{"id":18484,"date":"2026-09-22T07:28:33","date_gmt":"2026-09-22T07:28:33","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18484"},"modified":"2026-09-22T07:28:33","modified_gmt":"2026-09-22T07:28:33","slug":"microsoft-az-500-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-500-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Microsoft AZ-500 Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/az-500-exam-dumps\"><b>Microsoft AZ-500 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>What is the primary purpose of an Azure Policy remediation task?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete noncompliant resources<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restore deleted resources<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Correct supported existing resources that are already noncompliant<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace Azure RBAC assignments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Azure Policy remediation task helps bring existing resources into compliance when a policy uses a remediation-capable effect such as Modify or DeployIfNotExists. Policy evaluation can identify resources that do not currently meet requirements, while remediation can apply supported changes or deploy required configurations. This is different from simply auditing resources or blocking future deployments. Remediation is particularly useful when an organization introduces a new security requirement and needs previously deployed resources to receive the required configuration without manually updating every resource.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>Which Azure Policy component determines the rules and conditions that are evaluated when a policy assignment is applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy definition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Diagnostic setting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Management group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Azure Policy definition contains the policy rule that determines which resources or properties are evaluated and what compliance behavior should occur. The definition can specify conditions and an effect such as Audit, Deny, Modify, or DeployIfNotExists. A policy assignment applies the definition to a selected scope. Resource locks protect resources, diagnostic settings configure telemetry collection, and management groups provide organizational hierarchy. The policy definition is therefore the component that establishes the actual governance logic evaluated by Azure Policy.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>An administrator wants an Azure Policy assignment to apply to every subscription beneath a management group. What scope should be used for the assignment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Individual virtual machine<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Management group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Assigning an Azure Policy at the management group scope allows the policy to apply to subscriptions and resources beneath that management group, subject to inheritance and any applicable exclusions or exemptions. This is useful for organizations that need consistent governance across multiple subscriptions. Assigning the policy directly to a virtual machine, storage account, or resource group would provide a much narrower scope. Management groups therefore provide an effective governance level when security requirements need to be inherited across multiple Azure subscriptions.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>Which Microsoft Entra feature can detect potentially compromised user identities by evaluating signals such as unusual sign-in behavior and leaked credentials?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra ID Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel workbook<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra ID Protection uses identity-related signals to identify potentially risky users and sign-ins. These signals can include unusual authentication behavior, compromised credentials, and other indicators associated with identity-based threats. Risk information can then be used with Conditional Access policies to require additional controls or block risky access. Azure Policy governs Azure resources, Azure Firewall filters network traffic, and Sentinel workbooks primarily visualize security information. Microsoft Entra ID Protection is therefore the appropriate service for detecting and responding to identity-related risk signals.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>Which security option provides private connectivity to a supported Azure Storage account while also allowing the storage account&#8217;s public network endpoint to remain disabled?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public IP address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network security group only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS public zone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A private endpoint provides a private IP address within a virtual network for accessing supported Azure Storage services. This allows workloads to communicate with the storage account through private connectivity while public network access can remain disabled. A public IP address would expose the service through a public network path, an NSG alone does not create private connectivity to the storage service, and a public DNS zone does not provide private network access. A private endpoint is therefore appropriate for highly restricted storage architectures requiring private connectivity.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>Which Microsoft Entra object is created in a tenant when an application registration needs an identity that can be assigned permissions and used for authentication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Management group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service principal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy initiative<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A service principal provides an identity for an application within a Microsoft Entra tenant. Permissions can be assigned to the service principal so the application can access supported resources according to the organization&#8217;s authorization requirements. An application registration defines the application&#8217;s identity configuration, while the service principal represents that application in a specific tenant. Management groups organize subscriptions, resource groups organize Azure resources, and policy initiatives group governance policies. A service principal is therefore the identity used by an application for tenant-specific access.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>Which Conditional Access mode allows administrators to evaluate the potential effect of a policy without immediately enforcing its access controls?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Block mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Report-only mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ReadOnly mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit lock mode<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Conditional Access report-only mode allows administrators to evaluate how a policy would affect users and sign-ins without immediately enforcing the policy&#8217;s controls. This provides an opportunity to review expected results, identify unintended consequences, and adjust conditions before enabling enforcement. Block mode is an enforcement concept rather than the specific testing mode, while ReadOnly and Audit lock mode are not Conditional Access policy modes. Report-only mode is therefore useful when administrators want to validate a new security policy before applying it to production access.