|
via Udemy |
Go to Course: https://www.udemy.com/course/az-500-practice-test-latest/
These Practice question sets is developed based on the inputs and Microsoft Latest dumps. Consider this module as a practice test to get clear understanding on the format.Candidates for this exam implement, manage, and monitor security for resources in Azure, multi-cloud, and hybrid environments as part of an end-to-end infrastructure. They recommend security components and configurations to protect identity & access, data, applications, and networks.Responsibilities for an Azure security engineer include managing the security posture, identifying and remediating vulnerabilities, performing threat modelling, and implementing threat protection. They may also participate in responding to security incidents.Azure security engineers work with architects, administrators, and developers to plan and implement solutions that meet security and compliance requirements.The Azure security engineer should have practical experience in administration of Microsoft Azure and hybrid environments. The Azure security engineer should have a strong familiarity with compute, network, and storage in Azure, as well as Azure Active Directory, part of Microsoft Entra.Audience profileThe Azure Security Engineer implements, manages, and monitors security for resources in Azure, multi-cloud, and hybrid environments as part of an end-to-end infrastructure. They recommend security components and configurations to protect identity & access, data, applications, and networks.Responsibilities for an Azure Security Engineer include managing the security posture, identifying and remediating vulnerabilities, performing threat modelling, and implementing threat protection. They may also participate in responding to security incidents.Azure Security Engineers work with architects, administrators, and developers to plan and implement solutions that meet security and compliance requirements.The Azure Security Engineer should have practical experience in administration of Microsoft Azure and hybrid environments. The Azure Security Engineer should have a strong familiarity with compute, network, and storage in Azure, as well as Azure Active Directory, part of Microsoft Entra.Manage identity and access (25-30%)Secure networking (20-25%)Secure compute, storage, and databases (20-25%)Manage security operations (25-30%)AZ-500 - Skills Measured - Manage identity and access (25-30%)Manage identities in Azure ADSecure users in Azure ADSecure directory groups in Azure ADRecommend when to use external identitiesSecure external identitiesImplement Azure AD Identity ProtectionManage authentication by using Azure ADConfigure Microsoft Entra Verified IDImplement multi-factor authentication (MFA)Implement passwordless authenticationImplement password protectionImplement single sign-on (SSO)Integrate single sign on (SSO) and identity providersRecommend and enforce modern authentication protocolsManage authorization by using Azure ADConfigure Azure role permissions for management groups, subscriptions, resource groups, and resourcesAssign built-in roles in Azure ADAssign built-in roles in AzureCreate and assign custom roles, including Azure roles and Azure AD rolesImplement and manage Microsoft Entra Permissions ManagementConfigure Azure AD Privileged Identity Management (PIM)Configure role management and access reviews by using Microsoft Entra Identity GovernanceImplement Conditional Access policiesManage application access in Azure ADManage access to enterprise applications in Azure AD, including OAuth permission grantsManage app registrations in Azure ADConfigure app registration permission scopesManage app registration permission consentManage and use service principalsManage managed identities for Azure resourcesRecommend when to use and configure an Azure AD Application Proxy, including authenticationSecure networking (20-25%)Plan and implement security for virtual networksPlan and implement Network Security Groups (NSGs) and Application Security Groups (ASGs)Plan and implement user-defined routes (UDRs)Plan and implement VNET peering or VPN gatewayPlan and implement Virtual WAN, including secured virtual hubSecure VPN connectivity, including point-to-site and site-to-siteImplement encryption over ExpressRouteConfigure firewall settings on PaaS resourcesMonitor network security by using Network Watcher, including NSG flow loggingPlan and implement security for private access to Azure resourcesPlan and implement virtual network Service EndpointsPlan and implement Private EndpointsPlan and implement Private Link servicesPlan and implement network integration for Azure App Service and Azure FunctionsPlan and implement network security configurations for an App Service Environment (ASE)Plan and implement network security configurations for an Azure SQL Managed InstancePlan and implement security for public access to Azure resourcesPlan and implement TLS to applications, including Azure App Service and API ManagementPlan, implement, and manage an Azure Firewall, including Azure Firewall Manager and firewall policiesPlan and implement an Azure Application GatewayPlan and implement an Azure Front Door, including Content Delivery Network (CDN)Plan and implement a Web Application Firewall (WAF)Recommend when to use Azure DDoS Protection StandardSecure compute, storage, and databases (20-25%)Plan and implement advanced security for computePlan and implement remote access to public endpoints, including Azure Bastion and JITConfigure network isolation for Azure Kubernetes Service (AKS)Secure and monitor AKSConfigure authentication for AKSConfigure security monitoring for Azure Container Instances (ACIs)Configure security monitoring for Azure Container Apps (ACAs)Manage access to Azure Container Registry (ACR)Configure disk encryption, including Azure Disk Encryption (ADE), encryption as host, and confidential disk encryptionRecommend security configurations for Azure API ManagementPlan and implement security for storageConfigure access control for storage accountsManage life cycle for storage account access keysSelect and configure an appropriate method for access to Azure FilesSelect and configure an appropriate method for access to Azure Blob StorageSelect and configure an appropriate method for access to Azure TablesSelect and configure an appropriate method for access to Azure QueuesSelect and configure appropriate methods for protecting against data security threats, including soft delete, backups, versioning, and immutable storageConfigure Bring your own key (BYOK)Enable double encryption at the Azure Storage infrastructure levelPlan and implement security for Azure SQL Database and Azure SQL Managed InstanceEnable database authentication by using Microsoft Azure ADEnable database auditingIdentify use cases for the Microsoft Purview governance portalImplement data classification of sensitive information by using the Microsoft Purview governance portalPlan and implement dynamic maskingImplement Transparent Database Encryption (TDE)Recommend when to use Azure SQL Database Always EncryptedManage security operations (25-30%)Plan, implement, and manage governance for securityCreate, assign, and interpret security policies and initiatives in Azure PolicyConfigure security settings by using Azure BlueprintDeploy secure infrastructures by using a landing zoneCreate and configure an Azure Key VaultRecommend when to use a Dedicated HSMConfigure access to Key Vault, including vault access policies and Azure Role Based Access ControlManage certificates, secrets, and keysConfigure key rotationConfigure backup and recovery of certificates, secrets, and keysManage security posture by using Microsoft Defender for CloudIdentify and remediate security risks by using the Microsoft Defender for Cloud Secure Score and InventoryAssess compliance against security frameworks and Microsoft Defender for CloudAdd industry and regulatory standards to Microsoft Defender for CloudAdd custom initiatives to Microsoft Defender for CloudConnect hybrid cloud and multi-cloud environments to Microsoft Defender for CloudIdentify and monitor external assets by using Microsoft Defender External Attack Surface ManagementConfigure and manage threat protection by using Microsoft Defender for CloudEnable workload protection services in Microsoft Defender for Cloud, including Microsoft Defender for Storage, Databases, Containers, App Service, Key Vault, Resource Manager, and DNSConfigure Microsoft Defender for ServersConfigure Microsoft Defender for Azure SQL DatabaseManage and respond to security alerts in Microsoft Defender for CloudConfigure workflow automation by using Microsoft Defender for CloudEvaluate vulnerability scans from Microsoft Defender for ServerConfigure and manage security monitoring and automation solutionsMonitor security events by using Azure MonitorConfigure data connectors in Microsoft SentinelCreate and customize analytics rules in Microsoft SentinelEvaluate alerts and incidents in Microsoft SentinelConfigure automation in Microsoft SentinelMS-500 - Candidates for this exam have functional experience with Microsoft 365 workloads and with Microsoft Azure Active Directory (Azure AD), part of Microsoft Entra. They have implemented security for Microsoft 365 environments, including hybrid environments. They have a working knowledge of Windows clients, Windows servers, Active Directory, and PowerShell.Implement and manage identity and access (25-30%)Implement and manage threat protection (30-35%)Implement and manage information protection (15-20%)Manage compliance in Microsoft 365 (20-25%)Implement and manage identity and access (25-30%)Plan and implement identity and access for Microsoft 365 hybrid environmentsChoose an authentication method to connect to a hybrid environmentPlan and implement pass-through authentication and password hash syncPlan and implement Azure AD synchronization for hybrid environmentsMonitor and troubleshoot Azure AD Connect eventsPlan and implement identities in Azure ADImplement Azure AD group membershipImplement password management, including self-service password reset and Azure AD Password ProtectionManage external identities in Azure AD and Microsoft 365 workloadsPlan and implement roles and role groupsAudit Azure ADImplement authentication methodsImplement multi-factor authentication (MFA) by using conditional access policiesManage and monitor MFAPlan and implement Windows Hello for Business, FIDO, and password less authenticationPlan and implement conditional accessPlan and implement conditional access policiesPlan and implement device compliance policiesTest and troubleshoot conditional access policiesConfigure and manage identity governanceImplement Azure AD Privileged Identity ManagementImplement and manage entitlement managementImplement and manage access reviewsImplement Azure AD Identity ProtectionImplement user risk policyImplement sign-in risk policyConfigure Identity Protection alertsReview and respond to risk eventsImplement and manage threat protection (30-35%)Secure identity by using Microsoft Defender for IdentityPlan a Microsoft Defender for Identity solutionInstall and configure Microsoft Defender for IdentityManage and monitor Microsoft Defender for IdentitySecure scoreAnalyze identity-related threats and risks identified in Microsoft 365 DefenderSecure endpoints by using Microsoft Defender for EndpointPlan a Microsoft Defender for Endpoint solutionImplement Microsoft Defender for EndpointManage and monitor Microsoft Defender for EndpointAnalyze and remediate threats and risks to endpoints identified in Microsoft 365 DefenderSecure endpoints by using Microsoft Endpoint ManagerPlan for device and application protectionConfigure and manage Microsoft Defender Application GuardConfigure and manage Windows Defender Application ControlConfigure and manage exploit protectionConfigure and manage device encryptionConfigure and manage application protection policiesMonitor and manage device security status using Microsoft Endpoint Manager admin centerAnalyze and remediate threats and risks to endpoints identified in Microsoft Endpoint ManagerSecure collaboration by using Microsoft Defender for Office 365Plan a Microsoft Defender for Office 365 solutionConfigure Microsoft Defender for Office 365Monitor for threats by using Microsoft Defender for Office 365Analyze and remediate threats and risks to collaboration workloads identified in Microsoft 365 DefenderConduct simulated attacks by using Attack simulation trainingDetect and respond to threats in Microsoft 365 by using Microsoft SentinelPlan a Microsoft Sentinel solution for Microsoft 365Implement and configure Microsoft Sentinel for Microsoft 365Manage and monitor Microsoft 365 security by using Microsoft SentinelRespond to threats using built-in playbooks in Microsoft SentinelSecure connections to cloud apps by using Microsoft Defender for Cloud AppsPlan Microsoft Defender for Cloud Apps implementationConfigure Microsoft Defender for Cloud AppsManage cloud app discoveryManage entries in the Microsoft Defender for Cloud Apps catalogManage apps in Microsoft Defender for Cloud AppsConfigure Microsoft Defender for Cloud Apps connectors and OAuth appsConfigure Microsoft Defender for Cloud Apps policies and templatesAnalyze and remediate threats and risks relating to cloud app connections identified in Microsoft 365 DefenderManage App governance in Microsoft Defender for Cloud AppsImplement and manage information protection (15-20%)Manage sensitive informationPlan a sensitivity label solutionCreate and manage sensitive information typesConfigure sensitivity labels and policiesPublish sensitivity labels to Microsoft 365 workloadsMonitor data classification and label usage by using Content explorer and Activity explorerApply labels to files and schematized data assets in Microsoft Purview Data MapImplement and manage Microsoft Purview Data Loss Prevention (DLP)Plan a DLP solutionCreate and manage DLP policies for Microsoft 365 workloadsImplement and manage Endpoint DLPMonitor DLPRespond to DLP alerts and notificationsPlan and implement Microsoft Purview Data lifecycle managementPlan for data lifecycle managementReview and interpret data lifecycle management reports and dashboardsConfigure retention labels, policies, and label policiesPlan and implement adaptive scopesConfigure retention in Microsoft 365 workloadsFind and recover deleted Office 365 dataManage compliance in Microsoft 365 (20-25%)Manage and analyze audit logs and reports in Microsoft PurviewPlan for auditing and reportingInvestigate compliance activities by using audit logsReview and interpret compliance reports and dashboardsConfigure alert policiesConfigure audit retention policiesPlan for, conduct, and manage eDiscovery casesRecommend eDiscovery Standard or PremiumPlan for content search and eDiscoveryDelegate permissions to use search and discovery toolsUse search and investigation tools to discover and respondManage eDiscovery casesManage regulatory and privacy requirementsPlan for regulatory compliance in Microsoft 365Manage regulatory compliance in the Microsoft Purview Compliance ManagerImplement privacy risk management in Microsoft PrivaImplement and manage Subject Rights Requests in Microsoft PrivaManage insider risk solutions in Microsoft 365Implement and manage Customer LockboxImplement and manage Communication compliance policiesImplement and manage Insider risk management policiesImplement and manage Information barrier policiesImplement and manage Privileged access management