Courseiva

Microsoft Azure Security Engineer Associate AZ-500 (AZ-500) — Questions 451–525

617 questions total · 9pages · All types, answers revealed

Page 6

Page 7 of 9

Page 8
451
MCQmedium

A company uses Microsoft Defender for Cloud to monitor its security posture. The compliance team wants to receive email notifications immediately when a control in the ISO 27001 regulatory compliance standard fails. They want to be alerted only when specific controls change from 'compliant' to 'non-compliant'. Which feature should they configure?

A.Security Alerts from Microsoft Defender for Cloud
B.Regulatory Compliance dashboard with continuous export
C.Workflow automation based on regulatory compliance assessment changes
D.Custom recommendations in Microsoft Defender for Cloud
AnswerC

Workflow automation in Microsoft Defender for Cloud is the native mechanism to react to changes in regulatory compliance assessments. You configure an automation rule to watch for a specific assessment status change (e.g., a control failing) and then invoke a Logic App or Power Automate flow to send an email, post to Teams, or create a ticket. This provides the proactive notification (e.g., email) required by the scenario. It is the only built-in way to directly trigger external actions based on compliance assessment changes.

Why this answer

Workflow automation in Microsoft Defender for Cloud can be configured to trigger based on regulatory compliance assessment changes, specifically when a control transitions from 'compliant' to 'non-compliant'. This allows the compliance team to receive immediate email notifications for ISO 27001 control failures without manual polling or dashboard monitoring.

Exam trap

The trap here is that candidates often confuse Security Alerts (which are threat-focused) with compliance state change notifications, or assume the Regulatory Compliance dashboard's continuous export can directly send real-time email alerts, but it only exports data to external sinks without built-in notification logic.

How to eliminate wrong answers

Option A is wrong because Security Alerts in Defender for Cloud are triggered by threat detection events (e.g., suspicious activities, vulnerabilities), not by regulatory compliance control state changes. Option B is wrong because the Regulatory Compliance dashboard with continuous export sends data to Log Analytics or Event Hubs for archival and analysis, but it does not natively support immediate email notifications based on specific control state transitions. Option D is wrong because custom recommendations are used to define additional security best practices or policies, not to trigger notifications on compliance control changes.

452
MCQhard

Your company has an Azure subscription with a hub-spoke network topology. The hub contains an Azure Firewall and a VPN gateway for on-premises connectivity. The spoke virtual network hosts a critical application. You need to ensure that all outbound traffic from the spoke to the internet and on-premises networks flows through the Azure Firewall. You configure a user-defined route (UDR) on the spoke subnet with the default route (0.0.0.0/0) pointing to the Azure Firewall private IP. However, traffic to on-premises still bypasses the firewall. What is the most likely cause?

A.The on-premises traffic uses a more specific route learned via BGP from the VPN gateway, which overrides the UDR
B.The UDR must be applied to the subnet that hosts the Azure Firewall
C.The spoke subnet does not have 'GatewaySubnet' route propagation enabled
D.The Azure Firewall is not configured with a route to the on-premises network
AnswerA

BGP-learned routes for on-premises networks are more specific than 0.0.0.0/0. They will be used even if a UDR for 0.0.0.0/0 exists. To force through firewall, you must either disable BGP route propagation or create specific UDRs for on-premises ranges.

Why this answer

The most likely cause is that the on-premises traffic uses a more specific route learned via BGP from the VPN gateway, which overrides the user-defined route (UDR). In Azure, when a UDR and a BGP-propagated route both match traffic, the route with the most specific prefix (longest prefix match) wins. Since on-premises networks are typically advertised with specific IP prefixes (e.g., 10.0.0.0/16) rather than 0.0.0.0/0, the BGP-learned routes take precedence, causing traffic to bypass the Azure Firewall.

Exam trap

The trap here is that candidates assume a default route (0.0.0.0/0) UDR will always override all other routes, but Azure's route selection uses longest prefix match, so more specific BGP-learned routes for on-premises networks will take precedence over the default UDR.

How to eliminate wrong answers

Option B is wrong because the UDR must be applied to the subnet where the workload (spoke) resides, not to the Azure Firewall subnet; the firewall subnet itself uses system routes or BGP for its own traffic. Option C is wrong because 'GatewaySubnet' route propagation is not a property of the spoke subnet; it is a setting on the virtual network gateway subnet, and disabling it would not affect UDR precedence over BGP routes. Option D is wrong because the Azure Firewall does not need a specific route to the on-premises network; it only needs to be the next hop for traffic, and the issue is that traffic is not reaching the firewall due to BGP route override, not a missing route on the firewall.

453
MCQeasy

You are configuring Azure Private Link for a SQL Database. You want to ensure that all traffic from your virtual network to the SQL Database stays within the Microsoft Azure backbone network. What is the primary benefit of using Azure Private Link over a service endpoint?

A.Private Link provides higher throughput than service endpoints.
B.Private Link assigns a private IP address to the SQL Database within your virtual network, preventing exposure to the public internet.
C.Private Link enables access to the SQL Database from on-premises via VPN/ExpressRoute without traversing the internet.
D.Private Link allows you to use NSGs to filter traffic to the SQL Database.
AnswerB

Private Link creates a private endpoint, which is a network interface with a private IP address assigned from your virtual network's subnet. When you connect to the SQL Database's FQDN, traffic is resolved and sent to this private IP, bypassing the public endpoint entirely. Combined with the 'Deny public network access' setting, the database is not reachable from the internet.

Why this answer

Azure Private Link exposes the SQL Database as a private endpoint within your virtual network, assigning it a private IP address from your VNet's address space. This ensures that all traffic to the database stays on the Microsoft backbone network and never traverses the public internet, which is the primary benefit over a service endpoint. Service endpoints still route traffic to the public endpoint of the SQL Database, even though the source traffic originates from the VNet.

Exam trap

The trap here is that candidates often confuse service endpoints with Private Link, thinking both provide the same level of isolation, but service endpoints still route to the public endpoint of the Azure service, whereas Private Link assigns a private IP and completely removes public internet exposure.

How to eliminate wrong answers

Option A is wrong because Private Link does not inherently provide higher throughput than service endpoints; throughput is determined by the database tier and network path, not the connectivity method. Option C is wrong because both Private Link and service endpoints can be used with VPN/ExpressRoute to access SQL Database from on-premises without traversing the internet, so this is not a unique benefit of Private Link. Option D is wrong because NSGs can filter traffic to the SQL Database when using service endpoints as well, via service tags, so this is not a distinguishing benefit of Private Link.

454
MCQeasy

You need to restrict access to a web app hosted on Azure App Service so that only traffic from a specific virtual network (VNet) is allowed. Which Azure service should you configure?

A.Azure Application Gateway
B.Azure Front Door
C.App Service access restrictions
D.Azure Firewall
AnswerC

App Service access restrictions are the built-in, platform-level feature that lets you control inbound traffic to your web app by allowing or denying accesses from specific IP addresses, IP CIDR ranges, or virtual network service endpoints. These rules are evaluated at the front-end of the App Service, blocking unauthorized requests before they reach your code. By combining a default 'deny' rule with explicit 'allow' rules, you can precisely limit access to selected sources, making this the correct feature for the requirement.

Why this answer

App Service access restrictions allow you to define an allow/deny list of IP addresses or virtual network (VNet) sources directly at the App Service level. By configuring a VNet integration and a service endpoint or private endpoint, you can restrict inbound traffic to only originate from a specific VNet, without needing an additional network appliance.

Exam trap

The trap here is that candidates often confuse Azure Firewall or Application Gateway as the required service for VNet-only access, but the native App Service access restrictions feature is the simplest and most direct way to achieve this without additional cost or complexity.

How to eliminate wrong answers

Option A is wrong because Azure Application Gateway is a Layer 7 load balancer and web application firewall (WAF) that can route traffic to App Service, but it does not natively restrict traffic to a specific VNet; it would require additional network rules and does not replace the VNet-level access control. Option B is wrong because Azure Front Door is a global content delivery network (CDN) and application accelerator that operates at the edge; it cannot restrict traffic to a specific VNet as it routes over the public internet and does not integrate with VNet service endpoints. Option D is wrong because Azure Firewall is a managed, cloud-based network security service that filters traffic at the network and application layers, but it is not directly configurable to restrict access to an App Service from a specific VNet without complex routing and is not the native App Service access control mechanism.

455
MCQeasy

A company has a virtual network in Azure with a subnet that hosts a web application. They want to allow inbound HTTPS traffic only from a specific source IP range (198.51.100.0/24). They are using Network Security Groups (NSGs) associated with the subnet. What is the minimal set of inbound security rules required?

A.One inbound rule: Allow TCP port 443 from source '198.51.100.0/24'
B.Two inbound rules: one to allow HTTPS, and one to deny all other traffic
C.Three inbound rules: allow HTTPS, allow RDP for management, and deny all
D.One inbound rule: Allow TCP port 443 from source 'Any' and a separate rule to deny from '198.51.100.0/24'
AnswerB

Correct. The minimal set is two rules: an allow rule for HTTPS from 198.51.100.0/24 with high priority, and a deny-all inbound rule with sufficiently high priority to override the default allow rules, ensuring only traffic from the specified IP range is allowed.

Why this answer

Network Security Groups (NSGs) contain default inbound security rules: AllowVNetInBound (priority 65000) and AllowAzureLoadBalancerInBound (priority 65001). These default rules would permit HTTPS traffic from sources within the virtual network or from Azure Load Balancer, violating the requirement to allow HTTPS only from the specific IP range 198.51.100.0/24. Therefore, an explicit deny-all rule must be added with a higher priority (lower numerical value) than the default allow rules to block all other traffic, including that from VNet and Azure Load Balancer.

The minimal set is: one rule to allow HTTPS from 198.51.100.0/24 (high priority), and one rule to deny all inbound traffic from any source (at a slightly lower priority but still above the default rules). Option A is insufficient because it relies on the default deny rule (priority 65500), which is processed after the default allow rules, so VNet and Load Balancer traffic would still be permitted.

Exam trap

The trap is that candidates assume the default deny rule implicitly blocks all unwanted traffic, but they forget that NSGs also have default allow rules for virtual network and Azure Load Balancer traffic. These default allow rules have higher priority than the default deny rule, so traffic from those sources would be allowed unless explicitly denied. Therefore, to restrict traffic to a specific external IP range, an explicit deny rule is needed to override those default allows.

How to eliminate wrong answers

Option B is wrong because it includes an explicit 'deny all' rule, which is redundant and unnecessary — NSGs already have an implicit deny rule at the end of the rule list, so adding another deny rule does not change behavior and violates the 'minimal set' requirement. Option C is wrong because it adds an RDP rule (TCP 3389) that is not required by the scenario and would allow management traffic beyond the specified HTTPS-only restriction, plus the explicit deny is again redundant. Option D is wrong because it allows HTTPS from 'Any' (which violates the requirement to restrict to 198.51.100.0/24) and then attempts to deny that same source range, which would be ineffective since the allow rule has higher priority (lower number) than the deny rule, and the deny rule would block the very traffic you want to allow.

456
MCQmedium

You have an Azure Application Gateway v2 with WAF policy in prevention mode to protect a web app. Users report that legitimate requests are being blocked. You review the WAF logs and see many false positives. You need to resolve this while maintaining security. What should you do?

A.Add a custom rule to block all requests that do not match a known pattern.
B.Use managed rule sets with custom rules to allow the legitimate traffic that is being falsely blocked.
C.Disable the WAF and rely on NSGs.
D.Switch the WAF policy to detection mode.
AnswerB

Managed rule sets (for example, OWASP 3.2) can produce false positives when a benign request carries content that looks like SQL injection or cross-site scripting. Because custom rules are evaluated before managed rules in Application Gateway v2, a custom rule with action Allow can explicitly whitelist the legitimate traffic by matching on specific attributes such as URI path, headers, source IP, or query string values; the Allow action stops further evaluation, so the managed rule's Block action is not applied to that request. This lets you keep managed protection active while surgically correcting false positives.

Why this answer

Azure Application Gateway WAF allows you to use managed rule sets (e.g., OWASP 3.2) and then add custom rules to explicitly allow traffic that is being falsely blocked. This approach maintains the WAF in prevention mode, ensuring that true threats are still blocked, while overriding false positives for specific request patterns (e.g., based on URI, headers, or source IP). Custom rules are evaluated before managed rules, so you can create an 'allow' rule with a higher priority to bypass the false positive detection.

Exam trap

The trap here is that candidates often think switching to detection mode (Option D) is a safe compromise, but the question explicitly requires maintaining security, and detection mode does not block any threats, making it an incorrect choice.

How to eliminate wrong answers

Option A is wrong because blocking all requests that do not match a known pattern would likely block even more legitimate traffic and is overly restrictive, not resolving the false positive issue. Option C is wrong because disabling the WAF entirely removes all web application firewall protection, leaving the app vulnerable to attacks that NSGs (which operate at the network layer) cannot mitigate, such as SQL injection or XSS. Option D is wrong because switching to detection mode only logs alerts without blocking traffic, which fails to maintain security as the question requires resolving false positives while keeping protection active.

457
MCQmedium

A company has an on-premises web application that they want to expose to external users over the internet without requiring a VPN. External users must authenticate with Modern Authentication (e.g., using Azure Multi-Factor Authentication) and access policies must be enforced via Conditional Access. The application does not support SAML or OAuth. Which Azure service should they use to publish this application securely?

A.Azure AD B2C (Business-to-Consumer).
B.Azure Application Gateway with Web Application Firewall (WAF).
C.Azure AD Application Proxy.
D.Azure Front Door.
AnswerC

Azure AD Application Proxy is the appropriate service here because it is purpose-built to publish on-premises HTTP/HTTPS apps to external users through Azure AD. A lightweight connector installed on the corporate network establishes an outbound connection to the Azure AD Application Proxy service, eliminating the need for inbound firewall ports or a VPN; the external endpoint is an Azure AD URL that performs full Azure AD pre-authentication, including MFA and Conditional Access, before passing the authenticated request back through the connector to the internal web application. It effectively acts as an HTTPS reverse proxy bridged by an outbound-only tunnel, which is exactly what is required to securely expose an on-premises web app without making it publicly reachable.

Why this answer

Azure AD Application Proxy is the correct choice because it allows publishing on-premises web applications to external users without requiring a VPN, supports Modern Authentication (including Azure MFA), and enforces Conditional Access policies. It works by installing a connector on-premises that proxies traffic through Azure AD, enabling authentication and policy enforcement even for legacy applications that do not support SAML or OAuth.

Exam trap

The trap here is that candidates often confuse Azure AD Application Proxy with Azure Application Gateway, assuming that WAF provides authentication, but Application Gateway does not integrate with Azure AD for Modern Authentication or Conditional Access enforcement.

How to eliminate wrong answers

Option A is wrong because Azure AD B2C is designed for customer-facing identity management with social logins and custom policies, not for publishing internal on-premises applications with Conditional Access enforcement. Option B is wrong because Azure Application Gateway with WAF provides layer 7 load balancing and web application firewall protection but does not handle Modern Authentication or Conditional Access policies for legacy apps. Option D is wrong because Azure Front Door is a global load balancer and CDN service that accelerates web traffic but does not provide identity-based authentication or Conditional Access integration for on-premises applications.

458
Multi-Selectmedium

Which TWO actions can you perform using Microsoft Defender for Cloud's regulatory compliance dashboard? (Select two.)

Select 2 answers
A.Create custom regulatory compliance recommendations.
B.Automatically remediate non-compliant resources.
C.View the compliance status for built-in standards like SOC 2 or PCI DSS.
D.Assign a compliance standard (e.g., SOC 2) to a subscription.
E.Enable or disable Microsoft Defender plans for a subscription.
AnswersC, D

The regulatory compliance view in Microsoft Defender for Cloud displays a continuous assessment of Azure resources against built-in regulatory standards such as SOC 2, PCI DSS, ISO 27001, and GDPR. For each assigned standard, the dashboard shows controls, policy mappings, and pass/fail status, making it the primary interface for monitoring compliance posture across subscriptions. This is a read-only visibility function, distinct from modifying standards or plans.

Why this answer

The regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built view of compliance status against built-in standards such as SOC 2, PCI DSS, ISO 27001, and Azure CIS. This dashboard aggregates security assessments and displays pass/fail status for each control, allowing you to track your compliance posture without manual configuration.

Exam trap

The trap here is that candidates often confuse the regulatory compliance dashboard's ability to assign standards (which is correct) with the ability to create custom recommendations or auto-remediate, which are separate functions handled by Azure Policy and Defender for Cloud's security recommendations, not the compliance dashboard itself.

459
MCQhard

A company has virtual networks in East US and West US connected via global VNet peering. The security policy requires that all traffic between the peered VNets be encrypted using IPsec. Which action should the company take to meet this requirement?

A.Enable the 'Allow gateway transit' setting on the VNet peering.
B.Deploy an Azure VPN Gateway in each VNet and create a site-to-site VPN connection between them.
C.Enable 'Use remote gateways' on the VNet peering.
D.Configure Azure Firewall to encrypt the traffic between the VNets.
AnswerB

Deploying an Azure VPN Gateway in each VNet and creating a site-to-site VPN connection (also supported via the VNet-to-VNet connection type) establishes IPsec/IKE tunnels that encrypt the traffic in transit between the two virtual networks. The VPN gateways negotiate security associations and encapsulate packets, ensuring confidentiality and integrity of traffic crossing between the regions. This is the only option that actively provides the IPsec encryption the scenario requires.

