{"id":18464,"date":"2026-09-22T07:25:30","date_gmt":"2026-09-22T07:25:30","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18464"},"modified":"2026-09-22T07:25:30","modified_gmt":"2026-09-22T07:25:30","slug":"microsoft-az-500-practice-test-questions-and-exam-dumps-part10-q181-200","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-500-practice-test-questions-and-exam-dumps-part10-q181-200\/","title":{"rendered":"Microsoft AZ-500 Practice Test Questions and Exam Dumps Part10 Q181-200"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/az-500-exam-dumps\"><b>Microsoft AZ-500 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 181<\/b><\/h3>\n<p><b>Which Azure service can help identify vulnerabilities in supported virtual machine workloads and provide recommendations for remediation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Servers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Queue Storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Servers provides security capabilities for supported server workloads, including Azure virtual machines. Depending on the enabled plan and configuration, it can provide vulnerability-related insights, security recommendations, threat protection, and other workload security capabilities. These features help administrators identify weaknesses and take remediation actions before vulnerabilities can be exploited. Azure DNS handles name resolution, Traffic Manager routes traffic, and Queue Storage provides messaging functionality. Therefore, Microsoft Defender for Servers is the appropriate service when vulnerability assessment and security protection are required for supported virtual machine workloads.<\/span><\/p>\n<h3><b>Question 182<\/b><\/h3>\n<p><b>An organization wants to ensure that users cannot create Azure resources without applying required security tags. Which Azure service should enforce this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Policy can enforce organizational requirements for resource configurations, including mandatory tags. An administrator can create a policy that evaluates whether required security or ownership tags are present and can use an appropriate policy effect to deny noncompliant deployments or audit existing resources. This supports consistent governance across Azure environments. Azure Bastion provides secure VM administration, Azure Firewall filters network traffic, and Microsoft Sentinel provides security analytics. Therefore, Azure Policy is the appropriate service for enforcing required resource tags as part of an organization&#8217;s security and governance standards.<\/span><\/p>\n<h3><b>Question 183<\/b><\/h3>\n<p><b>Which Azure security feature can help prevent accidental permanent deletion of protected Key Vault objects during their retention period?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Purge protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Security Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Network Watcher<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Purge protection adds an additional safeguard to Azure Key Vault by preventing protected objects from being permanently purged during the configured retention period. It is particularly useful for sensitive cryptographic keys, secrets, and certificates where permanent deletion could cause data-access or recovery problems. Soft delete supports recovery of deleted objects, while purge protection helps prevent those objects from being permanently removed before the retention period ends. DDoS Protection, Application Security Groups, and Network Watcher address network security or troubleshooting rather than Key Vault object retention.<\/span><\/p>\n<h3><b>Question 184<\/b><\/h3>\n<p><b>A security administrator needs to verify which user performed a management operation on an Azure resource. Which log should be examined first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Activity Log<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application cache<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS query cache<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancer health probe<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Activity Log records management-plane operations performed on Azure resources at the subscription level. It can provide details about actions such as creating, updating, or deleting resources and can identify the caller associated with the operation. This makes it useful for auditing administrative activity and investigating unauthorized or unexpected resource changes. Application caches and DNS query caches do not provide Azure resource management records, while load balancer health probes report service availability. Therefore, Azure Activity Log should be examined first when investigating who performed an Azure management operation.<\/span><\/p>\n<h3><b>Question 185<\/b><\/h3>\n<p><b>Which Azure networking feature can restrict communication between application tiers by allowing only explicitly permitted traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Security Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Graph<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Network Security Group can restrict network communication between application tiers by using inbound and outbound security rules. Administrators can specify permitted or denied traffic based on source, destination, port, protocol, and related network characteristics. This allows organizations to limit communication to only the connections required by an application architecture. Key Vault manages secrets, Resource Graph queries Azure resources, and Entra ID Protection detects identity risks. Therefore, an NSG is the appropriate network security control for restricting communication between application tiers.<\/span><\/p>\n<h3><b>Question 186<\/b><\/h3>\n<p><b>A company wants to analyze Azure security events in real time and create automated responses when certain threat patterns are detected. Which service should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel provides cloud-native SIEM and SOAR capabilities that allow organizations to collect and analyze security data from many sources. Analytics rules can detect suspicious patterns and generate alerts or incidents, while automation capabilities can trigger response actions through supported mechanisms. This enables security teams to move from manual event review toward centralized detection and response workflows. Azure Storage provides data storage, Bastion provides secure VM access, and DNS provides name resolution. Therefore, Microsoft Sentinel is the appropriate service for centralized security-event analysis and automated response workflows.<\/span><\/p>\n<h3><b>Question 187<\/b><\/h3>\n<p><b>Which Microsoft Entra capability allows an organization to review whether users still require access to a group on a recurring schedule?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra access reviews provide recurring governance over user access to groups, applications, and other resources. Organizations can configure reviews so that designated reviewers periodically confirm whether access remains necessary. This helps identify and remove permissions that are no longer justified, particularly for guest users or changing business responsibilities. Azure Firewall controls network traffic, Azure Policy governs resource configurations, and DDoS Protection mitigates denial-of-service attacks. Therefore, Microsoft Entra access reviews are the appropriate capability for regularly validating whether users should continue to belong to a group.