Courseiva

Microsoft Azure Security Engineer Associate AZ-500 (AZ-500) — Questions 376–450

617 questions total · 9pages · All types, answers revealed

Page 5

Page 6 of 9

Page 7
376
MCQmedium

Your company deploys Microsoft Sentinel for security operations. You need to configure just-in-time (JIT) access for Azure VMs. Which Azure security feature should you integrate with Sentinel?

A.Microsoft Defender for Cloud
B.Azure Policy
C.Azure Firewall
D.Microsoft Entra Privileged Identity Management
AnswerA

Microsoft Defender for Cloud is the correct choice because it directly provides just-in-time (JIT) VM access, a feature that locks down inbound traffic to virtual machines and opens designated ports only when requested and approved. This integration sends activity data to Microsoft Sentinel for advanced threat detection and response, making it the service that operationalizes JIT for security operations.

Why this answer

Microsoft Defender for Cloud provides the just-in-time (JIT) VM access capability, which can be integrated with Microsoft Sentinel to enable automated threat response. When a security incident is detected in Sentinel, a playbook can trigger Defender for Cloud to lock down or open specific ports (e.g., RDP 3389, SSH 22) for a defined time window, reducing the attack surface. This integration relies on the Defender for Cloud's JIT policy applied at the subscription or VM level, not on external network controls or identity governance.

Exam trap

The trap here is that candidates confuse just-in-time network access (JIT VM access) with just-in-time privileged role activation (PIM), because both use the term 'just-in-time' but operate at completely different layers—network vs. identity.

How to eliminate wrong answers

Option B (Azure Policy) is wrong because Azure Policy enforces compliance rules (e.g., requiring JIT to be enabled) but does not itself grant or manage time-bound network access; it is a governance tool, not an access control mechanism. Option C (Azure Firewall) is wrong because Azure Firewall is a managed network firewall that filters traffic at the perimeter, but JIT access is a VM-level network security group (NSG) feature that dynamically modifies NSG rules, not a firewall rule. Option D (Microsoft Entra Privileged Identity Management) is wrong because PIM manages just-in-time privileged role activation for Azure AD roles and Azure resource roles (e.g., Contributor), not network-level access to VM ports; it controls who can administer resources, not how traffic reaches the VM.

377
Multi-Selectmedium

Which TWO actions can you perform using Microsoft Sentinel's UEBA (User and Entity Behavior Analytics) feature? (Choose two.)

Select 2 answers
A.Block sign-ins from anonymous IP addresses
B.Run KQL queries to find threats across multiple data sources
C.Automatically disable compromised user accounts
D.Detect anomalous behavior based on historical user activity
E.Identify users whose activities are anomalous compared to their peers
AnswersD, E

Microsoft Sentinel UEBA builds a baseline of each user's historical behavior, including sign-in patterns, resource access, and geographic locations, using machine learning. When a user's activity deviates significantly from their own established baseline, UEBA flags it as an anomaly with a risk score. This historical individual baseline is a core mechanism of UEBA, distinguishing it from simple rule-based alerting.

Why this answer

Option D is correct because Microsoft Sentinel UEBA builds behavioral baselines from historical log data (sign-in, Azure Activity, Office 365, etc.) and uses machine learning to surface deviations from a user's own normal activity, such as unusual logon times or data volumes. Option E is correct because UEBA also performs peer-group analysis, comparing each user's actions against similar users in the organization to flag anomalous behavior that would not stand out against the user's own baseline. Options A, B, and C are not UEBA capabilities: blocking anonymous-IP sign-ins is done via Conditional Access or named-location policies, running KQL queries across multiple data sources is core Log Analytics/Sentinel hunting (not UEBA-specific), and automatically disabling compromised accounts requires automated response playbooks (Logic Apps) or identity protection tooling, not UEBA itself.

Exam trap

The trap here is that candidates confuse UEBA's detection-only role with automated response actions (like blocking or disabling accounts), which are separate capabilities in Microsoft Sentinel's automation and playbook features.

378
MCQhard

A company has Azure AD Conditional Access policies that require multi-factor authentication (MFA) for all users accessing sensitive cloud apps. The security team wants to extend this protection by monitoring and controlling user activities within those applications (e.g., preventing data exfiltration during a session). Which Conditional Access session control should they implement?

A.Grant control: Require MFA
B.Session control: Use app enforced restrictions
C.Session control: Sign-in frequency
D.Session control: Conditional Access Application Control
AnswerD

Conditional Access Application Control is the correct session control because it integrates with Microsoft Defender for Cloud Apps to route sessions through a reverse proxy, enabling real-time monitoring and policy enforcement. Administrators can apply granular actions such as blocking downloads, restricting access, or applying data protection policies dynamically based on user and risk context. This provides the centralized, in-session activity monitoring and control that the scenario specifically requires.

Why this answer

Conditional Access Application Control (also known as Microsoft Defender for Cloud Apps session control) allows real-time monitoring and control of user activities within cloud apps, such as blocking downloads or preventing data exfiltration. This session control works by redirecting user traffic through Microsoft Defender for Cloud Apps as a reverse proxy, enabling granular policy enforcement during the session. The requirement specifically asks for monitoring and controlling activities inside the app, which goes beyond just requiring MFA at sign-in.

Exam trap

The trap here is that candidates confuse session controls that manage sign-in frequency or app-enforced restrictions with the more advanced session monitoring and data exfiltration prevention capabilities provided by Conditional Access Application Control, which is the only option that offers real-time in-app activity control.

How to eliminate wrong answers

Option A is wrong because Grant control: Require MFA is an access control that enforces multi-factor authentication at sign-in, but it does not provide any monitoring or control of user activities once the session is established. Option B is wrong because Session control: Use app enforced restrictions relies on the cloud app itself to enforce its own controls (e.g., SharePoint IP-based restrictions), but it does not offer the real-time session monitoring or data exfiltration prevention that Microsoft Defender for Cloud Apps provides. Option C is wrong because Session control: Sign-in frequency controls how often a user must reauthenticate during a session, which is a session lifetime control, not a mechanism to monitor or control in-app activities like downloads or copy-paste.

379
MCQeasy

You need to block outbound internet access from all VMs in a VNet except for specific allowed destinations (e.g., Microsoft updates). You cannot use a third-party NVA. Which Azure service should you use to meet this requirement?

A.Azure Bastion
B.Azure Firewall
C.Network Security Groups (NSGs)
D.Azure Virtual Network NAT
AnswerB

Azure Firewall is a managed, stateful firewall service that acts as a central egress filter in a hub VNet. By creating a route table with a default route (0.0.0.0/0) to the firewall's private IP, all outbound VM traffic can be forced through it. Azure Firewall supports application rules with fully qualified domain names (FQDNs) and network rules with IP/port/protocol, allowing you to deny all outbound internet traffic while selectively permitting only specific FQDNs. This makes it the appropriate solution for the requirement to block outbound internet access except for approved destinations.

Why this answer

Azure Firewall is a managed, cloud-native network security service that can filter outbound traffic from VMs in a VNet based on fully qualified domain names (FQDNs), IP addresses, and port/protocol rules. It supports application rules (e.g., allow *.update.microsoft.com) and network rules, enabling you to block all outbound internet access except for specific allowed destinations like Microsoft Updates. Unlike NSGs, Azure Firewall provides stateful inspection and centralized logging, making it the correct choice for this requirement without a third-party NVA.

Exam trap

The trap here is that candidates often confuse NSGs with a firewall, thinking NSGs can filter outbound traffic by FQDN or application identity, but NSGs only support IP-based rules and cannot inspect application-layer protocols like HTTPS to allow specific destinations such as Microsoft Updates.

How to eliminate wrong answers

Option A is wrong because Azure Bastion is a PaaS service that provides secure RDP/SSH connectivity to VMs inside a VNet without exposing public IPs; it does not filter outbound internet traffic. Option C is wrong because Network Security Groups (NSGs) can filter traffic only at Layer 3 (IP) and Layer 4 (port/protocol), not at the application layer (FQDN), and they cannot selectively allow outbound traffic to specific destinations like Microsoft Updates while blocking all other internet access. Option D is wrong because Azure Virtual Network NAT (VNet NAT) provides outbound connectivity with source network address translation but does not include any filtering or firewall capabilities to block or allow specific destinations.

380
MCQhard

A company plans to enable Azure Disk Encryption (ADE) on their Windows virtual machines. They will use a Key Encryption Key (KEK) stored in Azure Key Vault. What additional configuration must be made in the Key Vault to allow the Azure platform to access the KEK for encrypting the VM disks?

A.Grant the Azure Disk Encryption service principal 'Reader' role on the key vault.
B.Set the key vault's 'enabledForDiskEncryption' property to true.
C.Grant the virtual machine's managed identity 'Contributor' role on the key vault.
D.Configure soft-delete and purge protection on the key vault.
AnswerB

The 'enabledForDiskEncryption' boolean property on the key vault is a specific vault-level flag that tells Azure's compute platform that the vault is allowed to be used by the Azure Disk Encryption service. When set to true, it grants the ADE service (which runs as part of the Microsoft.Compute resource provider) the necessary access to read secrets and use keys wrapped in the vault during the encryption workflow. This is the standard prerequisite because neither a user-assigned identity nor a service principal with RBAC on the vault alone can suffice without this setting.

Why this answer

Azure Disk Encryption requires the key vault's 'enabledForDiskEncryption' property to be set to true. This property explicitly authorizes the Azure platform (specifically the Azure Disk Encryption service) to access the Key Encryption Key (KEK) stored in the vault for encrypting VM disks. Without this flag, the platform cannot retrieve the KEK, even if other permissions exist.

Exam trap

The trap here is that candidates often confuse the 'enabledForDiskEncryption' property with RBAC roles or managed identity permissions, assuming that granting a role to the VM or service principal is sufficient, when in fact the platform requires this specific vault-level flag to be enabled.

How to eliminate wrong answers

Option A is wrong because granting the Azure Disk Encryption service principal the 'Reader' role on the key vault is unnecessary; the platform uses the 'enabledForDiskEncryption' property, not an RBAC role, to authorize access. Option C is wrong because granting the VM's managed identity 'Contributor' role on the key vault is not required; ADE does not use the VM's identity to access the KEK—it uses the platform's identity authorized by the vault property. Option D is wrong because soft-delete and purge protection are important for recovery and compliance but are not required for the platform to access the KEK during encryption; they are separate prerequisites for some scenarios but not the specific configuration needed here.

381
MCQhard

A security operations team uses Microsoft Sentinel. They have created a playbook that sends an email notification to the security team when a high-severity incident is created by a specific analytics rule named 'CriticalRDPAccess'. They want the playbook to trigger automatically only when the incident has severity 'High' AND the incident was created by the rule named 'CriticalRDPAccess'. Which automation rule configuration should they use?

A.Condition: Incident severity equals High; AND Incident rule name contains 'CriticalRDPAccess'. Action: Run playbook.
B.Condition: Incident severity equals High; OR Incident rule name equals 'CriticalRDPAccess'. Action: Run playbook.
C.Condition: Incident severity equals High; AND Incident rule name equals 'CriticalRDPAccess'. Action: Run playbook.
D.Condition: Incident severity in ['High', 'Critical']; AND Incident rule name equals 'CriticalRDPAccess'. Action: Run playbook.
AnswerC

This condition is correct because it uses `AND` to combine two precise constraints: the incident severity must be literally 'High', and the rule name must exactly equal 'CriticalRDPAccess' using the `equals` operator. This ensures that only High severity incidents generated by the specific analytics rule named CriticalRDPAccess will run the playbook, eliminating false positives from similarly named rules and other severity levels. The use of exact match is aligned with the Microsoft Sentinel documentation for automation rules.

Why this answer

The automation rule must use the AND operator to require both conditions—incident severity equals 'High' AND incident rule name equals 'CriticalRDPAccess'—to trigger the playbook. This ensures the playbook runs only when both criteria are met, matching the requirement exactly. Using 'contains' instead of 'equals' (as in Option A) would incorrectly match rules with 'CriticalRDPAccess' as a substring, potentially triggering on unintended rules.

Exam trap

The trap here is that candidates may confuse 'contains' with 'equals' for rule name matching, or incorrectly use OR instead of AND, leading to unintended playbook triggers for similar rule names or unrelated high-severity incidents.

How to eliminate wrong answers

Option A is wrong because 'Incident rule name contains' uses a substring match, which would trigger the playbook for any rule whose name includes 'CriticalRDPAccess' (e.g., 'CriticalRDPAccessV2'), not just the exact rule name. Option B is wrong because the OR operator means the playbook would trigger if either condition is true—e.g., any high-severity incident or any incident from the rule—violating the requirement for both conditions to be true. Option D is wrong because it includes 'Critical' in the severity list, which would trigger the playbook for critical-severity incidents as well, not just high-severity incidents as specified.

382
MCQeasy

A company uses Microsoft Defender for Cloud to manage the security posture of their Azure workloads. The compliance officer needs to generate a report that shows the current compliance status against the SOC 2 standard, including the pass/fail status of each control. Which feature in Defender for Cloud should they use?

A.Regulatory compliance dashboard
B.Inventory
C.Secure Score
D.Workbooks
AnswerA

The Regulatory compliance dashboard is the built-in feature in Microsoft Defender for Cloud that provides a compliance posture view against chosen standards such as SOC 2 Type II. It maps Azure Policy initiative controls to the specific requirements of the standard, showing per-control status, affected resources, and actionable recommendations. This is the direct, purpose-built tool for reporting compliance with a regulatory standard like SOC 2, so it is correct.

Why this answer

The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built, continuously updated view of compliance posture against standards like SOC 2. It maps Azure Policy initiatives to specific controls and shows the pass/fail status for each control, enabling the compliance officer to generate the required report directly.

Exam trap

The trap here is that candidates often confuse the Secure Score (which measures overall security posture) with regulatory compliance reporting, not realizing that Secure Score does not map to specific standard controls like SOC 2.

How to eliminate wrong answers

Option B (Inventory) is wrong because it lists Azure resources and their configurations, but does not evaluate or report compliance against specific regulatory standards like SOC 2. Option C (Secure Score) is wrong because it aggregates security recommendations into a single score based on best practices, not a control-by-control pass/fail report for a specific compliance standard. Option D (Workbooks) is wrong because while Workbooks can create custom visualizations from Azure Monitor data, they are not a pre-built feature for regulatory compliance reporting and require manual configuration to map controls.

383
Multi-Selectmedium

A company uses Defender for Servers Plan 2. Which two capabilities are included compared with a basic posture-only configuration?

Select 2 answers
A.Azure Cost Management budget alerts
B.File integrity monitoring or equivalent advanced server protection capabilities
C.Endpoint detection and response integration through Microsoft Defender for Endpoint
D.Microsoft 365 message trace
AnswersB, C

File integrity monitoring (FIM) is included in Defender for Servers Plan 2 and watches critical system files, registry entries, and configuration settings for unauthorized changes by comparing them to a baseline. When a change is detected, the response is enriched with details about the change and the user or process responsible so security teams can determine if it indicates compromise. This advanced server protection capability satisfies the stated requirement, making the option correct.

Why this answer

Defender for Servers Plan 2 includes advanced server protection capabilities such as file integrity monitoring (FIM), which tracks changes to critical system files and registry keys, and endpoint detection and response (EDR) integration through Microsoft Defender for Endpoint. These capabilities go beyond the basic posture-only configuration, which only provides vulnerability assessment and security recommendations without real-time threat detection or file change monitoring.

Exam trap

The trap here is that candidates often confuse basic posture-only features (like vulnerability assessment and secure score) with advanced capabilities like FIM and EDR, assuming all Defender for Servers tiers include endpoint detection, when only Plan 2 adds these specific protections.

384
MCQmedium

A company has an Azure SQL Database that contains sensitive financial data. They want to audit all successful and failed login attempts for the database. What should they configure?

A.Azure SQL Database auditing
B.SQL Vulnerability Assessment
C.Microsoft Defender for Cloud alerts
D.Azure AD sign-in logs
AnswerA

Azure SQL Database auditing records both failed and successful login attempts to the SQL database, along with all database events such as INSERT, UPDATE, and DELETE operations. It writes the audit logs to an Azure Storage account, Log Analytics workspace, or Event Hub, giving a complete, queryable audit trail of who accessed the database and what actions they performed. This makes it the correct service for detecting and investigating sensitive-data access or brute-force login attempts.

Why this answer

Azure SQL Database auditing is the correct configuration because it captures both successful and failed login attempts (authentication events) at the database level. Auditing writes these events to an audit log destination (such as Azure Storage, Log Analytics, or Event Hubs), enabling detailed forensic analysis of access patterns. This directly meets the requirement to audit all login attempts for the sensitive financial database.

Exam trap

The trap here is that candidates often confuse Azure AD sign-in logs (which track Azure AD authentication) with SQL Database login auditing, failing to realize that SQL Database auditing is the only feature that captures all authentication attempts at the database engine level, including SQL authentication and contained database users.

How to eliminate wrong answers

Option B is wrong because SQL Vulnerability Assessment is a service that scans for potential security misconfigurations and vulnerabilities in the database, not a tool for capturing login audit events. Option C is wrong because Microsoft Defender for Cloud alerts provide security incident notifications based on threat detection, but they do not natively log every successful or failed login attempt for auditing purposes. Option D is wrong because Azure AD sign-in logs track authentication to Azure AD itself, not to the Azure SQL Database; SQL Database authentication events are not recorded in Azure AD sign-in logs unless Azure AD authentication is used and the logs are specifically configured to capture them, but even then, they do not cover all SQL-level login attempts (e.g., SQL authentication).

385
MCQhard

Your organization has multiple Azure subscriptions and uses Microsoft Defender for Cloud. You need to ensure that all subscriptions have a consistent security policy applied. You create a management group containing all subscriptions. What should you do next to assign a Defender for Cloud initiative to all subscriptions?

A.Use Azure Blueprints to define the initiative and assign it to the management group.
B.Assign the initiative as an Azure Policy at the management group scope.
C.Create a custom RBAC role that includes the initiative and assign it to the management group.
D.Assign the initiative to each subscription individually using the Defender for Cloud interface.
AnswerB

Correct: Policy assignment at management group scope applies to all subscriptions under it.

Why this answer

Assigning the initiative as an Azure Policy at the management group scope is the correct approach because Azure Policy can be applied at the management group, subscription, or resource group level, and it will be inherited by all child subscriptions. This ensures a consistent security policy across all subscriptions without manual per-subscription configuration. Microsoft Defender for Cloud uses Azure Policy initiatives (such as the Microsoft Cloud Security Benchmark) to enforce security controls, and assigning at the management group scope is the most efficient method for bulk compliance.

Exam trap

The trap here is that candidates often confuse Azure Blueprints with Azure Policy inheritance, thinking Blueprints can apply policies across a management group hierarchy, when in fact Blueprints require per-subscription assignment and do not support automatic inheritance like Azure Policy does.

How to eliminate wrong answers

Option A is wrong because Azure Blueprints are used for deploying repeatable sets of Azure resources and policies, but they require explicit assignment to each subscription and do not automatically inherit down the management group hierarchy like Azure Policy does. Option C is wrong because RBAC roles control permissions to Azure resources, not the assignment of policy initiatives; a custom RBAC role cannot assign or enforce a Defender for Cloud initiative. Option D is wrong because assigning the initiative to each subscription individually is inefficient and error-prone, and it does not leverage the management group inheritance that Azure Policy provides for consistent application.

386
MCQmedium

A company uses Azure SQL Database and wants to protect sensitive data (e.g., credit card numbers) from database administrators. They require that the data is encrypted at rest and in transit, and only a client application using a specific driver can decrypt it. Which technology should they implement?

A.Transparent Data Encryption (TDE)
B.Always Encrypted
C.Dynamic Data Masking (DDM)
D.Row-Level Security (RLS)
AnswerB

Always Encrypted encrypts sensitive columns at the client side, ensuring that the data is never exposed in plaintext to the server or DBAs. Only the client application with the column master key can decrypt the data.

Why this answer

Always Encrypted is the correct choice because it ensures that sensitive data (e.g., credit card numbers) is encrypted both at rest and in transit, and the encryption keys are never exposed to the database engine. Only a client application using the Always Encrypted-enabled driver (e.g., ADO.NET with Column Encryption Setting=enabled) can decrypt the data, protecting it from database administrators or any unauthorized access to the database server.

Exam trap

The trap here is that candidates often confuse Transparent Data Encryption (TDE) with Always Encrypted because both involve encryption, but TDE does not protect data from database administrators or encrypt data in transit, which is the core requirement in this scenario.

How to eliminate wrong answers

Option A is wrong because Transparent Data Encryption (TDE) encrypts data at rest but does not protect data in transit, and the database engine has access to the encryption keys, so DBAs can still see plaintext data. Option C is wrong because Dynamic Data Masking (DDM) only obfuscates data at query results for unauthorized users, but the underlying data remains unencrypted in storage and in transit, and DBAs can bypass masking. Option D is wrong because Row-Level Security (RLS) controls access to rows based on user context but does not encrypt data at rest or in transit, and DBAs with elevated permissions can still read all data.

387
MCQmedium

Your company uses Microsoft Sentinel to monitor security events. You need to detect brute-force attacks against Azure VMs that are not yet onboarded to Sentinel. What should you do?

A.Use the Office 365 connector to collect sign-in logs.
B.Use the Windows Security Events connector via Azure Monitor Agent.
C.Use the Common Event Format connector to forward syslog.
D.Use the Azure Activity connector to collect sign-in logs.
AnswerB

The Windows Security Events connector using the Azure Monitor Agent (AMA) is the correct choice because it collects Windows Event Log entries, including security events such as successful and failed logon attempts (Event IDs 4624, 4625) from Azure VMs. AMA is configured with a data collection rule (DCR) that specifies which event IDs to send to the Log Analytics workspace where Microsoft Sentinel can analyze them. This is exactly the native, supported path for OS-level sign-in monitoring on Windows virtual machines.

Why this answer

The Windows Security Events connector via Azure Monitor Agent can collect security event logs from Azure VMs, including failed logon attempts that indicate brute-force attacks. Since the VMs are not yet onboarded to Sentinel, this connector allows you to ingest their existing Windows Event Logs (specifically Event ID 4625 for failed logons) directly into Sentinel for detection and alerting.

Exam trap

The trap here is that candidates often confuse the Azure Activity connector (which logs control-plane operations) with VM-level sign-in logs, mistakenly thinking it captures authentication events, when it only records resource management activities like VM start/stop.

How to eliminate wrong answers

Option A is wrong because the Office 365 connector collects sign-in logs from Microsoft 365 services, not from Azure VMs, and cannot capture local authentication attempts on the VMs. Option C is wrong because the Common Event Format connector is designed to ingest syslog data from on-premises or third-party appliances, not from Azure VMs that generate Windows Security Events. Option D is wrong because the Azure Activity connector collects subscription-level operational logs (e.g., resource creation, policy changes), not VM-level sign-in or authentication events.

388
Multi-Selectmedium

Which two actions should you take to secure Azure Storage accounts against data exfiltration?

Select 2 answers
A.Use Azure Private Endpoints for storage accounts.
B.Enable shared access key authentication.
C.Configure firewall and virtual network service endpoints.
D.Enable soft delete for blobs.
E.Configure CORS rules to allow all origins.
AnswersA, C

A private endpoint grants the storage account a private IP address within your virtual network, so clients connect directly to that IP and all traffic is encapsulated within the Microsoft backbone, never traversing the public internet. This lets you block all public access to the storage account, eliminating the network path an attacker could use to exfiltrate data. It is therefore a core boundary control for preventing data exfiltration.

Why this answer

Correct: A and C. Firewall and virtual network service endpoints restrict network access, and private endpoints provide secure connectivity. Option B (shared access keys) does not prevent exfiltration.

Option D (soft delete) helps recovery but not prevention. Option E (CORS) controls cross-origin requests, not exfiltration.

389
MCQeasy

You have an Azure virtual machine that hosts a web application on port 443 and a management interface on port 8443. You need to allow inbound HTTPS traffic from the internet to port 443, and allow inbound traffic on port 8443 only from the company's office public IP range (203.0.113.0/24). You want to use a managed service that provides basic DDoS protection at no additional cost. What should you use?

A.Azure Application Gateway with WAF
B.Azure Front Door
C.Azure Firewall
D.Network Security Group (NSG)
AnswerD

An NSG can be associated with the VM's subnet or network interface. You can create rules to allow inbound HTTPS on port 443 from any source, and allow inbound on port 8443 only from the office IP range. NSGs are free and the default DDoS Protection Basic is included at no additional cost.

Why this answer

A Network Security Group (NSG) is the correct choice because it is a free, managed Azure service that provides basic DDoS protection at no additional cost. NSGs allow you to define inbound security rules to permit HTTPS traffic (port 443) from any source and restrict management traffic (port 8443) to a specific public IP range (203.113.0.0/24). This meets all requirements without incurring extra charges for advanced services.

Exam trap

The trap here is that candidates often over-engineer the solution by choosing a paid, advanced service (like Application Gateway or Azure Firewall) when a simple, free NSG with basic DDoS protection fully satisfies the requirements, especially since the question explicitly states 'at no additional cost'.

How to eliminate wrong answers

Option A is wrong because Azure Application Gateway with WAF is a layer-7 load balancer that incurs additional cost and does not provide basic DDoS protection at no extra cost; its WAF SKU is billed separately. Option B is wrong because Azure Front Door is a global layer-7 CDN and load balancer that also has additional cost and is not a free managed service for basic DDoS protection. Option C is wrong because Azure Firewall is a paid, stateful firewall service that provides advanced filtering but is not free and does not include basic DDoS protection as a built-in feature at no cost.

390
MCQeasy

You need to ensure that Azure SQL Database automatically detects and alerts on potential SQL injection attacks. Which Microsoft Defender for Cloud plan should you enable?

A.Microsoft Defender for SQL
B.Microsoft Defender for Storage
C.Microsoft Defender for Cloud (free tier)
D.Microsoft Defender for App Service
AnswerA

Microsoft Defender for SQL is the security plan that specifically protects Azure SQL Database, SQL Managed Instance, and Azure Synapse SQL. When enabled, it automatically monitors SQL audit logs for suspicious activities such as SQL injection, brute-force login attempts, and anomalous data exfiltration, generating security alerts in Microsoft Defender for Cloud. This is the direct service needed to satisfy the requirement for automatic threat detection on Azure SQL Database.

Why this answer

Microsoft Defender for SQL includes advanced SQL security features such as Vulnerability Assessment, Advanced Threat Protection, and Data Discovery & Classification. Specifically, its Advanced Threat Protection capability uses machine learning models to detect anomalous database activities, including SQL injection attempts, and can trigger alerts or automated responses. Enabling this plan on your Azure SQL Database ensures that potential SQL injection attacks are automatically detected and alerted.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud's free tier with the paid plans, assuming basic threat detection is included, or they mistakenly think Defender for App Service covers database-level threats, when in fact only Defender for SQL provides the specific SQL injection detection for Azure SQL Database.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Storage is designed to detect threats like malware uploads, anomalous access patterns, and data exfiltration in Azure Blob Storage, Azure Files, and Azure Data Lake Storage, not SQL injection attacks against Azure SQL Database. Option C is wrong because the free tier of Microsoft Defender for Cloud provides only basic security assessments and recommendations without the advanced threat detection capabilities, such as SQL injection alerting, which require a paid plan. Option D is wrong because Microsoft Defender for App Service protects web applications running on Azure App Service from threats like DDoS, brute force, and web application attacks, but it does not directly monitor or alert on SQL injection attacks targeting Azure SQL Database.

391
MCQmedium

You have an Azure subscription with a virtual network (VNet1) that hosts a SQL Managed Instance. You need to connect from an on-premises application to the SQL Managed Instance using a private IP address, with minimal latency and without traversing the public internet. The on-premises network has a high-speed ExpressRoute connection to Microsoft. What should you configure?

A.Connect the on-premises network to Azure via ExpressRoute private peering and ensure the SQL Managed Instance subnet is reachable.
B.Configure a public endpoint on the SQL Managed Instance and allow the on-premises public IP.
C.Use Azure Private Link Service and connect via a VPN.
D.Create a site-to-site VPN connection and enable forced tunneling.
AnswerA

ExpressRoute private peering establishes a dedicated, private Layer 3 connection between your on-premises network and Azure, bypassing the public internet entirely. SQL Managed Instance is deployed into a dedicated subnet within your Azure VNet, so once that subnet is reachable via ExpressRoute (through BGP route exchange or appropriate routing), on-premises clients can directly connect to the instance's private IP address. This yields low latency, high throughput, and enterprise-grade reliability, and it does not require exposing a public endpoint or relying on a VPN tunnel.

Why this answer

ExpressRoute private peering establishes a Layer 3 connection between on-premises and Azure, ensuring traffic to the SQL Managed Instance subnet traverses the Microsoft backbone network without touching the public internet. This provides the lowest latency and highest security for private IP connectivity, as the managed instance's private IP is directly routable over the ExpressRoute circuit.

Exam trap

The trap here is that candidates often confuse ExpressRoute private peering with Microsoft peering or assume that a VPN with forced tunneling is sufficient, but forced tunneling only ensures outbound traffic goes through the VPN, not that inbound traffic avoids the internet, and it still uses the public internet path.

How to eliminate wrong answers

Option B is wrong because configuring a public endpoint on the SQL Managed Instance would expose it to the internet, violating the requirement to avoid traversing the public internet and potentially increasing latency. Option C is wrong because Azure Private Link Service is used for accessing Azure PaaS services over a private endpoint, but SQL Managed Instance already resides in a VNet subnet; using a VPN would introduce additional latency and complexity compared to ExpressRoute private peering. Option D is wrong because a site-to-site VPN connection traverses the public internet (even with forced tunneling), which does not meet the 'without traversing the public internet' requirement and would have higher latency than ExpressRoute private peering.

392
Multi-Selecteasy

You are designing a hub-and-spoke network topology with Azure Firewall in the hub VNet. Which TWO components are essential for routing traffic from spoke VNets through the firewall? (Choose two.)

Select 2 answers
A.Azure Private DNS zones
B.Azure Bastion host in the hub VNet
C.VPN gateway in each spoke VNet
D.VNet peering between spoke and hub VNets
E.Route tables with default route to Azure Firewall private IP
AnswersD, E

VNet peering is the foundational connectivity mechanism in a hub-spoke topology; each spoke's virtual network is peered to the hub's virtual network to create a low-latency, high-bandwidth link over the Microsoft backbone. Peering is non-transitive, so spokes cannot communicate directly with each other unless they are both peered to the hub and the hub's route tables forward traffic between them. When combined with user-defined routes and a network virtual appliance like Azure Firewall, peering enables controlled east-west and hub-originated traffic without a VPN gateway.

Why this answer

Option D is correct because VNet peering between each spoke and the hub VNet is the foundational connectivity that allows traffic to flow from spokes to the hub where Azure Firewall resides; without peering (or another connectivity method), spoke traffic cannot reach the firewall at all. Option E is correct because even with peering, Azure's default system routes would send internet-bound traffic directly out of the spoke, so user-defined routes (UDRs) in a route table must set 0.0.0.0/0 (and typically spoke-to-spoke prefixes) with a next hop of the Azure Firewall's private IP to force traffic through the firewall for inspection. Option A is incorrect because Azure Private DNS zones provide name resolution for private endpoints and are unrelated to traffic routing through a firewall.

Option B is incorrect because Azure Bastion provides secure RDP/SSH access to VMs and does not influence packet routing between VNets. Option C is incorrect because a VPN gateway in each spoke is not required for hub-and-spoke firewall routing; VNet peering is the standard mechanism, and gateways are only needed for hybrid/on-premises connectivity, typically deployed in the hub.

Exam trap

The trap here is that candidates often assume a VPN gateway or other gateway is required for routing traffic through a firewall in a hub-and-spoke topology, but Azure Firewall works with VNet peering and UDRs alone, without any gateway in the spoke.

393
MCQhard

Your company uses Microsoft Defender for Cloud to protect Azure resources. You notice that some Azure VMs are not showing any security recommendations. You verify that the VMs are running and have network connectivity. What is the most likely cause?

A.The Log Analytics agent is not installed on the VMs
B.The VMs are in a resource group that lacks the required Azure RBAC role
C.The VMs have a resource lock preventing policy evaluation
D.The VMs are in the Free tier of Defender for Cloud
AnswerA

Defender for Cloud relies on the Log Analytics agent (Microsoft Monitoring Agent) on each VM to collect telemetry such as installed patches, endpoint protection status, and audit logs; without it, the VM cannot be assessed and often appears as 'Not monitored' or missing data. The agent sends data to a Log Analytics workspace where the security engine evaluates the configuration and generates recommendations. Therefore, the absence of the agent directly explains why Defender for Cloud shows no or incomplete recommendations for these VMs.

Why this answer

Microsoft Defender for Cloud relies on the Log Analytics agent (or Azure Monitor Agent) to collect security-relevant data from Azure VMs, such as configuration settings, event logs, and vulnerability signals. Without this agent installed, Defender for Cloud cannot assess the VM's security posture, and therefore no security recommendations will be generated for that VM, even if the VM is running and has network connectivity.

Exam trap

The trap here is that candidates often assume network connectivity or VM running status is sufficient for Defender for Cloud to generate recommendations, but they overlook the critical dependency on the Log Analytics agent for data collection and policy evaluation.

How to eliminate wrong answers

Option B is wrong because Azure RBAC roles control who can manage resources, not whether Defender for Cloud can collect data from a VM; the agent installation is what enables data collection. Option C is wrong because resource locks prevent accidental deletion or modification of resources but do not block Defender for Cloud's policy evaluation or data collection from the VM. Option D is wrong because the Free tier of Defender for Cloud still provides security recommendations for Azure VMs; the absence of recommendations is not caused by the pricing tier but by missing data collection via the agent.

394
MCQmedium

A company uses Azure SQL Database with Azure Active Directory authentication. To meet compliance requirements, they need to audit all failed login attempts and store the audit logs in a storage account located in a different Azure region for disaster recovery. What should they configure?

A.Enable SQL Auditing and set the destination to a Log Analytics workspace in a different region.
B.Enable SQL Auditing and set the destination to an Event Hub namespace in the same region.
C.Enable SQL Auditing and set the destination to an Azure Storage account in a different region.
D.Enable Advanced Threat Protection for Azure SQL Database and configure email notifications.
AnswerC

Azure SQL Auditing can write audit logs directly to an Azure Storage account, and placing that account in a different region provides geographic separation for disaster recovery. You can select a storage account configured with geo-redundant storage (GRS) or geo-zone-redundant storage (GZRS), so audit .xel files are replicated to a paired region and remain accessible even if the primary SQL database region fails. This durable, long-term storage model satisfies compliance requirements for failed-login auditing and supports immutable retention policies to prevent tampering.

Why this answer

Azure SQL Database auditing can be configured to write audit logs directly to an Azure Storage account. Storing the logs in a storage account located in a different Azure region meets the disaster recovery requirement by ensuring logs survive a regional outage. The audit logs capture all database events, including failed login attempts, which satisfies the compliance need.

Exam trap

The trap here is that candidates often confuse auditing with threat detection or choose a Log Analytics workspace for centralized logging, overlooking the explicit requirement for durable, cross-region storage for compliance and disaster recovery.

How to eliminate wrong answers

Option A is wrong because a Log Analytics workspace does not provide geo-redundant storage for disaster recovery; it is primarily for log analytics and monitoring, not for long-term archival in a different region. Option B is wrong because an Event Hub namespace is a real-time streaming service, not a durable storage destination for audit logs, and it is specified to be in the same region, which fails the disaster recovery requirement. Option D is wrong because Advanced Threat Protection (ATP) detects suspicious activities and sends email notifications, but it does not audit or store failed login attempts in a storage account for compliance purposes.

395
MCQhard

You are troubleshooting connectivity issues from an Azure VM to an on-premises server. The VM is in a VNet that uses a custom DNS server. The on-premises network is connected via ExpressRoute. You can ping the on-premises server by IP address but not by name. What is the most likely cause?

A.The ExpressRoute circuit is not configured for DNS forwarding.
B.The custom DNS server does not have a conditional forwarder to the on-premises DNS.
C.The Azure Private DNS zone does not include the on-premises hostname.
D.An NSG rule is blocking DNS traffic.
AnswerB

When you set a custom DNS server on an Azure virtual network, all VMs in that network send their DNS queries to that server. Because your VM can ping the on-premises host by IP but cannot resolve its name, the custom DNS server is receiving the query but does not know where to send it. A conditional forwarder specifically forwards queries for a given on-premises domain suffix (e.g., corp.contoso.com) to the on-premises DNS server. Without this forwarder, the custom DNS server either tries to resolve the name against the internet root hints or responds with an error, failing to resolve the on-premises hostname.

Why this answer

The custom DNS server in the Azure VNet is authoritative for the VNet's DNS resolution. When the VM tries to resolve the on-premises server's name, the custom DNS server does not know how to forward the query to the on-premises DNS infrastructure. A conditional forwarder must be configured on the custom DNS server to send queries for the on-premises domain to the on-premises DNS server, which is reachable via ExpressRoute.

Without this forwarder, name resolution fails even though IP connectivity (ping) works.

Exam trap

The trap here is that candidates often assume ExpressRoute automatically handles DNS resolution or that Azure Private DNS zones extend to on-premises, but the real issue is the lack of a conditional forwarder on the custom DNS server to bridge the two DNS namespaces.

How to eliminate wrong answers

Option A is wrong because ExpressRoute circuits do not have a 'DNS forwarding' feature; they provide Layer 3 connectivity between on-premises and Azure, but DNS forwarding is a function of DNS servers, not the circuit itself. Option C is wrong because Azure Private DNS zones are used for resolving names within Azure VNets and do not automatically include on-premises hostnames; they require manual configuration and are not the mechanism for resolving on-premises names from Azure. Option D is wrong because if an NSG rule were blocking DNS traffic (UDP/TCP port 53), the ping by IP would still succeed, but DNS queries would fail; however, the question states that ping by IP works, and the issue is specifically name resolution, which points to a DNS forwarding problem, not a firewall rule.

396
MCQeasy

A company has an Azure virtual network with two subnets: Frontend and Backend. They deploy a network virtual appliance (NVA) in a subnet named NVA_Subnet. They want to route all traffic from the Frontend subnet to the Backend subnet through the NVA for inspection. What is the minimum number of route tables required to achieve this traffic steering?

A.1
B.2
C.3
D.4
AnswerA

A single route table associated with the Frontend subnet is all that is required. You define one user-defined route (UDR) with the Backend subnet's address space as the destination and the NVA's private IP as the next hop. Because the traffic flow originates only from Frontend to Backend, outbound traffic on Frontend is steered through the NVA, while return traffic automatically uses the default system routes without requiring a separate route table on the Backend subnet.

Why this answer

A single route table can be associated with the Frontend subnet and configured with a user-defined route (UDR) that has the NVA's private IP as the next hop for traffic destined to the Backend subnet. This ensures all traffic from Frontend to Backend is forwarded to the NVA for inspection. No additional route tables are needed because the NVA itself handles the routing decision after inspection, and the Backend subnet does not require a specific route to return traffic unless asymmetric routing is a concern.

Exam trap

The trap here is that candidates often assume each subnet requires its own route table, or that the NVA subnet itself needs a custom route, but Azure's default routing handles the return path unless asymmetric routing is explicitly required.

How to eliminate wrong answers

Option B is wrong because two route tables would be unnecessary; the requirement is only to steer traffic from Frontend to Backend through the NVA, which can be achieved with a single route table associated with the Frontend subnet. Option C is wrong because three route tables imply a misconception that each subnet or the NVA subnet requires its own route table, but the NVA subnet does not need a custom route for this scenario. Option D is wrong because four route tables would be excessive and suggests a misunderstanding of how Azure routing works; the default system routes handle intra-VNet traffic unless overridden, and only the source subnet (Frontend) needs a custom route.

397
MCQmedium

You are using Microsoft Sentinel to monitor security events. You need to create a custom analytics rule that detects when a user account is added to a privileged group. The rule should run every 5 minutes and generate an incident. Which query language and data source should you use?

A.KQL against the AzureActivity table.
B.KQL against the AuditLogs table.
C.KQL against the SigninLogs table.
D.KQL against the SecurityEvent table.
AnswerB

The AuditLogs table in Microsoft Sentinel contains Azure Active Directory (Microsoft Entra ID) audit logs, which include events for adding members to groups, especially privileged groups. This is the correct data source for detecting user account additions to privileged groups. KQL is the query language used in Sentinel analytics rules, and this table provides the necessary events.

Why this answer

To detect user account additions to privileged groups, you need Azure Active Directory audit logs, which are stored in the AuditLogs table in Microsoft Sentinel. KQL is the query language for analytics rules. The AuditLogs table captures group management activities, including additions to privileged roles.

The rule can be scheduled to run every 5 minutes and generate incidents when the condition is met.

Exam trap

The trap here is assuming that SecurityEvent or AzureActivity tables contain Azure AD group changes, but those are in AuditLogs.

398
Multi-Selecthard

Which TWO of the following are required to implement a successful Just-In-Time (JIT) access strategy using Microsoft Entra Privileged Identity Management (PIM) for Azure resources?

Select 2 answers
A.Enable Azure Multi-Factor Authentication for all users in the tenant
B.Create custom RBAC roles for the JIT access
C.Configure role settings to specify activation duration and require approval if needed
D.Assign users as eligible for the roles they need to activate
E.Assign users as permanently active for the roles they need
AnswersC, D

Configuring role settings is a required step because these settings define the operational parameters of JIT activation, such as the maximum activation duration (e.g., 1 hour), whether approval is required, and whether justification and ticket information are mandatory. Without these settings, PIM cannot enforce time-bound activation or control the approval workflow, so the JIT strategy would lack governance. You must explicitly configure the settings for each role that you plan to manage with PIM.

Why this answer

Option C is correct because PIM role settings define the activation parameters that make access just-in-time, such as maximum activation duration, whether approval is required, and whether justification or MFA is needed at activation; without configuring these settings, eligible assignments would not enforce time-bound, controlled activation. Option D is correct because JIT access in PIM for Azure resources requires users to be assigned as eligible for the Azure RBAC roles they need, so they can activate the role only when required rather than holding standing access. Option A is not required for the JIT strategy itself, since MFA can be enforced as a role setting at activation rather than mandating MFA for all tenant users.

Option B is not required because PIM works with built-in Azure RBAC roles and custom roles are not a prerequisite for JIT access. Option E is incorrect because permanently active assignments provide standing access, which is the opposite of just-in-time access.

Exam trap

The trap here is that candidates often confuse enabling MFA tenant-wide (Option A) with PIM's ability to require MFA at activation time, which is a separate setting within the role activation policy, not a prerequisite.

399
MCQmedium

Security analysts in your company use Microsoft Sentinel to manage incidents. They want to automatically assign any incident with a severity of 'High' or 'Critical' to the senior analyst on duty. Which Microsoft Sentinel feature should they configure to accomplish this?

A.Automation rules
B.Playbooks
C.Workbooks
D.Analytics rules
AnswerA

Automation rules are the native, no-code mechanism in Microsoft Sentinel for automating incident management tasks. You define a trigger condition (e.g., incident severity is High or Critical) and then assign an action such as 'Set owner' to a specific user or group. Because these rules run directly within Sentinel and are evaluated on incident creation/update, they are the simplest and most direct way to ensure every matching incident is immediately assigned to the appropriate analyst without additional Logic Apps consumption.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific users or groups based on conditions such as severity. By creating an automation rule that triggers when an incident is created with a severity of 'High' or 'Critical', you can set the owner to the senior analyst on duty, fulfilling the requirement without manual intervention.

Exam trap

The trap here is that candidates often confuse automation rules with playbooks, assuming that any automated response requires a playbook, but Microsoft Sentinel's automation rules natively support direct incident assignment without needing a separate playbook workflow.

How to eliminate wrong answers

Option B is wrong because playbooks are automated workflows (often based on Azure Logic Apps) that perform complex response actions like sending emails or blocking IPs, but they cannot directly assign incident ownership; assignment is a property managed by automation rules. Option C is wrong because workbooks are visualization tools for creating dashboards and reports from Sentinel data, not for automating incident assignment. Option D is wrong because analytics rules are used to generate alerts and incidents from data sources (e.g., scheduled queries or Microsoft Security alerts), but they do not handle post-creation actions like assignment.

400
Multi-Selecthard

Which THREE are valid methods to ingest data into Microsoft Sentinel? (Select three.)

Select 3 answers
A.Microsoft Sentinel Data Collector API
B.Azure CLI
C.Common Event Format (CEF) over Syslog
D.Azure Data Factory
E.Azure Monitor Agent
AnswersA, C, E

The Microsoft Sentinel Data Collector API is a valid ingestion method because it provides a direct REST endpoint for sending custom and third-party log sources into a Log Analytics workspace, which Sentinel monitors. It accepts structured data formats such as JSON, and supports the creation of custom log tables, making it essential for integrating proprietary systems or hardening existing connectors. The API uses Azure AD authentication and can be invoked from automation scripts or security tools, enabling near real-time log upload without requiring an agent.

Why this answer

The Microsoft Sentinel Data Collector API is a valid ingestion method because it allows custom logs and data sources to be sent directly to Sentinel via a RESTful API endpoint. This is commonly used for non-standard data sources that do not have built-in connectors, enabling organizations to ingest data from custom applications or legacy systems.

Exam trap

The trap here is that candidates may confuse Azure CLI or Azure Data Factory as valid ingestion methods because they are common Azure tools, but neither directly sends log data to Sentinel's ingestion pipeline.

401
MCQmedium

A company has a hub-spoke network topology in Azure. The hub virtual network contains an Azure Firewall. Spoke virtual networks are peered to the hub. The security team wants to inspect all traffic between virtual machines in different spoke virtual networks. What is the minimum configuration required?

A.Enable VNet peering gateway transit and allow forwarded traffic.
B.Deploy a VPN gateway in each spoke and configure site-to-site VPNs to the hub.
C.Define user-defined routes (UDRs) in each spoke that direct inter-spoke traffic to the Azure Firewall in the hub.
D.Configure network security groups (NSGs) on each spoke subnet.
AnswerC

Defining user-defined routes (UDRs) on each spoke subnet whose address prefix covers the other spoke's address space and whose next hop is the Azure Firewall's private IP address ensures that any inter-spoke traffic is forced to traverse the hub firewall for inspection and policy enforcement. This is the canonical pattern for a hub-spoke architecture with forced tunneling, as the route table overrides the default system routes that would otherwise use the direct peering path. The firewall's network and application rules then filter, log, and optionally forward the traffic to the destination spoke.

Why this answer

User-defined routes (UDRs) in each spoke subnet are required to force inter-spoke traffic through the Azure Firewall in the hub. Without UDRs, traffic between peered spokes would flow directly over the VNet peering connections, bypassing the firewall. The UDRs must have the Azure Firewall's private IP as the next hop to ensure all inter-spoke traffic is inspected.

Exam trap

The trap here is that candidates often assume VNet peering automatically routes inter-spoke traffic through the hub, but without UDRs, Azure's default system routes allow direct communication between peered spokes, bypassing any inspection appliance.

How to eliminate wrong answers

Option A is wrong because enabling VNet peering gateway transit and allowing forwarded traffic only permits traffic to flow through a VPN gateway or ExpressRoute gateway in the hub, not through an Azure Firewall; it does not force inter-spoke traffic to be inspected. Option B is wrong because deploying VPN gateways in each spoke and configuring site-to-site VPNs to the hub is unnecessary, adds cost and complexity, and does not leverage the existing Azure Firewall for traffic inspection. Option D is wrong because network security groups (NSGs) are stateful, stateless packet filters that can allow or deny traffic but cannot redirect traffic to a firewall for inspection; they lack routing capabilities.

402
MCQmedium

An organization has deployed Microsoft Sentinel as their SIEM. They need to ingest audit logs from their Amazon Web Services (AWS) environment, including CloudTrail logs. Which data connector should they use in Microsoft Sentinel to collect these logs?

A.Amazon Web Services connector
B.AWS S3 connector
C.Azure Sentinel to AWS connector
D.CloudTrail connector
AnswerA

The correct connector in Microsoft Sentinel is named 'Amazon Web Services,' and it is specifically designed to ingest AWS CloudTrail audit logs into Sentinel. This connector uses an S3 bucket as the log source and SQS for automated notifications, while also requiring an AWS role for cross-account access. Its official display name in the Sentinel data connectors gallery is 'Amazon Web Services (AWS),' which is why it is the precise answer.

Why this answer

The Amazon Web Services connector is the correct data connector in Microsoft Sentinel for ingesting AWS audit logs, including CloudTrail logs. It establishes a connection to AWS by requiring a role ARN and external ID, enabling Sentinel to pull CloudTrail events via the AWS API. This connector specifically supports CloudTrail management and data events, making it the appropriate choice for audit log ingestion.

Exam trap

The trap here is that candidates may confuse the generic 'AWS S3 connector' with CloudTrail log ingestion, but CloudTrail logs are ingested via the dedicated 'Amazon Web Services' connector, not through direct S3 bucket access.

How to eliminate wrong answers

Option B is wrong because the AWS S3 connector is designed to ingest logs from S3 buckets (e.g., VPC Flow Logs, ELB logs), not specifically CloudTrail audit logs, and requires additional configuration like SQS for event-driven ingestion. Option C is wrong because there is no data connector named 'Azure Sentinel to AWS connector'; the official connector is called 'Amazon Web Services' in the Sentinel data connectors gallery. Option D is wrong because there is no standalone 'CloudTrail connector' in Microsoft Sentinel; CloudTrail logs are ingested through the Amazon Web Services connector, which handles the CloudTrail integration.

403
MCQhard

Your company uses Azure SQL Database with Microsoft Entra ID authentication. You need to restrict a user to only view data from the 'Sales' schema, without granting permissions to other schemas. What should you do?

A.Add the user to the db_datareader role in the database.
B.Use a DENY statement on all other schemas for the user.
C.Create a user mapped to the Entra ID user and grant SELECT on the Sales schema only.
D.Create a contained database user with password and assign to db_datareader.
AnswerC

This is the correct approach because Azure SQL Database supports creating a database user mapped directly to a Microsoft Entra ID user (CREATE USER [user@domain.com] FROM EXTERNAL PROVIDER). After creating that mapped user, you can issue a focused GRANT SELECT ON SCHEMA::Sales TO [user], which grants read access solely to objects in the Sales schema. This aligns with least privilege by allowing only the specific schema needed and works natively with Entra ID authentication.

