Free SC-500 Microsoft SC-500 Practice Test Question

Loading demo links...

Showing 1–3 of 5 questions

Question 1 (Topic 1)

You have a management group named MG1 that contains two subscriptions named Sub1 and Sub2. Sub1 contains a resource group named RG-Exception and a resource group named RG1 that hosts Microsoft Foundry resources. You need to assign an Azure policy to force new Foundry deployments in MG1 to use private endpoints. The solution must NOT restrict deployments in RG-Exception. How should you configure the policy?

Select an option, then click Submit answer.

  • Assign the policy to MG1 and exclude RG-Exception.
  • Assign the policy to Sub1 and RG-Exception.
  • Assign the policy to MG1 and RG-Exception.
  • Assign the policy to Sub1 and exclude RG-Exception.
Question 2 (Topic 1)

You have an Azure subscription. You need to deploy an Azure virtual WAN to meet the following requirements: Create three secured virtual hubs located in the East US, West US, and North Europe Azure regions. Ensure that security rules sync between the regions. What should you use?

Select an option, then click Submit answer.

  • Azure Network Function Manager
  • Azure Firewall Manager
  • Azure Virtual Network Manager
  • Azure Front Door
Question 3 (Topic 1)

HOTSPOT - Overview - Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas. Contoso has a hybrid environment that contains on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1. Existing Environment. Microsoft Entra tenant Contoso has a Microsoft Entra tenant named contoso.com that contains the users shown in the following table. Existing Environment. On-premises environment The on-premises network contains an Active Directory Domain Services (AD DS) forest that syncs with contoso.com. The forest contains a server named Server1 that runs Windows Server. Existing Environment. Azure subscription Sub1 contains the storage accounts shown in the following table. Sub1 contains the virtual networks shown in the following table. Sub1 contains the virtual machines shown in the following table. The network interface of VM1 is associated with an application security group named ASG1. Sub1 contains the resources shown in the following table. Vault1 stores the objects shown in the following table. Existing Environment. Privileged Identity Management (PIM) configuration You manage privileged roles by using Privileged Identity Management (PIM). The PIM role settings are configured as shown in the following table. Existing Environment. Microsoft Sentinel configuration Contoso has a Microsoft Sentinel workspace that contains the following tables. Requirements. Planned changes - Contoso plans to implement the following changes: Integrate AKS1 with Vault1. Enable Microsoft Entra Kerberos authentication for all supported storage. Configure auditing for sql1 by using the Azure portal and store audit logs in a centralized location. Requirements. Technical requirements Contoso identifies the following technical requirements: Protect Server1 by using file integrity monitoring. Protect AKS1 by using Microsoft Defender for Cloud. Configure Microsoft Sentinel to retain data for the maximum supported duration without changing the tier. Store objects used for authentication and encryption in Vault1 and ensure that Vault1 regenerates the objects every 30 days, whenever possible. You need to configure Server1 to meet the technical requirements. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Answer is in the explanation below.