Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You manage Azure security for a subscription. Members of the DevOps group must be able to act as Contributors in the RG1 resource group only during deployments. Requirements:

  • Users must submit a justification when elevating.
  • The DevOps lead must approve.
  • Permissions must be removed automatically one hour after activation. Using Microsoft Entra Privileged Identity Management, which configuration should you implement?
  • Create a permanent active assignment for the DevOps group to the Contributor role on RG1 and configure an access review that removes assignments after one hour.

  • Enable Just-in-Time VM access for RG1 from Microsoft Defender for Cloud and limit access duration to one hour.

  • Create an eligible assignment that adds the DevOps group to the Contributor role on RG1, require approval to activate with the DevOps lead as approver, and set the maximum activation duration to 1 hour.

  • Assign the DevOps group a custom role scoped to RG1 that excludes dangerous actions and enforce sign-in frequency of one hour in a Conditional Access policy.

Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot