AZ-500 Subscription Practice Questions
The free AZ-500: Microsoft Azure Security Technologies questions that deal with subscription, with answers and explanations. The full bank and the timed practice test cover every topic the exam asks about.
Question #1
You have an Azure subscription. You configure the subscription to use a different Azure Active Directory (Azure AD) tenant. What are two possible effects of the change? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
Select 2 answers.
Correct answer: A, B
Explanation
Reference: https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-how-subscriptions-associ
Question #2
You have an Azure subscription named Subscription1 that contains the resources shown in the following table. You have an Azure subscription named Subscription2 that contains the following resources: An Azure Sentinel workspace An Azure Event Grid instance You need to ingest the CEF messages from the NVAs to Azure Sentinel. What should you configure for each subscription? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.


Type your answer, then reveal.
Correct answer: Subscription1: An Azure Log Analytics agent on a Linux virtual machine; Subscription2: A new Azure Sentinel data connector
Explanation
CEF logs are collected by the Log Analytics agent on a Linux VM (syslog forwarder) in Subscription1, which forwards them to the Sentinel workspace. In Subscription2, enable the Common Event Format (CEF) data connector in Azure Sentinel.
Question #5
You have an Azure subscription that contains the storage accounts shown in the following table. You need to configure authorization access. Which authorization types can you use for each storage account? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.


Type your answer, then reveal.
Correct answer: storage1: Shared Key, shared access signature (SAS), and Azure Active Directory (Azure AD); storage2: Shared Key and shared access signature (SAS); storage3: Shared Key and shared access signature (SAS) only
Explanation
Blob storage supports Shared Key, SAS and Azure AD authorization. Azure Files over SMB supports Shared Key and SAS (identity-based access uses AD DS, not listed). At the time of this question Table storage supported only Shared Key and SAS.
Question #10
You have an Azure subscription that contains four Azure SQL managed instances. You need to evaluate the vulnerability of the managed instances to SQL injection attacks. What should you do first?
Correct answer: B
Explanation
Enabling Advanced Data Security on the managed instances turns on the built-in vulnerability assessment, which scans the databases for weaknesses such as SQL injection. Sentinel, a health check solution and ATP do not provide that assessment.
Continue with AZ-500: Microsoft Azure Security Technologies
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in AZ-500: Microsoft Azure Security Technologies, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
All AZ-500: Microsoft Azure Security Technologies practice questions →
