Courseiva

CCNA Identity Governance Monitoring Questions

75 of 222 questions · Page 1/3 · Identity Governance Monitoring topic · Answers revealed

1
Multi-Selecteasy

Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to collect logs from on-premises firewalls and send them to Sentinel. Which TWO connectors can you use? (Choose two.)

Select 2 answers
A.DNS
C.Common Event Format (CEF)
D.Azure Activity Log
E.Windows Security Events via AMA
AnswersB, C

Syslog is a ubiquitous standard protocol (RFC 5424) supported by virtually all enterprise firewalls, including Palo Alto, Fortinet, Cisco ASA, and Check Point. The Microsoft Sentinel Syslog connector collects these raw syslog messages and normalizes them for detection and investigation, making it the correct and most flexible choice for ingesting firewall logs.

Why this answer

Syslog is a standard protocol for sending log messages from network devices, including firewalls, to a central collector. Common Event Format (CEF) is a syslog-based format that normalizes logs from different security products, making them easier to parse and analyze in Sentinel. Both connectors allow on-premises firewalls to forward their logs to a Log Analytics agent or AMA, which then sends them to Sentinel.

Exam trap

The trap here is that candidates may confuse 'Syslog' with 'DNS' or 'Windows Security Events' because they think any log source can be collected via a generic connector, but Sentinel requires specific connectors for each data source type.

2
MCQeasy

A company uses Microsoft Entra ID for identity management. They need to automate the process of granting access to resources for employees and external partners, and require periodic access reviews to ensure compliance. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Privileged Identity Management (PIM)
B.Microsoft Entra ID Entitlement Management
C.Microsoft Entra ID Conditional Access
D.Microsoft Entra ID Identity Protection
AnswerB

Microsoft Entra ID Entitlement Management is the correct choice because it creates access packages that bundle resources—groups, apps, SharePoint sites, and Teams—and define policies for who can request, who must approve, when access expires, and which access reviews are required. It automates the end-to-end lifecycle of access assignments and lets external partners request time-limited access through the Microsoft Entra admin center or a custom portal, satisfying both automation and periodic recertification.

Why this answer

Microsoft Entra ID Entitlement Management is the correct feature because it enables automation of access request workflows for employees and external partners, including time-limited access packages and periodic access reviews to enforce compliance. This directly matches the requirement for granting access and ensuring ongoing governance through reviews.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with Entitlement Management because both involve access and reviews, but PIM is strictly for privileged roles, not for general resource access automation for employees and partners.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) focuses on just-in-time privileged role activation and oversight for admin roles, not on automating general resource access for employees and partners or managing access reviews for non-privileged users. Option C is wrong because Conditional Access enforces real-time access policies based on signals like location or device compliance, but it does not automate the initial granting of access or provide periodic review capabilities. Option D is wrong because Identity Protection detects and remediates identity-based risks (e.g., leaked credentials, sign-in anomalies), but it does not handle access request workflows or compliance-driven access reviews.

3
MCQeasy

Your organization plans to deploy Microsoft Entra ID Governance. You need to ensure that access to critical applications is reviewed quarterly by the application owners. Which Microsoft Entra ID feature should you use?

A.Microsoft Entra ID Privileged Identity Management
B.Microsoft Entra ID Entitlement Management
C.Microsoft Entra ID Terms of Use
D.Microsoft Entra ID Access Reviews
AnswerD

Microsoft Entra ID Access Reviews is the correct service because it provides recurring, owner-driven attestation workflows where designated reviewers—such as application owners or managers—are asked to confirm whether a user, group, or application role assignment should continue. Administrators can configure the review frequency (e.g., weekly, monthly, quarterly), specify the scope to all users or only guest users, and enable auto-apply settings that remove denied access automatically after the review period ends. It also supports self-review and multi-stage reviews, giving organizations a complete control loop for regularly proving that access is still necessary. In this scenario, the requirement for owners to periodically attest to whether users still need access directly maps to Access Reviews, not to a request, consent, or privileged-role feature.

Why this answer

Microsoft Entra ID Access Reviews (Option D) is the correct feature because it enables recurring, delegated review of user access to applications, groups, or roles. By configuring an access review with quarterly frequency and assigning application owners as reviewers, you directly meet the requirement for periodic attestation of access to critical applications. This is the specific Entra ID capability designed for governance-driven access recertification.

Exam trap

The trap here is that candidates confuse Entitlement Management (which includes access packages and can trigger reviews) with the dedicated Access Reviews feature, but the question explicitly asks for the feature that ensures reviews are conducted quarterly by application owners, which is the core purpose of Access Reviews, not a secondary function of Entitlement Management.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Privileged Identity Management (PIM) is focused on just-in-time privileged role activation and approval workflows, not on recurring access reviews for all users of critical applications. Option B is wrong because Microsoft Entra ID Entitlement Management handles automated access request and approval workflows via access packages, but it does not natively provide the recurring review cycle that Access Reviews offer. Option C is wrong because Microsoft Entra ID Terms of Use is a policy acceptance feature that requires users to consent to terms before accessing an application, but it does not perform any periodic review or attestation of existing access.

4
MCQhard

A company uses Microsoft Entra ID (Microsoft Entra ID) and Microsoft Intune. They want to block access to all corporate cloud applications (e.g., Office 365, Azure portal) from devices that are not enrolled in Intune or do not meet the company's compliance policies. The solution must work seamlessly for all cloud apps without requiring per-app configuration. Which Microsoft Entra ID feature should they configure?

A.Conditional Access policy with 'Require device to be marked as compliant' grant control
B.Microsoft Entra ID Identity Protection
C.Privileged Identity Management (PIM)
D.Microsoft Entra ID B2C
AnswerA

Conditional Access is the correct control because it evaluates signals at sign-in, including device compliance state that Intune/MDM reports via the DeviceManagement service. By creating a policy scoped to 'All cloud apps' with the 'Require device to be marked as compliant' grant control, you force any access to corporate resources to come only from devices that have been enrolled, inventoried, and found compliant with your policies such as OS version, encryption, and jailbreak detection. If a device isn't compliant, access is blocked or conditional re-authentication is triggered, directly satisfying the requirement.

Why this answer

A Conditional Access policy with the 'Require device to be marked as compliant' grant control enforces device compliance across all cloud apps (Office 365, Azure portal, etc.) without per-app configuration. This works by integrating with Intune compliance policies and checking device enrollment status at the time of authentication, blocking non-compliant or unenrolled devices at the Entra ID level.

Exam trap

The trap here is that candidates often confuse Identity Protection (risk-based) with Conditional Access (policy-based), or assume that per-app configuration is required, when in fact Conditional Access applies globally to all cloud apps registered in Entra ID.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID Identity Protection is designed to detect and respond to identity-based risks (e.g., leaked credentials, anonymous IP addresses), not to enforce device compliance or enrollment for cloud app access. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not device-level access controls. Option D is wrong because Microsoft Entra ID B2C is a customer-facing identity service for external users (e.g., social logins), not for blocking corporate cloud apps based on device compliance.

5
MCQeasy

You are designing a monitoring solution for a critical application hosted on Azure Virtual Machines. The application is latency-sensitive and you need to be alerted when CPU usage exceeds 90% for more than 5 minutes. Which Azure Monitor feature should you use?

A.Service health alert
B.Metric alert
C.Log alert
D.Activity log alert
AnswerB

Metric alerts are the native Azure Monitor alert type for continuously tracking numeric time-series data, such as a VM's "Percentage CPU" or memory bytes. You can define a threshold condition that is evaluated at a specified frequency, with alert activation when the metric crosses the threshold for a configured aggregation window. This provides near-real-time, low-latency detection of performance issues, which exactly matches the requirement to monitor an application's operational health by watching VM metric values.

Why this answer

Metric alerts in Azure Monitor evaluate resource metrics (like CPU percentage) at regular intervals and trigger actions when a threshold is breached for a specified duration. Since the question involves a latency-sensitive application and a numeric threshold (CPU > 90% for 5 minutes), a metric alert is the correct choice because it provides near-real-time, low-latency evaluation directly from the VM's performance counters.

Exam trap

The trap here is that candidates often confuse Log alerts (which are powerful for complex queries) with Metric alerts, forgetting that Log alerts introduce latency from log ingestion and indexing, making them inappropriate for time-sensitive, threshold-based CPU monitoring.

How to eliminate wrong answers

Option A is wrong because Service Health alerts notify about Azure service-level issues (e.g., regional outages, planned maintenance), not about the performance of your specific virtual machines. Option C is wrong because Log alerts query log data (e.g., from Azure Monitor Logs or Application Insights) and have inherent ingestion and query latency, making them unsuitable for sub-5-minute, latency-sensitive CPU threshold alerts. Option D is wrong because Activity Log alerts monitor changes to Azure resources (e.g., VM creation, deletion, or configuration changes), not the operational metrics like CPU usage.

6
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to automatically detect and respond to high-risk sign-in events, such as sign-ins from malware-linked IP addresses or leaked credentials. When such risks are detected, they want to require multi-factor authentication (MFA) or block the sign-in. They also need a dashboard to review risk events and generate reports. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra ID Privileged Identity Management (PIM)
B.Microsoft Entra ID Identity Protection
C.Microsoft Entra ID Conditional Access
D.Microsoft Entra ID Identity Governance
AnswerB

Identity Protection is the correct answer because it is Entra ID's risk detection engine, using signals like leaked credentials, anonymous IP addresses, impossible travel, malware-linked IPs, and unfamiliar sign-in properties to compute per-user and per-risk assignments. It provides an interactive risk dashboard, programmatic risk detection APIs, and supports risk-based Conditional Access policies, such as requiring MFA or blocking access when risk levels exceed a threshold, and can auto-remediate via self-service password reset for confirmed compromised users.

Why this answer

Microsoft Entra ID Identity Protection is the correct feature because it is specifically designed to automatically detect and respond to high-risk sign-in events, such as sign-ins from malware-linked IP addresses or leaked credentials. It provides risk-based conditional access policies that can require MFA or block sign-ins, and it includes a dashboard for reviewing risk events and generating reports. This aligns directly with the scenario's requirements for detection, automated response, and reporting.

Exam trap

The trap here is that candidates often confuse Conditional Access with Identity Protection, not realizing that Conditional Access is the enforcement mechanism while Identity Protection is the detection and risk-scoring engine that provides the necessary risk signals.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) is focused on managing, controlling, and monitoring access to privileged roles, not on detecting or responding to sign-in risks like leaked credentials or malware-linked IPs. Option C is wrong because Conditional Access is a policy engine that enforces access controls (like MFA) based on conditions, but it does not itself detect risk events or provide a risk dashboard; it relies on Identity Protection to supply risk signals. Option D is wrong because Identity Governance handles access reviews, entitlement management, and lifecycle workflows, not real-time risk detection or automated response to high-risk sign-ins.

7
Multi-Selectmedium

Which TWO of the following are valid Azure Policy effects that can be used to enforce compliance?

Select 2 answers
A.DeployIfNotExists
B.Deny
C.AuditIfNotExists
D.Modify
E.AutoRemediate
AnswersA, B

DeployIfNotExists is a valid effect that enforces compliance by deploying resources to remediate non-compliant resources after creation.

Why this answer

DeployIfNotExists (A) is a valid Azure Policy effect that enforces compliance by deploying a related resource when a specified resource does not exist, using a managed identity to perform the deployment. Deny (B) is also a valid effect that enforces compliance by blocking a resource request that violates the policy definition, causing the deployment to fail. AuditIfNotExists (C) is a real effect, but it only logs a non-compliance warning rather than enforcing compliance, so it is not one of the two enforcement effects.

Modify (D) is a valid effect that adds or updates properties during deployment, but it is not marked correct here. AutoRemediate (E) is not an Azure Policy effect; remediation is a separate task performed via remediation tasks, not an effect name.

Exam trap

Candidates often incorrectly think that AuditIfNotExists enforces compliance, but it only audits. Additionally, some may think AutoRemediate is a real effect when it is not. Deny is a straightforward enforcement effect that is sometimes overlooked.

8
Multi-Selecthard

Your organization is designing a governance solution for multiple Azure subscriptions. You need to enforce that all resources are created in specific Azure regions (East US and West Europe only). Additionally, any resource group must have a cost center tag. Which THREE Azure components should you use? (Choose three.)

Select 3 answers
A.Azure Policy
B.Azure Blueprints
C.Policy Initiative
D.Management Groups
E.Role-Based Access Control (RBAC)
AnswersA, C, D

Azure Policy is the correct service for implementing resource governance rules such as allowed region constraints and mandatory tags. It evaluates resources against business rules and can automatically deny non-compliant resource creation, audit existing resources, or remediate drift. Policies are assigned at management group, subscription, or resource group scopes, making it the primary tool in a multi-subscription governance architecture.

Why this answer

Azure Policy is correct because it allows you to define and enforce rules for resource creation, such as restricting allowed locations to East US and West Europe. By assigning a built-in or custom policy definition to a management group or subscription, you can prevent any resource from being created outside the specified regions. This directly addresses the requirement to enforce regional compliance.

Exam trap

The trap here is that candidates often confuse Azure Blueprints (which packages and deploys resources) with Azure Policy (which enforces rules), or they overlook that Management Groups are needed to apply policies across multiple subscriptions efficiently.

9
MCQeasy

A company uses Microsoft Entra ID. They need to automatically block sign-ins from users whose accounts have been identified as high-risk for compromise. They also want users to be prompted to reset their password when the risk is detected. Which Microsoft Entra ID feature should they use?

A.Identity Protection with user risk policy
B.Conditional Access with location policy
C.Microsoft Entra ID MFA
D.Microsoft Entra ID Privileged Identity Management
AnswerA

Identity Protection with a user risk policy is the appropriate solution because it continuously analyzes signals such as leaked credentials and anomalous sign-in patterns to assign a risk score to each user. You can configure a user risk policy to automatically block sign-ins or require MFA and a password change when the risk level is high. This directly meets the need to automatically react to user risk without requiring manual intervention.

Why this answer

Identity Protection with a user risk policy is the correct feature because it allows automatic blocking of sign-ins when a user's account is flagged as high-risk by Microsoft's machine learning models. Additionally, the policy can be configured to require a secure password reset (self-service password reset) as a remediation action, directly meeting both requirements.

Exam trap

The trap here is that candidates often confuse Conditional Access (which handles location, device, and app conditions) with Identity Protection's risk-based policies, but only Identity Protection directly evaluates user risk and triggers automated password reset remediation.

How to eliminate wrong answers

Option B is wrong because Conditional Access with a location policy controls access based on geographic location (e.g., blocking sign-ins from untrusted countries), not on user risk level. Option C is wrong because Microsoft Entra ID MFA adds a second authentication factor but does not automatically block sign-ins based on risk or force a password reset. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and oversight, not risk-based sign-in blocking or password reset prompts.

10
MCQmedium

You need to monitor Azure resources and send alerts when the CPU usage of a virtual machine exceeds 90% for 5 minutes. Which two Azure services should you use? (Select TWO.)

A.Azure Monitor Action Groups
B.Log Analytics
C.Azure Monitor
D.Application Insights
E.Event Grid
AnswerA, C

An Azure Monitor Action Group is the notification endpoint that alert rules invoke when a condition fires—it defines delivery channels such as email, SMS, voice, webhook, ITSM, or an automation runbook. Without an action group, an alert rule may log the hitting state but cannot actually send an email or SMS to operations staff. Therefore, for the specific goal of 'sending alerts,' the action group is the direct, correct component that carries out the notification.

Why this answer

Azure Monitor is the core service for collecting and analyzing metrics and logs from Azure resources. It can be configured with metric alerts that trigger when CPU usage exceeds 90% for 5 minutes. Action Groups define the notification and response actions (e.g., email, SMS, webhook) that are executed when the alert fires, making them essential for sending alerts.

Exam trap

The trap here is that candidates often confuse Log Analytics (a log query tool) with Azure Monitor (the alerting engine), or mistakenly think Application Insights can monitor VM-level metrics, when it is designed for application-level telemetry.

How to eliminate wrong answers

Option B is wrong because Log Analytics is a tool for querying and analyzing log data, not for creating metric-based alerts or sending notifications directly. Option D is wrong because Application Insights is focused on application performance monitoring (APM) for web applications, not infrastructure-level VM CPU metrics. Option E is wrong because Event Grid is a serverless event routing service used for reacting to Azure resource state changes (e.g., VM creation), not for monitoring CPU thresholds or sending alerts.

11
MCQeasy

Your company has a Azure subscription with multiple resource groups. You need to ensure that all resources are tagged with a 'CostCenter' tag. What should you use?

A.Azure Policy
B.Azure Blueprints
C.Management Groups
D.Azure RBAC
AnswerA

Azure Policy is the correct answer because it is a native governance service that can evaluate and enforce resource properties such as tags at scale. You can define a policy with an effect like 'deny' or 'modify' to either reject non-compliant tags or automatically append missing ones via a remediation task. Unlike RBAC, the policy engine runs independently of access control, directly inspecting each resource for compliance.

Why this answer

Azure Policy is the correct choice because it enforces organizational standards and compliance by evaluating resources for non-compliance with defined rules, such as requiring a specific tag. You can create a policy that audits or denies resources missing the 'CostCenter' tag, ensuring all resources are tagged automatically or during deployment.

Exam trap

The trap here is that candidates often confuse Azure Policy with Azure Blueprints, thinking Blueprints can enforce tags directly, but Blueprints only define the initial state and do not enforce ongoing compliance like Policy does.

How to eliminate wrong answers

Option B is wrong because Azure Blueprints is used for orchestrating the deployment of resource groups, policies, role assignments, and ARM templates as a repeatable environment, not for enforcing tags on individual resources. Option C is wrong because Management Groups provide a hierarchical structure for organizing subscriptions and applying policies at scale, but they are not the direct enforcement mechanism for tagging resources. Option D is wrong because Azure RBAC manages access control by assigning roles to users, groups, or applications, and does not enforce resource tagging.

12
MCQhard

Refer to the exhibit. You are reviewing an ARM template for deploying a storage account. The template is missing the storage account name parameter definition. What will happen when you attempt to deploy this template?

A.The deployment will prompt the user to provide the missing parameter.
B.The deployment will fail with a validation error because the parameter is not defined.
C.The deployment will succeed using a default name based on the resource group.
D.The deployment will create a storage account with a random name.
AnswerB

During the pre-deployment validation phase, Azure Resource Manager parses the template and evaluates all expressions that reference parameters. If a parameter is used in the resources section but is not declared in the parameters section—or has no default and is not provided—the template is considered malformed and the validation error rejection happens before any resource group changes are attempted.

Why this answer

In Azure Resource Manager (ARM) templates, all parameters must be explicitly defined in the `parameters` section of the template. If a parameter is referenced (e.g., in the `resources` section) but not defined, the deployment fails with a validation error before any resource provisioning begins. This is because ARM validates the template structure and parameter definitions during the pre-deployment validation phase, and an undefined parameter is considered a syntax error.

Exam trap

The trap here is that candidates may assume Azure will automatically prompt for or generate a missing parameter, similar to how some Azure Portal experiences handle missing inputs, but ARM templates strictly enforce parameter definitions and fail fast on validation.

How to eliminate wrong answers

Option A is wrong because ARM templates do not prompt the user for missing parameters; they fail validation if a referenced parameter is not defined. Option C is wrong because there is no default name generation based on the resource group; storage account names must be explicitly provided or generated via a defined parameter or variable. Option D is wrong because ARM does not automatically assign random names; the deployment fails before any resource creation occurs.

13
MCQhard

A multinational company uses Microsoft Entra ID and several Azure subscriptions. Security administrators need to review privileged role assignments every month and require justification for continued access. Which design should be recommended?

A.Azure Monitor metric alerts
B.Management group locks
C.Microsoft Entra Privileged Identity Management with access reviews
D.Azure Policy guest configuration
AnswerC

Privileged Identity Management (PIM) enables just-in-time activation of eligible roles with time-bound assignments, mandatory multi-factor authentication, and a rule-based justification that must be supplied prior to elevation. Access reviews in PIM run on a schedule to confirm whether users still need privileged roles, automatically removing stale or unjustified assignments and generating compliance reports. Together, they directly address the requirement to require and review justifications for privileged access.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) with access reviews is the correct design because it provides time-bound, just-in-time privileged role assignments and requires users to periodically justify their continued access through automated access reviews. This directly meets the monthly review and justification requirement for privileged roles, as PIM integrates with Entra ID to enforce approval workflows and expiration policies.

Exam trap

The trap here is that candidates often confuse Azure RBAC management tools (like management locks or Azure Policy) with identity governance tools, mistakenly thinking they can control user role assignments, when in fact only Entra ID PIM provides the required review and justification workflow for privileged roles.

How to eliminate wrong answers

Option A is wrong because Azure Monitor metric alerts are used to detect and notify on performance or operational metrics (e.g., CPU usage, response times) and cannot enforce or review privileged role assignments. Option B is wrong because management group locks prevent accidental deletion or modification of Azure resources at the management group scope but do not manage identity or role assignments in Entra ID. Option D is wrong because Azure Policy guest configuration audits and configures settings inside virtual machines (e.g., OS compliance) and has no capability to review or justify privileged role assignments in Entra ID.

14
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID). External partners need temporary access to an internal application. The process must be self-service: partners request access, the request goes through an approval workflow managed by a manager from the partner's organization, and access automatically expires after 30 days. The company also wants to send reminder emails 7 days before expiration. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Identity Governance - Access Reviews
B.Microsoft Entra ID Identity Governance - Entitlement Management
C.Microsoft Entra ID Privileged Identity Management (PIM)
D.Microsoft Entra ID Conditional Access
AnswerB

Entitlement Management provides access packages that external users can request. It includes approval workflows, automatic expiration after a defined duration, and email reminders before expiration. It is designed for managing external identities and time-limited access.

Why this answer

Microsoft Entra ID Identity Governance - Entitlement Management is specifically designed to manage access for external users through self-service access packages. It supports approval workflows with external managers, automatic time-bound access (e.g., 30-day expiration), and lifecycle notifications like reminder emails 7 days before expiry. This aligns perfectly with the requirement for partner-managed, temporary, self-service access.

Exam trap

The trap here is confusing Entitlement Management (designed for external user access lifecycle) with Access Reviews (which is for periodic recertification, not self-service provisioning) or PIM (which is for internal privileged roles, not application access for partners).

How to eliminate wrong answers

Option A is wrong because Access Reviews are used for periodic attestation of existing access, not for self-service request workflows with automatic expiration and reminders. Option C is wrong because Privileged Identity Management (PIM) is focused on just-in-time privileged role activation for internal administrators, not for granting temporary access to external partners for an application. Option D is wrong because Conditional Access enforces policies (e.g., MFA, location) during sign-in but does not provide self-service request, approval workflows, or automatic expiration management.

15
Multi-Selecteasy

Which TWO features of Microsoft Entra ID can be used to secure hybrid identities?

Select 2 answers
A.Microsoft Sentinel
B.Microsoft Intune
C.Seamless Single Sign-On
D.Azure Active Directory Domain Services
E.Password Hash Synchronization
AnswersC, E

Seamless Single Sign-On is a correct answer: it silently signs users into Microsoft Entra ID when they are on a domain-joined device connected to the corporate network, using their existing on-premises AD Kerberos tickets. It lets users access cloud and SaaS applications without re-entering passwords, reducing password fatigue and phishing exposure while relying on the on-premises credential validation. However, it is not a standalone authentication method and must be paired with Password Hash Synchronization or Pass-through Authentication.

Why this answer

Seamless Single Sign-On (Seamless SSO) automatically signs users in when they are on corporate devices connected to the corporate network, eliminating password prompts. Password Hash Synchronization (PHS) synchronizes a hash of the user's on-premises AD password to Azure AD, enabling cloud authentication without additional infrastructure. Both features directly secure hybrid identities by extending on-premises credentials to the cloud.

Exam trap

The trap here is that candidates often confuse Azure AD DS (a managed domain service) with a feature of Microsoft Entra ID, when in fact it is a separate service that provides legacy LDAP and NTLM capabilities, not a native hybrid identity authentication feature.

16
Multi-Selectmedium

Your company uses Microsoft Entra ID. You need to implement a privileged identity management (PIM) strategy to secure administrative roles. Which TWO capabilities does PIM provide? (Choose two.)

Select 2 answers
A.Approval workflows for role activation
B.Conditional Access policies for role activation
C.Management of external identities
D.Just-in-time (JIT) access to privileged roles
E.Automated user provisioning to applications
AnswersA, D

PIM's approval workflows require designated approvers to approve an activation request before the role becomes active, adding human oversight to privileged access. Approvals are configured per role and support multi-stage approval via approver groups, with users able to provide justification. This gate prevents unauthorized or casual elevation, complementing time-bound eligibility.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID provides time-based and approval-based role activation to secure privileged roles. Approval workflows for role activation (Option A) are a core PIM feature, allowing designated approvers to review and approve activation requests before a user gains elevated permissions. This ensures that privileged access is granted only after explicit authorization, reducing the risk of unauthorized use.

Exam trap

The trap here is that candidates often confuse Conditional Access policies (which control access to apps) with PIM's role activation policies (which control access to privileged roles), leading them to incorrectly select Option B.

17
Drag & Dropmedium

Drag and drop the steps to implement Azure Site Recovery for a Hyper-V VM into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First, create the vault. Then ensure network connectivity. Install the provider and agent.

Create and apply a replication policy. Finally, enable replication.

18
MCQhard

Your company plans to deploy a new SaaS application that will be used by employees and external users. The application requires single sign-on (SSO) and must support conditional access policies that enforce MFA for external users. Additionally, the application must be able to read user profile attributes from Microsoft Entra ID. You need to design an identity solution that meets these requirements. What should you include in the design?

A.Register the application in Microsoft Entra ID (App Registration) and configure it to use OpenID Connect for authentication; apply conditional access policies to the app.
B.Use Azure AD Application Proxy to publish the SaaS app and configure pre-authentication with Entra ID.
C.Use Microsoft Entra Domain Services to authenticate the application via LDAP.
D.Register the application in Microsoft Entra B2C and configure federation with your Entra ID tenant.
AnswerA

Registering the SaaS app as an App Registration in Microsoft Entra ID and using OpenID Connect (OIDC) is the correct approach because OIDC is the modern, standards-based authentication protocol that Microsoft Entra ID fully supports for SSO. The app registration generates service principles, enabling Entra ID to issue ID and access tokens, which the SaaS app can validate. OIDC also exposes the application to conditional access policies in the same tenant, allowing you to enforce MFA, device compliance, and sign-in risk controls. Additionally, the Microsoft Graph API can be consented to read user profile data seamlessly, a capability not available through the alternatives.

Why this answer

Registering the application in Microsoft Entra ID (App Registration) and configuring OpenID Connect (OIDC) enables SSO and allows the application to read user profile attributes via the Microsoft Graph API. Conditional access policies can be applied directly to the enterprise app in Entra ID to enforce MFA for external users, meeting all stated requirements.

Exam trap

The trap here is that candidates may confuse Azure AD Application Proxy (for on-premises apps) or Entra B2C (for customer identities) with the correct solution for a SaaS app requiring employee and external user access with conditional access and Graph API reads.

How to eliminate wrong answers

Option B is wrong because Azure AD Application Proxy is designed for publishing on-premises apps, not SaaS applications, and does not inherently support reading user profile attributes via Graph API. Option C is wrong because Microsoft Entra Domain Services provides LDAP/Kerberos/NTLM authentication for legacy apps and does not support modern SSO protocols like OIDC or conditional access policies for SaaS apps. Option D is wrong because Microsoft Entra B2C is intended for customer-facing identity management with external identity providers, not for employee access to a SaaS app, and it does not natively support reading user profile attributes from the primary Entra ID tenant via Graph API.

19
MCQhard

Refer to the exhibit. You run this Kusto query in Azure Monitor Logs. What does it return?

A.The number of heartbeats per computer in the last hour.
B.Computers that sent a heartbeat in the last 5 minutes.
C.Computers that have not sent a heartbeat in the last 5 minutes.
D.The average heartbeat frequency per computer.
AnswerC

This is the correct interpretation. The query first obtains each computer's latest heartbeat timestamp (typically via `summarize max(TimeGenerated) by Computer` or `arg_max`), then applies a `where` clause that retains only rows where that latest timestamp is less than `ago(5m)`. Computers that satisfy this predicate have not emitted a heartbeat in the past five minutes, so they are correctly identified as stale or offline.

Why this answer

The query uses the `Heartbeat` table and filters for heartbeats older than 5 minutes (`ago(5m)`). The `where` clause selects records where `TimeGenerated` is less than 5 minutes ago, meaning it finds heartbeats that were sent before that threshold. The `distinct Computer` then returns only computers whose most recent heartbeat is older than 5 minutes, i.e., computers that have not sent a heartbeat in the last 5 minutes.

This is a common pattern for detecting unresponsive or offline machines.

Exam trap

The trap here is that candidates misread the comparison operator: `TimeGenerated < ago(5m)` selects records older than 5 minutes (not newer), leading them to incorrectly think the query returns computers that recently sent a heartbeat.

How to eliminate wrong answers

Option A is wrong because the query does not count heartbeats per computer; it uses `distinct Computer` to return unique computer names, not an aggregation like `summarize count()`. Option B is wrong because the filter `TimeGenerated < ago(5m)` selects records older than 5 minutes, not records within the last 5 minutes; to find computers that sent a heartbeat in the last 5 minutes, the filter would be `TimeGenerated > ago(5m)`. Option D is wrong because the query does not calculate any average or frequency; it simply returns distinct computer names based on a time filter, with no aggregation or statistical function.

20
MCQmedium

Your organization uses Microsoft Entra ID and requires that all external users accessing resources must be approved by a designated reviewer. You need to automate the review process for external identities. What should you implement?

A.Microsoft Purview
B.Privileged Identity Management (PIM)
C.Microsoft Entra access reviews
D.Conditional Access
AnswerC

Microsoft Entra access reviews enables administrators to create recurring review campaigns for group memberships, enterprise application assignments, and role assignments. Reviewers can sign off on each user's access with a decision and justification, and results can be configured to automatically remove access when needed. This directly meets the requirement for periodic review of external users' access, making it the correct service for this scenario.

Why this answer

Microsoft Entra access reviews allow you to automate the periodic review of external identities, ensuring that only approved users retain access. This feature directly supports the requirement for a designated reviewer to approve or deny external users, with automated reminders and results. It is the correct choice because it is purpose-built for governance of external identities in Entra ID.

Exam trap

The trap here is confusing Privileged Identity Management (PIM) with access reviews, as both involve approvals, but PIM is for privileged roles while access reviews are for ongoing user access certification, especially for external identities.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview is a data governance and compliance solution focused on data classification, labeling, and risk management, not on automating identity access reviews. Option B is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval, not the periodic review of all external identities. Option D is wrong because Conditional Access enforces access policies based on conditions like location or device state, but does not provide a workflow for designated reviewers to approve or deny external user access.

21
Multi-Selectmedium

Your company uses Microsoft Entra ID. You need to implement a governance strategy for guest users. Which TWO actions should you take? (Choose two.)

Select 2 answers
A.Create access reviews for guest users
B.Disable external identities
C.Block all guest user access
D.Enable self-service sign-up for guest users
E.Configure Microsoft Entra entitlement management
AnswersA, E

Access reviews in Microsoft Entra ID provide a planned, recurring recertification workflow for guest users, forcing owners to confirm or revoke each guest's access to sensitive resources. By assigning reviewers per access package or application, you can automatically remove stale or unauthorized external accounts, satisfying compliance requirements and enforcing the principle of least privilege. This is a core governance control because it operationalizes periodic oversight rather than relying on one-time provisioning decisions.

Why this answer

Access reviews for guest users (Option A) are a core governance control in Microsoft Entra ID, allowing administrators to periodically review and confirm or revoke guest access. This ensures that guest accounts remain necessary and compliant with security policies, directly addressing the governance requirement.

Exam trap

The trap here is that candidates may confuse blocking or disabling guest access (Options B and C) with governance, when the correct approach involves reviewing and managing guest access through reviews and entitlement management.

22
Multi-Selecteasy

Your company uses Microsoft Entra ID for identity management. You need to implement a solution that automatically blocks sign-ins from risky users and requires multi-factor authentication (MFA) when a sign-in risk is detected. Which TWO services should you use? (Choose two.)

Select 2 answers
A.Microsoft Purview
B.Microsoft Entra ID Protection
C.Microsoft Defender XDR
D.Microsoft Intune
E.Conditional Access policies
AnswersB, E

Microsoft Entra ID Protection is the dedicated identity risk engine that continuously analyzes user and sign-in behavior using signals such as leaked credentials, impossible travel, anomalous token usage, and unfamiliar properties. It calculates user risk and sign-in risk levels and automatically remediates or responds to these risks by requiring MFA or password change, or by blocking access via Conditional Access policies. This makes it the correct service for detecting risky users and risky sign-ins in a Microsoft Entra ID environment.

Why this answer

Microsoft Entra ID Protection (B) is the service that detects sign-in risks (e.g., anonymous IP, atypical travel) and labels users or sign-ins as risky. Conditional Access policies (E) then enforce automated responses, such as blocking the sign-in or requiring MFA, based on the risk level from Entra ID Protection. Together, they provide the detection and enforcement mechanism described in the requirement.

Exam trap

The trap here is that candidates often confuse Microsoft Defender XDR (which includes identity threat detection) with the policy enforcement layer, but only Conditional Access policies can apply the automated MFA or block action based on risk from Entra ID Protection.

23
MCQhard

Your Azure subscription contains multiple virtual machines (VMs) that run a line-of-business application. You need to configure alerts when the CPU usage exceeds 90% for more than 5 minutes. Additionally, the alert must automatically trigger a runbook to scale out the application. Which Azure service should you use to create this alert?

A.Azure Automation
B.Azure Logic Apps
C.Azure Monitor metric alert
D.Azure Autoscale
AnswerC

An Azure Monitor metric alert continuously evaluates one or more VM metrics—such as CPU percentage, memory pressure, or disk IOPS—against a defined threshold and firing condition. When the alert fires, its action group can contain an Automation runbook, webhook, or ITSM ticket, so this is the appropriate service to trigger custom remediation on the VMs.

Why this answer

Azure Monitor metric alerts can evaluate resource metrics like CPU usage at a specified frequency and trigger actions when a threshold (e.g., 90%) is breached for a given duration (e.g., 5 minutes). The alert can invoke an Automation runbook via an action group, enabling automatic scaling of the application. This is the correct service because it directly supports metric-based alerting with multi-condition evaluation and action group integration.

Exam trap

The trap here is that candidates confuse Azure Monitor metric alerts with Azure Autoscale, assuming Autoscale can both alert and trigger runbooks, when in fact Autoscale only performs scaling actions based on its own rules and does not generate alerts or invoke runbooks.

How to eliminate wrong answers

Option A is wrong because Azure Automation is a service for authoring and running runbooks, but it does not itself evaluate metrics or generate alerts; it can only be triggered by an alert action group. Option B is wrong because Azure Logic Apps is a workflow orchestration service that can respond to alerts via connectors, but it is not the native alerting service for metric thresholds and would require additional configuration to evaluate CPU usage. Option D is wrong because Azure Autoscale is a scaling service that can automatically adjust resources based on metrics, but it does not create alerts or trigger runbooks; it directly scales resources without an intermediate alerting step.

24
MCQmedium

A company uses Microsoft Entra ID. They want to grant a user temporary access to the Global Administrator role for a specific task. The access must require approval from a manager and automatically expire after 4 hours. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Conditional Access
B.Microsoft Entra ID Identity Protection
C.Microsoft Entra ID Privileged Identity Management (PIM)
D.Microsoft Entra ID Access Reviews
AnswerC

Microsoft Entra ID Privileged Identity Management (PIM) is the correct service because it enables just-in-time, time-bound activation of privileged Entra ID roles. With PIM, you can make a user eligible for a role, and the user can activate it for a configured maximum duration, optionally requiring business justification and approval from designated approvers. Once the activation time expires, the role is automatically deactivated, so the user no longer has the elevated permissions. PIM also provides audit logs and access reviews, but its core value is exactly the time-limited, approval-based elevation scenario described in the requirement.

Why this answer

Microsoft Entra ID Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access, allowing users to activate roles like Global Administrator for a limited time. It supports approval workflows (manager approval) and configurable activation duration (e.g., 4 hours), making it the correct choice for temporary, approved, time-bound role elevation.

Exam trap

The trap here is confusing PIM's JIT activation with Conditional Access policies, which control access to applications but not role elevation, or with Access Reviews, which are for periodic recertification rather than temporary activation.

How to eliminate wrong answers

Option A is wrong because Conditional Access enforces policies based on signals like location or device state to control access to resources, but it does not provide time-bound role activation or approval workflows for privileged roles. Option B is wrong because Identity Protection detects and remediates identity-based risks (e.g., leaked credentials, sign-in anomalies) and does not manage role activation or approval. Option D is wrong because Access Reviews automate periodic attestation of group memberships or role assignments but do not support on-demand, temporary activation with approval and automatic expiration.

25
MCQeasy

A company uses Microsoft Entra ID. They need to grant external partners access to an internal application for a limited time (30 days). The access must be approved by a manager from the partner's organization. After the period ends, access should automatically be removed. The company also wants to send email reminders 7 days before expiration. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Access Reviews
B.Microsoft Entra ID Entitlement Management
C.Microsoft Entra ID Conditional Access
D.Microsoft Entra ID Identity Protection
AnswerB

Microsoft Entra ID Entitlement Management uses access packages with an expiration policy, automatically removing access after 30 days. It supports connected organisations, letting the partner's manager approve requests, and sends email notifications 7 days before expiry — satisfying the time-bound, externally approved access requirement.

Why this answer

Microsoft Entra ID Entitlement Management is the correct feature because it provides automated access lifecycle management for external users, including time-limited access packages, approval workflows (including external manager approval), and automatic expiration with email notifications. This directly matches the requirement for 30-day access with partner manager approval and 7-day reminder emails.

Exam trap

The trap here is confusing Entitlement Management (which handles the full lifecycle of external access with expiration and approvals) with Access Reviews (which is a periodic review tool, not an automated expiration mechanism).

How to eliminate wrong answers

Option A is wrong because Access Reviews are a periodic attestation mechanism that requires manual or semi-automated review cycles, not a one-time 30-day expiration with automatic removal and email reminders. Option C is wrong because Conditional Access enforces access policies (e.g., MFA, device compliance) in real time but does not manage access expiration, approval workflows, or automated email reminders. Option D is wrong because Identity Protection focuses on detecting and remediating identity-based risks (e.g., leaked credentials, sign-in anomalies) and does not handle external partner access lifecycle or time-bound approvals.

26
MCQmedium

A company uses Microsoft Entra ID Premium P2. They need to automatically detect users with high-risk sign-ins (e.g., from anonymous IP addresses or leaked credentials) and require them to reset their password. Which Microsoft Entra ID feature should they configure?

A.Identity Protection
B.Privileged Identity Management
C.Conditional Access
D.Access Reviews
AnswerA

Identity Protection in Microsoft Entra ID Premium P2 continuously evaluates user and sign-in risk signals, such as leaked credentials and impossible travel. Its risk policies can automatically trigger a secure password change for high user risk, remediating compromised accounts without manual intervention. This automated remediation capability is exactly what the company needs.

Why this answer

Identity Protection is the correct feature because it is specifically designed to detect and remediate risky sign-ins, including those from anonymous IP addresses or leaked credentials. It uses machine learning to assign a risk level to each sign-in and user, and can automatically enforce password resets when high-risk events are detected, aligning with the requirement for automated detection and remediation.

Exam trap

The trap here is that candidates often confuse Conditional Access with Identity Protection, not realizing that Conditional Access is the enforcement engine that requires Identity Protection to first detect and assign the risk level, making Identity Protection the correct feature for automatic detection.

How to eliminate wrong answers

Option B (Privileged Identity Management) is wrong because it focuses on just-in-time access and approval workflows for privileged roles, not on detecting risky sign-ins or enforcing password resets for all users. Option C (Conditional Access) is wrong because while it can enforce policies based on sign-in risk, it does not automatically detect or assign risk levels; it relies on Identity Protection to provide the risk assessment. Option D (Access Reviews) is wrong because it is a governance tool for periodic review of group memberships or application access, not for real-time risk detection or password reset enforcement.

27
MCQmedium

You have an Azure subscription that contains 100 virtual machines. You need to monitor the virtual machines for security vulnerabilities and receive recommendations. What should you use?

A.Microsoft Defender for Cloud
B.Azure Monitor
C.Microsoft Sentinel
D.Microsoft Defender XDR
AnswerA

Microsoft Defender for Cloud is the correct choice because it natively provides continuous vulnerability assessment for Azure VMs via its built-in Qualys scanner or the integrated Microsoft Defender for Servers plan. It identifies missing patches, misconfigurations, and potential security issues, then offers actionable remediation recommendations and hardening guidance. Beyond vulnerability scanning, it also delivers compliance assessments. Its recommendations are directly generated from resource configuration analysis and threat signals, making it the only listed service designed for cloud security posture management and vulnerability detection.

Why this answer

Microsoft Defender for Cloud (formerly Azure Security Center) provides unified security management and advanced threat protection across hybrid cloud workloads. It continuously assesses your virtual machines for security vulnerabilities, misconfigurations, and missing updates, then delivers actionable recommendations and a secure score to prioritize remediation. This directly matches the requirement to monitor VMs for vulnerabilities and receive recommendations.

Exam trap

The trap here is that candidates confuse Azure Monitor (which monitors performance and availability) with security monitoring, or assume Microsoft Sentinel (a SIEM) is the correct tool for vulnerability scanning, when in fact Defender for Cloud is the dedicated service for security posture management and vulnerability assessment.

How to eliminate wrong answers

Option B is wrong because Azure Monitor is a platform for collecting and analyzing telemetry data (metrics, logs) from resources, but it does not perform vulnerability scanning or provide security recommendations—it lacks the built-in vulnerability assessment and secure score features. Option C is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR solution for aggregating security logs, detecting threats, and orchestrating incident response; it does not natively scan VMs for vulnerabilities or generate compliance recommendations. Option D is wrong because Microsoft Defender XDR (formerly Microsoft 365 Defender) is an extended detection and response solution that correlates signals across endpoints, email, and identities, but it is not designed for vulnerability assessment of Azure VMs and does not provide the same centralized security posture management as Defender for Cloud.

28
MCQhard

You are reviewing a Conditional Access policy for a Microsoft Entra ID tenant. The exhibit shows the policy configuration. Users report that they are prompted for MFA every hour even when using approved Microsoft applications. The security team wants to reduce MFA prompts but maintain security. What should you modify?

A.Enable 'persistentBrowser' session control
B.Change cloudAppSecurityType to 'blockDownloads'
C.Remove the 'approvedApplication' grant control
D.Increase the signInFrequency value to 24 hours
AnswerD

Increasing the signInFrequency value to 24 hours directly reduces how often a user must re-authenticate, because this setting dictates the maximum time allowed between credential entries for all assigned apps. By setting it to a full day, users will only be challenged once within any 24-hour window, alleviating the frequent MFA prompts while still requiring periodic verification to maintain a reasonable security baseline. This is the correct adjustment because it targets the exact parameter that controls prompt cadence without weakening other access controls.

Why this answer

The sign-in frequency control in Conditional Access determines how often a user must re-authenticate. Increasing the value from 1 hour to 24 hours directly reduces the frequency of MFA prompts while still requiring re-authentication daily, balancing security and user experience. This change applies to approved Microsoft applications as configured in the policy.

Exam trap

The trap here is that candidates confuse session controls like 'persistentBrowser' with sign-in frequency, assuming that keeping the browser session alive will also reduce MFA prompts, but sign-in frequency is a separate, explicit time-based re-authentication control that overrides session persistence.

How to eliminate wrong answers

Option A is wrong because enabling 'persistentBrowser' session control keeps the browser session alive but does not affect the sign-in frequency for MFA prompts; it only prevents re-authentication for browser-based sessions, not for all approved applications. Option B is wrong because changing cloudAppSecurityType to 'blockDownloads' is a session control for Microsoft Defender for Cloud Apps that restricts data exfiltration, not a mechanism to reduce MFA prompt frequency. Option C is wrong because removing the 'approvedApplication' grant control would eliminate the requirement that only approved Microsoft applications can be used, potentially allowing non-approved apps and increasing security risk, not reducing MFA prompts.

29
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to automatically detect sign-in attempts from anonymous IP addresses and sign-ins from unfamiliar locations. When such a risk is detected, they want to block the sign-in or require multi-factor authentication (MFA) in real time. Additionally, they need a dashboard that provides a summary of risk events and allows investigation. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Identity Protection
B.Microsoft Entra ID Conditional Access
C.Microsoft Entra ID Privileged Identity Management (PIM)
D.Microsoft Entra ID Access Reviews
AnswerA

Microsoft Entra ID Identity Protection is the risk detection engine that continuously analyzes sign-ins and user behavior, flagging events such as leaked credentials, impossible travel, and anonymous IP addresses. It assigns a risk level to both users and individual sign-ins and surfaces these findings on a dashboard with detailed investigation tools. These risk levels are then consumed by Conditional Access policies to enforce remediation like password reset or blocking access. Without Identity Protection, there is no risk signal source for other services to act on.

Why this answer

Microsoft Entra ID Identity Protection is the correct feature because it automatically detects sign-in risks such as anonymous IP addresses and unfamiliar locations, and can trigger real-time remediation actions like blocking the sign-in or requiring MFA. It also provides a risk dashboard and investigation capabilities, directly matching the requirements for risk detection, automated response, and reporting.

Exam trap

The trap here is that candidates often confuse Conditional Access as the detection mechanism, but Conditional Access is only the enforcement layer; Identity Protection is the actual detection engine that generates the risk signals used by Conditional Access.

How to eliminate wrong answers

Option B is wrong because Conditional Access is a policy engine that enforces access controls based on conditions, but it does not itself detect risks like anonymous IPs or unfamiliar locations; it relies on Identity Protection to provide risk signals. Option C is wrong because Privileged Identity Management (PIM) focuses on just-in-time privileged role activation and access governance, not on detecting sign-in risks from anonymous IPs or unfamiliar locations. Option D is wrong because Access Reviews are used for periodic attestation of group memberships or role assignments, not for real-time risk detection or automated sign-in blocking.

30
MCQeasy

Your company has a Microsoft Entra ID tenant with 10,000 users. You plan to grant external partners access to a specific SharePoint Online site using Microsoft Entra B2B collaboration. You need to ensure that partners can authenticate using their own corporate credentials. What should you configure?

A.Cross-tenant synchronization
B.Conditional Access policy for guest users
C.Microsoft Entra B2B collaboration with external identities
D.Microsoft Entra guest user accounts with password
AnswerC

Microsoft Entra B2B collaboration is the external-identities feature that lets you invite external users to access resources while they authenticate with their own identity provider, such as a corporate Azure AD tenant, Microsoft account, or a social IdP. This creates a guest user object in your tenant but the actual sign-in occurs at the partner's home tenant, and your tenant accepts the resulting token. This satisfies the requirement of allowing partner users to use their own credentials without managing passwords for them.

Why this answer

Microsoft Entra B2B collaboration allows external partners to authenticate using their own corporate credentials (such as Azure AD, Microsoft account, or other identity providers) without requiring a separate password or local account. This is the correct solution because it directly supports the requirement for partners to use their own identity providers, enabling seamless access to the SharePoint Online site via guest user invitations.

Exam trap

The trap here is that candidates often confuse Cross-tenant synchronization (Option A) with B2B collaboration, but Cross-tenant synchronization is for internal multi-tenant scenarios, not for granting external partners access with their own credentials.

How to eliminate wrong answers

Option A is wrong because Cross-tenant synchronization is designed to synchronize users between two Azure AD tenants for internal collaboration, not for granting external partners access to a specific SharePoint site with their own credentials. Option B is wrong because a Conditional Access policy for guest users controls access conditions (e.g., MFA, device compliance) after the guest user is already invited, but it does not enable authentication with the partner's own corporate credentials. Option D is wrong because creating guest user accounts with passwords would require partners to manage separate credentials, defeating the purpose of using their own corporate identities and violating the principle of federated authentication.

31
Multi-Selecthard

Your company has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You need to design a solution to monitor changes to privileged groups in both directories and ensure that any unauthorized changes trigger an automated response. Which THREE services should you include in the design?

Select 3 answers
A.Microsoft Sentinel
B.Microsoft Purview
C.Microsoft Entra Identity Protection
D.Group Policy Management Console
E.Microsoft Defender for Identity
AnswersA, C, E

Microsoft Sentinel ingests audit and sign-in logs from Microsoft Entra ID and on-premises Active Directory, correlates privileged group changes, and runs automation rules or playbooks that trigger an automated response when unauthorised modifications are detected.

Why this answer

Microsoft Sentinel (A) is correct because it is the cloud-native SIEM/SOAR platform that ingests audit and directory logs from both Microsoft Entra ID and on-premises Active Directory (via connectors and agents), correlates privileged group change events, and uses analytics rules plus playbooks (Logic Apps) to trigger automated responses such as disabling accounts or notifying admins. Microsoft Entra Identity Protection (C) is correct because it detects risky sign-ins and risky users, including risk detections tied to privileged account compromise, and can feed those signals into Conditional Access or Sentinel so that unauthorized privileged activity is flagged and remediated automatically. Microsoft Defender for Identity (E) is correct because it monitors on-premises Active Directory Domain Services traffic and events (e.g., via the sensor on domain controllers) to detect suspicious changes to privileged groups such as Domain Admins, and it forwards alerts to Defender XDR/Sentinel for automated response.

Microsoft Purview (B) is not included because it focuses on data governance, compliance, and information protection rather than real-time monitoring and automated response to directory privilege changes. Group Policy Management Console (D) is not included because it is an administrative tool for creating and managing GPOs, not a monitoring or automated-response service for privileged group modifications.

Exam trap

The trap here is that candidates often confuse Microsoft Purview (data governance) with Microsoft Defender for Cloud Apps (which can monitor group changes in SaaS apps) or assume Entra Identity Protection covers group membership monitoring, but neither Purview nor Identity Protection is designed for auditing or responding to privileged group modifications in hybrid directories.

32
MCQeasy

Your company has a large Azure environment with thousands of resources. You need to design a solution to track resource ownership and ensure that resources are cleaned up when projects end. You want to use a tag-based approach where each resource has an 'Owner' and 'Project' tag. Additionally, you need to generate a weekly report of resources that are not tagged or have been orphaned (no recent activity). What should you include in the design?

A.Use Azure Policy to audit missing tags and create a custom dashboard in Azure Monitor.
B.Use Azure Monitor alerts with a metric alert for unmodified resources.
C.Use Azure Automation runbook to inventory resources and store in a SQL database, then use Power BI to report.
D.Use Azure Resource Graph queries in an Azure Logic App scheduled to run weekly, and send the report via email.
AnswerD

This is the correct approach because Azure Resource Graph (ARG) provides a centralized, KQL-queryable inventory of all resource types and properties, including tags and sometimes a lastModified timestamp, which lets you filter for resources that appear orphaned based on staleness. A Logic App with a Recurrence trigger can invoke the 'Run Azure Resource Graph query' connector action weekly, handle pagination via the skip token for thousands of resources, and send the formatted results through an Office 365 Outlook or SMTP email action. This serverless composition avoids standing infrastructure, directly addresses the schedule-and-email requirement, and scales well beyond the resource count in the scenario.

Why this answer

Azure Resource Graph (ARG) provides fast, queryable access to resource properties across subscriptions, enabling efficient identification of untagged or orphaned resources. Scheduling an Azure Logic App to run ARG queries weekly and email the report meets the requirements for automation and delivery without additional infrastructure. This approach is cost-effective and scales well for thousands of resources.

Exam trap

The trap here is that candidates overcomplicate the solution by choosing a database and Power BI (Option C) or misapplying Azure Monitor alerts (Option B), when Azure Resource Graph with Logic Apps provides a simpler, serverless, and fully managed solution for scheduled resource inventory and reporting.

How to eliminate wrong answers

Option A is wrong because Azure Policy can audit missing tags but cannot detect orphaned resources (no recent activity); a custom dashboard in Azure Monitor visualizes metrics but does not generate scheduled reports. Option B is wrong because Azure Monitor metric alerts are designed for performance metrics (e.g., CPU usage), not for tracking resource modification timestamps or tag compliance; they cannot identify untagged or orphaned resources. Option C is wrong because using an Azure Automation runbook to inventory resources into a SQL database and then Power BI adds unnecessary complexity, cost, and maintenance overhead; Azure Resource Graph queries are simpler and natively support cross-subscription inventory without a database.

33
MCQhard

You are designing a monitoring solution for a critical application running on Azure Kubernetes Service (AKS). The application generates custom metrics that need to be queried in real-time for dashboards. You also need to retain logs for one year for compliance. Which combination of services should you use?

A.Azure Monitor Metrics and Azure Monitor Logs
B.Prometheus and Azure Monitor Logs
C.Azure Data Explorer and Azure Blob Storage
D.Application Insights and Azure Storage
AnswerA

Azure Monitor Metrics provides lightweight, high-granularity time-series data with sub-minute ingestion for real-time dashboards and alert rules, while Azure Monitor Logs stores verbose diagnostic and resource logs for years, enabling powerful KQL queries and trend analysis. Together they deliver both immediate operational visibility and deep historical investigation without any additional tooling, making them the natural native pair for AKS monitoring.

Why this answer

Azure Monitor Metrics is the correct choice for real-time querying of custom metrics because it stores numeric time-series data with sub-minute granularity and supports near real-time alerting and dashboarding via Azure Dashboards or Grafana. Azure Monitor Logs (Log Analytics) is required for retaining logs for one year, as it offers configurable retention up to 730 days (2 years) and supports KQL queries for compliance and audit needs. Together, they provide a unified monitoring solution for AKS that meets both real-time metric querying and long-term log retention requirements.

Exam trap

The trap here is that candidates often confuse Prometheus as the only way to collect custom metrics in AKS, but Azure Monitor Metrics natively supports custom metrics via the Azure Monitor agent and does not require a separate Prometheus deployment for real-time dashboards.

How to eliminate wrong answers

Option B is wrong because Prometheus is a third-party monitoring tool that, while commonly used with AKS, does not natively integrate with Azure Monitor Logs for log retention; you would need Azure Monitor for logs, making this combination redundant and less integrated. Option C is wrong because Azure Data Explorer is designed for big data analytics and interactive queries on large datasets, not for real-time metric dashboards, and Azure Blob Storage is a cold storage option that does not support real-time querying or native dashboarding. Option D is wrong because Application Insights is primarily for application performance monitoring (APM) and traces, not for storing custom metrics from AKS in a real-time queryable format, and Azure Storage (Blob) is not a log analytics platform and lacks the querying capabilities needed for compliance retention.

34
Multi-Selectmedium

Which TWO of the following are true about Microsoft Entra ID Governance features?

Select 2 answers
A.Conditional Access policies govern access based on location and device.
B.Access reviews allow administrators to periodically review and attest to access rights.
C.Privileged Identity Management (PIM) provides just-in-time access for all users.
D.Identity Protection automatically blocks all risky sign-ins.
E.Entitlement management enables automation of access request workflows.
AnswersB, E

Access reviews in Microsoft Entra ID are a governance control that enables administrators, or delegated reviewers, to conduct recurring certifications of group memberships, application assignments, and privileged roles. These reviews generate attestation evidence for compliance audits, and, based on the reviewer's decision, automatically remove stale or inappropriate access when configured with auto-apply. That periodic, human-in-the-loop attestation is exactly the access-lifecycle governance the question is asking about.

Why this answer

Microsoft Entra ID Access Reviews enable administrators to periodically review and attest to the access rights of users, groups, or applications, ensuring that only authorized users retain access. This is a core governance feature that helps organizations meet compliance and security requirements by automating the certification process.

Exam trap

The trap here is confusing security features (Conditional Access, Identity Protection) with governance features (Access Reviews, Entitlement Management), leading candidates to select options that enforce access rather than manage its lifecycle.

35
MCQmedium

A company uses Microsoft Entra ID. They need to monitor sign-in logs for anomalous activity (e.g., sign-ins from unfamiliar locations) and automatically take action such as requiring MFA or blocking sign-in. Which Microsoft Entra ID feature should they configure?

A.Identity Protection
B.Conditional Access
C.Access Reviews
D.Privileged Identity Management
AnswerA

Identity Protection is the correct choice because it continuously evaluates user sign-ins against dozens of risk signals—such as impossible travel, anonymous IP addresses, unfamiliar properties, and leaked credentials—using machine learning models that produce a per-sign-in risk level. It not only flags anomalous activity in real time but also exposes risk history in Entra ID reports, and it can natively trigger automated remediation when paired with a Conditional Access policy (e.g., block sign-in or require MFA). Its purpose is precisely to detect and respond to risky sign-ins rather than to enforce static policies or manage permissions.

Why this answer

Identity Protection is the correct feature because it is specifically designed to detect anomalous sign-in activities, such as sign-ins from unfamiliar locations or anonymous IP addresses, and can automatically trigger risk-based remediation actions like requiring MFA or blocking sign-ins. It leverages machine learning models and real-time risk detections to assess sign-in risks and apply policies accordingly, directly meeting the requirement for monitoring and automated response.

Exam trap

The trap here is that candidates often confuse Conditional Access as the detection mechanism, but it is only the enforcement layer; Identity Protection is the service that performs the actual anomaly detection and risk assessment.

How to eliminate wrong answers

Option B (Conditional Access) is wrong because it is a policy engine that enforces access controls based on conditions (e.g., location, device state), but it does not itself detect anomalous activity; it relies on risk signals from Identity Protection to trigger actions. Option C (Access Reviews) is wrong because it is used for periodic attestation of group memberships or application access, not for real-time monitoring or automated response to sign-in anomalies. Option D (Privileged Identity Management) is wrong because it focuses on just-in-time privileged role activation and approval workflows, not on detecting or responding to anomalous sign-in behavior.

36
MCQhard

Your organization uses Microsoft Entra ID with P2 licensing. You need to implement a strategy to automatically detect and remediate risky sign-ins without requiring user interaction for low-risk events. What should you configure?

A.Identity Protection sign-in risk policy set to allow access and log for low risk, and require MFA for medium and above
B.Conditional Access policy with session control requiring MFA for all sign-ins
C.Identity Protection user risk policy set to block high risk
D.Identity Protection sign-in risk policy set to allow access with MFA for medium and above
AnswerA

The Identity Protection sign-in risk policy evaluates real-time risk signals for each authentication event, such as anonymous IP addresses, impossible travel, or atypical directory access. Configuring it to allow access and log for low risk automatically remediates low-risk sign-ins by letting them proceed while generating an audit log for later review, while setting the medium-and-above action to require MFA forces stronger authentication only when risk warrants it. This precisely matches a risk-based remediation approach without disrupting ordinary sign-ins.

Why this answer

The Identity Protection sign-in risk policy allows you to automatically respond to sign-in risk levels. By configuring it to 'allow access' and 'log' for low risk, you meet the requirement of no user interaction for low-risk events, while requiring MFA for medium and above ensures remediation for higher-risk sign-ins without manual intervention.

Exam trap

The trap here is confusing sign-in risk policies (which evaluate individual sign-in events) with user risk policies (which evaluate overall user compromise), leading candidates to select Option C, which addresses user risk rather than the sign-in risk requirement.

How to eliminate wrong answers

Option B is wrong because a Conditional Access policy requiring MFA for all sign-ins does not differentiate by risk level, forcing user interaction even for low-risk events, which contradicts the requirement to avoid user interaction for low risk. Option C is wrong because the Identity Protection user risk policy targets user account compromise (e.g., leaked credentials), not sign-in risk; it blocks high-risk users but does not address the sign-in risk detection and remediation for low-risk events. Option D is wrong because it requires MFA for medium and above but does not explicitly allow and log low-risk sign-ins without user interaction; the 'allow access with MFA' for medium and above still triggers MFA for medium risk, but the policy lacks the 'log' action for low risk, potentially blocking or requiring interaction for low-risk events depending on defaults.

37
MCQmedium

Your company has a Microsoft Entra ID tenant with 50,000 users. You need to design a solution to ensure that users can reset their own passwords without help desk intervention, while preventing password reuse for the last 10 passwords. Which feature should you enable?

A.Microsoft Entra ID Protection
B.Microsoft Entra Connect
C.Privileged Identity Management (PIM)
D.Self-Service Password Reset (SSPR)
AnswerD

Self-Service Password Reset (SSPR) is the correct Entra ID capability that lets end users reset or change their own passwords after verifying authentication methods such as phone, email, or security questions. Administrators can configure SSPR registration requirements, and by combining SSPR with Entra ID Password Protection, the tenant can enforce password reuse restrictions—for example, specifying that a new password cannot match a remembered set of prior passwords. This directly satisfies the company's need for users to reset their own passwords while enforcing anti-reuse policy.

Why this answer

Self-Service Password Reset (SSPR) is the correct feature because it allows users to reset their own passwords without help desk intervention. Additionally, SSPR can be configured with password protection policies that enforce password history, preventing reuse of the last 10 passwords. This directly meets both requirements stated in the question.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID Protection (which handles risk-based policies) with SSPR, or they mistakenly think PIM is involved because it deals with passwords, but PIM is strictly for privileged role management, not end-user password resets.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Protection is a security tool that detects and responds to identity-based risks (e.g., leaked credentials, sign-in anomalies), but it does not provide self-service password reset capabilities or enforce password history policies. Option B is wrong because Microsoft Entra Connect is used for hybrid identity synchronization between on-premises Active Directory and Azure AD, not for password reset or reuse prevention. Option C is wrong because Privileged Identity Management (PIM) manages just-in-time access and role activation for privileged roles, not general user password reset or password history enforcement.

38
Multi-Selectmedium

Which TWO actions should you take to implement a least-privilege identity strategy for Azure resources?

Select 2 answers
A.Use managed identities for Azure resources instead of service principals with secrets
B.Assign the Contributor role at the subscription scope to allow flexibility
C.Use storage account keys for access to blob data
D.Enable Privileged Identity Management (PIM) for just-in-time role assignments
E.Use a single service principal for all applications
AnswersA, D

Managed identities for Azure resources eliminate the need to store, rotate, or protect service principal secrets because Azure automatically binds the identity to the resource and rotates credentials. You can assign a granular RBAC role, such as Storage Blob Data Reader at a specific resource scope, so the identity cannot exceed its intended permissions. This directly supports least privilege by removing long-lived credential management and enforcing scoped access without human intervention.

Why this answer

Managed identities for Azure resources eliminate the need to manage credentials by automatically rotating them and binding them to a resource lifecycle. This removes the risk of secret leakage or mismanagement that exists with service principal secrets, directly supporting a least-privilege identity strategy by ensuring identities are scoped and ephemeral.

Exam trap

The trap here is that candidates often confuse 'least privilege' with 'convenience' and select broad roles like Contributor at subscription scope, thinking it provides flexibility, when in reality it grants excessive permissions that violate the core principle.

39
MCQeasy

Your company has multiple Azure subscriptions and needs a single pane of glass to monitor the health and performance of all resources across subscriptions. Which Azure service should you use?

A.Microsoft Sentinel
B.Azure Service Health
C.Azure Monitor
D.Azure Advisor
AnswerC

Azure Monitor is the central monitoring platform in Azure that collects, analyzes, and responds to telemetry from secure resources, applications, and even on-premises systems. It acquires platform metrics, custom logs, and diagnostics data via Azure Diagnostics extensions and Log Analytics agent, enabling comprehensive visibility into resource health, performance, and dependencies across all subscriptions in a tenant. Azure Monitor supports powerful querying with KQL, creating alert rules, and visualizing dashboards, making it the exact service for a requirement spanning multiple subscriptions. It is the correct answer because it is purpose-built for unified resource observability.

Why this answer

Azure Monitor is the correct choice because it provides a unified, single-pane-of-glass experience for collecting, analyzing, and acting on telemetry from all Azure resources across multiple subscriptions. It aggregates metrics, logs, and alerts from various sources, enabling cross-subscription monitoring of health and performance without requiring separate tools.

Exam trap

The trap here is confusing Azure Monitor's broad monitoring capabilities with specialized services like Sentinel (security) or Service Health (Azure infrastructure status), leading candidates to pick a tool that addresses only a subset of the requirement.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) tool focused on security detection, investigation, and response, not general resource health and performance monitoring. Option B is wrong because Azure Service Health provides personalized alerts and guidance for Azure service issues and planned maintenance, but it does not monitor the health and performance of your own deployed resources. Option D is wrong because Azure Advisor is a personalized cloud consultant that offers best-practice recommendations for cost, security, reliability, and performance, but it does not provide real-time monitoring or a dashboard for resource health and performance.

40
MCQeasy

A multinational company uses Microsoft Entra ID. The company has regional IT teams that need to manage users and groups within their respective regions. Each region has a distinct set of users in specific organizational units. The company wants to assign the User Administrator role to regional IT staff, but limit their scope to only the users in their region. Which Microsoft Entra ID feature should they use?

A.Administrative Units
B.Dynamic Groups
C.Microsoft Entra ID B2B
D.Microsoft Entra ID Identity Protection
AnswerA

Administrative Units are the correct approach because they partition a tenant's users, groups, and devices into explicit management boundaries. An administrator can assign a built-in or custom role such as User Administrator or Helpdesk Administrator scoped to a specific Administrative Unit, so regional IT staff see and manage only the objects in their local unit. This gives the desired delegated administration while preventing tenant-wide access.

Why this answer

Administrative Units in Microsoft Entra ID allow you to delegate administrative roles, such as User Administrator, to a specific subset of users and groups defined by organizational boundaries (e.g., region). By creating an Administrative Unit for each region and adding the regional users and groups to it, you can assign the User Administrator role scoped to that unit, ensuring regional IT staff can only manage their own region's identities.

Exam trap

The trap here is that candidates often confuse Administrative Units with Dynamic Groups, thinking that group-based membership scoping is equivalent to role-based administrative scoping, but Dynamic Groups only control group membership, not administrative permissions.

How to eliminate wrong answers

Option B is wrong because Dynamic Groups automatically manage group membership based on user attributes (e.g., department), but they do not provide role-based access control scoping; they cannot restrict administrative permissions to a subset of users. Option C is wrong because Microsoft Entra ID B2B is designed for external collaboration with guest users from partner organizations, not for delegating administrative control over internal users within the same tenant. Option D is wrong because Microsoft Entra ID Identity Protection is a security feature that detects and responds to identity risks (e.g., compromised credentials), and it does not offer any capability to scope administrative roles to specific users or regions.

41
MCQeasy

You need to ensure that only authorized users can access the Azure portal. What should you use?

A.Conditional Access policies
B.Azure RBAC
C.Privileged Identity Management (PIM)
D.Azure AD Identity Protection
AnswerA

Conditional Access policies are Azure AD policies that evaluate multiple signals—such as user and group membership, device compliance, location, and sign-in risk—before allowing access to the Azure portal. They can enforce multi-factor authentication, block access from high-risk geographies, or require hybrid-joined devices, thereby making the authorization decision at the authentication layer. This is the correct mechanism for ensuring only authorized users can access the portal, because it does not rely on resource-level permissions but on the user's identity and sign-in context.

Why this answer

Conditional Access policies are the correct choice because they enforce access control decisions at the Azure AD authentication layer, allowing you to require specific conditions (e.g., MFA, compliant device, trusted IP) before a user can sign in to the Azure portal. This directly ensures that only authorized users—those meeting the defined conditions—can access the portal, regardless of their role assignments. Azure RBAC controls what actions a user can perform after authentication, not whether they can sign in at all.

Exam trap

The trap here is confusing authorization (what you can do after signing in, handled by RBAC) with authentication and access control (who can sign in, handled by Conditional Access), leading candidates to incorrectly choose Azure RBAC or PIM.

How to eliminate wrong answers

Option B is wrong because Azure RBAC (Role-Based Access Control) manages permissions for Azure resources after authentication, such as who can create VMs or read storage accounts, but it does not control the initial sign-in process to the Azure portal. Option C is wrong because Privileged Identity Management (PIM) provides just-in-time activation and approval workflows for privileged roles, but it does not block unauthorized users from accessing the portal; it only manages role assignments and activation. Option D is wrong because Azure AD Identity Protection detects and responds to identity risks (e.g., leaked credentials, sign-ins from anonymous IPs) but does not directly enforce access control policies to block unauthorized users from the portal; it feeds risk signals into Conditional Access for enforcement.

42
MCQmedium

A company is migrating on-premises Windows applications that require LDAP, NTLM, or Kerberos authentication to Azure VMs. They want to provide domain services for these applications without deploying and managing domain controllers. Which Azure service should they use?

A.Microsoft Entra ID
B.Microsoft Entra ID Domain Services
C.Active Directory on Azure VMs
D.Microsoft Entra ID B2C
AnswerB

Microsoft Entra ID Domain Services (AAD DS) provides a fully managed Windows Server Active Directory-compatible domain controller that is synchronized from Entra ID. It natively supports LDAP, including secure LDAP (LDAPS), and NTLM/Kerberos authentication, making it the intended choice for lifting and shifting on-premises apps that need an AD-joined infrastructure. Microsoft handles patching, availability, and domain controller replication, eliminating the administration burden.

Why this answer

Microsoft Entra ID Domain Services (formerly Azure AD DS) provides managed domain services such as LDAP, NTLM, and Kerberos authentication without requiring you to deploy, patch, or manage domain controllers. It integrates with your existing Microsoft Entra tenant and supports group policy, domain join, and legacy authentication protocols needed by the on-premises Windows applications being migrated to Azure VMs.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID (a modern identity provider) with Microsoft Entra ID Domain Services (which provides legacy protocol support), leading them to incorrectly select Entra ID for LDAP/NTLM/Kerberos needs.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID is a cloud-based identity and access management service that uses modern protocols like OAuth 2.0, OpenID Connect, and SAML, and does not natively support LDAP, NTLM, or Kerberos authentication required by legacy Windows applications. Option C is wrong because deploying Active Directory on Azure VMs would require you to manually manage domain controllers, which contradicts the requirement to avoid deploying and managing domain controllers. Option D is wrong because Microsoft Entra ID B2C is designed for customer-facing identity management with social and local account sign-ins, not for providing domain services like LDAP or Kerberos for enterprise applications.

43
Multi-Selecteasy

Which TWO features of Microsoft Entra ID help protect against credential compromise? (Choose two.)

Select 2 answers
A.Microsoft Entra Conditional Access
B.Microsoft Entra Identity Protection
C.Microsoft Entra Password Protection
D.Microsoft Entra Smart Lockout
E.Microsoft Entra access reviews
AnswersC, D

Microsoft Entra Password Protection actively blocks users from selecting weak or easily guessed passwords by maintaining a global banned password list (e.g., 'Password123', 'P@ssw0rd') and allowing tenant administrators to add custom banned words and patterns. It is applied at the point of password creation or change, preventing the credential from ever being set to a vulnerable value. This directly hardens the password against dictionary and guessing attacks, making it a correct answer.

Why this answer

Microsoft Entra Password Protection automatically blocks weak passwords and common password variations (e.g., 'Password123!') by comparing them against a global banned password list and an optional custom banned password list. This directly prevents users from setting easily guessable credentials, reducing the risk of credential compromise.

Exam trap

The trap here is that candidates often confuse detection/remediation features (Identity Protection) or policy enforcement (Conditional Access) with direct credential protection mechanisms, leading them to select options that manage risk after compromise rather than preventing weak passwords or brute-force attacks.

44
MCQhard

Your company has a Microsoft Entra ID tenant with 10,000 users. You need to implement a lifecycle workflow that automatically disables user accounts when employees leave the organization, and then deletes them after 30 days. What should you use?

A.Microsoft Entra Domain Services
B.Microsoft Entra ID Governance
C.Microsoft Intune
D.Microsoft Entra Connect Health
AnswerB

Microsoft Entra ID Governance contains Lifecycle Workflows, a feature that automates joiner, mover, and leaver scenarios by orchestrating tasks like sending notifications, assigning access, and disabling accounts. These workflows can be triggered by HR-driven provisioning, schedules, or on-demand execution, and they provide centralized logging and audit trails. This exactly addresses the company's need to automate lifecycle processes for 10,000 users, making it the correct choice.

Why this answer

Microsoft Entra ID Governance includes lifecycle workflows that automate the process of disabling and deleting user accounts based on triggers such as employee departure. This feature allows you to configure a workflow that disables the account immediately and then schedules deletion after a specified period, such as 30 days, without requiring custom scripting or manual intervention.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID Governance with Microsoft Entra Domain Services, mistakenly thinking that domain services include user lifecycle management, when in fact Entra ID Governance is the correct service for automated identity lifecycle tasks.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Domain Services provides managed domain services like LDAP and Kerberos, not lifecycle automation for user accounts. Option C is wrong because Microsoft Intune focuses on mobile device management (MDM) and mobile application management (MAM), not on automating user account lifecycle in Entra ID. Option D is wrong because Microsoft Entra Connect Health monitors the health of on-premises identity infrastructure and sync, not user account lifecycle workflows.

45
MCQmedium

A company uses Microsoft Entra ID B2B collaboration for external partners. They want to enforce that external users must use multi-factor authentication (MFA) and access company resources only from devices that are compliant with Intune policies. Additionally, they need to require a session timeout of 1 hour. Which combination of Microsoft Entra ID features should they use?

A.Configure cross-tenant access settings to trust MFA and device compliance from external organizations, and then create a Conditional Access policy that requires MFA, compliant device, and a session sign-in frequency of 1 hour.
B.Create a Conditional Access policy for external users that requires MFA and compliant device, and set session controls for sign-in frequency. Trusting MFA from external tenants is automatic.
C.Use Microsoft Entra ID Identity Protection to detect risky sessions for external users and require MFA only when risk is high. This will also enforce device compliance automatically.
D.Configure Microsoft Entra ID Privileged Identity Management (PIM) for external users to activate MFA and require compliant device. PIM is for role activation, not for external user access policies.
AnswerA

Cross-tenant access settings in Microsoft Entra ID let you explicitly trust MFA, compliant device, and hybrid Azure AD joined device claims that external organizations assert about their own users. After configuring that inbound trust for the partner tenant, you must create a Conditional Access policy that targets external users and grants access only when MFA is satisfied, a compliant device is reported, and the session sign-in frequency does not exceed one hour. This two-step approach is mandatory because the trust settings establish which claims are honored, while the Conditional Access policy defines the conditions and session controls that are actually enforced at the resource tenant.

Why this answer

Cross-tenant access settings in Microsoft Entra ID allow you to trust MFA and device compliance claims from external organizations, which is necessary when external users bring their own devices. Then, a Conditional Access policy targeting external users can enforce MFA, require compliant device, and set a session sign-in frequency of 1 hour using session controls. This combination ensures that the company's security requirements are met without relying on the external tenant's policies.

Exam trap

The trap here is that candidates assume MFA and device compliance from external users are automatically trusted or can be enforced solely through Conditional Access, forgetting that cross-tenant trust settings must be explicitly configured to accept those claims from the external organization.

How to eliminate wrong answers

Option B is wrong because trusting MFA from external tenants is not automatic; it must be explicitly configured in cross-tenant access settings, otherwise the Conditional Access policy cannot rely on MFA claims from the external user's home tenant. Option C is wrong because Identity Protection detects risk but does not enforce device compliance automatically; it can require MFA based on risk level but cannot mandate compliant device or session timeout. Option D is wrong because Privileged Identity Management (PIM) is designed for just-in-time role activation, not for enforcing MFA, device compliance, or session controls for external user access to resources.

46
MCQeasy

Your company is implementing a new Azure subscription for a project that requires strict separation of duties. The security team requires that all resource creation must be approved by a central IT team. Additionally, any resource that does not comply with company tagging standards should be automatically reported. You need to design a solution that meets these requirements using Azure Policy and Azure Role-Based Access Control (RBAC). What should you do?

A.Use Azure Policy with 'Audit' effect to report non-compliant resources. Use Azure RBAC to assign Owner role to IT team.
B.Use Azure Policy with 'Append' effect to automatically add required tags at creation. Use Azure Monitor alerts for non-compliance.
C.Create an Azure Policy with 'DeployIfNotExists' to deploy a tagging template. Use Azure RBAC to assign Contributor role to IT team.
D.Create a custom RBAC role that allows only the IT team to add a specific 'Approved' tag. Use Azure Policy with 'Deny' effect to block resources without that tag. Use a separate 'Audit' policy for other tagging standards.
AnswerD

This solution enforces approval at the point of creation by combining a custom RBAC role that grants the IT team exclusive permission to write the 'Approved' tag (via Microsoft.Resources/tags/write) with an Azure Policy using the Deny effect that blocks any resource lacking that tag. When a deployment attempts to create a resource without the approved tag, the Deny policy causes the deployment to fail, making the approval a mandatory part of the provisioning process. A separate Audit policy then monitors other tagging standards, providing compliance visibility without blocking deployments, while the Deny policy enforces the critical approval requirement.

Why this answer

It uses a custom RBAC role to restrict the ability to add an 'Approved' tag to the IT team, combined with a Deny policy that blocks creation of any resource lacking that tag, ensuring all resource creation requires IT approval. The separate Audit policy automatically reports resources that fail to meet other company tagging standards, fulfilling both the approval and compliance reporting requirements without manual intervention.

Exam trap

The trap here is that candidates often think a simple RBAC role assignment (like Owner or Contributor) combined with an Audit policy is sufficient, but they overlook the need for a Deny policy to actively block unapproved resource creation, which is essential for strict separation of duties.

How to eliminate wrong answers

Option A is wrong because assigning the Owner role to the IT team grants them full control over all resources, including the ability to bypass approval and modify permissions, which violates strict separation of duties. Option B is wrong because the Append effect automatically adds required tags at creation but does not enforce approval; Azure Monitor alerts can report non-compliance but do not block unapproved creation or enforce tagging standards at the policy level. Option C is wrong because DeployIfNotExists deploys a tagging template to remediate non-compliant resources but does not prevent creation of unapproved resources; assigning Contributor role to the IT team allows them to create resources without requiring approval, breaking separation of duties.

47
MCQmedium

Refer to the exhibit. You are an Azure administrator reviewing a custom Azure Policy definition. What does this policy do?

A.Denies the creation of virtual machines with the SKUs Standard_D2s_v3 or Standard_D4s_v3.
B.Denies the creation of resource groups that contain virtual machines with the specified SKUs.
C.Allows only virtual machines with the SKUs Standard_D2s_v3 or Standard_D4s_v3 to be created in a specific region.
D.Audits virtual machines to check if they have the SKUs Standard_D2s_v3 or Standard_D4s_v3.
AnswerA

This policy definition uses the `Microsoft.Compute/virtualMachines/sku.name` property in its `if` condition, checking whether the SKU name matches either `Standard_D2s_v3` or `Standard_D4s_v3`. When a VM creation or update request contains one of these SKUs, the `Deny` effect is triggered and the deployment is blocked before any resource is provisioned. This is the correct interpretation because the policy targets the VM resource type directly, not the resource group or a specific region.

Why this answer

The policy definition uses the 'deny' effect, which blocks any request that matches the specified condition. The condition checks if the virtual machine SKU is either 'Standard_D2s_v3' or 'Standard_D4s_v3' using the 'in' operator on the 'Microsoft.Compute/virtualMachines/sku.name' alias. Therefore, any attempt to create a VM with these SKUs will be denied, making Option A correct.

Exam trap

The trap here is that candidates confuse the 'deny' effect with 'audit' or 'DeployIfNotExists', or misinterpret the condition as allowing only those SKUs instead of denying them, leading them to select Option C or D.

How to eliminate wrong answers

Option B is wrong because the policy targets the 'Microsoft.Compute/virtualMachines' resource type, not 'Microsoft.Resources/resourceGroups', and the condition evaluates the VM SKU, not the resource group's contents. Option C is wrong because the policy uses a 'deny' effect, not 'allow' or 'DeployIfNotExists', and it does not include any location-based condition (e.g., 'location' alias) to restrict creation to a specific region. Option D is wrong because the policy uses the 'deny' effect, not 'audit' or 'AuditIfNotExists', so it actively blocks creation rather than merely auditing existing VMs.

48
MCQmedium

An organization wants to enforce MFA only when sign-in risk is medium or high. Which Microsoft Entra capability should be used?

A.Azure RBAC deny assignments only
B.Conditional Access with Identity Protection risk signals
C.Access reviews only
D.Administrative units only
AnswerB

Conditional Access policies can directly reference Identity Protection sign-in risk levels (low, medium, high) and evaluate them during the authentication event. Configuring a policy to require MFA when sign-in risk is medium or high achieves the exact requirement, while optionally adding a block action for high risk. This is the built-in Azure AD mechanism for dynamic, risk-based step-up authentication.

Why this answer

Conditional Access policies can integrate with Microsoft Entra Identity Protection risk signals to enforce MFA based on the calculated sign-in risk level (low, medium, high). When the risk is medium or high, the policy triggers MFA, meeting the requirement precisely. This is the only Microsoft Entra capability that directly uses risk-based conditional enforcement.

Exam trap

The trap here is that candidates often confuse Azure RBAC (which controls resource access) with Conditional Access (which controls authentication and session conditions), leading them to pick a permission-based option instead of the risk-based policy engine.

How to eliminate wrong answers

Option A is wrong because Azure RBAC deny assignments control access to Azure resources via role-based permissions and cannot evaluate sign-in risk or enforce MFA. Option C is wrong because Access reviews are used for periodic attestation of group memberships or application access, not for real-time risk-based MFA enforcement. Option D is wrong because Administrative units are used to delegate administrative scope within a tenant, not to enforce authentication policies based on risk.

49
MCQhard

Your Azure environment includes multiple subscriptions that are managed by different teams. You need to ensure that all resources are compliant with your company's security policies, and any non-compliant resources must be automatically remediated or reported. Which solution should you implement?

A.Azure Policy with remediation tasks
B.Azure Blueprints
C.Azure RBAC
D.Microsoft Defender for Cloud
AnswerA

Azure Policy with remediation tasks is correct because DeployIfNotExists and Modify effects can automatically correct non-compliant resources when the policy is assigned. A managed identity is assigned to the policy definition, and remediation tasks run on existing resources, while new resources are fixed during creation. This provides continuous, automated enforcement across your subscriptions, making it the only option that actively remediates configuration drift, not just reports it.

Why this answer

Azure Policy with remediation tasks is the correct solution because it allows you to define and enforce security policies across multiple subscriptions, and automatically remediate non-compliant resources using managed identities and DeployIfNotExists or Modify policy effects. This ensures continuous compliance without manual intervention, meeting the requirement for both automatic remediation and reporting.

Exam trap

The trap here is that candidates often confuse Azure Policy (for governance and remediation) with Azure Blueprints (for environment setup) or Microsoft Defender for Cloud (for security monitoring), but only Azure Policy with remediation tasks provides the automatic, continuous enforcement and remediation required for compliance.

How to eliminate wrong answers

Option B (Azure Blueprints) is wrong because it is primarily a packaging and orchestration tool for deploying consistent environments (including policies, RBAC, and resource groups), but it does not provide automatic remediation of non-compliant resources after deployment; it is a one-time or versioned deployment artifact, not a continuous compliance enforcement mechanism. Option C (Azure RBAC) is wrong because it controls who can access and manage resources (authorization), not what resources are compliant with security policies; it cannot detect or remediate non-compliant configurations. Option D (Microsoft Defender for Cloud) is wrong because it provides security posture management, threat detection, and recommendations, but it does not automatically remediate non-compliant resources by itself; it can integrate with Azure Policy for remediation, but the core enforcement and remediation engine is Azure Policy, not Defender for Cloud.

50
MCQeasy

A company wants to monitor sign-in failures for their Microsoft Entra ID-integrated applications. They need a dashboard in Azure Monitor showing sign-in failures by application and user location. Which data source should they stream to a Log Analytics workspace?

A.Microsoft Entra ID Audit logs
B.Microsoft Entra ID Sign-in logs
C.Microsoft Entra ID Provisioning logs
D.Office 365 Activity logs
AnswerB

Microsoft Entra ID Sign-in logs are the authoritative telemetry for authentication against the directory, containing both successful and failed sign-in attempts for interactive and non-interactive sessions. Each entry includes the user principal name, application, client IP, device, location, and a specific sign-in error code (e.g., 50126 for invalid password), along with conditional access and MFA status. Because they persist and expose the exact failure reason, they are the correct data source for monitoring sign-in failures across Entra ID-integrated applications.

Why this answer

Microsoft Entra ID Sign-in logs contain detailed information about every sign-in attempt, including success or failure status, application name, user location (IP address), and failure reasons. Streaming these logs to a Log Analytics workspace enables you to build custom dashboards in Azure Monitor that visualize sign-in failures by application and user location. Audit logs track configuration changes, not authentication events; Provisioning logs cover user/group synchronization; and Office 365 Activity logs focus on workload-specific actions, not general sign-in failures.

Exam trap

The trap here is that candidates often confuse Audit logs with Sign-in logs, assuming Audit logs capture all security events, but Audit logs specifically exclude authentication attempts and location data.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Audit logs record changes made to the directory (e.g., user creation, policy updates) and do not contain sign-in failure events or user location data. Option C is wrong because Microsoft Entra ID Provisioning logs track synchronization activities between Entra ID and third-party applications (e.g., ServiceNow, SAP) and do not capture sign-in failures. Option D is wrong because Office 365 Activity logs capture user actions within Exchange Online, SharePoint Online, and other Office 365 workloads, but they do not include sign-in failure details for all Entra ID-integrated applications or user location data.

51
MCQeasy

Your company plans to use Microsoft Sentinel as a SIEM solution. You need to ensure that security events from all Azure subscriptions are collected in a single workspace. What should you configure?

A.Create a Log Analytics workspace per subscription and use cross-workspace queries
B.Use Azure Policy to enforce Log Analytics workspace configuration across subscriptions
C.Deploy Microsoft Sentinel in each subscription and connect them via Azure Lighthouse
D.Enable Microsoft Sentinel on a single Log Analytics workspace and configure diagnostic settings for all subscriptions to send logs to that workspace
AnswerD

Enabling Microsoft Sentinel on a single Log Analytics workspace makes that workspace the system-of-record for security telemetry, and configuring Azure diagnostic settings on each subscription (and resource) to stream logs — including Activity Logs and resource-specific logs — into that same workspace ensures all data converges in one location. This provides a centralized SIEM with unified incident management, hunting, and correlation, which is the exact architecture Sentinel requires for a single-tenant security operations center.

Why this answer

Microsoft Sentinel requires a single Log Analytics workspace to act as the SIEM repository. By enabling Sentinel on that workspace and configuring diagnostic settings on all Azure subscriptions to stream their security logs (e.g., Activity logs, NSG flow logs, Windows Event logs) to that same workspace, you centralize all security events in one location. This ensures unified detection, investigation, and response across the entire enterprise without needing multiple Sentinel instances.

Exam trap

The trap here is that candidates often confuse Azure Policy's ability to enforce log collection with the need to also enable Sentinel on a single workspace, or they mistakenly think cross-workspace queries or multiple Sentinel instances can achieve the same centralized correlation, which violates Sentinel's architecture requirement for a single data repository.

How to eliminate wrong answers

Option A is wrong because creating a separate Log Analytics workspace per subscription and using cross-workspace queries does not consolidate events into a single workspace; it only allows querying across workspaces, which breaks Sentinel's single-pane-of-glass requirement for correlation and incident management. Option B is wrong because Azure Policy can enforce that resources send logs to a specific Log Analytics workspace, but it cannot enable Microsoft Sentinel itself or guarantee that all security events from all subscriptions are collected in one workspace without also configuring diagnostic settings. Option C is wrong because deploying Microsoft Sentinel in each subscription creates isolated SIEM instances that cannot share incidents, analytics rules, or workbooks; Azure Lighthouse provides cross-subscription management but does not merge data into a single Sentinel workspace.

52
MCQmedium

Your organization uses Microsoft Defender for Cloud to assess the security posture of Azure resources. You need to ensure that all Azure subscriptions are covered by a single continuous export configuration that sends security alerts to a Log Analytics workspace. What should you do?

A.Use Azure Policy to deploy continuous export settings to all subscriptions.
B.Configure continuous export at the management group level.
C.Create an Azure Automation runbook to export settings to all subscriptions.
D.Configure continuous export in each subscription individually.
AnswerB

Configuring continuous export at the management group level is the correct single configuration point. In Microsoft Defender for Cloud, you can define the export settings (target Log Analytics workspace or Event Hub, and the data types such as alerts and recommendations) at a management group scope, and those settings are inherited by every subscription under that group. This ensures a consistent, centrally managed configuration without needing to touch individual subscriptions, and any new subscription added to the group automatically receives the same export settings.

Why this answer

Continuous export can be configured at the subscription level or management group scope. By configuring it at the management group level, all subscriptions under that management group inherit the export settings. This provides a single configuration point.

53
MCQmedium

Your organization is implementing a hybrid identity solution with Microsoft Entra ID. Users in an on-premises Active Directory domain need to access cloud applications. You need to ensure that password changes on-premises are synchronized to Entra ID within 30 seconds. Which configuration should you use?

A.Pass-through Authentication (PTA)
B.Federation with Active Directory Federation Services (AD FS)
C.Microsoft Entra Cloud Sync
D.Microsoft Entra Connect Sync with password hash synchronization
AnswerC

Microsoft Entra Cloud Sync uses a lightweight provisioning agent installed on-premises to connect directly to Entra ID, and its default delta synchronization cycle runs roughly every 30 seconds for user, group, and password hash changes. Because it supports password hash synchronization and synchronizes attributes in near-real time, it satisfies the requirement for changes to appear in the cloud quickly. Cloud Sync is therefore the correct choice when a 30-second sync window is required without running the full Microsoft Entra Connect sync engine.

Why this answer

Microsoft Entra Cloud Sync (Option C) is the correct choice because it is designed for near-real-time synchronization of identity changes, including password writes, with a target latency of under 30 seconds. It uses the lightweight Microsoft Entra Connect provisioning agent and the SCIM (System for Cross-domain Identity Management) protocol to sync changes from on-premises Active Directory to Entra ID, meeting the strict 30-second requirement for password change propagation.

Exam trap

The trap here is that candidates often confuse Microsoft Entra Connect Sync (Option D) with Microsoft Entra Cloud Sync (Option C), assuming both offer the same synchronization speed, but Connect Sync uses a scheduled batch process (default 2-minute interval) that cannot meet the 30-second requirement, while Cloud Sync is designed for near-real-time sync.

How to eliminate wrong answers

Option A is wrong because Pass-Through Authentication (PTA) validates passwords directly against on-premises AD without synchronizing password hashes to Entra ID, so it does not propagate password changes to the cloud. Option B is wrong because Federation with AD FS relies on on-premises authentication and does not synchronize password changes to Entra ID; it only redirects authentication requests. Option D is wrong because Microsoft Entra Connect Sync with password hash synchronization typically runs on a schedule (default every 2 minutes) and cannot guarantee synchronization within 30 seconds; it is designed for batch sync, not near-real-time propagation.

54
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID) for identity management. They want to automatically detect sign-in risks such as sign-ins from unfamiliar locations, anonymous IP addresses, or leaked credentials. Based on the risk level, they want to apply different controls: for low-risk sign-ins, show a message but allow access; for medium-risk sign-ins, require multi-factor authentication (MFA); for high-risk sign-ins, block the sign-in. They also need to receive a weekly summary report of risk events. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra ID Identity Protection policies
B.Microsoft Entra ID Conditional Access policies with sign-in risk conditions
C.Microsoft Entra ID Access Reviews
D.Microsoft Entra ID Privileged Identity Management (PIM)
AnswerB

Conditional Access policies can evaluate sign-in risk levels (low, medium, high) from Identity Protection and apply granular controls such as block, require MFA, or session controls. Combined with Identity Protection reports, you get the weekly summary.

Why this answer

Microsoft Entra ID Conditional Access policies can integrate sign-in risk conditions from Identity Protection to enforce granular controls based on risk levels. This allows you to configure actions such as showing a message for low risk, requiring MFA for medium risk, and blocking access for high risk, while Identity Protection provides the weekly summary report of risk events.

Exam trap

The trap here is that candidates often confuse Identity Protection (the detection engine) with Conditional Access (the enforcement engine), assuming Identity Protection alone can apply the per-risk-level controls, when in reality Conditional Access policies are required to map risk levels to specific actions like MFA or block.

How to eliminate wrong answers

Option A is wrong because Identity Protection policies alone detect risks and can trigger automated responses, but they do not natively support the granular per-risk-level controls (e.g., show message for low, MFA for medium, block for high) that Conditional Access policies provide; Conditional Access is the enforcement layer. Option C is wrong because Access Reviews are used for periodic attestation of group memberships or application access, not for real-time risk-based sign-in controls or risk event reporting. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not sign-in risk detection or conditional access based on risk levels.

55
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID). They have a SaaS application that supports SCIM (System for Cross-domain Identity Management). The company wants to automatically create, update, and deactivate user accounts in the SaaS application whenever changes occur in Microsoft Entra ID. They do not want to use custom scripts. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra ID Application Proxy
B.Microsoft Entra ID Provisioning (Automatic User Provisioning)
C.Microsoft Entra ID Connect
D.Microsoft Entra ID B2B Collaboration
AnswerB

Microsoft Entra ID Provisioning (Automatic User Provisioning) is the correct answer because it enables the Entra ID provisioning service to automatically create, update, and deactivate user accounts in any SaaS application that implements a System for Cross-domain Identity Management (SCIM) 2.0 endpoint, based on user and group assignments in Entra ID. This service continuously remediates identity matches against the tenant directory, ensuring that attribute changes and role changes are propagated and that accounts are disabled when a user loses access. It is exactly the mechanism that automates identity lifecycle in SaaS apps, often replacing manual CSV-based administration.

Why this answer

Microsoft Entra ID Provisioning (Automatic User Provisioning) is the correct feature because it natively supports the SCIM (System for Cross-domain Identity Management) protocol to automate the creation, update, and deactivation of user accounts in SaaS applications. This eliminates the need for custom scripts by synchronizing identity changes from Microsoft Entra ID to the target application in near real-time.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID Connect (which syncs from on-premises AD) with cloud-to-SaaS provisioning, but the question explicitly targets a cloud-only SaaS application with no on-premises dependency.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Application Proxy provides secure remote access to on-premises web applications, not user provisioning to SaaS apps. Option C is wrong because Microsoft Entra ID Connect is used for hybrid identity synchronization between on-premises Active Directory and Microsoft Entra ID, not for provisioning users to third-party SaaS applications. Option D is wrong because Microsoft Entra ID B2B Collaboration enables external user access to your organization's resources, not automated user lifecycle management in a SaaS application.

56
MCQmedium

A company uses Azure Policy to enforce tagging on resources. The security team reports that some resources are missing the required 'CostCenter' tag. You need to ensure that any resource created without the required tag is automatically remediated by adding the tag with a default value. What should you configure in Azure Policy?

A.DeployIfNotExists effect
B.AuditIfNotExists effect
C.Append effect
D.Deny effect
AnswerA

DeployIfNotExists effect evaluates resources after they are created and, if they are missing the required tag, triggers a remediation task through Azure Policy. This remediation task uses a managed identity to run a nested deployment that adds the missing tag, effectively modifying the existing resource. It is the only effect among the options that both identifies and automatically fixes non-compliant existing resources, making it the correct choice for enforcing tags across the entire environment.

Why this answer

The DeployIfNotExists effect is correct because it automatically remediates non-compliant resources by deploying a tag with a default value when the required 'CostCenter' tag is missing. This effect triggers a deployment task that adds the tag, ensuring continuous compliance without manual intervention.

Exam trap

The trap here is that candidates often confuse Append (which only works during creation/update) with DeployIfNotExists (which can remediate existing resources), leading them to choose Append for automatic remediation of all resources.

How to eliminate wrong answers

Option B (AuditIfNotExists) is wrong because it only audits and reports non-compliance without performing any automatic remediation. Option C (Append) is wrong because it adds the tag during resource creation or update but does not remediate existing resources that are already missing the tag. Option D (Deny) is wrong because it blocks resource creation if the tag is missing, but the requirement is to automatically add the tag with a default value, not to deny creation.

57
Multi-Selecthard

Which THREE should you consider when designing a monitoring solution for a critical application that requires high availability and low latency? (Choose three.)

Select 3 answers
A.Dashboard visual appeal and color scheme
B.Data volume and associated costs
C.Log retention period and archival strategy
D.Alerting latency and frequency
E.Custom metric creation for all application counters
AnswersB, C, D

Data volume and associated costs are a primary design consideration because Azure Monitor and Log Analytics charge based on data ingestion, storage, and archival. High metric and log volumes directly increase monthly spend and can degrade query performance if the workspace becomes cluttered, so you must plan for sampling, aggregation, and filtering of telemetry. For example, Application Insights supports sampling to reduce data transfer, and you can set daily caps in Log Analytics to avoid unexpected bills. Estimating the volume generated per resource, and selecting the right pricing tier, ensures the monitoring solution remains sustainable and economical.

Why this answer

Monitoring data volume directly impacts cost, especially in Azure Monitor where data ingestion and retention are billed per GB. For a critical application with high availability and low latency, you must balance the granularity of monitoring data against budget constraints to avoid unexpected costs that could compromise operational sustainability.

Exam trap

The trap here is that candidates confuse 'monitoring solution design' with 'dashboard aesthetics' or assume more metrics always improve observability, ignoring the cost and latency trade-offs inherent in Azure Monitor's pay-per-GB model.

58
MCQeasy

You need to provide a team of developers with access to create and manage Azure resources in a specific resource group. The developers should not be able to modify access policies for other users. Which built-in role should you assign?

A.Contributor
B.Owner
C.Reader
D.User Access Administrator
AnswerA

Contributor is the correct choice because it grants full management rights over all resource types within the assigned scope, allowing developers to create, modify, and delete resources as needed. However, it explicitly excludes the ability to assign roles or manage access, which is not required for the team's task. By using Contributor, you adhere to the principle of least privilege, giving developers the capabilities they need without exposing access-control functions.

Why this answer

The Contributor role allows full management of resources but cannot manage access (role assignments). Owner can manage access. Reader is read-only.

User Access Administrator only manages access, not resources.

59
MCQmedium

A company wants to monitor sign-in activity for their Microsoft Entra ID-integrated applications. They need to detect risky sign-ins, such as sign-ins from anonymous IP addresses or unfamiliar locations, and automatically block or require multi-factor authentication. They also need a dashboard showing risk events and the ability to investigate and remediate. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Identity Protection
B.Microsoft Entra ID Privileged Identity Management (PIM)
C.Microsoft Entra ID Access Reviews
D.Microsoft Entra ID Self-Service Password Reset (SSPR)
AnswerA

Identity Protection detects risky sign-ins using Microsoft's threat intelligence, including anonymous IP and unfamiliar location signals, then applies risk-based Conditional Access to block or require MFA. Its dashboard and investigation tooling satisfy the monitoring and remediation requirements.

Why this answer

Microsoft Entra ID Identity Protection is the correct feature because it specifically detects and responds to risky sign-ins, such as those from anonymous IP addresses or unfamiliar locations, by automatically blocking access or requiring multi-factor authentication. It provides a dashboard of risk events (e.g., leaked credentials, impossible travel) and supports investigation and remediation workflows, directly matching the requirements for monitoring sign-in activity and enforcing conditional access policies.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with Identity Protection because both involve 'risk' and 'security,' but PIM is solely for privileged role governance, not for detecting risky sign-ins from anonymous IPs or unfamiliar locations.

How to eliminate wrong answers

Option B (Privileged Identity Management) is wrong because it focuses on managing, controlling, and monitoring access to privileged roles (e.g., global administrator) through just-in-time activation and approval workflows, not on detecting risky sign-ins or enforcing MFA for general users. Option C (Access Reviews) is wrong because it automates periodic attestation of group memberships or application access to ensure only the right users have access, but it does not detect or respond to risky sign-in events in real time. Option D (Self-Service Password Reset) is wrong because it allows users to reset their own passwords without help desk intervention, addressing password management, not risk-based sign-in detection or conditional access enforcement.

60
MCQmedium

You are designing an identity solution for a large enterprise that uses Microsoft Entra ID. The company has a partner organization that needs access to a specific application. The partner uses their own identity provider (IdP). You need to enable seamless access without duplicating user accounts. What should you configure?

A.Federation with the partner's IdP
B.Microsoft Entra External ID
C.Passwordless authentication
D.Identity synchronization
AnswerB

Microsoft Entra External ID is the correct approach because it includes B2B collaboration, which allows external users to sign in using their own identities—whether that be a Microsoft account, a Google account, a Facebook account, or any SAML/WS-Fed identity provider—without creating a separate local account in your tenant. It provides self-service sign-up, conditional access policies, and lifecycle management such as just-in-time access and access reviews, making it ideal for large enterprises that need to collaborate with a broad range of external partners, vendors, and customers. External ID also supports cross-tenant access settings for trusted MFA and device compliance from partner tenants, so the user's own identity provider is the authority for authentication while your tenant controls access policies. This is the only option that directly enables external users to bring their own identities without requiring federation prior to the invitation.

Why this answer

Microsoft Entra External ID (formerly Azure AD B2B) is the correct solution because it allows the partner organization to access the specific application using their own identity provider (IdP) without requiring duplicate user accounts in your tenant. It leverages federation trust, enabling seamless single sign-on (SSO) by authenticating users against their home IdP and issuing a token for your application. This aligns with the requirement for a zero-trust, external identity scenario where user lifecycle is managed externally.

Exam trap

The trap here is that candidates often confuse federation (Option A) with External ID, not realizing that federation is a broader concept that can be implemented via External ID for external users, while the exam expects you to recognize that External ID is the specific service designed for this partner access scenario without account duplication.

How to eliminate wrong answers

Option A is wrong because federation with the partner's IdP typically implies a direct trust relationship between your Entra ID and the partner's IdP for all users, which is more complex and often used for hybrid identity scenarios, not for granting granular application access to external users without account duplication. Option C is wrong because passwordless authentication (e.g., FIDO2, Windows Hello) is an internal authentication method that does not solve the problem of allowing external users from a different IdP to access your application; it focuses on eliminating passwords for your own users. Option D is wrong because identity synchronization (e.g., using Azure AD Connect) would require creating and syncing user objects from the partner's directory into your tenant, which duplicates accounts and violates the requirement to avoid duplication.

61
Multi-Selectmedium

Which TWO Microsoft Entra ID features should you use to protect against credential attacks?

Select 2 answers
A.Password Protection
B.Identity Protection
C.Group-based licensing
D.Self-Service Password Reset (SSPR)
E.Application Proxy
AnswersA, B

Password Protection actively blocks users from selecting common, easily guessable passwords by enforcing both Microsoft's global banned password list and a custom banned list you define. It also performs fuzzy matching to catch variations like common letter substitutions, thereby directly reducing the likelihood of successful password spray or brute-force attacks against your tenant.

Why this answer

Password Protection is correct because it specifically targets credential attacks by blocking weak passwords and common variations (e.g., 'Password123!') using a global banned password list and the option to add custom terms. Identity Protection is correct because it uses real-time risk detection (e.g., leaked credentials, anonymous IP addresses) to automatically block or require MFA for suspicious sign-ins, directly mitigating credential-based attacks like password spray or brute force.

Exam trap

The trap here is that candidates often confuse SSPR (a self-service recovery tool) with a proactive attack prevention feature, but SSPR does not block credential attacks—it only helps users after they are locked out or have forgotten their password.

62
Multi-Selecthard

Which THREE Azure services or features should you use to design a comprehensive monitoring solution for a hybrid infrastructure spanning on-premises and Azure?

Select 3 answers
A.Azure Monitor
B.Network Watcher
C.Log Analytics agent (or Azure Monitor Agent)
D.Azure Arc-enabled servers
E.Azure Traffic Manager
AnswersA, C, D

Azure Monitor is the correct choice because it is the central platform for telemetry collection, analysis, and alerting across Azure and on-premises workloads. It ingests metrics and logs into a unified data plane, supports log queries with KQL, and provides dashboards, alerts, and integration with Log Analytics workspaces and Application Insights. This makes it the foundational service for any hybrid monitoring architecture.

Why this answer

Azure Monitor is the central platform for collecting, analyzing, and acting on telemetry from both Azure and on-premises resources. It provides a unified monitoring experience by aggregating metrics and logs, enabling alerting, dashboards, and integration with other services like Log Analytics. For a hybrid infrastructure, Azure Monitor serves as the core data ingestion and analysis hub, making it essential for a comprehensive monitoring solution.

Exam trap

The trap here is that candidates often confuse Network Watcher (a network diagnostics tool) with a general monitoring solution, or they overlook Azure Arc-enabled servers as a prerequisite for managing and monitoring on-premises machines with Azure Monitor.

63
MCQmedium

Your organization uses Azure Monitor to monitor a fleet of 500 VMs running Windows Server. You need to collect security event logs (Event ID 4625 for failed logons) from all VMs and send them to a Log Analytics workspace. The solution must support centralized configuration and be scalable. You also want to filter out high-volume noise events to reduce costs. What should you do?

A.Enable VM Insights on all VMs and use the Performance view to detect failed logons.
B.Stream events to Azure Event Hubs and use a function to filter and send to Log Analytics.
C.Install the Log Analytics agent on each VM and configure Windows Event log collection in the workspace.
D.Deploy the Azure Monitor agent via Azure Policy and create a data collection rule to collect Event ID 4625.
AnswerD

This is the correct, future-ready approach because Azure Monitor agent (AMA) is designed to collect Windows Security events and supports fine-grained XPath filtering in Data Collection Rules (DCRs) to ingest only Event ID 4625. Using Azure Policy ensures the agent is automatically deployed to every VM with consistent configuration, and the DCR can be applied at scale across subscriptions. This avoids manual installation and reduces data costs by filtering noise before it reaches the workspace, while still providing centralized control over the data collection pipeline.

Why this answer

The Azure Monitor agent (AMA) is the current recommended agent for collecting security events from VMs, and using Azure Policy to deploy it ensures centralized, scalable configuration across 500 VMs. A data collection rule (DCR) can be configured to collect only Event ID 4625, filtering out high-volume noise events at the source, which reduces costs by minimizing data ingestion into the Log Analytics workspace.

Exam trap

The trap here is that candidates may choose the Log Analytics agent (MMA) option because it is familiar from legacy setups, but the exam tests knowledge of the newer Azure Monitor agent (AMA) and its centralized configuration via DCRs, which is the recommended and scalable solution for modern environments.

How to eliminate wrong answers

Option A is wrong because VM Insights is designed for performance monitoring (CPU, memory, disk, network) and does not collect security event logs like Event ID 4625; it cannot detect failed logons. Option B is wrong because streaming events to Azure Event Hubs and using a function to filter and send to Log Analytics adds unnecessary complexity and cost; the Azure Monitor agent with a DCR can filter events directly without intermediate services. Option C is wrong because the Log Analytics agent (MMA) is deprecated in favor of the Azure Monitor agent (AMA), and while it can collect Windows event logs, it does not support centralized configuration via DCRs as efficiently as AMA, and it lacks the native filtering capabilities to reduce noise at the source.

64
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to allow external business partners to access an internal web application using their own organizational identities. The solution must support self-service sign-up and enforce multi-factor authentication for partner users. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra ID B2B collaboration
B.Microsoft Entra ID B2C
C.Microsoft Entra ID Domain Services
D.Microsoft Entra ID Connect
AnswerA

Microsoft Entra ID B2B collaboration is the correct solution because it lets you invite employees from partner organizations as guest users, granting them access to your internal business apps while they authenticate using their own employer-issued Entra ID or other federated credentials. It natively supports conditional access policies such as MFA and allows self-service sign-up for external partners, making it purpose-built for B2B sharing without duplicating identities.

Why this answer

Microsoft Entra ID B2B collaboration is the correct feature because it allows external business partners to access internal applications using their own organizational identities (home directory credentials) without requiring them to have a separate account in your tenant. It supports self-service sign-up through entitlement management and can enforce multi-factor authentication (MFA) via Conditional Access policies that evaluate the partner user's session, even if the partner's home tenant does not enforce MFA.

Exam trap

The trap here is that candidates often confuse B2B collaboration (for business partners with existing organizational identities) with B2C (for customers using social or local accounts), leading them to select B2C when the requirement explicitly states 'business partners' and 'their own organizational identities.'

How to eliminate wrong answers

Option B (Microsoft Entra ID B2C) is wrong because B2C is designed for customer-facing applications where users sign up with social or local identities, not for business partner access with existing organizational identities. Option C (Microsoft Entra ID Domain Services) is wrong because it provides managed domain services (e.g., LDAP, Kerberos) for legacy applications, not external identity federation or self-service sign-up. Option D (Microsoft Entra ID Connect) is wrong because it synchronizes on-premises Active Directory objects to Entra ID for internal users, not for inviting external partners or enforcing MFA on guest users.

65
MCQhard

Your company has a hybrid identity environment with 10,000 on-premises users synchronized to Microsoft Entra ID using Microsoft Entra Connect. You plan to implement a modern access control strategy for all cloud applications. The requirements are: enforce multifactor authentication (MFA) for all users when accessing sensitive applications, allow users to self-remediate risky sign-ins via a mobile app, and minimize infrastructure complexity. You need to design the identity and governance solution. What should you do?

A.Deploy Azure AD Domain Services and configure Kerberos authentication for cloud apps. Use Azure MFA Server on-premises for MFA enforcement.
B.Configure Microsoft Entra ID Protection to detect risky sign-ins and create a conditional access policy that requires MFA for sensitive apps. Enable the risky user policy to require password change, and use Microsoft Authenticator for self-remediation.
C.Implement Microsoft Defender for Identity to monitor on-premises AD and require MFA via on-premises NPS extension.
D.Use Microsoft Entra Permissions Management to enforce MFA policies and manage user permissions.
AnswerB

Microsoft Entra ID Protection continuously evaluates user and sign-in risk signals (e.g., impossible travel, leaked credentials, anonymous IP) and makes them available to Conditional Access policies. A policy can require Microsoft Entra MFA only when a user is classified as risky for sensitive applications, while the user-risk policy can force an authenticated password change to remediate a compromised account. Microsoft Authenticator enables self-remediation by providing number matching and push notifications so a user can approve MFA and then complete a password reset without a helpdesk call.

Why this answer

It uses Microsoft Entra ID Protection to detect risky sign-ins and a Conditional Access policy to require MFA for sensitive applications, meeting the MFA enforcement requirement. The risky user policy requiring a password change combined with Microsoft Authenticator for self-remediation allows users to resolve their own risk without admin intervention, satisfying the self-remediation requirement. This approach minimizes infrastructure complexity by relying entirely on cloud-native services rather than on-premises components.

Exam trap

The trap here is that candidates may confuse Microsoft Defender for Identity or Azure AD Domain Services with identity protection and access control solutions, overlooking that Entra ID Protection and Conditional Access are the correct cloud-native services for risk-based MFA enforcement and self-remediation.

How to eliminate wrong answers

Option A is wrong because deploying Azure AD Domain Services and configuring Kerberos authentication for cloud apps does not enforce MFA or provide self-remediation; Azure MFA Server is deprecated and adds on-premises complexity, contradicting the requirement to minimize infrastructure complexity. Option C is wrong because Microsoft Defender for Identity monitors on-premises AD for security threats but does not enforce MFA or provide self-remediation; the on-premises NPS extension for MFA requires additional infrastructure and does not support user self-remediation via a mobile app. Option D is wrong because Microsoft Entra Permissions Management (formerly CloudKnox) focuses on cloud infrastructure entitlement management and permissions, not on enforcing MFA policies or providing self-remediation for risky sign-ins.

66
MCQeasy

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to automatically detect identity risks, such as users with leaked credentials or sign-ins from anonymous IP addresses, and generate alerts. They also want to automatically trigger a password reset for high-risk users. Which Microsoft Entra ID feature should they configure?

A.Microsoft Entra ID Identity Protection
B.Microsoft Entra ID Privileged Identity Management
C.Microsoft Entra ID Conditional Access
D.Microsoft Entra ID Access Reviews
AnswerA

Identity Protection continuously evaluates sign-in and user risk signals, including leaked credentials and anonymous IP sign-ins, raising risk detections automatically. Its risk-based Conditional Access policies can then force a password reset when a user is flagged high risk, satisfying both requirements.

Why this answer

Microsoft Entra ID Identity Protection is the correct feature because it is specifically designed to automatically detect identity risks such as leaked credentials and sign-ins from anonymous IP addresses. It generates alerts based on risk detections and can be configured to automatically trigger remediation actions like forcing a password reset for high-risk users through risk-based policies.

Exam trap

The trap here is that candidates often confuse Conditional Access with Identity Protection, but Conditional Access is a policy engine that enforces controls based on risk signals, whereas Identity Protection is the service that generates those risk signals and can directly trigger password resets.

How to eliminate wrong answers

Option B (Privileged Identity Management) is wrong because it focuses on just-in-time privileged access management and role activation, not on detecting identity risks like leaked credentials or anonymous IP sign-ins. Option C (Conditional Access) is wrong because it enforces access control policies based on signals (e.g., location, device compliance) but does not natively detect or alert on identity risks or automatically trigger password resets; it can integrate with Identity Protection but is not the primary feature for risk detection. Option D (Access Reviews) is wrong because it provides periodic attestation of group memberships and role assignments, not real-time risk detection or automated password reset triggers.

67
MCQhard

A company uses Microsoft Entra ID (Microsoft Entra ID). They have many guest users with access to internal SharePoint sites and applications. They need to review guest user access every 90 days and automatically remove access if the guest does not respond to the review request. The solution must be fully automated without custom scripting. Which Microsoft Entra ID feature should they use?

A.Microsoft Entra ID Access Reviews
B.Microsoft Entra ID Conditional Access
C.Microsoft Entra ID Identity Protection
D.Microsoft Entra ID Privileged Identity Management
AnswerA

Microsoft Entra ID Access Reviews are the governance feature that handles the recurring recertification of guest accounts, group memberships, and application assignments. An admin can create a review that periodically asks guest users to self-attest or asks their manager to approve continued access, with automatic removal after a specified non-response period. This ensures guest access is regularly validated and cleaned up, meeting the requirement described.

Why this answer

Microsoft Entra ID Access Reviews is the correct feature because it allows administrators to create recurring reviews of guest user access to groups, applications, and SharePoint sites. It can be configured to automatically remove access if the guest does not respond within a specified period (e.g., 90 days), and it supports full automation without custom scripting by leveraging built-in review schedules and auto-apply actions.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with Access Reviews, but PIM is designed for privileged roles and requires activation, whereas Access Reviews handle recurring attestation of any user's access, including guest users, with automatic removal on non-response.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID Conditional Access enforces access policies based on signals like location or device state, but it does not provide recurring access reviews or automatic removal of access for non-responsive guests. Option C is wrong because Microsoft Entra ID Identity Protection detects and remediates identity-based risks (e.g., leaked credentials, sign-ins from anonymous IPs) but does not schedule periodic guest access reviews or remove access based on lack of response. Option D is wrong because Microsoft Entra ID Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not recurring reviews of standard guest user access to SharePoint sites and applications.

68
Multi-Selecthard

Your company is designing a governance strategy for Azure. You need to ensure that all resource groups in a subscription are created with a specific naming convention and mandatory tags. Which THREE services or features should you use together? (Choose three.)

Select 3 answers
A.Azure RBAC
B.Azure Blueprints
C.Management Groups
D.Azure Policy
E.Resource Locks
AnswersB, C, D

Azure Blueprints packages Role Assignments, Policy Assignments, Azure Resource Manager templates, and resource groups into a single, versionable, assignable artifact. When assigned to a subscription, the included policy assignments automatically enforce naming patterns and tag requirements, while bundled ARM templates can deploy resources with consistent tags. Blueprints maintain a tracking record of assignments and allow a governance team to orchestrate compliance across many subscriptions, making it a holistic governance solution. Because it can directly embed Azure Policy definitions, it is a correct answer for enforcing naming and tag governance.

Why this answer

Azure Blueprints is correct because it enables the orchestrated deployment of Azure Policy, RBAC, and resource templates as a single composable artifact. By defining a blueprint that includes a policy for naming conventions and mandatory tags, you can enforce these requirements consistently across all resource groups within a subscription or management group hierarchy.

Exam trap

The trap here is that candidates often confuse Azure RBAC (which controls permissions) with Azure Policy (which enforces rules on resource properties), or they overlook that Blueprints is the orchestration layer that bundles Policy, RBAC, and templates together to enforce governance at scale.

69
MCQeasy

A company uses Microsoft Entra ID. They want to enforce that all users must use multi-factor authentication (MFA) when accessing sensitive applications from outside the corporate network, but allow access without MFA when coming from the corporate office IP range. Which Microsoft Entra ID feature should they use to create this policy?

A.Conditional Access policy
B.Identity Protection
C.Privileged Identity Management (PIM)
D.Microsoft Entra ID roles
AnswerA

Conditional Access is the Entra ID engine for evaluating access signals, including IP geolocation via named locations, and then applying grant controls such as requiring MFA. A policy can be scoped to users and apps, and for the 'location' condition, an untrusted or unfamiliar IP address triggers the MFA grant control, while trusted corporate IPs may skip it. This directly enforces MFA only when needed, matching the requirement.

Why this answer

Conditional Access policies in Microsoft Entra ID allow administrators to define access controls based on conditions such as user location, device state, and application sensitivity. By creating a policy that requires MFA for all users accessing sensitive applications from outside the corporate network, and excluding the trusted corporate office IP range from the MFA requirement, the company can enforce the desired behavior. This is the correct feature because it directly supports location-based access controls and granular policy conditions.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based policies with Conditional Access's location-based MFA enforcement, assuming that risk policies can also enforce MFA based on network location, but Identity Protection only triggers MFA based on risk level, not static IP ranges.

How to eliminate wrong answers

Option B (Identity Protection) is wrong because it focuses on detecting and remediating identity-based risks (e.g., leaked credentials, sign-ins from anonymous IPs) and does not provide the ability to enforce MFA based on network location or IP ranges. Option C (Privileged Identity Management, PIM) is wrong because it is designed for just-in-time privileged role activation and access reviews, not for enforcing MFA on end-user access to applications based on location. Option D (Microsoft Entra ID roles) is wrong because roles define administrative permissions within the directory, not access policies for end-user application access; they cannot enforce MFA based on network location.

70
MCQhard

Refer to the exhibit. You deploy this Azure Network Watcher connection monitor to test TCP connectivity on port 443 between two VMs. The test consistently shows 'Unreachable' status. Both VMs are running and have correct NSG rules allowing inbound port 443 from the source VM's IP. What is the most likely cause?

A.The source VM does not have the Network Watcher Agent installed.
B.The destination VM's NSG is blocking the traffic despite the rule.
C.The destination VM's private IP address is incorrect.
D.A firewall on the destination VM is blocking TCP port 443.
AnswerA

Connection Monitor relies on the Network Watcher Agent (AzureNetworkWatcherExtension) installed in the source VM's guest OS to originate synthetic probe traffic. Without that agent, the monitor cannot even send TCP 443 tests to the destination, so the probe results will show 'unreachable' regardless of how permissive the NSGs or route tables are. The exhibit confirms all NSG rules are correct, so a missing source agent is the definitive root cause.

Why this answer

Azure Network Watcher connection monitor relies on the Network Watcher Agent extension installed on both source and destination VMs to collect and report connectivity data. Without the agent on the source VM, the test cannot initiate the TCP probes, resulting in a persistent 'Unreachable' status regardless of NSG rules or VM health.

Exam trap

The trap here is that candidates often assume NSG rules are the sole cause of connectivity failures, overlooking the prerequisite that the Network Watcher Agent must be installed on both VMs for connection monitor to function.

How to eliminate wrong answers

Option B is wrong because the question states that correct NSG rules allowing inbound port 443 from the source VM's IP are in place, so the NSG is not blocking traffic. Option C is wrong because an incorrect private IP address would cause a different error (e.g., 'Invalid endpoint' or failure to resolve), not a consistent 'Unreachable' status in a connection monitor test that already references the correct VM. Option D is wrong because while a guest OS firewall could block port 443, the question specifies that the test consistently shows 'Unreachable' and both VMs are running with correct NSG rules; the most likely cause given the dependency on the Network Watcher Agent is its absence, not a firewall misconfiguration.

71
MCQmedium

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to provide external business partners with access to an internal application. The access must be time-limited to 60 days, approved by a manager within the partner company, and automatically expire. The company also needs to generate reports of who has access. Which Microsoft Entra ID feature should they implement?

A.Microsoft Entra ID B2B collaboration with entitlement management
B.Microsoft Entra ID B2C custom policies
C.Microsoft Entra ID Identity Governance with Privileged Identity Management (PIM)
D.Microsoft Entra ID Conditional Access with session controls
AnswerA

Microsoft Entra ID B2B collaboration with entitlement management is correct because it specifically addresses granting external partners access to internal applications with time-bound, approval-based access packages. Entitlement management enables admins to create access packages that include multiple assignments, require approvals, set expiration dates, and provide access reviews, while B2B collaboration supplies the necessary identity lifecycle and authentication for external users. This combination delivers governed, auditable, and expiring access for 10 partners, aligning with the requirement for approval and time-bound access.

Why this answer

Microsoft Entra ID B2B collaboration with entitlement management allows you to invite external users from partner companies and manage their access through access packages. These packages can enforce time-limited access (e.g., 60 days), require approval from the partner's manager, and automatically expire. Entitlement management also provides built-in reporting to track who has access, meeting all stated requirements.

Exam trap

The trap here is confusing Identity Governance with Privileged Identity Management (PIM) — PIM is for privileged roles, not for managing external partner access with time-limited, approved, and expiring access packages.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra ID B2C custom policies are designed for consumer-facing identity scenarios (e.g., sign-up/sign-in for customers), not for granting time-limited access to external business partners with manager approval and automatic expiration. Option C is wrong because Privileged Identity Management (PIM) focuses on just-in-time privileged role activation for internal users, not on managing external partner access with time limits, approval workflows, and expiration. Option D is wrong because Conditional Access with session controls enforces policies during authentication (e.g., MFA, device compliance) but cannot manage time-limited access, approval workflows, or automatic expiration for external users.

72
MCQmedium

Your company has a Microsoft Entra ID tenant with 10,000 users. You need to design a monitoring solution to detect when users are assigned to high-privilege roles (e.g., Global Administrator) and ensure that any such assignment triggers an automated investigation. Additionally, you need to monitor sign-in failures for guest users and automatically block accounts after 5 failed attempts within 10 minutes. You have the following requirements: 1) Use a cloud-native solution that minimizes administrative overhead. 2) Integrate with Microsoft Sentinel for incident response. 3) Use built-in features where possible. What should you do?

A.Use Microsoft Entra audit logs streamed to Log Analytics, create Azure Logic Apps to detect role assignments and sign-in failures, and trigger Sentinel incidents.
B.Use Azure Policy to audit role assignments and create custom KQL functions in Log Analytics to detect sign-in failures, then forward to Sentinel.
C.Use Microsoft Entra Privileged Identity Management (PIM) alerts for role assignments and Microsoft Entra Identity Protection for sign-in risk policies; integrate both with Microsoft Sentinel.
D.Deploy Microsoft Identity Manager (MIM) on-premises to monitor role changes, and use Azure AD Connect Health for sign-in failures.
AnswerC

This is the correct approach because it uses purpose-built Microsoft Entra security controls rather than custom or legacy tooling. PIM generates alerts on permanent role assignments and privileged role activations, enabling review of who has elevated access, while Identity Protection evaluates sign-in risk signals (e.g., password spray, impossible travel, anonymous IP) and can enforce policies to block sign-ins after repeated failures or require MFA. Both natively integrate with Microsoft Sentinel through out-of-the-box data connectors, giving security analysts a unified SIEM view without building custom orchestration logic.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) provides built-in alerts for high-privilege role assignments, and Microsoft Entra Identity Protection offers risk-based policies for sign-in failures, including user risk policies that can automatically block accounts after a specified number of failures. Both services natively integrate with Microsoft Sentinel via built-in data connectors, enabling automated incident creation with minimal administrative overhead, meeting all requirements.

Exam trap

The trap here is that candidates often over-engineer a solution with custom Logic Apps or KQL queries, overlooking the fact that PIM and Identity Protection already provide built-in alerting and automated blocking capabilities that natively integrate with Sentinel, satisfying the 'cloud-native' and 'minimize administrative overhead' requirements.

How to eliminate wrong answers

Option A is wrong because while audit logs can be streamed to Log Analytics, using Azure Logic Apps to detect role assignments and sign-in failures introduces unnecessary custom development and administrative overhead, contradicting the requirement to use built-in features and minimize overhead. Option B is wrong because Azure Policy is designed for auditing and enforcing compliance of Azure resources, not for monitoring Entra ID role assignments or sign-in failures; custom KQL functions in Log Analytics would require manual setup and lack the automated blocking capability for guest accounts. Option D is wrong because Microsoft Identity Manager (MIM) is an on-premises identity management solution that adds complexity and does not provide cloud-native monitoring; Azure AD Connect Health focuses on synchronization health, not sign-in failure monitoring or automated blocking.

73
MCQeasy

A company plans to migrate on-premises applications to Azure. They require users to authenticate using their existing on-premises Active Directory credentials without syncing password hashes to the cloud. Which Microsoft Entra ID authentication method should they use?

A.Microsoft Entra ID Pass-through Authentication
B.Microsoft Entra ID Password Hash Sync
C.Microsoft Entra ID Federation Services (AD FS)
D.Microsoft Entra ID Connect with Seamless SSO
AnswerA

Pass-through Authentication (PTA) uses a lightweight agent on a domain-joined server to validate user passwords directly against on-premises Active Directory. Because authentication occurs on-premises, no password hashes are ever transferred to or stored in Microsoft Entra ID, which precisely satisfies the stated requirement to avoid hash sync. PTA is also simpler to deploy than AD FS while still supporting interactive sign-in.

Why this answer

Pass-through Authentication (PTA) validates user passwords directly against on-premises Active Directory without storing password hashes in the cloud. A lightweight agent on-premises forwards authentication requests to the local domain controller, meeting the requirement to avoid password hash synchronization.

Exam trap

The trap here is that candidates often confuse Seamless SSO (which is a convenience feature, not an authentication method) with a primary authentication method, or they assume AD FS is required when the real constraint is avoiding password hash sync.

How to eliminate wrong answers

Option B (Password Hash Sync) is wrong because it synchronizes password hashes to Microsoft Entra ID, which violates the requirement to not sync password hashes. Option C (AD FS) is wrong because it requires deploying and managing federation infrastructure (on-premises or in Azure) and does not inherently avoid password hash sync; it also introduces additional complexity and a separate trust relationship. Option D (Seamless SSO) is wrong because it is not a standalone authentication method—it is a feature that works with Password Hash Sync or Pass-through Authentication to provide silent sign-on, and by itself it does not handle password validation without one of those methods.

74
MCQmedium

A company is building a customer-facing web application. They want to allow users to sign in using their existing social accounts (Microsoft, Google, Facebook) or create a local account. The solution must be fully managed and support custom branding. Which Azure service should they use?

A.Microsoft Entra ID B2C (Business to Consumer)
B.Microsoft Entra ID External Identities
C.Microsoft Entra ID B2B collaboration
D.Microsoft Entra ID Application Proxy
AnswerA

Correct. Microsoft Entra ID B2C is the dedicated customer identity and access management (CIAM) service, purpose-built for consumer-facing applications. It supports local accounts (email or user ID with password) and social identity providers such as Google, Facebook, Apple, and Microsoft, and it offers customizable user flows for sign-up, sign-in, and password reset. For a customer-facing web app requiring self-service registration and consumer authentication, Microsoft Entra ID B2C is the exact service to deploy.

Why this answer

Microsoft Entra ID B2C (Business to Consumer) is the correct choice because it is a fully managed identity service designed specifically for customer-facing applications. It supports social identity providers (Microsoft, Google, Facebook) via OAuth 2.0 and OpenID Connect, allows local account creation, and provides extensive custom branding capabilities through customizable user flows and page layouts.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID External Identities (which includes B2B collaboration) with B2C, but External Identities is for business partner access to internal apps, not for building a consumer-facing identity system with social logins and local accounts.

How to eliminate wrong answers

Option B (Microsoft Entra ID External Identities) is wrong because it is primarily designed for B2B scenarios, allowing external business partners to sign in with their own corporate identities, not for consumer social logins or local account creation. Option C (Microsoft Entra ID B2B collaboration) is wrong because it focuses on inviting external business users from other organizations to access internal resources, not on building a customer-facing sign-in experience with social providers. Option D (Microsoft Entra ID Application Proxy) is wrong because it is a reverse proxy service for publishing on-premises web applications to external users, not an identity provider for authentication or sign-in.

75
Multi-Selecthard

Your organization uses Azure Monitor Logs to analyze application performance. You need to create a custom log query that calculates the 95th percentile of response times for a web app over the last 24 hours. Which THREE KQL functions should you use? (Choose three.)

Select 3 answers
A.percentile
B.summarize
C.project
D.sort
E.where
AnswersA, B, E

The percentile function computes the 95th percentile of a numeric column, such as response time, over the queried set. Combined with a time filter and a summarise operator, it satisfies the requirement to calculate p95 response times across the last 24 hours.

Why this answer

Option A, percentile, is correct because it is the KQL aggregation function that computes the 95th percentile value of a numeric column such as response time. Option B, summarize, is correct because percentile must be invoked inside a summarize operator to group and aggregate the data over the desired window. Option E, where, is correct because it filters the dataset to the last 24 hours (for example, where TimeGenerated > ago(24h)) before aggregation.

Option C, project, is not required since it only selects or renames columns and does not perform percentile calculation. Option D, sort, is not required because ordering rows does not contribute to computing a percentile aggregate.

Exam trap

The trap here is that candidates often confuse `project` or `sort` with filtering or aggregation functions, mistakenly thinking they can help narrow the data or compute percentiles, when in fact only `where`, `summarize`, and `percentile` perform the required operations.

Page 1 of 3 · 222 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Identity Governance Monitoring questions.