<\/span><\/p>\n<h3><b>Question 188<\/b><\/h3>\n<p><b>A company needs to protect a web application from malicious HTTP requests while also maintaining centralized application delivery through Azure Front Door. Which capability should be integrated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Graph<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web Application Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Watcher<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web Application Firewall can be integrated with supported Azure application delivery services, including Azure Front Door, to provide application-layer protection. It inspects HTTP and HTTPS requests and can help detect and block common web attacks using managed and custom rules. Resource Graph is used for querying resources, Key Vault manages sensitive cryptographic material and secrets, and Network Watcher provides network monitoring and troubleshooting tools. Therefore, Web Application Firewall is the appropriate capability when an application delivered through Azure Front Door requires protection from malicious web requests.<\/span><\/p>\n<h3><b>Question 189<\/b><\/h3>\n<p><b>Which Azure capability can help an organization automatically identify resources that do not comply with required security configurations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Policy evaluates Azure resources against defined organizational requirements and provides compliance information for assigned policies. Administrators can use policy results to identify resources that do not meet requirements related to locations, tags, resource types, security settings, or other supported properties. Depending on the policy effect, noncompliant configurations can also be prevented or modified. Azure CDN, Bastion, and Load Balancer provide content delivery, secure VM administration, and traffic distribution respectively. Therefore, Azure Policy is the appropriate capability for identifying resources that violate required security configurations.<\/span><\/p>\n<h3><b>Question 190<\/b><\/h3>\n<p><b>An administrator needs to allow a workload to access Azure Key Vault without creating or storing a client secret. Which identity mechanism is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Managed identity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared password<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP address<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Managed identity allows an Azure workload to authenticate to supported services without requiring administrators or developers to store application credentials. Azure manages the identity&#8217;s credentials, while administrators grant the identity only the permissions needed to access resources such as Key Vault. This reduces the risk associated with exposed client secrets and simplifies credential management. Shared passwords introduce additional credential-management risks, anonymous authentication does not provide appropriate identity verification, and public IP addresses are networking identifiers rather than authentication mechanisms. Therefore, managed identity is the appropriate choice.<\/span><\/p>\n<h3><b>Question 191<\/b><\/h3>\n<p><b>Which Azure service provides centralized security recommendations and can help prioritize security improvements across supported workloads?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Queue Storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud provides centralized security posture management capabilities for supported cloud workloads. It can identify security weaknesses, generate recommendations, and provide security information that helps organizations prioritize remediation activities. Depending on enabled plans, it can also provide workload protection and threat detection capabilities. Traffic Manager manages DNS-based traffic routing, Azure DNS handles name resolution, and Queue Storage supports asynchronous messaging. Therefore, Microsoft Defender for Cloud is the appropriate service for centralized security recommendations and security posture improvement.<\/span><\/p>\n<h3><b>Question 192<\/b><\/h3>\n<p><b>A security team wants to determine whether a network flow between two Azure resources is being blocked by an NSG rule. Which Network Watcher capability can assist with this investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP flow verify<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Blob versioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Watcher&#8217;s IP flow verify capability can help determine whether a particular network flow is allowed or denied by the applicable security rules. It evaluates traffic information against NSG rules and can identify the rule responsible for the decision. This is useful when administrators need to troubleshoot connectivity between Azure resources without manually reviewing every possible rule. Blob versioning protects storage data, access reviews govern identity permissions, and key rotation manages cryptographic material. Therefore, IP flow verify is the appropriate Network Watcher capability for investigating NSG-based traffic decisions.<\/span><\/p>\n<h3><b>Question 193<\/b><\/h3>\n<p><b>Which Azure feature allows administrators to create a new version of a Key Vault key while retaining the existing key versions for supported operations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource locks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key versioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service tags<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Diagnostic settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Key Vault supports key versioning, allowing new versions of a key to be created during the key lifecycle. This capability supports controlled key rotation and allows applications or administrators to transition to newer key versions according to their configuration and operational requirements. Maintaining versions can also help with controlled migration and key lifecycle management. Resource locks protect resources, service tags simplify NSG rules, and diagnostic settings route logs and metrics to supported destinations. Therefore, key versioning is the appropriate Key Vault capability for managing successive versions of cryptographic keys.<\/span><\/p>\n<h3><b>Question 194<\/b><\/h3>\n<p><b>A security architect wants to prevent a privileged account from retaining permanent administrative permissions. Which design follows the principle of least standing privilege?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign permanent Owner access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use just-in-time privileged access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Share one administrator account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enable anonymous access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Just-in-time privileged access reduces standing administrative permissions by allowing eligible users to activate elevated roles only when necessary. Microsoft Entra Privileged Identity Management can support this model through activation controls such as time limits, approval, multifactor authentication, and justification. Permanent Owner access provides unnecessarily broad and continuously available privileges, while shared accounts reduce accountability and increase credential risk. Anonymous access eliminates appropriate identity controls. Therefore, just-in-time privileged access best supports the principle of minimizing standing administrative privileges.