{"id":18470,"date":"2026-09-22T07:26:38","date_gmt":"2026-09-22T07:26:38","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18470"},"modified":"2026-09-22T07:26:38","modified_gmt":"2026-09-22T07:26:38","slug":"microsoft-az-500-practice-test-questions-and-exam-dumps-part13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-500-practice-test-questions-and-exam-dumps-part13-q241-260\/","title":{"rendered":"Microsoft AZ-500 Practice Test Questions and Exam Dumps Part13 Q241-260"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/az-500-exam-dumps\"><b>Microsoft AZ-500 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 241<\/b><\/h3>\n<p><b>Which Azure feature can help protect a virtual machine by allowing administrative ports to be opened only for a limited period when access is required?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Just-in-time VM access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Graph<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Just-in-time VM access in Microsoft Defender for Cloud helps reduce exposure to attacks against management ports such as RDP and SSH. Instead of leaving these ports continuously accessible, administrators can request temporary access for a specified duration. Defender for Cloud can then modify the applicable network security controls to permit the connection during the approved period. After the period expires, the access is removed. This approach reduces the attack surface of virtual machines while still allowing administrators to perform legitimate maintenance and troubleshooting when necessary.<\/span><\/p>\n<h3><b>Question 242<\/b><\/h3>\n<p><b>A security administrator needs to create a custom Azure role that permits users to read resources but prevents them from deleting or modifying those resources. Which Azure capability should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure RBAC custom role<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure RBAC custom roles allow administrators to define a specific set of permitted management-plane actions. A custom role can include read operations while excluding write and delete permissions, allowing organizations to implement a precise least-privilege model. Resource locks protect resources from deletion or modification but do not define user permissions. Azure Policy governs resource configurations, while Conditional Access controls authentication and access conditions for identities. When an organization needs a tailored permission set for a particular job function, an Azure RBAC custom role is the appropriate mechanism.<\/span><\/p>\n<h3><b>Question 243<\/b><\/h3>\n<p><b>Which Microsoft Entra capability can require users to authenticate with stronger methods, such as phishing-resistant authentication, for sensitive applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication strengths<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Entitlement management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity Protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra authentication strengths allow organizations to define which authentication methods or combinations are acceptable for specific access scenarios. Conditional Access policies can require an authentication strength when users access sensitive applications or resources. This provides more control than simply requiring generic multifactor authentication. Access reviews evaluate whether access should continue, entitlement management governs resource access packages, and Identity Protection identifies identity risks. Authentication strengths are therefore useful when an organization needs to require stronger authentication methods for higher-risk or more sensitive applications.<\/span><\/p>\n<h3><b>Question 244<\/b><\/h3>\n<p><b>An Azure administrator wants to prevent a resource from being deleted accidentally while still allowing authorized administrators to modify its configuration. Which resource lock should be applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ReadOnly<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CanNotDelete<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deny<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A CanNotDelete resource lock prevents deletion while allowing authorized users to continue making changes to the resource configuration. This makes it useful for protecting important production resources against accidental removal without completely preventing administrative updates. A ReadOnly lock prevents both modification and deletion through the management plane. Deny is an Azure Policy effect rather than a resource lock type, while Audit reports policy compliance without blocking actions. Therefore, CanNotDelete is appropriate when deletion must be prevented but normal administrative modifications should remain possible.<\/span><\/p>\n<h3><b>Question 245<\/b><\/h3>\n<p><b>Which Azure Storage security setting should be disabled when an organization wants to prevent anonymous users from accessing blob data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public network access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure transfer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous public blob access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage encryption<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Anonymous public blob access allows clients to access certain blob data without authentication when the storage account and container configuration permit it. Disabling this capability helps ensure that blob data requires appropriate authorization rather than being publicly accessible. Secure transfer protects data while moving between clients and Azure Storage, encryption protects stored data, and public network access controls network reachability rather than specifically determining whether anonymous blob access is permitted. Therefore, disabling anonymous public blob access is the direct control for preventing unauthenticated access to blob data.<\/span><\/p>\n<h3><b>Question 246<\/b><\/h3>\n<p><b>A security team needs to ensure that Azure resources are deployed only in approved geographic regions and that noncompliant deployments are blocked. Which Azure Policy configuration should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit effect with all locations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Modify effect with unrestricted locations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Append effect with approved tags<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deny effect with an approved locations list<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Azure Policy using the Deny effect can prevent resource deployments when their location does not match the organization&#8217;s approved list. The policy evaluates the requested resource configuration and rejects deployments that violate the defined geographic restriction. Audit would identify noncompliant resources after deployment rather than preventing them. Modify can alter supported resource properties but is not the direct control for blocking unauthorized regions. Append adds fields where applicable. A Deny policy with an approved locations list therefore provides preventive geographic governance.