비스를 제공해드려 아무런 걱정없이 SC-500시험에 도전하도록 힘이 되어드립니다. Fast2test덤프를 사용하여 시험에서 통과하신 분이 전해주신 희소식이 Fast2test 덤프품질을 증명해드립니다.
| Section | Weight | Objectives |
|---|---|---|
| Manage identity, access, and governance | 20–25% | - Implement secure authentication and authorization
|
| Secure storage, databases, and networking | 25–30% | - Secure storage and data services
|
| Secure compute | 20–25% | - Secure application and workload identities
|
| Manage and monitor security posture | 20–25% | - Monitor, assess, and improve security posture
|
우리Fast2test가 제공하는 최신, 최고의Microsoft SC-500시험관련 자료를 선택함으로 여러분은 이미 시험패스성공이라고 보실수 있습니다.
질문 # 13
You have a hybrid environment that contains the following servers:
- 50 Azure virtual machines that run Windows Server 2019
- 20 physical, on-premises servers that run Windows Server 2019
All the servers use a third-party antivirus solution that must remain active during a phased security rollout.
You need to onboard all the servers to Microsoft Defender for Endpoint by using a centralized deployment method. The solution must meet the following requirements:
- Endpoint detection and response (EDR) capabilities must be enabled.
- Antivirus conflicts must be prevented during onboarding.
What should you do on the servers?
정답:B
설명:
Configuring ForceDefenderPassiveMode places Microsoft Defender Antivirus in passive mode on the Windows Server machines before onboarding them to Microsoft Defender for Endpoint. This allows the third-party antivirus solution to remain the primary antivirus product while Microsoft Defender for Endpoint provides endpoint detection and response capabilities, preventing antivirus conflicts during the phased rollout.
Reference:
https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-compatibility
질문 # 14
You have an Azure subscription named Sub1 that contains multiple virtual machines. Sub1 has the Microsoft Defender Cloud Security Posture Management (CSPM) plan enabled.
You discover that Defender for Cloud fails to identify plaintext connection strings and SSH keys stored on the virtual machines.
You need to ensure that secrets can be identified on the virtual machines.
What should you do?
정답:A
설명:
Agentless machine scanning enables Defender CSPM to scan virtual machine disks for exposed plaintext secrets, including connection strings and SSH private keys. It uses disk snapshots and cloud APIs without requiring an agent installation or affecting virtual machine performance.
Reference:
https://learn.microsoft.com/en-us/azure/defender-for-cloud/secrets-scanning-servers
https://learn.microsoft.com/en-us/azure/defender-for-cloud/secrets-scanning
질문 # 15
You have a virtual network named VNet1 that contains a subnet named Subnet1. Azure App Service is integrated with VNet1. You have an Azure SQL Database logical server named Server1 that contains a database named DB1. Server1 is accessible only by using a public IP address.
You need to ensure that Server does NOT use a public IP address and Azure App Service can still access Server1.
What should you create?
정답:C
설명:
To eliminate the public IP address while maintaining access from the Azure App Service, you must create an Azure Private Endpoint for the Azure SQL Database logical server and disable public network access on the SQL Server. Because your Azure App Service already features regional virtual network integration, it will route database traffic securely through your virtual network using a private IP address.
Reference:
https://learn.microsoft.com/en-us/azure/app-service/overview-vnet-integration
질문 # 16
You have a Microsoft 365 tenant that uses Microsoft Security Copilot and Microsoft Defender XDR.
Access to Microsoft Defender XDR is managed by using Microsoft entra global roles.
The Phishing triage Agent is available in Microsoft Defender. The required agent prerequisites and approvals are complete Two users will perform the following tasks:
* User1 will enable and manage the Phishing Triage Agent settings.
* User2 will use Security Copilot in Microsoft Defender XDR to manage phishing incidents identified by the agent.
You need to assign the least-privileged built in Microsoft Entra role and Security Copilot role combination to each us Which roles should you assign to each user? To answer, select the appropriate options in the answer area.
정답:
설명:
Explanation:
질문 # 17
Case Study 2 - Fabrikam, Inc.
Overview
Fabrikam, Inc. is a consulting company. The company has a main office in New York City and branch offices in Amsterdam and Singapore.
Existing Environment. Network environment
The on-premises network contains a datacenter in each office.
Existing Environment. Cloud environment
Fabrikam has two Azure subscriptions named Sub1 and Sub2 and a Microsoft 365 subscription that includes Microsoft 365 E5 licenses.
All the subscriptions are linked to a Microsoft Entra tenant named fabrikam.com that contains the identities shown in the following table.
The tenant contains the groups shown in the following table.
All devices are enrolled in Microsoft Intune.
Existing Environment. Sub1 Resources
Sub1 contains a resource group named RG1 that contains the resources shown in the following table.
SQLServer1 uses Microsoft SQL Server authentication.
Sub1 has an Azure Web Application Firewall (WAF) named WAF1 that has the following types of rule sets:
- Bot Manager 1.1
- Azure-managed Default Rule Set (DRS)
Sub1 has the following compliance standards assigned in Microsoft Defender for Cloud:
- NIST SP 800-53 Rev. 4
- Microsoft cloud security benchmark (MCSB)
- System and Organization Controls (SOC) 2 Type 2
Existing Environment. Sub2 Resources
Sub2 contains a resource group named RG2.
Planned Changes and Requirements. Planned Changes
Fabrikam plans to implement the following changes:
- Deploy the following key vaults to RG1:
AKV2 in the West Europe Azure region
AKV3 in the Central US Azure region
AKV4 in the East US Azure region
- Deploy the following key vaults to RG2:
AKV5 in the East US region
- Configure VM1 to read data from storage1.
- Create function apps that have the following hosting plans:
Fa1: Flex Consumption hosting plan
Fa2: Consumption hosting plan
Fa3: Dedicated hosting plan
- For WAF1, implement rate limiting rules based on the request
location.
- Enable the NIST SP 800-53 Rev. 5 compliance standard in Defender for
Cloud.
- Create a new storage account named storage2 that supports Azure Table storage.
- Enforce multifactor authentication (MFA) when database administrators access SQLdb1.
- Implement ExpressRoute circuits to the on-premises network as shown
in the following table.
- For RG1, create a new Privileged Identity Management (PIM) eligible role assignment that assigns the Contributor role to supported groups.
Planned Changes and Requirements. Technical Requirements
Fabrikam has the following technical requirements:
- If VM1 is deleted, the permissions for VM1 must be removed
automatically.
- The AKS1 managed identity must only be able to pull images from
Registry1.
- The ID1 managed identity must be able to push images to and pull
images from Registry1.
- All the data in the storage accounts must be encrypted by using
Fabrikam-managed keys.
- All outbound traffic from the function apps to the on-premises
network must use ExpressRoute circuits.
- ExpressRoute connectivity between the on-premises network and the
Azure environment must be encrypted by using Layer 2 or Layer 3
encryption.
You need to implement the planned change for WAF1. The solution must minimize administrative effort. What should you do?
정답:B
설명:
To implement location-based rate limiting rules on an Azure Web Application Firewall (WAF) using the Bot Manager 1.1 and Default Rule Set (DRS), you must create a custom rule with a rule type set to "Rate limit" and configure a "Geo location" match condition.
Scenario:
Sub1 has an Azure Web Application Firewall (WAF) named WAF1 that has the following types of rule sets: Bot Manager 1.1, Azure-managed Default Rule Set (DRS) For WAF1, implement rate limiting rules based on the request location.
Reference:
https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/rate-limiting-overview
질문 # 18
......
만일Microsoft SC-500인증시험을 첫 번째 시도에서 실패를 한다면 Microsoft SC-500덤프비용 전액을 환불 할 것입니다. 만일 고객이 우리 제품을 구입하고 첫 번째 시도에서 성공을 하지 못 한다면 모든 정보를 확인 한 후에 구매 금액 전체를 환불 할 것 입니다. 이러한 방법으로 저희는 고객에게 어떠한 손해도 주지 않을 것을 보장합니다.
SC-500인증덤프 샘플체험: https://kr.fast2test.com/SC-500-premium-file.html