Courseiva

Microsoft Cybersecurity Architect (SC-100) — Questions 301–375

605 questions total · 9pages · All types, answers revealed

Page 4

Page 5 of 9

Page 6
301
MCQmedium

A company uses Microsoft Entra ID and wants to enable passwordless authentication for all users to reduce phishing risks. Users are already using Microsoft Authenticator for MFA. Which passwordless method should you prioritize?

A.Windows Hello for Business
B.FIDO2 security keys
C.Certificate-based authentication
D.Microsoft Authenticator passwordless sign-in
AnswerD

Microsoft Authenticator passwordless sign-in is the correct answer because it leverages the same mobile app already widely used for multi-factor authentication, requiring no extra hardware or PKI. The user simply enters their username and then approves a push notification on their phone, sometimes matching a number, while the phone's biometric or PIN validates the physical presence. This provides a phishing-resistant, strong authentication experience that works across Android and iOS, and because it reuses an existing app, user adoption is high and deployment is straightforward.

Why this answer

The organization already uses Microsoft Authenticator for MFA, making the transition to passwordless sign-in via Authenticator the most seamless and cost-effective path. This method leverages the existing app registration and push notification infrastructure, allowing users to authenticate with a biometric or PIN gesture without deploying additional hardware or certificates.

Exam trap

The trap here is that candidates may choose Windows Hello for Business (A) because it is a common passwordless option, but they overlook the requirement that it only works on Windows devices, not for all users across platforms.

How to eliminate wrong answers

Option A is wrong because Windows Hello for Business requires Windows devices and is not universally applicable to all users (e.g., mobile or non-Windows users). Option B is wrong because FIDO2 security keys require purchasing and distributing physical hardware, which adds cost and logistical overhead not justified when Authenticator is already deployed. Option C is wrong because certificate-based authentication requires a public key infrastructure (PKI) and certificate enrollment, which is more complex to deploy and manage than leveraging the existing Authenticator app.

302
MCQmedium

Your organization is deploying Microsoft Defender for Cloud Apps. You need to create a policy that blocks downloads of sensitive files from sanctioned cloud apps to unmanaged devices. What type of policy should you create?

A.Session policy
B.App discovery policy
C.Anomaly detection policy
D.Access policy
AnswerA

Session policies in Microsoft Defender for Cloud Apps operate in real time via a reverse proxy to enforce granular conditional access actions on a user's session. They can explicitly block downloads, uploads, and copy/paste based on risk signals such as device posture or user behavior, making them the correct policy type for preventing data exfiltration.

Why this answer

A session policy (option A) is correct because in Microsoft Defender for Cloud Apps, session policies are used with Conditional Access App Control to monitor and control user sessions in real time, including blocking downloads of sensitive files from sanctioned cloud apps to unmanaged devices. Session policies can apply actions such as block download, protect, or block based on the sensitivity of the content and the device state. App discovery policies (option B) are used to identify and assess shadow IT and unsanctioned apps, not to control file downloads in real time.

Anomaly detection policies (option C) trigger alerts on unusual user behavior but do not enforce download blocking. Access policies (option D) in Defender for Cloud Apps are used to allow or block sign-ins to apps based on conditions, not to control in-session file download activity.

303
MCQeasy

A company plans to use Microsoft Defender for Cloud to secure a multi-cloud environment including Azure, AWS, and GCP. What is the first step to enable multi-cloud visibility?

A.Enable all Defender plans for subscription
B.Connect AWS and GCP accounts using the cloud connectors in Defender for Cloud
C.Create custom compliance policies
D.Deploy Azure Arc agents on all cloud VMs
AnswerB

The Defender for Cloud multi-cloud connectors establish the onboarding bridge between Azure and AWS or GCP, synchronizing security configurations, threat indicators, and resource inventory into the unified Azure dashboard. This connector-level integration, which leverages read-only credentials from the foreign cloud, is the mandatory first step because all subsequent security policies, recommendations, and Defender plan coverage depend on the cloud accounts being visible to Azure. Without this connector, Defender for Cloud has no access to the AWS or GCP workloads.

Why this answer

The correct answer is B: connect AWS and GCP accounts using the cloud connectors in Defender for Cloud. Defender for Cloud's native multi-cloud support requires onboarding non-Azure environments through the AWS and GCP connectors, which establish the necessary trust and inventory so that resources, recommendations, and alerts from those clouds become visible in the portal. Only after this connection can Defender plans, compliance policies, or agent-based extensions be applied to those resources.

Option A is premature because enabling subscription-level Defender plans only affects Azure resources, not AWS or GCP. Option C is a later configuration step that depends on data already being collected, and Option D is not the onboarding mechanism for multi-cloud visibility, since Azure Arc is used for connecting specific servers rather than enabling cloud-wide AWS/GCP visibility.

304
MCQeasy

Your company uses Microsoft Sentinel as a SIEM. You need to ensure that all Azure subscription activity logs are ingested into Sentinel. What is the most efficient way to configure this?

A.Configure diagnostic settings on the subscription to send logs to a Log Analytics workspace.
B.Create an Azure Logic App to periodically pull activity logs.
C.Enable the 'Azure Activity' data connector in Sentinel.
D.Manually export activity logs to a storage account and connect to Sentinel.
AnswerC

Enabling the Azure Activity data connector in Microsoft Sentinel automatically configures the required diagnostic settings at the subscription level and begins near-real-time streaming of control-plane events into the AzureActivity table within your Sentinel workspace. It is the supported, turnkey method for this integration: the connector handles schema mapping, enrichment, and provides out-of-the-box detection rules, workbooks, and hunting queries. Once enabled, all operations such as resource creation, policy changes, and security alerts are immediately visible in Sentinel.

Why this answer

The Azure Activity data connector is specifically designed to ingest subscription-level activity logs into Microsoft Sentinel. Option A is incorrect because although diagnostic settings can send activity logs to a Log Analytics workspace, Sentinel requires the data connector to properly collect and correlate the data. Option B is incorrect because an Azure Logic App would be an inefficient custom solution when a built-in connector exists.

Option D is incorrect because manually exporting to a storage account is not efficient or automated.

305
MCQmedium

Your organization uses Microsoft Sentinel for security operations. You need to ensure that incident investigations automatically enrich alerts with relevant user and device information from Microsoft Defender XDR and Microsoft Entra ID. What should you configure?

A.Enable Fusion detection for multistage attacks.
B.Create watchlists for user and device information and reference them in analytics rules.
C.Configure automation rules to trigger a playbook on alert creation.
D.Enable User and Entity Behavior Analytics (UEBA) and configure entity behavior settings.
AnswerD

UEBA in Microsoft Sentinel profiles entities (users, devices, etc.) using historical activity to detect anomalies and enrich alerts with contextual information like risk scores, behavioral deviations, and peer comparisons. Configuring entity behavior settings enables this enrichment to be applied automatically to analytics alerts, providing security analysts with a richer view of the entity's normal vs. anomalous behavior. This directly meets the requirement to enrich alerts with user and device information, unlike static watchlists or detection-only features.

Why this answer

The correct option is D: enabling User and Entity Behavior Analytics (UEBA) and configuring entity behavior settings. In Microsoft Sentinel, UEBA ingests and correlates user and device entity data from sources such as Microsoft Defender XDR and Microsoft Entra ID, building behavior profiles and enriching incidents with entity insights (e.g., user, host, IP) that investigators see on the incident page. Option A is wrong because Fusion detection correlates multistage attack signals into incidents but does not enrich them with user/device context.

Option B is wrong because watchlists are custom reference lists used for matching in analytics rules, not automatic enrichment from Defender XDR/Entra ID. Option C is wrong because automation rules and playbooks execute response actions, not entity enrichment of incidents.

306
MCQhard

A company is planning their cloud governance strategy. They have multiple business units with varying compliance requirements. They need to enforce policies consistently across subscriptions while allowing some flexibility. Which Azure governance structure should they recommend?

A.Assign RBAC roles to each subscription owner.
B.Use a management group hierarchy with Azure Policy assignments and exemptions.
C.Create separate Azure AD tenants for each business unit.
D.Use Azure Blueprints with locked permissions.
AnswerB

A management group hierarchy provides a scalable governance structure by organizing subscriptions under corporate-level domains, allowing Azure Policy assignments to inherit across all descendant subscriptions and resource groups. Policies, such as enforcing approved VM sizes or location restrictions, can be centrally assigned at the root management group, ensuring consistent compliance. Exemptions offer a controlled mechanism to exclude specific resources from policy evaluation when legitimate exceptions are required, with the ability to set an expiry date. This combination delivers both enforcement and flexibility, making it the correct governance approach.

Why this answer

B is correct because a management group hierarchy allows the company to organize subscriptions by business unit or compliance requirement, then apply Azure Policy assignments at the management group level to enforce consistent policies across all subscriptions. Exemptions can be granted at lower scopes (e.g., specific subscriptions or resource groups) to provide the required flexibility while maintaining overall governance. This structure centralizes policy enforcement without requiring separate tenants or manual RBAC assignments.

Exam trap

The trap here is that candidates often confuse RBAC (access control) with Azure Policy (compliance enforcement), or assume that separate tenants or Blueprints are needed for isolation, when in fact management groups with policy exemptions provide the exact balance of consistency and flexibility required.

How to eliminate wrong answers

Option A is wrong because assigning RBAC roles to each subscription owner delegates access control but does not enforce consistent policies across subscriptions; RBAC controls who can manage resources, not what configurations or compliance rules must be applied. Option C is wrong because creating separate Azure AD tenants for each business unit isolates identities and policies completely, preventing centralized governance and increasing administrative overhead; it also breaks cross-tenant resource access and reporting. Option D is wrong because Azure Blueprints with locked permissions can define a repeatable environment, but locked permissions prevent any flexibility for business units to deviate when needed, and Blueprints are deprecated in favor of deployment stacks; they do not support the exemption-based flexibility required.

307
MCQeasy

Your company uses Microsoft Sentinel for security information and event management (SIEM). You need to design a solution that reduces alert fatigue by correlating low-fidelity alerts from multiple sources into a single high-fidelity incident. Which Microsoft Sentinel feature should you use?

A.Workbooks
B.Analytics rules with alert grouping enabled
C.Playbooks
D.Hunting queries
AnswerB

Analytics rules with alert grouping enabled are the correct mechanism for correlating alerts because Sentinel's incident creation settings allow you to group multiple alerts into one incident based on matching entities, alert titles, or within a specified time window. This grouping reduces alert fatigue by consolidating related detections into a single case for investigation, and it can be configured as either system alert grouping (group all or by entity) or custom grouping with a predefined window.

Why this answer

Analytics rules with alert grouping enabled allow you to configure a rule that correlates multiple low-fidelity alerts (e.g., from different data sources or detection types) into a single high-fidelity incident. When alert grouping is enabled, the rule groups alerts that occur within a specified time window and share common entities (such as IP addresses or user accounts), reducing alert fatigue by presenting one consolidated incident instead of many individual alerts.

Exam trap

The trap here is that candidates often confuse 'alert grouping' with 'playbook automation' or 'workbook visualization', thinking that any tool that reduces noise must involve automation or dashboards, rather than understanding that the correlation logic is built directly into the analytics rule configuration.

How to eliminate wrong answers

Option A is wrong because Workbooks are visualization tools that display data from queries and logs; they do not perform correlation or grouping of alerts into incidents. Option C is wrong because Playbooks are automated response workflows (based on Azure Logic Apps) that trigger on incidents or alerts but do not correlate or group alerts into a single incident. Option D is wrong because Hunting queries are ad-hoc, interactive searches for threats in raw log data; they do not automatically create incidents or group alerts.

308
MCQhard

A healthcare organization uses Microsoft Purview Information Protection to classify and protect patient data. They want to automatically apply a 'High Confidentiality' label to any document containing a patient ID pattern (###-####). The label should also encrypt the document. Which configuration should they use?

A.Retention label with auto-labeling policy
B.Data Loss Prevention (DLP) policy with a block action
C.Sensitivity label with auto-labeling for sensitive info types
D.Trainable classifier with a retention policy
AnswerC

This is the correct choice: a sensitivity label with auto-labeling for sensitive info types (e.g., a patient ID regex) can be delivered through an auto-labeling policy in Purview, and the label can be configured with encryption via Azure Rights Management. When the label is applied, it encrypts the file, sets viewer/edit permissions, and embeds persistent protection metadata so that the PHI remains protected both at rest and when shared. Because both the classification trigger and the encryption action are integral to the sensitivity label, it uniquely combines automated detection with immediate protection.

Why this answer

To automatically apply a label that encrypts documents containing a patient ID pattern, the organization should use a sensitivity label with auto-labeling configured for sensitive info types. Sensitivity labels can enforce encryption and are applied automatically based on conditions such as the presence of sensitive information types (e.g., a custom regex for ###-####).

Exam trap

SC-100 often tests the confusion between retention labels, DLP policies, and sensitivity labels, and candidates may incorrectly choose DLP or retention when the requirement is automatic classification with encryption, which is a sensitivity label feature.

How to eliminate wrong answers

Option A is wrong because retention labels are used for data lifecycle management (retain or delete) and do not provide encryption or classification based on sensitive info types. Option B is wrong because a DLP policy with a block action can prevent sharing but does not apply a label or encrypt the document; it enforces actions but not classification. Option D is wrong because a trainable classifier is used to identify content based on examples, but it does not automatically apply a sensitivity label with encryption; it is typically used in conjunction with auto-labeling policies, but the label itself must be a sensitivity label.

309
MCQmedium

Your organization is implementing Microsoft Entra ID Conditional Access. You need to require multi-factor authentication (MFA) for all users accessing financial applications, but only when the sign-in risk is medium or higher. What is the most efficient way to achieve this?

A.Create a Microsoft Entra ID Protection user risk policy to require MFA
B.Enable MFA per user for all users in the financial team
C.Create a Conditional Access policy that targets all users, includes a named location, and requires MFA
D.Create a Conditional Access policy that targets the financial applications, uses sign-in risk as a condition, and requires MFA
AnswerD

A Conditional Access policy can be precisely scoped to the financial applications as the assigned target resources, while using sign-in risk as a condition to trigger MFA. Sign-in risk is calculated in real time by Microsoft Entra ID Protection, and Conditional Access allows it to be set to a threshold such as Low, Medium, or High. When a sign-in to a financial app has a risk level that meets the threshold, MFA is required, directly fulfilling the requirement for risk-based MFA protection on the financial applications without affecting unrelated apps or users.

Why this answer

It uses a single Conditional Access policy to target the specific financial applications and sets the sign-in risk condition to medium or higher, which triggers MFA only when the risk threshold is met. This approach is efficient as it avoids per-user MFA configuration and leverages Microsoft Entra ID Protection's risk detection to dynamically enforce MFA based on real-time sign-in risk, aligning with the principle of adaptive access control.

Exam trap

The trap here is that candidates often confuse user risk policies with sign-in risk conditions, or they default to per-user MFA or location-based policies, missing the precise combination of application scoping and risk-based conditions that the question requires.

How to eliminate wrong answers

Option A is wrong because a user risk policy in Microsoft Entra ID Protection targets user-level risk (e.g., compromised credentials) rather than sign-in risk, and it cannot be scoped to specific applications like financial apps; it would apply MFA based on user risk, not sign-in risk. Option B is wrong because enabling MFA per user forces MFA on every authentication for those users, regardless of sign-in risk level, which violates the requirement to only require MFA when risk is medium or higher and is less efficient than a risk-based policy. Option C is wrong because it includes a named location condition, which is irrelevant to sign-in risk, and targets all users without application scoping, meaning it would apply MFA to all applications for all users, not just financial apps when risk is elevated.

310
MCQmedium

You are designing a security architecture for Litware Inc., which uses Microsoft 365 E5 and Azure. The company wants to adopt a Zero Trust model and needs to ensure that access to corporate resources is granted based on real-time risk assessment. The security team wants to automatically remediate risky user behavior by requiring password changes or blocking access. You need to recommend a solution that integrates with Microsoft Entra ID and provides risk-based conditional access. What should you recommend?

A.Azure AD Conditional Access with named locations
B.Microsoft Cloud App Security (Defender for Cloud Apps) session policies
C.Microsoft Defender for Identity
D.Microsoft Entra ID Protection
AnswerD

Microsoft Entra ID Protection detects risky users and sign-ins using machine learning and heuristics, and it integrates with Conditional Access to enforce risk-based policies. It can automatically require password changes or block access when risk is detected, directly meeting the requirement for real-time risk assessment and automated remediation.

Why this answer

Microsoft Entra ID Protection evaluates sign-in and user risk in real time and integrates with Conditional Access to enforce policies such as requiring MFA or password change for risky users. It can also block access when risk is high, providing the automated remediation and risk-based access required for a Zero Trust architecture.

Exam trap

The trap here is confusing Defender for Identity, which monitors on-premises Active Directory, with Entra ID Protection, which assesses cloud identity risk and drives conditional access policies.

311
MCQeasy

A company wants to monitor and respond to threats across their entire digital estate, including on-premises servers, cloud workloads, and identities. Which Microsoft solution should they use as a central security information and event management (SIEM) and extended detection and response (XDR) platform?

A.Microsoft Intune
B.Microsoft Defender for Cloud
C.Microsoft Sentinel and Microsoft Defender XDR
D.Microsoft Purview
AnswerC

Microsoft Sentinel and Microsoft Defender XDR together form a complete monitoring-and-response solution. Sentinel is a cloud-native SIEM that ingests logs from every source, applies analytics rules to detect anomalies, and provides incident management, investigation, and threat hunting, while Microsoft Defender XDR correlates signals across Microsoft Defender for Office 365, Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps. This pairing enables automated response and a single pane of glass for security operations, satisfying the requirement to both monitor and respond to threats across the enterprise.

Why this answer

The correct answer is C: Microsoft Sentinel and Microsoft Defender XDR, because Sentinel is Microsoft's cloud-native SIEM that ingests and correlates logs from on-premises servers, cloud workloads, and identities, while Defender XDR provides the extended detection and response layer across endpoints, identities, email, and cloud apps, together forming the central security operations platform the company needs. Microsoft Intune (A) is a mobile device and endpoint management (MDM/MAM) service, not a SIEM/XDR. Microsoft Defender for Cloud (B) is a cloud security posture management (CSPM) and workload protection service, not a central SIEM/XDR.

Microsoft Purview (D) is a data governance, compliance, and information protection suite, not a threat monitoring SIEM/XDR platform.

312
MCQhard

The exhibit shows a conditional access policy in Microsoft Entra ID. What will be the effect of this policy?

A.Allow all applications except Office365
B.Block all applications including Office365
C.Allow all applications including Office365
D.Block all applications except Office365
AnswerD

The policy is configured to target 'All cloud apps', excludes Office 365, and uses the 'Block access' grant control. When a user attempts to access an included application, the policy is evaluated and blocks the sign-in. Since Office 365 is in the exclusion list, the policy is skipped for that application, leaving it unblocked. Therefore, the policy blocks all applications except Office 365.

Why this answer

The exhibit shows a Conditional Access policy that includes 'All cloud apps' in the target resources and is configured with a 'Block access' grant control. The 'Exclude' list contains 'Office365', meaning the policy applies to all applications except Office365. Therefore, the effect is to block access to all applications except Office365, making option D correct.

Exam trap

The trap here is that candidates often overlook the 'Exclude' list and assume that selecting 'All cloud apps' with 'Block access' blocks everything, but the exclusion of Office365 means it is not blocked.

How to eliminate wrong answers

Option A is wrong because the policy blocks access, not allows it; 'Allow all applications except Office365' would require an 'Allow' grant control, not 'Block'. Option B is wrong because Office365 is explicitly excluded from the policy, so it is not blocked; 'Block all applications including Office365' would require no exclusion for Office365. Option C is wrong because the policy blocks access, not allows it; 'Allow all applications including Office365' would require an 'Allow' grant control and no block action.

313
MCQhard

Refer to the exhibit. You are reviewing a Conditional Access policy in Azure AD. The policy requires MFA and a compliant device for all users and all cloud apps. Some users report that they are able to access apps without being prompted for MFA even though their devices are compliant. What is the most likely reason?

A.The policy does not include all cloud apps
B.The policy is set to 'Report-only' mode
C.The policy excludes specific locations
D.The policy does not include session controls to enforce MFA re-prompt
AnswerB

Report-only mode evaluates the policy and logs what would have happened without enforcing controls, so MFA and device compliance prompts never appear. Because the policy targets all users and all cloud apps, only this mode explains compliant-device users accessing apps unprompted while Microsoft Entra ID records the would-be result.

Why this answer

A Conditional Access policy set to 'Report-only' mode evaluates the policy and logs results but does not enforce any controls, such as requiring MFA or a compliant device. Users can access apps without MFA prompts because the policy is not actively blocking or challenging them, even if their devices are compliant. This mode is used for testing before enabling enforcement.

Exam trap

The trap here is that candidates may overlook the 'Report-only' mode setting and assume the policy is enforcing controls, focusing instead on app scope or location exclusions, which are common red herrings in Conditional Access troubleshooting questions.

How to eliminate wrong answers

Option A is wrong because the policy explicitly states it includes 'all cloud apps,' so missing apps is not the issue. Option C is wrong because excluding specific locations would only bypass MFA for users from those locations, but the question states users report access without MFA even though devices are compliant, implying the issue is not location-based. Option D is wrong because session controls for MFA re-prompt are not required for initial MFA enforcement; the policy's grant controls (requiring MFA and compliant device) are sufficient to prompt MFA on first access, and the lack of re-prompt controls does not explain why MFA is never prompted.

314
MCQhard

A global organization uses Microsoft Sentinel for SIEM and Microsoft Defender for Cloud for cloud security posture management. The security team notices that critical alerts from Azure Active Directory Identity Protection are not triggering automated response playbooks in Sentinel. The team needs to ensure that all high-severity Identity Protection risk detections automatically create incidents in Sentinel and trigger a playbook to block the user. What should the team configure?

A.Enable the Identity Protection data connector and create a Microsoft Security incident creation rule for Identity Protection.
B.Enable the Azure Active Directory Identity Protection data connector in Sentinel.
C.Configure diagnostic settings on Azure AD to stream logs to Sentinel and create a playbook automation rule.
D.Configure the Identity Protection connector with the 'Create incidents' toggle enabled.
AnswerA

This is the correct, complete configuration for Microsoft Sentinel. The Identity Protection data connector ingests risk detections and alerts from Azure AD Identity Protection into Sentinel, and the Microsoft Security incident creation rule for Identity Protection is the required analytics rule that automatically generates incidents from those ingested alerts. Without this analytics rule, the alerts remain as raw events with no incident lifecycle, so enabling both together satisfies the requirement to create incidents automatically.

Why this answer

To have Identity Protection risk detections automatically create incidents in Microsoft Sentinel and trigger a playbook, you must first enable the Identity Protection data connector (which brings the alerts into Sentinel) and then create a Microsoft Security incident creation rule specifically for Identity Protection. This rule ingests the alerts as security incidents, and you can attach an automation rule to run a playbook (e.g., to block the user) when a high-severity incident is created. Without the incident creation rule, the alerts would be ingested as raw events but not automatically turned into incidents.

Exam trap

The trap here is that candidates confuse simply enabling a data connector (which only ingests data) with the separate requirement of creating an incident creation rule to transform those alerts into actionable incidents, leading them to pick Option B or D.

How to eliminate wrong answers

Option B is wrong because simply enabling the Azure AD Identity Protection data connector only ingests the alerts into Sentinel as raw data; it does not automatically create incidents or trigger playbooks. Option C is wrong because configuring diagnostic settings on Azure AD streams sign-in and audit logs, not Identity Protection risk detections; Identity Protection alerts are not sent via diagnostic settings and require the dedicated connector. Option D is wrong because the Identity Protection connector does not have a 'Create incidents' toggle; incident creation is handled by a separate Microsoft Security incident creation rule, not by a toggle on the connector itself.

315
MCQhard

Refer to the exhibit. You are reviewing an ARM template snippet for an Azure Storage container. Which security best practice does this configuration enforce?

A.Disables anonymous public access to the container
B.Allows public access from the internet
C.Configures a firewall rule to restrict access to specific IPs
D.Enables encryption at rest for the container
AnswerA

In an ARM template for Azure Storage, the `publicAccess` property of a container is set to 'None', which explicitly blocks any anonymous read requests to the blob data within that container. This configuration ensures that clients must present valid authentication credentials—such as an account key, a shared access signature (SAS), or an Azure AD identity—to access the container's contents. Setting `publicAccess` to 'None' is a critical security control that prevents unauthorized exposure of stored data.

Why this answer

The ARM template snippet sets the `publicAccess` property of the container to `None`. This explicitly disables anonymous public access to the container, enforcing the security best practice of preventing unauthenticated access to Azure Storage data. By default, Azure Storage containers allow anonymous read access if enabled at the account level, but this configuration overrides that to block any public requests.

Exam trap

The trap here is that candidates may confuse the container-level `publicAccess` property with storage account-level firewall rules or encryption settings, leading them to select options that describe unrelated security features.

How to eliminate wrong answers

Option B is wrong because allowing public access from the internet is the opposite of the security best practice; the snippet disables public access, not enables it. Option C is wrong because the snippet does not include any `networkAcls` or `ipRules` properties; firewall rules are configured at the storage account level, not within a container resource definition. Option D is wrong because encryption at rest is enabled by default for Azure Storage and is not controlled by the `publicAccess` property; the snippet does not reference any encryption settings.

316
MCQmedium

Your organization uses Microsoft Sentinel to centralize security logs from multiple clouds. They need to ensure that logs from Amazon Web Services (AWS) are ingested and analyzed for threats. Which connector should you implement?

A.Microsoft Defender for Cloud
B.Azure Monitor Agent
C.AWS S3 connector
D.Azure Event Hubs
AnswerC

The AWS S3 connector is the correct native Microsoft Sentinel data connector for ingesting AWS CloudTrail logs. It connects to a configured S3 bucket that receives CloudTrail events and optionally uses SQS for near-real-time notifications, then normalizes the JSON records into the AWSCloudTrail table in Log Analytics. This is the standard architectural pattern for centralizing AWS activity monitoring in Sentinel, and it directly satisfies the organization's requirement.

Why this answer

The AWS S3 connector is the correct choice because it is the native Microsoft Sentinel data connector designed specifically to ingest AWS CloudTrail logs (and other AWS service logs) from an S3 bucket. It uses an AWS Simple Queue Service (SQS) to poll for new log files, then streams them into Sentinel for analysis, enabling threat detection across multi-cloud environments.

Exam trap

The trap here is that candidates may confuse Microsoft Defender for Cloud (a security posture tool) with a log ingestion connector, or assume Azure Event Hubs is the default streaming solution for all external logs, overlooking the purpose-built AWS S3 connector that handles the specific S3-to-Sentinel pipeline.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection tool, not a log ingestion connector for AWS; it does not directly pull raw logs from S3 into Sentinel. Option B is wrong because Azure Monitor Agent (AMA) is designed to collect telemetry from Azure VMs and on-premises machines via Data Collection Rules, not from external cloud storage like AWS S3. Option D is wrong because Azure Event Hubs is a data streaming platform that can receive logs from external sources, but it is not a pre-built Sentinel connector for AWS; using it would require custom configuration and additional components to replicate the S3 connector's functionality.

317
MCQhard

Contoso is a financial services company migrating critical workloads to Azure. They must comply with PCI DSS and have a Security Operations Center (SOC) team that uses Microsoft Sentinel. The CISO wants to ensure that the security posture aligns with Microsoft's cybersecurity reference architecture (MCRA). You need to design a solution that includes the following requirements: 1) All Azure subscriptions must be managed under a single management group hierarchy with consistent policies. 2) The SOC must have a centralized view of security alerts across all resources, including on-premises servers and multi-cloud environments. 3) Privileged access to Azure resources must be protected using just-in-time (JIT) access and Privileged Identity Management (PIM). 4) Compliance with PCI DSS must be continuously monitored and reported. 5) The solution must minimize operational overhead. What should you include in the design?

A.Create separate management groups per business unit. Enable Microsoft Defender for Cloud on each subscription individually. Use Azure Policy to assign PCI DSS policies per subscription. Configure PIM at the tenant root management group. Use a third-party SIEM to aggregate alerts.
B.Deploy a single management group containing all subscriptions. Enable Microsoft Defender for Cloud with the 'PCI DSS v3.2.1' regulatory compliance dashboard on the management group. Configure Azure Policy to enforce security standards. Enable PIM and configure JIT VM access. Use Microsoft Sentinel as the SIEM, connecting it to Defender for Cloud and on-premises security sources.
C.Deploy a management group hierarchy with policies inherited. Use Microsoft Defender for Cloud's secure score to monitor compliance manually. Implement PIM without JIT. Use Microsoft Sentinel but only for cloud workloads.
D.Use a single management group with Azure Policy to enforce PCI DSS controls. Rely on Azure Monitor for security alerts. Do not enable Defender for Cloud to reduce costs. Use PIM for privileged roles. Connect on-premises logs to a Log Analytics workspace for the SOC.
AnswerB

This design centralizes subscription management under a single management group, allowing Azure Policy and Defender for Cloud regulatory compliance dashboards to span the entire environment consistently. The PCI DSS v3.2.1 dashboard continuously assesses all resources, PIM combined with JIT VM access reduces standing privilege and exposed attack surface, and Microsoft Sentinel ingests both cloud and on-premises security data for a unified SOC. It provides an integrated, continuous compliance monitoring and threat detection solution that scales across the organization.

Why this answer

Option B is correct because it directly satisfies all five requirements with minimal operational overhead: a single management group with inherited Azure Policy enforces consistent PCI DSS controls across all subscriptions, and enabling Microsoft Defender for Cloud's 'PCI DSS v3.2.1' regulatory compliance dashboard on the management group provides continuous compliance monitoring and reporting. Microsoft Sentinel, connected to Defender for Cloud and on-premises security sources, gives the SOC a centralized SIEM view spanning Azure, on-premises, and multi-cloud, while PIM with JIT VM access secures privileged access as required. Option A fails because it fragments governance into separate management groups per business unit, uses a third-party SIEM instead of the existing Microsoft Sentinel, and applies Defender for Cloud per subscription, increasing overhead.

Option C is wrong because it omits JIT access, limits Sentinel to cloud workloads only, and relies on manual secure score review rather than continuous PCI DSS reporting. Option D is incorrect because it disables Defender for Cloud (losing regulatory compliance monitoring) and uses Azure Monitor rather than Sentinel for SOC alerting.

318
MCQmedium

Your organization is planning to deploy Microsoft Purview Information Protection to classify and protect sensitive data. You need to design a solution that automatically applies sensitivity labels to documents containing personally identifiable information (PII) when they are uploaded to SharePoint Online. Which configuration should you use?

A.Set a default sensitivity label for the SharePoint site
B.Use trainable classifiers to identify PII and apply labels
C.Create an auto-labeling policy that uses a sensitive info type for PII
D.Configure a manual labeling policy that prompts users to classify documents
AnswerC

Creating an auto-labeling policy in the Microsoft Purview compliance portal lets you define a rule that scans SharePoint sites, OneDrive accounts, and Exchange for content containing sensitive info types (SITs) for PII, such as U.S. SSN, EU debit card number, or U.S. individual taxpayer identification number. When a match is found, the policy automatically applies the configured sensitivity label and can optionally enforce encryption or a visual marking. This is a rule-based, deterministic detection that works immediately on existing and new content, without user intervention, and is the intended mechanism for automatically classifying PII.

Why this answer

Microsoft Purview auto-labeling policies can automatically apply sensitivity labels to documents containing PII when they are uploaded to SharePoint Online. By configuring a policy with a sensitive info type (e.g., U.S. Social Security Number) as the condition, the service scans content at rest and applies the label without user intervention, meeting the requirement for automatic classification.

Exam trap

The trap here is confusing trainable classifiers with sensitive info types; candidates often pick trainable classifiers because they sound like a smart AI solution, but they are designed for broader content categories, not specific PII patterns like SSNs or credit card numbers.

How to eliminate wrong answers

Option A is wrong because setting a default sensitivity label for a SharePoint site applies a label to all new documents in that site, but it does not automatically detect and label only those containing PII; it labels everything regardless of content. Option B is wrong because trainable classifiers are used for pattern-based content categorization (e.g., contracts or resumes) and are not designed to identify specific PII data types like credit card numbers or SSNs; sensitive info types are the correct mechanism for PII detection. Option D is wrong because a manual labeling policy requires users to classify documents themselves, which does not meet the requirement for automatic labeling upon upload.

319
MCQeasy

Your organization is migrating to Microsoft 365 and wants to implement a defense-in-depth strategy for email security. Which combination of Microsoft services should you use?

A.Microsoft Defender for Office 365 and Exchange Online Protection
B.Microsoft Purview Compliance Manager and Microsoft Defender for Cloud Apps
C.Microsoft Intune and Microsoft Entra ID
D.Microsoft Sentinel and Microsoft Defender for Identity
AnswerA

Exchange Online Protection (EOP) provides the always-on baseline filtering for all Exchange Online mailboxes, including spam, bulk mail, malware, and spoof intelligence before a message reaches the user. Microsoft Defender for Office 365 (MDO) layers on top with Safe Attachments, Safe Links, and advanced anti-phishing policy that checks URLs and attachments in real time, plus impersonation and domain-based protection. Together they form the native email security stack, with EOP as the foundation and MDO handling zero-day or social-engineering threats that basic filters miss.

Why this answer

Defense-in-depth for email security requires layered protection at the transport, filtering, and post-delivery stages. Exchange Online Protection (EOP) provides baseline anti-malware, anti-spam, and transport rules, while Microsoft Defender for Office 365 adds advanced threat protection like Safe Attachments, Safe Links, and anti-phishing policies that inspect URLs and attachments in real time. Together, they cover the full email threat chain from ingress to user interaction.

Exam trap

The trap here is that candidates confuse compliance or identity services with email security layers, forgetting that defense-in-depth for email specifically requires both transport-level (EOP) and post-delivery (Defender for Office 365) protections.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Compliance Manager focuses on compliance posture and risk assessments, not on email security filtering or threat detection. Option C is wrong because Microsoft Intune manages device compliance and application policies, and Microsoft Entra ID handles identity and access management; neither provides email transport or content inspection. Option D is wrong because Microsoft Sentinel is a SIEM for centralized security analytics and Microsoft Defender for Identity detects on-premises Active Directory attacks; they do not directly protect email transport or attachments.

320
MCQeasy

Your organization wants to implement a security baseline for Azure resources using built-in policies. Which Azure service should you use to assign policies that enforce compliance with security best practices?

A.Azure Blueprints
B.Microsoft Defender for Cloud
C.Azure Policy
D.Azure Role-Based Access Control (RBAC)
AnswerC

Azure Policy is the correct service for implementing a security baseline because it creates, assigns, and manages rules that audit, deny, or remediate resource properties. It includes built-in policy definitions for the Azure Security Benchmark and other regulatory standards, enabling consistent enforcement across all resources. Policies can be applied to resource groups, subscriptions, and management groups, ensuring that new and existing resources continuously meet security requirements like encryption, network restrictions, and version compliance.

Why this answer

Azure Policy is the correct service because it allows you to create, assign, and manage policies that enforce specific rules and effects on your Azure resources. These policies can be used to implement a security baseline by ensuring resources comply with built-in security best practices, such as requiring encryption or restricting resource types. Azure Policy evaluates resources against assigned policies and can automatically remediate non-compliant resources.

Exam trap

The trap here is that candidates often confuse Azure Policy with Microsoft Defender for Cloud, thinking Defender for Cloud is the tool for enforcing security baselines, but Defender for Cloud only recommends policies and monitors compliance, while Azure Policy is the actual service that enforces them.

How to eliminate wrong answers

Option A is wrong because Azure Blueprints is used to orchestrate the deployment of resource templates, policies, and role assignments as a repeatable set of artifacts, but it is not the service for directly assigning and enforcing individual policies; it can include Azure Policy definitions as part of a blueprint, but the core policy enforcement mechanism is Azure Policy itself. Option B is wrong because Microsoft Defender for Cloud provides security posture management, threat detection, and recommendations based on security benchmarks, but it does not directly assign or enforce policies; it can integrate with Azure Policy to apply regulatory compliance initiatives, but the assignment and enforcement of policies is done through Azure Policy. Option D is wrong because Azure Role-Based Access Control (RBAC) manages who has access to Azure resources and what actions they can perform, but it does not enforce compliance rules or security baselines on resource configurations; RBAC is about authorization, not about ensuring resources meet specific security standards.

321
MCQhard

You are designing a data classification strategy for Microsoft Purview. The compliance team requires that documents containing personally identifiable information (PII) like credit card numbers are automatically labeled and encrypted when stored in Microsoft SharePoint Online. The solution must use built-in sensitive information types. What should you include in the design?

A.Create a sensitivity label with auto-labeling for credit card numbers and enable encryption
B.Create a retention label and apply it automatically via a data loss prevention (DLP) policy
C.Use a trainable classifier to detect PII and apply a sensitivity label
D.Configure a manual sensitivity label policy for users to apply
AnswerA

This is correct because a sensitivity label can be configured with auto-labeling rules and encryption so that when an item in SharePoint Online, OneDrive, or Exchange contains a credit card number (detected by the built-in Credit Card Number sensitive information type), the label is applied automatically and the file or email is protected with Azure Rights Management encryption. The auto-labeling policy can run as a simulation first to evaluate matches, then be enforced, ensuring both classification and protection happen without user action. This architecture directly satisfies a requirement for automatic classification and encryption.

Why this answer

Option A is correct because Microsoft Purview sensitivity labels support auto-labeling policies that can use built-in sensitive information types (SITs) such as Credit Card Number, and the label itself can enforce encryption via the label's encryption settings when applied to documents in SharePoint Online. This directly satisfies the requirement to automatically label and encrypt PII-containing documents using built-in SITs. Option B is incorrect because retention labels govern retention/deletion, not encryption, and DLP policies do not apply retention labels.

Option C is incorrect because trainable classifiers are for custom content patterns, not built-in PII SITs like credit card numbers. Option D is incorrect because manual labeling does not meet the automatic labeling requirement.

322
MCQhard

A company uses Azure Cosmos DB with Microsoft Defender for Cloud to protect its NoSQL database. The security team wants to audit all data plane operations for compliance. Which diagnostic setting should they enable?

A.MongoRequests
B.PartitionKeyStatistics
C.QueryRuntimeStatistics
D.DataPlaneRequests
AnswerD

DataPlaneRequests is the diagnostic log that records every data plane request against an Azure Cosmos DB account, regardless of the API in use (SQL, MongoDB, Cassandra, Gremlin, Table). Each entry includes the operation type (e.g., create, read, upsert, delete, query), resource URI, partition key range, current status code, request charge, client IP, and authentication token type. This comprehensive coverage of all CRUD and other data operations makes it the correct source for auditing and forensic analysis of data plane activity.

Why this answer

The correct option is D, DataPlaneRequests. This diagnostic setting in Azure Cosmos DB logs all data plane operations, including CRUD actions on documents, which is exactly what the security team needs to audit for compliance. The other options do not fit: MongoRequests only captures requests for the MongoDB API, PartitionKeyStatistics provides metrics on partition key usage, and QueryRuntimeStatistics logs query execution details rather than a full audit of data plane operations.

323
MCQmedium

A company is designing a microservices architecture on Azure Kubernetes Service (AKS). They need to secure communication between services using mutual TLS (mTLS). Which solution should they implement?

A.Azure Application Gateway
B.Azure Firewall
C.Azure API Management
D.Istio service mesh
AnswerD

Istio service mesh runs Envoy sidecar proxies next to each microservice, giving it the ability to issue SPIFFE-based identities and automatically encrypt and authenticate all service-to-service traffic with mutual TLS. It also provides authorization policies and traffic management, making it the correct solution for internal microservice mTLS on Azure Kubernetes Service or virtual machines. This directly addresses the need for workload-level identity and encryption between microservices.

Why this answer

Istio service mesh is the correct solution because it provides a dedicated infrastructure layer for managing service-to-service communication, including automatic mutual TLS (mTLS) between microservices. Istio injects Envoy sidecar proxies into each pod, which handle encryption, authentication, and authorization without requiring application code changes. This enables zero-trust network security within the AKS cluster.

Exam trap

The trap here is that candidates often confuse ingress/egress security appliances (like Application Gateway or API Management) with internal service-to-service security, assuming a gateway can handle mTLS for east-west traffic when it is designed only for north-south traffic.

How to eliminate wrong answers

Option A is wrong because Azure Application Gateway is a Layer 7 load balancer and web application firewall (WAF) that operates at the ingress edge, not within the cluster for east-west traffic; it cannot enforce mTLS between individual microservices. Option B is wrong because Azure Firewall is a stateful network firewall that filters traffic at the network and application layers but does not provide service-level identity or mTLS capabilities for pod-to-pod communication. Option C is wrong because Azure API Management is an API gateway for managing external APIs and does not handle internal service-to-service mTLS within the AKS cluster; it lacks sidecar proxy injection and service mesh features.

324
MCQmedium

An organization uses Microsoft Sentinel to monitor their hybrid infrastructure. They need to detect brute-force attacks against their on-premises Windows servers. Which data source should they connect to Sentinel?

A.Azure Activity Log
B.Windows Security Events via Azure Monitor Agent
C.DNS Events
D.Sysmon Events
AnswerB

The Windows Security event log via the Azure Monitor Agent (AMA) is the standard and authoritative source for logon audit events, specifically Event ID 4625, which logs every failed account logon attempt. For hybrid machines, configuring a data collection rule (DCR) to forward Security events to Microsoft Sentinel enables detection of password-spraying and brute-force attempts. AMA is the current agent replacing the Log Analytics agent and preserves the necessary event details, such as source IP and target account, for high-fidelity analytics.

Why this answer

Windows Security Events from Event ID 4625 (failed logon) are the primary source for detecting brute-force attacks. Azure Activity Log is for resource management events. DNS events are for DNS queries.

Sysmon is for process activity, not logon failures.

325
Multi-Selectmedium

Which TWO Azure policies should you assign to enforce secure configuration of Azure SQL Database? (Select two.)

Select 2 answers
A.Ensure that 'Auditing' is set to 'On' for SQL Database
B.Ensure that 'TDE' is enabled for SQL Server VMs
C.Audit SQL Server level audit setting
D.Ensure that 'Firewall and virtual network settings' for SQL Database are configured
E.Ensure secure transfer to storage accounts is enabled
AnswersA, D

Enabling SQL Database auditing satisfies the secure-configuration requirement by recording all database events to a storage, Log Analytics or Event Hub destination, giving the detective evidence trail that Azure Policy's Auditing effect enforces at scale across every server and database in scope.

Why this answer

Option A is correct because the built-in Azure Policy 'Auditing on SQL Database should be enabled' enforces that auditing is set to 'On' for Azure SQL Database, ensuring database activity is logged for security and compliance monitoring. Option D is correct because the policy 'Firewall and virtual network settings for SQL Database should be configured' enforces that Azure SQL Database has network-level access controls (firewall rules or virtual network service endpoints/private endpoints) in place, restricting access to authorized networks only. Option B is incorrect because it targets TDE on SQL Server running on VMs (IaaS), not Azure SQL Database (PaaS), so it does not apply to this scenario.

Option C is incorrect because it audits the SQL Server-level audit setting rather than enforcing a secure configuration on Azure SQL Database itself. Option E is incorrect because it concerns secure transfer for storage accounts, which is unrelated to Azure SQL Database configuration.

Exam trap

The trap here is that candidates confuse SQL Server VM policies (like TDE or SQL Server-level audit settings) with Azure SQL Database policies, or they mistakenly apply storage account policies to SQL Database, which is a separate Azure service with its own security controls.

326
MCQeasy

Your organization, Adatum, is migrating its on-premises applications to Azure. The applications include a legacy .NET Framework web app that uses Windows authentication and a modern ASP.NET Core API that uses OAuth 2.0. You need to design a secure solution for these applications using Azure App Service. The security requirements include: (1) enforce HTTPS only, (2) restrict access to the web app based on the user's corporate identity, (3) allow the API to access an Azure SQL Database using a managed identity. Which of the following is the correct design?

A.Configure the web app to use Windows authentication via Azure AD Domain Services, and the API to use SQL authentication with a managed identity.
B.Configure the web app to use Microsoft Entra ID authentication with a built-in policy, and the API to use a connection string with a username and password.
C.Configure the web app to require client certificates for authentication, and the API to use a connection string with SQL authentication.
D.Configure both apps to enforce HTTPS only, configure the web app to use Microsoft Entra ID authentication, and configure the API to use a system-assigned managed identity to access Azure SQL Database.
AnswerD

Enforcing HTTPS on both apps meets requirement one, Microsoft Entra ID authentication on the web app restricts access by corporate identity, and a system-assigned managed identity lets the API reach Azure SQL Database without stored secrets.

Why this answer

Option D is correct because it satisfies all three requirements: enabling HTTPS-only on both apps enforces TLS, configuring the web app with Microsoft Entra ID authentication restricts access based on corporate identity, and using a system-assigned managed identity lets the API authenticate to Azure SQL Database without storing credentials. Managed identity works with Azure SQL via Entra ID authentication, so no password is needed in the connection string. Option A is wrong because Azure AD Domain Services-based Windows authentication is not the recommended App Service approach and SQL authentication with a managed identity is contradictory.

Option B is wrong because a username/password connection string does not use managed identity. Option C is wrong because client certificates do not provide corporate identity-based access and SQL authentication does not meet the managed identity requirement.

327
MCQmedium

Your company uses Microsoft Intune to manage corporate devices. You need to design a compliance policy that requires devices to have a minimum OS version, be encrypted, and not be jailbroken or rooted. Additionally, you want to automatically block non-compliant devices from accessing corporate email. What should you configure?

A.Intune compliance policies and Conditional Access
B.Device configuration profiles and Azure AD join
C.App protection policies and Microsoft Defender for Endpoint
D.Device enrollment restrictions
AnswerA

Intune compliance policies assess a device's security posture—such as jailbreak status, OS version, encryption, and threat level from Defender for Endpoint—and generate a compliant/non-compliant state that is stored in Azure AD. Conditional Access policies then consume that state at sign-in, using a 'Require device to be marked compliant' grant control to block or allow access to email and other corporate resources. This is the definitive mechanism because it combines continuous health evaluation with identity-driven enforcement, and it works with both Android and iOS device-specific checks like the SafetyNet attestation or Apple's device compliance.

Why this answer

The correct answer is A: Intune compliance policies and Conditional Access. Compliance policies in Intune define the specific requirements you listed—minimum OS version, encryption, and jailbreak/root detection—and Conditional Access then enforces those results by blocking non-compliant devices from accessing corporate resources such as Exchange Online email. The other options do not fit: device configuration profiles and Azure AD join (B) configure settings and identity but do not evaluate compliance or block access; app protection policies and Defender for Endpoint (C) protect app data and detect threats but do not enforce device compliance for email access; and device enrollment restrictions (D) only control which devices can enroll, not ongoing compliance or access control.

328
MCQmedium

A financial services company is designing a security strategy for its Azure SQL Database. The database contains sensitive financial data. The company requires that all connections to the database be encrypted and that the database be protected against SQL injection attacks. Additionally, they need to monitor and audit all database activities for compliance. Which Azure features should the security architect recommend?

A.Use Azure Private Link to connect to the database, enable Always Encrypted for sensitive columns, and use Azure Policy to enforce auditing.
B.Configure Azure SQL Database firewall rules to restrict IP addresses, enable Transparent Data Encryption (TDE), and use Azure Monitor for auditing.
C.Enforce TLS 1.2 for connections, enable Azure Defender for SQL, and configure auditing to Azure Monitor logs.
D.Enable Azure SQL Database auditing to a storage account, configure Advanced Threat Protection, and enforce TLS 1.2 for connections.
AnswerC

Enforcing TLS 1.2 ensures encrypted connections. Azure Defender for SQL (part of Microsoft Defender for Cloud) provides vulnerability assessment and advanced threat protection, including detection of SQL injection attempts. Configuring auditing to Azure Monitor logs enables monitoring and auditing of database activities. This combination addresses all three requirements: encryption, SQL injection protection, and auditing.

Why this answer

The requirements are encrypted connections, SQL injection protection, and auditing. Enforcing TLS 1.2 ensures connections are encrypted. Azure Defender for SQL provides advanced threat protection that detects and alerts on SQL injection attempts.

Configuring auditing to Azure Monitor logs centralizes monitoring and auditing. Together, these features meet the security and compliance needs for the Azure SQL Database.

Exam trap

The trap here is equating network-level protections like firewall rules or Private Link with application-layer SQL injection prevention, which requires threat detection and secure coding practices.

329
MCQeasy

Adventure Works is a startup that uses Microsoft 365 Business Premium. They have 20 employees and no cloud expertise. The CEO has been hearing about ransomware attacks on small businesses. They want to implement basic protection against ransomware using built-in Microsoft 365 features. They also want to ensure they can recover from an attack quickly. What should you recommend?

A.Purchase Azure Backup for all user devices. Configure backup policies to run daily. Use Microsoft Intune to enforce encryption. Implement Conditional Access to require MFA.
B.Enable Microsoft Defender for Office 365 to block malicious attachments and links. Configure Microsoft Defender for Business to enable controlled folder access and ransomware protection. Educate users on phishing. Use OneDrive Files Restore to recover from ransomware.
C.Use Microsoft Sentinel as a SIEM to detect ransomware patterns. Deploy Azure ATP for identity protection. Use Azure Policy to enforce backup.
D.Implement Azure Site Recovery for on-premises servers. Use Microsoft Defender for Cloud for threat detection. Deploy a third-party antivirus.
AnswerB

This option is correct because it leverages the built-in, integrated protections of Microsoft 365 Business Premium. Microsoft Defender for Office 365 filters malicious attachments and link-time detonation in Exchange Online, while Defender for Business provides endpoint detection and response plus controlled folder access that blocks unauthorized processes from modifying user files. Phishing education reduces initial compromise, and OneDrive Files Restore enables users to roll back an entire library to a known-good state within 30 days without heavy IT administration.

Why this answer

It leverages built-in Microsoft 365 Business Premium features to provide immediate ransomware protection without requiring cloud expertise. Microsoft Defender for Office 365 blocks malicious attachments and links at the email gateway, while Defender for Business provides endpoint protection with controlled folder access. OneDrive Files Restore enables self-service recovery of files from ransomware within the last 30 days, aligning with the startup's need for quick recovery without additional infrastructure.

Exam trap

The trap here is that candidates often over-engineer the solution by recommending enterprise-grade tools like Azure Backup or Sentinel, failing to recognize that Microsoft 365 Business Premium includes sufficient built-in capabilities for a small startup with no cloud expertise.

How to eliminate wrong answers

Option A is wrong because Azure Backup is not included in Microsoft 365 Business Premium and requires additional licensing and cloud expertise to configure; it also does not address ransomware prevention at the email or endpoint level. Option C is wrong because Microsoft Sentinel and Azure ATP are advanced security tools requiring significant cloud expertise and additional licensing, far beyond the scope of a 20-employee startup with no cloud expertise. Option D is wrong because Azure Site Recovery is designed for on-premises server disaster recovery, not for user devices or Microsoft 365 data, and deploying a third-party antivirus contradicts the requirement to use built-in Microsoft 365 features.

330
MCQhard

Contoso is a large enterprise with a complex Azure environment. They have multiple management groups, subscriptions, and a hub-spoke network topology. The security team wants to implement a consistent security baseline across all subscriptions using Azure Policy. They need to ensure that: 1) All resources must be deployed in approved regions only. 2) Network security groups must have specific rules to block high-risk ports. 3) All storage accounts must enforce HTTPS traffic. 4) The policies must be applied at the management group level to ensure inheritance. 5) Non-compliant resources must be automatically remediated where possible. What should you do?

A.Use Azure Policy Guest Configuration to enforce region and NSG rules. Assign policies at each subscription. Use Azure Automation runbooks for remediation.
B.Create custom Azure Policy definitions for the required configurations (allowed locations, NSG rule blocking ports, storage HTTPS). Assign the policies at the root management group. Enable 'deployIfNotExists' effect for automatic remediation of non-compliant resources. Use Azure Policy remediation tasks to fix existing non-compliant resources.
C.Use Azure Blueprints to define the environment. Include Azure Policy assignments in the blueprint. Assign blueprint to each management group. Remediate manually.
D.Create a custom script using Azure PowerShell to check compliance daily. Use Azure Logic Apps to send alerts for non-compliance. Have IT staff manually fix issues.
AnswerB

This is the correct approach because Azure Policy is the native, continuous compliance service for resource-level configurations. By creating custom policy definitions for allowed locations, NSG rules, and storage HTTPS and assigning them at the root management group, the policies inherit to all child subscriptions and resource groups, providing a single, central governance baseline. Enabling the DeployIfNotExists effect makes Azure Policy automatically deploy the required configuration (e.g., a compliant NSG or secure storage setting) whenever a non-compliant resource is created or updated, and remediation tasks then correct pre-existing non-compliant resources, closing the compliance gap without manual intervention.

Why this answer

It uses Azure Policy at the root management group to enforce inheritance across all subscriptions, with custom policy definitions for allowed locations, NSG rules blocking high-risk ports, and storage HTTPS. The 'deployIfNotExists' effect enables automatic remediation of non-compliant resources, and remediation tasks fix existing non-compliant resources, meeting all requirements without manual intervention.

Exam trap

The trap here is confusing Azure Policy's 'deployIfNotExists' effect with manual remediation or third-party automation, leading candidates to choose options that lack native, automatic, and inherited policy enforcement at the management group level.

How to eliminate wrong answers

Option A is wrong because Azure Policy Guest Configuration is designed for in-guest machine settings (e.g., OS configuration), not for enforcing region, NSG rules, or storage HTTPS; assigning policies at each subscription breaks inheritance, and Azure Automation runbooks are not the native remediation mechanism for Azure Policy. Option C is wrong because Azure Blueprints are used for orchestrating resource deployments (including policy assignments) but do not provide automatic remediation; manual remediation violates the requirement for automatic remediation where possible. Option D is wrong because a custom PowerShell script with Logic Apps alerts and manual fixes is not a scalable, automated, or policy-driven solution; it lacks inheritance, automatic remediation, and centralized enforcement at the management group level.

331
Multi-Selectmedium

Which THREE security controls should you implement to protect a web application against common OWASP Top 10 vulnerabilities?

Select 3 answers
A.Role-Based Access Control (RBAC)
B.Input validation on all user inputs
C.Content Security Policy (CSP) headers
D.Web Application Firewall (WAF)
E.Multi-factor authentication (MFA)
AnswersB, C, D

Input validation is a secure-coding control that rejects or sanitizes any user-supplied data that does not conform to expected formats, types, or lengths before the application processes it. By applying allowlist patterns and output encoding, it prevents malicious payloads from being interpreted as executable code, directly thwarting SQL injection, command injection, and stored/reflected XSS. It must be applied both on the client for UX and, critically, on the server as the authoritative enforcement point, and it is the first line of defense against the OWASP Top 10.

Why this answer

Input validation on all user inputs (B) is correct because it directly mitigates injection flaws such as SQL injection, command injection, and cross-site scripting (XSS) by rejecting or sanitizing untrusted data before it reaches interpreters or the browser. Content Security Policy (CSP) headers (C) are correct because they restrict which scripts, styles, and other resources the browser may load, providing defense-in-depth against XSS and data injection attacks listed in the OWASP Top 10. A Web Application Firewall (WAF) (D) is correct because it inspects HTTP/HTTPS traffic and blocks common attack patterns like SQLi, XSS, and path traversal, offering a compensating control for vulnerabilities that may not yet be patched in the application.

Role-Based Access Control (A) and Multi-factor authentication (E) are valuable identity and access management controls, but they address authentication and authorization concerns rather than the broad set of injection, misconfiguration, and client-side vulnerabilities targeted by the OWASP Top 10, so they are not among the three required controls here.

332
MCQeasy

A company uses Microsoft Sentinel for SIEM. They need to ensure that security events from Azure Active Directory (now Microsoft Entra ID) are ingested into Sentinel. Which data connector should they enable?

A.Microsoft Entra ID connector
B.Office 365 connector
C.Azure Activity connector
D.Microsoft Defender XDR connector
AnswerA

The Microsoft Entra ID connector (formerly Azure AD) is the correct choice because it directly ingests SigninLogs and AuditLogs from Entra ID into Sentinel. These tables contain authentication attempts, conditional access results, and user and group administrative changes, which are the exact identity telemetry the customer needs. This connector enables you to build analytics rules for sign-in anomalies, MFA failures, and suspicious audit activity.

Why this answer

The Microsoft Entra ID connector (option A) is correct because it is the built-in Microsoft Sentinel data connector designed to ingest sign-in logs, audit logs, and other security events from Azure Active Directory / Microsoft Entra ID. Enabling it streams Entra ID diagnostic logs into the Sentinel workspace for analytics and detection. The Office 365 connector (B) ingests Exchange, SharePoint, and Teams activity logs, not Entra ID sign-in or audit events.

The Azure Activity connector (C) collects subscription-level control-plane operations from Azure Resource Manager, not directory events. The Microsoft Defender XDR connector (D) pulls alerts and incidents from Defender services rather than raw Entra ID security logs.

333
MCQmedium

You are reviewing a Conditional Access policy in Microsoft Entra ID. The policy is intended to block sign-ins from high-risk users. However, some high-risk users are still able to sign in. What is the most likely reason?

A.The policy is not enforced because user risk is not being evaluated (e.g., missing licenses or risk policy)
B.The policy does not include all client app types
C.The policy is set to report-only mode
D.The policy does not include all locations
AnswerA

The user risk condition in Conditional Access depends on Azure AD Identity Protection's risk signals. Without Azure AD Premium P2 licenses, or if the Identity Protection risk policy is not configured, the user risk condition has no data to evaluate, so the condition is never satisfied and the policy never applies. Consequently, even though the policy appears active, it will not enforce its access controls because risk evaluation is effectively skipped.

Why this answer

The correct answer is A: the policy is not enforced because user risk is not being evaluated (e.g., missing licenses or risk policy). For a Conditional Access policy that blocks high-risk users to work, Microsoft Entra ID Protection must actually compute user risk, which requires Entra ID P2 (or equivalent) licensing and the risk detections feeding the risk level; if risk is never evaluated, the condition never matches and high-risk users sign in. Report-only mode (C) would also let users through, but it is a deliberate configuration state rather than the most likely cause of risk-based enforcement silently failing, and the scenario implies the policy is intended to be active.

Options B and D are irrelevant here because client app types and locations are separate conditions that do not affect whether user risk is evaluated.

334
MCQeasy

Refer to the exhibit. A security analyst runs the following KQL query in Microsoft Sentinel. What is the purpose of this query?

A.List all accounts that have been locked out
B.Identify successful logins from multiple IP addresses
C.Detect brute-force attacks against Windows servers
D.Find users who logged in after hours
AnswerC

This query detects brute-force attacks by identifying patterns of repeated failed logon attempts (EventID 4625) originating from the same source IP address or targeting a single account. In a brute-force attack, an attacker systematically tries many username/password combinations against Windows servers, generating a high volume of 4625 events with a common Source Network Address. The query likely aggregates failed logon counts and thresholds, making it directly suitable for surfacing brute-force activity.

Why this answer

The query filters Windows Security Events for failed logon attempts (EventID 4625) in the last hour, groups by user account, computer, and IP address, and then shows only those with more than 10 failures. This is used to detect brute-force attacks.

335
MCQhard

Your company is deploying a new line-of-business application in Azure that must comply with PCI DSS. The application uses Azure SQL Database. You need to design a solution to encrypt sensitive data at rest and in transit, and to audit access to sensitive columns. Which combination of Microsoft security capabilities should you recommend?

A.Dynamic Data Masking and Azure SQL Firewall rules
B.Transparent Data Encryption, Always Encrypted, and Azure SQL Auditing
C.Azure Policy and Microsoft Defender for Cloud
D.Azure Storage Service Encryption and Azure Key Vault
AnswerB

Transparent Data Encryption (TDE) encrypts entire database files, backups, and transaction logs at rest using a database encryption key, protecting data at the storage layer. Always Encrypted goes further by encrypting sensitive columns with client-side keys so that database administrators and cloud operators see only ciphertext, ensuring data remains confidential even during queries. Azure SQL Auditing captures a trace of database events and queries, enabling compliance monitoring and forensic analysis of access to sensitive data. Together, these three technologies deliver encryption at rest, column-level encryption with key separation, and a clear audit trail, fully addressing typical enterprise data protection and compliance requirements.

Why this answer

Transparent Data Encryption (TDE) encrypts the SQL database at rest, Always Encrypted protects sensitive columns in transit and at rest by ensuring encryption keys are never exposed to the database engine, and Azure SQL Auditing logs all access to sensitive columns for compliance with PCI DSS requirements.

Exam trap

The trap here is that candidates often confuse Dynamic Data Masking with encryption, but masking does not protect data at rest or in transit and can be bypassed by privileged users, whereas Always Encrypted and TDE provide true encryption required by PCI DSS.

How to eliminate wrong answers

Option A is wrong because Dynamic Data Masking only obfuscates data at query time for unauthorized users but does not encrypt data at rest or in transit, and Azure SQL Firewall rules control network access but do not provide encryption or auditing. Option C is wrong because Azure Policy enforces compliance rules and Microsoft Defender for Cloud provides threat detection, but neither directly encrypts data at rest or in transit nor audits column-level access. Option D is wrong because Azure Storage Service Encryption applies only to Azure Blob and File storage, not to Azure SQL Database, and Azure Key Vault is a key management service that must be paired with an encryption mechanism like TDE or Always Encrypted to actually encrypt data.

336
Multi-Selectmedium

Your organization is designing a security solution for a new web application that will be deployed on Azure App Service. The application will access an Azure SQL Database and an Azure Storage account. The security requirements include: (1) use managed identities for authentication, (2) encrypt data at rest and in transit, (3) restrict network access to the database and storage account to only the App Service, and (4) use Azure Key Vault for secrets management. Which TWO of the following should you implement?

Select 2 answers
A.Configure the App Service to use a connection string with a storage account access key.
B.Configure private endpoints for the SQL Database and Storage account.
C.Configure the App Service to use a system-assigned managed identity.
D.Use shared access signatures (SAS) for the App Service to access the Storage account.
E.Configure service endpoints for the SQL Database and Storage account.
AnswersB, C

Private endpoints for Azure SQL Database and Azure Storage assign each resource a private IP address from your virtual network, ensuring that all traffic to these PaaS services traverses the Microsoft backbone network and never the public internet. This provides strong network-level isolation because the service endpoint is only reachable from your VNet, and you can disable public access entirely, eliminating exposure to internet-based attacks. Private endpoints also support Azure Private Link, which integrates with network security groups, route tables, and on-premises connectivity via VPN or ExpressRoute. Unlike service endpoints, private endpoints give you granular control over which specific resource instances can be accessed, not just the service as a whole.

Why this answer

Option B is correct because private endpoints assign a private IP address from your virtual network to the Azure SQL Database and Storage account, so those PaaS services are reachable only through the private link and public network access can be disabled, satisfying the requirement to restrict network access to only the App Service (when the App Service is VNet-integrated). Option C is correct because a system-assigned managed identity gives the App Service an identity in Microsoft Entra ID, allowing it to authenticate to Azure SQL Database and Storage without storing credentials, which directly fulfills the managed-identity authentication requirement. Option A is incorrect because using a storage account access key in a connection string relies on a shared secret rather than a managed identity and exposes a highly privileged key.

Option D is incorrect because SAS tokens are shared secrets with delegated permissions, not managed-identity authentication, and they do not restrict network access to the App Service. Option E is incorrect because service endpoints only extend the VNet identity to the PaaS service over the Azure backbone; they do not give the SQL Database or Storage account a private IP, and the service still exposes a public endpoint, so they do not meet the strict 'only the App Service' network restriction as well as private endpoints do.

Exam trap

SC-100 often tests the difference between service endpoints and private endpoints; candidates may choose service endpoints thinking they restrict access to a specific resource, but they only restrict to a subnet and do not provide private IP connectivity.

337
Multi-Selecthard

A company wants to implement hybrid identity with Microsoft Entra ID. Which TWO components are required for password hash synchronization? (Choose two.)

Select 2 answers
A.Microsoft Entra Connect
B.Microsoft Entra Domain Services
C.Password hash synchronization feature enabled in Entra Connect
D.Microsoft Entra ID Protection
E.Azure AD Application Proxy
AnswersA, C

Microsoft Entra Connect is the on-premises hybrid identity synchronization engine that installs on a server and replicates directory objects (users, groups, contacts, and devices) from your local Active Directory to Microsoft Entra ID. It is the correct answer because its primary purpose is to establish a single source of identity across on-premises and cloud directories, and it also configures the chosen authentication method (password hash sync, pass-through authentication, or AD FS federation). Without this tool, you cannot maintain synchronized identities for hybrid scenarios.

Why this answer

Microsoft Entra Connect (option A) is required because it is the on-premises synchronization tool that connects Active Directory Domain Services to Microsoft Entra ID and performs the directory synchronization and sign-in method configuration. The password hash synchronization feature enabled in Entra Connect (option C) is also required, since password hash synchronization is a sign-in option that must be explicitly selected and configured within Entra Connect for on-premises password hashes to be synchronized to Entra ID. Microsoft Entra Domain Services (option B) is a managed domain service for legacy protocols and does not perform password hash synchronization from on-premises AD.

Microsoft Entra ID Protection (option D) provides risk detection and Conditional Access signals, not directory synchronization. Azure AD Application Proxy (option E) publishes on-premises web applications remotely and is unrelated to password hash synchronization.

Exam trap

The trap here is that candidates often confuse 'Microsoft Entra Domain Services' (a managed domain service) with 'Microsoft Entra Connect' (the sync tool), or they think enabling the feature alone is sufficient without the sync engine, but both the tool and the feature toggle are required.

338
MCQhard

A multinational company uses Microsoft Purview for data governance. They need to automatically classify sensitive data in Microsoft 365 and apply retention labels. The solution must use pattern-based detection for credit card numbers and support custom keywords. What should they configure?

A.Use a trainable classifier for credit card numbers.
B.Create a custom sensitive info type with a regex pattern and keyword list.
C.Configure a DLP policy with a rule for credit card numbers.
D.Create a retention label with auto-labeling policy.
AnswerB

A custom sensitive info type is the right mechanism because it lets you define a regular expression to match the credit card number format, optionally with the Luhn checksum validation, plus a keyword list (e.g., 'VISA', 'MasterCard', 'card number') to raise confidence and reduce false positives. Purview uses these custom SITs in DLP policies, auto-labeling, and retention label conditions. This directly gives you a detectable classification without depending on built-in types.

Why this answer

The requirement specifies pattern-based detection for credit card numbers and support for custom keywords. A custom sensitive info type in Microsoft Purview allows you to define a regex pattern (e.g., for credit card numbers) and associate a custom keyword list, enabling precise auto-classification and retention label application. Trainable classifiers use machine learning, not pattern-based detection, and DLP policies or retention label auto-labeling policies do not directly create the pattern and keyword logic needed.

Exam trap

The trap here is that candidates confuse the configuration of a custom sensitive info type (which defines the detection logic) with the policy that uses it (DLP or auto-labeling), assuming DLP or auto-labeling policies can directly define regex patterns and keywords without a separate sensitive info type.

How to eliminate wrong answers

Option A is wrong because a trainable classifier uses machine learning to identify content based on examples, not pattern-based detection with regex and custom keywords. Option C is wrong because a DLP policy enforces actions (e.g., block, notify) on sensitive data but does not itself define the pattern or keyword logic for classification; it relies on existing sensitive info types. Option D is wrong because a retention label with auto-labeling policy applies labels based on existing sensitive info types or trainable classifiers, but does not create the pattern-based detection and custom keyword configuration itself.

339
Multi-Selecthard

Which THREE of the following are best practices for designing a secure hybrid network architecture with Azure?

Select 3 answers
A.Use Azure Bastion for secure VM access without public IPs
B.Open all ports to a management subnet for ease of administration
C.Use ExpressRoute with Azure Firewall for traffic inspection
D.Use a single VPN gateway for all regions
E.Enable forced tunneling for all internet-bound traffic
AnswersA, C, E

Azure Bastion is a fully PaaS-based service that provides secure RDP/SSH access to Azure VMs over TLS, eliminating the need for any public IP addresses on the VMs themselves. It includes RBAC integration, Azure AD authentication, and hybrid AAD join support, while also allowing you to restrict inbound traffic through NSG rules to only the Bastion subnet. This reduces the attack surface for management ports by never exposing them to the internet and supports auditing via Azure Monitor.

Why this answer

Option A is correct because Azure Bastion provides RDP/SSH connectivity to VMs directly through the Azure portal over TLS, eliminating the need to expose public IP addresses or open inbound management ports (3389/22) on the VMs, which removes a major attack surface in a hybrid design. Option C is correct because ExpressRoute gives private, dedicated connectivity between on-premises and Azure that bypasses the public internet, and pairing it with Azure Firewall provides centralized, stateful Layer 3–7 traffic inspection and filtering across the hybrid boundary. Option E is correct because forced tunneling routes all internet-bound traffic from Azure subnets back through on-premises (via UDRs with a next hop of the VPN/ExpressRoute gateway), enabling on-premises firewalls, proxies, and DLP to inspect and control that traffic consistently.

Option B is wrong because opening all ports to a management subnet violates least-privilege and network segmentation principles, dramatically expanding the attack surface. Option D is wrong because a single VPN gateway is a regional resource and a single point of failure; multi-region designs should use gateways per region (or zone-redundant/active-active configurations) for resiliency and latency.

340
Multi-Selectmedium

Which TWO Microsoft security solutions should be integrated to provide a comprehensive Zero Trust architecture that includes identity protection, endpoint detection, and response? (Select exactly two correct options.)

Select 2 answers
A.Microsoft 365 E5
B.Microsoft Defender XDR
C.Microsoft Entra ID
D.Microsoft Sentinel
E.Microsoft Purview
AnswersB, C

Microsoft Defender XDR is a core security solution because it correlates signals across endpoints, email, identities, and cloud apps, enabling extended detection and response. In a Zero Trust architecture, it serves as the enforcement and detection plane that consumes identity and endpoint telemetry. Integrating it with Entra ID lets suspicious identity behavior trigger automated response actions such as blocking a sign-in.

Why this answer

Microsoft Defender XDR (B) is correct because it is the extended detection and response platform that unifies signals across endpoints (Defender for Endpoint), identities (Defender for Identity), email and collaboration (Defender for Office 365), and cloud apps (Defender for Cloud Apps), delivering automated endpoint detection and response capabilities required by the scenario. Microsoft Entra ID (C) is correct because it provides the identity protection pillar of Zero Trust, including Conditional Access, risk-based sign-in and user risk detection via Entra ID Protection, and phishing-resistant authentication such as FIDO2 and Windows Hello for Business. Together, Entra ID secures and verifies identities while Defender XDR detects, investigates, and responds to threats across endpoints and other workloads, satisfying the identity protection plus endpoint detection and response requirement.

Microsoft 365 E5 (A) is a licensing bundle rather than a distinct security solution, so it does not itself constitute the integration of identity protection and XDR. Microsoft Sentinel (D) is a SIEM/SOAR platform for centralized log ingestion and orchestration, not the endpoint detection and response engine, and Microsoft Purview (E) focuses on data governance, compliance, and information protection rather than identity or endpoint threat response.

Exam trap

The trap here is that candidates often confuse Microsoft 365 E5 (a licensing bundle) with a specific security solution, or they mistakenly think Microsoft Sentinel (a SIEM) fulfills the endpoint detection requirement, when in fact Sentinel is for log analysis and not for real-time endpoint detection and response.

341
MCQmedium

Your organization is designing a solution to protect sensitive data in Microsoft SharePoint Online. You need to ensure that documents containing credit card numbers are automatically encrypted when shared with external users. What should you configure?

A.A Data Loss Prevention (DLP) policy that blocks sharing
B.Information Rights Management (IRM) for SharePoint
C.An auto-labeling policy for sensitivity labels with encryption
D.A retention policy with a hold
AnswerC

An auto-labeling policy for sensitivity labels with encryption is correct because it uses sensitive info types or trainable classifiers to scan content and automatically apply a label that triggers Microsoft 365 encryption (AES-256) and rights management. This label persists with the file or email and enforces policies such as view-only, Do Not Forward, watermarking, and conditional access, regardless of where the data is stored or shared. Because the encryption is tied to the label and managed by Azure AD RMS, the protection is permanent and follows the data even when it leaves the tenant or is copied to other applications, meeting the core requirement to protect sensitive data automatically.

Why this answer

The correct option is C: an auto-labeling policy for sensitivity labels with encryption. In Microsoft Purview, auto-labeling policies scan SharePoint Online content for sensitive information types such as credit card numbers and automatically apply a sensitivity label; when that label is configured with encryption, the document is encrypted and the protection travels with the file even when shared with external users. Option A is wrong because a DLP policy that blocks sharing prevents external sharing rather than encrypting the document, and DLP does not itself apply encryption.

Option B is wrong because SharePoint IRM encrypts files at rest in the library and relies on the service to enforce permissions, but it does not automatically classify and encrypt documents based on sensitive content detection. Option D is wrong because a retention policy with a hold only preserves content for compliance and does not encrypt it.

342
Multi-Selecthard

A company is deploying Microsoft Entra ID Governance. They need to implement a least privilege access model for their Azure resources. Which TWO features should they use? (Choose two.)

Select 2 answers
A.Privileged Identity Management (PIM)
B.Identity Protection
C.Conditional Access policies
D.Microsoft Intune compliance policies
E.Entitlement Management
AnswersA, E

PIM provides just-in-time, time-bound, and approval-based activation of privileged roles across Azure AD, Azure resources, and other Microsoft services. It eliminates permanent standing admin access by requiring users to request activation for a limited window, with MFA and policy-based approvals. In an Entra ID governance deployment, PIM directly governs the assignment and activation of privileged roles, making it the correct answer for the scenario.

Why this answer

Privileged Identity Management (PIM) is correct because it provides just-in-time (JIT) privileged access to Azure resources, enabling time-bound and approval-based role activation. This directly supports a least privilege model by ensuring users only have elevated permissions when needed, reducing standing access.

Exam trap

The trap here is confusing Identity Protection (a risk-detection tool) or Conditional Access (an access-enforcement tool) with governance features that directly manage role assignments and time-bound access, leading candidates to overlook the two specific features designed for least privilege in Azure resources.

343
MCQeasy

A company uses Microsoft Sentinel and wants to use a built-in connector to ingest logs from Amazon Web Services (AWS). Which connector should they use?

A.ServiceNow connector
B.Azure Policy for AWS
C.Office 365 connector
D.Amazon Web Services S3 connector
AnswerD

The Amazon Web Services S3 connector is the built-in Microsoft Sentinel connector for AWS, ingesting CloudTrail management events (and optionally data events) via logs stored in an S3 bucket. It uses an SQS queue to notify Sentinel of new log files, and an Azure Function runs to pull them into the Log Analytics workspace. This is the standard, supported method for continuous AWS log ingestion, making it the correct option.

Why this answer

The Amazon Web Services (AWS) S3 connector is the correct built-in connector in Microsoft Sentinel for ingesting logs from AWS. It works by configuring AWS to send logs (such as CloudTrail, VPC Flow Logs, or GuardDuty findings) to an S3 bucket, which Sentinel then polls via the S3 REST API using an IAM role for secure, cross-account access. This is the native, supported method for log ingestion from AWS into Sentinel.

Exam trap

The trap here is that candidates may confuse Azure Policy for AWS (which is a governance tool, not a log ingestion connector) with a valid data source, or assume that a generic connector like ServiceNow could be adapted for AWS log ingestion, when only the AWS S3 connector is the built-in, purpose-built option.

How to eliminate wrong answers

Option A is wrong because the ServiceNow connector is designed to ingest security incidents and IT service management data from ServiceNow, not logs from AWS. Option B is wrong because Azure Policy for AWS is a governance and compliance feature that applies Azure Policy definitions to AWS resources via Azure Arc, not a log ingestion connector for Sentinel. Option C is wrong because the Office 365 connector ingests audit logs and activity data from Microsoft 365 services, not from AWS.

344
MCQmedium

A company is implementing a cloud security governance strategy. They need to ensure that all Azure resources are compliant with internal security policies before deployment. Which approach should they use?

A.Configure Azure Firewall to block non-compliant resources
B.Assign Azure Policy definitions with 'deny' effect at the subscription scope
C.Deploy resources using Azure Blueprints
D.Use Azure DevOps pipelines with manual approval gates
AnswerB

Assigning a policy with the 'deny' effect at subscription scope makes Azure Resource Manager evaluate every create/update operation against the policy rule before provisioning. If a resource is non-compliant, the platform rejects the request with a 403 or similar error, so no infrastructure is ever deployed that violates governance. Because this happens in the control plane, it works uniformly for portal, CLI, PowerShell, templates, and DevOps pipelines, closing the gap that manual or network-based controls leave open.

Why this answer

Azure Policy with the 'deny' effect is the correct approach because it proactively prevents the deployment of any resource that violates defined security policies at the subscription scope. This ensures compliance before deployment by evaluating the resource against policy rules during the creation or update operation, blocking the request if non-compliant. Unlike reactive measures, this enforces governance at the point of deployment without requiring post-deployment remediation.

Exam trap

The trap here is that candidates confuse Azure Policy with Azure Blueprints, thinking Blueprints enforce compliance, but Blueprints only package and deploy policies—the actual enforcement comes from the Policy definitions themselves.

How to eliminate wrong answers

Option A is wrong because Azure Firewall is a network security service that filters traffic at layers 3-7, not a governance tool that can evaluate or block resource deployments based on compliance policies. Option C is wrong because Azure Blueprints orchestrates the deployment of resource templates and policies but does not inherently enforce compliance; it relies on Azure Policy definitions within the blueprint for enforcement. Option D is wrong because Azure DevOps pipelines with manual approval gates add a human review step but do not automatically enforce compliance; they can be bypassed or delayed and do not prevent deployment of non-compliant resources at the Azure Resource Manager level.

345
Multi-Selecthard

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You need to design a unified security operations platform. Which THREE capabilities should you enable?

Select 3 answers
A.Azure Policy for security controls
B.Microsoft Purview Information Protection
C.Microsoft Defender XDR incident integration with Sentinel
D.Microsoft Sentinel SIEM
E.Microsoft Sentinel UEBA (User and Entity Behavior Analytics)
AnswersC, D, E

The Microsoft Defender XDR incident integration is the correct answer because it connects Microsoft 365 Defender (covering endpoints, identities, email, and cloud apps) directly to Sentinel, pulling in pre-correlated incidents rather than raw alerts. This integration provides a single queue for security operations, enables bidirectional incident synchronization (status changes propagate both ways), and allows analysts to leverage Sentinel's SOAR actions across Defender XDR incidents. Without this integration, defenders would need to juggle multiple portals, losing the unified visibility that the question requires.

Why this answer

Option C is correct because integrating Microsoft Defender XDR incidents with Microsoft Sentinel streams correlated alerts and incidents from Defender XDR products (Defender for Endpoint, Identity, Office 365, Cloud Apps) into Sentinel, enabling a single incident queue and unified investigation across the SOC. Option D is correct because Microsoft Sentinel provides the cloud-native SIEM layer—log ingestion via data connectors, analytics rules, and KQL-based hunting—that serves as the central platform for the unified security operations design. Option E is correct because Sentinel UEBA builds behavioral baselines and entity pages (users, hosts, IPs) that surface anomalous activity and enrich incidents, which is essential for detecting threats that static rules miss in a unified SOC.

Option A is not correct here because Azure Policy governs resource compliance and configuration, not security operations incident detection or response. Option B is not correct because Microsoft Purview Information Protection focuses on data classification, labeling, and DLP, which is a data-governance capability rather than a SIEM/XDR operations capability.

Exam trap

The trap here is that candidates may confuse Azure Policy (a compliance tool) or Purview Information Protection (a data protection tool) with core security operations capabilities, when the question specifically asks for capabilities that unify detection and response across a SIEM and XDR platform.

346
MCQeasy

You are designing a network security solution for a multi-tier application hosted in Azure. The front-end web tier must be accessible from the internet, but the back-end database tier must only accept traffic from the front-end tier. Which Azure service should you use to enforce this restriction?

A.Azure Firewall
B.Network Security Groups (NSGs)
C.Azure Bastion
D.Application Gateway
AnswerB

Network Security Groups are the fundamental Azure service for filtering traffic between subnets in the same virtual network. They are stateful and contain inbound and outbound security rules that evaluate source/destination IP, port, and protocol, allowing you to permit only required traffic between tiers (e.g., web to app on 443). By default, all VNet traffic is allowed, so explicit NSG rules are required to enforce least-privilege segmentation.

Why this answer

Network Security Groups (NSGs) [CORRECT] are the right choice because they let you write inbound security rules that allow traffic to the database tier only from the front-end tier's subnet or NSG (using source service tags or NSG references), while denying all other inbound traffic including internet sources. NSGs operate at the subnet/NIC level in Azure and are the standard mechanism for micro-segmentation between tiers of an application. Azure Firewall (A) is a centralized, stateful firewall for controlling outbound/inbound traffic at the VNet level, but it is not the typical tool for simple tier-to-tier allow/deny rules and is more costly and complex than needed here.

Azure Bastion (C) provides secure RDP/SSH access to VMs via the Azure portal and does not restrict application-tier traffic. Application Gateway (D) is a layer-7 web traffic load balancer and WAF for the front-end web tier, not a mechanism for restricting database-tier access.

347
MCQeasy

Your company uses Microsoft Defender for Cloud to secure Azure workloads. You need to ensure that all storage accounts have the 'Secure transfer required' setting enabled. What should you use?

A.Azure role-based access control (RBAC)
B.Azure Blueprints
C.Microsoft Defender for Cloud regulatory compliance dashboard
D.Azure Policy
AnswerD

Azure Policy evaluates storage accounts against a built-in or custom definition and enforces the 'Secure transfer required' setting, remediating non-compliant resources at scale. This satisfies the stem's requirement to ensure the setting is enabled across all storage accounts.

Why this answer

Azure Policy can audit and enforce the 'Secure transfer required' setting across all storage accounts. Option A (RBAC) is incorrect because RBAC controls access permissions, not resource configuration. Option B (Azure Blueprints) is deprecated and not the direct solution for this requirement.

Option C (Microsoft Defender for Cloud regulatory compliance dashboard) provides visibility but does not enforce settings.

348
MCQmedium

A multinational corporation is designing a secure access solution for remote employees using company-managed devices. The solution must enforce device compliance before granting access to corporate resources, support single sign-on (SSO) for SaaS applications, and provide conditional access policies based on risk. Which combination of Microsoft security products should you recommend?

A.Microsoft Intune + Microsoft Entra ID + Microsoft Defender for Cloud Apps
B.Microsoft Intune + Microsoft Defender for Endpoint + Microsoft Sentinel
C.Microsoft Entra ID + Microsoft Defender for Cloud Apps + Microsoft Purview
D.Microsoft Configuration Manager + Microsoft Entra ID + Microsoft Defender for Identity
AnswerA

This combination forms a complete Conditional Access pipeline. Intune reports device compliance state—including patching, encryption, and jailbreak status—to Entra ID, which evaluates that signal alongside user and location at sign-in. Defender for Cloud Apps then enforces session-level and app-level policies, such as blocking downloads from a risky app or requiring additional controls. Together they deliver end-to-end Zero Trust for cloud resources.

Why this answer

Microsoft Intune provides device compliance, Microsoft Entra ID provides SSO and conditional access, and Microsoft Defender for Cloud Apps provides risk-based access control. The other combinations miss key components.

349
MCQeasy

A company is designing a security operations strategy using Microsoft Sentinel. They want to prioritize triage of incidents that involve critical assets. The SOC manager suggests using the entity behavior analytics feature. Which capability of entity behavior analytics helps achieve this goal?

A.It combines multiple alerts into a single incident using Fusion.
B.It uses threat intelligence to correlate with known bad actors.
C.It profiles entities and assigns an anomaly score based on deviations from baseline behaviors.
D.It automatically groups incidents by severity and asset criticality.
AnswerC

UEBA in Microsoft Sentinel profiles entities such as users, devices, and applications by establishing a baseline of their typical activities—like login times, geo-locations, accessed resources, and peer-group interactions. It then assigns an anomaly score to each deviation from that baseline, with high scores indicating potentially malicious or risky behavior. This method detects threats that may be unrecognized by signature-based tools because it focuses on behavioral change rather than known attack patterns, enabling identification of compromised entities or insider threats.

Why this answer

Entity behavior analytics (UEBA) in Microsoft Sentinel profiles entities such as users, hosts, or applications by establishing baseline behaviors over time. It then assigns an anomaly score to deviations from that baseline, enabling SOC analysts to prioritize incidents involving critical assets based on unusual activity rather than static rules. This directly supports the goal of triaging incidents by highlighting anomalous behavior on high-value targets.

Exam trap

The trap here is that candidates confuse entity behavior analytics (UEBA) with Fusion or threat intelligence correlation, assuming any 'intelligent' feature must involve combining alerts or external threat data, rather than recognizing that UEBA is specifically about profiling internal entity behavior and scoring anomalies.

How to eliminate wrong answers

Option A is wrong because Fusion is a correlation engine that combines multiple alerts from different products into a single incident using machine learning, not entity behavior profiling or anomaly scoring. Option B is wrong because threat intelligence correlation with known bad actors is a separate capability (e.g., TI integration), not entity behavior analytics, which focuses on internal behavioral baselines rather than external threat feeds. Option D is wrong because automatic grouping by severity and asset criticality is a feature of incident classification or automation rules, not a function of entity behavior analytics, which provides per-entity anomaly scores rather than grouping incidents.

350
MCQhard

Your organization, Contoso Ltd., is migrating its on-premises workloads to Azure. The environment includes 200 virtual machines (VMs) running Windows Server and 50 VMs running Linux. You are responsible for designing the security infrastructure. The company has the following requirements: 1) All VMs must be protected against malware. 2) Security updates must be applied automatically to Windows VMs within 24 hours of release. 3) Linux VMs must receive critical security patches within 48 hours. 4) A central dashboard must provide visibility into the security posture of all VMs. 5) All VMs must be onboarded to Microsoft Defender for Cloud to enable advanced threat protection. 6) The solution must minimize administrative overhead. You have implemented the following: - All VMs are enrolled in Microsoft Defender for Cloud with the enhanced security features enabled. - Azure Update Manager is configured to schedule updates. - Microsoft Defender for Endpoint is installed on all Windows VMs. However, after a month, the security team reports that: - 50 Windows VMs did not receive security updates within 24 hours. - 10 Linux VMs have not received any patches. - The central dashboard shows that 30 VMs are not reporting their security status. - A malware outbreak occurred on 5 Windows VMs that were not protected by Defender for Endpoint. You need to identify the most likely root cause and recommend a corrective action.

A.Onboard the VMs to Azure Arc and enable the Azure Update Manager on all VMs via Arc.
B.Implement Azure Policy to enforce that all VMs have the 'Deploy default Microsoft IaaS anti-malware extension for Windows' policy assigned and create a remediation task.
C.Configure Microsoft Entra Privileged Identity Management (PIM) to require approval for update deployments.
D.Review the network security groups (NSGs) and firewall rules to ensure outbound connectivity to the required Microsoft endpoints for Microsoft Defender for Endpoint and Windows Update.
AnswerD

Reviewing NSGs and firewall rules is correct because VMs require outbound connectivity to Microsoft endpoints for both Windows Update and Microsoft Defender for Endpoint cloud services. If egress is blocked, update scans fail, definition updates cannot download, and Defender for Endpoint sensors cannot upload machine telemetry or receive policy. The fix should ensure NSG rules and any network virtual appliance or firewall allow traffic to the service tags (e.g., WindowsUpdate, AzureFrontDoor, and Defender for Endpoint URLs/IPs). This directly addresses the root cause rather than layering management, policy, or identity tools.

Why this answer

The symptoms—VMs missing updates, not reporting status, and lacking Defender for Endpoint protection—point to a connectivity failure. Microsoft Defender for Endpoint and Windows Update require outbound connectivity to specific Microsoft endpoints (e.g., *.endpoint.microsoft.com, *.update.microsoft.com). Without this, VMs cannot receive updates, report security posture, or download Defender definitions, directly explaining all reported issues.

Exam trap

The trap here is that candidates often focus on configuration or policy gaps (like missing extensions or update schedules) instead of recognizing that all symptoms—missing updates, no reporting, and unprotected VMs—stem from a single underlying network connectivity issue.

How to eliminate wrong answers

Option A is wrong because Azure Arc is used to manage non-Azure machines; all VMs are already in Azure, so onboarding to Arc adds unnecessary complexity and does not address the root cause of connectivity or missing Defender protection. Option B is wrong because the 'Deploy default Microsoft IaaS anti-malware extension for Windows' policy deploys the legacy Microsoft Antimalware extension, not Microsoft Defender for Endpoint, and does not solve the update or reporting failures. Option C is wrong because Microsoft Entra PIM controls privileged access and approval workflows for role assignments, not update deployment scheduling or connectivity; it does not fix missing patches or Defender protection.

351
MCQmedium

Your company uses Microsoft Sentinel for security operations. You need to design a solution that automatically remediates a detected threat by blocking a malicious IP address on Azure Firewall. Which Microsoft Sentinel feature should you use?

A.Analytics rules
B.Workbooks
C.SOAR playbooks
D.User and Entity Behavior Analytics (UEBA)
AnswerC

SOAR playbooks in Microsoft Sentinel are Azure Logic Apps–based workflows that automate response and remediation actions when triggered by an incident, alert, or automation rule. They can run actions like isolating a compromised VM, blocking an IP, or sending notifications, and they integrate with external tools like Microsoft Defender or third-party SOC platforms. Playbooks are the correct option because they provide active remediation, not just detection or visualization.

Why this answer

Security Orchestration, Automation, and Response (SOAR) in Microsoft Sentinel uses playbooks to automate remediation actions like blocking IPs on Azure Firewall. Option A is wrong because analytics rules only generate alerts. Option B is wrong because workbooks visualize data.

Option D is wrong because UEBA analyzes behavior but does not automate remediation.

352
MCQeasy

A company has a hybrid identity deployment using Azure AD Connect. They want to ensure that if a user's on-premises account is disabled, the corresponding Azure AD account is also disabled within 30 minutes. Which setting should they configure?

A.Enable password hash synchronization
B.Configure the synchronization interval for directory changes
C.Install Azure AD Application Proxy
D.Enable password writeback
AnswerB

Azure AD Connect's default delta synchronization runs every 30 minutes, which determines how soon on-premises directory changes appear in Azure AD. By configuring the synchronization interval to a shorter period, you reduce the latency of object and attribute updates. This is the appropriate action to speed up propagation of directory changes, because the interval directly controls the replication rhythm. Since the step is to take for faster synchronization, this choice satisfies the scenario.

Why this answer

Azure AD Connect's default synchronization cycle for directory changes is 30 minutes. By configuring the synchronization interval (via the Azure AD Connect scheduler or PowerShell), you can ensure that disabled on-premises accounts are reflected in Azure AD within that timeframe. This setting directly controls how frequently Azure AD Connect processes and synchronizes changes from the on-premises Active Directory to Azure AD.

Exam trap

The trap here is that candidates confuse account status synchronization (which relies on the sync interval) with password-related features like password hash sync or writeback, assuming they also propagate account state changes.

How to eliminate wrong answers

Option A is wrong because password hash synchronization only synchronizes password hashes for authentication, not account status (enabled/disabled). Option C is wrong because Azure AD Application Proxy provides secure remote access to on-premises web applications and has no role in synchronizing user account states. Option D is wrong because password writeback enables password changes from Azure AD to on-premises AD, not the synchronization of account disabled status.

353
MCQmedium

A company is deploying Azure SQL Database with Azure Active Directory authentication for their application. They want to ensure that only specific Azure AD users can access the database, and that these users are authenticated at the database level. What should they do?

A.Create a server-level login for each user
B.Assign the Azure AD admin to the SQL server
C.Configure firewall rules to allow specific IPs
D.Create contained database users mapped to Azure AD identities
AnswerD

Contained database users mapped to Azure AD identities are the correct mechanism for authenticating users at the database scope. These users are defined entirely inside the database, and Azure SQL validates their Azure AD bearer token during login, so no server-level login is needed. This approach supports least privilege because permissions are scoped to the database, and you can map the user to an individual Azure AD user or a group using CREATE USER ... FROM EXTERNAL PROVIDER.

Why this answer

Contained database users in Azure SQL Database are authenticated directly at the database level using Azure AD identities, without requiring a server-level login. This allows you to grant access to specific Azure AD users or groups while enforcing authentication within the database itself, aligning with the requirement for database-level authentication.

Exam trap

The trap here is that candidates often confuse server-level Azure AD admin assignment (which enables Azure AD authentication at the server level) with the ability to control specific user access at the database level, leading them to select Option B instead of understanding that contained database users are required for granular, database-scoped authentication.

How to eliminate wrong answers

Option A is wrong because server-level logins are SQL Server authentication principals that exist at the server scope, not Azure AD identities, and they require a login to be created in the master database, which does not meet the requirement for Azure AD authentication at the database level. Option B is wrong because assigning an Azure AD admin to the SQL server grants that user or group full administrative access to the server, not the ability to restrict specific users at the database level; it is a prerequisite for Azure AD authentication but does not by itself control database-level access. Option C is wrong because firewall rules control network access by IP address, not user authentication; they are a separate security layer that allows or blocks connections from specific IP ranges but do not authenticate individual Azure AD users.

354
Multi-Selectmedium

Which TWO actions align with the Zero Trust principle of 'verify explicitly'? (Select two.)

Select 2 answers
A.Deploy a VPN for remote access
B.Use conditional access policies to evaluate user and device risk before granting access
C.Encrypt all data at rest
D.Require multifactor authentication for all users
E.Implement network segmentation to limit lateral movement
AnswersB, D

Conditional Access policies in Microsoft Entra ID act on real-time signals such as user risk, device compliance state, sign-in location, and session risk to allow access, block it, or trigger step-up authentication. This is a direct implementation of 'verify explicitly' because every access attempt is evaluated against multiple context-aware criteria before a token is issued or access is granted. The same user can be permitted on a compliant managed device but blocked or challenged when the same request originates from an unmanaged personal device, embodying never-trust-always-verify.

Why this answer

Option B is correct because conditional access policies in Microsoft Entra ID evaluate signals such as user risk, sign-in risk, device compliance, and location at the moment of each access request, which is the essence of 'verify explicitly' — authenticating and authorizing based on all available contextual signals rather than a one-time check. Option D is correct because requiring multifactor authentication for all users forces verification of identity through multiple independent credential factors (something you know plus something you have or are), directly implementing the 'verify explicitly' tenet instead of trusting a single password. The unmarked options do not belong: A (VPN for remote access) primarily establishes a secure tunnel and perimeter-style access, which is more aligned with network-based trust than explicit per-request verification; C (encrypting data at rest) supports the 'assume breach' tenet by protecting data confidentiality, not identity verification; and E (network segmentation) limits lateral movement, which also maps to 'assume breach' rather than 'verify explicitly'.

Exam trap

Microsoft often tests the misconception that encryption or network segmentation are forms of verification, but they are actually data protection and containment controls, respectively, and do not satisfy the 'verify explicitly' requirement of Zero Trust.

355
MCQhard

You are designing a security solution for an Azure SQL Database that stores sensitive customer data. The solution must encrypt the database at rest and in transit, and also mask sensitive columns from non-privileged users. Which combination of features should you implement?

A.Transparent Data Encryption (TDE) and Dynamic Data Masking (DDM)
B.Always Encrypted and Row-Level Security
C.Always Encrypted and Dynamic Data Masking (DDM)
D.Cell-level encryption and row-level security
AnswerA

TDE encrypts the entire Azure SQL database, including backups and transaction logs, transparently to applications, satisfying the at-rest encryption requirement without schema changes. DDM complements this by obfuscating sensitive columns at query runtime for non-privileged users, preventing accidental exposure of sensitive data over the network or in application results. Together they provide encryption at rest plus a display-level control, covering both storage and query-time confidentiality.

Why this answer

Option A is correct because Transparent Data Encryption (TDE) provides encryption at rest for Azure SQL Database by encrypting the database files, and Dynamic Data Masking (DDM) masks sensitive columns from non-privileged users by obfuscating data in query results without changing the stored data. Azure SQL Database also enforces encryption in transit by default via TLS, so TDE plus DDM satisfies the stated requirements. Option B is wrong because Always Encrypted protects data at rest and in use at the client, but it does not by itself mask columns from non-privileged users, and Row-Level Security restricts rows rather than masking columns.

Option C is wrong because Always Encrypted does not provide column masking for non-privileged users. Option D is wrong because cell-level encryption and row-level security address encryption and row filtering, not the required column masking.

356
MCQeasy

Your organization is using Microsoft Sentinel to collect security logs from multiple sources, including Azure Activity Logs, Office 365 Audit Logs, and on-premises Windows Event Logs. You need to ensure that security incidents are automatically created when a user from a specific IP address attempts to access a sensitive application. You have already configured the data connectors. What should you create?

A.Create a workbook to visualize the access attempts.
B.Create a watchlist containing the IP address and use it in a query.
C.Create an analytics rule that triggers an incident when access from the IP is detected.
D.Create a playbook that runs when a specific event occurs.
AnswerC

An analytics rule in Microsoft Sentinel is the detection engine that runs a scheduled or near-real-time KQL query against the workspace. When the query returns results that match the rule's condition (for example, any logs showing access from the suspect IP), it triggers an alert and automatically creates an incident with associated entities, severity, and tactics. This is the only option that performs both detection and incident creation, making it the correct way to be alerted to such access.

Why this answer

The correct option is C: Create an analytics rule that triggers an incident when access from the IP is detected. In Microsoft Sentinel, analytics rules are the built-in mechanism that evaluates ingested log data against detection logic and automatically generates incidents when conditions match, which is exactly what is required to flag access attempts from a specific IP to a sensitive application. A watchlist (option B) can store the IP for reference or enrichment in queries, but by itself it does not create incidents.

A workbook (option A) is only a visualization/reporting tool and takes no automated action, and a playbook (option D) is an automation workflow that responds to incidents or alerts but does not itself detect the access or create the incident.

357
MCQhard

Refer to the exhibit. This is a risk alert from Microsoft Entra ID Identity Protection for user jdoe@contoso.com. You are designing an automated response using Microsoft Sentinel. Which condition should you use to trigger a high-severity incident?

A.If the user risk level is 'high'
B.If the sign-in risk level is 'high'
C.If the risk event types include 'leakedCredentials'
D.If the user risk level is 'medium'
AnswerA

In Microsoft Entra ID Protection, the user risk level is an aggregated probability that an account has been compromised, calculated from multiple risk detections over time. When the user risk level is rated 'high', the service raises a user risk alert, which is exactly what this exhibit displays. The alert metadata shows the user risk as 'high', so the condition that triggered this alert is the high user risk classification, not any other factor like sign-in risk or a specific leaked credential event.

Why this answer

The correct condition is A: trigger the high-severity incident when the user risk level is 'high'. In Microsoft Entra ID Identity Protection, user risk represents the probability that a given identity has been compromised, and a 'high' user risk is the strongest aggregate signal for an account-level compromise, making it the appropriate trigger for a high-severity Microsoft Sentinel incident. Option B is not the best fit because sign-in risk is scoped to a single authentication attempt rather than the overall user account.

Option C is too narrow, since 'leakedCredentials' is only one risk detection type and does not by itself indicate the highest severity. Option D is incorrect because 'medium' user risk is a lower severity than 'high' and would not justify a high-severity incident.

358
Multi-Selecteasy

Your organization is implementing a Zero Trust network architecture in Azure. Which TWO principles are foundational to Zero Trust?

Select 2 answers
A.Use network segmentation
B.Verify explicitly
C.Assume breach
D.Rely on perimeter security
E.Trust but verify
AnswersB, C

Verifying explicitly is the core zero trust principle: every access request is authenticated and authorized based on all available data points, including user identity, device posture, location, data classification, and anomaly signals. This eliminates implicit trust and ensures that access decisions are made for each session and each request, even for previously authenticated entities. It is the primary principle that distinguishes zero trust from traditional perimeter models.

Why this answer

Option B, 'Verify explicitly,' is correct because Zero Trust requires that every access request be authenticated and authorized based on all available data points—user identity, device health, location, and workload—rather than granting implicit trust based on network location. Option C, 'Assume breach,' is correct because Zero Trust operates on the assumption that the environment is already compromised, so organizations must minimize blast radius through micro-segmentation, end-to-end encryption, and continuous monitoring to detect and respond to threats. These two principles, along with 'Use least privilege access,' form the three core Zero Trust principles as defined by Microsoft and NIST SP 800-207.

Option A, 'Use network segmentation,' is a technique or implementation control that supports Zero Trust rather than a foundational principle itself. Option D, 'Rely on perimeter security,' contradicts Zero Trust, which explicitly rejects the castle-and-moat model of trusting everything inside the corporate firewall. Option E, 'Trust but verify,' is a traditional security adage that still implies initial trust, which is incompatible with Zero Trust's requirement to never trust implicitly.

Exam trap

The trap here is that candidates often confuse network segmentation (a tactical control) with the strategic Zero Trust principle of 'Assume breach', or mistakenly think 'Trust but verify' is acceptable when the exam requires the explicit 'Verify explicitly' and 'Assume breach' as the two foundational pillars.

359
MCQmedium

Refer to the exhibit. You are reviewing an ARM template that deploys a network security group (NSG) for a web application. The NSG allows inbound HTTP traffic from any source and then denies all other inbound traffic. However, after deployment, you find that HTTP traffic is being blocked. What is the most likely cause?

A.The AllowHTTP rule uses sourcePortRange '*' which conflicts with the DenyAll rule.
B.The NSG is not associated with the subnet or network interface where the web server is deployed.
C.The DenyAll rule has a higher priority than the AllowHTTP rule, so it takes precedence.
D.The DenyAll rule uses protocol '*' which blocks all traffic including HTTP.
AnswerC

In Azure, NSG rules are evaluated in ascending priority order, where smaller numbers are processed first and the first matching rule determines the outcome. If DenyAll has a numerically lower priority (e.g., 100) than AllowHTTP (e.g., 200), then incoming TCP port 80 HTTP traffic matches DenyAll first, and since its action is Deny, the packet is dropped before AllowHTTP is ever considered. This explicit numeric precedence is the direct cause of the HTTP failure, making the higher priority of DenyAll the definitive reason.

Why this answer

The DenyAll rule has a higher priority (lower priority number) than the AllowHTTP rule, so it is evaluated first and blocks all traffic, including HTTP. To fix this, the AllowHTTP rule should have a higher priority (lower number) than the DenyAll rule.

Exam trap

Candidates often overlook that NSG rules are evaluated in priority order (lower number = higher priority). A deny-all rule with a priority lower than the allow rule will block the intended traffic.

How to eliminate wrong answers

Option A is wrong because sourcePortRange '*' is the default wildcard that matches any source port and does not conflict with the DenyAll rule; port ranges are evaluated independently, and a wildcard source port does not cause blocking. Option C is wrong because the DenyAll rule must have a higher priority number (lower precedence) than the AllowHTTP rule to be effective; if the DenyAll rule had a higher priority (lower number), it would override the Allow rule, but the question implies the Allow rule is correctly prioritized, so this is not the cause. Option D is wrong because protocol '*' matches all protocols, including HTTP (TCP port 80), but the DenyAll rule is intended to block all traffic; the issue is not the protocol wildcard but the lack of NSG association, as the DenyAll rule would only block traffic if the NSG were applied.

360
MCQeasy

Your organization wants to use Microsoft Defender XDR to automatically investigate and respond to alerts. You need to ensure that the solution can autonomously remediate confirmed threats on endpoints, such as quarantining files and isolating devices. What should you enable?

A.Microsoft Defender for Identity
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Endpoint
D.Microsoft Defender for Office 365
AnswerC

Microsoft Defender for Endpoint is the correct choice because it is an endpoint detection and response (EDR) solution that continuously monitors devices for malicious activity, triggers automated investigation, and executes remediation playbooks. Its automated response capabilities include quarantining infected or suspicious files, killing malicious processes, and isolating entire devices from the network—exactly the kind of 'auto' response the organization requires. As the endpoint component of Microsoft Defender XDR, it provides the necessary telemetry and action primitives for autonomous threat containment.

Why this answer

The correct option is C, Microsoft Defender for Endpoint, because it is the Microsoft Defender XDR workload that provides endpoint detection and response (EDR) capabilities, including automated investigation and response (AIR) that can autonomously quarantine files and isolate devices. Defender for Endpoint integrates with Defender XDR to trigger automated remediation actions on confirmed threats on endpoints. The other options do not provide endpoint remediation: Defender for Identity monitors identity signals, Defender for Cloud Apps governs cloud app usage, and Defender for Office 365 protects email and collaboration workloads, so none of them can isolate devices or quarantine endpoint files.

361
MCQmedium

Fabrikam is a healthcare organization that uses Microsoft 365 E5 and Azure. They have a hybrid identity environment with Active Directory on-premises synced to Microsoft Entra ID. The security team wants to implement a Zero Trust strategy following the 'verify explicitly' principle. They need to ensure that all access to Microsoft 365 services and Azure applications is conditionally enforced based on real-time risk signals. Additionally, they want to block legacy authentication protocols that do not support modern authentication. The solution must integrate with Microsoft Defender XDR and Microsoft Sentinel for threat intelligence. Which combination of technologies should you recommend?

A.Implement Azure AD Identity Governance with access reviews. Use Conditional Access to require hybrid Azure AD joined devices. Block legacy authentication by disabling protocols in Exchange Online. Use Azure Sentinel without Defender XDR.
B.Use Azure AD B2B for external users only. Configure Conditional Access with MFA for all users. Use Azure AD Identity Protection for risk. Block legacy authentication at the firewall level.
C.Deploy Microsoft Intune for mobile device management and require compliant devices. Use Conditional Access to block legacy protocols. Rely on Azure ATP (now Microsoft Defender for Identity) for risk signals.
D.Use Microsoft Entra Conditional Access policies with session controls from Microsoft Defender for Cloud Apps. Enable Microsoft Entra ID Protection to feed risk signals into Conditional Access. Block legacy authentication via a Conditional Access policy targeting 'Exchange Active Sync' and 'Other clients'. Integrate Microsoft Sentinel to ingest alerts from Defender XDR.
AnswerD

This solution combines real-time risk assessment from Microsoft Entra ID Protection with adaptive Conditional Access policies, allowing sign-in risk to trigger MFA, block, or session restrictions dynamically. Session controls from Microsoft Defender for Cloud Apps enable granular cloud app session monitoring and policy enforcement, such as blocking download of sensitive files based on user risk. Blocking legacy authentication explicitly via a Conditional Access policy on client apps 'Exchange ActiveSync' and 'Other clients' is the documented method to prevent credential replay attacks. Finally, integrating Microsoft Sentinel with Defender XDR centralizes alerts from across the identity, endpoint, and cloud app domains, enabling advanced hunting and a unified incident response workflow.

Why this answer

It directly implements the 'verify explicitly' principle by using Microsoft Entra ID Protection to feed real-time risk signals into Conditional Access policies, which then enforce session controls via Microsoft Defender for Cloud Apps. It blocks legacy authentication through a targeted Conditional Access policy (not just disabling protocols in Exchange Online or at the firewall), and integrates Microsoft Sentinel to ingest alerts from Defender XDR for centralized threat intelligence. This combination ensures all access to Microsoft 365 and Azure applications is conditionally enforced based on dynamic risk, while also addressing the requirement to block legacy protocols that lack modern authentication support.

Exam trap

The trap here is that candidates often think blocking legacy authentication must be done at the protocol level (e.g., disabling in Exchange Online or firewall) rather than using a Conditional Access policy, which is the recommended and more comprehensive method in a Zero Trust architecture.

How to eliminate wrong answers

Option A is wrong because it relies on disabling legacy protocols in Exchange Online (which is incomplete—does not block protocols like POP3/IMAP/SMTP across all services) and uses Azure Sentinel without Defender XDR, violating the requirement to integrate both. Option B is wrong because it blocks legacy authentication at the firewall level (which is not granular enough and does not address protocol-level blocking within Microsoft 365), and Azure AD B2B is only for external users, not the core Zero Trust strategy for internal access. Option C is wrong because it relies on Azure ATP (now Microsoft Defender for Identity) for risk signals, but the correct modern approach is Microsoft Entra ID Protection, which provides real-time risk detection and feeds directly into Conditional Access; also, Intune for compliant devices is not the primary mechanism for risk-based conditional access.

362
MCQmedium

Your organization uses Microsoft Defender for Office 365 to protect against phishing attacks. The security team wants to implement a custom advanced phishing threshold policy that blocks suspicious emails more aggressively. Which policy type should they modify?

A.ATP policy
B.Safe Attachments policy
C.Safe Links policy
D.Anti-phishing policy
AnswerD

Anti-phishing policies in Microsoft Defender for Office 365 contain the 'Phishing email threshold' setting, which adjusts the sensitivity of the machine-learning models that detect phishing attempts. These policies also include features like impersonation protection, mailbox intelligence, and spoof intelligence, all relevant to phishing defense. This is the correct policy selection because it directly modifies the advanced threshold that controls how many phishing candidates are flagged.

Why this answer

The Anti-phishing policy in Microsoft Defender for Office 365 includes the Advanced Phishing Threshold (APT) settings that allow administrators to control the aggressiveness of phishing detection. By modifying the anti-phishing policy, you can set the phishing threshold to 'Aggressive' or 'Most Aggressive,' which applies more stringent machine learning models to block suspicious emails earlier. This is the correct policy type because it directly governs the phishing threshold level, not attachment or link scanning.

Exam trap

The trap here is that candidates confuse the outdated 'ATP policy' term with the modern anti-phishing policy, or they mistakenly think Safe Attachments or Safe Links control phishing thresholds, when in fact only the anti-phishing policy contains the Advanced Phishing Threshold settings.

How to eliminate wrong answers

Option A is wrong because 'ATP policy' is an outdated term; Microsoft Defender for Office 365 no longer uses 'ATP' as a policy name—it has been rebranded, and the correct policy for phishing thresholds is the anti-phishing policy. Option B is wrong because Safe Attachments policy controls the scanning of email attachments for malware, not the phishing threshold or aggressiveness of phishing detection. Option C is wrong because Safe Links policy protects users from malicious URLs in emails and Office documents, but it does not control the phishing threshold level or the aggressiveness of email filtering.

363
MCQmedium

Your organization uses Microsoft Purview Information Protection to label sensitive documents. You need to ensure that documents containing personally identifiable information (PII) are automatically labeled when saved in SharePoint Online. What should you configure?

A.Create a retention label with auto-labeling rule.
B.Publish a sensitivity label with auto-labeling for SharePoint.
C.Configure an auto-labeling policy for sensitivity labels targeting SharePoint.
D.Set up a DLP policy to detect PII and apply a label.
AnswerC

An auto-labeling policy in Microsoft Purview can be configured to automatically apply a sensitivity label to documents stored in SharePoint Online. You select the sensitivity label, choose the 'SharePoint Online' location, specify the sites, and define conditions based on sensitive info types or trainable classifiers. After testing, the policy can be set to enforce automatic labeling, which satisfies the requirement to classify the documents.

Why this answer

The correct answer is C: configure an auto-labeling policy for sensitivity labels targeting SharePoint. Auto-labeling policies in Microsoft Purview Information Protection are the specific mechanism that scans SharePoint Online (and OneDrive/Exchange) content for sensitive information types such as PII and automatically applies a sensitivity label when a match is found, which is exactly the requirement here. Option A is wrong because retention labels govern data lifecycle and retention, not sensitivity classification, and cannot apply sensitivity labels.

Option B is incorrect because publishing a sensitivity label only makes it available to users for manual application; it does not by itself auto-apply labels to content. Option D is incorrect because a DLP policy can detect PII and block or warn on sharing, but it does not automatically apply sensitivity labels to documents.

364
Multi-Selectmedium

Which TWO of the following are key components of a Zero Trust architecture according to Microsoft? (Choose two.)

Select 2 answers
A.Trust but verify
B.Implicit trust for internal traffic
C.Use least privilege access
D.Verify explicitly
E.Rely on a strong perimeter
AnswersC, D

Least privilege access is a cornerstone of Zero Trust because it directly reduces the potential blast radius of any compromised identity or device. Access is granted strictly on a need-to-know basis, often enforced with just-in-time (JIT) elevation and just-enough-access (JEA) scoping. This applies not only to human users but also to workloads, services, and APIs via fine-grained conditional access policies and microsegmentation. Implementing least privilege ensures that a single credential theft does not automatically grant access to downstream systems.

Why this answer

Option D, 'Verify explicitly,' is correct because Microsoft's Zero Trust model requires that every access request be authenticated and authorized based on all available data points, including user identity, device health, location, and data sensitivity, rather than assuming trust based on network location. Option C, 'Use least privilege access,' is correct because Zero Trust limits user access with just-in-time and just-enough-access (JIT/JEA) principles, risk-based adaptive policies, and data protection to minimize lateral movement and exposure. The three guiding principles Microsoft defines are verify explicitly, use least privilege access, and assume breach, so these two options align directly with that framework.

Option A, 'Trust but verify,' is not a Zero Trust principle; it reflects a traditional perimeter mindset where trust is initially granted. Option B, 'Implicit trust for internal traffic,' contradicts Zero Trust, which removes implicit trust based on network location. Option E, 'Rely on a strong perimeter,' is also contrary to Zero Trust, which assumes the perimeter can be breached and therefore does not rely on it for security.

Exam trap

The trap here is that candidates often confuse 'trust but verify' (a legacy model) with Zero Trust's 'never trust, always verify' principle, leading them to incorrectly select Option A as a key component.

365
MCQhard

Your organization uses Microsoft Defender for Cloud to assess the security posture of Azure resources. The compliance team wants to ensure that all storage accounts have secure transfer required enabled. Which action should you take in Defender for Cloud?

