Courseiva

Microsoft Cybersecurity Architect (SC-100) — Questions 526–600

605 questions total · 9pages · All types, answers revealed

Page 7

Page 8 of 9

Page 9
526
MCQeasy

Your company plans to deploy Microsoft Defender for Cloud to secure a multi-cloud environment that includes Azure, AWS, and GCP. You need to ensure that security recommendations from all three cloud providers are centrally visible. What should you configure?

A.Onboard AWS and GCP accounts to Microsoft Defender for Cloud using the multicloud connectors feature.
B.Deploy Azure Policy on AWS and GCP using Azure Arc to enforce security policies.
C.Ingest security logs from AWS and GCP into Microsoft Sentinel and use workbooks to view recommendations.
D.Connect AWS accounts to AWS Security Hub and GCP accounts to Google Cloud Security Command Center, then view via a single pane of glass.
AnswerA

The native way to extend Defender for Cloud to AWS and GCP is the multicloud connectors feature: for AWS you create a CloudFormation stack that provisions a role with the required read permissions, and for GCP you create a service account and project binding. Once connected, Defender for Cloud automatically aggregates security recommendations, regulatory compliance scores (CIS, PCI DSS, etc.), and workload protection plans across Azure, AWS, and GCP in the same portal blade. This is the intended first-class mechanism and does not require Azure Arc or Sentinel.

Why this answer

The correct option is A: onboarding AWS and GCP accounts to Microsoft Defender for Cloud using the multicloud connectors feature. This is the native capability that lets Defender for Cloud pull security posture and recommendations from AWS and GCP into the same central dashboard as Azure, giving a unified view across all three clouds. Option B is wrong because Azure Policy and Azure Arc govern and configure resources but do not aggregate AWS/GCP security recommendations into Defender for Cloud.

Option C is wrong because Microsoft Sentinel is a SIEM/SOAR for log ingestion and workbooks, not the mechanism that surfaces Defender for Cloud recommendations. Option D is wrong because AWS Security Hub and Google Cloud Security Command Center are separate provider-native tools and do not provide a single centralized Defender for Cloud view.

527
MCQhard

Your company uses Microsoft Intune to manage devices. You need to design a solution that prevents users from installing unauthorized applications on corporate Windows 10 devices. Which Intune policy should you configure?

A.Compliance policy
B.App protection policy (MAM)
C.Device restriction policy (Windows 10)
D.Configuration policy (OMA-URI)
AnswerC

A Windows 10 device restriction profile contains an 'Apps' category with a setting named 'Block installing apps from sources other than Microsoft Store' (the Store-only installation toggle). Setting this to 'Block' enforces the Windows AppRuntime policy that allows or disallows apps based on trusted source. The Intune profile also covers related switches like 'Block all apps from the Microsoft Store,' giving granular control. This is the native, purpose-built mechanism in Microsoft Intune to prevent untrusted app installation.

Why this answer

The correct answer is C, a Device restriction policy (Windows 10), because this policy type includes settings that control app installation behavior on Windows 10 devices, such as blocking users from installing apps from untrusted sources or restricting Microsoft Store access. In Intune, device restriction policies are specifically designed to enforce hardware, software, and app-related restrictions on managed devices, making them the appropriate choice for preventing unauthorized application installations. A compliance policy (A) only evaluates and reports device state against conditions and can trigger conditional access, but it does not directly block app installation.

An app protection policy (B) applies to mobile app management (MAM) for protecting corporate data within apps, not to blocking installation of unauthorized apps on Windows 10. A configuration policy using OMA-URI (D) can set custom CSP settings, but it is not the purpose-built policy for app installation restrictions that the device restriction policy provides.

528
MCQmedium

Your organization uses Microsoft Sentinel to centralize security monitoring. You need to detect anomalous access to a critical Azure SQL Database from unusual geographic locations. Which data connector and analytic rule should you use?

A.Azure SQL Database connector and a custom scheduled query rule with geo-location
B.Azure Active Directory connector and an anomaly rule for sign-ins
C.Windows Security Events connector and a rule for failed logins
D.Azure Activity connector and a rule for resource deletion
AnswerA

The Azure SQL Database connector ingests diagnostic telemetry such as SQLInsights and QueryStoreRuntimeStatistics, which include the client IP address for every connection. A custom scheduled query rule can run KQL to map these IPs to geographic locations (using the GeoIP enrichment or a watchlist) and alert when a connection originates from a country that is abnormal for your environment. This directly captures data-plane connection attempts to Azure SQL, so it is the correct pairing of source and detection logic.

Why this answer

The correct option is A: Azure SQL Database connector and a custom scheduled query rule with geo-location. The Azure SQL Database connector ingests SQL audit and diagnostic logs into Microsoft Sentinel, which include client IP addresses, so a custom scheduled analytics rule can parse those IPs, enrich them with geo-location data (e.g., via the GeoIP watchlist or built-in functions), and alert on access from unusual regions. Option B does not fit because Azure AD sign-in anomaly rules cover identity authentication events, not direct database access.

Option C is wrong because Windows Security Events cover OS-level logons on Windows hosts, not Azure SQL Database access. Option D is wrong because Azure Activity logs track control-plane operations like resource deletion, not data-plane SQL connections.

529
MCQeasy

A company wants to enforce that all administrators use just-in-time (JIT) access to privileged roles in Microsoft Entra ID. Which feature should they enable?

A.Microsoft Entra ID Conditional Access
B.Microsoft Entra ID Privileged Identity Management (PIM)
C.Microsoft Entra ID Access Reviews
D.Microsoft Entra ID Protection
AnswerB

PIM is the Entra ID service purpose-built for just-in-time, time-bound privileged role activation. Administrators are made eligible for roles, and when they need access they activate for a requested duration—optionally with MFA, business justification, and an approval workflow—after which the role expires automatically. This directly replaces permanent 'standing' admin access with auditable, as-needed elevation.

Why this answer

Microsoft Entra ID Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access by enabling time-bound and approval-based role activation. This directly meets the requirement to enforce JIT access for administrators, as PIM allows roles to be activated only when needed and for a limited duration, reducing standing access.

Exam trap

The trap here is that candidates often confuse Conditional Access (which controls access to apps) with PIM (which controls privileged role activation), leading them to select Option A because they think JIT access is a policy-based access control feature.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Conditional Access enforces access policies based on signals like location or device state, but it does not provide time-bound role activation or JIT privileged access. Option C is wrong because Microsoft Entra ID Access Reviews are used to periodically audit and recertify group memberships or role assignments, not to grant or activate privileged roles on demand. Option D is wrong because Microsoft Entra ID Protection detects and responds to identity-based risks (e.g., leaked credentials) but does not manage privileged role activation or JIT access.

530
MCQmedium

Your organization uses Microsoft Defender for Cloud to assess security posture. You need to ensure that your Azure App Service web applications are protected against common web vulnerabilities like SQL injection. What should you enable?

A.Web Application Firewall (WAF) on Azure Front Door
B.Just-in-time (JIT) VM access
C.Adaptive Application Controls
D.Azure DDoS Protection
AnswerA

Web Application Firewall (WAF) on Azure Front Door is the correct choice because it operates at the application layer (Layer 7) and uses managed rule sets (e.g., OWASP Core Rule Set) to inspect incoming HTTP/HTTPS requests for malicious payloads like SQL injection and cross-site scripting. By enforcing these rules at the edge, it blocks attacks before they reach the origin web server. Unlike network-level controls, WAF deeply inspects request bodies and headers, directly mitigating the vulnerability described in the question.

Why this answer

The correct option is A: Web Application Firewall (WAF) on Azure Front Door. A WAF inspects incoming HTTP/HTTPS traffic and applies managed rule sets (such as the OWASP Core Rule Set) to block common web exploits like SQL injection and cross-site scripting before they reach the App Service. Just-in-time (JIT) VM access (B) only brokers temporary, approved RDP/SSH access to virtual machines and has no bearing on web application layer attacks.

Adaptive Application Controls (C) are an Azure Security Center/Defender for Cloud feature that whitelists processes on VMs to detect anomalous execution, not HTTP payloads. Azure DDoS Protection (D) mitigates volumetric and protocol-level network floods, not application-layer injection attacks.

531
MCQmedium

Your company uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. You need to prevent users from sharing credit card numbers via email in Outlook on the web. The policy should notify users when they try to send such data and allow them to override with a business justification. What should you configure?

A.Create a DLP policy with the action 'Audit only' for credit card numbers
B.Create a DLP policy with the action 'Block with override' and enable 'Business justification'
C.Create a DLP policy that encrypts emails containing credit card numbers
D.Create a DLP policy with the action 'Block' for credit card numbers
AnswerB

'Block with override' in Purview DLP halts the sharing of credit card numbers by default, but when 'Business justification' is enabled, users can bypass the block if they provide a reason. This balances security with operational continuity, and because overrides are audited, it maintains accountability while preventing accidental data exposure.

Why this answer

The correct option is B: create a DLP policy with the action 'Block with override' and enable 'Business justification'. This is the only configuration that both prevents users from sending credit card numbers in Outlook on the web and lets them override the block by supplying a business justification, which is exactly what the scenario requires. Option A ('Audit only') merely logs activity without stopping the email, so it does not prevent sharing.

Option C (encrypting emails) addresses confidentiality but does not block or notify the sender with an override path. Option D ('Block') stops the email but provides no override mechanism, so users cannot proceed with a justification.

532
MCQmedium

Refer to the exhibit. A company applies this Azure Policy to their subscription. An administrator tries to create a VM with a public IP address. What will happen?

A.The public IP will be automatically removed
B.The VM creation will be denied
C.The VM will be created, but an alert will be generated
D.The policy will only apply to VMs in a specific resource group
AnswerB

The policy explicitly prohibits the creation of network interfaces that are configured with a public IP, and since a virtual machine must have at least one NIC to boot, any VM deployment that attempts to attach a public IP to its primary NIC will be blocked. The deny effect causes the entire deployment request to fail with a conflict or forbidden error, preventing both the NIC and the VM from being created. This is a hard failure, not a soft warning, because the policy's effect is Deny, not Audit or Modify.

Why this answer

Azure Policy with a 'Deny' effect blocks the non-compliant resource creation request at the Azure Resource Manager layer, so the VM creation with a public IP will be denied. The policy is evaluated during the ARM template/resource deployment, and if the resource violates the rule, the request fails with a policy violation error. This is the intended behavior of a Deny-effect policy assignment.

Exam trap

SC-100 often tests the difference between Azure Policy effects — candidates confuse Deny (blocks creation) with Audit (logs non-compliance) or Modify (changes the resource), and pick 'alert generated' or 'automatically removed' incorrectly.

How to eliminate wrong answers

Option A is wrong because Azure Policy does not modify or remove properties from a resource — it evaluates and either allows, denies, or audits; automatic remediation requires a DeployIfNotExists or Modify effect, not Deny. Option C is wrong because an alert is generated only with an Audit effect (or via Azure Monitor on policy compliance), not with Deny, which blocks the request outright. Option D is wrong because the policy scope is defined by the assignment (subscription, resource group, or management group), and the question states it is applied to the subscription, so it applies to all resource groups within that subscription unless excluded.

533
MCQmedium

Your team develops a web application hosted on Azure App Service. You need to secure the application against common web vulnerabilities like SQL injection and cross-site scripting. What should you implement?

A.Enable Azure Web Application Firewall (WAF) on Azure Front Door or Application Gateway.
B.Store application secrets in Azure Key Vault and enable managed identity.
C.Configure Network Security Groups (NSGs) on the App Service subnet to restrict inbound traffic.
D.Enable Azure DDoS Protection on the virtual network.
AnswerA

Azure WAF on Front Door or Application Gateway is the correct solution because it inspects incoming HTTP(S) requests at Layer 7, specifically filtering for SQL injection, cross-site scripting (XSS), and other OWASP Top 10 attack patterns before they reach the App Service backend. Using managed rule sets such as the OWASP CRS, it provides continuous, low-maintenance adaptability to new attack signatures. This directly addresses the described application vulnerabilities, unlike network- or secret-management controls.

Why this answer

The correct option is A: enabling Azure Web Application Firewall (WAF) on Azure Front Door or Application Gateway, because WAF provides managed rule sets (OWASP Core Rule Set) that inspect HTTP/HTTPS traffic and block layer 7 attacks such as SQL injection and cross-site scripting before they reach the App Service. Options B, C, and D do not address application-layer attacks: Key Vault with managed identity only protects secrets and credentials, NSGs filter traffic by IP/port/protocol at layers 3-4 and cannot detect SQLi or XSS payloads, and Azure DDoS Protection mitigates volumetric network-layer floods rather than web application vulnerabilities.

534
MCQmedium

Your organization is deploying a new web application in Azure and needs to secure it against common web attacks like SQL injection and cross-site scripting. You need to configure a solution that provides centralized protection at the network edge. Which Azure service should you use?

A.Azure Web Application Firewall (WAF) on Azure Application Gateway
B.Network Security Groups (NSGs)
C.Azure DDoS Protection
D.Azure Firewall
AnswerA

Azure Web Application Firewall on Application Gateway inspects HTTP traffic at the edge and applies managed rule sets that block SQL injection and cross-site scripting. Terminating at the gateway gives the centralised, network-edge protection the scenario requires.

Why this answer

Azure Web Application Firewall (WAF) on Azure Application Gateway is correct because it provides centralized, edge-level protection specifically against Layer 7 web attacks such as SQL injection and cross-site scripting (XSS) using OWASP rule sets. It inspects HTTP/HTTPS traffic at the application layer and can be attached to Application Gateway to filter malicious requests before they reach the web application. NSGs operate at Layers 3/4 and only filter traffic by IP, port, and protocol, so they cannot detect SQL injection or XSS payloads.

Azure DDoS Protection mitigates volumetric and protocol-level denial-of-service attacks, not application-layer injection or scripting attacks. Azure Firewall is a stateful Layer 3-7 network firewall with FQDN and threat-intelligence filtering, but it does not provide the dedicated OWASP-based web attack inspection that WAF does.

535
MCQmedium

Refer to the exhibit. You are reviewing a KQL query in Microsoft Sentinel. What is the primary purpose of this query?

A.To identify accounts with multiple failed logon attempts from a single IP.
B.To list all successful logon events in the last 7 days.
C.To calculate the total number of failed logons per hour.
D.To detect account lockout events.
AnswerA

The query aggregates failed sign-in events, grouping by account and source IP address, then filters for counts exceeding a threshold. This surfaces accounts experiencing multiple failed logon attempts from a single IP, indicating possible brute-force or password-spray activity.

Why this answer

The query uses the `SecurityEvent` table and filters for `EventID == 4625`, which indicates a failed logon attempt. By summarizing `count()` by `IPAddress` and `Account` and filtering for `FailedAttempts > 5`, the query identifies accounts with multiple failed logon attempts from a single IP address. This is typical for detecting brute-force or password-spray attacks, making option A correct.

Exam trap

Candidates may confuse EventID 4625 with successful logon (EventID 4624) or account lockout (EventID 4740). They might also overlook that the query groups by both IP and account, not by time, leading them to select options B, C, or D.

How to eliminate wrong answers

Option B is wrong because the query filters for `ResultType == 50057`, which is a failed logon event, not a successful one; successful logons would use `ResultType == 0`. Option C is wrong because the query summarizes by `IPAddress` and `UserPrincipalName`, not by time bins (e.g., `bin(TimeGenerated, 1h)`), so it cannot calculate failed logons per hour. Option D is wrong because account lockout events are represented by a different `ResultType` value (e.g., 50053 or 50074 in Azure AD), and the query does not filter for those codes.

536
MCQmedium

You are reviewing the ARM template snippet for an Azure Storage container. What does the 'denyEncryptionScopeOverride' property set to 'true' ensure?

A.Double encryption is enabled for the container.
B.Encryption at rest is required for all blobs in the container.
C.The container automatically uses a customer-managed key for encryption.
D.Users cannot override the default encryption scope for blobs in this container.
AnswerD

Setting `denyEncryptionScopeOverride` to `true` on a container blocks any client from supplying an encryption scope different from the container's default scope on a per-blob request. As a result, every blob uploaded to this container is encrypted exactly with the default encryption scope, which administrators centrally define and manage. This is essential for compliance scenarios where data must always be encrypted with an approved key or key management policy.

Why this answer

Option D is correct because setting denyEncryptionScopeOverride to true on a container prevents clients from specifying a different encryption scope when uploading blobs, forcing them to use the container's default encryption scope. This property is specifically about locking the encryption scope at the container level, not about enabling or requiring encryption itself. Option A is wrong because double encryption is configured via infrastructure encryption settings, not this property.

Option B is wrong because encryption at rest is always enabled for Azure Storage blobs by default and is not controlled by denyEncryptionScopeOverride. Option C is wrong because customer-managed keys are configured through the account's encryption key source settings, not through this container property.

537
Multi-Selectmedium

Which TWO of the following are benefits of using Microsoft Defender XDR (Extended Detection and Response)? (Choose two.)

Select 2 answers
A.Scans for vulnerabilities in VMs
B.Provides compliance assessments
C.Cross-domain correlation of alerts
D.Replaces the need for a firewall
E.Automated investigation and response
AnswersC, E

Cross-domain correlation of alerts is a core benefit of Microsoft Defender XDR because it ingests signals from Microsoft Defender for Endpoint, Identity, Office 365, and Cloud Apps, and fuses them into a unified incident. This correlation enables security teams to see the full attack chain—such as a phishing email leading to credential theft and lateral movement—rather than investigating disjointed alerts. This is exactly the value that differentiates XDR from single-vector security tools.

Why this answer

Option C is correct because Microsoft Defender XDR is specifically designed to correlate signals and alerts across multiple security domains — endpoints (Defender for Endpoint), identities (Defender for Identity), email and collaboration (Defender for Office 365), and cloud apps (Defender for Cloud Apps) — into unified incidents, which is the core value of an XDR platform. Option E is correct because Defender XDR includes automated investigation and response (AIR) capabilities that use playbooks and automation to investigate alerts, remediate threats, and reduce analyst workload. Option A is not correct because vulnerability scanning of VMs is a function of Microsoft Defender for Cloud (or Defender Vulnerability Management), not the defining benefit of Defender XDR.

Option B is not correct because compliance assessments are provided by Microsoft Purview Compliance Manager and Microsoft Defender for Cloud regulatory compliance dashboards, not by Defender XDR itself. Option D is not correct because Defender XDR is a detection and response platform and does not replace a network firewall, which remains necessary for perimeter and network-layer filtering.

Exam trap

The trap here is that candidates confuse the broad capabilities of the Microsoft security portfolio (e.g., Defender for Cloud, Purview) with the specific scope of Defender XDR, leading them to select features that belong to other services.

538
MCQmedium

Litware, a software development company, has adopted a DevOps culture and uses Azure DevOps for CI/CD pipelines. They deploy applications to Azure Kubernetes Service (AKS) and Azure App Services. The security team wants to ensure that secrets (API keys, connection strings) are not exposed in source code or pipeline logs. They also need to scan container images for vulnerabilities before deployment and ensure that only approved images are used in production. The solution must integrate with Microsoft Defender for Cloud and follow security best practices. What should you include in the design?

A.Use Azure App Configuration to store secrets with encryption. Run vulnerability scans using a third-party tool integrated into the pipeline. Create a custom script to check image registry location.
B.Store secrets in Azure Key Vault and use Azure DevOps Variable Groups linked to Key Vault for retrieval during pipelines. Enable Microsoft Defender for Containers on AKS to scan container images for vulnerabilities. Use Azure Policy (specifically Azure Policy for AKS with Gatekeeper) to enforce that only images from approved registries are deployed.
C.Store secrets as encrypted pipeline variables in Azure DevOps. Use Azure Container Registry (ACR) tasks to scan images. Implement manual approval gates in release pipelines to verify image source.
D.Store secrets in Azure Key Vault but use a custom task to retrieve them. Scan images using Microsoft Defender for Cloud after deployment. Use role-based access control to restrict registry access.
AnswerB

Azure Key Vault is the correct service for secrets because it offers centralized management, access policies, rotation, and auditing; linking Azure DevOps Variable Groups to Key Vault retrieves secrets securely at pipeline runtime without exposing them in logs. Enabling Microsoft Defender for Containers on AKS automatically scans container images in ACR for vulnerabilities and provides runtime threat detection. Azure Policy with Gatekeeper (the AKS admission controller) enforces that only images from approved registries are deployed, providing governance and preventing unauthorized or malicious image usage.

Why this answer

It aligns with security best practices by using Azure Key Vault to securely store secrets and linking them to Azure DevOps Variable Groups for secure retrieval during pipelines, preventing exposure in source code or logs. It enables Microsoft Defender for Containers on AKS to scan container images for vulnerabilities before deployment, and uses Azure Policy with Gatekeeper to enforce that only images from approved registries are deployed, ensuring compliance and integration with Microsoft Defender for Cloud.

Exam trap

The trap here is that candidates often confuse Azure App Configuration with Azure Key Vault for secret storage, or assume that post-deployment scanning is acceptable, but the requirement explicitly demands scanning before deployment and integration with Microsoft Defender for Cloud.

How to eliminate wrong answers

Option A is wrong because Azure App Configuration is not designed for secret storage (it lacks native key rotation and access policies compared to Key Vault), and using a third-party tool for vulnerability scanning and a custom script for registry checks does not integrate with Microsoft Defender for Cloud as required. Option C is wrong because storing secrets as encrypted pipeline variables in Azure DevOps still exposes them in pipeline logs and does not provide centralized secret management or rotation, and ACR tasks scan images only after push, not before deployment, while manual approval gates do not enforce policy-based image source control. Option D is wrong because using a custom task to retrieve secrets from Key Vault bypasses the secure, native integration of Variable Groups linked to Key Vault, and scanning images after deployment (post-deployment) violates the requirement to scan before deployment, while RBAC alone does not enforce that only approved images are used.

539
MCQhard

Your organization uses Microsoft Sentinel for security operations. You need to design a solution to automatically respond to a DDoS attack detected by Azure DDoS Protection. The response should include blocking the attacker's IP address in Azure Firewall and sending an alert to the security team. Which approach should you use?

A.Configure an alert rule in Azure Monitor to send an email to the security team
B.Use Azure Policy to deny network traffic from the attacker's IP range
C.Configure a resource lock on the Azure Firewall to prevent changes
D.Create an automation rule in Microsoft Sentinel that triggers a playbook to block the IP in Azure Firewall
AnswerD

Automation rules in Microsoft Sentinel continuously run on incident creation, updating, or closing events and can invoke an Azure Logic Apps playbook when an incident is triggered. The playbook can use the Azure Firewall connector to add a deny rule for the specific IP, directly modifying the firewall's network rule collection to stop the attack at the network layer. This combines SIEM threat detection with SOAR-driven response, enabling real-time, automated IP blocking without manual intervention and with full audit trail.

Why this answer

Microsoft Sentinel automation rules can trigger a playbook (an Azure Logic App) when a DDoS attack detection alert fires. The playbook can execute an action to block the attacker's IP address in Azure Firewall via its REST API or PowerShell cmdlets, and simultaneously send an alert to the security team (e.g., via email or Teams). This provides an automated, orchestrated response directly from the SIEM, aligning with security operations best practices.

Exam trap

The trap here is that candidates may confuse Azure Monitor alert rules (which only notify) with Sentinel automation rules (which can trigger remediation playbooks), or think Azure Policy can dynamically block IPs when it is actually a static compliance enforcement tool.

How to eliminate wrong answers

Option A is wrong because an Azure Monitor alert rule can only send notifications (e.g., email) and cannot perform remediation actions like blocking an IP in Azure Firewall; it lacks the orchestration capability needed for automated response. Option B is wrong because Azure Policy is a governance tool for enforcing compliance rules on resource configurations (e.g., denying creation of certain resources), not for dynamically blocking network traffic from a specific attacker IP in real time. Option C is wrong because a resource lock on Azure Firewall prevents accidental deletion or modification of the firewall itself, but does not block attacker IPs or send alerts; it actually hinders the automated response by locking the resource.

540
MCQeasy

Your organization is implementing Microsoft Defender for Cloud Apps to protect against malicious OAuth app permissions. Users have been granting permissions to third-party apps that request excessive scopes. What should you configure to automatically revoke such permissions?

A.OAuth app policies in Defender for Cloud Apps
B.Microsoft Intune app protection policies
C.Conditional Access policies
D.Azure AD app permissions management
AnswerA

OAuth app policies in Defender for Cloud Apps are the correct choice because they specifically enable automated governance for third-party applications that have been granted consent in Azure AD. These policies can continuously monitor the app's activity, user involvement, and permissions, and automatically revoke access or apply a quarantine action when the app is deemed risky or exceeds a preset threshold. Unlike manual remediation, these policies execute the revocation directly on the OAuth application, removing its granted permissions without requiring a user to revoke consent manually.

Why this answer

The correct option is A, OAuth app policies in Defender for Cloud Apps. These policies are purpose-built to detect risky or over-privileged OAuth apps and can automatically revoke user-granted permissions or disable the app when it matches conditions such as excessive scopes or low community use. Intune app protection policies (B) govern mobile app data handling (MAM) and do not revoke OAuth consent grants.

Conditional Access policies (C) control sign-in conditions and session access, not OAuth permission revocation. Azure AD app permissions management (D) allows reviewing and revoking consent grants manually but does not provide the automated, risk-based revocation that Defender for Cloud Apps OAuth app policies deliver.

541
MCQmedium

Refer to the exhibit. You are reviewing an ARM template for an Azure storage account. Which security best practice is implemented?

A.Enforce HTTPS traffic only
B.Restrict network access by IP address
C.Deny all network traffic by default
D.Enable soft delete for blobs
AnswerC

Deny all network traffic by default is correct because the storage account template sets the networkAcls.defaultAction property to Deny. With this configuration, any request that does not match an explicitly permitted rule (such as a service endpoint or virtual network rule) is blocked at the network layer. This enforces a strict zero-trust baseline: all inbound traffic is denied unless an exception is explicitly defined, making it the primary network hardening control in the template.

Why this answer

The ARM template snippet shows the 'defaultAction' property set to 'Deny' under 'networkAcls', which explicitly denies all network traffic by default. This is a security best practice because it implements a zero-trust network model, ensuring that only explicitly allowed traffic (via IP rules or virtual network rules) can access the storage account. Option C correctly identifies this as the default deny behavior.

Exam trap

The trap here is that candidates may confuse 'defaultAction: Deny' with 'restrict network access by IP address' (Option B), but the default deny does not itself restrict by IP—it simply blocks everything until explicit allow rules are added.

How to eliminate wrong answers

Option A is wrong because the template does not include the 'supportsHttpsTrafficOnly' property or set it to true; enforcing HTTPS traffic only is a separate best practice not shown here. Option B is wrong because while IP rules can be added to allow specific addresses, the template only shows the default deny action, not any IP-based restrictions. Option D is wrong because soft delete for blobs is configured via the 'deleteRetentionPolicy' property on blob services, which is absent from this storage account-level network ACL configuration.

542
MCQeasy

Your organization is a small business with 50 employees that uses Microsoft 365 Business Premium. You need to design a security baseline that protects against common threats like phishing, ransomware, and data leakage. The solution must be easy to manage and require minimal ongoing effort. You have the following requirements: 1. Block malicious emails and links. 2. Protect sensitive data from being shared externally. 3. Require multi-factor authentication for all users. 4. Keep devices healthy. Which combination of policies should you implement?

A.Enable Microsoft Defender for Office 365 for phishing protection. Use Microsoft Purview Information Protection to automatically label sensitive emails. Create a Conditional Access policy to require MFA for admins only. Use Azure Information Protection scanner.
B.Enable Exchange Online Protection (EOP) for spam and malware filtering. Create a Conditional Access policy to require MFA for all users. Enable device compliance policies in Microsoft Intune.
C.Enable Microsoft Defender for Office 365 Safe Links and Safe Attachments. Create a Microsoft Purview DLP policy to prevent external sharing of sensitive data. Create a Conditional Access policy to require MFA and device compliance.
D.Enable Microsoft Defender for Office 365 Safe Links and Safe Attachments. Create a Microsoft Purview DLP policy to block sharing of credit card numbers. Enable security defaults in Microsoft Entra ID to enforce MFA.
AnswerC

This is the correct solution because it layers the three essential controls: Defender for Office 365 Safe Links and Safe Attachments protect users from sophisticated phishing payloads in real time, while a Microsoft Purview DLP policy detects and blocks external sharing of sensitive data at the point of exfiltration. The Conditional Access policy requiring MFA and device compliance ties identity and device trust together, ensuring that only healthy, authenticated devices can access corporate resources. Together these address email security, data exfiltration prevention, strong authentication for all users, and device health—the four core requirements.

Why this answer

It directly addresses all four requirements: Microsoft Defender for Office 365 Safe Links and Safe Attachments blocks malicious emails and links; a Microsoft Purview DLP policy prevents external sharing of sensitive data, protecting against data leakage; a Conditional Access policy requiring MFA and device compliance enforces multi-factor authentication for all users and ensures devices are healthy. This combination is easy to manage with minimal ongoing effort, as it leverages built-in Microsoft 365 Business Premium capabilities without complex custom configurations.

Exam trap

The trap here is that candidates often confuse Exchange Online Protection (EOP) with Defender for Office 365, not realizing that EOP lacks advanced link and attachment protection, and they may overlook the need for device compliance policies when only security defaults are used for MFA.

How to eliminate wrong answers

Option A is wrong because it requires MFA for admins only, not all users, and uses Azure Information Protection scanner (which is not included in Business Premium and requires additional licensing) instead of a DLP policy for data leakage protection. Option B is wrong because Exchange Online Protection (EOP) alone does not block malicious links in emails or attachments at the same level as Defender for Office 365 Safe Links and Safe Attachments, and it lacks a DLP policy to prevent external sharing of sensitive data. Option D is wrong because it blocks only credit card numbers via DLP, not all sensitive data types, and security defaults in Microsoft Entra ID enforce MFA but do not include device compliance checks, failing the 'keep devices healthy' requirement.

543
MCQhard

Refer to the exhibit. A security administrator needs to ensure that the storage account 'securestore' is compliant with the company policy that requires encryption at rest using customer-managed keys and network access restricted to a specific virtual network. Which of the following statements is correct?

A.The storage account is compliant only if encryption is enabled for blob and file services.
B.The storage account is non-compliant because it uses Microsoft-managed keys for encryption.
C.The storage account is compliant because it uses customer-managed keys from Key Vault and network access is restricted to a specific virtual network.
D.The storage account is non-compliant because network access is allowed from any virtual network.
AnswerC

The storage account is compliant because encryption is configured with customer-managed keys from Key Vault, as shown by 'keySource': 'Microsoft.Keyvault', and the network rule 'defaultAction': 'Deny' is overridden only for a specific virtualNetworkResourceGroup and subnet. This combination ensures data at rest is encrypted with controlled keys and access is restricted to a designated virtual network, meeting policy requirements.

Why this answer

Option C is correct because it states that the storage account uses customer-managed keys from Key Vault for encryption at rest and restricts network access to a specific virtual network, which exactly matches the company policy requirements. Customer-managed keys stored in Azure Key Vault satisfy the encryption-at-rest requirement, and a virtual network rule or service endpoint scoped to one VNet satisfies the network restriction. Option A is wrong because enabling encryption for blob and file services does not by itself address the customer-managed key or network restriction requirements.

Option B is wrong because it assumes Microsoft-managed keys, which contradicts the scenario where customer-managed keys are used. Option D is wrong because it claims network access is open to any virtual network, which is not the case when access is restricted to a specific VNet.

544
MCQmedium

Your organization uses Microsoft Defender for Cloud to protect Azure resources. You need to ensure that only authorized applications can access Azure Key Vault secrets. The solution must use managed identities and least privilege. What should you configure?

A.Use a shared access signature (SAS) token stored in an environment variable
B.Assign a system-assigned managed identity to the application and grant it Key Vault Secrets User role
C.Enable public network access on Key Vault and restrict inbound IP addresses
D.Install a client certificate on the application server and use it to authenticate to Key Vault
AnswerB

A system-assigned managed identity creates an Azure Active Directory-backed identity directly tied to the application resource, so no credentials are stored in code or configuration. Granting only the Key Vault Secrets User role on the key vault enables least-privilege read access to secrets, and Azure automatically rotates the backing principal's credentials, which eliminates secret management and reduces the risk of credential leakage.

Why this answer

Option B is correct because assigning a system-assigned managed identity to the application and granting it the Key Vault Secrets User role provides an Azure AD-backed identity that can be authorized via RBAC to read secrets, eliminating stored credentials and enforcing least privilege. The Key Vault Secrets User role grants only read access to secret contents, which matches the requirement that only authorized applications access secrets. Option A is wrong because SAS tokens are not the managed identity mechanism for Key Vault and storing a token in an environment variable introduces a shared secret.

Option C is wrong because restricting inbound IP addresses controls network reachability, not application identity or least-privilege authorization. Option D is wrong because client certificate authentication does not use managed identities and requires certificate lifecycle management rather than Azure RBAC.

545
MCQmedium

A company plans to implement a Zero Trust security model. Which of the following is the primary principle that should guide their strategy?

A.Assume breach and verify explicitly
B.Use a strong perimeter firewall as the primary defense
C.Grant trusted users full access to all resources
D.Trust but verify all internal traffic
AnswerA

Zero Trust rejects implicit trust from network location; every request is authenticated and authorised against policy using identity, device and context signals. Assuming breach drives least-privilege access and continuous verification, which is the guiding principle the strategy requires.

Why this answer

The primary principle of Zero Trust is 'never trust, always verify,' which is operationalized as 'assume breach and verify explicitly.' This means every access request—regardless of source (internal or external)—must be authenticated, authorized, and encrypted before granting access. It eliminates implicit trust based on network location and enforces least-privilege access, which is foundational to the Zero Trust architecture.

Exam trap

The trap here is that candidates often confuse 'trust but verify' (Option D) with Zero Trust, but Zero Trust explicitly rejects any pre-established trust and requires verification at every access attempt, making 'assume breach and verify explicitly' the correct guiding principle.

How to eliminate wrong answers

Option B is wrong because relying on a strong perimeter firewall as the primary defense violates Zero Trust's core tenet of eliminating implicit trust based on network location; Zero Trust assumes the network is already compromised and requires micro-segmentation and per-request verification instead. Option C is wrong because granting trusted users full access to all resources contradicts the least-privilege principle of Zero Trust, which mandates that access be limited to only what is necessary for a specific task, regardless of user trust level. Option D is wrong because 'trust but verify' is the opposite of Zero Trust; Zero Trust requires 'never trust, always verify'—verification must occur before access is granted, not after trust is assumed.

546
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only approved applications can run on corporate devices. Which Intune feature should you configure?

A.Windows Defender Firewall
B.BitLocker
C.Windows Information Protection
D.AppLocker
AnswerD

AppLocker is the correct answer because it enforces application control by creating rules that allow or deny executables, scripts, installers, and DLLs based on file attributes like publisher, product name, file hash, or path. These rules are applied by the AppLocker engine at process initiation, so unauthorized applications are blocked from running. Intune can deploy AppLocker policies via endpoint security and configuration settings, making it a valid application control solution for managed Windows 10 devices.

Why this answer

AppLocker (option D) is the correct choice because it is the Windows feature that lets administrators define and enforce rules specifying which applications users can run on managed devices, and it can be configured and deployed through Intune via an application control policy. This directly satisfies the requirement that only approved applications execute on corporate Windows 10 devices. Windows Defender Firewall (A) controls network traffic by port, protocol, and address, not which local applications are permitted to launch.

BitLocker (B) provides full-disk encryption for data-at-rest protection and has no application execution control. Windows Information Protection (C) is designed to separate and protect corporate data from personal data, not to whitelist approved applications for execution.

547
MCQeasy

You are designing security for a web application that will be developed by an external vendor. The vendor will have access to the source code repository and the development environment. You need to ensure that no secrets (e.g., API keys, connection strings) are stored in the source code. What is the best approach to manage secrets for this application?

A.Use Azure Key Vault to store secrets and configure the application to use managed identity to retrieve them.
B.Store secrets in environment variables on the application server.
C.Store secrets in Azure App Service application settings encrypted at rest.
D.Embed secrets in the compiled code using obfuscation.
AnswerA

Azure Key Vault provides centralized, hardware-backed secret storage with granular access policies and full audit logging. Pairing it with a managed identity means the application authenticates to Azure AD using a workload identity token, never needing a secret or connection string in code or configuration. This enables seamless secret rotation and supports the zero-standing-credentials principle, making it the only option that meets cloud-native security best practices.

Why this answer

Using Azure Key Vault to store secrets and referencing them from the application is the standard best practice. The application can use managed identity to authenticate to Key Vault securely. Storing secrets in app settings is not secure if the repository is accessible.

Using environment variables is better but still not as secure as Key Vault. Hardcoding is unacceptable.

548
Multi-Selecteasy

A company is implementing Microsoft Defender for Cloud to protect their Azure environment. Which TWO of the following are security best practices that should be enabled? (Choose two.)

Select 2 answers
A.Cloud Security Posture Management (CSPM)
B.Microsoft Defender for Cloud workload protection
C.Microsoft Defender for Office 365
D.Microsoft Defender for Endpoint onboarding
E.Microsoft Sentinel integration
AnswersA, B

Cloud Security Posture Management (CSPM) is a foundational capability of Microsoft Defender for Cloud that continually scans resource configurations across Azure, AWS, and GCP, comparing them against standards like the Azure Security Benchmark. It generates a Secure Score, highlights misconfigurations, and offers step-by-step remediation, enabling security teams to prevent vulnerabilities before exploitation. Because it directly targets the cloud control plane and configuration drift, CSPM is the best practice for continuous security assessment.

Why this answer

Option A, Cloud Security Posture Management (CSPM), is correct because Defender for Cloud's foundational CSPM continuously assesses Azure resources against security benchmarks like Microsoft Cloud Security Benchmark, surfaces secure score recommendations, and detects misconfigurations and external attack surface risks — the core best practice for hardening an Azure environment. Option B, Microsoft Defender for Cloud workload protection, is correct because enabling the Defender plans (e.g., Defender for Servers, Storage, SQL, Containers, App Service, Key Vault) adds threat detection, vulnerability assessment, and advanced protection for running workloads, which is the recommended complement to CSPM. Option C, Microsoft Defender for Office 365, is not part of Defender for Cloud's Azure protection scope; it protects Exchange Online, SharePoint, Teams, and email against phishing and malware.

Option D, Microsoft Defender for Endpoint onboarding, is a separate endpoint security product (though Defender for Servers can auto-provision it), not a Defender for Cloud best-practice toggle itself. Option E, Microsoft Sentinel integration, is an optional SIEM/SOAR data-connector scenario for centralized detection and response, not a required Defender for Cloud security best practice.

Exam trap

The trap here is that candidates often confuse 'security best practices that should be enabled' with 'all available security products,' leading them to select options like Defender for Office 365 or Sentinel, which are valuable but not mandatory foundational practices for Azure environment protection in the context of Defender for Cloud.

549
MCQeasy

Your company uses Microsoft Purview to protect sensitive data. You need to automatically apply a retention label to documents containing credit card numbers detected in SharePoint Online. What should you configure?

A.Configure a Data Loss Prevention (DLP) policy to apply the label.
B.Create a sensitivity label with auto-labeling for SharePoint.
C.Use a trainable classifier to detect credit card numbers and apply the label.
D.Create an auto-labeling policy for retention labels targeting sensitive info types.
AnswerD

An auto-labeling policy for retention labels is the correct solution because it natively supports automatic application of retention labels to content that matches sensitive info types, such as credit card numbers. These policies run across a tenant and can target SharePoint sites, OneDrive accounts, and Exchange mailboxes, evaluating content against built-in sensitive information types and applying the designated retention label. This approach directly aligns with the requirement to protect sensitive data while ensuring it is retained appropriately. Auto-labeling for retention labels is distinct from sensitivity-label auto-labeling, as it specifically governs data lifecycle rather than classification.

Why this answer

Auto-labeling policies in Microsoft Purview can automatically apply retention labels to documents based on sensitive info types, such as credit card numbers. This allows you to enforce retention rules without manual intervention, directly targeting the detected sensitive data in SharePoint Online.

Exam trap

The trap here is that candidates confuse retention labels with sensitivity labels, or assume DLP policies can apply retention labels directly, when in fact DLP applies sensitivity labels and auto-labeling policies are the correct mechanism for retention labels.

How to eliminate wrong answers

Option A is wrong because DLP policies are designed to prevent data loss by blocking or alerting on sensitive data, not to apply retention labels; they can apply sensitivity labels but not retention labels. Option B is wrong because sensitivity labels with auto-labeling are for classification and protection (e.g., encryption), not for retention; retention labels are a separate concept in Purview. Option C is wrong because trainable classifiers are used to identify content based on patterns or machine learning, but they do not directly apply retention labels; they can be used in auto-labeling policies, but the policy itself must be configured for retention labels targeting sensitive info types.

550
MCQhard

Wide World Importers is deploying a critical line-of-business application on Azure Kubernetes Service (AKS). The application processes financial transactions and must meet SOX compliance. You need to design a security solution that includes: encryption of secrets (e.g., database connection strings) using Azure Key Vault, automatic certificate rotation for TLS termination, network isolation of the AKS cluster, and audit logging of all access to secrets. The solution should use a managed identity for the AKS cluster to access Key Vault. Which of the following designs meets the requirements?

A.Enable managed identity for the AKS cluster, integrate Key Vault with AKS using the Secrets Store CSI driver, deploy the cluster as a private cluster, and enable diagnostic settings on Key Vault to send logs to a Log Analytics workspace.
B.Use a service principal for AKS to access Key Vault, store secrets as Kubernetes secrets, configure a private cluster, and enable audit logging on Key Vault.
C.Enable managed identity for the AKS cluster, store secrets in the cluster's native Kubernetes secrets, use a private endpoint for the AKS API server, and enable Azure Monitor for containers.
D.Use a service principal to access Key Vault, store secrets as encrypted Kubernetes secrets with a customer-managed key, deploy a public cluster with network policies, and enable Key Vault logging.
AnswerA

Managed identity eliminates long-lived service principal credentials by providing an Azure AD-backed identity automatically rotated, which AKS uses to authenticate to Key Vault. The Secrets Store CSI driver mounts selected Key Vault items directly into pods as ephemeral volumes, so secret material never persists in etcd and supports rotation without pod restarts. Deploying AKS as a private cluster ensures the Kubernetes API server receives only private IP addresses, preventing exposure to the public internet. Enabling diagnostic settings on Key Vault streams audit event logs to Log Analytics, giving the security operations team a centralized, queryable trail of access and modifications.

Why this answer

Option A meets all requirements: using managed identity for AKS to access Key Vault (secure, no credentials), integrating Key Vault with AKS via the Secrets Store CSI driver (enables encryption and automatic certificate rotation), deploying as a private cluster (network isolation), and enabling diagnostic settings on Key Vault to send logs to Log Analytics (audit logging). This design leverages Azure-native integrations for security and compliance.

Exam trap

SC-100 often tests the preference for managed identity over service principals and the use of Azure Key Vault integration with AKS, causing candidates to overlook the need for the Secrets Store CSI driver and diagnostic settings for comprehensive compliance.

How to eliminate wrong answers

Option B is wrong because it uses a service principal instead of managed identity, which requires managing credentials and is less secure; also, storing secrets as Kubernetes secrets does not provide encryption with Key Vault or automatic rotation. Option C is wrong because it stores secrets in native Kubernetes secrets (not encrypted with Key Vault) and uses a private endpoint for the API server, which provides network isolation but does not address secret encryption or rotation; Azure Monitor for containers does not audit Key Vault access. Option D is wrong because it uses a service principal, stores secrets as encrypted Kubernetes secrets with customer-managed key (not Key Vault integration for secrets), deploys a public cluster (not network isolated), and Key Vault logging alone does not ensure audit logging of all access to secrets in the context of AKS.

551
MCQhard

You are designing a Microsoft Purview solution for a healthcare organization that must retain electronic protected health information for seven years and ensure that when a custodian leaves the company, their mailbox content remains discoverable. The organization also wants to prevent users from permanently deleting content that is under retention. Which Microsoft Purview feature should you use?

A.Sensitivity labels with encryption applied to all email containing patient data
B.Retention labels published to Exchange mailboxes with a retention period and a retention policy for the workload
C.Data Loss Prevention policies that block sharing of patient records externally
D.Communication compliance policies that review messages for inappropriate content
AnswerB

Retention labels and retention policies in Microsoft Purview can keep Exchange mailbox content for a defined period and preserve it when a user leaves by converting the mailbox to an inactive mailbox if the hold is applied. Retention also blocks permanent deletion of items that are still within the retention period, which satisfies the preservation requirement across the seven-year window.

Why this answer

The scenario requires three things: a seven-year retention period, preservation of a departed custodian's mailbox, and prevention of permanent deletion. Retention labels and retention policies in Microsoft Purview deliver all three, because items under retention cannot be permanently removed and a mailbox under retention becomes inactive when the user account is deleted. The other features address confidentiality, exfiltration, or message review rather than retention.

Exam trap

The trap here is treating sensitivity labels or DLP as retention controls, when only retention labels and policies keep content and preserve inactive mailboxes.

552
MCQhard

Your organization is adopting Microsoft Copilot for Security. You need to ensure that the AI model does not expose sensitive data during interactions. What is the primary security control you should implement?

A.Microsoft Entra Conditional Access policies
B.Microsoft Entra Privileged Identity Management
C.Microsoft Purview Information Protection sensitivity labels
D.Microsoft Purview Data Loss Prevention policies for Copilot
AnswerD

Data Loss Prevention policies for Copilot are specifically designed to detect sensitive information types—such as credit card numbers or personally identifiable information—within Copilot prompts and responses, and can take automatic actions like blocking or warning the user. These policies integrate with the Microsoft Purview console and apply contextual constraints based on the data being processed, making them a content-aware control that mitigates exposure at the point of interaction. Unlike identity or classification-only controls, DLP actively prevents exfiltration by interrupting the prompt/response flow when a violation is matched.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies for Copilot for Security are the primary control to prevent sensitive data exposure because they can inspect and block sensitive information (e.g., credit card numbers, health records) in real-time during Copilot interactions. DLP policies integrate directly with Copilot to enforce data protection rules on both prompts and responses, ensuring that sensitive data is not leaked through the AI model. This is the most direct and effective control for preventing data exposure in AI interactions.

Exam trap

The trap here is that candidates often confuse data classification (sensitivity labels) with data loss prevention (DLP), assuming that labeling data is sufficient to prevent exposure, but DLP is the active enforcement mechanism required for real-time AI interactions.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Conditional Access policies control access to resources based on conditions like location or device compliance, but they do not inspect or block sensitive data within Copilot interactions. Option B is wrong because Microsoft Entra Privileged Identity Management (PIM) manages just-in-time privileged role assignments and does not have any capability to scan or prevent data leakage in AI conversations. Option C is wrong because Microsoft Purview Information Protection sensitivity labels classify and protect data at rest (e.g., documents, emails) but do not enforce real-time data loss prevention rules during active Copilot sessions.

553
MCQmedium

Your organization uses Microsoft Sentinel to monitor hybrid workloads. You need to design a solution to detect lateral movement attempts using pass-the-hash attacks. Which data source should you prioritize for ingestion?

A.Sysmon Event ID 1 (Process creation)
B.DNS Query Logs
C.Azure Activity Logs
D.Windows Security Events (Event ID 4624)
AnswerD

Windows Security Event ID 4624 records every successful logon, including the logon type (Type 3 for network logons), the authentication package, and the source workstation/IP address. Pass-the-Hash attacks commonly result in a Type 3 logon using NTLM, where the logon process and elevated privileges stand out when correlated with other anomalies. This event is the definitive source for detecting credential reuse because it reveals the method by which the account accessed the target machine, making it the correct telemetry for Pass-the-Hash monitoring.

Why this answer

The correct option is D, Windows Security Events (Event ID 4624), because pass-the-hash lateral movement is detected by analyzing logon events, and Event ID 4624 (successful logon) with Logon Type 3 (network) and NTLM authentication reveals the use of stolen NTLM hashes to authenticate to remote systems. Microsoft Sentinel's built-in analytics rules and the SecurityEvent table rely on these 4624 records to correlate anomalous NTLM logons across hosts. Option A (Sysmon Event ID 1) captures process creation and may show suspicious tools but does not directly record the authentication mechanism used in pass-the-hash.

Option B (DNS Query Logs) and Option C (Azure Activity Logs) track name resolution and control-plane operations respectively, neither of which exposes NTLM network logon activity needed to detect pass-the-hash.

554
MCQeasy

You are designing a secure remote access solution for employees using Windows 10/11 devices that are managed by Microsoft Intune. The solution must enforce device compliance before allowing access to corporate resources and must support single sign-on (SSO). Which technology should you use?

A.Deploy a traditional VPN with certificate-based authentication.
B.Set up Azure AD Application Proxy for remote access.
C.Implement Microsoft Defender for Endpoint to block non-compliant devices.
D.Use Microsoft Entra ID with Conditional Access policies that require compliant devices.
AnswerD

Using Microsoft Entra ID with Conditional Access policies that require compliant devices evaluates the device’s compliance state as reported by Intune at sign-in time, combining identity signals with device health to grant or deny access. This approach enforces Zero Trust principles by allowing only managed, compliance-checked devices to reach both cloud and on-premises applications, while also providing seamless SSO through Entra ID. Because it blocks non-compliant devices before session establishment, it directly satisfies the remote access security requirement more effectively than a VPN or application proxy alone.

Why this answer

The correct option is D: Microsoft Entra ID with Conditional Access policies that require compliant devices. Conditional Access is the policy engine that evaluates signals such as Intune device compliance status and enforces access decisions to corporate resources, while Entra ID provides the identity platform that enables single sign-on (SSO) across integrated applications. This directly satisfies both requirements: compliance-gated access and SSO for managed Windows 10/11 devices.

Option A (traditional VPN with certificate-based authentication) can restrict access but does not natively evaluate Intune compliance or deliver SSO to cloud apps. Option B (Azure AD Application Proxy) publishes on-premises web apps for remote access but is not a compliance enforcement or SSO mechanism by itself. Option C (Microsoft Defender for Endpoint) is an endpoint detection and response service and does not act as the access-control gate for corporate resources.

555
MCQmedium

A company plans to implement Microsoft Purview to enforce data loss prevention (DLP) policies. They need to prevent users from sharing credit card numbers via email. What should they configure?

A.Create a sensitivity label and apply it to emails
B.Enable communication compliance policies
C.Create a DLP policy that detects and blocks credit card numbers in Exchange Online
D.Configure a retention policy for email
AnswerC

A DLP policy scoped to Exchange Online inspects email traffic and applies sensitive information type matching for credit card numbers, blocking sharing at the transport layer. This directly satisfies the stem's requirement to prevent email exfiltration, since Exchange Online is the workload governing mail flow within Microsoft Purview.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies can be configured to detect sensitive data types, such as credit card numbers, in Exchange Online emails. When a DLP policy is created with a rule that identifies credit card numbers and blocks the email from being sent, it directly prevents users from sharing that data via email. This is the native mechanism for enforcing DLP on email traffic in Microsoft 365.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which classify data) with DLP policies (which enforce actions on data in motion), leading them to select Option A instead of the correct DLP policy.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are used to classify and protect data based on sensitivity, but they do not inherently detect or block specific sensitive information like credit card numbers in transit; they require manual or automatic labeling and rely on other controls (like DLP) for enforcement. Option B is wrong because communication compliance policies are designed to detect and remediate inappropriate or policy-violating communications (e.g., harassment, insider trading), not to block the sharing of specific sensitive data patterns like credit card numbers. Option D is wrong because retention policies control how long data is kept or deleted, not how data is shared or blocked in real-time; they have no effect on preventing the transmission of credit card numbers via email.

556
MCQmedium

You are designing a security solution for a hybrid identity environment that uses Microsoft Entra ID and on-premises Active Directory. The company wants to enforce Zero Trust principles by continuously verifying user access. Which feature should you implement?

A.Implement Microsoft Entra Hybrid Join for all devices
B.Implement Conditional Access policies that evaluate session risk in real time using continuous access evaluation
C.Implement Microsoft Entra Seamless Single Sign-On
D.Implement Microsoft Entra ID Protection to require multi-factor authentication for all users
AnswerB

Continuous Access Evaluation (CAE) is the correct mechanism because it forces Microsoft Entra ID to re-evaluate Conditional Access policies when critical events occur, such as user account disablement, password reset, or session revocation, rather than waiting for token expiration. It uses a multi-party token that carries a time-limited claim, and resource providers listen for cancellation signals, allowing access to be cut off within minutes. This is true continuous verification because both the token lifetime is shortened and the risk or compliance state is rechecked proactively.

Why this answer

Continuous access evaluation (CAE) is the correct feature because it enforces Zero Trust by evaluating access decisions in real time when critical events occur (e.g., user risk changes, device compliance loss, or token revocation), rather than relying on token lifetime. This ensures that session risk is continuously verified, aligning with the Zero Trust principle of 'never trust, always verify'.

Exam trap

The trap here is that candidates often confuse 'Conditional Access policies' (which are static, policy-based controls evaluated at sign-in) with 'continuous access evaluation' (which dynamically re-evaluates access during an active session), leading them to choose a generic MFA or device join option instead of the real-time evaluation feature.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Hybrid Join only registers devices in both on-premises AD and Entra ID, enabling device-based Conditional Access, but it does not provide continuous real-time session risk evaluation. Option C is wrong because Seamless SSO only eliminates password prompts for users on domain-joined devices; it does not enforce continuous verification or evaluate session risk. Option D is wrong because requiring MFA for all users via Identity Protection is a static, policy-based control that does not continuously re-evaluate access during an active session based on real-time risk changes.

557
MCQmedium

A security administrator applies the Azure Policy definition shown in the exhibit to a management group containing multiple subscriptions. After the policy is assigned, a development team reports they cannot create a new storage account in their subscription. What is the most likely cause?

A.The storage account was created using an older API version that does not support Azure Policy enforcement.
B.The storage account was created in a region that does not support the premium tier.
C.The storage account was assigned a network security group (NSG) that blocks inbound HTTPS traffic.
D.The storage account was created with the 'Secure transfer required' setting disabled.
AnswerD

This is the correct reason. The Azure Policy definition likely contains a rule that denies or audits storage accounts where SupportsHttpsTrafficOnly is false. When secure transfer is disabled, the storage account accepts HTTP traffic, so the property is set to false and the policy marks the resource as non-compliant. If the policy effect is Deny, the storage account creation would even be blocked at deployment time. Therefore, the storage account was created with the 'Secure transfer required' setting disabled.

Why this answer

The Azure Policy definition in the exhibit likely includes an effect (e.g., 'Deny') that requires the 'Secure transfer required' setting to be enabled on storage accounts. When the development team attempts to create a storage account with this setting disabled, the policy denies the request, preventing the creation. This is the most direct cause because Azure Policy enforces compliance rules at resource creation time, and disabling secure transfer violates the policy's condition.

Exam trap

The trap here is that candidates may confuse post-creation network controls (like NSGs) with pre-creation policy enforcement, or assume API version or regional limitations are the cause, when the actual denial stems from a specific property mismatch in the policy rule.

How to eliminate wrong answers

Option A is wrong because Azure Policy enforcement is independent of the API version used; older API versions still trigger policy evaluation, and the policy would deny the request regardless. Option B is wrong because the premium tier support per region is a service availability constraint, not a policy-driven denial; the policy would not block creation based on region unless explicitly configured, and the exhibit shows no such condition. Option C is wrong because network security groups (NSGs) are applied to network interfaces or subnets, not to storage accounts directly; blocking HTTPS traffic would affect connectivity after creation, not prevent the creation itself.

558
MCQeasy

A company is designing a Zero Trust architecture for their hybrid identity environment. They plan to require multifactor authentication (MFA) for all users accessing sensitive applications. Which Microsoft Entra ID capability should they use to enforce MFA based on risk level?

A.Self-service password reset
B.Microsoft Entra Privileged Identity Management
C.Conditional Access
D.Microsoft Entra ID Protection
AnswerC

Conditional Access is the correct enforcement point because it lets you build policies that require MFA based on any combination of signals—user, group, device compliance, location, application, or session risk—from the Entra Identity Protection feed and other sources. A policy such as 'Require MFA for all users' directly enforces a second factor on every authentication attempt, and can also apply step-up auth or session controls conditionally. This policy-driven control is the core of a zero trust architecture, ensuring authentication is continuously verified per access request.

Why this answer

Conditional Access is the correct choice because it is the Microsoft Entra ID policy engine that evaluates signals such as user, device, location, and sign-in risk, and can then require MFA for access to sensitive applications. In a Zero Trust hybrid identity design, Conditional Access policies are where you enforce MFA based on risk level, including integration with risk detections from Microsoft Entra ID Protection. Self-service password reset only lets users reset or unlock their own accounts and does not enforce MFA for application access.

Privileged Identity Management governs just-in-time role activation and approvals for privileged roles, not general MFA enforcement for sensitive apps. Microsoft Entra ID Protection detects and reports risk but does not itself enforce the MFA requirement; that enforcement is done through Conditional Access.

559
Multi-Selectmedium

A company uses Microsoft Purview to classify and label sensitive data. They want to automatically apply a sensitivity label to documents containing a specific custom sensitive information type. Which TWO components are required for this?

Select 2 answers
A.Data loss prevention (DLP) policy
B.Retention label
C.Custom sensitive information type
D.Auto-labeling policy
E.Trainable classifier
AnswersC, D

A custom sensitive information type allows you to define a pattern using regular expressions, keywords, and validity checks to match specific sensitive data (e.g., employee IDs). When this type is referenced in an auto-labeling policy, Purview scans content and applies the configured sensitivity label on matches. It is the mechanism that identifies the content pattern, making it the correct choice for classification and labeling based on custom-defined data.

Why this answer

Option C (Custom sensitive information type) is required because the scenario specifically calls for detecting a custom-defined pattern of sensitive data, and a custom SIT (defined via regex, function, or keyword list) is what identifies that unique content. Option D (Auto-labeling policy) is required because it is the client-side or service-side policy that automatically applies a sensitivity label to items matching a condition, and that condition can reference the custom SIT. Together, the custom SIT supplies the detection logic and the auto-labeling policy supplies the automatic label application.

Option A (DLP policy) is incorrect because DLP enforces protective actions like blocking or warning on data in motion or use, not the automatic application of sensitivity labels. Option B (Retention label) is incorrect because retention labels govern how long content is kept or deleted, not classification or labeling for sensitivity. Option E (Trainable classifier) is incorrect because trainable classifiers are used for content that is hard to define by pattern (e.g., resumes, contracts), whereas this scenario calls for a specific custom SIT.

Exam trap

The trap here is that candidates often confuse the role of a DLP policy (which enforces actions like blocking) with an auto-labeling policy (which applies labels), or they mistakenly think a trainable classifier is needed when a custom sensitive information type already provides deterministic pattern matching.

560
Multi-Selecteasy

Your organization wants to enable Microsoft Defender for Cloud Apps to monitor and control the use of Box and Dropbox. Which TWO steps must you perform?

Select 2 answers
A.Connect the app using an app connector
B.Add Box and Dropbox to the unsanctioned list
C.Deploy a forward proxy
D.Configure Conditional Access App Control
E.Run a cloud discovery report
AnswersA, D

App connectors in Microsoft Defender for Cloud Apps leverage the cloud provider's native APIs (e.g., Box and Dropbox REST APIs) to pull metadata, activities, and file content for continuous, near-real-time monitoring. This allows you to enforce data loss prevention policies, detect user anomalies, and apply governance actions without relying on traffic interception. This is the correct method because it integrates directly with the apps you want to monitor and control, giving you full visibility and control over sanctioned usage.

Why this answer

Option A is correct because Defender for Cloud Apps monitors and governs sanctioned SaaS apps such as Box and Dropbox by connecting them through an app connector (API connector), which uses the app's APIs and OAuth to pull activity logs, files, and user data for governance and control. Option D is correct because Conditional Access App Control (session control) uses Azure AD Conditional Access policies and a reverse proxy to enforce real-time session controls like block download, block upload, and read-only access for Box and Dropbox. Option B is incorrect because adding apps to the unsanctioned list only tags them in Cloud Discovery as unsanctioned; it does not enable monitoring or control of the apps.

Option C is incorrect because a forward proxy is not required; Cloud Discovery can use log upload or Defender for Cloud Apps log collectors, and session control uses a reverse proxy, not a forward proxy. Option E is incorrect because running a Cloud Discovery report only provides visibility into discovered apps and does not by itself enable monitoring and control of Box and Dropbox.

561
Multi-Selecthard

Which THREE components are included in Microsoft Defender XDR?

Select 3 answers
A.Microsoft Defender for Office 365
B.Microsoft Defender for IoT
C.Microsoft Defender for Identity
D.Microsoft Defender for Endpoint
E.Microsoft Defender for Cloud
AnswersA, C, D

Microsoft Defender for Office 365 is one of the core workload products natively integrated into Microsoft Defender XDR. It protects email and collaboration services such as Exchange Online, SharePoint, Teams, and OneDrive for Business by detecting phishing, malware, malicious links, and business email compromise. Its telemetry is shared with the XDR unified incident engine, enabling cross-domain correlation with endpoint and identity signals for automated investigation and response.

Why this answer

Microsoft Defender XDR is the unified extended detection and response suite that correlates signals across Microsoft's first-party security workloads, and its core components include Microsoft Defender for Office 365 (A), which protects email, collaboration tools, and Office apps against phishing, malware, and business email compromise; Microsoft Defender for Identity (C), which monitors on-premises Active Directory Domain Services signals via domain controllers to detect identity-based attacks like lateral movement and credential theft; and Microsoft Defender for Endpoint (D), which provides endpoint detection and response, threat and vulnerability management, and automated investigation on devices. These three feed alerts and incidents into the Defender XDR portal alongside Defender for Cloud Apps to enable cross-domain correlation. Microsoft Defender for IoT (B) is a separate offering for operational technology and IoT/OT environments, and Microsoft Defender for Cloud (E) is a cloud security posture management and workload protection solution (CSPM/CWPP) that, while integrated with the Defender portal, is not one of the three named Defender XDR components tested here.

Exam trap

The trap here is that candidates often assume all 'Defender' branded products are automatically part of Microsoft Defender XDR, but Microsoft Defender for IoT and Microsoft Defender for Cloud are separate services that integrate via connectors rather than being core components of the unified XDR suite.

562
Multi-Selecteasy

Your company is planning to use Microsoft Intune for mobile device management (MDM). You need to ensure that devices are compliant before accessing corporate resources. Which TWO components should you configure?

Select 2 answers
A.Device configuration policies.
B.Enrollment restrictions.
C.Conditional Access policies in Microsoft Entra ID.
D.Compliance policies.
E.App protection policies.
AnswersC, D

Conditional Access policies in Microsoft Entra ID are the enforcement engine that uses signals such as device compliance, user risk, and location to allow or block access to cloud resources. When paired with Intune compliance policies, a Conditional Access policy can require that a device be marked as compliant, thereby blocking access if the device is not compliant. This makes Conditional Access the correct mechanism for enforcing access based on compliance, rather than merely defining compliance.

Why this answer

Compliance policies (D) are the correct component because they define the rules a device must meet—such as requiring a PIN, encryption, or a minimum OS version—and Intune uses them to mark devices as compliant or non-compliant, which is the prerequisite for gating access to corporate resources. Conditional Access policies in Microsoft Entra ID (C) are also correct because they enforce the actual access decision, using signals like device compliance status to grant, block, or require additional controls (for example, MFA) before a device can reach corporate resources. Together, compliance policies evaluate the device and Conditional Access enforces that evaluation at sign-in.

Device configuration policies (A) only push settings to devices but do not by themselves determine compliance, enrollment restrictions (B) merely limit which devices or platforms can enroll, and app protection policies (E) protect app-level data on mobile apps without establishing device compliance for resource access.

563
Multi-Selecthard

Your organization is designing a Zero Trust architecture using Microsoft 365 security features. You need to ensure that all access requests are verified and least-privilege principles are applied. Which TWO capabilities should you implement?

Select 2 answers
A.Privileged Identity Management (PIM)
B.Microsoft Defender for Cloud Apps
C.Microsoft Entra ID
D.Microsoft Purview
E.Conditional Access
AnswersA, E

Azure AD Privileged Identity Management (PIM) is the specific capability designed to enforce just-in-time (JIT) and time-bound activation of privileged roles, directly implementing least-privilege access by requiring step-up authentication, approval workflows, and justifications before elevation. PIM additionally issues scoped, temporary role assignments and provides audit logs and access reviews, making it the targeted answer for minimizing standing administrative privileges in a zero-trust architecture.

Why this answer

Conditional Access (E) is a core Zero Trust policy engine in Microsoft Entra ID that evaluates signals such as user, device, location, and risk at access time, enforcing controls like MFA and compliant-device requirements so every access request is explicitly verified. Privileged Identity Management (A) enforces least privilege by making admin roles eligible rather than permanently active, requiring activation with justification, approval, MFA, and time-bound assignments, which directly satisfies the least-privilege requirement. Together they cover the two stated needs: verify every request (Conditional Access) and minimize standing privileges (PIM).

Microsoft Defender for Cloud Apps (B) provides CASB visibility and threat protection but is not the mechanism that verifies access requests or enforces least privilege. Microsoft Entra ID (C) is the underlying identity platform that hosts Conditional Access and PIM, but as a directory service it is not itself the specific capability being implemented. Microsoft Purview (D) addresses data governance, compliance, and information protection, not access verification or privilege minimization.

564
MCQeasy

Refer to the exhibit. You are reviewing a Bicep template for deploying an Azure SQL Database server. Which security best practice is violated?

A.Minimal TLS version is set to 1.2, which is acceptable.
B.Administrator password is hardcoded in plain text.
C.Public network access is disabled, which may affect connectivity.
D.Azure AD authentication is not configured.
AnswerB

Hardcoding the administrator password as a plaintext string in the Bicep template is a critical security flaw. Anyone with read access to the template or the source control repository can extract the credential, and the secret is also exposed in deployment history. This violates Microsoft's recommendation that secrets must be stored in Azure Key Vault and referenced via the `keyVault` reference or `getSecret` function, or accepted as a secure parameter at deployment time.

Why this answer

The correct answer is B: the administrator password is hardcoded in plain text, which violates the security best practice of never embedding secrets directly in infrastructure-as-code templates. Hardcoded credentials in a Bicep file can be exposed through source control, deployment history, or template exports, so the password should instead be supplied via a secure parameter using Key Vault or a secure string parameter. Option A is not a violation because TLS 1.2 is the minimum acceptable version for Azure SQL Database.

Option C is not a violation because disabling public network access is actually a recommended security hardening measure, typically paired with private endpoints. Option D is a weaker recommendation rather than the clear violation shown, since Azure AD authentication is encouraged but the exposed plaintext password is the definitive security flaw.

565
MCQeasy

Your organization is using Microsoft Defender for Cloud to assess the security posture of your Azure resources. You need to ensure that all storage accounts have secure transfer required enabled. Which Defender for Cloud feature should you use?

A.Security policies and initiatives
B.File integrity monitoring
C.Adaptive network hardening
D.Just-In-Time VM access
AnswerA

Security policies and initiatives in Microsoft Defender for Cloud are built on Azure Policy and include regulatory compliance frameworks like the Microsoft cloud security benchmark. These initiatives contain policy definitions that can audit, deny, or deploy settings such as 'Secure transfer to storage accounts should be enabled' (supportsHttpsTrafficOnly). When assigned to a subscription, Defender for Cloud continuously evaluates storage account compliance and can enforce secure transfer automatically via a DeployIfNotExists effect, directly addressing the requirement to enable secure transfer.

Why this answer

Security policies and initiatives in Microsoft Defender for Cloud are the correct choice because they let you define and assign Azure Policy definitions—such as the built-in 'Secure transfer to storage accounts should be enabled' policy—that continuously assess storage accounts and flag any that lack Secure transfer required (HTTPS-only). This directly addresses the requirement to ensure all storage accounts have secure transfer enabled. File integrity monitoring is incorrect because it tracks changes to OS files and registry keys on VMs, not storage account configuration.

Adaptive network hardening is incorrect because it generates NSG rules based on traffic analysis, and Just-In-Time VM access is incorrect because it restricts inbound VM ports on demand—neither evaluates storage account encryption-in-transit settings.

566
MCQhard

You are designing a privileged access strategy for a company that uses Microsoft Entra ID. The company requires that administrators must activate their privileged roles only after providing a justification and obtaining approval from a designated approver. The activation must be limited to a maximum of 4 hours. You need to configure the solution. What should you use?

A.Microsoft Entra ID Protection risk policies that block sign-ins for privileged users with risky sign-in behavior.
B.Microsoft Entra Privileged Identity Management (PIM) with role settings configured for approval and maximum activation duration.
C.Microsoft Entra ID Governance access reviews for privileged roles, configured to run monthly.
D.Conditional Access policies that require multi-factor authentication and compliant devices for privileged roles.
AnswerB

Microsoft Entra Privileged Identity Management (PIM) allows you to configure role settings that require approval for activation and set a maximum activation duration. You can specify approvers, require justification, and limit activation to a specific number of hours. This directly meets the requirements for just-in-time privileged access with approval workflow and time-bound activation.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) is designed for just-in-time privileged access. It allows you to configure roles as eligible, requiring activation with justification and approval. You can set the maximum activation duration, such as 4 hours, and designate approvers.

This ensures that administrators only have privileged access when needed and for a limited time, reducing the attack surface. Other options do not provide the required approval and time-bound activation features.

Exam trap

The trap here is confusing Conditional Access or access reviews with PIM, but only PIM provides just-in-time activation with approval and time limits.

567
Multi-Selecteasy

Which THREE are components of Microsoft's Zero Trust model?

Select 3 answers
A.Data
B.Assume breach
C.Microsoft Defender for Cloud
D.Identities
E.Endpoints
AnswersA, D, E

Data is the ultimate security target and is protected at rest, in transit, and in use through classification, encryption, and rights management. Zero Trust enforces granular access policies based on data sensitivity, with DLP and DRM ensuring protection even after access is granted. Without data protection, all other components become moot, making data one of the central pillars of the model.

Why this answer

Microsoft's Zero Trust model is built on three foundational principles—verify explicitly, use least privilege access, and assume breach—and it organizes its architecture around six core components: identities, devices (endpoints), applications, data, infrastructure, and networks. Option A (Data) is correct because data is one of those six pillars, protected through classification, labeling, and encryption so that access is granted based on sensitivity and policy. Option D (Identities) is correct because identities are the primary control plane in Zero Trust, verified with strong authentication (such as MFA and conditional access) before any resource is reached.

Option E (Endpoints) is correct because devices/endpoints are a core component, validated for health and compliance before being trusted to access corporate resources. Option B (Assume breach) is not a component but one of the three guiding principles of Zero Trust, and Option C (Microsoft Defender for Cloud) is a specific product/CNAPP offering rather than a structural component of the model.

Exam trap

The trap here is that candidates confuse the Zero Trust guiding principles (like 'Assume breach') with the architectural components (identities, endpoints, data, apps, infrastructure, network), leading them to select 'Assume breach' as a component rather than a principle.

568
Multi-Selecteasy

Your organization uses Microsoft Purview. You need to design a solution that discovers and classifies sensitive data across Microsoft 365 services. Which two services should you include in your data map? (Choose TWO.)

Select 2 answers
A.Power BI
B.SharePoint Online
C.Azure SQL Database
D.OneDrive for Business
E.Azure Blob Storage
AnswersB, D

SharePoint Online is the primary collaborative document repository in Microsoft 365 where organizations store most sensitive files, including contracts, policies, and confidential records. Microsoft Purview natively indexes SharePoint Online sites and document libraries, allowing sensitivity labels, trainable classifiers, and data loss prevention (DLP) policies to identify and protect sensitive content. Because SharePoint is central to M365 file storage and classification, it is the correct source to include in a Purview data classification design.

Why this answer

SharePoint Online (B) is correct because it is a core Microsoft 365 workload whose sites, document libraries, and files are scanned by Microsoft Purview's data map via the sensitive information types and trainable classifiers, enabling discovery and classification of sensitive data at rest. OneDrive for Business (D) is also correct because each user's personal Microsoft 365 storage is crawled by the same Purview data map, so documents containing sensitive data are identified and labeled consistently with SharePoint. Power BI (A), Azure SQL Database (C), and Azure Blob Storage (E) are not the intended Microsoft 365 services for this scenario: Power BI is a business analytics service, while Azure SQL Database and Azure Blob Storage are Azure (non-Microsoft 365) data sources that would be covered by separate Purview connectors or Azure-native classification rather than the Microsoft 365 service data map.

569
MCQeasy

Your organization is adopting Microsoft Copilot for Microsoft 365. You need to ensure that Copilot respects the existing sensitivity labels when processing data. What should you configure?

A.Create Data Loss Prevention (DLP) policies.
B.Configure sensitivity labels in Microsoft Purview Information Protection.
C.Use Azure Information Protection.
D.Apply retention labels to documents.
AnswerB

Sensitivity labels in Microsoft Purview Information Protection apply persistent, tamper-proof metadata to content—such as confidentiality, encryption, and visual markings—which Copilot for Microsoft 365 explicitly consumes to determine whether it may summarize, extract, or generate from the underlying data. Because the labels are honored inside the Microsoft 365 ecosystem, they provide the granular, per-item control needed to govern AI responses. This is the correct answer as it establishes classification at the source.

Why this answer

The correct option is B: Configure sensitivity labels in Microsoft Purview Information Protection. Copilot for Microsoft 365 honors the sensitivity labels applied to content, so labels must be defined and published through Microsoft Purview Information Protection (the current unified labeling platform) for Copilot to respect classification and protection settings such as encryption and content marking. DLP policies (A) enforce rules on sharing or handling of sensitive data but do not provide the classification metadata Copilot uses to respect sensitivity.

Azure Information Protection (C) is the legacy labeling client/service being retired in favor of Purview Information Protection, so it is not the configuration target. Retention labels (D) govern lifecycle and retention, not sensitivity-based protection, so they do not control how Copilot treats sensitive content.

570
MCQmedium

You are designing a solution to protect an Azure App Service web app that authenticates users via Microsoft Entra ID. The app needs to ensure that only users from specific external partner organizations can access it. You do not want to create user objects for each partner user in your tenant. What should you configure?

A.Configure a Conditional Access policy that restricts access to partners' IP ranges.
B.Enable Microsoft Entra B2B collaboration and configure the application to accept tokens from partner tenants.
C.Create guest user accounts for each external user and assign them to a group.
D.Use Azure AD B2C custom policies to allow partner authentication.
AnswerB

Enabling Microsoft Entra B2B collaboration is the correct approach because it lets external partners authenticate with their own home tenant credentials while the application is configured to accept tokens from those partner tenants. A B2B guest object is created in your directory for authorization, but no full user object or local credential exists, keeping your tenant clean and reducing password management. This supports true federation, single sign-on, and lifecycle management via the partner's identity provider. The application can use tenant allowlists to trust tokens from specific partner tenants, aligning with zero-trust principles.

Why this answer

Option B is correct because Microsoft Entra B2B collaboration lets partner users authenticate with their own organizational credentials and receive tokens from their home tenant, which the app can accept without creating user objects in your tenant. This directly satisfies the requirement to allow only specific external partner organizations while avoiding per-user objects in your directory. Option A is insufficient because IP-range restrictions do not identify or validate partner organizations and can be bypassed or misapplied.

Option C contradicts the requirement by creating guest user objects for each external user. Option D is wrong because Azure AD B2C is intended for customer-facing identity scenarios with local or social accounts, not for federating access with specific partner Microsoft Entra tenants.

571
MCQmedium

A company is implementing Microsoft Priva to manage subject rights requests. Users submit requests to access their personal data stored in Exchange Online, SharePoint, and Teams. The privacy team needs to automate the retrieval of data from these sources. Which Priva capability should they use?

A.Subject Rights Requests
B.Consent Management
C.Data Inventory
D.Data Breach Notifications
AnswerA

Subject Rights Requests in Microsoft Priva is the automated workflow that locates, retrieves, and packages personal data stored across Microsoft 365 services to fulfill data subject requests such as access, export, and deletion. It uses data profiles and content search to identify relevant records, then facilitates review in a centralized case management experience, making it the correct module for managing subject rights requests.

Why this answer

Microsoft Priva's Subject Rights Requests capability is purpose-built to automate the intake, search, and fulfillment of data subject access requests (DSARs) across Microsoft 365 workloads including Exchange Online, SharePoint, OneDrive, and Teams. It provides templates, automated searches, and review workflows that map directly to the scenario described.

Exam trap

The trap is confusing Priva's privacy risk management features (Data Inventory, Consent Management) with the DSAR-specific Subject Rights Requests capability; only the latter automates personal data retrieval across M365 workloads.

How to eliminate wrong answers

Option B is wrong because Consent Management in Priva handles tracking and managing user consent for data processing, not retrieving personal data for DSARs. Option C is wrong because Data Inventory (part of Priva Privacy Risk Management) maps and classifies personal data across the tenant for visibility, but does not fulfill subject access requests. Option D is wrong because Data Breach Notifications is not a distinct Priva capability for DSAR automation — breach response is handled through other compliance tooling.

572
Multi-Selecteasy

Your company, Fabrikam, is designing a solution to securely store and manage secrets (e.g., API keys, database passwords) for cloud applications. The solution must use Azure Key Vault and support automatic rotation of secrets. The applications will run on Azure VMs and Azure App Service. Which TWO of the following should you include in your design?

Select 2 answers
A.Use service principals with client secrets to authenticate to Key Vault.
B.Rotate secrets manually using Azure Automation runbooks on a schedule.
C.Store secrets in application configuration files encrypted with Azure Key Vault.
D.Implement automatic secret rotation using Key Vault with Event Grid and Azure Functions.
E.Use managed identities for Azure resources to authenticate to Key Vault.
AnswersD, E

Implementing automatic secret rotation using Key Vault with Event Grid and Azure Functions uses an event-driven model: Key Vault emits SecretNearExpiry events to Event Grid when a secret approaches expiration, and Event Grid triggers an Azure Function to generate a new secret version and store it back in the vault. This approach reacts in near real-time to actual secret lifecycle states, avoids manual scheduling, and is serverless and scalable, requiring no custom infrastructure. It automatically keeps secrets fresh, reduces the risk of expiration-related service outages, and eliminates the need for human-initiated rotation scripts.

Why this answer

Option E is correct because managed identities for Azure resources let Azure VMs and App Service apps authenticate to Key Vault without storing any credentials in code or configuration, which is the recommended, most secure authentication method for this scenario. Option D is correct because Key Vault's secret rotation can be automated by emitting near-expiration events to Event Grid, which triggers an Azure Function to generate and write a new secret version back into Key Vault, satisfying the automatic rotation requirement. Option A is not appropriate because service principals with client secrets require you to store and manage a credential, reintroducing the secret-management problem managed identities solve.

Option B is wrong because manual rotation via Azure Automation runbooks is not automatic rotation and adds operational overhead. Option C is wrong because storing secrets in application configuration files, even if encrypted with Key Vault, does not use Key Vault as the secret store and undermines centralized secure storage and rotation.

573
MCQeasy

A company's security team wants to automate response to common incidents like malware detected on endpoints. They have Microsoft 365 Defender and Microsoft Sentinel. Which feature should they use to create automated playbooks?

A.Microsoft Purview's data loss prevention policies
B.Microsoft Sentinel automation rules and playbooks
C.Azure Policy
D.Microsoft Defender for Cloud's workflow automation
AnswerB

Microsoft Sentinel automation rules and playbooks are the correct choice because Sentinel is a cloud-native SIEM/SOAR that centrally ingests security signals across the enterprise, including endpoints, and can trigger automated responses. Automation rules automatically run playbooks, which are built on Azure Logic Apps, to perform actions such as isolating a compromised device, blocking indicators, notifying security teams, and opening tickets. These playbooks can integrate with Microsoft Defender for Endpoint and other EDR solutions, making them a flexible and comprehensive way to automate response to common incidents.

Why this answer

Microsoft Sentinel's automation rules and playbooks are the correct choice because they are specifically designed to automate incident response by triggering predefined actions (e.g., running a Logic App) when a detection event, such as malware on an endpoint, is ingested from Microsoft 365 Defender. This integration allows security teams to create custom, automated workflows that respond to common incidents without manual intervention.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud's workflow automation (which can send notifications or trigger a Logic App for Defender for Cloud alerts) with Sentinel's full playbook engine, but Sentinel is the correct choice because it is the centralized SIEM/SOAR platform that ingests alerts from Microsoft 365 Defender and orchestrates complex, multi-step automated responses across the entire security ecosystem.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview's data loss prevention policies focus on classifying and protecting sensitive data (e.g., preventing unauthorized sharing), not on automating incident response to security alerts like malware. Option C is wrong because Azure Policy is used to enforce compliance rules on Azure resources (e.g., ensuring VMs have specific tags), not to orchestrate response actions to security incidents. Option D is wrong because Microsoft Defender for Cloud's workflow automation is limited to triggering actions (e.g., sending email) for security recommendations and alerts within Defender for Cloud, but it lacks the deep integration and flexible Logic Apps-based playbook engine that Sentinel provides for multi-source incident response.

574
MCQhard

You are designing a network security architecture for an Azure application that uses Azure Front Door and Azure Application Gateway. The application must be protected from DDoS attacks and common web exploits. Application traffic should be inspected by a web application firewall (WAF) before reaching the backend. What is the recommended deployment order?

A.Azure Front Door with WAF only, no Application Gateway.
B.Azure Front Door without WAF in front of Azure Application Gateway without WAF.
C.Azure Application Gateway with WAF in front of Azure Front Door.
D.Azure Front Door with WAF in front of Azure Application Gateway with WAF.
AnswerD

It places Azure Front Door with WAF at the edge for global DDoS protection and web application firewall, followed by Azure Application Gateway with WAF for regional WAF inspection before the backend. This layered approach provides comprehensive security.

Why this answer

The recommended architecture places Azure Front Door with WAF at the global edge to absorb DDoS and block common web exploits close to the client, then routes traffic to Azure Application Gateway with WAF for regional, path-based, and application-layer protection before reaching the backend. This layered approach provides defense in depth and satisfies the requirement that traffic be inspected by a WAF before reaching the backend.

Exam trap

SC-100 often tests the order of layered security services — candidates incorrectly place Application Gateway in front of Front Door, forgetting that Front Door is the global entry point and must be the first hop.

How to eliminate wrong answers

Option A is wrong because using only Front Door with WAF omits regional Application Gateway capabilities such as path-based routing, URL rewrite, and private backend connectivity, and does not provide the layered inspection the scenario implies. Option B is wrong because deploying Front Door and Application Gateway without WAF leaves the application unprotected from web exploits at both layers, violating the requirement. Option C is wrong because placing Application Gateway with WAF in front of Front Door reverses the intended order — Front Door is a global entry point and should be the first hop, not behind a regional gateway.

575
MCQhard

You are a security architect for a large multinational organization that uses Microsoft 365, Azure, and third-party SaaS applications. The organization has recently experienced a breach where an attacker compromised a user account via a phishing email and then used that account to access sensitive data in SharePoint Online and exfiltrate it via email. The security team wants to implement a comprehensive solution that aligns with the Zero Trust principles of 'verify explicitly', 'use least privilege', and 'assume breach'. You need to design a solution that includes identity protection, conditional access, data protection, and continuous monitoring. You have the following requirements: 1. Block phishing attacks in real time. 2. Enforce least privilege access to sensitive data. 3. Detect and respond to anomalous user behavior. 4. Protect data at rest and in transit. 5. Enable automated response to incidents. Which combination of Microsoft security services and configurations should you recommend?

A.Implement Microsoft Defender for Cloud Apps to discover and control SaaS apps. Use Conditional Access with app control. Deploy Microsoft Purview Data Lifecycle Management. Use Azure Sentinel for monitoring.
B.Implement Microsoft Entra ID Protection to detect and block risky sign-ins. Use Conditional Access policies to require MFA and block legacy authentication. Use Microsoft Purview sensitivity labels to classify data and Azure Monitor to collect logs.
C.Implement Microsoft Defender for Office 365 to block phishing emails. Use Conditional Access policies with session risk to enforce access controls. Deploy Microsoft Purview DLP and sensitivity labels to protect data. Use Microsoft Sentinel with automation rules and playbooks to detect and respond to incidents.
D.Implement Microsoft Defender for Identity to detect on-premises threats. Use Conditional Access with device compliance policies. Deploy Microsoft Purview Information Protection. Use Azure Security Center for monitoring.
AnswerC

Defender for Office 365 blocks phishing emails at the mail gateway using threat intelligence and safe attachments/links. Conditional Access with session risk enforces least-privilege access based on real-time risk, while Purview DLP and sensitivity labels protect data across workloads. Sentinel integrates these signals and uses automation rules and playbooks for rapid, automated incident response, fulfilling all stated requirements. This layered approach covers email security, identity, data protection, and security operations.

Why this answer

Option C is correct because it directly maps to all five requirements: Defender for Office 365 provides real-time anti-phishing protection, Conditional Access with session risk enforces least-privilege and adaptive access, Microsoft Purview DLP and sensitivity labels protect data at rest and in transit, and Microsoft Sentinel with automation rules and playbooks delivers continuous monitoring plus automated incident response. This combination also aligns with Zero Trust by verifying explicitly through risk-based Conditional Access, applying least privilege via DLP and labels, and assuming breach through Sentinel detection and automated response. Option A lacks identity risk detection and phishing blocking, and Azure Sentinel alone does not provide the required automated response without playbooks.

Option B omits phishing protection and automated response, and Azure Monitor is not a SIEM/SOAR platform for incident automation. Option D focuses on on-premises identity threats, which does not address the cloud-based phishing and SaaS exfiltration scenario, and Azure Security Center is not the right tool for Microsoft 365 data protection and automated response.

576
MCQeasy

Your company is migrating to Azure and needs to secure virtual networks with network segmentation. You need to design a solution that filters traffic between subnets based on application requirements. Which Azure service should you use?

A.Azure DDoS Protection
B.Azure Firewall
C.Azure Bastion
D.Network Security Groups (NSGs)
AnswerD

Network Security Groups (NSGs) are a stateful packet-filtering service that evaluates allow/deny rules — based on source/destination IP, port, and protocol — against traffic flowing between subnets, VMs, or NICs in a virtual network. By default, NSGs include built-in rules that allow all internal VNet traffic and deny inbound internet, and they can be overridden with custom rules for granular segmentation. Because NSGs can be assigned to a subnet or NIC directly and incur no extra cost, they are the appropriate service for isolating subnets and controlling traffic between them.

Why this answer

Network Security Groups (NSGs) are the correct choice because they are Azure's native stateful packet-filtering service that can be associated with subnets (and NICs) to allow or deny traffic based on rules using source/destination IP, port, and protocol, which directly enables subnet-level segmentation per application requirements. Azure Firewall is a managed, centralized Layer 3-7 firewall for broader perimeter and egress control, not the primary mechanism for filtering traffic between subnets. Azure DDoS Protection mitigates volumetric and protocol-layer attacks against public endpoints and does not segment or filter inter-subnet traffic.

Azure Bastion provides secure RDP/SSH access to VMs over TLS without public IPs and performs no subnet traffic filtering.

577
MCQmedium

You are the security architect for a company that uses Azure Firewall to protect a hub-and-spoke network topology. The company requires that all outbound traffic from the spoke virtual networks be inspected by the firewall. You need to recommend a solution that ensures traffic is forced through the firewall without requiring complex routing configurations on each spoke. What should you recommend?

A.Enable Azure Firewall forced tunneling and configure the spokes to use the firewall as the next hop via BGP.
B.Configure user-defined routes (UDRs) on each spoke subnet to route 0.0.0.0/0 to the Azure Firewall private IP address.
C.Use Azure Virtual WAN with a secured virtual hub and associate the spoke virtual networks to the hub. Configure routing intent to direct traffic to the firewall.
D.Deploy Azure Firewall in each spoke virtual network and configure peering between spokes to route traffic through the firewalls.
AnswerC

Azure Virtual WAN with a secured virtual hub allows you to associate spoke virtual networks and use routing intent to automatically route traffic through the firewall. This eliminates the need for manual UDRs on each spoke, providing a centralized and scalable solution that meets the requirement of minimal complexity.

Why this answer

Azure Virtual WAN with a secured virtual hub provides a scalable and centralized way to route traffic through Azure Firewall. By associating spoke virtual networks to the hub and configuring routing intent, traffic is automatically directed to the firewall without the need for manual UDRs on each spoke. This reduces administrative complexity and ensures consistent inspection.

Exam trap

The trap here is assuming that UDRs on each spoke are the only way to force traffic through Azure Firewall, overlooking the automated routing capabilities of Azure Virtual WAN with routing intent.

578
MCQeasy

Your organization uses Microsoft Sentinel to centralize security events. You need to ensure that alerts from Microsoft Defender for Cloud are automatically ingested into Sentinel. Which data connector should you enable?

A.DNS connector
B.Office 365 connector
C.Microsoft Defender for Cloud connector
D.Azure Activity connector
AnswerC

The Microsoft Defender for Cloud connector is the native data connector that directly imports security alerts and recommendations from Defender for Cloud into Sentinel via its API. This connector populates the SecurityAlert table with structured findings, including severity, status, and associated entities, enabling correlation with other data sources and automated SOAR actions. It is the only connector from the options that is purpose-built for this integration.

Why this answer

The Microsoft Defender for Cloud connector (formerly Azure Security Center) is specifically designed to ingest alerts and recommendations from Defender for Cloud into Sentinel. The other options are unrelated: Office 365 connector ingests Office logs, Azure Activity logs track Azure resource operations, and DNS connector ingests DNS queries.

579
MCQeasy

A security architect is designing a solution to detect and respond to advanced threats across email, endpoints, and identities. Which Microsoft security solution should they use?

A.Microsoft Purview
B.Microsoft Sentinel
C.Microsoft Defender XDR
D.Microsoft Intune
AnswerC

Microsoft Defender XDR is the correct choice because it is a true XDR solution that unifies detection, investigation, and response across endpoints, email, identities, applications, and data. It natively collects signals from Microsoft Defender for Endpoint, Office 365, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps, and combines them into a single incident view with automated self-healing actions. This enables security teams to detect and respond to sophisticated multi-stage attacks across the entire attack surface, which is exactly the goal of an XDR architecture.

Why this answer

Microsoft Defender XDR (Extended Detection and Response) is the correct solution because it provides unified pre- and post-breach detection, investigation, and response across email, endpoints, and identities. It correlates signals from Microsoft Defender for Endpoint, Defender for Office 365, and Defender for Identity into a single incident queue, enabling automated remediation of advanced multi-vector attacks.

Exam trap

The trap here is that candidates confuse Microsoft Sentinel (a SIEM) with Microsoft Defender XDR (an XDR), but Sentinel is a log aggregation and analysis tool requiring manual correlation, while Defender XDR provides native, automated cross-domain detection and response across email, endpoints, and identities.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview is a data governance, compliance, and risk management solution (e.g., data loss prevention, eDiscovery, insider risk), not a threat detection and response platform. Option B is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR that ingests logs from multiple sources for broad security analytics, but it is not purpose-built for unified cross-domain detection and automated response across email, endpoints, and identities; it requires custom correlation rules and playbooks. Option D is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service for endpoint configuration and compliance, not a threat detection or response tool.

580
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that only devices with a specific minimum OS version can access corporate resources. Which configuration should you use?

A.Device compliance policy with minimum OS version rule
B.Device configuration profile
C.Enrollment restrictions
D.App protection policy
AnswerA

A device compliance policy with a minimum OS version rule is correct because Intune evaluates the installed OS version against this rule during each compliance check. If the device falls below the threshold, it is marked non-compliant, which can trigger conditional access blocks or end-user remediation prompts. This rule directly enforces that devices remain on a supported OS version as a condition of accessing organizational resources.

Why this answer

A device compliance policy with a minimum OS version rule is the correct choice because Intune compliance policies evaluate device attributes—including OS version—against defined rules before granting access to corporate resources. When a device fails the minimum OS version check, Conditional Access blocks access until the device is updated or remediated, ensuring only compliant devices can connect.

Exam trap

The trap here is confusing enrollment restrictions (which only check OS version at the point of enrollment) with compliance policies (which enforce OS version continuously after enrollment), leading candidates to pick enrollment restrictions as a one-time gate rather than an ongoing control.

How to eliminate wrong answers

Option B is wrong because a device configuration profile manages settings and features on the device (e.g., Wi-Fi, VPN, restrictions) but does not enforce access control based on OS version; it lacks the conditional access integration needed to block non-compliant devices. Option C is wrong because enrollment restrictions control which devices can enroll in Intune (e.g., by platform, manufacturer, or OS version at enrollment time), but they do not enforce ongoing compliance after enrollment—a device could be enrolled with a compliant OS and later be downgraded or fail to update. Option D is wrong because an app protection policy (APP) manages data protection within applications (e.g., preventing copy/paste or requiring PIN) and does not evaluate device-level OS version; APP applies to apps on both managed and unmanaged devices, not to device compliance for resource access.

581
Multi-Selectmedium

An organization uses Microsoft Defender XDR to detect and respond to threats. Which THREE data sources does Defender XDR ingest? (Choose three.)

Select 3 answers
A.Microsoft Defender for Identity
B.Microsoft Defender for Endpoint
C.Microsoft Sentinel
D.Microsoft Defender for Office 365
E.Microsoft Intune
AnswersA, B, D

Microsoft Defender for Identity is a cloud-based security solution that monitors on-premises Active Directory and cloud identities, generating signals for identity-based attacks such as pass-the-hash, Kerberoasting, and lateral movement. Its telemetry, including user behavior, logon events, and group policy modifications, is ingested by Microsoft Defender XDR to correlate and enrich incident detection with the identity context that is often central to attacks.

Why this answer

Microsoft Defender XDR is the unified extended detection and response platform that correlates signals from Microsoft's first-party security workloads. Option A, Microsoft Defender for Identity, is correct because it feeds identity-based signals (domain controller sensors, AD FS, Entra ID) into Defender XDR for detecting identity threats like lateral movement and pass-the-hash. Option B, Microsoft Defender for Endpoint, is correct because it supplies endpoint telemetry (device alerts, file/process events) that Defender XDR correlates into incidents.

Option D, Microsoft Defender for Office 365, is correct because it contributes email and collaboration signals (phishing, malicious attachments/URLs) to the unified incident queue. Option C, Microsoft Sentinel, is not a native Defender XDR data source; it is a separate SIEM/SOAR that can ingest Defender XDR incidents, not the reverse. Option E, Microsoft Intune, is a device management service and is not one of the Defender XDR native signal sources, even though it integrates with Defender for Endpoint for compliance and onboarding.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel as a data source for Defender XDR, when in reality Sentinel is a SIEM that consumes data from Defender XDR, not the reverse.

582
MCQeasy

Your organization needs to enforce multi-factor authentication (MFA) for all users accessing Microsoft Entra ID integrated applications. However, users in the finance department should be exempted from MFA when accessing a specific legacy financial app that does not support modern authentication. What should you design?

A.Enable security defaults for all users
B.Enable per-user MFA and exclude the finance department
C.Use Microsoft Entra Identity Protection to require MFA based on risk
D.Create a Conditional Access policy that requires MFA for all cloud apps except the legacy app
AnswerD

A Conditional Access policy can include all cloud apps in the 'target resources' assignment and then exclude the legacy application from the same assignment, allowing you to require MFA for every other cloud app. When the finance department is included in the users/groups, they will be prompted for MFA unless the sign-in targets the excluded legacy app, which precisely matches the stated requirement. Conditional Access policies are evaluated at sign-in time and provide the granular, app-level scoping that the other options lack.

Why this answer

Conditional Access policies allow granular control over which applications require MFA. By creating a policy that requires MFA for all cloud apps except the legacy financial app, you can enforce MFA broadly while exempting the specific app that does not support modern authentication. This approach is more flexible and secure than per-user MFA or security defaults, as it can target specific applications and conditions.

