Courseiva
Develop Azure compute solutionsmediumMatchingObjective-mapped

AZ-204 Develop Azure compute solutions Practice Question

Match each Azure security feature to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Securely store and manage secrets, keys, and certificates

Cloud workload protection with threat detection

Enforce organizational standards and compliance rules

Fine-grained access management for Azure resources

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Azure Security Center: Unified security management and threat protection across hybrid cloud workloads

Azure Security Center provides unified security management and threat protection; Azure Sentinel is a cloud-native SIEM/SOAR; Azure Key Vault safeguards keys and secrets; Azure Active Directory manages identity and access. Common confusions include mixing Security Center with Sentinel or Sentinel with Azure AD.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure Security Center: Unified security management and threat protection across hybrid cloud workloads

    Why this is correct

    Azure Security Center, now integrated into Microsoft Defender for Cloud, offers comprehensive security posture management and advanced threat protection across hybrid cloud workloads. It continuously assesses the security state of Azure, on-premises, and multi-cloud environments, providing actionable recommendations to strengthen security configurations. This service helps organizations prevent, detect, and respond to threats by unifying security visibility and controls.

  • Azure Sentinel: Cloud-native SIEM and SOAR solution

    Why this is correct

    Azure Sentinel is a highly scalable, cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution. It aggregates security data from various sources, including Azure services, on-premises infrastructure, and other clouds, to detect sophisticated threats using built-in analytics and machine learning. Sentinel enables security operations teams to investigate incidents efficiently and automate responses to mitigate risks.

  • Azure Key Vault: Safeguard cryptographic keys and secrets used by cloud applications and services

    Why this is correct

    Azure Key Vault provides a secure, centralized store for safeguarding cryptographic keys, secrets, and certificates used by cloud applications and services. It helps developers eliminate the need to store sensitive information directly in application code or configuration files, significantly enhancing security and compliance. Key Vault supports both software-backed and hardware security module (HSM)-backed keys, ensuring robust protection for critical assets.

  • Azure Active Directory: Identity and access management service

    Why this is correct

    Azure Active Directory (Azure AD) is Microsoft's comprehensive, cloud-based identity and access management (IAM) service. It enables organizations to manage user identities, authenticate users, and control access to Azure resources, Microsoft 365, and thousands of other SaaS applications. Azure AD provides features like single sign-on (SSO), multi-factor authentication (MFA), and conditional access policies to secure access and enhance productivity.

  • Azure Security Center: Cloud-native SIEM and SOAR solution

    Why it's wrong here

    This statement incorrectly describes Azure Security Center. While Azure Security Center (now Microsoft Defender for Cloud) provides security posture management and threat protection, its primary function is not a cloud-native SIEM and SOAR solution. That specific capability, focused on security data aggregation, threat detection, and automated response across an enterprise's entire digital estate, is the distinct domain of Azure Sentinel.

  • Azure Sentinel: Identity and access management service

    Why it's wrong here

    This statement incorrectly attributes the function of identity and access management to Azure Sentinel. Azure Sentinel is designed as a cloud-native SIEM and SOAR solution, focused on collecting security logs, detecting threats, and orchestrating automated responses to security incidents. The core responsibility for managing user identities, authentication, and authorization across cloud resources and applications belongs to Azure Active Directory, not Sentinel.

About these practice questions

This AZ-204 question is part of Courseiva's 881-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.