<\/span><\/p>\n<h3><b>Question 247<\/b><\/h3>\n<p><b>Which Azure security service provides recommendations that can help organizations improve their cloud security posture based on identified configuration weaknesses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Cloud<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure VPN Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud continuously evaluates supported Azure resources and workloads and provides security recommendations that can help administrators address configuration weaknesses and other security issues. These recommendations contribute to improving the organization&#8217;s overall security posture and can help prioritize remediation activities. Azure Bastion provides secure administrative connectivity to virtual machines, Azure DNS provides name resolution, and VPN Gateway establishes encrypted network connections. Defender for Cloud is therefore the appropriate service when the objective is to receive actionable recommendations for improving cloud security configurations.<\/span><\/p>\n<h3><b>Question 248<\/b><\/h3>\n<p><b>Which Azure networking control can restrict inbound traffic to a subnet or network interface based on source, destination, port, and protocol?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private Link<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Security Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Network Security Group provides rules that can allow or deny inbound and outbound network traffic based on factors such as source, destination, protocol, and port. NSGs can be associated with supported network interfaces and subnets, allowing administrators to control network communication between application components. Azure Private Link provides private connectivity to supported services, Key Vault manages cryptographic material and secrets, and Microsoft Sentinel provides security monitoring and response. An NSG is therefore the appropriate network security control for filtering traffic according to defined network rules.<\/span><\/p>\n<h3><b>Question 249<\/b><\/h3>\n<p><b>A company wants to detect unusual activity against Azure Key Vault resources and receive security alerts when suspicious behavior is identified. Which Microsoft Defender plan is designed for this workload?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defender for Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defender for Servers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defender for Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defender for Containers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Key Vault provides security monitoring and threat detection capabilities for Azure Key Vault resources. It can help identify suspicious or potentially malicious activity involving key vault operations and generate relevant security alerts. Defender for Storage focuses on storage workloads, Defender for Servers protects supported server environments, and Defender for Containers addresses container-related workloads. When the protected workload is specifically Azure Key Vault and the organization wants workload-focused threat detection, Defender for Key Vault is the appropriate Defender plan.<\/span><\/p>\n<h3><b>Question 250<\/b><\/h3>\n<p><b>Which Microsoft Entra feature allows administrators to periodically verify whether users should retain access to applications, groups, or other resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication strengths<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privileged Identity Management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra access reviews provide a structured process for periodically reviewing whether users, groups, or other identities should continue to have access to selected resources. Reviewers can confirm or remove access based on current business requirements, helping organizations reduce unnecessary permissions over time. Authentication strengths define acceptable authentication methods, Conditional Access evaluates conditions before granting access, and Privileged Identity Management focuses on privileged role activation and management. Access reviews are therefore appropriate when the primary requirement is periodic verification of whether existing access remains justified.<\/span><\/p>\n<h3><b>Question 251<\/b><\/h3>\n<p><b>A security engineer needs to identify whether a virtual machine&#8217;s network security rules are allowing unexpected traffic between two endpoints. Which Network Watcher capability can help test the effective network path?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connection troubleshoot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key Vault diagnostics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Watcher Connection troubleshoot can help determine connectivity between endpoints and identify issues affecting communication. It can provide information about the path and connectivity state, helping administrators investigate whether routing, network security controls, or other configuration issues are affecting traffic. Azure Policy governs resource configurations, access reviews evaluate identity permissions, and Key Vault diagnostics are unrelated to network path testing. Connection troubleshoot is therefore a useful capability when a security engineer needs to investigate whether a virtual machine can establish the expected network connection.<\/span><\/p>\n<h3><b>Question 252<\/b><\/h3>\n<p><b>Which Microsoft Defender for Cloud capability can help prioritize security issues by showing relationships between vulnerable resources and potential attack paths?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure transfer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attack path analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource locks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication strengths<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attack path analysis in Microsoft Defender for Cloud helps security teams understand how combinations of weaknesses could potentially be used to reach sensitive resources. Instead of considering every security recommendation in isolation, attack paths provide contextual information about relationships between resources, exposures, and possible routes toward high-value targets. Secure transfer protects data in transit, resource locks prevent certain management operations, and authentication strengths control acceptable authentication methods. Attack path analysis is therefore useful when security teams need additional context for prioritizing interconnected risks.<\/span><\/p>\n<h3><b>Question 253<\/b><\/h3>\n<p><b>An organization wants Azure Policy to automatically add a required tag to resources when the tag is missing, where the property is supported for modification. Which policy effect should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deny<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Modify<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Modify effect can add or update supported resource properties when resources are created or updated. It is commonly used for governance requirements such as ensuring that required tags are present on resources. Audit only identifies noncompliant configurations without changing them, while Deny blocks requests that violate the policy. A disabled policy does not enforce any requirement. Therefore, Modify is appropriate when the objective is to automatically apply a required property, such as a governance tag, rather than merely report or reject noncompliant resources.<\/span><\/p>\n<h3><b>Question 254<\/b><\/h3>\n<p><b>Which Azure service provides centralized protection against distributed denial-of-service attacks targeting Azure resources and public endpoints?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Graph<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure DDoS Protection is designed to help protect Azure resources from distributed denial-of-service attacks. It provides dedicated DDoS mitigation capabilities and can help organizations protect public-facing applications and network resources against volumetric and protocol-level attacks. Azure Key Vault protects secrets and cryptographic material, Resource Graph supports resource inventory and querying, and Azure Policy enforces governance requirements. DDoS Protection is therefore the service specifically intended to mitigate DDoS attacks and reduce their potential impact on supported Azure workloads.