Why this answer

VNet peering does not encrypt traffic between peered virtual networks by default; it relies on the Microsoft backbone network. To enforce IPsec encryption for all traffic between the peered VNets, you must deploy an Azure VPN Gateway in each VNet and configure a site-to-site VPN connection between them. This creates an encrypted tunnel using IPsec/IKE protocols, satisfying the security policy requirement.

Exam trap

The trap here is that candidates assume VNet peering inherently encrypts traffic or that Azure Firewall can enforce encryption, but neither is true; only a VPN gateway provides IPsec encryption between VNets.

How to eliminate wrong answers

Option A is wrong because enabling 'Allow gateway transit' on VNet peering allows one VNet to use the other VNet's VPN gateway for connectivity to on-premises networks, but it does not encrypt traffic between the peered VNets themselves. Option C is wrong because 'Use remote gateways' is used when a spoke VNet wants to use the hub VNet's gateway for transit, not to encrypt traffic between the peered VNets. Option D is wrong because Azure Firewall is a stateful firewall that filters traffic but does not provide IPsec encryption; it cannot encrypt traffic between VNets.

460
Multi-Selecthard

Which TWO of the following are valid ways to encrypt data at rest in Azure SQL Database? (Choose two.)

Select 2 answers
A.Dynamic Data Masking
B.Transparent Data Encryption (TDE)
C.Row-Level Security
D.Always Encrypted
E.Azure Disk Encryption (ADE)
AnswersB, D

Transparent Data Encryption performs real-time encryption and decryption of the database, backups, and transaction logs at rest using a symmetric database encryption key, with no application changes. It satisfies the at-rest encryption requirement natively at the storage layer.

Why this answer

Transparent Data Encryption (TDE) [B] is correct because it performs real-time encryption and decryption of the database, associated backups, and transaction log files at rest using a symmetric database encryption key (DEK) protected by a certificate stored in Azure Key Vault or the service-managed key store, directly satisfying the data-at-rest requirement. Always Encrypted [D] is also correct because it encrypts sensitive columns at rest and in memory, with keys held outside the database (in Windows Certificate Store or Azure Key Vault), so the data stored on disk is ciphertext and never exposed to the SQL Database engine. Dynamic Data Masking [A] is not encryption — it merely obfuscates column values in query results for non-privileged users while the underlying data remains plaintext.

Row-Level Security [C] restricts which rows a user can access via predicates but does not encrypt stored data. Azure Disk Encryption (ADE) [E] is not applicable to Azure SQL Database because it targets IaaS virtual machine OS and data disks (BitLocker/DM-Crypt), not the PaaS SQL Database service.

Exam trap

Candidates often confuse Dynamic Data Masking or Row-Level Security with encryption at rest. Another common trap is assuming Azure Disk Encryption applies to Azure SQL Database when it is actually for Azure VMs (IaaS).

461
MCQhard

A company stores sensitive data in Azure Blob Storage. They want to enforce encryption at rest using a customer-managed key (CMK) stored in Azure Key Vault. Additionally, they require that the key vault be in a different region than the storage account to protect against regional disasters. Can this be achieved, and if so, what is the implication?

A.Yes, but the storage account must use a different key vault per region; no other implications.
B.Yes, but you must enable cross-region replication for the key vault and pay additional costs.
C.No, Azure does not support CMK from a different region than the storage account.
D.Yes, but you must use a managed identity from the storage account's region to access the key vault.
AnswerC

Correct. Azure Storage customer-managed keys require the key vault (or managed HSM) to be in the same Azure region as the storage account. Azure Key Vault is a regional service, and the key material cannot be used for encryption operations outside that region, so a CMK from a different region is simply not supported. This is a documented architectural constraint, and no configuration or feature—such as geo-replication or multi-region vaults—bypasses this requirement.

Why this answer

Azure Blob Storage encryption with customer-managed keys (CMK) requires the key vault to reside in the same Azure region as the storage account. This is a hard platform constraint because the storage account's encryption service must communicate with the key vault over the regional boundary to wrap/unwrap the data encryption key (DEK) using the customer-managed key (KEK). Cross-region CMK is not supported, making option C the correct answer.

Exam trap

The trap here is that candidates assume Azure's global infrastructure allows cross-region key vault access for CMK, but Azure explicitly restricts CMK to the same region to maintain low-latency encryption operations and avoid cross-region dependency for data at rest.

How to eliminate wrong answers

Option A is wrong because it incorrectly states that a different key vault per region is acceptable; Azure does not allow CMK from a different region at all, regardless of the number of key vaults. Option B is wrong because cross-region replication for the key vault does not enable cross-region CMK usage—the storage account's encryption service still requires the key vault to be in the same region, and Azure does not offer a feature to bypass this restriction. Option D is wrong because while a managed identity is required for the storage account to access the key vault, it does not override the regional constraint; the key vault must still be in the same region as the storage account.

462
MCQhard

A Sentinel scheduled rule runs every 5 minutes and looks back 1 hour. Analysts see repeated alerts for the same event. Which change best prevents duplicate detections without missing late-arriving logs?

A.Reduce the query lookback to 1 minute
B.Use an ingestion-time or event-time exclusion window in the query
C.Disable alert grouping
D.Change the workspace retention period
AnswerB

Adding a filter such as `where ingestion_time() > ago(5m)` or comparing an event-time column to the previous run's execution time creates an exclusion window in the KQL query. This ensures each scheduled run only evaluates events that are new since the last run, while keeping the original lookback for late-arriving telemetry. As a result, the query is idempotent and the same underlying event will not trigger a new alert in every 5-minute execution. This is the recommended way to meet the stated requirement directly.

Why this answer

Using an ingestion-time or event-time exclusion window in the query allows the rule to skip events that have already generated an alert within a specific time range, preventing duplicate detections while still accommodating late-arriving logs. This approach leverages the query logic to filter out duplicates based on a time-based deduplication key, ensuring that only new or unique events trigger alerts without altering the lookback period.

Exam trap

The trap here is that candidates often confuse reducing the lookback period (Option A) as a quick fix, not realizing it will miss late-arriving logs, while the correct solution uses a query-level exclusion window that preserves the lookback for completeness.

How to eliminate wrong answers

Option A is wrong because reducing the query lookback to 1 minute would cause the rule to miss late-arriving logs that arrive after the initial 5-minute run window, defeating the purpose of the 1-hour lookback and potentially missing critical events. Option C is wrong because disabling alert grouping would not prevent duplicate detections; it would simply stop grouping similar alerts into a single incident, potentially increasing alert noise without addressing the root cause of repeated alerts for the same event. Option D is wrong because changing the workspace retention period affects how long data is stored, not how alerts are deduplicated or how queries handle late-arriving logs, so it has no impact on duplicate alert prevention.

463
MCQmedium

Refer to the exhibit. You run the PowerShell command above and get the output: Access: Allow, SourceAddressPrefix: *, DestinationAddressPrefix: VirtualNetwork, DestinationPortRange: 22, Protocol: TCP, Priority: 100. A security audit requires that SSH access be restricted to only the management subnet (10.0.1.0/24). What should you do?

A.Change the SourceAddressPrefix to '10.0.1.0/24'.
B.Change the DestinationAddressPrefix to '10.0.1.0/24'.
C.Change the Access to Deny and create a new rule to allow SSH from management subnet.
D.Change the SourceAddressPrefix to 'VirtualNetwork'.
AnswerA

Changing SourceAddressPrefix to '10.0.1.0/24' correctly scopes the inbound SSH rule so that only clients from the management subnet can initiate connections to port 22. In an NSG rule, the source address prefix explicitly controls the allowable origin of traffic, and this change restricts the rule to the intended administrative range. This is the minimal and proper modification to enforce the stated network security requirement.

Why this answer

The existing rule allows SSH (TCP port 22) from any source (*) to the virtual network. To restrict SSH access to only the management subnet (10.0.1.0/24), you must change the SourceAddressPrefix from '*' to '10.0.1.0/24'. This ensures only traffic originating from the management subnet is permitted, meeting the security audit requirement.

Exam trap

The trap here is that candidates often confuse SourceAddressPrefix and DestinationAddressPrefix, mistakenly thinking that changing the destination restricts the source, or they overcomplicate the solution by adding a deny rule instead of simply modifying the existing rule's source.

How to eliminate wrong answers

Option B is wrong because changing the DestinationAddressPrefix to '10.0.1.0/24' would restrict the destination of SSH traffic to the management subnet itself, not the source, which does not limit which clients can initiate SSH connections. Option C is wrong because changing the Access to Deny would block all SSH traffic, and creating a new allow rule for the management subnet would be redundant and could cause confusion; instead, you should modify the existing rule's source. Option D is wrong because changing the SourceAddressPrefix to 'VirtualNetwork' would allow SSH from any virtual network in the same region, which is broader than the required management subnet and does not enforce the specific /24 restriction.

464
MCQeasy

Your organization is using Azure Database for MySQL. You need to ensure that only traffic from Azure services and specific client IP addresses can connect to the database. What should you configure?

A.Azure Active Directory authentication
B.Virtual Network service endpoints
C.Network Security Group (NSG) rules on the subnet
D.Firewall rules with 'Allow access to Azure services' enabled and specific IP rules
AnswerD

The correct network access control for Azure Database for MySQL is the server-level firewall, which accepts connections only from explicitly allowed IP ranges. Enabling 'Allow access to Azure services' adds the special Azure internal IP range, permitting connections from other Azure services without a specific public IP. Adding precise IP rules for client workstations or office ranges further restricts the database to known sources, making this the suitable mechanism for the described requirement.

Why this answer

Azure Database for MySQL uses firewall rules to control access at the server level. Enabling 'Allow access to Azure services' permits connections from Azure internal IP ranges, while adding specific client IP rules restricts access to only those addresses. This dual configuration meets the requirement to allow traffic from Azure services and specific client IPs while blocking all other traffic.

Exam trap

The trap here is that candidates often confuse network-level controls (NSGs, service endpoints) with the PaaS firewall, mistakenly thinking they can apply NSG rules to a PaaS database or that service endpoints alone can restrict access to specific IPs without additional firewall configuration.

How to eliminate wrong answers

Option A is wrong because Azure Active Directory authentication controls user identity, not network-level access; it does not restrict traffic by source IP or service. Option B is wrong because Virtual Network service endpoints integrate Azure Database for MySQL with a virtual network, but they do not provide a mechanism to allow all Azure services or specific client IPs; they require the database to be joined to a VNet, which changes the connectivity model. Option C is wrong because Network Security Group (NSG) rules operate at the subnet or NIC level and cannot be applied directly to Azure Database for MySQL, which is a PaaS service with its own firewall; NSGs are irrelevant for controlling traffic to the database endpoint.

465
MCQmedium

A company uses a hub-spoke network topology in Azure. They need to inspect and filter all traffic flowing between spoke virtual networks for security compliance. Which Azure-native service should be deployed in the hub virtual network to achieve this?

A.Azure Firewall
B.Network Virtual Appliance (NVA)
C.Azure VPN Gateway
D.Azure Load Balancer
AnswerA

Azure Firewall is a fully managed, cloud-native firewall service that provides stateful, L3-L7 inspection. In a hub-spoke topology, it is deployed in the hub VNet and user-defined routes (UDRs) in each spoke direct inter-spoke traffic to the firewall's private IP for centralized filtering. It supports application FQDN rules, network rules, and threat intelligence, making it the correct choice for an Azure-native traffic inspection service.

Why this answer

Azure Firewall is a fully managed, stateful firewall-as-a-service that can inspect and filter traffic between spoke virtual networks when deployed in the hub VNet. It supports application (FQDN) and network (IP/port/protocol) rules, and can enforce security compliance by logging and blocking non-compliant traffic. Unlike a Network Virtual Appliance (NVA), Azure Firewall is a native PaaS service with built-in high availability and auto-scaling, making it the recommended choice for hub-spoke traffic inspection.

Exam trap

The trap here is that candidates often confuse Azure Firewall with a Network Virtual Appliance (NVA), assuming both are equally 'native' or that an NVA is required for deep packet inspection, but Azure Firewall is the native PaaS solution with built-in high availability and no licensing overhead.

How to eliminate wrong answers

Option B is wrong because a Network Virtual Appliance (NVA) is a third-party VM-based firewall (e.g., Palo Alto, Fortinet) that requires manual configuration, licensing, and high-availability setup; while it can inspect traffic, it is not an Azure-native service and introduces operational overhead. Option C is wrong because Azure VPN Gateway is designed for encrypted site-to-site or point-to-site connectivity, not for stateful traffic inspection or filtering between spoke VNets. Option D is wrong because Azure Load Balancer operates at Layer 4 (TCP/UDP) and distributes traffic based on health probes and load-balancing rules; it does not inspect or filter traffic for security compliance.

466
MCQmedium

Your organization uses Azure Files shares. You need to ensure that users authenticate using on-premises Active Directory credentials and that access is logged. What should you do?

A.Configure a firewall rule to allow on-premises IPs and enable diagnostic logs
B.Use shared access signatures (SAS) for access and enable diagnostic logs
C.Enable identity-based authentication for Azure Files and configure diagnostic logs
D.Configure Azure RBAC for the share and enable diagnostic logs
AnswerC

Enabling identity-based authentication for Azure Files lets SMB clients authenticate with Kerberos using either Azure AD Domain Services or an on-premises AD DS domain, so user access is tied to actual directory identities. After authentication, Azure Files enforces both RBAC share-level roles and Windows ACLs on directories and files. Configuring diagnostic logs then gives you audit trails of which identity performed which operation. This fully satisfies the requirement.

Why this answer

Azure Files supports identity-based authentication using on-premises Active Directory Domain Services (AD DS) via Kerberos. This allows users to authenticate with their on-premises AD credentials and access the file share seamlessly. Enabling diagnostic logs captures access events, meeting the logging requirement.

Exam trap

The trap here is that candidates often confuse Azure RBAC (which controls management-plane access) with identity-based authentication for data-plane access, or they mistakenly think SAS tokens or firewall rules can satisfy both authentication and logging requirements.

How to eliminate wrong answers

Option A is wrong because firewall rules control network access but do not authenticate users with on-premises AD credentials; they only restrict IP addresses. Option B is wrong because shared access signatures (SAS) provide token-based access without authenticating individual users via on-premises AD, and they do not log per-user access. Option D is wrong because Azure RBAC controls management-plane permissions (e.g., share-level roles) but does not authenticate users at the data-plane level with on-premises AD credentials; it also does not inherently log file-level access.

467
Multi-Selectmedium

A team enables Microsoft Defender for Storage. Which two threats can the plan help detect?

Select 2 answers
A.Access from suspicious IP addresses to storage accounts
B.Expired Azure AD PIM role assignments
C.Public IP address creation on virtual machines
D.Malware uploaded to Blob Storage when malware scanning is enabled
AnswersA, D

Microsoft Defender for Storage flags access to storage accounts from suspicious IP addresses by matching request metadata—such as source IP, TLS version, and API behavior—against global threat intelligence and Microsoft's cybercrime attribution data. This is a core detection capability that identifies potential credential compromise or unauthorized access attempts directly on the storage data plane, making it correct for a threat detection requirement.

Why this answer

Microsoft Defender for Storage detects anomalous activities that could indicate threats to storage accounts. Option A is correct because the service analyzes incoming requests to identify access from suspicious IP addresses, such as known malicious IPs or Tor exit nodes, using threat intelligence feeds. Option D is correct because when malware scanning is enabled, Defender for Storage can detect malware uploaded to Blob Storage by scanning files for known malicious signatures.

Exam trap

The trap here is that candidates may confuse Defender for Storage with broader Defender for Cloud capabilities, incorrectly assuming it monitors identity or networking threats outside the storage data plane.

468
MCQhard

Your organization uses Microsoft Entra ID with Privileged Identity Management (PIM) to manage roles. You need to ensure that when a user activates a role, the activation is automatically approved only if the user's manager approves within 30 minutes. If the manager does not respond, the activation is denied. What configuration should you implement?

A.Enable just-in-time access for the role and configure a group approval with a 30-minute timeout.
B.Configure the role settings to require approval, set the maximum activation duration to 30 minutes, and add the user's manager as an approver.
C.Create an approval workflow in Microsoft Entra ID that assigns the manager as the approver and set a timeout of 30 minutes.
D.Configure the role settings to require approval and set the approval timeout to 0 minutes.
AnswerB

This ensures the manager must approve within the activation window, or the request expires.

Why this answer

In Microsoft Entra ID PIM, the 'Maximum activation duration' setting in role settings controls the time window within which an approval must be granted. If the approver does not respond within that duration, the activation request is denied. By setting this to 30 minutes, requiring approval, and adding the user's manager as an approver, you ensure the manager must approve within 30 minutes or the activation is automatically denied.

This directly meets the requirement.

Exam trap

The trap here is thinking that a separate 'Approval timeout' setting exists, when in fact the 'Maximum activation duration' serves as the timeout for the approval request itself. Candidates may incorrectly look for a distinct approval timeout setting, leading them to choose options that do not exist or are misconfigured.

How to eliminate wrong answers

Option A is wrong because enabling just-in-time access and configuring a group approval with a 30-minute timeout does not specifically assign the user's manager as the approver; group approval requires a predefined group, not dynamic manager assignment. Option C is wrong because creating an approval workflow in Microsoft Entra ID is not a native PIM feature; PIM uses role settings for approval, not separate workflows, and the timeout must be configured in the role settings, not in a workflow. Option D is wrong because setting the approval timeout to 0 minutes would cause the approval request to expire immediately, not wait 30 minutes for the manager's response, and it does not specify the manager as the approver.

469
MCQmedium

You are configuring Microsoft Defender for Cloud's regulatory compliance dashboard. Your organization must comply with SOC 2. You have enabled the SOC 2 regulatory compliance standard. After a week, some controls show as 'Unhealthy'. What is the most likely reason for the 'Unhealthy' status?

A.The standard is not fully enabled for all subscriptions.
B.The SOC 2 standard is not supported by Defender for Cloud.
C.You need to manually attest to the controls to mark them as healthy.
D.The underlying Azure Policy initiatives have resources that are non-compliant.
AnswerD

Regulatory compliance in Defender for Cloud is built on Azure Policy initiatives: each control is backed by one or more policy definitions that continuously audit your resources. When a resource is found to be non-compliant with a policy assignment, the corresponding control is marked 'Unhealthy', since compliance is aggregated at the control level across all evaluated resources. This is the direct and expected cause of the unhealthy status you are seeing, rather than a misconfiguration of the standard assignment.

Why this answer

The 'Unhealthy' status in Defender for Cloud's regulatory compliance dashboard indicates that the underlying Azure Policy initiatives associated with the SOC 2 standard have identified resources that are non-compliant. Defender for Cloud maps regulatory standards to Azure Policy definitions, and the compliance score is derived from the compliance state of those policies. Therefore, when controls show as 'Unhealthy', it is because the corresponding Azure Policy evaluations have found resources that do not meet the required configuration or security controls defined by SOC 2.

Exam trap

The trap here is that candidates often assume 'Unhealthy' means the standard is misconfigured or not fully enabled, rather than understanding that it directly reflects Azure Policy non-compliance results from the underlying resources.

How to eliminate wrong answers

Option A is wrong because enabling the SOC 2 standard for all subscriptions is not required for the standard to show controls; the standard is enabled at the management group or subscription scope, and partial enablement would not cause individual controls to show as 'Unhealthy'—it would simply not evaluate those subscriptions. Option B is wrong because SOC 2 is a supported regulatory compliance standard in Microsoft Defender for Cloud, as documented in the list of available standards. Option C is wrong because manual attestation is not a feature for marking controls as healthy; compliance is determined automatically by Azure Policy evaluations, and there is no manual attestation mechanism for SOC 2 controls in Defender for Cloud.

470
MCQmedium

A Kubernetes workload in AKS needs to pull images from Azure Container Registry without using admin credentials. Which configuration should be used?

A.Grant the AKS kubelet identity AcrPull on the registry
B.Enable anonymous pull access on the registry
C.Store the ACR admin password in a ConfigMap
D.Expose the registry through a public load balancer
AnswerA

The AKS cluster's kubelet runs on each node and is responsible for pulling container images. Each cluster has a kubelet identity (a managed identity in Microsoft Entra ID) that can be granted the AcrPull role on the container registry, giving that identity permission to authenticate and pull images without any stored secrets. This is the recommended approach because it uses Azure's managed identity-based authentication, follows least privilege, and avoids managing or exposing long-lived credentials.

Why this answer

The AKS cluster uses a kubelet identity (managed identity) to authenticate with ACR. By granting the AcrPull role to this identity, the kubelet can pull container images without requiring admin credentials, as Azure RBAC handles the authentication via Azure AD tokens. This is the recommended secure method for image pull operations.

Exam trap

The trap here is that candidates may confuse anonymous pull access (Option B) as a valid alternative, but Azure explicitly recommends using managed identities with AcrPull for secure, credential-free image pulls in AKS.

How to eliminate wrong answers

Option B is wrong because enabling anonymous pull access on ACR allows unauthenticated pulls, which bypasses all security controls and is not recommended for production workloads. Option C is wrong because storing the ACR admin password in a ConfigMap exposes credentials in plaintext within the cluster, violating security best practices and the principle of least privilege. Option D is wrong because exposing the registry through a public load balancer does not solve authentication; it only changes network access and still requires credentials for image pulls.

471
MCQmedium

A DevOps team wants Defender for Cloud to identify secrets exposed in GitHub repositories. What should be configured?

A.Azure Bastion native client
B.Defender for Cloud DevOps Security connector
C.Sentinel Syslog connector
D.Azure Storage lifecycle management
AnswerB

The Defender for Cloud DevOps Security connector connects Azure DevOps and GitHub organizations to Defender for Cloud, enabling security assessments of repositories, builds, and release pipelines. Once connected during the enablement of Defender CSPM, it runs secret scanning, code scanning, and dependency scanning, surfacing exposed credentials as recommendations. This connector is the direct mechanism by which a DevOps team's secrets are identified and remediated in the portal.

Why this answer

Defender for Cloud's DevOps Security connector integrates with GitHub to scan repositories for exposed secrets (e.g., API keys, tokens) using Microsoft's secret scanning engine. This connector enables Defender for Cloud to monitor commits and pull requests, alerting on secrets detected in code. It is the correct solution because it directly addresses the requirement to identify secrets in GitHub repositories within the Defender for Cloud ecosystem.

Exam trap

The trap here is that candidates may confuse the Defender for Cloud DevOps Security connector with GitHub's own secret scanning (which requires GitHub Advanced Security), but the question specifically asks for a Defender for Cloud configuration, making the connector the correct choice.

How to eliminate wrong answers

Option A is wrong because Azure Bastion native client is a secure RDP/SSH connectivity service for virtual machines, not a tool for scanning GitHub repositories for secrets. Option C is wrong because Sentinel Syslog connector ingests syslog events from on-premises or cloud devices into Azure Sentinel for security monitoring, but it does not scan GitHub repositories for secrets. Option D is wrong because Azure Storage lifecycle management automates tiering or deletion of blobs based on age or rules, and has no capability to scan GitHub code for exposed secrets.

472
MCQeasy

Your company uses Microsoft Defender for Cloud's 'Vulnerability Assessment' solution for Azure VMs. You have enabled the 'Microsoft Defender for Servers' plan and deployed the integrated Qualys agent. You need to view the vulnerability assessment findings for all VMs in a single dashboard in Microsoft Defender for Cloud. Which blade in the Defender for Cloud portal should you navigate to?

A.Inventory
B.Security alerts
C.Regulatory compliance
D.Recommendations
AnswerD

In Defender for Cloud, every vulnerability assessment result is represented as a recommendation; the 'Remediate vulnerabilities' recommendation contains all discovered findings across your machines. When you open it, you see affected resources, CVE IDs, severity scores, and remediation guidance, and the findings update as scans complete. This is the dedicated location where vulnerability data is surfaced for action.

Why this answer

The correct option is D, Recommendations. In Microsoft Defender for Cloud, vulnerability assessment findings from the integrated Qualys agent (part of the Defender for Servers plan) are surfaced as security recommendations, so navigating to the Recommendations blade lets you view and filter findings such as 'Vulnerabilities in your virtual machines should be remediated' across all VMs in one place. The Inventory blade only lists resources and their security posture, not aggregated vulnerability findings.

Security alerts shows active threat detections rather than vulnerability assessment results. Regulatory compliance maps controls to standards and does not present the raw vulnerability findings dashboard.

473
Multi-Selectmedium

Which TWO actions should you take to integrate on-premises servers with Microsoft Defender for Cloud for unified security management? (Choose two.)

Select 2 answers
A.Install the Log Analytics agent on each server.
B.Migrate the servers to Azure Stack HCI.
C.Enroll the servers in Microsoft Intune.
D.Deploy the Azure Connected Machine agent (Azure Arc) on each server.
E.Establish a site-to-site VPN connection to Azure.
AnswersA, D

This is a correct action because the Log Analytics agent (or its successor, the Azure Monitor Agent) is required to collect security-relevant data from each server's event logs, performance counters, and syslog. Defender for Cloud correlates this data into security alerts, vulnerabilities, and compliance recommendations. Without the agent, the on-premises server would be invisible to Defender for Cloud's detection engine, so installing it is a direct prerequisite for the integration.

Why this answer

The Log Analytics agent (now the Azure Monitor Agent) is required to collect security events and performance data from on-premises servers and send it to the Log Analytics workspace used by Microsoft Defender for Cloud. This enables Defender for Cloud to apply security policies, detect threats, and provide unified security management across hybrid environments.

Exam trap

The trap here is that candidates often confuse network connectivity (VPN) with agent-based data collection, or they mistakenly think Intune or Azure Stack HCI are valid integration methods for Defender for Cloud's hybrid security management.

474
Multi-Selecthard

A Key Vault should be accessible only from selected private networks and approved Azure services. Which two settings are most relevant?

Select 2 answers
A.Configure Key Vault networking with private endpoint or selected networks
B.Disable soft delete permanently
C.Use firewall and virtual network restrictions
D.Store secrets as plain text tags
AnswersA, C

Private endpoint gives the vault a private IP inside your VNet, while selected networks plus service endpoints restrict public access to approved subnets; the service firewall's 'Allow trusted Microsoft services' toggle then admits approved Azure services, satisfying both constraints.

Why this answer

Option A is correct because configuring Key Vault networking with a private endpoint or selected networks restricts access to the vault from approved private IP ranges within your virtual networks, blocking public internet access. Option C is correct because Key Vault's firewall and virtual network restrictions let you allow traffic only from specified VNets/subnets and trusted Azure services, directly enforcing the 'selected private networks and approved Azure services' requirement. Option B is incorrect because soft delete is a data-protection feature that retains deleted vaults/objects for recovery; disabling it does not control network accessibility and would weaken security.

Option D is incorrect because storing secrets as plain text tags is insecure and unrelated to network access restrictions; tags are metadata and should never hold secret values.

Exam trap

The trap here is that candidates often confuse data protection features like soft delete (Option B) with network access controls, or mistakenly think that storing secrets in tags (Option D) is a valid configuration, when in fact tags are unencrypted metadata and never intended for secret storage.

475
MCQmedium

You are a security analyst in a company that uses Microsoft Sentinel. You need to create a hunting query that identifies failed sign-in attempts from a specific IP address range and then automatically create an incident if the count exceeds a threshold. Which Microsoft Sentinel feature should you use?

A.Create a scheduled analytics rule that runs the query and triggers an incident based on the threshold.
B.Configure a workbook that visualizes failed sign-ins and set up an alert rule in Azure Monitor to create an incident.
C.Create a playbook that runs the query on a schedule and sends an email to the security team.
D.Use the hunting dashboard to run the query and manually create an incident from the results.
AnswerA

Scheduled analytics rules in Microsoft Sentinel are designed to run queries at regular intervals, evaluate results against a threshold, and generate incidents automatically. You can write a query to filter failed sign-ins from the IP range, set the rule to trigger when the number of results exceeds a specified threshold, and configure incident creation. This directly meets the requirement for automated detection and incident generation.

Why this answer

Scheduled analytics rules are the correct feature for automated detection and incident creation in Microsoft Sentinel. They allow you to define a query, set a schedule, and specify a threshold for generating incidents. When the query returns results exceeding the threshold, Sentinel creates an incident with the mapped entities.

This is ideal for detecting patterns like multiple failed sign-ins from a specific IP range. Other features like hunting or workbooks do not provide this automated incident creation capability.

Exam trap

The trap here is confusing hunting queries with scheduled analytics rules; hunting is for manual exploration, while scheduled analytics rules are for automated detection and incident generation.

476
MCQhard

A company uses Azure SQL Database with Transparent Data Encryption (TDE) and wants to use a customer-managed key (CMK) stored in Azure Key Vault. The security policy requires that the Key Vault be protected by a firewall and virtual network service endpoints to restrict network access. The storage account for TDE logs is in the same Azure region. Which additional configuration is necessary in the Key Vault to allow Azure SQL Database to access the CMK for encryption operations?

A.Add a network rule in the Key Vault firewall allowing the public IP range of the Azure SQL Database server.
B.Enable the 'Allow trusted Microsoft services to bypass this firewall' option in the Key Vault networking settings.
C.Create a private endpoint for the Key Vault and connect it to the same virtual network as the Azure SQL Database.
D.Configure the Key Vault to use role-based access control (RBAC) and assign the 'Key Vault Crypto Service Encryption User' role to the SQL Database server's managed identity.
AnswerB

Enabling 'Allow trusted Microsoft services to bypass this firewall' is the correct solution because Azure SQL Database is a trusted Microsoft service and its managed identity can authenticate to the Key Vault using Azure AD, then fetch the encryption key for TDE. With this setting, the Key Vault firewall remains enabled for public internet traffic, but Azure services like SQL Database are permitted to bypass the IP restrictions. This is the intended pattern for TDE with customer-managed keys, as SQL Database runs outside your virtual network and its outbound IPs cannot be reliably scoped.

Why this answer

Azure SQL Database uses TDE with CMK stored in Azure Key Vault, and when the Key Vault firewall is enabled with virtual network service endpoints, Azure SQL Database must be able to bypass the firewall to retrieve the key. The 'Allow trusted Microsoft services to bypass this firewall' setting permits Azure services like Azure SQL Database, which are considered trusted by Microsoft, to access the Key Vault even when network restrictions are in place. This is the only configuration that satisfies the security policy while enabling the necessary encryption operations.

Exam trap

The trap here is that candidates often confuse network-level access controls (firewall rules) with authorization (RBAC or access policies), leading them to select Option D, which addresses permissions but not the network restriction imposed by the Key Vault firewall.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database does not have a static public IP range; its outbound IPs can change and are not predictable, so adding a public IP range would be unreliable and insecure. Option C is wrong because a private endpoint would require the Azure SQL Database to be in the same virtual network or have connectivity to it, but Azure SQL Database is a PaaS service that does not reside in a customer's virtual network by default, and creating a private endpoint for Key Vault does not grant the SQL Database access unless the SQL Database itself is network-integrated (e.g., via Azure SQL Managed Instance or a private endpoint for SQL). Option D is wrong because role-based access control (RBAC) is used for authorization, not network access; the 'Key Vault Crypto Service Encryption User' role grants permissions to use the key, but it does not bypass the Key Vault firewall, which is a network-level restriction.

477
MCQeasy

You need to distribute incoming internet traffic across multiple Azure virtual machines in the same region. The solution must provide layer 7 load balancing and SSL offloading. Which Azure service should you use?

A.Azure Application Gateway
B.Azure Traffic Manager
C.Azure Load Balancer
D.Azure Front Door
AnswerA

Azure Application Gateway is the correct choice because it is a regional Layer 7 load balancer that operates at the HTTP/HTTPS application layer. It can distribute incoming internet traffic across VMs in the same region, perform SSL offloading, and route based on URL paths or host headers. This combination of regional scope and application-level inspection makes it uniquely suited to this requirement.

Why this answer

Azure Application Gateway is a layer 7 load balancer that can distribute incoming traffic across multiple Azure virtual machines in the same region. It supports SSL termination (offloading), which offloads the decryption work from the backend VMs, and provides advanced routing based on URL path, host headers, or other HTTP attributes.

Exam trap

The trap here is confusing Azure Front Door (global, multi-region) with Azure Application Gateway (regional, single-region), as both offer layer 7 features and SSL offloading, but the question explicitly specifies 'same region'.

How to eliminate wrong answers

Option B (Azure Traffic Manager) is wrong because it operates at the DNS layer (layer 3/4) and performs global traffic routing based on DNS resolution, not layer 7 load balancing or SSL offloading within a single region. Option C (Azure Load Balancer) is wrong because it operates at layer 4 (TCP/UDP) and cannot inspect HTTP/HTTPS traffic, perform SSL offloading, or route based on URL paths. Option D (Azure Front Door) is wrong because it is a global, multi-region application delivery network that provides layer 7 load balancing and SSL offloading, but it is designed for cross-region traffic distribution, not for distributing traffic across VMs within the same region.

478
MCQhard

A company has a partner organization in another Azure AD tenant. They want to allow users from the partner tenant to access their Azure resources through Azure AD B2B collaboration. They also want the partner's Multi-Factor Authentication (MFA) claims to be trusted when partner users access their resources, so that they do not need to perform MFA again. Which configuration in cross-tenant access settings should they enable?

A.Trust multi-factor authentication from the partner tenant (inbound trust).
B.Trust device compliance from the partner tenant.
C.Enable a Conditional Access policy that grants access to the partner tenant.
D.Configure identity synchronization with the partner tenant.
AnswerA

This setting, located in the partner tenant's cross-tenant access settings under 'Inbound access' > 'Trust settings', instructs your Azure AD to accept the multi-factor authentication (MFA) claims already performed in the partner tenant. When enabled, B2B collaboration users from that tenant are not prompted for MFA again in your tenant, provided their home tenant has satisfied MFA. This is the correct mechanism to avoid redundant authentication prompts.

Why this answer

Cross-tenant access settings in Azure AD allow you to configure inbound trust for MFA from an external Azure AD tenant. When enabled, Azure AD B2B collaboration will accept the partner tenant's MFA claims, so partner users who have already satisfied MFA in their home tenant will not be prompted again when accessing your resources. This is configured under 'Cross-tenant access settings' > 'Inbound trust settings' for the specific partner tenant.

