nerdexam
MicrosoftMicrosoft

AZ-500 · Question #282

AZ-500 Question #282: Real Exam Question with Answer & Explanation

This hotspot question tests knowledge of Azure AD Connect cloud sync scope and Azure resource hierarchy, requiring candidates to evaluate Yes/No statements about Fabrikam's environment based on the given configuration details.

Submitted by krish.m· Mar 6, 2026Secure compute, storage, and databases

Question

Case Study 3 - Fabrikam, Inc General Overview Fabrikam, Inc. is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. Fabrikam has IT, human resources (HR), and finance departments. Existing Environment Network Environment Fabrikam has a Microsoft 365 subscription and an Azure subscription named subscription1. The network contains an on-premises Active Directory domain named Fabrikam.com. The domain contains two organizational units (OUs) named OU1 and OU2. Azure AD Connect cloud sync syncs only OU1. The Azure resources hierarchy is shown in the following exhibit. The Azure Active Directory (Azure AD) tenant contains the users shown in the following table. Azure AD contains the resources shown in the following table. Subscription1 Resources Subscription1 contains the virtual networks shown in the following table. Subscription1 contains the network security groups (NSGs) shown in the following table. Subscription1 contains the virtual machines shown in the following table. Subscription1 contains the Azure key vaults shown in the following table. Subscription1 contains a storage account named storage1 in the West US Azure region. Planned Changes and Requirements Planned Changes Fabrikam plans to implement the following changes: Create two application security groups as shown in the following table. Associate the network interface of VM1 to ASG1. Deploy SecPol1 by using Azure Security Center. Deploy a third-party app named App1. A version of App1 exists for all available operating systems. Create a resource group named RG2. Sync OU2 to Azure AD. Add User1 to Group1. Technical Requirements Fabrikam identifies the following technical requirements: The finance department users must reauthenticate after three hours when they access SharePoint Online. Storage1 must be encrypted by using customer-managed keys and automatic key rotation. From Sentinel1, you must ensure that the following notebooks can be launched: - Entity Explorer - Account - Entity Explorer - Windows Host - Guided Investigation Process Alerts VM1, VM2, and VM3 must be encrypted by using Azure Disk Encryption. Just in time (JIT) VM access for VM1, VM2, and VM3 must be enabled. App1 must use a secure connection string stored in KeyVault1. KeyVault1 traffic must NOT travel over the internet. Hotspot Question You need to configure support for Azure Sentinel notebooks to meet the technical requirements. What is the minimum number of Azure container registries and Azure Machine Learning workspaces required? Answer:

Options

  • __typehotspot
  • variantdropdown

Explanation

This hotspot question tests knowledge of Azure AD Connect cloud sync scope and Azure resource hierarchy, requiring candidates to evaluate Yes/No statements about Fabrikam's environment based on the given configuration details.

Approach. The key facts to analyze are: Azure AD Connect cloud sync is configured to sync ONLY OU1 (not OU2), meaning users in OU2 are NOT synced to Azure AD. The Azure resource hierarchy determines which management groups, subscriptions, and resource groups inherit policies and permissions. When evaluating each hotspot statement, you must cross-reference whether users belong to OU1 or OU2, whether resources are in the correct region or resource group, and whether NSG rules or RBAC assignments permit the described actions. For example, if a statement asks whether a user from OU2 can sign in to Azure AD, the answer is No because OU2 is excluded from cloud sync. Similarly, questions about resource access depend on the management group hierarchy and any inherited role assignments shown in the exhibit.

Concept tested. Azure AD Connect cloud sync OU filtering, Azure resource hierarchy (management groups/subscriptions/resource groups), NSG rule evaluation, and RBAC inheritance - specifically understanding that only OU1 is synced, so OU2 users have no Azure AD presence, and that permissions/policies flow down through the management group hierarchy.

Reference. Microsoft Learn: Azure AD Connect cloud sync - Configure filtering by OU | Azure resource management hierarchy | NSG traffic filtering

Topics

#resource inventory#Azure Container Registry#Log Analytics workspace

Community Discussion

No community discussion yet for this question.

Full AZ-500 PracticeBrowse All AZ-500 Questions