Courseiva

CCNA Secure identity and access Questions

70 questions · Secure identity and access · All types, answers revealed

1
Multi-Selecthard

Which TWO features are available in Microsoft Entra ID Privileged Identity Management (PIM) for managing Azure AD roles? (Choose two.)

Select 2 answers
A.Self-service password reset
B.Just-in-time activation
C.Multi-factor authentication enforcement
D.Automatic role assignment based on group membership
E.Approval workflow for role activation
AnswersB, E

Just-in-time activation is a core PIM capability that lets administrators make eligible roles available for temporary, time-boxed elevation. When a user needs elevated privileges, they activate the role for a specific duration, often with a justification, MFA check, and optional scope constraints. This reduces standing access and implements the principle of least privilege.

Why this answer

Option B (Just-in-time activation) is correct because PIM's core capability is making users eligible for Azure AD roles and requiring them to activate the role only when needed, granting time-bound, temporary elevation instead of permanent assignment. Option E (Approval workflow for role activation) is correct because PIM role settings allow administrators to require approval before an eligible user's activation request is granted, with designated approvers reviewing the request. The other options do not belong: self-service password reset (A) is an Entra ID authentication feature, not a PIM role-management feature; multi-factor authentication enforcement (C) is configured via Conditional Access or authentication methods, not as a PIM role feature; and automatic role assignment based on group membership (D) is handled by group-based licensing/role-assignable groups, not by PIM activation.

Exam trap

The trap here is that candidates often confuse features that are integrated with PIM (like MFA enforcement and self-service password reset) as being features of PIM itself, when in fact PIM's core capabilities are just-in-time activation and approval workflows for role activation.

2
MCQeasy

Your organization uses Microsoft Entra ID and needs to implement a policy that blocks all sign-ins from countries that are not approved. What should you configure?

A.Enable multi-factor authentication for all users
B.Create a Conditional Access policy with a location condition set to block
C.Review sign-in logs and manually block IPs
D.Configure an Identity Protection risk policy
AnswerB

A Conditional Access policy with a location condition allows you to define named locations (such as specific countries or IP ranges) and explicitly block sign-ins originating from those locations. The policy is evaluated in real time during authentication, before token issuance, and can also be scoped to all cloud apps and specific users or groups. This directly enforces the requirement to restrict access by geographic location, making it the correct answer.

Why this answer

A Conditional Access policy in Microsoft Entra ID allows you to define location conditions based on IP ranges, countries, or regions. By configuring the location condition to include all countries except the approved ones and setting the access control to 'Block access', you can effectively block sign-ins from non-approved countries. This is the native, policy-driven approach to enforce geographic restrictions without manual intervention.

Exam trap

The trap here is that candidates often confuse location-based blocking with risk-based policies or MFA, assuming that adding authentication factors or reviewing logs can achieve geographic restrictions, but only a Conditional Access policy with a location condition provides a direct, automated block based on country.

How to eliminate wrong answers

Option A is wrong because enabling multi-factor authentication (MFA) for all users does not block sign-ins based on location; it only adds an additional verification step, which does not prevent access from unapproved countries. Option C is wrong because manually reviewing sign-in logs and blocking IPs is not scalable, does not cover dynamic IP ranges, and is not a policy-based solution; it also fails to address the requirement for a continuous, automated block. Option D is wrong because an Identity Protection risk policy focuses on detecting and responding to risky user behavior (e.g., leaked credentials, anonymous IP addresses) rather than enforcing static geographic restrictions based on country.

3
Multi-Selectmedium

Which TWO of the following are capabilities of Microsoft Entra ID Protection?

Select 2 answers
A.Conditional Access session controls
B.Sign-in risk policy
C.User risk policy
D.Access reviews
E.Role-based access control (RBAC)
AnswersB, C

Sign-in risk policy is a native Microsoft Entra ID Protection capability that automates responses to risky sign-in events. It evaluates real-time and offline risk detections (like impossible travel, anonymous IP addresses, or atypical sign-in behavior) and triggers actions such as requiring multi-factor authentication or blocking access. This policy is part of the risk-based protection model, not a generic access control, and is explicitly distinct from session controls or governance features.

Why this answer

Microsoft Entra ID Protection is specifically designed to detect identity-based risks and let administrators respond to them via two built-in policies: the sign-in risk policy (B), which evaluates each authentication attempt and can require MFA or block the sign-in when the sign-in is deemed risky, and the user risk policy (C), which evaluates the overall risk of a user account (for example, from leaked credentials) and can force a secure password change. Both B and C are core, out-of-the-box capabilities of Entra ID Protection and are configured directly in its Risk policies blade. Conditional Access session controls (A) are a feature of Conditional Access (sign-in frequency, app-enforced restrictions, Cloud App Security/Defender for Cloud Apps controls), not of ID Protection itself, even though risk signals can feed Conditional Access.

Access reviews (D) belong to Entra ID Governance (Identity Governance), and role-based access control (E) is the general authorization model used across Azure and Entra ID, not a risk-detection capability of ID Protection.

Exam trap

The trap here is that candidates often confuse the risk-based policies of Entra ID Protection (sign-in risk and user risk) with Conditional Access session controls or other Entra ID features like Access Reviews and RBAC, because all are part of the broader Entra ID suite but serve distinct functions.

4
MCQmedium

You are the security administrator for a company that uses Microsoft Entra ID. You need to configure a Conditional Access policy that applies to all users except the emergency break-glass accounts. The policy must require multi-factor authentication (MFA) when accessing the Azure portal from a location that is not trusted. What should you include in the policy?

A.Include all users, exclude break-glass accounts, require MFA for Azure portal, and use 'Locations' condition to specify untrusted locations
B.Include all users, require MFA for Azure portal, and exclude all administrators
C.Include break-glass accounts, require MFA for Azure portal, and block access from untrusted locations
D.Include all users, require MFA for Azure portal, and exclude break-glass accounts
AnswerA

This configuration is correct because it precisely implements the stated requirement: the policy includes every user, explicitly excludes break-glass accounts to preserve emergency access, triggers on the Azure portal cloud app, and uses the Conditions > Locations element to scope MFA to untrusted public networks. By selecting 'Any location' except trusted IPs, the policy will prompt for MFA only when a user signs in from outside the corporate network, avoiding excessive prompts on trusted IP ranges. This matches the directive to require MFA for all users except emergency access accounts from untrusted locations.

Why this answer

It includes all users, excludes the emergency break-glass accounts to ensure they remain accessible during outages, requires MFA for the Azure portal, and uses the 'Locations' condition to target untrusted locations. This configuration aligns with the requirement to enforce MFA only when accessing Azure portal from untrusted locations, while preserving access for break-glass accounts.

Exam trap

The trap here is that candidates often forget to include the 'Locations' condition to scope the MFA requirement to untrusted locations, leading them to choose Option D which requires MFA for all Azure portal access, not just from untrusted locations.

How to eliminate wrong answers

Option B is wrong because it excludes all administrators, which is too broad and would leave administrative accounts unprotected from untrusted locations, violating the requirement to apply the policy to all users except break-glass accounts. Option C is wrong because it includes break-glass accounts, which should be excluded to maintain their availability during emergencies, and it blocks access from untrusted locations instead of requiring MFA, which is overly restrictive. Option D is wrong because it lacks the 'Locations' condition to specify untrusted locations, so the policy would require MFA for all Azure portal access regardless of location, not just from untrusted locations.

5
MCQeasy

You need to assign the 'Security Administrator' role in Microsoft Entra ID to a user named User1. The role assignment must be eligible, and User1 must provide a justification when activating the role. What should you use?

A.Direct role assignment in Azure AD roles and administrators
B.Privileged Identity Management (PIM)
C.Global Administrator role with custom activation policy
D.User Administrator role with access reviews
AnswerB

Privileged Identity Management (PIM) lets you assign the Security Administrator role as 'eligible' rather than 'active'. The member then activates the role when needed, specifying a business justification and, if configured, obtains approval from designated approvers. This provides just-in-time, time-bound access with full audit logs, satisfying the requirement to assign the role securely and with least privilege.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID is the only service that supports time-bound, eligible role assignments with activation justification. By configuring a PIM policy for the Security Administrator role, you can require User1 to provide a business justification before the role is activated for a specified duration.

Exam trap

The trap here is that candidates confuse direct role assignment (which is permanent and active) with PIM's eligible assignment (which is time-bound and requires activation), leading them to choose Option A instead of B.

How to eliminate wrong answers

Option A is wrong because direct role assignment in Azure AD roles and administrators makes the role permanently active, not eligible, and does not enforce activation justification. Option C is wrong because the Global Administrator role cannot be assigned with a custom activation policy; activation policies are configured per role in PIM, not via a separate role assignment. Option D is wrong because the User Administrator role does not control activation justification for other roles; it manages user attributes and group memberships, not PIM activation policies.

6
MCQeasy

Your organization uses Microsoft Entra ID. You need to ensure that users can reset their own passwords without contacting IT. Which feature should you enable?

A.Identity Protection
B.Self-service password reset (SSPR)
C.Multifactor authentication
D.Password Protection
AnswerB

Self-service password reset (SSPR) is an Azure Active Directory (Entra ID) feature that lets users reset or unlock their own passwords without administrator intervention. When enabled, users must first register authentication methods (e.g., authenticator app, phone, or security questions), which are used to verify identity during the reset flow. Because the goal is explicitly to ensure users can reset their own passwords, SSPR is the correct control—it provides the user-facing, self-directed reset capability that the other options lack.

Why this answer

Self-service password reset (SSPR) is the correct feature because it allows users to reset their own passwords without IT intervention. SSPR integrates with Microsoft Entra ID and can be configured to require verification methods such as email, phone, or security questions before allowing a password change. This directly meets the requirement of enabling users to reset passwords independently.

Exam trap

The trap here is that candidates often confuse Multifactor Authentication (MFA) with SSPR, thinking MFA alone allows password resets, when in fact MFA is only a verification step within SSPR and does not provide the self-service reset functionality itself.

How to eliminate wrong answers

Option A is wrong because Identity Protection is a risk-based conditional access and detection tool that identifies potential vulnerabilities and suspicious sign-ins, but it does not provide password reset capabilities. Option C is wrong because Multifactor Authentication (MFA) adds an extra layer of security during sign-in but does not enable self-service password changes; it can be used as a verification method within SSPR but is not the feature itself. Option D is wrong because Password Protection is a feature that blocks weak or compromised passwords from being used in the directory, but it does not allow users to reset their own passwords.

7
MCQeasy

Your organization uses Microsoft Entra ID to manage identities. You need to ensure that users can reset their own passwords without help desk intervention, but they must register for self-service password reset (SSPR) first. Which configuration is required?

A.Configure Microsoft Entra Password Protection
B.Enable Privileged Identity Management for SSPR
C.Enable SSPR and set the registration campaign to require registration at next sign-in
D.Enable combined registration for SSPR and Microsoft Entra ID Protection
AnswerC

Self-Service Password Reset requires users to first register authentication methods — such as phone numbers, the Microsoft Authenticator app, or email addresses — so those methods can be challenged during reset. By enabling SSPR and setting the registration campaign to require registration at next sign-in, the directory ensures users are prompted to register before they need a reset, which is the critical success factor for SSPR adoption. This is the correct configuration because an SSPR policy is meaningless if users have no registered methods to verify their identity.

Why this answer

Enabling SSPR and configuring the registration campaign to require registration at next sign-in ensures users must register for SSPR before they can reset their own passwords. This satisfies the requirement that users register first, and the registration campaign enforces this without requiring help desk intervention.

Exam trap

The trap here is that candidates often confuse enabling SSPR with enforcing registration, or mistakenly think that combined registration or PIM automatically requires registration, when in fact only the registration campaign configuration forces the user to register before using SSPR.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Password Protection is a feature that detects and blocks weak passwords, not a mechanism to enforce SSPR registration or enable self-service password reset. Option B is wrong because Privileged Identity Management (PIM) is designed for just-in-time privileged access management, not for configuring or enforcing SSPR registration for all users. Option D is wrong because combined registration for SSPR and Microsoft Entra ID Protection allows users to register for both services simultaneously, but it does not enforce that users must register before they can reset their passwords; it only provides a unified registration experience.

8
Multi-Selectmedium

Which TWO actions should you take to implement a zero-trust identity model using Microsoft Entra ID? (Choose two.)

Select 2 answers
A.Configure password expiration policies to force frequent changes
B.Enable password hash synchronization to Azure AD
C.Configure Privileged Identity Management to require approval for role activation
D.Assign permanent Global Administrator roles to IT staff
E.Implement Conditional Access policies that require MFA and device compliance
AnswersC, E

Configuring Privileged Identity Management (PIM) to require approval for role activation enforces just-in-time (JIT) access, a core zero-trust tenet. With PIM, a role is eligible but not active; the user must request activation for a specific time window, and an approver must grant it, which limits standing privileges and reduces the attack surface. This also provides auditing and time-bound access, ensuring that privileged roles are never permanently available and that every activation is specifically authorized. This aligns with 'use least privilege access' and 'verify explicitly' because the approval step adds an explicit verification of requestor legitimacy.

Why this answer

Privileged Identity Management (PIM) enforces just-in-time (JIT) access by requiring approval for role activation, which aligns with the zero-trust principle of 'never trust, always verify' by eliminating standing privileges. Option E is correct because Conditional Access policies that require MFA and device compliance enforce continuous verification of user identity and device health before granting access, a core tenet of zero-trust identity.

Exam trap

The trap here is that candidates often confuse password hash synchronization (a hybrid sync tool) with a security control, or they mistakenly think password expiration policies are still a recommended zero-trust practice, when in fact zero-trust focuses on real-time verification and risk-based policies rather than static password rotation.

9
Multi-Selectmedium

Your organization uses Microsoft Entra ID and wants to implement a secure passwordless authentication strategy. Which TWO solutions can be used natively in Microsoft Entra ID for passwordless sign-in?

Select 2 answers
A.FIDO2 security keys
B.Microsoft Authenticator app with OTP
C.Third-party password managers
D.Windows Hello for Business
E.Duo Security push notifications
AnswersA, D

FIDO2 security keys are a natively supported passwordless authentication method in Microsoft Entra ID. They use public-key cryptography via the WebAuthn/CTAP2 protocol, where the private key never leaves the hardware key and the public key is registered with the tenant. Because sign-in requires a user gesture (e.g., PIN or touch) and the key's cryptographic assertion is tied to the specific site, it is phishing-resistant and does not require a password.

Why this answer

FIDO2 security keys are a native passwordless authentication method in Microsoft Entra ID, leveraging the WebAuthn standard to provide phishing-resistant, hardware-based credential verification. They eliminate passwords entirely by using public-key cryptography, where the private key never leaves the device, ensuring strong security against credential theft.

Exam trap

The trap here is that candidates confuse multi-factor authentication methods (like OTP or push notifications) with true passwordless authentication, which requires eliminating the password as a primary factor entirely, not just adding a second factor.

10
Multi-Selecteasy

Your company wants to implement a least-privilege model for administrative roles in Microsoft Entra ID. Which TWO features should you use?

Select 2 answers
A.Azure RBAC roles
B.Custom roles in Microsoft Entra ID
C.Conditional Access policies
D.Microsoft Entra B2B external identities
E.Privileged Identity Management (PIM)
AnswersB, E

Custom roles in Microsoft Entra ID allow you to define granular permissions by selecting specific tasks, such as reading audit logs or resetting passwords, that aren't combined into built-in roles. This lets you craft a role with exactly the permissions needed for a job, eliminating standing overprivileged access. By assigning such custom roles to principals, you implement least privilege at the directory level.

Why this answer

Custom roles in Microsoft Entra ID (option B) are correct because they let you define a precise set of directory permissions (for example, scoping actions like microsoft.directory/users/read) so administrators get only the access they need, which is the essence of least privilege. Privileged Identity Management (option E) is also correct because it enforces just-in-time activation of eligible directory roles with approval, MFA, and time-bound assignments, eliminating standing privileged access. Azure RBAC roles (option A) govern Azure resource-plane access, not Microsoft Entra ID administrative roles, so they don't address the directory role model in scope.

Conditional Access policies (option C) control sign-in conditions and access to resources but do not define or limit administrative role permissions. Microsoft Entra B2B external identities (option D) is about collaborating with external users, not about constraining administrative privileges.

Exam trap

The trap here is that candidates often confuse Azure RBAC roles (which manage Azure resources) with Microsoft Entra ID roles (which manage directory objects), leading them to incorrectly select Azure RBAC roles as a feature for Entra ID least-privilege administration.

11
MCQhard

Your organization uses Microsoft Entra ID with Privileged Identity Management (PIM). You need to ensure that all privileged role activations are approved by a manager and require a ticket number. What should you configure in PIM?

A.Role settings for the privileged role
B.Audit history
C.Alerts
D.Access reviews
AnswerA

In Privileged Identity Management (PIM) for Microsoft Entra ID roles, role settings configure the activation policy, including whether approval is required, what justification must be submitted, and the maximum duration the role stays active. Requiring users to submit an activation request that must be both justified and approved by designated approvers is the direct control that prevents arbitrary, self-service escalation to a privileged role.

Why this answer

In Microsoft Entra ID PIM, role settings for each privileged role allow you to configure approval requirements and justification fields. By editing the role settings, you can require approval from a designated approver (e.g., a manager) and mandate a ticket number in the justification field, ensuring compliance with organizational policies.

Exam trap

The trap here is that candidates may confuse role settings (which control activation policies) with audit history or alerts, thinking that logging or notifications can enforce approval requirements, but only role settings provide the configuration to mandate approvals and ticket numbers.

How to eliminate wrong answers

Option B (Audit history) is wrong because it only provides a log of past activations and changes, not a configuration mechanism to enforce approval or ticket number requirements. Option C (Alerts) is wrong because alerts are used to notify administrators of suspicious or anomalous activities, not to enforce approval workflows or mandatory fields. Option D (Access reviews) is wrong because access reviews are periodic recertifications of existing role assignments, not a setting to control activation conditions like approval or ticket numbers.

12
MCQeasy

You are troubleshooting why a user cannot sign in to a custom line-of-business application that is federated with Microsoft Entra ID. The user reports that they are repeatedly prompted for credentials and then receive an error. The application is configured for SAML-based SSO. What is the most likely cause?

A.The user's browser cookies are disabled
B.The application is not registered in the app gallery
C.The SAML certificate has expired or the configuration has a mismatch
D.The user does not have a license for Microsoft Entra ID
AnswerC

SAML certificates are used to sign the SAML response; the service provider uses the certificate's public key to validate the signature. If the certificate has expired or the configured certificate doesn't match the one trusted by the application, the SP will discard the assertion and deny sign-in. Likewise, a mismatch in the SAML configuration (e.g., Entity ID, Reply URL, or signing algorithm) will cause authentication failures even when the certificate is valid.

Why this answer

When a SAML-based SSO application repeatedly prompts for credentials and then fails, the most common cause is an expired or misconfigured SAML signing certificate. The certificate is used by Microsoft Entra ID to sign SAML assertions; if it has expired, or if the thumbprint, audience URI, or reply URL in the Entra ID configuration does not match what the application expects, the application will reject the assertion and force re-authentication or display an error.

Exam trap

The trap here is that candidates often confuse a SAML certificate expiration/mismatch with a licensing issue or browser configuration problem, but the repeated credential prompt followed by an error is the hallmark of a failed SAML assertion validation, not a missing license or disabled cookies.

How to eliminate wrong answers

Option A is wrong because disabled browser cookies would typically cause session persistence issues or repeated prompts, but they would not directly cause a SAML assertion validation failure with a specific error; the error described is characteristic of a token trust issue, not a cookie storage issue. Option B is wrong because an application does not need to be in the Microsoft Entra ID app gallery to function with SAML SSO; custom line-of-business applications can be registered as non-gallery applications and work identically. Option D is wrong because Microsoft Entra ID licensing is not required for a user to authenticate via SAML federation; free tier Entra ID supports SAML-based SSO for up to 10 applications per tenant, and the error is unrelated to license assignment.

13
Multi-Selectmedium

Which TWO of the following are methods to enforce MFA in Microsoft Entra ID?

Select 2 answers
A.Identity Protection user risk policy
B.Password Protection
C.Security defaults
D.Conditional Access policy
E.Self-service password reset
AnswersC, D

Security defaults provide a predefined baseline of security settings that automatically enforce MFA for all users, requiring registration through the Microsoft Authenticator app and blocking legacy authentication protocols. This is a mandatory, tenant-wide enforcement mechanism that is enabled by default for new tenants, making it a direct and comprehensive method to enforce MFA.

Why this answer

Security defaults (C) is correct because it is a Microsoft-managed baseline that, once enabled, automatically requires all users to register for MFA and enforces MFA for privileged actions such as Azure portal, Microsoft Entra admin center, and Azure CLI/PowerShell access. Conditional Access policy (D) is correct because it is the primary granular method to enforce MFA, letting you create a policy that targets users/groups and cloud apps with a Grant control of 'Require multifactor authentication' (optionally combined with conditions like sign-in risk, location, or device state). Identity Protection user risk policy (A) does not itself enforce MFA; it can require a password change or, in some configurations, allow access, and MFA enforcement is typically achieved by pairing risk signals with a Conditional Access grant control.

Password Protection (B) only blocks weak or banned passwords via custom banned password lists and does not perform MFA. Self-service password reset (E) is a credential-reset feature and does not enforce MFA, even though it may require MFA as an authentication method for the reset process.

Exam trap

The trap here is that candidates often confuse Identity Protection user risk policy (Option A) as a direct MFA enforcement method, but it only detects risk and requires a Conditional Access policy to actually enforce MFA as a control.

14
MCQhard

Your organization uses Microsoft Entra ID to manage access for employees and partners. You need to implement a solution that allows partners to self-service request access to specific applications, with approval from their manager, and access expires after 30 days. Which feature should you use?

A.Entitlement Management access packages
B.Azure AD B2B collaboration
C.Privileged Identity Management (PIM)
D.Conditional Access with session restrictions
AnswerA

Entitlement Management access packages are the correct choice because they are specifically designed to govern end-user access to resources such as groups, applications, and SharePoint sites. These packages bundle resources with configurable policies for request approval, recurring access reviews, expiration, and automatic revocation when the policy ends. This enables self-service access requests while maintaining an auditable lifecycle for both internal and external users.

Why this answer

Entitlement Management access packages are designed to allow external partners to request access to specific applications through a self-service portal. The feature supports approval workflows (e.g., manager approval) and automatically enforces time-bound access, such as a 30-day expiration. This directly matches the requirement for partner self-service with approval and expiration.

Exam trap

The trap here is that candidates often confuse Azure AD B2B collaboration (which handles identity provisioning) with Entitlement Management (which handles the full lifecycle of access requests, approvals, and expiration), leading them to pick B2B collaboration as the answer.

How to eliminate wrong answers

Option B (Azure AD B2B collaboration) is wrong because it only provides the mechanism to invite external users into the tenant and assign them access, but it does not include built-in self-service request workflows, approval processes, or automatic expiration policies. Option C (Privileged Identity Management (PIM)) is wrong because it is focused on just-in-time privileged role activation for administrators and does not handle self-service access requests for non-privileged applications or partner scenarios. Option D (Conditional Access with session restrictions) is wrong because it enforces access policies (e.g., session timeouts) on already authenticated users, but it does not provide any self-service request, approval, or expiration lifecycle management for partner access.

15
MCQhard

Refer to the exhibit. You are reviewing user sign-in activity using Microsoft Graph API. The user has not performed an interactive sign-in since December 1, but had a non-interactive sign-in on December 5. You need to determine if the user should be considered inactive for a policy that defines inactivity as no interactive sign-in for 30 days. Today is December 15. What should you do?

A.Check if the user has any sign-in in the last 30 days; since there is a non-interactive sign-in, the user is active.
B.Use the lastNonInteractiveSignInDateTime as the last sign-in time, so the user is not inactive.
C.Use the lastSignInDateTime of December 1, which is only 14 days ago, so the user is not inactive.
D.The user is inactive because the account is enabled but there is no interactive sign-in in the last 30 days.
AnswerC

This is correct because lastSignInDateTime corresponds to the user's last successful interactive sign-in, which occurred on December 1. As of the review date (presumably December 15), that is only 14 days ago—well under the 30-day threshold defined by the policy. Therefore, the user is not inactive, and no further action is required.

Why this answer

The policy defines inactivity as no interactive sign-in for 30 days. The user's last interactive sign-in was on December 1, which is only 14 days ago as of December 15, so the user is not inactive. Microsoft Graph API's lastSignInDateTime property specifically tracks interactive sign-ins, while non-interactive sign-ins are tracked separately via lastNonInteractiveSignInDateTime and do not reset the interactive inactivity timer.

Exam trap

The trap here is that candidates confuse 'any sign-in' with 'interactive sign-in' and incorrectly assume non-interactive sign-ins reset the inactivity timer, when the policy explicitly specifies only interactive sign-ins count.

How to eliminate wrong answers

Option A is wrong because the policy explicitly defines inactivity based on interactive sign-ins, not any sign-in; non-interactive sign-ins (e.g., token refreshes, service-to-service calls) do not count toward the interactive inactivity threshold. Option B is wrong because lastNonInteractiveSignInDateTime is irrelevant for a policy that only considers interactive sign-ins; using it would incorrectly treat the user as active when they have not performed an interactive sign-in for 30 days. Option D is wrong because the user is not inactive—the last interactive sign-in was only 14 days ago, which is within the 30-day window, so the account being enabled does not change the inactivity status.

16
MCQmedium

You are designing a privileged access strategy for Microsoft Entra ID. Your organization requires that all users who are assigned to the Global Administrator role must perform a privileged elevation only when needed, and the elevation must be approved by a security officer. Which feature should you implement?

A.Microsoft Entra Identity Governance – Privileged Identity Management
B.Azure AD administrative units
C.Conditional Access with session control
D.Microsoft Entra ID protection risk policies
AnswerA

Microsoft Entra Privileged Identity Management (PIM) delivers just-in-time privileged access by letting users activate eligible role assignments for a maximum time window, with optional approval workflows, MFA, and business justification. Because activation is time-bound and audited, PIM directly supports a privileged access strategy that requires temporary elevation with oversight.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) provides just-in-time (JIT) privileged elevation for roles like Global Administrator, requiring approval from designated approvers (e.g., a security officer) before activation. This directly meets the requirement of elevation only when needed with approval, as PIM manages time-bound role assignments and approval workflows.

Exam trap

The trap here is that candidates often confuse Conditional Access (which controls sign-in access) with PIM (which controls role activation), leading them to select Option C because they think session controls can enforce approval for elevation, but Conditional Access cannot manage role activation workflows.

How to eliminate wrong answers

Option B is wrong because Azure AD administrative units restrict administrative scope to specific organizational units (e.g., departments) but do not provide JIT elevation or approval workflows for role activation. Option C is wrong because Conditional Access with session control enforces policies during sign-in (e.g., requiring MFA or device compliance) but cannot control role activation or require approval for elevation. Option D is wrong because Microsoft Entra ID Protection risk policies detect and respond to user or sign-in risks (e.g., blocking risky sign-ins) but do not manage privileged role elevation or approval processes.

17
MCQmedium

You are a security engineer for a company that uses Microsoft Entra ID. The company has a policy that users must sign in using Windows Hello for Business or a FIDO2 security key. You need to block legacy authentication protocols that do not support these methods. What should you configure?

A.Enable security defaults in Microsoft Entra ID.
B.Create an authentication method policy that disables SMS and voice call methods.
C.Create a Conditional Access policy that targets all users and all cloud apps, and set the client apps condition to 'Exchange ActiveSync clients' and 'Other clients', then set access control to 'Block'.
D.Configure a sign-in risk policy in Microsoft Entra ID Protection to block sign-ins with medium or high risk.
AnswerC

This correctly blocks legacy authentication protocols because 'Exchange ActiveSync clients' and 'Other clients' represent legacy clients that do not support modern authentication. By targeting all users and cloud apps and blocking these client types, you prevent sign-ins that cannot enforce Windows Hello for Business or FIDO2. This is the recommended approach in Microsoft Entra ID to eliminate legacy authentication.

Why this answer

To block legacy authentication, you must use Conditional Access to target client apps that use legacy protocols. The 'Exchange ActiveSync clients' and 'Other clients' conditions specifically cover clients that do not support modern authentication. Setting the access control to 'Block' ensures these clients cannot sign in.

Other options do not directly block legacy protocols; they address different security aspects such as risk, baseline defaults, or authentication methods.

Exam trap

The trap here is confusing security defaults or authentication method policies with the granular control needed to block legacy authentication while allowing modern methods.

18
Multi-Selecthard

Which THREE of the following are required to configure Microsoft Entra ID self-service password reset (SSPR)?

Select 3 answers
A.Microsoft Entra ID P1 or P2 license
B.Microsoft Entra ID Premium P2 license
C.Password writeback must be enabled
D.Users must register for authentication methods
E.SSPR must be enabled in the tenant
AnswersA, D, E

Microsoft Entra ID P1 or P2 license includes self-service password reset (SSPR) at either tier, so a P1 subscription is the minimum required for this feature. P1 provides full SSPR functionality for cloud-managed users, while P2 layers on advanced capabilities like Identity Protection and Privileged Identity Management that are not prerequisites for password reset. Therefore, stating P1 or P2 is the accurate licensing requirement, as P2 is not necessary.

Why this answer

Option A is correct because Microsoft Entra ID self-service password reset requires a Microsoft Entra ID P1 or P2 license (or Microsoft 365 Business Premium, which includes Entra ID P1 features); the P1 tier is the minimum paid license that unlocks SSPR for cloud-only and hybrid users. Option D is correct because users must register their authentication methods (such as Microsoft Authenticator, email, phone, or security questions) before they can prove their identity and reset their own password. Option E is correct because an administrator must explicitly enable SSPR in the tenant (for example, by selecting All users or a pilot group under Password reset > Properties), since the feature is not active by default.

Option B is not required because Premium P2 is not the minimum license — P1 already satisfies the SSPR licensing requirement, and P2 is only needed for features like Identity Protection and Privileged Identity Management. Option C is not required because password writeback is only necessary for hybrid environments where the password must sync back to on-premises Active Directory via Microsoft Entra Connect; for cloud-only users, SSPR works without writeback.

Exam trap

The trap here is that candidates often assume password writeback is always required for SSPR, but it is only necessary when integrating with on-premises Active Directory; for cloud-only users, SSPR works without it.

19
MCQeasy

You need to ensure that only approved iOS devices can access corporate email. Which Microsoft Intune policy should you configure?

A.Enrollment restriction
B.Device configuration policy
C.App protection policy
D.Device compliance policy
AnswerD

A device compliance policy in Microsoft Intune defines the rules that an iOS device must satisfy, such as a minimum OS version, a specific model, or jailbreak detection, and then scores the device as compliant or noncompliant on a regular schedule. This compliance state is consumed by Azure AD Conditional Access to allow or block access to Exchange, SharePoint, and other corporate apps. Therefore, it directly ensures that only approved iOS devices can access—because any device that fails the policy is denied at the time of access.

Why this answer

The correct option is D, Device compliance policy. A compliance policy defines the rules a device must meet (for example, requiring a compliant/approved iOS device state) and, combined with Conditional Access, blocks noncompliant devices from accessing corporate email such as Exchange Online. Enrollment restrictions (A) only control which devices may enroll or which platforms are allowed, not ongoing email access.

Device configuration policies (B) push settings to devices but do not gate access, and app protection policies (C) protect app data on enrolled or unenrolled devices without enforcing device-level approval for email access.

20
MCQhard

You are designing a Microsoft Entra ID tenant for a multinational organization. The security team requires that all administrative users must use phishing-resistant MFA. Administrators are located in different regions and may use different devices. Which MFA method should you enforce?

A.FIDO2 security keys
B.SMS-based verification
C.Phone call verification
D.Microsoft Authenticator with OTP
AnswerA

FIDO2 security keys are phishing-resistant because they use public-key cryptography where the private key never leaves the device and authentication is bound to the exact relying party origin. During a phishing attack, the key’s challenge-response only works for the legitimate site’s domain, so the credential cannot be relayed to a malicious impersonator. This eliminates shared secrets and prevents man-in-the-middle relay attacks, making it a strong authenticator for Microsoft Entra ID.

Why this answer

FIDO2 security keys are the only option that provides phishing-resistant MFA, as they use public-key cryptography and are bound to a specific web origin, preventing credential theft via man-in-the-middle attacks. This satisfies the security team's requirement for all administrative users, regardless of region or device, because FIDO2 keys are hardware-based and interoperable across platforms.

Exam trap

The trap here is that candidates often confuse 'multi-factor authentication' with 'phishing-resistant MFA', and select Microsoft Authenticator with OTP because it is a common MFA method, but it does not protect against real-time phishing attacks where the OTP is captured and replayed.

How to eliminate wrong answers

Option B is wrong because SMS-based verification is vulnerable to SIM-swapping and phishing attacks, and is not considered phishing-resistant. Option C is wrong because phone call verification relies on the PSTN network, which can be intercepted or spoofed, and does not provide phishing resistance. Option D is wrong because Microsoft Authenticator with OTP (time-based one-time password) is susceptible to phishing if the user is tricked into entering the OTP on a fake site, and it does not meet the phishing-resistant requirement.

21
MCQmedium

Your company uses Microsoft Entra ID and Microsoft Intune for mobile device management. You need to ensure that only devices that are compliant with your security policies can access corporate email. You configure a Conditional Access policy targeting Exchange Online. Which grant control should you use?

A.Require multifactor authentication
B.Require device to be marked as compliant
C.Block access
D.Require hybrid Azure AD joined device
AnswerB

This grant control checks the device compliance status reported by Microsoft Intune/Microsoft Entra ID, ensuring the device meets policies such as OS version, disk encryption, and jailbreak detection. Only devices marked as compliant by Intune are allowed access, which directly enforces the requirement to block non-compliant devices.

Why this answer

The scenario requires that only devices compliant with security policies can access corporate email. The 'Require device to be marked as compliant' grant control in Conditional Access checks the device compliance status reported by Microsoft Intune. If the device is not compliant, access to Exchange Online is blocked, ensuring policy enforcement.

Exam trap

The trap here is that candidates often confuse device compliance with device join status (hybrid Azure AD join) or authentication strength (MFA), not realizing that Intune compliance is a separate attribute that must be explicitly required in the grant control.

How to eliminate wrong answers

Option A is wrong because requiring multifactor authentication (MFA) verifies user identity but does not enforce device compliance; a non-compliant device could still access email after MFA. Option C is wrong because 'Block access' is a grant control that unconditionally denies access, which does not allow compliant devices to proceed. Option D is wrong because requiring a hybrid Azure AD joined device enforces domain join status, not Intune compliance; a device could be hybrid joined but still be non-compliant with security policies.

22
MCQhard

You are a security administrator for a company that uses Microsoft Entra ID. You need to provide a partner organization with access to specific resources in your tenant. The partner users must use their own credentials, and you must be able to revoke access without managing their accounts. What should you configure?

A.Configure B2C authentication with a local account for each partner user.
B.Create an app registration and share the client secret with the partner organization.
C.Create guest user accounts in your tenant and assign them to a security group.
D.Configure B2B collaboration with a cross-tenant access policy that allows the partner tenant and grants access to a specific enterprise application.
AnswerD

Microsoft Entra B2B collaboration lets partner users authenticate with their home tenant credentials, and cross-tenant access policies control inbound access. You can scope access to specific applications and revoke it by changing the policy, without managing the partner's accounts.

Why this answer

B2B collaboration with cross-tenant access settings allows partner users to authenticate against their home tenant while you control which applications and resources they can access. Revocation is achieved by modifying or deleting the cross-tenant access policy or the application assignment, without managing partner accounts.

Exam trap

The trap here is confusing B2B collaboration with B2C or guest account management, which involve different identity models and administrative overhead.

23
MCQmedium

You have configured the Conditional Access policy shown in the exhibit. Users report that they can still access Exchange Online using legacy authentication protocols. What is the most likely reason?

A.The policy should use 'Require MFA' instead of 'Block'
B.The policy does not include the correct client app types
C.The policy state is set to reporting mode
D.The policy should include 'mobileAppsAndDesktopClients' instead
AnswerC

Conditional Access policies in report-only mode (also called reporting mode) are evaluated against the conditions and the result is logged in the sign-in logs, but the configured access controls are never applied. As a result, a Block control will not prevent the user from accessing the resource; the policy only emits a 'reportOnly: failure' entry. To enforce the block, the policy state must be set to 'Enabled' (or 'On'), which applies the Block control during authentication. This is the direct reason why the block is not in effect.

Why this answer

The policy state is set to 'Report-only' (reporting mode), which means the Conditional Access policy is evaluated but not enforced. Users can still access Exchange Online using legacy authentication because the policy only logs the outcome without blocking access. To enforce the block, the policy state must be set to 'On'.

Exam trap

The trap here is that candidates often overlook the policy state setting and focus on grant controls or client app types, assuming a 'Block' control is always enforced, but Azure AD's reporting mode explicitly disables enforcement regardless of other configurations.

How to eliminate wrong answers

Option A is wrong because 'Require MFA' would grant access after MFA, not block legacy authentication; the goal is to block legacy protocols, and 'Block' is the correct grant control for that. Option B is wrong because the policy does include the correct client app types—legacy authentication is covered by the 'Exchange ActiveSync clients' and 'Other clients' selections, which are the appropriate app types for blocking legacy protocols. Option D is wrong because 'mobileAppsAndDesktopClients' targets modern authentication clients, not legacy protocols; legacy authentication is specifically controlled via 'Exchange ActiveSync clients' and 'Other clients'.

24
MCQmedium

Your organization uses Microsoft Entra ID. You need to manage access to a line-of-business application that supports SAML 2.0. The application should be integrated as an enterprise application in Entra ID. What steps must you take?

A.Configure user consent settings for the application
B.Register the application in App Registrations and configure SAML
C.Create a new enterprise application as a non-gallery app, configure SAML, assign users, and test
D.Add the application from the Azure AD gallery
AnswerC

This is the correct approach because a non-gallery enterprise application acts as a container for your custom SAML application's service principal and all SSO settings. After adding it, you configure SAML 2.0 by providing the application's identifier and reply URL, uploading or generating a signing certificate, and mapping user attributes to the claims. You then assign users or groups to the enterprise application to validate access, and use the built-in test functionality to confirm the federated sign-in flow works end-to-end.

Why this answer

To integrate a line-of-business application that supports SAML 2.0 as an enterprise application in Microsoft Entra ID, you must create a new enterprise application using the 'Non-gallery application' option, configure SAML-based sign-on with the application's metadata, assign users or groups, and test the integration. This process allows you to define custom SAML attributes and claims specific to the application, which is necessary for non-gallery apps that are not pre-integrated.

Exam trap

The trap here is that candidates confuse App Registrations (used for OAuth/OpenID Connect) with Enterprise applications (used for SAML and gallery apps), leading them to choose Option B instead of correctly selecting the non-gallery enterprise application creation path.

How to eliminate wrong answers

Option A is wrong because configuring user consent settings controls whether users can consent to permissions for applications, but it does not create or integrate the enterprise application itself; consent settings are a separate administrative control. Option B is wrong because registering the application in App Registrations creates a service principal for custom-developed apps, but enterprise applications for SAML integration are created directly under 'Enterprise applications' in the portal, not via App Registrations; App Registrations is for OAuth/OpenID Connect apps, not SAML. Option D is wrong because adding the application from the Azure AD gallery is only possible if the application is pre-integrated and listed in the gallery; for a custom line-of-business application that supports SAML 2.0 but is not in the gallery, you must use the non-gallery option.

25
MCQhard

Your organization uses Microsoft Entra ID and requires that all accesses to sensitive applications be approved by the application owner. You need to implement a solution where users can request access to these applications, and the request is automatically routed to the owner for approval. What should you configure?

A.Microsoft Entra roles and administrative units
B.Entitlement management access packages
C.Privileged Identity Management for groups
D.Cross-tenant access settings
AnswerB

Entitlement management access packages are the correct identity governance solution because they bundle resources such as applications, groups, and SharePoint sites into packages that users can request. Access package policies can require specified custom approvers, define approval stages, set access durations, and trigger recurring access reviews. This directly satisfies the requirement for user-driven application access requests with custom approvals.

Why this answer

Entitlement management access packages in Microsoft Entra ID are the correct choice because they let you bundle resources such as sensitive applications into an access package with an approval policy, so users request access through the My Access portal and the request is automatically routed to the designated approver (the application owner) before access is granted. This directly satisfies the requirement for owner-approved, request-based access to applications. Option A (Entra roles and administrative units) governs role assignments and scoping, not user access-request approval workflows for applications.

Option C (Privileged Identity Management for groups) handles just-in-time activation of privileged group membership, not application access requests with owner approval. Option D (cross-tenant access settings) controls collaboration and trust with external Entra tenants, which is unrelated to internal application access approvals.

26
Multi-Selecthard

You are designing a security baseline for Microsoft Entra ID. Which THREE settings are recommended by Microsoft as part of the identity security baseline?

Select 3 answers
A.Enable risk-based Conditional Access policies
B.Allow self-service group management for all users
C.Set sign-in session timeout to 8 hours
D.Enable MFA for all Global Administrators
E.Block legacy authentication protocols
AnswersA, D, E

Risk-based Conditional Access policies are a core component of a security baseline because they dynamically evaluate sign-in risk and user risk in real time, enabling automatic remediation actions such as requiring MFA, blocking access, or forcing password change for compromised identities. Unlike static policies, these adapt to evolving threat signals like anonymous IP addresses, impossible travel, or atypical sign-ins, thereby reducing the attack surface without permanently disrupting legitimate users. In a baseline, this should be configured with risk thresholds (e.g., medium or higher for user risk) and paired with registration campaigns for combined security information.

Why this answer

Risk-based Conditional Access policies are a core recommendation in the Microsoft identity security baseline. These policies automatically respond to detected user or sign-in risks (e.g., anonymous IP, leaked credentials) by requiring MFA or blocking access, aligning with the Zero Trust principle of continuous verification. Microsoft explicitly includes risk-based policies in its security baseline to proactively mitigate identity threats.

Exam trap

The trap here is that candidates often confuse Microsoft's general best practices (like self-service group management) with the specific, hardened settings in the identity security baseline, which prioritizes risk-based controls and blocking legacy protocols over convenience features.

27
MCQmedium

Refer to the exhibit. You are configuring an Entitlement Management access package. The policy allows any existing user to request access without approval, and access expires after 30 days. However, security requirements dictate that all access to Finance applications must be reviewed by the finance team manager every quarter. What should you add to the policy?

A.Add a connected organization for external users
B.Set 'isApprovalRequiredForAdd' to true
C.Set 'durationInDays' to 90
D.Enable access reviews and assign the finance team manager as reviewer
AnswerD

Enabling access reviews in entitlement management configures recurring attestation cycles—in this case quarterly—where access packages are periodically recertified. Assigning the finance team manager as the reviewer gives a business owner the responsibility to approve, deny, or remove access at each cycle. This exactly satisfies the compliance requirement for a periodic review.

Why this answer

The security requirement mandates quarterly reviews by the finance team manager, which is exactly what an access review does in Entitlement Management. Access reviews allow you to require periodic attestation of access by a designated reviewer, ensuring ongoing compliance even though the initial request does not require approval. The policy already sets a 30-day expiration, but a quarterly review adds a separate recurring governance check that overrides the shorter duration for compliance purposes.

Exam trap

The trap here is that candidates confuse 'approval at request time' with 'periodic review after access is granted' — the question explicitly says no approval is needed for the initial request, so adding approval (Option B) is incorrect, but the quarterly review (Option D) is a separate governance control that satisfies the security requirement without changing the request flow.

How to eliminate wrong answers

Option A is wrong because a connected organization is used to allow external users from a specific partner or tenant to request access; the scenario specifies 'any existing user' (internal users), so external user configuration is irrelevant. Option B is wrong because setting 'isApprovalRequiredForAdd' to true would require approval at the time of request, but the question explicitly states the policy allows access without approval; adding approval would contradict the requirement. Option C is wrong because setting 'durationInDays' to 90 would extend the access expiration to 90 days, but the requirement is to keep the 30-day expiration and add a quarterly review; changing the duration does not enforce periodic review by the finance team manager.

28
MCQmedium

You are the identity security engineer for a company that uses Microsoft Entra ID. A new security policy requires that any user who is assigned the Global Administrator role must use a phishing-resistant authentication method when signing in. You need to enforce this requirement with the least administrative effort. What should you do?

A.Configure a per-user MFA setting for each Global Administrator and disable SMS and voice call methods.
B.Enable security defaults for the tenant and require all users to register for Microsoft Authenticator.
C.Assign a Microsoft Entra ID P1 license to each Global Administrator and enable self-service password reset with number matching.
D.Create a Conditional Access policy that targets the Global Administrator directory role and requires an authentication strength of Phishing-resistant MFA.
AnswerD

Conditional Access can target directory roles, and authentication strengths let you require specific method combinations such as phishing-resistant MFA. This directly enforces the policy for Global Administrators without changing per-user settings or relying on legacy per-user MFA, which cannot distinguish phishing-resistant methods.

Why this answer

A Conditional Access policy scoped to directory roles and combined with an authentication strength requirement is the supported way to mandate phishing-resistant MFA for privileged users. Authentication strengths map to method combinations such as FIDO2 security keys and certificate-based authentication, giving you granular, role-based enforcement.

Exam trap

The trap here is assuming that enabling security defaults or per-user MFA can enforce phishing-resistant authentication for a specific privileged role.

29
Multi-Selecthard

Your company has a Microsoft Entra ID tenant with 10,000 users. You need to implement a secure authentication strategy that satisfies the following requirements: - Users must not be able to bypass security verification using alternate authentication methods. - Passwordless authentication should be used where possible. - Legacy authentication protocols must be blocked. Which THREE actions should you take? (Choose three.)

Select 3 answers
A.Create a Conditional Access policy to block legacy authentication protocols.
B.Configure per-user MFA to require verification.
C.Enable FIDO2 security keys as an authentication method and configure passwordless sign-in.
D.Enable the 'Security defaults' feature in Microsoft Entra ID.
E.Disable SMS and voice call authentication methods in Microsoft Entra ID.
AnswersA, C, E

Conditional Access policies operate at the authentication plane and allow granular control based on client app, IP, and risk. By targeting 'Other clients' and explicitly selecting 'Block access,' you can deny legacy protocols like POP3, IMAP4, and SMTP AUTH that bypass modern authentication and MFA, effectively closing known attack vectors for password-spraying and credential-stuffing. This is the most direct and policy-driven method to prohibit these insecure sign-ins across all users and apps.

Why this answer

Option A is correct because a Conditional Access policy targeting the 'Other clients' client apps condition (which covers legacy protocols such as IMAP, POP3, SMTP AUTH, and older Office clients) is the supported way to block legacy authentication in Microsoft Entra ID. Option C is correct because enabling the FIDO2 security key authentication method and configuring it for passwordless sign-in provides a phishing-resistant, passwordless credential that satisfies the passwordless requirement. Option E is correct because disabling SMS and voice call methods removes weaker alternate authentication methods that users could otherwise use to bypass stronger security verification, directly addressing the no-bypass requirement.

Option B is not correct because per-user MFA is a legacy, always-on setting that cannot enforce method restrictions or passwordless flows and does not block legacy authentication. Option D is not correct because Security defaults are a baseline for tenants without Conditional Access and cannot be combined with the granular Conditional Access policy needed here, nor do they enforce passwordless authentication.

Exam trap

The trap here is that candidates often assume Security defaults is the simplest way to block legacy authentication and enforce MFA, but they overlook that Security defaults cannot be customized to selectively enable FIDO2 or disable specific methods, making it incompatible with the requirement for passwordless authentication and granular control.

30
MCQeasy

You are configuring Microsoft Entra ID Connect to synchronize on-premises Active Directory identities to the cloud. You need to ensure that password hashes are synchronized to enable Microsoft Entra ID Password Protection and Identity Protection. Which option should you enable?

A.Pass-through authentication
B.Federation with AD FS
C.Password hash synchronization
D.Azure AD Connect Health
AnswerC

Password hash synchronization (PHS) is the correct option because Entra ID Connect computes a one-way salted SHA256 hash of each on-premises Active Directory password and synchronizes that hash to Azure AD. This synchronized hash enables cloud authentication using the same password while also feeding downstream features such as Identity Protection's leaked credentials detection and Azure AD Password Protection's banned password list. The process is designed to be irreversible; the plaintext password is never transmitted or stored, only the derived hash, which directly fulfills the requirement to synchronize password hashes.

Why this answer

Password hash synchronization (PHS) is the correct option because it is the specific feature that synchronizes password hashes from on-premises Active Directory to Microsoft Entra ID. This enables Microsoft Entra ID Password Protection (which blocks weak passwords by comparing against a global banned password list) and Identity Protection (which detects leaked credentials by comparing synchronized hashes against known compromised password databases). Without PHS, these cloud-based security features have no access to the on-premises password hashes.

Exam trap

The trap here is that candidates often confuse Pass-through authentication with Password hash synchronization, assuming that any password validation method that touches on-premises AD will automatically provide hash data for cloud security features, but only PHS actually stores the hashes in Microsoft Entra ID.

How to eliminate wrong answers

Option A is wrong because Pass-through authentication validates passwords directly against on-premises AD without storing password hashes in the cloud, so it does not provide the hash data needed for Password Protection or Identity Protection. Option B is wrong because Federation with AD FS relies on on-premises authentication and does not synchronize password hashes to Microsoft Entra ID, making it incompatible with cloud-only password analysis features. Option D is wrong because Azure AD Connect Health is a monitoring and diagnostics tool for the synchronization infrastructure, not a mechanism for synchronizing password hashes.

31
MCQeasy

Your organization uses Microsoft Entra ID for identity management. You need to ensure that users can sign in using a one-time passcode sent to their mobile device, without requiring any additional app or software installation. Which authentication method should you enable?

A.One-time passcode (OTP)
B.Microsoft Authenticator app
C.FIDO2 security keys
D.Certificate-based authentication
AnswerA

One-time passcode (OTP) is a built-in Microsoft Entra ID authentication method that sends a verification code to a user's verified email or phone number via SMS or email. It requires no additional app installation, hardware token, or certificate infrastructure, making it the simplest way to authenticate a user without a password. The code is time-limited and used once, providing a low-friction option for temporary or initial sign-in scenarios.

Why this answer

The one-time passcode (OTP) authentication method in Microsoft Entra ID allows users to sign in with a temporary code sent via SMS to their mobile device, requiring no additional app or software installation. This method is specifically designed for scenarios where users cannot or should not install the Microsoft Authenticator app, such as for guest users or in bring-your-own-device (BYOD) environments. The OTP is generated by Entra ID and delivered over the mobile network, satisfying the requirement of no extra software.

Exam trap

The trap here is that candidates often confuse the 'one-time passcode' option with the Microsoft Authenticator app's push notification or time-based code feature, but the question explicitly requires no additional app installation, making the SMS-based OTP the only correct choice.

How to eliminate wrong answers

Option B is wrong because the Microsoft Authenticator app requires installation of a mobile application on the user's device, which contradicts the requirement of 'without requiring any additional app or software installation.' Option C is wrong because FIDO2 security keys are hardware-based devices that must be physically plugged in or used via NFC, and they require additional software (browser support and platform attestation) to function, not meeting the no-software-installation condition. Option D is wrong because certificate-based authentication requires digital certificates to be provisioned and installed on the user's device, which involves software (certificate store, enrollment) and is not a simple one-time passcode delivered via SMS.

32
Multi-Selecteasy

Which TWO of the following are valid authentication methods in Microsoft Entra ID?

Select 2 answers
A.Temporary Access Pass
B.App registration
C.FIDO2 security key
D.Managed identity
E.Azure AD Connect
AnswersA, C

Temporary Access Pass is a time-limited, admin-issued passcode that allows a user to sign in and complete first-time onboarding, such as registering phishing-resistant credentials like FIDO2 keys or Microsoft Authenticator. It is a first-class authentication method in Microsoft Entra ID, designed as a secure temporary credential that can be used once or for a short validity window, and it supports both primary and secondary authentication scenarios, including passwordless recovery when a user loses their existing methods.

Why this answer

Temporary Access Pass (TAP) is a valid authentication method in Microsoft Entra ID that allows users to register passwordless methods (like FIDO2 or Microsoft Authenticator) by providing a time-limited passcode. It is designed for scenarios where users have forgotten their credentials or need to onboard new devices without a password. TAP is configured via the Authentication methods policy in Entra ID and supports both one-time use and configurable lifetimes.

Exam trap

The trap here is that candidates confuse identity infrastructure tools (like Azure AD Connect) or workload identities (like Managed identities) with user authentication methods, leading them to select options that are related to identity but not valid for user sign-in.

33
MCQmedium

You are designing a privileged identity management strategy for Microsoft Entra ID. You need to ensure that eligible role assignments require approval from a designated group before activation. What configuration is required?

A.Configure the role as eligible and set activation duration
B.Configure a Conditional Access policy with approval control
C.In PIM, configure the role settings to require approval and specify an approver group
D.Create an access review for the role
AnswerC

In PIM, open the role's Activation settings, enable 'Require approval to activate', and specify one or more approvers or an approver group. When an eligible member activates the role, the request is sent to those approvers, who approve or deny via the Microsoft Entra admin center or email notification. The role becomes active only after approval is granted, and you can also require justification as part of the activation request, creating a full audit trail.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure role settings to require approval for activation. By specifying an approver group, you ensure that eligible role assignments cannot be activated without explicit approval from designated members, enforcing a just-in-time (JIT) access control model.

Exam trap

The trap here is that candidates often confuse Conditional Access approval controls (used for session policies) with PIM role activation approval, which is a separate configuration within the role settings in Privileged Identity Management.

How to eliminate wrong answers

Option A is wrong because configuring the role as eligible and setting activation duration only defines the eligibility and time limit for activation, but does not enforce an approval workflow. Option B is wrong because Conditional Access policies with approval control are used for session or sign-in risk scenarios, not for PIM role activation approval. Option D is wrong because creating an access review for the role is a periodic review mechanism to confirm ongoing access, not a real-time approval gate for activation.

34
MCQeasy

You are a security engineer for a company that uses Microsoft Entra ID. You need to ensure that all users accessing the company's Salesforce application from unmanaged devices are prompted for multi-factor authentication (MFA) every time. What should you configure?

A.Enable per-user MFA for all users in the Salesforce application.
B.Create a Conditional Access policy that targets the Salesforce application, apply to all users, include 'All device platforms' with 'Device state' filter for 'Unmanaged', and grant access requiring MFA with session control 'Sign-in frequency - Every time'.
C.Configure device compliance policy to require MFA on non-compliant devices.
D.Configure MFA registration policy to require all users to register MFA.
AnswerB

This Conditional Access policy is correct because it precisely targets the Salesforce app and all users, then uses the 'Device state' filter to include only 'Unmanaged' devices, excluding managed, compliant, and hybrid-joined devices. The grant control 'Require MFA' forces an MFA challenge on those unmanaged devices, while the session control 'Sign-in frequency - Every time' ensures that even within an existing session, every sign-in to Salesforce is reauthenticated with MFA, closing the gap for stolen tokens or stale sessions. This delivers exactly the required behavior: MFA every time on unmanaged devices, without affecting managed ones.

Why this answer

A Conditional Access policy with a 'Device state' filter for 'Unmanaged' and 'Sign-in frequency - Every time' session control forces MFA prompts on every access attempt from unmanaged devices. This meets the requirement to prompt MFA every time for users accessing Salesforce from unmanaged devices, without affecting managed devices or requiring per-user MFA.

Exam trap

The trap here is that candidates often confuse per-user MFA (Option A) with Conditional Access MFA, not realizing that per-user MFA cannot target specific applications or device states, and that 'Sign-in frequency' is a session control, not a grant control.

How to eliminate wrong answers

Option A is wrong because per-user MFA applies MFA to all sign-ins for the user, regardless of device state or application, and does not provide the granularity to target only unmanaged devices or enforce 'every time' frequency. Option C is wrong because device compliance policies evaluate device health (e.g., encryption, OS version) but do not directly trigger MFA prompts; they can block or grant access but cannot enforce 'Sign-in frequency - Every time' as a session control. Option D is wrong because the MFA registration policy only ensures users have registered MFA methods; it does not enforce MFA prompts during sign-in, nor does it target specific applications or device states.

35
MCQeasy

You are a security administrator for a financial institution. You need to implement a solution that allows users to authenticate using biometrics and prevents password-based attacks. Which Microsoft Entra ID feature should you enable?

A.Microsoft Entra ID Protection
B.Passwordless authentication (FIDO2 or Windows Hello for Business)
C.Password hash synchronization
D.Azure Multi-Factor Authentication
AnswerB

Passwordless authentication using FIDO2 security keys or Windows Hello for Business replaces the password entirely with public/private key cryptography. The private key never leaves the device and is unlocked by a biometric gesture (fingerprint or face) or a PIN, while the public key is registered with Microsoft Entra ID. Because no shared secret is transmitted over the network, these methods are phishing-resistant and eliminate the most common attack vectors like password spraying and credential theft, making this the only option that truly removes passwords.

Why this answer

Passwordless authentication methods like FIDO2 and Windows Hello for Business eliminate the use of passwords entirely, thereby preventing password-based attacks such as brute force, phishing, and credential stuffing. Biometric verification (e.g., fingerprint or facial recognition) is a core component of these methods, meeting the requirement for biometric authentication. This aligns with the Zero Trust principle of reducing the attack surface by removing shared secrets.

Exam trap

The trap here is that candidates often confuse Azure MFA (which still requires a password) with passwordless methods, mistakenly thinking MFA alone eliminates password-based attacks, when in fact it only adds a second layer after the password is entered.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Protection is a risk-based conditional access tool that detects and responds to identity risks (e.g., leaked credentials, anomalous sign-ins) but does not itself enable biometric authentication or eliminate passwords. Option C is wrong because Password Hash Synchronization (PHS) is a synchronization mechanism that hashes and syncs on-premises AD passwords to Azure AD for hybrid identity scenarios; it does not provide biometric authentication or prevent password attacks. Option D is wrong because Azure Multi-Factor Authentication (MFA) adds a second factor (e.g., phone call, OTP) but still relies on a password as the first factor, so it does not prevent password-based attacks—it only mitigates them after a password is compromised.

36
MCQhard

Your company is migrating from on-premises Active Directory to Microsoft Entra ID. You need to synchronize user accounts and enable self-service password reset (SSPR) for cloud users. You have set up Microsoft Entra Connect Sync. Which additional configuration is required to allow password writeback for SSPR?

A.Enable password writeback in Microsoft Entra Connect and assign Azure AD Premium licenses
B.Configure pass-through authentication
C.Enable password hash synchronization
D.Install the Azure AD Password Protection proxy
AnswerA

Password writeback is an optional feature in Microsoft Entra Connect that must be explicitly enabled in the configuration wizard, and it requires Azure AD Premium P1 or P2 licenses to be assigned to users. When enabled, password changes performed in Azure AD (for example, via self-service password reset) are written back to on-premises Active Directory, making the hybrid password bidirectional. This is the only mechanism that fulfills the requirement of writing back passwords from the cloud to on-premises.

Why this answer

Password writeback requires both the feature to be enabled in Microsoft Entra Connect (via the synchronization settings) and Azure AD Premium licenses (P1 or P2) assigned to users. Without the license, the SSPR writeback functionality is not available, even if the feature is enabled in the sync tool. This combination allows password changes from the cloud to be written back to on-premises Active Directory.

Exam trap

The trap here is that candidates often assume password hash synchronization (PHS) alone enables writeback, but PHS only handles one-way hash flow to the cloud, while writeback is a separate bidirectional feature requiring explicit enablement and licensing.

How to eliminate wrong answers

Option B is wrong because pass-through authentication validates passwords against on-premises AD but does not enable password writeback for SSPR; it is an authentication method, not a writeback mechanism. Option C is wrong because password hash synchronization (PHS) is required for cloud authentication and SSPR, but it alone does not provide writeback capability; writeback is a separate feature that must be explicitly enabled. Option D is wrong because the Azure AD Password Protection proxy is used to enforce custom banned password lists for on-premises environments, not to enable password writeback for SSPR.

37
MCQmedium

Your company uses Microsoft Entra ID and has Microsoft Defender for Cloud Apps. You need to monitor and control access to cloud apps based on user behavior. Which feature should you use?

A.Conditional Access for Cloud Apps (session control)
B.Information Protection (DLP)
C.Cloud Discovery
D.Application Proxy
AnswerA

Microsoft Entra Conditional Access for Cloud Apps (session control) is an identity-driven, real-time enforcement point that uses a reverse proxy to monitor and restrict user actions inside sanctioned cloud apps. It applies policies at the session layer, allowing you to block download, upload, cut/copy/paste, or print based on user, device, or risk signals—beyond mere sign-in conditions. This is the correct answer because it directly satisfies the requirement to monitor and control behavior in real time within a cloud app session, not just gate initial access.

Why this answer

Conditional Access for Cloud Apps with session control is the correct feature because it allows you to monitor and control access to cloud apps in real time based on user behavior. It uses Microsoft Entra ID Conditional Access policies combined with Microsoft Defender for Cloud Apps to enforce session policies, such as blocking downloads or requiring multi-factor authentication, when anomalous behavior is detected.

Exam trap

The trap here is that candidates often confuse Cloud Discovery (which identifies app usage) with session control (which monitors and controls behavior in real time), leading them to select Option C incorrectly.

How to eliminate wrong answers

Option B is wrong because Information Protection (DLP) focuses on preventing data loss by inspecting and protecting sensitive data at rest or in transit, not on monitoring or controlling access based on user behavior. Option C is wrong because Cloud Discovery is used to identify shadow IT by analyzing traffic logs to discover which cloud apps are being used in your organization, not to monitor or control access based on user behavior. Option D is wrong because Application Proxy provides secure remote access to on-premises web applications through Microsoft Entra ID, but it does not include behavior-based monitoring or control of cloud app access.

38
MCQeasy

Your company uses Microsoft Entra ID. You need to block sign-ins from countries where your company does not operate. Which approach should you use?

A.Configure MFA for all users
B.Create a Conditional Access policy to block access from those countries
C.Use Identity Protection user risk policy
D.Add those countries as Named locations
AnswerB

Create a Conditional Access policy that targets the 'Locations' condition and specifies the relevant countries as Named Locations. When you set the access control to 'Block access', Entra ID checks the sign-in IP address at runtime and denies authentication if it maps to a blocked country. This policy must be assigned to the appropriate users and apps, and should exclude emergency access accounts to avoid tenant lockout.

Why this answer

The correct option is B: create a Conditional Access policy to block access from those countries. Conditional Access is the Microsoft Entra ID feature designed to enforce sign-in decisions based on conditions such as location, and a policy can be scoped to all users and cloud apps with a Block grant control, using a Named location that defines the countries to exclude or block. Option D is only a building block—Named locations merely define geographic IP ranges and do not by themselves block anything.

Option A (MFA for all users) adds an authentication requirement but does not prevent sign-ins from specific countries, and Option C (Identity Protection user risk policy) responds to risky user behavior, not geographic origin.

39
MCQmedium

Refer to the exhibit. You are creating a custom Azure RBAC role for a security analyst. The role as shown allows read access to storage accounts. The analyst reports that they cannot read the contents of a blob container in a storage account. Why is this?

A.The role is not assigned to the analyst's user account.
B.The role does not include dataActions to read blob data.
C.The assignable scope is incorrect; it should be at the resource group level.
D.The storage account does not exist in the specified subscription.
AnswerB

The custom role's 'Actions' list includes only control-plane operations such as Microsoft.Storage/storageAccounts/read, which govern resource management actions but not blob reads. Reading blob data is a data-plane operation and must be granted via the 'dataActions' property, for example Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read. Because no dataActions exist in the role definition, the analyst is denied blob read access despite having a valid role assignment.

Why this answer

The custom RBAC role only includes read permissions for the storage account's control plane (e.g., listing keys, reading properties) but lacks the necessary dataActions to read blob data. To read blob container contents, the role must include 'Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read' under dataActions, which governs access to the data plane. Without this, the analyst can see the storage account but cannot access the blobs within it.

Exam trap

The trap here is that candidates often assume that 'read' access to a storage account automatically grants read access to its data, but Azure RBAC requires explicit dataActions for data plane operations, a distinction that is frequently tested on the AZ-500 exam.

How to eliminate wrong answers

Option A is wrong because the question states the role is created and assigned, so the issue is not a missing assignment but a missing permission. Option C is wrong because the assignable scope (subscription) is broader than the resource group level and does not prevent reading blob data; the problem is the lack of dataActions, not the scope. Option D is wrong because the storage account exists in the specified subscription (the analyst can see it), and the error is about reading blob contents, not account existence.

40
Multi-Selecthard

Which THREE components are part of Microsoft Entra Conditional Access? (Choose three.)

Select 3 answers
A.Multi-factor authentication service settings
B.Conditions (sign-in risk, device state, location)
C.Access controls (grant, block, session controls)
D.Role assignments
E.Assignments (users, groups, workload identities)
AnswersB, C, E

Conditions define the specific circumstances under which the policy is evaluated, including sign-in risk (from Identity Protection), device state (compliant or hybrid joined), and location (named locations or countries). These conditions act as the 'when' of the policy, allowing the same user assignment to trigger different access requirements based on context. This is one of the three core components of a Conditional Access policy, distinct from Assignments and Access controls.

Why this answer

Conditional Access in Microsoft Entra is built on an if-then policy model, and option B correctly identifies the 'if' side: Conditions such as sign-in risk, user risk, device state/platform, location, and client app that determine when a policy applies. Option C correctly identifies the 'then' side: Access controls, which include grant controls (for example require MFA or compliant device), block controls, and session controls (such as app-enforced restrictions or sign-in frequency). Option E correctly identifies Assignments, which scope the policy to specific users, groups, directory roles, or workload identities (service principals) as the target of the policy.

Option A is not a component of Conditional Access; MFA is one possible grant control configured within a policy, not a standalone Conditional Access component. Option D is not a Conditional Access component either; role assignments belong to Entra RBAC and govern administrative permissions, not policy evaluation.

Exam trap

The trap here is that candidates often confuse the 'Assignments' component (users/groups/workload identities) with Azure RBAC role assignments, but Conditional Access Assignments define who the policy applies to, not what permissions they have.

41
Multi-Selectmedium

Which TWO methods can be used to protect privileged accounts in Microsoft Entra ID? (Choose two.)

Select 2 answers
A.Enable external identities for guest users
B.Enable self-service password reset for all users
C.Register all devices with Azure AD
D.Create a Conditional Access policy that requires MFA for privileged roles
E.Configure Privileged Identity Management for just-in-time access
AnswersD, E

Creating a Conditional Access policy that targets privileged roles and requires MFA forces administrators to prove possession of a second authentication factor before signing in to Azure AD, the Azure portal, or Microsoft 365 admin centers. This neutralizes the risk of credential theft and password reuse because even a stolen password is insufficient alone to access high-impact administrative actions. Microsoft recommends this as a baseline control for every privileged account.

Why this answer

Option D is correct because a Conditional Access policy that requires multifactor authentication for privileged roles enforces an additional authentication factor specifically when members of highly privileged directory roles (such as Global Administrator) sign in, directly reducing the risk of credential compromise for those accounts. Option E is correct because Microsoft Entra Privileged Identity Management (PIM) provides just-in-time role activation, so privileged roles are not permanently assigned; users must activate eligibility with justification, approval, and MFA, and access expires after a set duration, which minimizes standing administrative access. Option A is not correct because enabling external identities for guest users governs B2B collaboration and does not protect privileged administrative accounts.

Option B is not correct because self-service password reset for all users is a general account-recovery feature and does not specifically secure privileged roles. Option C is not correct because registering devices with Azure AD (now Microsoft Entra ID) supports device-based Conditional Access but by itself does not protect privileged accounts.

Exam trap

The trap here is that candidates often confuse general security best practices (like SSPR or device registration) with specific privileged account protection mechanisms, overlooking that only MFA enforcement for privileged roles and JIT access via PIM directly reduce the standing privileges and credential exposure of high-value accounts.

42
MCQhard

You are the security architect for a large enterprise that uses Microsoft Entra ID with 50,000 users. The company recently adopted a cloud-first strategy and is migrating on-premises applications to Azure. You need to design a secure identity and access solution that meets the following requirements: - All access to cloud applications must be authenticated using modern authentication protocols. - Legacy authentication protocols (such as POP3, IMAP4, SMTP, and basic authentication) must be blocked. - Users must be required to use multi-factor authentication (MFA) when accessing any application from outside the corporate network. - Administrative access to Azure resources must be time-bound and require approval. - The solution must minimize user friction for internal users on the corporate network. - All sign-in risks must be detected and automatically remediated. You have deployed Microsoft Entra ID P2 licensing and configured Microsoft Defender for Cloud Apps. Which of the following is the most appropriate combination of actions to meet all requirements?

A.Enable Security defaults for all users and configure risk-based Conditional Access policies for admin roles. Use PIM for time-bound access.
B.Configure device compliance policies in Intune and require compliant devices for access. Use PIM with time-bound roles but without approval. Enable Identity Protection for risk detection.
C.Create a Conditional Access policy to require MFA for all cloud apps and allow legacy authentication for non-interactive service accounts. Use PIM without approval for admin roles.
D.Create a Conditional Access policy to block legacy authentication and require MFA for all users when accessing from outside the corporate network. Exclude trusted locations from MFA. Use PIM with approval for admin roles. Enable Identity Protection for risk detection and automatic remediation.
AnswerD

This solution correctly blocks legacy authentication as a client-app condition in Conditional Access, ensuring that protocols like POP, IMAP, and SMTP cannot bypass modern security controls. MFA is required only for non-corporate-network access by excluding trusted named locations, which minimizes user friction for internal employees. PIM with approval grants time-bound admin roles and enforces an approval workflow, while Identity Protection with automatic remediation (e.g., requiring a password change for risky users) closes the gap for identity-based threats, fully satisfying all requirements.

Why this answer

Option D is correct because it directly satisfies every stated requirement: a Conditional Access policy blocking legacy authentication eliminates POP3, IMAP4, SMTP, and basic authentication; requiring MFA for all users outside the corporate network with trusted locations excluded minimizes friction for internal users; PIM with approval provides time-bound, approved administrative access to Azure resources; and Microsoft Entra ID Protection (included with Entra ID P2) detects sign-in risk and enables automatic remediation via risk-based Conditional Access. Option A is wrong because Security defaults cannot enforce the granular legacy-auth blocking, trusted-location MFA exclusions, or risk-based remediation required here, and it does not scope MFA by network location. Option B is wrong because it omits blocking legacy authentication and omits approval for PIM activation, and device compliance alone does not meet the MFA-from-outside requirement.

Option C is wrong because it explicitly allows legacy authentication for service accounts and uses PIM without approval, violating two requirements.

43
Multi-Selecteasy

Which TWO of the following are authentication methods supported by Microsoft Entra ID?

Select 2 answers
A.Certificate-based authentication (CBA)
B.Security questions
C.Smart card with PIN
D.OAuth 2.0 authorization code flow
E.SMS-based one-time passcode
AnswersA, E

Certificate-based authentication (CBA) leverages X.509 digital certificates issued by a trusted certification authority to verify a user's identity. In Microsoft Entra ID, this method is supported for federated domains, where the certificate is used to authenticate against the identity provider instead of a password. It offers strong, phishing-resistant protection and is distinct from the physical smart card interaction, which is not natively supported.

Why this answer

Microsoft Entra ID natively supports certificate-based authentication (CBA), where a user presents an X.509 certificate and Entra ID validates it against configured trusted certificate authorities to satisfy authentication, making option A correct. Entra ID also supports SMS-based one-time passcode as a built-in authentication method, sending a code to a registered phone number that the user enters to complete sign-in, making option E correct. Security questions (B) are not an Entra ID authentication method; they are used in self-service password reset (SSPR) for identity verification, not as a primary or MFA authentication method.

Smart card with PIN (C) is not a distinct Entra ID authentication method — smart cards are typically surfaced through certificate-based authentication, so C is not separately supported. OAuth 2.0 authorization code flow (D) is an authorization protocol used by applications to obtain tokens, not an authentication method offered by Entra ID.

Exam trap

The trap here is that candidates often confuse authentication methods with authorization protocols (like OAuth 2.0) or confuse legacy on-premises methods (like security questions) with cloud-supported methods in Entra ID, leading them to select options that are not actual authentication methods in the Microsoft Entra ID context.

44
MCQmedium

Your company deploys Microsoft Sentinel for security operations. You need to configure just-in-time (JIT) access for Azure VMs. Which Azure security feature should you integrate with Sentinel?

A.Microsoft Defender for Cloud
B.Azure Policy
C.Azure Firewall
D.Microsoft Entra Privileged Identity Management
AnswerA

Microsoft Defender for Cloud is the correct choice because it directly provides just-in-time (JIT) VM access, a feature that locks down inbound traffic to virtual machines and opens designated ports only when requested and approved. This integration sends activity data to Microsoft Sentinel for advanced threat detection and response, making it the service that operationalizes JIT for security operations.

Why this answer

Microsoft Defender for Cloud provides the just-in-time (JIT) VM access capability, which can be integrated with Microsoft Sentinel to enable automated threat response. When a security incident is detected in Sentinel, a playbook can trigger Defender for Cloud to lock down or open specific ports (e.g., RDP 3389, SSH 22) for a defined time window, reducing the attack surface. This integration relies on the Defender for Cloud's JIT policy applied at the subscription or VM level, not on external network controls or identity governance.

Exam trap

The trap here is that candidates confuse just-in-time network access (JIT VM access) with just-in-time privileged role activation (PIM), because both use the term 'just-in-time' but operate at completely different layers—network vs. identity.

How to eliminate wrong answers

Option B (Azure Policy) is wrong because Azure Policy enforces compliance rules (e.g., requiring JIT to be enabled) but does not itself grant or manage time-bound network access; it is a governance tool, not an access control mechanism. Option C (Azure Firewall) is wrong because Azure Firewall is a managed network firewall that filters traffic at the perimeter, but JIT access is a VM-level network security group (NSG) feature that dynamically modifies NSG rules, not a firewall rule. Option D (Microsoft Entra Privileged Identity Management) is wrong because PIM manages just-in-time privileged role activation for Azure AD roles and Azure resource roles (e.g., Contributor), not network-level access to VM ports; it controls who can administer resources, not how traffic reaches the VM.

45
Multi-Selecthard

Which TWO of the following are required to implement a successful Just-In-Time (JIT) access strategy using Microsoft Entra Privileged Identity Management (PIM) for Azure resources?

Select 2 answers
A.Enable Azure Multi-Factor Authentication for all users in the tenant
B.Create custom RBAC roles for the JIT access
C.Configure role settings to specify activation duration and require approval if needed
D.Assign users as eligible for the roles they need to activate
E.Assign users as permanently active for the roles they need
AnswersC, D

Configuring role settings is a required step because these settings define the operational parameters of JIT activation, such as the maximum activation duration (e.g., 1 hour), whether approval is required, and whether justification and ticket information are mandatory. Without these settings, PIM cannot enforce time-bound activation or control the approval workflow, so the JIT strategy would lack governance. You must explicitly configure the settings for each role that you plan to manage with PIM.

Why this answer

Option C is correct because PIM role settings define the activation parameters that make access just-in-time, such as maximum activation duration, whether approval is required, and whether justification or MFA is needed at activation; without configuring these settings, eligible assignments would not enforce time-bound, controlled activation. Option D is correct because JIT access in PIM for Azure resources requires users to be assigned as eligible for the Azure RBAC roles they need, so they can activate the role only when required rather than holding standing access. Option A is not required for the JIT strategy itself, since MFA can be enforced as a role setting at activation rather than mandating MFA for all tenant users.

Option B is not required because PIM works with built-in Azure RBAC roles and custom roles are not a prerequisite for JIT access. Option E is incorrect because permanently active assignments provide standing access, which is the opposite of just-in-time access.

Exam trap

The trap here is that candidates often confuse enabling MFA tenant-wide (Option A) with PIM's ability to require MFA at activation time, which is a separate setting within the role activation policy, not a prerequisite.

46
Multi-Selecthard

Which THREE Microsoft Entra ID roles can be assigned to a user to manage Microsoft Defender XDR (formerly Microsoft 365 Defender) incidents? (Choose three.)

Select 3 answers
A.Exchange Administrator
B.Security Administrator
C.Global Reader
D.Security Operator
E.Global Administrator
AnswersB, D, E

Security Administrator is a built-in Microsoft Entra ID role that grants permission to read security information, manage security policies, and act on security alerts and incidents in Microsoft 365 Defender, Defender for Cloud, and Identity Protection. It includes important actions such as managing conditional access policies, resetting passwords, and updating MFA settings, making it an appropriate role for incident response without granting full tenant-wide control. Because it supports day-to-day security administration and remediation, it is one of the roles that can be correctly assigned to a user.

Why this answer

The Security Administrator role (Option B) can manage Microsoft Defender XDR incidents because it grants full access to security features, including the ability to view, investigate, and respond to incidents in the Microsoft 365 Defender portal. This role is designed for users who need to manage security policies and incidents without having full administrative control over the tenant.

Exam trap

The trap here is that candidates often confuse the Security Reader role with the Security Operator role, or assume that Global Reader (which can view security settings) is sufficient to manage incidents, but only roles with write permissions like Security Administrator, Security Operator, or Global Administrator can actually manage Defender XDR incidents.

47
MCQmedium

Your organization uses Microsoft Entra ID for identity management. You need to implement a solution that automatically detects and remediates identity risks such as leaked credentials and impossible travel. The solution must use built-in Microsoft Entra capabilities without additional licensing beyond Microsoft Entra ID P2. What should you configure?

A.Enable Privileged Identity Management (PIM) for role activation.
B.Create Conditional Access policies requiring MFA for all users.
C.Set up Access Reviews for guest users.
D.Configure Identity Protection policies for sign-in risk and user risk.
AnswerD

Identity Protection in Microsoft Entra ID aggregates machine-learning-based risk detections, including leaked credentials, impossible travel, anonymous IP addresses, and unfamiliar sign-in properties, into user-risk and sign-in-risk levels. You can configure risk-based Conditional Access policies to automatically require MFA or a secure password reset when risk thresholds are exceeded, providing both detection and auto-remediation. This is the service designed specifically to identify and act on identity risks.

Why this answer

The correct answer is D: Configure Identity Protection policies for sign-in risk and user risk. Microsoft Entra ID Protection is the built-in P2 capability that detects identity risks such as leaked credentials (user risk) and impossible travel (sign-in risk), and it can automatically remediate them by requiring MFA or password change through risk-based Conditional Access policies. PIM (A) governs just-in-time privileged role activation and does not detect leaked credentials or impossible travel.

Conditional Access requiring MFA for all users (B) enforces a static control and does not perform risk detection or risk-based remediation. Access Reviews for guest users (C) handle periodic attestation of guest access, not identity risk detection or remediation.

48
MCQeasy

You need to ensure that external users who are invited to your Microsoft Entra ID tenant via B2B collaboration can only access a specific SaaS application. What should you configure?

A.Configure SharePoint Online external sharing settings.
B.Create a Conditional Access policy targeting 'All cloud apps' and include guest users.
C.Create a Conditional Access policy targeting the SaaS application and apply it to 'Guest or external users'.
D.Use Microsoft Entra application proxy.
AnswerC

Using a Conditional Access policy that explicitly targets the SaaS application and applies it to 'Guest or external users' scopes both the identity and the resource. Under Target resources you select the specific app, and under Users a particular external user type such as 'B2B collaboration guest' is chosen, allowing the policy to enforce conditions like MFA or session controls. This is the correct pattern because it enforces access decisions at the app boundary for exactly the intended account type without affecting internal users or other applications.

Why this answer

A Conditional Access policy can be scoped to a specific SaaS application and applied to 'Guest or external users'. This ensures that only invited B2B collaboration users are subject to the access control for that application, while all other users and apps remain unaffected. The policy enforces authentication and authorization rules exclusively for the targeted SaaS app and guest identity type.

Exam trap

The trap here is that candidates often confuse broad Conditional Access policies (targeting 'All cloud apps') with application-specific policies, mistakenly thinking that including guest users in a blanket policy achieves the same restriction, when in fact it would block or require MFA for guest users across all apps, not just the target SaaS application.

How to eliminate wrong answers

Option A is wrong because SharePoint Online external sharing settings control sharing of documents and sites, not access to a specific SaaS application; they operate at the SharePoint level, not at the Entra ID application layer. Option B is wrong because targeting 'All cloud apps' would apply the policy to every application in the tenant, including Microsoft services and other SaaS apps, which is overly broad and does not restrict access to only the specific SaaS application. Option D is wrong because Microsoft Entra application proxy is used to publish on-premises web applications externally, not to control access for B2B guest users to a SaaS application; it does not provide granular access restriction per application for external identities.

49
MCQmedium

Refer to the exhibit. You are analyzing a Conditional Access policy JSON. The policy requires MFA for Office 365 applications. However, users report that they are still able to access Office 365 without MFA. What is the most likely reason?

A.The policy excludes some Office 365 apps
B.The 'grantControls' section is empty
C.The 'authenticationStrength' property is not a valid Conditional Access policy property
D.The policy does not include all users
AnswerB

Grant controls define what the policy enforces. With an empty grantControls section, no access requirement such as require multifactor authentication is applied, so the policy evaluates as satisfied and users reach Office 365 without completing MFA.

Why this answer

The most likely reason is that the 'grantControls' section is empty. In a Conditional Access policy, the 'grantControls' section specifies the controls to enforce, such as requiring MFA. If this section is empty, no controls are applied, and users can access Office 365 without MFA.

Exam trap

Candidates often overlook that an empty 'grantControls' section means no controls are enforced. The policy appears structurally correct but fails to apply any requirements.

How to eliminate wrong answers

Option A is wrong because excluding some Office 365 apps would still require MFA for the included apps, not allow all Office 365 access without MFA. Option B is wrong because an empty 'grantControls' section would cause the policy to fail validation or not apply, but the JSON shown does not have an empty 'grantControls'; the issue is the invalid property. Option D is wrong because not including all users would only exempt those specific users, but the policy would still enforce MFA for included users; the reported behavior is that all users can bypass MFA, indicating a policy-wide failure.

50
Multi-Selectmedium

Which TWO of the following are valid configurations for Microsoft Entra ID Conditional Access policies?

Select 2 answers
A.Include all users and exclude specific groups
B.Force password change on next sign-in
C.Target a specific cloud application
D.Block access for users without MFA registered
E.Assign licenses to users based on location
AnswersA, C

This is a valid user-and-group assignment in a Conditional Access policy. Selecting All users scopes the policy to every account in the tenant, while the Exclude tab lets you remove specific security groups such as break-glass emergency access accounts. This is the standard way to blanket-apply a policy while preserving administrative exceptions.

Why this answer

Conditional Access policies allow you to include all users as a baseline and then exclude specific groups (e.g., break-glass emergency accounts) to ensure critical access is never blocked. Option C is correct because you can target a specific cloud application (e.g., Microsoft Azure Management, SharePoint Online) to apply granular access controls only to that app, leaving other apps unaffected.

Exam trap

The trap here is that candidates confuse user risk remediation actions (like forcing a password change) with Conditional Access grant controls, or mistakenly think that Conditional Access can directly enforce MFA registration or license assignment, which are separate administrative functions.

51
MCQmedium

Your company uses Microsoft Entra ID with a hybrid identity model. You need to implement a solution that allows you to block legacy authentication attempts while still allowing modern authentication protocols. What should you use?

A.Create a Conditional Access policy to block legacy authentication
B.Enable Security defaults
C.Use Identity Protection to detect legacy authentication
D.Configure MFA for all users
AnswerA

A Conditional Access policy can be configured with the 'Client apps' condition to specifically block legacy authentication (e.g., basic auth over POP, IMAP, SMTP, or Exchange ActiveSync) while allowing modern OAuth 2.0 and OpenID Connect-based client flows. This provides granular control, so you can set exclusions for service accounts or privileged users and combine with session controls like MFA or sign-in frequency. This is the only option that selectively targets the authentication protocol itself without altering the modern authentication experience.

Why this answer

Conditional Access policies in Microsoft Entra ID allow you to explicitly block legacy authentication protocols (such as POP3, IMAP, SMTP, and basic auth) while permitting modern authentication (OAuth 2.0, OpenID Connect). By targeting the 'Client apps' condition and selecting 'Exchange ActiveSync clients' and 'Other clients', you can block all legacy auth attempts without affecting modern protocol traffic. This is the precise, granular control required for a hybrid identity model.

Exam trap

The trap here is that candidates often confuse Identity Protection's risk-based detection with the ability to block legacy authentication, or assume that enabling MFA alone will prevent legacy auth, when in fact legacy clients can still authenticate with just a password if the protocol is not explicitly blocked.

How to eliminate wrong answers

Option B is wrong because Security defaults enforces a blanket set of security baselines (including blocking legacy authentication for all users) but cannot be customized; it would block legacy auth for all users without the ability to selectively allow modern protocols or exclude specific accounts. Option C is wrong because Identity Protection detects and responds to risky sign-ins (e.g., leaked credentials, anonymous IP addresses) but does not block legacy authentication protocols; it is a risk-based detection tool, not a protocol-level enforcement mechanism. Option D is wrong because configuring MFA for all users forces multifactor authentication but does not inherently block legacy authentication; legacy clients that do not support MFA would still be able to authenticate using basic auth unless explicitly blocked.

52
MCQmedium

Your organization uses Microsoft Entra ID for identity management. You need to ensure that users accessing sensitive data from unmanaged devices are required to use a compliant device. What should you configure?

A.Configure a device registration policy
B.Configure a Conditional Access policy that requires that the device be marked as compliant
C.Configure an Identity Protection policy for user risk
D.Configure a Conditional Access policy that requires multi-factor authentication
AnswerB

A Conditional Access policy evaluates device state at sign-in, and requiring the device be marked compliant enforces that only Intune-managed, policy-compliant devices reach the sensitive data. This directly satisfies the stem's constraint of blocking access from unmanaged devices.

Why this answer

A Conditional Access policy that requires the device to be marked as compliant ensures that only devices meeting your organization's compliance standards (e.g., antivirus enabled, encryption active) can access sensitive data. This policy evaluates device compliance status reported by Microsoft Intune or another MDM provider, and blocks or grants access based on that status. It directly addresses the requirement to enforce compliant device access from unmanaged devices.

Exam trap

The trap here is that candidates often confuse requiring MFA (Option D) with requiring device compliance, but MFA only verifies the user, not the device's security posture, which is the core requirement in this scenario.

How to eliminate wrong answers

Option A is wrong because a device registration policy only controls whether devices can be registered or joined to Entra ID, not whether they are compliant or can access sensitive data. Option C is wrong because an Identity Protection policy for user risk focuses on user sign-in risk (e.g., leaked credentials, anonymous IP) and does not evaluate device compliance status. Option D is wrong because a Conditional Access policy requiring multi-factor authentication strengthens authentication but does not enforce device compliance; an unmanaged device could still access data after MFA.

53
Multi-Selectmedium

Which THREE of the following are valid methods to secure service principals in Microsoft Entra ID?

Select 3 answers
A.Use certificate-based credentials instead of client secrets
B.Assign the service principal to the Global Administrator role to monitor its activity
C.Configure Conditional Access for workload identities to restrict sign-in conditions
D.Enable Azure Multi-Factor Authentication for the service principal sign-in
E.Use Managed Identities for Azure resources to avoid managing credentials
AnswersA, C, E

Certificates rely on a public/private key pair: Azure AD stores and validates only the public key, while the private X.509 key stays protected in a certificate store or hardware security module. This removes shared client secrets from source code and configuration, and certificate expiry and rollover can be automated. Because a client secret is simply a string that can be copied or leaked, certificate-bound credentials provide substantially stronger authentication assurance for service principals.

Why this answer

Option A is correct because certificate-based credentials are a more secure alternative to client secrets for service principals; the public key is registered in Microsoft Entra ID and the private key is held by the app, so no shared secret is transmitted or stored, reducing the risk of credential theft. Option C is correct because Conditional Access for workload identities is a policy engine specifically designed to evaluate service principal sign-ins and can block or restrict them based on conditions such as location, risk, or IP range, which helps protect non-human identities. Option E is correct because Managed Identities for Azure resources let Azure create and rotate the service principal's credentials automatically, eliminating the need to store and manage secrets or certificates in code or configuration.

Option B is not appropriate because assigning a service principal the Global Administrator role grants excessive, unnecessary privileges and does not secure the principal; it increases risk. Option D is not valid because Azure Multi-Factor Authentication applies to interactive user sign-ins and cannot be enforced for a service principal, which authenticates non-interactively with secrets, certificates, or federated credentials.

Exam trap

The trap here is that candidates often confuse user identity security controls (like MFA) with workload identity security controls, assuming MFA can be applied to service principals, when in fact it cannot.

54
MCQeasy

Your organization wants to ensure that users accessing Office 365 from outside the corporate network must use MFA. What is the most efficient way to enforce this?

A.Enable MFA for all users in Microsoft Entra ID.
B.Create a Conditional Access policy for all cloud apps with location condition.
C.Use Conditional Access with device compliance condition.
D.Create a Conditional Access policy for Office 365 with location condition and require MFA.
AnswerD

Create a Conditional Access policy that targets the Office 365 cloud app, sets the location condition to include an untrusted named location or exclude trusted corporate IP ranges, and grants access only when MFA is satisfied. Because the scope is limited to the Office 365 application and an external location condition, internal users on the corporate trusted network are not subjected to MFA prompts, while external accesses to Exchange Online, SharePoint Online, and Teams are challenged. This is the least-privilege approach that precisely matches the stated requirement.

Why this answer

It specifically targets Office 365 cloud apps and uses the location condition to restrict MFA enforcement to access from outside the corporate network. This is the most efficient approach as it applies only to the relevant application and network location, minimizing user friction while meeting the requirement exactly.

Exam trap

The trap here is that candidates often choose a broad policy (Option B) thinking it covers all scenarios, but the question specifically asks for Office 365, so the most efficient solution targets only that app to avoid unnecessary MFA prompts on other cloud services.

How to eliminate wrong answers

Option A is wrong because enabling MFA for all users globally forces MFA on every sign-in, including from inside the corporate network, which is overly broad and inefficient. Option B is wrong because creating a Conditional Access policy for all cloud apps with a location condition would enforce MFA on every cloud app (e.g., Azure Portal, Dynamics 365), not just Office 365, which is unnecessary and may disrupt non-Office 365 workflows. Option C is wrong because using a device compliance condition enforces MFA based on device health rather than network location, failing to address the specific requirement of enforcing MFA only for external access.

55
MCQhard

Your organization uses Microsoft Entra ID with Privileged Identity Management (PIM) to manage roles. You need to ensure that when a user activates a role, the activation is automatically approved only if the user's manager approves within 30 minutes. If the manager does not respond, the activation is denied. What configuration should you implement?

A.Enable just-in-time access for the role and configure a group approval with a 30-minute timeout.
B.Configure the role settings to require approval, set the maximum activation duration to 30 minutes, and add the user's manager as an approver.
C.Create an approval workflow in Microsoft Entra ID that assigns the manager as the approver and set a timeout of 30 minutes.
D.Configure the role settings to require approval and set the approval timeout to 0 minutes.
AnswerB

This ensures the manager must approve within the activation window, or the request expires.

Why this answer

In Microsoft Entra ID PIM, the 'Maximum activation duration' setting in role settings controls the time window within which an approval must be granted. If the approver does not respond within that duration, the activation request is denied. By setting this to 30 minutes, requiring approval, and adding the user's manager as an approver, you ensure the manager must approve within 30 minutes or the activation is automatically denied.

This directly meets the requirement.

Exam trap

The trap here is thinking that a separate 'Approval timeout' setting exists, when in fact the 'Maximum activation duration' serves as the timeout for the approval request itself. Candidates may incorrectly look for a distinct approval timeout setting, leading them to choose options that do not exist or are misconfigured.

How to eliminate wrong answers

Option A is wrong because enabling just-in-time access and configuring a group approval with a 30-minute timeout does not specifically assign the user's manager as the approver; group approval requires a predefined group, not dynamic manager assignment. Option C is wrong because creating an approval workflow in Microsoft Entra ID is not a native PIM feature; PIM uses role settings for approval, not separate workflows, and the timeout must be configured in the role settings, not in a workflow. Option D is wrong because setting the approval timeout to 0 minutes would cause the approval request to expire immediately, not wait 30 minutes for the manager's response, and it does not specify the manager as the approver.

56
MCQmedium

You are designing a secure access solution for an Azure App Service web application. The application uses Microsoft Entra ID for authentication. You need to ensure that only users from specific partner organizations can access the app. Which configuration should you use?

A.Use a custom domain for the app
B.Configure the app to accept tokens from the partner tenants as external identity providers
C.Block all external users
D.Require multi-factor authentication for all users
AnswerB

Configuring the app to accept tokens from partner tenants as external identity providers is the core of Azure AD B2B collaboration. You register the app as a multi-tenant application or add partner tenants as trusted identity providers; users authenticate in their home tenant and receive tokens that your app validates. This allows you to grant specific partner users access while keeping your own tenant as the authority for the application.

Why this answer

Azure App Service can be configured to accept tokens from multiple Microsoft Entra ID tenants as external identity providers. This allows users from specific partner organizations to authenticate using their own Entra ID tenant, while the app validates the tokens and grants access only to those partner tenants you explicitly trust.

Exam trap

The trap here is that candidates often confuse 'external identity providers' with 'blocking external users' or 'MFA', not realizing that the correct approach is to explicitly allow specific partner tenants as identity providers rather than applying a blanket security policy.

How to eliminate wrong answers

Option A is wrong because using a custom domain for the app only changes the app's URL and does not control which identity providers or tenants can authenticate users. Option C is wrong because blocking all external users would prevent access from partner organizations entirely, which contradicts the requirement to allow specific partner users. Option D is wrong because requiring multi-factor authentication for all users enhances security but does not restrict access to specific partner tenants; it applies to all authenticated users regardless of their origin.

57
MCQmedium

You are troubleshooting a sign-in issue. A user reports that they are repeatedly prompted for authentication when accessing a cloud app, even though they already authenticated earlier in the day. You check the Conditional Access policy and see that 'Session control - Sign-in frequency' is set to 1 hour. What is the most likely cause?

A.The sign-in frequency setting forces reauthentication after 1 hour
B.The browser is blocking persistent cookies
C.Token lifetime policy overrides the sign-in frequency
D.The user is considered high risk by Identity Protection
AnswerA

This is correct because in Azure AD Conditional Access, the sign-in frequency session control is configured to require the user to reauthenticate after a specified time period, here 1 hour. When that interval elapses, Azure AD forces a fresh authentication prompt even if the user's browser session and tokens are still technically valid, so the user experiences a sign-in interruption. The setting is evaluated independently of the underlying session, which explains why the user is prompted again exactly after 1 hour.

Why this answer

The 'Session control - Sign-in frequency' setting in Conditional Access enforces reauthentication at the specified interval. When set to 1 hour, the user must re-authenticate every hour, regardless of prior authentication earlier in the day. This explains the repeated prompts, as the session lifetime is capped by this policy.

Exam trap

The trap here is that candidates confuse sign-in frequency with token lifetime policies, assuming token lifetimes control reauthentication frequency, when in fact Conditional Access session controls override token lifetime settings for the specified apps.

How to eliminate wrong answers

Option B is wrong because persistent cookies are not required for sign-in frequency enforcement; the policy uses session tokens and refresh tokens, not browser cookies. Option C is wrong because token lifetime policies (e.g., via Azure AD or AD FS) are overridden by Conditional Access session controls when both are configured; the sign-in frequency takes precedence. Option D is wrong because Identity Protection risk-based policies would trigger additional controls (e.g., MFA or block), not simply reauthentication prompts at a fixed interval.

58
MCQhard

Your organization uses Microsoft Intune for mobile device management. You need to implement a conditional access policy that only allows access to corporate email from devices that are enrolled in Intune and compliant with security policies. However, the policy is not working for some users who report that they cannot access email even though their devices are compliant. You discover that the users have multiple devices and are signing in from a device that is not enrolled. What should you do?

A.Enroll all devices in Intune
B.Remove the conditional access policy
C.Use app protection policies instead
D.Ensure users sign in only from compliant devices
AnswerD

Conditional access evaluates the device used at sign-in, so a compliant device does not help when the user authenticates from an unenrolled one. Requiring sign-in only from compliant devices blocks that access, satisfying the policy's device-compliance constraint.

Why this answer

The correct answer is D: Ensure users sign in only from compliant devices. In a Conditional Access scenario, the policy evaluates the specific device used for the sign-in, so if a user has multiple devices and authenticates from a non-enrolled or non-compliant one, access to corporate email will be blocked even if another of their devices is compliant; the fix is to make sure the sign-in originates from a compliant device. Option A is unnecessary and impractical because enrolling every device is not required by the policy, only the device being used for access must be enrolled and compliant.

Option B would defeat the security requirement entirely by removing the control. Option C does not fit because app protection policies (MAM) protect app data on unmanaged devices but do not satisfy a Conditional Access requirement that the device itself be Intune-enrolled and compliant.

59
MCQmedium

Your company uses Microsoft Intune for mobile device management. You need to ensure that only devices that are compliant with company policies can access corporate resources. You have configured compliance policies in Intune. What additional step is required to enforce access control based on device compliance?

A.Create a Conditional Access policy that requires device to be marked as compliant
B.Enable certificate-based authentication for all devices
C.Deploy device configuration profiles to all devices
D.Configure app protection policies in Microsoft Defender for Cloud Apps
AnswerA

A Conditional Access policy that requires a device to be marked as compliant works directly with Microsoft Intune's compliance policies. When a device fails to meet compliance rules (e.g., PIN required, OS version, threat level), Intune marks it as non-compliant, and Conditional Access evaluates this state at sign-in to block access to cloud apps. This is the standard enforcement mechanism for Intune-managed devices.

Why this answer

A is correct because Conditional Access in Azure AD is the policy engine that enforces access control decisions based on signals like device compliance. Even after Intune compliance policies are configured, you must create a Conditional Access policy that requires the device to be marked as compliant. This policy blocks or grants access to corporate resources (e.g., Exchange Online, SharePoint) based on the compliance state reported by Intune to Azure AD.

Exam trap

The trap here is that candidates often assume Intune compliance policies alone enforce access control, but they only define the rules; Conditional Access is the separate service that actually enforces the block or grant based on those rules.

How to eliminate wrong answers

Option B is wrong because certificate-based authentication (CBA) authenticates the device or user but does not enforce compliance-based access control; it only verifies identity via certificates. Option C is wrong because device configuration profiles define settings (e.g., Wi-Fi, VPN) but do not enforce access control based on compliance state. Option D is wrong because app protection policies in Microsoft Defender for Cloud Apps (formerly MCAS) manage data protection within apps, not device-level compliance enforcement for access.

60
MCQeasy

You are configuring a conditional access policy to block access from untrusted locations. The policy should apply to all cloud apps except Microsoft Entra ID Administration. How should you configure the policy?

A.Include 'All cloud apps' and set 'Block access'
B.Include 'Select apps' and choose all apps except admin
C.Include 'All cloud apps' and exclude 'Microsoft Entra ID Administration'
D.Include 'All cloud apps' and exclude 'Office 365'
AnswerC

Conditional access evaluates include and exclude scopes, with exclusions taking precedence. Selecting 'All cloud apps' as the include and excluding 'Microsoft Entra ID Administration' satisfies the requirement to block untrusted locations everywhere except administrative access, avoiding the need to enumerate every individual app.

Why this answer

The requirement is to block access from untrusted locations for all cloud apps except Microsoft Entra ID Administration. In Conditional Access, you include 'All cloud apps' to cover every app, then explicitly exclude 'Microsoft Entra ID Administration' to exempt it from the block. This ensures the policy applies broadly while honoring the exclusion.

Exam trap

The trap here is that candidates often confuse 'Microsoft Entra ID Administration' with 'Office 365' or think they must manually select all apps, missing the efficient 'All cloud apps' plus exclusion pattern.

How to eliminate wrong answers

Option A is wrong because including 'All cloud apps' and setting 'Block access' would block all cloud apps, including Microsoft Entra ID Administration, which violates the requirement to exclude it. Option B is wrong because 'Select apps' requires manually picking each app, which is impractical for 'all cloud apps except one' and does not dynamically cover future apps. Option D is wrong because excluding 'Office 365' does not match the requirement to exclude 'Microsoft Entra ID Administration'; Office 365 is a different app set and would incorrectly block the admin portal.

61
MCQmedium

Your company uses Microsoft Entra ID and Microsoft Intune for mobile device management. You need to ensure that only devices that are compliant with your security policies can access Exchange Online. The solution must require users to reauthenticate every 12 hours. What should you configure?

A.Create a Conditional Access policy that requires MFA for Exchange Online and set sign-in frequency to 12 hours.
B.Create a Conditional Access policy that grants access to Exchange Online only if the device is compliant, and set session sign-in frequency to 12 hours.
C.Create an app protection policy for Exchange Online that requires device compliance and sets sign-in frequency.
D.Configure a device compliance policy for all devices and enable 'Reauthenticate every 12 hours' in the compliance policy.
AnswerB

Conditional Access enforces the compliance gate by requiring Intune-marked compliant devices before granting Exchange Online access. Sign-in frequency set to 12 hours forces reauthentication at that interval, satisfying both the device-compliance and periodic-reauthentication constraints in one policy.

Why this answer

A Conditional Access policy can enforce device compliance as a grant control for Exchange Online, ensuring only compliant devices can access the service. Setting the session sign-in frequency to 12 hours forces users to reauthenticate at that interval, meeting the requirement without requiring MFA. This combines device compliance enforcement with session lifetime control in a single policy.

Exam trap

The trap here is that candidates confuse device compliance policies with Conditional Access session controls, assuming sign-in frequency can be set directly in a compliance policy, when it is actually a separate Conditional Access setting.

How to eliminate wrong answers

Option A is wrong because requiring MFA does not enforce device compliance; it only adds an authentication factor, so non-compliant devices could still access Exchange Online. Option C is wrong because app protection policies (MAM) manage data protection within apps, not device-level compliance, and they do not support a sign-in frequency setting. Option D is wrong because a device compliance policy itself does not include a 'Reauthenticate every 12 hours' setting; sign-in frequency is a Conditional Access session control, not a compliance policy setting.

62
MCQeasy

You are the identity security engineer for a multinational company that uses Microsoft Entra ID. The company has recently experienced a security breach where an attacker compromised a non-administrator user account and then used that account to enumerate all users in the tenant. The attacker then attempted to brute-force passwords for high-privilege accounts. To prevent such attacks, management requires the following: - Users with administrative roles must use phishing-resistant MFA. - Any sign-in from a risky IP address must be blocked. - Users must not be able to enumerate directory information via the Graph API unless they have a specific role. - The solution should be implemented using built-in Microsoft Entra ID features. What should you configure?

A.Enable Security defaults and configure Identity Protection user risk policy to block high-risk users.
B.Configure Conditional Access policy with authentication strength for admins requiring phishing-resistant MFA. Configure Identity Protection sign-in risk policy to block risky sign-ins. Restrict access to the Graph API by requiring a specific role assignment.
C.Configure Conditional Access policy for admins to require phishing-resistant MFA. Use PIM to require approval. Enable Identity Protection sign-in risk policy.
D.Configure PIM for all admin roles. Create access reviews for all users. Enable Identity Protection to detect risky sign-ins.
AnswerB

This is the correct answer because it layers three complementary controls that directly counter the attacker's tactic. Conditional Access with an authentication strength policy requiring phishing-resistant MFA (such as FIDO2 or Windows Hello) prevents credential theft and token replay that bypass ordinary MFA. The Identity Protection sign-in risk policy blocks sign-ins in real time when the risk level is high, such as those coming from anonymous IP addresses or anomalous locations. Restricting access to the Microsoft Graph API by requiring a specific role assignment ensures that only authorized identities can enumerate directory objects, closing the enumeration vector.

Why this answer

Phishing-resistant MFA can be enforced via Conditional Access with authentication strength. Sign-in risk policies in Identity Protection can block sign-ins from risky IPs. To prevent directory enumeration, you can restrict access to the Graph API by requiring a specific role assignment.

Option A is wrong because Security defaults enforce MFA but do not block all enumeration. Option C is wrong because PIM does not block enumeration. Option D is wrong because access reviews do not block enumeration.

63
MCQhard

Your company is implementing a zero-trust security model. You need to ensure that all access to cloud applications is continuously verified based on user identity, device health, and location. Which combination of Microsoft security solutions should you use?

A.Microsoft Sentinel and Azure Policy
B.Microsoft Entra ID Protection and Privileged Identity Management
C.Azure Active Directory Domain Services and Azure Firewall
D.Microsoft Entra ID Conditional Access, Microsoft Intune, and Microsoft Defender for Cloud Apps
AnswerD

Conditional Access acts as the policy enforcement engine that combines user, device, location, and risk signals to require MFA or block sign-in, while Intune supplies the device compliance and configuration evidence that Conditional Access consumes. Defender for Cloud Apps extends enforcement beyond sign-in by applying session controls to discovered SaaS apps, so a flagged user can be allowed in read-only mode or prevented from uploading sensitive files. This identity-device-app trio verifies trust before access, during a session, and on the data plane, which is exactly the continuous verification model zero trust demands.

Why this answer

The zero-trust requirement for continuous verification of user identity, device health, and location is met by combining Microsoft Entra ID Conditional Access (enforces policies based on user, device, and location signals), Microsoft Intune (manages device compliance and health), and Microsoft Defender for Cloud Apps (provides continuous session-level monitoring and control of cloud app access). This trio delivers the real-time, policy-driven access checks that zero trust demands.

Exam trap

The trap here is that candidates often pick Option B (Identity Protection + PIM) because they associate identity protection with zero trust, but they miss the critical need for device health verification (Intune) and continuous session monitoring (Defender for Cloud Apps) that are explicitly required by the question.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel is a SIEM/SOAR for threat detection and response, not an access control solution, and Azure Policy enforces resource compliance at the Azure infrastructure layer, not user/device/location-based access to cloud apps. Option B is wrong because Microsoft Entra ID Protection focuses on risk-based detection and remediation of compromised identities, and Privileged Identity Management (PIM) manages just-in-time privileged role activation; neither continuously verifies device health or location for all cloud app access. Option C is wrong because Azure Active Directory Domain Services provides managed domain services (e.g., LDAP, Kerberos) for legacy apps, not modern conditional access, and Azure Firewall is a network-layer firewall that cannot evaluate user identity, device health, or application-level signals.

64
MCQeasy

You need to ensure that when a user's role in Microsoft Entra ID is changed (e.g., from User to Global Administrator), the change is approved by a manager before it takes effect. Additionally, you need to enforce just-in-time (JIT) access for that role. What should you use?

A.Configure Microsoft Entra Privileged Identity Management (PIM) for the role with approval required and JIT activation.
B.Use Microsoft Entra access reviews to review role assignments monthly.
C.Create a Conditional Access policy requiring manager approval for role assignment.
D.Assign the role via Azure RBAC with a custom role.
AnswerA

Microsoft Entra Privileged Identity Management provides eligible role assignments with approval workflows and time-bound JIT activation, so a manager must approve before the Global Administrator role becomes active. Standard role assignment cannot enforce approval or JIT.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) is the correct choice because it is the only service that provides just-in-time (JIT) role activation with an approval workflow, allowing you to require a manager's approval before a role assignment becomes active. In PIM, you configure the role's settings to require approval for activation and set the maximum activation duration, so the user is eligible but not permanently assigned until approved. Access reviews (B) only recertify existing assignments periodically and do not gate activation or provide JIT.

Conditional Access (C) controls access to resources based on signals like user, device, and location, but it cannot require manager approval for a directory role assignment. Azure RBAC custom roles (D) scope permissions on Azure resources but do not provide approval workflows or JIT activation for Microsoft Entra ID roles.

65
Multi-Selectmedium

You are the identity security engineer for a company that uses Microsoft Entra ID. You need to reduce the risk of credential theft for administrative accounts. Which TWO controls should you implement? (Choose two.)

Select 2 answers
A.Configure a long password expiration interval of 730 days for administrator accounts.
B.Assign the Privileged Authentication Administrator role to a shared helpdesk account.
C.Require passwordless authentication methods such as FIDO2 security keys for administrators.
D.Enable self-service password reset for all administrator accounts.
E.Enable Microsoft Entra Password Protection with a custom banned password list.
AnswersC, E

Passwordless methods remove the shared secret from the sign-in process, so there is no password to phish or steal. Requiring FIDO2 or Windows Hello for Business for administrators significantly reduces credential theft risk because the credential is bound to a device and cannot be replayed.

Why this answer

Passwordless authentication removes the password as a stealable secret, and banned password lists prevent weak or predictable passwords from being set. Together they reduce the likelihood that an administrative credential can be phished, guessed, or reused, which directly addresses credential theft risk.

Exam trap

The trap here is assuming that password expiration policies or self-service password reset reduce credential theft, when they mainly address password age and recovery.

66
MCQeasy

Refer to the exhibit. You run the command and see the output. What does the UserType 'Member' indicate?

A.The user is a service principal
B.The user is a guest user
C.The user is an administrator
D.The user is a member of the tenant
AnswerD

When the output shows UserType 'Member', it means the user account is an internal, home-directory member of the Azure AD tenant. Such users are typically created directly in that tenant or synchronized from on-premises Active Directory via Azure AD Connect, and they belong to the tenant organization rather than being invited from outside. This is precisely the correct interpretation: the command returned a user object whose directory membership type is Member, so the user is a member of the tenant.

Why this answer

The UserType 'Member' indicates that the user is a member of the tenant, meaning the user's identity is native to the Azure AD tenant and not from an external directory. This is distinct from 'Guest' (UserType = Guest), which represents external users invited via B2B collaboration. The command shown is likely Get-AzureADUser or a similar cmdlet, where the UserType property directly reflects the user's relationship to the tenant.

Exam trap

The trap here is that candidates confuse the UserType property with the user's role or administrative status, when in fact UserType only distinguishes between native tenant members and external B2B guests, not their permissions or directory roles.

How to eliminate wrong answers

Option A is wrong because a service principal is represented by a ServicePrincipal object, not a User object, and its UserType would not be 'Member'; service principals have their own object type and are not users. Option B is wrong because a guest user has UserType = 'Guest', not 'Member'; the 'Member' value explicitly indicates the user is not a guest. Option C is wrong because being an administrator is a role assignment, not a user type; a user can be a Member and have no admin roles, or be a Guest and have admin roles, so UserType does not indicate administrative status.

67
MCQeasy

Your organization uses Microsoft Entra ID and has deployed Microsoft Defender for Cloud Apps. You need to monitor and control access to cloud applications based on user behavior and device health. Which feature should you use?

A.Microsoft Purview Information Protection
B.Conditional Access App Control
C.Cloud App Discovery
D.OAuth app policies
AnswerB

Conditional Access App Control, part of Microsoft Defender for Cloud Apps, integrates with Microsoft Entra ID Conditional Access to reroute user sessions through a reverse proxy, enabling real-time monitoring and control. It analyzes signals such as user behavior, device compliance, and location to enforce granular actions like blocking downloads, restricting uploads, or requiring step-up authentication during the session. This precisely matches the requirement for session-level access control based on behavior and device health, making it the correct solution.

Why this answer

Conditional Access App Control (CAAC) is a feature of Microsoft Defender for Cloud Apps that integrates with Microsoft Entra ID Conditional Access policies to monitor and control access to cloud applications in real time. It enforces access controls based on user behavior (e.g., risky sign-ins) and device health (e.g., compliance status from Intune), allowing actions like blocking downloads or requiring session monitoring. This directly meets the requirement to monitor and control access based on user behavior and device health.

Exam trap

The trap here is that candidates often confuse Cloud App Discovery (which only identifies apps in use) with Conditional Access App Control (which enforces real-time access policies based on user behavior and device health), leading them to select Option C incorrectly.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Protection focuses on classifying, labeling, and protecting sensitive data (e.g., encryption, rights management), not on monitoring or controlling access based on user behavior or device health. Option C is wrong because Cloud App Discovery is a feature that identifies shadow IT by discovering cloud apps in use across the organization, but it does not provide real-time access control or session monitoring based on user behavior or device health. Option D is wrong because OAuth app policies in Defender for Cloud Apps govern permissions granted to third-party OAuth apps (e.g., revoking or approving app consent), not user behavior or device health-based access control.

68
MCQhard

Your organization has Microsoft Entra ID and uses Microsoft Copilot for Microsoft 365. You need to ensure that Copilot interactions are logged and accessible for security investigations. What should you configure?

A.Configure Microsoft Sentinel to collect Copilot logs via the Office 365 connector
B.Enable diagnostic settings in Azure Monitor to collect Copilot logs
C.Ensure that auditing is enabled in Microsoft Purview to capture Copilot interactions
D.Deploy Microsoft Defender for Cloud Apps to monitor Copilot usage
AnswerC

Microsoft Purview's unified audit log is the authoritative repository for compliance-related events across Microsoft 365, including Copilot user prompts and responses. When Purview auditing is enabled at the tenant level, the audit engine records Copilot interaction metadata such as the user, timestamp, and action performed, making these records searchable in the Purview compliance portal. This audit trail can also be exported through the Office 365 Management Activity API or integrated with Microsoft Sentinel after the logs have been collected by Purview, but the core requirement is enabling Purview auditing itself.

Why this answer

Microsoft Copilot for Microsoft 365 interactions are audited through the Microsoft Purview audit log. Enabling auditing in Purview captures detailed records of Copilot prompts and responses, which are then accessible for security investigations via the Purview compliance portal or through the Office 365 Management Activity API. This is the designated mechanism for logging Copilot activity, as Copilot interactions are considered Microsoft 365 workload events.

Exam trap

The trap here is that candidates often assume Copilot logs are collected via Azure Monitor or Microsoft Sentinel connectors by default, when in reality Copilot auditing is a Microsoft Purview feature that must be explicitly enabled and is not automatically routed to Azure monitoring tools.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel's Office 365 connector ingests logs from the Office 365 Management Activity API, but it does not natively collect Copilot-specific interaction logs; Copilot logs require Purview auditing to be enabled first, and even then, Sentinel can only consume them if Purview auditing is already active. Option B is wrong because Azure Monitor diagnostic settings are used to collect telemetry from Azure resources (e.g., VMs, App Services), not from Microsoft 365 workloads like Copilot; Copilot logs are not emitted to Azure Monitor. Option D is wrong because Microsoft Defender for Cloud Apps focuses on shadow IT discovery and session-level monitoring for SaaS apps, not on capturing detailed Copilot prompt/response audit logs; it can use Purview audit logs as a source but does not replace the need for Purview auditing.

69
MCQhard

You are troubleshooting an issue where users are unable to access a sensitive application protected by a Conditional Access policy. The policy requires MFA from trusted locations, but users are reporting that they are prompted for MFA even when connecting from the corporate office, which is defined as a trusted location. What is the most likely cause?

A.The corporate office's public IP address is not correctly defined in the trusted location
B.The policy is configured to require MFA for all locations regardless of trust
C.The policy is set to 'Require MFA' instead of 'Require MFA from trusted locations'
D.Users are not assigned to the policy
AnswerA

A named location in Azure AD must exactly match the current public egress IP range of the corporate network. If the range is stale, missing, or mistakenly configured with the wrong CIDR (for example, after an ISP change or a new NAT device), the user's source IP at the office will not match the trusted location. As a result, the Conditional Access policy sees the request as coming from an untrusted network and enforces MFA even though the user is physically inside the office. Verify the public IP and CIDR range in the named location, and confirm that the office's outbound IP has not changed.

Why this answer

The most likely cause is that the corporate office's public IP address is not correctly defined in the trusted location. Conditional Access policies evaluate location based on named locations configured in Azure AD, which must include the exact public IP ranges (CIDR notation) of the trusted network. If the IP address is missing, misconfigured, or the user's outbound IP differs (e.g., due to a VPN or proxy), the policy treats the location as untrusted and enforces MFA.

Exam trap

The trap here is that candidates may assume the policy is misconfigured to require MFA for all locations (Option B) or that the policy type is wrong (Option C), but the real issue is a misalignment between the actual public IP and the defined trusted location, which is a common oversight in real-world deployments.

How to eliminate wrong answers

Option B is wrong because if the policy were configured to require MFA for all locations regardless of trust, users would be prompted for MFA everywhere, not just from the corporate office, and the question specifies the issue is only from the corporate office. Option C is wrong because the policy setting 'Require MFA' versus 'Require MFA from trusted locations' is not a distinct toggle; Conditional Access policies use grant controls like 'Require multi-factor authentication' combined with a condition for locations, so this option misrepresents the configuration. Option D is wrong because if users were not assigned to the policy, they would not be prompted for MFA at all, contradicting the reported behavior.

70
Multi-Selectmedium

Your company uses Microsoft Entra ID (P2 licensed) and requires that all user logins from untrusted networks be blocked unless the user's device is marked as compliant by Microsoft Intune. You need to implement this requirement. Which TWO components should you use together to achieve this? (Choose two.)

Select 2 answers
A.Privileged Identity Management (PIM)
B.Microsoft Entra Identity Protection
C.Conditional Access policy with device compliance condition
D.Microsoft Intune Device Compliance policy
E.Microsoft Entra Access Reviews
AnswersC, D

A Conditional Access policy with the "Require device to be marked as compliant" condition is the actual enforcement mechanism that blocks or grants access based on the device's current compliance status. When a user attempts to access a cloud app from an untrusted network, the policy combines location and device compliance conditions to deny access if the device is not marked compliant, or grant it if the device is compliant. This policy evaluates the compliance state in real time, using data supplied by Intune, and is the direct control that enforces the requirement.

Why this answer

Option C is correct because a Conditional Access policy is the mechanism in Microsoft Entra ID that enforces access decisions at sign-in; you configure it with conditions (for example, 'All locations' or 'Any location' excluding trusted named locations) and grant controls requiring a compliant device, so logins from untrusted networks are blocked unless the device meets the compliance requirement. Option D is correct because Microsoft Intune Device Compliance policy defines what 'compliant' actually means (for example, BitLocker enabled, minimum OS version, Defender/antivirus active, no jailbreak/root), and it sets the device's compliance state in Entra ID that the Conditional Access policy evaluates. Together, the Intune compliance policy produces the device compliance signal and the Conditional Access policy consumes it to block non-compliant devices from untrusted networks.

Option A (PIM) is for just-in-time privileged role activation and approval, not for device-based sign-in blocking. Option B (Identity Protection) detects and responds to risky users/sign-ins but does not itself enforce device compliance. Option E (Access Reviews) is for periodic attestation of group, role, or application access, not for real-time conditional access enforcement.

Ready to test yourself?

Try a timed practice session using only Secure identity and access questions.