Exam trap

The trap here is that candidates often confuse Conditional Access policies with cross-tenant trust settings, thinking they can use a Conditional Access policy to 'trust' external MFA, when in fact the trust must be explicitly configured in the cross-tenant access settings for inbound MFA claims.

How to eliminate wrong answers

Option B is wrong because trusting device compliance from the partner tenant is a separate inbound trust option that applies to device state (e.g., compliant or hybrid Azure AD joined), not to MFA claims; it does not address the requirement to skip MFA re-prompting. Option C is wrong because a Conditional Access policy that grants access to the partner tenant does not control trust of MFA claims; it defines conditions and access controls (like requiring MFA) but cannot make your tenant trust the partner's MFA claims—that is a cross-tenant trust setting. Option D is wrong because identity synchronization with the partner tenant is not supported for B2B collaboration; Azure AD B2B uses federation or invitation-based relationships, not synchronization, and synchronizing identities would create duplicate or conflicting objects without enabling MFA claim trust.

479
MCQhard

You have an Azure SQL Database that stores Personally Identifiable Information (PII). You need to mask the PII columns for support staff but allow full access to managers. What should you implement?

A.Dynamic Data Masking with a masking policy and grant UNMASK permission to managers
B.Always Encrypted with separate column encryption keys for managers
C.Azure Information Protection labels and encryption
D.Row-level security to restrict rows for support staff
AnswerA

Dynamic Data Masking (DDM) operates at query time, applying a masking function to the target column's values in the result set based on the executing user's permissions. By creating a masking policy on the PII column and granting the UNMASK permission only to managers, support staff automatically see obfuscated values (e.g., partial email or random digits) while managers see the plaintext. This directly satisfies the requirement to hide PII from certain roles without changing application queries or requiring client-side key management, making it a built-in, low-friction Azure SQL Database capability.

Why this answer

Dynamic Data Masking (DDM) obfuscates sensitive data in query results based on a masking policy, without altering the underlying data. Granting the UNMASK permission to managers allows them to see the original values, while support staff see masked data. This directly meets the requirement to mask PII columns for support staff but allow full access to managers.

Exam trap

The trap here is that candidates often confuse Dynamic Data Masking with Row-Level Security, thinking both restrict data access, but DDM masks columns while RLS filters rows, and only DDM with UNMASK permission provides the column-level obfuscation and selective full access described.

How to eliminate wrong answers

Option B is wrong because Always Encrypts encrypts data at rest and in transit, and while it can restrict access via column encryption keys, it does not provide granular per-user masking within the same query; managers would need separate keys, which is impractical for dynamic masking scenarios. Option C is wrong because Azure Information Protection (AIP) is a classification and labeling service for files and emails, not for masking columns in Azure SQL Database query results. Option D is wrong because Row-Level Security (RLS) restricts which rows a user can read, not which columns; it cannot mask specific columns like PII while leaving others visible.

480
MCQhard

You are designing a security solution for Azure Cosmos DB that stores Personally Identifiable Information (PII). You need to encrypt data at rest and in transit. You also need to implement row-level security to restrict access based on user role. What should you configure?

A.Enable Azure Disk Encryption on the Cosmos DB account.
B.Enable Always Encrypted and configure column encryption.
C.Use Dynamic Data Masking to restrict sensitive data.
D.Encryption at rest is automatically enabled; enforce TLS for transit; implement row-level security via application code.
AnswerD

Azure Cosmos DB automatically encrypts all data at rest using Azure-managed keys, and this encryption cannot be disabled; transit security is enforced by requiring TLS for all client connections to the account. Row-level security is not natively provided by Cosmos DB, so you must implement it in the application layer — typically by filtering queries based on the authenticated user's token claims or by using partition keys to isolate tenant data. This aligns with the shared responsibility model: Cosmos DB secures the physical and network layers, while the application enforces fine-grained authorization over individual document access.

Why this answer

Azure Cosmos DB automatically encrypts data at rest using AES-256 encryption, and data in transit is secured by enforcing TLS (Transport Layer Security). Row-level security is not natively supported in Cosmos DB; instead, it must be implemented at the application layer by filtering queries based on user roles, typically using a partition key or a custom property in the document.

Exam trap

The trap here is that candidates often confuse Cosmos DB with SQL-based services and incorrectly assume features like Always Encrypted or Dynamic Data Masking apply, when in reality Cosmos DB relies on automatic encryption and application-layer row-level security.

How to eliminate wrong answers

Option A is wrong because Azure Disk Encryption is for encrypting virtual machine disks, not Azure Cosmos DB, which is a PaaS service with its own built-in encryption. Option B is wrong because Always Encrypted is a SQL Server and Azure SQL Database feature for column-level encryption, not applicable to Cosmos DB's NoSQL document model. Option C is wrong because Dynamic Data Masking is a feature for Azure SQL Database and SQL Server to obfuscate data at query time, not for Cosmos DB, and it does not provide row-level security.

481
MCQmedium

Your company has an Azure Cosmos DB account that stores customer profiles. You need to ensure that only authenticated and authorized users can access the data. Which access control method should you use?

A.Configure an IP firewall rule to allow only corporate IP ranges.
B.Use Azure RBAC with Microsoft Entra ID authentication.
C.Use primary read-write keys with connection strings.
D.Use resource tokens generated from a master key.
AnswerB

Azure RBAC with Microsoft Entra ID (formerly Azure AD) is the correct approach because Cosmos DB supports data-plane role assignments using Microsoft Entra identities. By assigning built-in roles like Cosmos DB Built-in Data Reader or Contributor to a user or group, you can grant fine-grained, identity-based access to specific databases/containers. This provides per-user authentication, follows the principle of least privilege, and integrates with conditional access and auditing, unlike shared secret keys.

Why this answer

Azure RBAC with Microsoft Entra ID authentication provides fine-grained, identity-based access control for Azure Cosmos DB. This method allows you to assign specific roles (e.g., Cosmos DB Built-in Data Reader) to users or service principals, ensuring that only authenticated and authorized identities can access the data plane operations, such as reading or writing documents. It eliminates the need to share or manage keys, aligning with the principle of least privilege.

Exam trap

The trap here is that candidates often confuse network-level controls (IP firewall) or key-based access (primary keys or resource tokens) with proper identity-based authentication, overlooking that only Azure RBAC with Microsoft Entra ID provides per-user authorization without exposing secrets.

How to eliminate wrong answers

Option A is wrong because an IP firewall rule only restricts network-level access based on source IP addresses; it does not authenticate or authorize individual users, so any user within the allowed IP range could still access the data without proper identity verification. Option C is wrong because primary read-write keys provide full administrative access to the Cosmos DB account; using them in connection strings exposes the key, which can be compromised, and does not enforce per-user authentication or authorization. Option D is wrong because resource tokens are generated from a master key and are typically used for scoped access to specific containers or items, but they still rely on the master key for generation and do not integrate with Microsoft Entra ID for user-level authentication and authorization.

482
MCQmedium

You are designing a secure access solution for an Azure App Service web application. The application uses Microsoft Entra ID for authentication. You need to ensure that only users from specific partner organizations can access the app. Which configuration should you use?

A.Use a custom domain for the app
B.Configure the app to accept tokens from the partner tenants as external identity providers
C.Block all external users
D.Require multi-factor authentication for all users
AnswerB

Configuring the app to accept tokens from partner tenants as external identity providers is the core of Azure AD B2B collaboration. You register the app as a multi-tenant application or add partner tenants as trusted identity providers; users authenticate in their home tenant and receive tokens that your app validates. This allows you to grant specific partner users access while keeping your own tenant as the authority for the application.

Why this answer

Azure App Service can be configured to accept tokens from multiple Microsoft Entra ID tenants as external identity providers. This allows users from specific partner organizations to authenticate using their own Entra ID tenant, while the app validates the tokens and grants access only to those partner tenants you explicitly trust.

Exam trap

The trap here is that candidates often confuse 'external identity providers' with 'blocking external users' or 'MFA', not realizing that the correct approach is to explicitly allow specific partner tenants as identity providers rather than applying a blanket security policy.

How to eliminate wrong answers

Option A is wrong because using a custom domain for the app only changes the app's URL and does not control which identity providers or tenants can authenticate users. Option C is wrong because blocking all external users would prevent access from partner organizations entirely, which contradicts the requirement to allow specific partner users. Option D is wrong because requiring multi-factor authentication for all users enhances security but does not restrict access to specific partner tenants; it applies to all authenticated users regardless of their origin.

483
MCQhard

Your security team wants to automatically detect and remediate misconfigurations in Azure Storage accounts, such as enabling public access. The solution should use Azure Policy and be centrally managed for multiple subscriptions. What should you configure?

A.Azure Blueprints
B.Azure Resource Graph
C.Microsoft Defender for Cloud (formerly Azure Security Center)
D.Azure Policy with a custom initiative for storage security
AnswerD

Azure Policy with a custom initiative is the correct service because it allows you to author an initiative—a grouped set of policy definitions—that targets storage security controls such as secure transfer, encryption, public network access, and shared key auth. With the DeployIfNotExists or Modify effect, Azure Policy triggers remediation tasks to bring non-compliant storage accounts back into compliance, either automatically for new resources or via scheduled/on-demand remediation for existing ones. Scoping the initiative to the subscription or resource group and assigning it ensures continuous compliance evaluation and automatic corrective action, fulfilling the team's requirement.

Why this answer

Azure Policy with a custom initiative allows you to define a set of policies (e.g., 'Audit storage accounts with unrestricted public access') that can be assigned at a management group scope, covering multiple subscriptions. This enables automatic detection and remediation of misconfigurations like enabling public access, using built-in effects such as 'Deny' or 'DeployIfNotExists' to enforce compliance centrally.

Exam trap

The trap here is that candidates often confuse Azure Blueprints (a deployment orchestration tool) with Azure Policy (a continuous compliance enforcement service), or assume Microsoft Defender for Cloud alone can perform automatic remediation without an underlying policy assignment.

How to eliminate wrong answers

Option A is wrong because Azure Blueprints is used for orchestrating the deployment of resource templates, policies, and role assignments as a repeatable package, but it does not provide ongoing automatic detection and remediation of misconfigurations; it is a deployment artifact, not a continuous compliance engine. Option B is wrong because Azure Resource Graph is a query service for exploring and auditing resources across subscriptions, but it cannot enforce or remediate configurations; it only provides read-only data for analysis. Option C is wrong because Microsoft Defender for Cloud (formerly Azure Security Center) provides security recommendations and alerts for storage accounts, but it relies on Azure Policy to enforce remediation; Defender for Cloud itself does not natively perform automatic remediation via policy effects like 'DeployIfNotExists' without an underlying policy assignment.

484
Multi-Selecthard

You are the Azure Security Engineer for a company that uses Microsoft Entra ID. The security team wants to enforce that any user who is assigned the 'Privileged Role Administrator' role must activate it through Privileged Identity Management (PIM) with multi-factor authentication (MFA) and approval. You have already enabled PIM for the role. Which two actions must you perform to meet these requirements? (Choose two.)

Select 2 answers
A.In the PIM role settings for 'Privileged Role Administrator', configure the 'Require multi-factor authentication on activation' setting to 'Yes'.
B.Enable 'Just-in-time' (JIT) access for the role in PIM.
C.In the PIM role settings for 'Privileged Role Administrator', configure 'Require approval to activate' and specify at least one approver.
D.Assign the user as an eligible member of the 'Privileged Role Administrator' role.
E.Create a conditional access policy that requires MFA for all users when they access the Azure portal.
AnswersA, C

Enabling the MFA requirement in the PIM role settings forces users to perform MFA when they activate the role. This directly satisfies the MFA enforcement requirement. Without this setting, activation would not challenge the user for a second factor, leaving the privileged role vulnerable to credential compromise, even if the role is eligible and approval is required.

Why this answer

To enforce MFA and approval for PIM role activation, you must configure the role settings: set 'Require multi-factor authentication on activation' to 'Yes' and set 'Require approval to activate' with approvers. These settings apply to the role itself and are enforced when a user attempts activation. Other options like conditional access or eligible assignment do not meet the specific activation-time requirements.

Exam trap

The trap here is assuming that enabling PIM automatically enforces MFA and approval, or that conditional access can replace PIM activation settings.

485
MCQmedium

A company wants Defender for Cloud to automatically open a Logic App when a high-severity alert is generated for a subscription. Which feature should be configured?

A.Regulatory compliance dashboard
B.Secure score recommendation exemption
C.Workflow automation
D.Continuous export
AnswerC

Workflow automation in Microsoft Defender for Cloud orchestrates Azure Logic Apps in response to triggers such as the creation of a security alert or a recommendation finding. You can define conditions based on severity, type, or resource, and then invoke a Logic App to open a ticket in an ITSM system like ServiceNow or send an email. This is the built-in mechanism that directly satisfies the requirement to automatically open a support ticket when an event occurs.

Why this answer

Workflow automation in Defender for Cloud allows you to trigger a Logic App automatically in response to specific security alerts, such as high-severity alerts. This feature uses Azure Event Grid to listen for alert creation events and invoke the Logic App via an HTTP trigger, enabling automated remediation or notification workflows without manual intervention.

Exam trap

The trap here is that candidates often confuse Continuous export with workflow automation, thinking that exporting alerts to a Log Analytics workspace can directly trigger a Logic App, but Continuous export only sends data to a destination and requires a separate Azure Monitor alert rule or Logic App connector to process the exported data.

How to eliminate wrong answers

Option A is wrong because the Regulatory compliance dashboard is a reporting tool that shows compliance posture against standards like ISO 27001 or SOC 2, not a mechanism to trigger automated actions on alerts. Option B is wrong because Secure score recommendation exemption is used to exclude specific recommendations from affecting your secure score, not to automate responses to alerts. Option D is wrong because Continuous export streams security data (e.g., alerts, recommendations) to Log Analytics or Event Hubs for external analysis, but it does not directly invoke a Logic App or any automated action upon alert generation.

486
MCQeasy

A company uses Azure AD Privileged Identity Management (PIM) for the 'Security Administrator' role. They want to ensure that when a user activates the role, they must provide a justification, and the activation requires approval from a designated security group. Which PIM role settings should they configure?

A.Require justification on activation (Yes), Require approval (Yes), Select approver(s) (the security group).
B.Require justification on activation (No), Require approval (Yes), Select approver(s) (the security group).
C.Expiration > Maximum activation duration (4 hours).
D.On activation, require Azure MFA registration.
AnswerA

Enabling justification forces the user to enter a business rationale when requesting activation, directly satisfying the justification requirement. Enabling approval with the security group as the approver means a member of that group must review and approve every activation request before the privilege is granted. This combination is both necessary and sufficient for the stated conditions.

Why this answer

PIM role settings allow administrators to enforce both justification and approval workflows for role activation. Setting 'Require justification on activation' to 'Yes' ensures the user provides a reason, and setting 'Require approval' to 'Yes' with the designated security group as the approver enforces the approval requirement. This combination directly meets the company's stated requirements.

Exam trap

The trap here is that candidates may confuse activation duration settings (Option C) or MFA registration (Option D) with the justification and approval workflow, but only the combination of justification and approval settings directly addresses the stated requirements.

How to eliminate wrong answers

Option B is wrong because setting 'Require justification on activation' to 'No' would bypass the justification requirement, which the company explicitly needs. Option C is wrong because configuring 'Maximum activation duration' controls how long the role remains active, not the activation workflow of justification or approval. Option D is wrong because requiring Azure MFA registration is a separate security control for authentication, not a mechanism for justification or approval during activation.

487
MCQmedium

You are deploying a new line-of-business application on an Azure virtual machine. The application needs to access an Azure SQL Database. The security team requires that the application uses a managed identity to authenticate to the database without storing credentials in code or configuration files. You assign a system-assigned managed identity to the virtual machine. What should you do next to allow the application to authenticate to Azure SQL Database?

A.Generate a client secret for the managed identity and store it in Azure Key Vault.
B.Create a contained database user in Azure SQL Database that maps to the managed identity and grant the necessary permissions.
C.Add the managed identity's object ID to the Azure SQL Server's Azure Active Directory admin group.
D.Assign the virtual machine's managed identity the Contributor role on the Azure SQL Server resource.
AnswerB

For a managed identity to authenticate to Azure SQL Database, you must create a contained database user that represents the managed identity and assign appropriate permissions. This is done using the CREATE USER ... FROM EXTERNAL PROVIDER statement. This allows the managed identity to authenticate without credentials. It is the correct step after assigning the identity to the VM.

Why this answer

After enabling a system-assigned managed identity on the VM, you must create a contained database user in Azure SQL Database for that identity and grant it the necessary permissions. This enables the application to authenticate using the managed identity. Other options either grant excessive permissions, misunderstand managed identity capabilities, or use the wrong plane of access.

Exam trap

The trap here is confusing Azure RBAC roles with database-level permissions, or thinking managed identities require secrets.

488
MCQhard

You are a security engineer for Litware. The company has an Azure virtual network named VNet1 that contains an Azure Bastion host and several VMs. The VMs have public IP addresses, but the security team wants to eliminate all public IP exposure while still allowing administrators to connect via RDP and SSH from the internet. You need to recommend a solution that meets these requirements with the least administrative effort. What should you do?

A.Remove the public IP addresses from the VMs and create a site-to-site VPN connection from each administrator's workstation to VNet1.
B.Keep the public IP addresses but restrict inbound RDP and SSH to the administrators' source IP addresses using a network security group on the VM subnet.
C.Remove the public IP addresses from the VMs and configure Azure Bastion in VNet1. Administrators connect to the VMs through the Azure portal using the Bastion host.
D.Remove the public IP addresses from the VMs and deploy an Azure Firewall with DNAT rules to forward RDP and SSH traffic to the VMs.
AnswerC

Azure Bastion provides RDP and SSH connectivity over TLS directly from the Azure portal without exposing VM public IPs. Removing the public IPs eliminates internet exposure. Bastion is deployed to a dedicated subnet named AzureBastionSubnet in the same VNet, and no additional client software is required, making it the least-effort solution.

Why this answer

Azure Bastion offers secure RDP and SSH access from the Azure portal without public IPs on VMs. Deploying Bastion in VNet1 and removing VM public IPs meets the security requirement with minimal administrative effort, as administrators use the portal directly and no VPN or firewall configuration is needed.

Exam trap

The trap here is thinking that a network security group restricting RDP/SSH to specific source IPs is sufficient, when the requirement explicitly demands eliminating public IP exposure entirely.

489
MCQmedium

Refer to the exhibit. You are deploying an Azure Storage account with the ARM template snippet shown. The deployment fails with an error about the encryption configuration. What is the most likely cause?

A.The key vault URI is incorrect
B.The storage account does not have the required permissions on the key vault
C.The key name or version is missing
D.The key vault is in a different region than the storage account
AnswerB

The most likely root cause is that the storage account's system-assigned managed identity has not been granted the required permissions on the key vault. When you use customer-managed keys (CMK) with Azure Storage, the storage service must wrap and unwrap the data encryption key using the key vault key. To do this, the managed identity needs at least Get, WrapKey, and UnwrapKey permissions on the key vault's access policy (or the equivalent RBAC role such as "Key Vault Crypto Service Encryption User"). Without these permissions, the storage account cannot perform the envelope encryption operation and the deployment fails.

Why this answer

The storage account must be granted explicit permissions on the Azure Key Vault to access the encryption key. Even if the key vault URI, key name, and version are correct, the deployment will fail if the storage account's managed identity (or the user-assigned identity) does not have 'Get', 'Wrap Key', and 'Unwrap Key' permissions on the key vault. This is a common oversight when configuring customer-managed keys for Azure Storage encryption.

Exam trap

The trap here is that candidates often assume the key vault URI or key identifier is the only configuration needed, overlooking the critical requirement that the storage account's identity must have explicit permissions on the key vault.

How to eliminate wrong answers

Option A is wrong because an incorrect key vault URI would cause a different error (e.g., 'KeyVaultNotFound' or 'InvalidKeyVaultUri'), not a generic encryption configuration error. Option C is wrong because missing key name or version would produce a specific error about the key identifier being incomplete, not a generic encryption configuration failure. Option D is wrong because Azure Key Vault and storage accounts can be in different regions when using customer-managed keys; cross-region access is supported as long as the key vault is in the same Azure Active Directory tenant.

490
MCQeasy

You need to provide secure remote administration access to Azure virtual machines in a production environment. You want to eliminate public RDP/SSH endpoints and provide just-in-time access. Which Azure service should you use?

A.Network Security Groups (NSGs)
B.Azure Firewall
C.Just-in-time VM access in Microsoft Defender for Cloud
D.Azure Bastion
AnswerC

Just-in-time (JIT) VM access in Microsoft Defender for Cloud is a workload-protection feature that deliberately denies inbound RDP/SSH traffic to Azure VMs using automatically configured NSG rules. When an authenticated user with the appropriate Azure AD identity requests access, Defender for Cloud applies targeted NSG rules for a limited, configurable time window and then reverts them automatically after expiration. It supports approval workflows, can enforce MFA, and produces audit logs, making it the only option here that directly delivers time-bound administrative access.

Why this answer

Just-in-time (JIT) VM access in Microsoft Defender for Cloud is the correct choice because it specifically provides time-bound, policy-controlled access to Azure VMs via RDP/SSH while eliminating permanent public endpoints. JIT dynamically opens NSG rules for a specified duration only when an authorized user requests access, then automatically closes them, enforcing the principle of least privilege for remote administration.

Exam trap

The trap here is that candidates often confuse Azure Bastion's 'no public IP' secure access with just-in-time access, but Bastion provides persistent, always-on connectivity, whereas JIT VM access enforces time-limited, approval-based access with automatic port closure.

How to eliminate wrong answers

Option A is wrong because Network Security Groups (NSGs) alone provide static, persistent rules that do not offer just-in-time access or automatic rule expiration; they require manual management to open/close ports, which is not a JIT solution. Option B is wrong because Azure Firewall is a managed, stateful firewall service for network-level traffic filtering across virtual networks, but it does not provide per-VM, time-bound JIT access for RDP/SSH; it lacks the granular, user-request-based access control of JIT. Option D is wrong because Azure Bastion provides secure, browser-based RDP/SSH connectivity to VMs without public IPs, but it offers persistent, always-on access rather than just-in-time, time-limited access; Bastion does not enforce time-bound approval workflows or automatic port closure.

491
MCQmedium

You are troubleshooting a sign-in issue. A user reports that they are repeatedly prompted for authentication when accessing a cloud app, even though they already authenticated earlier in the day. You check the Conditional Access policy and see that 'Session control - Sign-in frequency' is set to 1 hour. What is the most likely cause?

A.The sign-in frequency setting forces reauthentication after 1 hour
B.The browser is blocking persistent cookies
C.Token lifetime policy overrides the sign-in frequency
D.The user is considered high risk by Identity Protection
AnswerA

This is correct because in Azure AD Conditional Access, the sign-in frequency session control is configured to require the user to reauthenticate after a specified time period, here 1 hour. When that interval elapses, Azure AD forces a fresh authentication prompt even if the user's browser session and tokens are still technically valid, so the user experiences a sign-in interruption. The setting is evaluated independently of the underlying session, which explains why the user is prompted again exactly after 1 hour.

Why this answer

The 'Session control - Sign-in frequency' setting in Conditional Access enforces reauthentication at the specified interval. When set to 1 hour, the user must re-authenticate every hour, regardless of prior authentication earlier in the day. This explains the repeated prompts, as the session lifetime is capped by this policy.

Exam trap

The trap here is that candidates confuse sign-in frequency with token lifetime policies, assuming token lifetimes control reauthentication frequency, when in fact Conditional Access session controls override token lifetime settings for the specified apps.

How to eliminate wrong answers

Option B is wrong because persistent cookies are not required for sign-in frequency enforcement; the policy uses session tokens and refresh tokens, not browser cookies. Option C is wrong because token lifetime policies (e.g., via Azure AD or AD FS) are overridden by Conditional Access session controls when both are configured; the sign-in frequency takes precedence. Option D is wrong because Identity Protection risk-based policies would trigger additional controls (e.g., MFA or block), not simply reauthentication prompts at a fixed interval.

492
MCQeasy

Your organization uses Microsoft Defender for Cloud. You need to ensure that all Azure subscriptions have the 'Auto-provisioning' extension enabled for Log Analytics agent on new VMs. What should you configure?

A.Configure Azure Automation State Configuration to push the agent.
B.Set up data connectors in Microsoft Sentinel.
C.Enable 'Auto-provisioning' in Defender for Cloud's environment settings.
D.Create an Azure Policy assignment to deploy the Log Analytics agent.
AnswerC

In Defender for Cloud's environment settings, enabling 'Auto-provisioning' deploys the Log Analytics agent extension automatically to new VMs without manual intervention. This satisfies the stem's requirement for a subscription-wide, automated mechanism that ensures all new VMs receive the agent, as opposed to per-VM manual installation or policy-based assignment.

Why this answer

Defender for Cloud's environment settings include a dedicated 'Auto-provisioning' toggle for the Log Analytics agent. When enabled, Defender for Cloud automatically installs the agent on any new Azure VM that is provisioned in the selected subscriptions, ensuring continuous monitoring without manual intervention. This is the native mechanism within Defender for Cloud to enforce agent deployment at scale.

Exam trap

The trap here is that candidates often confuse the Azure Policy-based deployment of the Log Analytics agent (which is a valid method but not the one specified in the question) with Defender for Cloud's native auto-provisioning toggle, leading them to select option D instead of C.

How to eliminate wrong answers

Option A is wrong because Azure Automation State Configuration (DSC) is a configuration management tool that can install software, but it is not the built-in method for auto-provisioning the Log Analytics agent across all subscriptions; it requires custom DSC configurations and does not integrate with Defender for Cloud's auto-provisioning logic. Option B is wrong because data connectors in Microsoft Sentinel are used to ingest logs from various sources into Sentinel, not to enable auto-provisioning of the Log Analytics agent on new VMs; Sentinel relies on the agent being already present or deployed separately. Option D is wrong because while an Azure Policy assignment can deploy the Log Analytics agent via the 'Deploy Log Analytics agent' built-in policy, it is a separate mechanism from Defender for Cloud's auto-provisioning setting; the question specifically asks for the configuration within Defender for Cloud, not a policy-based approach.

493
MCQmedium

Your organization uses Microsoft Defender for Cloud to protect Azure workloads. You notice that a critical Azure VM is not covered by any of the Defender for Cloud plans. You need to ensure that the VM is protected by the Defender for Servers plan. What should you do?

A.Create a custom Azure Policy to assign the Defender for Servers plan to the VM.
B.Enable the Defender for Servers plan in the Defender for Cloud environment settings for the subscription containing the VM.
C.Enable the Defender for Servers plan directly on the VM's security configuration blade.
D.Ensure the VM is running a supported operating system; the plan is automatically enabled for all VMs.
AnswerB

Navigate to Defender for Cloud > Environment settings, select the subscription that contains the VM, and under 'Defender plans' toggle the Defender for Servers plan to On. This activation is a subscription-scoped configuration that immediately protects the target VM as well as all other current and future VMs in that subscription (assuming the subscription is the plan's scope). The environment settings blade is the authoritative place for enabling any Defender plan; once enabled, the VM's Defender for Cloud status changes to covered, and you will start accruing per-resource billing according to the plan's pricing model.

Why this answer

Defender for Cloud plans are enabled at the subscription level, not per resource. By enabling the Defender for Servers plan in the Defender for Cloud environment settings for the subscription containing the VM, all current and future VMs in that subscription will be automatically protected, including the critical VM in question.

Exam trap

The trap here is that candidates often think Defender for Cloud plans can be enabled per resource (like a VM) or via Azure Policy, when in fact they are subscription-level settings that must be enabled in the Defender for Cloud environment settings.

How to eliminate wrong answers

Option A is wrong because custom Azure Policy can enforce compliance but cannot directly enable a Defender for Cloud plan; plans are enabled at the subscription or management group level in Defender for Cloud settings, not via policy assignment. Option C is wrong because there is no 'Defender for Servers plan' toggle on a VM's security configuration blade; Defender for Cloud plans are configured at the subscription level in the Defender for Cloud environment settings, not per VM. Option D is wrong because while supported OS is required for protection, the plan is not automatically enabled for all VMs; it must be explicitly enabled at the subscription level.

494
MCQmedium

A security team wants to visualize MITRE ATT&CK coverage for Microsoft Sentinel analytics rules. Which Sentinel experience should they use?

A.Hunting bookmarks
B.Watchlists
C.MITRE ATT&CK coverage in analytics/content hub views
D.Data collection endpoints
AnswerC

In Microsoft Sentinel, the MITRE ATT&CK coverage view is accessible from the Analytics blade and in Content Hub solution views, where enabled analytics rules are mapped to specific tactics and techniques on the ATT&CK matrix. Each rule's 'Tactics' and 'Techniques' properties drive the color-coded cells, letting security teams quickly identify which techniques are currently detected. This directly provides the visualization required.

Why this answer

The MITRE ATT&CK coverage view in the Microsoft Sentinel analytics/content hub provides a direct mapping between configured analytics rules and specific MITRE ATT&CK techniques. This allows security teams to visually identify gaps in detection coverage by seeing which techniques are covered by active rules and which are not, enabling targeted rule deployment.

Exam trap

The trap here is that candidates confuse the MITRE ATT&CK coverage view with other Sentinel features like Hunting or Watchlists, which are unrelated to analytics rule mapping, leading them to select a plausible-sounding but incorrect option.

How to eliminate wrong answers

Option A is wrong because Hunting bookmarks are used to save and annotate specific query results for later investigation, not to visualize MITRE ATT&CK coverage of analytics rules. Option B is wrong because Watchlists are collections of data (e.g., IP addresses, hostnames) used for correlation and enrichment in queries, not for mapping analytics rules to MITRE ATT&CK techniques. Option D is wrong because Data collection endpoints are configuration objects for ingesting data from sources like Azure Monitor Agent, unrelated to analytics rule coverage mapping.

495
MCQhard

You are a security engineer for Contoso Ltd. The company has a hybrid environment with Azure VMs and on-premises servers running Windows Server 2022. You have enabled Microsoft Defender for Cloud's multi-cloud posture management for AWS and GCP. Recently, you deployed Microsoft Sentinel in a Log Analytics workspace named 'ContosoWorkspace'. The security team needs to centralize security alerts from all sources: Azure, on-premises, AWS, and GCP. They also require automated investigation and response for common threats. Specifically, they want to automatically disable a compromised user account when a high-severity alert is generated. You have configured data connectors for Azure Activity, Microsoft Entra ID, and AWS CloudTrail. For on-premises servers, you installed the Azure Monitor Agent (AMA) and enabled Defender for Cloud's plan for servers. For GCP, you are using the GCP Security Command Center connector. The team needs to create a playbook that runs when a high-severity alert from any source is triggered. The playbook should disable the user account in Microsoft Entra ID. You have created a playbook using Azure Logic Apps and granted it the necessary permissions. Which step should you take to ensure the playbook runs automatically when alerts are generated?

A.Create an automation rule in Microsoft Sentinel that triggers the playbook when a high-severity alert is created.
B.Create an automation rule in Microsoft Defender for Cloud that triggers the playbook when a high-severity alert is generated.
C.Create an analytics rule in Microsoft Sentinel that triggers the playbook when a high-severity alert is created.
D.Configure the Logic App to run on a schedule and query Sentinel for high-severity alerts.
AnswerA

In Microsoft Sentinel, automation rules are the native mechanism for executing a playbook when an incident or alert is generated; you configure a condition such as 'Alert severity equals High' and an action of 'Run playbook' on the selected Logic App. This triggers immediately at alert creation time, without requiring polling or scheduled jobs. It is the correct and recommended approach for real-time response to high-severity Sentinel alerts.

Why this answer

The correct option is A: create an automation rule in Microsoft Sentinel that triggers the playbook when a high-severity alert is created. Automation rules in Microsoft Sentinel are the native mechanism for automatically invoking playbooks (Logic Apps) in response to incidents or alerts, and they can filter by severity so the playbook runs only for high-severity alerts. Option B is wrong because automation rules in Microsoft Defender for Cloud govern Defender for Cloud alerts and cannot directly trigger a Sentinel playbook for alerts from all connected sources.

Option C is wrong because analytics rules generate alerts/incidents from ingested data; they do not trigger playbooks. Option D is wrong because a scheduled Logic App polling Sentinel would not provide the required automatic, event-driven response when an alert is generated.

496
Multi-Selectmedium

A company manages Azure AD roles with Privileged Identity Management (PIM). They want to enforce that when a user activates the Global Administrator role, they must provide a justification and also use Multi-Factor Authentication. Which PIM settings should they configure? (Choose two.)

Select 2 answers
A.Require approval on activation.
B.Require Multi-Factor Authentication on activation.
C.Require justification on activation.
D.Extend activation duration.
AnswersB, C

Requiring Multi-Factor Authentication on activation forces the user to complete an MFA challenge during the activation request, such as through the Microsoft Authenticator app or a phone call, before the privileged role is assigned. This directly satisfies the security requirement for MFA on activation, and PIM evaluates this condition even if the user already has an existing Azure AD session.

Why this answer

PIM allows you to enforce Multi-Factor Authentication (MFA) as a mandatory step during role activation, ensuring the user's identity is verified beyond just a password. Option C is correct because PIM's 'Require justification on activation' setting forces the user to provide a business reason for activating the Global Administrator role, which is a common compliance requirement. Together, these two settings satisfy the requirement for both MFA and justification during activation.

Exam trap

The trap here is that candidates often confuse 'Require approval on activation' with 'Require justification on activation'—approval involves a separate approver, while justification is simply a text input from the user, and the question specifically asks for justification, not approval.

497
MCQmedium

You are a security engineer for a company that uses Microsoft Sentinel. The security operations center (SOC) wants to automatically assign new incidents to the on-call analyst based on the incident's severity and product name. You need to configure this with minimal administrative effort. What should you do?

A.Create an automation rule that triggers when an incident is created and uses conditions on severity and product name to assign the incident to a specific owner.
B.Use an analytics rule that groups related alerts into incidents and sets the owner based on severity and product name.
C.Configure a playbook that runs on incident creation and uses the 'Update incident' action to assign the incident to the on-call analyst.
D.Modify the incident settings in Microsoft Sentinel to enable automatic assignment of incidents to the on-call analyst based on severity and product name.
AnswerA

Automation rules in Microsoft Sentinel are designed to automatically triage incidents. They can trigger on incident creation and evaluate conditions such as severity and product name. The action 'Assign owner' allows you to set the incident owner dynamically, fulfilling the requirement with minimal effort.

Why this answer

Automation rules in Microsoft Sentinel are the native mechanism for automatically triaging incidents. They can trigger on incident creation, evaluate conditions such as severity and product name, and perform actions like assigning an owner. This approach requires minimal configuration and directly addresses the SOC's requirement without the overhead of building a playbook.

Exam trap

The trap here is assuming that analytics rules or incident settings can automatically assign incident owners, when in fact that capability resides in automation rules.

498
MCQeasy

A company has a subscription with Azure Active Directory (Azure AD). They want to enable a conditional access policy that requires all users to use multi-factor authentication (MFA) when accessing the Azure portal. The policy should only apply to users who are members of a group called 'AllUsers'. Which assignment should they configure in the policy?

A.Assign the 'AllUsers' group to the 'Cloud apps' section and select 'Azure portal' as the application
B.Assign the 'AllUsers' group to the 'Users' section and select 'Azure portal' as the cloud app
C.Add a condition for 'Client apps' specifying 'Browser' only
D.Create two policies: one for users and one for the Azure portal
AnswerB

This is the correct configuration because a Conditional Access policy requires both a user scope and an application scope. Adding the AllUsers group in the Users section targets all user identities, and selecting Azure portal as the cloud app limits the policy to sign-ins to that specific application. This combination ensures that every user is evaluated when accessing the Azure portal, allowing you to apply access controls such as MFA.

Why this answer

In an Azure AD Conditional Access policy, the 'Users' section is where you specify which users or groups the policy applies to, and the 'Cloud apps' section is where you select the target application (Azure portal). By assigning the 'AllUsers' group to 'Users' and selecting 'Azure portal' as the cloud app, the policy enforces MFA for all members of that group when they access the Azure portal.

Exam trap

The trap here is that candidates confuse the 'Users' assignment with the 'Cloud apps' assignment, mistakenly thinking that groups are assigned to applications rather than to the user scope of the policy.

How to eliminate wrong answers

Option A is wrong because the 'AllUsers' group should be assigned to the 'Users' section, not the 'Cloud apps' section; the 'Cloud apps' section is for selecting the target application (e.g., Azure portal), not for user assignment. Option C is wrong because restricting to 'Browser' client apps would only enforce MFA for browser-based access, but the requirement is to enforce MFA for all access to the Azure portal, including PowerShell, CLI, or mobile apps; this condition would be too narrow. Option D is wrong because a single Conditional Access policy can include both user assignment and cloud app selection; creating two separate policies is unnecessary and could lead to conflicting or overlapping rules.

499
MCQmedium

You are the security administrator for a company that uses Azure Blob Storage to store sensitive documents. You need to ensure that all blob data is encrypted at rest using customer-managed keys (CMK) stored in Azure Key Vault. You have enabled encryption with CMK on the storage account. However, after a key rotation in Key Vault, you notice that newly uploaded blobs are encrypted with the new key, but existing blobs are still encrypted with the old key. You need to ensure that all blobs are re-encrypted with the new key. What should you do?

A.Update the storage account's encryption scope to use the new key version and then call the 'Rewrite' operation on each blob.
B.Set the storage account encryption to use a different key, then revert to the original key to force re-encryption.
C.No action is needed; Azure Storage automatically re-encrypts existing blobs with the new key after rotation.
D.Re-upload the existing blobs using the new key version by calling the Put Blob operation with the new encryption key.
AnswerD

To encrypt existing blobs with the new key version, you need to rewrite them. The recommended approach is to call the Put Blob operation (e.g., using the same blob name) with the new encryption key version, which overwrites the existing blob and encrypts it under the current key. This ensures the blob's encryption metadata is updated to reflect the new key version. You could also use Copy Blob or an Azure Storage SDK to read and re-upload the data, but Put Blob is the direct mechanism.

Why this answer

To ensure all blobs are re-encrypted with the new key, you must trigger a rewrite of the blob data. Re-uploading the existing blobs using the Put Blob operation with the new encryption key forces the storage account to re-encrypt the data using the latest key version from Key Vault. Option A is incorrect because the 'Rewrite' operation does not exist in Azure Blob Storage; you must overwrite the blob to trigger re-encryption.

Option B is incorrect because changing the encryption key setting does not retroactively re-encrypt existing blobs; it only applies to new blobs. Option C is incorrect because Azure Storage does not automatically re-encrypt existing blobs when the key is rotated; only new blobs use the new key version.

500
MCQmedium

A company generates shared access signature (SAS) tokens to grant time-limited access to blobs in an Azure Storage container. A security administrator needs the ability to immediately revoke all active SAS tokens for that container if a token is compromised. What should they use?

A.Use a stored access policy on the container and reference it in the SAS token.
B.Use a user delegation key to create the SAS token.
C.Use an account-level SAS token.
D.Use a service-level SAS token with IP address restrictions.
AnswerA

By attaching the SAS to a stored access policy defined on the container, you gain a centralized revocation point: deleting or shortening the policy's expiry immediately invalidates every SAS token that references it, regardless of the token's own expiry time. Because the policy controls permissions, start time, and expiry, you can also modify access after issuance without redeploying new tokens. This is why a stored access policy is required for full revocation control in Azure Storage.

Why this answer

A stored access policy on the container provides a centralized way to manage permissions for shared access signatures (SAS). By associating the SAS token with the policy, you can immediately revoke all tokens that reference that policy by simply deleting or modifying the policy's permissions or expiry time. This is the only method that allows instant revocation of multiple SAS tokens without waiting for their individual expiry.

Exam trap

The trap here is that candidates often assume that regenerating storage account keys (which invalidates account-level SAS tokens) is the fastest way to revoke access, but that approach is overly broad and disruptive, whereas a stored access policy provides granular, immediate revocation for a specific container without affecting other resources.

How to eliminate wrong answers

Option B is wrong because a user delegation key is used to sign a user delegation SAS, but revoking the key requires regenerating the storage account's delegated key, which invalidates all SAS tokens signed with that key, not just those for a specific container. Option C is wrong because an account-level SAS token grants access to multiple services (blobs, queues, tables, files) and cannot be scoped to a single container; revoking it would require regenerating the storage account keys, affecting all SAS tokens and applications. Option D is wrong because a service-level SAS token with IP address restrictions only limits the source IP addresses from which the token can be used, but it does not provide a mechanism to revoke the token before its expiry; the token remains valid until its expiration time.

501
MCQmedium

You are reviewing an Azure Policy definition. You need to determine the effect of this policy when a user attempts to create a new storage account with 'Secure transfer required' set to 'Disabled'. What happens?

A.The storage account is created but 'Secure transfer required' is automatically enabled.
B.The creation request is denied.
C.The creation is allowed but an audit event is generated.
D.The creation is allowed and no action is taken.
AnswerB

This is correct: when the Azure Policy definition contains the effect 'deny', the policy engine evaluates the incoming resource creation request and, if the defined condition (for example, a storage account lacking 'Secure transfer required') is true, the request is rejected before any resource is provisioned. The operation fails with an error such as 403 Forbidden or a policy enforcement error, and no storage account is created. Policy enforcement is deterministic and prevents the non-compliant resource from entering the environment.

Why this answer

The correct answer is B: the creation request is denied. This policy uses a Deny effect, which blocks any request that violates the policy rule—here, creating a storage account with 'Secure transfer required' set to Disabled—so the deployment fails before the resource is provisioned. Option A is wrong because Deny does not remediate or modify the request; auto-enabling would require a Modify or DeployIfNotExists effect.

Option C is wrong because generating an audit event corresponds to the Audit effect, which only logs non-compliance without blocking. Option D is wrong because Deny actively prevents the non-compliant creation rather than allowing it silently.

502
MCQmedium

A company enables Azure SQL Database auditing to log database events to a storage account. The security policy requires that the audit logs be protected from tampering and deletion after they are written. Which storage account feature should the company enable to ensure that audit log files cannot be modified or deleted by anyone for a specified retention period?

A.Soft delete
B.Immutable storage
C.Hierarchical namespace
D.Firewall and virtual networks
AnswerB

Immutable storage is correct because it enforces a Write-Once-Read-Many (WORM) policy at the container or version level, blocking any delete or modify operation on blobs for a set retention period. This time-based retention lock makes the stored audit logs tamper-proof and compliant with regulatory frameworks such as SEC 17a-4f. After the policy is locked, even an account administrator cannot shorten the retention interval or disable immutability, ensuring that Azure SQL Database audit records remain intact until the policy expires.

Why this answer

Immutable storage for Azure Blob Storage provides a WORM (Write Once, Read Many) policy that prevents audit log files from being modified or deleted by any user, including administrators, for a specified retention period. This directly meets the security requirement to protect audit logs from tampering and deletion after they are written.

Exam trap

The trap here is that candidates often confuse soft delete with immutable storage, thinking that soft delete's ability to recover deleted blobs is sufficient for tamper-proofing, but soft delete does not prevent modification or deletion in the first place.

How to eliminate wrong answers

Option A is wrong because soft delete only protects against accidental deletion by retaining deleted blobs for a configurable period, but it does not prevent intentional modification or deletion by authorized users during the retention period. Option C is wrong because hierarchical namespace is a feature of Azure Data Lake Storage Gen2 that organizes blobs into a directory hierarchy, but it provides no data immutability or tamper-proof protection. Option D is wrong because firewall and virtual networks restrict network access to the storage account but do not prevent modification or deletion of blobs by users who have legitimate access through the network.

503
MCQmedium

A company uses Microsoft Defender for Cloud to manage security posture. The security team wants to receive alerts when a virtual machine has a vulnerability rated as 'Critical' by the integrated vulnerability assessment solution. Which Defender for Cloud plan must be enabled for the subscription to receive these alerts?

A.Defender for Servers Plan 1
B.Defender for Servers Plan 2
C.Defender for Storage
D.Defender for Databases
AnswerB

Defender for Servers Plan 2 builds on Plan 1 by adding integrated vulnerability assessment (Defender Vulnerability Management), just-in-time VM access, and allowlisting. This tier continuously scans Azure VMs for missing security updates, known CVEs, and OS misconfigurations, then raises security alerts and recommendations. For a company using Defender for Cloud to manage server security, Plan 2 is the correct choice to generate alerts for critical vulnerabilities.

Why this answer

Defender for Servers Plan 2 is required because it includes the integrated Qualys-based vulnerability assessment solution that automatically scans VMs and generates security alerts for critical vulnerabilities. Plan 1 only provides basic threat detection and does not include the vulnerability assessment engine or the corresponding alerting capability.

Exam trap

The trap here is that candidates often assume Defender for Servers Plan 1 is sufficient because it provides basic threat alerts, but they overlook that the integrated vulnerability assessment (Qualys) and its critical vulnerability alerts are exclusive to Plan 2.

How to eliminate wrong answers

Option A is wrong because Defender for Servers Plan 1 only offers basic threat detection and does not include the integrated vulnerability assessment solution (Qualys) that generates alerts for critical vulnerabilities. Option C is wrong because Defender for Storage is designed to protect Azure Storage accounts from threats like malware and data exfiltration, not to assess VM vulnerabilities. Option D is wrong because Defender for Databases focuses on database services (e.g., Azure SQL, Azure Database for PostgreSQL) and does not provide vulnerability scanning for virtual machines.

504
MCQmedium

Refer to the exhibit. You are analyzing a KQL query in Microsoft Sentinel. The query returns a list of IP addresses that have attempted to sign in more than 10 times in the last day. You notice that the query does not filter out successful sign-ins. You need to modify the query to count only failed sign-in attempts. What should you add?

A.Add '| where Status == "Failure"' before the summarize
B.Add '| where Result == "Failure"' before the summarize
C.Add '| where ResultType == "0"' before the summarize
D.Add '| where ResultType != "0"' before the summarize
AnswerD

Placing `ResultType != '0'` before the summarize filters the stream down to failed authentication attempts, because every successful sign-in shares ResultType 0 and every non-zero code represents a specific failure condition. Kusto evaluates row filters before aggregations, so the subsequent summarize counts only the intended failure events and produces the required hourly failure trend. This predicate also avoids the non-existent columns and string labels used in the incorrect options.

Why this answer

In Microsoft Sentinel, the KQL query for sign-in logs uses the 'ResultType' field to indicate success or failure. A 'ResultType' of '0' represents a successful sign-in, while any non-zero value indicates a failure. Therefore, to count only failed sign-in attempts, you must filter with '| where ResultType != "0"' before the summarize operator.

Option D correctly applies this filter, excluding successful sign-ins and ensuring the count reflects only failures.

Exam trap

The trap here is that candidates may confuse the field names (e.g., 'Status' or 'Result') or mistakenly filter for 'ResultType == "0"' (success) instead of 'ResultType != "0"' (failure), because the question explicitly asks to count only failed attempts.

How to eliminate wrong answers

Option A is wrong because 'Status' is not a standard field in Azure AD sign-in logs; the correct field for sign-in outcome is 'ResultType'. Option B is wrong because 'Result' is not a valid field name in the SigninLogs table; the actual field is 'ResultType'. Option C is wrong because 'ResultType == "0"' would filter for successful sign-ins only, which is the opposite of what is needed.

505
MCQmedium

Your company uses Microsoft Defender for Cloud to assess the security posture of Azure subscriptions. The security team receives an alert about a critical vulnerability in an Azure VM that was remediated two weeks ago. What is the most likely reason the alert is still active?

A.The VM has not been rescanned after the remediation was applied.
B.The alert is a false positive due to a known issue in the vulnerability assessment engine.
C.The alert has a 30-day retention period and cannot be dismissed before that.
D.Silent Remediation was enabled, preventing the alert from being dismissed.
AnswerA

Defender for Cloud evaluates VMs against the last completed vulnerability scan, not in real time. Applying a patch or configuration change does not automatically clear the finding; the VM must be rescanned (via the 'Rescan' action or the next scheduled scan) for the vulnerability status to refresh. Without that rescan, the vulnerability management dashboard continues to show the VM as vulnerable, even though the remediation actually succeeded.

Why this answer

The alert remains active because Microsoft Defender for Cloud relies on periodic vulnerability scans to update the security findings. Remediating the vulnerability on the VM does not automatically trigger a rescan; the alert status is only updated after the next scheduled scan or a manual rescan is initiated. Until the VM is rescanned, Defender for Cloud continues to display the previous vulnerable state.

Exam trap

The trap here is that candidates assume remediation automatically clears the alert, but Microsoft Defender for Cloud requires a rescan to update the vulnerability state, and the alert will persist until the next scan cycle or manual rescan.

How to eliminate wrong answers

Option B is wrong because false positives in the vulnerability assessment engine are rare and typically documented; the question states the vulnerability was actually remediated, so the alert is not a false positive. Option C is wrong because alerts in Defender for Cloud do not have a mandatory 30-day retention period that prevents dismissal; alerts can be dismissed or closed manually once the issue is resolved, and retention policies affect historical data, not active alert status. Option D is wrong because Silent Remediation is a feature for automatically applying certain recommendations, but it does not prevent alerts from being dismissed; it actually helps resolve vulnerabilities, and the alert would still update after a rescan.

506
MCQmedium

A security team uses Microsoft Defender for Cloud. They want to receive a weekly email summary of the Secure Score, top recommendations, and new alerts for their subscription. Which feature should they configure?

A.Enable the 'Weekly email summary' option in the Defender for Cloud email notifications settings.
B.Configure continuous export to export all security data to a Log Analytics workspace and use a workbook to create a summary.
C.Create a workflow automation that triggers on a schedule and uses a Logic App to send an email summary.
D.Enable the 'Security Policy' default initiative to automatically send reports.
AnswerA

Defender for Cloud email notifications settings include 'Weekly email summary' that sends a personalized overview of Secure Score, top recommendations, and alerts to specified recipients. It's a native, built-in reporting feature that can be enabled directly from the environment settings without any external integration or compute. Ensure the email is configured to be sent weekly by checking the 'Weekly email summary' checkbox and setting the recipient email address(es) in the Defender for Cloud email notifications pane.

Why this answer

Defender for Cloud includes a built-in 'Email notifications' settings page where you can enable a weekly email summary that automatically delivers the Secure Score, top recommendations, and new alerts. This feature is designed specifically for periodic, high-level security posture summaries without requiring custom infrastructure.

Exam trap

The trap here is that candidates confuse the built-in 'Weekly email summary' with custom automation solutions (Logic Apps, continuous export) or policy-based reporting, assuming a scheduled email requires external orchestration when Defender for Cloud already provides a native, one-click configuration.

How to eliminate wrong answers

Option B is wrong because continuous export to a Log Analytics workspace is used for real-time streaming of security data for custom analytics or retention, not for generating a pre-built weekly email summary; it requires additional manual setup (e.g., workbooks, scheduled queries) to produce an email. Option C is wrong because workflow automation in Defender for Cloud triggers on specific events (e.g., alert generation, recommendation state change), not on a schedule; using a Logic App on a schedule would be a custom workaround, not the native feature designed for this purpose. Option D is wrong because the 'Security Policy' default initiative (e.g., Azure Security Benchmark) defines compliance controls and remediation logic, but it does not include any capability to automatically send reports or email summaries.

507
MCQhard

Your organization uses Microsoft Intune for mobile device management. You need to implement a conditional access policy that only allows access to corporate email from devices that are enrolled in Intune and compliant with security policies. However, the policy is not working for some users who report that they cannot access email even though their devices are compliant. You discover that the users have multiple devices and are signing in from a device that is not enrolled. What should you do?

