Courseiva

Microsoft Cybersecurity Architect (SC-100) — Questions 376–450

605 questions total · 9pages · All types, answers revealed

Page 5

Page 6 of 9

Page 7
376
MCQmedium

Your organization uses Microsoft Purview to protect sensitive data. You need to create a sensitivity label that automatically encrypts documents containing credit card numbers when they are shared externally. Which configuration should you use?

A.Create a trainable classifier to detect credit cards
B.Create an auto-labeling policy that applies a label with encryption for external sharing
C.Create a default label policy for SharePoint
D.Create a manual sensitivity label that users apply
AnswerB

An auto-labeling policy in Microsoft Purview can automatically detect credit card numbers using sensitive information types or classifiers and then apply a sensitivity label that is configured with encryption. By specifying that the label be applied only when content is shared externally, the policy ensures that documents containing credit card data are encrypted upon external sharing, while internal collaboration remains unaffected. This satisfies the requirement for automatic, content-aware protection without user intervention, making it the correct solution.

Why this answer

Auto-labeling in Purview can be configured to apply a sensitivity label based on sensitive info types like credit card numbers. The label should have encryption enabled for external sharing. The other options describe different scenarios: manual labeling, default labeling, or classification without encryption.

377
MCQmedium

Your organization uses Microsoft Intune and Microsoft Defender for Endpoint. You need to design a solution that automatically remediates non-compliant devices by running a remediation script. Which Intune component should you use?

A.Remediation policy in Microsoft Intune
B.Device compliance policy
C.App protection policy
D.Device configuration profile
AnswerA

Remediation policy in Microsoft Intune is a Proactive Remediation feature that pairs detection and remediation PowerShell scripts and runs them on managed Windows devices on a set schedule. When the detection script finds a rule violation, the remediation script automatically executes to restore the device to a compliant state. It reports execution results back to Intune, allowing administrators to verify fixes without manual intervention. This is the only option here that actively performs corrective actions rather than just evaluating or defining state.

Why this answer

The correct option is A, a Remediation policy in Microsoft Intune, because this feature is specifically designed to detect and automatically fix non-compliant devices by running remediation scripts (PowerShell) on them, either on a schedule or when a compliance issue is detected. It pairs with compliance policies to evaluate device state and then executes the script to bring the device back into compliance. Device compliance policies (B) only define and evaluate compliance rules and mark devices compliant or non-compliant; they do not run scripts to remediate.

App protection policies (C) protect app data on mobile devices and do not remediate device compliance. Device configuration profiles (D) push settings to devices but do not provide detection-and-remediation script logic.

378
MCQhard

Refer to the exhibit. An Azure policy is defined as shown. Which resources will be audited?

A.All Azure resources that are not compliant
B.All virtual machines with unmanaged disks
C.Virtual machines with Standard_LRS managed disks
D.Virtual machines with Premium_LRS managed disks and disk size 1024 GB
AnswerC

Standard_LRS is a managed disk SKU but does not equal Premium_LRS, so the policy's notEquals Premium_LRS condition evaluates to true for any VM using it. This makes those VMs non-compliant because the policy mandates Premium_LRS for all managed disks attached to virtual machines. The disk size is not part of the condition, so every Standard_LRS disk, regardless of capacity, triggers the same non-compliance result.

Why this answer

The Azure policy definition in the exhibit uses the 'audit' effect to evaluate a condition that checks whether the virtual machine's managed disk storage account type is 'Standard_LRS'. When the condition is true (i.e., the VM has a Standard_LRS managed disk), the policy triggers an audit event. Therefore, the policy audits all virtual machines with Standard_LRS managed disks, making option C correct.

Options A, B, and D are incorrect because the policy does not audit all non-compliant resources, unmanaged disks, or VMs with Premium_LRS disks of size 1024 GB.

Exam trap

Microsoft often tests the nuance of 'auditIfNotExists' vs. 'audit' effects, where candidates mistakenly think the policy audits all non-compliant resources or unmanaged disks, but the policy actually audits only when the specified condition (Standard_LRS disk exists) is true, not when it is false.

How to eliminate wrong answers

Option A is wrong because the policy is scoped to virtual machines and their associated disks, not all Azure resources; it does not audit general non-compliance across resource types. Option B is wrong because the policy audits virtual machines that have Standard_LRS managed disks, not unmanaged disks; unmanaged disks would not match the 'Microsoft.Compute/disks' resource type with a managed disk SKU, so they would not trigger the audit. Option D is wrong because the policy does not include a condition on disk size; it only checks for the presence of a Standard_LRS managed disk, so a Premium_LRS disk of any size would not be audited.

379
MCQmedium

Refer to the exhibit. You are reviewing a conditional access policy JSON in Microsoft Entra ID. The policy is enabled but users with the Global Administrator role are not being prompted for MFA. What is the most likely reason?

A.The policy does not include any users except by role.
B.The policy does not include any applications.
C.The grant control requires a compliant device instead of MFA.
D.The policy state is disabled.
AnswerA

The conditional access policy defines user targeting exclusively through the includeRoles array and omits the includeUsers array entirely. This means the policy only applies to sign-ins from users assigned to the specified directory roles, leaving every non-role user outside the policy scope. The absence of an includeUsers entry, such as the shortcut value 'All', prevents the policy from being universally enforced and is the root cause of the misconfiguration.

Why this answer

The Conditional Access policy JSON shows that the 'users' object does not include an 'includeUsers' property for all users or specific groups; instead, users are only included by directory role (e.g., through 'includeRoles'). If the 'includeRoles' array is either empty or does not contain the 'Global Administrator' role, then Global Administrators are not targeted by the policy. Therefore, they are not prompted for MFA despite the policy being enabled.

This is the most likely reason because the other options are incorrect: the policy may include applications (option B), the grant control could be set to MFA (not requiring compliant device) (option C), and the policy is enabled (option D).

Exam trap

The trap here is that candidates assume 'All users' includes all users regardless of role, but they overlook that the exclusion of specific roles or users can completely bypass the policy, and the exam tests whether you understand that exclusion rules override inclusion rules in Conditional Access policies.

How to eliminate wrong answers

Option B is wrong because the policy does not need to include any specific applications; if no applications are selected, the policy applies to all applications by default, which would still trigger MFA for included users. Option C is wrong because the grant control in the policy explicitly requires MFA ('mfa' in the grantControls), not a compliant device, so that does not explain why Global Administrators are not prompted. Option D is wrong because the policy state is set to 'enabled' (as shown in the JSON), so it is active and should enforce MFA for users who are not excluded.

380
MCQhard

You are designing a Zero Trust strategy for Fabrikam Inc., which uses Microsoft Entra ID, Microsoft Intune, and Microsoft Defender for Endpoint. The security team wants to enforce the principle of least privilege for administrative access to Azure resources. They require that administrators use dedicated, cloud-only accounts with no permanent role assignments. You need to recommend a solution that provides just-in-time (JIT) privileged access with approval workflows and full auditing. What should you include in your design?

A.Microsoft Defender for Cloud just-in-time (JIT) VM access
B.Azure role-based access control (RBAC) with custom roles
C.Microsoft Entra Privileged Identity Management (PIM)
D.Microsoft Entra ID Conditional Access with device compliance
AnswerC

Microsoft Entra Privileged Identity Management (PIM) provides just-in-time privileged access to Azure AD and Azure resources, requiring activation with approval and MFA. It supports eligible assignments, time-bound activations, and comprehensive audit logs, directly fulfilling the requirement for JIT access with approval workflows and auditing.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) is the designated solution for just-in-time privileged access in Microsoft Entra ID and Azure. It enables eligible role assignments, requires approval and MFA for activation, and logs all activations for auditing. This aligns with Zero Trust principles of least privilege and verifies explicitly.

Exam trap

The trap here is assuming that Azure RBAC alone provides just-in-time access, when in fact RBAC assignments are persistent unless combined with PIM for time-bound activation.

381
MCQmedium

Your organization is using Microsoft Defender for Cloud to secure applications running on Azure. You need to ensure that all Azure Storage accounts have secure transfer required enabled. What is the BEST way to enforce this?

A.Create a custom recommendation in Microsoft Defender for Cloud to alert when storage accounts do not have secure transfer required.
B.Use Azure Blueprints to apply the setting to all subscriptions.
C.Assign an Azure Policy initiative that includes the built-in policy 'Secure transfer to storage accounts should be enabled' with a 'Deny' effect.
D.Grant the 'Storage Account Contributor' role to a security group that will manually enable the setting.
AnswerC

Assigning an Azure Policy initiative that contains the built-in policy 'Secure transfer to storage accounts should be enabled' with a Deny effect is the correct preventive control. Azure Policy evaluates resource creation and update requests during the ARM API call, and the Deny effect rejects any storage account that does not have the 'Secure transfer required' property set to true, returning an error before the resource is provisioned. This ensures non-compliant storage accounts are never created, and assigning it at a management group or subscription scale provides consistent enforcement across the entire environment. An initiative bundles together multiple policies, enabling comprehensive compliance with frameworks like the Azure Security Benchmark while the Deny effect specifically blocks insecure configurations.

Why this answer

The best way to enforce that all Azure Storage accounts have secure transfer required enabled is to assign an Azure Policy initiative that includes the built-in policy 'Secure transfer to storage accounts should be enabled' with a 'Deny' effect (option C). Azure Policy is the native governance service that evaluates resource properties and can block non-compliant deployments, so a Deny effect prevents creation or modification of storage accounts that do not have secure transfer required enabled. A custom recommendation in Defender for Cloud (option A) only provides visibility and alerts; it does not enforce the setting.

Azure Blueprints (option B) can orchestrate policy assignments but is not itself the enforcement mechanism, and it is being deprecated in favor of template specs and deployment stacks. Granting the Storage Account Contributor role (option D) relies on manual action and does not guarantee enforcement.

382
MCQhard

A company is designing a secure hybrid network architecture. They have an on-premises network connected to Azure via ExpressRoute and a site-to-site VPN as backup. They want to ensure that traffic from Azure to on-premises always uses ExpressRoute when available, but automatically fails over to VPN if ExpressRoute goes down. Which configuration should they implement?

A.Configure the VPN to have a lower BGP weight than ExpressRoute.
B.Use both connections in active-active mode with BGP and rely on ECMP.
C.Disable BGP on the VPN connection and use static routes with a higher metric for the VPN.
D.Configure BGP on both connections and assign a higher local preference (e.g., 200) to routes learned via ExpressRoute.
AnswerD

BGP local preference is a standard, AS-wide attribute used to select the preferred path for outbound traffic, with higher values (e.g., 200) being preferred over the default of 100. By enabling BGP on both connections and assigning a higher local preference to routes learned via ExpressRoute, both on-premises devices and (with appropriate configuration) peers will consistently prefer ExpressRoute for all traffic. When ExpressRoute fails and its routes are withdrawn, the VPN route automatically becomes the best path because it carries the lower local preference, enabling seamless and deterministic failover. This approach is platform-independent, unlike proprietary weight, and gives explicit control over the primary/backup relationship.

Why this answer

BGP local preference is an attribute used to influence outbound traffic from an AS. By assigning a higher local preference (e.g., 200) to routes learned via ExpressRoute, Azure will prefer those routes over VPN routes (which default to local preference 100). This ensures that traffic from Azure to on-premises uses ExpressRoute when available, and automatically fails over to the VPN if the ExpressRoute BGP session drops, as the VPN routes will then be selected.

Exam trap

The trap here is that candidates often confuse BGP weight (Cisco-proprietary, local to a router) with local preference (standard, AS-wide), and incorrectly assume that lowering weight on the VPN would achieve the same result as raising local preference on ExpressRoute, but Azure does not support Cisco weight and local preference is the correct attribute for influencing outbound traffic from Azure to on-premises.

How to eliminate wrong answers

Option A is wrong because BGP weight is a Cisco-proprietary attribute that influences inbound traffic on a single router, not outbound traffic from Azure; Azure does not use Cisco weight, and lowering VPN weight would not reliably force ExpressRoute preference. Option B is wrong because active-active mode with ECMP would load-balance traffic across both connections simultaneously, not provide a primary/backup failover where ExpressRoute is always preferred. Option C is wrong because disabling BGP on the VPN connection and using static routes with a higher metric would work for simple failover, but it prevents dynamic route propagation and failover detection; BGP provides faster convergence and automatic route withdrawal, which is critical for reliable failover.

383
MCQmedium

Your organization is implementing a secure DevOps pipeline for a critical application. You need to design a solution that scans container images for vulnerabilities before they are deployed to production. Which Azure service should you integrate into the pipeline?

A.Azure Key Vault
B.Azure Policy
C.Microsoft Defender for Cloud
D.Azure Security Center
AnswerC

Microsoft Defender for Cloud is the correct choice because it includes built-in vulnerability scanning for container images in Azure Container Registry and other supported registries. It continuously scans images when they are pushed, detects known vulnerabilities using integrated CVE databases, and provides actionable remediation recommendations. Integrating this into a secure DevOps pipeline allows automated gating to block vulnerable images from reaching production.

Why this answer

Microsoft Defender for Cloud (formerly Azure Security Center) provides integrated vulnerability assessment for container images stored in Azure Container Registry (ACR). When integrated into a DevOps pipeline, Defender for Cloud can scan images on push or on demand, using the Qualys scanner to detect CVEs and generate detailed security reports. This allows the pipeline to block or flag vulnerable images before they reach production, directly addressing the requirement for pre-deployment vulnerability scanning.

Exam trap

The trap here is that candidates may confuse the old name 'Azure Security Center' with the current service 'Microsoft Defender for Cloud', or assume that Azure Policy can perform vulnerability scanning when it only enforces configuration compliance, not image-level security analysis.

How to eliminate wrong answers

Option A is wrong because Azure Key Vault is a secrets management service for storing keys, certificates, and passwords, not a container image vulnerability scanner. Option B is wrong because Azure Policy enforces compliance rules on Azure resources (e.g., requiring ACR to use private endpoints) but does not perform runtime or image-level vulnerability scanning. Option D is wrong because Azure Security Center was the previous name for what is now Microsoft Defender for Cloud; the current service name is Defender for Cloud, and the exam expects the updated terminology.

384
MCQhard

Your company uses Microsoft Entra ID for identity management. You need to implement a solution that allows external partners to access a specific application using their own identity providers, while ensuring that their accounts are automatically deprovisioned when removed from their home organization. Which feature should you use?

A.B2B direct federation
B.Entitlement management with connected organizations
C.Self-service sign-up
D.Identity Governance access reviews
AnswerB

Entitlement management with connected organizations lets external partners authenticate via their own identity providers while Microsoft Entra ID governs access through access packages. Lifecycle workflows automatically deprovision those accounts when partners leave their home organization, meeting the automatic removal requirement.

Why this answer

Entitlement management with connected organizations in Microsoft Entra ID (part of Identity Governance) is designed exactly for this scenario: it lets you onboard external partners, define access packages tied to their home identity providers, and automatically deprovision access when the user leaves their home organization via lifecycle workflows and connected-organization sync. This provides both the cross-tenant access and the automatic deprovisioning requirement.

Exam trap

SC-100 often tests the confusion between B2B direct federation (authentication trust only) and entitlement management with connected organizations (full governance plus automatic deprovisioning), causing candidates to pick the simpler federation option.

How to eliminate wrong answers

Option A is wrong because B2B direct federation only establishes a trust relationship for authentication between Entra ID and an external IdP (like SAML/WS-Fed); it does not provide access packages, approval workflows, or automatic deprovisioning when the user leaves their home org. Option C is wrong because self-service sign-up allows external users to request access via a custom app, but it lacks governance, lifecycle management, and automatic deprovisioning tied to the home organization. Option D is wrong because access reviews are a periodic recertification control that flags stale access for reviewers to approve or deny — they do not automatically deprovision users when they are removed from their home organization, nor do they onboard external IdPs.

385
MCQmedium

Your organization plans to use Microsoft Defender for Cloud to protect hybrid workloads across Azure and on-premises servers. You need to ensure that security policies are consistently applied and that compliance status is monitored centrally. What should you configure?

A.Implement Azure Security Benchmark recommendations manually.
B.Create Azure Policy initiatives and assign them to management groups and subscriptions.
C.Configure security policies directly in Microsoft Defender for Cloud.
D.Deploy Azure Blueprints to assign policies to management groups.
AnswerB

Creating Azure Policy initiatives—such as the built-in Microsoft Cloud Security Benchmark initiative—and assigning them to management groups and subscriptions is the correct approach because Defender for Cloud pulls its recommendations and regulatory compliance findings directly from these policy assignments. The assignments define audit, Deny, and DeployIfNotExists effects that enforce secure configuration continuously across native Azure resources and hybrid machines connected via Azure Arc. This model gives organizations centralized governance, automated remediation, and a clear audit trail for compliance evidence. It is the foundation that makes Defender for Cloud's recommendations actionable and repeatable.

Why this answer

The correct option is B: Create Azure Policy initiatives and assign them to management groups and subscriptions. Azure Policy initiatives (policy sets) are the mechanism Microsoft Defender for Cloud uses to evaluate and enforce security controls consistently across Azure and hybrid/Arc-connected servers, and assigning them at management-group scope cascades the same definitions to all child subscriptions so compliance is monitored centrally in Defender for Cloud's regulatory compliance dashboard. Options A and C do not fit because manually applying Azure Security Benchmark recommendations or configuring policies only inside Defender for Cloud lacks the scalable, centrally assigned initiative/scope model needed for consistent enforcement.

Option D is wrong because Azure Blueprints is a deprecated orchestration service for packaging role assignments, policies, and templates at subscription scope, not the recommended way to assign policy initiatives to management groups.

386
MCQmedium

Your organization uses Microsoft Entra ID and plans to implement a Zero Trust security model. You need to ensure that all access requests to corporate applications are continuously evaluated based on user risk, device compliance, and location. Which Microsoft Entra ID feature should you configure?

A.Identity Governance
B.Privileged Identity Management (PIM)
C.Identity Protection
D.Conditional Access
AnswerD

Conditional Access evaluates each access request against signals — user risk, device compliance and location — and enforces grant or session controls accordingly, delivering the continuous, context-aware evaluation Zero Trust demands rather than relying on a one-off authentication event.

Why this answer

Conditional Access is the correct feature because it enables real-time policy evaluation of access requests based on signals such as user risk (from Identity Protection), device compliance (via Microsoft Intune), and location (IP address ranges or named locations). This aligns directly with the Zero Trust principle of 'never trust, always verify' by continuously re-evaluating each access attempt rather than relying on static permissions.

Exam trap

The trap here is that candidates often confuse Identity Protection (which only detects risk) with Conditional Access (which enforces policies based on that risk), leading them to select Option C instead of D.

How to eliminate wrong answers

Option A is wrong because Identity Governance focuses on managing user lifecycle, access reviews, and entitlement management, not on real-time risk-based access evaluation. Option B is wrong because Privileged Identity Management (PIM) provides just-in-time privileged role activation and approval workflows, but it does not evaluate device compliance or location for general application access. Option C is wrong because Identity Protection detects and reports user and sign-in risks (e.g., leaked credentials, anonymous IP addresses) but does not enforce access decisions itself; it requires integration with Conditional Access to block or require MFA based on those risks.

387
Multi-Selecteasy

Which TWO of the following are features of Azure DDoS Protection?

Select 2 answers
A.Cost protection for scaled resources during an attack
B.Web application firewall (WAF) capabilities
C.Site-to-site VPN connectivity
D.SSL termination and offloading
E.Adaptive tuning and mitigation of DDoS attacks
AnswersA, E

Under Azure DDoS Network Protection, if an attack triggers auto-scaling of protected resources, Microsoft automatically applies a credit for the incremental compute and bandwidth consumed during the attack window. This cost protection is provided by default for resources with DDoS protection enabled, ensuring that the necessary scale-out to absorb volumetric attacks doesn't cause an unexpected billing spike.

Why this answer

Option A is correct because Azure DDoS Protection includes DDoS cost protection, which provides service credits for resource costs incurred from scale-out during a documented DDoS attack, helping avoid unexpected charges. Option E is correct because Azure DDoS Protection uses adaptive tuning and automatic mitigation, learning normal traffic patterns and applying tailored mitigation policies to protect Azure resources from volumetric, protocol, and application-layer attacks. Option B is not a feature of Azure DDoS Protection itself; WAF capabilities are provided by Azure Web Application Firewall, typically through Application Gateway or Front Door.

Option C is unrelated, as site-to-site VPN connectivity is provided by Azure VPN Gateway. Option D is also unrelated, since SSL termination and offloading are handled by services such as Application Gateway or Azure Front Door, not by Azure DDoS Protection.

388
MCQmedium

A company, Fabrikam, has a hybrid identity environment with on-premises Active Directory synchronized to Azure AD using Azure AD Connect. They have implemented a Zero Trust strategy that includes requiring multi-factor authentication (MFA) for all users accessing cloud applications. They use Conditional Access policies to enforce MFA. Recently, they noticed that users who authenticate from the on-premises network are not being prompted for MFA when accessing cloud apps, even though the Conditional Access policy is configured to require MFA for all users. The network location is not excluded in the policy. The Conditional Access policy is enabled and in 'Enforce' mode. The users' devices are not domain-joined. What is the most likely reason for this behavior?

A.Azure AD Connect is not configured for Pass-through Authentication
B.The Conditional Access policy does not include session controls
C.The Conditional Access policy is not targeting the correct user group
D.Users are using legacy authentication protocols that do not support MFA
AnswerD

Legacy authentication protocols such as POP3, IMAP4, and SMTP do not support modern authentication and therefore cannot present additional MFA challenges or respond to Conditional Access grant controls. Azure AD treats these clients as unmanaged and typically exempts them from Conditional Access policies unless explicitly blocked via a separate legacy authentication policy. As a result, users relying on legacy clients can authenticate with only a password, explaining why MFA is being bypassed.

Why this answer

The most likely reason is that users are using legacy authentication protocols (e.g., POP3, IMAP, SMTP, or older Office clients) that do not support modern authentication and thus cannot enforce MFA via Conditional Access. Even though the policy requires MFA, legacy protocols bypass the Conditional Access engine entirely, allowing authentication without MFA prompts.

Exam trap

The trap here is that candidates often focus on policy configuration (e.g., user targeting, session controls) or authentication methods, but the real issue is that legacy protocols completely bypass Conditional Access, making MFA enforcement impossible regardless of policy settings.

How to eliminate wrong answers

Option A is wrong because Pass-through Authentication is an authentication method (not related to MFA enforcement) and does not affect whether Conditional Access policies prompt for MFA; the issue is about protocol support, not authentication flow. Option B is wrong because session controls (e.g., app-enforced restrictions, sign-in frequency) are optional and not required for MFA enforcement; the core MFA requirement is a grant control, not a session control. Option C is wrong because the scenario states the policy targets 'all users' and is in 'Enforce' mode, so user group targeting is not the issue; the problem is protocol-level bypass.

389
Multi-Selectmedium

Your organization is implementing Microsoft Intune for mobile device management. You need to design a solution that ensures corporate data on mobile devices is protected if the device is lost or stolen. Which TWO actions should you configure?

Select 2 answers
A.Enforce a minimum PIN length on devices
B.Configure a compliance policy that requires device encryption
C.Deploy a selective wipe policy that removes corporate data
D.Require app protection policies (MAM) for all apps
E.Enable jailbreak detection in a device compliance policy
AnswersB, C

A compliance policy that mandates device encryption ensures that the storage medium (e.g., internal flash) is encrypted, typically using the hardware security module and a recovery key managed by the device, so that if the device is lost, the data is unreadable without the decryption key. This is a protective measure at rest; in addition, the compliance policy can trigger conditional access to block non-compliant devices, but the encryption itself is the core safeguard that prevents data exposure from physical access.

Why this answer

A compliance policy requiring device encryption ensures that if a device is lost or stolen, the data stored on it is unreadable without the decryption key. Intune compliance policies evaluate encryption status (e.g., BitLocker on Windows, FileVault on macOS, or device encryption on iOS/Android) and mark noncompliant devices for conditional access blocking, preventing unauthorized access to corporate data.

Exam trap

The trap here is that candidates often confuse device-level encryption (compliance policy) with app-level protection (MAM) or access controls (PIN, jailbreak detection), failing to recognize that only encryption and selective wipe directly address data protection on a lost or stolen device.

390
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that devices that are not compliant with your organization's security policies are blocked from accessing corporate resources. Which Intune feature should you configure?

A.App protection policies
B.Device configuration profiles
C.Compliance policies
D.Enrollment restrictions
AnswerC

Compliance policies in Intune define the specific conditions a device must meet to be considered compliant, such as required OS versions, password requirements, encryption status, and threats detected by Mobile Threat Defense. Each device periodically uploads its health and configuration to the Intune service, which computes a compliant/non-compliant state. This state can then be consumed by Azure AD Conditional Access to allow or block access to emails, apps, and data based on real-time compliance. When a policy is combined with a Conditional Access policy requiring device compliance, non-compliant devices are blocked from accessing protected resources—making this the correct answer.

Why this answer

Compliance policies in Microsoft Intune define the rules and settings that devices must meet to be considered compliant (e.g., requiring a minimum OS version, encryption, or a healthy device health attestation). When a device is marked as non-compliant, Intune can automatically block access to corporate resources such as Exchange Online, SharePoint, or VPN by integrating with Conditional Access in Microsoft Entra ID. This is the correct feature because it directly evaluates device compliance and enforces access control.

Exam trap

The trap here is that candidates confuse device configuration profiles (which apply settings) with compliance policies (which evaluate settings and enforce access), leading them to select Option B when the question specifically asks about blocking access based on non-compliance.

How to eliminate wrong answers

Option A is wrong because App protection policies (MAM) manage how data is accessed and shared within apps on devices that may not be enrolled in Intune, but they do not block device-level access to corporate resources based on device compliance. Option B is wrong because Device configuration profiles push settings (e.g., Wi-Fi, VPN, email) to devices but do not evaluate or enforce compliance; they are separate from the compliance evaluation and conditional access workflow. Option D is wrong because Enrollment restrictions control which devices can enroll in Intune (e.g., by platform or OS version), but they do not block access for devices that are already enrolled and become non-compliant after enrollment.

391
MCQmedium

Your organization uses Microsoft Purview to govern sensitive data. You need to design a solution that automatically detects and protects credit card numbers in emails and documents stored in Microsoft 365. The solution should also provide data loss prevention (DLP) policy tips to users when they try to share such data externally. What should you configure?

A.Sensitivity labels with auto-classification
B.Microsoft Purview Data Loss Prevention policies
C.Microsoft 365 compliance center
D.Microsoft Information Protection unified labeling
AnswerB

Microsoft Purview Data Loss Prevention (DLP) policies are the correct feature because they are purpose-built to detect sensitive data in real time and can trigger interactive policy tips in supported Microsoft 365 apps. When a user tries to share an email, document, or message that contains sensitive information, the DLP policy evaluates the content and displays a non-blocking tip or block action, educating the user and enforcing compliance. Unlike classification-only tools, DLP policies directly implement the user-notification workflow described in the question.

Why this answer

Microsoft Purview Data Loss Prevention policies (option B) are the correct choice because DLP is the service that detects sensitive information types such as credit card numbers in Exchange Online email and SharePoint/OneDrive documents, and it can enforce protection by blocking or restricting external sharing while displaying policy tips to users in supported apps like Outlook and Office. DLP policies natively support the credit card number sensitive information type and the policy tip configuration for user notifications during external sharing attempts. Sensitivity labels with auto-classification (A) apply classification and protection to content but do not provide DLP policy tips or block external sharing in real time.

The Microsoft 365 compliance center (C) is just the administrative portal, not a protection mechanism, and Microsoft Information Protection unified labeling (D) is the labeling infrastructure, not the DLP enforcement engine.

392
MCQhard

You are a security architect for a large enterprise that is migrating to Microsoft 365. The organization has 50,000 users across multiple regions. They have recently experienced a ransomware attack that encrypted files on SharePoint Online and OneDrive for Business. The security team wants to implement a comprehensive protection strategy. Requirements: 1. Automatically detect and block ransomware-like behavior in real-time. 2. Provide users with self-service recovery of files encrypted by ransomware. 3. Ensure that all files in SharePoint and OneDrive are scanned for malware upon upload. 4. Minimize administrative overhead. Which combination of Microsoft 365 security features should you recommend?

A.Use Microsoft Entra ID Protection to detect compromised accounts and automatically block access.
B.Enable Microsoft Endpoint DLP and configure file policies to block encrypted files.
C.Enable Microsoft Defender for Office 365 to scan files on upload and use version history and recycle bin for recovery.
D.Configure Microsoft Purview auto-labeling to apply a 'Ransomware' label and then block all labeled files.
AnswerC

Defender for Office 365 runs anti-malware and detonation-in-sandbox scanning on files uploaded to SharePoint, OneDrive, and Microsoft Teams, immediately removing known malicious files. It also continuously monitors for ransomware activity with heuristic and machine-learning rules, then alerts you to impacted files. Version history and the recycle bin act as a self-service recovery mechanism, letting you restore a previous unencrypted version of a file with a few clicks, even after mass encryption. This combines prevention, detection, and remediation—exactly what the question asks for.

Why this answer

Microsoft Defender for Office 365 provides real-time scanning of files uploaded to SharePoint and OneDrive, detecting and blocking known malware. Combined with version history and the recycle bin, users can self-recover files encrypted by ransomware without administrative intervention, satisfying all requirements with minimal overhead.

Exam trap

The trap here is that candidates may confuse Microsoft Defender for Office 365 with Microsoft Defender for Cloud Apps or Microsoft Purview, but only Defender for Office 365 provides both upload scanning and native version history/recycle bin recovery for SharePoint and OneDrive.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Protection detects compromised accounts and can block access, but it does not scan files for malware upon upload, nor does it provide self-service recovery of encrypted files. Option B is wrong because Microsoft Endpoint DLP focuses on preventing data loss via policies (e.g., blocking sensitive data sharing), not on detecting ransomware behavior or scanning files for malware in real-time. Option D is wrong because Microsoft Purview auto-labeling applies labels based on content, but it cannot block files in real-time based on ransomware behavior, and it does not provide file scanning or self-service recovery.

393
Multi-Selecthard

You are designing a secure access strategy for Azure App Service web applications. The requirements are: use Azure AD for authentication, restrict access to specific IP ranges, and require multi-factor authentication (MFA) for all users. Which two components should you configure? (Choose two.)

Select 2 answers
A.Apply a network security group (NSG) to the App Service subnet
B.Configure Azure App Service authentication with Microsoft Entra ID
C.Create a Conditional Access policy in Microsoft Entra ID that requires MFA and restricts IP ranges
D.Deploy Azure Firewall to filter inbound traffic
E.Register the application in Microsoft Entra ID
AnswersB, C

Azure App Service authentication can be configured to use Microsoft Entra ID, which is required for user authentication.

Why this answer

Option B is correct because configuring App Service authentication with Microsoft Entra ID (formerly Azure AD) enables the built-in Easy Auth middleware to authenticate users against the Entra ID identity provider, satisfying the requirement to use Azure AD for authentication. Option C is correct because a Conditional Access policy in Microsoft Entra ID can enforce MFA for all users and apply named locations or IP-based conditions to restrict access to specific IP ranges, meeting both the MFA and IP restriction requirements at the identity layer. Option A is not correct because an NSG applied to the App Service subnet only filters network traffic by IP/port at the network layer and does not provide Azure AD authentication or MFA.

Option D is not correct because Azure Firewall filters inbound/outbound traffic but does not perform user authentication or MFA enforcement. Option E is not correct because registering the application in Microsoft Entra ID only creates the identity object/service principal; it does not by itself enable authentication, IP restrictions, or MFA.

Exam trap

SC-100 often tests the layering of identity vs. network controls — candidates pick NSG or Azure Firewall for IP restriction when the requirement is user-level access with MFA, which only Conditional Access can enforce.

394
Multi-Selecthard

Your company is deploying Microsoft Defender XDR. You need to design a solution that uses advanced hunting to proactively search for threats. Which THREE data sources should be included in the advanced hunting schema to enable comprehensive threat hunting across endpoints, identities, and cloud apps?

Select 3 answers
A.EmailEvents
B.AzureActivity
C.CloudAppEvents
D.IdentityInfo
E.DeviceEvents
AnswersC, D, E

CloudAppEvents is the correct table for investigating SaaS application activity because it aggregates sign-in and activity transactions from Defender for Cloud Apps across thousands of cloud apps, including Office 365, AWS, and Google Workspace. Each row contains user, device, IP address, and app-specific action metadata, allowing analysts to pivot from a suspicious identity or endpoint to cloud-side anomalies. This table is one of the five default tables in Defender XDR advanced hunting and is essential for end-to-end, cloud-inclusive threat hunting.

Why this answer

CloudAppEvents (C) is correct because it is the Microsoft Defender for Cloud Apps table in the advanced hunting schema, providing audit and activity events from cloud applications (including Office 365 and other connected apps) needed to hunt for threats in the cloud-app pillar. IdentityInfo (D) is correct because it is the Microsoft Defender for Identity table that supplies identity and account metadata (such as account details, group memberships, and directory context) used to investigate and hunt identity-based attacks. DeviceEvents (E) is correct because it is the Microsoft Defender for Endpoint table containing endpoint event telemetry (such as process, file, registry, and network-related events) that enables hunting across the endpoint pillar.

EmailEvents (A) is not among the marked answers because, while it is a valid advanced hunting table for email threats, it is not one of the three sources selected to cover endpoints, identities, and cloud apps in this scenario. AzureActivity (B) is not marked correct because it is an Azure control-plane activity log table rather than a core Defender XDR endpoint, identity, or cloud-app hunting source for this design.

395
MCQhard

Your organization is implementing a zero-trust security model. You need to design a solution that continuously verifies user identity, device compliance, and access context before granting access to corporate resources. The solution should also support risk-based policies. Which Microsoft security capability should be at the core of this design?

A.Microsoft Defender for Identity
B.Microsoft Entra ID Conditional Access
C.Microsoft Sentinel
D.Microsoft Intune
AnswerB

Microsoft Entra ID Conditional Access evaluates user identity, device compliance and sign-in context at every access request, and applies risk-based policies through signals such as user risk and sign-in risk. This continuous, context-aware evaluation is the core enforcement point of a zero-trust design.

Why this answer

Microsoft Entra ID Conditional Access is the core policy engine for zero-trust, enabling continuous verification of user identity, device compliance, and access context before granting resource access. It integrates with risk signals from Microsoft Entra ID Protection to enforce risk-based policies, such as requiring multi-factor authentication when sign-in risk is high. This aligns directly with the zero-trust principle of 'never trust, always verify' by evaluating conditions in real time.

Exam trap

The trap here is that candidates often confuse Microsoft Intune's device compliance enforcement with the actual policy decision engine, not realizing that Intune provides the device compliance state but Conditional Access is the component that evaluates that state along with identity and risk to make the access decision.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Identity is a security solution that detects on-premises Active Directory attacks using behavioral analytics, not a policy engine for continuous access verification or risk-based conditional access. Option C is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR for threat detection and incident response, not a tool for enforcing access policies based on user identity, device compliance, or risk context at the point of authentication. Option D is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service that enforces device compliance policies, but it does not evaluate identity, access context, or risk signals to grant or deny access—it relies on Conditional Access to consume its compliance status.

396
MCQeasy

A company uses Azure SQL Database and needs to implement column-level encryption for a column containing social security numbers (SSNs). The encryption must use a customer-managed key stored in Azure Key Vault. The application queries this column using parameterized queries. Which technology should be used?

A.Dynamic Data Masking (DDM)
B.Row-Level Security (RLS)
C.Transparent Data Encryption (TDE) with customer-managed keys
D.Always Encrypted with secure enclaves
AnswerD

Always Encrypted with secure enclaves is the correct solution because it provides true column-level encryption where plaintext values are never exposed to the Azure SQL Database engine. Client-side drivers encrypt data before transmission, and the database only sees ciphertext; secure enclaves (based on Intel SGX or Windows Virtualization-Based Security) enable confidential computing operations such as equality and pattern matching on encrypted columns without revealing plaintext to the engine. This accomplishes both at-rest and in-use column protection, which is exactly what the requirement asks for.

Why this answer

Always Encrypted with secure enclaves is the correct choice because it enables client-side encryption of specific columns (like SSNs) using a customer-managed key stored in Azure Key Vault, while still allowing rich computations (e.g., equality, pattern matching) on the encrypted data within a secure enclave. This meets the requirement for column-level encryption with customer-managed keys and supports parameterized queries without exposing plaintext to the database engine.

Exam trap

The trap here is that candidates often confuse Transparent Data Encryption (TDE) with column-level encryption, mistakenly believing TDE protects data from the database engine or privileged users, whereas TDE only protects data at rest on disk and does not prevent in-memory exposure.

How to eliminate wrong answers

Option A is wrong because Dynamic Data Masking (DDM) only obfuscates data at query results time for unauthorized users, but does not encrypt the data at rest or in transit, and the underlying plaintext remains accessible to the database engine. Option B is wrong because Row-Level Security (RLS) controls access to rows based on user predicates but does not encrypt individual columns or protect data from the database engine itself. Option C is wrong because Transparent Data Encryption (TDE) encrypts the entire database at rest, not individual columns, and does not prevent the database engine or privileged users from seeing plaintext data in memory or during query execution.

397
MCQmedium

Your organization uses Microsoft Intune for mobile device management and Microsoft Entra ID for identity. You are designing a solution to ensure that only devices that are compliant with security policies can access corporate resources. The requirements are: 1) Devices must have a minimum OS version. 2) Devices must have encryption enabled. 3) Devices must not be jailbroken or rooted. 4) Access to corporate apps must be blocked if the device is non-compliant. 5) The solution should automatically remediate non-compliant devices when possible. You need to recommend the minimum configuration. What should you do?

A.Configure Microsoft Purview Compliance Manager to assess compliance and block access.
B.Create an app protection policy in Intune that requires minimum OS and encryption.
C.Create a device compliance policy in Intune with the required settings, and create a Conditional Access policy that requires compliant devices.
D.Create a device configuration policy in Intune for the settings, and use Azure AD Identity Protection to block access.
AnswerC

An Intune compliance policy enforces the minimum OS version, encryption and jailbreak or root detection requirements, while a Conditional Access policy requiring compliant devices blocks corporate app access for non-compliant devices and supports automatic remediation.

Why this answer

The minimum configuration is to create a device compliance policy in Intune with the required settings (minimum OS version, encryption, jailbreak/root detection) and create a Conditional Access policy that requires compliant devices. This ensures only compliant devices can access corporate resources, and Intune can automatically remediate non-compliant devices where possible.

Exam trap

SC-100 often tests the difference between configuration policies (which set settings) and compliance policies (which assess settings), and candidates may confuse the two or overlook Conditional Access as the enforcement mechanism.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Compliance Manager is for assessing compliance with regulations, not for enforcing device access. Option B is wrong because an app protection policy (MAM) protects app data but does not enforce device compliance settings like OS version or encryption; it also does not block access to all corporate apps. Option D is wrong because a device configuration policy configures settings but does not assess compliance; Azure AD Identity Protection is for identity risks, not device compliance.

398
MCQmedium

You are designing a Zero Trust architecture for a company that uses Microsoft Entra ID and Microsoft Intune. The security team wants to enforce device compliance before granting access to cloud apps. Which policy should you implement?

A.Microsoft Entra Identity Protection user risk policy
B.Microsoft Defender for Cloud Apps session policy
C.Microsoft Entra Conditional Access policy requiring compliant device
D.Azure AD Identity Protection sign-in risk policy
AnswerC

An Entra Conditional Access policy requiring a compliant device is the correct mechanism because it directly checks the device's compliance state as reported by Microsoft Intune at sign-in time. The policy evaluates device health attributes like encryption, jailbreak status, and threat detection, and can block access or grant access only when compliant. This is the standard zero trust control that enforces device compliance before granting access to applications or resources.

Why this answer

Microsoft Entra Conditional Access policies can require that devices are marked as compliant by Microsoft Intune before granting access to cloud apps. This directly enforces device compliance as a condition for access, which is a core Zero Trust principle of verifying every access request based on device health.

Exam trap

The trap here is that candidates confuse risk-based policies (Identity Protection) with device compliance policies, assuming any policy that checks 'risk' or 'session' can enforce device health, but only Conditional Access with the compliant device grant control directly ties Intune compliance to access decisions.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Identity Protection user risk policy evaluates the likelihood that a user's identity has been compromised, not the compliance state of the device. Option B is wrong because Microsoft Defender for Cloud Apps session policy controls app behavior in real-time (e.g., blocking downloads) but does not enforce device compliance before access is granted. Option D is wrong because Azure AD Identity Protection sign-in risk policy assesses the risk of the authentication attempt (e.g., from an anonymous IP), not the device's compliance with security policies.

399
Multi-Selecthard

Which THREE components are essential for implementing a successful SIEM strategy using Microsoft Sentinel?

Select 3 answers
A.Automation rules
B.Workbooks
C.Analytics rules
D.Watchlists
E.Data connectors
AnswersA, C, E

Automation rules are central to Sentinel's SOAR capabilities because they let you define automated incident orchestration—such as assigning ownership, changing status, or running a playbook—when an alert is triggered or an incident is created. They close the gap between detection and response by turning analytics alerts into coordinated actions across Office 365, Microsoft Entra ID, and third-party systems. Without automation rules, alerts would require manual triage and response, reducing Sentinel to a passive monitoring tool rather than an active, automated security operations platform.

Why this answer

Data connectors (E) are essential because Microsoft Sentinel must first ingest telemetry from sources such as Microsoft 365, Azure, AWS, and third-party systems via connectors like the Azure Activity or Syslog connector before any detection or response can occur. Analytics rules (C) are essential because they correlate the ingested events and generate alerts/incidents based on scheduled, NRT, or Microsoft security rules, forming the core detection engine of the SIEM. Automation rules (A) are essential because they provide the orchestration and response layer, allowing Sentinel to automatically triage, assign, tag, or trigger playbooks on incidents to reduce response time.

Workbooks (B) are valuable for visualization and reporting but are not required for the core detect-and-respond SIEM pipeline, and watchlists (D) are an optional enrichment feature for importing reference data such as IPs or VIP users, not a foundational component of a Sentinel SIEM strategy.

Exam trap

The trap here is that candidates often confuse 'nice-to-have' features like Workbooks and Watchlists with 'essential' components, but Microsoft defines the three pillars of a successful SIEM strategy as data ingestion (connectors), detection (analytics rules), and automated response (automation rules).

400
MCQhard

Your organization is implementing a data loss prevention (DLP) strategy using Microsoft Purview. The compliance team needs to automatically classify and label sensitive data in Microsoft 365, Azure SQL Database, and Amazon S3. Which Purview feature should you use?

A.Microsoft Purview Data Map
B.Microsoft Purview Information Protection
C.Microsoft Purview Records Management
D.Microsoft Defender for Cloud Apps
AnswerA

Microsoft Purview Data Map is the correct choice because it provides automated scanning and classification of sensitive data across hybrid and multi-cloud environments, including on-premises, Azure, and other clouds such as AWS S3. Its data scanners can connect to Azure SQL databases and S3 buckets, inspect schemas and content, and apply classifications that feed into DLP policies. This makes it uniquely capable of discovering and mapping sensitive data at rest in non-Microsoft 365 sources, which is the core requirement here.

Why this answer

Microsoft Purview Data Map is the correct choice because it provides unified data governance across hybrid and multi-cloud environments, including Microsoft 365, Azure SQL Database, and Amazon S3. It automatically scans, classifies, and labels sensitive data using built-in classifiers and sensitivity labels, enabling consistent DLP policies across these disparate data sources.

Exam trap

The trap here is that candidates often confuse the scanning and classification capabilities of Microsoft Purview Data Map with the labeling and protection features of Microsoft Purview Information Protection, but the Data Map is the service that actually discovers and classifies data across multiple clouds, while Information Protection applies the labels after classification.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Information Protection focuses on applying sensitivity labels and encryption to data within Microsoft 365 and Azure, but it does not natively scan or classify data in Amazon S3. Option C is wrong because Microsoft Purview Records Management is designed for managing retention, disposition, and legal hold of records, not for automatic classification and labeling of sensitive data across multi-cloud sources. Option D is wrong because Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides threat protection and visibility for cloud apps, but it does not perform automatic data classification and labeling across Microsoft 365, Azure SQL, and Amazon S3 as a primary function.

401
MCQeasy

You are designing a secure infrastructure for an e-commerce platform hosted on Azure. The platform must meet PCI DSS compliance. Which Azure service should you use to centrally manage and monitor security policies across subscriptions?

A.Azure Policy
B.Azure Firewall
C.Microsoft Defender for Cloud
D.Azure Blueprints
AnswerA

Azure Policy is the correct service for centrally managing and monitoring security policies because it provides a unified governance plane for creating, assigning, and managing policy definitions and initiatives at management group, subscription, or resource group scope. It continuously evaluates resources against your compliance rules using effects such as Deny, Audit, Append, and DeployIfNotExists, and it presents a compliance dashboard showing the state of your environment. Built-in initiatives like the Microsoft Cloud Security Benchmark are delivered through Azure Policy, making it the primary service for enforcing security and compliance standards across all Azure resources.

Why this answer

Azure Policy is the correct choice because it is the Azure service designed to centrally create, assign, and manage policy definitions that enforce and audit security and compliance rules across subscriptions, which directly supports PCI DSS governance at scale. It evaluates resources against built-in or custom policies and reports compliance state, making it suitable for monitoring policy adherence across multiple subscriptions. Azure Firewall (B) is a network security service that filters traffic but does not manage or monitor security policies across subscriptions.

Microsoft Defender for Cloud (C) provides security posture management and threat protection, but it is not the primary mechanism for centrally defining and enforcing policy rules across subscriptions. Azure Blueprints (D) is used to package and deploy governed environments with artifacts like policies and role assignments, but it is not the central ongoing policy management and monitoring service.

402
MCQeasy

You are designing a solution for a healthcare organization that needs to share patient health information (PHI) with a partner organization. The partner must be able to query the data but should not be able to modify it. Both organizations use Microsoft Entra ID. What should you use?

A.Azure Active Directory B2C (now part of Entra) to allow the partner to authenticate and access data via a custom API.
B.Microsoft Entra entitlement management with an access package that grants read-only access to a SharePoint Online site.
C.Microsoft Purview Information Protection to label the data and allow the partner to decrypt it.
D.Azure DevOps for sharing the data in a repository with read-only permissions.
AnswerB

Microsoft Entra entitlement management is the correct approach because it is purpose-built for governing external access to resources in a B2B scenario. An access package can be created that contains a SharePoint Online site; when a partner user is assigned the package, they receive precisely the permissions defined — in this case read-only — and those permissions are enforced by SharePoint and Entra. The solution also provides built-in lifecycle management, such as expiration, approval workflows, and access reviews, ensuring access is time-bound and auditable, which aligns with a healthcare organization's privacy and compliance obligations.

Why this answer

The correct option is B: Microsoft Entra entitlement management with an access package that grants read-only access to a SharePoint Online site. Entitlement management is designed for B2B collaboration, allowing external partner users from another Entra ID tenant to request and receive governed access to resources, and an access package can assign a read-only permission level (e.g., SharePoint Visitors/Read) so the partner can query but not modify PHI. Option A is wrong because Entra ID B2C is for customer-facing identity scenarios, not partner B2B collaboration, and a custom API would require you to build and enforce read-only authorization yourself.

Option C is wrong because Purview Information Protection labels and encrypts data but does not provide the partner query access or enforce read-only permissions. Option D is wrong because Azure DevOps repositories are for source code, not for sharing PHI with a partner organization.

403
Multi-Selectmedium

Which THREE of the following are best practices for securing Azure Kubernetes Service (AKS) clusters? (Choose three.)

Select 3 answers
A.Enable Azure Policy for AKS to enforce pod security
B.Use managed identities for pod authentication
C.Store secrets in ConfigMaps
D.Enable network policies to restrict pod traffic
E.Disable Kubernetes RBAC to simplify management
AnswersA, B, D

Azure Policy for AKS uses built-in initiatives built on Gatekeeper/OPA to enforce pod security standards at admission control time, rejecting or auditing non-compliant workloads before they are created. This centralizes governance across multiple clusters and can apply effects like deny, audit, or mutate to ensure Pod Security Standards (baseline/restricted) are consistently enforced. As a right answer, it prevents misconfigured security contexts, hostPath mounts, or privileged containers that would otherwise violate policy.

Why this answer

Option A is correct because Azure Policy for AKS (via the Azure Policy add-on for Kubernetes) enforces pod security standards and organizational guardrails at admission time, preventing non-compliant workloads from being deployed. Option B is correct because managed identities (including workload identity / Azure AD pod identity) let pods authenticate to Azure resources without embedding credentials in code or config, eliminating secret sprawl and credential leakage. Option D is correct because Kubernetes NetworkPolicies enforce pod-level segmentation, restricting east-west traffic so a compromised pod cannot freely reach other workloads.

Option C is wrong because ConfigMaps store data in plaintext and are not designed for sensitive values; secrets should go in Kubernetes Secrets backed by Azure Key Vault (or the Secrets Store CSI driver). Option E is wrong because disabling Kubernetes RBAC removes least-privilege access control and weakens, rather than strengthens, cluster security.

404
MCQhard

Refer to the exhibit. You are evaluating a custom Azure Policy definition for storage accounts. The policy is assigned with effect set to 'Deny'. An administrator attempts to create a new storage account with network rules configured to allow all traffic (defaultAction set to Allow). What will happen?

A.The storage account creation is denied.
B.The storage account is created, and the network rules are automatically changed to deny all traffic.
C.The storage account is created, and an audit event is generated.
D.The storage account is created successfully, and no action is taken.
AnswerA

The Azure Policy definition uses a condition that checks the storage account's networkAcls.defaultAction property, and because the effect is set to 'Deny', the resource provider rejects the create request before any storage account is provisioned. The deployment fails with a policy violation error, and no resource is created.

Why this answer

The correct answer is A: the storage account creation is denied. Because the Azure Policy definition is assigned with the effect set to 'Deny', Azure Policy evaluates the resource request before deployment and blocks any storage account whose network rules use defaultAction set to Allow, so the create operation fails with a policy violation. Deny is a preventive enforcement effect, not a remediation or audit effect, so it stops the request rather than modifying the resource.

Option B is wrong because Azure Policy does not automatically rewrite network rules to deny all traffic, and option C is wrong because audit events are produced by the Audit effect, not Deny. Option D is wrong because Deny actively blocks the noncompliant creation instead of allowing it with no action.

405
MCQmedium

A company uses Microsoft Purview to classify data and enforce retention policies. They need to automatically apply a retention label to all documents containing credit card numbers. Which approach should they use?

A.Configure an auto-labeling policy with a sensitive info type
B.Use a trainable classifier
C.Create a manual labeling policy for users
D.Use a default label for SharePoint libraries
AnswerA

Auto-labeling policies scan content and apply retention labels when items match a sensitive info type, such as credit card numbers. This delivers automatic, condition-based labelling at scale, satisfying the requirement without relying on manual user classification.

Why this answer

Microsoft Purview auto-labeling policies can automatically apply retention labels to documents based on sensitive info types (SITs), such as credit card numbers. This approach uses pattern matching to detect the credit card number format and applies the label without user intervention, meeting the requirement for automatic enforcement.

Exam trap

The trap here is that candidates may confuse trainable classifiers with sensitive info types, thinking that 'intelligent' classification is always better, but SITs are the correct choice for specific, pattern-based data like credit card numbers.

How to eliminate wrong answers

Option B is wrong because trainable classifiers are designed to identify content based on context and patterns (e.g., contracts or resumes), not specific sensitive data like credit card numbers, which are better matched by SITs. Option C is wrong because manual labeling policies require users to apply labels themselves, contradicting the requirement for automatic application. Option D is wrong because a default label for SharePoint libraries applies a label to all documents in the library regardless of content, not selectively to those containing credit card numbers.

406
MCQmedium

You are designing a CI/CD pipeline for a containerized application using Azure DevOps. You need to ensure that container images are scanned for vulnerabilities before being deployed to production. Which service should you integrate?

A.Azure Policy
B.Azure Key Vault
C.Microsoft Defender for Cloud
D.Azure Monitor
AnswerC

Microsoft Defender for Cloud is the correct choice because it includes a built-in, agentless vulnerability scanner for container images stored in Azure Container Registry (ACR). When an image is pushed or pulled, Defender for Cloud automatically scans it using the Qualys scanner and matches findings against a continuously updated CVE database. The results provide severity levels, remediation guidance, and can be integrated into CI/CD gates via Defender for Cloud APIs or CLI to block deployment of images above a certain risk threshold. It also re-scans images on a regular basis to detect newly discovered vulnerabilities, providing both pre-deployment and ongoing protection.

Why this answer

Microsoft Defender for Cloud [CORRECT] is the right choice because it provides container image vulnerability scanning for images stored in Azure Container Registry and can be integrated into CI/CD workflows to gate deployments before production. It continuously assesses images and surfaces findings that Azure DevOps pipelines can act on. Azure Policy is for enforcing governance and compliance rules on resources, not for scanning container images for vulnerabilities.

Azure Key Vault manages secrets and keys, and Azure Monitor collects telemetry and logs, so neither performs vulnerability scanning.

407
Drag & Dropmedium

Order the steps to configure a Conditional Access policy requiring MFA for all users.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Conditional Access policy creation involves assignments for users and apps, then access controls like MFA.

408
MCQhard

A multinational corporation is implementing a privileged access strategy. They need to ensure that all users with permanent administrative roles sign in using phishing-resistant authentication methods. Which Microsoft Entra ID feature should they enforce?

A.Privileged Identity Management (PIM) with access reviews
B.Multifactor authentication (MFA) with Conditional Access
C.Authentication Strengths in Conditional Access
D.Conditional Access policies requiring MFA for all admins
AnswerC

Authentication Strengths is a Conditional Access grant control that lets an administrator define a policy requiring a specific set of acceptable authentication methods, such as FIDO2 security keys or certificate-based authentication. It evaluates the method actually used at sign-in and blocks sessions that do not meet the configured strength, making it the correct mechanism for enforcing phishing-resistant MFA on privileged accounts.

Why this answer

Authentication Strengths in Conditional Access allows organizations to enforce specific authentication methods, such as FIDO2 security keys or certificate-based authentication, which are phishing-resistant. This directly meets the requirement to ensure users with permanent administrative roles use phishing-resistant methods, unlike general MFA policies that may allow weaker methods like SMS or OTP.

Exam trap

The trap here is that candidates confuse general MFA enforcement with the ability to enforce specific authentication method types, assuming any MFA policy is sufficient for phishing resistance, whereas Authentication Strengths provides granular control over which methods are allowed.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) with access reviews manages just-in-time access and recertification, not the enforcement of specific authentication methods. Option B is wrong because standard MFA with Conditional Access can enforce MFA but does not restrict to phishing-resistant methods; it may allow SMS, voice, or OATH tokens that are vulnerable to phishing. Option D is wrong because a Conditional Access policy requiring MFA for all admins is too broad and does not specify phishing-resistant methods; it could still permit weaker MFA factors.

409
MCQmedium

Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel. What is the primary purpose of this query?

A.Identify accounts that have experienced more than 10 failed login attempts from the same IP address within an hour
B.Identify IP addresses that have successfully brute-forced an account
C.Identify users who have logged in from multiple IPs in a short time
D.Identify accounts that have been disabled due to multiple failures
AnswerA

This query correctly identifies the specified brute-force pattern: it groups failed sign-in events (e.g., ResultType indicating failure) by user account, source IP address, and a 1-hour time bucket using bin(), then filters for groups where the failure count exceeds 10. That precisely matches 'accounts with more than 10 failed login attempts from the same IP within an hour.' It deliberately ignores successful logons and post-incident account states, which is exactly the described behavior.

Why this answer

The KQL query uses the `summarize` operator to count failed logon events (EventID 4625) grouped by account and IP address, then filters for counts greater than 10 within a 1-hour time window. This directly identifies accounts that have experienced more than 10 failed login attempts from the same IP address within an hour, which is a classic indicator of a brute-force attack targeting a specific account.

Exam trap

Microsoft often tests the distinction between identifying brute-force attempts (failed logins) and confirming successful brute-force attacks (failed logins followed by a successful login), so candidates may incorrectly choose Option B without checking for a successful logon event.

How to eliminate wrong answers

Option B is wrong because the query does not check for a subsequent successful login (EventID 4624) after the failures, so it cannot confirm that a brute-force attack succeeded. Option C is wrong because the query groups by both account and IP address, not by users logging in from multiple IPs; it focuses on failures from a single IP. Option D is wrong because the query does not query for account lockout events (EventID 4740) or disabled account status; it only counts failed logon attempts.

410
MCQhard

Refer to the exhibit. You are reviewing a Microsoft Defender for Cloud automation resource. You want the automation to trigger a playbook in Microsoft Sentinel when a high-severity security assessment is found. Based on the exhibit, what is the missing configuration?

A.The severity filter should be 'Low' to capture all assessments
B.The action type should be 'LogicApp' instead of 'EventHub'
C.The eventSource should be 'Alerts' instead of 'Assessments'
D.The API version should be '2020-01-01'
AnswerB

To invoke a playbook in Microsoft Defender for Cloud, the automation action must be of type 'LogicApp' and contain the playbook's callback URL, not 'EventHub'. An EventHub action simply exports the event to an event hub for ingestion by external systems, whereas LogicApp directly triggers the playbook's workflow. Because the requirement is to run a playbook, the action type is the misconfigured property, and correcting it from EventHub to LogicApp is the necessary fix.

Why this answer

Microsoft Defender for Cloud automation can trigger a playbook in Microsoft Sentinel only by using a LogicApp action. The exhibit shows an EventHub action type, which is used for streaming events to an event hub, not for invoking a playbook. To trigger a Sentinel playbook from a Defender for Cloud assessment, the action type must be set to 'LogicApp' and configured with the playbook's trigger URL.

Exam trap

The trap here is that candidates may focus on the severity filter or event source, overlooking that the action type must be specifically 'LogicApp' to invoke a playbook, as 'EventHub' is a valid action but for a different purpose.

How to eliminate wrong answers

Option A is wrong because setting the severity filter to 'Low' would capture low-severity assessments, not high-severity ones; the requirement is to trigger on high-severity assessments, so the filter should be 'High'. Option C is wrong because the eventSource should remain 'Assessments' to trigger on security assessments; changing it to 'Alerts' would trigger on security alerts instead, which is a different data type. Option D is wrong because the API version '2020-01-01' is not relevant to the missing configuration; the automation resource uses the correct API version for its definition, and the issue is the action type, not the API version.

411
MCQmedium

Your organization uses Microsoft Sentinel and wants to correlate security events from multiple sources to detect multi-stage attacks. What should you create?

A.Scheduled query rule
B.NRT rule
C.Anomaly rule
D.Fusion rule
AnswerD

Fusion rules are built-in analytics rules in Microsoft Sentinel that use machine learning to correlate alerts from multiple Microsoft security products (e.g., Microsoft Defender for Identity, Defender for Office 365, Microsoft Entra ID Protection) into a single incident. The fusion engine maps alerts to MITRE ATT&CK stages, linking actions like initial access, lateral movement, and exfiltration into one coherent story. Because it automatically identifies multi-stage attack patterns without custom KQL, Fusion is the correct rule type for the organization's requirement to correlate multi-stage attacks.

Why this answer

Fusion rules in Microsoft Sentinel are specifically designed to correlate security events from multiple sources and detect multi-stage attacks by combining alerts from different detection technologies into a single incident. This matches the requirement to correlate events across sources for complex attack chains, unlike other rule types that focus on single-source or single-event detection.

Exam trap

The trap here is that candidates often confuse scheduled query rules or NRT rules as the primary tool for correlation, but those require manual KQL logic to join data across sources, whereas Fusion provides automated, built-in multi-source correlation for multi-stage attacks.

How to eliminate wrong answers

Option A is wrong because scheduled query rules run queries at regular intervals against a single data source or table, and they cannot natively correlate events from multiple disparate sources to detect multi-stage attacks. Option B is wrong because NRT (Near-Real-Time) rules provide low-latency detection but still operate on a single query against one or more tables, lacking the built-in multi-source correlation logic of Fusion. Option C is wrong because anomaly rules use machine learning to detect deviations from baseline behavior on a single data source, not to correlate events across multiple sources for multi-stage attack detection.

412
MCQmedium

Your company is designing a hybrid identity solution using Microsoft Entra ID. You need to ensure that users can access on-premises applications using modern authentication methods. The solution must support multi-factor authentication and Conditional Access policies. What should you implement?

A.Microsoft Entra Connect
B.Microsoft Entra application proxy
C.Azure AD Domain Services
D.Microsoft Intune
AnswerB

Microsoft Entra application proxy is the correct choice because it publishes on-premises web applications to external users through an outbound connector installed on an internal server. The connector establishes an outbound connection to Microsoft Entra ID, eliminating the need for inbound firewall rules; users authenticate against Entra ID with support for MFA, conditional access, and modern protocols, after which requests are routed via the connector to the internal application. This enables secure remote access to legacy apps without a VPN.

Why this answer

Microsoft Entra application proxy publishes on-premises web applications to the cloud, letting remote users reach them through Entra ID. Because authentication flows through Entra ID, it natively supports modern authentication, MFA, and Conditional Access policies. This is the correct solution for hybrid access to on-prem apps with modern identity controls.

Exam trap

SC-100 often tests the confusion between identity synchronization (Entra Connect), managed domain services (Azure AD DS), and application publishing (application proxy) — candidates must map the requirement 'modern auth to on-prem apps' to application proxy.

How to eliminate wrong answers

Option A is wrong because Entra Connect synchronizes identities between on-prem AD and Entra ID; it does not publish or proxy on-prem applications. Option C is wrong because Azure AD Domain Services provides managed domain services (LDAP, Kerberos, domain join) in Azure, not modern-auth access to on-prem apps. Option D is wrong because Intune handles device and app management (MDM/MAM), not application publishing or authentication brokering.

413
MCQmedium

Your organization, Fabrikam Inc., uses Microsoft Intune for device management and Microsoft Entra ID for identity. You need to design a solution to ensure that only compliant and healthy devices can access corporate resources. The solution must require that devices are either enrolled in Intune and compliant, or joined to Azure AD with a health attestation. Additionally, you need to block access from devices that are rooted or jailbroken. You have the following requirements: 1) Enforce conditional access policies to check device compliance and health. 2) Use Microsoft Defender for Endpoint integration for device health signals. 3) Provide a fallback option for unmanaged devices to access only web apps via browser with app protection policies. Which combination of actions should you take?

A.Configure conditional access to require MFA for all devices, and use device filters to exclude non-compliant devices.
B.Configure conditional access to require device compliance, and enable device health attestation via Intune.
C.Configure conditional access to block access from unknown locations, and require device enrollment for all users.
D.Configure conditional access policies: one requiring device compliance or Azure AD joined with health attestation, and another for unmanaged devices requiring app protection policies.
AnswerD

This option correctly applies a dual-policy conditional access strategy that covers both managed and unmanaged device scenarios. The first policy grants access only when the device is either Intune-compliant or Microsoft Entra joined and passes health attestation, ensuring that managed endpoints meet security baselines. The second policy requires app protection policies for unmanaged devices, which enforce data-loss-prevention and secure app-level controls without requiring full device enrollment, thereby protecting corporate data across every access path.

Why this answer

Option D is correct because it directly implements the stated requirements: a conditional access policy that grants access only when the device is Intune-enrolled and compliant or Azure AD joined with health attestation, plus a separate policy that allows unmanaged devices to reach only web apps when app protection policies (and thus browser-based access with Intune app protection) are applied. This layered approach also supports blocking rooted or jailbroken devices, since compliance and health attestation signals from Intune and Microsoft Defender for Endpoint integration surface device health and tamper state. Option A does not enforce compliance or health, only MFA, and excluding non-compliant devices via filters would not grant the required compliant-device access path.

Option B is incomplete because it omits the fallback policy for unmanaged devices and does not explicitly cover the Azure AD joined with health attestation alternative. Option C blocks unknown locations and forces enrollment for everyone, which contradicts the requirement to allow unmanaged devices limited browser access to web apps.

414
MCQeasy

A retail company uses Microsoft Purview to protect customer data across Microsoft 365 and Azure. The compliance team wants to detect when sensitive information such as credit card numbers is uploaded to SharePoint Online and automatically apply a sensitivity label that encrypts the content. The label must be applied without user interaction. You need to recommend the Purview capability to use. What should you recommend?

A.An Insider Risk Management policy that flags credit card numbers in SharePoint.
B.A sensitivity label with user-defined permissions and mandatory labeling in SharePoint.
C.An auto-labeling policy for sensitive information types in Microsoft Purview.
D.A data loss prevention policy that blocks uploads containing credit card numbers.
AnswerC

Auto-labeling policies in Microsoft Purview scan locations such as SharePoint Online for sensitive information types like credit card numbers and apply the configured sensitivity label automatically, with no user action. This directly matches the requirement to detect and encrypt sensitive content at rest without interaction.

Why this answer

The scenario requires automatic detection of sensitive information and automatic application of an encrypting sensitivity label, with no user involvement. Microsoft Purview auto-labeling policies are purpose-built for this: they use sensitive information types and trainable classifiers to find content in SharePoint Online and other locations and apply the designated label. DLP, mandatory labeling, and Insider Risk Management serve different purposes and do not apply encryption labels automatically.

Exam trap

The trap here is conflating DLP, which blocks or warns, with auto-labeling, which applies the label and encryption.

415
MCQhard

Refer to the exhibit. You are reviewing an Azure Policy definition that is assigned to a subscription. What is the primary effect of this policy?

A.It modifies the OS disk to use a specific disk encryption set.
B.It deploys a disk encryption set to each virtual machine.
C.It denies creation of virtual machines without the specified disk encryption set.
D.It audits virtual machines that do not use the specified disk encryption set.
AnswerA

This statement is correct. The policy definition uses the 'modify' effect, which updates an existing resource in place. Specifically, it sets the `diskEncryptionSet.id` property on the OS disk to the customer-managed key encryption set identifier specified in the policy parameters. This action, performed during evaluation or via a remediation task, applies encryption to the OS disk without creating a new disk or deploying any additional resources.

Why this answer

The policy uses the 'modify' effect to add or replace the disk encryption set ID on any virtual machine's OS disk managed disk. This ensures VMs use a specific encryption set. 'deployIfNotExists' would deploy a resource, 'audit' would only log, 'deny' would block creation.

416
MCQeasy

A company is planning their Zero Trust data protection strategy. They want to classify and protect sensitive data stored in SharePoint Online. Which Microsoft tool should they use?

A.Microsoft Intune
B.Microsoft Defender for Cloud Apps
C.Microsoft Purview Information Protection
D.Azure Policy
AnswerC

Microsoft Purview Information Protection is the correct service for implementing a Zero Trust data protection strategy because it provides data classification, sensitivity labeling, and protection directly on documents and emails. It uses sensitive information types, trainable classifiers, and exact data match to automatically detect content and apply labels, which then can trigger encryption or access restrictions. Additionally, the Content Explorer and Activity Explorer give security teams visibility into labeled data, and the labels integrate across endpoints, cloud apps, and on-premises repositories.

Why this answer

Microsoft Purview Information Protection (formerly Microsoft Information Protection) is the correct tool because it provides integrated classification, labeling, and protection for sensitive data across Microsoft 365 services, including SharePoint Online. It uses sensitivity labels that can automatically apply encryption, rights management, and visual markings (headers/footers) to documents based on policy conditions, directly supporting the Zero Trust principle of 'assume breach' by protecting data at rest and in transit.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps (a CASB for monitoring and controlling cloud app usage) with the data classification and labeling capabilities of Microsoft Purview Information Protection, because both tools can handle sensitive data but serve fundamentally different roles in a Zero Trust strategy.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) tool focused on managing devices and apps, not on classifying or protecting data within SharePoint Online documents. Option B is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that provides visibility, threat detection, and access controls for cloud apps, but it does not natively classify or label sensitive data within SharePoint Online; it can discover sensitive data via integration with Purview but is not the primary tool for classification. Option D is wrong because Azure Policy is used to enforce compliance and governance rules on Azure resources (e.g., resource types, locations, tags) and does not apply sensitivity labels or encryption to SharePoint Online documents.

417
MCQhard

Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel. The query returns a list of users and IP addresses with failed sign-ins due to 'User Account Disabled' (ResultType 50057). The analyst wants to create a scheduled analytics rule that generates an incident when a user exceeds 5 such failures from the same IP in an hour. Which setting is missing from the query to meet the requirement?

A.Add a 'let' statement to define the threshold.
B.Add a 'project' to select columns.
C.Add a 'bin' or 'bin_at' to group by time windows.
D.Add a 'where' clause to filter by ResultType.
AnswerC

Without a bin or bin_at, the query computes a single count over the entire 1-hour period, and every time the scheduled rule runs it re-counts all events in that sliding window, creating duplicate incidents. Binning by a fixed interval (e.g., 5m) groups events into distinct time buckets, so each event contributes to exactly one bucket and the rule can reference the previous run's bucket to avoid reprocessing. Use bin_at with a fixed reference point to align buckets across runs when the schedule offset matters.

Why this answer

The query currently returns all failed sign-ins due to 'User Account Disabled' but does not aggregate them into time-based windows. To meet the requirement of generating an incident when a user exceeds 5 failures from the same IP in an hour, the query must group the results into 1-hour time buckets using 'bin' or 'bin_at' on the timestamp column, then count the failures per user and IP per bucket, and filter for counts greater than 5. Without this time-windowing, the query cannot enforce the 'in an hour' condition.

Exam trap

Microsoft often tests the candidate's understanding that time-based analytics rules require explicit time-windowing in the query (via bin or bin_at) rather than relying on the rule's run frequency or lookback period alone.

How to eliminate wrong answers

Option A is wrong because a 'let' statement defines a variable or threshold, but the threshold (5 failures) can be applied directly in a 'where' clause after aggregation; the missing piece is time-based grouping, not variable definition. Option B is wrong because 'project' selects or renames columns, which is useful for output but does not affect the aggregation or time-windowing required to count failures per hour. Option D is wrong because the query already filters by ResultType 50057 using a 'where' clause; adding another 'where' for ResultType would be redundant and does not address the missing time-window grouping.

418
MCQhard

An organization uses Microsoft Purview Information Protection. They want to automatically apply a sensitivity label to documents containing credit card numbers. Which policy should they configure?

A.Retention policy
B.Sensitivity label policy
C.Auto-labeling policy
D.Data loss prevention policy
AnswerC

Auto-labeling policies in Microsoft Purview scan items in SharePoint, OneDrive, and Exchange, and when they detect defined sensitive information types—such as credit card numbers—they automatically apply the specified sensitivity label to that content. These policies can first run in simulation mode to assess impact and then be enforced, ensuring consistent, touchless labeling across the organization. This is the correct answer because the question describes automatically labeling documents containing credit card data.

Why this answer

Auto-labeling policies in Microsoft Purview Information Protection automatically apply sensitivity labels to documents and emails that match specified conditions, such as the presence of credit card numbers. This policy uses sensitive information types (e.g., Credit Card Number) to scan content and apply the label without user intervention, meeting the requirement for automatic labeling.

Exam trap

The trap here is confusing sensitivity label policies (which require user action or default labeling) with auto-labeling policies (which automatically scan and apply labels based on sensitive data patterns), leading candidates to choose option B incorrectly.

How to eliminate wrong answers

Option A is wrong because retention policies manage how long content is kept or deleted, not the application of sensitivity labels. Option B is wrong because sensitivity label policies publish labels for manual or default application by users, but they do not automatically scan for sensitive data like credit card numbers. Option D is wrong because data loss prevention (DLP) policies detect and block sharing of sensitive data, but they do not apply sensitivity labels to content.

419
MCQeasy

Your organization uses Microsoft Sentinel. You need to design a solution that automatically responds to a detected ransomware incident by isolating the affected device in Microsoft Defender for Endpoint. Which tool should you use to create the automated response?

A.Create a workbook in Microsoft Sentinel.
B.Create a playbook in Microsoft Sentinel using Azure Logic Apps.
C.Create an automation rule in Microsoft Sentinel.
D.Create a hunting query in Microsoft Sentinel.
AnswerB

A playbook in Microsoft Sentinel is a collection of automated procedures built on Azure Logic Apps, enabling incident response actions such as isolating a device, disabling a user, or blocking an IP address. These playbooks contain the logic and steps that execute directly against security controls, and they can be triggered by alerts or incidents. This is exactly what is needed to design an automated response workflow.

Why this answer

The correct option is B: create a playbook in Microsoft Sentinel using Azure Logic Apps. Playbooks are built on Azure Logic Apps and are the mechanism in Microsoft Sentinel for orchestrating automated response actions, including calling the Microsoft Defender for Endpoint connector to run the 'Isolate machine' action against an affected device. Automation rules (option C) can trigger playbooks and perform basic triage, but they do not themselves contain the multi-step response logic that isolates a device.

A workbook (option A) is only a visualization/reporting tool, and a hunting query (option D) is a proactive search for threats, neither of which performs automated remediation.

420
Multi-Selecteasy

Your organization needs to comply with GDPR. You need to design a data protection strategy using Microsoft Purview. Which THREE capabilities should you include?

Select 3 answers
A.Azure Policy
B.eDiscovery
C.Data classification and labeling
D.Data subject request management
E.Data Loss Prevention (DLP) policies
AnswersC, D, E

Data classification and labeling are correct because GDPR requires you to know what personal data you hold, where it is stored, and how it is processed. Azure Purview Information Protection lets you classify and label files and emails based on sensitivity (e.g., Personal, Highly Confidential), which then enables automated protections like encryption or access restrictions. This labeling is foundational for data minimization, accountability (Article 5), and the ability to efficiently respond to data subject requests, making it a key GDPR enabler.

Why this answer

Data classification and labeling (C) is essential because Microsoft Purview sensitivity labels and trainable classifiers identify and tag personal data, which is the foundation for applying GDPR-mandated protections. Data subject request management (D) directly supports GDPR data subject rights (access, erasure, portability) by using Purview's Data Subject Request case tooling to find and act on personal data across Microsoft 365. Data Loss Prevention policies (E) enforce GDPR's protection and breach-prevention requirements by detecting sensitive information types (such as EU identifiers) and blocking or auditing their improper sharing.

Azure Policy (A) governs Azure resource compliance, not the discovery, classification, or protection of personal data in Purview, and eDiscovery (B) is a legal-hold and investigation tool rather than a GDPR data protection control, so neither belongs in this strategy.

421
MCQmedium

Your organization uses Microsoft Entra ID and needs to ensure that external partners can access only specific applications for 30 days. What should you configure?

A.Entitlement management and create an access package with an expiration of 30 days
B.B2B direct connect
C.Self-service group management
D.Conditional Access policy with session control
AnswerA

Entitlement management access packages bundle specific application assignments with an expiry, directly satisfying the 30-day external partner constraint. Time-limited access packages automatically revoke access at expiration, unlike conditional access policies, which govern session conditions rather than provisioning and lifecycle.

Why this answer

Entitlement management in Microsoft Entra ID allows you to create access packages that govern external partner access to specific applications. By configuring an access package with a 30-day expiration, you enforce time-limited access, ensuring partners can only access the designated applications for the required duration. This directly meets the requirement of restricting access to specific apps with a defined expiry.

Exam trap

The trap here is that candidates often confuse Conditional Access session controls (which manage sign-in frequency or app restrictions) with the ability to grant and expire access to specific applications, overlooking that entitlement management is the correct identity governance solution for time-limited external access.

How to eliminate wrong answers

Option B (B2B direct connect) is wrong because it is designed for mutual two-way access between organizations, typically for Teams Connect shared channels, and does not provide granular control over application-specific access or automatic expiration. Option C (self-service group management) is wrong because it allows users to create and manage their own groups, but it does not enforce time-bound access to specific applications or support external partner lifecycle management. Option D (Conditional Access policy with session control) is wrong because while it can enforce session restrictions like sign-in frequency, it cannot grant or expire access to specific applications for external users; it only controls access conditions for users who already have access.

422
MCQeasy

You are reviewing an ARM template snippet that creates a blob container. The security team requires that the container be accessible only via authorized Azure AD identities, not via anonymous access. Based on the exhibit, is the configuration correct?

A.Yes, but you also need to disable shared key access
B.No, you need to set 'publicAccess' to 'Blob' to restrict access
C.Yes, the setting 'publicAccess': 'None' prevents anonymous access, and Azure AD authentication is available by default
D.No, you must also configure a firewall rule to restrict access to Azure AD users
AnswerC

With `publicAccess: None`, Azure Storage rejects any anonymous request to the container, so unauthenticated clients cannot read or write data. Azure AD authentication is natively enabled for Blob Storage, meaning authorized users and applications can authenticate via their Azure AD identities without any additional configuration. This satisfies the requirement to block anonymous access while still allowing authenticated access.

Why this answer

Option C is correct because setting 'publicAccess' to 'None' on a blob container disables anonymous read access, and Azure AD (Microsoft Entra ID) authorization is always available for Blob Storage data-plane operations when a caller presents a valid OAuth 2.0 token with the appropriate RBAC role. No additional template property is required to enable Azure AD authentication; it is a service-level capability. Option A is wrong because disabling shared key access is an optional hardening step, not a prerequisite for Azure AD-only access.

Option B is wrong because 'Blob' or 'Container' publicAccess values actually permit anonymous read access, the opposite of the requirement. Option D is wrong because firewall rules restrict network origin, not the authentication method, and are not required to enforce Azure AD authorization.

423
MCQhard

A company uses Microsoft Sentinel and wants to prioritize incidents using user risk scores from Microsoft Entra ID Protection. Which configuration should they use to automatically assign a Sentinel severity based on the user's risk level?

A.Create a custom analytics rule that uses the RiskLevel field to set severity
B.Configure an automation rule to set severity when risk is high
C.Use a watchlist to map risk levels to severity
D.Create a playbook that assigns severity based on risk
AnswerA

Creating a custom analytics rule is the technically correct approach because analytics rules in Microsoft Sentinel evaluate telemetry at ingestion time and can dynamically assign incident severity by referencing data fields such as the RiskLevel attribute from Microsoft Entra ID Protection. By setting the Alert Severity to a value derived from RiskLevel (e.g., High if risk is medium, Higher if risk is high), the incident is created with the appropriate priority immediately, enabling efficient triage without further post-processing. This native, rule-based mapping is the only option among the listed alternatives that directly controls initial incident severity as the incident is generated from raw log data.

Why this answer

A is correct because Microsoft Sentinel's custom analytics rules can directly reference the `RiskLevel` field from Microsoft Entra ID Protection user risk data ingested via the UEBA connector. By writing a KQL query that checks the user's risk level (e.g., `RiskLevel == 'high'`) and mapping it to a Sentinel severity (e.g., High, Medium, Low) within the rule's incident creation settings, you automate severity assignment without external dependencies. This native integration ensures real-time synchronization of risk levels to incident priority.

Exam trap

The trap here is that candidates often assume automation rules or playbooks are required for any custom severity assignment, overlooking that custom analytics rules can directly map query results to severity fields without additional automation layers.

How to eliminate wrong answers

Option B is wrong because automation rules can set severity based on conditions like incident properties or entities, but they cannot directly read the `RiskLevel` field from Entra ID Protection user risk data; they operate on incident metadata after creation, not on raw risk signals. Option C is wrong because watchlists are static reference tables used for enrichment or correlation, not for dynamic, real-time mapping of continuously changing user risk levels to severity. Option D is wrong because playbooks (Azure Logic Apps) can assign severity, but they introduce latency and complexity compared to a native analytics rule, and they require additional permissions and orchestration, making them less efficient for this straightforward mapping.

424
MCQmedium

Your organization uses Microsoft Entra ID and wants to implement a passwordless authentication strategy. Users have smartphones. Which method should you recommend as the primary authentication method?

A.FIDO2 security keys
B.Microsoft Authenticator app with passwordless sign-in
C.SMS-based authentication
D.Windows Hello for Business
AnswerB

Microsoft Authenticator app with passwordless sign-in is the correct choice because it leverages the user's smartphone as a possession factor, using a cryptographic challenge-response protocol. When the user enters their username, the Authenticator app displays a number or a number match prompt; the user's approval signs the request with a private key stored in the device's secure enclave, eliminating the password entirely. This method is phishing-resistant, supports conditional access policies, and works seamlessly on iOS and Android, making it ideal for smartphone-centric users.

Why this answer

The Microsoft Authenticator app with passwordless sign-in is the correct primary method because it leverages the user's smartphone to provide a seamless, phishing-resistant authentication experience using public/private key cryptography (FIDO2/WebAuthn). This method aligns with the organization's goal of eliminating passwords while utilizing existing smartphone hardware, and it supports a simple user experience by requiring only a biometric or PIN verification on the phone.

Exam trap

The trap here is that candidates often confuse 'passwordless' with 'MFA' and select SMS-based authentication, not realizing that SMS still relies on a shared secret (the code) and is not truly passwordless or phishing-resistant.

How to eliminate wrong answers

Option A is wrong because FIDO2 security keys are hardware tokens that require additional procurement and distribution, making them less practical as a primary method for all users who already have smartphones. Option C is wrong because SMS-based authentication is not passwordless (it still relies on a one-time code sent via text) and is vulnerable to SIM-swapping and phishing attacks, failing to meet the passwordless strategy's security goals. Option D is wrong because Windows Hello for Business is tied to Windows devices and does not leverage smartphones, so it cannot serve as the primary method for users who may not always have access to a Windows PC.

425
Multi-Selectmedium

A company is designing a secure baseline for Azure VMs using Azure Policy and Microsoft Defender for Cloud. Which TWO recommendations should you include to ensure VMs are protected against common threats?

Select 2 answers
A.Configure Azure Backup for all VMs
B.Deploy the Log Analytics agent on all VMs
C.Enable just-in-time (JIT) VM access
D.Enable Azure Site Recovery
E.Use Azure Disk Encryption with Azure Key Vault
AnswersB, C

Deploying the Log Analytics agent (or its current replacement, the Azure Monitor Agent) is a foundational requirement for Microsoft Defender for Cloud to ingest operating system security events, audit logs, and vulnerability telemetry. Without this agent, Defender for Cloud cannot assess OS-level hardening or detect malicious activity, making the security baseline ineffective. This agent enables continuous monitoring, threat detection, and integration with Microsoft Sentinel, so it directly supports the threat protection baseline.

Why this answer

Enabling just-in-time (JIT) VM access reduces attack surface by blocking inbound traffic to management ports. Deploying the Log Analytics agent is required for Defender for Cloud to collect security data. The other options are either not security baselines or not VM-specific.

426
MCQhard

Refer to the exhibit. You are reviewing a Conditional Access policy in Microsoft Entra ID. Based on the JSON snippet, what is the most likely outcome when a user with high user risk attempts to sign in?

A.The sign-in is blocked because user risk is high
B.The sign-in is blocked only if sign-in risk is also high
C.The sign-in is allowed because sign-in risk is not high
D.The user is prompted for multi-factor authentication
AnswerA

The Conditional Access policy explicitly assigns the 'High' user risk condition to the 'Block access' grant control, meaning any sign-in event where the user's risk level is assessed as High will be immediately denied. User risk is derived from identity protection signals such as leaked credentials or anomalous behavior, and once it meets the configured threshold, the policy's block action applies without regard to other conditions. In the exhibit, no sign-in risk condition is configured, so user risk alone is sufficient to trigger the block.

Why this answer

The Conditional Access policy shown in the JSON snippet includes a condition for 'userRiskLevels' set to 'high', and the grant control is 'block'. When a user with high user risk attempts to sign in, the policy evaluates the user risk level and, since it matches the condition, applies the block action, preventing the sign-in entirely.

Exam trap

The trap here is that candidates often confuse user risk with sign-in risk, assuming both must be high for a block to occur, or mistakenly think that high user risk only triggers MFA rather than a block, when the policy explicitly specifies 'block' as the control.

How to eliminate wrong answers

Option B is wrong because the policy does not require sign-in risk to be high; it only evaluates user risk, and the block is triggered solely by high user risk regardless of sign-in risk. Option C is wrong because the policy does not check sign-in risk at all; the sign-in is blocked due to high user risk, not allowed because sign-in risk is not high. Option D is wrong because the grant control is set to 'block', not 'requireMfa', so the user is not prompted for multi-factor authentication; they are blocked.

427
Multi-Selecteasy

Your organization needs to comply with regulatory requirements for data retention and deletion. Which TWO Microsoft Purview features should you use?

Select 2 answers
A.Retention policies
B.Data Loss Prevention (DLP) policies
C.Audit logs
D.Retention labels
E.eDiscovery
AnswersA, D

Retention policies in Microsoft Purview let you retain content for a defined period and then delete it automatically, directly satisfying regulatory retention and deletion obligations. They apply across Exchange, SharePoint, OneDrive and Teams without requiring manual intervention.

Why this answer

Retention policies (A) are correct because they let you apply retention and deletion settings at the workload, location, or site level (for example, all Exchange mailboxes or all SharePoint sites) so content is kept for a defined period and then deleted, which directly satisfies regulatory data-retention and deletion requirements. Retention labels (D) are also correct because they provide item-level retention and deletion control, including event-based retention and disposition review, allowing specific documents or emails to be governed precisely per regulation. Together, policies handle broad, automatic governance while labels handle granular, item-specific governance.

DLP policies (B) are not the right fit because they prevent sharing or leakage of sensitive data rather than enforcing retention or deletion periods. Audit logs (C) only record activity for investigation and compliance monitoring, and eDiscovery (E) is used to identify, hold, and export content for legal cases, not to implement retention or deletion schedules.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention (DLP) policies with retention policies because both involve data governance, but DLP focuses on preventing data exfiltration, not on lifecycle management of data retention and deletion.

428
MCQhard

Refer to the exhibit. A security analyst is reviewing a Windows security event log from a domain controller. The event indicates an attempted logon failure. Which type of attack is most likely being attempted?

A.Kerberos golden ticket attack
B.DCSync attack
C.Pass-the-hash attack
D.Brute-force password guessing attack
AnswerD

Event 4625 with Logon Type 3 is generated when a network logon attempt (e.g., SMB/NetBIOS) fails due to an invalid username or password, which is the classic signature of a brute-force password guessing attack. The combination of multiple sequential failed logon attempts originating from a single source IP and targeting a privileged account such as a domain administrator indicates that the attacker is systematically trying many passwords to crack the account. This is distinct from opportunistic scanning because the failures are concentrated on one high-value account, and if successful, the attacker could move laterally using the compromised credentials.

Why this answer

The correct answer is D, a brute-force password guessing attack, because a logon failure event on a domain controller most directly indicates repeated or attempted authentication with incorrect credentials, which is the signature of password guessing. Brute-force attacks generate failed logon events (e.g., Windows Security Event ID 4625) as the attacker tries multiple passwords against an account. In contrast, a Kerberos golden ticket attack (A) forges a TGT using the KRBTGT hash and typically does not produce logon failures, and a DCSync attack (B) abuses directory replication permissions to extract password hashes, not to guess passwords.

A pass-the-hash attack (C) authenticates using a stolen NTLM hash and usually succeeds without failed logon attempts, so it does not match the failed-logon scenario.

429
MCQeasy

A company wants to use Microsoft Defender XDR to correlate alerts across endpoints, email, and identities. Which component enables this correlation?

A.Microsoft 365 Defender
B.Microsoft Defender XDR
C.Microsoft Sentinel
D.Microsoft Defender for Cloud
AnswerB

Microsoft Defender XDR is the correct answer because it is the integrated, cloud-native extended detection and response (XDR) platform that natively correlates alerts from Microsoft Defender for Endpoint, Office 365, Identity, and Cloud Apps. By combining signals across domains into a single incident queue, it performs the automatic cross-product correlation the company requires. Its machine-learning-driven analytics unify threat hunting and response without needing external SIEM logic.

Why this answer

Microsoft Defender XDR (the new name for Microsoft 365 Defender) is the unified pre- and post-breach enterprise defense suite that natively correlates signals from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps. Its correlation engine uses machine learning and the Microsoft Intelligent Security Graph to fuse alerts across these domains into a single incident, enabling security teams to see the full attack chain from email to endpoint to identity.

Exam trap

The trap here is that candidates confuse the old branding (Microsoft 365 Defender) with the new branding (Microsoft Defender XDR) and pick the outdated name, or they mistake Microsoft Sentinel's broader SIEM capabilities for the native cross-domain correlation engine that Defender XDR provides.

How to eliminate wrong answers

Option A is wrong because 'Microsoft 365 Defender' is the previous name for the same product now called Microsoft Defender XDR; the question explicitly uses the current name, so selecting the old name would be technically inaccurate. Option C is wrong because Microsoft Sentinel is a cloud-native SIEM and SOAR solution that ingests logs from many sources, including Defender XDR, but it does not perform the native, real-time cross-domain alert correlation that Defender XDR's built-in engine does; Sentinel correlates at a higher level using analytics rules and is not the component that directly correlates alerts across endpoints, email, and identities. Option D is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) focused on securing Azure, AWS, and GCP resources, not on correlating alerts across endpoints, email, and identities.

430
MCQeasy

You need to design a backup and disaster recovery solution for Azure virtual machines that meets a recovery time objective (RTO) of 15 minutes and a recovery point objective (RPO) of 1 hour. Which Azure service should you use?

A.Azure Site Recovery
B.Azure managed disk
C.Azure VM snapshot
D.Azure Backup
AnswerA

Azure Site Recovery is the correct choice because it provides continuous, block-level replication of Azure VMs to a secondary region. It delivers a recovery point objective (RPO) in the range of minutes, well within the required 1-hour RPO, and offers orchestrated failover and failback with predictable recovery time objectives (RTO). This makes it the only listed option that is purpose-built for disaster recovery, not just backup or local redundancy.

Why this answer

Azure Site Recovery is the correct choice because it provides continuous replication of Azure VMs to a secondary region with recovery points as often as every 5 minutes, easily meeting the 1-hour RPO, and supports orchestrated failover that can bring workloads online within the 15-minute RTO. Azure Backup (D) is designed for data protection and long-term retention, with typical RPOs of once or twice per day and restore times that generally exceed 15 minutes, so it cannot meet these objectives. Azure managed disk (B) is only a storage abstraction and provides no replication or failover capability, while Azure VM snapshots (C) are point-in-time copies with no automated orchestration or cross-region recovery, so neither satisfies the RTO/RPO requirements.

431
Multi-Selectmedium

Your organization is designing a solution to protect sensitive data in Microsoft 365. You need to implement Microsoft Purview Data Loss Prevention (DLP) policies. Which TWO actions can a DLP policy take when a match occurs? (Choose TWO.)

Select 2 answers
A.Encrypt the file with Azure Information Protection.
B.Quarantine the file for administrator review.
C.Automatically apply a sensitivity label.
D.Block the sharing of sensitive information.
E.Show a policy tip to the user.
AnswersD, E

Blocking the sharing of sensitive information is a core DLP enforcement action. In Microsoft Purview, you can configure DLP policies to block sharing via email (e.g., 'Block only people outside your organization'), block uploads to external sites, or block copy/paste to unsanitized apps. This action can be configured with an override option or a policy tip, directly preventing data loss. It is the definitive 'enforce' behavior for DLP scenarios.

Why this answer

Option D is correct because Microsoft Purview DLP policies can block sharing of sensitive information across workloads such as Exchange Online, SharePoint, OneDrive, and Teams, preventing users from sending or sharing content that matches a DLP rule. Option E is correct because DLP policies can display policy tips to users in supported apps (for example, Outlook, Word, Excel, and Teams), notifying them that content matches a rule and offering override or report options. Option A is not a native DLP action; encryption with Azure Information Protection is typically achieved through sensitivity labels or auto-labeling policies, not directly as a DLP policy action.

Option B is not a standard DLP action in Microsoft Purview; DLP can block, restrict access, or notify, but it does not quarantine files for administrator review. Option C is not a DLP policy action; automatically applying a sensitivity label is performed by auto-labeling policies in Microsoft Purview, not by DLP policies.

432
Multi-Selecteasy

You are designing a backup strategy for Azure virtual machines using Azure Backup. The solution must support cross-region restore and provide 10 years of retention for compliance. Which THREE features should you enable? (Choose THREE.)

Select 3 answers
A.Cross-Region Restore
B.Azure Site Recovery replication
C.Soft Delete
D.Immutable vault
E.Archive Tier
AnswersA, D, E

Cross-Region Restore enables you to restore backup data to a paired Azure region, providing a robust disaster recovery posture when the primary region is unavailable. It is a critical component of a comprehensive backup strategy, as it ensures business continuity and geographic resilience for your VMs. While it does not directly address long-term retention, it complements immutable vault and Archive Tier by guaranteeing that your backup data is accessible even in a regional failure scenario.

Why this answer

Option A (Cross-Region Restore) is correct because it is the Azure Backup feature that enables restoring data from a secondary, paired Azure region when the primary region's backup data is unavailable, directly satisfying the cross-region restore requirement. Option D (Immutable vault) is correct because enabling immutability on the Recovery Services vault prevents backup data from being deleted or modified before its retention period expires, which is essential for meeting the 10-year compliance retention requirement. Option E (Archive Tier) is correct because Azure Backup's archive tier supports long-term retention of recovery points for up to 10 years at lower cost, matching the compliance retention duration.

Option B (Azure Site Recovery replication) is not a backup feature but a disaster-recovery orchestration service for replicating and failing over VMs, so it does not provide the required backup retention or cross-region restore of backup data. Option C (Soft Delete) only provides a 14-day grace period to recover deleted backup data and does not deliver cross-region restore or 10-year retention, so it does not meet the stated requirements.

433
MCQeasy

Your organization plans to use Microsoft Defender for Cloud to secure Azure resources. The security team wants to continuously assess compliance against the CIS Azure Foundations Benchmark. What should you do?

A.Create a custom Azure Blueprint for CIS
B.Deploy Azure Security Center (legacy)
C.Enable the CIS Azure Foundations Benchmark in Defender for Cloud regulatory compliance dashboard
D.Assign Azure Policy for all CIS controls manually
AnswerC

Enabling the CIS Azure Foundations Benchmark in Defender for Cloud's regulatory compliance dashboard is the correct action because it automatically attaches a curated Azure Policy initiative containing the required policies and controls. The dashboard continuously assesses your Azure environment against CIS controls, provides a compliance score, and surfaces remediation recommendations. This directly supports the benchmark with minimal manual effort and ongoing visibility, fulfilling your organization's compliance monitoring requirement.

