Summer Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the Microsoft Certified: Information Security Administrator Associate SC-500 Questions and answers with Dumpstech

Exam SC-500 Premium Access

View all detail and faqs for the SC-500 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

You have an Azure Storage account named storage1 that hosts a blob container named container1.

You have an Azure Functions app named app1 that uses a managed identity.

You need to configure app1 to read, write, and delete blobs in container1. The solution must follow the principle of least privilege.

What should you do?

Options:

A.

Assign the Storage Account Contributor role to the managed identity of app1 at the scope of storage1.

B.

Assign the Storage Blob Delegator role to the managed identity of app1 at the scope of container1.

C.

Assign the Owner role to the managed identity of app1 at the scope of container1.

D.

Assign the Storage Blob Data Contributor role to the managed identity of app1 at the scope of container1.

Questions # 12:

You have an Azure Logic Apps Consumption workflow that uses a Request trigger. All supported authentication methods are enabled on the Request trigger

You need to ensure that the endpoint accepts only OAuth-based requests. The solution must minimize costs.

What should you do?

Options:

A.

Use OAuth 2.0 authorization.

B.

Enable Secure Inputs and enable Secure Outputs for the Request trigger.

C.

Disable shared access signature (SAS) authentication for the Request trigger.

D.

Deploy Azure API Management.

Questions # 13:

You have a Microsoft 365 subscription.

You use Microsoft Entra Agent ID to manage an agent identity.

You manage AI agents from the Microsoft 365 admin center.

An autonomous agent named Agent1 runs without a signed-in user. The agent must access Microsoft Graph and read secrets from a single Azure key vault.

You need to grant Agent 1 access to Microsoft Graph and Key Vault without requiring user interaction or consent at runtime.

What should you do for the agent identity? To answer, drag the appropriate actions to the correct services. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 13

Options:

Questions # 14:

You have an Azure subscription named Sub1 that contains a storage account named storage1

Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has on-upload malware scanning enabled for a monthly cap of 10,000 GB per storage account.

You use a Microsoft Sentinel workspace to monitor security events on all Azure resources.

You need to configure storage1 to use a malware scanning cap of 2.000 GB per month.

What should you do?

Options:

A.

Enable Override Defender for Storage subscription-level settings for storage1.

B.

From Microsoft Sentinel, modify the data collection rule (DCR) to restrict log ingestion from storage1.

C.

Modify the malware scanning configuration of Sub1.

D.

From the Microsoft Sentinel workspace, modify the daily cap.

Questions # 15:

You have an Azure virtual network named VNet1 that contains an Azure Bastion Subnet. VNet1 contains a subnet named Subnet1 Subnet1 contains multiple virtual machines.

You plan to deploy Azure Bastion to provide secure RDP access to the virtual machines on Subnet1. You associate a network security group (NSG) named NSG1 to Azure Bastion Subnet.

You need to configure rules for NSG1. The solution must meet the following requirements:

•Allow required inbound access to Azure Bastion from the internet.

•Allow user access to the virtual machines by using Azure Bastion.

Which TCP ports should you allow for the NSG1 rules? To answer, drag the appropriate ports to the correct rules. Each port may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 15

Options:

Questions # 16:

You have an Azure subscription that has Microsoft Defender for Cloud enabled.

You have an Amazon Web Services (AWS) account connected to Defender for Cloud that has the Defender Cloud Security Posture Management (CSPM) plan enabled.

You need to identify the potential impact of security incidents that exploit multiple risks reported by Defender CSPM.

What should you use?

Options:

A.

Regulatory compliance

B.

Cloud security explorer

C.

Security recommendations

D.

Attack path analysis

Questions # 17:

You have two management groups named MG1 and MG2 that contain multiple Azure subscriptions. The subscriptions are linked to a Microsoft Entra tenant.

You have a user named User1 and a global administrator named Admin 1

You are informed that User1 created an Azure subscription named Sub1 under the MG2 management group and is the only owner of the subscription.

You need to ensure that Admin1 can remove the Owner role from User1 for Sub1.

What should you do first?

Options:

A.

Move Sub1 to MG1.

B.

Assign Admin1 the User Access Administrator role for Sub1.

C.

Instruct Admin1 to use Privileged Identity Management (PIM) to request the Security Administrator role.

D.

Instruct Admin1 to enable Access management for Azure resources.

Questions # 18:

You have a Microsoft Sentinel workspace named Workspace1.

You hire a security consultant. You provide the consultant with a guest account named User1 in your Microsoft Entra tenant

You need to enable User1 to assign incidents in Workspace1.

Which roles should you assign to User1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 18

Options:

Questions # 19:

You have an Azure subscription named Sub1 that contains an Azure Kubernetes Service (AKS) cluster named cluster1 and an Azure container registry named ACR1 Sub1 has Microsoft Defender for Containers enabled, and runtime protection is active on cluster!

The developers at your company deploy pods that have elevated privileges, and the deployments are created in cluster1

You need to prevent pods with elevated privileges from being accepted by cluster!

What should you do?

Options:

A.

Create an Azure Policy for cluster1.

B.

Enable agentless discovery for Kubernetes in Defender for Containers.

C.

Configure runtime threat protection alerts for privileged container activity.

D.

Enable vulnerability assessment for images in ACR1.

Questions # 20:

You have an Azure management group named MG1 that contains two subscriptions named Sub1 and Sub? Both subscriptions are linked to a Microsoft Entra tenant that contains a security group named Group!

You need to ensure that the members of Group1 can assign roles to the resources in Sub1 and Sub2. The solution must follow the principle of least privilege.

Which role should you assign to Group1?

Options:

A.

Contributor at the MG1 scope

B.

Contributor at the Sub1 and Sub2 scopes

C.

User Access Administrator at the MG1 scope

D.

Owner at the MG1 scope

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions