Microsoft Azure Security Engineer Associate AZ-500 Practice Question

Your organization uses Microsoft Entra Privileged Identity Management (PIM) for Azure resource roles. The Production subscription has been onboarded to PIM. Compliance mandates that eligible users who activate the Owner role must obtain manager approval and that the role remains active for no longer than 1 hour. Which PIM setting should you change to meet the requirements?

  • Create a Conditional Access policy that requires multi-factor authentication for the Owner role.

  • Edit the Owner role's settings in PIM for the Production subscription to require approval and set a 1-hour activation duration.

  • Enable Just-In-Time (JIT) VM access in Microsoft Defender for Cloud for the Production subscription.

  • Create an access review for the Owner role in the Production subscription and set reviewers to managers.

Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot