{"id":18450,"date":"2026-09-22T07:22:18","date_gmt":"2026-09-22T07:22:18","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18450"},"modified":"2026-09-22T07:22:18","modified_gmt":"2026-09-22T07:22:18","slug":"microsoft-az-500-practice-test-questions-and-exam-dumps-part3-q41-60","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-500-practice-test-questions-and-exam-dumps-part3-q41-60\/","title":{"rendered":"Microsoft AZ-500 Practice Test Questions and Exam Dumps Part3 Q41-60"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/az-500-exam-dumps\"><b>Microsoft AZ-500 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 41<\/b><\/h3>\n<p><b>Which Azure service provides centralized network traffic filtering for resources across virtual networks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall is a managed, stateful network security service that provides centralized traffic filtering for Azure virtual networks. It can control network traffic using rules for applications, network addresses, ports, and other supported criteria. This makes it useful when an organization needs a centralized security control for traffic flowing between networks or toward external destinations. Azure Key Vault manages secrets and keys, Entra ID Protection focuses on identity risks, and Azure Policy governs resource configurations. Therefore, Azure Firewall is the appropriate service for centralized network traffic filtering.<\/span><\/p>\n<h3><b>Question 42<\/b><\/h3>\n<p><b>An administrator needs to create a security rule that allows HTTPS traffic to a virtual machine while blocking other unwanted inbound connections. Which port should be allowed for HTTPS?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">22<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">53<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">80<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">443<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HTTPS normally uses TCP port 443 for encrypted web communication. A security rule can allow inbound traffic on port 443 when a web application or service needs to receive secure HTTPS connections. Port 22 is commonly used for SSH, port 53 is associated with DNS, and port 80 is commonly used for unencrypted HTTP traffic. Network security controls such as Network Security Groups can use ports and protocols as conditions in traffic rules. Therefore, TCP port 443 is the appropriate port for HTTPS traffic.<\/span><\/p>\n<h3><b>Question 43<\/b><\/h3>\n<p><b>A company wants to provide secure access to Azure resources from employees working remotely without exposing internal services directly to the public internet. Which connectivity option can establish an encrypted connection from a user device to an Azure virtual network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Point-to-site VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A point-to-site VPN provides an encrypted connection between an individual client device and an Azure virtual network. It is useful when remote employees or administrators need secure access to resources hosted inside Azure without making those resources directly accessible from the public internet. Public DNS provides name resolution, Azure CDN accelerates content delivery, and Traffic Manager distributes traffic using DNS-based routing. Therefore, point-to-site VPN is the appropriate connectivity option when individual remote users need secure access to an Azure virtual network.<\/span><\/p>\n<h3><b>Question 44<\/b><\/h3>\n<p><b>A network security team wants to inspect and control traffic based on application-layer characteristics rather than only IP addresses and ports. Which Azure service is designed for this purpose?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Queue Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall provides centralized network security and supports application and network traffic filtering capabilities. Application rules can help control outbound traffic based on supported application-level information, while network rules can filter traffic using network addresses, ports, and protocols. Azure Storage is used for storing data, Queue Storage supports messaging scenarios, and Key Vault protects secrets and cryptographic material. Therefore, Azure Firewall is the service among these options designed to provide centralized inspection and control of network traffic using application-aware and network-level rules.<\/span><\/p>\n<h3><b>Question 45<\/b><\/h3>\n<p><b>An organization needs to ensure that only approved administrators can modify critical Azure resources. What combination best supports this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP addresses and DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RBAC and least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CDN and caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing and autoscaling<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role-Based Access Control and the principle of least privilege can work together to restrict administrative actions to authorized identities. RBAC assigns permissions through roles, while least privilege ensures that users receive only the permissions necessary for their responsibilities. This combination reduces unnecessary administrative access and helps limit the impact of compromised accounts. Public IP addresses and DNS address networking, CDN and caching improve content delivery, and load balancing and autoscaling address availability and performance. Therefore, RBAC combined with least privilege is appropriate for restricting administrative changes.<\/span><\/p>\n<h3><b>Question 46<\/b><\/h3>\n<p><b>A security engineer wants to identify configuration weaknesses across an Azure environment and prioritize actions that can improve its overall security posture. Which service should be reviewed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Data Box<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud provides security posture management capabilities that can identify security recommendations and configuration weaknesses across supported cloud resources. It helps organizations understand their current security posture and prioritize improvements based on identified recommendations and risks. Azure Data Box is designed for data transfer, Load Balancer distributes network traffic, and Azure DNS provides name resolution. Therefore, Defender for Cloud is the most relevant service when security teams need centralized visibility into configuration weaknesses and recommendations for improving the security posture.<\/span><\/p>\n<h3><b>Question 47<\/b><\/h3>\n<p><b>Which Azure feature allows an administrator to assign permissions to users or groups for specific Azure resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure RBAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Monitor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Role-Based Access Control allows administrators to assign permissions to users, groups, service principals, and managed identities. Roles can be assigned at scopes such as management groups, subscriptions, resource groups, or individual resources. This enables organizations to control which actions identities can perform and where those permissions apply. Azure CDN and Front Door focus on application delivery and traffic routing, while Azure Monitor provides monitoring and observability. Therefore, Azure RBAC is the Azure authorization mechanism used to assign permissions to identities.<\/span><\/p>\n<h3><b>Question 48<\/b><\/h3>\n<p><b>A company uses Azure Storage for sensitive business documents. The security team wants the storage account to accept requests only from a predefined list of public IP addresses. Which configuration can support this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage firewall and network rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Storage network access controls can restrict access to selected public IP addresses and virtual networks. Storage firewall and network rules allow administrators to define which network sources are permitted to connect to supported storage services. This can reduce exposure by preventing requests from unauthorized network locations. Azure Bastion provides administrative access to virtual machines, Traffic Manager performs DNS-based traffic distribution, and DDoS Protection focuses on denial-of-service attacks. Therefore, storage firewall and network rules are appropriate for limiting storage access to predefined public IP addresses.<\/span><\/p>\n<h3><b>Question 49<\/b><\/h3>\n<p><b>A development team needs to store a database password used by an application. The password should not appear in source code, configuration files, or deployment scripts. Which service should store it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Monitor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Virtual Network<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Key Vault is designed to securely store secrets such as passwords, connection strings, tokens, certificates, and cryptographic keys. Applications can retrieve secrets from Key Vault through authorized identities instead of embedding sensitive values in source code or configuration files. This approach helps reduce the risk of credentials being accidentally exposed through source repositories or deployment artifacts. Azure Monitor handles observability, Load Balancer distributes traffic, and Virtual Network provides networking. Therefore, Azure Key Vault is the appropriate service for securely storing an application&#8217;s database password.<\/span><\/p>\n<h3><b>Question 50<\/b><\/h3>\n<p><b>A security team wants to ensure that a particular Azure resource cannot be accidentally deleted even by an authorized user performing routine administrative work. Which Azure feature can provide this protection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Security Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure CDN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure resource locks help prevent accidental modification or deletion of important resources. A delete lock can be applied when an organization wants to ensure that a resource remains available even if an authorized administrator unintentionally attempts to remove it. Resource locks are an additional safeguard and do not replace proper identity permissions or governance policies. Network Security Groups control network traffic, Azure DNS provides name resolution, and Azure CDN supports content delivery. Therefore, a resource lock is the appropriate feature for protecting an important Azure resource against accidental deletion.<\/span><\/p>\n<h3><b>Question 51<\/b><\/h3>\n<p><b>An administrator needs to protect a virtual network from unauthorized inbound traffic. The administrator wants rules based on source address, destination port, and protocol. Which Azure control should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Security Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Network Security Group provides network security rules that can allow or deny inbound and outbound traffic based on conditions such as source and destination addresses, ports, and protocols. NSGs can be associated with subnets or network interfaces to control traffic reaching Azure resources. Key Vault protects sensitive information, Entra ID Protection detects identity risks, and Azure Policy enforces resource governance requirements. Therefore, an NSG is the appropriate Azure control when network traffic needs to be filtered using source addresses, ports, and protocols.<\/span><\/p>\n<h3><b>Question 52<\/b><\/h3>\n<p><b>A company has deployed an internet-facing application and wants protection against distributed denial-of-service attacks that attempt to overwhelm the application with large amounts of traffic. Which Azure capability addresses this threat?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure DDoS Protection is designed to help defend supported Azure resources against distributed denial-of-service attacks. DDoS attacks attempt to make services unavailable by overwhelming them with large volumes of traffic or other malicious requests. DDoS Protection provides additional safeguards for applications and network resources against these attacks. Azure Key Vault protects secrets and keys, Azure Policy governs resource configurations, and Azure Bastion provides secure virtual machine administration. Therefore, Azure DDoS Protection is the appropriate capability for reducing the impact of distributed denial-of-service attacks.<\/span><\/p>\n<h3><b>Question 53<\/b><\/h3>\n<p><b>An organization wants to enforce a rule requiring all newly created resources to use only approved Azure regions. Which Azure governance tool should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Monitor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Policy enables organizations to define and enforce governance requirements for Azure resources. A policy can restrict resource deployments to approved regions and can audit or deny deployments that do not comply with the defined requirement. This helps organizations maintain consistent security, regulatory, or operational standards. Azure Bastion provides secure VM access, Azure Monitor provides monitoring, and Load Balancer distributes network traffic. Therefore, Azure Policy is the appropriate governance tool for enforcing approved-region requirements on newly created Azure resources.<\/span><\/p>\n<h3><b>Question 54<\/b><\/h3>\n<p><b>A security architect wants to protect a web application by filtering malicious HTTP requests before they reach the application. The architect also wants rules specifically designed for common web attacks. What should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Web Application Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure VPN Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage Queue<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Web Application Firewall provides application-layer protection by inspecting HTTP and HTTPS requests and applying rules designed to detect common web attacks. It can help protect applications against threats such as SQL injection and cross-site scripting. This makes WAF different from network-level controls that primarily filter traffic according to addresses, ports, and protocols. VPN Gateway provides encrypted network connectivity, Private DNS manages private name resolution, and Storage Queue provides messaging functionality. Therefore, Web Application Firewall is the appropriate choice for filtering malicious web requests.<\/span><\/p>\n<h3><b>Question 55<\/b><\/h3>\n<p><b>An administrator is reviewing permissions for an application that needs to read files from a storage account but does not need to delete or modify them. Which access-design approach follows the principle of least privilege?