Courseiva

Microsoft Cybersecurity Architect (SC-100) — Questions 226–300

605 questions total · 9pages · All types, answers revealed

Page 3

Page 4 of 9

Page 5
226
MCQeasy

Your company uses Microsoft 365 E5 licenses and has deployed Microsoft Defender for Office 365. The security team wants to be alerted when a user reports a phishing email using the built-in report message button in Outlook. The alert should be sent to the security team's email address. You need to configure this in the Microsoft 365 Defender portal. What should you do?

A.Create an anti-phishing policy that notifies users about phishing.
B.Configure the User reported messages settings to send alerts to the security team.
C.Create a Safe Attachments policy to detect phishing attachments.
D.Create a Safe Links policy that alerts on phishing URLs.
AnswerB

The User reported messages settings in the Microsoft 365 Defender portal (under Email & collaboration > Policies & rules > Threat policies) let you specify where messages reported by users via Outlook, Outlook on the web, or the built-in Report Message button are sent. You can direct these submissions to an internal mailbox, Microsoft, or both, and configure alert notifications so the security team is immediately informed when a user submits a message. This directly satisfies the requirement to make reports visible and actionable.

Why this answer

The correct option is B: configure the User reported messages settings to send alerts to the security team. In the Microsoft 365 Defender portal, under Email & collaboration > Policies & rules > Threat policies > User reported messages, you can specify a reporting mailbox and enable notifications so that when a user reports a phishing message via the built-in Report Message/Report Phishing add-in, the security team is alerted. This directly addresses the requirement to alert the security team when a user reports a phishing email.

Options A, C, and D do not fit: anti-phishing policies control impersonation and spoofing protections and user tips, while Safe Attachments and Safe Links policies detonate attachments and rewrite/scan URLs at delivery and click time, respectively, and none of them trigger an alert based on a user's manual report.

227
MCQhard

Your organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft Teams. You need to prevent users from sharing credit card numbers in Teams chat messages. However, the policy should allow sharing with external vendors if they are in your organization's approved list. What should you configure?

A.Configure a DLP policy with a condition to block sharing of credit card numbers to external users except those from approved domains.
B.Create a DLP policy that blocks credit card numbers and set the action to 'Block external sharing' for all external users.
C.Use Microsoft Purview Information Protection to automatically apply a 'Confidential' label to messages containing credit card numbers and block forwarding.
D.Create a sensitivity label for credit card data and publish it to Teams, then configure auto-labeling.
AnswerA

A DLP policy lets you combine the sensitive info type condition (credit card numbers) with 'External sharing' and then use the action 'Restrict access to external users' to specify an allowed domain list via the 'Only people in domains on your approved list' option. This grants exceptions to approved external vendors while any other external recipient is blocked, exactly matching the requirement.

Why this answer

You can configure a DLP policy in Microsoft Purview to block sensitive data like credit card numbers in Teams messages, and use the 'Block sharing to external users except' condition to allow sharing with approved domains. This meets the requirement to prevent sharing with unauthorized external users while allowing sharing with approved vendors. Option B is wrong because blocking all external sharing is too restrictive and does not allow the approved external vendors.

Option C is wrong because Information Protection labels do not have the granular control over sharing conditions based on external domains. Option D is wrong because sensitivity labels are not designed for DLP actions such as blocking sharing in Teams chat based on external approval.

228
Multi-Selecthard

A company is implementing a Zero Trust security model using Microsoft 365 Defender. Which THREE of the following are key principles they should follow?

Select 3 answers
A.Trust all traffic originating from within the corporate network.
B.Use least privilege access by limiting user permissions with Just-In-Time and Just-Enough-Access.
C.Provide implicit trust to known users and devices.
D.Assume breach and segment access to minimize blast radius.
E.Verify explicitly based on all available data points (user, device, location, etc.).
AnswersB, D, E

Least privilege with Just-In-Time and Just-Enough-Access limits standing permissions, granting elevated rights only when needed and for the minimum scope. This satisfies Zero Trust's explicit-verification and assume-breach principles by shrinking the persistent attack surface available to compromised identities.

Why this answer

Option B is correct because Zero Trust requires least privilege access, and Microsoft recommends Just-In-Time (JIT) and Just-Enough-Access (JEA) with Privileged Identity Management (PIM) to grant permissions only when needed and only for the required scope. Option D is correct because the 'assume breach' principle means designing as if attackers are already present, using micro-segmentation, network segmentation, and conditional access to limit lateral movement and reduce blast radius. Option E is correct because 'verify explicitly' is the foundational Zero Trust principle: every access request must be authenticated and authorized using all available signals such as user identity, device compliance, location, and risk level via Conditional Access and Microsoft 365 Defender signals.

Option A is incorrect because trusting all traffic from the corporate network is the traditional perimeter-based model that Zero Trust explicitly rejects; internal networks are not inherently trusted. Option C is incorrect because implicit trust for known users or devices contradicts Zero Trust, which requires continuous verification rather than granting trust based on prior knowledge or network location.

Exam trap

The trap here is that candidates often confuse Zero Trust with traditional perimeter-based security, mistakenly believing that internal network origin or known user status should be trusted implicitly, when in fact Zero Trust requires explicit verification for every access request regardless of source.

229
MCQeasy

You are designing an incident response plan for a company using Microsoft Defender XDR. The team needs to automatically notify the SOC via email when an incident of high severity is created. What should you use?

A.Modify the analytics rule to send an email when an alert fires.
B.Create a playbook that sends an email when an incident is created.
C.Configure an automation rule with an action to send an email notification.
D.Use advanced hunting to query high severity incidents and send email.
AnswerC

Configuring an automation rule with an action to send an email notification is the correct approach in Microsoft Sentinel for alerting on incident creation. Automation rules are specifically designed to handle incident lifecycle events (created, updated, etc.) and can perform one or more actions immediately, without needing an external logic app. The 'Send Email' action directly sends an email to a specified recipient, using configured SMTP or Microsoft 365 settings, and can include incident details in the body. This method is natively supported, requires minimal setup, and ensures timely notification whenever an incident meets the condition (e.g., high severity).

Why this answer

Automation rules in Microsoft Defender XDR are specifically designed to trigger automated actions—including sending email notifications—when an incident is created or updated. Unlike playbooks, automation rules can directly send email without requiring a Logic Apps connector, and they operate natively within the Defender portal's incident lifecycle.

Exam trap

The trap here is that candidates often confuse Microsoft Defender XDR automation rules with Microsoft Sentinel playbooks or analytics rules, assuming that playbooks are the only way to send email, when in fact Defender XDR has a built-in email notification action within automation rules.

How to eliminate wrong answers

Option A is wrong because analytics rules are used in Microsoft Sentinel, not Microsoft Defender XDR; Defender XDR uses detection rules, and modifying an analytics rule would not apply to Defender incidents. Option B is wrong because a playbook (Logic Apps) can send email but requires additional configuration and licensing, and is not the simplest or most direct method for email notification on incident creation. Option D is wrong because advanced hunting is a query tool for threat hunting and does not have native capabilities to automatically send email notifications; it would require custom scripting and external integration.

230
MCQeasy

Your organization uses Microsoft 365 and wants to prevent users from sharing sensitive documents externally via email. The solution must be able to detect credit card numbers and automatically block the email. Which technology should you use?

A.Microsoft Purview Sensitivity labels with auto-classification
B.Microsoft Defender for Office 365 Safe Attachments
C.Microsoft Purview Data Loss Prevention (DLP) policy for Exchange Online
D.Azure Information Protection (AIP) unified labeling client
AnswerC

A Microsoft Purview Data Loss Prevention (DLP) policy for Exchange Online is the only option that directly inspects email in transit for sensitive info types (e.g., PII, PCI, healthcare records) and applies actions like 'Reject the message', 'Encrypt', or 'Notify the sender' by leveraging Exchange mail flow rules. When a sensitive data match occurs, the policy can block the email from leaving the tenant, redirect it to a reviewer, or block only if the amount exceeds a threshold. This is precisely the protection needed to 'prevent us' from leaking data via email.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policy for Exchange Online is the correct choice because DLP is purpose-built to inspect email content in transit and detect sensitive information types such as credit card numbers, then automatically block or restrict the message per policy actions. It natively integrates with Exchange Online so detection and blocking happen at the mail-flow level without user intervention. Sensitivity labels with auto-classification apply classification and protection to content but do not themselves block an email from being sent externally based on credit card detection.

Safe Attachments focuses on malware detonation in attachments, not on detecting sensitive data patterns, and the AIP unified labeling client is a client-side labeling tool rather than a server-side email blocking control.

231
MCQmedium

A company uses Microsoft Defender for Cloud Apps to enforce session policies. The security team needs to block downloads of sensitive files from Microsoft 365 when accessed from unmanaged devices. Which type of policy should they configure?

A.File policy
B.Data Loss Prevention (DLP) policy in Microsoft 365
C.Session policy
D.Access policy
AnswerC

A session policy in Defender for Cloud Apps enforces real-time controls on user activities inside a cloud app by using Conditional Access App Control as a reverse proxy. When a user accesses a SaaS app from an unmanaged device, the proxy intercepts traffic and can apply actions such as blocking download, masking sensitive content, or restricting uploads based on the session's risk posture. This provides granular just-in-time enforcement at the session level, which is exactly what is needed to enforce controls in real time.

Why this answer

The correct answer is C, Session policy. In Microsoft Defender for Cloud Apps, session policies are used with Conditional Access App Control to monitor and control user sessions in real time, including blocking downloads of sensitive files from Microsoft 365 when accessed from unmanaged devices. This is the specific policy type designed for session-based enforcement, such as blocking downloads, uploads, or copy/paste actions during an active session.

A file policy (A) applies to files in connected cloud apps for governance and alerting but does not control live session actions like downloads from unmanaged devices. A DLP policy in Microsoft 365 (B) enforces data protection within Microsoft 365 workloads but does not provide the same session proxy-based control for unmanaged device access. An access policy (D) in Defender for Cloud Apps is used to allow or block app access based on conditions, not to block downloads within an active session.

232
MCQhard

A company uses Microsoft Defender for Cloud to protect their hybrid environment. They have on-premises servers that are monitored by Microsoft Defender for Servers. The security team notices that some servers are missing critical security updates. They want to automatically remediate missing updates on these servers. Which feature should they enable?

A.Adaptive Application Controls
B.Azure Automation Update Management
C.Azure Update Manager
D.Just-in-Time (JIT) VM access
AnswerC

Azure Update Manager is the current, first-party service for overseeing and applying OS updates across Azure VMs, on-premises servers, and machines in other cloud environments. It directly integrates with Defender for Cloud: the security recommendation 'Machines should have security updates installed' can be remediated using Azure Update Manager to establish a schedule or trigger immediate patching of non-compliant resources. This native integration makes it the appropriate tool for automatically remediating missing updates as part of a Defender for Cloud workflow.

Why this answer

Azure Update Manager (option C) is the correct choice because it is the native Azure service designed to assess and automatically remediate missing OS security updates across Azure, on-premises, and multicloud servers, including those onboarded to Microsoft Defender for Servers. It provides update assessment, scheduling, and automatic patching for Windows and Linux machines, which directly addresses the team's need to remediate missing updates on their hybrid servers. Adaptive Application Controls (option A) only create allowlist/denylist rules for applications to control execution and do not patch operating systems.

Azure Automation Update Management (option B) is the legacy predecessor that has been superseded by Azure Update Manager, so it is not the recommended feature. Just-in-Time VM access (option D) only restricts inbound management ports on VMs and has nothing to do with update remediation.

233
MCQhard

Refer to the exhibit. You run the PowerShell command against an Azure SQL Database. The command returns a baseline object for rule VA2108. What does this indicate about the database's vulnerability assessment configuration?

A.The vulnerability assessment scan is automatically remediating findings for rule VA2108
B.The security team has approved the current state of rule VA2108 as acceptable
C.Vulnerability assessment is disabled for this database
D.The database has no vulnerability findings
AnswerB

When you set a baseline, you are formally recording the security team's decision that the current state of the rule is an accepted risk. The PowerShell cmdlet stores the current scan result for VA2108 as the expected baseline for future scans, so any deviation from this approved configuration would be flagged. It is a governance process of waiver approval, not a technical remediation.

Why this answer

The correct answer is B: the security team has approved the current state of rule VA2108 as acceptable. In Azure SQL Database vulnerability assessment, a baseline object returned for a rule such as VA2108 means a baseline has been set for that rule, which records the current scan results as the accepted/approved state so those results are no longer flagged as findings. It does not mean automatic remediation is occurring, so A is wrong; vulnerability assessment being disabled would prevent baseline objects from being returned, so C is wrong; and a baseline does not mean there are no findings, only that the baselined results are treated as acceptable, so D is wrong.

234
Multi-Selectmedium

Your organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft 365. You need to create a DLP policy that detects and blocks sharing of credit card numbers in Exchange Online emails. Which TWO components must you configure?

Select 2 answers
A.Retention label for financial data
B.Auto-labeling policy
C.Action to block sharing
D.Sensitive info type for credit card number
E.Trainable classifier for credit card numbers
AnswersC, D

A DLP rule is incomplete without an action that defines the enforcement response. For an email containing credit card data, the 'Block' action (often configured as 'Block the message from being sent' or 'Block sharing externally') is the critical component that stops the data exfiltration, fulfilling the DLP policy's purpose. This action ensures that when the sensitive info type condition matches, the mail flow is interrupted and the sender is notified or the message is quarantined.

Why this answer

Option D is correct because a DLP policy must reference a sensitive information type (SIT) — in this case the built-in 'Credit Card Number' SIT — so Purview can detect the credit card patterns in Exchange Online email content. Option C is correct because detection alone does nothing; the policy rule must define an action such as 'Block' (or restrict access/encrypt) to prevent the credit card data from being shared via email. Option A is incorrect because retention labels govern data lifecycle and retention, not real-time blocking of sensitive data sharing.

Option B is incorrect because auto-labeling policies apply sensitivity labels to content and do not enforce DLP blocking actions. Option E is incorrect because trainable classifiers are used for custom content categories (e.g., resumes, contracts), not for detecting standardized numeric patterns like credit card numbers, which are handled by built-in SITs.

235
MCQmedium

A company uses Microsoft 365 and wants to protect sensitive documents from being shared externally. They need a solution that automatically classifies documents containing personally identifiable information (PII) and applies appropriate protection. Which two services should they combine?

A.Microsoft Defender for Cloud Apps and Microsoft Intune
B.Microsoft Purview Compliance Manager and Microsoft Sentinel
C.Azure Information Protection and Microsoft Entra ID
D.Microsoft Purview Information Protection and Data Loss Prevention (DLP)
AnswerD

Microsoft Purview Information Protection is the unified labeling engine that applies sensitivity labels to documents and emails, enabling persistent classification, encryption, and visual markings, while DLP policies inspect content and detect labeled data to enforce actions such as blocking external sharing or quarantining risky messages. These two services work symbiotically: labels drive policy decisions, and DLP can also use content patterns alongside labels to catch violations. This is the current recommended architecture for protecting sensitive information in Microsoft 365, with AIP's legacy functionality replaced by Purview.

Why this answer

Microsoft Purview Information Protection allows for classification and labeling of documents based on content, while Data Loss Prevention (DLP) policies can enforce actions such as blocking external sharing or applying encryption. Together, they provide automated protection for sensitive documents like those containing PII. Option D is correct because these two services work together to classify and protect documents.

Option A is incorrect because Microsoft Defender for Cloud Apps focuses on SaaS app security and Intune is for device management; they do not directly classify documents. Option B is incorrect because Compliance Manager is for managing compliance posture, and Sentinel is a SIEM; they are not used for automatic document classification. Option C is incorrect because Azure Information Protection is a previous version, now part of Purview, and Microsoft Entra ID is an identity service; they do not provide the same integrated classification and DLP capabilities as the Purview solutions.

