Courseiva

Microsoft Azure Security Engineer Associate AZ-500 (AZ-500) — Questions 76–150

617 questions total · 9pages · All types, answers revealed

Page 1

Page 2 of 9

Page 3
76
MCQmedium

Your organization uses Azure Storage accounts with blob containers. You need to ensure that only authorized applications can access the storage account, without using shared keys or shared access signatures. What should you configure?

A.Use a stored access policy with a shared access signature
B.Configure a firewall on the storage account to allow only the application's IP address
C.Enable a private endpoint for the storage account
D.Use Azure AD authentication with managed identities
AnswerD

Azure AD authentication with managed identities assigns an automatically managed service principal to the compute resource, and the SDK obtains an OAuth 2.0 token from Azure Instance Metadata Service without storing any secrets. The identity is then mapped to Azure RBAC roles such as Storage Blob Data Contributor/Reader, providing granular, revocable access. This eliminates shared-key management and clearly ties each request to an application identity, aligning with the requirement to authenticate without managing credentials.

Why this answer

Azure AD authentication with managed identities allows applications to authenticate to Azure Storage without using shared keys or SAS tokens. Managed identities provide an automatically managed identity in Azure AD, enabling applications to use OAuth 2.0 tokens for secure access to storage accounts. This approach eliminates the need for any shared secrets or keys, meeting the requirement exactly.

Exam trap

The trap here is that candidates often confuse network-level controls (firewall or private endpoint) with authentication mechanisms, mistakenly believing that restricting network access alone satisfies the requirement to avoid shared keys or SAS.

How to eliminate wrong answers

Option A is wrong because a stored access policy with a shared access signature still uses a SAS token, which is a shared key-based mechanism and does not eliminate the use of shared keys. Option B is wrong because configuring a firewall on the storage account to allow only the application's IP address does not authenticate the application; it only restricts network access and still requires shared keys or SAS for authorization. Option C is wrong because enabling a private endpoint ensures private network connectivity but does not replace the need for authentication; the application still requires shared keys, SAS, or Azure AD credentials to access the storage account.

77
MCQmedium

An application hosted on an Azure VM needs to read secrets from Key Vault without storing credentials. Which identity pattern should be used?

A.System-assigned managed identity with Key Vault access granted by RBAC or access policy
B.Client secret stored in appsettings.json
C.Shared access signature stored as an environment variable
D.A user account excluded from MFA
AnswerA

A system-assigned managed identity is the correct choice because Azure automatically provisions a service principal for the VM, and the application can obtain an Azure AD token through the instance metadata service (IMDS) without storing any credentials in code or configuration. Key Vault access is then granted to that identity via either Azure RBAC (for example, the Key Vault Secrets User role) or a legacy vault access policy, enabling the VM to read secrets securely and with automatic credential rotation managed by Azure.

Why this answer

A system-assigned managed identity enables an Azure VM to authenticate to Azure Key Vault without storing any credentials in code or configuration. Azure automatically creates a service principal for the VM in Azure AD, and the VM can obtain an access token from the Azure Instance Metadata Service (IMDS) endpoint (169.254.169.254) to authenticate to Key Vault. Access to secrets is then controlled by assigning RBAC roles (e.g., Key Vault Secrets User) or configuring a Key Vault access policy for that identity, eliminating the need for any stored secrets.

Exam trap

The trap here is that candidates may confuse managed identities with other credential-based patterns (like client secrets or SAS tokens) and fail to recognize that the question explicitly requires 'without storing credentials,' which only a managed identity satisfies.

How to eliminate wrong answers

Option B is wrong because storing a client secret in appsettings.json directly violates the requirement of not storing credentials; it introduces a security risk of secret exposure in configuration files. Option C is wrong because a shared access signature (SAS) is used for delegating access to Azure Storage resources, not for authenticating to Key Vault, and storing it as an environment variable still requires managing a credential. Option D is wrong because a user account excluded from MFA does not provide an identity pattern for a VM to access Key Vault; it is a human identity that would require interactive sign-in and credential storage, and excluding MFA weakens security without solving the credential storage problem.

78
MCQeasy

A security analyst uses Microsoft Defender for Cloud. They need to view the current compliance status of their Azure subscription against the Payment Card Industry Data Security Standard (PCI DSS). Which feature in Defender for Cloud should they use?

A.Security posture dashboard
B.Regulatory compliance dashboard
C.Vulnerability assessment solutions
D.Workflow automation
AnswerB

The regulatory compliance dashboard in Defender for Cloud is specifically designed to display your environment's alignment with industry standards and regulatory frameworks, such as PCI DSS, SOC 2, ISO 27001, and Azure CIS. It continuously evaluates Azure Policy initiatives and maps discovered assessments to individual controls within each standard, showing pass/fail status per control and providing a detailed view of recommendations and affected resources. This makes it the correct tool for an analyst seeking to track compliance against a specific regulatory standard, unlike the other options which focus on security posture, vulnerabilities, or automation.

Why this answer

The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built view of your Azure subscription's compliance posture against specific standards like PCI DSS. It continuously assesses your resources against the controls defined in the selected compliance framework and displays a compliance score, passed/failed controls, and remediation steps. This is the dedicated feature for tracking regulatory compliance, not general security posture or vulnerability management.

Exam trap

The trap here is that candidates confuse the general Security posture dashboard (which shows a security score) with the Regulatory compliance dashboard, which is the only place to see compliance against specific standards like PCI DSS, SOC 2, or ISO 27001.

How to eliminate wrong answers

Option A is wrong because the Security posture dashboard shows an overall security score based on security recommendations, but it does not map to specific regulatory frameworks like PCI DSS. Option C is wrong because Vulnerability assessment solutions (e.g., integrated Qualys or Microsoft Defender Vulnerability Management) focus on identifying software vulnerabilities in VMs and containers, not on compliance with regulatory standards. Option D is wrong because Workflow automation is used to trigger automated responses (e.g., sending notifications or creating tickets) based on security alerts or recommendations, not to view compliance status.

79
MCQeasy

You need to securely connect an on-premises network to Azure over the internet with encrypted traffic. The connection must be site-to-site and use IPsec. Which Azure service should you use?

A.Azure VPN Gateway
B.Azure ExpressRoute
C.Azure Virtual WAN
D.Azure Bastion
AnswerA

Azure VPN Gateway provides site-to-site connectivity over the public internet using IPsec/IKE encryption, terminating tunnels between on-premises VPN devices and the Azure virtual network gateway. This directly satisfies the encrypted, internet-based site-to-site IPsec requirement without dedicated private circuits.

Why this answer

Azure VPN Gateway supports site-to-site (S2S) VPN connections over the internet using IPsec/IKE (IKEv1 or IKEv2) to encrypt traffic between an on-premises VPN device and Azure. This matches the requirement for an encrypted, internet-based site-to-site connection. ExpressRoute bypasses the internet entirely, Virtual WAN is a higher-level orchestration service that still relies on VPN Gateway for S2S IPsec, and Bastion is for RDP/SSH access to VMs without public IPs.

Exam trap

The trap here is that candidates confuse Azure Virtual WAN as a direct replacement for VPN Gateway, but Virtual WAN still requires VPN Gateway instances for S2S IPsec termination and is an orchestration/management layer, not the underlying connectivity service.

How to eliminate wrong answers

Option B (Azure ExpressRoute) is wrong because it provides a private, dedicated connection that does not traverse the internet and does not use IPsec by default; it is designed for high-bandwidth, low-latency scenarios, not encrypted internet-based S2S. Option C (Azure Virtual WAN) is wrong because it is a managed networking service that can aggregate multiple VPN connections, but the actual S2S IPsec termination is still performed by a VPN Gateway instance within the Virtual WAN hub; the question asks for the specific service, not the orchestration layer. Option D (Azure Bastion) is wrong because it is a PaaS service for secure RDP/SSH access to Azure VMs via TLS, not for site-to-site IPsec VPN connectivity.

80
MCQmedium

A security team uses Microsoft Sentinel. They want to detect a potential privilege escalation scenario: when a user is added to the Global Administrator role in Azure AD (audit log) and within 10 minutes that user signs in from a suspicious location (sign-in log). Which type of analytics rule should they create to correlate these two different log sources?

A.Fusion rule
B.Scheduled query rule
C.Anomaly rule
D.NRT rule (Near Real-Time)
AnswerB

Scheduled query rules are the correct choice because they let you author custom KQL queries that join multiple tables such as SecurityEvent, SigninLogs, and CommonSecurityLog to correlate events across data sources. By setting a query schedule and alert logic, you can precisely define the multi-source correlation the security team needs.

Why this answer

A scheduled query rule is the correct choice because it allows you to define a KQL query that joins the AuditLogs table (for role assignment events) with the SigninLogs table (for sign-in events) and then uses a time window (e.g., 10 minutes) to correlate the two disparate log sources. This rule type supports cross-table joins and custom time-based correlation, which is exactly what is needed to detect a user added to Global Administrator followed by a suspicious sign-in.

Exam trap

The trap here is that candidates confuse Fusion rules (which correlate alerts) with the need to correlate raw log entries, or they mistakenly think NRT rules can handle multi-table joins with custom time windows, when in fact only scheduled query rules provide the necessary KQL flexibility for this scenario.

How to eliminate wrong answers

Option A is wrong because Fusion rules use machine learning to correlate multiple alerts from different security products, not to join raw audit and sign-in logs with a custom time window. Option C is wrong because Anomaly rules are designed to detect unusual patterns in a single data source using baselines, not to correlate two different log sources with a specific temporal condition. Option D is wrong because NRT (Near Real-Time) rules run every minute but do not support cross-table joins or custom time windows longer than a few minutes; they are intended for single-table, low-latency detection.

81
MCQmedium

Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel. What is the purpose of this query?

A.To list all alerts with severity 'High' in the last 7 days.
B.To list the top 10 most frequent alert names along with their severity over the last 7 days.
C.To list all alerts generated in the last 7 days.
D.To list the count of alerts per severity for the last 7 days.
AnswerB

The query groups alert records by AlertName and Severity using summarize, counts the occurrences in each combination, and applies top to rank those combinations descending by count. This returns the ten most frequent alert-name/severity pairs over the rolling 7-day window, which precisely matches the stated purpose. The inclusion of both fields in the grouping key is essential to the output.

Why this answer

The KQL query uses the `summarize` operator to group alerts by `AlertName` and `Severity`, then sorts by `count_` in descending order and takes the top 10 results. This produces a list of the 10 most frequent alert names along with their severity over the last 7 days, matching option B.

Exam trap

The trap here is that candidates often confuse aggregation (`summarize`) with filtering or listing, leading them to choose options that describe simple filtering (A, C) or a different aggregation (D) instead of recognizing the top-N grouping by alert name and severity.

How to eliminate wrong answers

Option A is wrong because the query does not filter by severity 'High'; it includes all severities and summarizes counts. Option C is wrong because the query does not list all alerts individually; it aggregates them using `summarize` and limits output to the top 10. Option D is wrong because the query groups by `AlertName` and `Severity`, not by severity alone, and it returns the top 10 alert names, not a count per severity.

82
MCQeasy

Your organization uses Microsoft Entra ID to manage identities. You need to ensure that users can reset their own passwords without help desk intervention, but they must register for self-service password reset (SSPR) first. Which configuration is required?

A.Configure Microsoft Entra Password Protection
B.Enable Privileged Identity Management for SSPR
C.Enable SSPR and set the registration campaign to require registration at next sign-in
D.Enable combined registration for SSPR and Microsoft Entra ID Protection
AnswerC

Self-Service Password Reset requires users to first register authentication methods — such as phone numbers, the Microsoft Authenticator app, or email addresses — so those methods can be challenged during reset. By enabling SSPR and setting the registration campaign to require registration at next sign-in, the directory ensures users are prompted to register before they need a reset, which is the critical success factor for SSPR adoption. This is the correct configuration because an SSPR policy is meaningless if users have no registered methods to verify their identity.

Why this answer

Enabling SSPR and configuring the registration campaign to require registration at next sign-in ensures users must register for SSPR before they can reset their own passwords. This satisfies the requirement that users register first, and the registration campaign enforces this without requiring help desk intervention.

Exam trap

The trap here is that candidates often confuse enabling SSPR with enforcing registration, or mistakenly think that combined registration or PIM automatically requires registration, when in fact only the registration campaign configuration forces the user to register before using SSPR.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Password Protection is a feature that detects and blocks weak passwords, not a mechanism to enforce SSPR registration or enable self-service password reset. Option B is wrong because Privileged Identity Management (PIM) is designed for just-in-time privileged access management, not for configuring or enforcing SSPR registration for all users. Option D is wrong because combined registration for SSPR and Microsoft Entra ID Protection allows users to register for both services simultaneously, but it does not enforce that users must register before they can reset their passwords; it only provides a unified registration experience.

83
Multi-Selectmedium

You are designing a backup strategy for Azure virtual machines. You need to ensure that backups are encrypted at rest and can be restored in a different Azure region in case of a regional disaster. Which two configurations should you use?

Select 2 answers
A.Configure Azure Site Recovery for the VMs
B.Enable encryption at rest for the Recovery Services vault using platform-managed keys
C.Enable Cross-Region Restore (CRR) for the Recovery Services vault
D.Enable Azure Disk Encryption on the VMs
E.Use geo-redundant storage (GRS) for the Recovery Services vault
AnswersB, C

Azure Backup automatically encrypts all backup data at rest in the Recovery Services vault using Storage Service Encryption (SSE), which by default is enforced with platform-managed keys. Enabling or confirming this default protects vaulted recovery points from storage-layer threats and unauthorized physical access without requiring you to manage key lifecycle. This is a foundational security control in any backup strategy, though it does not by itself address availability or regional resilience, which is handled separately by features like Cross-Region Restore.

Why this answer

Enabling encryption at rest for the Recovery Services vault using platform-managed keys ensures that backup data is encrypted when stored in Azure's storage layer. This is a default encryption mechanism that protects data at rest without requiring additional key management overhead. Option C is correct because Cross-Region Restore (CRR) allows you to restore backup data to a paired Azure region, providing disaster recovery capability if the primary region fails.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (disaster recovery) with backup services, or assume that enabling GRS alone allows cross-region restores, when in fact CRR is a separate configuration that must be explicitly enabled.

84
MCQmedium

Your company uses Microsoft Sentinel to monitor Azure resources. A new analytics rule is created to detect anomalous access to storage accounts. The rule runs every 5 minutes and looks at the last 15 minutes of data. After deploying, the rule generates no alerts even though you suspect there are anomalies. What is the most likely issue?

A.The rule is not enabled.
B.The rule query logic is incorrect or the entities are not properly mapped.
C.The rule severity is set too low.
D.The rule query frequency is longer than the data lookback period.
AnswerB

For a scheduled analytics rule, an alert is only created when the KQL query returns at least one row. The most common reason for silence is that the query contains incorrect logic—such as referencing a non-existent table, filtering on misspelled columns, or using a where clause that never evaluates to true—which results in zero matching records. Improper entity mapping does not directly prevent alert generation, but it can cause alerts to lack the required entity fields, which may interfere with incident creation and automation, making it appear as though the rule is failing.

Why this answer

The most likely issue is that the rule query logic is incorrect or the entities are not properly mapped. In Microsoft Sentinel, an analytics rule uses a KQL query to detect anomalies; if the query syntax is wrong, the logic fails to match the expected data patterns, or the entity mappings (e.g., Account, IP, Host) are misconfigured, the rule will not generate alerts even when anomalous activity exists. Without correct entity mapping, the rule cannot correlate events or trigger incidents, resulting in zero alerts despite underlying anomalies.

Exam trap

The trap here is that candidates often assume a rule's frequency or lookback period is the root cause, but Microsoft Sentinel allows the frequency to be shorter than the lookback period (e.g., 5 min frequency with 15 min lookback) to enable sliding window analysis; the real issue is almost always incorrect query logic or missing entity mappings.

How to eliminate wrong answers

Option A is wrong because if the rule were not enabled, it would not run at all, but the question states the rule is deployed and runs every 5 minutes, implying it is enabled. Option C is wrong because rule severity (e.g., Low, Medium, High) only affects the classification of alerts once generated, not whether alerts are generated in the first place; a low severity rule still produces alerts. Option D is wrong because the rule query frequency (5 minutes) being shorter than the data lookback period (15 minutes) is actually a valid and common configuration—it allows the rule to re-evaluate overlapping windows of data; this does not prevent alert generation.

85
MCQeasy

A company has a virtual network with a subnet hosting Azure VMs. They want to restrict all inbound traffic to only allow HTTPS (port 443) from the internet, but also allow SSH (port 22) only from a specific management IP address range (e.g., 203.0.113.0/24). Which Azure service should they use to achieve this filtering?

A.Azure Firewall
B.Network Security Group (NSG) rule
C.Azure DDoS Protection
D.Azure Bastion
AnswerB

An NSG rule provides stateful, Layer 4 packet filtering directly at the subnet or network interface level. You can create an inbound rule to allow HTTPS (443) from 'Any' source and a separate rule to allow SSH (22) only from your specific management IP range, blocking all other unsolicited inbound traffic. This is the simplest, most cost-effective solution for basic port-and-source filtering on a single subnet, as it requires no additional routing or virtual appliances. NSGs are enforced by the Azure network stack, and each rule is evaluated in priority order, giving you precise control over permitted traffic.

Why this answer

A Network Security Group (NSG) rule is the correct choice because NSGs provide stateful, granular inbound and outbound filtering at the subnet or NIC level. You can create a rule to allow HTTPS (TCP/443) from any source (Internet) and a separate rule to allow SSH (TCP/22) only from the specific management IP range 203.0.113.0/24, while implicitly denying all other inbound traffic. NSGs are the native Azure service for this type of traffic filtering and do not require additional cost or deployment.

Exam trap

The trap here is that candidates often choose Azure Firewall because they think it is required for any IP-based filtering, but NSGs are the correct and simpler service for subnet-level inbound port and source IP filtering without needing a centralized firewall appliance.

How to eliminate wrong answers

Option A is wrong because Azure Firewall is a managed, centralized network security service used for advanced filtering across multiple VNets, outbound traffic inspection, and application rules, but it is overkill and more expensive for simple inbound port filtering on a single subnet; NSGs are the appropriate and simpler solution. Option C is wrong because Azure DDoS Protection is designed to protect against volumetric distributed denial-of-service attacks at the network layer, not to filter specific ports or IP addresses for legitimate traffic. Option D is wrong because Azure Bastion provides secure, browser-based RDP/SSH connectivity to VMs without exposing public IPs, but it does not filter inbound traffic to VMs; it replaces the need for SSH/RDP exposure entirely.

86
MCQhard

You are troubleshooting connectivity between two Azure VMs in the same virtual network. VM1 can ping VM2, but VM1's application cannot connect to VM2's application on port 8080. Both VMs have NSGs that allow inbound traffic on port 8080. What is the most likely cause?

A.The VNet is peered with another VNet that has a conflicting address space.
B.An Azure Load Balancer is directing traffic away from VM2.
C.The NSG on VM2's subnet has a deny rule for port 8080.
D.The guest OS firewall on VM2 is blocking inbound port 8080.
AnswerD

The guest OS firewall on VM2 is a host-based firewall that filters traffic after the NSG has already permitted it and after the packet arrives at the virtual NIC. Even when network security groups explicitly allow port 8080, the OS firewall can still drop or reject the connection if there is no matching inbound allow rule or if an active deny rule is present. This is a common cause of 'connection refused' or timeout when all Azure network-level controls appear correct, making it the correct answer.

Why this answer

Since ICMP (ping) succeeds between the VMs, the network path is functional at Layer 3, and the NSGs are allowing traffic (as stated). The application failure on a specific port (8080) while ICMP works strongly indicates a host-level firewall blocking the TCP connection. The guest OS firewall (e.g., Windows Firewall or iptables) on VM2 is the most likely cause because it operates independently of Azure NSGs and can filter traffic by port and protocol, even when NSGs permit it.

Exam trap

The trap here is that candidates assume NSG rules are the only firewall layer in Azure, overlooking the guest OS firewall which operates independently and can block application traffic even when NSGs permit it.

How to eliminate wrong answers

Option A is wrong because VNet peering with a conflicting address space would cause routing issues for all traffic, not just a specific port; ping would also fail. Option B is wrong because an Azure Load Balancer only affects traffic destined for its frontend IP and load-balancing rules; it does not intercept direct VM-to-VM traffic within the same VNet unless explicitly configured with a backend pool and rule for that traffic. Option C is wrong because the question explicitly states that both VMs have NSGs allowing inbound traffic on port 8080; a subnet NSG deny rule would contradict that statement and would also block ICMP if it were a general deny, but ping works.

87
MCQeasy

You have an Azure virtual machine that hosts a custom web application. You need to restrict inbound internet traffic to only HTTPS (port 443) from any source. Which Azure resource should you configure?

A.Application Security Group (ASG)
B.Azure Bastion
C.Azure Firewall
D.Network Security Group (NSG)
AnswerD

A Network Security Group (NSG) is a stateful traffic-filtering resource that you can associate with a virtual machine's NIC or a virtual network subnet to allow or deny inbound and outbound traffic based on rules. To allow HTTPS from the Internet to your custom web app, you would add an inbound security rule with source set to 'Internet', destination set to the VM's IP (or its NIC/ASG), protocol set to TCP, and destination port set to 443. NSGs are the correct and simplest resource for this scenario because they enforce security rules directly at the network interface or subnet level, blocking any traffic that does not match an explicit allow rule. This is why NSG is the correct answer.

Why this answer

A Network Security Group (NSG) is the correct choice because it acts as a distributed, stateful firewall that filters inbound and outbound traffic at the subnet or network interface level. By creating an inbound security rule allowing TCP port 443 from any source (0.0.0.0/0) and denying all other inbound traffic, you can restrict internet traffic to HTTPS only. NSGs are the native Azure resource for controlling network traffic to VMs without additional cost or complexity.

Exam trap

The trap here is that candidates often confuse Azure Firewall with NSGs, thinking a full firewall is required for any traffic filtering, but for simple port-based restrictions on a single VM, an NSG is the correct and cost-effective choice.

How to eliminate wrong answers

Option A is wrong because an Application Security Group (ASG) is a logical grouping of VMs based on application roles, not a firewall; it is used in conjunction with NSG rules to define traffic flows between groups, but it cannot itself filter or restrict inbound internet traffic. Option B is wrong because Azure Bastion provides secure RDP/SSH connectivity to VMs over HTTPS, but it is not designed to filter general inbound web traffic; it only tunnels management protocols and does not block or allow arbitrary port 443 traffic from the internet. Option C is wrong because Azure Firewall is a managed, stateful firewall as a service that can filter traffic, but it is overkill for a single VM and incurs additional cost; an NSG is the simpler, more appropriate resource for this specific requirement.

88
MCQhard

A security team uses Microsoft Defender for Cloud to protect Azure virtual machines. They want to implement application allowlisting to prevent execution of unauthorized software on a set of Windows Server VMs. They need to create a baseline of allowed applications and then enforce the allowlist. Which Defender for Cloud feature should they enable?

A.Adaptive application controls
B.Just-in-time VM access
C.File integrity monitoring
D.Adaptive network hardening
AnswerA

Adaptive application controls is correct because Defender for Cloud builds a machine-learning baseline of known-good executables, scripts, and installation processes running on your VMs, then lets you enforce an allowlist that prevents unknown or untrusted binaries from launching. It can run in audit mode to detect suspicious execution or enforce mode to actively block it, making it the only option here that governs application execution itself.

Why this answer

Adaptive application controls (AAC) in Microsoft Defender for Cloud is the correct feature because it specifically provides application allowlisting for Azure VMs. AAC uses machine learning to analyze processes running on a VM, generate a baseline of allowed applications, and then enforce that allowlist by blocking execution of any unauthorized software. This directly meets the requirement to create a baseline and enforce it on Windows Server VMs.

Exam trap

The trap here is that candidates often confuse adaptive application controls with file integrity monitoring, thinking both prevent unauthorized software, but FIM only detects changes after the fact and does not block execution.

How to eliminate wrong answers

Option B (Just-in-time VM access) is wrong because it controls network access to management ports (e.g., RDP, SSH) by locking down inbound traffic, not application execution on the VM. Option C (File integrity monitoring) is wrong because it monitors changes to critical files, registry keys, and software installations, but it does not block unauthorized software execution—it only alerts on changes. Option D (Adaptive network hardening) is wrong because it recommends and enforces network security group (NSG) rules based on traffic patterns, not application-level allowlisting on the VM.

89
Multi-Selectmedium

Which TWO actions should you take to implement a zero-trust identity model using Microsoft Entra ID? (Choose two.)

Select 2 answers
A.Configure password expiration policies to force frequent changes
B.Enable password hash synchronization to Azure AD
C.Configure Privileged Identity Management to require approval for role activation
D.Assign permanent Global Administrator roles to IT staff
E.Implement Conditional Access policies that require MFA and device compliance
AnswersC, E

Configuring Privileged Identity Management (PIM) to require approval for role activation enforces just-in-time (JIT) access, a core zero-trust tenet. With PIM, a role is eligible but not active; the user must request activation for a specific time window, and an approver must grant it, which limits standing privileges and reduces the attack surface. This also provides auditing and time-bound access, ensuring that privileged roles are never permanently available and that every activation is specifically authorized. This aligns with 'use least privilege access' and 'verify explicitly' because the approval step adds an explicit verification of requestor legitimacy.

Why this answer

Privileged Identity Management (PIM) enforces just-in-time (JIT) access by requiring approval for role activation, which aligns with the zero-trust principle of 'never trust, always verify' by eliminating standing privileges. Option E is correct because Conditional Access policies that require MFA and device compliance enforce continuous verification of user identity and device health before granting access, a core tenet of zero-trust identity.

Exam trap

The trap here is that candidates often confuse password hash synchronization (a hybrid sync tool) with a security control, or they mistakenly think password expiration policies are still a recommended zero-trust practice, when in fact zero-trust focuses on real-time verification and risk-based policies rather than static password rotation.

90
MCQmedium

A company has an Azure virtual network with a subnet hosting web servers. The security policy requires that all inbound HTTP traffic must be sourced from a specific IP address range (203.0.113.0/24). All other inbound traffic must be denied. The subnet is associated with a network security group (NSG). Which set of inbound rules should they configure?

A.Allow HTTP from 203.0.113.0/24 (priority 100), then Deny all inbound (priority 200)
B.Deny all inbound (priority 100), then Allow HTTP from 203.0.113.0/24 (priority 200)
C.Allow HTTP from any (priority 100), then Deny all inbound (priority 200)
D.Only Allow HTTP from 203.0.113.0/24 (priority 100) with no explicit deny
AnswerA

This rule set works because NSG rules are processed in ascending priority order, and a lower numeric priority (100) is evaluated before a higher one (200). The specific allow rule for HTTP from 203.0.113.0/24 is matched first, permitting only that source and port, after which the deny-all rule at priority 200 blocks any inbound traffic that did not match the earlier allow. Critically, Azure's default inbound rules (AllowVnetInBound and AllowAzureLoadBalancerInBound) remain in effect unless explicitly denied, so the explicit deny-all is necessary to close those implicit allowances and enforce a true allowlist. The ordering ensures the desired traffic is accepted before the catch-all deny blocks everything else.

Why this answer

NSG rules are evaluated in priority order (lowest number first). The Allow rule for HTTP from 203.0.113.0/24 at priority 100 permits the desired traffic, and the subsequent Deny all inbound rule at priority 200 blocks all other traffic, including HTTP from any other source. This satisfies the security policy of allowing only HTTP from the specified IP range and denying everything else.

Exam trap

The trap here is that candidates often think a single Allow rule with no explicit Deny is sufficient, forgetting that NSGs have default implicit allow rules (e.g., AllowVNetInBound) that would permit other traffic unless explicitly denied.

How to eliminate wrong answers

Option B is wrong because the Deny all inbound rule at priority 100 would block all traffic, including HTTP from 203.0.113.0/24, before the Allow rule at priority 200 is evaluated, resulting in no allowed traffic. Option C is wrong because allowing HTTP from any source at priority 100 permits inbound HTTP traffic from all IP addresses, violating the policy that restricts HTTP to only the 203.0.113.0/24 range. Option D is wrong because without an explicit Deny all inbound rule, any traffic not matching the Allow rule (e.g., HTTP from other IPs or other protocols) would be implicitly allowed by the default NSG rules, failing to deny all other inbound traffic as required.

91
Multi-Selectmedium

Your organization uses Microsoft Entra ID and wants to implement a secure passwordless authentication strategy. Which TWO solutions can be used natively in Microsoft Entra ID for passwordless sign-in?

Select 2 answers
A.FIDO2 security keys
B.Microsoft Authenticator app with OTP
C.Third-party password managers
D.Windows Hello for Business
E.Duo Security push notifications
AnswersA, D

FIDO2 security keys are a natively supported passwordless authentication method in Microsoft Entra ID. They use public-key cryptography via the WebAuthn/CTAP2 protocol, where the private key never leaves the hardware key and the public key is registered with the tenant. Because sign-in requires a user gesture (e.g., PIN or touch) and the key's cryptographic assertion is tied to the specific site, it is phishing-resistant and does not require a password.

Why this answer

FIDO2 security keys are a native passwordless authentication method in Microsoft Entra ID, leveraging the WebAuthn standard to provide phishing-resistant, hardware-based credential verification. They eliminate passwords entirely by using public-key cryptography, where the private key never leaves the device, ensuring strong security against credential theft.

Exam trap

The trap here is that candidates confuse multi-factor authentication methods (like OTP or push notifications) with true passwordless authentication, which requires eliminating the password as a primary factor entirely, not just adding a second factor.

92
MCQmedium

A company wants to detect exposed internet-facing assets that are not yet known in its Azure inventory. Which Microsoft Defender capability is most relevant?

A.Defender for SQL vulnerability assessment
B.Microsoft Entra Permissions Management
C.Defender External Attack Surface Management
D.Azure Monitor VM insights
AnswerC

Defender External Attack Surface Management (EASM) continuously discovers and inventories an organization's internet-facing assets, including unknown or shadow IT resources, by scanning domains, IP blocks, ports, and web components from an attacker perspective. It uses Microsoft's global infrastructure data to identify these assets and integrates with Microsoft Defender for Cloud to provide security exposure insights. This is the only option directly engineered to detect exposed assets that were previously not known to the organization.

Why this answer

Defender External Attack Surface Management (EASM) is specifically designed to discover and inventory internet-facing assets (e.g., domains, IPs, open ports, certificates) that are not yet known to an organization's Azure inventory. It continuously scans public attack surfaces to identify unknown or unmanaged resources, making it the most relevant capability for detecting exposed assets outside the current Azure footprint.

Exam trap

The trap here is that candidates may confuse Defender EASM with Microsoft Entra Permissions Management (CIEM), assuming both deal with 'unknown assets' when in fact CIEM focuses on permissions and identity risks, not external asset discovery.

How to eliminate wrong answers

Option A is wrong because Defender for SQL vulnerability assessment focuses on identifying and remediating database-specific vulnerabilities (e.g., misconfigurations, missing patches) within known Azure SQL resources, not on discovering unknown internet-facing assets. Option B is wrong because Microsoft Entra Permissions Management (formerly CloudKnox) is a Cloud Infrastructure Entitlement Management (CIEM) tool that analyzes and manages permissions across multi-cloud environments, but it does not perform external asset discovery or attack surface scanning. Option D is wrong because Azure Monitor VM insights provides performance monitoring and dependency mapping for existing virtual machines, but it has no capability to discover unknown or external internet-facing assets.

93
MCQhard

You have an Azure SQL Database that stores financial data. You need to prevent unauthorized access by encrypting specific columns containing credit card numbers. The solution must allow authorized applications to query the data transparently. What should you implement?

A.Azure Storage service encryption
B.Transparent Data Encryption (TDE)
C.Dynamic Data Masking
D.Always Encrypted
AnswerD

Always Encrypted is a client-side encryption technology that encrypts sensitive data in specific columns before it is ever sent to Azure SQL Database. The database engine only receives and stores ciphertext, and encryption/decryption occurs transparently inside the client application using a column encryption key protected by a column master key stored in Azure Key Vault or a Windows certificate store. This ensures that even database administrators and cloud operators cannot view the plaintext financial data. Authorized applications that hold the column master key can query and decrypt the data transparently, making Always Encrypted the correct choice for protecting individual financial columns.

Why this answer

Always Encrypted is the correct choice because it encrypts specific columns (e.g., credit card numbers) at the client-side, ensuring that the data remains encrypted both at rest and in transit, and only authorized applications with the column encryption key can decrypt and query the data transparently. This meets the requirement of preventing unauthorized access (including database administrators) while allowing transparent querying for authorized applications.

Exam trap

The trap here is that candidates often confuse Transparent Data Encryption (TDE) with column-level encryption, mistakenly believing TDE protects specific columns from unauthorized access, when in fact TDE only protects data at rest and does not prevent authorized database users or DBAs from reading the data.

How to eliminate wrong answers

Option A is wrong because Azure Storage service encryption encrypts data at rest for Azure Blob Storage, Files, and Queues, not for Azure SQL Database columns. Option B is wrong because Transparent Data Encryption (TDE) encrypts the entire database at rest (pages on disk) but does not protect data from unauthorized access during query execution or from database administrators who have access to the database. Option C is wrong because Dynamic Data Masking obfuscates data in query results for unauthorized users but does not encrypt the underlying data; it can be bypassed by users with elevated permissions or by querying the data directly.

94
MCQmedium

Your organization has multiple Azure subscriptions managed by Microsoft Defender for Cloud. You need to ensure that all subscriptions have the same security policies applied, and that any new subscription automatically inherits these policies. What should you do?

A.Create an Azure Blueprint and assign it to each subscription
B.Assign a policy initiative to a resource group and then move subscriptions into that group
C.Assign a policy initiative to each subscription individually
D.Assign a policy initiative at the management group level
AnswerD

Assigning a policy initiative at the management group scope is the correct centralized approach because all subscriptions and resource groups under that management group inherit the policy assignment automatically. This includes future subscriptions added later, which become compliant without any additional assignment effort. Management group assignments also provide a single point to manage exclusions, remediation, and compliance reporting across the entire organizational hierarchy.

Why this answer

Assigning a policy initiative at the management group level ensures that all subscriptions within that management group inherit the same security policies. When a new subscription is added to the management group, it automatically receives the assigned initiative, meeting the requirement for consistent and automatic inheritance. This is the most efficient and scalable approach for managing multiple subscriptions in Microsoft Defender for Cloud.

Exam trap

The trap here is that candidates often confuse Azure Blueprints with management group policy assignments, thinking Blueprints provide automatic inheritance, when in fact Blueprints require explicit assignment per scope and do not dynamically apply to new subscriptions.

How to eliminate wrong answers

Option A is wrong because Azure Blueprints are used to deploy a repeatable set of Azure resources and policies, but they require manual assignment to each subscription and do not automatically apply to new subscriptions unless explicitly assigned again. Option B is wrong because policy initiatives cannot be assigned to resource groups and then have subscriptions moved into them; subscriptions are not moved into resource groups, and resource groups are containers for resources, not for subscriptions. Option C is wrong because assigning a policy initiative to each subscription individually would require manual effort for every existing and new subscription, failing to meet the requirement for automatic inheritance.

95
MCQmedium

A security operations team uses Microsoft Sentinel. They want to create a rule that generates an incident when an Azure virtual machine is deployed with a public IP address that is not in a predefined approved list. The rule should run every hour and query Azure Activity logs. Which type of analytics rule should they create?

A.Scheduled query rule
B.NRT (Near-Real-Time) rule
C.Anomaly rule
D.Fusion rule
AnswerA

Scheduled query rules are the core analytics rule type in Microsoft Sentinel for running KQL queries on a fixed cadence such as every hour. A defender can write a deterministic query that checks every virtual machine's public IP against a watchlist or lookup table of approved addresses, and trigger an incident when a non-approved IP is found. Because the schedule, query, and incident-generation settings are all configurable, this rule type exactly matches the requirement of an hourly deterministic check.

Why this answer

A scheduled query rule is correct because the requirement specifies a rule that runs every hour and queries Azure Activity logs. Scheduled query rules in Microsoft Sentinel are designed for periodic, time-based queries against log data, such as Azure Activity logs, and can generate incidents based on predefined conditions like detecting a VM deployment with an unapproved public IP. This aligns perfectly with the need for a recurring, non-real-time check.

Exam trap

The trap here is that candidates confuse the frequency requirement (every hour) with the near-real-time label, assuming NRT rules can be configured for any interval, when in fact NRT rules are hard-limited to 1-minute intervals and cannot be set to hourly runs.

How to eliminate wrong answers

Option B (NRT rule) is wrong because near-real-time rules run at intervals of 1 minute or less, not every hour, and are designed for low-latency detection, not scheduled hourly checks. Option C (Anomaly rule) is wrong because anomaly rules use machine learning to detect unusual patterns over time, not static conditions like a predefined approved IP list. Option D (Fusion rule) is wrong because Fusion rules correlate alerts from multiple security products to detect multi-stage attacks, not single-event conditions like VM deployment with a specific IP.

96
MCQmedium

Your security team is investigating a potential data exfiltration incident. They have identified that a user has been downloading large amounts of data from Azure Blob Storage to an external IP address. You need to create a Microsoft Sentinel analytics rule that triggers when more than 1 GB of data is downloaded from a storage account in a single hour. Which KQL query should be the basis of the rule?

A.StorageBlobLogs | where OperationName == 'GetBlob' | summarize TotalGB = sum(ResponseBodySize) / 1073741824 by bin(TimeGenerated, 1h) | where TotalGB > 1
B.StorageBlobLogs | where OperationName == 'GetBlob' | summarize avg(ResponseBodySize) by bin(TimeGenerated, 1h) | where avg_ResponseBodySize > 1073741824
C.StorageBlobLogs | where OperationName == 'GetBlob' and ResponseBodySize > 1073741824
D.StorageBlobLogs | where OperationName == 'GetBlob' | summarize count() by bin(TimeGenerated, 1h) | where count_ > 1000
AnswerA

This is correct because it sums the ResponseBodySize of all GetBlob operations in each one-hour bin, converting bytes to gigabytes by dividing by 1,073,741,824 (2^30). This captures the total volume of data downloaded per hour, which is the true signal for a bulk exfiltration scenario. The `where TotalGB > 1` then isolates hours where more than 1 GB left the storage account, aligning with the security team's threshold.

Why this answer

Option A is correct because it filters StorageBlobLogs to GetBlob operations, sums ResponseBodySize (which is in bytes) over a one-hour bin, converts the total to gigabytes by dividing by 1073741824, and then filters for totals greater than 1 GB — exactly matching the requirement to detect more than 1 GB downloaded per hour. Option B uses avg(ResponseBodySize), which measures the average size of individual downloads rather than the total volume, so it would not detect aggregate exfiltration. Option C checks each individual GetBlob event against 1 GB, missing the scenario where many smaller downloads sum to over 1 GB in an hour.

Option D counts the number of GetBlob operations rather than bytes transferred, so it does not measure data volume at all.

97
MCQmedium

A company has an Azure virtual network with a subnet that hosts a web application. They need to allow inbound HTTP (port 80) and HTTPS (port 443) traffic from a specific source IP range (203.0.113.0/24) to the web servers. Additionally, they need to allow inbound RDP (port 3389) traffic from a management subnet (10.0.1.0/24). They want to block all other inbound traffic. They are using a network security group (NSG) associated with the subnet. What is the minimum number of inbound security rules required?

A.3
B.4
C.5
D.2
AnswerA

You need exactly three inbound allow rules: one for HTTP (destination port 80), one for HTTPS (destination port 443), and one for RDP (destination port 3389), each scoped to the appropriate source address prefix. Azure NSGs include a default inbound deny rule, so any traffic not explicitly allowed by these three rules is automatically blocked. This satisfies the requirement with the minimum number of rules while preserving least privilege.

Why this answer

(3 rules) because an NSG includes default rules that already block all inbound traffic by default. You only need explicit allow rules for the three permitted traffic types: HTTP (port 80) from 203.0.113.0/24, HTTPS (port 443) from 203.0.113.0/24, and RDP (port 3389) from 10.0.1.0/24. The default deny rule handles blocking all other traffic, so no additional deny rule is required.

Exam trap

The trap here is that candidates often think they need an explicit deny rule to block all other traffic, forgetting that the default 'DenyAllInBound' rule already accomplishes this, leading them to overcount the required rules.

How to eliminate wrong answers

Option B (4) is wrong because it assumes a separate deny-all rule is needed, but the default deny rule already blocks all unmatched traffic. Option C (5) is wrong because it might incorrectly count separate rules for HTTP and HTTPS plus an explicit deny rule, or mistakenly include a rule for the management subnet's outbound traffic. Option D (2) is wrong because it would require combining HTTP and HTTPS into a single rule, but NSG rules cannot have multiple destination ports in a single rule unless using a port range, and port 80 and 443 are not contiguous; thus, two separate rules are needed for HTTP and HTTPS, plus one for RDP, totaling three.

98
MCQeasy

A company has Azure AD with Premium P2 licenses. They want to enforce Azure Multi-Factor Authentication (MFA) for all users accessing the Azure portal from untrusted networks, but only after the user has successfully entered their password. Which Conditional Access grant control should they configure?

A.Require multi-factor authentication
B.Require device to be marked as compliant
C.Require approved client app
D.Require domain join
AnswerA

The "Require multi-factor authentication" grant control, found under Access controls > Grant in a Conditional Access policy, forces the user to complete an MFA challenge (for example, an authenticator app, phone call, or hardware token) immediately after the initial password-based sign-in, blocking the session if MFA fails. This is the only option that directly enforces the stated requirement of requiring MFA after password authentication, because it specifically adds a second authentication factor rather than evaluating the device or client app state.

Why this answer

The 'Require multi-factor authentication' grant control in Conditional Access enforces MFA after password authentication, which aligns with the requirement to prompt for MFA only after the user has successfully entered their password. This control is applied based on the condition of 'untrusted networks' (e.g., using the 'Locations' condition to target all locations except trusted IPs), ensuring that MFA is triggered specifically for Azure portal access from untrusted networks.

Exam trap

The trap here is that candidates often confuse 'Require multi-factor authentication' with 'Require device to be marked as compliant' or 'Require domain join', mistakenly thinking device state controls can enforce MFA step-up, when in fact only the MFA grant control triggers the additional authentication challenge after password entry.

How to eliminate wrong answers

Option B is wrong because 'Require device to be marked as compliant' enforces device compliance (e.g., Intune policy) but does not enforce MFA after password entry; it blocks or grants access based on device health, not authentication step-up. Option C is wrong because 'Require approved client app' restricts access to specific client applications (e.g., Microsoft Authenticator) but does not enforce MFA after password entry; it is used for app-level restrictions, not authentication step-up. Option D is wrong because 'Require domain join' enforces hybrid Azure AD join or domain-joined devices, which does not enforce MFA after password entry; it is a device state control, not an authentication enforcement.

99
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) for Azure AD roles. They want to require that users must perform multi-factor authentication (MFA) when activating a role. Which PIM setting should they configure?

A.Require Azure AD Multi-Factor Authentication on activation
B.Require approval to activate
C.Require justification on activation
D.Require ticket information on activation
AnswerA

This setting enforces Azure AD Multi-Factor Authentication during the role activation process, so an eligible user must prove possession of a second factor (e.g., Authenticator app, phone call, FIDO2 key) each time they activate a privileged role. Because activation is time-bound, MFA at this step reduces the risk that a stolen primary credential alone can grant elevated access. In PIM, this is a mandatory best practice for highly privileged roles like Global Administrator.

Why this answer

To enforce multi-factor authentication during role activation in Azure AD Privileged Identity Management (PIM), you must configure the 'Require Azure AD Multi-Factor Authentication on activation' setting. This ensures that before a user’s role assignment is activated, they must complete an MFA challenge, adding an extra layer of security against unauthorized access.

Exam trap

The trap here is that candidates often confuse 'Require approval to activate' with MFA enforcement, but approval is a separate authorization step that does not verify the user’s identity through a second factor.

How to eliminate wrong answers

Option B is wrong because 'Require approval to activate' enforces a workflow where one or more approvers must authorize the activation, but it does not mandate MFA. Option C is wrong because 'Require justification on activation' only prompts the user to provide a business reason for activation, not an MFA challenge. Option D is wrong because 'Require ticket information on activation' asks for a support ticket number for auditing purposes, which is unrelated to multi-factor authentication.

100
Multi-Selecthard

A company uses Azure AD Privileged Identity Management (PIM) to manage access to Azure AD roles. They want to require that users who activate the Global Administrator role must get approval from their manager before activation, and that the approval must be time-bound (maximum 8 hours). Which two PIM configurations should they set?

Select 2 answers
A.Set the activation maximum duration to 8 hours.
B.Enable approval workflow by adding the manager as an approver.
C.Require multi-factor authentication on activation.
D.Require justification on activation.
AnswersA, B

Setting the activation maximum duration to 8 hours in Azure AD PIM enforces a strict time-bound on any privileged role activation. This ensures that a user cannot remain in the role indefinitely; after the configured duration, the role assignment automatically expires and reverts to eligible state. Since 8 hours is the maximum allowed activation duration for Azure AD roles, this directly satisfies the requirement that privileged access be temporary and bounded by a specific time limit.

Why this answer

Setting the activation maximum duration to 8 hours enforces the time-bound requirement, ensuring that once a user activates the Global Administrator role, the activation automatically expires after 8 hours. Option B is correct because enabling the approval workflow and adding the manager as an approver ensures that the manager must approve each activation request, meeting the requirement for manager approval. Together, these two configurations satisfy both the time-bound and approval constraints.

Exam trap

The trap here is that candidates often confuse 'justification' or 'MFA' with approval and time-bound constraints, but justification and MFA are separate security controls that do not satisfy the specific requirements for manager approval and a maximum duration.

101
MCQhard

You are a security engineer for Contoso. The company uses Azure Firewall for all inbound and outbound traffic. To prevent misconfiguration, you assign the Azure Policy shown in the exhibit at the management group scope. After assignment, a network administrator reports that they cannot create a new subnet in an existing virtual network. The subnet creation fails with a 'deny' policy error. You need to allow subnet creation while still blocking NSG rule changes. What should you do?

A.Change the effect to 'audit' instead of 'deny'.
B.Modify the policy rule to remove the subnet condition from the anyOf array.
C.Add an exemption for the virtual network resource group.
D.Remove the policy assignment and create a custom role to block subnet creation.
AnswerB

The `anyOf` array in an Azure Policy definition is evaluated as an OR, so if a subnet-specific condition (e.g., `Microsoft.Network/virtualNetworks/subnets`) is included alongside NSG rule conditions, the deny effect will incorrectly apply to subnet creation. Removing the subnet condition from that array narrows the policy scope to only NSG rule changes, preserving the deny behavior exactly where required while no longer blocking subnets. This is the only option that directly corrects the over-broad policy logic without losing the intended NSG rule enforcement.

Why this answer

The policy rule uses an `anyOf` array that includes conditions for both NSG rule changes and subnet creation. By removing the subnet condition from the `anyOf` array, the policy will no longer evaluate subnet creation against the deny effect, allowing subnets to be created while still blocking NSG rule modifications. This directly addresses the administrator's issue without weakening the security posture for NSG changes.

Exam trap

The trap here is that candidates may think adding an exemption (Option C) is the easiest fix, but they overlook that exemptions apply to the entire scope and would also exempt NSG rule changes, defeating the primary security requirement.

How to eliminate wrong answers

Option A is wrong because changing the effect to 'audit' would only log violations without blocking them, which fails to meet the requirement of blocking NSG rule changes. Option C is wrong because adding an exemption for the virtual network resource group would exempt all resources in that group from the policy, including NSG rule changes, thus bypassing the intended security control. Option D is wrong because removing the policy assignment and creating a custom role to block subnet creation would not prevent NSG rule changes, as custom roles do not enforce policy-based deny effects on resource modifications.

102
Multi-Selecteasy

Your company wants to implement a least-privilege model for administrative roles in Microsoft Entra ID. Which TWO features should you use?

Select 2 answers
A.Azure RBAC roles
B.Custom roles in Microsoft Entra ID
C.Conditional Access policies
D.Microsoft Entra B2B external identities
E.Privileged Identity Management (PIM)
AnswersB, E

Custom roles in Microsoft Entra ID allow you to define granular permissions by selecting specific tasks, such as reading audit logs or resetting passwords, that aren't combined into built-in roles. This lets you craft a role with exactly the permissions needed for a job, eliminating standing overprivileged access. By assigning such custom roles to principals, you implement least privilege at the directory level.

Why this answer

Custom roles in Microsoft Entra ID (option B) are correct because they let you define a precise set of directory permissions (for example, scoping actions like microsoft.directory/users/read) so administrators get only the access they need, which is the essence of least privilege. Privileged Identity Management (option E) is also correct because it enforces just-in-time activation of eligible directory roles with approval, MFA, and time-bound assignments, eliminating standing privileged access. Azure RBAC roles (option A) govern Azure resource-plane access, not Microsoft Entra ID administrative roles, so they don't address the directory role model in scope.

Conditional Access policies (option C) control sign-in conditions and access to resources but do not define or limit administrative role permissions. Microsoft Entra B2B external identities (option D) is about collaborating with external users, not about constraining administrative privileges.

Exam trap

The trap here is that candidates often confuse Azure RBAC roles (which manage Azure resources) with Microsoft Entra ID roles (which manage directory objects), leading them to incorrectly select Azure RBAC roles as a feature for Entra ID least-privilege administration.

103
MCQmedium

A company uses Azure Blob Storage to store sensitive documents. The security policy requires that the storage account can only be accessed from a specific Azure virtual network (VNet) and that all access must use Azure Active Directory (Azure AD) authentication. They want to block any access that uses storage account keys or shared access signatures (SAS). Which configuration should they implement?

A.Configure the storage account firewall to allow access from the specific VNet, and disable 'Allow storage account key access'.
B.Configure a private endpoint for the storage account and disable 'Allow storage account key access'.
C.Configure the storage account firewall to deny all networks, and set 'Allow storage account key access' to 'Disabled'.
D.Configure the storage account firewall to allow access from the specific VNet, and enable 'Require secure transfer' (HTTPS only).
AnswerA

Configuring the firewall with an allow rule for the specific VNet permits only traffic originating from that VNet's service endpoint or private endpoint, while setting 'Allow storage account key access' to Disabled forces Azure AD authentication by rejecting shared keys and SAS tokens. With this combination, clients in the allowed VNet must authenticate via Azure AD and be granted an RBAC role such as Storage Blob Data Reader or Storage Blob Data Contributor. This satisfies both the network restriction and the authentication requirement precisely.

Why this answer

It combines two essential controls: the storage account firewall restricts access to only the specified VNet, and disabling 'Allow storage account key access' enforces Azure AD authentication by blocking all requests that use account keys or SAS tokens. This ensures that only authenticated Azure AD identities from the allowed VNet can access the storage account, meeting the security policy requirements.

Exam trap

The trap here is that candidates often confuse 'Require secure transfer' (which only mandates HTTPS) with authentication enforcement, or assume that a private endpoint alone blocks key-based access, when in fact it only secures network connectivity.

How to eliminate wrong answers

Option B is wrong because while a private endpoint restricts network access to a specific VNet, disabling 'Allow storage account key access' alone does not block SAS tokens—SAS can still be generated and used unless explicitly disabled via other settings. Option C is wrong because denying all networks in the firewall blocks all traffic, including from the specific VNet, making the storage account inaccessible even with Azure AD authentication. Option D is wrong because enabling 'Require secure transfer' enforces HTTPS but does not block storage account keys or SAS tokens; it only ensures encrypted transport, not authentication method enforcement.

104
MCQmedium

A security team uses Microsoft Sentinel. They want to automatically isolate a compromised virtual machine by applying a network security group (NSG) rule. They have created a playbook in Azure Logic Apps that modifies the NSG. How should they trigger this playbook when an incident of type 'Suspicious VM activity' is created?

A.Create an automation rule in Microsoft Sentinel that is triggered when an incident is created, and set the action to run the playbook.
B.Configure a data connector to send all alerts to the playbook.
C.Enable the playbook as a response action in the analytics rule.
D.Use a logic app trigger that polls Sentinel incidents every minute.
AnswerA

This is the correct approach because automation rules are Microsoft Sentinel's native event-driven response mechanism. When an incident is created, the rule fires, evaluates conditions (such as severity, tactic, or analytics rule name), and executes a playbook as an action. This enables immediate, consistent automated response without custom code or background polling.

Why this answer

Microsoft Sentinel automation rules are designed to trigger playbooks automatically when incidents are created, updated, or closed. By configuring an automation rule with the condition 'When incident is created' and the action 'Run playbook', the playbook that modifies the NSG will execute immediately upon the creation of a 'Suspicious VM activity' incident, achieving the desired automated isolation without manual intervention.

Exam trap

The trap here is that candidates often confuse analytics rule response actions (which trigger on alert generation) with automation rules (which trigger on incident creation), leading them to incorrectly select Option C when the question explicitly requires incident-based triggering.

How to eliminate wrong answers

Option B is wrong because data connectors ingest raw logs and alerts into Sentinel, but they do not trigger playbooks; playbooks are triggered by automation rules or analytics rule response actions, not by data connectors. Option C is wrong because analytics rules can have automated responses, but those responses run when an alert is generated, not when an incident is created; the question specifies triggering on incident creation, which requires an automation rule. Option D is wrong because polling every minute introduces latency and inefficiency, and Sentinel provides event-driven triggers (via automation rules) that react instantly to incident creation, making polling unnecessary and suboptimal.

105
MCQmedium

A security operations team uses Microsoft Sentinel. They are investigating a security incident that involves multiple alerts from different Azure resources. They need to see the entire attack timeline and all related entities (such as user accounts, IP addresses, and hosts) in a single, visual graph to understand the scope of the attack. Which Microsoft Sentinel feature should they use?

A.Investigation graph
B.Incident dashboard
C.Entity behavior analytics (UEBA)
D.Threat hunting blade
AnswerA

The Investigation graph in Microsoft Sentinel is purpose-built for incident response, rendering an interactive, visual map of entities such as IP addresses, hosts, accounts, and URLs alongside their connected relationships. Analysts can expand nodes to uncover hidden lateral movement, trace the full attack timeline, and pivot between related alerts and bookmarks, which makes it the correct choice for investigating a specific incident. Unlike static lists, the graph dynamically correlates evidence to reveal causal chains and support rapid root-cause analysis.

Why this answer

The Investigation graph in Microsoft Sentinel is specifically designed to visually map the relationships between alerts, entities (such as user accounts, IP addresses, and hosts), and the attack timeline. It allows security analysts to explore the scope of an incident by interactively expanding nodes and viewing connections, which directly meets the requirement for a single visual graph showing the entire attack timeline and related entities.

Exam trap

The trap here is that candidates often confuse the Incident dashboard (which shows a list of incidents) with the Investigation graph (which provides the interactive visual graph of entities and timeline), leading them to select the dashboard option because it sounds like the place to 'see' incident details.

How to eliminate wrong answers

Option B (Incident dashboard) is wrong because it provides a high-level summary of incidents (e.g., severity, status, count) but does not offer a visual graph of entity relationships or an attack timeline. Option C (Entity behavior analytics / UEBA) is wrong because it focuses on profiling and detecting anomalous behavior of individual entities over time, not on mapping the relationships and timeline of multiple alerts in a single incident. Option D (Threat hunting blade) is wrong because it is used for proactive, query-based searches for potential threats across large datasets, not for visualizing the scope and relationships of an already identified incident.

106
Multi-Selecthard

Which THREE of the following are capabilities of Microsoft Defender for Cloud's workload protection plans?

Select 3 answers
A.Adaptive application controls
B.DDoS protection
C.Data Loss Prevention (DLP)
D.File Integrity Monitoring (FIM)
E.Just-in-time (JIT) VM access
AnswersA, D, E

Adaptive application controls are a workload-protection capability in Microsoft Defender for Cloud that uses machine learning to establish a baseline of applications permitted to run on a specific set of Azure or non-Azure VMs. In audit mode, it learns typical running processes; in enforce mode, it blocks untrusted executables and generates security alerts. This feature directly protects the workload plane, distinguishing it from network-layer services like DDoS protection.

Why this answer

Adaptive application controls (A) are a capability of Microsoft Defender for Cloud's workload protection plans. They use machine learning to analyze processes running on Azure and non-Azure machines, allowing you to define allowlists for known safe applications and generate security alerts when unauthorized applications execute, thus reducing the attack surface.

Exam trap

The trap here is that candidates may confuse Azure DDoS Protection (a separate network-layer service) or Microsoft Purview DLP (a data security solution) as being part of Defender for Cloud's workload protection plans, when in fact they are distinct services with different scopes and integration points.

107
MCQhard

Your organization uses Microsoft Entra ID with Privileged Identity Management (PIM). You need to ensure that all privileged role activations are approved by a manager and require a ticket number. What should you configure in PIM?

A.Role settings for the privileged role
B.Audit history
C.Alerts
D.Access reviews
AnswerA

In Privileged Identity Management (PIM) for Microsoft Entra ID roles, role settings configure the activation policy, including whether approval is required, what justification must be submitted, and the maximum duration the role stays active. Requiring users to submit an activation request that must be both justified and approved by designated approvers is the direct control that prevents arbitrary, self-service escalation to a privileged role.

Why this answer

In Microsoft Entra ID PIM, role settings for each privileged role allow you to configure approval requirements and justification fields. By editing the role settings, you can require approval from a designated approver (e.g., a manager) and mandate a ticket number in the justification field, ensuring compliance with organizational policies.

Exam trap

The trap here is that candidates may confuse role settings (which control activation policies) with audit history or alerts, thinking that logging or notifications can enforce approval requirements, but only role settings provide the configuration to mandate approvals and ticket numbers.

How to eliminate wrong answers

Option B (Audit history) is wrong because it only provides a log of past activations and changes, not a configuration mechanism to enforce approval or ticket number requirements. Option C (Alerts) is wrong because alerts are used to notify administrators of suspicious or anomalous activities, not to enforce approval workflows or mandatory fields. Option D (Access reviews) is wrong because access reviews are periodic recertifications of existing role assignments, not a setting to control activation conditions like approval or ticket numbers.

108
MCQhard

A KQL hunting query joins SecurityIncident with SecurityAlert but returns duplicate rows for incidents with multiple alerts. What KQL approach best preserves one row per incident while summarizing alert details?

A.Use order by TimeGenerated desc only
B.Replace join with union
C.Use take 1 before the join
D.Use summarize make_set() or arg_max() grouped by IncidentNumber
AnswerD

Summarize make_set() collects the distinct values of a chosen column (for example AlertId or AlertName) into an array for each IncidentNumber, guaranteeing exactly one output row per incident while preserving all associated alert details. If only the most recent alert per incident is needed, arg_max(TimeGenerated, *) returns the latest alert row for each incident. Both operators perform the aggregation after the join and directly address the duplicate-row issue.

Why this answer

`summarize make_set()` or `arg_max()` grouped by `IncidentNumber` collapses multiple alert rows into a single incident row while preserving alert details in an array or the most recent alert. This directly addresses the duplicate rows caused by a one-to-many join between SecurityIncident and SecurityAlert, ensuring one row per incident without data loss.

Exam trap

The trap here is that candidates often confuse sorting or limiting rows (options A and C) with deduplication, or incorrectly think a union can replace a join, missing the fundamental need to aggregate after a one-to-many relationship.

How to eliminate wrong answers

Option A is wrong because `order by TimeGenerated desc` only sorts the results and does not remove duplicate rows; it leaves the duplicates intact. Option B is wrong because `union` combines rows from two tables without any join logic, which would not correlate incidents with their alerts and would produce a completely different, incorrect result set. Option C is wrong because `take 1` before the join arbitrarily limits the input rows before the join, which can discard relevant alerts and still produce duplicates if the incident has multiple alerts in the remaining data.

109
MCQeasy

You are responsible for securing an Azure environment using Microsoft Defender for Cloud. You need to reduce the number of false positive security alerts for a specific Azure SQL Database. The database is regularly scanned by a legitimate security tool that generates alerts. What should you do?

A.Disable the security alert rule for SQL databases in Defender for Cloud.
B.Exclude the database from the vulnerability assessment solution.
C.Create a suppression rule for the specific alert type and source IP address.
D.Modify the Azure SQL Database firewall rules to allow the scanning tool's IP.
AnswerC

Creating a suppression rule for the specific alert type and source IP address is the targeted, recommended solution. Defender for Cloud lets you define a rule on an alert that automatically dismisses future matches based on properties like entity, IP address, or attack evidence, so benign scanning activity from that IP is ignored while all other alerts continue to fire. This reduces alert fatigue without disabling any detection capability.

Why this answer

Microsoft Defender for Cloud allows you to create suppression rules to automatically filter out specific security alerts that are known to be benign. By configuring a suppression rule for the specific alert type and the source IP address of the legitimate security scanning tool, you can prevent those alerts from appearing in the security alerts queue without disabling broader detection for SQL databases. This approach reduces false positives while maintaining visibility into other potential threats.

Exam trap

The trap here is that candidates often confuse suppression rules (which filter alerts) with disabling detection rules or modifying firewall settings, thinking that blocking the source IP or disabling the rule entirely is the correct way to handle false positives.

How to eliminate wrong answers

Option A is wrong because disabling the entire security alert rule for SQL databases would stop all alerts for that resource, including legitimate threat detections, leaving the database unprotected. Option B is wrong because excluding the database from the vulnerability assessment solution would prevent the assessment from scanning for vulnerabilities, but the false positive alerts are generated by security alerts (e.g., SQL injection detection), not by the vulnerability assessment itself. Option D is wrong because modifying the Azure SQL Database firewall rules to allow the scanning tool's IP addresses does not affect how Defender for Cloud generates alerts; firewall rules control network access, not alert suppression.

110
Drag & Dropmedium

Drag and drop the steps to configure Azure AD Privileged Identity Management (PIM) for a role into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

PIM requires enabling the service first, then selecting roles, configuring settings, and finally assigning users as eligible.

111
MCQhard

A company uses Azure AD Privileged Identity Management (PIM) to manage access to critical roles. They want to require that users who are eligible for the 'Security Administrator' role must provide a support ticket number in the justification when activating the role. Additionally, they want to set a maximum activation duration of 4 hours. Which PIM role setting should they configure?

A.Activation settings
B.Notification settings
C.Approval settings
D.Assignment settings
AnswerA

Activation settings in Microsoft Entra ID PIM control what happens when an eligible user activates a role, including requiring justification such as a support ticket number and enforcing a maximum activation duration. Configuring these satisfies both the ticket-justification and four-hour duration constraints.

Why this answer

The 'Activation settings' in Azure AD PIM allow you to configure the maximum activation duration (in hours) and require justification, including a support ticket number, when a user activates an eligible role. These settings directly control the conditions under which role activation occurs, such as duration and mandatory justification fields.

Exam trap

The trap here is that candidates often confuse 'Assignment settings' (which control the duration of an eligible or active assignment) with 'Activation settings' (which control the duration and conditions of activation for eligible users), leading them to incorrectly select Option D.

How to eliminate wrong answers

Option B is wrong because 'Notification settings' control who receives email alerts when roles are activated or assigned, not the activation duration or justification requirements. Option C is wrong because 'Approval settings' require designated approvers to approve activation requests, but they do not enforce a maximum activation duration or a support ticket number in the justification. Option D is wrong because 'Assignment settings' define whether a role assignment is eligible or active, and the duration of the assignment itself, not the activation duration or justification content for eligible users.

112
MCQeasy

You are troubleshooting why a user cannot sign in to a custom line-of-business application that is federated with Microsoft Entra ID. The user reports that they are repeatedly prompted for credentials and then receive an error. The application is configured for SAML-based SSO. What is the most likely cause?

A.The user's browser cookies are disabled
B.The application is not registered in the app gallery
C.The SAML certificate has expired or the configuration has a mismatch
D.The user does not have a license for Microsoft Entra ID
AnswerC

SAML certificates are used to sign the SAML response; the service provider uses the certificate's public key to validate the signature. If the certificate has expired or the configured certificate doesn't match the one trusted by the application, the SP will discard the assertion and deny sign-in. Likewise, a mismatch in the SAML configuration (e.g., Entity ID, Reply URL, or signing algorithm) will cause authentication failures even when the certificate is valid.

Why this answer

When a SAML-based SSO application repeatedly prompts for credentials and then fails, the most common cause is an expired or misconfigured SAML signing certificate. The certificate is used by Microsoft Entra ID to sign SAML assertions; if it has expired, or if the thumbprint, audience URI, or reply URL in the Entra ID configuration does not match what the application expects, the application will reject the assertion and force re-authentication or display an error.

Exam trap

The trap here is that candidates often confuse a SAML certificate expiration/mismatch with a licensing issue or browser configuration problem, but the repeated credential prompt followed by an error is the hallmark of a failed SAML assertion validation, not a missing license or disabled cookies.

How to eliminate wrong answers

Option A is wrong because disabled browser cookies would typically cause session persistence issues or repeated prompts, but they would not directly cause a SAML assertion validation failure with a specific error; the error described is characteristic of a token trust issue, not a cookie storage issue. Option B is wrong because an application does not need to be in the Microsoft Entra ID app gallery to function with SAML SSO; custom line-of-business applications can be registered as non-gallery applications and work identically. Option D is wrong because Microsoft Entra ID licensing is not required for a user to authenticate via SAML federation; free tier Entra ID supports SAML-based SSO for up to 10 applications per tenant, and the error is unrelated to license assignment.

113
Drag & Dropmedium

Drag and drop the steps to configure Azure Defender for SQL on an Azure SQL Database into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Defender for SQL is enabled per database under security settings, requiring storage for scans.

114
Multi-Selecthard

You are configuring security for an Azure Functions app that processes credit card numbers. You need to ensure that the function can securely access a storage account without storing any credentials in code or configuration, and that all data in the storage account is encrypted with a customer-managed key. Which three actions should you take?

Select 3 answers
A.Assign the 'Storage Blob Data Contributor' role to the function app's managed identity
B.Configure the storage account to use customer-managed keys for encryption
C.Store the storage account connection string in an application setting
D.Enable system-assigned managed identity on the function app
E.Use a Key Vault reference in the function app configuration to retrieve the storage account key
AnswersA, B, D

Assigning the 'Storage Blob Data Contributor' role to the function app's managed identity grants data-plane access to the storage account through Azure AD RBAC rather than a shared key. This role gives the identity read/write/delete permissions on blob containers, and Azure AD-based access supports conditional access policies and operation logs for auditing. Since the identity is a security principal, the access can be revoked or scoped independently, eliminating the need to rotate credentials or store keys in configuration.

Why this answer

Assigning the 'Storage Blob Data Contributor' role to the function app's managed identity authorizes the function to read and write blobs in the storage account using Azure RBAC, without requiring any credentials in code or configuration. This aligns with the requirement to avoid storing credentials, as the managed identity provides a secure identity for the function app to authenticate to Azure services.

Exam trap

The trap here is that candidates often confuse using Key Vault references (which still rely on a stored secret) with managed identity authentication (which eliminates secrets entirely), leading them to select option E instead of the correct combination of managed identity and RBAC.

115
MCQmedium

You are a security engineer at Northwind Traders. The company has an Azure subscription with a virtual network named VNet1. You need to ensure that all outbound internet traffic from VNet1 is inspected by a central security appliance before leaving the network. You also need to log all traffic for auditing. The solution must minimize administrative effort and support scaling. What should you deploy?

A.Network security groups (NSGs) on each subnet with rules to allow only required outbound traffic, and enable NSG flow logs.
B.Azure Firewall in a hub virtual network, with user-defined routes (UDRs) in VNet1 pointing to the firewall's private IP address as the next hop for 0.0.0.0/0.
C.Azure VPN Gateway with forced tunneling configured to route all traffic through an on-premises firewall.
D.Azure Application Gateway with Web Application Firewall (WAF) and configure custom routing rules to send all outbound traffic to the gateway.
AnswerB

Azure Firewall is a managed, scalable cloud-native firewall that provides central inspection and logging. By creating a UDR in VNet1 that routes 0.0.0.0/0 to the firewall's private IP, all outbound internet traffic is forced through the firewall. This meets the inspection and logging needs with minimal management overhead and supports autoscaling.

Why this answer

Azure Firewall is a managed, cloud-native network security service that provides central inspection, logging, and scalability. By deploying it in a hub and using user-defined routes in VNet1 to direct all outbound traffic (0.0.0.0/0) to the firewall's private IP, you ensure every packet is inspected and logged. This design minimizes administrative effort because Azure manages the firewall infrastructure and scaling.

Exam trap

The trap here is assuming that network security groups alone can provide central inspection and logging of outbound traffic, when they are merely basic access control lists without payload inspection or centralized routing control.

116
MCQmedium

Your security operations center (SOC) uses Microsoft Sentinel. You need to ensure that an incident is automatically created when a specific type of alert fires from Microsoft Defender for Cloud. What is the most efficient way to configure this?

A.Create a playbook that triggers on alert and generates an incident via API.
B.Configure the Microsoft Defender for Cloud data connector in Sentinel and enable incident creation.
C.Design a workbook to monitor alerts and manually create incidents.
D.Write a scheduled analytics rule that queries Defender for Cloud logs.
AnswerB

The Microsoft Defender for Cloud data connector in Microsoft Sentinel is the native integration that ingests security alerts from Defender for Cloud plans into your workspace, and enabling incident creation on that connector activates the built-in analytics rule that automatically generates a Sentinel incident for each incoming alert. This is the intended, supportable path because it requires no custom code or manual effort, and it ensures that Defender for Cloud detection signals flow directly into your SOC incident queue for triage and investigation.

Why this answer

Option B is correct because the Microsoft Defender for Cloud data connector in Microsoft Sentinel includes an option to automatically create incidents from Defender for Cloud alerts, which is the native and most efficient integration for this scenario. Once the connector is configured and incident creation is enabled, alerts from Defender for Cloud flow into Sentinel and generate incidents without custom automation. Option A is unnecessary because a playbook and API calls add complexity when the connector already supports automatic incident creation.

Option C is incorrect because workbooks are only for visualization and do not create incidents, and manual creation is not automatic. Option D is also incorrect because scheduled analytics rules query log data on a schedule and are not the intended mechanism for ingesting Defender for Cloud alerts as incidents.

117
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) to manage the 'Global Administrator' role. The security team wants to ensure that when a user activates the role, they must provide a justification, and the activation request must be approved by a specific group of security administrators. They have already configured the role for activation with a maximum duration of 8 hours. Which additional PIM settings should they configure?

A.Enable 'Require approval to activate' and select the security group as approver
B.Set 'Require Azure Multi-Factor Authentication' to 'On'
C.Set 'Require justification on activation' to 'On' and also enable 'Require ticket information'
D.Create a separate PIM request workflow using Azure Logic Apps
AnswerA

Enabling 'Require approval to activate' in PIM forces any eligible user's activation request to enter a pending state until a designated approver explicitly approves it. By selecting the security group as the approver, you guarantee that a human decision point exists outside the requesting user, so the security group enforces separation of duties. This is the native, built-in PIM approval mechanism that directly implements the required governance control.

Why this answer

The scenario requires both justification and approval for role activation. PIM allows you to enforce 'Require justification on activation' and 'Require approval to activate' as separate settings. By enabling 'Require approval to activate' and selecting the security group as the approver, you meet the requirement for approval.

Justification is already a default requirement in PIM when approval is enabled, but you must also explicitly set 'Require justification on activation' to 'On' if not already enforced; however, the question states they have already configured the role for activation with a maximum duration, so the missing piece is the approval configuration.

Exam trap

The trap here is that candidates may think 'Require justification on activation' alone satisfies the requirement, but the question explicitly asks for approval by a specific group, which requires the separate 'Require approval to activate' setting.

How to eliminate wrong answers

Option B is wrong because requiring Azure Multi-Factor Authentication (MFA) is a separate security control that does not enforce approval or justification; it only adds an authentication step during activation. Option C is wrong because while 'Require justification on activation' is needed, the scenario also requires approval by a specific group, which is not addressed by justification or ticket information alone. Option D is wrong because Azure Logic Apps are not a native PIM setting for role activation approval; PIM has built-in approval workflows that do not require custom Logic Apps.

118
Multi-Selecthard

Which THREE of the following are required to enable network traffic flow between two peered Azure virtual networks in different Azure regions?

Select 3 answers
A.Both VNets must have the Allow virtual network access setting enabled for the peering.
B.If using a network virtual appliance, the Allow forwarded traffic setting must be enabled.
C.Gateway transit must be enabled in at least one VNet.
D.An NSG rule must allow traffic between the VNets.
E.The address spaces of the VNets must not overlap.
AnswersA, B, E

The 'Allow virtual network access' setting is the master switch that permits the two virtual networks to communicate directly through peering. Both peering links must have it enabled; if one side disables it, traffic from that VNet will not be allowed to pass to the other. Without this setting, no other peering features (forwarded traffic or gateway transit) matter.

Why this answer

Option A is correct because each side of a VNet peering link has an 'Allow virtual network access' setting that must be enabled so the peered VNet's address space is reachable; if it is disabled, traffic to that VNet is blocked even though the peering exists. Option B is correct because when traffic is routed through a network virtual appliance in the peered VNet, the receiving peering must have 'Allow forwarded traffic' enabled, otherwise traffic not originating from the peered VNet's own address space is dropped. Option E is correct because VNet peering requires the address spaces of the two VNets to be non-overlapping; overlapping prefixes make routing ambiguous and the peering cannot be created.

Option C is not required: gateway transit only matters when sharing a VPN/ExpressRoute gateway, not for basic VNet-to-VNet traffic flow. Option D is not required: NSGs are optional security filters, and peering itself does not depend on an NSG rule allowing traffic.

Exam trap

The trap here is that candidates often confuse optional features like gateway transit or NSG rules as mandatory requirements for VNet peering, when in fact only the peering settings and non-overlapping address spaces are required for basic traffic flow.

119
MCQhard

Your organization is migrating to Azure and needs to protect against advanced threats like fileless malware. You must use a solution that provides real-time protection and integrates with Microsoft Defender for Cloud. What should you deploy on Azure VMs?

A.Microsoft Antimalware for Azure
B.Microsoft Defender for Endpoint (Microsoft Defender XDR)
C.Azure Monitor Agent (AMA)
D.Azure Security Center (free tier)
AnswerB

Microsoft Defender for Endpoint, integrated into Microsoft Defender XDR, provides true endpoint detection and response with continuous memory scanning, kernel-level behavioral monitoring, and cloud-driven machine learning. It identifies fileless malware by correlating anomalous process activity, script execution, and in-memory indicators, then automatically contains the host. This capability is precisely why it, not any agent-based scanner, defeats fileless attacks.

Why this answer

Microsoft Defender for Endpoint (part of Microsoft Defender XDR) provides next-generation protection, including behavior-based, real-time detection of fileless malware and other advanced threats. It integrates natively with Microsoft Defender for Cloud to deliver unified security management and automated response for Azure VMs, meeting the requirement for real-time protection against sophisticated attacks.

Exam trap

The trap here is that candidates often confuse Microsoft Antimalware for Azure (a legacy, signature-based solution) with modern endpoint detection and response (EDR) capabilities, mistakenly believing it can handle fileless malware when it cannot.

How to eliminate wrong answers

Option A is wrong because Microsoft Antimalware for Azure is a signature-based antimalware solution that lacks the behavioral analysis and machine learning capabilities needed to detect fileless malware; it also does not integrate with Defender for Cloud for advanced threat protection. Option C is wrong because Azure Monitor Agent (AMA) is a data collection agent for monitoring and diagnostics, not a security solution for real-time malware protection. Option D is wrong because Azure Security Center (free tier) provides basic security assessment and recommendations but does not include real-time endpoint protection or advanced threat detection capabilities.

120
MCQhard

A company uses Microsoft Defender for Cloud's Just-In-Time (JIT) VM access to manage RDP connections to a critical jump-box virtual machine. The company has a CI/CD pipeline running on Azure DevOps agent pools that needs to periodically RDP into this VM to deploy software. The agent pool's source IP addresses are dynamic and change frequently. They want the pipeline to automatically request JIT access before each deployment without manual intervention. Which approach should they implement?

A.Use the Azure REST API with a managed identity assigned to the DevOps agent to request JIT access, specifying the agent's current source IP address
B.Create a JIT access rule in Defender for Cloud with a scheduled time window that matches the pipeline's deployment schedule
C.Configure a PowerShell script in the pipeline to modify the network security group (NSG) to allow the agent's IP during deployment
D.Assign a static public IP to the Azure DevOps agent and add that IP to the JIT allowed list permanently
AnswerA

The REST API endpoint for JIT allows programmatic requests. A managed identity on the agent (or virtual machine running the agent) provides secure authentication without secrets. The pipeline can fetch its current outbound IP and request JIT access for the required time.

Why this answer

It uses the Azure REST API with a managed identity to dynamically request JIT VM access, specifying the agent's current source IP address. This approach allows the CI/CD pipeline to authenticate without secrets and automatically obtain time-bound RDP access, even though the agent's IP changes frequently. The managed identity provides secure, automated authentication to Azure Resource Manager, enabling the pipeline to call the JIT policy endpoint and grant access for the deployment duration.

Exam trap

The trap here is that candidates may think scheduled JIT rules (Option B) exist or that permanently whitelisting an IP (Option D) is acceptable, but Azure JIT is designed for dynamic, on-demand access requests, not static schedules or permanent allowances.

How to eliminate wrong answers

Option B is wrong because scheduled JIT access rules do not exist; JIT access is request-based and time-bound, not scheduled, and a fixed time window cannot accommodate dynamic IP changes or unpredictable deployment schedules. Option C is wrong because directly modifying the NSG bypasses Defender for Cloud's JIT access control, defeating the purpose of using JIT for security and auditability, and it would require additional permissions and manual cleanup. Option D is wrong because assigning a static public IP to the Azure DevOps agent is often impractical or impossible (agents may be in a dynamic pool or behind a NAT), and adding it permanently to the JIT allowed list eliminates the just-in-time security benefit, leaving the VM exposed continuously.

121
MCQmedium

A security team uses Microsoft Defender for Cloud to monitor the security posture of a hybrid environment that includes on-premises servers connected via Azure Arc. They want to enable a vulnerability assessment solution that automatically scans all servers (both Azure VMs and on-premises Arc-enabled servers) for OS vulnerabilities. Which solution should they enable directly from Defender for Cloud?

A.Enable the integrated vulnerability assessment solution (Qualys) in Defender for Cloud
B.Enable Microsoft Defender for Endpoint and integrate it with Defender for Cloud
C.Configure Azure Update Management to assess missing patches
D.Use Azure Policy to deploy the Log Analytics agent and manually enable scanning
AnswerA

The integrated vulnerability assessment (VA) solution in Defender for Cloud uses Qualys as the built-in scanner, and it is available at no additional cost for both Azure VMs and Arc-enabled on-premises servers. When you enable it, Defender for Cloud deploys the Qualys agent and automatically performs continuous OS vulnerability scanning, mapping findings to CVEs and security misconfigurations. This is the native, first-party path that does not require a separate Qualys license, making it the correct way to meet the monitoring requirement.

Why this answer

The integrated vulnerability assessment (VA) solution in Defender for Cloud, powered by Qualys, is the correct choice because it is a native, built-in capability that can be automatically enabled for both Azure VMs and Azure Arc-enabled on-premises servers. It requires no additional licensing or external configuration, and it automatically discovers and scans OS vulnerabilities without manual intervention, directly from the Defender for Cloud portal.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Endpoint's threat and vulnerability management (TVM) with a dedicated vulnerability assessment solution, but the question specifically asks for a solution that can be enabled directly from Defender for Cloud for automatic OS vulnerability scanning, which is the integrated Qualys-based VA solution.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Endpoint (MDE) is an endpoint detection and response (EDR) solution focused on threat detection and response, not a dedicated vulnerability assessment scanner; while MDE includes threat and vulnerability management (TVM), the question specifically asks for a solution that automatically scans for OS vulnerabilities directly from Defender for Cloud, and the integrated Qualys solution is the one that meets this requirement natively. Option C is wrong because Azure Update Management is designed to manage and deploy OS patches, not to assess vulnerabilities; it reports missing updates but does not perform vulnerability scanning or provide a vulnerability score. Option D is wrong because deploying the Log Analytics agent and manually enabling scanning is not a built-in vulnerability assessment solution; it requires custom configuration and does not provide the automated, integrated scanning that the Qualys-based solution offers directly from Defender for Cloud.

122
MCQmedium

Your organization uses Azure Storage for sensitive financial data. You need to restrict access to storage accounts based on the client's IP address. Which Azure Storage service feature should you configure?

A.Firewalls and virtual networks
B.Shared access signatures (SAS)
C.Azure Private Link
D.Azure AD role-based access control
AnswerA

Firewalls and virtual networks is the correct answer because it is the Azure Storage account networking feature that lets you define IP address rules, including ranges and specific IPs, to restrict access to the storage account. When you configure these firewall rules, only requests originating from allowed IP addresses (or from selected virtual networks using service endpoints) can reach the storage endpoint, effectively blocking all other clients. This directly satisfies the requirement to restrict storage access by IP address.

Why this answer

Firewalls and virtual networks allow you to restrict access to Azure Storage accounts based on source IP address ranges, including specific client IPs. This is the correct feature because it provides network-level access control that can block or allow traffic from defined IP addresses, which directly meets the requirement to restrict access based on the client's IP address.

Exam trap

The trap here is that candidates often confuse Shared Access Signatures (SAS) with network-level access control, mistakenly thinking SAS tokens can restrict by IP, when in fact SAS tokens only grant access to anyone holding the token unless you explicitly configure an IP ACL within the SAS token itself—but the question asks for a storage service feature, not a token-level option, and the correct answer is the Firewall and virtual networks feature.

How to eliminate wrong answers

Option B is wrong because Shared Access Signatures (SAS) provide time-limited, delegated access to specific storage resources via a token, but they do not restrict access based on the client's IP address; they grant access to anyone who possesses the token, regardless of their IP. Option C is wrong because Azure Private Link exposes the storage account over a private endpoint within a virtual network, which restricts access to traffic from that VNet but does not filter by client IP address; it is designed for private connectivity, not IP-based restrictions. Option D is wrong because Azure AD role-based access control (RBAC) manages authorization at the control plane (management operations) and data plane (via Azure AD authentication) but does not enforce network-level IP restrictions; it controls who can access the storage account, not from which IP addresses.

123
MCQmedium

A team wants to automatically deploy Defender for Cloud settings across new subscriptions under a management group. Which Azure capability should they use?

A.Application security groups
B.Conditional Access templates
C.Sentinel workbooks
D.Azure Policy initiative assignment
AnswerD

An Azure Policy initiative assignment is the correct solution because it allows you to assign a built-in or custom initiative, such as the Microsoft cloud security benchmark, at resource group, subscription, or management group scope. When assigned at a management group, the policy definitions are inherited by all existing and future subscriptions, enabling Defender for Cloud plans and configuring required monitoring settings automatically on new subscriptions. This policy-driven governance ensures consistency and eliminates the need for manual per-subscription configuration.

Why this answer

Azure Policy initiative assignments allow you to bundle multiple policy definitions (such as those for Defender for Cloud) and assign them at the management group scope. This ensures that all new subscriptions under that management group automatically inherit and enforce the Defender for Cloud settings, including enabling security monitoring and threat detection. This is the correct approach because Azure Policy provides continuous compliance evaluation and remediation at scale across the entire resource hierarchy.

Exam trap

The trap here is that candidates often confuse Azure Policy with Azure Blueprints or think that Defender for Cloud settings can only be configured per subscription manually, missing that Policy initiatives at the management group level provide automatic, scalable enforcement for new subscriptions.

How to eliminate wrong answers

Option A is wrong because Application security groups are used to group virtual machines and define network security rules based on those groups, not to deploy or enforce security settings across subscriptions. Option B is wrong because Conditional Access templates are part of Azure AD and control access to applications based on conditions like location or device state; they do not deploy Defender for Cloud settings. Option C is wrong because Sentinel workbooks are visualization tools for security data within Azure Sentinel, not a mechanism to automatically deploy or enforce security configurations across subscriptions.

124
MCQeasy

A company deploys multiple Azure virtual machines across several subnets in a virtual network. The VMs are grouped by application tiers: web, application, and database. The security team wants to apply network security group (NSG) rules that target all VMs in a specific tier, and they need a way to easily add or remove VMs from these groups without updating NSG rules. Which Azure feature should they use to define these logical VM groups?

A.Network security group (NSG) with multiple IP address ranges.
B.Application Security Group (ASG).
C.Azure Resource Manager tags.
D.Virtual Network peering.
AnswerB

ASGs enable you to define logical groups of VMs based on their function. You can reference an ASG in NSG rules, and as VMs are added or removed from the ASG, the rule applies to the current members automatically.

Why this answer

Application Security Groups (ASGs) allow you to group VMs logically by application tier (e.g., web, application, database) without relying on IP addresses or subnet boundaries. NSG rules can reference ASGs as source or destination, so adding or removing a VM from an ASG automatically updates the effective security policy without modifying the NSG rules themselves.

Exam trap

The trap here is that candidates often confuse Azure Resource Manager tags with ASGs, thinking tags can be used in NSG rules, but NSG rules only support IP addresses, service tags, and application security groups, not tags.

How to eliminate wrong answers

Option A is wrong because NSGs with multiple IP address ranges require manual updates to the IP list whenever VMs are added or removed, which does not provide the dynamic, logical grouping the scenario requires. Option C is wrong because Azure Resource Manager tags are metadata labels that cannot be directly referenced in NSG rules; they are used for resource organization, cost tracking, and policy enforcement, not for defining network security group membership. Option D is wrong because Virtual Network peering connects separate virtual networks at the network layer and does not create logical groups of VMs within a single VNet or across subnets.

125
MCQhard

You are the security engineer for a financial services company that has multiple Azure subscriptions. The company uses Azure Virtual WAN with a secured hub containing Azure Firewall. Recently, the compliance team identified that traffic between two spoke virtual networks (SpokeA and SpokeB) is bypassing the firewall. Investigation shows that SpokeA and SpokeB are directly peered and have not been routed through the hub. The requirement is that all inter-spoke traffic must be inspected by Azure Firewall. You need to enforce this without disrupting existing applications. Also, the company uses Azure Firewall Manager for policy management and wants to use Azure Policy to prevent future direct peering. What should you do first?

A.Remove the VNet peering between SpokeA and SpokeB.
B.Disable 'Use remote virtual network gateways' on both spokes.
C.Create an Azure Policy to deny VNet peering between spokes.
D.Add a user-defined route in SpokeA and SpokeB pointing to the Azure Firewall for inter-spoke traffic.
AnswerA

The direct VNet peering is the path letting SpokeA-to-SpokeB traffic bypass Azure Firewall entirely. Removing that peering forces traffic through the secured hub, where Azure Firewall inspects it. This is the prerequisite step before applying Azure Policy to block future direct peerings.

Why this answer

The immediate problem is the existing VNet peering between SpokeA and SpokeB that bypasses Azure Firewall. The first step must address this existing peering. Removing the peering removes the direct path, forcing inter-spoke traffic to route through the Virtual WAN hub where Azure Firewall inspects it.

Option C (Azure Policy) is a preventive measure for future peerings but does not resolve the current violation. Option D (UDR) is ineffective because VNet peering has higher precedence than user-defined routes. Option B is unrelated to the peering issue.

Therefore, the correct first action is to remove the VNet peering.

126
Multi-Selecteasy

Which TWO of the following are supported ways to connect an on-premises network to Azure?

Select 2 answers
A.Azure Bastion
B.Azure ExpressRoute
C.Point-to-Site VPN
D.Site-to-Site VPN
E.Azure Front Door
AnswersB, D

Azure ExpressRoute is a dedicated, private network connection that extends an enterprise's on-premises infrastructure into Azure over a service provider's MPLS or similar reliable infrastructure, bypassing the public internet entirely. It uses BGP for dynamic routing and offers higher reliability, lower latency, and fixed bandwidth options, with regional redundancy. As a result, it is one of the two supported ways to connect an organization's network directly to Azure for hybrid deployments.

Why this answer

Azure ExpressRoute (B) is correct because it provides a private, dedicated connection between an on-premises network and Azure through a connectivity provider, bypassing the public internet. Site-to-Site VPN (D) is correct because it establishes an IPsec/IKE VPN tunnel over the public internet between an on-premises VPN device and an Azure VPN gateway, connecting entire networks. Azure Bastion (A) is not a network-to-network connection method; it provides secure RDP/SSH access to VMs through the Azure portal over TLS.

Point-to-Site VPN (C) connects an individual client computer to an Azure virtual network, not an on-premises network as a whole. Azure Front Door (E) is a global HTTP/HTTPS application delivery and load-balancing service, not a site-to-site connectivity solution.

Exam trap

The trap here is confusing Azure Bastion (a secure access service for VMs) with a network connectivity solution, or assuming Point-to-Site VPN can connect an entire on-premises network when it only supports individual client connections.

127
MCQmedium

A company stores sensitive job processing messages in Azure Queue Storage. They have a web application running on an Azure virtual machine in a VNet that reads and writes to the queue. The security team requires that only the web application's VM can access the queue, and all access from the public internet must be blocked. Which configuration should they implement?

A.Configure a service endpoint for Azure Storage on the VNet subnet and add a firewall rule allowing the VNet.
B.Deploy a private endpoint for the storage account in the same VNet and disable public network access on the storage account.
C.Route all traffic from the VNet through an Azure Firewall and create a NAT rule to the storage account.
D.Generate a shared access signature (SAS) token with narrow permissions and require the web app to use that token.
AnswerB

This is correct because a private endpoint assigns the storage account a private IP address from the VNet's address space, and all traffic to the storage account is routed over the Microsoft backbone rather than the public internet. Disabling public network access on the storage account then blocks every connection that does not originate from that private endpoint. Together these controls enforce a network-level isolation boundary, ensuring that only resources inside the VNet can reach the queue messages and no external client or public internet path exists.

Why this answer

Deploying a private endpoint for the storage account in the same VNet assigns the storage account a private IP from the VNet, effectively bringing the service into the VNet. Disabling public network access then ensures that all traffic to the queue must traverse the private endpoint, blocking any public internet access. This meets the requirement that only the web application's VM can access the queue, as the private endpoint is accessible only from within that VNet.

Exam trap

The trap here is that candidates often confuse service endpoints (which only extend VNet identity but leave the public endpoint exposed) with private endpoints (which fully remove public exposure), leading them to choose option A instead of B.

How to eliminate wrong answers

Option A is wrong because a service endpoint for Azure Storage on the VNet subnet only extends the VNet identity to the storage account but does not remove the public endpoint; the storage account remains accessible from the public internet unless additional firewall rules explicitly block all other traffic, which is not specified. Option C is wrong because routing traffic through an Azure Firewall with a NAT rule does not inherently block public internet access to the storage account; the storage account's public endpoint would still be reachable from the internet, and the NAT rule only translates traffic, not restrict source. Option D is wrong because a shared access signature (SAS) token with narrow permissions does not restrict network-level access; the storage account's public endpoint remains accessible from the internet, and any client with the SAS token (including potentially malicious actors) could access the queue from anywhere.

128
MCQhard

Your company, Contoso Ltd., has a hybrid environment with 500 on-premises Windows servers and 200 Azure VMs. The Azure VMs are spread across multiple subscriptions. You need to implement a centralized security monitoring solution using Microsoft Sentinel. The requirements are: - Collect security events from all on-premises servers. - Collect Azure activity logs and VM logs from all Azure subscriptions. - Detect and respond to threats using built-in and custom analytics. - Automatically remediate common threats such as disabling compromised user accounts. - Ensure compliance with regulatory standards (e.g., NIST 800-53). - Minimize administrative overhead and cost. What should you do?

A.Install Microsoft Monitoring Agent on on-premises servers and connect to a Log Analytics workspace. Enable Sentinel. Use Azure Automation runbooks for remediation.
B.Enable Microsoft Defender for Cloud on all subscriptions and install Defender for Endpoint on all servers. Forward logs to a third-party SIEM.
C.Create a Log Analytics workspace and enable Sentinel on the Free tier. Use KQL queries for detection and manual remediation.
D.Deploy Azure Arc on all on-premises servers. Use Azure Monitor Agent with Data Collection Rules to collect security events. Enable Microsoft Sentinel on a Log Analytics workspace. Configure analytics rules and automation rules with playbooks for remediation.
AnswerD

Deploying Azure Arc gives on-premises servers an Azure Resource Manager identity, allowing them to be governed with Azure Policy, Defender for Cloud, and Data Collection Rules just like Azure VMs. Azure Monitor Agent, configured via Data Collection Rules, efficiently collects Windows and Linux security events and forwards them to a Log Analytics workspace where Microsoft Sentinel ingests and analyzes them. Sentinel analytics rules detect threats and generate incidents, while automation rules trigger Azure Logic Apps playbooks for consistent, automated remediation. This is the current, fully supported hybrid SIEM/SOAR design that unifies on-premises and cloud security operations.

Why this answer

Option D is correct because it uses Azure Arc to onboard the 500 on-premises Windows servers into Azure, then Azure Monitor Agent (AMA) with Data Collection Rules (DCRs) to collect Windows security events into a Log Analytics workspace where Microsoft Sentinel is enabled; Sentinel's analytics rules provide built-in and custom threat detection, and automation rules with playbooks (Logic Apps) deliver automated remediation such as disabling compromised accounts, while Sentinel's compliance workbook and built-in NIST 800-53 content address regulatory requirements. This approach centralizes monitoring across all subscriptions and on-premises servers with minimal administrative overhead. Option A is outdated because the Microsoft Monitoring Agent (MMA) is deprecated in favor of AMA, and it lacks the Arc-based onboarding and DCR-based collection needed for modern hybrid coverage.

Option B does not meet the requirement for Microsoft Sentinel, since it forwards logs to a third-party SIEM instead. Option C relies on manual remediation and the Sentinel Free tier, which has limited data ingestion and retention, so it does not satisfy automated remediation or compliance needs.

129
MCQmedium

You are a security engineer for a large enterprise using Microsoft Sentinel. You have multiple workspaces deployed across different Azure regions to meet data residency requirements. You need to query data across all workspaces from a single query. You have set up a workspace as the 'central' workspace for cross-workspace queries. The central workspace has the necessary permissions to access the other workspaces. Which KQL operator should you use to include data from other workspaces in your query?

A.where
B.union
C.join
D.project
AnswerB

Correct. In Kusto Query Language (KQL), the union operator merges rows from two or more table expressions, and its workspace('workspace-id') function lets each branch point to another Log Analytics/Microsoft Sentinel workspace. This makes union the fundamental operator for cross-workspace queries: each table reference can be rewritten as workspace('<workspace>').<Table>, and the results are concatenated into a single result set.

Why this answer

The correct option is B, the union operator, because in Microsoft Sentinel and Azure Monitor Log Analytics, cross-workspace queries are performed by using union with workspace identifiers, such as union workspace("WorkspaceName").TableName, which combines rows from tables in the central workspace and the referenced workspaces into a single result set. This matches the scenario where the central workspace has permissions to query the other workspaces for data residency-compliant cross-region reporting. The where operator only filters rows within a single table and cannot reference another workspace, join correlates columns across tables but does not by itself aggregate multiple workspaces, and project only selects or renames columns from an existing result set.

Therefore, union is the only operator that satisfies the requirement to include data from other workspaces in one query.

130
MCQeasy

A company has an Azure virtual network with a subnet that hosts a public web application. They want to allow inbound HTTPS traffic (port 443) only from the source IP range 203.0.113.0/24, and block all other inbound traffic. They associate a network security group (NSG) with the subnet. What is the minimum number of inbound security rules required in the NSG to achieve this?

A.0 (no additional rules needed because the default rules block all inbound traffic)
B.1
C.2 (one allow rule for HTTPS and one deny rule for all other traffic)
D.3 (one allow HTTPS, one allow for Azure Load Balancer health probes, and one deny all)
AnswerB

One carefully scoped inbound rule is sufficient: allow TCP 443 from the specific IP range to the subnet's destination port 443 at a priority like 100. Because NSG rules are evaluated in numeric priority order and DenyAllInBound (65500) is the final default rule, all other inbound traffic from the internet is automatically blocked without additional deny rules. This also avoids redundant rule overhead while preserving the default deny posture.

Why this answer

NSGs include default inbound rules that already block all inbound traffic not explicitly allowed. By adding a single inbound rule to allow HTTPS (port 443) from the source IP range 203.0.113.0/24, all other inbound traffic is implicitly denied by the default deny-all rule (rule 65000). No explicit deny rule is needed, and no additional rules for Azure Load Balancer health probes are required unless the application is behind a load balancer, which is not specified in the scenario.

Exam trap

The trap here is that candidates often think they need an explicit deny rule to block all other traffic, forgetting that NSGs have a built-in default deny-all rule that automatically handles this.

How to eliminate wrong answers

Option A is wrong because default rules do not block all inbound traffic; they allow traffic within the virtual network and from Azure load balancers, so additional rules are needed to restrict access to only the specified IP range. Option C is wrong because an explicit deny rule is unnecessary; the default deny-all rule (priority 65000) already blocks all traffic not matched by a higher-priority allow rule. Option D is wrong because Azure Load Balancer health probes are only relevant if a load balancer is used, and the scenario does not mention one; adding such a rule would be unnecessary and not the minimum.

131
Multi-Selectmedium

Which TWO of the following are methods to enforce MFA in Microsoft Entra ID?

Select 2 answers
A.Identity Protection user risk policy
B.Password Protection
C.Security defaults
D.Conditional Access policy
E.Self-service password reset
AnswersC, D

Security defaults provide a predefined baseline of security settings that automatically enforce MFA for all users, requiring registration through the Microsoft Authenticator app and blocking legacy authentication protocols. This is a mandatory, tenant-wide enforcement mechanism that is enabled by default for new tenants, making it a direct and comprehensive method to enforce MFA.

Why this answer

Security defaults (C) is correct because it is a Microsoft-managed baseline that, once enabled, automatically requires all users to register for MFA and enforces MFA for privileged actions such as Azure portal, Microsoft Entra admin center, and Azure CLI/PowerShell access. Conditional Access policy (D) is correct because it is the primary granular method to enforce MFA, letting you create a policy that targets users/groups and cloud apps with a Grant control of 'Require multifactor authentication' (optionally combined with conditions like sign-in risk, location, or device state). Identity Protection user risk policy (A) does not itself enforce MFA; it can require a password change or, in some configurations, allow access, and MFA enforcement is typically achieved by pairing risk signals with a Conditional Access grant control.

Password Protection (B) only blocks weak or banned passwords via custom banned password lists and does not perform MFA. Self-service password reset (E) is a credential-reset feature and does not enforce MFA, even though it may require MFA as an authentication method for the reset process.

Exam trap

The trap here is that candidates often confuse Identity Protection user risk policy (Option A) as a direct MFA enforcement method, but it only detects risk and requires a Conditional Access policy to actually enforce MFA as a control.

132
MCQmedium

An organization uses Microsoft Defender for Cloud. They want to allow specific administrators to temporarily open RDP (port 3389) to a virtual machine only when needed, and for a limited time, while minimizing management overhead. Which Defender for Cloud feature should they use?

A.Azure Bastion
B.Just-in-time (JIT) VM access
C.Azure AD Privileged Identity Management (PIM)
D.Network Security Groups (NSGs)
AnswerB

Just-in-time (JIT) VM access in Microsoft Defender for Cloud dynamically creates NSG allow rules for specific ports and source IPs, and automatically removes them after the requested duration elapses (e.g., 1–3 hours). It supports approval workflows, audit logging, and integration with Azure AD, making it the only option here that provides time-limited, on-demand access to VMs. This directly meets the stated requirement.

Why this answer

Just-in-time (JIT) VM access in Microsoft Defender for Cloud allows administrators to temporarily open RDP (port 3389) to a virtual machine for a limited time, reducing exposure to brute-force attacks. It integrates with Azure Network Security Groups (NSGs) and Azure Firewall to automatically lock down inbound traffic when not in use, minimizing management overhead by eliminating the need for manual NSG rule changes.

Exam trap

The trap here is that candidates confuse Azure Bastion (persistent secure access) with JIT (time-limited port opening), or mistakenly think PIM controls network access rather than role activation.

How to eliminate wrong answers

Option A is wrong because Azure Bastion provides persistent, secure RDP/SSH access via TLS over the Azure portal without exposing public IPs, but it does not offer time-limited, on-demand port opening; it is always available once deployed. Option C is wrong because Azure AD Privileged Identity Management (PIM) manages just-in-time activation of Azure AD roles and Azure resource roles (e.g., Contributor), not network-level port access to VMs. Option D is wrong because Network Security Groups (NSGs) are the underlying mechanism to allow or deny traffic, but they require manual rule creation and removal, which increases management overhead and does not provide automated, time-limited access.

133
MCQhard

Your organization uses Microsoft Entra ID to manage access for employees and partners. You need to implement a solution that allows partners to self-service request access to specific applications, with approval from their manager, and access expires after 30 days. Which feature should you use?

A.Entitlement Management access packages
B.Azure AD B2B collaboration
C.Privileged Identity Management (PIM)
D.Conditional Access with session restrictions
AnswerA

Entitlement Management access packages are the correct choice because they are specifically designed to govern end-user access to resources such as groups, applications, and SharePoint sites. These packages bundle resources with configurable policies for request approval, recurring access reviews, expiration, and automatic revocation when the policy ends. This enables self-service access requests while maintaining an auditable lifecycle for both internal and external users.

Why this answer

Entitlement Management access packages are designed to allow external partners to request access to specific applications through a self-service portal. The feature supports approval workflows (e.g., manager approval) and automatically enforces time-bound access, such as a 30-day expiration. This directly matches the requirement for partner self-service with approval and expiration.

Exam trap

The trap here is that candidates often confuse Azure AD B2B collaboration (which handles identity provisioning) with Entitlement Management (which handles the full lifecycle of access requests, approvals, and expiration), leading them to pick B2B collaboration as the answer.

How to eliminate wrong answers

Option B (Azure AD B2B collaboration) is wrong because it only provides the mechanism to invite external users into the tenant and assign them access, but it does not include built-in self-service request workflows, approval processes, or automatic expiration policies. Option C (Privileged Identity Management (PIM)) is wrong because it is focused on just-in-time privileged role activation for administrators and does not handle self-service access requests for non-privileged applications or partner scenarios. Option D (Conditional Access with session restrictions) is wrong because it enforces access policies (e.g., session timeouts) on already authenticated users, but it does not provide any self-service request, approval, or expiration lifecycle management for partner access.

134
MCQeasy

You are configuring Microsoft Sentinel to ingest logs from Azure Active Directory. Which two data connectors are necessary to collect sign-in logs and audit logs?

A.Azure Activity and Azure Active Directory Audit logs
B.Office 365 and Azure Active Directory Sign-in logs
C.Azure Active Directory Sign-in logs and Azure Active Directory Audit logs
D.Security Events and Azure Active Directory Sign-in logs
AnswerC

Azure Active Directory Sign-in Logs ingest authentication and authorization events, such as successful and failed user sign-ins, conditional access results, and MFA challenges. Azure Active Directory Audit Logs capture all directory-management activities, including user creation, group membership changes, password resets, and application role assignments. These two complementary connectors provide the full AAD security telemetry needed to monitor both user access and administrative changes in Microsoft Sentinel.

Why this answer

To collect sign-in logs and audit logs in Microsoft Sentinel, you need the Azure Active Directory Sign-in logs connector for sign-in activity and the Azure Active Directory Audit logs connector for directory changes and user management events. These two connectors directly correspond to the two log categories required by the question.

Exam trap

The trap here is that candidates confuse Azure Activity logs (subscription-level) with Azure AD Audit logs (tenant-level), or assume Office 365 logs include Azure AD sign-in events, when in fact each log type requires its own dedicated connector.

How to eliminate wrong answers

Option A is wrong because Azure Activity logs capture subscription-level control plane events (e.g., resource creation), not Azure AD sign-in or audit logs. Option B is wrong because Office 365 connector collects Exchange, SharePoint, and Teams logs, not Azure AD sign-in logs; the Azure AD Sign-in logs connector is required separately. Option D is wrong because Security Events are Windows security logs from virtual machines, not Azure AD sign-in or audit logs.

135
Drag & Dropmedium

Drag and drop the steps to implement Azure AD Identity Protection to detect risky sign-ins into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Identity Protection policies are configured under Security, with user risk policy settings.

136
MCQmedium

You are a security engineer for a company that uses Azure SQL Database. The database contains sensitive financial data and is currently encrypted with Transparent Data Encryption (TDE) using a service-managed key. A new policy requires that the TDE protector be a customer-managed key stored in Azure Key Vault, and that the key be automatically rotated every 90 days. You have created an Azure Key Vault and generated a key. What should you do next to meet the policy?

A.Create a new Azure SQL Database with the customer-managed key as the TDE protector, and migrate the data.
B.Configure the SQL server's TDE protector to use the customer-managed key from Key Vault, and enable auto-rotation on the key.
C.Enable Always Encrypted on the database and use the customer-managed key for column encryption.
D.Store the customer-managed key in Azure Key Vault and configure the database to use it for backup encryption.
AnswerB

To use a customer-managed key for TDE, you must configure the Azure SQL logical server to use the key from Key Vault as the TDE protector. Azure Key Vault supports automatic key rotation, which can be set to rotate every 90 days. This satisfies both the requirement for customer-managed key and automatic rotation. The SQL server must have a managed identity with appropriate permissions to access the key vault.

Why this answer

To meet the policy, you must set the Azure SQL logical server's TDE protector to the customer-managed key stored in Azure Key Vault. Azure Key Vault supports automatic key rotation, which can be configured for 90-day rotation. This ensures the database is encrypted with a customer-managed key and the key is rotated regularly.

Other options either address different features (Always Encrypted) or involve unnecessary migration.

Exam trap

The trap here is thinking that Always Encrypted or backup encryption settings are needed for TDE with customer-managed keys.

137
MCQmedium

A company has enabled Microsoft Defender for Cloud on all subscriptions. The security team wants to ensure that all virtual machines have vulnerability assessment solutions installed. What should they configure?

A.Enable Azure Update Management for all VMs
B.Enable the Vulnerability Assessment solution in Defender for Cloud and set it to 'On'
C.Create an Azure Policy to audit VMs without vulnerability assessment
D.Use Azure Automation to run a script that installs a vulnerability scanner
AnswerB

The Vulnerability Assessment solution in Microsoft Defender for Cloud, when set to 'On', auto-provisions a built-in scanner (Qualys or Microsoft Defender Vulnerability Management) to supported machines. This continuously scans for known CVEs, misconfigurations, and security weaknesses, and surfaces findings in the Defender for Cloud recommendations and Secure Score. It is the native, integrated way to meet the requirement of vulnerability assessment across all VMs.

Why this answer

Microsoft Defender for Cloud provides a built-in Vulnerability Assessment solution that can be enabled at the subscription level. When set to 'On', it automatically deploys the Qualys or Microsoft threat and vulnerability management agent to all supported Azure VMs, ensuring continuous vulnerability scanning without manual intervention.

Exam trap

The trap here is that candidates often confuse 'auditing' (Option C) with 'remediation' — an Azure Policy audit only checks compliance, but the question asks to ensure the solution is installed, which requires enabling the built-in Defender for Cloud vulnerability assessment solution.

How to eliminate wrong answers

Option A is wrong because Azure Update Management focuses on OS patch compliance, not vulnerability assessment; it does not scan for software vulnerabilities or misconfigurations. Option C is wrong because an Azure Policy to audit VMs without vulnerability assessment only reports non-compliance but does not install or enable the solution; it requires a separate remediation task or initiative to deploy the agent. Option D is wrong because using Azure Automation to run a custom script is a manual, non-native approach that lacks integration with Defender for Cloud's centralized vulnerability reporting and auto-provisioning capabilities.

138
MCQhard

Refer to the exhibit. You are reviewing user sign-in activity using Microsoft Graph API. The user has not performed an interactive sign-in since December 1, but had a non-interactive sign-in on December 5. You need to determine if the user should be considered inactive for a policy that defines inactivity as no interactive sign-in for 30 days. Today is December 15. What should you do?

A.Check if the user has any sign-in in the last 30 days; since there is a non-interactive sign-in, the user is active.
B.Use the lastNonInteractiveSignInDateTime as the last sign-in time, so the user is not inactive.
C.Use the lastSignInDateTime of December 1, which is only 14 days ago, so the user is not inactive.
D.The user is inactive because the account is enabled but there is no interactive sign-in in the last 30 days.
AnswerC

This is correct because lastSignInDateTime corresponds to the user's last successful interactive sign-in, which occurred on December 1. As of the review date (presumably December 15), that is only 14 days ago—well under the 30-day threshold defined by the policy. Therefore, the user is not inactive, and no further action is required.

Why this answer

The policy defines inactivity as no interactive sign-in for 30 days. The user's last interactive sign-in was on December 1, which is only 14 days ago as of December 15, so the user is not inactive. Microsoft Graph API's lastSignInDateTime property specifically tracks interactive sign-ins, while non-interactive sign-ins are tracked separately via lastNonInteractiveSignInDateTime and do not reset the interactive inactivity timer.

Exam trap

The trap here is that candidates confuse 'any sign-in' with 'interactive sign-in' and incorrectly assume non-interactive sign-ins reset the inactivity timer, when the policy explicitly specifies only interactive sign-ins count.

How to eliminate wrong answers

Option A is wrong because the policy explicitly defines inactivity based on interactive sign-ins, not any sign-in; non-interactive sign-ins (e.g., token refreshes, service-to-service calls) do not count toward the interactive inactivity threshold. Option B is wrong because lastNonInteractiveSignInDateTime is irrelevant for a policy that only considers interactive sign-ins; using it would incorrectly treat the user as active when they have not performed an interactive sign-in for 30 days. Option D is wrong because the user is not inactive—the last interactive sign-in was only 14 days ago, which is within the 30-day window, so the account being enabled does not change the inactivity status.

139
MCQhard

Your organization uses Microsoft Sentinel and has enabled User and Entity Behavior Analytics (UEBA). You need to investigate a possible insider threat where a user is accessing sensitive data from unusual locations. Which Sentinel feature should you use to visualize the user's activities and related entities?

A.Hunting queries
B.UEBA investigation insights and entity pages
C.Analytics rules
D.Workbooks
AnswerB

Microsoft Sentinel's UEBA builds entity pages that consolidate a user, device, or other entity's activity into a single pane, including a timeline, related entities, and behavioral analytics. These pages surface investigation insights like anomalous logon patterns, impossible travel, and peer-group deviations, which are automatically generated via machine learning baselines. This gives analysts an entity-centric, visual starting point for investigation, making it the exact feature that matches the question's requirement for timeline and related-entity visualization.

Why this answer

UEBA in Microsoft Sentinel provides investigation insights and entity pages that aggregate user activities, related entities, and behavioral anomalies into a visual timeline. This allows you to see a user's access patterns from unusual locations and correlate them with other entities like devices or IP addresses, making it the correct feature for investigating insider threats.

Exam trap

The trap here is that candidates confuse the proactive, query-based nature of Hunting queries with the reactive, visual investigation capabilities of UEBA entity pages, leading them to select Option A when they need to investigate a specific user's behavior.

How to eliminate wrong answers

Option A is wrong because Hunting queries are proactive searches for threats using KQL, not a visual investigation tool for a specific user's activities and related entities. Option C is wrong because Analytics rules are used to generate alerts based on predefined conditions, not to visualize or investigate a user's historical behavior and entity relationships. Option D is wrong because Workbooks are customizable dashboards for reporting and monitoring, not designed for interactive, entity-centric investigation of a single user's activities.

140
MCQmedium

A company is enabling Azure Disk Encryption (ADE) on Windows virtual machines. They have enabled soft-delete on Azure Key Vault and configured a Key Encryption Key (KEK). However, the disk encryption fails with an error indicating that the key vault does not have the required permissions. What is the most likely missing configuration?

A.The Key Vault access policy does not grant the Azure Disk Encryption service principal the 'unwrap key' and 'wrap key' permissions.
B.The Key Vault firewall is blocking the Azure platform.
C.The VM does not have a managed identity assigned.
D.The KEK is in a different Azure region than the VM.
AnswerA

Correct. Azure Disk Encryption (ADE) relies on the Azure Disk Encryption service principal (AzureDiskEncryption) to access your Key Vault. When a KEK is used, that service principal must be granted the 'unwrap key' and 'wrap key' permissions in the Key Vault's access policy; otherwise, the service cannot decrypt or re-encrypt the disk encryption key. The error you see is a classic permissions failure, not a network or identity issue, because the service principal lacks the required cryptographic operations on the vault's keys.

Why this answer

Azure Disk Encryption (ADE) requires the Azure Disk Encryption service principal (also known as the Azure Disk Encryption service) to have 'unwrap key' and 'wrap key' permissions on the Key Vault. These permissions allow the service to encrypt and decrypt the disk encryption keys using the Key Encryption Key (KEK). Without these specific cryptographic permissions, the encryption operation fails, even if soft-delete and a KEK are correctly configured.

Exam trap

The trap here is that candidates often confuse the required permissions for ADE with general Key Vault access policies (e.g., 'get' and 'list') or mistakenly think a managed identity or firewall configuration is the root cause, rather than recognizing the need for explicit 'wrap key' and 'unwrap key' permissions for the Azure Disk Encryption service principal.

How to eliminate wrong answers

Option B is wrong because the Key Vault firewall, if enabled, would block external access, but the error message specifically indicates a permissions issue, not a network connectivity problem. Option C is wrong because a managed identity is not required for ADE on Windows VMs; ADE uses the Azure Disk Encryption service principal, not the VM's identity, to access the Key Vault. Option D is wrong because the KEK can be in a different region than the VM; ADE supports cross-region key references as long as the Key Vault is in the same Azure subscription and the service principal has the required permissions.

141
MCQmedium

A company uses Azure Bastion to provide secure RDP and SSH access to Azure VMs without public IPs. Recently, a security audit recommended logging all connections to Bastion. What should you enable?

A.Azure Monitor alerts for Bastion resource health
B.Azure Activity Logs for the Bastion resource
C.Network Security Group flow logs on the subnet containing Bastion
D.Diagnostic settings on the Bastion resource to stream Bastion logs to a Log Analytics workspace
AnswerD

Diagnostic settings on the Bastion resource are the correct method to collect Azure Bastion's resource logs, specifically the BastionAuditLog, and stream them to a Log Analytics workspace. Once enabled, these logs capture RDP/SSH session events including the source IP address, the target VM, the username, the connection attempt result, and session duration. This data can then be queried with KQL to audit for compliance, investigate unauthorized access, and generate reports on Bastion usage—exactly the requirement in this scenario.

Why this answer

Azure Bastion does not support Network Security Group flow logs or Azure Activity Logs for capturing connection-level details like source IP, target VM, or session duration. Diagnostic settings on the Bastion resource must be enabled to stream Bastion logs (e.g., BastionAuditLogs) to a Log Analytics workspace, which records all RDP/SSH connection attempts and session metadata. This is the only way to meet the audit requirement for logging all connections to Bastion.

Exam trap

The trap here is that candidates assume NSG flow logs (Option C) capture all network traffic, but Azure Bastion operates at a higher layer and its connection logs are only available through diagnostic settings, not through traditional network-level logging.

How to eliminate wrong answers

Option A is wrong because Azure Monitor alerts for resource health only notify about service availability or degradation, not connection-level logging. Option B is wrong because Azure Activity Logs record control-plane operations (e.g., creating or deleting a Bastion resource), not data-plane connection events like RDP/SSH sessions. Option C is wrong because Network Security Group flow logs capture IP traffic through NSGs, but Azure Bastion bypasses NSGs on the subnet (it uses a dedicated, hardened service endpoint) and flow logs do not include Bastion-specific session details.

142
MCQmedium

A storage account should be reachable only from a specific subnet over the Microsoft backbone, while keeping the public endpoint firewall restricted. Which feature should be used?

A.Application Security Group
B.Azure Bastion
C.Service endpoint for Microsoft.Storage with storage firewall rules
D.Public IP prefix
AnswerC

A service endpoint for Microsoft.Storage extends the virtual network identity to the storage account, and when combined with storage firewall rules that deny all traffic except from the chosen subnet(s), it ensures the storage account is reachable only from that specific virtual network/subnet. This is the standard Azure mechanism for restricting PaaS storage to a private network segment, as the firewall rule blocks public internet and other sources while the service endpoint routes traffic from the subnet.

Why this answer

A service endpoint for Microsoft.Storage extends your virtual network private address space and the identity of your VNet to the Azure Storage service over the Microsoft backbone. By combining the service endpoint with a storage firewall rule that restricts access to only that specific subnet, you ensure the storage account is reachable only from that subnet while keeping the public endpoint firewall restricted to deny all other traffic.

Exam trap

The trap here is that candidates often confuse service endpoints with private endpoints, but the question explicitly requires keeping the public endpoint firewall restricted, which is exactly what service endpoints support by allowing selective subnet access through firewall rules without creating a private IP connection.

How to eliminate wrong answers

Option A is wrong because an Application Security Group is a logical grouping of VMs based on application workloads for network security group filtering, not a mechanism to restrict storage account access to a specific subnet. Option B is wrong because Azure Bastion provides secure RDP/SSH connectivity to VMs directly in the Azure portal over SSL, without exposing public IPs, but it does not control access to storage accounts. Option D is wrong because a Public IP prefix reserves a contiguous range of public IP addresses for your Azure resources, but it does not restrict storage account access to a specific subnet or enforce routing over the Microsoft backbone.

143
MCQmedium

A company stores sensitive healthcare data in Azure SQL Database. They need to encrypt specific columns containing patient diagnosis codes so that even database administrators with the 'sysadmin' role cannot view the plaintext. The application must be able to perform equality searches (WHERE clauses) on the encrypted columns. Which encryption technology should they implement?

A.Transparent Data Encryption (TDE)
B.Always Encrypted (deterministic encryption)
C.Row-Level Security (RLS)
D.Dynamic Data Masking (DDM)
AnswerB

Always Encrypted is the correct choice because it encrypts selected column data between the client application and the database engine, with the column encryption keys never being passed to or stored in SQL Database in plaintext. The client-side driver performs encryption and decryption, so the database engine only ever sees ciphertext; even a sysadmin with full server access cannot view the sensitive values without the client-held Column Master Key. Deterministic encryption is specifically suitable here because it allows equality comparison and inner join operations on the ciphertext, enabling indexed equality searches on fields like national identifiers or medical record numbers while still shielding the values from DBAs.

Why this answer

Always Encrypted with deterministic encryption ensures that sensitive columns are encrypted at the client side, so the encryption keys are never revealed to the database engine, including sysadmin roles. Deterministic encryption generates the same ciphertext for the same plaintext, enabling equality searches (WHERE clauses) on encrypted columns without exposing plaintext data to the server.

Exam trap

The trap here is that candidates confuse encryption at rest (TDE) with client-side column-level encryption, failing to recognize that TDE does not protect data from privileged users who can run queries, while Always Encrypted does by keeping keys off the server.

How to eliminate wrong answers

Option A is wrong because Transparent Data Encryption (TDE) encrypts the entire database at rest (pages on disk) but does not protect data from database administrators who have access to the decrypted data in memory or via queries. Option C is wrong because Row-Level Security (RLS) controls access to rows based on user predicates but does not encrypt data; it relies on database permissions and can be bypassed by privileged users. Option D is wrong because Dynamic Data Masking (DDM) obfuscates data in query results for non-privileged users but does not encrypt the underlying data; privileged users like sysadmin can still view plaintext by querying directly.

144
MCQmedium

A company uses Azure SQL Database for a critical application. Security policy requires that all client connections to the database use at least TLS 1.2 encryption. What configuration change must be made to enforce this requirement?

A.Configure the minimum TLS version in the SQL server's settings.
B.Enable Transparent Data Encryption (TDE).
C.Update the server firewall rules to allow only specific IP addresses.
D.Implement Always Encrypted for all sensitive columns.
AnswerA

Configuring the minimum TLS version at the Azure SQL logical server level directly enforces the encryption-protocol policy for all incoming client connections. When set to 1.2, the server rejects any TLS handshake attempt using 1.0 or 1.1, ensuring only modern, secure transport is used. This is the specific control that guarantees data is encrypted in transit between clients and the database.

Why this answer

To enforce that all client connections to Azure SQL Database use at least TLS 1.2, you must configure the minimum TLS version at the SQL server level. This setting overrides the default behavior, which allows older, less secure TLS versions, and ensures that any connection attempt using TLS 1.0 or 1.1 is rejected. The configuration is made in the Azure portal under the SQL server's 'Connectivity' settings or via the 'Minimal TLS Version' property in ARM templates or PowerShell.

Exam trap

The trap here is that candidates often confuse encryption at rest (TDE) or column-level encryption (Always Encrypted) with encryption in transit, leading them to select options that do not enforce the TLS protocol version.

How to eliminate wrong answers

Option B is wrong because Transparent Data Encryption (TDE) encrypts data at rest, not data in transit, so it does not enforce TLS version requirements. Option C is wrong because firewall rules control network access by IP address, not the encryption protocol or TLS version used for the connection. Option D is wrong because Always Encrypted protects sensitive columns with client-side encryption, but it does not enforce a minimum TLS version for the overall connection; it can even work over TLS 1.0 if the server allows it.

145
MCQeasy

A security team wants to receive a weekly email summary of the security posture of all their Azure subscriptions, including the Secure Score, top recommendations, and the number of healthy resources. Which Microsoft Defender for Cloud feature should they configure?

A.Continuous export to a Log Analytics workspace
B.Email notifications for weekly digest
C.Automation rules to trigger a Logic App on a schedule
D.Workflow automation to export data daily
AnswerB

Within Microsoft Defender for Cloud's 'Email notifications' settings, the 'Send weekly digest' checkbox enables an automatic email containing your Secure Score, top recommendations, and number of healthy resources. This digest can be addressed to all users with specific roles or to a custom list of email addresses, and it is delivered once per week without any additional Logic App or export configuration. It is the only first-party feature that matches the security team's requirement for a weekly email summary.

Why this answer

The 'Email notifications for weekly digest' feature in Microsoft Defender for Cloud is specifically designed to send a weekly summary of security posture, including Secure Score, top recommendations, and healthy resources, directly to specified email recipients. This feature is configured under Defender for Cloud's 'Email notifications' settings, where you can enable the weekly digest and define the recipients.

Exam trap

The trap here is that candidates confuse the weekly digest with workflow automation or continuous export, assuming any automated export can be scheduled to send emails, but only the dedicated 'Email notifications for weekly digest' feature provides the exact preformatted summary without custom Logic App development.

How to eliminate wrong answers

Option A is wrong because Continuous export to a Log Analytics workspace is used for streaming security data (e.g., alerts, recommendations) to a workspace for custom analysis or retention, not for sending a preformatted weekly email summary. Option C is wrong because Automation rules trigger actions (e.g., Logic Apps) based on specific events like new alerts or recommendations, not on a schedule for a weekly digest; scheduling requires a separate Logic App trigger. Option D is wrong because Workflow automation triggers Logic Apps or runbooks in response to Defender for Cloud events (e.g., when a recommendation is created), not for scheduled daily exports; daily exports to email are not a native feature.

146
MCQeasy

A security analyst receives a high-severity alert in Microsoft Sentinel indicating a potential brute-force attack against an Azure VM. The analyst wants to automatically block the attacker IP for 24 hours. What is the most efficient way to achieve this?

A.Create an automation rule in Sentinel that runs a playbook to add a deny NSG rule.
B.Enable Just-in-Time VM access to restrict all RDP traffic.
C.Create an Azure Policy to deny all traffic from the attacker IP.
D.Manually add a deny rule to the NSG attached to the VM's subnet.
AnswerA

An automation rule in Microsoft Sentinel triggers a playbook—a Logic Apps workflow—that can programmatically add a deny rule to the network security group (NSG) attached to the VM's subnet, blocking the attacker's source IP. This provides immediate and consistent containment without manual intervention, making it the correct response for a high-severity alert requiring rapid network-level blocking.

Why this answer

It leverages Microsoft Sentinel's automation rules to trigger a playbook that programmatically adds a deny Network Security Group (NSG) rule, blocking the attacker's IP for a specified duration. This is the most efficient approach as it automates the response without manual intervention, directly modifying the NSG attached to the VM's subnet to drop inbound traffic from the malicious IP.

Exam trap

The trap here is that candidates may confuse Azure Policy (which is for compliance and governance) with NSG rules (which are for network traffic control), or mistakenly think Just-in-Time VM access can block a specific IP, when it only manages port access timing.

How to eliminate wrong answers

Option B is wrong because Just-in-Time (JIT) VM access controls inbound RDP/SSH access via Azure Security Center, but it does not block a specific attacker IP; it reduces the attack surface by opening ports only when needed, not by adding a deny rule for a particular address. Option C is wrong because Azure Policy is used for enforcing organizational compliance and governance rules (e.g., requiring specific tags or SKUs), not for real-time, dynamic network access control like blocking an IP address. Option D is wrong because manually adding a deny rule to the NSG is inefficient and not automated; it requires human intervention, which delays response time and is not suitable for a high-severity alert requiring immediate action.

147
MCQeasy

You have an Azure virtual machine that hosts a web application. You need to allow inbound HTTP (80) and HTTPS (443) traffic from the internet to this VM only. You also need to allow outbound traffic to the internet from the VM. You want to use a managed Azure service with minimal configuration. What should you use?

A.Azure Application Gateway
B.Azure Firewall
C.Network Security Group (NSG)
D.Azure Bastion
AnswerC

A Network Security Group (NSG) is the correct, lightweight choice because it acts as a stateful, distributed packet filter that you can attach directly to the VM's NIC or its subnet. You can define allow/deny rules for inbound HTTP/HTTPS (e.g., ports 80/443) while relying on the default outbound internet access that NSGs permit unless you explicitly block it. It is free, requires no additional infrastructure, and its simplicity aligns perfectly with the requirement to secure a single VM hosting a web application.

Why this answer

A Network Security Group (NSG) is the correct choice because it is a managed Azure service that provides a stateful, layer-3/4 firewall for filtering inbound and outbound traffic to a virtual machine. With minimal configuration, you can create inbound rules to allow HTTP (TCP/80) and HTTPS (TCP/443) from the internet (source 'Internet' or 'Any') and an outbound rule to allow all traffic to the internet (default outbound rule already allows this). NSGs are directly associated with a VM's subnet or network interface, making them the simplest managed solution for this scenario.

Exam trap

The trap here is that candidates often overthink and choose Azure Firewall or Application Gateway for simple traffic filtering, forgetting that an NSG is the most lightweight, cost-effective, and minimal-configuration managed service for basic inbound/outbound access control on a single VM.

How to eliminate wrong answers

Option A is wrong because Azure Application Gateway is a layer-7 load balancer and web application firewall (WAF) that requires additional configuration for routing rules, health probes, and SSL termination; it is overkill for simply allowing inbound HTTP/HTTPS and outbound internet traffic to a single VM. Option B is wrong because Azure Firewall is a fully managed, centralized network security service designed for hub-and-spoke topologies and enterprise-level traffic inspection, not for minimal configuration on a single VM; it introduces unnecessary complexity and cost. Option D is wrong because Azure Bastion is a managed service for secure RDP/SSH access to VMs via the Azure portal, not for allowing HTTP/HTTPS inbound traffic or general outbound internet traffic.

148
MCQhard

Your organization has deployed Azure Front Door Premium with Web Application Firewall (WAF) policy in front of an Azure App Service. You need to ensure that only traffic from Azure Front Door is allowed to reach the App Service, and all other traffic is blocked. Which configuration should you implement?

A.Configure IP restrictions on the App Service to allow only the Azure Front Door service tag AzureFrontDoor.Backend.
B.Configure the App Service to require client certificates and configure Azure Front Door to present a certificate.
C.Set the App Service access restrictions to deny all and then add a rule to allow the Azure Front Door service tag AzureFrontDoor.Frontend.
D.Configure a WAF policy to block all requests that do not contain the X-Azure-FDID header.
AnswerA

The AzureFrontDoor.Backend service tag covers the IP ranges that Azure Front Door's origin-facing servers use when they forward requests to your App Service. By adding an access restriction that allows only this service tag, any request that does not originate from those backend IPs—including direct traffic to the App Service's public URL—is rejected. This is the standard, low-overhead method for locking down an App Service origin to only receive traffic from Front Door.

Why this answer

The Azure Front Door Premium service tag 'AzureFrontDoor.Backend' represents the backend IP address range used by Azure Front Door to forward traffic to the origin. By configuring IP restrictions on the App Service to allow only this service tag, you ensure that only traffic originating from Azure Front Door can reach the App Service, effectively blocking all other traffic.

Exam trap

The trap here is confusing the Azure Front Door service tags 'AzureFrontDoor.Backend' and 'AzureFrontDoor.Frontend', where candidates often select the frontend tag (Option C) thinking it represents the traffic source, but the backend tag is required to allow the actual forwarding traffic from Front Door to the origin.

How to eliminate wrong answers

Option B is wrong because requiring client certificates on the App Service and having Azure Front Door present a certificate authenticates the Front Door instance to the App Service, but it does not block traffic that bypasses Front Door entirely; a direct request to the App Service without a valid certificate would be rejected, but this does not prevent other traffic from reaching the App Service if the certificate requirement is misconfigured or bypassed. Option C is wrong because the service tag 'AzureFrontDoor.Frontend' represents the Front Door frontend IP addresses used for incoming client traffic, not the backend IPs that forward requests to the origin; using this tag would allow traffic from Front Door's edge but not the actual backend traffic, potentially blocking legitimate Front Door requests. Option D is wrong because configuring a WAF policy to block requests without the 'X-Azure-FDID' header is a valid additional security measure, but it does not prevent direct traffic to the App Service that bypasses Front Door entirely; the WAF policy is applied at the Front Door level, not at the App Service, so requests sent directly to the App Service would not be inspected by the WAF.

149
MCQmedium

You have an Azure SQL Database that contains sensitive customer data. You need to ensure that database administrators (DBAs) cannot view the data in the 'CreditCard' column. What should you implement?

A.Enable Transparent Data Encryption (TDE) on the database.
B.Use Always Encrypted with column encryption key stored in Azure Key Vault.
C.Implement Azure SQL Auditing for the database.
D.Configure Dynamic Data Masking for the 'CreditCard' column.
AnswerB

Always Encrypted is a client-side encryption technology where sensitive column data is encrypted in the application layer before it is ever sent to SQL Database. The column encryption key is stored in Azure Key Vault and never exposed to the database engine, so SQL Server sees only ciphertext and returns only ciphertext to the client. Even if a DBA has full server permissions, they cannot decrypt the data without the column encryption key, making it the only option here that truly prevents DBAs from viewing plaintext CreditCard data.

Why this answer

Always Encrypted ensures that sensitive data, such as the 'CreditCard' column, is encrypted at rest and in transit, and that the encryption keys are never exposed to the database engine. By storing the column encryption key in Azure Key Vault, DBAs with full server access cannot decrypt the data because they lack access to the key material. This provides client-side encryption where only authorized applications with the key can view plaintext data.

Exam trap

The trap here is that candidates often confuse Dynamic Data Masking (which can be bypassed by privileged users) with Always Encrypted (which provides cryptographic separation of duties), leading them to choose masking as a simpler solution without realizing it does not protect against DBAs.

How to eliminate wrong answers

Option A is wrong because Transparent Data Encryption (TDE) encrypts the entire database at rest but does not prevent DBAs from viewing data while the database is online; TDE protects against offline theft of physical files, not against authorized database administrators. Option C is wrong because Azure SQL Auditing logs database events but does not restrict or encrypt data access; it only provides an audit trail of who viewed data, not a control to prevent viewing. Option D is wrong because Dynamic Data Masking obfuscates the 'CreditCard' column in query results for non-privileged users, but DBAs with elevated permissions (e.g., db_owner) can bypass the mask by using direct queries or altering the masking rule.

150
Multi-Selectmedium

Which TWO are benefits of using Microsoft Sentinel's automation rules? (Choose two.)

Select 2 answers
A.Aggregate multiple incidents into a single incident.
B.Create new analytics rules based on incident patterns.
C.Automatically query external threat intelligence feeds.
D.Trigger a playbook when an incident is created or updated.
E.Automatically assign incidents to a specific analyst or team.
AnswersD, E

A primary benefit of automation rules is the 'Run playbook' action, which can be triggered automatically when an incident is created or updated. This enables incident response teams to execute Logic Apps that perform enrichment, containment, or remediation steps without manual intervention. Playbooks can be invoked with the incident as context, making it easy to gather data, block indicators, or send notifications.

Why this answer

Option D is correct because Microsoft Sentinel automation rules can define conditions (such as incident creation or update) and then invoke a playbook (Logic App) as the action, enabling automated response workflows. Option E is correct because automation rules support an 'Assign owner' action, letting you automatically route incidents to a specific analyst or team based on rule conditions. Options A, B, and C are not benefits of automation rules: incident aggregation/merging is handled by the incident merging feature rather than automation rules, analytics rules are created manually or via templates/API rather than generated from incident patterns by automation rules, and querying external threat intelligence feeds is performed through threat intelligence connectors, watchlists, or analytics rule queries, not automation rules.

Exam trap

The trap here is that candidates confuse automation rules with analytics rules or playbooks, mistakenly thinking automation rules can create rules or query external feeds, when in fact automation rules only respond to incidents with predefined actions.

Page 1

Page 2 of 9

Page 3

All pages