Courseiva

AZ-305 Design business continuity solutions Practice Question

Match each Azure security service to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Unified security management and threat protection

Cloud-native SIEM and SOAR

Manage secrets, keys, and certificates

Protect against distributed denial-of-service attacks

Managed cloud network security service

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Sentinel: Provides intelligent security analytics and threat intelligence across the enterprise.

Correct matches: Azure Sentinel (intelligent security analytics), Azure Firewall (network firewall). Common confusions: Security Center with Key Vault (secret management), Key Vault with DDoS Protection, DDoS Protection with Security Center.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Security Center: Manages secrets, keys, and certificates used by cloud applications.

    Why it's wrong here

    Azure Security Center (now Microsoft Defender for Cloud) is a cloud security posture management (CSPM) and workload protection platform, not a secret store. It assesses misconfigurations, provides secure-score recommendations, and enables just-in-time VM access, whereas the described behavior belongs to Azure Key Vault, which centralizes storage and controlled access to secrets, keys, and certificates.

  • ✓

    Azure Sentinel: Provides intelligent security analytics and threat intelligence across the enterprise.

    Why this is correct

    Azure Sentinel is Microsoft's cloud-native SIEM (Security Information and Event Management) plus SOAR (Security Orchestration, Automation, and Response) solution. It ingests data from numerous sources—including Microsoft 365, Microsoft Entra ID, and third-party appliances—to detect threats via analytics rules, hunt for suspicious activity, and automate response playbooks. This option correctly pairs Sentinel with its core purpose of providing intelligent security analytics and threat intelligence across the enterprise.

  • ✗

    Azure Key Vault: Protects against distributed denial-of-service (DDoS) attacks.

    Why it's wrong here

    Azure Key Vault is a secure vault for storing and managing cryptographic keys, secrets, and certificates, and it enforces fine-grained access policies and hardware security module (HSM) backed keys. It is not designed to absorb or mitigate large volumetric network floods; that is the role of Azure DDoS Protection, which uses Always-On traffic monitoring and adaptive tuning to defend Azure resources against distributed denial-of-service attacks.

  • ✗

    Azure DDoS Protection: Provides unified security management and threat protection for hybrid workloads.

    Why it's wrong here

    Azure DDoS Protection mitigates network-layer and application-layer volumetric, protocol, and resource attacks targeting public IP addresses, leveraging Microsoft's global traffic monitoring infrastructure. It does not deliver unified security management or threat protection for hybrid workloads—that broader posture and workload-protection function belongs to Azure Security Center/Microsoft Defender for Cloud, which includes regulatory compliance, security recommendations, and integrated Microsoft Defender plans across on-premises and cloud environments.

  • ✓

    Azure Firewall: Provides cloud-native network firewall protection for Azure virtual networks.

    Why this is correct

    Azure Firewall is a managed, stateful, cloud-native firewall-as-a-service that secures Azure Virtual Network egress, ingress, and east-west traffic via fully qualified domain name (FQDN) filtering, network rules, threat intelligence-based filtering, and optional IDPS. It enables centralized policy creation and logging across multiple virtual networks and subscriptions, making it the correct service for network-layer protection of Azure virtual networks.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.