Courseiva

CCNA Design identity, governance, and monitoring solutions Questions

75 of 222 questions · Page 2/3 · Design identity, governance, and monitoring solutions · Answers revealed

76
MCQhard

Refer to the exhibit. You deploy this ARM template to create an Azure Monitor Workbook. The template deploys successfully. What will the workbook display?

A.CPU utilization averaged over 1-hour intervals.
B.CPU utilization averaged over 5-minute intervals.
C.Memory utilization over time.
D.Disk I/O utilization over time.
AnswerB

This is correct because the query references the Processor object with counter '% Processor Time' and then uses summarize avg(CounterValue) by bin(TimeGenerated, 5m). The average of that counter over each 5-minute window is exactly CPU utilization averaged over 5-minute intervals, and the render timechart visualizes those averages over time. No other object or counter is selected.

Why this answer

The ARM template configures an Azure Monitor Workbook to query the `InsightsMetrics` table for the `cpu_usage_percentage` metric, which is collected by Azure Monitor Agent (AMA) at a default granularity of 1 minute. The workbook uses the `avg` aggregation and a time grain of `5m` (5 minutes) in the query, so it displays CPU utilization averaged over 5-minute intervals. The `summarize` operator with `bin(TimeGenerated, 5m)` explicitly groups data into 5-minute buckets, making option B correct.

Exam trap

The trap here is that candidates assume the default collection interval (1 minute) determines the display granularity, but the `bin()` function in the KQL query explicitly overrides that to 5-minute averages, making option B correct instead of a 1-hour or raw interval.

How to eliminate wrong answers

Option A is wrong because the query uses `bin(TimeGenerated, 5m)` to aggregate data into 5-minute intervals, not 1-hour intervals; a 1-hour interval would require `bin(TimeGenerated, 1h)`. Option C is wrong because the query filters for `cpu_usage_percentage` (CPU metric), not memory utilization; memory would require a metric like `memory_available_bytes` or `memory_percentage`. Option D is wrong because the query targets CPU utilization, not disk I/O; disk I/O would involve metrics such as `disk_read_bytes_per_second` or `disk_write_operations_per_second`.

77
MCQmedium

Your organization uses Microsoft Entra ID. You need to allow external users to sign in using their own identity providers (e.g., Google, Facebook) to access a custom application. What should you configure?

A.Microsoft Entra Connect
B.Microsoft Entra External ID
C.Microsoft Entra B2B collaboration
D.Microsoft Entra ID (tenant)
AnswerB

Microsoft Entra External ID, formerly Azure AD B2C, is a customer identity and access management (CIAM) service specifically built to handle external user authentication. It natively integrates with social identity providers like Google, Facebook, Apple, and Microsoft accounts via OIDC/OAuth2 protocols, and offers configurable user flows for registration, sign-in, and profile management. This makes it the correct solution when the requirement is to allow external identities to authenticate through social IdPs.

Why this answer

Microsoft Entra External ID (formerly Azure AD External Identities) is the correct solution because it is specifically designed to allow external users to authenticate using their own social identity providers (e.g., Google, Facebook) via OAuth 2.0 and OpenID Connect protocols. This configuration enables a custom application to accept sign-ins from these external identities without requiring them to have a Microsoft Entra ID account, using a dedicated external tenant or identity experience.

Exam trap

The trap here is that candidates often confuse Microsoft Entra B2B collaboration (which is for business-to-business guest access using work/school accounts) with Microsoft Entra External ID (which is for consumer-facing social identity providers), leading them to incorrectly select B2B collaboration.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Connect is used for hybrid identity synchronization between on-premises Active Directory and Microsoft Entra ID, not for enabling external social identity providers. Option C is wrong because Microsoft Entra B2B collaboration allows external users to access your organization's resources using their own work or school accounts (e.g., another Microsoft Entra tenant), but it does not natively support social identity providers like Google or Facebook for custom applications. Option D is wrong because a standard Microsoft Entra ID (tenant) alone does not provide the built-in identity provider federation for social logins; it requires the External ID configuration to add those social identity providers.

78
MCQmedium

Your company uses Microsoft Sentinel for security monitoring. You need to design a solution to detect when a user account is created in Microsoft Entra ID with Global Administrator privileges. When detected, an incident must be created in Sentinel and the account should be disabled temporarily until reviewed. You want to use built-in capabilities where possible. What should you do?

A.Use Microsoft Entra Privileged Identity Management to require approval for role activation, and audit logs to detect permanent assignments.
B.Use Microsoft Defender for Cloud Apps to monitor for privileged role assignments and send an alert to Sentinel.
C.Use a Microsoft Sentinel analytics rule template for 'Suspicious Entra ID role assignment' and configure a playbook to disable the account via Microsoft Graph API.
D.Create a custom KQL query in Log Analytics and schedule it as a Sentinel analytics rule, then use an Azure Function to disable the account.
AnswerC

The Sentinel analytics rule template 'Suspicious Entra ID role assignment' is purpose-built to detect privileged role assignments that match known attack patterns, such as a new administrator added to a highly privileged role outside normal activation times. Because it natively surfaces the event as an incident, you can attach an automated playbook that invokes Microsoft Graph API to disable the compromised account immediately. This combination provides detection, correlation, and automated response exactly as required.

Why this answer

It uses a built-in Sentinel analytics rule template specifically designed to detect suspicious Entra ID role assignments, which meets the requirement for built-in capabilities. The playbook, triggered by the rule, can use the Microsoft Graph API to disable the account temporarily, providing automated remediation without custom code or external services.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing custom KQL queries or external services (like Defender for Cloud Apps) when a built-in analytics rule template and playbook are available and sufficient for the detection and automated response.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) requires approval for role activation but does not detect permanent assignments or create Sentinel incidents; it focuses on just-in-time access, not post-creation detection. Option B is wrong because Microsoft Defender for Cloud Apps can monitor for privileged role assignments but is not a built-in Sentinel capability for creating incidents directly; it would require additional configuration to forward alerts to Sentinel, and it does not natively disable accounts. Option D is wrong because creating a custom KQL query and using an Azure Function introduces unnecessary custom development and complexity, whereas built-in analytics rule templates and playbooks are available and preferred for this scenario.

79
Multi-Selectmedium

Your company is planning to use Azure Monitor Workbooks to create custom dashboards for IT operations. You need to select the data sources that can be used in a workbook. Which TWO data sources are supported? (Choose two.)

Select 2 answers
A.Azure Resource Graph
B.Azure SQL Database
C.Microsoft Sentinel
D.Log Analytics workspace
E.Azure Blob Storage
AnswersA, D

Azure Resource Graph is a fully supported data source in Azure Monitor workbooks. Workbooks include a dedicated query control that natively targets Azure Resource Graph (ARG), enabling you to run KQL-based resource exploration queries across subscriptions, management groups, and resource types. Because ARG provides a live, inventory-level view of Azure resources rather than logs or metrics, it is the correct choice when the workbook’s goal is to visualize resource properties, tags, or compliance-related metadata. This direct integration differentiates ARG from stores like SQL Database or Blob Storage, which require an intermediate log-ingestion step.

Why this answer

Azure Monitor Workbooks support Azure Resource Graph as a data source, allowing you to query Azure resources and their properties across subscriptions. This enables rich, resource-centric visualizations in custom dashboards without needing to export data to a separate store.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel as a separate data source, when in reality it relies on Log Analytics workspaces, and they may incorrectly assume Azure SQL Database or Blob Storage are directly queryable by workbooks.

80
MCQhard

You are reviewing a custom RBAC role in Azure. The exhibit shows the role definition. A user with this role reports they cannot read diagnostic settings for a storage account in the Production resource group. What is the most likely cause?

A.The role does not include 'Microsoft.Storage/storageAccounts/read'
B.Custom roles cannot be assigned to users
C.The role lacks the 'Microsoft.Storage/storageAccounts/listKeys/action' permission
D.The role is assigned at the wrong scope
AnswerA

Although the custom role grants Microsoft.Storage/storageAccounts/listKeys/action and possibly other storage permissions, it omits the control-plane action Microsoft.Storage/storageAccounts/read. Azure Resource Manager relies on that read action to list and enumerate storage accounts, and the portal uses it to populate the Storage accounts view. Without it, a user cannot discover storage accounts or navigate to them, because even a known resource ID only works if the caller has the read action on that resource; the role is therefore functionally incomplete.

Why this answer

The user cannot read diagnostic settings because the custom role lacks the 'Microsoft.Storage/storageAccounts/read' permission. This permission is required to read the storage account resource itself, which is a prerequisite for accessing its diagnostic settings. Without it, the role cannot perform any read operations on the storage account, including reading diagnostic logs or metrics configuration.

Exam trap

The trap here is that candidates may confuse data plane permissions (like listKeys) with control plane permissions (like read), or assume that diagnostic settings can be read independently of the parent resource's read permission.

How to eliminate wrong answers

Option B is wrong because custom roles can be assigned to users, groups, or service principals just like built-in roles; the limitation is that custom roles must be defined in the same tenant. Option C is wrong because 'listKeys/action' is used to retrieve storage account access keys for data plane operations, not for reading diagnostic settings, which is a control plane operation. Option D is wrong because even if the role is assigned at the wrong scope, the core issue is the missing 'read' permission; assigning at the correct scope would still fail without the required permission.

81
MCQhard

A large enterprise has a management group hierarchy with 50 subscriptions. They need to enforce that every resource group must have a 'CostCenter' tag and that any new resource group without that tag is automatically denied creation. Additionally, they need to ensure that only the Finance team can modify tags on any resource. They also want to generate monthly compliance reports showing which resources are non-compliant. Which combination of Azure services should they use?

A.Azure Policy for tag enforcement, Azure RBAC for scoping tag modification to Finance, and Azure Policy for compliance reporting
B.Azure Blueprints with tag policy and Azure RBAC, and Azure Security Center for compliance
C.Azure Policy for tag enforcement, Azure Management Groups for governance, and Azure Monitor for compliance reports
D.Azure Policy for tag enforcement, Azure RBAC for tag modification, and Azure Security Center for compliance
AnswerA

The correct combination uses Azure Policy to assign a tag requirement at the root or intermediate management group, so the Deny or Modify effects apply consistently across every subscription and the Policy compliance dashboard gives finance stakeholders a continuously updated report of noncompliant resources. Azure RBAC then grants the Finance team the Tag Contributor built-in role at the necessary scope, letting them edit tag keys and values without broader write access. Because compliance reporting is generated from the same Azure Policy assignments, no separate monitoring or security tool is needed. This is the only option that both enforces the policy and correctly identifies the reporting service.

Why this answer

Azure Policy can enforce the 'CostCenter' tag on resource groups via a 'deny' effect policy, Azure RBAC can restrict tag modification to the Finance team by assigning the 'Tag Contributor' role at the appropriate scope, and Azure Policy's compliance reporting (via the Azure Policy Compliance dashboard or export to Log Analytics) provides monthly reports on non-compliant resources without needing additional services.

Exam trap

The trap here is that candidates confuse Azure Security Center (for security compliance) with Azure Policy (for governance compliance), or assume Azure Monitor can generate compliance reports when it is designed for metrics and logs, not policy evaluation.

How to eliminate wrong answers

Option B is wrong because Azure Blueprints are for deploying consistent environments (including policies), but they do not provide ongoing compliance reporting; Azure Security Center (now Microsoft Defender for Cloud) focuses on security posture, not tag compliance. Option C is wrong because Azure Management Groups are for organizing subscriptions and applying policies, not for governance enforcement itself, and Azure Monitor is for telemetry and alerts, not for generating compliance reports on tags. Option D is wrong because Azure Security Center is not designed for tag compliance reporting; it handles security recommendations and vulnerabilities, not resource metadata compliance.

82
Matchingmedium

Match each Azure compute service to its characteristic.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

IaaS with full control over OS and apps

PaaS for web apps, APIs, and mobile backends

Managed Kubernetes for container orchestration

Serverless compute for event-driven code

Simple, fast container deployment without orchestration

Why these pairings

Azure compute services range from IaaS (Virtual Machines) to PaaS (App Service) to serverless (Azure Functions) and container orchestration (AKS). Distractors confuse definitions of serverless and container orchestration, or PaaS and managed Kubernetes.

83
MCQeasy

Your organization is moving to a cloud-only identity model using Microsoft Entra ID. You need to ensure that users can reset their own passwords without help desk intervention. The solution must support multi-factor authentication and notify administrators of password resets. What should you implement?

A.Microsoft Entra Connect Password Writeback
B.Conditional Access policies for password change
C.Microsoft Entra Self-Service Password Reset (SSPR)
D.Microsoft Entra ID Protection
AnswerC

Microsoft Entra Self-Service Password Reset (SSPR) lets users reset or unlock their own passwords through the Microsoft Entra portal using pre-registered authentication methods, satisfying the self-service requirement. It supports multi-factor authentication by requiring verification via methods such as mobile app or SMS before allowing a reset, and administrators can configure email notifications whenever a reset occurs. SSPR works natively in a cloud-only identity model and aligns with all constraints in the scenario.

Why this answer

Microsoft Entra Self-Service Password Reset (SSPR) allows users to reset their own passwords without help desk intervention. It supports multi-factor authentication (MFA) as a verification step before resetting, and can be configured to send notifications to administrators when a password reset occurs. This directly meets all stated requirements.

Exam trap

The trap here is that candidates often confuse password writeback (a prerequisite for hybrid environments) with the actual self-service reset feature, or they mistake Conditional Access policies (which enforce MFA during sign-in) for the self-service reset process itself.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Connect Password Writeback is a feature that enables password changes from the cloud to be written back to an on-premises Active Directory; it is not a self-service reset solution and does not by itself provide MFA or admin notifications. Option B is wrong because Conditional Access policies for password change control the conditions under which a password change is allowed (e.g., requiring MFA during sign-in), but they do not provide a self-service reset portal or admin notification for password resets. Option D is wrong because Microsoft Entra ID Protection is a risk-based security service that detects and responds to identity risks (e.g., leaked credentials, anomalous sign-ins); it does not provide a self-service password reset capability.

84
MCQeasy

Refer to the exhibit. You are deploying an ARM template that assigns a policy to audit virtual machines not using managed disks. After deployment, you need to verify that the policy assignment is working. Which Azure CLI command should you run?

A.az policy assignment list --subscription 12345678-1234-1234-1234-123456789abc
B.az policy state list --resource-group myResourceGroup
C.az policy definition list --subscription 12345678-1234-1234-1234-123456789abc
D.az policy event list --subscription 12345678-1234-1234-1234-123456789abc
AnswerA

The az policy assignment list command enumerates policy assignments at the specified subscription scope, and because the ARM template was deployed at that scope, the newly created assignment object appears as an entry in the output. It returns each assignment’s name, ID, scope, associated definition, and parameters, allowing you to verify that the deployment actually registered the assignment. This is the only option that directly queries the assignment resource rather than definitions or derived evaluation records.

Why this answer

The `az policy assignment list` command retrieves all policy assignments in the specified subscription, including the one deployed via the ARM template. This allows you to confirm that the policy assignment exists and is properly configured. To verify that the policy is actually evaluating resources and producing compliance states, you would then use `az policy state list` to see the compliance results, but the question specifically asks to verify that the assignment itself is working, which is done by listing assignments.

Exam trap

The trap here is that candidates confuse the command for listing policy assignments with the command for viewing compliance states, leading them to choose `az policy state list` (Option B) instead of `az policy assignment list` (Option A) when the question asks to verify that the assignment itself is working.

How to eliminate wrong answers

Option B is wrong because `az policy state list` shows the current compliance states of resources against a policy, not the existence or configuration of the policy assignment itself. Option C is wrong because `az policy definition list` retrieves the built-in or custom policy definitions, not the assignments of those definitions to a scope. Option D is wrong because `az policy event list` is not a valid Azure CLI command; the correct command for viewing policy events is `az policy state list` with the `--filter` parameter, and events are not used for verifying assignment existence.

85
MCQeasy

A company uses Microsoft Entra ID. They want to automatically detect sign-ins from anonymous IP addresses, sign-ins from unfamiliar locations, and other risky activities. When such a risk is detected, they want to block the sign-in or require multi-factor authentication. They also need a dashboard to review risk events. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Conditional Access
B.Microsoft Entra ID Identity Protection
C.Microsoft Entra ID Privileged Identity Management (PIM)
D.Microsoft Entra ID Access Reviews
AnswerB

Identity Protection detects anonymous IP sign-ins, unfamiliar locations and other risky activities, then applies risk-based policies to block sign-ins or require multi-factor authentication. Its dashboard surfaces detected risk events, satisfying every stated requirement within Microsoft Entra ID.

Why this answer

Microsoft Entra ID Identity Protection is the correct feature because it is specifically designed to detect and respond to identity-based risks such as sign-ins from anonymous IP addresses, unfamiliar locations, and other risky activities. It provides a risk-based conditional access policy that can automatically block sign-ins or require multi-factor authentication (MFA) when a risk is detected, and it includes a dashboard for reviewing risk events and reports.

Exam trap

The trap here is that candidates often confuse Conditional Access (which enforces policies) with Identity Protection (which provides the risk detection signals), leading them to select Conditional Access as the answer when the question explicitly asks for the feature that detects risks and provides a dashboard.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Conditional Access is a policy engine that enforces access controls based on conditions (e.g., location, device state), but it does not itself detect risky sign-ins or provide a risk dashboard; it relies on Identity Protection to supply risk signals. Option C is wrong because Privileged Identity Management (PIM) focuses on just-in-time privileged role activation, approval workflows, and access reviews for administrative roles, not on detecting anonymous IP addresses or unfamiliar location sign-ins. Option D is wrong because Access Reviews are used for periodic recertification of group memberships or application access, not for real-time risk detection or automated blocking of risky sign-ins.

86
Matchingmedium

Match each Azure migration tool to its use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Centralized hub for discovery, assessment, and migration

Migrate databases to Azure with minimal downtime

Physical device for offline data transfer

Replicate and migrate on-premises VMs to Azure

Ship hard drives to transfer large data volumes

Why these pairings

Azure Migrate is for server assessment/migration, Azure Site Recovery for disaster recovery, and Azure Database Migration Service for database migrations. Common confusions involve swapping these use cases.

87
MCQhard

Refer to the exhibit. A user reports they cannot access a secret in the vault 'vault-prod'. The user has a Contributor role at the subscription scope and a Key Vault Secrets User role at the specific vault scope. What is the most likely reason for the failure?

A.The user does not have write permissions on the vault.
B.The vault uses access policies instead of RBAC for authorization.
C.The Key Vault Secrets User role does not allow reading secrets.
D.The scope of the Key Vault Secrets User role is incorrect.
AnswerB

Key Vault can authorize data-plane access either through the older vault access policy model or through Azure RBAC, and the two are mutually exclusive for a given vault. When the vault is set to use access policies, Azure RBAC role assignments such as Key Vault Secrets User are not evaluated at all by the data plane, so the user will be denied even though the role appears correct. The fix is to switch the vault's access configuration to Azure RBAC, or more directly, add the user to the vault's access policy with Get and List permissions on secrets.

Why this answer

The user has the Key Vault Secrets User role at the vault scope, which grants read permissions to secrets via Azure RBAC. However, if the vault is configured to use access policies instead of RBAC for authorization, the RBAC role assignment is ignored. In that case, the user must be granted explicit permissions through the vault's access policy to read secrets.

The Contributor role at subscription scope does not include data plane permissions for Key Vault secrets.

Exam trap

The trap here is that candidates assume RBAC roles always apply to Key Vault data plane operations, forgetting that the vault's authorization model must be set to RBAC for those roles to take effect; otherwise, access policies override them.

How to eliminate wrong answers

Option A is wrong because the issue is about reading a secret, not writing; the user has the Key Vault Secrets User role which includes read permissions, so write permissions are irrelevant. Option C is wrong because the Key Vault Secrets User role specifically allows reading secrets (Microsoft.KeyVault/vaults/secrets/read). Option D is wrong because the role is assigned at the specific vault scope, which is correct for granting permissions to that vault.

88
MCQhard

Your company has multiple Azure subscriptions managed by different teams. You need to design a governance solution that ensures: 1) All subscriptions must have a consistent set of policies (e.g., allowed locations, allowed VM SKUs). 2) Compliance reports must be generated daily for each subscription. 3) Non-compliant resources must be automatically remediated where possible (e.g., add tags). 4) The solution must use a single management group hierarchy. What should you include in the design?

A.Create a management group hierarchy, assign Azure Policy at the root management group level with both 'audit' and 'deployIfNotExists' effects, and use a daily Logic App to query compliance via Azure Resource Graph and send reports.
B.Create a management group hierarchy and use Azure Blueprints to assign policies and role assignments per subscription.
C.Use Azure DevOps to deploy a pipeline that runs PowerShell scripts to enforce policies and generate reports.
D.Create a custom Azure Policy initiative with all required policies and assign it to each subscription individually.
AnswerA

Assigning Azure Policy at the root management group scopes the policy to all nested subscriptions, ensuring uniform governance across the entire tenant. Using both audit and deployIfNotExists effects allows you to first assess non-compliant resources and then automatically trigger remediation tasks to fix them without manual intervention. A daily Logic App calling Azure Resource Graph to query compliance aggregates results across subscriptions and can automatically email a report, providing a scalable, native reporting mechanism.

Why this answer

Assigning Azure Policy at the root management group level ensures consistent policy enforcement across all subscriptions in the hierarchy. The 'deployIfNotExists' effect enables automatic remediation (e.g., adding missing tags), while a daily Logic App querying Azure Resource Graph can generate compliance reports without manual intervention. This design satisfies all requirements with a single management group hierarchy.

Exam trap

The trap here is that candidates may assume Azure Blueprints (Option B) are required for consistent governance, but Blueprints are for initial environment setup, not ongoing policy enforcement and automatic remediation, which is the core of this question.

How to eliminate wrong answers

Option B is wrong because Azure Blueprints assign policies per subscription or management group, but they do not provide built-in automatic remediation or daily compliance reporting; they are primarily for environment composition, not ongoing governance. Option C is wrong because using Azure DevOps with PowerShell scripts is a custom, non-native approach that lacks the automatic remediation capabilities of Azure Policy's 'deployIfNotExists' effect and requires manual pipeline maintenance. Option D is wrong because assigning a custom initiative to each subscription individually violates the requirement to use a single management group hierarchy and creates administrative overhead, failing to enforce consistency at the root level.

89
MCQeasy

A company uses Microsoft Entra ID and wants to allow users to sign in using their existing personal Microsoft accounts, Google, and Facebook identities. They also need custom sign-up and sign-in flows with collection of specific user attributes. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID B2B
B.Microsoft Entra ID B2C
C.Microsoft Entra ID Identity Protection
D.Microsoft Entra ID Conditional Access
AnswerB

Microsoft Entra ID B2C is the correct solution because it is a Customer Identity and Access Management (CIAM) service built specifically to handle consumer identities at scale. It natively supports multiple identity providers, including Microsoft, Google, and Facebook, and provides self-service sign-up/sign-in user flows. With the Identity Experience Framework, you can define custom policies that collect custom attributes, perform API-based validation, and create fully branded, tailored registration journeys for customers, which is exactly what this company needs.

Why this answer

Microsoft Entra ID B2C (Business-to-Consumer) is the correct choice because it is specifically designed to support external identity providers like personal Microsoft accounts, Google, and Facebook, and it provides a customizable policy framework (user flows) for sign-up and sign-in that can collect custom user attributes. Unlike B2B, which focuses on business partner collaboration, B2C allows you to define attribute collection during registration via built-in or custom policies.

Exam trap

The trap here is that candidates often confuse Entra ID B2B with B2C, assuming B2B can handle consumer identities and custom sign-up flows, but B2B is strictly for business partner collaboration and lacks the user flow customization and social identity provider support that B2C provides.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID B2B is intended for business-to-business collaboration, allowing external users from partner organizations to access your apps using their work or school accounts, not personal Microsoft accounts, Google, or Facebook identities, and it does not support custom sign-up flows with attribute collection. Option C is wrong because Microsoft Entra ID Identity Protection is a security feature that detects and responds to identity-based risks (e.g., leaked credentials, sign-in anomalies) and does not provide federation with external identity providers or custom sign-up flows. Option D is wrong because Microsoft Entra ID Conditional Access is a policy engine that enforces access controls (e.g., MFA, device compliance) based on conditions like user, location, or risk, but it cannot configure external identity providers or custom sign-up/attribute collection.

90
Multi-Selectmedium

Which THREE Azure services can be used to monitor the performance of a web application? (Choose three.)

Select 3 answers
A.Azure Policy
B.Application Insights
C.Azure Monitor Metrics
D.Microsoft Defender for Cloud
E.Azure Monitor Logs
AnswersB, C, E

Application Insights collects request rates, response times, dependency calls and failures through the SDK or auto-instrumentation, providing end-to-end telemetry for a web application. It satisfies the monitoring requirement by surfacing performance and availability data at the application layer.

Why this answer

Application Insights (B) is correct because it is the APM feature of Azure Monitor that automatically collects request rates, response times, failure rates, dependency calls, and server/client performance telemetry for web applications. Azure Monitor Metrics (C) is correct because it stores numeric time-series performance data such as CPU percentage, memory usage, request counts, and response times that can be charted and alerted on. Azure Monitor Logs (E) is correct because Log Analytics workspaces collect and query detailed telemetry (e.g., via KQL over AppRequests, Perf, and AppTraces tables) to analyze web app performance and trends.

Azure Policy (A) is incorrect because it enforces governance and compliance rules on resources rather than monitoring runtime performance. Microsoft Defender for Cloud (D) is incorrect because it provides security posture management and threat protection, not application performance monitoring.

Exam trap

The trap here is that candidates often confuse governance tools like Azure Policy or security tools like Defender for Cloud with performance monitoring, but the exam specifically tests the distinction between monitoring (Application Insights, Metrics, Logs) and management/security services.

91
MCQmedium

Your company uses Microsoft Entra ID and has a custom application that requires users to have specific roles assigned. You need to ensure that role assignments are reviewed quarterly and automatically remove assignments that are not approved. Which feature should you use?

A.Microsoft Entra Privileged Identity Management
B.Microsoft Entra Identity Protection
C.Microsoft Entra ID Governance access reviews
D.Microsoft Entra Conditional Access
AnswerC

Microsoft Entra ID Governance access reviews is the correct answer because it is specifically designed for periodic, auditable re-certification of access. Administrators can create a review campaign targeting a single role or multiple role assignments, delegate reviewers (such as department managers or resource owners), and configure scheduled recurrence for the review. Reviewers approve or deny an assignment, and the system can enforce the decision by automatically removing a denied user's role at the end of the review period. This directly supports the requirement to periodically review role assignments and automatically remove users who no longer need access, which is the hallmark of identity governance and least-privilege management.

Why this answer

Microsoft Entra ID Governance access reviews enable you to create recurring reviews of role assignments, with automatic removal of assignments that reviewers do not approve. This directly meets the requirement for quarterly reviews and automatic removal of unapproved assignments, making it the correct choice.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with access reviews, but PIM handles just-in-time activation and approval, not recurring reviews with automatic removal of unapproved assignments.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Privileged Identity Management (PIM) provides just-in-time role activation and approval workflows for privileged roles, but it does not natively support recurring access reviews with automatic removal of unapproved assignments. Option B is wrong because Microsoft Entra Identity Protection focuses on detecting and remediating identity-based risks (e.g., compromised credentials, sign-in anomalies) and does not manage role assignment reviews or removals. Option D is wrong because Microsoft Entra Conditional Access enforces access policies based on conditions like location or device state, but it does not provide periodic review or automatic removal of role assignments.

92
MCQmedium

You are designing a governance strategy for Azure resources. The company has multiple departments, each requiring separate cost tracking and policy enforcement. You need to organize resources to align with the departments while minimizing management overhead. What should you use?

A.Management groups
B.Azure Blueprints
C.Resource tags
D.Resource groups
AnswerA

Management groups provide a hierarchical governance structure above subscriptions, allowing you to apply Azure Policy and RBAC assignments at scale, and aggregate cost data across multiple subscriptions for consolidated billing and compliance. They enable enterprise-level organization of your Azure estate, with policies and governance inherited down through child management groups and subscriptions.

Why this answer

Management groups are the correct choice because they allow you to organize Azure subscriptions into a hierarchy that aligns with your organizational structure, enabling you to apply Azure Policy and cost management controls at scale across multiple departments. By placing each department's subscriptions into separate management groups, you can enforce department-specific policies and track costs without managing each subscription individually, minimizing administrative overhead.

Exam trap

The trap here is that candidates often confuse resource tags with a governance mechanism for policy enforcement and cost tracking, but tags are only metadata and cannot enforce policies or aggregate costs across subscriptions like management groups can.

How to eliminate wrong answers

Option B (Azure Blueprints) is wrong because Blueprints are used to define a repeatable set of Azure resources and policies for deploying compliant environments, not for organizing existing resources or subscriptions for cost tracking and policy enforcement across departments. Option C (Resource tags) is wrong because tags are metadata key-value pairs applied to resources for filtering and reporting, but they do not provide hierarchical policy enforcement or cost aggregation at the subscription or management group level. Option D (Resource groups) is wrong because resource groups are logical containers for resources within a single subscription, and they cannot span subscriptions or provide the cross-subscription policy and cost management needed for multiple departments.

93
MCQmedium

Refer to the exhibit. You are deploying NSG flow logs. After deployment, you notice that no logs are being written to the storage account. What is the most likely cause?

A.Network Watcher is not enabled in the region.
B.Retention policy is set to 0 days.
C.The storage account is in a different subscription.
D.The format version is incorrect.
AnswerA

NSG flow logs are implemented as a child resource of Network Watcher, so the Network Watcher provider must be registered and the regional Network Watcher instance must exist in the exact Azure region where the NSG resides. Without an active Network Watcher in that region, any attempt to enable flow logs fails with a provisioning error. This is the definitive root cause in this scenario.

Why this answer

NSG flow logs require Network Watcher to be enabled in the region where the NSG resides. If Network Watcher is not enabled, the flow logs cannot be written to the storage account because the logging pipeline depends on the Network Watcher agent to capture and forward flow data. Enabling Network Watcher in the region resolves this issue.

Exam trap

The trap here is that candidates often assume the retention policy (0 days) or storage account subscription mismatch is the root cause, but the actual issue is the missing regional Network Watcher dependency, which is a prerequisite for NSG flow logs to function.

How to eliminate wrong answers

Option B is wrong because a retention policy of 0 days means logs are deleted immediately after being written, but logs would still be written to the storage account initially. Option C is wrong because NSG flow logs support writing to a storage account in a different subscription as long as the appropriate RBAC permissions are configured. Option D is wrong because the format version (e.g., version 1 or 2) affects the schema of the logs but does not prevent logs from being written to the storage account.

94
MCQeasy

A company has an Azure subscription with a Log Analytics workspace. They need to ensure that all administrative operations performed on Azure resources are logged and retained for 90 days. The logs must be queryable using Kusto Query Language (KQL). What should you configure?

A.Azure Activity Log with a diagnostic setting to send logs to the Log Analytics workspace.
B.Azure Monitor Logs with a data collection rule to collect Windows event logs from all VMs.
C.Microsoft Defender for Cloud with continuous export to the Log Analytics workspace.
D.Azure Monitor metrics with a diagnostic setting to send metrics to the Log Analytics workspace.
AnswerA

Azure Activity Log records administrative operations on resources. By creating a diagnostic setting to forward the Activity Log to a Log Analytics workspace, the logs become queryable using KQL and can be retained for 90 days (or more). This meets the requirement for logging administrative operations and querying them.

Why this answer

The Azure Activity Log captures administrative operations at the subscription level. To retain and query these logs with KQL, you create a diagnostic setting that sends the Activity Log to a Log Analytics workspace. This provides long-term retention and powerful querying capabilities.

Metrics, Defender for Cloud, and VM data collection rules do not capture administrative operations.

Exam trap

The trap here is assuming that Azure Monitor metrics or Defender for Cloud can provide administrative operation logs; they serve different purposes and do not capture control-plane operations.

95
Multi-Selecthard

Your organization has multiple Azure subscriptions and uses Azure Blueprints to enforce governance. You need to design a blueprint that includes role assignments, policy assignments, and resource groups. Which THREE components can be included in an Azure Blueprint? (Choose three.)

Select 3 answers
A.Management group
B.Role assignments
C.Policy assignment
D.Subscription
E.ARM template
AnswersB, C, E

Role assignments in Azure Blueprints are artifacts that specify which Azure RBAC role (e.g., Contributor, Reader, Owner) is granted to a named user, group, or service principal at the blueprint's assigned scope. When the blueprint is assigned, these assignments are created automatically, enabling consistent identity-based access control across multiple subscriptions. For example, a blueprint can assign the 'Security Reader' role to a central security team in every subscription, ensuring uniform visibility without manual configuration.

Why this answer

Azure Blueprints allow you to define a repeatable set of Azure resources that adhere to your organization's standards, patterns, and requirements. Role assignments (B) are a core artifact that can be included to grant specific Azure RBAC roles at the blueprint scope, ensuring consistent access control. Policy assignments (C) are also a native blueprint artifact, enabling you to enforce compliance rules across the environment.

ARM templates (E) can be included as an artifact to deploy infrastructure as code, making them a valid component of a blueprint definition.

Exam trap

The trap here is that candidates often confuse the target scope (management group or subscription) with the artifacts that can be included in the blueprint definition, leading them to incorrectly select management group or subscription as valid blueprint components.

96
MCQeasy

Your company uses Microsoft Entra ID for identity management. You need to ensure that users can access corporate resources without passwords while maintaining a high level of security. Which feature should you implement?

A.Azure AD B2C
B.Conditional Access policies
C.Passwordless authentication
D.Multifactor authentication (MFA)
AnswerC

Passwordless authentication in Microsoft Entra ID lets users sign in without entering a password by using methods like Windows Hello for Business, FIDO2/WebAuthn security keys, or the Microsoft Authenticator app. These methods rely on asymmetric cryptography: the user's device or key securely stores a private key, and the server verifies a signed challenge using the corresponding public key. This eliminates common password attack vectors like phishing, credential stuffing, and password reuse. By replacing the password entirely with biometrics or a hardware-bound credential, it directly achieves the goal of password-free sign-in for internal users.

Why this answer

Passwordless authentication (Option C) is correct because it allows users to access corporate resources without entering a password, using methods like Windows Hello for Business, FIDO2 security keys, or the Microsoft Authenticator app. This eliminates password-related risks (e.g., phishing, credential theft) while maintaining strong security through cryptographic key pairs or biometric verification, aligning with the requirement for both password-free access and high security.

Exam trap

The trap here is that candidates confuse 'passwordless' with 'multifactor authentication' (MFA), assuming MFA alone removes the password requirement, but MFA still requires a password as the first factor unless explicitly combined with a passwordless method.

How to eliminate wrong answers

Option A is wrong because Azure AD B2C is a customer-facing identity service for external users (e.g., social logins), not for internal corporate resource access without passwords. Option B is wrong because Conditional Access policies enforce access controls (e.g., requiring MFA or location checks) but do not eliminate passwords; they still rely on a password as the primary authentication factor unless combined with passwordless methods. Option D is wrong because Multifactor Authentication (MFA) adds a second factor (e.g., SMS, app notification) but still requires a password as the first factor, so it does not achieve passwordless access.

97
MCQhard

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to implement a solution that automatically detects identity-related risks such as leaked credentials, impossible travel, and sign-ins from anonymous IP addresses. They want to generate reports summarizing risk events and integrate the risk data with their existing Security Information and Event Management (SIEM) system via API. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Conditional Access
B.Microsoft Entra ID Identity Protection
C.Microsoft Entra ID Privileged Identity Management (PIM)
D.Microsoft Entra ID Entitlement Management
AnswerB

Microsoft Entra ID Identity Protection is the correct service because it continuously detects a broad range of identity risks—including leaked credentials, impossible travel, unfamiliar sign-in properties, and anomalous user activity—and stores each detection as a rich risk event. It provides detailed risk reports in the portal and, importantly, exposes these risk events through Microsoft Graph API endpoints (e.g., riskDetection and riskyUser), enabling direct integration with a SIEM. This combination of detection, reporting, and API access makes it the only option that meets the stated requirement.

Why this answer

Microsoft Entra ID Identity Protection is the correct feature because it is specifically designed to automatically detect identity-related risks such as leaked credentials, impossible travel, and sign-ins from anonymous IP addresses. It provides risk event reports and integrates with SIEM systems via the Microsoft Graph API, enabling automated risk data export for centralized monitoring.

Exam trap

The trap here is that candidates often confuse Conditional Access (which enforces policies) with Identity Protection (which detects risks), but Conditional Access relies on Identity Protection's risk signals and cannot generate risk events on its own.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Conditional Access is a policy engine that enforces access controls based on signals (e.g., risk level from Identity Protection), but it does not detect or generate risk events itself. Option C is wrong because Privileged Identity Management (PIM) focuses on just-in-time privileged role activation and access reviews, not on detecting identity risks like leaked credentials or impossible travel. Option D is wrong because Entitlement Management handles access packages and lifecycle management for external users and groups, not risk detection or SIEM integration.

98
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to grant specific IT administrators just-in-time (JIT) access to Azure virtual machines for troubleshooting. The access must be time-bound, require approval from a senior manager, and be automatically revoked after the granted time period. The company also needs an audit log of all access requests and assignments. Which Azure service or feature should they use?

A.Azure Bastion
B.Microsoft Entra ID Privileged Identity Management (PIM) for Azure resources
C.Just-in-Time VM access (Microsoft Defender for Cloud)
D.Microsoft Entra ID Application Proxy
AnswerB

Microsoft Entra ID Privileged Identity Management (PIM) for Azure resources is the correct choice because it activates RBAC roles, such as Virtual Machine Administrator Login or Contributor, just-in-time with a configurable maximum duration (typically 1–8 hours). Activation can require justification, multi-factor authentication, and an explicit approval from a designated manager or approver, and the role is automatically deactivated when the time window expires. Every activation and action is logged in the Microsoft Entra audit log, providing a complete and auditable record of who accessed what, when, and for how long.

Why this answer

Microsoft Entra ID Privileged Identity Management (PIM) for Azure resources provides just-in-time (JIT) access with time-bound activation, approval workflows, and automatic revocation. It also includes full audit logging of all requests and assignments, meeting all the specified requirements for granting temporary access to Azure VMs.

Exam trap

The trap here is that candidates confuse Just-in-Time VM access in Microsoft Defender for Cloud (which is network-level JIT) with PIM for Azure resources (which is role-level JIT), but only PIM supports the required approval workflow and audit logging for role assignments.

How to eliminate wrong answers

Option A is wrong because Azure Bastion provides secure RDP/SSH connectivity to VMs over TLS without public IPs, but it does not offer time-bound JIT access, approval workflows, or automatic revocation. Option C is wrong because Just-in-Time VM access in Microsoft Defender for Cloud provides time-bound network-level access (NSG rules) to VMs, but it lacks the built-in approval workflow from a senior manager and does not integrate with Entra ID PIM for role-based access control. Option D is wrong because Microsoft Entra ID Application Proxy enables secure remote access to on-premises web applications via pre-authentication, not to Azure VMs, and it does not provide JIT access, approval workflows, or automatic revocation.

99
MCQeasy

Your company requires that all administrative actions in Azure subscriptions be logged and retained for seven years. Which service should you use to collect and store these logs?

A.Azure Monitor Metrics
B.Azure Resource Health
C.Azure Activity Log
D.Microsoft Entra ID audit logs
AnswerC

The Azure Activity Log is a subscription-level audit log that records every control-plane operation (create, update, delete, and write) on Azure resources, including the actor (who initiated the action), the timestamp, the operation name, and the status. It captures administrative actions such as starting or stopping a virtual machine, modifying a network security group, or assigning a policy, and can be retained for up to 7 years when exported to a storage account or Log Analytics workspace. This makes it the correct source for answering who did what, when, and where in your Azure environment.

Why this answer

The Azure Activity Log (now part of Azure Monitor) records all control-plane operations (create, update, delete) on Azure resources and can be retained for up to seven years by configuring a diagnostic setting to stream the logs to a Log Analytics workspace or Azure Storage. This meets the requirement for logging and long-term retention of administrative actions.

Exam trap

The trap here is that candidates confuse the Azure Activity Log (control-plane) with Microsoft Entra ID audit logs (identity-plane), or mistakenly think Azure Monitor Metrics can store long-term administrative logs instead of numerical performance data.

How to eliminate wrong answers

Option A is wrong because Azure Monitor Metrics stores numerical time-series data (e.g., CPU usage, request counts) with a default retention of 93 days, not administrative action logs for seven years. Option B is wrong because Azure Resource Health provides real-time status of resource availability and service issues, not a historical log of administrative actions. Option D is wrong because Microsoft Entra ID audit logs capture user sign-ins and directory changes, not Azure resource-level administrative actions (control-plane operations).

100
MCQhard

Refer to the exhibit. You are deploying a Log Analytics workspace using an ARM template with the parameters shown. Your compliance team requires that all log data be retained for at least 2 years. Which parameter value should you modify?

A.retentionInDays
B.workspaceName
C.sku
D.dailyQuotaGb
AnswerA

In Azure Log Analytics, retentionInDays is the workspace-level property that determines exactly how many days log data is retained before being purged from the storage layer. The current setting of 365 fails the 2-year requirement, so this value must be set to 730 or higher. This is the only property that directly controls the retention period; no other workspace setting can extend it.

Why this answer

The `retentionInDays` parameter controls how long log data is retained in a Log Analytics workspace. To meet the compliance requirement of at least 2 years (730 days), you must set this value to 730 or higher. The default retention is 30 days for free tiers and up to 730 days for paid tiers, but the parameter must be explicitly modified to enforce the 2-year retention.

Exam trap

The trap here is that candidates often confuse `sku` with retention capabilities, assuming that upgrading the SKU automatically extends retention, when in fact `retentionInDays` is an independent parameter that must be explicitly set to meet compliance requirements.

How to eliminate wrong answers

Option B is wrong because `workspaceName` only defines the name of the Log Analytics workspace and has no impact on data retention policies. Option C is wrong because `sku` determines the pricing tier (e.g., PerGB2018, Standalone) and affects features like ingestion costs and retention limits, but does not directly set the retention period; retention is configured separately via `retentionInDays`. Option D is wrong because `dailyQuotaGb` sets a cap on daily data ingestion to control costs, not the retention duration of stored logs.

101
MCQhard

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to enforce that all users accessing the company's internal application from mobile devices must be compliant with device management policies (e.g., require a PIN and encryption). The application does not support modern authentication. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Conditional Access
B.Microsoft Entra ID Application Proxy
C.Microsoft Entra ID Identity Protection
D.Microsoft Entra ID Privileged Identity Management
AnswerB

Application Proxy is the correct choice because it publishes the legacy on-premises application as an enterprise application in Microsoft Entra ID, adding a modern OAuth/OIDC authentication layer in front of it. Once published, the app becomes visible to Conditional Access, so device compliance requirements can be enforced during pre-authentication. The connector then forwards the authenticated request to the legacy backend using Kerberos or NTLM, preserving the original app's behavior without changing its code.

Why this answer

Microsoft Entra ID Application Proxy is the correct choice because it enables secure remote access to on-premises web applications that do not support modern authentication. By publishing the internal application through Application Proxy, you can enforce device compliance policies (e.g., requiring a PIN and encryption) via Conditional Access policies applied to the Application Proxy service, even though the application itself uses legacy authentication.

Exam trap

The trap here is that candidates often assume Conditional Access alone can enforce device compliance on any application, but they miss the critical requirement that the application must support modern authentication; Application Proxy is the bridge that enables Conditional Access to work with legacy apps.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Conditional Access is a policy engine that enforces access controls, but it cannot directly enforce device compliance on an application that does not support modern authentication; it requires the application to support modern authentication protocols (e.g., OAuth 2.0, OpenID Connect) to evaluate device state. Option C is wrong because Microsoft Entra ID Identity Protection is focused on detecting and responding to identity-based risks (e.g., leaked credentials, anomalous sign-ins), not on enforcing device management policies or enabling legacy app access. Option D is wrong because Microsoft Entra ID Privileged Identity Management is designed for managing, controlling, and monitoring privileged roles and just-in-time access, not for enforcing device compliance or proxying legacy applications.

102
Multi-Selecteasy

Which TWO Microsoft Entra ID editions include Conditional Access? (Choose two.)

Select 2 answers
A.Microsoft Entra ID P1
B.Microsoft Entra ID P2
C.Azure AD Basic (legacy)
D.Microsoft 365 Business Basic
E.Microsoft Entra ID Free
AnswersA, B

Microsoft Entra ID P1 is the entry-level premium edition that licenses the Conditional Access policy engine. It evaluates a rich set of signals—including user identity, group membership, device status, and geographic location—to grant, block, or require multifactor authentication on every authentication request. P1 is available as a standalone SKU or via Microsoft 365 E3/E5 and Enterprise Mobility+Security E3, and it covers most policy-driven conditional access scenarios such as 'require MFA for all users' or 'block legacy authentication protocols.'

Why this answer

Microsoft Entra ID P1 includes Conditional Access, which allows organizations to enforce access policies based on signals like user, location, device, and application. This edition provides the core Conditional Access capabilities needed for most enterprise scenarios, such as requiring multi-factor authentication or blocking access from untrusted locations.

Exam trap

The trap here is that candidates often confuse Microsoft 365 Business Basic (which includes only Azure AD Free) with a higher-tier license that includes Conditional Access, or mistakenly think legacy Azure AD Basic still supports Conditional Access.

103
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to grant temporary administrative roles to users for specific tasks. The process must require approval from a designated approver, and the access must automatically expire after a defined period. The company also needs audit logs of all role assignments and activations. Which Microsoft Entra ID feature should they implement?

A.Microsoft Entra ID Privileged Identity Management (PIM)
B.Microsoft Entra ID Entitlement Management
C.Microsoft Entra ID Identity Protection
D.Microsoft Entra ID Conditional Access
AnswerA

PIM is the correct choice because it provides just-in-time, time-bound administrative role activation (eligible vs. active) for Microsoft Entra ID roles and Azure resources. It supports approval workflows, MFA enforcement on activation, risk-based conditional access policies during activation, automatic expiration, and comprehensive audit logs, making it the dedicated tool for granting temporary privileged access. Unlike the other options, PIM directly addresses role governance and removes the need for standing admin privileges.

Why this answer

Microsoft Entra ID Privileged Identity Management (PIM) is the correct choice because it provides just-in-time (JIT) privileged access, requiring approval from designated approvers and automatically expiring role assignments after a defined duration. PIM also generates detailed audit logs for all role activations and assignments, meeting the compliance and monitoring requirements.

Exam trap

The trap here is confusing Entitlement Management (which handles access packages and reviews) with PIM (which specifically handles privileged role activation and approval workflows), leading candidates to pick Option B for its 'approval' and 'expiration' keywords.

How to eliminate wrong answers

Option B is wrong because Entitlement Management focuses on automating access requests and reviews for groups, apps, and sites, not on granting temporary administrative roles with approval workflows and automatic expiration. Option C is wrong because Identity Protection is designed to detect and remediate identity-based risks (e.g., compromised credentials, sign-in anomalies), not to manage role-based access or approvals. Option D is wrong because Conditional Access enforces policies based on signals (e.g., location, device state) at sign-in, but does not handle role activation, approval workflows, or automatic expiration of administrative roles.

104
MCQmedium

A company uses Microsoft Entra ID. They want to integrate their security operations with a third-party SIEM tool. They need to export all Microsoft Entra ID sign-in logs and audit logs to the SIEM for analysis. The solution should be automated and near real-time. Which Azure service should they configure?

A.Azure Event Hubs
B.Azure Logic Apps
C.Azure Monitor
D.Azure Storage
AnswerA

Microsoft Entra ID diagnostic settings can export audit and sign-in logs directly to an Azure Event Hubs namespace, which acts as a highly scalable, low-latency streaming buffer. SIEM platforms can then consume these events using the Event Hubs Kafka-compatible endpoint, making it the optimal choice for near real-time log streaming.

Why this answer

Azure Event Hubs is the correct service because it provides a high-throughput, low-latency data ingestion platform that can receive streaming diagnostic data from Microsoft Entra ID. By configuring diagnostic settings in Entra ID to stream sign-in and audit logs to an Event Hubs namespace, you enable near real-time export to a third-party SIEM tool via the Event Hubs-compatible endpoint, typically using the AMQP or HTTPS protocol.

Exam trap

The trap here is that candidates often confuse Azure Monitor's log collection capability with real-time streaming, not realizing that Monitor itself cannot natively push logs to external SIEMs without Event Hubs as the intermediary pipeline.

How to eliminate wrong answers

Option B (Azure Logic Apps) is wrong because Logic Apps is an orchestration and workflow service, not a streaming data ingestion platform; it would introduce latency and complexity for continuous, near real-time log export. Option C (Azure Monitor) is wrong because Azure Monitor is a monitoring and alerting service that can collect logs but does not natively stream them to external SIEM tools in near real-time; it relies on Event Hubs as a pipeline for such exports. Option D (Azure Storage) is wrong because Azure Storage is a batch-oriented, blob/table storage service that does not support real-time streaming; logs exported there would require additional processing and polling, breaking the near real-time requirement.

105
MCQeasy

Your company uses Azure Resource Manager templates for infrastructure deployment. You need to ensure that all deployments are validated against organizational policies before resources are provisioned. Which Azure service should you use?

A.Azure RBAC
B.Management Groups
C.Azure Policy
D.Azure Blueprints
AnswerC

Azure Policy evaluates resource properties against organisational rules and blocks non-compliant provisioning, satisfying the requirement that deployments be validated before resources are created. Assigned at management group, subscription or resource group scope, its deny effect prevents policy-violating resources from being deployed at all.

Why this answer

Azure Policy is the correct service because it enforces organizational standards and assesses compliance at scale. It evaluates resources during deployment (via the ARM template deployment process) and can deny non-compliant resources before they are provisioned. Specifically, policies with a 'deny' effect block the deployment if the resource violates the policy, ensuring validation against organizational policies.

This directly meets the requirement to validate deployments before resources are provisioned.

Exam trap

AZ-305 often tests the confusion between Azure Policy and Azure Blueprints, where candidates mistakenly think Blueprints enforces policies, but Blueprints only packages them; the actual validation and enforcement is done by Azure Policy.

How to eliminate wrong answers

Option A is wrong because Azure RBAC (Role-Based Access Control) manages who can perform actions on resources, not what configurations are allowed; it does not validate resource properties against policies. Option B is wrong because Management Groups are containers for organizing subscriptions and applying governance (like Azure Policy) across them, but they do not themselves validate deployments. Option D is wrong because Azure Blueprints is a declarative way to orchestrate deployment of artifacts (including policies, RBAC, templates) but is not the service that performs policy validation; it packages policies but relies on Azure Policy for enforcement.

106
MCQeasy

A company requires all users to use multi-factor authentication (MFA) when accessing cloud applications. However, they want to exempt users from MFA when they connect from the company's headquarters, which has a trusted IP range. They want to enforce this policy centrally. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Conditional Access
B.Microsoft Entra ID Identity Protection
C.Microsoft Entra ID Privileged Identity Management
D.Microsoft Entra ID Self-Service Password Reset
AnswerA

Microsoft Entra ID Conditional Access is the policy service that evaluates sign-in signals—such as user, device, and network location—to decide whether to block access or require additional authentication. To enforce MFA for all users except those connecting from trusted IP ranges, you would create a Conditional Access policy targeting All Users, set the location condition to 'Any location' with 'Exclude trusted IPs,' and configure the grant control 'Require multi-factor authentication.' This directly implements the stated requirement, and the same engine can also integrate risk signals from Identity Protection for layered policies.

Why this answer

Microsoft Entra ID Conditional Access is the correct feature because it allows administrators to create policies that enforce MFA based on conditions such as user location, device state, and application sensitivity. By configuring a Conditional Access policy with a 'trusted location' condition (defined via named locations with specific IP ranges), the company can require MFA for all cloud app access except when users connect from the headquarters' trusted IP range. This provides centralized, granular control over authentication requirements without needing to modify individual user settings.

Exam trap

The trap here is that candidates often confuse Identity Protection (which handles risk-based MFA prompts) with Conditional Access (which handles location-based MFA exemptions), leading them to select Identity Protection because it also deals with MFA, but it lacks the trusted IP range exclusion capability.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID Identity Protection is designed to detect and respond to identity-based risks (e.g., leaked credentials, anonymous IP addresses) and can trigger automated remediation like requiring MFA on risky sign-ins, but it does not natively support exempting users based on trusted IP ranges; its primary focus is risk-based policies, not location-based conditional access. Option C is wrong because Microsoft Entra ID Privileged Identity Management (PIM) manages just-in-time privileged role activation, approval workflows, and access reviews for elevated roles, not general user MFA enforcement or location-based exemptions. Option D is wrong because Microsoft Entra ID Self-Service Password Reset (SSPR) allows users to reset their own passwords without administrator intervention, but it does not enforce or exempt MFA based on network location; it is a password management feature, not an authentication policy engine.

107
Multi-Selecthard

Which THREE capabilities are provided by Microsoft Entra ID Identity Governance? (Select THREE.)

Select 3 answers
A.Entitlement management
B.Access reviews
C.Privileged Identity Management
D.Conditional Access
E.Identity Protection
AnswersA, B, C

Entitlement management is a core identity governance capability in Microsoft Entra ID that operationalizes access lifecycle management through access packages. These packages bundle resources such as groups, apps, and SharePoint sites, and enforce policies for request, approval, and automatic expiration or removal of access. This enables self-service access requests while ensuring that assignments are time-bound and auditable, directly satisfying least-privilege and compliance requirements.

Why this answer

Microsoft Entra ID Identity Governance is a suite of capabilities designed to help organizations manage and govern access to resources. Entitlement management (A) enables the creation of access packages to automate access requests, approvals, and assignments. Access reviews (B) allow periodic recertification of group memberships and application access to ensure only the right users have access.

Privileged Identity Management (C) provides just-in-time privileged access and role activation workflows for Azure AD roles and Azure resources, directly supporting governance of elevated access.

Exam trap

The trap here is that candidates often confuse Conditional Access and Identity Protection (which are security-focused features) with Identity Governance capabilities, but the exam specifically tests that governance includes entitlement management, access reviews, and PIM as the three core pillars.

108
MCQmedium

A company uses Microsoft Entra ID and wants to enforce that all users must use multi-factor authentication (MFA) when accessing sensitive applications. However, they want to exclude users when connecting from the corporate office IP range and only allow access from devices that are compliant with Intune policies. Which Microsoft Entra ID feature should they use to create this policy?

A.Microsoft Entra ID Identity Protection
B.Microsoft Entra ID Privileged Identity Management
C.Microsoft Entra ID Conditional Access
D.Microsoft Entra ID Identity Governance
AnswerC

Conditional Access policies allow you to specify conditions (e.g., IP location, device compliance) and controls (e.g., require MFA, block access). This enables the described scenario: require MFA for sensitive apps, but exclude corporate IP range and require compliant device.

Why this answer

C is correct because Microsoft Entra ID Conditional Access is the feature specifically designed to enforce granular access policies based on conditions such as user, location, device compliance, and application sensitivity. By configuring a Conditional Access policy, you can require MFA for sensitive applications, exclude the corporate office IP range, and restrict access to Intune-compliant devices, all within a single policy.

Exam trap

The trap here is that candidates often confuse Conditional Access with Identity Protection, thinking risk-based policies can enforce location or device compliance, but Identity Protection only triggers actions based on risk scores, not static conditions like IP ranges or Intune compliance.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Identity Protection focuses on detecting and responding to identity-based risks (e.g., leaked credentials, sign-ins from anonymous IPs) and can trigger MFA based on risk level, but it cannot enforce device compliance or exclude specific IP ranges directly. Option B is wrong because Microsoft Entra ID Privileged Identity Management manages just-in-time privileged role activation and access reviews, not general user access policies for sensitive applications. Option D is wrong because Microsoft Entra ID Identity Governance handles access lifecycle, entitlement management, and certification campaigns, not real-time access enforcement based on location or device compliance.

109
Multi-Selecthard

Which THREE of the following are required to collect Windows security events into Microsoft Sentinel?

Select 3 answers
A.Log Analytics workspace
B.Data collection rule (DCR)
C.Azure Policy
D.Azure Monitor Agent (AMA)
E.Microsoft Defender for Cloud
AnswersA, B, D

A Log Analytics workspace is the mandatory ingestion destination for all log data collected by the Azure Monitor Agent. Without a workspace, the agent has no target endpoint to send events to, and there is no table structure to store Windows Event logs or custom logs. The workspace also defines data retention, permissions, and can be used to query collected logs with log analytics queries. Even if a data collection rule is configured, it must point to an existing workspace to actually receive the data.

Why this answer

A Log Analytics workspace is required because Microsoft Sentinel is built on top of it; all security events collected by Sentinel are stored in the workspace's tables, and Sentinel uses the workspace as its data repository for analytics, alerting, and investigation.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a security management service) with a data collection agent, or think Azure Policy can be used to collect logs, when in fact only the combination of a Log Analytics workspace, a DCR, and the AMA fulfills the requirement.

110
MCQeasy

You are designing identity governance for a company that uses Microsoft Entra ID. The company wants to grant external partners access to an internal application for 90 days. After 90 days, access must be automatically removed. Additionally, the application requires that users have multi-factor authentication (MFA) and a compliant device. You need to design a solution that meets these requirements with minimal administrative effort. What should you do?

A.Create an access package in Microsoft Entra entitlement management with a 90-day policy and conditional access policies for MFA and device compliance.
B.Manually create guest user accounts, assign app, and set calendar reminder to delete after 90 days.
C.Create a dynamic group in Microsoft Entra ID that includes partners and assign the app; use a scheduled script to remove membership after 90 days.
D.Use Microsoft Entra Privileged Identity Management to grant just-in-time access for 90 days.
AnswerA

An access package in Microsoft Entra entitlement management is the correct approach because it creates a time-boxed assignment with a 90-day access policy that triggers automatic expiration and can require access reviews. When combined with conditional access policies enforcing MFA and device compliance, it ensures that only compliant, authenticated users can gain access, and because the assignment lifecycle is managed by Entra Identity Governance, it removes the need for manual cleanup. The access package also supports per-assignment expiration that applies to guest and internal users alike.

Why this answer

Microsoft Entra entitlement management allows you to create an access package that automatically grants external partners access to the application for exactly 90 days, after which access is automatically removed via an expiration policy. Additionally, you can enforce multi-factor authentication (MFA) and device compliance by configuring conditional access policies that are applied to the access package, meeting all requirements with minimal administrative effort through automation.

Exam trap

The trap here is that candidates may confuse Privileged Identity Management (PIM) with entitlement management, thinking PIM's time-limited role activation can be applied to application access, but PIM is for Azure AD roles and Azure resource roles, not for granting external user access to applications with conditional access enforcement.

How to eliminate wrong answers

Option B is wrong because manually creating guest accounts and setting a calendar reminder is not automated, requires ongoing administrative effort, and does not enforce MFA or device compliance policies. Option C is wrong because using a dynamic group with a scheduled script to remove membership after 90 days is not a native, automated solution; dynamic groups are based on user attributes, not time-based expiration, and scripting adds complexity and potential failure points. Option D is wrong because Microsoft Entra Privileged Identity Management (PIM) is designed for just-in-time privileged role activation, not for granting time-limited access to applications for external partners, and it does not natively enforce MFA or device compliance for application access.

111
MCQeasy

Your organization uses Microsoft Azure and has a subscription with multiple resource groups. You need to ensure that only users in the Finance department can access storage accounts in the 'Finance' resource group. The solution must use role-based access control (RBAC). What should you assign?

A.Assign the Contributor role to the Finance users at the management group scope
B.Assign the Storage Blob Data Reader role to the Finance users at the Finance resource group scope
C.Assign the Reader role to the Finance users at the subscription scope
D.Assign the Storage Account Contributor role to the Finance users at each storage account scope
AnswerB

Assigning Storage Blob Data Reader at the Finance resource group scope is correct because it grants exactly the data-plane permission needed to read blobs and containers (Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read) across all storage accounts in that group, without allowing write, delete, or management operations. The resource-group scope is also efficient: one assignment covers existing and future storage accounts in Finance, and it is scoped narrowly enough to avoid exposing other subscriptions or resource groups. This is the least-privileged, maintainable approach.

Why this answer

Assigning the Storage Blob Data Reader role at the Finance resource group scope grants Finance users read access to blob data within all storage accounts in that resource group, using RBAC. This meets the requirement of restricting access to only the Finance department while leveraging Azure RBAC's built-in data plane role for storage.

Exam trap

The trap here is that candidates often confuse management plane roles (like Contributor or Storage Account Contributor) with data plane roles (like Storage Blob Data Reader), mistakenly thinking Contributor grants data access, when in fact it only grants management access unless combined with a data plane role.

How to eliminate wrong answers

Option A is wrong because assigning the Contributor role at the management group scope would grant full management access to all resources across multiple subscriptions, far exceeding the requirement to restrict access to only storage accounts in the Finance resource group. Option C is wrong because the Reader role at the subscription scope provides read-only access to all resources in the subscription, including non-Finance resource groups, violating the principle of least privilege. Option D is wrong because assigning the Storage Account Contributor role at each storage account scope grants management access to the storage account itself (e.g., configuration, networking) but not necessarily data access (e.g., blobs), and it requires individual assignments per account, which is less efficient than a single resource group scope assignment.

112
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to automatically review and remove guest accounts that have not signed in for 90 days. They also need to generate reports for auditors. Which Microsoft Entra ID feature should they use?

A.Identity Protection
B.Access Reviews
C.Privileged Identity Management
D.Conditional Access
AnswerB

Microsoft Entra Access Reviews are the intended mechanism for periodic attestation of guest users, because they allow creation of recurring review cycles that can be assigned to tenant admins, guest's manager, or the guest themselves. Reviewers are presented with activity indicators such as last sign-in, and the review policy can automatically apply the result to block or remove any user who is denied or who has been inactive for the configured threshold. This yields an auditable certification process for guest access, satisfying the requirement for scheduled recertification and automated cleanup.

Why this answer

Access Reviews in Microsoft Entra ID allow administrators to create recurring reviews of guest users' access. By configuring a review with a 'days since last sign-in' condition (e.g., 90 days), Entra ID automatically flags and can remove guest accounts that have not authenticated within that period. The review process also generates detailed audit logs and reports suitable for auditor compliance, directly meeting the stated requirements.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with Access Reviews because both involve 'reviewing' access, but PIM is strictly for privileged roles, not for reviewing inactive guest accounts.

How to eliminate wrong answers

Option A is wrong because Identity Protection is designed to detect and respond to identity-based risks (e.g., leaked credentials, anomalous sign-ins) and does not provide scheduled, automated access reviews or removal of inactive guest accounts. Option C is wrong because Privileged Identity Management (PIM) focuses on just-in-time privileged role activation and approval workflows for administrators, not on reviewing or removing standard guest user accounts based on inactivity. Option D is wrong because Conditional Access enforces policies during sign-in (e.g., requiring MFA, blocking locations) but cannot perform scheduled reviews or automatically remove guest accounts that have not signed in for a specific period.

113
MCQeasy

Your company plans to use Microsoft Sentinel for security information and event management (SIEM). You need to ingest security logs from multiple Azure resources and on-premises servers. Which data connector should you use for Windows servers on-premises?

A.Azure Monitor Agent
B.Log Analytics agent
C.Microsoft Defender for Cloud agent
D.Azure Arc agent
AnswerA

Azure Monitor Agent is the current, consolidated logging agent designed for Microsoft Sentinel and Azure Monitor. It uses data collection rules (DCRs) to define exactly which events and performance counters are ingested, and it can span Linux, Windows, on-premises, and Azure Arc-enabled machines. Because it is the actively supported agent that replaces legacy options, using it is the correct way to collect and forward logs into Sentinel.

Why this answer

The Azure Monitor Agent (AMA) is the correct choice because it is the current, recommended data collection agent for Microsoft Sentinel, replacing the legacy Log Analytics agent. It supports collecting security logs from Windows servers on-premises via the Windows Security Events via AMA connector, which uses data collection rules (DCRs) for flexible, scalable log ingestion. AMA is optimized for Sentinel's SIEM requirements and provides better performance, security, and manageability than its predecessor.

Exam trap

The trap here is that candidates often confuse the Azure Monitor Agent with the Log Analytics agent, assuming the older agent is still the primary choice for Sentinel, when in fact Microsoft has deprecated the Log Analytics agent and now mandates the Azure Monitor Agent for all new deployments.

How to eliminate wrong answers

Option B (Log Analytics agent) is wrong because it is the legacy agent that Microsoft is deprecating in favor of the Azure Monitor Agent; it lacks support for newer Sentinel features and data collection rules. Option C (Microsoft Defender for Cloud agent) is wrong because it is designed for vulnerability assessment and security posture monitoring, not for general SIEM log ingestion into Sentinel; it does not collect Windows Security Event logs directly. Option D (Azure Arc agent) is wrong because it is used for managing on-premises servers as Azure Arc-enabled resources (e.g., policy, extensions), but it does not natively collect and forward security logs to Sentinel; you still need the Azure Monitor Agent for log ingestion.

114
MCQmedium

A company uses Microsoft Entra ID and wants to automate the lifecycle management of user accounts in their SaaS applications, such as Salesforce and ServiceNow. The solution should automatically create, update, and deactivate accounts when users join, move, or leave the organization. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Provisioning
B.Microsoft Entra ID Connect
C.Microsoft Entra ID Application Proxy
D.Microsoft Entra ID Entitlement Management
AnswerA

Microsoft Entra ID Provisioning is the correct service because it automates the entire identity lifecycle in SaaS applications by creating, updating, and deactivating user accounts based on authoritative sources such as HR systems or Microsoft Entra ID itself. It uses the SCIM 2.0 protocol, built-in app connectors, attribute mapping, and scoping filters to keep account statuses synchronized, and supports on-demand provisioning for immediate changes. This directly fulfills the requirement to automate user account management in external applications.

Why this answer

Microsoft Entra ID Provisioning (specifically, HR-driven provisioning) automates the creation, update, and deactivation of user accounts in SaaS applications like Salesforce and ServiceNow based on changes in the organization's HR system or directory. It uses SCIM (System for Cross-domain Identity Management) protocol to synchronize identity lifecycle events, ensuring accounts are automatically created when users join, updated when they move, and deactivated when they leave.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID Connect (which syncs to Entra ID) with provisioning to external SaaS apps, or they mistakenly think Entitlement Management handles account creation when it only manages access rights, not identity lifecycle.

How to eliminate wrong answers

Option B (Microsoft Entra ID Connect) is wrong because it is designed for synchronizing on-premises Active Directory objects to Microsoft Entra ID, not for provisioning user accounts into third-party SaaS applications. Option C (Microsoft Entra ID Application Proxy) is wrong because it provides secure remote access to on-premises web applications via reverse proxy, not lifecycle management of user accounts. Option D (Microsoft Entra ID Entitlement Management) is wrong because it manages access packages and approval workflows for resource access, not the automated creation, update, and deactivation of user accounts in SaaS apps.

115
MCQmedium

Refer to the exhibit. You run this PowerShell script in an Azure subscription. The script executes successfully. What is the outcome?

A.All existing tags are replaced with 'Environment'='Unknown'.
B.All resources without tags get the tag 'Environment' with value 'Unknown'.
C.All resources in the subscription get the tag 'Environment' with value 'Unknown'.
D.The script fails because Update-AzTag does not support merge.
AnswerB

The PowerShell script successfully identifies all Azure resources that currently possess no tags. It then systematically iterates through these untagged resources, utilising cmdlets such as `Update-AzResource` to apply the 'Environment' tag with the value 'Unknown' to each. This precise mechanism ensures that all previously untagged resources within the subscription are now categorised, satisfying the successful execution implied by the stem.

Why this answer

The `Update-AzTag` cmdlet with the `-Operation Merge` parameter merges the specified tags into existing resource tags without removing any existing tags. When a resource already has tags, only the specified tag is added or updated; when a resource has no tags, the specified tag is applied. This matches option B: all resources without tags get the tag 'Environment' with value 'Unknown'.

Exam trap

The trap here is that candidates often assume `Update-AzTag` with Merge behaves like a full replacement (Option A) or applies to all resources (Option C), when in fact Merge only adds or updates the specified tags and only targets resources that match the resource ID pipeline input — in this case, resources without tags due to the `Where-Object` filter.

How to eliminate wrong answers

Option A is wrong because `-Operation Merge` does not replace existing tags; it only adds or updates the specified tags, leaving all other existing tags intact. Option C is wrong because the script targets only resources without tags, not all resources in the subscription; resources that already have tags are not affected unless they lack the 'Environment' tag. Option D is wrong because `Update-AzTag` does support the `Merge` operation; the script executes successfully, proving the operation is valid.

116
MCQeasy

Refer to the exhibit. You are creating a role assignment in Azure. The role definition ID is for the Contributor role. What is the effect of this assignment?

A.The principal can manage all resources in resource group RG1.
B.The principal can read all resources in resource group RG1.
C.The principal can manage all resources in the subscription.
D.The principal can manage access to resource group RG1.
AnswerA

The Contributor role assigned at the resource group scope grants full management permissions over all resources contained in that resource group. This includes creating, deleting, and modifying resources as well as starting or stopping VMs, but it explicitly excludes the ability to grant access to the resource group. Because the assignment is scoped to RG1, these management rights apply only to resources within RG1, not to any other scope.

Why this answer

The Contributor role in Azure provides full management access to all resources within the assigned scope, but it cannot grant access to other users (role assignments). Since the scope is resource group RG1, the principal can manage all resources in that resource group, including creating, deleting, and modifying them, but cannot manage access to the resource group itself.

Exam trap

The trap here is that candidates often confuse the Contributor role with the Owner role, mistakenly thinking Contributor can manage access (role assignments), or they overlook the scope and assume the assignment applies to the entire subscription.

How to eliminate wrong answers

Option B is wrong because the Contributor role includes write and delete permissions, not just read; the Reader role provides read-only access. Option C is wrong because the scope is explicitly resource group RG1, not the subscription; assigning the Contributor role at the resource group scope limits management to that resource group only. Option D is wrong because managing access (role assignments) requires the Owner role or a custom role with Microsoft.Authorization/roleAssignments/write permission, which the Contributor role does not include.

117
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to ensure that users who access sensitive cloud applications from untrusted networks (e.g., public Wi-Fi) are prompted for multi-factor authentication (MFA). Which Microsoft Entra ID feature should they configure?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management (PIM)
D.Microsoft Entra ID B2C
AnswerA

Conditional Access is the correct Microsoft Entra ID feature because it centrally evaluates authentication signals—such as user, device, and network location—and applies granular access controls. Administrators define named locations (e.g., office IP ranges) and create a policy that requires MFA when a sign-in originates from any other location. This policy-driven approach gives real-time, condition-based enforcement of MFA for untrusted networks.

Why this answer

Conditional Access policies in Microsoft Entra ID allow administrators to define conditions (e.g., network location, device state) under which access to cloud applications is granted. By configuring a policy that targets sensitive applications and requires MFA when the user's IP address is from an untrusted network (such as public Wi-Fi), the company can enforce MFA only when the risk condition is met, without affecting access from trusted corporate networks.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based MFA with Conditional Access's location-based MFA, but Identity Protection alone cannot enforce MFA based solely on network location—it requires a Conditional Access policy to act on the risk signal.

How to eliminate wrong answers

Option B (Identity Protection) is wrong because it focuses on detecting and remediating identity risks (e.g., leaked credentials, sign-ins from anonymous IPs) and can trigger MFA via risk-based Conditional Access, but it is not the feature that directly configures network-location-based MFA prompts; it requires integration with Conditional Access. Option C (Privileged Identity Management) is wrong because it manages just-in-time privileged role activation and approval workflows, not network-based access controls for all users. Option D (Microsoft Entra ID B2C) is wrong because it is a customer-facing identity service for external users (e.g., social logins) and does not apply to internal corporate users accessing sensitive cloud apps.

118
MCQmedium

Refer to the exhibit. You create this Conditional Access policy in Microsoft Entra ID. What is the result?

A.Only administrators are prompted for MFA.
B.All users are prompted for MFA when accessing any application from a browser or mobile app.
C.External users are prompted for MFA.
D.Access is blocked for all users.
AnswerB

Because the policy includes 'All users', 'All cloud apps', and the grant control 'Require multi-factor authentication', every user in the tenant must perform MFA when accessing any application. The client app type configuration restricts enforcement to browser-based sessions and mobile apps using modern authentication, such as logging in through a browser or an app like Microsoft Authenticator. This produces a consistent MFA prompt for all internal users and any guest accounts present in the directory, across all registered applications.

Why this answer

The exhibit shows a Conditional Access policy that applies to 'All users' and targets 'All cloud apps' with the grant control set to 'Require multi-factor authentication'. This configuration forces every user, including administrators and external users, to complete MFA when accessing any cloud application from any platform (browser or mobile app). Option B correctly states this universal MFA requirement.

Exam trap

The trap here is that candidates often assume a policy targeting 'All users' only applies to internal users or that 'All cloud apps' excludes certain Microsoft services, but in reality both scopes are comprehensive and include external users and every registered application.

How to eliminate wrong answers

Option A is wrong because the policy targets 'All users', not just administrators, so administrators are not the only group prompted for MFA. Option C is wrong because while external users are included under 'All users', the policy also applies to internal users, so the result is not limited to external users. Option D is wrong because the grant control is set to 'Require multi-factor authentication', not 'Block access', so access is not blocked; it is allowed after MFA is satisfied.

119
MCQeasy

Your company is implementing a monitoring solution for Azure virtual machines. You need to collect performance counters and log events from the VMs and send them to a centralized Log Analytics workspace. Which agent should you install on the VMs?

A.Azure Monitor Agent
B.Log Analytics agent (MMA)
C.Diagnostics Extension
D.Dependency Agent
AnswerA

Azure Monitor Agent (AMA) is the current, cross-platform data-collection agent that collects performance counters, Windows and Linux event logs, and other telemetry directly into a Log Analytics workspace. Unlike legacy agents, AMA is governed by configurable Data Collection Rules (DCRs), which allow you to scope, filter, and route data to multiple workspaces without redeploying or reconfiguring the agent. It is Microsoft's recommended replacement for the Log Analytics agent and is required for the latest Azure Monitor features.

Why this answer

Azure Monitor Agent (AMA) is the current recommended agent for collecting performance counters and log events from Azure VMs and sending them to a Log Analytics workspace. It replaces the legacy Log Analytics agent (MMA) and offers centralized management via data collection rules (DCRs), improved security, and support for both Windows and Linux VMs. The AMA uses the Azure Monitor service pipeline and supports multi-homing to multiple workspaces natively.

Exam trap

The trap here is that candidates often confuse the legacy Log Analytics agent (MMA) as the correct choice because it was the standard for years, but Azure Monitor Agent is the modern replacement explicitly tested in the AZ-305 exam as the recommended solution for centralized log and performance collection.

How to eliminate wrong answers

Option B (Log Analytics agent, MMA) is wrong because it is the legacy agent that is being deprecated in favor of Azure Monitor Agent; it lacks support for data collection rules and does not provide the same level of centralized configuration or security. Option C (Diagnostics Extension) is wrong because it is designed to collect guest OS diagnostics and boot diagnostics for Azure VMs, not to send performance counters and log events to a Log Analytics workspace; it uses Azure Storage as its primary destination, not Log Analytics. Option D (Dependency Agent) is wrong because it is specifically used for collecting network and process dependency data for Azure Monitor's Service Map and VM Insights features, not for general performance counters and log events.

120
MCQhard

A company uses Microsoft Entra ID Premium P2. They need to implement a solution that allows users to request access to an access package that includes membership in a Microsoft Entra security group and access to a SharePoint Online site. The access must be time-limited and require approval by the user's manager. What should you configure?

A.Microsoft Entra ID self-service group management with expiration policies and approval workflows.
B.Entitlement management with an access package, assignment policies, and connected organizations.
C.Privileged Identity Management (PIM) for Microsoft Entra groups and SharePoint sites.
D.Conditional Access policies that require multi-factor authentication and device compliance for SharePoint access.
AnswerB

Entitlement management, part of Microsoft Entra ID Governance, allows creating access packages that bundle resources like groups and SharePoint sites. Assignment policies define who can request, approvers (e.g., manager), and expiration. This meets the requirement for time-limited access with approval. It is the correct solution for managing access at scale.

Why this answer

Entitlement management is designed for exactly this scenario: bundling access to multiple resources (groups, SharePoint sites) into an access package, with assignment policies that define who can request, require manager approval, and set expiration. It provides a self-service request portal and lifecycle management. PIM and Conditional Access serve different purposes and do not provide the required request-and-approval workflow for non-privileged resources.

Exam trap

The trap here is confusing Privileged Identity Management with entitlement management; PIM is for privileged roles, while entitlement management is for access packages that can include groups and SharePoint sites with approval and expiration.

121
MCQeasy

Your company is deploying Microsoft Entra ID Governance and needs to ensure that guest users' access to internal applications expires after 90 days. Which feature should you configure?

A.Privileged Identity Management (PIM)
B.Access reviews
C.Conditional Access policies
D.Entitlement management
AnswerD

Entitlement management in Microsoft Entra ID Governance is purpose-built for creating and managing access packages with built-in assignment policies, including an expiration date or duration (e.g., 30, 60, 90 days) for guest users. These access packages can include group memberships, app roles, or SharePoint site access, and when the expiration period elapses, Entra ID automatically removes those assignments without manual intervention. This directly satisfies the 'one-time automatic expiration after a fixed period' requirement and is the only option among the four that automates the entire lifecycle of a guest user's access.

Why this answer

Entitlement management in Microsoft Entra ID Governance allows you to create access packages that govern guest user access to internal applications. You can configure an access package with a specific expiration policy, such as setting the access to expire after 90 days, ensuring automatic removal of guest access without manual intervention.

Exam trap

The trap here is that candidates often confuse Access reviews (which require manual attestation) with automatic expiration, but Entitlement management provides the automated, policy-driven expiration that the question explicitly requires.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) is designed for just-in-time privileged role activation and oversight, not for managing expiration of guest user access to applications. Option B is wrong because Access reviews provide periodic attestation and manual review of access, but they do not enforce automatic expiration after a fixed duration like 90 days; they require reviewer action to remove access. Option C is wrong because Conditional Access policies enforce real-time access controls based on conditions (e.g., location, device state), but they cannot automatically expire or remove access after a set time period.

122
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID) Premium P2. They want to automatically block sign-ins from malicious IP addresses and require users to perform multi-factor authentication (MFA) when signing in from untrusted locations. Which Microsoft Entra ID feature should they use?

A.Conditional Access policies
B.Identity Protection
C.Privileged Identity Management
D.Access Reviews
AnswerB

Identity Protection detects risky sign-ins using detections such as 'Anonymous IP address' and 'Malicious IP address' from Microsoft Threat Intelligence, along with machine learning models that assign a risk level to each sign-in and user. In Microsoft Entra ID Premium P2, it also supports risk-based Conditional Access policies that can automatically block the risky sign-in or require MFA. This detection capability is what directly identifies a malicious IP, making Identity Protection the correct answer.

Why this answer

Identity Protection (option B) is the correct feature because it uses machine learning and heuristics to detect risky sign-ins, such as those from malicious IP addresses or untrusted locations. It can automatically block sign-ins from known malicious IPs and, when combined with Conditional Access, require MFA for sign-ins from untrusted locations. This directly addresses the requirement to block malicious IPs and enforce MFA based on location risk.

Exam trap

The trap here is that candidates often confuse Conditional Access (the policy engine) with the risk detection source, forgetting that Identity Protection provides the risk signals (like malicious IPs) that Conditional Access then enforces.

How to eliminate wrong answers

Option A is wrong because Conditional Access policies enforce access controls based on conditions like location or device state, but they do not natively detect or block malicious IP addresses; they rely on Identity Protection to provide the risk signals. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not sign-in risk detection or MFA enforcement from untrusted locations. Option D is wrong because Access Reviews are used to audit and recertify group memberships or role assignments periodically, not to block sign-ins or enforce MFA based on real-time risk.

123
MCQhard

Refer to the exhibit. You deploy this Azure Monitor scheduled query rule to alert when CPU usage exceeds 90% for sustained periods. However, alerts are not firing even when the condition is met. What is the most likely cause?

A.The KQL query syntax is incorrect and returns no results.
B.The action group is not configured with a valid email address.
C.The evaluation frequency is too short compared to the window size.
D.The threshold of 5 with 'Count' aggregation requires more than 5 data points above 90% in the window, which may not be happening.
AnswerD

With 'Count' aggregation, the alert fires only if the query returns more than 5 records, where each record corresponds to a data point with CPU usage above 90%. In a 15-minute window with, say, 1-minute metrics, there are 15 possible samples, but not all will necessarily exceed 90%; sustained high CPU is needed. If spikes are brief or stay just below the threshold, the count may remain below 6, leaving the alert silent.

Why this answer

The alert rule uses a 'Count' aggregation with a threshold of 5, meaning the alert fires only when the number of data points exceeding 90% CPU within the evaluation window is greater than 5. If the sustained high CPU usage produces fewer than 5 such data points (e.g., due to a short burst or insufficient sampling), the condition is not met, and the alert will not fire. This is a common misconfiguration where the threshold value is set too high relative to the actual data point frequency.

Exam trap

Microsoft often tests the misconception that any sustained high metric value will trigger an alert, ignoring how the 'Count' aggregation and threshold value interact with the number of data points in the evaluation window.

How to eliminate wrong answers

Option A is wrong because if the KQL query syntax were incorrect, the alert rule would typically show an error during creation or evaluation, and the rule would not be in a 'healthy' state; the question implies the rule is deployed and running. Option B is wrong because the action group's email validity affects notification delivery, not the firing of the alert itself; the alert can still trigger even if the action group is misconfigured. Option C is wrong because a short evaluation frequency relative to a long window size actually increases the chance of detecting sustained high CPU, as the rule checks more frequently; this would not prevent alerts from firing.

124
MCQmedium

You are designing a governance strategy for Azure resources. Your organization has multiple departments, each with its own set of Azure subscriptions. You need to enforce consistent policies across all subscriptions, such as allowed resource locations and required tags, while allowing departments to manage their own resources within those constraints. Which Azure service should you use?

A.Azure Blueprints
B.Azure Policy
C.Azure Management Groups
D.Azure Role-Based Access Control (RBAC)
AnswerB

Azure Policy is the correct choice because it centralizes enforcement of resource governance rules across management groups, subscriptions, and resource groups. It evaluates resources against policy definitions using effects such as Deny, Audit, Modify, and DeployIfNotExists, and it continuously scans for drift, not just at deployment time. This lets you enforce tagging standards, restrict resource types and locations, and auto-remediate non-compliant configurations with managed identities.

Why this answer

Azure Policy is the correct service because it enforces organizational standards and compliance rules across all Azure resources, such as allowed locations and required tags, at scale. It applies policies to management groups, subscriptions, or resource groups, ensuring consistent governance while allowing departments to manage their own resources within those constraints. Unlike Azure Blueprints, which deploys a full environment template, Azure Policy focuses solely on rule enforcement and remediation.

Exam trap

The trap here is confusing Azure Policy with Azure Blueprints, as both involve governance, but Blueprints is for deploying a full environment template while Policy is for ongoing rule enforcement and compliance auditing.

How to eliminate wrong answers

Option A is wrong because Azure Blueprints is used to deploy a repeatable set of Azure resources and policies as a package (e.g., ARM templates, RBAC assignments), but it does not enforce ongoing compliance or prevent non-compliant resources from being created after deployment. Option C is wrong because Azure Management Groups provide a hierarchical structure for organizing subscriptions and applying policies at scale, but they are not the service that enforces rules; they are the container for policy assignment. Option D is wrong because Azure Role-Based Access Control (RBAC) manages who can perform actions on resources (authorization), not what resource configurations are allowed (compliance); RBAC cannot enforce tag requirements or restrict resource locations.

125
MCQmedium

You are designing a governance strategy for a new Azure subscription. The security team requires that all resources must have a 'CostCenter' tag and an 'Environment' tag. Which Azure policy effect should you use to automatically apply the tags to new resources?

A.audit
B.modify
C.deny
D.deployIfNotExists
AnswerB

The modify effect is designed to add, replace, or remove tags on a resource during creation or update, and with a remediation task it can also apply tags to existing non-compliant resources. This makes it the appropriate effect for an automated tagging governance strategy, since it actively brings resources into compliance without blocking them. It supports both addOrReplace and add operations, giving flexible tag enforcement.

Why this answer

The 'modify' effect is correct because it can automatically append or replace missing tags on new or existing non-compliant resources during resource creation or update. Unlike 'deployIfNotExists', which only runs remediation tasks after creation, 'modify' applies the tags inline as part of the resource creation request, ensuring compliance without requiring a separate remediation task.

Exam trap

The trap here is that candidates often confuse 'deployIfNotExists' with 'modify', thinking both can automatically apply tags, but 'deployIfNotExists' requires a separate remediation task and does not apply tags inline during resource creation, making 'modify' the correct choice for automatic tag application on new resources.

How to eliminate wrong answers

Option A is wrong because 'audit' only logs non-compliance without taking any action to apply the tags. Option C is wrong because 'deny' blocks resource creation if tags are missing, but does not automatically apply them. Option D is wrong because 'deployIfNotExists' can deploy a remediation task to apply tags, but it runs after resource creation and requires a separate remediation trigger, whereas 'modify' applies tags inline during the creation or update request.

126
Multi-Selectmedium

Your organization uses Azure Monitor to collect metrics from Azure resources. You need to create a custom metric alert that triggers when the average CPU usage of a specific virtual machine exceeds 80% for 10 minutes. Which TWO components are required? (Choose two.)

Select 2 answers
A.Metric alert rule
B.Automation runbook
C.Action group
D.Log Analytics workspace
E.Diagnostic setting
AnswersA, C

This is the core resource that continuously evaluates a specified metric (e.g., percentage CPU) against a threshold (e.g., >80%) over a given aggregation window (e.g., 5 minutes). It defines the target resource, metric name, operator, threshold, and evaluation frequency, and it triggers a state change when the condition is met. Without a metric alert rule, no alert is generated from the metric stream.

Why this answer

A metric alert rule is required because it defines the condition (average CPU > 80%) and the evaluation frequency (every 1 minute over a 10-minute aggregation window) that triggers the alert. Without the rule, Azure Monitor has no logic to evaluate the metric data and fire the alert.

Exam trap

The trap here is that candidates often confuse the required components for creating an alert (the rule and the action group) with optional components like diagnostic settings or runbooks, which are only needed for advanced scenarios or log-based alerts.

127
MCQmedium

Your company runs a mission-critical application on Azure Virtual Machines in a single region. You need to design a monitoring solution that provides proactive alerts for performance degradation and allows the operations team to analyze historical trends. The solution must minimize cost and operational overhead. You have an existing Log Analytics workspace. What should you include in the design?

A.Enable VM insights in Azure Monitor and use its live map and performance views for historical analysis.
B.Configure Azure Autoscale for the VMs based on CPU metrics and use Azure Monitor for logging.
C.Deploy Application Insights on each VM and use its built-in alerts for performance.
D.Enable Azure Monitor on all VMs using the Azure Monitor agent. Create metric alerts for high CPU and memory usage. Use Log Analytics to query and analyze historical performance data.
AnswerD

Enable the Azure Monitor agent on all VMs to collect guest OS performance counters (CPU, memory, disk) and forward them to a Log Analytics workspace. Metric alerts can then be configured on these performance counters for near-real-time proactive notification when thresholds are breached. The historical data in the workspace can be queried with Kusto Query Language to analyze long-term trends and capacity forecasting. This combination gives low-overhead, proactive alerting plus powerful historical analysis, and is the standard Azure Well-Architected approach for VM monitoring.

Why this answer

It uses the Azure Monitor agent to collect performance data from VMs, enabling metric alerts for proactive notification of high CPU and memory usage, while leveraging the existing Log Analytics workspace for cost-effective historical analysis. This approach minimizes operational overhead by using a single agent and native Azure Monitor features without additional services or complex configurations.

Exam trap

The trap here is that candidates may confuse VM insights (which offers rich visualizations but limited historical analysis) with the full monitoring solution required, or mistakenly think Application Insights is appropriate for VM-level performance monitoring when it is designed for application telemetry.

How to eliminate wrong answers

Option A is wrong because VM insights provides live map and performance views for real-time monitoring but is not designed for deep historical trend analysis, and its prebuilt performance charts have limited retention without Log Analytics. Option B is wrong because Azure Autoscale is for automatically scaling VM instances based on metrics, not for monitoring performance degradation or analyzing historical trends; it also does not address the requirement for proactive alerts and historical analysis. Option C is wrong because Application Insights is primarily for application-level monitoring (e.g., web apps, APIs) and requires instrumenting each application, which adds cost and complexity; it is not suitable for OS-level performance metrics like CPU and memory on VMs.

128
MCQmedium

A company wants workload deployments to access Azure resources without storing client secrets in CI/CD variables. The pipeline runs from GitHub Actions. Which identity design should be used?

A.A shared user account with MFA disabled
B.A storage account access key
C.Workload identity federation with Microsoft Entra ID
D.A long-lived app registration client secret
AnswerC

Workload identity federation with Microsoft Entra ID lets an external workload (for example, a GitHub Actions job or a Kubernetes pod) present a token from its own trusted identity provider to Entra ID in exchange for an Entra access token. This uses OAuth 2.0 client credentials grant flow with no client secret, because the federated credential defines trust by issuer, subject, and audience. The resulting short-lived tokens can be scoped to Azure resources or Microsoft Graph, eliminating long-lived secrets and enabling automated rotation through the source identity provider.

Why this answer

Workload identity federation with Microsoft Entra ID allows GitHub Actions to exchange an OpenID Connect (OIDC) token for an Azure access token, eliminating the need to store client secrets in CI/CD variables. This design uses short-lived tokens and federated identity credentials, aligning with the principle of zero-trust and secretless authentication.

Exam trap

The trap here is that candidates may choose a long-lived client secret (Option D) thinking it is the standard way to authenticate, overlooking the requirement to avoid storing secrets and the modern OIDC-based federation approach.

How to eliminate wrong answers

Option A is wrong because a shared user account with MFA disabled violates security best practices and does not eliminate secrets; it still requires storing credentials in CI/CD variables. Option B is wrong because a storage account access key is a static secret that must be stored in CI/CD variables, and it provides broad, unmonitored access to the storage account. Option D is wrong because a long-lived app registration client secret is a static secret that must be stored in CI/CD variables, defeating the requirement to avoid storing secrets.

129
MCQmedium

Your organization uses Microsoft Entra ID and Azure Key Vault. You need to ensure that a custom application can securely access secrets in Key Vault without storing credentials in code. The application runs on an Azure Virtual Machine. What should you use?

A.Store the Key Vault URL and connection string in the application configuration
B.Create a service principal and upload a certificate to the VM
C.Assign a system-assigned managed identity to the VM
D.Use a shared access signature (SAS) token
AnswerC

Assigning a system-assigned managed identity to the VM is the most secure and least operationally complex approach because Azure automatically creates an identity tied to the VM's lifecycle, and you can grant that identity access to Azure Key Vault via an access policy or Azure RBAC. The application uses the Azure SDK to acquire an access token from the Azure Instance Metadata Service (IMDS) with no credentials stored in code, configuration, or on disk. This identity is automatically rotated by Azure, eliminating the need to manage or store any secrets, and it aligns with best practices for Azure workloads.

Why this answer

A system-assigned managed identity for Azure Virtual Machines allows the application to authenticate to Azure Key Vault without storing any credentials in code. Azure automatically manages the identity's lifecycle and tokens, enabling the VM to obtain an access token from Azure AD (now Microsoft Entra ID) to call Key Vault's REST API. This aligns with the principle of zero-trust and eliminates the need for service principals or certificates in the application.

Exam trap

The trap here is that candidates may confuse SAS tokens (used for Azure Storage) with Key Vault authentication, or mistakenly think that a service principal with a certificate is the most secure option, overlooking the fully managed, credential-less nature of managed identities.

How to eliminate wrong answers

Option A is wrong because storing the Key Vault URL and connection string in application configuration still exposes credentials (the connection string) in code or config files, violating the requirement to avoid storing credentials. Option B is wrong because creating a service principal and uploading a certificate to the VM requires manual certificate management, rotation, and storage of the certificate on the VM, which introduces credential management overhead and security risks. Option D is wrong because a shared access signature (SAS) token is used for delegating access to Azure Storage resources, not for authenticating to Azure Key Vault; Key Vault does not support SAS tokens for authentication.

130
Multi-Selectmedium

Your company has an Azure subscription that contains 100 virtual machines (VMs). You are designing a monitoring solution that must meet the following requirements: - Alert when any VM's CPU usage exceeds 90% for 15 minutes. - Alert when any VM's available memory drops below 1 GB. - Provide a centralized dashboard showing real-time performance metrics for all VMs. Which TWO Azure services should you include in the solution? (Choose two.)

Select 2 answers
A.Azure Policy
B.Microsoft Sentinel
C.Azure Monitor
D.Azure Monitor Workbooks
E.Azure Automation
AnswersC, D

Azure Monitor is the foundational monitoring service in Azure, collecting platform metrics and logs from resources, including virtual machines. When the Azure Diagnostics extension or Log Analytics agent is enabled, it captures guest OS metrics such as CPU percentage and memory utilization. Azure Monitor natively supports metric alerts that fire when a threshold is exceeded and can trigger action groups to send notifications or start automation. This makes it the primary correct service for the scenario's real-time performance monitoring and alerting need.

Why this answer

Azure Monitor is the core service for collecting, analyzing, and acting on telemetry from Azure resources. It can collect CPU and memory metrics from VMs via the Azure Monitor Agent, and its alerting engine can trigger actions when CPU exceeds 90% for 15 minutes or available memory drops below 1 GB, meeting both alerting requirements.

Exam trap

The trap here is that candidates often confuse Azure Monitor Workbooks with Azure Dashboards or Power BI, but Workbooks are the correct service for creating a centralized, real-time performance dashboard that integrates directly with Azure Monitor alerts and metrics.

131
MCQeasy

Your organization plans to use Azure Policy to enforce tagging on all resources. The tags must include 'CostCenter' and 'Environment'. Resources that do not have these tags should be automatically remediated. What should you use?

A.A policy with 'append' effect
B.A policy with 'audit' effect
C.A policy with 'deployIfNotExists' effect and a remediation task
D.A policy with 'deny' effect
AnswerC

DeployIfNotExists is evaluated periodically and can trigger a template deployment when a resource lacks the required tag, and a remediation task can be started after the policy is assigned to proactively fix all existing non-compliant resources. The remediation task uses managed identity to modify those resources by executing the linked ARM template that attaches the tag, bringing the current inventory into compliance without requiring a manual update. This combination is the only one among the choices that both detects and corrects pre-existing resources.

Why this answer

The 'deployIfNotExists' effect is correct because it allows Azure Policy to evaluate resources for missing tags and then deploy a remediation task that automatically adds the required tags. This effect is specifically designed for scenarios where non-compliance can be corrected by deploying or modifying resources, such as adding tags via a policy definition that triggers a remediation task.

Exam trap

The trap here is that candidates often confuse 'append' with 'deployIfNotExists', thinking that 'append' can remediate existing resources, but 'append' only applies during resource creation or update, not to already deployed resources.

How to eliminate wrong answers

Option A is wrong because the 'append' effect adds tags only during resource creation or update, but it does not automatically remediate existing resources that are already missing the tags. Option B is wrong because the 'audit' effect only logs non-compliance without any automatic remediation, requiring manual intervention. Option D is wrong because the 'deny' effect prevents creation or update of resources that do not have the required tags, but it does not remediate existing non-compliant resources.

132
MCQmedium

Your organization uses Microsoft Entra ID. You need to enforce multifactor authentication (MFA) for all guest users accessing a specific SharePoint Online site. What is the most efficient way to achieve this?

A.Use SharePoint site permissions to require MFA.
B.Create a Conditional Access policy targeting guest users and the SharePoint Online app.
C.Enable MFA per-user for each guest account.
D.Configure Microsoft Entra Entitlement Management to require MFA.
AnswerB

Conditional Access evaluates sign-in signals and enforces MFA at authentication time, scoped to guest user identities and the SharePoint Online cloud app. This targets exactly the required population and resource in one policy, avoiding per-site configuration or broader tenant-wide MFA enforcement.

Why this answer

Conditional Access policies in Microsoft Entra ID allow you to enforce MFA specifically for guest users when they access the SharePoint Online app. This is the most efficient approach as it targets the exact user group (guests) and the specific application (SharePoint Online) without requiring per-user configuration or additional licensing overhead.

Exam trap

The trap here is that candidates often confuse SharePoint site permissions with identity-level security controls, assuming that MFA can be enforced at the site level, when in fact MFA must be enforced through Entra ID Conditional Access policies.

How to eliminate wrong answers

Option A is wrong because SharePoint site permissions control access at the site level but cannot enforce MFA; MFA is an identity-level security requirement managed by Entra ID, not SharePoint. Option C is wrong because enabling MFA per-user for each guest account is inefficient, requires manual management, and does not scale; it also lacks the granularity to target only the specific SharePoint Online site. Option D is wrong because Microsoft Entra Entitlement Management manages access packages and approval workflows, not MFA enforcement; it can require MFA as part of an access package policy, but that is not the most efficient or direct method for enforcing MFA on a single SharePoint site.

133
Multi-Selecthard

Which THREE components are required to monitor and audit Azure resource changes using Azure Monitor?

Select 3 answers
A.An Application Insights resource
B.A Log Analytics workspace
C.Diagnostic settings on resources to send logs to the workspace
D.Azure Activity Log export to the workspace
E.Azure Policy with audit effect
AnswersB, C, D

A Log Analytics workspace is the fundamental aggregation and analysis destination that underpins Azure Monitor auditing and monitoring. It stores log data from Activity Log exports, resource diagnostic settings, and many other sources, enabling near-real-time log queries with Kusto Query Language (KQL), Azure Monitor alert rules, and workbooks. Without a workspace, there is no centralized, queryable store to retain and correlate audit traces, making it an essential component for any monitoring and auditing scenario in Azure.

Why this answer

A Log Analytics workspace is required because it serves as the central repository where Azure Monitor collects and stores log data from various sources, including diagnostic settings and activity logs. Without a workspace, there is no destination for the logs to be ingested, queried, or analyzed, making it an essential component for monitoring and auditing resource changes.

Exam trap

The trap here is that candidates often confuse Azure Policy’s audit effect as a direct logging mechanism, when in fact it only evaluates compliance and requires diagnostic settings to send its data to a Log Analytics workspace for auditing.

134
MCQmedium

You are designing a governance solution for a Microsoft Azure environment that contains multiple subscriptions. You need to ensure that all resources are compliant with corporate security policies. The solution must automatically remediate non-compliant resources. What should you include in the design?

A.Azure RBAC custom roles
B.Azure Policy with DeployIfNotExists effect
C.Azure Resource Graph queries
D.Azure Blueprints
AnswerB

Azure Policy with the DeployIfNotExists effect evaluates resources against policy definitions and, when a non-compliant resource lacks a required configuration, triggers a deployment to remediate it automatically. This deployment is performed by a managed identity defined in the policy assignment, and remediation tasks can be run on demand or continuously to fix existing and newly created resources. Because it couples compliance assessment with actual resource modification, it directly satisfies the requirement for automated governance remediation.

Why this answer

Azure Policy with the DeployIfNotExists effect is the correct choice because it automatically remediates non-compliant resources by triggering a deployment (e.g., via a template) when a resource is created or updated and does not meet the policy condition. This ensures continuous compliance with corporate security policies without manual intervention, as the effect can also be assigned a remediation task to fix existing resources.

Exam trap

The trap here is that candidates often confuse Azure Policy's audit-only effects (like AuditIfNotExists) with the automatic remediation capability, or they mistakenly think Azure Blueprints can handle ongoing compliance enforcement, when in fact Blueprints are a one-time deployment orchestration tool and do not provide continuous remediation.

How to eliminate wrong answers

Option A is wrong because Azure RBAC custom roles control who can access and manage resources (authorization), not what configurations those resources must comply with (governance), and they cannot automatically remediate non-compliant resources. Option C is wrong because Azure Resource Graph queries are used for exploring and querying resources across subscriptions at scale, but they are read-only and cannot enforce or remediate compliance. Option D is wrong because Azure Blueprints are used to orchestrate the deployment of resource groups, policies, role assignments, and ARM templates as a package, but they do not automatically remediate non-compliant resources after deployment; remediation requires Policy effects like DeployIfNotExists.

135
MCQhard

Refer to the exhibit. You are reviewing an Azure Policy definition. Which virtual machines will be denied?

A.No virtual machines because the condition is invalid
B.All virtual machines regardless of SKU
C.Only virtual machines with SKU Standard_DS2_v2
D.All virtual machines except those with SKU Standard_DS2_v2
AnswerD

This is the correct behavior. The policy definition evaluates the field 'Microsoft.Compute/virtualMachines/sku.name' and applies the deny effect when that value is 'notEquals' to Standard_DS2_v2. As a result, any virtual machine using another SKU will be denied, while a Standard_DS2_v2 VM will be allowed. This is a common pattern for restricting compute SKUs to an approved allowlist using Azure Policy.

Why this answer

The Azure Policy definition uses a 'deny' effect with a condition that checks if the virtual machine's SKU field is not equal to 'Standard_DS2_v2'. This means any VM whose SKU does not match 'Standard_DS2_v2' will be denied. Only VMs with the exact SKU 'Standard_DS2_v2' will be allowed, making option D correct.

Exam trap

The trap here is that candidates may misinterpret 'notEquals' as denying the specified SKU, when in fact it denies everything except that SKU, leading them to incorrectly choose option C.

How to eliminate wrong answers

Option A is wrong because the condition 'notEquals' is a valid Azure Policy condition operator, so the policy is not invalid. Option B is wrong because the policy specifically denies VMs that do not match the specified SKU, not all VMs. Option C is wrong because the policy denies VMs that are not 'Standard_DS2_v2', not only those with that SKU; it actually allows VMs with that SKU.

136
MCQhard

You are designing an identity solution for a multinational company that uses Microsoft Entra ID. The company has a requirement that all users must authenticate using biometrics or FIDO2 security keys. Which Entra ID feature should you configure?

A.Passwordless authentication
B.Identity Protection
C.Entra Verified ID
D.Conditional Access policies
AnswerD

Conditional Access policies in Microsoft Entra ID are the correct enforcement mechanism because they can evaluate granular conditions—such as user, location, device compliance, and risk—and then apply grant controls that mandate specific authentication methods. Through the 'Authentication Strengths' feature or the 'Require authentication method' grant control, you can require FIDO2 security keys or Windows Hello for Business, both of which are hardware-backed and inherently phishing-resistant. This aligns with the requirement for rigorous phishing resistance, as these methods use asymmetric cryptography and are not susceptible to phishing attacks, unlike password-based or OTP-based methods.

Why this answer

Conditional Access policies in Microsoft Entra ID allow you to enforce authentication strength requirements, such as requiring biometrics or FIDO2 security keys, by targeting specific user groups or applications. This is achieved by configuring a Conditional Access policy with the 'Require multifactor authentication' control and integrating with authentication methods like Windows Hello for Business or FIDO2 security keys, ensuring that only passwordless authentication methods meeting the company's biometric or FIDO2 requirement are permitted.

Exam trap

The trap here is that candidates confuse the authentication method itself (passwordless authentication) with the policy mechanism (Conditional Access) that enforces its use, leading them to select Option A instead of D.

How to eliminate wrong answers

Option A is wrong because Passwordless authentication is a category of authentication methods (e.g., Windows Hello, FIDO2, Microsoft Authenticator) but not a feature that enforces a requirement; it must be combined with Conditional Access policies to mandate its use. Option B is wrong because Identity Protection is a risk-based detection and remediation service (e.g., detecting leaked credentials or risky sign-ins) and does not enforce specific authentication methods like biometrics or FIDO2. Option C is wrong because Entra Verified ID is a decentralized identity solution for verifiable credentials (e.g., digital IDs for employees or customers) and is unrelated to enforcing authentication method requirements.

137
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to automate the process of granting users access to a specific application only during business hours and revoking it automatically. The access should be based on a request-approval workflow. Which Microsoft Entra ID feature should they use?

A.Privileged Identity Management (PIM)
B.Conditional Access
C.Access Reviews
D.Entitlement Management
AnswerD

Entitlement Management is the correct tool because it enables administrators to create access packages that bundle resources like groups, apps, and SharePoint sites with request and approval policies. These policies support time-limited assignments, expiration dates, and automatic revocation of access when the entitlement expires. It also integrates with connected organizations and access reviews, providing a complete automated identity governance lifecycle for internal and external users.

Why this answer

Entitlement Management (D) is correct because it provides automated access lifecycle management through access packages, which can include time-bound assignments (e.g., business hours) and require approval workflows. This allows you to define policies that grant access to the application only during specified hours and automatically revoke it when the policy expires or conditions change, without manual intervention.

Exam trap

The trap here is confusing Conditional Access (which controls access at authentication time) with Entitlement Management (which provisions and deprovisions access over time), leading candidates to pick B because they focus on the 'business hours' condition rather than the automated lifecycle workflow.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) is designed for just-in-time privileged role activation (e.g., Global Administrator) and does not support time-bound access to non-privileged applications or request-approval workflows for standard users. Option B is wrong because Conditional Access enforces real-time access policies based on signals (e.g., location, device state) but cannot automate granting or revoking access through a request-approval workflow; it is a gate, not a provisioning mechanism. Option C is wrong because Access Reviews only provide periodic attestation of existing access (e.g., recertification) and do not automate the initial granting or time-bound revocation of access based on a request-approval process.

138
Multi-Selectmedium

You are designing a monitoring solution for a multi-region application deployed on Azure Virtual Machines and Azure SQL Database. The solution must provide a unified view of metrics and logs from all resources, detect anomalies using machine learning, and send alerts to the operations team. Which TWO capabilities should you include in the design?

Select 2 answers
A.Azure Service Health
B.Azure Application Insights
C.Azure Security Center
D.Azure Monitor
E.Azure Log Analytics
AnswersB, D

Azure Application Insights is a feature of Azure Monitor and a full-fledged Application Performance Management (APM) service for developers. It automatically collects request rates, response times, dependency calls, exceptions, and custom events, and it uses smart detection to flag anomalies without you having to define thresholds. It also provides distributed tracing and a rich query language, making it the definitive choice for application-specific monitoring.

Why this answer

Azure Monitor is the core platform for collecting, analyzing, and acting on telemetry from Azure resources, including metrics and logs from VMs and SQL Database. Application Insights extends Azure Monitor with application performance management (APM) and built-in machine learning anomaly detection (e.g., Smart Detection) for proactive alerting. Together, they provide a unified monitoring view with ML-driven insights.

Exam trap

The trap here is that candidates often confuse Azure Log Analytics as a separate monitoring service rather than recognizing it as a component of Azure Monitor, leading them to select it as an independent capability instead of Azure Monitor itself.

139
MCQmedium

Your company operates in a highly regulated industry and must retain all sign-in logs for 7 years. The logs must be immutable and cannot be modified or deleted by administrators. You need to design a monitoring solution that stores sign-in logs in a cost-effective manner while meeting compliance requirements. The solution should also allow for real-time analysis of sign-in activity. What should you include in the design?

A.Stream sign-in logs to Log Analytics for real-time analysis and simultaneously archive them to an Azure Storage account with immutable blob policy (WORM).
B.Stream sign-in logs to Azure Event Hubs and then to cold storage in Azure Blob with lifecycle management.
C.Stream sign-in logs to Log Analytics workspace with 7-year retention and use Azure Policy to restrict deletion.
D.Use Azure Data Explorer to store logs for 7 years and configure a purge policy to prevent deletion.
AnswerA

Streaming sign-in logs to Log Analytics enables near real-time querying and alerting for security operations, satisfying the need for fast analysis. Simultaneously archiving the same logs to an Azure Storage account with immutable blob policy (WORM) ensures that the archived copies are both write-once-read-many and tamper-proof for the mandatory retention period. This dual-destination pattern is explicitly supported by Azure diagnostic settings, making it the correct approach for regulated industries that require both investigative access and compliance-grade immutability.

Why this answer

It meets both compliance and real-time analysis requirements. Streaming sign-in logs to Log Analytics enables real-time monitoring and querying, while simultaneously archiving them to an Azure Storage account with an immutable blob policy (WORM) ensures the logs cannot be modified or deleted for the required 7-year retention period. This combination provides cost-effective long-term storage (Azure Blob is cheaper than Log Analytics for long-term retention) and satisfies regulatory immutability mandates.

Exam trap

The trap here is that candidates often assume Log Analytics retention alone suffices for compliance, but Log Analytics does not provide immutable storage, and Azure Policy cannot prevent data modification within the workspace; the correct approach requires separate immutable archival in Azure Storage.

How to eliminate wrong answers

Option B is wrong because Azure Event Hubs is a real-time ingestion service, but cold storage in Azure Blob with lifecycle management does not provide immutability; lifecycle management can delete blobs based on rules, which violates the requirement that logs cannot be modified or deleted by administrators. Option C is wrong because Log Analytics workspace retention of 7 years does not guarantee immutability; Azure Policy can restrict deletion of the workspace but cannot prevent data modification or deletion within the workspace itself, and Log Analytics does not natively support WORM (Write Once, Read Many) compliance. Option D is wrong because Azure Data Explorer (ADX) is designed for interactive analytics, not long-term immutable archival; a purge policy is used to delete data, not to prevent deletion, and ADX does not provide WORM capabilities required for regulatory compliance.

140
MCQmedium

Your organization is implementing a zero-trust security model. You need to ensure that all access to corporate resources from mobile devices is conditional based on device compliance, user risk, and location. Which Microsoft Entra ID feature should you use?

A.Identity Protection
B.Microsoft Intune
C.Conditional Access policies
D.Microsoft Defender XDR
AnswerC

Conditional Access is Azure AD's policy engine that evaluates real-time signals—including user/group membership, location, application, device compliance, and risk scores—to allow, deny, or require additional verification such as MFA or a compliant device. It natively integrates with Intune compliance status and Identity Protection risk assessments, making it the central enforcement point for zero-trust access control. By combining these signals into granular, context-aware policies, Conditional Access directly enforces the zero-trust principle of never trusting implicit access.

Why this answer

Conditional Access policies in Microsoft Entra ID are the correct choice because they allow you to enforce access controls based on conditions such as device compliance (via integration with Microsoft Intune), user risk (via integration with Identity Protection), and location (via IP ranges or named locations). This directly supports the zero-trust principle of 'never trust, always verify' by evaluating signals before granting access to corporate resources.

Exam trap

The trap here is that candidates often confuse Microsoft Intune (which manages device compliance) with the policy engine that enforces access decisions, failing to realize that Conditional Access is the orchestration layer that consumes compliance, risk, and location signals to enforce zero-trust access.

How to eliminate wrong answers

Option A is wrong because Identity Protection is a feature within Entra ID that detects and responds to identity-based risks (e.g., leaked credentials, anonymous IP addresses), but it does not itself enforce access decisions or combine multiple conditions like device compliance and location—it only provides risk signals that Conditional Access policies can consume. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service that manages device compliance policies (e.g., requiring encryption, PIN), but it does not evaluate user risk or location, nor does it enforce conditional access decisions at the authentication gateway—it only reports device compliance status to Entra ID. Option D is wrong because Microsoft Defender XDR is a unified security incident and response platform that correlates alerts across endpoints, email, and identities, but it does not enforce real-time access control policies based on device compliance, user risk, or location at the authentication layer—it focuses on threat detection and response, not conditional access enforcement.

141
MCQmedium

A company uses Microsoft Entra ID. They want to block all access to corporate applications from devices that are not managed by their organization. They require that only devices enrolled in Microsoft Intune and compliant with company policies can access company resources. Which Microsoft Entra ID feature should they use?

A.Conditional Access policy requiring device compliance
B.Identity Protection with user risk policy
C.Privileged Identity Management (PIM)
D.Microsoft Entra ID Join process
AnswerA

Conditional Access is Microsoft Entra ID's policy engine that can evaluate device compliance status from Microsoft Intune at sign-in time. By targeting all users and cloud apps with a 'Require device to be marked as compliant' grant, the policy will block access for any device that is not enrolled and compliant with the organization's compliance policies. This directly satisfies the goal of blocking all access from non-compliant devices, and it can also be combined with session controls to continuously re-evaluate compliance.

Why this answer

Conditional Access policies in Microsoft Entra ID can enforce device compliance as a condition for granting access. By configuring a policy that requires devices to be marked as compliant in Microsoft Intune, only devices enrolled and meeting company policies can access corporate applications, effectively blocking unmanaged devices.

Exam trap

The trap here is that candidates may confuse Identity Protection's user risk policies with device-based controls, or assume that simply joining a device to Entra ID (Option D) is sufficient to enforce compliance, when in fact a Conditional Access policy is required to block non-compliant devices.

How to eliminate wrong answers

Option B is wrong because Identity Protection with user risk policy focuses on detecting and responding to risky user behavior (e.g., leaked credentials, anonymous IP addresses) rather than evaluating device management or compliance status. Option C is wrong because Privileged Identity Management (PIM) provides just-in-time privileged access and role activation controls, not device-level access restrictions. Option D is wrong because Microsoft Entra ID Join is a device identity registration process that enables devices to authenticate with Entra ID, but it does not by itself enforce compliance policies or block non-compliant devices; it must be combined with a Conditional Access policy to achieve the described requirement.

142
MCQhard

You are designing a monitoring solution for a hybrid environment with on-premises servers and Azure VMs. You need to collect performance data from all servers and visualize it in a single dashboard. Which Azure service should you use?

A.Azure Service Health
B.Azure Workbooks
C.Azure Arc
D.Azure Monitor
AnswerD

Azure Monitor is the comprehensive monitoring platform that collects metrics, logs, and dependency data from cloud and hybrid sources. Agents such as the Azure Monitor Agent can be deployed to on-premises VMs via Azure Arc, sending data to a Log Analytics workspace for querying and visualization. It also supports custom dashboards, Workbooks, alert rules, and integration with Service Health, making it the appropriate core service for the hybrid monitoring solution in question.

Why this answer

Azure Monitor is the correct service because it provides a unified platform for collecting, analyzing, and visualizing performance data from both on-premises servers and Azure VMs. By deploying the Azure Monitor agent on all servers, you can send metrics and logs to a single Log Analytics workspace and then use Azure Workbooks or Metrics Explorer to create a consolidated dashboard.

Exam trap

The trap here is that candidates often confuse Azure Workbooks (a visualization tool) with a monitoring solution, forgetting that Workbooks are just a presentation layer and require a data source like Azure Monitor to function.

How to eliminate wrong answers

Option A is wrong because Azure Service Health is a service that provides personalized alerts and guidance for Azure service issues and planned maintenance, not for collecting or visualizing server performance data. Option B is wrong because Azure Workbooks is a visualization tool that can create rich dashboards, but it is not a data collection service; it relies on data already in Azure Monitor (e.g., Log Analytics or Metrics). Option C is wrong because Azure Arc extends Azure management and governance to on-premises and multi-cloud resources, but it does not itself collect performance data or provide a dashboard; it can enable Azure Monitor agents on those servers, but the monitoring and visualization are still done by Azure Monitor.

143
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to allow external business partners to request access to a specific application. The access must be time-limited and require approval from the partner's manager. Additionally, access must automatically expire after the defined period. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Privileged Identity Management (PIM)
B.Microsoft Entra ID Entitlement Management
C.Microsoft Entra ID Identity Protection
D.Microsoft Entra ID Access Reviews
AnswerB

Microsoft Entra ID Entitlement Management is the correct solution because it is a feature of Microsoft Entra ID Identity Governance that lets administrators create access packages, which are bundles of resources such as groups, applications, and SharePoint sites. These access packages can be made available to external users via connected organizations, with customizable request policies that enforce approval workflows and define assignment duration—including automatic expiration and removal of access when the assignment ends. This directly matches the need to grant controlled, time-limited access to applications for external identities, while also supporting recurring access reviews as a complementary control.

Why this answer

Microsoft Entra ID Entitlement Management enables organizations to manage access for external business partners through access packages. These packages can enforce time-limited access, require manager approval, and automatically expire access after a defined period, directly meeting all the stated requirements.

Exam trap

The trap here is that candidates often confuse Entitlement Management with PIM because both involve time-limited access, but PIM is strictly for privileged roles within the organization, not for external partner application access with manager approval.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) is designed for just-in-time privileged role activation and oversight, not for granting time-limited access to applications for external partners. Option C is wrong because Identity Protection focuses on detecting and responding to identity-based risks, such as compromised credentials or suspicious sign-ins, not on managing access requests or approvals. Option D is wrong because Access Reviews are used to periodically audit and confirm existing access assignments, not to handle initial access requests with manager approval and automatic expiration.

144
MCQmedium

Your company has a Microsoft Entra ID tenant with 10,000 users. You are designing an identity governance solution to automate user access reviews for critical applications. The compliance team requires that access reviews be conducted quarterly and that any reviewer who does not respond within 7 days have their decisions auto-approved. You need to implement the solution using Microsoft Entra ID Governance. What should you do?

A.Use Microsoft Entra Privileged Identity Management (PIM) to require activation for access to critical applications.
B.Create an access review with 'Auto deny' after 7 days of no response.
C.Create a recurring campaign in Microsoft Purview Compliance Manager.
D.Create an access review with 'Auto approve' after 7 days of no response.
AnswerD

Configuring an access review with the auto-approve fallback directly aligns with the business rule: the review is created in Microsoft Entra ID, managers are assigned as reviewers, and a recurrence schedule is set. When the 7-day response window lapses, the system automatically applies an 'approve' decision for each pending access, preserving user access. This ensures that access is recertified periodically without being disrupted by manager delays, satisfying the requirement precisely.

Why this answer

The compliance team explicitly requires that unreviewed decisions be auto-approved after 7 days. In Microsoft Entra ID Governance, an access review can be configured with 'Auto approve' to automatically approve any reviewer decisions that are not submitted within the specified duration. This directly satisfies the requirement for quarterly reviews with a 7-day auto-approval policy.

Exam trap

The trap here is confusing 'Auto approve' with 'Auto deny' — candidates often assume that non-response should result in denial for security, but the question explicitly states the compliance team requires auto-approval, so the answer must match the stated requirement.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Privileged Identity Management (PIM) is designed for just-in-time privileged role activation, not for recurring user access reviews of critical applications. Option B is wrong because 'Auto deny' would automatically deny access after 7 days of no response, which contradicts the compliance team's requirement for auto-approval. Option C is wrong because Microsoft Purview Compliance Manager is a compliance management solution for assessments and controls, not for automating user access reviews.

145
MCQmedium

A company wants to automatically detect sign-in attempts from anonymous IP addresses and sign-ins from unfamiliar locations. When such a risk is detected, they want to require multi-factor authentication (MFA) or block the sign-in in real time. Additionally, they need a dashboard that shows risk events and allows generating weekly risk reports. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Identity Protection
B.Microsoft Entra ID Conditional Access
C.Microsoft Entra ID Privileged Identity Management
D.Microsoft Entra ID Identity Governance
AnswerA

Microsoft Entra ID Identity Protection is the dedicated detection engine that evaluates each sign-in against a set of risk signals, including the anonymous IP address signal, which flags sign-ins originating from Tor, virtual private networks (VPNs), and other IP-anonymizing services. It applies machine-learning models and heuristics to produce a risk score (Low/Medium/High) and generates a risky sign-in report, which can then trigger automated remediation such as requiring multifactor authentication (MFA) or blocking the sign-in. This is the component responsible for the underlying detection, not Conditional Access.

Why this answer

Microsoft Entra ID Identity Protection is the correct feature because it specifically detects sign-in risks such as anonymous IP addresses and unfamiliar locations, and it can automatically enforce conditional access policies like requiring MFA or blocking sign-ins in real time. It also provides a dashboard for risk events and supports generating weekly risk reports, directly matching all stated requirements.

Exam trap

The trap here is that candidates often confuse Conditional Access as the detection mechanism, but it is only the enforcement layer; Identity Protection is the service that actually detects the risks and provides the risk signals that Conditional Access uses.

How to eliminate wrong answers

Option B is wrong because Conditional Access is a policy engine that enforces access controls based on conditions, but it does not itself detect risks like anonymous IPs or unfamiliar locations; it relies on Identity Protection to provide risk signals. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role assignments and access reviews, not risk detection or sign-in anomaly monitoring. Option D is wrong because Identity Governance focuses on access lifecycle management, entitlement reviews, and compliance, not real-time risk detection or MFA enforcement during sign-in.

146
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID) for identity management. They want to enforce that only devices compliant with security policies (e.g., BitLocker enabled, antivirus running) can access corporate cloud applications (Microsoft 365 and custom SaaS apps). They also need a dashboard to monitor device compliance status. Which Microsoft Entra ID feature(s) should they configure?

A.Conditional Access policies with device compliance conditions, and Microsoft Intune for compliance management
B.Microsoft Entra ID Identity Protection with user risk policies
C.Microsoft Entra ID Access Reviews
D.Microsoft Entra ID Device Registration only
AnswerA

Intune compliance policies define the security baseline a device must meet—such as minimum OS versions, BitLocker/FileVault encryption, and jailbreak/root detection—and report each device's compliance state in the Intune console. Conditional Access then consumes that state during authentication: if the policy requires 'Device to be marked as compliant,' Entra ID blocks or allows access based on the current Intune signal. This combination provides both the enforcement and the visibility of device health that the scenario demands.

Why this answer

Conditional Access policies in Microsoft Entra ID can enforce device compliance as a condition for granting access to cloud applications, while Microsoft Intune provides the device compliance policies (e.g., BitLocker, antivirus) and the dashboard to monitor compliance status. Together, they ensure only compliant devices can access corporate resources and provide visibility into device health.

Exam trap

The trap here is that candidates often confuse Identity Protection (user risk) with device compliance, or assume Device Registration alone is sufficient, missing the need for Intune to define and monitor compliance policies.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID Identity Protection focuses on user and sign-in risk (e.g., leaked credentials, anonymous IP addresses), not device compliance status or enforcement. Option C is wrong because Microsoft Entra ID Access Reviews are used for periodic attestation of group memberships, application access, and role assignments, not for device compliance monitoring or conditional access based on device state. Option D is wrong because Microsoft Entra ID Device Registration only registers devices in the directory, but without Intune or Conditional Access, it cannot enforce compliance policies or provide a compliance dashboard.

147
MCQmedium

A company has an Azure subscription with many resource groups. The security team requires that all diagnostic settings for every Azure resource be automatically configured to send logs to a central Log Analytics workspace. You need to design a solution that enforces this configuration at scale without manual intervention. What should you include in the design?

A.Use Azure Blueprints to assign a policy that audits diagnostic settings and manually remediate non-compliant resources.
B.Assign a built-in Azure Policy that uses the DeployIfNotExists effect to deploy diagnostic settings for each resource type.
C.Create an Azure Monitor alert rule that triggers an Azure Automation runbook to enable diagnostic settings when a resource is created.
D.Configure Azure Monitor diagnostic settings on each resource type using an ARM template and deploy it to all resource groups.
AnswerB

Azure Policy with DeployIfNotExists can automatically deploy diagnostic settings when a resource is created or updated. It evaluates the resource and, if the setting is missing, triggers a deployment to add it. This enforces compliance at scale across subscriptions and resource groups, meeting the requirement without manual effort.

Why this answer

Azure Policy with the DeployIfNotExists effect is designed to automatically deploy required configurations, such as diagnostic settings, when non-compliant resources are detected. It continuously evaluates resources and can remediate them, ensuring that all resources send logs to the central workspace without manual intervention. This provides scalable, consistent enforcement across the environment.

Exam trap

The trap here is assuming that Azure Monitor alerts or Azure Automation can automatically enforce configuration, when they are event-driven and require custom logic, unlike Azure Policy which provides declarative, continuous compliance.

148
MCQhard

A company uses Microsoft Entra ID (Microsoft Entra ID) Premium P2. They need to automatically detect users whose credentials have been leaked and require them to reset their password at their next sign-in. Additionally, they want to block sign-ins from anonymous IP addresses (e.g., Tor network). Which combination of Microsoft Entra ID features should they enable to meet both requirements?

A.Conditional Access with MFA policy and Identity Protection sign-in risk policy
B.Identity Protection user risk policy and sign-in risk policy
C.Privileged Identity Management and Conditional Access
D.Microsoft Entra ID Connect Health and Identity Protection
AnswerB

Identity Protection's user risk policy evaluates signals such as leaked credentials and, when the user risk score is elevated, automatically requires the user to perform a secure password change during sign-in. Its sign-in risk policy independently assesses real-time signals, including anonymous IP addresses, and can block the sign-in. Together, these two policies directly and automatically enforce both stated requirements, making this the correct answer.

Why this answer

Identity Protection user risk policy can automatically detect leaked credentials and force a password reset at next sign-in, while the sign-in risk policy can block sign-ins from anonymous IP addresses (e.g., Tor). These two policies together address both requirements without needing additional Conditional Access or MFA policies.

Exam trap

The trap here is that candidates confuse Conditional Access with Identity Protection risk policies, not realizing that leaked credential detection and anonymous IP blocking are native Identity Protection risk policies, not Conditional Access controls.

How to eliminate wrong answers

Option A is wrong because Conditional Access with MFA policy does not detect leaked credentials or block anonymous IPs; it only enforces MFA based on conditions, not risk. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time privileged access and does not detect leaked credentials or block anonymous IPs; Conditional Access alone cannot detect leaked credentials without Identity Protection. Option D is wrong because Microsoft Entra ID Connect Health monitors synchronization health and does not provide user risk or sign-in risk policies for leaked credentials or anonymous IP blocking.

149
MCQmedium

Your organization has multiple Azure subscriptions. You need to create a central view of policy compliance across all subscriptions. What should you use?

A.Azure Monitor
B.Azure Policy compliance dashboard
C.Azure Resource Graph
D.Azure Blueprints
AnswerB

The Azure Policy compliance dashboard is the native portal surface in Azure Policy that aggregates compliance states for all policies, initiatives, and assignments, and it can scope the view to a management group, subscription, or resource group. It uses the policy evaluation pipeline to mark resources as compliant or noncompliant against definitions, then shows rollups and drill-downs so administrators can identify offending resources and exemptions. This precisely meets the need to see compliance across multiple subscriptions.

Why this answer

The Azure Policy compliance dashboard provides a centralized view of policy compliance across all subscriptions in a management group or tenant. It aggregates compliance data from all assigned policies and initiatives, allowing you to filter by subscription, policy definition, or compliance state. This is the native tool designed specifically for cross-subscription policy compliance monitoring.

Exam trap

The trap here is that candidates often confuse Azure Policy compliance dashboard with Azure Monitor or Azure Resource Graph, thinking either can serve as a central compliance viewer, but only the Policy dashboard provides the out-of-the-box aggregated view across subscriptions without requiring custom queries or workbooks.

How to eliminate wrong answers

Option A is wrong because Azure Monitor is a platform for collecting, analyzing, and acting on telemetry data from cloud and on-premises environments, not for viewing policy compliance across subscriptions. Option C is wrong because Azure Resource Graph is a query engine for exploring Azure resources and their properties, but it does not provide a pre-built compliance dashboard or aggregate policy compliance states across subscriptions. Option D is wrong because Azure Blueprints is used for orchestrating the deployment of resource templates, policies, and role assignments to create compliant environments, not for viewing ongoing compliance status.

150
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to generate periodic reports of user sign-ins and audit activities for compliance. They want to store the logs for 1 year. Which Azure service should they use?

A.Microsoft Entra ID sign-in logs and audit logs with retention set to 1 year in the Azure portal
B.Azure Monitor Log Analytics workspace with Microsoft Entra ID diagnostic settings
C.Azure Storage account with lifecycle management
D.Azure Event Hubs for streaming
AnswerB

This is the correct answer because Microsoft Entra ID diagnostic settings can stream sign-in and audit logs directly to an Azure Monitor Log Analytics workspace. Log Analytics supports configurable retention periods up to 730 days (with options for longer-term archival), and its KQL query engine enables you to generate custom reports, dashboards, and alerts directly on the historical log data. This combined long-term storage and querying capability exactly satisfies the company's requirement to generate reports on sign-in and audit activity.

Why this answer

Microsoft Entra ID sign-in and audit logs are retained for only 30 days by default. To store them for 1 year, you must route the logs via diagnostic settings to an Azure Monitor Log Analytics workspace, which allows configurable retention up to 2 years (or more with a commitment tier). This is the only native Azure service that supports long-term retention of Entra ID logs for compliance reporting.

Exam trap

The trap here is that candidates assume the Azure portal's retention slider for Entra ID logs can be extended beyond 30 days, but Microsoft intentionally limits it to 30 days to force the use of diagnostic settings and Log Analytics for long-term retention.

How to eliminate wrong answers

Option A is wrong because the Azure portal's retention setting for Entra ID sign-in and audit logs only allows a maximum of 30 days; you cannot set it to 1 year directly in the portal. Option C is wrong because while an Azure Storage account with lifecycle management can store logs for 1 year, it does not support querying or generating periodic compliance reports—it is a cold storage solution, not a reporting tool. Option D is wrong because Azure Event Hubs is a real-time streaming service for log ingestion, not a storage or reporting solution; it cannot retain logs for 1 year or generate periodic reports.

← PreviousPage 2 of 3 · 222 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Design identity, governance, and monitoring solutions questions.