Courseiva

Microsoft Azure Security Engineer Associate AZ-500 (AZ-500) — Questions 151–225

617 questions total · 9pages · All types, answers revealed

Page 2

Page 3 of 9

Page 4
151
MCQhard

You are a security analyst using Microsoft Sentinel. You need to create an analytics rule that triggers an incident when more than 10 failed sign-ins occur from the same IP address within 5 minutes. The rule should use a KQL query. Which query should you use?

A.SigninLogs | where ResultType !in ("0","50125") // failed attempts | summarize Count = count() by IPAddress, bin(TimeGenerated, 5m) | where Count > 10
B.SigninLogs | where ResultType != "0" | make-series Count=count() default=0 on TimeGenerated from ago(5m) to now() step 5m by IPAddress
C.SigninLogs | where ResultType == "0" | summarize Count = count() by IPAddress, bin(TimeGenerated, 5m) | where Count > 10
D.SigninLogs | where ResultType == "0" | summarize Count = count() by IPAddress, bin(time-generated, 5m) | where Count > 10
AnswerA

This query correctly groups failed sign-ins by IP and 5-minute bin, and filters for >10.

Why this answer

It filters for failed sign-ins by excluding successful results (ResultType '0' and '50125', where '50125' is a non-failure code), then uses `summarize` with `bin(TimeGenerated, 5m)` to count failed attempts per IP address within 5-minute windows, and finally filters for counts exceeding 10. This directly meets the requirement to trigger an incident when more than 10 failed sign-ins occur from the same IP within 5 minutes.

Exam trap

The trap here is that candidates often confuse the ResultType values, mistakenly filtering for successful sign-ins (ResultType == '0') instead of failed sign-ins, or they use `make-series` which is designed for time-series analysis rather than event counting with threshold filtering.

How to eliminate wrong answers

Option B is wrong because `make-series` creates a time series with default values, which is not appropriate for counting discrete events and does not filter for failed sign-ins (it includes all ResultType values except '0'). Option C is wrong because it filters for successful sign-ins (`ResultType == '0'`), which is the opposite of what is needed. Option D is wrong because it filters for successful sign-ins (`ResultType == '0'`) and uses an incorrect field name `time-generated` (should be `TimeGenerated`), which would cause the query to fail or return no results.

152
Multi-Selecthard

A team wants to deploy Sentinel content consistently across workspaces. Which two approaches are appropriate?

Select 2 answers
A.Manually copy screenshots of rules
B.Use Content Hub solutions where available
C.Store incidents in Azure Key Vault
D.Use infrastructure-as-code or automation for analytic rules and workbooks
AnswersB, D

Content Hub solutions are Microsoft Sentinel's packaged, versioned bundles of data connectors, analytic rules, workbooks, and playbooks. Installing the same solution across multiple workspaces guarantees a common content baseline and simplifies updates because solutions can be centrally managed. This is correct because it directly addresses consistent, repeatable content deployment at scale.

Why this answer

Content Hub solutions in Azure Sentinel provide pre-packaged content (analytic rules, workbooks, playbooks) that can be installed consistently across multiple workspaces via the Azure portal or API. This ensures standardized deployment without manual errors, leveraging Microsoft's curated content for common scenarios.

Exam trap

The trap here is that candidates may confuse 'storing incidents' (operational data) with 'deploying content' (configuration), leading them to incorrectly select Azure Key Vault as a deployment mechanism for Sentinel rules.

153
MCQmedium

A company stores sensitive data in Azure Blob Storage. They use customer-managed keys (CMK) stored in Azure Key Vault for encryption at rest. The security policy requires that the encryption keys be automatically rotated every 90 days. Which configuration should they implement to meet this requirement without manual intervention?

A.Enable key auto-rotation in Key Vault by setting a rotation policy on the key.
B.Use a custom Azure Automation runbook to rotate the key.
C.Set a key expiration date of 90 days and manually renew.
D.Enable versioning on the storage account and manually create a new key version.
AnswerA

Key Vault's rotation policy is the native mechanism that automatically generates new key versions at a defined interval (e.g., 90 days) or before an expiry date, without any custom code or manual action. For storage encryption, a versionless key URI in the storage account automatically references the latest rotated version, minimizing disruption. This directly satisfies the requirement for automatic rotation.

Why this answer

Azure Key Vault supports automatic key rotation by configuring a rotation policy on the key. When you enable auto-rotation, Key Vault automatically creates a new key version at the specified interval (e.g., every 90 days) without any manual intervention. This directly satisfies the requirement for automatic rotation of customer-managed keys used for Azure Storage encryption at rest.

Exam trap

The trap here is that candidates may think custom automation (Option B) is required for key rotation, but Azure Key Vault's built-in auto-rotation feature directly meets the requirement without additional overhead.

How to eliminate wrong answers

Option B is wrong because using a custom Azure Automation runbook introduces unnecessary complexity and potential failure points; Key Vault natively supports automatic rotation, making a custom solution redundant. Option C is wrong because setting a key expiration date only marks the key as expired after 90 days but does not automatically rotate it; manual renewal is required, which violates the 'without manual intervention' requirement. Option D is wrong because enabling versioning on the storage account only allows storing multiple blob versions, not key rotation; manually creating a new key version in Key Vault still requires manual action and does not automate the rotation process.

154
MCQhard

You are configuring Microsoft Defender for Cloud's 'Workload protections' for a Kubernetes cluster that is already using Azure Kubernetes Service (AKS). The cluster has 'Azure Policy' enabled. You need to enable the 'Microsoft Defender for Containers' plan to protect the cluster. You have already enabled the plan at the subscription level. However, the cluster is not showing as protected in the 'Inventory' blade. You have confirmed that the 'Azure Policy for Kubernetes' add-on is installed. What should you do to ensure the cluster is protected?

A.Install the 'Defender profile' on the AKS cluster.
B.Enable the 'Azure Policy for Kubernetes' add-on on the cluster.
C.Wait for 24 hours for the protection to automatically apply.
D.Install the Log Analytics agent on the cluster nodes.
AnswerA

Installing the Defender profile is the correct action because Microsoft Defender for Cloud’s Defender for Containers plan uses a dedicated DaemonSet on each AKS node to collect security signals such as Kubernetes audit logs, node events, and container runtime telemetry. The profile must be explicitly enabled on the cluster; enabling the plan at the subscription level alone does not protect existing clusters. Without this profile, the cluster remains visible in Defender for Cloud but lacks workload-level threat detection.

Why this answer

Even with the subscription-level plan enabled, you need to install the 'Defender profile' on the AKS cluster to enable protection. The Defender profile deploys the necessary agents for threat detection. Option A is correct.

Option B is incorrect because Azure Policy for Kubernetes is already enabled; it is a separate feature. Option C is incorrect because protection does not automatically apply; you must install the profile. Option D is incorrect because the Log Analytics agent is not required for Defender for Containers; the Defender profile handles agent deployment.

155
MCQmedium

You are designing a privileged access strategy for Microsoft Entra ID. Your organization requires that all users who are assigned to the Global Administrator role must perform a privileged elevation only when needed, and the elevation must be approved by a security officer. Which feature should you implement?

A.Microsoft Entra Identity Governance – Privileged Identity Management
B.Azure AD administrative units
C.Conditional Access with session control
D.Microsoft Entra ID protection risk policies
AnswerA

Microsoft Entra Privileged Identity Management (PIM) delivers just-in-time privileged access by letting users activate eligible role assignments for a maximum time window, with optional approval workflows, MFA, and business justification. Because activation is time-bound and audited, PIM directly supports a privileged access strategy that requires temporary elevation with oversight.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) provides just-in-time (JIT) privileged elevation for roles like Global Administrator, requiring approval from designated approvers (e.g., a security officer) before activation. This directly meets the requirement of elevation only when needed with approval, as PIM manages time-bound role assignments and approval workflows.

Exam trap

The trap here is that candidates often confuse Conditional Access (which controls sign-in access) with PIM (which controls role activation), leading them to select Option C because they think session controls can enforce approval for elevation, but Conditional Access cannot manage role activation workflows.

How to eliminate wrong answers

Option B is wrong because Azure AD administrative units restrict administrative scope to specific organizational units (e.g., departments) but do not provide JIT elevation or approval workflows for role activation. Option C is wrong because Conditional Access with session control enforces policies during sign-in (e.g., requiring MFA or device compliance) but cannot control role activation or require approval for elevation. Option D is wrong because Microsoft Entra ID Protection risk policies detect and respond to user or sign-in risks (e.g., blocking risky sign-ins) but do not manage privileged role elevation or approval processes.

156
MCQeasy

A company deploys a public-facing web application behind Azure Application Gateway. They want to enable the Web Application Firewall (WAF) to protect against SQL injection and cross-site scripting attacks. During the initial testing phase, they want to identify malicious requests without blocking them, to tune the WAF rules before enabling full protection. Which WAF mode should they configure?

A.Prevention mode
B.Detection mode
C.Logging mode
D.Off
AnswerB

Detection mode configures the WAF policy to pass every request through to the backend while evaluating it against the enabled rule sets, and any matches are recorded in the WAF log for later analysis. Because no request is denied, legitimate traffic cannot be interrupted, making it the appropriate setting for identifying attacks and tuning rules before enabling enforcement. This is the exact behavior needed by the team during the validation phase.

Why this answer

Detection mode logs WAF alerts and records the full request details without blocking any traffic. This allows the security team to analyze malicious requests, tune rule exclusions, and validate that legitimate traffic is not falsely flagged before switching to Prevention mode. It is the correct choice for the initial testing phase described.

Exam trap

The trap here is that candidates may confuse Detection mode with a hypothetical 'Logging mode' or assume Prevention mode is needed for any protection, overlooking the explicit requirement to identify without blocking during tuning.

How to eliminate wrong answers

Option A is wrong because Prevention mode actively blocks malicious requests, which would disrupt testing and prevent the team from tuning rules based on observed traffic. Option C is wrong because Azure WAF does not have a 'Logging mode'; logging is a feature enabled within Detection or Prevention mode, not a standalone operational mode. Option D is wrong because Off disables the WAF entirely, providing no protection or logging of malicious requests, which defeats the purpose of the testing phase.

157
MCQmedium

A healthcare organization stores sensitive patient data in Azure SQL Database. They need to encrypt specific columns containing medical history so that even database administrators with highly privileged roles, such as 'sysadmin', cannot view the plaintext data. Additionally, they need to support complex queries on the encrypted data, including pattern matching and range comparisons. Which encryption technology should they implement?

A.Always Encrypted with secure enclaves
B.Transparent Data Encryption (TDE)
C.Dynamic Data Masking
D.Row-Level Security
AnswerA

Always Encrypted with secure enclaves performs client-side column encryption, so the database engine only ever processes ciphertext while the encryption keys are held outside SQL Server. The enclave—a trusted hardware environment such as Intel SGX inside Azure Confidential Computing—enables rich operations like pattern matching, range comparisons, and sorting without ever exposing plaintext to the database process. This makes it the only option that both prevents database administrators from seeing data and supports computed queries over encrypted columns.

Why this answer

Always Encrypted with secure enclaves is correct because it encrypts specific columns at the client side, ensuring that even database administrators with sysadmin privileges cannot view the plaintext data. The secure enclave feature allows computations (such as pattern matching and range comparisons) to be performed on the encrypted data inside a trusted execution environment, which is required by the question's need for complex queries on encrypted columns.

Exam trap

The trap here is that candidates often confuse Transparent Data Encryption (TDE) with column-level encryption, assuming TDE protects data from privileged users, but TDE only protects data at rest and does not prevent authorized database users from reading plaintext data.

How to eliminate wrong answers

Option B (Transparent Data Encryption) is wrong because it encrypts the entire database at rest (on disk) but does not protect data from users or administrators who have access to the database engine; the data is decrypted transparently when queried, so sysadmins can still view plaintext. Option C (Dynamic Data Masking) is wrong because it only obfuscates data in query results for unauthorized users, but the underlying data remains stored in plaintext and can be accessed by privileged users like sysadmins. Option D (Row-Level Security) is wrong because it controls access to rows based on user context but does not encrypt the data; privileged users can still read the plaintext data directly.

158
MCQmedium

Your company has a hybrid environment with on-premises servers and Azure VMs. All resources are onboarded to Microsoft Defender for Cloud. You need to receive alerts when a critical vulnerability is detected on any server. The security team wants to minimize false positives. What should you configure?

A.Enable vulnerability assessment for servers via the integrated VA solution.
B.Configure just-in-time VM access to reduce attack surface.
C.Enable adaptive application controls to detect unapproved software.
D.Enable file integrity monitoring on critical files.
AnswerA

The integrated vulnerability assessment (VA) solution in Microsoft Defender for Cloud, powered by Qualys, performs agent-based scans of the OS and installed software to identify missing patches, insecure configurations, and known Common Vulnerabilities and Exposures (CVEs). It surfaces these findings as security recommendations and can generate alerts when discovered vulnerabilities align with known attack vectors. For on-premises and hybrid servers, you must first onboard them to Azure Arc and enable the Defender for Servers plan so the VA scanner can report to the cloud workload-protection dashboard.

Why this answer

Microsoft Defender for Cloud's integrated vulnerability assessment (VA) solution, powered by Qualys or Microsoft Defender Vulnerability Management, continuously scans servers for known CVEs and generates security alerts when critical vulnerabilities are found. This directly meets the requirement to receive alerts on critical vulnerabilities while minimizing false positives, as the VA solution uses curated, verified vulnerability data rather than heuristic or behavioral detections that might produce noise.

Exam trap

The trap here is that candidates confuse vulnerability detection (finding CVEs) with other security controls like access restriction (JIT), application whitelisting (AAC), or change monitoring (FIM), all of which address different threat vectors and do not directly alert on critical vulnerabilities.

How to eliminate wrong answers

Option B is wrong because just-in-time (JIT) VM access reduces the attack surface by controlling network access to management ports, but it does not detect or alert on critical vulnerabilities; it is a preventive control, not a detection mechanism. Option C is wrong because adaptive application controls (AAC) create allowlists for approved software and generate alerts only when unapproved software runs, which addresses application control, not vulnerability detection; it would miss critical OS-level or service-level CVEs. Option D is wrong because file integrity monitoring (FIM) tracks changes to critical files and registry keys, alerting on modifications, not on vulnerabilities; it would not detect a critical CVE unless the vulnerability itself caused a file change, which is unreliable and indirect.

159
MCQhard

An Azure Storage account is configured with server-side encryption (SSE) using a customer-managed key stored in Azure Key Vault. The security team requires that the storage account's identity be used to authenticate to the key vault for key access. Additionally, they want the identity to be automatically deleted when the storage account is deleted. Which type of identity should they assign to the storage account?

A.System-assigned managed identity
B.User-assigned managed identity
C.Service principal
D.Azure AD user account
AnswerA

A system-assigned managed identity is created directly on the storage account and shares its lifecycle: when enabled, Azure AD automatically provisions a corresponding service principal for the account, and when the storage account is deleted, the identity is removed automatically. It requires no application ID, client secret, or certificate rotation, so it meets both requirements of credential-free authentication and automatic cleanup. The storage account can use this identity to authenticate to Azure Key Vault for customer-managed key operations.

Why this answer

A system-assigned managed identity is tied to the lifecycle of the Azure resource (the storage account) and is automatically deleted when the resource is deleted. This identity can be used to authenticate to Azure Key Vault for accessing the customer-managed key used in server-side encryption (SSE), satisfying the security team's requirement for automatic deletion upon storage account deletion.

Exam trap

The trap here is that candidates often confuse user-assigned managed identities with system-assigned ones, overlooking the critical lifecycle coupling requirement that system-assigned identities are automatically deleted with the parent resource, while user-assigned identities persist independently.

How to eliminate wrong answers

Option B is wrong because a user-assigned managed identity has an independent lifecycle and is not automatically deleted when the storage account is deleted; it must be manually removed. Option C is wrong because a service principal is a separate application identity that requires manual credential management (secrets or certificates) and does not automatically delete with the storage account. Option D is wrong because an Azure AD user account is a human identity that cannot be assigned to an Azure resource and would require interactive authentication, which is not suitable for automated key access.

160
MCQmedium

A company uses Azure Managed Disks for their virtual machines. They want to ensure that all managed disks are encrypted at rest using a customer-managed key (CMK) stored in Azure Key Vault. They also want to automatically revoke access to the disks if the key is disabled or deleted. Which feature should they configure?

A.Azure Disk Encryption (ADE) with a Key Encryption Key (KEK)
B.Server-side encryption with customer-managed keys (SSE-CMK)
C.Azure Storage Service Encryption (SSE) with platform-managed keys
D.Azure Key Vault soft-delete and purge protection
AnswerB

Server-side encryption with customer-managed keys (SSE-CMK) is the native Azure managed-disk encryption feature that encrypts disk data at rest using a customer-provided key from Azure Key Vault or a managed HSM. Because the managed-disk service must unwrap the disk encryption key from the CMK for every attach and I/O operation, disabling or deleting the CMK makes the disk inaccessible and fully satisfies the key-revocation requirement without any in-VM agent or manual configuration. This approach works at the platform layer, applying encryption to all writes sent to the disk, and is the preferred way to achieve both encryption at rest and customer-controlled revocation.

Why this answer

Server-side encryption with customer-managed keys (SSE-CMK) encrypts Azure Managed Disks at rest using a key stored in Azure Key Vault. When the key is disabled or deleted, Azure automatically revokes access to the disk by failing any I/O operations that require that key, ensuring the disk becomes inaccessible. This directly meets the requirement for both CMK-based encryption and automatic access revocation upon key loss.

Exam trap

The trap here is that candidates confuse Azure Disk Encryption (ADE) with server-side encryption (SSE-CMK), mistakenly thinking ADE provides automatic access revocation when the key is disabled, whereas ADE only encrypts at the guest OS level and does not enforce platform-level access control based on key state.

How to eliminate wrong answers

Option A is wrong because Azure Disk Encryption (ADE) with a KEK uses BitLocker (Windows) or DM-Crypt (Linux) to encrypt the OS and data disks at the VM guest OS level, not at the Azure platform level, and disabling the KEK does not automatically revoke access to the underlying managed disk; the disk remains accessible at the storage layer. Option C is wrong because Azure Storage Service Encryption (SSE) with platform-managed keys uses Microsoft-managed keys, not customer-managed keys, so it cannot meet the requirement for CMK-based encryption or allow key revocation by the customer. Option D is wrong because Azure Key Vault soft-delete and purge protection only prevents permanent deletion of keys and secrets; it does not encrypt disks or automatically revoke access to disks when a key is disabled or deleted.

161
MCQmedium

You are a security engineer for a company that uses Microsoft Entra ID. The company has a policy that users must sign in using Windows Hello for Business or a FIDO2 security key. You need to block legacy authentication protocols that do not support these methods. What should you configure?

A.Enable security defaults in Microsoft Entra ID.
B.Create an authentication method policy that disables SMS and voice call methods.
C.Create a Conditional Access policy that targets all users and all cloud apps, and set the client apps condition to 'Exchange ActiveSync clients' and 'Other clients', then set access control to 'Block'.
D.Configure a sign-in risk policy in Microsoft Entra ID Protection to block sign-ins with medium or high risk.
AnswerC

This correctly blocks legacy authentication protocols because 'Exchange ActiveSync clients' and 'Other clients' represent legacy clients that do not support modern authentication. By targeting all users and cloud apps and blocking these client types, you prevent sign-ins that cannot enforce Windows Hello for Business or FIDO2. This is the recommended approach in Microsoft Entra ID to eliminate legacy authentication.

Why this answer

To block legacy authentication, you must use Conditional Access to target client apps that use legacy protocols. The 'Exchange ActiveSync clients' and 'Other clients' conditions specifically cover clients that do not support modern authentication. Setting the access control to 'Block' ensures these clients cannot sign in.

Other options do not directly block legacy protocols; they address different security aspects such as risk, baseline defaults, or authentication methods.

Exam trap

The trap here is confusing security defaults or authentication method policies with the granular control needed to block legacy authentication while allowing modern methods.

162
MCQmedium

Your organization has a hybrid network with an Azure VPN gateway connecting to an on-premises site. You need to ensure that traffic between Azure and on-premises is encrypted and authenticated. Which protocol should the VPN gateway use?

A.SSL/TLS
B.IPsec
C.SSH
D.HTTPS
AnswerB

IPsec is the standard protocol suite for site-to-site VPN tunnels, and Azure VPN Gateway explicitly uses IPsec/IKE to establish encrypted tunnels between on-premises networks and Azure virtual networks. IPsec operates at the network layer, providing confidentiality, data integrity, and anti-replay protection by encrypting and authenticating every IP packet in an ESP (Encapsulating Security Payload) header. This allows all traffic, not just specific applications, to be securely transmitted between sites, which is why it is the correct answer.

Why this answer

Azure VPN gateways use IPsec (Internet Protocol Security) to establish secure site-to-site tunnels between Azure and on-premises networks. IPsec provides both encryption (via protocols like AES) and authentication (via IKEv2 or IKEv1) for all traffic traversing the VPN tunnel, ensuring confidentiality and integrity. This is the required protocol for Azure VPN gateway connections as defined in Microsoft documentation.

Exam trap

The trap here is that candidates confuse SSL/TLS with IPsec because both provide encryption, but SSL/TLS is designed for client-server web security, not for routing all traffic between two entire networks via a VPN gateway.

How to eliminate wrong answers

Option A (SSL/TLS) is wrong because SSL/TLS is used for securing web traffic (HTTPS) and client-to-server connections, not for site-to-site VPN tunnels between networks. Option C (SSH) is wrong because SSH is a protocol for secure remote administration of devices (e.g., CLI access), not for encrypting bulk network traffic between sites. Option D (HTTPS) is wrong because HTTPS is an application-layer protocol for secure web browsing, not a tunneling protocol for network-to-network connectivity.

163
MCQhard

You are designing a Microsoft Sentinel deployment for a multinational company. The company requires that data from different geographic regions be stored separately to comply with data residency laws. What is the recommended approach?

A.Deploy a single Sentinel workspace and use Azure Purview to tag data for residency.
B.Deploy a single Sentinel workspace and configure diagnostic settings to send data to separate Log Analytics workspaces.
C.Deploy a single Sentinel workspace and use data collection rules to route data to different storage accounts.
D.Deploy a separate Microsoft Sentinel workspace in each required region.
AnswerD

Each Microsoft Sentinel workspace is functionally a Log Analytics workspace with Sentinel enabled, and the workspace's location determines where all underlying data is stored at rest. Deploying Sentinel in each required region creates separate, region-pinned data stores that fully contain that region's logs, satisfying residency requirements. This also allows rules and workbooks to be scoped to local data, though cross-workspace queries or Azure Lighthouse can still provide a pane-of-glass view for centralized monitoring.

Why this answer

Microsoft Sentinel is built on top of Log Analytics workspaces, and each workspace is a distinct data container with its own retention, encryption, and geographic location. To comply with data residency laws that require data from different regions to be stored separately, you must deploy a separate Sentinel workspace in each required region. This ensures that data ingested from a specific region remains within that region's boundaries and is not mixed with data from other regions.

Exam trap

The trap here is that candidates may think data collection rules or diagnostic settings can route data to different storage accounts or workspaces within a single Sentinel instance, but Sentinel's architecture requires each workspace to be a separate Log Analytics workspace with its own regional binding.

How to eliminate wrong answers

Option A is wrong because Azure Purview is a data governance and catalog service, not a data routing or residency enforcement tool; it cannot separate stored data by region within a single Sentinel workspace. Option B is wrong because diagnostic settings send data to a Log Analytics workspace, but a single Sentinel workspace is tied to a single Log Analytics workspace; you cannot use diagnostic settings to split data into separate Log Analytics workspaces from within one Sentinel deployment. Option C is wrong because data collection rules (DCRs) in Azure Monitor can route data to different destinations like storage accounts, but Sentinel requires data to be in a Log Analytics workspace to be analyzed; routing to separate storage accounts does not satisfy the requirement for separate Sentinel workspaces for regional data residency.

164
MCQmedium

A security analyst uses Microsoft Defender for Cloud. They need to assess their Azure environment's compliance against the Payment Card Industry Data Security Standard (PCI DSS). Which dashboard in Defender for Cloud should they use to view the compliance status?

A.Secure Score
B.Security Alerts
C.Regulatory Compliance
D.Workbooks
AnswerC

The Regulatory Compliance dashboard in Defender for Cloud provides a dedicated view of how your Azure environment scores against a specific regulatory standard, such as CIS 1.4, NIST SP 800-53, or PCI DSS v3.2.1. It uses Azure Policy initiatives with policy definitions underlying each compliance control; each control displays a Pass/Fail status and a list of non-compliant resources based on continuous policy evaluation. The dashboard also shows the compliance score for that standard, giving you an immediate audit-ready overview. This directly meets the analyst's need to display compliance against a specific regulatory standard.

Why this answer

The Regulatory Compliance dashboard in Microsoft Defender for Cloud provides a pre-built assessment of your Azure environment against specific compliance standards, including PCI DSS. It maps your security controls to the requirements of the standard and shows a compliance score based on the results of continuous assessments. This is the correct tool for viewing compliance status against PCI DSS.

Exam trap

The trap here is that candidates may confuse Secure Score (which measures general security hygiene) with regulatory compliance scoring, but Secure Score does not map to specific standards like PCI DSS, while Regulatory Compliance does.

How to eliminate wrong answers

Option A is wrong because Secure Score measures your overall security posture based on implemented security controls, not compliance with a specific regulatory standard like PCI DSS. Option B is wrong because Security Alerts lists active threats and suspicious activities, not compliance status. Option D is wrong because Workbooks are customizable visualizations that can be built from Azure Monitor data, but they do not provide a pre-built, out-of-the-box compliance assessment against PCI DSS.

165
MCQmedium

Your company uses Azure SQL Managed Instance. You need to ensure that all connections from clients use TLS 1.2 or higher. What should you configure?

A.Set the 'Minimal TLS version' property to 1.2 in the Managed Instance settings
B.Configure a firewall rule to block non-TLS 1.2 connections
C.Create an Azure Policy to require TLS 1.2 for all SQL Managed Instances
D.Enable the 'Force encryption' option on the client side
AnswerA

The Minimal TLS version property on Azure SQL Managed Instance is the native server-side setting that enforces the lowest TLS protocol accepted for client connections. Setting it to 1.2 rejects any handshake attempt using TLS 1.0 or 1.1 before the session is established, independent of the client driver or connection string. This is the only direct control that guarantees all connections use at least TLS 1.2.

Why this answer

Azure SQL Managed Instance exposes a 'Minimal TLS version' property in its settings that enforces the minimum TLS version for all client connections. Setting this to 1.2 ensures that any connection attempt using TLS 1.0 or 1.1 is rejected at the server level, providing a centralized, server-side enforcement mechanism without relying on client-side configurations.

Exam trap

The trap here is that candidates often confuse 'Force encryption' (which only ensures encryption, not a specific TLS version) with the 'Minimal TLS version' setting, or mistakenly think Azure Policy or firewall rules can directly control TLS protocol negotiation at the connection level.

How to eliminate wrong answers

Option B is wrong because firewall rules in Azure SQL Managed Instance control IP-based access, not TLS protocol versions; they cannot inspect or block connections based on the TLS version used. Option C is wrong because Azure Policy can audit or enforce compliance at the resource level (e.g., requiring the 'Minimal TLS version' property to be set to 1.2), but it does not directly enforce TLS version on connections—it only ensures the setting is configured correctly. Option D is wrong because enabling 'Force encryption' on the client side only mandates that the connection be encrypted (using TLS), but it does not specify or enforce a minimum TLS version; clients could still connect using TLS 1.0 or 1.1.

166
MCQeasy

A security administrator is troubleshooting network connectivity to an Azure virtual machine. The VM is behind a network security group (NSG) that has a deny-all inbound rule as the default. The administrator wants to quickly verify whether a specific TCP packet on port 3389 from their client IP (203.0.113.50) would be allowed or blocked by the NSG. Which Azure Network Watcher tool should they use?

A.Network Performance Monitor.
B.IP flow verify.
C.Next hop.
D.NSG diagnostics (flow logs).
AnswerB

IP flow verify, part of Azure Network Watcher, takes a specified protocol, source IP/port, destination IP/port, and the target virtual machine’s network interface to simulate an actual packet. The tool then evaluates the effective security rules applied at both the subnet and network interface levels and returns an allow or deny decision along with the exact rule that allowed or blocked the traffic. This makes it the correct choice for validating NSG rules because it directly answers whether a specific packet is permitted in real time.

Why this answer

IP flow verify is the correct tool because it tests whether a specific packet (source IP, destination IP, protocol, port) is allowed or denied by an NSG or virtual network (VNet) route. In this scenario, the administrator needs to quickly validate inbound TCP traffic on port 3389 from client IP 203.0.113.50 to the VM, and IP flow verify provides a pass/fail result along with the exact rule that caused the outcome.

Exam trap

The trap here is that candidates often confuse NSG flow logs (which provide historical traffic data) with the real-time diagnostic capability of IP flow verify, leading them to select NSG diagnostics (flow logs) instead of the correct tool for on-demand packet testing.

How to eliminate wrong answers

Option A is wrong because Network Performance Monitor is a tool for monitoring network latency, packet loss, and performance between endpoints, not for testing NSG rule evaluation for a specific packet. Option C is wrong because Next hop shows the next hop type and IP address for traffic from a VM, but it does not evaluate NSG rules or indicate whether a packet is allowed or blocked. Option D is wrong because NSG diagnostics (flow logs) record information about IP traffic flowing through an NSG after the fact, but they are not designed for real-time, on-demand verification of a single packet's allow/deny status.

167
Multi-Selecthard

Which THREE of the following are required to configure Microsoft Entra ID self-service password reset (SSPR)?

Select 3 answers
A.Microsoft Entra ID P1 or P2 license
B.Microsoft Entra ID Premium P2 license
C.Password writeback must be enabled
D.Users must register for authentication methods
E.SSPR must be enabled in the tenant
AnswersA, D, E

Microsoft Entra ID P1 or P2 license includes self-service password reset (SSPR) at either tier, so a P1 subscription is the minimum required for this feature. P1 provides full SSPR functionality for cloud-managed users, while P2 layers on advanced capabilities like Identity Protection and Privileged Identity Management that are not prerequisites for password reset. Therefore, stating P1 or P2 is the accurate licensing requirement, as P2 is not necessary.

Why this answer

Option A is correct because Microsoft Entra ID self-service password reset requires a Microsoft Entra ID P1 or P2 license (or Microsoft 365 Business Premium, which includes Entra ID P1 features); the P1 tier is the minimum paid license that unlocks SSPR for cloud-only and hybrid users. Option D is correct because users must register their authentication methods (such as Microsoft Authenticator, email, phone, or security questions) before they can prove their identity and reset their own password. Option E is correct because an administrator must explicitly enable SSPR in the tenant (for example, by selecting All users or a pilot group under Password reset > Properties), since the feature is not active by default.

Option B is not required because Premium P2 is not the minimum license — P1 already satisfies the SSPR licensing requirement, and P2 is only needed for features like Identity Protection and Privileged Identity Management. Option C is not required because password writeback is only necessary for hybrid environments where the password must sync back to on-premises Active Directory via Microsoft Entra Connect; for cloud-only users, SSPR works without writeback.

Exam trap

The trap here is that candidates often assume password writeback is always required for SSPR, but it is only necessary when integrating with on-premises Active Directory; for cloud-only users, SSPR works without it.

168
MCQhard

A company has deployed Azure Firewall in a hub virtual network with forced tunneling enabled. Spoke virtual networks are peered to the hub. The security team reports that outbound traffic from the spoke VMs is bypassing the firewall. What is the most likely reason?

A.The Azure Firewall policy has an allow-all network rule.
B.Azure Firewall is deployed in the same virtual network as the spoke VMs.
C.The spoke virtual networks are not peered to the hub.
D.The spoke subnets do not have a route table with a default route (0.0.0.0/0) pointing to the Azure Firewall.
AnswerD

Without a user-defined route table on the spoke subnets, Azure's default system routes send internet-bound traffic directly out, bypassing the firewall despite peering. A 0.0.0.0/0 route with next hop Virtual appliance forces spoke egress through the hub firewall.

Why this answer

Forced tunneling on Azure Firewall requires that all outbound traffic from spoke VMs is routed to the firewall via a user-defined route (UDR) with a default route (0.0.0.0/0) pointing to the firewall's private IP as the next hop. Without this route, traffic from spoke subnets will use the default system route and bypass the firewall, even if the firewall itself is configured with forced tunneling.

Exam trap

The trap here is that candidates often assume forced tunneling on the firewall itself automatically redirects all spoke traffic, but in reality, forced tunneling only affects traffic from the firewall's own subnet; spoke subnets require explicit UDRs to route traffic to the firewall.

How to eliminate wrong answers

Option A is wrong because an allow-all network rule in the firewall policy would permit traffic that reaches the firewall, but it does not cause traffic to bypass the firewall; the issue is that traffic never reaches the firewall. Option B is wrong because Azure Firewall must be deployed in a dedicated subnet (AzureFirewallSubnet) in the hub, not in the same virtual network as the spoke VMs; if it were in the same VNet, it would still require UDRs to direct traffic to it. Option C is wrong because the question states that spoke virtual networks are peered to the hub, so this is not the cause; even if peering were missing, traffic would not flow at all, not bypass the firewall.

169
MCQeasy

You are the Azure Security Engineer for a company that uses Azure SQL Database. A recent security audit requires that all connections to the database be encrypted and that the database reject any unencrypted connections. You need to enforce this requirement with the least administrative effort. What should you do?

A.Configure a firewall rule on the Azure SQL Database server to allow only connections from specific IP addresses.
B.Implement Always Encrypted on all sensitive columns in the database.
C.Enable Transparent Data Encryption (TDE) on the Azure SQL Database.
D.Enable the 'Enforce SSL connection' setting on the Azure SQL Database server.
AnswerD

Azure SQL Database provides a server-level setting called 'Enforce SSL connection' (or 'Require secure transfer' in some interfaces). When enabled, the server rejects any connection that is not encrypted with TLS. This is a simple configuration change that enforces encryption for all connections to the database, meeting the audit requirement with minimal effort.

Why this answer

The 'Enforce SSL connection' setting on the Azure SQL Database server forces all connections to use TLS encryption. When enabled, any attempt to connect without encryption is rejected. This directly satisfies the requirement to encrypt all connections and reject unencrypted ones, and it requires only a single configuration change.

Exam trap

The trap here is confusing data-at-rest encryption features like TDE or Always Encrypted with transport encryption enforcement.

170
MCQeasy

Your company uses Azure Firewall to protect a virtual network. The security team needs to allow outbound HTTPS traffic from a specific subnet to a set of FQDNs, such as '*.contoso.com', while blocking all other outbound traffic. Which type of Azure Firewall rule should they configure?

A.A network rule with destination port 443 and protocol TCP, and the destination IP address set to the resolved IPs of the FQDNs
B.An application rule with the 'Https' protocol and the target FQDNs set to '*.contoso.com'
C.A NAT rule that translates the source IP to a public IP and allows traffic to any destination on port 443
D.A DNAT rule that redirects outbound HTTPS traffic to an internal proxy server
AnswerB

Application rules are designed to allow or deny outbound traffic based on FQDNs. For HTTPS traffic, you can specify the target FQDNs and the protocol (Https). This is the correct configuration to allow traffic to specific domains while blocking others.

Why this answer

Azure Firewall application rules are specifically designed to allow outbound HTTP/HTTPS traffic based on fully qualified domain names (FQDNs). By configuring an application rule with protocol 'Https' and target FQDNs set to '*.contoso.com', the firewall inspects the TLS Server Name Indication (SNI) extension to match the requested domain, allowing traffic only to the specified FQDNs while blocking all other outbound traffic.

Exam trap

The trap here is that candidates often confuse network rules (which filter by IP/port) with application rules (which filter by FQDN), leading them to choose Option A because they think resolved IPs are sufficient, ignoring the dynamic nature of FQDNs and the need for domain-level control.

How to eliminate wrong answers

Option A is wrong because network rules filter traffic based on source/destination IP addresses and ports, not FQDNs; using resolved IPs would break if the FQDNs resolve to dynamic IPs or multiple IPs, and it cannot enforce domain-level filtering. Option C is wrong because a NAT rule translates source IP addresses for outbound traffic but does not filter destinations; it would allow HTTPS traffic to any destination, not just '*.contoso.com'. Option D is wrong because a DNAT rule is used for inbound traffic (destination network address translation) to redirect incoming connections to an internal resource, not for outbound traffic filtering.

171
MCQmedium

You are a security engineer managing a Microsoft Sentinel workspace. The security operations team wants to automatically create a ServiceNow incident whenever a new high-severity incident is generated in Microsoft Sentinel. You need to configure the automation rule to trigger only for incidents with severity High and to include the incident's entities in the ServiceNow ticket. What should you do first?

A.Enable the Microsoft Sentinel data connector for ServiceNow and configure the connector to automatically create incidents for all high-severity alerts.
B.Create an analytics rule that generates an incident and configure its incident settings to run a playbook automatically.
C.Create a playbook that uses the ServiceNow connector, then create an automation rule with the condition Severity equals High and add an action to run the playbook.
D.Create a workbook that monitors incidents and use Azure Logic Apps to send an email to the security team when a high-severity incident occurs.
AnswerC

Automation rules in Microsoft Sentinel can trigger playbooks based on incident conditions. The playbook must be created first, then referenced in the automation rule. The condition Severity equals High ensures only high-severity incidents trigger the playbook, and the playbook can access incident entities to populate ServiceNow fields. This is the correct sequence to achieve the requirement.

Why this answer

Automation rules in Microsoft Sentinel allow you to define conditions and actions that run when incidents are created or updated. To integrate with ServiceNow, you must first create a playbook that contains the logic to create a ServiceNow incident, using the ServiceNow connector. Then, you create an automation rule that triggers on High severity incidents and runs that playbook.

This ensures that only high-severity incidents result in ServiceNow tickets, and the playbook can access incident entities to populate the ticket details.

Exam trap

The trap here is confusing the direction of the ServiceNow connector: it ingests ServiceNow data into Sentinel, not the reverse; outbound automation requires playbooks triggered by automation rules.

172
Multi-Selecteasy

You need to secure traffic between an on-premises network and Azure using a VPN connection. Which TWO configurations are required?

Select 2 answers
A.Create a virtual network gateway (VPN)
B.Deploy Azure Firewall
C.Assign a public IP to the local network gateway
D.Provision an ExpressRoute circuit
E.Create a local network gateway
AnswersA, E

The virtual network gateway is the Azure-side endpoint of a site-to-site VPN tunnel. It must be deployed in a dedicated GatewaySubnet and receives a public IP address to terminate the encrypted IPsec/IKE connection originating from the on-premises VPN device. Without this gateway, Azure has no component to establish the secure tunnel, so it is essential for securing traffic between the on-premises network and the virtual network.

Why this answer

Option A is correct because a virtual network gateway of type VPN is the Azure-side endpoint that terminates the IPsec/IKE tunnel and is mandatory for any site-to-site VPN connection. Option E is correct because the local network gateway is the Azure resource that represents the on-premises VPN device, holding its public IP address and address spaces so Azure knows how to route traffic to the remote network. Together, the virtual network gateway and local network gateway form the two required endpoints for a site-to-site VPN.

Option B is not required because Azure Firewall provides traffic filtering and security policies, not the VPN tunnel itself. Option C is not required because the public IP is assigned to the on-premises VPN device (or referenced in the local network gateway), not to the local network gateway resource itself. Option D is not required because ExpressRoute is a separate dedicated private connectivity service, not a VPN solution.

Exam trap

The trap here is that candidates often confuse the local network gateway (a configuration object) with needing a public IP assigned to it, or think Azure Firewall can serve as a VPN endpoint, when in fact it is a separate security service.

173
Drag & Dropmedium

Drag and drop the steps to enable Azure Security Center's enhanced security features for a subscription into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

To enable Azure Security Center's enhanced security features for a subscription, you must first navigate to Security Center, then access 'Security policy' under Management. Within that blade, select the target subscription and set its pricing tier to Standard. This activates advanced threat detection and vulnerability assessment capabilities.

Common mistakes include confusing the order of subscription selection and tier setting, or mixing up the security policy with auto-provisioning settings.

174
MCQhard

A security team uses Microsoft Defender for Cloud's regulatory compliance dashboard to track compliance with PCI DSS. They notice that some controls are marked as 'N/A' even though they have relevant resources. What is the most likely reason?

A.The resources do not have the required custom assessment.
B.The compliance dashboard requires a Microsoft Purview Compliance Manager license.
C.The resources are in a subscription that is not included in the scope of the compliance standard.
D.The resources have not been manually claimed as compliant.
AnswerC

In Defender for Cloud, each regulatory compliance standard is assigned to a specific scope, such as a subscription or management group, when you enable it. Only resources within that assigned scope are evaluated and reported in the compliance dashboard, and resources in unassigned subscriptions are completely ignored. If the subscription containing the resources is not part of the standard's assignment, those resources will not appear in the compliance view.

Why this answer

The correct answer is C: resources in a subscription that is not included in the scope of the compliance standard. In Microsoft Defender for Cloud's regulatory compliance dashboard, a control is shown as 'N/A' when the standard's assessment scope does not cover the subscription containing those resources, so the control is not evaluated against them. This scoping is configured when assigning the regulatory compliance standard, and only in-scope subscriptions are assessed.

Option A is incorrect because a missing custom assessment would leave a control unassessed or healthy/unhealthy, not scoped out as N/A. Option B is incorrect because the regulatory compliance dashboard is a Defender for Cloud capability and does not require a Microsoft Purview Compliance Manager license. Option D is incorrect because manual attestation affects a control's compliance state, not whether it is marked N/A due to scope.

175
Multi-Selecthard

Which THREE capabilities are provided by Azure Storage Service Encryption (SSE) when using customer-managed keys?

Select 3 answers
A.Auditing of key usage via Azure Key Vault logs.
B.Client-side encryption of data before upload.
C.Automatic encryption of data at rest.
D.Ability to rotate keys periodically.
E.Control access to the storage account using RBAC.
AnswersA, C, D

Auditing of key usage via Azure Key Vault logs: When Azure Storage accesses a customer-managed key stored in Key Vault to encrypt or decrypt data at rest, the Key Vault records the operation, such as key wrap or unwrap, in its diagnostic logs. By enabling Key Vault auditing, you can monitor key usage, detect unauthorized access, and meet compliance requirements. This capability is present specifically when SSE is configured with customer-managed keys, not with Microsoft-managed keys.

Why this answer

Azure Storage Service Encryption (SSE) with customer-managed keys integrates with Azure Key Vault, which can be configured to log key operations such as encrypt, decrypt, wrap, and unwrap. These logs are sent to Azure Monitor or a storage account, enabling auditing of key usage for compliance and security monitoring.

Exam trap

The trap here is that candidates confuse SSE's server-side encryption with client-side encryption (Option B) or mix up access control mechanisms (RBAC) with encryption capabilities, leading them to select options that are valid Azure features but not provided by SSE.

176
MCQeasy

You need to ensure that only approved iOS devices can access corporate email. Which Microsoft Intune policy should you configure?

A.Enrollment restriction
B.Device configuration policy
C.App protection policy
D.Device compliance policy
AnswerD

A device compliance policy in Microsoft Intune defines the rules that an iOS device must satisfy, such as a minimum OS version, a specific model, or jailbreak detection, and then scores the device as compliant or noncompliant on a regular schedule. This compliance state is consumed by Azure AD Conditional Access to allow or block access to Exchange, SharePoint, and other corporate apps. Therefore, it directly ensures that only approved iOS devices can access—because any device that fails the policy is denied at the time of access.

Why this answer

The correct option is D, Device compliance policy. A compliance policy defines the rules a device must meet (for example, requiring a compliant/approved iOS device state) and, combined with Conditional Access, blocks noncompliant devices from accessing corporate email such as Exchange Online. Enrollment restrictions (A) only control which devices may enroll or which platforms are allowed, not ongoing email access.

Device configuration policies (B) push settings to devices but do not gate access, and app protection policies (C) protect app data on enrolled or unenrolled devices without enforcing device-level approval for email access.

177
MCQhard

You are designing a Microsoft Entra ID tenant for a multinational organization. The security team requires that all administrative users must use phishing-resistant MFA. Administrators are located in different regions and may use different devices. Which MFA method should you enforce?

A.FIDO2 security keys
B.SMS-based verification
C.Phone call verification
D.Microsoft Authenticator with OTP
AnswerA

FIDO2 security keys are phishing-resistant because they use public-key cryptography where the private key never leaves the device and authentication is bound to the exact relying party origin. During a phishing attack, the key’s challenge-response only works for the legitimate site’s domain, so the credential cannot be relayed to a malicious impersonator. This eliminates shared secrets and prevents man-in-the-middle relay attacks, making it a strong authenticator for Microsoft Entra ID.

Why this answer

FIDO2 security keys are the only option that provides phishing-resistant MFA, as they use public-key cryptography and are bound to a specific web origin, preventing credential theft via man-in-the-middle attacks. This satisfies the security team's requirement for all administrative users, regardless of region or device, because FIDO2 keys are hardware-based and interoperable across platforms.

Exam trap

The trap here is that candidates often confuse 'multi-factor authentication' with 'phishing-resistant MFA', and select Microsoft Authenticator with OTP because it is a common MFA method, but it does not protect against real-time phishing attacks where the OTP is captured and replayed.

How to eliminate wrong answers

Option B is wrong because SMS-based verification is vulnerable to SIM-swapping and phishing attacks, and is not considered phishing-resistant. Option C is wrong because phone call verification relies on the PSTN network, which can be intercepted or spoofed, and does not provide phishing resistance. Option D is wrong because Microsoft Authenticator with OTP (time-based one-time password) is susceptible to phishing if the user is tricked into entering the OTP on a fake site, and it does not meet the phishing-resistant requirement.

178
MCQmedium

A security operations team uses Microsoft Sentinel. They need to collect Syslog messages from on-premises Linux servers for analysis. Which data connector should they use to ingest these logs into Sentinel?

A.Azure Activity Log connector
B.Syslog connector via Log Analytics agent
C.Common Event Format (CEF) connector
D.Windows Security Events connector
AnswerB

The Syslog connector via the Log Analytics agent is the correct choice for ingesting standard Syslog messages into Microsoft Sentinel. To use it, you must install the Log Analytics agent on a Linux virtual machine (on-premises or in Azure) that acts as a Syslog collector, then configure the agent's syslog daemon to forward events with specific facilities and severities. The connector then maps those events to the Syslog table in the workspace, enabling detection rules and queries.

Why this answer

The Syslog connector via Log Analytics agent is the correct choice because it allows Microsoft Sentinel to collect Syslog messages from on-premises Linux servers. The Log Analytics agent (formerly OMS agent) listens on UDP port 514 (or a custom port) for Syslog messages forwarded by the Linux rsyslog or syslog-ng daemon, then forwards them to the Log Analytics workspace. This connector is specifically designed for standard Syslog ingestion without requiring format transformation.

Exam trap

The trap here is that candidates often confuse the Syslog connector (for standard Syslog) with the CEF connector (for formatted security logs), mistakenly thinking CEF is required for any Linux Syslog ingestion, when in fact CEF is only needed for specific security appliances that output CEF-formatted logs.

How to eliminate wrong answers

Option A is wrong because the Azure Activity Log connector ingests subscription-level events from Azure's control plane (e.g., resource creation, policy changes), not Syslog messages from on-premises Linux servers. Option C is wrong because the Common Event Format (CEF) connector is used for security appliances that output CEF-formatted logs (e.g., firewalls, IDS/IPS) and requires a Syslog forwarder to parse and transform the logs, whereas standard Syslog messages do not need this transformation. Option D is wrong because the Windows Security Events connector collects Windows Event Log data (specifically Security events) from Windows machines, not Syslog messages from Linux servers.

179
Multi-Selectmedium

Your company uses Microsoft Defender for Cloud to protect Azure resources. You want to enable the 'Defender for Containers' plan to secure AKS clusters. Which two configurations are necessary? (Choose two.)

Select 2 answers
A.Assign the 'Kubernetes cluster should be accessible only through private endpoint' Azure Policy.
B.Connect the AKS cluster to Azure Arc.
C.Enable the 'Defender for Containers' plan in Microsoft Defender for Cloud.
D.Install the Log Analytics agent on each AKS node.
E.Ensure the AKS cluster's audit logs are enabled and streamed to a Log Analytics workspace.
AnswersC, E

Enabling the 'Defender for Containers' plan in Microsoft Defender for Cloud is the fundamental step that activates threat detection, vulnerability assessment, and security recommendations for AKS clusters. This plan must be turned on for the subscription that contains the cluster; once enabled, Defender automatically deploys the necessary components to collect and analyze security signals. Without this plan, no amount of audit logging or agent installation will produce Defender's container-specific protection.

Why this answer

Enabling the 'Defender for Containers' plan in Microsoft Defender for Cloud is the primary configuration required to activate threat detection and security monitoring for AKS clusters. Option E is correct because audit logs must be enabled and streamed to a Log Analytics workspace to provide the necessary data for Defender for Containers to analyze Kubernetes audit events and detect suspicious activities.

Exam trap

The trap here is that candidates often confuse the Log Analytics agent requirement with the actual data collection mechanism, mistakenly thinking it must be installed on each node, whereas Defender for Containers uses its own dedicated Defender profile and relies on audit log streaming instead.

180
MCQmedium

Your organization uses Microsoft Defender for Cloud's workload protection for Azure SQL databases. You notice that Defender for Cloud is not generating alerts for anomalous activities on a specific SQL database. The database is in a VNet with a service endpoint enabled for SQL. What should you verify first?

A.Ensure the service endpoint is configured correctly.
B.Enable Advanced Threat Protection on the Azure SQL Server.
C.Enable auditing on the SQL database.
D.Configure a firewall rule to allow Defender for Cloud IP addresses.
AnswerB

Advanced Threat Protection (ATP) for Azure SQL Server (also known as Defender for SQL) must be enabled at the server level; it activates vulnerability assessment, anomaly detection, and the alerting engine that surface suspicious activities like SQL injection, brute-force attempts, or unusual access patterns. When ATP is on, Microsoft Defender for Cloud automatically collects and displays these SQL-specific security alerts in its alerts pane. Without ATP enabled, no anomaly-based SQL alert will ever appear in Defender for Cloud, regardless of auditing, firewalls, or service endpoints.

Why this answer

Defender for Cloud's workload protection for Azure SQL databases relies on Advanced Threat Protection (ATP) being enabled at the Azure SQL Server level. Without ATP enabled, Defender for Cloud cannot generate alerts for anomalous activities, regardless of network configurations like VNet service endpoints. Enabling ATP activates the threat detection engine that monitors SQL audit logs for suspicious patterns.

Exam trap

The trap here is that candidates often assume network-level controls (like service endpoints or firewall rules) are the root cause for missing alerts, when the actual requirement is enabling the threat detection feature (ATP) at the server level.

How to eliminate wrong answers

Option A is wrong because the service endpoint is correctly configured for SQL, as stated in the scenario, and service endpoints are for network connectivity, not for enabling threat detection alerts. Option C is wrong because auditing is a prerequisite for ATP to analyze logs, but enabling auditing alone does not activate the threat detection engine; ATP must be explicitly enabled. Option D is wrong because Defender for Cloud does not require specific IP addresses to be allowed; it analyzes audit logs stored in Azure, not direct network traffic to the database.

181
MCQmedium

Your company uses Azure SQL Database to store customer data. You need to ensure that database administrators cannot access sensitive columns (e.g., credit card numbers) even during maintenance. What should you implement?

A.Transparent Data Encryption
B.Dynamic Data Masking
C.Row-level security
D.Always Encrypted
AnswerD

Always Encrypted protects sensitive columns by encrypting data in the client-side driver before it is transmitted to SQL Server, so the database engine only receives and stores ciphertext. The cryptographic keys are held outside the server—in the application’s keystore or Azure Key Vault—and are never provided to the database engine. As a result, not even a DBA with sysadmin privileges can decrypt or view the plaintext values when querying the column, since the server lacks the key material. This is the only option among these that enforces client-side encryption to defeat elevated database permissions.

Why this answer

Always Encrypted ensures that sensitive columns like credit card numbers are encrypted at all times — both at rest and in transit — and that the encryption keys are never revealed to the database engine. This means database administrators (DBAs) cannot decrypt the data even during maintenance, because the decryption happens only on the client side. This directly meets the requirement to prevent DBA access to sensitive columns.

Exam trap

The trap here is that candidates often confuse Dynamic Data Masking with Always Encrypted, thinking masking prevents DBA access, but masking is easily bypassed by privileged users, whereas Always Encrypted provides cryptographic separation of duties.

How to eliminate wrong answers

Option A is wrong because Transparent Data Encryption (TDE) encrypts the entire database at rest but does not protect data from DBAs who have access to the database engine and can query the data while it is in use. Option B is wrong because Dynamic Data Masking only obfuscates data in query results for non-privileged users, but DBAs with elevated permissions can bypass the mask and see the actual values. Option C is wrong because Row-level security controls access to rows based on predicates but does not encrypt or hide column values from DBAs who can query the table.

182
MCQmedium

A company has two Azure virtual networks in different Azure regions that need to communicate with each other. The security policy mandates that all inter-region traffic must be encrypted over the public internet. Which connectivity solution should the company implement to meet this requirement?

A.VNet peering
B.Azure VPN Gateway (site-to-site connection)
C.Azure ExpressRoute
D.Azure Firewall
AnswerB

An Azure VPN Gateway site-to-site connection is the correct choice because it creates an IPsec tunnel using IKE and IPsec protocols, encrypting all data in transit between the two VNets as it travels over the public internet. Each VNet has a gateway endpoint that terminates the secure tunnel, with authentication via pre-shared keys or certificates, and route-based gateways support VNet-to-VNet connections with dynamic routing. This ensures confidentiality and integrity of traffic, which VNet peering does not provide by default.

Why this answer

Azure VPN Gateway with a site-to-site (S2S) connection is the correct solution because it establishes an encrypted IPSec tunnel over the public internet between the two virtual networks. This meets the security mandate for encryption of inter-region traffic traversing the public internet, as IPSec provides confidentiality, integrity, and authentication at the network layer.

Exam trap

The trap here is that candidates often confuse VNet peering (which is private and free of charge within a region) as automatically encrypted, but it does not encrypt traffic over the public internet because it uses Azure's backbone; the question explicitly requires encryption over the public internet, which only a VPN gateway provides.

How to eliminate wrong answers

Option A is wrong because VNet peering uses the Microsoft backbone network, not the public internet, and traffic is not encrypted by default; it relies on Azure's private network infrastructure, which does not satisfy the 'encrypted over the public internet' requirement. Option C is wrong because Azure ExpressRoute uses a dedicated private connection that bypasses the public internet entirely, so it does not meet the 'over the public internet' condition, and encryption is optional (e.g., via MACsec or IPsec over ExpressRoute). Option D is wrong because Azure Firewall is a stateful network security service that filters and inspects traffic but does not provide site-to-site VPN connectivity or encryption between virtual networks; it can be used in conjunction with a VPN gateway but is not a connectivity solution itself.

183
MCQmedium

Your company uses Microsoft Entra ID and Microsoft Intune for mobile device management. You need to ensure that only devices that are compliant with your security policies can access corporate email. You configure a Conditional Access policy targeting Exchange Online. Which grant control should you use?

A.Require multifactor authentication
B.Require device to be marked as compliant
C.Block access
D.Require hybrid Azure AD joined device
AnswerB

This grant control checks the device compliance status reported by Microsoft Intune/Microsoft Entra ID, ensuring the device meets policies such as OS version, disk encryption, and jailbreak detection. Only devices marked as compliant by Intune are allowed access, which directly enforces the requirement to block non-compliant devices.

Why this answer

The scenario requires that only devices compliant with security policies can access corporate email. The 'Require device to be marked as compliant' grant control in Conditional Access checks the device compliance status reported by Microsoft Intune. If the device is not compliant, access to Exchange Online is blocked, ensuring policy enforcement.

Exam trap

The trap here is that candidates often confuse device compliance with device join status (hybrid Azure AD join) or authentication strength (MFA), not realizing that Intune compliance is a separate attribute that must be explicitly required in the grant control.

How to eliminate wrong answers

Option A is wrong because requiring multifactor authentication (MFA) verifies user identity but does not enforce device compliance; a non-compliant device could still access email after MFA. Option C is wrong because 'Block access' is a grant control that unconditionally denies access, which does not allow compliant devices to proceed. Option D is wrong because requiring a hybrid Azure AD joined device enforces domain join status, not Intune compliance; a device could be hybrid joined but still be non-compliant with security policies.

184
Multi-Selecthard

Which TWO components are required to implement a secure hybrid network that connects on-premises to Azure using ExpressRoute? (Choose two.)

Select 2 answers
A.Virtual network gateway in Azure.
B.ExpressRoute circuit.
C.Azure Firewall.
D.Azure VPN Gateway for failover.
E.Azure Front Door.
AnswersA, B

A virtual network gateway in Azure is the required ExpressRoute gateway deployed in the gateway subnet of a virtual network. It terminates the ExpressRoute circuit at the Azure side and enables routing between on-premises networks and the VNet, with SKUs like ErGw1Az/ErGw2Az/ErGw3Az. Without this gateway, the circuit cannot be attached to a virtual network.

Why this answer

Option A is correct because an ExpressRoute connection terminates on a virtual network gateway of type 'ExpressRoute' (ExpressRouteGateway) deployed in the Azure virtual network's GatewaySubnet, which is the mandatory Azure-side endpoint that peers with the ExpressRoute circuit. Option B is correct because the ExpressRoute circuit is the connectivity resource provisioned through a connectivity provider (or ExpressRoute Direct) that establishes the private Layer 3 connection between on-premises and Microsoft's edge, and it is the fundamental component required for any ExpressRoute-based hybrid network. Option C is not required for the connectivity itself; Azure Firewall is an optional security service for traffic inspection and does not establish the ExpressRoute link.

Option D is not required because a VPN Gateway is only an optional failover path (or a separate S2S VPN design), not a mandatory component of an ExpressRoute implementation. Option E is not required because Azure Front Door is a global Layer 7 HTTP/HTTPS load balancer and CDN service, unrelated to private ExpressRoute hybrid connectivity.

Exam trap

A common trap is assuming the Azure VPN Gateway is a required component for ExpressRoute. In fact, it is only used for failover and is not mandatory. The required components are the ExpressRoute circuit and the virtual network gateway.

185
MCQhard

Your company uses Azure Firewall Premium with TLS inspection to filter outbound traffic from Azure VMs. Users report that some websites are not loading. You have configured the firewall to inspect traffic to *.microsoft.com. What is the most likely cause of the issue?

A.The firewall rule for *.microsoft.com is misconfigured.
B.The firewall cannot inspect HTTPS traffic.
C.The firewall is blocking HTTP traffic.
D.The client does not trust the certificate presented by the firewall during TLS inspection.
AnswerD

During TLS inspection, Azure Firewall Premium acts as a proxy: it establishes the TLS connection from the client and presents a certificate issued by your organization's private CA (or custom root). Every client that sends HTTPS through this inspection path must trust that CA certificate in its local certificate store; otherwise the browser or application aborts the handshake with a certificate authority invalid / unknown issuer error. Because the rule configuration and the firewall's inspection capability are both valid, the missing trust anchor on the client is the only remaining explanation.

Why this answer

Azure Firewall Premium with TLS inspection acts as a man-in-the-middle (MITM) proxy. It decrypts outbound HTTPS traffic, inspects it, then re-encrypts it using a certificate signed by an internal CA. If the client VM does not trust the firewall's internal CA certificate (e.g., it is not installed in the Trusted Root Certification Authorities store), the browser will reject the connection, causing websites to fail to load even though the firewall rule is correctly configured.

Exam trap

The trap here is that candidates assume the firewall rule is misconfigured or that HTTPS inspection is impossible, when in fact the core issue is client-side certificate trust, not firewall policy or protocol capability.

How to eliminate wrong answers

Option A is wrong because the firewall rule for *.microsoft.com is explicitly configured and working; the issue is not a misconfiguration of the rule itself but a certificate trust problem. Option B is wrong because Azure Firewall Premium is specifically designed to inspect HTTPS traffic via TLS termination and re-encryption, so it can inspect HTTPS. Option C is wrong because the firewall is not blocking HTTP traffic; the problem is with HTTPS inspection, and HTTP traffic would not be affected by TLS inspection at all.

186
MCQhard

A company stores sensitive files in Azure Files shares. They require encryption at rest using customer-managed keys (CMK) and encryption in transit using SMB 3.0 encryption. They have created a premium Azure Files share in a storage account and configured encryption at rest with a CMK. However, clients are able to connect without enforcing SMB encryption. What additional configuration is necessary to ensure that all connections to the file share are encrypted in transit?

A.Enable the 'Secure transfer required' property on the storage account.
B.Configure a network security group (NSG) to allow only encrypted traffic.
C.Set the minimum SMB protocol version to 3.0 on the file share.
D.Create a service endpoint for the storage account.
AnswerA

Enabling the storage account's 'Secure transfer required' property rejects requests over unencrypted connections. For Azure Files, this forces clients to use SMB 3.0 with encryption (or HTTPS for REST), so sensitive data is encrypted while traversing the network. This is the proper, supported control for enforcing encryption in transit for Azure Files.

Why this answer

Enabling the 'Secure transfer required' property on the storage account enforces encryption in transit for all client connections, including SMB 3.0 encryption for Azure Files. Without this setting, clients can connect using unencrypted SMB 2.1 or SMB 3.0 without encryption, even if the file share itself supports encryption. This property is a storage account-level flag that rejects any request not using HTTPS or SMB 3.0 with encryption.

Exam trap

The trap here is that candidates confuse protocol version enforcement (Option C) with encryption enforcement, not realizing that SMB 3.0 can be used without encryption unless the 'Secure transfer required' property is explicitly enabled.

How to eliminate wrong answers

Option B is wrong because a network security group (NSG) filters traffic at the network layer based on IP addresses and ports, but cannot inspect or enforce SMB encryption at the application layer; it would only block or allow traffic on port 445, not differentiate between encrypted and unencrypted SMB connections. Option C is wrong because setting the minimum SMB protocol version to 3.0 on the file share only restricts the protocol version, but SMB 3.0 can operate without encryption (encryption is an optional feature within SMB 3.0); this does not enforce encryption in transit. Option D is wrong because creating a service endpoint for the storage account secures traffic to the Azure backbone network but does not enforce encryption in transit; it only ensures traffic stays within the Azure network, leaving the connection potentially unencrypted.

187
Multi-Selecteasy

A company stores sensitive financial records in Azure Blob Storage. They want to ensure that if a blob is deleted or overwritten, it can be recovered within 30 days. They also want to protect against accidental deletion of the storage account itself. Which two configurations should they implement? (Choose two.)

Select 2 answers
A.Enable blob soft delete with a retention period of 30 days
B.Enable storage account soft delete with a retention period of 30 days
C.Enable container soft delete with a retention period of 30 days
D.Enable blob versioning
AnswersA, B

Blob soft delete retains deleted or overwritten blobs for a configurable retention period (here, 30 days), so a mistakenly deleted financial record can be undeleted from the soft-deleted state. Unlike versioning, it explicitly covers deletion events, and unlike container soft delete, it operates at the individual blob level, which is where the company's sensitive files live. This makes it a direct data-recovery safeguard for the scenario.

Why this answer

Blob soft delete (Option A) protects individual blobs by retaining deleted or overwritten blobs for a specified retention period, allowing recovery within that window. Storage account soft delete (Option B) protects the entire storage account from accidental deletion by retaining the deleted account for a configurable period. Together, they address both the blob-level and account-level recovery requirements for the 30-day window.

Exam trap

The trap here is that candidates often confuse blob versioning with soft delete, assuming versioning alone provides deletion recovery, but versioning only protects against overwrites, not deletions, and lacks a configurable retention period for recovery.

188
MCQhard

You are a security engineer at Adventure Works. The company has an Azure Kubernetes Service (AKS) cluster that uses the Azure CNI network plugin. The cluster's pods must access an Azure SQL Database securely without traversing the public internet. You need to configure private connectivity from the AKS cluster to the Azure SQL server. What should you implement?

A.Deploy an Azure Firewall in the AKS virtual network and configure DNAT rules to forward SQL traffic to the Azure SQL server's public endpoint.
B.Enable Azure Private Link service on the AKS cluster and create a private endpoint for the SQL server in the AKS subnet.
C.Configure a service endpoint for Microsoft.Sql on the AKS subnet and restrict the Azure SQL server firewall to that subnet.
D.Create an Azure Private Endpoint for the Azure SQL server in a subnet within the AKS virtual network, and configure private DNS integration.
AnswerD

Azure Private Endpoint creates a private IP address for the Azure SQL server inside your virtual network. With private DNS integration, the SQL server's fully qualified domain name resolves to that private IP, so traffic from AKS pods stays on the Microsoft backbone and never goes over the public internet. This meets the secure private connectivity requirement.

Why this answer

Azure Private Endpoint creates a network interface with a private IP address from your virtual network subnet for the Azure SQL server. Combined with private DNS zone integration, the SQL server's name resolves to that private IP, ensuring all traffic from AKS pods remains on the Microsoft backbone. This provides secure, private connectivity without exposing traffic to the public internet.

Exam trap

The trap here is confusing service endpoints with private endpoints; service endpoints secure traffic to the public endpoint of a PaaS service, while private endpoints assign a private IP address within your virtual network for truly private connectivity.

189
MCQhard

A Microsoft Sentinel rule should run with minimal delay against supported data sources and produce alerts close to event time. Which rule type should be considered?

A.Fusion rule
B.Near-real-time analytics rule
C.Workbook query
D.Threat intelligence indicator import
AnswerB

A near-real-time (NRT) analytics rule is executed once every minute against data that was ingested in the previous minute, so it provides the smallest detection-to-action delay of all Microsoft Sentinel rule types. Unlike scheduled analytics rules whose query interval is often 5 minutes or more, NRT rules are explicitly designed for time-sensitive use cases and can trigger automation immediately. This is why they are the correct choice for a rule that must run with minimal delay.

Why this answer

Near-real-time (NRT) analytics rules in Microsoft Sentinel are designed to run at 1-minute intervals, providing the minimal delay for alert generation against supported data sources. This rule type queries data with low latency, ensuring alerts are produced close to the event time, which is critical for timely threat detection.

Exam trap

The trap here is that candidates often confuse near-real-time rules with scheduled analytics rules, assuming scheduled rules can be configured for minimal delay, but NRT rules are the only type that guarantees sub-5-minute latency without custom scheduling.

How to eliminate wrong answers

Option A is wrong because Fusion rules are correlation-based and use machine learning to detect multistage attacks, not designed for minimal delay or near-real-time alerting. Option C is wrong because workbook queries are for visualization and reporting, not for generating alerts or running with minimal delay. Option D is wrong because threat intelligence indicator import is a data ingestion process for bringing in threat indicators, not a rule type that runs queries to produce alerts.

190
MCQeasy

You need to provide secure remote access to Azure virtual machines for developers without exposing public IP addresses. The solution must authenticate users via Microsoft Entra ID and support multifactor authentication. Which service should you use?

A.Azure Front Door
B.Azure VPN Gateway
C.Azure Bastion
D.Azure Firewall
AnswerC

Azure Bastion is a fully managed, agentless PaaS service that provides secure, seamless RDP and SSH connectivity to Azure VMs directly through the Azure portal over TLS. It is deployed in a dedicated subnet (AzureBastionSubnet) and lets users connect to VMs without any public IP, NSG rule allowing inbound RDP/SSH, or additional client software. Bastion integrates with Microsoft Entra ID authentication, MFA, and RBAC, making it the ideal answer for secure browser-based remote access to Azure VMs.

Why this answer

Azure Bastion provides secure RDP/SSH connectivity to Azure virtual machines directly from the Azure portal over TLS, without exposing public IP addresses. It integrates with Microsoft Entra ID for authentication and supports multifactor authentication (MFA) when combined with Conditional Access policies, meeting all requirements.

Exam trap

The trap here is that candidates often confuse Azure Bastion with Azure VPN Gateway, assuming a VPN is required for secure remote access, but Bastion is the correct choice when the goal is to avoid public IPs and integrate directly with Microsoft Entra ID for authentication and MFA.

How to eliminate wrong answers

Option A is wrong because Azure Front Door is a global load balancer and application delivery service for HTTP/HTTPS traffic, not a tool for RDP/SSH access to VMs. Option B is wrong because Azure VPN Gateway creates an encrypted tunnel from on-premises or remote clients to an Azure virtual network, but it requires a public IP address on the gateway and does not natively authenticate via Microsoft Entra ID or enforce MFA without additional components. Option D is wrong because Azure Firewall is a managed network security service that filters traffic based on rules, not a remote access solution for VMs.

191
MCQmedium

A security operations team uses Microsoft Sentinel. They want to create an automation that automatically changes the severity of an incident from 'Medium' to 'High' when a specific indicator of compromise (IOC) is observed in the incident's entities. The playbook should run immediately when the incident is created. Which type of automation rule trigger should they configure?

A.When incident is created
B.When incident is updated
C.When alert is generated
D.Scheduled
AnswerA

The "When incident is created" trigger is an automation rule trigger that fires the moment Microsoft Sentinel generates a new incident, either from an alert or through manual creation. This trigger enables a playbook to begin executing immediately, allowing security teams to perform instant triage, enrichment, or containment actions. It is the only trigger that guarantees execution exactly on incident creation, which is why it is the correct choice for this requirement.

Why this answer

The requirement specifies that the automation should run immediately when the incident is created. In Microsoft Sentinel, an automation rule with the trigger 'When incident is created' executes a playbook as soon as the incident is generated, before any updates occur. This allows the playbook to evaluate the incident's entities (e.g., IP addresses, hashes) and change the severity from 'Medium' to 'High' if a specific IOC is present, meeting the real-time response need.

Exam trap

The trap here is that candidates often confuse 'When alert is generated' with incident creation, not realizing that alerts are raw signals and incidents are the correlated case that can have severity changed, leading them to pick Option C instead of A.

How to eliminate wrong answers

Option B is wrong because 'When incident is updated' triggers only after an incident has been modified (e.g., status change, comment added), not at creation time, so it would not run immediately upon incident generation. Option C is wrong because 'When alert is generated' triggers on individual alerts, not incidents; incidents can aggregate multiple alerts, and the playbook needs to run at the incident level to change incident severity. Option D is wrong because 'Scheduled' triggers run on a recurring schedule (e.g., every hour), not in real-time upon incident creation, which fails the 'immediately' requirement.

192
MCQmedium

A company wants to ensure that users can only access Microsoft 365 services (e.g., Exchange Online, SharePoint Online) from devices that are confirmed to be compliant with corporate security policies (e.g., encryption enabled, antivirus active). Which Azure AD policy type should they create?

A.Conditional Access policy with the 'Require compliant device' grant control.
B.Identity Protection policy with a sign-in risk policy.
C.Access review policy for groups.
D.Privileged Identity Management (PIM) activation policy.
AnswerA

This grant control is enforced by Azure AD during authentication after Intune evaluates the device state; if the device is not enrolled in Mobile Device Management or fails compliance checks (such as missing encryption, a detected jailbreak, or a threat from Microsoft Defender for Endpoint), sign-in is blocked. Because the policy runs in real time on every authentication request, it precisely meets the requirement that users can only access Microsoft 365 services from devices that meet your organization's security baseline. It can also target specific cloud apps and the Microsoft 365 suite, and you can combine it with session controls for additional security.

Why this answer

A is correct because a Conditional Access policy with the 'Require compliant device' grant control enforces device-based access restrictions by checking the device's compliance status reported by Microsoft Intune. This ensures that only devices meeting corporate security policies (e.g., encryption enabled, antivirus active) can access Microsoft 365 services like Exchange Online and SharePoint Online.

Exam trap

The trap here is confusing device compliance (Conditional Access) with sign-in risk (Identity Protection), as both involve 'risk' or 'compliance' terminology but target fundamentally different aspects of security—device state versus authentication risk.

How to eliminate wrong answers

Option B is wrong because Identity Protection sign-in risk policies evaluate the likelihood that a sign-in attempt is unauthorized (e.g., from an anonymous IP or leaked credentials), not the compliance state of the device. Option C is wrong because Access review policies for groups manage periodic attestation of group memberships, not device compliance or access control. Option D is wrong because Privileged Identity Management (PIM) activation policies control the elevation of privileged roles (e.g., Global Admin) and do not enforce device compliance for service access.

193
MCQhard

A Conditional Access policy requiring compliant devices does not apply to Azure PowerShell access. Sign-in logs show the cloud app is excluded. What should be changed?

A.Disable device compliance in Intune
B.Convert the policy to a named location policy
C.Remove MFA from all users
D.Include the relevant cloud app or target all cloud apps after testing exclusions
AnswerD

A compliant-device policy does not automatically select which cloud apps are protected; you must explicitly add a target resource (cloud app or action) in the policy's assignments. To avoid blanket lockout, start with a pilot group and a specific app like Exchange Online, then expand to 'All cloud apps' with carefully tested exclusions. Without this assignment, the grant control has no app to apply to, so the policy is effectively inert.

Why this answer

Conditional Access policies apply only to cloud apps explicitly included in the policy. Since Azure PowerShell is excluded, the policy does not enforce the 'Require device to be marked as compliant' condition for that app. To fix this, you must either include the specific cloud app (Microsoft Azure PowerShell) or set the policy to target 'All cloud apps' and then test exclusions to ensure the compliant device requirement is applied to Azure PowerShell access.

Exam trap

The trap here is that candidates may assume a Conditional Access policy applies to all cloud apps by default, but in reality, policies only apply to apps explicitly included, and exclusions take precedence over inclusions.

How to eliminate wrong answers

Option A is wrong because disabling device compliance in Intune would remove the compliance status altogether, breaking the policy's intent rather than fixing the exclusion issue. Option B is wrong because converting the policy to a named location policy would change the condition from device compliance to network location, which does not address the missing cloud app inclusion for Azure PowerShell. Option C is wrong because removing MFA from all users is unrelated to the cloud app exclusion; MFA is a separate control and removing it would weaken security without resolving the policy scope problem.

194
MCQeasy

Your company has multiple Azure subscriptions and wants to use Microsoft Sentinel as a SIEM. You need to collect security events from all Azure VMs, including existing and future ones. What should you use?

A.Use the Azure portal to enable 'Security Center' on each VM.
B.Use Azure Automation Desired State Configuration (DSC) to push the agent.
C.Manually install the Log Analytics agent on each VM.
D.Create an Azure Policy assignment to deploy the Log Analytics agent.
AnswerD

Creating an Azure Policy assignment using a built-in definition such as 'Deploy Log Analytics agent to Windows VMs' automatically installs the agent on both existing and future VMs in the assigned scope via a deployIfNotExists effect. This approach centralizes governance at the subscription or management group level, requires only a Log Analytics workspace ID as a parameter, and continuously enforces compliance without human intervention.

Why this answer

Azure Policy can automatically deploy the Log Analytics agent to all existing and future Azure VMs via the 'Deploy Log Analytics agent for Windows/Linux VMs' built-in policy. This ensures consistent security event collection for Microsoft Sentinel without manual intervention, scaling across multiple subscriptions and VM lifecycles.

Exam trap

The trap here is that candidates often confuse manual or automation-based agent installation (options A, B, C) with the policy-driven, at-scale deployment that Azure Policy provides, which is the only method that automatically covers both existing and future resources without ongoing manual effort.

How to eliminate wrong answers

Option A is wrong because enabling 'Security Center' on each VM via the portal is a manual, per-VM action that does not scale to future VMs and does not directly deploy the Log Analytics agent required for Sentinel data ingestion. Option B is wrong because Azure Automation DSC is a configuration management tool for applying desired state configurations, not a scalable, policy-driven mechanism to deploy agents across all VMs in a subscription; it requires targeting individual VMs or VM sets and does not automatically cover new VMs. Option C is wrong because manually installing the Log Analytics agent on each VM is impractical for large environments, does not enforce compliance, and fails to cover future VMs without repeated manual effort.

195
MCQmedium

A security operations team uses Microsoft Sentinel. They want to create a custom analytics rule that detects when an Azure virtual machine is created with a public IP address that is not in an approved list. Which type of rule should they use?

A.Scheduled query rule
B.NRT rule
C.Anomaly rule
D.Fusion rule
AnswerA

Correct. Scheduled query rules allow you to run a KQL query on a schedule and create incidents based on the results. This is ideal for checking new VM creations against an approved IP list.

Why this answer

A scheduled query rule is the correct choice because it allows you to define a KQL query that runs on a recurring schedule (e.g., every 5 minutes) to detect when an Azure VM is created with a public IP not in an approved list. This rule type is designed for custom detection logic that requires periodic evaluation of log data, such as AzureActivity logs or Azure Resource Graph, making it ideal for this scenario.

Exam trap

The trap here is that candidates confuse NRT rules with scheduled query rules, assuming NRT's lower latency is always better, but NRT rules lack the ability to reference external data sources like watchlists for dynamic approved IP comparisons.

How to eliminate wrong answers

Option B (NRT rule) is wrong because near-real-time rules are designed for low-latency detection (up to 2 minutes) but do not support the complex KQL logic needed to cross-reference a dynamic approved list; they are better suited for simple, high-frequency patterns. Option C (Anomaly rule) is wrong because anomaly rules use machine learning to detect unusual patterns in time-series data, not static comparisons against an approved list. Option D (Fusion rule) is wrong because fusion rules are prebuilt for multi-stage attack detection across different data sources, not for custom single-condition checks like VM creation with an unapproved public IP.

196
MCQhard

You are a security administrator for a company that uses Microsoft Entra ID. You need to provide a partner organization with access to specific resources in your tenant. The partner users must use their own credentials, and you must be able to revoke access without managing their accounts. What should you configure?

A.Configure B2C authentication with a local account for each partner user.
B.Create an app registration and share the client secret with the partner organization.
C.Create guest user accounts in your tenant and assign them to a security group.
D.Configure B2B collaboration with a cross-tenant access policy that allows the partner tenant and grants access to a specific enterprise application.
AnswerD

Microsoft Entra B2B collaboration lets partner users authenticate with their home tenant credentials, and cross-tenant access policies control inbound access. You can scope access to specific applications and revoke it by changing the policy, without managing the partner's accounts.

Why this answer

B2B collaboration with cross-tenant access settings allows partner users to authenticate against their home tenant while you control which applications and resources they can access. Revocation is achieved by modifying or deleting the cross-tenant access policy or the application assignment, without managing partner accounts.

Exam trap

The trap here is confusing B2B collaboration with B2C or guest account management, which involve different identity models and administrative overhead.

197
MCQmedium

A company has an Azure SQL Database that stores personally identifiable information (PII) in columns. They need to encrypt those columns so that only authorized applications can decrypt the data, and even database administrators cannot view the plaintext. Additionally, they need to support equality comparisons (WHERE clauses) on the encrypted columns. Which encryption technology should they use?

A.Always Encrypted with deterministic encryption
B.Always Encrypted with randomized encryption
C.Transparent Data Encryption (TDE)
D.Dynamic Data Masking
AnswerA

Always Encrypted with deterministic encryption encrypts PII client-side so the SQL engine and database administrators never see plaintext. It uses a deterministic algorithm where the same plaintext always produces the same ciphertext for a given column encryption key, enabling the server to perform equality comparisons in WHERE, JOIN, and GROUP BY clauses. This supports business queries that require filtering on PII (e.g., searching by social security number) while preserving confidentiality. However, deterministic encryption can reveal equality patterns and is less secure than randomized, but it remains the correct choice for applications needing strict DBA access control.

Why this answer

Always Encrypted with deterministic encryption is the correct choice because it encrypts PII columns at the client side, ensuring that even database administrators cannot view plaintext data. Deterministic encryption generates the same ciphertext for the same plaintext, which allows equality comparisons (WHERE clauses) on encrypted columns, meeting the requirement for query support.

Exam trap

The trap here is that candidates often confuse Always Encrypted with TDE, thinking TDE provides client-side encryption and column-level query support, but TDE only encrypts data at rest and does not prevent database administrators from seeing plaintext data in memory or during queries.

How to eliminate wrong answers

Option B is wrong because Always Encrypted with randomized encryption does not support equality comparisons; it produces different ciphertext for the same plaintext, making WHERE clauses impossible on encrypted columns. Option C is wrong because Transparent Data Encryption (TDE) encrypts data at rest (the entire database file) but does not protect data from database administrators who have access to the database engine, and it does not support column-level encryption or client-side key control. Option D is wrong because Dynamic Data Masking only obfuscates data at query results for unauthorized users, but the underlying data remains in plaintext in storage and can be accessed by administrators or through direct queries.

198
MCQmedium

A cloud security team wants Defender for Cloud to assess AWS accounts and GCP projects from the same portal used for Azure posture management. What should they configure?

A.Environment settings with multicloud connectors
B.Azure Arc-enabled Kubernetes only
C.Microsoft Sentinel data connector for AWS CloudTrail only
D.Azure Lighthouse delegation
AnswerA

Environment settings in Microsoft Defender for Cloud provide the multicloud connectors that onboard AWS accounts at the subscription level, enabling continuous security posture management (CSPM), asset inventory, and regulatory compliance scoring across AWS services. The connector integrates with AWS Security Hub and CloudTrail to aggregate findings, and without creating this connector, Defender for Cloud cannot assess the AWS environment. This is the only option that directly fulfills the stated requirement for cloud security assessment.

Why this answer

Defender for Cloud's multicloud connectors allow you to onboard AWS accounts and GCP projects directly into the Azure portal, enabling unified security posture management across all three cloud environments. This feature integrates with AWS Security Hub and GCP Security Command Center to aggregate findings and assessments into a single dashboard, without requiring any migration of workloads.

Exam trap

The trap here is that candidates confuse Defender for Cloud's multicloud posture assessment with Microsoft Sentinel's SIEM data connectors, assuming any cloud integration must go through Sentinel, when in fact Defender for Cloud has its own dedicated multicloud connector for posture management.

How to eliminate wrong answers

Option B is wrong because Azure Arc-enabled Kubernetes only extends Azure management to Kubernetes clusters running outside Azure, not to AWS accounts or GCP projects for cloud posture assessment. Option C is wrong because Microsoft Sentinel's data connector for AWS CloudTrail is designed for security information and event management (SIEM) ingestion, not for continuous cloud security posture assessment and compliance monitoring. Option D is wrong because Azure Lighthouse delegation is used for managing multiple Azure tenants from a single control plane, not for integrating non-Azure cloud providers like AWS or GCP.

199
MCQmedium

A privileged administrator should activate the Security Administrator role only for approved work and for a limited time. What should be configured?

A.Permanent active assignment in Microsoft Entra ID
B.Eligible assignment with activation controls in Privileged Identity Management
C.Owner role at the subscription root
D.Conditional Access session persistence
AnswerB

An eligible assignment in Privileged Identity Management (PIM) allows the administrator to activate the security role on demand for a limited time, with activation controls such as MFA, business justification, approval workflows, and a maximum duration. This provides just-in-time privileged access, ensuring the security role is not permanently active and its permissions are only used after successful activation. This directly satisfies the requirement.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure eligible assignments for roles like Security Administrator. This means the user must activate the role on demand, with time-bound activation controls (e.g., maximum activation duration, approval, MFA), ensuring the role is used only for approved work and for a limited time. This directly meets the requirement of just-in-time (JIT) access and temporary activation.

Exam trap

The trap here is that candidates often confuse permanent active assignments (Option A) with eligible assignments, mistakenly thinking that permanent assignment is sufficient if the user is trusted, but the question explicitly requires 'limited time' activation, which only PIM can enforce.

How to eliminate wrong answers

Option A is wrong because a permanent active assignment grants the role continuously without any time limit or activation requirement, violating the principle of limited-time access. Option C is wrong because the Owner role at the subscription root is an Azure RBAC role, not a Microsoft Entra ID administrative role, and it does not provide the Security Administrator permissions needed for identity security tasks; it also lacks time-bound activation controls. Option D is wrong because Conditional Access session persistence controls how long a user stays signed in (e.g., browser session persistence), not the activation or duration of a privileged role assignment.

200
Multi-Selectmedium

You are designing network security for a three-tier application. You need to isolate each tier (web, application, data) and control traffic between them. Which TWO Azure services should you use to achieve this? (Choose two.)

Select 2 answers
A.Network Security Groups (NSGs)
B.VNet peering
C.Azure Policy
D.Azure Firewall
E.Application Security Groups (ASGs)
AnswersA, E

Network Security Groups (NSGs) serve as the core stateful filtering mechanism inside Azure VNets, with rules evaluated by priority to permit or deny traffic based on the 5-tuple (source, destination, port, protocol, direction). Applying NSGs to subnets or VM NICs allows you to segment a three-tier application by isolating the web, business, and data tiers from each other. They are the native, default choice for tier isolation because they require no extra cost and offer granular control over east-west traffic.

Why this answer

Network Security Groups (NSGs) are correct because they let you define inbound and outbound security rules (by IP, port, and protocol) that filter traffic to and from subnets or NICs, which is exactly how you enforce isolation and control traffic between the web, application, and data tiers. Application Security Groups (ASGs) are correct because they let you group VMs by workload role (for example, web, app, or data) and then reference those groups as sources/destinations in NSG rules, so you can control tier-to-tier traffic without hardcoding individual IP addresses. Together, NSGs provide the filtering mechanism and ASGs provide the logical grouping that makes tier-based rules scalable and maintainable.

VNet peering only connects virtual networks for private IP communication and does not itself filter or isolate tier traffic. Azure Policy is a governance/compliance tool for enforcing resource configurations, not a runtime traffic filter. Azure Firewall is a centralized, stateful network security service, but it is not the service used to isolate individual tiers within a VNet via subnet/NIC-level rules and workload grouping.

Exam trap

The trap here is that candidates often choose Azure Firewall for all traffic control scenarios, overlooking that NSGs and ASGs are the native, lightweight solution for east-west traffic isolation within a single VNet, while Azure Firewall is designed for centralized, cross-VNet, and outbound traffic inspection.

201
Multi-Selecthard

You are designing a secure network architecture for a multi-region application. You need to ensure that traffic between virtual networks in different Azure regions is encrypted and uses the Microsoft backbone network, and you must minimize latency. Which TWO configurations should you implement?

Select 1 answer
A.Enable 'Gateway transit' on the peering to use a VPN gateway if needed, but not required for encryption.
B.Configure VNet peering between the virtual networks.
C.Use Azure ExpressRoute with Microsoft peering.
D.Deploy Azure VPN Gateway in each region and connect them via site-to-site VPN.
E.Place an Azure Firewall in each region to inspect cross-region traffic.
AnswersB

VNet peering connects VNets using the Microsoft backbone and can be enabled globally.

Why this answer

Option B (Configure VNet peering between the virtual networks) is correct because Azure VNet peering routes traffic directly over the Microsoft backbone network, keeping it off the public internet and providing the lowest-latency path between VNets in different regions (global VNet peering). Option C is incorrect because ExpressRoute with Microsoft peering is used to reach Microsoft public services such as Microsoft 365 and Azure PaaS, not to connect virtual networks to each other, and ExpressRoute does not encrypt traffic by default. Option A is not required because gateway transit only lets a peered VNet share a VPN/ExpressRoute gateway; it does not itself provide encryption for VNet-to-VNet traffic.

Option D is not the best choice because site-to-site VPN traffic traverses the public internet and typically adds latency compared with backbone-based peering. Option E is incorrect because Azure Firewall inspects and filters traffic but does not encrypt cross-region traffic or optimize latency.

Exam trap

Candidates often assume that a VPN gateway or ExpressRoute is required for encrypted cross-region VNet traffic, but VNet peering already routes traffic over the Microsoft backbone. Note that ExpressRoute with Microsoft peering is for Microsoft public services, not VNet-to-VNet connectivity, and does not provide encryption by default.

202
MCQmedium

You have configured the Conditional Access policy shown in the exhibit. Users report that they can still access Exchange Online using legacy authentication protocols. What is the most likely reason?

A.The policy should use 'Require MFA' instead of 'Block'
B.The policy does not include the correct client app types
C.The policy state is set to reporting mode
D.The policy should include 'mobileAppsAndDesktopClients' instead
AnswerC

Conditional Access policies in report-only mode (also called reporting mode) are evaluated against the conditions and the result is logged in the sign-in logs, but the configured access controls are never applied. As a result, a Block control will not prevent the user from accessing the resource; the policy only emits a 'reportOnly: failure' entry. To enforce the block, the policy state must be set to 'Enabled' (or 'On'), which applies the Block control during authentication. This is the direct reason why the block is not in effect.

Why this answer

The policy state is set to 'Report-only' (reporting mode), which means the Conditional Access policy is evaluated but not enforced. Users can still access Exchange Online using legacy authentication because the policy only logs the outcome without blocking access. To enforce the block, the policy state must be set to 'On'.

Exam trap

The trap here is that candidates often overlook the policy state setting and focus on grant controls or client app types, assuming a 'Block' control is always enforced, but Azure AD's reporting mode explicitly disables enforcement regardless of other configurations.

How to eliminate wrong answers

Option A is wrong because 'Require MFA' would grant access after MFA, not block legacy authentication; the goal is to block legacy protocols, and 'Block' is the correct grant control for that. Option B is wrong because the policy does include the correct client app types—legacy authentication is covered by the 'Exchange ActiveSync clients' and 'Other clients' selections, which are the appropriate app types for blocking legacy protocols. Option D is wrong because 'mobileAppsAndDesktopClients' targets modern authentication clients, not legacy protocols; legacy authentication is specifically controlled via 'Exchange ActiveSync clients' and 'Other clients'.

203
MCQmedium

You are deploying a web application in Azure that must be accessible only from your corporate network via HTTPS. You have an Azure Application Gateway with a Web Application Firewall (WAF) policy. Your corporate network uses public IP addresses from a specific range. Which configuration should you use to restrict access?

A.Configure a WAF policy with a custom rule to allow traffic only from the corporate IP range and deny all other traffic.
B.Create a network security group (NSG) on the subnet hosting the application gateway and allow only the corporate IP range.
C.Use Azure Front Door with a WAF policy and geo-filtering to allow only your country.
D.Set up a private endpoint for the application gateway and disable public access.
AnswerA

A WAF policy attached to the Application Gateway can use custom rules to match on the source IP address of incoming requests. You would create a rule that permits traffic only from your corporate IP CIDR range and a subsequent (or lower-priority) rule that denies all other traffic, effectively whitelisting the corporate network. Since WAF operates at Layer 7, this restriction works alongside HTTPS termination or pass-through and does not affect the transport-level encryption.

Why this answer

Azure Application Gateway's WAF policy supports custom rules that can inspect source IP addresses and allow or deny traffic based on them. By creating a custom rule with a condition matching the corporate public IP range and setting the action to 'Allow', then adding a default 'Deny' rule, you restrict access exclusively to that range over HTTPS. This approach works at the application layer (Layer 7) and is independent of network-level controls, making it the most direct and supported method for IP-based restriction on the gateway itself.

Exam trap

The trap here is that candidates often confuse network-layer controls (NSGs) with application-layer controls (WAF custom rules) and assume an NSG on the gateway subnet is the correct way to restrict access, but NSGs block traffic before the WAF can inspect it, breaking the intended security model.

How to eliminate wrong answers

Option B is wrong because an NSG applied to the Application Gateway subnet would block traffic before it reaches the gateway's WAF, preventing the WAF from inspecting legitimate traffic and potentially breaking health probes or backend communication; NSGs are for network-layer filtering, not for application-layer IP restriction on the gateway. Option C is wrong because Azure Front Door with geo-filtering restricts by country, not by specific corporate IP range, and introduces an additional service that is not required for this scenario; the question explicitly requires access only from a specific corporate IP range, not a geographic region. Option D is wrong because a private endpoint for the Application Gateway is not a supported configuration—private endpoints are used for PaaS services like Storage or SQL, not for Application Gateway; disabling public access would make the gateway unreachable from the corporate network if it relies on public IPs.

204
Drag & Dropmedium

Drag and drop the steps to configure Azure AD Conditional Access policy to require MFA for all users into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Conditional Access policies require defining users and access controls before enabling.

205
MCQmedium

Your organization uses Microsoft Entra ID. You need to manage access to a line-of-business application that supports SAML 2.0. The application should be integrated as an enterprise application in Entra ID. What steps must you take?

A.Configure user consent settings for the application
B.Register the application in App Registrations and configure SAML
C.Create a new enterprise application as a non-gallery app, configure SAML, assign users, and test
D.Add the application from the Azure AD gallery
AnswerC

This is the correct approach because a non-gallery enterprise application acts as a container for your custom SAML application's service principal and all SSO settings. After adding it, you configure SAML 2.0 by providing the application's identifier and reply URL, uploading or generating a signing certificate, and mapping user attributes to the claims. You then assign users or groups to the enterprise application to validate access, and use the built-in test functionality to confirm the federated sign-in flow works end-to-end.

Why this answer

To integrate a line-of-business application that supports SAML 2.0 as an enterprise application in Microsoft Entra ID, you must create a new enterprise application using the 'Non-gallery application' option, configure SAML-based sign-on with the application's metadata, assign users or groups, and test the integration. This process allows you to define custom SAML attributes and claims specific to the application, which is necessary for non-gallery apps that are not pre-integrated.

Exam trap

The trap here is that candidates confuse App Registrations (used for OAuth/OpenID Connect) with Enterprise applications (used for SAML and gallery apps), leading them to choose Option B instead of correctly selecting the non-gallery enterprise application creation path.

How to eliminate wrong answers

Option A is wrong because configuring user consent settings controls whether users can consent to permissions for applications, but it does not create or integrate the enterprise application itself; consent settings are a separate administrative control. Option B is wrong because registering the application in App Registrations creates a service principal for custom-developed apps, but enterprise applications for SAML integration are created directly under 'Enterprise applications' in the portal, not via App Registrations; App Registrations is for OAuth/OpenID Connect apps, not SAML. Option D is wrong because adding the application from the Azure AD gallery is only possible if the application is pre-integrated and listed in the gallery; for a custom line-of-business application that supports SAML 2.0 but is not in the gallery, you must use the non-gallery option.

206
MCQmedium

A company uses Microsoft Sentinel as its SIEM. The security team wants to automatically respond to phishing emails detected by Microsoft Defender XDR. They want to create a playbook that, when triggered, will delete the email from all recipients' mailboxes. Which integration should the playbook use?

A.Microsoft Graph API
B.Microsoft Power Automate
C.Exchange Online PowerShell
D.Microsoft 365 Defender API
AnswerA

The Microsoft Graph API provides a unified REST endpoint for Microsoft 365 services, including Outlook mail, enabling Sentinel playbooks to execute remediation actions such as soft-deleting or purging malicious emails from a user's mailbox. Since Sentinel's Logic Apps connector supports HTTP requests to Graph API with proper OAuth authentication, it is the appropriate mechanism for mailbox-level threat remediation within an automated incident response workflow. Unlike PowerShell or other APIs, Graph API is directly consumable from a playbook and is designed for cross-service automation.

Why this answer

The Microsoft Graph API provides the necessary endpoints to programmatically access and manipulate Exchange Online mail items, including deleting emails from user mailboxes. A Sentinel playbook can use an HTTP trigger with the Graph API to perform the deletion action on behalf of the security team, enabling automated remediation of phishing emails across all recipients.

Exam trap

The trap here is that candidates confuse the Microsoft 365 Defender API (which handles detection data) with the Microsoft Graph API (which handles mailbox actions), leading them to select D instead of A.

How to eliminate wrong answers

Option B is wrong because Microsoft Power Automate is a workflow automation platform that can be used to build playbooks, but it is not the integration itself; the playbook would still need to call an API (like Graph API) to delete emails. Option C is wrong because Exchange Online PowerShell requires a persistent connection and is not designed for serverless, event-driven automation within a Sentinel playbook; it also lacks native HTTP trigger support. Option D is wrong because the Microsoft 365 Defender API focuses on threat detection and investigation data (e.g., alerts, incidents), not on direct mailbox manipulation like deleting emails.

207
MCQmedium

A Defender for Cloud secure score recommendation says storage accounts allow public blob access. What remediation best addresses the root issue?

A.Enable storage account static website hosting
B.Increase Log Analytics retention
C.Disable public blob access at the storage account level and review container ACLs
D.Create an Azure Front Door profile
AnswerC

Disabling public blob access at the storage account root overrides any container-level permission to 'public read access' for blobs or containers, preventing anonymous requests. Reviewing container Access Control Lists (ACLs) ensures no individual container has been set to allow public access, closing the exact misconfiguration flagged by Defender for Cloud. This directly reduces the attack surface and aligns with the principle of default-deny for storage data.

Why this answer

The secure score recommendation indicates that storage accounts allow public blob access, which is a security risk. The root cause is that anonymous access is enabled at the storage account level, and individual container ACLs may also permit public access. Disabling public blob access at the storage account level (via the 'AllowBlobPublicAccess' property) immediately blocks all anonymous requests, and reviewing container ACLs ensures no residual permissions exist.

This directly addresses the vulnerability by enforcing a deny-by-default posture.

Exam trap

The trap here is that candidates may confuse the storage account-level public access setting with container-level ACLs, thinking that disabling one automatically disables the other, or they may mistakenly believe that enabling static website hosting or using Front Door can override or mitigate the public access vulnerability.

How to eliminate wrong answers

Option A is wrong because enabling static website hosting does not affect public blob access settings; it only serves static content from a specific container ($web) and does not remediate the security recommendation. Option B is wrong because increasing Log Analytics retention only extends the storage duration of diagnostic logs, which does not change access permissions or block anonymous blob access. Option D is wrong because creating an Azure Front Door profile is a content delivery and acceleration service that does not modify storage account access policies or disable public blob access.

208
MCQhard

Refer to the exhibit. You have an Azure Application Gateway WAF policy with the above JSON configuration. A user from IP address 10.1.2.3 reports they cannot access the web application. What is the most likely cause?

A.The WAF policy is in prevention mode and detected a SQL injection.
B.The WAF policy is set to detection mode and logs the request.
C.The custom rule is disabled due to a syntax error.
D.The custom rule blocks all private IP addresses.
AnswerD

The custom rule explicitly defines a match condition on the client's source IP and uses action "Block" to deny traffic from RFC 1918 private ranges (10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16). Because the request's source IP falls inside 10.0.0.0/8, the custom rule matches and enforces the block immediately. In Application Gateway WAF, custom rules are evaluated before managed rule sets, so this request is denied without ever being inspected for SQL injection or other managed signatures.

Why this answer

The custom rule in the WAF policy explicitly blocks all traffic from IP addresses in the 10.0.0.0/8 private range. Since the user's IP address (10.1.2.3) falls within this range, the rule matches and blocks the request. The WAF policy is in prevention mode, so the rule actively blocks the request rather than just logging it.

Exam trap

The trap here is that candidates may overlook the custom rule's IP range and assume the issue is related to SQL injection or detection mode, when in fact the problem is a simple IP-based block rule targeting private addresses.

How to eliminate wrong answers

Option A is wrong because the JSON configuration shows no SQL injection detection rules are configured; the only rule is a custom IP-based block rule. Option B is wrong because the WAF policy is set to 'Prevention' mode (as shown in the JSON), not 'Detection' mode, so it actively blocks requests rather than just logging them. Option C is wrong because the custom rule is syntactically valid (it has proper JSON structure, a valid priority, condition, and action), and there is no indication of a syntax error.

209
MCQhard

You have configured Microsoft Sentinel to ingest logs from Azure Active Directory (now Microsoft Entra ID). You notice that sign-in logs for external guest users are not appearing in Sentinel. What is the most likely cause?

A.The diagnostic settings in Microsoft Entra ID are not configured to stream sign-in logs to the Log Analytics workspace used by Sentinel.
B.Microsoft Sentinel does not support ingestion of external guest user sign-in logs.
C.The Microsoft Sentinel Entra ID connector requires a separate connector for guest users.
D.Guest user sign-ins are not logged in Microsoft Entra ID.
AnswerA

The Microsoft Entra ID connector for Microsoft Sentinel relies on diagnostic settings that must be explicitly enabled in Microsoft Entra ID to route sign-in logs to a Log Analytics workspace. If these settings are absent or misconfigured, sign-in log ingestion fails even though the Sentinel connector itself appears connected, which precisely matches the reported symptom. You must verify that the diagnostic setting streams AuditLogs and SignInLogs to the same workspace that Sentinel uses, and that the workspace ID matches the one selected in the connector.

Why this answer

Microsoft Sentinel ingests Azure AD (Entra ID) logs via diagnostic settings configured on the Entra ID tenant. These settings must explicitly stream sign-in logs (including guest user sign-ins) to a Log Analytics workspace. If the diagnostic settings are missing or misconfigured, no sign-in logs—including those for external guest users—will appear in Sentinel.

Exam trap

The trap here is that candidates may assume guest user logs require a special connector or are not logged at all, when in reality the issue is simply a missing or incomplete diagnostic settings configuration in Entra ID.

How to eliminate wrong answers

Option B is wrong because Microsoft Sentinel fully supports ingestion of external guest user sign-in logs as long as the diagnostic settings stream them to the workspace. Option C is wrong because there is no separate connector for guest users; the single Entra ID connector handles all sign-in logs, including guest sign-ins, based on the diagnostic settings. Option D is wrong because Azure AD (Entra ID) does log guest user sign-ins in the Sign-in logs, provided the guest user has signed in at least once.

210
MCQmedium

You manage Azure Storage accounts for a healthcare organization. To comply with HIPAA, you need to ensure that all data at rest is encrypted and that encryption keys are rotated automatically every 90 days. What should you implement?

A.Configure Azure RBAC roles for storage accounts.
B.Enable infrastructure encryption for storage accounts.
C.Generate new storage account access keys manually every 90 days.
D.Use customer-managed keys (CMK) in Azure Key Vault with automatic key rotation.
AnswerD

Customer-managed keys in Azure Key Vault let you supply the key encryption key (KEK) that wraps the data encryption key (DEK) used to encrypt every storage object, giving you full control over key lifecycle. When you enable automatic key rotation, Azure Key Vault creates a new key version according to the rotation policy you define, and Azure Storage re-wraps the DEK without any downtime or data re-encryption. This directly satisfies both the encryption-at-rest and automatic-rotation requirements, which is why it is the correct choice.

Why this answer

Customer-managed keys (CMK) stored in Azure Key Vault with automatic key rotation fulfill the requirement for encrypted data at rest and automatic rotation of encryption keys. This ensures that HIPAA compliance is met by maintaining control over encryption keys and enforcing their periodic rotation. The other options do not provide automatic key rotation: RBAC controls access but does not rotate keys; infrastructure encryption adds another layer but does not include key rotation; manually rotating storage account access keys addresses authentication keys, not encryption keys, and is not automatic.

Exam trap

The main trap is confusing storage account access keys (used for authentication) with encryption keys (used for data at rest). Candidates may choose manual rotation of access keys, but that does not meet the automatic rotation requirement for encryption keys and only addresses a different type of key.

How to eliminate wrong answers

Option A is wrong because Azure RBAC roles control access permissions to storage accounts (e.g., who can read/write data), not encryption or key rotation. Option B is wrong because infrastructure encryption adds an extra layer of encryption at the infrastructure level but does not manage or rotate access keys. Option C is wrong because manually generating new storage account access keys every 90 days is error-prone, does not scale, and does not meet the requirement for automatic rotation; it also does not address encryption at rest with customer-controlled keys.

211
MCQhard

You are deploying an Azure SQL Database with a security alert policy as shown in the exhibit. Which statement is true?

A.Alerts are enabled and notifications are sent to both account admins and admin@contoso.com.
B.Email notifications are sent only to admin@contoso.com.
C.Alerts are not retained because retentionDays is set to 30.
D.All alerts are disabled because disabledAlerts is empty.
AnswerA

This configuration is correct because the security alert policy has its state set to Enabled, meaning alerts are actively generated. With emailAccountAdmins set to true, all Azure subscription account administrators receive alert notifications, and since emailAddresses explicitly includes admin@contoso.com, that address is also notified. Thus alerts go to both account admins and the specified email address.

Why this answer

The security alert policy in Azure SQL Database has 'state' set to 'Enabled' and 'emailAddresses' includes both 'admin@contoso.com' and the account admins (via 'emailAccountAdmins' set to true). This means alerts are active and notifications are sent to both the specified email and the account administrators, making option A correct.

Exam trap

The trap here is that candidates often assume an empty 'disabledAlerts' list means all alerts are disabled, but in Azure SQL Database, an empty list means no alerts are excluded, so all are enabled by default.

How to eliminate wrong answers

Option B is wrong because the policy explicitly sets 'emailAccountAdmins' to true, so notifications are sent to account admins in addition to admin@contoso.com, not only to admin@contoso.com. Option C is wrong because 'retentionDays' set to 30 controls how long alert data is retained in the log, not whether alerts are enabled or disabled; alerts are still generated and sent. Option D is wrong because an empty 'disabledAlerts' array means no specific alert types are disabled, so all alerts are enabled by default, not disabled.

212
Multi-Selecteasy

Which TWO are valid connection methods for Azure VPN Gateway? (Choose two.)

Select 2 answers
A.Point-to-Site
B.VNet-to-VNet
C.Site-to-Site
D.Azure Bastion
E.ExpressRoute
AnswersA, C

Azure VPN Gateway's Point-to-Site method allows individual client computers to establish a secure connection to a VNet from any location, using SSTP, IKEv2, or OpenVPN protocols. Each client authenticates via certificates or Azure AD, and traffic is wrapped in IPsec for IKEv2/OpenVPN or SSL/TLS for SSTP. It is one of the two primary VPN connection methods, distinct from Site-to-Site because it does not require a public-facing VPN device on the customer side.

Why this answer

Point-to-Site (P2S) is a valid connection method for Azure VPN Gateway because it allows individual client computers to connect securely to an Azure virtual network from anywhere using the SSTP, IKEv2, or OpenVPN protocols. This method is ideal for remote workers who need encrypted access without requiring a site-level VPN device.

Exam trap

The trap here is that candidates often confuse VNet-to-VNet as a distinct connection method when it is actually a specific use case of Site-to-Site, and they may also mistakenly think Azure Bastion or ExpressRoute are VPN gateway connection types when they are separate Azure services with different purposes.

213
MCQeasy

A company has an Azure virtual network with subnets SubnetA and SubnetB. They deploy a network virtual appliance (NVA) in a subnet called NVA_Subnet. They want all traffic between SubnetA and SubnetB to be routed through the NVA for inspection. What is the minimum number of route tables and routes required?

A.One route table with a route for each subnet via the NVA
B.Two route tables, each with a route to the other subnet via the NVA
C.No route tables needed; enable IP forwarding on the NVA
D.One route table with a single default route (0.0.0.0/0) via the NVA
AnswerB

A route table associated with a subnet influences only traffic originating from that subnet. Because subnet A and subnet B have different destination prefixes for their inter-subnet traffic, the proper design is two custom route tables, one bound to each subnet, each containing a single route: for subnet A, destination subnet B's address prefix with next hop set to the NVA; for subnet B, destination subnet A's prefix with next hop to the NVA. This forces the NVA to inspect every packet crossing between the two subnets while leaving all other traffic to the system routes.

Why this answer

Azure route tables are associated with subnets, not the virtual network as a whole. To force traffic between SubnetA and SubnetB through the NVA, you need two separate route tables: one for SubnetA with a route to SubnetB's address space with the next hop set to the NVA's private IP, and one for SubnetB with a route to SubnetA's address space with the next hop set to the NVA's private IP. This ensures bidirectional traffic is inspected.

Exam trap

The trap here is that candidates assume a single route table can be applied to multiple subnets or that a default route (0.0.0.0/0) will force inter-subnet traffic through the NVA, when in fact Azure requires explicit routes for each subnet's destination address space and separate route table associations per subnet.

How to eliminate wrong answers

Option A is wrong because a single route table cannot be associated with both subnets simultaneously; each subnet can have only one route table, and a single route table with routes for both subnets would require associating it with both subnets, which is not possible in Azure. Option C is wrong because IP forwarding on the NVA is necessary but not sufficient; without custom routes, Azure's default system routes would allow direct communication between SubnetA and SubnetB, bypassing the NVA. Option D is wrong because a default route (0.0.0.0/0) via the NVA would send all internet-bound traffic through the NVA, not specifically traffic between the two subnets, and would not force inter-subnet traffic through the NVA unless the subnets' address spaces are also covered by the default route, which is not the intended design.

214
MCQmedium

You are a security engineer at a company that uses Microsoft Sentinel. You need to create an automation rule that assigns a specific owner to incidents generated from a particular analytics rule and adds a comment. The automation rule must run when an incident is created. What should you use to define the condition?

A.A playbook that uses the incident creation trigger and a condition action.
B.A workbook that monitors incident metrics and triggers an alert.
C.A Microsoft Sentinel automation rule with a condition based on the analytics rule name.
D.A Microsoft Sentinel analytics rule with incident grouping enabled.
AnswerC

Automation rules in Microsoft Sentinel can trigger on incident creation and evaluate conditions such as the analytics rule name, severity, or tags. They can then assign an owner and add a comment. This directly meets the requirement to assign a specific owner and add a comment when an incident is created from a particular analytics rule.

Why this answer

Microsoft Sentinel automation rules are designed to automate incident handling. They can trigger on incident creation and evaluate conditions such as the analytics rule name. When the condition matches, the rule can assign an owner and add a comment.

Playbooks are for more complex orchestration and are invoked by automation rules, but the condition and simple actions are defined in the automation rule itself.

Exam trap

The trap here is confusing automation rules with playbooks; automation rules define conditions and basic actions, while playbooks are for complex workflows triggered by automation rules.

215
Multi-Selectmedium

Your organization uses Microsoft Sentinel to monitor security events. You need to configure automated response actions for incidents. Which TWO of the following can be used to trigger automated responses in Microsoft Sentinel?

Select 2 answers
A.Workbooks
B.Watchlists
C.Hunting queries
D.Automation rules
E.Playbooks (Azure Logic Apps)
AnswersD, E

Automation rules run independently of playbooks and can trigger responses directly when an incident is created, satisfying the requirement for automated response actions. They support conditions on analytics rules, severity, and entity mappings, and can execute playbooks, assign owners, or change status without manual intervention.

Why this answer

Automation rules in Microsoft Sentinel allow you to define automated responses that trigger when an incident is created or updated, based on conditions like severity or specific analytics rules. They can run playbooks (Azure Logic Apps) to execute complex workflows, such as sending notifications or creating tickets, without manual intervention.

Exam trap

The trap here is that candidates often confuse Workbooks or Hunting queries as automation triggers because they are interactive tools, but they lack the event-driven trigger capability that Automation rules and Playbooks provide.

216
MCQmedium

A company uses Microsoft Defender for Cloud to manage its security posture. The compliance team wants to monitor the subscription's compliance with the Payment Card Industry Data Security Standard (PCI DSS). They need to view a detailed compliance report and track progress over time. What should they do in Defender for Cloud?

A.Enable the relevant Defender for Cloud plans (e.g., Defender for Servers, Defender for SQL).
B.Add the PCI DSS standard from the regulatory compliance dashboard.
C.Create a custom regulatory compliance initiative based on PCI DSS controls.
D.Configure continuous export to send compliance data to a Log Analytics workspace.
AnswerB

Adding the PCI DSS standard from the regulatory compliance dashboard is the correct action because Defender for Cloud includes a built-in regulatory compliance initiative pre-mapped to PCI DSS controls. This initiative automatically runs assessments against your environment and presents the results in a dedicated compliance view, allowing you to track progress against each control requirement. This is the straightforward, intended method to start monitoring PCI DSS compliance.

Why this answer

The regulatory compliance dashboard in Microsoft Defender for Cloud allows you to add built-in compliance standards like PCI DSS. Once added, the dashboard automatically assesses your subscription against the standard's controls, provides a detailed compliance report, and tracks progress over time with a compliance score and historical trend. This is the direct method to monitor PCI DSS compliance without needing to enable specific Defender plans or create custom initiatives.

Exam trap

The trap here is that candidates often confuse enabling Defender plans (which provide threat detection) with adding a compliance standard (which provides a compliance assessment), leading them to select Option A instead of the correct dashboard action in Option B.

How to eliminate wrong answers

Option A is wrong because enabling Defender for Cloud plans (e.g., Defender for Servers, Defender for SQL) provides security alerts and advanced threat protection but does not by itself add or display a PCI DSS compliance report; the regulatory compliance dashboard must be explicitly configured with the standard. Option C is wrong because creating a custom regulatory compliance initiative based on PCI DSS controls is unnecessary and more complex; Microsoft provides a built-in PCI DSS initiative that is automatically updated and maintained, and custom initiatives are typically used for organization-specific controls, not for adopting a standard already available in the dashboard. Option D is wrong because configuring continuous export to a Log Analytics workspace sends raw security data (e.g., alerts, recommendations) for external analysis or retention, but it does not generate or display the PCI DSS compliance report or track progress within Defender for Cloud's dashboard.

217
MCQeasy

A security analyst needs to query Microsoft Sentinel logs to find all sign-in events from a specific IP address in the last 24 hours. Which query language should the analyst use?

A.GraphQL
B.Transact-SQL (T-SQL)
C.PowerShell
D.Kusto Query Language (KQL)
AnswerD

Microsoft Sentinel uses Kusto Query Language (KQL) for log queries and analytics. KQL is designed for querying large datasets in Azure Monitor and Log Analytics, and it supports filtering, aggregation, and time-based queries. The analyst can use KQL to search sign-in logs, such as SigninLogs, and filter by IP address and time range.

Why this answer

Microsoft Sentinel is built on Azure Monitor Log Analytics, which uses Kusto Query Language (KQL) for all log queries. KQL is optimized for fast filtering, sorting, and aggregation of large datasets. The analyst can write a KQL query against the SigninLogs table to find events from a specific IP within the last 24 hours, making it the correct choice.

Exam trap

The trap here is confusing query languages used in other Microsoft services, such as T-SQL for databases or GraphQL for APIs, with the native language for Sentinel.

218
MCQhard

Your organization uses Microsoft Entra ID and requires that all accesses to sensitive applications be approved by the application owner. You need to implement a solution where users can request access to these applications, and the request is automatically routed to the owner for approval. What should you configure?

A.Microsoft Entra roles and administrative units
B.Entitlement management access packages
C.Privileged Identity Management for groups
D.Cross-tenant access settings
AnswerB

Entitlement management access packages are the correct identity governance solution because they bundle resources such as applications, groups, and SharePoint sites into packages that users can request. Access package policies can require specified custom approvers, define approval stages, set access durations, and trigger recurring access reviews. This directly satisfies the requirement for user-driven application access requests with custom approvals.

Why this answer

Entitlement management access packages in Microsoft Entra ID are the correct choice because they let you bundle resources such as sensitive applications into an access package with an approval policy, so users request access through the My Access portal and the request is automatically routed to the designated approver (the application owner) before access is granted. This directly satisfies the requirement for owner-approved, request-based access to applications. Option A (Entra roles and administrative units) governs role assignments and scoping, not user access-request approval workflows for applications.

Option C (Privileged Identity Management for groups) handles just-in-time activation of privileged group membership, not application access requests with owner approval. Option D (cross-tenant access settings) controls collaboration and trust with external Entra tenants, which is unrelated to internal application access approvals.

219
MCQeasy

Your organization needs to securely connect an on-premises data center to Azure for disaster recovery. The connection must be encrypted and use the public internet. Which Azure service should you use?

A.Azure Front Door.
B.Azure ExpressRoute with private peering.
C.Azure VPN Gateway.
D.Azure DNS.
AnswerC

Azure VPN Gateway is correct because it implements a site-to-site IPsec/IKE VPN tunnel over the public internet between an on-premises VPN device and an Azure virtual network gateway. The tunnel encrypts traffic using industry-standard protocols such as IKEv2 and ESP, and the gateway supports active-active configurations and BGP for dynamic routing. This is the Azure service explicitly designed for secure internet-based hybrid connectivity.

Why this answer

Azure VPN Gateway is the correct choice because it provides encrypted site-to-site IPsec/IKE VPN tunnels over the public internet, enabling secure connectivity between an on-premises data center and Azure for disaster recovery. This meets the requirement for encryption and use of the public internet, as VPN Gateway leverages standard protocols like IKEv2 and IPsec to protect data in transit.

Exam trap

The trap here is that candidates often confuse Azure ExpressRoute with VPN Gateway, assuming ExpressRoute can be used over the public internet, but ExpressRoute always uses a private, dedicated connection that does not traverse the internet, making it unsuitable when the requirement explicitly states 'use the public internet'.

How to eliminate wrong answers

Option A is wrong because Azure Front Door is a global load balancer and application delivery controller that operates at Layer 7 (HTTP/HTTPS), not a site-to-site VPN solution; it does not provide encrypted tunnels between on-premises networks and Azure over the public internet. Option B is wrong because Azure ExpressRoute with private peering provides a private, dedicated connection that bypasses the public internet entirely, which contradicts the requirement to use the public internet. Option D is wrong because Azure DNS is a domain name resolution service that translates domain names to IP addresses and has no capability to create encrypted network connections between on-premises and Azure.

220
MCQeasy

A company deploys Azure Firewall to inspect and control outbound traffic from a virtual network. The security team wants to allow outbound HTTPS traffic only to specific FQDNs such as *.microsoft.com and *.windowsupdate.com, while blocking all other outbound internet access. Which type of rule should they configure in Azure Firewall to achieve this filtering?

A.Network Rule
B.Application Rule
C.NAT Rule
D.DNAT Rule
AnswerB

Application rules in Azure Firewall are purpose-built for outbound and east-west traffic filtering based on FQDNs, supporting wildcard patterns such as *.microsoft.com to match any subdomain. They work by inspecting the Host header of HTTP sessions or the SNI/TLS extension of encrypted connections, and with DNS proxy enabled they resolve FQDNs to current IPs before forwarding. This allows the firewall to enforce a precise allowlist of target domains, making it the correct rule type for this requirement.

Why this answer

Azure Firewall uses Application Rules to filter outbound traffic based on fully qualified domain names (FQDNs) for HTTP/HTTPS protocols. Since the requirement is to allow HTTPS traffic to specific FQDNs like *.microsoft.com and *.windowsupdate.com, an Application Rule is the correct choice because it can inspect the TLS Server Name Indication (SNI) extension to match the target FQDN, enabling granular allow/deny decisions for web traffic.

Exam trap

The trap here is that candidates often confuse Network Rules with Application Rules, mistakenly thinking that port 443 and IP addresses can achieve FQDN-based filtering, but Network Rules lack the ability to inspect the application layer (FQDN) and can only filter by IP/port, which is insufficient for domain-specific allowlisting.

How to eliminate wrong answers

Option A is wrong because Network Rules filter traffic based on source/destination IP addresses, ports, and protocols (TCP/UDP), not FQDNs, so they cannot selectively allow HTTPS to specific domain names. Option C is wrong because NAT Rules (Destination Network Address Translation) are used to translate inbound traffic to internal resources, not to filter outbound traffic. Option D is wrong because DNAT Rules are synonymous with NAT Rules in Azure Firewall and serve the same inbound translation purpose, not outbound FQDN filtering.

221
MCQhard

Refer to the exhibit. You assign this policy to a subscription that already has a security contact configured with email 'admin@contoso.com'. What will be the outcome?

A.The policy will not modify the existing security contact because it already exists.
B.The policy will fail because the security contact already exists.
C.The subscription will become non-compliant because the email does not match.
D.The policy will overwrite the existing security contact with the one in the policy.
AnswerA

The deployIfNotExists effect first evaluates the existence condition—here, checking whether a security contact with a non-empty email already exists. Because that condition is true, the policy skips the deployment template entirely, leaving the existing security contact unchanged. As a result, the policy is compliant and no modification occurs to the already-provisioned contact.

Why this answer

The Azure Policy definition shown uses the 'DeployIfNotExists' effect, which only deploys a resource (in this case, a security contact) if it does not already exist. Since the subscription already has a security contact configured with email 'admin@contoso.com', the policy will detect its presence and skip the deployment, leaving the existing contact unchanged. This behavior is by design to avoid overwriting existing configurations that may have been set manually or by other processes.

Exam trap

The trap here is that candidates often assume Azure Policy will enforce a specific configuration value (like the email address) and overwrite any existing setting, but 'DeployIfNotExists' only cares about the existence of the resource, not its properties, unless the policy rule explicitly includes a property match condition.

How to eliminate wrong answers

Option B is wrong because 'DeployIfNotExists' does not fail when the resource already exists; it simply evaluates to 'compliant' and takes no action. Option C is wrong because the policy does not enforce compliance based on email matching; it only checks for the existence of the security contact resource, and if it exists, the subscription is considered compliant regardless of the email value. Option D is wrong because 'DeployIfNotExists' is specifically designed to deploy only when the resource is absent; it will never overwrite an existing resource, as that would require a 'Modify' or 'Deploy' effect with a different evaluation logic.

222
MCQhard

An organization uses Microsoft Defender for Cloud. They want to implement just-in-time (JIT) VM access for a set of production VMs. However, the security team needs to ensure that JIT access requests are always approved by a manager before opening ports. Which configuration should they use?

A.Enable JIT in Defender for Cloud and configure a logic app to send approval emails
B.Use Azure AD Privileged Identity Management (PIM) for JIT activation
C.Enable JIT and configure a custom workflow automation with an approval step
D.Use Conditional Access with session controls
AnswerC

The correct approach is to enable Defender for Cloud's JIT VM access and then create a custom workflow automation rule that triggers an Azure Logic App containing an approval step. The Logic App can use an approval connector (e.g., Send approval request through email or Teams) to pause the workflow until a manager or security officer approve or rejects the request. Only after approval does the Logic App signal Defender for Cloud to apply the JIT policy and open the requested ports, thereby enforcing a true approval gate before network access is granted.

Why this answer

Microsoft Defender for Cloud's JIT VM access can be integrated with a custom workflow automation that includes an approval step. This allows the security team to enforce manager approval before ports are opened, meeting the requirement for a formal approval process. The workflow automation can trigger an Azure Logic App or other action that requires a designated approver to authorize the request.

Exam trap

The trap here is confusing Azure AD PIM (which manages role activation) with JIT VM access (which manages network port openings), leading candidates to incorrectly select PIM for VM-level access control.

How to eliminate wrong answers

Option A is wrong because while a logic app can send approval emails, it does not enforce a mandatory approval step before JIT access is granted; the JIT request would still be automatically approved unless the logic app is configured to block it, which is not a native capability. Option B is wrong because Azure AD PIM is designed for managing and approving privileged role activations, not for controlling JIT VM access requests to specific ports on VMs. Option D is wrong because Conditional Access with session controls governs access to applications and data based on conditions like location or device compliance, not for approving JIT port openings on VMs.

223
MCQhard

You are a security engineer for Adventure Works. The company has an Azure subscription with a virtual network named VNet1 that contains a subnet named Subnet1. Subnet1 hosts an Azure App Service Environment (ASE) and several Azure virtual machines. You need to inspect all traffic between Subnet1 and the internet for malicious content and generate alerts for suspicious activity. You also need to ensure that the solution can decrypt and inspect HTTPS traffic. What should you do?

A.Configure Azure Application Gateway with Web Application Firewall (WAF) in VNet1. Create a user-defined route to direct traffic from Subnet1 to the Application Gateway.
B.Configure Azure Firewall in VNet1. Create application rules to allow outbound traffic and enable threat intelligence in alert mode. Configure the VMs and ASE to use Azure Firewall as the default gateway.
C.Deploy a network virtual appliance (NVA) from Azure Marketplace that supports TLS inspection. Configure a user-defined route to direct traffic from Subnet1 to the NVA.
D.Deploy Azure Firewall Premium in VNet1. Enable TLS inspection and configure the firewall to use a certificate stored in Azure Key Vault. Create a user-defined route to direct traffic from Subnet1 to the firewall's private IP address.
AnswerD

Azure Firewall Premium supports TLS inspection, which allows it to decrypt, inspect, and re-encrypt HTTPS traffic. It requires a certificate stored in Azure Key Vault. To ensure all traffic from Subnet1 is inspected, you must create a user-defined route that directs traffic to the firewall's private IP address as the next hop. This solution meets the requirements for deep inspection and alerting on suspicious activity.

Why this answer

To inspect all traffic between Subnet1 and the internet, including HTTPS, deploy Azure Firewall Premium and enable TLS inspection. This allows the firewall to decrypt and inspect encrypted traffic. You must also configure a user-defined route to force traffic from Subnet1 through the firewall's private IP address.

This ensures all outbound traffic is inspected and alerts can be generated for suspicious activity.

Exam trap

The trap here is assuming that Azure Firewall Standard or threat intelligence alone can decrypt HTTPS traffic; TLS inspection is a Premium feature that requires a certificate and explicit configuration.

224
MCQmedium

A company uses Azure AD Conditional Access. They want to require multi-factor authentication (MFA) for all users accessing the Azure portal, but only when the sign-in risk level is medium or above. Which configuration should they use in the Conditional Access policy?

A.Assignments > Cloud apps > Include > Microsoft Azure Management, Conditions > Sign-in risk > Medium and above, Grant > Require MFA.
B.Assignments > Users > All users, Cloud apps > All cloud apps, Conditions > User risk > Medium, Grant > Require MFA.
C.Assignments > Conditions > Locations > All trusted locations, Grant > Require MFA.
D.Assignments > Cloud apps > Include > All cloud apps, Conditions > Device platforms > iOS, Grant > Require MFA.
AnswerA

This is correct because the Microsoft Azure Management cloud app encompasses the Azure portal, Azure Resource Manager, CLI, and PowerShell, so the policy applies to administrative control-plane sign-ins. Adding the Sign-in risk condition at 'Medium and above' causes Azure AD Identity Protection to evaluate the current authentication attempt for real-time risk, and the Grant control forces MFA when that risk threshold is met. This narrowly targets Azure management rather than all cloud apps, which is exactly what the company needs.

Why this answer

It specifically targets the Azure portal via 'Microsoft Azure Management' in Cloud apps, sets the sign-in risk condition to 'Medium and above', and requires MFA. This matches the requirement exactly: MFA is triggered only when accessing the Azure portal and the sign-in risk level is medium or higher.

Exam trap

The trap here is confusing 'User risk' with 'Sign-in risk' — user risk is a persistent score based on past user behavior, while sign-in risk is a session-level assessment, and the question explicitly requires the latter for the current sign-in event.

How to eliminate wrong answers

Option B is wrong because it uses 'User risk' instead of 'Sign-in risk' — user risk is based on historical user behavior, not the current sign-in session, and it applies to all cloud apps, not just the Azure portal. Option C is wrong because it uses 'Locations' with 'All trusted locations', which would require MFA from trusted locations regardless of risk, and does not target the Azure portal or sign-in risk. Option D is wrong because it targets 'All cloud apps' and 'Device platforms > iOS', which would require MFA for all iOS devices accessing any cloud app, not specifically the Azure portal based on sign-in risk.

225
Drag & Dropmedium

Drag and drop the steps to create an Azure Key Vault firewall rule to allow access from a specific virtual network into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The firewall configuration is under networking, and you must add the virtual network to allow traffic.

Page 2

Page 3 of 9

Page 4

All pages