236
MCQhard

A large enterprise is designing a secure infrastructure for a multi-region application deployment. They have a hub-spoke topology in two Azure regions (East US and West US) with VNet peering between the hubs. Each region has a shared services spoke containing Azure AD Domain Services (AAD DS) and management jump boxes. Application spokes in each region host VMs that need to authenticate to the local AAD DS. The company mandates that all traffic between regions must traverse a network virtual appliance (NVA) for inspection, except for Azure management traffic. They also require that all outbound internet traffic from application VMs goes through a single Azure Firewall in the East US hub. They have deployed ExpressRoute to on-premises. Currently, application VMs in West US cannot authenticate to the local AAD DS. What is the most likely cause?

A.The Azure Firewall in East US is not configured to allow traffic from West US to AAD DS.
B.The VNet peering between East and West US hubs is not properly configured with 'Allow forwarded traffic' enabled.
C.The ExpressRoute circuit is down, causing traffic to be routed over the internet.
D.The route table for the West US application spoke has a default route (0.0.0.0/0) pointing to the NVA, causing traffic to AAD DS to be sent across regions.
AnswerD

The route table on the West US application spoke's subnet contains a default route (0.0.0.0/0) that specifies the NVA as the next hop, overriding Azure's system default route. When the application resolves the AAD DS domain name, it receives a private IP address in the East US VNet, and because the default route matches all destinations, the traffic is sent to the NVA instead of being routed directly via the established VNet peering or hub. If the NVA is not configured to forward traffic to the East US region, or if it sends it over the internet or a different path, the traffic never reaches AAD DS while return traffic may arrive via a different route, causing asymmetric routing and session failures. The correct fix is to add a more specific route for the AAD DS IP range pointing to the East US hub or directly to the peered VNet, ensuring traffic stays within the Azure backbone and avoids the unintended NVA detour.

Why this answer

The most likely cause is that the route table for the West US application spoke has a default route (0.0.0.0/0) pointing to the NVA. This forces all outbound traffic, including traffic destined for the local AAD DS (which resides in the same region's shared services spoke), to be routed through the NVA and potentially across regions via the hub peering, rather than staying within the local VNet. Since AAD DS requires low-latency, direct connectivity within the same region, this misrouting prevents authentication.

Exam trap

The trap here is that candidates often assume the Azure Firewall or VNet peering is misconfigured, but the real issue is a routing override that forces local traffic through a non-local path, a classic 'asymmetric routing' or 'forced tunneling' pitfall in multi-region hub-spoke topologies.

How to eliminate wrong answers

Option A is wrong because the Azure Firewall in East US only inspects outbound internet traffic from application VMs; it does not handle intra-region traffic between West US application VMs and West US AAD DS, so its configuration is irrelevant to this issue. Option B is wrong because VNet peering between hubs is used for inter-region traffic, but the problem is that traffic is being forced across regions unnecessarily; the peering itself is likely functional, but the routing misdirects traffic. Option C is wrong because ExpressRoute is used for on-premises connectivity, not for Azure-to-Azure traffic between regions or within a region; its status does not affect local AAD DS authentication.

237
MCQhard

Your company uses Microsoft Azure to host a critical application that processes credit card payments. The application must comply with PCI DSS. You need to ensure that all access to cardholder data is logged and monitored, and that any unauthorized access attempts trigger an alert. Which combination of services should you use?

A.Azure Policy and Microsoft Defender for Cloud Apps
B.Azure Policy and Microsoft Defender for Cloud
C.Azure Key Vault and Microsoft Defender for Cloud
D.Azure Monitor and Microsoft Sentinel
AnswerD

Azure Monitor collects diagnostic logs, metrics, and activity data from Azure resources—such as App Service or virtual machines—into a Log Analytics workspace, forming the foundational telemetry pipeline for the critical application. Microsoft Sentinel then ingests those logs, uses built-in analytics rules and threat-intelligence correlation to detect suspicious behavior, and provides incident management and automated response (SOAR). This pairing directly satisfies the requirement to both log access/activity and alert on potential threats, making it the correct combination for detective security monitoring.

Why this answer

Azure Monitor and Microsoft Sentinel (option D) are the right combination because Azure Monitor collects and retains the logs and metrics from the application and its Azure resources, while Microsoft Sentinel ingests those logs to correlate events, detect unauthorized access attempts to cardholder data, and generate alerts via analytics rules and incident creation, satisfying PCI DSS logging and monitoring requirements. Azure Monitor provides the telemetry pipeline (Log Analytics workspace, diagnostic settings) and Sentinel adds SIEM/SOAR detection and alerting on top of it. Option A is wrong because Azure Policy enforces configuration compliance and Defender for Cloud Apps is a CASB for SaaS discovery/control, not a log-monitoring and alerting SIEM.

Option B is wrong because Azure Policy and Defender for Cloud provide posture management and threat protection but do not deliver the centralized log correlation and custom alerting on access to cardholder data that Sentinel does. Option C is wrong because Azure Key Vault only manages secrets, keys, and certificates, and Defender for Cloud alone does not provide the required log aggregation and alerting.

238
MCQmedium

Your organization uses Microsoft Entra ID. You need to design a solution that requires users to perform multifactor authentication when accessing a critical application from an untrusted network. The solution should not require additional licensing beyond Microsoft Entra ID P1. What should you use?

A.Create a Conditional Access policy in Microsoft Entra ID.
B.Configure a risk-based policy in Microsoft Entra ID Protection.
C.Enable per-user MFA in Microsoft Entra ID.
D.Deploy a device compliance policy in Microsoft Intune.
AnswerA

A Conditional Access policy is the modern, context-aware mechanism in Microsoft Entra ID for enforcing MFA. It can precisely target specified users, groups, or applications, and evaluate conditions such as geographic location (via named locations), trusted IPs, device state, and sign-in risk. Because Conditional Access is included with Entra ID P1, it directly satisfies the requirement to enforce MFA based on location without requiring any additional licensing.

Why this answer

The correct answer is A: Create a Conditional Access policy in Microsoft Entra ID. Conditional Access is included with Microsoft Entra ID P1 and lets you enforce MFA specifically when users access a chosen cloud app from an untrusted network location, using conditions such as the application and named locations plus a grant control requiring multifactor authentication. Option B is not the best fit because risk-based sign-in/user risk policies require Microsoft Entra ID P2 (Entra ID Protection), exceeding the stated P1 licensing limit.

Option C, per-user MFA, can require MFA but is an all-or-nothing setting that cannot target a specific application or network condition. Option D, an Intune device compliance policy, addresses device configuration and compliance rather than directly enforcing MFA for app access from untrusted networks.

Exam trap

The trap is that candidates might choose Microsoft Entra ID Protection (P2) because it seems more sophisticated, but the requirement is no additional licensing beyond P1, so Conditional Access with location condition is sufficient and included. Also candidates might confuse per-user MFA with Conditional Access.

239
MCQhard

Your organization uses Microsoft Defender XDR for detection and response. You need to create a custom detection rule that alerts when a user performs more than 10 failed sign-ins from different countries within 5 minutes. Which component should you use?

A.Automation rule in Microsoft Sentinel
B.Custom detection rule in Microsoft 365 Defender
C.Analytics rule in Microsoft Sentinel
D.Attack simulation training
AnswerB

Custom detection rules in Microsoft Defender XDR leverage Advanced Hunting Kusto Query Language (KQL) queries to continuously monitor event data across email, endpoints, identities, and cloud apps. When the query returns results, the rule triggers an alert and can also create an incident, enabling bespoke detection logic beyond built-in detections. This is the native detection engine for Defender XDR, distinct from SIEM-based rules.

Why this answer

Custom detection rules in Microsoft 365 Defender allow you to define advanced hunting queries that trigger alerts based on specific event patterns, such as more than 10 failed sign-ins from different countries within 5 minutes. This is the correct component because it operates directly on data within the Defender XDR ecosystem (e.g., AADSignInEventsBeta) without requiring data ingestion into Sentinel.

Exam trap

The trap here is that candidates confuse Microsoft Sentinel analytics rules (which require data ingestion) with Microsoft 365 Defender custom detection rules (which operate natively on Defender XDR data), leading them to choose Sentinel options when the question explicitly states 'Microsoft Defender XDR' as the platform.

How to eliminate wrong answers

Option A is wrong because automation rules in Microsoft Sentinel are used to automate incident response actions (e.g., assigning ownership or running playbooks), not to define detection logic based on raw event patterns. Option C is wrong because analytics rules in Microsoft Sentinel require data to be ingested into the Sentinel workspace first, whereas the question specifies using Microsoft Defender XDR directly for detection and response. Option D is wrong because attack simulation training is a phishing simulation and security awareness tool, not a detection mechanism for sign-in anomalies.

240
MCQmedium

You are designing a security solution for containers running on Azure Kubernetes Service (AKS). The requirements include: scanning container images for vulnerabilities, enforcing runtime security, and generating alerts for suspicious activities. Which combination of services should you use?

A.Azure Security Center and Azure Policy
B.Azure Container Registry and Azure Monitor
C.Azure Policy and Azure Firewall
D.Microsoft Defender for Cloud with Defender for Containers plan
AnswerD

Microsoft Defender for Cloud with the Defender for Containers plan is purpose-built for container security, offering continuous image vulnerability scanning, runtime threat detection using eBPF and audit logs, and Kubernetes hardening all in one solution. It detects suspicious activities like privilege escalations, cryptocurrency mining, or unauthorized cross-namespace communication and raises alerts with automated response capabilities. This plan fully addresses both pre-deployment image risks and post-deployment runtime security, matching the question's requirement for alerts and real-time protection.

Why this answer

Microsoft Defender for Cloud with the Defender for Containers plan (option D) is correct because it is the purpose-built Azure solution that provides image vulnerability scanning (via the integrated Qualys/registry scanner), runtime threat detection using the Defender sensor on AKS nodes, and security alerts for suspicious container activity in a single integrated service. It also supports Kubernetes-native hardening recommendations and integrates with AKS and Azure Container Registry out of the box. Option A is incomplete because Azure Security Center is the former name of Defender for Cloud and Azure Policy alone only enforces governance, not runtime detection or image scanning.

Option B does not fit because Azure Container Registry only stores images and Azure Monitor provides telemetry, not vulnerability scanning or container threat alerts. Option C is incorrect because Azure Policy and Azure Firewall address compliance and network filtering, not image scanning or runtime container security.

241
MCQmedium

A financial services company uses Microsoft Sentinel as its SIEM. The security operations team wants to reduce the number of low-fidelity alerts that reach analysts by correlating related alerts into incidents and automatically closing incidents that match known benign patterns. The team also wants to preserve an audit trail of every automated closure. Which Microsoft Sentinel capability should you design into the solution?

A.Automation rules that run a playbook to close incidents matching a benign pattern
B.Workbooks that visualize incident trends across the last 30 days
C.Data connectors that ingest Microsoft Defender XDR incidents into Microsoft Sentinel
D.Analytics rules configured with entity mapping to group alerts by IP address
AnswerA

Automation rules in Microsoft Sentinel can trigger on incident creation, evaluate conditions such as analytics rule name or entity, and run a playbook or change incident status. Running a playbook that closes the incident and leaves a comment records the automated action in the incident timeline, giving the required audit trail while removing low-fidelity noise before analysts see it.

Why this answer

The requirement combines automated triage with an auditable record of the action. Automation rules are the Microsoft Sentinel feature that evaluates incident properties and can run a playbook or change status, and a playbook that closes the incident with a comment creates the audit trail. Analytics rules, workbooks, and connectors each address detection, visualization, or ingestion rather than automated incident closure.

Exam trap

The trap here is confusing analytics rules, which create and group incidents, with automation rules, which act on incidents after they are created.

242
MCQhard

A company uses Azure Policy to enforce compliance. They want to automatically remediate non-compliant resources by deploying a custom template. Which effect should they use in the policy definition?

A.DeployIfNotExists
B.Audit
C.Disabled
D.Deny
AnswerA

DeployIfNotExists is correct because it actively remediates non-compliant resources by deploying an Azure Resource Manager (ARM) template defined in the policy rule. When a resource exists and fails compliance, this effect causes the template to be deployed, such as adding an agent or applying required configuration. It requires a managed identity and a remediation task to fully fix existing resources, making it the only effect among these that actually changes resources to bring them into compliance.

Why this answer

The DeployIfNotExists effect is correct because it allows Azure Policy to automatically remediate non-compliant resources by deploying a custom ARM template when the resource is found to be non-compliant. This effect is specifically designed for automatic remediation scenarios, as it triggers a deployment to bring the resource into compliance without manual intervention.

Exam trap

The trap here is that candidates often confuse DeployIfNotExists with Deny, thinking that blocking non-compliant resources is sufficient for remediation, but Deny only prevents future non-compliance and does not fix existing resources.

How to eliminate wrong answers

Option B (Audit) is wrong because it only logs non-compliance events without any remediation action, so it cannot automatically fix resources. Option C (Disabled) is wrong because it disables the policy entirely, preventing any evaluation or remediation. Option D (Deny) is wrong because it blocks the creation or update of non-compliant resources but does not remediate already existing non-compliant resources, which is required for automatic remediation.

243
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You need to design a solution that automatically creates an incident in Sentinel when a high-severity alert is generated in Defender for Cloud. What should you configure?

A.Enable the Microsoft Defender for Cloud data connector and create an analytics rule
B.Create a workbook to track alerts
C.Create a playbook in Microsoft Sentinel
D.Use a watchlist to import alerts
AnswerA

The Defender for Cloud data connector ingests security alerts from connected workloads into the Microsoft Sentinel workspace as raw events. However, incidents are not created automatically from these alerts; you must configure an analytics rule (typically a Microsoft security rule of type 'Microsoft Defender for Cloud') to transform the relevant alerts into incidents with assigned severity, status, and ownership. This two-step flow is the only way to get the expected incident-creation behavior from Defender for Cloud alerts.

Why this answer

The Microsoft Defender for Cloud data connector ingests security alerts from Defender for Cloud into Microsoft Sentinel. Once ingested, you create an analytics rule with a rule query that triggers on high-severity alerts and configures the rule to automatically create an incident. This is the standard method to convert a Defender for Cloud alert into a Sentinel incident without manual intervention.

Exam trap

The trap here is that candidates often confuse a playbook (which automates responses) with the analytics rule that actually creates the incident, or they think a workbook or watchlist can trigger incident creation, but only an analytics rule with the proper data connector can automatically generate incidents from ingested alerts.

How to eliminate wrong answers

Option B is wrong because a workbook is a visualization tool for dashboards and reports, not a mechanism to create incidents from alerts. Option C is wrong because a playbook automates response actions (e.g., sending emails or blocking IPs) after an incident is created, but it does not itself generate the incident from a Defender for Cloud alert. Option D is wrong because a watchlist is a collection of static data (e.g., IP addresses or hostnames) used for correlation or enrichment in analytics rules, not a method to import live alerts and create incidents.

244
MCQeasy

A company uses Azure DevOps for CI/CD. The security team wants to ensure that secrets like API keys and connection strings are never stored in code repositories. Which best practice should they recommend?

A.Use environment variables in the pipeline YAML
B.Use Azure Key Vault references in Azure DevOps variable groups
C.Encrypt secrets using Git-secret and commit to repo
D.Store secrets in Azure App Configuration with encryption
AnswerB

Azure Key Vault references in variable groups are the secure, recommended approach because secrets are stored only in Key Vault and are fetched at pipeline runtime via a managed identity or service principal. This eliminates the need to store secrets in the pipeline definition or repository, and access to the secrets is controlled by Azure role-based access on the Key Vault, allowing fine-grained permissions and auditability. Secrets can also be rotated in Key Vault without modifying the pipeline, and the variable group automatically retrieves the latest value, making this solution both secure and maintainable.

Why this answer

Azure Key Vault references in Azure DevOps variable groups allow secrets to be securely linked to pipelines without ever storing them in code repositories. At pipeline runtime, the agent retrieves the secret value directly from Azure Key Vault using a managed identity or service principal, ensuring secrets are never exposed in YAML files, logs, or build artifacts.

Exam trap

The trap here is that candidates confuse Azure App Configuration (which is for app-level settings) with Azure Key Vault (which is the correct service for secret management in CI/CD pipelines), or they assume that encrypting secrets before committing them is acceptable, when the best practice is to never store secrets in repositories at all.

How to eliminate wrong answers

Option A is wrong because environment variables in pipeline YAML still require the secret value to be defined somewhere in the pipeline definition or as a plain-text variable, which can be exposed in logs or repository history. Option C is wrong because committing encrypted secrets to a repo using Git-secret still stores the encrypted blob in the repository, violating the principle of never storing secrets in code; decryption keys must also be managed, increasing risk. Option D is wrong because Azure App Configuration with encryption is designed for application configuration settings, not for CI/CD pipeline secrets; it lacks native integration with Azure DevOps variable groups and does not support dynamic secret retrieval during pipeline execution.

245
MCQhard

Your organization uses Microsoft Intune to manage devices. You need to deploy a line-of-business (LOB) app to iOS devices that is not available in the public App Store. The app is signed with an enterprise certificate. Which app deployment method should you use?

A.Android Enterprise managed Google Play
B.Volume Purchase Program (VPP) token
C.Microsoft Store for Business
D.iOS line-of-business app deployment in Intune
AnswerD

iOS line-of-business (LOB) deployment in Intune is explicitly designed for enterprise-signed apps: you upload an .ipa (or .app) package, sign it with an Apple Enterprise Developer certificate, and assign it to users or devices. Intune creates a configuration profile to trust the enterprise certificate, allowing the app to install directly rather than through the App Store. This is the only option here that supports the scenario's iOS LOB requirement.

Why this answer

The correct answer is D: iOS line-of-business app deployment in Intune. Intune supports deploying custom in-house iOS apps via the iOS LOB app type, which uploads the signed .ipa file and installs it on enrolled devices without requiring the public App Store, matching the scenario of an enterprise-certificate-signed LOB app. Option A (Android Enterprise managed Google Play) is for Android apps distributed through managed Google Play, not iOS.

Option B (VPP token) is used for purchasing and distributing App Store apps in volume, not for custom in-house iOS apps. Option C (Microsoft Store for Business) distributes Windows apps and is unrelated to iOS deployment.

246
MCQmedium

Refer to the exhibit. You are analyzing a KQL query in Microsoft Sentinel that detects machines with more than two malware alerts in a day. The query returns no results even though you know there are machines with multiple malware alerts. What is the most likely reason?

A.The 'summarize' function is incorrectly used and creates duplicate counts.
B.The query filters out alerts with severity less than 'High'.
C.The query does not include a time range filter, so it returns data from all time.
D.The alert name in the environment is not exactly 'Malware detected'; it might include a suffix like 'on endpoint'.
AnswerD

The query uses an exact string match such as `where AlertName == 'Malware detected'`, which only matches alerts with precisely that entire name. In Microsoft Defender for Endpoint and Sentinel, alert names often include contextual suffixes like 'on endpoint' or platform-specific details, so this exact match is too restrictive and misses legitimate alerts. Using a broader operator like `contains` or `endswith` would capture those variations.

Why this answer

The KQL query likely uses a hardcoded string 'Malware detected' in a where clause to filter alerts. If the actual alert names in the environment include a suffix like 'on endpoint' (e.g., 'Malware detected on endpoint'), the exact string match fails, causing the query to return no results. This is a common issue when alert naming conventions vary across Microsoft Defender for Endpoint or other data sources ingested into Sentinel.

Exam trap

The trap here is that candidates assume the query logic is correct and focus on aggregation or time range issues, overlooking the exact string match requirement in KQL, which is a frequent cause of false negatives in detection queries.

How to eliminate wrong answers

Option A is wrong because the 'summarize' function, when used with 'dcount' or 'count', does not create duplicate counts; it aggregates correctly. If duplicates existed, the query would return results, not zero. Option B is wrong because the query does not filter on severity; the question states it detects 'more than two malware alerts in a day' without any severity filter, so excluding high severity would not cause zero results if lower severity alerts exist.

Option C is wrong because omitting a time range filter would cause the query to return data from all time, which would likely return more results, not zero; the issue is the opposite—no results despite known alerts.

247
Multi-Selectmedium

Which TWO actions should you take to implement a Zero Trust security strategy for identity and access? (Choose two.)

Select 2 answers
A.Require Multi-Factor Authentication for all users.
B.Use VPN for remote access to the corporate network.
C.Implement Conditional Access policies that evaluate user, device, and location.
D.Rely on strong passwords only.
E.Create shared accounts for temporary workers.
AnswersA, C

Multi-factor authentication (MFA) requires users to prove identity with at least two distinct factors—typically a password, a device-bound key, and biometrics—so that a stolen password alone cannot unlock access. In the Zero Trust model, MFA operationalizes 'verify explicitly' by forcing each authentication attempt through a nontrivial identity check. Although MFA alone does not comprise full Zero Trust, it is a mandatory baseline that reduces the impact of credential theft and phishing.

Why this answer

Option A is correct because requiring Multi-Factor Authentication (MFA) for all users enforces the Zero Trust principle of verifying identity explicitly, ensuring that a compromised password alone cannot grant access. Option C is correct because Conditional Access policies evaluate signals such as user identity, device compliance, and location to make dynamic, context-aware access decisions, which is central to Zero Trust's 'never trust, always verify' model. Options B, D, and E do not belong: VPNs grant broad network-level access once authenticated rather than per-resource verification, strong passwords alone are a single factor vulnerable to credential theft, and shared accounts eliminate individual accountability and violate least-privilege and explicit-verification principles.

Exam trap

The trap here is that candidates often confuse VPN (a perimeter-based network access solution) with Zero Trust network access (ZTNA), mistakenly thinking VPNs are a valid Zero Trust identity action, when in fact they violate the core Zero Trust principle of not trusting any network segment implicitly.

248
MCQmedium

Refer to the exhibit. You create this conditional access policy in Microsoft Entra ID. What is the result?

A.Requires MFA for medium and high risk users for all applications
B.Blocks sign-ins from medium and high risk users for all applications
C.Blocks sign-ins from low risk users for all applications
D.Blocks sign-ins from medium and high risk users only for selected applications
AnswerB

This policy assigns the target to 'All cloud apps' and sets the user risk condition to 'Medium or High,' then applies the 'Block' grant control. As a result, any sign-in with a user risk level of medium or higher is denied across every application, while low-risk sign-ins are unaffected. The combination of a broad application scope and a risk threshold yields a global block for medium and high risk users.

Why this answer

The conditional access policy shown assigns the 'Block access' control to the 'Medium and High' risk levels for 'All cloud apps'. This means any sign-in from a user or session detected as medium or high risk will be blocked, regardless of the application. Option B correctly identifies this outcome.

Exam trap

The trap here is that candidates often confuse 'Block access' with 'Require MFA' when they see risk levels, assuming the policy will prompt for MFA instead of outright blocking the sign-in.

How to eliminate wrong answers

Option A is wrong because the policy uses 'Block access', not 'Grant access' with MFA, so it does not require MFA. Option C is wrong because the policy targets 'Medium and High' risk levels, not 'Low' risk. Option D is wrong because the policy applies to 'All cloud apps', not only selected applications.

249
MCQeasy

Your organization uses Microsoft Purview to classify and protect sensitive data. You need to prevent users from accidentally sharing files that contain credit card numbers via email. What should you configure in Microsoft Purview?

A.Enable Microsoft Defender for Cloud Apps session policy to monitor file downloads.
B.Configure a retention policy for files containing credit card numbers.
C.Implement a data loss prevention (DLP) policy that detects credit card numbers and blocks email sharing.
D.Create a sensitivity label that automatically classifies credit card numbers.
AnswerC

A data loss prevention (DLP) policy in Microsoft Purview can be configured with a rule that uses a sensitive info type for credit card numbers, then applies an action to block external email sharing. This directly satisfies the stem’s constraint of preventing accidental sharing via email, as the policy inspects message content and enforces the block before the email is sent.

Why this answer

A DLP policy in Microsoft Purview is purpose-built to detect sensitive information types such as credit card numbers (via the built-in 'Credit Card Number' SIT, which uses regex plus Luhn checksum validation) and to enforce protective actions like blocking email sharing. DLP policies can be scoped to Exchange Online, SharePoint, OneDrive, and Teams, and can block or encrypt content when the sensitive data is detected. This directly addresses the requirement to prevent accidental email sharing of files containing credit card numbers.

Exam trap

SC-100 often tests the distinction between classification (sensitivity labels) and enforcement (DLP policies) — candidates incorrectly assume a sensitivity label alone blocks sharing, when enforcement requires a DLP or auto-labeling policy.

How to eliminate wrong answers

Option A is wrong because Defender for Cloud Apps session policies govern access to cloud apps (e.g., blocking downloads in a browser session) and do not inspect email content for credit card numbers. Option B is wrong because retention policies only govern how long content is kept or when it is deleted; they do not detect or block sensitive data sharing. Option D is wrong because a sensitivity label classifies and can protect content (e.g., encryption), but by itself it does not automatically detect credit card numbers or block email sharing — that requires an auto-labeling policy or a DLP policy to enforce the block.

250
MCQhard

A global enterprise uses Microsoft Entra ID with Privileged Identity Management (PIM) and Conditional Access. They need to ensure that all privileged role activations require an approval workflow, and that the approval process is documented for compliance. What configuration should they implement?

A.Create a Conditional Access policy requiring an Authentication Strength
B.In PIM, edit the role settings to require approval for activation
C.Configure an access review for the privileged roles
D.Create a role-assignable group and assign the privileged role to the group
AnswerB

Editing the role's activation settings to require approval enforces a documented authorisation step before any privileged role becomes active. This directly satisfies the stem's demand that every activation trigger an approval workflow, with the approval recorded in PIM for compliance auditing.

Why this answer

To require approval for privileged role activations in PIM, you must edit the role settings for the specific role and enable the 'Require approval to activate' option. This ensures that when a user activates the role, an approver must approve the request, and the approval is logged for compliance.

Exam trap

SC-100 often tests the difference between PIM settings and Conditional Access, and candidates may confuse approval workflows with access reviews or authentication strength, leading to wrong answers.

How to eliminate wrong answers

Option A is wrong because Conditional Access with Authentication Strength enforces stronger authentication methods but does not add an approval workflow. Option C is wrong because access reviews are for periodic attestation of role assignments, not for activation approval. Option D is wrong because role-assignable groups are for assigning roles to groups, not for configuring approval workflows.

251
MCQhard

A financial services organization is designing a zero-trust architecture for its Azure environment. They need to ensure that all administrative access to critical systems uses just-in-time (JIT) access and that privileged role assignments are time-bound. Which combination of Microsoft security best practices should they implement?

A.Azure AD Conditional Access and Azure AD Identity Protection
B.Azure Policy and Azure Blueprints
C.Azure Sentinel and Azure Workbook
D.Azure AD Privileged Identity Management (PIM) and Azure Bastion
AnswerD

Azure AD Privileged Identity Management (PIM) and Azure Bastion are the correct pair. PIM provides time-bound, approval-required role activation for Azure AD roles and Azure resource roles, eliminating standing privileged access and aligning with zero-trust JIT principles. Azure Bastion enables secure, browser-based RDP/SSH access to virtual machines without public IP exposure, and when combined with Azure Defender for Cloud's JIT VM access, it can further scope access to specific ports and time windows. Together they enable a complete JIT and JEA (just-enough-access) workflow: PIM governs privileged identity elevation, while Bastion enforces a secure, monitored, and ephemeral VM access path.

Why this answer

Azure AD Privileged Identity Management (PIM) provides just-in-time (JIT) activation and time-bound role assignments for privileged roles, directly meeting the requirement for time-bound administrative access. Azure Bastion enables secure, audited RDP/SSH access to Azure VMs without exposing public IP addresses, ensuring that administrative sessions are isolated and monitored. Together, they enforce zero-trust principles by granting ephemeral, scoped access to critical systems.

Exam trap

The trap here is that candidates confuse Azure AD Conditional Access (which controls sign-in conditions) with PIM’s JIT role activation, or they assume Azure Bastion is only a connectivity tool rather than a critical component of zero-trust administrative access.

How to eliminate wrong answers

Option A is wrong because Azure AD Conditional Access and Identity Protection focus on user sign-in risk and session controls, not on time-bound role assignments or JIT access to Azure resources. Option B is wrong because Azure Policy and Blueprints enforce compliance and resource governance (e.g., tagging, allowed locations), but they do not provide JIT activation or time-bound privileged role management. Option C is wrong because Azure Sentinel and Workbooks are for security information and event management (SIEM) and visualization, not for controlling privileged access or session isolation.

252
MCQmedium

You are designing a security solution for Azure Kubernetes Service (AKS). You need to ensure that only authorized container images from a private container registry can run in the cluster. What should you configure?

A.Use Azure Policy to enforce that containers run only from allowed registries.
B.Implement Azure Container Registry tasks to scan images.
C.Configure network policies in AKS to block outbound traffic to public registries.
D.Enable Microsoft Defender for Containers to block unauthorized images.
AnswerA

Azure Policy's built-in 'Ensure only allowed container images' initiative works with the Azure Policy add-on for AKS, which installs Gatekeeper as a validating admission webhook. At pod creation or update, the policy evaluates the image repository against an allowed list of fully qualified registry names, rejecting any non-conforming pod spec before it is persisted to etcd. This provides deterministic, cluster-wide, preventive enforcement rather than relying on runtime detection or network filtering.

Why this answer

Azure Policy is the correct choice (A) because it can enforce admission-time constraints on an AKS cluster, such as an allowed-registries policy that denies pods whose images do not originate from the specified private Azure Container Registry. This directly satisfies the requirement that only authorized images from a private registry can run. Option B is incorrect because ACR Tasks scan images for vulnerabilities but do not restrict which registries pods may pull from.

Option C is incorrect because network policies control pod-level traffic, not image provenance, and blocking outbound traffic does not enforce registry allowlisting. Option D is incorrect because Microsoft Defender for Containers provides threat detection and posture management, not admission control that blocks unauthorized images.

253
MCQmedium

You are designing a data classification strategy for a Microsoft 365 tenant. You need to automatically classify documents that contain personally identifiable information (PII) and apply a retention label. Which Microsoft Purview feature should you use?

A.Auto-labeling policies
B.Trainable classifiers
C.Manual labeling
D.Data Loss Prevention (DLP) policies
AnswerA

Auto-labeling policies in Microsoft Purview apply sensitivity labels automatically to emails and files when they match configured conditions, such as sensitive information types like Social Security numbers or credit card numbers. Because they rely on built-in detection engines rather than user input or custom model training, they are the simplest and most consistent way to automatically label PII content in a data classification strategy. A policy can be run in simulation mode to review the labels before enforcing, then set to auto-label new and existing items.

Why this answer

Auto-labeling policies (option A) are the correct choice because they can automatically apply sensitivity or retention labels to documents in Microsoft 365 services such as SharePoint, OneDrive, and Exchange when content matches specified conditions, including sensitive information types like PII. They are designed specifically for automatic classification and labeling at scale, which matches the requirement to classify PII-containing documents and apply a retention label. Trainable classifiers (option B) can identify content based on examples, but they are used to detect custom content types and still require a labeling policy to apply labels, so they are not the primary feature for this scenario.

Manual labeling (option C) requires user intervention and does not meet the need for automatic classification. DLP policies (option D) can detect and protect sensitive information, but they do not apply retention labels; they enforce actions like blocking or notifying.

254
MCQhard

Your organization uses Microsoft Sentinel to detect threats. You need to design a solution that automatically remediates a detected threat on an Azure VM by isolating the VM from the network. What should you use?