A.Configure the regulatory compliance dashboard
B.Review the secure score
C.Implement the 'Secure transfer to storage accounts should be enabled' recommendation
D.Enable the 'Cloud Security Posture Management' plan
AnswerC

In Microsoft Defender for Cloud, each security recommendation—including 'Secure transfer to storage accounts should be enabled'—is backed by an Azure Policy definition. Implementing this recommendation executes a remediation task that applies the policy effect (typically 'Audit' or 'DeployIfNotExists') to the identified storage accounts, setting the 'supportsHttpsTrafficOnly' property to true. This is the only option that directly enforces the required configuration, as it modifies the resource to meet the policy's compliance criteria, unlike assessment-only features.

Why this answer

The correct action is to implement the 'Secure transfer to storage accounts should be enabled' recommendation because Microsoft Defender for Cloud provides built-in security recommendations that map to specific controls. This recommendation directly checks whether the 'Secure transfer required' property is enabled on each storage account, and if not, it provides remediation steps to enforce HTTPS-only traffic, which aligns with the compliance team's requirement.

Exam trap

The trap here is that candidates confuse viewing compliance or score metrics (options A and B) with taking direct action to enforce a specific security control, or they mistakenly think enabling a higher-level plan (option D) automatically applies all underlying recommendations.

How to eliminate wrong answers

Option A is wrong because the regulatory compliance dashboard is used to view compliance posture against standards (e.g., PCI DSS, ISO 27001) and track progress, but it does not directly enforce or implement a specific security setting like secure transfer required. Option B is wrong because the secure score is a numerical summary of your overall security posture based on implemented recommendations; reviewing it shows the score impact but does not itself enable the secure transfer setting. Option D is wrong because enabling the 'Cloud Security Posture Management' plan is a prerequisite for receiving certain recommendations and advanced features, but it does not directly implement the 'Secure transfer to storage accounts should be enabled' recommendation; it only enables the capability to assess and recommend.

366
MCQeasy

Your organization is using Microsoft Sentinel for security information and event management (SIEM). You need to ensure that data from Azure Activity Logs is ingested into Sentinel. What should you configure?

A.Configure a Log Analytics workspace to collect Activity Logs
B.Use Azure Policy to stream Activity Logs to Sentinel
C.Enable Azure Monitor to forward Activity Logs to Sentinel
D.Connect Azure Activity Logs via the Microsoft Sentinel data connector
AnswerD

The Microsoft Sentinel data connector for Azure Activity is the authoritative, supported integration for ingesting control-plane events into the Sentinel workspace. This connector provisions the necessary data collector and maps the stream to the `AzureActivity` table, enabling analytics, hunting, and alerting. It appears in the Data connectors blade and is the standard first step when onboarding tenant-level logs.

Why this answer

You can connect Azure Activity Logs as a data connector in Microsoft Sentinel. Option A is wrong because Log Analytics workspace is the underlying storage, but the connection is made via data connectors. Option B is wrong because Azure Policy can enforce configuration but not directly ingest logs.

Option C is wrong because Azure Monitor is a broader service; the specific connector is needed.

367
MCQhard

Your organization uses Microsoft Purview and needs to automatically apply a retention label to all documents containing personally identifiable information (PII) in SharePoint Online. What should you configure?

A.Auto-labeling policy
B.Data loss prevention (DLP) policy
C.Service-side sensitivity label
D.Trainable classifier
AnswerA

In Microsoft Purview, an auto-labeling policy applies retention labels automatically to SharePoint Online documents based on sensitive information types, such as PII, using content pattern detection. This satisfies the stem’s constraint of automatic application without user intervention, unlike manual or default label policies, which require user action or static inheritance.

Why this answer

An auto-labeling policy in Microsoft Purview is the correct choice because it can automatically apply a retention label to SharePoint Online content when items match specified sensitive information types such as PII, without user intervention. Auto-labeling policies are designed specifically for automatic retention label application at scale across locations like SharePoint, OneDrive, and Exchange. A DLP policy is used to detect and prevent sharing or leakage of sensitive data, not to apply retention labels.

A service-side sensitivity label applies encryption/marking for sensitivity, not retention, and a trainable classifier identifies content categories but does not by itself apply retention labels.

368
MCQmedium

Your company plans to use Microsoft Sentinel to manage security incidents. You need to design a solution that reduces alert fatigue by grouping related alerts into incidents. Which feature should you enable?

A.Analytics rule with alert grouping enabled
B.Watchlists to filter noisy alerts
C.Automation rules that trigger on alert creation
D.Playbooks that run on alert creation
AnswerA

The correct mechanism for grouping related alerts into a single incident is configuring an analytics rule with alert grouping enabled. When enabled, the rule's alert grouping settings (such as grouping by entities or within a defined time window) cause multiple qualifying alerts to be automatically combined into one incident, rather than each alert creating a separate incident. This reduces alert noise and gives security analysts a correlated view of a potential attack chain.

Why this answer

The correct option is A, an analytics rule with alert grouping enabled, because in Microsoft Sentinel analytics rules can be configured with incident grouping so that related alerts are consolidated into a single incident, directly reducing alert fatigue. Grouping settings let you combine alerts that share entities or occur within a defined timeframe, which is exactly the scenario's requirement. Watchlists (B) are for storing reference data used in queries and detections, not for grouping alerts into incidents.

Automation rules (C) and playbooks (D) respond to or orchestrate actions on alerts/incidents but do not themselves group related alerts into incidents.

369
Multi-Selectmedium

Which TWO Microsoft security solutions can help enforce Zero Trust principles by verifying identity and device health before granting access to resources?

Select 2 answers
A.Microsoft Intune
B.Microsoft Purview
C.Microsoft Entra ID Conditional Access
D.Microsoft Defender for Cloud Apps
E.Microsoft Sentinel
AnswersA, C

Microsoft Intune is a unified endpoint management solution that enforces zero trust by ensuring devices are compliant and healthy before they access resources. It does this through device compliance policies (e.g., required OS versions, disk encryption, and jailbreak detection) that integrate with Entra ID Conditional Access, blocking or limiting access for non-compliant devices.

Why this answer

Microsoft Entra ID Conditional Access (C) is correct because it is the policy engine that evaluates signals such as user identity, group membership, and device compliance state to grant, block, or require MFA before access to resources, directly enforcing the Zero Trust 'verify explicitly' principle. Microsoft Intune (A) is correct because it manages device enrollment, configuration, and compliance policies, producing the device health and compliance signals that Conditional Access consumes to ensure only healthy, trusted devices get access. Together they implement the identity-plus-device verification required by Zero Trust.

Microsoft Purview (B) is a data governance, compliance, and information-protection suite, not an access-decision enforcement point. Microsoft Defender for Cloud Apps (D) is a CASB for discovering and controlling cloud app usage, and Microsoft Sentinel (E) is a SIEM/SOAR platform for threat detection and response; neither verifies identity and device health at the point of granting resource access.

Exam trap

The trap here is that candidates often confuse Microsoft Purview (data governance) or Microsoft Defender for Cloud Apps (CASB) with pre-access enforcement, but neither performs the identity and device health verification that is the core of Zero Trust's 'never trust, always verify' principle at the authentication stage.

370
MCQhard

A healthcare provider is building a new patient portal on Azure App Service. The portal calls a backend API hosted on Azure Functions. The security team requires that the API accept requests only from the portal, that the portal prove its identity to the API without storing secrets in code or configuration, and that the credentials rotate automatically. You need to recommend an authentication approach for the portal-to-API call. What should you recommend?

A.Store a client secret in Azure Key Vault and have the portal retrieve it at runtime to call the API.
B.Issue each portal instance a client certificate and configure mutual TLS between App Service and Azure Functions.
C.Enable a system-assigned managed identity on the App Service and use it to request an access token for the Azure Functions app.
D.Configure IP restrictions on the Azure Functions app to allow only the App Service outbound IP addresses.
AnswerC

A system-assigned managed identity lets App Service obtain Microsoft Entra ID tokens without any secret in code or configuration, and the underlying credential is rotated by the platform. Azure Functions can validate the token and restrict callers to the portal's identity, satisfying both the no-secret and auto-rotation requirements.

Why this answer

The cleanest way for one Azure compute resource to authenticate to another without secrets is a managed identity. The App Service obtains a Microsoft Entra ID token for the Functions app's audience, and the Functions app validates the token and authorizes the specific identity. The credential lifecycle is handled by the platform, which satisfies the automatic rotation requirement and eliminates secret sprawl.

Exam trap

The trap here is treating Key Vault as a complete answer to 'no secrets,' when the portal still has to possess and rotate a credential to reach the vault and the API.

371
MCQhard

Your organization has a Microsoft 365 E5 subscription and uses Microsoft Entra ID for identity. You need to implement a solution to secure privileged access to Azure resources, requiring just-in-time access and approval workflows. What should you configure?

A.Microsoft Defender for Identity
B.Azure AD administrative units
C.Microsoft Entra Conditional Access
D.Microsoft Entra Privileged Identity Management (PIM)
AnswerD

Microsoft Entra Privileged Identity Management (PIM) is the correct service for just-in-time privileged access. PIM allows an admin to configure roles so that users become eligible, and then activate the role for a specified time window, optionally requiring multi-approval. It also provides auditing, alerts, and access reviews to govern privilege use, directly addressing the need for approval workflows and time-bound activation.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) is the correct choice because it provides just-in-time privileged role activation, time-bound assignments, and approval workflows for Azure resources and Entra ID roles, which directly matches the requirement. PIM also supports access reviews, MFA enforcement on activation, and audit trails for privileged access. Microsoft Defender for Identity is a threat detection service for identity-based attacks, not a JIT access or approval mechanism.

Azure AD administrative units are used to scope administrative permissions to subsets of users or groups, not to provide just-in-time activation or approvals. Microsoft Entra Conditional Access enforces access policies based on conditions such as user, device, and location, but it does not provide JIT role activation or approval workflows.

372
MCQeasy

Your organization is implementing a security baseline for Windows 11 devices using Microsoft Intune. You need to ensure that BitLocker encryption is enabled on all devices and that recovery keys are stored in Microsoft Entra ID. Which policy type should you configure?

A.Device configuration profile for administrative templates.
B.Endpoint security policy for disk encryption.
C.Update rings for Windows 10 and later.
D.Compliance policy for device encryption.
AnswerB

Endpoint security policy for disk encryption is the correct approach because it consolidates all BitLocker controls — encryption method, XTS-AES cipher strength, TPM protector usage, and recovery key escrow to Entra ID — into a single, purpose-built policy type. Unlike compliance checks or ADMX templates, it actively configures BitLocker and can enforce encryption silently on target Windows devices. It aligns directly with Microsoft's security baseline guidance and provides clear status reporting in the security center.

Why this answer

The correct option is B, an Endpoint security policy for disk encryption, because in Intune this policy type is purpose-built to configure BitLocker on Windows 11 and includes the setting to back up recovery keys to Microsoft Entra ID (the 'Save BitLocker recovery information to Azure AD' option). It directly enforces encryption at the OS volume and manages key escrow to Entra ID, which is exactly the baseline requirement. Option A (administrative templates) can configure some BitLocker settings but is not the dedicated disk-encryption workload and lacks the streamlined recovery-key-to-Entra ID escrow flow.

Option C (update rings) only controls Windows quality/feature update deferrals and has nothing to do with encryption. Option D (compliance policy for device encryption) only evaluates and reports whether a device is encrypted; it does not enable BitLocker or store recovery keys.

373
Multi-Selectmedium

Which TWO should you implement to protect privileged accounts in Microsoft Entra ID?

Select 2 answers
A.Microsoft Purview Data Loss Prevention
B.Conditional Access policies requiring MFA for privileged roles
C.Microsoft Defender for Cloud security score
D.Microsoft Defender Vulnerability Management
E.Microsoft Entra Privileged Identity Management (PIM)
AnswersB, E

Conditional Access policies requiring MFA for privileged roles are a cornerstone identity protection control. These policies enforce an additional authentication factor at sign-in for users assigned to highly privileged directory roles, such as Global Administrator or Application Administrator, irrespective of location or device state. This directly thwarts stolen-password and password-spraying attacks, because an attacker lacking the second factor cannot gain access. For robust defense, such policies should be paired with device compliance checks and session controls to further harden privileged access.

Why this answer

Option B is correct because Conditional Access policies that require multifactor authentication for privileged directory roles (such as Global Administrator) enforce strong authentication at sign-in, directly reducing the risk of credential compromise for high-impact accounts. Option E is correct because Microsoft Entra Privileged Identity Management (PIM) provides just-in-time role activation, approval workflows, time-bound assignments, and access reviews, which minimize standing privileged access and its exposure window. Together, B and E address both authentication strength and the elimination of permanent admin rights, which are core controls for protecting privileged accounts in Entra ID.

Option A (Microsoft Purview Data Loss Prevention) is incorrect because it protects sensitive data in motion/at rest rather than securing privileged identities. Option C (Microsoft Defender for Cloud security score) is incorrect because it is a posture assessment metric, not an access control for privileged accounts. Option D (Microsoft Defender Vulnerability Management) is incorrect because it identifies and remediates software vulnerabilities, not privileged identity protection.

Exam trap

The trap here is that candidates often confuse a measurement or monitoring tool (like security score or vulnerability management) with an actual security control that directly protects privileged accounts, leading them to select options that are only indirectly related.

374
MCQhard

Refer to the exhibit. You are auditing an Azure subscription. The Azure Policy assignment above is targeting a resource group. The policy definition ID corresponds to a built-in policy that audits if SQL databases have transparent data encryption (TDE) enabled. What is the effect of this policy assignment?

A.The policy automatically enables TDE on non-compliant SQL databases.
B.The policy is only reported as audit, not enforced.
C.The policy applies to all resources in the management group.
D.The policy audits SQL databases for TDE and marks non-compliant resources.
AnswerD

This is correct. The Azure Policy assignment uses the 'audit' effect to evaluate whether SQL databases have Transparent Data Encryption (TDE) enabled. If a database does not have TDE enabled, the policy marks that resource as non-compliant in the Azure Policy compliance dashboard and potentially integrates with Azure Monitor for alerts and reports. The 'audit' effect only evaluates and reports—it does not automatically remediate the non-compliant database, but it does accomplish the goal of identifying and flagging resources that fail to meet the intent of the policy. This matches the behavior shown in the exhibit where the policy is configured with an audit effect and assigned to a resource group.

Why this answer

Option D is correct because the built-in policy definition audits whether SQL databases have transparent data encryption (TDE) enabled, and an audit-effect policy evaluates resources and flags non-compliant ones in the compliance report without blocking or modifying them. Since the assignment targets a resource group, it evaluates the SQL databases within that scope and marks those lacking TDE as non-compliant. Option A is wrong because audit policies do not remediate or enable TDE; that would require a DeployIfNotExists or Modify effect.

Option B is incorrect because 'audit' is the effect, not merely a reporting mode, and the policy still evaluates and flags resources. Option C is wrong because the assignment targets a resource group, not a management group, so its scope is limited to that resource group.

375
MCQmedium

The exhibit shows a KQL query in Microsoft Sentinel. What is the primary purpose of this query?

A.Find alerts that were not investigated
B.Analyze entities associated with alerts
C.Identify the most frequent high-severity alerts over the past week
D.Correlate alerts by time and alert name
AnswerC

The query first filters to High-severity alerts (likely via where Severity == 'High'), then uses summarize to count occurrences per alert name, and orders the results by count descending. This produces a ranked list of high-severity alert types based on frequency, which directly identifies the most common high-severity alerts over the specified time range. The 7-day window is established by a time filter in the where clause, aligning with the question's scenario.

Why this answer

The query uses `summarize` with `count()` and `top 5 by count_ desc` to rank alert names by frequency, filtered to `AlertSeverity == 'High'` and `TimeGenerated > ago(7d)`. This directly identifies the most common high-severity alerts over the past week, making option C correct.

Exam trap

The trap here is that candidates may misinterpret the `bin(TimeGenerated, 1h)` as correlating alerts by time and name (option D), but the query only aggregates counts per alert name, not correlating alerts across different time windows or names.

How to eliminate wrong answers

Option A is wrong because the query does not include any field or filter related to investigation status (e.g., `Status == 'New'` or `InvestigationState`), so it cannot find alerts that were not investigated. Option B is wrong because the query only aggregates `AlertName` and does not expand or analyze entity fields (e.g., `Entities`, `Account`, `IP`), so it cannot analyze entities associated with alerts. Option D is wrong because the query does not group or correlate by both time and alert name; it uses `bin(TimeGenerated, 1h)` only for time bucketing but does not correlate alerts across time windows or alert names—it simply counts occurrences per alert name.

Page 4

Page 5 of 9

Page 6

All pages