exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 1 question 9 discussion

Actual exam question from Microsoft's AZ-500
Question #: 9
Topic #: 1
[All AZ-500 Questions]

Your company recently created an Azure subscription. You have, subsequently, been tasked with making sure that you are able to secure Azure AD roles by making use of Azure Active Directory (Azure AD) Privileged Identity Management (PIM).
Which of the following actions should you take FIRST?

  • A. You should sign up Azure Active Directory (Azure AD) Privileged Identity Management (PIM) for Azure AD roles.
  • B. You should consent to Azure Active Directory (Azure AD) Privileged Identity Management (PIM).
  • C. You should discover privileged roles.
  • D. You should discover resources.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Rume
Highly Voted 3 years, 9 months ago
"Consent to PIM" is deprecated. No more required. So now only priv users needs to access/ visits PIM (Premium P2 is enabled") - Access will be provided automatically. "When a user who is active in a privileged role in an Azure AD organization with a Premium P2 license goes to Roles and administrators in Azure AD and selects a role (or even just visits Privileged Identity Management): We automatically enable PIM for the organization Their experience is now that they can either assign a "regular" role assignment or an eligible role assignment"
upvoted 45 times
Bjarki2330
3 years, 9 months ago
Yeah this question in particular is outdated.
upvoted 5 times
Hot_156
1 month, 3 weeks ago
AOUTDATED Prepare PIM for Microsoft Entra roles Here are the tasks we recommend for you to prepare Privileged Identity Management to manage Microsoft Entra roles: Configure Microsoft Entra role settings Give eligible assignments Allow eligible users to activate their Microsoft Entra role just-in-time Prepare PIM for Azure roles Here are the tasks we recommend for you to prepare Privileged Identity Management to manage Azure roles for a subscription: Discover Azure resources Configure Azure role settings Give eligible assignments Allow eligible users to activate their Azure roles just-in-time https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-getting-started#prepare-pim-for-azure-roles
upvoted 1 times
...
...
...
cris_exam
Highly Voted 7 months ago
Selected Answer: D
Correct answer is D. First thing you do is Discover Azure resources. 1. Discover Azure resources 2. Configure Azure role settings. 3. Give eligible assignments. 4. Allow eligible users to activate their Azure roles just-in-time. https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-getting-started#prepare-pim-for-azure-roles
upvoted 8 times
Jimmy500
10 months, 1 week ago
Hi please read question carefully , it does not say Enable role for Azure subscription, Your solution is correct but it is for Azure Subscription not Azure Roles. So since we are not talking about resources we must choose C. If in the condiition it says for Azure resource we must chose D in this case - Discover Azure resources.
upvoted 5 times
Rednevi
1 month ago
Actually according to Learn: "Prepare PIM for Azure roles Here are the tasks we recommend for you to prepare Privileged Identity Management to manage Azure roles for a subscription: 1) Discover Azure resources 2) Configure Azure role settings 3) Give eligible assignments 4) Allow eligible users to activate their Azure roles just-in-time" D seems correct
upvoted 1 times
...
...
...
gauravwagh16193
Most Recent 2 weeks, 6 days ago
Selected Answer: A
To secure Azure AD roles using Azure AD Privileged Identity Management (PIM), the first action you should take is to sign up for Azure AD Privileged Identity Management (PIM) for Azure AD roles1. This step is crucial as it enables PIM for your tenant, allowing you to manage, control, and monitor access to privileged roles. Once PIM is enabled, you can proceed with discovering privileged roles and resources, configuring role settings, and assigning eligible users2.
upvoted 1 times
...
stonwall12
2 months, 1 week ago
Selected Answer: A
Answer: Question is outdated Reason: Per current Microsoft documentation, with Microsoft Entra ID P2 or Microsoft Entra ID Governance license, PIM is automatically enabled for the tenant and doesn't require sign-up or consent. Reference: https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-getting-started#prerequisites
upvoted 1 times
...
Hot_156
2 months, 2 weeks ago
Selected Answer: A
To enable Azure AD Privileged Identity Management (PIM) for Azure AD roles, you can follow these steps: Step 1: Sign Up for PIM Go to the Azure portal. In the left-hand navigation pane, select Azure Active Directory. Under Manage, select Privileged Identity Management. If this is your first time accessing PIM, click Sign up to enable it for your Azure AD directory.
upvoted 2 times
...
ndtmartin
2 months, 3 weeks ago
Selected Answer: A
Before you can manage and secure Azure AD roles using PIM, you need to sign up for PIM. This is the first step in enabling PIM for Azure AD roles, after which you can configure role management, policies, and other settings.
upvoted 1 times
...
AlaNaj003
2 months, 4 weeks ago
Selected Answer: C
