exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 12 question 3 discussion

Actual exam question from Microsoft's AZ-500
Question #: 3
Topic #: 12
[All AZ-500 Questions]

HOTSPOT -
You need to deploy Microsoft Antimalware to meet the platform protection requirements.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Scenario: Microsoft Antimalware must be installed on the virtual machines in RG1.
RG1 is a resource group that contains Vnet1, VM0, and VM1.

Box 1: DeployIfNotExists -
DeployIfNotExists executes a template deployment when the condition is met.
Azure policy definition Antimalware
Incorrect Answers:
Append:
Append is used to add additional fields to the requested resource during creation or update. A common example is adding tags on resources such as costCenter or specifying allowed IPs for a storage resource.
Deny:
Deny is used to prevent a resource request that doesn't match defined standards through a policy definition and fails the request.
Box 2: The Create a Managed Identity setting
When Azure Policy runs the template in the deployIfNotExists policy definition, it does so using a managed identity. Azure Policy creates a managed identity for each assignment, but must have details about what roles to grant the managed identity.
Reference:
https://docs.microsoft.com/en-us/azure/governance/policy/concepts/effects

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
benito_nepomuceno
Highly Voted 4 years, 1 month ago
BOX 2 is SCOPE
upvoted 36 times
...
vijeet
Highly Voted 4 years ago
doesn't DeployIfNotExists require a managed identity. I understand the scope is important but following the order what comes first? 1. DeployIfNotExists 2. Managed Identity 3. Scope
upvoted 16 times
pentium75
9 months ago
I think you need a Managed Identity and you must specify that, but there is no "Create a Managed Identity setting"
upvoted 1 times
...
...
wardy1983
Most Recent 1 year, 5 months ago
Explanation: Scenario: Microsoft Antimalware must be installed on the virtual machines in RG1. RG1 is a resource group that contains Vnet1, VM0, and VM1. Box 1: DeployIfNotExists - DeployIfNotExists executes a template deployment when the condition is met. Azure policy definition Antimalware Incorrect Answers: Append: Append is used to add additional fields to the requested resource during creation or update. A common example is adding tags on resources such as costCenter or specifying allowed IPs for a storage resource. Deny: Deny is used to prevent a resource request that doesn't match defined standards through a policy definition and fails the request. Box 2: THE SCOPE scope as generally it will be applied on Sub but you need to change it to RG as per requirements
upvoted 3 times
...
_punky_
1 year, 6 months ago
Box2 is Correct Similar to AuditIfNotExists, a DeployIfNotExists policy definition executes a template deployment when the condition is met. Policy assignments with effect set as DeployIfNotExists require a managed identity to do remediation. Also in managed identity you will define type of identity and scope. Link: https://learn.microsoft.com/en-us/azure/governance/policy/concepts/effects#deployifnotexists
upvoted 5 times
...
majstor86
2 years, 2 months ago
DeployIfNotExists Scope
upvoted 9 times
...
subhuman
3 years, 2 months ago
Answer is correct "a DeployIfNotExists policy definition executes a template deployment when the condition is met. Policy assignments with effect set as DeployIfNotExists require a managed identity to do remediation " A scope is also required but a scope follows after managed identity
upvoted 7 times
...
Tonion
3 years, 5 months ago
Based on https://docs.microsoft.com/en-us/azure/governance/policy/concepts/effects#deployifnotexists-properties DeploymentScope and ExistenceScope are optional. Moreover the default value is Resource group. From the other hand roleDefinitionIds is required parameter where we define "role-based access control role ID accessible by the subscription". I believe it's what they meant by "Create a Managed Identity setting"
upvoted 1 times
...
kakakayayaya
3 years, 8 months ago
Vague question. When you create ASSIGNMENT 1) you CAN configure Scope (Subscription or/and RG). By default scope setuped in Sub where you reside. 2) you CAN NOT configure "Create a Managed Identity" permission and you CAN NOT deactivate it. You can configure "Managed Identity location" but it has default value so you don't have to configure it.
upvoted 4 times
kakakayayaya
3 years, 8 months ago
On more note: to "meet the platform protection requirements" we HAVE TO limit scope to certain resource group. So my answer for box 2 is Scope.
upvoted 1 times
...
...
thienvupt
3 years, 10 months ago
Correct, Box 2: The Create a Managed Identity setting When Azure Policy runs the template in the deployIfNotExists policy definition, it does so using a managed identity. Azure Policy creates a managed identity for each assignment, but must have details about what roles to grant the managed identity.
upvoted 3 times
...
kumax
3 years, 10 months ago
On exam, May 2021. This is a scenario that contains multiple (less than 5) questions.
upvoted 6 times
...
alexk0
3 years, 11 months ago
For me box2 is Scope. When you're assigning the create policy, the first row of the first screen asks you about scope. Also, the "Create Manages Identity" checkbox is checked by default for DeployIfNotExists.
upvoted 5 times
...
dadageer
4 years, 1 month ago
Box 2 scope as generally it will be applied on Sub but you need to change it to RG as per requirements
upvoted 10 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago