Courseiva

CCNA Design identity, governance, and monitoring solutions Questions

72 of 222 questions · Page 3/3 · Design identity, governance, and monitoring solutions · Answers revealed

151
MCQhard

Refer to the exhibit. You are reviewing a Bicep template for a storage account. You need to ensure that the storage account is only accessible via HTTPS and uses TLS 1.2. Which property validates this requirement?

A.type: Microsoft.Storage/storageAccounts
B.accessTier: Hot
C.supportsHttpsTrafficOnly: true and minimumTlsVersion: TLS1_2
D.name: stprod001
AnswerC

Configuring supportsHttpsTrafficOnly to true enforces that all client requests to the storage account must be made over HTTPS, causing any HTTP request to be rejected. The minimumTlsVersion property set to TLS1_2 further ensures that connections use at least TLS version 1.2, blocking older protocols such as TLS 1.0 and 1.1. Together, these two properties provide complete transport security enforcement, which is exactly what the requirement asks for.

Why this answer

The `supportsHttpsTrafficOnly` property enforces that all traffic to the storage account must use HTTPS, and the `minimumTlsVersion` property set to `TLS1_2` ensures that only TLS 1.2 or higher is accepted. Together, these two properties satisfy the requirement of HTTPS-only access with TLS 1.2, as defined in the Azure Storage security baseline.

Exam trap

The trap here is that candidates often confuse `supportsHttpsTrafficOnly` with a simple boolean toggle and forget that `minimumTlsVersion` is a separate, required property to enforce the specific TLS version, leading them to select an option that only partially addresses the requirement.

How to eliminate wrong answers

Option A is wrong because the `type` property only declares the resource provider and type (`Microsoft.Storage/storageAccounts`), not any security settings for HTTPS or TLS. Option B is wrong because `accessTier: Hot` controls the storage tier (Hot, Cool, Archive) for blob data, not transport security protocols. Option D is wrong because the `name` property simply assigns the storage account name (`stprod001`) and has no effect on HTTPS or TLS enforcement.

152
MCQeasy

You need to design a solution to monitor the performance of an Azure SQL Database. You want to create a dashboard that shows the top 10 queries by CPU usage over the last hour. What should you use?

A.Azure Monitor Workbooks
B.Power BI
C.Azure SQL Analytics
D.Log Analytics
AnswerC

Azure SQL Analytics is the correct choice because it is a cloud monitoring solution built specifically for Azure SQL Database, elastic pools, and managed instances. It connects to Azure Monitor to collect resource utilization, wait stats, deadlocks, and query performance data, then presents it through prebuilt dashboards that show DTU/CPU, storage, IO, and session trends. These dashboards are ready to use without manual configuration, giving immediate visibility into SQL performance.

Why this answer

Azure SQL Analytics is a dedicated monitoring solution for Azure SQL Database that provides built-in views and dashboards for top queries by CPU, duration, and other performance metrics. It leverages the Query Store and DMVs to surface the top 10 queries by CPU usage over the last hour without requiring custom queries or additional configuration.

Exam trap

The trap here is that candidates confuse Azure SQL Analytics (a dedicated monitoring solution) with Log Analytics (the underlying data platform) or Azure Monitor Workbooks (a general-purpose dashboard tool), assuming any of them can provide the same pre-built top queries view without additional effort.

How to eliminate wrong answers

Option A is wrong because Azure Monitor Workbooks are customizable, interactive dashboards but do not provide pre-built, out-of-the-box views for top queries by CPU; they require manual configuration of KQL queries to extract that data. Option B is wrong because Power BI is a business analytics service for creating reports from various data sources, not a native Azure SQL monitoring tool, and it would require complex data export and transformation to replicate the built-in top queries view. Option D is wrong because Log Analytics is the underlying data store and query engine for Azure Monitor logs, but it does not offer a ready-made dashboard for top queries by CPU; you would need to write custom KQL queries and build visualizations from scratch.

153
MCQmedium

You are designing a monitoring solution for a hybrid environment with on-premises servers and Azure VMs. You need to collect security events and performance data centrally, and create custom alerts. The solution must use the same agent for both environments. Which agent should you deploy?

A.Log Analytics agent (MMA)
B.Azure Monitor Agent
C.Microsoft Dependency Agent
D.Azure Diagnostics extension
AnswerB

Azure Monitor Agent (AMA) is the next-generation, unified agent designed to replace the Log Analytics agent for both Azure VMs and on-premises servers via Azure Arc. It provides a single agent to collect performance, event, security, and custom telemetry, with granular control through Data Collection Rules (DCRs) that separate data collection from configuration. AMA supports multi-homing by sending data to multiple Log Analytics workspaces simultaneously, making it the appropriate and recommended choice for a hybrid environment.

Why this answer

Azure Monitor Agent (AMA) is the correct choice because it is the next-generation agent that replaces the legacy Log Analytics agent (MMA) and supports both Windows and Linux machines in hybrid and Azure environments. It collects security events and performance data into a single Log Analytics workspace and enables custom alert rules via data collection rules (DCRs), all with a single agent deployment.

Exam trap

The trap here is that candidates often confuse the Log Analytics agent (MMA) as the 'standard' hybrid agent, not realizing it is being replaced by Azure Monitor Agent, which is the only agent that meets the 'same agent for both environments' requirement with unified data collection rules.

How to eliminate wrong answers

Option A is wrong because the Log Analytics agent (MMA) is legacy and will be deprecated by August 2024; it requires separate agents for different data types and does not support the same unified data collection rules as Azure Monitor Agent. Option C is wrong because the Microsoft Dependency Agent is used exclusively for service map and VM insights topology data, not for general security event or performance data collection, and it must be paired with another agent (MMA or AMA) to function. Option D is wrong because the Azure Diagnostics extension is designed for Azure VMs only, collecting boot diagnostics and guest OS metrics to Azure Storage or Event Hubs, not for hybrid on-premises servers, and it does not support custom alerts via Log Analytics workspaces.

154
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to automatically detect sign-ins from users with leaked credentials and prompt those users to reset their password during the next sign-in. Which Microsoft Entra ID feature should they enable?

A.Microsoft Entra ID Identity Protection
B.Conditional Access
C.Privileged Identity Management (PIM)
D.Microsoft Entra ID B2B
AnswerA

Microsoft Entra ID Identity Protection detects leaked-credential sign-ins through its leaked credentials detection signal and can enforce a user risk policy requiring password reset at next sign-in. This satisfies the requirement for automatic detection and remediation without manual monitoring.

Why this answer

Microsoft Entra ID Identity Protection includes a 'Leaked Credentials' detection capability that continuously monitors for credentials exposed in known data breaches. When a user's credentials are detected as leaked, Identity Protection can automatically trigger a password reset during the next sign-in, ensuring the compromised credentials are no longer usable.

Exam trap

The trap here is that candidates often confuse Conditional Access (which can enforce password changes via a 'Require password change' grant control) with Identity Protection, but Conditional Access alone cannot detect leaked credentials—it only enforces policies after a risk is detected by Identity Protection.

How to eliminate wrong answers

Option B (Conditional Access) is wrong because Conditional Access enforces access policies based on signals like location or device compliance, but it does not natively detect leaked credentials or trigger password resets. Option C (Privileged Identity Management) is wrong because PIM manages just-in-time privileged role activation and access reviews, not credential compromise detection. Option D (Microsoft Entra ID B2B) is wrong because B2B is designed for external user collaboration and guest access, not for detecting leaked credentials or enforcing password resets.

155
MCQeasy

Your organization uses Microsoft Purview to govern data across Azure and on-premises sources. You need to ensure that sensitive data, such as credit card numbers, is automatically detected and classified in Azure Blob Storage. Which Purview feature should you configure?

A.Microsoft Sentinel
B.Data catalog search
C.Data classification scanning with built-in sensitive information types
D.Data lineage tracking
AnswerC

Data classification scanning in Microsoft Purview uses system data source scanners to inspect structured and unstructured content, and it applies built-in sensitive information types (for example, credit card numbers, social security numbers, or email addresses) and custom classification rules to the sampled data. When a scan matches a defined pattern or classifier, Purview records those classification labels and can propagate them to associated assets, columns, or files, enabling downstream governance policies. Because this capability directly identifies sensitive data within the content, it is the correct answer for automatically classifying sensitive data across your data estate.

Why this answer

Microsoft Purview's data classification scanning can be configured to automatically detect sensitive data like credit card numbers using built-in sensitive information types (e.g., Credit Card Number). When a scan is run against Azure Blob Storage, Purview identifies and classifies the data based on these predefined patterns, enabling governance and compliance.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with Purview's classification capabilities, or assume data lineage or catalog search can perform content inspection, when only classification scanning with sensitive information types can automatically detect sensitive data.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a Security Information and Event Management (SIEM) tool for threat detection and response, not for data classification or governance. Option B is wrong because Data catalog search is a feature for discovering and searching assets already registered in Purview, not for automatically detecting or classifying sensitive data. Option D is wrong because Data lineage tracking captures how data moves and transforms across systems, but it does not perform content inspection or classification of sensitive information.

156
MCQeasy

A company wants to collect metrics and logs from all Azure resources in their subscription, including custom metrics from their applications, and create dashboards and alerts. Which Azure service should they use as the primary monitoring platform?

A.Azure Monitor
B.Azure Log Analytics
C.Azure Application Insights
D.Azure Service Health
AnswerA

Azure Monitor is the comprehensive, unified monitoring service that acts as the single pipeline for collecting platform metrics, activity logs, resource logs, and custom telemetry across all Azure resources. It stores metric data in a time-series database and log data in Log Analytics workspaces, then provides a unified query experience, dashboards, and alerting actions. This centralization is what makes it the correct answer for collecting both metrics and logs from every resource in an Azure environment.

Why this answer

Azure Monitor is the correct primary monitoring platform because it serves as the single, unified ingestion and analysis service for all metrics and logs across Azure resources, including custom metrics from applications via the Application Insights SDK or the custom metrics API. It provides a consolidated workspace for creating dashboards, setting alerts, and querying data, making it the foundational service for observability in Azure.

Exam trap

The trap here is that candidates often confuse Azure Monitor with its sub-services like Log Analytics or Application Insights, failing to recognize that Azure Monitor is the umbrella service that encompasses both metrics and logs, while the others are specialized components within it.

How to eliminate wrong answers

Option B (Azure Log Analytics) is wrong because it is a component within Azure Monitor that stores and queries log data, not the overarching monitoring platform; it lacks native support for metrics and dashboards without Azure Monitor as the parent. Option C (Azure Application Insights) is wrong because it is a subset of Azure Monitor focused specifically on application performance monitoring (APM) for live web apps, not a platform for collecting infrastructure metrics or logs from all Azure resources. Option D (Azure Service Health) is wrong because it only provides personalized alerts and guidance for Azure service issues and planned maintenance, not the collection of metrics, logs, or custom application data.

157
MCQmedium

Your organization uses Microsoft Entra ID and has a hybrid identity deployment with Active Directory Domain Services (AD DS) on-premises. You need to synchronize user identities to Microsoft Entra ID, but you must ensure that password hashes are never stored in the cloud. Which synchronization method should you use?

A.Password Hash Sync
B.Federation with AD FS
C.Pass-through Authentication (PTA)
D.Azure AD Connect Cloud Sync
AnswerC

Pass-through Authentication (PTA) is the correct method because it validates users' passwords directly against on-premises Active Directory through a lightweight authentication agent. The password is never written to or stored in Entra ID; it is transmitted to the on-prem agent and only a success/failure response is returned. This satisfies the 'no password hashes in the cloud' requirement exactly and also works with Seamless SSO to provide a user-friendly sign-in experience.

Why this answer

Pass-through Authentication (PTA) is the correct choice because it validates user passwords directly against on-premises Active Directory without ever storing password hashes in Azure AD. This meets the requirement that password hashes are never stored in the cloud, as PTA uses an agent on-premises to authenticate users, and only the validation result is sent to Azure AD.

Exam trap

The trap here is that candidates often confuse Pass-through Authentication with Password Hash Sync, assuming that any synchronization method must store password hashes in the cloud, but PTA avoids this by performing real-time validation without hash storage.

How to eliminate wrong answers

Option A is wrong because Password Hash Sync synchronizes a hash of the user's password to Azure AD, which directly violates the requirement that password hashes are never stored in the cloud. Option B is wrong because Federation with AD FS does not store password hashes in Azure AD, but it introduces a separate federation infrastructure and is not primarily a synchronization method; the question asks for a synchronization method, and AD FS is an identity federation service, not a synchronization tool. Option D is wrong because Azure AD Connect Cloud Sync uses Password Hash Sync by default and can also support Pass-through Authentication, but it is a lightweight synchronization agent that still stores password hashes in the cloud if Password Hash Sync is enabled; the question requires a method that ensures password hashes are never stored, which is not guaranteed by Cloud Sync alone.

158
MCQhard

A multinational company uses Microsoft Entra ID with a custom domain. They need to implement a governance strategy for Microsoft 365 groups, ensuring that group expiration policies are enforced and that group owners receive renewal notifications. What should you configure?

A.Microsoft Purview compliance portal – Data Lifecycle Management
B.Microsoft Entra ID – Group settings (Expiration policy)
C.Microsoft Intune – Device compliance policies
D.Microsoft Sentinel – Analytics rules
AnswerB

Microsoft Entra ID – Group settings (Expiration policy) is the correct administrative location because Microsoft 365 group expiration is a tenant-level policy that is enforced by Microsoft Entra ID. In the Entra admin center, you navigate to Identity > Groups > Group settings and configure the 'Expiration policy' to set a fixed validity period (e.g., 180 or 365 days) for all Microsoft 365 groups, with the option to send renewal notifications to group owners. This policy directly controls group lifecycle by automatically expiring inactive groups, and it can also be managed via Microsoft Graph or PowerShell (New-UnifiedGroupExpirationPolicy). This is the native mechanism provided by Microsoft for this exact scenario.

Why this answer

Microsoft Entra ID's Group settings include an expiration policy specifically designed to enforce lifecycle management for Microsoft 365 groups. This policy allows administrators to set a group expiration period (e.g., 180, 365 days) and automatically sends renewal notification emails to group owners before expiration, enabling them to renew the group if needed. This directly meets the requirement for enforcing group expiration and renewal notifications.

Exam trap

The trap here is that candidates often confuse Microsoft Purview's data lifecycle management with group lifecycle management, or mistakenly think Intune or Sentinel can handle group expiration policies, when in fact only Microsoft Entra ID's group settings provide the specific expiration and renewal notification functionality.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview compliance portal – Data Lifecycle Management focuses on retention and deletion of content (e.g., emails, documents) based on labels, not on managing the lifecycle of Microsoft 365 groups or sending renewal notifications to group owners. Option C is wrong because Microsoft Intune – Device compliance policies are used to enforce security and compliance requirements on managed devices (e.g., requiring encryption, PIN), not to manage group expiration or renewal notifications. Option D is wrong because Microsoft Sentinel – Analytics rules are used for security detection and threat hunting by analyzing logs and alerts, not for configuring group expiration policies or sending renewal notifications.

159
MCQeasy

A company uses Microsoft Entra ID for identity management. They want to ensure that users accessing sensitive data from unmanaged devices are prompted for multifactor authentication (MFA) and must accept a terms-of-use. Which policy should be configured?

A.Terms-of-use policy
B.Conditional Access policy
C.Identity Protection policy
D.Privileged Identity Management (PIM) policy
AnswerB

Conditional Access is the correct policy mechanism because it combines signals—such as device platform, join state, compliance status, and location—into conditions that apply at sign-in. You can target unmanaged devices by using a device filter for 'not hybrid Azure AD joined' or 'not compliant', and then require both MFA and an accepted terms-of-use as grant controls. This gives you a single policy that enforces authentication strength and consent only when the device is unmanaged.

Why this answer

Conditional Access policies in Microsoft Entra ID allow granular control over access based on conditions such as device state (managed vs. unmanaged). By configuring a policy that targets unmanaged devices, you can enforce MFA and require acceptance of a terms-of-use before granting access to sensitive data. This directly meets the requirement without needing separate policies for MFA and terms-of-use.

Exam trap

The trap here is that candidates often confuse a standalone Terms-of-use policy (Option A) with the ability to enforce it conditionally, not realizing that Conditional Access is required to tie the terms-of-use acceptance to a specific condition like unmanaged devices.

How to eliminate wrong answers

Option A is wrong because a Terms-of-use policy alone only creates and displays the terms document; it cannot enforce MFA or trigger based on device state. Option C is wrong because Identity Protection policies focus on risk-based signals (e.g., leaked credentials, sign-in anomalies) and do not natively enforce terms-of-use acceptance or device-based conditions. Option D is wrong because Privileged Identity Management (PIM) policies manage just-in-time access and approval workflows for privileged roles, not general user access conditions like device state or MFA enforcement.

160
MCQeasy

Your company is migrating on-premises applications to Azure. You need to ensure that users can sign in using their existing on-premises Active Directory credentials without duplicating accounts. Which identity solution should you recommend?

A.Microsoft Entra B2B collaboration
B.Microsoft Entra External ID
C.Microsoft Entra Connect
D.Microsoft Entra Domain Services
AnswerC

Microsoft Entra Connect is the correct tool for hybrid identity synchronization because it is an on-premises component that synchronizes users, groups, and other directory objects from your Active Directory to Microsoft Entra ID. It supports multiple sign-on methods—password hash synchronization, pass-through authentication, and federation (e.g., AD FS)—so users retain their existing on-premises credentials when accessing Microsoft 365 and other Azure-integrated apps. It also handles ongoing incremental sync, deprovisioning, and device writeback, making it the primary identity bridge between on-prem AD and the cloud.

Why this answer

Microsoft Entra Connect (formerly Azure AD Connect) is the correct solution because it synchronizes on-premises Active Directory identities to Microsoft Entra ID, enabling users to sign in with their existing credentials via password hash synchronization, pass-through authentication, or federation. This avoids duplicating accounts by maintaining a single identity source of truth, with optional seamless single sign-on (SSO) for a transparent experience.

Exam trap

The trap here is that candidates often confuse Microsoft Entra Domain Services (which provides domain-join capabilities for Azure VMs) with identity synchronization, but it does not sync user credentials for cloud app authentication.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra B2B collaboration is designed for external guest users (e.g., partners or vendors) to access your applications using their own identities, not for synchronizing existing on-premises AD users. Option B is wrong because Microsoft Entra External ID is a customer-facing identity platform for external consumer or customer scenarios, not for integrating an organization's own on-premises Active Directory. Option D is wrong because Microsoft Entra Domain Services provides managed domain services (e.g., LDAP, Kerberos, NTLM) for Azure VMs without domain-joining them to an on-premises DC, but it does not synchronize user credentials from on-premises AD for cloud app sign-in.

161
MCQeasy

You need to configure a monitoring solution for Azure virtual machines that collects performance counters, event logs, and enables alerting based on CPU usage exceeding 90%. Which Azure service should you use?

A.Azure Policy
B.Microsoft Sentinel
C.Azure Monitor
D.Azure Update Manager
AnswerC

Azure Monitor is the core monitoring service in Azure that ingests platform metrics, activity logs, and guest OS telemetry via agents like the Azure Monitor Agent. It supports metric and log-based alerts, custom workbooks, and dashboards for performance counters such as CPU %, memory, and disk I/O, making it the appropriate solution for this monitoring need.

Why this answer

Azure Monitor is the correct service because it provides a unified platform for collecting performance counters and event logs from Azure VMs via the Log Analytics agent or Azure Monitor Agent, and it supports metric-based alert rules that can trigger when CPU usage exceeds a defined threshold (e.g., 90%). This directly meets the requirements for monitoring, log collection, and alerting without additional services.

Exam trap

The trap here is that candidates often confuse Azure Monitor with Microsoft Sentinel because both involve log collection and alerts, but Sentinel is specifically for security incidents, not general performance monitoring and threshold-based alerting on metrics like CPU usage.

How to eliminate wrong answers

Option A is wrong because Azure Policy is a governance tool used to enforce compliance rules (e.g., requiring specific VM SKUs or tags) and does not collect performance counters, event logs, or generate CPU-based alerts. Option B is wrong because Microsoft Sentinel is a Security Information and Event Management (SIEM) solution focused on security threat detection and incident response, not general performance monitoring and alerting for CPU usage. Option D is wrong because Azure Update Manager is designed solely for managing OS updates and patches on VMs, with no capability to collect performance counters, event logs, or alert on CPU utilization.

162
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to automatically remove guest users who have not signed in for 60 days. Additionally, they must generate a report of all guest access for auditors. Which Microsoft Entra ID feature should they implement?

A.Access Reviews
B.Entitlement Management
C.Identity Protection
D.Terms of Use
AnswerA

Microsoft Entra Access Reviews are the right answer because they provide a recurring, attestation-based workflow to certify or deny access for users. You can scope a review to 'Guest users only' and set an inactivity threshold based on sign-in activity, so guests who haven't signed in by a certain date are automatically flagged and removed. When the review completes, you can auto-apply the results to remove denied guests from groups, applications, and directory roles, and every action is written to the Entra audit log for compliance evidence.

Why this answer

Access Reviews in Microsoft Entra ID allow administrators to create recurring reviews that automatically remove guest users who have not signed in within a specified period (e.g., 60 days) by configuring the 'Inactive users (in days)' setting. Additionally, Access Reviews generate a detailed report of all guest access decisions, which can be exported for auditors, meeting both requirements directly.

Exam trap

The trap here is that candidates often confuse Entitlement Management (which handles access packages) with Access Reviews (which handles periodic attestation and automated removal), missing that only Access Reviews directly support inactivity-based removal and audit reporting.

How to eliminate wrong answers

Option B (Entitlement Management) is wrong because it manages access packages and catalogs for resource provisioning but does not natively provide automated removal based on sign-in inactivity or generate audit reports for guest access. Option C (Identity Protection) is wrong because it focuses on detecting and remediating identity risks (e.g., compromised accounts, sign-in anomalies) rather than automating guest user lifecycle or producing access review reports. Option D (Terms of Use) is wrong because it enforces user consent to policies but lacks any capability to automatically remove inactive users or generate audit reports for guest access.

163
Drag & Dropmedium

Drag and drop the steps to implement Azure AD Privileged Identity Management (PIM) for a role into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Select role, configure settings, assign eligible members, set notifications, then test activation.

164
MCQhard

A company uses Microsoft Entra ID B2B to collaborate with external vendors. They want to enforce that external users must use multi-factor authentication (MFA) and access company resources only from compliant devices (e.g., managed by Intune). They also want to require a session timeout of 1 hour. Which combination of Microsoft Entra ID features should they use?

A.A
B.B
C.C
D.D
AnswerB

Microsoft Entra ID Conditional Access is the comprehensive policy engine that can enforce all the stated requirements during sign-in. A Conditional Access policy can require multi-factor authentication for external B2B users, require the device to be marked as compliant by integrating with Intune, and apply session controls that set sign-in frequency to force periodic reauthentication. These policies can be targeted to guest and external users specifically, making Conditional Access the right tool for controlling access in B2B collaboration scenarios.

Why this answer

It combines Conditional Access policies with session controls to enforce MFA, device compliance (via Intune), and a 1-hour session timeout. Conditional Access policies evaluate sign-in risk and require MFA and compliant devices, while the session control 'Sign-in frequency' can be set to 1 hour to enforce reauthentication. This meets all three requirements without relying on deprecated or separate features.

Exam trap

The trap here is that candidates often confuse Conditional Access session controls with token lifetime policies or think that Identity Protection alone can enforce device compliance, but only Conditional Access policies can combine MFA, device compliance, and session timeout in a single policy.

How to eliminate wrong answers

Option A is wrong because it uses Azure AD Identity Protection, which is designed for risk-based policies (e.g., risky sign-ins) but does not natively enforce device compliance or session timeout; it lacks the session control for a 1-hour timeout. Option C is wrong because it relies on Azure AD Privileged Identity Management (PIM), which manages just-in-time privileged access and does not enforce MFA or device compliance for external users accessing general resources. Option D is wrong because it uses Azure AD Terms of Use, which only requires acceptance of a policy document and cannot enforce MFA, device compliance, or session timeout.

165
MCQhard

You are designing a monitoring solution for a critical application that runs on Azure Virtual Machines. The application generates custom performance counters. You need to alert when the custom counter exceeds a threshold and trigger an Azure Automation runbook to remediate. Which two Azure services should you combine? (Select TWO.)

A.Azure Event Grid
B.Azure Monitor
C.Log Analytics
D.Azure Automation
AnswerB, D

Azure Monitor is the core Azure platform service for collecting metrics, logs, and activity data and for alerting on that telemetry. A metric alert rule in Azure Monitor continuously evaluates resource metric values (e.g., CPU percentage, request count) against a threshold and fires an action group when the condition is met, making it the correct foundation for a monitoring and alerting solution.

Why this answer

Azure Monitor is the correct choice because it collects and analyzes custom performance counters from Azure VMs, enabling metric-based alert rules. When a threshold is exceeded, Azure Monitor can trigger an action group that invokes an Azure Automation runbook, providing automated remediation. This combination directly addresses the requirement to alert on custom counters and execute a runbook in response.

Exam trap

The trap here is that candidates often confuse Log Analytics as a direct alerting and remediation service, when in fact it is a data repository that requires Azure Monitor to evaluate alerts and trigger actions via action groups.

How to eliminate wrong answers

Option A is wrong because Azure Event Grid is a pub-sub event routing service for handling discrete events (e.g., resource state changes), not for continuous metric monitoring or threshold-based alerting on custom performance counters. Option C is wrong because Log Analytics is a data storage and query platform for log and performance data; it does not natively trigger alerts or runbooks directly—it relies on Azure Monitor for alerting and action groups to invoke Automation runbooks.

166
MCQhard

You are designing a monitoring solution for an Azure function app that processes messages from Azure Service Bus. The function app is critical and must be highly available. You need to monitor for poison messages and trigger an alert when the dead-letter queue count exceeds 100. What should you use?

A.Azure Service Bus Explorer
B.Azure Monitor metric alert on the dead-letter message count
C.Azure Log Analytics workspace querying Service Bus logs
D.Azure Application Insights availability tests
AnswerB

An Azure Monitor metric alert can directly target the Service Bus namespace and use the 'Deadlettered Messages' metric (available at queue and subscription levels) to detect when messages are routed to the dead-letter queue. This alert can be configured with a threshold (e.g., a count over 100) and a frequency (e.g., every 5 minutes), and it can trigger action groups that send email, SMS, or webhook calls. Metric alerts are low-latency, simple to configure, and do not require diagnostic settings or log ingestion, making them the most direct and efficient way to monitor dead-letter counts in real time. This is the correct choice because it fulfills the requirement to alert proactively without extra layers.

Why this answer

Azure Monitor metric alerts can directly monitor the 'Dead-letter message count' metric for a Service Bus namespace or entity. When this count exceeds 100, the alert triggers, enabling automated response to poison messages without additional query overhead. This is the most efficient and native monitoring solution for real-time threshold-based alerts on Service Bus metrics.

Exam trap

The trap here is that candidates may overthink and choose Log Analytics (Option C) for its querying flexibility, but the question specifically asks for a threshold-based alert on a single metric, which is exactly what Azure Monitor metric alerts are designed for.

How to eliminate wrong answers

Option A is wrong because Azure Service Bus Explorer is a manual tool for browsing queues and dead-letter queues, not an automated monitoring or alerting mechanism. Option C is wrong because Log Analytics queries require logs to be sent to a workspace, which adds latency and cost; metric alerts are simpler and more immediate for threshold-based monitoring. Option D is wrong because Application Insights availability tests monitor HTTP endpoint availability, not Service Bus dead-letter queue metrics.

167
MCQhard

Refer to the exhibit. You are an Azure administrator for a company that enforces a policy that no virtual networks or network security groups can be created. However, a developer reports that they successfully created a virtual network. What is the most likely reason the policy did not block the creation?

A.The policy definition contains a syntax error.
B.The policy only applies to network security groups, not virtual networks.
C.The policy was assigned to a scope that does not include the subscription or resource group where the virtual network was created.
D.The policy effect should be 'append' instead of 'deny'.
AnswerC

Azure Policy assignments are scoped to management groups, subscriptions, or resource groups, and resources are only evaluated if they fall within that chosen scope. If the virtual network was created in a subscription or resource group that is not covered by the policy assignment (or outside the management group hierarchy), the deny effect never triggers. Even a correctly defined policy with a valid scope only affects resources inside that scope; a virtual network outside it will be created without restriction.

Why this answer

Azure Policy assignments are scoped to a specific management group, subscription, or resource group. If the policy was assigned to a scope that does not include the subscription or resource group where the developer created the virtual network, the policy would not apply, and the creation would succeed. The policy definition itself may be valid, but without proper assignment scope, it cannot enforce the deny effect.

Exam trap

The trap here is that candidates may assume a policy definition automatically applies to all resources in the tenant, but Azure Policy requires explicit assignment to a scope, and without proper scope coverage, the policy has no effect.

How to eliminate wrong answers

Option A is wrong because a syntax error in the policy definition would cause the policy to fail at evaluation time, typically resulting in an error message or the policy being non-functional, but it would not allow the virtual network creation to succeed silently; the policy would either not apply or produce an error. Option B is wrong because the question states the policy enforces that 'no virtual networks or network security groups can be created,' implying the policy definition explicitly includes both resource types; if it only applied to network security groups, the developer would not have been able to create a virtual network, but the scenario says they successfully created a virtual network, which contradicts the policy's stated scope. Option D is wrong because the 'append' effect is used to add additional properties or tags to a resource during creation or update, not to block creation; to deny creation, the correct effect is 'deny', and using 'append' would not prevent the virtual network from being created.

168
MCQhard

Your organization has a complex Azure environment with multiple subscriptions. You need to design a governance strategy that ensures: 1) All resources must have specific tags (CostCenter, Environment, Owner). 2) Any resource without required tags must be reported to the compliance team weekly. 3) Virtual machines must not be deployed in certain regions due to data sovereignty. 4) The solution must be automated and use native Azure services. You already have an Azure Log Analytics workspace and a central automation account. What should you include in the design?

A.Use Azure Resource Graph queries to find untagged resources and export to CSV manually each week.
B.Use Azure Blueprints to define tags and region restrictions; use Azure Monitor alerts to report non-compliance.
C.Use Azure Policy with 'deny' effect for missing tags and an Azure Automation runbook to add tags weekly.
D.Use Azure Policy with 'audit' effect for missing tags and region restriction; use Azure Logic Apps triggered by a schedule to query Azure Resource Graph and email the compliance report.
AnswerD

The 'audit' effect allows resource creation but records non-compliance, making it suitable for both existing and new resources that violate tag and region rules. A scheduled Logic App can run Azure Resource Graph queries (such as selecting resources where tags is empty or location is not in the allowed list), format the result set, and send an email report. This gives an automated, auditable, and repeatable compliance reporting mechanism that scales across complex environments.

Why this answer

It uses Azure Policy with 'audit' effect to detect missing tags and region violations without blocking deployment, which satisfies the reporting requirement. Azure Logic Apps, triggered on a schedule, queries Azure Resource Graph to identify non-compliant resources and sends an email report to the compliance team weekly, fulfilling the automation and native service criteria without manual intervention.

Exam trap

The trap here is that candidates often choose 'deny' effect (Option C) thinking it enforces compliance, but the question explicitly requires reporting non-compliance, not blocking resources, making 'audit' the correct effect for this scenario.

How to eliminate wrong answers

Option A is wrong because manually exporting to CSV each week violates the 'automated' requirement and does not use native Azure services for reporting. Option B is wrong because Azure Blueprints cannot enforce runtime region restrictions or tag requirements; they only define initial resource templates, and Azure Monitor alerts are not designed to query resource compliance or generate tag-based reports. Option C is wrong because using Azure Policy with 'deny' effect would block deployment of untagged resources, but the requirement is to report non-compliance, not prevent it; additionally, an Automation runbook adding tags weekly does not address the region restriction or the weekly reporting to the compliance team.

169
MCQeasy

Your company has multiple Azure subscriptions. You need to ensure that all security-related logs from Azure resources are centralized in a single Log Analytics workspace for analysis. Which Azure service should you use to collect and route these logs?

A.Azure Monitor
B.Microsoft Sentinel
C.Azure Policy
D.Azure Event Hubs
AnswerC

Azure Policy provides a governance control plane that can evaluate and enforce resource configuration at scale, and the built-in 'Deploy Diagnostic Settings to Log Analytics Workspace' initiative or a custom DeployIfNotExists policy will automatically create and remediate diagnostic settings on each supported resource. You can assign that initiative to a management group containing multiple subscriptions, and policy remediation tasks will continuously bring non-compliant resources back into compliance. This makes Azure Policy the correct tool because it enforces, rather than merely observes or analyzes, the routing of resource logs to a central workspace.

Why this answer

Azure Policy is correct because it can enforce the deployment of a diagnostic setting on all Azure resources, automatically routing security-related logs (such as Activity Logs, resource logs, and audit logs) to a single Log Analytics workspace. This ensures centralized collection and analysis without manual configuration per resource, meeting the requirement for a governance-driven approach.

Exam trap

The trap here is that candidates often confuse Azure Policy with Azure Monitor or Sentinel, thinking that monitoring or SIEM tools handle log routing, when in fact Azure Policy is the governance tool that enforces the configuration to centralize logs.

How to eliminate wrong answers

Option A is wrong because Azure Monitor is the platform that collects and analyzes telemetry, but it does not itself route or enforce the collection of logs from multiple subscriptions; it relies on diagnostic settings or other services to ingest data. Option B is wrong because Microsoft Sentinel is a SIEM that uses Log Analytics as its underlying data store, but it is not the service that collects or routes logs—it consumes data already in the workspace. Option D is wrong because Azure Event Hubs is a real-time data streaming service used for high-throughput ingestion, not for centralized log storage or analysis; it would require additional configuration to forward logs to Log Analytics.

170
MCQhard

You are tasked with ensuring that all VMs in the subscription have Azure Hybrid Benefit enabled for Windows Server. You create the Azure Policy shown in the exhibit. However, after assignment, the compliance report shows that some D-series VMs are still non-compliant. What is the most likely cause?

A.The 'deny' effect is incorrectly configured; it should be 'audit' to show compliance.
B.The policy does not apply to existing resources; it only blocks new or updated ones.
C.The 'like' operator does not match standard D-series SKUs.
D.The policy is scoped to a management group that excludes the resource group containing the VMs.
AnswerB

Azure Policy's deny effect operates during create and update operations through the Azure Resource Manager, but it never retroactively changes or removes existing resources. When the policy is assigned, existing VMs are scanned for compliance and will show as 'Non-compliant,' yet they remain running because deny only prevents a request from succeeding. To make existing VMs compliant, you must pair the policy with a DeployIfNotExists/Modify remediation task or manually redeploy them with the approved SKU.

Why this answer

Azure Policy with the 'deny' effect only blocks new or updated resources that violate the policy; it does not automatically remediate existing non-compliant resources. The D-series VMs were likely created before the policy was assigned, so they remain non-compliant until they are redeployed or a remediation task is triggered. To enforce compliance on existing resources, you would need to use a 'deployIfNotExists' or 'modify' effect with a remediation task.

Exam trap

The trap here is that candidates often assume Azure Policy automatically applies to all resources in scope, but they overlook the fundamental difference between 'deny' (only blocks new/updated resources) and 'deployIfNotExists'/'modify' (can remediate existing resources).

How to eliminate wrong answers

Option A is wrong because changing the effect from 'deny' to 'audit' would not make existing VMs compliant; it would only change the compliance state from 'Non-compliant' to 'Non-compliant' (audit reports non-compliance without blocking). Option B is correct as explained. Option C is wrong because the 'like' operator with pattern 'Standard_D*' correctly matches all D-series SKUs (e.g., Standard_D2s_v3, Standard_D4s_v5), as the wildcard '*' matches any suffix.

Option D is wrong because if the policy were scoped to a management group that excludes the resource group, the VMs would not be evaluated at all and would not appear in the compliance report as non-compliant; they would simply be out of scope.

171
MCQhard

A SaaS application must allow external partner users to sign in with their own organization credentials while the company controls application access. What should be used?

A.Create local cloud-only accounts for every partner user
B.Share one account per partner company
C.Use Azure DNS private zones
D.Microsoft Entra External ID/B2B collaboration with Conditional Access
AnswerD

Microsoft Entra External ID/B2B collaboration is the correct architecture because partner users authenticate against their own identity provider—be it Microsoft Entra, Google, or a SAML/WS-Fed IdP—while the resource tenant issues a token and applies its own access controls. Conditional Access policies then run at sign-in for each guest, enabling MFA, session risk, and device compliance checks without suddenly locking out valid partners. This design preserves user-level auditability with access reviews and entitlement management, so a partner user's access can be individually granted and revoked. It is the Azure-native way to meet the external-partner expectation, unlike the other options.

Why this answer

Microsoft Entra External ID (formerly Azure AD B2B) enables external partner users to sign in using their own organization's credentials (their existing Azure AD or Microsoft account) while the company retains control over application access. By combining B2B collaboration with Conditional Access policies, the company can enforce MFA, device compliance, or location-based controls on guest users without managing their identities or passwords.

Exam trap

The trap here is that candidates confuse Azure DNS private zones (a networking feature) with identity federation, or assume that creating local accounts or sharing accounts is acceptable for external collaboration, ignoring the security and manageability requirements of the scenario.

How to eliminate wrong answers

Option A is wrong because creating local cloud-only accounts for every partner user defeats the purpose of federated identity, introduces password management overhead, and violates the requirement that partners use their own credentials. Option B is wrong because sharing one account per partner company eliminates individual accountability, violates security best practices (no audit trail per user), and cannot enforce per-user Conditional Access policies. Option C is wrong because Azure DNS private zones are a networking feature for resolving custom domain names within virtual networks; they have no role in identity federation or external authentication.

172
MCQmedium

You are a solutions architect for a large healthcare organization that uses Microsoft 365 and Azure. The organization has a Microsoft Entra ID tenant with 15,000 users. The security team requires that all users use multi-factor authentication (MFA) when accessing cloud applications. Currently, only 60% of users have registered for MFA. The organization wants to enforce MFA registration for all users within 30 days. The solution must minimize user disruption and allow users to register their MFA methods during their normal work hours. The organization uses Microsoft Intune for mobile device management and has a conditional access policy that requires MFA for all cloud apps. You need to design a solution to enforce MFA registration. What should you do?

A.Modify the existing conditional access policy to require MFA for all cloud apps and block access if MFA is not registered.
B.Deploy an Intune compliance policy that requires MFA enrollment on mobile devices.
C.Configure a Microsoft Entra ID MFA registration campaign to target all users and require registration within 14 days.
D.Use Microsoft Entra ID password reset policy to force users to register MFA during password reset.
AnswerC

The Microsoft Entra ID MFA registration campaign is the purpose-built feature to drive adoption by targeting all users, setting a required registration deadline (e.g., 14 days), and gradually reminding them to register without immediately blocking access. Users can snooze or delay the prompt for a limited time, which avoids disruption while still moving the entire tenant toward MFA readiness. This campaign works alongside conditional access policies and is the recommended first step before enforcing MFA for all cloud apps.

Why this answer

A Microsoft Entra ID MFA registration campaign is specifically designed to nudge users to register for MFA with a configurable deadline (up to 14 days) without immediately blocking access. This minimizes disruption by allowing users to register during normal work hours, and it integrates with existing Conditional Access policies that require MFA for cloud apps.

Exam trap

The trap here is confusing enforcement of MFA at sign-in (Conditional Access) with the proactive registration workflow (MFA registration campaign), leading candidates to choose Option A which would cause immediate disruption instead of a phased, user-friendly registration process.

How to eliminate wrong answers

Option A is wrong because modifying the existing Conditional Access policy to block access if MFA is not registered would immediately lock out the 40% of users who haven't registered, causing massive disruption and violating the requirement to minimize user disruption. Option B is wrong because an Intune compliance policy that requires MFA enrollment on mobile devices only applies to mobile devices managed by Intune, not to all 15,000 users accessing cloud apps from any device, and it does not enforce registration within 30 days. Option D is wrong because using the Microsoft Entra ID password reset policy to force MFA registration during password reset only applies when users initiate a password reset, which is not a guaranteed event within 30 days for all users, and it does not proactively enforce registration for all users.

173
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID) Premium P2. They want to enforce that users accessing sensitive cloud applications from outside the corporate network must use multi-factor authentication (MFA). Which Microsoft Entra ID feature should they configure?

A.Conditional Access
B.Identity Protection
C.Privileged Identity Management
D.Access Reviews
AnswerA

Conditional Access is the correct answer because it is the policy engine that evaluates sign-in signals—such as user, group, location, device compliance, and session risk—and can require MFA for every user by creating a policy targeting 'All users' with the 'Require authentication strength' or 'Require multifactor authentication' grant control. It is tightly integrated with Entra ID Protection risk signals, allowing MFA to be enforced conditionally or universally, and supports excluding emergency access accounts to avoid lockout.

Why this answer

Conditional Access is the correct feature because it allows administrators to define policies that enforce MFA based on specific conditions, such as network location (outside corporate network) and cloud app sensitivity. By configuring a Conditional Access policy targeting 'All cloud apps' or specific sensitive apps with the condition 'Locations: All trusted/untrusted networks', you can require MFA for external access. This directly meets the requirement without needing additional licenses or features beyond Entra ID Premium P2.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based MFA triggers with Conditional Access's location-based MFA, assuming Identity Protection alone can enforce MFA for external access, but Identity Protection only suggests or triggers MFA via risk policies that require Conditional Access to actually enforce the block or MFA prompt.

How to eliminate wrong answers

Option B (Identity Protection) is wrong because it focuses on detecting and remediating identity risks (e.g., leaked credentials, sign-ins from anonymous IPs) and can trigger MFA via risk-based policies, but it does not natively enforce MFA based solely on network location; it requires integration with Conditional Access for enforcement. Option C (Privileged Identity Management) is wrong because it manages just-in-time privileged role activation and approval workflows, not general user access to cloud apps or MFA enforcement. Option D (Access Reviews) is wrong because it is used for periodic recertification of group memberships and application access, not for real-time authentication enforcement like MFA.

174
MCQmedium

A company has Microsoft Entra ID Premium P2 licenses and wants to ensure that privileged roles (e.g., Global Administrator) are only activated when needed and with approval. They also need to regularly review who has access to these roles. Which combination of features should they use?

A.Privileged Identity Management (PIM) and Microsoft Entra ID Access Reviews
B.Identity Protection and Conditional Access
C.Entitlement Management and Conditional Access
D.Microsoft Entra ID Access Reviews and Identity Protection
AnswerA

PIM is the correct core service because it provides just-in-time, time-bound activation of privileged Microsoft Entra roles with approval workflows and audit trails, which directly satisfies the requirement to ensure privileged access is controlled. Access Reviews complements PIM by enabling recurring recertification of role assignments, so administrators can automatically remove or keep access based on attestation. Together they fulfill both activation governance and periodic review, making this combination the only one that fully addresses the stated requirement.

Why this answer

Privileged Identity Management (PIM) provides just-in-time (JIT) activation of privileged roles with approval workflows, meeting the requirement for activation only when needed and with approval. Microsoft Entra ID Access Reviews then enable recurring certification of role assignments, ensuring that access is regularly reviewed and stale or inappropriate assignments are removed. Together, they form the correct combination for managing and governing privileged roles.

Exam trap

The trap here is that candidates often confuse Identity Protection (risk-based detection) with PIM (role activation and governance), leading them to select options that include Identity Protection instead of PIM for privileged role management.

How to eliminate wrong answers

Option B is wrong because Identity Protection focuses on detecting and remediating identity-based risks (e.g., compromised credentials, sign-in anomalies) and Conditional Access enforces access policies based on signals; neither provides JIT activation with approval or recurring access reviews for privileged roles. Option C is wrong because Entitlement Management manages access packages and resource access for external users and groups, not specifically privileged role activation with approval; Conditional Access does not provide role activation or review capabilities. Option D is wrong because while Access Reviews are correct, Identity Protection does not offer JIT activation or approval workflows for privileged roles, leaving the core requirement unmet.

175
MCQeasy

Your company uses Microsoft Entra ID and has recently deployed Microsoft Sentinel. You need to design a monitoring solution to detect brute-force attacks against user accounts. The solution should use built-in analytics rules where possible and must trigger an automated response to temporarily disable the affected account. What should you include in the design?

A.Use the built-in 'Brute force attack against an Entra ID account' analytics rule in Microsoft Sentinel and connect a playbook to disable the user.
B.Use Microsoft Entra Identity Protection to detect brute-force and configure a conditional access policy to block sign-ins.
C.Stream sign-in logs to Log Analytics and create a scheduled query that alerts on multiple failures, then manually disable accounts.
D.Create a custom KQL query in Microsoft Sentinel and configure an automation rule to disable the account.
AnswerA

The Microsoft Sentinel built-in analytics rule 'Brute force attack against an Entra ID account' already contains the KQL detection logic needed to identify repeated failed sign-ins and other brute-force indicators in Entra ID sign-in logs. By triggering an automation rule on the alert, you can invoke a Microsoft Sentinel playbook—an Azure Logic Apps workflow—that automatically disables the compromised user account. This provides both automated detection and automated response, satisfying the requirement to use built-in rules whenever possible.

Why this answer

Microsoft Sentinel includes a built-in analytics rule specifically for detecting brute-force attacks against Microsoft Entra ID accounts. By connecting a playbook to this rule, you can automate the response to temporarily disable the affected user account, meeting the requirement for an automated response without custom development.

Exam trap

The trap here is that candidates may confuse Microsoft Entra Identity Protection's ability to block sign-ins with the requirement to disable the user account, or they may overlook the 'use built-in analytics rules where possible' constraint and opt for a custom KQL query.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra Identity Protection detects risk events like brute-force but uses Conditional Access policies to block sign-ins, not to disable user accounts; disabling accounts requires a different mechanism. Option C is wrong because it relies on manually disabling accounts, which does not meet the requirement for an automated response. Option D is wrong because it suggests creating a custom KQL query and automation rule, but the question specifies using built-in analytics rules where possible, making a custom query unnecessary and less efficient.

176
MCQeasy

A company wants to allow remote users to access an internal web application hosted on-premises without opening inbound firewall ports. They need seamless single sign-on (SSO) using Microsoft Entra ID credentials. Which Azure service should they use?

A.Microsoft Entra ID Application Proxy
B.Microsoft Entra ID B2C
C.Microsoft Entra ID Domain Services
D.Microsoft Entra ID Connect
AnswerA

Microsoft Entra ID Application Proxy is a reverse proxy that securely publishes on-premises web applications to remote users through the Microsoft Entra ID service. It uses a lightweight connector on the internal network that initiates outbound connections, eliminating the need for inbound firewall ports or VPN. This enables seamless single sign-on and integration with Conditional Access policies, making it the ideal solution for internal app access.

Why this answer

Microsoft Entra ID Application Proxy provides secure remote access to on-premises web applications without requiring inbound firewall ports. It works by establishing an outbound connection from the on-premises Application Proxy connector to the Entra ID service, then routing user traffic through that tunnel. It integrates with Entra ID for pre-authentication and supports seamless SSO using the user's existing Entra ID credentials via Kerberos constrained delegation (KCD) or header-based authentication.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID Application Proxy with a VPN or DirectAccess solution, but the key differentiator is that Application Proxy requires no inbound firewall rules and uses outbound-only connectivity, which is a common exam scenario for secure remote access.

How to eliminate wrong answers

Option B (Microsoft Entra ID B2C) is wrong because it is designed for customer-facing identity management with social or local accounts, not for providing secure remote access to internal on-premises applications. Option C (Microsoft Entra ID Domain Services) is wrong because it provides managed domain services (e.g., LDAP, Kerberos) for Azure VMs but does not offer a reverse proxy or remote access capability for on-premises apps. Option D (Microsoft Entra ID Connect) is wrong because it is a synchronization tool that syncs on-premises AD objects to Entra ID; it does not provide any application proxy or remote access functionality.

177
Multi-Selectmedium

Which TWO actions should you take to design a monitoring solution for a multi-tier application running on Azure VMs? (Select TWO.)

Select 2 answers
A.Deploy VM Insights on each VM
B.Configure Azure Monitor Agent to collect metrics and logs from each tier
C.Create a Log Analytics workspace and connect all VMs
D.Instrument the application with Application Insights
E.Enable Azure Monitor for VMs on all VMs
AnswersB, D

Configuring the Azure Monitor Agent (AMA) is the foundational action for infrastructure monitoring because AMA collects metrics and logs from VMs in each tier and sends them to Azure Monitor Metrics and Log Analytics workspaces. Using data collection rules (DCRs), you can define exactly which counters and logs to capture per workload. This directly addresses the requirement to monitor all tiers, making it a correct primary action.

Why this answer

Azure Monitor Agent is the modern, unified agent that collects metrics and logs from Azure VMs and sends them to Azure Monitor, Log Analytics workspaces, and other destinations. For a multi-tier application, collecting data from each tier is essential for end-to-end monitoring. Option D is correct because Application Insights provides application performance monitoring (APM) by instrumenting the application code itself, capturing telemetry like request rates, dependency calls, and exceptions, which is critical for understanding the behavior of a multi-tier application.

Exam trap

The trap here is that candidates confuse 'VM Insights' (a feature that provides visualizations and dependency mapping) with the underlying agent installation, or they think that creating a Log Analytics workspace is a primary monitoring action rather than a prerequisite, leading them to select options A, C, or E instead of the correct combination of agent-based collection and application instrumentation.

178
MCQmedium

Your organization uses Microsoft Sentinel for security monitoring. You need to create a rule that triggers an incident when a user from a specific IP address performs more than 10 failed sign-ins within an hour. Which rule type should you use?

A.Microsoft Security rule
B.Scheduled query rule
C.Anomaly detection rule
D.Fusion rule
AnswerB

A scheduled query rule is the correct choice because it periodically executes a KQL query over a defined lookback window and evaluates the results against an alert condition. You can aggregate events with operators such as 'summarize count() by User, bin(TimeGenerated, 5m)' and design the query to return rows only when that aggregated count exceeds the desired threshold, such as five failed logins. The rule's configurable run frequency, lookback period, and alert settings make it the standard Sentinel mechanism for deterministic event-count threshold detection.

Why this answer

A scheduled query rule is the correct choice because it allows you to define a custom KQL query that counts failed sign-in events from a specific IP address over a 1-hour window and triggers an incident when the count exceeds 10. This rule type is designed for user-defined detection logic based on log data, such as SigninLogs, and supports aggregation and threshold-based alerting.

Exam trap

The trap here is that candidates confuse scheduled query rules with anomaly detection rules, assuming any threshold-based alert is 'anomaly detection,' but anomaly detection requires baseline learning and cannot enforce a static numeric threshold like 10.

How to eliminate wrong answers

Option A is wrong because Microsoft Security rules are prebuilt templates from Microsoft security products (e.g., Microsoft Defender for Cloud) and cannot be customized to count specific IP addresses or set custom thresholds like 10 failed sign-ins per hour. Option C is wrong because anomaly detection rules use machine learning to identify unusual patterns in baseline behavior, not fixed thresholds on a specific IP address. Option D is wrong because Fusion rules correlate multiple low-fidelity alerts from different sources to detect advanced multi-stage attacks, not single-condition threshold-based triggers.

179
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to enable users to reset their own passwords without contacting the help desk. They also want to enforce multi-factor authentication (MFA) during the password reset process. Which Microsoft Entra ID feature should they enable?

A.Microsoft Entra ID Identity Protection
B.Microsoft Entra ID Privileged Identity Management (PIM)
C.Microsoft Entra ID Self-Service Password Reset (SSPR)
D.Microsoft Entra ID Conditional Access
AnswerC

SSPR is the Microsoft Entra ID feature purpose-built for end users to unlock or reset their own passwords without helpdesk intervention, and it can enforce multi-factor authentication as part of the reset flow. When combined with the combined registration experience, users register their MFA methods once, and administrators can require two or more verification methods in the SSPR policy, meaning the user must prove possession of multiple factors before the password is changed. This directly satisfies both the need for self-service reset and the need to enforce MFA during that reset, because the verification gate is an integral part of SSPR itself.

Why this answer

Microsoft Entra ID Self-Service Password Reset (SSPR) enables users to reset their own passwords without help desk intervention. When combined with Microsoft Entra ID Conditional Access, SSPR can enforce multi-factor authentication (MFA) during the password reset process, meeting both requirements.

Exam trap

The trap here is that candidates often confuse Conditional Access as the sole solution for password reset, but Conditional Access only enforces policies on top of SSPR; without SSPR enabled, users cannot reset their own passwords at all.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Identity Protection is a risk-based detection and remediation tool that identifies potential vulnerabilities and suspicious activities, but it does not directly enable self-service password reset or enforce MFA during password reset. Option B is wrong because Microsoft Entra ID Privileged Identity Management (PIM) manages just-in-time privileged access and role activation, not self-service password reset or MFA enforcement for end users. Option D is wrong because Microsoft Entra ID Conditional Access is a policy engine that enforces access controls (like MFA) based on conditions, but it does not provide the self-service password reset capability itself; it can only be used to secure the SSPR process.

180
MCQmedium

A multinational company uses Microsoft Entra ID for identity. They need to grant external partners access to specific SharePoint Online sites. The access must be time-limited and require approval from a resource owner. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Entitlement Management.
B.Microsoft Entra ID B2C.
C.Microsoft Entra ID Conditional Access.
D.Microsoft Entra ID Identity Protection.
AnswerA

Entitlement Management is an identity governance feature that lets administrators create access packages containing SharePoint Online sites, Teams, and other resources, and publish them to internal or external users. Policies within an access package define who can request access, who must approve, and when the access expires, enabling time-limited collaboration. For external partners, it supports Connected Organizations and identity providers including Google and Microsoft accounts, automatically removing access when the policy ends. This directly provides the request/approval/expiration workflow needed for the scenario.

Why this answer

Microsoft Entra ID Entitlement Management (A) is the correct feature because it enables organizations to manage external partner access to resources like SharePoint Online sites through access packages. These access packages can enforce time-limited access and require approval from designated resource owners, directly meeting the scenario's requirements.

Exam trap

The trap here is that candidates may confuse Entitlement Management (which handles external user access governance) with B2C (which is for customer-facing apps) or Conditional Access (which is a security policy layer, not a provisioning workflow).

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID B2C (Business-to-Consumer) is designed for customer-facing identity management with social logins, not for granting external partners access to internal resources like SharePoint sites. Option C is wrong because Microsoft Entra ID Conditional Access enforces policies based on signals like location or device state, but it does not provide time-limited access or approval workflows for external partner access. Option D is wrong because Microsoft Entra ID Identity Protection focuses on detecting and remediating identity risks (e.g., leaked credentials), not on managing external user access with time limits and approvals.

181
MCQeasy

You are designing a monitoring solution for Azure SQL Database. The requirement is to track query performance metrics such as CPU usage, data IO, and wait statistics over time. You need to identify performance bottlenecks and provide historical data for analysis. Which Azure service should you use?

A.Azure Monitor Metrics for Azure SQL Database
B.Azure SQL Analytics (preview) in Azure Monitor
C.Azure SQL Database Intelligent Insights
D.Query Performance Insight for Azure SQL Database
AnswerD

Query Performance Insight for Azure SQL Database is the correct choice because it is the native Azure portal feature designed specifically to surface query-level performance data, including execution count, CPU time, duration, and logical reads per query over a customizable time window. It also displays wait statistics tied to query tuning recommendations, allowing you to pinpoint poorly performing SQL statements and observe their historical trends without requiring additional configuration beyond the database's query store.

Why this answer

Query Performance Insight for Azure SQL Database is the correct choice because it provides built-in, intelligent analysis of top queries by CPU, data IO, and wait statistics over time, enabling you to identify performance bottlenecks and review historical data. It is specifically designed for Azure SQL Database and offers a customizable time range for trend analysis, directly meeting the requirement to track query performance metrics and analyze historical data.

Exam trap

The trap here is that candidates often confuse Azure SQL Analytics (a broader monitoring solution) with Query Performance Insight (a focused query-level tool), or they assume Azure Monitor Metrics provides query-level details when it only offers aggregate resource metrics.

How to eliminate wrong answers

Option A is wrong because Azure Monitor Metrics for Azure SQL Database provides platform-level metrics (e.g., DTU/CPU percentage, storage) but does not offer per-query performance details like wait statistics or historical query-level analysis. Option B is wrong because Azure SQL Analytics (preview) in Azure Monitor is a broader monitoring solution that aggregates metrics and logs across multiple Azure SQL databases, but it does not provide the granular, query-specific historical performance data and wait statistics that Query Performance Insight offers. Option C is wrong because Azure SQL Database Intelligent Insights uses built-in intelligence to automatically detect and alert on performance issues, but it does not provide the detailed, customizable historical query performance metrics (CPU, IO, wait stats) that are needed for manual bottleneck analysis.

182
MCQhard

Refer to the exhibit. You are a security administrator reviewing a custom Azure Policy assignment. The policy definition with ID 'abc123' is an initiative containing two policies: one that audits storage accounts with blob public access enabled and one that deploys a diagnostic setting for network security groups. The scope includes a production resource group. However, the compliance state shows 'Non-compliant' for several resources. What is the most likely reason for the non-compliance?

A.The scope is incorrectly targeting the resource group, missing the subscription.
B.The audit policy is preventing the creation of storage accounts with public access.
C.The enforcement mode is set to 'Default' which disables policy evaluation.
D.The diagnostic setting deployment policy requires a remediation task to bring non-compliant resources into compliance.
AnswerD

A DeployIfNotExists policy is designed to deploy a resource when the policy condition is met, but it does not automatically apply the deployment during evaluation. After the evaluation cycle, the policy enters a non-compliant state and a remediation task must be run to deploy the diagnostic setting to the storage account. Without that remediation task, even though the policy is correctly assigned and enforced, the configuration remains missing. Hence, the storage account lacks the diagnostic setting because the needed remediation task has not been executed.

Why this answer

The policy that deploys a diagnostic setting for network security groups is a 'DeployIfNotExists' (DINE) policy. DINE policies do not automatically remediate existing non-compliant resources; they require a remediation task to be created and run, which will deploy the diagnostic settings to bring the resources into compliance. The audit-only policy for storage accounts does not require remediation, but the DINE policy's non-compliance indicates that the diagnostic settings are missing and need to be deployed via a remediation task.

Exam trap

The trap here is that candidates often assume all policy effects (like 'DeployIfNotExists') automatically remediate non-compliant resources, but in reality, they only mark non-compliance and require a separate remediation task to deploy the required configuration.

How to eliminate wrong answers

Option A is wrong because the scope includes the production resource group, which is a valid scope for policy assignment; missing the subscription is not an issue as policies can be assigned at the management group, subscription, or resource group level. Option B is wrong because an audit policy only evaluates and reports compliance; it does not prevent creation or enforce any action, so it cannot be the reason for non-compliance. Option C is wrong because the 'Default' enforcement mode does not disable policy evaluation; it enables evaluation and enforcement, whereas 'Disabled' mode would disable evaluation.

183
MCQhard

A large enterprise wants to enforce zero-trust conditional access policies that use real-time user risk, sign-in risk, and device compliance. Which combination of Microsoft Entra ID features should they use?

A.Microsoft Entra ID Identity Protection and Conditional Access
B.Microsoft Entra ID Privileged Identity Management and Access Reviews
C.Microsoft Entra ID B2B and External Identities
D.Microsoft Entra ID Domain Services and Managed Identities
AnswerA

Identity Protection evaluates millions of signals per sign-in to calculate user and sign-in risk, detecting anomalies such as leaked credential use, impossible travel, and anomalous token behavior. Conditional Access then consumes those risk signals in real time to enforce step-up authentication (e.g., MFA or password change) or block access entirely, operationalizing zero trust at the identity plane with adaptive, context-aware policies.

Why this answer

Microsoft Entra ID Identity Protection provides real-time risk detection for users and sign-ins, while Conditional Access policies can enforce access controls based on those risk signals and device compliance. Together, they enable zero-trust conditional access by blocking or requiring MFA when user or sign-in risk is high, and ensuring only compliant devices can access resources.

Exam trap

The trap here is that candidates confuse Privileged Identity Management (PIM) with risk-based conditional access, but PIM only manages role activation and does not evaluate user/sign-in risk or device compliance in real time.

How to eliminate wrong answers

Option B is wrong because Privileged Identity Management (PIM) and Access Reviews focus on just-in-time privileged role activation and periodic attestation, not on real-time user/sign-in risk or device compliance. Option C is wrong because B2B and External Identities are designed for guest user collaboration and identity federation, not for enforcing risk-based conditional access policies on internal users. Option D is wrong because Azure AD Domain Services provides managed domain services (like LDAP, Kerberos) for legacy apps, and Managed Identities are used for Azure resource authentication, neither of which offer risk detection or conditional access enforcement.

184
Multi-Selectmedium

You are designing an identity lifecycle management solution for a multinational company. Employees frequently change departments, and you need to automate the assignment and removal of application access based on their current department. Which THREE Microsoft Entra features should you use?

Select 3 answers
A.Dynamic membership groups
B.Microsoft Entra Privileged Identity Management
C.Microsoft Entra access reviews
D.Microsoft Entra entitlement management
E.Microsoft Entra self-service password reset
AnswersA, C, D

Dynamic membership groups in Microsoft Entra ID automatically add and remove user accounts based on rule expressions evaluated against attributes like department, jobTitle, or country. Because membership is recalculated whenever an attribute changes or a user signs in, access to the group's linked applications is granted or revoked immediately without manual intervention. For an identity lifecycle solution centered on automating access based on organizational attributes, dynamic groups are the most direct choice.

Why this answer

Dynamic membership groups (A) are correct because they automatically add or remove users based on attribute values like 'department'. When an employee changes departments, their department attribute is updated, and the group membership is recalculated, granting or revoking access to applications assigned to that group. This is the core mechanism for automating access changes based on user attributes.

Exam trap

The trap here is confusing Privileged Identity Management (PIM) with lifecycle management—PIM handles temporary elevation for admin roles, not the ongoing assignment of application access based on user attribute changes.

185
MCQmedium

A company wants to configure policies that detect risky sign-ins (e.g., from anonymous IPs or unfamiliar locations) and automatically require multi-factor authentication (MFA) when such risk is detected. Which Microsoft Entra ID feature should they use to create these policies?

A.Microsoft Entra ID Conditional Access
B.Microsoft Entra ID Identity Protection
C.Microsoft Entra ID Privileged Identity Management
D.Microsoft Entra ID Audit Logs
AnswerA

Conditional Access is the actual enforcement layer in Microsoft Entra ID that consumes risk signals, including sign-in risk scores generated by Identity Protection, and applies real-time policies. With conditions such as user risk or sign-in risk, it can require MFA, block access from anonymous IP addresses, or force password change. This policy-based action is exactly what is needed to 'configure policies that detect risky sign-ins' from anonymous sources.

Why this answer

Microsoft Entra ID Conditional Access is the correct feature because it allows administrators to create policies that evaluate sign-in risk signals (such as anonymous IP addresses or unfamiliar locations) and enforce access controls like requiring multi-factor authentication (MFA). Conditional Access policies can integrate with Identity Protection risk detections, but the policy itself is defined and managed within the Conditional Access blade, making it the direct tool for this requirement.

Exam trap

The trap here is that candidates often confuse Identity Protection (which detects risk) with Conditional Access (which enforces the policy), leading them to select Identity Protection as the answer when the question explicitly asks for the feature that 'creates policies' to require MFA.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID Identity Protection detects and reports risky sign-ins and users (e.g., via risk events like anonymous IP address or unfamiliar sign-in properties), but it does not itself enforce access controls like requiring MFA; it relies on Conditional Access policies to act on those risk detections. Option C is wrong because Microsoft Entra ID Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not risk-based sign-in policies or MFA enforcement. Option D is wrong because Microsoft Entra ID Audit Logs provide a record of sign-in and administrative activities for monitoring and compliance, but they cannot be used to create proactive policies that detect risk and enforce MFA.

186
Multi-Selectmedium

Which TWO actions can be performed using Microsoft Entra ID Governance? (Choose two.)

Select 2 answers
A.Synchronize users from on-premises Active Directory
B.Manage access packages for internal and external users
C.Perform access reviews of group memberships
D.Configure network security group rules
E.Deploy virtual machines in Azure
AnswersB, C

Managing access packages is a flagship capability of Microsoft Entra ID Governance, delivered through Entitlement Management. It enables administrators to create catalogs of resources (groups, apps, sites), define request-and-approval workflows, set time-bound assignments, and handle automatic revocation. This feature is explicitly designed to govern access for both internal employees and external collaborators, ensuring access matches business need and is auditable.

Why this answer

Microsoft Entra ID Governance includes entitlement management, which allows administrators to create and manage access packages that bundle resources (like groups, apps, and SharePoint sites) and assign them to internal and external users. This enables automated lifecycle management of access, including expiration and renewal, making Option B correct.

Exam trap

The trap here is that candidates confuse Entra ID Governance's access review capability (Option C) with a separate feature, but both B and C are correct; the question asks for two actions, and the trap is that some might think only one of these is valid, or they might incorrectly select A because synchronization is a common identity task, but it's not a governance action.

187
Multi-Selectmedium

Which TWO are benefits of using Microsoft Entra ID Governance? (Choose two.)

Select 2 answers
A.Automate the deprovisioning of user accounts when an employee leaves the organization
B.Implement entitlement management for access request workflows
C.Enable just-in-time privileged access to Azure resources
D.Provide single sign-on to all SaaS applications
E.Provide VPN connectivity for remote users
AnswersA, B

Automating deprovisioning when an employee leaves is a core identity lifecycle workflow in Entra ID Governance. This workflow integrates with HR systems to trigger account and access removal in near real time, eliminating the risk of orphaned accounts and security breaches. It also generates audit logs for compliance, ensuring that departed staff cannot retain access to sensitive resources.

Why this answer

Option A is correct because Microsoft Entra ID Governance includes lifecycle workflows that automate the joiner-mover-leaver process, including automatically disabling or deleting user accounts and revoking access when an employee leaves the organization. Option B is correct because entitlement management is a core capability of Entra ID Governance, providing access packages, catalogs, and approval-based access request workflows so users can request and be granted time-bound access. Option C is not correct because just-in-time privileged access to Azure resources is delivered by Microsoft Entra Privileged Identity Management (PIM), which is a separate product from Entra ID Governance.

Option D is not correct because single sign-on to SaaS applications is a core Microsoft Entra ID feature (via SAML/OIDC enterprise applications), not a specific benefit of Entra ID Governance. Option E is not correct because VPN connectivity for remote users is provided by Azure VPN Gateway or similar networking services, not by Entra ID Governance.

Exam trap

The trap here is that candidates confuse the overlapping capabilities of Microsoft Entra ID, Entra ID Governance, and Privileged Identity Management (PIM), mistakenly attributing JIT access or SSO to governance when they belong to separate services within the Microsoft Entra portfolio.

188
Multi-Selecthard

Which THREE conditions should be met to implement a successful Azure landing zone for a new enterprise subscription? (Choose three.)

Select 3 answers
A.A dedicated Azure Active Directory tenant.
B.A management group hierarchy that separates environments.
C.Microsoft Sentinel enabled for security monitoring.
D.A defined network topology with connectivity to on-premises.
E.A subscription vending process to automate creation.
AnswersB, D, E

Management groups form the backbone of governance in a landing zone by enabling role assignments and Azure Policy to be inherited down to the subscription level. Separating environments (such as production, non-production, and shared) into distinct hierarchy branches allows cloud admins to enforce different compliance and cost controls per environment. This hierarchy is a prerequisite in the Azure landing zone accelerator because it provides the structural placement point for policy and RBAC.

Why this answer

A management group hierarchy that separates environments (e.g., production, non-production, and management) is a core design principle of an Azure landing zone. It enables policy inheritance, role-based access control (RBAC) isolation, and cost tracking across different workloads, aligning with the Cloud Adoption Framework's governance best practices.

Exam trap

The trap here is that candidates often confuse optional security tools like Microsoft Sentinel or dedicated tenants as mandatory prerequisites, when the Azure landing zone's success hinges on governance structure (management groups), network connectivity (hub-spoke topology), and automation (subscription vending).

189
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID) and Microsoft Intune. They want to block all access to internal corporate applications from devices that are not enrolled in Intune and do not meet the company's compliance policies. The solution must apply to all cloud app access seamlessly. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra ID Conditional Access
B.Microsoft Entra ID Identity Protection
C.Microsoft Entra ID Privileged Identity Management
D.Microsoft Entra ID Access Reviews
AnswerA

Microsoft Entra ID Conditional Access is the correct tool because it evaluates signal-rich policies at every authentication event, including the user's device state, to enforce access decisions. Administrators can create a policy that requires the device to be marked as compliant by Intune or to be hybrid Azure AD joined, blocking sign-ins from non-compliant devices and integrating directly with device compliance signals.

Why this answer

Microsoft Entra ID Conditional Access is the correct feature because it enables you to create policies that evaluate device compliance and enrollment status before granting access to cloud applications. By configuring a Conditional Access policy with a condition requiring devices to be marked as compliant and enrolled in Intune, you can block access from non-compliant or unenrolled devices seamlessly across all integrated cloud apps.

Exam trap

The trap here is that candidates often confuse Identity Protection (which handles risk-based conditional access) with Conditional Access (which handles broader policy conditions like device compliance), leading them to select Identity Protection when the question explicitly requires device enrollment and compliance enforcement.

How to eliminate wrong answers

Option B (Microsoft Entra ID Identity Protection) is wrong because it focuses on detecting and responding to identity-based risks (e.g., leaked credentials, sign-ins from anonymous IPs) rather than enforcing device compliance or enrollment requirements. Option C (Microsoft Entra ID Privileged Identity Management) is wrong because it manages just-in-time privileged role assignments and access reviews for administrative roles, not device-level access controls for all users. Option D (Microsoft Entra ID Access Reviews) is wrong because it automates periodic attestation of group memberships or application access, but does not enforce real-time device compliance checks at the point of authentication.

190
Multi-Selectmedium

A company is designing a governance solution for a large Azure environment with multiple subscriptions. They need to ensure that all resources are deployed only in approved Azure regions and that all resources have a specific tag 'CostCenter'. They also need to be able to delegate management of policies to individual business units while maintaining central control. Which two features should be included in the design? (Choose two.)

Select 2 answers
A.Management groups to organize subscriptions and apply policies hierarchically.
B.Role-based access control (RBAC) assignments to restrict who can create resources in certain regions.
C.Azure Blueprints to define and assign policies across subscriptions.
D.Azure Resource Manager templates to enforce tagging and region constraints at deployment time.
E.Azure Policy with a deny effect for allowed locations and a deny effect for required tags.
AnswersA, E

Management groups allow hierarchical organization of subscriptions and inheritance of policies and role assignments. By assigning policies at a management group, all subscriptions inherit them. This provides central control while allowing delegation to business units through separate management groups with their own policies.

Why this answer

Azure Policy with deny effects enforces that resources can only be created in approved regions and must have the required tag. Management groups provide a hierarchical structure to apply these policies across subscriptions and allow delegation to business units while maintaining central oversight. Together, they deliver scalable governance with central control and delegated administration.

Exam trap

The trap here is assuming that RBAC or ARM templates can enforce resource properties like location and tags, when they only control permissions or deployment-time settings, not ongoing compliance.

191
Matchingmedium

Match each Azure service to its primary function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

DNS-based traffic routing

Global HTTP(S) load balancing with WAF

Regional layer-7 load balancer with WAF

Regional layer-4 load balancer

Site-to-site VPN connectivity

Why these pairings

Correct matches: Azure Virtual Network provides private connectivity; Azure Load Balancer distributes traffic. Common confusions mix layer-4 and layer-7 services, and regional vs. global routing.

192
Multi-Selectmedium

Your company uses Microsoft Entra ID for identity management. You need to design a monitoring solution for sign-in logs to detect suspicious activity. Which TWO Azure services should you include in the design?

Select 2 answers
A.Azure Monitor
B.Microsoft Defender for Cloud Apps
C.Microsoft Sentinel
D.Microsoft Purview
E.Log Analytics workspace
AnswersB, C

Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that uses behavioral analytics and UEBA to profile each user's normal sign-in patterns. It can detect impossible-travel behavior, sign-ins from anonymous or risky IPs, and atypical locations or applications, then trigger alerts or conditional access policies based on the calculated risk. Because it is natively integrated with Microsoft Entra ID, it can directly monitor sign-in events and respond to suspicious activities, making it a strong fit for this identity-threat scenario.

Why this answer

Microsoft Defender for Cloud Apps (Option B) is correct because it provides Cloud Access Security Broker (CASB) capabilities that analyze sign-in logs for anomalous behavior, such as impossible travel, suspicious IP addresses, and credential theft. It integrates with Microsoft Entra ID to detect and respond to risky sign-in events in real time, making it a core component for monitoring suspicious activity.

Exam trap

The trap here is that candidates often select Azure Monitor or Log Analytics workspace alone, thinking they can detect suspicious activity, but they lack the built-in threat detection and analytics engines that are specific to security-focused services like Defender for Cloud Apps and Sentinel.

193
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to allow users to sign in to multiple SaaS applications using their Microsoft Entra ID credentials without being prompted again for each application. Which Microsoft Entra ID feature should they enable?

A.Single Sign-On (SSO)
B.Multi-Factor Authentication (MFA)
C.Conditional Access
D.Identity Protection
AnswerA

SSO in Microsoft Entra ID uses the primary authentication token (e.g., SAML, OAuth2/OIDC) to establish a federated session, so subsequent application requests are silently authenticated without re-prompting. This works because Entra ID acts as the trusted broker that issues session cookies or refresh tokens, eliminating per-app credential entry. For this scenario, deploying SSO directly satisfies the requirement for one authentication followed by seamless access across all integrated applications.

Why this answer

Single Sign-On (SSO) enables users to authenticate once with Microsoft Entra ID and then access multiple SaaS applications without being prompted again. This works by using standards like SAML 2.0 or OpenID Connect to issue a session token or cookie that is reused across applications, eliminating repeated credential prompts.

Exam trap

The trap here is that candidates confuse MFA or Conditional Access with SSO, thinking that additional security features inherently reduce sign-in prompts, but in reality, SSO is the specific feature designed to eliminate repeated prompts, while MFA and Conditional Access are complementary security controls that do not provide that functionality.

How to eliminate wrong answers

Option B (Multi-Factor Authentication) is wrong because MFA adds an extra layer of security by requiring a second verification factor, but it does not eliminate repeated sign-in prompts across applications; it actually increases authentication friction. Option C (Conditional Access) is wrong because it is a policy engine that enforces access controls (e.g., requiring MFA or blocking sign-ins from untrusted locations) based on signals, but it does not provide the seamless token reuse that SSO offers. Option D (Identity Protection) is wrong because it is a risk-based detection and remediation service that identifies compromised identities and suspicious sign-ins, not a mechanism to avoid repeated authentication prompts.

194
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to integrate their on-premises Active Directory with Microsoft Entra ID to enable single sign-on (SSO) for cloud applications. Users should be able to use the same password for on-premises resources and cloud applications. The company has a large on-premises user base and wants to avoid additional infrastructure for federation. Which Microsoft Entra ID feature should they implement?

A.Microsoft Entra ID Connect (Password Hash Synchronization)
B.Microsoft Entra ID Application Proxy
C.Microsoft Entra ID B2B
D.Microsoft Entra ID Domain Services
AnswerA

Password Hash Synchronization (PHS) is the correct choice because it synchronizes a cryptographic hash of each on-premises password to Microsoft Entra ID, enabling users to authenticate to cloud SaaS applications with their existing corporate credentials. Unlike federation options, it requires no additional servers or infrastructure and works even if a user's on-premises password changes, as the hash is updated in near-real-time. PHS can be combined with Microsoft Entra Seamless SSO to give a silent sign-in experience on domain-joined devices. This makes it a lightweight, reliable hybrid identity mechanism.

Why this answer

Password Hash Synchronization (PHS) is the correct choice because it synchronizes password hashes from on-premises Active Directory to Microsoft Entra ID, enabling users to use the same password for both on-premises and cloud resources without requiring any additional federation infrastructure. This meets the requirement for SSO to cloud applications while avoiding the complexity and cost of deploying Active Directory Federation Services (AD FS) or other federation servers.

Exam trap

The trap here is that candidates often confuse federation (e.g., AD FS) as the only way to achieve SSO with password reuse, but Password Hash Synchronization provides a simpler, infrastructure-free alternative that still meets the requirement.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID Application Proxy is designed to provide secure remote access to on-premises web applications, not to synchronize identities or enable SSO via password reuse. Option C is wrong because Microsoft Entra ID B2B (Business-to-Business) is used for collaborating with external guest users from other organizations, not for integrating an on-premises AD with Entra ID for internal user SSO. Option D is wrong because Microsoft Entra ID Domain Services provides managed domain services (e.g., group policy, LDAP, Kerberos) for Azure VMs, but it does not synchronize passwords or enable SSO to cloud applications from on-premises AD.

195
MCQeasy

You need to monitor the sign-in activities of users in Microsoft Entra ID and detect risky sign-ins, such as those from anonymous IP addresses. Which service should you use?

A.Microsoft Entra Identity Protection
B.Microsoft Defender XDR
C.Azure Monitor
D.Microsoft Sentinel
AnswerA

Microsoft Entra Identity Protection is the correct service because it is purpose-built for identity risk detection. It applies machine-learning algorithms to signals such as impossible travel, anonymous IP addresses, atypical sign-ins, and leaked credentials to assign a risk level to each sign-in and user. These risk assessments drive conditional access policies and can trigger automated remediation, such as requiring MFA or blocking the sign-in. For monitoring sign-in activities specifically for risk, this is the native Entra ID capability.

Why this answer

Microsoft Entra Identity Protection is the correct service because it is specifically designed to detect and respond to risky sign-in activities, including sign-ins from anonymous IP addresses, using machine learning-based risk detection policies. It integrates directly with Microsoft Entra ID to evaluate sign-in risk in real time and can automatically block or require multi-factor authentication based on configured risk thresholds.

Exam trap

Microsoft often tests the distinction between a dedicated identity risk detection service (Identity Protection) and a broader security or monitoring platform (Defender XDR, Sentinel, or Azure Monitor), leading candidates to choose the more general tool when the question specifically asks for a service that detects risky sign-ins from anonymous IP addresses.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender XDR (Extended Detection and Response) focuses on detecting and responding to security threats across endpoints, email, and applications, not specifically on monitoring sign-in risk from anonymous IP addresses in Entra ID. Option C is wrong because Azure Monitor is a platform for collecting and analyzing telemetry from Azure resources and applications, but it does not have built-in risk detection algorithms for sign-in activities like anonymous IP addresses. Option D is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) that ingests logs from multiple sources for advanced threat hunting and analysis, but it is not the primary service for real-time, policy-driven risky sign-in detection in Entra ID; that is the role of Identity Protection.

196
MCQeasy

You are designing a monitoring solution for a cloud-native application that uses Azure Functions, Azure Storage, and Azure Cosmos DB. The solution must provide centralized log collection and analysis, enable proactive alerting on application errors, and support long-term log retention for compliance (7 years). What should you include in the design?

A.Use Azure Storage with cool tier for logs and enable Azure Storage Analytics logs.
B.Store logs in Azure Monitor Metrics with a retention of 93 days.
C.Use Application Insights to collect logs and set retention to 90 days, then export to Azure Blob Storage for archival.
D.Configure diagnostic settings for each Azure resource to send logs and metrics to a Log Analytics workspace.
AnswerD

Configuring diagnostic settings on each Azure resource sends resource logs, activity logs, and metrics to a central Log Analytics workspace, which provides a single repository for storage, querying, alerting, and long-term retention. This approach supports cross-resource KQL queries and allows you to align retention policies with your compliance requirements. It is the recommended Azure-native pattern for a cloud-native application because it centralizes logs and metrics on the platform's unified monitoring plane.

Why this answer

It leverages Log Analytics workspace as a centralized destination for diagnostic settings from Azure Functions, Storage, and Cosmos DB, enabling unified log collection, Kusto Query Language (KQL)-based analysis, proactive alerting, and long-term retention (up to 7 years) for compliance. This design satisfies all requirements: centralized logging, alerting on application errors, and archival-grade retention.

Exam trap

The trap here is that candidates often confuse Application Insights' export-to-blob feature as a complete solution, overlooking that exported logs become cold storage and lose the centralized query and alerting capabilities required by the scenario.

How to eliminate wrong answers

Option A is wrong because Azure Storage cool tier with Storage Analytics logs only provides basic storage-level metrics and logs (e.g., 200/400/500 responses) without the query, alert, or centralized analysis capabilities needed for application errors; it also lacks native 7-year retention control. Option B is wrong because Azure Monitor Metrics retain data for a maximum of 93 days (93 days for most metrics, 30 days for some), which falls far short of the 7-year compliance requirement and does not support log-based querying or alerting on application errors. Option C is wrong because Application Insights has a default retention of 90 days (extendable to 730 days with additional cost), and while export to Azure Blob Storage can archive logs, it breaks centralized querying and alerting—logs in blob storage are cold and not searchable via KQL, requiring additional processing to analyze.

197
Multi-Selecthard

Which THREE Azure Monitor capabilities can be used to detect and diagnose performance issues in a multi-tier application?

Select 3 answers
A.Azure Monitor Workbooks
B.Azure Policy
C.Live Metrics Stream in Application Insights
D.Application Insights Profiler
E.Application Map in Application Insights
AnswersC, D, E

Live Metrics Stream in Application Insights delivers real-time telemetry with sub-second latency, enabling you to see incoming requests, failures, and performance counters as they occur. Crucially, it uses live sampling and filtering, allowing you to isolate specific operations or attribute values on demand, which makes it an essential tool for detecting issues immediately during a deployment or incident. Unlike other tools, it does not persist data for retrospective analysis, but it is unmatched for live detection and validation.

Why this answer

Live Metrics Stream in Application Insights (Option C) provides real-time monitoring of application performance metrics, such as request rates, response times, and failure rates, with sub-second latency. This allows immediate detection of performance issues as they occur, making it ideal for diagnosing live problems in a multi-tier application.

Exam trap

The trap here is that candidates may confuse Azure Monitor Workbooks (a visualization tool) with a diagnostic capability, or think Azure Policy can monitor performance, when in fact only Application Insights features like Live Metrics Stream, Profiler, and Application Map provide real-time or deep diagnostic insights.

198
Multi-Selecthard

Which THREE components are required to implement a complete monitoring solution with Azure Monitor? (Choose three.)

Select 3 answers
A.Application Insights for every application
B.Azure Policy assignments
C.Alert rules to notify on conditions
D.A Log Analytics workspace for log storage
E.Data sources such as Azure resources and applications
AnswersC, D, E

Alert rules are the active, response-enabling component of a monitoring solution: they evaluate metric or log queries on a predefined schedule and, when conditions are breached, fire notifications or automated actions via action groups. Without alert rules, telemetry is merely stored and visualized, meaning issues like CPU spikes, request failures, or storage capacity overruns would go unnoticed until someone manually queries the workspace. A truly complete monitoring solution must include alerting to convert collected data into actionable notifications, enabling proactive incident response and minimizing downtime.

Why this answer

Alert rules (C) are a core component of a complete monitoring solution because they define conditions that trigger notifications or automated actions when monitored metrics or log data cross thresholds. Without alert rules, collected data remains passive and cannot proactively inform administrators of issues, making the solution incomplete.

Exam trap

The trap here is that candidates often confuse optional monitoring tools (like Application Insights) with mandatory components, or they mistakenly think governance tools (like Azure Policy) are part of the monitoring pipeline, when in fact the three required components are data sources, a Log Analytics workspace, and alert rules.

199
MCQmedium

A company uses Microsoft Entra ID to manage identities for employees and partners. They need to allow partners to self-service reset their passwords using a mobile app notification. Which feature should you enable?

A.Microsoft Entra ID Self-Service Password Reset (SSPR)
B.Microsoft Entra ID Identity Protection
C.Microsoft Intune
D.Microsoft Entra ID Privileged Identity Management
AnswerA

Microsoft Entra ID Self-Service Password Reset (SSPR) is the correct choice because it directly addresses the requirement for users to reset their own passwords without IT intervention. SSPR works by having users pre-register authentication methods—such as the Microsoft Authenticator mobile app notification, a phone number, or security questions—and then using one of those methods to verify their identity during the reset flow. This feature is tightly integrated with Entra ID and can be configured with Conditional Access policies to enforce appropriate security controls, making it the right identity-based solution for password self-service.

Why this answer

Microsoft Entra ID Self-Service Password Reset (SSPR) is the correct feature because it allows users, including partners configured as external users in the tenant, to reset their own passwords without administrator intervention. SSPR supports multiple authentication methods, including mobile app notification via the Microsoft Authenticator app, which satisfies the requirement for a mobile app notification-based reset. This feature is specifically designed for password reset scenarios and can be scoped to include guest users when properly configured.

Exam trap

The trap here is that candidates often confuse Identity Protection (which deals with risk and conditional access) with SSPR, because both involve authentication methods, but Identity Protection does not enable password reset functionality.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID Identity Protection is a risk-based detection and remediation tool that identifies suspicious sign-in activities and potential vulnerabilities, but it does not provide self-service password reset capabilities. Option C is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service for managing devices and apps, not a password reset feature for user accounts. Option D is wrong because Microsoft Entra ID Privileged Identity Management (PIM) manages just-in-time privileged access and role activation, not self-service password reset for standard users or partners.

200
MCQmedium

A company uses Microsoft Entra ID. They want to allow external business partners to request access to a specific internal application. The access must be time-limited and require approval from a manager within the partner's organization. Additionally, access should automatically expire after the defined period. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Entitlement Management
B.Microsoft Entra ID B2B Collaboration
C.Microsoft Entra ID Identity Governance
D.Microsoft Entra ID Privileged Identity Management (PIM)
AnswerA

Microsoft Entra ID Entitlement Management enables you to create access packages that external users can request. You can configure approval workflows, set time limits, and auto-expire access. It is part of Microsoft Entra ID Identity Governance.

Why this answer

Microsoft Entra ID Entitlement Management enables organizations to manage access requests for internal and external users through access packages. It supports time-limited access with automatic expiration and allows delegation of approval to a manager within the partner's organization via connected organizations. This directly meets the requirement for external partner self-service access with time-bound, approved access.

Exam trap

The trap here is that candidates often confuse Entitlement Management with B2B Collaboration, thinking B2B alone provides access control and expiration, when in fact B2B only handles identity creation and invitation, while Entitlement Management adds the governance layer for time-limited, approved access.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID B2B Collaboration provides the underlying invitation and redemption mechanism for external users but does not include built-in time-limited access, approval workflows, or automatic expiration; it requires additional configuration with Entitlement Management or other features. Option C is wrong because Microsoft Entra ID Identity Governance is an overarching category that includes Entitlement Management, access reviews, and lifecycle workflows, but it is not a specific feature that directly handles external partner access requests with time limits and manager approval. Option D is wrong because Microsoft Entra ID Privileged Identity Management (PIM) is designed for managing, controlling, and monitoring privileged roles within an organization, not for granting time-limited access to applications for external business partners.

201
MCQmedium

Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to ensure that an alert is generated when an Azure VM is created with an open inbound SSH port (22) from the internet. The solution should use existing Azure resources and minimize administrative overhead. What should you use?

A.Create a Microsoft Sentinel analytics rule using the Azure Activity data connector.
B.Create an Azure Policy with audit effect and configure a Sentinel data connector for Azure Policy.
C.Create an Azure Monitor metric alert on the 'Network In' metric.
D.Enable Microsoft Defender for Cloud and configure a continuous export to Sentinel.
AnswerA

The Azure Activity data connector ingests control-plane events for virtual machine creation and updates. An analytics rule can filter for `Microsoft.Compute/virtualMachines/write` and use KQL to correlate the resource ID with NSG flow logs, network security rules, or resource properties to determine when a new VM is publicly accessible with port 22 open. This is the only option that combines the exact ARM event with a configurable check for SSH port exposure inside a single detection rule.

Why this answer

Microsoft Sentinel's Azure Activity data connector ingests resource logs from Azure's control plane (Azure Resource Manager). By creating an analytics rule that detects a 'Microsoft.Compute/virtualMachines/write' operation with a network security group rule allowing inbound SSH (port 22) from 'Internet' (any IP), you can generate an alert without deploying additional agents or infrastructure. This minimizes administrative overhead by using existing Sentinel resources and the built-in Activity log connector.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing Defender for Cloud or Azure Policy, thinking they need a security-specific service, when the simplest path is to use the already-connected Azure Activity data connector in Sentinel to monitor control-plane operations for risky configurations.

How to eliminate wrong answers

Option B is wrong because Azure Policy with audit effect can evaluate compliance and log to the Activity Log, but it does not natively generate Sentinel alerts; you would need a separate data connector for Azure Policy (which is not a standard Sentinel connector) and additional logic to create alerts, increasing overhead. Option C is wrong because the 'Network In' metric on Azure Monitor measures data throughput at the VM's virtual NIC, not inbound SSH port 22 access; it cannot detect open ports or security rules. Option D is wrong because enabling Microsoft Defender for Cloud and configuring continuous export to Sentinel adds unnecessary complexity and cost; while Defender for Cloud can detect open SSH ports, the question specifically requires using existing resources with minimal overhead, and the Azure Activity data connector alone suffices.

202
MCQhard

Your organization uses Microsoft Entra ID and requires that all external users invited via B2B collaboration must authenticate using multi-factor authentication (MFA). You need to enforce this for all guest users. What should you configure?

A.Microsoft Entra B2B collaboration settings
B.Microsoft Entra Identity Protection user risk policy
C.Microsoft Entra ID MFA registration policy
D.Microsoft Entra Conditional Access policy
AnswerD

A Microsoft Entra Conditional Access policy is the correct mechanism because it can target guest users—or all external identities—and apply the "Require MFA" grant control directly at each authentication attempt. You can further scope the policy to specific cloud apps, conditions, or locations, giving fine-grained enforcement. This is the standard identity-driven control for ensuring guests must complete MFA before accessing resources, making it the only option here that actually forces MFA at sign-in.

Why this answer

Conditional Access policies in Microsoft Entra ID allow you to enforce MFA for guest users by targeting the 'Guest or external users' identity type and requiring MFA as a grant control. This provides granular control over authentication requirements for B2B collaboration users, unlike the other options which either lack enforcement capability or apply to different scenarios.

Exam trap

The trap here is confusing MFA registration (a prerequisite) with MFA enforcement (a runtime control), leading candidates to select Option C, which only ensures users have registered for MFA but does not require them to actually use it during sign-in.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra B2B collaboration settings only control invitation behavior (e.g., who can invite, allowed domains) and do not enforce MFA during authentication. Option B is wrong because Identity Protection user risk policy triggers based on detected risk signals (e.g., leaked credentials) and does not enforce MFA for all guest users unconditionally. Option C is wrong because the MFA registration policy only requires users to register for MFA but does not enforce MFA during sign-in; it is a prerequisite, not an enforcement mechanism.

203
MCQmedium

Your company uses Microsoft Sentinel for security monitoring. You need to design a solution that automatically responds to incidents involving high-severity alerts. The response should include creating an incident in Microsoft Teams and sending an email to the security team. What should you use?

A.Microsoft Sentinel automation rules and playbooks
B.Azure Policy with remediation tasks
C.Azure Monitor alert rules with action groups
D.Microsoft Defender for Cloud security alerts
AnswerA

Automation rules in Microsoft Sentinel are the native incident-response engine; they evaluate incidents as they are created or updated and can immediately trigger a playbook, which is an Azure Logic Apps workflow. A playbook can call the Teams connector to post a message to a security channel, send email through Outlook, open a ticket, or run containment actions, making it the only option here that directly addresses the requirement to create Teams messages and send emails during incident response.

Why this answer

Microsoft Sentinel automation rules and playbooks (built on Azure Logic Apps) are specifically designed to orchestrate automated responses to security incidents. When a high-severity alert triggers an incident, an automation rule can invoke a playbook that creates a Microsoft Teams message and sends an email via connectors like Office 365 Outlook, meeting the exact requirements.

Exam trap

The trap here is that candidates confuse Azure Monitor action groups (which can send emails/SMS for metric alerts) with Sentinel's incident-specific automation, overlooking that Sentinel requires its own automation rules and playbooks to orchestrate security response workflows.

How to eliminate wrong answers

Option B is wrong because Azure Policy with remediation tasks enforces compliance rules on Azure resources (e.g., ensuring encryption is enabled) and cannot trigger incident response workflows in Microsoft Teams or send emails based on Sentinel alerts. Option C is wrong because Azure Monitor alert rules with action groups are designed for infrastructure and application monitoring (e.g., CPU usage, HTTP errors), not for security incident response; they lack the context of Sentinel's threat intelligence and cannot create Teams incidents natively. Option D is wrong because Microsoft Defender for Cloud security alerts provide security posture recommendations and threat detections but do not include built-in automation to create Teams incidents or send emails; they rely on Sentinel or other tools for response orchestration.

204
MCQeasy

Refer to the exhibit. You assign this Azure Policy to a resource group. A user attempts to create a new Azure SQL Server without specifying an administrator login. What will happen?

A.The SQL Server is created with a default administrator login.
B.The SQL Server creation is denied.
C.The policy is ignored because the condition is not met.
D.The SQL Server is created but a compliance alert is generated.
AnswerB

When the policy condition detects that the `administratorLogin` field is absent, the `deny` effect is triggered during policy evaluation, causing the deployment request to fail. Azure Resource Manager enforces this policy before the SQL Server is provisioned, so the creation operation is blocked and no resource is created. This is a hard enforcement action, not a soft warning.

Why this answer

The Azure Policy assigned to the resource group includes a condition that checks if the 'administratorLogin' property is missing or null when creating a SQL Server. Since the user does not specify an administrator login, the condition evaluates to true, triggering the 'deny' effect. This prevents the creation of the SQL Server entirely, as Azure Policy enforces compliance before the resource is provisioned.

Exam trap

The trap here is that candidates may assume Azure SQL Server has a default administrator login or that the policy would only generate an alert, but Azure Policy's 'deny' effect proactively blocks non-compliant resource creation, not just reports on it.

How to eliminate wrong answers

Option A is wrong because Azure SQL Server requires an administrator login to be specified; there is no default login, and the policy explicitly denies creation when it is missing. Option C is wrong because the condition is met—the administrator login is not specified—so the policy is not ignored; it actively denies the request. Option D is wrong because the policy's 'deny' effect blocks creation before the resource is deployed, so no SQL Server is created to generate a compliance alert; alerts only occur for 'audit' or 'modify' effects, not 'deny'.

205
MCQmedium

Your company uses Microsoft Entra ID to manage identities for 5,000 employees. You plan to implement Microsoft Entra ID Governance to automate the user provisioning lifecycle for a third-party SaaS application. The application supports SCIM 2.0. You need to ensure that user accounts are automatically created, updated, and disabled in the application based on changes in Entra ID. What should you do?

A.Use Microsoft Graph API to write a custom provisioning solution
B.Configure Microsoft Entra B2B collaboration for the application
C.Publish the application using Microsoft Entra Application Proxy
D.Configure automatic provisioning in Microsoft Entra ID using the SCIM endpoint
AnswerD

Configuring automatic provisioning in Microsoft Entra ID with the application's SCIM endpoint is the correct approach because SCIM is a standardized, cloud-scale protocol for automating user lifecycle management. Microsoft Entra ID will act as the SCIM client and call the app's SCIM 2.0 API to create, update, and deactivate users and groups in sync with changes in your identity source. This is a built-in feature, eliminating custom code and providing attribute mapping, scoping filters, and synchronization logs out of the box.

Why this answer

Microsoft Entra ID's automatic provisioning feature natively supports SCIM 2.0 endpoints, enabling automated creation, update, and deactivation of user accounts in third-party SaaS applications based on changes in Entra ID. This eliminates the need for custom code and provides a managed, scalable solution for the user provisioning lifecycle.

Exam trap

The trap here is that candidates may confuse the purpose of Application Proxy (remote access) or B2B collaboration (external identities) with provisioning automation, or assume that a custom Graph API solution is necessary when the built-in SCIM provisioning service is the correct, managed approach.

How to eliminate wrong answers

Option A is wrong because using Microsoft Graph API to write a custom provisioning solution would require significant development effort and ongoing maintenance, whereas the built-in provisioning service already handles SCIM-based automation without custom code. Option B is wrong because Microsoft Entra B2B collaboration is designed for external user access and guest identity management, not for automating the provisioning lifecycle of internal employees in a SaaS application. Option C is wrong because Microsoft Entra Application Proxy is used for secure remote access to on-premises web applications, not for provisioning user accounts to cloud SaaS applications.

206
MCQeasy

Your organization uses Microsoft Purview for data governance. You need to classify sensitive data in Azure SQL Database and automatically apply sensitivity labels. What should you configure?

A.Azure Information Protection scanner
B.Microsoft Purview Data Map with scanning and labeling
C.Microsoft Sentinel with a workbook
D.Azure Policy with built-in SQL classification policy
AnswerB

Microsoft Purview Data Map natively integrates with Azure SQL Database through system-assigned managed identities, performs automated scanning of schema and sensitive data patterns (e.g., PII, credentials), and applies sensitivity labels automatically via built-in classification rules. These labels can be enforced with Microsoft Defender for Cloud, and the Data Map provides a centralized catalog for governance, making this the correct tool.

Why this answer

Microsoft Purview Data Map with scanning and labeling is the correct solution because it integrates with Azure SQL Database to automatically scan for sensitive data types (e.g., credit card numbers, social security numbers) and apply sensitivity labels defined in Microsoft Purview Information Protection. This native integration uses the Purview scanning infrastructure to classify data at rest and propagate labels directly to the SQL database, meeting the requirement for automated classification and labeling.

Exam trap

The trap here is that candidates often confuse Azure Policy's 'SQL classification' built-in initiative (which only audits or enforces the presence of classification) with the actual scanning and labeling capability, leading them to choose Option D instead of recognizing that Purview Data Map is the service that performs the automated classification work.

How to eliminate wrong answers

Option A is wrong because Azure Information Protection (AIP) scanner is designed for on-premises file shares and SharePoint, not for Azure SQL Database; it cannot scan or label data within a PaaS database. Option C is wrong because Microsoft Sentinel is a SIEM/SOAR solution for security monitoring and threat detection, not a data classification or labeling tool; it lacks the capability to scan database schemas or apply sensitivity labels. Option D is wrong because Azure Policy with built-in SQL classification policy only enforces compliance rules (e.g., requiring classification to be enabled) but does not perform automatic scanning or labeling of sensitive data; it is a governance policy, not a classification engine.

207
MCQeasy

You need to monitor the performance and health of your Azure virtual machines, including custom metrics and logs. You also need to set up alerts based on specific thresholds. Which Azure service should you use?

A.Application Insights
B.Azure Service Health
C.Log Analytics
D.Azure Monitor
AnswerD

Azure Monitor is the correct answer because it is the comprehensive monitoring service that collects, analyzes, and responds to telemetry from Azure, on-premises, and hybrid resources, including compute capacity and health. It includes metric-based monitoring, guest-level performance counters through agents, resource health, activity logs, and alerting—all with native integration to dashboards and workbooks. For VMs, VM Insights (which relies on Log Analytics) extends this capability, while the platform itself remains Azure Monitor.

Why this answer

Azure Monitor is the correct choice because it provides a comprehensive solution for collecting, analyzing, and acting on telemetry from Azure virtual machines, including custom metrics and logs. It integrates with the Azure Monitor Agent to gather performance counters and event logs, and supports metric alerts and log alerts based on specific thresholds, directly meeting all stated requirements.

Exam trap

The trap here is that candidates often confuse Log Analytics (a data store and query tool) with Azure Monitor (the full monitoring and alerting platform), leading them to select Option C when Azure Monitor is the correct overarching service that includes Log Analytics and alerting capabilities.

How to eliminate wrong answers

Option A is wrong because Application Insights is an Application Performance Management (APM) service focused on monitoring live web applications, not infrastructure-level metrics and logs from Azure VMs. Option B is wrong because Azure Service Health provides information about Azure service-level issues and planned maintenance, not custom metrics, logs, or threshold-based alerts for individual VMs. Option C is wrong because Log Analytics is a component within Azure Monitor that stores and queries log data, but it is not the overarching service for monitoring, alerting, and metrics; Azure Monitor is the parent service that includes Log Analytics.

208
MCQmedium

Your organization is designing a monitoring solution for a critical application running on Azure VMs. You need to collect performance metrics and logs from the VMs and send them to a centralized Log Analytics workspace. You also need to visualize the data in near real-time. Which combination of services should you use?

A.Azure Monitor Agent and Azure Workbooks
B.Azure Diagnostics extension and VM Insights
C.Azure Monitor Agent and Azure Sentinel
D.Log Analytics Agent and Azure Dashboards
AnswerA

Azure Monitor Agent (AMA) is the current, unified data collection agent for Azure Monitor, replacing the legacy Log Analytics and Diagnostics agents. It uses data collection rules (DCRs) to route VM telemetry into a Log Analytics workspace with low overhead and support for near real-time streaming. Azure Workbooks then provide interactive, customizable visualizations and queries over that data, making this combination ideal for a modern monitoring and visualization solution.

Why this answer

Azure Monitor Agent is the current recommended agent for collecting performance metrics and logs from Azure VMs and sending them to a Log Analytics workspace. Azure Workbooks provide interactive, near real-time visualizations by querying the workspace data. This combination meets the requirements for centralized collection and visualization without unnecessary overhead.

Exam trap

The trap here is confusing Azure Sentinel (a SIEM) with Azure Monitor (a general monitoring solution), leading candidates to select a security-focused tool for a performance monitoring requirement.

How to eliminate wrong answers

Option B is wrong because VM Insights uses the Azure Monitor Agent (or legacy Log Analytics agent) to collect data, but it is a monitoring solution focused on VM health and dependencies, not a direct tool for building custom near real-time visualizations; the Diagnostics extension is legacy and does not send data to Log Analytics by default. Option C is wrong because Azure Sentinel is a SIEM (Security Information and Event Management) tool designed for security analytics and threat detection, not for general performance monitoring and visualization. Option D is wrong because the Log Analytics Agent is legacy and being deprecated in favor of Azure Monitor Agent, and Azure Dashboards are static views that do not support interactive near real-time querying like Workbooks do.

209
MCQhard

Your organization is deploying a critical application in Azure that must maintain an uptime SLA of 99.99%. The application runs on Azure Virtual Machines in a single region. You need to design a monitoring solution that alerts the operations team within 5 minutes of any VM unavailability. The solution must minimize false positives and avoid alert fatigue. What should you include in the design?

A.Configure Azure Monitor VM insights with availability metric alerts set to fire when the VM is unavailable for 2 out of the last 5 minutes.
B.Create an Azure Service Health alert for the 'Virtual machine' service.
C.Create an Azure Monitor alert based on the Activity Log for 'Virtual Machine Guest OS Unresponsive' events.
D.Deploy the Log Analytics agent on each VM and create an alert for when heartbeat data is missing for 5 minutes.
AnswerA

VM insights availability metric uses a combination of VM heartbeat and compute state to produce a rolling availability percentage. Alerting on 2 unavailable minutes out of the last 5 reliably signals sustained unavailability while ignoring transient network or agent blips. This dynamic-threshold approach directly measures the VM's availability and is the most precise option for a critical application requiring immediate detection of downtime.

Why this answer

VM insights availability metric alerts use the 'VM Availability' metric (a composite metric from the Azure Monitor agent) that tracks the VM's running state. Configuring it to fire when the VM is unavailable for 2 out of the last 5 minutes provides a 2-minute evaluation window, which balances the 5-minute notification requirement with a tolerance for transient blips, minimizing false positives. This approach directly monitors the VM's availability at the hypervisor level without relying on guest OS signals, ensuring reliable uptime detection for the 99.99% SLA.

Exam trap

The trap here is that candidates often confuse guest OS-level monitoring (heartbeats or guest OS events) with hypervisor-level availability monitoring, leading them to choose options that depend on the guest OS being responsive, which fails when the VM is truly unavailable.

How to eliminate wrong answers

Option B is wrong because Azure Service Health alerts notify about Azure service-level issues (e.g., regional outages or platform maintenance), not individual VM unavailability, so they cannot detect a single VM going down within 5 minutes. Option C is wrong because the Activity Log alert for 'Virtual Machine Guest OS Unresponsive' events relies on the guest OS to report its own unresponsiveness, which can fail if the OS is completely hung or the agent is down, leading to missed alerts and false negatives. Option D is wrong because the Log Analytics agent heartbeat alert (missing for 5 minutes) introduces a delay of at least 5 minutes before firing, and the heartbeat is sent every 60 seconds by default, so a 5-minute absence window could miss the 5-minute notification target and may generate false positives if the agent is slow to report.

210
MCQhard

You are designing a governance strategy for an Azure environment that includes multiple subscriptions. The security team requires that all storage accounts must have HTTPS traffic only. Any non-compliant storage account must be automatically remediated. What is the most efficient solution?

A.Create an Azure Blueprint that includes a policy initiative
B.Assign a custom RBAC role that denies creation of storage accounts without HTTPS
C.Use Azure Policy with a DeployIfNotExists effect to enable HTTPS-only traffic
D.Configure Azure Monitor alerts to notify the security team
AnswerC

Azure Policy with the DeployIfNotExists effect evaluates every existing resource against the definition and automatically triggers a remediation task to deploy the required configuration — in this case, setting the 'supportsHttpsTrafficOnly' property to true. This effect uses a managed identity to apply the change, and it can be run on-demand via a remediation task or on a schedule, ensuring all non-compliant storage accounts are brought into compliance without manual intervention. This is the only option that provides automated, continuous enforcement and correction for resources already in the subscription.

Why this answer

Azure Policy with a DeployIfNotExists effect can automatically remediate non-compliant storage accounts by enabling the 'HTTPS traffic only' property. This approach ensures continuous compliance without manual intervention, meeting the security team's requirement for automatic remediation.

Exam trap

The trap here is that candidates often confuse Azure Policy's DeployIfNotExists effect with Azure Blueprints, assuming Blueprints can also remediate, but Blueprints only enforce initial compliance and do not provide ongoing automatic remediation for existing resources.

How to eliminate wrong answers

Option A is wrong because Azure Blueprints are used to orchestrate the deployment of resource groups, policies, role assignments, and ARM templates, but they do not automatically remediate non-compliant resources after deployment; they only enforce initial compliance. Option B is wrong because a custom RBAC role that denies creation of storage accounts without HTTPS would only prevent new non-compliant accounts from being created, but it would not remediate existing non-compliant storage accounts. Option D is wrong because Azure Monitor alerts only notify the security team of non-compliance; they do not automatically remediate the issue, which is a core requirement of the question.

211
MCQeasy

Your organization has 500 users in Microsoft Entra ID. You need to ensure that users can only access Microsoft 365 apps from compliant devices (compliant with Intune policies). Users are already enrolled in Intune. The compliance policies are defined. You need to configure the access control mechanism. What should you do?

A.Create a Conditional Access policy that blocks all access and then create exclusions for compliant devices.
B.Configure Intune compliance policies to automatically revoke access for non-compliant devices.
C.Create a Conditional Access policy that requires device to be marked as compliant.
D.Create a Conditional Access policy that requires MFA based on location.
AnswerC

This is the intended pattern because Conditional Access acts as the enforcement engine: setting the grant control 'Require device to be marked as compliant' forces Entra ID to check the device's compliance claim issued by Intune before issuing a token. If the device is non-compliant or unenrolled, access is denied, and the user may be redirected to remediation. This precisely matches the requirement that only compliant devices can access Microsoft 365 applications.

Why this answer

Conditional Access in Microsoft Entra ID is the mechanism that enforces access controls based on signals like device compliance. By creating a policy that requires the device to be marked as compliant, you ensure that only devices meeting Intune compliance policies can access Microsoft 365 apps. This directly addresses the requirement without blocking all access or relying on automatic revocation.

Exam trap

The trap here is that candidates confuse Intune compliance policies (which define rules) with the access control enforcement mechanism (Conditional Access), leading them to choose Option B, which incorrectly assumes compliance policies can directly revoke access without a Conditional Access policy.

How to eliminate wrong answers

Option A is wrong because blocking all access and then creating exclusions for compliant devices is an overly complex and error-prone approach; Conditional Access policies should grant access based on conditions, not block all and carve out exceptions. Option B is wrong because Intune compliance policies define the compliance criteria but do not enforce access control themselves; they rely on Conditional Access to block or allow access based on compliance status. Option D is wrong because requiring MFA based on location addresses authentication strength, not device compliance, and does not ensure that only compliant devices can access Microsoft 365 apps.

212
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID) Premium P2. They need to automatically block sign-ins from anonymous IP addresses (e.g., Tor) and force users from risky sign-ins to reset their password. They want to minimize administrative effort and use built-in features. Which Microsoft Entra ID feature should they enable?

A.Microsoft Entra ID Identity Protection risk policies (sign-in risk and user risk).
B.Conditional Access policies with locations and grant controls.
C.Microsoft Entra ID Privileged Identity Management (PIM).
D.Microsoft Entra ID Access Reviews.
AnswerA

Identity Protection includes built-in policies that automatically detect sign-in risks (including anonymous IP addresses) and user risks (e.g., leaked credentials). The sign-in risk policy can block the sign-in, and the user risk policy can require a password reset. This minimizes manual configuration.

Why this answer

Microsoft Entra ID Identity Protection provides built-in risk policies that automatically detect and block sign-ins from anonymous IP addresses (e.g., Tor) via the sign-in risk policy, and force password reset for users flagged with high user risk via the user risk policy. These policies operate without manual intervention, minimizing administrative effort while leveraging Premium P2 capabilities.

Exam trap

The trap here is that candidates often confuse Conditional Access policies with Identity Protection risk policies, assuming that location-based blocking can replace dynamic risk detection, but Conditional Access lacks the built-in anonymous IP detection and automated password reset triggers that Identity Protection provides.

How to eliminate wrong answers

Option B is wrong because Conditional Access policies with locations and grant controls can block IP ranges or require MFA, but they cannot natively detect anonymous IP addresses like Tor or automatically trigger password resets based on risk; they rely on static location definitions rather than dynamic risk signals. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and access reviews, not sign-in risk detection or password reset enforcement. Option D is wrong because Access Reviews are used for periodic attestation of group memberships or role assignments, not for real-time blocking of anonymous IPs or risk-based password resets.

213
MCQeasy

Your company is deploying a new application on Azure Kubernetes Service (AKS). You need to monitor the health and performance of the cluster, including container logs, metrics, and request rates. Which Azure service should you enable?

A.Azure Service Health
B.Azure Monitor for VMs
C.Azure Application Insights
D.Azure Monitor Container Insights
AnswerD

Microsoft Azure Monitor Container Insights is the purpose-built monitoring solution for Azure Kubernetes Service (AKS). It deploys a containerized Log Analytics agent to your cluster that scrapes node, pod, and container metrics (CPU, memory, disk, network), collects container stdout/stderr logs, and captures Kubernetes inventory and health status. This gives you a unified view of cluster infrastructure, plus integration with Azure Monitor alerts, workbooks, and Log Analytics queries for root-cause analysis—capabilities no other listed option provides.

Why this answer

Azure Monitor Container Insights is the correct service because it is specifically designed to monitor the health and performance of Azure Kubernetes Service (AKS) clusters. It collects container logs, metrics (such as CPU/memory usage), and request rates from the cluster via a containerized Log Analytics agent, providing visibility into the performance of workloads running on AKS.

Exam trap

The trap here is that candidates often confuse Azure Application Insights (which monitors application-level telemetry like requests and exceptions) with Container Insights (which monitors cluster-level health and container logs), leading them to choose C instead of D.

How to eliminate wrong answers

Option A is wrong because Azure Service Health provides a personalized dashboard of service issues, planned maintenance, and health advisories for Azure services, but it does not monitor the performance or logs of individual AKS clusters. Option B is wrong because Azure Monitor for VMs monitors the health and performance of virtual machines, not containerized workloads on AKS; it cannot collect container logs or request rates from Kubernetes pods. Option C is wrong because Azure Application Insights is an application performance management (APM) service for monitoring live web applications, not for collecting cluster-level metrics, container logs, or request rates from AKS infrastructure.

214
MCQhard

Your company has an Azure subscription with 100 virtual machines. You need to monitor the performance of these VMs and be alerted when the average CPU usage across a set of VMs exceeds 80% for 10 minutes. The set of VMs is defined by a tag (Environment=Production). Which Azure Monitor solution should you implement?

A.Use Azure Monitor VM Insights to visualize performance and set alerts per VM.
B.Create a metric alert rule with a dynamic threshold and scope it to a resource group containing Production VMs.
C.Create a metric alert rule with a static threshold of 80% for each Production VM individually.
D.Use a Log Analytics query to calculate average CPU and set a log alert.
AnswerD

A Log Analytics query aggregates CPU across the tag-scoped VMs and a log alert fires when the average exceeds 80% for 10 minutes. Metric alerts cannot natively average across a dynamic tag-defined VM set, so the query satisfies the grouping constraint.

Why this answer

The requirement is to alert when the average CPU usage across a set of VMs (tagged Environment=Production) exceeds 80% for 10 minutes. Metric alert rules (including dynamic thresholds) evaluate per resource, not across multiple resources. Option D uses a Log Analytics query to calculate the average CPU usage across all VMs with the specified tag and then creates a log alert based on that query, which correctly aggregates the metric.

Therefore, Option D is the correct solution.

Exam trap

The trap is that candidates often assume a metric alert rule scoped to a resource group with tag filtering can aggregate metrics across VMs. However, metric alerts evaluate each VM individually, not the average across the set. The correct approach is to use a Log Analytics query to compute the aggregate and trigger a log alert.

How to eliminate wrong answers

Option A is wrong because VM Insights provides per-VM performance visualization and alerts, but it does not natively support aggregating metrics across a set of VMs defined by a tag to trigger a single alert based on the average CPU usage. Option C is wrong because creating individual metric alert rules for each Production VM would require managing 100 separate rules, which is inefficient and does not aggregate the average CPU usage across the set; it would alert per VM, not based on the collective average. Option D is wrong because a Log Analytics query with a log alert would require sending performance data to Log Analytics, incurring additional ingestion costs and complexity, whereas a metric alert is simpler and more cost-effective for this scenario.

215
MCQmedium

A company must prevent non-compliant devices from accessing Exchange Online and SharePoint Online. Which design should you recommend?

A.Conditional Access policy requiring a compliant device.
B.Azure Firewall application rule.
C.Storage account network rule.
D.Resource lock on the Microsoft 365 tenant.
AnswerA

A Conditional Access policy that requires a compliant device works by evaluating the device's compliance state (reported by Intune or a mobile device management solution) as a grant control at the moment of Entra ID authentication. When a user attempts to reach Microsoft 365 apps such as Exchange Online or SharePoint Online, the policy checks that the device meets all compliance policies—like encryption, OS patch level, and jailbreak status—before issuing an access token. This is the correct approach because device compliance is an identity-driven signal that integrates directly with the Entra ID authentication and authorization pipeline, and it can be scoped to require this for all cloud app access.

Why this answer

Conditional Access policies in Microsoft Entra ID (formerly Azure AD) can enforce device compliance by integrating with Microsoft Intune. When a policy requires a compliant device, it checks the device's compliance status before granting access to Exchange Online and SharePoint Online, blocking non-compliant devices at the authentication layer. This is the correct design because it directly controls access to these cloud services based on device health.

Exam trap

The trap here is that candidates may confuse network-level controls (like Azure Firewall) with identity-driven access controls (like Conditional Access), assuming a firewall can filter SaaS traffic, but Azure Firewall cannot inspect or enforce device compliance for Microsoft 365 services.

How to eliminate wrong answers

Option B is wrong because Azure Firewall is a network-layer firewall for Azure virtual networks and cannot inspect or control access to SaaS applications like Exchange Online or SharePoint Online, which are accessed over the internet. Option C is wrong because Storage account network rules control access to Azure Blob, File, Queue, and Table storage, not to Microsoft 365 services like Exchange Online or SharePoint Online. Option D is wrong because a resource lock prevents accidental deletion or modification of an Azure resource but does not enforce any access control or device compliance requirements for Microsoft 365 tenants.

216
MCQeasy

Your company uses Microsoft Entra ID for identity management. You need to ensure that only devices compliant with your company's security policies can access corporate resources. Which solution should you implement?

A.Conditional Access with device compliance policies from Microsoft Intune
B.Microsoft Purview Information Protection
C.Microsoft Sentinel
D.Microsoft Defender XDR
AnswerA

Conditional Access with device compliance policies from Microsoft Intune is the correct answer because Condition Access is the policy engine in Microsoft Entra ID that evaluates signals—including whether a device is compliant—before granting access. Intune compliance policies enforce technical requirements like OS version, disk encryption, and jailbreak detection, and report compliance status to Entra ID. The Conditional Access grant control 'Require device to be marked as compliant' then blocks non-compliant devices from accessing corporate resources. This is the standard Microsoft mechanism for enforcing device compliance at authentication time.

Why this answer

Conditional Access in Microsoft Entra ID allows you to enforce access controls based on conditions, including device compliance. By integrating with Microsoft Intune, you can define device compliance policies (e.g., requiring encryption, a minimum OS version, or anti-malware status) and then configure a Conditional Access policy to block or grant access only to devices that are marked as compliant. This directly ensures that only compliant devices can access corporate resources.

Exam trap

The trap here is that candidates often confuse Microsoft Defender XDR (which handles threat detection) with device compliance enforcement, not realizing that Conditional Access with Intune is the specific mechanism to gate access based on device health.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Information Protection focuses on classifying, labeling, and protecting sensitive data (e.g., via encryption and rights management), not on controlling device-level access based on compliance. Option C is wrong because Microsoft Sentinel is a Security Information and Event Management (SIEM) and Security Orchestration Automation and Response (SOAR) solution for threat detection and incident response, not for enforcing device compliance access policies. Option D is wrong because Microsoft Defender XDR (Extended Detection and Response) provides cross-domain threat detection and response across endpoints, email, and identities, but it does not natively enforce device compliance-based access control; that is the role of Conditional Access with Intune.

217
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID). They need to grant external partners access to an internal application for a limited time (30 days). The access request must be approved by a manager from the partner's organization, and after 30 days the access must automatically expire. They also want to send email reminders 7 days before expiration. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Identity Protection
B.Microsoft Entra ID Privileged Identity Management (PIM)
C.Microsoft Entra ID Entitlement Management
D.Microsoft Entra ID B2B with Conditional Access
AnswerC

Microsoft Entra ID Entitlement Management is the correct choice because it is specifically built to govern access to applications, groups, and SharePoint sites through access packages. Administrators can create access packages that include a partner's required app, define an approval workflow, and set an expiration date for each assignment, at which point access is automatically removed with optional reminder emails before expiry. External users from connected organizations can request access through the Microsoft Entra myaccess portal, and access reviews ensure continued need, making this the only option among those listed that fully supports time-limited external access with approvals and lifecycle governance.

Why this answer

Microsoft Entra ID Entitlement Management enables organizations to manage access for external partners through access packages, which can include time-limited assignments, approval workflows (including manager approval from the partner's organization), and automatic expiration with email notifications. This directly meets the requirement for a 30-day access period with manager approval and 7-day reminder emails.

Exam trap

The trap here is that candidates often confuse PIM (which handles privileged role activation for internal admins) with Entitlement Management (which handles external partner access with full lifecycle governance), or assume B2B with Conditional Access alone can enforce time limits and reminders without the access package framework.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Identity Protection is a security tool for detecting and responding to identity risks (e.g., compromised credentials, sign-in anomalies), not for managing time-limited external access with approvals and expiration. Option B is wrong because Microsoft Entra ID Privileged Identity Management (PIM) is designed for just-in-time privileged role activation and oversight for internal users, not for granting external partner access to applications with manager approval from the partner's organization. Option D is wrong because Microsoft Entra ID B2B with Conditional Access provides guest user invitations and access policies, but it lacks built-in capabilities for time-limited access packages, multi-stage approval workflows, and automatic expiration with email reminders; these require Entitlement Management.

218
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to require multi-factor authentication (MFA) for all users accessing the Azure portal, but do not want MFA to be required for other applications like Office 365. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra ID Security defaults
B.Microsoft Entra ID Conditional Access
C.Microsoft Entra ID Identity Protection
D.Microsoft Entra ID Privileged Identity Management (PIM)
AnswerB

Conditional Access lets an administrator create a policy that targets the 'Microsoft Azure Management' cloud app, which is the service principal behind the Azure portal, and applies the 'Require MFA' grant control to assigned users or groups. This scopes MFA enforcement to Azure portal sign-ins only, leaving other applications with their own separate access policies. It is the appropriate mechanism because it directly maps the exact resource (Azure portal) to the required control (MFA) while allowing granular exclusions and conditions.

Why this answer

Conditional Access in Microsoft Entra ID allows granular control over authentication requirements based on conditions such as application, user, location, or device state. By creating a Conditional Access policy targeting the Azure Portal application and requiring MFA, the company can enforce MFA specifically for Azure Portal access without affecting other applications like Office 365, which can be excluded from the policy.

Exam trap

The trap here is that candidates often confuse Security defaults (which enforces MFA broadly) with Conditional Access (which provides granular application-specific control), leading them to choose Security defaults when the question explicitly requires selective enforcement.

How to eliminate wrong answers

Option A is wrong because Security defaults enforces MFA for all users across all applications, including Office 365, which does not meet the requirement to restrict MFA only to the Azure portal. Option C is wrong because Identity Protection is a risk-based detection and remediation service that can trigger MFA based on user or sign-in risk, but it cannot be configured to require MFA for a specific application like the Azure portal while excluding others. Option D is wrong because Privileged Identity Management (PIM) provides just-in-time privileged access and approval workflows, not the ability to enforce MFA selectively per application.

219
MCQhard

Refer to the exhibit. You are implementing an Azure Policy to control VM SKU deployment. You assign this policy to a subscription. A developer attempts to deploy a virtual machine with SKU Standard_DS2_v2. What is the outcome?

A.The deployment is audited and logged.
B.The deployment is allowed.
C.The VM is deployed but flagged as non-compliant.
D.The deployment is denied.
AnswerD

The policy's condition (if the VM SKU is not equal to Standard_D2s_v3) evaluates to true for the attempted SKU, and the then block applies the Deny effect. Azure Policy returns a 403 Forbidden or similar conflict, and the deployment fails. This is the intended hard enforcement for restricting VM SKUs in the assigned scope.

Why this answer

The Azure Policy in the exhibit uses a 'deny' effect, which explicitly blocks any deployment that does not match the allowed VM SKUs. Since Standard_DS2_v2 is not in the allowed list, the policy engine evaluates the request during deployment and rejects it before any resource is created. This results in the deployment being denied entirely, not just audited or flagged.

Exam trap

The trap here is that candidates confuse the 'deny' effect with 'audit' or 'disabled', assuming the policy only logs non-compliance or allows deployment with a flag, when in fact 'deny' actively blocks the resource creation.

How to eliminate wrong answers

Option A is wrong because an 'audit' effect would log the non-compliant deployment without blocking it, but the policy uses 'deny', not 'audit'. Option B is wrong because the policy explicitly denies any SKU not in the allowed list, so the deployment is not allowed. Option C is wrong because the VM is never deployed; the 'deny' effect prevents resource creation, so there is no VM to flag as non-compliant.

220
MCQeasy

A company uses Microsoft Entra ID. They want to require users to use multi-factor authentication when accessing the Azure portal from any device. They do not want to require MFA for other applications. Which Microsoft Entra ID feature should they configure?

A.Conditional Access policy targeting Azure Portal
B.Per-user MFA (legacy)
C.Security defaults
D.Identity Protection
AnswerA

A Conditional Access policy that targets the Azure Portal is the correct solution because you can select the 'Microsoft Azure Management' cloud app (the enterprise application that represents the Azure portal and API management) and require MFA as a grant control. This policy is evaluated by the Conditional Access engine at sign-in and applies only to the selected app, leaving MFA behavior for other applications unaffected. You can further scope it by users, groups, locations, or device state to meet the company's exact requirement.

Why this answer

Conditional Access policies allow granular control over authentication requirements based on conditions such as application, user, location, or device state. By creating a policy that targets the 'Microsoft Azure Management' cloud app and requires multi-factor authentication, you can enforce MFA specifically for the Azure portal without affecting other applications. This provides the precise control requested, unlike broader or legacy methods.

Exam trap

The trap here is that candidates often confuse Security defaults (which is a blanket MFA enforcement for all apps) with the ability to scope MFA to a single application, leading them to choose Security defaults instead of the more precise Conditional Access policy.

How to eliminate wrong answers

Option B (Per-user MFA) is wrong because it enables MFA for all applications and sign-ins for the assigned user, not just the Azure portal, and is a legacy feature that lacks the conditional targeting required. Option C (Security defaults) is wrong because it enforces MFA for all users and all applications, including every cloud app, which contradicts the requirement to not require MFA for other applications. Option D (Identity Protection) is wrong because it is a risk-based detection and remediation service that can trigger MFA based on sign-in risk, but it does not allow you to target a specific application like the Azure portal; it works in conjunction with Conditional Access but is not the feature to configure for this requirement.

221
Multi-Selecteasy

Which TWO are valid methods to authenticate users in a Microsoft Entra ID hybrid identity solution? (Select TWO.)

Select 3 answers
A.Cloud-only authentication
B.Password hash synchronization
C.Federation with Active Directory Federation Services (ADFS)
D.Pass-through Authentication
E.Seamless Single Sign-On
AnswersB, C, D

Synchronizes password hashes to cloud for authentication.

Why this answer

Password hash synchronization (B), Federation with Active Directory Federation Services (ADFS) (C), and Pass-through Authentication (D) are all valid authentication methods in a Microsoft Entra ID hybrid identity solution. Cloud-only authentication (A) is not hybrid, and Seamless Single Sign-On (E) is a supplementary feature rather than a standalone authentication method.

Exam trap

The trap here is that candidates often confuse Seamless Single Sign-On (SSO) as an authentication method, when it is actually a feature that works on top of password hash sync or pass-through authentication to provide automatic sign-in, not a standalone authentication method.

222
MCQmedium

Your company plans to deploy a new application to Azure. The application will be used by external partners. You need to design an identity solution that allows partners to authenticate using their own corporate credentials while ensuring that the application can enforce conditional access policies based on partner device compliance. What should you include in the design?

A.Federate your Microsoft Entra tenant with each partner's on-premises Active Directory.
B.Create guest user accounts in your Microsoft Entra tenant and assign them application roles.
C.Configure Microsoft Entra B2C and federate with partner identity providers.
D.Configure Microsoft Entra B2B collaboration and enable conditional access policies for guest users.
AnswerD

Configuring Microsoft Entra B2B collaboration lets partners access the application using their own corporate identities, avoiding separate username/passwords. When you also enable Conditional Access policies that target guest users, you can require device compliance as an access condition, so only partner devices that are compliant with your (or their) Intune policies are granted access. This is the only option that combines external identity federation with the enforcement of device compliance for external users.

Why this answer

Microsoft Entra B2B collaboration allows you to invite external partners as guest users who can authenticate with their own corporate credentials. You can then enforce conditional access policies, including device compliance checks, on these guest users by targeting the policy to the 'Guest' user type or specific external users.

Exam trap

The trap here is that candidates often confuse Microsoft Entra B2C (for customers) with Microsoft Entra B2B (for partners), leading them to choose Option C, which cannot enforce conditional access policies based on partner device compliance.

How to eliminate wrong answers

Option A is wrong because federating your Entra tenant with each partner's on-premises Active Directory would require you to manage federation trusts for every partner, and it does not inherently enable conditional access policies based on partner device compliance; device compliance is typically evaluated against your own tenant's policies, not the partner's. Option B is wrong because creating guest user accounts and assigning application roles alone does not enable conditional access policies based on partner device compliance; guest users can authenticate, but without B2B collaboration settings, you cannot enforce device-based conditional access on their external devices. Option C is wrong because Microsoft Entra B2C is designed for customer-facing identity management with self-service sign-up, not for external partner access where partners use their own corporate credentials; B2C does not natively support conditional access policies based on device compliance for guest users.

← PreviousPage 3 of 3 · 222 questions total

Ready to test yourself?

Try a timed practice session using only Design identity, governance, and monitoring solutions questions.