{"id":18480,"date":"2026-09-22T07:28:00","date_gmt":"2026-09-22T07:28:00","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18480"},"modified":"2026-09-22T07:28:00","modified_gmt":"2026-09-22T07:28:00","slug":"microsoft-az-500-practice-test-questions-and-exam-dumps-part18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-500-practice-test-questions-and-exam-dumps-part18-q341-360\/","title":{"rendered":"Microsoft AZ-500 Practice Test Questions and Exam Dumps Part18 Q341-360"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/az-500-exam-dumps\"><b>Microsoft AZ-500 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 341<\/b><\/h3>\n<p><b>Which Azure security capability allows an organization to define a centralized set of policies that can be applied consistently to resources across multiple subscriptions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Security Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Policy provides centralized governance for Azure resources and can enforce or evaluate organizational requirements across subscriptions and management groups. Administrators can assign policies or policy initiatives at an appropriate scope so that security, compliance, tagging, location, and configuration requirements are consistently evaluated. Network Security Groups control network traffic, Azure Bastion provides secure virtual machine administration, and resource locks protect resources from selected management operations. Azure Policy is therefore the appropriate capability when an organization needs centralized and consistent resource governance across multiple Azure subscriptions.<\/span><\/p>\n<h3><b>Question 342<\/b><\/h3>\n<p><b>Which Microsoft Entra feature allows an organization to periodically confirm whether users still require access to a sensitive application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication strengths<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure RBAC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra access reviews provide a structured process for periodically reviewing whether users, groups, or other identities should retain access to applications and resources. Reviewers can confirm continued access or remove permissions that are no longer required. This helps organizations reduce unnecessary access and supports ongoing identity governance. Conditional Access controls access based on conditions, authentication strengths define acceptable authentication methods, and Azure RBAC manages permissions to Azure resources. Access reviews are therefore the appropriate feature when an organization needs recurring verification of existing application access.<\/span><\/p>\n<h3><b>Question 343<\/b><\/h3>\n<p><b>Which Azure Storage feature can help recover data after a blob has been accidentally overwritten by maintaining previous blob versions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Blob versioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure transfer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Blob versioning maintains previous versions of supported blobs when changes are made. If a user or application accidentally overwrites a blob, an earlier version can remain available for recovery, depending on the configured storage features and retention requirements. A storage firewall controls network access, a private endpoint provides private connectivity, and secure transfer protects communication between clients and the storage service. Blob versioning is therefore the appropriate feature when the organization needs to preserve historical blob versions and recover from accidental modifications.<\/span><\/p>\n<h3><b>Question 344<\/b><\/h3>\n<p><b>A security administrator wants to ensure that only resources in approved Azure regions can be created within a subscription. Which Azure Policy effect should be used to block deployments to unauthorized regions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deny<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Modify<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Append<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Deny effect prevents resource creation or modification when the requested configuration violates the policy requirement. A policy can evaluate the resource location and reject deployments outside the organization&#8217;s approved Azure regions. Audit only reports noncompliance, while Modify changes supported resource properties and Append adds supported fields to resource requests. When geographic restrictions must be enforced before deployment rather than simply reported afterward, the Deny effect is the appropriate preventive control.<\/span><\/p>\n<h3><b>Question 345<\/b><\/h3>\n<p><b>Which Azure service provides centralized protection and security recommendations for supported virtual machines and server workloads?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Defender for Servers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Graph<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Servers provides security capabilities for supported server workloads, including virtual machines. Depending on the enabled plan and environment, it can provide threat detection, security recommendations, vulnerability-related capabilities, and other workload protections. Azure DNS provides name resolution, Azure Bastion enables secure administrative access to virtual machines, and Azure Resource Graph supports resource inventory and querying. Defender for Servers is therefore the appropriate security service when an organization needs workload-focused protection and security recommendations for supported server environments.<\/span><\/p>\n<h3><b>Question 346<\/b><\/h3>\n<p><b>An organization wants to use a private IP address in its virtual network to access Azure Key Vault without routing requests through the public internet. Which solution should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A private endpoint provides a private IP address within an Azure virtual network for supported Azure services, including Azure Key Vault. This allows applications to communicate with the service through private connectivity while reducing dependence on public network access. A public IP address would maintain public exposure, a storage firewall is specific to storage network controls, and Azure Bastion provides administrative access to virtual machines. A private endpoint is therefore the appropriate solution when Key Vault must be accessed privately from an Azure virtual network.<\/span><\/p>\n<h3><b>Question 347<\/b><\/h3>\n<p><b>Which Microsoft Entra capability can provide temporary access to privileged groups while requiring users to activate that membership only when needed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access reviews<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privileged Identity Management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Named locations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management supports controlled, time-bound access to privileged roles and groups. Users can be made eligible rather than permanently privileged and can activate access when they need to perform an administrative task. Organizations can also apply requirements such as approval, multifactor authentication, justification, and activation time limits. Access reviews evaluate whether access should continue, Identity Protection detects identity risks, and named locations define network or geographic conditions. PIM is therefore the appropriate capability for temporary privileged group membership.<\/span><\/p>\n<h3><b>Question 348<\/b><\/h3>\n<p><b>A security engineer needs to determine whether a virtual machine can communicate with another endpoint and identify connectivity problems along the network path. Which Network Watcher capability should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP flow verify<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connection troubleshoot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NSG diagnostics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet capture<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Watcher Connection troubleshoot helps administrators test connectivity between endpoints and investigate problems affecting network communication. It can provide information about connectivity and the path involved, helping security and network teams identify routing or configuration issues. IP flow verify focuses on determining whether traffic is allowed or denied by network security rules. Packet capture collects traffic for deeper analysis, while NSG diagnostics can assist with security rule investigation. Connection troubleshoot is therefore the most appropriate option when the primary requirement is testing end-to-end connectivity.<\/span><\/p>\n<h3><b>Question 349<\/b><\/h3>\n<p><b>Which Azure security feature can help protect an application from distributed denial-of-service attacks by providing dedicated mitigation capabilities for supported resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure DDoS Protection provides dedicated capabilities for mitigating distributed denial-of-service attacks against supported Azure resources. It is designed to help protect applications and network resources from attacks that attempt to overwhelm services with large volumes of traffic or other malicious patterns. Azure Firewall provides centralized network filtering, Azure Policy enforces governance requirements, and Microsoft Sentinel provides security monitoring and response. Azure DDoS Protection is therefore the appropriate service when the primary security requirement is protection against distributed denial-of-service attacks.<\/span><\/p>\n<h3><b>Question 350<\/b><\/h3>\n<p><b>Which Azure Key Vault feature can automatically generate new versions of a key according to a configured rotation schedule?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key rotation policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Diagnostic setting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Azure Key Vault key rotation policy can define lifecycle and rotation settings for supported cryptographic keys. Automated rotation helps reduce dependence on manual key replacement and can support organizational requirements for regularly changing cryptographic material. Resource locks protect resources from selected management operations, diagnostic settings collect logs and telemetry, and private endpoints provide private connectivity. A key rotation policy is therefore the appropriate Key Vault feature when an organization wants keys to be rotated according to a defined schedule or lifecycle policy.<\/span><\/p>\n<h3><b>Question 351<\/b><\/h3>\n<p><b>Which Microsoft Sentinel capability evaluates security telemetry against detection logic to identify suspicious activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbooks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Analytics rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data connectors<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Playbooks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel analytics rules evaluate incoming security data against configured detection logic. When relevant conditions are identified, the rules can generate alerts and contribute to incident creation for investigation. Data connectors bring security information into Sentinel, workbooks provide visualization and analysis, and playbooks automate response workflows. Analytics rules are therefore the primary detection mechanism when a security team wants Sentinel to identify suspicious patterns within collected telemetry and turn those detections into actionable security events.<\/span><\/p>\n<h3><b>Question 352<\/b><\/h3>\n<p><b>A company wants to automatically add a required environment tag to Azure resources when the tag is missing and the resource property can be modified by policy. Which Azure Policy effect should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deny<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Modify<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Modify effect can add or update supported resource properties when resources are created or updated. This makes it useful for governance requirements such as automatically adding required tags to resources. Audit only reports noncompliant resources, Deny blocks requests that violate the policy, and a disabled policy performs no enforcement. When the organization&#8217;s objective is to automatically correct a supported property rather than simply report or block the resource, Modify is the appropriate Azure Policy effect.<\/span><\/p>\n<h3><b>Question 353<\/b><\/h3>\n<p><b>Which Azure security capability allows an application hosted on an Azure resource to authenticate to supported services without storing a client secret in application code?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Managed identity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared Access Signature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP address<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Managed identities provide Azure-managed identities that applications and services can use to authenticate to supported Azure resources without storing passwords, client secrets, or other credentials in application code. Administrators can assign permissions to the identity through appropriate authorization mechanisms, supporting least privilege and reducing credential-management risks. A SAS is primarily used for delegated Azure Storage access, a resource lock protects resource management operations, and a public IP address provides network addressing. Managed identity is therefore the appropriate solution for credential-free workload authentication.<\/span><\/p>\n<h3><b>Question 354<\/b><\/h3>\n<p><b>Which Microsoft Defender for Cloud feature can help security teams understand how multiple weaknesses could combine to create a possible route toward a sensitive resource?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security recommendations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Regulatory compliance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attack path analysis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attack path analysis in Microsoft Defender for Cloud provides contextual information about relationships between security weaknesses, resources, and potential routes toward sensitive assets. This can help security teams prioritize risks by understanding how multiple issues may interact rather than treating each recommendation independently. Secure Score provides a broader posture measurement, security recommendations identify specific improvement actions, and regulatory compliance focuses on supported standards and requirements. Attack path analysis is therefore the capability best suited to understanding how combinations of weaknesses can contribute to a potential attack route.