Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Manage identity and access Az 500

Total questions: 14

Worksheet time: 7mins

Name
Class
Date
1.

You have been tasked with applying conditional access policies for your company's current Azure Active Directory (Azure AD).
The process involves assessing the risk events and risk levels.
Which of the following is the risk level that should be configured for sign ins that originate from IP addresses with dubious activity?

a)

None

b)

Low

c)

Medium

d)

High

2.

You have been tasked with applying conditional access policies for your company's current Azure Active Directory (Azure AD).
The process involves assessing the risk events and risk levels.
Which of the following is the risk level that should be configured for users that have leaked credentials?

a)

None

b)

Low

c)

Medium

d)

High

3.

Your company recently created an Azure subscription.
You have been tasked with making sure that a specified user is able to implement Azure AD Privileged Identity Management (PIM).
Which of the following is the role you should assign to the user?

a)

The Global administrator role.

b)

The Security administrator role.

c)

The Password administrator role.

d)

The Compliance administrator role.

4.

You have been tasked with configuring an access review, which you plan to assigned to a new collection of reviews. You also have to make sure that the reviews can be reviewed by resource owners.
You start by creating an access review program and an access review control.
You now need to configure the Reviewers.
Which of the following should you set Reviewers to?

a)

Selected users.

b)

Members (Self)

c)

Group Owners

d)

Anyone

5.

Your company has an Azure Container Registry.
You have been tasked with assigning a user a role that allows for the uploading of images to the Azure Container Registry. The role assigned should not require more privileges than necessary.
Which of the following is the role you should assign?

a)

Owner

b)

Contributor

c)

AcrPush

d)

AcrPull

6.

Your company has an Azure Container Registry.
You have been tasked with assigning a user a role that allows for the downloading of images from the Azure Container Registry. The role assigned should not require more privileges than necessary.
Which of the following is the role you should assign?

a)

Reader

b)

Contributor

c)

AcrDelete

d)

AcrPull

7.

Your company's Azure subscription is linked to their Azure Active Directory (Azure AD) tenant.
After an internally developed application is registered in Azure AD, you are tasked with making sure that the application has the ability to access Azure Key Vault secrets on application the users' behalf.
Solution: You configure a delegated permission with admin consent.
Does the solution meet the goal?

a)

Yes

b)

No

8.

Your company's Azure subscription is linked to their Azure Active Directory (Azure AD) tenant.
After an internally developed application is registered in Azure AD, you are tasked with making sure that the application has the ability to access Azure Key Vault secrets on application the users' behalf.
Solution: You configure a delegated permission with no admin consent.
Does the solution meet the goal?

a)

Yes

b)

No

9.

Your Azure Active Directory Azure (Azure AD) tenant has an Azure subscription linked to it.
Your developer has created a mobile application that obtains Azure AD access tokens using the OAuth 2 implicit grant type.
The mobile application must be registered in Azure AD.
You require a redirect URI from the developer for registration purposes.


Select `No adjustment required` if the underlined segment is accurate.

If the underlined segment is inaccurate, select the accurate option.

a)

No adjustment required

b)

a secret

c)

a login hint

d)

a client ID

10.

You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.

You create and enforce an Azure AD Identity Protection user risk policy that has the following settings:
✑ Assignment: Include Group1, Exclude Group2
✑ Conditions: Sign-in risk of Medium and above
✑ Access: Allow access, Require password change

If User1 signs in from an unfamiliar location he must change his password

a)

Yes

b)

No

11.

You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.

You create and enforce an Azure AD Identity Protection user risk policy that has the following settings:
✑ Assignment: Include Group1, Exclude Group2
✑ Conditions: Sign-in risk of Medium and above
✑ Access: Allow access, Require password change

If User2 signs in from an anonymous IP address she must change her password

a)

Yes

b)

No

12.

You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.

You create and enforce an Azure AD Identity Protection user risk policy that has the following settings:
✑ Assignment: Include Group1, Exclude Group2
✑ Conditions: Sign-in risk of Medium and above
✑ Access: Allow access, Require password change

If User3 signs in from computer containing malware that is communicating with known bot servers he must change his password

a)

Yes

b)

No

13.

You have an Azure Active Directory (Azure AD) tenant named contoso.com. The tenant contains the users shown in the following image 1.

You configure an access review named Review1 as shown in the following image 2.

User 3 can perform review1 for

a)

User3 only

b)

User1 and User2 only

c)

User1 and User3 only

d)

User1 and User2 and User3

14.

You have an Azure Active Directory (Azure AD) tenant named contoso.com. The tenant contains the users shown in the following image 1.

You configure an access review named Review1 as shown in the following image 2.

If User2 fails to complete Review1 by December 12 2020

a)

The Password administrator role will be revoked from User2

b)

User2 will retain the password administrator role

c)

User3 will receive a confirmation request