Questions for the MS-500 were updated on : Nov 14 ,2024
An administrator configures Azure AD Privileged Identity Management as shown in the following exhibit.
What should you do to meet the security requirements?
D
You need to recommend a solution for the user administrators that meets the security requirements for auditing.
Which blade should you recommend using from the Azure Active Directory admin center?
A
Explanation:
References: https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/concept-sign-ins
HOTSPOT
You plan to configure an access review to meet the security requirements for the workload administrators. You create an
access review policy and specify the scope and a group.
Which other settings should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:
You need to recommend a solution to protect the sign-ins of Admin1 and Admin2.
What should you include in the recommendation?
D
Explanation:
Reference: https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-user-risk-policy
You need to resolve the issue that generates the automated email messages to the IT team.
Which tool should you run first?
B
Explanation:
References:
https://docs.microsoft.com/en-us/office365/enterprise/fix-problems-with-directory-synchronization
Which IP address space should you include in the Trusted IP MFA configuration?
A
Explanation:
Pilot users must use MFA unless they are signing in from the internal network of the Chicago office. MFA must NOT be used
on the Chicago office internal network. We must therefore use the IP range of the external network.
HOTSPOT
How should you configure Group3? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:
Explanation:
Reference: https://docs.microsoft.com/en-us/azure/information-protection/prepare
HOTSPOT
How should you configure Azure AD Connect? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:
You need to create Group3.
What are two possible ways to create the group?
A D
HOTSPOT
Which users are members of ADGroup1 and ADGroup2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:
Explanation:
Reference: https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/groups-dynamic-
membership#supported-values
HOTSPOT
You are evaluating which finance department users will be prompted for Azure MFA credentials.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Which user passwords will User2 be prevented from resetting?
E
Explanation:
Assign the Password admin role to a user who needs to reset passwords for non-administrators and Password
Administrators.
Reference: https://docs.microsoft.com/en-us/microsoft-365/admin/add-users/about-admin-roles?view=o365-worldwide
You need to meet the technical requirements for User9. What should you do?
D
Explanation:
To implement PIM, you must be a global admin.
Reference: https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-getting-
started#enable-pim
Which role should you assign to User1?
C
Explanation:
Privileged Role Administrator can manage role assignments in Azure Active Directory, as well as within Azure AD Privileged
Identity Management.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#privileged-role-administrator
HOTSPOT
You need to recommend an email malware solution that meets the security requirements.
What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area: