Courseiva

CCNA Design solutions that align with security best practices and priorities Questions

75 of 142 questions · Page 1/2 · Design solutions that align with security best practices and priorities · Answers revealed

1
MCQmedium

Your company uses Microsoft Intune to manage corporate devices. The security team wants to prevent users from copying sensitive data from corporate apps to personal apps on mobile devices. Which Intune policy should you configure?

A.Device configuration policies
B.App protection policies
C.Windows Information Protection
D.Device compliance policies
AnswerB

App protection policies (APPs) are the correct choice because they are specifically designed to prevent corporate data leakage in mobile apps. These MAM (mobile application management) policies apply directly to applications like Outlook or Teams and can restrict data transfer actions such as copy/paste, screen capture, or saving corporate data to unmanaged apps/cloud services. They work independently of device enrollment, so they remain effective even if the device is a personal phone, directly addressing the concern of safeguarding data in unmanaged apps.

Why this answer

App protection policies (APP) are the correct Intune policy to prevent data transfer from corporate apps to personal apps on mobile devices. These policies apply at the application layer, allowing you to configure data protection settings such as 'Restrict cut, copy, and paste' and 'Allow app to transfer data to other apps' specifically for managed apps, regardless of the device enrollment state.

Exam trap

The trap here is confusing device-level policies (compliance or configuration) with app-level data protection, leading candidates to select device compliance policies or device configuration policies instead of app protection policies.

How to eliminate wrong answers

Option A is wrong because device configuration policies manage device-level settings (e.g., Wi-Fi, VPN, certificates) and do not control data sharing between apps on mobile devices. Option C is wrong because Windows Information Protection (WIP) is a Windows-only feature for desktop devices and does not apply to mobile platforms like iOS or Android. Option D is wrong because device compliance policies enforce device-level security requirements (e.g., jailbreak detection, minimum OS version) and do not restrict app-to-app data transfer.

2
MCQeasy

Your organization uses Microsoft Intune for mobile device management. You need to ensure that only devices compliant with security policies can access corporate email. What should you implement?

A.Conditional Access policy requiring compliant device
B.Microsoft Purview Data Lifecycle Management
C.Microsoft Defender for Endpoint integration
D.Microsoft Intune App Protection Policies
AnswerA

A Conditional Access policy requiring a compliant device acts as a real-time access gate at authentication, checking the device's compliance state reported by Intune against defined compliance policies. It evaluates signals such as enrollment status, device health attestation, and configured security settings, and blocks or allows access to Microsoft 365 or other cloud apps. This is the appropriate control because it enforces device-level access decisions before any session begins.

Why this answer

A is correct because a Conditional Access policy in Microsoft Entra ID can evaluate device compliance status reported by Intune before granting access to corporate email. By configuring a policy that requires a device to be marked as compliant, only devices that meet your security policies (e.g., encryption, OS version, threat level) will be allowed to authenticate and access email. This directly enforces the requirement that only compliant devices can access corporate email.

Exam trap

The trap here is that candidates often confuse Intune App Protection Policies (MAM) with device-based compliance, but MAM policies protect data at the app level and do not require the device itself to be compliant, so they do not meet the requirement of 'only compliant devices'.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Data Lifecycle Management governs data retention and deletion policies, not real-time access control based on device compliance. Option C is wrong because Microsoft Defender for Endpoint integration provides threat detection and response on endpoints, but does not itself block access to email based on compliance status; it can feed signals into Conditional Access but is not the primary control. Option D is wrong because Intune App Protection Policies (MAM) protect data within apps without requiring device enrollment or compliance, so they do not ensure that only compliant devices can access email—they apply to apps on any device, including non-compliant ones.

3
Multi-Selectmedium

A company is designing a data security strategy using Microsoft Purview. They need to identify sensitive data across their data estate, including on-premises SQL Server, Azure SQL Database, and Amazon S3. Which THREE components should they use? (Choose three.)

Select 3 answers
A.Microsoft Purview Data Estate Insights
B.Microsoft Purview External Identities
C.Microsoft Purview Data Catalog
D.Microsoft Purview Compliance Manager
E.Microsoft Purview Data Map
AnswersA, C, E

Data Estate Insights provides monitoring and reporting.

Why this answer

Microsoft Purview Data Estate Insights provides visibility into data estate health and security posture, including sensitive data discovery across on-premises SQL Server, Azure SQL Database, and Amazon S3. It aggregates scan results and offers dashboards to identify where sensitive data resides, enabling targeted classification and protection actions.

Exam trap

The trap here is that candidates confuse Compliance Manager (a compliance posture tool) with data discovery capabilities, or think External Identities (an identity feature) is relevant to scanning data sources, when in fact only Data Map, Data Catalog, and Data Estate Insights form the core trio for sensitive data identification across hybrid estates.

4
MCQhard

A security team is designing a Microsoft Sentinel deployment. They need to minimize costs while ensuring critical alerts are always processed. Which data retention and ingestion strategy should they use?

A.Use Basic Logs for all data and retain for 90 days
B.Use Analytics Logs for all data and retain for 30 days
C.Use Basic Logs for critical alerts and retain for 30 days
D.Use Basic Logs for high-volume low-value data and Analytics Logs for critical alerts
AnswerD

This is the correct cost-performance trade-off: route high-volume, low-value data such as verbose firewall logs, debug traces, and raw DNS events to Basic Logs to slash ingestion costs, while steering critical security alerts and curated detection data into Analytics Logs for full KQL querying, alerting, and hunting workflows. Basic Logs' lower cost and acceptable simple-search capability align perfectly with data that is retained mainly for compliance or ad-hoc troubleshooting, while Analytics Logs' rich analytical features and long retention match the needs of high-priority security detections. Microsoft Sentinel supports this pattern natively by configuring table-level plans, enabling a single workspace to hold both tiers and ensuring that analysts can query the data that matters most with low latency. This balanced design meets both cost optimization and security operational requirements, making it the only viable answer.

Why this answer

It aligns with cost optimization and reliability requirements by using Basic Logs for high-volume, low-value data (e.g., firewall logs) and reserving Analytics Logs for critical alerts that require full query capabilities and interactive retention. This tiered approach ensures critical alerts are always processed with full fidelity while reducing storage costs for less important data.

Exam trap

The trap here is that candidates assume all data must be in Analytics Logs for security monitoring, overlooking the cost-saving strategy of tiered ingestion where Basic Logs handle high-volume, low-value data without sacrificing critical alert processing.

How to eliminate wrong answers

Option A is wrong because using Basic Logs for all data prevents critical alerts from being processed with full Analytics Logs features (e.g., advanced KQL queries, scheduled analytics rules), and 90-day retention on Basic Logs incurs unnecessary cost for low-value data. Option B is wrong because using Analytics Logs for all data maximizes cost (Analytics Logs are more expensive per GB) and 30-day retention may not meet compliance or investigation needs for critical alerts. Option C is wrong because using Basic Logs for critical alerts means they lose access to Analytics Logs capabilities (e.g., near-real-time detection, custom detections), and 30-day retention is insufficient for forensic analysis of critical incidents.

5
MCQhard

Your organization uses Microsoft Sentinel and has deployed the Analytics rule 'TI map IP entity to AzureActivity' to detect suspicious activities based on threat intelligence. The SOC team reports that the rule has a high false positive rate because it matches benign IP addresses used by legitimate services. What design change should you recommend to reduce false positives while maintaining detection coverage?

A.Increase the alert threshold to require multiple occurrences within a time window.
B.Disable the rule and rely on manual hunting queries.
C.Create a watchlist of trusted IP addresses and modify the rule to exclude those IPs.
D.Create a separate analytics rule that suppresses alerts when the source IP is in a trusted list.
AnswerC

Creating a watchlist of trusted IP addresses and modifying the rule to exclude those IPs directly addresses the source of the false positives without disabling detection. In Sentinel, you can build a watchlist (e.g., via CSV or PowerShell) and then reference it in the analytics rule's KQL query using the `_GetWatchlist` function—for instance, adding a `where IPAddress !in (_GetWatchlist('TrustedIPs'))` clause. This keeps the rule active for all other IPs, ensuring genuine threat-intelligence matches still generate alerts while known benign entities are filtered out, and it allows easy updates to the trusted list without re-editing the rule each time.

Why this answer

Creating a watchlist of trusted IP addresses and modifying the TI map IP entity to AzureActivity rule to exclude those IPs directly addresses the high false positive rate caused by benign IPs. This approach preserves detection coverage for all other threat intelligence matches while filtering out known legitimate services, leveraging Sentinel's watchlist feature for dynamic exclusion without disabling the rule.

Exam trap

The trap here is that candidates may choose Option D, thinking a separate suppression rule is needed, but Microsoft Sentinel's analytics rules support direct exclusion via watchlists in the query logic, making a separate rule redundant and less reliable.

How to eliminate wrong answers

Option A is wrong because increasing the alert threshold to require multiple occurrences within a time window does not address the root cause—benign IPs matching threat intelligence—and may delay detection of genuine threats or miss single-occurrence attacks. Option B is wrong because disabling the rule and relying on manual hunting queries eliminates automated detection entirely, increasing risk and workload, which contradicts the goal of maintaining detection coverage. Option D is wrong because creating a separate analytics rule that suppresses alerts when the source IP is in a trusted list introduces unnecessary complexity and potential race conditions; suppression logic should be integrated into the original rule via exclusion, not handled as a separate rule that may not suppress alerts in time or could conflict with other rules.

6
MCQeasy

Your organization uses Microsoft Sentinel as its SIEM. The security team needs to detect brute-force attacks against Azure VMs by analyzing Windows Security Event logs. Which data connector should you enable?

A.Office 365 connector
B.Azure Activity log connector
C.Microsoft Defender for Cloud connector
D.Windows Security Events via AMA connector
AnswerD

The Windows Security Events via Azure Monitor Agent (AMA) connector is purpose-built to stream Windows Event logs from servers and workstations directly into Microsoft Sentinel. Using a Data Collection Rule (DCR), it can collect the Security channel and other event channels, preserving the raw event details for detections and investigations. This is the correct connector when your organization must ingest Windows security events into Sentinel.

Why this answer

The Windows Security Events via AMA connector (D) is correct because it ingests Windows Event Logs (specifically Security logs with Event ID 4625 for failed logons) from Azure VMs into Microsoft Sentinel, enabling detection of brute-force patterns. This connector uses the Azure Monitor Agent (AMA) to collect events, which is the recommended method for modern Windows event collection in Sentinel.

Exam trap

The trap here is that candidates may confuse the Azure Activity log connector (which shows administrative actions like 'Deallocate VM') with guest OS-level security events, or mistakenly think Defender for Cloud provides raw Windows event logs instead of aggregated security alerts.

How to eliminate wrong answers

Option A is wrong because the Office 365 connector ingests audit logs from Microsoft 365 services (Exchange, SharePoint, Teams), not Windows Security Event logs from Azure VMs. Option B is wrong because the Azure Activity log connector collects subscription-level control plane events (e.g., VM creation, resource changes), not guest OS-level security events like logon failures. Option C is wrong because the Microsoft Defender for Cloud connector ingests security alerts and posture data from Defender for Cloud, not raw Windows Security Event logs needed for brute-force detection.

7
MCQmedium

Your company uses Microsoft Defender for Endpoint (MDE) and wants to integrate threat intelligence from an external source to improve detection. The security team needs to ingest custom indicators of compromise (IOCs) into MDE. Which feature should they use?

A.Advanced Hunting
B.Threat Analytics
C.Automated investigation and response
D.Custom indicators (IOCs)
AnswerD

Custom Indicators (IOCs) is the Microsoft Defender for Endpoint feature that allows tenants to import their own threat intelligence, including file hashes, IP addresses, URLs, domains, and certificates, from external sources. This ingestion can be performed through the Microsoft 365 Defender portal or programmatically via APIs, and the imported indicators are then evaluated during detection and enforcement. Enabling a connector to import IOCs from an external source specifically leverages this feature, as it is the sole mechanism among these options that accepts and manages external indicator data.

Why this answer

The Custom Indicators (IOCs) feature in Microsoft Defender for Endpoint allows security teams to manually ingest and manage threat intelligence from external sources, such as IP addresses, URLs, domains, or file hashes. These indicators are then used by MDE to create or block alerts, enabling tailored detection beyond built-in threat intelligence feeds.

Exam trap

The trap here is that candidates often confuse 'Advanced Hunting' (a query tool) with a feature for importing threat data, or they mistakenly think 'Threat Analytics' allows custom feed integration, when in fact it only displays Microsoft's pre-built analysis.

How to eliminate wrong answers

Option A is wrong because Advanced Hunting is a query-based tool for exploring raw telemetry data over the past 30 days, not a mechanism for ingesting external IOCs. Option B is wrong because Threat Analytics provides curated reports and insights on known threats from Microsoft's research, not a way to import custom indicators. Option C is wrong because Automated investigation and response is a workflow that triggers actions on alerts, but it cannot ingest or manage external IOCs; it relies on existing detection rules.

8
MCQeasy

Your organization is adopting Microsoft Purview to classify and protect sensitive data in Microsoft 365. You need to ensure that documents containing credit card numbers are automatically detected and encrypted when shared externally. What should you configure?

A.An Information Barrier policy between departments
B.A sensitivity label configured with auto-labeling for credit card numbers and encryption for external sharing
C.A retention label that deletes documents with credit card numbers after 90 days
D.A Data Loss Prevention (DLP) policy that blocks sharing of credit card numbers
AnswerB

A sensitivity label with auto-labeling uses Microsoft Purview's sensitive info types, such as credit card numbers, to automatically classify documents when those patterns are detected. The label can be configured with permissions-based encryption (via Azure Rights Management), which protects the content even when shared externally by enforcing view/edit restrictions. This directly satisfies both the classification and external-sharing protection requirements in the scenario.

Why this answer

Sensitivity labels in Microsoft Purview can be configured with auto-labeling conditions that detect sensitive data types (e.g., credit card numbers) and automatically apply encryption to documents when shared externally. This meets the requirement of automatic detection and encryption for external sharing without manual user intervention.

Exam trap

The trap here is confusing DLP policies (which block or warn) with sensitivity labels (which can auto-apply encryption), leading candidates to choose DLP when the requirement explicitly states 'encrypt when shared externally' rather than block.

How to eliminate wrong answers

Option A is wrong because Information Barrier policies are designed to prevent communication and collaboration between specific groups or departments, not to detect or encrypt sensitive data like credit card numbers. Option C is wrong because retention labels manage data lifecycle (retention or deletion) based on time, not real-time detection or encryption of sensitive content when shared externally. Option D is wrong because a DLP policy can block sharing of credit card numbers but does not encrypt the documents; it only prevents the action, whereas the requirement is to encrypt when shared externally.

9
MCQhard

Your organization is implementing a privileged access strategy using Microsoft Entra Privileged Identity Management (PIM). The compliance team requires that all privileged role activations be approved by a manager and that an audit trail is maintained for at least one year. Which configuration should you recommend?

A.Configure access reviews for privileged roles
B.Set PIM role settings to require approval and enable audit logging
C.Enable Conditional Access policies for privileged roles
D.Require Azure MFA for role activation
AnswerB

PIM supports approval workflow and logs are retained for auditing.

Why this answer

It directly addresses both compliance requirements: requiring approval ensures a manager authorizes each activation, and enabling audit logging in PIM retains activation history for at least one year. PIM role settings allow you to configure approval workflows and automatically log all activations to the Microsoft Entra audit log, which can be exported and retained for compliance purposes.

Exam trap

The trap here is that candidates confuse access reviews (periodic recertification) with the real-time approval workflow required for each activation, or they assume MFA alone satisfies the audit and approval requirements.

How to eliminate wrong answers

Option A is wrong because access reviews are used for periodic recertification of role assignments, not for real-time approval of activations or audit trail retention. Option C is wrong because Conditional Access policies control access based on conditions like location or device state, but they do not provide the required manager approval workflow or dedicated audit logging for role activations. Option D is wrong because Azure MFA for role activation enhances security but does not satisfy the compliance requirement for manager approval or the one-year audit trail retention.

10
MCQmedium

A company uses Microsoft Purview to manage data governance. They need to classify sensitive data automatically in Azure SQL Database. What should they configure?

A.Microsoft Defender for Cloud regulatory compliance
B.Microsoft Purview Data Map scanning rules
C.Microsoft Sentinel data connectors
D.Microsoft Entra ID Protection
AnswerB

Microsoft Purview Data Map scanning rules automatically connect to various data sources, both on-premises and multi-cloud, and run scans to profile and classify assets. These rules apply built-in or custom classification patterns—like regex for PII, financial, or health information—and assign sensitivity labels to structured and unstructured data. This is exactly the mechanism that enables data governance by building a searchable, classified inventory of enterprise data, making it the correct choice for a company using Purview.

Why this answer

Microsoft Purview Data Map scanning rules are the correct choice because they enable automated classification of sensitive data in Azure SQL Database by scanning the database schema and content against built-in or custom sensitive data types. This is the native mechanism within Purview to discover and label sensitive columns, such as credit card numbers or PII, directly in Azure SQL Database.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud's regulatory compliance dashboard with actual data classification, but Defender for Cloud only checks configuration settings against compliance frameworks, not the content of the data itself.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud regulatory compliance assesses the security posture of Azure resources against compliance standards (e.g., SOC 2, PCI DSS) but does not perform data classification or scanning of sensitive data within Azure SQL Database. Option C is wrong because Microsoft Sentinel data connectors ingest security logs and alerts from various sources for threat detection and SIEM purposes, not for scanning or classifying sensitive data in databases. Option D is wrong because Microsoft Entra ID Protection focuses on identity-based risks such as compromised credentials and sign-in anomalies, not on data classification within Azure SQL Database.

11
Multi-Selectmedium

Your organization is designing a secure access solution for a partner company that needs to access specific SharePoint Online sites. You need to implement Microsoft Entra ID B2B collaboration. Which THREE configurations are essential for a secure B2B collaboration setup?

Select 3 answers
A.Configure cross-tenant access settings in Microsoft Entra ID
B.Enable multi-factor authentication (MFA) for guest users
C.Use B2B direct connect for SharePoint site access
D.Allow all external domains to invite users without restrictions
E.Set Conditional Access policies that apply to guest users
AnswersA, B, E

Cross-tenant access settings in Microsoft Entra ID are the foundational control for managing B2B collaboration with partner organizations. They let you define granular inbound and outbound policies that govern trust claims (e.g., MFA, device compliance, hybrid Azure AD join) and apply Conditional Access scoping per tenant, user, group, or application. This replaces the older, less secure per-tenant manual configurations and provides a cohesive access-control plane for external identities.

Why this answer

Option A is correct because cross-tenant access settings in Microsoft Entra ID let you control inbound and outbound B2B collaboration with the partner tenant, including trust settings for MFA and device claims, which is essential for governing partner access to specific SharePoint Online sites. Option B is correct because enabling MFA for guest users strengthens authentication and reduces the risk of compromised credentials being used to access shared SharePoint resources. Option E is correct because Conditional Access policies scoped to guest users enforce sign-in controls such as MFA, compliant devices, and location restrictions, which are critical for securing B2B access.

Option C is not essential here because B2B direct connect is designed for Teams shared channels and does not apply to SharePoint site access in this scenario. Option D is incorrect because allowing all external domains without restrictions removes governance and exposes the tenant to unauthorized invitations and access.

Exam trap

The trap here is confusing B2B direct connect (for Teams shared channels) with B2B collaboration (for SharePoint and other apps), leading candidates to select Option C incorrectly.

12
MCQhard

A company uses Azure DevOps and wants to implement a DevSecOps practice by scanning code for secrets and vulnerabilities before deployment. Which tool should they integrate into their pipeline?

A.Azure Policy
B.Microsoft Purview
C.GitHub Advanced Security
D.Microsoft Defender for DevOps
AnswerD

Microsoft Defender for DevOps is a dedicated service that integrates directly with Azure DevOps (and GitHub) to provide continuous security scanning of code, secrets, infrastructure-as-code templates, and open-source dependencies. It leverages built-in scanners like Credential Scanner and integrates with Defender for Cloud to aggregate findings across the software development life cycle. This makes it the correct choice for an Azure DevOps-centric organization seeking DevOpsSec capabilities.

Why this answer

Microsoft Defender for DevOps is the correct choice because it is a unified DevSecOps solution that integrates directly into Azure DevOps pipelines to scan code for secrets, vulnerabilities, and open-source dependencies before deployment. It provides actionable security insights and remediation guidance, aligning with the requirement to implement a DevSecOps practice by scanning code for secrets and vulnerabilities.

Exam trap

The trap here is that candidates may confuse GitHub Advanced Security (which is for GitHub repositories) with Microsoft Defender for DevOps (which is for Azure DevOps pipelines), leading them to choose Option C even though the question explicitly states the company uses Azure DevOps.

How to eliminate wrong answers

Option A is wrong because Azure Policy is a governance tool that enforces compliance rules on Azure resources (e.g., tagging, location restrictions) and does not scan code for secrets or vulnerabilities. Option B is wrong because Microsoft Purview is a data governance and classification service for data estates (e.g., sensitive data discovery in storage) and lacks the capability to scan source code in a CI/CD pipeline. Option C is wrong because GitHub Advanced Security is a suite of security features for GitHub repositories (e.g., secret scanning, code scanning) but is not natively integrated into Azure DevOps pipelines; it requires a GitHub repository, whereas the question specifies Azure DevOps.

13
Multi-Selecthard

Refer to the exhibit. You are reviewing an ARM template for a storage account. The security team has mandated that all storage accounts must enforce HTTPS traffic and use TLS 1.2 or higher. Which two changes must be made to the template to comply? (Choose two.)

Select 2 answers
A.Change 'minimumTlsVersion' to 'TLS1_2'
B.Set 'kind' to 'BlobStorage'
C.Add 'networkAcls' with defaultAction Deny
D.Change 'sku.name' to 'Standard_LRS'
E.Set 'supportsHttpsTrafficOnly' to true
AnswersA, E

TLS 1.0 is deprecated and no longer considered secure; Azure Storage requires customers to enforce at least TLS 1.2 for all data plane access. By setting the 'minimumTlsVersion' property to 'TLS1_2', the account will reject any client connections attempting to use TLS 1.0 or 1.1. This is a distinct control from HTTPS enforcement, but it is the configuration that directly addresses the requirement to prevent outdated protocol usage.

Why this answer

Option A is correct because the storage account property 'minimumTlsVersion' must be set to 'TLS1_2' (or higher, such as 'TLS1_3' where supported) to enforce TLS 1.2 or above, satisfying the security team's TLS requirement. Option E is correct because the 'supportsHttpsTrafficOnly' property must be set to true so the storage account rejects non-HTTPS (HTTP) requests, enforcing HTTPS traffic. Option B is incorrect because 'kind' (BlobStorage vs StorageV2) controls the type of storage account and its supported features, not HTTPS or TLS enforcement.

Option C is incorrect because 'networkAcls' with defaultAction Deny restricts network access by IP or virtual network, which is unrelated to enforcing HTTPS or TLS versions. Option D is incorrect because 'sku.name' (Standard_LRS) only defines the redundancy/replication tier and performance level, not transport security settings.

Exam trap

Microsoft often tests the misconception that network access controls (like network ACLs) or storage account type changes can enforce encryption or TLS version requirements, when in fact only the explicit 'minimumTlsVersion' and 'supportsHttpsTrafficOnly' properties control these security settings.

14
MCQeasy

You are designing a security solution for Azure resources. You need to ensure that any changes to network security groups (NSGs) are automatically logged and sent to a central Log Analytics workspace. Which Azure feature should you use?

A.Diagnostic settings on the Azure Activity Log
B.Azure Policy
C.NSG flow logs
D.Azure Monitor alerts
AnswerA

Diagnostic settings on the Azure Activity Log are the correct mechanism because the Activity Log itself records every control-plane operation—such as resource creation, deletion, and configuration changes—for your Azure resources. By configuring a diagnostic setting on this log, you can stream those management events directly into a Log Analytics workspace, enabling centralized querying, alerting, and long-term retention for security auditing. This is the built-in, supported way to capture and route resource-level change activity to your security monitoring pipeline.

Why this answer

Diagnostic settings on the Azure Activity Log capture all control-plane operations, including changes to NSGs (e.g., rule additions or deletions). By configuring a diagnostic setting to stream the Activity Log to a Log Analytics workspace, you ensure that every NSG modification is automatically logged and centralized for monitoring and alerting.

Exam trap

The trap here is confusing NSG flow logs (which log network traffic) with the Activity Log (which logs configuration changes), leading candidates to select NSG flow logs instead of diagnostic settings on the Activity Log.

How to eliminate wrong answers

Option B (Azure Policy) is wrong because Azure Policy enforces compliance rules (e.g., preventing NSG changes that allow all inbound traffic) but does not automatically log changes; it can trigger remediation but not send logs to Log Analytics. Option C (NSG flow logs) is wrong because NSG flow logs capture IP traffic data (source/destination, ports, protocols) through the NSG, not configuration changes to the NSG itself. Option D (Azure Monitor alerts) is wrong because alerts are reactive notifications based on log data or metrics; they do not capture or forward logs themselves.

15
MCQeasy

You are designing a security operations strategy for Microsoft 365. You need to prioritize alerts from Microsoft Defender XDR based on their impact on business operations. Which security best practice should you follow?

A.Prioritize alerts based on a risk assessment that considers asset criticality, threat severity, and business impact
B.Prioritize alerts based on a qualitative risk assessment only
C.Treat all alerts with equal severity to ensure none are missed
D.Prioritize alerts based solely on the MITRE ATT&CK technique involved
AnswerA

Risk-based prioritization that scores asset criticality, threat severity, and business impact is the industry-standard approach because it translates raw signals into actionable decisions aligned with organizational value. By quantifying each alert's potential damage against the importance of the affected system, security operations teams can focus containment and investigation resources on events most likely to cause significant harm. This method also supports continuous improvement by allowing thresholds to be tuned based on telemetry and incident outcomes.

Why this answer

Microsoft Defender XDR integrates with Microsoft 365 Defender's risk-based alert prioritization, which uses a combination of asset criticality (e.g., from Microsoft Purview or Defender for Cloud Apps), threat severity (e.g., from the Microsoft Defender portal's alert severity levels: Informational, Low, Medium, High), and business impact (e.g., via sensitivity labels or data classification). This aligns with the security best practice of risk-based alert triage, ensuring that high-impact alerts are addressed first to minimize business disruption.

Exam trap

The trap here is that candidates may choose Option D because MITRE ATT&CK is a common framework in security operations, but they overlook that Microsoft Defender XDR's prioritization engine uses a multi-faceted risk assessment (including asset criticality and business impact) rather than a single technique-based filter.

How to eliminate wrong answers

Option B is wrong because a qualitative risk assessment alone lacks the quantitative data (e.g., asset criticality scores, threat severity levels) that Microsoft Defender XDR uses to dynamically prioritize alerts, leading to subjective and inconsistent triage. Option C is wrong because treating all alerts with equal severity ignores the risk-based prioritization built into Microsoft Defender XDR, which uses machine learning and threat intelligence to assign different severity levels (e.g., High, Medium, Low) and would overwhelm security operations with noise. Option D is wrong because prioritizing solely on the MITRE ATT&CK technique ignores asset criticality and business impact; for example, a low-severity technique on a critical server may be more impactful than a high-severity technique on a non-critical endpoint, and Microsoft Defender XDR's alert enrichment includes asset context beyond just the technique.

16
MCQeasy

A company is adopting Microsoft Purview for data security. They need to prevent users from sharing sensitive data like credit card numbers via email. Which feature should you configure?

A.Audit log search
B.Data Loss Prevention (DLP) policy
C.Insider Risk Management policy
D.Sensitivity labels
AnswerB

Data Loss Prevention (DLP) policies in Microsoft Purview are the correct inline control to block sharing of sensitive information. They use built-in sensitive info types (e.g., credit card numbers, personally identifiable information) and trainable classifiers to evaluate content in real time, then enforce actions such as 'Block' with the option to allow overrides for Exchange, SharePoint, OneDrive, and endpoints. By applying conditions like 'sharing with people outside the organization,' DLP can prevent the sharing action before any data leaves the tenant, making it the only option here that directly provides ex-ante prevention rather than detection or classification.

Why this answer

Data Loss Prevention (DLP) policies in Microsoft Purview are specifically designed to detect and prevent the accidental or intentional sharing of sensitive information, such as credit card numbers, through email and other channels. By configuring a DLP policy with a rule that scans for credit card number patterns (using predefined or custom sensitive info types), the system can block, quarantine, or notify users when such data is sent via Exchange Online. This directly addresses the requirement to prevent sharing sensitive data via email.

Exam trap

The trap here is that candidates often confuse Sensitivity labels as a direct replacement for DLP, but labels are for classification and protection (e.g., encryption), not for real-time content inspection and blocking of specific data patterns like credit card numbers in email.

How to eliminate wrong answers

Option A is wrong because Audit log search is a forensic tool for reviewing past activities, not a preventive control that blocks data sharing in real time. Option C is wrong because Insider Risk Management policies focus on identifying and investigating risky user behaviors (e.g., data exfiltration patterns) rather than enforcing content-based restrictions on outbound email. Option D is wrong because Sensitivity labels classify and protect data through encryption and visual markings, but they do not inherently block the transmission of specific sensitive data types like credit card numbers via email without being combined with a DLP policy.

17
MCQeasy

Tailwind Traders is a small business that uses Microsoft 365 Business Premium. They have no dedicated IT staff. The owner wants to implement basic security measures to protect against common threats like phishing, ransomware, and unauthorized access. They need a simple, cost-effective solution that aligns with Microsoft's security best practices for small businesses. Which set of actions should you recommend?

A.Implement Privileged Identity Management (PIM) for all accounts. Use Azure Information Protection to classify all emails. Set up a SIEM using Microsoft Sentinel.
B.Deploy Microsoft Intune to manage devices. Configure Conditional Access policies to require compliant devices. Use Microsoft Defender for Endpoint for antivirus. Set up a VPN for remote access.
C.Purchase Azure AD Premium P2 for all users. Use Identity Protection to detect risks. Configure Conditional Access with session controls. Use Azure AD Identity Governance for access reviews.
D.Enable Security Defaults in Microsoft Entra ID to enforce MFA for all users. Configure Microsoft Defender for Office 365 to protect against phishing and malware. Use Microsoft Defender for Business (included) for endpoint protection. Regularly review the Microsoft 365 Secure Score and implement top recommendations.
AnswerD

Security Defaults in Microsoft Entra ID automatically enforce MFA for all users and block legacy authentication, providing a strong baseline without extra licensing or complex policy setup. Defender for Office 365 protects against phishing, malware, and malicious links in email, which is critical for small businesses that rely heavily on email communication. Defender for Business is included in Microsoft 365 Business plans and provides managed endpoint protection tailored to smaller organizations. Regularly reviewing the Secure Score helps prioritize low-effort, high-impact security improvements that align with the business's actual risk profile.

Why this answer

It aligns with Microsoft's security best practices for small businesses with no dedicated IT staff. Security Defaults in Microsoft Entra ID provide a baseline of MFA enforcement without requiring complex configuration. Microsoft Defender for Office 365 and Defender for Business (included in Microsoft 365 Business Premium) offer integrated phishing, malware, and endpoint protection.

Regularly reviewing the Secure Score ensures continuous improvement against common threats like ransomware and unauthorized access.

Exam trap

The trap here is that candidates often over-engineer the solution by selecting advanced identity or endpoint management options (like PIM, Intune, or Azure AD Premium P2) that are technically valid but inappropriate for a small business with no IT staff, ignoring the cost and complexity constraints explicitly stated in the scenario.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) requires Azure AD Premium P2 licensing, which is not included in Microsoft 365 Business Premium and adds unnecessary complexity for a small business with no IT staff; Azure Information Protection and Microsoft Sentinel are also overkill and not cost-effective. Option B is wrong because Microsoft Intune requires additional licensing beyond Business Premium and managing device compliance via Conditional Access policies demands dedicated IT expertise; a VPN is not a core security control for phishing or ransomware and adds complexity. Option C is wrong because Azure AD Premium P2 for all users is expensive and unnecessary for a small business; Identity Protection and Identity Governance are advanced features designed for larger enterprises with dedicated identity teams, not a simple, cost-effective baseline.

18
MCQeasy

Your organization needs to audit all changes to Azure resources, including who made the change and what was changed. Which Azure service should you use to collect and analyze this audit data?

A.Azure Policy
B.Azure Monitor with activity logs
C.Microsoft Defender for Cloud
D.Microsoft Sentinel
AnswerB

The Azure Activity Log records every control-plane write operation (create, update, delete) on Azure resources, including the caller identity, timestamp, operation name, and resource ID—precisely the data required for change auditing. Azure Monitor provides a unified platform to query and analyze these logs via Log Analytics, configure alerts on specific changes, and export them to storage or event hubs for retention. This combination yields a comprehensive, queryable audit trail of all resource modifications, making it the correct foundational service for auditing every change to Azure resources.

Why this answer

Azure Monitor with activity logs is the correct service because it captures all control-plane operations on Azure resources, including who performed the change (via Azure Active Directory authentication), what was changed (the resource and properties), and when it occurred. Activity logs are retained for 90 days by default and can be exported to Log Analytics workspaces for advanced querying and alerting, making them the native audit trail for Azure resource modifications.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel as the audit service because it is a SIEM, but Sentinel ingests logs from other sources (including activity logs) and is not the native collection mechanism; the question specifically asks for the service that collects and analyzes the audit data, which is Azure Monitor with activity logs.

How to eliminate wrong answers

Option A is wrong because Azure Policy is a governance tool that enforces compliance rules on resources (e.g., requiring specific tags or denying certain SKUs) and does not natively log who made changes or what was changed; it evaluates resource configurations against policies but does not provide an audit trail of modifications. Option C is wrong because Microsoft Defender for Cloud focuses on security posture management, threat detection, and vulnerability assessments, not on auditing all resource changes; it uses activity logs for some security alerts but is not designed as a primary audit log service. Option D is wrong because Microsoft Sentinel is a SIEM (Security Information and Event Management) solution that ingests logs from multiple sources, including activity logs, but it is not the service that collects the audit data itself; the underlying source for resource change auditing remains Azure Monitor activity logs.

19
MCQeasy

Your organization is adopting Microsoft Entra ID as the identity provider for all SaaS applications. The security team wants to enforce multifactor authentication (MFA) for all users accessing these applications. Which approach aligns with security best practices and minimizes user friction?

A.Enable per-user MFA for all users in Microsoft Entra ID.
B.Disable MFA and rely on strong password policies.
C.Enable Microsoft Entra ID Security defaults.
D.Create a Conditional Access policy requiring MFA for all cloud apps, excluding trusted locations and devices.
AnswerD

A Conditional Access policy gives granular control to require MFA for all cloud apps while excluding trusted locations and devices, enabling risk-based, context-aware enforcement. It can leverage named locations, device compliance, and sign-in risk, and integrate with session controls, session persistence, and break-glass accounts, directly satisfying both the MFA mandate and the need for exception handling.

Why this answer

Conditional Access policies allow granular, risk-based MFA enforcement that excludes trusted locations (e.g., corporate offices) and trusted devices (e.g., compliant or hybrid-joined devices). This aligns with the Zero Trust principle of 'verify explicitly' while minimizing user friction by not prompting for MFA when the user is already in a trusted context. Security defaults (Option C) enforce MFA for all users but lack the ability to exclude trusted locations or devices, which can cause unnecessary friction.

Exam trap

The trap here is that candidates often confuse Security defaults (Option C) as the best practice for MFA enforcement, but Security defaults lack the exclusion capabilities of Conditional Access, which is the recommended approach for minimizing friction while maintaining security.

How to eliminate wrong answers

Option A is wrong because per-user MFA is a legacy approach that forces MFA on every authentication attempt regardless of context, leading to high user friction and no ability to exclude trusted locations or devices; it also lacks the granular control of Conditional Access. Option B is wrong because disabling MFA and relying solely on strong password policies violates security best practices, as passwords alone are vulnerable to phishing, credential stuffing, and brute-force attacks, and does not meet the requirement to enforce MFA. Option C is wrong because while Security defaults enforce MFA for all users, they do not allow exclusion of trusted locations or devices, which means users are prompted for MFA even from the corporate network or on compliant devices, increasing friction unnecessarily.

20
Multi-Selecthard

Which THREE are security best practices for Microsoft Entra ID? (Select three.)

Select 3 answers
A.Block legacy authentication protocols
B.Enable multifactor authentication for all administrators
C.Disable self-service password reset for users
D.Synchronize all on-premises user accounts to Microsoft Entra ID
E.Use Privileged Identity Management to enforce just-in-time access
AnswersA, B, E

Legacy authentication protocols such as POP3, IMAP, and SMTP Auth do not support modern authentication or conditional access, forcing password-only sign-ins. Since these protocols bypass MFA enforcement, they are a primary gateway for password spray and credential-stuffing attacks. Microsoft recommends blocking them entirely via Conditional Access or tenant-wide settings, reserving exceptions only for unavoidable service accounts.

Why this answer

Option A is correct because blocking legacy authentication protocols (such as IMAP, POP3, SMTP AUTH, and older Office clients that cannot enforce MFA) closes a common bypass that attackers use to conduct password-spray and credential-stuffing attacks against Microsoft Entra ID. Option B is correct because enabling multifactor authentication for all administrators adds a strong second factor to privileged sign-ins, directly mitigating the risk of compromised admin credentials, and Microsoft recommends MFA for all users with privileged roles. Option E is correct because Privileged Identity Management enforces just-in-time role activation with approval, justification, and time-bound assignments, reducing standing privileged access that attackers could abuse.

Option C is not a best practice because self-service password reset improves security and reduces helpdesk burden when combined with MFA and strong authentication methods. Option D is not inherently a security best practice because synchronizing all on-premises accounts can propagate stale, unnecessary, or compromised identities into Entra ID; synchronization should be scoped to required accounts with proper governance.

Exam trap

The trap here is that candidates often assume disabling self-service password reset (SSPR) improves security by reducing attack surface, but in reality, SSPR reduces help desk load and encourages users to reset compromised passwords quickly, while blocking legacy authentication is the actual critical control to prevent MFA bypass.

21
MCQmedium

A company uses Microsoft Intune to manage devices. They want to ensure that only devices that have passed health attestation can access corporate email. Which method should they use?

A.Use Microsoft Defender for Endpoint to block devices that fail health attestation
B.Create a device compliance policy for health attestation and use Conditional Access to require compliant devices
C.Create an app protection policy to require device health attestation
D.Create a device configuration policy to enforce health attestation
AnswerB

Device compliance policies in Microsoft Intune include a 'Device Health Attestation' section that reports security boot, BitLocker, and code integrity state from supported Windows devices. After the policy is evaluated, Conditional Access can require 'Device to be marked as compliant' as a grant control, preventing sign-in from devices that fail attestation checks. This pairing is the correct sequence: Intune establishes the health baseline and Conditional Access enforces access, making it the only option here that actually gates authentication.

Why this answer

It combines a device compliance policy that evaluates health attestation (e.g., BitLocker status, Secure Boot, code integrity) with a Conditional Access policy that grants access to corporate email only when the device is marked as compliant. This is the standard Microsoft approach for enforcing health attestation before granting access to cloud resources like Exchange Online.

Exam trap

The trap here is confusing device compliance policies (which evaluate and report health state) with device configuration policies (which only apply settings), leading candidates to pick Option D, which cannot enforce access control.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Endpoint can detect and alert on device health issues but cannot directly block access to corporate email; blocking requires integration with Conditional Access or a network enforcement point. Option C is wrong because app protection policies (MAM) manage data protection at the app level without evaluating device health attestation; they rely on app-level conditions like jailbreak detection, not hardware-attested health. Option D is wrong because device configuration policies set settings (e.g., BitLocker enablement) but do not enforce real-time attestation checks or block access; compliance is determined by a separate compliance policy, not a configuration profile.

22
MCQhard

A company is designing a security strategy for their AI-powered applications using Microsoft Azure OpenAI Service. They need to ensure that the AI models are not used to generate harmful content and that the data sent to the models is protected. Which Microsoft Purview feature should they use?

A.Microsoft Purview Endpoint DLP
B.Microsoft Purview Information Protection
C.Microsoft Purview Data Loss Prevention (DLP) for AI
D.Microsoft Purview Audit
AnswerC

Microsoft Purview Data Loss Prevention (DLP) for AI extends DLP policies to AI services, allowing administrators to detect sensitive information—like financial, health, or personal data—within user prompts and AI-generated responses. It can enforce real-time actions such as blocking or warning users when sensitive data is exchanged, and it integrates with services like Microsoft Copilot. This makes it the only option that actively prevents harmful content from being processed or generated in AI interactions.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) for AI is the correct feature because it is specifically designed to monitor and control the data sent to and from AI applications, including Azure OpenAI Service, to prevent the generation of harmful content and protect sensitive data. It uses deep content analysis and policy-based controls to detect and block policy violations in real-time, directly addressing the dual requirements of content safety and data protection.

Exam trap

The trap here is that candidates often confuse general data protection features (like Information Protection or Endpoint DLP) with the specialized AI-focused DLP capability, assuming any DLP or protection feature can handle AI workloads, when only DLP for AI is purpose-built for Azure OpenAI Service interactions.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Endpoint DLP focuses on monitoring and controlling data on endpoints (e.g., Windows 10/11 devices) and does not natively integrate with Azure OpenAI Service to inspect AI model prompts or outputs. Option B is wrong because Microsoft Purview Information Protection is primarily for classifying, labeling, and protecting sensitive data at rest (e.g., files and emails) using encryption and rights management, not for real-time content filtering of AI interactions. Option D is wrong because Microsoft Purview Audit provides logging and investigation of user and admin activities (e.g., who accessed what) but does not enforce policies to prevent harmful content generation or protect data in transit to AI models.

23
MCQmedium

You are designing a security solution for an Azure Kubernetes Service (AKS) cluster. You need to ensure that only authorized images from a specific container registry can be deployed. Which Azure Policy definition should you use?

A.Kubernetes cluster should be accessible only over HTTPS
B.Kubernetes cluster containers should only use allowed images
C.Kubernetes cluster should use internal load balancers
D.Kubernetes cluster should not allow privileged containers
AnswerB

This is the correct restriction because Azure Policy's built-in initiative for AKS evaluates each container image against an approved registry list at admission control time. By preventing pods from using images outside the configured allowlist, it reduces the attack surface from tampered or untrusted images, directly addressing supply chain risks within the cluster. This policy is applied via the Azure Policy add-on for AKS, enforcing compliance at scale across all namespaces.

Why this answer

The Azure Policy built-in definition 'Kubernetes cluster containers should only use allowed images' enforces a constraint on the container images deployed in an AKS cluster. This policy uses an Open Policy Agent (OPA) constraint to validate that every container's image reference matches a specified list of allowed registries or image patterns, ensuring only authorized images from a specific container registry can be deployed.

Exam trap

The trap here is that candidates often confuse policies that restrict container behavior (like privileged containers) with policies that restrict image sources, leading them to select Option D instead of the correct image-based constraint.

How to eliminate wrong answers

Option A is wrong because the policy 'Kubernetes cluster should be accessible only over HTTPS' enforces TLS for the API server endpoint, not image source restrictions. Option C is wrong because 'Kubernetes cluster should use internal load balancers' mandates internal-facing load balancers for services, which addresses network exposure, not image authorization. Option D is wrong because 'Kubernetes cluster should not allow privileged containers' prevents containers from running with elevated privileges but does not restrict which images can be deployed.

24
MCQmedium

Your company uses Microsoft Purview to classify and label sensitive data. The data protection team needs to automatically apply a 'Confidential' label to documents that contain a custom sensitive info type for employee IDs. Which should you create?

A.A trainable classifier
B.A sensitivity label
C.A retention label
D.A custom sensitive information type and an auto-labeling policy
AnswerD

A custom sensitive information type (SIT) lets you define a precise regex or keyword-based pattern for the employee ID, giving Purview deterministic detection logic for that exact structure. An auto-labeling policy then continuously scans documents in SharePoint, OneDrive, and Exchange for that SIT and automatically applies a sensitivity label when matches are found. Together, these two components provide end-to-end, content-based discovery and labeling — the correct combination for classifying files based on a custom employee ID pattern.

Why this answer

To automatically apply a 'Confidential' label based on the presence of a custom sensitive info type (employee IDs), you need both a custom sensitive information type (SIT) to define the pattern and an auto-labeling policy to trigger the label application. The auto-labeling policy uses the SIT to scan documents and automatically applies the specified sensitivity label when a match is found. This is the only option that combines the detection mechanism with automated labeling.

Exam trap

The trap here is that candidates often confuse the role of a sensitivity label (which is just the label definition) with the auto-labeling policy (which provides the detection and automation), leading them to select only the sensitivity label without the necessary policy.

How to eliminate wrong answers

Option A is wrong because a trainable classifier uses machine learning to identify content based on examples, not a custom pattern like employee IDs, and it cannot directly apply labels without an auto-labeling policy. Option B is wrong because a sensitivity label alone defines the label and its protection settings but does not include the detection logic or automation to apply it automatically based on content. Option C is wrong because a retention label is used for data lifecycle management (retention and deletion), not for sensitivity classification or automatic application based on sensitive info types.

25
MCQmedium

A company uses Microsoft Defender for Cloud to manage security across hybrid workloads. They need to ensure that all Azure VMs have guest-level threat detection enabled. Which security policy should they assign?

A.Azure Security Benchmark
B.Microsoft cloud security benchmark
C.Microsoft Defender for Cloud Apps
D.NIST SP 800-53
AnswerB

The Microsoft cloud security benchmark (MCSB) is the unified, built-in policy initiative that evolved from the Azure Security Benchmark and includes policies that deploy the Guest Configuration extension onto VMs and enable Microsoft Defender for Servers, which provides guest-level threat detection. When this initiative is assigned, its DeployIfNotExists policies automatically install required agents and extensions, directly fulfilling the stated requirement. Thus, it is the correct initiative for enabling guest-level threat detection.

Why this answer

The Microsoft cloud security benchmark (MCSB) is the correct policy because it includes built-in guest-level threat detection recommendations for Azure VMs, such as deploying the Log Analytics agent and enabling Microsoft Defender for Servers with guest-level monitoring. This benchmark is the default initiative in Defender for Cloud and directly maps to the requirement of enabling guest-level threat detection across all VMs.

Exam trap

The trap here is that candidates confuse the deprecated 'Azure Security Benchmark' with the current 'Microsoft cloud security benchmark' or mistakenly think a compliance framework like NIST SP 800-53 can be directly assigned as a security policy in Defender for Cloud to enable technical controls like guest-level threat detection.

How to eliminate wrong answers

Option A is wrong because the Azure Security Benchmark is the predecessor to the Microsoft cloud security benchmark and has been deprecated; it does not include the specific guest-level threat detection policies required for this scenario. Option C is wrong because Microsoft Defender for Cloud Apps is a CASB (Cloud Access Security Broker) for SaaS applications, not a security policy for enabling guest-level threat detection on Azure VMs. Option D is wrong because NIST SP 800-53 is a compliance framework from the U.S.

National Institute of Standards and Technology, not a security policy initiative in Defender for Cloud that can be assigned to enable guest-level threat detection.

26
MCQmedium

A company is designing a security operations center (SOC). They want to use Microsoft Sentinel as their SIEM. They need to ensure that all security events from on-premises servers are collected. Which data connector should they configure?

A.Windows Firewall via Legacy Agent
B.Syslog via AMA
C.Azure Activity Log
D.Windows Security Events via Azure Monitor Agent (AMA)
AnswerD

Windows Security Events via Azure Monitor Agent (AMA) is the correct approach because AMA supports collection of Windows Security event logs from on-premises servers when they are connected via Azure Arc. The agent can be configured with Data Collection Rules (DCRs) to filter specific event IDs (e.g., 4624, 4688) and forward them to a Log Analytics workspace for analysis in Microsoft Sentinel or Microsoft Defender for Endpoint. This modern method replaces the deprecated Legacy Agent and provides the granular security telemetry needed by the SOC.

Why this answer

The Windows Security Events via Azure Monitor Agent (AMA) connector is the recommended method for collecting security events from on-premises Windows servers into Microsoft Sentinel. AMA is the current generation agent that supports data collection rules (DCRs) for granular filtering and is fully supported by Sentinel, replacing the legacy Log Analytics Agent. This ensures comprehensive collection of Windows security logs such as Event ID 4625 (failed logons) and 4688 (process creation) for SOC analysis.

Exam trap

The trap here is that candidates may confuse Syslog (used for Linux/network devices) with Windows Security Events, or mistakenly think the legacy Log Analytics Agent (now deprecated) is still the primary connector for Windows events, when AMA is the current best practice.

How to eliminate wrong answers

Option A is wrong because Windows Firewall via Legacy Agent collects only firewall logs, not the full range of Windows security events (e.g., logon, process creation, object access) required for a SOC. Option B is wrong because Syslog via AMA collects syslog messages from Linux or network devices, not Windows Security Events from on-premises servers. Option C is wrong because Azure Activity Log collects subscription-level control plane events from Azure, not on-premises server security events.

27
Multi-Selecthard

Which TWO are best practices for designing a Microsoft 365 Defender (XDR) deployment to ensure optimal detection and response?

Select 2 answers
A.Deploy Defender for Endpoint on unsupported operating systems with limited functionality
B.Configure automated investigation and response for common incident types
C.Rely solely on manual alert triage to avoid missing complex attacks
D.Enable all supported data sources and ensure proper licensing
E.Configure each workload (Endpoint, Identity, etc.) in SILO mode to avoid false positives
AnswersB, D

Automated investigation and response (AIR) should be enabled for well-understood incident patterns such as phishing, malware outbreaks, or credential theft, because it allows Microsoft 365 Defender to quarantine files, disable accounts, and contain compromised assets in near real time. This reduces manual burden and shortens attacker dwell time by acting consistently at machine speed. Ensuring AIR runs only for high-confidence, common scenarios also minimizes false-positive disruptions and frees analysts to focus on complex incidents.

Why this answer

Option B is correct because configuring automated investigation and response (AIR) for common incident types lets Microsoft 365 Defender automatically investigate and remediate recurring, well-understood threats, which reduces analyst workload and speeds response so human effort can focus on complex attacks. Option D is correct because XDR detection quality depends on ingesting all supported signal sources (endpoint, identity, email, cloud apps, and other connectors) and having the corresponding licenses enabled, since missing telemetry or unlicensed workloads create blind spots that degrade correlation and incident detection. Option A is not a best practice because deploying Defender for Endpoint on unsupported operating systems with limited functionality provides incomplete telemetry and unreliable protection, undermining XDR detection rather than optimizing it.

Option C is not a best practice because relying solely on manual alert triage does not scale and increases the risk of missing complex or high-volume attacks that automation and correlation are designed to catch. Option E is not a best practice because configuring workloads in silo mode prevents cross-domain signal correlation, which is the core value of Microsoft 365 Defender XDR and would increase, not reduce, false positives and missed detections.

Exam trap

The trap here is that candidates may think enabling all data sources (option D) is unnecessary or could cause noise, but in XDR, comprehensive data ingestion is essential for accurate correlation and detection, while proper tuning and automation handle false positives.

28
MCQeasy

A company wants to implement a secure web application gateway to protect their public-facing web apps from common exploits like SQL injection and cross-site scripting. Which Azure service should they use?

A.Azure Front Door with WAF
B.Azure Firewall
C.Azure DDoS Protection
D.Azure Application Gateway with WAF
AnswerD

Azure Application Gateway with WAF is a regional Layer 7 load balancer that handles HTTP(S) traffic with features like cookie-based session affinity, URL-path routing, and SSL termination. Its WAF SKU enforces managed rule sets from the OWASP Core Rule Set, including rules that detect and block SQL injection, cross-site scripting, command injection, and other common exploits. This makes it the ideal choice for a single web app that needs application-layer inspection and protection close to the backend.

Why this answer

Azure Application Gateway with WAF is the correct choice because it is a regional, layer-7 load balancer that includes a built-in Web Application Firewall (WAF) specifically designed to protect web applications from common exploits such as SQL injection and cross-site scripting (XSS). The WAF uses OWASP Core Rule Sets (CRS) to inspect HTTP/HTTPS traffic and block malicious payloads at the application layer, making it the ideal service for securing public-facing web apps.

Exam trap

The trap here is that candidates often confuse Azure Front Door with WAF as a direct alternative to Application Gateway with WAF, but Front Door is a global service for multi-region distribution, while Application Gateway is the regional, layer-7 load balancer with WAF that is the correct choice for protecting a single-region web application gateway.

How to eliminate wrong answers

Option A is wrong because Azure Front Door with WAF is a global, multi-region load balancer and CDN service that also includes WAF capabilities, but it is optimized for global distribution and edge caching, not for protecting a single regional web application gateway; the question implies a single gateway deployment, and Application Gateway is the standard regional choice. Option B is wrong because Azure Firewall is a stateful, network-layer firewall that filters traffic based on IP addresses, ports, and protocols (layers 3-4), and it does not inspect application-layer payloads like SQL injection or XSS; it lacks the WAF functionality required for web application exploits. Option C is wrong because Azure DDoS Protection provides mitigation against volumetric distributed denial-of-service attacks at layers 3 and 4, but it does not inspect or block application-layer attacks such as SQL injection or XSS, which require a WAF.

29
MCQeasy

An organization wants to ensure that all Windows 10 devices are compliant with security policies before they can access corporate email. Microsoft Intune is used for device management. Which component should be used to enforce compliance and block non-compliant devices?

A.Intune device compliance policy alone
B.Microsoft Entra ID Conditional Access policy integrated with Intune compliance
C.Microsoft 365 Defender portal
D.Microsoft Defender for Endpoint device risk score
AnswerB

The correct approach uses a Microsoft Entra Conditional Access policy that contains a grant control such as 'Require device to be marked as compliant.' During authentication, Entra ID retrieves the device's compliance state from Intune; if the Windows 10 device is non-compliant or unenrolled, the policy can block access or require the user to remediate before a token is issued. This is the enforcement point that couples the compliance signal with the identity flow.

Why this answer

Microsoft Entra ID Conditional Access policies can evaluate Intune device compliance status in real time. When a device is marked non-compliant by an Intune compliance policy, the Conditional Access policy blocks access to corporate email (e.g., Exchange Online) until the device is remediated. This integration enforces a 'compliant device required' gate that cannot be achieved by Intune compliance alone, which only reports status without blocking access.

Exam trap

The trap here is that candidates assume Intune compliance policies alone can block access, but they forget that enforcement requires a separate Conditional Access policy to act on the compliance state—Intune only reports, it does not gate authentication.

How to eliminate wrong answers

Option A is wrong because Intune device compliance policy alone only marks devices as compliant or non-compliant; it does not enforce access control or block email access—that requires a Conditional Access policy to act on the compliance state. Option C is wrong because the Microsoft 365 Defender portal provides threat detection, investigation, and response capabilities, but it does not directly enforce device compliance-based access control for email. Option D is wrong because Microsoft Defender for Endpoint device risk score is a signal that can be used within Conditional Access (via risk-based policies), but it is not the primary component for enforcing compliance policies; the question specifically asks for enforcing compliance, not risk-based access.

30
MCQhard

You are designing a secure DevOps pipeline in GitHub that deploys to Azure Kubernetes Service (AKS). The security team requires that no secrets are stored in the pipeline variables and that all container images are scanned for vulnerabilities before deployment. Which approach aligns with security best practices?

A.Use Azure DevOps with a service principal that has a client secret stored in Azure Key Vault. Use Trivy to scan images.
B.Use GitHub Actions with OpenID Connect to authenticate to Azure without storing any secrets. Integrate Microsoft Defender for Containers to scan images in Azure Container Registry.
C.Use GitHub Actions with a managed identity for the GitHub runner. Disable image scanning to speed up deployments.
D.Use GitHub Actions with environment secrets for Azure service principal credentials. Use Docker Hub's vulnerability scanning.
AnswerB

OpenID Connect (OIDC) lets GitHub Actions authenticate to Azure AD using federated credentials, so the workflow receives a short-lived token without storing any client secret, password, or persistent key in the repository. Microsoft Defender for Containers integrates natively with Azure Container Registry to scan images for vulnerabilities on push, continuously assessing compliance and providing runtime protection without adding third-party components.

Why this answer

It uses OpenID Connect (OIDC) to authenticate GitHub Actions to Azure without storing any long-lived secrets, which aligns with the requirement that no secrets be stored in pipeline variables. Additionally, integrating Microsoft Defender for Containers provides vulnerability scanning for container images in Azure Container Registry (ACR), meeting the image scanning requirement before deployment to AKS.

Exam trap

The trap here is that candidates may assume Azure DevOps is the only secure option or that storing secrets in Azure Key Vault is acceptable, but the question explicitly requires 'no secrets stored in the pipeline variables,' and OIDC eliminates secrets entirely, while Key Vault still requires a secret retrieval step that counts as a stored secret in the pipeline context.

How to eliminate wrong answers

Option A is wrong because it uses Azure DevOps instead of GitHub Actions as specified in the question, and it stores a client secret in Azure Key Vault, which still requires a secret to be retrieved and used in the pipeline, violating the 'no secrets stored in pipeline variables' requirement. Option C is wrong because it disables image scanning, which directly contradicts the requirement that all container images be scanned for vulnerabilities before deployment. Option D is wrong because it uses environment secrets for Azure service principal credentials, which stores secrets in the pipeline environment, and Docker Hub's vulnerability scanning does not integrate with ACR or AKS for pre-deployment scanning in the Azure context.

31
Multi-Selecthard

Your organization is designing a Microsoft Sentinel solution to detect and respond to threats across multi-cloud environments (Azure, AWS, GCP). Which TWO components are essential for this design?

Select 2 answers
A.Azure Policy assignments
B.Data connectors for AWS and GCP
C.Microsoft Defender for Cloud
D.Azure Automation accounts
E.Analytics rules for multi-cloud detection
AnswersB, E

Microsoft Sentinel's data connectors for AWS (using S3 with CloudTrail, VPC Flow Logs, and GuardDuty findings) and for GCP (using Cloud Logging via Pub/Sub) are purpose-built to ingest cloud-native telemetry into the Log Analytics workspace. These connectors are the foundational first step in a multi-cloud design, transforming raw logs into tables that analytics rules and workbooks can query. Without them, none of the subsequent detection or incident response logic has data to operate on, so they are the correct answer.

Why this answer

Option B is correct because Microsoft Sentinel ingests AWS and GCP telemetry through dedicated data connectors (for example, the AWS S3/CloudTrail connector and the GCP Pub/Sub connector), which are the mechanism that brings multi-cloud logs into the Sentinel workspace for correlation and detection. Option E is correct because analytics rules are the Sentinel detection logic that runs scheduled or near-real-time queries against the ingested multi-cloud data to generate incidents and alerts, which is the core of detecting threats across Azure, AWS, and GCP. Option A is not essential here because Azure Policy assignments govern resource compliance and configuration within Azure, not cross-cloud threat detection in Sentinel.

Option C is not essential because Microsoft Defender for Cloud primarily provides CSPM/CWPP posture and workload protection for Azure, AWS, and GCP but is not the Sentinel component that ingests and detects on multi-cloud logs. Option D is not essential because Azure Automation accounts are used for runbook orchestration and task automation, not for the core ingestion and detection design of a multi-cloud Sentinel solution.

Exam trap

The trap here is that candidates confuse Microsoft Defender for Cloud (a CSPM tool) with a data ingestion mechanism, or assume Azure Policy can enforce log collection across non-Azure clouds, when in fact only purpose-built data connectors can bring external logs into Sentinel.

32
Multi-Selecteasy

Which TWO are recommended practices for securing Microsoft 365 workloads? (Select two.)

Select 2 answers
A.Allow external sharing for all SharePoint sites
B.Disable multifactor authentication for users who access from trusted IPs
C.Allow all third-party apps to access Microsoft 365 data
D.Enable unified audit logging in Microsoft Purview
E.Use Microsoft Defender for Office 365 Safe Attachments policy
AnswersD, E

Unified audit logging in Microsoft Purview is a critical detective control because it records every event across Exchange, SharePoint, Teams, and other workloads, enabling you to trace user actions and respond to incidents. Without a complete, centrally searchable audit trail, your security team cannot effectively investigate data breaches, insider threats, or compliance violations.

Why this answer

Option D is correct because enabling unified audit logging in Microsoft Purview ensures that user and admin activities across Exchange Online, SharePoint Online, OneDrive, and Teams are recorded, which is essential for incident investigation, forensic analysis, and compliance reporting. Option E is correct because a Microsoft Defender for Office 365 Safe Attachments policy detonates email attachments in a sandbox before delivery, blocking zero-day malware and malicious payloads that traditional signature-based filtering would miss. The unmarked options do not belong: A weakens security by exposing SharePoint content externally, B undermines account protection by removing MFA even for trusted IPs (which can be spoofed or compromised), and C grants broad OAuth access to third-party apps, increasing the risk of data exfiltration and consent-phishing attacks.

Exam trap

The trap here is that candidates often confuse 'enabling audit logging' with 'enabling mailbox auditing only' or assume that audit logging is enabled by default, but Microsoft Purview unified audit logging must be explicitly enabled per tenant and is not automatically turned on for all workloads.

33
MCQhard

Your organization uses Microsoft Sentinel for security operations. The SOC team wants to automatically disable a compromised user account in Microsoft Entra ID when a high-severity alert is generated. Which automation method should you use?

A.An automation rule with a playbook
B.A workbook
C.A KQL query in a hunting rule
D.An analytics rule
AnswerA

An automation rule with a playbook is the correct choice for automated remediation because automation rules can be configured to trigger a playbook when an incident is created or updated. The playbook, built on Azure Logic Apps, can then execute actions such as calling Microsoft Graph API to disable a compromised user account, making it the only option here that both detects and responds automatically.

Why this answer

Automation rules in Microsoft Sentinel can trigger a playbook (an Azure Logic Apps workflow) when a high-severity alert fires. The playbook can then execute an action to disable the user account in Microsoft Entra ID via the Microsoft Graph API. This is the correct method because it provides the necessary integration between Sentinel alerts and Entra ID identity remediation.

Exam trap

The trap here is that candidates often confuse analytics rules (which detect and alert) with automation rules (which respond), leading them to select an analytics rule thinking it can directly perform remediation actions.

How to eliminate wrong answers

Option B is wrong because a workbook is a visualization and reporting tool, not an automation mechanism; it cannot execute actions like disabling a user account. Option C is wrong because a KQL query in a hunting rule is used for proactive threat hunting and manual investigation, not for automated response to alerts. Option D is wrong because an analytics rule generates alerts based on detection logic but does not itself perform remediation actions; it requires an automation rule or playbook to act on the alert.

34
MCQmedium

A company uses Microsoft Intune to manage devices. They want to ensure that all devices accessing corporate email are compliant with security policies before they can connect. Which feature should they enable?

A.Microsoft Entra Conditional Access
B.Microsoft Defender for Endpoint
C.Microsoft Intune App Protection Policies
D.Mobile Device Management (MDM) enrollment
AnswerA

Microsoft Entra Conditional Access is the correct control because it is the policy engine that evaluates conditions such as device compliance status, user risk, location, and application sensitivity before granting access. It consumes the compliance state reported by Intune (via compliance policies) and then either allows, blocks, or restricts access with an MFA or app-policy challenge. Without Conditional Access, a compliant device gets no automatic enforcement; the policy must be explicitly configured to require compliance, making it the actual mechanism that turns Intune compliance into an access decision.

Why this answer

Microsoft Entra Conditional Access is the correct feature because it enforces compliance-based access control at the authentication layer. By integrating with Intune compliance policies, Conditional Access can block or allow device access to corporate email (e.g., Exchange Online) based on real-time compliance status, ensuring only compliant devices can connect.

Exam trap

The trap here is that candidates often confuse Intune compliance policies themselves with the enforcement mechanism, not realizing that compliance policies only mark a device as compliant or non-compliant—they do not block access; Conditional Access is the gate that enforces the block.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Endpoint is a threat protection and response solution, not an access control mechanism; it does not enforce pre-connection compliance checks for email. Option C is wrong because Intune App Protection Policies (MAM) manage data protection within apps without requiring device enrollment, but they do not block device-level access to email based on device compliance. Option D is wrong because MDM enrollment alone only registers the device; it does not enforce conditional access—compliance policies must be combined with Conditional Access to gate access.

35
MCQmedium

A company plans to implement a Zero Trust architecture using Microsoft security solutions. They want to ensure that all access to corporate resources is verified explicitly, uses least privilege, and assumes breach. Which Microsoft service should be the central policy engine for enforcing conditional access decisions?

A.Microsoft Entra ID Conditional Access
B.Microsoft Defender for Cloud
C.Microsoft Sentinel
D.Microsoft Intune
AnswerA

Microsoft Entra ID Conditional Access is the core policy engine for Zero Trust, evaluating signals such as user identity, device health, location, and risk in real time. It enforces 'never trust, always verify' by granting, blocking, or requiring step-up authentication based on conditional policies. As the central access decision point, it integrates with all other Zero Trust pillars and is the primary mechanism for securing user access.

Why this answer

Microsoft Entra ID Conditional Access is the correct central policy engine because it directly enforces Zero Trust principles by evaluating signals (user, device, location, risk) in real time to grant or block access. It acts as the policy decision point (PDP) that enforces explicit verification, least privilege, and assumes breach by requiring continuous authentication and authorization for every access request.

Exam trap

The trap here is that candidates confuse Microsoft Defender for Cloud's security policy (which governs cloud resource configurations) with Entra ID's conditional access policy (which governs user access decisions), leading them to select Defender for Cloud as the central policy engine.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform, not a policy engine for conditional access decisions. Option C is wrong because Microsoft Sentinel is a SIEM/SOAR solution for threat detection and response, not a real-time access policy enforcer. Option D is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service that manages devices and apps but does not make conditional access policy decisions.

36
MCQhard

Your organization uses Microsoft Sentinel for SIEM. You need to ensure that security incidents are automatically responded to without human intervention for known false positives. What should you implement?

A.An analytics rule with alert suppression
B.A playbook that runs on incident creation
C.An entity behavior analytics rule
D.An automation rule with incident closure action
AnswerD

An automation rule with an incident closure action directly satisfies the no-human-intervention constraint: automation rules run in Microsoft Sentinel without a playbook, and the closure action resolves matching incidents automatically. For known false positives, this eliminates analyst triage entirely, unlike playbooks, which require a Logic Apps trigger and typically perform richer remediation.

Why this answer

Automation rules in Microsoft Sentinel can be configured to automatically close incidents when specific conditions are met, such as when an incident is identified as a known false positive. This eliminates the need for human intervention by triggering an incident closure action based on predefined criteria, directly addressing the requirement for automated response to false positives.

Exam trap

The trap here is that candidates often confuse alert suppression (which prevents duplicate alerts) with incident closure automation, or they assume a playbook is always required for automation, when in fact a simple automation rule with a closure action is the direct and correct solution for automatically handling known false positives.

How to eliminate wrong answers

Option A is wrong because analytics rules with alert suppression only prevent the creation of duplicate alerts for the same event within a specified time window; they do not automatically respond to or close incidents that have already been created. Option B is wrong because a playbook that runs on incident creation can automate responses, but it requires a separate automation rule to trigger it and is typically used for complex orchestration, not simply for closing known false positives without human intervention. Option C is wrong because entity behavior analytics rules are designed to detect anomalous behavior based on historical patterns, not to automatically respond to or close incidents identified as false positives.

37
MCQmedium

Your organization uses Microsoft Defender for Cloud to assess the security posture of Azure resources. The security team wants to prioritize remediation of high-severity findings based on the greatest potential business impact. Which security policy or framework should you configure to align remediation with business priorities?

A.Use the Azure Security Benchmark initiative
B.Enable the Regulatory Compliance dashboard
C.Set up workflow automation for high-severity findings
D.Configure the Secure Score dashboard
AnswerB

The Regulatory Compliance dashboard in Microsoft Defender for Cloud maps security findings to specific regulatory standards (e.g., CIS, NIST SP 800-53, PCI DSS, ISO 27001) and tracks compliance status for each control. This directly ties security gaps to business and legal obligations, enabling you to prioritize remediation efforts based on which non-compliant controls carry the highest regulatory and business impact. By focusing on the standards that matter to your organization, you can align operational security work with audit deadlines, contractual obligations, and risk tolerance, making it the correct method for business-impact-centric prioritization.

Why this answer

The Regulatory Compliance dashboard in Microsoft Defender for Cloud allows you to map security controls to specific regulatory standards (e.g., SOC 2, ISO 27001, PCI DSS) and track compliance posture. By selecting a framework that aligns with your organization's business obligations (e.g., a standard required by customers or regulators), you can prioritize remediation of high-severity findings based on the greatest potential business impact, such as fines or loss of certification.

Exam trap

The trap here is that candidates often confuse the Secure Score dashboard (which measures overall security posture) with the Regulatory Compliance dashboard (which aligns remediation to specific business-impacting standards), leading them to select D instead of B.

How to eliminate wrong answers

Option A is wrong because the Azure Security Benchmark initiative is a Microsoft-defined set of best practices for Azure security, but it does not inherently map to business-specific regulatory or compliance priorities; it focuses on technical security posture rather than business impact. Option C is wrong because workflow automation (e.g., sending emails or creating tickets) is a response mechanism for findings, not a framework for prioritizing which findings to remediate based on business impact. Option D is wrong because the Secure Score dashboard provides a numerical score based on security recommendations, but it does not allow you to configure or align remediation with specific business or regulatory frameworks; it is a general health indicator, not a prioritization tool.

38
MCQeasy

Your organization is adopting a Zero Trust security model. You need to design a solution that ensures continuous verification of user identity and device health before granting access to resources. Which Microsoft Entra ID feature should you prioritize?

A.Microsoft Entra ID Domain Services
B.Microsoft Entra ID Identity Protection
C.Microsoft Entra ID Conditional Access
D.Microsoft Entra ID Privileged Identity Management (PIM)
AnswerC

Microsoft Entra ID Conditional Access is the correct answer because it is the policy engine that evaluates real-time signals—such as user identity, group membership, location, device compliance, and sign-in risk—to allow or restrict access. It enables Zero Trust policies like requiring compliant devices, enforcing multi-factor authentication, and blocking sessions when risk is detected. Conditional Access also integrates with continuous access evaluation (CAE) to revoke access in near real-time when conditions change, directly aligning with the 'never trust, always verify' principle and your requirement for device health verification before access.

Why this answer

Conditional Access is the primary Microsoft Entra ID feature that enforces continuous verification by evaluating user identity, device health (via compliance policies or Microsoft Defender for Endpoint signals), location, and risk in real-time before granting access. It directly supports the Zero Trust principle of 'never trust, always verify' by requiring authentication and authorization at every access attempt, not just at the perimeter.

Exam trap

The trap here is that candidates confuse Identity Protection's risk detection capabilities with the enforcement mechanism, but Identity Protection alone cannot block access based on device health or enforce conditional policies—it only provides signals that must be consumed by Conditional Access to make a decision.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Domain Services provides managed domain services like LDAP, Kerberos, and NTLM for legacy applications, not continuous identity or device health verification. Option B is wrong because Identity Protection focuses on detecting and responding to identity-based risks (e.g., leaked credentials, anomalous sign-ins) but does not enforce access decisions based on device health or real-time verification; it feeds risk signals into Conditional Access. Option D is wrong because Privileged Identity Management (PIM) manages just-in-time privileged role activation and approval workflows, not continuous verification of all user identities or device health for general resource access.

39
Multi-Selecthard

Your organization is implementing Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. You need to design a policy that prevents users from sharing credit card numbers via email. Which THREE components are required to build this DLP policy?

Select 3 answers
A.A policy tip to warn users before sending
B.A rule that includes a sensitive info type for credit card numbers
C.A trainable classifier for financial data
D.A policy scope that includes Exchange Online
E.An action to block the email and send a notification
AnswersB, D, E

The rule must include a condition that matches the data you want to protect; for credit card numbers, Microsoft Purview DLP provides a built-in sensitive information type (SIT) called "Credit Card Number" that detects 15-16 digit card numbers and uses Luhn checksum validation to reduce false positives. Without this SIT as a condition, the policy has no trigger and will never be evaluated against outgoing mail. This SIT is part of the default DLP rule conditions and is the correct, deterministic way to identify credit card data versus using experimental AI classifiers.

Why this answer

Option B is correct because a DLP rule must reference a sensitive information type (SIT), such as the built-in Credit Card Number SIT, to detect the credit card data the policy is meant to protect. Option D is correct because the policy must be scoped to the Exchange Online workload so that email traffic is actually evaluated by the DLP engine. Option E is correct because a rule needs an action, such as blocking the email and notifying the sender or admin, to enforce protection once credit card numbers are detected.

Option A is not required because a policy tip is an optional user-notification enhancement, not a mandatory component for the policy to function. Option C is not required because trainable classifiers are used for content that is hard to identify with patterns, whereas credit card numbers are detected by a built-in sensitive information type.

Exam trap

The trap here is that candidates often confuse optional enhancements (like policy tips or trainable classifiers) with mandatory components, but the core requirement is a rule with a sensitive info type, a scope (Exchange Online), and an action to block and notify.

40
MCQmedium

Your organization wants to implement a zero-trust security model for on-premises and cloud resources. As part of this strategy, you need to ensure that all access requests are authenticated and authorized based on dynamic risk signals. Which Microsoft security solution should you use to enforce conditional access policies based on real-time risk?

A.Microsoft Entra ID Conditional Access
B.Microsoft Intune
C.Microsoft Sentinel
D.Microsoft Defender for Cloud
AnswerA

Microsoft Entra ID Conditional Access is the policy enforcement engine that operationalizes zero trust by evaluating real-time signals such as user identity, device health, location, and risk level at the moment of authentication. It dynamically allows or blocks access, or requires additional controls like MFA or session policies, integrated directly with identity authentication. This makes it the central decision point for enforcing conditional access policies, rather than a supporting or monitoring tool.

Why this answer

Microsoft Entra ID Conditional Access is the correct solution because it enables you to enforce access policies based on real-time risk signals, such as user risk, sign-in risk, and device compliance. It integrates with Identity Protection to evaluate dynamic risk levels and can block or require multi-factor authentication (MFA) accordingly, directly supporting the zero-trust principle of 'never trust, always verify'.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with a real-time access control solution, but Sentinel only provides detection and response after the fact, not inline policy enforcement during authentication.

How to eliminate wrong answers

Option B (Microsoft Intune) is wrong because it is a mobile device management (MDM) and mobile application management (MAM) solution that focuses on device compliance and app protection policies, not on real-time risk-based conditional access enforcement. Option C (Microsoft Sentinel) is wrong because it is a security information and event management (SIEM) and security orchestration automated response (SOAR) solution that aggregates logs and detects threats, but it does not natively enforce conditional access policies at the authentication layer. Option D (Microsoft Defender for Cloud) is wrong because it is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides recommendations and threat protection for cloud workloads, not real-time risk-based access control for user sign-ins.

41
MCQhard

Your organization plans to use Microsoft Purview to protect sensitive data in Microsoft 365. The compliance team needs to detect when users share credit card numbers via email and automatically apply encryption. Which solution should you implement?

A.Microsoft Purview Audit
B.Microsoft Purview eDiscovery
C.Microsoft Purview Information Protection
D.Microsoft Purview Data Loss Prevention (DLP)
AnswerD

Microsoft Purview Data Loss Prevention (DLP) policies continuously monitor emails for sensitive information types such as credit card numbers or social security numbers, and when a match is detected, the policy can automatically trigger protection actions. In Exchange Online, DLP leverages transport rules to apply IRM encryption to outbound messages, ensuring only intended recipients can read them. This capability directly aligns with the requirement to automatically encrypt emails based on content, making DLP the correct choice.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect sensitive data types—such as credit card numbers—in email messages and automatically apply protective actions like encryption. DLP policies can inspect email content in transit via Exchange Online, match patterns against predefined sensitive info types (e.g., credit card number regex), and trigger actions such as 'Encrypt the message' using Azure Rights Management. This directly meets the requirement to detect sharing of credit card numbers and enforce encryption automatically.

Exam trap

Microsoft often tests the distinction between Information Protection (labeling/classification) and Data Loss Prevention (content inspection and automated enforcement), leading candidates to pick Information Protection because they confuse 'protecting data' with 'detecting and acting on sensitive content.'

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Audit only logs user and admin activities for forensic review; it cannot inspect email content for sensitive data or apply encryption. Option B is wrong because Microsoft Purview eDiscovery is used for searching and exporting content in legal or compliance investigations, not for real-time detection and automated protection of sensitive data in transit. Option C is wrong because Microsoft Purview Information Protection focuses on classifying and labeling documents and emails (e.g., sensitivity labels), but it does not natively scan for specific sensitive data patterns like credit card numbers or enforce automatic encryption based on content detection—that requires DLP policies to trigger the label or encryption action.

42
MCQhard

Refer to the exhibit. Your organization is required to comply with PCI DSS. You need to prioritize remediation efforts to meet PCI DSS requirements. Based on the exhibit, which recommendation should you address first?

A.Enable MFA on accounts with owner permissions
B.Migrate VMs from classic to ARM
C.Enable vulnerability assessment on SQL databases
D.Enable diagnostic logs in Key Vault
AnswerA

MFA on account owner permissions directly satisfies PCI DSS 8.3.1, which mandates multi-factor authentication for all administrative access to cardholder data environments. In Azure, the Owner role grants full control over all resource and security configurations, making it a primary target for credential compromise. Enabling MFA via Conditional Access or Azure AD security defaults is an immediate, auditable control that closes a current high-risk exposure and is a prerequisite for passing any PCI DSS assessment.

Why this answer

PCI DSS requires strong access control, including multi-factor authentication for remote access and for all accounts with administrative access. The recommendation 'MFA should be enabled on accounts with owner permissions' directly impacts PCI DSS requirements for authentication. While vulnerability assessment is important, MFA is a key control for PCI DSS.

The other recommendations are less directly related to PCI DSS.

43
MCQhard

Refer to the exhibit. You are analyzing an Azure PowerShell script that checks a blob property. The output of the last command returns 'False'. What does this indicate about the blob storage configuration?

A.Diagnostic logging is not configured for the container.
B.Access time tracking is disabled for the storage account.
C.The blob has an immutability policy applied.
D.Server-side encryption is disabled for the blob.
AnswerB

The Azure PowerShell output likely reveals that the storage account's LastAccessTimeTrackingPolicy.Enabled property is set to False. When this account-level feature is disabled, reads against blobs do not refresh their LastAccessTime property, leaving it stale or empty regardless of how frequently the blob is accessed. Enabling this policy via Set-AzStorageAccount -EnableLastAccessTimeTracking is a prerequisite for seeing current last-access timestamps, so the disabled state directly explains the unexpected value.

Why this answer

The correct answer is B: Access time tracking is disabled for the storage account. In Azure Storage, the blob property that reports whether last-access time tracking is enabled returns False when the account-level setting `LastAccessTimeTrackingPolicy` is not enabled, meaning the service is not recording last access times for blobs. Options A, C, and D are unrelated to this property: diagnostic logging is configured via Azure Monitor diagnostic settings, immutability policies are set through container/blob immutability settings, and server-side encryption is always enabled for Azure Storage blobs and is not reported by this property.

44
MCQhard

Your organization uses Microsoft Sentinel as its SIEM. You need to design a solution to automatically respond to detected threats in Azure resources. The response must include isolating the affected virtual machine and creating a support ticket. Which approach should you use?

A.Create a Microsoft Sentinel automation rule that triggers a playbook when an incident is generated. The playbook uses Azure Logic Apps to isolate the VM and create a ticket in your IT service management tool.
B.Create an Azure Policy initiative that automatically remediates non-compliant resources
C.Create a Microsoft Sentinel analytics rule that runs a KQL query and automatically sends an email to the security team
D.Create an Azure Automation runbook that runs on a schedule to check for threats and isolate VMs
AnswerA

An automation rule in Microsoft Sentinel is the native, event-driven mechanism that fires when an incident is generated, and it can invoke a playbook without any human intervention. The playbook, built in Azure Logic Apps, contains the orchestration steps to isolate the compromised VM—for example, by calling Microsoft Defender for Cloud or Azure Resource Manager to apply a network security group or an isolation action—and then create a ticket in your IT service management tool through its connector. This tightly integrates detection and response, ensuring a repeatable, auditable, and low-latency reaction to a security incident.

Why this answer

Microsoft Sentinel automation rules can trigger playbooks (Azure Logic Apps) when incidents are generated. Logic Apps provide native connectors to isolate Azure VMs (via the Azure Resource Manager connector) and create tickets in IT service management tools (e.g., ServiceNow, Jira), meeting both requirements in a single automated workflow.

Exam trap

The trap here is confusing scheduled or policy-based automation (Options B and D) with event-driven incident response, which requires a trigger tied to Sentinel incident creation and a playbook capable of multi-step actions like VM isolation and ITSM ticket creation.

How to eliminate wrong answers

Option B is wrong because Azure Policy initiatives enforce compliance at resource creation or configuration drift, not real-time threat response; they cannot isolate a VM already under attack or create a support ticket. Option C is wrong because analytics rules generate alerts or incidents but cannot perform automated actions like VM isolation or ticket creation; they only trigger email notifications. Option D is wrong because an Azure Automation runbook on a schedule cannot respond to threats in real time; it lacks integration with Sentinel incident triggers and cannot create tickets in an ITSM tool without custom code.

45
MCQeasy

Your organization is implementing a Zero Trust security model. Which Microsoft security solution should you use to enforce conditional access policies based on user, device, location, and real-time risk signals?

A.Microsoft Entra ID Conditional Access
B.Microsoft Defender for Cloud Apps
C.Microsoft Intune
D.Microsoft Purview
AnswerA

Microsoft Entra ID Conditional Access is the direct policy engine for access control in a Zero Trust architecture. It continuously evaluates signals such as user identity, group membership, location, device compliance, and real-time risk (from Entra ID Protection) to enforce granular decisions like allow, deny, or require MFA. Because it applies these conditions to every sign-in and session in real time, it is the core mechanism for implementing 'explicit verification' in Zero Trust.

Why this answer

Microsoft Entra ID Conditional Access is the correct solution because it is the native policy engine in Azure AD that evaluates signals from user identity, device compliance, location (IP ranges or countries), and real-time risk from Microsoft Entra ID Protection to enforce access decisions. It directly implements the 'explicit verification' and 'assume breach' principles of Zero Trust by blocking or requiring step-up authentication based on these dynamic conditions.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps as the primary policy enforcement point because of its session monitoring capabilities, but it is actually a downstream consumer of Conditional Access decisions, not the engine that evaluates user, device, location, and risk signals in real time.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides shadow IT discovery, session controls, and data protection, but it does not natively enforce conditional access policies based on user, device, location, and risk signals—it integrates with Conditional Access for those decisions. Option C is wrong because Microsoft Intune is a Mobile Device Management (MDM) and Mobile Application Management (MAM) solution that manages device compliance and app protection policies, but it does not evaluate real-time risk signals or enforce access policies at the authentication layer. Option D is wrong because Microsoft Purview is a data governance, compliance, and information protection solution focused on data classification, labeling, and eDiscovery, not on enforcing authentication-time conditional access based on user, device, location, or risk.

46
MCQmedium

Your company uses Microsoft Sentinel as its SIEM. You need to design a solution that automatically responds to high-severity incidents by creating a ticket in ServiceNow and notifying the security team via Teams. Which Sentinel feature should you configure?

A.Workbooks
B.Automation rules
C.Analytics rules
D.Hunting queries
AnswerB

Automation rules are the core mechanism in Microsoft Sentinel for centrally managing and executing automated response actions. They run whenever an incident is created or updated, and can perform actions such as triggering playbooks, changing incident severity, assigning ownership, adding tags, or applying custom logic. You can scope automation rules by analytics rule, severity, or other conditions, making them the purpose-built and correct answer for automating response in Sentinel.

Why this answer

Automation rules in Microsoft Sentinel are designed to trigger automated responses to incidents based on conditions like severity. They can integrate with external systems via playbooks (Azure Logic Apps) to create ServiceNow tickets and send Teams notifications, making them the correct choice for this requirement.

Exam trap

The trap here is that candidates often confuse Analytics rules (which generate alerts) with Automation rules (which respond to incidents), failing to recognize that incident response orchestration requires the latter's trigger-and-action pipeline.

How to eliminate wrong answers

Option A is wrong because Workbooks are visualization tools for querying and displaying data, not for automated response actions. Option C is wrong because Analytics rules generate alerts from log data but do not directly orchestrate multi-step responses like ticket creation or Teams notifications. Option D is wrong because Hunting queries are proactive, ad-hoc searches for threats and do not provide automated incident response capabilities.

47
Multi-Selecthard

Which THREE Microsoft security solutions can be used to detect and respond to threats across hybrid cloud environments? (Choose three.)

Select 3 answers
A.Microsoft Defender for Cloud
B.Microsoft Sentinel
C.Microsoft Defender for Office 365
D.Microsoft Intune
E.Microsoft Defender for Identity
AnswersA, B, E

Microsoft Defender for Cloud is a cloud-native application protection platform (CNAPP) specifically designed to detect and respond to threats across hybrid and multicloud environments. It provides security alerts for compute, storage, databases, and containers, extending on-premises coverage through Azure Arc. Unlike email or device management tools, Defender for Cloud directly performs workload-level threat detection, making it a correct solution for this scenario.

Why this answer

Microsoft Defender for Cloud (A) is correct because it provides Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) capabilities that continuously assess and protect Azure, AWS, GCP, and on-premises resources, generating security alerts and recommendations across hybrid environments. Microsoft Sentinel (B) is correct because it is a cloud-native SIEM and SOAR solution that ingests data from hybrid sources via connectors, correlates it with analytics rules, and enables automated threat detection and response through playbooks. Microsoft Defender for Identity (E) is correct because it monitors on-premises Active Directory Domain Services signals and integrates with Defender for Cloud Apps and Sentinel to detect identity-based attacks such as lateral movement and credential theft in hybrid identity scenarios.

Microsoft Defender for Office 365 (C) is not correct because it focuses on protecting email, collaboration, and Office apps from phishing and malware, not on broad hybrid cloud threat detection and response. Microsoft Intune (D) is not correct because it is a mobile device and endpoint management (MDM/MAM) service for configuration and compliance, not a threat detection and response solution for hybrid cloud workloads.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Office 365 with a broader hybrid cloud security solution, but it is limited to the Microsoft 365 suite and does not cover compute, network, or identity threats across hybrid cloud workloads.

48
MCQmedium

Your company uses Microsoft Defender XDR to protect endpoints. The security team wants to implement automated response actions when a malicious file is detected on a device. Which Microsoft security feature should you configure to automatically isolate the affected device from the network?

A.Automated investigation and response (AIR) capabilities
B.Microsoft Sentinel automation rules
C.Attack surface reduction rules
D.Microsoft Intune compliance policies
AnswerA

Automated investigation and response (AIR) is a built-in Microsoft Defender XDR engine that orchestrates detection, investigation, and remediation across endpoints. When malicious activity such as a suspected ransomware or credential theft is identified, AIR can automatically perform device isolation — a native action that severs the endpoint's network connections while preserving communication with Defender for Endpoint services. This isolation can be executed without human intervention or with approval depending on the automation level configured, making it the appropriate capability for this requirement.

Why this answer

Automated investigation and response (AIR) in Microsoft Defender XDR is the correct feature because it includes built-in playbooks that can automatically isolate a device from the network when a malicious file is detected. AIR leverages the Microsoft 365 Defender portal's automation capabilities to run investigation steps and execute response actions, such as device isolation, without manual intervention. This directly meets the requirement for automated response upon file detection.

Exam trap

The trap here is that candidates often confuse the proactive prevention capabilities of Attack surface reduction rules with the automated response capabilities of AIR, or they overestimate the real-time response abilities of Intune compliance policies, which are designed for configuration enforcement rather than incident response actions like network isolation.

How to eliminate wrong answers

Option B is wrong because Microsoft Sentinel automation rules are designed for cloud-scale SIEM and SOAR across multiple data sources, not for endpoint-specific automated isolation triggered by Defender XDR detections; they require custom analytics and playbooks to achieve similar behavior, making them less direct for this use case. Option C is wrong because Attack surface reduction rules are proactive policies that block or audit specific behaviors (e.g., Office apps creating child processes) to prevent infection, but they do not perform automated response actions like device isolation after a file is already detected as malicious. Option D is wrong because Microsoft Intune compliance policies enforce device configuration and health requirements (e.g., requiring encryption or a minimum OS version) and can trigger conditional access blocks, but they cannot automatically isolate a device from the network in real time based on a malicious file detection; that action is outside Intune's scope.

49
MCQhard

A company needs to design a secure DevOps pipeline using GitHub Actions and Microsoft Defender for Cloud. They want to scan infrastructure-as-code (IaC) templates for misconfigurations before deployment. What should they integrate?

A.Microsoft Defender for Cloud Infrastructure as Code scanning
B.Microsoft Purview Compliance Manager
C.Microsoft Sentinel
D.Microsoft Defender for Cloud Apps
AnswerA

Microsoft Defender for Cloud Infrastructure as Code scanning is the correct choice because it directly integrates with DevOps platforms like GitHub and Azure DevOps to continuously scan Infrastructure as Code templates (e.g., ARM, Bicep, Terraform) in pull requests and pipelines. It leverages Defender for Cloud's security recommendations and policy library to identify misconfigurations before deployment, preventing insecure cloud resources from ever being provisioned. This is a native cloud security posture management capability purpose-built for IaC validation.

Why this answer

Microsoft Defender for Cloud includes a native Infrastructure as Code (IaC) scanning capability that integrates directly with GitHub Actions. This feature automatically analyzes IaC templates (such as ARM, Bicep, Terraform, and CloudFormation) for security misconfigurations during the CI/CD pipeline, providing pre-deployment guardrails. By failing the pipeline on critical findings, it ensures only compliant infrastructure is deployed, aligning with the secure DevOps principle of shifting security left.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud's IaC scanning with Microsoft Sentinel's threat detection capabilities, mistakenly thinking Sentinel can scan code before deployment, when in fact Sentinel only analyzes logs and alerts from already-deployed resources.

How to eliminate wrong answers

Option B (Microsoft Purview Compliance Manager) is wrong because it focuses on regulatory compliance posture management and risk assessments, not on scanning IaC templates for misconfigurations in a DevOps pipeline. Option C (Microsoft Sentinel) is wrong because it is a SIEM and SOAR solution for threat detection and incident response after deployment, not a pre-deployment IaC scanning tool. Option D (Microsoft Defender for Cloud Apps) is wrong because it is a CASB (Cloud Access Security Broker) for controlling user access and data protection in SaaS applications, not for scanning infrastructure code.

50
MCQmedium

Wide World Importers uses Azure Active Directory (now Microsoft Entra ID) and Microsoft 365. They have a hybrid identity with password hash sync. They want to implement a passwordless authentication strategy to improve security and user experience. They have a mix of Windows 10/11 devices and mobile devices (iOS/Android). They also have some shared computers in kiosk mode. The solution must support all user scenarios and align with Microsoft's authentication best practices. What should you recommend?

A.Use SMS-based authentication for all users. Deploy OATH tokens for shared computers. Implement Azure AD Conditional Access to require passwordless for admins only.
B.Implement Windows Hello for Business for all Windows devices. Use smart cards for mobile devices. Use FIDO2 keys for shared computers.
C.Implement Windows Hello for Business for Windows 10/11 devices. Deploy Microsoft Authenticator for mobile devices for passwordless sign-in. Use FIDO2 security keys for shared computers and kiosk scenarios. Enable combined registration for self-service password reset and Microsoft Authenticator.
D.Use the Microsoft Authenticator app for all users. Configure passwordless sign-in with the app. Use QR codes for kiosk computers.
AnswerC

Windows Hello for Business covers Windows 10/11 with hardware-bound credentials, Microsoft Authenticator enables phone sign-in for iOS/Android, and FIDO2 keys suit shared kiosks where per-user enrolment is impractical. Combined registration lets users set up SSPR and Authenticator together, satisfying the mixed-device and kiosk constraints.

Why this answer

It aligns with Microsoft's passwordless authentication best practices by using Windows Hello for Business for Windows 10/11 devices (which supports biometric and PIN-based sign-in), Microsoft Authenticator for mobile devices (enabling phone-sign-in passwordless authentication), and FIDO2 security keys for shared computers and kiosk scenarios (which provide hardware-backed, phishing-resistant credentials). Combined registration streamlines the user enrollment process for both SSPR and Microsoft Authenticator, ensuring a seamless deployment across all device types.

Exam trap

The trap here is that candidates may assume SMS-based authentication or smart cards are acceptable passwordless methods, but Microsoft's best practices explicitly exclude SMS due to security weaknesses and smart cards due to lack of mobile device support, while FIDO2 keys are the only recommended solution for shared/kiosk computers.

How to eliminate wrong answers

Option A is wrong because SMS-based authentication is not truly passwordless (it relies on a phone number and one-time code, which is susceptible to SIM-swap attacks and does not meet Microsoft's passwordless best practices), and OATH tokens for shared computers are not a recommended passwordless solution for kiosk scenarios (FIDO2 keys are preferred for phishing resistance). Option B is wrong because smart cards are not a practical or supported passwordless solution for mobile devices (iOS/Android do not natively support smart card authentication without additional hardware and middleware), and Windows Hello for Business is not available on all Windows devices (it requires Windows 10/11 Pro or Enterprise with TPM 2.0, and shared computers in kiosk mode may not support it). Option D is wrong because using Microsoft Authenticator for all users ignores Windows Hello for Business for Windows devices (which provides a better integrated experience), and QR codes for kiosk computers are not a supported passwordless authentication method for shared devices (FIDO2 keys are required for kiosk scenarios).

51
Multi-Selectmedium

You are designing a solution to protect Microsoft 365 data from insider threats. Which TWO Microsoft Purview features should you use?

Select 2 answers
A.Microsoft Purview Insider Risk Management
B.Microsoft Purview Data Loss Prevention (DLP)
C.Microsoft Purview Communication Compliance
D.Microsoft Purview Audit (Premium)
E.Microsoft Purview eDiscovery (Premium)
AnswersA, B

Microsoft Purview Insider Risk Management applies machine learning and behavioral analytics to signal anomalies in user activity—such as mass file downloads, unusual external sharing, or data staging—and then scores the risk to enable investigation and response. It is purpose-built to identify exfiltration patterns that indicate malicious or negligent insiders, making it the most directly relevant control for this scenario. Its built-in investigation workflow, templates, and correlation across activity signals provide proactive detection that other tools lack.

Why this answer

Microsoft Purview Insider Risk Management (A) is correct because it is the purpose-built solution for detecting and remediating insider threat activity, using machine learning and behavioral signals (such as mass downloads, exfiltration to personal cloud storage, or unusual file access) to surface risky user activity and trigger investigation workflows. Microsoft Purview Data Loss Prevention (B) is also correct because DLP policies can identify and block sensitive information (for example, credit card numbers, HIPAA data, or custom sensitive info types) from being shared inappropriately across Exchange Online, SharePoint, OneDrive, Teams, and endpoint devices, directly mitigating insider exfiltration scenarios. Communication Compliance (C) is not the right fit here because it focuses on monitoring and reviewing potentially inappropriate or policy-violating communications (harassment, regulatory compliance in chats/email), not on detecting or preventing data exfiltration by insiders.

Audit (Premium) (D) provides long-term retention and high-value forensic events for investigations, but it is a logging/investigation capability rather than a protective control against insider threats. eDiscovery (Premium) (E) is designed for legal hold, identification, collection, and review of content for litigation or investigations, not for proactively protecting data from insider risk.

Exam trap

The trap here is that candidates often confuse Data Loss Prevention (DLP) as the primary insider threat tool, but DLP is a content-aware policy enforcement mechanism that blocks or alerts on data sharing based on rules, whereas Insider Risk Management focuses on behavioral analytics and user risk scoring to detect threats that DLP might miss, such as slow data exfiltration or credential misuse.

52
MCQmedium

Your company uses Microsoft Sentinel as a SIEM. You need to create an analytics rule that detects when a user account is created outside of business hours. The rule should trigger an incident for investigation. Which type of analytics rule should you use?

A.Anomaly rule
B.Fusion rule
C.Scheduled query rule
D.NRT query rule
AnswerC

Scheduled query rules in Microsoft Sentinel are the appropriate choice because they run on a defined cadence (e.g., every 5 minutes or hourly) and execute a KQL query against ingested data. You can set a schedule that matches the desired time window, and the rule will trigger an incident if the query returns results. This allows you to easily implement a condition like 'alert when events occur during a specific time range' by embedding that time filter in the query and scheduling the rule to run accordingly.

Why this answer

A scheduled query rule is the correct choice because it allows you to define a KQL query that checks for user account creation events (e.g., from the SecurityEvent or AuditLogs table) and then use the query scheduling settings to run the query at a specific interval. You can then add a condition in the rule logic to filter for events occurring outside business hours (e.g., using the `datetime_part` function to check the hour of the event). When the query returns results, Sentinel automatically generates an incident for investigation.

Exam trap

The trap here is that candidates often confuse scheduled query rules with NRT query rules, assuming that 'near-real-time' is always better for time-sensitive detections. While NRT rules run every minute, they have significant limitations, including a fixed 1-minute lookback, limited KQL support, and no custom scheduling. For a detection based on the hour of an event, a scheduled query rule is the appropriate and recommended choice because it allows full KQL and configurable scheduling to reliably detect all relevant events, not just those in the most recent minute.

How to eliminate wrong answers

Option A is wrong because anomaly rules use machine learning to detect unusual patterns over time without a predefined query, and they cannot be configured with a specific KQL query to filter for account creation outside business hours. Option B is wrong because Fusion rules correlate alerts from multiple products to detect multistage attacks, and they do not allow you to define a custom query for a single event type like user account creation. Option D is wrong because NRT (near-real-time) query rules run queries every minute with a 1-minute lookback, which is not suitable for checking events against a static time window like 'outside business hours' and does not support the same flexible scheduling and incident creation logic as scheduled query rules.

53
MCQmedium

A security architect needs to design a solution that provides a unified view of security alerts from multiple clouds (Azure, AWS, GCP) and on-premises systems. The solution must also support automated response using playbooks. Which Microsoft service should they use?

A.Microsoft Defender XDR
B.Microsoft Defender for Cloud
C.Microsoft Purview
D.Microsoft Sentinel
AnswerD

Microsoft Sentinel is a cloud-native SIEM and SOAR that natively ingests data from Azure and, via built-in connectors, from AWS, Google Cloud, other SaaS platforms, and on-premises sources such as syslog and CEF, allowing centralized multi-cloud log collection. Its analytical rules use Kusto Query Language to detect suspicious activity and trigger automated response playbooks built on Azure Logic Apps, providing real-time containment like device isolation or account disablement. Sentinel's architecture includes Common Event Format (CEF) and Syslog agents for on-premises, plus API connectors for AWS CloudTrail and GCP, making it the only option that fulfills the full multi-cloud SIEM/SOAR requirement with integrated UEBA and threat intelligence.

Why this answer

Microsoft Sentinel is the correct choice because it is a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution that ingests security alerts from multiple clouds (Azure, AWS, GCP) and on-premises systems via connectors. It supports automated response through playbooks built on Azure Logic Apps, enabling unified alert management and remediation workflows.

Exam trap

The trap here is confusing Microsoft Defender for Cloud (a CSPM tool) with Microsoft Sentinel (a SIEM/SOAR), as both appear in the Azure portal and deal with security alerts, but only Sentinel provides native multi-cloud SIEM ingestion and automated playbook orchestration for cross-cloud incident response.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender XDR is an extended detection and response solution focused on correlating signals across Microsoft 365, endpoints, and identities, but it does not natively ingest alerts from AWS, GCP, or on-premises systems for a unified multi-cloud SIEM view. Option B is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform that provides security recommendations and alerts primarily for Azure and hybrid environments, but it lacks the native multi-cloud SIEM ingestion and SOAR playbook automation of Sentinel. Option C is wrong because Microsoft Purview is a data governance, risk, and compliance solution (e.g., data classification, eDiscovery, insider risk management) and does not provide SIEM alert correlation or automated response playbooks for security incidents.

54
MCQmedium

Your organization uses Microsoft Defender XDR for incident response. You need to design a process to automatically isolate a compromised device when a high-severity incident is triggered. Which automation approach should you use?

A.Create a compliance policy in Microsoft Intune that marks the device as noncompliant
B.Configure an Azure Automation runbook to poll Defender alerts and isolate devices
C.Set up a Power Automate flow triggered by email notifications from Defender
D.Use automation rules in Microsoft Sentinel with a playbook that runs a Defender for Endpoint isolation action
AnswerD

Microsoft Sentinel automation rules are event-driven: when an incident matches criteria (e.g., a high-severity malware incident on a specific device), the rule triggers a playbook built on Logic Apps. That playbook uses the Microsoft Defender for Endpoint connector to run the 'Isolate machine' action, which calls the Defender for Endpoint API to sever the device's network connectivity while maintaining communication with the management plane. This is a native, first-party integration that responds immediately and can be extended with manual approval steps or additional enrichment actions.

Why this answer

Microsoft Sentinel's automation rules can directly trigger a playbook (Azure Logic App) that executes the Microsoft Defender for Endpoint 'Isolate device' action. This provides near-real-time, event-driven isolation without polling, aligning with the requirement to automatically isolate a compromised device when a high-severity incident is triggered in Defender XDR.

Exam trap

The trap here is that candidates confuse 'marking a device as noncompliant' (Option A) with actual network isolation, or assume that any automation (Options B and C) is sufficient, overlooking the requirement for event-driven, low-latency integration with Defender for Endpoint's native isolation capability.

How to eliminate wrong answers

Option A is wrong because a compliance policy in Microsoft Intune marks a device as noncompliant but does not perform device isolation; it can trigger conditional access or wipe actions, not the network-level isolation needed for incident response. Option B is wrong because polling Defender alerts via an Azure Automation runbook introduces latency and inefficiency, and it bypasses the native event-driven automation capabilities of Microsoft Sentinel and Defender XDR. Option C is wrong because email notifications are unreliable and introduce delay; Power Automate flows triggered by email cannot guarantee timely, automated isolation and lack direct integration with Defender for Endpoint's isolation API.

55
MCQmedium

Refer to the exhibit. You are analyzing a KQL query in Microsoft Sentinel that detects machines with more than two malware alerts in a day. The query returns no results even though you know there are machines with multiple malware alerts. What is the most likely reason?

A.The 'summarize' function is incorrectly used and creates duplicate counts.
B.The query filters out alerts with severity less than 'High'.
C.The query does not include a time range filter, so it returns data from all time.
D.The alert name in the environment is not exactly 'Malware detected'; it might include a suffix like 'on endpoint'.
AnswerD

The query uses an exact string match such as `where AlertName == 'Malware detected'`, which only matches alerts with precisely that entire name. In Microsoft Defender for Endpoint and Sentinel, alert names often include contextual suffixes like 'on endpoint' or platform-specific details, so this exact match is too restrictive and misses legitimate alerts. Using a broader operator like `contains` or `endswith` would capture those variations.

Why this answer

The KQL query likely uses a hardcoded string 'Malware detected' in a where clause to filter alerts. If the actual alert names in the environment include a suffix like 'on endpoint' (e.g., 'Malware detected on endpoint'), the exact string match fails, causing the query to return no results. This is a common issue when alert naming conventions vary across Microsoft Defender for Endpoint or other data sources ingested into Sentinel.

Exam trap

The trap here is that candidates assume the query logic is correct and focus on aggregation or time range issues, overlooking the exact string match requirement in KQL, which is a frequent cause of false negatives in detection queries.

How to eliminate wrong answers

Option A is wrong because the 'summarize' function, when used with 'dcount' or 'count', does not create duplicate counts; it aggregates correctly. If duplicates existed, the query would return results, not zero. Option B is wrong because the query does not filter on severity; the question states it detects 'more than two malware alerts in a day' without any severity filter, so excluding high severity would not cause zero results if lower severity alerts exist.

Option C is wrong because omitting a time range filter would cause the query to return data from all time, which would likely return more results, not zero; the issue is the opposite—no results despite known alerts.

56
MCQhard

Your organization uses Microsoft Purview Information Protection to classify and protect sensitive data. The compliance team wants to automatically apply a 'Highly Confidential' sensitivity label to emails that contain credit card numbers. Which solution should you configure?

A.Microsoft Purview auto-labeling policy
B.Microsoft Defender for Office 365 Safe Attachments policy
C.Microsoft 365 Data Loss Prevention (DLP) policy
D.Microsoft Endpoint DLP
AnswerA

Microsoft Purview auto-labeling is the correct mechanism because it can evaluate email content and context (e.g., sensitive info types like credit card numbers, or trainable classifiers) and automatically assign sensitivity labels to messages. Policies run in simulation mode or enforce automatically, and label actions like encryption can then be applied based on the label. This directly addresses the requirement to apply an information protection label to emails.

Why this answer

The correct option is A, Microsoft Purview auto-labeling policy, because auto-labeling policies are the native Purview Information Protection mechanism that scans content for sensitive information types (such as credit card numbers) and automatically applies a specified sensitivity label like 'Highly Confidential' to emails and files. This directly matches the requirement to classify and protect data at the label level, since sensitivity labels can also enforce encryption and other protection settings. Option B, Safe Attachments, is a Defender for Office 365 threat-detection feature that sandboxes attachments and does not apply sensitivity labels.

Option C, a DLP policy, can detect credit card numbers and block or warn on sharing, but it enforces DLP rules rather than automatically applying a sensitivity label. Option D, Microsoft Endpoint DLP, extends DLP controls to endpoint devices and likewise does not apply sensitivity labels to email.

57
MCQhard

Refer to the exhibit. You are analyzing a KQL query in Microsoft Sentinel. What is the purpose of this query?

A.Correlate malware alerts with device OS version
B.List all malware alerts in the last 7 days
C.Identify malware alerts on unmanaged devices
D.Show device inventory for unmanaged devices
AnswerC

The query joins SecurityAlert with DeviceInfo, filtering where ManagedDevice equals false and alert severity is High, which surfaces malware detections on unmanaged endpoints. This satisfies the stem's requirement to identify malware alerts on unmanaged devices, since the join correlates alert context with device management state rather than merely listing alerts.

Why this answer

The query uses the `DeviceInfo` table to filter for devices where `IsManaged` is `false`, then joins with `SecurityAlert` to find alerts where `AlertName` contains 'Malware'. This specifically identifies malware alerts generated on unmanaged devices, not all malware alerts or a general device inventory.

Exam trap

The trap here is that candidates may confuse the purpose of the query as simply listing all malware alerts (Option B) or showing device inventory (Option D), overlooking the critical `IsManaged == false` filter that narrows the scope to unmanaged devices.

How to eliminate wrong answers

Option A is wrong because the query does not correlate malware alerts with device OS version; it only filters on `IsManaged` and `AlertName`, with no reference to OS version fields. Option B is wrong because the query does not list all malware alerts in the last 7 days; it restricts results to alerts on unmanaged devices (IsManaged == false) and does not include a time filter for the last 7 days. Option D is wrong because the query returns alerts, not a device inventory; the output includes alert details (e.g., AlertName, TimeGenerated) rather than a list of devices.

58
MCQhard

Refer to the exhibit. You are an Azure security engineer reviewing a custom Azure Policy definition. The policy is intended to audit virtual machines to ensure they have the Azure Security extension installed. However, the policy is not triggering on any resources. What is the most likely reason?

A.The policy condition requires a managed disk, but the VMs might have unmanaged disks.
B.The 'existenceCondition' field path is incorrect; it should be 'Microsoft.Compute/virtualMachines/extensions/publisher'.
C.The policy is assigned to a management group, but the VMs are in a subscription under a different management group.
D.The policy effect should be 'Deny' instead of 'auditIfNotExists'.
AnswerA

The policy definition's 'if' clause matches only VMs that have a managed disk (e.g., by checking that the 'managedDisk' property is present). VMs that still use unmanaged disks do not satisfy this condition, so the 'auditIfNotExists' effect is never evaluated for them. Consequently, the policy silently ignores the very machines that likely need the missing-extension audit, making the compliance report incomplete rather than identifying all noncompliant VMs.

Why this answer

The policy condition uses `field` to check for `Microsoft.Compute/virtualMachines/storageProfile.osDisk.managedDisk.id`, which requires the VM to have a managed disk. If the VMs use unmanaged disks (i.e., the `managedDisk` property is absent), the condition evaluates to false, and the `auditIfNotExists` effect never triggers the existence check for the Azure Security extension.

Exam trap

The trap here is that candidates focus on the `existenceCondition` or effect syntax, overlooking that the parent `field` condition silently fails on VMs without managed disks, preventing the entire policy from evaluating.

How to eliminate wrong answers

Option B is wrong because the `existenceCondition` field path `Microsoft.Compute/virtualMachines/extensions/publisher` is syntactically valid for checking the extension's publisher property; the issue is not with the path but with the parent condition failing. Option C is wrong because policy assignment inheritance works correctly across management group hierarchies—if the policy is assigned to a management group, it applies to all descendant subscriptions, so VMs in a child subscription would still be evaluated. Option D is wrong because changing the effect to `Deny` would not fix the triggering issue; the policy is not evaluating resources at all due to the condition, not because of the effect type.

59
MCQmedium

Your company is implementing Microsoft Purview Information Protection to protect sensitive data. The compliance team requires that when a user applies a 'Highly Confidential' sensitivity label to a document, the document is automatically encrypted and watermarked. Which configuration should you use?

A.Create a DLP policy that encrypts and watermarks the document when it is shared externally
B.Create an auto-labeling policy that detects sensitive content and applies the label automatically
C.Create a Conditional Access policy that requires the label to be applied to all documents
D.Configure the sensitivity label to apply encryption and dynamic watermarking. Publish the label to users.
AnswerD

A sensitivity label is the correct mechanism because encryption and dynamic watermarking are configured as part of the label's protection settings, and publishing the label makes it available in the Office apps' Sensitivity button. When the user manually applies this label, the label enforces the configured encryption rights and dynamically inserts the user's identity (or other custom text) as a watermark, satisfying the 'user-applied' and 'dynamic watermarking' requirements precisely.

Why this answer

The correct option is D: configure the sensitivity label itself to apply encryption and dynamic watermarking, then publish the label to users. In Microsoft Purview Information Protection, encryption and content marking (including watermarks) are protection settings defined on the sensitivity label, so when a user manually applies the 'Highly Confidential' label, those protections are enforced automatically. Publishing the label via a label policy makes it available in Office apps so users can apply it.

Option A is wrong because DLP policies act on sharing/transmission conditions rather than applying label-based encryption and watermarks at label time. Option B is wrong because auto-labeling applies labels based on content detection, not when a user manually selects a label. Option C is wrong because Conditional Access governs access to cloud resources, not document encryption or watermarking.

60
MCQhard

You are a security architect for a large financial services company. The company has a hybrid identity environment with on-premises Active Directory synchronized to Microsoft Entra ID using Microsoft Entra Connect. They use Microsoft 365 E5 licenses and have deployed Microsoft Defender for Cloud, Microsoft Defender for Identity, Microsoft Sentinel, and Microsoft Purview. The company has recently suffered a ransomware attack where an attacker gained access via a compromised service account that had permanent Global Administrator privileges. The attacker then used the account to create a backdoor user and exfiltrate sensitive data from SharePoint Online. After the incident, the CISO mandates a Zero Trust security transformation with the following requirements: 1. Eliminate standing privileged access for all cloud admins. 2. Require phishing-resistant authentication for all privileged roles. 3. Ensure that all sensitive data in SharePoint Online is automatically classified and protected. 4. Enable detection of lateral movement using anomalous behavior analytics. Which combination of actions should you recommend?

A.Implement Privileged Identity Management (PIM) for Global Administrator roles, configure Authentication Strengths to require FIDO2, create auto-labeling policies for credit card numbers, and enable Defender for Identity lateral movement path detection.
B.Deploy Microsoft Entra Identity Protection for all users, configure Azure AD Conditional Access with MFA, use Microsoft Purview Information Protection with manual labeling, and enable Microsoft Sentinel analytics for lateral movement.
C.Configure Conditional Access to require MFA for admins, enable Microsoft Purview DLP for SharePoint, deploy Defender for Cloud Apps, and use Identity Protection for user risk.
D.Remove all permanent admin roles and use just-in-time access via PIM, enforce MFA via Conditional Access, apply sensitivity labels via Microsoft Purview Data Map, and use Microsoft Defender for Cloud for network security groups.
AnswerA

Privileged Identity Management removes standing Global Administrator access and activates roles just-in-time with approval, time limits, and audit trail, meeting the privileged access requirement. Configuring Authentication Strengths to require FIDO2 enforces phishing-resistant MFA specifically for activation and sign-in, satisfying the hardened MFA mandate. Auto-labeling policies for credit card numbers apply sensitivity labels automatically based on sensitive info types, ensuring data protection without manual effort. Defender for Identity lateral movement path detection analyzes entity activities to expose vulnerable paths attackers could exploit, fulfilling the lateral movement detection requirement.

Why this answer

It directly addresses all four CISO requirements: Privileged Identity Management (PIM) eliminates standing Global Administrator privileges by requiring just-in-time activation; Authentication Strengths with FIDO2 enforces phishing-resistant authentication for privileged roles; auto-labeling policies in Microsoft Purview automatically classify and protect sensitive data like credit card numbers in SharePoint Online; and Defender for Identity lateral movement path detection uses behavioral analytics to detect anomalous lateral movement, fulfilling the detection requirement.

Exam trap

The trap here is that candidates often confuse MFA (which can be phishable) with phishing-resistant authentication (e.g., FIDO2 or certificate-based), and they may overlook that automatic classification requires auto-labeling policies, not manual labeling or data discovery tools like Data Map.

How to eliminate wrong answers

Option B is wrong because it relies on manual labeling instead of automatic classification, which fails to meet the requirement for automatic protection of sensitive data in SharePoint Online; additionally, Identity Protection does not provide lateral movement detection. Option C is wrong because it only enforces MFA via Conditional Access, which is not phishing-resistant (e.g., it allows TOTP or phone call verification), and it lacks automatic data classification and lateral movement detection. Option D is wrong because it enforces MFA via Conditional Access instead of phishing-resistant authentication (e.g., FIDO2), and it uses Microsoft Defender for Cloud for network security groups, which does not address lateral movement detection; Purview Data Map is for data discovery, not automatic classification and protection.

61
MCQmedium

A company uses Microsoft Entra ID for identity management. They want to ensure that only managed devices can access corporate email. Which Conditional Access policy setting should be configured?

A.Require multifactor authentication
B.Block legacy authentication
C.Require approved client app
D.Require device to be marked as compliant
AnswerD

Requiring the device to be marked as compliant enforces that only managed, policy-conformant devices reach corporate email. Conditional Access evaluates device compliance state from Microsoft Entra ID, satisfying the constraint that unmanaged devices be blocked from Exchange Online.

Why this answer

To ensure only managed devices can access corporate email, you need to enforce device compliance. The Conditional Access policy setting 'Require device to be marked as compliant' checks that the device is enrolled in Microsoft Intune and meets all compliance policies (e.g., encryption, OS version, jailbreak detection) before granting access. This directly restricts access to managed devices only.

Exam trap

The trap here is that candidates often confuse 'Require device to be marked as compliant' with 'Require approved client app' or 'Require multifactor authentication,' thinking that MFA or app approval alone ensures device management, but only compliance enforcement ties directly to Intune-managed device policies.

How to eliminate wrong answers

Option A is wrong because requiring multifactor authentication (MFA) verifies the user's identity but does not enforce any device management or compliance; a personal device with MFA could still access email. Option B is wrong because blocking legacy authentication prevents protocols like POP3, IMAP, or SMTP that don't support modern authentication, but it does not ensure the device is managed or compliant; a managed device using legacy auth would still be blocked, but an unmanaged device using modern auth would not be blocked. Option C is wrong because requiring an approved client app (e.g., Outlook mobile) ensures the app is from a trusted source but does not enforce device management; an unmanaged device with the approved app could still access email.

62
Multi-Selecthard

Which THREE of the following are valid ways to protect sensitive data in Microsoft 365 using Microsoft Purview? (Choose three.)

Select 3 answers
A.Sensitivity labels
B.Data Loss Prevention (DLP) policies
C.Data Lifecycle Management (retention policies)
D.Conditional Access policies
E.Microsoft Defender for Endpoint
AnswersA, B, C

Sensitivity labels are a data-centric protection mechanism in Microsoft Purview that classify documents and emails, then apply persistent protections such as encryption, rights management restrictions, and visual markings. These labels travel with the data (e.g., when shared externally), ensuring that protection remains enforced regardless of location or device, and they can be applied automatically based on classification rules, user recommendations, or admin-defined policies.

Why this answer

Sensitivity labels (A) are a core Microsoft Purview capability that let you classify and encrypt content with protection settings (e.g., encryption, content marking, and access restrictions) that travel with the data across Microsoft 365 workloads. Data Loss Prevention policies (B) in Microsoft Purview detect and block risky sharing of sensitive information (e.g., credit card or PII patterns) in Exchange Online, SharePoint, OneDrive, Teams, and endpoint locations, directly protecting data from exfiltration. Data Lifecycle Management retention policies (C) are also part of Microsoft Purview and protect sensitive data by retaining it for required periods and deleting it when no longer needed, reducing exposure and supporting compliance obligations.

Conditional Access (D) is a Microsoft Entra ID feature that governs sign-in and access conditions, not a Purview data-protection control, and Defender for Endpoint (E) is an endpoint security product rather than a Microsoft Purview data protection mechanism.

Exam trap

The trap here is that candidates often confuse Conditional Access policies (which control access) or Defender for Endpoint (which protects endpoints) with Purview's data protection capabilities, but neither directly classifies, encrypts, or prevents data loss at the content level.

63
MCQmedium

A company is migrating its on-premises Active Directory to Microsoft Entra ID. They need to ensure that all user authentication for cloud apps uses passwordless methods. Which security best practice should they implement?

A.Implement Microsoft Entra ID passwordless authentication
B.Configure conditional access policies to block legacy authentication
C.Enable Microsoft Entra ID Privileged Identity Management (PIM)
D.Require multifactor authentication (MFA) for all users
AnswerA

Implementing Microsoft Entra ID passwordless authentication replaces the password with a cryptographic key pair bound to the user's device or a FIDO2 security key. Methods such as Windows Hello for Business, FIDO2 security keys, or the Microsoft Authenticator app's passwordless mode allow authentication through a biometric gesture or PIN, with the private key never leaving the device. This directly eliminates the shared-secret model that attackers can phish or replay, and it aligns with Zero Trust by verifying possession and intent without ever transmitting a password over the network.

Why this answer

The company's requirement is specifically to ensure all user authentication for cloud apps uses passwordless methods. Microsoft Entra ID passwordless authentication (e.g., Windows Hello for Business, FIDO2 security keys, or Microsoft Authenticator) directly eliminates passwords from the authentication flow, aligning with the stated goal. Other options, while enhancing security, do not enforce passwordless authentication.

Exam trap

The trap here is that candidates often confuse 'blocking legacy authentication' or 'requiring MFA' with achieving passwordless authentication, but neither eliminates the password as a factor; only a dedicated passwordless method does.

How to eliminate wrong answers

Option B is wrong because blocking legacy authentication (e.g., POP3, IMAP, SMTP) prevents older protocols that cannot enforce modern authentication, but it does not mandate passwordless methods; users could still authenticate with passwords via modern protocols. Option C is wrong because Microsoft Entra ID Privileged Identity Management (PIM) provides just-in-time privileged access management and does not address user authentication methods for cloud apps. Option D is wrong because requiring multifactor authentication (MFA) adds a second factor but still allows password-based authentication as the first factor, failing to meet the passwordless requirement.

64
MCQmedium

Refer to the exhibit. You are reviewing a Conditional Access policy JSON. What is the effect of this policy?

A.Blocks sign-ins from locations with high sign-in risk
B.Blocks sign-ins from users with high user risk
C.Blocks all sign-ins from any user
D.Requires multifactor authentication for high-risk users
AnswerB

This is the correct interpretation: the policy sets the 'User risk' condition to 'High' and the access control to 'Block.' When a user's risk level, as determined by Microsoft Entra ID Protection detections, is high, the conditional access engine denies the sign-in attempt. Thus, the policy's effective behavior is to block sign-ins from users with high user risk.

Why this answer

The policy JSON specifies `"userRiskLevels": ["high"]` under the conditions block, which means it targets only users whose user risk level is assessed as high by Microsoft Entra ID Protection. The grant control is set to `"builtInControls": ["block"]`, so the policy blocks sign-ins for those high-risk users. Option B is correct because the policy explicitly blocks sign-ins from users with high user risk, not sign-in risk or all users.

Exam trap

Microsoft often tests the distinction between `userRiskLevels` and `signInRiskLevels` in Conditional Access policies, and candidates frequently confuse the two, thinking a high user risk policy blocks sign-in risk events rather than user account risk.

How to eliminate wrong answers

Option A is wrong because the policy uses `userRiskLevels`, not `signInRiskLevels`; sign-in risk levels are a separate property in Conditional Access policies that assess the risk of a specific authentication attempt, not the user account. Option C is wrong because the policy has a condition targeting only high user risk levels, not all users; a block-all policy would omit the risk level condition or use an empty conditions block. Option D is wrong because the grant control is `"block"`, not `"mfa"`; requiring multifactor authentication would use `"mfa"` in the builtInControls array, and the policy does not include any authentication requirement.

65
MCQmedium

A company uses Microsoft Entra ID and wants to enable passwordless authentication for all users to reduce phishing risks. Users are already using Microsoft Authenticator for MFA. Which passwordless method should you prioritize?

A.Windows Hello for Business
B.FIDO2 security keys
C.Certificate-based authentication
D.Microsoft Authenticator passwordless sign-in
AnswerD

Microsoft Authenticator passwordless sign-in is the correct answer because it leverages the same mobile app already widely used for multi-factor authentication, requiring no extra hardware or PKI. The user simply enters their username and then approves a push notification on their phone, sometimes matching a number, while the phone's biometric or PIN validates the physical presence. This provides a phishing-resistant, strong authentication experience that works across Android and iOS, and because it reuses an existing app, user adoption is high and deployment is straightforward.

Why this answer

The organization already uses Microsoft Authenticator for MFA, making the transition to passwordless sign-in via Authenticator the most seamless and cost-effective path. This method leverages the existing app registration and push notification infrastructure, allowing users to authenticate with a biometric or PIN gesture without deploying additional hardware or certificates.

Exam trap

The trap here is that candidates may choose Windows Hello for Business (A) because it is a common passwordless option, but they overlook the requirement that it only works on Windows devices, not for all users across platforms.

How to eliminate wrong answers

Option A is wrong because Windows Hello for Business requires Windows devices and is not universally applicable to all users (e.g., mobile or non-Windows users). Option B is wrong because FIDO2 security keys require purchasing and distributing physical hardware, which adds cost and logistical overhead not justified when Authenticator is already deployed. Option C is wrong because certificate-based authentication requires a public key infrastructure (PKI) and certificate enrollment, which is more complex to deploy and manage than leveraging the existing Authenticator app.

66
MCQeasy

Your company uses Microsoft Sentinel for security information and event management (SIEM). You need to design a solution that reduces alert fatigue by correlating low-fidelity alerts from multiple sources into a single high-fidelity incident. Which Microsoft Sentinel feature should you use?

A.Workbooks
B.Analytics rules with alert grouping enabled
C.Playbooks
D.Hunting queries
AnswerB

Analytics rules with alert grouping enabled are the correct mechanism for correlating alerts because Sentinel's incident creation settings allow you to group multiple alerts into one incident based on matching entities, alert titles, or within a specified time window. This grouping reduces alert fatigue by consolidating related detections into a single case for investigation, and it can be configured as either system alert grouping (group all or by entity) or custom grouping with a predefined window.

Why this answer

Analytics rules with alert grouping enabled allow you to configure a rule that correlates multiple low-fidelity alerts (e.g., from different data sources or detection types) into a single high-fidelity incident. When alert grouping is enabled, the rule groups alerts that occur within a specified time window and share common entities (such as IP addresses or user accounts), reducing alert fatigue by presenting one consolidated incident instead of many individual alerts.

Exam trap

The trap here is that candidates often confuse 'alert grouping' with 'playbook automation' or 'workbook visualization', thinking that any tool that reduces noise must involve automation or dashboards, rather than understanding that the correlation logic is built directly into the analytics rule configuration.

How to eliminate wrong answers

Option A is wrong because Workbooks are visualization tools that display data from queries and logs; they do not perform correlation or grouping of alerts into incidents. Option C is wrong because Playbooks are automated response workflows (based on Azure Logic Apps) that trigger on incidents or alerts but do not correlate or group alerts into a single incident. Option D is wrong because Hunting queries are ad-hoc, interactive searches for threats in raw log data; they do not automatically create incidents or group alerts.

67
MCQmedium

Your organization is implementing Microsoft Entra ID Conditional Access. You need to require multi-factor authentication (MFA) for all users accessing financial applications, but only when the sign-in risk is medium or higher. What is the most efficient way to achieve this?

A.Create a Microsoft Entra ID Protection user risk policy to require MFA
B.Enable MFA per user for all users in the financial team
C.Create a Conditional Access policy that targets all users, includes a named location, and requires MFA
D.Create a Conditional Access policy that targets the financial applications, uses sign-in risk as a condition, and requires MFA
AnswerD

A Conditional Access policy can be precisely scoped to the financial applications as the assigned target resources, while using sign-in risk as a condition to trigger MFA. Sign-in risk is calculated in real time by Microsoft Entra ID Protection, and Conditional Access allows it to be set to a threshold such as Low, Medium, or High. When a sign-in to a financial app has a risk level that meets the threshold, MFA is required, directly fulfilling the requirement for risk-based MFA protection on the financial applications without affecting unrelated apps or users.

Why this answer

It uses a single Conditional Access policy to target the specific financial applications and sets the sign-in risk condition to medium or higher, which triggers MFA only when the risk threshold is met. This approach is efficient as it avoids per-user MFA configuration and leverages Microsoft Entra ID Protection's risk detection to dynamically enforce MFA based on real-time sign-in risk, aligning with the principle of adaptive access control.

Exam trap

The trap here is that candidates often confuse user risk policies with sign-in risk conditions, or they default to per-user MFA or location-based policies, missing the precise combination of application scoping and risk-based conditions that the question requires.

How to eliminate wrong answers

Option A is wrong because a user risk policy in Microsoft Entra ID Protection targets user-level risk (e.g., compromised credentials) rather than sign-in risk, and it cannot be scoped to specific applications like financial apps; it would apply MFA based on user risk, not sign-in risk. Option B is wrong because enabling MFA per user forces MFA on every authentication for those users, regardless of sign-in risk level, which violates the requirement to only require MFA when risk is medium or higher and is less efficient than a risk-based policy. Option C is wrong because it includes a named location condition, which is irrelevant to sign-in risk, and targets all users without application scoping, meaning it would apply MFA to all applications for all users, not just financial apps when risk is elevated.

68
MCQmedium

You are designing a security architecture for Litware Inc., which uses Microsoft 365 E5 and Azure. The company wants to adopt a Zero Trust model and needs to ensure that access to corporate resources is granted based on real-time risk assessment. The security team wants to automatically remediate risky user behavior by requiring password changes or blocking access. You need to recommend a solution that integrates with Microsoft Entra ID and provides risk-based conditional access. What should you recommend?

A.Azure AD Conditional Access with named locations
B.Microsoft Cloud App Security (Defender for Cloud Apps) session policies
C.Microsoft Defender for Identity
D.Microsoft Entra ID Protection
AnswerD

Microsoft Entra ID Protection detects risky users and sign-ins using machine learning and heuristics, and it integrates with Conditional Access to enforce risk-based policies. It can automatically require password changes or block access when risk is detected, directly meeting the requirement for real-time risk assessment and automated remediation.

Why this answer

Microsoft Entra ID Protection evaluates sign-in and user risk in real time and integrates with Conditional Access to enforce policies such as requiring MFA or password change for risky users. It can also block access when risk is high, providing the automated remediation and risk-based access required for a Zero Trust architecture.

Exam trap

The trap here is confusing Defender for Identity, which monitors on-premises Active Directory, with Entra ID Protection, which assesses cloud identity risk and drives conditional access policies.

69
MCQhard

Refer to the exhibit. You are reviewing an ARM template snippet for an Azure Storage container. Which security best practice does this configuration enforce?

A.Disables anonymous public access to the container
B.Allows public access from the internet
C.Configures a firewall rule to restrict access to specific IPs
D.Enables encryption at rest for the container
AnswerA

In an ARM template for Azure Storage, the `publicAccess` property of a container is set to 'None', which explicitly blocks any anonymous read requests to the blob data within that container. This configuration ensures that clients must present valid authentication credentials—such as an account key, a shared access signature (SAS), or an Azure AD identity—to access the container's contents. Setting `publicAccess` to 'None' is a critical security control that prevents unauthorized exposure of stored data.

Why this answer

The ARM template snippet sets the `publicAccess` property of the container to `None`. This explicitly disables anonymous public access to the container, enforcing the security best practice of preventing unauthenticated access to Azure Storage data. By default, Azure Storage containers allow anonymous read access if enabled at the account level, but this configuration overrides that to block any public requests.

Exam trap

The trap here is that candidates may confuse the container-level `publicAccess` property with storage account-level firewall rules or encryption settings, leading them to select options that describe unrelated security features.

How to eliminate wrong answers

Option B is wrong because allowing public access from the internet is the opposite of the security best practice; the snippet disables public access, not enables it. Option C is wrong because the snippet does not include any `networkAcls` or `ipRules` properties; firewall rules are configured at the storage account level, not within a container resource definition. Option D is wrong because encryption at rest is enabled by default for Azure Storage and is not controlled by the `publicAccess` property; the snippet does not reference any encryption settings.

70
MCQmedium

Your organization uses Microsoft Sentinel to centralize security logs from multiple clouds. They need to ensure that logs from Amazon Web Services (AWS) are ingested and analyzed for threats. Which connector should you implement?

A.Microsoft Defender for Cloud
B.Azure Monitor Agent
C.AWS S3 connector
D.Azure Event Hubs
AnswerC

The AWS S3 connector is the correct native Microsoft Sentinel data connector for ingesting AWS CloudTrail logs. It connects to a configured S3 bucket that receives CloudTrail events and optionally uses SQS for near-real-time notifications, then normalizes the JSON records into the AWSCloudTrail table in Log Analytics. This is the standard architectural pattern for centralizing AWS activity monitoring in Sentinel, and it directly satisfies the organization's requirement.

Why this answer

The AWS S3 connector is the correct choice because it is the native Microsoft Sentinel data connector designed specifically to ingest AWS CloudTrail logs (and other AWS service logs) from an S3 bucket. It uses an AWS Simple Queue Service (SQS) to poll for new log files, then streams them into Sentinel for analysis, enabling threat detection across multi-cloud environments.

Exam trap

The trap here is that candidates may confuse Microsoft Defender for Cloud (a security posture tool) with a log ingestion connector, or assume Azure Event Hubs is the default streaming solution for all external logs, overlooking the purpose-built AWS S3 connector that handles the specific S3-to-Sentinel pipeline.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection tool, not a log ingestion connector for AWS; it does not directly pull raw logs from S3 into Sentinel. Option B is wrong because Azure Monitor Agent (AMA) is designed to collect telemetry from Azure VMs and on-premises machines via Data Collection Rules, not from external cloud storage like AWS S3. Option D is wrong because Azure Event Hubs is a data streaming platform that can receive logs from external sources, but it is not a pre-built Sentinel connector for AWS; using it would require custom configuration and additional components to replicate the S3 connector's functionality.

71
MCQhard

Contoso is a financial services company migrating critical workloads to Azure. They must comply with PCI DSS and have a Security Operations Center (SOC) team that uses Microsoft Sentinel. The CISO wants to ensure that the security posture aligns with Microsoft's cybersecurity reference architecture (MCRA). You need to design a solution that includes the following requirements: 1) All Azure subscriptions must be managed under a single management group hierarchy with consistent policies. 2) The SOC must have a centralized view of security alerts across all resources, including on-premises servers and multi-cloud environments. 3) Privileged access to Azure resources must be protected using just-in-time (JIT) access and Privileged Identity Management (PIM). 4) Compliance with PCI DSS must be continuously monitored and reported. 5) The solution must minimize operational overhead. What should you include in the design?

A.Create separate management groups per business unit. Enable Microsoft Defender for Cloud on each subscription individually. Use Azure Policy to assign PCI DSS policies per subscription. Configure PIM at the tenant root management group. Use a third-party SIEM to aggregate alerts.
B.Deploy a single management group containing all subscriptions. Enable Microsoft Defender for Cloud with the 'PCI DSS v3.2.1' regulatory compliance dashboard on the management group. Configure Azure Policy to enforce security standards. Enable PIM and configure JIT VM access. Use Microsoft Sentinel as the SIEM, connecting it to Defender for Cloud and on-premises security sources.
C.Deploy a management group hierarchy with policies inherited. Use Microsoft Defender for Cloud's secure score to monitor compliance manually. Implement PIM without JIT. Use Microsoft Sentinel but only for cloud workloads.
D.Use a single management group with Azure Policy to enforce PCI DSS controls. Rely on Azure Monitor for security alerts. Do not enable Defender for Cloud to reduce costs. Use PIM for privileged roles. Connect on-premises logs to a Log Analytics workspace for the SOC.
AnswerB

This design centralizes subscription management under a single management group, allowing Azure Policy and Defender for Cloud regulatory compliance dashboards to span the entire environment consistently. The PCI DSS v3.2.1 dashboard continuously assesses all resources, PIM combined with JIT VM access reduces standing privilege and exposed attack surface, and Microsoft Sentinel ingests both cloud and on-premises security data for a unified SOC. It provides an integrated, continuous compliance monitoring and threat detection solution that scales across the organization.

Why this answer

Option B is correct because it directly satisfies all five requirements with minimal operational overhead: a single management group with inherited Azure Policy enforces consistent PCI DSS controls across all subscriptions, and enabling Microsoft Defender for Cloud's 'PCI DSS v3.2.1' regulatory compliance dashboard on the management group provides continuous compliance monitoring and reporting. Microsoft Sentinel, connected to Defender for Cloud and on-premises security sources, gives the SOC a centralized SIEM view spanning Azure, on-premises, and multi-cloud, while PIM with JIT VM access secures privileged access as required. Option A fails because it fragments governance into separate management groups per business unit, uses a third-party SIEM instead of the existing Microsoft Sentinel, and applies Defender for Cloud per subscription, increasing overhead.

Option C is wrong because it omits JIT access, limits Sentinel to cloud workloads only, and relies on manual secure score review rather than continuous PCI DSS reporting. Option D is incorrect because it disables Defender for Cloud (losing regulatory compliance monitoring) and uses Azure Monitor rather than Sentinel for SOC alerting.

72
MCQmedium

Your organization is planning to deploy Microsoft Purview Information Protection to classify and protect sensitive data. You need to design a solution that automatically applies sensitivity labels to documents containing personally identifiable information (PII) when they are uploaded to SharePoint Online. Which configuration should you use?

A.Set a default sensitivity label for the SharePoint site
B.Use trainable classifiers to identify PII and apply labels
C.Create an auto-labeling policy that uses a sensitive info type for PII
D.Configure a manual labeling policy that prompts users to classify documents
AnswerC

Creating an auto-labeling policy in the Microsoft Purview compliance portal lets you define a rule that scans SharePoint sites, OneDrive accounts, and Exchange for content containing sensitive info types (SITs) for PII, such as U.S. SSN, EU debit card number, or U.S. individual taxpayer identification number. When a match is found, the policy automatically applies the configured sensitivity label and can optionally enforce encryption or a visual marking. This is a rule-based, deterministic detection that works immediately on existing and new content, without user intervention, and is the intended mechanism for automatically classifying PII.

Why this answer

Microsoft Purview auto-labeling policies can automatically apply sensitivity labels to documents containing PII when they are uploaded to SharePoint Online. By configuring a policy with a sensitive info type (e.g., U.S. Social Security Number) as the condition, the service scans content at rest and applies the label without user intervention, meeting the requirement for automatic classification.

Exam trap

The trap here is confusing trainable classifiers with sensitive info types; candidates often pick trainable classifiers because they sound like a smart AI solution, but they are designed for broader content categories, not specific PII patterns like SSNs or credit card numbers.

How to eliminate wrong answers

Option A is wrong because setting a default sensitivity label for a SharePoint site applies a label to all new documents in that site, but it does not automatically detect and label only those containing PII; it labels everything regardless of content. Option B is wrong because trainable classifiers are used for pattern-based content categorization (e.g., contracts or resumes) and are not designed to identify specific PII data types like credit card numbers or SSNs; sensitive info types are the correct mechanism for PII detection. Option D is wrong because a manual labeling policy requires users to classify documents themselves, which does not meet the requirement for automatic labeling upon upload.

73
MCQeasy

Your organization is migrating to Microsoft 365 and wants to implement a defense-in-depth strategy for email security. Which combination of Microsoft services should you use?

A.Microsoft Defender for Office 365 and Exchange Online Protection
B.Microsoft Purview Compliance Manager and Microsoft Defender for Cloud Apps
C.Microsoft Intune and Microsoft Entra ID
D.Microsoft Sentinel and Microsoft Defender for Identity
AnswerA

Exchange Online Protection (EOP) provides the always-on baseline filtering for all Exchange Online mailboxes, including spam, bulk mail, malware, and spoof intelligence before a message reaches the user. Microsoft Defender for Office 365 (MDO) layers on top with Safe Attachments, Safe Links, and advanced anti-phishing policy that checks URLs and attachments in real time, plus impersonation and domain-based protection. Together they form the native email security stack, with EOP as the foundation and MDO handling zero-day or social-engineering threats that basic filters miss.

Why this answer

Defense-in-depth for email security requires layered protection at the transport, filtering, and post-delivery stages. Exchange Online Protection (EOP) provides baseline anti-malware, anti-spam, and transport rules, while Microsoft Defender for Office 365 adds advanced threat protection like Safe Attachments, Safe Links, and anti-phishing policies that inspect URLs and attachments in real time. Together, they cover the full email threat chain from ingress to user interaction.

Exam trap

The trap here is that candidates confuse compliance or identity services with email security layers, forgetting that defense-in-depth for email specifically requires both transport-level (EOP) and post-delivery (Defender for Office 365) protections.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview Compliance Manager focuses on compliance posture and risk assessments, not on email security filtering or threat detection. Option C is wrong because Microsoft Intune manages device compliance and application policies, and Microsoft Entra ID handles identity and access management; neither provides email transport or content inspection. Option D is wrong because Microsoft Sentinel is a SIEM for centralized security analytics and Microsoft Defender for Identity detects on-premises Active Directory attacks; they do not directly protect email transport or attachments.

74
MCQeasy

Your organization wants to implement a security baseline for Azure resources using built-in policies. Which Azure service should you use to assign policies that enforce compliance with security best practices?

A.Azure Blueprints
B.Microsoft Defender for Cloud
C.Azure Policy
D.Azure Role-Based Access Control (RBAC)
AnswerC

Azure Policy is the correct service for implementing a security baseline because it creates, assigns, and manages rules that audit, deny, or remediate resource properties. It includes built-in policy definitions for the Azure Security Benchmark and other regulatory standards, enabling consistent enforcement across all resources. Policies can be applied to resource groups, subscriptions, and management groups, ensuring that new and existing resources continuously meet security requirements like encryption, network restrictions, and version compliance.

Why this answer

Azure Policy is the correct service because it allows you to create, assign, and manage policies that enforce specific rules and effects on your Azure resources. These policies can be used to implement a security baseline by ensuring resources comply with built-in security best practices, such as requiring encryption or restricting resource types. Azure Policy evaluates resources against assigned policies and can automatically remediate non-compliant resources.

Exam trap

The trap here is that candidates often confuse Azure Policy with Microsoft Defender for Cloud, thinking Defender for Cloud is the tool for enforcing security baselines, but Defender for Cloud only recommends policies and monitors compliance, while Azure Policy is the actual service that enforces them.

How to eliminate wrong answers

Option A is wrong because Azure Blueprints is used to orchestrate the deployment of resource templates, policies, and role assignments as a repeatable set of artifacts, but it is not the service for directly assigning and enforcing individual policies; it can include Azure Policy definitions as part of a blueprint, but the core policy enforcement mechanism is Azure Policy itself. Option B is wrong because Microsoft Defender for Cloud provides security posture management, threat detection, and recommendations based on security benchmarks, but it does not directly assign or enforce policies; it can integrate with Azure Policy to apply regulatory compliance initiatives, but the assignment and enforcement of policies is done through Azure Policy. Option D is wrong because Azure Role-Based Access Control (RBAC) manages who has access to Azure resources and what actions they can perform, but it does not enforce compliance rules or security baselines on resource configurations; RBAC is about authorization, not about ensuring resources meet specific security standards.

75
MCQeasy

Adventure Works is a startup that uses Microsoft 365 Business Premium. They have 20 employees and no cloud expertise. The CEO has been hearing about ransomware attacks on small businesses. They want to implement basic protection against ransomware using built-in Microsoft 365 features. They also want to ensure they can recover from an attack quickly. What should you recommend?

A.Purchase Azure Backup for all user devices. Configure backup policies to run daily. Use Microsoft Intune to enforce encryption. Implement Conditional Access to require MFA.
B.Enable Microsoft Defender for Office 365 to block malicious attachments and links. Configure Microsoft Defender for Business to enable controlled folder access and ransomware protection. Educate users on phishing. Use OneDrive Files Restore to recover from ransomware.
C.Use Microsoft Sentinel as a SIEM to detect ransomware patterns. Deploy Azure ATP for identity protection. Use Azure Policy to enforce backup.
D.Implement Azure Site Recovery for on-premises servers. Use Microsoft Defender for Cloud for threat detection. Deploy a third-party antivirus.
AnswerB

This option is correct because it leverages the built-in, integrated protections of Microsoft 365 Business Premium. Microsoft Defender for Office 365 filters malicious attachments and link-time detonation in Exchange Online, while Defender for Business provides endpoint detection and response plus controlled folder access that blocks unauthorized processes from modifying user files. Phishing education reduces initial compromise, and OneDrive Files Restore enables users to roll back an entire library to a known-good state within 30 days without heavy IT administration.

Why this answer

It leverages built-in Microsoft 365 Business Premium features to provide immediate ransomware protection without requiring cloud expertise. Microsoft Defender for Office 365 blocks malicious attachments and links at the email gateway, while Defender for Business provides endpoint protection with controlled folder access. OneDrive Files Restore enables self-service recovery of files from ransomware within the last 30 days, aligning with the startup's need for quick recovery without additional infrastructure.

Exam trap

The trap here is that candidates often over-engineer the solution by recommending enterprise-grade tools like Azure Backup or Sentinel, failing to recognize that Microsoft 365 Business Premium includes sufficient built-in capabilities for a small startup with no cloud expertise.

How to eliminate wrong answers

Option A is wrong because Azure Backup is not included in Microsoft 365 Business Premium and requires additional licensing and cloud expertise to configure; it also does not address ransomware prevention at the email or endpoint level. Option C is wrong because Microsoft Sentinel and Azure ATP are advanced security tools requiring significant cloud expertise and additional licensing, far beyond the scope of a 20-employee startup with no cloud expertise. Option D is wrong because Azure Site Recovery is designed for on-premises server disaster recovery, not for user devices or Microsoft 365 data, and deploying a third-party antivirus contradicts the requirement to use built-in Microsoft 365 features.

Page 1 of 2 · 142 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Design solutions that align with security best practices and priorities questions.