Win IT Exam with Last Dumps 2024


Microsoft AZ-500 Exam

Page 9/45
Viewing Questions 81 90 out of 443 Questions
20.00%

Question 81
You have an Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com.
The User administrator role is assigned to a user named Admin1.
An external partner has a Microsoft account that uses the [email protected] sign in.
Admin1 attempts to invite the external partner to sign in to the Azure AD tenant and receives the following error message: `Unable to invite user [email protected] Generic authorization exception.`
You need to ensure that Admin1 can invite the external partner to sign in to the Azure AD tenant.
What should you do?



You need to allow guest invitations in the External collaboration settings.

Question 82
You have an Azure Active Directory (Azure AD) tenant.
You have the deleted objects shown in the following table.
AZ-500_82Q.png related to the Microsoft AZ-500 Exam
On May 4, 2020, you attempt to restore the deleted objects by using the Azure Active Directory admin center.
Which two objects can you restore? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.



Deleted users and deleted Office 365 groups are available for restore for 30 days.
You cannot restore a deleted security group.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/groups-restore-deleted

Question 83
HOTSPOT -
You have an Azure subscription named Subscription1 that contains the resources shown in the following table.
AZ-500_83Q_1.png related to the Microsoft AZ-500 Exam
You create an Azure role by using the following JSON file.
AZ-500_83Q_2.jpg related to the Microsoft AZ-500 Exam
You assign Role1 to User1 for RG1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
AZ-500_83Q_3.png related to the Microsoft AZ-500 Exam
Image AZ-500_83R.png related to the Microsoft AZ-500 Exam



Reference:
https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#compute

Question 84
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains a user named User1.
You plan to publish several apps in the tenant.
You need to ensure that User1 can grant admin consent for the published apps.
Which two possible user roles can you assign to User1 to achieve this goal? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.



Reference:
https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/grant-admin-consent

Question 85
You have an Azure subscription that is associated with an Azure Active Directory (Azure AD) tenant.
When a developer attempts to register an app named App1 in the tenant, the developer receives the error message shown in the following exhibit.
AZ-500_85Q.png related to the Microsoft AZ-500 Exam
You need to ensure that the developer can register App1 in the tenant.
What should you do for the tenant?



Reference:
https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-how-applications-are-added


Question 86
You have an Azure subscription that contains an Azure Active Directory (Azure AD) tenant and a user named User1.
The App registrations settings for the tenant are configured as shown in the following exhibit.
AZ-500_86Q.jpg related to the Microsoft AZ-500 Exam
You plan to deploy an app named App1.
You need to ensure that User1 can register App1 in Azure AD. The solution must use the principle of least privilege.
Which role should you assign to User1?



Reference:
https://docs.microsoft.com/en-us/azure/active-directory/roles/delegate-by-task

Question 87
You have the Azure virtual machines shown in the following table.
AZ-500_87Q.png related to the Microsoft AZ-500 Exam
Each virtual machine has a single network interface.
You add the network interface of VM1 to an application security group named ASG1.
You need to identify the network interfaces of which virtual machines you can add to ASG1.
What should you identify?



Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/application-security-groups

Question 88
SIMULATION -
You need to create a new Azure Active Directory (Azure AD) directory named 12345678.onmicrosoft.com. The new directory must contain a user named user12345678 who is configured to sign in by using Azure Multi-Factor Authentication (MFA).



To create a new Azure AD tenant:
1. Browse to the Azure portal and sign in with an account that has an Azure subscription.
2. Select the plus icon (+) and search for Azure Active Directory.
AZ-500_88E_1.png related to the Microsoft AZ-500 Exam
3. Select Azure Active Directory in the search results.
AZ-500_88E_2.png related to the Microsoft AZ-500 Exam
4. Select Create.
5. Provide an Organization name (12345678) and an Initial domain name (12345678). Then select Create. This will create the directory named
12345678.onmicrosoft.com.
AZ-500_88E_3.png related to the Microsoft AZ-500 Exam
6. After directory creation is complete, select the information box to manage your new directory.
To create the user:
1. In the Azure portal, make sure you are on the Azure Active Directory fly out.
AZ-500_88E_4.png related to the Microsoft AZ-500 Exam
If not, select the Azure Active Directory icon from the left services navigation.
AZ-500_88E_5.png related to the Microsoft AZ-500 Exam
2. Under Manage, select Users.
AZ-500_88E_6.jpg related to the Microsoft AZ-500 Exam
3. Select All users and then select + New user.
4. Provide a Name and User name (user12345678) for the user. When you're done, select Create.
To enable MFA:
1. In the Azure portal, make sure you are on the Azure Active Directory fly out.
AZ-500_88E_7.png related to the Microsoft AZ-500 Exam
If not, select the Azure Active Directory icon from the left services navigation.
AZ-500_88E_8.png related to the Microsoft AZ-500 Exam
2. Under Manage, select Users.
AZ-500_88E_9.jpg related to the Microsoft AZ-500 Exam
3. Click on the Multi-Factor Authentication link.
4. Tick the checkbox next to the user's name and click the Enable link.
Reference:
https://docs.microsoft.com/en-us/power-bi/developer/create-an-azure-active-directory-tenant

Question 89
You have an Azure subscription named Subcription1 that contains an Azure Active Directory (Azure AD) tenant named contoso.com and a resource group named
RG1.
You create a custom role named Role1 for contoso.com.
Where you can use Role1 for permission delegation?




Question 90
You have an Azure subscription.
You enable Azure Active Directory (Azure AD) Privileged Identity Management (PIM).
Your company's security policy for administrator accounts has the following conditions:
- The accounts must use multi-factor authentication (MFA).
- The accounts must use 20-character complex passwords.
- The passwords must be changed every 180 days.
- The accounts must be managed by using PIM.
You receive multiple alerts about administrators who have not changed their password during the last 90 days.
You need to minimize the number of generated alerts.
Which PIM alert should you modify?



Reference:
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-configure-security-alerts?tabs=new





Premium Version