Courseiva

Microsoft Azure Security Engineer Associate AZ-500 (AZ-500) — Questions 226–300

617 questions total · 9pages · All types, answers revealed

Page 3

Page 4 of 9

Page 5
226
Multi-Selecthard

Which two security configurations should you apply to an Azure SQL Database to meet a requirement for data protection at rest and in transit?

Select 2 answers
A.Enable Microsoft Defender for Azure SQL.
B.Use Always Encrypted for sensitive columns.
C.Enable Transparent Data Encryption (TDE).
D.Configure firewall rules to allow only trusted IP addresses.
E.Enable Azure SQL Auditing.
AnswersB, C

Use Always Encrypted for sensitive columns: Correct. It encrypts sensitive data both at rest and in transit by keeping encryption keys on the client side.

Why this answer

Option B (Always Encrypted for sensitive columns) is correct because Always Encrypted protects sensitive data both at rest and in transit by keeping data encrypted on the client side, so the database engine never sees plaintext — the column encryption keys are never exposed to Azure SQL Database. Option C (Transparent Data Encryption, TDE) is correct because TDE performs real-time encryption and decryption of the database, backups, and transaction log files at rest using a symmetric database encryption key protected by a certificate stored in Azure Key Vault or the service-managed key store, satisfying the data-at-rest requirement. Option A (Microsoft Defender for Azure SQL) is not correct here because it is a threat detection and vulnerability assessment service, not a data encryption mechanism for protecting data at rest or in transit.

Option D (firewall rules to allow only trusted IP addresses) is not correct because it is network access control, not encryption of data at rest or in transit. Option E (Azure SQL Auditing) is not correct because auditing tracks and logs database events for compliance and forensic purposes, but it does not encrypt or protect the data itself.

Exam trap

The trap here is that candidates often confuse Transparent Data Encryption (TDE) with protecting data in transit, but TDE only encrypts data at rest (the database files and backups), not data moving between the client and server.

227
MCQhard

A company uses Azure SQL Database with Transparent Data Encryption (TDE) and a customer-managed key (CMK) stored in Azure Key Vault. The Key Vault has a firewall that blocks all public access. The SQL server is a managed service that needs to access the key to perform TDE operations. The Key Vault is in the same Azure region as the SQL server. Which additional configuration is needed?

A.Enable 'Allow trusted Microsoft services to bypass this firewall' in the Key Vault firewall settings
B.Configure a service endpoint for Microsoft.KeyVault on the SQL server's subnet
C.Assign the SQL server's server identity the 'Contributor' role on the Key Vault
D.Create a private endpoint for the Key Vault in the SQL server's virtual network
AnswerA

The Key Vault firewall blocks all data plane access by default, which would break TDE key operations. Enabling 'Allow trusted Microsoft services to bypass this firewall' explicitly authorizes Azure SQL Database (as a trusted Microsoft service) to reach the vault for wrap/unwrap operations, provided the SQL server's managed identity is also granted the correct RBAC role or access policy. This is the standard configuration when using customer-managed keys for TDE on Azure SQL Database while the vault firewall is turned on.

Why this answer

When Azure Key Vault has a firewall that blocks all public access, Azure services like SQL Database that need to access the key for TDE operations must be explicitly allowed. Enabling 'Allow trusted Microsoft services to bypass this firewall' permits the SQL server's managed service identity to authenticate and retrieve the CMK from Key Vault, even when public network access is denied. This setting is required because the SQL server, as a platform-as-a-service (PaaS) resource, does not reside in a virtual network by default and cannot use a private endpoint or service endpoint without additional networking configuration.

Exam trap

The trap here is that candidates often assume a private endpoint or service endpoint is always required for secure access, but for PaaS services like Azure SQL Database that use managed identities, the 'Allow trusted Microsoft services' setting is the simplest and correct solution when the Key Vault firewall blocks public access.

How to eliminate wrong answers

Option B is wrong because configuring a service endpoint for Microsoft.KeyVault on the SQL server's subnet is not applicable—Azure SQL Database is a PaaS service that does not have a subnet in a virtual network by default; service endpoints are used for VNet-integrated resources like VMs or App Service, not for SQL Database's managed identity access to Key Vault. Option C is wrong because assigning the 'Contributor' role on the Key Vault grants excessive permissions (e.g., ability to modify keys) and is not required; the SQL server's identity only needs the 'Get' and 'Unwrap Key' permissions on the key itself, which are granted via a Key Vault access policy, not RBAC roles. Option D is wrong because creating a private endpoint for Key Vault in the SQL server's virtual network would require the SQL server to be integrated into a VNet, which is not the default configuration for Azure SQL Database; private endpoints are used for network isolation but do not solve the firewall bypass issue for a managed service that needs to reach Key Vault over the public endpoint.

228
MCQmedium

You are the Azure Security Engineer for a company that uses Microsoft Entra ID (formerly Azure AD). The security team wants to ensure that when a user signs in from an unknown location, they are required to perform multi-factor authentication (MFA). However, users signing in from the corporate office should not be prompted for MFA. You create a Conditional Access policy with a condition for trusted locations. What should you configure to ensure the policy works as intended?

A.Enable security defaults in Microsoft Entra ID to automatically require MFA for all users except those with privileged roles.
B.Create a conditional access policy that requires MFA for all users and then exclude users who are in the corporate office by using a dynamic group.
C.Configure a sign-in risk policy in Microsoft Entra ID Protection to block sign-ins from unknown locations.
D.Add the corporate office public IP addresses as named locations and mark them as trusted.
AnswerD

Named locations allow you to define IP ranges that are considered trusted. By marking them as trusted, you can exclude them from the Conditional Access policy's MFA requirement. This is the correct approach because Conditional Access conditions can include location, and trusted named locations are specifically designed for this scenario. It ensures users from the corporate office are not prompted for MFA while others are.

Why this answer

The correct approach is to define named locations for the corporate office IP ranges and mark them as trusted. Conditional Access policies can then include or exclude these locations. This allows the policy to require MFA for unknown locations while exempting the trusted corporate office.

Other options do not provide the necessary location-based control or are not granular enough.

Exam trap

The trap here is confusing location-based conditions with risk-based policies or group membership, which do not evaluate real-time network location.

229
MCQeasy

You are configuring Microsoft Defender for Cloud for an Azure subscription. You want to receive email notifications when a high-severity alert is generated. What should you configure?

A.Azure Monitor action groups with an email action.
B.The Email notifications settings in Microsoft Defender for Cloud.
C.A Microsoft Sentinel analytics rule with an email playbook.
D.A Log Analytics workspace with a scheduled query alert.
AnswerB

Microsoft Defender for Cloud provides a dedicated email notifications configuration where you can specify email addresses and choose which severity levels trigger notifications. This is the direct and intended way to receive email alerts for high-severity findings. It also allows notifying subscription owners and security contacts. This meets the requirement without additional services.

Why this answer

Microsoft Defender for Cloud includes a built-in email notification feature that allows you to specify recipients and severity levels for alerts. This is the simplest and most direct method to receive email notifications for high-severity alerts. It does not require additional services like Azure Monitor, Microsoft Sentinel, or Log Analytics, and it is designed specifically for this purpose.

Exam trap

The trap here is overcomplicating the solution by involving other services when Defender for Cloud has a native email notification setting.

230
MCQeasy

You run the PowerShell cmdlet shown in the exhibit for an Azure SQL Database. What is the security implication?

A.Auditing of database queries is not configured.
B.The database is not protected against anomalous activities.
C.The database firewall allows all public IP addresses.
D.Transparent data encryption is not enabled.
AnswerB

The PowerShell cmdlet output indicates that Advanced Threat Protection is disabled on the Azure SQL Database. With ATP disabled, the service does not analyze database activity for anomalies such as SQL injection attempts, unusual access patterns, or brute-force attacks, leaving the database without this specific protective layer. This is the direct and accurate interpretation of the cmdlet result, as ATP is exactly the feature that protects against anomalous activities.

Why this answer

The cmdlet shown is `Set-AzSqlDatabaseVulnerabilityAssessmentSettings`, which enables Vulnerability Assessment (VA) but does not enable Advanced Threat Protection (ATP). Without ATP, the database lacks anomaly detection capabilities such as SQL injection detection, brute-force attack alerts, and unusual access pattern monitoring. Therefore, the database is not protected against anomalous activities, making option B correct.

Exam trap

The trap here is that candidates confuse Vulnerability Assessment (which scans for misconfigurations and missing patches) with Advanced Threat Protection (which detects ongoing anomalous activities), leading them to overlook the specific security gap of missing anomaly detection.

How to eliminate wrong answers

Option A is wrong because auditing is configured separately via `Set-AzSqlDatabaseAuditing` or the Azure portal; the cmdlet shown does not affect auditing settings. Option C is wrong because firewall rules are managed via `Set-AzSqlServerFirewallRule` or the portal, and the cmdlet does not modify IP allow lists. Option D is wrong because Transparent Data Encryption (TDE) is enabled by default for new Azure SQL Databases and is managed via `Set-AzSqlDatabaseTransparentDataEncryption`; the cmdlet shown does not disable TDE.

231
Multi-Selecthard

You are designing a security baseline for Microsoft Entra ID. Which THREE settings are recommended by Microsoft as part of the identity security baseline?

Select 3 answers
A.Enable risk-based Conditional Access policies
B.Allow self-service group management for all users
C.Set sign-in session timeout to 8 hours
D.Enable MFA for all Global Administrators
E.Block legacy authentication protocols
AnswersA, D, E

Risk-based Conditional Access policies are a core component of a security baseline because they dynamically evaluate sign-in risk and user risk in real time, enabling automatic remediation actions such as requiring MFA, blocking access, or forcing password change for compromised identities. Unlike static policies, these adapt to evolving threat signals like anonymous IP addresses, impossible travel, or atypical sign-ins, thereby reducing the attack surface without permanently disrupting legitimate users. In a baseline, this should be configured with risk thresholds (e.g., medium or higher for user risk) and paired with registration campaigns for combined security information.

Why this answer

Risk-based Conditional Access policies are a core recommendation in the Microsoft identity security baseline. These policies automatically respond to detected user or sign-in risks (e.g., anonymous IP, leaked credentials) by requiring MFA or blocking access, aligning with the Zero Trust principle of continuous verification. Microsoft explicitly includes risk-based policies in its security baseline to proactively mitigate identity threats.

Exam trap

The trap here is that candidates often confuse Microsoft's general best practices (like self-service group management) with the specific, hardened settings in the identity security baseline, which prioritizes risk-based controls and blocking legacy protocols over convenience features.

232
MCQhard

You are deploying a critical application on Azure Virtual Machines that must remain highly available. You need to implement a security solution that ensures the application can recover from a ransomware attack that encrypts all data disks. What is the most cost-effective approach?

A.Configure Azure Backup with immutable vault and soft delete.
B.Use Azure Files share with snapshots for the application data.
C.Enable Azure Site Recovery for the virtual machines.
D.Take daily snapshots of the disks and store them in the same storage account.
AnswerA

Azure Backup's immutable vault (now generally available as immutable vault for Azure Backup) enforces a Write-Once, Read-Many (WORM) policy on recovery points, preventing ransomware from encrypting or deleting backups even with compromised administrator credentials. Soft delete adds a configurable retention window during which deleted backup data is retained and recoverable, giving defenders a second chance to restore from an attack. This layered approach directly addresses the backup integrity and recoverability requirements for a critical application, making it the correct choice.

Why this answer

Azure Backup with an immutable vault and soft delete (option A) is the most cost-effective solution because it provides ransomware-resistant, tamper-proof recovery points for the VM data disks at a lower cost than full VM replication, and immutability plus soft delete prevents attackers from deleting or altering backups during an attack. Azure Site Recovery (option C) is designed for disaster recovery and VM replication, which is more expensive and not specifically aimed at protecting backup data from ransomware. Azure Files snapshots (option B) only apply to Azure Files shares, not VM data disks, so they cannot protect the application's disk data.

Daily disk snapshots stored in the same storage account (option D) are not immutable and can be deleted or encrypted along with the source data, making them a weak ransomware defense.

233
MCQmedium

Refer to the exhibit. You are configuring an Entitlement Management access package. The policy allows any existing user to request access without approval, and access expires after 30 days. However, security requirements dictate that all access to Finance applications must be reviewed by the finance team manager every quarter. What should you add to the policy?

A.Add a connected organization for external users
B.Set 'isApprovalRequiredForAdd' to true
C.Set 'durationInDays' to 90
D.Enable access reviews and assign the finance team manager as reviewer
AnswerD

Enabling access reviews in entitlement management configures recurring attestation cycles—in this case quarterly—where access packages are periodically recertified. Assigning the finance team manager as the reviewer gives a business owner the responsibility to approve, deny, or remove access at each cycle. This exactly satisfies the compliance requirement for a periodic review.

Why this answer

The security requirement mandates quarterly reviews by the finance team manager, which is exactly what an access review does in Entitlement Management. Access reviews allow you to require periodic attestation of access by a designated reviewer, ensuring ongoing compliance even though the initial request does not require approval. The policy already sets a 30-day expiration, but a quarterly review adds a separate recurring governance check that overrides the shorter duration for compliance purposes.

Exam trap

The trap here is that candidates confuse 'approval at request time' with 'periodic review after access is granted' — the question explicitly says no approval is needed for the initial request, so adding approval (Option B) is incorrect, but the quarterly review (Option D) is a separate governance control that satisfies the security requirement without changing the request flow.

How to eliminate wrong answers

Option A is wrong because a connected organization is used to allow external users from a specific partner or tenant to request access; the scenario specifies 'any existing user' (internal users), so external user configuration is irrelevant. Option B is wrong because setting 'isApprovalRequiredForAdd' to true would require approval at the time of request, but the question explicitly states the policy allows access without approval; adding approval would contradict the requirement. Option C is wrong because setting 'durationInDays' to 90 would extend the access expiration to 90 days, but the requirement is to keep the 30-day expiration and add a quarterly review; changing the duration does not enforce periodic review by the finance team manager.

234
MCQmedium

You are a security engineer at Adatum. The company has an Azure subscription with a virtual network named VNet1 that contains an Azure Firewall in a subnet named AzureFirewallSubnet. You need to ensure that all outbound traffic from a subnet named AppSubnet is inspected by the firewall, including traffic to other subnets in VNet1 and to the internet. What should you configure?

A.Create a user-defined route (UDR) on AppSubnet with a default route (0.0.0.0/0) that has a next hop type of Virtual appliance and points to the private IP address of the Azure Firewall.
B.Enable Azure Firewall forced tunneling by configuring a UDR with a next hop type of Virtual network gateway on AppSubnet.
C.Associate a network security group (NSG) with AppSubnet that denies all outbound traffic except to the firewall's private IP address.
D.Configure Azure Firewall to use DNS proxy and set the DNS servers on AppSubnet to the firewall's private IP address.
AnswerA

Azure Firewall inspects traffic only if it is routed through the firewall. A UDR on AppSubnet with a default route pointing to the firewall's private IP as a virtual appliance ensures all outbound traffic, including intra-VNet and internet-bound, is sent to the firewall for inspection.

Why this answer

Azure Firewall inspects traffic only when it is in the data path. A user-defined route on AppSubnet with a default route using next hop Virtual appliance and the firewall's private IP ensures all outbound traffic, including to other subnets and the internet, is sent to the firewall. Without this UDR, traffic would bypass the firewall.

Exam trap

The trap here is assuming that associating a network security group or enabling DNS proxy will automatically route traffic through Azure Firewall, when only a user-defined route can change the next hop.

235
MCQmedium

You have an Azure Web Application Firewall (WAF) policy associated with an Azure Front Door instance. You want to block requests from a specific country (e.g., Country X) unless the request includes a valid API key. How should you configure this?

A.Use a geo-match custom rule to allow all countries except Country X, and use a rate limit rule to block Country X.
B.Configure IP restriction on the origin to block Country X IPs.
C.Configure the WAF policy to use 'Prevention' mode and add a managed rule set that includes the country block.
D.Use a geo-match custom rule to block Country X, and create a separate custom rule with higher priority to allow traffic from Country X if the request contains the API key header.
AnswerD

This approach works because Azure WAF evaluates custom rules in strict priority order, with lower numeric priority values evaluated first. Create an allow custom rule with a higher priority (for example, priority 1) that matches requests from Country X only when the required API key header is present and sets the action to Allow; then create a lower-priority block rule (for example, priority 2) with a geo-match condition for Country X. When a request from Country X contains the API key, the allow rule matches first and stops further evaluation, bypassing the block rule. Requests from Country X without the API key do not match the allow rule, fall through to the block rule, and are denied.

Why this answer

Azure WAF custom rules are evaluated in priority order, and a higher-priority 'allow' rule can override a lower-priority 'block' rule. By creating a geo-match rule to block Country X, and then a separate custom rule with a higher priority (lower numeric value) that allows requests from Country X if they contain a valid API key header, you achieve the conditional access requirement. This leverages WAF's ability to inspect request headers and apply logic based on multiple conditions within a single policy.

Exam trap

The trap here is that candidates often think geo-blocking must be done with a single rule or that managed rule sets can handle geography, but Azure WAF requires custom rules for geo-filtering and relies on rule priority to implement conditional overrides.

How to eliminate wrong answers

Option A is wrong because a geo-match custom rule to allow all countries except Country X would still allow Country X traffic (since it's not explicitly blocked), and a rate limit rule limits request frequency, not blocks based on geography or API key presence. Option B is wrong because IP restrictions on the origin are applied after the WAF, cannot inspect API keys, and would block all traffic from Country X IPs regardless of API key, which does not meet the conditional requirement. Option C is wrong because managed rule sets do not include a 'country block' capability; geo-filtering is only available through custom rules, and 'Prevention' mode simply enables action on matched rules, it does not add geo-blocking logic.

236
MCQmedium

You are the identity security engineer for a company that uses Microsoft Entra ID. A new security policy requires that any user who is assigned the Global Administrator role must use a phishing-resistant authentication method when signing in. You need to enforce this requirement with the least administrative effort. What should you do?

A.Configure a per-user MFA setting for each Global Administrator and disable SMS and voice call methods.
B.Enable security defaults for the tenant and require all users to register for Microsoft Authenticator.
C.Assign a Microsoft Entra ID P1 license to each Global Administrator and enable self-service password reset with number matching.
D.Create a Conditional Access policy that targets the Global Administrator directory role and requires an authentication strength of Phishing-resistant MFA.
AnswerD

Conditional Access can target directory roles, and authentication strengths let you require specific method combinations such as phishing-resistant MFA. This directly enforces the policy for Global Administrators without changing per-user settings or relying on legacy per-user MFA, which cannot distinguish phishing-resistant methods.

Why this answer

A Conditional Access policy scoped to directory roles and combined with an authentication strength requirement is the supported way to mandate phishing-resistant MFA for privileged users. Authentication strengths map to method combinations such as FIDO2 security keys and certificate-based authentication, giving you granular, role-based enforcement.

Exam trap

The trap here is assuming that enabling security defaults or per-user MFA can enforce phishing-resistant authentication for a specific privileged role.

237
Multi-Selecthard

You are configuring Microsoft Entra Privileged Identity Management (PIM) for a group of users who need to activate the Security Administrator role. The role should only be activated after approval by a designated approver, and the activation should be limited to a maximum of 4 hours. Which two settings must you configure in the role's PIM settings? (Choose two.)

Select 2 answers
A.Require approval to activate.
B.Require conditional access authentication context.
C.Require multi-factor authentication on activation.
D.Require justification on activation.
E.Set the maximum activation duration to 4 hours.
AnswersA, E

The 'Require approval to activate' setting enforces that a designated approver must approve the activation request before the role becomes active. This matches the requirement that activation should only occur after approval by a designated approver. Without this setting, users could activate the role without any oversight, violating the scenario's conditions.

Why this answer

To enforce approval and a maximum activation duration, you must enable 'Require approval to activate' and set the 'Maximum activation duration' to 4 hours. These two settings directly address the requirements. Other settings like justification or MFA are optional and do not fulfill the specified conditions.

Proper configuration ensures that privileged access is tightly controlled.

Exam trap

The trap here is assuming that MFA or justification are required when the scenario only specifies approval and a time limit.

238
MCQhard

A company wants to deploy an Azure VPN Gateway in active-active mode to ensure high availability for their site-to-site VPN connection. They have two on-premises VPN devices, each with a distinct public IP address. What is the minimum configuration required for the Azure VPN Gateway to utilize both on-premises devices?

A.Create two local network gateways, each with one on-premises public IP, and connect each to a different IP of the VPN gateway.
B.Create one local network gateway that includes both on-premises IP addresses and enable BGP on the connection.
C.Use active-passive mode and configure a second VPN gateway in the same virtual network.
D.Deploy two separate VPN gateways in different Azure regions.
AnswerA

In active-active mode, the Azure VPN gateway is deployed with two public IP addresses, and the correct configuration requires two separate on-premises VPN devices, each represented by its own local network gateway. By creating a local network gateway for each on-premises public IP and connecting each one to a different gateway IP address via separate connections, you establish two independent IPsec tunnels that operate concurrently. This satisfies high availability because failure of one on-premises device or one Azure gateway instance still leaves a functional tunnel. Without this placement — one local network gateway per on-premises IP — the gateway cannot build active-active tunnels to two distinct on-premises endpoints.

Why this answer

Active-active mode requires two distinct IP addresses on the Azure VPN gateway, and each on-premises VPN device must be represented by its own local network gateway. By creating two local network gateways (one per on-premises public IP) and connecting each to a different Azure VPN gateway IP, you establish two independent IPsec tunnels, achieving high availability. This configuration ensures that if one on-premises device or one Azure instance fails, traffic can still flow through the other tunnel.

Exam trap

The trap here is that candidates often think a single local network gateway can hold multiple on-premises IPs or that BGP alone can handle dual tunnels, but Azure requires a separate local network gateway per on-premises device to establish distinct IPsec SAs in active-active mode.

How to eliminate wrong answers

Option B is wrong because a single local network gateway can only define one on-premises public IP address; including both IPs in one gateway is not supported, and enabling BGP does not solve the need for separate tunnels to each on-premises device. Option C is wrong because active-passive mode uses only one active tunnel at a time, so it cannot utilize both on-premises devices simultaneously; deploying a second VPN gateway in the same VNet is not a valid configuration (only one gateway per VNet is allowed). Option D is wrong because deploying two VPN gateways in different Azure regions creates a multi-region disaster recovery setup, not an active-active site-to-site VPN within a single region, and it does not leverage both on-premises devices for the same connection.

239
MCQmedium

A company stores sensitive customer data in an Azure Storage account. The security policy requires that all data be encrypted at rest using a customer-managed key (CMK) stored in Azure Key Vault. They also need the ability to disable the key in case of a security breach and have the data become inaccessible immediately. Which feature should they enable on the storage account to achieve this?

A.Enable Azure Storage encryption with customer-managed keys (CMK)
B.Use service-managed keys (SSE) with platform-managed keys
C.Enable Azure Disk Encryption on VMs that access the storage account
D.Configure Azure Information Protection for the storage account
AnswerA

Azure Storage always encrypts data at rest with AES-256, but enabling customer-managed keys (CMK) lets you supply your own key in Azure Key Vault or Managed HSM. You control the key lifecycle, rotation, and revocation; if you disable or delete the key, Azure Storage begins rejecting blob operation requests and the data becomes inaccessible. There is a short delay of up to 24 hours before the cached key is evicted, which is why revocation is not instantaneous. This meets the requirement of giving the customer the ability to revoke access on demand, which is the core control needed here.

Why this answer

Enabling Azure Storage encryption with customer-managed keys (CMK) allows the customer to use their own key stored in Azure Key Vault for encrypting the storage account data at rest. The key can be disabled or revoked in Key Vault, which immediately renders the data inaccessible because Azure Storage uses the key to wrap the data encryption key; without access to the CMK, decryption cannot occur.

Exam trap

The trap here is that candidates often confuse Azure Disk Encryption (which encrypts VM disks) with storage account encryption, or assume that platform-managed keys (SSE) provide the same revocation capability as customer-managed keys.

How to eliminate wrong answers

Option B is wrong because service-managed keys (SSE) with platform-managed keys do not allow the customer to control or disable the key; Microsoft manages the keys, so the customer cannot revoke access in a breach scenario. Option C is wrong because Azure Disk Encryption encrypts the OS and data disks of VMs, not the data stored in Azure Storage accounts; it does not provide encryption at rest for the storage account itself. Option D is wrong because Azure Information Protection is a classification and labeling service for documents and emails, not a storage encryption mechanism; it does not encrypt data at rest in Azure Storage accounts.

240
MCQeasy

You need to allow a specific IP address (203.0.113.5) to access an Azure Storage account over the internet. All other internet traffic must be denied. You have enabled the storage account firewall. What should you configure?

A.Create a private endpoint for the storage account.
B.Add the IP address to the firewall rules of the storage account.
C.Configure an NSG on the subnet to allow the IP address.
D.Add a service endpoint for Microsoft.Storage to the subnet.
AnswerB

The storage account firewall supports IP-based network rules, allowing you to explicitly list 203.0.113.5/32 as an allowed client IP. All other public traffic is denied by default, making this the only option that directly addresses access from a specific public IP address. You can add the IP rule either on the storage account's Networking blade or programmatically via the REST API, and existing connections remain unaffected.

Why this answer

The Azure Storage account firewall allows you to configure IP-based access control rules. By adding the specific IP address 203.0.113.5 to the firewall rules, you explicitly permit traffic from that IP while denying all other internet traffic, as the default rule is to deny when the firewall is enabled.

Exam trap

The trap here is confusing network-level controls (NSGs, service endpoints, private endpoints) with the storage account's built-in IP firewall, which is the only mechanism that can whitelist a specific internet IP address when the storage account firewall is enabled.

How to eliminate wrong answers

Option A is wrong because a private endpoint uses a private IP address from your virtual network to access the storage account over Microsoft's backbone network, not over the internet, and it does not allow a specific internet IP address. Option C is wrong because NSGs operate at the subnet or NIC level within a virtual network and cannot control access to an Azure Storage account over the internet; they only filter traffic within the VNet. Option D is wrong because a service endpoint extends your VNet identity to the storage account, allowing traffic from the subnet without a public IP, but it does not provide a mechanism to allow a specific internet IP address; it still relies on the storage account firewall rules for IP-based access.

241
MCQhard

Your company uses Azure SQL Database and wants to protect sensitive data stored in a column named 'CreditCardNumber'. You need to ensure that the data is encrypted at rest and that only authorized users can decrypt the data at the application layer. Additionally, you want to prevent unauthorized administrators from accessing the plaintext. Which solution should you implement?

A.Enable Transparent Data Encryption (TDE) and store the encryption key in Azure Key Vault
B.Use Dynamic Data Masking to mask the credit card column for non-privileged users
C.Implement Azure SQL Database's Always Encrypted with enclaves
D.Implement Always Encrypted and store the column encryption key in Azure Key Vault
AnswerD

Always Encrypted is a client-side encryption technology that encrypts sensitive column data before it is sent to Azure SQL Database, so the database engine and its administrators never see plaintext. The application's driver uses the column encryption key (CEK) to encrypt and decrypt, while the CEK is wrapped by a column master key (CMK); storing the CMK in Azure Key Vault provides centralized, audited key management without exposing the CEK to the database server. Because only client applications possessing the necessary key material can decrypt the credit card values, database administrators and cloud operators are prevented from viewing the data.

Why this answer

Always Encrypted ensures that sensitive data, such as credit card numbers, is encrypted at rest and remains encrypted throughout its lifecycle, including during query processing. By storing the column encryption key in Azure Key Vault, you separate key management from the database, preventing even database administrators from accessing plaintext data. Only authorized applications with access to the key can decrypt the data at the application layer, meeting all stated requirements.

Exam trap

The trap here is confusing Transparent Data Encryption (TDE) with Always Encrypted; TDE protects at rest but not from database administrators or during query processing, whereas Always Encrypted provides client-side encryption that prevents even the database engine from seeing plaintext data.

How to eliminate wrong answers

Option A is wrong because Transparent Data Encryption (TDE) encrypts the entire database at rest but does not protect data from database administrators or during query execution; it also does not enforce application-layer decryption. Option B is wrong because Dynamic Data Masking only obfuscates data in query results for non-privileged users but does not encrypt data at rest or prevent privileged users from accessing plaintext. Option C is wrong because Always Encrypted with enclaves allows computations on encrypted data within a secure enclave, which is unnecessary here and introduces additional complexity; the core requirement of application-layer decryption with key separation is met by standard Always Encrypted.

242
Multi-Selecthard

Which THREE are prerequisites for integrating Microsoft Sentinel with Microsoft Defender XDR? (Choose three.)

Select 3 answers
A.Appropriate permissions (Security Administrator or Global Administrator)
B.The Microsoft 365 Defender data connector must be enabled in Sentinel
C.The Microsoft Monitoring Agent installed on all endpoints
D.A valid license for Microsoft 365 Defender (or individual workloads)
E.An Azure Sentinel workspace in the same region as the Microsoft 365 tenant
AnswersA, B, D

Correct: Required to enable the connector.

Why this answer

Integrating Microsoft Sentinel with Microsoft Defender XDR requires the user to have either Security Administrator or Global Administrator roles in Azure Active Directory. These permissions are necessary to grant consent for the data connector and to configure cross-tenant or cross-service access policies that enable Defender XDR to send incident and alert data to Sentinel.

Exam trap

The trap here is that candidates often assume the Microsoft Monitoring Agent is required for all Microsoft security integrations, but the Sentinel–Defender XDR connector is API-based and does not use MMA, and they also mistakenly think the workspace must be in the same region as the tenant, which is not enforced by the integration.

243
Multi-Selectmedium

Which TWO Azure services can be used to filter inbound internet traffic to a virtual network? (Choose two.)

Select 2 answers
A.Azure Firewall
B.Azure Bastion
C.Azure Front Door
D.Network security group (NSG)
E.VPN gateway
AnswersA, D

Azure Firewall is a stateful, managed network security service that inspects and filters inbound internet traffic at the virtual network boundary, satisfying the requirement to control traffic entering the VNet from the internet using FQDN and threat intelligence rules.

Why this answer

Both Azure Firewall and Network Security Groups (NSGs) can filter inbound internet traffic to a virtual network. Azure Firewall provides centralized, stateful filtering at Layers 3-7 with features like threat intelligence and application rules. NSGs are distributed, stateful packet filters that apply to subnets or NICs, filtering traffic based on source/destination IP, port, and protocol rules, and are commonly used to block inbound internet traffic at the subnet boundary.

Exam trap

The trap here is that candidates may overlook NSGs because they are a basic security feature, thinking only a dedicated firewall service can filter inbound traffic. However, NSGs are perfectly capable of filtering inbound internet traffic at the network layer. Another common mistake is selecting Azure Bastion, which is a secure jump box for management traffic, not a general traffic filter.

244
MCQmedium

A company uses Azure Active Directory (Azure AD) and has a conditional access policy that requires multi-factor authentication (MFA) for all external users accessing SharePoint Online. However, the security team wants to enforce that external users must re-authenticate every 30 minutes when accessing SharePoint. Which control should they configure in a new conditional access policy targeting SharePoint Online?

A.Assign the policy to 'All cloud apps' and use a grant control to require multi-factor authentication.
B.Configure a condition for sign-in risk level and set it to 'High'.
C.Add a session control and set 'Sign-in frequency' to 30 minutes.
D.Configure a session control to use 'App enforced restrictions' for SharePoint.
AnswerC

The 'Sign-in frequency' session control in Azure AD Conditional Access defines how long a user's session remains valid before they must sign in again. Setting it to 30 minutes forces reauthentication every half hour for the targeted cloud app, exactly matching the stated requirement. This is the appropriate control because it is enforced by Azure AD at the session level, independent of the application's own settings.

Why this answer

The 'Sign-in frequency' session control in a Conditional Access policy allows administrators to enforce re-authentication at a specified interval. By setting this to 30 minutes and targeting the SharePoint Online app, external users will be prompted to re-authenticate every 30 minutes, meeting the security team's requirement. This control is independent of MFA and specifically addresses the frequency of authentication sessions.

Exam trap

The trap here is that candidates often confuse 'Sign-in frequency' with 'Grant controls' (like MFA) or 'Conditions' (like risk), not realizing that session controls specifically manage the duration of authentication sessions rather than the method of authentication.

How to eliminate wrong answers

Option A is wrong because assigning the policy to 'All cloud apps' and requiring MFA does not enforce a re-authentication frequency; it only mandates MFA at initial sign-in, not every 30 minutes. Option B is wrong because configuring a condition for sign-in risk level set to 'High' triggers MFA or block based on risk, not a fixed 30-minute re-authentication interval. Option D is wrong because 'App enforced restrictions' is a session control that delegates session management to the application (e.g., SharePoint), but it does not enforce a specific re-authentication frequency like 30 minutes.

245
MCQmedium

A security team uses Microsoft Sentinel. They want to create a custom analytics rule that detects when a user account is created in Azure AD and then within 5 minutes attempts to access a sensitive SharePoint site. What should they use to correlate these two events?

A.KQL query with join on UserId
B.Watchlist
C.Automation rule
D.Playbook
AnswerA

A KQL query with a join on UserId is the correct choice because it directly correlates events from multiple Sentinel tables, such as SigninLogs and AuditLogs, on a common field to detect suspicious patterns. The join operator in KQL supports different join kinds (inner, leftouter, etc.) to capture matching or non-matching records, enabling the security team to define precise detection logic. This alignment between the query's data correlation and the scenario makes it the only option that fulfills the requirement for real-time detection.

Why this answer

A KQL query with a join on UserId allows you to correlate two separate tables—such as AuditLogs for user creation and SharePoint access logs—based on a common field (UserId) within a specified time window (5 minutes). This is the standard method in Microsoft Sentinel for creating multi-event detection rules that require temporal correlation between distinct activities.

Exam trap

The trap here is that candidates may confuse a Watchlist (used for static lookups) with a correlation mechanism, or mistakenly think Automation rules or Playbooks can perform event correlation, when in fact only KQL queries with joins can correlate multiple events in a single detection rule.

How to eliminate wrong answers

Option B is wrong because a Watchlist is a static list of items (e.g., IP addresses or account names) used for reference or filtering, not for correlating dynamic events across time. Option C is wrong because an Automation rule in Sentinel triggers a response (e.g., incident creation or playbook execution) based on a single alert or incident, not for correlating two separate events. Option D is wrong because a Playbook is a set of automated actions (often using Azure Logic Apps) triggered by an alert, not a mechanism to correlate events in a detection query.

246
MCQeasy

You need to prioritize security recommendations in Microsoft Defender for Cloud. Your compliance team requires a framework that maps to regulatory standards. What should you use?

A.Regulatory compliance standards
B.Azure Policy compliance dashboard
C.Inventory feature
D.Secure score
AnswerA

Regulatory compliance standards in Microsoft Defender for Cloud are the correct choice because they directly map security recommendations to specific compliance frameworks, such as SOC 2, PCI DSS, and ISO 27001. This feature provides a dashboard where you can track your organization's compliance posture against each standard, with controls and corresponding recommendations that need remediation. It allows you to prioritize recommendations based on regulatory audit deadlines and requirements, which aligns with the compliance team's need to map recommendations to regulations.

Why this answer

Regulatory compliance standards in Microsoft Defender for Cloud map security recommendations to specific regulatory frameworks (e.g., SOC 2, PCI DSS, ISO 27001), enabling the compliance team to prioritize based on regulatory requirements. The secure score (Option D) provides an overall posture but does not map to specific standards. Azure Policy compliance dashboard (Option B) is used for policy enforcement, not recommendation prioritization.

Inventory (Option C) lists resources without compliance mapping.

247
MCQmedium

A company has two application tiers: web servers and application servers. They want to allow traffic from the web servers to the application servers on port 8080, but only for a specific set of web servers. They have deployed the web servers in an Availability Set and want to use a single NSG rule to allow traffic from any web server that is part of that application tier. Which component should they use?

A.Application security group
B.Service tag
C.Source IP address range
D.Virtual network peering
AnswerA

An application security group (ASG) is the correct choice because it lets you group VM network interfaces by workload role, such as all web servers, and reference that group directly as the source in a network security group (NSG) rule. As VMs are added or removed from the tier, the ASG membership updates automatically, so the NSG rule dynamically reflects the current set of web server IP addresses without requiring manual edits. ASGs provide a scalable, intent-based way to enforce microsegmentation and zero-trust network access across VMs.

Why this answer

An Application Security Group (ASG) allows you to group virtual machines logically by their application roles (e.g., web servers) and then use that ASG as the source in a single NSG rule. Since the web servers are in an Availability Set, you can assign the same ASG to their NICs, and the NSG rule will dynamically include all current and future VMs in that ASG. This meets the requirement to allow traffic from any web server in that tier to the application servers on port 8080 without maintaining individual IP addresses.

Exam trap

The trap here is that candidates often confuse Application Security Groups with Network Security Groups themselves, or mistakenly think Service Tags can be used to group custom sets of VMs, when in fact Service Tags are only for Azure services or broad network scopes.

How to eliminate wrong answers

Option B is wrong because a Service Tag (e.g., 'VirtualNetwork') represents a predefined group of IP addresses from Azure services or the entire virtual network, not a custom set of specific VMs like the web servers in an Availability Set. Option C is wrong because using a Source IP address range would require you to list the individual private IPs of each web server, which is not dynamic and would break the requirement to use a single rule for any web server in the tier. Option D is wrong because Virtual Network Peering connects two virtual networks at the network layer, but it does not provide granular control to filter traffic from a specific subset of VMs within a peered network; it simply enables connectivity between the entire VNets.

248
Multi-Selecthard

Your company has a Microsoft Entra ID tenant with 10,000 users. You need to implement a secure authentication strategy that satisfies the following requirements: - Users must not be able to bypass security verification using alternate authentication methods. - Passwordless authentication should be used where possible. - Legacy authentication protocols must be blocked. Which THREE actions should you take? (Choose three.)

Select 3 answers
A.Create a Conditional Access policy to block legacy authentication protocols.
B.Configure per-user MFA to require verification.
C.Enable FIDO2 security keys as an authentication method and configure passwordless sign-in.
D.Enable the 'Security defaults' feature in Microsoft Entra ID.
E.Disable SMS and voice call authentication methods in Microsoft Entra ID.
AnswersA, C, E

Conditional Access policies operate at the authentication plane and allow granular control based on client app, IP, and risk. By targeting 'Other clients' and explicitly selecting 'Block access,' you can deny legacy protocols like POP3, IMAP4, and SMTP AUTH that bypass modern authentication and MFA, effectively closing known attack vectors for password-spraying and credential-stuffing. This is the most direct and policy-driven method to prohibit these insecure sign-ins across all users and apps.

Why this answer

Option A is correct because a Conditional Access policy targeting the 'Other clients' client apps condition (which covers legacy protocols such as IMAP, POP3, SMTP AUTH, and older Office clients) is the supported way to block legacy authentication in Microsoft Entra ID. Option C is correct because enabling the FIDO2 security key authentication method and configuring it for passwordless sign-in provides a phishing-resistant, passwordless credential that satisfies the passwordless requirement. Option E is correct because disabling SMS and voice call methods removes weaker alternate authentication methods that users could otherwise use to bypass stronger security verification, directly addressing the no-bypass requirement.

Option B is not correct because per-user MFA is a legacy, always-on setting that cannot enforce method restrictions or passwordless flows and does not block legacy authentication. Option D is not correct because Security defaults are a baseline for tenants without Conditional Access and cannot be combined with the granular Conditional Access policy needed here, nor do they enforce passwordless authentication.

Exam trap

The trap here is that candidates often assume Security defaults is the simplest way to block legacy authentication and enforce MFA, but they overlook that Security defaults cannot be customized to selectively enable FIDO2 or disable specific methods, making it incompatible with the requirement for passwordless authentication and granular control.

249
MCQhard

You are configuring Microsoft Sentinel to use a playbook for automated response to incidents. The playbook needs to block the source IP address of a malicious sign-in on the Azure Firewall. Which Microsoft Sentinel feature should the playbook use?

A.Azure Automation runbooks
B.Azure Functions
C.Azure Logic Apps
D.KQL queries
AnswerC

Azure Logic Apps are the correct platform for Sentinel playbooks because they provide a low-code workflow engine with native connectors to Microsoft Defender, Teams, ServiceNow, and hundreds of other services. Logic Apps are triggered by Sentinel incidents and alerts through dedicated connectors, allowing automated investigation and response actions. They support both consumption and standard hosting plans and are the only compute service that integrates natively with Sentinel automation rules.

Why this answer

Microsoft Sentinel playbooks are built on Azure Logic Apps, which provide the workflow automation and connectors needed to orchestrate response actions like blocking an IP on Azure Firewall. Logic Apps can integrate with Azure Firewall via its REST API or the Azure Resource Manager connector to update firewall rules, making it the correct feature for this automated incident response task.

Exam trap

The trap here is that candidates often confuse Azure Automation runbooks (Option A) with Logic Apps because both can automate tasks, but Sentinel playbooks are explicitly built on Logic Apps, not Automation runbooks, and the exam tests this specific architectural distinction.

How to eliminate wrong answers

Option A is wrong because Azure Automation runbooks are designed for script-based automation (e.g., PowerShell, Python) and lack the native connectors and workflow designer for direct integration with Sentinel incidents and Azure Firewall rule updates; they require custom code and are less suited for event-driven playbooks. Option B is wrong because Azure Functions are serverless compute units for running code in response to events, but they do not provide the built-in connectors, workflow state management, or visual designer that Sentinel playbooks require; using Functions would necessitate manual implementation of the entire orchestration and connector logic. Option D is wrong because KQL queries are used for querying and analyzing log data in Sentinel, not for executing automated response actions like blocking an IP address on a firewall.

250
MCQmedium

An organization is required to comply with the Health Insurance Portability and Accountability Act (HIPAA). They use Microsoft Defender for Cloud to manage their Azure security posture. Which feature in Defender for Cloud should they use to view their current compliance status against HIPAA controls?

A.Regulatory compliance dashboard.
B.Security posture dashboard.
C.Recommendations dashboard.
D.Inventory dashboard.
AnswerA

The Regulatory compliance dashboard in Microsoft Defender for Cloud is the correct tool because it continuously assesses your Azure environment against built-in regulatory standards such as HIPAA HITRUST, GDPR, and ISO 27001. It uses Azure Policy initiatives to map specific controls to resources, presenting a compliance score and per-control pass/fail status. This dashboard directly provides the evidence and remediation tracking needed to demonstrate adherence to HIPAA requirements, unlike the other dashboards.

Why this answer

The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built view of your compliance posture against various standards, including HIPAA. It continuously assesses your Azure environment against HIPAA controls and displays the current compliance status, enabling you to track and improve adherence to regulatory requirements.

Exam trap

The trap here is that candidates often confuse the Security posture dashboard (which shows overall security health) with the Regulatory compliance dashboard, mistakenly thinking the former includes compliance status against specific standards like HIPAA.

How to eliminate wrong answers

Option B is wrong because the Security posture dashboard focuses on the overall security state of your resources (e.g., secure score, attack paths) rather than mapping to specific regulatory frameworks like HIPAA. Option C is wrong because the Recommendations dashboard lists actionable security recommendations to improve your secure score, but it does not organize them by compliance standard or show compliance status against HIPAA controls. Option D is wrong because the Inventory dashboard provides a list of all monitored resources and their configurations, not a compliance-specific view against regulatory standards.

251
MCQmedium

A security team uses Microsoft Defender for Cloud to monitor the security posture of their Azure environment. They want to ensure that the Log Analytics agent is automatically installed on all new Azure virtual machines as soon as they are provisioned, to collect security logs. Which feature should they enable in Defender for Cloud?

A.Data Collection Rules (DCR) in Azure Monitor.
B.Auto-provisioning of the Log Analytics agent in Defender for Cloud's environment settings.
C.Azure Policy 'Deploy Log Analytics agent for Linux/Windows VM'.
D.Use Azure Automation State Configuration.
AnswerB

Auto-provisioning installs the Log Analytics agent automatically on newly created and existing Azure VMs, using the workspace configured in environment settings. This satisfies the requirement that new VMs receive the agent immediately at provisioning without manual installation.

Why this answer

Defender for Cloud's auto-provisioning feature is specifically designed to automatically install the Log Analytics agent on all existing and new Azure VMs to collect security logs. When enabled in the environment settings, it ensures that any new VM provisioned in the subscription gets the agent installed without manual intervention, directly addressing the requirement for automatic installation on new VMs.

Exam trap

The trap here is that candidates often confuse Azure Policy-based deployment (Option C) with Defender for Cloud's native auto-provisioning, but the question specifically asks for the feature within Defender for Cloud's environment settings, which is auto-provisioning, not a separate policy assignment.

How to eliminate wrong answers

Option A is wrong because Data Collection Rules (DCRs) in Azure Monitor are used to define data collection for the Azure Monitor Agent (AMA), not for the Log Analytics agent, and they do not automatically install agents on new VMs. Option C is wrong because the Azure Policy 'Deploy Log Analytics agent for Linux/Windows VM' is a built-in policy that can deploy the agent, but it requires assignment and evaluation, and it does not automatically trigger on new VM provisioning without policy compliance checks; it is a policy-based remediation, not a native auto-provisioning feature of Defender for Cloud. Option D is wrong because Azure Automation State Configuration is used for managing PowerShell DSC configurations and ensuring VM state compliance, not for automatically installing the Log Analytics agent for security log collection.

252
Multi-Selectmedium

You are a security engineer at Litware. The company has an Azure virtual network named VNet1 with a subnet named Subnet1 that hosts several virtual machines. You need to restrict outbound internet access from Subnet1 to only allow traffic to specific FQDNs, such as *.microsoft.com and *.azure.com, while blocking all other outbound internet traffic. You also need to log allowed and denied traffic. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Create a user-defined route (UDR) in Subnet1 that directs all outbound traffic (0.0.0.0/0) to the Azure Firewall's private IP address as the next hop.
B.Enable Azure DDoS Protection Standard on VNet1 to filter outbound traffic based on domain names.
C.Configure a network security group (NSG) on Subnet1 with outbound rules that allow traffic to the FQDNs and deny all other outbound traffic.
D.Deploy an Azure Application Gateway with WAF and configure custom rules to allow the FQDNs for outbound traffic.
E.Deploy Azure Firewall and configure application rules to allow the specified FQDNs, then set a default deny for all other outbound traffic.
AnswersA, E

A user-defined route with address prefix 0.0.0.0/0 and next hop type Virtual appliance, pointing to the Azure Firewall's private IP, forces all outbound traffic from Subnet1 through the firewall. Without this route, traffic would bypass the firewall and go directly to the internet, so it is essential to enforce inspection.

Why this answer

To restrict outbound internet access to specific FQDNs and log traffic, you need Azure Firewall with application rules that allow the desired FQDNs and deny everything else. You also need a user-defined route in Subnet1 that sends all outbound traffic (0.0.0.0/0) to the firewall's private IP. This combination ensures traffic is forced through the firewall and filtered by FQDN, with logging of allowed and denied flows.

Exam trap

The trap here is assuming that network security groups can filter by FQDN or that simply deploying Azure Firewall without a user-defined route will automatically redirect traffic through it.

253
MCQeasy

You are configuring Microsoft Entra ID Connect to synchronize on-premises Active Directory identities to the cloud. You need to ensure that password hashes are synchronized to enable Microsoft Entra ID Password Protection and Identity Protection. Which option should you enable?

A.Pass-through authentication
B.Federation with AD FS
C.Password hash synchronization
D.Azure AD Connect Health
AnswerC

Password hash synchronization (PHS) is the correct option because Entra ID Connect computes a one-way salted SHA256 hash of each on-premises Active Directory password and synchronizes that hash to Azure AD. This synchronized hash enables cloud authentication using the same password while also feeding downstream features such as Identity Protection's leaked credentials detection and Azure AD Password Protection's banned password list. The process is designed to be irreversible; the plaintext password is never transmitted or stored, only the derived hash, which directly fulfills the requirement to synchronize password hashes.

Why this answer

Password hash synchronization (PHS) is the correct option because it is the specific feature that synchronizes password hashes from on-premises Active Directory to Microsoft Entra ID. This enables Microsoft Entra ID Password Protection (which blocks weak passwords by comparing against a global banned password list) and Identity Protection (which detects leaked credentials by comparing synchronized hashes against known compromised password databases). Without PHS, these cloud-based security features have no access to the on-premises password hashes.

Exam trap

The trap here is that candidates often confuse Pass-through authentication with Password hash synchronization, assuming that any password validation method that touches on-premises AD will automatically provide hash data for cloud security features, but only PHS actually stores the hashes in Microsoft Entra ID.

How to eliminate wrong answers

Option A is wrong because Pass-through authentication validates passwords directly against on-premises AD without storing password hashes in the cloud, so it does not provide the hash data needed for Password Protection or Identity Protection. Option B is wrong because Federation with AD FS relies on on-premises authentication and does not synchronize password hashes to Microsoft Entra ID, making it incompatible with cloud-only password analysis features. Option D is wrong because Azure AD Connect Health is a monitoring and diagnostics tool for the synchronization infrastructure, not a mechanism for synchronizing password hashes.

254
Multi-Selecthard

You are a security engineer for Fabrikam. The company has an Azure virtual network named VNet1 that contains a subnet named Subnet1 with several VMs. You need to ensure that all traffic from Subnet1 to the internet is inspected by Azure Firewall, and that the VMs can resolve external DNS names using Azure-provided DNS. The firewall is deployed in a subnet named AzureFirewallSubnet. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Create a service endpoint for Microsoft.Storage on Subnet1 to allow VMs to resolve external DNS names.
B.Deploy an Azure Bastion host in VNet1 and configure the VMs to use it as a DNS forwarder.
C.Associate a network security group with Subnet1 that allows outbound traffic only to the Azure Firewall's private IP address.
D.Configure the Azure Firewall to use DNS proxy, and set the DNS servers on Subnet1 to the private IP address of the Azure Firewall.
E.Create a user-defined route on Subnet1 with address prefix 0.0.0.0/0 and next hop type Virtual appliance, pointing to the private IP address of the Azure Firewall.
AnswersD, E

Enabling DNS proxy on Azure Firewall allows the firewall to resolve external names on behalf of clients. Setting Subnet1's DNS servers to the firewall's private IP ensures that DNS queries from the VMs are sent to the firewall, which then forwards them to Azure-provided DNS, satisfying the name resolution requirement.

Why this answer

To inspect all internet-bound traffic from Subnet1 with Azure Firewall, a user-defined route must direct that traffic to the firewall's private IP. To allow VMs to resolve external names, enable DNS proxy on the firewall and point Subnet1's DNS settings to the firewall's private IP. Together, these actions meet both requirements.

Exam trap

The trap here is assuming that a network security group or service endpoint can redirect traffic to Azure Firewall or provide DNS resolution, when only a user-defined route and DNS proxy configuration achieve those goals.

255
MCQmedium

A company has Azure AD Identity Protection enabled. The security team wants to automatically block sign-ins that are detected as coming from a known malicious IP address. They have created a Conditional Access policy and assigned it to all users. Which configuration should they add to the policy to trigger the block based on Identity Protection risk?

A.Add a condition for 'Sign-in risk' set to 'High' and a grant control of 'Block access'.
B.Add a condition for 'Locations' and specify the known malicious IP ranges as 'Blocked locations'.
C.Add a condition for 'User risk' set to 'High' and a grant control of 'Require multi-factor authentication'.
D.Add a condition for 'Device state' set to 'Not compliant' and a grant control of 'Block access'.
AnswerA

In Azure AD Identity Protection, a sign-in from a known malicious IP is one of the real-time sign-in risk detections that raises the sign-in risk level to High. A Conditional Access policy with the 'Sign-in risk' condition set to High and a grant control of 'Block access' enforces a block on that specific risky sign-in, exactly meeting the requirement. This is the correct risk-based control because it relies on Identity Protection's detection rather than a static list.

Why this answer

Identity Protection detects sign-ins from known malicious IP addresses and assigns a 'Sign-in risk' level (e.g., High). By adding a condition for 'Sign-in risk' set to 'High' and a grant control of 'Block access', the Conditional Access policy will automatically block those sign-ins. This directly uses Identity Protection's risk detection to enforce the block without needing to manually maintain IP address lists.

Exam trap

The trap here is that candidates often confuse 'Sign-in risk' (based on the sign-in event's characteristics like IP) with 'User risk' (based on user account compromise likelihood), leading them to incorrectly choose Option C or to think that manually listing IPs in Locations (Option B) is the correct approach.

How to eliminate wrong answers

Option B is wrong because specifying known malicious IP ranges as 'Blocked locations' in the Locations condition would require manual maintenance of IP lists and does not leverage Identity Protection's dynamic risk detection; it also does not use the 'Sign-in risk' condition. Option C is wrong because 'User risk' is based on user behavior patterns (e.g., leaked credentials), not on the IP address of the sign-in, and 'Require multi-factor authentication' does not block access. Option D is wrong because 'Device state' set to 'Not compliant' checks device compliance status, not the IP address or sign-in risk, and is unrelated to Identity Protection's malicious IP detection.

256
MCQeasy

You need to securely connect to an Azure SQL Database from an on-premises application without exposing the database to the public internet. Which solution should you use?

A.Configure a firewall rule to allow the on-premises public IP address
B.Use Azure Private Link to connect via a private endpoint
C.Enable Always Encrypted on the database
D.Use a virtual network service endpoint for Azure SQL Database
AnswerB

Azure Private Link creates a private endpoint inside your virtual network, assigning the database a private IP address that is reachable only through your network. On-premises clients can securely connect to this endpoint via a VPN gateway or ExpressRoute, ensuring traffic never traverses the public internet. This eliminates exposure to the public endpoint and provides the highest level of network security for connecting to Azure SQL Database.

Why this answer

Azure Private Link allows you to access Azure SQL Database over a private endpoint within your virtual network, using a private IP address from your on-premises network via ExpressRoute or VPN. This ensures traffic never traverses the public internet, meeting the requirement for secure, non-public connectivity.

Exam trap

The trap here is that candidates often confuse service endpoints (which still use the public endpoint) with private endpoints (which provide truly private connectivity), leading them to choose Option D thinking it eliminates internet exposure.

How to eliminate wrong answers

Option A is wrong because configuring a firewall rule to allow the on-premises public IP address still exposes the database to the public internet, as traffic flows over the internet and the database endpoint remains publicly resolvable. Option C is wrong because Always Encrypted is a client-side encryption feature that protects data at rest and in transit, but it does not control network connectivity or prevent public internet exposure. Option D is wrong because a virtual network service endpoint for Azure SQL Database still uses the database's public endpoint, and traffic from on-premises would need to traverse the internet unless routed through a VPN/ExpressRoute, which still leaves the endpoint publicly accessible.

257
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) to manage the 'Security Administrator' role. They want to require that when a user activates this role, they must provide a support ticket number and a brief justification. Additionally, the activation should have a maximum duration of 4 hours. Which PIM role setting should they configure?

A.Require approval
B.Require MFA
C.Require justification on activation
D.Require Azure AD Identity Protection
AnswerC

This setting, often labeled 'Require justification' in PIM role settings, makes the justification text box mandatory during role activation. When enabled, the user must type a reason (and typically a support ticket number, depending on the ticketing requirement) before the activation request is submitted, and this value is then recorded in the PIM audit log. It directly satisfies the business requirement to enforce entering a ticket number and justification; activation duration is configured separately and does not affect this enforcement.

Why this answer

The 'Require justification on activation' setting in Azure AD PIM allows you to mandate that users provide a support ticket number and a brief justification when activating a role. This setting enforces the collection of business-specific details during activation, which aligns with the requirement. The maximum activation duration of 4 hours is configured separately via the 'Activation maximum duration' setting, not through justification.

Exam trap

The trap here is that candidates confuse 'Require justification on activation' with 'Require approval', mistakenly thinking that a support ticket number implies an approval workflow, but justification is a mandatory input field, not an approval step.

How to eliminate wrong answers

Option A is wrong because 'Require approval' enforces a workflow where a designated approver must approve the activation request, which is not the same as requiring a support ticket number and justification; it adds an approval step rather than a mandatory input field. Option B is wrong because 'Require MFA' enforces multi-factor authentication during activation, which addresses security verification but does not collect a support ticket number or justification. Option D is wrong because 'Require Azure AD Identity Protection' is not a valid PIM role setting; Azure AD Identity Protection is a separate service for risk-based policies and does not apply to PIM activation requirements.

258
MCQeasy

A security analyst uses Microsoft Defender for Cloud. They want to view a list of all security recommendations for their Azure subscription, prioritized by their potential impact. Which Defender for Cloud dashboard should they use?

A.Secure Score
B.Regulatory Compliance
C.Inventory
D.Workload protections
AnswerA

The Secure Score blade in Microsoft Defender for Cloud is specifically designed as a prioritized, actionable list of security recommendations. Each recommendation is shown with its potential score impact, so you can see how many points you gain by remediating it, and the list is sorted to highlight the highest-impact actions first. Because it consolidates all recommendations from applied security policies and weights them by severity and resource health, it directly answers the analyst's need to prioritize remediation work.

Why this answer

The Secure Score dashboard in Microsoft Defender for Cloud provides a prioritized list of security recommendations based on their potential impact on your overall security posture. Each recommendation is assigned a score contribution, allowing you to focus on the actions that will most improve your secure score. This directly matches the requirement to view recommendations prioritized by impact.

Exam trap

The trap here is that candidates often confuse the Secure Score dashboard with the Regulatory Compliance dashboard, thinking compliance standards inherently prioritize recommendations, but Secure Score is the only dashboard that explicitly ranks recommendations by their potential impact on your security score.

How to eliminate wrong answers

Option B (Regulatory Compliance) is wrong because it focuses on compliance with specific standards (e.g., SOC 2, ISO 27001) and does not prioritize recommendations by impact on secure score. Option C (Inventory) is wrong because it lists all resources in your Azure environment but does not provide security recommendations or prioritization. Option D (Workload protections) is wrong because it shows alerts and threats for specific workloads (e.g., servers, databases) rather than a prioritized list of security recommendations.

259
MCQeasy

Your organization uses Microsoft Entra ID for identity management. You need to ensure that users can sign in using a one-time passcode sent to their mobile device, without requiring any additional app or software installation. Which authentication method should you enable?

A.One-time passcode (OTP)
B.Microsoft Authenticator app
C.FIDO2 security keys
D.Certificate-based authentication
AnswerA

One-time passcode (OTP) is a built-in Microsoft Entra ID authentication method that sends a verification code to a user's verified email or phone number via SMS or email. It requires no additional app installation, hardware token, or certificate infrastructure, making it the simplest way to authenticate a user without a password. The code is time-limited and used once, providing a low-friction option for temporary or initial sign-in scenarios.

Why this answer

The one-time passcode (OTP) authentication method in Microsoft Entra ID allows users to sign in with a temporary code sent via SMS to their mobile device, requiring no additional app or software installation. This method is specifically designed for scenarios where users cannot or should not install the Microsoft Authenticator app, such as for guest users or in bring-your-own-device (BYOD) environments. The OTP is generated by Entra ID and delivered over the mobile network, satisfying the requirement of no extra software.

Exam trap

The trap here is that candidates often confuse the 'one-time passcode' option with the Microsoft Authenticator app's push notification or time-based code feature, but the question explicitly requires no additional app installation, making the SMS-based OTP the only correct choice.

How to eliminate wrong answers

Option B is wrong because the Microsoft Authenticator app requires installation of a mobile application on the user's device, which contradicts the requirement of 'without requiring any additional app or software installation.' Option C is wrong because FIDO2 security keys are hardware-based devices that must be physically plugged in or used via NFC, and they require additional software (browser support and platform attestation) to function, not meeting the no-software-installation condition. Option D is wrong because certificate-based authentication requires digital certificates to be provisioned and installed on the user's device, which involves software (certificate store, enrollment) and is not a simple one-time passcode delivered via SMS.

260
MCQeasy

A security team uses Microsoft Sentinel. They have created a playbook in Azure Logic Apps that automatically isolates a compromised VM by modifying a network security group. They want the playbook to run automatically whenever an incident of type 'VM Isolation' is created. Which Microsoft Sentinel feature should they use to trigger the playbook automatically?

A.Automation rules.
B.Scheduled analytics rules.
C.Fusion rules.
D.Workbooks.
AnswerA

Automation rules are the correct mechanism in Microsoft Sentinel for incident-centric orchestration. They allow you to define trigger conditions based on incident properties such as severity, status, title, or tactic, and then run playbooks, change incident status, assign ownership, add tasks, or apply tags whenever an incident is created or updated. This provides a single, consistent automation pipeline for incident management rather than tying actions to the specific detection that generated the alert.

Why this answer

Automation rules in Microsoft Sentinel are designed to trigger automated responses, such as running a playbook, when an incident is created or updated. In this scenario, the rule can be configured to match incidents of type 'VM Isolation' and automatically execute the Logic Apps playbook to isolate the compromised VM. This is the correct feature for incident-triggered automation without requiring a separate analytics rule.

Exam trap

The trap here is that candidates often confuse automation rules with analytics rules, thinking that a scheduled query rule is needed to trigger a playbook, but automation rules are the dedicated feature for incident-based automation without requiring a separate alert generation rule.

How to eliminate wrong answers

Option B (Scheduled analytics rules) is wrong because they generate alerts based on periodic queries of log data, not directly trigger playbooks on incident creation; they can be used with automation rules but are not the trigger themselves. Option C (Fusion rules) is wrong because they are a correlation engine that combines multiple alerts into a single incident using machine learning, not a mechanism to trigger playbooks automatically. Option D (Workbooks) is wrong because they are for visualizing and analyzing data, not for triggering automated responses or playbooks.

261
MCQmedium

You are a security engineer for a company that uses Microsoft Defender for Cloud. The security team wants to automatically trigger a Logic App playbook when a high-severity alert is generated for an Azure Storage account. The playbook must run without manual intervention. What should you configure?

A.Create an automation rule in Microsoft Defender for Cloud that triggers the playbook on alerts with severity High and resource type Storage accounts.
B.Configure a diagnostic setting to stream alerts to an event hub and use Azure Functions to invoke the playbook.
C.Enable just-in-time (JIT) VM access on the storage account and attach the playbook to the JIT policy.
D.Create an Azure Monitor action group that triggers the playbook when an alert is fired, and assign the action group to the storage account.
AnswerA

Automation rules in Microsoft Defender for Cloud can trigger Logic Apps based on alert severity, resource type, and other conditions. This directly satisfies the requirement for automatic, no-touch execution. The rule evaluates new alerts and invokes the playbook, which can then perform remediation steps such as isolating the storage account or notifying the SOC.

Why this answer

Automation rules in Microsoft Defender for Cloud are the native way to automatically respond to security alerts. They can filter by alert severity, resource type, and other properties, and then trigger a Logic App playbook. This provides a no-code, scalable solution that meets the requirement for automatic execution without manual intervention.

Other options either require custom code or apply to the wrong resource type.

Exam trap

The trap here is assuming that Azure Monitor action groups can directly trigger playbooks for Defender for Cloud alerts, when automation rules are the correct feature.

262
MCQhard

You are designing a secure data solution for a financial application. The data must be encrypted at rest, in transit, and in use. You choose Azure SQL Database. Which combination of features should you implement?

A.Transparent Data Encryption, enforce TLS, and Always Encrypted
B.Azure Information Protection, Dynamic Data Masking, and column-level security
C.Always Encrypted, Azure Active Directory authentication, and Azure Information Protection
D.Transparent Data Encryption, Dynamic Data Masking, and Azure Active Directory authentication
AnswerA

Transparent Data Encryption (TDE) encrypts database files, backups, and transaction logs at rest, ensuring stored data is unreadable without the database encryption key. Enforcing TLS 1.2+ protects data in transit between the application and Azure SQL, preventing man-in-the-middle interception. Always Encrypted encrypts sensitive columns client-side so the SQL engine never sees plaintext values, covering the data-in-use state during query processing. Together they comprehensively protect data at rest, in transit, and in use.

Why this answer

It addresses all three encryption states required by the scenario: Transparent Data Encryption (TDE) encrypts data at rest, enforcing TLS secures data in transit, and Always Encrypted protects data in use by keeping encryption keys client-side, ensuring plaintext data never appears in the database engine.

Exam trap

The trap here is that candidates often confuse Dynamic Data Masking with encryption, but masking only hides data from unauthorized users at query time while the underlying data remains unencrypted, failing the 'encrypted in use' requirement.

How to eliminate wrong answers

Option B is wrong because Azure Information Protection is a classification and labeling service, not an encryption mechanism for data at rest or in use; Dynamic Data Masking only obfuscates data at query time but does not encrypt it; column-level security controls access but does not encrypt data. Option C is wrong because Azure Active Directory authentication provides identity management, not encryption for data at rest or in transit; Azure Information Protection again does not encrypt database data. Option D is wrong because Dynamic Data Masking does not encrypt data in use or in transit; Azure Active Directory authentication does not provide encryption for data in transit or in use.

263
Multi-Selecthard

Which THREE are best practices for securing network traffic in Azure? (Choose three.)

Select 3 answers
A.Use private endpoints for Azure services
B.Assign public IP addresses to every VM
C.Allow direct outbound internet access from VMs
D.Implement just-in-time (JIT) VM access
E.Use service tags in NSG rules
AnswersA, D, E

Azure Private Endpoints use a network interface with a private IP from your VNet to connect to PaaS services (e.g., Storage, SQL DB), so traffic flows entirely over the Microsoft backbone and never reaches the public internet. This eliminates data exposure to the internet and enables secure connections from on-premises via ExpressRoute or VPN, while also helping prevent data exfiltration by keeping service communication inside your virtual network.

Why this answer

Option A is correct because private endpoints assign a private IP address from your VNet to an Azure PaaS service via Azure Private Link, keeping traffic on the Microsoft backbone and eliminating exposure to the public internet. Option D is correct because just-in-time (JIT) VM access in Microsoft Defender for Cloud opens NSG rules only on demand for a limited time and from approved source IPs, reducing the attack surface of management ports like RDP 3389 and SSH 22. Option E is correct because service tags in NSG rules let you allow or deny traffic to specific Azure services (for example, Storage or Sql) by Microsoft-managed IP ranges, avoiding broad 0.0.0.0/0 or Internet rules and simplifying maintenance.

Option B is not a best practice because assigning public IP addresses to every VM directly exposes them to internet scanning and brute-force attacks; VMs should generally be reached via Bastion, VPN, or private endpoints. Option C is not a best practice because allowing direct outbound internet access from VMs bypasses inspection and enables data exfiltration and command-and-control traffic; outbound traffic should be routed through Azure Firewall, NAT Gateway, or a user-defined route to a controlled egress point.

Exam trap

The trap here is that candidates often confuse 'just-in-time VM access' (which controls RDP/SSH access) with network traffic security, but it is indeed a best practice for reducing the attack surface of management ports, so it is correct; the real distractors are the obviously insecure options B and C that test your understanding of exposure minimization.

264
MCQhard

A company uses Azure AD Identity Protection. They want to automatically block sign-ins that have a high user risk level, but only for users in the 'Finance' department. They also want to require MFA for medium user risk level for all users (including Finance) when sign-in risk is not blocked. They have already created a Conditional Access policy for the Finance department that has a condition of 'User risk level: High' and a grant control of 'Block access'. What additional configuration is needed to also require MFA for all users with medium user risk?

A.Create a second Conditional Access policy targeting all users with condition 'User risk level: Medium' and grant control 'Require multi-factor authentication'
B.Modify the existing policy to include 'User risk level: Medium' and change the grant control to 'Require multi-factor authentication'
C.Use Identity Protection's 'User risk policy' instead of Conditional Access
D.Create a new Conditional Access policy with condition 'User risk level: Medium' and grant control 'Block access'
AnswerA

A separate policy for medium user risk applied to all users will require MFA when medium risk is detected. The existing policy will continue to block Finance users with high risk. Policy evaluation is not mutually exclusive; the block takes precedence for high risk, and the MFA requirement applies for medium risk.

Why this answer

Azure AD Conditional Access policies are evaluated independently, and a separate policy is needed to require MFA for medium user risk across all users. The existing policy blocks high-risk sign-ins for Finance only, but does not address medium risk for any user. Creating a second policy targeting all users with 'User risk level: Medium' and grant control 'Require multi-factor authentication' satisfies the requirement without conflicting with the existing block policy, as Conditional Access policies are combined (unless explicitly excluded).

Exam trap

The trap here is that candidates often think a single policy can handle multiple risk levels with different grant controls, but Conditional Access policies enforce a single grant control per policy, so separate policies are required for different risk level actions.

How to eliminate wrong answers

Option B is wrong because modifying the existing policy to include 'User risk level: Medium' and changing the grant control to 'Require multi-factor authentication' would remove the block for high-risk Finance users, violating the requirement to block high-risk sign-ins for Finance. Option C is wrong because Identity Protection's 'User risk policy' is a legacy, tenant-wide risk-based policy that cannot target specific departments like Finance; it also does not support the granularity of Conditional Access for combining risk levels with other conditions. Option D is wrong because creating a new policy with 'User risk level: Medium' and grant control 'Block access' would block medium-risk users instead of requiring MFA, which contradicts the requirement to require MFA for medium risk.

265
MCQeasy

A company is deploying Microsoft Sentinel in a new Azure subscription. The security team wants to ingest Windows security events from on-premises servers. Which data connector should they use?

A.Windows Security Events via AMA (Azure Monitor Agent)
B.Office 365 connector
C.Azure Active Directory connector
D.Common Event Format (CEF) connector
AnswerA

The Windows Security Events via AMA connector is the correct choice because Azure Monitor Agent (AMA) is the modern agent that collects Windows Event Logs, including the Security channel, using a Data Collection Rule (DCR). This connector streams events such as successful/failed logons, process creation, and privilege use directly into Sentinel's WindowsEvent table, making it the current standard for this source. Unlike the legacy Log Analytics agent, AMA provides a single agent for both Log Analytics and extension-based workloads, with more granular filtering and network-friendly control.

Why this answer

The Windows Security Events via AMA connector is the current recommended method for streaming Windows security events to Azure Sentinel using the Azure Monitor Agent. Option B is wrong because the Azure Active Directory connector is for Microsoft Entra ID logs, not Windows events. Option C is wrong because the Office 365 connector is for Office logs.

Option D is wrong because the Common Event Format (CEF) connector is for syslog from security appliances, not Windows security events.

266
MCQmedium

You are designing network security for a hybrid application that uses Azure Front Door and Azure Application Gateway. The application must block malicious requests at the edge before they reach the backend. You need to implement Web Application Firewall (WAF) protection with the lowest latency and the ability to inspect traffic at the application layer. Which solution should you use?

A.Enable Azure DDoS Protection on the virtual network.
B.Apply WAF policy on Azure Application Gateway only.
C.Apply WAF policy on Azure Front Door.
D.Use Azure Firewall with threat intelligence-based filtering.
AnswerC

Applying a WAF policy on Azure Front Door is the correct choice because Front Door operates at the global edge, inspecting all incoming HTTP/S requests in the closest PoP to the client, which minimizes latency and blocks malicious traffic before it travels to the origin or Application Gateway. Front Door's WAF supports managed rule sets (e.g., OWASP Core Rule Set), custom rules, geo-filtering, rate limiting, and bot protection, allowing comprehensive application-layer defense at the edge. This design keeps the hybrid application's internal network and gateway isolated from attack traffic, reducing the risk of resource exhaustion and ensuring only legitimate requests are forwarded.

Why this answer

Azure Front Door's WAF operates at the edge of the Microsoft global network, inspecting HTTP/HTTPS traffic at the application layer (Layer 7) with minimal latency due to its distributed point-of-presence (PoP) architecture. This allows malicious requests to be blocked before they traverse the backbone to the origin, meeting the requirement for edge protection and low latency.

Exam trap

The trap here is that candidates often confuse Azure Application Gateway's WAF (which is regional and higher latency) with Azure Front Door's WAF (which is global and edge-based), leading them to choose Option B because they assume all WAF policies are equivalent, ignoring the latency and edge placement requirements.

How to eliminate wrong answers

Option A is wrong because Azure DDoS Protection operates at the network layer (Layer 3/4) and does not inspect application-layer traffic or provide WAF capabilities to block malicious HTTP requests. Option B is wrong because applying WAF on Azure Application Gateway only protects traffic after it reaches the regional gateway, not at the edge, which introduces higher latency and does not block malicious requests before they enter the Azure backbone. Option D is wrong because Azure Firewall with threat intelligence-based filtering operates at the network and transport layers (Layer 3/4) and does not perform deep application-layer inspection or WAF rule matching for HTTP/HTTPS payloads.

267
MCQhard

A company has two Azure virtual networks, VNet-A and VNet-B, connected via VNet peering. They want all traffic between the VNets to be inspected by a network virtual appliance (NVA) deployed in a subnet in VNet-A. They have configured a user-defined route (UDR) on the subnet in VNet-B that points the destination address space of VNet-A to the private IP of the NVA. However, traffic between the VNets is still not passing through the NVA. What is the most likely cause?

A.The UDR is not associated with the subnet in VNet-B.
B.The NVA's network interface (NIC) does not have IP forwarding enabled.
C.The VNet peering connection is not in a 'Connected' state.
D.The NVA is deployed in the same subnet as the source VMs.
AnswerB

IP forwarding must be explicitly enabled on the network interface (NIC) of the NVA before Azure will deliver packets whose destination IP is not assigned to that NIC. Without it, the Azure fabric drops packets that are addressed to other IPs, so even if the NVA's operating system is configured to route traffic, the packets never reach it. This is the most common omission when deploying NVAs with UDRs, and it precisely explains why traffic flows end-to-end via peering but not through the NVA — the NVA silently discards (or never receives) the forwarded packets.

Why this answer

The most likely cause is that the NVA's network interface (NIC) does not have IP forwarding enabled. Even with a correctly configured UDR on VNet-B pointing traffic to the NVA's private IP, the NVA will drop any traffic not destined for its own IP unless IP forwarding is enabled on its NIC. This setting allows the NVA to accept packets with a destination other than itself and forward them based on its routing table, which is essential for traffic inspection scenarios.

Exam trap

The trap here is that candidates often focus on UDR configuration or peering state, overlooking the critical NIC-level IP forwarding setting that is required for any NVA to function as a transit hop in Azure.

How to eliminate wrong answers

Option A is wrong because the question explicitly states that a UDR has been configured on the subnet in VNet-B, implying it is associated; if it were not associated, the UDR would have no effect, but the core issue here is the NVA's inability to forward traffic. Option C is wrong because if the VNet peering were not in a 'Connected' state, no traffic would flow between the VNets at all, but the question indicates traffic is still passing (just not through the NVA), so peering is functional. Option D is wrong because the NVA being in the same subnet as source VMs does not inherently prevent traffic inspection; UDRs can still direct traffic to the NVA, but the NVA's NIC must have IP forwarding enabled to process and forward that traffic.

268
MCQmedium

A company uses Microsoft Defender for Cloud. They have assigned a custom regulatory compliance initiative that includes policies to enforce encryption on storage accounts and SQL databases. They want to automatically remediate any non-compliant resources that are discovered, without manual intervention. Which feature should they configure?

A.Enable 'Auto provisioning' for the relevant extensions
B.Enable 'Remediation' for each policy assignment in the custom initiative
C.Enable 'Just-in-time (JIT) VM access'
D.Enable 'Workflow automation' to trigger a Logic App when non-compliance is detected
AnswerB

Azure Policy's remediation feature is the native mechanism for automatically fixing resources that are non-compliant with policies that use the DeployIfNotExists or Modify effects. When you assign a custom initiative, you can enable remediation for each assignment, which creates a managed identity and allows the policy engine to run remediation tasks during evaluation cycles. These tasks deploy the required template or modify the resource configuration—such as enabling disk encryption—directly, without manual intervention. This is the correct option because it uses the built-in, continuously-running remediation engine tied to policy assignments.

Why this answer

The 'Remediation' setting on a policy assignment in Azure Policy (used by Defender for Cloud custom initiatives) creates a managed identity and a remediation task that automatically applies the required encryption configuration to non-compliant resources. This ensures that when a storage account or SQL database is found without encryption, the policy engine triggers a deployment to enforce encryption without manual intervention.

Exam trap

The trap here is that candidates confuse 'Auto provisioning' (which installs agents for data collection) with automatic remediation of compliance policies, or they assume 'Workflow automation' directly fixes non-compliance when it only triggers a notification or custom action.

How to eliminate wrong answers

Option A is wrong because 'Auto provisioning' in Defender for Cloud installs extensions (like the Log Analytics agent) on VMs to collect security data, not to remediate encryption policies on storage or SQL resources. Option C is wrong because 'Just-in-time (JIT) VM access' controls network access to VMs by opening ports temporarily, which is unrelated to enforcing encryption compliance on storage accounts and SQL databases. Option D is wrong because 'Workflow automation' triggers a Logic App when non-compliance is detected, but it does not automatically remediate the resource; it only sends notifications or runs custom actions, requiring additional setup to perform remediation.

269
MCQhard

You are the security engineer for a healthcare company that uses Azure to store electronic health records (EHR) in Azure Blob Storage. Compliance requires that all data be encrypted at rest with customer-managed keys stored in a hardware security module (HSM), that the storage account be accessible only from a specific virtual network, and that all access to the storage account be logged and sent to a central security information and event management (SIEM) system. Additionally, you must ensure that any blobs containing protected health information (PHI) are automatically labeled with a sensitivity label that prevents them from being shared externally. You have decided to use Azure Key Vault Managed HSM for key storage, Azure Private Endpoint for network access, and Azure Monitor for logging. However, you are unsure how to automatically apply sensitivity labels to blobs based on content inspection. Which service should you use to achieve automatic labeling of PHI data in Azure Blob Storage?

A.Microsoft Defender for Storage with sensitivity labeling integration
B.Azure Policy with custom policies to tag blobs containing PHI
C.Microsoft Purview Information Protection with auto-labeling policies for Azure Blob Storage
D.Microsoft Sentinel with analytics rules to detect PHI and apply labels via automation
AnswerC

Purview Information Protection auto-labelling policies scan blob content and apply sensitivity labels automatically, and those labels travel with the data to block external sharing. This satisfies the content-inspection requirement that Key Vault Managed HSM, Private Endpoint and Azure Monitor do not address.

Why this answer

Microsoft Purview Information Protection with auto-labeling policies for Azure Blob Storage (option C) is the correct choice because it is the service designed to scan and classify data in Azure Blob Storage using sensitive information types and then automatically apply sensitivity labels that enforce protection such as preventing external sharing. It integrates with the same Microsoft Purview compliance stack that provides sensitivity labels, so labels applied to blobs can carry encryption and sharing restrictions. The other options do not provide native automatic sensitivity labeling: Defender for Storage (A) offers threat detection and can integrate with Purview labeling but does not itself perform content-based auto-labeling, Azure Policy (B) can audit or tag resources but cannot inspect blob content or apply sensitivity labels, and Microsoft Sentinel (D) is a SIEM/SOAR tool for detection and automation, not a data classification and labeling engine.

270
MCQmedium

A company wants to use Microsoft Defender for Cloud to continuously assess their Azure resources against the Microsoft cloud security benchmark (MCSB). They need to view the current compliance score and specific recommendations for failing controls. Which feature in Defender for Cloud should they use?

A.Security Policy
B.Regulatory Compliance dashboard
C.Secure Score
D.Workload Protections
AnswerB

The Regulatory Compliance dashboard is the dedicated reporting interface within Microsoft Defender for Cloud that continuously aggregates assessment results for assigned standards like MCSB. It provides a compliance score per standard, a per-control breakdown of pass and fail status, and drill-down details for each recommendation that impacts a control. This dashboard directly answers the requirement to assess compliance against a chosen regulatory framework by showing exactly which controls are not met and why. It is the correct tool because it maps Azure Security benchmark recommendations to regulatory compliance controls and offers a visual, actionable score.

Why this answer

The Regulatory Compliance dashboard in Microsoft Defender for Cloud is specifically designed to assess resources against compliance standards like the Microsoft cloud security benchmark (MCSB). It provides a current compliance score, a breakdown of failing controls, and actionable recommendations to remediate those controls, directly meeting the company's requirement.

Exam trap

The trap here is confusing Secure Score (which shows overall security posture) with Regulatory Compliance (which shows adherence to a specific benchmark), leading candidates to pick Secure Score when the question explicitly asks for compliance against MCSB.

How to eliminate wrong answers

Option A is wrong because Security Policy defines the rules and initiatives applied to resources (e.g., allowed VM SKUs), but it does not display a compliance score or specific failing controls against a benchmark. Option C is wrong because Secure Score aggregates security posture based on security recommendations, but it is not tied to a specific compliance standard like MCSB and does not show per-control compliance status. Option D is wrong because Workload Protections focuses on advanced threat detection and protection for workloads (e.g., servers, databases), not on compliance assessment against benchmarks.

271
Multi-Selecteasy

Which TWO of the following are valid authentication methods in Microsoft Entra ID?

Select 2 answers
A.Temporary Access Pass
B.App registration
C.FIDO2 security key
D.Managed identity
E.Azure AD Connect
AnswersA, C

Temporary Access Pass is a time-limited, admin-issued passcode that allows a user to sign in and complete first-time onboarding, such as registering phishing-resistant credentials like FIDO2 keys or Microsoft Authenticator. It is a first-class authentication method in Microsoft Entra ID, designed as a secure temporary credential that can be used once or for a short validity window, and it supports both primary and secondary authentication scenarios, including passwordless recovery when a user loses their existing methods.

Why this answer

Temporary Access Pass (TAP) is a valid authentication method in Microsoft Entra ID that allows users to register passwordless methods (like FIDO2 or Microsoft Authenticator) by providing a time-limited passcode. It is designed for scenarios where users have forgotten their credentials or need to onboard new devices without a password. TAP is configured via the Authentication methods policy in Entra ID and supports both one-time use and configurable lifetimes.

Exam trap

The trap here is that candidates confuse identity infrastructure tools (like Azure AD Connect) or workload identities (like Managed identities) with user authentication methods, leading them to select options that are related to identity but not valid for user sign-in.

272
MCQeasy

You need to protect Azure VMs from ransomware by ensuring that encrypted file systems cannot be read by attackers. Which solution should you implement?

A.Apply network security groups (NSGs) to block unauthorized access.
B.Configure Azure Backup for the VMs.
C.Enable Azure Disk Encryption on the VMs.
D.Enable Microsoft Defender for Cloud on the subscription.
AnswerC

Azure Disk Encryption (ADE) uses BitLocker on Windows and DM-Crypt on Linux to encrypt every OS and data disk at rest, so ransomware cannot read or recover plaintext data even if it gains storage-level access. ADE stores disk encryption keys in Azure Key Vault, optionally wrapped by a key encryption key (KEK), enabling dual encryption and stronger key governance. This directly ensures the VM disks are unreadable without proper key access, satisfying the core protection requirement.

Why this answer

Azure Disk Encryption uses BitLocker (Windows) or DM-Crypt (Linux) to encrypt the OS and data disks of Azure VMs at rest. This ensures that even if an attacker gains access to the underlying storage or exports the VHD files, the encrypted file system cannot be read without the encryption keys, which are protected by Azure Key Vault. This directly addresses the requirement to prevent attackers from reading encrypted file systems.

Exam trap

The trap here is that candidates often confuse network-level controls (NSGs) or backup solutions with data-at-rest encryption, or they assume that a security monitoring tool like Defender for Cloud provides encryption, when in fact only a dedicated disk encryption solution like Azure Disk Encryption protects the file system from being read by an attacker with access to the storage.

How to eliminate wrong answers

Option A is wrong because NSGs filter network traffic at the subnet or NIC level and do not protect data at rest on the VM's disks; they cannot prevent an attacker from reading the file system if they gain administrative access or access the underlying storage. Option B is wrong because Azure Backup creates recovery point copies of VM data but does not encrypt the live file system; it protects against data loss, not against unauthorized reading of the current encrypted file system. Option D is wrong because Microsoft Defender for Cloud provides threat detection, security posture management, and recommendations but does not itself encrypt disks; it may recommend enabling encryption but does not implement the encryption required to protect file systems from being read by attackers.

273
MCQeasy

Your company is using Microsoft Sentinel to monitor security events. You need to ensure that all incidents generated in Sentinel are automatically sent to a third-party ticketing system via a webhook. Which Sentinel feature should you configure?

A.Create an automation rule that runs a playbook when an incident is created.
B.Use a watchlist to map incidents to ticketing system IDs.
C.Create a workbook that exports incidents to the ticketing system.
D.Configure a data connector to the ticketing system.
AnswerA

Automation rules in Microsoft Sentinel are condition-based triggers that fire on incident creation, and they can invoke a playbook (an Azure Logic Apps workflow). The playbook can use an HTTP or webhook action to create a ticket in your external ticketing system, making this the correct outbound integration path. Unlike the other options, this is an active, automated mechanism that sends data out of Sentinel.

Why this answer

Automation rules in Microsoft Sentinel can trigger a playbook (an Azure Logic Apps workflow) when an incident is created. The playbook can then use an HTTP action to call a webhook endpoint on the third-party ticketing system, sending the incident data automatically. This is the native, built-in mechanism for outbound event-driven integration with external systems.

Exam trap

The trap here is confusing inbound data ingestion (data connectors) with outbound event-driven automation (automation rules + playbooks), leading candidates to incorrectly select a data connector for exporting incidents.

How to eliminate wrong answers

Option B is wrong because watchlists are used for storing reference data (e.g., IP addresses, usernames) to correlate with events during analytics rule processing, not for triggering outbound webhook calls to ticketing systems. Option C is wrong because workbooks are visualization and reporting tools that display data from Log Analytics workspaces; they cannot execute automated actions like sending HTTP requests to external systems. Option D is wrong because data connectors are designed to ingest data into Sentinel from external sources (e.g., security appliances, cloud platforms), not to export incidents outbound to a ticketing system.

274
MCQhard

An analyst investigates a Defender for Cloud alert for suspicious process execution on a VM. Which next step best preserves evidence while enabling deeper endpoint investigation?

A.Delete the VM immediately to stop the process
B.Pivot to Microsoft Defender for Endpoint device timeline and isolate the device if containment is required
C.Disable all analytics rules in Sentinel
D.Rotate every subscription key before reviewing the process tree
AnswerB

Defender for Endpoint's device timeline preserves the forensic process tree and related events while allowing deeper investigation, and device isolation contains the threat without destroying volatile evidence. This satisfies the requirement to preserve evidence and enable endpoint-level analysis before remediation.

Why this answer

Pivoting to the Microsoft Defender for Endpoint device timeline allows the analyst to investigate the suspicious process execution in a forensically sound manner without disrupting the live environment. Isolating the device from the network, if needed, contains the threat while preserving volatile evidence such as running processes, memory, and registry state. This approach aligns with incident response best practices and leverages Defender for Endpoint's deep endpoint visibility.

Exam trap

The trap here is that candidates may confuse immediate containment with evidence preservation, mistakenly choosing to delete or disable resources instead of using the platform's native investigation and isolation capabilities.

How to eliminate wrong answers

Option A is wrong because deleting the VM immediately destroys all volatile evidence (memory, running processes, network connections) and prevents any forensic analysis or root cause determination. Option C is wrong because disabling analytics rules in Microsoft Sentinel does not preserve evidence or aid investigation; it only stops future alert generation, potentially allowing the threat to propagate undetected. Option D is wrong because rotating subscription keys is a credential hygiene action unrelated to endpoint investigation and does not preserve process execution evidence or enable containment.

275
MCQmedium

You are the Azure Security Engineer for a healthcare company that stores patient imaging data in an Azure Storage account. The compliance team requires that all data written to the account be encrypted with a customer-managed key stored in Azure Key Vault, and that this key be automatically rotated every 12 months. You configure a customer-managed key for the storage account. Which additional configuration must you apply to meet the automatic rotation requirement?

A.Create an Azure Automation runbook that updates the storage account encryption key version every 12 months.
B.Enable Azure Defender for Storage and set the key rotation period in the Defender for Cloud security policy.
C.In Azure Key Vault, configure a key rotation policy on the customer-managed key that rotates the key every 12 months.
D.In the storage account's encryption settings, set the key rotation interval to 12 months and enable auto-rotation.
AnswerC

Azure Key Vault supports key rotation policies that automatically generate a new key version on a schedule. When the storage account references the key without a specific version, it will automatically use the latest version, so rotating the key in Key Vault every 12 months meets the requirement. This is the supported and recommended approach for automatic key rotation.

Why this answer

Customer-managed keys for Azure Storage encryption are stored in Azure Key Vault. To automatically rotate the key, you configure a rotation policy on the key itself in Key Vault. The storage account should reference the key without a specific version so that it always uses the latest key version.

This native integration ensures seamless rotation without manual intervention or custom scripting.

Exam trap

The trap here is assuming that Azure Storage provides a built-in key rotation interval setting, when rotation must actually be configured on the Key Vault key itself.

276
Multi-Selectmedium

Which TWO actions should you take to secure a virtual network in Azure? (Choose two.)

Select 2 answers
A.Apply network security groups (NSGs) to subnets.
B.Configure Azure DNS zones.
C.Deploy Azure Bastion for VM access.
D.Implement Azure Firewall for perimeter control.
E.Set up Azure Monitor alerts.
AnswersA, D

Network security groups (NSGs) are a core, stateful filtering layer in Azure that enforce allow/deny rules based on source/destination IP, port, and protocol. When applied to subnets, they segment traffic between workloads inside a VNet and control traffic entering or leaving the subnet from the internet or peered networks. NSGs also provide default rules and support service tags, making them a fundamental security action for any VNet.

Why this answer

Network security groups (NSGs) are a fundamental Azure security control that filter traffic at the subnet or network interface level. Applying an NSG to a subnet allows you to define inbound and outbound security rules based on source/destination IP, port, and protocol, effectively segmenting and protecting the virtual network from unauthorized access.

Exam trap

The trap here is that candidates often confuse Azure Bastion (a PaaS management service) with a network security control, or think Azure Monitor alerts can actively block traffic, when in fact neither provides traffic filtering or perimeter security.

277
MCQhard

A Sentinel rule using a threat intelligence table fires on stale indicators that expired last week. What should be added to the query?

A.A union with Usage
B.A sort by Description
C.A project-away of ConfidenceScore
D.A filter for active indicators whose expiration time is in the future
AnswerD

The correct query filters the ThreatIntelligenceIndicator table to rows where the indicator's expiration time is later than the current time (ExpirationDateTime > now()) and where the indicator's action status is active, thereby including only indicators that are currently valid and in use. This ensures the rule matches only threat intelligence that is still relevant, avoiding alerts from indicators that have expired or been deactivated. In Sentinel you would typically combine this filter with the TI map data and set the rule's query to evaluate at runtime using now(), so the freshness is automatically enforced.

Why this answer

The rule fires on stale indicators because the query lacks a filter to exclude expired threat intelligence entries. Adding a filter for active indicators whose expiration time is in the future ensures that only current, valid indicators trigger the rule, preventing false positives from outdated data.

Exam trap

The trap here is that candidates may think removing a column (project-away) or sorting data addresses the root cause of stale data, rather than recognizing that a row-level filter is required to exclude expired indicators.

How to eliminate wrong answers

Option A is wrong because a union with Usage would combine data from the Usage table, which tracks billing or resource consumption, not threat intelligence expiration, and does not filter out stale indicators. Option B is wrong because sorting by Description merely reorders results without excluding expired indicators; it does not affect which rows are returned. Option C is wrong because projecting away ConfidenceScore removes a column but does not filter rows; the query would still return stale indicators regardless of confidence score.

278
MCQeasy

Your security team wants to use Microsoft Defender for Cloud's 'Just-In-Time (JIT) VM access' to reduce the attack surface. Which Azure policy must be enabled on the subscription to use JIT?

A.Microsoft Defender for Databases
B.Microsoft Defender for Servers
C.Microsoft Defender for Storage
D.Microsoft Defender for Key Vault
AnswerB

Microsoft Defender for Servers is the only plan that includes Just-in-Time VM access, which locks down inbound management ports by default and lets defenders request temporary, time-bound access through Defender for Cloud. The feature works by automatically configuring and updating NSG rules to allow a specific source IP and port pair for a defined window, then reverting to close the port. This makes Defender for Servers the correct choice for a security team seeking JIT capabilities for their virtual machines.

Why this answer

Just-In-Time (JIT) VM access is a feature of Microsoft Defender for Cloud that requires the Microsoft Defender for Servers plan to be enabled on the subscription. This plan provides the advanced threat protection and access control capabilities, including JIT, which dynamically locks down inbound traffic to VMs and opens ports only when authorized users request access via Azure Policy or the portal.

Exam trap

The trap here is that candidates often confuse the 'Microsoft Defender for Servers' plan with other Defender plans (like Databases or Storage) because they assume any 'Defender' plan can enable JIT, but only the Servers plan provides the necessary VM-level access control and network security group management.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Databases is designed to protect database services (e.g., Azure SQL, Azure Database for PostgreSQL) and does not include JIT VM access functionality. Option C is wrong because Microsoft Defender for Storage protects Azure Blob Storage, Azure Files, and Data Lake Storage from threats, but it has no role in managing VM network access. Option D is wrong because Microsoft Defender for Key Vault provides advanced threat protection for Azure Key Vault, focusing on secrets and key management, not VM network-level just-in-time access.

279
MCQeasy

A company deploys Azure virtual machines in a virtual network. A security policy requires that only Remote Desktop Protocol (RDP) traffic from the corporate VPN's public IP address (203.0.113.0/26) is allowed. All other inbound RDP traffic must be denied. Which configuration should be applied to the network security group (NSG) associated with the VM subnet?

A.Add an inbound rule to allow RDP from the Internet and a deny rule for RDP from the corporate IP.
B.Add an inbound rule to deny RDP from the corporate IP and a default deny all inbound.
C.Add an inbound rule to allow RDP from the corporate IP range, and add a default deny rule for all other inbound RDP traffic.
D.No additional rules are needed because the default NSG rules already deny RDP.
AnswerC

To allow RDP only from the corporate IP range, you must create an inbound NSG rule with priority number lower than any competing deny rule, permitting traffic from that source to TCP port 3389. Then a second inbound rule with a higher priority number (lower precedence) should deny RDP from all other sources, ensuring that any traffic not matching the corporate allow rule is blocked. This pair of rules works with the default DenyAllInbound rule to restrict unauthorized access while preserving the required administrative path.

Why this answer

The requirement is to allow RDP (TCP port 3389) only from the corporate VPN's public IP range (203.0.113.0/26) and deny all other inbound RDP traffic. An NSG processes rules in priority order; by adding an inbound allow rule for the corporate IP range with a high priority (e.g., 100) and relying on the default deny rule (which denies all inbound traffic not explicitly allowed), only RDP from the specified range is permitted. This matches the security policy precisely.

Exam trap

The trap here is that candidates often forget that NSGs have default rules that allow inbound traffic from the virtual network and Azure load balancer, and they mistakenly think a default deny rule already blocks all RDP, when in fact you must explicitly allow the specific source IP and rely on the default deny to block everything else.

How to eliminate wrong answers

Option A is wrong because it allows RDP from the Internet (which violates the policy) and then denies RDP from the corporate IP (which would block the allowed traffic). Option B is wrong because it denies RDP from the corporate IP (the only source that should be allowed) and relies on a default deny all inbound, which would block all RDP traffic entirely. Option D is wrong because the default NSG rules allow inbound RDP from the virtual network and Azure load balancer, but not from the Internet; they do not restrict RDP to a specific public IP range, so additional rules are required.

280
Multi-Selecthard

A Defender for Cloud alert indicates possible credential theft on a VM. Which two response actions are sensible early containment steps?

Select 2 answers
A.Isolate the affected endpoint or restrict network access if business impact allows
B.Delete all Log Analytics workspaces
C.Reset or revoke suspected compromised credentials
D.Disable Microsoft Defender for Endpoint onboarding
AnswersA, C

Isolating the endpoint or restricting its network access severs the attacker's command-and-control and lateral movement paths, containing credential theft before persistence or exfiltration. This preserves forensic evidence on the VM while business impact remains acceptable.

Why this answer

Option A is correct because isolating the affected endpoint (for example, via Microsoft Defender for Endpoint's 'Isolate device' action) or otherwise restricting its network access stops an attacker from moving laterally or exfiltrating data while the investigation proceeds, and it is a standard early containment step when business impact permits. Option C is correct because credential theft means the attacker may hold valid account secrets, so resetting passwords and revoking tokens, sessions, or refresh tokens (for example, via Microsoft Entra ID revoke sessions or password reset) invalidates the stolen credentials and cuts off the attacker's access. Option B is not appropriate because deleting Log Analytics workspaces destroys the very telemetry and audit evidence needed to investigate the alert and would not contain the threat.

Option D is not appropriate because disabling Defender for Endpoint onboarding removes the endpoint detection and response capability that is essential for monitoring, investigating, and remediating the compromised VM.

Exam trap

The trap here is that candidates may confuse 'containment' with 'remediation' and choose to delete workspaces or disable security tools, which are destructive or counterproductive actions, rather than the correct containment step of network isolation.

281
MCQeasy

You are evaluating Microsoft Defender for Cloud's cloud security posture management (CSPM) capabilities. You need to identify misconfigurations across your Azure, AWS, and GCP environments. What should you enable?

A.Ingest logs from AWS and GCP into Microsoft Sentinel.
B.Create Azure Policy assignments for AWS and GCP resources.
C.Deploy Azure Arc on VMs in AWS and GCP.
D.Enable the 'Defender for Cloud' multicloud connector for AWS and GCP.
AnswerD

Microsoft Defender for Cloud provides multicloud CSPM via its connector feature: in the Azure Portal, you enable the AWS connector (using a CloudFormation template and cross-account role) or GCP connector (using a service account) to on-board your entire cloud environments. Once connected, Defender for Cloud continuously pulls resource configuration and workload telemetry using AWS Config/AWS Security Hub and GCP Cloud Asset Inventory, then applies built-in security standards (e.g., CIS, NIST, Azure Security Benchmark) to generate recommendations and compliance scores across AWS, GCP, and Azure. This native multicloud connector also enables advanced threat protection features such as attack path analysis and cloud security explorer, making it the only listed option that fulfills multicloud CSPM.

Why this answer

The Defender for Cloud multicloud connector is specifically designed to ingest security findings and configuration data from AWS and GCP into Microsoft Defender for Cloud's CSPM dashboard. This enables unified visibility and assessment of misconfigurations across Azure, AWS, and GCP environments without requiring agents or log ingestion into Sentinel.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel's log ingestion with Defender for Cloud's CSPM capabilities, assuming that any multicloud security requires a SIEM, when in fact Defender for Cloud's native connector provides the required posture management without Sentinel.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a SIEM/SOAR solution for threat detection and incident response, not a CSPM tool for identifying cloud misconfigurations; ingesting logs into Sentinel does not provide the built-in compliance and posture assessments that Defender for Cloud offers. Option B is wrong because Azure Policy can only enforce rules on Azure resources; it cannot directly manage or evaluate AWS or GCP resources, as those environments do not support Azure Policy assignments. Option C is wrong because Azure Arc extends Azure management to on-premises and multicloud servers, but it does not provide CSPM scanning for cloud-native services like AWS S3 or GCP Cloud Storage; Arc focuses on VM-level management, not cloud-wide posture assessment.

282
MCQhard

A company uses Microsoft Defender for Cloud to manage the security posture of multiple Azure subscriptions. The security team wants to ensure that all subscriptions are covered by the same Microsoft Defender for Cloud policy initiative, but one subscription is not showing compliance data. The subscription is in the same Azure AD tenant and has the same tags. What is the most likely cause?

A.The user does not have Security Admin permissions on the subscription.
B.The subscription does not have any tags applied.
C.The subscription does not have the default policy initiative assigned.
D.The subscription is not registered with the Microsoft.Security resource provider.
AnswerD

For Defender for Cloud to assess a subscription, the Microsoft.Security resource provider must be registered at the subscription level, as this registration is what allows the service to query Azure Resource Manager for resource metadata and configuration. When the provider is unregistered, Defender for Cloud cannot perform any resource discovery, so no security recommendations, regulatory compliance controls, or secure score data are generated for that subscription. Registration is typically performed automatically when a user first opens Defender for Cloud in the portal, but it can also be done programmatically via Azure CLI (`az provider register --namespace Microsoft.Security`) or PowerShell. An unregistered provider explains both the absence of data and why the user perceives that security posture is completely missing.

Why this answer

Microsoft Defender for Cloud relies on the Microsoft.Security resource provider to collect security configurations, apply policy initiatives, and report compliance data. If a subscription is not registered with the Microsoft.Security resource provider, Defender for Cloud cannot evaluate policies or generate compliance results, even if the subscription is in the same tenant and has identical tags. Registering the resource provider is a prerequisite for any Defender for Cloud functionality, including policy assignment and compliance reporting.

Exam trap

The trap here is that candidates often assume missing compliance data is due to permissions (Security Admin) or missing policy assignments, but the root cause is frequently the unregistered Microsoft.Security resource provider, which is a prerequisite that many overlook.

How to eliminate wrong answers

Option A is wrong because Security Admin permissions control who can manage security policies and view alerts, but they do not affect whether the subscription itself can report compliance data; a subscription without the required resource provider will show no compliance data regardless of user permissions. Option B is wrong because tags are metadata used for organizing resources and do not influence policy compliance or the underlying resource provider registration; a subscription without tags will still show compliance data if the policy initiative is assigned and the resource provider is registered. Option C is wrong because while a missing default policy initiative would result in no compliance data for that specific initiative, the question states that all subscriptions should be covered by the same policy initiative, implying it is assigned; the core issue is that the subscription cannot process the policy at all due to the missing resource provider.

283
MCQmedium

Your company uses Microsoft Defender for Cloud's Security Posture Management (CSPM) features. You need to identify resources that are not compliant with the organization's security baseline. What should you do?

A.View the secure score
B.Review the security recommendations
C.Use the regulatory compliance dashboard
D.Use the inventory blade
AnswerC

The regulatory compliance dashboard in Microsoft Defender for Cloud is the correct tool because it provides a continuous, standards-based assessment by mapping Azure Policy initiatives to controls from frameworks such as Azure CIS, PCI DSS, ISO 27001, SOC 2, and even custom standards. It shows a compliance percentage per standard, lets you drill down to non-compliant resources and controls, and tracks compliance history over time. You can select which standards to assess in the compliance policies settings, giving you exactly the detailed compliance status needed.

Why this answer

The regulatory compliance dashboard in Microsoft Defender for Cloud provides a view of how your resources comply with specific security standards and baselines, such as the Microsoft Cloud Security Benchmark (MCSB) or custom regulatory frameworks. By selecting the appropriate compliance standard that matches your organization's security baseline, you can identify resources that are non-compliant with specific controls. This dashboard directly maps security assessments to compliance controls, making it the correct tool for identifying resources not meeting your baseline.

Exam trap

The trap here is that candidates often confuse the secure score or security recommendations with compliance tracking, not realizing that the regulatory compliance dashboard is the dedicated tool for mapping resources to specific baseline controls and standards.

How to eliminate wrong answers

Option A is wrong because the secure score is a numerical summary of your overall security posture based on implemented recommendations, not a detailed view of compliance with a specific baseline. Option B is wrong because security recommendations are actionable steps to improve security, but they do not map directly to a regulatory or custom baseline compliance status. Option D is wrong because the inventory blade lists all resources and their basic security configurations, but it does not provide compliance status against a defined baseline or regulatory standard.

284
MCQmedium

A company is designing a hub-spoke network topology with Azure Firewall in the hub virtual network. Spoke virtual networks are peered to the hub. They want to ensure that all outbound internet traffic from virtual machines in a spoke subnet goes through the Azure Firewall. They have configured a route table on the spoke subnet with a default route (0.0.0.0/0) pointing to the Azure Firewall's private IP address as the next hop. However, traffic is still bypassing the firewall. What is the most likely cause?

A.The Azure Firewall is in a different region than the spoke VNet.
B.The route table is not associated to the spoke subnet.
C.The Azure Firewall does not have the correct network and application rules configured.
D.The spoke VNet has the 'Use remote virtual network gateways' setting disabled.
AnswerB

A user-defined route table only takes effect when it is explicitly associated with a subnet; simply creating a route table and adding a route to the firewall's private IP does nothing otherwise. Without that association, the subnet uses Azure's default system routes, which send traffic between peered VNets directly, bypassing the firewall entirely. This is the classic cause of 'spoke traffic isn't going through the firewall' when the routes appear to be configured correctly.

Why this answer

The most likely cause is that the route table with the default route (0.0.0.0/0) pointing to the Azure Firewall's private IP has not been associated to the spoke subnet. Without this association, the route table is not applied to the subnet's traffic, so the default system route (which directs internet traffic directly to the internet) remains in effect, bypassing the firewall. Associating the route table to the subnet is a required step for user-defined routes (UDRs) to influence traffic flow.

Exam trap

The trap here is that candidates often assume creating a route table and adding a default route is sufficient, overlooking the critical step of associating the route table to the subnet, which is a distinct configuration action in the Azure portal or CLI.

How to eliminate wrong answers

Option A is wrong because Azure Firewall can be in a different region than the spoke VNet and still function correctly; cross-region peering supports traffic routing through the firewall as long as the route table is properly associated. Option C is wrong because network and application rules on the firewall control which traffic is allowed or denied, but they do not affect whether traffic is routed to the firewall in the first place; the routing issue occurs before the firewall inspects packets. Option D is wrong because the 'Use remote virtual network gateways' setting is relevant only for VPN/ExpressRoute gateway transit scenarios, not for routing traffic to an Azure Firewall via a UDR.

285
MCQmedium

A company uses Azure Firewall to filter outbound traffic. They want to ensure that all DNS queries from virtual machines in a spoke VNet are routed through the Azure Firewall for logging and inspection. They have already configured the firewall to use a custom DNS server. Which additional Azure Firewall feature must be enabled to ensure that the VMs use the firewall as a DNS proxy?

A.Enable DNS proxy on the firewall policy
B.Configure a DNS forwarding rule
C.Enable Threat Intelligence DNS logging
D.Create a NAT rule for DNS traffic
AnswerA

Enabling DNS proxy on the Azure Firewall policy is the correct choice because it makes the firewall's private IP address the DNS server for virtual networks. VMs send DNS queries to the firewall, which then forwards them to the configured DNS server, ensuring that all outbound DNS traffic traverses the firewall for inspection and filtering. This gives a single, consistent path for DNS egress and enables FQDN-based rules to be applied to outbound traffic.

Why this answer

Enabling DNS proxy on the Azure Firewall policy allows the firewall to act as a DNS proxy for the virtual machines in the spoke VNet. When DNS proxy is enabled, the firewall listens on port 53 and forwards DNS queries from the VMs to the configured custom DNS server, ensuring all DNS traffic is logged and inspected. This is required even after setting a custom DNS server on the firewall, as the VMs must be configured to use the firewall's private IP address as their DNS server, and the proxy handles the forwarding.

Exam trap

The trap here is that candidates often confuse enabling DNS proxy with simply configuring a custom DNS server on the firewall, or they think that a NAT rule or forwarding rule alone will route DNS traffic through the firewall, but without the DNS proxy feature, the firewall does not listen on port 53 and cannot intercept DNS queries from VMs.

How to eliminate wrong answers

Option B is wrong because configuring a DNS forwarding rule is used to forward specific DNS queries to different DNS servers based on domain names, but it does not enable the firewall to act as a DNS proxy for all VM DNS traffic; the VMs still need to point to the firewall's IP, and the proxy feature must be enabled. Option C is wrong because enabling Threat Intelligence DNS logging only logs DNS queries that match threat intelligence indicators, but it does not route or proxy DNS traffic through the firewall; it is a logging feature, not a routing mechanism. Option D is wrong because creating a NAT rule for DNS traffic would translate the destination IP of DNS queries, but it does not make the firewall a DNS proxy; the VMs would still need to send DNS queries directly to the firewall's IP, and without DNS proxy, the firewall does not listen on port 53 for DNS queries.

286
MCQhard

A Sentinel analyst needs to preserve investigation notes, related entities, and ownership while escalating a case to another analyst. Which object should be updated?

A.A watchlist item
B.A workbook parameter
C.A data connector
D.The Sentinel incident
AnswerD

The Microsoft Sentinel incident is the correct place to preserve investigation notes because incidents have a dedicated comments section and audit history that persist with the case. Each comment is timestamped and attributed to the analyst, creating an immutable, chronological record of observations, hypotheses, and actions taken. This documentation is retained as part of the incident's metadata, is visible to all team members investigating the incident, and can be exported or queried via APIs for compliance or post-incident review. Storing notes on the incident directly ties the documentation to the investigation's lifecycle, ensuring no context is lost when the incident is closed or reopened.

Why this answer

The Sentinel incident object is the correct entity to update because it serves as the central container for investigation notes, related entities, and ownership assignments during case escalation. Updating the incident preserves the full investigation context—including comments, tags, and assigned owner—ensuring seamless handoff between analysts without data loss.

Exam trap

The trap here is that candidates confuse operational artifacts (watchlists, workbooks, connectors) with the incident object that actually holds case-specific metadata, leading them to select a static or non-persistent option instead of the dynamic incident record.

How to eliminate wrong answers

Option A is wrong because a watchlist item is a static collection of data (e.g., IP addresses or hashes) used for correlation and alerting, not for storing investigation notes or ownership metadata. Option B is wrong because a workbook parameter is a configurable input for visualizations and queries, not a persistent object that tracks case ownership or notes. Option C is wrong because a data connector defines the source and ingestion pipeline for log data; it has no role in storing investigation artifacts or managing case ownership.

287
MCQhard

Your organization uses Azure Files shares for user home directories. You need to enforce that users access these shares only from trusted locations (corporate IP ranges) and that all access is logged. Which combination of actions should you take?

A.Use a Private Endpoint for the storage account and configure a service endpoint on the virtual network.
B.Generate a shared access signature (SAS) token that is valid only from corporate IPs and attach it to the file share.
C.Configure a storage account firewall to allow only the corporate IP range, and enable diagnostic settings to send logs to a Log Analytics workspace.
D.Assign Azure AD DS to the storage account and enable Azure AD authentication for Azure Files, then configure conditional access policies.
AnswerC

A storage account firewall is a network-level access control that evaluates the source IP of every request to the Azure Files endpoint, so locking it to the corporate IP range prevents all other clients from reaching the share over SMB or REST. Enabling diagnostic settings exports StorageRead and StorageWrite operation logs to a Log Analytics workspace, giving you a queryable record of access attempts, successful reads, and failures. Together, they enforce the IP restriction and provide the visibility needed to audit and alert on file share activity.

Why this answer

Azure Files supports network security via storage account firewalls, which can restrict access to specific IP ranges. Enabling diagnostic settings allows sending logs (e.g., to a Log Analytics workspace) for auditing. Option C correctly combines both requirements.

Option A is incorrect because Private Endpoints and service endpoints provide network isolation but do not filter by IP source. Option B is incorrect because while a SAS token can include an IP restriction, it is not designed for persistent user access to home directories and complicates management. Option D is incorrect because Azure AD DS and conditional access control authentication but do not enforce network-level IP restrictions.

288
MCQeasy

You need to configure a continuous export of Microsoft Defender for Cloud alerts to a third-party SIEM. Which feature should you use?

A.Create an Azure Logic App to periodically query and send alerts.
B.Use the Defender for Cloud REST API to pull alerts.
C.Configure Azure Monitor agent on all VMs.
D.Use the continuous export feature in Defender for Cloud to stream alerts to an Event Hubs namespace.
AnswerD

The continuous export feature in Microsoft Defender for Cloud natively streams security alerts and recommendations to an Azure Event Hubs namespace, allowing near real-time integration with an external SIEM or log management tool. You configure it under Environment settings for a subscription or a management group, and it supports filtering for specific alert severities or recommendations. Because this is built in, it handles batching, schema, and transport without custom code, making it the correct method for continuous alert export.

Why this answer

The continuous export feature in Microsoft Defender for Cloud is specifically designed to stream security alerts and recommendations to an Event Hubs namespace, which can then be consumed by a third-party SIEM. This native integration eliminates the need for custom polling or scripting, ensuring near real-time data flow with minimal latency.

Exam trap

The trap here is that candidates often confuse the Azure Monitor agent (which collects VM logs) with the continuous export feature (which streams Defender for Cloud alerts), leading them to select Option C despite it being unrelated to alert export.

How to eliminate wrong answers

Option A is wrong because creating a Logic App to periodically query and send alerts introduces unnecessary polling overhead and latency, whereas continuous export provides a push-based streaming model. Option B is wrong because using the Defender for Cloud REST API to pull alerts requires custom code and manual scheduling, lacking the automated, event-driven streaming capability of continuous export. Option C is wrong because the Azure Monitor agent collects OS-level performance and event logs, not Defender for Cloud alerts; it is unrelated to exporting security alerts to a SIEM.

289
MCQmedium

Your company uses Azure Firewall Premium. You need to inspect outbound traffic for malware using signature-based detection. Which feature should you enable?

A.Web categories
B.URL filtering
C.Threat intelligence-based filtering
D.Intrusion Detection and Prevention System (IDPS)
AnswerD

Intrusion Detection and Prevention System (IDPS) in Azure Firewall Premium provides deep packet inspection using a signature-based detection engine. It compares traffic patterns against a large database of known malware and exploit signatures and can alert or block malicious packets in real time. This feature directly inspects packet payloads for signature matches, making it the correct option for inspecting traffic for malware signatures.

Why this answer

Intrusion Detection and Prevention System (IDPS) on Azure Firewall Premium uses signature-based detection to inspect outbound traffic for known malware patterns. It can alert or block traffic matching malicious signatures, making it the correct feature for this requirement.

Exam trap

The trap here is that candidates often confuse Threat intelligence-based filtering (which uses IP/domain reputation) with signature-based malware detection, but IDPS is the only feature that inspects packet payloads for known malware signatures.

How to eliminate wrong answers

Option A is wrong because Web categories classify traffic by content type (e.g., social media, gambling) but do not perform signature-based malware inspection. Option B is wrong because URL filtering allows or denies traffic based on specific URLs or FQDNs, not by inspecting packet payloads for malware signatures. Option C is wrong because Threat intelligence-based filtering uses known malicious IPs, domains, and URLs from Microsoft feeds, not signature-based detection of malware patterns in traffic.

290
MCQmedium

You are designing a privileged identity management strategy for Microsoft Entra ID. You need to ensure that eligible role assignments require approval from a designated group before activation. What configuration is required?

A.Configure the role as eligible and set activation duration
B.Configure a Conditional Access policy with approval control
C.In PIM, configure the role settings to require approval and specify an approver group
D.Create an access review for the role
AnswerC

In PIM, open the role's Activation settings, enable 'Require approval to activate', and specify one or more approvers or an approver group. When an eligible member activates the role, the request is sent to those approvers, who approve or deny via the Microsoft Entra admin center or email notification. The role becomes active only after approval is granted, and you can also require justification as part of the activation request, creating a full audit trail.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure role settings to require approval for activation. By specifying an approver group, you ensure that eligible role assignments cannot be activated without explicit approval from designated members, enforcing a just-in-time (JIT) access control model.

Exam trap

The trap here is that candidates often confuse Conditional Access approval controls (used for session policies) with PIM role activation approval, which is a separate configuration within the role settings in Privileged Identity Management.

How to eliminate wrong answers

Option A is wrong because configuring the role as eligible and setting activation duration only defines the eligibility and time limit for activation, but does not enforce an approval workflow. Option B is wrong because Conditional Access policies with approval control are used for session or sign-in risk scenarios, not for PIM role activation approval. Option D is wrong because creating an access review for the role is a periodic review mechanism to confirm ongoing access, not a real-time approval gate for activation.

291
MCQmedium

A company uses Microsoft Defender for Cloud to monitor security alerts. They receive an alert about a compromised virtual machine and want to automatically execute a playbook that isolates the VM by modifying the network security group. Which Defender for Cloud feature should they use to create this automated response?

A.Workflow automation
B.Security policy
C.Alert suppression
D.Continuous export
AnswerA

Workflow automation is the correct answer because it directly enables an automated response to a security alert. In Microsoft Defender for Cloud, you can create a workflow automation rule that triggers an Azure Logic App when a specific security alert is generated. The Logic App can then execute an automatic isolation action on the affected Virtual Machine, for instance by using an Azure SQL or Resource Manager connector to modify network security groups or apply an Azure Policy. This is the only option that provides a built-in event-driven mechanism to take a protective action without human intervention.

Why this answer

Workflow automation in Microsoft Defender for Cloud allows you to define automated responses to security alerts by triggering Azure Logic Apps. In this scenario, you would create a Logic App that modifies the network security group (NSG) to isolate the compromised VM, and then configure a workflow automation rule to run that Logic App whenever the specific alert is triggered. This provides a no-code, event-driven remediation without manual intervention.

Exam trap

The trap here is that candidates often confuse 'Continuous export' (which sends data to external systems) with 'Workflow automation' (which executes a playbook), assuming any export can trigger a response, but Continuous export only streams data and does not invoke Logic Apps directly.

How to eliminate wrong answers

Option B (Security policy) is wrong because security policies define compliance and configuration requirements (e.g., enforcing encryption or vulnerability assessments), not automated response actions to alerts. Option C (Alert suppression) is wrong because it only hides or dismisses alerts based on rules (e.g., false positives), it does not execute any remediation or playbook. Option D (Continuous export) is wrong because it streams alert data to Event Hubs, Log Analytics, or Azure Monitor for external processing or archiving, but it does not directly trigger a playbook or modify NSGs.

292
MCQmedium

A company uses Azure SQL Database with Transparent Data Encryption (TDE) protected by a customer-managed key (CMK) stored in Azure Key Vault. The Key Vault has a firewall enabled that denies all public network access. The SQL server is a Microsoft service. How can the SQL server be granted access to the key vault to perform TDE operations?

A.Create a private endpoint on the Key Vault for the SQL server
B.Disable the Key Vault firewall
C.Enable the 'Allow trusted Microsoft services to bypass the firewall' setting on the Key Vault
D.Assign the SQL server a system-assigned managed identity and grant it access to the key vault
AnswerC

This setting permits Azure Key Vault to accept requests from Azure SQL Database and other first-party Microsoft services even when the firewall is enabled, without opening the vault to public internet traffic. The service's request originates from Azure's internal infrastructure, and the firewall bypass is combined with strict identity-based authorization via the SQL server's managed identity and access policies. It directly addresses the network-layer restriction for TDE operations while keeping the vault protected against all other external clients.

Why this answer

Azure Key Vault's firewall includes a setting to 'Allow trusted Microsoft services to bypass this firewall.' Azure SQL Database is a trusted Microsoft service, so enabling this setting allows the SQL server to authenticate to Key Vault using its system-assigned managed identity to retrieve the customer-managed key for TDE operations, without needing to disable the firewall or create a private endpoint.

Exam trap

The trap here is that candidates often think a private endpoint is required for PaaS services to access a firewalled Key Vault, but they overlook that Azure SQL Database is a trusted Microsoft service that can bypass the firewall with the appropriate setting, and that a private endpoint would require the SQL server to be network-integrated, which it is not by default.

How to eliminate wrong answers

Option A is wrong because creating a private endpoint on the Key Vault for the SQL server would require the SQL server to be in a virtual network, but Azure SQL Database is a platform-as-a-service (PaaS) resource that does not reside in a customer VNet by default; a private endpoint on Key Vault does not directly grant the SQL server network access. Option B is wrong because disabling the Key Vault firewall would expose the vault to all public network traffic, violating the security requirement to deny all public network access. Option D is wrong because while assigning a system-assigned managed identity and granting it access to the key vault is necessary for authentication and authorization, it does not solve the network connectivity issue caused by the Key Vault firewall blocking all public traffic; the managed identity alone cannot bypass the firewall without the 'Allow trusted Microsoft services' setting.

293
MCQmedium

You manage security for a company using Microsoft Sentinel. The security team wants to automatically assign incidents to the on-call analyst based on the incident severity and the entity involved. They also want to ensure that when an incident is updated, the assignment is re-evaluated. You need to configure this with minimal administrative effort. What should you use?

A.Configure the analytics rule to include the owner in the incident details, and use a scheduled query to update the owner periodically.
B.Create a playbook that uses the Microsoft Sentinel connector to assign the incident, and configure the analytics rule to run the playbook on incident creation.
C.Create an automation rule that triggers on incident creation and update, with conditions based on severity and entity, and an action to assign the incident to the on-call analyst.
D.Use Microsoft Defender for Cloud's workflow automation to assign the incident to the on-call analyst based on severity.
AnswerC

Automation rules in Microsoft Sentinel are designed to handle incident management tasks such as assignment, tagging, and status changes. They can trigger on incident creation and update, and support conditions based on analytics rule name, severity, and entities. This meets the requirement with minimal effort, as no custom logic or playbooks are needed.

Why this answer

Automation rules in Microsoft Sentinel are the native mechanism for incident management, allowing automatic assignment based on conditions such as severity and entities. They can trigger on both incident creation and update, ensuring re-evaluation when incidents change. This approach requires minimal effort because it is built into the platform and does not require custom playbook development.

Exam trap

The trap here is assuming that playbooks are required for any automation in Microsoft Sentinel, when automation rules are specifically designed for incident management tasks like assignment and can trigger on updates.

294
MCQmedium

A company uses Azure AD Conditional Access. They need to restrict access to a cloud application such that users with unmanaged devices can only view data but cannot download it. Which Conditional Access session control should they enable?

A.Sign-in frequency
B.Use Conditional Access App Control
C.Session persistence
D.Application consent policy
AnswerB

Conditional Access App Control, also known as session control, integrates with Microsoft Defender for Cloud Apps by routing the user's session through a reverse proxy in real time. This allows administrators to create session policies that block or restrict specific activities, such as downloading, uploading, copying, or printing files, based on conditions like user risk or location. For the requirement to restrict data downloads, this is the correct and only option among those listed that provides true session-level enforcement.

Why this answer

Conditional Access App Control (Microsoft Defender for Cloud Apps) provides session-level controls that can enforce restrictions like 'Block Download' based on device compliance. This allows administrators to apply policies that restrict data exfiltration from unmanaged devices while still permitting read-only access to the cloud application.

Exam trap

The trap here is confusing session controls (like sign-in frequency or persistence) with app-level data protection controls, leading candidates to pick a control that manages authentication behavior rather than data exfiltration.

How to eliminate wrong answers

Option A is wrong because Sign-in frequency controls how often a user must re-authenticate, not the ability to download data. Option C is wrong because Session persistence controls whether a browser session remains signed in after the browser is closed, not data download restrictions. Option D is wrong because Application consent policy governs which applications can request permissions to access organizational data, not session-level data handling restrictions.

295
MCQeasy

You are analyzing network traffic patterns. You have configured NSG flow logs with Traffic Analytics as shown in the exhibit. You need to identify which virtual machines are communicating with a specific malicious IP address. Which tool should you use to query the flow log data?

A.Azure Storage Explorer
B.Log Analytics workspace using KQL queries
C.Azure Monitor Metrics Explorer
D.Network Watcher Topology
AnswerB

Network Watcher Traffic Analytics enriches NSG flow logs and sends them to a Log Analytics workspace, where you can use KQL to investigate traffic. For example, you can query the AzureNetworkAnalytics_CL table, filter by DestinationIP, group by FlowDirection_s, and summarize total bytes or flow counts to identify traffic to a specific IP. KQL supports time-series analysis, joins, and aggregations, making it the correct and efficient tool for this task.

Why this answer

NSG flow logs with Traffic Analytics are stored in a Log Analytics workspace. To query the flow log data and identify which virtual machines are communicating with a specific malicious IP address, you must use Log Analytics with Kusto Query Language (KQL). KQL allows you to filter, aggregate, and join flow log records based on source/destination IP addresses, ports, and protocols, enabling precise identification of affected VMs.

Exam trap

The trap here is that candidates may confuse NSG flow logs with metrics or topology tools, but only Log Analytics with KQL can perform the ad-hoc, IP-specific queries required to identify malicious communications from the raw flow data.

How to eliminate wrong answers

Option A is wrong because Azure Storage Explorer is a GUI tool for browsing and managing Azure Storage accounts (blobs, files, queues, tables), but it cannot run KQL queries against flow log data stored in a Log Analytics workspace. Option C is wrong because Azure Monitor Metrics Explorer is designed for querying and visualizing numeric time-series metrics (e.g., CPU, network throughput), not for analyzing detailed flow log records with IP addresses and connection states. Option D is wrong because Network Watcher Topology provides a visual representation of the network infrastructure and relationships between resources, but it does not support querying historical flow log data or filtering by specific IP addresses.

296
MCQmedium

Your company deploys a web application in an Azure App Service that needs to securely connect to an Azure SQL Database. You want to avoid exposing the database to the public internet. What is the recommended approach?

A.Configure the SQL database firewall to allow only the App Service outbound IP
B.Use Azure Firewall to block outbound traffic to the database
C.Create an NSG on the database subnet to deny internet traffic
D.Use a private endpoint for the SQL database and VNet integration for the App Service
AnswerD

Using a private endpoint for the SQL database combined with VNet integration for the App Service is the correct approach because it removes the database's public endpoint entirely. The private endpoint assigns the SQL database a private IP address inside your VNet, and VNet Integration routes the App Service's traffic through that VNet, ensuring all communication stays within the Microsoft backbone and never traverses the public internet. After enabling the private endpoint, you can set the SQL server's public network access to 'Disabled', which fully blocks any internet-based access and leaves only the private connection. This provides a secure, stable, and compliant network path for the app-to-database traffic.

Why this answer

It uses Azure Private Endpoint to place the Azure SQL Database on a virtual network, removing its public endpoint, and combines it with VNet integration for the App Service to route traffic through the same VNet. This ensures the database is never exposed to the public internet, meeting the security requirement without relying on IP-based firewall rules that can change or be spoofed.

Exam trap

The trap here is that candidates often assume IP-based firewall rules (Option A) are sufficient for security, but Azure explicitly recommends private endpoints for PaaS services to avoid reliance on dynamic public IPs and to achieve true network isolation.

How to eliminate wrong answers

Option A is wrong because allowing only the App Service outbound IP is unreliable—App Service outbound IPs can change without notice (e.g., during scaling or region failover) and still expose the database to the internet via that IP, which is not truly private. Option B is wrong because Azure Firewall blocks outbound traffic from the App Service to the database, which would prevent the connection entirely rather than securing it. Option C is wrong because an NSG on the database subnet cannot deny internet traffic to the database if the database has a public endpoint; NSGs filter traffic at the subnet level but do not remove the public exposure of the database's FQDN.

297
MCQmedium

You administer an Azure environment with Microsoft Defender for Cloud enabled. A security analyst reports that a suspicious process was executed on a virtual machine, but no alert was found in the portal. You need to ensure that Defender for Cloud can detect and alert on suspicious activities on the VM. What should you do?

A.Configure a custom alert rule in Azure Monitor to trigger on specific process creation events.
B.Enable the Log Analytics agent and configure a data collection rule to forward Security events.
C.Ensure the Microsoft Defender for Servers plan is enabled and that the Azure Monitor Agent is installed on the VM.
D.Enable just-in-time (JIT) VM access to restrict inbound traffic and log connection attempts.
AnswerC

Defender for Servers provides advanced threat detection for VMs, including process-level monitoring and behavioral analytics. The Azure Monitor Agent, when deployed via the plan, installs the required extensions (such as the Defender for Endpoint sensor) to collect and analyze security events. Without this plan and agent, process execution events may not be captured, and alerts will not be generated.

Why this answer

To detect suspicious process execution on a VM, Defender for Cloud must have the Defender for Servers plan enabled, which deploys the Azure Monitor Agent and integrates with Microsoft Defender for Endpoint. This combination provides deep endpoint detection and response capabilities, including process-level monitoring. Other options either use outdated agents or focus on network controls, which do not fulfill the requirement.

Exam trap

The trap here is assuming that any logging agent or custom alert rule will provide the same depth of threat detection as the built-in Defender for Servers plan.

298
MCQmedium

You are configuring a site-to-site VPN connection between your on-premises network and Azure. You need to ensure that traffic between the networks is encrypted and authenticated. Which Azure service should you use?

A.Azure Virtual WAN
B.Azure ExpressRoute
C.Azure Firewall
D.Azure VPN Gateway
AnswerD

Azure VPN Gateway is the specific Azure service designed to create site-to-site (S2S) VPN connections by terminating IPsec/IKE tunnels between on-premises networks and Azure virtual networks. It supports multiple configurations, including active-active instances, BGP routing, and both policy-based and route-based VPN devices, making it the exact fit for the scenario. This is the correct choice because it directly provides the encrypted, secure tunnel required for a site-to-site VPN.

Why this answer

Azure VPN Gateway is the correct service because it provides encrypted and authenticated site-to-site VPN connections using IPsec/IKE protocols. It establishes a secure tunnel between your on-premises VPN device and the Azure VPN gateway, ensuring confidentiality and integrity of traffic across the public internet.

Exam trap

The trap here is that candidates often confuse Azure Virtual WAN (which includes VPN gateway capabilities) with the specific service required, or they assume ExpressRoute provides encryption by default, when in fact it does not encrypt traffic unless additional measures are taken.

How to eliminate wrong answers

Option A is wrong because Azure Virtual WAN is a networking service that aggregates multiple VPN, ExpressRoute, and SD-WAN connections into a unified hub, but it is not the specific service that directly provides the encrypted site-to-site VPN tunnel; it relies on VPN Gateway instances within its hubs. Option B is wrong because Azure ExpressRoute provides a private, dedicated connection to Azure that bypasses the public internet, but it does not natively encrypt traffic; encryption must be added separately (e.g., over ExpressRoute with MACsec or IPsec), and it is not a VPN service. Option C is wrong because Azure Firewall is a managed, cloud-based network security service that filters and inspects traffic, but it does not terminate VPN tunnels or provide site-to-site VPN connectivity; it can be used in conjunction with a VPN gateway for inspection but is not the VPN service itself.

299
MCQeasy

You need to ensure that an Azure Key Vault is accessible only from a specific virtual network and that all operations are logged. What should you configure?

A.Key Vault firewall and virtual network service endpoints, and diagnostic settings
B.Azure RBAC roles and diagnostic settings
C.Soft-delete and purge protection, and diagnostic settings
D.Azure Policy and diagnostic settings
AnswerA

Enabling the Key Vault firewall with an "Allow selected networks" rule and configuring virtual network service endpoints for Microsoft.KeyVault restricts data-plane access to approved virtual networks and specified IP CIDRs. This is the enforcement mechanism that determines whether a request originates from an allowed network before the vault processes it. Adding diagnostic settings then captures audit and authentication logs, giving you the observability needed to verify that only permitted clients reached the vault.

Why this answer

To restrict Key Vault access to a specific virtual network, you must configure the Key Vault firewall and virtual network service endpoints, which allow you to deny all traffic except that originating from the specified VNet/subnet. To log all operations, you must configure diagnostic settings to send audit events (e.g., AuditEvent logs) to a Log Analytics workspace, Storage account, or Event Hub. Option A is correct because it combines both network access control and logging requirements.

Exam trap

The trap here is that candidates often confuse Azure RBAC (which controls permissions) with network-level access controls, or they think Azure Policy alone can enforce VNet restrictions, but Policy only audits or enforces configuration settings—it does not configure the actual firewall rules or diagnostic logging.

How to eliminate wrong answers

Option B is wrong because Azure RBAC roles control data-plane permissions (who can read/write secrets) but do not restrict network-level access to a specific virtual network; they cannot enforce the VNet-only connectivity requirement. Option C is wrong because soft-delete and purge protection are recovery and data retention features that prevent accidental or malicious deletion, not network access restrictions or logging. Option D is wrong because Azure Policy enforces compliance rules (e.g., requiring Key Vaults to have firewall enabled) but does not itself configure the VNet-specific firewall rules or enable diagnostic logging for the Key Vault.

300
MCQeasy

You need to provide secure remote access to Azure virtual machines for administrators without exposing them to the public internet. The solution must use a single entry point and support Azure Active Directory (now Microsoft Entra ID) authentication. Which Azure service should you use?

A.Azure Bastion.
B.Just-in-time (JIT) VM access with Microsoft Defender for Cloud.
C.Azure Front Door with private endpoints.
D.Azure VPN Gateway with point-to-site VPN.
AnswerA

Azure Bastion is a fully managed PaaS service deployed inside the VNet that brokers RDP and SSH sessions over TLS to the Azure portal, so VMs never need a public IP address or inbound internet-facing NSG rules. It authenticates with Entra ID (Azure AD) and can require MFA or Conditional Access before brokering the session, and it connects directly to the VM's private IP over the Bastion subnet. This is the only option here that gives administrators portal-based, client-less remote access while completely removing VMs from internet exposure.

Why this answer

Azure Bastion provides secure, seamless RDP/SSH connectivity to Azure VMs directly from the Azure portal over TLS, without exposing public IP addresses. It uses a single entry point (the Bastion host) and supports Azure AD authentication for login, meeting both requirements.

Exam trap

The trap here is that candidates often confuse Just-in-time VM access (which reduces exposure but still requires public IPs) with a true zero-public-IP solution, or they assume a VPN gateway provides a single entry point when it actually creates multiple client-specific tunnels.

How to eliminate wrong answers

Option B is wrong because Just-in-time (JIT) VM access reduces exposure by opening ports only when needed but still requires the VM to have a public IP address and does not provide a single entry point or native Azure AD authentication for the connection. Option C is wrong because Azure Front Door is a global load balancer and application delivery service, not designed for direct VM remote access; it operates at the HTTP/HTTPS layer and cannot proxy RDP/SSH traffic. Option D is wrong because Azure VPN Gateway with point-to-site VPN creates a tunnel into the virtual network but requires clients to install a VPN client and does not provide a single entry point for all administrators; it also does not natively support Azure AD authentication for the VPN connection itself.

Page 3

Page 4 of 9

Page 5

All pages