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>Which Azure SQL feature protects sensitive column values by encrypting them so that the database service does not have access to the plaintext data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL Auditing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Data Masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Always Encrypted<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability Assessment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Always Encrypted protects sensitive data by encrypting selected values on the client side before they are sent to Azure SQL. The database service stores encrypted data rather than receiving the plaintext value, which provides stronger protection for selected sensitive columns against unauthorized database-level access. SQL Auditing records activity, Dynamic Data Masking limits exposure of data returned to certain users, and Vulnerability Assessment identifies potential security weaknesses. Always Encrypted is therefore the appropriate Azure SQL feature when sensitive values need strong protection from plaintext exposure to the database service.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>A security administrator wants to require users to provide a justification whenever they activate an eligible privileged role through Microsoft Entra PIM. Which PIM capability supports this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Activation settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage lifecycle management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network security rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Diagnostic settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra Privileged Identity Management activation settings can define requirements that users must satisfy when activating eligible privileged roles. Depending on the configuration, administrators can require justification, multifactor authentication, approval, and other controls before elevated access becomes active. These requirements help provide accountability and reduce the risk associated with standing administrative privileges. Storage lifecycle management handles storage data policies, network security rules control traffic, and diagnostic settings collect telemetry. PIM activation settings are therefore the appropriate mechanism for requiring justification during privileged role activation.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>Which Azure networking feature can provide name resolution for private endpoint addresses inside a virtual network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private DNS zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall DNAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Watcher<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Private DNS zones can provide DNS name resolution for private endpoint addresses within Azure virtual networks. When a private endpoint is used, DNS configuration is important so applications can resolve the service&#8217;s normal hostname to the appropriate private IP address rather than a public endpoint. Azure DDoS Protection mitigates distributed denial-of-service attacks, Azure Firewall DNAT performs destination address translation, and Network Watcher provides network monitoring and troubleshooting capabilities. A private DNS zone is therefore the appropriate solution for resolving private endpoint names internally.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>Which Azure Storage security setting prevents anonymous public access to blobs and containers when configured to disable public access at the storage account level?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AllowBlobPublicAccess disabled<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure transfer disabled<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Versioning disabled<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared Key enabled<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The storage account setting that controls anonymous public access to blobs and containers can be configured to prevent public access. Disabling the relevant public access setting helps ensure that containers and blobs cannot be exposed anonymously through public access configurations. Secure transfer controls encryption in transit, versioning preserves previous blob versions, and Shared Key relates to account-key authorization. Disabling public blob access is therefore an important storage security control when an organization requires authenticated and authorized access instead of anonymous access to stored data.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>Which Microsoft Defender for Cloud capability can automatically trigger an action or workflow when a security alert or recommendation meets specified conditions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workflow automation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Regulatory compliance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attack path analysis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Defender for Cloud workflow automation can trigger supported actions based on security alerts and recommendations that meet configured conditions. This can help security teams automate repetitive responses and integrate Defender for Cloud with other operational or security workflows. Secure Score measures aspects of security posture, regulatory compliance helps evaluate supported standards, and attack path analysis provides contextual information about potential routes through security weaknesses. Workflow automation is therefore the appropriate capability when the requirement is to automatically initiate actions in response to specified Defender for Cloud events.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>An organization wants to use a security policy package containing multiple related controls and assign the entire collection to a subscription. What should the administrator create?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy initiative<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network security group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Azure Policy initiative combines multiple related policy definitions into one logical collection. Administrators can assign the initiative to a management group, subscription, resource group, or other supported scope depending on governance requirements. This approach simplifies management when many related security controls need to be applied together. Resource locks protect resources, private endpoints provide private connectivity, and network security groups filter network traffic. A policy initiative is therefore the appropriate choice when an organization wants to package several governance controls and manage them through one assignment.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>Which Microsoft Entra capability can allow an organization to define trusted geographic or network locations that can be referenced by Conditional Access policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Named locations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access packages<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privileged groups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enterprise applications<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Entra named locations allow administrators to define locations using supported IP ranges or geographic conditions. These named locations can then be referenced in Conditional Access policies to apply different access controls depending on where a sign-in originates. Access packages support governed resource access, privileged groups support controlled privileged membership, and enterprise applications represent integrated applications. Named locations are therefore the appropriate Microsoft Entra feature when an organization needs to create reusable trusted or restricted location conditions for access policies.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>Which Azure security feature allows administrators to restrict inbound network traffic to a virtual machine based on source address, destination port, and protocol?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Sentinel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Security Group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Policy initiative<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Network Security Group provides stateful network traffic filtering for supported Azure resources. Security rules can specify source and destination addresses, ports, protocols, direction, and access behavior. This allows administrators to restrict inbound traffic to virtual machines and other supported resources according to defined network security requirements. Azure Key Vault manages secrets and cryptographic material, Microsoft Sentinel provides security analytics, and Azure Policy initiatives provide governance controls. An NSG is therefore the appropriate mechanism for controlling inbound network traffic at the network security layer.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>Which Azure Key Vault protection feature helps prevent an authorized user or process from permanently deleting a vault object and then purging it before the retention period expires?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Purge protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Diagnostic settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate renewal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Key Vault purge protection helps prevent permanently deleting protected objects through purge operations during the configured retention period. It works with soft-delete behavior to provide stronger protection against destructive actions involving keys, secrets, and certificates. Key rotation manages cryptographic key lifecycle, diagnostic settings collect logs and telemetry, and certificate renewal manages certificate lifecycle. Purge protection is therefore particularly important for critical cryptographic material because it helps prevent irreversible deletion even when a user or process has sufficient permissions to initiate deletion.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>Which Azure service can query resources across subscriptions using resource properties without requiring administrators to inspect each resource individually?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Graph<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Bastion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DDoS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Resource Graph provides efficient querying of Azure resources across subscriptions and management groups. Security and governance teams can use it to inventory resources, identify configurations, investigate properties, and support compliance analysis at scale. Azure Bastion provides secure administrative access to virtual machines, Azure DDoS Protection provides DDoS mitigation, and Key Vault manages sensitive information and cryptographic assets. Resource Graph is therefore the appropriate service when administrators need to query and analyze resource metadata across a broad Azure environment.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>A security team needs to collect sign-in and security information from an external security product into Microsoft Sentinel. Which Sentinel capability should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automation rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data connector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Workbook<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource lock<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft Sentinel data connectors provide supported methods for bringing security information and telemetry from external products and Azure services into Sentinel. Once the data is available, analytics rules can detect suspicious activity and incidents can be investigated through Sentinel capabilities. Automation rules can automate incident actions, workbooks visualize collected information, and resource locks protect Azure resources. A data connector is therefore the appropriate capability when the primary requirement is to ingest security data from an external product into Microsoft Sentinel.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>Which Azure SQL security capability identifies potential database security weaknesses and can provide recommendations for addressing discovered vulnerabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL vulnerability assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Blob soft delete<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Resource Graph<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SQL vulnerability assessment helps identify potential security weaknesses in Azure SQL environments and provides findings that can guide administrators toward remediation. It can support security reviews by examining database configurations and other supported security conditions. Blob soft delete protects Azure Storage data from accidental deletion, Azure Firewall provides network traffic filtering, and Resource Graph supports resource querying. SQL vulnerability assessment is therefore the appropriate security capability when an organization needs to identify database vulnerabilities and receive guidance for improving the security configuration.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>Which security principle requires administrators to grant users and workloads only the permissions necessary to perform their assigned tasks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principle of least privilege requires users, applications, and workloads to receive only the permissions necessary to perform their required tasks. Limiting permissions reduces the potential impact of compromised identities, accidental actions, and unauthorized activity. Defense in depth uses multiple complementary security controls, zero trust requires continuous verification and explicit authorization, and network segmentation separates network environments to reduce unwanted communication. Least privilege is therefore the principle directly concerned with minimizing unnecessary authorization and ensuring that access rights remain limited to legitimate operational requirements.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Microsoft AZ-500 Exam Dumps and Practice Test Dumps. &nbsp; Question 381 What is the primary purpose of an Azure Policy remediation task? Delete noncompliant resources Restore deleted resources Correct supported existing resources that are already noncompliant Replace Azure RBAC assignments Correct Answer: 3 Explanation An Azure Policy remediation task helps bring existing resources [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18484"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18484"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18484\/revisions"}],"predecessor-version":[{"id":18485,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18484\/revisions\/18485"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18484"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18484"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18484"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}