Courseiva

CCNA Design security solutions for infrastructure Questions

75 of 128 questions · Page 1/2 · Design security solutions for infrastructure · Answers revealed

1
MCQeasy

You are a security architect for a retail company that uses Microsoft 365 and Azure. The company has a large number of remote employees who use both company-managed and personal devices. You need to design a solution to ensure that only compliant devices can access corporate email (Exchange Online) and files (SharePoint Online). The company has Microsoft Intune and Microsoft Entra ID P1 licenses. You need to implement device-based conditional access. What should you do?

A.Deploy app protection policies (MAM) in Intune to protect data in Exchange Online and SharePoint Online.
B.Enroll devices in Intune, create compliance policies, and configure Conditional Access policies in Entra ID to require compliant devices.
C.Require all devices to be enrolled in Intune using automatic enrollment via Group Policy.
D.Use Microsoft Endpoint Configuration Manager to manage device compliance and integrate with Entra ID.
AnswerB

This is the correct approach because it combines Intune enrollment (giving the device an identity in Entra ID), compliance policies (defining security baselines such as BitLocker, Windows Defender, or iOS / Android compliance settings), and Conditional Access policies in Entra ID that gate access based on the device's compliance state. When a device is both enrolled and marked compliant, Entra ID trusts that signal and grants or blocks access to cloud resources accordingly. The Conditional Access policy 'Require compliant device' relies on this evaluation and is the only way to enforce compliance-driven access across both managed and unmanaged apps.

Why this answer

Intune compliance policies define device health requirements, and Conditional Access policies enforce access based on compliance. Option A is wrong because app protection policies are for mobile application management (MAM) without device enrollment, but the requirement is device-based. Option C is wrong because device enrollment itself does not enforce compliance.

Option D is wrong because Configuration Manager is for on-premises management, not cloud devices.

2
MCQmedium

You are designing a secure hybrid network architecture for a company that uses Azure and an on-premises datacenter. The company requires that all traffic between Azure and on-premises traverses Microsoft's backbone network and never the public internet. Additionally, the solution must provide automatic failover if the primary connection fails. Which Azure service should you include in the design?

A.Azure ExpressRoute with redundant circuits
B.Azure Virtual WAN
C.Azure Front Door
D.Azure VPN Gateway
AnswerA

Azure ExpressRoute with redundant circuits creates a private, dedicated connection from on-premises to Azure over Microsoft's global backbone, bypassing the public internet entirely. Redundant circuits, usually configured with BGP for active-active or active-passive, provide automatic failover if a circuit fails, satisfying the requirement for resilient hybrid connectivity. This direct backbone path is exactly what the scenario demands.

Why this answer

Azure ExpressRoute with redundant circuits is correct because ExpressRoute provides a private, dedicated connection through a connectivity provider that does not traverse the public internet, and deploying two or more circuits in different peering locations enables automatic failover if the primary circuit fails. Azure Virtual WAN is a networking hub service that can aggregate connectivity but does not by itself guarantee private backbone-only transport or automatic failover. Azure Front Door is a global HTTP/HTTPS load balancer and CDN for web applications, not a hybrid connectivity service.

Azure VPN Gateway sends traffic over the public internet via IPsec tunnels, so it fails the requirement that traffic never use the public internet.

3
MCQmedium

Your organization uses Microsoft Defender for Identity (MDI) to protect on-premises Active Directory. You need to integrate MDI with Microsoft Sentinel to centralize detection and response. What is the required configuration?

A.Deploy the MDI sensor on an Azure VM to send data to Sentinel.
B.Integrate Microsoft Entra ID Protection with Sentinel instead.
C.Enable the Microsoft Defender for Identity data connector in Microsoft Sentinel.
D.Configure MDI to forward logs to a Syslog server, then use the Syslog connector in Sentinel.
AnswerC

The Microsoft Defender for Identity data connector in Microsoft Sentinel is the native integration path: once enabled, it uses the Microsoft 365 Defender API to pull MDI alerts and incidents into Sentinel, making them available for analytics rules, hunting, and incident correlation. This connector is the official—and only supported—way to ingest MDI data into Sentinel, and it requires no additional sensors, log forwarders, or syslog infrastructure. Enabling it consumes the correct, purpose-built pipeline.

Why this answer

The correct option is C: enabling the Microsoft Defender for Identity data connector in Microsoft Sentinel. MDI integrates with Sentinel through a built-in data connector that streams MDI alerts and related identity events into the Sentinel workspace, allowing centralized detection and response without extra infrastructure. Option A is unnecessary because the MDI sensor is deployed on domain controllers or AD FS servers, not Azure VMs, and the sensor does not send data directly to Sentinel.

Option B is incorrect because Entra ID Protection covers cloud identity risk, not on-premises AD signals from MDI. Option D is incorrect because MDI does not natively forward to Syslog for Sentinel ingestion; the supported path is the MDI data connector.

4
MCQeasy

Your organization is planning to deploy a new web application on Azure VMs. The security team requires that all incoming traffic to the VMs be inspected by a network virtual appliance (NVA) before reaching the VMs. Which Azure networking solution should you use to route traffic through the NVA?

A.Azure Firewall
B.Azure Load Balancer
C.Network Security Groups (NSGs)
D.User Defined Routes (UDRs)
AnswerD

User-defined routes are custom route table entries that allow you to override Azure's automatic system routes for selected subnets. By associating a route table with a subnet and setting the next hop to an NVA's private IP address, you force all matching traffic to be forwarded to that appliance for processing such as inspection or firewall enforcement. This is exactly the routing mechanism needed to steer web application traffic through a network virtual appliance, and it is the only option listed that actively changes packet forwarding behavior.

Why this answer

User Defined Routes (UDRs) are the correct choice because they let you override Azure's default system routes and force traffic to be sent to a specific next hop, such as the private IP of a network virtual appliance, so packets are inspected before reaching the VMs. In this scenario, the security team requires traffic to pass through the NVA, which is exactly what a UDR with the NVA as the next hop accomplishes. Azure Firewall (A) is itself a managed firewall service, not the routing mechanism used to redirect traffic to a third-party NVA.

Azure Load Balancer (B) distributes traffic across endpoints but does not control routing paths, and Network Security Groups (C) only filter traffic with allow/deny rules rather than steering it through an appliance.

Exam trap

Candidates often confuse Azure Firewall (a managed firewall service) with a routing mechanism. UDRs are the correct way to direct traffic through an NVA, not Azure Firewall.

5
MCQmedium

Refer to the exhibit. You are reviewing an Azure Policy definition. What is the effect of this policy?

A.Denies creation of Windows VMs that have automatic updates enabled
B.Audits Windows VMs that have automatic updates disabled
C.Audits Linux VMs that have automatic updates enabled
D.Denies creation of Windows VMs without automatic updates enabled
AnswerD

This is correct because the condition uses 'exists': 'false' on the 'Microsoft.Compute/virtualMachines/enableAutomaticUpdates' field. When a deployment request for a Windows VM omits the enableAutomaticUpdates property, the condition is met and the deny effect blocks the create or update operation. This forces callers to explicitly include the property on the VM resource to pass the policy.

Why this answer

The correct answer is D: the policy denies creation of Windows VMs without automatic updates enabled. In Azure Policy, a Deny effect blocks the deployment request when the resource does not satisfy the condition, so a Windows VM whose automatic updates setting is not enabled would fail the policy evaluation and be rejected. This matches the scenario of enforcing automatic updates on Windows VMs at creation time.

Option A is incorrect because it reverses the condition, denying VMs that already have automatic updates enabled. Option B is incorrect because it describes an Audit effect, not Deny, and audits VMs with updates disabled rather than blocking noncompliant deployments. Option C is incorrect because it targets Linux VMs and uses Audit, neither of which matches the policy's Windows VM Deny behavior.

6
MCQmedium

Refer to the exhibit. You are reviewing an Azure Policy definition. What does this policy do?

A.Requires all virtual machines to use encryption at host
B.Allows only virtual machines with unmanaged disks
C.Denies virtual machines with managed disks if the OS disk type is not Standard_LRS or Premium_LRS
D.Denies all virtual machines without managed disks
AnswerC

This is the accurate interpretation. The policy definition's condition evaluates the 'Microsoft.Compute/virtualMachines' resource to see if a managed OS disk exists, and if so, it further checks whether the 'storageAccountType' of that managed disk is 'Standard_LRS' or 'Premium_LRS'. When the managed disk exists and its type is not in that allowed list, the policy's 'deny' effect blocks the deployment or update operation. This directly matches the statement, making it the correct answer.

Why this answer

The correct option is C: the policy denies virtual machines with managed disks when the OS disk type is not Standard_LRS or Premium_LRS. This matches a typical Azure Policy definition that evaluates the managed disk's storage account type (for example, the field Microsoft.Compute/disks sku.name) and uses a deny effect to block any value outside the allowed set of Standard_LRS and Premium_LRS. Option A is wrong because encryption at host is controlled by a different setting (encryptionAtHost) and is not what this disk-type policy enforces.

Option B is wrong because the policy targets managed disks, not unmanaged disks, and it does not allow unmanaged disks. Option D is wrong because the policy does not deny all VMs without managed disks; it only denies managed-disk VMs whose OS disk SKU is not Standard_LRS or Premium_LRS.

7
Multi-Selectmedium

Which TWO actions should you take to protect Azure Virtual Machines from ransomware? (Choose two.)

Select 2 answers
A.Deploy Azure Firewall to block all inbound traffic.
B.Configure Azure Site Recovery for all VMs.
C.Enable Azure Backup with immutable vault.
D.Assign Azure Policy to require encryption at rest.
E.Enable Microsoft Defender for Servers.
AnswersC, E

Azure Backup with an immutable vault uses Write-Once, Read-Many (WORM) storage, which prevents backups from being deleted, modified, or encrypted by ransomware even if admin credentials are stolen. This ensures you always have a clean, valid recovery point to restore VMs to a pre-infection state. Immutable backups are a critical last line of defense because they isolate recovery data from the attack surface and align with Azure's recommended ransomware protection strategy.

Why this answer

Option C is correct because Azure Backup with an immutable vault prevents backup data from being altered or deleted during the retention period, which is essential for recovering VMs after a ransomware attack encrypts or destroys production data. Option E is correct because Microsoft Defender for Servers provides threat detection, vulnerability assessment, and file integrity monitoring, and it can raise alerts on suspicious ransomware-like behavior on the VM. Option A is not correct because blocking all inbound traffic with Azure Firewall would not stop ransomware delivered through outbound connections, compromised credentials, or already-running workloads, and it is not a ransomware-specific protection.

Option B is not correct because Azure Site Recovery provides replication and disaster recovery failover, but it does not by itself protect backups from tampering or detect ransomware. Option D is not correct because encryption at rest protects data confidentiality if disks are stolen, but it does not prevent ransomware from encrypting files on a running VM.

8
MCQeasy

You need to ensure that Azure SQL Database always encrypts data at rest and in transit. Which features should you enable?

A.Firewall rules and Azure Active Directory authentication
B.Transparent Data Encryption (TDE) and enforce TLS connections
C.Always Encrypted and firewall rules
D.Azure Defender for SQL and vulnerability assessment
AnswerB

Transparent Data Encryption encrypts Azure SQL data at rest at the page level, while enforcing TLS connections protects data in transit. Together they satisfy the requirement to always encrypt data both at rest and in transit.

Why this answer

The correct answer is B: Transparent Data Encryption (TDE) and enforce TLS connections. TDE provides encryption of data at rest by encrypting the database, backups, and transaction logs at the page level, while enforcing TLS (Transport Layer Security) ensures data in transit is encrypted between the client and Azure SQL Database. Firewall rules, Azure AD authentication, Always Encrypted, Azure Defender, and vulnerability assessment address access control, client-side encryption, or threat detection, but they do not by themselves guarantee encryption of data at rest and in transit.

Therefore, options A, C, and D do not satisfy the stated requirement.

9
MCQeasy

You need to design a solution to protect Azure VMs from malware and provide security recommendations. Which Azure service should you enable?

A.Azure Sentinel
B.Microsoft Intune
C.Azure Monitor
D.Microsoft Defender for Cloud
AnswerD

Microsoft Defender for Cloud is the correct solution because it is a cloud workload protection platform (CWPP) and CSPM tool that natively provides antimalware for Azure VMs. It includes the Microsoft Antimalware extension for real-time scanning and removal of malicious software, and it can integrate with Microsoft Defender for Endpoint for next-generation endpoint detection and response (EDR). It also delivers actionable security recommendations, adaptive application controls, and just-in-time VM access to reduce attack surface and prevent malware. This integrated, proactive protection is exactly what is required to secure Azure VMs against malware.

Why this answer

Microsoft Defender for Cloud (option D) is the correct choice because it provides cloud workload protection, including Microsoft Defender for Servers, which delivers antimalware/endpoint protection and security recommendations for Azure VMs. It continuously assesses VM configurations and surfaces hardening recommendations, satisfying both the malware protection and security-recommendation requirements. Azure Sentinel (A) is a SIEM/SOAR platform for collecting and analyzing security events, not for directly protecting VMs from malware.

Microsoft Intune (B) is for mobile device and endpoint management, primarily for user devices, not Azure VM workload protection. Azure Monitor (C) collects metrics and logs for observability but does not provide malware protection or security recommendations.

10
MCQmedium

Your organization uses Azure SQL Database and needs to protect sensitive data from being exported by unauthorized users. You must implement a solution that prevents users from copying data to clipboard or taking screenshots of query results, while allowing legitimate business operations. What should you implement?

