{"id":18452,"date":"2026-09-22T07:22:41","date_gmt":"2026-09-22T07:22:41","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18452"},"modified":"2026-09-22T07:22:41","modified_gmt":"2026-09-22T07:22:41","slug":"microsoft-az-500-practice-test-questions-and-exam-dumps-part4-q61-80","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-500-practice-test-questions-and-exam-dumps-part4-q61-80\/","title":{"rendered":"Microsoft AZ-500 Practice Test Questions and Exam Dumps Part4 Q61-80"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/az-500-exam-dumps\"><b>Microsoft AZ-500 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 61<\/b><\/h3>\n<p><b>Which Azure service is designed to manage secrets, certificates, and cryptographic keys securely?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Monitor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Key Vault provides centralized and secure management of sensitive information such as secrets, certificates, and cryptographic keys. Applications can retrieve required secrets through authorized identities instead of storing passwords or keys directly in source code. This reduces the risk of exposing sensitive information through application files or repositories. Azure Monitor focuses on monitoring and diagnostics, Azure Firewall filters network traffic, and Azure Bastion provides secure administrative access to virtual machines. Therefore, Azure Key Vault is the appropriate service for securely managing cryptographic material and application secrets.<\/span><\/p>\n<h3><b>Question 62<\/b><\/h3>\n<p><b>A security administrator wants to ensure that a user can manage virtual machines but cannot modify networking resources in the subscription. Which access-control approach should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign the user the Owner role<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign an appropriate VM-focused RBAC role<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Give the user Global Administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use a shared administrator account<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure RBAC allows administrators to assign roles that provide specific permissions required for a user&#8217;s responsibilities. If a user only needs to manage virtual machines, an appropriate virtual-machine-focused role can provide those permissions without granting unnecessary access to networking resources. Assigning Owner or broad administrator privileges would violate the principle of least privilege because those roles provide much wider permissions. Shared administrator accounts also reduce accountability. Therefore, assigning an appropriate narrowly scoped RBAC role is the best approach for limiting the user&#8217;s access to required VM operations.<\/span><\/p>\n<h3><b>Question 63<\/b><\/h3>\n<p><b>Which Microsoft Entra feature can require multifactor authentication when a user signs in from an untrusted location?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Lock<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access allows organizations to create policies that evaluate conditions such as user identity, location, device state, application, and sign-in risk. Based on those conditions, the organization can require multifactor authentication, block access, or apply other controls. Azure Policy governs resource configurations, Azure Firewall controls network traffic, and resource locks help prevent accidental modification or deletion. Therefore, Conditional Access is the appropriate Microsoft Entra feature for requiring additional authentication when users access resources from untrusted locations.<\/span><\/p>\n<h3><b>Question 64<\/b><\/h3>\n<p><b>An organization wants to prevent a production resource from being accidentally deleted by an administrator. Which Azure feature should be applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Security Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure resource locks can protect important resources against accidental modification or deletion. A delete lock can be applied to production resources when the organization wants to prevent them from being removed unintentionally. Resource locks provide an additional safeguard and should be used together with appropriate identity permissions and governance controls. Network Security Groups control network traffic, private endpoints provide private connectivity, and Azure Bastion provides secure virtual machine management. Therefore, a resource lock is the suitable feature for protecting a production resource from accidental deletion.<\/span><\/p>\n<h3><b>Question 65<\/b><\/h3>\n<p><b>A company needs to identify whether an Azure resource violates an organizational requirement and wants to evaluate compliance without necessarily deleting or blocking the resource. Which Azure capability can perform this type of assessment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure VPN Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Policy can audit resource configurations against organizational requirements. Policies can identify resources that do not comply with defined standards and provide compliance information without necessarily blocking the resource. Depending on the policy effect selected, policies can also deny noncompliant deployments or modify supported configurations. Load Balancer distributes traffic, Bastion provides secure VM access, and VPN Gateway establishes encrypted network connectivity. Therefore, Azure Policy is appropriate when an organization wants to assess whether resources comply with established governance and security requirements.<\/span><\/p>\n<h3><b>Question 66<\/b><\/h3>\n<p><b>A security team wants to monitor suspicious activity and receive recommendations for improving the security configuration of Azure workloads. Which service should they use?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Queue Storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud provides security posture management and workload protection capabilities. It can provide security recommendations, identify potential threats, and help organizations monitor and improve the security posture of supported cloud resources. Azure Storage is used to store data, Azure DNS handles name resolution, and Queue Storage supports asynchronous messaging. None of these services provides the same centralized security posture and threat-protection capabilities. Therefore, Microsoft Defender for Cloud is the appropriate service for monitoring security issues and receiving recommendations for improving Azure workload protection.<\/span><\/p>\n<h3><b>Question 67<\/b><\/h3>\n<p><b>Which network security control can filter traffic based on source and destination IP addresses, ports, and protocols?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Security Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Network Security Group provides rules that can allow or deny network traffic based on source and destination IP addresses, ports, and protocols. NSGs can be associated with subnets or network interfaces to control network communication to Azure resources. Azure Key Vault protects secrets and keys, Microsoft Entra ID Protection focuses on identity risks, and Azure Policy governs resource configurations. Therefore, an NSG is the appropriate control when administrators need to filter traffic according to network addresses, ports, and protocols.<\/span><\/p>\n<h3><b>Question 68<\/b><\/h3>\n<p><b>An application needs to retrieve a secret from Azure Key Vault. The developers do not want to store a password or client secret in the application code. Which authentication method is preferred?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Managed identity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Managed identity allows an Azure application or resource to authenticate to supported services without storing credentials directly in application code. The identity is managed by Azure and can be granted appropriate permissions to access secrets in Key Vault. This reduces the need for developers to maintain passwords, client secrets, or other long-lived credentials within the application. Anonymous authentication provides no identity protection, shared administrator credentials increase security risk, and public IP addresses are not authentication mechanisms. Therefore, managed identity is the preferred option for secure application access to Key Vault.<\/span><\/p>\n<h3><b>Question 69<\/b><\/h3>\n<p><b>A company wants to restrict a storage account so that it can be accessed only from approved virtual networks. What should the administrator configure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage network rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Storage provides network access controls that can restrict access to selected virtual networks and other approved network sources. By configuring storage network rules, an organization can reduce exposure and prevent unauthorized network locations from accessing the storage account. Traffic Manager distributes traffic through DNS-based routing, Azure CDN accelerates content delivery, and Public DNS manages publicly resolvable domain names. Therefore, storage network rules are appropriate when access to a storage account must be restricted to approved virtual networks.<\/span><\/p>\n<h3><b>Question 70<\/b><\/h3>\n<p><b>An organization wants to securely administer Azure virtual machines through a browser while avoiding direct exposure of RDP and SSH ports to the public internet. Which service should be deployed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Front Door<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Bastion provides secure RDP and SSH connectivity to virtual machines through the Azure portal. It allows administrators to connect without exposing the virtual machines&#8217; RDP or SSH ports directly to the public internet. This can reduce the attack surface associated with publicly accessible management ports. Azure Front Door provides global application delivery, Azure DNS handles domain name resolution, and Load Balancer distributes traffic. Therefore, Azure Bastion is the appropriate service for secure browser-based administrative access to Azure virtual machines.<\/span><\/p>\n<h3><b>Question 71<\/b><\/h3>\n<p><b>A company wants to prevent resources from being deployed unless they use approved resource types and configurations. Which Azure governance service can enforce this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Monitor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure CDN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Policy enables organizations to define rules that govern which resources and configurations are permitted in an Azure environment. Depending on the policy effect, administrators can audit existing resources, deny noncompliant deployments, or apply supported modifications. This makes Azure Policy useful for enforcing standards such as approved resource types, regions, tags, and security configurations. Azure Monitor focuses on observability, Azure Bastion provides VM management access, and Azure CDN accelerates content delivery. Therefore, Azure Policy is the appropriate governance service for enforcing deployment requirements.<\/span><\/p>\n<h3><b>Question 72<\/b><\/h3>\n<p><b>An administrator wants to determine who deleted a virtual network yesterday and investigate the operation. Which Azure source should be checked?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Activity Log<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure CDN logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage blob metadata<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Activity Log records management operations performed on Azure resources at the subscription level. A deletion of a virtual network is a management-plane operation, so the Activity Log can provide information about the operation, including the identity associated with the action and relevant timing information. CDN logs focus on content delivery activity, DNS records describe name-resolution configurations, and blob metadata describes stored objects. Therefore, Azure Activity Log should be checked when investigating who performed a resource deletion and when the operation occurred.<\/span><\/p>\n<h3><b>Question 73<\/b><\/h3>\n<p><b>Which security principle recommends giving an identity only the permissions required to complete its assigned task?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">High availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Elasticity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege means providing users, applications, and services only the permissions necessary to perform their intended functions. This principle reduces unnecessary access and limits the potential impact of compromised accounts or accidental actions. Defense in depth involves using multiple security controls, while high availability and elasticity relate primarily to resilience and resource scaling. Therefore, least privilege is the security principle that directly addresses limiting permissions to only those required for a specific task.<\/span><\/p>\n<h3><b>Question 74<\/b><\/h3>\n<p><b>A security architect is designing a solution where network controls, identity controls, data encryption, monitoring, and threat detection are all used together. What security strategy does this represent?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-point protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public exposure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Defense in depth uses multiple complementary security controls so that protection does not depend on a single mechanism. Identity controls can restrict who accesses resources, network controls can limit communication, encryption can protect data, monitoring can identify suspicious activity, and threat detection can help respond to attacks. If one layer is bypassed, additional layers may still reduce the attacker&#8217;s ability to access or damage resources. Therefore, a security architecture combining several different protective mechanisms represents the defense-in-depth strategy.<\/span><\/p>\n<h3><b>Question 75<\/b><\/h3>\n<p><b>A company needs to allow an administrator to manage resources only inside a particular subscription. Which RBAC scope is appropriate if the permissions should apply across that subscription but not other subscriptions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Management group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Subscription<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Individual resource<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource property<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Azure RBAC role assignment at the subscription scope applies the assigned permissions to resources within that subscription, subject to the role definition and inheritance behavior. This allows an administrator to manage appropriate resources across the subscription without automatically extending the same assignment to unrelated subscriptions. A management group scope can affect multiple subscriptions, while an individual resource scope is narrower. Resource properties are not an RBAC assignment scope. Therefore, subscription scope is appropriate when permissions should cover resources within one specific subscription.<\/span><\/p>\n<h3><b>Question 76<\/b><\/h3>\n<p><b>A security team wants to protect a public web application from common HTTP-based attacks while maintaining the ability to inspect incoming web requests. Which Azure service is most suitable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Web Application Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure VPN Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Lock<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Web Application Firewall provides application-layer protection for web applications by inspecting HTTP and HTTPS requests. It can help identify and block common web attacks, including SQL injection and cross-site scripting, using supported rules and configurations. Azure Key Vault manages secrets and cryptographic keys, VPN Gateway provides encrypted network connectivity, and resource locks protect resources from accidental modification or deletion. Therefore, Web Application Firewall is the most suitable service when a public web application needs inspection and protection against common HTTP-based attacks.<\/span><\/p>\n<h3><b>Question 77<\/b><\/h3>\n<p><b>An organization has a policy requiring all resources to include an owner tag. The team wants Azure to identify resources that do not meet this requirement. Which service should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Policy can evaluate resource configurations and identify resources that do not comply with organizational requirements. A policy can audit whether required tags, such as an owner tag, are present on resources. Depending on the policy configuration, organizations may also use supported policy effects to enforce or modify certain resource settings. Azure Firewall filters network traffic, Bastion provides secure VM administration, and DDoS Protection addresses denial-of-service threats. Therefore, Azure Policy is the appropriate service for monitoring and enforcing resource-tag requirements.<\/span><\/p>\n<h3><b>Question 78<\/b><\/h3>\n<p><b>An application needs to connect securely to an Azure service using a private IP address within its virtual network. Which feature provides this connectivity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet-facing load balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A private endpoint provides a private IP address from an Azure virtual network for accessing supported Azure services. This allows applications to communicate with the service through private network connectivity rather than using a public endpoint. Private endpoints can help reduce public exposure and support network isolation requirements. A public endpoint, public DNS zone, and internet-facing load balancer are associated with public accessibility rather than private service connectivity. Therefore, a private endpoint is the appropriate feature when an application needs to access a supported Azure service using private network connectivity.<\/span><\/p>\n<h3><b>Question 79<\/b><\/h3>\n<p><b>A security administrator wants to review security recommendations and determine whether Azure workloads have unresolved security issues. Which service should provide this centralized security view?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Queue Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud provides a centralized view of security posture information, recommendations, and security alerts for supported cloud resources. It can help security teams identify unresolved security issues and prioritize improvements across workloads. Azure DNS provides name resolution, Queue Storage supports asynchronous messaging, and Load Balancer distributes network traffic. These services do not provide the same security posture management capabilities. Therefore, Microsoft Defender for Cloud is the appropriate service for reviewing security recommendations and identifying unresolved security issues.<\/span><\/p>\n<h3><b>Question 80<\/b><\/h3>\n<p><b>A security architect wants an application to use short-lived access to sensitive resources rather than permanently storing privileged credentials. Which approach most closely supports this security goal?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent shared passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Just-in-time privileged access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public administrative endpoints<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Just-in-time privileged access reduces standing administrative privileges by allowing users to activate elevated access only when it is required and for a limited period. Microsoft Entra Privileged Identity Management supports this type of controlled privileged access. Reducing permanent privileges can lower the risk associated with compromised accounts and accidental administrative actions. Permanent shared passwords create credential-management and accountability risks, while anonymous access and public administrative endpoints increase exposure. Therefore, just-in-time privileged access most closely supports the goal of using temporary access instead of permanently stored privileged credentials.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AZ-500 Exam Dumps and Practice Test Dumps. &nbsp; Question 61 Which Azure service is designed to manage secrets, certificates, and cryptographic keys securely? Azure Monitor Azure Key Vault Azure Firewall Azure Bastion Correct Answer: 2 Explanation Azure Key Vault provides centralized and secure management of sensitive information such as secrets, certificates, and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18452"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18452"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18452\/revisions"}],"predecessor-version":[{"id":18453,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18452\/revisions\/18453"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18452"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18452"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18452"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}