Courseiva

CCNA Manage identity and access Questions

75 of 140 questions · Page 1/2 · Manage identity and access · Answers revealed

1
MCQmedium

A company uses Microsoft Defender for Cloud. The security team wants to receive a weekly email digest that includes the current Secure Score, the number of healthy and unhealthy resources, and a list of top recommendations. Which Defender for Cloud feature should they configure?

A.Regulatory Compliance dashboard
B.Security policies
C.Email notifications for alerts and weekly digests
D.Continuous Export
AnswerC

Email notifications for alerts and weekly digests is the correct feature. Under Environment settings > Email notifications, you can enable both real-time alerts for high severity findings and a separate weekly digest. The digest email includes your current Secure Score, a summary of resource health, and the top recommendations, and it can be sent to specified individual email addresses or Microsoft Entra ID role members such as subscription owners. This is the only option that natively delivers a scheduled, human-readable email summary, making it the proper choice for the team's request.

Why this answer

Microsoft Defender for Cloud provides a built-in 'Email notifications for alerts and weekly digests' feature that allows security teams to configure a weekly email containing the current Secure Score, the number of healthy and unhealthy resources, and a list of top recommendations. This feature is specifically designed to deliver a summary of the security posture directly to recipients without requiring manual export or custom automation.

Exam trap

The trap here is that candidates often confuse the weekly digest feature with Continuous Export, assuming that exporting data to a third-party system is the only way to get a summary, but Defender for Cloud has a native email notification feature specifically for this purpose.

How to eliminate wrong answers

Option A is wrong because the Regulatory Compliance dashboard displays compliance posture against standards (e.g., SOC 2, ISO 27001) and does not generate weekly email digests with Secure Score or resource health counts. Option B is wrong because Security policies define the rules and initiatives that govern resource compliance (e.g., enabling MFA or encryption), but they do not include any notification or email delivery mechanism for weekly summaries. Option D is wrong because Continuous Export streams security data (e.g., alerts, recommendations) to Log Analytics or Event Hubs for external processing, but it does not natively generate or send weekly email digests with Secure Score and resource health summaries.

2
MCQmedium

A security analyst is using Microsoft Sentinel to investigate a security incident. The analyst needs to view all related events, alerts, and entities (users, IPs, hosts) in a single, interactive graph to understand the full scope of the attack. Which Microsoft Sentinel feature should they use?

A.Incident timeline
B.Investigation graph
C.Hunting
D.Analytics rules
AnswerB

The investigation graph in Microsoft Sentinel is purpose-built for interactive incident analysis: it displays the incident's extracted entities—such as accounts, IP addresses, hosts, and URLs—as nodes and connects them to the alerts that reference those entities, creating an attack-path visualization. From any node, an analyst can expand to see related alerts, user activities, and other entities, helping to identify the root cause and the scope of the threat. This is the correct tool because it directly supports the analyst's need to examine entity relationships, unlike a sequential timeline or a proactive query engine.

Why this answer

The Investigation graph in Microsoft Sentinel provides an interactive, visual map that correlates all related events, alerts, and entities (such as users, IPs, and hosts) for a given incident. This allows the analyst to explore the full scope of an attack by dragging and dropping entities to uncover hidden relationships, making it the correct feature for this scenario.

Exam trap

The trap here is that candidates often confuse the Incident timeline (which shows a linear history) with the Investigation graph (which shows relational connections), leading them to choose the timeline option when the question explicitly asks for an interactive graph to understand the full scope of an attack.

How to eliminate wrong answers

Option A is wrong because the Incident timeline shows a chronological list of activities and changes for an incident, but it does not provide an interactive graph with entities and relationships. Option C is wrong because Hunting is a proactive search for threats using queries and bookmarks, not a tool for viewing all related events and entities in a single graph for an existing incident. Option D is wrong because Analytics rules are used to create detection logic that generates alerts and incidents, not to visualize or investigate the relationships between events and entities in an existing incident.

3
MCQeasy

A company uses Azure Active Directory and has guest users invited via B2B collaboration. The security team wants to require that all guest users from specific external organizations must complete multi-factor authentication (MFA) when accessing the company's SaaS applications. Which Conditional Access policy configuration should they use?

A.Create a policy that applies to 'All users' with a condition for 'Guest or external users' and a grant control of 'Require multi-factor authentication'.
B.Create a policy that applies to 'Guest or external users' with a condition for 'External tenants' specifying the organizations, and a grant control of 'Require multi-factor authentication'.
C.Create a policy that applies to 'All guest users' and assign it to the SaaS applications. Use a session control 'Use app enforced restrictions'.
D.Create a policy that applies to 'Guest or external users' with a condition for 'Sign-in risk' set to 'Medium and above' and a grant control of 'Block access'.
AnswerB

This is the correct approach in Azure AD Conditional Access. By setting the assignment to 'Guest or external users' and adding a condition for 'External tenants' with specific organization IDs, you narrowly and explicitly target only guest users from those partner tenants. The grant control 'Require multi-factor authentication' then enforces MFA at sign-in, which is exactly the stated requirement. This policy avoids affecting internal users and does not rely on risk signals or session-based restrictions, so it fulfills the policy objective with the least disruption.

Why this answer

It uses the 'External tenants' condition within a Conditional Access policy targeting 'Guest or external users' to specify the exact organizations from which guests must complete MFA. This directly meets the requirement to scope MFA enforcement to specific external organizations, not all guests. The 'Require multi-factor authentication' grant control ensures MFA is enforced for those guests when accessing SaaS applications.

Exam trap

The trap here is that candidates confuse the broad 'Guest or external users' identity with the granular 'External tenants' condition, mistakenly thinking that selecting 'Guest or external users' alone is sufficient to scope MFA to specific organizations.

How to eliminate wrong answers

Option A is wrong because applying the policy to 'All users' would include internal users, not just guests from specific external organizations, and the 'Guest or external users' condition alone does not filter by specific organizations. Option C is wrong because 'All guest users' applies to all guests regardless of their home organization, and 'Use app enforced restrictions' is a session control that relies on the application itself to enforce restrictions, not a grant control for MFA. Option D is wrong because 'Sign-in risk' condition targets risky sign-ins based on Microsoft's risk detection, not specific external organizations, and 'Block access' prevents access entirely rather than requiring MFA.

4
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) to manage the 'Security Administrator' role. They want to require that activation of this role must be approved by a designated group of security engineers before it becomes active. Which PIM role setting should they configure?

A.Activation maximum duration (hours)
B.MFA on activation
C.Require approval
D.Require justification on activation
AnswerC

Enabling 'Require approval' in PIM role settings means that when an eligible user requests activation, the request enters a pending state and a designated set of approvers (e.g., security team members) must explicitly approve or reject it before the role is activated. This provides an extra layer of human oversight, ensuring that no one can elevate their privileges without another party's review. This is the only setting among the four that directly implements an approval workflow.

Why this answer

Azure AD PIM's 'Require approval' setting enforces that a designated group of approvers must authorize each activation request before the role becomes active. This directly meets the requirement for approval by security engineers, ensuring that role activation is gated by explicit consent rather than being automatic.

Exam trap

The trap here is that candidates often confuse 'Require justification' or 'MFA on activation' with approval workflows, but neither introduces a separate approval step by a designated group—they only add authentication or logging requirements.

How to eliminate wrong answers

Option A is wrong because 'Activation maximum duration (hours)' controls how long a role can remain active after approval, not the approval process itself. Option B is wrong because 'MFA on activation' enforces multi-factor authentication during activation but does not introduce a separate approval step by a designated group. Option D is wrong because 'Require justification on activation' mandates a reason for activation but does not require approval from another party.

5
MCQmedium

A company uses Azure AD B2B collaboration to invite external partner users. The security policy requires that guest users who have not signed in for more than 90 days should have their access automatically reviewed and, if not approved, removed. The company has Azure AD Premium P2 licenses. Which Azure AD feature should they configure to meet this requirement?

A.Enable automatic user deletion in the Azure AD B2B collaboration settings.
B.Create a Conditional Access policy that blocks sign-ins for guest users who haven't authenticated in 90 days.
C.Configure an Azure AD Access Review that reviews guest user access and automatically removes access after 90 days of inactivity.
D.Use Azure AD Identity Protection to detect guest user sign-in anomalies and revoke sessions.
AnswerC

Access Reviews can be configured to run periodically (e.g., quarterly) and include only guest users. The review can be set to automatically remove users who do not respond or who are not approved, effectively removing access for inactive guests.

Why this answer

Azure AD Access Reviews, available with Azure AD Premium P2 licenses, allow you to create recurring reviews that specifically target guest users who have not signed in for a specified period (e.g., 90 days). The review can be configured to automatically remove access if the reviewer does not approve, directly meeting the requirement for automatic review and removal after 90 days of inactivity.

Exam trap

The trap here is that candidates often confuse blocking sign-ins via Conditional Access (Option B) with actually removing access, but Conditional Access only prevents future authentication and does not revoke existing permissions or trigger a review workflow.

How to eliminate wrong answers

Option A is wrong because Azure AD B2B collaboration settings do not include an 'automatic user deletion' feature; user deletion must be performed manually or via automated scripts, and there is no built-in inactivity-based deletion in those settings. Option B is wrong because a Conditional Access policy can block sign-ins based on sign-in frequency or risk, but it cannot automatically remove guest user access or trigger a review process; it only prevents future sign-ins without addressing existing access. Option D is wrong because Azure AD Identity Protection is designed to detect and respond to sign-in anomalies and risky behaviors, not to manage inactivity-based access reviews or removals for guest users.

6
MCQmedium

An organization wants to export Defender for Cloud recommendations and alerts into a central Log Analytics workspace for retention and hunting. Which feature should they use?

A.Microsoft Defender External Attack Surface Management
B.Continuous export
C.Microsoft Entra access reviews
D.Azure Monitor autoscale
AnswerB

Continuous export is the dedicated Defender for Cloud feature that streams security recommendations and alerts to an Azure Log Analytics workspace, Event Hub, or Azure Monitor using diagnostic settings. It supports granular selection of resource types and can be configured via ARM/REST, enabling integration with SIEMs like Microsoft Sentinel. This directly fulfills the requirement, as it is the native mechanism for exporting this data.

Why this answer

Continuous export is the correct feature because it allows you to stream Defender for Cloud security alerts and recommendations to a Log Analytics workspace for long-term retention and custom hunting queries. This feature supports both real-time and scheduled export of security data, enabling centralized monitoring and compliance auditing. It directly addresses the requirement to export Defender for Cloud data into a Log Analytics workspace without additional third-party tools.

Exam trap

The trap here is that candidates may confuse 'Continuous export' with 'Azure Monitor autoscale' or 'External Attack Surface Management' because they all involve monitoring or scaling, but only continuous export directly addresses the requirement to export Defender for Cloud data to Log Analytics.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender External Attack Surface Management (EASM) is a service for discovering and mapping an organization's external attack surface, not for exporting Defender for Cloud alerts or recommendations to Log Analytics. Option C is wrong because Microsoft Entra access reviews are used for managing identity governance, such as reviewing group memberships and application access, and have no capability to export security alerts or recommendations. Option D is wrong because Azure Monitor autoscale is a feature that automatically adjusts the number of compute resources based on demand, and it does not handle the export of security data to Log Analytics.

7
MCQhard

A company uses Azure AD Privileged Identity Management (PIM) for the Security Administrator role. The security policy requires that when a user activates the Security Administrator role, they must: 1) Provide a justification, 2) Get approval from a designated security group, and 3) The activation must last a maximum of 4 hours. Which combination of PIM settings should they configure?

A.Enable 'Require justification', 'Require approval', and set 'Maximum activation duration' to 4 hours. Assign the security group as the approver.
B.Enable 'Require justification', 'Require ticket information', and set 'Maximum activation duration' to 8 hours.
C.Enable 'Require approval' and set 'Maximum activation duration' to 4 hours. Do not require justification.
D.Enable 'Require Azure MFA on activation', 'Require justification', and set 'Maximum activation duration' to 4 hours.
AnswerA

These PIM settings map directly onto the three stated requirements: justification on activation, approval by the designated security group, and a four-hour maximum activation duration. Assigning that group as approver enforces the approval workflow the policy demands.

Why this answer

Azure AD PIM allows you to enforce all three requirements: justification, approval from a specified security group, and a maximum activation duration. By enabling 'Require justification' and 'Require approval' and setting the 'Maximum activation duration' to 4 hours, you meet the security policy exactly. The approval step requires assigning a designated security group as the approver, which is supported in PIM role settings.

Exam trap

The trap here is that candidates often confuse 'Require justification' with 'Require ticket information' or assume that MFA is always required for activation, but the question explicitly lists only three requirements—justification, approval, and 4-hour duration—so any extra or missing settings make the option incorrect.

How to eliminate wrong answers

Option B is wrong because it includes 'Require ticket information' instead of 'Require approval', and sets the maximum activation duration to 8 hours instead of the required 4 hours. Option C is wrong because it omits 'Require justification', which is a mandatory policy requirement. Option D is wrong because it includes 'Require Azure MFA on activation' (not required by the policy) and omits 'Require approval', which is explicitly required.

8
MCQmedium

A security team uses Microsoft Sentinel. They want to create a custom analytics rule that generates an incident whenever a user from a list of known malicious IP addresses attempts to sign in to any Azure AD app. They have imported the IP list into Sentinel using Threat Intelligence. Which rule type should they use?

A.Scheduled query rule
B.Near-real-time (NRT) rule
C.Microsoft Security rule
D.Anomaly rule
AnswerA

Scheduled query rules are Sentinel analytics rules that execute a KQL query on a fixed cadence (for example, every 5 or 15 minutes) and can create alerts and incidents based on the returned results. They are the only rule type that supports joining against the ThreatIntelligenceIndicator table, and Sentinel provides 'TI map' templates that match entities such as IP addresses, domains, and file hashes from your imported threat intelligence lists. Because the query is fully customizable, you can filter by indicator expiry, excluded IPs, or severity, and the results feed the incident creation workflow.

Why this answer

A scheduled query rule is the correct choice because it allows you to run a KQL query at a defined interval (e.g., every 5 minutes) to match sign-in events from IP addresses in a Threat Intelligence indicator. This rule type supports alert grouping and incident creation based on the query results, making it ideal for correlating Azure AD sign-in logs with a known malicious IP list imported via Threat Intelligence.

Exam trap

The trap here is that candidates often confuse NRT rules with scheduled queries, assuming 'near-real-time' is always better for threat intelligence matching, but NRT rules lack the ability to join against the ThreatIntelligenceIndicator table, making scheduled queries the only viable option for this use case.

How to eliminate wrong answers

Option B (NRT rule) is wrong because NRT rules run continuously with a near-real-time latency of 1-2 minutes but cannot reference Threat Intelligence indicators directly; they are designed for high-frequency, low-latency detection on streaming data without the ability to join against static or dynamic indicator lists. Option C (Microsoft Security rule) is wrong because it is used to create incidents from alerts generated by Microsoft security products (e.g., Microsoft Defender for Cloud, Microsoft 365 Defender), not from custom KQL queries against imported threat intelligence. Option D (Anomaly rule) is wrong because anomaly rules use machine learning to detect unusual patterns in data over time, not to match specific known malicious IP addresses from a predefined list.

9
MCQmedium

A security analyst uses Microsoft Sentinel. They have created a playbook that tags Azure VMs as 'isolated' when a high-severity malware alert is triggered. They want this playbook to run automatically whenever a related alert is generated. Which feature should they configure?

A.Automation rule.
B.Scheduled analytics rule.
C.Incident creation rule.
D.Workbook.
AnswerA

Automation rules in Microsoft Sentinel enable automated incident management by executing playbooks directly in response to incident creation or update events. You can define conditions based on alert properties and specify actions like running a playbook, changing status, or assigning ownership. This is the correct mechanism to run a playbook automatically without manual intervention.

Why this answer

Automation rules in Microsoft Sentinel allow you to define triggers that automatically run playbooks when specific alerts or incidents are created. In this scenario, the playbook tags Azure VMs as 'isolated' upon a high-severity malware alert, and an automation rule can be configured to run that playbook automatically whenever such an alert is generated, without manual intervention.

Exam trap

The trap here is that candidates often confuse automation rules with analytics rules, mistakenly thinking that scheduled analytics rules can directly trigger playbooks, but analytics rules only generate alerts and do not natively invoke automated responses.

How to eliminate wrong answers

Option B is wrong because scheduled analytics rules are used to periodically query data and generate alerts based on predefined schedules, not to trigger automated responses like running playbooks. Option C is wrong because incident creation rules are not a native feature in Microsoft Sentinel; incidents are created automatically from alerts, and there is no separate rule type for incident creation that triggers playbooks. Option D is wrong because workbooks are visualization tools for dashboards and reports, not mechanisms for automating response actions like running playbooks.

10
MCQhard

A Sentinel watchlist contains high-value administrator accounts. Which KQL pattern best uses it in a detection rule?

A.Load the watchlist with _GetWatchlist() and join or filter SigninLogs by the account identifier
B.Export the watchlist to CSV and manually compare it after alerts fire
C.Use the watchlist as a replacement for the SigninLogs table
D.Attach the watchlist to a workbook without changing the detection query
AnswerA

Load the watchlist inside the analytics rule query by calling _GetWatchlist('<alias>'), which returns the watchlist as a KQL table. You can then use a join or a where filter against the SigninLogs table using the account identifier column (for example, UserPrincipalName or UserId) to restrict or enrich the results to only high-value administrator accounts. This executes at query time, so each scheduled run automatically uses the current watchlist contents and triggers alerts only when a matching account produces a sign-in event.

Why this answer

The `_GetWatchlist()` function in KQL allows you to dynamically load a Sentinel watchlist into a query. By joining or filtering `SigninLogs` against the watchlist's account identifier field, you can create a detection rule that triggers only when a high-value administrator account (defined in the watchlist) performs a sign-in, enabling precise, automated alerting without manual intervention.

Exam trap

The trap here is that candidates confuse a watchlist as a static data source that can replace log tables, rather than understanding it as a reference dataset that must be explicitly joined or filtered within a KQL query to be useful in detection rules.

How to eliminate wrong answers

Option B is wrong because exporting a watchlist to CSV and manually comparing it after alerts fire defeats the purpose of automation and real-time detection; it introduces latency and human error, which is not a valid KQL pattern for a detection rule. Option C is wrong because a watchlist is a reference dataset (a list of values), not a log table like `SigninLogs`; it cannot replace a table that contains event data, and attempting to use it as such would result in a query error or no meaningful results. Option D is wrong because attaching a watchlist to a workbook only visualizes data in a dashboard; it does not integrate the watchlist into the detection query logic, so the detection rule would not use the watchlist to filter or alert on high-value accounts.

11
MCQmedium

A security team uses Microsoft Defender for Cloud. They have assigned a custom regulatory compliance initiative that includes policies to enforce encryption on storage accounts and SQL databases. They want to automatically remediate any non-compliant resources as soon as they are created, without manual intervention. Which feature should they configure?

A.Security policies (assignments)
B.Azure Policy with a 'DeployIfNotExists' effect
C.Just-in-time VM access
D.Adaptive application controls
AnswerB

Azure Policy with a 'DeployIfNotExists' effect triggers a deployment through a linked managed identity when a non-compliant resource is created or updated, automatically applying the required configuration—for example, enabling the Azure Disk Encryption extension on newly created VMs. Because the effect both detects non-compliance and takes a corrective action, it closes the loop that a plain audit-only assignment leaves open. This is exactly the mechanism Defender for Cloud uses to auto-remediate certain recommendations, making it the correct choice for automatically enforcing encryption.

Why this answer

The 'DeployIfNotExists' effect in Azure Policy automatically deploys a resource (e.g., encryption configuration) when a non-compliant resource is created or updated, without manual intervention. This aligns with the requirement to remediate non-compliant storage accounts and SQL databases as soon as they are provisioned, as part of a custom regulatory compliance initiative assigned via Defender for Cloud.

Exam trap

The trap here is that candidates often confuse 'DeployIfNotExists' with 'AuditIfNotExists' or assume that simply assigning a policy (Option A) will automatically fix non-compliant resources, but only 'DeployIfNotExists' provides automatic remediation without manual steps.

How to eliminate wrong answers

Option A is wrong because Security policies (assignments) in Defender for Cloud only define which initiatives and standards are applied to a scope; they do not perform automatic remediation of non-compliant resources. Option C is wrong because Just-in-time VM access is a security control for managing VM inbound traffic and has no role in enforcing encryption on storage accounts or SQL databases. Option D is wrong because Adaptive application controls are used to create allowlists for running applications on Azure VMs, not for deploying encryption configurations to storage or SQL resources.

12
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) to manage the 'Security Administrator' role. They want a user to be able to activate this role for a maximum of 2 hours per activation. Which PIM setting should they configure?

A.Set the 'Activation maximum duration' to 2 hours in the role settings for Security Administrator.
B.Set the 'Expire eligible assignments after' to 2 hours in the role settings.
C.Enable 'Require justification' and 'Require approval' to ensure the role is not misused.
D.Set the 'Activation maximum duration' to 1 hour and the user can activate twice.
AnswerA

The 'Activation maximum duration' in the role settings for Security Administrator directly defines the maximum time a user can remain active in that role after requesting activation. By setting it to 2 hours, you guarantee that any single activation session expires after two hours, at which point the user's role assignment is deactivated unless they reactivate. This is the specific setting that enforces the 2-hour limit requested by the company.

Why this answer

The 'Activation maximum duration' setting in Azure AD PIM role settings directly controls the maximum time a user can remain active in an eligible role after activation. By setting this to 2 hours, the user will be able to activate the Security Administrator role for up to 2 hours per activation, after which the role assignment expires automatically.

Exam trap

The trap here is confusing 'Activation maximum duration' (the time a role is active after activation) with 'Expire eligible assignments after' (the time a user remains eligible to activate), leading candidates to incorrectly choose Option B.

How to eliminate wrong answers

Option B is wrong because 'Expire eligible assignments after' controls how long a user can remain eligible for the role before their eligibility expires, not the duration of an activation. Option C is wrong because 'Require justification' and 'Require approval' are additional security controls that do not limit the activation duration; they enforce auditing and approval workflows but do not set a time limit. Option D is wrong because setting the 'Activation maximum duration' to 1 hour would limit each activation to 1 hour, and the user activating twice does not achieve a 2-hour continuous activation; the maximum duration per activation is a single session limit, not a cumulative allowance.

13
MCQmedium

An organization is deploying Microsoft Sentinel to centrally collect and analyze security events. They need to ingest logs from multiple on-premises Windows servers located behind a firewall. Which agent should they deploy on those servers?

A.Azure Monitor Agent (AMA)
B.Log Analytics agent (Microsoft Monitoring Agent)
C.Azure Security Center agent
D.Azure Automation Agent
AnswerA

Azure Monitor Agent (AMA) is the current, consolidated data-collection platform that unifies the functionality of the Log Analytics agent and the Diagnostics extension. It uses Data Collection Rules (DCRs) to define exactly which logs and metrics to collect from Windows and Linux machines, including security events, Syslog, and custom logs. Microsoft Sentinel fully supports AMA, and it is the recommended agent for all new deployments, providing better performance, manageability, and feature parity across Azure and non-Azure resources.

Why this answer

The Azure Monitor Agent (AMA) is the correct choice because it is the current, unified data-collection agent for Microsoft Sentinel and Azure Monitor, designed to collect logs from Windows servers behind firewalls via outbound HTTPS (port 443) to the Log Analytics workspace. It supports data-collection rules (DCRs) for flexible, scalable ingestion and is the recommended replacement for the legacy Log Analytics agent. AMA can be deployed on-premises Windows servers using Azure Arc for management, ensuring secure log forwarding to Sentinel.

Exam trap

The trap here is that candidates often confuse the legacy Log Analytics agent (option B) as still being the primary agent for Sentinel, but Microsoft has deprecated it in favor of AMA, and the exam expects knowledge of the current recommended agent.

How to eliminate wrong answers

Option B is wrong because the Log Analytics agent (Microsoft Monitoring Agent) is legacy and deprecated for new deployments in Microsoft Sentinel as of August 2024; it lacks support for advanced data-collection rules and is being phased out. Option C is wrong because the Azure Security Center agent (now part of Defender for Cloud) is specifically for security posture and threat detection, not for general log ingestion into Sentinel; it does not replace the log-collection agent. Option D is wrong because the Azure Automation Agent (Hybrid Runbook Worker) is designed to run automation runbooks on-premises, not to collect and forward security logs to Sentinel; it serves a completely different purpose.

14
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) to manage the 'Security Administrator' role. They want to ensure that when a user activates the role, they must provide a ticket number as justification, and the activation must be approved by a designated approver group. The role activation duration should be limited to 4 hours. Which PIM settings should be configured?

A.Enable 'Require approval' for the role and set 'Approvers' to the designated group. Also, set 'Activation maximum duration' to 4 hours.
B.Enable 'Require justification on activation' and set 'Activation maximum duration' to 4 hours. No approval configuration is needed.
C.Enable 'Require approval' and set 'Approvers' to the designated group. Also, enable 'Require ticket information on activation' and set 'Activation maximum duration' to 4 hours.
D.Enable 'Require ticket information on activation' and set 'Activation maximum duration' to 4 hours. Approval is not required because the ticket number serves as justification.
AnswerC

This is the correct configuration because it enables all three required policies in PIM: approval by the designated group, mandatory ticket information on activation, and a 4-hour maximum activation duration. Requiring ticket information ensures that every activation request includes a support ticket number, which satisfies the ticketing compliance requirement. The approval workflow with the designated group as approvers guarantees that a human approves each eligible activation before the role becomes active.

Why this answer

The scenario requires both approval and ticket-based justification. In Azure AD PIM, 'Require approval' enforces that a designated approver group must approve the activation, while 'Require ticket information on activation' ensures the user provides a ticket number as justification. Setting 'Activation maximum duration' to 4 hours limits the role activation time.

These three settings together satisfy all requirements.

Exam trap

The trap here is that candidates may confuse 'justification' with 'ticket information' and assume that enabling justification alone satisfies the ticket number requirement, or they may think that a ticket number inherently serves as approval, leading them to omit the approval configuration.

How to eliminate wrong answers

Option A is wrong because it omits the requirement for ticket information on activation; the scenario explicitly requires a ticket number as justification, not just any justification. Option B is wrong because it does not include approval configuration; the scenario requires activation to be approved by a designated approver group, which is not addressed by just enabling justification. Option D is wrong because it incorrectly assumes that a ticket number alone serves as sufficient justification and that approval is not needed; the scenario requires both a ticket number and approval from a designated group.

15
MCQmedium

A company wants to allow external business partners to access specific SharePoint Online sites using their own corporate credentials. They do not want to manage partner accounts in their own Azure AD tenant. Which Azure AD feature should they use?

A.Azure AD B2C
B.Azure AD External Identities
C.Conditional Access
D.Privileged Identity Management
AnswerB

Azure AD External Identities (B2B collaboration) is the correct mechanism to allow external business partners access to specific SharePoint resources. It lets you invite partners who authenticate with their own organization's identity (Azure AD, SAML/WS-Fed IdP, or social identity), and they are represented as guest users in your directory. These guest accounts can be added to SharePoint sites, document libraries, or individual items through SharePoint's external sharing capabilities, with optional Conditional Access policies applied. This approach maintains your partner's home identity without requiring duplicate credentials in your tenant.

Why this answer

Azure AD External Identities (specifically B2B collaboration) allows you to invite external business partners to access your SharePoint Online sites using their own corporate credentials (their home Azure AD or identity provider). This eliminates the need to manage partner accounts in your tenant, as identities remain in their home directory and are authenticated via federation or SAML/WS-Fed protocols.

Exam trap

The trap here is confusing Azure AD B2C (customer-facing) with Azure AD External Identities B2B (business-to-business), as both involve 'external' users but serve fundamentally different scenarios and identity providers.

How to eliminate wrong answers

Option A is wrong because Azure AD B2C is designed for customer-facing applications where users sign up with social or local accounts, not for business-to-business collaboration with existing corporate identities. Option C is wrong because Conditional Access is a policy engine that enforces access controls (e.g., MFA, device compliance) on already-authenticated users, not a feature for inviting external partners or managing their identities. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role assignments for users within your own tenant, not for external partner identity federation or guest access.

16
MCQmedium

A company wants Defender for Cloud to recommend fixes for container image vulnerabilities stored in Azure Container Registry. Which capability is most relevant?

A.Container vulnerability assessment in Defender for Containers
B.Azure SQL auditing
C.Microsoft Entra access reviews
D.Application Gateway rewrite rules
AnswerA

Container vulnerability assessment in Defender for Containers scans images in Azure Container Registry and surfaces findings as Defender for Cloud recommendations, satisfying the requirement to recommend fixes for registry-stored images. It assesses OS package and language dependency vulnerabilities, unlike Kubernetes runtime hardening or registry access controls.

Why this answer

Defender for Containers includes a container vulnerability assessment capability that scans container images stored in Azure Container Registry (ACR) for known vulnerabilities. This assessment integrates with Defender for Cloud to provide actionable recommendations for fixing identified vulnerabilities, directly addressing the company's requirement.

Exam trap

The trap here is that candidates may confuse general container security features (like runtime protection) with the specific vulnerability assessment capability, or mistakenly think that Azure SQL auditing or access reviews could be repurposed for image scanning.

How to eliminate wrong answers

Option B is wrong because Azure SQL auditing is a database auditing feature for tracking database events and changes, not for scanning container images for vulnerabilities. Option C is wrong because Microsoft Entra access reviews are used to manage user access rights and certifications, not for vulnerability scanning of container images. Option D is wrong because Application Gateway rewrite rules are used to modify HTTP request/response headers and URLs in web traffic, not for assessing container image security.

17
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) to manage access to the 'Security Administrator' role. They want a specific user to be able to activate the role only when needed, rather than having standing access. The user should not have the role active at all times. Which type of assignment should they configure for this user in PIM?

A.Assign the user as 'Active' for the role.
B.Assign the user as 'Eligible' for the role.
C.Assign the user as 'Permanent' for the role.
D.Add the user as a 'Guest' in the directory.
AnswerB

This is the correct approach because an Eligible assignment in PIM is a dormant state where the user has no effective role permissions until they activate it through the PIM portal or API. During activation, the user can be required to supply a business justification, pass Azure AD Multi-Factor Authentication, and, if configured, receive approval from role approvers. The role then becomes active only for a limited, configurable duration, meaning privileged access exists exactly when needed and expires automatically.

Why this answer

In Azure AD Privileged Identity Management (PIM), an 'Eligible' assignment means the user does not have permanent access to the role. They must activate the role on-demand through a time-bound activation process, which may require approval and multi-factor authentication. This directly meets the requirement of having no standing access, as the role is inactive until the user explicitly activates it.

Exam trap

The trap here is confusing 'Active' (permanent standing access) with 'Eligible' (just-in-time activation), as candidates often think 'Active' means the user can activate the role, when in fact it means the role is always active.

How to eliminate wrong answers

Option A is wrong because an 'Active' assignment grants the user standing access to the role at all times, which contradicts the requirement for on-demand activation. Option C is wrong because 'Permanent' is not a valid assignment type in PIM; roles are either 'Active' (permanent) or 'Eligible' (requiring activation). Option D is wrong because adding the user as a 'Guest' in the directory does not assign any Azure AD role; it only provides external collaboration access without any privileged role permissions.

18
MCQmedium

An application hosted on an Azure VM needs to read secrets from Key Vault without storing credentials. Which identity pattern should be used?

A.System-assigned managed identity with Key Vault access granted by RBAC or access policy
B.Client secret stored in appsettings.json
C.Shared access signature stored as an environment variable
D.A user account excluded from MFA
AnswerA

A system-assigned managed identity is the correct choice because Azure automatically provisions a service principal for the VM, and the application can obtain an Azure AD token through the instance metadata service (IMDS) without storing any credentials in code or configuration. Key Vault access is then granted to that identity via either Azure RBAC (for example, the Key Vault Secrets User role) or a legacy vault access policy, enabling the VM to read secrets securely and with automatic credential rotation managed by Azure.

Why this answer

A system-assigned managed identity enables an Azure VM to authenticate to Azure Key Vault without storing any credentials in code or configuration. Azure automatically creates a service principal for the VM in Azure AD, and the VM can obtain an access token from the Azure Instance Metadata Service (IMDS) endpoint (169.254.169.254) to authenticate to Key Vault. Access to secrets is then controlled by assigning RBAC roles (e.g., Key Vault Secrets User) or configuring a Key Vault access policy for that identity, eliminating the need for any stored secrets.

Exam trap

The trap here is that candidates may confuse managed identities with other credential-based patterns (like client secrets or SAS tokens) and fail to recognize that the question explicitly requires 'without storing credentials,' which only a managed identity satisfies.

How to eliminate wrong answers

Option B is wrong because storing a client secret in appsettings.json directly violates the requirement of not storing credentials; it introduces a security risk of secret exposure in configuration files. Option C is wrong because a shared access signature (SAS) is used for delegating access to Azure Storage resources, not for authenticating to Key Vault, and storing it as an environment variable still requires managing a credential. Option D is wrong because a user account excluded from MFA does not provide an identity pattern for a VM to access Key Vault; it is a human identity that would require interactive sign-in and credential storage, and excluding MFA weakens security without solving the credential storage problem.

19
MCQeasy

A security analyst uses Microsoft Defender for Cloud. They need to view the current compliance status of their Azure subscription against the Payment Card Industry Data Security Standard (PCI DSS). Which feature in Defender for Cloud should they use?

A.Security posture dashboard
B.Regulatory compliance dashboard
C.Vulnerability assessment solutions
D.Workflow automation
AnswerB

The regulatory compliance dashboard in Defender for Cloud is specifically designed to display your environment's alignment with industry standards and regulatory frameworks, such as PCI DSS, SOC 2, ISO 27001, and Azure CIS. It continuously evaluates Azure Policy initiatives and maps discovered assessments to individual controls within each standard, showing pass/fail status per control and providing a detailed view of recommendations and affected resources. This makes it the correct tool for an analyst seeking to track compliance against a specific regulatory standard, unlike the other options which focus on security posture, vulnerabilities, or automation.

Why this answer

The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built view of your Azure subscription's compliance posture against specific standards like PCI DSS. It continuously assesses your resources against the controls defined in the selected compliance framework and displays a compliance score, passed/failed controls, and remediation steps. This is the dedicated feature for tracking regulatory compliance, not general security posture or vulnerability management.

Exam trap

The trap here is that candidates confuse the general Security posture dashboard (which shows a security score) with the Regulatory compliance dashboard, which is the only place to see compliance against specific standards like PCI DSS, SOC 2, or ISO 27001.

How to eliminate wrong answers

Option A is wrong because the Security posture dashboard shows an overall security score based on security recommendations, but it does not map to specific regulatory frameworks like PCI DSS. Option C is wrong because Vulnerability assessment solutions (e.g., integrated Qualys or Microsoft Defender Vulnerability Management) focus on identifying software vulnerabilities in VMs and containers, not on compliance with regulatory standards. Option D is wrong because Workflow automation is used to trigger automated responses (e.g., sending notifications or creating tickets) based on security alerts or recommendations, not to view compliance status.

20
MCQmedium

A security team uses Microsoft Sentinel. They want to detect a potential privilege escalation scenario: when a user is added to the Global Administrator role in Azure AD (audit log) and within 10 minutes that user signs in from a suspicious location (sign-in log). Which type of analytics rule should they create to correlate these two different log sources?

A.Fusion rule
B.Scheduled query rule
C.Anomaly rule
D.NRT rule (Near Real-Time)
AnswerB

Scheduled query rules are the correct choice because they let you author custom KQL queries that join multiple tables such as SecurityEvent, SigninLogs, and CommonSecurityLog to correlate events across data sources. By setting a query schedule and alert logic, you can precisely define the multi-source correlation the security team needs.

Why this answer

A scheduled query rule is the correct choice because it allows you to define a KQL query that joins the AuditLogs table (for role assignment events) with the SigninLogs table (for sign-in events) and then uses a time window (e.g., 10 minutes) to correlate the two disparate log sources. This rule type supports cross-table joins and custom time-based correlation, which is exactly what is needed to detect a user added to Global Administrator followed by a suspicious sign-in.

Exam trap

The trap here is that candidates confuse Fusion rules (which correlate alerts) with the need to correlate raw log entries, or they mistakenly think NRT rules can handle multi-table joins with custom time windows, when in fact only scheduled query rules provide the necessary KQL flexibility for this scenario.

How to eliminate wrong answers

Option A is wrong because Fusion rules use machine learning to correlate multiple alerts from different security products, not to join raw audit and sign-in logs with a custom time window. Option C is wrong because Anomaly rules are designed to detect unusual patterns in a single data source using baselines, not to correlate two different log sources with a specific temporal condition. Option D is wrong because NRT (Near Real-Time) rules run every minute but do not support cross-table joins or custom time windows longer than a few minutes; they are intended for single-table, low-latency detection.

21
MCQhard

A security team uses Microsoft Defender for Cloud to protect Azure virtual machines. They want to implement application allowlisting to prevent execution of unauthorized software on a set of Windows Server VMs. They need to create a baseline of allowed applications and then enforce the allowlist. Which Defender for Cloud feature should they enable?

A.Adaptive application controls
B.Just-in-time VM access
C.File integrity monitoring
D.Adaptive network hardening
AnswerA

Adaptive application controls is correct because Defender for Cloud builds a machine-learning baseline of known-good executables, scripts, and installation processes running on your VMs, then lets you enforce an allowlist that prevents unknown or untrusted binaries from launching. It can run in audit mode to detect suspicious execution or enforce mode to actively block it, making it the only option here that governs application execution itself.

Why this answer

Adaptive application controls (AAC) in Microsoft Defender for Cloud is the correct feature because it specifically provides application allowlisting for Azure VMs. AAC uses machine learning to analyze processes running on a VM, generate a baseline of allowed applications, and then enforce that allowlist by blocking execution of any unauthorized software. This directly meets the requirement to create a baseline and enforce it on Windows Server VMs.

Exam trap

The trap here is that candidates often confuse adaptive application controls with file integrity monitoring, thinking both prevent unauthorized software, but FIM only detects changes after the fact and does not block execution.

How to eliminate wrong answers

Option B (Just-in-time VM access) is wrong because it controls network access to management ports (e.g., RDP, SSH) by locking down inbound traffic, not application execution on the VM. Option C (File integrity monitoring) is wrong because it monitors changes to critical files, registry keys, and software installations, but it does not block unauthorized software execution—it only alerts on changes. Option D (Adaptive network hardening) is wrong because it recommends and enforces network security group (NSG) rules based on traffic patterns, not application-level allowlisting on the VM.

22
MCQmedium

A company wants to detect exposed internet-facing assets that are not yet known in its Azure inventory. Which Microsoft Defender capability is most relevant?

A.Defender for SQL vulnerability assessment
B.Microsoft Entra Permissions Management
C.Defender External Attack Surface Management
D.Azure Monitor VM insights
AnswerC

Defender External Attack Surface Management (EASM) continuously discovers and inventories an organization's internet-facing assets, including unknown or shadow IT resources, by scanning domains, IP blocks, ports, and web components from an attacker perspective. It uses Microsoft's global infrastructure data to identify these assets and integrates with Microsoft Defender for Cloud to provide security exposure insights. This is the only option directly engineered to detect exposed assets that were previously not known to the organization.

Why this answer

Defender External Attack Surface Management (EASM) is specifically designed to discover and inventory internet-facing assets (e.g., domains, IPs, open ports, certificates) that are not yet known to an organization's Azure inventory. It continuously scans public attack surfaces to identify unknown or unmanaged resources, making it the most relevant capability for detecting exposed assets outside the current Azure footprint.

Exam trap

The trap here is that candidates may confuse Defender EASM with Microsoft Entra Permissions Management (CIEM), assuming both deal with 'unknown assets' when in fact CIEM focuses on permissions and identity risks, not external asset discovery.

How to eliminate wrong answers

Option A is wrong because Defender for SQL vulnerability assessment focuses on identifying and remediating database-specific vulnerabilities (e.g., misconfigurations, missing patches) within known Azure SQL resources, not on discovering unknown internet-facing assets. Option B is wrong because Microsoft Entra Permissions Management (formerly CloudKnox) is a Cloud Infrastructure Entitlement Management (CIEM) tool that analyzes and manages permissions across multi-cloud environments, but it does not perform external asset discovery or attack surface scanning. Option D is wrong because Azure Monitor VM insights provides performance monitoring and dependency mapping for existing virtual machines, but it has no capability to discover unknown or external internet-facing assets.

23
MCQmedium

A security operations team uses Microsoft Sentinel. They want to create a rule that generates an incident when an Azure virtual machine is deployed with a public IP address that is not in a predefined approved list. The rule should run every hour and query Azure Activity logs. Which type of analytics rule should they create?

A.Scheduled query rule
B.NRT (Near-Real-Time) rule
C.Anomaly rule
D.Fusion rule
AnswerA

Scheduled query rules are the core analytics rule type in Microsoft Sentinel for running KQL queries on a fixed cadence such as every hour. A defender can write a deterministic query that checks every virtual machine's public IP against a watchlist or lookup table of approved addresses, and trigger an incident when a non-approved IP is found. Because the schedule, query, and incident-generation settings are all configurable, this rule type exactly matches the requirement of an hourly deterministic check.

Why this answer

A scheduled query rule is correct because the requirement specifies a rule that runs every hour and queries Azure Activity logs. Scheduled query rules in Microsoft Sentinel are designed for periodic, time-based queries against log data, such as Azure Activity logs, and can generate incidents based on predefined conditions like detecting a VM deployment with an unapproved public IP. This aligns perfectly with the need for a recurring, non-real-time check.

Exam trap

The trap here is that candidates confuse the frequency requirement (every hour) with the near-real-time label, assuming NRT rules can be configured for any interval, when in fact NRT rules are hard-limited to 1-minute intervals and cannot be set to hourly runs.

How to eliminate wrong answers

Option B (NRT rule) is wrong because near-real-time rules run at intervals of 1 minute or less, not every hour, and are designed for low-latency detection, not scheduled hourly checks. Option C (Anomaly rule) is wrong because anomaly rules use machine learning to detect unusual patterns over time, not static conditions like a predefined approved IP list. Option D (Fusion rule) is wrong because Fusion rules correlate alerts from multiple security products to detect multi-stage attacks, not single-event conditions like VM deployment with a specific IP.

24
MCQeasy

A company has Azure AD with Premium P2 licenses. They want to enforce Azure Multi-Factor Authentication (MFA) for all users accessing the Azure portal from untrusted networks, but only after the user has successfully entered their password. Which Conditional Access grant control should they configure?

A.Require multi-factor authentication
B.Require device to be marked as compliant
C.Require approved client app
D.Require domain join
AnswerA

The "Require multi-factor authentication" grant control, found under Access controls > Grant in a Conditional Access policy, forces the user to complete an MFA challenge (for example, an authenticator app, phone call, or hardware token) immediately after the initial password-based sign-in, blocking the session if MFA fails. This is the only option that directly enforces the stated requirement of requiring MFA after password authentication, because it specifically adds a second authentication factor rather than evaluating the device or client app state.

Why this answer

The 'Require multi-factor authentication' grant control in Conditional Access enforces MFA after password authentication, which aligns with the requirement to prompt for MFA only after the user has successfully entered their password. This control is applied based on the condition of 'untrusted networks' (e.g., using the 'Locations' condition to target all locations except trusted IPs), ensuring that MFA is triggered specifically for Azure portal access from untrusted networks.

Exam trap

The trap here is that candidates often confuse 'Require multi-factor authentication' with 'Require device to be marked as compliant' or 'Require domain join', mistakenly thinking device state controls can enforce MFA step-up, when in fact only the MFA grant control triggers the additional authentication challenge after password entry.

How to eliminate wrong answers

Option B is wrong because 'Require device to be marked as compliant' enforces device compliance (e.g., Intune policy) but does not enforce MFA after password entry; it blocks or grants access based on device health, not authentication step-up. Option C is wrong because 'Require approved client app' restricts access to specific client applications (e.g., Microsoft Authenticator) but does not enforce MFA after password entry; it is used for app-level restrictions, not authentication step-up. Option D is wrong because 'Require domain join' enforces hybrid Azure AD join or domain-joined devices, which does not enforce MFA after password entry; it is a device state control, not an authentication enforcement.

25
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) for Azure AD roles. They want to require that users must perform multi-factor authentication (MFA) when activating a role. Which PIM setting should they configure?

A.Require Azure AD Multi-Factor Authentication on activation
B.Require approval to activate
C.Require justification on activation
D.Require ticket information on activation
AnswerA

This setting enforces Azure AD Multi-Factor Authentication during the role activation process, so an eligible user must prove possession of a second factor (e.g., Authenticator app, phone call, FIDO2 key) each time they activate a privileged role. Because activation is time-bound, MFA at this step reduces the risk that a stolen primary credential alone can grant elevated access. In PIM, this is a mandatory best practice for highly privileged roles like Global Administrator.

Why this answer

To enforce multi-factor authentication during role activation in Azure AD Privileged Identity Management (PIM), you must configure the 'Require Azure AD Multi-Factor Authentication on activation' setting. This ensures that before a user’s role assignment is activated, they must complete an MFA challenge, adding an extra layer of security against unauthorized access.

Exam trap

The trap here is that candidates often confuse 'Require approval to activate' with MFA enforcement, but approval is a separate authorization step that does not verify the user’s identity through a second factor.

How to eliminate wrong answers

Option B is wrong because 'Require approval to activate' enforces a workflow where one or more approvers must authorize the activation, but it does not mandate MFA. Option C is wrong because 'Require justification on activation' only prompts the user to provide a business reason for activation, not an MFA challenge. Option D is wrong because 'Require ticket information on activation' asks for a support ticket number for auditing purposes, which is unrelated to multi-factor authentication.

26
Multi-Selecthard

A company uses Azure AD Privileged Identity Management (PIM) to manage access to Azure AD roles. They want to require that users who activate the Global Administrator role must get approval from their manager before activation, and that the approval must be time-bound (maximum 8 hours). Which two PIM configurations should they set?

Select 2 answers
A.Set the activation maximum duration to 8 hours.
B.Enable approval workflow by adding the manager as an approver.
C.Require multi-factor authentication on activation.
D.Require justification on activation.
AnswersA, B

Setting the activation maximum duration to 8 hours in Azure AD PIM enforces a strict time-bound on any privileged role activation. This ensures that a user cannot remain in the role indefinitely; after the configured duration, the role assignment automatically expires and reverts to eligible state. Since 8 hours is the maximum allowed activation duration for Azure AD roles, this directly satisfies the requirement that privileged access be temporary and bounded by a specific time limit.

Why this answer

Setting the activation maximum duration to 8 hours enforces the time-bound requirement, ensuring that once a user activates the Global Administrator role, the activation automatically expires after 8 hours. Option B is correct because enabling the approval workflow and adding the manager as an approver ensures that the manager must approve each activation request, meeting the requirement for manager approval. Together, these two configurations satisfy both the time-bound and approval constraints.

Exam trap

The trap here is that candidates often confuse 'justification' or 'MFA' with approval and time-bound constraints, but justification and MFA are separate security controls that do not satisfy the specific requirements for manager approval and a maximum duration.

27
MCQmedium

A security team uses Microsoft Sentinel. They want to automatically isolate a compromised virtual machine by applying a network security group (NSG) rule. They have created a playbook in Azure Logic Apps that modifies the NSG. How should they trigger this playbook when an incident of type 'Suspicious VM activity' is created?

A.Create an automation rule in Microsoft Sentinel that is triggered when an incident is created, and set the action to run the playbook.
B.Configure a data connector to send all alerts to the playbook.
C.Enable the playbook as a response action in the analytics rule.
D.Use a logic app trigger that polls Sentinel incidents every minute.
AnswerA

This is the correct approach because automation rules are Microsoft Sentinel's native event-driven response mechanism. When an incident is created, the rule fires, evaluates conditions (such as severity, tactic, or analytics rule name), and executes a playbook as an action. This enables immediate, consistent automated response without custom code or background polling.

Why this answer

Microsoft Sentinel automation rules are designed to trigger playbooks automatically when incidents are created, updated, or closed. By configuring an automation rule with the condition 'When incident is created' and the action 'Run playbook', the playbook that modifies the NSG will execute immediately upon the creation of a 'Suspicious VM activity' incident, achieving the desired automated isolation without manual intervention.

Exam trap

The trap here is that candidates often confuse analytics rule response actions (which trigger on alert generation) with automation rules (which trigger on incident creation), leading them to incorrectly select Option C when the question explicitly requires incident-based triggering.

How to eliminate wrong answers

Option B is wrong because data connectors ingest raw logs and alerts into Sentinel, but they do not trigger playbooks; playbooks are triggered by automation rules or analytics rule response actions, not by data connectors. Option C is wrong because analytics rules can have automated responses, but those responses run when an alert is generated, not when an incident is created; the question specifies triggering on incident creation, which requires an automation rule. Option D is wrong because polling every minute introduces latency and inefficiency, and Sentinel provides event-driven triggers (via automation rules) that react instantly to incident creation, making polling unnecessary and suboptimal.

28
MCQmedium

A security operations team uses Microsoft Sentinel. They are investigating a security incident that involves multiple alerts from different Azure resources. They need to see the entire attack timeline and all related entities (such as user accounts, IP addresses, and hosts) in a single, visual graph to understand the scope of the attack. Which Microsoft Sentinel feature should they use?

A.Investigation graph
B.Incident dashboard
C.Entity behavior analytics (UEBA)
D.Threat hunting blade
AnswerA

The Investigation graph in Microsoft Sentinel is purpose-built for incident response, rendering an interactive, visual map of entities such as IP addresses, hosts, accounts, and URLs alongside their connected relationships. Analysts can expand nodes to uncover hidden lateral movement, trace the full attack timeline, and pivot between related alerts and bookmarks, which makes it the correct choice for investigating a specific incident. Unlike static lists, the graph dynamically correlates evidence to reveal causal chains and support rapid root-cause analysis.

Why this answer

The Investigation graph in Microsoft Sentinel is specifically designed to visually map the relationships between alerts, entities (such as user accounts, IP addresses, and hosts), and the attack timeline. It allows security analysts to explore the scope of an incident by interactively expanding nodes and viewing connections, which directly meets the requirement for a single visual graph showing the entire attack timeline and related entities.

Exam trap

The trap here is that candidates often confuse the Incident dashboard (which shows a list of incidents) with the Investigation graph (which provides the interactive visual graph of entities and timeline), leading them to select the dashboard option because it sounds like the place to 'see' incident details.

How to eliminate wrong answers

Option B (Incident dashboard) is wrong because it provides a high-level summary of incidents (e.g., severity, status, count) but does not offer a visual graph of entity relationships or an attack timeline. Option C (Entity behavior analytics / UEBA) is wrong because it focuses on profiling and detecting anomalous behavior of individual entities over time, not on mapping the relationships and timeline of multiple alerts in a single incident. Option D (Threat hunting blade) is wrong because it is used for proactive, query-based searches for potential threats across large datasets, not for visualizing the scope and relationships of an already identified incident.

29
MCQhard

A KQL hunting query joins SecurityIncident with SecurityAlert but returns duplicate rows for incidents with multiple alerts. What KQL approach best preserves one row per incident while summarizing alert details?

A.Use order by TimeGenerated desc only
B.Replace join with union
C.Use take 1 before the join
D.Use summarize make_set() or arg_max() grouped by IncidentNumber
AnswerD

Summarize make_set() collects the distinct values of a chosen column (for example AlertId or AlertName) into an array for each IncidentNumber, guaranteeing exactly one output row per incident while preserving all associated alert details. If only the most recent alert per incident is needed, arg_max(TimeGenerated, *) returns the latest alert row for each incident. Both operators perform the aggregation after the join and directly address the duplicate-row issue.

Why this answer

`summarize make_set()` or `arg_max()` grouped by `IncidentNumber` collapses multiple alert rows into a single incident row while preserving alert details in an array or the most recent alert. This directly addresses the duplicate rows caused by a one-to-many join between SecurityIncident and SecurityAlert, ensuring one row per incident without data loss.

Exam trap

The trap here is that candidates often confuse sorting or limiting rows (options A and C) with deduplication, or incorrectly think a union can replace a join, missing the fundamental need to aggregate after a one-to-many relationship.

How to eliminate wrong answers

Option A is wrong because `order by TimeGenerated desc` only sorts the results and does not remove duplicate rows; it leaves the duplicates intact. Option B is wrong because `union` combines rows from two tables without any join logic, which would not correlate incidents with their alerts and would produce a completely different, incorrect result set. Option C is wrong because `take 1` before the join arbitrarily limits the input rows before the join, which can discard relevant alerts and still produce duplicates if the incident has multiple alerts in the remaining data.

30
Drag & Dropmedium

Drag and drop the steps to configure Azure AD Privileged Identity Management (PIM) for a role into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

PIM requires enabling the service first, then selecting roles, configuring settings, and finally assigning users as eligible.

31
MCQhard

A company uses Azure AD Privileged Identity Management (PIM) to manage access to critical roles. They want to require that users who are eligible for the 'Security Administrator' role must provide a support ticket number in the justification when activating the role. Additionally, they want to set a maximum activation duration of 4 hours. Which PIM role setting should they configure?

A.Activation settings
B.Notification settings
C.Approval settings
D.Assignment settings
AnswerA

Activation settings in Microsoft Entra ID PIM control what happens when an eligible user activates a role, including requiring justification such as a support ticket number and enforcing a maximum activation duration. Configuring these satisfies both the ticket-justification and four-hour duration constraints.

Why this answer

The 'Activation settings' in Azure AD PIM allow you to configure the maximum activation duration (in hours) and require justification, including a support ticket number, when a user activates an eligible role. These settings directly control the conditions under which role activation occurs, such as duration and mandatory justification fields.

Exam trap

The trap here is that candidates often confuse 'Assignment settings' (which control the duration of an eligible or active assignment) with 'Activation settings' (which control the duration and conditions of activation for eligible users), leading them to incorrectly select Option D.

How to eliminate wrong answers

Option B is wrong because 'Notification settings' control who receives email alerts when roles are activated or assigned, not the activation duration or justification requirements. Option C is wrong because 'Approval settings' require designated approvers to approve activation requests, but they do not enforce a maximum activation duration or a support ticket number in the justification. Option D is wrong because 'Assignment settings' define whether a role assignment is eligible or active, and the duration of the assignment itself, not the activation duration or justification content for eligible users.

32
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) to manage the 'Global Administrator' role. The security team wants to ensure that when a user activates the role, they must provide a justification, and the activation request must be approved by a specific group of security administrators. They have already configured the role for activation with a maximum duration of 8 hours. Which additional PIM settings should they configure?

A.Enable 'Require approval to activate' and select the security group as approver
B.Set 'Require Azure Multi-Factor Authentication' to 'On'
C.Set 'Require justification on activation' to 'On' and also enable 'Require ticket information'
D.Create a separate PIM request workflow using Azure Logic Apps
AnswerA

Enabling 'Require approval to activate' in PIM forces any eligible user's activation request to enter a pending state until a designated approver explicitly approves it. By selecting the security group as the approver, you guarantee that a human decision point exists outside the requesting user, so the security group enforces separation of duties. This is the native, built-in PIM approval mechanism that directly implements the required governance control.

Why this answer

The scenario requires both justification and approval for role activation. PIM allows you to enforce 'Require justification on activation' and 'Require approval to activate' as separate settings. By enabling 'Require approval to activate' and selecting the security group as the approver, you meet the requirement for approval.

Justification is already a default requirement in PIM when approval is enabled, but you must also explicitly set 'Require justification on activation' to 'On' if not already enforced; however, the question states they have already configured the role for activation with a maximum duration, so the missing piece is the approval configuration.

Exam trap

The trap here is that candidates may think 'Require justification on activation' alone satisfies the requirement, but the question explicitly asks for approval by a specific group, which requires the separate 'Require approval to activate' setting.

How to eliminate wrong answers

Option B is wrong because requiring Azure Multi-Factor Authentication (MFA) is a separate security control that does not enforce approval or justification; it only adds an authentication step during activation. Option C is wrong because while 'Require justification on activation' is needed, the scenario also requires approval by a specific group, which is not addressed by justification or ticket information alone. Option D is wrong because Azure Logic Apps are not a native PIM setting for role activation approval; PIM has built-in approval workflows that do not require custom Logic Apps.

33
MCQhard

A company uses Microsoft Defender for Cloud's Just-In-Time (JIT) VM access to manage RDP connections to a critical jump-box virtual machine. The company has a CI/CD pipeline running on Azure DevOps agent pools that needs to periodically RDP into this VM to deploy software. The agent pool's source IP addresses are dynamic and change frequently. They want the pipeline to automatically request JIT access before each deployment without manual intervention. Which approach should they implement?

A.Use the Azure REST API with a managed identity assigned to the DevOps agent to request JIT access, specifying the agent's current source IP address
B.Create a JIT access rule in Defender for Cloud with a scheduled time window that matches the pipeline's deployment schedule
C.Configure a PowerShell script in the pipeline to modify the network security group (NSG) to allow the agent's IP during deployment
D.Assign a static public IP to the Azure DevOps agent and add that IP to the JIT allowed list permanently
AnswerA

The REST API endpoint for JIT allows programmatic requests. A managed identity on the agent (or virtual machine running the agent) provides secure authentication without secrets. The pipeline can fetch its current outbound IP and request JIT access for the required time.

Why this answer

It uses the Azure REST API with a managed identity to dynamically request JIT VM access, specifying the agent's current source IP address. This approach allows the CI/CD pipeline to authenticate without secrets and automatically obtain time-bound RDP access, even though the agent's IP changes frequently. The managed identity provides secure, automated authentication to Azure Resource Manager, enabling the pipeline to call the JIT policy endpoint and grant access for the deployment duration.

Exam trap

The trap here is that candidates may think scheduled JIT rules (Option B) exist or that permanently whitelisting an IP (Option D) is acceptable, but Azure JIT is designed for dynamic, on-demand access requests, not static schedules or permanent allowances.

How to eliminate wrong answers

Option B is wrong because scheduled JIT access rules do not exist; JIT access is request-based and time-bound, not scheduled, and a fixed time window cannot accommodate dynamic IP changes or unpredictable deployment schedules. Option C is wrong because directly modifying the NSG bypasses Defender for Cloud's JIT access control, defeating the purpose of using JIT for security and auditability, and it would require additional permissions and manual cleanup. Option D is wrong because assigning a static public IP to the Azure DevOps agent is often impractical or impossible (agents may be in a dynamic pool or behind a NAT), and adding it permanently to the JIT allowed list eliminates the just-in-time security benefit, leaving the VM exposed continuously.

34
MCQmedium

A security team uses Microsoft Defender for Cloud to monitor the security posture of a hybrid environment that includes on-premises servers connected via Azure Arc. They want to enable a vulnerability assessment solution that automatically scans all servers (both Azure VMs and on-premises Arc-enabled servers) for OS vulnerabilities. Which solution should they enable directly from Defender for Cloud?

A.Enable the integrated vulnerability assessment solution (Qualys) in Defender for Cloud
B.Enable Microsoft Defender for Endpoint and integrate it with Defender for Cloud
C.Configure Azure Update Management to assess missing patches
D.Use Azure Policy to deploy the Log Analytics agent and manually enable scanning
AnswerA

The integrated vulnerability assessment (VA) solution in Defender for Cloud uses Qualys as the built-in scanner, and it is available at no additional cost for both Azure VMs and Arc-enabled on-premises servers. When you enable it, Defender for Cloud deploys the Qualys agent and automatically performs continuous OS vulnerability scanning, mapping findings to CVEs and security misconfigurations. This is the native, first-party path that does not require a separate Qualys license, making it the correct way to meet the monitoring requirement.

Why this answer

The integrated vulnerability assessment (VA) solution in Defender for Cloud, powered by Qualys, is the correct choice because it is a native, built-in capability that can be automatically enabled for both Azure VMs and Azure Arc-enabled on-premises servers. It requires no additional licensing or external configuration, and it automatically discovers and scans OS vulnerabilities without manual intervention, directly from the Defender for Cloud portal.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Endpoint's threat and vulnerability management (TVM) with a dedicated vulnerability assessment solution, but the question specifically asks for a solution that can be enabled directly from Defender for Cloud for automatic OS vulnerability scanning, which is the integrated Qualys-based VA solution.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Endpoint (MDE) is an endpoint detection and response (EDR) solution focused on threat detection and response, not a dedicated vulnerability assessment scanner; while MDE includes threat and vulnerability management (TVM), the question specifically asks for a solution that automatically scans for OS vulnerabilities directly from Defender for Cloud, and the integrated Qualys solution is the one that meets this requirement natively. Option C is wrong because Azure Update Management is designed to manage and deploy OS patches, not to assess vulnerabilities; it reports missing updates but does not perform vulnerability scanning or provide a vulnerability score. Option D is wrong because deploying the Log Analytics agent and manually enabling scanning is not a built-in vulnerability assessment solution; it requires custom configuration and does not provide the automated, integrated scanning that the Qualys-based solution offers directly from Defender for Cloud.

35
MCQmedium

A team wants to automatically deploy Defender for Cloud settings across new subscriptions under a management group. Which Azure capability should they use?

A.Application security groups
B.Conditional Access templates
C.Sentinel workbooks
D.Azure Policy initiative assignment
AnswerD

An Azure Policy initiative assignment is the correct solution because it allows you to assign a built-in or custom initiative, such as the Microsoft cloud security benchmark, at resource group, subscription, or management group scope. When assigned at a management group, the policy definitions are inherited by all existing and future subscriptions, enabling Defender for Cloud plans and configuring required monitoring settings automatically on new subscriptions. This policy-driven governance ensures consistency and eliminates the need for manual per-subscription configuration.

Why this answer

Azure Policy initiative assignments allow you to bundle multiple policy definitions (such as those for Defender for Cloud) and assign them at the management group scope. This ensures that all new subscriptions under that management group automatically inherit and enforce the Defender for Cloud settings, including enabling security monitoring and threat detection. This is the correct approach because Azure Policy provides continuous compliance evaluation and remediation at scale across the entire resource hierarchy.

Exam trap

The trap here is that candidates often confuse Azure Policy with Azure Blueprints or think that Defender for Cloud settings can only be configured per subscription manually, missing that Policy initiatives at the management group level provide automatic, scalable enforcement for new subscriptions.

How to eliminate wrong answers

Option A is wrong because Application security groups are used to group virtual machines and define network security rules based on those groups, not to deploy or enforce security settings across subscriptions. Option B is wrong because Conditional Access templates are part of Azure AD and control access to applications based on conditions like location or device state; they do not deploy Defender for Cloud settings. Option C is wrong because Sentinel workbooks are visualization tools for security data within Azure Sentinel, not a mechanism to automatically deploy or enforce security configurations across subscriptions.

36
MCQmedium

An organization uses Microsoft Defender for Cloud. They want to allow specific administrators to temporarily open RDP (port 3389) to a virtual machine only when needed, and for a limited time, while minimizing management overhead. Which Defender for Cloud feature should they use?

A.Azure Bastion
B.Just-in-time (JIT) VM access
C.Azure AD Privileged Identity Management (PIM)
D.Network Security Groups (NSGs)
AnswerB

Just-in-time (JIT) VM access in Microsoft Defender for Cloud dynamically creates NSG allow rules for specific ports and source IPs, and automatically removes them after the requested duration elapses (e.g., 1–3 hours). It supports approval workflows, audit logging, and integration with Azure AD, making it the only option here that provides time-limited, on-demand access to VMs. This directly meets the stated requirement.

Why this answer

Just-in-time (JIT) VM access in Microsoft Defender for Cloud allows administrators to temporarily open RDP (port 3389) to a virtual machine for a limited time, reducing exposure to brute-force attacks. It integrates with Azure Network Security Groups (NSGs) and Azure Firewall to automatically lock down inbound traffic when not in use, minimizing management overhead by eliminating the need for manual NSG rule changes.

Exam trap

The trap here is that candidates confuse Azure Bastion (persistent secure access) with JIT (time-limited port opening), or mistakenly think PIM controls network access rather than role activation.

How to eliminate wrong answers

Option A is wrong because Azure Bastion provides persistent, secure RDP/SSH access via TLS over the Azure portal without exposing public IPs, but it does not offer time-limited, on-demand port opening; it is always available once deployed. Option C is wrong because Azure AD Privileged Identity Management (PIM) manages just-in-time activation of Azure AD roles and Azure resource roles (e.g., Contributor), not network-level port access to VMs. Option D is wrong because Network Security Groups (NSGs) are the underlying mechanism to allow or deny traffic, but they require manual rule creation and removal, which increases management overhead and does not provide automated, time-limited access.

37
MCQeasy

A security team wants to receive a weekly email summary of the security posture of all their Azure subscriptions, including the Secure Score, top recommendations, and the number of healthy resources. Which Microsoft Defender for Cloud feature should they configure?

A.Continuous export to a Log Analytics workspace
B.Email notifications for weekly digest
C.Automation rules to trigger a Logic App on a schedule
D.Workflow automation to export data daily
AnswerB

Within Microsoft Defender for Cloud's 'Email notifications' settings, the 'Send weekly digest' checkbox enables an automatic email containing your Secure Score, top recommendations, and number of healthy resources. This digest can be addressed to all users with specific roles or to a custom list of email addresses, and it is delivered once per week without any additional Logic App or export configuration. It is the only first-party feature that matches the security team's requirement for a weekly email summary.

Why this answer

The 'Email notifications for weekly digest' feature in Microsoft Defender for Cloud is specifically designed to send a weekly summary of security posture, including Secure Score, top recommendations, and healthy resources, directly to specified email recipients. This feature is configured under Defender for Cloud's 'Email notifications' settings, where you can enable the weekly digest and define the recipients.

Exam trap

The trap here is that candidates confuse the weekly digest with workflow automation or continuous export, assuming any automated export can be scheduled to send emails, but only the dedicated 'Email notifications for weekly digest' feature provides the exact preformatted summary without custom Logic App development.

How to eliminate wrong answers

Option A is wrong because Continuous export to a Log Analytics workspace is used for streaming security data (e.g., alerts, recommendations) to a workspace for custom analysis or retention, not for sending a preformatted weekly email summary. Option C is wrong because Automation rules trigger actions (e.g., Logic Apps) based on specific events like new alerts or recommendations, not on a schedule for a weekly digest; scheduling requires a separate Logic App trigger. Option D is wrong because Workflow automation triggers Logic Apps or runbooks in response to Defender for Cloud events (e.g., when a recommendation is created), not for scheduled daily exports; daily exports to email are not a native feature.

38
Multi-Selecthard

A team wants to deploy Sentinel content consistently across workspaces. Which two approaches are appropriate?

Select 2 answers
A.Manually copy screenshots of rules
B.Use Content Hub solutions where available
C.Store incidents in Azure Key Vault
D.Use infrastructure-as-code or automation for analytic rules and workbooks
AnswersB, D

Content Hub solutions are Microsoft Sentinel's packaged, versioned bundles of data connectors, analytic rules, workbooks, and playbooks. Installing the same solution across multiple workspaces guarantees a common content baseline and simplifies updates because solutions can be centrally managed. This is correct because it directly addresses consistent, repeatable content deployment at scale.

Why this answer

Content Hub solutions in Azure Sentinel provide pre-packaged content (analytic rules, workbooks, playbooks) that can be installed consistently across multiple workspaces via the Azure portal or API. This ensures standardized deployment without manual errors, leveraging Microsoft's curated content for common scenarios.

Exam trap

The trap here is that candidates may confuse 'storing incidents' (operational data) with 'deploying content' (configuration), leading them to incorrectly select Azure Key Vault as a deployment mechanism for Sentinel rules.

39
MCQmedium

A security analyst uses Microsoft Defender for Cloud. They need to assess their Azure environment's compliance against the Payment Card Industry Data Security Standard (PCI DSS). Which dashboard in Defender for Cloud should they use to view the compliance status?

A.Secure Score
B.Security Alerts
C.Regulatory Compliance
D.Workbooks
AnswerC

The Regulatory Compliance dashboard in Defender for Cloud provides a dedicated view of how your Azure environment scores against a specific regulatory standard, such as CIS 1.4, NIST SP 800-53, or PCI DSS v3.2.1. It uses Azure Policy initiatives with policy definitions underlying each compliance control; each control displays a Pass/Fail status and a list of non-compliant resources based on continuous policy evaluation. The dashboard also shows the compliance score for that standard, giving you an immediate audit-ready overview. This directly meets the analyst's need to display compliance against a specific regulatory standard.

Why this answer

The Regulatory Compliance dashboard in Microsoft Defender for Cloud provides a pre-built assessment of your Azure environment against specific compliance standards, including PCI DSS. It maps your security controls to the requirements of the standard and shows a compliance score based on the results of continuous assessments. This is the correct tool for viewing compliance status against PCI DSS.

Exam trap

The trap here is that candidates may confuse Secure Score (which measures general security hygiene) with regulatory compliance scoring, but Secure Score does not map to specific standards like PCI DSS, while Regulatory Compliance does.

How to eliminate wrong answers

Option A is wrong because Secure Score measures your overall security posture based on implemented security controls, not compliance with a specific regulatory standard like PCI DSS. Option B is wrong because Security Alerts lists active threats and suspicious activities, not compliance status. Option D is wrong because Workbooks are customizable visualizations that can be built from Azure Monitor data, but they do not provide a pre-built, out-of-the-box compliance assessment against PCI DSS.

40
MCQmedium

A security operations team uses Microsoft Sentinel. They need to collect Syslog messages from on-premises Linux servers for analysis. Which data connector should they use to ingest these logs into Sentinel?

A.Azure Activity Log connector
B.Syslog connector via Log Analytics agent
C.Common Event Format (CEF) connector
D.Windows Security Events connector
AnswerB

The Syslog connector via the Log Analytics agent is the correct choice for ingesting standard Syslog messages into Microsoft Sentinel. To use it, you must install the Log Analytics agent on a Linux virtual machine (on-premises or in Azure) that acts as a Syslog collector, then configure the agent's syslog daemon to forward events with specific facilities and severities. The connector then maps those events to the Syslog table in the workspace, enabling detection rules and queries.

Why this answer

The Syslog connector via Log Analytics agent is the correct choice because it allows Microsoft Sentinel to collect Syslog messages from on-premises Linux servers. The Log Analytics agent (formerly OMS agent) listens on UDP port 514 (or a custom port) for Syslog messages forwarded by the Linux rsyslog or syslog-ng daemon, then forwards them to the Log Analytics workspace. This connector is specifically designed for standard Syslog ingestion without requiring format transformation.

Exam trap

The trap here is that candidates often confuse the Syslog connector (for standard Syslog) with the CEF connector (for formatted security logs), mistakenly thinking CEF is required for any Linux Syslog ingestion, when in fact CEF is only needed for specific security appliances that output CEF-formatted logs.

How to eliminate wrong answers

Option A is wrong because the Azure Activity Log connector ingests subscription-level events from Azure's control plane (e.g., resource creation, policy changes), not Syslog messages from on-premises Linux servers. Option C is wrong because the Common Event Format (CEF) connector is used for security appliances that output CEF-formatted logs (e.g., firewalls, IDS/IPS) and requires a Syslog forwarder to parse and transform the logs, whereas standard Syslog messages do not need this transformation. Option D is wrong because the Windows Security Events connector collects Windows Event Log data (specifically Security events) from Windows machines, not Syslog messages from Linux servers.

41
MCQhard

A Microsoft Sentinel rule should run with minimal delay against supported data sources and produce alerts close to event time. Which rule type should be considered?

A.Fusion rule
B.Near-real-time analytics rule
C.Workbook query
D.Threat intelligence indicator import
AnswerB

A near-real-time (NRT) analytics rule is executed once every minute against data that was ingested in the previous minute, so it provides the smallest detection-to-action delay of all Microsoft Sentinel rule types. Unlike scheduled analytics rules whose query interval is often 5 minutes or more, NRT rules are explicitly designed for time-sensitive use cases and can trigger automation immediately. This is why they are the correct choice for a rule that must run with minimal delay.

Why this answer

Near-real-time (NRT) analytics rules in Microsoft Sentinel are designed to run at 1-minute intervals, providing the minimal delay for alert generation against supported data sources. This rule type queries data with low latency, ensuring alerts are produced close to the event time, which is critical for timely threat detection.

Exam trap

The trap here is that candidates often confuse near-real-time rules with scheduled analytics rules, assuming scheduled rules can be configured for minimal delay, but NRT rules are the only type that guarantees sub-5-minute latency without custom scheduling.

How to eliminate wrong answers

Option A is wrong because Fusion rules are correlation-based and use machine learning to detect multistage attacks, not designed for minimal delay or near-real-time alerting. Option C is wrong because workbook queries are for visualization and reporting, not for generating alerts or running with minimal delay. Option D is wrong because threat intelligence indicator import is a data ingestion process for bringing in threat indicators, not a rule type that runs queries to produce alerts.

42
MCQmedium

A security operations team uses Microsoft Sentinel. They want to create an automation that automatically changes the severity of an incident from 'Medium' to 'High' when a specific indicator of compromise (IOC) is observed in the incident's entities. The playbook should run immediately when the incident is created. Which type of automation rule trigger should they configure?

A.When incident is created
B.When incident is updated
C.When alert is generated
D.Scheduled
AnswerA

The "When incident is created" trigger is an automation rule trigger that fires the moment Microsoft Sentinel generates a new incident, either from an alert or through manual creation. This trigger enables a playbook to begin executing immediately, allowing security teams to perform instant triage, enrichment, or containment actions. It is the only trigger that guarantees execution exactly on incident creation, which is why it is the correct choice for this requirement.

Why this answer

The requirement specifies that the automation should run immediately when the incident is created. In Microsoft Sentinel, an automation rule with the trigger 'When incident is created' executes a playbook as soon as the incident is generated, before any updates occur. This allows the playbook to evaluate the incident's entities (e.g., IP addresses, hashes) and change the severity from 'Medium' to 'High' if a specific IOC is present, meeting the real-time response need.

Exam trap

The trap here is that candidates often confuse 'When alert is generated' with incident creation, not realizing that alerts are raw signals and incidents are the correlated case that can have severity changed, leading them to pick Option C instead of A.

How to eliminate wrong answers

Option B is wrong because 'When incident is updated' triggers only after an incident has been modified (e.g., status change, comment added), not at creation time, so it would not run immediately upon incident generation. Option C is wrong because 'When alert is generated' triggers on individual alerts, not incidents; incidents can aggregate multiple alerts, and the playbook needs to run at the incident level to change incident severity. Option D is wrong because 'Scheduled' triggers run on a recurring schedule (e.g., every hour), not in real-time upon incident creation, which fails the 'immediately' requirement.

43
MCQmedium

A company wants to ensure that users can only access Microsoft 365 services (e.g., Exchange Online, SharePoint Online) from devices that are confirmed to be compliant with corporate security policies (e.g., encryption enabled, antivirus active). Which Azure AD policy type should they create?

A.Conditional Access policy with the 'Require compliant device' grant control.
B.Identity Protection policy with a sign-in risk policy.
C.Access review policy for groups.
D.Privileged Identity Management (PIM) activation policy.
AnswerA

This grant control is enforced by Azure AD during authentication after Intune evaluates the device state; if the device is not enrolled in Mobile Device Management or fails compliance checks (such as missing encryption, a detected jailbreak, or a threat from Microsoft Defender for Endpoint), sign-in is blocked. Because the policy runs in real time on every authentication request, it precisely meets the requirement that users can only access Microsoft 365 services from devices that meet your organization's security baseline. It can also target specific cloud apps and the Microsoft 365 suite, and you can combine it with session controls for additional security.

Why this answer

A is correct because a Conditional Access policy with the 'Require compliant device' grant control enforces device-based access restrictions by checking the device's compliance status reported by Microsoft Intune. This ensures that only devices meeting corporate security policies (e.g., encryption enabled, antivirus active) can access Microsoft 365 services like Exchange Online and SharePoint Online.

Exam trap

The trap here is confusing device compliance (Conditional Access) with sign-in risk (Identity Protection), as both involve 'risk' or 'compliance' terminology but target fundamentally different aspects of security—device state versus authentication risk.

How to eliminate wrong answers

Option B is wrong because Identity Protection sign-in risk policies evaluate the likelihood that a sign-in attempt is unauthorized (e.g., from an anonymous IP or leaked credentials), not the compliance state of the device. Option C is wrong because Access review policies for groups manage periodic attestation of group memberships, not device compliance or access control. Option D is wrong because Privileged Identity Management (PIM) activation policies control the elevation of privileged roles (e.g., Global Admin) and do not enforce device compliance for service access.

44
MCQhard

A Conditional Access policy requiring compliant devices does not apply to Azure PowerShell access. Sign-in logs show the cloud app is excluded. What should be changed?

A.Disable device compliance in Intune
B.Convert the policy to a named location policy
C.Remove MFA from all users
D.Include the relevant cloud app or target all cloud apps after testing exclusions
AnswerD

A compliant-device policy does not automatically select which cloud apps are protected; you must explicitly add a target resource (cloud app or action) in the policy's assignments. To avoid blanket lockout, start with a pilot group and a specific app like Exchange Online, then expand to 'All cloud apps' with carefully tested exclusions. Without this assignment, the grant control has no app to apply to, so the policy is effectively inert.

Why this answer

Conditional Access policies apply only to cloud apps explicitly included in the policy. Since Azure PowerShell is excluded, the policy does not enforce the 'Require device to be marked as compliant' condition for that app. To fix this, you must either include the specific cloud app (Microsoft Azure PowerShell) or set the policy to target 'All cloud apps' and then test exclusions to ensure the compliant device requirement is applied to Azure PowerShell access.

Exam trap

The trap here is that candidates may assume a Conditional Access policy applies to all cloud apps by default, but in reality, policies only apply to apps explicitly included, and exclusions take precedence over inclusions.

How to eliminate wrong answers

Option A is wrong because disabling device compliance in Intune would remove the compliance status altogether, breaking the policy's intent rather than fixing the exclusion issue. Option B is wrong because converting the policy to a named location policy would change the condition from device compliance to network location, which does not address the missing cloud app inclusion for Azure PowerShell. Option C is wrong because removing MFA from all users is unrelated to the cloud app exclusion; MFA is a separate control and removing it would weaken security without resolving the policy scope problem.

45
MCQmedium

A security operations team uses Microsoft Sentinel. They want to create a custom analytics rule that detects when an Azure virtual machine is created with a public IP address that is not in an approved list. Which type of rule should they use?

A.Scheduled query rule
B.NRT rule
C.Anomaly rule
D.Fusion rule
AnswerA

Correct. Scheduled query rules allow you to run a KQL query on a schedule and create incidents based on the results. This is ideal for checking new VM creations against an approved IP list.

Why this answer

A scheduled query rule is the correct choice because it allows you to define a KQL query that runs on a recurring schedule (e.g., every 5 minutes) to detect when an Azure VM is created with a public IP not in an approved list. This rule type is designed for custom detection logic that requires periodic evaluation of log data, such as AzureActivity logs or Azure Resource Graph, making it ideal for this scenario.

Exam trap

The trap here is that candidates confuse NRT rules with scheduled query rules, assuming NRT's lower latency is always better, but NRT rules lack the ability to reference external data sources like watchlists for dynamic approved IP comparisons.

How to eliminate wrong answers

Option B (NRT rule) is wrong because near-real-time rules are designed for low-latency detection (up to 2 minutes) but do not support the complex KQL logic needed to cross-reference a dynamic approved list; they are better suited for simple, high-frequency patterns. Option C (Anomaly rule) is wrong because anomaly rules use machine learning to detect unusual patterns in time-series data, not static comparisons against an approved list. Option D (Fusion rule) is wrong because fusion rules are prebuilt for multi-stage attack detection across different data sources, not for custom single-condition checks like VM creation with an unapproved public IP.

46
MCQmedium

A cloud security team wants Defender for Cloud to assess AWS accounts and GCP projects from the same portal used for Azure posture management. What should they configure?

A.Environment settings with multicloud connectors
B.Azure Arc-enabled Kubernetes only
C.Microsoft Sentinel data connector for AWS CloudTrail only
D.Azure Lighthouse delegation
AnswerA

Environment settings in Microsoft Defender for Cloud provide the multicloud connectors that onboard AWS accounts at the subscription level, enabling continuous security posture management (CSPM), asset inventory, and regulatory compliance scoring across AWS services. The connector integrates with AWS Security Hub and CloudTrail to aggregate findings, and without creating this connector, Defender for Cloud cannot assess the AWS environment. This is the only option that directly fulfills the stated requirement for cloud security assessment.

Why this answer

Defender for Cloud's multicloud connectors allow you to onboard AWS accounts and GCP projects directly into the Azure portal, enabling unified security posture management across all three cloud environments. This feature integrates with AWS Security Hub and GCP Security Command Center to aggregate findings and assessments into a single dashboard, without requiring any migration of workloads.

Exam trap

The trap here is that candidates confuse Defender for Cloud's multicloud posture assessment with Microsoft Sentinel's SIEM data connectors, assuming any cloud integration must go through Sentinel, when in fact Defender for Cloud has its own dedicated multicloud connector for posture management.

How to eliminate wrong answers

Option B is wrong because Azure Arc-enabled Kubernetes only extends Azure management to Kubernetes clusters running outside Azure, not to AWS accounts or GCP projects for cloud posture assessment. Option C is wrong because Microsoft Sentinel's data connector for AWS CloudTrail is designed for security information and event management (SIEM) ingestion, not for continuous cloud security posture assessment and compliance monitoring. Option D is wrong because Azure Lighthouse delegation is used for managing multiple Azure tenants from a single control plane, not for integrating non-Azure cloud providers like AWS or GCP.

47
MCQmedium

A privileged administrator should activate the Security Administrator role only for approved work and for a limited time. What should be configured?

A.Permanent active assignment in Microsoft Entra ID
B.Eligible assignment with activation controls in Privileged Identity Management
C.Owner role at the subscription root
D.Conditional Access session persistence
AnswerB

An eligible assignment in Privileged Identity Management (PIM) allows the administrator to activate the security role on demand for a limited time, with activation controls such as MFA, business justification, approval workflows, and a maximum duration. This provides just-in-time privileged access, ensuring the security role is not permanently active and its permissions are only used after successful activation. This directly satisfies the requirement.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure eligible assignments for roles like Security Administrator. This means the user must activate the role on demand, with time-bound activation controls (e.g., maximum activation duration, approval, MFA), ensuring the role is used only for approved work and for a limited time. This directly meets the requirement of just-in-time (JIT) access and temporary activation.

Exam trap

The trap here is that candidates often confuse permanent active assignments (Option A) with eligible assignments, mistakenly thinking that permanent assignment is sufficient if the user is trusted, but the question explicitly requires 'limited time' activation, which only PIM can enforce.

How to eliminate wrong answers

Option A is wrong because a permanent active assignment grants the role continuously without any time limit or activation requirement, violating the principle of limited-time access. Option C is wrong because the Owner role at the subscription root is an Azure RBAC role, not a Microsoft Entra ID administrative role, and it does not provide the Security Administrator permissions needed for identity security tasks; it also lacks time-bound activation controls. Option D is wrong because Conditional Access session persistence controls how long a user stays signed in (e.g., browser session persistence), not the activation or duration of a privileged role assignment.

48
MCQmedium

A Defender for Cloud secure score recommendation says storage accounts allow public blob access. What remediation best addresses the root issue?

A.Enable storage account static website hosting
B.Increase Log Analytics retention
C.Disable public blob access at the storage account level and review container ACLs
D.Create an Azure Front Door profile
AnswerC

Disabling public blob access at the storage account root overrides any container-level permission to 'public read access' for blobs or containers, preventing anonymous requests. Reviewing container Access Control Lists (ACLs) ensures no individual container has been set to allow public access, closing the exact misconfiguration flagged by Defender for Cloud. This directly reduces the attack surface and aligns with the principle of default-deny for storage data.

Why this answer

The secure score recommendation indicates that storage accounts allow public blob access, which is a security risk. The root cause is that anonymous access is enabled at the storage account level, and individual container ACLs may also permit public access. Disabling public blob access at the storage account level (via the 'AllowBlobPublicAccess' property) immediately blocks all anonymous requests, and reviewing container ACLs ensures no residual permissions exist.

This directly addresses the vulnerability by enforcing a deny-by-default posture.

Exam trap

The trap here is that candidates may confuse the storage account-level public access setting with container-level ACLs, thinking that disabling one automatically disables the other, or they may mistakenly believe that enabling static website hosting or using Front Door can override or mitigate the public access vulnerability.

How to eliminate wrong answers

Option A is wrong because enabling static website hosting does not affect public blob access settings; it only serves static content from a specific container ($web) and does not remediate the security recommendation. Option B is wrong because increasing Log Analytics retention only extends the storage duration of diagnostic logs, which does not change access permissions or block anonymous blob access. Option D is wrong because creating an Azure Front Door profile is a content delivery and acceleration service that does not modify storage account access policies or disable public blob access.

49
MCQmedium

A company uses Microsoft Defender for Cloud to manage its security posture. The compliance team wants to monitor the subscription's compliance with the Payment Card Industry Data Security Standard (PCI DSS). They need to view a detailed compliance report and track progress over time. What should they do in Defender for Cloud?

A.Enable the relevant Defender for Cloud plans (e.g., Defender for Servers, Defender for SQL).
B.Add the PCI DSS standard from the regulatory compliance dashboard.
C.Create a custom regulatory compliance initiative based on PCI DSS controls.
D.Configure continuous export to send compliance data to a Log Analytics workspace.
AnswerB

Adding the PCI DSS standard from the regulatory compliance dashboard is the correct action because Defender for Cloud includes a built-in regulatory compliance initiative pre-mapped to PCI DSS controls. This initiative automatically runs assessments against your environment and presents the results in a dedicated compliance view, allowing you to track progress against each control requirement. This is the straightforward, intended method to start monitoring PCI DSS compliance.

Why this answer

The regulatory compliance dashboard in Microsoft Defender for Cloud allows you to add built-in compliance standards like PCI DSS. Once added, the dashboard automatically assesses your subscription against the standard's controls, provides a detailed compliance report, and tracks progress over time with a compliance score and historical trend. This is the direct method to monitor PCI DSS compliance without needing to enable specific Defender plans or create custom initiatives.

Exam trap

The trap here is that candidates often confuse enabling Defender plans (which provide threat detection) with adding a compliance standard (which provides a compliance assessment), leading them to select Option A instead of the correct dashboard action in Option B.

How to eliminate wrong answers

Option A is wrong because enabling Defender for Cloud plans (e.g., Defender for Servers, Defender for SQL) provides security alerts and advanced threat protection but does not by itself add or display a PCI DSS compliance report; the regulatory compliance dashboard must be explicitly configured with the standard. Option C is wrong because creating a custom regulatory compliance initiative based on PCI DSS controls is unnecessary and more complex; Microsoft provides a built-in PCI DSS initiative that is automatically updated and maintained, and custom initiatives are typically used for organization-specific controls, not for adopting a standard already available in the dashboard. Option D is wrong because configuring continuous export to a Log Analytics workspace sends raw security data (e.g., alerts, recommendations) for external analysis or retention, but it does not generate or display the PCI DSS compliance report or track progress within Defender for Cloud's dashboard.

50
MCQhard

An organization uses Microsoft Defender for Cloud. They want to implement just-in-time (JIT) VM access for a set of production VMs. However, the security team needs to ensure that JIT access requests are always approved by a manager before opening ports. Which configuration should they use?

A.Enable JIT in Defender for Cloud and configure a logic app to send approval emails
B.Use Azure AD Privileged Identity Management (PIM) for JIT activation
C.Enable JIT and configure a custom workflow automation with an approval step
D.Use Conditional Access with session controls
AnswerC

The correct approach is to enable Defender for Cloud's JIT VM access and then create a custom workflow automation rule that triggers an Azure Logic App containing an approval step. The Logic App can use an approval connector (e.g., Send approval request through email or Teams) to pause the workflow until a manager or security officer approve or rejects the request. Only after approval does the Logic App signal Defender for Cloud to apply the JIT policy and open the requested ports, thereby enforcing a true approval gate before network access is granted.

Why this answer

Microsoft Defender for Cloud's JIT VM access can be integrated with a custom workflow automation that includes an approval step. This allows the security team to enforce manager approval before ports are opened, meeting the requirement for a formal approval process. The workflow automation can trigger an Azure Logic App or other action that requires a designated approver to authorize the request.

Exam trap

The trap here is confusing Azure AD PIM (which manages role activation) with JIT VM access (which manages network port openings), leading candidates to incorrectly select PIM for VM-level access control.

How to eliminate wrong answers

Option A is wrong because while a logic app can send approval emails, it does not enforce a mandatory approval step before JIT access is granted; the JIT request would still be automatically approved unless the logic app is configured to block it, which is not a native capability. Option B is wrong because Azure AD PIM is designed for managing and approving privileged role activations, not for controlling JIT VM access requests to specific ports on VMs. Option D is wrong because Conditional Access with session controls governs access to applications and data based on conditions like location or device compliance, not for approving JIT port openings on VMs.

51
MCQmedium

A company uses Azure AD Conditional Access. They want to require multi-factor authentication (MFA) for all users accessing the Azure portal, but only when the sign-in risk level is medium or above. Which configuration should they use in the Conditional Access policy?

A.Assignments > Cloud apps > Include > Microsoft Azure Management, Conditions > Sign-in risk > Medium and above, Grant > Require MFA.
B.Assignments > Users > All users, Cloud apps > All cloud apps, Conditions > User risk > Medium, Grant > Require MFA.
C.Assignments > Conditions > Locations > All trusted locations, Grant > Require MFA.
D.Assignments > Cloud apps > Include > All cloud apps, Conditions > Device platforms > iOS, Grant > Require MFA.
AnswerA

This is correct because the Microsoft Azure Management cloud app encompasses the Azure portal, Azure Resource Manager, CLI, and PowerShell, so the policy applies to administrative control-plane sign-ins. Adding the Sign-in risk condition at 'Medium and above' causes Azure AD Identity Protection to evaluate the current authentication attempt for real-time risk, and the Grant control forces MFA when that risk threshold is met. This narrowly targets Azure management rather than all cloud apps, which is exactly what the company needs.

Why this answer

It specifically targets the Azure portal via 'Microsoft Azure Management' in Cloud apps, sets the sign-in risk condition to 'Medium and above', and requires MFA. This matches the requirement exactly: MFA is triggered only when accessing the Azure portal and the sign-in risk level is medium or higher.

Exam trap

The trap here is confusing 'User risk' with 'Sign-in risk' — user risk is a persistent score based on past user behavior, while sign-in risk is a session-level assessment, and the question explicitly requires the latter for the current sign-in event.

How to eliminate wrong answers

Option B is wrong because it uses 'User risk' instead of 'Sign-in risk' — user risk is based on historical user behavior, not the current sign-in session, and it applies to all cloud apps, not just the Azure portal. Option C is wrong because it uses 'Locations' with 'All trusted locations', which would require MFA from trusted locations regardless of risk, and does not target the Azure portal or sign-in risk. Option D is wrong because it targets 'All cloud apps' and 'Device platforms > iOS', which would require MFA for all iOS devices accessing any cloud app, not specifically the Azure portal based on sign-in risk.

52
MCQmedium

You are the Azure Security Engineer for a company that uses Microsoft Entra ID (formerly Azure AD). The security team wants to ensure that when a user signs in from an unknown location, they are required to perform multi-factor authentication (MFA). However, users signing in from the corporate office should not be prompted for MFA. You create a Conditional Access policy with a condition for trusted locations. What should you configure to ensure the policy works as intended?

A.Enable security defaults in Microsoft Entra ID to automatically require MFA for all users except those with privileged roles.
B.Create a conditional access policy that requires MFA for all users and then exclude users who are in the corporate office by using a dynamic group.
C.Configure a sign-in risk policy in Microsoft Entra ID Protection to block sign-ins from unknown locations.
D.Add the corporate office public IP addresses as named locations and mark them as trusted.
AnswerD

Named locations allow you to define IP ranges that are considered trusted. By marking them as trusted, you can exclude them from the Conditional Access policy's MFA requirement. This is the correct approach because Conditional Access conditions can include location, and trusted named locations are specifically designed for this scenario. It ensures users from the corporate office are not prompted for MFA while others are.

Why this answer

The correct approach is to define named locations for the corporate office IP ranges and mark them as trusted. Conditional Access policies can then include or exclude these locations. This allows the policy to require MFA for unknown locations while exempting the trusted corporate office.

Other options do not provide the necessary location-based control or are not granular enough.

Exam trap

The trap here is confusing location-based conditions with risk-based policies or group membership, which do not evaluate real-time network location.

53
Multi-Selecthard

You are configuring Microsoft Entra Privileged Identity Management (PIM) for a group of users who need to activate the Security Administrator role. The role should only be activated after approval by a designated approver, and the activation should be limited to a maximum of 4 hours. Which two settings must you configure in the role's PIM settings? (Choose two.)

Select 2 answers
A.Require approval to activate.
B.Require conditional access authentication context.
C.Require multi-factor authentication on activation.
D.Require justification on activation.
E.Set the maximum activation duration to 4 hours.
AnswersA, E

The 'Require approval to activate' setting enforces that a designated approver must approve the activation request before the role becomes active. This matches the requirement that activation should only occur after approval by a designated approver. Without this setting, users could activate the role without any oversight, violating the scenario's conditions.

Why this answer

To enforce approval and a maximum activation duration, you must enable 'Require approval to activate' and set the 'Maximum activation duration' to 4 hours. These two settings directly address the requirements. Other settings like justification or MFA are optional and do not fulfill the specified conditions.

Proper configuration ensures that privileged access is tightly controlled.

Exam trap

The trap here is assuming that MFA or justification are required when the scenario only specifies approval and a time limit.

54
MCQmedium

A company uses Azure Active Directory (Azure AD) and has a conditional access policy that requires multi-factor authentication (MFA) for all external users accessing SharePoint Online. However, the security team wants to enforce that external users must re-authenticate every 30 minutes when accessing SharePoint. Which control should they configure in a new conditional access policy targeting SharePoint Online?

A.Assign the policy to 'All cloud apps' and use a grant control to require multi-factor authentication.
B.Configure a condition for sign-in risk level and set it to 'High'.
C.Add a session control and set 'Sign-in frequency' to 30 minutes.
D.Configure a session control to use 'App enforced restrictions' for SharePoint.
AnswerC

The 'Sign-in frequency' session control in Azure AD Conditional Access defines how long a user's session remains valid before they must sign in again. Setting it to 30 minutes forces reauthentication every half hour for the targeted cloud app, exactly matching the stated requirement. This is the appropriate control because it is enforced by Azure AD at the session level, independent of the application's own settings.

Why this answer

The 'Sign-in frequency' session control in a Conditional Access policy allows administrators to enforce re-authentication at a specified interval. By setting this to 30 minutes and targeting the SharePoint Online app, external users will be prompted to re-authenticate every 30 minutes, meeting the security team's requirement. This control is independent of MFA and specifically addresses the frequency of authentication sessions.

Exam trap

The trap here is that candidates often confuse 'Sign-in frequency' with 'Grant controls' (like MFA) or 'Conditions' (like risk), not realizing that session controls specifically manage the duration of authentication sessions rather than the method of authentication.

How to eliminate wrong answers

Option A is wrong because assigning the policy to 'All cloud apps' and requiring MFA does not enforce a re-authentication frequency; it only mandates MFA at initial sign-in, not every 30 minutes. Option B is wrong because configuring a condition for sign-in risk level set to 'High' triggers MFA or block based on risk, not a fixed 30-minute re-authentication interval. Option D is wrong because 'App enforced restrictions' is a session control that delegates session management to the application (e.g., SharePoint), but it does not enforce a specific re-authentication frequency like 30 minutes.

55
MCQmedium

A security team uses Microsoft Sentinel. They want to create a custom analytics rule that detects when a user account is created in Azure AD and then within 5 minutes attempts to access a sensitive SharePoint site. What should they use to correlate these two events?

A.KQL query with join on UserId
B.Watchlist
C.Automation rule
D.Playbook
AnswerA

A KQL query with a join on UserId is the correct choice because it directly correlates events from multiple Sentinel tables, such as SigninLogs and AuditLogs, on a common field to detect suspicious patterns. The join operator in KQL supports different join kinds (inner, leftouter, etc.) to capture matching or non-matching records, enabling the security team to define precise detection logic. This alignment between the query's data correlation and the scenario makes it the only option that fulfills the requirement for real-time detection.

Why this answer

A KQL query with a join on UserId allows you to correlate two separate tables—such as AuditLogs for user creation and SharePoint access logs—based on a common field (UserId) within a specified time window (5 minutes). This is the standard method in Microsoft Sentinel for creating multi-event detection rules that require temporal correlation between distinct activities.

Exam trap

The trap here is that candidates may confuse a Watchlist (used for static lookups) with a correlation mechanism, or mistakenly think Automation rules or Playbooks can perform event correlation, when in fact only KQL queries with joins can correlate multiple events in a single detection rule.

How to eliminate wrong answers

Option B is wrong because a Watchlist is a static list of items (e.g., IP addresses or account names) used for reference or filtering, not for correlating dynamic events across time. Option C is wrong because an Automation rule in Sentinel triggers a response (e.g., incident creation or playbook execution) based on a single alert or incident, not for correlating two separate events. Option D is wrong because a Playbook is a set of automated actions (often using Azure Logic Apps) triggered by an alert, not a mechanism to correlate events in a detection query.

56
MCQmedium

An organization is required to comply with the Health Insurance Portability and Accountability Act (HIPAA). They use Microsoft Defender for Cloud to manage their Azure security posture. Which feature in Defender for Cloud should they use to view their current compliance status against HIPAA controls?

A.Regulatory compliance dashboard.
B.Security posture dashboard.
C.Recommendations dashboard.
D.Inventory dashboard.
AnswerA

The Regulatory compliance dashboard in Microsoft Defender for Cloud is the correct tool because it continuously assesses your Azure environment against built-in regulatory standards such as HIPAA HITRUST, GDPR, and ISO 27001. It uses Azure Policy initiatives to map specific controls to resources, presenting a compliance score and per-control pass/fail status. This dashboard directly provides the evidence and remediation tracking needed to demonstrate adherence to HIPAA requirements, unlike the other dashboards.

Why this answer

The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built view of your compliance posture against various standards, including HIPAA. It continuously assesses your Azure environment against HIPAA controls and displays the current compliance status, enabling you to track and improve adherence to regulatory requirements.

Exam trap

The trap here is that candidates often confuse the Security posture dashboard (which shows overall security health) with the Regulatory compliance dashboard, mistakenly thinking the former includes compliance status against specific standards like HIPAA.

How to eliminate wrong answers

Option B is wrong because the Security posture dashboard focuses on the overall security state of your resources (e.g., secure score, attack paths) rather than mapping to specific regulatory frameworks like HIPAA. Option C is wrong because the Recommendations dashboard lists actionable security recommendations to improve your secure score, but it does not organize them by compliance standard or show compliance status against HIPAA controls. Option D is wrong because the Inventory dashboard provides a list of all monitored resources and their configurations, not a compliance-specific view against regulatory standards.

