Courseiva

CCNA Design security solutions for applications and data Questions

75 of 121 questions · Page 1/2 · Design security solutions for applications and data · Answers revealed

1
MCQhard

You are designing a data security solution for a Microsoft 365 tenant that contains highly confidential files. You need to ensure that these files are encrypted and can only be accessed by authorized users, even if the files are downloaded and stored on a personal device. Which technology should you use?

A.Office 365 Message Encryption
B.Microsoft Purview Information Protection with encryption and usage rights
C.BitLocker Drive Encryption
D.Azure Information Protection
AnswerB

Microsoft Purview Information Protection with encryption and usage rights is the current, unified file-protection service in Microsoft 365. It lets you apply labels that encrypt files (Word, Excel, PowerPoint, PDF) and attach usage rights—such as View, Edit, Copy, Print, and Forward—that are enforced by Azure Rights Management. These rights are embedded in the file metadata and travel with the file wherever it goes, so even if a user downloads a document to a USB stick or emails it to a third party, access is still governed by the policy. This persistent protection, combined with user-friendly labeling and DLP integration, makes it the correct answer for protecting data at rest and in motion within and outside the tenant.

Why this answer

Microsoft Purview Information Protection with encryption and usage rights (option B) is correct because it applies persistent protection to the file itself via sensitivity labels, so the encryption and usage restrictions travel with the document even after it is downloaded to a personal device, and only authorized users with the granted rights can open it. Office 365 Message Encryption (A) only protects email messages in transit and does not persist on files stored locally. BitLocker (C) encrypts the whole drive at the OS level, so protection is lost once the file leaves that device.

Azure Information Protection (D) is the legacy predecessor now superseded by Purview Information Protection, making B the current, appropriate choice.

2
MCQhard

A large financial services company is migrating its customer-facing web application to Azure. The application handles sensitive personal data and must comply with PCI DSS. The solution will use Azure App Service (Linux) with a custom container, Azure SQL Database, and Azure Redis Cache. The security architect mandates that all data in transit be encrypted using the latest TLS version, and that the application must be protected against common web vulnerabilities. The company also wants to ensure that only authenticated users can access the Redis cache. Users will authenticate via Microsoft Entra ID. The operations team needs to be able to monitor for SQL injection attempts and anomalous access patterns. You need to design the security configuration. Which of the following is the most comprehensive approach that meets all requirements?

A.Configure App Service to enforce TLS 1.2 as minimum. Deploy Azure Application Gateway with WAF enabled in front of App Service. Enable Azure AD authentication for Azure Redis Cache. Enable Microsoft Defender for SQL for Azure SQL Database.
B.Use Azure Front Door with custom domain and enforce TLS 1.2. Configure IP firewall on Redis Cache. Use Azure SQL Database with VNet service endpoints.
C.Deploy App Service with HTTPS only enabled. Use Azure API Management with WAF. Use Redis Cache with access keys. Enable SQL audit logging.
D.Enable TLS 1.3 on App Service. Use Azure CDN with WAF. Configure Redis Cache with a firewall rule allowing only App Service outbound IPs.
AnswerA

This is the correct defense-in-depth approach. Enforcing TLS 1.2 as the minimum on App Service guarantees strong transport encryption for all client communications. Deploying Azure Application Gateway with WAF enabled in front of App Service provides an OWASP Top 10 web application firewall that inspects and blocks malicious L7 traffic, preventing SQL injection, XSS, and other common attacks. Enabling Azure AD authentication for Redis Cache replaces key-based access with managed identity, supporting passwordless, conditional access policies. Microsoft Defender for SQL for Azure SQL Database adds threat detection, vulnerability assessment, and anomaly alerts, covering the database tier comprehensively.

Why this answer

Azure App Service enforces TLS 1.2/1.3 by default. Azure WAF (Web Application Firewall) in front of App Service protects against OWASP Top 10. Azure AD authentication for Redis Cache is supported via Azure AD RBAC for Redis (currently in preview but available).

Microsoft Defender for SQL detects SQL injection and anomalous access. Option A covers all requirements. Option B uses Application Gateway without WAF.

Option C uses Redis firewall which doesn't enforce authentication. Option D uses Azure Front Door without WAF.

3
MCQeasy

Your organization stores sensitive customer data in Azure Blob Storage. You need to implement data classification and labeling using Microsoft Purview. Which resource should you use to automatically scan and classify the data?

A.Azure Policy
B.Microsoft Purview Data Map
C.Microsoft Purview Information Protection
D.Microsoft Purview Data Loss Prevention
AnswerB

Microsoft Purview Data Map is the correct choice because it performs automated metadata scanning and classification of assets across data sources, including Azure Blob Storage. It uses built-in system classification rules and custom classification rules to inspect actual data content (e.g., regex, keywords) and applies classifications like "Person's Name" or "Credit Card Number" to the schema and data. These classifications are then used in the Data Catalog, enabling sensitivity reporting and integration with information protection for labeling. It does not enforce access control or policy, but it is specifically designed for data discovery and classification at scale.

Why this answer

Microsoft Purview Data Map is the correct choice because it is the foundational service that performs automated scanning, data discovery, and classification of data sources such as Azure Blob Storage, populating the catalog with sensitivity labels and classifications. It uses scan rule sets and classification rules to detect sensitive data types across registered sources. Azure Policy is a governance service for enforcing resource compliance, not for scanning and classifying data content.

Microsoft Purview Information Protection applies sensitivity labels to files and emails but does not itself scan and classify data at rest in Blob Storage. Microsoft Purview Data Loss Prevention enforces policies to prevent data exfiltration, not to discover and classify stored data.

4
MCQmedium

Your organization uses Microsoft Purview Information Protection to label and protect sensitive emails and documents. You need to ensure that when a user applies a 'Highly Confidential' label, the content is automatically encrypted and a watermark is added. Which configuration should you use?

A.Use Azure Information Protection scanner to apply labels automatically.
B.Create a DLP policy that blocks sharing of highly confidential content.
C.Configure a sensitivity label with encryption and watermark settings.
D.Enable Microsoft 365 Message Encryption for all emails.
AnswerC

Sensitivity labels are the only Microsoft Purview option that can simultaneously apply encryption with Azure Rights Management and configure content marking, including visual watermarks, headers, and footers. When a label with these settings is applied to a document or email, the watermark is automatically rendered behind the content or in the header, and encryption protects the file at rest and in transit. This provides a unified, policy-driven way to add watermarks without separate tooling or manual intervention.

Why this answer

Sensitivity labels in Microsoft Purview Information Protection can be configured with encryption and content marking (watermark) settings, which are applied automatically when users apply the label. Option A is incorrect: the Azure Information Protection scanner discovers and labels existing files but does not configure label settings; the label itself must be defined. Option B is incorrect: a DLP policy can block sharing but cannot add watermarks or encrypt content on its own.

Option D is incorrect: Microsoft 365 Message Encryption provides encryption for email transport but does not apply watermarks or enforce labels.

5
MCQhard

Refer to the exhibit. You are reviewing an Azure Policy definition that uses a 'modify' effect. The policy is intended to automatically enable transparent data encryption (TDE) on Azure SQL databases after they are created. Which condition must be met for the modify effect to work?

A.The policy must be assigned at the management group scope.
B.A managed identity must be associated with the policy assignment and have permissions to modify TDE.
C.The database must be newly created.
D.The SQL database must be using the General Purpose service tier.
AnswerB

The Modify effect in Azure Policy requires a managed identity to be attached to the policy assignment and that identity must be granted RBAC permissions, such as SQL Security Manager, on the target SQL servers or databases to change Transparent Data Encryption settings. Without a properly configured identity, the policy assignment fails during evaluation/remediation and cannot apply the desired TDE state. This is a mandatory prerequisite, making the option the correct answer.

Why this answer

The correct answer is B: a managed identity must be associated with the policy assignment and have permissions to modify TDE. Azure Policy's modify effect performs remediation-style changes to resources, so the assignment needs a system-assigned or user-assigned managed identity with the required RBAC permissions (such as SQL DB Contributor or a custom role granting Microsoft.Sql/servers/databases/transparentDataEncryption/write) to actually enable TDE on the database. Option A is incorrect because modify works at any assignment scope (management group, subscription, resource group) as long as the identity and permissions are configured.

Option C is incorrect because modify can act on existing resources during evaluation/remediation, not only newly created ones. Option D is incorrect because TDE enablement via modify is not limited to the General Purpose service tier.

6
MCQhard

Your organization uses Azure API Management (APIM) to expose APIs to external partners. You need to ensure that only authorized partners can access the APIs and that the API requests are rate-limited to prevent abuse. What should you implement?

A.Use a validate JWT policy to authenticate partners and a rate-limit by key policy to control request rates.
B.Configure client certificate authentication and set a global rate limit in the APIM service.
C.Require a subscription key for each partner and configure IP whitelisting.
D.Use OAuth 2.0 tokens and store partner API keys in Azure Key Vault.
AnswerA

Validate JWT policy ensures that only requests carrying a valid JSON Web Token signed by a trusted identity provider reach the API, thereby authenticating each partner's identity. The rate-limit-by-key policy then uses the subscription key as the scope to apply per-partner request quotas, preventing any single partner from consuming all available capacity. This combination provides both secure identity verification and granular throttling, which is exactly what an API exposure to partners requires.

Why this answer

Option A is correct because in Azure API Management, the validate-jwt policy validates OAuth 2.0/JWT bearer tokens issued by an identity provider (such as Microsoft Entra ID), ensuring only authorized partners with valid tokens can call the APIs, while the rate-limit-by-key policy throttles requests based on a key such as the subscription key or a claim (e.g., partner ID), directly preventing abuse. Together these policies satisfy both the authentication and rate-limiting requirements within the APIM policy pipeline. Option B does not fit because client certificate authentication alone does not provide token-based authorization and a global rate limit applies to all callers rather than per-partner, so one partner could exhaust the quota.

Option C is insufficient because a subscription key is a shared secret that can be leaked and IP whitelisting is brittle and does not enforce per-partner request limits. Option D is incomplete because OAuth 2.0 tokens and Key Vault key storage address credential handling but do not themselves implement rate limiting in APIM.

7
MCQmedium

A company uses Microsoft Sentinel for security operations. They want to collect logs from a custom application running on Azure Virtual Machines. The application writes logs to a local file. Which data connector should they use?

A.Application Insights
B.Syslog
C.Windows Event Forwarding
D.Custom Logs via Log Analytics agent
AnswerD

Custom Logs via the Log Analytics agent is the correct solution because the agent provides a native 'Custom Logs' feature that lets you specify a local directory and file mask (e.g., C:\Logs\*.log or /var/log/app/*.txt) to continuously monitor. When a new entry is appended to a matching file, the agent reads it, parses each line using a sample-based custom log definition, and sends the data to a custom table (e.g., MyLog_CL) in the Log Analytics workspace, which Microsoft Sentinel can then query and alert on. This is the built-in method specifically designed to collect existing application-generated log files from Windows or Linux VMs without requiring code changes.

Why this answer

The correct option is D, Custom Logs via Log Analytics agent, because Microsoft Sentinel can ingest arbitrary text-based log files from Azure VMs by installing the Log Analytics agent (MMA/AMA) and defining a custom log table that points to the local file path, which is exactly the scenario of a custom application writing to a local file. Application Insights (A) is an APM service for instrumented application telemetry, not for collecting pre-existing local log files from VMs. Syslog (B) only handles syslog-format messages from Linux/network devices, and Windows Event Forwarding (C) only collects Windows Event Log data, so neither fits a custom application's local log file.

8
MCQeasy

A company uses Microsoft Intune to manage corporate devices. They want to ensure that only compliant devices can access corporate email in Outlook Mobile. Which type of policy should they configure?

A.App protection policy
B.Device configuration policy
C.Conditional Access policy
D.Compliance policy
AnswerC

Conditional Access evaluates device compliance signals from Microsoft Intune and grants or blocks access to cloud apps such as Outlook Mobile accordingly. This satisfies the requirement that only compliant devices reach corporate email, which Intune compliance policies alone cannot enforce.

Why this answer

The correct answer is C, Conditional Access policy, because Conditional Access is the Intune/Microsoft Entra mechanism that enforces access decisions such as requiring a device to be compliant before granting access to corporate resources like Exchange Online for Outlook Mobile. In this scenario, the company needs an access control that evaluates device compliance at sign-in and blocks noncompliant devices, which is exactly what a Conditional Access policy with a 'Require device to be marked as compliant' grant control does. A compliance policy (D) only defines and evaluates compliance state but does not itself block or grant access, and a device configuration policy (B) merely configures settings on devices without enforcing access.

An app protection policy (A) protects app data with PINs and encryption but does not gate access to corporate email based on device compliance.

9
MCQeasy

A company uses Microsoft Sentinel to detect threats. They want to automatically send an email to the security team when a high-severity incident is created. What should they configure?

A.An analytics rule with an automated response
B.A workbook
C.A watchlist
D.A hunting query
AnswerA

An analytics rule with an automated response is the correct option because Microsoft Sentinel's analytics rules not only detect threats and generate incidents but also allow you to attach an automated response, commonly an Azure Logic Apps-based playbook, directly in the rule's 'Incident automation' step. When a high-severity incident is created, that automatic response triggers the playbook, which can send an email via Office 365 Outlook or other connectors. This couples the detection engine with an actionable response workflow, meeting the stated requirement exactly. Unlike workbooks, watchlists, or hunting queries, this is the only option that provides a direct, automatic, and incident-driven notification mechanism.

Why this answer

The correct option is A, an analytics rule with an automated response, because in Microsoft Sentinel analytics rules generate incidents from detected events, and their automated response (via automation rules or playbooks triggered on incident creation) can send an email to the security team when a high-severity incident is created. This directly satisfies the requirement of automatic notification upon incident creation. A workbook (B) is only a visualization/reporting dashboard and does not trigger notifications.

A watchlist (C) stores reference data for enrichment or correlation and cannot send emails. A hunting query (D) is a manual, proactive search for threats and does not automatically notify anyone.

10
MCQmedium

Your company develops a web application hosted on Azure App Service. The application uses Azure SQL Database and requires managed identities to access the database. You need to ensure that the application can authenticate to Azure SQL without storing credentials in code. Which authentication method should you implement?

A.Store a client certificate in Azure Key Vault and reference it from the app.
B.Use an Azure AD service principal with a client secret.
C.Use Azure SQL database-level firewall rules with a static IP restriction.
D.Enable system-assigned managed identity on the App Service and grant it access to the SQL database.
AnswerD

A system-assigned managed identity gives the App Service a Microsoft Entra ID (Azure AD) identity that is automatically created with the app and requires no secrets to be stored in code or configuration. You enable Microsoft Entra authentication on the SQL logical server, then run `CREATE USER [<app-name>] FROM EXTERNAL PROVIDER` to map the identity to a database user and grant least-privilege roles like `db_datareader` and `db_datawriter`. The connection uses token-based authentication (for example, `Authentication=ActiveDirectoryManagedIdentity` in the connection string), eliminating credential storage and rotation.

Why this answer

Option D is correct because enabling a system-assigned managed identity on the Azure App Service creates an identity in Azure AD tied to the app's lifecycle, and that identity can be granted access to Azure SQL Database (for example, by creating a contained database user with CREATE USER [app-name] FROM EXTERNAL PROVIDER and assigning db_datareader/db_datawriter roles), letting the app authenticate without storing any credentials in code. This is the recommended passwordless approach for App Service to Azure SQL. Option A still requires managing and referencing a client certificate, which is credential material rather than eliminating secrets.

Option B uses a service principal with a client secret, which is exactly the stored credential the scenario wants to avoid. Option C only restricts network access via firewall rules and does not provide authentication or authorization to the database.

11
MCQmedium

Your organization uses Microsoft Entra ID for identity and access management. You are developing a web application that needs to access Microsoft Graph API on behalf of the signed-in user. Which authentication flow should you implement?

A.Implicit Flow
B.Client Credentials Flow
C.Authorization Code Flow with PKCE
D.Device Code Flow
AnswerC

The Authorization Code Flow with PKCE is the recommended OAuth 2.0 grant for web applications that access APIs on behalf of a user. It starts with a user interactive authentication, then the app exchanges an authorization code for tokens, and PKCE (Proof Key for Code Exchange) adds a cryptographic verifier to prevent code interception attacks. Also, it supports refresh tokens, allowing long-lived access without re-authentication.

Why this answer

Authorization Code Flow with PKCE (C) is correct because it is the recommended OAuth 2.0 flow for web applications that call Microsoft Graph on behalf of a signed-in user, exchanging the authorization code for delegated access and refresh tokens while PKCE protects the code exchange against interception. Implicit Flow (A) is deprecated for this purpose and returns tokens directly from the authorization endpoint without an authorization code, offering weaker security. Client Credentials Flow (B) is app-only and has no signed-in user, so it cannot act on behalf of a user.

Device Code Flow (D) is intended for input-constrained devices, not a standard web application with a browser-based sign-in.

12
MCQhard

A company is designing a microservices architecture on Azure Kubernetes Service (AKS). Each microservice needs to authenticate to Azure SQL Database using its own identity. The security team requires that no service principal secrets or certificates be stored in the cluster. What should you implement to authenticate the microservices to Azure SQL Database?

A.Create a service principal and store its secret in Azure Key Vault; use the Key Vault Secrets Store CSI driver to mount it.
B.Enable a system-assigned managed identity on the AKS cluster nodes and have pods use it.
C.Use Azure AD Workload Identity for each pod to authenticate to Azure SQL Database using managed identities.
D.Store the Azure SQL connection string with credentials in a Kubernetes secret.
AnswerC

Using Azure AD Workload Identity for each pod assigns a unique Azure AD identity to each Kubernetes service account via federated identity credentials and the cluster's OIDC issuer. The pod's service account token is exchanged for an Azure AD token that grants access to Azure SQL Database without storing any secrets in the cluster. This enables per-microservice least-privilege access, supports conditional access and audit logs, and is the modern, secure replacement for service principals and node-level managed identities.

Why this answer

Azure AD Workload Identity is the correct choice because it federates a Kubernetes service account with an Azure AD managed identity, allowing each pod to obtain Azure AD tokens without any stored secrets or certificates in the cluster. This directly satisfies the requirement that each microservice authenticates with its own identity and that no service principal secrets or certificates be stored. Option A is wrong because it still relies on a service principal secret stored in Key Vault and mounted into the cluster.

Option B is wrong because a node-level system-assigned managed identity is shared by all pods on the node, so it does not give each microservice its own identity. Option D is wrong because storing credentials in a Kubernetes secret violates the no-secrets requirement and is not identity-based authentication.

13
Multi-Selecteasy

Your organization is using Microsoft Sentinel for security operations. Which THREE data sources can be connected to Microsoft Sentinel out of the box? (Choose THREE.)

Select 3 answers
A.Azure Active Directory (now Microsoft Entra ID)
B.Amazon Web Services (AWS) CloudTrail
C.Azure DevOps
D.Microsoft 365 Defender
E.Power BI
AnswersA, B, D

Microsoft Sentinel has a built-in data connector for Azure Active Directory (now Microsoft Entra ID) that streams sign-in logs and audit logs into the SigninLogs and AuditLogs tables. This connector is a first-party, low-latency ingestion path for identity telemetry, enabling detection of risky sign-ins, MFA failures, and privilege escalation. Because identity is a primary attack surface, this connector is a standard and correct choice for Sentinel data sources.

Why this answer

Options A (Azure Active Directory/Entra ID), B (AWS CloudTrail), and D (Microsoft 365 Defender) are all supported out-of-the-box data connectors in Microsoft Sentinel. Option C (Azure DevOps) is not a built-in connector; it requires a custom API or solution. Option E (Power BI) is not a data source connector for Sentinel.

14
Multi-Selecthard

Your organization uses Microsoft Purview to protect sensitive data. You need to implement a solution that automatically detects and protects personally identifiable information (PII) in Microsoft 365. Which THREE should be part of your solution? (Choose THREE.)

Select 3 answers
A.Azure Policy
B.Microsoft Defender for Cloud
C.Microsoft Purview Information Protection scanner
D.Microsoft Purview Data Loss Prevention (DLP) policies
E.Sensitivity labels in Microsoft Purview Information Protection
AnswersC, D, E

The Microsoft Purview Information Protection scanner is a forensic data-discovery engine that runs on Windows Server and scans on-premises repositories, including file shares, SharePoint Server, and SQL Server, for sensitive content. Using built-in or custom sensitive information types, it detects PII such as passport numbers, addresses, and bank details, and can automatically apply sensitivity labels via the same label administration used across Microsoft 365. It supports both discover-and-report and enforce modes, and its results feed into analytics and DLP policy evaluation. This makes it a correct choice because it directly scans content and applies protection at the data source.

Why this answer

Sensitivity labels in Microsoft Purview Information Protection (E) are the core classification mechanism that lets you tag content containing PII so protection (encryption, marking, access restrictions) travels with the data across Microsoft 365 workloads. Microsoft Purview Data Loss Prevention (DLP) policies (D) automatically detect PII using sensitive information types and then block, warn, or audit risky sharing in Exchange Online, SharePoint, OneDrive, Teams, and endpoint locations. The Microsoft Purview Information Protection scanner (C) extends that same labeling and protection to on-premises file shares and SharePoint Server repositories, which is required for a complete PII detection and protection solution.

Azure Policy (A) governs Azure resource compliance and cannot classify or protect PII in Microsoft 365 content, and Microsoft Defender for Cloud (B) is a cloud security posture and workload protection service, not a data classification or DLP tool for Microsoft 365 PII.

15
Multi-Selectmedium

A company is designing a secure data sharing solution with a partner organization. The data will be stored in Azure Blob Storage. Requirements include: encryption at rest with customer-managed keys, granular access control to specific blobs, and the ability to expire access automatically. Which TWO solutions should you combine? (Choose two.)

Select 2 answers
A.Generate shared access signatures (SAS) with specific permissions and expiry times.
B.Enable Azure Active Directory authentication for the storage account.
C.Configure a firewall on the storage account to allow only partner IP addresses.
D.Use Azure RBAC to assign the Storage Blob Data Reader role to partner users.
E.Use Azure Storage Service Encryption with customer-managed keys in Azure Key Vault.
AnswersA, E

SAS tokens provide granular, delegated access to specific Azure Storage resources, such as a single blob or container, with custom permissions (read, write, delete, list) and an expiry time. Because the token is signed with the storage account key or a user delegation key, the partner only needs the SAS URL, not Azure AD credentials or network access, making it ideal for time-boxed data sharing. The ability to revoke a SAS before expiry (by regenerating the account key or using a stored access policy) adds operational control.

Why this answer

Option A is correct because shared access signatures (SAS) let you delegate granular, time-limited access to specific blobs or containers, specifying exact permissions (read, write, etc.) and an expiry time, which directly satisfies the requirements for granular access control and automatic access expiration. Option E is correct because Azure Storage Service Encryption with customer-managed keys stored in Azure Key Vault provides encryption at rest where the customer controls the key lifecycle, meeting the customer-managed key requirement. Option B is not correct because enabling Azure AD authentication alone does not provide granular per-blob access or automatic expiry; it is an authentication mechanism, not an access delegation or expiration feature.

Option C is not correct because IP firewall rules restrict network access but do not provide granular blob-level permissions or automatic access expiration. Option D is not correct because the Storage Blob Data Reader role grants broad read access at the scope assigned and does not inherently expire, so it fails the granularity and automatic expiration requirements.

16
MCQmedium

Refer to the exhibit. What is the effect of this Azure Policy definition?

A.It denies creation of virtual networks that are not using HTTPS.
B.It denies creation or update of storage accounts that do not enforce HTTPS traffic.
C.It audits storage accounts to check if HTTPS traffic is enforced.
D.It denies creation of blob services that do not enforce HTTPS.
AnswerB

This is the correct effect because the policy uses the `deny` effect and the condition `Microsoft.Storage/storageAccounts/supportsHttpsTrafficOnly` equals `false`, so any create or update request for a storage account that does not enable secure transfer is rejected. Since HTTPS traffic enforcement is the only requirement checked, the operation is blocked with a Resource Manager error rather than allowed and logged.

Why this answer

The correct option is B: it denies creation or update of storage accounts that do not enforce HTTPS traffic. An Azure Policy definition with a deny effect targeting the Microsoft.Storage/storageAccounts resource type and the supportsHttpsTrafficOnly property blocks any create or update request where that property is false or missing, enforcing secure transfer. Option A is wrong because the policy targets storage accounts, not virtual networks, and HTTPS enforcement is not a virtual network property.

Option C is wrong because the effect is deny, not audit, so noncompliant requests are blocked rather than merely logged. Option D is wrong because the policy scope is the storage account resource itself, not the blob service child resource.

17
MCQmedium

Your organization uses Microsoft Entra ID and plans to implement a custom line-of-business application that accesses Microsoft Graph APIs. The application will be used by employees and external partners. You need to ensure that the application can authenticate users and obtain appropriate permissions without exposing the client secret. What should you implement?

A.Use a system-assigned managed identity to authenticate to Microsoft Graph.
B.Implement OAuth 2.0 authorization code flow with PKCE.
C.Store the client secret in Azure Key Vault and retrieve it at runtime.
D.Register the application as a public client and use the implicit grant flow.
AnswerB

The OAuth 2.0 authorization code flow with PKCE (Proof Key for Code Exchange) is the recommended approach for native, mobile, and single-page applications that need to call Microsoft Graph. It first obtains an authorization code, which is then exchanged for tokens, and PKCE adds a cryptographically random code verifier that prevents authorization code interception or replay attacks. This flow eliminates the need for a client secret, making it secure for public clients while providing full support for refresh tokens and user consent.

Why this answer

The application is a line-of-business app used by employees and external partners, which implies it may be a public client (e.g., mobile or desktop) that cannot securely store a client secret. OAuth 2.0 authorization code flow with PKCE (Proof Key for Code Exchange) is the recommended authentication pattern for such clients because it eliminates the need for a client secret by using a dynamically generated code verifier. This ensures the client secret is never exposed.

Option B is correct. Option A (system-assigned managed identity) is only suitable for Azure-hosted services, not client applications. Option C (storing client secret in Key Vault) still requires secret retrieval at runtime, which can be insecure for public clients.

Option D (implicit grant flow) is outdated and less secure than authorization code flow with PKCE.

18
MCQmedium

A company is designing a secure API for a customer-facing application that will handle sensitive personal data. They need to ensure that only authorized client applications can call the API and that the identity of the end-user is verified. Which of the following should they implement?

A.HTTP Basic Authentication
B.OAuth 2.0 with client credentials and OpenID Connect
C.JWT bearer tokens
D.API keys
AnswerB

Client credentials authenticates the calling application, while OpenID Connect adds an identity layer atop OAuth 2.0 that verifies the end-user via ID tokens. Together they satisfy both constraints: authorised client applications and verified end-user identity for sensitive personal data.

Why this answer

OAuth 2.0 with client credentials authenticates the client application, while OpenID Connect (OIDC) adds an identity layer to verify the end-user's identity via ID tokens. This combination ensures both client authorization and user authentication, which are the two requirements. OAuth 2.0 alone handles authorization, and OIDC extends it for authentication.

Exam trap

SC-100 often tests the distinction between authentication and authorization, causing candidates to pick API keys or JWT alone when the requirement explicitly includes verifying both the client application and the end-user identity.

How to eliminate wrong answers

Option A is wrong because HTTP Basic Authentication sends credentials in base64 (easily decoded) and does not provide delegated authorization or user identity verification beyond a username/password. Option C is wrong because JWT bearer tokens are a token format, not a complete authentication/authorization framework; they can be used within OAuth 2.0 but do not by themselves verify client applications or end-users. Option D is wrong because API keys only identify the calling application, not the end-user, and are static secrets prone to leakage; they do not provide user authentication.

19
Multi-Selecthard

Which TWO actions should you take to secure Azure Functions with HTTP triggers?

Select 2 answers
A.Enable App Service Authentication (EasyAuth)
B.Configure network restrictions to allow only specific IP ranges
C.Set authorization level to anonymous
D.Enable Application Insights
E.Use function keys only
AnswersA, B

App Service Authentication (EasyAuth) is built into the App Service platform and sits in front of your function code. When enabled, it requires every HTTP request to present a valid token from a configured identity provider (e.g., Azure AD), and it rejects unauthenticated requests before they reach your function. It also gives you access to authenticated user claims in your code, so you can enforce fine-grained authorization beyond mere presence of a token.

Why this answer

Option A is correct because enabling App Service Authentication (EasyAuth) on the Function App enforces identity verification via Microsoft Entra ID or other identity providers before requests reach the function, providing strong authentication for HTTP triggers. Option B is correct because configuring network restrictions (access restrictions / IP allowlists) on the Function App limits inbound HTTP traffic to trusted IP ranges, reducing exposure to unauthorized or malicious callers. Option C is wrong because setting the authorization level to anonymous removes the function key requirement and allows unauthenticated access, weakening security.

Option D is wrong because Application Insights is a monitoring and telemetry service, not a security control. Option E is wrong because function keys alone are shared secrets that can be leaked and do not provide robust authentication or network-level protection.

Exam trap

Candidates often mistake monitoring tools like Application Insights for security controls, but they do not restrict access.

20
Multi-Selecteasy

A software company, Northwind, is developing a mobile app that uses Microsoft Entra ID for authentication. The app accesses an Azure Function App backend that stores data in Azure Cosmos DB. The company wants to implement a defense-in-depth security strategy. Which TWO of the following should you implement?

Select 2 answers
A.Use OAuth 2.0 with Microsoft Entra ID to secure the Azure Functions.
B.Restrict access to the Azure Functions by IP whitelisting.
C.Configure Azure Cosmos DB with a private endpoint.
D.Use function-level authorization keys for the Azure Functions.
E.Enforce TLS 1.0 for all API calls.
AnswersA, C

Using OAuth 2.0 with Microsoft Entra ID is correct because it provides robust user authentication and delegated authorization, allowing the mobile app to obtain access tokens that represent the signed-in user's identity. The Azure Functions can then validate these JWT tokens and use claims (such as object ID or roles) to implement fine-grained authorization. This approach supports multi-factor authentication, Conditional Access policies, and token expiry, which are essential for a modern mobile application and align with the principle of least privilege.

Why this answer

Option A is correct because using OAuth 2.0 with Microsoft Entra ID lets the Azure Functions validate the bearer tokens issued to the mobile app, providing strong, identity-based authentication and enabling fine-grained authorization through app roles or scopes in a defense-in-depth model. Option C is correct because configuring Azure Cosmos DB with a private endpoint (via Azure Private Link) removes the database from the public internet and restricts traffic to the virtual network, adding a network-layer control that complements the identity-layer protection. Option B is not appropriate because IP whitelisting is brittle for a mobile app whose users connect from many dynamic addresses and does not authenticate the caller.

Option D is weaker than A because function-level authorization keys are shared secrets that are hard to rotate and do not provide user identity or scoped permissions. Option E is incorrect because TLS 1.0 is deprecated and insecure; TLS 1.2 or higher should be enforced.

21
Multi-Selectmedium

Your company uses Microsoft Defender for Cloud Apps to protect its SaaS environment. You need to configure settings to detect and block risky user activities. Which TWO actions should you take? (Choose TWO.)

Select 2 answers
A.Block all third-party app access.
B.Define IP address ranges for trusted locations.
C.Configure anomaly detection policies.
D.Configure app discovery policies.
E.Enable session monitoring for critical applications.
AnswersC, E

Anomaly detection policies in Defender for Cloud Apps apply machine learning and user entity behavior analytics (UEBA) to establish baseline activity for each user and then flag deviations such as mass downloads, impossible travel, failed sign-ins, or unusual admin operations. These policies are purpose-built to detect risky behaviors, including compromised users and insider threats, and can trigger automated remediation through integration with Microsoft 365. Because the scenario asks for protecting user activities by detecting suspicious actions, this is the most directly relevant configuration.

Why this answer

Option C is correct because anomaly detection policies in Microsoft Defender for Cloud Apps are specifically designed to detect unusual user behavior—such as impossible travel, atypical download volumes, or suspicious admin activity—and can be tuned to alert on or automatically remediate risky activities in your SaaS environment. Option E is correct because enabling session monitoring (via Conditional Access App Control) for critical applications lets Defender for Cloud Apps inspect and control user sessions in real time, allowing it to block risky actions like downloads, uploads, or copy/paste based on session policies. Option A is not appropriate because blocking all third-party app access is an overly broad, disruptive measure rather than a targeted risky-activity detection and blocking configuration.

Option B does not belong because defining IP address ranges for trusted locations only informs risk evaluation and conditional access decisions; by itself it neither detects nor blocks risky user activities. Option D is incorrect because app discovery policies focus on identifying shadow IT and unsanctioned cloud apps from traffic logs, not on detecting and blocking risky user activities within sanctioned SaaS apps.

Exam trap

SC-100 often tests the distinction between discovery/sanctioning controls and real-time session enforcement, tempting candidates to pick app discovery when the requirement is detecting and blocking risky activity.

22
MCQeasy

A startup, Alpine Ski House, is developing a mobile app that allows users to book ski lessons. The app communicates with an Azure Function App backend via REST APIs. The function app stores data in Azure Cosmos DB. The company wants to secure the API endpoints using OAuth 2.0 with Microsoft Entra ID and ensure that only authenticated users can invoke the functions. The function app should also use a managed identity to access Cosmos DB. Which of the following configurations should you implement?

A.Configure the function app to require authentication with Microsoft Entra ID, enforce HTTPS only, and use a system-assigned managed identity to access Cosmos DB.
B.Configure the function app to use function-level authorization keys, enforce HTTPS only, and use a connection string with a read-write key to access Cosmos DB.
C.Configure the function app to require client certificates, enforce HTTPS only, and use a managed identity to access Cosmos DB.
D.Configure the function app to use IP whitelisting, enforce HTTPS only, and use a managed identity to access Cosmos DB.
AnswerA

Requiring Microsoft Entra ID authentication in the function app enables the OAuth 2.0 authorization code flow with OpenID Connect, so the mobile app's users are authenticated via tokens that the function app validates. Enforcing HTTPS-only ensures all API traffic is cryptographically protected in transit. Using a system-assigned managed identity gives the function app a dedicated Azure AD identity to authenticate to Cosmos DB and grants least-privilege role-based access without storing or rotating database keys in code or configuration.

Why this answer

It uses OAuth 2.0 with Entra ID for authentication, managed identity for database access, and enforces HTTPS. Option B is wrong because function keys are not secure for user authentication. Option C is wrong because client certificates do not provide user-level authentication.

Option D is wrong because IP whitelisting is not a substitute for authentication.

23
MCQhard

You are designing a microservices application running on Azure Kubernetes Service (AKS). You need to ensure that secrets (e.g., API keys, connection strings) are securely stored and automatically rotated without application downtime. What is the recommended approach?

A.Store secrets in Azure App Configuration with key vault references.
B.Store secrets as Kubernetes Secrets and use a controller to rotate them.
C.Use Azure Key Vault with the Secrets Store CSI driver to mount secrets as volumes and enable rotation.
D.Inject secrets as environment variables from Azure Key Vault using a pod identity.
AnswerC

The Secrets Store CSI driver mounts Azure Key Vault secrets as volumes in AKS pods, so applications read them from the filesystem. Enabling rotation updates the mounted content automatically, delivering secure storage and rotation without application downtime.

Why this answer

Option C is correct because the Azure Key Vault provider for the Secrets Store CSI driver mounts secrets from Azure Key Vault as volumes in AKS pods and supports auto-rotation via the secret rotation feature, which periodically re-fetches updated secrets and updates the mounted files without restarting the application. This satisfies the requirement for secure storage in Key Vault plus automatic rotation with no downtime. Option A is aimed at application configuration scenarios and does not natively mount or rotate secrets into AKS pods.

Option B stores secrets in Kubernetes Secrets, which are only base64-encoded and lack the managed rotation and centralized security of Key Vault. Option D injects secrets as environment variables, which cannot be updated in a running container without a pod restart, causing downtime.

24
MCQmedium

Refer to the exhibit. You are investigating a security incident in Microsoft Sentinel. The KQL query above is used to identify potential brute-force attacks. What does the query return?

A.A list of computers with more than 5 failed logins from any account.
B.A list of user accounts with more than 5 failed logins across all computers.
C.A list of user accounts and computers where the account has more than 5 failed logins in the last 24 hours.
D.A list of user accounts with more than 5 successful logins in the last 24 hours.
AnswerC

The query aggregates failed sign-in events by user and computer, then filters with a count greater than five within a 24-hour window. This threshold and time constraint directly satisfy the brute-force detection scenario, returning the affected account and host pairs.

Why this answer

The correct answer is C: a list of user accounts and computers where the account has more than 5 failed logins in the last 24 hours. This matches a typical Sentinel brute-force KQL pattern that filters SecurityEvent for EventID 4625 (failed logon), restricts the TimeGenerated window to the last 24 hours, and then summarizes failed attempts by Account and Computer, filtering with a threshold greater than 5. Option A is wrong because the grouping is by account and computer, not by computer alone, and it ignores the 24-hour time window.

Option B is wrong because it omits the per-computer grouping, so it would not return computer context. Option D is wrong because it references successful logins rather than failed logons (EventID 4625).

25
Multi-Selecthard

You are designing a solution to protect sensitive data in Azure Blob Storage. The data must be encrypted at rest using customer-managed keys (CMK) stored in Azure Key Vault. Additionally, you need to ensure that only specific virtual networks can access the storage account, and all access must be logged. Which three configurations should you implement? (Choose three.)

Select 3 answers
A.Enable Azure Storage logging for read and write requests
B.Enable Azure Storage encryption with customer-managed keys in Key Vault
C.Configure a firewall and virtual network service endpoint for the storage account
D.Enable Azure Files encryption at rest
E.Enable soft delete for blobs
AnswersA, B, C

Enabling Azure Storage logging captures read and write requests against blobs, producing the audit trail the scenario demands. Diagnostic logging records authenticated access details, satisfying the requirement that all access to the sensitive data be logged for later review.

Why this answer

Option B is correct because the scenario explicitly requires encryption at rest with customer-managed keys (CMK) stored in Azure Key Vault, which is achieved by configuring the storage account to use CMK encryption referencing a Key Vault key. Option C is correct because restricting access to specific virtual networks requires configuring the storage account firewall (network rules) and enabling a virtual network service endpoint (Microsoft.Storage) on the designated subnets so traffic reaches the storage account over the Azure backbone. Option A is correct because the requirement that all access be logged is satisfied by enabling Azure Storage logging (diagnostic logging for read and write requests) for the blob service, capturing authentication and access details.

Option D is incorrect because Azure Files encryption at rest is unrelated to Blob Storage and does not address CMK, network restriction, or logging for blobs. Option E is incorrect because soft delete for blobs is a data-protection/recovery feature that retains deleted blobs; it does not provide encryption with CMK, network access control, or access logging.

26
MCQeasy

Your company uses Microsoft Purview to classify and protect sensitive data. You need to automatically detect and protect credit card numbers in documents stored in SharePoint Online. Which solution should you implement?

A.Configure Azure Information Protection to automatically apply protection.
B.Apply a sensitivity label that encrypts documents with credit card numbers.
C.Create a Data Loss Prevention (DLP) policy to detect credit card numbers and block sharing.
D.Use Microsoft Defender for Cloud Apps to scan documents for credit card numbers.
AnswerC

A Microsoft Purview DLP policy is the correct tool because it uses built-in sensitive information types—such as 'Credit Card Number' with Luhn checksum validation—to inspect content stored in SharePoint Online and OneDrive for Business both at rest and when shared. Upon detection, the policy can automatically block external sharing, deny access, or display a policy tip to the user, thereby directly preventing the data loss scenario described in the question.

Why this answer

The correct answer is C: create a Data Loss Prevention (DLP) policy to detect credit card numbers and block sharing. In Microsoft Purview, DLP policies are the built-in mechanism that inspects SharePoint Online content for sensitive information types such as credit card numbers and enforces protective actions like blocking external sharing or restricting access. This directly matches the requirement to automatically detect and protect credit card numbers in SharePoint Online documents.

Option A is incorrect because Azure Information Protection is a labeling/encryption client, not a policy engine that automatically detects sensitive data in SharePoint. Option B is incomplete because a sensitivity label alone does not automatically detect credit card numbers unless combined with auto-labeling conditions, and it does not block sharing. Option D is incorrect because Defender for Cloud Apps focuses on cloud app discovery, session controls, and anomaly detection rather than enforcing DLP rules on SharePoint content.

27
Multi-Selecteasy

Which TWO Microsoft Purview features can be used to classify and label data in Microsoft 365?

Select 2 answers
A.Retention policies
B.eDiscovery
C.Auto-labeling policies
D.Audit logs
E.Sensitive info types
AnswersC, E

Auto-labeling policies in Microsoft Purview automatically apply sensitivity labels to documents and emails when they meet specified conditions, such as containing sensitive info types or matching trainable classifiers. These policies can run in simulation mode to test their impact, then be configured to auto-apply labels, directly fulfilling the requirement to classify content by labeling it based on detected data characteristics.

Why this answer

Auto-labeling policies (C) are a Microsoft Purview Information Protection capability that automatically applies sensitivity labels to content by scanning items for sensitive data, so they directly classify and label data in Microsoft 365. Sensitive info types (E) are the pattern-based classifiers (for example, credit card or national ID patterns) that define what sensitive data looks like and are used by auto-labeling and other Purview rules to classify data. Retention policies (A) govern how long content is kept or deleted rather than classifying or labeling it, eDiscovery (B) is used for identifying and collecting content for legal cases, and Audit logs (D) record user and admin activity for investigation and compliance reporting, so none of these three perform classification or labeling.

28
MCQhard

Your company is deploying a new AI-powered customer service chatbot using Azure OpenAI Service. The chatbot will access customer data stored in Azure Cosmos DB. The security team requires that all data in transit is encrypted, and that the chatbot only accesses data necessary for its function. Additionally, the chatbot must use managed identities to authenticate to Cosmos DB. You need to design the security architecture. Which combination of controls should you implement?

A.Restrict network access to the chatbot's IP address. Use a system-assigned managed identity and assign the Cosmos DB Account Reader role.
B.Use a connection string with the Cosmos DB account key and enforce TLS 1.2. Grant the chatbot's managed identity contributor role.
C.Enable TLS enforcement on Cosmos DB. Use a managed identity for the chatbot and assign the Cosmos DB Built-in Data Reader role. Configure the chatbot to authenticate using the managed identity.
D.Use Azure AD authentication with a service principal and assign the Cosmos DB Built-in Data Contributor role. Enforce TLS 1.2.
AnswerC

Enabling TLS on Cosmos DB encrypts all data in transit, protecting the AI chatbot's queries and responses from interception. A system-assigned or user-assigned managed identity for the chatbot lets it authenticate to Azure AD without storing any secrets in code or configuration. Assigning the Cosmos DB Built-in Data Reader role grants only read access to the actual data containers (the data plane), satisfying the function's read-only requirement while following least privilege.

Why this answer

It enforces TLS for data in transit, uses a managed identity for authentication, and assigns the Cosmos DB Built-in Data Reader role to implement least privilege access. Option A is incorrect because IP restrictions alone do not provide authentication and the Account Reader role does not allow data access. Option B is incorrect because using a connection string exposes secrets and the Contributor role grants excessive permissions.

Option D is incorrect because it uses a service principal instead of a managed identity, which is a requirement.

29
MCQmedium

Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to create an analytics rule that detects when a user account is created outside of business hours from an unusual IP address. Which type of rule should you use?

A.Anomaly rule
B.Scheduled query rule
C.ML Behavior Analytics rule
D.Fusion rule
AnswerB

Scheduled query rules in Microsoft Sentinel let you author a KQL query that runs at a defined interval (for example, every 5 minutes) and can alert when the result set meets a specified condition. With KQL you can filter sign-in activity, aggregate by user, and compare the count of failed attempts to your threshold, giving you full control over the detection logic. This is the only rule type among the options that supports arbitrary custom KQL and deterministic alerting for a specific pattern.

Why this answer

The correct option is B, a Scheduled query rule, because this rule type lets you write a KQL query against your log data (e.g., SecurityEvent or AuditLogs) and schedule it to run at defined intervals, which is exactly what's needed to detect user account creation events filtered by time-of-day and unusual source IP conditions. Scheduled query rules support custom detection logic, entity mapping, and alert/incident generation, making them ideal for this scenario. Anomaly rules (A) are built-in templates that detect deviations from learned baselines and don't let you author arbitrary detection logic for specific conditions like account creation outside business hours.

ML Behavior Analytics rules (C) are also prebuilt Microsoft-defined detections for specific behaviors, not customizable queries. Fusion rules (D) correlate multiple signals across products to detect multi-stage attacks and are not designed for a single custom condition like this.

30
MCQhard

A government agency, Northwind, is deploying a sensitive application on Azure App Service Environment (ASE) v3. The application handles classified data and must meet FedRAMP High requirements. You need to design a security solution that includes: (1) encryption at rest for the app's content and configuration, (2) encryption in transit with TLS 1.2 or higher, (3) network isolation using VNet integration and private endpoints, (4) identity-based access to Azure SQL Database using managed identity, and (5) certificate management for custom domains using Azure Key Vault. Which of the following designs meets all requirements?

A.Deploy the app on a multi-tenant App Service plan, enforce HTTPS only with TLS 1.2, use a system-assigned managed identity to access Azure SQL Database, and configure TLS/SSL certificates from Azure Key Vault.
B.Deploy the app on an ASE v3 in a VNet, enforce HTTPS only with TLS 1.2, use a system-assigned managed identity to access Azure SQL Database, and configure TLS/SSL certificates from Azure Key Vault.
C.Deploy the app on an ASE v3 in a VNet, enforce HTTPS only with TLS 1.2, use a user-assigned managed identity to access Azure SQL Database, and configure TLS/SSL certificates from App Service certificates.
D.Deploy the app on an ASE v3 in a VNet, enforce HTTPS only with TLS 1.2, use a service principal to access Azure SQL Database, and configure TLS/SSL certificates from Azure Key Vault.
AnswerB

ASE v3 provides the isolated VNet deployment, HTTPS-only with TLS 1.2 satisfies encryption in transit, the system-assigned managed identity enables passwordless Microsoft Entra ID authentication to Azure SQL Database, and Key Vault supplies the custom-domain certificates, meeting every stated constraint.

Why this answer

Option B is correct because ASE v3 provides a fully isolated, single-tenant App Service environment deployed into a customer VNet, which is required for FedRAMP High and network isolation. It also correctly combines HTTPS-only with TLS 1.2, a system-assigned managed identity for passwordless Azure SQL authentication, and Key Vault for certificate management — all of which are supported natively in ASE v3. The other options either use multi-tenant App Service (not isolated) or substitute components that don't meet the full requirement set.

Exam trap

SC-100 often tests the assumption that multi-tenant App Service with TLS and managed identity is 'good enough' for high-compliance workloads, when the exam expects recognition that single-tenant ASE v3 plus Key Vault-backed certificates is mandatory for FedRAMP High isolation.

How to eliminate wrong answers

Option A is wrong because a multi-tenant App Service plan does not provide the network isolation or single-tenant hosting required for FedRAMP High classified workloads, even though the other controls are valid. Option C is wrong because it uses App Service certificates instead of Azure Key Vault, which fails the explicit certificate management requirement and lacks the centralized key lifecycle controls needed for classified data. Option D is wrong because it uses a service principal instead of a managed identity, which requires storing and rotating credentials and does not meet the identity-based access requirement as cleanly as managed identity.

31
Multi-Selecthard

A company is deploying a new application that uses Azure Cosmos DB. The security requirements include: data encryption at rest, data encryption in transit, and the ability to audit all data access. Which THREE of the following should you implement?

Select 3 answers
A.Use Azure SQL Database instead of Cosmos DB
B.Require TLS for all connections to Cosmos DB
C.Use Azure Active Directory authentication for Cosmos DB
D.Enable encryption at rest with customer-managed keys
E.Enable diagnostic logging for Cosmos DB
AnswersB, D, E

Requiring TLS for all connections to Cosmos DB enforces encryption in transit, using TLS 1.2 or later as the minimum protocol version. This prevents eavesdropping, man-in-the-middle attacks, and tampering while data is on the wire between client applications, SDKs, and the Cosmos DB service endpoints. TLS also helps meet compliance standards that explicitly mandate in-transit confidentiality, but it does not protect data at rest on the storage backend—that is a separate control.

Why this answer

Option B is correct because requiring TLS for all Cosmos DB connections enforces data encryption in transit, protecting data as it moves between clients and the service. Option D is correct because enabling encryption at rest with customer-managed keys ensures stored data is encrypted and gives the organization control over the key lifecycle, satisfying the encryption-at-rest requirement. Option E is correct because enabling diagnostic logging for Cosmos DB captures data-plane and control-plane operations, providing the audit trail needed to monitor and audit all data access.

Option A is incorrect because replacing Cosmos DB with Azure SQL Database does not meet the stated application requirement to use Cosmos DB and does not by itself address all three security controls. Option C is incorrect because Azure AD authentication addresses identity and access control, not encryption at rest, encryption in transit, or auditing of data access.

32
MCQeasy

Your company is developing a Microsoft Teams app that accesses user profiles. You need to ensure the app only accesses minimal required data. What should you implement?

A.Admin consent for all scopes
B.Application permissions for Microsoft Graph
C.Delegated permissions with User.Read
D.Delegated permissions with User.Read.All
AnswerC

Delegated permissions with User.Read are the correct choice because the app calls Microsoft Graph with a token that includes the signed-in user's identity and consent scope. This scope is the minimal privilege needed to read the current user's profile—name, email, photo, and other basic attributes—while preventing access to other users' data. The user or an administrator can consent to this scope during app usage, and it aligns with the Teams app's requirement to access only the caller's own profile.

Why this answer

The correct option is C: Delegated permissions with User.Read. Delegated permissions let the app act on behalf of the signed-in user, and User.Read is the least-privileged Microsoft Graph scope that allows reading the signed-in user's own profile, satisfying the requirement for minimal data access. Option A is unnecessary because admin consent for all scopes grants far broader access than needed.

Option B is wrong because application permissions run without a signed-in user and typically require broader tenant-wide access. Option D is excessive since User.Read.All allows reading all users' full profiles, not just the current user's minimal data.

33
MCQhard

A company is deploying a new application that will store sensitive customer data in Azure SQL Database. The security team requires that all data at rest be encrypted using a customer-managed key stored in Azure Key Vault. Additionally, they need to ensure that the database can be restored to a point in time and that the encryption key is rotated every 90 days. Which combination of features should you configure?

A.Enable TDE with service-managed keys and use Azure Policy to enforce rotation.
B.Use Always Encrypted with column master key in Azure Key Vault and manual rotation.
C.Use Azure Storage Service Encryption with customer-managed keys and enable soft delete.
D.Enable TDE with customer-managed keys in Azure Key Vault and configure automatic key rotation.
AnswerD

Transparent Data Encryption with customer-managed keys in Azure Key Vault encrypts the entire SQL database by using a symmetric Database Encryption Key (DEK) that is itself protected by an asymmetric TDE protector stored in the vault. You can enable automatic rotation on the TDE protector, which configures Azure SQL to automatically use the latest version of the key from Azure Key Vault without any manual intervention. This gives the organization full control over key management and satisfies the requirement for automated, periodic rotation.

Why this answer

Option D is correct because Transparent Data Encryption (TDE) with customer-managed keys (CMK) in Azure Key Vault encrypts Azure SQL Database data at rest, and TDE supports point-in-time restore (PITR) via automated backups while allowing automatic key rotation through the Key Vault key rotation policy. Configuring TDE with a CMK satisfies the requirement that the encryption key be customer-managed and rotated every 90 days. Option A is wrong because service-managed keys do not meet the customer-managed key requirement, and Azure Policy cannot itself rotate TDE protector keys.

Option B is wrong because Always Encrypted protects data in use and in transit at the client, not data at rest as required, and manual rotation does not meet the 90-day automated rotation need. Option C is wrong because Azure Storage Service Encryption applies to Azure Storage, not Azure SQL Database, and soft delete is a Key Vault data-protection feature, not a database encryption solution.

34
MCQmedium

Trey Research, a biotech firm, is developing a machine learning model on Azure Machine Learning that uses sensitive genomic data. The data is stored in Azure Blob Storage. The company requires that all data be encrypted at rest using customer-managed keys stored in Azure Key Vault, and that access to the storage account be restricted to the Azure Machine Learning workspace and specific data scientists via Azure AD authentication. Additionally, the storage account must be accessible only from the company's virtual network. Which of the following configurations should you implement?

A.Enable encryption at rest with a customer-managed key, configure a firewall to allow the Machine Learning workspace's IP range, and grant data scientists access via storage account access keys.
B.Enable encryption at rest with a service-managed key, configure a private endpoint, and grant data scientists access using Azure RBAC with the Storage Blob Data Reader role.
C.Enable encryption at rest with a customer-managed key, configure a private endpoint for the storage account, and grant the Machine Learning workspace and data scientists access using Azure RBAC with the Storage Blob Data Contributor role.
D.Enable encryption at rest with a customer-managed key, configure a service endpoint for the storage account, and grant the Machine Learning workspace access using a SAS token.
AnswerC

Customer-managed keys in Key Vault satisfy the encryption-at-rest requirement, the private endpoint restricts the storage account to the virtual network, and Azure RBAC with Storage Blob Data Contributor grants least-privilege access via Microsoft Entra ID. Together these meet all three stated constraints.

Why this answer

It provides encryption at rest with a customer-managed key (CMK) stored in Azure Key Vault, a private endpoint to restrict access to the company's virtual network, and Azure RBAC with the Storage Blob Data Contributor role for both the Machine Learning workspace and data scientists, ensuring Azure AD authentication. Option A is wrong because firewall rules using IP ranges are less secure than private endpoints, and granting access via storage account access keys bypasses Azure AD authentication. Option B is wrong because it uses a service-managed key, which does not meet the customer-managed key requirement.

Option D is wrong because a service endpoint is less secure than a private endpoint, and using a SAS token does not provide Azure AD-based access control.

35
MCQhard

Refer to the exhibit. A security architect is reviewing an ARM template that deploys an Azure Storage container. They want to ensure the container is not publicly accessible. What is the security implication of this template?

A.The container allows public access
B.The template creates a container with versioning enabled
C.The template enables encryption at rest
D.The template does not configure network rules, so the container may be accessible from the internet, but only to authenticated users
AnswerD

The template does not define any network access restrictions, such as virtual network rules, IP rules, or a default action of Deny. As a result, the storage account is reachable from the internet, but because the container's publicAccess is set to None, only authenticated requests (using account keys, SAS, or Microsoft Entra) are accepted. This is a distinct security concern: the storage endpoint is publicly exposed, even though data access requires authentication.

Why this answer

Option D is correct because the ARM template does not define any network rules (such as a virtual network rule or IP firewall rule) for the storage account, so the storage endpoint remains reachable from the internet; however, since public blob access is not enabled, anonymous access is denied and only authenticated requests with valid credentials or SAS tokens can succeed. This means the container is not publicly accessible in the anonymous sense, but the lack of network restrictions still exposes the endpoint to authenticated access from any network. Option A is wrong because nothing in the template enables anonymous public access to the container.

Option B is wrong because versioning is a data-protection feature, not a public-access control, and it is not the security implication being asked about. Option C is wrong because encryption at rest is enabled by default for Azure Storage and is unrelated to whether the container is publicly reachable.

36
MCQhard

Your organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft Teams. You need to prevent users from sharing credit card numbers in Teams chat messages. However, the policy should allow sharing with external vendors if they are in your organization's approved list. What should you configure?

A.Configure a DLP policy with a condition to block sharing of credit card numbers to external users except those from approved domains.
B.Create a DLP policy that blocks credit card numbers and set the action to 'Block external sharing' for all external users.
C.Use Microsoft Purview Information Protection to automatically apply a 'Confidential' label to messages containing credit card numbers and block forwarding.
D.Create a sensitivity label for credit card data and publish it to Teams, then configure auto-labeling.
AnswerA

A DLP policy lets you combine the sensitive info type condition (credit card numbers) with 'External sharing' and then use the action 'Restrict access to external users' to specify an allowed domain list via the 'Only people in domains on your approved list' option. This grants exceptions to approved external vendors while any other external recipient is blocked, exactly matching the requirement.

Why this answer

You can configure a DLP policy in Microsoft Purview to block sensitive data like credit card numbers in Teams messages, and use the 'Block sharing to external users except' condition to allow sharing with approved domains. This meets the requirement to prevent sharing with unauthorized external users while allowing sharing with approved vendors. Option B is wrong because blocking all external sharing is too restrictive and does not allow the approved external vendors.

Option C is wrong because Information Protection labels do not have the granular control over sharing conditions based on external domains. Option D is wrong because sensitivity labels are not designed for DLP actions such as blocking sharing in Teams chat based on external approval.

37
MCQeasy

Your organization uses Microsoft 365 and wants to prevent users from sharing sensitive documents externally via email. The solution must be able to detect credit card numbers and automatically block the email. Which technology should you use?

A.Microsoft Purview Sensitivity labels with auto-classification
B.Microsoft Defender for Office 365 Safe Attachments
C.Microsoft Purview Data Loss Prevention (DLP) policy for Exchange Online
D.Azure Information Protection (AIP) unified labeling client
AnswerC

A Microsoft Purview Data Loss Prevention (DLP) policy for Exchange Online is the only option that directly inspects email in transit for sensitive info types (e.g., PII, PCI, healthcare records) and applies actions like 'Reject the message', 'Encrypt', or 'Notify the sender' by leveraging Exchange mail flow rules. When a sensitive data match occurs, the policy can block the email from leaving the tenant, redirect it to a reviewer, or block only if the amount exceeds a threshold. This is precisely the protection needed to 'prevent us' from leaking data via email.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policy for Exchange Online is the correct choice because DLP is purpose-built to inspect email content in transit and detect sensitive information types such as credit card numbers, then automatically block or restrict the message per policy actions. It natively integrates with Exchange Online so detection and blocking happen at the mail-flow level without user intervention. Sensitivity labels with auto-classification apply classification and protection to content but do not themselves block an email from being sent externally based on credit card detection.

Safe Attachments focuses on malware detonation in attachments, not on detecting sensitive data patterns, and the AIP unified labeling client is a client-side labeling tool rather than a server-side email blocking control.

38
MCQmedium

A company uses Microsoft Defender for Cloud Apps to enforce session policies. The security team needs to block downloads of sensitive files from Microsoft 365 when accessed from unmanaged devices. Which type of policy should they configure?

A.File policy
B.Data Loss Prevention (DLP) policy in Microsoft 365
C.Session policy
D.Access policy
AnswerC

A session policy in Defender for Cloud Apps enforces real-time controls on user activities inside a cloud app by using Conditional Access App Control as a reverse proxy. When a user accesses a SaaS app from an unmanaged device, the proxy intercepts traffic and can apply actions such as blocking download, masking sensitive content, or restricting uploads based on the session's risk posture. This provides granular just-in-time enforcement at the session level, which is exactly what is needed to enforce controls in real time.

Why this answer

The correct answer is C, Session policy. In Microsoft Defender for Cloud Apps, session policies are used with Conditional Access App Control to monitor and control user sessions in real time, including blocking downloads of sensitive files from Microsoft 365 when accessed from unmanaged devices. This is the specific policy type designed for session-based enforcement, such as blocking downloads, uploads, or copy/paste actions during an active session.

A file policy (A) applies to files in connected cloud apps for governance and alerting but does not control live session actions like downloads from unmanaged devices. A DLP policy in Microsoft 365 (B) enforces data protection within Microsoft 365 workloads but does not provide the same session proxy-based control for unmanaged device access. An access policy (D) in Defender for Cloud Apps is used to allow or block app access based on conditions, not to block downloads within an active session.

39
MCQhard

A company uses Microsoft Defender for Cloud to protect their hybrid environment. They have on-premises servers that are monitored by Microsoft Defender for Servers. The security team notices that some servers are missing critical security updates. They want to automatically remediate missing updates on these servers. Which feature should they enable?

A.Adaptive Application Controls
B.Azure Automation Update Management
C.Azure Update Manager
D.Just-in-Time (JIT) VM access
AnswerC

Azure Update Manager is the current, first-party service for overseeing and applying OS updates across Azure VMs, on-premises servers, and machines in other cloud environments. It directly integrates with Defender for Cloud: the security recommendation 'Machines should have security updates installed' can be remediated using Azure Update Manager to establish a schedule or trigger immediate patching of non-compliant resources. This native integration makes it the appropriate tool for automatically remediating missing updates as part of a Defender for Cloud workflow.

Why this answer

Azure Update Manager (option C) is the correct choice because it is the native Azure service designed to assess and automatically remediate missing OS security updates across Azure, on-premises, and multicloud servers, including those onboarded to Microsoft Defender for Servers. It provides update assessment, scheduling, and automatic patching for Windows and Linux machines, which directly addresses the team's need to remediate missing updates on their hybrid servers. Adaptive Application Controls (option A) only create allowlist/denylist rules for applications to control execution and do not patch operating systems.

Azure Automation Update Management (option B) is the legacy predecessor that has been superseded by Azure Update Manager, so it is not the recommended feature. Just-in-Time VM access (option D) only restricts inbound management ports on VMs and has nothing to do with update remediation.

40
Multi-Selectmedium

Your organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft 365. You need to create a DLP policy that detects and blocks sharing of credit card numbers in Exchange Online emails. Which TWO components must you configure?

Select 2 answers
A.Retention label for financial data
B.Auto-labeling policy
C.Action to block sharing
D.Sensitive info type for credit card number
E.Trainable classifier for credit card numbers
AnswersC, D

A DLP rule is incomplete without an action that defines the enforcement response. For an email containing credit card data, the 'Block' action (often configured as 'Block the message from being sent' or 'Block sharing externally') is the critical component that stops the data exfiltration, fulfilling the DLP policy's purpose. This action ensures that when the sensitive info type condition matches, the mail flow is interrupted and the sender is notified or the message is quarantined.

Why this answer

Option D is correct because a DLP policy must reference a sensitive information type (SIT) — in this case the built-in 'Credit Card Number' SIT — so Purview can detect the credit card patterns in Exchange Online email content. Option C is correct because detection alone does nothing; the policy rule must define an action such as 'Block' (or restrict access/encrypt) to prevent the credit card data from being shared via email. Option A is incorrect because retention labels govern data lifecycle and retention, not real-time blocking of sensitive data sharing.

Option B is incorrect because auto-labeling policies apply sensitivity labels to content and do not enforce DLP blocking actions. Option E is incorrect because trainable classifiers are used for custom content categories (e.g., resumes, contracts), not for detecting standardized numeric patterns like credit card numbers, which are handled by built-in SITs.

41
MCQmedium

A company uses Microsoft 365 and wants to protect sensitive documents from being shared externally. They need a solution that automatically classifies documents containing personally identifiable information (PII) and applies appropriate protection. Which two services should they combine?

A.Microsoft Defender for Cloud Apps and Microsoft Intune
B.Microsoft Purview Compliance Manager and Microsoft Sentinel
C.Azure Information Protection and Microsoft Entra ID
D.Microsoft Purview Information Protection and Data Loss Prevention (DLP)
AnswerD

Microsoft Purview Information Protection is the unified labeling engine that applies sensitivity labels to documents and emails, enabling persistent classification, encryption, and visual markings, while DLP policies inspect content and detect labeled data to enforce actions such as blocking external sharing or quarantining risky messages. These two services work symbiotically: labels drive policy decisions, and DLP can also use content patterns alongside labels to catch violations. This is the current recommended architecture for protecting sensitive information in Microsoft 365, with AIP's legacy functionality replaced by Purview.

Why this answer

Microsoft Purview Information Protection allows for classification and labeling of documents based on content, while Data Loss Prevention (DLP) policies can enforce actions such as blocking external sharing or applying encryption. Together, they provide automated protection for sensitive documents like those containing PII. Option D is correct because these two services work together to classify and protect documents.

Option A is incorrect because Microsoft Defender for Cloud Apps focuses on SaaS app security and Intune is for device management; they do not directly classify documents. Option B is incorrect because Compliance Manager is for managing compliance posture, and Sentinel is a SIEM; they are not used for automatic document classification. Option C is incorrect because Azure Information Protection is a previous version, now part of Purview, and Microsoft Entra ID is an identity service; they do not provide the same integrated classification and DLP capabilities as the Purview solutions.

42
MCQhard

Your company uses Microsoft Azure to host a critical application that processes credit card payments. The application must comply with PCI DSS. You need to ensure that all access to cardholder data is logged and monitored, and that any unauthorized access attempts trigger an alert. Which combination of services should you use?

A.Azure Policy and Microsoft Defender for Cloud Apps
B.Azure Policy and Microsoft Defender for Cloud
C.Azure Key Vault and Microsoft Defender for Cloud
D.Azure Monitor and Microsoft Sentinel
AnswerD

Azure Monitor collects diagnostic logs, metrics, and activity data from Azure resources—such as App Service or virtual machines—into a Log Analytics workspace, forming the foundational telemetry pipeline for the critical application. Microsoft Sentinel then ingests those logs, uses built-in analytics rules and threat-intelligence correlation to detect suspicious behavior, and provides incident management and automated response (SOAR). This pairing directly satisfies the requirement to both log access/activity and alert on potential threats, making it the correct combination for detective security monitoring.

Why this answer

Azure Monitor and Microsoft Sentinel (option D) are the right combination because Azure Monitor collects and retains the logs and metrics from the application and its Azure resources, while Microsoft Sentinel ingests those logs to correlate events, detect unauthorized access attempts to cardholder data, and generate alerts via analytics rules and incident creation, satisfying PCI DSS logging and monitoring requirements. Azure Monitor provides the telemetry pipeline (Log Analytics workspace, diagnostic settings) and Sentinel adds SIEM/SOAR detection and alerting on top of it. Option A is wrong because Azure Policy enforces configuration compliance and Defender for Cloud Apps is a CASB for SaaS discovery/control, not a log-monitoring and alerting SIEM.

Option B is wrong because Azure Policy and Defender for Cloud provide posture management and threat protection but do not deliver the centralized log correlation and custom alerting on access to cardholder data that Sentinel does. Option C is wrong because Azure Key Vault only manages secrets, keys, and certificates, and Defender for Cloud alone does not provide the required log aggregation and alerting.

43
MCQhard

Your organization uses Microsoft Intune to manage devices. You need to deploy a line-of-business (LOB) app to iOS devices that is not available in the public App Store. The app is signed with an enterprise certificate. Which app deployment method should you use?

A.Android Enterprise managed Google Play
B.Volume Purchase Program (VPP) token
C.Microsoft Store for Business
D.iOS line-of-business app deployment in Intune
AnswerD

iOS line-of-business (LOB) deployment in Intune is explicitly designed for enterprise-signed apps: you upload an .ipa (or .app) package, sign it with an Apple Enterprise Developer certificate, and assign it to users or devices. Intune creates a configuration profile to trust the enterprise certificate, allowing the app to install directly rather than through the App Store. This is the only option here that supports the scenario's iOS LOB requirement.

Why this answer

The correct answer is D: iOS line-of-business app deployment in Intune. Intune supports deploying custom in-house iOS apps via the iOS LOB app type, which uploads the signed .ipa file and installs it on enrolled devices without requiring the public App Store, matching the scenario of an enterprise-certificate-signed LOB app. Option A (Android Enterprise managed Google Play) is for Android apps distributed through managed Google Play, not iOS.

Option B (VPP token) is used for purchasing and distributing App Store apps in volume, not for custom in-house iOS apps. Option C (Microsoft Store for Business) distributes Windows apps and is unrelated to iOS deployment.

44
MCQeasy

Your organization uses Microsoft Purview to classify and protect sensitive data. You need to prevent users from accidentally sharing files that contain credit card numbers via email. What should you configure in Microsoft Purview?

A.Enable Microsoft Defender for Cloud Apps session policy to monitor file downloads.
B.Configure a retention policy for files containing credit card numbers.
C.Implement a data loss prevention (DLP) policy that detects credit card numbers and blocks email sharing.
D.Create a sensitivity label that automatically classifies credit card numbers.
AnswerC

A data loss prevention (DLP) policy in Microsoft Purview can be configured with a rule that uses a sensitive info type for credit card numbers, then applies an action to block external email sharing. This directly satisfies the stem’s constraint of preventing accidental sharing via email, as the policy inspects message content and enforces the block before the email is sent.

Why this answer

A DLP policy in Microsoft Purview is purpose-built to detect sensitive information types such as credit card numbers (via the built-in 'Credit Card Number' SIT, which uses regex plus Luhn checksum validation) and to enforce protective actions like blocking email sharing. DLP policies can be scoped to Exchange Online, SharePoint, OneDrive, and Teams, and can block or encrypt content when the sensitive data is detected. This directly addresses the requirement to prevent accidental email sharing of files containing credit card numbers.

Exam trap

SC-100 often tests the distinction between classification (sensitivity labels) and enforcement (DLP policies) — candidates incorrectly assume a sensitivity label alone blocks sharing, when enforcement requires a DLP or auto-labeling policy.

How to eliminate wrong answers

Option A is wrong because Defender for Cloud Apps session policies govern access to cloud apps (e.g., blocking downloads in a browser session) and do not inspect email content for credit card numbers. Option B is wrong because retention policies only govern how long content is kept or when it is deleted; they do not detect or block sensitive data sharing. Option D is wrong because a sensitivity label classifies and can protect content (e.g., encryption), but by itself it does not automatically detect credit card numbers or block email sharing — that requires an auto-labeling policy or a DLP policy to enforce the block.

45
MCQmedium

You are designing a data classification strategy for a Microsoft 365 tenant. You need to automatically classify documents that contain personally identifiable information (PII) and apply a retention label. Which Microsoft Purview feature should you use?

A.Auto-labeling policies
B.Trainable classifiers
C.Manual labeling
D.Data Loss Prevention (DLP) policies
AnswerA

Auto-labeling policies in Microsoft Purview apply sensitivity labels automatically to emails and files when they match configured conditions, such as sensitive information types like Social Security numbers or credit card numbers. Because they rely on built-in detection engines rather than user input or custom model training, they are the simplest and most consistent way to automatically label PII content in a data classification strategy. A policy can be run in simulation mode to review the labels before enforcing, then set to auto-label new and existing items.

Why this answer

Auto-labeling policies (option A) are the correct choice because they can automatically apply sensitivity or retention labels to documents in Microsoft 365 services such as SharePoint, OneDrive, and Exchange when content matches specified conditions, including sensitive information types like PII. They are designed specifically for automatic classification and labeling at scale, which matches the requirement to classify PII-containing documents and apply a retention label. Trainable classifiers (option B) can identify content based on examples, but they are used to detect custom content types and still require a labeling policy to apply labels, so they are not the primary feature for this scenario.

Manual labeling (option C) requires user intervention and does not meet the need for automatic classification. DLP policies (option D) can detect and protect sensitive information, but they do not apply retention labels; they enforce actions like blocking or notifying.

46
MCQhard

Your organization uses Microsoft Sentinel to detect threats. You need to design a solution that automatically remediates a detected threat on an Azure VM by isolating the VM from the network. What should you use?

A.Create a Microsoft Sentinel automation rule that triggers a playbook to run an Azure Automation runbook to modify the NSG.
B.Configure a Log Analytics workspace query to run on a schedule and automatically block the VM.
C.Use Azure Policy to audit and automatically remediate non-compliant VMs.
D.Enable Microsoft Defender for Cloud's 'Just-in-time VM access' policy.
AnswerA

Microsoft Sentinel automation rules are designed to invoke playbooks (Logic Apps) in response to security alerts. A playbook can call an Azure Automation runbook, which can programmatically update the NSG to add a deny rule for the compromised VM, quarantining it from network traffic. This is the correct SOAR-based remediation approach because it leverages Sentinel's native alert triggers and Azure Automation's compute capabilities.

Why this answer

Microsoft Sentinel can trigger a playbook (automation rule) that runs an Azure Automation runbook to modify the NSG and isolate the VM. Option B is wrong because Log Analytics workspace doesn't have remediation actions. Option C is wrong because Azure Policy is for compliance, not incident response.

Option D is wrong because Defender for Cloud has some automation, but Sentinel playbook is the designed method for automated response.

47
Multi-Selecthard

Your company is designing a zero-trust security posture for a new application in Azure. The application uses Azure Functions, Azure SQL Database, and Azure Blob Storage. You need to ensure that data in transit is encrypted and that the application can authenticate without storing secrets in code. Which THREE actions should you take?

Select 3 answers
A.Enable 'Enforce minimum TLS version' on the Blob Storage account
B.Configure the application to use TLS 1.2 or higher for all connections
C.Use managed identity for Azure Functions to access Azure SQL Database
D.Enable customer-managed keys (CMK) for Azure SQL Database
E.Configure the Azure SQL firewall to allow only the Functions IP range
AnswersA, B, C

Enabling 'Enforce minimum TLS version' on the Blob Storage account is a server-side control that rejects any connection attempting to use TLS 1.0 or 1.1, forcing clients to negotiate TLS 1.2 or higher for all data transfers. This is a critical zero-trust measure for encryption in transit, as it ensures that data traveling between the client and Blob Storage is protected by a modern cipher suite. It also prevents downgrade attacks where an attacker could force a weaker protocol.

Why this answer

Options A, B, and C are correct. Enforcing a minimum TLS version on Blob Storage (A) and configuring the application to use TLS 1.2 or higher (B) both ensure data in transit is encrypted. Using managed identity for Azure Functions to access Azure SQL Database (C) provides secretless authentication.

Option D (CMK) encrypts data at rest, not in transit. Option E (firewall IP restriction) controls network access but does not encrypt data in transit.

48
MCQeasy

You are designing a secure DevOps pipeline using GitHub Actions and Azure. The security team requires that all container images pushed to Azure Container Registry (ACR) are scanned for vulnerabilities before deployment. If critical vulnerabilities are found, the pipeline must fail. What should you integrate into the pipeline?

A.Configure Azure Policy to require image scanning before deployment
B.Integrate Microsoft Defender for Cloud with Azure Container Registry scanning and configure a GitHub Actions step to check scan results
C.Deploy Azure Bastion to scan images during build
D.Use Azure Security Center (legacy) to scan images on push
AnswerB

Microsoft Defender for Cloud provides integrated vulnerability assessment for Azure Container Registry (ACR) images, using the Qualys scanner, which detects OS package and known software vulnerabilities. After enabling Defender for Cloud on the subscription or specifically for ACR, you can programmatically query scan results via the Microsoft Defender for Cloud REST API (e.g., Assessments - Get) or use the az acr security-status command to retrieve findings. A GitHub Actions step can then call this API in a script, parse the severity levels, and conditionally fail the job if critical or high vulnerabilities exceed a threshold. This architectural pattern is a valid 'shift-left' security gate because the scan occurs on the registry image before deployment, and the workflow enforces the policy based on real-time data.

Why this answer

Option B is correct because Microsoft Defender for Cloud's container registry scanning (Defender for Containers) integrates natively with ACR to scan images on push, and a GitHub Actions step can query the scan results via the Azure CLI/REST API and fail the pipeline when critical vulnerabilities are detected. This directly satisfies the requirement to block deployment when critical findings exist. Option A does not fit because Azure Policy enforces governance on deployed resources and cannot fail a GitHub Actions build step based on scan results.

Option C is wrong because Azure Bastion is a managed jump-host service for RDP/SSH access, not an image scanner. Option D is wrong because Azure Security Center is the legacy name for Defender for Cloud and, by itself, does not provide the pipeline-failing GitHub Actions integration described in B.

49
MCQeasy

Your organization uses Microsoft Sentinel to detect threats. You need to ensure that sensitive data stored in Azure SQL Database is protected from unauthorized access by Sentinel playbooks. What should you implement?

A.Enable dynamic data masking on the SQL database
B.Use customer-managed keys (CMK) for SQL Transparent Data Encryption
C.Configure Azure SQL firewall rules to allow only Sentinel IP addresses
D.Use a managed identity assigned to the playbook to authenticate to Azure SQL
AnswerD

Assigning a managed identity to the playbook (a Logic App) enables it to authenticate to Azure SQL using Microsoft Entra ID tokens, eliminating hard-coded secrets. You must create a contained database user mapped to that identity (e.g., CREATE USER FROM EXTERNAL PROVIDER) and grant least-privilege permissions. This is the correct approach because it provides secure, credential-free, and automatically rotating authentication for automated workflows.

Why this answer

The correct option is D: use a managed identity assigned to the playbook to authenticate to Azure SQL. In Microsoft Sentinel, playbooks are Logic Apps, and when they need to access Azure SQL Database, the recommended approach is to assign a managed identity to the playbook and grant that identity the appropriate database permissions, so no credentials are stored and access is scoped to the playbook. This directly protects sensitive data by ensuring only the authorized playbook identity can authenticate to Azure SQL.

Option A (dynamic data masking) limits data exposure in query results but does not control which principals can access the database. Option B (CMK for TDE) protects data at rest via encryption key management, not playbook authorization. Option C (SQL firewall rules for Sentinel IPs) is impractical because Sentinel playbooks run as Logic Apps without a fixed, reliable set of Sentinel IP addresses, and firewall rules alone do not authenticate the playbook.

50
Multi-Selecthard

You are designing a solution to protect Azure SQL Database from SQL injection attacks. The solution must use a web application firewall (WAF) and also ensure that queries from the application are parameterized. Which two components should you include? (Choose two. Each correct answer presents part of the solution.)

Select 2 answers
A.Azure SQL Database firewall rules
B.Transparent Data Encryption (TDE)
C.Azure Application Gateway with WAF
D.Parameterized queries in the application code
AnswersC, D

Azure Application Gateway with Web Application Firewall (WAF) inspects inbound HTTP/HTTPS traffic at the application layer and applies the OWASP Core Rule Set, which includes specialized SQL injection rules. It can detect and block malicious patterns in query strings, request bodies, and headers before the request reaches Azure SQL Database. This provides a centralized, cloud-managed defense layer that is particularly effective for public web applications exposing APIs or SQL-backed endpoints.

Why this answer

Option C is correct because Azure Application Gateway with WAF provides a web application firewall that can inspect incoming HTTP/HTTPS traffic and block common SQL injection patterns using OWASP rule sets before requests reach the application or database. Option D is correct because parameterized queries in the application code ensure user input is treated as data rather than executable SQL, which is the primary defense against SQL injection at the application layer. Together, these two components satisfy both stated requirements: a WAF and parameterized queries.

Option A, Azure SQL Database firewall rules, only controls which IP addresses or Azure services can connect to the database and does not inspect query content for injection attacks. Option B, Transparent Data Encryption (TDE), encrypts data at rest and does not prevent SQL injection or filter malicious queries.

51
MCQeasy

Refer to the exhibit. You are analyzing sign-in failures in Microsoft Sentinel using a KQL query. What does this query identify?

A.Accounts that have been locked out due to multiple failures.
B.Computers with more than 10 login attempts from the same IP address.
C.Accounts that had more than 10 failed logon attempts in the last 7 days.
D.Accounts that successfully logged in more than 10 times.
AnswerC

Event ID 4625 is generated for every failed logon attempt, and the query sums these records by account and computer, then applies a threshold of greater than 10 to the count within the last seven days. This yields accounts that exceeded ten failed logon attempts in that rolling window, which is exactly the indicated answer. The per-computer grouping means an account must exceed the threshold on a single computer, not across all computers taken together.

Why this answer

The correct answer is C: Accounts that had more than 10 failed logon attempts in the last 7 days. This is because the KQL query filters SigninLogs for failed sign-in results (e.g., ResultType != 0 or ResultType == 50126) and summarizes the count by user over a 7-day window, returning accounts whose failure count exceeds 10. Option A is wrong because account lockout is a specific event/status (e.g., ResultType 50053) and the query counts failures rather than lockout events.

Option B is wrong because the query aggregates by account, not by computer or source IP address. Option D is wrong because the query targets failed logons, not successful sign-ins.

52
MCQeasy

You are designing a secure data classification strategy for documents in Microsoft 365. The compliance officer wants to automatically apply a 'Confidential' label to documents containing credit card numbers. Which Microsoft Purview feature should you use?

A.Auto-labeling policies
B.Data loss prevention policies
C.Trainable classifiers
D.Manual labeling
AnswerA

Auto-labeling policies in Microsoft Purview can automatically assign sensitivity labels to files and emails when their content matches built-in sensitive info types, such as credit card numbers, at a specified confidence or instance count. These policies run service-side on Exchange, SharePoint, and OneDrive, meaning content is evaluated by the service without requiring a user to open or interact with it. A policy simulation mode lets you test which items would be labeled before enforcing the rule, and once applied, the label can trigger protective actions like encryption. This directly meets the requirement of automatically applying labels based on predefined sensitive data patterns.

Why this answer

Auto-labeling policies (option A) are the correct choice because they are the Microsoft Purview feature designed to automatically apply sensitivity labels to content that matches specified conditions, such as documents containing credit card numbers detected via sensitive information types. This directly satisfies the compliance officer's requirement to apply a 'Confidential' label automatically without user intervention. Data loss prevention policies (B) can detect and block or warn about sensitive content but do not apply sensitivity labels.

Trainable classifiers (C) can identify content categories by example, but they are used as conditions within labeling or DLP, not as the labeling mechanism itself. Manual labeling (D) requires users to apply labels themselves, which does not meet the automation requirement.

53
MCQmedium

Your company uses Microsoft Intune to manage mobile devices. You need to ensure that corporate data in Microsoft 365 apps cannot be copied to personal apps on the same device. What should you configure?

A.App protection policy (MAM) with 'Restrict cut, copy, and paste'
B.Conditional Access policy requiring compliant device
C.Device configuration profile with restrictions
D.Device compliance policy for mobile devices
AnswerA

App protection policy (MAM) with 'Restrict cut, copy, and paste' is correct because it applies at the application layer, targeting the clipboard as a data-channel control. This setting explicitly defines which apps can receive data copied from a managed app, typically allowing only other managed apps. It is effective even on unenrolled BYOD devices because it operates through the Intune App SDK/wrapped apps, not through device management. Unlike Conditional Access or device policies, this granular DLP control directly governs data transfer between managed and unmanaged apps.

Why this answer

The correct answer is A: an App protection policy (MAM) with 'Restrict cut, copy, and paste'. App protection policies in Intune operate at the app layer, so they can block copying corporate data from Microsoft 365 apps into personal apps on the same device, even on unmanaged or BYOD devices. This directly addresses the requirement to prevent data leakage between managed and personal apps.

Option B (Conditional Access requiring a compliant device) controls access to resources but does not prevent copy/paste between apps. Option C (device configuration profile with restrictions) applies device-level settings and cannot selectively govern app-to-app data sharing. Option D (device compliance policy) only evaluates and reports device state; it does not enforce app-level copy/paste restrictions.

54
MCQeasy

You are designing a solution to protect an Azure App Service web application from common web attacks like SQL injection and cross-site scripting. What should you implement?

A.Azure Firewall
B.Azure DDoS Protection
C.Azure Web Application Firewall (WAF) policy on Azure Front Door
D.Network Security Groups (NSGs) on the subnet
AnswerC

A WAF policy on Azure Front Door inspects HTTP traffic at the edge, applying managed rule sets that block SQL injection and cross-site scripting before requests reach App Service, satisfying the requirement to protect against common web attacks.

Why this answer

Azure Web Application Firewall (WAF) policy on Azure Front Door (option C) is correct because WAF is specifically designed to inspect HTTP/HTTPS traffic and block Layer 7 attacks such as SQL injection and cross-site scripting using managed rule sets (OWASP rules). Azure Front Door provides global edge delivery and integrates WAF policies directly, making it the appropriate choice for protecting a public web application. Azure Firewall (A) is a Layer 3-4 network firewall with limited FQDN filtering and does not provide OWASP-style web attack protection.

Azure DDoS Protection (B) mitigates volumetric and protocol-level attacks, not application-layer injection or scripting attacks. NSGs (D) filter traffic by IP, port, and protocol at the network layer and cannot inspect HTTP payloads for SQLi or XSS.

55
MCQeasy

Your organization uses Microsoft Purview to govern data assets across Azure and on-premises. You need to automatically classify sensitive data such as credit card numbers in Azure SQL Database. What should you use?

A.Microsoft Purview Data Map
B.Microsoft Defender for Cloud
C.Microsoft Entra ID
D.Microsoft Sentinel
AnswerA

The Microsoft Purview Data Map is the correct choice because it performs automated scans of registered data sources, applying built-in and custom classifiers to identify sensitive content such as PII and financial data, and then publishing those classifications as business assets. It also integrates with sensitivity labels from Microsoft Purview Information Protection, giving a centralized, governed map of your data estate for classification and lineage. No other Azure service directly scans and classifies data at this asset level.

Why this answer

Microsoft Purview Data Map is the correct choice because it is the component that scans and automatically classifies data sources such as Azure SQL Database, detecting sensitive information types like credit card numbers and applying classifications. It builds the metadata catalog and applies built-in or custom classification rules during scans, which is exactly what's needed for automated sensitive-data discovery. Microsoft Defender for Cloud provides security posture management and threat protection, not data classification.

Microsoft Entra ID handles identity and access management, and Microsoft Sentinel is a SIEM/SOAR solution for security analytics, so neither performs data classification.

56
Multi-Selecthard

Which THREE actions should you take to secure a CI/CD pipeline using Azure DevOps and GitHub?

Select 3 answers
A.Enable secret scanning in GitHub to detect leaked credentials
B.Run all pipeline tasks with administrative privileges
C.Disable pull request code reviews to speed deployment
D.Store secrets in Azure Key Vault and use variable groups linked to Key Vault
E.Configure branch protection rules in GitHub to require status checks
AnswersA, D, E

GitHub secret scanning automatically detects known patterns of credentials such as Azure Active Directory client secrets, AWS access keys, and private keys within repository content. When a match is found, GitHub alerts the organization or individual, and optionally integrates with secret scanning partners to revoke the leaked credential. This proactive detection helps prevent accidental exposure of secrets that could be used for unauthorized access, but it should be part of a broader strategy that includes preventing secrets from entering repos in the first place.

Why this answer

Option A is correct because enabling secret scanning in GitHub automatically detects committed credentials such as API keys and tokens, allowing them to be revoked before they can be exploited in the pipeline. Option D is correct because storing secrets in Azure Key Vault and referencing them through variable groups linked to Key Vault keeps credentials out of pipeline YAML and repository history, enforcing centralized access control and auditing. Option E is correct because branch protection rules in GitHub that require status checks prevent unreviewed or failing code from being merged, ensuring only validated commits reach the CI/CD pipeline.

Option B is incorrect because running all pipeline tasks with administrative privileges violates least privilege and expands the blast radius of a compromised task. Option C is incorrect because disabling pull request code reviews removes a critical human verification gate and increases the risk of malicious or flawed code being deployed.

57
MCQmedium

Your organization is deploying Microsoft Defender for Cloud Apps. You need to create a policy that blocks downloads of sensitive files from sanctioned cloud apps to unmanaged devices. What type of policy should you create?

A.Session policy
B.App discovery policy
C.Anomaly detection policy
D.Access policy
AnswerA

Session policies in Microsoft Defender for Cloud Apps operate in real time via a reverse proxy to enforce granular conditional access actions on a user's session. They can explicitly block downloads, uploads, and copy/paste based on risk signals such as device posture or user behavior, making them the correct policy type for preventing data exfiltration.

Why this answer

A session policy (option A) is correct because in Microsoft Defender for Cloud Apps, session policies are used with Conditional Access App Control to monitor and control user sessions in real time, including blocking downloads of sensitive files from sanctioned cloud apps to unmanaged devices. Session policies can apply actions such as block download, protect, or block based on the sensitivity of the content and the device state. App discovery policies (option B) are used to identify and assess shadow IT and unsanctioned apps, not to control file downloads in real time.

Anomaly detection policies (option C) trigger alerts on unusual user behavior but do not enforce download blocking. Access policies (option D) in Defender for Cloud Apps are used to allow or block sign-ins to apps based on conditions, not to control in-session file download activity.

58
MCQhard

A healthcare organization uses Microsoft Purview Information Protection to classify and protect patient data. They want to automatically apply a 'High Confidentiality' label to any document containing a patient ID pattern (###-####). The label should also encrypt the document. Which configuration should they use?

A.Retention label with auto-labeling policy
B.Data Loss Prevention (DLP) policy with a block action
C.Sensitivity label with auto-labeling for sensitive info types
D.Trainable classifier with a retention policy
AnswerC

This is the correct choice: a sensitivity label with auto-labeling for sensitive info types (e.g., a patient ID regex) can be delivered through an auto-labeling policy in Purview, and the label can be configured with encryption via Azure Rights Management. When the label is applied, it encrypts the file, sets viewer/edit permissions, and embeds persistent protection metadata so that the PHI remains protected both at rest and when shared. Because both the classification trigger and the encryption action are integral to the sensitivity label, it uniquely combines automated detection with immediate protection.

Why this answer

To automatically apply a label that encrypts documents containing a patient ID pattern, the organization should use a sensitivity label with auto-labeling configured for sensitive info types. Sensitivity labels can enforce encryption and are applied automatically based on conditions such as the presence of sensitive information types (e.g., a custom regex for ###-####).

Exam trap

SC-100 often tests the confusion between retention labels, DLP policies, and sensitivity labels, and candidates may incorrectly choose DLP or retention when the requirement is automatic classification with encryption, which is a sensitivity label feature.

How to eliminate wrong answers

Option A is wrong because retention labels are used for data lifecycle management (retain or delete) and do not provide encryption or classification based on sensitive info types. Option B is wrong because a DLP policy with a block action can prevent sharing but does not apply a label or encrypt the document; it enforces actions but not classification. Option D is wrong because a trainable classifier is used to identify content based on examples, but it does not automatically apply a sensitivity label with encryption; it is typically used in conjunction with auto-labeling policies, but the label itself must be a sensitivity label.

59
MCQhard

You are designing a data classification strategy for Microsoft Purview. The compliance team requires that documents containing personally identifiable information (PII) like credit card numbers are automatically labeled and encrypted when stored in Microsoft SharePoint Online. The solution must use built-in sensitive information types. What should you include in the design?

A.Create a sensitivity label with auto-labeling for credit card numbers and enable encryption
B.Create a retention label and apply it automatically via a data loss prevention (DLP) policy
C.Use a trainable classifier to detect PII and apply a sensitivity label
D.Configure a manual sensitivity label policy for users to apply
AnswerA

This is correct because a sensitivity label can be configured with auto-labeling rules and encryption so that when an item in SharePoint Online, OneDrive, or Exchange contains a credit card number (detected by the built-in Credit Card Number sensitive information type), the label is applied automatically and the file or email is protected with Azure Rights Management encryption. The auto-labeling policy can run as a simulation first to evaluate matches, then be enforced, ensuring both classification and protection happen without user action. This architecture directly satisfies a requirement for automatic classification and encryption.

Why this answer

Option A is correct because Microsoft Purview sensitivity labels support auto-labeling policies that can use built-in sensitive information types (SITs) such as Credit Card Number, and the label itself can enforce encryption via the label's encryption settings when applied to documents in SharePoint Online. This directly satisfies the requirement to automatically label and encrypt PII-containing documents using built-in SITs. Option B is incorrect because retention labels govern retention/deletion, not encryption, and DLP policies do not apply retention labels.

Option C is incorrect because trainable classifiers are for custom content patterns, not built-in PII SITs like credit card numbers. Option D is incorrect because manual labeling does not meet the automatic labeling requirement.

60
MCQhard

A company uses Azure Cosmos DB with Microsoft Defender for Cloud to protect its NoSQL database. The security team wants to audit all data plane operations for compliance. Which diagnostic setting should they enable?

A.MongoRequests
B.PartitionKeyStatistics
C.QueryRuntimeStatistics
D.DataPlaneRequests
AnswerD

DataPlaneRequests is the diagnostic log that records every data plane request against an Azure Cosmos DB account, regardless of the API in use (SQL, MongoDB, Cassandra, Gremlin, Table). Each entry includes the operation type (e.g., create, read, upsert, delete, query), resource URI, partition key range, current status code, request charge, client IP, and authentication token type. This comprehensive coverage of all CRUD and other data operations makes it the correct source for auditing and forensic analysis of data plane activity.

Why this answer

The correct option is D, DataPlaneRequests. This diagnostic setting in Azure Cosmos DB logs all data plane operations, including CRUD actions on documents, which is exactly what the security team needs to audit for compliance. The other options do not fit: MongoRequests only captures requests for the MongoDB API, PartitionKeyStatistics provides metrics on partition key usage, and QueryRuntimeStatistics logs query execution details rather than a full audit of data plane operations.

61
MCQeasy

Your organization, Adatum, is migrating its on-premises applications to Azure. The applications include a legacy .NET Framework web app that uses Windows authentication and a modern ASP.NET Core API that uses OAuth 2.0. You need to design a secure solution for these applications using Azure App Service. The security requirements include: (1) enforce HTTPS only, (2) restrict access to the web app based on the user's corporate identity, (3) allow the API to access an Azure SQL Database using a managed identity. Which of the following is the correct design?

A.Configure the web app to use Windows authentication via Azure AD Domain Services, and the API to use SQL authentication with a managed identity.
B.Configure the web app to use Microsoft Entra ID authentication with a built-in policy, and the API to use a connection string with a username and password.
C.Configure the web app to require client certificates for authentication, and the API to use a connection string with SQL authentication.
D.Configure both apps to enforce HTTPS only, configure the web app to use Microsoft Entra ID authentication, and configure the API to use a system-assigned managed identity to access Azure SQL Database.
AnswerD

Enforcing HTTPS on both apps meets requirement one, Microsoft Entra ID authentication on the web app restricts access by corporate identity, and a system-assigned managed identity lets the API reach Azure SQL Database without stored secrets.

Why this answer

Option D is correct because it satisfies all three requirements: enabling HTTPS-only on both apps enforces TLS, configuring the web app with Microsoft Entra ID authentication restricts access based on corporate identity, and using a system-assigned managed identity lets the API authenticate to Azure SQL Database without storing credentials. Managed identity works with Azure SQL via Entra ID authentication, so no password is needed in the connection string. Option A is wrong because Azure AD Domain Services-based Windows authentication is not the recommended App Service approach and SQL authentication with a managed identity is contradictory.

Option B is wrong because a username/password connection string does not use managed identity. Option C is wrong because client certificates do not provide corporate identity-based access and SQL authentication does not meet the managed identity requirement.

62
MCQmedium

A financial services company is designing a security strategy for its Azure SQL Database. The database contains sensitive financial data. The company requires that all connections to the database be encrypted and that the database be protected against SQL injection attacks. Additionally, they need to monitor and audit all database activities for compliance. Which Azure features should the security architect recommend?

A.Use Azure Private Link to connect to the database, enable Always Encrypted for sensitive columns, and use Azure Policy to enforce auditing.
B.Configure Azure SQL Database firewall rules to restrict IP addresses, enable Transparent Data Encryption (TDE), and use Azure Monitor for auditing.
C.Enforce TLS 1.2 for connections, enable Azure Defender for SQL, and configure auditing to Azure Monitor logs.
D.Enable Azure SQL Database auditing to a storage account, configure Advanced Threat Protection, and enforce TLS 1.2 for connections.
AnswerC

Enforcing TLS 1.2 ensures encrypted connections. Azure Defender for SQL (part of Microsoft Defender for Cloud) provides vulnerability assessment and advanced threat protection, including detection of SQL injection attempts. Configuring auditing to Azure Monitor logs enables monitoring and auditing of database activities. This combination addresses all three requirements: encryption, SQL injection protection, and auditing.

Why this answer

The requirements are encrypted connections, SQL injection protection, and auditing. Enforcing TLS 1.2 ensures connections are encrypted. Azure Defender for SQL provides advanced threat protection that detects and alerts on SQL injection attempts.

Configuring auditing to Azure Monitor logs centralizes monitoring and auditing. Together, these features meet the security and compliance needs for the Azure SQL Database.

Exam trap

The trap here is equating network-level protections like firewall rules or Private Link with application-layer SQL injection prevention, which requires threat detection and secure coding practices.

63
Multi-Selectmedium

Which THREE security controls should you implement to protect a web application against common OWASP Top 10 vulnerabilities?

Select 3 answers
A.Role-Based Access Control (RBAC)
B.Input validation on all user inputs
C.Content Security Policy (CSP) headers
D.Web Application Firewall (WAF)
E.Multi-factor authentication (MFA)
AnswersB, C, D

Input validation is a secure-coding control that rejects or sanitizes any user-supplied data that does not conform to expected formats, types, or lengths before the application processes it. By applying allowlist patterns and output encoding, it prevents malicious payloads from being interpreted as executable code, directly thwarting SQL injection, command injection, and stored/reflected XSS. It must be applied both on the client for UX and, critically, on the server as the authoritative enforcement point, and it is the first line of defense against the OWASP Top 10.

Why this answer

Input validation on all user inputs (B) is correct because it directly mitigates injection flaws such as SQL injection, command injection, and cross-site scripting (XSS) by rejecting or sanitizing untrusted data before it reaches interpreters or the browser. Content Security Policy (CSP) headers (C) are correct because they restrict which scripts, styles, and other resources the browser may load, providing defense-in-depth against XSS and data injection attacks listed in the OWASP Top 10. A Web Application Firewall (WAF) (D) is correct because it inspects HTTP/HTTPS traffic and blocks common attack patterns like SQLi, XSS, and path traversal, offering a compensating control for vulnerabilities that may not yet be patched in the application.

Role-Based Access Control (A) and Multi-factor authentication (E) are valuable identity and access management controls, but they address authentication and authorization concerns rather than the broad set of injection, misconfiguration, and client-side vulnerabilities targeted by the OWASP Top 10, so they are not among the three required controls here.

64
MCQeasy

A company uses Microsoft Sentinel for SIEM. They need to ensure that security events from Azure Active Directory (now Microsoft Entra ID) are ingested into Sentinel. Which data connector should they enable?

A.Microsoft Entra ID connector
B.Office 365 connector
C.Azure Activity connector
D.Microsoft Defender XDR connector
AnswerA

The Microsoft Entra ID connector (formerly Azure AD) is the correct choice because it directly ingests SigninLogs and AuditLogs from Entra ID into Sentinel. These tables contain authentication attempts, conditional access results, and user and group administrative changes, which are the exact identity telemetry the customer needs. This connector enables you to build analytics rules for sign-in anomalies, MFA failures, and suspicious audit activity.

Why this answer

The Microsoft Entra ID connector (option A) is correct because it is the built-in Microsoft Sentinel data connector designed to ingest sign-in logs, audit logs, and other security events from Azure Active Directory / Microsoft Entra ID. Enabling it streams Entra ID diagnostic logs into the Sentinel workspace for analytics and detection. The Office 365 connector (B) ingests Exchange, SharePoint, and Teams activity logs, not Entra ID sign-in or audit events.

The Azure Activity connector (C) collects subscription-level control-plane operations from Azure Resource Manager, not directory events. The Microsoft Defender XDR connector (D) pulls alerts and incidents from Defender services rather than raw Entra ID security logs.

65
MCQmedium

You are reviewing a Conditional Access policy in Microsoft Entra ID. The policy is intended to block sign-ins from high-risk users. However, some high-risk users are still able to sign in. What is the most likely reason?

A.The policy is not enforced because user risk is not being evaluated (e.g., missing licenses or risk policy)
B.The policy does not include all client app types
C.The policy is set to report-only mode
D.The policy does not include all locations
AnswerA

The user risk condition in Conditional Access depends on Azure AD Identity Protection's risk signals. Without Azure AD Premium P2 licenses, or if the Identity Protection risk policy is not configured, the user risk condition has no data to evaluate, so the condition is never satisfied and the policy never applies. Consequently, even though the policy appears active, it will not enforce its access controls because risk evaluation is effectively skipped.

Why this answer

The correct answer is A: the policy is not enforced because user risk is not being evaluated (e.g., missing licenses or risk policy). For a Conditional Access policy that blocks high-risk users to work, Microsoft Entra ID Protection must actually compute user risk, which requires Entra ID P2 (or equivalent) licensing and the risk detections feeding the risk level; if risk is never evaluated, the condition never matches and high-risk users sign in. Report-only mode (C) would also let users through, but it is a deliberate configuration state rather than the most likely cause of risk-based enforcement silently failing, and the scenario implies the policy is intended to be active.

Options B and D are irrelevant here because client app types and locations are separate conditions that do not affect whether user risk is evaluated.

66
Multi-Selectmedium

Your organization is designing a security solution for a new web application that will be deployed on Azure App Service. The application will access an Azure SQL Database and an Azure Storage account. The security requirements include: (1) use managed identities for authentication, (2) encrypt data at rest and in transit, (3) restrict network access to the database and storage account to only the App Service, and (4) use Azure Key Vault for secrets management. Which TWO of the following should you implement?

Select 2 answers
A.Configure the App Service to use a connection string with a storage account access key.
B.Configure private endpoints for the SQL Database and Storage account.
C.Configure the App Service to use a system-assigned managed identity.
D.Use shared access signatures (SAS) for the App Service to access the Storage account.
E.Configure service endpoints for the SQL Database and Storage account.
AnswersB, C

Private endpoints for Azure SQL Database and Azure Storage assign each resource a private IP address from your virtual network, ensuring that all traffic to these PaaS services traverses the Microsoft backbone network and never the public internet. This provides strong network-level isolation because the service endpoint is only reachable from your VNet, and you can disable public access entirely, eliminating exposure to internet-based attacks. Private endpoints also support Azure Private Link, which integrates with network security groups, route tables, and on-premises connectivity via VPN or ExpressRoute. Unlike service endpoints, private endpoints give you granular control over which specific resource instances can be accessed, not just the service as a whole.

Why this answer

Option B is correct because private endpoints assign a private IP address from your virtual network to the Azure SQL Database and Storage account, so those PaaS services are reachable only through the private link and public network access can be disabled, satisfying the requirement to restrict network access to only the App Service (when the App Service is VNet-integrated). Option C is correct because a system-assigned managed identity gives the App Service an identity in Microsoft Entra ID, allowing it to authenticate to Azure SQL Database and Storage without storing credentials, which directly fulfills the managed-identity authentication requirement. Option A is incorrect because using a storage account access key in a connection string relies on a shared secret rather than a managed identity and exposes a highly privileged key.

Option D is incorrect because SAS tokens are shared secrets with delegated permissions, not managed-identity authentication, and they do not restrict network access to the App Service. Option E is incorrect because service endpoints only extend the VNet identity to the PaaS service over the Azure backbone; they do not give the SQL Database or Storage account a private IP, and the service still exposes a public endpoint, so they do not meet the strict 'only the App Service' network restriction as well as private endpoints do.

Exam trap

SC-100 often tests the difference between service endpoints and private endpoints; candidates may choose service endpoints thinking they restrict access to a specific resource, but they only restrict to a subnet and do not provide private IP connectivity.

67
MCQmedium

Your organization is designing a solution to protect sensitive data in Microsoft SharePoint Online. You need to ensure that documents containing credit card numbers are automatically encrypted when shared with external users. What should you configure?

A.A Data Loss Prevention (DLP) policy that blocks sharing
B.Information Rights Management (IRM) for SharePoint
C.An auto-labeling policy for sensitivity labels with encryption
D.A retention policy with a hold
AnswerC

An auto-labeling policy for sensitivity labels with encryption is correct because it uses sensitive info types or trainable classifiers to scan content and automatically apply a label that triggers Microsoft 365 encryption (AES-256) and rights management. This label persists with the file or email and enforces policies such as view-only, Do Not Forward, watermarking, and conditional access, regardless of where the data is stored or shared. Because the encryption is tied to the label and managed by Azure AD RMS, the protection is permanent and follows the data even when it leaves the tenant or is copied to other applications, meeting the core requirement to protect sensitive data automatically.

Why this answer

The correct option is C: an auto-labeling policy for sensitivity labels with encryption. In Microsoft Purview, auto-labeling policies scan SharePoint Online content for sensitive information types such as credit card numbers and automatically apply a sensitivity label; when that label is configured with encryption, the document is encrypted and the protection travels with the file even when shared with external users. Option A is wrong because a DLP policy that blocks sharing prevents external sharing rather than encrypting the document, and DLP does not itself apply encryption.

Option B is wrong because SharePoint IRM encrypts files at rest in the library and relies on the service to enforce permissions, but it does not automatically classify and encrypt documents based on sensitive content detection. Option D is wrong because a retention policy with a hold only preserves content for compliance and does not encrypt it.

68
MCQeasy

Your company uses Microsoft Defender for Cloud to secure Azure workloads. You need to ensure that all storage accounts have the 'Secure transfer required' setting enabled. What should you use?

A.Azure role-based access control (RBAC)
B.Azure Blueprints
C.Microsoft Defender for Cloud regulatory compliance dashboard
D.Azure Policy
AnswerD

Azure Policy evaluates storage accounts against a built-in or custom definition and enforces the 'Secure transfer required' setting, remediating non-compliant resources at scale. This satisfies the stem's requirement to ensure the setting is enabled across all storage accounts.

Why this answer

Azure Policy can audit and enforce the 'Secure transfer required' setting across all storage accounts. Option A (RBAC) is incorrect because RBAC controls access permissions, not resource configuration. Option B (Azure Blueprints) is deprecated and not the direct solution for this requirement.

Option C (Microsoft Defender for Cloud regulatory compliance dashboard) provides visibility but does not enforce settings.

69
MCQmedium

Your company uses Microsoft Sentinel for security operations. You need to design a solution that automatically remediates a detected threat by blocking a malicious IP address on Azure Firewall. Which Microsoft Sentinel feature should you use?

A.Analytics rules
B.Workbooks
C.SOAR playbooks
D.User and Entity Behavior Analytics (UEBA)
AnswerC

SOAR playbooks in Microsoft Sentinel are Azure Logic Apps–based workflows that automate response and remediation actions when triggered by an incident, alert, or automation rule. They can run actions like isolating a compromised VM, blocking an IP, or sending notifications, and they integrate with external tools like Microsoft Defender or third-party SOC platforms. Playbooks are the correct option because they provide active remediation, not just detection or visualization.

Why this answer

Security Orchestration, Automation, and Response (SOAR) in Microsoft Sentinel uses playbooks to automate remediation actions like blocking IPs on Azure Firewall. Option A is wrong because analytics rules only generate alerts. Option B is wrong because workbooks visualize data.

Option D is wrong because UEBA analyzes behavior but does not automate remediation.

70
MCQhard

Refer to the exhibit. This is a risk alert from Microsoft Entra ID Identity Protection for user jdoe@contoso.com. You are designing an automated response using Microsoft Sentinel. Which condition should you use to trigger a high-severity incident?

A.If the user risk level is 'high'
B.If the sign-in risk level is 'high'
C.If the risk event types include 'leakedCredentials'
D.If the user risk level is 'medium'
AnswerA

In Microsoft Entra ID Protection, the user risk level is an aggregated probability that an account has been compromised, calculated from multiple risk detections over time. When the user risk level is rated 'high', the service raises a user risk alert, which is exactly what this exhibit displays. The alert metadata shows the user risk as 'high', so the condition that triggered this alert is the high user risk classification, not any other factor like sign-in risk or a specific leaked credential event.

Why this answer

The correct condition is A: trigger the high-severity incident when the user risk level is 'high'. In Microsoft Entra ID Identity Protection, user risk represents the probability that a given identity has been compromised, and a 'high' user risk is the strongest aggregate signal for an account-level compromise, making it the appropriate trigger for a high-severity Microsoft Sentinel incident. Option B is not the best fit because sign-in risk is scoped to a single authentication attempt rather than the overall user account.

Option C is too narrow, since 'leakedCredentials' is only one risk detection type and does not by itself indicate the highest severity. Option D is incorrect because 'medium' user risk is a lower severity than 'high' and would not justify a high-severity incident.

71
MCQeasy

Your organization is using Microsoft Sentinel for security information and event management (SIEM). You need to ensure that data from Azure Activity Logs is ingested into Sentinel. What should you configure?

A.Configure a Log Analytics workspace to collect Activity Logs
B.Use Azure Policy to stream Activity Logs to Sentinel
C.Enable Azure Monitor to forward Activity Logs to Sentinel
D.Connect Azure Activity Logs via the Microsoft Sentinel data connector
AnswerD

The Microsoft Sentinel data connector for Azure Activity is the authoritative, supported integration for ingesting control-plane events into the Sentinel workspace. This connector provisions the necessary data collector and maps the stream to the `AzureActivity` table, enabling analytics, hunting, and alerting. It appears in the Data connectors blade and is the standard first step when onboarding tenant-level logs.

Why this answer

You can connect Azure Activity Logs as a data connector in Microsoft Sentinel. Option A is wrong because Log Analytics workspace is the underlying storage, but the connection is made via data connectors. Option B is wrong because Azure Policy can enforce configuration but not directly ingest logs.

Option C is wrong because Azure Monitor is a broader service; the specific connector is needed.

72
MCQhard

A healthcare provider is building a new patient portal on Azure App Service. The portal calls a backend API hosted on Azure Functions. The security team requires that the API accept requests only from the portal, that the portal prove its identity to the API without storing secrets in code or configuration, and that the credentials rotate automatically. You need to recommend an authentication approach for the portal-to-API call. What should you recommend?

A.Store a client secret in Azure Key Vault and have the portal retrieve it at runtime to call the API.
B.Issue each portal instance a client certificate and configure mutual TLS between App Service and Azure Functions.
C.Enable a system-assigned managed identity on the App Service and use it to request an access token for the Azure Functions app.
D.Configure IP restrictions on the Azure Functions app to allow only the App Service outbound IP addresses.
AnswerC

A system-assigned managed identity lets App Service obtain Microsoft Entra ID tokens without any secret in code or configuration, and the underlying credential is rotated by the platform. Azure Functions can validate the token and restrict callers to the portal's identity, satisfying both the no-secret and auto-rotation requirements.

Why this answer

The cleanest way for one Azure compute resource to authenticate to another without secrets is a managed identity. The App Service obtains a Microsoft Entra ID token for the Functions app's audience, and the Functions app validates the token and authorizes the specific identity. The credential lifecycle is handled by the platform, which satisfies the automatic rotation requirement and eliminates secret sprawl.

Exam trap

The trap here is treating Key Vault as a complete answer to 'no secrets,' when the portal still has to possess and rotate a credential to reach the vault and the API.

73
MCQhard

Refer to the exhibit. You are auditing an Azure subscription. The Azure Policy assignment above is targeting a resource group. The policy definition ID corresponds to a built-in policy that audits if SQL databases have transparent data encryption (TDE) enabled. What is the effect of this policy assignment?

A.The policy automatically enables TDE on non-compliant SQL databases.
B.The policy is only reported as audit, not enforced.
C.The policy applies to all resources in the management group.
D.The policy audits SQL databases for TDE and marks non-compliant resources.
AnswerD

This is correct. The Azure Policy assignment uses the 'audit' effect to evaluate whether SQL databases have Transparent Data Encryption (TDE) enabled. If a database does not have TDE enabled, the policy marks that resource as non-compliant in the Azure Policy compliance dashboard and potentially integrates with Azure Monitor for alerts and reports. The 'audit' effect only evaluates and reports—it does not automatically remediate the non-compliant database, but it does accomplish the goal of identifying and flagging resources that fail to meet the intent of the policy. This matches the behavior shown in the exhibit where the policy is configured with an audit effect and assigned to a resource group.

Why this answer

Option D is correct because the built-in policy definition audits whether SQL databases have transparent data encryption (TDE) enabled, and an audit-effect policy evaluates resources and flags non-compliant ones in the compliance report without blocking or modifying them. Since the assignment targets a resource group, it evaluates the SQL databases within that scope and marks those lacking TDE as non-compliant. Option A is wrong because audit policies do not remediate or enable TDE; that would require a DeployIfNotExists or Modify effect.

Option B is incorrect because 'audit' is the effect, not merely a reporting mode, and the policy still evaluates and flags resources. Option C is wrong because the assignment targets a resource group, not a management group, so its scope is limited to that resource group.

74
MCQmedium

Your organization is using Microsoft Defender for Cloud to secure applications running on Azure. You need to ensure that all Azure Storage accounts have secure transfer required enabled. What is the BEST way to enforce this?

A.Create a custom recommendation in Microsoft Defender for Cloud to alert when storage accounts do not have secure transfer required.
B.Use Azure Blueprints to apply the setting to all subscriptions.
C.Assign an Azure Policy initiative that includes the built-in policy 'Secure transfer to storage accounts should be enabled' with a 'Deny' effect.
D.Grant the 'Storage Account Contributor' role to a security group that will manually enable the setting.
AnswerC

Assigning an Azure Policy initiative that contains the built-in policy 'Secure transfer to storage accounts should be enabled' with a Deny effect is the correct preventive control. Azure Policy evaluates resource creation and update requests during the ARM API call, and the Deny effect rejects any storage account that does not have the 'Secure transfer required' property set to true, returning an error before the resource is provisioned. This ensures non-compliant storage accounts are never created, and assigning it at a management group or subscription scale provides consistent enforcement across the entire environment. An initiative bundles together multiple policies, enabling comprehensive compliance with frameworks like the Azure Security Benchmark while the Deny effect specifically blocks insecure configurations.

Why this answer

The best way to enforce that all Azure Storage accounts have secure transfer required enabled is to assign an Azure Policy initiative that includes the built-in policy 'Secure transfer to storage accounts should be enabled' with a 'Deny' effect (option C). Azure Policy is the native governance service that evaluates resource properties and can block non-compliant deployments, so a Deny effect prevents creation or modification of storage accounts that do not have secure transfer required enabled. A custom recommendation in Defender for Cloud (option A) only provides visibility and alerts; it does not enforce the setting.

Azure Blueprints (option B) can orchestrate policy assignments but is not itself the enforcement mechanism, and it is being deprecated in favor of template specs and deployment stacks. Granting the Storage Account Contributor role (option D) relies on manual action and does not guarantee enforcement.

75
MCQhard

Your company uses Microsoft Entra ID for identity management. You need to implement a solution that allows external partners to access a specific application using their own identity providers, while ensuring that their accounts are automatically deprovisioned when removed from their home organization. Which feature should you use?

A.B2B direct federation
B.Entitlement management with connected organizations
C.Self-service sign-up
D.Identity Governance access reviews
AnswerB

Entitlement management with connected organizations lets external partners authenticate via their own identity providers while Microsoft Entra ID governs access through access packages. Lifecycle workflows automatically deprovision those accounts when partners leave their home organization, meeting the automatic removal requirement.

Why this answer

Entitlement management with connected organizations in Microsoft Entra ID (part of Identity Governance) is designed exactly for this scenario: it lets you onboard external partners, define access packages tied to their home identity providers, and automatically deprovision access when the user leaves their home organization via lifecycle workflows and connected-organization sync. This provides both the cross-tenant access and the automatic deprovisioning requirement.

Exam trap

SC-100 often tests the confusion between B2B direct federation (authentication trust only) and entitlement management with connected organizations (full governance plus automatic deprovisioning), causing candidates to pick the simpler federation option.

How to eliminate wrong answers

Option A is wrong because B2B direct federation only establishes a trust relationship for authentication between Entra ID and an external IdP (like SAML/WS-Fed); it does not provide access packages, approval workflows, or automatic deprovisioning when the user leaves their home org. Option C is wrong because self-service sign-up allows external users to request access via a custom app, but it lacks governance, lifecycle management, and automatic deprovisioning tied to the home organization. Option D is wrong because access reviews are a periodic recertification control that flags stale access for reviewers to approve or deny — they do not automatically deprovision users when they are removed from their home organization, nor do they onboard external IdPs.

Page 1 of 2 · 121 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Design security solutions for applications and data questions.