{"id":18458,"date":"2026-09-22T07:23:56","date_gmt":"2026-09-22T07:23:56","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18458"},"modified":"2026-09-22T07:23:56","modified_gmt":"2026-09-22T07:23:56","slug":"microsoft-az-500-practice-test-questions-and-exam-dumps-part7-q121-140","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-500-practice-test-questions-and-exam-dumps-part7-q121-140\/","title":{"rendered":"Microsoft AZ-500 Practice Test Questions and Exam Dumps Part7 Q121-140"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/az-500-exam-dumps\"><b>Microsoft AZ-500 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 121<\/b><\/h3>\n<p><b>Which Azure service can help identify suspicious sign-in patterns and assign risk levels to authentication events?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID Protection analyzes identity-related signals to detect potentially risky users and sign-ins. It can identify suspicious authentication patterns and assign risk information that organizations can use in their identity security policies. Risk-based Conditional Access policies can then require additional verification or block access when appropriate. Azure Policy governs resource configurations, Azure Firewall protects network traffic, and Azure Storage provides data services. Therefore, Microsoft Entra ID Protection is the appropriate service for detecting and evaluating identity-related risks during authentication.<\/span><\/p>\n<h3><b>Question 122<\/b><\/h3>\n<p><b>An administrator needs to prevent a resource from being deleted but must still allow authorized administrators to change its configuration. Which resource lock should be selected?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ReadOnly<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CanNotDelete<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deny<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The CanNotDelete resource lock prevents a protected Azure resource from being deleted while still permitting authorized users to modify its configuration. This makes it useful for important production resources where administrators need to make operational changes but accidental deletion must be prevented. A ReadOnly lock is more restrictive because it prevents both modification and deletion. Audit and Deny are not Azure resource lock types. Therefore, CanNotDelete is the appropriate lock when deletion must be prevented without blocking authorized configuration changes.<\/span><\/p>\n<h3><b>Question 123<\/b><\/h3>\n<p><b>A company wants to route security logs from several Azure resources into Microsoft Sentinel for centralized analysis. Which destination is commonly used through Azure diagnostic settings?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log Analytics workspace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion subnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS zone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Log Analytics workspace can serve as a centralized destination for logs collected from supported Azure resources through diagnostic settings. Microsoft Sentinel can use data stored in a connected Log Analytics workspace for security analytics, investigations, detections, and incident management. This design allows security teams to bring information from multiple Azure services into a centralized monitoring environment. Azure Bastion subnets, Load Balancer, and public DNS zones are not centralized security-log destinations. Therefore, a Log Analytics workspace is the appropriate destination for collecting and analyzing Azure security data with Sentinel.<\/span><\/p>\n<h3><b>Question 124<\/b><\/h3>\n<p><b>Which Azure security control is primarily responsible for inspecting and filtering network traffic at the subnet or network-interface level?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Security Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Network Security Group provides network-level access control rules that can allow or deny traffic associated with Azure subnets and network interfaces. Rules can evaluate information such as source and destination addresses, ports, and protocols. This makes NSGs useful for controlling communication between application tiers and restricting unnecessary network access. Key Vault manages secrets and keys, Microsoft Sentinel provides security analytics, and Entra ID Protection addresses identity risks. Therefore, a Network Security Group is the appropriate control for filtering traffic at the subnet or network-interface level.<\/span><\/p>\n<h3><b>Question 125<\/b><\/h3>\n<p><b>An organization wants to ensure that a privileged administrator can activate an elevated role only for a limited period instead of retaining permanent access. Which feature should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure CDN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management helps organizations reduce standing administrative privileges by allowing eligible users to activate privileged roles when needed. Activation can be limited by duration and may also require controls such as multifactor authentication, approval, justification, or notifications. This approach reduces the period during which powerful permissions are available to an account. Azure DNS, Azure Storage, and Azure CDN provide networking, storage, and content-delivery functionality rather than privileged identity management. Therefore, Microsoft Entra PIM is the appropriate feature for temporary elevated administrative access.<\/span><\/p>\n<h3><b>Question 126<\/b><\/h3>\n<p><b>Which Azure capability can help enforce that only approved resource types are deployed within a subscription?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Monitor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Policy allows organizations to define and enforce governance requirements for Azure resources. An administrator can create policies that restrict or audit resource types, regions, tags, configurations, and other supported properties. A deny policy can prevent noncompliant deployments from being created. Azure Monitor focuses on monitoring and observability, Bastion provides secure virtual machine access, and Traffic Manager provides DNS-based traffic routing. Therefore, Azure Policy is the appropriate governance mechanism for ensuring that deployments comply with approved resource-type requirements.<\/span><\/p>\n<h3><b>Question 127<\/b><\/h3>\n<p><b>A security team wants to protect sensitive web applications from common application-layer attacks while using a managed Azure service. Which option is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Web Application Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Graph<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure VPN Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Web Application Firewall provides managed application-layer protection for supported web application delivery services. It can inspect HTTP and HTTPS requests and use security rules to help detect and block common attacks such as SQL injection and cross-site scripting. Resource Graph is used to query Azure resources, Key Vault protects secrets and cryptographic material, and VPN Gateway provides encrypted network connectivity. Therefore, Azure Web Application Firewall is the appropriate managed security option for protecting web applications from common application-layer threats.<\/span><\/p>\n<h3><b>Question 128<\/b><\/h3>\n<p><b>A company needs to give an Azure application access to another Azure service without storing a client secret in the application&#8217;s source code. What should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Managed identity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A managed identity provides an Azure workload with an identity that can authenticate to supported Azure services without requiring developers to embed client secrets or passwords in application code. Azure manages the identity credentials, while administrators assign the required permissions. This reduces the risk of exposed long-lived credentials and simplifies application authentication. Public IP addresses do not authenticate applications, shared administrator accounts create unnecessary security and accountability risks, and anonymous access removes identity-based protection. Therefore, managed identity is the appropriate approach for secure application-to-service authentication.<\/span><\/p>\n<h3><b>Question 129<\/b><\/h3>\n<p><b>Which Azure service can help security teams investigate incidents by correlating security events and creating incidents from detected threats?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel provides cloud-native SIEM and SOAR capabilities for collecting, correlating, and analyzing security events. Analytics rules can identify suspicious patterns and generate alerts that contribute to security incidents. Security analysts can then investigate incidents using collected data, entity information, and related events. Azure Load Balancer distributes network traffic, Azure DNS manages name resolution, and Azure Bastion provides secure VM administration. Therefore, Microsoft Sentinel is the appropriate service for centralized security incident detection, investigation, and response.<\/span><\/p>\n<h3><b>Question 130<\/b><\/h3>\n<p><b>An organization wants to make Azure Storage accessible only through private network connectivity from approved virtual networks. Which configuration should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet-facing load balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A private endpoint provides a private IP address inside a virtual network for accessing supported Azure services such as Azure Storage. This allows applications to communicate with the service through private connectivity rather than depending on its public endpoint. Organizations can combine private endpoints with appropriate DNS and network controls to support isolated architectures. Public IP addresses, internet-facing load balancers, and public DNS do not by themselves provide private service connectivity. Therefore, a private endpoint is the appropriate configuration for private access to Azure Storage.<\/span><\/p>\n<h3><b>Question 131<\/b><\/h3>\n<p><b>Which Azure service can provide security recommendations for improving the configuration of virtual machines and other cloud workloads?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Queue Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud provides security posture management capabilities that can identify weaknesses and generate recommendations for supported Azure workloads. Security teams can review recommendations and use them to improve configurations, reduce exposure, and address security gaps. Defender for Cloud can also provide workload protection and threat detection capabilities depending on the enabled plans and services. Azure DNS, Queue Storage, and Load Balancer provide networking, messaging, and traffic-distribution functions rather than centralized security recommendations. Therefore, Microsoft Defender for Cloud is the appropriate service.<\/span><\/p>\n<h3><b>Question 132<\/b><\/h3>\n<p><b>An administrator needs to query Azure resources across many subscriptions to identify all virtual machines missing a required security tag. Which service is designed for this type of large-scale resource query?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Graph<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure VPN Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Resource Graph is designed for efficiently querying Azure resource information across large environments and multiple subscriptions. Administrators can use its query capabilities to locate resources based on properties such as resource type, location, tags, and configuration values. This makes it useful for security inventory, governance checks, and compliance investigations. Azure Bastion provides secure VM access, VPN Gateway provides encrypted network connectivity, and Key Vault manages secrets and keys. Therefore, Azure Resource Graph is the appropriate service for large-scale resource inventory and security queries.<\/span><\/p>\n<h3><b>Question 133<\/b><\/h3>\n<p><b>Which Azure capability can help an organization review whether guest users still require access to groups and applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra access reviews provide a governance mechanism for periodically reviewing whether users should retain access to applications, groups, and other resources. They are particularly useful for guest and external users because access requirements may change over time. Reviewers can confirm whether access should continue and remove unnecessary permissions according to organizational processes. Azure Firewall protects network traffic, DDoS Protection mitigates denial-of-service attacks, and Storage provides data services. Therefore, Microsoft Entra access reviews are appropriate for periodically validating guest-user access.<\/span><\/p>\n<h3><b>Question 134<\/b><\/h3>\n<p><b>A company wants to protect a critical Azure resource against accidental deletion while continuing to permit authorized configuration changes. Which control should be applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ReadOnly resource lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CanNotDelete resource lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy audit rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A CanNotDelete resource lock prevents deletion while allowing authorized users to continue modifying the protected resource. This is useful for critical resources where configuration changes may be necessary but accidental deletion could cause significant disruption. A ReadOnly lock prevents both modification and deletion and is therefore more restrictive. A public endpoint does not provide deletion protection, while an Azure Policy audit rule reports compliance without functioning as a resource lock. Therefore, a CanNotDelete resource lock is the suitable control for this requirement.<\/span><\/p>\n<h3><b>Question 135<\/b><\/h3>\n<p><b>Which security feature can require multifactor authentication when a user&#8217;s sign-in risk reaches a defined level?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access can use identity risk information as a condition for access decisions. When integrated with Microsoft Entra ID Protection, organizations can configure policies that require multifactor authentication or apply other controls when a user&#8217;s risk or sign-in risk meets defined conditions. This provides adaptive protection rather than applying identical authentication requirements to every access attempt. Azure Load Balancer distributes traffic, Storage provides data services, and Bastion provides secure VM administration. Therefore, Microsoft Entra Conditional Access is the appropriate feature for enforcing MFA based on sign-in risk.<\/span><\/p>\n<h3><b>Question 136<\/b><\/h3>\n<p><b>An organization requires cryptographic keys to remain protected using dedicated hardware security modules rather than software-only storage. Which Azure service should be evaluated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault Managed HSM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure CDN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Key Vault Managed HSM provides dedicated hardware-backed protection for cryptographic keys. It is intended for organizations with stringent requirements concerning key custody, cryptographic operations, and security controls. Managed HSM can provide centralized management while keeping cryptographic material protected within dedicated hardware security modules. Azure DNS handles name resolution, Traffic Manager provides traffic routing, and Azure CDN provides content delivery. Therefore, Azure Key Vault Managed HSM should be evaluated when an organization requires dedicated hardware-backed protection for cryptographic keys.<\/span><\/p>\n<h3><b>Question 137<\/b><\/h3>\n<p><b>Which network security feature allows administrators to reference predefined Azure service IP ranges instead of manually entering changing IP addresses in NSG rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service tags<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource locks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Managed identities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access reviews<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Service tags simplify NSG rule management by representing groups of IP address prefixes associated with specific Azure services or categories of network traffic. Administrators can reference a service tag instead of manually maintaining individual IP addresses that may change over time. This can reduce administrative overhead and help keep network security rules aligned with supported Azure service address ranges. Resource locks protect resources, managed identities provide workload authentication, and access reviews govern identity permissions. Therefore, service tags are the appropriate feature for simplifying NSG rules involving Azure services.<\/span><\/p>\n<h3><b>Question 138<\/b><\/h3>\n<p><b>A security team wants to forward Azure resource logs to an Event Hub so that an external security platform can consume the events. Which Azure configuration should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Diagnostic settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Security Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure diagnostic settings allow supported logs and metrics to be routed to destinations such as Log Analytics workspaces, storage accounts, and Event Hubs. Sending logs to an Event Hub can allow external security or monitoring platforms to consume Azure events for centralized analysis. Resource locks protect resources, Application Security Groups organize network interfaces for security rules, and private endpoints provide private connectivity. Therefore, diagnostic settings are the appropriate configuration when Azure resource logs need to be forwarded to an Event Hub for downstream security analysis.<\/span><\/p>\n<h3><b>Question 139<\/b><\/h3>\n<p><b>An administrator wants to identify network connectivity problems caused by routing or security rules between Azure resources. Which Azure service provides dedicated network troubleshooting tools?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Watcher<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Network Watcher provides a collection of network monitoring and troubleshooting capabilities for Azure environments. Administrators can use tools such as connection troubleshooting and IP flow verification to investigate connectivity failures, routing behavior, and security-rule effects. This makes Network Watcher useful when diagnosing communication problems between Azure resources. Microsoft Sentinel focuses on security analytics, Key Vault manages secrets and cryptographic material, and Entra ID Protection detects identity risks. Therefore, Network Watcher is the appropriate service for investigating Azure network connectivity issues.<\/span><\/p>\n<h3><b>Question 140<\/b><\/h3>\n<p><b>A company wants administrators to receive elevated permissions only after an approval process and for a limited duration. Which capability provides this form of privileged access management?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Graph<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management supports controlled activation of eligible privileged roles. Organizations can configure approval requirements, multifactor authentication, activation durations, justification, and other controls before elevated permissions become active. This reduces standing privilege and provides greater oversight over sensitive administrative access. Azure Resource Graph is used for querying resource information, Storage provides data services, and Load Balancer distributes network traffic. Therefore, Microsoft Entra Privileged Identity Management is the appropriate capability for requiring approval and limiting the duration of elevated administrative permissions.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AZ-500 Exam Dumps and Practice Test Dumps. &nbsp; Question 121 Which Azure service can help identify suspicious sign-in patterns and assign risk levels to authentication events? Azure Policy Azure Firewall Microsoft Entra ID Protection Azure Storage Correct Answer: 3 Explanation Microsoft Entra ID Protection analyzes identity-related signals to detect potentially risky users [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18458"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18458"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18458\/revisions"}],"predecessor-version":[{"id":18459,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18458\/revisions\/18459"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18458"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18458"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}