57
MCQmedium

A security team uses Microsoft Defender for Cloud to monitor the security posture of their Azure environment. They want to ensure that the Log Analytics agent is automatically installed on all new Azure virtual machines as soon as they are provisioned, to collect security logs. Which feature should they enable in Defender for Cloud?

A.Data Collection Rules (DCR) in Azure Monitor.
B.Auto-provisioning of the Log Analytics agent in Defender for Cloud's environment settings.
C.Azure Policy 'Deploy Log Analytics agent for Linux/Windows VM'.
D.Use Azure Automation State Configuration.
AnswerB

Auto-provisioning installs the Log Analytics agent automatically on newly created and existing Azure VMs, using the workspace configured in environment settings. This satisfies the requirement that new VMs receive the agent immediately at provisioning without manual installation.

Why this answer

Defender for Cloud's auto-provisioning feature is specifically designed to automatically install the Log Analytics agent on all existing and new Azure VMs to collect security logs. When enabled in the environment settings, it ensures that any new VM provisioned in the subscription gets the agent installed without manual intervention, directly addressing the requirement for automatic installation on new VMs.

Exam trap

The trap here is that candidates often confuse Azure Policy-based deployment (Option C) with Defender for Cloud's native auto-provisioning, but the question specifically asks for the feature within Defender for Cloud's environment settings, which is auto-provisioning, not a separate policy assignment.

How to eliminate wrong answers

Option A is wrong because Data Collection Rules (DCRs) in Azure Monitor are used to define data collection for the Azure Monitor Agent (AMA), not for the Log Analytics agent, and they do not automatically install agents on new VMs. Option C is wrong because the Azure Policy 'Deploy Log Analytics agent for Linux/Windows VM' is a built-in policy that can deploy the agent, but it requires assignment and evaluation, and it does not automatically trigger on new VM provisioning without policy compliance checks; it is a policy-based remediation, not a native auto-provisioning feature of Defender for Cloud. Option D is wrong because Azure Automation State Configuration is used for managing PowerShell DSC configurations and ensuring VM state compliance, not for automatically installing the Log Analytics agent for security log collection.

58
MCQmedium

A company has Azure AD Identity Protection enabled. The security team wants to automatically block sign-ins that are detected as coming from a known malicious IP address. They have created a Conditional Access policy and assigned it to all users. Which configuration should they add to the policy to trigger the block based on Identity Protection risk?

A.Add a condition for 'Sign-in risk' set to 'High' and a grant control of 'Block access'.
B.Add a condition for 'Locations' and specify the known malicious IP ranges as 'Blocked locations'.
C.Add a condition for 'User risk' set to 'High' and a grant control of 'Require multi-factor authentication'.
D.Add a condition for 'Device state' set to 'Not compliant' and a grant control of 'Block access'.
AnswerA

In Azure AD Identity Protection, a sign-in from a known malicious IP is one of the real-time sign-in risk detections that raises the sign-in risk level to High. A Conditional Access policy with the 'Sign-in risk' condition set to High and a grant control of 'Block access' enforces a block on that specific risky sign-in, exactly meeting the requirement. This is the correct risk-based control because it relies on Identity Protection's detection rather than a static list.

Why this answer

Identity Protection detects sign-ins from known malicious IP addresses and assigns a 'Sign-in risk' level (e.g., High). By adding a condition for 'Sign-in risk' set to 'High' and a grant control of 'Block access', the Conditional Access policy will automatically block those sign-ins. This directly uses Identity Protection's risk detection to enforce the block without needing to manually maintain IP address lists.

Exam trap

The trap here is that candidates often confuse 'Sign-in risk' (based on the sign-in event's characteristics like IP) with 'User risk' (based on user account compromise likelihood), leading them to incorrectly choose Option C or to think that manually listing IPs in Locations (Option B) is the correct approach.

How to eliminate wrong answers

Option B is wrong because specifying known malicious IP ranges as 'Blocked locations' in the Locations condition would require manual maintenance of IP lists and does not leverage Identity Protection's dynamic risk detection; it also does not use the 'Sign-in risk' condition. Option C is wrong because 'User risk' is based on user behavior patterns (e.g., leaked credentials), not on the IP address of the sign-in, and 'Require multi-factor authentication' does not block access. Option D is wrong because 'Device state' set to 'Not compliant' checks device compliance status, not the IP address or sign-in risk, and is unrelated to Identity Protection's malicious IP detection.

59
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) to manage the 'Security Administrator' role. They want to require that when a user activates this role, they must provide a support ticket number and a brief justification. Additionally, the activation should have a maximum duration of 4 hours. Which PIM role setting should they configure?

A.Require approval
B.Require MFA
C.Require justification on activation
D.Require Azure AD Identity Protection
AnswerC

This setting, often labeled 'Require justification' in PIM role settings, makes the justification text box mandatory during role activation. When enabled, the user must type a reason (and typically a support ticket number, depending on the ticketing requirement) before the activation request is submitted, and this value is then recorded in the PIM audit log. It directly satisfies the business requirement to enforce entering a ticket number and justification; activation duration is configured separately and does not affect this enforcement.

Why this answer

The 'Require justification on activation' setting in Azure AD PIM allows you to mandate that users provide a support ticket number and a brief justification when activating a role. This setting enforces the collection of business-specific details during activation, which aligns with the requirement. The maximum activation duration of 4 hours is configured separately via the 'Activation maximum duration' setting, not through justification.

Exam trap

The trap here is that candidates confuse 'Require justification on activation' with 'Require approval', mistakenly thinking that a support ticket number implies an approval workflow, but justification is a mandatory input field, not an approval step.

How to eliminate wrong answers

Option A is wrong because 'Require approval' enforces a workflow where a designated approver must approve the activation request, which is not the same as requiring a support ticket number and justification; it adds an approval step rather than a mandatory input field. Option B is wrong because 'Require MFA' enforces multi-factor authentication during activation, which addresses security verification but does not collect a support ticket number or justification. Option D is wrong because 'Require Azure AD Identity Protection' is not a valid PIM role setting; Azure AD Identity Protection is a separate service for risk-based policies and does not apply to PIM activation requirements.

60
MCQeasy

A security analyst uses Microsoft Defender for Cloud. They want to view a list of all security recommendations for their Azure subscription, prioritized by their potential impact. Which Defender for Cloud dashboard should they use?

A.Secure Score
B.Regulatory Compliance
C.Inventory
D.Workload protections
AnswerA

The Secure Score blade in Microsoft Defender for Cloud is specifically designed as a prioritized, actionable list of security recommendations. Each recommendation is shown with its potential score impact, so you can see how many points you gain by remediating it, and the list is sorted to highlight the highest-impact actions first. Because it consolidates all recommendations from applied security policies and weights them by severity and resource health, it directly answers the analyst's need to prioritize remediation work.

Why this answer

The Secure Score dashboard in Microsoft Defender for Cloud provides a prioritized list of security recommendations based on their potential impact on your overall security posture. Each recommendation is assigned a score contribution, allowing you to focus on the actions that will most improve your secure score. This directly matches the requirement to view recommendations prioritized by impact.

Exam trap

The trap here is that candidates often confuse the Secure Score dashboard with the Regulatory Compliance dashboard, thinking compliance standards inherently prioritize recommendations, but Secure Score is the only dashboard that explicitly ranks recommendations by their potential impact on your security score.

How to eliminate wrong answers

Option B (Regulatory Compliance) is wrong because it focuses on compliance with specific standards (e.g., SOC 2, ISO 27001) and does not prioritize recommendations by impact on secure score. Option C (Inventory) is wrong because it lists all resources in your Azure environment but does not provide security recommendations or prioritization. Option D (Workload protections) is wrong because it shows alerts and threats for specific workloads (e.g., servers, databases) rather than a prioritized list of security recommendations.

61
MCQeasy

A security team uses Microsoft Sentinel. They have created a playbook in Azure Logic Apps that automatically isolates a compromised VM by modifying a network security group. They want the playbook to run automatically whenever an incident of type 'VM Isolation' is created. Which Microsoft Sentinel feature should they use to trigger the playbook automatically?

A.Automation rules.
B.Scheduled analytics rules.
C.Fusion rules.
D.Workbooks.
AnswerA

Automation rules are the correct mechanism in Microsoft Sentinel for incident-centric orchestration. They allow you to define trigger conditions based on incident properties such as severity, status, title, or tactic, and then run playbooks, change incident status, assign ownership, add tasks, or apply tags whenever an incident is created or updated. This provides a single, consistent automation pipeline for incident management rather than tying actions to the specific detection that generated the alert.

Why this answer

Automation rules in Microsoft Sentinel are designed to trigger automated responses, such as running a playbook, when an incident is created or updated. In this scenario, the rule can be configured to match incidents of type 'VM Isolation' and automatically execute the Logic Apps playbook to isolate the compromised VM. This is the correct feature for incident-triggered automation without requiring a separate analytics rule.

Exam trap

The trap here is that candidates often confuse automation rules with analytics rules, thinking that a scheduled query rule is needed to trigger a playbook, but automation rules are the dedicated feature for incident-based automation without requiring a separate alert generation rule.

How to eliminate wrong answers

Option B (Scheduled analytics rules) is wrong because they generate alerts based on periodic queries of log data, not directly trigger playbooks on incident creation; they can be used with automation rules but are not the trigger themselves. Option C (Fusion rules) is wrong because they are a correlation engine that combines multiple alerts into a single incident using machine learning, not a mechanism to trigger playbooks automatically. Option D (Workbooks) is wrong because they are for visualizing and analyzing data, not for triggering automated responses or playbooks.

62
MCQhard

A company uses Azure AD Identity Protection. They want to automatically block sign-ins that have a high user risk level, but only for users in the 'Finance' department. They also want to require MFA for medium user risk level for all users (including Finance) when sign-in risk is not blocked. They have already created a Conditional Access policy for the Finance department that has a condition of 'User risk level: High' and a grant control of 'Block access'. What additional configuration is needed to also require MFA for all users with medium user risk?

A.Create a second Conditional Access policy targeting all users with condition 'User risk level: Medium' and grant control 'Require multi-factor authentication'
B.Modify the existing policy to include 'User risk level: Medium' and change the grant control to 'Require multi-factor authentication'
C.Use Identity Protection's 'User risk policy' instead of Conditional Access
D.Create a new Conditional Access policy with condition 'User risk level: Medium' and grant control 'Block access'
AnswerA

A separate policy for medium user risk applied to all users will require MFA when medium risk is detected. The existing policy will continue to block Finance users with high risk. Policy evaluation is not mutually exclusive; the block takes precedence for high risk, and the MFA requirement applies for medium risk.

Why this answer

Azure AD Conditional Access policies are evaluated independently, and a separate policy is needed to require MFA for medium user risk across all users. The existing policy blocks high-risk sign-ins for Finance only, but does not address medium risk for any user. Creating a second policy targeting all users with 'User risk level: Medium' and grant control 'Require multi-factor authentication' satisfies the requirement without conflicting with the existing block policy, as Conditional Access policies are combined (unless explicitly excluded).

Exam trap

The trap here is that candidates often think a single policy can handle multiple risk levels with different grant controls, but Conditional Access policies enforce a single grant control per policy, so separate policies are required for different risk level actions.

How to eliminate wrong answers

Option B is wrong because modifying the existing policy to include 'User risk level: Medium' and changing the grant control to 'Require multi-factor authentication' would remove the block for high-risk Finance users, violating the requirement to block high-risk sign-ins for Finance. Option C is wrong because Identity Protection's 'User risk policy' is a legacy, tenant-wide risk-based policy that cannot target specific departments like Finance; it also does not support the granularity of Conditional Access for combining risk levels with other conditions. Option D is wrong because creating a new policy with 'User risk level: Medium' and grant control 'Block access' would block medium-risk users instead of requiring MFA, which contradicts the requirement to require MFA for medium risk.

63
MCQmedium

A company uses Microsoft Defender for Cloud. They have assigned a custom regulatory compliance initiative that includes policies to enforce encryption on storage accounts and SQL databases. They want to automatically remediate any non-compliant resources that are discovered, without manual intervention. Which feature should they configure?

A.Enable 'Auto provisioning' for the relevant extensions
B.Enable 'Remediation' for each policy assignment in the custom initiative
C.Enable 'Just-in-time (JIT) VM access'
D.Enable 'Workflow automation' to trigger a Logic App when non-compliance is detected
AnswerB

Azure Policy's remediation feature is the native mechanism for automatically fixing resources that are non-compliant with policies that use the DeployIfNotExists or Modify effects. When you assign a custom initiative, you can enable remediation for each assignment, which creates a managed identity and allows the policy engine to run remediation tasks during evaluation cycles. These tasks deploy the required template or modify the resource configuration—such as enabling disk encryption—directly, without manual intervention. This is the correct option because it uses the built-in, continuously-running remediation engine tied to policy assignments.

Why this answer

The 'Remediation' setting on a policy assignment in Azure Policy (used by Defender for Cloud custom initiatives) creates a managed identity and a remediation task that automatically applies the required encryption configuration to non-compliant resources. This ensures that when a storage account or SQL database is found without encryption, the policy engine triggers a deployment to enforce encryption without manual intervention.

Exam trap

The trap here is that candidates confuse 'Auto provisioning' (which installs agents for data collection) with automatic remediation of compliance policies, or they assume 'Workflow automation' directly fixes non-compliance when it only triggers a notification or custom action.

How to eliminate wrong answers

Option A is wrong because 'Auto provisioning' in Defender for Cloud installs extensions (like the Log Analytics agent) on VMs to collect security data, not to remediate encryption policies on storage or SQL resources. Option C is wrong because 'Just-in-time (JIT) VM access' controls network access to VMs by opening ports temporarily, which is unrelated to enforcing encryption compliance on storage accounts and SQL databases. Option D is wrong because 'Workflow automation' triggers a Logic App when non-compliance is detected, but it does not automatically remediate the resource; it only sends notifications or runs custom actions, requiring additional setup to perform remediation.

64
MCQmedium

A company wants to use Microsoft Defender for Cloud to continuously assess their Azure resources against the Microsoft cloud security benchmark (MCSB). They need to view the current compliance score and specific recommendations for failing controls. Which feature in Defender for Cloud should they use?

A.Security Policy
B.Regulatory Compliance dashboard
C.Secure Score
D.Workload Protections
AnswerB

The Regulatory Compliance dashboard is the dedicated reporting interface within Microsoft Defender for Cloud that continuously aggregates assessment results for assigned standards like MCSB. It provides a compliance score per standard, a per-control breakdown of pass and fail status, and drill-down details for each recommendation that impacts a control. This dashboard directly answers the requirement to assess compliance against a chosen regulatory framework by showing exactly which controls are not met and why. It is the correct tool because it maps Azure Security benchmark recommendations to regulatory compliance controls and offers a visual, actionable score.

Why this answer

The Regulatory Compliance dashboard in Microsoft Defender for Cloud is specifically designed to assess resources against compliance standards like the Microsoft cloud security benchmark (MCSB). It provides a current compliance score, a breakdown of failing controls, and actionable recommendations to remediate those controls, directly meeting the company's requirement.

Exam trap

The trap here is confusing Secure Score (which shows overall security posture) with Regulatory Compliance (which shows adherence to a specific benchmark), leading candidates to pick Secure Score when the question explicitly asks for compliance against MCSB.

How to eliminate wrong answers

Option A is wrong because Security Policy defines the rules and initiatives applied to resources (e.g., allowed VM SKUs), but it does not display a compliance score or specific failing controls against a benchmark. Option C is wrong because Secure Score aggregates security posture based on security recommendations, but it is not tied to a specific compliance standard like MCSB and does not show per-control compliance status. Option D is wrong because Workload Protections focuses on advanced threat detection and protection for workloads (e.g., servers, databases), not on compliance assessment against benchmarks.

65
MCQhard

An analyst investigates a Defender for Cloud alert for suspicious process execution on a VM. Which next step best preserves evidence while enabling deeper endpoint investigation?

A.Delete the VM immediately to stop the process
B.Pivot to Microsoft Defender for Endpoint device timeline and isolate the device if containment is required
C.Disable all analytics rules in Sentinel
D.Rotate every subscription key before reviewing the process tree
AnswerB

Defender for Endpoint's device timeline preserves the forensic process tree and related events while allowing deeper investigation, and device isolation contains the threat without destroying volatile evidence. This satisfies the requirement to preserve evidence and enable endpoint-level analysis before remediation.

Why this answer

Pivoting to the Microsoft Defender for Endpoint device timeline allows the analyst to investigate the suspicious process execution in a forensically sound manner without disrupting the live environment. Isolating the device from the network, if needed, contains the threat while preserving volatile evidence such as running processes, memory, and registry state. This approach aligns with incident response best practices and leverages Defender for Endpoint's deep endpoint visibility.

Exam trap

The trap here is that candidates may confuse immediate containment with evidence preservation, mistakenly choosing to delete or disable resources instead of using the platform's native investigation and isolation capabilities.

How to eliminate wrong answers

Option A is wrong because deleting the VM immediately destroys all volatile evidence (memory, running processes, network connections) and prevents any forensic analysis or root cause determination. Option C is wrong because disabling analytics rules in Microsoft Sentinel does not preserve evidence or aid investigation; it only stops future alert generation, potentially allowing the threat to propagate undetected. Option D is wrong because rotating subscription keys is a credential hygiene action unrelated to endpoint investigation and does not preserve process execution evidence or enable containment.

66
MCQhard

A Sentinel rule using a threat intelligence table fires on stale indicators that expired last week. What should be added to the query?

A.A union with Usage
B.A sort by Description
C.A project-away of ConfidenceScore
D.A filter for active indicators whose expiration time is in the future
AnswerD

The correct query filters the ThreatIntelligenceIndicator table to rows where the indicator's expiration time is later than the current time (ExpirationDateTime > now()) and where the indicator's action status is active, thereby including only indicators that are currently valid and in use. This ensures the rule matches only threat intelligence that is still relevant, avoiding alerts from indicators that have expired or been deactivated. In Sentinel you would typically combine this filter with the TI map data and set the rule's query to evaluate at runtime using now(), so the freshness is automatically enforced.

Why this answer

The rule fires on stale indicators because the query lacks a filter to exclude expired threat intelligence entries. Adding a filter for active indicators whose expiration time is in the future ensures that only current, valid indicators trigger the rule, preventing false positives from outdated data.

Exam trap

The trap here is that candidates may think removing a column (project-away) or sorting data addresses the root cause of stale data, rather than recognizing that a row-level filter is required to exclude expired indicators.

How to eliminate wrong answers

Option A is wrong because a union with Usage would combine data from the Usage table, which tracks billing or resource consumption, not threat intelligence expiration, and does not filter out stale indicators. Option B is wrong because sorting by Description merely reorders results without excluding expired indicators; it does not affect which rows are returned. Option C is wrong because projecting away ConfidenceScore removes a column but does not filter rows; the query would still return stale indicators regardless of confidence score.

67
Multi-Selecthard

A Defender for Cloud alert indicates possible credential theft on a VM. Which two response actions are sensible early containment steps?

Select 2 answers
A.Isolate the affected endpoint or restrict network access if business impact allows
B.Delete all Log Analytics workspaces
C.Reset or revoke suspected compromised credentials
D.Disable Microsoft Defender for Endpoint onboarding
AnswersA, C

Isolating the endpoint or restricting its network access severs the attacker's command-and-control and lateral movement paths, containing credential theft before persistence or exfiltration. This preserves forensic evidence on the VM while business impact remains acceptable.

Why this answer

Option A is correct because isolating the affected endpoint (for example, via Microsoft Defender for Endpoint's 'Isolate device' action) or otherwise restricting its network access stops an attacker from moving laterally or exfiltrating data while the investigation proceeds, and it is a standard early containment step when business impact permits. Option C is correct because credential theft means the attacker may hold valid account secrets, so resetting passwords and revoking tokens, sessions, or refresh tokens (for example, via Microsoft Entra ID revoke sessions or password reset) invalidates the stolen credentials and cuts off the attacker's access. Option B is not appropriate because deleting Log Analytics workspaces destroys the very telemetry and audit evidence needed to investigate the alert and would not contain the threat.

Option D is not appropriate because disabling Defender for Endpoint onboarding removes the endpoint detection and response capability that is essential for monitoring, investigating, and remediating the compromised VM.

Exam trap

The trap here is that candidates may confuse 'containment' with 'remediation' and choose to delete workspaces or disable security tools, which are destructive or counterproductive actions, rather than the correct containment step of network isolation.

68
MCQhard

A Sentinel analyst needs to preserve investigation notes, related entities, and ownership while escalating a case to another analyst. Which object should be updated?

A.A watchlist item
B.A workbook parameter
C.A data connector
D.The Sentinel incident
AnswerD

The Microsoft Sentinel incident is the correct place to preserve investigation notes because incidents have a dedicated comments section and audit history that persist with the case. Each comment is timestamped and attributed to the analyst, creating an immutable, chronological record of observations, hypotheses, and actions taken. This documentation is retained as part of the incident's metadata, is visible to all team members investigating the incident, and can be exported or queried via APIs for compliance or post-incident review. Storing notes on the incident directly ties the documentation to the investigation's lifecycle, ensuring no context is lost when the incident is closed or reopened.

Why this answer

The Sentinel incident object is the correct entity to update because it serves as the central container for investigation notes, related entities, and ownership assignments during case escalation. Updating the incident preserves the full investigation context—including comments, tags, and assigned owner—ensuring seamless handoff between analysts without data loss.

Exam trap

The trap here is that candidates confuse operational artifacts (watchlists, workbooks, connectors) with the incident object that actually holds case-specific metadata, leading them to select a static or non-persistent option instead of the dynamic incident record.

How to eliminate wrong answers

Option A is wrong because a watchlist item is a static collection of data (e.g., IP addresses or hashes) used for correlation and alerting, not for storing investigation notes or ownership metadata. Option B is wrong because a workbook parameter is a configurable input for visualizations and queries, not a persistent object that tracks case ownership or notes. Option C is wrong because a data connector defines the source and ingestion pipeline for log data; it has no role in storing investigation artifacts or managing case ownership.

69
MCQmedium

A company uses Microsoft Defender for Cloud to monitor security alerts. They receive an alert about a compromised virtual machine and want to automatically execute a playbook that isolates the VM by modifying the network security group. Which Defender for Cloud feature should they use to create this automated response?

A.Workflow automation
B.Security policy
C.Alert suppression
D.Continuous export
AnswerA

Workflow automation is the correct answer because it directly enables an automated response to a security alert. In Microsoft Defender for Cloud, you can create a workflow automation rule that triggers an Azure Logic App when a specific security alert is generated. The Logic App can then execute an automatic isolation action on the affected Virtual Machine, for instance by using an Azure SQL or Resource Manager connector to modify network security groups or apply an Azure Policy. This is the only option that provides a built-in event-driven mechanism to take a protective action without human intervention.

Why this answer

Workflow automation in Microsoft Defender for Cloud allows you to define automated responses to security alerts by triggering Azure Logic Apps. In this scenario, you would create a Logic App that modifies the network security group (NSG) to isolate the compromised VM, and then configure a workflow automation rule to run that Logic App whenever the specific alert is triggered. This provides a no-code, event-driven remediation without manual intervention.

Exam trap

The trap here is that candidates often confuse 'Continuous export' (which sends data to external systems) with 'Workflow automation' (which executes a playbook), assuming any export can trigger a response, but Continuous export only streams data and does not invoke Logic Apps directly.

How to eliminate wrong answers

Option B (Security policy) is wrong because security policies define compliance and configuration requirements (e.g., enforcing encryption or vulnerability assessments), not automated response actions to alerts. Option C (Alert suppression) is wrong because it only hides or dismisses alerts based on rules (e.g., false positives), it does not execute any remediation or playbook. Option D (Continuous export) is wrong because it streams alert data to Event Hubs, Log Analytics, or Azure Monitor for external processing or archiving, but it does not directly trigger a playbook or modify NSGs.

70
MCQmedium

A company uses Azure AD Conditional Access. They need to restrict access to a cloud application such that users with unmanaged devices can only view data but cannot download it. Which Conditional Access session control should they enable?

A.Sign-in frequency
B.Use Conditional Access App Control
C.Session persistence
D.Application consent policy
AnswerB

Conditional Access App Control, also known as session control, integrates with Microsoft Defender for Cloud Apps by routing the user's session through a reverse proxy in real time. This allows administrators to create session policies that block or restrict specific activities, such as downloading, uploading, copying, or printing files, based on conditions like user risk or location. For the requirement to restrict data downloads, this is the correct and only option among those listed that provides true session-level enforcement.

Why this answer

Conditional Access App Control (Microsoft Defender for Cloud Apps) provides session-level controls that can enforce restrictions like 'Block Download' based on device compliance. This allows administrators to apply policies that restrict data exfiltration from unmanaged devices while still permitting read-only access to the cloud application.

Exam trap

The trap here is confusing session controls (like sign-in frequency or persistence) with app-level data protection controls, leading candidates to pick a control that manages authentication behavior rather than data exfiltration.

How to eliminate wrong answers

Option A is wrong because Sign-in frequency controls how often a user must re-authenticate, not the ability to download data. Option C is wrong because Session persistence controls whether a browser session remains signed in after the browser is closed, not data download restrictions. Option D is wrong because Application consent policy governs which applications can request permissions to access organizational data, not session-level data handling restrictions.

71
Drag & Dropmedium

Drag and drop the steps to configure Azure Disk Encryption for a Windows VM using Azure Key Vault into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for configuring Azure Disk Encryption for a Windows VM using Azure Key Vault is to first create or configure the Key Vault with soft-delete and purge protection, then set the Key Vault access policy to grant the Azure Disk Encryption service the required permissions, and finally enable disk encryption on the VM specifying the Key Vault and key. This order ensures that all prerequisites are met, preventing errors during the encryption process.

72
MCQmedium

A company uses Azure AD B2B collaboration to invite external partner users to collaborate on a project. The security team wants to ensure that when a partner user's account is disabled in their home Azure AD tenant, the user should immediately lose access to the company's resources, even if the user had a valid session token. Which configuration should they implement in cross-tenant access settings?

A.Configure cross-tenant access settings to trust the user's account status from the home tenant.
B.Configure external collaboration settings to restrict B2B users to specific apps.
C.Assign a conditional access policy that requires device compliance for B2B users.
D.Enable Azure AD Identity Protection for B2B users.
AnswerA

Enabling 'Trust user's account' in Azure AD cross-tenant access inbound settings causes Azure AD to call the user's home tenant directory during each interactive token acquisition to verify the accountEnabled attribute. If the account is disabled or deleted in the home tenant, the sign-in is blocked immediately, regardless of any previously issued tokens. This is the only option that directly and continuously checks the external account's status, not just policies or device state.

Why this answer

Configuring cross-tenant access settings to trust the user's account status from the home tenant enables Azure AD to evaluate the external user's account state (enabled/disabled) in their home tenant at each authentication. When the partner user's account is disabled in their home tenant, Azure AD will deny access even if a valid session token exists, because the token's validity is rechecked against the home tenant's account status via the cross-tenant trust policy.

Exam trap

The trap here is that candidates often confuse session token revocation with conditional access policies or app restrictions, failing to realize that only the cross-tenant trust setting directly ties the external user's access to their home tenant's account status, enabling immediate revocation without waiting for token expiry.

How to eliminate wrong answers

Option B is wrong because restricting B2B users to specific apps controls which applications they can access, not whether their account status is honored from the home tenant; it does not enforce immediate revocation when the account is disabled. Option C is wrong because a conditional access policy requiring device compliance checks the device state, not the user account status in the home tenant; it cannot detect or react to a disabled account in the external tenant. Option D is wrong because enabling Azure AD Identity Protection for B2B users provides risk-based conditional access (e.g., risky sign-ins), but it does not directly trust the home tenant's account disabled state; it relies on Microsoft's risk signals, not the partner tenant's directory status.

73
MCQeasy

A security analyst uses Microsoft Sentinel. They want to create a scheduled analytics rule that runs every hour and queries Azure Activity logs to detect deployment of VMs in non-approved regions. They want to generate an incident automatically when suspicious activity is found. Which configuration is required to automatically create an incident?

A.Enable 'Create incident from alerts triggered by this rule' in the Incident settings
B.Configure the 'Alert details' section with the appropriate severity and description
C.Define entity mapping in the 'Entity mapping' tab
D.Connect Azure Activity log to Sentinel via Event Hub
AnswerA

The 'Create incident from alerts triggered by this rule' toggle resides in the Incident settings tab of the analytics rule wizard in Microsoft Sentinel. When enabled, every alert generated by the rule is automatically fed into the incident creation pipeline, where alert grouping rules determine whether alerts are merged into a single incident or create separate ones. This is the definitive switch that controls whether the rule produces incidents at all; without it, alerts are stored in the Sentinel alerts table but no incident is created.

Why this answer

The 'Create incident from alerts triggered by this rule' setting in the Incident settings tab is the specific toggle that instructs Microsoft Sentinel to automatically generate a security incident whenever the scheduled analytics rule fires an alert. Without this setting enabled, the rule will only produce raw alerts that must be manually triaged or routed through a separate automation rule to become incidents. This is the direct configuration required for automatic incident creation from a scheduled query rule.

Exam trap

The trap here is that candidates often confuse the 'Alert details' configuration (which only sets alert metadata) with the incident creation toggle, assuming that defining severity and description automatically generates an incident, when in fact a separate explicit setting is required.

How to eliminate wrong answers

Option B is wrong because configuring the 'Alert details' section (severity and description) only defines the metadata of the alert itself, not the automatic creation of an incident from that alert. Option C is wrong because entity mapping enriches alerts with entity types (e.g., IP, host) for correlation and investigation, but does not control whether an incident is automatically generated. Option D is wrong because connecting Azure Activity log to Sentinel via Event Hub is a data ingestion method, not a configuration for incident creation; the log source must already be connected for the rule to query it, but that step is separate from the incident creation setting.

74
MCQmedium

A company wants to identify excessive permissions across Azure, AWS, and GCP identities. Which Microsoft security capability is designed for cloud infrastructure entitlement management?

A.Azure Monitor metrics
B.Microsoft Purview eDiscovery
C.Azure Front Door WAF
D.Microsoft Entra Permissions Management
AnswerD

Microsoft Entra Permissions Management is the correct CIEM (Cloud Infrastructure Entitlement Management) tool because it continuously discovers every identity, role assignment, and permission in Azure, AWS, and GCP, then applies analytics to separate used permissions from unused ones. It calculates a 'permission creep index,' surfaces over-privileged or dormant accounts, and supports remediation actions such as permission right-sizing, on-demand access, and just-in-time elevation. That is exactly the capability needed to identify excessive permissions across all three clouds.

Why this answer

Microsoft Entra Permissions Management is a Cloud Infrastructure Entitlement Management (CIEM) solution that provides visibility into permissions assigned to identities across multi-cloud environments (Azure, AWS, GCP). It helps detect and remediate excessive, unused, or risky permissions by analyzing identity activity and entitlement data, enabling least-privilege access control.

Exam trap

The trap here is that candidates may confuse Azure Monitor (a monitoring tool) with a security management tool, or assume a WAF or eDiscovery solution can handle identity permissions, when only a dedicated CIEM like Entra Permissions Management is designed for multi-cloud entitlement visibility.

How to eliminate wrong answers

Option A is wrong because Azure Monitor metrics collect and analyze telemetry data (e.g., CPU usage, request rates) from Azure resources, not identity permissions across clouds. Option B is wrong because Microsoft Purview eDiscovery focuses on legal discovery and compliance searches for content in Microsoft 365, not on managing cloud infrastructure entitlements. Option C is wrong because Azure Front Door WAF is a web application firewall that protects HTTP/HTTPS traffic from common web exploits, not a tool for identity permission analysis.

75
MCQmedium

A Defender for Cloud recommendation requires enabling private endpoints for a storage account. Which security risk is primarily reduced?

A.VM disk fragmentation
B.Public internet exposure of the storage service endpoint
C.Unauthorized changes to Azure AD users
D.Excessive Log Analytics ingestion
AnswerB

Correct. Private endpoints eliminate public internet access to the storage account, directly reducing the risk of unauthorized network-based attacks via the public endpoint.

Why this answer

Enabling private endpoints for a storage account connects it to an Azure Virtual Network over a private IP address, eliminating access from the public internet. This directly reduces the risk of public internet exposure of the storage service endpoint (Option B). The primary risk addressed is network-level exposure, not identity-related risks like unauthorized changes to Azure AD users (Option C).

While private endpoints can contribute to a defense-in-depth strategy, the most immediate and primary risk reduction is the removal of public network accessibility.

Exam trap

The trap is that candidates may incorrectly associate private endpoints with identity protection (Option C) because private endpoints limit network access, which could indirectly reduce identity attacks. However, the question asks for the primary risk reduced, which is specifically public internet exposure (Option B). Private endpoints are a network security control, not an identity control.

How to eliminate wrong answers

Option A is wrong because VM disk fragmentation is a performance issue related to virtual hard disk (VHD) storage and I/O operations, not a security risk that private endpoints address. Option B is wrong because while private endpoints do reduce public internet exposure, the question asks which risk is primarily reduced, and the correct answer is unauthorized changes to Azure AD users, which is not directly related to private endpoints for storage accounts. Option D is wrong because excessive Log Analytics ingestion is a cost and data volume management concern, not a security risk that private endpoints mitigate.

Page 1 of 2 · 140 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Manage identity and access questions.