A.Create a Microsoft Sentinel automation rule that triggers a playbook to run an Azure Automation runbook to modify the NSG.
B.Configure a Log Analytics workspace query to run on a schedule and automatically block the VM.
C.Use Azure Policy to audit and automatically remediate non-compliant VMs.
D.Enable Microsoft Defender for Cloud's 'Just-in-time VM access' policy.
AnswerA

Microsoft Sentinel automation rules are designed to invoke playbooks (Logic Apps) in response to security alerts. A playbook can call an Azure Automation runbook, which can programmatically update the NSG to add a deny rule for the compromised VM, quarantining it from network traffic. This is the correct SOAR-based remediation approach because it leverages Sentinel's native alert triggers and Azure Automation's compute capabilities.

Why this answer

Microsoft Sentinel can trigger a playbook (automation rule) that runs an Azure Automation runbook to modify the NSG and isolate the VM. Option B is wrong because Log Analytics workspace doesn't have remediation actions. Option C is wrong because Azure Policy is for compliance, not incident response.

Option D is wrong because Defender for Cloud has some automation, but Sentinel playbook is the designed method for automated response.

255
MCQhard

Your company is designing a Zero Trust network for a hybrid workforce. Remote users connect via VPN to on-premises resources, while cloud apps use Microsoft Entra ID. You need to enforce conditional access based on device compliance and user risk. Which Microsoft security solution should you integrate with Entra ID to provide real-time device posture signals?

A.Microsoft Purview
B.Microsoft Intune
C.Microsoft Defender for Cloud Apps
D.Microsoft Sentinel
AnswerB

Microsoft Intune supplies real-time device compliance and posture signals directly into Microsoft Entra ID conditional access policies, satisfying the requirement to evaluate device state alongside user risk. Its compliance engine continuously reports encryption, OS patch level and jailbreak status, enabling hybrid workers on VPN and cloud apps to be granted or blocked access per Zero Trust policy.

Why this answer

Microsoft Intune provides device compliance policies and can send device posture signals to Entra ID Conditional Access. With Intune, you can enforce device health and compliance requirements before granting access. Option A is wrong because Microsoft Purview focuses on data governance and compliance, not device management.

Option C is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) and does not directly manage device compliance. Option D is wrong because Microsoft Sentinel is a security information and event management (SIEM) solution and does not provide device posture signals.

256
MCQhard

Your organization uses Microsoft Purview Information Protection to classify and protect sensitive data. The compliance team wants to automatically apply a 'Highly Confidential' sensitivity label to emails that contain credit card numbers. Which solution should you configure?

A.Microsoft Purview auto-labeling policy
B.Microsoft Defender for Office 365 Safe Attachments policy
C.Microsoft 365 Data Loss Prevention (DLP) policy
D.Microsoft Endpoint DLP
AnswerA

Microsoft Purview auto-labeling is the correct mechanism because it can evaluate email content and context (e.g., sensitive info types like credit card numbers, or trainable classifiers) and automatically assign sensitivity labels to messages. Policies run in simulation mode or enforce automatically, and label actions like encryption can then be applied based on the label. This directly addresses the requirement to apply an information protection label to emails.

Why this answer

The correct option is A, Microsoft Purview auto-labeling policy, because auto-labeling policies are the native Purview Information Protection mechanism that scans content for sensitive information types (such as credit card numbers) and automatically applies a specified sensitivity label like 'Highly Confidential' to emails and files. This directly matches the requirement to classify and protect data at the label level, since sensitivity labels can also enforce encryption and other protection settings. Option B, Safe Attachments, is a Defender for Office 365 threat-detection feature that sandboxes attachments and does not apply sensitivity labels.

Option C, a DLP policy, can detect credit card numbers and block or warn on sharing, but it enforces DLP rules rather than automatically applying a sensitivity label. Option D, Microsoft Endpoint DLP, extends DLP controls to endpoint devices and likewise does not apply sensitivity labels to email.

257
Multi-Selecthard

Your company is designing a zero-trust security posture for a new application in Azure. The application uses Azure Functions, Azure SQL Database, and Azure Blob Storage. You need to ensure that data in transit is encrypted and that the application can authenticate without storing secrets in code. Which THREE actions should you take?

Select 3 answers
A.Enable 'Enforce minimum TLS version' on the Blob Storage account
B.Configure the application to use TLS 1.2 or higher for all connections
C.Use managed identity for Azure Functions to access Azure SQL Database
D.Enable customer-managed keys (CMK) for Azure SQL Database
E.Configure the Azure SQL firewall to allow only the Functions IP range
AnswersA, B, C

Enabling 'Enforce minimum TLS version' on the Blob Storage account is a server-side control that rejects any connection attempting to use TLS 1.0 or 1.1, forcing clients to negotiate TLS 1.2 or higher for all data transfers. This is a critical zero-trust measure for encryption in transit, as it ensures that data traveling between the client and Blob Storage is protected by a modern cipher suite. It also prevents downgrade attacks where an attacker could force a weaker protocol.

Why this answer

Options A, B, and C are correct. Enforcing a minimum TLS version on Blob Storage (A) and configuring the application to use TLS 1.2 or higher (B) both ensure data in transit is encrypted. Using managed identity for Azure Functions to access Azure SQL Database (C) provides secretless authentication.

Option D (CMK) encrypts data at rest, not in transit. Option E (firewall IP restriction) controls network access but does not encrypt data in transit.

258
MCQhard

Refer to the exhibit. You are analyzing a KQL query in Microsoft Sentinel. What is the purpose of this query?

A.Correlate malware alerts with device OS version
B.List all malware alerts in the last 7 days
C.Identify malware alerts on unmanaged devices
D.Show device inventory for unmanaged devices
AnswerC

The query joins SecurityAlert with DeviceInfo, filtering where ManagedDevice equals false and alert severity is High, which surfaces malware detections on unmanaged endpoints. This satisfies the stem's requirement to identify malware alerts on unmanaged devices, since the join correlates alert context with device management state rather than merely listing alerts.

Why this answer

The query uses the `DeviceInfo` table to filter for devices where `IsManaged` is `false`, then joins with `SecurityAlert` to find alerts where `AlertName` contains 'Malware'. This specifically identifies malware alerts generated on unmanaged devices, not all malware alerts or a general device inventory.

Exam trap

The trap here is that candidates may confuse the purpose of the query as simply listing all malware alerts (Option B) or showing device inventory (Option D), overlooking the critical `IsManaged == false` filter that narrows the scope to unmanaged devices.

How to eliminate wrong answers

Option A is wrong because the query does not correlate malware alerts with device OS version; it only filters on `IsManaged` and `AlertName`, with no reference to OS version fields. Option B is wrong because the query does not list all malware alerts in the last 7 days; it restricts results to alerts on unmanaged devices (IsManaged == false) and does not include a time filter for the last 7 days. Option D is wrong because the query returns alerts, not a device inventory; the output includes alert details (e.g., AlertName, TimeGenerated) rather than a list of devices.

259
MCQmedium

Refer to the exhibit. You receive an alert from Microsoft Defender for Cloud Apps. You need to investigate this alert in Microsoft Sentinel. Which Microsoft Sentinel feature should you use to visualize the relationship between the user account and the IP address?

A.Configure an automation rule to trigger a playbook.
B.Run a hunting query to search for similar alerts.
C.Use the Investigation graph to explore the entities involved.
D.Create a new workbook to display the alert details.
AnswerC

The Investigation graph in Microsoft Defender XDR is purpose-built for visually exploring the entities involved in an alert or incident. It dynamically maps nodes such as users, devices, IP addresses, and mailboxes, along with edges representing their connections, letting you investigate scope and expand the investigation. This interactive relationship mapping is exactly what the scenario requires, unlike automation or reporting tools.

Why this answer

The Investigation graph in Microsoft Sentinel is the correct feature because it is purpose-built to visualize and explore relationships among entities such as user accounts, IP addresses, hosts, and alerts, letting you pivot from the Defender for Cloud Apps alert to see how the user account connects to the IP address. It provides an interactive, entity-centric view that surfaces related incidents, alerts, and activities, which is exactly what is needed to investigate the relationship in this scenario. Automation rules (A) only trigger playbooks in response to alerts and do not visualize entity relationships, hunting queries (B) search log data for matching events but return tabular results rather than a relationship graph, and workbooks (D) are for building dashboards and reports of alert details, not for interactively exploring entity links.

260
MCQeasy

You are designing a secure DevOps pipeline using GitHub Actions and Azure. The security team requires that all container images pushed to Azure Container Registry (ACR) are scanned for vulnerabilities before deployment. If critical vulnerabilities are found, the pipeline must fail. What should you integrate into the pipeline?

A.Configure Azure Policy to require image scanning before deployment
B.Integrate Microsoft Defender for Cloud with Azure Container Registry scanning and configure a GitHub Actions step to check scan results
C.Deploy Azure Bastion to scan images during build
D.Use Azure Security Center (legacy) to scan images on push
AnswerB

Microsoft Defender for Cloud provides integrated vulnerability assessment for Azure Container Registry (ACR) images, using the Qualys scanner, which detects OS package and known software vulnerabilities. After enabling Defender for Cloud on the subscription or specifically for ACR, you can programmatically query scan results via the Microsoft Defender for Cloud REST API (e.g., Assessments - Get) or use the az acr security-status command to retrieve findings. A GitHub Actions step can then call this API in a script, parse the severity levels, and conditionally fail the job if critical or high vulnerabilities exceed a threshold. This architectural pattern is a valid 'shift-left' security gate because the scan occurs on the registry image before deployment, and the workflow enforces the policy based on real-time data.

Why this answer

Option B is correct because Microsoft Defender for Cloud's container registry scanning (Defender for Containers) integrates natively with ACR to scan images on push, and a GitHub Actions step can query the scan results via the Azure CLI/REST API and fail the pipeline when critical vulnerabilities are detected. This directly satisfies the requirement to block deployment when critical findings exist. Option A does not fit because Azure Policy enforces governance on deployed resources and cannot fail a GitHub Actions build step based on scan results.

Option C is wrong because Azure Bastion is a managed jump-host service for RDP/SSH access, not an image scanner. Option D is wrong because Azure Security Center is the legacy name for Defender for Cloud and, by itself, does not provide the pipeline-failing GitHub Actions integration described in B.

261
MCQhard

You are designing a secure access strategy for a manufacturing plant using Azure IoT Hub and Azure Defender for IoT. The plant has unpatched legacy PLCs that cannot be updated. What is the best approach to prevent these devices from being compromised and used as an entry point into the corporate network?

A.Use Azure VPN Gateway to connect PLCs to the virtual network.
B.Implement network micro-segmentation using Azure Firewall and NSGs to isolate the PLCs from the corporate network.
C.Install the Microsoft Defender for IoT micro-agent on each PLC.
D.Enforce TLS 1.2 for all PLC communications.
AnswerB

Micro-segmentation with Azure Firewall and NSGs is a compensating control that works even when PLCs cannot be patched or updated. By placing PLCs in a dedicated subnet, applying NSG rules to deny inbound/outbound traffic except allowed industrial protocols, and centralizing policy in Azure Firewall, you enforce least-privilege communication. This containment limits the blast radius so a compromised PLC cannot reach corporate systems or other OT zones.

Why this answer

The correct option is B: implementing network micro-segmentation with Azure Firewall and NSGs to isolate the PLCs from the corporate network. Since the legacy PLCs cannot be patched, the most effective mitigation is to limit their attack surface and blast radius by placing them in a segmented network zone with strict allow-list rules, so a compromised PLC cannot pivot laterally into corporate systems. Azure Firewall provides centralized Layer 3–7 filtering and NSGs enforce subnet/NIC-level traffic control, which directly addresses the unpatched-device risk.

Option A is wrong because a VPN gateway only provides encrypted connectivity, not isolation or traffic restriction. Option C is wrong because the Defender for IoT micro-agent requires installation and support on the device, which unpatched legacy PLCs typically cannot accommodate. Option D is wrong because TLS 1.2 only protects data in transit and does not prevent compromise or lateral movement from an unpatched PLC.

262
MCQeasy

Your organization uses Microsoft Sentinel to detect threats. You need to ensure that sensitive data stored in Azure SQL Database is protected from unauthorized access by Sentinel playbooks. What should you implement?

A.Enable dynamic data masking on the SQL database
B.Use customer-managed keys (CMK) for SQL Transparent Data Encryption
C.Configure Azure SQL firewall rules to allow only Sentinel IP addresses
D.Use a managed identity assigned to the playbook to authenticate to Azure SQL
AnswerD

Assigning a managed identity to the playbook (a Logic App) enables it to authenticate to Azure SQL using Microsoft Entra ID tokens, eliminating hard-coded secrets. You must create a contained database user mapped to that identity (e.g., CREATE USER FROM EXTERNAL PROVIDER) and grant least-privilege permissions. This is the correct approach because it provides secure, credential-free, and automatically rotating authentication for automated workflows.

Why this answer

The correct option is D: use a managed identity assigned to the playbook to authenticate to Azure SQL. In Microsoft Sentinel, playbooks are Logic Apps, and when they need to access Azure SQL Database, the recommended approach is to assign a managed identity to the playbook and grant that identity the appropriate database permissions, so no credentials are stored and access is scoped to the playbook. This directly protects sensitive data by ensuring only the authorized playbook identity can authenticate to Azure SQL.

Option A (dynamic data masking) limits data exposure in query results but does not control which principals can access the database. Option B (CMK for TDE) protects data at rest via encryption key management, not playbook authorization. Option C (SQL firewall rules for Sentinel IPs) is impractical because Sentinel playbooks run as Logic Apps without a fixed, reliable set of Sentinel IP addresses, and firewall rules alone do not authenticate the playbook.

263
MCQhard

Refer to the exhibit. You are an Azure security engineer reviewing a custom Azure Policy definition. The policy is intended to audit virtual machines to ensure they have the Azure Security extension installed. However, the policy is not triggering on any resources. What is the most likely reason?

A.The policy condition requires a managed disk, but the VMs might have unmanaged disks.
B.The 'existenceCondition' field path is incorrect; it should be 'Microsoft.Compute/virtualMachines/extensions/publisher'.
C.The policy is assigned to a management group, but the VMs are in a subscription under a different management group.
D.The policy effect should be 'Deny' instead of 'auditIfNotExists'.
AnswerA

The policy definition's 'if' clause matches only VMs that have a managed disk (e.g., by checking that the 'managedDisk' property is present). VMs that still use unmanaged disks do not satisfy this condition, so the 'auditIfNotExists' effect is never evaluated for them. Consequently, the policy silently ignores the very machines that likely need the missing-extension audit, making the compliance report incomplete rather than identifying all noncompliant VMs.

Why this answer

The policy condition uses `field` to check for `Microsoft.Compute/virtualMachines/storageProfile.osDisk.managedDisk.id`, which requires the VM to have a managed disk. If the VMs use unmanaged disks (i.e., the `managedDisk` property is absent), the condition evaluates to false, and the `auditIfNotExists` effect never triggers the existence check for the Azure Security extension.

Exam trap

The trap here is that candidates focus on the `existenceCondition` or effect syntax, overlooking that the parent `field` condition silently fails on VMs without managed disks, preventing the entire policy from evaluating.

How to eliminate wrong answers

Option B is wrong because the `existenceCondition` field path `Microsoft.Compute/virtualMachines/extensions/publisher` is syntactically valid for checking the extension's publisher property; the issue is not with the path but with the parent condition failing. Option C is wrong because policy assignment inheritance works correctly across management group hierarchies—if the policy is assigned to a management group, it applies to all descendant subscriptions, so VMs in a child subscription would still be evaluated. Option D is wrong because changing the effect to `Deny` would not fix the triggering issue; the policy is not evaluating resources at all due to the condition, not because of the effect type.

264
MCQmedium

Your organization uses Microsoft Sentinel for security operations. You need to ensure that an attacker cannot disable data collection by deleting the diagnostic settings on the Sentinel workspace. What should you configure?

A.Enable Sentinel's workspace deletion protection.
B.Assign the Log Analytics Contributor role only to specific users.
C.Apply a CanNotDelete resource lock on the Log Analytics workspace.
D.Create an Azure Policy to audit diagnostic settings.
AnswerC

Applying a CanNotDelete resource lock on the Log Analytics workspace is the only option that actively blocks any delete operation on the workspace and all its child resources, including diagnostic settings. This lock enforces a deny at the Azure Resource Manager level, overriding even elevated RBAC permissions unless a matching delete lock is removed first. As a result, it provides a robust, unbreakable-by-default safeguard that directly prevents the diagnostic settings from being deleted.

Why this answer

Applying a CanNotDelete resource lock on the Log Analytics workspace prevents any user or process, including an attacker, from deleting the workspace or its diagnostic settings. This lock overrides all role-based permissions, ensuring that even if an attacker gains high-privileged access, they cannot remove the diagnostic settings that stream telemetry to Microsoft Sentinel. Sentinel's data collection relies entirely on these diagnostic settings, so protecting them with a resource lock is the most direct and effective defense against deletion attacks.

Exam trap

The trap here is that candidates confuse workspace deletion protection (which only prevents workspace deletion) with diagnostic settings deletion protection, or they assume that RBAC alone (Option B) is sufficient to block a privileged attacker, when in fact a resource lock is the only control that enforces a hard deny on deletion regardless of permissions.

How to eliminate wrong answers

Option A is wrong because Sentinel's workspace deletion protection only prevents the accidental deletion of the Sentinel workspace itself, not the deletion of diagnostic settings on that workspace; an attacker could still remove the diagnostic settings and stop data ingestion without deleting the workspace. Option B is wrong because assigning the Log Analytics Contributor role only to specific users limits who can modify the workspace, but it does not prevent an attacker with compromised credentials or a privileged user from deleting diagnostic settings; role-based access control (RBAC) alone is insufficient against a determined attacker with elevated permissions. Option D is wrong because creating an Azure Policy to audit diagnostic settings only reports on compliance (e.g., whether settings exist) but does not block deletion; it provides no preventive control and cannot stop an attacker from removing the settings in real time.

265
Multi-Selectmedium

An organization uses Microsoft Purview to classify and protect sensitive data. Which THREE capabilities can be used to discover sensitive data? (Choose three.)

Select 3 answers
A.Trainable classifiers
B.Data loss prevention policies
C.Retention labels
D.Data classification rules
E.Sensitive information types
AnswersA, D, E

Trainable classifiers are machine learning models in Microsoft Purview that analyze content using contextual, semantic, and visual signals to identify data types that do not rely on fixed patterns. They can be trained on seed documents unique to your organization, allowing them to classify content that lacks standardized formats, such as intellectual property or internal forms. This makes them the correct answer for a ML-driven classification approach.

Why this answer

Trainable classifiers use machine learning to identify content based on patterns and context, not just exact matches. They can be trained on sample data to recognize custom sensitive information, such as specific contract clauses or internal project codes, enabling discovery of sensitive data that predefined sensitive information types might miss.

Exam trap

Microsoft often tests the distinction between discovery capabilities (which identify sensitive data) and enforcement or lifecycle management capabilities (which act on already-discovered data), causing candidates to mistakenly select DLP policies or retention labels as discovery tools.

266
MCQhard

Your organization uses Microsoft Sentinel with the Microsoft 365 Defender connector. You need to create an analytics rule that generates an incident when a user is reported as compromised by Microsoft Defender for Identity. The rule should use the most efficient method to get this data. What should you use as the data source?

A.The SecurityAlert table with a filter for Defender for Identity.
B.The DeviceEvents table from Advanced Hunting.
C.The OfficeActivity table.
D.The IdentityInfo table.
AnswerA

Defender for Identity alerts are normalized into the SecurityAlert table when Sentinel's data connectors ingest them from Microsoft 365 Defender or Azure ATP. This table uses a unified schema for all security alerts, so filtering by the provider or product name (such as 'Azure Advanced Threat Protection') isolates only Defender for Identity detections. Querying SecurityAlert is the correct approach because it is the standard Sentinel table for pre-correlated, high-fidelity security findings, not raw telemetry or audit logs.

Why this answer

The SecurityAlert table contains security alerts from various sources, including Microsoft Defender for Identity, when ingested via the Microsoft 365 Defender connector. By filtering for Defender for Identity alerts, you can create an analytics rule that triggers an incident when a user is reported as compromised. This is the most efficient method because the alerts are already available in this table.

Option B (DeviceEvents) is from Advanced Hunting and is not directly available in Sentinel tables; it requires running queries against the Microsoft 365 Defender advanced hunting schema, which is less efficient for creating analytics rules. Option C (OfficeActivity) contains Office 365 audit logs, not security alerts. Option D (IdentityInfo) contains identity information such as user details, but not alerts or compromise status.

267
MCQmedium

Your organization uses Microsoft Defender for Cloud to secure a multi-cloud environment including Azure, AWS, and GCP. You need to design a solution that centralizes security alerts and automates remediation across all clouds. Which security operations capability should you prioritize?

A.Configure Microsoft Purview Compliance Manager for regulatory assessments
B.Enable Microsoft Defender for Cloud's multi-cloud connector to aggregate alerts
C.Use Microsoft Sentinel as a single SIEM and SOAR platform with connectors for AWS and GCP
D.Deploy Microsoft Defender for Identity to monitor hybrid identities
AnswerC

Microsoft Sentinel is a cloud-native SIEM and SOAR that centralizes security telemetry from Azure, AWS, and GCP via native connectors, such as AWS CloudTrail/Security Hub and the GCP Pub/Sub-based connector, into a single Log Analytics workspace. It empowers analysts to run KQL-based hunt queries across all clouds, create custom analytics rules for multi-cloud attack detection, and use Automation rules and Logic Apps playbooks to orchestrate response. This provides true unified incident management and automated remediation across heterogeneous environments, far beyond what individual cloud security tools offer.

Why this answer

Microsoft Sentinel is the correct choice because it functions as a cloud-native SIEM and SOAR platform that can ingest security alerts from Azure, AWS, and GCP via native data connectors, then centralize them and drive automated remediation through playbooks (Logic Apps). This directly satisfies the requirement to centralize alerts and automate remediation across a multi-cloud estate. Option B is only partially relevant: Defender for Cloud's multi-cloud connector aggregates posture and alert data but does not provide the full SIEM/SOAR automation capability Sentinel delivers.

Option A (Purview Compliance Manager) is for regulatory compliance assessments, not security operations, and Option D (Defender for Identity) only monitors identity signals in hybrid Active Directory environments, not multi-cloud alert centralization or remediation.

268
Multi-Selectmedium

Which THREE capabilities are provided by Microsoft Defender for Cloud Apps (MDA) when integrated with Microsoft Defender XDR?

Select 3 answers
A.Email protection against phishing and malware.
B.Discovery of shadow IT cloud apps.
C.App permissions and OAuth app governance.
D.Endpoint detection and response (EDR) for devices.
E.Conditional access session controls for cloud apps.
AnswersB, C, E

MDA discovers apps used in the organization.

Why this answer

Microsoft Defender for Cloud Apps (MDA) integrates with Microsoft Defender XDR to provide shadow IT discovery by analyzing traffic logs from network devices and cloud app catalogs, identifying unsanctioned cloud applications used in the organization. This capability is core to MDA's Cloud Discovery feature, which uses log parsing and machine learning to detect and classify shadow IT.

Exam trap

The trap here is that candidates often confuse the capabilities of Microsoft Defender for Cloud Apps with those of other Microsoft Defender XDR components, such as Defender for Office 365 (email security) or Defender for Endpoint (EDR), leading them to select options that are valid security features but not provided by MDA.

269
MCQmedium

An organization is planning to use Microsoft Defender for Cloud's regulatory compliance dashboard to track adherence to PCI DSS. The security team wants to ensure that all Azure resources are covered by the compliance assessment. What is the first step?

A.Enable Microsoft Defender for Cloud on all subscriptions and ensure resources are covered.
B.Configure the compliance dashboard to show PCI DSS controls.
C.Create a custom regulatory compliance standard for PCI DSS.
D.Enable the built-in PCI DSS policy initiative in Azure Policy.
AnswerA

Microsoft Defender for Cloud is the required assessment engine that evaluates Azure resources against built-in regulatory compliance standards such as PCI DSS. Enabling Defender for Cloud on every subscription and confirming that all resources are covered ensures the underlying Azure Policy initiative is automatically assigned and the regulatory compliance dashboard can collect continuous assessment data. Without this onboarding step, the compliance standard will have no resources to evaluate and will display an incomplete or zero score, making this the mandatory first action.

Why this answer

For the regulatory compliance dashboard to assess resources, Microsoft Defender for Cloud must first be enabled on all subscriptions and resources must be covered by its enhanced security features. Without enabling Defender for Cloud, the compliance dashboard cannot collect the necessary data to evaluate compliance. Option B is incorrect because configuring the dashboard to show PCI DSS controls is a subsequent step after ensuring coverage.

Option C is incorrect because creating a custom standard is not the first step; the built-in PCI DSS initiative should be used. Option D is incorrect because the built-in PCI DSS policy initiative in Azure Policy does not automatically apply to resources unless Defender for Cloud is already enabled and the initiative is assigned; enabling Defender for Cloud is the prerequisite.

270
Multi-Selecthard

You are designing a solution to protect Azure SQL Database from SQL injection attacks. The solution must use a web application firewall (WAF) and also ensure that queries from the application are parameterized. Which two components should you include? (Choose two. Each correct answer presents part of the solution.)

Select 2 answers
A.Azure SQL Database firewall rules
B.Transparent Data Encryption (TDE)
C.Azure Application Gateway with WAF
D.Parameterized queries in the application code
AnswersC, D

Azure Application Gateway with Web Application Firewall (WAF) inspects inbound HTTP/HTTPS traffic at the application layer and applies the OWASP Core Rule Set, which includes specialized SQL injection rules. It can detect and block malicious patterns in query strings, request bodies, and headers before the request reaches Azure SQL Database. This provides a centralized, cloud-managed defense layer that is particularly effective for public web applications exposing APIs or SQL-backed endpoints.

Why this answer

Option C is correct because Azure Application Gateway with WAF provides a web application firewall that can inspect incoming HTTP/HTTPS traffic and block common SQL injection patterns using OWASP rule sets before requests reach the application or database. Option D is correct because parameterized queries in the application code ensure user input is treated as data rather than executable SQL, which is the primary defense against SQL injection at the application layer. Together, these two components satisfy both stated requirements: a WAF and parameterized queries.

Option A, Azure SQL Database firewall rules, only controls which IP addresses or Azure services can connect to the database and does not inspect query content for injection attacks. Option B, Transparent Data Encryption (TDE), encrypts data at rest and does not prevent SQL injection or filter malicious queries.

271
MCQmedium

Your company is implementing Microsoft Purview Information Protection to protect sensitive data. The compliance team requires that when a user applies a 'Highly Confidential' sensitivity label to a document, the document is automatically encrypted and watermarked. Which configuration should you use?

A.Create a DLP policy that encrypts and watermarks the document when it is shared externally
B.Create an auto-labeling policy that detects sensitive content and applies the label automatically
C.Create a Conditional Access policy that requires the label to be applied to all documents
D.Configure the sensitivity label to apply encryption and dynamic watermarking. Publish the label to users.
AnswerD

A sensitivity label is the correct mechanism because encryption and dynamic watermarking are configured as part of the label's protection settings, and publishing the label makes it available in the Office apps' Sensitivity button. When the user manually applies this label, the label enforces the configured encryption rights and dynamically inserts the user's identity (or other custom text) as a watermark, satisfying the 'user-applied' and 'dynamic watermarking' requirements precisely.

Why this answer

The correct option is D: configure the sensitivity label itself to apply encryption and dynamic watermarking, then publish the label to users. In Microsoft Purview Information Protection, encryption and content marking (including watermarks) are protection settings defined on the sensitivity label, so when a user manually applies the 'Highly Confidential' label, those protections are enforced automatically. Publishing the label via a label policy makes it available in Office apps so users can apply it.

Option A is wrong because DLP policies act on sharing/transmission conditions rather than applying label-based encryption and watermarks at label time. Option B is wrong because auto-labeling applies labels based on content detection, not when a user manually selects a label. Option C is wrong because Conditional Access governs access to cloud resources, not document encryption or watermarking.

272
MCQhard

Your organization uses Microsoft Defender XDR to correlate alerts across endpoints, email, and identities. You need to create a custom detection rule that triggers when a user receives a phishing email and then attempts to log in from a new location. Which approach should you use?

A.Use Advanced Hunting to create a custom detection rule
B.Create a custom detection rule in Microsoft Defender for Endpoint
C.Use an automation rule in Microsoft Defender XDR
D.Create an analytics rule in Microsoft Sentinel
AnswerA

Advanced Hunting is the XDR-native KQL query interface spanning the unified Defender XDR data schema, including endpoint, email, identity, and cloud app tables. By saving an advanced hunting query as a custom detection rule, Defender XDR continuously evaluates cross-domain signals and generates alerts, making it the correct mechanism for correlating evidence from multiple sources.

Why this answer

Advanced Hunting in Microsoft Defender XDR allows you to write Kusto Query Language (KQL) queries that correlate events across multiple data tables (e.g., EmailEvents, IdentityLogonEvents). You can then create a custom detection rule from that query, which will trigger an alert when a user receives a phishing email and subsequently logs in from a new location, enabling cross-domain correlation within Defender XDR.

Exam trap

The trap here is that candidates often confuse the scope of custom detection rules in Defender for Endpoint (endpoint-only) with the cross-domain capability of Advanced Hunting in Defender XDR, or they mistakenly think automation rules can create new detection logic rather than just automate responses to existing alerts.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Endpoint custom detection rules are limited to endpoint data (e.g., DeviceEvents, DeviceProcessEvents) and cannot query email or identity events, so they cannot correlate a phishing email with a login from a new location. Option C is wrong because automation rules in Microsoft Defender XDR are designed to automate responses (e.g., isolate a device, block an IP) based on existing alerts, not to create new detection logic that correlates raw events across different data sources. Option D is wrong because analytics rules in Microsoft Sentinel are used for SIEM-style detection across multiple data sources ingested into Sentinel, but the question specifies using Microsoft Defender XDR (not Sentinel) to correlate alerts, and Sentinel requires separate licensing and data ingestion pipelines.

273
Multi-Selecthard

Your organization is implementing Microsoft Defender for Identity to protect on-premises Active Directory. Which THREE activities does Defender for Identity monitor?

Select 3 answers
A.Privilege escalation attempts
B.Lateral movement paths using Pass-the-Hash
C.File integrity changes on domain controllers
D.Reconnaissance attacks using LDAP queries
E.Network traffic to external IP addresses
AnswersA, B, D

Defender for Identity monitors domain controller traffic for privilege escalation attempts, detecting techniques such as adding accounts to privileged groups or exploiting unpatched escalation paths, which satisfies the stem's requirement to identify on-premises Active Directory attack activity.

Why this answer

Defender for Identity is designed to detect advanced threats against on-premises Active Directory by analyzing signals from domain controllers and AD FS. Option A is correct because it identifies privilege escalation attempts, such as unauthorized additions to privileged groups or abuse of AdminSDHolder, by monitoring directory changes and authentication events. Option B is correct because it detects lateral movement techniques like Pass-the-Hash by correlating NTLM authentication anomalies and suspicious logon patterns across domain controllers.

Option D is correct because it flags reconnaissance attacks that use LDAP queries to enumerate users, groups, and privileged accounts, which is a common precursor to AD attacks. Option C is not correct because file integrity monitoring on domain controllers is not a Defender for Identity capability; that is handled by other tools such as Microsoft Defender for Endpoint or File Integrity Monitoring in Defender for Cloud. Option E is not correct because Defender for Identity focuses on identity and directory signals rather than monitoring outbound network traffic to external IP addresses, which is covered by network security solutions.

Exam trap

SC-100 often tests the boundary between Defender for Identity (identity/AD attack detection) and Defender for Servers/Endpoint (file integrity, host monitoring) — candidates pick file integrity or network monitoring because those sound security-relevant but belong to other products.

274
MCQeasy

Your organization is deploying a new application on Azure Kubernetes Service (AKS). You need to ensure that only authorized containers can run in the cluster and that any unauthorized containers are automatically blocked. What should you configure?

A.Implement network policies to restrict communication between pods.
B.Apply an Azure Policy that restricts container images to only those from approved registries.
C.Enable Azure AD integration for the AKS cluster.
D.Configure Azure RBAC roles to limit who can deploy containers.
AnswerB

Azure Policy for AKS integrates with the Gatekeeper admission controller, enabling enforcement of built-in policies such as 'Ensure only allowed container images'. At pod creation or update time, the admission webhook evaluates each container's image repository and rejects any deployment that references a registry not on the approved list. This is a preventive control at the point of scheduling, directly addressing the requirement to restrict container images to approved registries only.

Why this answer

The correct option is B: applying an Azure Policy that restricts container images to only those from approved registries. Azure Policy for AKS uses the Gatekeeper admission controller to evaluate requests against policy definitions at admission time, so any pod or deployment referencing a non-approved image is automatically denied and blocked from running in the cluster. This directly enforces the requirement that only authorized containers can run.

Option A does not fit because network policies only control pod-to-pod traffic, not which images are allowed to run. Option C does not fit because Azure AD integration handles authentication of users to the cluster, not image authorization. Option D does not fit because Azure RBAC controls who can perform deployment actions, but it does not validate or block unauthorized container images.

275
Multi-Selecteasy

Which TWO features of Microsoft Defender for Cloud help you identify and remediate misconfigurations in your Azure environment? (Choose two.)

Select 2 answers
A.File integrity monitoring (FIM).
B.Security recommendations.
C.Just-in-time (JIT) VM access.
D.Adaptive application controls.
E.Secure score.
AnswersB, E

Security recommendations are Defender for Cloud's core mechanism for surfacing misconfigurations and insecure settings in supported resources, such as VMs, storage accounts, and databases. Each recommendation results from a policy-driven assessment against Azure Security Benchmark, CIS, or other standards, and includes affected resources, impact, and remediation steps. They directly answer the question 'what is misconfigured?' and are the underlying data that drives the secure score, making them the primary feature for identifying configuration errors.

Why this answer

Security recommendations (B) is correct because Microsoft Defender for Cloud continuously assesses Azure resources against built-in and regulatory benchmarks (e.g., Azure Security Benchmark, CIS, PCI DSS) and surfaces specific, actionable remediation steps for each misconfiguration it detects. Secure score (E) is correct because it aggregates the results of those assessments into a measurable score and highlights the highest-impact misconfigurations and improvement actions, letting you prioritize and track remediation progress over time. Together, recommendations identify the misconfigurations and secure score quantifies and prioritizes them.

File integrity monitoring (A) is wrong because FIM detects changes to critical OS files and registry keys on VMs, not Azure resource misconfigurations. Just-in-time VM access (C) is wrong because it reduces the attack surface by opening management ports only on demand, rather than identifying configuration issues. Adaptive application controls (D) is wrong because it uses machine-learning allowlists to control which applications can run on VMs, which is workload protection, not misconfiguration assessment.

276
MCQeasy

Refer to the exhibit. You are analyzing sign-in failures in Microsoft Sentinel using a KQL query. What does this query identify?

A.Accounts that have been locked out due to multiple failures.
B.Computers with more than 10 login attempts from the same IP address.
C.Accounts that had more than 10 failed logon attempts in the last 7 days.
D.Accounts that successfully logged in more than 10 times.
AnswerC

Event ID 4625 is generated for every failed logon attempt, and the query sums these records by account and computer, then applies a threshold of greater than 10 to the count within the last seven days. This yields accounts that exceeded ten failed logon attempts in that rolling window, which is exactly the indicated answer. The per-computer grouping means an account must exceed the threshold on a single computer, not across all computers taken together.

Why this answer

The correct answer is C: Accounts that had more than 10 failed logon attempts in the last 7 days. This is because the KQL query filters SigninLogs for failed sign-in results (e.g., ResultType != 0 or ResultType == 50126) and summarizes the count by user over a 7-day window, returning accounts whose failure count exceeds 10. Option A is wrong because account lockout is a specific event/status (e.g., ResultType 50053) and the query counts failures rather than lockout events.

Option B is wrong because the query aggregates by account, not by computer or source IP address. Option D is wrong because the query targets failed logons, not successful sign-ins.

277
Multi-Selecteasy

Which TWO Azure services should you use to implement a defense-in-depth strategy for protecting Azure virtual machines?

Select 2 answers
A.Network Security Groups (NSGs)
B.Azure Logic Apps
C.Azure Backup
D.Azure Automation
E.Azure Front Door
AnswersA, C

Network Security Groups (NSGs) are stateful packet-filtering controls that protect Azure virtual networks by enforcing allow/deny rules on inbound and outbound traffic to subnets and NICs. They operate at layers 3 and 4, matching source/destination IPs, ports, and protocols, with a default-deny rule at the end. NSGs provide essential network segmentation and perimeter defense, forming a fundamental preventive layer in a defense-in-depth strategy against lateral movement and unauthorized access.

Why this answer

Network Security Groups (NSGs) are correct because they enforce network-layer defense-in-depth by filtering inbound and outbound traffic to and from Azure VMs using allow/deny security rules based on source/destination IP, port, and protocol, effectively segmenting and restricting access at the subnet or NIC level. Azure Backup is correct because it provides the data-recovery layer of defense-in-depth, protecting VM data against accidental deletion, corruption, or ransomware by creating recoverable recovery points stored in a Recovery Services vault. Azure Logic Apps is not a security control for VMs; it is a workflow-orchestration service for integrating apps and automating business processes.

Azure Automation is a configuration-management and process-automation service (runbooks, DSC, update management) and does not itself provide a protective security boundary for VM traffic or data. Azure Front Door is a global layer-7 web application delivery and CDN/WAF service for HTTP/HTTPS workloads, not a mechanism for protecting Azure VMs directly.

278
MCQhard

You are a security architect for a large financial services company. The company has a hybrid identity environment with on-premises Active Directory synchronized to Microsoft Entra ID using Microsoft Entra Connect. They use Microsoft 365 E5 licenses and have deployed Microsoft Defender for Cloud, Microsoft Defender for Identity, Microsoft Sentinel, and Microsoft Purview. The company has recently suffered a ransomware attack where an attacker gained access via a compromised service account that had permanent Global Administrator privileges. The attacker then used the account to create a backdoor user and exfiltrate sensitive data from SharePoint Online. After the incident, the CISO mandates a Zero Trust security transformation with the following requirements: 1. Eliminate standing privileged access for all cloud admins. 2. Require phishing-resistant authentication for all privileged roles. 3. Ensure that all sensitive data in SharePoint Online is automatically classified and protected. 4. Enable detection of lateral movement using anomalous behavior analytics. Which combination of actions should you recommend?

A.Implement Privileged Identity Management (PIM) for Global Administrator roles, configure Authentication Strengths to require FIDO2, create auto-labeling policies for credit card numbers, and enable Defender for Identity lateral movement path detection.
B.Deploy Microsoft Entra Identity Protection for all users, configure Azure AD Conditional Access with MFA, use Microsoft Purview Information Protection with manual labeling, and enable Microsoft Sentinel analytics for lateral movement.
C.Configure Conditional Access to require MFA for admins, enable Microsoft Purview DLP for SharePoint, deploy Defender for Cloud Apps, and use Identity Protection for user risk.
D.Remove all permanent admin roles and use just-in-time access via PIM, enforce MFA via Conditional Access, apply sensitivity labels via Microsoft Purview Data Map, and use Microsoft Defender for Cloud for network security groups.
AnswerA

Privileged Identity Management removes standing Global Administrator access and activates roles just-in-time with approval, time limits, and audit trail, meeting the privileged access requirement. Configuring Authentication Strengths to require FIDO2 enforces phishing-resistant MFA specifically for activation and sign-in, satisfying the hardened MFA mandate. Auto-labeling policies for credit card numbers apply sensitivity labels automatically based on sensitive info types, ensuring data protection without manual effort. Defender for Identity lateral movement path detection analyzes entity activities to expose vulnerable paths attackers could exploit, fulfilling the lateral movement detection requirement.

Why this answer

It directly addresses all four CISO requirements: Privileged Identity Management (PIM) eliminates standing Global Administrator privileges by requiring just-in-time activation; Authentication Strengths with FIDO2 enforces phishing-resistant authentication for privileged roles; auto-labeling policies in Microsoft Purview automatically classify and protect sensitive data like credit card numbers in SharePoint Online; and Defender for Identity lateral movement path detection uses behavioral analytics to detect anomalous lateral movement, fulfilling the detection requirement.

Exam trap

The trap here is that candidates often confuse MFA (which can be phishable) with phishing-resistant authentication (e.g., FIDO2 or certificate-based), and they may overlook that automatic classification requires auto-labeling policies, not manual labeling or data discovery tools like Data Map.

How to eliminate wrong answers

Option B is wrong because it relies on manual labeling instead of automatic classification, which fails to meet the requirement for automatic protection of sensitive data in SharePoint Online; additionally, Identity Protection does not provide lateral movement detection. Option C is wrong because it only enforces MFA via Conditional Access, which is not phishing-resistant (e.g., it allows TOTP or phone call verification), and it lacks automatic data classification and lateral movement detection. Option D is wrong because it enforces MFA via Conditional Access instead of phishing-resistant authentication (e.g., FIDO2), and it uses Microsoft Defender for Cloud for network security groups, which does not address lateral movement detection; Purview Data Map is for data discovery, not automatic classification and protection.

279
MCQeasy

Your organization uses Microsoft Defender for Office 365 and wants to block malicious links in email messages in real time. Which policy should you configure?

A.Anti-phishing policy
B.Safe Attachments policy
C.Safe Links policy
D.Anti-spam policy
AnswerC

The Safe Links policy is the correct control because it directly handles malicious URLs by rewriting every link in email at the time of delivery and then performing a verdict check at the moment of click using Microsoft's threat intelligence. This time-of-click protection means that even if a URL was previously benign, it can be re-evaluated and blocked as soon as the user clicks. Safe Links extends beyond email to Teams, Office documents, and other supported workloads, making it the dedicated mechanism for URL-based threats.

Why this answer

Safe Links policy in Microsoft Defender for Office 365 provides real-time URL scanning and rewriting at the time of click, enabling the blocking of malicious links in email messages. This policy wraps URLs to route clicks through Microsoft's threat intelligence service, which checks the link against current threat data and blocks access if malicious content is detected.

Exam trap

The trap here is that candidates often confuse Safe Links with Safe Attachments, mistakenly thinking that attachment scanning covers embedded links, but Safe Attachments only handles file payloads, not URLs.

How to eliminate wrong answers

Option A is wrong because Anti-phishing policy is designed to protect against impersonation attacks and phishing attempts by analyzing sender identity and message content, not by scanning or blocking individual URLs in real time. Option B is wrong because Safe Attachments policy focuses on scanning email attachments for malware using detonation in a sandbox environment, not on inspecting links within the message body. Option D is wrong because Anti-spam policy filters messages based on bulk mail, spam, and spoofing criteria, and does not perform real-time URL blocking or rewriting.

280
MCQmedium

A company uses Microsoft Entra ID for identity management. They want to ensure that only managed devices can access corporate email. Which Conditional Access policy setting should be configured?

A.Require multifactor authentication
B.Block legacy authentication
C.Require approved client app
D.Require device to be marked as compliant
AnswerD

Requiring the device to be marked as compliant enforces that only managed, policy-conformant devices reach corporate email. Conditional Access evaluates device compliance state from Microsoft Entra ID, satisfying the constraint that unmanaged devices be blocked from Exchange Online.

Why this answer

To ensure only managed devices can access corporate email, you need to enforce device compliance. The Conditional Access policy setting 'Require device to be marked as compliant' checks that the device is enrolled in Microsoft Intune and meets all compliance policies (e.g., encryption, OS version, jailbreak detection) before granting access. This directly restricts access to managed devices only.

Exam trap

The trap here is that candidates often confuse 'Require device to be marked as compliant' with 'Require approved client app' or 'Require multifactor authentication,' thinking that MFA or app approval alone ensures device management, but only compliance enforcement ties directly to Intune-managed device policies.

How to eliminate wrong answers

Option A is wrong because requiring multifactor authentication (MFA) verifies the user's identity but does not enforce any device management or compliance; a personal device with MFA could still access email. Option B is wrong because blocking legacy authentication prevents protocols like POP3, IMAP, or SMTP that don't support modern authentication, but it does not ensure the device is managed or compliant; a managed device using legacy auth would still be blocked, but an unmanaged device using modern auth would not be blocked. Option C is wrong because requiring an approved client app (e.g., Outlook mobile) ensures the app is from a trusted source but does not enforce device management; an unmanaged device with the approved app could still access email.

281
MCQmedium

A company uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They want to prevent users from sharing credit card numbers in email but allow sharing via encrypted email. What should they configure?

A.Assign a sensitivity label that encrypts the email automatically
B.Create a Microsoft Purview Message Encryption policy
C.Configure a DLP rule that blocks sharing unless the email is encrypted, with user override
D.Use Exchange mail flow rules to block unencrypted credit card data
AnswerC

To enforce that unencrypted emails containing credit card data are blocked, you need a Microsoft Purview DLP rule. The rule can include the condition "Content contains" the sensitive info type for credit card numbers, and an action to "Block" the message if it is not encrypted, with an option to allow users to override the block for legitimate business needs. DLP integrates with Exchange Online to inspect the message in transit and conditionally allow encrypted messages as an exception, directly addressing the stated requirement, whereas proactive encryption strategies alone cannot guarantee compliance.

Why this answer

Microsoft Purview DLP can enforce a policy that blocks sharing of credit card numbers unless the email is encrypted, with a user override option to allow legitimate encrypted sharing. This directly meets the requirement to prevent unencrypted sharing while permitting encrypted email transmission, leveraging DLP's ability to inspect email content and conditionally apply actions based on encryption status.

Exam trap

The trap here is that candidates often confuse DLP's conditional encryption check with Message Encryption policies or mail flow rules, failing to recognize that DLP provides the specific 'unless the email is encrypted' condition and user override capability needed for this requirement.

How to eliminate wrong answers

Option A is wrong because assigning a sensitivity label that encrypts the email automatically does not provide a conditional mechanism to block unencrypted sharing; it would either always encrypt or require manual labeling, failing to prevent users from sending unencrypted credit card data. Option B is wrong because Microsoft Purview Message Encryption is a service that encrypts email messages but does not include DLP rules to block unencrypted sharing; it lacks the policy-driven conditional enforcement needed to prevent non-encrypted transmission. Option D is wrong because Exchange mail flow rules (transport rules) can block or encrypt messages based on patterns, but they do not natively integrate with DLP's sensitive information types for credit card numbers and lack the user override capability that DLP provides for justified business exceptions.

282
Multi-Selecthard

Which THREE of the following are valid ways to protect sensitive data in Microsoft 365 using Microsoft Purview? (Choose three.)

Select 3 answers
A.Sensitivity labels
B.Data Loss Prevention (DLP) policies
C.Data Lifecycle Management (retention policies)
D.Conditional Access policies
E.Microsoft Defender for Endpoint
AnswersA, B, C

Sensitivity labels are a data-centric protection mechanism in Microsoft Purview that classify documents and emails, then apply persistent protections such as encryption, rights management restrictions, and visual markings. These labels travel with the data (e.g., when shared externally), ensuring that protection remains enforced regardless of location or device, and they can be applied automatically based on classification rules, user recommendations, or admin-defined policies.

Why this answer

Sensitivity labels (A) are a core Microsoft Purview capability that let you classify and encrypt content with protection settings (e.g., encryption, content marking, and access restrictions) that travel with the data across Microsoft 365 workloads. Data Loss Prevention policies (B) in Microsoft Purview detect and block risky sharing of sensitive information (e.g., credit card or PII patterns) in Exchange Online, SharePoint, OneDrive, Teams, and endpoint locations, directly protecting data from exfiltration. Data Lifecycle Management retention policies (C) are also part of Microsoft Purview and protect sensitive data by retaining it for required periods and deleting it when no longer needed, reducing exposure and supporting compliance obligations.

Conditional Access (D) is a Microsoft Entra ID feature that governs sign-in and access conditions, not a Purview data-protection control, and Defender for Endpoint (E) is an endpoint security product rather than a Microsoft Purview data protection mechanism.

Exam trap

The trap here is that candidates often confuse Conditional Access policies (which control access) or Defender for Endpoint (which protects endpoints) with Purview's data protection capabilities, but neither directly classifies, encrypts, or prevents data loss at the content level.

283
MCQeasy

A company deploys Azure App Service with a custom domain and SSL certificate. They want to enforce HTTPS only. Which configuration setting should they enable?

A.HTTPS Only
B.Client Certificates
C.Minimum TLS Version
D.Custom Domain
AnswerA

HTTPS Only is an App Service flag that instructs the front-end load balancer to return a 301/302 redirect for any request arriving over plain HTTP on port 80, sending the client to the same URL with https://. This setting is evaluated before any application code or authentication middleware runs, so it guarantees that no request ever reaches the app unencrypted. It is the direct mechanism to satisfy a requirement that all HTTP traffic be redirected to HTTPS, and it works independently of whether a custom domain or a managed certificate is configured.

Why this answer

The 'HTTPS Only' setting in Azure App Service enforces that all incoming requests are redirected from HTTP to HTTPS, ensuring encrypted communication. This is achieved by returning a 301 redirect for any HTTP request, which aligns with the requirement to enforce HTTPS only.

Exam trap

The trap here is that candidates may confuse 'HTTPS Only' with 'Minimum TLS Version', thinking that setting a high TLS version also enforces HTTPS, but the latter only restricts the TLS protocol version without redirecting HTTP traffic.

How to eliminate wrong answers

Option B is wrong because 'Client Certificates' enables mutual TLS authentication, requiring clients to present a certificate, but does not enforce HTTPS-only traffic. Option C is wrong because 'Minimum TLS Version' controls the lowest TLS version allowed for incoming connections, but does not redirect HTTP to HTTPS. Option D is wrong because 'Custom Domain' is used to map a custom domain name to the app service, not to enforce HTTPS-only traffic.

284
MCQeasy

You are designing a secure data classification strategy for documents in Microsoft 365. The compliance officer wants to automatically apply a 'Confidential' label to documents containing credit card numbers. Which Microsoft Purview feature should you use?

A.Auto-labeling policies
B.Data loss prevention policies
C.Trainable classifiers
D.Manual labeling
AnswerA

Auto-labeling policies in Microsoft Purview can automatically assign sensitivity labels to files and emails when their content matches built-in sensitive info types, such as credit card numbers, at a specified confidence or instance count. These policies run service-side on Exchange, SharePoint, and OneDrive, meaning content is evaluated by the service without requiring a user to open or interact with it. A policy simulation mode lets you test which items would be labeled before enforcing the rule, and once applied, the label can trigger protective actions like encryption. This directly meets the requirement of automatically applying labels based on predefined sensitive data patterns.

Why this answer

Auto-labeling policies (option A) are the correct choice because they are the Microsoft Purview feature designed to automatically apply sensitivity labels to content that matches specified conditions, such as documents containing credit card numbers detected via sensitive information types. This directly satisfies the compliance officer's requirement to apply a 'Confidential' label automatically without user intervention. Data loss prevention policies (B) can detect and block or warn about sensitive content but do not apply sensitivity labels.

Trainable classifiers (C) can identify content categories by example, but they are used as conditions within labeling or DLP, not as the labeling mechanism itself. Manual labeling (D) requires users to apply labels themselves, which does not meet the automation requirement.

285
MCQeasy

You are designing a security operations strategy for a multinational organization. The SOC team needs to correlate alerts from multiple sources including Microsoft Defender for Cloud, Microsoft Sentinel, and third-party firewalls. Which solution should you use as the primary platform for correlation?

A.Microsoft Defender for Cloud
B.Microsoft 365 Defender
C.Azure Monitor
D.Microsoft Sentinel
AnswerD

Microsoft Sentinel is the correct choice because it is a cloud-native SIEM and SOAR platform purpose-built for security operations. It ingests logs from 100+ connectors across Azure, Microsoft 365, third-party security products, on-premises infrastructure, and open-source formats, then uses KQL-based analytics rules and built-in detections to correlate signals into incidents. Sentinel also automates response via playbooks, making it the central multi-source correlation and incident management engine that the other services are not.

Why this answer

Microsoft Sentinel (option D) is the correct choice because it is a cloud-native SIEM and SOAR platform designed to ingest, correlate, and analyze security alerts and logs from many sources, including Microsoft Defender for Cloud, Microsoft Sentinel-connected services, and third-party firewalls via data connectors and CEF/Syslog. It provides built-in analytics rules, KQL-based hunting, and incident correlation across multicloud and multiplatform telemetry, which matches the SOC's need for a central correlation platform. Microsoft Defender for Cloud (option A) is a cloud security posture management and workload protection service, not a cross-source SIEM correlation platform.

Microsoft 365 Defender (option B) correlates signals primarily across Microsoft 365 and Defender workloads, not third-party firewall telemetry as the primary platform. Azure Monitor (option C) is an infrastructure and application monitoring service, not a security incident correlation SIEM.

286
MCQmedium

A company is migrating its on-premises Active Directory to Microsoft Entra ID. They need to ensure that all user authentication for cloud apps uses passwordless methods. Which security best practice should they implement?

A.Implement Microsoft Entra ID passwordless authentication
B.Configure conditional access policies to block legacy authentication
C.Enable Microsoft Entra ID Privileged Identity Management (PIM)
D.Require multifactor authentication (MFA) for all users
AnswerA

Implementing Microsoft Entra ID passwordless authentication replaces the password with a cryptographic key pair bound to the user's device or a FIDO2 security key. Methods such as Windows Hello for Business, FIDO2 security keys, or the Microsoft Authenticator app's passwordless mode allow authentication through a biometric gesture or PIN, with the private key never leaving the device. This directly eliminates the shared-secret model that attackers can phish or replay, and it aligns with Zero Trust by verifying possession and intent without ever transmitting a password over the network.

Why this answer

The company's requirement is specifically to ensure all user authentication for cloud apps uses passwordless methods. Microsoft Entra ID passwordless authentication (e.g., Windows Hello for Business, FIDO2 security keys, or Microsoft Authenticator) directly eliminates passwords from the authentication flow, aligning with the stated goal. Other options, while enhancing security, do not enforce passwordless authentication.

Exam trap

The trap here is that candidates often confuse 'blocking legacy authentication' or 'requiring MFA' with achieving passwordless authentication, but neither eliminates the password as a factor; only a dedicated passwordless method does.

How to eliminate wrong answers

Option B is wrong because blocking legacy authentication (e.g., POP3, IMAP, SMTP) prevents older protocols that cannot enforce modern authentication, but it does not mandate passwordless methods; users could still authenticate with passwords via modern protocols. Option C is wrong because Microsoft Entra ID Privileged Identity Management (PIM) provides just-in-time privileged access management and does not address user authentication methods for cloud apps. Option D is wrong because requiring multifactor authentication (MFA) adds a second factor but still allows password-based authentication as the first factor, failing to meet the passwordless requirement.

287
MCQeasy

Your organization uses Microsoft Intune to manage endpoints. The security team wants to ensure that devices that cannot be enrolled in Intune (e.g., unmanaged BYOD devices) are still subject to security policies when accessing corporate resources. Which Microsoft Entra ID feature should you use?

A.Microsoft Entra Conditional Access policies
B.Microsoft Intune enrollment policies
C.Windows Defender Application Control
D.Microsoft Defender for Endpoint
AnswerA

Microsoft Entra Conditional Access is the correct policy layer because it acts as the decision engine that evaluates the full signal stack—user, application, device compliance, location, and risk—to enforce access controls like requiring MFA, requiring a compliant device, or blocking unmanaged endpoints. Under the hood, Conditional Access policies can leverage Intune compliance rules as one input, but its true power is that it applies globally to every device (managed or not) and runs before tokens are issued. Unlike Intune enrollment or MDE, it is the authoritative gatekeeper that translates 'is this device managed and compliant?' into an allow/deny decision.

Why this answer

Microsoft Entra Conditional Access policies (option A) are correct because they evaluate signals such as user, device state, and location at authentication time and can enforce controls like requiring MFA or compliant devices even for unmanaged BYOD endpoints that cannot be enrolled in Intune. Conditional Access can block or restrict access to corporate resources for devices that don't meet policy, which directly addresses the scenario. Intune enrollment policies (B) only apply to devices being enrolled and cannot govern unenrolled devices.

Windows Defender Application Control (C) is an application control mechanism on Windows endpoints, not an access policy for corporate resources. Microsoft Defender for Endpoint (D) is an endpoint detection and response platform, not the feature that enforces access policy for unmanaged devices.

288
MCQmedium

Your company uses Microsoft Intune to manage mobile devices. You need to ensure that corporate data in Microsoft 365 apps cannot be copied to personal apps on the same device. What should you configure?

A.App protection policy (MAM) with 'Restrict cut, copy, and paste'
B.Conditional Access policy requiring compliant device
C.Device configuration profile with restrictions
D.Device compliance policy for mobile devices
AnswerA

App protection policy (MAM) with 'Restrict cut, copy, and paste' is correct because it applies at the application layer, targeting the clipboard as a data-channel control. This setting explicitly defines which apps can receive data copied from a managed app, typically allowing only other managed apps. It is effective even on unenrolled BYOD devices because it operates through the Intune App SDK/wrapped apps, not through device management. Unlike Conditional Access or device policies, this granular DLP control directly governs data transfer between managed and unmanaged apps.

Why this answer

The correct answer is A: an App protection policy (MAM) with 'Restrict cut, copy, and paste'. App protection policies in Intune operate at the app layer, so they can block copying corporate data from Microsoft 365 apps into personal apps on the same device, even on unmanaged or BYOD devices. This directly addresses the requirement to prevent data leakage between managed and personal apps.

Option B (Conditional Access requiring a compliant device) controls access to resources but does not prevent copy/paste between apps. Option C (device configuration profile with restrictions) applies device-level settings and cannot selectively govern app-to-app data sharing. Option D (device compliance policy) only evaluates and reports device state; it does not enforce app-level copy/paste restrictions.

289
MCQeasy

Refer to the exhibit. You need to ensure that the storage account 'seccorpstorage' is only accessible from a specific Azure virtual network. What should you do?

A.Add a virtual network rule for the specific VNet
B.Enable the service endpoint for Microsoft.Storage on the VNet subnet
C.Enable firewall and add an IP rule for the VNet's public IP
D.Enable public network access and add a firewall rule
AnswerA

Adding a virtual network rule for the specific VNet is the correct action because it explicitly authorizes traffic from that VNet's subnet(s) to the storage account. When the storage firewall is set to 'Selected networks', all traffic is denied by default, and a VNet rule carves out an exception that allows inbound requests from the trusted VNet only. This aligns with the requirement to restrict access to a single VNet while keeping public network access disabled.

Why this answer

The correct answer is A: Add a virtual network rule for the specific VNet. In Azure Storage, network access restrictions are configured on the storage account's Networking blade, where you can add virtual network rules that allow access only from selected VNets and subnets; this directly satisfies the requirement that 'seccorpstorage' be accessible only from a specific Azure virtual network. Option B is incomplete because enabling the Microsoft.Storage service endpoint on the subnet is a prerequisite that makes the subnet eligible, but the storage account still needs the corresponding virtual network rule to actually restrict access.

Option C is wrong because an IP-based firewall rule uses public IP addresses and does not restrict access to a specific VNet's private traffic. Option D is wrong because enabling public network access opens the account to public connectivity rather than limiting it to one VNet.

290
MCQhard

Your organization uses Microsoft Sentinel to aggregate logs from on-premises and cloud sources. You need to reduce the cost of data ingestion while ensuring security-critical logs are retained for at least one year. What should you do?

A.Archive all logs to Azure Storage after 90 days
B.Ingress security-critical logs to the Analytics logs tier with 365-day retention, and other logs to the Auxiliary logs tier with shorter retention
C.Use the Basic logs tier for all logs and set retention to 365 days
D.Set the default retention to 30 days and export logs to Log Analytics Workspace
AnswerB

This hybrid approach directly addresses the one-year retention requirement while optimizing cost. Security-critical logs reside in the Analytics tier, which supports full KQL, advanced hunting, detections, and 365-day retention, ensuring no loss of investigative power. The Auxiliary logs tier, introduced for verbose telemetry, offers lower ingestion cost and basic query functionality for non-critical data, letting you retain comprehensive logs without overpaying. This separation balances compliance, performance, and budget far better than a one-size-fits-all strategy.

Why this answer

Use the Analytics logs tier for security-critical logs because it provides full KQL query capabilities and supports setting 365-day retention to meet compliance. For other logs, use the Auxiliary logs tier (or Basic logs) to reduce ingestion costs while accepting shorter retention and limited query capabilities. This tiered approach balances cost and security requirements.

Exam trap

Candidates often think that using the Basic logs tier (or Auxiliary logs) for all logs is a cost-saving measure, but this fails to ensure that security-critical logs retain full query capability and long retention. The correct approach is to apply tiered retention based on log importance.

How to eliminate wrong answers

Option A is wrong because archiving all logs to Azure Storage after 90 days would remove them from Sentinel's queryable workspace, preventing real-time security monitoring and alerting on older logs, and does not guarantee one-year retention for security-critical logs. Option C is wrong because using the Basic logs tier for all logs limits query capabilities (no full KQL support) and incurs higher costs for security-critical logs that require Analytics-tier features; setting retention to 365 days on Basic logs does not address cost optimization for non-critical logs. Option D is wrong because setting default retention to 30 days and exporting logs to Log Analytics Workspace is redundant (Log Analytics Workspace is the same as Sentinel workspace) and does not reduce ingestion costs; it also fails to ensure security-critical logs are retained for one year without additional configuration.

291
MCQeasy

You are designing a solution to protect an Azure App Service web application from common web attacks like SQL injection and cross-site scripting. What should you implement?

A.Azure Firewall
B.Azure DDoS Protection
C.Azure Web Application Firewall (WAF) policy on Azure Front Door
D.Network Security Groups (NSGs) on the subnet
AnswerC

A WAF policy on Azure Front Door inspects HTTP traffic at the edge, applying managed rule sets that block SQL injection and cross-site scripting before requests reach App Service, satisfying the requirement to protect against common web attacks.

Why this answer

Azure Web Application Firewall (WAF) policy on Azure Front Door (option C) is correct because WAF is specifically designed to inspect HTTP/HTTPS traffic and block Layer 7 attacks such as SQL injection and cross-site scripting using managed rule sets (OWASP rules). Azure Front Door provides global edge delivery and integrates WAF policies directly, making it the appropriate choice for protecting a public web application. Azure Firewall (A) is a Layer 3-4 network firewall with limited FQDN filtering and does not provide OWASP-style web attack protection.

Azure DDoS Protection (B) mitigates volumetric and protocol-level attacks, not application-layer injection or scripting attacks. NSGs (D) filter traffic by IP, port, and protocol at the network layer and cannot inspect HTTP payloads for SQLi or XSS.

292
MCQmedium

A company is designing a defense-in-depth strategy for their Azure environment. They want to ensure that if a virtual machine is compromised, the attacker cannot move laterally to other VMs in the same virtual network. Which security control should they prioritize?

A.Enable Azure DDoS Protection on the virtual network
B.Implement network segmentation using NSGs and application security groups
C.Enable multi-factor authentication (MFA) for all admin accounts
D.Deploy Azure Bastion for secure remote access
AnswerB

Implementing network segmentation with Network Security Groups (NSGs) and Application Security Groups (ASGs) explicitly controls east-west traffic by enforcing allow-listed rules based on workload roles, protocols, and ports. NSGs act as distributed firewalls at the subnet and NIC level, while ASGs simplify grouping VMs by function (e.g., web, app, data) so you can deny all traffic by default and permit only required inter-tier flows. This zero-trust network approach directly limits an attacker's ability to move laterally from a compromised VM to other resources, making it the correct defense-in-depth measure for this threat.

Why this answer

Network segmentation using NSGs and application security groups is the correct priority because it directly controls east-west traffic between VMs within the same virtual network. By defining explicit inbound and outbound rules that restrict communication to only necessary ports and protocols (e.g., TCP 443 for HTTPS), an attacker who compromises one VM cannot initiate lateral movement to other VMs, as the NSG will drop unauthorized traffic at the subnet or NIC level.

Exam trap

The trap here is that candidates often confuse network-level controls (NSGs) with identity or access controls (MFA, Bastion) or perimeter defenses (DDoS Protection), failing to recognize that lateral movement is a network traffic problem that requires explicit east-west traffic filtering.

How to eliminate wrong answers

Option A is wrong because Azure DDoS Protection protects against volumetric attacks from the internet, not against lateral movement from a compromised VM inside the same virtual network. Option C is wrong because MFA protects authentication to the Azure portal or management plane, but does not prevent an attacker who already has a foothold on a VM from moving laterally via network traffic. Option D is wrong because Azure Bastion provides secure RDP/SSH access to VMs without exposing public IPs, but once a VM is compromised, Bastion does not restrict the attacker's ability to initiate outbound connections to other VMs in the same network.

293
MCQeasy

Your organization uses Microsoft Purview to govern data assets across Azure and on-premises. You need to automatically classify sensitive data such as credit card numbers in Azure SQL Database. What should you use?

A.Microsoft Purview Data Map
B.Microsoft Defender for Cloud
C.Microsoft Entra ID
D.Microsoft Sentinel
AnswerA

The Microsoft Purview Data Map is the correct choice because it performs automated scans of registered data sources, applying built-in and custom classifiers to identify sensitive content such as PII and financial data, and then publishing those classifications as business assets. It also integrates with sensitivity labels from Microsoft Purview Information Protection, giving a centralized, governed map of your data estate for classification and lineage. No other Azure service directly scans and classifies data at this asset level.

Why this answer

Microsoft Purview Data Map is the correct choice because it is the component that scans and automatically classifies data sources such as Azure SQL Database, detecting sensitive information types like credit card numbers and applying classifications. It builds the metadata catalog and applies built-in or custom classification rules during scans, which is exactly what's needed for automated sensitive-data discovery. Microsoft Defender for Cloud provides security posture management and threat protection, not data classification.

Microsoft Entra ID handles identity and access management, and Microsoft Sentinel is a SIEM/SOAR solution for security analytics, so neither performs data classification.

294
Multi-Selecthard

Which THREE actions should you take to secure a CI/CD pipeline using Azure DevOps and GitHub?

Select 3 answers
A.Enable secret scanning in GitHub to detect leaked credentials
B.Run all pipeline tasks with administrative privileges
C.Disable pull request code reviews to speed deployment
D.Store secrets in Azure Key Vault and use variable groups linked to Key Vault
E.Configure branch protection rules in GitHub to require status checks
AnswersA, D, E

GitHub secret scanning automatically detects known patterns of credentials such as Azure Active Directory client secrets, AWS access keys, and private keys within repository content. When a match is found, GitHub alerts the organization or individual, and optionally integrates with secret scanning partners to revoke the leaked credential. This proactive detection helps prevent accidental exposure of secrets that could be used for unauthorized access, but it should be part of a broader strategy that includes preventing secrets from entering repos in the first place.

Why this answer

Option A is correct because enabling secret scanning in GitHub automatically detects committed credentials such as API keys and tokens, allowing them to be revoked before they can be exploited in the pipeline. Option D is correct because storing secrets in Azure Key Vault and referencing them through variable groups linked to Key Vault keeps credentials out of pipeline YAML and repository history, enforcing centralized access control and auditing. Option E is correct because branch protection rules in GitHub that require status checks prevent unreviewed or failing code from being merged, ensuring only validated commits reach the CI/CD pipeline.

Option B is incorrect because running all pipeline tasks with administrative privileges violates least privilege and expands the blast radius of a compromised task. Option C is incorrect because disabling pull request code reviews removes a critical human verification gate and increases the risk of malicious or flawed code being deployed.

295
MCQmedium

Refer to the exhibit. You are reviewing a Conditional Access policy JSON. What is the effect of this policy?

A.Blocks sign-ins from locations with high sign-in risk
B.Blocks sign-ins from users with high user risk
C.Blocks all sign-ins from any user
D.Requires multifactor authentication for high-risk users
AnswerB

This is the correct interpretation: the policy sets the 'User risk' condition to 'High' and the access control to 'Block.' When a user's risk level, as determined by Microsoft Entra ID Protection detections, is high, the conditional access engine denies the sign-in attempt. Thus, the policy's effective behavior is to block sign-ins from users with high user risk.

Why this answer

The policy JSON specifies `"userRiskLevels": ["high"]` under the conditions block, which means it targets only users whose user risk level is assessed as high by Microsoft Entra ID Protection. The grant control is set to `"builtInControls": ["block"]`, so the policy blocks sign-ins for those high-risk users. Option B is correct because the policy explicitly blocks sign-ins from users with high user risk, not sign-in risk or all users.

Exam trap

Microsoft often tests the distinction between `userRiskLevels` and `signInRiskLevels` in Conditional Access policies, and candidates frequently confuse the two, thinking a high user risk policy blocks sign-in risk events rather than user account risk.

How to eliminate wrong answers

Option A is wrong because the policy uses `userRiskLevels`, not `signInRiskLevels`; sign-in risk levels are a separate property in Conditional Access policies that assess the risk of a specific authentication attempt, not the user account. Option C is wrong because the policy has a condition targeting only high user risk levels, not all users; a block-all policy would omit the risk level condition or use an empty conditions block. Option D is wrong because the grant control is `"block"`, not `"mfa"`; requiring multifactor authentication would use `"mfa"` in the builtInControls array, and the policy does not include any authentication requirement.

296
Multi-Selecthard

Which THREE components are required to implement a secure hybrid network architecture using Azure VPN Gateway? (Choose three.)

Select 3 answers
A.A local network gateway resource in Azure.
B.A connection resource with a shared key.
C.An ExpressRoute circuit.
D.A virtual network gateway in Azure.
E.An Azure Firewall.
AnswersA, B, D

The local network gateway is a logical Azure object that points to your on-premises VPN device by its public IP address and defines the on-premises address space(s) that Azure should advertise over the tunnel. Without it, the Azure virtual network gateway has no remote endpoint to establish an IPsec session with, nor any knowledge of which on-premises routes should be reachable. It is therefore a mandatory configuration item for a Site-to-Site VPN.

Why this answer

Option A (a local network gateway resource in Azure) is required because it defines the on-premises VPN device's public IP address and address spaces, which Azure uses as the remote endpoint for the site-to-site tunnel. Option B (a connection resource with a shared key) is required because the connection object links the virtual network gateway to the local network gateway and carries the pre-shared key (PSK) used for IKE/IPsec authentication. Option D (a virtual network gateway in Azure) is required because it is the Azure-side VPN Gateway (VpnGw SKU) that terminates the IPsec/IKE tunnel and routes traffic into the virtual network.

Option C (an ExpressRoute circuit) does not belong because ExpressRoute is a private dedicated-circuit connectivity model, not a VPN Gateway component, and the scenario specifies VPN Gateway. Option E (an Azure Firewall) does not belong because it is a managed network security service for traffic filtering and is not a prerequisite for establishing a VPN Gateway site-to-site connection.

297
MCQmedium

A company uses Microsoft Intune and wants to ensure that devices are compliant before accessing corporate resources. They create a Conditional Access policy that requires devices to be marked as compliant. However, some users report that they are blocked even though their device shows as compliant in Intune. What is the most likely cause?

A.The user's location is blocked by a location-based policy
B.The policy also requires MFA, and users haven't registered for MFA
C.The device is not registered in Microsoft Entra ID
D.The policy requires an app protection policy, which is not applied
AnswerC

For Conditional Access to require a compliant device, the device must have an identity object in Microsoft Entra ID—either through Microsoft Entra join, hybrid join, or enrollment in Intune as a registered device. Intune's compliance policy is applied to that device identity, and the resulting compliance status is stored as an attribute in Entra ID that Conditional Access can read. Without registration, the device is completely invisible to the compliance evaluation, so the policy marks it as not compliant and blocks access.

Why this answer

The correct answer is C: the device is not registered in Microsoft Entra ID. Conditional Access evaluates device compliance using the device identity and compliance state that Intune writes back to Microsoft Entra ID, so if the device object is not registered (or not properly joined/registered) in Entra ID, the 'Require device to be marked as compliant' grant control cannot be satisfied even if Intune shows the device as compliant. Options A and B describe other possible blocks (location policy or MFA registration), but they do not explain the mismatch between Intune compliance and Conditional Access blocking.

Option D is also not the most likely cause because an app protection policy requirement is a separate grant control and would not typically contradict a device already showing compliant in Intune.

298
MCQeasy

Your organization is deploying Microsoft Intune to manage Windows 11 devices. You need to ensure that devices automatically receive security updates and that users cannot defer updates. Which configuration profile setting should you configure?

A.Create a device configuration profile to enable automatic updates.
B.Create a Windows 10/11 Update Rings policy with a deadline for quality and feature updates.
C.Create a compliance policy that requires the device to have the latest updates installed.
D.Create an endpoint security policy for Windows Defender Antivirus to enforce update installation.
AnswerB

A Windows 10/11 Update Rings policy in Intune is the correct tool because it maps directly to Windows Update for Business settings, allowing you to configure deferral periods for quality and feature updates, set installation deadlines, and define grace periods. Deadlines force the device to install updates after the specified period even if the user has delayed them, ensuring automatic installation. This is the only option that controls the actual update scheduling behavior rather than just checking or reporting on it.

Why this answer

The correct option is B: a Windows 10/11 Update Rings policy with a deadline for quality and feature updates. Update Rings in Intune are the purpose-built mechanism for controlling Windows Update behavior on managed devices, and configuring a deadline forces installation of quality and feature updates by a set time, preventing users from deferring them indefinitely. Option A is too vague and device configuration profiles do not provide the update-ring deadline enforcement needed here.

Option C only evaluates and reports compliance; it does not install updates or block deferrals. Option D concerns Defender Antivirus security settings, not Windows Update ring scheduling or deadlines.

299
MCQmedium

A company uses Microsoft Sentinel for security operations. The SOC team needs to automatically respond to a specific type of incident involving a known malicious IP address. They want to create an automated response that blocks the IP at the firewall and creates a Teams notification. Which feature should they use?

A.UEBA to detect anomalous behavior
B.Watchlist to correlate IP addresses
C.Automation rule with a playbook
D.Analytics rule with scheduled query
AnswerC

An automation rule in Microsoft Sentinel is the correct mechanism to automate response actions because it evaluates incident triggers or alert creation and then executes a set of configured actions, which can include running a playbook. Playbooks are built on Azure Logic Apps and can perform complex, orchestrated tasks like blocking a user, sending emails to stakeholders, opening a ticket, or gathering additional evidence—all without manual intervention. This directly fulfills the requirement to automatically respond to a security incident by turning detection results into immediate, actionable remediation steps.

Why this answer

Automation rules in Microsoft Sentinel allow you to trigger automated responses when incidents are created or updated. By associating a playbook (an Azure Logic Apps workflow) with the automation rule, you can execute actions such as blocking an IP at a firewall via a connector and posting a Teams notification. This directly meets the requirement for a two-step automated response triggered by a specific incident type.

Exam trap

The trap here is that candidates confuse the role of analytics rules (which generate incidents) with automation rules (which respond to incidents), leading them to choose option D, thinking a scheduled query can directly execute actions, whereas it only creates alerts or incidents.

How to eliminate wrong answers

Option A is wrong because UEBA (User and Entity Behavior Analytics) is used to detect anomalous behavior based on historical baselines, not to trigger automated responses to known malicious IPs. Option B is wrong because a Watchlist is a static or dynamic list of data (e.g., IP addresses) used for correlation in analytics rules or queries, but it does not itself execute automated actions like blocking or notifications. Option D is wrong because an analytics rule with a scheduled query generates alerts or incidents based on log data, but it cannot directly run multi-step automated responses; it requires an automation rule or playbook to act on the incident.

300
MCQhard

You are the security architect for a large financial services company. The company has a hybrid environment with on-premises Active Directory, Azure AD, and multiple Azure subscriptions. They use Microsoft Sentinel as their SIEM and have deployed Microsoft Defender for Cloud to assess their cloud security posture. Recently, the security team discovered that a critical Azure SQL database was exposed to the internet with a firewall rule allowing 'AllowAllWindowsAzureIps'. This misconfiguration was not flagged by Defender for Cloud because the corresponding recommendation was disabled in the security policy. The company wants to prevent such misconfigurations in the future and ensure that all critical resources are covered by security recommendations. They also need to ensure that any changes to security policies are reviewed and approved. Which of the following actions should you recommend as the most comprehensive solution?

A.Review and enable all relevant security recommendations in Defender for Cloud, and implement a change management process using Azure Policy and a custom workflow that requires approval before modifying security policies.
B.Deploy Azure Monitor alerts on all SQL Server firewall rule changes and instruct the security team to manually review each change.
C.Assign the Contributor role to the security team on the subscription so they can directly modify firewall rules if needed.
D.Enable the specific recommendation for SQL Server firewall rules in Defender for Cloud and set up an automation rule to send alerts when the recommendation is triggered.
AnswerA

Reviewing and enabling all relevant Defender for Cloud security recommendations establishes a comprehensive security baseline across the subscription, ensuring misconfigurations such as exposed SQL firewall rules are proactively identified and remediated. Pairing this with a change management process built on Azure Policy and a custom approval workflow enforces governance, so any modification to security policies requires audited, authorized action—directly addressing the root cause of disabled recommendations rather than reacting to individual incidents.

Why this answer

It addresses the root cause—disabled security recommendations—by enabling all relevant recommendations in Defender for Cloud, and it enforces a change management process using Azure Policy with a custom approval workflow. This ensures that any modifications to security policies are reviewed and approved, preventing future misconfigurations like the 'AllowAllWindowsAzureIps' rule from going unnoticed. The combination of policy enforcement and approval workflow provides a comprehensive, automated governance layer that covers both detection and prevention.

Exam trap

The trap here is that candidates often focus on a single technical fix (like enabling a recommendation or setting an alert) rather than recognizing the need for a comprehensive governance solution that combines policy enforcement with a change management approval process to prevent and detect misconfigurations across all critical resources.

How to eliminate wrong answers

Option B is wrong because Azure Monitor alerts on firewall rule changes only provide reactive notifications; they do not prevent misconfigurations or ensure that security policies are reviewed and approved, leaving the manual review process prone to human error and delays. Option C is wrong because assigning the Contributor role to the security team grants them broad permissions to modify firewall rules directly, which increases the risk of unauthorized or accidental changes without any approval gate, contradicting the requirement for reviewed and approved changes. Option D is wrong because enabling only the specific recommendation for SQL Server firewall rules and setting up automation alerts is a narrow, reactive fix that does not address the broader need to ensure all critical resources are covered by security recommendations, nor does it implement a change management process for policy modifications.

Page 3

Page 4 of 9

Page 5

All pages