nerdexam
Microsoft

AZ-500 · Question #95

Hotspot Question You have a network security group (NSG) bound to an Azure subnet. You run Get-AzureRmNetworkSecurityRuleConfig and receive the output shown in the following exhibit. Use the…

The correct answer is Users from the Contoso named location must use multi-factor authentication (MFA) to access the Azure portal. = Yes; Users from the Contoso named location must use multi-factor authentication (MFA) to access the web services hosted in the Azure subscription. = No; Users external to the Contoso named location must use multi-factor authentication (MFA) to access the Azure portal. = No. Based on the conditional access policy output, the policy targets the 'Contoso named location' and requires MFA when accessing 'Microsoft Azure Management' (the Azure portal). Users FROM the Contoso named location are included in the policy scope and must use MFA to access the…

Submitted by klara.se· Mar 6, 2026Implement and manage identity and access - specifically configuring and interpreting Azure Active Directory Conditional Access policies including named locations, MFA enforcement, and cloud app targeting (AZ-500 / SC-300 / AZ-104)

Question

Hotspot Question You have a network security group (NSG) bound to an Azure subnet. You run Get-AzureRmNetworkSecurityRuleConfig and receive the output shown in the following exhibit. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-500 question #95 exhibit 1
AZ-500 question #95 exhibit 2
AZ-500 question #95 exhibit 3
AZ-500 question #95 exhibit 4

Answer Area

  • Users from the Contoso named location must use multi-factor authentication (MFA) to access the Azure portal.Yes
  • Users from the Contoso named location must use multi-factor authentication (MFA) to access the web services hosted in the Azure subscription.No
  • Users external to the Contoso named location must use multi-factor authentication (MFA) to access the Azure portal.No

Explanation

Based on the conditional access policy output, the policy targets the 'Contoso named location' and requires MFA when accessing 'Microsoft Azure Management' (the Azure portal). Users FROM the Contoso named location are included in the policy scope and must use MFA to access the Azure portal (Yes). The policy does NOT apply to web services hosted in the Azure subscription - it only targets Azure Management endpoints, not custom-hosted web services (No). Users EXTERNAL to the Contoso named location are excluded from the policy scope, meaning the policy does not enforce MFA for them accessing the portal (No).

Topics

#Azure Conditional Access#Multi-Factor Authentication#Named Locations#Azure AD Identity Protection

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice