Courseiva

Microsoft Cybersecurity Architect (SC-100) — Questions 451–525

605 questions total · 9pages · All types, answers revealed

Page 6

Page 7 of 9

Page 8
451
MCQhard

Your company uses Microsoft Purview to manage data governance. You need to create a data classification rule that scans Azure Data Lake Storage for personally identifiable information (PII) such as email addresses. The rule must also apply a sensitivity label automatically. Which approach should you use?

A.Create an Azure Policy to detect and label PII.
B.Create a custom scan rule in Microsoft Purview and configure auto-labeling.
C.Use a Power Automate flow to scan files and apply labels.
D.Use Microsoft Defender for Cloud to scan for PII.
AnswerB

Microsoft Purview provides native scanning that discovers data assets across on-premises and cloud sources, and you can define custom classification rules using regex or keyword patterns to identify PII such as SSNs or credit card numbers. Once the scan classifies content, Purview's auto-labeling automatically applies Microsoft 365 sensitivity labels to the assets based on the custom rule's classifier, enabling consistent data governance and protection. This directly matches the requirement to detect and label PII.

Why this answer

The correct option is B: create a custom scan rule in Microsoft Purview and configure auto-labeling. Microsoft Purview is the data governance service that supports scanning Azure Data Lake Storage with custom classification rules (using regex or dictionaries) to detect PII such as email addresses, and its auto-labeling policies can then apply sensitivity labels automatically to matching content. Option A is wrong because Azure Policy enforces resource configuration and compliance, not content-level PII detection or sensitivity labeling.

Option C is wrong because Power Automate is a workflow automation tool and does not provide Purview's built-in classification scanning for Data Lake Storage. Option D is wrong because Microsoft Defender for Cloud focuses on security posture and threat protection, not data classification or sensitivity labeling.

452
MCQmedium

A retail company is designing a security operations model in Microsoft Sentinel. The security team wants to detect suspicious activity in Microsoft Entra ID, including sign-ins from unfamiliar locations and changes to privileged roles, and they want the detections to be based on Microsoft's continuously updated threat intelligence rather than custom queries. Which Microsoft Sentinel feature should you recommend?

A.A threat intelligence platform connector that ingests indicators of compromise
B.A watchlist that contains the company's list of privileged role assignments
C.Custom analytics rules written with Kusto Query Language against the SigninLogs table
D.Microsoft Sentinel solutions for Microsoft Entra ID that include analytics rule templates
AnswerD

Solutions in the Microsoft Sentinel content hub package data connectors, analytics rule templates, workbooks, and playbooks for a specific domain such as Microsoft Entra ID. The analytics rule templates cover identity scenarios like unfamiliar sign-in locations and privileged role changes, and they are maintained by Microsoft, so the team gets up-to-date detections without authoring custom queries.

Why this answer

The requirement is for Microsoft-maintained, continuously updated identity detections rather than custom logic. Solutions in the Microsoft Sentinel content hub deliver connectors, analytics rule templates, and other artifacts for domains such as Microsoft Entra ID, and the templates cover the described identity scenarios. Custom rules, threat intelligence connectors, and watchlists are supporting components, not the source of maintained detections.

Exam trap

The trap here is assuming a threat intelligence connector or a watchlist provides detection logic, when those supply enrichment data that analytics rules must consume.

453
MCQmedium

A company is using Microsoft Intune to manage devices. They need to ensure that only devices with a specific operating system version can access corporate resources. Which Intune policy should they use?

A.App protection policy
B.Enrollment restriction
C.Compliance policy
D.Device configuration policy
AnswerC

A compliance policy evaluates device attributes against defined rules, including a minimum OS version, and marks the device compliant or non-compliant. Conditional Access then blocks resource access for non-compliant devices, directly satisfying the requirement that only devices running the specified OS version reach corporate resources.

Why this answer

Compliance policies in Microsoft Intune define the rules that devices must meet to be considered compliant, such as requiring a specific operating system version. When a device is marked non-compliant, Conditional Access policies can block access to corporate resources. This directly enforces the requirement that only devices with the correct OS version can access company data.

Exam trap

The trap here is confusing the purpose of Compliance policies (which enforce ongoing access rules based on device health) with Enrollment restrictions (which only gate initial enrollment) or Device configuration policies (which apply settings but do not evaluate compliance).

How to eliminate wrong answers

Option A is wrong because App protection policies (MAM) manage how apps handle data (e.g., preventing copy/paste) and do not enforce device-level OS version requirements. Option B is wrong because Enrollment restrictions control which devices can enroll in Intune (e.g., by platform or manufacturer) but do not enforce ongoing compliance with OS version after enrollment. Option D is wrong because Device configuration policies push settings (e.g., Wi-Fi, VPN, certificates) to devices but do not evaluate or enforce OS version compliance; they are not used for access control decisions.

454
MCQhard

You are designing a solution to securely store and manage secrets for a cloud-native application deployed on Azure Kubernetes Service (AKS). The application needs to retrieve database connection strings and API keys at runtime without hardcoding them. The solution must minimize administrative overhead and integrate with Azure Active Directory (now Microsoft Entra ID) for access control. Which service should you use?

A.Kubernetes Secrets
B.HashiCorp Vault on AKS
C.Azure Key Vault with managed identities
D.Azure App Configuration
AnswerC

Azure Key Vault stores secrets centrally, and managed identities give the AKS workload a Microsoft Entra ID-backed identity that authenticates to Key Vault without stored credentials. This removes secret rotation and credential management overhead while enforcing access control through Microsoft Entra ID.

Why this answer

Azure Key Vault with managed identities (option C) is correct because it provides a fully managed, cloud-native secrets store that integrates natively with Microsoft Entra ID, and managed identities let the AKS pods authenticate to Key Vault without storing credentials, minimizing administrative overhead. The application can retrieve database connection strings and API keys at runtime via the Key Vault SDK or the Secrets Store CSI Driver, so nothing is hardcoded. Kubernetes Secrets (A) are only base64-encoded and stored in etcd, lack Entra ID-based access control, and require manual rotation and RBAC management.

HashiCorp Vault on AKS (B) is powerful but self-managed, adding significant operational and administrative overhead. Azure App Configuration (D) is designed for application settings and feature flags, not for secure secret storage with Entra ID access control.

455
MCQeasy

You are designing a compliance solution for your organization that must enforce retention policies for documents stored in SharePoint Online. Which Microsoft Purview solution should you use?

A.Microsoft Purview Data Lifecycle Management
B.Microsoft Purview eDiscovery
C.Microsoft Purview Communication Compliance
D.Microsoft Purview Insider Risk Management
AnswerA

Data Lifecycle Management is the dedicated service for enforcing retention and deletion policies across Microsoft 365 workloads. It provides retention labels and policies that let you preserve content for a specified period, then automatically dispose of it, optionally with disposition review. This directly addresses compliance needs for record keeping, regulatory retention, and data minimization. Other services lack the policy-driven automation that DLM offers for lifecycle control.

Why this answer

Microsoft Purview Data Lifecycle Management (formerly Microsoft 365 Retention) is the correct solution because it is specifically designed to enforce retention policies for documents in SharePoint Online. It allows you to apply retention labels and policies that automatically retain or delete content based on compliance requirements, without user intervention.

Exam trap

The trap here is that candidates often confuse 'retention' with 'eDiscovery holds' or 'compliance monitoring,' leading them to select eDiscovery or Communication Compliance, but Data Lifecycle Management is the only solution that directly enforces retention schedules for content in SharePoint Online.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview eDiscovery is used for searching, holding, and exporting content for legal or investigative purposes, not for enforcing retention policies. Option C is wrong because Microsoft Purview Communication Compliance is designed to detect and manage inappropriate communications (e.g., harassment, sensitive info sharing), not to apply retention schedules. Option D is wrong because Microsoft Purview Insider Risk Management focuses on identifying and mitigating internal security risks (e.g., data theft, policy violations), not on lifecycle retention of documents.

456
Multi-Selecthard

Your organization uses Microsoft Intune for mobile device management. You need to configure a compliance policy for iOS devices that requires the device to be jailbreak-detected and have a minimum OS version. Which two settings should you configure in the compliance policy? (Choose two.)

Select 2 answers
A.Require passcode
B.Minimum OS version
C.Device encryption
D.Jailbreak detection
AnswersB, D

The Minimum OS version setting specifies the lowest operating system version a device must run to be considered compliant, such as iOS 16.0 or Windows 10, version 22H2. This rule directly enforces that devices are on a supported and permitted OS release, but it does not detect jailbreaks or root access—a device can be jailbroken while running a fully up-to-date OS. For the scenario described, this is the correct answer because it is the only option among those listed that explicitly checks the OS version level required by the policy.

Why this answer

B is correct because the compliance policy must specify a minimum OS version to ensure iOS devices meet the required security baseline, preventing outdated devices with known vulnerabilities from accessing corporate resources. D is correct because jailbreak detection is a specific compliance setting that identifies compromised devices, which are a significant security risk as they bypass iOS security controls.

Exam trap

The trap here is that candidates may confuse 'jailbreak detection' with 'device encryption' or 'passcode requirements,' but the question explicitly asks for the two settings that directly address jailbreak detection and minimum OS version, not general security settings.

457
MCQeasy

Your organization is implementing a zero-trust network strategy. You need to ensure that all network traffic between Azure virtual machines is encrypted and authenticated at the IP layer, regardless of the virtual network they are in. Which Azure feature should you configure?

A.Azure Service Endpoints
B.Azure VPN Gateway
C.Azure Private Link
D.Azure Virtual Network encryption
AnswerD

Azure Virtual Network encryption is the correct solution because it applies IPsec encryption to all traffic between virtual machines and virtual network scale sets in the same VNet and between peered VNets. It uses AES-256-GCM with per-flow session keys that are negotiated automatically, and it is enforced on the Azure hypervisor vSwitch, making it transparent to applications and operating systems. This directly fulfills the zero-trust principle of 'assume breach' by ensuring no VM-to-VM traffic travels in plaintext, even within the trusted network perimeter.

Why this answer

Azure Virtual Network encryption provides IPsec encryption for traffic between VMs within the same virtual network or peered virtual networks. Service endpoints use public IPs. Private Link is for accessing PaaS services privately.

VPN Gateway is for site-to-site.

458
MCQmedium

A company uses Microsoft Defender for Cloud to assess the security posture of their Azure subscriptions. They need to ensure that all resources are compliant with the Payment Card Industry Data Security Standard (PCI DSS). What should they do?

A.Create Azure Policy initiatives to enforce PCI DSS controls
B.Use Microsoft Purview to classify data and apply PCI DSS labels
C.Deploy Azure Blueprints that include PCI DSS policies
D.Enable the PCI DSS regulatory compliance standard in Microsoft Defender for Cloud
AnswerD

Microsoft Defender for Cloud includes built-in regulatory compliance standards, including PCI DSS 3.2.1 (and newer versions), directly under the 'Regulatory compliance' blade. When you enable the PCI DSS standard, Defender for Cloud automatically maps your Azure Policy and security configurations to the applicable PCI controls, provides a compliance score, and generates prioritized recommendations with remediation steps, all updated continuously as your environment changes.

Why this answer

Microsoft Defender for Cloud includes built-in regulatory compliance standards, such as PCI DSS, that can be enabled directly. Once enabled, Defender for Cloud continuously assesses your Azure subscriptions against the PCI DSS controls and provides a compliance score with detailed remediation steps. This is the simplest and most effective method to monitor compliance without creating custom policies or blueprints.

Exam trap

The trap here is that candidates often confuse Azure Policy or Blueprints as the primary tool for compliance assessment, when in fact Defender for Cloud's built-in regulatory compliance standards are the correct, out-of-the-box solution for monitoring against frameworks like PCI DSS.

How to eliminate wrong answers

Option A is wrong because Azure Policy initiatives enforce custom or built-in policies for resource configuration, but they do not natively map to PCI DSS controls; you would need to create or import a custom initiative, which is more complex and less accurate than using the built-in standard. Option B is wrong because Microsoft Purview is a data governance and classification service, not a compliance assessment tool for PCI DSS; it cannot evaluate resource configurations or provide a compliance score against PCI DSS. Option C is wrong because Azure Blueprints can include policies and resource templates, but they are used for deploying consistent environments, not for ongoing compliance assessment; the PCI DSS standard in Defender for Cloud already provides the necessary policy mappings and continuous monitoring.

459
MCQeasy

Your application uses Azure Key Vault to store secrets. You need to ensure that the application rotates secrets automatically without downtime. Which feature should you enable?

A.Key Vault automatic rotation with Event Grid integration
B.Key Vault manual rotation
C.Key Vault soft-delete
D.Key Vault RBAC
AnswerA

This solution enables near-real-time secret rotation by publishing events to Event Grid whenever a secret nears its expiration date or is updated, triggering an Azure Function or Logic App to generate a new secret version and update dependent applications. It removes human intervention, aligns with security best practices, and ensures business continuity with minimal downtime. The Event Grid integration supports both time-based and manual rotation triggers, making it the only option that fully automates the secret lifecycle.

Why this answer

Key Vault automatic rotation with Event Grid integration (option A) is correct because it lets Key Vault rotate secrets on a schedule and emit near-real-time events (e.g., Microsoft.KeyVault.SecretNewVersionCreated) that the application can subscribe to, so it can fetch the new secret version before the old one expires and avoid downtime. Manual rotation (option B) requires an operator to create new secret versions, which cannot guarantee timely, zero-downtime rotation. Soft-delete (option C) only retains deleted vaults/secrets for recovery and does not rotate anything.

RBAC (option D) governs authorization to Key Vault operations but provides no rotation mechanism.

460
MCQhard

Your organization uses Microsoft Sentinel and wants to reduce alert fatigue by grouping related alerts into incidents. Which configuration should you use?

A.Configure incident creation in the analytics rule properties
B.Use a workbook to aggregate alerts
C.Use a playbook to create incidents
D.Create an automation rule to group alerts
AnswerA

The analytics rule's 'Incident settings' tab (in the rule wizard or via API) controls whether alerts generated by that rule are automatically turned into incidents, and whether related alerts are grouped into a single incident based on entity or alert properties such as account, host, or IP. This is the correct and intended mechanism because incident creation and grouping are natively executed by the rule itself at alert generation time, ensuring the grouping logic is atomic with the rule's detection and does not require separate orchestration. To reduce noise, you set the rule to create incidents and choose an entity-based grouping key (e.g., 'Group alerts by entities into a single incident') or alert property, which Microsoft Sentinel then uses to merge correlated alerts into one incident before any automation or response.

Why this answer

In Microsoft Sentinel, incident creation is configured directly within the analytics rule properties. When you create or edit a scheduled or Microsoft Security analytics rule, the 'Incident settings' tab allows you to enable incident creation and define how alerts are grouped into incidents. This is the native mechanism for reducing alert fatigue by automatically grouping related alerts into a single incident based on criteria such as entity matching or time window.

Exam trap

The trap here is that candidates often confuse automation rules with incident grouping logic, assuming that automation rules can create or group incidents, when in fact automation rules only manage incidents after they are created by analytics rules.

How to eliminate wrong answers

Option B is wrong because workbooks in Microsoft Sentinel are visualization tools that display data from queries; they do not create or group incidents. Option C is wrong because playbooks are automated workflows triggered by incidents or alerts (using Azure Logic Apps) and can perform response actions, but they are not designed to initially group alerts into incidents; incident creation is a function of the analytics rule. Option D is wrong because automation rules in Sentinel are used to automate incident management tasks (e.g., assigning, tagging, or running playbooks) after an incident is created, not to group alerts into incidents at creation time.

461
MCQmedium

Your company is migrating on-premises Active Directory to Microsoft Entra ID. The security team requires that users must use passwordless authentication methods for all sign-ins. Which Microsoft Entra ID feature should you enable to support passwordless authentication?

A.Microsoft Entra ID passwordless authentication methods
B.Password hash synchronization
C.Seamless Single Sign-On (Seamless SSO)
D.Pass-through authentication
AnswerA

These methods replace the password with a device-bound cryptographic key (e.g., Windows Hello for Business, FIDO2 security keys) or a biometric gesture in the Microsoft Authenticator app. By requiring proof of possession and user presence, they eliminate the password secret entirely and are inherently phishing-resistant, which aligns with the passwordless goal of the migration.

Why this answer

Microsoft Entra ID passwordless authentication methods (such as Windows Hello for Business, FIDO2 security keys, and Microsoft Authenticator) are the native features designed to eliminate passwords entirely. These methods satisfy the security team's requirement by enabling users to sign in without a password, using biometrics or cryptographic keys instead.

Exam trap

The trap here is that candidates often confuse 'passwordless authentication' with features that reduce password usage (like Seamless SSO or PHS) rather than understanding that only the dedicated passwordless methods in Entra ID actually remove the password requirement entirely.

How to eliminate wrong answers

Option B is wrong because Password hash synchronization (PHS) synchronizes password hashes from on-premises AD to Entra ID for authentication, but it does not enable passwordless methods; it still relies on passwords. Option C is wrong because Seamless SSO provides automatic sign-in when users are on domain-joined devices connected to the corporate network, but it does not eliminate the need for passwords—it just skips the password prompt in certain scenarios. Option D is wrong because Pass-through authentication (PTA) validates passwords directly against on-premises AD, but it still requires a password to be entered and does not support passwordless authentication.

462
MCQeasy

Your organization uses Microsoft Defender for Cloud to assess the security posture of Azure resources. The security team wants to ensure that all virtual machines are covered by Defender for Cloud's vulnerability assessment capabilities. Which plan must be enabled?

A.Microsoft Defender for Storage
B.Microsoft Defender for Servers Plan 2
C.Microsoft Defender for Cloud Apps
D.Defender Cloud Security Posture Management (CSPM)
AnswerB

Microsoft Defender for Servers Plan 2 is the correct selection because it includes the Microsoft Defender Vulnerability Management add-on, which uses an agent (or agentless integration) to continuously scan VM operating systems and installed applications for known CVEs and misconfigurations. The scan results flow directly into Defender for Cloud's security recommendations, and findings are prioritized using real-world threat intelligence and exploit-maturity information. This makes Plan 2 the only option among the choices that provides a dedicated, integrated VM vulnerability assessment capability.

Why this answer

Microsoft Defender for Servers Plan 2 is the correct choice because it is the Defender for Cloud plan that includes built-in vulnerability assessment for Azure and hybrid virtual machines, using the integrated Microsoft Defender Vulnerability Management scanner. Enabling this plan on the subscription ensures VMs receive agentless or agent-based vulnerability scanning and findings surface in Defender for Cloud's recommendations. Microsoft Defender for Storage protects storage accounts, not VMs, so it does not provide VM vulnerability assessment.

Microsoft Defender for Cloud Apps is a CASB solution for SaaS application visibility and control, and Defender CSPM provides posture management and attack path analysis but not the VM vulnerability assessment capability itself.

463
MCQhard

You are the security architect for a company that has a hybrid identity infrastructure with Microsoft Entra ID (formerly Azure AD) and an on-premises Active Directory Domain Services (AD DS) forest. The company is planning to migrate several line-of-business (LOB) applications to Azure Virtual Machines. The applications currently use Windows Integrated Authentication (WIA) and rely on Kerberos delegation. You need to design a solution that allows the Azure VMs to authenticate on-premises users and access on-premises resources using Kerberos constrained delegation (KCD) without exposing on-premises-domain controllers to the internet. The solution must minimize latency and administrative overhead. You have configured Azure ExpressRoute for connectivity between the on-premises network and Azure. What should you do?

A.Deploy domain controllers as Azure VMs in the same virtual network as the application VMs. Configure the application VMs to use these domain controllers for authentication and KCD.
B.Implement Azure AD Application Proxy to publish the applications and use Azure AD for authentication.
C.Use Azure AD Domain Services to provide domain join and KCD capabilities for the Azure VMs.
D.Configure the application VMs to use the on-premises domain controllers over ExpressRoute for authentication and KCD.
AnswerA

Deploying domain controllers as Azure VMs in the same virtual network as the application VMs provides a low-latency and fully compatible Active Directory presence for authentication and Kerberos Constrained Delegation (KCD). These Azure-based domain controllers are full replicas of the on-premises domain, so they can issue Kerberos tickets, perform KCD with protocol transition, and handle all directory operations exactly like on-premises DCs, satisfying stringent application requirements. Because the DCs reside in the same virtual network, authentication traffic never traverses the WAN, reducing latency and avoiding timeouts; this design also prevents direct exposure of on-premises domain controllers to Azure or internet traffic while maintaining identity consistency through Active Directory replication over ExpressRoute or S2S VPN. This is the recommended pattern for hybrid applications that require fast, full-featured directory access and KCD.

Why this answer

Option A is correct because deploying replica domain controllers as Azure VMs in the same virtual network as the application VMs keeps Kerberos authentication and KCD traffic local to Azure, minimizing latency while avoiding any internet exposure of on-premises domain controllers; the VMs join the on-premises AD DS domain and use these in-Azure DCs for authentication and delegation. Option D would work functionally over ExpressRoute but adds WAN latency and dependency on the on-premises DCs for every Kerberos exchange, so it does not minimize latency. Option C is wrong because Microsoft Entra Domain Services (Azure AD DS) is a managed domain that does not support Kerberos constrained delegation to on-premises resources or joining an existing on-premises AD DS forest.

Option B is wrong because Azure AD Application Proxy publishes web apps for remote access and uses Entra ID authentication, which does not provide Kerberos KCD for LOB applications running on Azure VMs.

464
MCQhard

Your company uses Azure Firewall to filter outbound traffic from a virtual network. You need to allow only HTTP and HTTPS traffic to specific FQDNs, while blocking all other outbound traffic. Which Azure Firewall rule type should you use?

A.NAT rule
B.Application rule
C.Threat intelligence rule
D.Network rule
AnswerB

Application rules filter outbound traffic by FQDN and HTTP/HTTPS protocol, satisfying the requirement to permit only those destinations while denying everything else. Network rules cannot inspect FQDN-based HTTP/HTTPS traffic, as they operate at IP and port level, so they cannot meet the FQDN constraint.

Why this answer

Application rules in Azure Firewall allow filtering outbound traffic based on fully qualified domain names (FQDNs) for HTTP and HTTPS protocols. Option A is wrong because NAT rules only perform destination network address translation, not FQDN filtering. Option C is wrong because threat intelligence rules are used to block traffic from known malicious IP addresses, not for allowing FQDNs.

Option D is wrong because network rules filter traffic based on IP addresses, ports, and protocols, not FQDNs.

465
MCQhard

Your organization is deploying Microsoft Copilot for Security and wants to ensure that the AI model does not expose sensitive data in its responses. You need to configure data loss prevention (DLP) policies that apply to Copilot interactions. Which Microsoft Purview capability should you use?

A.eDiscovery
B.Data Loss Prevention policies
C.Information Protection and sensitivity labels
D.Communication Compliance
AnswerB

DLP policies in Microsoft Purview inspect prompts and responses during Copilot interactions, detecting sensitive information types and blocking or auditing exposure. This directly satisfies the requirement to prevent sensitive data appearing in AI-generated responses, since the policy evaluates content at the interaction layer rather than relying on model training.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies for Copilot are designed to prevent sensitive data from being exposed in AI interactions. These policies can scan prompts and responses for sensitive information and take actions like blocking or alerting. Communication Compliance (Option D) is intended for monitoring communications, such as emails and Teams messages, but not specifically for DLP in AI interactions.

Therefore, DLP policies are the correct capability for this requirement.

Exam trap

The trap is that candidates may confuse Communication Compliance as the DLP solution for Copilot, but Microsoft has specifically extended DLP policies to cover Copilot interactions, making standard DLP policies the correct choice.

How to eliminate wrong answers

Option A is wrong because eDiscovery is used for legal and investigative searches of content across Microsoft 365, not for real-time data loss prevention in AI interactions. Option B is wrong because standard Data Loss Prevention policies apply to traditional data-at-rest and data-in-transit scenarios (e.g., email, SharePoint), but they do not natively extend to Copilot for Security interactions without Communication Compliance integration. Option C is wrong because Information Protection and sensitivity labels classify and protect data through encryption and labeling, but they do not provide the real-time scanning and policy enforcement needed to prevent sensitive data exposure in Copilot responses.

466
Multi-Selectmedium

Your organization uses Microsoft Purview to comply with regulatory requirements. Which TWO features should you use to manage data retention and deletion?

Select 2 answers
A.Data lifecycle management policies (retention policies).
B.Sensitivity labels.
C.Records management (retention labels and disposition).
D.Data Loss Prevention (DLP) policies.
E.Trainable classifiers.
AnswersA, C

Data lifecycle management policies in Microsoft Purview (formerly Microsoft 365 compliance retention policies) let you automatically retain and then delete content across Exchange, SharePoint, OneDrive, and Teams based on age, event, or location. These policies are organization-wide or scoped via adaptive scopes, and they run continuously without user intervention, providing a primary mechanism to meet regulatory retention requirements. They manage the entire lifecycle from retention to expiration, making them the correct choice for broad compliance mandates.

Why this answer

Data lifecycle management policies (retention policies) (A) are correct because they let you centrally define how long content is kept and when it is deleted across Exchange, SharePoint, OneDrive, Teams, and other workloads, satisfying regulatory retention and deletion requirements. Records management (retention labels and disposition) (C) is also correct because it uses retention labels with file plan descriptors, event-based retention, and disposition review to declare items as records and control their deletion with proof of disposition. Sensitivity labels (B) are for classification and protection (encryption, marking, access control), not for retention or deletion timing.

Data Loss Prevention (D) policies detect and block risky sharing of sensitive data but do not govern retention periods or deletion. Trainable classifiers (E) identify content types to support classification and labeling, but they do not themselves manage retention or deletion.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which handle classification and protection) with retention labels (which handle retention and deletion), leading them to incorrectly select sensitivity labels as a retention feature.

467
MCQhard

You are analyzing a custom detection rule in Microsoft 365 Defender. Based on the exhibit, what is a potential operational issue with this rule?

A.The threshold is too low, leading to alert fatigue.
B.The query syntax is invalid.
C.The severity should be Medium instead of High.
D.The rule does not cover PowerShell 7 (pwsh.exe).
AnswerA

A threshold of 5 events in a day, combined with a High severity rating and a rule that matches common PowerShell processes, will produce a large number of alerts from benign administrative and scripting activity. This overwhelms the SOC with low-fidelity alerts, desensitizing analysts to genuinely malicious signals and increasing the risk that a true positive is buried in the noise. The fundamental problem is the low threshold causing alert fatigue, not a technical defect in the query.

Why this answer

Option A is correct because a custom detection rule whose threshold is set too low will trigger on very few or even a single event, generating excessive alerts that overwhelm analysts with false positives and cause alert fatigue. In Microsoft 365 Defender custom detections, the threshold (aggregation) value controls how many events must occur within the query's timeframe before an alert fires, so setting it too low directly increases alert volume. Option B is incorrect because the scenario asks about an operational issue, not a syntax error, and the exhibit implies the query runs.

Option C is incorrect because severity is a triage preference, not an operational defect, and changing High to Medium would not fix alert volume. Option D is incorrect because PowerShell 7 coverage depends on the query's data source and process filters, not on the threshold, and the scenario does not indicate pwsh.exe is relevant.

468
MCQhard

You are designing a secure solution for an Azure Kubernetes Service (AKS) cluster that hosts a critical application. You need to ensure that pods can only communicate with specific back-end services and that traffic is encrypted. What should you implement?

A.Implement Kubernetes network policies and enable mTLS using a service mesh like Istio or Linkerd.
B.Use network security groups (NSGs) on the subnet.
C.Configure Azure Application Gateway Ingress Controller.
D.Deploy Azure Firewall and configure application rules.
AnswerA

Kubernetes NetworkPolicies are the native, CNI-backed mechanism for enforcing pod-level segmentation by filtering traffic based on labels, namespaces, and ports at L3/L4. Adding a service mesh like Istio or Linkerd enables mTLS, which authenticates workload identities and encrypts east-west traffic, giving defense-in-depth for both authorization and confidentiality. This pairing is the only option that directly governs pod-to-pod communication inside the cluster, adapting dynamically to ephemeral pod IPs.

Why this answer

Kubernetes network policies allow you to restrict pod-to-pod communication to specific back-end services, and mutual TLS (mTLS) from a service mesh like Istio or Linkerd encrypts the traffic. Option B is incorrect because network security groups (NSGs) operate at the subnet level and cannot enforce pod-level network policies. Option C is incorrect because Azure Application Gateway Ingress Controller handles inbound traffic from outside the cluster, not pod-to-pod communication.

Option D is incorrect because Azure Firewall controls north-south traffic (ingress/egress) and does not manage east-west traffic between pods.

469
MCQmedium

Refer to the exhibit. A security architect is reviewing an Azure Policy definition. What is the effect of this policy?

A.Modifies storage accounts to enable HTTPS traffic only
B.Audits storage accounts that do not require HTTPS traffic
C.Denies creation or update of storage accounts that do not require HTTPS traffic
D.Deploys a remediation task to enable HTTPS traffic only
AnswerC

The 'deny' effect is the correct behavior for this policy definition. When a request to create or update a storage account arrives at Azure Resource Manager, the policy engine checks whether the property 'supportsHttpsTrafficOnly' is set to 'true'. If the property is false or omitted, the entire create or update operation is rejected with a policy violation error. This ensures that no new or updated storage account can be deployed without requiring HTTPS traffic, providing a strong security control.

Why this answer

The correct answer is C: the policy denies creation or update of storage accounts that do not require HTTPS traffic. In Azure Policy, a Deny effect blocks the request at the resource provider during create or update operations when the resource does not satisfy the condition, so a storage account with supportsHttpsTrafficOnly set to false would be rejected. Option A is incorrect because Modify effects change properties via remediation and do not block the request.

Option B is incorrect because Audit only records non-compliance without preventing deployment. Option D is incorrect because DeployIfNotExists remediation tasks are triggered after evaluation and do not deny the original request.

470
Multi-Selecthard

Your organization is implementing Microsoft Entra ID governance. Which THREE capabilities should you include to manage the identity lifecycle and access reviews?

Select 3 answers
A.Microsoft Entra Identity Protection.
B.Microsoft Entra Access Reviews.
C.Microsoft Entra Entitlement Management.
D.Microsoft Entra Lifecycle Workflows.
E.Privileged Identity Management (PIM).
AnswersB, C, D

Access Reviews allow an administrator to create recurring review scopes covering group memberships, application assignments, and role assignments, where designated reviewers attest whether each user's access remains necessary. Once a cycle completes, the reviewer's decisions can be applied automatically to remove access that was denied, and the entire history is stored to demonstrate compliance with internal and regulatory standards. This is the purpose-built mechanism for periodic access certification.

Why this answer

Microsoft Entra Access Reviews (B) is correct because it lets reviewers periodically attest to users' group memberships, application assignments, and role assignments, which is the core mechanism for recertifying access in an identity governance program. Microsoft Entra Entitlement Management (C) is correct because access packages, catalogs, and connected organizations automate the request, approval, and assignment of resource bundles, including external user lifecycle, which is central to governing access at scale. Microsoft Entra Lifecycle Workflows (D) is correct because it automates joiner, mover, and leaver tasks such as generating Temporary Access Passes, assigning licenses, and disabling accounts based on HR events, directly addressing identity lifecycle management.

Microsoft Entra Identity Protection (A) is not included because it detects and remediates identity-based risks like risky sign-ins and compromised credentials rather than managing lifecycle or access reviews. Privileged Identity Management (E) is not included because it focuses on just-in-time privileged role activation and approval, which is privileged access management rather than the lifecycle and review capabilities the scenario asks for.

471
MCQhard

An organization uses Microsoft Defender for Cloud to secure their multi-cloud environment, including Azure and AWS. They want to ensure that all AWS EC2 instances are automatically onboarded to Defender for Cloud. What should they configure?

A.Deploy Azure Arc on each EC2 instance
B.Use AWS Systems Manager to push Defender workload
C.Set up the AWS connector in Defender for Cloud
D.Configure AWS Config rules to report to Defender
AnswerC

Setting up the AWS connector in Microsoft Defender for Cloud is the correct action because the connector uses an AWS cross-account IAM role to automatically discover and monitor EC2 instances along with other AWS resources, bringing them into Defender’s Cloud Security Posture Management (CSPM) and workload protection plans. Once connected, Defender can apply Azure Policy-based recommendations, integration with Azure Arc for hybrid management, and threat detection without needing to manually install anything on each instance.

Why this answer

The AWS connector in Microsoft Defender for Cloud is the native integration that enables automatic discovery and onboarding of AWS resources, including EC2 instances, into Defender for Cloud. Once configured, the connector uses AWS IAM roles and APIs to continuously sync EC2 inventory and apply Defender plans (e.g., Defender for Servers) without requiring manual agent installation on each instance.

Exam trap

The trap here is that candidates confuse the AWS connector (a cloud-to-cloud integration) with Azure Arc (a hybrid management tool), assuming Arc is required for any non-Azure workload, when in fact the connector handles automatic onboarding without per-instance configuration.

How to eliminate wrong answers

Option A is wrong because deploying Azure Arc on each EC2 instance is an alternative method for managing non-Azure servers, but it is not the automatic onboarding mechanism for Defender for Cloud; it requires manual installation and does not leverage the native AWS connector. Option B is wrong because AWS Systems Manager is an AWS-native management service and cannot directly push Defender workloads; Defender for Cloud relies on its own agents (e.g., Azure Monitor Agent or Microsoft Defender for Endpoint) deployed via the AWS connector integration, not via Systems Manager. Option D is wrong because AWS Config rules are used for compliance auditing and resource configuration tracking, not for onboarding EC2 instances to Defender for Cloud; they lack the capability to install security agents or enable Defender plans.

472
MCQhard

Your organization is migrating to Microsoft 365 and wants to implement a data classification strategy. The compliance team needs to automatically detect and label documents containing personal data (e.g., Social Security numbers) in SharePoint Online. Which Microsoft Purview solution should you use?

A.Auto-labeling policies
B.Records Management
C.eDiscovery
D.Data Loss Prevention policies
AnswerA

Auto-labeling policies in Microsoft Purview scan SharePoint Online content using sensitive information types, such as Social Security numbers, and apply sensitivity labels automatically without user input. This satisfies the compliance team's requirement for automatic detection and labelling of personal data at scale.

Why this answer

Auto-labeling policies in Microsoft Purview are designed to automatically detect sensitive data types (e.g., Social Security numbers) using built-in or custom sensitive information types and apply sensitivity labels to documents in SharePoint Online. This meets the requirement for automatic detection and labeling without user intervention, as the compliance team needs.

Exam trap

The trap here is confusing Data Loss Prevention (DLP) policies with auto-labeling policies, as both can detect sensitive data, but DLP policies enforce protective actions (block/alert) while auto-labeling policies apply sensitivity labels for classification and downstream protection.

How to eliminate wrong answers

Option B (Records Management) is wrong because it focuses on managing retention and disposition of content, not on automatic detection and labeling of sensitive data. Option C (eDiscovery) is wrong because it is used for searching and exporting content for legal or investigative purposes, not for applying classification labels. Option D (Data Loss Prevention policies) is wrong because DLP policies are designed to prevent unauthorized sharing or leakage of sensitive data by blocking or alerting on activities, not to automatically apply sensitivity labels to documents at rest.

473
Multi-Selectmedium

Your organization is implementing Microsoft Entra ID Governance. You need to design a solution that automates user access reviews for cloud applications. Which TWO capabilities should you include?

Select 2 answers
A.Identity Protection
B.Entitlement Management with access packages
C.Terms of Use
D.Access Reviews
E.Privileged Identity Management (PIM)
AnswersB, D

Entitlement Management access packages group cloud applications, groups, and SharePoint sites into catalogs with request policies, approval chains, assignment durations, and optional recurring review stages. By attaching an access review policy to an access package, the organization automates both the initial grant and the periodic recertification: when a reviewer marks a user as denied, the user's assignments are automatically removed from all resources in the package. This lifecycle-centric design directly satisfies the requirement to automate recurring user access reviews for cloud applications in Microsoft Entra ID Governance.

Why this answer

Access Reviews (D) is correct because it is the Microsoft Entra ID Governance capability specifically designed to automate periodic reviews of users' group memberships, application assignments, and role assignments, allowing reviewers to attest to continued access and automatically remove access when reviewers deny it or don't respond. Entitlement Management with access packages (B) is correct because access packages bundle resources such as cloud applications, groups, and SharePoint sites, and they support mandatory access reviews and expiration policies that automate the access lifecycle for cloud applications. Identity Protection (A) is not correct because it detects and remediates identity risk signals like risky sign-ins and compromised credentials, not access attestation workflows.

Terms of Use (C) is not correct because it presents legal disclaimers that users must accept before accessing resources, which is a consent mechanism rather than an access review. Privileged Identity Management (E) is not correct because PIM governs just-in-time activation and approval of privileged directory and Azure roles, not recurring reviews of general cloud application access.

474
Drag & Dropmedium

Order the steps to troubleshoot an Azure VPN gateway connection failure.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Troubleshooting starts with Azure side, then on-premises, and may require reset.

475
MCQeasy

Your company plans to migrate on-premises servers to Azure. You need to ensure that the migrated servers are protected against malware and vulnerabilities. Which Microsoft Defender for Cloud plan should you enable for the Azure VMs?

A.Microsoft Defender for SQL
B.Microsoft Defender for Storage
C.Microsoft Defender for Containers
D.Microsoft Defender for Servers
AnswerD

Microsoft Defender for Servers is the correct plan because it is purpose-built for protecting Azure virtual machines and on-premises servers via Azure Arc, directly aligning with the migration of on-premises servers to Azure. It provides integrated Microsoft Defender for Endpoint for endpoint detection and response, malware scanning, vulnerability management, file integrity monitoring, and Just-in-Time (JIT) access controls. This comprehensive coverage ensures the migrated VMs maintain continuous security monitoring and threat protection across their entire workload.

Why this answer

Microsoft Defender for Servers (option D) is the correct choice because it is the Defender for Cloud plan specifically designed to protect Azure VMs and on-premises servers, providing threat detection, vulnerability assessment, and malware protection through integration with Microsoft Defender for Endpoint. It covers server workloads regardless of whether they run in Azure, other clouds, or on-premises, which matches the migration scenario. The other options target different resource types: Defender for SQL (A) protects Azure SQL and SQL Server workloads, Defender for Storage (B) protects Azure Storage accounts against threats like malware uploads and data exfiltration, and Defender for Containers (C) protects Kubernetes clusters and container registries, none of which address VM-level malware and vulnerability protection.

476
MCQmedium

A company uses Azure Arc to manage on-premises servers. The security team wants to enforce that all servers (on-premises and Azure) have Microsoft Defender for Endpoint installed and running. Which solution should you use to ensure compliance across hybrid environments?

A.Microsoft Intune
B.Azure Policy with Guest Configuration
C.Azure Update Manager
D.Microsoft Defender for Cloud
AnswerB

Azure Policy with Guest Configuration is the correct choice because it brings Azure's policy engine inside the guest OS of Arc-connected servers via the Azure Connected Machine agent. It can audit and enforce settings such as installed applications, Windows security baselines, and registry keys, evaluating compliance continuously as part of Azure Policy. The DeployIfNotExists effect can automatically remediate non-compliant configuration, making it the only listed option that both audits and enforces configurations on hybrid servers.

Why this answer

Azure Policy with Guest Configuration is the correct choice because it extends Azure Policy's audit and enforcement capabilities into the operating system of both Azure VMs and Azure Arc-enabled on-premises servers, allowing you to audit and enforce settings such as whether the Microsoft Defender for Endpoint agent is installed and running. Guest Configuration assignments (built on the Guest Configuration extension and DSC-based audit/apply policies) can detect and remediate the MDE agent state across hybrid machines, which is exactly the cross-environment compliance requirement here. Microsoft Intune (A) manages device configuration and endpoint security primarily for enrolled user devices and does not provide the same Azure Policy-driven compliance enforcement for Arc-enabled servers.

Azure Update Manager (C) handles patching and update compliance, not endpoint protection agent enforcement, and Microsoft Defender for Cloud (D) provides security posture and threat protection but does not itself enforce agent installation state through policy assignments.

477
Multi-Selecteasy

Your organization needs to meet compliance requirements for GDPR. You need to design a solution that uses Microsoft Purview to classify and protect personal data. Which TWO capabilities should you include?

Select 2 answers
A.Data Subject Requests (DSR) tool
B.Data Classification and labeling
C.eDiscovery (Premium)
D.Insider Risk Management
E.Communication Compliance
AnswersA, B

The DSR tool in Microsoft Purview is the correct choice because it operationalizes GDPR Article 15-21 individual rights: access, rectification, erasure, restriction, processing objection, and portability. It lets administrators search across Exchange, SharePoint, OneDrive, and Teams for a data subject's content, then generate a downloadable report for review and action, including the ability to close out the request in a auditable manner. It is specifically designed for these privacy obligations, not for general content discovery.

Why this answer

The Data Subject Requests (DSR) tool (A) is correct because GDPR grants individuals rights over their personal data (access, rectification, erasure, portability), and the Microsoft Purview DSR tool provides a workflow to discover, review, and respond to these requests across Microsoft 365 data sources. Data Classification and labeling (B) is correct because GDPR requires identifying and protecting personal data, and Purview's sensitive information types, trainable classifiers, and sensitivity labels let you automatically classify and apply protection such as encryption and access restrictions. eDiscovery (Premium) (C) is not the right fit because it is designed for legal investigations and litigation hold workflows, not for fulfilling GDPR data subject rights or building a classification/protection scheme. Insider Risk Management (D) addresses detecting and mitigating risky user behavior, which supports security but does not directly satisfy GDPR classification, protection, or DSR obligations.

Communication Compliance (E) focuses on monitoring communications for policy violations such as harassment or regulatory breaches, which is unrelated to classifying and protecting personal data for GDPR compliance.

478
MCQmedium

You are a security architect for a software development company. The company uses GitHub for source control and Azure DevOps for CI/CD. They have a large number of repositories and want to ensure that secrets (e.g., API keys, connection strings) are never committed to code. They also want to scan pull requests for secrets before merging. The company has Microsoft Defender for Cloud and Microsoft Purview available. You need to design a solution that prevents secret leaks. What should you use?

A.Enable Microsoft Defender for Cloud's 'Secrets scanning' feature for GitHub repositories.
B.Use Azure Key Vault to store secrets and enforce policies that require developers to use Key Vault references.
C.Use Microsoft Purview Information Protection to scan repositories and classify secrets.
D.Enable GitHub secret scanning for all repositories. Configure push protection to block commits containing secrets. Use custom patterns to scan for company-specific secrets.
AnswerD

GitHub secret scanning with push protection blocks commits containing detected secrets before they reach the repository, while custom patterns extend detection to company-specific formats. This satisfies the stem's requirements to prevent secret leaks and scan pull requests before merging.

Why this answer

GitHub secret scanning can scan repositories for known secret patterns and supports custom patterns for company-specific secrets. Push protection blocks commits containing secrets before they are pushed. Option A is incorrect because Microsoft Defender for Cloud does not provide built-in secret scanning for GitHub repositories; GitHub secret scanning is a separate feature.

Option B is incorrect because Azure Key Vault stores secrets but does not scan code for secrets. Option C is incorrect because Microsoft Purview Information Protection is for data classification and labeling, not for secret scanning in source code.

Exam trap

Candidates may think Microsoft Defender for Cloud can scan GitHub repositories for secrets, but that is not a feature of Defender for Cloud. GitHub secret scanning is separate.

479
MCQhard

A healthcare organization is designing a zero-trust application security strategy. They use Microsoft Entra ID for identity and plan to deploy a legacy on-premises web application with no modern authentication support. The solution must ensure that only authorized users can access the app and that access is logged for auditing. Which Microsoft security service should they use to secure access?

A.Azure AD B2C
B.Microsoft Entra application proxy
C.Microsoft Defender for Cloud Apps
D.Microsoft Intune
AnswerB

Microsoft Entra Application Proxy is a cloud reverse proxy that publishes on-premises legacy web applications under an Entra ID external URL, using a lightweight connector installed on the internal network that initiates outbound connections only. Users authenticate through Entra ID first, which enables Conditional Access, MFA, and device compliance policies before the connector forwards the request via Kerberos Constrained Delegation to the app. Since it requires no VPN or code modifications, it directly supports zero trust for apps that lack modern authentication.

Why this answer

Microsoft Entra application proxy (option B) is correct because it is designed to publish on-premises web applications, including legacy apps without modern authentication support, and enforce Entra ID pre-authentication plus conditional access before traffic reaches the app, while also providing access logging for auditing. It fits the zero-trust scenario by brokering remote access through the Application Proxy connector without exposing the app directly to the internet. Azure AD B2C (option A) is for customer identity and access management for consumer-facing apps, not for securing internal legacy on-premises apps.

Microsoft Defender for Cloud Apps (option C) is a CASB for discovering, monitoring, and controlling cloud app usage, not for publishing and pre-authenticating on-premises web apps. Microsoft Intune (option D) is for device and mobile application management, not for brokering authenticated access to legacy on-premises web applications.

480
MCQhard

Your company has a Microsoft Defender for Cloud environment with Azure Arc-enabled on-premises servers. The security team wants to ensure that all servers have the Log Analytics agent installed and that missing updates are automatically remediated for critical vulnerabilities. Which policy initiative should you assign to the management group containing these servers?

A.Azure Policy for Kubernetes
B.CIS Microsoft Azure Foundations Benchmark
C.NIST SP 800-53 R5
D.Azure Security Benchmark
AnswerD

Azure Security Benchmark (ASB) is a Microsoft-designed initiative that consolidates security best practices and is implemented as a set of Azure Policy definitions. Within Defender for Cloud, the ASB initiative includes the policy 'Deploy Log Analytics agent on Azure Arc-enabled machines' (and equivalent for Azure VMs), which uses DeployIfNotExists to automatically install the agent on on-premises servers connected via Azure Arc. This same initiative also contains policies for vulnerability remediation, making it the correct choice for agent deployment and remediation workflow.

Why this answer

The Azure Security Benchmark initiative includes policies for agent installation and vulnerability remediation. The other options are either not policy initiatives or focus on different aspects like container security or regulatory compliance.

481
Multi-Selectmedium

A financial institution, Contoso Bank, is deploying a new application on Azure Kubernetes Service (AKS) that processes credit card transactions (PCI DSS). The application uses Azure SQL Database and Azure Redis Cache. You need to design a security solution that meets PCI DSS requirements. Which THREE of the following should you implement?

Select 3 answers
A.Deploy AKS as a private cluster with no public endpoint.
B.Configure Always Encrypted for sensitive columns in Azure SQL Database.
C.Enable Azure RBAC for Kubernetes authorization.
D.Use private endpoints for Azure SQL Database and Azure Cache for Redis.
E.Disable TLS for Azure Cache for Redis to improve performance.
AnswersA, B, D

Deploying AKS as a private cluster with no public endpoint is essential because the Kubernetes API server is placed behind a private IP address on a virtual network, using Azure Private Link. This prevents the control plane from being reachable from the internet, directly satisfying PCI DSS network compartmentalization requirements for cardholder data environments. Unlike merely disabling public access, this design ensures administrative and operational traffic to the API server also traverses the private network.

Why this answer

Option A is correct because deploying AKS as a private cluster with no public endpoint removes the API server's public exposure, ensuring all control-plane communication stays on the private network and reducing the PCI DSS attack surface. Option B is correct because Always Encrypted protects sensitive cardholder data columns in Azure SQL Database by keeping encryption keys outside the database engine, so even DBAs or compromised SQL instances cannot read plaintext data. Option D is correct because private endpoints for Azure SQL Database and Azure Cache for Redis route traffic over Azure Private Link, keeping data off the public internet and satisfying PCI DSS network segmentation and encryption-in-transit expectations.

Option C is not among the required three because Azure RBAC for Kubernetes authorization is a general access-control hardening measure, not a PCI DSS-specific control for protecting cardholder data in this scenario. Option E is incorrect because disabling TLS on Azure Cache for Redis exposes data in transit and directly violates PCI DSS encryption requirements for cardholder data.

Exam trap

Candidates may mistakenly believe that enabling Azure RBAC for Kubernetes is sufficient for PCI DSS compliance, but it only addresses authorization, not network isolation. Additionally, disabling TLS may be considered for performance but violates encryption requirements.

482
MCQmedium

A company deploys Microsoft Defender for Cloud Apps. They need to detect anomalous behavior in user activities across multiple cloud apps. Which feature should they enable?

A.Session policies
B.Anomaly detection policies
C.Data loss prevention policies
D.App governance
AnswerB

Anomaly detection policies in Microsoft Defender for Cloud Apps baseline each user's normal activity across connected apps, then alert on deviations such as impossible travel or mass downloads. This directly satisfies the requirement to detect anomalous behaviour spanning multiple cloud apps.

Why this answer

Anomaly detection policies in Microsoft Defender for Cloud Apps are specifically designed to identify unusual patterns in user activities across connected cloud apps, such as impossible travel, mass file downloads, or ransomware-like behavior. These policies leverage machine learning and behavioral analytics to establish a baseline of normal user behavior and trigger alerts when deviations occur, making them the correct choice for detecting anomalous behavior.

Exam trap

The trap here is that candidates often confuse session policies (which enforce real-time access controls) with anomaly detection policies (which analyze historical patterns), leading them to select session policies when the question specifically asks for detecting anomalous behavior rather than controlling it.

How to eliminate wrong answers

Option A is wrong because session policies are used for real-time control of user sessions based on risk level, not for detecting anomalous behavior patterns over time. Option C is wrong because data loss prevention policies focus on preventing unauthorized sharing or leakage of sensitive data, not on detecting behavioral anomalies in user activities. Option D is wrong because app governance provides visibility and control over app permissions and compliance, but it does not include the behavioral anomaly detection capabilities needed for user activity monitoring.

483
Multi-Selecteasy

Which THREE features of Microsoft Defender for Cloud help secure Azure Kubernetes Service (AKS) clusters? (Select three.)

Select 3 answers
A.Advanced threat protection for Azure Cosmos DB
B.Azure Defender for Kubernetes (cluster hardening)
C.Vulnerability assessment for container images
D.DDoS Protection Standard
E.Runtime threat detection for AKS clusters
AnswersB, C, E

Azure Defender for Kubernetes, now part of Microsoft Defender for Containers, provides continuous security assessment of your cluster's configuration, including checks against CIS Kubernetes Benchmarks, overly permissive RBAC roles, and insecure pod settings. It automatically generates prioritized hardening recommendations that analysts can implement to reduce attack surface. This directly helps secure AKS clusters and is the correct answer for cluster hardening.

Why this answer

Azure Defender for Kubernetes (option B) is correct because it provides cluster hardening by continuously assessing AKS configurations against CIS Kubernetes benchmark controls and surfacing misconfiguration recommendations in Microsoft Defender for Cloud. Vulnerability assessment for container images (option C) is correct because Defender for Cloud scans images stored in Azure Container Registry and images running in AKS, using Qualys-based scanning to detect known CVEs in OS packages and language dependencies. Runtime threat detection for AKS clusters (option E) is correct because Defender for Containers monitors AKS node and workload activity via eBPF-based sensors and Kubernetes audit logs to alert on suspicious behavior such as crypto-mining, privilege escalation, and anomalous process execution.

Option A does not belong because Advanced threat protection for Azure Cosmos DB protects database accounts, not AKS clusters. Option D does not belong because DDoS Protection Standard mitigates volumetric network attacks at the Azure edge and is not an AKS workload security feature of Defender for Cloud.

Exam trap

The trap here is that candidates may confuse general Azure security services (like DDoS Protection) or unrelated Defender plans (like Cosmos DB) with the specific Defender for Cloud features that directly protect AKS workloads, leading them to select options that are technically valid Azure services but not applicable to AKS cluster security.

484
MCQmedium

Your organization is migrating on-premises applications to Azure and needs to secure secrets (database connection strings, API keys) used by these applications. You are required to rotate secrets automatically without downtime. Which Azure service should you use?

A.Microsoft Purview Information Protection
B.Azure App Configuration with feature flags
C.Azure Key Vault with managed identity and certificate auto-rotation
D.Azure AD Application Proxy
AnswerC

Azure Key Vault is the appropriate service for securely storing and managing sensitive information such as certificates, keys, and secrets. By combining it with a managed identity, an application authenticates to Key Vault without any hardcoded credentials, and the built-in certificate auto-rotation ensures certificates are renewed and renewed versions are made available transparently. This integrated approach fully addresses secret storage, access control, and lifecycle management for your migration.

Why this answer

Azure Key Vault with managed identity and certificate auto-rotation is correct because it provides a centralized, secure store for secrets like database connection strings and API keys, supports automatic rotation of certificates and secrets via Event Grid notifications or lifecycle policies, and integrates with Azure resources using managed identities to enable zero-downtime rotation without exposing credentials in code or configuration.

Exam trap

The trap here is that candidates confuse Azure App Configuration (which can store configuration values but not secrets securely with rotation) with Azure Key Vault, or mistakenly think Purview Information Protection handles secrets management, when only Key Vault provides the required secure storage and automated rotation capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Protection is a data classification and labeling service for protecting sensitive data at rest and in transit, not a secrets management or rotation service. Option B is wrong because Azure App Configuration with feature flags is designed for managing application configuration settings and feature toggles, not for securely storing or rotating secrets like connection strings or API keys. Option D is wrong because Azure AD Application Proxy provides secure remote access to on-premises web applications by publishing them through Azure AD, not for storing or rotating secrets.

485
MCQmedium

Refer to the exhibit. You are reviewing a conditional access policy. What is the effect of this policy?

A.The policy is disabled and has no effect
B.Blocks access for all users
C.Requires multifactor authentication for all users
D.Requires multifactor authentication for Global Administrators and Security Administrators
AnswerD

The policy configuration targets the directory roles Global Administrators and Security Administrators, and its grant control is set to 'Require multi-factor authentication'. When a user who holds either of these roles attempts to access a protected resource, the policy is triggered and MFA is enforced. This correctly matches the statement that MFA is required for both administrator roles.

Why this answer

The exhibit shows a conditional access policy that targets the 'Global Administrators' and 'Security Administrators' directory roles, and the policy is configured to 'Require multifactor authentication' for those roles. The policy is enabled (as indicated by the 'On' toggle), so it actively enforces MFA for members of those two admin roles, blocking access if they do not complete MFA. This aligns with the principle of securing high-privilege roles with stronger authentication.

Exam trap

The trap here is that candidates may overlook the specific role targeting in the policy and assume it applies to all users, leading them to choose option C, or they may mistakenly think the policy is disabled because they misread the toggle state, choosing option A.

How to eliminate wrong answers

Option A is wrong because the policy is enabled (the 'On' toggle is visible in the exhibit), so it is not disabled and does have an effect. Option B is wrong because the policy targets only specific directory roles (Global Administrators and Security Administrators), not all users, so it does not block access for everyone. Option C is wrong because the policy does not apply to all users; it is scoped to only the two specified admin roles, so it does not require MFA for all users.

486
Multi-Selecteasy

Which THREE are valid methods to secure privileged access in Microsoft Entra ID? (Choose three.)

Select 3 answers
A.Use privileged access groups to manage elevated access to resources.
B.Require device enrollment via Microsoft Intune.
C.Use Privileged Identity Management (PIM) for just-in-time access.
D.Configure conditional access policies to require MFA for admins.
E.Enable self-service password reset for all users.
AnswersA, C, D

Privileged access groups, such as role-assignable groups in Microsoft Entra ID, allow administrators to assign highly privileged Azure AD roles to a group rather than to individual users. This enables scalable and consistent membership management, and when integrated with Privileged Identity Management (PIM), group membership can be time-limited so users hold elevated access only during an approved activation window. Because the group itself carries the role, adding or removing members centrally controls privileged access across multiple resources.

Why this answer

Option A is correct because privileged access groups in Microsoft Entra ID (specifically Privileged Access Management for groups) let you assign users as eligible or active members of a role-assignable group, so elevated access to resources is governed and time-bound rather than permanently granted. Option C is correct because Privileged Identity Management (PIM) provides just-in-time role activation with approval workflows, MFA on activation, justification, and time-limited assignments, which directly reduces standing privileged access. Option D is correct because a Conditional Access policy that requires multifactor authentication for directory roles (admin roles) enforces strong authentication at sign-in for privileged accounts, a core control for securing privileged access.

Option B is not one of the three because Intune device enrollment/compliance is a device-management control that can be referenced in Conditional Access but is not itself a privileged-access security method. Option E is not correct because self-service password reset is an end-user credential-recovery feature and does not govern or restrict privileged access.

Exam trap

The trap here is that candidates may confuse general security best practices (like device enrollment or self-service password reset) with specific methods for securing privileged access, which require granular controls like PIM, conditional access, and privileged groups.

487
MCQeasy

A company is designing an application architecture using Azure Kubernetes Service (AKS) and Azure Cosmos DB. The application requires that secrets (database connection strings) be injected into pods securely without storing them in the container image. The solution must minimize management overhead. What is the recommended approach?

A.Store secrets in a Kubernetes ConfigMap and reference them in the deployment YAML.
B.Use Azure Key Vault Provider for Secrets Store CSI Driver to mount secrets as volumes in pods.
C.Define secrets in a Kubernetes Secret object and reference them in the pod spec.
D.Hardcode the connection string in an environment variable in the deployment manifest.
AnswerB

The Azure Key Vault Provider for Secrets Store CSI Driver securely injects secrets from Azure Key Vault into pods as mounted volumes or environment variables, using a managed identity for authentication to avoid hardcoding any credentials. Secrets are never stored in Kubernetes etcd, and the provider integrates with Azure Key Vault's built-in rotation, access policies, and audit logging, ensuring that secret access is controlled and traceable. This native Azure integration provides a fully managed, secure, and scalable solution for secret management in AKS, satisfying both operational and compliance needs.

Why this answer

The Azure Key Vault Provider for Secrets Store CSI Driver integrates directly with AKS to securely inject secrets from Azure Key Vault into pods as mounted volumes or environment variables, without storing them in container images or Kubernetes objects. This approach minimizes management overhead by leveraging Azure-managed Key Vault for secret lifecycle management and avoids the operational burden of manually managing Kubernetes Secrets.

Exam trap

The trap here is that candidates often assume Kubernetes Secrets are inherently secure because they are base64-encoded, but the exam tests the understanding that Secrets are only obfuscated, not encrypted by default, and that a managed external secrets store like Azure Key Vault is the recommended pattern for production-grade secret management with minimal overhead.

How to eliminate wrong answers

Option A is wrong because ConfigMaps are designed for non-sensitive configuration data (e.g., plain text), not secrets; storing database connection strings in a ConfigMap would expose them in plain text and violate security best practices. Option C is wrong because Kubernetes Secret objects are base64-encoded, not encrypted by default, and require additional encryption configuration (e.g., encryption at rest with KMS) and manual management, increasing overhead and risk compared to a dedicated secrets store. Option D is wrong because hardcoding connection strings in environment variables in the deployment manifest exposes secrets in plain text within the YAML file, version control, and cluster logs, completely violating security principles.

488
MCQhard

You are designing a security operations solution for a multinational organization using Microsoft Sentinel. The organization has multiple Azure subscriptions, each with its own Log Analytics workspace. You need to centralize incident management while minimizing data egress costs. What should you recommend?

A.Deploy a Sentinel workspace in each region and use cross-workspace views.
B.Export all logs to a third-party SIEM using Azure Event Hubs.
C.Configure Azure Monitor cross-workspace queries to correlate incidents.
D.Use a single Log Analytics workspace for all subscriptions and configure Sentinel in that workspace.
AnswerD

A single Log Analytics workspace for all subscriptions lets Microsoft Sentinel ingest every security log into one repository, so incidents are generated and managed from a unified console. This eliminates cross-region egress fees and enables seamless correlation across subscriptions, while also simplifying automation, access control, and compliance reporting. One caveat is that workspace scale limits and data sovereignty must be carefully evaluated, but for most SOC designs this is the recommended pattern.

Why this answer

Option D is correct because Microsoft Sentinel is enabled on a Log Analytics workspace, and using a single workspace for all subscriptions centralizes incident management in one place while avoiding cross-workspace query and data egress charges. All subscriptions can onboard to that workspace via Azure Lighthouse or the Sentinel data connectors, so incidents, analytics rules, and workbooks are managed centrally. Option A does not truly centralize incidents and adds cross-workspace complexity, while Option B sends data to a third-party SIEM and increases egress costs rather than minimizing them.

Option C only allows cross-workspace queries for correlation but still leaves incident management distributed across multiple workspaces.

489
MCQmedium

A company uses Microsoft Entra ID Governance. They need to automate the process of granting access to a SaaS application based on the user's department attribute. Which feature should they use?

A.Lifecycle workflows
B.Entitlement management
C.Access reviews
D.Privileged identity management
AnswerB

Entitlement management in Microsoft Entra ID Governance provides access packages that bundle resources, roles, and policies. It can automate assignment based on member attributes through dynamic membership rules or by connecting to a source like an HR system, and it supports time-bound assignments, self-service requests, and approvals. This makes it the appropriate tool for automatically granting access to applications based on an attribute such as the user's department, aligning directly with the stated need.

Why this answer

Entitlement management in Microsoft Entra ID Governance allows you to create access packages that define collections of resources (like SaaS apps) and policies for who can request access. By configuring a dynamic membership rule based on the user's department attribute, you can automate granting access to the SaaS application without manual intervention. This directly meets the requirement to automate access based on a user attribute.

Exam trap

The trap here is that candidates confuse Lifecycle workflows (which automate HR-driven provisioning events) with Entitlement management (which automates attribute-based access requests), leading them to choose Option A incorrectly.

How to eliminate wrong answers

Option A is wrong because Lifecycle workflows automate joiner, mover, and leaver processes (e.g., account provisioning, email forwarding) but do not handle attribute-based access requests to SaaS applications. Option C is wrong because Access reviews are periodic attestation processes to review existing access, not an automated mechanism to grant access based on a user attribute. Option D is wrong because Privileged identity management (PIM) provides just-in-time privileged access to Azure AD roles and Azure resources, not automated entitlement to a SaaS application based on a department attribute.

490
MCQeasy

Your organization uses Microsoft Defender for Office 365. You need to protect users from malicious links in emails. What should you configure?

A.Anti-malware policy
B.Safe Links policy
C.Anti-phishing policy
D.Safe Attachments policy
AnswerB

Safe Links is the dedicated protection feature for URLs, automatically applying URL rewriting and time-of-click checks in Microsoft 365. When a user clicks a link, Safe Links verifies the destination against the latest threat intelligence and blocks or warns if it leads to a malicious site, even if the link initially looked benign. This is precisely the control that fulfills a requirement for malicious link protection at click time.

Why this answer

Safe Links policy is the correct answer because it specifically protects users from malicious links in emails by scanning URLs at the time of click, checking against Microsoft's threat intelligence, and optionally rewriting links to route clicks through the Safe Links service. This is the dedicated Defender for Office 365 feature designed to mitigate link-based attacks in email messages.

Exam trap

The trap here is that candidates often confuse Safe Links with Safe Attachments, but Safe Attachments handles file payloads (attachments) while Safe Links handles URL payloads (links) — a common misconception that leads to selecting the wrong policy for link protection.

How to eliminate wrong answers

Option A is wrong because Anti-malware policy focuses on scanning email attachments and messages for malware signatures, not on protecting against malicious links. Option C is wrong because Anti-phishing policy primarily protects against impersonation attacks (e.g., spoofed domains, user impersonation) and does not directly scan or rewrite URLs in emails. Option D is wrong because Safe Attachments policy is designed to detonate and analyze email attachments in a sandbox environment, not to handle hyperlinks within the message body.

491
MCQmedium

Refer to the exhibit. You are troubleshooting a KQL query in Microsoft Sentinel that is supposed to return alerts for ransomware detections in the last day. The query returns no results, but you know there were ransomware alerts. What is the most likely cause?

A.The ThreatFamily field is an integer, not a string.
B.The AlertName filter is too specific and does not match the actual alert name.
C.The TimeGenerated filter uses the wrong time range.
D.The parse_json function is failing due to malformed JSON.
AnswerB

The AlertName filter is too specific and does not match the actual alert name. In Microsoft Sentinel, analytics rule names often include suffixes, version numbers, or localized display names, and the exact string comparison in KQL is case-sensitive. For example, an alert named 'Suspicious PowerShell Activity' might be stored as 'Suspicious PowerShell Activity (Preview)' or with a different casing. Because the query filters for an exact match, it silently returns zero rows even though alerts exist. To resolve this, use the `has` or `contains` operator to match a substring instead of exact equality.

Why this answer

The query's `AlertName` filter is likely too specific (e.g., using a hardcoded string like 'RansomwareAlert') and does not match the actual alert name generated by Microsoft Sentinel's analytics rules. Ransomware alerts often have dynamic naming conventions that include variant names or suffixes, so an exact match filter fails to return results even though alerts exist. The query otherwise appears syntactically correct, and the `TimeGenerated` filter is set to the last day, which aligns with the known presence of alerts.

Exam trap

The trap here is that candidates assume a simple string comparison will match all alerts of a given category, overlooking that Microsoft Sentinel alert names often include variant-specific suffixes or prefixes, making exact-match filters too restrictive.

How to eliminate wrong answers

Option A is wrong because the `ThreatFamily` field in Microsoft Sentinel's alert schema is a string type, not an integer, and comparing it to a string literal would work correctly; an integer mismatch would cause a type error or implicit conversion, not a silent empty result. Option C is wrong because the `TimeGenerated` filter using `ago(1d)` is a standard and correct way to query the last 24 hours, and if alerts existed within that window, this filter would not suppress them. Option D is wrong because the `parse_json` function failing due to malformed JSON would typically produce an error or null value in the output, not an empty result set, and the query would still return rows with null fields rather than zero rows.

492
MCQmedium

Your company uses Microsoft Sentinel for security operations. You need to design a solution to automatically respond to a confirmed ransomware incident by isolating affected devices and blocking malicious IPs. What should you use?

A.Azure Policy
B.Sentinel automation rules with playbooks
C.Microsoft Defender for Cloud Apps
D.Microsoft Intune
AnswerB

Sentinel automation rules are the native orchestration mechanism that listens for incident/alert triggers and invokes playbooks—workflows built on Azure Logic Apps. When an incident matches a rule condition, the automation rule runs a playground that can execute actions such as isolating a device via the Microsoft Defender for Endpoint connector, blocking an IP using a firewall connector, or opening a ticket in ITSM systems. This is the correct answer because it provides a first-party, built-in path that directly links Sentinel's alert pipeline to automated response actions via Log Apps' rich connector ecosystem, with no custom scripting required.

Why this answer

Sentinel automation rules with playbooks (option B) is correct because automation rules in Microsoft Sentinel trigger Logic App playbooks in response to analytics rule alerts, and those playbooks can call Microsoft Defender for Endpoint APIs to isolate devices and update firewall/blocklist mechanisms to block malicious IPs. This directly matches the requirement for automated incident response to a confirmed ransomware incident. Azure Policy (A) is for enforcing governance and compliance on Azure resources, not for orchestrating incident response actions.

Microsoft Defender for Cloud Apps (C) is a CASB for discovering and controlling cloud app usage, not for device isolation or IP blocking. Microsoft Intune (D) is for device management and compliance, not for automated security incident response workflows.

493
MCQhard

Your organization uses Microsoft Sentinel as its SIEM. You receive a large number of low-severity alerts from various sources, overwhelming the security operations team. You need to design a solution to reduce alert fatigue while ensuring that critical incidents are not missed. The solution should also automatically collect feedback from analysts when they close an incident. What should you implement?

A.Tune analytics rules to generate incidents only for high-fidelity alerts and use automation rules to collect feedback on incident closure
B.Create a separate analytics rule for each severity level
C.Implement a playbook that automatically closes low-severity alerts and collects feedback
D.Increase the severity threshold for all analytics rules
AnswerA

Tuning analytics rules is the correct approach because it targets the root cause of alert fatigue: noisy or overly broad detection logic. By refining query thresholds, alert grouping, and incident creation settings, you ensure that only high-fidelity findings become incidents, while automation rules can trigger a playbook (e.g., an HTTP request or Teams message) to gather analyst feedback at incident closure. This feedback loop lets security operations continuously improve rule tuning without adding manual burden.

Why this answer

Tuning analytics rules to generate incidents only for high-fidelity alerts directly reduces alert volume without compromising detection of critical threats. Automation rules in Microsoft Sentinel can trigger a playbook or run a logic app on incident closure, enabling automatic collection of analyst feedback via custom fields or external systems.

Exam trap

The trap here is that candidates confuse 'automatically closing low-severity alerts' (Option C) with a valid noise-reduction technique, failing to recognize that automatic closure without analyst review can suppress true positives and violates the requirement to not miss critical incidents.

How to eliminate wrong answers

Option B is wrong because creating a separate analytics rule for each severity level does not reduce alert volume—it merely organizes alerts by severity, still overwhelming the SOC. Option C is wrong because automatically closing low-severity alerts via a playbook bypasses analyst review and risks missing critical incidents that may initially appear low-severity; feedback collection should be tied to incident closure, not automatic closure. Option D is wrong because increasing the severity threshold for all analytics rules is a blunt approach that can cause high-fidelity, critical alerts to be downgraded or missed entirely, violating the requirement to not miss critical incidents.

494
MCQeasy

Your security team needs to receive alerts when a user is assigned a privileged role in Microsoft Entra ID. Which service should you use to create an alert for privileged role assignments?

A.Microsoft Entra ID Privileged Identity Management (PIM)
B.Microsoft Defender for Identity
C.Microsoft Sentinel
D.Microsoft Defender for Cloud Apps
AnswerA

PIM is the native Microsoft Entra ID identity governance engine that delivers built-in, out-of-the-box alerting for privileged role assignments and activations. It monitors for suspicious activities such as permanent privileged assignments, off-hours role activation, or activation attempts that bypass just-in-time access policies, and can trigger email notifications or integrate with SIEM tools. These alerts are natively scoped to Entra ID roles, requiring no additional log ingestion or custom rule authoring, making it the correct choice for this requirement.

Why this answer

Microsoft Entra ID Privileged Identity Management (PIM) is the correct service because it provides built-in alerting capabilities specifically for privileged role assignments in Microsoft Entra ID. PIM can generate alerts when a user is assigned a privileged role, such as Global Administrator, without requiring additional configuration or external data sources. This aligns directly with the requirement to receive alerts for privileged role assignments within the identity platform.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Identity or Microsoft Sentinel as the primary alerting tool for Entra ID role assignments, but PIM is the native, purpose-built service for this specific identity governance task.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Identity is a security solution that monitors on-premises Active Directory signals and hybrid identities for threats like lateral movement and compromised accounts, not for generating alerts on Entra ID role assignments. Option C is wrong because Microsoft Sentinel is a SIEM/SOAR platform that ingests logs from multiple sources, including Entra ID, but it requires custom analytics rules and log ingestion to create alerts for role assignments, making it an indirect and more complex solution compared to PIM's native alert. Option D is wrong because Microsoft Defender for Cloud Apps focuses on cloud application discovery, session controls, and anomaly detection for SaaS apps, not on monitoring Entra ID privileged role assignments.

495
MCQmedium

Your organization is deploying a customer-facing web application in Azure. The application must authenticate users via Microsoft Entra ID and access Microsoft Graph to read user profiles. The security team requires that the application never has access to user passwords. Which authentication flow should you recommend?

A.OAuth 2.0 implicit grant flow
B.OAuth 2.0 device authorization flow
C.OAuth 2.0 client credentials grant flow
D.OAuth 2.0 authorization code flow with PKCE
AnswerD

Authorization code flow with PKCE is the recommended OAuth 2.0 flow for customer-facing web applications. The user authenticates and consents, and the app receives an authorization code rather than a token; this code is then exchanged for tokens using a PKCE verifier, ensuring that even if the code is intercepted it cannot be redeemed. The flow supports refresh tokens and never exposes the user's password to the app, making it secure for JavaScript and server-based web apps alike.

Why this answer

The correct option is D, OAuth 2.0 authorization code flow with PKCE, because it is the recommended flow for customer-facing web applications that authenticate users interactively via Microsoft Entra ID and call Microsoft Graph on their behalf. With PKCE, the client proves possession of a one-time code verifier, and the user authenticates directly against Entra ID, so the application never handles or sees user passwords. The resulting delegated access token also allows reading user profiles through Microsoft Graph with the appropriate scopes.

Option A (implicit grant) is deprecated and exposes tokens in the browser URL fragment, while option B (device authorization flow) is intended for input-constrained devices and is not suited to a normal web app. Option C (client credentials grant) is app-only authentication with no user context, so it cannot authenticate users or read their profiles as required.

496
Multi-Selectmedium

Your organization is planning to deploy Microsoft Defender for Cloud Apps (formerly Cloud App Security). You need to discover shadow IT usage and control access to cloud apps. Which TWO capabilities should you enable? (Choose TWO.)

Select 2 answers
A.Conditional Access App Control
B.Microsoft Intune device compliance policies
C.Data Loss Prevention (DLP) policies
D.On-premises app discovery via Microsoft Defender for Identity
E.Cloud Discovery
AnswersA, E

Conditional Access App Control (CAAC) is a session-level reverse proxy capability within Microsoft Defender for Cloud Apps that dynamically enforces access policies on cloud applications in real time. It can block downloads, restrict uploads, or require step-up authentication without modifying the app itself. This control operates after a user is authenticated and is ideal for protecting access to both sanctioned and unsanctioned cloud apps.

Why this answer

Cloud Discovery [E] is correct because it is the Defender for Cloud Apps feature that analyzes your traffic logs (from firewalls, proxies, or Defender for Endpoint) against the Cloud App Catalog to identify shadow IT usage, giving risk scores and usage analytics for discovered apps. Conditional Access App Control [A] is correct because it uses reverse-proxy deployment (via Azure AD Conditional Access policies) to enforce real-time session controls—such as block download, block upload, and read-only access—on cloud apps, directly satisfying the requirement to control access to cloud apps. Intune device compliance policies [B] govern device health and compliance, not cloud app discovery or session-level app access control.

DLP policies [C] protect sensitive data from exfiltration but do not perform shadow IT discovery or app access control. On-premises app discovery via Defender for Identity [D] only surfaces on-premises shadow IT (e.g., unsanctioned SaaS used from domain controllers), not the broad cloud app discovery and access control this scenario requires.

497
MCQhard

Refer to the exhibit. A security administrator is reviewing a Conditional Access policy JSON. They want to ensure that users with medium risk level are prompted for multi-factor authentication (MFA), while high-risk users are blocked. The policy is not working as expected. Which issue is present in the policy?

A.The policy mode should be 'report-only'
B.The policy requires both user and sign-in risk to be high to block, but a user with high user risk and low sign-in risk would not be blocked
C.The JSON syntax is invalid
D.The conditions are combined with 'Or' instead of 'And'
AnswerB

In Microsoft Entra Conditional Access, conditions are evaluated cumulatively; a user must satisfy every condition for the 'Block access' grant to be applied. With user risk set to High and sign-in risk set to High, a user whose user risk is High but whose sign-in risk is Low will not match both conclusions, so the block is skipped. This leaves a predictable gap that an attacker with a compromised account and low sign-in risk could exploit. The correct fix would be to treat high user risk OR high sign-in risk as sufficient, either by using separate policies or by adjusting the controls.

Why this answer

The correct answer is B: the policy's block condition requires both user risk and sign-in risk to be high, so a user with high user risk but low sign-in risk would not be blocked as intended. In Microsoft Entra Conditional Access, user risk and sign-in risk are separate conditions, and if the JSON combines them so that both must be 'high' for the block to apply, the policy fails to block all high-risk users. The intended design should block when user risk is high, regardless of sign-in risk, or use separate grant controls for medium-risk MFA and high-risk block.

Option A is wrong because report-only mode would not enforce MFA or blocking at all. Option C is wrong because the scenario describes a logic problem, not invalid JSON syntax. Option D is wrong because combining conditions with 'Or' would make the policy broader, not narrower, and would not explain the failure to block high-risk users.

498
MCQmedium

A company is designing a data protection strategy for Azure SQL Database. They need to ensure that backups are retained for 7 years to meet regulatory compliance. Which Azure feature should they use?

A.Geo-redundant backup storage
B.Long-Term Retention (LTR)
C.Point-in-Time Restore
D.Active Geo-Replication
AnswerB

Long-Term Retention (LTR) is the correct choice because it preserves database backups for up to 10 years, commonly required for regulatory compliance or historical data archiving. LTR operates separately from automated short-term backups, allowing you to define independent retention schedules—for example, weekly full backups kept for 5 years. This directly addresses the scenario's need for an extended data protection strategy beyond the standard 35-day window.

Why this answer

Long-Term Retention (LTR) for Azure SQL Database allows you to retain full database backups for up to 10 years, which meets the 7-year regulatory compliance requirement. LTR is specifically designed for archival and compliance scenarios, storing backups in separate containers with configurable retention policies based on weekly, monthly, or yearly intervals.

Exam trap

The trap here is that candidates confuse Point-in-Time Restore (PITR) with Long-Term Retention (LTR), mistakenly thinking PITR can be configured for years-long retention, when in fact PITR is limited to a maximum of 35 days and LTR is the only feature that supports multi-year archival retention.

How to eliminate wrong answers

Option A is wrong because Geo-redundant backup storage (RA-GRS) provides geographic redundancy for automated backups but does not extend the retention period beyond the default 7-35 days for point-in-time restore backups. Option C is wrong because Point-in-Time Restore (PITR) enables recovery to any point within the retention window (default 7 days, configurable up to 35 days), but it cannot retain backups for years. Option D is wrong because Active Geo-Replication is a continuous replication feature for disaster recovery and read-scale, not a backup retention mechanism; it does not provide long-term archival storage.

499
Multi-Selectmedium

Your organization uses Azure Data Lake Storage Gen2 for big data analytics. You need to secure access to the data using Azure RBAC and ACLs. Which two methods can you use to authorize access? (Choose two.)

Select 2 answers
A.Configure IP firewall rules to restrict access.
B.Assign Azure RBAC roles such as Storage Blob Data Contributor to security principals.
C.Set POSIX-like access control lists (ACLs) on directories and files.
D.Use managed identities for Azure resources.
E.Generate shared access signatures (SAS) for delegated access.
AnswersB, C

Azure RBAC role assignments are the recommended, identity-based authorization method for controlling access to Azure Data Lake Storage Gen2. Roles like Storage Blob Data Contributor grant a security principal (user, group, service principal, or managed identity) permissions at the storage account, container, or directory/file scope using Azure's centralized control plane. When a principal makes a request, Azure evaluates RBAC assignments, integrating with Microsoft Entra ID, to determine coarse-grained access such as read, write, delete, and list, making this the go-to choice for broad or automated access control.

Why this answer

Option B is correct because Azure Data Lake Storage Gen2 supports Azure RBAC role assignments, such as Storage Blob Data Contributor, Storage Blob Data Reader, and Storage Blob Data Owner, to authorize security principals (users, groups, service principals, managed identities) at the container or account scope. Option C is correct because ADLS Gen2 implements a POSIX-like ACL model at the directory and file level, allowing fine-grained read, write, and execute permissions for named users and groups in addition to RBAC. Option A is not a valid authorization method here; IP firewall rules are network-level access restrictions, not an authorization mechanism for data access.

Option D is not itself an authorization method—managed identities are an identity type that must still be granted access via RBAC or ACLs. Option E is not the intended answer because SAS tokens are a delegation mechanism primarily associated with Blob Storage and are not the standard authorization approach for ADLS Gen2 hierarchical namespace access via RBAC and ACLs.

500
MCQhard

Your organization has Microsoft Sentinel. You need to create an analytics rule that detects when a user account is created outside of business hours (9 AM to 5 PM, Monday-Friday). Which KQL query should you use as the rule query?

A.... | where dayofweek(TimeGenerated) between (1 .. 5) and datetime_part("hour", TimeGenerated) !between (9 .. 17)
B.... | where dayofweek(TimeGenerated) between (2 .. 6) and datetime_part("hour", TimeGenerated) !between (9 .. 17)
C.... | where dayofweek(TimeGenerated) between (2 .. 6) and datetime_part("hour", TimeGenerated) between (9 .. 17)
D.... | where dayofweek(TimeGenerated) !between (2 .. 6) or datetime_part("hour", TimeGenerated) between (9 .. 17)
AnswerB

This query is correct because KQL's dayofweek() returns an integer where Sunday=1, Monday=2, ..., Saturday=7. The range 2..6 therefore includes Monday, Tuesday, Wednesday, Thursday, and Friday exactly, and the !between (9..17) operator excludes hours that are greater than or equal to 9 and less than or equal to 17, so only hours before 9 AM or after 5 PM remain. Combining these conditions with AND yields all events that occurred on weekdays and outside standard business hours, which is precisely the requirement.

Why this answer

`dayofweek()` returns 1 for Sunday, 2 for Monday, ..., 7 for Saturday. To represent Monday (2) through Friday (6), the range must be `between (2 .. 6)`. The `!between (9 .. 17)` correctly excludes the 9 AM to 5 PM business hours, so the rule triggers only when a user account is created outside those hours on a weekday.

Exam trap

The trap here is that `dayofweek()` uses a 1-based index starting on Sunday (1), not Monday (1), so candidates often incorrectly use `between (1 .. 5)` expecting Monday through Friday, but that actually covers Sunday through Thursday.

How to eliminate wrong answers

Option A is wrong because `dayofweek(TimeGenerated) between (1 .. 5)` includes Sunday (1) through Thursday (5), which misses Friday and incorrectly includes Sunday. Option C is wrong because it uses `between (9 .. 17)` instead of `!between (9 .. 17)`, so it would detect accounts created *during* business hours, not outside them. Option D is wrong because it uses `!between (2 .. 6)` which includes weekends (Sunday and Saturday) and `or` with `between (9 .. 17)`, so it would fire for any account created during business hours on any day, including weekends, failing to target only weekday after-hours creation.

501
MCQeasy

A company uses Microsoft Defender for Endpoint (MDE) and needs to ensure that all devices report their security configuration to Microsoft Defender XDR. Which setting should they verify?

A.Devices are enrolled in Microsoft Intune
B.Microsoft Sentinel is connected to Defender for Endpoint
C.Microsoft Purview Information Protection is enabled
D.Devices are onboarded to Microsoft Defender XDR
AnswerD

Onboarding to Microsoft Defender XDR is the act of enrolling each device with the Defender for Endpoint agent, which then establishes the connection to the XDR backend and begins submitting raw sensor data, process events, network signals, and security alerts. This is the required technical prerequisite for a device to appear in the Defender XDR device inventory and to contribute to the unified incident story. Without onboarding, no other Microsoft service can cause the endpoint to report its security state to the XDR experience.

Why this answer

Devices must be onboarded to Microsoft Defender XDR to report their security configuration. Onboarding registers the device with the Defender for Endpoint service, enabling the collection and forwarding of security telemetry to the Microsoft 365 Defender portal. Without onboarding, the device cannot communicate its security state, regardless of other integrations.

Exam trap

The trap here is that candidates confuse Intune enrollment with Defender for Endpoint onboarding, but Intune only manages policies and compliance, while onboarding is the specific process that enables security telemetry reporting to Defender XDR.

How to eliminate wrong answers

Option A is wrong because Intune enrollment manages device compliance and configuration policies but does not automatically onboard devices to Defender for Endpoint; a separate onboarding step is required. Option B is wrong because connecting Microsoft Sentinel to Defender for Endpoint ingests alerts and incidents into Sentinel for SIEM purposes, but it does not cause devices to report their security configuration to Defender XDR. Option C is wrong because Microsoft Purview Information Protection focuses on data classification and labeling, not device-level security configuration reporting.

502
MCQeasy

A company is implementing a Zero Trust security model. Which principle requires verifying every access request as if it originates from an uncontrolled network?

A.Least privilege
B.Micro-segmentation
C.Assume breach
D.Verify explicitly
AnswerD

Verify explicitly is the foundational Zero Trust principle mandating that every access request is continuously authenticated and authorized based on all available data points, including user identity, device compliance, location, data sensitivity, and behavioral anomalies. No implicit trust is granted, even for requests originating from internal networks or previously trusted endpoints. This principle directly addresses the 'always verify' core by evaluating each request dynamically at the policy enforcement point.

Why this answer

The 'Assume breach' principle is not about verifying requests. 'Verify explicitly' is the Zero Trust principle that mandates authenticating and authorizing every access request. 'Least privilege' limits access rights. 'Micro-segmentation' is a network isolation technique.

503
MCQhard

Your organization has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You need to design a solution that ensures all user authentication requests are evaluated by Conditional Access policies before granting access to cloud apps. However, some legacy apps still require basic authentication. What should you recommend?

A.Enable authentication policies in Microsoft Entra ID to block legacy authentication
B.Configure Active Directory Federation Services (AD FS) as the identity provider
C.Deploy Microsoft Entra Application Proxy for all legacy apps
D.Enable pass-through authentication (PTA) to forward authentication requests
AnswerA

Enabling authentication policies in Microsoft Entra ID, such as the legacy authentication block, is the correct approach because legacy protocols like POP3, IMAP4, and SMTP do not support modern authentication and thus cannot be evaluated against Conditional Access policies. Blocking these protocols forces clients to use modern authentication (OAuth 2.0, OpenID Connect, SAML), ensuring multi-factor authentication and device compliance checks are enforced on every sign-in.

Why this answer

Enabling authentication policies in Microsoft Entra ID to block legacy authentication ensures that all user authentication requests are evaluated by Conditional Access policies before granting access to cloud apps. Legacy authentication protocols (e.g., POP3, IMAP, SMTP, basic auth) bypass modern authentication and Conditional Access, so blocking them forces clients to use modern protocols (OAuth 2.0, OpenID Connect) that are subject to Conditional Access evaluation. This directly addresses the requirement while allowing legacy apps to be updated or replaced over time.

Exam trap

The trap here is that candidates often confuse 'blocking legacy authentication' with 'disabling basic authentication' in Exchange Online or other services, but the correct approach is to use the tenant-wide Conditional Access policy to block all legacy authentication protocols, which is a distinct setting in Microsoft Entra ID.

How to eliminate wrong answers

Option B is wrong because configuring AD FS as the identity provider does not inherently block legacy authentication; AD FS can still accept legacy authentication requests unless explicitly configured to block them, and it does not enforce Conditional Access policies for cloud apps as effectively as Entra ID. Option C is wrong because deploying Microsoft Entra Application Proxy for all legacy apps provides secure remote access but does not block legacy authentication protocols; the apps themselves may still use basic authentication, which bypasses Conditional Access. Option D is wrong because enabling pass-through authentication (PTA) forwards authentication requests to on-premises AD but does not block legacy authentication; PTA works with modern authentication but legacy protocols still bypass Conditional Access unless explicitly blocked.

504
Multi-Selecthard

Your organization is implementing a secure DevOps pipeline for Azure. You need to ensure that secrets (e.g., API keys) are not stored in source code and that access to production resources is controlled. Which THREE practices should you implement?

Select 3 answers
A.Store secrets in Azure DevOps pipeline variables with encryption enabled
B.Use Azure Key Vault to store secrets and retrieve them at deployment time
C.Use Azure DevOps variable groups linked to Azure Key Vault
D.Store secrets in a configuration file in a private Git repository
E.Use managed identities for Azure resources to authenticate to Key Vault
AnswersB, C, E

Azure Key Vault is the centralized, hardware-backed secret store that offers fine-grained access policies, automated certificate/secret rotation, and comprehensive audit logs. Retrieving secrets at deployment time—via tasks like the Azure Key Vault task or by referencing Key Vault in ARM templates—ensures releases always use the current secret version and never hardcode credentials in code or config files. This pattern also enables legitimate emergency credential rollover without pipeline modifications.

Why this answer

Option B is correct because Azure Key Vault is the dedicated Azure service for centrally storing and managing secrets such as API keys, with encryption at rest and fine-grained access policies, so pipeline code never contains the secret values. Option C is correct because Azure DevOps variable groups can be linked to Azure Key Vault, which lets pipelines consume Key Vault secrets as variables at runtime without duplicating or hardcoding them in the pipeline definition. Option E is correct because managed identities for Azure resources give the pipeline or compute an automatically managed identity in Microsoft Entra ID, allowing it to authenticate to Key Vault without storing credentials, which directly supports controlled access to production resources.

Option A is not correct because pipeline variables with encryption enabled still store the secret within Azure DevOps rather than in a dedicated vault, lacking Key Vault's centralized governance, rotation, and auditing. Option D is not correct because a configuration file in a private Git repository still places secrets in source control, which is exactly the practice the scenario requires avoiding.

Exam trap

SC-100 often tests the misconception that encrypted pipeline variables or private Git repos are acceptable secret stores, when only a dedicated secrets manager with managed identity authentication meets the zero-trust bar.

505
MCQhard

Fabrikam uses Microsoft Entra ID P2 and Microsoft Defender for Identity. The security operations team wants to detect and respond to suspicious activities such as pass-the-hash attacks and reconnaissance attempts against on-premises Active Directory Domain Services (AD DS) domain controllers. They need a solution that provides behavioral analytics and integrates with Microsoft Sentinel for incident correlation. What should you include in the design?

A.Deploy Microsoft Defender for Identity sensors on domain controllers and configure Microsoft Sentinel to ingest Defender for Identity alerts.
B.Configure Microsoft Entra ID Protection risk policies and stream risk detections to Microsoft Sentinel.
C.Enable Microsoft Defender for Cloud Apps anomaly detection policies and connect them to Microsoft Sentinel.
D.Install Microsoft Monitoring Agent on domain controllers and create custom log queries in Microsoft Sentinel to detect suspicious activity.
AnswerA

This is correct because Microsoft Defender for Identity sensors installed on domain controllers monitor AD DS traffic and use behavioral analytics to detect advanced attacks like pass-the-hash and reconnaissance. Integrating with Microsoft Sentinel allows centralized incident correlation and response. This directly meets the requirement for detecting on-premises AD DS threats and integrating with Sentinel.

Why this answer

Microsoft Defender for Identity sensors on domain controllers provide deep behavioral analytics and detect advanced on-premises AD DS attacks such as pass-the-hash and reconnaissance. Integrating Defender for Identity with Microsoft Sentinel enables centralized incident correlation and automated response. This combination directly satisfies the requirement for detecting on-premises threats and integrating with Sentinel for a comprehensive security operations solution.

Exam trap

The trap here is confusing Microsoft Entra ID Protection, which focuses on cloud identity risks, with Microsoft Defender for Identity, which monitors on-premises Active Directory Domain Services for advanced attacks.

506
MCQeasy

Your company uses Microsoft Defender for Cloud Apps to discover shadow IT. You need to ensure that data exfiltration from sanctioned cloud apps is blocked in real-time. Which control should you configure?

A.Conditional Access App Control
B.IP address ranges
C.Cloud discovery
D.App connector
AnswerA

Conditional Access App Control is a reverse-proxy based capability that integrates with Azure AD Conditional Access to enforce session policies on sanctioned cloud apps in real time. When a user accesses a configured app, the session is routed through Microsoft Defender for Cloud Apps, giving it the ability to inspect each request and response. This allows granular controls such as blocking downloads, preventing copy/paste, or forcing step-up authentication, which directly mitigates data exfiltration during the active session.

Why this answer

Conditional Access App Control is the correct answer because it enables real-time session monitoring and control over sanctioned cloud apps, allowing you to block data exfiltration actions such as downloads, copy/paste, and uploads via reverse proxy integration with Azure AD Conditional Access. It is specifically designed for inline enforcement on user sessions, which matches the requirement to block exfiltration in real time. IP address ranges are used for defining corporate network boundaries in Cloud Discovery, not for session-level blocking.

Cloud discovery only identifies shadow IT usage from logs and does not enforce real-time controls. App connectors provide API-based visibility and governance for sanctioned apps but do not block user actions in real time.

507
MCQhard

A company uses Azure Policy to enforce compliance. They have a custom policy that denies creation of storage accounts without encryption enabled. A developer reports that they cannot create a storage account even though they specified encryption. What is the most likely cause?

A.The developer does not have 'Microsoft.Authorization/policyAssignments/write' permission
B.The policy effect is set to 'audit' instead of 'deny'
C.The policy's 'then' block uses 'deny' but the condition logic evaluates the 'encryption' property incorrectly
D.The policy is scoped to a management group that includes the developer's subscription
AnswerC

A deny policy can block a resource if the condition evaluates to true, but the condition must reference the correct property path via an Azure Policy alias. In this scenario, the condition likely uses an incorrect field or alias for the encryption property, causing the policy engine to consider the resource non-compliant even when encryption is properly configured. For example, using 'properties.encryption.enabled' instead of the correct alias 'Microsoft.Storage/storageAccounts/encryption.services.blob.enabled' can make the condition always true. This mis-evaluation leads the deny effect to fire incorrectly, preventing the storage account from being created.

Why this answer

The most likely cause is that the policy's condition logic incorrectly evaluates the 'encryption' property. Azure Policy uses JSON-based condition expressions to check resource properties; if the condition does not match the actual property path (e.g., 'properties.encryption.enabled' vs. 'properties.encryption') or uses an incorrect operator, the deny effect will trigger even when encryption is specified. This is a common misconfiguration in custom policies.

Exam trap

The trap here is that candidates often assume permission issues (Option A) or scope problems (Option D) are the cause, but the real issue is a misconfigured condition in the policy definition that fails to correctly match the encryption property.

How to eliminate wrong answers

Option A is wrong because 'Microsoft.Authorization/policyAssignments/write' permission is required to assign policies, not to create resources; the developer only needs contributor or owner permissions on the resource scope to create storage accounts. Option B is wrong because if the policy effect were set to 'audit', it would only log non-compliance without blocking creation, so the developer would succeed in creating the account. Option D is wrong because scoping a policy to a management group that includes the developer's subscription would apply the policy correctly; it does not inherently cause a false deny—the issue is with the policy logic, not the scope.

508
MCQmedium

A security architect is designing a data protection strategy for a Microsoft 365 tenant. The company must prevent users from sharing sensitive documents with external users via SharePoint Online. They want to apply a policy that automatically detects sensitive content and blocks external sharing. Which Microsoft Purview solution should they use?

A.Sensitivity labels
B.Retention policies
C.Data Loss Prevention (DLP) policy
D.Microsoft Purview Information Protection
AnswerC

Data Loss Prevention (DLP) policies are purpose-built to detect sensitive information (e.g., credit card numbers, PII) using sensitive info types and then take protective actions including blocking external sharing. In Microsoft Purview, a DLP policy can be scoped to SharePoint/OneDrive and configured with a rule that blocks sharing outside your organization while allowing users to override with justification, making it the correct control for this scenario.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies can detect sensitive data and block external sharing. Option C is correct. Option A is wrong because sensitivity labels require manual application or automatic classification, but blocking external sharing is typically done by DLP.

Option B is wrong because retention policies are for data retention, not blocking sharing. Option D is wrong because Microsoft Purview Information Protection is the umbrella, but the specific policy is DLP.

509
Multi-Selecteasy

You are designing a secure infrastructure for an Azure Kubernetes Service (AKS) cluster that will host sensitive workloads. Which TWO configurations should you implement to secure the cluster?

Select 2 answers
A.Enable Azure AD integration for role-based access control (RBAC).
B.Enable Azure Monitor for containers.
C.Enable the HTTP application routing add-on.
D.Use Azure AD pod identity to provide identities for pods.
E.Enable the cluster autoscaler.
AnswersA, D

Integrating Azure AD with AKS for role-based access control (RBAC) provides a centrally managed, authenticated identity for every human user who accesses the cluster. These identities are then mapped to Kubernetes RBAC roles and cluster roles, enabling granular, least-privilege authorization. This control also supports conditional access policies, multi-factor authentication, and comprehensive audit logs for cluster access, making it the fundamental security control for controlling who can perform administrative actions.

Why this answer

Option A is correct because enabling Azure AD integration for RBAC ties Kubernetes authorization to Azure AD identities and group memberships, so cluster access is centrally governed and auditable rather than relying on static client certificates or local accounts. Option D is correct because Azure AD pod identity (now largely superseded by Azure Workload Identity) lets pods obtain Azure AD tokens via managed identities, eliminating the need to store credentials or secrets in containers for accessing Azure resources like Key Vault. Option B is not a security control but an observability feature, so it does not itself secure the cluster.

Option C is incorrect and even risky, since the HTTP application routing add-on exposes an ingress endpoint and is intended for dev/test, not hardened production workloads. Option E is a scaling feature that improves availability and cost, not a security configuration.

510
MCQeasy

Your organization has a Microsoft 365 E5 subscription and wants to detect insider data exfiltration attempts. You need to design a solution that can identify users copying sensitive data to personal cloud storage services. Which Microsoft Purview capability should you use?

A.Data Loss Prevention (DLP) policies
B.eDiscovery (Premium)
C.Communication Compliance
D.Insider Risk Management
AnswerD

Insider Risk Management correlates signals such as file copies to personal cloud storage, detecting exfiltration intent rather than only content matches. This satisfies the requirement to identify users moving sensitive data to unsanctioned services, which DLP alone cannot contextualise.

Why this answer

Microsoft Purview Insider Risk Management is designed to detect, investigate, and act on risky user activities such as data exfiltration to personal cloud storage. It uses machine learning and policy templates to correlate signals like unusual downloads, uploads to personal cloud services, and other indicators of insider risk. DLP policies enforce data handling rules but do not focus on detecting insider intent or anomalous behavior.

Exam trap

SC-100 often tests the boundary between DLP (policy enforcement) and Insider Risk Management (behavioral detection), so candidates who see 'sensitive data' and pick DLP miss the insider threat detection requirement.

How to eliminate wrong answers

Option A is wrong because DLP policies prevent sharing of sensitive data based on content and context, but they are enforcement-focused and do not provide the behavioral analytics and investigation workflow for insider exfiltration. Option B is wrong because eDiscovery (Premium) is for legal hold, identification, and collection of content for litigation or investigations, not proactive detection of insider risk. Option C is wrong because Communication Compliance monitors communications for policy violations (e.g., harassment, sensitive info in chat), not data exfiltration to cloud storage.

511
MCQmedium

You are the security architect for a company that uses Microsoft Defender for Cloud. The company has Azure virtual machines (VMs) and on-premises Windows Servers onboarded to Microsoft Defender for Servers Plan 2. The security team requires that all servers be protected against fileless attacks and that suspicious process behavior be detected in near real-time. You need to recommend a solution that meets these requirements while minimizing administrative effort. What should you include in your recommendation?

A.Enable just-in-time (JIT) VM access for all servers to limit exposure to brute-force attacks.
B.Configure adaptive application controls in Microsoft Defender for Cloud to allow only approved applications to run on the servers.
C.Deploy the Log Analytics agent to all servers and create custom alerts based on Windows Security event logs.
D.Enable Microsoft Defender for Endpoint integration and ensure that the automatic provisioning of the Microsoft Defender for Endpoint agent is turned on for all supported machines.
AnswerD

Defender for Servers Plan 2 includes integration with Microsoft Defender for Endpoint, which provides endpoint detection and response (EDR) capabilities such as fileless attack detection and behavioral monitoring. Enabling automatic provisioning ensures the agent is deployed to all supported machines without manual intervention, meeting the near real-time detection and minimal administrative effort requirements.

Why this answer

The requirement is for advanced endpoint detection and response, specifically fileless attack detection and behavioral monitoring. Microsoft Defender for Servers Plan 2 includes Defender for Endpoint integration, which delivers these capabilities. Automatic provisioning ensures the agent is deployed to all supported machines with minimal administrative effort, satisfying both the technical and operational requirements.

Exam trap

The trap here is confusing network access control features like just-in-time VM access with endpoint detection and response capabilities, which are distinct and serve different security purposes.

512
MCQmedium

A company is implementing a zero-trust security model. They need to enforce conditional access policies that require device compliance from Microsoft Intune. However, some users report being blocked when using personal devices that are not enrolled. What is the best approach to allow access while maintaining security?

A.Allow all devices but monitor with Defender for Cloud Apps
B.Require app protection policies via Microsoft Intune
C.Block all non-compliant devices
D.Require device enrollment for all devices
AnswerB

App protection policies via Microsoft Intune are correct because they apply conditional access at the app layer, safeguarding corporate data within managed applications even on unenrolled, personally owned devices. These policies enforce PIN, encryption, and restricted copy-paste, and can remotely wipe corporate data selectively. This approach meets zero trust requirements for identity and data protection without the privacy invasive step of full device management.

Why this answer

Microsoft Intune app protection policies (APP) can enforce data protection and access controls on personal devices without requiring full enrollment. This allows the company to maintain a zero-trust posture by applying conditional access policies that check for app-level compliance, such as requiring a managed browser or blocking copy/paste, while still permitting access from unenrolled personal devices. This approach aligns with the zero-trust principle of 'never trust, always verify' by verifying device health at the application layer rather than the device layer.

Exam trap

The trap here is that candidates often assume device compliance (via Intune enrollment) is the only way to enforce zero-trust access, overlooking that app protection policies can achieve similar security controls on unmanaged devices without requiring full device enrollment.

How to eliminate wrong answers

Option A is wrong because merely monitoring with Defender for Cloud Apps does not enforce any access control; it only provides visibility, leaving the organization vulnerable to non-compliant devices accessing sensitive data. Option C is wrong because blocking all non-compliant devices would deny access to all personal devices, which contradicts the requirement to allow access while maintaining security. Option D is wrong because requiring device enrollment for all devices would force users to enroll personal devices, which is often impractical and violates privacy, and does not address the scenario where users need to use unenrolled personal devices.

513
MCQeasy

Your organization uses Microsoft Defender for Cloud to secure a hybrid environment. You need to ensure that virtual machines running on-premises are assessed for security misconfigurations. What should you deploy?

A.Log Analytics agent on the on-premises servers
B.Microsoft Defender for Cloud's Vulnerability Assessment solution
C.Azure Arc on the on-premises servers
D.Azure Policy guest configuration
AnswerC

Azure Arc-enabled servers uses the Connected Machine agent to register on-premises machines as full Azure resources with resource IDs in Azure Resource Manager. This registration is what enables Defender for Cloud to perform security assessments, monitor for vulnerabilities, and produce compliance recommendations across hybrid workloads. By placing the on-premises server under Azure's management plane, Arc is the essential prerequisite that unlocks Defender for Cloud's full set of features for machines outside Azure.

Why this answer

Azure Arc on the on-premises servers (option C) is correct because Azure Arc projects non-Azure machines into Azure as connected machine resources, which is the prerequisite for Defender for Cloud to assess on-premises VMs for security misconfigurations via the Azure Monitor Agent and its recommendations. Without Arc-enabling the servers, Defender for Cloud cannot treat them as supported compute resources for misconfiguration assessment. Option A (Log Analytics agent) only collects log/telemetry data and does not by itself enable Defender for Cloud's security posture assessment of on-premises machines.

Option B (Vulnerability Assessment solution) addresses CVE scanning rather than general security misconfiguration assessment, and it also depends on the machine already being onboarded. Option D (Azure Policy guest configuration) audits settings inside Azure VMs and Arc-enabled machines but is not the deployment that enables Defender for Cloud assessment of on-premises servers.

514
MCQeasy

Your company is deploying Azure Kubernetes Service (AKS) and needs to secure container workloads. You must ensure that only approved container images from a trusted Azure Container Registry (ACR) can be deployed. What should you implement?

A.Enable Azure AD integration for AKS.
B.Apply an Azure Policy initiative to only allow images from a specific ACR.
C.Use Azure Key Vault to store container image credentials.
D.Configure network policies in AKS to restrict egress traffic.
AnswerB

Azure Policy provides a built-in initiative for AKS that includes the 'Kubernetes cluster containers should only use allowed images' policy, which is enforced by the azurepolicy add-on acting as an admission controller. When a pod is created, the add-on intercepts the admission request, parses each container's image reference using Rego constraints, and compares the registry hostname against the allowed patterns you define in the policy parameters (e.g., yourACR.azurecr.io/*). If the image does not match the whitelist, the API server rejects the deployment before any workload is scheduled, providing a hard guarantee at the Kubernetes control plane. This is precisely the required capability: enforcing image source at pod creation time, independent of any credentials or network paths.

Why this answer

Azure Policy for AKS can enforce admission control on the cluster so that only container images originating from an approved Azure Container Registry are admitted, which directly satisfies the requirement to restrict deployments to trusted ACR images. The built-in initiative/policy (for example, 'Kubernetes cluster containers should only use allowed images') evaluates image references against an allowlist of registry prefixes and denies non-compliant pods. Azure AD integration (A) handles authentication and RBAC for cluster access, not image provenance.

Key Vault (C) stores secrets such as registry credentials but does not restrict which images can be deployed. Network policies (D) control pod-level traffic flows and cannot enforce image registry allowlisting.

515
MCQhard

A company uses Microsoft Defender for Endpoint to protect endpoints. They want to configure attack surface reduction rules to block executable files from running unless they meet a specific prevalence, age, or trust level. Which ASR rule should they enable?

A.Block Office communication application from creating child processes
B.Block credential stealing from the Windows local security authority subsystem
C.Block untrusted and unsigned processes that run from USB
D.Block executable files from running unless they meet a prevalence, age, or trusted list criteria
AnswerD

This is the exact Microsoft Defender for Endpoint ASR rule that uses cloud-delivered reputation to block executable files that lack sufficient prevalence, are too new (low age), or do not appear on a trusted list. Before allowing the process to run, the endpoint consults Microsoft's reputation service and enforces the decision based on those collective metadata signals. This behavior directly matches the scenario in the question, making it the correct choice.

Why this answer

The ASR rule 'Block executable files from running unless they meet a prevalence, age, or trusted list criteria' (GUID: 01443614-cd74-433a-b99e-2ecdc07bfc25) is specifically designed to block executables that do not meet Microsoft's cloud-based prevalence, age, or trustworthiness criteria. This rule uses the Microsoft Intelligent Security Graph to evaluate files against global telemetry, blocking those that are new, rare, or unsigned, which directly matches the requirement to block executables based on prevalence, age, or trust level.

Exam trap

The trap here is that candidates confuse the USB-specific rule (Option C) with the global executable prevalence rule (Option D), because both mention 'untrusted' or 'unsigned', but only Option D explicitly includes prevalence, age, and trusted list criteria as stated in the question.

How to eliminate wrong answers

Option A is wrong because 'Block Office communication application from creating child processes' (GUID: 26190899-1602-49e8-8b27-eb1d0a1ce869) targets child processes spawned by Office communication apps (e.g., Outlook, Skype) to prevent lateral movement via macro-based attacks, not executable file prevalence or trust. Option B is wrong because 'Block credential stealing from the Windows local security authority subsystem' (GUID: 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2) protects LSASS memory from credential theft tools like Mimikatz, not executable file execution policies. Option C is wrong because 'Block untrusted and unsigned processes that run from USB' (GUID: b2b3f03d-6a4c-4b7e-8c97-3f0e5c7b8a9d) only applies to USB-removable media, not all executable files, and does not consider prevalence or age criteria.

516
Multi-Selectmedium

You need to design a secure solution for a web application that authenticates users via Microsoft Entra ID and calls a downstream API. Which TWO should you implement to secure the application? (Choose TWO.)

Select 2 answers
A.Use the OAuth 2.0 authorization code flow with PKCE.
B.Store application secrets in Azure Key Vault.
C.Store application secrets in app configuration files.
D.Use the OAuth 2.0 client credentials flow.
E.Use shared access signatures (SAS) for API authentication.
AnswersA, B

The OAuth 2.0 authorization code flow with PKCE is the recommended authentication flow for web applications that need to authenticate users and obtain access tokens for downstream APIs. It provides proof of possession and mitigates interception attacks.

Why this answer

Option A is correct because the OAuth 2.0 authorization code flow with PKCE is the recommended pattern for interactive web applications that sign users in through Microsoft Entra ID and then call a downstream API on the user's behalf; PKCE protects the authorization code exchange against interception, and the resulting access token is presented to the API. Option B is correct because confidential client applications still need credentials (client secrets or certificates), and Azure Key Vault provides centralized, access-controlled, audited storage for those secrets instead of leaving them in code or config. Option C is wrong because storing secrets in app configuration files exposes them to anyone with file or repository access and is not a secure secret-management practice.

Option D is wrong for this scenario because the client credentials flow is a daemon/app-only flow with no user context, so it cannot authenticate interactive users. Option E is wrong because shared access signatures are an Azure Storage authorization mechanism, not an authentication protocol for a Microsoft Entra ID-protected web API.

517
MCQmedium

You are designing a secure hybrid network for a multinational company. They require encrypted communication between on-premises data centers and Azure, with high availability and no single point of failure. Which solution should you recommend?

A.Deploy ExpressRoute with a site-to-site VPN as a failover.
B.Deploy a site-to-site VPN over the internet with two active VPN devices.
C.Deploy Azure Virtual WAN with point-to-site VPN for each data center.
D.Deploy ExpressRoute without encryption and rely on Microsoft backbone security.
AnswerA

ExpressRoute offers a private, dedicated, and low-latency path from on-premises data centers to Azure, ensuring reliable connectivity that avoids the public internet. By pairing ExpressRoute with a site-to-site VPN as a failover, you add an encrypted tunnel over the internet or over the ExpressRoute circuit itself, satisfying both encryption and high-availability requirements. This hybrid approach provides a robust connection that meets strict enterprise security policies while maintaining business continuity during a primary circuit failure.

Why this answer

Option A is correct because ExpressRoute provides a private, high-bandwidth dedicated connection to Azure, and pairing it with a site-to-site VPN failover ensures encrypted traffic and eliminates a single point of failure if the ExpressRoute circuit goes down. The VPN failover also satisfies the encryption requirement since ExpressRoute by itself does not encrypt data in transit. Option B provides encryption and redundancy but relies solely on internet-based VPN, which lacks the dedicated private connectivity and predictable performance of ExpressRoute.

Option C is wrong because point-to-site VPN is designed for individual client devices, not data center-to-Azure connectivity. Option D is wrong because ExpressRoute without encryption does not meet the encrypted communication requirement, and relying only on Microsoft backbone security does not provide the required encryption or redundancy.

518
MCQhard

Your organization has a Microsoft Defender for Cloud Apps policy that detects suspicious OAuth app permissions. You need to ensure that when a high-risk app is detected, the app is automatically disabled and the user is notified. What is the most efficient design?

A.Use the 'Disable app' governance action in the policy, and configure email notification
B.Configure the policy to notify the user via email
C.Send the alert to Microsoft Sentinel and create an incident with a playbook
D.Create a Power Automate flow that triggers on the alert to disable the app
AnswerA

The 'Disable app' governance action is a native policy response in Microsoft Defender for Cloud Apps that instantly revokes access to the connected third-party app. Because it is a built-in governance action, you can also enable email notification in the same policy to alert the affected user, achieving both remediation and communication in one cohesive, low-latency step without any external orchestration.

Why this answer

Option A is correct because Microsoft Defender for Cloud Apps policies natively support governance actions such as 'Disable app,' which can be applied automatically when a policy match occurs, and the same policy can be configured to send email notifications to affected users, making this the most efficient single-policy design. Option B only notifies the user and does not disable the high-risk app, so it fails the requirement. Option C adds unnecessary complexity by routing the alert to Microsoft Sentinel and building a playbook, which is not the most efficient approach when the native governance action exists.

Option D relies on an external Power Automate flow triggered by the alert, which is also less efficient than using the built-in 'Disable app' governance action.

519
MCQmedium

A global retail company, Northwind Traders, is adopting a cloud-first strategy using Azure and Microsoft 365. They have a large number of temporary seasonal workers who need access to specific applications and data for limited periods. The security team wants to minimize the risk of standing privileges and ensure that access is granted only when needed and for a limited duration. They also need to audit all privileged access actions. The environment includes Microsoft Entra ID, Azure resources, and Microsoft 365 services. You need to design a privileged access strategy that follows the principle of least privilege and aligns with Microsoft's best practices for privileged identity management. What should you recommend?

A.Use Microsoft Entra Privileged Identity Management (PIM) to grant just-in-time access to Azure AD roles and Azure resources. Configure approval workflows for high-privilege roles. Set maximum activation durations. For non-Azure resources, use Privileged Access Groups (PAG) to manage access. Enable audit logging to a Log Analytics workspace for monitoring.
B.Create a custom role in Azure AD with limited permissions. Assign the role to a security group. Have users request access via a manual email process. The IT team approves and assigns the group membership temporarily.
C.Assign permanent roles to seasonal workers for the duration of their contract. Use Azure AD access reviews to periodically confirm access. Enable Azure AD audit logs. Use Conditional Access to require MFA for privileged roles.
D.Create separate Azure AD roles for each seasonal worker with granular permissions. Use Azure AD Identity Governance to automate access requests. Do not enable PIM to reduce complexity.
AnswerA

This is correct because Microsoft Entra Privileged Identity Management (PIM) provides just-in-time (JIT) administrative access, meaning users get the rights only when needed and for a limited, configurable duration. For high-privilege roles, you can require approval workflows so that activations are explicitly authorized, and setting maximum activation durations enforces a time-bound window that minimizes standing privilege. For non-Azure resources such as on-premises apps or Azure AD-joined groups, Privileged Access Groups (PAG) extend PIM's JIT and approval controls to group membership. Additionally, routing audit logs to a Log Analytics workspace centralizes monitoring and enables alerting on suspicious activations, which satisfies both security and compliance requirements.

Why this answer

It leverages Microsoft Entra Privileged Identity Management (PIM) to enforce just-in-time (JIT) access for Azure AD roles and Azure resources, aligning with the principle of least privilege and minimizing standing privileges. It includes approval workflows for high-privilege roles, maximum activation durations to limit exposure, and Privileged Access Groups (PAG) to manage access to non-Azure resources like Microsoft 365 workloads. Audit logging to a Log Analytics workspace provides comprehensive monitoring of all privileged actions, meeting the auditing requirement.

Exam trap

The trap here is that candidates may assume permanent role assignments with periodic access reviews are sufficient, but this fails to eliminate standing privileges between reviews, which is the core risk the question targets.

How to eliminate wrong answers

Option B is wrong because a manual email process for access requests is insecure, lacks automation, and does not enforce just-in-time activation or time-bound access, violating the requirement to minimize standing privileges. Option C is wrong because assigning permanent roles to seasonal workers for the duration of their contract creates standing privileges, which contradicts the goal of granting access only when needed and for a limited duration; access reviews alone do not prevent persistent access between reviews. Option D is wrong because creating separate Azure AD roles for each seasonal worker is administratively unsustainable and violates least privilege by not using PIM, which is essential for JIT activation and approval workflows; disabling PIM increases complexity and risk.

520
MCQeasy

Your company uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate Exchange Online mailboxes. Which conditional access policy setting should you configure?

A.Grant: Require device to be marked as compliant.
B.Grant: Require approved client app.
C.Grant: Require multifactor authentication.
D.Grant: Require Intune enrollment.
AnswerA

The 'Require device to be marked as compliant' conditional access grant checks the device's compliance state as reported by Intune via Microsoft Entra ID device registration. Intune evaluates compliance policies (such as OS version, encryption, and threat level) and sets the device state, which Azure AD enforces during sign-in. This directly blocks non-compliant devices from accessing resources.

Why this answer

The correct option is A, Grant: Require device to be marked as compliant, because this conditional access grant control evaluates the device's compliance state reported by Intune and only allows access to Exchange Online when the device meets the assigned compliance policy. This directly enforces the requirement that only compliant devices can reach corporate mailboxes. Option B, Require approved client app, restricts which apps can access the resource but does not verify device compliance.

Option C, Require multifactor authentication, strengthens user sign-in verification but does not assess the device's compliance status. Option D, Require Intune enrollment, only ensures the device is managed by Intune, not that it satisfies the compliance policy.

521
MCQeasy

Your company uses Microsoft Purview to classify and protect sensitive data. You need to ensure that when a user sends an email containing a credit card number, the email is automatically encrypted and a notification is sent to the user. Which Microsoft Purview feature should you configure?

A.Sensitivity labels
B.Audit log policies
C.Insider risk management policies
D.Data Loss Prevention (DLP) policies
AnswerD

Microsoft Purview Data Loss Prevention (DLP) policies inspect email messages and attachments in transit against sensitive information types and trainable classifiers. When a matching sensitive item is detected, DLP can automatically enforce actions such as applying encryption (via Azure Rights Management), blocking delivery, or sending policy tips and notifications to users. This makes DLP the correct control for content-triggered automated encryption of outbound emails.

Why this answer

Data Loss Prevention (DLP) policies in Microsoft Purview are the correct choice because they can inspect email content for sensitive information types such as credit card numbers and trigger protective actions like encryption and user notifications. DLP rules support conditions based on sensitive info types and actions including encrypting messages and sending policy tips or notifications to the sender. Sensitivity labels apply protection based on manual or auto-labeling, but they do not natively detect credit card numbers in transit and send user notifications in the same rule-based way.

Audit log policies only record activity for later review, and insider risk management policies focus on detecting risky user behavior rather than automatically encrypting an email containing a credit card number.

522
Multi-Selecthard

Your organization uses Microsoft 365 and wants to implement a data loss prevention (DLP) strategy. You need to ensure that sensitive data is protected both at rest and in transit, and that incidents are automatically reported to the security team. Which THREE actions should you take?

Select 3 answers
A.Deploy Microsoft Intune to control app permissions on mobile devices
B.Implement Conditional Access policies to block external sharing of sensitive data
C.Enable Endpoint DLP for Windows 10/11 devices
D.Configure Microsoft Purview DLP policies for Exchange, SharePoint, and OneDrive
E.Configure DLP incident reports to be sent to the security team via email or Teams
AnswersC, D, E

Endpoint DLP extends Microsoft Purview DLP to devices, inspecting content in documents, emails, and clipboard operations. When a policy match occurs, it blocks the action and raises an alert that appears in the Purview DLP incident report. This directly supports the requirement to protect data in use and report incidents.

Why this answer

Option C is correct because Endpoint DLP extends Microsoft Purview DLP to Windows 10/11 devices, monitoring and restricting sensitive data actions on endpoints (copy to USB, print, upload to cloud) so data at rest on devices and in use is protected. Option D is correct because configuring Microsoft Purview DLP policies for Exchange Online, SharePoint Online, and OneDrive for Business enforces protection for data at rest and in transit across email and cloud storage workloads, detecting sensitive information types and blocking or auditing risky sharing. Option E is correct because configuring DLP incident reports to be sent to the security team via email or Teams ensures automatic alerting and reporting of policy matches, satisfying the requirement that incidents are automatically reported.

Option A is not correct because Intune app protection policies manage mobile app permissions and are not the DLP mechanism that detects and protects sensitive data at rest and in transit. Option B is not correct because Conditional Access governs sign-in and access conditions, not DLP content inspection or automatic incident reporting for sensitive data.

523
MCQmedium

Your organization is deploying a new line-of-business application on Azure App Service. The app must authenticate users from Microsoft Entra ID and also access a downstream API that requires a client secret. You need to recommend the most secure method for managing the client secret. What should you use?

A.Store the secret in the Azure AD app registration manifest.
B.Store the secret in an App Service application setting.
C.Store the secret in Azure Key Vault and use a Key Vault reference in App Service.
D.Store the secret in the application code as a constant.
AnswerC

Correct. Azure Key Vault provides secure, centralized storage for secrets with encryption and access auditing. App Service can reference Key Vault secrets via Key Vault references, using a managed identity to authenticate without exposing the secret.

Why this answer

Storing the client secret in Azure Key Vault and referencing it from App Service via a Key Vault reference is the most secure method. Key Vault provides centralized secret management, access control via Entra ID, auditing, rotation capabilities, and hardware-backed protection (HSM) for keys. App Service can resolve Key Vault references at runtime using its managed identity, so the secret never appears in application settings or code.

Exam trap

SC-100 often tests the misconception that App Service application settings are secure because they are 'encrypted' — candidates may pick option B, but the exam expects Key Vault with managed identity as the only answer that provides centralized, auditable, rotatable secret management.

How to eliminate wrong answers

Option A is wrong because storing a secret in the app registration manifest exposes it in a readable configuration file and lacks rotation/audit controls. Option B is wrong because App Service application settings are stored in plaintext (or encrypted at rest but visible to anyone with portal/API access) and do not provide centralized rotation or auditing. Option D is wrong because hardcoding a secret in application code embeds it in source control and build artifacts, making rotation and leak remediation extremely difficult.

524
MCQhard

Refer to the exhibit. A security architect reviews the Azure AD Conditional Access policy JSON. The policy is intended to require MFA for all users accessing Azure management (Microsoft Azure Management app ID 797f4846-ba77-4853-9e6f-4433c3e1d1c5), except for the BreakGlassAdmin account and from trusted locations. However, some users report being prompted for MFA even when connecting from the corporate office (which is marked as a trusted location). What is the most likely cause?

A.The corporate office location is not correctly defined as a trusted location in Azure AD
B.The grant controls operator is set to 'OR' instead of 'AND'
C.The policy is in 'Report-only' mode
D.The policy applies to all cloud apps, not just Azure management
AnswerA

The conditional access policy is configured to exclude trusted locations, but the corporate office IP range is not added as a named location in Azure AD. Without that configuration, the corporate office is not considered a trusted location by the policy engine. As a result, the 'AllTrusted' exclusion does not apply to corporate IPs, so the policy enforces MFA for those sign-ins, causing users at the office to be prompted unexpectedly.

Why this answer

The policy is designed to require MFA for all users accessing Azure management, except for the BreakGlassAdmin account and from trusted locations. If the corporate office location is not correctly defined as a trusted location in Azure AD, the Conditional Access policy will not recognize it as an exception, and users connecting from that location will still be prompted for MFA. This mismatch between the intended trusted location definition and the actual location configuration is the most likely cause of the unexpected MFA prompts.

Exam trap

The trap here is that candidates often assume the policy logic is flawed (e.g., grant operator or app scope) when the real issue is a misconfiguration in the location definition, which is a common oversight in Conditional Access troubleshooting.

How to eliminate wrong answers

Option B is wrong because the grant controls operator being set to 'OR' would actually make the policy less restrictive (allowing MFA or other controls), not more restrictive, and would not cause unexpected MFA prompts; the issue is about location exclusion, not grant logic. Option C is wrong because if the policy were in 'Report-only' mode, it would not enforce MFA at all—users would not be prompted—so this cannot explain why MFA is being enforced. Option D is wrong because the policy explicitly targets the Microsoft Azure Management app (ID 797f4846-ba77-4853-9e6f-4433c3e1d1c5), not all cloud apps; if it applied to all cloud apps, the behavior would be broader, but the specific complaint is about Azure management access, and the policy scope is correctly set.

525
MCQhard

Your organization uses Microsoft Entra ID with Privileged Identity Management (PIM). You need to design a role activation policy that requires approval from a security group for global administrator roles, but allows self-activation for other roles. What is the correct configuration?

A.Create a single PIM policy for all roles with approver group
B.Configure separate PIM settings per role: Global Administrator requires approval, others self-activate
C.Enable just-in-time access in Azure AD Identity Protection
D.Use Azure AD entitlement management with access packages
AnswerB

This is correct because PIM supports granular, per-role configuration of activation settings, including whether approval is required. For Global Administrator, you can enable 'Require approval to activate' and assign a specific approver group, while leaving other roles configured for self-activation without approval. This balances security for highly sensitive roles with operational efficiency for lower-privilege roles, directly matching the requirement.

Why this answer

Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure role-specific activation settings. By creating separate PIM policies per role, you can require approval for the Global Administrator role while allowing self-activation for other roles. This granular control ensures that high-privilege roles have additional oversight, while lower-privilege roles remain agile.

Exam trap

The trap here is that candidates confuse PIM role-specific policies with broader identity governance tools like entitlement management or Identity Protection, failing to recognize that PIM's granular per-role settings are the correct mechanism for mixed approval requirements.

How to eliminate wrong answers

Option A is wrong because a single PIM policy applies uniformly to all roles, making it impossible to require approval for only Global Administrators while allowing self-activation for others. Option C is wrong because Azure AD Identity Protection focuses on risk-based policies for user sign-ins and sessions, not role activation approval workflows. Option D is wrong because Azure AD entitlement management manages access packages and resource access, not the activation approval process for built-in directory roles like Global Administrator.

Page 6

Page 7 of 9

Page 8

All pages