https://learn.microsoft.com/en-us/training/modules/manage-authorization-microsoft-entra-id/15-configure-privileged-identity-management
upvoted 1 times
...
jamju
3 months, 1 week ago
Selected Answer: D
https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-getting-started#prepare-pim-for-azure-roles
upvoted 2 times
...
aocferreira
5 months, 3 weeks ago
Selected Answer: C
As per the below site, the correct answer is C. Before implementing PIM for Entra or RBAC roles, the first step is to "discover and mitigate privileged roles": https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-deployment-plan
upvoted 3 times
...
codeunit
6 months, 2 weeks ago
To secure Azure AD roles using Azure Active Directory Privileged Identity Management (PIM), the first action you should take is to enable Privileged Identity Management (PIM) for Azure AD. This step is essential as it sets up PIM for your Azure AD environment, allowing you to manage and secure privileged roles. After enabling PIM, you can proceed with other tasks like assigning eligible roles, configuring role settings, and setting up just-in-time (JIT) access. However, enabling PIM is the foundational step.
upvoted 1 times
...
purek77
7 months ago
Selected Answer: C
Yes, question is outdated (consent is no longer required), however looking at below link - it seems that you have to "Discover and mitigate privileged roles" - therefore C is potentially correct answer nowadays. https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-deployment-plan
upvoted 4 times
...
Andre369
7 months ago
Selected Answer: C
Before you can effectively manage and secure privileged roles in Azure AD using PIM, you need to discover the existing privileged roles in your Azure subscription. This involves identifying the roles that have elevated permissions and need to be managed through PIM. By discovering privileged roles, you gain visibility into the current role assignments and can determine which roles should be subject to PIM and undergo the access review and just-in-time (JIT) activation process.
upvoted 3 times
...
zellck
7 months ago
Selected Answer: C
C is the answer. https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-deployment-plan#discover-and-mitigate-privileged-roles List who has privileged roles in your organization. Review the users assigned, identify administrators who no longer need the role, and remove them from their assignments. You can use Azure AD roles access reviews to automate the discovery, review, and approval or removal of assignments.
upvoted 2 times
...
Terman
7 months ago
Selected Answer: C
The sequence is as follows, as per the documentation: 1. Plan a PIM deployment: a step of this includes 'C. Discover and mitigate privileged roles' https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-deployment-plan 2. Start using PIM: a step of this includes 'D. Discover resources' https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-getting-started So though both steps C & D are valid, C refers to the planning phase, D to the usage phase, therefore C comes first.
upvoted 2 times
...
MeisAdriano
7 months ago
Selected Answer: C
ChatGPT: For securing Azure AD roles using Azure Active Directory (Azure AD) Privileged Identity Management (PIM), the FIRST action you should take is: C. You should discover privileged roles. Before enabling and configuring Azure AD Privileged Identity Management (PIM), it's essential to discover and identify the privileged roles within your Azure environment. Understanding the roles and their permissions is a crucial initial step in implementing proper security measures and access controls. Once you have discovered these roles, you can proceed to configure and manage them using Azure AD PIM.
upvoted 2 times
...
wingcheuk
7 months ago
The correct answer is B. Before you can start using Azure AD PIM to manage and secure privileged roles, you must first give your consent to use the service within your Azure environment. This step is crucial as it involves agreeing to the terms of use and understanding the permissions and capabilities that PIM will have within your Azure AD environment. The process of signing up for Azure AD PIM (Option A) typically follows after you have given consent. Signing up may involve configuring specific settings or initiating the service within your Azure subscription, but it cannot be done before consent is provided. Discovering privileged roles (Option C) and discovering resources (Option D) are actions taken after Azure AD PIM is activated and consented to. These steps are part of the process of setting up and configuring PIM, wherein you identify which roles and resources require privileged access management.
upvoted 2 times
...
Jimmy500
10 months, 1 week ago
Ladies and Jentelmens please read question carefully: Hi please read question carefully , it does not say Enable role for Azure subscription, Your solution is correct but it is for Azure Subscription not Azure Roles. So since we are not talking about resources we must choose C. If in the condiition it says for Azure resource we must chose D in this case - Discover Azure resources. Here Answer is C
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago