deployed together. The containers must communicate to each other only on ports that are not externally exposed. What should you include in the deployment?

A. application security groups
B. network security groups (NSGs)
C. management groups
D. container groups
Show Answer
Correct Answer: D
Explanation:
Azure Container Instances deploy multiple containers together using a container group. Containers in the same container group are scheduled and started as a single unit, share the same network namespace, and can communicate with each other over localhost on any port without exposing those ports externally. This meets the requirement to deploy the application and validation containers together and restrict their communication to non-exposed internal ports.

Question 217

You need to encrypt storage1 to meet the technical requirements. Which key vaults can you use?

A. KeyVault2 and KeyVault3 only
B. KeyVault1 only
C. KeyVault1 and KeyVault3 only
D. KeyVault1, KeyVault2, and KeyVault3
Show Answer
Correct Answer: D
Explanation:
For Azure Storage customer-managed keys, the storage account can use a key stored in any Azure Key Vault or managed HSM regardless of region, subscription, or tenant, provided permissions are correctly configured. Standard and Premium Key Vaults both support CMKs for Storage, including key rotation. Therefore, all listed key vaults can be used.

Question 218

You plan to configure Azure Disk Encryption for VM4. Which key vault can you use to store the encryption key?

A. KeyVault1
B. KeyVault2
C. KeyVault3
Show Answer
Correct Answer: A
Explanation:
Azure Disk Encryption requires the Azure Key Vault to be in the same subscription and the same Azure region as the virtual machine. VM4 is located in the West US region, and KeyVault1 is the only key vault in West US. Therefore, KeyVault1 can be used to store the encryption key.

Question 219

You have a Microsoft 365 tenant that uses an Azure Active Directory (Azure AD) tenant. The Azure AD tenant syncs to an on-premises Active Directory domain by using an instance of Azure AD Connect. You create a new Azure subscription. You discover that the synced on-premises user accounts cannot be assigned roles in the new subscription. You need to ensure that you can assign Azure and Microsoft 365 roles to the synced Azure AD user accounts. What should you do fist?

A. Configure the Azure AD tenant used by the new subscription to use pass-through authentication.
B. Configure the Azure AD tenant used by the new subscription to use federated authentication.
C. Change the Azure AD tenant used by the new subscription.
D. Configure a second instance of Azure AD Connect.
Show Answer
Correct Answer: C
Explanation:
Azure roles can only be assigned to identities that exist in the Azure AD tenant associated with the subscription. If the synced on‑premises users cannot be assigned roles, the new subscription is using a different Azure AD tenant than the one synced by Azure AD Connect. The first step is to change (associate) the subscription to the existing Azure AD tenant that already contains the synced users. Authentication method or adding another Azure AD Connect instance does not address the tenant mismatch.

Question 220

You have an Azure Active Directory (Azure AD) tenant that contains a user named Admin1. Admin1 is assigned the Application developer role. You purchase a cloud app named App1 and register App1 in Azure AD. Admin1 reports that the option to enable token encryption for App1 is unavailable. You need to ensure that Admin1 can enable token encryption for App1 in the Azure portal. What should you do?

A. Upload a certificate for App1.
B. Modify the API permissions of App1.
C. Add App1 as an enterprise application.
D. Assign Admin1 the Cloud application administrator role.
Show Answer
Correct Answer: A
Explanation:
The Token encryption option in Azure AD becomes available only after an encryption certificate is configured for the application. Admin1 already has sufficient rights as an Application Developer to manage the app, but without an uploaded certificate Azure AD cannot enable token encryption, so the option is disabled. Uploading a certificate for App1 enables token encryption in the portal.

Question 221

You plan to deploy an app that will modify the properties of Azure Active Directory (Azure AD) users by using Microsoft Graph. You need to ensure that the app can access Azure AD. What should you configure first?

A. an app registration
B. an external identity
C. a custom role-based access control (RBAC) role
D. an Azure AD Application Proxy
Show Answer
Correct Answer: A
Explanation:
To access and modify Azure AD user properties via Microsoft Graph, the application must first be registered in Azure AD. An app registration creates the application identity (service principal), allows configuration of Microsoft Graph API permissions, and enables authentication and authorization. The other options are not prerequisites for Microsoft Graph access.

Question 222

HOTSPOT - You have an Azure subscription named Subscription1 that contains the resources shown in the following table. You create a custom RBAC role in Subscription1 by using the following JSON file. You assign Role1 to User1 on RG1. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Hot Area:

Illustration for AZ-500 question 222 Illustration for AZ-500 question 222 Illustration for AZ-500 question 222
Show Answer
Correct Answer: User1 can add VM1 to VNET1: No User1 can start and stop App1: No User1 can start and stop cont1: No
Explanation:
The custom role grants */read (read-only for all providers) and Microsoft.Compute/* (full actions only for Compute resources). Adding a VM to a VNet requires Microsoft.Network permissions, starting/stopping an App Service requires Microsoft.Web permissions, and starting/stopping a container instance requires Microsoft.ContainerInstance permissions, none of which are included.

$19

Get all 440 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.