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Grant full administrative access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Grant only the required read permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Grant subscription owner permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Share a global administrator account<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege requires an identity to receive only the permissions necessary to perform its assigned task. If an application only needs to read files, granting write, delete, or administrative permissions would provide unnecessary access. Excessive permissions increase the potential impact of compromised credentials or application vulnerabilities. Subscription Owner permissions and shared administrator accounts provide much broader access than required. Therefore, assigning only the required read permissions is the appropriate access design because it satisfies the application&#8217;s functional requirement while minimizing unnecessary privileges.<\/span><\/p>\n<h3><b>Question 56<\/b><\/h3>\n<p><b>A company wants to audit whether users are making unauthorized configuration changes to Azure resources. Which source provides records of management operations performed on the Azure subscription?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Activity Log<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure CDN cache<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage container<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Activity Log records management-plane operations performed on Azure resources at the subscription level. Security teams can use these records to investigate actions such as resource creation, deletion, configuration changes, and other administrative operations. This makes the Activity Log useful for auditing and investigating unexpected changes. A CDN cache stores content for delivery, a DNS zone contains name-resolution records, and a storage container organizes stored data. Therefore, Azure Activity Log is the appropriate source for reviewing management operations and investigating configuration changes.<\/span><\/p>\n<h3><b>Question 57<\/b><\/h3>\n<p><b>An organization needs to provide an application with access to Azure resources using an identity that Azure manages automatically. Which option should be selected?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Managed identity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared password<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public certificate file<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Managed identities provide Azure resources with identities that can authenticate to supported Azure services without requiring developers to manage credentials directly. Azure manages the identity and its authentication credentials, while administrators can assign appropriate permissions through supported authorization mechanisms. Using shared passwords or storing credentials manually increases the burden of credential management and can create security risks. Anonymous access removes authentication rather than strengthening it. Therefore, a managed identity is the appropriate option when an application needs Azure-managed identity-based access to resources.<\/span><\/p>\n<h3><b>Question 58<\/b><\/h3>\n<p><b>A security administrator wants users to activate privileged roles only when they need to perform a specific administrative task, with access automatically ending after a defined period. Which solution is designed for this scenario?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Application Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management is designed to manage privileged access using controlled and time-limited role activation. Users can be eligible for privileged roles and activate them when necessary, rather than maintaining permanent active privileges. Organizations can configure controls such as activation duration, approval, justification, and multifactor authentication. Traffic Manager handles DNS-based traffic routing, Storage firewall controls storage network access, and Application Gateway provides application delivery and web traffic management. Therefore, PIM is the appropriate solution for temporary and controlled activation of privileged roles.<\/span><\/p>\n<h3><b>Question 59<\/b><\/h3>\n<p><b>A security team wants to reduce the number of publicly accessible endpoints in its Azure environment. For a supported Azure service, which option provides private connectivity from an Azure virtual network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public load balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A private endpoint provides a private IP address within an Azure virtual network for accessing supported Azure services. This enables applications to communicate with the service through private connectivity and can reduce dependence on publicly exposed endpoints. A public IP address and public load balancer provide public network accessibility, while an internet gateway is not the Azure feature used for this specific private-service connectivity model. Therefore, a private endpoint is the appropriate option when the security goal is to reduce public exposure while maintaining access from an Azure virtual network.<\/span><\/p>\n<h3><b>Question 60<\/b><\/h3>\n<p><b>An organization is designing security controls for a critical Azure workload. The team plans to restrict permissions, protect secrets, filter network traffic, monitor activity, and continuously review security recommendations. What is the main benefit of using multiple complementary security controls?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It eliminates the need for authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It creates multiple layers of protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It guarantees that attacks cannot occur<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It removes the need for monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Using multiple complementary security controls creates layers of protection across identities, data, networks, resources, and monitoring processes. This approach is commonly associated with defense in depth. If one security control is bypassed or fails to prevent an attack, other controls may still limit access, detect suspicious behavior, protect sensitive information, or reduce the attacker&#8217;s ability to move further through the environment. No security architecture can guarantee that attacks will never occur. Therefore, combining access controls, secret protection, network security, and monitoring provides multiple defensive layers.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AZ-500 Exam Dumps and Practice Test Dumps. &nbsp; Question 41 Which Azure service provides centralized network traffic filtering for resources across virtual networks? Azure Key Vault Microsoft Entra ID Protection Azure Firewall Azure Policy Correct Answer: 3 Explanation Azure Firewall is a managed, stateful network security service that provides centralized traffic filtering [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18450"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18450"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18450\/revisions"}],"predecessor-version":[{"id":18451,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18450\/revisions\/18451"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18450"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18450"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18450"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}