SC-500 無料問題集「Microsoft Implementing End-to-End Security Controls for Cloud and AI Workloads」

You have an Azure Storage account named storage1 that hosts a blob container named container1.
You have an Azure Functions app named app1 that uses a managed identity.
You need to configure app1 to read, write, and delete blobs in container1. The solution must follow the principle of least privilege.
What should you do?

解説: (JPNTest メンバーにのみ表示されます)
You have a Microsoft Entra tenant that has user consent for applications disabled.
You register an application named App1 that requests the following Microsoft Graph delegated permissions:
*user.Read
*Mail.Read
You need to configure tenant permissions to meet the following requirements:
*Enable users to grant consent for low-risk permissions without administrator interaction.
*Ensure that applications requesting higher-privilege permissions require administrator approval.
What should you do?

解説: (JPNTest メンバーにのみ表示されます)
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals.
More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.
You have an Azure Storage account named storage. Public access from all networks is enabled for storage1.
You need to ensure that VM1 and VM2 can access storage1.
Solution: You create a private endpoint on storage1.
Does this meet the goal?

解説: (JPNTest メンバーにのみ表示されます)
You have an Azure Functions app named App1 that uses an HTTP trigger, runs on an Elastic Premium plan, and uses virtual network integration.
A partner application sends requests to App1 from a public IP address of xxx.xxx.xxx.xx.
You need to ensure that the requests are accepted from only xxx.xxx.xxx.xx.
What should you do?

解説: (JPNTest メンバーにのみ表示されます)
You have an Azure API Management instance named APIM1 that publishes an API named OrdersAPI.
Applications call OrdersAPI by using Microsoft Entra access tokens.
A security review finds that requests that do NOT contain a valid access token can still be forwarded to OrdersAPI.
You need to ensure that APIM1 rejects requests that do NOT contain a valid Microsoft Entra token before the requests reach OrdersAPI.
What should you configure?

You use Azure Virtual Network Manager to manage multiple virtual networks organized into two network groups named Production and Development.
You need to configure Virtual Network Manager to meet the following requirements:
Allow traffic between all the virtual networks in Production.
Block traffic between Development and Production.
What should you use for each requirement? To answer, drag the components to the correct requirements. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
正解:

Explanation:
Requirement
Component
To allow traffic between all the virtual networks in Production
A connectivity configuration
To block traffic between Development and Production
A security admin configuration
An Azure Virtual Network Manager connectivity configuration defines how virtual networks within network groups communicate. For the Production network group, a connectivity configuration can implement a mesh topology , which establishes connectivity among the virtual networks in that group without requiring administrators to create and maintain individual VNet peerings. Microsoft documents connectivity configurations as the mechanism for establishing managed connectivity patterns such as mesh and hub-and- spoke across virtual networks.
To prevent communication between the Development and Production environments, use a security admin configuration . Security admin configurations contain centrally managed security admin rule collections that can Allow, Always Allow, or Deny network traffic. These rules can be applied across targeted network groups and are specifically suitable for enforcing network segmentation. Microsoft identifies blocking traffic between virtual networks or subnets as a supported security-admin-rule scenario. A Deny security admin rule terminates traffic evaluation and prevents the traffic from reaching the destination, independently of ordinary NSG permissions.
A routing configuration controls routing behavior rather than organizational security segmentation. IPAM manages address-space planning and allocation, while a scope defines which resources Virtual Network Manager can manage; neither directly satisfies these two traffic-control requirements.
You have an Azure subscription that has Microsoft Defender for Cloud enabled.
You have an Amazon Web Services (AWS) account connected to Defender for Cloud that has the Defender Cloud Security Posture Management (CSPM) plan enabled.
You need to identify the potential impact of security incidents that exploit multiple risks reported by Defender CSPM.
What should you use?

解説: (JPNTest メンバーにのみ表示されます)

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