Courseiva

AZ-305 · domain

Design identity, governance, and monitoring solutions

This domain covers identity, governance, and monitoring design on Azure: Entra ID authentication and Conditional Access, RBAC and Azure Policy for compliance, management group and subscription hierarchy for cost and policy scoping, plus Azure Monitor, Log Analytics, and Application Insights for observability. Questions present business or security requirements and ask you to select the service, scope, or configuration that satisfies them.

222 questions73 easy92 medium57 hard

Focused practice

Practice Design identity, governance, and monitoring solutions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Design identity, governance, and monitoring solutions

Be able to map a stated requirement to the correct Entra ID, Azure Policy, RBAC, or Azure Monitor construct and choose the right scope. The single most important thing: distinguish governance controls that restrict configuration (Azure Policy) from those that restrict identities and access (RBAC, Conditional Access).

Microsoft Entra Conditional Access policies triggered by sign-in risk and user risk

Azure Policy definitions, initiatives, and remediation tasks enforcing resource compliance

Management groups, subscriptions, and resource groups for scoping RBAC and cost tracking

Azure Monitor, Log Analytics workspaces, and Application Insights for metrics, logs, and alerts

Watch out for

Common Design identity, governance, and monitoring solutions exam traps

  • ▸Confusing Azure Policy (resource compliance, deny/audit) with RBAC (who can perform actions), and applying policy at the wrong scope.
  • ▸Assuming MFA is enforced globally instead of using Conditional Access with risk-based conditions and named locations.
  • ▸Placing Log Analytics workspaces or diagnostic settings at the wrong scope, so logs from multiple subscriptions are not centralized.

Question index

All Design identity, governance, and monitoring solutions questions (222)

Click any question to see the full explanation, or start a practice session above.

1

Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to collect logs from on-premises firewalls and send them to Sentinel. Which TWO connectors can you use? (Choose two.)

Easy
2

A company uses Microsoft Entra ID for identity management. They need to automate the process of granting access to resources for employees and external partners, and require periodic access reviews to ensure compliance. Which Microsoft Entra ID feature should they use?

Easy
3

Your organization plans to deploy Microsoft Entra ID Governance. You need to ensure that access to critical applications is reviewed quarterly by the application owners. Which Microsoft Entra ID feature should you use?

Easy
4

A company uses Microsoft Entra ID (Microsoft Entra ID) and Microsoft Intune. They want to block access to all corporate cloud applications (e.g., Office 365, Azure portal) from devices that are not enrolled in Intune or do not meet the company's compliance policies. The solution must work seamlessly for all cloud apps without requiring per-app configuration. Which Microsoft Entra ID feature should they configure?

Hard
5

You are designing a monitoring solution for a critical application hosted on Azure Virtual Machines. The application is latency-sensitive and you need to be alerted when CPU usage exceeds 90% for more than 5 minutes. Which Azure Monitor feature should you use?

Easy
6

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to automatically detect and respond to high-risk sign-in events, such as sign-ins from malware-linked IP addresses or leaked credentials. When such risks are detected, they want to require multi-factor authentication (MFA) or block the sign-in. They also need a dashboard to review risk events and generate reports. Which Microsoft Entra ID feature should they configure?

Easy
7

Which TWO of the following are valid Azure Policy effects that can be used to enforce compliance?

Medium
8

Your organization is designing a governance solution for multiple Azure subscriptions. You need to enforce that all resources are created in specific Azure regions (East US and West Europe only). Additionally, any resource group must have a cost center tag. Which THREE Azure components should you use? (Choose three.)

Hard
9

A company uses Microsoft Entra ID. They need to automatically block sign-ins from users whose accounts have been identified as high-risk for compromise. They also want users to be prompted to reset their password when the risk is detected. Which Microsoft Entra ID feature should they use?

Easy
10

You need to monitor Azure resources and send alerts when the CPU usage of a virtual machine exceeds 90% for 5 minutes. Which two Azure services should you use? (Select TWO.)

Medium
11

Your company has a Azure subscription with multiple resource groups. You need to ensure that all resources are tagged with a 'CostCenter' tag. What should you use?

Easy
12

Refer to the exhibit. You are reviewing an ARM template for deploying a storage account. The template is missing the storage account name parameter definition. What will happen when you attempt to deploy this template?

Hard
13

A multinational company uses Microsoft Entra ID and several Azure subscriptions. Security administrators need to review privileged role assignments every month and require justification for continued access. Which design should be recommended?

Hard
14

A company uses Microsoft Entra ID (Microsoft Entra ID). External partners need temporary access to an internal application. The process must be self-service: partners request access, the request goes through an approval workflow managed by a manager from the partner's organization, and access automatically expires after 30 days. The company also wants to send reminder emails 7 days before expiration. Which Microsoft Entra ID feature should they use?

Medium
15

Which TWO features of Microsoft Entra ID can be used to secure hybrid identities?

Easy
16

Your company uses Microsoft Entra ID. You need to implement a privileged identity management (PIM) strategy to secure administrative roles. Which TWO capabilities does PIM provide? (Choose two.)

Medium
17

Drag and drop the steps to implement Azure Site Recovery for a Hyper-V VM into the correct order.

Medium
18

Your company plans to deploy a new SaaS application that will be used by employees and external users. The application requires single sign-on (SSO) and must support conditional access policies that enforce MFA for external users. Additionally, the application must be able to read user profile attributes from Microsoft Entra ID. You need to design an identity solution that meets these requirements. What should you include in the design?

Hard
19

Refer to the exhibit. You run this Kusto query in Azure Monitor Logs. What does it return?

Hard
20

Your organization uses Microsoft Entra ID and requires that all external users accessing resources must be approved by a designated reviewer. You need to automate the review process for external identities. What should you implement?

Medium
21

Your company uses Microsoft Entra ID. You need to implement a governance strategy for guest users. Which TWO actions should you take? (Choose two.)

Medium
22

Your company uses Microsoft Entra ID for identity management. You need to implement a solution that automatically blocks sign-ins from risky users and requires multi-factor authentication (MFA) when a sign-in risk is detected. Which TWO services should you use? (Choose two.)

Easy
23

Your Azure subscription contains multiple virtual machines (VMs) that run a line-of-business application. You need to configure alerts when the CPU usage exceeds 90% for more than 5 minutes. Additionally, the alert must automatically trigger a runbook to scale out the application. Which Azure service should you use to create this alert?

Hard
24

A company uses Microsoft Entra ID. They want to grant a user temporary access to the Global Administrator role for a specific task. The access must require approval from a manager and automatically expire after 4 hours. Which Microsoft Entra ID feature should they use?

Medium
25

A company uses Microsoft Entra ID. They need to grant external partners access to an internal application for a limited time (30 days). The access must be approved by a manager from the partner's organization. After the period ends, access should automatically be removed. The company also wants to send email reminders 7 days before expiration. Which Microsoft Entra ID feature should they use?

Easy
26

A company uses Microsoft Entra ID Premium P2. They need to automatically detect users with high-risk sign-ins (e.g., from anonymous IP addresses or leaked credentials) and require them to reset their password. Which Microsoft Entra ID feature should they configure?

Medium
27

You have an Azure subscription that contains 100 virtual machines. You need to monitor the virtual machines for security vulnerabilities and receive recommendations. What should you use?

Medium
28

You are reviewing a Conditional Access policy for a Microsoft Entra ID tenant. The exhibit shows the policy configuration. Users report that they are prompted for MFA every hour even when using approved Microsoft applications. The security team wants to reduce MFA prompts but maintain security. What should you modify?

Hard
29

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to automatically detect sign-in attempts from anonymous IP addresses and sign-ins from unfamiliar locations. When such a risk is detected, they want to block the sign-in or require multi-factor authentication (MFA) in real time. Additionally, they need a dashboard that provides a summary of risk events and allows investigation. Which Microsoft Entra ID feature should they use?

Medium
30

Your company has a Microsoft Entra ID tenant with 10,000 users. You plan to grant external partners access to a specific SharePoint Online site using Microsoft Entra B2B collaboration. You need to ensure that partners can authenticate using their own corporate credentials. What should you configure?

Easy
31

Your company has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You need to design a solution to monitor changes to privileged groups in both directories and ensure that any unauthorized changes trigger an automated response. Which THREE services should you include in the design?

Hard
32

Your company has a large Azure environment with thousands of resources. You need to design a solution to track resource ownership and ensure that resources are cleaned up when projects end. You want to use a tag-based approach where each resource has an 'Owner' and 'Project' tag. Additionally, you need to generate a weekly report of resources that are not tagged or have been orphaned (no recent activity). What should you include in the design?

Easy
33

You are designing a monitoring solution for a critical application running on Azure Kubernetes Service (AKS). The application generates custom metrics that need to be queried in real-time for dashboards. You also need to retain logs for one year for compliance. Which combination of services should you use?

Hard
34

Which TWO of the following are true about Microsoft Entra ID Governance features?

Medium
35

A company uses Microsoft Entra ID. They need to monitor sign-in logs for anomalous activity (e.g., sign-ins from unfamiliar locations) and automatically take action such as requiring MFA or blocking sign-in. Which Microsoft Entra ID feature should they configure?

Medium
36

Your organization uses Microsoft Entra ID with P2 licensing. You need to implement a strategy to automatically detect and remediate risky sign-ins without requiring user interaction for low-risk events. What should you configure?

Hard
37

Your company has a Microsoft Entra ID tenant with 50,000 users. You need to design a solution to ensure that users can reset their own passwords without help desk intervention, while preventing password reuse for the last 10 passwords. Which feature should you enable?

Medium
38

Which TWO actions should you take to implement a least-privilege identity strategy for Azure resources?

Medium
39

Your company has multiple Azure subscriptions and needs a single pane of glass to monitor the health and performance of all resources across subscriptions. Which Azure service should you use?

Easy
40

A multinational company uses Microsoft Entra ID. The company has regional IT teams that need to manage users and groups within their respective regions. Each region has a distinct set of users in specific organizational units. The company wants to assign the User Administrator role to regional IT staff, but limit their scope to only the users in their region. Which Microsoft Entra ID feature should they use?

Easy
41

You need to ensure that only authorized users can access the Azure portal. What should you use?

Easy
42

A company is migrating on-premises Windows applications that require LDAP, NTLM, or Kerberos authentication to Azure VMs. They want to provide domain services for these applications without deploying and managing domain controllers. Which Azure service should they use?

Medium
43

Which TWO features of Microsoft Entra ID help protect against credential compromise? (Choose two.)

Easy
44

Your company has a Microsoft Entra ID tenant with 10,000 users. You need to implement a lifecycle workflow that automatically disables user accounts when employees leave the organization, and then deletes them after 30 days. What should you use?

Hard
45

A company uses Microsoft Entra ID B2B collaboration for external partners. They want to enforce that external users must use multi-factor authentication (MFA) and access company resources only from devices that are compliant with Intune policies. Additionally, they need to require a session timeout of 1 hour. Which combination of Microsoft Entra ID features should they use?

Medium
46

Your company is implementing a new Azure subscription for a project that requires strict separation of duties. The security team requires that all resource creation must be approved by a central IT team. Additionally, any resource that does not comply with company tagging standards should be automatically reported. You need to design a solution that meets these requirements using Azure Policy and Azure Role-Based Access Control (RBAC). What should you do?

Easy
47

Refer to the exhibit. You are an Azure administrator reviewing a custom Azure Policy definition. What does this policy do?

Medium
48

An organization wants to enforce MFA only when sign-in risk is medium or high. Which Microsoft Entra capability should be used?

Medium
49

Your Azure environment includes multiple subscriptions that are managed by different teams. You need to ensure that all resources are compliant with your company's security policies, and any non-compliant resources must be automatically remediated or reported. Which solution should you implement?

Hard
50

A company wants to monitor sign-in failures for their Microsoft Entra ID-integrated applications. They need a dashboard in Azure Monitor showing sign-in failures by application and user location. Which data source should they stream to a Log Analytics workspace?

Easy
51

Your company plans to use Microsoft Sentinel as a SIEM solution. You need to ensure that security events from all Azure subscriptions are collected in a single workspace. What should you configure?

Easy
52

Your organization uses Microsoft Defender for Cloud to assess the security posture of Azure resources. You need to ensure that all Azure subscriptions are covered by a single continuous export configuration that sends security alerts to a Log Analytics workspace. What should you do?

Medium
53

Your organization is implementing a hybrid identity solution with Microsoft Entra ID. Users in an on-premises Active Directory domain need to access cloud applications. You need to ensure that password changes on-premises are synchronized to Entra ID within 30 seconds. Which configuration should you use?

Medium
54

A company uses Microsoft Entra ID (Microsoft Entra ID) for identity management. They want to automatically detect sign-in risks such as sign-ins from unfamiliar locations, anonymous IP addresses, or leaked credentials. Based on the risk level, they want to apply different controls: for low-risk sign-ins, show a message but allow access; for medium-risk sign-ins, require multi-factor authentication (MFA); for high-risk sign-ins, block the sign-in. They also need to receive a weekly summary report of risk events. Which Microsoft Entra ID feature should they configure?

Medium
55

A company uses Microsoft Entra ID (Microsoft Entra ID). They have a SaaS application that supports SCIM (System for Cross-domain Identity Management). The company wants to automatically create, update, and deactivate user accounts in the SaaS application whenever changes occur in Microsoft Entra ID. They do not want to use custom scripts. Which Microsoft Entra ID feature should they configure?

Medium
56

A company uses Azure Policy to enforce tagging on resources. The security team reports that some resources are missing the required 'CostCenter' tag. You need to ensure that any resource created without the required tag is automatically remediated by adding the tag with a default value. What should you configure in Azure Policy?

Medium
57

Which THREE should you consider when designing a monitoring solution for a critical application that requires high availability and low latency? (Choose three.)

Hard
58

You need to provide a team of developers with access to create and manage Azure resources in a specific resource group. The developers should not be able to modify access policies for other users. Which built-in role should you assign?

Easy
59

A company wants to monitor sign-in activity for their Microsoft Entra ID-integrated applications. They need to detect risky sign-ins, such as sign-ins from anonymous IP addresses or unfamiliar locations, and automatically block or require multi-factor authentication. They also need a dashboard showing risk events and the ability to investigate and remediate. Which Microsoft Entra ID feature should they use?

Medium
60

You are designing an identity solution for a large enterprise that uses Microsoft Entra ID. The company has a partner organization that needs access to a specific application. The partner uses their own identity provider (IdP). You need to enable seamless access without duplicating user accounts. What should you configure?

Medium
61

Which TWO Microsoft Entra ID features should you use to protect against credential attacks?

Medium
62

Which THREE Azure services or features should you use to design a comprehensive monitoring solution for a hybrid infrastructure spanning on-premises and Azure?

Hard
63

Your organization uses Azure Monitor to monitor a fleet of 500 VMs running Windows Server. You need to collect security event logs (Event ID 4625 for failed logons) from all VMs and send them to a Log Analytics workspace. The solution must support centralized configuration and be scalable. You also want to filter out high-volume noise events to reduce costs. What should you do?

Medium
64

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to allow external business partners to access an internal web application using their own organizational identities. The solution must support self-service sign-up and enforce multi-factor authentication for partner users. Which Microsoft Entra ID feature should they configure?

Easy
65

Your company has a hybrid identity environment with 10,000 on-premises users synchronized to Microsoft Entra ID using Microsoft Entra Connect. You plan to implement a modern access control strategy for all cloud applications. The requirements are: enforce multifactor authentication (MFA) for all users when accessing sensitive applications, allow users to self-remediate risky sign-ins via a mobile app, and minimize infrastructure complexity. You need to design the identity and governance solution. What should you do?

Hard
66

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to automatically detect identity risks, such as users with leaked credentials or sign-ins from anonymous IP addresses, and generate alerts. They also want to automatically trigger a password reset for high-risk users. Which Microsoft Entra ID feature should they configure?

Easy
67

A company uses Microsoft Entra ID (Microsoft Entra ID). They have many guest users with access to internal SharePoint sites and applications. They need to review guest user access every 90 days and automatically remove access if the guest does not respond to the review request. The solution must be fully automated without custom scripting. Which Microsoft Entra ID feature should they use?

Hard
68

Your company is designing a governance strategy for Azure. You need to ensure that all resource groups in a subscription are created with a specific naming convention and mandatory tags. Which THREE services or features should you use together? (Choose three.)

Hard
69

A company uses Microsoft Entra ID. They want to enforce that all users must use multi-factor authentication (MFA) when accessing sensitive applications from outside the corporate network, but allow access without MFA when coming from the corporate office IP range. Which Microsoft Entra ID feature should they use to create this policy?

Easy
70

Refer to the exhibit. You deploy this Azure Network Watcher connection monitor to test TCP connectivity on port 443 between two VMs. The test consistently shows 'Unreachable' status. Both VMs are running and have correct NSG rules allowing inbound port 443 from the source VM's IP. What is the most likely cause?

Hard
71

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to provide external business partners with access to an internal application. The access must be time-limited to 60 days, approved by a manager within the partner company, and automatically expire. The company also needs to generate reports of who has access. Which Microsoft Entra ID feature should they implement?

Medium
72

Your company has a Microsoft Entra ID tenant with 10,000 users. You need to design a monitoring solution to detect when users are assigned to high-privilege roles (e.g., Global Administrator) and ensure that any such assignment triggers an automated investigation. Additionally, you need to monitor sign-in failures for guest users and automatically block accounts after 5 failed attempts within 10 minutes. You have the following requirements: 1) Use a cloud-native solution that minimizes administrative overhead. 2) Integrate with Microsoft Sentinel for incident response. 3) Use built-in features where possible. What should you do?

Medium
73

A company plans to migrate on-premises applications to Azure. They require users to authenticate using their existing on-premises Active Directory credentials without syncing password hashes to the cloud. Which Microsoft Entra ID authentication method should they use?

Easy
74

A company is building a customer-facing web application. They want to allow users to sign in using their existing social accounts (Microsoft, Google, Facebook) or create a local account. The solution must be fully managed and support custom branding. Which Azure service should they use?

Medium
75

Your organization uses Azure Monitor Logs to analyze application performance. You need to create a custom log query that calculates the 95th percentile of response times for a web app over the last 24 hours. Which THREE KQL functions should you use? (Choose three.)

Hard
76

Refer to the exhibit. You deploy this ARM template to create an Azure Monitor Workbook. The template deploys successfully. What will the workbook display?

Hard
77

Your organization uses Microsoft Entra ID. You need to allow external users to sign in using their own identity providers (e.g., Google, Facebook) to access a custom application. What should you configure?

Medium
78

Your company uses Microsoft Sentinel for security monitoring. You need to design a solution to detect when a user account is created in Microsoft Entra ID with Global Administrator privileges. When detected, an incident must be created in Sentinel and the account should be disabled temporarily until reviewed. You want to use built-in capabilities where possible. What should you do?

Medium
79

Your company is planning to use Azure Monitor Workbooks to create custom dashboards for IT operations. You need to select the data sources that can be used in a workbook. Which TWO data sources are supported? (Choose two.)

Medium
80

You are reviewing a custom RBAC role in Azure. The exhibit shows the role definition. A user with this role reports they cannot read diagnostic settings for a storage account in the Production resource group. What is the most likely cause?

Hard
81

A large enterprise has a management group hierarchy with 50 subscriptions. They need to enforce that every resource group must have a 'CostCenter' tag and that any new resource group without that tag is automatically denied creation. Additionally, they need to ensure that only the Finance team can modify tags on any resource. They also want to generate monthly compliance reports showing which resources are non-compliant. Which combination of Azure services should they use?

Hard
82

Match each Azure compute service to its characteristic.

Medium
83

Your organization is moving to a cloud-only identity model using Microsoft Entra ID. You need to ensure that users can reset their own passwords without help desk intervention. The solution must support multi-factor authentication and notify administrators of password resets. What should you implement?

Easy
84

Refer to the exhibit. You are deploying an ARM template that assigns a policy to audit virtual machines not using managed disks. After deployment, you need to verify that the policy assignment is working. Which Azure CLI command should you run?

Easy
85

A company uses Microsoft Entra ID. They want to automatically detect sign-ins from anonymous IP addresses, sign-ins from unfamiliar locations, and other risky activities. When such a risk is detected, they want to block the sign-in or require multi-factor authentication. They also need a dashboard to review risk events. Which Microsoft Entra ID feature should they use?

Easy
86

Match each Azure migration tool to its use case.

Medium
87

Refer to the exhibit. A user reports they cannot access a secret in the vault 'vault-prod'. The user has a Contributor role at the subscription scope and a Key Vault Secrets User role at the specific vault scope. What is the most likely reason for the failure?

Hard
88

Your company has multiple Azure subscriptions managed by different teams. You need to design a governance solution that ensures: 1) All subscriptions must have a consistent set of policies (e.g., allowed locations, allowed VM SKUs). 2) Compliance reports must be generated daily for each subscription. 3) Non-compliant resources must be automatically remediated where possible (e.g., add tags). 4) The solution must use a single management group hierarchy. What should you include in the design?

Hard
89

A company uses Microsoft Entra ID and wants to allow users to sign in using their existing personal Microsoft accounts, Google, and Facebook identities. They also need custom sign-up and sign-in flows with collection of specific user attributes. Which Microsoft Entra ID feature should they use?

Easy
90

Which THREE Azure services can be used to monitor the performance of a web application? (Choose three.)

Medium
91

Your company uses Microsoft Entra ID and has a custom application that requires users to have specific roles assigned. You need to ensure that role assignments are reviewed quarterly and automatically remove assignments that are not approved. Which feature should you use?

Medium
92

You are designing a governance strategy for Azure resources. The company has multiple departments, each requiring separate cost tracking and policy enforcement. You need to organize resources to align with the departments while minimizing management overhead. What should you use?

Medium
93

Refer to the exhibit. You are deploying NSG flow logs. After deployment, you notice that no logs are being written to the storage account. What is the most likely cause?

Medium
94

A company has an Azure subscription with a Log Analytics workspace. They need to ensure that all administrative operations performed on Azure resources are logged and retained for 90 days. The logs must be queryable using Kusto Query Language (KQL). What should you configure?

Easy
95

Your organization has multiple Azure subscriptions and uses Azure Blueprints to enforce governance. You need to design a blueprint that includes role assignments, policy assignments, and resource groups. Which THREE components can be included in an Azure Blueprint? (Choose three.)

Hard
96

Your company uses Microsoft Entra ID for identity management. You need to ensure that users can access corporate resources without passwords while maintaining a high level of security. Which feature should you implement?

Easy
97

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to implement a solution that automatically detects identity-related risks such as leaked credentials, impossible travel, and sign-ins from anonymous IP addresses. They want to generate reports summarizing risk events and integrate the risk data with their existing Security Information and Event Management (SIEM) system via API. Which Microsoft Entra ID feature should they use?

Hard
98

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to grant specific IT administrators just-in-time (JIT) access to Azure virtual machines for troubleshooting. The access must be time-bound, require approval from a senior manager, and be automatically revoked after the granted time period. The company also needs an audit log of all access requests and assignments. Which Azure service or feature should they use?

Medium
99

Your company requires that all administrative actions in Azure subscriptions be logged and retained for seven years. Which service should you use to collect and store these logs?

Easy
100

Refer to the exhibit. You are deploying a Log Analytics workspace using an ARM template with the parameters shown. Your compliance team requires that all log data be retained for at least 2 years. Which parameter value should you modify?

Hard
101

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to enforce that all users accessing the company's internal application from mobile devices must be compliant with device management policies (e.g., require a PIN and encryption). The application does not support modern authentication. Which Microsoft Entra ID feature should they use?

Hard
102

Which TWO Microsoft Entra ID editions include Conditional Access? (Choose two.)

Easy
103

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to grant temporary administrative roles to users for specific tasks. The process must require approval from a designated approver, and the access must automatically expire after a defined period. The company also needs audit logs of all role assignments and activations. Which Microsoft Entra ID feature should they implement?

Easy
104

A company uses Microsoft Entra ID. They want to integrate their security operations with a third-party SIEM tool. They need to export all Microsoft Entra ID sign-in logs and audit logs to the SIEM for analysis. The solution should be automated and near real-time. Which Azure service should they configure?

Medium
105

Your company uses Azure Resource Manager templates for infrastructure deployment. You need to ensure that all deployments are validated against organizational policies before resources are provisioned. Which Azure service should you use?

Easy
106

A company requires all users to use multi-factor authentication (MFA) when accessing cloud applications. However, they want to exempt users from MFA when they connect from the company's headquarters, which has a trusted IP range. They want to enforce this policy centrally. Which Microsoft Entra ID feature should they use?

Easy
107

Which THREE capabilities are provided by Microsoft Entra ID Identity Governance? (Select THREE.)

Hard
108

A company uses Microsoft Entra ID and wants to enforce that all users must use multi-factor authentication (MFA) when accessing sensitive applications. However, they want to exclude users when connecting from the corporate office IP range and only allow access from devices that are compliant with Intune policies. Which Microsoft Entra ID feature should they use to create this policy?

Medium
109

Which THREE of the following are required to collect Windows security events into Microsoft Sentinel?

Hard
110

You are designing identity governance for a company that uses Microsoft Entra ID. The company wants to grant external partners access to an internal application for 90 days. After 90 days, access must be automatically removed. Additionally, the application requires that users have multi-factor authentication (MFA) and a compliant device. You need to design a solution that meets these requirements with minimal administrative effort. What should you do?

Easy
111

Your organization uses Microsoft Azure and has a subscription with multiple resource groups. You need to ensure that only users in the Finance department can access storage accounts in the 'Finance' resource group. The solution must use role-based access control (RBAC). What should you assign?

Easy
112

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to automatically review and remove guest accounts that have not signed in for 90 days. They also need to generate reports for auditors. Which Microsoft Entra ID feature should they use?

Easy
113

Your company plans to use Microsoft Sentinel for security information and event management (SIEM). You need to ingest security logs from multiple Azure resources and on-premises servers. Which data connector should you use for Windows servers on-premises?

Easy
114

A company uses Microsoft Entra ID and wants to automate the lifecycle management of user accounts in their SaaS applications, such as Salesforce and ServiceNow. The solution should automatically create, update, and deactivate accounts when users join, move, or leave the organization. Which Microsoft Entra ID feature should they use?

Medium
115

Refer to the exhibit. You run this PowerShell script in an Azure subscription. The script executes successfully. What is the outcome?

Medium
116

Refer to the exhibit. You are creating a role assignment in Azure. The role definition ID is for the Contributor role. What is the effect of this assignment?

Easy
117

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to ensure that users who access sensitive cloud applications from untrusted networks (e.g., public Wi-Fi) are prompted for multi-factor authentication (MFA). Which Microsoft Entra ID feature should they configure?

Easy
118

Refer to the exhibit. You create this Conditional Access policy in Microsoft Entra ID. What is the result?

Medium
119

Your company is implementing a monitoring solution for Azure virtual machines. You need to collect performance counters and log events from the VMs and send them to a centralized Log Analytics workspace. Which agent should you install on the VMs?

Easy
120

A company uses Microsoft Entra ID Premium P2. They need to implement a solution that allows users to request access to an access package that includes membership in a Microsoft Entra security group and access to a SharePoint Online site. The access must be time-limited and require approval by the user's manager. What should you configure?

Hard
121

Your company is deploying Microsoft Entra ID Governance and needs to ensure that guest users' access to internal applications expires after 90 days. Which feature should you configure?

Easy
122

A company uses Microsoft Entra ID (Microsoft Entra ID) Premium P2. They want to automatically block sign-ins from malicious IP addresses and require users to perform multi-factor authentication (MFA) when signing in from untrusted locations. Which Microsoft Entra ID feature should they use?

Easy
123

Refer to the exhibit. You deploy this Azure Monitor scheduled query rule to alert when CPU usage exceeds 90% for sustained periods. However, alerts are not firing even when the condition is met. What is the most likely cause?

Hard
124

You are designing a governance strategy for Azure resources. Your organization has multiple departments, each with its own set of Azure subscriptions. You need to enforce consistent policies across all subscriptions, such as allowed resource locations and required tags, while allowing departments to manage their own resources within those constraints. Which Azure service should you use?

Medium
125

You are designing a governance strategy for a new Azure subscription. The security team requires that all resources must have a 'CostCenter' tag and an 'Environment' tag. Which Azure policy effect should you use to automatically apply the tags to new resources?

Medium
126

Your organization uses Azure Monitor to collect metrics from Azure resources. You need to create a custom metric alert that triggers when the average CPU usage of a specific virtual machine exceeds 80% for 10 minutes. Which TWO components are required? (Choose two.)

Medium
127

Your company runs a mission-critical application on Azure Virtual Machines in a single region. You need to design a monitoring solution that provides proactive alerts for performance degradation and allows the operations team to analyze historical trends. The solution must minimize cost and operational overhead. You have an existing Log Analytics workspace. What should you include in the design?

Medium
128

A company wants workload deployments to access Azure resources without storing client secrets in CI/CD variables. The pipeline runs from GitHub Actions. Which identity design should be used?

Medium
129

Your organization uses Microsoft Entra ID and Azure Key Vault. You need to ensure that a custom application can securely access secrets in Key Vault without storing credentials in code. The application runs on an Azure Virtual Machine. What should you use?

Medium
130

Your company has an Azure subscription that contains 100 virtual machines (VMs). You are designing a monitoring solution that must meet the following requirements: - Alert when any VM's CPU usage exceeds 90% for 15 minutes. - Alert when any VM's available memory drops below 1 GB. - Provide a centralized dashboard showing real-time performance metrics for all VMs. Which TWO Azure services should you include in the solution? (Choose two.)

Medium
131

Your organization plans to use Azure Policy to enforce tagging on all resources. The tags must include 'CostCenter' and 'Environment'. Resources that do not have these tags should be automatically remediated. What should you use?

Easy
132

Your organization uses Microsoft Entra ID. You need to enforce multifactor authentication (MFA) for all guest users accessing a specific SharePoint Online site. What is the most efficient way to achieve this?

Medium
133

Which THREE components are required to monitor and audit Azure resource changes using Azure Monitor?

Hard
134

You are designing a governance solution for a Microsoft Azure environment that contains multiple subscriptions. You need to ensure that all resources are compliant with corporate security policies. The solution must automatically remediate non-compliant resources. What should you include in the design?

Medium
135

Refer to the exhibit. You are reviewing an Azure Policy definition. Which virtual machines will be denied?

Hard
136

You are designing an identity solution for a multinational company that uses Microsoft Entra ID. The company has a requirement that all users must authenticate using biometrics or FIDO2 security keys. Which Entra ID feature should you configure?

Hard
137

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to automate the process of granting users access to a specific application only during business hours and revoking it automatically. The access should be based on a request-approval workflow. Which Microsoft Entra ID feature should they use?

Medium
138

You are designing a monitoring solution for a multi-region application deployed on Azure Virtual Machines and Azure SQL Database. The solution must provide a unified view of metrics and logs from all resources, detect anomalies using machine learning, and send alerts to the operations team. Which TWO capabilities should you include in the design?

Medium
139

Your company operates in a highly regulated industry and must retain all sign-in logs for 7 years. The logs must be immutable and cannot be modified or deleted by administrators. You need to design a monitoring solution that stores sign-in logs in a cost-effective manner while meeting compliance requirements. The solution should also allow for real-time analysis of sign-in activity. What should you include in the design?

Medium
140

Your organization is implementing a zero-trust security model. You need to ensure that all access to corporate resources from mobile devices is conditional based on device compliance, user risk, and location. Which Microsoft Entra ID feature should you use?

Medium
141

A company uses Microsoft Entra ID. They want to block all access to corporate applications from devices that are not managed by their organization. They require that only devices enrolled in Microsoft Intune and compliant with company policies can access company resources. Which Microsoft Entra ID feature should they use?

Medium
142

You are designing a monitoring solution for a hybrid environment with on-premises servers and Azure VMs. You need to collect performance data from all servers and visualize it in a single dashboard. Which Azure service should you use?

Hard
143

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to allow external business partners to request access to a specific application. The access must be time-limited and require approval from the partner's manager. Additionally, access must automatically expire after the defined period. Which Microsoft Entra ID feature should they use?

Easy
144

Your company has a Microsoft Entra ID tenant with 10,000 users. You are designing an identity governance solution to automate user access reviews for critical applications. The compliance team requires that access reviews be conducted quarterly and that any reviewer who does not respond within 7 days have their decisions auto-approved. You need to implement the solution using Microsoft Entra ID Governance. What should you do?

Medium
145

A company wants to automatically detect sign-in attempts from anonymous IP addresses and sign-ins from unfamiliar locations. When such a risk is detected, they want to require multi-factor authentication (MFA) or block the sign-in in real time. Additionally, they need a dashboard that shows risk events and allows generating weekly risk reports. Which Microsoft Entra ID feature should they use?

Medium
146

A company uses Microsoft Entra ID (Microsoft Entra ID) for identity management. They want to enforce that only devices compliant with security policies (e.g., BitLocker enabled, antivirus running) can access corporate cloud applications (Microsoft 365 and custom SaaS apps). They also need a dashboard to monitor device compliance status. Which Microsoft Entra ID feature(s) should they configure?

Medium
147

A company has an Azure subscription with many resource groups. The security team requires that all diagnostic settings for every Azure resource be automatically configured to send logs to a central Log Analytics workspace. You need to design a solution that enforces this configuration at scale without manual intervention. What should you include in the design?

Medium
148

A company uses Microsoft Entra ID (Microsoft Entra ID) Premium P2. They need to automatically detect users whose credentials have been leaked and require them to reset their password at their next sign-in. Additionally, they want to block sign-ins from anonymous IP addresses (e.g., Tor network). Which combination of Microsoft Entra ID features should they enable to meet both requirements?

Hard
149

Your organization has multiple Azure subscriptions. You need to create a central view of policy compliance across all subscriptions. What should you use?

Medium
150

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to generate periodic reports of user sign-ins and audit activities for compliance. They want to store the logs for 1 year. Which Azure service should they use?

Easy
151

Refer to the exhibit. You are reviewing a Bicep template for a storage account. You need to ensure that the storage account is only accessible via HTTPS and uses TLS 1.2. Which property validates this requirement?

Hard
152

You need to design a solution to monitor the performance of an Azure SQL Database. You want to create a dashboard that shows the top 10 queries by CPU usage over the last hour. What should you use?

Easy
153

You are designing a monitoring solution for a hybrid environment with on-premises servers and Azure VMs. You need to collect security events and performance data centrally, and create custom alerts. The solution must use the same agent for both environments. Which agent should you deploy?

Medium
154

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to automatically detect sign-ins from users with leaked credentials and prompt those users to reset their password during the next sign-in. Which Microsoft Entra ID feature should they enable?

Easy
155

Your organization uses Microsoft Purview to govern data across Azure and on-premises sources. You need to ensure that sensitive data, such as credit card numbers, is automatically detected and classified in Azure Blob Storage. Which Purview feature should you configure?

Easy
156

A company wants to collect metrics and logs from all Azure resources in their subscription, including custom metrics from their applications, and create dashboards and alerts. Which Azure service should they use as the primary monitoring platform?

Easy
157

Your organization uses Microsoft Entra ID and has a hybrid identity deployment with Active Directory Domain Services (AD DS) on-premises. You need to synchronize user identities to Microsoft Entra ID, but you must ensure that password hashes are never stored in the cloud. Which synchronization method should you use?

Medium
158

A multinational company uses Microsoft Entra ID with a custom domain. They need to implement a governance strategy for Microsoft 365 groups, ensuring that group expiration policies are enforced and that group owners receive renewal notifications. What should you configure?

Hard
159

A company uses Microsoft Entra ID for identity management. They want to ensure that users accessing sensitive data from unmanaged devices are prompted for multifactor authentication (MFA) and must accept a terms-of-use. Which policy should be configured?

Easy
160

Your company is migrating on-premises applications to Azure. You need to ensure that users can sign in using their existing on-premises Active Directory credentials without duplicating accounts. Which identity solution should you recommend?

Easy
161

You need to configure a monitoring solution for Azure virtual machines that collects performance counters, event logs, and enables alerting based on CPU usage exceeding 90%. Which Azure service should you use?

Easy
162

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to automatically remove guest users who have not signed in for 60 days. Additionally, they must generate a report of all guest access for auditors. Which Microsoft Entra ID feature should they implement?

Medium
163

Drag and drop the steps to implement Azure AD Privileged Identity Management (PIM) for a role into the correct order.

Medium
164

A company uses Microsoft Entra ID B2B to collaborate with external vendors. They want to enforce that external users must use multi-factor authentication (MFA) and access company resources only from compliant devices (e.g., managed by Intune). They also want to require a session timeout of 1 hour. Which combination of Microsoft Entra ID features should they use?

Hard
165

You are designing a monitoring solution for a critical application that runs on Azure Virtual Machines. The application generates custom performance counters. You need to alert when the custom counter exceeds a threshold and trigger an Azure Automation runbook to remediate. Which two Azure services should you combine? (Select TWO.)

Hard
166

You are designing a monitoring solution for an Azure function app that processes messages from Azure Service Bus. The function app is critical and must be highly available. You need to monitor for poison messages and trigger an alert when the dead-letter queue count exceeds 100. What should you use?

Hard
167

Refer to the exhibit. You are an Azure administrator for a company that enforces a policy that no virtual networks or network security groups can be created. However, a developer reports that they successfully created a virtual network. What is the most likely reason the policy did not block the creation?

Hard
168

Your organization has a complex Azure environment with multiple subscriptions. You need to design a governance strategy that ensures: 1) All resources must have specific tags (CostCenter, Environment, Owner). 2) Any resource without required tags must be reported to the compliance team weekly. 3) Virtual machines must not be deployed in certain regions due to data sovereignty. 4) The solution must be automated and use native Azure services. You already have an Azure Log Analytics workspace and a central automation account. What should you include in the design?

Hard
169

Your company has multiple Azure subscriptions. You need to ensure that all security-related logs from Azure resources are centralized in a single Log Analytics workspace for analysis. Which Azure service should you use to collect and route these logs?

Easy
170

You are tasked with ensuring that all VMs in the subscription have Azure Hybrid Benefit enabled for Windows Server. You create the Azure Policy shown in the exhibit. However, after assignment, the compliance report shows that some D-series VMs are still non-compliant. What is the most likely cause?

Hard
171

A SaaS application must allow external partner users to sign in with their own organization credentials while the company controls application access. What should be used?

Hard
172

You are a solutions architect for a large healthcare organization that uses Microsoft 365 and Azure. The organization has a Microsoft Entra ID tenant with 15,000 users. The security team requires that all users use multi-factor authentication (MFA) when accessing cloud applications. Currently, only 60% of users have registered for MFA. The organization wants to enforce MFA registration for all users within 30 days. The solution must minimize user disruption and allow users to register their MFA methods during their normal work hours. The organization uses Microsoft Intune for mobile device management and has a conditional access policy that requires MFA for all cloud apps. You need to design a solution to enforce MFA registration. What should you do?

Medium
173

A company uses Microsoft Entra ID (Microsoft Entra ID) Premium P2. They want to enforce that users accessing sensitive cloud applications from outside the corporate network must use multi-factor authentication (MFA). Which Microsoft Entra ID feature should they configure?

Easy
174

A company has Microsoft Entra ID Premium P2 licenses and wants to ensure that privileged roles (e.g., Global Administrator) are only activated when needed and with approval. They also need to regularly review who has access to these roles. Which combination of features should they use?

Medium
175

Your company uses Microsoft Entra ID and has recently deployed Microsoft Sentinel. You need to design a monitoring solution to detect brute-force attacks against user accounts. The solution should use built-in analytics rules where possible and must trigger an automated response to temporarily disable the affected account. What should you include in the design?

Easy
176

A company wants to allow remote users to access an internal web application hosted on-premises without opening inbound firewall ports. They need seamless single sign-on (SSO) using Microsoft Entra ID credentials. Which Azure service should they use?

Easy
177

Which TWO actions should you take to design a monitoring solution for a multi-tier application running on Azure VMs? (Select TWO.)

Medium
178

Your organization uses Microsoft Sentinel for security monitoring. You need to create a rule that triggers an incident when a user from a specific IP address performs more than 10 failed sign-ins within an hour. Which rule type should you use?

Medium
179

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to enable users to reset their own passwords without contacting the help desk. They also want to enforce multi-factor authentication (MFA) during the password reset process. Which Microsoft Entra ID feature should they enable?

Easy
180

A multinational company uses Microsoft Entra ID for identity. They need to grant external partners access to specific SharePoint Online sites. The access must be time-limited and require approval from a resource owner. Which Microsoft Entra ID feature should they use?

Medium
181

You are designing a monitoring solution for Azure SQL Database. The requirement is to track query performance metrics such as CPU usage, data IO, and wait statistics over time. You need to identify performance bottlenecks and provide historical data for analysis. Which Azure service should you use?

Easy
182

Refer to the exhibit. You are a security administrator reviewing a custom Azure Policy assignment. The policy definition with ID 'abc123' is an initiative containing two policies: one that audits storage accounts with blob public access enabled and one that deploys a diagnostic setting for network security groups. The scope includes a production resource group. However, the compliance state shows 'Non-compliant' for several resources. What is the most likely reason for the non-compliance?

Hard
183

A large enterprise wants to enforce zero-trust conditional access policies that use real-time user risk, sign-in risk, and device compliance. Which combination of Microsoft Entra ID features should they use?

Hard
184

You are designing an identity lifecycle management solution for a multinational company. Employees frequently change departments, and you need to automate the assignment and removal of application access based on their current department. Which THREE Microsoft Entra features should you use?

Medium
185

A company wants to configure policies that detect risky sign-ins (e.g., from anonymous IPs or unfamiliar locations) and automatically require multi-factor authentication (MFA) when such risk is detected. Which Microsoft Entra ID feature should they use to create these policies?

Medium
186

Which TWO actions can be performed using Microsoft Entra ID Governance? (Choose two.)

Medium
187

Which TWO are benefits of using Microsoft Entra ID Governance? (Choose two.)

Medium
188

Which THREE conditions should be met to implement a successful Azure landing zone for a new enterprise subscription? (Choose three.)

Hard
189

A company uses Microsoft Entra ID (Microsoft Entra ID) and Microsoft Intune. They want to block all access to internal corporate applications from devices that are not enrolled in Intune and do not meet the company's compliance policies. The solution must apply to all cloud app access seamlessly. Which Microsoft Entra ID feature should they configure?

Medium
190

A company is designing a governance solution for a large Azure environment with multiple subscriptions. They need to ensure that all resources are deployed only in approved Azure regions and that all resources have a specific tag 'CostCenter'. They also need to be able to delegate management of policies to individual business units while maintaining central control. Which two features should be included in the design? (Choose two.)

Medium
191

Match each Azure service to its primary function.

Medium
192

Your company uses Microsoft Entra ID for identity management. You need to design a monitoring solution for sign-in logs to detect suspicious activity. Which TWO Azure services should you include in the design?

Medium
193

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to allow users to sign in to multiple SaaS applications using their Microsoft Entra ID credentials without being prompted again for each application. Which Microsoft Entra ID feature should they enable?

Easy
194

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to integrate their on-premises Active Directory with Microsoft Entra ID to enable single sign-on (SSO) for cloud applications. Users should be able to use the same password for on-premises resources and cloud applications. The company has a large on-premises user base and wants to avoid additional infrastructure for federation. Which Microsoft Entra ID feature should they implement?

Easy
195

You need to monitor the sign-in activities of users in Microsoft Entra ID and detect risky sign-ins, such as those from anonymous IP addresses. Which service should you use?

Easy
196

You are designing a monitoring solution for a cloud-native application that uses Azure Functions, Azure Storage, and Azure Cosmos DB. The solution must provide centralized log collection and analysis, enable proactive alerting on application errors, and support long-term log retention for compliance (7 years). What should you include in the design?

Easy
197

Which THREE Azure Monitor capabilities can be used to detect and diagnose performance issues in a multi-tier application?

Hard
198

Which THREE components are required to implement a complete monitoring solution with Azure Monitor? (Choose three.)

Hard
199

A company uses Microsoft Entra ID to manage identities for employees and partners. They need to allow partners to self-service reset their passwords using a mobile app notification. Which feature should you enable?

Medium
200

A company uses Microsoft Entra ID. They want to allow external business partners to request access to a specific internal application. The access must be time-limited and require approval from a manager within the partner's organization. Additionally, access should automatically expire after the defined period. Which Microsoft Entra ID feature should they use?

Medium
201

Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to ensure that an alert is generated when an Azure VM is created with an open inbound SSH port (22) from the internet. The solution should use existing Azure resources and minimize administrative overhead. What should you use?

Medium
202

Your organization uses Microsoft Entra ID and requires that all external users invited via B2B collaboration must authenticate using multi-factor authentication (MFA). You need to enforce this for all guest users. What should you configure?

Hard
203

Your company uses Microsoft Sentinel for security monitoring. You need to design a solution that automatically responds to incidents involving high-severity alerts. The response should include creating an incident in Microsoft Teams and sending an email to the security team. What should you use?

Medium
204

Refer to the exhibit. You assign this Azure Policy to a resource group. A user attempts to create a new Azure SQL Server without specifying an administrator login. What will happen?

Easy
205

Your company uses Microsoft Entra ID to manage identities for 5,000 employees. You plan to implement Microsoft Entra ID Governance to automate the user provisioning lifecycle for a third-party SaaS application. The application supports SCIM 2.0. You need to ensure that user accounts are automatically created, updated, and disabled in the application based on changes in Entra ID. What should you do?

Medium
206

Your organization uses Microsoft Purview for data governance. You need to classify sensitive data in Azure SQL Database and automatically apply sensitivity labels. What should you configure?

Easy
207

You need to monitor the performance and health of your Azure virtual machines, including custom metrics and logs. You also need to set up alerts based on specific thresholds. Which Azure service should you use?

Easy
208

Your organization is designing a monitoring solution for a critical application running on Azure VMs. You need to collect performance metrics and logs from the VMs and send them to a centralized Log Analytics workspace. You also need to visualize the data in near real-time. Which combination of services should you use?

Medium
209

Your organization is deploying a critical application in Azure that must maintain an uptime SLA of 99.99%. The application runs on Azure Virtual Machines in a single region. You need to design a monitoring solution that alerts the operations team within 5 minutes of any VM unavailability. The solution must minimize false positives and avoid alert fatigue. What should you include in the design?

Hard
210

You are designing a governance strategy for an Azure environment that includes multiple subscriptions. The security team requires that all storage accounts must have HTTPS traffic only. Any non-compliant storage account must be automatically remediated. What is the most efficient solution?

Hard
211

Your organization has 500 users in Microsoft Entra ID. You need to ensure that users can only access Microsoft 365 apps from compliant devices (compliant with Intune policies). Users are already enrolled in Intune. The compliance policies are defined. You need to configure the access control mechanism. What should you do?

Easy
212

A company uses Microsoft Entra ID (Microsoft Entra ID) Premium P2. They need to automatically block sign-ins from anonymous IP addresses (e.g., Tor) and force users from risky sign-ins to reset their password. They want to minimize administrative effort and use built-in features. Which Microsoft Entra ID feature should they enable?

Medium
213

Your company is deploying a new application on Azure Kubernetes Service (AKS). You need to monitor the health and performance of the cluster, including container logs, metrics, and request rates. Which Azure service should you enable?

Easy
214

Your company has an Azure subscription with 100 virtual machines. You need to monitor the performance of these VMs and be alerted when the average CPU usage across a set of VMs exceeds 80% for 10 minutes. The set of VMs is defined by a tag (Environment=Production). Which Azure Monitor solution should you implement?

Hard
215

A company must prevent non-compliant devices from accessing Exchange Online and SharePoint Online. Which design should you recommend?

Medium
216

Your company uses Microsoft Entra ID for identity management. You need to ensure that only devices compliant with your company's security policies can access corporate resources. Which solution should you implement?

Easy
217

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to grant external partners access to an internal application for a limited time (30 days). The access request must be approved by a manager from the partner's organization, and after 30 days the access must automatically expire. They also want to send email reminders 7 days before expiration. Which Microsoft Entra ID feature should they use?

Medium
218

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to require multi-factor authentication (MFA) for all users accessing the Azure portal, but do not want MFA to be required for other applications like Office 365. Which Microsoft Entra ID feature should they configure?

Easy
219

Refer to the exhibit. You are implementing an Azure Policy to control VM SKU deployment. You assign this policy to a subscription. A developer attempts to deploy a virtual machine with SKU Standard_DS2_v2. What is the outcome?

Hard
220

A company uses Microsoft Entra ID. They want to require users to use multi-factor authentication when accessing the Azure portal from any device. They do not want to require MFA for other applications. Which Microsoft Entra ID feature should they configure?

Easy
221

Which TWO are valid methods to authenticate users in a Microsoft Entra ID hybrid identity solution? (Select TWO.)

Easy
222

Your company plans to deploy a new application to Azure. The application will be used by external partners. You need to design an identity solution that allows partners to authenticate using their own corporate credentials while ensuring that the application can enforce conditional access policies based on partner device compliance. What should you include in the design?

Medium

Frequently asked questions

What does the Design identity, governance, and monitoring solutions domain cover on the AZ-305 exam?
Be able to map a stated requirement to the correct Entra ID, Azure Policy, RBAC, or Azure Monitor construct and choose the right scope. The single most important thing: distinguish governance controls that restrict configuration (Azure Policy) from those that restrict identities and access (RBAC, Conditional Access).
How many questions are in this domain?
This page lists all 222 Design identity, governance, and monitoring solutions questions in the AZ-305 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Design identity, governance, and monitoring solutions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
az-305 AZ-305 identity governance monitoring Practice Questions