AZ-500 exam dumps

AZ-500 practice question 11 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 11

Select 2

You are a security administrator for your organization, which uses multiple Azure subscriptions. You have onboarded these subscriptions to Microsoft Entra Permissions Management and discovered via the Permission Creep Index (PCI) report that several users hold high-privilege roles (such as Owner) yet rarely perform any privileged tasks. You want to reduce unnecessary entitlements and enforce least privilege. Which two actions should you take to accomplish this using Microsoft Entra Permissions Management?

  1. A

    Remove roles directly in Azure without using Microsoft Entra Permissions Management and rely on default access assignments.

  2. B

    Use Microsoft Entra Permissions Management to analyze member activity and create a tailored role assignment that includes only the necessary permissions.

  3. C

    Enable Just-In-Time (JIT) access for the Owner role by configuring Privileged Identity Management (PIM) in Microsoft Entra Permissions Management.

  4. D

    Review access recommendations generated by Microsoft Entra Permissions Management and remove or downgrade accounts whose activity does not justify high-privilege entitlements.

  5. E

    Create a new policy in Microsoft Entra Permissions Management that automatically revokes all Contributor and Owner roles after 24 hours of inactivity.

Show answer and explanation

Correct answers: B, D

Explanation

Microsoft Entra Permissions Management helps identify excessive privileges by analyzing usage data and producing reports such as the Permission Creep Index (PCI). The best practice is to apply the recommended adjustments, either removing unneeded roles or creating granular custom roles, to enforce least privilege. References: Microsoft Learn documentation on Microsoft Entra Permissions Management discusses analyzing permission usage and generating right-sized roles for improved security posture.

  • A. Incorrect.

    Option 1 is incorrect. Simply removing roles outside of Microsoft Entra Permissions Management and relying solely on default assignments does not leverage the analytic and monitoring capabilities of Permissions Management. It also bypasses the recommended process of carefully tailoring role assignments based on user activity.

  • B. Correct.

    Option 2 is correct. Microsoft Entra Permissions Management can analyze user activity and recommend which permissions are actually needed. Creating a custom, right-sized role assignment based on these findings enforces least privilege while preserving necessary access.

  • C. Incorrect.

    Option 3 is incorrect. Just-In-Time (JIT) access through PIM is a feature of Microsoft Entra ID (formerly Azure AD) Privileged Identity Management, not Microsoft Entra Permissions Management itself. Permissions Management focuses on visibility and right-sizing. While PIM can be used in conjunction with Permissions Management, this option alone does not address removing unneeded high-privilege roles or tailoring those roles effectively.

  • D. Correct.

    Option 4 is correct. Microsoft Entra Permissions Management provides insights on which users are assigned excessive privileges. Reviewing and applying its recommendations to remove or downgrade accounts that do not require those privileges helps maintain the least-privilege model.

  • E. Incorrect.

    Option 5 is incorrect. While Microsoft Entra Permissions Management can set and enforce access controls, arbitrarily revoking all high-level roles after only 24 hours of inactivity is overly restrictive and not typically recommended. Policies should be aligned with actual usage data rather than a static short-time window.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam