AZ-500 無料問題集「Microsoft Azure Security Technologies」
You have an Azure key vault named KeyVault1 that contains the items shown in the following table.

In KeyVault, the following events occur in sequence:
* Item1 is deleted
* Administrator enables soft delete
* Item2 and Policy1 are deleted.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.


In KeyVault, the following events occur in sequence:
* Item1 is deleted
* Administrator enables soft delete
* Item2 and Policy1 are deleted.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

正解:

Explanation:
NO. Policies cannot be recovered
YES, Item1 is permanently deleted
NO, You cannot use the same name cause Item2 is in Seoft-deleted status
https://docs.microsoft.com/en-us/azure/key-vault/general/soft-delete-overview
You have an Azure subscription that contains a Microsoft Defender External Attack Surface Management (Defender EASM) resource named EASM1. You review the Attack Surface Summary dashboard. You need to identify the following insights:
* Deprecated technologies that are no longer supported
* Infrastructure that will soon expire
Which section of the dashboard should you review?
* Deprecated technologies that are no longer supported
* Infrastructure that will soon expire
Which section of the dashboard should you review?
正解:B
解答を投票する
You have an Azure subscription.
You have the following custom role-based access control (RBAC) role definition.

For each of the following statements, select Yes if the statement is true. Otherwise, Select No.
NOTE; Each correct selection is worth one point.

You have the following custom role-based access control (RBAC) role definition.

For each of the following statements, select Yes if the statement is true. Otherwise, Select No.
NOTE; Each correct selection is worth one point.

正解:

Explanation:

You have an Azure subscription that is linked to an Azure AD tenant and contains the virtual machines shown in the following table.

The subnets of the virtual networks have the service endpoints shown in the following table.

You create the resources shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.


The subnets of the virtual networks have the service endpoints shown in the following table.

You create the resources shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

正解:

Explanation:

You have an Azure subscription that contains the resources shown in the following table.

You perform the following tasks:
Create a managed identity named Managed1.
Create a Microsoft 365 group named Group1.
You need to identify which service principals were created and which identities can be assigned the Reader role for RG1. What should you identify? To answer, select the appropriate options in the answer area. NOTE:
Each correct selection is worth one point.


You perform the following tasks:
Create a managed identity named Managed1.
Create a Microsoft 365 group named Group1.
You need to identify which service principals were created and which identities can be assigned the Reader role for RG1. What should you identify? To answer, select the appropriate options in the answer area. NOTE:
Each correct selection is worth one point.

正解:

Explanation:

You have an Azure Active Directory (Azure AD) tenant that contains a user named Admin1. Admin1 is assigned the Application developer role.
You purchase a cloud app named App1 and register App1 in Azure AD.
Admin1 reports that the option to enable token encryption for App1 is unavailable.
You need to ensure that Admin1 can enable token encryption for App1 in the Azure portal.
What should you do?
You purchase a cloud app named App1 and register App1 in Azure AD.
Admin1 reports that the option to enable token encryption for App1 is unavailable.
You need to ensure that Admin1 can enable token encryption for App1 in the Azure portal.
What should you do?
正解:D
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)
You have an Azure subscription that contains the resources shown in the following table.

Transparent Data Encryption (TDE) is disabled on SQL1.
You assign policies to the resource groups as shown in the following table.

You plan to deploy Azure SQL databases by using an Azure Resource Manager (ARM) template. The databases will be configured as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.


Transparent Data Encryption (TDE) is disabled on SQL1.
You assign policies to the resource groups as shown in the following table.

You plan to deploy Azure SQL databases by using an Azure Resource Manager (ARM) template. The databases will be configured as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

正解:

Explanation:
Graphical user interface, text, application Description automatically generated

Reference:
https://docs.microsoft.com/en-us/azure/governance/policy/concepts/effects
You need to create an Azure key vault. The solution must ensure that any object deleted from the key vault be retained for 90 days.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

Explanation:

Box 1: -EnablePurgeProtection
If specified, protection against immediate deletion is enabled for this vault; requires soft delete to be enabled as well.
Box 2: -EnableSoftDelete
Specifies that the soft-delete functionality is enabled for this key vault. When soft-delete is enabled, for a grace period, you can recover this key vault and its contents after it is deleted.
References:
https://docs.microsoft.com/en-us/powershell/module/azurerm.keyvault/new-azurermkeyvault
Lab Task
use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password. place your cursor in the Enter password box and click on the password below.
Azure Username: Userl [email protected]
Azure Password: GpOAe4@lDg
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance: 28681041
Task 6
You need to email an alert to a user named [email protected] if the average CPU usage of a virtual machine named VM1 is greater than 70 percent for a period of 15 minutes.
use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password. place your cursor in the Enter password box and click on the password below.
Azure Username: Userl [email protected]
Azure Password: GpOAe4@lDg
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance: 28681041
Task 6
You need to email an alert to a user named [email protected] if the average CPU usage of a virtual machine named VM1 is greater than 70 percent for a period of 15 minutes.
正解:
Check below steps in explanation for Task.
Explanation:
To email an alert to a user named [email protected] if the average CPU usage of a virtual machine named VM1 is greater than 70 percent for a period of 15 minutes, you can follow these steps:
* In the Azure portal, search for and select the virtual machine named VM1.
* In the left pane, select Alerts.
* Select New alert rule.
* In the New alert rule pane, enter the following information:
* Name: Enter a name for the alert rule.
* Description: Enter a description for the alert rule.
* Condition: Select Metric measurement.
* Resource: Select the virtual machine named VM1.
* Metric: Select Percentage CPU.
* Operator: Select Greater than.
* Threshold: Enter 70.
* Aggregation type: Select Average.
* Period: Select 15 minutes.
* In the Actions pane, select Add action group.
* In the Add action group pane, enter the following information:
* Name: Enter a name for the action group.
* Short name: Enter a short name for the action group.
* Email recipient: Enter the email address of the user you want to receive the alert. For example, [email protected].
* Select OK.
Explanation:
To email an alert to a user named [email protected] if the average CPU usage of a virtual machine named VM1 is greater than 70 percent for a period of 15 minutes, you can follow these steps:
* In the Azure portal, search for and select the virtual machine named VM1.
* In the left pane, select Alerts.
* Select New alert rule.
* In the New alert rule pane, enter the following information:
* Name: Enter a name for the alert rule.
* Description: Enter a description for the alert rule.
* Condition: Select Metric measurement.
* Resource: Select the virtual machine named VM1.
* Metric: Select Percentage CPU.
* Operator: Select Greater than.
* Threshold: Enter 70.
* Aggregation type: Select Average.
* Period: Select 15 minutes.
* In the Actions pane, select Add action group.
* In the Add action group pane, enter the following information:
* Name: Enter a name for the action group.
* Short name: Enter a short name for the action group.
* Email recipient: Enter the email address of the user you want to receive the alert. For example, [email protected].
* Select OK.