A.Enroll all devices in Intune
B.Remove the conditional access policy
C.Use app protection policies instead
D.Ensure users sign in only from compliant devices
AnswerD

Conditional access evaluates the device used at sign-in, so a compliant device does not help when the user authenticates from an unenrolled one. Requiring sign-in only from compliant devices blocks that access, satisfying the policy's device-compliance constraint.

Why this answer

The correct answer is D: Ensure users sign in only from compliant devices. In a Conditional Access scenario, the policy evaluates the specific device used for the sign-in, so if a user has multiple devices and authenticates from a non-enrolled or non-compliant one, access to corporate email will be blocked even if another of their devices is compliant; the fix is to make sure the sign-in originates from a compliant device. Option A is unnecessary and impractical because enrolling every device is not required by the policy, only the device being used for access must be enrolled and compliant.

Option B would defeat the security requirement entirely by removing the control. Option C does not fit because app protection policies (MAM) protect app data on unmanaged devices but do not satisfy a Conditional Access requirement that the device itself be Intune-enrolled and compliant.

508
MCQhard

You are designing a solution to store sensitive documents in Azure Blob Storage. The documents must be encrypted at rest using a customer-managed key that is automatically rotated every 90 days. Microsoft Entra ID must be used to control access to the key. What should you use?

A.Azure Storage Service Encryption (SSE) with platform-managed keys.
B.Azure Storage encryption with infrastructure encryption enabled.
C.Azure Storage Service Encryption (SSE) with a customer-managed key stored in Azure Key Vault and configure key rotation.
D.Client-side encryption (CSE) using Azure Key Vault.
AnswerC

Azure Storage Service Encryption (SSE) with a customer-managed key stored in Azure Key Vault allows you to bring your own key (BYOK) and retain full control over key lifecycle, including enabling automatic rotation on schedule. By configuring key rotation, you can replace keys periodically to meet security and compliance policies, and you can audit key usage through Key Vault and Azure Monitor. This provides the necessary customer control and rotation that are missing from Microsoft-managed key options.

Why this answer

Azure Storage Service Encryption (SSE) with a customer-managed key (CMK) stored in Azure Key Vault allows you to control the encryption key used for data at rest in Blob Storage. By storing the key in Key Vault, you can configure automatic key rotation every 90 days, and you can use Microsoft Entra ID (formerly Azure AD) to control access to the key via RBAC roles such as Key Vault Crypto Officer. This meets all requirements: encryption at rest, customer-managed key, automatic rotation, and Entra ID-based access control.

Exam trap

The trap here is that candidates often confuse client-side encryption (CSE) with server-side encryption (SSE), mistakenly thinking CSE is required for customer-managed keys, when in fact SSE with CMK in Key Vault provides the same key control with automatic rotation and simpler management.

How to eliminate wrong answers

Option A is wrong because SSE with platform-managed keys uses Microsoft-managed keys, which cannot be rotated on a customer-defined schedule (e.g., every 90 days) and do not allow customer control over the key. Option B is wrong because infrastructure encryption is an additional layer of encryption that uses platform-managed keys at the storage infrastructure level; it does not involve customer-managed keys or automatic rotation. Option D is wrong because client-side encryption (CSE) encrypts data before it is sent to Azure Storage, which requires managing encryption keys on the client side and does not natively support automatic key rotation or direct Entra ID-based access control for the key in the same way as SSE with CMK.

509
MCQmedium

Your company uses Microsoft Intune for mobile device management. You need to ensure that only devices that are compliant with company policies can access corporate resources. You have configured compliance policies in Intune. What additional step is required to enforce access control based on device compliance?

A.Create a Conditional Access policy that requires device to be marked as compliant
B.Enable certificate-based authentication for all devices
C.Deploy device configuration profiles to all devices
D.Configure app protection policies in Microsoft Defender for Cloud Apps
AnswerA

A Conditional Access policy that requires a device to be marked as compliant works directly with Microsoft Intune's compliance policies. When a device fails to meet compliance rules (e.g., PIN required, OS version, threat level), Intune marks it as non-compliant, and Conditional Access evaluates this state at sign-in to block access to cloud apps. This is the standard enforcement mechanism for Intune-managed devices.

Why this answer

A is correct because Conditional Access in Azure AD is the policy engine that enforces access control decisions based on signals like device compliance. Even after Intune compliance policies are configured, you must create a Conditional Access policy that requires the device to be marked as compliant. This policy blocks or grants access to corporate resources (e.g., Exchange Online, SharePoint) based on the compliance state reported by Intune to Azure AD.

Exam trap

The trap here is that candidates often assume Intune compliance policies alone enforce access control, but they only define the rules; Conditional Access is the separate service that actually enforces the block or grant based on those rules.

How to eliminate wrong answers

Option B is wrong because certificate-based authentication (CBA) authenticates the device or user but does not enforce compliance-based access control; it only verifies identity via certificates. Option C is wrong because device configuration profiles define settings (e.g., Wi-Fi, VPN) but do not enforce access control based on compliance state. Option D is wrong because app protection policies in Microsoft Defender for Cloud Apps (formerly MCAS) manage data protection within apps, not device-level compliance enforcement for access.

510
MCQhard

You are designing a secure compute solution for a critical application that must comply with PCI DSS. The application runs on Azure Virtual Machines with sensitive data. You need to ensure that ephemeral disks are encrypted at the host level. Which Azure Disk Encryption option should you use?

A.Server-side encryption (SSE) with platform-managed keys
B.Azure Disk Encryption (ADE) with Key Vault
C.Double encryption (SSE with CMK and ADE)
D.Encryption at host
AnswerD

Encryption at host encrypts the VM's temp disk and the caches of the OS and data disks at the physical compute host, using platform-managed or customer-managed keys. This is the only option that directly covers the ephemeral disk, which is where unencrypted cardholder data could otherwise be written. When enabled, it satisfies the PCI DSS at-rest encryption requirement for all disk types in the VM, including managed disks, temp disk, and caches.

Why this answer

Encryption at host encrypts data at the VM host level, including ephemeral disks, before it is transmitted to Azure Storage. This meets the PCI DSS requirement for encrypting ephemeral disks at rest without relying on the guest OS or key management. It uses server-side encryption with platform-managed or customer-managed keys directly on the host node.

Exam trap

The trap here is that candidates confuse guest OS encryption (ADE) with host-level encryption, assuming ADE covers ephemeral disks when it only encrypts OS and data disks within the VM.

How to eliminate wrong answers

Option A is wrong because Server-side encryption (SSE) with platform-managed keys encrypts only managed disks and snapshots at the Azure Storage service level, not ephemeral disks on the host. Option B is wrong because Azure Disk Encryption (ADE) with Key Vault uses BitLocker (Windows) or DM-Crypt (Linux) within the guest OS, which does not encrypt ephemeral disks at the host level. Option C is wrong because Double encryption (SSE with CMK and ADE) combines two layers of encryption for managed disks but still does not address host-level encryption of ephemeral disks.

511
MCQeasy

A security analyst uses Microsoft Defender for Cloud to monitor the security posture of their Azure subscription. They want to receive an email notification whenever a high-severity security alert is generated for any of their Azure resources. What should they configure in Defender for Cloud?

A.Create an alert rule in Azure Monitor that triggers an email when a security alert is raised.
B.Configure email notifications in the Defender for Cloud settings under 'Notifications'.
C.Use a Logic Apps playbook to send an email when a new alert is generated.
D.Set up a workflow automation rule in Microsoft Sentinel to forward alerts to email.
AnswerB

Configuring email notifications directly in Microsoft Defender for Cloud is the native, built-in mechanism for receiving security alert emails. In the Defender for Cloud portal, you navigate to Environment Settings, select the relevant subscription, and under 'Notifications' you can specify recipient email addresses and the severity levels (e.g., High, Medium, Low) that trigger emails. This setting is managed within Defender for Cloud itself, so it does not require external services like Azure Monitor, Logic Apps, or a separate SIEM, and it is the exact option designed for this scenario.

Why this answer

Microsoft Defender for Cloud has a built-in 'Email notifications' setting under its environment settings that allows you to configure email recipients for high-severity alerts directly, without needing external services. This feature sends real-time email notifications for security alerts based on severity levels you define, making it the simplest and most direct method for this requirement.

Exam trap

The trap here is that candidates often confuse Defender for Cloud's native email notification settings with Azure Monitor alert rules or Logic Apps playbooks, assuming that security alerts must be routed through external services to trigger email, when in fact Defender for Cloud provides a direct configuration option for this purpose.

How to eliminate wrong answers

Option A is wrong because Azure Monitor alert rules can trigger on metrics or logs, but they cannot directly consume Defender for Cloud security alerts as a signal source; security alerts are managed within Defender for Cloud's own alert pipeline, not Azure Monitor metric/log alerts. Option C is wrong because Logic Apps playbooks are typically used for automated response actions (e.g., remediation) triggered by Defender for Cloud alerts, but they require additional configuration and are not the native email notification mechanism for alert generation. Option D is wrong because Microsoft Sentinel workflow automation rules are designed for incident creation and orchestration within Sentinel, not for forwarding Defender for Cloud alerts to email; Sentinel can ingest Defender for Cloud alerts, but email notification for those alerts is not a direct feature of Sentinel's automation rules.

512
MCQmedium

A security team uses Microsoft Sentinel. They want to automatically assign a severity level and an owner to every incident that is created from a specific analytics rule. The owner should be a specific security operations group. Which Microsoft Sentinel feature should they configure to achieve this automation?

A.Modify the analytics rule to include a custom script that runs upon alert generation.
B.Create an automation rule that triggers when an incident is created and sets the severity and owner fields.
C.Use a Logic Apps playbook connected to the analytics rule's alert generation trigger.
D.Configure a workbook to filter and manually assign incidents.
AnswerB

Automation rules in Sentinel are purpose-built to perform immediate actions, such as changing severity or assigning an owner, when an incident is created (e.g., when triggered by a specific analytics rule's incident generation). They support conditions and multiple actions and can be prioritized to ensure the desired incident properties are set consistently. This makes automation rules the correct way to enforce classification and ownership at the point of incident creation, without custom code or external integration.

Why this answer

Automation rules in Microsoft Sentinel allow you to centrally manage incident handling by triggering actions when incidents are created or updated. By configuring an automation rule that triggers on incident creation from the specific analytics rule, you can automatically set the severity and assign the incident to a security operations group (via an Azure AD group or user) without custom scripting or manual intervention.

Exam trap

The trap here is that candidates often confuse automation rules with playbooks, assuming that any automation requires a Logic Apps playbook, but automation rules are the correct, lightweight feature for simple field assignments like severity and owner.

How to eliminate wrong answers

Option A is wrong because analytics rules do not support embedding custom scripts directly; they generate alerts or incidents, and automation is handled separately via automation rules or playbooks. Option C is wrong because while a Logic Apps playbook can be triggered by an analytics rule, it is typically used for complex, multi-step orchestration (e.g., enrichment or response actions), not for simply setting severity and owner fields, which is more efficiently done with an automation rule. Option D is wrong because workbooks are visualization and reporting tools, not automation mechanisms; they cannot assign severity or ownership to incidents.

513
MCQeasy

Your organization has multiple Azure subscriptions and wants to centrally manage Azure Firewall policies across all subscriptions. What should you use?

A.Azure Policy to enforce firewall rules
B.Azure Firewall Manager
C.Azure Resource Manager templates
D.Azure Network Watcher
AnswerB

Azure Firewall Manager is the central management service that lets you create, organize, and apply firewall policies to multiple Azure Firewalls across different subscriptions in a single tenant. It provides hierarchical policy inheritance (global, regional), and can also deploy and manage firewalls in both secured virtual hubs (Virtual WAN) and hub virtual networks, while integrating with security partners. This directly addresses the need for consistent, centrally managed firewall rules across subscriptions.

Why this answer

Azure Firewall Manager is the correct choice because it provides a centralized platform to create, manage, and enforce firewall policies across multiple Azure subscriptions and regions. It allows you to define a parent policy that child firewall instances inherit, ensuring consistent security rules without manual per-firewall configuration. This aligns directly with the requirement for central management of Azure Firewall policies.

Exam trap

The trap here is that candidates often confuse Azure Policy (which enforces resource compliance) with Azure Firewall Manager (which manages firewall policies), leading them to incorrectly select Azure Policy for centralized firewall rule management.

How to eliminate wrong answers

Option A is wrong because Azure Policy is used to enforce compliance rules on Azure resources (e.g., requiring a specific SKU or tagging), but it cannot directly manage or deploy Azure Firewall policy rules (like network or application rules) across firewalls. Option C is wrong because Azure Resource Manager templates are infrastructure-as-code artifacts for deploying resources, but they do not provide ongoing centralized management or policy inheritance across multiple subscriptions; each deployment would require manual template updates. Option D is wrong because Azure Network Watcher provides network monitoring and diagnostic tools (e.g., packet capture, topology, NSG flow logs), but it has no capability to manage or enforce firewall policies.

514
MCQeasy

You are configuring a conditional access policy to block access from untrusted locations. The policy should apply to all cloud apps except Microsoft Entra ID Administration. How should you configure the policy?

A.Include 'All cloud apps' and set 'Block access'
B.Include 'Select apps' and choose all apps except admin
C.Include 'All cloud apps' and exclude 'Microsoft Entra ID Administration'
D.Include 'All cloud apps' and exclude 'Office 365'
AnswerC

Conditional access evaluates include and exclude scopes, with exclusions taking precedence. Selecting 'All cloud apps' as the include and excluding 'Microsoft Entra ID Administration' satisfies the requirement to block untrusted locations everywhere except administrative access, avoiding the need to enumerate every individual app.

Why this answer

The requirement is to block access from untrusted locations for all cloud apps except Microsoft Entra ID Administration. In Conditional Access, you include 'All cloud apps' to cover every app, then explicitly exclude 'Microsoft Entra ID Administration' to exempt it from the block. This ensures the policy applies broadly while honoring the exclusion.

Exam trap

The trap here is that candidates often confuse 'Microsoft Entra ID Administration' with 'Office 365' or think they must manually select all apps, missing the efficient 'All cloud apps' plus exclusion pattern.

How to eliminate wrong answers

Option A is wrong because including 'All cloud apps' and setting 'Block access' would block all cloud apps, including Microsoft Entra ID Administration, which violates the requirement to exclude it. Option B is wrong because 'Select apps' requires manually picking each app, which is impractical for 'all cloud apps except one' and does not dynamically cover future apps. Option D is wrong because excluding 'Office 365' does not match the requirement to exclude 'Microsoft Entra ID Administration'; Office 365 is a different app set and would incorrectly block the admin portal.

515
MCQmedium

A company deploys a web application on Azure VMs behind an Azure Load Balancer (Standard SKU). They want to protect the application from common web attacks like SQL injection and cross-site scripting. Which Azure service should they enable?

A.Azure Application Gateway with Web Application Firewall (WAF) policy.
B.Azure Firewall.
C.Network Security Groups on the VM subnet.
D.Azure DDoS Protection.
AnswerA

Azure Application Gateway is a Layer 7 load balancer that can terminate TLS, route HTTP traffic, and enforce a Web Application Firewall policy using the Open Web Application Security Project (OWASP) Core Rule Set. The WAF inspects headers, body, cookies, and URL parameters to detect and block common attacks such as SQL injection, cross-site scripting, and remote file inclusion. This is the appropriate service because it operates at the application layer and can be integrated directly into the application delivery path for the VMs.

Why this answer

Azure Application Gateway with a Web Application Firewall (WAF) policy is the correct choice because it operates at Layer 7 (HTTP/HTTPS) and provides centralized, inbound protection against common web attacks such as SQL injection and cross-site scripting (XSS). The WAF policy uses OWASP Core Rule Sets (CRS) to inspect HTTP request payloads and headers, blocking malicious traffic before it reaches the backend VMs behind the Load Balancer.

Exam trap

The trap here is that candidates confuse Azure Firewall (a Layer 3-4 network firewall) with a web application firewall, mistakenly believing it can inspect HTTP payloads, when in fact only a Layer 7 WAF (like Application Gateway WAF or Azure Front Door WAF) can protect against SQL injection and XSS.

How to eliminate wrong answers

Option B (Azure Firewall) is wrong because it is a stateful, Layer 3-4 network firewall that filters traffic based on IP addresses, ports, and protocols, but it does not inspect HTTP application-layer payloads for SQL injection or XSS patterns. Option C (Network Security Groups on the VM subnet) is wrong because NSGs provide stateless or stateful Layer 3-4 filtering (IP/port rules) and cannot perform deep packet inspection at the application layer to detect web attack signatures. Option D (Azure DDoS Protection) is wrong because it only mitigates volumetric DDoS attacks at the network layer (Layer 3-4) and does not inspect or block application-layer threats like SQL injection or XSS.

516
MCQmedium

You are configuring Microsoft Sentinel to ingest logs from Azure Active Directory (now Microsoft Entra ID). You need to collect sign-in logs and audit logs. Which data connector should you enable?

A.Azure AD Identity Protection
B.Office 365
C.Azure AD Authentication
D.Azure Active Directory (now Microsoft Entra ID)
AnswerD

The Azure Active Directory (now Microsoft Entra ID) connector is the correct choice because it directly ingests both SignInLogs and AuditLogs into Sentinel. This enables monitoring of user sign-in attempts, multi-factor authentication challenges, and directory configuration changes, providing the core identity telemetry needed for investigations.

Why this answer

The Azure Active Directory (now Microsoft Entra ID) data connector is the correct choice because it is specifically designed to ingest both sign-in logs and audit logs from Microsoft Entra ID into Microsoft Sentinel. This connector enables the collection of user sign-in activities and directory audit events, which are essential for security monitoring and incident detection.

Exam trap

The trap here is that candidates may confuse the 'Office 365' connector (which handles Exchange, SharePoint, and Teams logs) with Azure AD logs, or mistakenly think 'Azure AD Authentication' is a valid connector name, when the correct name is 'Azure Active Directory' (now Microsoft Entra ID).

How to eliminate wrong answers

Option A is wrong because Azure AD Identity Protection is a separate service that provides risk detection and conditional access policies, not a data connector for ingesting sign-in and audit logs into Sentinel. Option B is wrong because the Office 365 connector ingests logs from Exchange Online, SharePoint Online, and Teams, not from Azure AD sign-in or audit activities. Option C is wrong because Azure AD Authentication is not a valid data connector name in Sentinel; the correct connector is named 'Azure Active Directory' (now Microsoft Entra ID).

517
MCQhard

Your organization has Microsoft Sentinel deployed in the East US region. You need to ensure that security logs are retained for 2 years to meet compliance requirements. The workspace retention policy is set to 90 days. What should you do?

A.Configure data retention for the specific tables that need long-term retention
B.Change the workspace retention setting to 730 days
C.Use Azure Policy to enforce retention on the Log Analytics workspace
D.Export logs to an Azure Storage account and set a lifecycle management policy
AnswerA

Configuring table-level retention in Log Analytics is the most precise way to meet long-term retention requirements because each table (e.g., SecurityEvent, SigninLogs) can have its own retention period, independent of the workspace default. This allows you to keep security-critical tables for up to 730 days (or 2 years for some data types) while avoiding the cost of retaining verbose, low-value tables like Perf or Heartbeat for that long. The Azure portal, Azure CLI, and the Tables API all support setting per-table retention, making it a supported and audit-friendly solution.

Why this answer

Microsoft Sentinel allows you to configure table-level retention in Log Analytics workspaces, overriding the workspace default retention of 90 days. By setting the retention period to 730 days (2 years) on specific tables containing security logs, you meet compliance requirements without affecting other tables. This is the recommended approach for long-term retention of security data in Sentinel.

Exam trap

The trap here is that candidates often assume workspace-level retention is the only option, overlooking the table-level retention feature in Log Analytics that Sentinel uses to meet specific compliance needs without exporting data.

How to eliminate wrong answers

Option B is wrong because changing the workspace retention setting to 730 days would apply to all tables in the workspace, which may not be necessary or cost-effective for non-security tables, and it does not leverage Sentinel's table-level retention capabilities. Option C is wrong because Azure Policy can enforce compliance rules but cannot directly set retention periods on Log Analytics tables; it would require custom policy definitions and still relies on table-level settings. Option D is wrong because exporting logs to Azure Storage with lifecycle management retains the data but removes it from Sentinel's queryable workspace, breaking the ability to run security analytics and incident investigations within Sentinel.

518
MCQhard

A SOC wants a Sentinel rule to include account, host, and IP entities so analysts can pivot during investigation. What should be configured in the analytics rule?

A.Custom details only
B.Entity mapping
C.Suppression rules
D.Workbook parameters
AnswerB

Entity mapping is the correct mechanism because it explicitly binds event fields to typed entity objects in the alert, assigning one field to the Account, another to the Host, and another to the IP. In the rule's alert enrichment section, the SOC can map the exact event properties to entity identifiers such as Account Name, Host Hostname, and IP Address. Once mapped, Microsoft Sentinel stores these as real entities, enabling correlation across alerts, entity pages, and incident enrichment.

Why this answer

Entity mapping is the correct configuration because it explicitly links the analytics rule's results to known entity types (account, host, IP) in Microsoft Sentinel. This enables analysts to pivot directly from an alert to related entities in the investigation graph, enriching context without manual cross-referencing. Without entity mapping, the rule would generate alerts but lack the structured entity data needed for seamless pivot actions.

Exam trap

The trap here is that candidates confuse 'custom details' with 'entity mapping' because both involve extracting data from query results, but custom details only add flat key-value pairs to the alert, whereas entity mapping creates structured, pivotable objects that the investigation graph can traverse.

How to eliminate wrong answers

Option A is wrong because custom details only allow you to extract and display specific fields from the query results in the alert, but they do not create structured entity objects (account, host, IP) that Sentinel's investigation graph can use for pivoting. Option C is wrong because suppression rules are used to temporarily stop generating alerts for a rule after a certain number of occurrences, which is unrelated to entity enrichment or pivot capabilities. Option D is wrong because workbook parameters are used to customize visualizations in Azure Workbooks, not to define entities within an analytics rule for investigation pivoting.

519
MCQmedium

A security team uses Microsoft Defender for Cloud. They want to ensure that all Azure virtual machines have the guest configuration extension installed to apply a security baseline automatically. They need to remediate non-compliant VMs without manual intervention. Which Defender for Cloud feature should be configured?

A.Assign a security policy (built-in initiative) that includes a policy with DeployIfNotExists effect
B.Enable automatic provisioning of the Log Analytics agent
C.Create an Automation rule that triggers a runbook when a recommendation appears
D.Configure a workflow automation scheduled task
AnswerA

The built-in Microsoft Defender for Cloud initiative (such as the default Azure Security Benchmark) includes policy definitions with the DeployIfNotExists effect, for example 'Deploy prerequisites to enable Guest Configuration policies on Windows VMs.' When assigned, this policy evaluates each VM and, if the Guest Configuration extension is missing, automatically deploys it using a managed identity and nested ARM template. This provides continuous, at-scale remediation without manual intervention, making it the correct choice.

Why this answer

The guest configuration extension is deployed automatically via a DeployIfNotExists policy effect within a built-in initiative (such as the Azure Security Benchmark). This effect evaluates VMs for the extension and, if missing, deploys it without manual intervention, ensuring the security baseline is applied. Defender for Cloud uses this policy-driven approach to remediate non-compliant resources at scale.

Exam trap

The trap here is that candidates confuse automatic provisioning of the Log Analytics agent (which collects logs) with the guest configuration extension (which applies baselines), or they assume that Automation rules or scheduled tasks can proactively deploy extensions, when only a DeployIfNotExists policy can enforce deployment without manual steps or external triggers.

How to eliminate wrong answers

Option B is wrong because automatic provisioning of the Log Analytics agent collects security data but does not install the guest configuration extension or apply a security baseline. Option C is wrong because an Automation rule triggers a runbook only after a recommendation appears, requiring the recommendation to exist first and introducing latency; it is not a proactive, policy-driven deployment. Option D is wrong because a workflow automation scheduled task runs on a timer, not in response to compliance state, and cannot deploy extensions dynamically based on policy evaluation.

520
MCQhard

A team wants Sentinel to ingest firewall logs from an appliance that emits Common Event Format over Syslog. Which connector pattern is most appropriate?

A.CEF connector using a Linux log forwarder or AMA-supported collection path
B.Azure Activity connector
C.Microsoft Entra ID Protection connector
D.Office 365 connector
AnswerA

The CEF connector is the correct choice because it ingests Common Event Format logs, which is the industry-standard format produced by firewall appliances such as Palo Alto, Fortinet, and Cisco ASA. The recommended data collection path uses a Linux-based log forwarder (rsyslog or Syslog-NG) running the Log Analytics agent (or the Azure Monitor Agent via a DCR) to forward CEF-formatted syslog messages to Sentinel's Log Analytics workspace. This directly satisfies the requirement to ingest firewall appliance logs.

Why this answer

The Common Event Format (CEF) over Syslog is a standard logging format used by many security appliances. Sentinel's CEF connector is specifically designed to ingest these logs, typically using a Linux log forwarder (rsyslog or syslog-ng) or the Azure Monitor Agent (AMA) with a Data Collection Rule to parse and forward the CEF messages to the Log Analytics workspace.

Exam trap

The trap here is that candidates confuse CEF with other log formats (e.g., Windows Event Log or JSON) and select a connector that ingests cloud-native logs instead of recognizing that CEF over Syslog requires a dedicated forwarder or AMA-based collection path.

How to eliminate wrong answers

Option B is wrong because the Azure Activity connector ingests Azure subscription-level operational logs (e.g., resource creation, policy changes), not third-party firewall syslog data. Option C is wrong because the Microsoft Entra ID Protection connector ingests risk detection and user risk events from Entra ID, not firewall logs. Option D is wrong because the Office 365 connector ingests audit and activity logs from Exchange, SharePoint, and Teams, not syslog-based firewall events.

521
MCQeasy

You need to enable transparent data encryption (TDE) for an Azure SQL Managed Instance. What is the prerequisite?

A.Configure a backup policy for the managed instance.
B.Enable a service endpoint for Azure SQL.
C.No additional configuration is needed; TDE is enabled by default.
D.Create an Azure Key Vault and configure a customer-managed key.
AnswerC

Azure SQL Managed Instance is created with Transparent Data Encryption already enabled by default, using a service-managed key that Microsoft rotates automatically. No configuration, such as creating a key or modifying settings, is required on the managed instance to activate TDE. The encryption of data and log files happens automatically in real time, making this the correct choice because the question's requirement is already satisfied.

Why this answer

Transparent Data Encryption (TDE) is enabled by default for Azure SQL Managed Instance. When you create a new managed instance, TDE is automatically turned on using a service-managed key, so no additional configuration is required. This default behavior ensures data at rest is encrypted without any prerequisite steps from the user.

Exam trap

The trap here is that candidates often assume TDE requires manual setup or a key vault, but Azure SQL Managed Instance enables TDE by default with a service-managed key, making options like D a common distractor for those familiar with on-premises or IaaS-based SQL Server configurations.

How to eliminate wrong answers

Option A is wrong because configuring a backup policy is unrelated to enabling TDE; backup policies manage retention and recovery, not encryption at rest. Option B is wrong because service endpoints are used for network connectivity and access control, not for enabling TDE on a managed instance. Option D is wrong because while you can optionally use customer-managed keys from Azure Key Vault for TDE (bring your own key), it is not a prerequisite; TDE works with a service-managed key by default without any key vault configuration.

522
MCQhard

Your company has multiple Azure subscriptions managed through Azure Firewall Manager. You need to deploy Azure Firewall policies that apply to all subscriptions in a region. What is the most efficient way to manage this?

A.Create a separate firewall policy for each subscription
B.Use Azure Firewall Manager to create a parent policy and assign it to all firewalls
C.Use Azure Policy to enforce firewall rules across subscriptions
D.Deploy a single network security group (NSG) to all VNets
AnswerB

Azure Firewall Manager solves this by letting you create one parent firewall policy that can be associated with Azure Firewalls in any subscription and region, centralizing network rules, application rules, NAT rules, and threat intelligence settings. Each firewall receives the same policy assignment while still supporting child policies for per-firewall customization, making this the correct way to enforce consistent rules across subscriptions without duplicating configuration.

Why this answer

Azure Firewall Manager provides a centralized management plane for firewall policies across multiple subscriptions and regions. By creating a parent policy and assigning it to all firewalls, you ensure consistent rule enforcement without duplicating effort. This approach is the most efficient because it leverages inheritance, where child policies can override specific rules while inheriting the parent's base configuration.

Exam trap

The trap here is that candidates confuse Azure Policy (which enforces resource compliance) with Azure Firewall Manager (which manages firewall policies and rules), leading them to choose option C even though Azure Policy cannot directly apply firewall rule collections.

How to eliminate wrong answers

Option A is wrong because creating separate policies per subscription defeats the purpose of centralized management, leading to administrative overhead and inconsistency. Option C is wrong because Azure Policy can enforce compliance (e.g., requiring a firewall to exist) but cannot directly define or assign firewall rule collections or policies. Option D is wrong because NSGs are stateful, layer-4 access control lists applied to subnets or NICs, not a substitute for the application-layer inspection and centralized policy management that Azure Firewall provides.

523
Multi-Selecteasy

Which TWO actions can be taken using Azure Network Watcher?

Select 2 answers
A.Diagnose whether a security rule is blocking traffic to a VM.
B.Create and manage private endpoints.
C.Configure WAF policies on Application Gateway.
D.Determine the next hop for traffic from a VM.
E.Configure Azure Firewall rules.
AnswersA, D

Network Watcher's IP flow verify checks whether a packet is allowed or denied by a network security group (NSG) based on the selected VM, network interface, and security rules. You provide source and destination IPs, port, protocol, and direction, and it returns the specific NSG rule that permitted or blocked the traffic. This directly answers whether a security rule is blocking traffic to a VM, making it a core diagnostic feature.

Why this answer

Azure Network Watcher includes the IP flow verify capability, which checks whether a packet is allowed or denied to or from a VM and identifies the specific security rule (NSG rule) responsible, so option A is correct. It also includes the Next hop capability, which determines the next hop type and IP address for traffic originating from a VM, validating routing behavior, so option D is correct. Options B, C, and E are incorrect because private endpoints, Application Gateway WAF policies, and Azure Firewall rules are configured through their respective services (Private Link, Application Gateway, and Azure Firewall), not through Network Watcher.

Exam trap

The trap here is that candidates confuse Network Watcher's diagnostic tools (IP flow verify, next hop) with configuration services (Private Link, WAF, Azure Firewall), which are separate Azure resources.

524
MCQeasy

Your company has multiple Azure subscriptions. You need to centralize security alerts and incidents in a single dashboard for the security operations center (SOC) team. The solution should provide advanced analytics and threat detection. Which service should you use?

A.Azure Monitor
B.Microsoft Sentinel
C.Microsoft 365 Defender
D.Microsoft Defender for Cloud
AnswerB

Microsoft Sentinel is a cloud-native SIEM and SOAR solution specifically designed to collect and centralize security alerts and data from all Azure subscriptions and external sources. It uses built-in analytics, fusion, and UEBA to detect threats, and provides incident management, investigation, and automated response across the enterprise. For the requirement to centralize security alerts across multiple Azure subscriptions, Sentinel is the correct choice because it aggregates alerts from Defender for Cloud and other sources into a single, actionable incident queue.

Why this answer

Microsoft Sentinel is the correct choice because it is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution that centralizes security alerts and incidents from multiple Azure subscriptions into a single dashboard. It provides advanced analytics, built-in threat detection, and AI-driven investigation capabilities, making it ideal for a SOC team requiring a unified view across the enterprise.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud (a CSPM and workload protection tool) with a SIEM solution, but Defender for Cloud lacks the centralized incident management and advanced analytics capabilities that Microsoft Sentinel provides for a SOC dashboard.

How to eliminate wrong answers

Option A is wrong because Azure Monitor is a platform monitoring service focused on collecting and analyzing telemetry from Azure resources (metrics, logs) for performance and health, not for aggregating security alerts and incidents with advanced threat detection. Option C is wrong because Microsoft 365 Defender is a unified pre- and post-breach enterprise defense suite for endpoints, identities, email, and apps, but it does not natively centralize security alerts from multiple Azure subscriptions into a single SOC dashboard; it integrates with Sentinel for that purpose. Option D is wrong because Microsoft Defender for Cloud (formerly Azure Security Center) provides security posture management and threat protection for cloud workloads, but it lacks the full SIEM capabilities (e.g., custom analytics, incident management, and SOAR) required for a centralized SOC dashboard across subscriptions; it feeds alerts into Sentinel for advanced correlation.

525
MCQeasy

You are designing a solution for Azure Blob Storage that must prevent data from being overwritten or deleted for a specified retention period. Which feature should you enable?

A.Blob versioning
B.Immutable storage with time-based retention policy
C.Lifecycle management policies
D.Soft delete for blobs
AnswerB

Immutable storage with a time-based retention policy applies a WORM (write once, read many) state to blobs within a container, preventing deletion and overwrite for the configured retention interval. The policy is set at the container level and, when locked, cannot be removed or shortened by any user, including administrators, making it the correct choice for regulatory or compliance-based retention. During the retention period, attempts to delete the blob, its versions, or even the underlying container will fail, ensuring the data remains intact.

Why this answer

Immutable storage with a time-based retention policy (WORM – Write Once, Read Many) is the correct feature because it explicitly prevents any user, including the storage account owner, from overwriting or deleting blobs until the retention period expires. This is enforced at the container level and overrides all other permissions, making it the only option that guarantees data cannot be altered or removed for a specified duration.

Exam trap

The trap here is that candidates confuse blob versioning or soft delete with true immutability, not realizing that those features allow the current blob to be overwritten or deleted and only provide recovery or history, not a hard write-once lock.

How to eliminate wrong answers

Option A is wrong because blob versioning preserves previous versions of a blob when overwrites or deletes occur, but it does not prevent the current version from being overwritten or deleted; it simply retains a history. Option C is wrong because lifecycle management policies automate tiering or deletion of blobs based on age or conditions, but they do not enforce a retention lock that blocks deletion or overwrite operations. Option D is wrong because soft delete for blobs retains deleted blobs for a recovery period, but it does not prevent overwrites or deletions from happening in the first place; it only allows recovery after the fact.

Page 6

Page 7 of 9

Page 8

All pages