Courseiva

Microsoft Cybersecurity Architect (SC-100) — Questions 1–75

605 questions total · 9pages · All types, answers revealed

Page 1 of 9

Page 2
1
MCQeasy

You are a security architect for a retail company that uses Microsoft 365 and Azure. The company has a large number of remote employees who use both company-managed and personal devices. You need to design a solution to ensure that only compliant devices can access corporate email (Exchange Online) and files (SharePoint Online). The company has Microsoft Intune and Microsoft Entra ID P1 licenses. You need to implement device-based conditional access. What should you do?

A.Deploy app protection policies (MAM) in Intune to protect data in Exchange Online and SharePoint Online.
B.Enroll devices in Intune, create compliance policies, and configure Conditional Access policies in Entra ID to require compliant devices.
C.Require all devices to be enrolled in Intune using automatic enrollment via Group Policy.
D.Use Microsoft Endpoint Configuration Manager to manage device compliance and integrate with Entra ID.
AnswerB

This is the correct approach because it combines Intune enrollment (giving the device an identity in Entra ID), compliance policies (defining security baselines such as BitLocker, Windows Defender, or iOS / Android compliance settings), and Conditional Access policies in Entra ID that gate access based on the device's compliance state. When a device is both enrolled and marked compliant, Entra ID trusts that signal and grants or blocks access to cloud resources accordingly. The Conditional Access policy 'Require compliant device' relies on this evaluation and is the only way to enforce compliance-driven access across both managed and unmanaged apps.

Why this answer

Intune compliance policies define device health requirements, and Conditional Access policies enforce access based on compliance. Option A is wrong because app protection policies are for mobile application management (MAM) without device enrollment, but the requirement is device-based. Option C is wrong because device enrollment itself does not enforce compliance.

Option D is wrong because Configuration Manager is for on-premises management, not cloud devices.

2
Multi-Selecthard

Which TWO of the following are true about Azure Policy initiatives?

Select 2 answers
A.Initiatives cannot be assigned to a management group
B.Initiatives can be assigned to management groups, subscriptions, or resource groups
C.An initiative can only contain one policy definition
D.Initiatives are predefined and cannot be customized
E.Initiatives help to organize policies by grouping them under a common goal
AnswersB, E

Microsoft Azure Policy allows both individual policy definitions and initiative definitions to be assigned at the exact same scopes: management groups, subscriptions, and resource groups. This is by design, because an initiative is simply a bundle of policy definitions that are evaluated together when assigned. Because management groups form a hierarchy, assigning an initiative at a higher scope causes it to be inherited by all descendant scopes, which is useful for enforcing standards across an entire organization.

Why this answer

Azure Policy initiatives (also known as policy sets) are designed to group multiple policy definitions together to achieve a common compliance goal. They can be assigned at the management group, subscription, or resource group scope, which allows for broad or granular enforcement of compliance rules across the Azure hierarchy.

Exam trap

The trap here is that candidates often confuse initiatives with single policy definitions, assuming they cannot be customized or assigned broadly, when in fact initiatives are designed for grouping and flexible assignment across multiple scopes.

3
MCQhard

You are designing a data security solution for a Microsoft 365 tenant that contains highly confidential files. You need to ensure that these files are encrypted and can only be accessed by authorized users, even if the files are downloaded and stored on a personal device. Which technology should you use?

A.Office 365 Message Encryption
B.Microsoft Purview Information Protection with encryption and usage rights
C.BitLocker Drive Encryption
D.Azure Information Protection
AnswerB

Microsoft Purview Information Protection with encryption and usage rights is the current, unified file-protection service in Microsoft 365. It lets you apply labels that encrypt files (Word, Excel, PowerPoint, PDF) and attach usage rights—such as View, Edit, Copy, Print, and Forward—that are enforced by Azure Rights Management. These rights are embedded in the file metadata and travel with the file wherever it goes, so even if a user downloads a document to a USB stick or emails it to a third party, access is still governed by the policy. This persistent protection, combined with user-friendly labeling and DLP integration, makes it the correct answer for protecting data at rest and in motion within and outside the tenant.

Why this answer

Microsoft Purview Information Protection with encryption and usage rights (option B) is correct because it applies persistent protection to the file itself via sensitivity labels, so the encryption and usage restrictions travel with the document even after it is downloaded to a personal device, and only authorized users with the granted rights can open it. Office 365 Message Encryption (A) only protects email messages in transit and does not persist on files stored locally. BitLocker (C) encrypts the whole drive at the OS level, so protection is lost once the file leaves that device.

Azure Information Protection (D) is the legacy predecessor now superseded by Purview Information Protection, making B the current, appropriate choice.

4
MCQhard

A large financial services company is migrating its customer-facing web application to Azure. The application handles sensitive personal data and must comply with PCI DSS. The solution will use Azure App Service (Linux) with a custom container, Azure SQL Database, and Azure Redis Cache. The security architect mandates that all data in transit be encrypted using the latest TLS version, and that the application must be protected against common web vulnerabilities. The company also wants to ensure that only authenticated users can access the Redis cache. Users will authenticate via Microsoft Entra ID. The operations team needs to be able to monitor for SQL injection attempts and anomalous access patterns. You need to design the security configuration. Which of the following is the most comprehensive approach that meets all requirements?

A.Configure App Service to enforce TLS 1.2 as minimum. Deploy Azure Application Gateway with WAF enabled in front of App Service. Enable Azure AD authentication for Azure Redis Cache. Enable Microsoft Defender for SQL for Azure SQL Database.
B.Use Azure Front Door with custom domain and enforce TLS 1.2. Configure IP firewall on Redis Cache. Use Azure SQL Database with VNet service endpoints.
C.Deploy App Service with HTTPS only enabled. Use Azure API Management with WAF. Use Redis Cache with access keys. Enable SQL audit logging.
D.Enable TLS 1.3 on App Service. Use Azure CDN with WAF. Configure Redis Cache with a firewall rule allowing only App Service outbound IPs.
AnswerA

This is the correct defense-in-depth approach. Enforcing TLS 1.2 as the minimum on App Service guarantees strong transport encryption for all client communications. Deploying Azure Application Gateway with WAF enabled in front of App Service provides an OWASP Top 10 web application firewall that inspects and blocks malicious L7 traffic, preventing SQL injection, XSS, and other common attacks. Enabling Azure AD authentication for Redis Cache replaces key-based access with managed identity, supporting passwordless, conditional access policies. Microsoft Defender for SQL for Azure SQL Database adds threat detection, vulnerability assessment, and anomaly alerts, covering the database tier comprehensively.

Why this answer

Azure App Service enforces TLS 1.2/1.3 by default. Azure WAF (Web Application Firewall) in front of App Service protects against OWASP Top 10. Azure AD authentication for Redis Cache is supported via Azure AD RBAC for Redis (currently in preview but available).

Microsoft Defender for SQL detects SQL injection and anomalous access. Option A covers all requirements. Option B uses Application Gateway without WAF.

Option C uses Redis firewall which doesn't enforce authentication. Option D uses Azure Front Door without WAF.

5
MCQeasy

Your organization stores sensitive customer data in Azure Blob Storage. You need to implement data classification and labeling using Microsoft Purview. Which resource should you use to automatically scan and classify the data?

A.Azure Policy
B.Microsoft Purview Data Map
C.Microsoft Purview Information Protection
D.Microsoft Purview Data Loss Prevention
AnswerB

Microsoft Purview Data Map is the correct choice because it performs automated metadata scanning and classification of assets across data sources, including Azure Blob Storage. It uses built-in system classification rules and custom classification rules to inspect actual data content (e.g., regex, keywords) and applies classifications like "Person's Name" or "Credit Card Number" to the schema and data. These classifications are then used in the Data Catalog, enabling sensitivity reporting and integration with information protection for labeling. It does not enforce access control or policy, but it is specifically designed for data discovery and classification at scale.

Why this answer

Microsoft Purview Data Map is the correct choice because it is the foundational service that performs automated scanning, data discovery, and classification of data sources such as Azure Blob Storage, populating the catalog with sensitivity labels and classifications. It uses scan rule sets and classification rules to detect sensitive data types across registered sources. Azure Policy is a governance service for enforcing resource compliance, not for scanning and classifying data content.

Microsoft Purview Information Protection applies sensitivity labels to files and emails but does not itself scan and classify data at rest in Blob Storage. Microsoft Purview Data Loss Prevention enforces policies to prevent data exfiltration, not to discover and classify stored data.

6
Multi-Selecthard

Which THREE components are required to implement a secure hybrid network with Azure using a site-to-site VPN?

Select 3 answers
A.Public IP address for the VPN device
B.ExpressRoute circuit
C.VPN gateway (route-based)
D.Virtual network gateway
E.Local network gateway
AnswersA, D, E

A public IP address is required for the Azure VPN gateway to be reachable from the on-premises VPN device. This IP is assigned to the gateway's IPsec tunnel endpoint and must be a standard SKU public IP, which can be dynamic or static. Without this publicly routable address, the on-premises device cannot initiate or complete the IPsec connection, making it a mandatory component for a site-to-site VPN.

Why this answer

To implement a secure hybrid network with Azure using a site-to-site VPN, three components are required: a virtual network gateway (which provides the VPN termination), a local network gateway (which represents the on-premises network), and a public IP address (which is assigned to the virtual network gateway to enable communication over the internet). The VPN gateway (option C) is not a separate component; it is a type of virtual network gateway. An ExpressRoute circuit (option B) is for dedicated private connections, not VPN.

Exam trap

Candidates often confuse the virtual network gateway with the VPN gateway, thinking they are separate components, and may omit the public IP address. However, the virtual network gateway (option D) is the actual Azure resource, and the VPN gateway is a configuration type. Additionally, a public IP address is a required resource that must be created and assigned to the gateway.

7
MCQmedium

Your company uses Microsoft Defender for Cloud Apps and wants to prevent users from uploading sensitive files to personal cloud storage apps. What should you configure?

A.Activity policy
B.App connector
C.Session policy
D.File policy
AnswerC

Session policies, part of Conditional Access App Control, route user traffic through Defender for Cloud Apps as a reverse proxy, allowing synchronous inspection of each request and response. The proxy can evaluate conditions like device compliance, user risk, or file sensitivity and then block, allow, or restrict actions — including preventing uploads to unsanctioned apps before the request is passed through. This real-time inline enforcement is exactly what the scenario requires, making session policy the correct choice.

Why this answer

Session policy in Microsoft Defender for Cloud Apps allows real-time monitoring and control of user activities based on app and content inspection. By configuring a session policy, you can block or restrict uploads of sensitive files to personal cloud storage apps like Dropbox or Google Drive during the user's session, leveraging reverse proxy capabilities to inspect and intervene in traffic.

Exam trap

The trap here is that candidates confuse 'File policy' (which governs files at rest) with 'Session policy' (which governs files in motion), leading them to select D, even though real-time upload prevention requires session-level control via reverse proxy.

How to eliminate wrong answers

Option A is wrong because Activity policies are used for auditing and generating alerts on specific activities (e.g., multiple failed logins), not for real-time blocking of file uploads. Option B is wrong because App connectors enable API-based visibility and control for connected apps (e.g., retrieving logs), but they cannot intercept and block uploads in real time during a user session. Option D is wrong because File policies are designed for scanning and governing files already stored in cloud apps (e.g., detecting DLP violations in SharePoint), not for preventing uploads at the point of action.

8
MCQmedium

You are designing a secure hybrid network architecture for a company that uses Azure and an on-premises datacenter. The company requires that all traffic between Azure and on-premises traverses Microsoft's backbone network and never the public internet. Additionally, the solution must provide automatic failover if the primary connection fails. Which Azure service should you include in the design?

A.Azure ExpressRoute with redundant circuits
B.Azure Virtual WAN
C.Azure Front Door
D.Azure VPN Gateway
AnswerA

Azure ExpressRoute with redundant circuits creates a private, dedicated connection from on-premises to Azure over Microsoft's global backbone, bypassing the public internet entirely. Redundant circuits, usually configured with BGP for active-active or active-passive, provide automatic failover if a circuit fails, satisfying the requirement for resilient hybrid connectivity. This direct backbone path is exactly what the scenario demands.

Why this answer

Azure ExpressRoute with redundant circuits is correct because ExpressRoute provides a private, dedicated connection through a connectivity provider that does not traverse the public internet, and deploying two or more circuits in different peering locations enables automatic failover if the primary circuit fails. Azure Virtual WAN is a networking hub service that can aggregate connectivity but does not by itself guarantee private backbone-only transport or automatic failover. Azure Front Door is a global HTTP/HTTPS load balancer and CDN for web applications, not a hybrid connectivity service.

Azure VPN Gateway sends traffic over the public internet via IPsec tunnels, so it fails the requirement that traffic never use the public internet.

9
MCQeasy

Your company uses Microsoft Purview Data Loss Prevention (DLP). You need to ensure that credit card numbers are not shared externally via email. What should you configure?

A.Create a sensitivity label that applies encryption to emails containing credit card numbers.
B.Create a DLP policy that detects credit card numbers and blocks external sharing.
C.Configure auto-labeling for credit card numbers in Microsoft 365.
D.Create a retention policy for credit card data.
AnswerB

A DLP policy is the correct control because it combines detection of a sensitive info type (credit card number uses patterns plus Luhn checksum validation) with a condition that the content is shared externally, and then enforces a blocking action. When you create a DLP policy in the Microsoft Purview compliance portal, you select the credit card number detector, scope it to Exchange/SharePoint/OneDrive, and set the rule to block access or block sending before the content leaves your tenant. This is the only option that directly prevents unauthorized external sharing while also providing user overrides and incident alerts.

Why this answer

The correct option is B: create a DLP policy that detects credit card numbers and blocks external sharing. Microsoft Purview DLP is purpose-built to identify sensitive information types such as credit card numbers and enforce protective actions like blocking email to external recipients, which directly satisfies the requirement. Option A is wrong because sensitivity labels apply encryption and classification but do not themselves block external email sharing based on content detection.

Option C is wrong because auto-labeling applies labels rather than enforcing DLP blocking actions. Option D is wrong because retention policies govern data lifecycle and deletion, not prevention of external sharing.

10
Multi-Selectmedium

Your organization is deploying Microsoft Defender for Cloud Apps. Which THREE capabilities are included in Defender for Cloud Apps? (Select three.)

Select 3 answers
A.Session controls
B.App governance
C.Cloud Discovery
D.Data Loss Prevention (DLP) policies
E.Conditional Access
AnswersA, B, C

Session controls in Microsoft Defender for Cloud Apps enforce real-time monitoring and control of user sessions via a reverse proxy. They allow organizations to apply granular access policies on cloud apps, such as preventing downloads, blocking access to sensitive files, or requiring step-up authentication. Session controls operate at the data plane level, evaluating user activity as it happens, and are often triggered by Conditional Access policies from Microsoft Entra ID.

Why this answer

Session controls (A) are a core Defender for Cloud Apps capability, delivered through Conditional Access App Control, which lets you monitor and restrict user sessions in real time (for example, blocking downloads or requiring reauthentication) for SaaS apps. App governance (B) is included in Defender for Cloud Apps and provides visibility, policy enforcement, and remediation for OAuth-enabled apps and their permissions across Microsoft 365 and other connected apps. Cloud Discovery (C) is also a foundational Defender for Cloud Apps feature that analyzes traffic logs to identify shadow IT and assess the risk of cloud apps in use.

DLP policies (D) are not a native Defender for Cloud Apps capability; data protection is handled by Microsoft Purview DLP and can be surfaced in Defender for Cloud Apps, but the policy engine itself belongs to Purview. Conditional Access (E) is a Microsoft Entra ID feature, not a Defender for Cloud Apps capability, although Defender for Cloud Apps integrates with it for app control and risk-based policies.

Exam trap

The trap here is confusing integrated features with native capabilities: candidates often select DLP policies or Conditional Access because Defender for Cloud Apps integrates with them, but the question asks for capabilities included in Defender for Cloud Apps itself, not those it leverages from other services.

11
Multi-Selecthard

Your organization uses Microsoft Sentinel and wants to improve threat hunting efficiency. Which THREE actions should you take?

Select 3 answers
A.Enable UEBA (User and Entity Behavior Analytics)
B.Integrate Microsoft Defender XDR for cross-domain hunting
C.Create custom hunting queries using KQL
D.Use watchlists to filter out known benign IPs
E.Reduce data retention period to improve query speed
AnswersA, B, C

Enabling UEBA in Microsoft Sentinel gives threat hunters behavioral baselines for users, hosts, and applications. By leveraging machine learning to detect anomalies such as unusual sign-in patterns or lateral movement, UEBA surfaces high-fidelity leads. This enriches entities in hunting queries with risk scores and behavioral insights, making detection of insider threats or compromised accounts far more effective.

Why this answer

UEBA (User and Entity Behavior Analytics) in Microsoft Sentinel uses machine learning models to establish baseline behavioral patterns for users, hosts, and other entities. It then detects anomalous activities such as unusual logon times, impossible travel, or abnormal data exfiltration, which directly enhances threat hunting by surfacing suspicious behaviors that might otherwise go unnoticed.

Exam trap

The trap here is that candidates often confuse passive data enrichment tools (like watchlists) with active hunting techniques, or mistakenly think reducing data retention improves security operations, when in fact it hinders long-term threat detection and forensic analysis.

12
MCQmedium

Your organization uses Microsoft Purview Information Protection to label and protect sensitive emails and documents. You need to ensure that when a user applies a 'Highly Confidential' label, the content is automatically encrypted and a watermark is added. Which configuration should you use?

A.Use Azure Information Protection scanner to apply labels automatically.
B.Create a DLP policy that blocks sharing of highly confidential content.
C.Configure a sensitivity label with encryption and watermark settings.
D.Enable Microsoft 365 Message Encryption for all emails.
AnswerC

Sensitivity labels are the only Microsoft Purview option that can simultaneously apply encryption with Azure Rights Management and configure content marking, including visual watermarks, headers, and footers. When a label with these settings is applied to a document or email, the watermark is automatically rendered behind the content or in the header, and encryption protects the file at rest and in transit. This provides a unified, policy-driven way to add watermarks without separate tooling or manual intervention.

Why this answer

Sensitivity labels in Microsoft Purview Information Protection can be configured with encryption and content marking (watermark) settings, which are applied automatically when users apply the label. Option A is incorrect: the Azure Information Protection scanner discovers and labels existing files but does not configure label settings; the label itself must be defined. Option B is incorrect: a DLP policy can block sharing but cannot add watermarks or encrypt content on its own.

Option D is incorrect: Microsoft 365 Message Encryption provides encryption for email transport but does not apply watermarks or enforce labels.

13
MCQhard

Your organization uses Microsoft Sentinel as a SIEM. You need to design a solution to detect advanced persistent threats (APTs) by correlating data from multiple sources, including network logs, endpoint data, and threat intelligence feeds. The solution must use machine learning to identify anomalies and reduce false positives. Which analytics rule type should you configure?

A.ML Behavior Analytics
B.Fusion
C.Anomaly detection rules
D.Scheduled query rules
AnswerB

Fusion is a built-in analytics rule in Microsoft Sentinel that leverages machine learning to correlate security alerts from multiple products—such as Microsoft Defender for Endpoint, Defender for Identity, and Defender for Office 365—into a single incident. It is specifically designed to detect advanced multi-stage attacks, including APTs, by analyzing cross-source alert relationships and timestamps. This makes Fusion the correct answer because it uniquely uses ML for multi-source correlation and APT detection.

Why this answer

Fusion analytics rules in Microsoft Sentinel are specifically designed for advanced multistage attack detection, using machine learning to correlate alerts and signals from multiple sources (network logs, endpoint data, threat intelligence) into high-fidelity incidents, which matches the APT detection and false-positive reduction requirement. ML Behavior Analytics rules focus on specific user/entity behavior anomalies rather than cross-source APT correlation. Anomaly detection rules identify unusual behavior within a single data type and do not perform the multistage fusion correlation.

Scheduled query rules run KQL queries on a schedule and lack the built-in ML-driven cross-source correlation for APTs.

14
MCQmedium

Your organization uses Microsoft Defender for Identity (MDI) to protect on-premises Active Directory. You need to integrate MDI with Microsoft Sentinel to centralize detection and response. What is the required configuration?

A.Deploy the MDI sensor on an Azure VM to send data to Sentinel.
B.Integrate Microsoft Entra ID Protection with Sentinel instead.
C.Enable the Microsoft Defender for Identity data connector in Microsoft Sentinel.
D.Configure MDI to forward logs to a Syslog server, then use the Syslog connector in Sentinel.
AnswerC

The Microsoft Defender for Identity data connector in Microsoft Sentinel is the native integration path: once enabled, it uses the Microsoft 365 Defender API to pull MDI alerts and incidents into Sentinel, making them available for analytics rules, hunting, and incident correlation. This connector is the official—and only supported—way to ingest MDI data into Sentinel, and it requires no additional sensors, log forwarders, or syslog infrastructure. Enabling it consumes the correct, purpose-built pipeline.

Why this answer

The correct option is C: enabling the Microsoft Defender for Identity data connector in Microsoft Sentinel. MDI integrates with Sentinel through a built-in data connector that streams MDI alerts and related identity events into the Sentinel workspace, allowing centralized detection and response without extra infrastructure. Option A is unnecessary because the MDI sensor is deployed on domain controllers or AD FS servers, not Azure VMs, and the sensor does not send data directly to Sentinel.

Option B is incorrect because Entra ID Protection covers cloud identity risk, not on-premises AD signals from MDI. Option D is incorrect because MDI does not natively forward to Syslog for Sentinel ingestion; the supported path is the MDI data connector.

15
MCQhard

Refer to the exhibit. You are reviewing an Azure Policy definition that uses a 'modify' effect. The policy is intended to automatically enable transparent data encryption (TDE) on Azure SQL databases after they are created. Which condition must be met for the modify effect to work?

A.The policy must be assigned at the management group scope.
B.A managed identity must be associated with the policy assignment and have permissions to modify TDE.
C.The database must be newly created.
D.The SQL database must be using the General Purpose service tier.
AnswerB

The Modify effect in Azure Policy requires a managed identity to be attached to the policy assignment and that identity must be granted RBAC permissions, such as SQL Security Manager, on the target SQL servers or databases to change Transparent Data Encryption settings. Without a properly configured identity, the policy assignment fails during evaluation/remediation and cannot apply the desired TDE state. This is a mandatory prerequisite, making the option the correct answer.

Why this answer

The correct answer is B: a managed identity must be associated with the policy assignment and have permissions to modify TDE. Azure Policy's modify effect performs remediation-style changes to resources, so the assignment needs a system-assigned or user-assigned managed identity with the required RBAC permissions (such as SQL DB Contributor or a custom role granting Microsoft.Sql/servers/databases/transparentDataEncryption/write) to actually enable TDE on the database. Option A is incorrect because modify works at any assignment scope (management group, subscription, resource group) as long as the identity and permissions are configured.

Option C is incorrect because modify can act on existing resources during evaluation/remediation, not only newly created ones. Option D is incorrect because TDE enablement via modify is not limited to the General Purpose service tier.

16
MCQhard

Your organization uses Azure API Management (APIM) to expose APIs to external partners. You need to ensure that only authorized partners can access the APIs and that the API requests are rate-limited to prevent abuse. What should you implement?

A.Use a validate JWT policy to authenticate partners and a rate-limit by key policy to control request rates.
B.Configure client certificate authentication and set a global rate limit in the APIM service.
C.Require a subscription key for each partner and configure IP whitelisting.
D.Use OAuth 2.0 tokens and store partner API keys in Azure Key Vault.
AnswerA

Validate JWT policy ensures that only requests carrying a valid JSON Web Token signed by a trusted identity provider reach the API, thereby authenticating each partner's identity. The rate-limit-by-key policy then uses the subscription key as the scope to apply per-partner request quotas, preventing any single partner from consuming all available capacity. This combination provides both secure identity verification and granular throttling, which is exactly what an API exposure to partners requires.

Why this answer

Option A is correct because in Azure API Management, the validate-jwt policy validates OAuth 2.0/JWT bearer tokens issued by an identity provider (such as Microsoft Entra ID), ensuring only authorized partners with valid tokens can call the APIs, while the rate-limit-by-key policy throttles requests based on a key such as the subscription key or a claim (e.g., partner ID), directly preventing abuse. Together these policies satisfy both the authentication and rate-limiting requirements within the APIM policy pipeline. Option B does not fit because client certificate authentication alone does not provide token-based authorization and a global rate limit applies to all callers rather than per-partner, so one partner could exhaust the quota.

Option C is insufficient because a subscription key is a shared secret that can be leaked and IP whitelisting is brittle and does not enforce per-partner request limits. Option D is incomplete because OAuth 2.0 tokens and Key Vault key storage address credential handling but do not themselves implement rate limiting in APIM.

17
Multi-Selecteasy

Which TWO of the following are components of Microsoft Defender XDR (Extended Detection and Response)?

Select 2 answers
A.Microsoft Sentinel
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Office 365
D.Microsoft Intune
E.Microsoft Purview
AnswersB, C

Microsoft Defender for Endpoint is a foundational component of Microsoft Defender XDR (formerly Microsoft 365 Defender). It delivers endpoint detection and response (EDR), vulnerability management, and attack surface reduction capabilities, sharing signals with the unified XDR pipeline to enable cross-domain threat correlation and automated response.

Why this answer

Microsoft Defender XDR is the unified extended detection and response suite that natively correlates signals across Microsoft's first-party security workloads, and Microsoft Defender for Endpoint (B) is a core component, providing endpoint detection and response (EDR), attack surface reduction, and automated investigation and remediation for devices. Microsoft Defender for Office 365 (C) is likewise a core component, delivering protection and detection for email, collaboration tools, and phishing/URL detonation signals that feed into the XDR incident graph. By contrast, Microsoft Sentinel (A) is a standalone cloud-native SIEM/SOAR platform that, while it can integrate with Defender XDR, is not itself one of its components.

Microsoft Intune (D) is a mobile device management (MDM) and endpoint management service, and Microsoft Purview (E) is a data governance, compliance, and information-protection suite — neither is a Defender XDR component.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) as part of Defender XDR, but Sentinel is a separate Azure service that can ingest Defender XDR alerts, not a component of the XDR platform itself.

18
MCQmedium

Your company uses Microsoft Intune to manage corporate devices. The security team wants to prevent users from copying sensitive data from corporate apps to personal apps on mobile devices. Which Intune policy should you configure?

A.Device configuration policies
B.App protection policies
C.Windows Information Protection
D.Device compliance policies
AnswerB

App protection policies (APPs) are the correct choice because they are specifically designed to prevent corporate data leakage in mobile apps. These MAM (mobile application management) policies apply directly to applications like Outlook or Teams and can restrict data transfer actions such as copy/paste, screen capture, or saving corporate data to unmanaged apps/cloud services. They work independently of device enrollment, so they remain effective even if the device is a personal phone, directly addressing the concern of safeguarding data in unmanaged apps.

Why this answer

App protection policies (APP) are the correct Intune policy to prevent data transfer from corporate apps to personal apps on mobile devices. These policies apply at the application layer, allowing you to configure data protection settings such as 'Restrict cut, copy, and paste' and 'Allow app to transfer data to other apps' specifically for managed apps, regardless of the device enrollment state.

Exam trap

The trap here is confusing device-level policies (compliance or configuration) with app-level data protection, leading candidates to select device compliance policies or device configuration policies instead of app protection policies.

How to eliminate wrong answers

Option A is wrong because device configuration policies manage device-level settings (e.g., Wi-Fi, VPN, certificates) and do not control data sharing between apps on mobile devices. Option C is wrong because Windows Information Protection (WIP) is a Windows-only feature for desktop devices and does not apply to mobile platforms like iOS or Android. Option D is wrong because device compliance policies enforce device-level security requirements (e.g., jailbreak detection, minimum OS version) and do not restrict app-to-app data transfer.

19
MCQeasy

Your organization uses Microsoft Intune for mobile device management. You need to ensure that only devices compliant with security policies can access corporate email. What should you implement?

A.Conditional Access policy requiring compliant device
B.Microsoft Purview Data Lifecycle Management
C.Microsoft Defender for Endpoint integration
D.Microsoft Intune App Protection Policies
AnswerA

A Conditional Access policy requiring a compliant device acts as a real-time access gate at authentication, checking the device's compliance state reported by Intune against defined compliance policies. It evaluates signals such as enrollment status, device health attestation, and configured security settings, and blocks or allows access to Microsoft 365 or other cloud apps. This is the appropriate control because it enforces device-level access decisions before any session begins.

Why this answer

A is correct because a Conditional Access policy in Microsoft Entra ID can evaluate device compliance status reported by Intune before granting access to corporate email. By configuring a policy that requires a device to be marked as compliant, only devices that meet your security policies (e.g., encryption, OS version, threat level) will be allowed to authenticate and access email. This directly enforces the requirement that only compliant devices can access corporate email.

Exam trap

The trap here is that candidates often confuse Intune App Protection Policies (MAM) with device-based compliance, but MAM policies protect data at the app level and do not require the device itself to be compliant, so they do not meet the requirement of 'only compliant devices'.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Data Lifecycle Management governs data retention and deletion policies, not real-time access control based on device compliance. Option C is wrong because Microsoft Defender for Endpoint integration provides threat detection and response on endpoints, but does not itself block access to email based on compliance status; it can feed signals into Conditional Access but is not the primary control. Option D is wrong because Intune App Protection Policies (MAM) protect data within apps without requiring device enrollment or compliance, so they do not ensure that only compliant devices can access email—they apply to apps on any device, including non-compliant ones.

20
Multi-Selectmedium

A company is designing a data security strategy using Microsoft Purview. They need to identify sensitive data across their data estate, including on-premises SQL Server, Azure SQL Database, and Amazon S3. Which THREE components should they use? (Choose three.)

Select 3 answers
A.Microsoft Purview Data Estate Insights
B.Microsoft Purview External Identities
C.Microsoft Purview Data Catalog
D.Microsoft Purview Compliance Manager
E.Microsoft Purview Data Map
AnswersA, C, E

Data Estate Insights provides monitoring and reporting.

Why this answer

Microsoft Purview Data Estate Insights provides visibility into data estate health and security posture, including sensitive data discovery across on-premises SQL Server, Azure SQL Database, and Amazon S3. It aggregates scan results and offers dashboards to identify where sensitive data resides, enabling targeted classification and protection actions.

Exam trap

The trap here is that candidates confuse Compliance Manager (a compliance posture tool) with data discovery capabilities, or think External Identities (an identity feature) is relevant to scanning data sources, when in fact only Data Map, Data Catalog, and Data Estate Insights form the core trio for sensitive data identification across hybrid estates.

21
MCQeasy

Your organization is planning to deploy a new web application on Azure VMs. The security team requires that all incoming traffic to the VMs be inspected by a network virtual appliance (NVA) before reaching the VMs. Which Azure networking solution should you use to route traffic through the NVA?

A.Azure Firewall
B.Azure Load Balancer
C.Network Security Groups (NSGs)
D.User Defined Routes (UDRs)
AnswerD

User-defined routes are custom route table entries that allow you to override Azure's automatic system routes for selected subnets. By associating a route table with a subnet and setting the next hop to an NVA's private IP address, you force all matching traffic to be forwarded to that appliance for processing such as inspection or firewall enforcement. This is exactly the routing mechanism needed to steer web application traffic through a network virtual appliance, and it is the only option listed that actively changes packet forwarding behavior.

Why this answer

User Defined Routes (UDRs) are the correct choice because they let you override Azure's default system routes and force traffic to be sent to a specific next hop, such as the private IP of a network virtual appliance, so packets are inspected before reaching the VMs. In this scenario, the security team requires traffic to pass through the NVA, which is exactly what a UDR with the NVA as the next hop accomplishes. Azure Firewall (A) is itself a managed firewall service, not the routing mechanism used to redirect traffic to a third-party NVA.

Azure Load Balancer (B) distributes traffic across endpoints but does not control routing paths, and Network Security Groups (C) only filter traffic with allow/deny rules rather than steering it through an appliance.

Exam trap

Candidates often confuse Azure Firewall (a managed firewall service) with a routing mechanism. UDRs are the correct way to direct traffic through an NVA, not Azure Firewall.

22
MCQmedium

Refer to the exhibit. You are reviewing an Azure Policy definition. What is the effect of this policy?

A.Denies creation of Windows VMs that have automatic updates enabled
B.Audits Windows VMs that have automatic updates disabled
C.Audits Linux VMs that have automatic updates enabled
D.Denies creation of Windows VMs without automatic updates enabled
AnswerD

This is correct because the condition uses 'exists': 'false' on the 'Microsoft.Compute/virtualMachines/enableAutomaticUpdates' field. When a deployment request for a Windows VM omits the enableAutomaticUpdates property, the condition is met and the deny effect blocks the create or update operation. This forces callers to explicitly include the property on the VM resource to pass the policy.

Why this answer

The correct answer is D: the policy denies creation of Windows VMs without automatic updates enabled. In Azure Policy, a Deny effect blocks the deployment request when the resource does not satisfy the condition, so a Windows VM whose automatic updates setting is not enabled would fail the policy evaluation and be rejected. This matches the scenario of enforcing automatic updates on Windows VMs at creation time.

Option A is incorrect because it reverses the condition, denying VMs that already have automatic updates enabled. Option B is incorrect because it describes an Audit effect, not Deny, and audits VMs with updates disabled rather than blocking noncompliant deployments. Option C is incorrect because it targets Linux VMs and uses Audit, neither of which matches the policy's Windows VM Deny behavior.

23
MCQmedium

Refer to the exhibit. You are reviewing an Azure Policy definition. What does this policy do?

A.Requires all virtual machines to use encryption at host
B.Allows only virtual machines with unmanaged disks
C.Denies virtual machines with managed disks if the OS disk type is not Standard_LRS or Premium_LRS
D.Denies all virtual machines without managed disks
AnswerC

This is the accurate interpretation. The policy definition's condition evaluates the 'Microsoft.Compute/virtualMachines' resource to see if a managed OS disk exists, and if so, it further checks whether the 'storageAccountType' of that managed disk is 'Standard_LRS' or 'Premium_LRS'. When the managed disk exists and its type is not in that allowed list, the policy's 'deny' effect blocks the deployment or update operation. This directly matches the statement, making it the correct answer.

Why this answer

The correct option is C: the policy denies virtual machines with managed disks when the OS disk type is not Standard_LRS or Premium_LRS. This matches a typical Azure Policy definition that evaluates the managed disk's storage account type (for example, the field Microsoft.Compute/disks sku.name) and uses a deny effect to block any value outside the allowed set of Standard_LRS and Premium_LRS. Option A is wrong because encryption at host is controlled by a different setting (encryptionAtHost) and is not what this disk-type policy enforces.

Option B is wrong because the policy targets managed disks, not unmanaged disks, and it does not allow unmanaged disks. Option D is wrong because the policy does not deny all VMs without managed disks; it only denies managed-disk VMs whose OS disk SKU is not Standard_LRS or Premium_LRS.

24
MCQmedium

A company uses Microsoft Sentinel for security operations. They want to collect logs from a custom application running on Azure Virtual Machines. The application writes logs to a local file. Which data connector should they use?

A.Application Insights
B.Syslog
C.Windows Event Forwarding
D.Custom Logs via Log Analytics agent
AnswerD

Custom Logs via the Log Analytics agent is the correct solution because the agent provides a native 'Custom Logs' feature that lets you specify a local directory and file mask (e.g., C:\Logs\*.log or /var/log/app/*.txt) to continuously monitor. When a new entry is appended to a matching file, the agent reads it, parses each line using a sample-based custom log definition, and sends the data to a custom table (e.g., MyLog_CL) in the Log Analytics workspace, which Microsoft Sentinel can then query and alert on. This is the built-in method specifically designed to collect existing application-generated log files from Windows or Linux VMs without requiring code changes.

Why this answer

The correct option is D, Custom Logs via Log Analytics agent, because Microsoft Sentinel can ingest arbitrary text-based log files from Azure VMs by installing the Log Analytics agent (MMA/AMA) and defining a custom log table that points to the local file path, which is exactly the scenario of a custom application writing to a local file. Application Insights (A) is an APM service for instrumented application telemetry, not for collecting pre-existing local log files from VMs. Syslog (B) only handles syslog-format messages from Linux/network devices, and Windows Event Forwarding (C) only collects Windows Event Log data, so neither fits a custom application's local log file.

25
MCQhard

A security team is designing a Microsoft Sentinel deployment. They need to minimize costs while ensuring critical alerts are always processed. Which data retention and ingestion strategy should they use?

A.Use Basic Logs for all data and retain for 90 days
B.Use Analytics Logs for all data and retain for 30 days
C.Use Basic Logs for critical alerts and retain for 30 days
D.Use Basic Logs for high-volume low-value data and Analytics Logs for critical alerts
AnswerD

This is the correct cost-performance trade-off: route high-volume, low-value data such as verbose firewall logs, debug traces, and raw DNS events to Basic Logs to slash ingestion costs, while steering critical security alerts and curated detection data into Analytics Logs for full KQL querying, alerting, and hunting workflows. Basic Logs' lower cost and acceptable simple-search capability align perfectly with data that is retained mainly for compliance or ad-hoc troubleshooting, while Analytics Logs' rich analytical features and long retention match the needs of high-priority security detections. Microsoft Sentinel supports this pattern natively by configuring table-level plans, enabling a single workspace to hold both tiers and ensuring that analysts can query the data that matters most with low latency. This balanced design meets both cost optimization and security operational requirements, making it the only viable answer.

Why this answer

It aligns with cost optimization and reliability requirements by using Basic Logs for high-volume, low-value data (e.g., firewall logs) and reserving Analytics Logs for critical alerts that require full query capabilities and interactive retention. This tiered approach ensures critical alerts are always processed with full fidelity while reducing storage costs for less important data.

Exam trap

The trap here is that candidates assume all data must be in Analytics Logs for security monitoring, overlooking the cost-saving strategy of tiered ingestion where Basic Logs handle high-volume, low-value data without sacrificing critical alert processing.

How to eliminate wrong answers

Option A is wrong because using Basic Logs for all data prevents critical alerts from being processed with full Analytics Logs features (e.g., advanced KQL queries, scheduled analytics rules), and 90-day retention on Basic Logs incurs unnecessary cost for low-value data. Option B is wrong because using Analytics Logs for all data maximizes cost (Analytics Logs are more expensive per GB) and 30-day retention may not meet compliance or investigation needs for critical alerts. Option C is wrong because using Basic Logs for critical alerts means they lose access to Analytics Logs capabilities (e.g., near-real-time detection, custom detections), and 30-day retention is insufficient for forensic analysis of critical incidents.

26
Multi-Selectmedium

Which TWO actions should you take to protect Azure Virtual Machines from ransomware? (Choose two.)

Select 2 answers
A.Deploy Azure Firewall to block all inbound traffic.
B.Configure Azure Site Recovery for all VMs.
C.Enable Azure Backup with immutable vault.
D.Assign Azure Policy to require encryption at rest.
E.Enable Microsoft Defender for Servers.
AnswersC, E

Azure Backup with an immutable vault uses Write-Once, Read-Many (WORM) storage, which prevents backups from being deleted, modified, or encrypted by ransomware even if admin credentials are stolen. This ensures you always have a clean, valid recovery point to restore VMs to a pre-infection state. Immutable backups are a critical last line of defense because they isolate recovery data from the attack surface and align with Azure's recommended ransomware protection strategy.

Why this answer

Option C is correct because Azure Backup with an immutable vault prevents backup data from being altered or deleted during the retention period, which is essential for recovering VMs after a ransomware attack encrypts or destroys production data. Option E is correct because Microsoft Defender for Servers provides threat detection, vulnerability assessment, and file integrity monitoring, and it can raise alerts on suspicious ransomware-like behavior on the VM. Option A is not correct because blocking all inbound traffic with Azure Firewall would not stop ransomware delivered through outbound connections, compromised credentials, or already-running workloads, and it is not a ransomware-specific protection.

Option B is not correct because Azure Site Recovery provides replication and disaster recovery failover, but it does not by itself protect backups from tampering or detect ransomware. Option D is not correct because encryption at rest protects data confidentiality if disks are stolen, but it does not prevent ransomware from encrypting files on a running VM.

27
MCQhard

Your organization uses Microsoft Sentinel and has deployed the Analytics rule 'TI map IP entity to AzureActivity' to detect suspicious activities based on threat intelligence. The SOC team reports that the rule has a high false positive rate because it matches benign IP addresses used by legitimate services. What design change should you recommend to reduce false positives while maintaining detection coverage?

A.Increase the alert threshold to require multiple occurrences within a time window.
B.Disable the rule and rely on manual hunting queries.
C.Create a watchlist of trusted IP addresses and modify the rule to exclude those IPs.
D.Create a separate analytics rule that suppresses alerts when the source IP is in a trusted list.
AnswerC

Creating a watchlist of trusted IP addresses and modifying the rule to exclude those IPs directly addresses the source of the false positives without disabling detection. In Sentinel, you can build a watchlist (e.g., via CSV or PowerShell) and then reference it in the analytics rule's KQL query using the `_GetWatchlist` function—for instance, adding a `where IPAddress !in (_GetWatchlist('TrustedIPs'))` clause. This keeps the rule active for all other IPs, ensuring genuine threat-intelligence matches still generate alerts while known benign entities are filtered out, and it allows easy updates to the trusted list without re-editing the rule each time.

Why this answer

Creating a watchlist of trusted IP addresses and modifying the TI map IP entity to AzureActivity rule to exclude those IPs directly addresses the high false positive rate caused by benign IPs. This approach preserves detection coverage for all other threat intelligence matches while filtering out known legitimate services, leveraging Sentinel's watchlist feature for dynamic exclusion without disabling the rule.

Exam trap

The trap here is that candidates may choose Option D, thinking a separate suppression rule is needed, but Microsoft Sentinel's analytics rules support direct exclusion via watchlists in the query logic, making a separate rule redundant and less reliable.

How to eliminate wrong answers

Option A is wrong because increasing the alert threshold to require multiple occurrences within a time window does not address the root cause—benign IPs matching threat intelligence—and may delay detection of genuine threats or miss single-occurrence attacks. Option B is wrong because disabling the rule and relying on manual hunting queries eliminates automated detection entirely, increasing risk and workload, which contradicts the goal of maintaining detection coverage. Option D is wrong because creating a separate analytics rule that suppresses alerts when the source IP is in a trusted list introduces unnecessary complexity and potential race conditions; suppression logic should be integrated into the original rule via exclusion, not handled as a separate rule that may not suppress alerts in time or could conflict with other rules.

28
MCQeasy

Your organization uses Microsoft Sentinel as its SIEM. The security team needs to detect brute-force attacks against Azure VMs by analyzing Windows Security Event logs. Which data connector should you enable?

A.Office 365 connector
B.Azure Activity log connector
C.Microsoft Defender for Cloud connector
D.Windows Security Events via AMA connector
AnswerD

The Windows Security Events via Azure Monitor Agent (AMA) connector is purpose-built to stream Windows Event logs from servers and workstations directly into Microsoft Sentinel. Using a Data Collection Rule (DCR), it can collect the Security channel and other event channels, preserving the raw event details for detections and investigations. This is the correct connector when your organization must ingest Windows security events into Sentinel.

Why this answer

The Windows Security Events via AMA connector (D) is correct because it ingests Windows Event Logs (specifically Security logs with Event ID 4625 for failed logons) from Azure VMs into Microsoft Sentinel, enabling detection of brute-force patterns. This connector uses the Azure Monitor Agent (AMA) to collect events, which is the recommended method for modern Windows event collection in Sentinel.

Exam trap

The trap here is that candidates may confuse the Azure Activity log connector (which shows administrative actions like 'Deallocate VM') with guest OS-level security events, or mistakenly think Defender for Cloud provides raw Windows event logs instead of aggregated security alerts.

How to eliminate wrong answers

Option A is wrong because the Office 365 connector ingests audit logs from Microsoft 365 services (Exchange, SharePoint, Teams), not Windows Security Event logs from Azure VMs. Option B is wrong because the Azure Activity log connector collects subscription-level control plane events (e.g., VM creation, resource changes), not guest OS-level security events like logon failures. Option C is wrong because the Microsoft Defender for Cloud connector ingests security alerts and posture data from Defender for Cloud, not raw Windows Security Event logs needed for brute-force detection.

29
MCQeasy

You need to ensure that Azure SQL Database always encrypts data at rest and in transit. Which features should you enable?

A.Firewall rules and Azure Active Directory authentication
B.Transparent Data Encryption (TDE) and enforce TLS connections
C.Always Encrypted and firewall rules
D.Azure Defender for SQL and vulnerability assessment
AnswerB

Transparent Data Encryption encrypts Azure SQL data at rest at the page level, while enforcing TLS connections protects data in transit. Together they satisfy the requirement to always encrypt data both at rest and in transit.

Why this answer

The correct answer is B: Transparent Data Encryption (TDE) and enforce TLS connections. TDE provides encryption of data at rest by encrypting the database, backups, and transaction logs at the page level, while enforcing TLS (Transport Layer Security) ensures data in transit is encrypted between the client and Azure SQL Database. Firewall rules, Azure AD authentication, Always Encrypted, Azure Defender, and vulnerability assessment address access control, client-side encryption, or threat detection, but they do not by themselves guarantee encryption of data at rest and in transit.

Therefore, options A, C, and D do not satisfy the stated requirement.

30
MCQeasy

A company uses Microsoft Intune to manage corporate devices. They want to ensure that only compliant devices can access corporate email in Outlook Mobile. Which type of policy should they configure?

A.App protection policy
B.Device configuration policy
C.Conditional Access policy
D.Compliance policy
AnswerC

Conditional Access evaluates device compliance signals from Microsoft Intune and grants or blocks access to cloud apps such as Outlook Mobile accordingly. This satisfies the requirement that only compliant devices reach corporate email, which Intune compliance policies alone cannot enforce.

Why this answer

The correct answer is C, Conditional Access policy, because Conditional Access is the Intune/Microsoft Entra mechanism that enforces access decisions such as requiring a device to be compliant before granting access to corporate resources like Exchange Online for Outlook Mobile. In this scenario, the company needs an access control that evaluates device compliance at sign-in and blocks noncompliant devices, which is exactly what a Conditional Access policy with a 'Require device to be marked as compliant' grant control does. A compliance policy (D) only defines and evaluates compliance state but does not itself block or grant access, and a device configuration policy (B) merely configures settings on devices without enforcing access.

An app protection policy (A) protects app data with PINs and encryption but does not gate access to corporate email based on device compliance.

31
MCQeasy

You need to design a solution to protect Azure VMs from malware and provide security recommendations. Which Azure service should you enable?

A.Azure Sentinel
B.Microsoft Intune
C.Azure Monitor
D.Microsoft Defender for Cloud
AnswerD

Microsoft Defender for Cloud is the correct solution because it is a cloud workload protection platform (CWPP) and CSPM tool that natively provides antimalware for Azure VMs. It includes the Microsoft Antimalware extension for real-time scanning and removal of malicious software, and it can integrate with Microsoft Defender for Endpoint for next-generation endpoint detection and response (EDR). It also delivers actionable security recommendations, adaptive application controls, and just-in-time VM access to reduce attack surface and prevent malware. This integrated, proactive protection is exactly what is required to secure Azure VMs against malware.

Why this answer

Microsoft Defender for Cloud (option D) is the correct choice because it provides cloud workload protection, including Microsoft Defender for Servers, which delivers antimalware/endpoint protection and security recommendations for Azure VMs. It continuously assesses VM configurations and surfaces hardening recommendations, satisfying both the malware protection and security-recommendation requirements. Azure Sentinel (A) is a SIEM/SOAR platform for collecting and analyzing security events, not for directly protecting VMs from malware.

Microsoft Intune (B) is for mobile device and endpoint management, primarily for user devices, not Azure VM workload protection. Azure Monitor (C) collects metrics and logs for observability but does not provide malware protection or security recommendations.

32
MCQmedium

Your company uses Microsoft Defender for Endpoint (MDE) and wants to integrate threat intelligence from an external source to improve detection. The security team needs to ingest custom indicators of compromise (IOCs) into MDE. Which feature should they use?

A.Advanced Hunting
B.Threat Analytics
C.Automated investigation and response
D.Custom indicators (IOCs)
AnswerD

Custom Indicators (IOCs) is the Microsoft Defender for Endpoint feature that allows tenants to import their own threat intelligence, including file hashes, IP addresses, URLs, domains, and certificates, from external sources. This ingestion can be performed through the Microsoft 365 Defender portal or programmatically via APIs, and the imported indicators are then evaluated during detection and enforcement. Enabling a connector to import IOCs from an external source specifically leverages this feature, as it is the sole mechanism among these options that accepts and manages external indicator data.

Why this answer

The Custom Indicators (IOCs) feature in Microsoft Defender for Endpoint allows security teams to manually ingest and manage threat intelligence from external sources, such as IP addresses, URLs, domains, or file hashes. These indicators are then used by MDE to create or block alerts, enabling tailored detection beyond built-in threat intelligence feeds.

Exam trap

The trap here is that candidates often confuse 'Advanced Hunting' (a query tool) with a feature for importing threat data, or they mistakenly think 'Threat Analytics' allows custom feed integration, when in fact it only displays Microsoft's pre-built analysis.

How to eliminate wrong answers

Option A is wrong because Advanced Hunting is a query-based tool for exploring raw telemetry data over the past 30 days, not a mechanism for ingesting external IOCs. Option B is wrong because Threat Analytics provides curated reports and insights on known threats from Microsoft's research, not a way to import custom indicators. Option C is wrong because Automated investigation and response is a workflow that triggers actions on alerts, but it cannot ingest or manage external IOCs; it relies on existing detection rules.

33
MCQhard

A company is designing a security operations strategy. They want to use Microsoft Sentinel to detect and respond to threats across their hybrid environment. They need to ensure that logs from all sources are collected cost-effectively and that analysts can easily query data. Which data ingestion strategy should they recommend?

A.Send all logs to the Basic logs table to reduce costs.
B.Send only Windows Security Events to Sentinel.
C.Send all logs to the Analytics logs table for full query capabilities.
D.Use Analytics logs for high-value security logs and Basic logs for verbose logs with low security value.
AnswerD

This tiered strategy optimizes both security visibility and cost by routing high-value, actionable security logs—such as authentication failures, privilege use, and security events—to Analytics logs where they support advanced KQL queries and alert rules. Simultaneously, verbose logs with low security value, like informational audit entries or diagnostic logs, are sent to Basic logs for occasional queries and compliance. This balances operational effectiveness with budget constraints, ensuring the SOC retains critical detection and investigation capabilities without paying premium analytics costs for every byte of log data.

Why this answer

It balances cost and query performance by routing high-value security logs (e.g., Windows Security Events, network logs) to the Analytics logs table for full KQL query capabilities and retention, while sending verbose, low-security-value logs (e.g., DNS debug, firewall flow logs) to the Basic logs table, which offers lower ingestion cost and limited query features (e.g., no KQL summarization). This tiered approach ensures analysts can efficiently hunt on critical data without incurring unnecessary costs for voluminous, less actionable logs.

Exam trap

The trap here is that candidates assume 'cost-effective' means using only the cheapest option (Basic logs) or only the most capable option (Analytics logs), failing to recognize that Microsoft Sentinel’s tiered ingestion model is designed specifically to optimize cost versus query capability by separating high-value and low-value log sources.

How to eliminate wrong answers

Option A is wrong because sending all logs to the Basic logs table would severely limit query capabilities—Basic logs support only simple search and no KQL aggregation functions like summarize or make-series—making threat hunting and advanced analytics impractical. Option B is wrong because sending only Windows Security Events ignores other critical sources like Azure Activity logs, network logs, and third-party security appliances, creating blind spots in the hybrid environment and violating the requirement to detect threats across all sources. Option C is wrong because sending all logs to the Analytics logs table would incur high ingestion and retention costs for verbose logs (e.g., DNS queries, firewall flow logs) that have low security value, contradicting the cost-effectiveness requirement.

34
Multi-Selectmedium

A company uses Microsoft Purview Data Lifecycle Management. They need to retain financial records for 7 years and then delete them. Which TWO actions should they configure?

Select 2 answers
A.Create a DLP policy that blocks deletion
B.Apply a sensitivity label to the records
C.Create a retention label with a 7-year retention period
D.Use a trainable classifier to identify records
E.Configure a disposition review to approve deletion
AnswersC, E

A retention label is the Purview mechanism that directly enforces retention and deletion behavior on documents, emails, and other content. By creating a retention label with a 7-year retention period and publishing it (or auto-applying it), the organization ensures the record remains immutable and un-deletable during that period, and the label can also trigger a disposition review at expiration. This aligns with regulatory requirements for retaining records. Thus, it is the correct action to preserve the records for the mandated timeframe.

Why this answer

Option C is correct because a retention label in Microsoft Purview Data Lifecycle Management is the mechanism that defines how long content is retained (here, 7 years) and what happens at the end of that period, such as deletion. Option E is correct because a disposition review can be attached to a retention label so that when the 7-year retention period expires, designated reviewers must approve the deletion before the records are permanently removed, which is a common compliance requirement for financial records. Option A is incorrect because DLP policies are designed to prevent data loss or leakage, not to enforce retention or deletion schedules.

Option B is incorrect because sensitivity labels classify and protect content (for example, encryption and access restrictions) but do not by themselves define retention or deletion periods. Option D is incorrect because trainable classifiers identify content types for classification or auto-labeling; they do not enforce a 7-year retention-then-delete lifecycle.

Exam trap

The trap here is confusing sensitivity labels (used for classification and protection) with retention labels (used for lifecycle management), leading candidates to incorrectly select Option B instead of understanding that retention labels are the correct mechanism for timed deletion.

35
MCQeasy

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. What should you configure?

A.Create a Conditional Access policy that requires compliant device
B.Set up enrollment restrictions in Intune
C.Create a device configuration policy that blocks non-compliant devices
D.Configure an app protection policy for email apps
AnswerA

Conditional Access policies are the access-control layer that evaluates the device's compliance state at sign-in. When combined with an Intune compliance policy, the 'Require device to be marked as compliant' grant control forces Azure AD to check the device's compliance status and block access if the device is non-compliant. This is the correct approach because it directly enforces the access requirement for corporate resources, unlike enrollment or configuration policies that only manage settings or enrollment.

Why this answer

A Conditional Access policy in Microsoft Entra ID (formerly Azure AD) can enforce the requirement that only devices marked as compliant by Intune can access corporate email. This policy evaluates the device compliance status at authentication time and blocks or grants access based on that signal, ensuring that only managed and compliant devices can connect to services like Exchange Online.

Exam trap

The trap here is that candidates often confuse device configuration policies (which set device settings) with Conditional Access (which enforces access control based on compliance), leading them to choose option C instead of the correct policy-based access control.

How to eliminate wrong answers

Option B is wrong because enrollment restrictions in Intune control which devices can enroll into management (e.g., by platform or ownership type), but they do not enforce compliance at the point of access to corporate email. Option C is wrong because device configuration policies in Intune are used to set settings and features on devices (like password policies or restrictions), not to block non-compliant devices from accessing resources; blocking access is done via Conditional Access. Option D is wrong because an app protection policy (MAM) protects data within apps (e.g., preventing copy/paste or requiring PIN) but does not evaluate device compliance; it can be used without device enrollment but does not replace the need for a Conditional Access policy that checks device compliance.

36
MCQmedium

Your organization uses Azure SQL Database and needs to protect sensitive data from being exported by unauthorized users. You must implement a solution that prevents users from copying data to clipboard or taking screenshots of query results, while allowing legitimate business operations. What should you implement?

A.Apply Azure Information Protection labels to the database.
B.Use Dynamic Data Masking to obscure sensitive columns.
C.Enable Azure SQL Database Auditing and threat detection.
D.Configure a session policy in Microsoft Defender for Cloud Apps to block clipboard and screenshot actions.
AnswerD

Configuring a session policy in Microsoft Defender for Cloud Apps (MDA) is a preventive, real-time DLP control that uses a reverse-proxy architecture to sit between the user and Azure SQL Database. When a user accesses the database through a supported web portal or app, the session policy can apply conditional access and enforce behavioral controls such as blocking clipboard operations (copy, cut, paste) and prohibiting screenshot capture, thereby preventing data exfiltration at the client session level. This goes beyond traditional database permissions and masking because MDA inspects and restricts the user's interactive environment in real time. To be effective, you target the specific app (e.g., Azure Portal or SQL Query Editor) and define policy conditions and actions for sensitive data.

Why this answer

The correct option is D: configuring a session policy in Microsoft Defender for Cloud Apps to block clipboard and screenshot actions. Defender for Cloud Apps Conditional Access App Control uses a session policy to proxy the session and apply controls such as blocking copy/paste to the clipboard and preventing screenshots, which directly addresses the requirement while still permitting legitimate query operations. Option A is incorrect because Azure Information Protection labels classify and protect data at rest or in documents, not interactive query result sessions.

Option B is incorrect because Dynamic Data Masking only obscures column values in query output and does not prevent copying or screenshotting. Option C is incorrect because Auditing and threat detection only log and alert on suspicious activity; they do not block clipboard or screenshot actions.

37
MCQeasy

You are designing a backup strategy for Azure virtual machines that host a mission-critical application. The solution must support daily backups with a retention of 30 days for daily backups, weekly backups retained for 12 weeks, and monthly backups retained for 3 years. What should you use?

A.Azure Files backup with a custom script.
B.Azure Disk Backup with a snapshot schedule.
C.Azure Site Recovery with a recovery plan.
D.Azure Backup with a backup policy that specifies daily, weekly, and monthly retention.
AnswerD

Azure Backup with a VM backup policy precisely matches the requirement: the policy allows a daily, weekly, and monthly retention schedule, with each retention tier preserving recovery points for up to 180 days, 10 years, and 10 years respectively. You can also adjust retention to meet compliance needs, and Azure Backup stores recovery points in the Recovery Services vault. This gives you application-consistent, crash-consistent, or file-consistent snapshots and supports instant restore from snapshots. It is the correct strategy for multi-tier retention of Azure VMs.

Why this answer

Azure Backup with a backup policy that specifies daily, weekly, and monthly retention (option D) is correct because Azure Backup for virtual machines natively supports long-term retention through policy rules that define daily, weekly, monthly, and yearly retention durations, exactly matching the required 30-day daily, 12-week weekly, and 3-year monthly schedule. Azure Backup also provides application-consistent snapshots and recovery points for mission-critical VMs without custom scripting. Option A is wrong because Azure Files backup targets file shares, not VM disks, and requires custom scripting that Azure Backup handles natively.

Option B is wrong because Azure Disk Backup only supports snapshot-based retention up to a limited period and does not provide the multi-tier daily/weekly/monthly retention policy required. Option C is wrong because Azure Site Recovery is a disaster-recovery replication service, not a backup solution with retention policies.

38
MCQeasy

A company uses Microsoft Sentinel to detect threats. They want to automatically send an email to the security team when a high-severity incident is created. What should they configure?

A.An analytics rule with an automated response
B.A workbook
C.A watchlist
D.A hunting query
AnswerA

An analytics rule with an automated response is the correct option because Microsoft Sentinel's analytics rules not only detect threats and generate incidents but also allow you to attach an automated response, commonly an Azure Logic Apps-based playbook, directly in the rule's 'Incident automation' step. When a high-severity incident is created, that automatic response triggers the playbook, which can send an email via Office 365 Outlook or other connectors. This couples the detection engine with an actionable response workflow, meeting the stated requirement exactly. Unlike workbooks, watchlists, or hunting queries, this is the only option that provides a direct, automatic, and incident-driven notification mechanism.

Why this answer

The correct option is A, an analytics rule with an automated response, because in Microsoft Sentinel analytics rules generate incidents from detected events, and their automated response (via automation rules or playbooks triggered on incident creation) can send an email to the security team when a high-severity incident is created. This directly satisfies the requirement of automatic notification upon incident creation. A workbook (B) is only a visualization/reporting dashboard and does not trigger notifications.

A watchlist (C) stores reference data for enrichment or correlation and cannot send emails. A hunting query (D) is a manual, proactive search for threats and does not automatically notify anyone.

39
MCQeasy

Your organization is adopting Microsoft Purview to classify and protect sensitive data in Microsoft 365. You need to ensure that documents containing credit card numbers are automatically detected and encrypted when shared externally. What should you configure?

A.An Information Barrier policy between departments
B.A sensitivity label configured with auto-labeling for credit card numbers and encryption for external sharing
C.A retention label that deletes documents with credit card numbers after 90 days
D.A Data Loss Prevention (DLP) policy that blocks sharing of credit card numbers
AnswerB

A sensitivity label with auto-labeling uses Microsoft Purview's sensitive info types, such as credit card numbers, to automatically classify documents when those patterns are detected. The label can be configured with permissions-based encryption (via Azure Rights Management), which protects the content even when shared externally by enforcing view/edit restrictions. This directly satisfies both the classification and external-sharing protection requirements in the scenario.

Why this answer

Sensitivity labels in Microsoft Purview can be configured with auto-labeling conditions that detect sensitive data types (e.g., credit card numbers) and automatically apply encryption to documents when shared externally. This meets the requirement of automatic detection and encryption for external sharing without manual user intervention.

Exam trap

The trap here is confusing DLP policies (which block or warn) with sensitivity labels (which can auto-apply encryption), leading candidates to choose DLP when the requirement explicitly states 'encrypt when shared externally' rather than block.

How to eliminate wrong answers

Option A is wrong because Information Barrier policies are designed to prevent communication and collaboration between specific groups or departments, not to detect or encrypt sensitive data like credit card numbers. Option C is wrong because retention labels manage data lifecycle (retention or deletion) based on time, not real-time detection or encryption of sensitive content when shared externally. Option D is wrong because a DLP policy can block sharing of credit card numbers but does not encrypt the documents; it only prevents the action, whereas the requirement is to encrypt when shared externally.

40
MCQhard

Your organization uses Microsoft Defender for Cloud to secure multi-cloud workloads. You need to ensure that Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP) resources are assessed against the same security baseline. What should you do?

A.Configure AWS Config and GCP Security Command Center to export findings to Microsoft Sentinel
B.Connect AWS and GCP accounts to Defender for Cloud and use Azure Policy to enforce the Microsoft Cloud Security Benchmark
C.Use regulatory compliance standards for each cloud separately
D.Enable the Cloud Security Posture Management (CSPM) plan and configure AWS and GCP connectors
AnswerB

Connecting AWS and GCP accounts to Defender for Cloud surfaces those resources in Azure Resource Graph, where Azure Policy can apply the Microsoft Cloud Security Benchmark (MCSB), a unified initiative built on CIS/NIST plus Microsoft controls. This gives continuous compliance assessment and enforcement, like DeployIfNotExists remediation, across all clouds. As a result, every subscription or cloud account is measured against the same baseline, regardless of native cloud tooling—this is the only option that both centralizes and enforces a single baseline.

Why this answer

Microsoft Defender for Cloud's multi-cloud CSPM capabilities allow you to connect AWS and GCP accounts directly, and then apply Azure Policy to enforce the Microsoft Cloud Security Benchmark (MCSB) across all connected clouds. This ensures a unified security baseline assessment for Azure, AWS, and GCP resources, as MCSB is the default policy initiative in Defender for Cloud.

Exam trap

The trap here is that candidates confuse enabling the CSPM plan and connectors (Option D) with the complete solution, forgetting that a specific baseline policy (MCSB) must be assigned via Azure Policy to enforce the unified assessment.

How to eliminate wrong answers

Option A is wrong because exporting findings from AWS Config and GCP Security Command Center to Microsoft Sentinel is for centralized SIEM and threat detection, not for enforcing a unified security baseline across clouds. Option C is wrong because using separate regulatory compliance standards for each cloud would not enforce a single, consistent security baseline; it would result in fragmented assessments. Option D is wrong because enabling the CSPM plan and configuring connectors is a prerequisite step, but it does not by itself enforce a specific security baseline; you must also assign the Microsoft Cloud Security Benchmark policy via Azure Policy to achieve the stated goal.

41
MCQhard

Your organization is implementing a privileged access strategy using Microsoft Entra Privileged Identity Management (PIM). The compliance team requires that all privileged role activations be approved by a manager and that an audit trail is maintained for at least one year. Which configuration should you recommend?

A.Configure access reviews for privileged roles
B.Set PIM role settings to require approval and enable audit logging
C.Enable Conditional Access policies for privileged roles
D.Require Azure MFA for role activation
AnswerB

PIM supports approval workflow and logs are retained for auditing.

Why this answer

It directly addresses both compliance requirements: requiring approval ensures a manager authorizes each activation, and enabling audit logging in PIM retains activation history for at least one year. PIM role settings allow you to configure approval workflows and automatically log all activations to the Microsoft Entra audit log, which can be exported and retained for compliance purposes.

Exam trap

The trap here is that candidates confuse access reviews (periodic recertification) with the real-time approval workflow required for each activation, or they assume MFA alone satisfies the audit and approval requirements.

How to eliminate wrong answers

Option A is wrong because access reviews are used for periodic recertification of role assignments, not for real-time approval of activations or audit trail retention. Option C is wrong because Conditional Access policies control access based on conditions like location or device state, but they do not provide the required manager approval workflow or dedicated audit logging for role activations. Option D is wrong because Azure MFA for role activation enhances security but does not satisfy the compliance requirement for manager approval or the one-year audit trail retention.

42
MCQmedium

Your organization uses Microsoft Purview to manage data governance. You need to create a unified data catalog that automatically classifies and labels data across Azure SQL Database, Amazon S3, and on-premises SQL Server. What should you configure?

A.Microsoft Purview account with scans for all data sources.
B.Azure Data Catalog with custom classification.
C.Azure Purview (legacy) with multi-cloud scanning.
D.Microsoft Information Protection scanner on each source.
AnswerA

A Microsoft Purview account is the correct choice because it provides an automated, unified data governance solution that scans and catalogs metadata from all data sources, including on-premises, Azure, AWS, Google Cloud, and SaaS applications. This enables centralized data discovery, classification, lineage, and policy enforcement. Unlike legacy or single-purpose tools, it creates a comprehensive data map for the entire organization.

Why this answer

The correct option is A: a Microsoft Purview account with scans for all data sources. Microsoft Purview is the unified data governance service that builds a data map and catalog by registering and scanning sources such as Azure SQL Database, Amazon S3, and on-premises SQL Server, then automatically applying built-in and custom classifications and sensitivity labels during those scans. The other options do not fit: Azure Data Catalog is a retired service that lacks automated classification and labeling, Azure Purview (legacy) is the former branding of the same service and not the current configuration, and the Microsoft Information Protection scanner only discovers and labels sensitive files on file shares and on-premises repositories, not cloud databases or S3 buckets.

43
MCQmedium

A company uses Microsoft Purview to manage data governance. They need to classify sensitive data automatically in Azure SQL Database. What should they configure?

A.Microsoft Defender for Cloud regulatory compliance
B.Microsoft Purview Data Map scanning rules
C.Microsoft Sentinel data connectors
D.Microsoft Entra ID Protection
AnswerB

Microsoft Purview Data Map scanning rules automatically connect to various data sources, both on-premises and multi-cloud, and run scans to profile and classify assets. These rules apply built-in or custom classification patterns—like regex for PII, financial, or health information—and assign sensitivity labels to structured and unstructured data. This is exactly the mechanism that enables data governance by building a searchable, classified inventory of enterprise data, making it the correct choice for a company using Purview.

Why this answer

Microsoft Purview Data Map scanning rules are the correct choice because they enable automated classification of sensitive data in Azure SQL Database by scanning the database schema and content against built-in or custom sensitive data types. This is the native mechanism within Purview to discover and label sensitive columns, such as credit card numbers or PII, directly in Azure SQL Database.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud's regulatory compliance dashboard with actual data classification, but Defender for Cloud only checks configuration settings against compliance frameworks, not the content of the data itself.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud regulatory compliance assesses the security posture of Azure resources against compliance standards (e.g., SOC 2, PCI DSS) but does not perform data classification or scanning of sensitive data within Azure SQL Database. Option C is wrong because Microsoft Sentinel data connectors ingest security logs and alerts from various sources for threat detection and SIEM purposes, not for scanning or classifying sensitive data in databases. Option D is wrong because Microsoft Entra ID Protection focuses on identity-based risks such as compromised credentials and sign-in anomalies, not on data classification within Azure SQL Database.

44
Multi-Selectmedium

Your organization is designing a secure access solution for a partner company that needs to access specific SharePoint Online sites. You need to implement Microsoft Entra ID B2B collaboration. Which THREE configurations are essential for a secure B2B collaboration setup?

Select 3 answers
A.Configure cross-tenant access settings in Microsoft Entra ID
B.Enable multi-factor authentication (MFA) for guest users
C.Use B2B direct connect for SharePoint site access
D.Allow all external domains to invite users without restrictions
E.Set Conditional Access policies that apply to guest users
AnswersA, B, E

Cross-tenant access settings in Microsoft Entra ID are the foundational control for managing B2B collaboration with partner organizations. They let you define granular inbound and outbound policies that govern trust claims (e.g., MFA, device compliance, hybrid Azure AD join) and apply Conditional Access scoping per tenant, user, group, or application. This replaces the older, less secure per-tenant manual configurations and provides a cohesive access-control plane for external identities.

Why this answer

Option A is correct because cross-tenant access settings in Microsoft Entra ID let you control inbound and outbound B2B collaboration with the partner tenant, including trust settings for MFA and device claims, which is essential for governing partner access to specific SharePoint Online sites. Option B is correct because enabling MFA for guest users strengthens authentication and reduces the risk of compromised credentials being used to access shared SharePoint resources. Option E is correct because Conditional Access policies scoped to guest users enforce sign-in controls such as MFA, compliant devices, and location restrictions, which are critical for securing B2B access.

Option C is not essential here because B2B direct connect is designed for Teams shared channels and does not apply to SharePoint site access in this scenario. Option D is incorrect because allowing all external domains without restrictions removes governance and exposes the tenant to unauthorized invitations and access.

Exam trap

The trap here is confusing B2B direct connect (for Teams shared channels) with B2B collaboration (for SharePoint and other apps), leading candidates to select Option C incorrectly.

45
Multi-Selecteasy

Which TWO Microsoft Purview solutions should you use to protect sensitive data in Microsoft 365? (Choose two.)

Select 2 answers
A.Microsoft Purview Audit.
B.Insider Risk Management.
C.Sensitivity labels and policies.
D.Microsoft Purview eDiscovery.
E.Data Loss Prevention (DLP) policies.
AnswersC, E

Sensitivity labels apply persistent encryption and visual markings directly to content, satisfying the requirement to protect sensitive data at the item level across Microsoft 365 workloads. Unlike perimeter controls, labels travel with the file, enforcing protection even after it leaves the tenant, which is precisely what the scenario demands.

Why this answer

Sensitivity labels and policies (C) are correct because they apply persistent protection to content by classifying data and enforcing encryption, content marking, and usage restrictions that travel with the file or email across Microsoft 365 workloads. Data Loss Prevention (DLP) policies (E) are correct because they detect sensitive information types and take protective actions such as blocking, warning, or encrypting data when it is shared inappropriately in Exchange Online, SharePoint, OneDrive, and Teams. Audit (A) is not a protection solution; it records and searches user and admin activity for investigation and compliance reporting.

Insider Risk Management (B) focuses on detecting and remediating risky user behavior rather than directly protecting sensitive data. eDiscovery (D) is used to identify, preserve, collect, and review content for legal or investigative purposes, not to enforce data protection.

Exam trap

SC-100 often tests the distinction between preventive data protection controls (labels, DLP) and detective/investigative tools (Audit, Insider Risk, eDiscovery) — candidates pick Audit or Insider Risk because they sound security-related but do not actually protect data.

46
MCQmedium

Your organization uses Microsoft Purview and needs to prevent users from copying sensitive data to USB drives. Which solution should you implement?

A.Sensitivity labels with encryption
B.Insider Risk Management
C.Endpoint data loss prevention (DLP)
D.Communication Compliance
AnswerC

Endpoint data loss prevention (Endpoint DLP) is the correct choice because it installs an agent on Windows and macOS endpoints that inspects data in real time as users interact with files. It can enforce policies to block the copying of sensitive items, such as those matching sensitive info types or trainable classifiers, to removable USB devices, and optionally show a policy tip to the user. This direct, pre-action enforcement provides the precise control needed to prevent data leakage via USB.

Why this answer

Endpoint DLP is the correct solution because it extends data loss prevention policies to endpoints, enabling the detection and blocking of sensitive data being copied to removable USB drives. Unlike other controls, Endpoint DLP can monitor and restrict data exfiltration actions at the device level, such as copying files to USB media, based on the content's sensitivity classification.

Exam trap

The trap here is that candidates often confuse Insider Risk Management (a detective control) with Endpoint DLP (a preventive control), assuming that risk management can block actions, when in fact it only alerts on suspicious behavior after the fact.

How to eliminate wrong answers

Option A is wrong because sensitivity labels with encryption protect data at rest and in transit by restricting access, but they do not block the act of copying labeled data to a USB drive; encryption alone does not prevent data exfiltration via removable media. Option B is wrong because Insider Risk Management is a detection and investigation tool that identifies risky user activities (e.g., unusual file copying) but does not actively block or prevent the copy action in real time. Option D is wrong because Communication Compliance focuses on monitoring and analyzing communications (e.g., email, Teams) for policy violations, not on controlling data movement to USB drives.

47
MCQmedium

Your company develops a web application hosted on Azure App Service. The application uses Azure SQL Database and requires managed identities to access the database. You need to ensure that the application can authenticate to Azure SQL without storing credentials in code. Which authentication method should you implement?

A.Store a client certificate in Azure Key Vault and reference it from the app.
B.Use an Azure AD service principal with a client secret.
C.Use Azure SQL database-level firewall rules with a static IP restriction.
D.Enable system-assigned managed identity on the App Service and grant it access to the SQL database.
AnswerD

A system-assigned managed identity gives the App Service a Microsoft Entra ID (Azure AD) identity that is automatically created with the app and requires no secrets to be stored in code or configuration. You enable Microsoft Entra authentication on the SQL logical server, then run `CREATE USER [<app-name>] FROM EXTERNAL PROVIDER` to map the identity to a database user and grant least-privilege roles like `db_datareader` and `db_datawriter`. The connection uses token-based authentication (for example, `Authentication=ActiveDirectoryManagedIdentity` in the connection string), eliminating credential storage and rotation.

Why this answer

Option D is correct because enabling a system-assigned managed identity on the Azure App Service creates an identity in Azure AD tied to the app's lifecycle, and that identity can be granted access to Azure SQL Database (for example, by creating a contained database user with CREATE USER [app-name] FROM EXTERNAL PROVIDER and assigning db_datareader/db_datawriter roles), letting the app authenticate without storing any credentials in code. This is the recommended passwordless approach for App Service to Azure SQL. Option A still requires managing and referencing a client certificate, which is credential material rather than eliminating secrets.

Option B uses a service principal with a client secret, which is exactly the stored credential the scenario wants to avoid. Option C only restricts network access via firewall rules and does not provide authentication or authorization to the database.

48
MCQeasy

You need to audit user activities in Microsoft 365, including who accessed a specific file in SharePoint Online. Which Microsoft Purview solution should you use?

A.Microsoft Purview Information Protection
B.Microsoft Purview Communication Compliance
C.Microsoft Purview Audit
D.Microsoft Purview Data Lifecycle Management
AnswerC

Microsoft Purview Audit is the correct solution because it provides a unified audit log that records user and admin activities across Microsoft 365 services, including file access, permission changes, and sign-ins. Organizations can search and export these audit records from the Purview compliance portal or via Office 365 Management Activity API, enabling security teams to investigate incidents and meet compliance requirements. This capability directly addresses the need to audit user activities.

Why this answer

Microsoft Purview Audit (specifically Audit (Standard) or Audit (Premium)) is the correct solution because it captures and logs user activities across Microsoft 365 services, including SharePoint Online. When a user accesses a specific file, the audit log records the event with details such as the user, file name, action (e.g., FileAccessed), and timestamp, enabling you to query this data via the Microsoft 365 Defender portal or Search-UnifiedAuditLog cmdlet.

Exam trap

The trap here is that candidates often confuse 'auditing' with 'protection' or 'compliance' solutions, mistakenly choosing Information Protection (A) because they think labeling controls access, or Communication Compliance (B) because they associate 'compliance' with monitoring user actions, when in fact Audit is the dedicated logging service for user activity tracking.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Protection focuses on classifying, labeling, and protecting sensitive data (e.g., via sensitivity labels and encryption), not on auditing user activities or file access events. Option B is wrong because Microsoft Purview Communication Compliance is designed to detect and remediate inappropriate communications (e.g., offensive language or insider trading) in Exchange Online, Teams, or Yammer, not to audit file access in SharePoint Online. Option D is wrong because Microsoft Purview Data Lifecycle Management manages retention and deletion policies for data (e.g., automatically archiving or deleting old files), not the logging of user access events.

49
MCQeasy

A company uses Microsoft Defender for Cloud to assess the security posture of their Azure subscriptions. They want to receive alerts when a resource is deployed without encryption enabled. What should they configure?

A.Azure Blueprints
B.Microsoft Defender for Cloud regulatory compliance dashboard
C.Microsoft Defender for Cloud security alerts
D.Azure Policy definition to audit or deny resources without encryption
AnswerD

An Azure Policy definition with audit or deny effects is the correct enforcement mechanism because it evaluates resource properties (such as encryption settings) against rules during provisioning and continuously thereafter. A deny effect blocks deployment of any resource that violates the encryption policy, while an audit effect marks the resource as non-compliant for reporting and follow-up. This approach ensures encryption requirements are consistently applied across new and existing resources, directly closing the configuration gap.

Why this answer

Azure Policy with a custom policy definition can audit or deny resources without encryption. Defender for Cloud's regulatory compliance dashboard shows compliance status. Security alerts are for threats, not configuration drift.

Azure Blueprints are for packaging resources.

50
MCQmedium

Your organization uses Microsoft Entra ID for identity and access management. You are developing a web application that needs to access Microsoft Graph API on behalf of the signed-in user. Which authentication flow should you implement?

A.Implicit Flow
B.Client Credentials Flow
C.Authorization Code Flow with PKCE
D.Device Code Flow
AnswerC

The Authorization Code Flow with PKCE is the recommended OAuth 2.0 grant for web applications that access APIs on behalf of a user. It starts with a user interactive authentication, then the app exchanges an authorization code for tokens, and PKCE (Proof Key for Code Exchange) adds a cryptographic verifier to prevent code interception attacks. Also, it supports refresh tokens, allowing long-lived access without re-authentication.

Why this answer

Authorization Code Flow with PKCE (C) is correct because it is the recommended OAuth 2.0 flow for web applications that call Microsoft Graph on behalf of a signed-in user, exchanging the authorization code for delegated access and refresh tokens while PKCE protects the code exchange against interception. Implicit Flow (A) is deprecated for this purpose and returns tokens directly from the authorization endpoint without an authorization code, offering weaker security. Client Credentials Flow (B) is app-only and has no signed-in user, so it cannot act on behalf of a user.

Device Code Flow (D) is intended for input-constrained devices, not a standard web application with a browser-based sign-in.

51
MCQeasy

A software company uses Microsoft 365 E5 and wants to ensure that when an employee is terminated, their access to all Microsoft Entra ID integrated applications is removed immediately and their manager is notified to reassign their files. The company wants to automate this without manual intervention from the IT help desk. Which Microsoft Entra ID Governance feature should you design into the solution?

A.Access reviews that require managers to certify their team's group memberships quarterly
B.Lifecycle workflows that run a leaver task on the employee's last day
C.Conditional Access policies that block sign-ins from unmanaged devices
D.Privileged Identity Management to make all application roles eligible rather than active
AnswerB

Lifecycle workflows in Microsoft Entra ID Governance automate joiner, mover, and leaver tasks based on events or schedules. A leaver workflow can disable the account, remove group and application assignments, and send notifications to the manager, which matches the requirement to revoke access immediately and notify the manager without help desk involvement.

Why this answer

The scenario calls for automated, event-driven removal of access plus manager notification at termination. Lifecycle workflows in Microsoft Entra ID Governance are built for exactly this leaver pattern, running tasks such as disabling the account, removing assignments, and sending notifications. Access reviews are periodic and manual, conditional access governs authentication conditions, and Privileged Identity Management governs privileged role activation.

Exam trap

The trap here is choosing access reviews for termination, when reviews are periodic certification cycles rather than event-driven leaver automation.

52
MCQeasy

Your company uses Microsoft Entra ID for identity management. You need to implement a solution to automatically detect and remediate risky sign-ins using machine learning. What should you configure?

A.Configure Microsoft Entra Connect to sync on-premises identities.
B.Configure Conditional Access policies with session controls.
C.Configure Microsoft Entra ID Protection and enable risk-based policies.
D.Configure Privileged Identity Management (PIM) for admin roles.
AnswerC

Microsoft Entra ID Protection actively monitors user and sign-in risk using machine learning, heuristic analysis, and Microsoft's threat intelligence feeds. Enabling risk-based policies (which are a type of Conditional Access policy using risk as a condition) allows automatic remediation, such as requiring MFA, blocking the sign-in, or forcing a secure password change. This directly addresses the need to detect risky identities and respond without manual intervention, making it the correct choice for identity-based threat detection and auto-remediation.

Why this answer

Microsoft Entra ID Protection is the correct choice (Option C) because it uses machine learning to detect risky sign-ins and user risk events, and it lets you enable risk-based Conditional Access policies that automatically remediate those risks (for example, requiring MFA or blocking access). It is purpose-built for identity risk detection and automated remediation, matching the scenario's requirement exactly. Option A, Entra Connect, only synchronizes on-premises identities to Entra ID and does not perform risk detection.

Option B, Conditional Access with session controls, enforces access and session restrictions but does not itself provide the machine-learning risk detection engine. Option D, PIM, manages just-in-time privileged role activation and approvals, not risky sign-in detection or remediation.

53
MCQhard

A company is designing a microservices architecture on Azure Kubernetes Service (AKS). Each microservice needs to authenticate to Azure SQL Database using its own identity. The security team requires that no service principal secrets or certificates be stored in the cluster. What should you implement to authenticate the microservices to Azure SQL Database?

A.Create a service principal and store its secret in Azure Key Vault; use the Key Vault Secrets Store CSI driver to mount it.
B.Enable a system-assigned managed identity on the AKS cluster nodes and have pods use it.
C.Use Azure AD Workload Identity for each pod to authenticate to Azure SQL Database using managed identities.
D.Store the Azure SQL connection string with credentials in a Kubernetes secret.
AnswerC

Using Azure AD Workload Identity for each pod assigns a unique Azure AD identity to each Kubernetes service account via federated identity credentials and the cluster's OIDC issuer. The pod's service account token is exchanged for an Azure AD token that grants access to Azure SQL Database without storing any secrets in the cluster. This enables per-microservice least-privilege access, supports conditional access and audit logs, and is the modern, secure replacement for service principals and node-level managed identities.

Why this answer

Azure AD Workload Identity is the correct choice because it federates a Kubernetes service account with an Azure AD managed identity, allowing each pod to obtain Azure AD tokens without any stored secrets or certificates in the cluster. This directly satisfies the requirement that each microservice authenticates with its own identity and that no service principal secrets or certificates be stored. Option A is wrong because it still relies on a service principal secret stored in Key Vault and mounted into the cluster.

Option B is wrong because a node-level system-assigned managed identity is shared by all pods on the node, so it does not give each microservice its own identity. Option D is wrong because storing credentials in a Kubernetes secret violates the no-secrets requirement and is not identity-based authentication.

54
MCQhard

You are a security architect for a global financial services company that uses Microsoft 365 E5 and Azure. The company has 50,000 users across 10 regions. The security team needs to detect and respond to identity-based threats in real-time, automate remediation for compromised accounts, and meet regulatory requirements for audit logging. The following requirements must be met: (1) Detect risky sign-ins and user anomalies, (2) Automatically block sign-ins when risk level is high, (3) Provide a centralized dashboard for security analysts to investigate incidents, (4) Retain logs for at least one year for compliance, (5) Minimize false positives by using machine learning. You have the following services available: Microsoft Entra ID P2, Microsoft Sentinel, Microsoft Defender for Identity, Microsoft Purview, and Microsoft Intune. Which combination of services should you use to meet all requirements?

A.Microsoft Intune and Microsoft Defender for Cloud
B.Microsoft Entra ID Protection (P2) and Microsoft Sentinel
C.Microsoft Defender for Identity and Microsoft Purview
D.Microsoft Purview and Microsoft Sentinel
AnswerB

Entra ID Protection (P2) uses machine learning to continuously evaluate sign-in and user risk, assigning risk levels and enabling Conditional Access to require MFA or block high-risk attempts. Sentinel then ingests these risk detections, along with other identity logs, into a central SIEM that provides long-term retention, advanced hunting through KQL, and analyst workflow for investigation. Together they deliver both the real-time detection and the centralized visibility needed by a global financial services security team.

Why this answer

Microsoft Entra ID Protection (P2) provides the risk-based sign-in and user risk detections powered by machine learning, and its Conditional Access integration can automatically block sign-ins when risk is high, satisfying requirements 1, 2, and 5. Microsoft Sentinel supplies the centralized SIEM dashboard for analysts to investigate incidents and supports long-term log retention (including one-year retention via the data lake or workspace retention settings), covering requirements 3 and 4. Together, option B meets all five requirements.

Option A is wrong because Intune handles device management and Defender for Cloud covers cloud workload protection, not identity risk detection or SIEM. Option C is wrong because Defender for Identity monitors on-premises Active Directory signals and Purview handles data governance/compliance, not real-time sign-in risk blocking. Option D is wrong because Purview does not perform identity risk detection or automated sign-in remediation.

Exam trap

Candidates often confuse Microsoft Defender for Identity (on-premises AD) with Entra ID Protection (cloud identity). The question specifies a cloud-only environment with Microsoft 365 and Azure, so Defender for Identity is not suitable.

55
MCQhard

A company uses Azure DevOps and wants to implement a DevSecOps practice by scanning code for secrets and vulnerabilities before deployment. Which tool should they integrate into their pipeline?

A.Azure Policy
B.Microsoft Purview
C.GitHub Advanced Security
D.Microsoft Defender for DevOps
AnswerD

Microsoft Defender for DevOps is a dedicated service that integrates directly with Azure DevOps (and GitHub) to provide continuous security scanning of code, secrets, infrastructure-as-code templates, and open-source dependencies. It leverages built-in scanners like Credential Scanner and integrates with Defender for Cloud to aggregate findings across the software development life cycle. This makes it the correct choice for an Azure DevOps-centric organization seeking DevOpsSec capabilities.

Why this answer

Microsoft Defender for DevOps is the correct choice because it is a unified DevSecOps solution that integrates directly into Azure DevOps pipelines to scan code for secrets, vulnerabilities, and open-source dependencies before deployment. It provides actionable security insights and remediation guidance, aligning with the requirement to implement a DevSecOps practice by scanning code for secrets and vulnerabilities.

Exam trap

The trap here is that candidates may confuse GitHub Advanced Security (which is for GitHub repositories) with Microsoft Defender for DevOps (which is for Azure DevOps pipelines), leading them to choose Option C even though the question explicitly states the company uses Azure DevOps.

How to eliminate wrong answers

Option A is wrong because Azure Policy is a governance tool that enforces compliance rules on Azure resources (e.g., tagging, location restrictions) and does not scan code for secrets or vulnerabilities. Option B is wrong because Microsoft Purview is a data governance and classification service for data estates (e.g., sensitive data discovery in storage) and lacks the capability to scan source code in a CI/CD pipeline. Option C is wrong because GitHub Advanced Security is a suite of security features for GitHub repositories (e.g., secret scanning, code scanning) but is not natively integrated into Azure DevOps pipelines; it requires a GitHub repository, whereas the question specifies Azure DevOps.

56
Multi-Selecthard

Refer to the exhibit. You are reviewing an ARM template for a storage account. The security team has mandated that all storage accounts must enforce HTTPS traffic and use TLS 1.2 or higher. Which two changes must be made to the template to comply? (Choose two.)

Select 2 answers
A.Change 'minimumTlsVersion' to 'TLS1_2'
B.Set 'kind' to 'BlobStorage'
C.Add 'networkAcls' with defaultAction Deny
D.Change 'sku.name' to 'Standard_LRS'
E.Set 'supportsHttpsTrafficOnly' to true
AnswersA, E

TLS 1.0 is deprecated and no longer considered secure; Azure Storage requires customers to enforce at least TLS 1.2 for all data plane access. By setting the 'minimumTlsVersion' property to 'TLS1_2', the account will reject any client connections attempting to use TLS 1.0 or 1.1. This is a distinct control from HTTPS enforcement, but it is the configuration that directly addresses the requirement to prevent outdated protocol usage.

Why this answer

Option A is correct because the storage account property 'minimumTlsVersion' must be set to 'TLS1_2' (or higher, such as 'TLS1_3' where supported) to enforce TLS 1.2 or above, satisfying the security team's TLS requirement. Option E is correct because the 'supportsHttpsTrafficOnly' property must be set to true so the storage account rejects non-HTTPS (HTTP) requests, enforcing HTTPS traffic. Option B is incorrect because 'kind' (BlobStorage vs StorageV2) controls the type of storage account and its supported features, not HTTPS or TLS enforcement.

Option C is incorrect because 'networkAcls' with defaultAction Deny restricts network access by IP or virtual network, which is unrelated to enforcing HTTPS or TLS versions. Option D is incorrect because 'sku.name' (Standard_LRS) only defines the redundancy/replication tier and performance level, not transport security settings.

Exam trap

Microsoft often tests the misconception that network access controls (like network ACLs) or storage account type changes can enforce encryption or TLS version requirements, when in fact only the explicit 'minimumTlsVersion' and 'supportsHttpsTrafficOnly' properties control these security settings.

57
Multi-Selecteasy

Your organization is using Microsoft Sentinel for security operations. Which THREE data sources can be connected to Microsoft Sentinel out of the box? (Choose THREE.)

Select 3 answers
A.Azure Active Directory (now Microsoft Entra ID)
B.Amazon Web Services (AWS) CloudTrail
C.Azure DevOps
D.Microsoft 365 Defender
E.Power BI
AnswersA, B, D

Microsoft Sentinel has a built-in data connector for Azure Active Directory (now Microsoft Entra ID) that streams sign-in logs and audit logs into the SigninLogs and AuditLogs tables. This connector is a first-party, low-latency ingestion path for identity telemetry, enabling detection of risky sign-ins, MFA failures, and privilege escalation. Because identity is a primary attack surface, this connector is a standard and correct choice for Sentinel data sources.

Why this answer

Options A (Azure Active Directory/Entra ID), B (AWS CloudTrail), and D (Microsoft 365 Defender) are all supported out-of-the-box data connectors in Microsoft Sentinel. Option C (Azure DevOps) is not a built-in connector; it requires a custom API or solution. Option E (Power BI) is not a data source connector for Sentinel.

58
Multi-Selecthard

Your organization uses Microsoft Entra ID and Microsoft Intune. You need to design a solution that allows corporate users to access a sensitive internal application only from managed devices that are compliant with company security policies. The solution should block access from personal devices. Which two components should you use? (Choose TWO.)

Select 2 answers
A.Microsoft Intune app protection policy
B.Microsoft Entra ID Conditional Access policy that requires hybrid Azure AD join
C.Microsoft Intune device enrollment
D.Microsoft Intune device compliance policy
E.Microsoft Entra ID Conditional Access policy that requires a compliant device
AnswersD, E

A Microsoft Intune device compliance policy defines the exact security and configuration standards that a device must meet to be considered compliant, such as requiring encryption, a minimum OS version, no jailbreak/root, or a healthy threat agent score. The policy assigns a compliance state (compliant/non-compliant) for each enrolled device, and that state is then published to Entra ID. This policy is the foundation of device-based access control because it establishes the authoritative criteria that determine whether a device should be trusted.

Why this answer

Option D (Microsoft Intune device compliance policy) is correct because it defines and evaluates the security requirements—such as BitLocker, OS version, and firewall settings—that a device must meet to be marked compliant, which is the foundation for gating access to the sensitive application. Option E (Microsoft Entra ID Conditional Access policy that requires a compliant device) is correct because Conditional Access enforces the access decision at authentication time, granting access only when Intune reports the device as compliant and blocking personal or non-compliant devices. Together, the compliance policy determines device state and the Conditional Access policy enforces it for the target app.

Option A is not correct because app protection policies (MAM) protect app data on unmanaged/personal devices rather than blocking access from them. Option B is not correct because requiring hybrid Azure AD join restricts access to domain-joined devices and does not directly enforce the company's compliance policy baseline. Option C is not correct because device enrollment alone only registers devices in Intune; without a compliance policy and Conditional Access enforcement, it does not block personal or non-compliant devices.

59
Multi-Selecthard

Your company uses Microsoft Sentinel to manage security incidents. You need to design a solution that automatically triages low-severity incidents and enriches them with threat intelligence. Which THREE capabilities would you include? (Choose three.)

Select 3 answers
A.Advanced hunting queries to investigate incidents.
B.Analytics rules to generate alerts for low-severity incidents.
C.Playbooks to perform enrichment actions like querying threat intelligence.
D.Automation rules to trigger playbooks on incident creation.
E.Watchlists to store known indicators for correlation.
AnswersC, D, E

Playbooks are Azure Logic Apps workflows that can be automatically invoked by automation rules to perform enrichment operations on an incident, such as querying Threat Intelligence platforms like MISP or Microsoft Graph Security API. By pulling threat intel about involved entities (IPs, hashes, domains) and writing those findings back to the incident, playbooks give analysts and automated rules the context needed to rapidly triage and prioritize low-severity incidents without manual querying.

Why this answer

Option C is correct because Microsoft Sentinel playbooks, built on Azure Logic Apps, are the automation mechanism that can call the Threat Intelligence connectors and other enrichment actions to add context (for example, IP/domain reputation) to an incident. Option D is correct because automation rules evaluate incident conditions (such as severity or title) at incident creation and can trigger the playbook, which is exactly how low-severity incidents get automatically triaged and enriched. Option E is correct because watchlists let you upload and correlate known indicators (IPs, domains, hashes) against incident entities, providing a lightweight threat-intelligence enrichment source within Sentinel.

Option A is not appropriate here because advanced hunting queries are manual, interactive KQL investigations rather than an automated triage/enrichment capability. Option B is not appropriate because analytics rules generate alerts and incidents; they do not perform the automated triage or threat-intelligence enrichment the scenario requires.

60
MCQmedium

Refer to the exhibit. You run the PowerShell command to retrieve information about a Managed HSM in Azure. The output shows that the HSM is in 'Provisioned' state and has two security domains. What is the purpose of the security domains?

A.To manage the HSM's private endpoint connections.
B.To back up and restore the HSM's key material and configuration.
C.To enable role-based access control (RBAC) for the HSM.
D.To define the HSM's network access and firewall rules.
AnswerB

The security domain contains the encrypted material needed to reconstruct the HSM's master key, which in turn wraps all keys and protects the HSM's configuration. Downloading it creates a backup that, along with the quorum of security domain keys, can restore the HSM to a usable state after a disaster. This is why the security domain is essential for disaster recovery of the managed HSM.

Why this answer

The correct answer is B: security domains in Azure Managed HSM are used to back up and restore the HSM's key material and configuration. A security domain is a specially encrypted blob containing the HSM's full key material and configuration, and it is the only way to restore an HSM to a new instance or recover from a total loss of the HSM. Options A, C, and D are incorrect because private endpoint connections, RBAC, and network/firewall rules are managed through Azure networking and Azure RBAC features, not through security domains.

61
MCQeasy

You are designing a security solution for Azure resources. You need to ensure that any changes to network security groups (NSGs) are automatically logged and sent to a central Log Analytics workspace. Which Azure feature should you use?

A.Diagnostic settings on the Azure Activity Log
B.Azure Policy
C.NSG flow logs
D.Azure Monitor alerts
AnswerA

Diagnostic settings on the Azure Activity Log are the correct mechanism because the Activity Log itself records every control-plane operation—such as resource creation, deletion, and configuration changes—for your Azure resources. By configuring a diagnostic setting on this log, you can stream those management events directly into a Log Analytics workspace, enabling centralized querying, alerting, and long-term retention for security auditing. This is the built-in, supported way to capture and route resource-level change activity to your security monitoring pipeline.

Why this answer

Diagnostic settings on the Azure Activity Log capture all control-plane operations, including changes to NSGs (e.g., rule additions or deletions). By configuring a diagnostic setting to stream the Activity Log to a Log Analytics workspace, you ensure that every NSG modification is automatically logged and centralized for monitoring and alerting.

Exam trap

The trap here is confusing NSG flow logs (which log network traffic) with the Activity Log (which logs configuration changes), leading candidates to select NSG flow logs instead of diagnostic settings on the Activity Log.

How to eliminate wrong answers

Option B (Azure Policy) is wrong because Azure Policy enforces compliance rules (e.g., preventing NSG changes that allow all inbound traffic) but does not automatically log changes; it can trigger remediation but not send logs to Log Analytics. Option C (NSG flow logs) is wrong because NSG flow logs capture IP traffic data (source/destination, ports, protocols) through the NSG, not configuration changes to the NSG itself. Option D (Azure Monitor alerts) is wrong because alerts are reactive notifications based on log data or metrics; they do not capture or forward logs themselves.

62
MCQeasy

A company is moving to a zero-trust security model. Which principle is most important for securing network traffic?

A.Rely on perimeter firewalls to block threats
B.Verify explicitly every access request
C.Trust all traffic within the corporate network
D.Allow all traffic and monitor for anomalies
AnswerB

In a zero-trust model, network traffic is secured by enforcing conditional access policies that require real-time authentication and authorisation for every packet flow, rather than relying on implicit trust from network location. This satisfies the stem’s constraint of eliminating inherent trust by mandating explicit verification per request, typically implemented through Microsoft Entra ID’s continuous access evaluation and micro-segmentation rules.

Why this answer

In a zero-trust model, the principle of 'verify explicitly' means every access request—regardless of source—must be authenticated, authorized, and encrypted before being allowed. This eliminates implicit trust based on network location, which is the core shift from traditional perimeter-based security.

Exam trap

The trap here is that candidates often confuse zero-trust with traditional defense-in-depth, mistakenly thinking perimeter firewalls or anomaly detection are sufficient, when the exam specifically tests the 'verify explicitly' principle as the foundational requirement for zero-trust network traffic.

How to eliminate wrong answers

Option A is wrong because relying solely on perimeter firewalls assumes a trusted internal network, which violates zero-trust's 'never trust, always verify' mandate; threats can originate from inside the network. Option C is wrong because trusting all traffic within the corporate network is the opposite of zero-trust; it ignores lateral movement risks and assumes internal traffic is safe, which is a common attack vector. Option D is wrong because allowing all traffic and monitoring for anomalies is a detect-and-respond approach, not a prevent-and-verify one; zero-trust requires explicit denial by default and only allowing traffic after verification, not passive monitoring.

63
MCQmedium

Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to design a solution to detect brute-force attacks against Azure virtual machines. The solution should use Azure Activity Logs and Windows Security Events. What should you configure in Sentinel?

A.Create a threat intelligence watchlist
B.Create a workbook
C.Create a scheduled analytics rule
D.Create a playbook
AnswerC

A scheduled analytics rule is the core detection primitive in Microsoft Sentinel. It defines a KQL query, a query frequency (how often to run), a lookback period (how much historical data to examine), and an alert threshold or result condition. When the query returns results on the schedule, the rule creates a security alert, optionally with entity mapping for investigation and automated responses. This is precisely the mechanism Sentinel uses for always-on, time-based threat detection across your workspace.

Why this answer

Sentinel can ingest Azure Activity Logs and Windows Events, and then use analytics rules to detect brute-force patterns. Option A is wrong because watchlists are for reference data, not detection logic. Option B is wrong because workbooks visualize data, not detect.

Option D is wrong because playbooks automate responses, not detect.

64
Multi-Selecthard

Your organization uses Microsoft Purview to protect sensitive data. You need to implement a solution that automatically detects and protects personally identifiable information (PII) in Microsoft 365. Which THREE should be part of your solution? (Choose THREE.)

Select 3 answers
A.Azure Policy
B.Microsoft Defender for Cloud
C.Microsoft Purview Information Protection scanner
D.Microsoft Purview Data Loss Prevention (DLP) policies
E.Sensitivity labels in Microsoft Purview Information Protection
AnswersC, D, E

The Microsoft Purview Information Protection scanner is a forensic data-discovery engine that runs on Windows Server and scans on-premises repositories, including file shares, SharePoint Server, and SQL Server, for sensitive content. Using built-in or custom sensitive information types, it detects PII such as passport numbers, addresses, and bank details, and can automatically apply sensitivity labels via the same label administration used across Microsoft 365. It supports both discover-and-report and enforce modes, and its results feed into analytics and DLP policy evaluation. This makes it a correct choice because it directly scans content and applies protection at the data source.

Why this answer

Sensitivity labels in Microsoft Purview Information Protection (E) are the core classification mechanism that lets you tag content containing PII so protection (encryption, marking, access restrictions) travels with the data across Microsoft 365 workloads. Microsoft Purview Data Loss Prevention (DLP) policies (D) automatically detect PII using sensitive information types and then block, warn, or audit risky sharing in Exchange Online, SharePoint, OneDrive, Teams, and endpoint locations. The Microsoft Purview Information Protection scanner (C) extends that same labeling and protection to on-premises file shares and SharePoint Server repositories, which is required for a complete PII detection and protection solution.

Azure Policy (A) governs Azure resource compliance and cannot classify or protect PII in Microsoft 365 content, and Microsoft Defender for Cloud (B) is a cloud security posture and workload protection service, not a data classification or DLP tool for Microsoft 365 PII.

65
MCQeasy

You are designing a security operations strategy for Microsoft 365. You need to prioritize alerts from Microsoft Defender XDR based on their impact on business operations. Which security best practice should you follow?

A.Prioritize alerts based on a risk assessment that considers asset criticality, threat severity, and business impact
B.Prioritize alerts based on a qualitative risk assessment only
C.Treat all alerts with equal severity to ensure none are missed
D.Prioritize alerts based solely on the MITRE ATT&CK technique involved
AnswerA

Risk-based prioritization that scores asset criticality, threat severity, and business impact is the industry-standard approach because it translates raw signals into actionable decisions aligned with organizational value. By quantifying each alert's potential damage against the importance of the affected system, security operations teams can focus containment and investigation resources on events most likely to cause significant harm. This method also supports continuous improvement by allowing thresholds to be tuned based on telemetry and incident outcomes.

Why this answer

Microsoft Defender XDR integrates with Microsoft 365 Defender's risk-based alert prioritization, which uses a combination of asset criticality (e.g., from Microsoft Purview or Defender for Cloud Apps), threat severity (e.g., from the Microsoft Defender portal's alert severity levels: Informational, Low, Medium, High), and business impact (e.g., via sensitivity labels or data classification). This aligns with the security best practice of risk-based alert triage, ensuring that high-impact alerts are addressed first to minimize business disruption.

Exam trap

The trap here is that candidates may choose Option D because MITRE ATT&CK is a common framework in security operations, but they overlook that Microsoft Defender XDR's prioritization engine uses a multi-faceted risk assessment (including asset criticality and business impact) rather than a single technique-based filter.

How to eliminate wrong answers

Option B is wrong because a qualitative risk assessment alone lacks the quantitative data (e.g., asset criticality scores, threat severity levels) that Microsoft Defender XDR uses to dynamically prioritize alerts, leading to subjective and inconsistent triage. Option C is wrong because treating all alerts with equal severity ignores the risk-based prioritization built into Microsoft Defender XDR, which uses machine learning and threat intelligence to assign different severity levels (e.g., High, Medium, Low) and would overwhelm security operations with noise. Option D is wrong because prioritizing solely on the MITRE ATT&CK technique ignores asset criticality and business impact; for example, a low-severity technique on a critical server may be more impactful than a high-severity technique on a non-critical endpoint, and Microsoft Defender XDR's alert enrichment includes asset context beyond just the technique.

66
MCQeasy

A company is adopting Microsoft Purview for data security. They need to prevent users from sharing sensitive data like credit card numbers via email. Which feature should you configure?

A.Audit log search
B.Data Loss Prevention (DLP) policy
C.Insider Risk Management policy
D.Sensitivity labels
AnswerB

Data Loss Prevention (DLP) policies in Microsoft Purview are the correct inline control to block sharing of sensitive information. They use built-in sensitive info types (e.g., credit card numbers, personally identifiable information) and trainable classifiers to evaluate content in real time, then enforce actions such as 'Block' with the option to allow overrides for Exchange, SharePoint, OneDrive, and endpoints. By applying conditions like 'sharing with people outside the organization,' DLP can prevent the sharing action before any data leaves the tenant, making it the only option here that directly provides ex-ante prevention rather than detection or classification.

Why this answer

Data Loss Prevention (DLP) policies in Microsoft Purview are specifically designed to detect and prevent the accidental or intentional sharing of sensitive information, such as credit card numbers, through email and other channels. By configuring a DLP policy with a rule that scans for credit card number patterns (using predefined or custom sensitive info types), the system can block, quarantine, or notify users when such data is sent via Exchange Online. This directly addresses the requirement to prevent sharing sensitive data via email.

Exam trap

The trap here is that candidates often confuse Sensitivity labels as a direct replacement for DLP, but labels are for classification and protection (e.g., encryption), not for real-time content inspection and blocking of specific data patterns like credit card numbers in email.

How to eliminate wrong answers

Option A is wrong because Audit log search is a forensic tool for reviewing past activities, not a preventive control that blocks data sharing in real time. Option C is wrong because Insider Risk Management policies focus on identifying and investigating risky user behaviors (e.g., data exfiltration patterns) rather than enforcing content-based restrictions on outbound email. Option D is wrong because Sensitivity labels classify and protect data through encryption and visual markings, but they do not inherently block the transmission of specific sensitive data types like credit card numbers via email without being combined with a DLP policy.

67
MCQeasy

Tailwind Traders is a small business that uses Microsoft 365 Business Premium. They have no dedicated IT staff. The owner wants to implement basic security measures to protect against common threats like phishing, ransomware, and unauthorized access. They need a simple, cost-effective solution that aligns with Microsoft's security best practices for small businesses. Which set of actions should you recommend?

A.Implement Privileged Identity Management (PIM) for all accounts. Use Azure Information Protection to classify all emails. Set up a SIEM using Microsoft Sentinel.
B.Deploy Microsoft Intune to manage devices. Configure Conditional Access policies to require compliant devices. Use Microsoft Defender for Endpoint for antivirus. Set up a VPN for remote access.
C.Purchase Azure AD Premium P2 for all users. Use Identity Protection to detect risks. Configure Conditional Access with session controls. Use Azure AD Identity Governance for access reviews.
D.Enable Security Defaults in Microsoft Entra ID to enforce MFA for all users. Configure Microsoft Defender for Office 365 to protect against phishing and malware. Use Microsoft Defender for Business (included) for endpoint protection. Regularly review the Microsoft 365 Secure Score and implement top recommendations.
AnswerD

Security Defaults in Microsoft Entra ID automatically enforce MFA for all users and block legacy authentication, providing a strong baseline without extra licensing or complex policy setup. Defender for Office 365 protects against phishing, malware, and malicious links in email, which is critical for small businesses that rely heavily on email communication. Defender for Business is included in Microsoft 365 Business plans and provides managed endpoint protection tailored to smaller organizations. Regularly reviewing the Secure Score helps prioritize low-effort, high-impact security improvements that align with the business's actual risk profile.

Why this answer

It aligns with Microsoft's security best practices for small businesses with no dedicated IT staff. Security Defaults in Microsoft Entra ID provide a baseline of MFA enforcement without requiring complex configuration. Microsoft Defender for Office 365 and Defender for Business (included in Microsoft 365 Business Premium) offer integrated phishing, malware, and endpoint protection.

Regularly reviewing the Secure Score ensures continuous improvement against common threats like ransomware and unauthorized access.

Exam trap

The trap here is that candidates often over-engineer the solution by selecting advanced identity or endpoint management options (like PIM, Intune, or Azure AD Premium P2) that are technically valid but inappropriate for a small business with no IT staff, ignoring the cost and complexity constraints explicitly stated in the scenario.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) requires Azure AD Premium P2 licensing, which is not included in Microsoft 365 Business Premium and adds unnecessary complexity for a small business with no IT staff; Azure Information Protection and Microsoft Sentinel are also overkill and not cost-effective. Option B is wrong because Microsoft Intune requires additional licensing beyond Business Premium and managing device compliance via Conditional Access policies demands dedicated IT expertise; a VPN is not a core security control for phishing or ransomware and adds complexity. Option C is wrong because Azure AD Premium P2 for all users is expensive and unnecessary for a small business; Identity Protection and Identity Governance are advanced features designed for larger enterprises with dedicated identity teams, not a simple, cost-effective baseline.

68
MCQeasy

Your organization needs to monitor and respond to threats across email, endpoints, and identities. Which Microsoft solution provides a unified incident response experience?

A.Microsoft Purview
B.Microsoft Intune
C.Microsoft Defender XDR
D.Microsoft Sentinel
AnswerC

Microsoft Defender XDR unifies signals across the Microsoft 365 ecosystem—Defender for Endpoint, Office 365, Identity, and Cloud Apps—into a single incident queue with automated investigation and response. It correlates kill-chain events across domains, enabling security teams to monitor and respond to threats holistically. This cross-domain correlation and built-in response automation are exactly what is required for organization-wide threat monitoring and response.

Why this answer

Microsoft Defender XDR (Extended Detection and Response) is the correct choice because it provides a unified incident response experience by correlating alerts and signals from email (Defender for Office 365), endpoints (Defender for Endpoint), and identities (Defender for Identity) into a single incident queue. This cross-domain correlation enables security teams to investigate and remediate complex multi-stage attacks from a single pane of glass, rather than switching between separate consoles.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with Microsoft Defender XDR (an XDR), but Sentinel ingests logs and requires manual or KQL-based correlation, while Defender XDR provides automatic cross-domain incident correlation out of the box for Microsoft security signals.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview is a compliance and data governance solution focused on data classification, retention, and eDiscovery, not on real-time threat detection or incident response across email, endpoints, and identities. Option B is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service for managing devices and apps, not a security operations tool for monitoring and responding to threats. Option D is wrong because Microsoft Sentinel is a cloud-native SIEM (Security Information and Event Management) that ingests logs from multiple sources and provides advanced analytics, but it does not natively unify incident response across Microsoft 365 security products; it requires separate data connectors and custom correlation rules to achieve similar cross-domain visibility.

69
MCQmedium

A company uses Microsoft Intune to manage devices. They need to ensure that only devices with a minimum OS version can access corporate email. Which policy type should they implement?

A.Device enrollment restrictions
B.App protection policies
C.Compliance policies combined with conditional access
D.Device configuration profiles
AnswerC

A compliance policy in Intune evaluates a device's health attributes—including whether its OS version meets the minimum required for that platform—and simply marks the device compliant or non-compliant. That compliance status is then consumed by a Conditional Access policy as a grant control, which, at the time of every authentication request, rejects access for non-compliant devices (or requires additional steps like re-enrollment or OS update). This combination is the actual enforcement chain: the compliance policy identifies the OS-version gap, and Conditional Access blocks the user's access accordingly.

Why this answer

The correct answer is C: Compliance policies combined with conditional access. Compliance policies in Intune define the required conditions a device must meet, such as a minimum OS version, and conditional access in Entra ID enforces those requirements by blocking access to corporate email (for example, Exchange Online) when the device is noncompliant. This combination is the standard way to gate email access on OS version.

Device enrollment restrictions (A) only control which devices can enroll or which platforms are allowed, not ongoing OS-version-based access to email. App protection policies (B) protect app data with PINs and encryption but do not enforce a minimum OS version for email access. Device configuration profiles (D) configure settings on devices but do not by themselves block email access based on compliance.

70
Multi-Selecteasy

Your organization uses Microsoft Purview Information Protection to label sensitive emails. You need to ensure that labels are applied automatically based on content. Which THREE methods can you use?

Select 3 answers
A.Manual labeling by users
B.File plan (for records management)
C.Sensitive information types
D.Auto-labeling policies in Microsoft Purview
E.Trainable classifiers
AnswersC, D, E

Sensitive information types detect content patterns such as credit card or national insurance numbers, so Microsoft Purview Information Protection can auto-apply labels without user input. This satisfies the requirement for automatic, content-based labelling rather than manual or default labelling.

Why this answer

Sensitive information types (C) are predefined or custom patterns that detect sensitive data such as credit card numbers or social security numbers, enabling automatic label application. Auto-labeling policies in Microsoft Purview (D) apply labels automatically to emails and files based on conditions like sensitive information types or trainable classifiers. Trainable classifiers (E) use machine learning to identify content patterns and automatically apply labels without requiring explicit pattern definitions.

Exam trap

The trap here is that candidates may confuse manual labeling or records management tools (like file plans) with automatic content-based labeling mechanisms, but only sensitive information types, auto-labeling policies, and trainable classifiers directly support automatic label application based on content analysis.

71
MCQeasy

You are designing identity security for a hybrid organization using Microsoft Entra ID. You need to enforce multi-factor authentication (MFA) for all users accessing sensitive applications. What is the recommended approach?

A.Create a Conditional Access policy that requires MFA for the sensitive applications
B.Enable Security defaults
C.Enable per-user MFA in Entra ID
D.Use Azure AD Identity Protection user risk policy
AnswerA

A Conditional Access policy is the correct approach because it uses application-based conditions to require MFA selectively for sensitive apps while allowing other apps to use less restrictive authentication. In a hybrid environment, this integrates with on-premises applications via Azure AD Application Proxy or federated trusts, and supports session controls like sign-in frequency. This granularity aligns with the Zero Trust principle of least privilege, unlike tenant-wide or user-wide MFA enforcement.

Why this answer

Conditional Access policies in Entra ID are the recommended method to require MFA for specific applications. The other options are less granular or outdated: per-user MFA is legacy, Security defaults apply to all apps and cannot be scoped, and Azure AD Identity Protection focuses on risk-based policies.

72
MCQmedium

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that devices must have a minimum OS version and cannot be jailbroken. Which configuration profile type should you assign?

A.Device configuration policy.
B.Device restrictions profile.
C.Enrollment restriction.
D.Compliance policy.
AnswerD

Intune Device Compliance policies for iOS/iPadOS evaluate a device against rules such as minimum OS version, jailbreak/root detection, and required encryption to determine a compliant or non-compliant state. This assessment runs on an ongoing basis (check-in) and integrates directly with Conditional Access for blocking access to cloud resources until compliant. That's why a compliance policy is the correct choice for assessing conditions like minimum OS version and jailbreak status.

Why this answer

A compliance policy (option D) is the correct choice because Intune compliance policies are specifically designed to evaluate device health and posture, including defining a minimum OS version for iOS/iPadOS and detecting jailbroken devices via the device compliance check. When a device fails these conditions, it is marked noncompliant, which can then drive Conditional Access or other remediation actions. Device configuration policies (A) and device restrictions profiles (B) push settings to devices but do not evaluate jailbreak status or enforce a minimum OS version as a compliance condition.

Enrollment restrictions (C) only control which devices or platforms are allowed to enroll, not the ongoing OS version or jailbreak state of already-enrolled devices.

73
Multi-Selectmedium

Which TWO actions should you take to implement a zero-trust identity strategy in Microsoft Entra ID?

Select 2 answers
A.Enable single sign-on for all applications
B.Require multi-factor authentication for all users
C.Implement passwordless authentication for all users
D.Synchronize all on-premises identities to the cloud
E.Configure Conditional Access policies based on user risk and device compliance
AnswersB, E

Requiring multi-factor authentication for all users directly enforces the zero-trust principle of verify explicitly, ensuring every sign-in is validated rather than trusted by network location. It satisfies the stem's identity-strategy constraint by adding a possession factor to credentials, blocking compromised-password attacks that single-factor authentication would otherwise permit.

Why this answer

Option B is correct because requiring multi-factor authentication (MFA) for all users is a foundational zero-trust control in Microsoft Entra ID: it enforces verification of identity beyond a password, directly supporting the 'verify explicitly' principle and reducing the risk of credential compromise. Option E is correct because Conditional Access policies that evaluate signals such as user risk (via Entra ID Protection) and device compliance (via Intune) implement adaptive, context-aware access decisions, which is the core enforcement mechanism of a zero-trust identity strategy. Options A, C, and D are not the required actions: enabling single sign-on (A) improves user experience but does not itself verify identity or enforce least-privilege access; passwordless authentication (C) is a strong phishing-resistant method but is not mandatory for zero trust and can be a subset of MFA strategy; and synchronizing on-premises identities (D) via Entra Connect extends identity reach but does not by itself enforce zero-trust verification or policy-based access.

Exam trap

SC-100 often tests the difference between identity hygiene features (SSO, passwordless, directory sync) and actual zero-trust enforcement controls (MFA and risk-based Conditional Access), and candidates who pick SSO or sync as zero-trust actions fall for the distractor.

74
MCQhard

Refer to the exhibit. You are deploying this Bicep template to enable Microsoft Defender for Cloud's VM protection. After deployment, you notice that Agentless VM scanning is not enabled for existing VMs. What is the most likely reason?

A.The pricing tier must be 'Free' to enable agentless scanning.
B.Agentless scanning is only enabled for new VMs; existing VMs require rescanning.
C.The resource name 'VirtualMachines' is incorrect; it should be 'virtualMachines'.
D.The extension 'AgentlessVmScanning' must be defined outside the pricing resource.
AnswerD

The 'AgentlessVmScanning' extension cannot be declared as a child property of the Microsoft.Security/pricings resource. In Azure Resource Manager (ARM) and Bicep, agentless scanning for virtual machines is enabled by defining a separate resource of type Microsoft.Security/vmScanners, which holds the scanner configuration such as 'scanningMode' and exclusion tags. Attempting to place it within the pricing resource's properties.extensions array will cause a validation error because that extension is not a valid member of the pricing schema. Therefore, the deployment fails unless the extension is moved to its own top-level resource definition.

Why this answer

The 'AgentlessVmScanning' extension is not a valid sub-resource of the pricing resource. In Bicep, agentless VM scanning is configured via a separate 'Microsoft.Security/vmScanners' resource, not nested inside the pricing resource. Defining it inside the pricing resource would cause a configuration error, resulting in agentless scanning not being enabled.

Option B is incorrect: agentless scanning is automatically enabled for all existing and new VMs when the plan is enabled; existing VMs do not require manual rescanning.

75
MCQeasy

Your organization needs to audit all changes to Azure resources, including who made the change and what was changed. Which Azure service should you use to collect and analyze this audit data?

A.Azure Policy
B.Azure Monitor with activity logs
C.Microsoft Defender for Cloud
D.Microsoft Sentinel
AnswerB

The Azure Activity Log records every control-plane write operation (create, update, delete) on Azure resources, including the caller identity, timestamp, operation name, and resource ID—precisely the data required for change auditing. Azure Monitor provides a unified platform to query and analyze these logs via Log Analytics, configure alerts on specific changes, and export them to storage or event hubs for retention. This combination yields a comprehensive, queryable audit trail of all resource modifications, making it the correct foundational service for auditing every change to Azure resources.

Why this answer

Azure Monitor with activity logs is the correct service because it captures all control-plane operations on Azure resources, including who performed the change (via Azure Active Directory authentication), what was changed (the resource and properties), and when it occurred. Activity logs are retained for 90 days by default and can be exported to Log Analytics workspaces for advanced querying and alerting, making them the native audit trail for Azure resource modifications.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel as the audit service because it is a SIEM, but Sentinel ingests logs from other sources (including activity logs) and is not the native collection mechanism; the question specifically asks for the service that collects and analyzes the audit data, which is Azure Monitor with activity logs.

How to eliminate wrong answers

Option A is wrong because Azure Policy is a governance tool that enforces compliance rules on resources (e.g., requiring specific tags or denying certain SKUs) and does not natively log who made changes or what was changed; it evaluates resource configurations against policies but does not provide an audit trail of modifications. Option C is wrong because Microsoft Defender for Cloud focuses on security posture management, threat detection, and vulnerability assessments, not on auditing all resource changes; it uses activity logs for some security alerts but is not designed as a primary audit log service. Option D is wrong because Microsoft Sentinel is a SIEM (Security Information and Event Management) solution that ingests logs from multiple sources, including activity logs, but it is not the service that collects the audit data itself; the underlying source for resource change auditing remains Azure Monitor activity logs.

Page 1 of 9

Page 2

All pages