Exam trap

The trap here is that candidates may think per-user MFA (Option B) is sufficient for granular exclusions, but it lacks application-level control and would either block the legacy app or leave the entire finance department unprotected.

How to eliminate wrong answers

Option A is wrong because enabling security defaults enforces MFA for all users without any exclusion capability, which would block the finance department from accessing the legacy app that does not support modern authentication. Option B is wrong because per-user MFA is a legacy method that does not allow application-specific exclusions; it either enables MFA for a user entirely or not, and excluding the entire finance department would leave them unprotected for all other apps. Option C is wrong because Identity Protection risk-based policies require MFA based on user or sign-in risk, not application-specific exemptions; it cannot exempt a specific legacy app from MFA requirements.

583
MCQmedium

Your organization deploys Microsoft Sentinel and wants to automatically respond to phishing emails reported by users. You need to recommend a solution that creates an incident in Sentinel and blocks the email sender in Exchange Online. What should you configure?

A.Use a watchlist to store known phishing senders.
B.Create an automation rule that runs a playbook when an incident is created.
C.Enable UEBA to detect anomalous email behavior.
D.Create an analytics rule that queries user-reported phishing data.
AnswerB

An automation rule can be set to trigger when a Sentinel incident is created, and its action can call a playbook. The playbook, a Logic App, can use the Exchange Online connector to block the sender, disable the account, or quarantine the email, depending on the response logic. Because automation rules fire immediately on incident creation, this option provides the desired automated response to the phishing event. This is the designated mechanism for incident-driven orchestration in Sentinel.

Why this answer

Microsoft Sentinel automation rules trigger playbooks (Logic Apps) in response to incident creation. A playbook can call the Exchange Online connector to block the sender and can also update the Sentinel incident, providing the automated response the scenario requires. This is the standard SOAR pattern in Sentinel.

Exam trap

SC-100 often tests the confusion between detection (analytics rules, UEBA) and response (automation rules + playbooks); candidates must pick the component that actually performs the blocking action.

How to eliminate wrong answers

Option A is wrong because a watchlist is just a reference list of data; it does not execute any response action. Option C is wrong because UEBA detects anomalous behavior but does not block senders or create incidents by itself. Option D is wrong because an analytics rule generates alerts/incidents but does not perform the blocking action in Exchange Online.

584
MCQeasy

You are a security architect at Tailwind Traders. The company uses Microsoft 365 E5 and has a hybrid identity environment with Microsoft Entra Connect. The CIO wants to reduce the risk of credential theft and phishing attacks for all employees. You need to recommend an authentication method that eliminates passwords for users and aligns with Zero Trust principles. What should you recommend?

A.Certificate-based authentication
B.Microsoft Authenticator with phone sign-in
C.Windows Hello for Business
D.Security questions as a secondary authentication factor
AnswerB

Microsoft Authenticator with phone sign-in enables passwordless authentication for users by allowing them to sign in with their mobile device using biometrics or PIN. It works across applications and platforms, integrates with Microsoft Entra ID, and supports phishing-resistant methods, directly reducing credential theft risk and eliminating passwords.

Why this answer

Microsoft Authenticator with phone sign-in provides a passwordless authentication method that works across devices and applications. It uses biometrics or PIN on the mobile device, reducing the risk of phishing and credential theft. This aligns with Zero Trust principles by verifying explicitly and eliminating passwords.

Exam trap

The trap here is assuming that Windows Hello for Business is the universal passwordless solution, when it only works on Windows devices and does not cover all employee scenarios.

585
MCQeasy

A company is implementing Microsoft Purview to protect sensitive data in SharePoint Online. They need to automatically apply a 'Highly Confidential' label to documents that contain credit card numbers. What should they create?

A.A communication compliance policy
B.A data loss prevention (DLP) rule
C.A manual labeling policy
D.An auto-labeling policy for sensitivity labels
AnswerD

An auto-labeling policy for sensitivity labels in Microsoft Purview lets you define rules that automatically inspect documents and emails for sensitive content (e.g., sensitive info types, patterns, or trainable classifiers) and apply the appropriate sensitivity label without user intervention. These policies run in simulation mode initially to gauge accuracy, then can be enforced in production to assign the label, enforce encryption, and trigger subsequent DLP. This is the only option that directly and automatically classifies content at scale, meeting the stated goal.

Why this answer

Microsoft Purview auto-labeling policies for sensitivity labels can automatically detect sensitive data types (e.g., credit card numbers) in SharePoint Online documents and apply a 'Highly Confidential' label without user intervention. This meets the requirement for automatic, policy-driven labeling based on content inspection.

Exam trap

The trap here is that candidates confuse DLP rules (which detect and protect data) with auto-labeling policies (which apply sensitivity labels), but the question specifically asks for automatic label application, not just detection or blocking.

How to eliminate wrong answers

Option A is wrong because communication compliance policies are designed to detect and remediate inappropriate communications (e.g., harassment, insider trading) in Exchange Online and Teams, not to automatically label documents based on sensitive data patterns. Option B is wrong because a data loss prevention (DLP) rule can detect credit card numbers and block or alert, but it does not apply sensitivity labels; DLP rules and sensitivity labels are separate controls. Option C is wrong because manual labeling requires users to apply the label themselves, which contradicts the requirement for automatic application.

586
MCQhard

A company plans to use Microsoft Purview to manage data governance across their on-premises SQL Server databases and Azure SQL databases. They need to classify sensitive data and create a unified data map. Which resource should they deploy?

A.Microsoft Purview
B.Azure Synapse Analytics
C.Azure Data Factory
D.Azure SQL Database
AnswerA

Microsoft Purview is the correct choice because it is Microsoft's unified data governance and compliance platform, providing automated scanning, classification, and labeling of data assets across cloud and on-premises sources. It includes the Data Map, Data Catalog, and Data Estate Insights to give a central inventory, track lineage, and enforce sensitivity labels via Microsoft Information Protection, which aligns directly with the company's data governance requirement.

Why this answer

Microsoft Purview is the correct choice because it provides a unified data governance service that can scan both on-premises SQL Server and Azure SQL databases, automatically classify sensitive data using built-in classifiers (e.g., PII, financial info), and build a centralized data map. This aligns with the requirement to manage data governance across hybrid environments with a single pane of glass.

Exam trap

The trap here is that candidates often confuse Azure Data Factory's data movement capabilities with Purview's governance role, or mistakenly think Azure Synapse Analytics can perform classification because it includes data warehousing and some security features.

How to eliminate wrong answers

Option B (Azure Synapse Analytics) is wrong because it is an analytics service for large-scale data warehousing and big data processing, not a data governance or classification tool. Option C (Azure Data Factory) is wrong because it is a data integration and orchestration service for ETL/ELT pipelines, lacking native data classification and data map capabilities. Option D (Azure SQL Database) is wrong because it is a specific database platform, not a governance service; it cannot unify metadata or classify data across multiple sources like on-premises SQL Server.

587
MCQmedium

Refer to the exhibit. A KQL query is used in Microsoft Sentinel to detect brute-force attacks. The query returns no results despite known brute-force attempts. What is the most likely issue?

A.The EventID 4625 may not cover all authentication failures
B.The query lacks a time filter
C.The 'IPAddress' field does not exist in SecurityEvent
D.The 'count()' aggregation is incorrect
AnswerA

While EventID 4625 captures Windows failed logon attempts, it does not include all authentication failure scenarios, such as Kerberos pre-authentication failures (EventID 4771), credential validation failures (EventID 4776), or failures from non-Windows sources like Azure AD sign-in logs. Additionally, certain failure conditions may generate different event IDs depending on the logon type or protocol, so a detection rule based solely on 4625 will have blind spots for those authentication failures.

Why this answer

EventID 4625 in Windows Security logs specifically records failed logon attempts, but brute-force attacks may target other authentication protocols (e.g., RDP, SMB, or network-level authentication) that generate different EventIDs (such as 4648, 4776, or 5156). Additionally, some brute-force attempts might be blocked at the network layer or use non-Windows authentication methods, so relying solely on EventID 4625 will miss those events. Therefore, the query returns no results because it does not capture all authentication failure scenarios.

Exam trap

Microsoft often tests the misconception that a single EventID (like 4625) covers all authentication failures, when in reality different protocols and authentication methods generate distinct EventIDs, and candidates must consider the broader log source landscape.

How to eliminate wrong answers

Option B is wrong because the absence of a time filter would cause the query to return results from all available data, not zero results; a missing time filter might cause performance issues or overly broad results, but it would not suppress known brute-force attempts. Option C is wrong because if the 'IPAddress' field did not exist in the SecurityEvent table, the query would fail with a schema error or return no results for that field, but the question states the query returns no results at all, implying the field exists but the filter is too narrow. Option D is wrong because the 'count()' aggregation is syntactically correct and commonly used in KQL to count events; an incorrect aggregation would cause a syntax error or unexpected counts, but it would not cause the query to return zero results for known brute-force attempts.

588
MCQeasy

Your organization is planning to use Microsoft Sentinel for security information and event management (SIEM). You need to ingest security logs from on-premises Active Directory. What should you deploy?

A.Microsoft Monitoring Agent (MMA)
B.Log Analytics agent
C.Microsoft Defender for Cloud agent
D.Azure Monitor Agent
AnswerD

Azure Monitor Agent (AMA) is the correct modern agent for Microsoft Sentinel because it unifies data collection across the entire Azure Monitor platform. It uses data collection rules (DCRs) to define exactly which data sources to collect, enabling granular filtering, multi-homing to multiple workspaces, and support for both Windows and Linux without the overhead of separate agents. AMA is the only forward-looking agent that Microsoft is actively investing in, with rich features like network isolation, Azure Arc support, and the ability to handle all log types Sentinel consumes.

Why this answer

The correct option is D, Azure Monitor Agent (AMA). AMA is the current, supported agent for collecting data into Log Analytics workspaces, which back Microsoft Sentinel, and it supports Data Collection Rules (DCRs) to ingest Windows security events from on-premises Active Directory domain controllers via the Azure Arc-enabled servers or the AMA extension. The Microsoft Monitoring Agent (A) and the Log Analytics agent (B) are legacy agents that are deprecated for Sentinel data collection and are being replaced by AMA.

The Microsoft Defender for Cloud agent (C) is not a standalone log-ingestion agent for Sentinel; Defender for Cloud uses the Log Analytics/AMA agents for data collection, so it does not fit the requirement directly.

589
Multi-Selecthard

Your organization is implementing a defense-in-depth strategy for a multi-tier application hosted on Azure. You need to secure the network layers. Which THREE measures should you implement?

Select 3 answers
A.Enable Azure DDoS Protection on the virtual network.
B.Configure Azure Front Door to protect the application layer.
C.Implement Azure Firewall for traffic inspection and filtering.
D.Deploy a site-to-site VPN gateway.
E.Use network security groups (NSGs) to control traffic between subnets.
AnswersA, C, E

Enabling Azure DDoS Protection on the virtual network is a foundational network security layer because it continuously monitors and mitigates volumetric, protocol, and resource-layer DDoS attacks at the Azure edge, using always-on traffic profiling and adaptive tuning to protect all public IP resources within the VNet. It provides both infrastructure-level (L3/L4) protection at no extra cost and the Standard tier with additional mitigation policies, telemetry, and cost protection. This directly aligns with defense-in-depth as the outermost perimeter defense for network availability, complementing but not replacing internal controls.

Why this answer

Azure DDoS Protection (A) is correct because it defends the virtual network against volumetric and protocol-layer attacks targeting the network/infrastructure layer, which is a core component of defense-in-depth for a multi-tier Azure application. Azure Firewall (C) is correct because it provides stateful traffic inspection, filtering, and centralized policy enforcement (FQDN, network, and application rules) between tiers and to/from the internet, adding a managed network-layer control. Network security groups (E) are correct because NSGs enforce Layer 3/Layer 4 allow/deny rules on subnets and NICs, segmenting traffic between the application's tiers (for example, allowing only the web tier to reach the app tier on specific ports).

Azure Front Door (B) is not selected because it is a Layer 7 web application firewall/CDN service, so it addresses the application layer rather than the network layers this scenario asks to secure. A site-to-site VPN gateway (D) is not selected because it provides encrypted connectivity between on-premises networks and Azure, which is a hybrid connectivity measure, not a network-layer security control for the multi-tier application.

590
MCQhard

Your company, Lucerne Publishing, is migrating its on-premises SQL Server databases to Azure SQL Managed Instance. The databases contain sensitive customer data subject to GDPR. You need to design a security solution that includes: (1) Always Encrypted for sensitive columns, (2) dynamic data masking for non-privileged users, (3) auditing of all data access, and (4) encryption at rest using customer-managed keys stored in Azure Key Vault. Which of the following configurations should you implement?

A.Enable Always Encrypted for sensitive columns, configure dynamic data masking, enable auditing via Azure Policy, and enable TDE with a customer-managed key stored in Azure Key Vault.
B.Enable Always Encrypted for sensitive columns, configure dynamic data masking, disable TDE to improve performance, and use row-level security to restrict access.
C.Enable Always Encrypted for sensitive columns, configure dynamic data masking, enable SQL Server auditing to Azure Blob Storage, and enable Transparent Data Encryption (TDE) with a service-managed key.
D.Enable Always Encrypted for sensitive columns, configure dynamic data masking, enable Azure SQL auditing to a Log Analytics workspace, and enable TDE with a customer-managed key stored in Azure Key Vault.
AnswerD

This is the correct combination because each service maps to a distinct requirement: Always Encrypted protects sensitive columns cryptographically so database administrators and compromised servers cannot read plaintext; Dynamic Data Masking limits unauthorized display of sensitive data; Azure SQL auditing sends fine-grained query and security logs to Log Analytics for centralized monitoring; and TDE with a customer-managed key in Azure Key Vault gives you control over encryption keys for at-rest protection, including rotation and revocation. Together they form a layered defense without conflicting overrides, and all are native to Azure SQL Managed Instance.

Why this answer

The correct configuration must satisfy all four requirements: Always Encrypted for sensitive columns, dynamic data masking for non-privileged users, auditing of all data access, and encryption at rest with customer-managed keys in Azure Key Vault. Option D meets all four by enabling Azure SQL auditing to a Log Analytics workspace and TDE with a customer-managed key stored in Azure Key Vault, alongside Always Encrypted and dynamic data masking.

Exam trap

SC-100 often tests whether candidates conflate Azure Policy with SQL auditing, or accept service-managed keys when customer-managed keys are explicitly required.

How to eliminate wrong answers

Option A is wrong because enabling auditing via Azure Policy does not by itself configure SQL auditing of all data access; auditing must be enabled on the SQL resource. Option B is wrong because disabling TDE violates the encryption-at-rest requirement and row-level security does not replace TDE. Option C is wrong because using a service-managed key for TDE violates the customer-managed key requirement, even though auditing to Blob Storage is acceptable.

591
Multi-Selectmedium

You are designing a security solution for Azure SQL Database. The requirements include: encrypting data at rest and in transit, and masking sensitive data from non-privileged users. Which two features should you implement? (Choose two.)

Select 2 answers
A.Dynamic Data Masking
B.Azure Firewall
C.Transparent Data Encryption (TDE)
D.Column-level encryption
E.Always Encrypted
AnswersA, C

Dynamic Data Masking (DDM) is a database-level security feature that obfuscates sensitive columns in query results for non-privileged users. When a user lacks the UNMASK permission, Azure SQL Database rewrites the data on the fly so that values appear masked (e.g., '123-45-6789' becomes 'XXX-XX-6789') without altering the underlying stored data. This masking is applied at query time, which means the raw data remains intact in the database, and privileged users with the UNMASK permission see the original values. DDM is ideal for hiding data from application users or junior DBAs while keeping the data physically unchanged.

Why this answer

Transparent Data Encryption (TDE) [CORRECT] is the right choice for encrypting data at rest, as it performs real-time encryption and decryption of the database, associated backups, and transaction log files at the page level using a symmetric key protected by a certificate stored in Azure Key Vault or the service-managed keystore. Dynamic Data Masking [CORRECT] is the right choice for masking sensitive data from non-privileged users, since it limits data exposure by obfuscating the results of queries on designated columns (for example, showing XXXX for a credit card number) without altering the underlying data, and privileged users can be excluded via UNMASK permission. Encryption in transit is handled automatically by Azure SQL Database through TLS, so no additional feature is needed for that requirement.

Azure Firewall (B) is a network security service for filtering traffic to Azure resources and does not provide data-at-rest encryption or data masking. Column-level encryption (D) and Always Encrypted (E) both encrypt specific column data, but they address data-at-rest confidentiality for privileged applications rather than masking data from non-privileged users, and Always Encrypted additionally requires client-side key management, making them less appropriate for the stated masking requirement.

592
Multi-Selecthard

You are designing a Microsoft Purview data security solution for a multinational organization subject to GDPR and CCPA. Which THREE Purview capabilities should you include to meet regulatory requirements?

Select 3 answers
A.Data Loss Prevention (DLP) policies
B.Advanced eDiscovery
C.Microsoft Purview Audit (Premium) and Activity Explorer
D.Data classification and sensitivity labels
E.Data Lifecycle Management (retention policies)
AnswersA, C, D

Prevents unauthorized sharing of personal data.

Why this answer

Data Loss Prevention (DLP) policies are correct because they allow the organization to detect and prevent the accidental or intentional sharing of sensitive data—such as personally identifiable information (PII) covered under GDPR and CCPA—across email, SharePoint, OneDrive, and endpoints. By scanning content for sensitive information types (e.g., credit card numbers, EU passport numbers) and applying protective actions (e.g., blocking transmission, showing policy tips), DLP directly enforces data protection mandates required by these regulations.

Exam trap

The trap here is that candidates often confuse 'detective' controls (like eDiscovery) with 'preventive' controls (like DLP and sensitivity labels), or they mistakenly think retention policies alone satisfy data security requirements, when in fact GDPR and CCPA demand active protection against data breaches and unauthorized disclosure.

593
MCQeasy

Your organization wants to implement a security information and event management (SIEM) solution that can ingest logs from multiple sources, including on-premises servers, Azure resources, and third-party SaaS applications. Which Microsoft service should you choose?

A.Microsoft Purview
B.Microsoft Defender for Cloud
C.Microsoft Sentinel
D.Azure Monitor
AnswerC

Microsoft Sentinel is the correct answer because it is a scalable, cloud-native SIEM and SOAR service that ingests logs from a wide range of sources, including Microsoft 365, Azure, third-party apps, and on-premises systems. It uses Kusto Query Language (KQL) for advanced hunting and custom analytics, and it provides built-in connectors for many security products. Sentinel centralizes security data, triggers alerts based on correlation rules, and supports automated response playbooks for end-to-end incident management.

Why this answer

Microsoft Sentinel is the correct choice because it is a cloud-native SIEM solution specifically designed to ingest logs from diverse sources, including on-premises servers, Azure resources, and third-party SaaS applications, using built-in connectors for over 100 data sources. It provides centralized security analytics, threat detection, and incident response, making it the appropriate service for this multi-source log ingestion requirement.

Exam trap

The trap here is that candidates often confuse Azure Monitor with a SIEM because it collects logs and metrics, but it lacks the security-specific correlation, threat intelligence integration, and incident management features that define a true SIEM like Microsoft Sentinel.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview is a data governance and compliance solution focused on data classification, labeling, and risk management, not a SIEM for ingesting and analyzing security logs. Option B is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform that provides security recommendations and alerts for Azure and hybrid resources, but it lacks the comprehensive log ingestion and SIEM capabilities needed for multi-source log aggregation. Option D is wrong because Azure Monitor is a monitoring and diagnostics service for Azure resources and applications, primarily collecting metrics and logs for performance and operational health, not a SIEM solution designed for security event correlation and threat hunting across diverse sources.

594
MCQmedium

You are a security architect for a healthcare organization that is adopting Microsoft 365 and Azure. The organization must comply with HIPAA and has the following requirements: - All users must use multi-factor authentication (MFA) when accessing Microsoft 365 from outside the corporate network. - Mobile devices must be managed and must be compliant before accessing email. - Access to Azure virtual machines must be limited to specific admin users and must be audited. - All sensitive data stored in Azure SQL Database must be encrypted at rest and in transit. You have the following technologies: Microsoft Entra ID, Microsoft Intune, Azure SQL Database, Azure Policy, Azure Key Vault, Microsoft Defender for Cloud, and Azure Bastion. Which combination of services and configurations should you implement?

A.Configure Conditional Access to require MFA only for external access, use Intune for mobile device management, deploy Always Encrypted for Azure SQL Database, and use Azure AD Application Proxy for VM access.
B.Configure Microsoft Entra PIM for MFA, use Intune for mobile devices, deploy Azure VPN Gateway for VM access, and enable Double Encryption for Azure SQL Database.
C.Configure Conditional Access policies for MFA, use Intune compliance policies for mobile devices, deploy Azure Bastion for VM access with audit logging, and enable TDE and enforce TLS for Azure SQL Database.
D.Use Azure AD Identity Protection for MFA, use Microsoft Endpoint Manager for device compliance, deploy Azure Firewall for VM access, and use Azure Key Vault for SQL encryption keys.
AnswerC

This option correctly maps each requirement to the right Azure service: Conditional Access policies enforce MFA for all users and sign-ins, Intune compliance policies verify device health for mobile access, and Azure Bastion provides secure RDP/SSH to VMs through the Azure portal with built-in audit logging. For the database, enabling Transparent Data Encryption (TDE) encrypts data at rest, while enforcing TLS protects data in transit, together satisfying the encryption requirements. Notably, Bastion eliminates the need to expose VMs to a public IP or VPN, and its session logs provide the required audit trail.

Why this answer

Option C is correct because it maps each requirement to the appropriate native service: Conditional Access policies enforce MFA for external Microsoft 365 access, Intune compliance policies gate mobile email access on managed compliant devices, Azure Bastion provides audited RDP/SSH access to Azure VMs limited to specific admins without exposing public IPs, and TDE plus enforced TLS encrypt Azure SQL Database at rest and in transit. The other options miss key controls: A uses Azure AD Application Proxy (for web apps, not VM RDP/SSH) and Always Encrypted alone doesn't cover at-rest database encryption or transit TLS; B uses PIM (privileged role activation, not MFA enforcement) and Azure VPN Gateway (network connectivity, not audited admin access); D uses Azure Firewall (network filtering, not VM admin access) and Key Vault (key storage, not SQL data encryption).

595
MCQmedium

A company is designing a Zero Trust network strategy. They want to ensure that all network traffic between on-premises and Azure is inspected and logged, regardless of source or destination. Which Azure service should they use to achieve this?

A.Azure Front Door
B.Azure Bastion
C.Azure Firewall
D.Azure DDoS Protection
AnswerC

Azure Firewall is a stateful, cloud-native firewall as a service that can be deployed in a hub VNet to centralize and enforce network security policies. It supports forced tunneling to route all internet-bound traffic (including traffic from on-premises via ExpressRoute/VPN) through the firewall, where it can inspect, filter, and log every session using application rules, network rules, and threat intelligence. Its built-in logging—via diagnostics, Azure Monitor, and Firewall Insights—provides the full traffic visibility required for a zero trust strategy.

Why this answer

Azure Firewall is a managed, cloud-based network security service that provides inbound and outbound traffic inspection and logging for all traffic between on-premises networks and Azure, regardless of source or destination. It supports application and network-level filtering, threat intelligence-based filtering, and integrates with Azure Monitor for comprehensive logging, making it the correct choice for a Zero Trust network strategy that requires full traffic inspection and logging.

Exam trap

The trap here is that candidates may confuse Azure Firewall with Azure Front Door or Azure Bastion, thinking that any security or access service can inspect all traffic, but only Azure Firewall provides the necessary stateful inspection and logging for all network traffic between on-premises and Azure.

How to eliminate wrong answers

Option A is wrong because Azure Front Door is a global, scalable entry point for web applications, focusing on HTTP/HTTPS load balancing and acceleration, not on inspecting and logging all network traffic between on-premises and Azure (it does not handle non-web protocols or provide stateful packet inspection). Option B is wrong because Azure Bastion is a fully managed PaaS service that provides secure RDP/SSH connectivity to virtual machines directly from the Azure portal, without exposing public IPs; it does not inspect or log general network traffic between on-premises and Azure. Option D is wrong because Azure DDoS Protection is a service that protects against distributed denial-of-service attacks by monitoring and mitigating volumetric attacks at the network layer, but it does not provide general traffic inspection or logging for all network flows.

596
MCQhard

Your organization uses Microsoft Defender for Endpoint (MDE) and Microsoft Sentinel. You need to create an analytics rule in Sentinel that triggers an incident when a device is reported as 'high risk' by MDE. Which data source and rule type should you use?

A.Microsoft Sentinel's Anomalous Activity rule
B.Microsoft 365 Defender connector with an NRT query rule
C.Microsoft Defender XDR connector with a Scheduled query rule
D.Microsoft Defender for Cloud connector with a Fusion rule
AnswerC

The Microsoft Defender XDR connector brings Microsoft Defender for Endpoint's DeviceInfo table into Sentinel, including fields such as RiskScore and ExposureLevel. Running a Scheduled query rule on that connector lets you use KQL to filter where DeviceRiskScore equals 'High', map entities, and create an incident. This is the supported pattern because scheduled rules allow complex joins, longer time ranges, and robust entity mapping—essential for turning a live risk score into a reliable security alert.

Why this answer

The Microsoft Defender XDR connector ingests alerts from Microsoft Defender for Endpoint (MDE) into Sentinel. A Scheduled query rule is required to run a KQL query at a defined interval (e.g., every 5 minutes) that checks for devices with a 'high risk' severity level in the ingested alert data. This combination allows you to create an incident when MDE reports a device as high risk.

Exam trap

The trap here is confusing the Microsoft Defender XDR connector (which covers MDE, MDO, MDI, and MDCA) with the Microsoft 365 Defender connector (which is deprecated or used for legacy scenarios), leading candidates to incorrectly choose Option B.

How to eliminate wrong answers

Option A is wrong because Anomalous Activity rules use machine learning to detect unusual patterns in time-series data, not to trigger on a specific static alert severity like 'high risk' from MDE. Option B is wrong because the Microsoft 365 Defender connector is used for Microsoft 365 Defender (formerly Microsoft Threat Protection) alerts, not for MDE alerts directly; also, NRT (near-real-time) query rules are designed for low-latency scenarios but require a specific connector (Microsoft Defender XDR) for MDE data. Option D is wrong because the Microsoft Defender for Cloud connector ingests security alerts from Azure and hybrid workloads, not from MDE endpoint devices; Fusion rules correlate multiple alert types across different products, not a single static condition.

597
Multi-Selecthard

A company uses Microsoft Intune to manage devices. They need to ensure that only compliant devices can access corporate email. They plan to use Conditional Access in Microsoft Entra ID. Which THREE components must be configured?

Select 3 answers
A.Device registration in Entra ID
B.Conditional Access policy in Entra ID
C.Windows Autopilot deployment profile
D.Compliance policy in Intune
E.Configuration profile in Intune
AnswersA, B, D

Devices must be registered to be evaluated.

Why this answer

Device registration in Entra ID (A) is required because Conditional Access policies evaluate device compliance based on the device's identity in Entra ID. Without registration, the device lacks a unique identity that Entra ID can assess for compliance status, making it impossible to enforce access controls based on device state.

Exam trap

The trap here is that candidates often confuse Configuration profiles (which apply settings) with Compliance policies (which define security requirements), leading them to incorrectly select Configuration profile instead of Compliance policy for enforcing device-based access control.

598
MCQmedium

Your organization is designing a new application that will store sensitive customer data in Azure Cosmos DB. You need to ensure that data at rest is encrypted using a customer-managed key (CMK) stored in Azure Key Vault. What should you configure?

A.Enable Transparent Data Encryption (TDE) on the Cosmos DB account.
B.Enable Azure Storage Service Encryption (SSE) on the Cosmos DB account.
C.Use Always Encrypted with Azure SQL Database.
D.Configure a customer-managed key in Azure Key Vault and assign it to the Cosmos DB account.
AnswerD

To meet a bring-your-own-key (BYOK) requirement on Azure Cosmos DB, you must configure a customer-managed key in Azure Key Vault and associate it with the Cosmos DB account. This uses envelope encryption where the Key Vault key wraps the account's data encryption keys, allowing you to independently rotate, revoke, or audit key usage. You can establish this by assigning a key URI from Key Vault to the Cosmos DB account (typically via a managed identity and appropriate Key Vault access policy), which gives you control over at-rest encryption.

Why this answer

Option D is correct because Azure Cosmos DB supports encryption at rest with customer-managed keys (CMKs), which are created and stored in Azure Key Vault and then assigned to the Cosmos DB account via its encryption settings. This satisfies the requirement to control the key used for data-at-rest encryption rather than relying on Microsoft-managed keys. Option A is incorrect because Transparent Data Encryption (TDE) is an Azure SQL feature, not a Cosmos DB configuration.

Option B is incorrect because Azure Storage Service Encryption (SSE) applies to Azure Storage services, not Cosmos DB. Option C is incorrect because Always Encrypted is an Azure SQL Database/client-side encryption feature and does not configure CMK encryption for Cosmos DB.

599
Multi-Selecteasy

Which TWO of the following are best practices for securing Microsoft 365 tenants? (Choose two.)

Select 2 answers
A.Enable security defaults in Microsoft Entra ID
B.Use Conditional Access policies to enforce MFA
C.Enable basic authentication for all apps
D.Disable modern authentication for legacy protocols
E.Allow all external sharing in SharePoint
AnswersA, B

Security defaults in Microsoft Entra ID are a preset group of identity security policies that automatically enforce MFA, require administrators to authenticate with MFA, and block legacy authentication. This is a best practice because it provides a robust baseline security posture out-of-the-box, drastically reducing account compromise risk without requiring per-user configuration or Premium licensing. For organizations that lack the licensing for Conditional Access, security defaults are the recommended way to ensure consistent enforcement of strong authentication across all users.

Why this answer

Enabling security defaults provides a baseline of security. Using Conditional Access policies allows granular access control. These are best practices.

Disabling modern authentication is counterproductive. Allowing all external sharing is risky. Using basic authentication is insecure.

So the correct two are A and B.

600
MCQeasy

Refer to the exhibit. You configure this mail flow rule in Exchange Online. What happens to emails with 'FREE' in the subject?

A.Emails are deleted
B.Emails have a custom header added
C.Emails are moved to the Junk Email folder
D.Emails are blocked and not delivered
AnswerC

This is the correct behavior. The 'mark as spam' action sets the message's SCL to 6, which is the threshold used by Exchange Online to route the email to the recipient's Junk Email folder (depending on the mailbox's safe sender settings). It does not delete or reject the email; instead, it delivers it to the spam quarantine location within the mailbox, allowing the user to review it later.

Why this answer

The mail flow rule is configured to add the header 'X-CustomHeader' with the value 'Free' to emails that have 'FREE' in the subject. However, the rule also has the action 'Increase the spam confidence level (SCL) to 9', which causes Exchange Online to treat the message as high-confidence spam. When the SCL is set to 9, Exchange Online automatically moves the email to the Junk Email folder for the recipient, unless a transport rule or mailbox setting overrides this behavior.

Therefore, the emails are not deleted, blocked, or simply have a header added; they are moved to the Junk Email folder due to the SCL increase.

Exam trap

The trap here is that candidates see the 'add a custom header' action and assume that is the only effect, overlooking that the subsequent 'increase SCL to 9' action takes precedence and causes the email to be moved to the Junk Email folder, making the header addition secondary.

How to eliminate wrong answers

Option A is wrong because the rule does not include a 'Delete the message without notifying anyone' action; it only adds a header and increases the SCL, which does not result in deletion. Option B is wrong because while the rule does add a custom header ('X-CustomHeader: Free'), this is not the final outcome—the SCL increase to 9 overrides this action by causing the message to be moved to Junk Email, so the primary effect is the junking, not just header addition. Option D is wrong because the rule does not use a 'Reject the message' action (such as with a non-delivery report or 550 status code); increasing the SCL to 9 does not block delivery but instead routes the message to the Junk Email folder.

Page 7

Page 8 of 9

Page 9

All pages