Microsoft AZ-500 Microsoft Azure Security Technologies Online Training
Microsoft AZ-500 Online Training
The questions for AZ-500 were last updated at Dec 20,2024.
- Exam Code: AZ-500
- Exam Name: Microsoft Azure Security Technologies
- Certification Provider: Microsoft
- Latest update: Dec 20,2024
Topic 3, Fabrikam inc
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
General Overview
Fabrikam, Inc. is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. Fabrikam has IT, human resources (HR), and finance departments.
Existing Environment
Network Environment
Fabrikam has a Microsoft 365 subscription and an Azure subscription named subscription1.
The network contains an on-premises Active Directory domain named Fabrikam.com. The domain contains two organizational units (OUs) named OU1 and OU2. Azure AD Connect cloud sync syncs only OU1.
The Azure resources hierarchy is shown in the following exhibit.
The Azure Active Directory (Azure AD) tenant contains the users shown in the following table.
Azure AD contains the resources shown in the following table.
Subscription1 Resources
Subscription1 contains the virtual networks shown in the following table.
Subscription1 contains the network security groups (NSGs) shown in the following table.
Subscription1 contains the virtual machines shown in the following table.
Subscription1 contains the Azure key vaults shown in the following table.
Subscription1 contains a storage account named storage1 in the West US Azure region.
Planned Changes and Requirements
Planned Changes
Fabrikam plans to implement the following changes:
✑ Create two application security groups as shown in the following table.
✑ Associate the network interface of VM1 to ASG1.
✑ Deploy SecPol1 by using Azure Security Center.
✑ Deploy a third-party app named App1. A version of App1 exists for all available operating systems.
✑ Create a resource group named RG2.
✑ Sync OU2 to Azure AD.
✑ Add User1 to Group1.
Technical Requirements
Fabrikam identifies the following technical requirements:
✑ The finance department users must reauthenticate after three hours when they access SharePoint Online.
✑ Storage1 must be encrypted by using customer-managed keys and automatic key rotation.
✑ From Sentinel1, you must ensure that the following notebooks can be launched:
✑ VM1, VM2, and VM3 must be encrypted by using Azure Disk Encryption.
✑ Just in time (JIT) VM access for VM1, VM2, and VM3 must be enabled.
✑ App1 must use a secure connection string stored in KeyVault1.
✑ KeyVault1 traffic must NOT travel over the internet.
DRAG DROP
You need to perform the planned changes for OU2 and User1.
Which tools should you use? To answer, drag the appropriate tools to the correct resources. Each tool may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.
You need to meet the technical requirements for the finance department users.
Which CAPolicy1 settings should you modify?
- A . Cloud apps or actions
- B . Conditions
- C . Grant
- D . Session
HOTSPOT
You need to configure support for Azure Sentinel notebooks to meet the technical requirements.
What is the minimum number of Azure container registries and Azure Machine Learning workspaces required?
From Azure Security Center, you need to deploy SecPol1.
What should you do first?
- A . Enable Azure Defender.
- B . Create an Azure Management group.
- C . Create an initiative.
- D . Configure continuous export.
You need to encrypt storage1 to meet the technical requirements.
Which key vaults can you use?
- A . KeyVault1 only
- B . KeyVault2 and KeyVault3 only
- C . KeyVault1 and KeyVault3 only
- D . KeyVault1 KeyVault2 and KeyVault3
HOTSPOT
You need to delegate the creation of RG2 and the management of permissions for RG1.
Which users can perform each task? To answer select the appropriate options in the answer area. NOTE: Each correct selection is worth one point
You plan to configure Azure Disk Encryption for VM4.
Which key vault can you use to store the encryption key?
- A . KeyVault1
- B . KeyVault3
- C . KeyVault2
HOTSPOT
You implement the planned changes for ASG1 and ASG2.
In which NSGs can you use ASG1. and the network interfaces of which virtual machines can you assign to ASG2?
You plan to implement JIT VM access.
Which virtual machines will be supported?
- A . VM1 and VM3 only
- B . VM1. VM2. VM3, and VM4
- C . VM2, VM3, and VM4 only
- D . VM1 only
Topic 4, Mix Questions
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure Subscription named Sub1.
You have an Azure Storage account named Sa1 in a resource group named RG1.
Users and applications access the blob service and the file service in Sa1 by using several shared access signatures (SASs) and stored access policies.
You discover that unauthorized users accessed both the file service and the blob service.
You need to revoke all access to Sa1.
Solution: You generate new SASs.
Does this meet the goal?
- A . Yes
- B . No
May i ask about where to get the AZ-500 Exam lab that contains 12 Questions?
Thank you.