Weekend Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

AZ-500 Exam Dumps - Microsoft Azure Security Engineer Associate Questions and Answers

Question # 24

You have an Azure Sentinel workspace that has an Azure Active Directory (Azure AD) data connector.

You are threat hunting suspicious traffic from a specific IP address.

You need to annotate an intermediate event stored in the workspace and be able to reference the IP address when navigating through the investigation graph.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Options:

Buy Now
Question # 25

You have an Azure subscription that uses Microsoft Defender for Cloud.

You have an Amazon Web Service (AWS) account named AWS1 that is connected to defender for Cloud.

You need to ensure that AWS foundational Security Best Practices. The solution must minimize administrate effort.

What should do you in Defender for Cloud?

Options:

A.

Create a new customer assessment.

B.

Assign a built-in assessment.

C.

Assign a built-in compliance standard.

D.

Create a new custom standard.

Buy Now
Question # 26

You need to implement the planned change for WAF1.

The solution must minimize administrative effort

What should you do?

Options:

A.

Create an Azure policy.

B.

Modify the Azure-managed DRS.

C.

Add a custom rule.

D.

Modify the Bot Manager 1.1 rule set.

Buy Now
Question # 27

You implement the planned changes for the key vaults.

To which key vaults can you restore AKV1 backups?

Options:

A.

AKV4only

B.

AKV3 and AKV4 only

C.

AKV4 and AKV5 only

D.

AKV2, AKV3, and AKV4 only

E.

AKV2, AKV3, AKV4, and AKV5

Buy Now
Question # 28

You need to implement the planned change for SQLdb1.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

Create a compliance policy.

B.

Configure Microsoft Entra authentication for SQLServer1.

C.

Create a Conditional Access policy.

D.

Configure a user-assigned managed identity for SQLdb1.

E.

Configure Federated client identity for SQLdb1.

Buy Now
Question # 29

You have an Azure subscription that contains a user named User1. You need to ensure that User1 can create managed identities. The solution must use the principle of least privilege.

What should you do?

Options:

A.

Create a resource group and assign User1 to the Managed Identity Contributor role.

B.

Create a management group and assign User1 the Managed Identity Operator role.

C.

Create an organizational unit (OU) and assign User1 the User administrator Azure AD role.

D.

Create management group and assign User1 the Hybrid Identity Administrator Azure AD role.

Buy Now
Question # 30

You have a Microsoft Entra tenant that contains a user named User1.

You have an app registration named App1.

For App1, you create an app role named Role1.

You need to assign User1 to Role1.

What should you use in the Azure portal?

Options:

A.

Roles and administrators for App1 from Enterprise applications

B.

App roles for App1 from App registrations

C.

Users and groups for App1 from Enterprise applications

D.

API permissions for App1 from App registrations

E.

Roles and administrators from the Microsoft Entra admin center

Buy Now
Question # 31

You have an Azure subscription that contains an Azure Data Lake Storage account named sa1.

You plan to deploy an app named App1 that will access sa1 and perform operations, including Read. List, Create Directory, and Delete Directory.

You need to ensure that App1 can connect securely to sa1 by using a private endpoint

What is the minimum number of private endpoints required for sa1?

Options:

A.

1

B.

2

C.

3

D.

4

E.

5

Buy Now
Question # 32

You have an Azure subscription mat contains a resource group named RG1. RG1 contains a storage account named storage1.

You have two custom Azure rotes named Role1 and Role2 that are scoped to RG1.

The permissions for Role1 are shown in the following JSON code.

Options:

Buy Now
Question # 33

You have an Azure Container Registry named ContReg1 that contains a container image named image1.

You enable content trust for ContReg1.

After content trust is enabled, you push two images to ContReg1 as shown in the following table.

Which images are trusted images?

Options:

A.

image1 and image2 only

B.

image2 only

C.

image1, image2, and image3

Buy Now
Exam Code: AZ-500
Exam Name: Microsoft Azure Security Technologies
Last Update: Aug 16, 2025
Questions: 492
AZ-500 pdf

AZ-500 PDF

$28.5  $94.99
AZ-500 Engine

AZ-500 Testing Engine

$33  $109.99
AZ-500 PDF + Engine

AZ-500 PDF + Testing Engine

$43.5  $144.99