Courseiva

CCNA Manage identity and access Questions

65 of 140 questions · Page 2/2 · Manage identity and access · Answers revealed

76
MCQmedium

A security team uses Microsoft Defender for Cloud to monitor Azure virtual machines. They want to automatically install a specific endpoint protection solution on all Windows VMs that are currently missing it, without manual intervention. The solution is not integrated natively with Defender for Cloud. Which feature should they use?

A.Enable the 'Endpoint protection' recommendation and use the 'Fix' option
B.Create an Azure Policy 'DeployIfNotExists' assignment that installs the endpoint protection extension on VMs missing it
C.Configure adaptive application controls to allow the endpoint protection software
D.Enable just-in-time VM access for the VMs
AnswerB

Create an Azure Policy definition using the DeployIfNotExists effect that targets VMs (or VM extensions) where the specific endpoint protection extension is absent. When the policy evaluates a VM and the condition is true, it deploys a linked ARM template, which installs the vendor's protection extension using the assignment's managed identity. This approach works for non-native, third-party solutions because you provide the extension template, and it can be used both for automatic evaluation of new VMs and for a remediation task to cover already-running VMs. The policy assignment must have a managed identity with Contributor (or equivalent) permissions on the target scope.

Why this answer

Azure Policy's 'DeployIfNotExists' effect can automatically deploy a custom endpoint protection extension to Windows VMs that are missing it, even if the solution is not natively integrated with Defender for Cloud. This allows the security team to enforce compliance by installing the specific third-party endpoint protection agent via a policy assignment, without manual intervention.

Exam trap

The trap here is that candidates often assume Defender for Cloud's 'Fix' option can deploy any endpoint protection solution, but it only supports solutions that are natively integrated and listed in the Defender for Cloud dashboard.

How to eliminate wrong answers

Option A is wrong because the 'Endpoint protection' recommendation in Defender for Cloud and its 'Fix' option only work with endpoint protection solutions that are natively integrated (e.g., Microsoft Defender Antivirus, Trend Micro, Symantec); it cannot deploy a non-integrated, custom solution. Option C is wrong because adaptive application controls are a whitelisting feature that controls which applications can run on a VM, not a mechanism to install or deploy software. Option D is wrong because just-in-time VM access manages network access to management ports (e.g., RDP, SSH) to reduce attack surface, not the installation of endpoint protection agents.

77
MCQhard

A security operations team uses Microsoft Sentinel. They have a scheduled analytics rule that generates an incident when a user signs in from an unusual location. They want to automatically assign the incident to the 'Security Engineering' team and set its severity to 'High' when it is created. Which feature should they use?

A.Automation rules
B.Playbooks
C.Incident settings in analytics rule
D.Workbooks
AnswerA

Automation rules in Microsoft Sentinel run immediately on incident creation, letting you assign the owner to 'Security Engineering' and set severity to 'High' without playbook latency. Unlike analytics rule configuration, they act post-creation, satisfying the requirement to modify incidents automatically at creation time.

Why this answer

Automation rules in Microsoft Sentinel allow you to centrally manage the automated handling of incidents, including assigning them to a specific team and setting their severity. When a scheduled analytics rule generates an incident, an automation rule can trigger on incident creation to perform these actions without requiring a playbook or manual intervention.

Exam trap

The trap here is that candidates often confuse playbooks with automation rules, thinking that playbooks are required for any automated action, when in fact automation rules are the native, simpler mechanism for assignment and severity changes without needing Logic Apps.

How to eliminate wrong answers

Option B is wrong because playbooks are collections of actions based on Azure Logic Apps that run in response to alerts or incidents, but they are typically used for more complex, multi-step orchestration and require additional configuration; automation rules are the simpler, built-in feature for direct assignment and severity changes. Option C is wrong because incident settings within an analytics rule only allow you to configure group-related settings (e.g., alert grouping) and entity mapping, not post-creation actions like assignment or severity override. Option D is wrong because workbooks are interactive dashboards for visualizing data and reports, not for automating incident response actions.

78
MCQhard

A compliance team wants evidence that Azure resources are evaluated against the Microsoft Cloud Security Benchmark. Which Defender for Cloud area should they use?

A.Regulatory compliance and security policy assignments
B.Microsoft Entra app consent settings
C.Azure Firewall DNAT rules
D.Log Analytics saved searches only
AnswerA

Regulatory compliance and security policy assignments are the primary mechanism in Azure for evidence that resources comply with standards. Azure Policy initiative definitions (e.g., CIS Microsoft Azure Foundations Benchmark, NIST SP 800-53, HIPAA) continuously evaluate resource configuration against required controls and report compliance states per resource. Defender for Cloud's regulatory compliance blade aggregates these policy assignments into a dashboard showing pass/fail status, making them the direct evidence source for a compliance team.

Why this answer

The Regulatory compliance dashboard in Microsoft Defender for Cloud provides continuous monitoring of Azure resources against the Microsoft Cloud Security Benchmark (MCSB). It maps built-in policy assignments to compliance controls, generates a compliance score, and offers remediation steps. This is the designated area for evidence of MCSB evaluation.

Exam trap

The trap here is that candidates may confuse the Regulatory compliance dashboard with general log querying or network security controls, overlooking that the MCSB is specifically enforced through Azure Policy initiatives within Defender for Cloud's compliance monitoring.

How to eliminate wrong answers

Option B is wrong because Microsoft Entra app consent settings manage user consent for application permissions, not compliance evaluation against security benchmarks. Option C is wrong because Azure Firewall DNAT rules configure inbound network address translation for traffic, unrelated to compliance assessment. Option D is wrong because Log Analytics saved searches are used for querying log data, not for providing a structured compliance dashboard against the MCSB.

79
MCQmedium

A security team uses Microsoft Sentinel. They want to automatically block a user's account in Azure AD when a high-severity incident is created in Sentinel indicating the user's credentials are compromised. Which automation feature should they use?

A.Create a playbook that uses the Azure AD connector to block the user, and associate it with an automation rule for high-severity incidents.
B.Configure the analytic rule for credential compromise to include a script that blocks the user as part of the rule.
C.Use a workbook to monitor incidents and manually block users.
D.Enable the 'User blocking' feature directly in the Microsoft Sentinel settings for all high-severity incidents.
AnswerA

Microsoft Sentinel playbooks are Logic Apps-based workflows that execute response actions. By using the Azure AD (Entra ID) connector, a playbook can call a user-blocking action such as disabling the user account via the 'Update user' or the dedicated 'Block user' action. Automation rules evaluate incident properties (e.g., severity, entity) and can automatically trigger the playbook when a high-severity incident is created, providing a fully automated containment response.

Why this answer

Microsoft Sentinel automation rules can trigger a playbook (an Azure Logic Apps workflow) when a high-severity incident is created. The playbook can use the Azure AD connector to call the Microsoft Graph API and block the user account, providing automated response to credential compromise without manual intervention.

Exam trap

The trap here is that candidates may think analytic rules can include scripts or that Sentinel has a native user-blocking toggle, but in reality, automated response requires a separate playbook triggered by an automation rule.

How to eliminate wrong answers

Option B is wrong because analytic rules in Sentinel define detection logic (KQL queries) and cannot contain scripts to perform actions like blocking users; actions are handled separately by automation rules and playbooks. Option C is wrong because workbooks are for visualization and reporting, not for automated response; they require manual monitoring and action, which does not meet the requirement for automatic blocking. Option D is wrong because Microsoft Sentinel does not have a built-in 'User blocking' feature in its settings; blocking users requires integration with Azure AD via a playbook or other external automation.

80
Multi-Selectmedium

A security engineer needs to collect custom application logs from Azure VMs using Azure Monitor Agent for Sentinel analysis. Which two components are required?

Select 2 answers
A.A Data Collection Rule that defines the custom log collection
B.A storage account configured for static website hosting
C.Association of the Data Collection Rule with the target machines
D.A Conditional Access policy requiring MFA
AnswersA, C

A Data Collection Rule defines which custom logs Azure Monitor Agent gathers, including the destination workspace and parsing logic. Without a DCR, the agent has no collection specification, making it an essential component for Sentinel ingestion.

Why this answer

Option A is correct because a Data Collection Rule (DCR) is the Azure Monitor Agent mechanism that defines what data to collect, including custom logs via a custom text or JSON log definition, and where to send it (e.g., a Log Analytics workspace used by Microsoft Sentinel). Option C is correct because a DCR must be associated with the target machines (through a DCR association on the VM or via Azure Policy/monitoring insights) for the Azure Monitor Agent to actually apply that collection configuration to those VMs. Option B is incorrect because a storage account configured for static website hosting is unrelated to log ingestion by Azure Monitor Agent; custom logs are sent to a Log Analytics workspace, not served as web content.

Option D is incorrect because Conditional Access policies govern user/identity sign-in access to resources and play no role in agent-based log collection from VMs.

Exam trap

The trap here is that candidates may confuse storage accounts (used for Azure Diagnostics extension or legacy agents) with the modern Azure Monitor Agent requirement, or mistakenly think Conditional Access policies are relevant to log ingestion.

81
MCQhard

A company has Azure AD Conditional Access policies that require multi-factor authentication (MFA) for all users accessing sensitive cloud apps. The security team wants to extend this protection by monitoring and controlling user activities within those applications (e.g., preventing data exfiltration during a session). Which Conditional Access session control should they implement?

A.Grant control: Require MFA
B.Session control: Use app enforced restrictions
C.Session control: Sign-in frequency
D.Session control: Conditional Access Application Control
AnswerD

Conditional Access Application Control is the correct session control because it integrates with Microsoft Defender for Cloud Apps to route sessions through a reverse proxy, enabling real-time monitoring and policy enforcement. Administrators can apply granular actions such as blocking downloads, restricting access, or applying data protection policies dynamically based on user and risk context. This provides the centralized, in-session activity monitoring and control that the scenario specifically requires.

Why this answer

Conditional Access Application Control (also known as Microsoft Defender for Cloud Apps session control) allows real-time monitoring and control of user activities within cloud apps, such as blocking downloads or preventing data exfiltration. This session control works by redirecting user traffic through Microsoft Defender for Cloud Apps as a reverse proxy, enabling granular policy enforcement during the session. The requirement specifically asks for monitoring and controlling activities inside the app, which goes beyond just requiring MFA at sign-in.

Exam trap

The trap here is that candidates confuse session controls that manage sign-in frequency or app-enforced restrictions with the more advanced session monitoring and data exfiltration prevention capabilities provided by Conditional Access Application Control, which is the only option that offers real-time in-app activity control.

How to eliminate wrong answers

Option A is wrong because Grant control: Require MFA is an access control that enforces multi-factor authentication at sign-in, but it does not provide any monitoring or control of user activities once the session is established. Option B is wrong because Session control: Use app enforced restrictions relies on the cloud app itself to enforce its own controls (e.g., SharePoint IP-based restrictions), but it does not offer the real-time session monitoring or data exfiltration prevention that Microsoft Defender for Cloud Apps provides. Option C is wrong because Session control: Sign-in frequency controls how often a user must reauthenticate during a session, which is a session lifetime control, not a mechanism to monitor or control in-app activities like downloads or copy-paste.

82
MCQhard

A security operations team uses Microsoft Sentinel. They have created a playbook that sends an email notification to the security team when a high-severity incident is created by a specific analytics rule named 'CriticalRDPAccess'. They want the playbook to trigger automatically only when the incident has severity 'High' AND the incident was created by the rule named 'CriticalRDPAccess'. Which automation rule configuration should they use?

A.Condition: Incident severity equals High; AND Incident rule name contains 'CriticalRDPAccess'. Action: Run playbook.
B.Condition: Incident severity equals High; OR Incident rule name equals 'CriticalRDPAccess'. Action: Run playbook.
C.Condition: Incident severity equals High; AND Incident rule name equals 'CriticalRDPAccess'. Action: Run playbook.
D.Condition: Incident severity in ['High', 'Critical']; AND Incident rule name equals 'CriticalRDPAccess'. Action: Run playbook.
AnswerC

This condition is correct because it uses `AND` to combine two precise constraints: the incident severity must be literally 'High', and the rule name must exactly equal 'CriticalRDPAccess' using the `equals` operator. This ensures that only High severity incidents generated by the specific analytics rule named CriticalRDPAccess will run the playbook, eliminating false positives from similarly named rules and other severity levels. The use of exact match is aligned with the Microsoft Sentinel documentation for automation rules.

Why this answer

The automation rule must use the AND operator to require both conditions—incident severity equals 'High' AND incident rule name equals 'CriticalRDPAccess'—to trigger the playbook. This ensures the playbook runs only when both criteria are met, matching the requirement exactly. Using 'contains' instead of 'equals' (as in Option A) would incorrectly match rules with 'CriticalRDPAccess' as a substring, potentially triggering on unintended rules.

Exam trap

The trap here is that candidates may confuse 'contains' with 'equals' for rule name matching, or incorrectly use OR instead of AND, leading to unintended playbook triggers for similar rule names or unrelated high-severity incidents.

How to eliminate wrong answers

Option A is wrong because 'Incident rule name contains' uses a substring match, which would trigger the playbook for any rule whose name includes 'CriticalRDPAccess' (e.g., 'CriticalRDPAccessV2'), not just the exact rule name. Option B is wrong because the OR operator means the playbook would trigger if either condition is true—e.g., any high-severity incident or any incident from the rule—violating the requirement for both conditions to be true. Option D is wrong because it includes 'Critical' in the severity list, which would trigger the playbook for critical-severity incidents as well, not just high-severity incidents as specified.

83
MCQeasy

A company uses Microsoft Defender for Cloud to manage the security posture of their Azure workloads. The compliance officer needs to generate a report that shows the current compliance status against the SOC 2 standard, including the pass/fail status of each control. Which feature in Defender for Cloud should they use?

A.Regulatory compliance dashboard
B.Inventory
C.Secure Score
D.Workbooks
AnswerA

The Regulatory compliance dashboard is the built-in feature in Microsoft Defender for Cloud that provides a compliance posture view against chosen standards such as SOC 2 Type II. It maps Azure Policy initiative controls to the specific requirements of the standard, showing per-control status, affected resources, and actionable recommendations. This is the direct, purpose-built tool for reporting compliance with a regulatory standard like SOC 2, so it is correct.

Why this answer

The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built, continuously updated view of compliance posture against standards like SOC 2. It maps Azure Policy initiatives to specific controls and shows the pass/fail status for each control, enabling the compliance officer to generate the required report directly.

Exam trap

The trap here is that candidates often confuse the Secure Score (which measures overall security posture) with regulatory compliance reporting, not realizing that Secure Score does not map to specific standard controls like SOC 2.

How to eliminate wrong answers

Option B (Inventory) is wrong because it lists Azure resources and their configurations, but does not evaluate or report compliance against specific regulatory standards like SOC 2. Option C (Secure Score) is wrong because it aggregates security recommendations into a single score based on best practices, not a control-by-control pass/fail report for a specific compliance standard. Option D (Workbooks) is wrong because while Workbooks can create custom visualizations from Azure Monitor data, they are not a pre-built feature for regulatory compliance reporting and require manual configuration to map controls.

84
Multi-Selectmedium

A company uses Defender for Servers Plan 2. Which two capabilities are included compared with a basic posture-only configuration?

Select 2 answers
A.Azure Cost Management budget alerts
B.File integrity monitoring or equivalent advanced server protection capabilities
C.Endpoint detection and response integration through Microsoft Defender for Endpoint
D.Microsoft 365 message trace
AnswersB, C

File integrity monitoring (FIM) is included in Defender for Servers Plan 2 and watches critical system files, registry entries, and configuration settings for unauthorized changes by comparing them to a baseline. When a change is detected, the response is enriched with details about the change and the user or process responsible so security teams can determine if it indicates compromise. This advanced server protection capability satisfies the stated requirement, making the option correct.

Why this answer

Defender for Servers Plan 2 includes advanced server protection capabilities such as file integrity monitoring (FIM), which tracks changes to critical system files and registry keys, and endpoint detection and response (EDR) integration through Microsoft Defender for Endpoint. These capabilities go beyond the basic posture-only configuration, which only provides vulnerability assessment and security recommendations without real-time threat detection or file change monitoring.

Exam trap

The trap here is that candidates often confuse basic posture-only features (like vulnerability assessment and secure score) with advanced capabilities like FIM and EDR, assuming all Defender for Servers tiers include endpoint detection, when only Plan 2 adds these specific protections.

85
MCQmedium

Security analysts in your company use Microsoft Sentinel to manage incidents. They want to automatically assign any incident with a severity of 'High' or 'Critical' to the senior analyst on duty. Which Microsoft Sentinel feature should they configure to accomplish this?

A.Automation rules
B.Playbooks
C.Workbooks
D.Analytics rules
AnswerA

Automation rules are the native, no-code mechanism in Microsoft Sentinel for automating incident management tasks. You define a trigger condition (e.g., incident severity is High or Critical) and then assign an action such as 'Set owner' to a specific user or group. Because these rules run directly within Sentinel and are evaluated on incident creation/update, they are the simplest and most direct way to ensure every matching incident is immediately assigned to the appropriate analyst without additional Logic Apps consumption.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific users or groups based on conditions such as severity. By creating an automation rule that triggers when an incident is created with a severity of 'High' or 'Critical', you can set the owner to the senior analyst on duty, fulfilling the requirement without manual intervention.

Exam trap

The trap here is that candidates often confuse automation rules with playbooks, assuming that any automated response requires a playbook, but Microsoft Sentinel's automation rules natively support direct incident assignment without needing a separate playbook workflow.

How to eliminate wrong answers

Option B is wrong because playbooks are automated workflows (often based on Azure Logic Apps) that perform complex response actions like sending emails or blocking IPs, but they cannot directly assign incident ownership; assignment is a property managed by automation rules. Option C is wrong because workbooks are visualization tools for creating dashboards and reports from Sentinel data, not for automating incident assignment. Option D is wrong because analytics rules are used to generate alerts and incidents from data sources (e.g., scheduled queries or Microsoft Security alerts), but they do not handle post-creation actions like assignment.

86
MCQmedium

An organization has deployed Microsoft Sentinel as their SIEM. They need to ingest audit logs from their Amazon Web Services (AWS) environment, including CloudTrail logs. Which data connector should they use in Microsoft Sentinel to collect these logs?

A.Amazon Web Services connector
B.AWS S3 connector
C.Azure Sentinel to AWS connector
D.CloudTrail connector
AnswerA

The correct connector in Microsoft Sentinel is named 'Amazon Web Services,' and it is specifically designed to ingest AWS CloudTrail audit logs into Sentinel. This connector uses an S3 bucket as the log source and SQS for automated notifications, while also requiring an AWS role for cross-account access. Its official display name in the Sentinel data connectors gallery is 'Amazon Web Services (AWS),' which is why it is the precise answer.

Why this answer

The Amazon Web Services connector is the correct data connector in Microsoft Sentinel for ingesting AWS audit logs, including CloudTrail logs. It establishes a connection to AWS by requiring a role ARN and external ID, enabling Sentinel to pull CloudTrail events via the AWS API. This connector specifically supports CloudTrail management and data events, making it the appropriate choice for audit log ingestion.

Exam trap

The trap here is that candidates may confuse the generic 'AWS S3 connector' with CloudTrail log ingestion, but CloudTrail logs are ingested via the dedicated 'Amazon Web Services' connector, not through direct S3 bucket access.

How to eliminate wrong answers

Option B is wrong because the AWS S3 connector is designed to ingest logs from S3 buckets (e.g., VPC Flow Logs, ELB logs), not specifically CloudTrail audit logs, and requires additional configuration like SQS for event-driven ingestion. Option C is wrong because there is no data connector named 'Azure Sentinel to AWS connector'; the official connector is called 'Amazon Web Services' in the Sentinel data connectors gallery. Option D is wrong because there is no standalone 'CloudTrail connector' in Microsoft Sentinel; CloudTrail logs are ingested through the Amazon Web Services connector, which handles the CloudTrail integration.

87
MCQeasy

A company needs to demonstrate compliance with the Payment Card Industry Data Security Standard (PCI DSS) for their Azure workloads. They use Microsoft Defender for Cloud for security management. Which feature should they use to view their current compliance status against PCI DSS controls and track progress over time?

A.Security policy
B.Recommendations
C.Regulatory compliance dashboard
D.Security incidents
AnswerC

The Regulatory compliance dashboard continuously evaluates selected standards, including PCI DSS 3.2.1, through built-in Azure Policy initiatives and displays the overall percentage of compliant controls across your subscriptions. It maps each standard requirement to compliance controls, shows the resources that passed or failed the linked policies, and identifies which failed recommendations must be fixed to restore that control. You can also drill down to view evidence, assign manual assessments for customer-managed controls, and track compliance trends over time, making it the correct place to demonstrate PCI DSS status.

Why this answer

The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built view of compliance posture against standards like PCI DSS. It maps Azure resource configurations to specific PCI DSS controls, shows pass/fail status per control, and tracks compliance score over time, enabling continuous monitoring and evidence collection for auditors.

Exam trap

The trap here is that candidates may confuse the Recommendations blade (which shows individual security findings) with the Regulatory compliance dashboard (which aggregates those findings into a compliance framework view), leading them to select Recommendations instead of the correct dashboard.

How to eliminate wrong answers

Option A is wrong because Security policy defines rules and initiatives for resource compliance but does not provide a dashboard to view current compliance status or track progress against PCI DSS controls. Option B is wrong because Recommendations are individual security findings that suggest actions to improve security posture, but they do not aggregate or map to PCI DSS controls in a compliance dashboard format. Option D is wrong because Security incidents are alerts about detected threats or attacks, not a compliance tracking tool for standards like PCI DSS.

88
MCQmedium

A company uses Azure AD Identity Protection. They have detected a user with a 'High' user risk level due to suspicious activity. The security team wants to automatically block sign-ins for this user only when the sign-in comes from a location that is not in the company's list of trusted IPs. They have created a Conditional Access policy. Which configuration should they use?

A.Assign the user to the policy, set condition 'User risk level: High' and condition 'Locations: All locations except trusted', and set 'Grant' to 'Block access'
B.Assign the user to the policy, set condition 'Sign-in risk level: High' and condition 'Locations: All trusted locations', and set 'Grant' to 'Block access'
C.Assign the user to the policy, set condition 'User risk level: High' and set 'Grant' to 'Require multi-factor authentication'
D.Create a risk detection policy in Identity Protection that triggers a user risk policy, and have Conditional Access use the risk policy
AnswerA

In a Conditional Access policy, conditions are combined with a logical AND, so this configuration triggers only when Identity Protection has computed the user's account risk as High and the sign-in originates from a location that is not on the trusted list. The Grant control is set to Block access, which denies the authentication session outright rather than allowing it with additional challenges. Because user risk is a cumulative account-level signal, pairing it with the trusted-location exception precisely targets high-risk users signing in from untrusted networks while leaving trusted-network activity unaffected.

Why this answer

It combines the 'User risk level: High' condition (triggered by Identity Protection's user risk detection) with the 'Locations: All locations except trusted' condition, and sets 'Grant' to 'Block access'. This ensures that only sign-ins from untrusted locations are blocked when the user's risk is high, meeting the requirement to allow sign-ins from trusted IPs even for high-risk users.

Exam trap

The trap here is confusing 'User risk level' (associated with the user account's overall risk) with 'Sign-in risk level' (associated with a specific authentication attempt), leading candidates to incorrectly choose Option B which uses sign-in risk and targets trusted locations.

How to eliminate wrong answers

Option B is wrong because it uses 'Sign-in risk level: High' instead of 'User risk level: High', and it targets 'All trusted locations' which would block sign-ins from trusted IPs, the opposite of the requirement. Option C is wrong because it sets 'Grant' to 'Require multi-factor authentication' instead of 'Block access', which does not block sign-ins but only prompts for MFA, failing the requirement to block sign-ins from untrusted locations. Option D is wrong because it describes creating a separate risk detection policy in Identity Protection; Conditional Access policies directly use user risk and sign-in risk conditions without needing an additional risk policy, and this approach adds unnecessary complexity without achieving the specific location-based block.

89
MCQhard

A company uses Azure AD Privileged Identity Management (PIM) to manage the Global Administrator role. They want to require that when a user activates the role, they must be using a device that is compliant with Intune policies (e.g., compliant device) and must provide a justification. The company already has Conditional Access policies in place for regular access. How should they enforce the device compliance requirement specifically during PIM activation?

A.Configure a Conditional Access policy that targets the 'Azure AD Privileged Identity Management' cloud app, requiring compliant device.
B.In PIM settings for the Global Administrator role, enable 'Require Multi-Factor Authentication on activation'.
C.In PIM settings for the Global Administrator role, enable 'Require Azure AD Conditional Access authentication context' and create a Conditional Access policy that requires compliant device when that authentication context is used.
D.Use Azure AD Identity Protection's user risk policy to require device compliance when a high-risk user activates the role.
AnswerC

This is the correct approach because PIM supports emitting an Azure AD Conditional Access authentication context during role activation. When you enable 'Require Azure AD Conditional Access authentication context' in PIM settings, Azure AD sends that context as a signal to Conditional Access for the activation request. A separate Conditional Access policy can then target that authentication context and apply the 'Require device to be marked as compliant' grant control. This is the documented integration pattern for combining PIM with device-compliance policies, and it satisfies the requirement without relying on unsupported targets like the PIM app itself.

Why this answer

Azure AD PIM can integrate with Conditional Access via authentication context. By enabling 'Require Azure AD Conditional Access authentication context' in the PIM role settings and then creating a Conditional Access policy that targets that authentication context with the 'Require compliant device' grant control, you enforce device compliance specifically during role activation. This approach ensures the device compliance check is applied only when the user activates the Global Administrator role, not during regular access.

Exam trap

The trap here is that candidates often confuse applying a Conditional Access policy to the 'Azure AD Privileged Identity Management' cloud app (which controls access to the PIM portal) with enforcing conditions during the actual role activation process, which requires authentication context integration.

How to eliminate wrong answers

Option A is wrong because targeting the 'Azure AD Privileged Identity Management' cloud app in a Conditional Access policy applies the policy to the PIM service itself (e.g., accessing the PIM portal), not to the role activation process; it would not enforce device compliance during activation. Option B is wrong because enabling 'Require Multi-Factor Authentication on activation' only adds an MFA requirement, not a device compliance check; it does not address the device compliance requirement. Option D is wrong because Azure AD Identity Protection's user risk policy evaluates user risk and can require MFA or password change, but it cannot directly enforce device compliance; it is designed for risk-based remediation, not for role activation-specific device compliance.

90
MCQhard

A Defender for Cloud recommendation is valid for most subscriptions but not for a legacy subscription with an approved exception. The team wants secure score to reflect the exception without disabling the recommendation everywhere. What should they do?

A.Delete the built-in initiative from the management group
B.Change the recommendation severity to Low
C.Create an exemption for the affected scope with a justification
D.Disable Defender for Cloud on the legacy subscription
AnswerC

Creating an exemption for the affected scope with a justification is the correct approach because Microsoft Defender for Cloud natively supports exemptions to exclude a specific scope from a recommendation while leaving the initiative intact. You can target the exact subscription (or resource group) and provide a reason, such as 'legacy system' or 'not applicable,' and optionally set an expiration date. This directly addresses the requirement by suppressing the recommendation only where it's not valid, while preserving security monitoring and compliance for all other scopes.

Why this answer

Azure Policy exemptions allow you to exclude a specific scope (e.g., a subscription or resource group) from a policy or initiative effect while still having the policy enforced elsewhere. By creating an exemption for the legacy subscription with a justification, the Defender for Cloud recommendation remains active for all other subscriptions, and the secure score calculation will correctly reflect the exception without disabling the recommendation globally.

Exam trap

The trap here is that candidates often confuse 'exemption' with 'disabling' or 'removing' the policy, leading them to choose options that either globally disable the recommendation (A or D) or incorrectly assume severity changes can create exceptions (B), when in fact Azure Policy exemptions are the precise mechanism to exclude a specific scope while preserving the policy for all others.

How to eliminate wrong answers

Option A is wrong because deleting the built-in initiative from the management group would remove the policy from all subscriptions under that management group, not just the legacy subscription, and would prevent the secure score from reflecting the recommendation at all. Option B is wrong because changing the recommendation severity to Low does not create an exception; it only adjusts the weight of the recommendation in the secure score, but the recommendation would still apply to the legacy subscription and could generate alerts or compliance failures. Option D is wrong because disabling Defender for Cloud on the legacy subscription would turn off all security monitoring and recommendations for that subscription, which is an overly broad action that goes beyond creating a single exception and could leave the subscription unprotected.

91
MCQhard

A Sentinel analytics rule creates a new incident every time the same brute-force activity is detected for the same account within an hour. The SOC wants one incident that continues to group related alerts. What should be changed?

A.Disable entity mapping for the account entity
B.Configure incident grouping in the scheduled analytics rule
C.Change the rule query to use project-away on TimeGenerated
D.Run the rule as a near-real-time rule
AnswerB

Configuring incident grouping in the scheduled analytics rule lets you define how alerts from the same rule are grouped into incidents, such as by matching entities (e.g., account) or within a specific time window. When grouping is set to 'Group all alerts into a single incident' or based on entity mapping, Sentinel will not create a new incident for every alert that fires. This directly satisfies the requirement to avoid a new incident each time the same entity triggers the rule.

Why this answer

Incident grouping in a scheduled analytics rule allows multiple alerts triggered by the same entity (e.g., the same account) within a specified time window to be combined into a single incident. By configuring the 'Group related alerts into a single incident' setting and setting the grouping window to one hour, the SOC ensures that all brute-force alerts for the same account are merged into one incident, reducing alert fatigue and providing a consolidated view of the attack.

Exam trap

The trap here is that candidates often confuse incident grouping with alert suppression or think that disabling entity mapping will reduce noise, but entity mapping is actually required for grouping to work correctly.

How to eliminate wrong answers

Option A is wrong because disabling entity mapping for the account entity would prevent the rule from identifying the specific account involved, breaking the grouping logic and potentially causing alerts to not be correlated at all. Option C is wrong because using project-away on TimeGenerated would remove the timestamp column from the query results, which is essential for time-based grouping and would break the rule's ability to correctly evaluate the 1-hour window. Option D is wrong because running the rule as a near-real-time rule (NRT) does not support incident grouping; NRT rules run every few minutes and create separate incidents for each detection, which is the opposite of what the SOC wants.

92
MCQmedium

A security operations team uses Microsoft Sentinel. They want to automatically assign incidents to different tiers of analysts based on severity when incidents are created. Which feature should they configure?

A.Fusion - Advanced Multistage Attack Detection
B.Analytics rules with scheduled queries
C.Automation rules
D.Playbooks
AnswerC

Automation rules allow you to automatically trigger actions like assigning an incident to a specific user or team, changing severity, adding tags, or running a playbook. This is the correct feature to automatically assign incidents based on severity.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific analysts or teams based on criteria such as severity. When an incident is created, the automation rule triggers and can set the owner (assignee) to a predefined user or group, enabling tiered assignment without manual intervention.

Exam trap

The trap here is that candidates often confuse automation rules with playbooks, assuming playbooks are required for any automated action, but automation rules are the correct feature for simple, rule-based incident assignment without the overhead of a full Logic App workflow.

How to eliminate wrong answers

Option A is wrong because Fusion - Advanced Multistage Attack Detection is a correlation engine that detects multistage attacks by combining alerts, not a mechanism for incident assignment. Option B is wrong because analytics rules with scheduled queries generate alerts based on log queries, but they do not include incident assignment or ownership logic. Option D is wrong because playbooks are automated workflows (often using Azure Logic Apps) that can respond to incidents, but they are triggered by automation rules or analytics rules and are not the feature used to directly assign incidents to analysts.

93
MCQmedium

A security operations team uses Microsoft Sentinel. They create a playbook that changes the severity of an incident from 'Medium' to 'High' when a specific indicator of compromise (IOC) is detected within the incident's entities. The team wants this playbook to run automatically as soon as the incident is created, without manual intervention. Which type of automation rule trigger should they configure to invoke the playbook?

A.When incident is created
B.When incident is updated
C.When alert is created
D.On a time schedule
AnswerA

The 'When incident is created' trigger fires the moment Microsoft Sentinel generates an incident, so the playbook executes with no analyst action. This satisfies the requirement for automatic severity escalation on IOC detection, unlike manual or entity-based triggers.

Why this answer

The 'When incident is created' trigger in Microsoft Sentinel automation rules is designed to invoke a playbook immediately upon incident generation, without requiring any manual action. This matches the requirement for automatic execution as soon as the incident is created, allowing the playbook to evaluate entities and change severity from 'Medium' to 'High' based on the IOC detection.

Exam trap

The trap here is that candidates may confuse 'When alert is created' with incident creation, not realizing that incidents are higher-level constructs that can aggregate multiple alerts, and the playbook must run at the incident scope to change severity based on entities across all alerts.

How to eliminate wrong answers

Option B is wrong because 'When incident is updated' triggers only after an incident is modified (e.g., status change or comment), not at creation time, so it would not run automatically on the initial creation. Option C is wrong because 'When alert is created' triggers on alert generation, not incident creation; incidents can aggregate multiple alerts, and the playbook needs to run at the incident level, not per alert. Option D is wrong because 'On a time schedule' is a recurring trigger (e.g., every hour) that does not respond to real-time incident creation events, making it unsuitable for immediate automated response.

94
MCQhard

A Sentinel playbook fails to update incidents even though the Logic App runs successfully. The playbook uses a managed identity. What is the most likely missing configuration?

A.The managed identity lacks Microsoft Sentinel Responder or Contributor permissions on the workspace
B.The analytics rule does not include MITRE ATT&CK tactics
C.The Log Analytics workspace is not linked to Azure Monitor Private Link
D.The incident title does not contain an entity mapping
AnswerA

The managed identity assigned to the Logic Apps playbook must be granted Microsoft Sentinel Responder (least privilege) or Contributor at the workspace scope to invoke incident-update operations via the Sentinel API. Without it, the API returns 403 Forbidden even if the playbook run is triggered. This RBAC assignment controls write access to Sentinel incidents, so adding it directly resolves the failure.

Why this answer

The managed identity assigned to the Logic App must have at least Microsoft Sentinel Responder or Contributor permissions on the workspace to update incidents. Without these RBAC roles, the Logic App's API calls to modify incident properties (e.g., status, severity) are denied, even if the Logic App itself runs without errors.

Exam trap

The trap here is that candidates assume a successful Logic App run means permissions are correct, but the playbook can complete without errors while the incident update silently fails due to missing RBAC on the managed identity.

How to eliminate wrong answers

Option B is wrong because MITRE ATT&CK tactics are metadata for rule classification and do not affect the playbook's ability to update incidents. Option C is wrong because Azure Monitor Private Link controls network access to the workspace, not authorization for managed identity actions. Option D is wrong because entity mappings are used for alert enrichment, not for granting permissions to modify incidents.

95
MCQhard

A SOC analyst needs a Sentinel query that detects multiple failed sign-ins followed by a successful sign-in for the same user. Which table is the best primary source?

A.SecurityAlert
B.AzureActivity
C.DeviceNetworkEvents
D.SigninLogs
AnswerD

SigninLogs stores every Azure AD sign-in attempt, including both interactive and non-interactive logons, with detailed attributes such as `ResultType`, `ResultDescription`, `IPAddress`, and `UserPrincipalName`. By using a Kusto query to filter on error codes indicating failure (e.g., `ResultType != 0` or specific codes like `50053`), you can aggregate attempts with `summarize count() by UserPrincipalName` over a sliding time window to identify multiple failed logons. This is the definitive table for detecting brute-force or password-spray patterns in Azure Sentinel.

Why this answer

SigninLogs is the correct primary source because it captures both failed and successful user sign-in events from Azure AD, including interactive and non-interactive logins. This table provides the necessary fields like ResultType (e.g., 0 for success, 50125 for failure) and UserPrincipalName to build a KQL query that detects a sequence of failed sign-ins followed by a successful one for the same user.

Exam trap

The trap here is that candidates often confuse AzureActivity (which logs administrative actions) with sign-in logs, or assume SecurityAlert contains raw event data, when in fact only SigninLogs provides the granular authentication events needed for this detection pattern.

How to eliminate wrong answers

Option A is wrong because SecurityAlert contains pre-built security alerts (e.g., from Microsoft Defender for Cloud), not raw sign-in event logs, so it cannot be used to query individual sign-in success/failure sequences. Option B is wrong because AzureActivity logs control plane operations (e.g., resource creation, RBAC changes) and does not include user authentication events like sign-ins. Option C is wrong because DeviceNetworkEvents logs network-level events (e.g., connections, DNS queries) from Microsoft Defender for Endpoint, not Azure AD authentication events.

96
MCQmedium

A security analyst is using Microsoft Sentinel to detect multi-stage attacks. They want to create an analytics rule that correlates a user sign-in from an unusual location with a subsequent data exfiltration attempt from Azure Blob Storage within one hour. Which type of analytics rule should they use?

A.Scheduled query rule with entity mapping.
B.Fusion rule.
C.Microsoft Security incident rule.
D.Anomaly rule.
AnswerA

Scheduled query rules are the only listed Sentinel analytics rule type that execute custom KQL directly against Log Analytics workspace tables, so an analyst can write a query that joins storage logs, sign-in logs, and other data sources within a defined lookback window to detect multi-event sequences. Entity mapping is what turns query result rows into normalized alert entities—Account, Host, IP, URL—so Sentinel can enrich the incident, correlate related alerts, and pass machine-readable context to playbooks and investigations. This makes it the correct choice when the SOC needs custom detection logic that matches a specific attack pattern rather than relying on a built-in source alert.

Why this answer

A scheduled query rule with entity mapping is correct because it allows the security analyst to write a KQL query that correlates two distinct events—a sign-in from an unusual location and a subsequent data exfiltration from Azure Blob Storage—within a defined time window (one hour). Entity mapping enables the rule to link these events by common entities (e.g., user account or IP address), which is essential for detecting multi-stage attacks. This rule type runs on a schedule, making it ideal for time-bound correlation queries.

Exam trap

The trap here is that candidates often confuse Fusion rules (which also correlate events) with scheduled queries, but Fusion rules are limited to pre-built correlations from Microsoft security products, whereas scheduled queries allow custom KQL logic across any data source.

How to eliminate wrong answers

Option B (Fusion rule) is wrong because Fusion rules are designed to automatically correlate alerts from multiple Microsoft security products (e.g., Microsoft Defender for Cloud Apps, Azure AD Identity Protection) into a single incident, not to run custom KQL queries that correlate raw log data like sign-in logs and storage logs. Option C (Microsoft Security incident rule) is wrong because it creates incidents from alerts generated by Microsoft security services (e.g., Microsoft Defender for Endpoint), not from custom log analytics queries. Option D (Anomaly rule) is wrong because anomaly rules use machine learning to detect unusual patterns in a single data source over time, not to correlate two specific event types across different data sources within a fixed time window.

97
MCQhard

An organization wants to detect when a privileged Azure role assignment is created outside the approved change window. Which log source should a Sentinel rule query?

A.Heartbeat
B.AzureActivity
C.Perf
D.StorageBlobLogs
AnswerB

The AzureActivity table is the Log Analytics destination for the Azure Activity Log, which captures all control plane (Azure Resource Manager) events, including Microsoft.Authorization/roleAssignments/write operations. When a privileged role assignment is created, this write operation is logged there, allowing you to build a log alert or query to detect it. This makes AzureActivity the directly relevant and correct data source for the stated requirement.

Why this answer

AzureActivity logs capture all control-plane operations on Azure resources, including role assignment creations (e.g., 'Microsoft.Authorization/roleAssignments/write'). By querying AzureActivity in a Sentinel rule, you can detect when a privileged role assignment is made outside an approved change window. Heartbeat, Perf, and StorageBlobLogs do not record Azure RBAC changes.

Exam trap

The trap here is that candidates may confuse data-plane logs (StorageBlobLogs) or agent health logs (Heartbeat, Perf) with control-plane activity logs, failing to recognize that only AzureActivity captures RBAC changes at the subscription scope.

How to eliminate wrong answers

Option A is wrong because Heartbeat logs are used for agent health monitoring and do not contain Azure RBAC activity. Option C is wrong because Perf logs contain performance counters (CPU, memory, disk) and have no role assignment data. Option D is wrong because StorageBlobLogs record data-plane operations on blob storage (e.g., reads, writes) and not control-plane role assignments.

98
MCQmedium

A company uses Microsoft Defender for Cloud to monitor its security posture. The compliance team wants to receive email notifications immediately when a control in the ISO 27001 regulatory compliance standard fails. They want to be alerted only when specific controls change from 'compliant' to 'non-compliant'. Which feature should they configure?

A.Security Alerts from Microsoft Defender for Cloud
B.Regulatory Compliance dashboard with continuous export
C.Workflow automation based on regulatory compliance assessment changes
D.Custom recommendations in Microsoft Defender for Cloud
AnswerC

Workflow automation in Microsoft Defender for Cloud is the native mechanism to react to changes in regulatory compliance assessments. You configure an automation rule to watch for a specific assessment status change (e.g., a control failing) and then invoke a Logic App or Power Automate flow to send an email, post to Teams, or create a ticket. This provides the proactive notification (e.g., email) required by the scenario. It is the only built-in way to directly trigger external actions based on compliance assessment changes.

Why this answer

Workflow automation in Microsoft Defender for Cloud can be configured to trigger based on regulatory compliance assessment changes, specifically when a control transitions from 'compliant' to 'non-compliant'. This allows the compliance team to receive immediate email notifications for ISO 27001 control failures without manual polling or dashboard monitoring.

Exam trap

The trap here is that candidates often confuse Security Alerts (which are threat-focused) with compliance state change notifications, or assume the Regulatory Compliance dashboard's continuous export can directly send real-time email alerts, but it only exports data to external sinks without built-in notification logic.

How to eliminate wrong answers

Option A is wrong because Security Alerts in Defender for Cloud are triggered by threat detection events (e.g., suspicious activities, vulnerabilities), not by regulatory compliance control state changes. Option B is wrong because the Regulatory Compliance dashboard with continuous export sends data to Log Analytics or Event Hubs for archival and analysis, but it does not natively support immediate email notifications based on specific control state transitions. Option D is wrong because custom recommendations are used to define additional security best practices or policies, not to trigger notifications on compliance control changes.

99
MCQmedium

A company has an on-premises web application that they want to expose to external users over the internet without requiring a VPN. External users must authenticate with Modern Authentication (e.g., using Azure Multi-Factor Authentication) and access policies must be enforced via Conditional Access. The application does not support SAML or OAuth. Which Azure service should they use to publish this application securely?

A.Azure AD B2C (Business-to-Consumer).
B.Azure Application Gateway with Web Application Firewall (WAF).
C.Azure AD Application Proxy.
D.Azure Front Door.
AnswerC

Azure AD Application Proxy is the appropriate service here because it is purpose-built to publish on-premises HTTP/HTTPS apps to external users through Azure AD. A lightweight connector installed on the corporate network establishes an outbound connection to the Azure AD Application Proxy service, eliminating the need for inbound firewall ports or a VPN; the external endpoint is an Azure AD URL that performs full Azure AD pre-authentication, including MFA and Conditional Access, before passing the authenticated request back through the connector to the internal web application. It effectively acts as an HTTPS reverse proxy bridged by an outbound-only tunnel, which is exactly what is required to securely expose an on-premises web app without making it publicly reachable.

Why this answer

Azure AD Application Proxy is the correct choice because it allows publishing on-premises web applications to external users without requiring a VPN, supports Modern Authentication (including Azure MFA), and enforces Conditional Access policies. It works by installing a connector on-premises that proxies traffic through Azure AD, enabling authentication and policy enforcement even for legacy applications that do not support SAML or OAuth.

Exam trap

The trap here is that candidates often confuse Azure AD Application Proxy with Azure Application Gateway, assuming that WAF provides authentication, but Application Gateway does not integrate with Azure AD for Modern Authentication or Conditional Access enforcement.

How to eliminate wrong answers

Option A is wrong because Azure AD B2C is designed for customer-facing identity management with social logins and custom policies, not for publishing internal on-premises applications with Conditional Access enforcement. Option B is wrong because Azure Application Gateway with WAF provides layer 7 load balancing and web application firewall protection but does not handle Modern Authentication or Conditional Access policies for legacy apps. Option D is wrong because Azure Front Door is a global load balancer and CDN service that accelerates web traffic but does not provide identity-based authentication or Conditional Access integration for on-premises applications.

100
MCQhard

A Sentinel scheduled rule runs every 5 minutes and looks back 1 hour. Analysts see repeated alerts for the same event. Which change best prevents duplicate detections without missing late-arriving logs?

A.Reduce the query lookback to 1 minute
B.Use an ingestion-time or event-time exclusion window in the query
C.Disable alert grouping
D.Change the workspace retention period
AnswerB

Adding a filter such as `where ingestion_time() > ago(5m)` or comparing an event-time column to the previous run's execution time creates an exclusion window in the KQL query. This ensures each scheduled run only evaluates events that are new since the last run, while keeping the original lookback for late-arriving telemetry. As a result, the query is idempotent and the same underlying event will not trigger a new alert in every 5-minute execution. This is the recommended way to meet the stated requirement directly.

Why this answer

Using an ingestion-time or event-time exclusion window in the query allows the rule to skip events that have already generated an alert within a specific time range, preventing duplicate detections while still accommodating late-arriving logs. This approach leverages the query logic to filter out duplicates based on a time-based deduplication key, ensuring that only new or unique events trigger alerts without altering the lookback period.

Exam trap

The trap here is that candidates often confuse reducing the lookback period (Option A) as a quick fix, not realizing it will miss late-arriving logs, while the correct solution uses a query-level exclusion window that preserves the lookback for completeness.

How to eliminate wrong answers

Option A is wrong because reducing the query lookback to 1 minute would cause the rule to miss late-arriving logs that arrive after the initial 5-minute run window, defeating the purpose of the 1-hour lookback and potentially missing critical events. Option C is wrong because disabling alert grouping would not prevent duplicate detections; it would simply stop grouping similar alerts into a single incident, potentially increasing alert noise without addressing the root cause of repeated alerts for the same event. Option D is wrong because changing the workspace retention period affects how long data is stored, not how alerts are deduplicated or how queries handle late-arriving logs, so it has no impact on duplicate alert prevention.

101
Multi-Selectmedium

A team enables Microsoft Defender for Storage. Which two threats can the plan help detect?

Select 2 answers
A.Access from suspicious IP addresses to storage accounts
B.Expired Azure AD PIM role assignments
C.Public IP address creation on virtual machines
D.Malware uploaded to Blob Storage when malware scanning is enabled
AnswersA, D

Microsoft Defender for Storage flags access to storage accounts from suspicious IP addresses by matching request metadata—such as source IP, TLS version, and API behavior—against global threat intelligence and Microsoft's cybercrime attribution data. This is a core detection capability that identifies potential credential compromise or unauthorized access attempts directly on the storage data plane, making it correct for a threat detection requirement.

Why this answer

Microsoft Defender for Storage detects anomalous activities that could indicate threats to storage accounts. Option A is correct because the service analyzes incoming requests to identify access from suspicious IP addresses, such as known malicious IPs or Tor exit nodes, using threat intelligence feeds. Option D is correct because when malware scanning is enabled, Defender for Storage can detect malware uploaded to Blob Storage by scanning files for known malicious signatures.

Exam trap

The trap here is that candidates may confuse Defender for Storage with broader Defender for Cloud capabilities, incorrectly assuming it monitors identity or networking threats outside the storage data plane.

102
MCQmedium

A DevOps team wants Defender for Cloud to identify secrets exposed in GitHub repositories. What should be configured?

A.Azure Bastion native client
B.Defender for Cloud DevOps Security connector
C.Sentinel Syslog connector
D.Azure Storage lifecycle management
AnswerB

The Defender for Cloud DevOps Security connector connects Azure DevOps and GitHub organizations to Defender for Cloud, enabling security assessments of repositories, builds, and release pipelines. Once connected during the enablement of Defender CSPM, it runs secret scanning, code scanning, and dependency scanning, surfacing exposed credentials as recommendations. This connector is the direct mechanism by which a DevOps team's secrets are identified and remediated in the portal.

Why this answer

Defender for Cloud's DevOps Security connector integrates with GitHub to scan repositories for exposed secrets (e.g., API keys, tokens) using Microsoft's secret scanning engine. This connector enables Defender for Cloud to monitor commits and pull requests, alerting on secrets detected in code. It is the correct solution because it directly addresses the requirement to identify secrets in GitHub repositories within the Defender for Cloud ecosystem.

Exam trap

The trap here is that candidates may confuse the Defender for Cloud DevOps Security connector with GitHub's own secret scanning (which requires GitHub Advanced Security), but the question specifically asks for a Defender for Cloud configuration, making the connector the correct choice.

How to eliminate wrong answers

Option A is wrong because Azure Bastion native client is a secure RDP/SSH connectivity service for virtual machines, not a tool for scanning GitHub repositories for secrets. Option C is wrong because Sentinel Syslog connector ingests syslog events from on-premises or cloud devices into Azure Sentinel for security monitoring, but it does not scan GitHub repositories for secrets. Option D is wrong because Azure Storage lifecycle management automates tiering or deletion of blobs based on age or rules, and has no capability to scan GitHub code for exposed secrets.

103
MCQhard

A company has a partner organization in another Azure AD tenant. They want to allow users from the partner tenant to access their Azure resources through Azure AD B2B collaboration. They also want the partner's Multi-Factor Authentication (MFA) claims to be trusted when partner users access their resources, so that they do not need to perform MFA again. Which configuration in cross-tenant access settings should they enable?

A.Trust multi-factor authentication from the partner tenant (inbound trust).
B.Trust device compliance from the partner tenant.
C.Enable a Conditional Access policy that grants access to the partner tenant.
D.Configure identity synchronization with the partner tenant.
AnswerA

This setting, located in the partner tenant's cross-tenant access settings under 'Inbound access' > 'Trust settings', instructs your Azure AD to accept the multi-factor authentication (MFA) claims already performed in the partner tenant. When enabled, B2B collaboration users from that tenant are not prompted for MFA again in your tenant, provided their home tenant has satisfied MFA. This is the correct mechanism to avoid redundant authentication prompts.

Why this answer

Cross-tenant access settings in Azure AD allow you to configure inbound trust for MFA from an external Azure AD tenant. When enabled, Azure AD B2B collaboration will accept the partner tenant's MFA claims, so partner users who have already satisfied MFA in their home tenant will not be prompted again when accessing your resources. This is configured under 'Cross-tenant access settings' > 'Inbound trust settings' for the specific partner tenant.

Exam trap

The trap here is that candidates often confuse Conditional Access policies with cross-tenant trust settings, thinking they can use a Conditional Access policy to 'trust' external MFA, when in fact the trust must be explicitly configured in the cross-tenant access settings for inbound MFA claims.

How to eliminate wrong answers

Option B is wrong because trusting device compliance from the partner tenant is a separate inbound trust option that applies to device state (e.g., compliant or hybrid Azure AD joined), not to MFA claims; it does not address the requirement to skip MFA re-prompting. Option C is wrong because a Conditional Access policy that grants access to the partner tenant does not control trust of MFA claims; it defines conditions and access controls (like requiring MFA) but cannot make your tenant trust the partner's MFA claims—that is a cross-tenant trust setting. Option D is wrong because identity synchronization with the partner tenant is not supported for B2B collaboration; Azure AD B2B uses federation or invitation-based relationships, not synchronization, and synchronizing identities would create duplicate or conflicting objects without enabling MFA claim trust.

104
Multi-Selecthard

You are the Azure Security Engineer for a company that uses Microsoft Entra ID. The security team wants to enforce that any user who is assigned the 'Privileged Role Administrator' role must activate it through Privileged Identity Management (PIM) with multi-factor authentication (MFA) and approval. You have already enabled PIM for the role. Which two actions must you perform to meet these requirements? (Choose two.)

Select 2 answers
A.In the PIM role settings for 'Privileged Role Administrator', configure the 'Require multi-factor authentication on activation' setting to 'Yes'.
B.Enable 'Just-in-time' (JIT) access for the role in PIM.
C.In the PIM role settings for 'Privileged Role Administrator', configure 'Require approval to activate' and specify at least one approver.
D.Assign the user as an eligible member of the 'Privileged Role Administrator' role.
E.Create a conditional access policy that requires MFA for all users when they access the Azure portal.
AnswersA, C

Enabling the MFA requirement in the PIM role settings forces users to perform MFA when they activate the role. This directly satisfies the MFA enforcement requirement. Without this setting, activation would not challenge the user for a second factor, leaving the privileged role vulnerable to credential compromise, even if the role is eligible and approval is required.

Why this answer

To enforce MFA and approval for PIM role activation, you must configure the role settings: set 'Require multi-factor authentication on activation' to 'Yes' and set 'Require approval to activate' with approvers. These settings apply to the role itself and are enforced when a user attempts activation. Other options like conditional access or eligible assignment do not meet the specific activation-time requirements.

Exam trap

The trap here is assuming that enabling PIM automatically enforces MFA and approval, or that conditional access can replace PIM activation settings.

105
MCQmedium

A company wants Defender for Cloud to automatically open a Logic App when a high-severity alert is generated for a subscription. Which feature should be configured?

A.Regulatory compliance dashboard
B.Secure score recommendation exemption
C.Workflow automation
D.Continuous export
AnswerC

Workflow automation in Microsoft Defender for Cloud orchestrates Azure Logic Apps in response to triggers such as the creation of a security alert or a recommendation finding. You can define conditions based on severity, type, or resource, and then invoke a Logic App to open a ticket in an ITSM system like ServiceNow or send an email. This is the built-in mechanism that directly satisfies the requirement to automatically open a support ticket when an event occurs.

Why this answer

Workflow automation in Defender for Cloud allows you to trigger a Logic App automatically in response to specific security alerts, such as high-severity alerts. This feature uses Azure Event Grid to listen for alert creation events and invoke the Logic App via an HTTP trigger, enabling automated remediation or notification workflows without manual intervention.

Exam trap

The trap here is that candidates often confuse Continuous export with workflow automation, thinking that exporting alerts to a Log Analytics workspace can directly trigger a Logic App, but Continuous export only sends data to a destination and requires a separate Azure Monitor alert rule or Logic App connector to process the exported data.

How to eliminate wrong answers

Option A is wrong because the Regulatory compliance dashboard is a reporting tool that shows compliance posture against standards like ISO 27001 or SOC 2, not a mechanism to trigger automated actions on alerts. Option B is wrong because Secure score recommendation exemption is used to exclude specific recommendations from affecting your secure score, not to automate responses to alerts. Option D is wrong because Continuous export streams security data (e.g., alerts, recommendations) to Log Analytics or Event Hubs for external analysis, but it does not directly invoke a Logic App or any automated action upon alert generation.

106
MCQeasy

A company uses Azure AD Privileged Identity Management (PIM) for the 'Security Administrator' role. They want to ensure that when a user activates the role, they must provide a justification, and the activation requires approval from a designated security group. Which PIM role settings should they configure?

A.Require justification on activation (Yes), Require approval (Yes), Select approver(s) (the security group).
B.Require justification on activation (No), Require approval (Yes), Select approver(s) (the security group).
C.Expiration > Maximum activation duration (4 hours).
D.On activation, require Azure MFA registration.
AnswerA

Enabling justification forces the user to enter a business rationale when requesting activation, directly satisfying the justification requirement. Enabling approval with the security group as the approver means a member of that group must review and approve every activation request before the privilege is granted. This combination is both necessary and sufficient for the stated conditions.

Why this answer

PIM role settings allow administrators to enforce both justification and approval workflows for role activation. Setting 'Require justification on activation' to 'Yes' ensures the user provides a reason, and setting 'Require approval' to 'Yes' with the designated security group as the approver enforces the approval requirement. This combination directly meets the company's stated requirements.

Exam trap

The trap here is that candidates may confuse activation duration settings (Option C) or MFA registration (Option D) with the justification and approval workflow, but only the combination of justification and approval settings directly addresses the stated requirements.

How to eliminate wrong answers

Option B is wrong because setting 'Require justification on activation' to 'No' would bypass the justification requirement, which the company explicitly needs. Option C is wrong because configuring 'Maximum activation duration' controls how long the role remains active, not the activation workflow of justification or approval. Option D is wrong because requiring Azure MFA registration is a separate security control for authentication, not a mechanism for justification or approval during activation.

107
MCQmedium

You are deploying a new line-of-business application on an Azure virtual machine. The application needs to access an Azure SQL Database. The security team requires that the application uses a managed identity to authenticate to the database without storing credentials in code or configuration files. You assign a system-assigned managed identity to the virtual machine. What should you do next to allow the application to authenticate to Azure SQL Database?

A.Generate a client secret for the managed identity and store it in Azure Key Vault.
B.Create a contained database user in Azure SQL Database that maps to the managed identity and grant the necessary permissions.
C.Add the managed identity's object ID to the Azure SQL Server's Azure Active Directory admin group.
D.Assign the virtual machine's managed identity the Contributor role on the Azure SQL Server resource.
AnswerB

For a managed identity to authenticate to Azure SQL Database, you must create a contained database user that represents the managed identity and assign appropriate permissions. This is done using the CREATE USER ... FROM EXTERNAL PROVIDER statement. This allows the managed identity to authenticate without credentials. It is the correct step after assigning the identity to the VM.

Why this answer

After enabling a system-assigned managed identity on the VM, you must create a contained database user in Azure SQL Database for that identity and grant it the necessary permissions. This enables the application to authenticate using the managed identity. Other options either grant excessive permissions, misunderstand managed identity capabilities, or use the wrong plane of access.

Exam trap

The trap here is confusing Azure RBAC roles with database-level permissions, or thinking managed identities require secrets.

108
MCQmedium

A security team wants to visualize MITRE ATT&CK coverage for Microsoft Sentinel analytics rules. Which Sentinel experience should they use?

A.Hunting bookmarks
B.Watchlists
C.MITRE ATT&CK coverage in analytics/content hub views
D.Data collection endpoints
AnswerC

In Microsoft Sentinel, the MITRE ATT&CK coverage view is accessible from the Analytics blade and in Content Hub solution views, where enabled analytics rules are mapped to specific tactics and techniques on the ATT&CK matrix. Each rule's 'Tactics' and 'Techniques' properties drive the color-coded cells, letting security teams quickly identify which techniques are currently detected. This directly provides the visualization required.

Why this answer

The MITRE ATT&CK coverage view in the Microsoft Sentinel analytics/content hub provides a direct mapping between configured analytics rules and specific MITRE ATT&CK techniques. This allows security teams to visually identify gaps in detection coverage by seeing which techniques are covered by active rules and which are not, enabling targeted rule deployment.

Exam trap

The trap here is that candidates confuse the MITRE ATT&CK coverage view with other Sentinel features like Hunting or Watchlists, which are unrelated to analytics rule mapping, leading them to select a plausible-sounding but incorrect option.

How to eliminate wrong answers

Option A is wrong because Hunting bookmarks are used to save and annotate specific query results for later investigation, not to visualize MITRE ATT&CK coverage of analytics rules. Option B is wrong because Watchlists are collections of data (e.g., IP addresses, hostnames) used for correlation and enrichment in queries, not for mapping analytics rules to MITRE ATT&CK techniques. Option D is wrong because Data collection endpoints are configuration objects for ingesting data from sources like Azure Monitor Agent, unrelated to analytics rule coverage mapping.

109
Multi-Selectmedium

A company manages Azure AD roles with Privileged Identity Management (PIM). They want to enforce that when a user activates the Global Administrator role, they must provide a justification and also use Multi-Factor Authentication. Which PIM settings should they configure? (Choose two.)

Select 2 answers
A.Require approval on activation.
B.Require Multi-Factor Authentication on activation.
C.Require justification on activation.
D.Extend activation duration.
AnswersB, C

Requiring Multi-Factor Authentication on activation forces the user to complete an MFA challenge during the activation request, such as through the Microsoft Authenticator app or a phone call, before the privileged role is assigned. This directly satisfies the security requirement for MFA on activation, and PIM evaluates this condition even if the user already has an existing Azure AD session.

Why this answer

PIM allows you to enforce Multi-Factor Authentication (MFA) as a mandatory step during role activation, ensuring the user's identity is verified beyond just a password. Option C is correct because PIM's 'Require justification on activation' setting forces the user to provide a business reason for activating the Global Administrator role, which is a common compliance requirement. Together, these two settings satisfy the requirement for both MFA and justification during activation.

Exam trap

The trap here is that candidates often confuse 'Require approval on activation' with 'Require justification on activation'—approval involves a separate approver, while justification is simply a text input from the user, and the question specifically asks for justification, not approval.

110
MCQeasy

A company has a subscription with Azure Active Directory (Azure AD). They want to enable a conditional access policy that requires all users to use multi-factor authentication (MFA) when accessing the Azure portal. The policy should only apply to users who are members of a group called 'AllUsers'. Which assignment should they configure in the policy?

A.Assign the 'AllUsers' group to the 'Cloud apps' section and select 'Azure portal' as the application
B.Assign the 'AllUsers' group to the 'Users' section and select 'Azure portal' as the cloud app
C.Add a condition for 'Client apps' specifying 'Browser' only
D.Create two policies: one for users and one for the Azure portal
AnswerB

This is the correct configuration because a Conditional Access policy requires both a user scope and an application scope. Adding the AllUsers group in the Users section targets all user identities, and selecting Azure portal as the cloud app limits the policy to sign-ins to that specific application. This combination ensures that every user is evaluated when accessing the Azure portal, allowing you to apply access controls such as MFA.

Why this answer

In an Azure AD Conditional Access policy, the 'Users' section is where you specify which users or groups the policy applies to, and the 'Cloud apps' section is where you select the target application (Azure portal). By assigning the 'AllUsers' group to 'Users' and selecting 'Azure portal' as the cloud app, the policy enforces MFA for all members of that group when they access the Azure portal.

Exam trap

The trap here is that candidates confuse the 'Users' assignment with the 'Cloud apps' assignment, mistakenly thinking that groups are assigned to applications rather than to the user scope of the policy.

How to eliminate wrong answers

Option A is wrong because the 'AllUsers' group should be assigned to the 'Users' section, not the 'Cloud apps' section; the 'Cloud apps' section is for selecting the target application (e.g., Azure portal), not for user assignment. Option C is wrong because restricting to 'Browser' client apps would only enforce MFA for browser-based access, but the requirement is to enforce MFA for all access to the Azure portal, including PowerShell, CLI, or mobile apps; this condition would be too narrow. Option D is wrong because a single Conditional Access policy can include both user assignment and cloud app selection; creating two separate policies is unnecessary and could lead to conflicting or overlapping rules.

111
MCQmedium

A company uses Microsoft Defender for Cloud to manage security posture. The security team wants to receive alerts when a virtual machine has a vulnerability rated as 'Critical' by the integrated vulnerability assessment solution. Which Defender for Cloud plan must be enabled for the subscription to receive these alerts?

A.Defender for Servers Plan 1
B.Defender for Servers Plan 2
C.Defender for Storage
D.Defender for Databases
AnswerB

Defender for Servers Plan 2 builds on Plan 1 by adding integrated vulnerability assessment (Defender Vulnerability Management), just-in-time VM access, and allowlisting. This tier continuously scans Azure VMs for missing security updates, known CVEs, and OS misconfigurations, then raises security alerts and recommendations. For a company using Defender for Cloud to manage server security, Plan 2 is the correct choice to generate alerts for critical vulnerabilities.

Why this answer

Defender for Servers Plan 2 is required because it includes the integrated Qualys-based vulnerability assessment solution that automatically scans VMs and generates security alerts for critical vulnerabilities. Plan 1 only provides basic threat detection and does not include the vulnerability assessment engine or the corresponding alerting capability.

Exam trap

The trap here is that candidates often assume Defender for Servers Plan 1 is sufficient because it provides basic threat alerts, but they overlook that the integrated vulnerability assessment (Qualys) and its critical vulnerability alerts are exclusive to Plan 2.

How to eliminate wrong answers

Option A is wrong because Defender for Servers Plan 1 only offers basic threat detection and does not include the integrated vulnerability assessment solution (Qualys) that generates alerts for critical vulnerabilities. Option C is wrong because Defender for Storage is designed to protect Azure Storage accounts from threats like malware and data exfiltration, not to assess VM vulnerabilities. Option D is wrong because Defender for Databases focuses on database services (e.g., Azure SQL, Azure Database for PostgreSQL) and does not provide vulnerability scanning for virtual machines.

112
MCQmedium

A security team uses Microsoft Defender for Cloud. They want to receive a weekly email summary of the Secure Score, top recommendations, and new alerts for their subscription. Which feature should they configure?

A.Enable the 'Weekly email summary' option in the Defender for Cloud email notifications settings.
B.Configure continuous export to export all security data to a Log Analytics workspace and use a workbook to create a summary.
C.Create a workflow automation that triggers on a schedule and uses a Logic App to send an email summary.
D.Enable the 'Security Policy' default initiative to automatically send reports.
AnswerA

Defender for Cloud email notifications settings include 'Weekly email summary' that sends a personalized overview of Secure Score, top recommendations, and alerts to specified recipients. It's a native, built-in reporting feature that can be enabled directly from the environment settings without any external integration or compute. Ensure the email is configured to be sent weekly by checking the 'Weekly email summary' checkbox and setting the recipient email address(es) in the Defender for Cloud email notifications pane.

Why this answer

Defender for Cloud includes a built-in 'Email notifications' settings page where you can enable a weekly email summary that automatically delivers the Secure Score, top recommendations, and new alerts. This feature is designed specifically for periodic, high-level security posture summaries without requiring custom infrastructure.

Exam trap

The trap here is that candidates confuse the built-in 'Weekly email summary' with custom automation solutions (Logic Apps, continuous export) or policy-based reporting, assuming a scheduled email requires external orchestration when Defender for Cloud already provides a native, one-click configuration.

How to eliminate wrong answers

Option B is wrong because continuous export to a Log Analytics workspace is used for real-time streaming of security data for custom analytics or retention, not for generating a pre-built weekly email summary; it requires additional manual setup (e.g., workbooks, scheduled queries) to produce an email. Option C is wrong because workflow automation in Defender for Cloud triggers on specific events (e.g., alert generation, recommendation state change), not on a schedule; using a Logic App on a schedule would be a custom workaround, not the native feature designed for this purpose. Option D is wrong because the 'Security Policy' default initiative (e.g., Azure Security Benchmark) defines compliance controls and remediation logic, but it does not include any capability to automatically send reports or email summaries.

113
MCQeasy

A security analyst uses Microsoft Defender for Cloud to monitor the security posture of their Azure subscription. They want to receive an email notification whenever a high-severity security alert is generated for any of their Azure resources. What should they configure in Defender for Cloud?

A.Create an alert rule in Azure Monitor that triggers an email when a security alert is raised.
B.Configure email notifications in the Defender for Cloud settings under 'Notifications'.
C.Use a Logic Apps playbook to send an email when a new alert is generated.
D.Set up a workflow automation rule in Microsoft Sentinel to forward alerts to email.
AnswerB

Configuring email notifications directly in Microsoft Defender for Cloud is the native, built-in mechanism for receiving security alert emails. In the Defender for Cloud portal, you navigate to Environment Settings, select the relevant subscription, and under 'Notifications' you can specify recipient email addresses and the severity levels (e.g., High, Medium, Low) that trigger emails. This setting is managed within Defender for Cloud itself, so it does not require external services like Azure Monitor, Logic Apps, or a separate SIEM, and it is the exact option designed for this scenario.

Why this answer

Microsoft Defender for Cloud has a built-in 'Email notifications' setting under its environment settings that allows you to configure email recipients for high-severity alerts directly, without needing external services. This feature sends real-time email notifications for security alerts based on severity levels you define, making it the simplest and most direct method for this requirement.

Exam trap

The trap here is that candidates often confuse Defender for Cloud's native email notification settings with Azure Monitor alert rules or Logic Apps playbooks, assuming that security alerts must be routed through external services to trigger email, when in fact Defender for Cloud provides a direct configuration option for this purpose.

How to eliminate wrong answers

Option A is wrong because Azure Monitor alert rules can trigger on metrics or logs, but they cannot directly consume Defender for Cloud security alerts as a signal source; security alerts are managed within Defender for Cloud's own alert pipeline, not Azure Monitor metric/log alerts. Option C is wrong because Logic Apps playbooks are typically used for automated response actions (e.g., remediation) triggered by Defender for Cloud alerts, but they require additional configuration and are not the native email notification mechanism for alert generation. Option D is wrong because Microsoft Sentinel workflow automation rules are designed for incident creation and orchestration within Sentinel, not for forwarding Defender for Cloud alerts to email; Sentinel can ingest Defender for Cloud alerts, but email notification for those alerts is not a direct feature of Sentinel's automation rules.

114
MCQmedium

A security team uses Microsoft Sentinel. They want to automatically assign a severity level and an owner to every incident that is created from a specific analytics rule. The owner should be a specific security operations group. Which Microsoft Sentinel feature should they configure to achieve this automation?

A.Modify the analytics rule to include a custom script that runs upon alert generation.
B.Create an automation rule that triggers when an incident is created and sets the severity and owner fields.
C.Use a Logic Apps playbook connected to the analytics rule's alert generation trigger.
D.Configure a workbook to filter and manually assign incidents.
AnswerB

Automation rules in Sentinel are purpose-built to perform immediate actions, such as changing severity or assigning an owner, when an incident is created (e.g., when triggered by a specific analytics rule's incident generation). They support conditions and multiple actions and can be prioritized to ensure the desired incident properties are set consistently. This makes automation rules the correct way to enforce classification and ownership at the point of incident creation, without custom code or external integration.

Why this answer

Automation rules in Microsoft Sentinel allow you to centrally manage incident handling by triggering actions when incidents are created or updated. By configuring an automation rule that triggers on incident creation from the specific analytics rule, you can automatically set the severity and assign the incident to a security operations group (via an Azure AD group or user) without custom scripting or manual intervention.

Exam trap

The trap here is that candidates often confuse automation rules with playbooks, assuming that any automation requires a Logic Apps playbook, but automation rules are the correct, lightweight feature for simple field assignments like severity and owner.

How to eliminate wrong answers

Option A is wrong because analytics rules do not support embedding custom scripts directly; they generate alerts or incidents, and automation is handled separately via automation rules or playbooks. Option C is wrong because while a Logic Apps playbook can be triggered by an analytics rule, it is typically used for complex, multi-step orchestration (e.g., enrichment or response actions), not for simply setting severity and owner fields, which is more efficiently done with an automation rule. Option D is wrong because workbooks are visualization and reporting tools, not automation mechanisms; they cannot assign severity or ownership to incidents.

115
MCQhard

A SOC wants a Sentinel rule to include account, host, and IP entities so analysts can pivot during investigation. What should be configured in the analytics rule?

A.Custom details only
B.Entity mapping
C.Suppression rules
D.Workbook parameters
AnswerB

Entity mapping is the correct mechanism because it explicitly binds event fields to typed entity objects in the alert, assigning one field to the Account, another to the Host, and another to the IP. In the rule's alert enrichment section, the SOC can map the exact event properties to entity identifiers such as Account Name, Host Hostname, and IP Address. Once mapped, Microsoft Sentinel stores these as real entities, enabling correlation across alerts, entity pages, and incident enrichment.

Why this answer

Entity mapping is the correct configuration because it explicitly links the analytics rule's results to known entity types (account, host, IP) in Microsoft Sentinel. This enables analysts to pivot directly from an alert to related entities in the investigation graph, enriching context without manual cross-referencing. Without entity mapping, the rule would generate alerts but lack the structured entity data needed for seamless pivot actions.

Exam trap

The trap here is that candidates confuse 'custom details' with 'entity mapping' because both involve extracting data from query results, but custom details only add flat key-value pairs to the alert, whereas entity mapping creates structured, pivotable objects that the investigation graph can traverse.

How to eliminate wrong answers

Option A is wrong because custom details only allow you to extract and display specific fields from the query results in the alert, but they do not create structured entity objects (account, host, IP) that Sentinel's investigation graph can use for pivoting. Option C is wrong because suppression rules are used to temporarily stop generating alerts for a rule after a certain number of occurrences, which is unrelated to entity enrichment or pivot capabilities. Option D is wrong because workbook parameters are used to customize visualizations in Azure Workbooks, not to define entities within an analytics rule for investigation pivoting.

116
MCQmedium

A security team uses Microsoft Defender for Cloud. They want to ensure that all Azure virtual machines have the guest configuration extension installed to apply a security baseline automatically. They need to remediate non-compliant VMs without manual intervention. Which Defender for Cloud feature should be configured?

A.Assign a security policy (built-in initiative) that includes a policy with DeployIfNotExists effect
B.Enable automatic provisioning of the Log Analytics agent
C.Create an Automation rule that triggers a runbook when a recommendation appears
D.Configure a workflow automation scheduled task
AnswerA

The built-in Microsoft Defender for Cloud initiative (such as the default Azure Security Benchmark) includes policy definitions with the DeployIfNotExists effect, for example 'Deploy prerequisites to enable Guest Configuration policies on Windows VMs.' When assigned, this policy evaluates each VM and, if the Guest Configuration extension is missing, automatically deploys it using a managed identity and nested ARM template. This provides continuous, at-scale remediation without manual intervention, making it the correct choice.

Why this answer

The guest configuration extension is deployed automatically via a DeployIfNotExists policy effect within a built-in initiative (such as the Azure Security Benchmark). This effect evaluates VMs for the extension and, if missing, deploys it without manual intervention, ensuring the security baseline is applied. Defender for Cloud uses this policy-driven approach to remediate non-compliant resources at scale.

Exam trap

The trap here is that candidates confuse automatic provisioning of the Log Analytics agent (which collects logs) with the guest configuration extension (which applies baselines), or they assume that Automation rules or scheduled tasks can proactively deploy extensions, when only a DeployIfNotExists policy can enforce deployment without manual steps or external triggers.

How to eliminate wrong answers

Option B is wrong because automatic provisioning of the Log Analytics agent collects security data but does not install the guest configuration extension or apply a security baseline. Option C is wrong because an Automation rule triggers a runbook only after a recommendation appears, requiring the recommendation to exist first and introducing latency; it is not a proactive, policy-driven deployment. Option D is wrong because a workflow automation scheduled task runs on a timer, not in response to compliance state, and cannot deploy extensions dynamically based on policy evaluation.

117
MCQhard

A team wants Sentinel to ingest firewall logs from an appliance that emits Common Event Format over Syslog. Which connector pattern is most appropriate?

A.CEF connector using a Linux log forwarder or AMA-supported collection path
B.Azure Activity connector
C.Microsoft Entra ID Protection connector
D.Office 365 connector
AnswerA

The CEF connector is the correct choice because it ingests Common Event Format logs, which is the industry-standard format produced by firewall appliances such as Palo Alto, Fortinet, and Cisco ASA. The recommended data collection path uses a Linux-based log forwarder (rsyslog or Syslog-NG) running the Log Analytics agent (or the Azure Monitor Agent via a DCR) to forward CEF-formatted syslog messages to Sentinel's Log Analytics workspace. This directly satisfies the requirement to ingest firewall appliance logs.

Why this answer

The Common Event Format (CEF) over Syslog is a standard logging format used by many security appliances. Sentinel's CEF connector is specifically designed to ingest these logs, typically using a Linux log forwarder (rsyslog or syslog-ng) or the Azure Monitor Agent (AMA) with a Data Collection Rule to parse and forward the CEF messages to the Log Analytics workspace.

Exam trap

The trap here is that candidates confuse CEF with other log formats (e.g., Windows Event Log or JSON) and select a connector that ingests cloud-native logs instead of recognizing that CEF over Syslog requires a dedicated forwarder or AMA-based collection path.

How to eliminate wrong answers

Option B is wrong because the Azure Activity connector ingests Azure subscription-level operational logs (e.g., resource creation, policy changes), not third-party firewall syslog data. Option C is wrong because the Microsoft Entra ID Protection connector ingests risk detection and user risk events from Entra ID, not firewall logs. Option D is wrong because the Office 365 connector ingests audit and activity logs from Exchange, SharePoint, and Teams, not syslog-based firewall events.

118
MCQhard

A security team uses Microsoft Sentinel. They create a scheduled analytics rule that queries Azure Activity Logs to detect virtual machines deployed in non-approved regions. The rule generates an incident. The team wants the incident to be automatically assigned to the 'Infrastructure' team and its severity set to 'High' when it is created. Which automation feature should they use?

A.Create an automation rule with trigger 'When incident is created' and actions to assign the incident to an owner and set severity
B.Create a playbook triggered by alert creation that performs the assignment and severity change
C.Use an automation rule with trigger 'When incident is updated' and condition on alert type
D.Configure the analytics rule directly to set severity and owner
AnswerA

Automation rules in Microsoft Sentinel are the native, low-latency mechanism for incident lifecycle operations, and the 'When incident is created' trigger fires within seconds of an incident being generated by an analytics rule. By specifying actions that assign an owner and set severity, the rule applies these changes deterministically and immediately, without requiring a playbook to be invoked. This is the recommended and simplest way to ensure the incident appears in the SOC queue with the correct owner and severity from the very first moment.

Why this answer

Automation rules in Microsoft Sentinel allow you to define triggers such as 'When incident is created' and then perform actions like assigning the incident to an owner and setting its severity. This is the native, no-code way to automate incident management without requiring a playbook or modifying the analytics rule itself.

Exam trap

The trap here is that candidates often confuse playbooks (which are triggered by alerts and require Logic Apps) with automation rules (which are triggered by incident lifecycle events and are simpler to configure), leading them to select Option B instead of the correct automation rule approach.

How to eliminate wrong answers

Option B is wrong because playbooks are triggered by alerts, not by incident creation, and they require additional configuration and logic apps, making them more complex than necessary for simple assignment and severity changes. Option C is wrong because the trigger 'When incident is updated' would not fire at incident creation time, so the assignment and severity would not be applied automatically when the incident is first generated. Option D is wrong because analytics rules do not have native settings to directly assign an owner or set severity; those properties are managed at the incident level, not within the rule definition.

119
MCQmedium

A security team uses Microsoft Sentinel. They have created a playbook that isolates a virtual machine by modifying a network security group rule. They want this playbook to execute automatically whenever a new incident of type 'Suspicious VM activity' is created. Which Microsoft Sentinel feature should they use to trigger the playbook?

A.Analytics rule
B.Automation rule
C.Playbook
D.Hunt
AnswerB

Automation rules are a built-in incident orchestration feature in Sentinel that activate when defined conditions are met—for example, when an incident is created. They can perform a variety of actions, including running a playbook as an automated response. Since they directly associate incident triggers with playbook execution, automation rules are the correct component to automatically start a playbook when a security incident is raised.

Why this answer

Automation rules in Microsoft Sentinel allow you to define triggers that automatically run playbooks when incidents are created or updated. In this scenario, the automation rule can be configured to trigger on incident creation with the condition 'Suspicious VM activity' and then execute the playbook that modifies the NSG rule to isolate the VM. This is the correct mechanism because automation rules are designed specifically for incident-based triggers, unlike analytics rules which generate alerts or incidents.

Exam trap

The trap here is confusing the playbook (the action) with the trigger (automation rule), leading candidates to select 'Playbook' as the trigger instead of recognizing that automation rules are the mechanism to invoke playbooks automatically on incident creation.

How to eliminate wrong answers

Option A is wrong because analytics rules are used to generate alerts or incidents from data sources, not to trigger playbooks in response to existing incidents. Option C is wrong because a playbook is the set of actions (like modifying an NSG rule) that runs, not the trigger mechanism itself; playbooks must be invoked by an automation rule or manually. Option D is wrong because Hunts are manual, ad-hoc investigations to find threats, not automated triggers for incident response.

120
Drag & Dropmedium

Drag and drop the steps to configure Azure Application Gateway with SSL termination using a Key Vault certificate into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

SSL termination requires a certificate from Key Vault, configured on the listener.

121
Multi-Selecthard

A KQL query in Microsoft Sentinel detects impossible travel but returns many false positives from known VPN egress IP addresses. Which two changes would best reduce noise while preserving useful detections?

Select 2 answers
A.Join or filter against a watchlist of approved VPN egress IPs
B.Disable the SigninLogs connector for the tenant
C.Exclude events where the source IP is in the approved network list
D.Raise the query frequency from 1 hour to 24 hours
AnswersA, C

Joining SigninLogs against a Sentinel watchlist of approved VPN egress IPs lets the query remove or tag sign-ins originating from trusted corporate VPN ranges before the impossible-travel logic is applied. A watchlist is the maintainable, centrally managed artifact for this, and the KQL join (or lookup) against _GetWatchlist('VPN-Egress') is the canonical way to enrich or filter anomalies. This directly targets the false-positive source while preserving all other sign-in telemetry.

Why this answer

Integrating a watchlist of known VPN egress IPs allows the KQL query to filter out these trusted IPs, reducing false positives from impossible travel detections. Option C is also correct because excluding events where the source IP is in an approved network list directly removes noise from legitimate VPN traffic, preserving detection of truly anomalous sign-ins. Both approaches leverage Sentinel's watchlist or allowlist capabilities to maintain detection fidelity while minimizing alert fatigue.

Exam trap

The trap here is that candidates may confuse reducing alert frequency (Option D) with reducing false positives, or think disabling a data connector (Option B) is a valid noise-reduction technique, when in fact both actions cripple detection capability rather than refining it.

122
MCQhard

A security analyst uses Microsoft Defender for Cloud. They need to continuously monitor the security posture of their Azure subscription against the Microsoft cloud security benchmark (MCSB). They want to see the current compliance score and specific recommendations for failing controls. Which Defender for Cloud feature should they use?

A.Regulatory compliance dashboard
B.Security posture
C.Workbooks
D.Advanced hunting
AnswerA

The regulatory compliance dashboard continuously assesses resources against MCSB controls, displaying the current compliance score and per-control recommendations for failing items. It satisfies the requirement for ongoing posture monitoring with both an aggregate score and specific remediation guidance, unlike one-off secure score snapshots or alert-based features.

Why this answer

The Regulatory compliance dashboard in Microsoft Defender for Cloud is specifically designed to track compliance against standards like the Microsoft cloud security benchmark (MCSB). It provides a current compliance score and lists specific recommendations for failing controls, enabling continuous monitoring and remediation tracking. This dashboard aggregates assessment results from the secure score and maps them to the controls defined in the selected regulatory standard.

Exam trap

The trap here is that candidates often confuse the 'Security posture' feature (which shows a general secure score) with the 'Regulatory compliance dashboard' (which maps that score to a specific regulatory standard like MCSB), leading them to choose the wrong option because they overlook the requirement for standard-specific compliance tracking.

How to eliminate wrong answers

Option B (Security posture) is wrong because the Security posture feature focuses on the overall secure score and security recommendations based on best practices, not on mapping to a specific regulatory standard like MCSB. Option C (Workbooks) is wrong because Workbooks are customizable Azure Monitor dashboards that can visualize data from multiple sources, but they do not natively provide the out-of-the-box compliance score and control mapping against MCSB. Option D (Advanced hunting) is wrong because Advanced hunting is a query-based threat hunting tool in Microsoft 365 Defender for investigating security incidents, not for monitoring compliance posture or regulatory benchmarks.

123
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) for the Global Administrator role. They want to ensure that when a user activates the role, the activation request must be approved by a member of the 'Global Admin Approvers' group, and the activation should be time-bound with a maximum of 4 hours. Which PIM settings should they configure?

A.Set the activation maximum duration to 4 hours and require approval from the 'Global Admin Approvers' group.
B.Set the activation maximum duration to 4 hours and enable MFA on activation.
C.Set the activation to require a ticket number justification and set the maximum duration to 8 hours.
D.Set the role to be permanently active but with a just-in-time approval workflow.
AnswerA

Setting the activation maximum duration to 4 hours directly enforces the time limit requirement in PIM's role settings, while requiring approval from the 'Global Admin Approvers' group ensures that every activation request is explicitly reviewed and approved before the role becomes active. This is the only option that fully aligns with both stated conditions: a 4-hour window and an approval workflow with the designated group.

Why this answer

Azure AD PIM allows you to configure role activation settings, including an activation maximum duration (which can be set to 4 hours) and requiring approval from a specified group (in this case, 'Global Admin Approvers'). These settings directly meet the requirement for time-bound activation with approval.

Exam trap

The trap here is that candidates may confuse 'require approval' with 'require MFA' or 'require justification', not realizing that approval is a distinct setting that must be explicitly configured to meet the requirement for a designated approver group.

How to eliminate wrong answers

Option B is wrong because enabling MFA on activation does not satisfy the requirement for approval from the 'Global Admin Approvers' group; MFA is an additional security measure, not a substitute for approval. Option C is wrong because requiring a ticket number justification does not enforce approval, and setting the maximum duration to 8 hours exceeds the required 4-hour limit. Option D is wrong because setting the role to be permanently active contradicts the requirement for time-bound activation, and just-in-time approval workflow does not enforce a maximum duration.

124
MCQmedium

A security engineer wants Defender for Cloud to detect threats against Azure SQL Database and SQL Server on Azure VMs. Which plan should be enabled?

A.Defender for Storage
B.Defender for Databases or Defender for SQL coverage as presented in the portal
C.Defender for App Service only
D.Defender External Attack Surface Management
AnswerB

Enabling Defender for Databases or Defender for SQL coverage in the Defender for Cloud portal activates SQL Advanced Threat Protection for supported engines such as Azure SQL Database, SQL Managed Instance, Azure Synapse dedicated SQL pools, and SQL Server on Azure VMs. This control analyzes database audit logs and query activity in real time to detect SQL injection, anomalous access, and brute-force attempts. It is the direct and correct mechanism for database threat detection in Defender for Cloud.

Why this answer

Defender for Databases (or the Defender for SQL coverage option in the portal) is the correct plan because it provides threat detection specifically for Azure SQL Database and SQL Server on Azure VMs. This plan monitors anomalous activities such as SQL injection, brute-force attacks, and unusual access patterns using Microsoft's threat intelligence and machine learning models. It is the only plan that directly covers both PaaS and IaaS SQL workloads as described.

Exam trap

The trap here is that candidates may confuse 'Defender for Storage' with protecting SQL databases because SQL databases store data, but Defender for Storage is specifically for blob, file, and data lake storage, not for relational database engines like SQL Server or Azure SQL Database.

How to eliminate wrong answers

Option A is wrong because Defender for Storage is designed to detect threats against Azure Blob Storage, Azure Files, and Data Lake Storage, not against SQL databases or SQL Server instances. Option C is wrong because Defender for App Service only protects web applications running on Azure App Service, not SQL databases or SQL Server on VMs. Option D is wrong because Defender External Attack Surface Management focuses on discovering and monitoring an organization's external internet-facing assets and attack surfaces, not on detecting threats within Azure SQL Database or SQL Server on VMs.

125
MCQeasy

You are the Azure Security Engineer for a company that uses Microsoft Entra ID. The company has a policy that all administrative accounts must use multi-factor authentication (MFA) when signing in. You need to enforce this policy for a group of administrators. What is the simplest way to achieve this?

A.Create a Conditional Access policy that requires MFA for the administrator group when accessing all cloud apps.
B.Configure per-user MFA for each administrator account.
C.Enable security defaults in Microsoft Entra ID.
D.Create a Microsoft Entra ID Protection sign-in risk policy that requires MFA for administrators.
AnswerA

A Conditional Access policy can be targeted to a specific group of administrators and require MFA for all cloud apps. This is the simplest and most direct method to enforce MFA for that group. It provides granular control and can be easily managed. This meets the requirement without affecting other users.

Why this answer

The simplest way to enforce MFA for a specific group of administrators is to create a Conditional Access policy that targets that group and requires MFA for all cloud apps. This provides granular control and is easy to manage. Other options either apply to all users, require manual per-user settings, or are risk-based rather than always-on.

Exam trap

The trap here is choosing security defaults or per-user MFA, which are either too broad or too manual, instead of the targeted Conditional Access policy.

126
MCQmedium

A company uses Azure Active Directory (Azure AD) and wants to regularly review the membership of a group that grants access to a critical application. Each member must attest their continued need for access. Which Azure AD feature should they use?

A.Azure AD Identity Governance access reviews
B.Azure AD Privileged Identity Management (PIM)
C.Azure AD Conditional Access
D.Azure AD Identity Protection
AnswerA

Access reviews in Azure AD Identity Governance are the native mechanism for recurring membership attestation. You can target an Azure AD group, application, or access package, and select reviewers—such as resource owners or the members themselves—to confirm each user still needs access. A review can be configured to recur automatically, and the completion logic can remove denied or non-responsive users from the group. This directly matches the requirement to periodically attest group membership and remediate stale access.

Why this answer

Azure AD Identity Governance access reviews enable administrators to create recurring reviews of group memberships, requiring each member to attest their continued need for access. This directly addresses the requirement for regular attestation of group membership for a critical application, as it automates the review process and ensures compliance.

Exam trap

The trap here is that candidates often confuse Privileged Identity Management (PIM) with access reviews, but PIM is for privileged roles (e.g., Global Administrator) while access reviews are for any group or application access, including non-privileged memberships.

How to eliminate wrong answers

Option B is wrong because Azure AD Privileged Identity Management (PIM) is designed for just-in-time privileged role activation and oversight, not for regular attestation of standard group membership access. Option C is wrong because Azure AD Conditional Access enforces access policies based on conditions like location or device state, but does not provide a mechanism for users to attest their need for access. Option D is wrong because Azure AD Identity Protection focuses on detecting and responding to identity risks (e.g., compromised credentials), not on periodic membership attestation.

127
MCQmedium

A team wants Sentinel incidents to automatically assign to the Tier 2 queue when severity is High and the product name is Microsoft Defender for Endpoint. What should they configure?

A.A workbook with a dropdown filter
B.A watchlist containing Tier 2 users only
C.An automation rule that updates owner/status based on conditions
D.A data retention policy
AnswerC

An automation rule in Microsoft Sentinel runs when an incident is created or updated and can evaluate conditions such as severity, service, or entity prior to executing actions. Its actions include setting the incident's owner (using a user or group name) and updating its status to Active, which directly satisfies the team's requirement to automatically assign incidents. Rules can also be ordered to ensure assignment happens before other processing, and they provide a consistent, auditable method for ownership.

Why this answer

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific owners or queues based on conditions like severity and product name. By configuring an automation rule with a condition that triggers when severity equals 'High' and the product name is 'Microsoft Defender for Endpoint', you can set the incident owner to a specific user or group (e.g., Tier 2 queue) and optionally update the status. This directly meets the requirement without manual intervention.

Exam trap

The trap here is that candidates confuse watchlists or workbooks with operational automation, thinking they can be used for real-time incident routing, when in fact they are designed for data enrichment and visualization, not for triggering actions on incidents.

How to eliminate wrong answers

Option A is wrong because a workbook with a dropdown filter is a visualization tool for querying and displaying data, not for automating incident assignment or ownership changes. Option B is wrong because a watchlist is a static list of values used for correlation or enrichment in analytics rules, not for dynamically assigning incidents to users or queues. Option D is wrong because a data retention policy controls how long log data is stored, not how incidents are routed or assigned.

128
Drag & Dropmedium

Drag and drop the steps to assign an Azure RBAC role to a user at the resource group scope into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

IAM is used for RBAC, and you add a role assignment by selecting the role and assigning it to a user.

129
MCQmedium

A company uses Azure AD Identity Protection and Conditional Access. A user is detected with a 'High' user risk level due to suspicious activity. The security team wants to automatically block sign-ins for this user, but only when the sign-in originates from a location that is not in the company's list of trusted IPs. They have created a Conditional Access policy targeting all users. Which configuration should they add to the policy to achieve this?

A.Add a condition for 'User risk' set to 'High', and a condition for 'Sign-in risk' set to 'High', then grant 'Block access'.
B.Add a condition for 'User risk' set to 'High' and exclude 'All trusted locations' under the 'Locations' condition, then grant 'Block access'.
C.Add a condition for 'User risk' set to 'High', and under 'Grant', select 'Require multi-factor authentication' and 'Block access'.
D.Add a condition for 'Locations' set to 'Any location' and under 'Grant', select 'Block access' for all users.
AnswerB

This is correct because it combines the specific condition—User risk High—with a location exclusion for all trusted IP ranges, ensuring the block only applies to sign-ins that originate from untrusted locations. Conditional Access evaluates the user risk condition and the location condition together, and with the grant control set to Block access, any matching sign-in is denied. This matches the requirement precisely: only high user risk accounts attempting sign-in from outside the corporate network are blocked.

Why this answer

It combines a condition for 'User risk' set to 'High' with an exclusion of 'All trusted locations' under the 'Locations' condition, then grants 'Block access'. This ensures that the block only applies when the sign-in originates from an untrusted location, meeting the requirement to automatically block sign-ins for high-risk users only from locations not in the company's trusted IP list.

Exam trap

The trap here is that candidates often confuse 'User risk' with 'Sign-in risk' or incorrectly combine 'Block access' with other grant controls, failing to realize that 'Block access' must be the sole grant control and that excluding trusted locations is the correct way to scope the policy to untrusted locations only.

How to eliminate wrong answers

Option A is wrong because it adds a condition for 'Sign-in risk' set to 'High', which is unnecessary and not required; the requirement only specifies 'User risk', and adding 'Sign-in risk' would narrow the policy to only block when both risks are high, potentially missing the intended scenario. Option C is wrong because it selects 'Require multi-factor authentication' alongside 'Block access' under Grant; 'Block access' cannot be combined with other grant controls, and MFA would not block access but instead require additional verification, which does not achieve the automatic block goal. Option D is wrong because it sets 'Locations' to 'Any location' without excluding trusted locations, and grants 'Block access' for all users; this would block all sign-ins from any location, ignoring the requirement to only block when the location is not trusted.

130
MCQeasy

A company develops a web application that runs on Azure App Service. The application needs to access Azure Key Vault to retrieve secrets. The security team wants to avoid using service principals or connection strings. Which identity should they assign to the App Service to authenticate to Key Vault?

A.System-assigned managed identity
B.User-assigned managed identity
C.Azure AD application registration with a client secret
D.Azure AD service principal with certificate-based authentication
AnswerA

A system-assigned managed identity is automatically provisioned for the App Service and is tied to the resource's lifecycle. It can be granted access to Key Vault via RBAC or access policies, and the application code uses Azure SDK to obtain tokens without handling secrets.

Why this answer

A system-assigned managed identity is the correct choice because it provides an automatically managed identity in Azure AD, directly tied to the App Service resource, without requiring any credentials to be stored or rotated. This allows the App Service to authenticate to Key Vault using Azure AD tokens, eliminating the need for service principals or connection strings. The security team's requirement to avoid service principals or connection strings is fully met, as the identity is managed entirely by Azure.

Exam trap

The trap here is that candidates often confuse user-assigned managed identities (Option B) as the only managed identity option, overlooking that system-assigned managed identities are simpler and fully meet the requirement to avoid service principals or connection strings without additional resource management.

How to eliminate wrong answers

Option B is wrong because a user-assigned managed identity, while also avoiding service principals and connection strings, is a standalone resource that must be explicitly created and assigned to the App Service, adding management overhead that the security team's requirement to avoid service principals or connection strings does not necessitate; the simpler system-assigned identity suffices. Option C is wrong because an Azure AD application registration with a client secret is a form of service principal that requires storing and rotating a secret, directly violating the security team's directive to avoid service principals or connection strings. Option D is wrong because an Azure AD service principal with certificate-based authentication is still a service principal, requiring certificate management and lifecycle, which contradicts the requirement to avoid service principals entirely.

131
Multi-Selectmedium

A managed identity is used by an Azure Function to access Key Vault. Which two configurations are required?

Select 2 answers
A.A client secret stored in the function app settings
B.A system-assigned or user-assigned managed identity enabled on the function app
C.A public IP address on the function app
D.Key Vault permissions granted to that managed identity
AnswersB, D

Enabling a system-assigned or user-assigned managed identity on the function app creates an Azure AD identity automatically managed by Azure and tied to the app's lifecycle. The function can then request an access token from the Azure Instance Metadata Service (IMDS) endpoint without any stored secrets, which is exactly the mechanism required to securely authenticate to an Azure key vault.

Why this answer

A managed identity (either system-assigned or user-assigned) provides an Azure AD-authenticated identity for the function app, eliminating the need for credentials like client secrets. This identity is used to obtain an Azure AD access token for authenticating to Key Vault. Option D is also required because the managed identity must be granted explicit Key Vault permissions (e.g., via an access policy or RBAC role) to read secrets; without these permissions, token-based authentication will fail with a 403 Forbidden error.

Exam trap

The trap here is that candidates often assume a client secret (Option A) is required for any Azure AD authentication, failing to recognize that managed identities provide a passwordless, credential-free authentication mechanism via Azure AD tokens.

132
MCQmedium

A security team has a list of known malicious IP addresses from an external threat intelligence feed in CSV format. They want to import this list into Microsoft Sentinel and use it in analytics rules to detect incoming attacks. Which feature should they use?

A.Watchlists
B.Threat intelligence indicators
C.Bookmark
D.User and Entity Behavior Analytics (UEBA)
AnswerA

Watchlists are the correct choice because Microsoft Sentinel's Watchlists feature allows you to import CSV files directly and store them in your workspace, making them queryable via the _GetWatchlist function. You can create a watchlist from a CSV containing your known malicious IP addresses, then reference it in analytics rules with KQL to match against incoming events, enabling custom threat intelligence without a formal TI feed.

Why this answer

Watchlists in Microsoft Sentinel allow you to import external data sources, such as CSV files containing known malicious IP addresses, and use them directly in analytics rules for detection. This feature is designed for lightweight, custom threat intelligence that doesn't require the full threat intelligence indicator (TI) lifecycle, making it ideal for ad-hoc lists from CSV feeds.

Exam trap

The trap here is confusing Watchlists with Threat intelligence indicators, as both can handle IP lists, but TI indicators require a formal TI platform integration and STIX/TAXII protocols, whereas Watchlists are the correct choice for simple CSV imports without additional infrastructure.

How to eliminate wrong answers

Option B is wrong because Threat intelligence indicators are used for structured, normalized threat data (e.g., STIX format) and require integration with a TI platform or API, not direct CSV import. Option C is wrong because Bookmarks are used to preserve specific search results or investigation states for later review, not to import external threat data for rule-based detection. Option D is wrong because User and Entity Behavior Analytics (UEBA) is a behavioral analytics feature that profiles user and entity activities to detect anomalies, not a mechanism for importing static IP lists.

133
MCQmedium

A security operations team uses Microsoft Sentinel to centralize security monitoring across their hybrid environment. They need to ingest AWS CloudTrail logs from an Amazon Web Services account to detect suspicious activities in their AWS environment. Which data connector should they configure in Microsoft Sentinel?

A.Azure Activity log connector
B.AWS CloudTrail connector
C.Syslog connector
D.Common Event Format (CEF) connector
AnswerB

The AWS CloudTrail connector is the purpose-built Data Connector in Microsoft Sentinel that ingests CloudTrail management and data events by reading a trail's Amazon S3 bucket, with optional SQS queue delivery for near real-time event collection. It requires you to create an AWS IAM role (with a cross-account or same-account trust) and configure the trail to forward logs to Sentinel, after which the connector normalizes AWS logs into the AWSCloudTrail table. This makes it the only option among these that directly supports the centralization of AWS security logs into Sentinel.

Why this answer

The AWS CloudTrail connector is the correct data connector for ingesting AWS CloudTrail logs into Microsoft Sentinel. It requires configuring an S3 bucket in AWS to receive CloudTrail logs and then connecting that bucket to Sentinel via the connector, enabling the detection of suspicious activities such as unauthorized API calls or privilege escalations in the AWS environment.

Exam trap

The trap here is that candidates may confuse the Azure Activity log connector with a generic cloud activity log connector, but it only works for Azure, not for AWS CloudTrail.

How to eliminate wrong answers

Option A is wrong because the Azure Activity log connector is designed to ingest logs from Azure subscription-level events, not from external cloud providers like AWS. Option C is wrong because the Syslog connector is used to collect logs from on-premises or network devices using the syslog protocol (UDP/TCP), not from AWS CloudTrail. Option D is wrong because the Common Event Format (CEF) connector is used to ingest logs from security appliances that forward CEF-formatted syslog messages, such as firewalls or IDS/IPS, not from AWS CloudTrail.

134
MCQhard

A custom Azure role should allow operators to restart virtual machines but not delete them or change networking. Which permission design is most appropriate?

A.Assign Contributor at the resource group scope
B.Create a custom role with Microsoft.Compute/virtualMachines/restart/action and required read permissions at the narrowest scope
C.Assign Virtual Machine Contributor at subscription scope
D.Assign Reader and ask operators to use Run Command
AnswerB

This is the correct approach because a custom role definition containing exactly Microsoft.Compute/virtualMachines/restart/action and Microsoft.Compute/virtualMachines/read provides only the control-plane action needed to restart a VM and the read permission required for the resource to be displayed and identified in Azure. By then assigning this custom role at the narrowest scope, such as the specific virtual machine resource, you guarantee operators cannot affect any other VM or resource. This satisfies the stated requirement while adhering to least privilege and is the most direct, security-focused solution.

Why this answer

It grants the specific 'restart/action' permission on virtual machines while excluding destructive actions like delete or network changes. Custom roles in Azure RBAC allow fine-grained control by including only the required data actions and read permissions, ensuring operators can restart VMs without the ability to delete them or modify networking.

Exam trap

The trap here is that candidates often confuse built-in roles like Contributor or Virtual Machine Contributor with the ability to restrict actions, not realizing these roles include delete and network write permissions that exceed the narrow restart-only requirement.

How to eliminate wrong answers

Option A is wrong because the Contributor role at any scope includes full management rights, allowing deletion and network changes, which violates the requirement. Option C is wrong because Virtual Machine Contributor at subscription scope includes permissions to delete VMs and modify networking (e.g., Microsoft.Network/*), exceeding the allowed actions. Option D is wrong because Reader only provides read access and does not include the restart action; Run Command is a separate feature that requires additional permissions and does not grant the restart capability.

135
MCQmedium

A security engineer connects Azure virtual machines to Microsoft Defender for Cloud. The team wants vulnerability findings without installing a vulnerability scanner extension on each VM. Which capability should be enabled?

A.Agentless vulnerability assessment for machines in Defender for Servers
B.Microsoft Sentinel User and Entity Behavior Analytics
C.Azure Firewall threat intelligence mode
D.Microsoft Entra Identity Protection sign-in risk
AnswerA

Agentless vulnerability assessment in Defender for Servers scans Azure VM operating system and installed software against the Microsoft Defender Vulnerability Management knowledge base without deploying any agent or extension on the machine. It leverages Azure-native metadata and managed disk snapshots to identify missing security updates and misconfigurations, directly satisfying the requirement to find vulnerabilities without agent installation. This makes it the correct solution for the scenario.

Why this answer

Agentless vulnerability assessment for machines in Defender for Servers is the correct capability because it uses Microsoft Defender for Cloud's built-in scanning engine to assess VMs for vulnerabilities without requiring any agent or extension installation. This feature leverages the VM's existing configuration and cloud APIs to perform scans, meeting the team's requirement to avoid installing a vulnerability scanner extension on each VM.

Exam trap

The trap here is that candidates often assume vulnerability scanning always requires an agent or extension, but Microsoft Defender for Cloud offers an agentless option that uses cloud-native APIs and OS-level data to perform assessments without any local software.

How to eliminate wrong answers

Option B is wrong because Microsoft Sentinel User and Entity Behavior Analytics (UEBA) is a security analytics feature that detects anomalous user and entity behavior, not a vulnerability assessment tool for VMs. Option C is wrong because Azure Firewall threat intelligence mode filters traffic based on known malicious IPs and domains, but it does not scan VMs for vulnerabilities. Option D is wrong because Microsoft Entra Identity Protection sign-in risk evaluates sign-in risks for user identities, not vulnerabilities on Azure virtual machines.

136
MCQeasy

A security team uses Microsoft Defender for Cloud to improve their security posture across multiple subscriptions. They want to quickly identify which security recommendations have the highest potential to improve their security score if remediated. Which dashboard or feature should they use?

A.Regulatory Compliance dashboard
B.Security Alerts dashboard
C.Secure Score dashboard
D.Inventory dashboard
AnswerC

The Secure Score dashboard is the correct location because it is built around the secure score calculation and assigns a concrete score increase to every recommendation in the Microsoft cloud security benchmark. Each recommendation shows 'Potential score increase' alongside the number of affected resources and health status, letting teams compare high-impact controls like enabling MFA against lower-priority hardening steps. This direct linkage between remediation actions and numeric score gain is exactly the prioritization information the security team needs.

Why this answer

The Secure Score dashboard in Microsoft Defender for Cloud is specifically designed to show security recommendations ranked by their potential impact on the overall security score. Each recommendation includes a 'score impact' value, allowing the team to prioritize remediation actions that will most effectively improve their security posture across multiple subscriptions.

Exam trap

The trap here is that candidates may confuse the Secure Score dashboard with the Regulatory Compliance dashboard, thinking compliance improvements always correlate with security score gains, but the Secure Score dashboard is the only tool that explicitly quantifies the score impact of each recommendation.

How to eliminate wrong answers

Option A is wrong because the Regulatory Compliance dashboard focuses on compliance with standards like ISO 27001 or SOC 2, not on prioritizing recommendations for score improvement. Option B is wrong because the Security Alerts dashboard displays active threats and incidents, not recommendations for proactive security hardening. Option D is wrong because the Inventory dashboard provides a list of resources and their configurations, but does not rank recommendations by score impact.

137
MCQmedium

A security operations team uses Microsoft Sentinel. They want to enable User and Entity Behavior Analytics (UEBA) to detect anomalous user activities. Which configuration is required?

A.Enable UEBA in the Sentinel settings
B.Install the UEBA data connector
C.Create an analytics rule with UEBA template
D.Assign the Security Reader role to Sentinel
AnswerA

UEBA must be explicitly turned on in Microsoft Sentinel by navigating to Settings > Entity behavior and toggling the feature. It does not require any separate deployment or data source configuration because it operates on data already ingested through existing connectors, such as Azure Active Directory and Windows Security Events. The toggle immediately activates behavioral profiling for entities like users and hosts, so without this action, no UEBA-based alerts or insights will appear.

Why this answer

UEBA in Microsoft Sentinel is a built-in feature that must be explicitly enabled in the Sentinel configuration settings under 'Entity behavior analytics'. It does not require a separate data connector or analytics rule template; once enabled, Sentinel automatically ingests and analyzes existing log data (e.g., Azure AD sign-ins, Office 365 audit logs) to establish behavioral baselines and detect anomalies.

Exam trap

The trap here is that candidates often confuse enabling a feature with installing a connector or creating a rule, but UEBA is a toggle in Sentinel settings, not a data source or alert rule.

How to eliminate wrong answers

Option B is wrong because UEBA does not have a dedicated data connector; it leverages data already collected by other connectors (e.g., Azure AD, Office 365, Windows Security Events). Option C is wrong because UEBA is not activated by creating an analytics rule with a template; it is a platform-level feature that must be toggled on in settings, after which anomaly detection rules are automatically generated. Option D is wrong because assigning the Security Reader role to Sentinel does not enable UEBA; it only grants read permissions to Sentinel resources, not the behavioral analytics engine.

138
MCQhard

An analyst creates a Sentinel automation rule and a playbook. The playbook should run only when incidents are created from a specific analytics rule and severity is High. Where should this filtering be configured?

A.Automation rule conditions
B.Logic App recurrence trigger
C.Log Analytics workspace retention settings
D.Analytics rule suppression only
AnswerA

Automation rule conditions are the correct answer because Microsoft Sentinel automation rules evaluate real-time alert or incident attributes—such as severity, status, entity types, and custom property values—against defined conditions. Only when every condition is satisfied does the rule invoke the linked Logic App playbook, providing precise, context-aware automation. This is exactly how Sentinel is designed to conditionally run playbooks, unlike the other options.

Why this answer

Automation rules in Microsoft Sentinel are designed to trigger actions based on incident creation or update events. By configuring conditions within the automation rule, you can specify that the associated playbook should only run when the incident is created from a specific analytics rule and has a severity of High. This is the correct and intended location for such filtering, as automation rules evaluate conditions before invoking the playbook.

Exam trap

The trap here is that candidates may confuse automation rule conditions with analytics rule suppression or Logic App triggers, mistakenly thinking filtering should be done at the analytics rule or Logic App level rather than in the automation rule that orchestrates the playbook execution.

How to eliminate wrong answers

Option B is wrong because the Logic App recurrence trigger is used for scheduled, time-based execution, not for event-driven responses to Sentinel incidents; it cannot filter on analytics rule or severity at incident creation. Option C is wrong because Log Analytics workspace retention settings control how long data is stored, not the triggering conditions for playbooks or automation rules. Option D is wrong because analytics rule suppression only prevents the rule from creating incidents or alerts for a specified period after an alert is generated; it does not filter which incidents trigger a playbook.

139
MCQmedium

A company uses Azure AD Privileged Identity Management (PIM) to manage the 'Security Administrator' role. They want users who activate this role to provide a justification and a support ticket number, and they want the activation to expire after a maximum of 4 hours. Which PIM role settings should they configure?

A.Configure the activation maximum duration only
B.Configure the requirement for justification only
C.Configure the requirement for ticket information only
D.Configure the activation maximum duration, require justification, and require ticket information in the role settings
AnswerD

In Azure AD PIM, the role settings for an eligible role contain separate toggles for maximum activation duration (in hours), requiring justification, and requiring ticket information. To enforce the exact policy in the scenario, all three must be configured: set the activation maximum duration to 4 hours, turn on 'Require justification' so a reason is entered, and turn on 'Require ticket information' so a support ticket number is provided. This ensures every activation is time-boxed, justified, and tied to an audit record, meeting the company's security and compliance requirements.

Why this answer

The scenario requires all three conditions: a maximum activation duration of 4 hours, mandatory justification, and mandatory ticket information. In Azure AD PIM, these are independent settings within the role settings configuration, and all must be enabled to meet the stated requirements. Without configuring all three, the activation would not enforce the specified controls.

Exam trap

The trap here is that candidates might think justification and ticket information are a single combined requirement, or that duration is automatically enforced, when in fact each setting must be explicitly configured in PIM role settings.

How to eliminate wrong answers

Option A is wrong because configuring only the activation maximum duration ignores the requirements for justification and ticket information, leaving those controls unenforced. Option B is wrong because requiring only justification omits the ticket information and duration limit, so users could activate without a ticket and for longer than 4 hours. Option C is wrong because requiring only ticket information misses the justification and duration limit, allowing activations without a reason and for an indefinite or default duration.

140
MCQhard

A company uses Azure AD Privileged Identity Management (PIM) for the Security Administrator role. They have configured the role activation to require Azure Multi-Factor Authentication and a support ticket number. However, users are reporting that they can activate the role without entering a ticket number. What is the most likely cause?

A.The 'Require ticket information on activation' setting is not enabled in the role settings
B.Users are activating through the Azure AD overview page instead of the PIM blade
C.The activation policy requires approval but the approvers ignore the ticket field
D.The role is configured for 'Active' assignment instead of 'Eligible'
AnswerA

The 'Require ticket information on activation' setting is a per-role toggle in PIM's role settings. When disabled, the activation flow omits the ticket number field entirely, so users can activate without supplying any justification. Even if the organization expects tickets, PIM will not enforce or even ask for one unless this specific setting is turned on. In the Azure portal, navigate to Privileged Identity Management > Roles > [Role] > Settings > Edit, and enable the 'Require ticket information on activation' checkbox per role.

Why this answer

The 'Require ticket information on activation' setting is a separate toggle in the PIM role settings that must be explicitly enabled. Even if the support ticket number field is displayed in the activation form, the system will not enforce its entry unless this specific setting is turned on. Without it, users can leave the field blank and still successfully activate the role.

Exam trap

The trap here is that candidates assume the presence of a ticket number field in the activation form means it is required, but PIM separates the UI display from the enforcement toggle, so the setting must be explicitly enabled for the field to be mandatory.

How to eliminate wrong answers

Option B is wrong because the Azure AD overview page does not provide role activation capabilities; all PIM activations must go through the PIM blade or the Azure AD Roles and Administrators blade, and the enforcement of ticket information is controlled by the role settings regardless of the entry point. Option C is wrong because if the activation policy requires approval, the approver's behavior does not override the system's enforcement of the ticket field; the system itself would block activation if the setting were enabled. Option D is wrong because the assignment type (Active vs.

Eligible) determines whether the user needs to activate the role at all, but it does not affect the enforcement of ticket information during activation; an Eligible assignment is required for PIM activation, but the ticket setting is independent.

← PreviousPage 2 of 2 · 140 questions total

Ready to test yourself?

Try a timed practice session using only Manage identity and access questions.