Why this answer

It directly implements the principle of least privilege by creating a database user mapped to the Microsoft Entra ID user and granting SELECT only on the Sales schema. This ensures the user can view data exclusively within that schema, with no implicit permissions on other schemas. Azure SQL Database supports schema-level permissions, making this a precise and secure approach.

Exam trap

The trap here is that candidates often confuse database-level roles (like db_datareader) with schema-level permissions, mistakenly assuming that adding a user to a read-only role is sufficient, while ignoring that db_datareader grants access to all schemas, not a specific one.

How to eliminate wrong answers

Option A is wrong because adding the user to the db_datareader role grants read access to all user tables and views across all schemas in the database, which violates the requirement to restrict access to only the Sales schema. Option B is wrong because using a DENY statement on all other schemas is overly broad and can be overridden by explicit GRANT permissions; more importantly, it does not grant the necessary SELECT permission on the Sales schema, so the user would have no access at all. Option D is wrong because creating a contained database user with a password bypasses Microsoft Entra ID authentication entirely, and assigning db_datareader again grants access to all schemas, not just Sales.

404
MCQeasy

Refer to the exhibit. This is an excerpt from an Azure Policy assignment. What is the effect of the 'notScopes' property?

A.The policy will apply only to the VM-Sensitive virtual machine.
B.The policy will apply to all resources in RG-Prod except the entire resource group.
C.The policy will apply to all resources in RG-Prod except the VM-Sensitive virtual machine.
D.The policy will apply to the subscription but not to RG-Prod.
AnswerC

The assignment's scope is RG-Prod, making every contained resource subject to policy evaluation. The notScopes array specifies the VM-Sensitive virtual machine resource ID, so that VM alone is excluded from compliance evaluation. All other resources, regardless of type, remain within the assignment's scope and are evaluated.

Why this answer

'notScopes' excludes specific sub-scopes from the policy assignment. In this case, the policy applies to all resources in 'RG-Prod' except the VM named 'VM-Sensitive'. Option A is wrong because 'notScopes' do not add resources.

Option B is wrong because it does not remove the entire resource group. Option D is wrong because it does not affect subscription-level exclusions.

405
Multi-Selecteasy

Which TWO of the following data connectors are available by default in Microsoft Sentinel?

Select 2 answers
A.Palo Alto Networks
B.ServiceNow
C.Microsoft Entra ID
D.Azure Activity
E.Amazon Web Services (AWS)
AnswersC, D

The Microsoft Entra ID connector, like the Azure Activity connector, is available by default in Microsoft Sentinel because it ingests sign-in logs, audit logs, and provisioning logs directly from the Microsoft cloud platform. You still need to enable it and possess the appropriate Microsoft Entra ID P1/P2 or relevant role permissions, but there is no extra licensing for the connector itself; it is considered a built-in, non-premium connector.

Why this answer

Microsoft Entra ID (Option C) is a default data connector in Microsoft Sentinel because it provides native integration for streaming Azure AD audit logs and sign-in logs directly into Sentinel without requiring additional licensing or configuration beyond enabling the connector. This is a core Microsoft source that is automatically available in the Sentinel data connector gallery.

Exam trap

The trap here is that candidates often assume any popular third-party service (like Palo Alto Networks or AWS) is a default connector because of its common use in security monitoring, but Microsoft Sentinel only includes first-party Microsoft services as default connectors, while all third-party integrations require manual setup.

406
Multi-Selecthard

Which THREE Microsoft Entra ID roles can be assigned to a user to manage Microsoft Defender XDR (formerly Microsoft 365 Defender) incidents? (Choose three.)

Select 3 answers
A.Exchange Administrator
B.Security Administrator
C.Global Reader
D.Security Operator
E.Global Administrator
AnswersB, D, E

Security Administrator is a built-in Microsoft Entra ID role that grants permission to read security information, manage security policies, and act on security alerts and incidents in Microsoft 365 Defender, Defender for Cloud, and Identity Protection. It includes important actions such as managing conditional access policies, resetting passwords, and updating MFA settings, making it an appropriate role for incident response without granting full tenant-wide control. Because it supports day-to-day security administration and remediation, it is one of the roles that can be correctly assigned to a user.

Why this answer

The Security Administrator role (Option B) can manage Microsoft Defender XDR incidents because it grants full access to security features, including the ability to view, investigate, and respond to incidents in the Microsoft 365 Defender portal. This role is designed for users who need to manage security policies and incidents without having full administrative control over the tenant.

Exam trap

The trap here is that candidates often confuse the Security Reader role with the Security Operator role, or assume that Global Reader (which can view security settings) is sufficient to manage incidents, but only roles with write permissions like Security Administrator, Security Operator, or Global Administrator can actually manage Defender XDR incidents.

407
MCQeasy

You are designing network security for a multi-tier application. The web tier must be accessible from the internet, but the database tier must only be accessible from the web tier. Both tiers are in the same virtual network. Which Azure service should you use to restrict traffic between the tiers?

A.Route table
B.Network Security Group (NSG)
C.Azure Firewall
D.Application Security Groups (ASGs)
AnswerB

Network Security Groups (NSGs) are the correct native solution because they filter traffic between subnets and NICs using priority-ordered security rules based on source/destination IP, port, and protocol. NSGs are stateful, meaning a permitted inbound flow's return traffic is automatically allowed, and they can be associated directly with the database subnet to only permit port 1433 from the app tier's subnet/IPs.

Why this answer

Network Security Groups (NSGs) are used to filter network traffic to and from Azure resources within a virtual network. They contain security rules that allow or deny inbound and outbound traffic based on source/destination IP, port, and protocol. By applying NSGs to the subnets or NICs of the web and database tiers, you can restrict database access to only the web tier.

Exam trap

AZ-500 often tests the difference between NSGs and ASGs; candidates might pick ASGs thinking they restrict traffic, but ASGs are just grouping mechanisms that must be used with NSGs to define rules. The key is that NSGs are the actual enforcement point.

How to eliminate wrong answers

Option A is wrong because a route table controls traffic routing, not security filtering; it cannot restrict access based on source or destination. Option C is wrong because Azure Firewall is a managed, cloud-based network security service that provides centralized protection, but it is overkill for simple inter-tier restrictions within a VNet and is more complex and costly. Option D is wrong because Application Security Groups (ASGs) are used to group VMs by workload and simplify NSG rule creation, but they are not a standalone service; they must be used with NSGs.

The question asks for the service to restrict traffic, which is NSG.

408
MCQmedium

A company uses Azure Firewall to inspect traffic between a spoke VNet hosting a web application and a hub VNet hosting a SQL database. The web application fails to connect to the database after a recent network topology change. You verify that the Azure Firewall rules allow the traffic. Which Azure Network Watcher feature should you use to identify the root cause?

A.Connection troubleshoot
B.Next hop
C.Network Performance Monitor
D.IP flow verify
AnswerA

Connection troubleshoot in Azure Network Watcher performs an end-to-end connectivity test between a source and destination, checking reachability over the network path. However, it returns a pass/fail status and may only indicate the hop where connectivity fails, not the specific security rule (such as an Azure Firewall rule or NSG rule) that dropped the packet. This makes it less precise than IP flow verify for identifying exactly which deny rule caused the blocking.

Why this answer

Connection troubleshoot (Option A) is the correct choice because it performs an end-to-end connectivity test from the source VM to the destination, evaluating the actual path, including Azure Firewall rules, NSGs, and route tables. Since the firewall rules are confirmed to allow the traffic, Connection troubleshoot can identify if a UDR misrouting or an NSG on the source or destination subnet is blocking the connection. IP flow verify only checks NSG rules at a single network interface and does not evaluate route tables or the entire path.

Exam trap

The trap is that IP flow verify is mistakenly thought to evaluate Azure Firewall and route tables, but it only evaluates effective NSGs on a single interface. Connection troubleshoot is the appropriate tool for diagnosing end-to-end connectivity issues.

How to eliminate wrong answers

Option A (Connection troubleshoot) is wrong because it performs end-to-end connectivity checks using ICMP/TCP probes and provides latency and hop-by-hop diagnostics, but it does not evaluate firewall or NSG rule logic; it assumes the network path is already reachable. Option B (Next hop) is wrong because it only returns the next hop type and IP address for a given destination, which helps identify routing issues (e.g., a missing route to the firewall) but does not inspect security rules or determine if traffic is permitted. Option C (Network Performance Monitor) is wrong because it is a deprecated monitoring solution for network latency and packet loss across hybrid connections; it does not perform rule-level traffic validation or diagnose firewall/NSG denials.

409
MCQeasy

A company needs to demonstrate compliance with the Payment Card Industry Data Security Standard (PCI DSS) for their Azure workloads. They use Microsoft Defender for Cloud for security management. Which feature should they use to view their current compliance status against PCI DSS controls and track progress over time?

A.Security policy
B.Recommendations
C.Regulatory compliance dashboard
D.Security incidents
AnswerC

The Regulatory compliance dashboard continuously evaluates selected standards, including PCI DSS 3.2.1, through built-in Azure Policy initiatives and displays the overall percentage of compliant controls across your subscriptions. It maps each standard requirement to compliance controls, shows the resources that passed or failed the linked policies, and identifies which failed recommendations must be fixed to restore that control. You can also drill down to view evidence, assign manual assessments for customer-managed controls, and track compliance trends over time, making it the correct place to demonstrate PCI DSS status.

Why this answer

The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built view of compliance posture against standards like PCI DSS. It maps Azure resource configurations to specific PCI DSS controls, shows pass/fail status per control, and tracks compliance score over time, enabling continuous monitoring and evidence collection for auditors.

Exam trap

The trap here is that candidates may confuse the Recommendations blade (which shows individual security findings) with the Regulatory compliance dashboard (which aggregates those findings into a compliance framework view), leading them to select Recommendations instead of the correct dashboard.

How to eliminate wrong answers

Option A is wrong because Security policy defines rules and initiatives for resource compliance but does not provide a dashboard to view current compliance status or track progress against PCI DSS controls. Option B is wrong because Recommendations are individual security findings that suggest actions to improve security posture, but they do not aggregate or map to PCI DSS controls in a compliance dashboard format. Option D is wrong because Security incidents are alerts about detected threats or attacks, not a compliance tracking tool for standards like PCI DSS.

410
MCQhard

A company plans to use Azure Private Endpoint to securely connect to an Azure SQL Database from an on-premises network via ExpressRoute. The private endpoint is deployed in a hub virtual network. The on-premises network is connected to the hub via ExpressRoute. What additional configuration is needed to ensure on-premises clients can resolve the private endpoint's DNS name?

A.Configure a DNS forwarder on-premises to forward the private link domain to Azure DNS.
B.Configure a network security group to allow inbound traffic from on-premises to the private endpoint.
C.Deploy a VPN gateway in the hub VNet for additional encryption.
D.Add a public DNS record for the SQL Database pointing to the private endpoint IP.
AnswerA

On-premises clients must resolve the resource's FQDN to the private IP that Azure Private Link assigns. The public Azure DNS endpoint normally returns a public IP, so the on-prem DNS suffix should include the 'privatelink' zone and forward those queries to Azure DNS (e.g., via Azure Private DNS Resolver or the DNS IP 168.63.129.16) after the ExpressRoute connection is established. This conditional forwarder enables seamless name resolution without exposing the private IP publicly.

Why this answer

Azure Private Endpoint requires DNS resolution to map the private endpoint's private IP address to the fully qualified domain name (FQDN) of the Azure SQL Database. On-premises clients connected via ExpressRoute cannot resolve the private link domain (e.g., `*.database.windows.net`) to the private IP unless a DNS forwarder is configured on-premises to forward queries for the `privatelink.database.windows.net` zone to Azure DNS (168.63.129.16). This ensures that DNS queries from on-premises resolve to the private endpoint IP instead of the public IP of the SQL Database.

Exam trap

The trap here is that candidates often assume that ExpressRoute alone provides full connectivity and DNS resolution, but they overlook the critical requirement of DNS configuration to ensure on-premises clients resolve the private endpoint's private IP instead of the public IP.

How to eliminate wrong answers

Option B is wrong because network security groups (NSGs) control network traffic at the subnet or NIC level, but they do not affect DNS resolution; the issue is about name resolution, not traffic filtering. Option C is wrong because a VPN gateway is not needed for additional encryption when ExpressRoute already provides a private, dedicated connection; the problem is DNS resolution, not encryption or connectivity. Option D is wrong because adding a public DNS record pointing to the private endpoint IP would expose the private IP publicly and defeat the purpose of using a private endpoint; moreover, public DNS records are not used for on-premises resolution of private endpoints.

411
MCQmedium

Your organization uses Microsoft Entra ID for identity management. You need to implement a solution that automatically detects and remediates identity risks such as leaked credentials and impossible travel. The solution must use built-in Microsoft Entra capabilities without additional licensing beyond Microsoft Entra ID P2. What should you configure?

A.Enable Privileged Identity Management (PIM) for role activation.
B.Create Conditional Access policies requiring MFA for all users.
C.Set up Access Reviews for guest users.
D.Configure Identity Protection policies for sign-in risk and user risk.
AnswerD

Identity Protection in Microsoft Entra ID aggregates machine-learning-based risk detections, including leaked credentials, impossible travel, anonymous IP addresses, and unfamiliar sign-in properties, into user-risk and sign-in-risk levels. You can configure risk-based Conditional Access policies to automatically require MFA or a secure password reset when risk thresholds are exceeded, providing both detection and auto-remediation. This is the service designed specifically to identify and act on identity risks.

Why this answer

The correct answer is D: Configure Identity Protection policies for sign-in risk and user risk. Microsoft Entra ID Protection is the built-in P2 capability that detects identity risks such as leaked credentials (user risk) and impossible travel (sign-in risk), and it can automatically remediate them by requiring MFA or password change through risk-based Conditional Access policies. PIM (A) governs just-in-time privileged role activation and does not detect leaked credentials or impossible travel.

Conditional Access requiring MFA for all users (B) enforces a static control and does not perform risk detection or risk-based remediation. Access Reviews for guest users (C) handle periodic attestation of guest access, not identity risk detection or remediation.

412
MCQmedium

A company uses Azure AD Identity Protection. They have detected a user with a 'High' user risk level due to suspicious activity. The security team wants to automatically block sign-ins for this user only when the sign-in comes from a location that is not in the company's list of trusted IPs. They have created a Conditional Access policy. Which configuration should they use?

A.Assign the user to the policy, set condition 'User risk level: High' and condition 'Locations: All locations except trusted', and set 'Grant' to 'Block access'
B.Assign the user to the policy, set condition 'Sign-in risk level: High' and condition 'Locations: All trusted locations', and set 'Grant' to 'Block access'
C.Assign the user to the policy, set condition 'User risk level: High' and set 'Grant' to 'Require multi-factor authentication'
D.Create a risk detection policy in Identity Protection that triggers a user risk policy, and have Conditional Access use the risk policy
AnswerA

In a Conditional Access policy, conditions are combined with a logical AND, so this configuration triggers only when Identity Protection has computed the user's account risk as High and the sign-in originates from a location that is not on the trusted list. The Grant control is set to Block access, which denies the authentication session outright rather than allowing it with additional challenges. Because user risk is a cumulative account-level signal, pairing it with the trusted-location exception precisely targets high-risk users signing in from untrusted networks while leaving trusted-network activity unaffected.

Why this answer

It combines the 'User risk level: High' condition (triggered by Identity Protection's user risk detection) with the 'Locations: All locations except trusted' condition, and sets 'Grant' to 'Block access'. This ensures that only sign-ins from untrusted locations are blocked when the user's risk is high, meeting the requirement to allow sign-ins from trusted IPs even for high-risk users.

Exam trap

The trap here is confusing 'User risk level' (associated with the user account's overall risk) with 'Sign-in risk level' (associated with a specific authentication attempt), leading candidates to incorrectly choose Option B which uses sign-in risk and targets trusted locations.

How to eliminate wrong answers

Option B is wrong because it uses 'Sign-in risk level: High' instead of 'User risk level: High', and it targets 'All trusted locations' which would block sign-ins from trusted IPs, the opposite of the requirement. Option C is wrong because it sets 'Grant' to 'Require multi-factor authentication' instead of 'Block access', which does not block sign-ins but only prompts for MFA, failing the requirement to block sign-ins from untrusted locations. Option D is wrong because it describes creating a separate risk detection policy in Identity Protection; Conditional Access policies directly use user risk and sign-in risk conditions without needing an additional risk policy, and this approach adds unnecessary complexity without achieving the specific location-based block.

413
MCQhard

A company uses Azure AD Privileged Identity Management (PIM) to manage the Global Administrator role. They want to require that when a user activates the role, they must be using a device that is compliant with Intune policies (e.g., compliant device) and must provide a justification. The company already has Conditional Access policies in place for regular access. How should they enforce the device compliance requirement specifically during PIM activation?

A.Configure a Conditional Access policy that targets the 'Azure AD Privileged Identity Management' cloud app, requiring compliant device.
B.In PIM settings for the Global Administrator role, enable 'Require Multi-Factor Authentication on activation'.
C.In PIM settings for the Global Administrator role, enable 'Require Azure AD Conditional Access authentication context' and create a Conditional Access policy that requires compliant device when that authentication context is used.
D.Use Azure AD Identity Protection's user risk policy to require device compliance when a high-risk user activates the role.
AnswerC

This is the correct approach because PIM supports emitting an Azure AD Conditional Access authentication context during role activation. When you enable 'Require Azure AD Conditional Access authentication context' in PIM settings, Azure AD sends that context as a signal to Conditional Access for the activation request. A separate Conditional Access policy can then target that authentication context and apply the 'Require device to be marked as compliant' grant control. This is the documented integration pattern for combining PIM with device-compliance policies, and it satisfies the requirement without relying on unsupported targets like the PIM app itself.

Why this answer

Azure AD PIM can integrate with Conditional Access via authentication context. By enabling 'Require Azure AD Conditional Access authentication context' in the PIM role settings and then creating a Conditional Access policy that targets that authentication context with the 'Require compliant device' grant control, you enforce device compliance specifically during role activation. This approach ensures the device compliance check is applied only when the user activates the Global Administrator role, not during regular access.

Exam trap

The trap here is that candidates often confuse applying a Conditional Access policy to the 'Azure AD Privileged Identity Management' cloud app (which controls access to the PIM portal) with enforcing conditions during the actual role activation process, which requires authentication context integration.

How to eliminate wrong answers

Option A is wrong because targeting the 'Azure AD Privileged Identity Management' cloud app in a Conditional Access policy applies the policy to the PIM service itself (e.g., accessing the PIM portal), not to the role activation process; it would not enforce device compliance during activation. Option B is wrong because enabling 'Require Multi-Factor Authentication on activation' only adds an MFA requirement, not a device compliance check; it does not address the device compliance requirement. Option D is wrong because Azure AD Identity Protection's user risk policy evaluates user risk and can require MFA or password change, but it cannot directly enforce device compliance; it is designed for risk-based remediation, not for role activation-specific device compliance.

414
MCQeasy

You need to enable Microsoft Defender for Cloud's workload protection for Azure Kubernetes Service (AKS) clusters. Which Defender plan should you enable?

A.Enable the foundational Cloud Security Posture Management (CSPM) plan.
B.Enable Defender for SQL.
C.Enable Defender for Containers.
D.Enable Defender for Servers.
AnswerC

Enabling Defender for Containers is the appropriate plan because it is specifically architected for Kubernetes and AKS, integrating Kubernetes audit logs, control-plane insight, runtime threat detection for workloads, and image vulnerability assessment. At the cluster level it monitors the Kubelet, etcd, and API server while also analyzing behaviors in running containers via the Defender agent (or Azure Arc for hybrid clusters). This single plan provides the runtime protection for container workloads that the scenario requires.

Why this answer

To enable workload protection for Azure Kubernetes Service (AKS) clusters in Microsoft Defender for Cloud, you must enable the Defender for Containers plan. This plan provides runtime threat detection, vulnerability assessment, and compliance monitoring specifically for containerized environments, including AKS, Azure Container Registry (ACR), and Azure Container Instances (ACI). It covers Kubernetes audit logs, host-level security, and container image scanning, which are essential for securing AKS workloads.

Exam trap

The trap here is that candidates often confuse the foundational CSPM plan (which provides basic security recommendations) with the workload-specific Defender plans, mistakenly thinking CSPM alone can protect AKS workloads when it only offers posture visibility without runtime threat detection.

How to eliminate wrong answers

Option A is wrong because the foundational Cloud Security Posture Management (CSPM) plan provides only posture management and basic security recommendations without workload-level threat detection for AKS. Option B is wrong because Defender for SQL is designed to protect Azure SQL Database, SQL Managed Instance, and SQL Server on Azure VMs, not container orchestration platforms like AKS. Option D is wrong because Defender for Servers protects Azure VMs and on-premises servers with endpoint detection and response (EDR) and vulnerability management, but it does not cover Kubernetes-specific threats such as pod-level attacks, container escape, or cluster misconfigurations.

415
Multi-Selecteasy

Which TWO security controls are automatically provided by enabling Microsoft Defender for Cloud's foundational CSPM (Cloud Security Posture Management) capabilities? (Choose two.)

Select 2 answers
A.Azure Firewall Manager integration.
B.Just-in-time (JIT) VM access.
C.Continuous assessment of Azure resources against the Microsoft cloud security benchmark.
D.Security recommendations for Azure resources.
E.Vulnerability assessment for VMs.
AnswersC, D

The foundational cloud security posture management (CSPM) tier in Microsoft Defender for Cloud provides continuous assessment of all supported Azure resources against the Microsoft cloud security benchmark (MCSB), a comprehensive set of security best-practice controls aligned with industry standards. This assessment runs automatically for every onboarded Azure subscription and drives the secure score and compliance dashboards without any additional configuration or licensing. As a built-in, always-on capability, this is a correct answer.

Why this answer

Option C is correct because the foundational CSPM plan in Microsoft Defender for Cloud continuously assesses Azure resources against the Microsoft cloud security benchmark (MCSB), producing a secure score and compliance view without any additional agent or paid plan. Option D is correct because the same foundational CSPM capabilities generate security recommendations for Azure resources based on those assessments, guiding remediation of misconfigurations. Options A, B, and E are not part of the free foundational CSPM offering: Azure Firewall Manager integration is a separate networking service, just-in-time VM access requires the paid Defender for Servers plan (Plan 2), and vulnerability assessment for VMs is also provided by Defender for Servers rather than by foundational CSPM.

416
MCQmedium

A company has a hub-spoke network topology in Azure. The spoke virtual networks contain Azure virtual machines that need to access the internet. The security team requires that all outbound internet traffic from the spoke VMs passes through the Azure Firewall deployed in the hub virtual network for inspection and logging. Which configuration should be implemented to ensure this traffic is routed through the firewall?

A.Configure an Azure Load Balancer in the hub to distribute traffic from spokes to the firewall.
B.Create a user-defined route (UDR) in the spoke subnet with 0.0.0.0/0 pointing to the private IP of the Azure Firewall.
C.Use Azure Firewall Manager to automatically enforce a global default route on all spokes. This is the only configuration needed.
D.Enable IP forwarding on the NICs of the spoke VMs so they forward traffic to the firewall.
AnswerB

A user-defined route with the 0.0.0.0/0 prefix in the spoke subnet overrides Azure's default system route, forcing all outbound internet-bound traffic to the Azure Firewall's private IP in the hub. This satisfies the requirement that spoke VM traffic be inspected and logged by the firewall.

Why this answer

A user-defined route (UDR) with the 0.0.0.0/0 prefix and the next hop set to the private IP address of the Azure Firewall forces all outbound internet traffic from the spoke subnet to be routed through the firewall in the hub. This ensures the traffic passes through the firewall for inspection and logging, as required by the security team.

Exam trap

The trap here is that candidates often confuse Azure Firewall Manager's ability to propagate routes in a virtual WAN with the need for explicit UDRs in a traditional hub-spoke topology using a hub virtual network, leading them to incorrectly select option C as a one-click solution.

How to eliminate wrong answers

Option A is wrong because an Azure Load Balancer distributes inbound traffic and does not route outbound traffic; it cannot force spoke VMs to send internet-bound traffic through the firewall. Option C is wrong because Azure Firewall Manager can enforce a default route via a virtual WAN secured hub, but in a hub-spoke topology using a hub virtual network (not a virtual WAN), a UDR must be explicitly configured on the spoke subnets; Firewall Manager alone does not automatically apply the route to all spokes in this topology. Option D is wrong because IP forwarding on the NICs of the spoke VMs is used to allow a VM to act as a router for traffic passing through it, not to direct outbound traffic from the same VM to a firewall; the spoke VMs are the source of the traffic, not intermediate routers.

417
MCQmedium

You are configuring Microsoft Defender for Cloud for a subscription that contains Azure Kubernetes Service (AKS) clusters. You need to ensure that Defender for Containers provides vulnerability assessment for container images stored in Azure Container Registry (ACR). What should you enable?

A.Enable the Defender for App Service plan and configure the ACR integration from the App Service environment.
B.Enable the Defender for Containers plan and ensure that the ACR integration is turned on, then grant the Defender for Cloud service principal the AcrPull role on the registry.
C.Enable the Defender for Storage plan and configure a private endpoint to ACR.
D.Enable the Defender for Servers plan and deploy the Log Analytics agent to all AKS nodes.
AnswerB

Defender for Containers includes vulnerability assessment for container images in ACR when the ACR integration is enabled. The integration requires the Defender for Cloud service principal to have AcrPull permissions to scan images. This allows Defender for Cloud to pull and analyze images for vulnerabilities, providing continuous assessment as new images are pushed.

Why this answer

Defender for Containers is the correct plan for protecting AKS clusters and container images in ACR. Enabling the plan and the ACR integration, along with granting the service principal AcrPull permissions, allows Defender for Cloud to scan images for vulnerabilities. The other plans target different resource types and do not include container image assessment.

Exam trap

The trap here is selecting Defender for Servers because AKS nodes are VMs, but container image scanning requires Defender for Containers.

418
Multi-Selectmedium

You need to protect Azure SQL Database from SQL injection attacks. Which TWO measures should you implement?

Select 2 answers
A.Enable Transparent Data Encryption (TDE)
B.Implement Azure Web Application Firewall (WAF)
C.Configure Azure SQL Database firewall rules
D.Use parameterized queries in application code
E.Enable Always Encrypted for sensitive columns
AnswersB, D

Azure Web Application Firewall inspects inbound HTTP/S requests and blocks known SQL injection signatures before they reach the database, satisfying the requirement to filter malicious payloads at the application edge rather than relying solely on database-side controls.

Why this answer

Option B (Azure Web Application Firewall) is correct because WAF, especially when deployed with Azure Application Gateway or Front Door, includes managed rule sets that detect and block common SQL injection patterns in HTTP requests before they reach the database. Option D (parameterized queries) is correct because parameterization separates SQL code from user-supplied data, so injected input is treated as a literal value rather than executable SQL, which is the most fundamental defense against SQL injection at the application layer. Option A (TDE) is not correct because it only encrypts data at rest and does nothing to prevent injection attacks.

Option C (Azure SQL Database firewall rules) is not correct because it restricts access by IP address or Azure service, not by inspecting query content. Option E (Always Encrypted) is not correct because it protects sensitive column data from unauthorized viewing, not from SQL injection logic.

Exam trap

The trap here is that candidates often confuse network-level controls (firewall rules) or encryption features (TDE, Always Encrypted) with application-layer defenses against SQL injection, leading them to select options that protect data confidentiality or access but do not prevent the injection attack itself.

419
MCQeasy

You need to ensure that external users who are invited to your Microsoft Entra ID tenant via B2B collaboration can only access a specific SaaS application. What should you configure?

A.Configure SharePoint Online external sharing settings.
B.Create a Conditional Access policy targeting 'All cloud apps' and include guest users.
C.Create a Conditional Access policy targeting the SaaS application and apply it to 'Guest or external users'.
D.Use Microsoft Entra application proxy.
AnswerC

Using a Conditional Access policy that explicitly targets the SaaS application and applies it to 'Guest or external users' scopes both the identity and the resource. Under Target resources you select the specific app, and under Users a particular external user type such as 'B2B collaboration guest' is chosen, allowing the policy to enforce conditions like MFA or session controls. This is the correct pattern because it enforces access decisions at the app boundary for exactly the intended account type without affecting internal users or other applications.

Why this answer

A Conditional Access policy can be scoped to a specific SaaS application and applied to 'Guest or external users'. This ensures that only invited B2B collaboration users are subject to the access control for that application, while all other users and apps remain unaffected. The policy enforces authentication and authorization rules exclusively for the targeted SaaS app and guest identity type.

Exam trap

The trap here is that candidates often confuse broad Conditional Access policies (targeting 'All cloud apps') with application-specific policies, mistakenly thinking that including guest users in a blanket policy achieves the same restriction, when in fact it would block or require MFA for guest users across all apps, not just the target SaaS application.

How to eliminate wrong answers

Option A is wrong because SharePoint Online external sharing settings control sharing of documents and sites, not access to a specific SaaS application; they operate at the SharePoint level, not at the Entra ID application layer. Option B is wrong because targeting 'All cloud apps' would apply the policy to every application in the tenant, including Microsoft services and other SaaS apps, which is overly broad and does not restrict access to only the specific SaaS application. Option D is wrong because Microsoft Entra application proxy is used to publish on-premises web applications externally, not to control access for B2B guest users to a SaaS application; it does not provide granular access restriction per application for external identities.

420
MCQhard

A Defender for Cloud recommendation is valid for most subscriptions but not for a legacy subscription with an approved exception. The team wants secure score to reflect the exception without disabling the recommendation everywhere. What should they do?

A.Delete the built-in initiative from the management group
B.Change the recommendation severity to Low
C.Create an exemption for the affected scope with a justification
D.Disable Defender for Cloud on the legacy subscription
AnswerC

Creating an exemption for the affected scope with a justification is the correct approach because Microsoft Defender for Cloud natively supports exemptions to exclude a specific scope from a recommendation while leaving the initiative intact. You can target the exact subscription (or resource group) and provide a reason, such as 'legacy system' or 'not applicable,' and optionally set an expiration date. This directly addresses the requirement by suppressing the recommendation only where it's not valid, while preserving security monitoring and compliance for all other scopes.

Why this answer

Azure Policy exemptions allow you to exclude a specific scope (e.g., a subscription or resource group) from a policy or initiative effect while still having the policy enforced elsewhere. By creating an exemption for the legacy subscription with a justification, the Defender for Cloud recommendation remains active for all other subscriptions, and the secure score calculation will correctly reflect the exception without disabling the recommendation globally.

Exam trap

The trap here is that candidates often confuse 'exemption' with 'disabling' or 'removing' the policy, leading them to choose options that either globally disable the recommendation (A or D) or incorrectly assume severity changes can create exceptions (B), when in fact Azure Policy exemptions are the precise mechanism to exclude a specific scope while preserving the policy for all others.

How to eliminate wrong answers

Option A is wrong because deleting the built-in initiative from the management group would remove the policy from all subscriptions under that management group, not just the legacy subscription, and would prevent the secure score from reflecting the recommendation at all. Option B is wrong because changing the recommendation severity to Low does not create an exception; it only adjusts the weight of the recommendation in the secure score, but the recommendation would still apply to the legacy subscription and could generate alerts or compliance failures. Option D is wrong because disabling Defender for Cloud on the legacy subscription would turn off all security monitoring and recommendations for that subscription, which is an overly broad action that goes beyond creating a single exception and could leave the subscription unprotected.

421
MCQhard

A Sentinel analytics rule creates a new incident every time the same brute-force activity is detected for the same account within an hour. The SOC wants one incident that continues to group related alerts. What should be changed?

A.Disable entity mapping for the account entity
B.Configure incident grouping in the scheduled analytics rule
C.Change the rule query to use project-away on TimeGenerated
D.Run the rule as a near-real-time rule
AnswerB

Configuring incident grouping in the scheduled analytics rule lets you define how alerts from the same rule are grouped into incidents, such as by matching entities (e.g., account) or within a specific time window. When grouping is set to 'Group all alerts into a single incident' or based on entity mapping, Sentinel will not create a new incident for every alert that fires. This directly satisfies the requirement to avoid a new incident each time the same entity triggers the rule.

Why this answer

Incident grouping in a scheduled analytics rule allows multiple alerts triggered by the same entity (e.g., the same account) within a specified time window to be combined into a single incident. By configuring the 'Group related alerts into a single incident' setting and setting the grouping window to one hour, the SOC ensures that all brute-force alerts for the same account are merged into one incident, reducing alert fatigue and providing a consolidated view of the attack.

Exam trap

The trap here is that candidates often confuse incident grouping with alert suppression or think that disabling entity mapping will reduce noise, but entity mapping is actually required for grouping to work correctly.

How to eliminate wrong answers

Option A is wrong because disabling entity mapping for the account entity would prevent the rule from identifying the specific account involved, breaking the grouping logic and potentially causing alerts to not be correlated at all. Option C is wrong because using project-away on TimeGenerated would remove the timestamp column from the query results, which is essential for time-based grouping and would break the rule's ability to correctly evaluate the 1-hour window. Option D is wrong because running the rule as a near-real-time rule (NRT) does not support incident grouping; NRT rules run every few minutes and create separate incidents for each detection, which is the opposite of what the SOC wants.

422
MCQmedium

A security operations team uses Microsoft Sentinel. They want to automatically assign incidents to different tiers of analysts based on severity when incidents are created. Which feature should they configure?

A.Fusion - Advanced Multistage Attack Detection
B.Analytics rules with scheduled queries
C.Automation rules
D.Playbooks
AnswerC

Automation rules allow you to automatically trigger actions like assigning an incident to a specific user or team, changing severity, adding tags, or running a playbook. This is the correct feature to automatically assign incidents based on severity.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific analysts or teams based on criteria such as severity. When an incident is created, the automation rule triggers and can set the owner (assignee) to a predefined user or group, enabling tiered assignment without manual intervention.

Exam trap

The trap here is that candidates often confuse automation rules with playbooks, assuming playbooks are required for any automated action, but automation rules are the correct feature for simple, rule-based incident assignment without the overhead of a full Logic App workflow.

How to eliminate wrong answers

Option A is wrong because Fusion - Advanced Multistage Attack Detection is a correlation engine that detects multistage attacks by combining alerts, not a mechanism for incident assignment. Option B is wrong because analytics rules with scheduled queries generate alerts based on log queries, but they do not include incident assignment or ownership logic. Option D is wrong because playbooks are automated workflows (often using Azure Logic Apps) that can respond to incidents, but they are triggered by automation rules or analytics rules and are not the feature used to directly assign incidents to analysts.

423
Multi-Selectmedium

You are securing an Azure Kubernetes Service (AKS) cluster. You need to restrict network traffic between pods and to external services using Azure network policies. Which three of the following options are valid considerations or steps? (Choose three.)

Select 3 answers
.Enable the Azure Network Policy Manager (Azure NPM) when creating the AKS cluster.
.Define Kubernetes NetworkPolicy objects that use selectors to allow or deny traffic between pods.
.Use Azure Firewall to enforce egress traffic rules for the AKS cluster.
.Configure an NSG directly on the AKS node subnet to filter pod-to-pod traffic.
.Set the AKS cluster to use Calico network policies instead of Azure NPM for better performance.
.Assign public IP addresses to each pod for direct internet access without a load balancer.

Why this answer

Azure Network Policy Manager (Azure NPM) is a required add-on for enforcing Kubernetes NetworkPolicy objects in an AKS cluster. It translates Kubernetes network policies into Azure-specific configurations to filter pod-to-pod traffic. Without enabling Azure NPM (or an alternative like Calico), standard Kubernetes NetworkPolicy objects will not be enforced by Azure.

Exam trap

The trap here is that candidates often confuse NSGs with Kubernetes network policies, thinking NSGs can filter pod-to-pod traffic, but NSGs operate at the subnet level and cannot see pod IPs, making them ineffective for pod-level segmentation.

424
MCQmedium

Refer to the exhibit. You are creating a Microsoft Sentinel scheduled analytics rule using the KQL query shown. The rule is set to run every hour. What will this rule detect?

A.Successful logins from a single IP address
B.Accounts that have more than 10 failed logins from a specific IP address in the last hour
C.Total failed logins in the last 24 hours
D.Accounts with more than 10 failed logins from any IP address
AnswerB

This is the correct answer because the query applies a 1-hour time filter via `TimeGenerated > ago(1h)`, selects only EventID 4625 (failed logons), and then runs `summarize Count = count() by Account, IpAddress`. The final `Count > 10` condition in the `having` clause ensures only account/IP pairs that exceeded 10 failures within that hour are returned, matching the described behavior.

Why this answer

The KQL query uses `summarize` with `bin(TimeGenerated, 1h)` to count failed logins per account and IP address within 1-hour bins. The `where` clause filters for `ResultType == 50057` (failed logins) and `where count_ > 10` ensures only accounts with more than 10 failed logins from a specific IP in that hour are returned. Since the rule runs every hour, it detects accounts exceeding 10 failed logins from a single IP in the last hour.

Exam trap

The trap here is that candidates overlook the `summarize` grouping by both `Account` and `IPAddress`, mistakenly thinking the count applies to all IPs combined, or they misinterpret `bin(TimeGenerated, 1h)` as a 24-hour window instead of a 1-hour aggregation.

How to eliminate wrong answers

Option A is wrong because the query specifically filters for `ResultType == 50057` (failed logins), not successful logins. Option C is wrong because the query uses `bin(TimeGenerated, 1h)` to aggregate data in 1-hour windows, not 24 hours. Option D is wrong because the `summarize` clause groups by `IPAddress` as well as `Account`, meaning it counts failed logins per specific IP address, not from any IP address.

425
MCQhard

You have an Azure application that uses a private endpoint for Azure SQL Database. Users report intermittent connectivity failures. You need to diagnose whether the private endpoint DNS resolution is working correctly. Which tool should you use?

A.tracert
B.netstat
C.ping
D.nslookup
AnswerD

nslookup is a dedicated DNS client utility that queries a specified DNS server (or the system default) and prints the resource records in the response, such as A, CNAME, and PTR. For an Azure private endpoint, you can run nslookup <private-endpoint-FQDN> to confirm it returns the private IP address from the attached Private DNS Zone, optionally targeting Azure's internal DNS (168.63.129.16) or your own forwarder to isolate resolution failures. This direct visibility into DNS answers makes nslookup the correct tool for verifying private endpoint name resolution.

Why this answer

When using a private endpoint for Azure SQL Database, connectivity relies on DNS resolution returning the private IP address of the endpoint rather than the public IP. `nslookup` queries the DNS server directly and shows the resolved IP address, allowing you to verify that the private endpoint's private IP is being returned. If it returns the public IP or fails, DNS configuration is incorrect.

Exam trap

The trap here is that candidates often choose `ping` or `tracert` because they think connectivity tests diagnose DNS, but DNS resolution must be verified separately with a DNS-specific tool like `nslookup` or `dig`.

How to eliminate wrong answers

Option A is wrong because `tracert` traces the network path (hops) to a destination, but does not verify DNS resolution; it works after DNS is already resolved. Option B is wrong because `netstat` displays active network connections and listening ports, not DNS resolution results. Option C is wrong because `ping` tests reachability via ICMP, but it relies on the system's cached DNS resolution and does not explicitly query the DNS server; it can also be blocked by firewalls or NSGs, giving false negatives.

426
MCQhard

You are a security administrator for a company that stores sensitive data in Azure Blob Storage. You need to ensure that data cannot be accessed from outside the corporate network, even if someone obtains a valid SAS token. The company uses a site-to-site VPN to connect to Azure. What should you configure?

A.Configure storage firewall to allow access only from selected virtual networks and IP ranges.
B.Enable soft delete for blobs.
C.Use customer-managed keys (CMK) for encryption at rest.
D.Enable Azure Defender for Storage.
AnswerA

The storage firewall restricts access to the storage account to specific virtual networks and IP addresses. By allowing only the corporate VPN's virtual network or public IP, you ensure that even with a valid SAS token, access from outside the corporate network is blocked.

Why this answer

To restrict blob access to the corporate network, you must configure the storage account firewall to allow only specific virtual networks or IP ranges. This ensures that requests from outside the allowed networks are denied, even if they present a valid SAS token.

Exam trap

The trap here is confusing data-at-rest encryption or threat detection with network access control, or assuming that SAS tokens alone provide sufficient security.

427
MCQmedium

A security operations team uses Microsoft Sentinel. They create a playbook that changes the severity of an incident from 'Medium' to 'High' when a specific indicator of compromise (IOC) is detected within the incident's entities. The team wants this playbook to run automatically as soon as the incident is created, without manual intervention. Which type of automation rule trigger should they configure to invoke the playbook?

A.When incident is created
B.When incident is updated
C.When alert is created
D.On a time schedule
AnswerA

The 'When incident is created' trigger fires the moment Microsoft Sentinel generates an incident, so the playbook executes with no analyst action. This satisfies the requirement for automatic severity escalation on IOC detection, unlike manual or entity-based triggers.

Why this answer

The 'When incident is created' trigger in Microsoft Sentinel automation rules is designed to invoke a playbook immediately upon incident generation, without requiring any manual action. This matches the requirement for automatic execution as soon as the incident is created, allowing the playbook to evaluate entities and change severity from 'Medium' to 'High' based on the IOC detection.

Exam trap

The trap here is that candidates may confuse 'When alert is created' with incident creation, not realizing that incidents are higher-level constructs that can aggregate multiple alerts, and the playbook must run at the incident scope to change severity based on entities across all alerts.

How to eliminate wrong answers

Option B is wrong because 'When incident is updated' triggers only after an incident is modified (e.g., status change or comment), not at creation time, so it would not run automatically on the initial creation. Option C is wrong because 'When alert is created' triggers on alert generation, not incident creation; incidents can aggregate multiple alerts, and the playbook needs to run at the incident level, not per alert. Option D is wrong because 'On a time schedule' is a recurring trigger (e.g., every hour) that does not respond to real-time incident creation events, making it unsuitable for immediate automated response.

428
MCQmedium

Refer to the exhibit. You are analyzing a Conditional Access policy JSON. The policy requires MFA for Office 365 applications. However, users report that they are still able to access Office 365 without MFA. What is the most likely reason?

A.The policy excludes some Office 365 apps
B.The 'grantControls' section is empty
C.The 'authenticationStrength' property is not a valid Conditional Access policy property
D.The policy does not include all users
AnswerB

Grant controls define what the policy enforces. With an empty grantControls section, no access requirement such as require multifactor authentication is applied, so the policy evaluates as satisfied and users reach Office 365 without completing MFA.

Why this answer

The most likely reason is that the 'grantControls' section is empty. In a Conditional Access policy, the 'grantControls' section specifies the controls to enforce, such as requiring MFA. If this section is empty, no controls are applied, and users can access Office 365 without MFA.

Exam trap

Candidates often overlook that an empty 'grantControls' section means no controls are enforced. The policy appears structurally correct but fails to apply any requirements.

How to eliminate wrong answers

Option A is wrong because excluding some Office 365 apps would still require MFA for the included apps, not allow all Office 365 access without MFA. Option B is wrong because an empty 'grantControls' section would cause the policy to fail validation or not apply, but the JSON shown does not have an empty 'grantControls'; the issue is the invalid property. Option D is wrong because not including all users would only exempt those specific users, but the policy would still enforce MFA for included users; the reported behavior is that all users can bypass MFA, indicating a policy-wide failure.

429
MCQhard

A Sentinel playbook fails to update incidents even though the Logic App runs successfully. The playbook uses a managed identity. What is the most likely missing configuration?

A.The managed identity lacks Microsoft Sentinel Responder or Contributor permissions on the workspace
B.The analytics rule does not include MITRE ATT&CK tactics
C.The Log Analytics workspace is not linked to Azure Monitor Private Link
D.The incident title does not contain an entity mapping
AnswerA

The managed identity assigned to the Logic Apps playbook must be granted Microsoft Sentinel Responder (least privilege) or Contributor at the workspace scope to invoke incident-update operations via the Sentinel API. Without it, the API returns 403 Forbidden even if the playbook run is triggered. This RBAC assignment controls write access to Sentinel incidents, so adding it directly resolves the failure.

Why this answer

The managed identity assigned to the Logic App must have at least Microsoft Sentinel Responder or Contributor permissions on the workspace to update incidents. Without these RBAC roles, the Logic App's API calls to modify incident properties (e.g., status, severity) are denied, even if the Logic App itself runs without errors.

Exam trap

The trap here is that candidates assume a successful Logic App run means permissions are correct, but the playbook can complete without errors while the incident update silently fails due to missing RBAC on the managed identity.

How to eliminate wrong answers

Option B is wrong because MITRE ATT&CK tactics are metadata for rule classification and do not affect the playbook's ability to update incidents. Option C is wrong because Azure Monitor Private Link controls network access to the workspace, not authorization for managed identity actions. Option D is wrong because entity mappings are used for alert enrichment, not for granting permissions to modify incidents.

430
Multi-Selectmedium

Which TWO of the following are valid configurations for Microsoft Entra ID Conditional Access policies?

Select 2 answers
A.Include all users and exclude specific groups
B.Force password change on next sign-in
C.Target a specific cloud application
D.Block access for users without MFA registered
E.Assign licenses to users based on location
AnswersA, C

This is a valid user-and-group assignment in a Conditional Access policy. Selecting All users scopes the policy to every account in the tenant, while the Exclude tab lets you remove specific security groups such as break-glass emergency access accounts. This is the standard way to blanket-apply a policy while preserving administrative exceptions.

Why this answer

Conditional Access policies allow you to include all users as a baseline and then exclude specific groups (e.g., break-glass emergency accounts) to ensure critical access is never blocked. Option C is correct because you can target a specific cloud application (e.g., Microsoft Azure Management, SharePoint Online) to apply granular access controls only to that app, leaving other apps unaffected.

Exam trap

The trap here is that candidates confuse user risk remediation actions (like forcing a password change) with Conditional Access grant controls, or mistakenly think that Conditional Access can directly enforce MFA registration or license assignment, which are separate administrative functions.

431
MCQeasy

A company has an Azure virtual network with a subnet that hosts a web application. The security team wants to allow inbound HTTPS traffic (port 443) from the internet to the web servers, but block all other inbound traffic. They have a network security group (NSG) associated with the subnet. What is the minimal set of inbound rules required?

A.A rule allowing HTTPS from Internet, and a default deny all rule.
B.A rule allowing HTTPS from Internet, and no other rules (default deny all inbound).
C.A rule allowing HTTPS from Internet, and a rule explicitly denying all other inbound traffic.
D.A rule allowing HTTPS from any source, and a rule denying all other traffic with lower priority.
AnswerB

The default DenyAllInbound rule in every NSG already blocks all inbound traffic from the Internet, so adding only an inbound rule that allows HTTPS (TCP 443) from the Internet source service tag is sufficient. Because NSG rules are evaluated in priority order, HTTPS traffic matches the allow rule before reaching the default deny rule, while all other inbound traffic is implicitly denied. This is the minimal viable configuration because no additional deny rules are needed.

Why this answer

Network security groups (NSGs) in Azure have a default deny-all inbound rule (rule 65500) that is automatically applied to all inbound traffic. Therefore, you only need to add an explicit allow rule for HTTPS (port 443) from the Internet. No additional deny rule is required because the default rule already blocks all other inbound traffic.

Exam trap

The trap here is that candidates often think they must add an explicit deny rule to block all other traffic, not realizing that Azure NSGs already include a default deny-all inbound rule that is automatically applied at the lowest priority.

How to eliminate wrong answers

Option A is wrong because it suggests adding a default deny all rule, but Azure NSGs already include a built-in default deny all inbound rule (rule 65500) that cannot be removed or overridden by a lower-priority rule, making an explicit deny unnecessary. Option C is wrong because it proposes an explicit deny all inbound rule, which is redundant and not minimal; the default deny rule already handles this. Option D is wrong because it suggests a rule allowing HTTPS from 'any source' (which is functionally the same as from Internet) and a lower-priority deny rule, but the default deny rule already exists at the lowest priority, so an explicit deny rule is not needed and would be redundant.

432
MCQmedium

You need to design a network security solution for a hub-spoke topology. The hub contains Azure Firewall and Azure Bastion. Spoke VNets contain application workloads. You need to ensure that all traffic from the spokes to the internet is routed through the Azure Firewall. What should you configure?

A.Add a user-defined route (UDR) on the spoke subnets with 0.0.0.0/0 next hop to the Azure Firewall private IP.
B.Use service endpoints for internet-bound traffic.
C.Enable BGP on the spoke VNets and advertise a default route from the hub.
D.Configure the Azure Firewall to have a default route to the internet.
AnswerA

A user-defined route (UDR) overrides Azure's system default route for 0.0.0.0/0, which normally sends all outbound traffic directly to the internet. By associating a route table with the spoke subnets and setting the next hop to the Azure Firewall's private IP, every packet destined outside the VNet is explicitly forwarded to the firewall for stateful inspection, logging, and policy enforcement. This also prevents asymmetric routing because the firewall's return traffic is handled separately, and the route can be propagated via BGP if needed, but a static UDR is the direct mechanism in a VNet-peered hub-and-spoke design.

Why this answer

A user-defined route (UDR) with 0.0.0.0/0 and next hop set to the Azure Firewall's private IP forces all internet-bound traffic from spoke subnets to be routed through the firewall. This ensures traffic inspection and control by the firewall, which is a key requirement in a hub-spoke topology for centralized security.

Exam trap

The trap here is that candidates often confuse the need for a default route on the firewall itself (Option D) with the requirement to route traffic from spokes, forgetting that UDRs on spoke subnets are necessary to direct traffic to the firewall's private IP.

How to eliminate wrong answers

Option B is wrong because service endpoints provide direct, private connectivity to Azure PaaS services (e.g., Azure Storage, SQL Database) and do not route general internet traffic; they bypass the firewall for those specific services, which contradicts the requirement. Option C is wrong because BGP is used for dynamic routing in VPN or ExpressRoute scenarios, not for forcing default route propagation within Azure VNets; Azure does not support BGP on spoke VNets for default route advertisement to subnets. Option D is wrong because configuring a default route on the Azure Firewall itself (e.g., via route table on the firewall subnet) only defines the firewall's own outbound path, not the routing of traffic from spoke subnets; the spokes need explicit UDRs to direct traffic to the firewall.

433
Multi-Selectmedium

Which TWO are features of Microsoft Defender for Cloud's workload protection for Azure SQL databases? (Select two.)

Select 2 answers
A.File integrity monitoring (FIM)
B.Adaptive network hardening
C.Just-in-time VM access
D.Advanced threat protection (ATP)
E.Vulnerability assessment
AnswersD, E

Advanced threat protection (ATP) for Azure SQL is a built-in feature of Microsoft Defender for SQL that continuously monitors database activity for unusual access patterns, suspicious location changes, and potential SQL injection attempts. It generates security alerts for anomalies such as a user accessing the database from an unfamiliar IP address or an attempt to enumerate credentials. This makes ATP a correct choice because it directly protects SQL database workload.

Why this answer

Option D (Advanced threat protection/ATP) is correct because Microsoft Defender for Cloud's workload protection for Azure SQL databases includes Defender for SQL's advanced threat protection, which detects anomalous activities such as potential SQL injection, brute-force attempts, and unusual access patterns, and raises security alerts. Option E (Vulnerability assessment) is correct because Defender for SQL provides a built-in vulnerability assessment that scans Azure SQL databases for misconfigurations, missing security updates, and other weaknesses, with findings surfaced in Defender for Cloud. Option A (File integrity monitoring) is not correct here because FIM applies to files and registry keys on servers/VMs (via Defender for Servers/Log Analytics), not to Azure SQL database workload protection.

Option B (Adaptive network hardening) is not correct because it is a Defender for Cloud feature for virtual machines that analyzes network security group rules and traffic patterns, not a SQL database protection feature. Option C (Just-in-time VM access) is not correct because JIT VM access is a Defender for Servers capability that locks down management ports on VMs, not an Azure SQL database workload protection feature.

Exam trap

The trap here is that candidates often confuse workload protection features that apply broadly to VMs (like FIM, Adaptive Network Hardening, and JIT VM Access) with those specifically designed for PaaS services like Azure SQL, leading them to select options that are not applicable to databases.

434
MCQeasy

A company has an Azure virtual network with a single subnet that hosts web servers. The security team needs to allow inbound HTTPS traffic from the internet to the web servers, but block all other inbound traffic. They want to use a single Azure resource to accomplish this at the subnet level. Which resource should they configure?

A.Azure Firewall
B.Azure Front Door
C.Network Security Group (NSG)
D.Application Security Group (ASG)
AnswerC

An NSG contains inbound and outbound security rules that can be associated with a subnet or a network interface. By creating an allow rule for HTTPS (TCP 443) from Internet and a default deny-all rule, the requirement is met efficiently.

Why this answer

A Network Security Group (NSG) is the correct resource because it can be associated with a subnet to filter inbound traffic at Layer 3/4. By creating a rule that allows TCP port 443 (HTTPS) from the Internet service tag and a default deny-all rule, the NSG blocks all other inbound traffic while permitting HTTPS. This meets the requirement of a single Azure resource operating at the subnet level.

Exam trap

The trap here is that candidates often confuse Azure Firewall (a centralized, stateful service) with a simple subnet-level ACL, or they mistakenly think an Application Security Group can independently filter traffic, when in fact it only works as a source or destination in an NSG rule.

How to eliminate wrong answers

Option A is wrong because Azure Firewall is a managed, stateful firewall service that operates at the network and application layers (Layer 3-7) and is typically used for centralized traffic inspection, logging, and advanced filtering across multiple subnets or virtual networks; it is overkill and not the simplest single resource for a basic subnet-level ACL. Option B is wrong because Azure Front Door is a global, Layer 7 load balancer and application delivery controller that routes HTTP/HTTPS traffic based on the closest point of presence; it does not filter traffic at the subnet level and cannot block all other inbound traffic to the subnet. Option D is wrong because an Application Security Group (ASG) is a logical grouping of virtual machines by application workload, used in conjunction with NSG rules to simplify rule management; it is not a standalone filtering resource and cannot be directly associated with a subnet to enforce inbound traffic rules.

435
MCQeasy

Refer to the exhibit. You are assigning a built-in Azure Policy definition to a subscription using Azure CLI. The policy is 'Audit VMs that do not use managed disks'. After assignment, you check in Microsoft Defender for Cloud and see that the policy is not generating any recommendations. What is the most likely reason?

A.The policy effect is set to 'Audit', but it should be 'Deny' to generate recommendations.
B.The policy requires a managed identity to run.
C.The policy is not part of a Defender for Cloud security initiative.
D.The policy is assigned to the wrong subscription.
AnswerC

Defender for Cloud does not display recommendations for every individual policy assigned in the environment; it only generates recommendations from policies that belong to a security initiative, such as the Azure Security Benchmark, that is assigned to the subscription or management group. A standalone policy assigned directly to the subscription will produce compliance results in Azure Policy but will not appear as a security recommendation in Defender for Cloud. Therefore, the missing initiative membership explains why this policy's recommendations are not visible.

Why this answer

Microsoft Defender for Cloud only generates security recommendations from policies that are part of a built-in or custom security initiative (such as the 'Microsoft cloud security benchmark' initiative). A standalone policy assignment, even if it has the 'Audit' effect, will not appear as a recommendation in Defender for Cloud unless it is included in an initiative that Defender for Cloud monitors.

Exam trap

The trap here is that candidates assume any Azure Policy with an 'Audit' effect will automatically generate a recommendation in Defender for Cloud, but in reality, only policies that are part of a Defender for Cloud security initiative are surfaced as recommendations.

How to eliminate wrong answers

Option A is wrong because the 'Audit' effect is specifically designed to log non-compliant resources and generate compliance results; changing it to 'Deny' would block non-compliant VMs but would not cause recommendations to appear in Defender for Cloud. Option B is wrong because this particular built-in policy ('Audit VMs that do not use managed disks') does not require a managed identity; it uses the Azure Resource Manager to evaluate resource properties without needing to perform any action that requires authentication. Option D is wrong because if the policy were assigned to the wrong subscription, it would simply evaluate resources in that subscription (or fail to evaluate the intended ones), but it would not prevent recommendations from appearing in Defender for Cloud for the assigned subscription; the core issue is the lack of initiative membership, not the subscription scope.

436
MCQhard

A company has a hub-spoke network topology with Azure Firewall deployed in the hub virtual network. Spoke virtual networks are peered to the hub. The security team needs to ensure that all outbound internet traffic from virtual machines in a spoke subnet goes through the Azure Firewall. They have configured a route table on the spoke subnet with a default route (0.0.0.0/0) pointing to the Azure Firewall private IP address. However, traffic from spoke VMs is still bypassing the firewall and going directly to the internet. What is the most likely reason?

A.The route table is not associated with the spoke subnet.
B.Azure Firewall is not configured with DNAT rules for outbound traffic.
C.The spoke VNet peering does not allow gateway transit.
D.The route table has a higher priority than system routes.
AnswerA

A route table only takes effect when it is explicitly associated with a subnet. In this hub-spoke topology, the spoke subnet still has the default system routes, so traffic destined for the internet follows the default route and bypasses Azure Firewall. You must associate the custom route table—with a UDR that uses the firewall's private IP as the next hop and next hop type 'VirtualAppliance'—to the spoke subnet for forced tunneling to work.

Why this answer

The most likely reason is that the route table containing the default route (0.0.0.0/0) pointing to the Azure Firewall private IP has not been associated with the spoke subnet. Without this association, the subnet continues to use system routes, which include a default route to the internet via the Azure default gateway, allowing traffic to bypass the firewall. Associating the route table with the subnet is a required step to override the system default route.

Exam trap

The trap here is that candidates often assume creating a route table with the correct route is sufficient, forgetting that the route table must be explicitly associated with the subnet to take effect.

How to eliminate wrong answers

Option B is wrong because DNAT rules are used for inbound traffic (destination network address translation), not for controlling outbound traffic routing; outbound traffic through Azure Firewall is handled by forced tunneling via the route table, not DNAT. Option C is wrong because gateway transit is a setting for VPN/ExpressRoute gateway sharing in VNet peering, not for directing outbound internet traffic through a firewall in a hub; the spoke VNet does not need gateway transit to use a user-defined route pointing to the firewall's private IP. Option D is wrong because user-defined routes (UDRs) always have a higher priority than system routes by default; the issue is not priority but the lack of association of the route table to the subnet.

437
MCQmedium

You are reviewing the ARM template for an Azure Disk Encryption Set. The template includes the JSON snippet shown. You notice that the key version is empty. What is the consequence?

A.The encryption set will use a platform-managed key.
B.The encryption set will automatically use the latest version of the key.
C.The encryption set will use the key name without any version, causing it to fail.
D.The deployment will fail because a key version is required.
AnswerB

When the keyUrl in the Disk Encryption Set ARM template omits the key version, Azure treats the reference as pointing to the latest version of the named key. This enables automatic key rotation because, whenever a new version of the key is created in Key Vault, the DES will pick it up without requiring a template update or redeployment. This is the intended behavior for customer-managed keys on managed disks, as long as the key vault has soft-delete and purge protection enabled.

Why this answer

When the key version is omitted in an Azure Disk Encryption Set ARM template, the encryption set automatically uses the latest version of the key from the specified Azure Key Vault. This behavior allows the encryption set to stay updated with key rotations without requiring manual template updates, as Azure Disk Encryption Sets support automatic key version updates when no version is specified.

Exam trap

The trap here is that candidates often assume a missing key version will cause a deployment failure or fallback to platform-managed keys, but Azure explicitly supports versionless key references to enable automatic key rotation, which is a key security and compliance feature.

How to eliminate wrong answers

Option A is wrong because omitting the key version does not fall back to a platform-managed key; the encryption set still uses a customer-managed key from Key Vault, just without a pinned version. Option C is wrong because the key name without a version does not cause a failure; Azure interprets the missing version as a directive to use the latest version of that key. Option D is wrong because a key version is not required for deployment; the ARM template will deploy successfully and the encryption set will dynamically resolve to the current version of the key.

438
MCQmedium

Your company uses Azure SQL Database. You need to ensure that all queries are audited for compliance. Which feature should you enable?

A.Enable SQL Vulnerability Assessment.
B.Enable SQL Auditing on the server and configure the audit log destination.
C.Configure Dynamic Data Masking.
D.Enable Advanced Threat Protection.
AnswerB

SQL Auditing in Azure SQL Database tracks database events at the server or database level and writes them to a configurable destination such as Azure Storage, Log Analytics, or Event Hubs. By enabling it, you can capture exact T-SQL statements, the principal executing them, timestamps, and success/failure status, effectively logging queries for forensic and compliance purposes. The audit log can be customized via audit action groups to include SELECT, INSERT, UPDATE, DELETE, and other data operations, making this the only option that directly provides query-level logging.

Why this answer

To audit all queries against Azure SQL Database for compliance, you must enable SQL Auditing at the server level and configure an audit log destination (such as Azure Storage, Log Analytics, or Event Hubs). This captures database events, including all queries, and writes them to the chosen destination for review and retention. Option B directly fulfills the requirement to track and log query activity.

Exam trap

The trap here is that candidates often confuse security monitoring features (like Advanced Threat Protection or Vulnerability Assessment) with the specific auditing capability required to log all queries for compliance, leading them to select a feature that detects threats rather than records query history.

How to eliminate wrong answers

Option A is wrong because SQL Vulnerability Assessment is a service that scans for potential security misconfigurations and vulnerabilities, not a feature that logs or audits query execution. Option C is wrong because Dynamic Data Masking limits exposure of sensitive data by obfuscating it in query results, but it does not create an audit trail of who ran which queries. Option D is wrong because Advanced Threat Protection detects anomalous activities and potential threats (e.g., SQL injection), but it does not provide a comprehensive audit log of all queries for compliance purposes.

439
MCQmedium

Your company uses Microsoft Entra ID with a hybrid identity model. You need to implement a solution that allows you to block legacy authentication attempts while still allowing modern authentication protocols. What should you use?

A.Create a Conditional Access policy to block legacy authentication
B.Enable Security defaults
C.Use Identity Protection to detect legacy authentication
D.Configure MFA for all users
AnswerA

A Conditional Access policy can be configured with the 'Client apps' condition to specifically block legacy authentication (e.g., basic auth over POP, IMAP, SMTP, or Exchange ActiveSync) while allowing modern OAuth 2.0 and OpenID Connect-based client flows. This provides granular control, so you can set exclusions for service accounts or privileged users and combine with session controls like MFA or sign-in frequency. This is the only option that selectively targets the authentication protocol itself without altering the modern authentication experience.

Why this answer

Conditional Access policies in Microsoft Entra ID allow you to explicitly block legacy authentication protocols (such as POP3, IMAP, SMTP, and basic auth) while permitting modern authentication (OAuth 2.0, OpenID Connect). By targeting the 'Client apps' condition and selecting 'Exchange ActiveSync clients' and 'Other clients', you can block all legacy auth attempts without affecting modern protocol traffic. This is the precise, granular control required for a hybrid identity model.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based detection with the ability to block legacy authentication, or assume that enabling MFA alone will prevent legacy auth, when in fact legacy clients can still authenticate with just a password if the protocol is not explicitly blocked.

How to eliminate wrong answers

Option B is wrong because Security defaults enforces a blanket set of security baselines (including blocking legacy authentication for all users) but cannot be customized; it would block legacy auth for all users without the ability to selectively allow modern protocols or exclude specific accounts. Option C is wrong because Identity Protection detects and responds to risky sign-ins (e.g., leaked credentials, anonymous IP addresses) but does not block legacy authentication protocols; it is a risk-based detection tool, not a protocol-level enforcement mechanism. Option D is wrong because configuring MFA for all users forces multifactor authentication but does not inherently block legacy authentication; legacy clients that do not support MFA would still be able to authenticate using basic auth unless explicitly blocked.

440
MCQhard

A SOC analyst needs a Sentinel query that detects multiple failed sign-ins followed by a successful sign-in for the same user. Which table is the best primary source?

A.SecurityAlert
B.AzureActivity
C.DeviceNetworkEvents
D.SigninLogs
AnswerD

SigninLogs stores every Azure AD sign-in attempt, including both interactive and non-interactive logons, with detailed attributes such as `ResultType`, `ResultDescription`, `IPAddress`, and `UserPrincipalName`. By using a Kusto query to filter on error codes indicating failure (e.g., `ResultType != 0` or specific codes like `50053`), you can aggregate attempts with `summarize count() by UserPrincipalName` over a sliding time window to identify multiple failed logons. This is the definitive table for detecting brute-force or password-spray patterns in Azure Sentinel.

Why this answer

SigninLogs is the correct primary source because it captures both failed and successful user sign-in events from Azure AD, including interactive and non-interactive logins. This table provides the necessary fields like ResultType (e.g., 0 for success, 50125 for failure) and UserPrincipalName to build a KQL query that detects a sequence of failed sign-ins followed by a successful one for the same user.

Exam trap

The trap here is that candidates often confuse AzureActivity (which logs administrative actions) with sign-in logs, or assume SecurityAlert contains raw event data, when in fact only SigninLogs provides the granular authentication events needed for this detection pattern.

How to eliminate wrong answers

Option A is wrong because SecurityAlert contains pre-built security alerts (e.g., from Microsoft Defender for Cloud), not raw sign-in event logs, so it cannot be used to query individual sign-in success/failure sequences. Option B is wrong because AzureActivity logs control plane operations (e.g., resource creation, RBAC changes) and does not include user authentication events like sign-ins. Option C is wrong because DeviceNetworkEvents logs network-level events (e.g., connections, DNS queries) from Microsoft Defender for Endpoint, not Azure AD authentication events.

441
MCQmedium

Your organization uses Microsoft Entra ID for identity management. You need to ensure that users accessing sensitive data from unmanaged devices are required to use a compliant device. What should you configure?

A.Configure a device registration policy
B.Configure a Conditional Access policy that requires that the device be marked as compliant
C.Configure an Identity Protection policy for user risk
D.Configure a Conditional Access policy that requires multi-factor authentication
AnswerB

A Conditional Access policy evaluates device state at sign-in, and requiring the device be marked compliant enforces that only Intune-managed, policy-compliant devices reach the sensitive data. This directly satisfies the stem's constraint of blocking access from unmanaged devices.

Why this answer

A Conditional Access policy that requires the device to be marked as compliant ensures that only devices meeting your organization's compliance standards (e.g., antivirus enabled, encryption active) can access sensitive data. This policy evaluates device compliance status reported by Microsoft Intune or another MDM provider, and blocks or grants access based on that status. It directly addresses the requirement to enforce compliant device access from unmanaged devices.

Exam trap

The trap here is that candidates often confuse requiring MFA (Option D) with requiring device compliance, but MFA only verifies the user, not the device's security posture, which is the core requirement in this scenario.

How to eliminate wrong answers

Option A is wrong because a device registration policy only controls whether devices can be registered or joined to Entra ID, not whether they are compliant or can access sensitive data. Option C is wrong because an Identity Protection policy for user risk focuses on user sign-in risk (e.g., leaked credentials, anonymous IP) and does not evaluate device compliance status. Option D is wrong because a Conditional Access policy requiring multi-factor authentication strengthens authentication but does not enforce device compliance; an unmanaged device could still access data after MFA.

442
MCQmedium

A company has an Azure virtual network with multiple subnets. They want to centrally inspect and log all outbound traffic to the internet. They also need to allow or deny traffic based on domain names (FQDNs). Which Azure resource should they deploy?

A.Azure Firewall
B.Network Virtual Appliance (NVA) from Azure Marketplace
C.Azure Application Gateway with Web Application Firewall (WAF)
D.Azure Network Security Groups (NSGs)
AnswerA

Azure Firewall is a fully managed, cloud-native firewall that can filter outbound internet traffic using application rules based on destination FQDNs, allowing or denying requests by hostname rather than only IP. It captures comprehensive diagnostic logs via diagnostic settings to Azure Monitor, where you can query the AzureDiagnostics table for denied/allowed flows. This combination of FQDN-level control and centralized, queryable logging directly meets the stated requirement.

Why this answer

Azure Firewall is a managed, cloud-native network security service that provides centralized outbound traffic inspection and logging. It supports application rules based on fully qualified domain names (FQDNs), enabling allow or deny decisions for outbound traffic to the internet using Layer 7 (application layer) filtering, which meets both requirements directly.

Exam trap

The trap here is that candidates often confuse Azure Firewall with Network Security Groups, mistakenly thinking NSGs can filter by domain names because they associate 'network security' with all traffic control, but NSGs lack Layer 7 capabilities and cannot inspect or filter based on FQDNs.

How to eliminate wrong answers

Option B (NVA from Azure Marketplace) is wrong because, while an NVA can inspect and log traffic and filter by FQDNs, it is not a native Azure managed service; it requires manual deployment, maintenance, and scaling, and does not provide the same level of integrated logging and central management as Azure Firewall for this specific use case. Option C (Azure Application Gateway with WAF) is wrong because it is designed for inbound HTTP/HTTPS traffic load balancing and web application protection, not for outbound traffic inspection or domain-based filtering of all outbound internet traffic. Option D (Azure Network Security Groups) is wrong because NSGs operate at Layer 3/4 (network and transport layers) and cannot filter traffic based on domain names (FQDNs); they only support source/destination IP addresses, ports, and protocols.

443
Multi-Selectmedium

You are designing a network security solution for a multi-tier application. The web tier must be accessible from the internet, but the application and database tiers must be isolated. Which TWO configurations should you implement?

Select 2 answers
A.Use network security groups (NSGs) on each subnet
B.Deploy each tier in a separate VNet
C.Deploy each tier in a separate subnet
D.Use VNet peering to connect the tiers
E.Place all VMs in the same subnet
AnswersA, C

Network security groups apply stateful allow and deny rules at the subnet and NIC level, so the web tier accepts internet traffic while application and database subnets reject unsolicited inbound flows. This enforces the required tier isolation directly.

Why this answer

Option C is correct because placing each tier in its own subnet provides the network segmentation needed to isolate the application and database tiers from the internet-facing web tier, allowing you to apply distinct security rules per tier. Option A is correct because network security groups (NSGs) applied to each subnet let you enforce inbound and outbound rules that permit internet traffic only to the web tier while restricting the app and database tiers to internal traffic. Together, separate subnets plus per-subnet NSGs deliver the required multi-tier isolation.

Option B is not needed because separate VNets add complexity and require peering for tier-to-tier communication, which is unnecessary for isolation. Option D is incorrect because VNet peering connects VNets rather than isolating tiers within a single VNet. Option E is incorrect because placing all VMs in one subnet removes the segmentation boundary needed to isolate the app and database tiers.

Exam trap

The trap here is that candidates often assume separate VNets are required for isolation, but Azure's subnet-level NSGs provide the same isolation with lower complexity and cost, making separate subnets the correct approach.

444
MCQhard

You have an Azure subscription with multiple VNets connected via VNet peering. You need to audit all network traffic between two specific VNets for compliance. The solution must capture traffic metadata (source/destination IP, ports, protocol) without affecting performance. What should you use?

A.Route all traffic through Azure Firewall and enable logs.
B.Enable NSG flow logs and use Network Watcher traffic analytics.
C.Use Network Watcher packet capture on the VMs.
D.Enable Azure Monitor metrics on the VNet peering.
AnswerB

NSG flow logs capture IP-level traffic metadata (source and destination IP, port, protocol, and flow decisions like allowed/denied) for all flows passing through a network security group, with minimal performance overhead because they operate asynchronously in the Azure backbone. Network Watcher traffic analytics then ingests these logs into a Log Analytics workspace, applying machine learning and graph algorithms to surface inter-VNet communication patterns, top talkers, anomalous traffic, and cross-subnet dependencies. Together they deliver continuous, near-real-time flow visibility across multiple peered VNets without forcing traffic through a central appliance or requiring agent installation on each VM.

Why this answer

NSG flow logs capture metadata (source/destination IP, port, protocol) for traffic traversing a Network Security Group, and Network Watcher traffic analytics provides aggregated visibility into inter-VNet flows without inline inspection. This meets the compliance requirement for auditing metadata without performance impact, as flow logs are collected asynchronously and do not alter the data path.

Exam trap

The trap here is that candidates often confuse NSG flow logs (metadata-only, no performance impact) with packet capture (full payload, high overhead) or assume that Azure Firewall is required for any traffic auditing, when in fact flow logs provide the required metadata without inline inspection.

How to eliminate wrong answers

Option A is wrong because routing all traffic through Azure Firewall introduces a forced-tunneling inline inspection point that adds latency and cost, and it is not designed solely for metadata auditing without performance impact. Option C is wrong because Network Watcher packet capture on VMs captures full packet payloads, which is resource-intensive, affects VM performance, and is not suitable for continuous compliance auditing of metadata only. Option D is wrong because Azure Monitor metrics on VNet peering provide only aggregate statistics (e.g., bytes in/out) and do not capture per-flow metadata such as source/destination IP, port, or protocol.

445
Multi-Selectmedium

Which THREE of the following are valid methods to secure service principals in Microsoft Entra ID?

Select 3 answers
A.Use certificate-based credentials instead of client secrets
B.Assign the service principal to the Global Administrator role to monitor its activity
C.Configure Conditional Access for workload identities to restrict sign-in conditions
D.Enable Azure Multi-Factor Authentication for the service principal sign-in
E.Use Managed Identities for Azure resources to avoid managing credentials
AnswersA, C, E

Certificates rely on a public/private key pair: Azure AD stores and validates only the public key, while the private X.509 key stays protected in a certificate store or hardware security module. This removes shared client secrets from source code and configuration, and certificate expiry and rollover can be automated. Because a client secret is simply a string that can be copied or leaked, certificate-bound credentials provide substantially stronger authentication assurance for service principals.

Why this answer

Option A is correct because certificate-based credentials are a more secure alternative to client secrets for service principals; the public key is registered in Microsoft Entra ID and the private key is held by the app, so no shared secret is transmitted or stored, reducing the risk of credential theft. Option C is correct because Conditional Access for workload identities is a policy engine specifically designed to evaluate service principal sign-ins and can block or restrict them based on conditions such as location, risk, or IP range, which helps protect non-human identities. Option E is correct because Managed Identities for Azure resources let Azure create and rotate the service principal's credentials automatically, eliminating the need to store and manage secrets or certificates in code or configuration.

Option B is not appropriate because assigning a service principal the Global Administrator role grants excessive, unnecessary privileges and does not secure the principal; it increases risk. Option D is not valid because Azure Multi-Factor Authentication applies to interactive user sign-ins and cannot be enforced for a service principal, which authenticates non-interactively with secrets, certificates, or federated credentials.

Exam trap

The trap here is that candidates often confuse user identity security controls (like MFA) with workload identity security controls, assuming MFA can be applied to service principals, when in fact it cannot.

446
MCQmedium

A security analyst is using Microsoft Sentinel to detect multi-stage attacks. They want to create an analytics rule that correlates a user sign-in from an unusual location with a subsequent data exfiltration attempt from Azure Blob Storage within one hour. Which type of analytics rule should they use?

A.Scheduled query rule with entity mapping.
B.Fusion rule.
C.Microsoft Security incident rule.
D.Anomaly rule.
AnswerA

Scheduled query rules are the only listed Sentinel analytics rule type that execute custom KQL directly against Log Analytics workspace tables, so an analyst can write a query that joins storage logs, sign-in logs, and other data sources within a defined lookback window to detect multi-event sequences. Entity mapping is what turns query result rows into normalized alert entities—Account, Host, IP, URL—so Sentinel can enrich the incident, correlate related alerts, and pass machine-readable context to playbooks and investigations. This makes it the correct choice when the SOC needs custom detection logic that matches a specific attack pattern rather than relying on a built-in source alert.

Why this answer

A scheduled query rule with entity mapping is correct because it allows the security analyst to write a KQL query that correlates two distinct events—a sign-in from an unusual location and a subsequent data exfiltration from Azure Blob Storage—within a defined time window (one hour). Entity mapping enables the rule to link these events by common entities (e.g., user account or IP address), which is essential for detecting multi-stage attacks. This rule type runs on a schedule, making it ideal for time-bound correlation queries.

Exam trap

The trap here is that candidates often confuse Fusion rules (which also correlate events) with scheduled queries, but Fusion rules are limited to pre-built correlations from Microsoft security products, whereas scheduled queries allow custom KQL logic across any data source.

How to eliminate wrong answers

Option B (Fusion rule) is wrong because Fusion rules are designed to automatically correlate alerts from multiple Microsoft security products (e.g., Microsoft Defender for Cloud Apps, Azure AD Identity Protection) into a single incident, not to run custom KQL queries that correlate raw log data like sign-in logs and storage logs. Option C (Microsoft Security incident rule) is wrong because it creates incidents from alerts generated by Microsoft security services (e.g., Microsoft Defender for Endpoint), not from custom log analytics queries. Option D (Anomaly rule) is wrong because anomaly rules use machine learning to detect unusual patterns in a single data source over time, not to correlate two specific event types across different data sources within a fixed time window.

447
MCQeasy

You run the above PowerShell script. What is the effect on the storage account?

A.Block blobs with the prefix 'logs' are deleted after 30 days
B.Block blobs with the prefix 'logs' are deleted after 90 days
C.All block blobs are deleted after 30 days
D.Block blobs with the prefix 'logs' are moved to cool tier after 30 days
AnswerA

The script creates an Azure Storage lifecycle management rule with a filter that matches only block blobs whose name has the prefix 'logs', and the rule's action is Delete on the base blob after a period defined by DaysAfterModificationGreaterThan is set to 30. Therefore, any existing or future block blob under that prefix will be permanently removed once it has been last modified more than 30 days ago, matching the policy intent.

Why this answer

The PowerShell script uses `Add-AzStorageAccountManagementPolicyAction` with `-Action Delete` and `-DaysAfterCreationGreaterThan 30` on a filter that targets block blobs with the prefix 'logs'. This creates a lifecycle management policy rule that automatically deletes those blobs 30 days after their creation. The correct answer is A because the rule specifically applies to block blobs (not all blobs) with the 'logs' prefix and sets a deletion action after 30 days.

Exam trap

The trap here is that candidates often confuse the action type (Delete vs. TierToCool) or misread the prefix filter, assuming the rule applies to all blobs instead of only those with the 'logs' prefix.

How to eliminate wrong answers

Option B is wrong because the script specifies `-DaysAfterCreationGreaterThan 30`, not 90, so blobs are deleted after 30 days, not 90. Option C is wrong because the filter uses `-BlobType 'BlockBlob'` and `-PrefixMatch 'logs'`, so the rule applies only to block blobs with the 'logs' prefix, not all block blobs. Option D is wrong because the action is `-Action Delete`, not `-Action TierToCool`; moving to cool tier would require a different action type.

448
MCQhard

An organization wants to detect when a privileged Azure role assignment is created outside the approved change window. Which log source should a Sentinel rule query?

A.Heartbeat
B.AzureActivity
C.Perf
D.StorageBlobLogs
AnswerB

The AzureActivity table is the Log Analytics destination for the Azure Activity Log, which captures all control plane (Azure Resource Manager) events, including Microsoft.Authorization/roleAssignments/write operations. When a privileged role assignment is created, this write operation is logged there, allowing you to build a log alert or query to detect it. This makes AzureActivity the directly relevant and correct data source for the stated requirement.

Why this answer

AzureActivity logs capture all control-plane operations on Azure resources, including role assignment creations (e.g., 'Microsoft.Authorization/roleAssignments/write'). By querying AzureActivity in a Sentinel rule, you can detect when a privileged role assignment is made outside an approved change window. Heartbeat, Perf, and StorageBlobLogs do not record Azure RBAC changes.

Exam trap

The trap here is that candidates may confuse data-plane logs (StorageBlobLogs) or agent health logs (Heartbeat, Perf) with control-plane activity logs, failing to recognize that only AzureActivity captures RBAC changes at the subscription scope.

How to eliminate wrong answers

Option A is wrong because Heartbeat logs are used for agent health monitoring and do not contain Azure RBAC activity. Option C is wrong because Perf logs contain performance counters (CPU, memory, disk) and have no role assignment data. Option D is wrong because StorageBlobLogs record data-plane operations on blob storage (e.g., reads, writes) and not control-plane role assignments.

449
MCQeasy

Your organization wants to ensure that users accessing Office 365 from outside the corporate network must use MFA. What is the most efficient way to enforce this?

A.Enable MFA for all users in Microsoft Entra ID.
B.Create a Conditional Access policy for all cloud apps with location condition.
C.Use Conditional Access with device compliance condition.
D.Create a Conditional Access policy for Office 365 with location condition and require MFA.
AnswerD

Create a Conditional Access policy that targets the Office 365 cloud app, sets the location condition to include an untrusted named location or exclude trusted corporate IP ranges, and grants access only when MFA is satisfied. Because the scope is limited to the Office 365 application and an external location condition, internal users on the corporate trusted network are not subjected to MFA prompts, while external accesses to Exchange Online, SharePoint Online, and Teams are challenged. This is the least-privilege approach that precisely matches the stated requirement.

Why this answer

It specifically targets Office 365 cloud apps and uses the location condition to restrict MFA enforcement to access from outside the corporate network. This is the most efficient approach as it applies only to the relevant application and network location, minimizing user friction while meeting the requirement exactly.

Exam trap

The trap here is that candidates often choose a broad policy (Option B) thinking it covers all scenarios, but the question specifically asks for Office 365, so the most efficient solution targets only that app to avoid unnecessary MFA prompts on other cloud services.

How to eliminate wrong answers

Option A is wrong because enabling MFA for all users globally forces MFA on every sign-in, including from inside the corporate network, which is overly broad and inefficient. Option B is wrong because creating a Conditional Access policy for all cloud apps with a location condition would enforce MFA on every cloud app (e.g., Azure Portal, Dynamics 365), not just Office 365, which is unnecessary and may disrupt non-Office 365 workflows. Option C is wrong because using a device compliance condition enforces MFA based on device health rather than network location, failing to address the specific requirement of enforcing MFA only for external access.

450
MCQmedium

Refer to the exhibit. You are reviewing the encryption configuration of an Azure Log Analytics workspace used by Microsoft Sentinel. The configuration shows infrastructure encryption enabled and customer-managed key (CMK) from Azure Key Vault. What additional step must be taken to ensure that the CMK is used for all data?

A.Enable double encryption on Sentinel
B.Enable purge protection on the Key Vault
C.Grant the Log Analytics workspace access to the Key Vault key
D.Ensure the Key Vault is in a different region than the workspace
AnswerC

For Sentinel to use a customer-managed key, the Log Analytics workspace that stores Sentinel data must present a managed identity and be granted explicit cryptographic permissions on the Key Vault key. Specifically, the workspace needs Key Vault operations such as Get, WrapKey, and UnwrapKey to encrypt and decrypt the workspace's data encryption key. This access is granted through a Key Vault access policy, so provisioning that policy is the correct remediation.

Why this answer

When you configure a customer-managed key (CMK) for a Log Analytics workspace, you must explicitly grant the workspace (via its managed identity) the 'Get', 'Unwrap Key', and 'Wrap Key' permissions on the Key Vault key. Without this access, the workspace cannot use the CMK to encrypt data at rest. Option C correctly identifies this required step.

Exam trap

The trap here is that candidates often confuse enabling CMK with simply selecting a key from Key Vault, forgetting that the workspace must be explicitly granted cryptographic permissions on that key to actually use it for encryption.

How to eliminate wrong answers

Option A is wrong because 'double encryption' is not a configurable setting in Microsoft Sentinel; infrastructure encryption already provides encryption at the storage layer, and enabling CMK adds a second layer, but no separate 'double encryption' toggle exists. Option B is wrong because purge protection is a Key Vault soft-delete feature that prevents permanent deletion of keys, but it does not affect whether the workspace can use the CMK for encryption. Option D is wrong because the Key Vault can be in any region; there is no requirement for it to be in a different region than the workspace, and placing it in a different region would add latency without any security benefit.

Page 5

Page 6 of 9

Page 7

All pages