Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: big75certs

Microsoft SC-500 Online Access

Page: 6 / 10
Total 135 questions

Microsoft Certified: Cloud and AI Security Engineer Associate Questions and Answers

Question 21

You have an Azure subscription that contains the resources shown in the following table.

VM1 contains an application that accesses storage1. Another application accesses storage1 from a public IP address of 131.107.10.20.

For storage1, you set Public network access to Enabled from selected virtual networks and IP addresses. You add an IP network rule for 131.107.10.20.

After the configuration, only connections from 131.107.10.20 succeed.

You need to ensure that both VM1 and 131.107.10.20 can access storage1 over the public endpoint, while preventing all other access.

What should you do?

Options:

A.

Add a public IP address to VM1.

B.

Set Public network access to Enabled from all networks.

C.

Enable the Microsoft.Storage service endpoint for Subnet1.

Question 22

You have a hybrid Microsoft entra tenant named contoso.com that contains a user named Userl and the servers shown in the following table.

The tenant Is linked to an Azure subscription that contains a storage account named storage 1- The storage! account contains a file

share named Share1

User1 is assigned the Storage File Data SMB Share Contributor role for storage1.

The security protocol settings for the file shares for storage1 are configured as shown in the following exhibit.

Options:

Question 23

Vou have a Microsoft Entra tenant that uses Microsoft Entra Agent ID. You have multiple Microsoft Foundry agents that have agent identities assigned. Vou dm OW that one of the identities is flagged as high risk duf in unusual sign-in activity. Vou need to ensure that agent access to resources is restricted automatically based on risk. What should you create?

Options:

A.

a Privileged Identity Management (PIM) activation policy

B.

a Microsoft Entra role assignment policy

C.

a Conditional Access policy for the identities

D.

an Access review for the identities

Question 24

You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.

You need to configure a solution that automates the remediation of malware detected in storage1.

What should you include in the solution?

Options:

A.

Application Insights

B.

Azure Event Hubs

C.

Azure Event Grid

D.

Azure Policy

Page: 6 / 10
Total 135 questions