Question 61

You have an Azure subscription.
You plan to create a custom role-based access control (RBAC) role that will provide permission to read the Azure Storage account.
Which property of the RBAC role definition should you configure?
  • Question 62

    You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.

    Azure AD Privileged Identity Management (PIM) is enabled for the tenant.
    In PIM, the Password Administrator role has the following settings:
    * Maximum activation duration (hours): 2
    * Send email notifying admins of activation: Disable
    * Require incident/request ticket number during activation: Disable
    * Require Azure Multi-Factor Authentication for activation: Enable
    * Require approval to activate this role: Enable
    * Selected approver: Group1
    You assign users the Password Administrator role as shown in the following table.

    For each of the following statements, select Yes if the statement is true. Otherwise, select No.
    NOTE: Each correct selection is worth one point.

    Question 63

    Note: This question is part of a series of questions that present the same scenario. Each question in
    the series contains a unique solution that might meet the stated goals. Some question sets might have
    more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these
    questions will not appear in the review screen.
    You use Azure Security Center for the centralized policy management of three Azure subscriptions.
    You use several policy definitions to manage the security of the subscriptions.
    You need to deploy the policy definitions as a group to all three subscriptions.
    Solution: You create a resource graph and an assignment that is scoped to a management group.
    Does this meet the goal?
  • Question 64

    You have an Azure subscription that contains virtual machines.
    You enable just in time (JIT) VM access to all the virtual machines.
    You need to connect to a virtual machine by using Remote Desktop.
    What should you do first?
  • Question 65

    SIMULATION
    The developers at your company plan to publish an app named App11641655 to Azure.
    You need to ensure that the app is registered to Azure Active Directory (Azure AD). The registration must use the sign-on URLs of https://app.contoso.com.
    To complete this task, sign in to the Azure portal and modify the Azure resources.