exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 1 question 7 discussion

Actual exam question from Microsoft's AZ-500
Question #: 7
Topic #: 1
[All AZ-500 Questions]

You have been tasked with applying conditional access policies for your company's current Azure Active Directory (Azure AD).
The process involves assessing the risk events and risk levels.
Which of the following is the risk level that should be configured for sign ins that originate from IP addresses with dubious activity?

  • A. None
  • B. Low
  • C. Medium
  • D. High
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Ucy
Highly Voted 3 years, 10 months ago
Correct Answer is B IP addresses with suspicious/dubious activity risk level is LOW
upvoted 50 times
bur88
3 years, 1 month ago
Update: in 2022 it is C : Medium already https://github.com/toddkitta/azure-content/blob/master/articles/active-directory/active-directory-identityprotection-risk-events-types.md#sign-ins-from-ip-addresses-with-suspicious-activity
upvoted 26 times
koreshio
2 years, 6 months ago
I think this should be 'Medium' too considering the "Microsoft's recommendation" section under this doco: https://learn.microsoft.com/sr-cyrl-rs/azure/active-directory/identity-protection/howto-identity-protection-configure-risk-policies
upvoted 2 times
...
siecz
3 years, 1 month ago
This repo last commit if from 2016... is it u to date ???
upvoted 6 times
...
...
...
thienvupt
Highly Voted 3 years, 9 months ago
The same with Sign-ins from IP addresses with suspicious activity so B is correct
upvoted 15 times
...
stonwall12
Most Recent 2 months, 2 weeks ago
Selected Answer: C
Answer: C, Medium Reason: Sign-ins from IP addresses with suspicious activity are classified as medium-risk in Azure AD Identity Protection. It was consisted LOW, but was updated a couple years back. Reference: https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks#risk-levels
upvoted 1 times
...
awfnewf1q243
7 months, 1 week ago
Selected Answer: C
C. Medium Note: It is very unlikely the Microsoft will require the memorization of specific risk levels given that they have changed the documentation. Previously the risk levels were very well defined, however they now provide this very vague paragraph: "Microsoft doesn't provide specific details about how risk is calculated. Each level of risk brings higher confidence that the user or sign-in is compromised. For example, something like one instance of unfamiliar sign-in properties for a user might not be as threatening as leaked credentials for another user." Modern Documentation: https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection#investigate-risk Legacy Documentation: https://web.archive.org/web/20190419234045/https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/concept-risk-events
upvoted 8 times
...
ittchmh
7 months, 1 week ago
Selected Answer: C
Latest information on MS Learn: https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks?source=recommendations#risk-levels Risk levels Identity Protection categorizes risk into three tiers: low, medium, and high. When configuring Identity protection policies, you can also configure it to trigger upon No risk level. No Risk means there's no active indication that the user's identity has been compromised. Microsoft doesn't provide specific details about how risk is calculated. Each level of risk brings higher confidence that the user or sign-in is compromised. For example, something like one instance of unfamiliar sign-in properties for a user might not be as threatening as leaked credentials for another user.
upvoted 5 times
...
MeisAdriano
7 months, 1 week ago
Selected Answer: B
ChatGPT: 1) Low Risk Level: Use this level if you believe the suspicious activity is low-risk or if you are conducting further investigations. It may be appropriate for situations where the IP address is not well-known as a source of malicious activity. 2) Medium Risk Level: This risk level is a common choice and represents a compromise between security and convenience. It might be suitable for suspicious activities that have some level of risk but are not considered severe. 3) High Risk Level: Use this level if you believe the suspicious activity represents a serious and immediate threat. It may require additional authentication and security verification to mitigate the risk.
upvoted 1 times
...
Jimmy500
7 months, 1 week ago
Leaked Credentials = High Impossible travel to atypical locations =Medium Sign IN from infected device =Low Sign-ins from anonymous Ip addresses = Medium Sign-ins from Ip address with suspicious Activity = Medium Sign-ins from unfamiliar locations = Medium
upvoted 2 times
...
WilianCArias
1 year, 4 months ago
Answer is LOW
upvoted 3 times
...
flafernan
1 year, 4 months ago
Selected Answer: C
This rating was upgraded in 2022 and went from low to medium.
upvoted 3 times
...
cometorule
1 year, 5 months ago
can you guys please stop asking ChatGPT for the answers? if you have answers based on Microsoft document, then state it in the comments, otherwise stfu.
upvoted 6 times
...
JunetGoyal
1 year, 6 months ago
Its Low
upvoted 1 times
...
timHAG
1 year, 8 months ago
Selected Answer: C
updated categorization
upvoted 1 times
...
ESAJRR
1 year, 9 months ago
Selected Answer: C
C. Medium
upvoted 1 times
...
Khairulanuar
1 year, 11 months ago
correct asnwer is C
upvoted 1 times
...
slick_orange
2 years ago
Selected Answer: C
Correct Answer is C Question outdated: It's C for now, only "Sign-ins from infected devices" is a "low" risk. Check with the link: https://github.com/toddkitta/azure-content/blob/master/articles/active-directory/active-directory-identityprotection-risk-events-types.md
upvoted 6 times
Strive_for_greatness_kc
1 year, 3 months ago
Last update from this page is 2016, 9 years ago.
upvoted 1 times
...
...
Andre369
2 years ago
Selected Answer: B
I'm going with B it seems to match the question best
upvoted 1 times
...
aiwaai
2 years, 1 month ago
Selected Answer: B
Correct Answer is B . It's same kind of question no. 6
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago