Courseiva

Microsoft Azure Security Engineer Associate AZ-500 (AZ-500) — Questions 1–75

617 questions total · 9pages · All types, answers revealed

Page 1 of 9

Page 2
1
Multi-Selecteasy

You need to secure an Azure Storage account that will host sensitive data. Which TWO configurations should you implement?

Select 2 answers
A.Generate a shared access signature (SAS)
B.Enable 'Secure transfer required'
C.Allow public network access from all networks
D.Enable Azure Files
E.Configure a private endpoint
AnswersB, E

Enabling 'Secure transfer required' enforces HTTPS by rejecting all requests made over HTTP, ensuring that every interaction with the storage account is encrypted with TLS. This is a fundamental security baseline that protects data in transit from interception and man-in-the-middle attacks. It is a mandatory control for sensitive data and works in conjunction with private endpoints to guarantee end-to-end encryption.

Why this answer

Option B is correct because enabling 'Secure transfer required' on the storage account enforces HTTPS/TLS for all requests to the storage endpoints, rejecting any HTTP traffic so sensitive data is never transmitted in cleartext. Option E is correct because configuring a private endpoint assigns the storage account a private IP address inside your virtual network via Azure Private Link, removing exposure to the public internet and letting access flow only over the Microsoft backbone network. Option A is not correct here because a SAS is a delegated, time-limited access token for granting scoped permissions to clients, not a baseline network or transport security configuration for the account.

Option C is not correct because allowing public network access from all networks does the opposite of securing the account, exposing it to the internet. Option D is not correct because enabling Azure Files simply turns on the SMB/NFS file share service and does not itself harden or restrict access to the storage account.

2
MCQhard

A company uses Azure SQL Database with Transparent Data Encryption (TDE) and a customer-managed key stored in Azure Key Vault. The Key Vault is configured with a firewall that denies all public access. The SQL server must be able to access the key. What additional configuration is necessary?

A.Enable trusted Microsoft services on the Key Vault firewall
B.Create a private endpoint for Key Vault
C.Assign the SQL server's managed identity to the Key Vault
D.Configure a service endpoint on the SQL server
AnswerA

Enabling “Allow trusted Microsoft services to bypass this firewall” on the Key Vault is the correct fix because Azure SQL Database’s TDE key fetches originate from Microsoft’s PaaS infrastructure and, with this setting, those requests are exempted from the Key Vault firewall even when all public network access is otherwise blocked. This setting must be combined with the SQL server’s managed identity being granted the required key permissions, but without it, firewall rules alone would continue to reject the TDE key-wrap and unwrap calls.

Why this answer

When Azure Key Vault's firewall denies all public access, enabling 'Allow trusted Microsoft services' is necessary because Azure SQL Database's TDE key retrieval is considered a trusted service operation. This setting bypasses the firewall for specific Azure services like SQL Database that are authenticated and authorized to access the vault, without requiring a private endpoint or service endpoint.

Exam trap

The trap here is that candidates often confuse the authentication/authorization step (assigning managed identity) with the network connectivity step (firewall bypass), assuming that granting permissions alone is sufficient when the Key Vault firewall is blocking all traffic.

How to eliminate wrong answers

Option B is wrong because creating a private endpoint for Key Vault would provide private connectivity from a virtual network, but the SQL server is a platform-as-a-service resource that does not reside in a VNet by default; while possible, it is not the simplest or required configuration for TDE key access when the firewall is enabled. Option C is wrong because assigning the SQL server's managed identity to Key Vault is necessary for authentication and authorization (to grant the SQL server permissions to the key), but it does not bypass the Key Vault firewall; the firewall must still allow the request. Option D is wrong because configuring a service endpoint on the SQL server is not applicable; service endpoints are used for VNet integration, and Azure SQL Database does not have a service endpoint that directly controls Key Vault access.

3
MCQeasy

You need to restrict access to an Azure Storage account so that only traffic from a specific virtual network is allowed. What should you configure?

A.Azure Firewall application rule
B.Storage account firewall and virtual network settings
C.Private endpoint connection
D.Network security group (NSG) on the subnet
AnswerB

The Storage account firewall and virtual network settings are the correct service-level control because they allow you to switch the storage account from 'All networks' to 'Selected networks,' then add a virtual network rule that permits traffic only from a specific virtual network (or subnet). This default-deny configuration explicitly blocks all other public IP ranges and network traffic that does not match an allow rule, thereby achieving the required restriction.

Why this answer

Azure Storage accounts have a built-in firewall that can be configured to restrict access based on source IP addresses or virtual network (VNet) rules. By enabling the storage account firewall and adding a rule that allows traffic only from a specific VNet/subnet, you effectively block all other traffic, including internet traffic, while permitting requests from the designated VNet. This is the native Azure method for network-level access control to storage accounts.

Exam trap

The trap here is that candidates often confuse the storage account firewall with network security groups (NSGs) or private endpoints, thinking that an NSG on a subnet can control access to a PaaS service like Storage, or that a private endpoint alone restricts access without also disabling public network access.

How to eliminate wrong answers

Option A is wrong because Azure Firewall application rules are used to allow or deny outbound HTTP/HTTPS traffic from a VNet to specific FQDNs, not to restrict inbound access to an Azure Storage account. Option C is wrong because a private endpoint connection assigns a private IP address to the storage account within a VNet, but it does not by itself restrict access; it must be combined with disabling public network access or configuring the storage account firewall to deny all public traffic. Option D is wrong because a Network Security Group (NSG) on a subnet can filter traffic to and from resources within that subnet, but it cannot directly restrict access to an Azure Storage account, which is a PaaS service with its own firewall; NSGs do not apply to the storage account's public endpoint.

4
MCQhard

Your organization is using Microsoft Defender for Cloud to protect Azure SQL databases. You need to enable Advanced Threat Protection (ATP) for all existing and future Azure SQL databases in a subscription. The solution must minimize administrative effort. What should you do?

A.Configure Microsoft Sentinel to monitor Azure SQL databases.
B.Enable the Azure SQL databases plan in Microsoft Defender for Cloud at the subscription level.
C.Create an Azure Policy to deploy Advanced Threat Protection on Azure SQL databases.
D.Enable Advanced Threat Protection on each Azure SQL database individually.
AnswerB

Enabling the Azure SQL databases plan at subscription level activates Defender for Cloud's threat detection across every existing and future Azure SQL database automatically, with no per-database configuration. This directly satisfies the stem's requirement to minimise administrative effort, since new databases inherit protection without any further action.

Why this answer

Enabling the Azure SQL databases plan in Microsoft Defender for Cloud at the subscription level automatically enables Advanced Threat Protection (ATP) for all existing and future Azure SQL databases within that subscription. This approach requires minimal administrative effort because it applies the protection globally without needing to configure each database individually or create custom policies. Microsoft Defender for Cloud manages the ATP settings centrally, ensuring consistent security coverage across the entire subscription.

Exam trap

The trap here is that candidates often confuse enabling a Defender for Cloud plan (which is a simple toggle at the subscription level) with creating an Azure Policy (which is a more complex, policy-as-code approach), leading them to choose Option C even though it requires more administrative effort than the direct plan enablement.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a Security Information and Event Management (SIEM) tool used for threat detection and response across multiple sources, not a mechanism to enable ATP on Azure SQL databases; it can ingest alerts from Defender for Cloud but does not enable the ATP feature itself. Option C is wrong because while an Azure Policy can enforce the deployment of ATP on Azure SQL databases, it requires creating and assigning a custom policy definition, which introduces additional administrative overhead compared to simply enabling the plan at the subscription level; the question specifically asks to minimize administrative effort. Option D is wrong because enabling ATP on each Azure SQL database individually is the most labor-intensive approach and contradicts the requirement to minimize administrative effort, as it does not automatically cover future databases.

5
MCQhard

Your organization has a complex Azure environment with multiple subscriptions, each containing hundreds of VMs and PaaS services. You are responsible for ensuring that all resources are monitored for security threats using Microsoft Defender for Cloud. The environment includes: - Subscription A: Production workloads, requires the highest security posture. - Subscription B: Development environment, has a lower security budget. - Subscription C: Shared services (e.g., DNS, Active Directory). You need to implement the most cost-effective security monitoring solution that meets the following requirements: - All subscriptions must be covered by Defender for Cloud. - Production subscription must have vulnerability assessment for VMs. - Development subscription does not need vulnerability assessment but must have basic CSPM. - Shared services subscription must have advanced threat protection for Azure SQL databases. - You must minimize administrative overhead and ensure that security policies are centrally managed. What should you do?

A.Enable all Defender plans on the management group to cover all subscriptions, then disable vulnerability assessment on Subscription B via policy.
B.Enable the 'Defender Cloud Security Posture Management' (CSPM) plan on the management group that contains all subscriptions. Then, on Subscription A, enable the 'Defender for Servers' plan with vulnerability assessment. On Subscription C, enable the 'Defender for Azure SQL' plan. Leave Subscription B with only the CSPM plan.
C.Enable the 'Defender for Servers' plan on Subscription A, 'Defender for Azure SQL' on Subscription C, and disable Defender for Cloud on Subscription B.
D.Enable only the free tier of Defender for Cloud on all subscriptions, then manually configure vulnerability assessment for VMs in Subscription A and advanced threat protection for SQL in Subscription C.
AnswerB

This option correctly treats Microsoft Defender for Cloud's plans as modular components: the CSPM plan at the management group gives every subscription a baseline of continuous security posture assessment, attack-path analysis, and regulatory compliance scoring. Then, workload-specific plans are scoped precisely—Defender for Servers on Subscription A delivers built-in vulnerability assessment (via Microsoft Defender for Endpoint or Qualys) and host-level endpoint detection, while Defender for Azure SQL on Subscription C provides SQL injection protection and anomalous access detection. Leaving Subscription B on CSPM alone is cost-effective and appropriate for a non-production environment that requires monitoring but not those advanced workload-specific defenses.

Why this answer

Option B is correct because enabling the Defender Cloud Security Posture Management (CSPM) plan at the management group scope centrally covers all subscriptions with basic CSPM at no/low cost, while selectively enabling Defender for Servers with vulnerability assessment only on Subscription A and Defender for Azure SQL only on Subscription C matches each subscription's specific requirement and minimizes cost and administrative overhead. This scoped approach avoids paying for unnecessary plans on Subscription B, which only needs basic CSPM. Option A is wrong because enabling all Defender plans on the management group would incur costs for plans not required (e.g., vulnerability assessment on Subscription B) and then require extra policy work to disable them.

Option C is wrong because disabling Defender for Cloud on Subscription B violates the requirement that all subscriptions be covered and that B have basic CSPM. Option D is wrong because the free tier does not provide the required vulnerability assessment for VMs or advanced threat protection for Azure SQL, and manual configuration increases administrative overhead.

6
MCQmedium

A company uses Microsoft Defender for Cloud. The security team wants to receive a weekly email digest that includes the current Secure Score, the number of healthy and unhealthy resources, and a list of top recommendations. Which Defender for Cloud feature should they configure?

A.Regulatory Compliance dashboard
B.Security policies
C.Email notifications for alerts and weekly digests
D.Continuous Export
AnswerC

Email notifications for alerts and weekly digests is the correct feature. Under Environment settings > Email notifications, you can enable both real-time alerts for high severity findings and a separate weekly digest. The digest email includes your current Secure Score, a summary of resource health, and the top recommendations, and it can be sent to specified individual email addresses or Microsoft Entra ID role members such as subscription owners. This is the only option that natively delivers a scheduled, human-readable email summary, making it the proper choice for the team's request.

Why this answer

Microsoft Defender for Cloud provides a built-in 'Email notifications for alerts and weekly digests' feature that allows security teams to configure a weekly email containing the current Secure Score, the number of healthy and unhealthy resources, and a list of top recommendations. This feature is specifically designed to deliver a summary of the security posture directly to recipients without requiring manual export or custom automation.

Exam trap

The trap here is that candidates often confuse the weekly digest feature with Continuous Export, assuming that exporting data to a third-party system is the only way to get a summary, but Defender for Cloud has a native email notification feature specifically for this purpose.

How to eliminate wrong answers

Option A is wrong because the Regulatory Compliance dashboard displays compliance posture against standards (e.g., SOC 2, ISO 27001) and does not generate weekly email digests with Secure Score or resource health counts. Option B is wrong because Security policies define the rules and initiatives that govern resource compliance (e.g., enabling MFA or encryption), but they do not include any notification or email delivery mechanism for weekly summaries. Option D is wrong because Continuous Export streams security data (e.g., alerts, recommendations) to Log Analytics or Event Hubs for external processing, but it does not natively generate or send weekly email digests with Secure Score and resource health summaries.

7
MCQmedium

A security analyst is using Microsoft Sentinel to investigate a security incident. The analyst needs to view all related events, alerts, and entities (users, IPs, hosts) in a single, interactive graph to understand the full scope of the attack. Which Microsoft Sentinel feature should they use?

A.Incident timeline
B.Investigation graph
C.Hunting
D.Analytics rules
AnswerB

The investigation graph in Microsoft Sentinel is purpose-built for interactive incident analysis: it displays the incident's extracted entities—such as accounts, IP addresses, hosts, and URLs—as nodes and connects them to the alerts that reference those entities, creating an attack-path visualization. From any node, an analyst can expand to see related alerts, user activities, and other entities, helping to identify the root cause and the scope of the threat. This is the correct tool because it directly supports the analyst's need to examine entity relationships, unlike a sequential timeline or a proactive query engine.

Why this answer

The Investigation graph in Microsoft Sentinel provides an interactive, visual map that correlates all related events, alerts, and entities (such as users, IPs, and hosts) for a given incident. This allows the analyst to explore the full scope of an attack by dragging and dropping entities to uncover hidden relationships, making it the correct feature for this scenario.

Exam trap

The trap here is that candidates often confuse the Incident timeline (which shows a linear history) with the Investigation graph (which shows relational connections), leading them to choose the timeline option when the question explicitly asks for an interactive graph to understand the full scope of an attack.

How to eliminate wrong answers

Option A is wrong because the Incident timeline shows a chronological list of activities and changes for an incident, but it does not provide an interactive graph with entities and relationships. Option C is wrong because Hunting is a proactive search for threats using queries and bookmarks, not a tool for viewing all related events and entities in a single graph for an existing incident. Option D is wrong because Analytics rules are used to create detection logic that generates alerts and incidents, not to visualize or investigate the relationships between events and entities in an existing incident.

8
Multi-Selectmedium

Which TWO actions can be performed using Microsoft Defender for Cloud's 'Regulatory Compliance' dashboard?

Select 2 answers
A.Upload evidence documents for manual controls.
B.Automatically remediate non-compliant resources.
C.View compliance score against a specific regulatory standard.
D.Configure continuous export of compliance data.
E.Integrate with third-party GRC tools directly from the dashboard.
AnswersA, C

The Regulatory Compliance dashboard supports manual attestation: for controls Defender for Cloud cannot assess automatically, you upload evidence files and mark them as compliant, which feeds the assessment. This satisfies the scenario's requirement to document manual control evidence within the dashboard.

Why this answer

Option A is correct because the Regulatory Compliance dashboard in Microsoft Defender for Cloud lets you attach evidence files to manual controls that cannot be assessed automatically, so auditors can verify attestation-based requirements. Option C is correct because the dashboard displays a compliance score for each selected regulatory standard (for example, PCI DSS, ISO 27001, or NIST SP 800-53), showing the percentage of passed controls and the breakdown by control domain. Options B, D, and E are not actions available from this dashboard: automatic remediation is driven by workflow automation or remediation logic in recommendations, continuous export is configured separately under Environment settings, and third-party GRC integration is not performed directly from the Regulatory Compliance dashboard.

Exam trap

AZ-500 often tests the distinction between viewing/attesting compliance versus remediating or exporting it, so candidates mistakenly select remediation or export options that belong to other Defender for Cloud blades.

9
MCQeasy

A company uses Azure Active Directory and has guest users invited via B2B collaboration. The security team wants to require that all guest users from specific external organizations must complete multi-factor authentication (MFA) when accessing the company's SaaS applications. Which Conditional Access policy configuration should they use?

A.Create a policy that applies to 'All users' with a condition for 'Guest or external users' and a grant control of 'Require multi-factor authentication'.
B.Create a policy that applies to 'Guest or external users' with a condition for 'External tenants' specifying the organizations, and a grant control of 'Require multi-factor authentication'.
C.Create a policy that applies to 'All guest users' and assign it to the SaaS applications. Use a session control 'Use app enforced restrictions'.
D.Create a policy that applies to 'Guest or external users' with a condition for 'Sign-in risk' set to 'Medium and above' and a grant control of 'Block access'.
AnswerB

This is the correct approach in Azure AD Conditional Access. By setting the assignment to 'Guest or external users' and adding a condition for 'External tenants' with specific organization IDs, you narrowly and explicitly target only guest users from those partner tenants. The grant control 'Require multi-factor authentication' then enforces MFA at sign-in, which is exactly the stated requirement. This policy avoids affecting internal users and does not rely on risk signals or session-based restrictions, so it fulfills the policy objective with the least disruption.

Why this answer

It uses the 'External tenants' condition within a Conditional Access policy targeting 'Guest or external users' to specify the exact organizations from which guests must complete MFA. This directly meets the requirement to scope MFA enforcement to specific external organizations, not all guests. The 'Require multi-factor authentication' grant control ensures MFA is enforced for those guests when accessing SaaS applications.

Exam trap

The trap here is that candidates confuse the broad 'Guest or external users' identity with the granular 'External tenants' condition, mistakenly thinking that selecting 'Guest or external users' alone is sufficient to scope MFA to specific organizations.

How to eliminate wrong answers

Option A is wrong because applying the policy to 'All users' would include internal users, not just guests from specific external organizations, and the 'Guest or external users' condition alone does not filter by specific organizations. Option C is wrong because 'All guest users' applies to all guests regardless of their home organization, and 'Use app enforced restrictions' is a session control that relies on the application itself to enforce restrictions, not a grant control for MFA. Option D is wrong because 'Sign-in risk' condition targets risky sign-ins based on Microsoft's risk detection, not specific external organizations, and 'Block access' prevents access entirely rather than requiring MFA.

10
MCQeasy

A company has several critical applications deployed in an Azure virtual network. The security team wants to protect the virtual network against Distributed Denial-of-Service (DDoS) attacks by enabling automatic attack mitigation, adaptive tuning, and access to DDoS Rapid Response Support. Which DDoS Protection tier should they enable for the virtual network?

A.DDoS Protection Basic (Free)
B.DDoS Protection Standard
C.DDoS Protection Premium
D.DDoS Protection Advanced
AnswerB

Standard is a paid tier that you enable on a virtual network, providing always-on monitoring, adaptive tuning to your application's traffic patterns, and mitigation of volumetric, protocol, and resource-layer attacks. It delivers real-time telemetry, rich diagnostic logs, and integration with Azure Monitor and Microsoft Defender for Cloud, plus access to DDoS Rapid Response Support for an additional cost. With SLA-backed protection and financial coverage during documented attacks, Standard is the correct tier for critical applications.

Why this answer

DDoS Protection Standard is the correct tier because it provides automatic attack mitigation, adaptive tuning based on traffic patterns, and access to DDoS Rapid Response Support (DRRS) for Azure virtual networks. The Basic tier only offers always-on traffic monitoring and basic mitigation without adaptive tuning or DRRS, while Premium and Advanced are not valid Azure DDoS Protection tiers.

Exam trap

The trap here is that candidates may confuse the non-existent 'Premium' or 'Advanced' tiers with the actual Standard tier, or assume the free Basic tier includes advanced features like adaptive tuning and DRRS, which are exclusive to the paid Standard tier.

How to eliminate wrong answers

Option A is wrong because DDoS Protection Basic is free but only provides always-on traffic monitoring and basic mitigation based on Azure's global network capacity; it does not include adaptive tuning or DDoS Rapid Response Support. Option C is wrong because DDoS Protection Premium is not a valid Azure DDoS Protection tier; Azure offers only Basic and Standard tiers. Option D is wrong because DDoS Protection Advanced is not a valid Azure DDoS Protection tier; the correct name for the paid tier is DDoS Protection Standard.

11
MCQeasy

You need to securely connect two Azure virtual networks in the same region to allow VM-to-VM communication using private IP addresses. The solution must minimize latency and administrative overhead. What should you use?

A.VNet peering
B.Azure VPN Gateway
C.Azure Front Door
D.ExpressRoute
AnswerA

VNet peering is the correct choice because it directly connects two virtual networks using Microsoft's private backbone, providing low-latency, high-bandwidth communication without traversing the public internet. It requires no gateway, VPN device, or extra transit, and involves simple, native configuration within Azure. Traffic remains entirely in the Microsoft network, making it both secure and cost-efficient for VNet-to-VNet connectivity.

Why this answer

VNet peering is the correct choice because it connects two Azure virtual networks in the same region using the Microsoft backbone infrastructure, enabling VM-to-VM communication over private IP addresses with near-zero latency and no intermediate hops. It requires no additional gateways or bandwidth charges within the same region, minimizing administrative overhead as it is a simple, one-time configuration.

Exam trap

The trap here is that candidates often confuse VNet peering with VPN Gateway, assuming a VPN is required for secure connectivity, but VNet peering inherently uses Microsoft's private network and provides the same security with lower latency and no gateway overhead.

How to eliminate wrong answers

Option B (Azure VPN Gateway) is wrong because it introduces a VPN tunnel over the public internet or ExpressRoute, adding latency and requiring gateway configuration and maintenance, which increases administrative overhead. Option C (Azure Front Door) is wrong because it is a global load balancer and application delivery service for HTTP/HTTPS traffic, not designed for private IP connectivity between VNets. Option D (ExpressRoute) is wrong because it is a dedicated private connection from on-premises to Azure, not for connecting two Azure VNets, and it incurs significant cost and provisioning complexity.

12
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) to manage the 'Security Administrator' role. They want to require that activation of this role must be approved by a designated group of security engineers before it becomes active. Which PIM role setting should they configure?

A.Activation maximum duration (hours)
B.MFA on activation
C.Require approval
D.Require justification on activation
AnswerC

Enabling 'Require approval' in PIM role settings means that when an eligible user requests activation, the request enters a pending state and a designated set of approvers (e.g., security team members) must explicitly approve or reject it before the role is activated. This provides an extra layer of human oversight, ensuring that no one can elevate their privileges without another party's review. This is the only setting among the four that directly implements an approval workflow.

Why this answer

Azure AD PIM's 'Require approval' setting enforces that a designated group of approvers must authorize each activation request before the role becomes active. This directly meets the requirement for approval by security engineers, ensuring that role activation is gated by explicit consent rather than being automatic.

Exam trap

The trap here is that candidates often confuse 'Require justification' or 'MFA on activation' with approval workflows, but neither introduces a separate approval step by a designated group—they only add authentication or logging requirements.

How to eliminate wrong answers

Option A is wrong because 'Activation maximum duration (hours)' controls how long a role can remain active after approval, not the approval process itself. Option B is wrong because 'MFA on activation' enforces multi-factor authentication during activation but does not introduce a separate approval step by a designated group. Option D is wrong because 'Require justification on activation' mandates a reason for activation but does not require approval from another party.

13
MCQeasy

You manage a multi-tier application in Azure with a web tier, application tier, and database tier. The web tier must be accessible from the internet, but the application and database tiers must only be accessible from the web tier. Which Azure networking feature should you use to isolate the tiers?

A.Virtual network peering between tiers.
B.Azure Firewall with application rules.
C.Network security groups (NSGs) on each subnet.
D.Application security groups (ASGs) within the same subnet.
AnswerC

NSGs apply stateful allow/deny rules at the subnet and NIC level, so you can permit internet traffic to the web subnet while restricting the application and database subnets to accept traffic only from the web tier's address range, satisfying the tier isolation requirement.

Why this answer

Network security groups (NSGs) allow you to define inbound and outbound security rules that filter traffic at the subnet or NIC level. By placing each tier in its own subnet and applying an NSG to the web tier subnet that allows inbound traffic from the internet, and NSGs to the application and database tier subnets that only allow inbound traffic from the web tier subnet (using the source IP address range or the virtual network tag), you can effectively isolate the tiers while permitting necessary east-west traffic.

Exam trap

The trap here is that candidates often confuse network segmentation (NSGs on subnets) with application-level grouping (ASGs) or perimeter security (Azure Firewall), and incorrectly assume that ASGs alone can provide isolation between tiers within the same subnet.

How to eliminate wrong answers

Option A is wrong because virtual network peering connects entire virtual networks, not subnets within the same VNet, and does not provide traffic filtering or isolation between tiers; it would actually allow all traffic between the peered VNets unless combined with NSGs. Option B is wrong because Azure Firewall is a managed, stateful firewall service typically deployed at the network perimeter for centralized inspection and logging, not for isolating subnets within a single VNet; using it for tier isolation would be overkill and introduce unnecessary latency and cost. Option D is wrong because application security groups (ASGs) allow you to group VMs and define NSG rules based on those groups, but they do not isolate traffic between tiers when all VMs are in the same subnet; ASGs are a logical grouping mechanism, not a network segmentation boundary.

14
Multi-Selectmedium

You are designing security for an Azure SQL Database that will store personally identifiable information (PII). The database will be accessed by multiple applications, some of which are legacy and cannot use Azure AD authentication. Your requirements include: encrypting data at rest, encrypting data in transit, and dynamically masking PII columns for non-privileged users. Which THREE features should you implement?

Select 3 answers
A.Configure Dynamic Data Masking (DDM) for the PII columns.
B.Implement Always Encrypted for the PII columns.
C.Set the 'Minimum TLS Version' to 1.2 on the Azure SQL Server.
D.Enable Transparent Data Encryption (TDE) for the Azure SQL Database.
E.Apply Azure Information Protection labels to the database.
AnswersA, C, D

Dynamic Data Masking (DDM) hides sensitive PII from non-privileged users by applying masking rules (e.g., email or credit-card patterns) at query runtime without altering the underlying data. It is a server/database-level security feature that can be enabled on specific columns, and privileged users can still see the full values. DDM does not protect data in transit or at rest—it only addresses unauthorized viewing by presenting masked values to certain principals.

Why this answer

(Dynamic Data Masking) masks PII columns for non-privileged users. Option C (Minimum TLS Version 1.2) ensures data in transit is encrypted. Option D (Transparent Data Encryption) encrypts data at rest.

Option B (Always Encrypted) is client-side and requires client support, not suitable for legacy apps. Option E (Azure Information Protection) is not a database security feature for this scenario.

15
MCQeasy

You need to securely connect an on-premises network to an Azure virtual network. The connection must use the internet and provide authenticated and encrypted communication. Which Azure service should you use?

A.Azure VPN Gateway
B.Azure ExpressRoute
C.Azure Application Gateway
D.Azure Virtual WAN
AnswerA

Azure VPN Gateway is the correct service because it establishes a site-to-site IPsec/IKE VPN tunnel over the standard internet, providing encrypted connectivity between your on-premises VPN device and the Azure virtual network. It supports both policy-based and route-based gateways, and can be deployed in active-active mode for high availability, making it ideal for a secure, single-site connection without dedicated circuits.

Why this answer

Azure VPN Gateway is the correct choice because it creates an encrypted site-to-site VPN connection over the internet using IPsec/IKE protocols. This meets the requirement for authenticated and encrypted communication between an on-premises network and an Azure virtual network without needing a dedicated private link.

Exam trap

The trap here is that candidates often confuse Azure VPN Gateway with Azure ExpressRoute, thinking both provide encrypted connections, but ExpressRoute does not use the internet and encryption is optional (not default), while the question explicitly requires internet-based encrypted communication.

How to eliminate wrong answers

Option B (Azure ExpressRoute) is wrong because it provides a private, dedicated connection that bypasses the internet entirely, so it does not use the internet as specified. Option C (Azure Application Gateway) is wrong because it is a Layer 7 load balancer and web application firewall, not a network connectivity service for site-to-site VPNs. Option D (Azure Virtual WAN) is wrong because while it can include VPN gateways, it is a broader networking orchestration service; the question asks for a specific service to create the encrypted internet-based connection, and the core component is the VPN Gateway itself.

16
MCQhard

A company uses Azure Disk Encryption (ADE) on Windows virtual machines. They use a key encryption key (KEK) stored in Azure Key Vault to wrap the disk encryption key. The security policy requires that the KEK be automatically rotated every 90 days. They need to ensure that after rotation, the OS and data disks of running VMs automatically get re-wrapped with the new KEK version. Which configuration should they implement?

A.Enable soft-delete and purge protection on the Key Vault.
B.Use Key Vault key auto-rotation with a 90-day rotation period, and configure the disk encryption set to use the latest key version (empty string).
C.Create a new KEK every 90 days and modify the disk encryption set to point to the new key version.
D.Use Azure Policy to enforce automatic key rotation.
AnswerB

Key Vault key auto-rotation creates new key versions on schedule. By setting the key version to empty in the disk encryption set, the VMs automatically re-wrap their disks with the latest key version after rotation.

Why this answer

Azure Key Vault supports automatic key rotation with a configurable rotation period, and when a disk encryption set (DES) is configured with an empty string as the key version, it automatically uses the latest version of the KEK. This ensures that after the KEK is rotated every 90 days, the running VMs' OS and data disks are re-wrapped with the new KEK version without manual intervention or VM restart.

Exam trap

The trap here is that candidates may confuse Azure Policy (which enforces compliance) with actual key rotation and re-wrapping mechanisms, or mistakenly believe that manual key version updates in the DES are sufficient for automatic re-wrapping of running VMs.

How to eliminate wrong answers

Option A is wrong because enabling soft-delete and purge protection on the Key Vault is a data protection and recovery feature, not a mechanism for automatic key rotation or re-wrapping of disks. Option C is wrong because manually creating a new KEK every 90 days and updating the DES to point to the new key version is a manual process that does not meet the requirement for automatic rotation and re-wrapping. Option D is wrong because Azure Policy can enforce compliance rules but cannot directly trigger automatic key rotation or re-wrapping of disks; it is a governance tool, not a key lifecycle management feature.

17
MCQmedium

A company has an Azure virtual network with two subnets: App and Data. The App subnet hosts web servers, and the Data subnet hosts SQL databases. Security policy requires that only HTTPS traffic from the App subnet is allowed to the Data subnet, and all other inbound traffic to the Data subnet must be blocked. The solution must use a single network security group (NSG) associated to the Data subnet. Which NSG inbound rule configuration meets the requirement?

A.Allow HTTPS from App subnet priority 100, then Deny All priority 200
B.Deny All priority 100, then Allow HTTPS from App subnet priority 200
C.Allow HTTPS from App subnet priority 100, and Deny All from any source priority 100 (duplicate priority)
D.Allow HTTPS from App subnet priority 100, no other rules
AnswerA

This configuration is correct because Azure NSGs process rules in ascending numeric order, and priority 100 is higher than 200. The HTTPS allow rule for the App subnet is evaluated first, matching the permitted traffic, and the later DenyAll rule with priority 200 blocks all other inbound traffic. This implements the recommended pattern: a specific allow for the desired source and port, followed by a catch-all deny.

Why this answer

NSG rules are evaluated in priority order, with lower numbers processed first. By placing the Allow HTTPS rule at priority 100, it matches and permits traffic from the App subnet to the Data subnet. The subsequent Deny All rule at priority 200 then blocks all other inbound traffic, satisfying the security policy with a single NSG on the Data subnet.

Exam trap

The trap here is that candidates may think a Deny All rule is unnecessary because NSGs have an implicit deny at the end, but the explicit Deny All at a lower priority ensures that any traffic not matching the Allow rule is explicitly blocked, which is required by the policy and avoids reliance on the implicit default.

How to eliminate wrong answers

Option B is wrong because the Deny All rule at priority 100 would block all inbound traffic, including HTTPS from the App subnet, before the Allow rule at priority 200 is ever evaluated, making the Allow rule ineffective. Option C is wrong because duplicate priority values (100) are not allowed in NSG rules; Azure requires unique priority numbers, and even if allowed, the order of evaluation would be ambiguous. Option D is wrong because without a Deny All rule, any traffic not matching the Allow HTTPS rule (e.g., other protocols or sources) would be permitted by the default implicit deny, but the requirement explicitly states all other inbound traffic must be blocked, and the implicit deny only applies after all explicit rules; however, the explicit Deny All ensures no unintended traffic is allowed, which is necessary for strict compliance.

18
MCQmedium

A company is deploying Azure Bastion to provide secure RDP/SSH access to VMs in a virtual network. The security requirement is that all administrative access must be logged and audited. What additional configuration is needed to meet this requirement?

A.Enable NSG flow logs on the subnet containing the target VMs.
B.Enable diagnostic settings on Azure Bastion to send logs to a Log Analytics workspace.
C.Enable Azure Activity Log for the Bastion resource.
D.Configure diagnostic settings on the target VMs to send logs to Log Analytics.
AnswerB

Enabling diagnostic settings on the Azure Bastion resource streams the resource-specific category, such as BastionAuditLogs, into a Log Analytics workspace. These logs contain each user connection's source IP, username, target VM, protocol, and session duration, directly satisfying the requirement to audit RDP/SSH sessions through Bastion.

Why this answer

The correct option is B: enabling diagnostic settings on Azure Bastion to send logs to a Log Analytics workspace. Azure Bastion emits session-level audit logs (such as BastionAuditLogs) that record who connected, to which VM, and when; routing these to Log Analytics makes them queryable and auditable, which directly satisfies the logging and auditing requirement. Option A does not fit because NSG flow logs capture network traffic metadata, not the administrative session identity or command context needed for Bastion access auditing.

Option C is insufficient because the Azure Activity Log records control-plane operations on the Bastion resource, not the RDP/SSH session activity. Option D is also wrong because diagnostic settings on the target VMs do not capture the Bastion-mediated administrative access events required here.

19
MCQmedium

A company uses Azure SQL Database to store customer data, including credit card numbers. The security policy requires that database administrators (DBAs) must not be able to view the credit card numbers in plaintext. The column containing the credit card numbers must be encrypted at rest and in transit, and only a specific application (using a dedicated client library) should be able to decrypt the data. Which technology should they implement?

A.Transparent Data Encryption (TDE) with a customer-managed key stored in Azure Key Vault.
B.Dynamic Data Masking (DDM) for the credit card column.
C.Always Encrypted with a client-side encryption key stored in Azure Key Vault.
D.Row-Level Security (RLS) to restrict DBA access to the credit card column.
AnswerC

Correct. Always Encrypted encrypts the data on the client side, so the SQL Database never sees the plaintext. Only the client application with access to the encryption key can decrypt the data, preventing DBAs from viewing sensitive columns.

Why this answer

Always Encrypted ensures that sensitive data, such as credit card numbers, is encrypted on the client side before being sent to Azure SQL Database, and the encryption keys are never revealed to the database engine. This prevents DBAs or any server-side administrators from viewing the plaintext data, as decryption can only occur using the client-side encryption key stored in Azure Key Vault and accessed by the dedicated application library.

Exam trap

The trap here is that candidates often confuse Dynamic Data Masking (DDM) with encryption, not realizing that DDM only masks output and does not protect the underlying plaintext from privileged users or direct database access.

How to eliminate wrong answers

Option A is wrong because Transparent Data Encryption (TDE) encrypts data at rest but does not protect data from DBAs who have access to the database; the database engine can still decrypt the data in memory and in transit unless additional measures are taken, and it does not enforce client-side-only decryption. Option B is wrong because Dynamic Data Masking (DDM) only obfuscates data in query results for unauthorized users, but the underlying plaintext is still stored in the database and can be accessed by privileged users or through direct queries. Option D is wrong because Row-Level Security (RLS) restricts access to rows based on predicates but does not encrypt the data; DBAs with elevated permissions can bypass RLS or still view the plaintext column values.

20
MCQmedium

A company uses Azure AD B2B collaboration to invite external partner users. The security policy requires that guest users who have not signed in for more than 90 days should have their access automatically reviewed and, if not approved, removed. The company has Azure AD Premium P2 licenses. Which Azure AD feature should they configure to meet this requirement?

A.Enable automatic user deletion in the Azure AD B2B collaboration settings.
B.Create a Conditional Access policy that blocks sign-ins for guest users who haven't authenticated in 90 days.
C.Configure an Azure AD Access Review that reviews guest user access and automatically removes access after 90 days of inactivity.
D.Use Azure AD Identity Protection to detect guest user sign-in anomalies and revoke sessions.
AnswerC

Access Reviews can be configured to run periodically (e.g., quarterly) and include only guest users. The review can be set to automatically remove users who do not respond or who are not approved, effectively removing access for inactive guests.

Why this answer

Azure AD Access Reviews, available with Azure AD Premium P2 licenses, allow you to create recurring reviews that specifically target guest users who have not signed in for a specified period (e.g., 90 days). The review can be configured to automatically remove access if the reviewer does not approve, directly meeting the requirement for automatic review and removal after 90 days of inactivity.

Exam trap

The trap here is that candidates often confuse blocking sign-ins via Conditional Access (Option B) with actually removing access, but Conditional Access only prevents future authentication and does not revoke existing permissions or trigger a review workflow.

How to eliminate wrong answers

Option A is wrong because Azure AD B2B collaboration settings do not include an 'automatic user deletion' feature; user deletion must be performed manually or via automated scripts, and there is no built-in inactivity-based deletion in those settings. Option B is wrong because a Conditional Access policy can block sign-ins based on sign-in frequency or risk, but it cannot automatically remove guest user access or trigger a review process; it only prevents future sign-ins without addressing existing access. Option D is wrong because Azure AD Identity Protection is designed to detect and respond to sign-in anomalies and risky behaviors, not to manage inactivity-based access reviews or removals for guest users.

21
MCQmedium

A company stores sensitive financial documents in Azure Blob Storage. The security team needs to maintain an immutable log of all changes to the blob content, including the previous versions and the identity of the user who made the changes, for forensic analysis. Which Azure Storage feature should they enable on the storage account to meet this requirement?

A.Azure Blob Storage soft delete.
B.Azure Blob Storage versioning.
C.Blob Storage change feed.
D.Azure Storage analytics logs.
AnswerC

Blob Storage change feed is the correct choice because it provides an append-only, immutable transaction log that captures every creation, update, and deletion of blobs in a storage account, ordered by blob modification time. Each change feed record includes the blob's ETag, content length, and a timestamp, but it does not natively capture user identity; however, by correlating change feed events with Azure Storage Analytics logs (which record the caller's user ID, IP address, and operation details), you can attribute each change to a specific principal. This enables a tamper-resistant, chronological audit trail that satisfies the requirement to show 'who' performed each action, something soft delete, versioning, or analytics logs alone cannot guarantee.

Why this answer

The Blob Storage change feed provides an immutable, append-only log of all changes (create, update, delete) to blobs and blob metadata, including the previous version and the identity of the user who made the change via the requestor's object ID. This meets the forensic requirement for a complete audit trail of blob content changes.

Exam trap

The trap here is that candidates often confuse versioning (which preserves previous versions for recovery) with the change feed (which provides an immutable audit log of changes), leading them to select versioning when the requirement explicitly calls for a forensic log with user identity.

How to eliminate wrong answers

Option A is wrong because soft delete only preserves deleted blobs for a retention period and does not log changes to existing blob content or track user identity. Option B is wrong because versioning maintains previous versions of blobs but does not provide a chronological log of changes with user identity; it is a point-in-time recovery feature, not an audit trail. Option D is wrong because Storage analytics logs (now deprecated in favor of Azure Monitor resource logs) capture storage service operations but are not immutable by default and do not include previous blob content or a guaranteed append-only log.

22
MCQeasy

You are configuring Microsoft Sentinel data connectors. Which data connector should you use to ingest logs from Microsoft Entra ID (Azure AD) audit logs and sign-in logs?

A.Office 365 connector
B.Microsoft Defender XDR connector
C.Azure Activity connector
D.Microsoft Entra ID connector
AnswerD

The Microsoft Entra ID connector uses the Microsoft Graph API to stream both sign-in reports and directory audit logs into Microsoft Sentinel. Ingested data populates tables such as SigninLogs and AuditLogs, enabling detection rules for suspicious logons, MFA failures, and tenant configuration changes. This is the directly appropriate data source for monitoring identity behavior in Microsoft Entra ID.

Why this answer

The Microsoft Entra ID connector (formerly Azure AD connector) is specifically designed to ingest both audit logs and sign-in logs from Microsoft Entra ID into Microsoft Sentinel. This connector uses the Microsoft Graph API to pull the data, enabling security monitoring of identity-related activities such as user sign-ins, directory changes, and risky sign-in events. The other connectors either focus on different data sources or do not capture the full set of Entra ID logs.

Exam trap

The trap here is that candidates often confuse the Azure Activity connector (which logs Azure resource management actions) with the Entra ID connector (which logs identity and authentication events), leading them to incorrectly select Option C.

How to eliminate wrong answers

Option A is wrong because the Office 365 connector ingests logs from Exchange Online, SharePoint Online, Teams, and other Office 365 workloads, not Microsoft Entra ID audit or sign-in logs. Option B is wrong because the Microsoft Defender XDR connector ingests alerts and incidents from Microsoft 365 Defender (including Defender for Endpoint, Defender for Office 365, etc.), not raw Entra ID audit or sign-in logs. Option C is wrong because the Azure Activity connector ingests subscription-level operational logs from Azure Resource Manager (e.g., create/delete resources), not identity-related logs from Entra ID.

23
MCQmedium

A storage account contains legal evidence that must not be modified or deleted for seven years. Which feature should be configured?

A.Soft delete only
B.Lifecycle management to archive tier
C.Customer-managed keys
D.Immutable blob storage with a time-based retention policy
AnswerD

Immutable blob storage with a time-based retention policy enforces WORM (write once, read many) semantics, which prohibit any deletion or overwrite of blobs until the retention interval expires. This policy is a hard data-integrity control that meets legal preservation requirements by keeping evidence immutable and auditable. It is the direct, purpose-built Azure feature for ensuring legal evidence cannot be altered or removed.

Why this answer

Immutable blob storage with a time-based retention policy (WORM – Write Once, Read Many) is the correct choice because it enforces a strict seven-year retention period during which blobs cannot be modified or deleted, even by account administrators. This is achieved through a policy that locks the data at the storage level, ensuring compliance with legal hold requirements for evidence preservation.

Exam trap

The trap here is that candidates often confuse soft delete (which only protects against accidental deletion for a short period) with immutable storage (which enforces a hard, non-negotiable retention lock against both modification and deletion for a specified duration).

How to eliminate wrong answers

Option A is wrong because soft delete only provides protection against accidental deletion for a configurable retention period (default 7 days), but it does not prevent modifications or enforce a fixed seven-year legal hold; data can still be overwritten or deleted permanently after the soft-delete period expires. Option B is wrong because lifecycle management to the archive tier is designed for cost optimization by moving data to cooler storage tiers, not for preventing modification or deletion; data in the archive tier can still be deleted or overwritten by authorized users. Option C is wrong because customer-managed keys (CMK) control encryption at rest using Azure Key Vault, but they do not impose any retention or immutability constraints; data remains fully mutable and deletable regardless of key management.

24
Multi-Selecthard

Which TWO features are available in Microsoft Entra ID Privileged Identity Management (PIM) for managing Azure AD roles? (Choose two.)

Select 2 answers
A.Self-service password reset
B.Just-in-time activation
C.Multi-factor authentication enforcement
D.Automatic role assignment based on group membership
E.Approval workflow for role activation
AnswersB, E

Just-in-time activation is a core PIM capability that lets administrators make eligible roles available for temporary, time-boxed elevation. When a user needs elevated privileges, they activate the role for a specific duration, often with a justification, MFA check, and optional scope constraints. This reduces standing access and implements the principle of least privilege.

Why this answer

Option B (Just-in-time activation) is correct because PIM's core capability is making users eligible for Azure AD roles and requiring them to activate the role only when needed, granting time-bound, temporary elevation instead of permanent assignment. Option E (Approval workflow for role activation) is correct because PIM role settings allow administrators to require approval before an eligible user's activation request is granted, with designated approvers reviewing the request. The other options do not belong: self-service password reset (A) is an Entra ID authentication feature, not a PIM role-management feature; multi-factor authentication enforcement (C) is configured via Conditional Access or authentication methods, not as a PIM role feature; and automatic role assignment based on group membership (D) is handled by group-based licensing/role-assignable groups, not by PIM activation.

Exam trap

The trap here is that candidates often confuse features that are integrated with PIM (like MFA enforcement and self-service password reset) as being features of PIM itself, when in fact PIM's core capabilities are just-in-time activation and approval workflows for role activation.

25
MCQmedium

A company runs a public-facing web application on Azure App Service in the West US region. They want to protect against network-layer (Layer 3/4) DDoS attacks and have a single web application. Which Azure DDoS Protection tier should they use?

A.DDoS Protection Basic (default)
B.DDoS Protection Standard
C.Azure Web Application Firewall (WAF) on Application Gateway
D.Azure Front Door with DDoS Protection Standard
AnswerA

DDoS Protection Basic is automatically enabled for all Azure resources, including a public-facing Azure App Service, at no additional cost and with no configuration required. It performs always-on traffic monitoring and real-time mitigation of common network-layer attacks such as SYN floods, UDP floods, and reflection attacks at Azure's global edge. For a single App Service, this default protection is sufficient because the platform itself shields the application from volumetric L3/L4 threats, and Basic is the correct baseline expectation.

Why this answer

DDoS Protection Basic is automatically enabled for all Azure resources at no additional cost, providing always-on traffic monitoring and real-time mitigation of common network-layer (Layer 3/4) attacks, such as SYN floods, UDP floods, and reflection attacks. Since the company has a single web application and only needs protection against Layer 3/4 DDoS attacks, the Basic tier is sufficient and requires no configuration or extra cost.

Exam trap

The trap here is that candidates often assume DDoS Protection Standard is always required for any DDoS protection, overlooking that Basic is automatically enabled and sufficient for Layer 3/4 attacks on a single resource, while Standard is an enhanced add-on for complex, multi-resource environments needing advanced features.

How to eliminate wrong answers

Option B is wrong because DDoS Protection Standard is a paid tier designed for larger, multi-resource deployments that require adaptive tuning, attack analytics, and SLA-backed mitigation; it is overkill and unnecessary for a single web application needing only basic Layer 3/4 protection. Option C is wrong because Azure Web Application Firewall (WAF) on Application Gateway operates at Layer 7 (application layer) to protect against HTTP-specific attacks like SQL injection and cross-site scripting, not Layer 3/4 DDoS attacks. Option D is wrong because Azure Front Door with DDoS Protection Standard combines global load balancing and WAF capabilities but still requires the Standard tier for enhanced DDoS protection, which is not needed for this single-app scenario and adds unnecessary complexity and cost.

26
Multi-Selecteasy

Which TWO features are available in Microsoft Defender for Cloud's Cloud Security Posture Management (CSPM) capabilities? (Choose two.)

Select 2 answers
A.Attack path analysis
B.Security governance and compliance scoring
C.Just-in-time VM access
D.User and Entity Behavior Analytics (UEBA)
E.Vulnerability assessment for VMs
AnswersA, B

Attack path analysis is a cloud security posture management (CSPM) capability in Microsoft Defender for Cloud that builds a graph of your cloud resources and identifies chains of misconfigurations, exposed credentials, and weak network controls that could allow an attacker to reach a critical asset. Each path is scored and visualized so security teams can prioritize a small number of fixes that break multiple high-risk attack routes. This feature belongs to the posture-management pillar, not to workload protection.

Why this answer

Attack path analysis is a CSPM capability in Microsoft Defender for Cloud that identifies the most likely sequences of actions an attacker could take to breach critical resources. It uses a graph-based model of your cloud environment to map dependencies and misconfigurations, enabling proactive risk mitigation. This is a core part of the Cloud Security Posture Management (CSPM) pillar, not a workload protection feature.

Exam trap

The trap here is that candidates confuse workload protection features (like JIT VM access and vulnerability assessment) with CSPM capabilities, which are specifically about cloud configuration posture and risk analysis, not runtime or endpoint security.

27
MCQhard

You are deploying an Azure Storage account using an ARM template that includes a networkAcls section with defaultAction set to Deny. After deployment, you need to allow access from a specific public IP address. What should you do?

A.Create a private endpoint and assign it to the storage account.
B.Add an IP rule to the ipRules array with the public IP address.
C.Configure a service endpoint for the storage account.
D.Update the defaultAction to Allow and set ipRules to deny the IP.
AnswerB

IP rules allow specific public IPs to bypass the deny default.

Why this answer

The ARM template includes a `networkAcls` section with `defaultAction` set to `Deny`, which blocks all traffic by default. To allow access from a specific public IP address, you must add an IP rule to the `ipRules` array, specifying the public IP address in CIDR notation (e.g., "20.10.10.10/32"). This overrides the default deny for that specific IP, enabling access while keeping the storage account locked down from other public traffic.

Exam trap

The trap here is that candidates often confuse network ACLs with service endpoints or private endpoints, mistakenly thinking that service endpoints (Option C) or private endpoints (Option A) can be used to allow a specific public IP, when in fact they are designed for private network connectivity from Azure virtual networks.

How to eliminate wrong answers

Option A is wrong because creating a private endpoint assigns a private IP address from your virtual network to the storage account, which is used for private connectivity and does not allow access from a specific public IP address. Option C is wrong because configuring a service endpoint extends your virtual network identity to the storage account, allowing traffic from a subnet, not from a specific public IP address. Option D is wrong because updating `defaultAction` to `Allow` would permit all public traffic, which is overly permissive and defeats the purpose of restricting access to a single IP; setting `ipRules` to deny the IP would be redundant and ineffective since the default allow would override any deny rules.

28
MCQeasy

A company has an Azure virtual network with multiple subnets hosting different tiers of an application. The security team requires inspection of all traffic between subnets for malicious patterns and the ability to allow or deny traffic based on fully qualified domain names (FQDNs). Which Azure networking service should they implement?

A.Azure Network Security Group (NSG)
B.Azure Firewall
C.Azure Application Gateway
D.Azure VPN Gateway
AnswerB

Azure Firewall is a fully managed, stateful platform service that enforces centralized network and application rules, including FQDN-based Layer-7 filtering, TLS inspection, and threat-intelligence-based filtering. When deployed with user-defined routes (UDRs) and forced tunneling, it can inspect and control traffic flowing between subnets, providing a unified audit and management point. Its combination of network and application rules makes it the correct choice for this scenario.

Why this answer

Azure Firewall is a managed, cloud-based network security service that provides full Layer 3–7 inspection and can filter traffic based on FQDNs in network and application rules. It can inspect all traffic between subnets in a virtual network (via forced tunneling or routing) and supports threat intelligence-based filtering for malicious patterns, making it the correct choice for this requirement.

Exam trap

The trap here is that candidates often confuse NSGs with Azure Firewall, assuming NSGs can filter based on FQDNs or inspect traffic for malicious patterns, but NSGs lack Layer 7 inspection and FQDN support, which are exclusive to Azure Firewall in this context.

How to eliminate wrong answers

Option A is wrong because Network Security Groups (NSGs) operate at Layers 3 and 4 only, filtering based on source/destination IP, port, and protocol; they cannot inspect traffic for malicious patterns or filter based on FQDNs. Option C is wrong because Azure Application Gateway is a Layer 7 load balancer with a Web Application Firewall (WAF) that inspects HTTP/HTTPS traffic for web application attacks, but it does not provide general inter-subnet traffic inspection or FQDN-based filtering for non-web protocols. Option D is wrong because Azure VPN Gateway is used for encrypted site-to-site or point-to-site connectivity over the public internet; it does not perform traffic inspection or FQDN-based filtering between subnets within a virtual network.

29
MCQeasy

You are deploying a web application that stores user-uploaded files in Azure Blob Storage. You need to ensure that only authenticated users can upload files, and that uploaded files are automatically scanned for malware. What should you use?

A.Use Azure Event Grid to trigger a function for malware scanning
B.Enable Azure AD authentication for the storage account and enable Microsoft Defender for Storage
C.Configure Azure Firewall to allow only the web app's IP address
D.Use shared access signatures (SAS) with stored access policies
AnswerB

Enabling Azure AD authentication for the storage account replaces shared-key or SAS access with OAuth 2.0 tokens, allowing you to assign RBAC roles such as Storage Blob Data Contributor to individual users or service principals. This gives you per-user identity, conditional access, and audit logs for every upload. Microsoft Defender for Storage then continuously analyzes blob activity and scans files for malware using threat intelligence and hash reputation, alerting on detections and optionally applying high-confidence malware scans. Together these two controls address both identity and content security, which is exactly what the scenario requires.

Why this answer

Enabling Azure AD authentication for the storage account ensures that only authenticated users (via Azure AD) can upload files, while Microsoft Defender for Storage provides built-in malware scanning for uploaded blobs. This combination directly addresses both requirements without additional infrastructure.

Exam trap

The trap here is that candidates often choose Event Grid (Option A) thinking it handles both authentication and scanning, but it only triggers scanning after upload and does not enforce authentication, missing the core requirement.

How to eliminate wrong answers

Option A is wrong because Azure Event Grid triggers a function for malware scanning only after the file is uploaded, but it does not enforce authentication for the upload itself; it also adds latency and complexity. Option C is wrong because Azure Firewall restricts network access by IP address, but it does not authenticate individual users or scan files for malware. Option D is wrong because shared access signatures (SAS) with stored access policies provide delegated access but do not enforce per-user authentication via Azure AD, nor do they include malware scanning.

30
MCQmedium

An organization wants to export Defender for Cloud recommendations and alerts into a central Log Analytics workspace for retention and hunting. Which feature should they use?

A.Microsoft Defender External Attack Surface Management
B.Continuous export
C.Microsoft Entra access reviews
D.Azure Monitor autoscale
AnswerB

Continuous export is the dedicated Defender for Cloud feature that streams security recommendations and alerts to an Azure Log Analytics workspace, Event Hub, or Azure Monitor using diagnostic settings. It supports granular selection of resource types and can be configured via ARM/REST, enabling integration with SIEMs like Microsoft Sentinel. This directly fulfills the requirement, as it is the native mechanism for exporting this data.

Why this answer

Continuous export is the correct feature because it allows you to stream Defender for Cloud security alerts and recommendations to a Log Analytics workspace for long-term retention and custom hunting queries. This feature supports both real-time and scheduled export of security data, enabling centralized monitoring and compliance auditing. It directly addresses the requirement to export Defender for Cloud data into a Log Analytics workspace without additional third-party tools.

Exam trap

The trap here is that candidates may confuse 'Continuous export' with 'Azure Monitor autoscale' or 'External Attack Surface Management' because they all involve monitoring or scaling, but only continuous export directly addresses the requirement to export Defender for Cloud data to Log Analytics.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender External Attack Surface Management (EASM) is a service for discovering and mapping an organization's external attack surface, not for exporting Defender for Cloud alerts or recommendations to Log Analytics. Option C is wrong because Microsoft Entra access reviews are used for managing identity governance, such as reviewing group memberships and application access, and have no capability to export security alerts or recommendations. Option D is wrong because Azure Monitor autoscale is a feature that automatically adjusts the number of compute resources based on demand, and it does not handle the export of security data to Log Analytics.

31
MCQhard

An AKS cluster needs to pull container images from a private Azure Container Registry (ACR). The security policy requires that the AKS cluster identity should not have direct access to the ACR; instead, a service principal with the AcrPull role should be used, with credentials stored as a Kubernetes secret. Which authentication method should be configured on the AKS cluster?

A.AKS managed identity
B.ACR admin account
C.Kubernetes pull secret using a service principal
D.Azure AD pod identity
AnswerC

To implement this, create a service principal with only the AcrPull role, use its app ID and password as the username and password fields, and store the base64-encoded Docker config in a Kubernetes secret of type `kubernetes.io/dockerconfigjson`. Reference that secret in a pod's `imagePullSecrets` so the kubelet uses it to authenticate only for the pods that declare it, limiting access to those specific workloads. This credential is scoped to the service principal and can be rotated or revoked independently without affecting the cluster's control-plane identity, making it the correct choice when the policy explicitly demands a service principal secret instead of an identity-based assignment.

Why this answer

The scenario explicitly requires that the AKS cluster identity not have direct access to ACR, and instead mandates using a service principal with AcrPull role whose credentials are stored as a Kubernetes secret. A Kubernetes pull secret of type 'docker-registry' stores the service principal's client ID and client secret, which kubelet uses to authenticate to ACR when pulling images. This method decouples the AKS cluster's managed identity from ACR access, satisfying the security policy.

Exam trap

The trap here is that candidates often confuse 'AKS managed identity' with the requirement for a service principal secret, mistakenly thinking managed identity is always the best practice, but the question explicitly prohibits direct cluster identity access to ACR.

How to eliminate wrong answers

Option A is wrong because AKS managed identity would grant the cluster's own identity direct access to ACR, which violates the policy that the cluster identity should not have direct access. Option B is wrong because the ACR admin account is a shared, static credential with full access to the registry, and it is not a service principal; it also bypasses the requirement to use a service principal with AcrPull role. Option D is wrong because Azure AD pod identity is used to assign Azure AD identities to pods for accessing Azure resources, but it does not store credentials as a Kubernetes secret; it relies on Azure AD authentication and would still involve the cluster identity or pod-level managed identities, not a service principal secret stored in the cluster.

32
MCQhard

A company uses Azure AD Privileged Identity Management (PIM) for the Security Administrator role. The security policy requires that when a user activates the Security Administrator role, they must: 1) Provide a justification, 2) Get approval from a designated security group, and 3) The activation must last a maximum of 4 hours. Which combination of PIM settings should they configure?

A.Enable 'Require justification', 'Require approval', and set 'Maximum activation duration' to 4 hours. Assign the security group as the approver.
B.Enable 'Require justification', 'Require ticket information', and set 'Maximum activation duration' to 8 hours.
C.Enable 'Require approval' and set 'Maximum activation duration' to 4 hours. Do not require justification.
D.Enable 'Require Azure MFA on activation', 'Require justification', and set 'Maximum activation duration' to 4 hours.
AnswerA

These PIM settings map directly onto the three stated requirements: justification on activation, approval by the designated security group, and a four-hour maximum activation duration. Assigning that group as approver enforces the approval workflow the policy demands.

Why this answer

Azure AD PIM allows you to enforce all three requirements: justification, approval from a specified security group, and a maximum activation duration. By enabling 'Require justification' and 'Require approval' and setting the 'Maximum activation duration' to 4 hours, you meet the security policy exactly. The approval step requires assigning a designated security group as the approver, which is supported in PIM role settings.

Exam trap

The trap here is that candidates often confuse 'Require justification' with 'Require ticket information' or assume that MFA is always required for activation, but the question explicitly lists only three requirements—justification, approval, and 4-hour duration—so any extra or missing settings make the option incorrect.

How to eliminate wrong answers

Option B is wrong because it includes 'Require ticket information' instead of 'Require approval', and sets the maximum activation duration to 8 hours instead of the required 4 hours. Option C is wrong because it omits 'Require justification', which is a mandatory policy requirement. Option D is wrong because it includes 'Require Azure MFA on activation' (not required by the policy) and omits 'Require approval', which is explicitly required.

33
MCQmedium

A security team uses Microsoft Sentinel. They want to create a custom analytics rule that generates an incident whenever a user from a list of known malicious IP addresses attempts to sign in to any Azure AD app. They have imported the IP list into Sentinel using Threat Intelligence. Which rule type should they use?

A.Scheduled query rule
B.Near-real-time (NRT) rule
C.Microsoft Security rule
D.Anomaly rule
AnswerA

Scheduled query rules are Sentinel analytics rules that execute a KQL query on a fixed cadence (for example, every 5 or 15 minutes) and can create alerts and incidents based on the returned results. They are the only rule type that supports joining against the ThreatIntelligenceIndicator table, and Sentinel provides 'TI map' templates that match entities such as IP addresses, domains, and file hashes from your imported threat intelligence lists. Because the query is fully customizable, you can filter by indicator expiry, excluded IPs, or severity, and the results feed the incident creation workflow.

Why this answer

A scheduled query rule is the correct choice because it allows you to run a KQL query at a defined interval (e.g., every 5 minutes) to match sign-in events from IP addresses in a Threat Intelligence indicator. This rule type supports alert grouping and incident creation based on the query results, making it ideal for correlating Azure AD sign-in logs with a known malicious IP list imported via Threat Intelligence.

Exam trap

The trap here is that candidates often confuse NRT rules with scheduled queries, assuming 'near-real-time' is always better for threat intelligence matching, but NRT rules lack the ability to join against the ThreatIntelligenceIndicator table, making scheduled queries the only viable option for this use case.

How to eliminate wrong answers

Option B (NRT rule) is wrong because NRT rules run continuously with a near-real-time latency of 1-2 minutes but cannot reference Threat Intelligence indicators directly; they are designed for high-frequency, low-latency detection on streaming data without the ability to join against static or dynamic indicator lists. Option C (Microsoft Security rule) is wrong because it is used to create incidents from alerts generated by Microsoft security products (e.g., Microsoft Defender for Cloud, Microsoft 365 Defender), not from custom KQL queries against imported threat intelligence. Option D (Anomaly rule) is wrong because anomaly rules use machine learning to detect unusual patterns in data over time, not to match specific known malicious IP addresses from a predefined list.

34
MCQmedium

A security analyst uses Microsoft Sentinel. They have created a playbook that tags Azure VMs as 'isolated' when a high-severity malware alert is triggered. They want this playbook to run automatically whenever a related alert is generated. Which feature should they configure?

A.Automation rule.
B.Scheduled analytics rule.
C.Incident creation rule.
D.Workbook.
AnswerA

Automation rules in Microsoft Sentinel enable automated incident management by executing playbooks directly in response to incident creation or update events. You can define conditions based on alert properties and specify actions like running a playbook, changing status, or assigning ownership. This is the correct mechanism to run a playbook automatically without manual intervention.

Why this answer

Automation rules in Microsoft Sentinel allow you to define triggers that automatically run playbooks when specific alerts or incidents are created. In this scenario, the playbook tags Azure VMs as 'isolated' upon a high-severity malware alert, and an automation rule can be configured to run that playbook automatically whenever such an alert is generated, without manual intervention.

Exam trap

The trap here is that candidates often confuse automation rules with analytics rules, mistakenly thinking that scheduled analytics rules can directly trigger playbooks, but analytics rules only generate alerts and do not natively invoke automated responses.

How to eliminate wrong answers

Option B is wrong because scheduled analytics rules are used to periodically query data and generate alerts based on predefined schedules, not to trigger automated responses like running playbooks. Option C is wrong because incident creation rules are not a native feature in Microsoft Sentinel; incidents are created automatically from alerts, and there is no separate rule type for incident creation that triggers playbooks. Option D is wrong because workbooks are visualization tools for dashboards and reports, not mechanisms for automating response actions like running playbooks.

35
MCQhard

A Sentinel watchlist contains high-value administrator accounts. Which KQL pattern best uses it in a detection rule?

A.Load the watchlist with _GetWatchlist() and join or filter SigninLogs by the account identifier
B.Export the watchlist to CSV and manually compare it after alerts fire
C.Use the watchlist as a replacement for the SigninLogs table
D.Attach the watchlist to a workbook without changing the detection query
AnswerA

Load the watchlist inside the analytics rule query by calling _GetWatchlist('<alias>'), which returns the watchlist as a KQL table. You can then use a join or a where filter against the SigninLogs table using the account identifier column (for example, UserPrincipalName or UserId) to restrict or enrich the results to only high-value administrator accounts. This executes at query time, so each scheduled run automatically uses the current watchlist contents and triggers alerts only when a matching account produces a sign-in event.

Why this answer

The `_GetWatchlist()` function in KQL allows you to dynamically load a Sentinel watchlist into a query. By joining or filtering `SigninLogs` against the watchlist's account identifier field, you can create a detection rule that triggers only when a high-value administrator account (defined in the watchlist) performs a sign-in, enabling precise, automated alerting without manual intervention.

Exam trap

The trap here is that candidates confuse a watchlist as a static data source that can replace log tables, rather than understanding it as a reference dataset that must be explicitly joined or filtered within a KQL query to be useful in detection rules.

How to eliminate wrong answers

Option B is wrong because exporting a watchlist to CSV and manually comparing it after alerts fire defeats the purpose of automation and real-time detection; it introduces latency and human error, which is not a valid KQL pattern for a detection rule. Option C is wrong because a watchlist is a reference dataset (a list of values), not a log table like `SigninLogs`; it cannot replace a table that contains event data, and attempting to use it as such would result in a query error or no meaningful results. Option D is wrong because attaching a watchlist to a workbook only visualizes data in a dashboard; it does not integrate the watchlist into the detection query logic, so the detection rule would not use the watchlist to filter or alert on high-value accounts.

36
Multi-Selectmedium

Which TWO actions should you take to ensure that an Azure Storage account is only accessible over HTTPS and that data in transit is encrypted?

Select 2 answers
A.Configure a custom domain with HTTPS enabled.
B.Set 'Secure transfer required' to Enabled.
C.Deploy Azure Firewall in front of the storage account.
D.Set the minimum TLS version to 1.2.
E.Use Azure Private Link to connect to the storage account.
AnswersB, D

Setting 'Secure transfer required' to Enabled instructs Azure Storage to reject any request that arrives over plain HTTP, returning an error such as 403 Forbidden for non-HTTPS attempts. This enforces that all data transmitted to or from blob, table, queue, and file endpoints must use TLS/HTTPS, regardless of whether the client uses the public endpoint, a custom domain, or a shared access signature. It is the primary control that makes encryption-in-transit mandatory for the storage account.

Why this answer

Enabling 'Secure transfer required' on an Azure Storage account rejects any HTTP requests and enforces HTTPS for all data in transit. Option D is correct because setting the minimum TLS version to 1.2 ensures that only clients using TLS 1.2 or higher can connect, which prevents downgrade attacks and enforces strong encryption for data in transit.

Exam trap

The trap here is that candidates often confuse 'Secure transfer required' with 'minimum TLS version' or think that Azure Firewall or Private Link alone can enforce encryption, but neither of those services actually enforces HTTPS or TLS for data in transit.

37
MCQmedium

A security team uses Microsoft Defender for Cloud. They have assigned a custom regulatory compliance initiative that includes policies to enforce encryption on storage accounts and SQL databases. They want to automatically remediate any non-compliant resources as soon as they are created, without manual intervention. Which feature should they configure?

A.Security policies (assignments)
B.Azure Policy with a 'DeployIfNotExists' effect
C.Just-in-time VM access
D.Adaptive application controls
AnswerB

Azure Policy with a 'DeployIfNotExists' effect triggers a deployment through a linked managed identity when a non-compliant resource is created or updated, automatically applying the required configuration—for example, enabling the Azure Disk Encryption extension on newly created VMs. Because the effect both detects non-compliance and takes a corrective action, it closes the loop that a plain audit-only assignment leaves open. This is exactly the mechanism Defender for Cloud uses to auto-remediate certain recommendations, making it the correct choice for automatically enforcing encryption.

Why this answer

The 'DeployIfNotExists' effect in Azure Policy automatically deploys a resource (e.g., encryption configuration) when a non-compliant resource is created or updated, without manual intervention. This aligns with the requirement to remediate non-compliant storage accounts and SQL databases as soon as they are provisioned, as part of a custom regulatory compliance initiative assigned via Defender for Cloud.

Exam trap

The trap here is that candidates often confuse 'DeployIfNotExists' with 'AuditIfNotExists' or assume that simply assigning a policy (Option A) will automatically fix non-compliant resources, but only 'DeployIfNotExists' provides automatic remediation without manual steps.

How to eliminate wrong answers

Option A is wrong because Security policies (assignments) in Defender for Cloud only define which initiatives and standards are applied to a scope; they do not perform automatic remediation of non-compliant resources. Option C is wrong because Just-in-time VM access is a security control for managing VM inbound traffic and has no role in enforcing encryption on storage accounts or SQL databases. Option D is wrong because Adaptive application controls are used to create allowlists for running applications on Azure VMs, not for deploying encryption configurations to storage or SQL resources.

38
MCQmedium

You are using Microsoft Defender for Cloud to protect Azure Kubernetes Service (AKS) clusters. You need to receive alerts about suspicious activities within the cluster, such as privilege escalations. What should you enable?

A.Microsoft Defender for Containers
B.Microsoft Sentinel with AKS data connector
C.Azure Policy for AKS
D.Azure Security Center (classic)
AnswerA

Microsoft Defender for Containers provides Kubernetes-aware threat detection, monitoring control plane audit logs and node-level runtime activity to surface suspicious events such as privilege escalation inside AKS clusters. Enabling it satisfies the stem's requirement for cluster activity alerts, which generic Defender for Cloud plans or standalone Microsoft Entra ID controls cannot deliver.

Why this answer

Microsoft Defender for Containers is the correct solution because it provides threat detection for AKS clusters, including alerts for privilege escalations, suspicious process execution, and other runtime threats. It integrates directly with Defender for Cloud to monitor the Kubernetes audit logs and container workloads without requiring additional data connectors or agents.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with Microsoft Defender for Cloud (a cloud security posture management and threat detection tool), assuming that ingesting AKS logs into Sentinel provides the same built-in threat detection alerts as Defender for Containers, but Sentinel requires custom analytics rules to generate alerts, whereas Defender for Containers provides out-of-the-box detection for privilege escalations.

How to eliminate wrong answers

Option B is wrong because Microsoft Sentinel with the AKS data connector ingests logs for security information and event management (SIEM) purposes, but it does not natively generate the specific threat detection alerts for privilege escalations within the cluster; that requires Defender for Containers. Option C is wrong because Azure Policy for AKS enforces compliance and governance rules (e.g., restricting privileged containers) but does not produce real-time security alerts for suspicious activities like privilege escalations. Option D is wrong because Azure Security Center (classic) is the predecessor to Microsoft Defender for Cloud and lacks the container-specific threat detection capabilities that Defender for Containers provides; it has been superseded and does not support the same level of AKS runtime monitoring.

39
MCQeasy

You need to ensure that security alerts from Microsoft Defender for Cloud are sent to a central SIEM system. What should you configure?

A.Create a playbook that forwards alerts to the SIEM
B.Configure diagnostic settings for the subscription
C.Assign an Azure Policy to export alerts
D.Enable continuous export to Event Hubs
AnswerD

Continuous export is a native Microsoft Defender for Cloud feature that streams security alerts and recommendations to an Event Hubs namespace or a Log Analytics workspace in near real time. This is the officially supported integration path for sending security alerts to an external SIEM, because Event Hubs serves as a high-throughput, durable ingestion endpoint that downstream tools like Splunk or QRadar can consume. You enable it per subscription or configure it centrally with Azure Policy, and it guarantees ongoing delivery without per-alert manual action. This satisfies the requirement of ensuring security alerts reach the SIEM continuously.

Why this answer

Microsoft Defender for Cloud can stream security alerts and recommendations to an Event Hubs namespace via the 'Continuous export' settings. This enables external SIEM systems, such as Splunk or Azure Sentinel, to ingest the data by connecting to the Event Hubs endpoint. Diagnostic settings export activity logs and metrics, not security alerts, and playbooks are for automated response, not data forwarding.

Exam trap

The trap here is that candidates often confuse 'diagnostic settings' (which export logs and metrics) with 'continuous export' (which specifically exports security alerts and recommendations), leading them to incorrectly select Option B.

How to eliminate wrong answers

Option A is wrong because a playbook in Microsoft Sentinel or Defender for Cloud is designed for automated incident response actions (e.g., triggering a ticket or blocking an IP), not for forwarding alerts to an external SIEM. Option B is wrong because diagnostic settings export platform logs and metrics (e.g., Azure Activity log, resource metrics) to destinations like Log Analytics or Storage, but they do not include security alerts from Defender for Cloud. Option C is wrong because Azure Policy is used to enforce compliance rules and configurations across resources, not to export security alerts; it cannot directly stream alert data to a SIEM.

40
MCQmedium

You have an Azure Cosmos DB account with multiple containers. You need to ensure that only specific Azure AD identities can access the data and that all access is logged. What should you use?

A.Use primary keys for authentication and enable audit logging
B.Use Azure AD authentication and RBAC roles, and enable diagnostic logs
C.Configure managed identities for Azure resources and enable diagnostic logs
D.Configure an Azure Cosmos DB firewall and enable diagnostic logs
AnswerB

Azure Active Directory authentication with RBAC roles is the correct choice because it binds each request to a specific user or service principal, enabling fine-grained permissions through built-in roles such as Cosmos DB Built-in Data Reader and Contributor. Enabling diagnostic logs for the account captures both control-plane and data-plane operations, providing a comprehensive audit trail for who accessed which container, when, and from where. This combination delivers identity-based access control, least privilege, and auditing that the other options lack.

Why this answer

Azure AD authentication with RBAC roles allows you to restrict data access to specific Azure AD identities, and enabling diagnostic logs captures all data plane operations for auditing. This combination meets the requirements of identity-based access control and comprehensive logging, unlike primary keys which are shared secrets and do not support identity-level auditing.

Exam trap

The trap here is that candidates often confuse network-level controls (firewall) or shared keys with identity-based access control, overlooking that Azure AD authentication with RBAC is the only option that provides both identity-specific access and auditable logging.

How to eliminate wrong answers

Option A is wrong because primary keys are shared secrets that grant full access to all data in the account and cannot be scoped to specific Azure AD identities, nor do they provide per-identity audit logging. Option C is wrong because managed identities are used for authenticating Azure resources to Cosmos DB, not for restricting access to specific Azure AD identities; they still require RBAC roles and diagnostic logs to meet the logging requirement, but the option omits RBAC. Option D is wrong because a firewall only controls network-level access by IP address, not identity-based access control, and while diagnostic logs can be enabled, the firewall does not enforce Azure AD identity restrictions.

41
MCQeasy

You run the PowerShell command shown in the exhibit. After execution, you check the Log Analytics workspace in the Azure portal. The workspace is created successfully. However, when you try to onboard the workspace to Microsoft Sentinel, you receive an error that Sentinel cannot be enabled on this workspace. What is the most likely cause?

A.The SKU is set to PerGB2018, which is not compatible with Sentinel.
B.The resource group location is different from the workspace location.
C.The workspace is in a region that does not support Microsoft Sentinel.
D.The retention period is set to 365 days, which exceeds the maximum for Sentinel.
AnswerC

Microsoft Sentinel is not available in every Azure region. The Log Analytics workspace must reside in a region where the Sentinel solution (Microsoft.SecurityInsights) is supported. If the workspace is in an unsupported region, enabling Sentinel will fail with a region-specific error. This is the only listed condition that directly and necessarily blocks Sentinel deployment, making it the correct answer.

Why this answer

Microsoft Sentinel is not available in all Azure regions. The error 'Sentinel cannot be enabled on this workspace' most commonly occurs when the Log Analytics workspace is deployed in a region that does not support Sentinel. Even though the workspace is created successfully, Sentinel requires specific regional availability, and if the workspace region is not in the supported list, onboarding will fail.

Exam trap

The trap here is that candidates assume any Log Analytics workspace can be onboarded to Sentinel as long as it is created successfully, overlooking the critical regional restriction that Sentinel is not globally available in all Azure regions.

How to eliminate wrong answers

Option A is wrong because PerGB2018 is a valid and supported pricing tier for Log Analytics workspaces used with Microsoft Sentinel; Sentinel does not require a specific SKU. Option B is wrong because the resource group location and workspace location can be different without affecting Sentinel enablement; Sentinel only cares about the workspace's own region. Option D is wrong because a retention period of 365 days is within the allowed range for Sentinel workspaces (up to 2 years by default, extendable to 7 years with add-on); it does not block Sentinel enablement.

42
MCQeasy

Your organization uses Microsoft Entra ID and needs to implement a policy that blocks all sign-ins from countries that are not approved. What should you configure?

A.Enable multi-factor authentication for all users
B.Create a Conditional Access policy with a location condition set to block
C.Review sign-in logs and manually block IPs
D.Configure an Identity Protection risk policy
AnswerB

A Conditional Access policy with a location condition allows you to define named locations (such as specific countries or IP ranges) and explicitly block sign-ins originating from those locations. The policy is evaluated in real time during authentication, before token issuance, and can also be scoped to all cloud apps and specific users or groups. This directly enforces the requirement to restrict access by geographic location, making it the correct answer.

Why this answer

A Conditional Access policy in Microsoft Entra ID allows you to define location conditions based on IP ranges, countries, or regions. By configuring the location condition to include all countries except the approved ones and setting the access control to 'Block access', you can effectively block sign-ins from non-approved countries. This is the native, policy-driven approach to enforce geographic restrictions without manual intervention.

Exam trap

The trap here is that candidates often confuse location-based blocking with risk-based policies or MFA, assuming that adding authentication factors or reviewing logs can achieve geographic restrictions, but only a Conditional Access policy with a location condition provides a direct, automated block based on country.

How to eliminate wrong answers

Option A is wrong because enabling multi-factor authentication (MFA) for all users does not block sign-ins based on location; it only adds an additional verification step, which does not prevent access from unapproved countries. Option C is wrong because manually reviewing sign-in logs and blocking IPs is not scalable, does not cover dynamic IP ranges, and is not a policy-based solution; it also fails to address the requirement for a continuous, automated block. Option D is wrong because an Identity Protection risk policy focuses on detecting and responding to risky user behavior (e.g., leaked credentials, anonymous IP addresses) rather than enforcing static geographic restrictions based on country.

43
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) to manage the 'Security Administrator' role. They want a user to be able to activate this role for a maximum of 2 hours per activation. Which PIM setting should they configure?

A.Set the 'Activation maximum duration' to 2 hours in the role settings for Security Administrator.
B.Set the 'Expire eligible assignments after' to 2 hours in the role settings.
C.Enable 'Require justification' and 'Require approval' to ensure the role is not misused.
D.Set the 'Activation maximum duration' to 1 hour and the user can activate twice.
AnswerA

The 'Activation maximum duration' in the role settings for Security Administrator directly defines the maximum time a user can remain active in that role after requesting activation. By setting it to 2 hours, you guarantee that any single activation session expires after two hours, at which point the user's role assignment is deactivated unless they reactivate. This is the specific setting that enforces the 2-hour limit requested by the company.

Why this answer

The 'Activation maximum duration' setting in Azure AD PIM role settings directly controls the maximum time a user can remain active in an eligible role after activation. By setting this to 2 hours, the user will be able to activate the Security Administrator role for up to 2 hours per activation, after which the role assignment expires automatically.

Exam trap

The trap here is confusing 'Activation maximum duration' (the time a role is active after activation) with 'Expire eligible assignments after' (the time a user remains eligible to activate), leading candidates to incorrectly choose Option B.

How to eliminate wrong answers

Option B is wrong because 'Expire eligible assignments after' controls how long a user can remain eligible for the role before their eligibility expires, not the duration of an activation. Option C is wrong because 'Require justification' and 'Require approval' are additional security controls that do not limit the activation duration; they enforce auditing and approval workflows but do not set a time limit. Option D is wrong because setting the 'Activation maximum duration' to 1 hour would limit each activation to 1 hour, and the user activating twice does not achieve a 2-hour continuous activation; the maximum duration per activation is a single session limit, not a cumulative allowance.

44
MCQmedium

An organization is deploying Microsoft Sentinel to centrally collect and analyze security events. They need to ingest logs from multiple on-premises Windows servers located behind a firewall. Which agent should they deploy on those servers?

A.Azure Monitor Agent (AMA)
B.Log Analytics agent (Microsoft Monitoring Agent)
C.Azure Security Center agent
D.Azure Automation Agent
AnswerA

Azure Monitor Agent (AMA) is the current, consolidated data-collection platform that unifies the functionality of the Log Analytics agent and the Diagnostics extension. It uses Data Collection Rules (DCRs) to define exactly which logs and metrics to collect from Windows and Linux machines, including security events, Syslog, and custom logs. Microsoft Sentinel fully supports AMA, and it is the recommended agent for all new deployments, providing better performance, manageability, and feature parity across Azure and non-Azure resources.

Why this answer

The Azure Monitor Agent (AMA) is the correct choice because it is the current, unified data-collection agent for Microsoft Sentinel and Azure Monitor, designed to collect logs from Windows servers behind firewalls via outbound HTTPS (port 443) to the Log Analytics workspace. It supports data-collection rules (DCRs) for flexible, scalable ingestion and is the recommended replacement for the legacy Log Analytics agent. AMA can be deployed on-premises Windows servers using Azure Arc for management, ensuring secure log forwarding to Sentinel.

Exam trap

The trap here is that candidates often confuse the legacy Log Analytics agent (option B) as still being the primary agent for Sentinel, but Microsoft has deprecated it in favor of AMA, and the exam expects knowledge of the current recommended agent.

How to eliminate wrong answers

Option B is wrong because the Log Analytics agent (Microsoft Monitoring Agent) is legacy and deprecated for new deployments in Microsoft Sentinel as of August 2024; it lacks support for advanced data-collection rules and is being phased out. Option C is wrong because the Azure Security Center agent (now part of Defender for Cloud) is specifically for security posture and threat detection, not for general log ingestion into Sentinel; it does not replace the log-collection agent. Option D is wrong because the Azure Automation Agent (Hybrid Runbook Worker) is designed to run automation runbooks on-premises, not to collect and forward security logs to Sentinel; it serves a completely different purpose.

45
MCQmedium

Your organization uses Azure Storage to host sensitive financial data. You need to ensure that all access to the storage account is encrypted in transit and that access keys are rotated automatically every 90 days. You also need to prevent access from public IP addresses. Which combination of configurations should you implement?

A.Configure a network firewall rule to block all traffic, enable 'Secure transfer required', and rotate keys manually every 90 days
B.Enable 'Allow trusted Microsoft services', configure key rotation policy, and disable 'Allow storage account key access'
C.Enable 'Secure transfer required', configure key rotation policy, and disable 'Allow Blob public access'
D.Enable 'Secure transfer required', configure key rotation policy, and set 'Public network access' to 'Disabled'
AnswerD

This is the correct configuration because it addresses three independent layers of protection. 'Secure transfer required' forces all clients to use HTTPS and reject HTTP requests; the key rotation policy automatically rotates shared account keys within a defined period, limiting the lifetime of any leaked key; and 'Public network access: Disabled' blocks the storage account's public endpoint entirely, requiring connections to come through private endpoints or approved virtual network paths. Together these controls provide defense-in-depth for sensitive financial data.

Why this answer

Option D is correct because it directly satisfies all three requirements: enabling 'Secure transfer required' enforces HTTPS/TLS encryption in transit, configuring a key rotation policy automatically rotates the storage account access keys on a 90-day schedule, and setting 'Public network access' to 'Disabled' blocks access from public IP addresses (forcing private endpoint/private link access). The other options fall short: A relies on manual key rotation and a blanket firewall block rather than automatic rotation, B disables storage account key access (which conflicts with rotating access keys) and does not disable public network access, and C disables only anonymous blob public access, which does not prevent access from public IP addresses.

46
MCQhard

An Azure SQL Database contains salary data. Support analysts need to query employee records but must not see full salary values. Which feature is most appropriate when the application cannot be changed immediately?

A.Transparent Data Encryption
B.Dynamic data masking
C.Geo-replication
D.Accelerated database recovery
AnswerB

Dynamic Data Masking (DDM) is a column-level, query-time control that applies masking rules to results returned to non-privileged users, making salary values appear as partial, default, or random placeholders. Because the masking is applied dynamically without modifying the underlying data, analysts can still query the table and see non-sensitive columns while sensitive salary content is obscured. This precisely satisfies the need to let support analysts work with the database without exposing salary data.

Why this answer

Dynamic data masking (DDM) is the correct choice because it obfuscates sensitive data in query results without modifying the underlying database or requiring application changes. The support analysts can still query employee records, but the salary column is masked according to a defined masking rule (e.g., showing only the last four digits or replacing with zeros). This meets the requirement of preventing full salary exposure while the application remains unchanged.

Exam trap

The trap here is confusing data-at-rest encryption (TDE) with data-masking at query time—candidates often assume encryption alone prevents unauthorized viewing, but encryption does not affect what authorized users see when they run SELECT queries.

How to eliminate wrong answers

Option A is wrong because Transparent Data Encryption (TDE) encrypts data at rest on disk and in backups, but it does not control what users see when querying the database—authorized users still see full salary values. Option C is wrong because geo-replication provides disaster recovery by maintaining a readable secondary replica in a different region, but it does not restrict data visibility in query results. Option D is wrong because accelerated database recovery (ADR) improves transaction rollback speed and database availability after failures, but it has no effect on data masking or access control.

47
MCQhard

Refer to the exhibit. You are reviewing a scheduled analytics rule in Microsoft Sentinel that uses the KQL query shown. The rule is configured to run every hour. A security analyst reports that the rule is generating too many incidents. What is the most likely cause?

A.The rule is configured to run too frequently.
B.The query does not filter out known safe IP addresses sufficiently.
C.The query uses 'ago(1h)' which includes data from the previous hour, causing duplicate incidents.
D.The query has a syntax error that causes all sign-ins to match.
AnswerB

The query excludes only two specific IP addresses, which leaves all other internal or trusted IPs subject to creating an incident when a disabled account signs in. Because disabled-account sign-in events are often generated by old service accounts, scheduled tasks, or users who have not been offboarded, the rule should apply an allowlist of corporate egress ranges or a blocklist/allowlist combination. Without a sufficiently broad safe-IP filter, the rule will repeatedly alert on legitimate activity and drown out genuinely suspicious disabled-account access.

Why this answer

The query likely uses a broad filter for sign-in events without excluding known safe IP addresses (e.g., corporate VPNs, trusted services). This causes every sign-in from those IPs to generate an incident, overwhelming the rule with false positives. The rule's frequency (every hour) is not the issue; the query logic is insufficiently scoped.

Exam trap

The trap here is that candidates often blame the rule frequency (Option A) or the time range (Option C) without realizing that the core issue is the query's lack of IP filtering, which is a common misconfiguration in Sentinel analytics rules.

How to eliminate wrong answers

Option A is wrong because running the rule every hour is a standard frequency for sign-in monitoring; the problem is not the schedule but the query's failure to exclude benign events. Option C is wrong because 'ago(1h)' correctly limits the query to the last hour's data, preventing overlap with previous runs; it does not cause duplicate incidents. Option D is wrong because a syntax error would cause the rule to fail or return no results, not generate too many incidents.

48
MCQhard

Your company is migrating a legacy on-premises application to Azure VMs. The application writes log files to a local folder. You need to collect these logs centrally for security analysis using Microsoft Sentinel. The application runs on Windows Server 2022 and is expected to generate about 50 GB of logs per day. The security team requires that logs be encrypted at rest and in transit, and that log collection has minimal latency. You set up Azure Monitor Agent (AMA) on the VM and configure a Data Collection Rule (DCR) to stream custom logs to a Log Analytics workspace. However, after 24 hours, no custom logs appear in the workspace. The AMA is reporting as healthy. You need to troubleshoot and resolve the issue. What is the most likely cause?

A.The DCR does not include the correct table name for the custom log, or the table does not exist in the Log Analytics workspace.
B.The custom log file path specified in the DCR is a local path, but AMA requires a network share for custom log collection.
C.The log file format is not JSON, but AMA only supports custom logs in JSON format.
D.The VM does not have local administrator privileges required for the AMA to read the log files.
AnswerA

The Data Collection Rule (DCR) must map the incoming stream to an existing table in the Log Analytics workspace, typically a custom table with a `_CL` suffix. The `tableName` specified in the `destinations` section must exactly match the table that was created, including case and suffix. The DCR does not automatically create the table, so if the name is misspelled or the table has not been provisioned, the ingestion pipeline silently drops the data.

Why this answer

The DCR must reference the custom log table created in the Log Analytics workspace; if the table name does not match or the table does not exist, logs will not be ingested. Option B: AMA can collect custom logs from a local file path; the path does not need to be a network share. Option C: The log file format is not limited to JSON; AMA can collect plain text logs with a defined pattern.

Option D: The agent does not require local admin privileges for custom log collection; it runs as Local System.

49
Multi-Selectmedium

Which TWO of the following are capabilities of Microsoft Entra ID Protection?

Select 2 answers
A.Conditional Access session controls
B.Sign-in risk policy
C.User risk policy
D.Access reviews
E.Role-based access control (RBAC)
AnswersB, C

Sign-in risk policy is a native Microsoft Entra ID Protection capability that automates responses to risky sign-in events. It evaluates real-time and offline risk detections (like impossible travel, anonymous IP addresses, or atypical sign-in behavior) and triggers actions such as requiring multi-factor authentication or blocking access. This policy is part of the risk-based protection model, not a generic access control, and is explicitly distinct from session controls or governance features.

Why this answer

Microsoft Entra ID Protection is specifically designed to detect identity-based risks and let administrators respond to them via two built-in policies: the sign-in risk policy (B), which evaluates each authentication attempt and can require MFA or block the sign-in when the sign-in is deemed risky, and the user risk policy (C), which evaluates the overall risk of a user account (for example, from leaked credentials) and can force a secure password change. Both B and C are core, out-of-the-box capabilities of Entra ID Protection and are configured directly in its Risk policies blade. Conditional Access session controls (A) are a feature of Conditional Access (sign-in frequency, app-enforced restrictions, Cloud App Security/Defender for Cloud Apps controls), not of ID Protection itself, even though risk signals can feed Conditional Access.

Access reviews (D) belong to Entra ID Governance (Identity Governance), and role-based access control (E) is the general authorization model used across Azure and Entra ID, not a risk-detection capability of ID Protection.

Exam trap

The trap here is that candidates often confuse the risk-based policies of Entra ID Protection (sign-in risk and user risk) with Conditional Access session controls or other Entra ID features like Access Reviews and RBAC, because all are part of the broader Entra ID suite but serve distinct functions.

50
MCQmedium

A company uses Azure Key Vault to store secrets. They want to grant developers the ability to read secrets, but only for specific secret names (e.g., 'App--ConnectionString'). They also want to use Azure RBAC instead of the Key Vault access policy model. Which RBAC role should they assign, and at which scope?

A.Assign the 'Key Vault Secrets User' role at the secret scope
B.Assign the 'Key Vault Secrets User' role at the vault scope
C.Assign the 'Key Vault Reader' role at the secret scope
D.Assign the 'Key Vault Secrets Officer' role at the secret scope
AnswerA

The 'Key Vault Secrets User' role permits reading secret content. When scoped to an individual secret, it restricts access to that specific secret only. Azure RBAC supports data plane roles at the secret, key, or certificate level.

Why this answer

The 'Key Vault Secrets User' role, when assigned at the individual secret scope (e.g., /subscriptions/{sub}/resourceGroups/{rg}/providers/Microsoft.KeyVault/vaults/{vault}/secrets/{secretName}), grants read-only access to that specific secret. This satisfies the requirement to use Azure RBAC (instead of the legacy access policy model) and to limit developers to reading only secrets with a specific name, such as 'App--ConnectionString'.

Exam trap

The trap here is that candidates often assume RBAC roles can only be assigned at the vault scope, forgetting that Azure RBAC supports fine-grained scoping down to the individual secret level, which is essential for least-privilege access control.

How to eliminate wrong answers

Option B is wrong because assigning the 'Key Vault Secrets User' role at the vault scope would grant read access to all secrets in the vault, not just the specific secret name required. Option C is wrong because the 'Key Vault Reader' role only allows listing vaults and reading metadata (e.g., vault properties), not reading secret values; it does not include the 'Microsoft.KeyVault/vaults/secrets/read' action needed to retrieve secret content. Option D is wrong because the 'Key Vault Secrets Officer' role includes write and delete permissions (e.g., 'Microsoft.KeyVault/vaults/secrets/write' and 'delete'), which exceeds the required read-only access and violates the principle of least privilege.

51
MCQmedium

A company uses Azure SQL Database with Transparent Data Encryption (TDE) using a customer-managed key (CMK) stored in Azure Key Vault. The Key Vault has a firewall enabled that denies all public network access. The SQL server has a system-assigned managed identity assigned the 'Key Vault Crypto Service Encryption User' role. However, TDE operations are failing because the SQL server cannot access the Key Vault. What additional configuration is needed?

A.Enable the Key Vault firewall to allow trusted Microsoft services
B.Create a private endpoint for the SQL server to access the Key Vault
C.Enable public network access on the Key Vault
D.Assign the SQL server's managed identity the 'Reader' role on the Key Vault
AnswerA

Azure SQL Database TDE with customer-managed keys requires SQL to access Key Vault for key wrap and unwrap operations. The Key Vault firewall blocks public access, but the 'Allow trusted Microsoft services' exception lets Azure SQL's underlying service bypass the firewall for these cryptographic operations, using the SQL server's managed identity. This is the only network change needed while keeping public access blocked.

Why this answer

When Azure Key Vault has its firewall enabled to deny all public network access, it blocks all traffic, including requests from Azure SQL Database. By enabling the 'Allow trusted Microsoft services' exception, Azure Key Vault permits specific Azure platform services (like Azure SQL Database) to bypass the firewall, provided the service authenticates using a managed identity with appropriate permissions. This setting is essential for TDE with CMK because the SQL server's system-assigned managed identity must reach the Key Vault to unwrap the encryption key, even when public access is disabled.

Exam trap

The trap here is that candidates often assume a private endpoint is required for any cross-service communication when firewalls are involved, but Azure's 'Allow trusted Microsoft services' exception is a simpler, first-line configuration that enables necessary platform-level access without exposing the Key Vault to the internet.

How to eliminate wrong answers

Option B is wrong because creating a private endpoint for the SQL server to access the Key Vault would require the SQL server to initiate a connection through a private IP, but the SQL server itself does not support outbound private endpoints to Key Vault; private endpoints are configured on the Key Vault side, not the SQL server side, and the scenario already has the Key Vault firewall denying all public access, so a private endpoint on the Key Vault would be needed, but that is not listed as an option and would not resolve the immediate firewall block without the trusted services exception. Option C is wrong because enabling public network access on the Key Vault would defeat the security purpose of the firewall and is unnecessary; the trusted services exception allows the required access without exposing the Key Vault to the public internet. Option D is wrong because the 'Reader' role on the Key Vault only grants read access to the vault's metadata and secrets list, not the cryptographic permissions needed for TDE operations; the 'Key Vault Crypto Service Encryption User' role is already assigned and provides the necessary unwrap key permission, so adding 'Reader' is irrelevant.

52
MCQeasy

You need to block inbound traffic from the internet to a specific subnet except for TCP port 443. Which Azure service should you use?

A.Azure Web Application Firewall (WAF)
B.Azure Firewall
C.Network security group (NSG)
D.Azure DDoS Protection
AnswerC

A network security group is a stateful Layer 3/4 filtering component that binds directly to a subnet or network interface, allowing ordered allow and deny rules based on source/destination IP, port, and protocol. You can create a default deny rule for Internet inbound traffic and a higher-priority allow rule for the specific TCP/UDP port that must remain reachable, giving precise control over the subnet's attack surface. Because it is enforced at the subnet boundary and requires no per-application inspection overhead, this is the correct mechanism for blocking all Internet traffic except a single allowed port.

Why this answer

Network security groups (NSGs) are the correct choice because they provide stateful filtering of inbound and outbound traffic at the subnet or NIC level. By creating an inbound security rule that denies all traffic from the Internet (source 'Internet' service tag) and a higher-priority allow rule for TCP port 443, you can precisely block all inbound internet traffic except HTTPS. NSGs are the native Azure service for granular subnet-level access control lists (ACLs).

Exam trap

The trap here is that candidates often choose Azure Firewall (Option B) because it sounds like the most comprehensive security solution, but the question specifically asks for blocking inbound internet traffic to a subnet except for a single TCP port, which is a classic NSG use case—Azure Firewall is unnecessary and more expensive for this simple ACL requirement.

How to eliminate wrong answers

Option A is wrong because Azure Web Application Firewall (WAF) is designed to inspect HTTP/HTTPS traffic at the application layer (Layer 7) for web vulnerabilities (e.g., SQL injection, XSS) and does not provide general-purpose network-layer (Layer 3/4) traffic filtering to block all inbound internet traffic except a specific port. Option B is wrong because Azure Firewall is a managed, stateful firewall as a service that operates at the network and application layers, but it is overkill for a simple subnet-level ACL and incurs additional cost; NSGs are the native, cost-effective solution for this specific subnet filtering requirement. Option D is wrong because Azure DDoS Protection is a mitigation service that protects against volumetric distributed denial-of-service attacks at the network layer, not a tool for defining granular inbound traffic rules based on source, destination, and port.

53
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) to manage the 'Security Administrator' role. They want to ensure that when a user activates the role, they must provide a ticket number as justification, and the activation must be approved by a designated approver group. The role activation duration should be limited to 4 hours. Which PIM settings should be configured?

A.Enable 'Require approval' for the role and set 'Approvers' to the designated group. Also, set 'Activation maximum duration' to 4 hours.
B.Enable 'Require justification on activation' and set 'Activation maximum duration' to 4 hours. No approval configuration is needed.
C.Enable 'Require approval' and set 'Approvers' to the designated group. Also, enable 'Require ticket information on activation' and set 'Activation maximum duration' to 4 hours.
D.Enable 'Require ticket information on activation' and set 'Activation maximum duration' to 4 hours. Approval is not required because the ticket number serves as justification.
AnswerC

This is the correct configuration because it enables all three required policies in PIM: approval by the designated group, mandatory ticket information on activation, and a 4-hour maximum activation duration. Requiring ticket information ensures that every activation request includes a support ticket number, which satisfies the ticketing compliance requirement. The approval workflow with the designated group as approvers guarantees that a human approves each eligible activation before the role becomes active.

Why this answer

The scenario requires both approval and ticket-based justification. In Azure AD PIM, 'Require approval' enforces that a designated approver group must approve the activation, while 'Require ticket information on activation' ensures the user provides a ticket number as justification. Setting 'Activation maximum duration' to 4 hours limits the role activation time.

These three settings together satisfy all requirements.

Exam trap

The trap here is that candidates may confuse 'justification' with 'ticket information' and assume that enabling justification alone satisfies the ticket number requirement, or they may think that a ticket number inherently serves as approval, leading them to omit the approval configuration.

How to eliminate wrong answers

Option A is wrong because it omits the requirement for ticket information on activation; the scenario explicitly requires a ticket number as justification, not just any justification. Option B is wrong because it does not include approval configuration; the scenario requires activation to be approved by a designated approver group, which is not addressed by just enabling justification. Option D is wrong because it incorrectly assumes that a ticket number alone serves as sufficient justification and that approval is not needed; the scenario requires both a ticket number and approval from a designated group.

54
MCQeasy

Refer to the exhibit. You have a VNet with two subnets, each with a different NSG. Both NSGs have default rules. What is the default connectivity between VMs in subnetA and subnetB?

A.Traffic is blocked by default.
B.Traffic is allowed only if the VNet has peering.
C.Traffic is allowed by default.
D.Traffic is allowed only if the subnets are in the same region.
AnswerC

This statement is correct. When an NSG is associated with a subnet or NIC, Azure automatically applies default security rules; the relevant default inbound rule, AllowVnetInBound, permits any traffic from the VirtualNetwork source and destination. This rule covers all subnets in the same VNet, so intra-VNet traffic is allowed by default. To block such traffic, you must add a custom deny rule with a higher priority than the default allow rule.

Why this answer

By default, Network Security Groups (NSGs) include an inbound rule named 'AllowVNetInBound' that permits traffic from any virtual network (including peered VNets) to any destination within the VNet. Since subnetA and subnetB are both part of the same VNet, this default rule allows all traffic between VMs in these subnets, regardless of the separate NSG assignments. No additional configuration like peering is required because the subnets share the same virtual network boundary.

Exam trap

The trap here is that candidates often assume separate NSGs on different subnets automatically block traffic between them, forgetting that the default 'AllowVNetInBound' rule overrides any implicit blocking and permits all intra-VNet communication unless explicitly denied.

How to eliminate wrong answers

Option A is wrong because the default NSG rules include an explicit 'AllowVNetInBound' rule that permits all traffic within the same VNet, so traffic is not blocked by default. Option B is wrong because VNet peering is only needed for connectivity between separate VNets, not between subnets within the same VNet; the default rules already allow intra-VNet traffic. Option D is wrong because Azure subnets within the same VNet can be in different regions (a VNet is regional), but the default NSG rules allow traffic regardless of region as long as the subnets belong to the same VNet.

55
MCQhard

A company has an Azure Storage account with infrastructure encryption enabled. They configure the storage account to use customer-managed keys (CMK) stored in Azure Key Vault for encryption at rest. Despite this configuration, newly uploaded blobs are still encrypted with Microsoft-managed keys. What is the most likely cause?

A.The storage account was created before infrastructure encryption was generally available
B.The customer-managed key in Key Vault is disabled or expired
C.The storage account's encryption type is set to Microsoft-managed keys
D.The blob container has a policy that overrides the encryption setting
AnswerC

The storage account's encryption type is the explicit control that determines which key type is used for Azure Storage encryption. If the encryption type is set to 'Microsoft-managed keys', all blob data is encrypted with Microsoft-managed keys regardless of any customer-managed key configuration that may also exist in the account. To use a customer-managed key, the account must be created or updated with the encryption type set to 'Customer-managed keys' and a key must be specified in Key Vault. Since the blobs are encrypted with Microsoft-managed keys, the encryption type must be the one controlling this behavior.

Why this answer

The storage account's encryption type must be explicitly set to 'Customer-managed keys' to use CMK from Azure Key Vault. If the encryption type remains at the default 'Microsoft-managed keys', newly uploaded blobs will continue to be encrypted with Microsoft-managed keys regardless of the CMK configuration in Key Vault. Infrastructure encryption is a separate feature that encrypts data at the hardware level and does not affect the key management type.

Exam trap

The trap here is that candidates often assume that simply configuring a customer-managed key in Key Vault automatically changes the storage account's encryption type, but Azure requires an explicit configuration step to switch the encryption type from 'Microsoft-managed keys' to 'Customer-managed keys'.

How to eliminate wrong answers

Option A is wrong because infrastructure encryption is a separate feature that encrypts data at the storage infrastructure level (before the data is written to disk) and does not influence the choice between Microsoft-managed and customer-managed keys; the storage account's creation date does not prevent CMK from being applied. Option B is wrong because if the customer-managed key in Key Vault is disabled or expired, the storage account would fail to encrypt new blobs with CMK and would likely throw an error or fall back to Microsoft-managed keys only if the account is configured to allow that fallback, but the question states the blobs are still encrypted with Microsoft-managed keys without error, indicating the encryption type was never set to CMK. Option D is wrong because blob containers do not have policies that can override the storage account's encryption setting; encryption at rest is configured at the storage account level and applies to all blobs uniformly.

56
MCQmedium

You are the security administrator for a company that uses Microsoft Entra ID. You need to configure a Conditional Access policy that applies to all users except the emergency break-glass accounts. The policy must require multi-factor authentication (MFA) when accessing the Azure portal from a location that is not trusted. What should you include in the policy?

A.Include all users, exclude break-glass accounts, require MFA for Azure portal, and use 'Locations' condition to specify untrusted locations
B.Include all users, require MFA for Azure portal, and exclude all administrators
C.Include break-glass accounts, require MFA for Azure portal, and block access from untrusted locations
D.Include all users, require MFA for Azure portal, and exclude break-glass accounts
AnswerA

This configuration is correct because it precisely implements the stated requirement: the policy includes every user, explicitly excludes break-glass accounts to preserve emergency access, triggers on the Azure portal cloud app, and uses the Conditions > Locations element to scope MFA to untrusted public networks. By selecting 'Any location' except trusted IPs, the policy will prompt for MFA only when a user signs in from outside the corporate network, avoiding excessive prompts on trusted IP ranges. This matches the directive to require MFA for all users except emergency access accounts from untrusted locations.

Why this answer

It includes all users, excludes the emergency break-glass accounts to ensure they remain accessible during outages, requires MFA for the Azure portal, and uses the 'Locations' condition to target untrusted locations. This configuration aligns with the requirement to enforce MFA only when accessing Azure portal from untrusted locations, while preserving access for break-glass accounts.

Exam trap

The trap here is that candidates often forget to include the 'Locations' condition to scope the MFA requirement to untrusted locations, leading them to choose Option D which requires MFA for all Azure portal access, not just from untrusted locations.

How to eliminate wrong answers

Option B is wrong because it excludes all administrators, which is too broad and would leave administrative accounts unprotected from untrusted locations, violating the requirement to apply the policy to all users except break-glass accounts. Option C is wrong because it includes break-glass accounts, which should be excluded to maintain their availability during emergencies, and it blocks access from untrusted locations instead of requiring MFA, which is overly restrictive. Option D is wrong because it lacks the 'Locations' condition to specify untrusted locations, so the policy would require MFA for all Azure portal access regardless of location, not just from untrusted locations.

57
MCQeasy

You are designing a secure network architecture for a three-tier application. The web tier must be accessible from the internet, while the application and database tiers must only be accessible from the web tier. Which Azure service should you use to isolate the tiers most securely?

A.Azure Firewall with application rules
B.Azure Front Door with Web Application Firewall
C.Network security groups (NSGs) on subnets
D.VNet peering between tiers
AnswerC

Network security groups on subnets are the correct control because they provide stateful filtering directly within the VNet using source/destination IP, port, and protocol. By associating an NSG to the web, app, and data subnets, you can enforce explicit allow rules for the necessary traffic (e.g., web to app on port 443) and add deny rules to block all other cross-tier traffic. This is the native, no-cost technique Azure provides for network segmentation, and it operates at both subnet and NIC levels for fine-grained control.

Why this answer

Network security groups (NSGs) on subnets are the correct choice because they provide stateful, layer-3/layer-4 traffic filtering at the subnet level, allowing you to explicitly deny all inbound traffic to the application and database subnets except from the web tier's subnet or private IP range. This creates a micro-segmentation boundary that enforces the principle of least privilege without introducing additional latency or routing complexity.

Exam trap

The trap here is that candidates often choose Azure Firewall or Front Door because they associate 'security' with those services, but the question specifically asks for isolating tiers within a VNet, which is a classic network segmentation task best solved by NSGs on subnets, not by perimeter or edge security appliances.

How to eliminate wrong answers

Option A is wrong because Azure Firewall is a managed, stateful firewall service that operates at the network and application layers, but it is designed for centralized policy enforcement across multiple VNets and outbound traffic control, not for isolating tiers within a single VNet; using it for tier isolation would introduce unnecessary cost and complexity. Option B is wrong because Azure Front Door with Web Application Firewall is a global load balancer and application-layer security service that protects web applications from common exploits, but it cannot restrict traffic between internal tiers (e.g., application to database) because it operates at the internet edge, not within the VNet. Option D is wrong because VNet peering connects entire VNets and allows full IP-level connectivity between them unless further restricted by NSGs or firewalls; peering alone does not provide any traffic filtering or isolation between tiers.

58
Multi-Selecthard

Which TWO components are required to enable Azure Disk Encryption for Windows VMs using Azure Key Vault? (Choose two.)

Select 2 answers
A.Azure Key Vault with an access policy granting permissions to the Azure Disk Encryption service
B.A key encryption key (KEK) in Azure Key Vault
C.A Recovery Services vault
D.A storage account to store the encryption logs
E.The Azure Disk Encryption extension installed on the VM
AnswersA, E

Azure Disk Encryption needs the Key Vault access policy that grants the Azure Disk Encryption service principal the wrapKey, unwrapKey and get permissions, so it can read and write the key encryption keys and secrets.

Why this answer

Option A is correct because Azure Disk Encryption (ADE) for Windows VMs requires an Azure Key Vault that holds the BitLocker encryption keys (BEKs) and secrets, and the vault must have an access policy that grants the Azure Disk Encryption service principal the required permissions (key permissions such as wrapKey/unwrapKey and secret permissions such as get/set) so the ADE extension can read and write the secrets. Option E is correct because ADE is delivered as a VM extension (the AzureDiskEncryption extension for Windows, or AzureDiskEncryptionForLinux for Linux) that must be installed on the VM to perform the actual encryption of the OS and data disks. Option B is not required: a key encryption key (KEK) is an optional second layer of key protection used to wrap the BitLocker keys, not a mandatory component.

Option C is not required: a Recovery Services vault is used for Azure Backup, not for ADE key storage. Option D is not required: ADE does not need a storage account to store encryption logs; diagnostic/audit data is handled through Azure Monitor and Key Vault logging.

Exam trap

The trap is that candidates often assume a KEK is mandatory because it is commonly used, but Azure Disk Encryption works without it. Additionally, candidates may confuse the requirements with those of Azure Backup, which does require a Recovery Services vault.

59
MCQmedium

A company wants to allow external business partners to access specific SharePoint Online sites using their own corporate credentials. They do not want to manage partner accounts in their own Azure AD tenant. Which Azure AD feature should they use?

A.Azure AD B2C
B.Azure AD External Identities
C.Conditional Access
D.Privileged Identity Management
AnswerB

Azure AD External Identities (B2B collaboration) is the correct mechanism to allow external business partners access to specific SharePoint resources. It lets you invite partners who authenticate with their own organization's identity (Azure AD, SAML/WS-Fed IdP, or social identity), and they are represented as guest users in your directory. These guest accounts can be added to SharePoint sites, document libraries, or individual items through SharePoint's external sharing capabilities, with optional Conditional Access policies applied. This approach maintains your partner's home identity without requiring duplicate credentials in your tenant.

Why this answer

Azure AD External Identities (specifically B2B collaboration) allows you to invite external business partners to access your SharePoint Online sites using their own corporate credentials (their home Azure AD or identity provider). This eliminates the need to manage partner accounts in your tenant, as identities remain in their home directory and are authenticated via federation or SAML/WS-Fed protocols.

Exam trap

The trap here is confusing Azure AD B2C (customer-facing) with Azure AD External Identities B2B (business-to-business), as both involve 'external' users but serve fundamentally different scenarios and identity providers.

How to eliminate wrong answers

Option A is wrong because Azure AD B2C is designed for customer-facing applications where users sign up with social or local accounts, not for business-to-business collaboration with existing corporate identities. Option C is wrong because Conditional Access is a policy engine that enforces access controls (e.g., MFA, device compliance) on already-authenticated users, not a feature for inviting external partners or managing their identities. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role assignments for users within your own tenant, not for external partner identity federation or guest access.

60
MCQeasy

You need to assign the 'Security Administrator' role in Microsoft Entra ID to a user named User1. The role assignment must be eligible, and User1 must provide a justification when activating the role. What should you use?

A.Direct role assignment in Azure AD roles and administrators
B.Privileged Identity Management (PIM)
C.Global Administrator role with custom activation policy
D.User Administrator role with access reviews
AnswerB

Privileged Identity Management (PIM) lets you assign the Security Administrator role as 'eligible' rather than 'active'. The member then activates the role when needed, specifying a business justification and, if configured, obtains approval from designated approvers. This provides just-in-time, time-bound access with full audit logs, satisfying the requirement to assign the role securely and with least privilege.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID is the only service that supports time-bound, eligible role assignments with activation justification. By configuring a PIM policy for the Security Administrator role, you can require User1 to provide a business justification before the role is activated for a specified duration.

Exam trap

The trap here is that candidates confuse direct role assignment (which is permanent and active) with PIM's eligible assignment (which is time-bound and requires activation), leading them to choose Option A instead of B.

How to eliminate wrong answers

Option A is wrong because direct role assignment in Azure AD roles and administrators makes the role permanently active, not eligible, and does not enforce activation justification. Option C is wrong because the Global Administrator role cannot be assigned with a custom activation policy; activation policies are configured per role in PIM, not via a separate role assignment. Option D is wrong because the User Administrator role does not control activation justification for other roles; it manages user attributes and group memberships, not PIM activation policies.

61
MCQmedium

A company enables Azure Disk Encryption (ADE) on Windows virtual machines using a key encryption key (KEK) stored in Azure Key Vault. They want the KEK to be automatically rotated every 30 days to meet compliance requirements. Which Azure Key Vault feature should they enable?

A.Key rotation policy
B.Key expiration date
C.Soft-delete
D.Purge protection
AnswerA

Azure Key Vault's key rotation policy enables automatic generation of a new key version at a specified interval, such as every 30 days, without administrator intervention. For Azure Disk Encryption, this rotation re-wraps the BitLocker key encryption key (KEK) used to encrypt the disk encryption key (DEK), ensuring that the underlying data remains encrypted while the key material is refreshed. This is the correct option because it satisfies the requirement for automatic, recurring key rotation as opposed to a one-time action.

Why this answer

A key rotation policy in Azure Key Vault allows you to define automatic rotation rules for keys, including a rotation interval (e.g., every 30 days) and a rotation time window. This feature ensures that the KEK is automatically replaced with a new key version at the specified interval without manual intervention, meeting compliance requirements for periodic key rotation.

Exam trap

The trap here is that candidates often confuse key expiration (which only invalidates a key) with key rotation (which creates a new version and keeps the old one valid for a time), leading them to select 'Key expiration date' instead of 'Key rotation policy'.

How to eliminate wrong answers

Option B is wrong because a key expiration date sets a fixed end-of-life date for a key, after which it becomes invalid, but it does not automatically rotate the key; it only marks it as expired. Option C is wrong because soft-delete is a recovery feature that retains deleted keys for a configurable retention period, but it does not perform any automatic rotation of keys. Option D is wrong because purge protection prevents permanent deletion of soft-deleted keys, but it has no role in key rotation or lifecycle management.

62
MCQeasy

You are a security analyst using Microsoft Defender for Cloud. You need to ensure that any new Azure subscription added to your management group automatically receives the default security policy assignments and that security recommendations are continuously assessed. What should you enable?

A.Azure Policy initiative assignment at the management group scope.
B.Azure Arc enrollment for all servers in the subscriptions.
C.Microsoft Sentinel workspace onboarding for each subscription.
D.Microsoft Defender for Cloud auto-provisioning of the Log Analytics agent.
AnswerA

Assigning the Azure Security Benchmark or default Microsoft Defender for Cloud policy initiative at the management group scope ensures that all subscriptions within that management group inherit the policy assignments. This enables continuous assessment and automatic application of security policies to new subscriptions. It is the recommended approach for centralized governance and meets the requirement for automatic policy application.

Why this answer

To ensure that new subscriptions automatically receive security policy assignments and continuous assessment, you should assign the appropriate Azure Policy initiative (such as the Microsoft cloud security benchmark) at the management group level. Subscriptions within that management group inherit the policy, and Defender for Cloud continuously evaluates resources against the policy, providing recommendations. This centralized approach simplifies governance and ensures compliance across all subscriptions without manual intervention.

Exam trap

The trap here is assuming that enabling auto-provisioning or onboarding to Sentinel will automatically apply security policies; those features handle data collection and threat detection, not policy assignment.

63
MCQeasy

A company plans to migrate on-premises SQL Server databases to Azure SQL Managed Instance. The security team requires that all data at rest be encrypted using customer-managed keys stored in Azure Key Vault. Which feature should be enabled?

A.Row-Level Security
B.Dynamic Data Masking
C.Always Encrypted with secure enclaves
D.Transparent Data Encryption (TDE) with customer-managed keys in Azure Key Vault
AnswerD

Transparent Data Encryption (TDE) encrypts the database at rest by performing real-time I/O encryption and decryption of data and log files, using a database encryption key (DEK) that is stored in the database boot record. When customer-managed keys are used, the DEK is protected by an asymmetric key stored in Azure Key Vault, enabling the customer to control and rotate the key hierarchy. This approach directly satisfies the requirement for encrypting on-premises databases at rest with customer-managed keys in Azure Key Vault, making it the correct option.

Why this answer

Transparent Data Encryption (TDE) with customer-managed keys in Azure Key Vault is the correct choice because it encrypts the entire database at rest using a symmetric key, and the option to use customer-managed keys (CMK) in Azure Key Vault satisfies the security team's requirement for full control over encryption keys. TDE performs real-time I/O encryption and decryption of data and log files, and when combined with Azure Key Vault, it supports bring-your-own-key (BYOK) scenarios, ensuring compliance with regulatory mandates for customer-managed key storage.

Exam trap

The trap here is that candidates may confuse Always Encrypted (which encrypts specific columns and requires client-side key management) with TDE (which encrypts the entire database at rest), leading them to choose option C because they think 'customer-managed keys' implies column-level encryption, but the requirement is for all data at rest, which TDE with Azure Key Vault fulfills.

How to eliminate wrong answers

Option A is wrong because Row-Level Security (RLS) controls access to rows in a table based on user identity or context, but it does not encrypt data at rest or involve key management. Option B is wrong because Dynamic Data Masking (DDM) obfuscates sensitive data in query results to unauthorized users, but it does not encrypt the underlying data at rest and does not use customer-managed keys. Option C is wrong because Always Encrypted with secure enclaves protects sensitive data in use and in transit by encrypting columns with client-side keys, but it does not encrypt the entire database at rest and does not natively integrate with Azure Key Vault for TDE-level customer-managed key storage; it focuses on column-level encryption and computations within enclaves, not full database encryption.

64
MCQmedium

Your organization uses Azure Storage for sensitive customer data. You need to ensure that data at rest is encrypted using a customer-managed key (CMK) stored in Azure Key Vault. Additionally, you want to automatically rotate the key every 90 days. What should you configure?

A.Enable Azure Disk Encryption on the storage account and store the key in Key Vault with rotation policy.
B.Enable server-side encryption with a platform-managed key and use Azure Policy to enforce rotation.
C.Use client-side encryption with .NET client library and implement custom rotation logic.
D.Enable Azure Storage encryption with a customer-managed key and configure a key rotation policy in Azure Key Vault.
AnswerD

Azure Storage encryption with a customer-managed key (CMK) allows you to specify a key stored in Azure Key Vault, which is used for server-side encryption of all data in the storage account. By configuring a key rotation policy in Key Vault, you can automatically rotate the key version at the desired interval, and the storage service will seamlessly use the new version without any manual intervention. This meets the requirement of both using a customer-managed key and enabling automated rotation through an Azure-native policy.

Why this answer

Azure Storage encryption with a customer-managed key (CMK) allows you to use your own key stored in Azure Key Vault to encrypt data at rest. By configuring a key rotation policy in Azure Key Vault, you can automatically rotate the key every 90 days, meeting both the CMK and rotation requirements without custom code.

Exam trap

The trap here is confusing Azure Disk Encryption (for VMs) with Azure Storage encryption (for data services), leading candidates to select Option A even though it does not apply to storage accounts.

How to eliminate wrong answers

Option A is wrong because Azure Disk Encryption is used for encrypting virtual machine disks, not Azure Storage account data; it does not apply to Blob, File, Queue, or Table storage. Option B is wrong because server-side encryption with a platform-managed key uses Microsoft-managed keys, not customer-managed keys, and Azure Policy cannot enforce key rotation for platform-managed keys. Option C is wrong because client-side encryption requires custom code to manage encryption and rotation logic, which is unnecessary when Azure Storage natively supports CMK with automatic rotation via Key Vault.

65
MCQeasy

Your organization uses Microsoft Entra ID. You need to ensure that users can reset their own passwords without contacting IT. Which feature should you enable?

A.Identity Protection
B.Self-service password reset (SSPR)
C.Multifactor authentication
D.Password Protection
AnswerB

Self-service password reset (SSPR) is an Azure Active Directory (Entra ID) feature that lets users reset or unlock their own passwords without administrator intervention. When enabled, users must first register authentication methods (e.g., authenticator app, phone, or security questions), which are used to verify identity during the reset flow. Because the goal is explicitly to ensure users can reset their own passwords, SSPR is the correct control—it provides the user-facing, self-directed reset capability that the other options lack.

Why this answer

Self-service password reset (SSPR) is the correct feature because it allows users to reset their own passwords without IT intervention. SSPR integrates with Microsoft Entra ID and can be configured to require verification methods such as email, phone, or security questions before allowing a password change. This directly meets the requirement of enabling users to reset passwords independently.

Exam trap

The trap here is that candidates often confuse Multifactor Authentication (MFA) with SSPR, thinking MFA alone allows password resets, when in fact MFA is only a verification step within SSPR and does not provide the self-service reset functionality itself.

How to eliminate wrong answers

Option A is wrong because Identity Protection is a risk-based conditional access and detection tool that identifies potential vulnerabilities and suspicious sign-ins, but it does not provide password reset capabilities. Option C is wrong because Multifactor Authentication (MFA) adds an extra layer of security during sign-in but does not enable self-service password changes; it can be used as a verification method within SSPR but is not the feature itself. Option D is wrong because Password Protection is a feature that blocks weak or compromised passwords from being used in the directory, but it does not allow users to reset their own passwords.

66
MCQmedium

Refer to the exhibit. A Microsoft Sentinel analytics rule uses this KQL query. What is the primary purpose of this rule?

A.Detect users who have never signed in from the US before.
B.Detect users with multiple risky sign-ins from non-US countries.
C.Detect impossible travel patterns between the US and other countries.
D.Detect users whose sign-in count is higher than the average for their region.
AnswerB

The rule's KQL query aggregates sign-in logs where the risk level is marked as risky and the location is outside the United States, grouping results by user principal name. When the count of such events exceeds a threshold (for example, more than 3) within the 7-day evaluation period, an alert is triggered. This directly matches the stated detection intent, making it the correct description of the query's behavior.

Why this answer

The KQL query filters sign-ins with risk level 'medium' or 'high' from countries other than the US, then counts them per user and filters for users with more than one such sign-in. This directly detects users who have multiple risky sign-ins from non-US countries, making option B correct. The rule does not consider historical sign-in patterns or averages, only the count of risky sign-ins outside the US.

Exam trap

The trap here is that candidates may confuse 'risky sign-ins from non-US countries' with 'impossible travel' (option C), but impossible travel requires analyzing the time gap between geographically distant sign-ins, which this query does not do.

How to eliminate wrong answers

Option A is wrong because the query does not check whether a user has never signed in from the US; it only counts risky sign-ins from non-US countries, so a user could have signed in from the US safely and still trigger the rule if they have multiple risky sign-ins elsewhere. Option C is wrong because impossible travel requires analyzing time and location differences between consecutive sign-ins, but this query only counts risky sign-ins per user without any temporal or sequential analysis. Option D is wrong because the query does not compute an average for the user's region; it simply counts risky sign-ins from non-US countries and compares the count to 1, not to any regional average.

67
MCQmedium

A company wants Defender for Cloud to recommend fixes for container image vulnerabilities stored in Azure Container Registry. Which capability is most relevant?

A.Container vulnerability assessment in Defender for Containers
B.Azure SQL auditing
C.Microsoft Entra access reviews
D.Application Gateway rewrite rules
AnswerA

Container vulnerability assessment in Defender for Containers scans images in Azure Container Registry and surfaces findings as Defender for Cloud recommendations, satisfying the requirement to recommend fixes for registry-stored images. It assesses OS package and language dependency vulnerabilities, unlike Kubernetes runtime hardening or registry access controls.

Why this answer

Defender for Containers includes a container vulnerability assessment capability that scans container images stored in Azure Container Registry (ACR) for known vulnerabilities. This assessment integrates with Defender for Cloud to provide actionable recommendations for fixing identified vulnerabilities, directly addressing the company's requirement.

Exam trap

The trap here is that candidates may confuse general container security features (like runtime protection) with the specific vulnerability assessment capability, or mistakenly think that Azure SQL auditing or access reviews could be repurposed for image scanning.

How to eliminate wrong answers

Option B is wrong because Azure SQL auditing is a database auditing feature for tracking database events and changes, not for scanning container images for vulnerabilities. Option C is wrong because Microsoft Entra access reviews are used to manage user access rights and certifications, not for vulnerability scanning of container images. Option D is wrong because Application Gateway rewrite rules are used to modify HTTP request/response headers and URLs in web traffic, not for assessing container image security.

68
MCQmedium

You have an Azure Storage account that contains sensitive documents. You need to generate a time-limited, secure URL that allows a specific user to download a file without requiring storage account keys. What should you use?

A.Azure Front Door custom domain
B.Storage account access key
C.Shared Access Signature (SAS)
D.Azure RBAC role assignment
AnswerC

A Shared Access Signature (SAS) is URI-based delegated authorization that grants time-limited, permission-scoped access to a specific blob, container, or service. You can set an expiration time, allowed permissions (read, write, delete, etc.), and even IP restrictions if needed. This makes it the ideal way to share sensitive data securely without exposing account keys. SAS tokens are the only option here that directly produce a URL with embedded authorization for direct access.

Why this answer

A Shared Access Signature (SAS) is the correct choice because it provides delegated, time-limited access to a specific storage resource (e.g., a blob) without exposing the storage account keys. You can scope the SAS to a specific user by using a stored access policy or by generating a service SAS with fine-grained permissions, and you can enforce expiration and allowed IP ranges. This meets the requirement of a secure, time-bound URL for a single file download.

Exam trap

The trap here is that candidates often confuse RBAC (which controls access via Azure AD roles) with SAS (which generates a time-limited URL), leading them to choose RBAC because it seems more secure, but RBAC does not produce a direct download link and requires the user to have an Azure AD identity and appropriate permissions at the time of access.

How to eliminate wrong answers

Option A is wrong because Azure Front Door custom domain is a global load balancer and application delivery service; it does not generate time-limited, user-specific URLs for storage blobs. Option B is wrong because the storage account access key provides full administrative access to the entire storage account and cannot be scoped to a single file or user, nor can it be time-limited without regenerating the key. Option D is wrong because Azure RBAC role assignment controls management-plane and data-plane access via Azure AD, but it does not produce a URL; it requires the user to authenticate with Azure AD and does not provide a direct, time-limited download link.

69
MCQmedium

You configure Azure Bastion to allow secure RDP access to VMs in a VNet. However, users report that they cannot connect to a specific VM, while other VMs in the same VNet are accessible. The VM is running and has a public IP. What is the most likely cause?

A.The user does not have 'Reader' role on the VM.
B.The NSG on the VM's subnet does not allow inbound RDP from the AzureBastionSubnet.
C.The VM is located in a different region than the Bastion host.
D.The VM has a public IP assigned, which interferes with Bastion connectivity.
AnswerB

Azure Bastion injects the Bastion host into the AzureBastionSubnet, and for RDP to reach a target VM, the NSG attached to the VM's subnet must include an inbound allow rule for TCP 3389 from the address prefix of the AzureBastionSubnet. Without that rule, packets from the Bastion host are silently dropped by the target subnet's network security group, so the connection fails even if the rest of the configuration is correct. This is a common misconfiguration because users often open RDP only from the internet or their local IP, not from the Bastion subnet's private address range.

Why this answer

Azure Bastion provides secure RDP/SSH connectivity to VMs in a peered VNet without exposing public IPs. For Bastion to reach a VM, the Network Security Group (NSG) on the VM's subnet must allow inbound TCP traffic on port 3389 from the AzureBastionSubnet (which uses the Azure Bastion service's private IP range). If the NSG blocks this traffic, Bastion cannot establish the RDP session even though the VM is running and has a public IP.

The correct answer is B because the NSG misconfiguration is the most likely cause when other VMs in the same VNet are accessible.

Exam trap

The trap here is that candidates assume a public IP on the VM is the problem, but Azure Bastion explicitly bypasses public IPs and uses private IPs, so the public IP is irrelevant; the real issue is the NSG rule blocking inbound traffic from the AzureBastionSubnet.

How to eliminate wrong answers

Option A is wrong because the 'Reader' role on the VM is not required for Bastion connectivity; the user needs at least 'Reader' role on the VM, the virtual network, and the Bastion resource, but the issue is specific to a single VM, not a role assignment problem. Option C is wrong because Azure Bastion can connect to VMs in any region within the same tenant; the Bastion host and the VM do not need to be in the same region. Option D is wrong because a public IP assigned to the VM does not interfere with Bastion connectivity; Bastion uses a private IP to connect to the VM, and the public IP is simply ignored or can be removed without affecting Bastion access.

70
MCQmedium

A company has an Azure virtual network with a subnet that hosts a web application. They want to allow inbound HTTPS traffic from any source on the internet (0.0.0.0/0) and block all other inbound traffic. They associate a network security group (NSG) with the subnet. What is the minimum number of inbound security rules required to achieve this?

A.One inbound rule allowing HTTPS from Internet, and one inbound rule DenyAllInbound.
B.One inbound rule allowing HTTPS from Internet.
C.Two inbound rules: one allowing HTTPS from Internet, one allowing HTTP from Internet.
D.Two inbound rules: one allowing HTTPS from Internet, one allowing RDP from Internet.
AnswerB

An NSG's default inbound security rules include a low-priority DenyAllInbound rule at priority 65500 that blocks any traffic not matched by a higher-priority allow rule. By creating one inbound allow rule for HTTPS (TCP 443) with a priority such as 100, legitimate HTTPS traffic to the web tier is permitted while all other inbound traffic is implicitly denied. Because the default deny rule is always evaluated last, this single rule fully satisfies the requirement and no other rules are necessary.

Why this answer

An NSG includes a set of default security rules that already block all inbound traffic not explicitly allowed. By adding a single inbound rule that allows HTTPS (TCP port 443) from the Internet (0.0.0.0/0), the default deny rule (DenyAllInbound) will block all other inbound traffic. Therefore, only one custom inbound rule is required to achieve the stated goal.

Exam trap

The trap here is that candidates often forget about the default NSG rules, especially the 'DenyAllInbound' rule, and incorrectly assume they must add an explicit deny rule to block all other traffic.

How to eliminate wrong answers

Option A is wrong because it suggests adding an explicit DenyAllInbound rule, which is redundant since the default NSG rule already denies all inbound traffic not explicitly permitted. Option C is wrong because it includes an unnecessary rule allowing HTTP (TCP port 80), which is not required and would violate the requirement to block all other inbound traffic. Option D is wrong because it includes an unnecessary rule allowing RDP (TCP port 3389), which is not required and would also violate the requirement to block all other inbound traffic.

71
MCQeasy

You need to secure traffic between two VNets in different Azure regions. The VNets contain virtual machines that must communicate over private IP addresses. Which Azure service should you use?

A.Azure Firewall
B.VNet peering
C.Azure VPN Gateway
D.ExpressRoute
AnswerB

VNet peering establishes a direct, low-latency connection between two virtual networks using Microsoft's backbone infrastructure, allowing private IP addresses to communicate across regions without going through the internet or a gateway. For the requirement to secure traffic between two VNets in different Azure regions, peering provides the connectivity layer, and security can then be applied via network security groups or a firewall. Peering is the correct answer because it is the native Azure mechanism for cross-region VNet-to-VNet private IP communication.

Why this answer

VNet peering enables direct, private IP connectivity between two VNets in different Azure regions (global VNet peering). Traffic flows over the Microsoft backbone network, not the public internet, ensuring low-latency and secure communication between virtual machines using private IP addresses without requiring a gateway or additional appliance.

Exam trap

The trap here is that candidates often confuse Azure VPN Gateway (which also connects VNets) with VNet peering, but VPN Gateway uses encrypted tunnels over the internet and incurs higher latency and throughput limitations, whereas VNet peering provides direct, private, high-bandwidth connectivity over the Microsoft backbone without a gateway.

How to eliminate wrong answers

Option A is wrong because Azure Firewall is a stateful, managed firewall service used to inspect and filter traffic at the network and application layers, not to connect VNets; it would be placed inline after connectivity is established, not as the connectivity mechanism itself. Option C is wrong because Azure VPN Gateway creates encrypted tunnels over the public internet, which introduces bandwidth limits (typically 1.25 Gbps per tunnel) and higher latency compared to VNet peering, and it is not the simplest or most performant solution for private IP communication between VNets. Option D is wrong because ExpressRoute provides dedicated private connectivity from on-premises networks to Azure, not between Azure VNets; while it can be used with VNet peering for hybrid scenarios, it is not the direct service for VNet-to-VNet private IP communication.

72
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) to manage access to the 'Security Administrator' role. They want a specific user to be able to activate the role only when needed, rather than having standing access. The user should not have the role active at all times. Which type of assignment should they configure for this user in PIM?

A.Assign the user as 'Active' for the role.
B.Assign the user as 'Eligible' for the role.
C.Assign the user as 'Permanent' for the role.
D.Add the user as a 'Guest' in the directory.
AnswerB

This is the correct approach because an Eligible assignment in PIM is a dormant state where the user has no effective role permissions until they activate it through the PIM portal or API. During activation, the user can be required to supply a business justification, pass Azure AD Multi-Factor Authentication, and, if configured, receive approval from role approvers. The role then becomes active only for a limited, configurable duration, meaning privileged access exists exactly when needed and expires automatically.

Why this answer

In Azure AD Privileged Identity Management (PIM), an 'Eligible' assignment means the user does not have permanent access to the role. They must activate the role on-demand through a time-bound activation process, which may require approval and multi-factor authentication. This directly meets the requirement of having no standing access, as the role is inactive until the user explicitly activates it.

Exam trap

The trap here is confusing 'Active' (permanent standing access) with 'Eligible' (just-in-time activation), as candidates often think 'Active' means the user can activate the role, when in fact it means the role is always active.

How to eliminate wrong answers

Option A is wrong because an 'Active' assignment grants the user standing access to the role at all times, which contradicts the requirement for on-demand activation. Option C is wrong because 'Permanent' is not a valid assignment type in PIM; roles are either 'Active' (permanent) or 'Eligible' (requiring activation). Option D is wrong because adding the user as a 'Guest' in the directory does not assign any Azure AD role; it only provides external collaboration access without any privileged role permissions.

73
MCQhard

An Application Gateway WAF blocks legitimate requests because a managed rule detects a known false positive. The team wants to keep the rule set enabled. What should they configure?

A.A narrowly scoped WAF exclusion for the affected variable or rule
B.Disable WAF prevention mode for the entire gateway
C.Remove TLS from the listener
D.Move the application behind an internal load balancer only
AnswerA

A narrowly scoped WAF exclusion is the correct approach because it creates a targeted exception for a specific rule or rule set and specific request attribute (such as a header, cookie, or query string parameter) that is causing the false positive. This preserves deep inspection and blocking across all other traffic, ensuring the WAF still mitigates real attacks while allowing the legitimate request to pass. Microsoft's documentation recommends precisely this kind of exclusion to reduce false positives without weakening the overall security posture.

Why this answer

A narrowly scoped WAF exclusion is the correct approach because it allows the team to keep the managed rule set enabled while preventing false positives. By configuring an exclusion for the specific variable (e.g., RequestHeaderNames, RequestCookieNames, RequestArgNames) or rule ID that triggers the false positive, the WAF will skip inspection on that particular element without weakening the overall security posture. This maintains protection against other threats while resolving the blocking of legitimate traffic.

Exam trap

The trap here is that candidates may think disabling prevention mode or removing TLS is a quick fix, but the correct solution requires a precise, rule-level exclusion to maintain security while addressing the false positive.

How to eliminate wrong answers

Option B is wrong because disabling WAF prevention mode for the entire gateway would switch the WAF to detection mode only, which logs alerts but does not block any malicious traffic, thereby removing protection entirely instead of targeting the false positive. Option C is wrong because removing TLS from the listener would expose traffic in plaintext, breaking encryption requirements and not addressing the WAF rule false positive issue. Option D is wrong because moving the application behind an internal load balancer only would restrict access to internal networks, which does not resolve the WAF false positive and may not be suitable for internet-facing applications.

74
MCQmedium

A company has a hub-and-spoke network topology in Azure. The hub virtual network contains an Azure Firewall and a VPN gateway. Spoke virtual networks are peered to the hub. The security team wants to ensure that all outbound internet traffic from VMs in the spokes flows through the Azure Firewall. What should be configured?

A.Create a route table with a default route (0.0.0.0/0) to the Azure Firewall private IP and associate it with the spoke subnets.
B.Configure forced tunneling on the VPN gateway to route all traffic through the Azure Firewall.
C.Create a route table with a default route to the VPN gateway and associate it with the hub subnet.
D.Configure an NSG on the spoke subnets with a rule that sends traffic to the Azure Firewall.
AnswerA

In a hub-and-spoke topology, the correct way to force all outbound internet traffic from spoke VMs through an Azure Firewall is to create a route table with a 0.0.0.0/0 route whose next hop is set to the firewall's private IP address, then associate that route table with each spoke subnet. This UDR overrides the default system route for internet traffic, and because the spoke VNet is peered to the hub, packets can reach the firewall through the peering. Additionally, the firewall must be configured with its own allow rules and SNAT so replies return symmetrically to avoid asymmetric routing.

Why this answer

To force all outbound internet traffic from spoke VNets through the Azure Firewall, you must create a route table with a default route (0.0.0.0/0) that has the Azure Firewall's private IP as the next hop, and associate that route table with the subnets in the spoke VNets. This overrides the default system route and sends all internet-bound traffic to the firewall. Option B is wrong because forced tunneling on a VPN gateway is used to route on-premises traffic, not to direct spoke traffic through the firewall.

Option C is wrong because the route table should be associated with spoke subnets, not the hub subnet. Option D is wrong because NSGs do not support next-hop routing; they filter traffic, not direct it.

75
MCQeasy

You need to ensure that Azure SQL Database connections are encrypted and the server's identity is verified. Which connection string parameter should be required?

A.Encrypt=Optional
B.Encrypt=True; TrustServerCertificate=False
C.TrustServerCertificate=True
D.Encrypt=False
AnswerB

This is the correct configuration for Azure SQL Database. Encrypt=True forces the client to use TLS for all data sent over the network, while TrustServerCertificate=False requires the client to validate the server's TLS certificate against a trusted root CA. Azure SQL Database's certificate chains are issued from trusted public CAs, so validation succeeds and the connection is both encrypted and protected against man-in-the-middle attacks.

Why this answer

Setting `Encrypt=True` forces TLS encryption for all data in transit between the client and Azure SQL Database, while `TrustServerCertificate=False` ensures that the server's TLS certificate is validated against a trusted certificate authority (CA). This combination provides both encryption and server identity verification, which is required for secure connections to Azure SQL Database.

Exam trap

The trap here is that candidates often assume `TrustServerCertificate=True` is sufficient for security, not realizing that it disables server identity verification, which is a critical component of a secure TLS connection.

How to eliminate wrong answers

Option A is wrong because `Encrypt=Optional` allows the client to connect without encryption if the server does not enforce it, which does not guarantee encryption. Option C is wrong because `TrustServerCertificate=True` bypasses certificate chain validation, meaning the server's identity is not verified, even if encryption is enabled. Option D is wrong because `Encrypt=False` disables encryption entirely, leaving the connection vulnerable to eavesdropping and man-in-the-middle attacks.

Page 1 of 9

Page 2

All pages