Microsoft

AZ-500 Free Practice Questions — Page 8

Question 76

You have an Azure subscription that contains a Microsoft Defender External Attack Surface Management (Defender EASM) resource named EASM1. You review the Attack Surface Summary dashboard. You need to identify the following insights: • Deprecated technologies that are no longer supported • Infrastructure that will soon expire Which section of the dashboard should you review?

A. Securing the Cloud
B. Sensitive Services
C. Attack Surface Priorities
D. attack surface composition
Show Answer
Correct Answer: C
Explanation:
The Attack Surface Priorities section of the Defender EASM Attack Surface Summary dashboard highlights actionable risks, including deprecated or unsupported technologies and assets with upcoming expirations (such as certificates or infrastructure). The other sections focus on different aspects like overall cloud security posture, sensitive exposed services, or asset inventory composition.

Question 77

HOTSPOT - You plan to deploy a custom policy initiative for Microsoft Defender for Cloud. You need to identify all the resource groups that have a Delete lock. How should you complete the policy definition? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for AZ-500 question 77
Show Answer
Correct Answer: Microsoft.Resources/subscriptions/resourceGroups existenceCondition
Explanation:
The policy must evaluate resource groups, so the type is set to Microsoft.Resources/subscriptions/resourceGroups. To check for a Delete lock using auditIfNotExists, the lock criteria is defined under existenceCondition with Microsoft.Authorization/locks and level equals CanNotDelete.

Question 78

You have an Azure subscription that uses Microsoft Defender for Cloud. You have an Amazon Web Services (AWS) account named AWS1 that is connected to Defender for Cloud. You need to ensure that AWS1 uses AWS Foundational Security Best Practices. The solution must minimize administrative effort. What should you do in Defender for Cloud?

A. Assign a built-in compliance standard.
B. Create a new custom standard.
C. Assign a built-in assessment.
D. Create a new custom assessment.
Show Answer
Correct Answer: A
Explanation:
Defender for Cloud provides built-in compliance standards for connected AWS accounts, including AWS Foundational Security Best Practices. Assigning the built-in compliance standard applies all relevant assessments automatically and requires the least administrative effort compared to creating custom standards or individual assessments.

Question 79

HOTSPOT - You have an Azure subscription that contains a Microsoft Defender External Attack Surface Management (Defender EASM) resource named EASM1. EAMS1 contains the inventory assets shown in the following table. Which assets are scanned daily, and which assets will display in the default dashboard charts? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for AZ-500 question 79 Illustration for AZ-500 question 79
Show Answer
Correct Answer: Scanned daily: VM1 only Display in the default dashboard charts: VM1 only
Explanation:
In Defender EASM, only assets in the **Approved Inventory** state are scanned daily and shown in default dashboard charts. VM1 is the only asset in Approved Inventory. Dependency, Monitor Only, and Candidate assets are not included in default charts, and Candidate assets are scanned only during discovery, not daily.

Question 80

HOTSPOT - You have an Azure subscription that uses Microsoft Defender for Cloud. You plan to use the Secure Score Over Time workbook. You need to configure the Continuous export settings for the Defender for Cloud data. Which two settings should you configure? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

Illustration for AZ-500 question 80
Show Answer
Correct Answer: Secure score Snapshots (Preview)
Explanation:
The Secure Score Over Time workbook requires Secure Score data to be exported to a Log Analytics workspace, and it relies on snapshot exports (in addition to streaming) to build historical trends over time.

Question 81

You have an Azure subscription. You plan to map an online infrastructure and perform vulnerability scanning for the following: • ASNs • Hostnames • IP addresses • SSL certificates What should you use?

A. Microsoft Defender for Cloud
B. Microsoft Defender External Attack Surface Management (Defender EASM)
C. Microsoft Defender for Identity
D. Microsoft Defender for Endpoint
Show Answer
Correct Answer: B
Explanation:
The requirement is to discover and map an organization’s external-facing infrastructure (ASNs, hostnames, IP addresses, SSL certificates) and perform vulnerability scanning. Microsoft Defender External Attack Surface Management (Defender EASM) is specifically designed for external attack surface discovery and assessment, including inventorying ASNs, IPs, domains/hostnames, and SSL certificates, and identifying exposures and vulnerabilities. The other Defender products focus on internal resources, identities, or endpoints rather than comprehensive external infrastructure mapping.

Question 82

You have an Azure subscription that uses Microsoft Defender for Cloud. You have accounts for the following cloud services: • Alibaba Cloud • Amazon Web Services (AWS) • Google Cloud Platform (GCP) What can you add to Defender for Cloud?

A. AWS only
B. Alibaba Cloud and AWS only
C. Alibaba Cloud and GCP only
D. AWS and GCP only
E. Alibaba Cloud, AWS, and GCP
Show Answer
Correct Answer: D
Explanation:
Microsoft Defender for Cloud supports multicloud connectors for Amazon Web Services (AWS) and Google Cloud Platform (GCP). Alibaba Cloud is not supported for direct integration with Defender for Cloud. Therefore, only AWS and GCP can be added.

Question 83

SIMULATION - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in the Enter password box and click on the password below. Azure Username: Azure Password: Gp0Ae4@!Dg - If the Azure portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab. The following information is for technical support purposes only: Lab Instance: 28681041 - You need to configure Azure to allow RDP connections from the Internet to a virtual machine named VM1. The solution must minimize the attack surface of VM1. To complete this task, sign in to the Azure portal.

Show Answer
Correct Answer: Configure an inbound Network Security Group (NSG) rule on VM1 to allow TCP port 3389 (RDP) from the Internet. Restrict the source to a specific public IP or IP range.
Explanation:
By default, inbound Internet traffic is blocked. Allowing only TCP 3389 enables RDP, and limiting the source IP range minimizes the attack surface while still permitting Internet-based RDP access.

Question 84

SIMULATION - You need to create a new Azure AD directory named 28681041.onmicrosoft.com. The new directory must contain a new user named . To complete this task, sign in to the Azure portal.

Show Answer
Correct Answer: Create a new Azure AD (Entra ID) tenant with initial domain name **28681041.onmicrosoft.com**. Switch to the new tenant. Create a new internal user in the directory.
Explanation:
In the Azure portal, create a new Azure AD tenant by specifying the initial domain name 28681041. After the tenant is created, switch to it and add a new user from Azure AD > Users using the New user option.

Question 85

SIMULATION - You need to ensure that a user named user2-28681041 can manage the properties of the virtual machines in the RG1lod28681041 resource group. The solution must use the principle of least privilege. To complete this task, sign in to the Azure portal.

Show Answer
Correct Answer: Assign the **Virtual Machine Contributor** role to user **user2-28681041** at the **RG1lod28681041** resource group scope.
Explanation:
The Virtual Machine Contributor role allows managing VM properties and operations without granting broader permissions to networking, storage, or role assignments, satisfying least privilege.

$19

Get all 440 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.