Why this answer

Microsoft Defender for Cloud's regulatory compliance dashboard includes built-in support for the CIS Azure Foundations Benchmark. By enabling this standard in the dashboard, Defender for Cloud continuously assesses your Azure resources against all CIS controls, providing automated compliance scores and remediation recommendations without requiring custom definitions or manual policy assignments.

Exam trap

The trap here is that candidates may think they need to create custom Azure Blueprints or manually assign Azure Policies for CIS compliance, overlooking that Defender for Cloud's regulatory compliance dashboard already includes a pre-configured, continuously updated CIS benchmark initiative that automates the entire assessment process.

How to eliminate wrong answers

Option A is wrong because Azure Blueprints are used to define a repeatable set of Azure resources and policies for deployment, not to continuously assess compliance against a specific benchmark like CIS; the CIS benchmark is already available as a built-in standard in Defender for Cloud. Option B is wrong because Azure Security Center (legacy) has been superseded by Microsoft Defender for Cloud, and the legacy version does not include the regulatory compliance dashboard with CIS Azure Foundations Benchmark support; you must use the current Defender for Cloud. Option D is wrong because manually assigning Azure Policy for all CIS controls is inefficient, error-prone, and unnecessary since Defender for Cloud provides a pre-built, automatically updated CIS benchmark initiative that maps policies to controls and continuously evaluates compliance.

434
MCQmedium

Your organization uses Microsoft Sentinel for security operations. You need to ensure that all incidents related to a specific critical asset are automatically assigned to the senior SOC analyst. The assignment should occur as soon as the incident is created. What should you configure?

A.Modify the analytics rule to include a custom details field for owner.
B.Create an automation rule that sets the incident owner to the senior SOC analyst.
C.Create a playbook and trigger it from an automation rule.
D.Configure a workbook to display incidents and manually assign them.
AnswerB

An automation rule is the native, direct mechanism for assigning incident ownership at creation time. You define a trigger condition (e.g., all incidents or specific severity) and add an action to set the owner to the senior SOC analyst; the rule runs automatically the moment an incident is created, ensuring immediate accountability without human intervention. This is the simplest and most scalable approach for a one-step assignment.

Why this answer

Automation rules in Microsoft Sentinel can directly set the incident owner upon creation without requiring a playbook. This is the simplest and most efficient method for immediate assignment, as automation rules run automatically when an incident is created and can modify incident properties like owner.

Exam trap

The trap here is that candidates often over-engineer the solution by selecting a playbook (Option C) for a task that can be handled natively by automation rules, failing to recognize that automation rules can directly modify incident properties without needing a playbook.

How to eliminate wrong answers

Option A is wrong because custom details fields in analytics rules are used to extract and surface specific data from raw events into the incident, not to assign ownership or trigger automated actions. Option C is wrong because while a playbook can assign an owner, it introduces unnecessary complexity and latency; automation rules can directly set the owner without invoking a playbook, making it the preferred approach for simple assignments. Option D is wrong because workbooks are visualization tools for analyzing data and cannot automate incident assignment; manual assignment contradicts the requirement for automatic assignment upon creation.

435
MCQmedium

A company is deploying Microsoft Defender for Cloud to secure their hybrid cloud environment. They need to ensure that regulatory compliance with PCI DSS is continuously monitored and reported. Which solution should they use to automatically assess and report compliance posture?

A.Azure Policy
B.Microsoft Purview Information Protection
C.Regulatory compliance dashboard in Microsoft Defender for Cloud
D.Microsoft Entra ID Governance
AnswerC

The Regulatory compliance dashboard in Microsoft Defender for Cloud is the correct tool because it continuously monitors subscribed cloud resources against a wide range of industry and regulatory standards (for example, PCI DSS, ISO 27001, SOC 2, and NIST). It provides a real-time compliance score, a control-by-control breakdown, automated evidence collection, and the ability to download authoritative PDF/CSV compliance reports. Unlike Azure Policy's raw policy compliance, this dashboard maps assessments directly to regulatory control gaps and maintains a standards-specific view, making it the purpose-built solution for continuous compliance assessment and reporting (e.g., PCI DSS).

Why this answer

The Regulatory compliance dashboard in Microsoft Defender for Cloud is the correct solution because it provides built-in, automated assessment of compliance against regulatory standards like PCI DSS. It continuously monitors your hybrid cloud environment against the PCI DSS controls, generates a compliance score, and produces detailed reports without requiring custom policy definitions. This dashboard integrates with Azure Policy to map controls to assessments, but the dashboard itself is the dedicated tool for viewing and reporting compliance posture.

Exam trap

The trap here is that candidates often confuse Azure Policy (the enforcement engine) with the Regulatory compliance dashboard (the reporting interface), leading them to select Azure Policy as the direct solution for compliance reporting, when in fact the dashboard is the correct tool for continuous monitoring and reporting of regulatory posture.

How to eliminate wrong answers

Option A is wrong because Azure Policy is a service that enforces and audits compliance rules by creating custom policies and initiatives, but it does not provide a pre-built, continuously updated regulatory compliance dashboard or reporting specifically for PCI DSS; it is the underlying mechanism that the Regulatory compliance dashboard uses, not the reporting solution itself. Option B is wrong because Microsoft Purview Information Protection focuses on classifying, labeling, and protecting sensitive data (e.g., credit card numbers) through encryption and access controls, not on assessing or reporting overall compliance posture against a framework like PCI DSS. Option D is wrong because Microsoft Entra ID Governance deals with identity lifecycle, access reviews, and entitlement management for users and groups, not with continuous monitoring or reporting of cloud infrastructure compliance against regulatory standards.

436
MCQeasy

A company wants to protect sensitive data in their Azure SQL Database from unauthorized access. Which feature should they enable?

A.Azure Information Protection
B.Transparent Data Encryption (TDE)
C.Azure Key Vault
D.Azure Firewall
AnswerB

Transparent Data Encryption (TDE) performs real-time I/O encryption and decryption of Azure SQL Database data and transaction log files, protecting data at rest without requiring changes to the application. The database engine writes encrypted pages to disk and decrypts them when they are read into memory, making the process completely transparent to clients. This is the only option listed that directly secures the database's stored sensitive data.

Why this answer

Transparent Data Encryption (TDE) performs real-time I/O encryption and decryption of the data and log files at the page level, protecting data at rest in Azure SQL Database. This directly addresses the requirement to prevent unauthorized access to the underlying storage files, as TDE ensures that data cannot be read if the physical media is compromised.

Exam trap

The trap here is that candidates often confuse Azure Information Protection (a classification tool) with database encryption, or think Azure Key Vault alone provides encryption, when in fact TDE is the specific feature that encrypts the database files at rest.

How to eliminate wrong answers

Option A is wrong because Azure Information Protection is a classification and labeling solution for documents and emails, not a database-level encryption feature for Azure SQL Database. Option C is wrong because Azure Key Vault is a secure key management service that can store TDE encryption keys, but it does not itself encrypt the database; it is a supporting component, not the primary feature. Option D is wrong because Azure Firewall is a network security service that controls inbound and outbound traffic at the network layer, not a data-at-rest encryption mechanism for database files.

437
MCQhard

A company is evaluating their incident response (IR) process. They use Microsoft Sentinel as their SIEM. During a security incident, the IR team struggles to quickly find related alerts and entities. Which improvement should they implement to enhance investigation efficiency?

A.Create more analytics rules to cover additional scenarios.
B.Configure automation rules to automatically classify incidents.
C.Increase data retention for all log tables.
D.Leverage the investigation graph to explore entity relationships.
AnswerD

The investigation graph in Microsoft Sentinel provides a visual, interactive map of entities—such as accounts, hosts, and IP addresses—and the relationships that connect them across alerts and incidents. Analysts can expand and pivot through nodes to uncover attack paths, lateral movement, and common associations that are not apparent in raw log lists. This direct exploration of entity relationships is the most effective way to understand the full scope and root cause of an incident, thereby improving investigation efficiency.

Why this answer

The investigation graph in Microsoft Sentinel provides a visual, interactive map of entity relationships (e.g., users, hosts, IP addresses, alerts) connected to an incident. This directly addresses the IR team's struggle to quickly find related alerts and entities by allowing them to explore and pivot across linked data points, drastically reducing manual correlation time.

Exam trap

The trap here is that candidates often confuse 'automation' (Option B) with 'investigation efficiency,' but automation rules handle classification and assignment, not the visual exploration of entity relationships that the investigation graph provides.

How to eliminate wrong answers

Option A is wrong because creating more analytics rules increases the volume of alerts and incidents, which would exacerbate the problem of finding related alerts and entities rather than improving investigation efficiency. Option B is wrong because configuring automation rules to automatically classify incidents helps with triage and prioritization, but does not assist investigators in exploring relationships between alerts and entities during an active investigation. Option C is wrong because increasing data retention for all log tables extends the storage period but does not provide any mechanism to correlate or visualize relationships between alerts and entities; it simply keeps more raw data without improving discoverability.

438
MCQhard

A company uses Azure Policy to audit storage accounts for secure transfer (HTTPS) enforcement. The policy is set to 'AuditIfNotExists' but compliance shows 0% non-compliant storage accounts even though some accounts have secure transfer disabled. What is the most likely cause?

A.The policy is in 'audit' mode and does not evaluate
B.The policy should use 'Audit' or 'Deny' effect instead of 'AuditIfNotExists'
C.The storage accounts are in a different region
D.The policy assignment scope does not include the non-compliant accounts
AnswerB

The 'AuditIfNotExists' effect is intended to validate the existence of a related resource, such as a diagnostic setting or an endpoint, and it flags resources where that related resource is missing. It does not directly inspect a property of the storage account itself, like whether secure transfer is enabled. To audit or deny a property value, the policy should use the 'Audit' effect (for alerting) or 'Deny' effect (for blocking), with a condition that evaluates that property.

Why this answer

The 'AuditIfNotExists' effect is designed to audit resources that do not have a specific extension or sub-resource (e.g., a diagnostic setting or an agent). For a policy that needs to check a property of the storage account itself (like secure transfer enabled), the correct effect is 'Audit' (or 'Deny'). 'AuditIfNotExists' will never flag a storage account as non-compliant for missing the secure transfer property because it is looking for the absence of a child resource, not a property misconfiguration.

Exam trap

The trap here is that candidates confuse 'AuditIfNotExists' with 'Audit', assuming both can check resource properties, but 'AuditIfNotExists' is specifically for auditing the absence of a sub-resource or extension, not the resource's own configuration.

How to eliminate wrong answers

Option A is wrong because 'audit' mode is not a valid Azure Policy mode; policies use 'audit' effect, not a mode, and all policies evaluate resources within their scope regardless of effect. Option C is wrong because Azure Policy evaluates all storage accounts in the assigned scope regardless of region; region does not affect policy evaluation. Option D is wrong because if the policy assignment scope did not include the non-compliant accounts, those accounts would simply not be evaluated, but the question states compliance shows 0% non-compliant, implying the accounts are in scope yet not flagged, which points to an effect mismatch.

439
MCQeasy

Your organization is required to retain all Microsoft Teams chat messages for 7 years due to regulatory compliance. You need to design a solution that automatically retains and, if needed, e-discovery searches these messages. What should you configure?

A.Microsoft Purview retention policies and eDiscovery
B.Microsoft Purview Data Loss Prevention policies
C.Azure Policy
D.Sensitivity labels auto-labeling
AnswerA

Microsoft Purview retention policies can be assigned to Teams channel and chat messages to preserve data for a defined period such as seven years, protecting it from permanent deletion. eDiscovery tools in the same compliance portal provide search, legal hold, and export capabilities, enabling the organization to locate and produce retained Teams communications when required. Together they satisfy the retention mandate because retention preserves the data and eDiscovery operationalizes access to it.

Why this answer

Microsoft Purview retention policies are designed to retain data for a specified period (e.g., 7 years) and can be applied to Microsoft Teams chat messages. eDiscovery (now part of Microsoft Purview eDiscovery) allows authorized users to search, hold, and export retained content for legal or compliance purposes. Together, they meet the regulatory requirement for retention and searchability.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention (DLP) policies with retention policies, thinking DLP can also retain data, but DLP only monitors and blocks data exfiltration, not retention or search.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) policies are used to prevent sensitive information from being shared or leaked, not to enforce retention or enable eDiscovery searches. Option C is wrong because Azure Policy is used to enforce organizational standards and assess compliance at the Azure resource level (e.g., VMs, storage), not to manage Microsoft Teams chat message retention or eDiscovery. Option D is wrong because sensitivity labels auto-labeling applies classification and protection (e.g., encryption, markings) to content based on sensitive data, but does not provide retention or eDiscovery search capabilities.

440
MCQhard

A company uses Microsoft Entra ID with P2 licenses. They want to implement a Zero Trust approach that requires step-up authentication for accessing high-value data in SharePoint. The solution must use risk-based policies and minimize user friction. Which combination should you recommend?

A.Microsoft Entra Conditional Access with trusted locations policy
B.Microsoft Entra Conditional Access with sign-in risk policy and authentication context for sensitive data
C.Azure AD Conditional Access with MFA for all SharePoint access
D.Microsoft Entra Identity Protection user risk policy with MFA
AnswerB

This is correct because the Conditional Access policy uses Microsoft Entra Identity Protection's real-time sign-in risk score to trigger step-up (for example MFA or restricted session) only when anomalous behavior is detected. Adding an authentication context makes the requirement granular: the risk-based control can be attached to SharePoint sites or files with a specific sensitivity label rather than to every resource. This combines risk assessment with data sensitivity, which is exactly the requirement. It is also the only option that pairs a per-sign-in risk signal with a context-aware session control.

Why this answer

It combines Conditional Access with a sign-in risk policy (from Identity Protection) and an authentication context that is applied to sensitive SharePoint data. This enforces step-up authentication only when risk is detected and the user accesses high-value data, minimizing friction for low-risk sessions while meeting Zero Trust requirements.

Exam trap

The trap here is that candidates often confuse user risk policies (which are based on historical user behavior) with sign-in risk policies (which evaluate the current session in real time), and they overlook the role of authentication context in scoping enforcement to specific data rather than all SharePoint access.

How to eliminate wrong answers

Option A is wrong because a trusted locations policy only checks the network location (e.g., corporate IP range) and does not evaluate user or sign-in risk, nor does it enforce step-up authentication based on data sensitivity. Option C is wrong because requiring MFA for all SharePoint access is not risk-based; it applies friction to every session regardless of risk level, violating the 'minimize user friction' requirement. Option D is wrong because a user risk policy with MFA triggers based on user-level risk (e.g., leaked credentials) but does not use authentication context to scope enforcement to specific high-value data in SharePoint, and it does not leverage sign-in risk for real-time step-up.

441
MCQmedium

A SOC team uses Microsoft Sentinel for incident management. They need to ensure that when a high-severity incident is created, a Teams message is sent to the security team and an email is sent to the IT manager. What is the most efficient way to achieve this?

A.Configure the analytics rule to send notifications when an incident is created.
B.Create an automation rule in Sentinel that triggers a playbook to send the notifications.
C.Use a workbook to display incidents and have a manual process to send notifications.
D.Enable incident creation in the data connector settings.
AnswerB

Automation rules are the native orchestration layer in Microsoft Sentinel that run automatically when an incident is created or updated, and they can invoke a playbook as an action. A playbook, built on Azure Logic Apps, can send email, post to Teams, create a ticket, or call any API, making it the proper way to deliver notifications. This is the recommended pattern for automating incident response notifications without custom code.

Why this answer

Automation rules in Microsoft Sentinel can trigger a playbook (an Azure Logic Apps workflow) when an incident is created, allowing you to send a Teams message and an email simultaneously. This is the most efficient, automated approach without manual intervention or modifying the analytics rule itself.

Exam trap

The trap here is that candidates often confuse analytics rule configuration (which can only generate incidents or alerts) with automation rules (which handle post-creation actions like playbooks), leading them to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because analytics rules in Sentinel do not have native capabilities to send Teams messages or emails directly; they only generate incidents or alerts. Option C is wrong because workbooks are for visualization and reporting, not for automated notification workflows, and relying on a manual process defeats efficiency. Option D is wrong because data connector settings only control ingestion of logs and incident creation from external sources, not post-incident notification actions.

442
MCQmedium

You are the security architect for a financial services company that stores customer PII in an Azure SQL Database. The database currently uses service-managed Transparent Data Encryption (TDE). A new regulatory requirement mandates that the company controls and rotates the encryption keys used to protect the database, and that all key operations are auditable. You need to recommend a solution that meets the requirement with the least administrative overhead. What should you recommend?

A.Enable Always Encrypted with secure enclaves on the sensitive columns.
B.Use service-managed TDE keys and enable Azure Policy to audit key rotation.
C.Configure TDE with a customer-managed key stored in Azure Key Vault (BYOK).
D.Store the database in an Azure Disk Encryption–protected VM-hosted SQL Server instance.
AnswerC

Customer-managed TDE keys in Azure Key Vault give the organization full control over key lifecycle, including rotation and revocation, and Key Vault logging records every key operation for audit. This directly satisfies the regulatory requirement for controlled, auditable key management without requiring application changes or additional infrastructure.

Why this answer

The requirement is customer control and auditability of the keys that protect data at rest in Azure SQL Database. Transparent Data Encryption with a customer-managed key in Azure Key Vault is the native Azure SQL feature that satisfies this: the customer owns the key, controls rotation and revocation, and Key Vault diagnostics provide the audit trail. Other options either protect a different data state or shift to an unsupported platform.

Exam trap

The trap here is assuming Always Encrypted is required whenever a regulation mentions customer-controlled keys, when the actual control point is the TDE key hierarchy.

443
MCQmedium

Your organization uses Microsoft Sentinel to monitor hybrid workloads. You need to design a solution to detect lateral movement attempts from compromised on-premises servers to Azure VMs. Which data connector should you prioritize?

A.Syslog via AMA
B.Office 365 Logs
C.Windows Security Events via AMA
D.Azure Activity Log
AnswerC

Windows Security Events via AMA is the correct choice because the Azure Monitor Agent can collect Windows Security log entries from on-premises and Azure Arc-enabled Windows servers. These events include critical authentication-related event IDs like 4624 (successful logon), 4625 (failed logon), and 4768 (Kerberos ticket request), which are essential for detecting lateral movement. The data can be streamed directly to Microsoft Sentinel, allowing analysts to build detections for suspicious logon patterns and pass-the-hash attacks across hybrid identities.

Why this answer

Windows Security Events via AMA is the correct choice because lateral movement from compromised on-premises servers to Azure VMs is detected through Windows security event telemetry such as logon events (4624, 4625), explicit credential use (4648), and special privilege assignment (4672), which this connector collects from both on-premises and Azure Windows machines into Microsoft Sentinel. The Azure Monitor Agent (AMA) with the Windows Security Events data connector supports the hybrid, multi-cloud scope described, making it the priority connector for this detection scenario. Syslog via AMA is not appropriate because Syslog captures Linux/network appliance messages, not the Windows authentication events needed to trace lateral movement.

Office 365 Logs cover cloud productivity audit activity, and Azure Activity Log records control-plane operations on Azure resources, neither of which provides the host-level Windows logon telemetry required here.

444
MCQeasy

Your organization uses Microsoft Defender for Office 365. You need to design a solution to protect users from malicious links in email. What should you configure?

A.Anti-spam policy
B.Safe Attachments policy
C.Safe Links policy
D.Anti-phishing policy
AnswerC

The Safe Links policy is the correct answer because it provides time-of-click URL protection by rewriting links in email messages to point to Microsoft's safety checking service, and it can also scan URLs in Teams and Office apps. When a user clicks a rewritten link, the service checks the URL against real-time threat intelligence and blocks navigation if it is malicious. This ensures that even URLs that look benign at delivery are protected.

Why this answer

Safe Links policy (option C) is correct because it is the Defender for Office 365 feature that rewrites and time-of-click verifies URLs in email (and Teams/Office apps), blocking malicious links at delivery and after delivery. This directly addresses the requirement to protect users from malicious links in email. Anti-spam policy (A) filters spam and bulk mail but does not detonate or rewrite URLs for malicious link protection.

Safe Attachments policy (B) detonates attachments in a sandbox, not links. Anti-phishing policy (D) covers impersonation and spoofing protections, not URL rewriting/blocking of malicious links.

445
MCQhard

Your organization is a multi-national corporation that uses Microsoft 365 E5 and Azure. You need to design a security operations center (SOC) to detect and respond to threats across identities, endpoints, and cloud apps. The SOC team will use a single pane of glass for incident management. Requirements: (1) Centralize alerts from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps, (2) Automate incident response playbooks, (3) Use advanced hunting across all data sources, (4) Integrate with external threat intelligence feeds, (5) Provide role-based access control for SOC analysts. Which Microsoft solution should you implement?

A.Microsoft 365 Defender portal
B.Microsoft Sentinel
C.Microsoft Purview Compliance Manager
D.Microsoft Defender for Cloud
AnswerB

Microsoft Sentinel is the only option that functions as a true cloud-native SIEM/SOAR, ingesting security telemetry from across Microsoft Defender products, Azure services, and third-party sources. It provides automation playbooks for incident response, advanced hunting with Kusto Query Language (KQL), built-in threat intelligence connectors, and role-based access control for the SOC. This centralized architecture is essential for aggregating identity, endpoint, and app signals into a single detection and response workflow, meeting the requirement for a security operations center.

Why this answer

Option B is correct because Microsoft Sentinel is a cloud-native SIEM and SOAR solution that ingests alerts from Microsoft Defender services, third-party sources, and external threat intelligence, provides a single pane of glass for incident management, supports automation playbooks via Logic Apps, and offers advanced hunting with KQL across all connected data sources. It also supports RBAC for SOC analysts. The Microsoft 365 Defender portal (A) centralizes Defender alerts but lacks the broader SIEM/SOAR capabilities and external threat intelligence integration required.

Exam trap

SC-100 often tests the misconception that the Microsoft 365 Defender portal is a full SIEM/SOAR solution, when in fact Sentinel is required for centralized incident management, external threat intelligence, and cross-platform advanced hunting.

How to eliminate wrong answers

Option A is wrong because the Microsoft 365 Defender portal is an XDR console for Defender workloads; it does not natively ingest external threat intelligence feeds, does not provide full SIEM correlation across non-Microsoft sources, and its automation is limited compared to Sentinel's Logic Apps playbooks. Option C is wrong because Microsoft Purview Compliance Manager is a compliance assessment tool, not a SOC detection and response platform. Option D is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection tool for Azure, AWS, and GCP, not a SIEM/SOAR platform for centralized incident management.

446
MCQmedium

A company uses Azure App Service to host a web application that stores sensitive data in Azure SQL Database. The security team requires that data at rest in the database be encrypted using a customer-managed key stored in Azure Key Vault. The key must be rotated automatically every 90 days. What is the recommended approach to meet these requirements?

A.Encrypt sensitive columns using cell-level encryption with keys stored in Azure Key Vault and rotate keys manually every 90 days.
B.Enable Transparent Data Encryption (TDE) with service-managed keys in Azure SQL Database.
C.Enable TDE with customer-managed keys in Azure Key Vault and set a key rotation policy in Key Vault to rotate the key every 90 days.
D.Use Always Encrypted with column master keys stored in Azure Key Vault and configure key rotation in the application code.
AnswerC

Enabling TDE with customer-managed keys in Azure Key Vault is the correct choice because it gives the organization explicit control over the key lifecycle while keeping encryption transparent to the application. You can configure a Key Vault key rotation policy to automatically rotate the TDE protector every 90 days, and Azure SQL Database will automatically use the new key version for new encryption operations without downtime or application changes. This satisfies the rotation requirement with a fully managed, auditable process that is aligned to Azure's native capabilities.

Why this answer

Transparent Data Encryption (TDE) with customer-managed keys (CMK) in Azure Key Vault meets the requirement for encrypting data at rest in Azure SQL Database using a key controlled by the customer. Azure Key Vault supports automatic key rotation policies that can be set to rotate the key every 90 days, satisfying the rotation requirement without manual intervention or application code changes.

Exam trap

The trap here is confusing data-at-rest encryption (TDE) with column-level encryption (Always Encrypted or cell-level encryption), leading candidates to pick options that encrypt only specific columns or require application changes, rather than the simpler, database-wide TDE approach with automatic key rotation in Key Vault.

How to eliminate wrong answers

Option A is wrong because cell-level encryption (e.g., Always Encrypted) encrypts individual columns, not the entire database at rest, and requires manual key rotation or application code changes, not automatic rotation via Key Vault policy. Option B is wrong because TDE with service-managed keys uses keys managed by Microsoft, not customer-managed keys, so it fails the requirement for customer-controlled keys. Option D is wrong because Always Encrypted encrypts data at the column level and requires application code changes for key rotation, whereas the requirement specifies data at rest in the database (TDE) and automatic rotation without application modifications.

447
MCQeasy

Your organization uses Microsoft Sentinel and has enabled User and Entity Behavior Analytics (UEBA). The security team receives an alert for a user who has failed authentication 10 times in 5 minutes. What should you configure to reduce false positives while ensuring legitimate brute-force attacks are still detected?

A.Customize the anomaly threshold in UEBA
B.Disable UEBA for that user
C.Modify the analytics rule that triggered the alert
D.Create a playbook to auto-acknowledge the alert
AnswerA

Customizing the anomaly threshold in UEBA is the correct approach because UEBA uses machine learning models that assign anomaly scores to user behaviors, and these models expose threshold and sensitivity settings you can tune. By adjusting the sensitivity, you directly influence the score required to trigger an alert, effectively filtering out low-confidence anomalies that cause false positives while still detecting genuinely suspicious activity. This is the intended, documented method for reducing noise from UEBA-detected behaviors without sacrificing the underlying behavioral analytics capability.

Why this answer

Customizing the anomaly threshold in UEBA allows you to adjust the sensitivity of the behavioral baseline, reducing false positives for users who legitimately fail authentication multiple times while still detecting true brute-force attacks. UEBA learns normal behavior patterns and flags deviations; by raising the threshold, you require a higher deviation from the baseline before an alert fires, preserving detection of actual attacks.

Exam trap

The trap here is that candidates assume modifying the analytics rule (Option C) is the correct tuning mechanism, but UEBA-specific thresholds are configured separately from the underlying analytics rule, and adjusting the rule itself would affect all users and all detection logic, not just the behavioral anomaly component.

How to eliminate wrong answers

Option B is wrong because disabling UEBA for that user would stop all behavioral analytics for that user, preventing detection of any future anomalous activity, including legitimate brute-force attacks. Option C is wrong because modifying the analytics rule that triggered the alert would change the detection logic for all users, potentially missing real attacks or increasing noise across the board, rather than tuning the behavioral sensitivity for this specific pattern. Option D is wrong because creating a playbook to auto-acknowledge the alert does not reduce false positives; it merely automates ignoring the alert, which could cause a real brute-force attack to be overlooked.

448
Multi-Selectmedium

Which THREE are valid sources for ingesting data into Microsoft Sentinel? (Choose three.)

Select 3 answers
A.AWS CloudTrail
B.Microsoft 365 Defender
C.Adobe Analytics
D.Azure Activity log
E.Google BigQuery
AnswersA, B, D

AWS CloudTrail is a valid source because Microsoft Sentinel provides a native data connector that ingests CloudTrail management and data plane logs. By leveraging an S3 bucket and an SQS queue, Sentinel pulls API activity from AWS, allowing security teams to detect misconfigurations, credential abuse, and unauthorized access across AWS accounts.

Why this answer

AWS CloudTrail is a valid data source for Microsoft Sentinel because Sentinel supports ingesting AWS service logs via the AWS CloudTrail data connector. This connector uses the AWS S3 bucket to collect CloudTrail logs, which are then pulled into Sentinel for analysis. This allows organizations to monitor and detect threats across their AWS environment alongside other cloud and on-premises data sources.

Exam trap

The trap here is that candidates may assume any popular cloud service (like Adobe Analytics or Google BigQuery) can be a data source for Sentinel, but Microsoft only provides built-in connectors for specific security-relevant sources, and these two are not among them.

449
MCQhard

Refer to the exhibit. You run the PowerShell script to protect high-confidentiality resources. After execution, you find that some resources with tag 'Confidentiality=High' are still unprotected. What is the most likely reason?

A.Some resources are in a different resource group than expected.
B.The script does not check for existing locks properly.
C.Tags are not inherited from resource groups.
D.The script overwrites existing locks.
AnswerA

When the script enumerates Azure resources, it derives the target resource group from the `ResourceGroupName` property of each resource object. This property is accurate for resources inside a resource group, but some resources (e.g., subscription-level policy or role assignments) return a null value, and if the script falls back to a variable or default group, those resources are processed against the wrong resource group. As a result, the lock is created on a scope that does not match the actual resource, leaving the resource unprotected. This is the root cause that also makes the existence-check behavior misleading.

Why this answer

The correct answer is A: some resources are in a different resource group than expected. If the PowerShell script scopes its protection (for example, applying locks or policies) to a specific resource group, any resource tagged 'Confidentiality=High' that resides in another resource group is outside the script's scope and remains unprotected, which matches the symptom of some tagged resources still being unprotected. Option B is not the likely cause because the failure is about scope, not lock-detection logic.

Option C is incorrect because tag inheritance from resource groups is not the issue here—the resources already carry the tag. Option D is irrelevant because overwriting existing locks would not leave tagged resources unprotected.

450
MCQmedium

Your company is deploying Microsoft Intune for mobile device management. You need to ensure that corporate data on personally owned devices is protected without affecting the user's personal data. Which Intune feature should you use?

A.Device compliance policies
B.Conditional Access for app control
C.Windows Autopilot
D.App Protection Policies (MAM)
AnswerD

App Protection Policies (MAM) are specifically designed to protect corporate data within applications without requiring the device to be enrolled in device management. They enforce data-loss prevention (DLP) rules like PIN enforcement, data encryption, restrict cut/copy/paste, and prevent saving corporate data to personal stores. In a BYOD scenario, MAM policies apply to managed apps (e.g., Outlook, Word) and ensure that corporate data is contained, regardless of the device's management state, which directly matches the scenario of securing data on personal mobile devices.

Why this answer

App Protection Policies (MAM) are the correct choice because they allow you to manage and protect corporate data within applications on personally owned devices without requiring device enrollment. This ensures that corporate data is encrypted, can be selectively wiped, and is prevented from being copied to personal apps, while leaving the user's personal data untouched.

Exam trap

The trap here is that candidates often confuse Conditional Access (which controls access to resources) with App Protection Policies (which protect data within apps), leading them to select Conditional Access for app control when the question specifically asks about protecting corporate data without affecting personal data.

How to eliminate wrong answers

Option A is wrong because Device Compliance Policies evaluate the security configuration of the entire device (e.g., jailbreak detection, encryption status) and require the device to be enrolled in Intune, which would give the organization visibility and control over the entire device, affecting personal data. Option B is wrong because Conditional Access for app control (e.g., using Azure AD Conditional Access with app-based policies) can restrict access based on app-level conditions but does not provide the granular data protection and selective wipe capabilities that MAM offers for corporate data within apps. Option C is wrong because Windows Autopilot is a device provisioning and deployment tool for Windows devices, not a mobile device management feature for protecting corporate data on personally owned devices.

Page 5

Page 6 of 9

Page 7

All pages