<\/span><\/p>\n<h3><b>Question 355<\/b><\/h3>\n<p><b>Which Azure Storage security control can restrict access to a storage account based on selected virtual networks and IP address rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Blob versioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage network access controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Data Masking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Storage network access controls allow administrators to restrict connectivity to storage accounts using supported network rules, selected virtual networks, IP address ranges, and private connectivity options. These controls reduce unwanted network exposure and can be combined with identity-based authorization for layered protection. Blob versioning preserves previous data versions, key rotation manages cryptographic keys, and Dynamic Data Masking is an Azure SQL capability for limiting exposure of sensitive query results. Storage network access controls are therefore appropriate when access must be limited based on network origin.<\/span><\/p>\n<h3><b>Question 356<\/b><\/h3>\n<p><b>Which Azure Firewall rule type should be used when an administrator needs to allow or deny traffic based primarily on source and destination IP addresses, ports, and protocols?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNAT rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat intelligence rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Firewall network rules provide filtering based on network-level properties such as source and destination IP addresses, ports, and protocols. They are appropriate when traffic needs to be controlled without relying on application-layer domain information. Application rules provide application-aware filtering for supported protocols, while DNAT rules perform destination address translation. Threat intelligence capabilities help identify known malicious sources and destinations. Network rules are therefore the correct choice when the required firewall decision is based primarily on IP addresses, ports, and network protocols.<\/span><\/p>\n<h3><b>Question 357<\/b><\/h3>\n<p><b>Which Microsoft Entra capability can use information about risky sign-ins as a condition for applying stronger access controls?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure RBAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Conditional Access can evaluate sign-in risk and apply additional controls when a sign-in meets a configured risk condition. For example, a policy can require multifactor authentication or another supported control when a sign-in is considered risky. Identity Protection supplies risk-related signals, while Conditional Access uses those conditions to make access decisions. Azure Policy governs Azure resource configurations, Azure RBAC controls resource permissions, and storage firewalls restrict network access. Conditional Access is therefore the appropriate control for applying stronger authentication based on sign-in risk.<\/span><\/p>\n<h3><b>Question 358<\/b><\/h3>\n<p><b>A security administrator needs to prevent a critical Azure resource from being deleted while still allowing authorized configuration changes. Which control should be applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ReadOnly lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CanNotDelete lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conditional Access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A CanNotDelete resource lock prevents deletion while continuing to allow supported modifications to the resource. This makes it useful for important production resources where accidental deletion must be prevented but administrators still need to make legitimate configuration changes. A ReadOnly lock is more restrictive because it prevents modification and deletion. Azure Policy Audit reports compliance issues but does not directly prevent deletion, while Conditional Access controls identity access conditions. CanNotDelete is therefore the appropriate resource protection mechanism for this requirement.<\/span><\/p>\n<h3><b>Question 359<\/b><\/h3>\n<p><b>Which Azure service can centralize security alerts and correlate information from multiple data sources for investigation and response?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Graph<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel is a cloud-native SIEM and SOAR service that can collect security information from multiple sources, analyze events, correlate activity, and support incident investigation and response. It can integrate with Azure resources and external services through supported connectors and use analytics rules, incidents, and automation capabilities to help security teams respond to threats. Key Vault manages sensitive credentials and cryptographic material, Bastion provides secure VM access, and Resource Graph supports resource queries. Microsoft Sentinel is therefore the appropriate centralized security analytics and response platform.<\/span><\/p>\n<h3><b>Question 360<\/b><\/h3>\n<p><b>Which Azure Policy effect can deploy a supporting resource or configuration when the evaluated resource does not already meet the required condition?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DeployIfNotExists<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deny<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabled<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The DeployIfNotExists effect can initiate deployment of a related resource or configuration when an evaluated resource does not satisfy a specified condition. This is useful for governance scenarios where organizations want required security or monitoring configurations to be established automatically. Audit identifies noncompliance without directly changing resources, Deny prevents noncompliant operations, and Disabled stops the policy from evaluating. DeployIfNotExists is therefore the appropriate effect when Azure Policy should trigger a supporting deployment whenever a required configuration or resource is missing.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AZ-500 Exam Dumps and Practice Test Dumps. &nbsp; Question 341 Which Azure security capability allows an organization to define a centralized set of policies that can be applied consistently to resources across multiple subscriptions? Network Security Group Azure Bastion Resource lock Azure Policy Correct Answer: 4 Explanation Azure Policy provides centralized governance [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18480"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18480"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18480\/revisions"}],"predecessor-version":[{"id":18481,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18480\/revisions\/18481"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18480"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18480"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18480"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}