<\/span><\/p>\n<h3><b>Question 255<\/b><\/h3>\n<p><b>A company needs to send Azure resource diagnostic logs to a Log Analytics workspace for centralized security monitoring. Which Azure configuration should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Diagnostic settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private DNS zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Management group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure diagnostic settings allow administrators to route supported resource logs and metrics to destinations such as Log Analytics workspaces, Azure Storage accounts, or event hubs. Sending logs to Log Analytics enables centralized querying, investigation, alerting, and correlation with other security information. Resource locks protect resources against certain management operations, private DNS zones provide name resolution for private resources, and management groups organize subscriptions. Diagnostic settings are therefore the appropriate configuration when the goal is to collect resource-level telemetry in a centralized security monitoring environment.<\/span><\/p>\n<h3><b>Question 256<\/b><\/h3>\n<p><b>Which Microsoft Sentinel feature provides visual dashboards that help analysts examine security trends, incidents, and collected data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Playbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data connectors<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource locks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel workbooks provide interactive dashboards and visualizations that help security teams analyze collected data, incidents, trends, and operational information. They can present information in charts, tables, and other visual formats, making complex security telemetry easier to understand. Data connectors are used to ingest data from supported sources, while playbooks automate response workflows. Resource locks are unrelated to Sentinel visualization. Therefore, workbooks are the appropriate Sentinel component when analysts need dashboards for examining security information and identifying patterns.<\/span><\/p>\n<h3><b>Question 257<\/b><\/h3>\n<p><b>Which Azure Storage security mechanism is most appropriate when a client application requires time-limited access to specific blob operations without receiving the storage account key?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared Access Signature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private DNS zone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Shared Access Signature can delegate limited access to Azure Storage without exposing the storage account&#8217;s primary or secondary access keys. Administrators or applications can define permissions, resources, and expiration conditions appropriate to the required operation. This supports the principle of least privilege by restricting access to what is necessary for a specific period. Resource locks protect resource management operations, Azure Policy enforces governance, and private DNS provides name resolution. SAS is therefore the appropriate mechanism for controlled, temporary access to specific storage operations.<\/span><\/p>\n<h3><b>Question 258<\/b><\/h3>\n<p><b>A security administrator wants to require users to reauthenticate or satisfy additional controls when accessing sensitive applications after a specified period. Which Conditional Access category can help manage this behavior?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Named locations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource locks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Conditional Access session controls can influence how user sessions behave after authentication. Depending on the scenario and supported configuration, session controls can help enforce requirements such as sign-in frequency or application session restrictions. Named locations define geographic or network-based conditions, access reviews evaluate whether users should retain access, and resource locks protect Azure resources from certain management actions. Session controls are therefore the relevant Conditional Access category when the organization needs to manage session behavior and require users to satisfy authentication requirements again under defined conditions.<\/span><\/p>\n<h3><b>Question 259<\/b><\/h3>\n<p><b>Which Microsoft Entra capability helps manage temporary membership in privileged groups while reducing the need for permanent administrative access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privileged Identity Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Monitor<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management can manage eligible access to privileged roles and groups, allowing users to activate elevated permissions only when needed. This reduces the amount of time that highly privileged access remains active and supports a least-privilege security model. Microsoft Sentinel provides security monitoring, Azure Policy manages resource governance, and Azure Monitor collects monitoring data. PIM is therefore the appropriate capability when administrators need temporary privileged group membership or role access instead of maintaining permanent elevated permissions.<\/span><\/p>\n<h3><b>Question 260<\/b><\/h3>\n<p><b>An organization wants to prevent a storage account from accepting unencrypted HTTP connections and require secure communication from clients. Which storage security setting should be enabled?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public blob access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure transfer required<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-tenant replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Secure transfer required setting ensures that supported requests to Azure Storage use secure transport such as HTTPS rather than unencrypted HTTP. This helps protect credentials, data, and other information while it travels between clients and the storage service. Public blob access and anonymous access relate to authorization and exposure rather than transport encryption. Cross-tenant replication addresses data replication scenarios and does not enforce encrypted client communication. Enabling secure transfer required is therefore the appropriate control when an organization wants to prevent insecure HTTP connections to a storage account.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AZ-500 Exam Dumps and Practice Test Dumps. &nbsp; Question 241 Which Azure feature can help protect a virtual machine by allowing administrative ports to be opened only for a limited period when access is required? Azure Policy Microsoft Sentinel Just-in-time VM access Azure Resource Graph Correct Answer: 3 Explanation Just-in-time VM access [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18470"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18470"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18470\/revisions"}],"predecessor-version":[{"id":18471,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18470\/revisions\/18471"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18470"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18470"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18470"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}