<\/span><\/p>\n<h3><b>Question 195<\/b><\/h3>\n<p><b>Which Azure Storage capability can help recover data after a blob has been accidentally deleted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Blob soft delete<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Blob soft delete allows deleted blobs to remain recoverable for a configured retention period. If a user or application accidentally deletes a blob, administrators or authorized users can restore it while it remains within the retention period. This provides an additional layer of data protection and can complement other Storage capabilities such as blob versioning. Azure Firewall controls network traffic, Azure Bastion provides secure VM administration, and Traffic Manager provides traffic routing. Therefore, blob soft delete is the appropriate capability for recovering accidentally deleted blob data.<\/span><\/p>\n<h3><b>Question 196<\/b><\/h3>\n<p><b>An organization wants to use private connectivity to an Azure Storage account and ensure DNS queries resolve the storage service to its private IP address. Which combination should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS and public IP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint and private DNS zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure CDN and Traffic Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion and NSG only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A private endpoint provides a private IP address for supported Azure services within a virtual network, while a private DNS zone can provide the appropriate name resolution for that private endpoint. Together, these components allow applications to access services such as Azure Storage through private connectivity while resolving the service name to the private address. Public DNS and public IP configurations do not provide the same private access model. CDN, Traffic Manager, and Bastion serve different purposes. Therefore, a private endpoint combined with a private DNS zone is appropriate for this architecture.<\/span><\/p>\n<h3><b>Question 197<\/b><\/h3>\n<p><b>Which Azure security feature can detect potentially malicious activity affecting supported SQL databases and generate security alerts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for SQL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Graph<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Traffic Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for SQL provides specialized security protection for supported SQL workloads. It can detect suspicious database activity, provide security alerts, and offer recommendations that can help improve database security. This service adds workload-specific protection beyond basic database authentication, authorization, encryption, and network controls. Azure CDN handles content delivery, Resource Graph queries Azure resource information, and Traffic Manager routes traffic using DNS-based methods. Therefore, Microsoft Defender for SQL is the appropriate service when an organization needs security monitoring and threat detection for supported SQL databases.<\/span><\/p>\n<h3><b>Question 198<\/b><\/h3>\n<p><b>A company wants to make sure that all storage requests use encrypted connections. Which Azure Storage setting should be enabled?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure transfer required<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public network access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP-only communication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The secure transfer required setting helps ensure that supported Azure Storage requests use encrypted transport, such as HTTPS. This protects information while it travels between clients and the Storage service and helps prevent exposure through unencrypted communication. Anonymous access controls whether unauthenticated users can access certain storage data, while public network access concerns network reachability. HTTP-only communication would not provide encrypted transport. Therefore, secure transfer required should be enabled when the organization wants to enforce encrypted connections to supported Azure Storage services.<\/span><\/p>\n<h3><b>Question 199<\/b><\/h3>\n<p><b>Which Azure service can use application-aware rules to control outbound web traffic from workloads?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Graph<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall supports application rules that can control traffic based on application-level characteristics such as fully qualified domain names for supported HTTP and HTTPS traffic. This allows administrators to create centralized policies governing which web destinations workloads can reach. Azure Firewall can also combine application rules with network rules and other supported security capabilities. Key Vault manages secrets and cryptographic keys, Entra ID Protection detects identity risks, and Resource Graph queries resource information. Therefore, Azure Firewall is the appropriate service for centralized application-aware outbound traffic filtering.<\/span><\/p>\n<h3><b>Question 200<\/b><\/h3>\n<p><b>A security architect wants to combine identity controls, network filtering, encryption, monitoring, and threat detection so that failure of one control does not expose the entire environment. Which security strategy does this represent?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-layer security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public exposure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Defense in depth uses multiple complementary security controls to protect systems at different layers. Identity controls can restrict who accesses resources, network controls can limit communication, encryption protects data, monitoring provides visibility, and threat detection helps identify suspicious activity. Using multiple layers means that bypassing one control does not automatically provide unrestricted access to the environment. Single-layer security depends heavily on one mechanism, while anonymous access and public exposure weaken protection. Therefore, combining multiple independent security mechanisms represents the defense-in-depth strategy.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AZ-500 Exam Dumps and Practice Test Dumps. &nbsp; Question 181 Which Azure service can help identify vulnerabilities in supported virtual machine workloads and provide recommendations for remediation? Azure DNS Microsoft Defender for Servers Azure Traffic Manager Azure Queue Storage Correct Answer: 2 Explanation Microsoft Defender for Servers provides security capabilities for supported [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18464"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18464"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18464\/revisions"}],"predecessor-version":[{"id":18465,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18464\/revisions\/18465"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18464"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18464"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18464"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}