A.Apply Azure Information Protection labels to the database.
B.Use Dynamic Data Masking to obscure sensitive columns.
C.Enable Azure SQL Database Auditing and threat detection.
D.Configure a session policy in Microsoft Defender for Cloud Apps to block clipboard and screenshot actions.
AnswerD

Configuring a session policy in Microsoft Defender for Cloud Apps (MDA) is a preventive, real-time DLP control that uses a reverse-proxy architecture to sit between the user and Azure SQL Database. When a user accesses the database through a supported web portal or app, the session policy can apply conditional access and enforce behavioral controls such as blocking clipboard operations (copy, cut, paste) and prohibiting screenshot capture, thereby preventing data exfiltration at the client session level. This goes beyond traditional database permissions and masking because MDA inspects and restricts the user's interactive environment in real time. To be effective, you target the specific app (e.g., Azure Portal or SQL Query Editor) and define policy conditions and actions for sensitive data.

Why this answer

The correct option is D: configuring a session policy in Microsoft Defender for Cloud Apps to block clipboard and screenshot actions. Defender for Cloud Apps Conditional Access App Control uses a session policy to proxy the session and apply controls such as blocking copy/paste to the clipboard and preventing screenshots, which directly addresses the requirement while still permitting legitimate query operations. Option A is incorrect because Azure Information Protection labels classify and protect data at rest or in documents, not interactive query result sessions.

Option B is incorrect because Dynamic Data Masking only obscures column values in query output and does not prevent copying or screenshotting. Option C is incorrect because Auditing and threat detection only log and alert on suspicious activity; they do not block clipboard or screenshot actions.

11
MCQeasy

You are designing a backup strategy for Azure virtual machines that host a mission-critical application. The solution must support daily backups with a retention of 30 days for daily backups, weekly backups retained for 12 weeks, and monthly backups retained for 3 years. What should you use?

A.Azure Files backup with a custom script.
B.Azure Disk Backup with a snapshot schedule.
C.Azure Site Recovery with a recovery plan.
D.Azure Backup with a backup policy that specifies daily, weekly, and monthly retention.
AnswerD

Azure Backup with a VM backup policy precisely matches the requirement: the policy allows a daily, weekly, and monthly retention schedule, with each retention tier preserving recovery points for up to 180 days, 10 years, and 10 years respectively. You can also adjust retention to meet compliance needs, and Azure Backup stores recovery points in the Recovery Services vault. This gives you application-consistent, crash-consistent, or file-consistent snapshots and supports instant restore from snapshots. It is the correct strategy for multi-tier retention of Azure VMs.

Why this answer

Azure Backup with a backup policy that specifies daily, weekly, and monthly retention (option D) is correct because Azure Backup for virtual machines natively supports long-term retention through policy rules that define daily, weekly, monthly, and yearly retention durations, exactly matching the required 30-day daily, 12-week weekly, and 3-year monthly schedule. Azure Backup also provides application-consistent snapshots and recovery points for mission-critical VMs without custom scripting. Option A is wrong because Azure Files backup targets file shares, not VM disks, and requires custom scripting that Azure Backup handles natively.

Option B is wrong because Azure Disk Backup only supports snapshot-based retention up to a limited period and does not provide the multi-tier daily/weekly/monthly retention policy required. Option C is wrong because Azure Site Recovery is a disaster-recovery replication service, not a backup solution with retention policies.

12
Multi-Selecteasy

Which TWO Microsoft Purview solutions should you use to protect sensitive data in Microsoft 365? (Choose two.)

Select 2 answers
A.Microsoft Purview Audit.
B.Insider Risk Management.
C.Sensitivity labels and policies.
D.Microsoft Purview eDiscovery.
E.Data Loss Prevention (DLP) policies.
AnswersC, E

Sensitivity labels apply persistent encryption and visual markings directly to content, satisfying the requirement to protect sensitive data at the item level across Microsoft 365 workloads. Unlike perimeter controls, labels travel with the file, enforcing protection even after it leaves the tenant, which is precisely what the scenario demands.

Why this answer

Sensitivity labels and policies (C) are correct because they apply persistent protection to content by classifying data and enforcing encryption, content marking, and usage restrictions that travel with the file or email across Microsoft 365 workloads. Data Loss Prevention (DLP) policies (E) are correct because they detect sensitive information types and take protective actions such as blocking, warning, or encrypting data when it is shared inappropriately in Exchange Online, SharePoint, OneDrive, and Teams. Audit (A) is not a protection solution; it records and searches user and admin activity for investigation and compliance reporting.

Insider Risk Management (B) focuses on detecting and remediating risky user behavior rather than directly protecting sensitive data. eDiscovery (D) is used to identify, preserve, collect, and review content for legal or investigative purposes, not to enforce data protection.

Exam trap

SC-100 often tests the distinction between preventive data protection controls (labels, DLP) and detective/investigative tools (Audit, Insider Risk, eDiscovery) — candidates pick Audit or Insider Risk because they sound security-related but do not actually protect data.

13
MCQeasy

A company uses Microsoft Defender for Cloud to assess the security posture of their Azure subscriptions. They want to receive alerts when a resource is deployed without encryption enabled. What should they configure?

A.Azure Blueprints
B.Microsoft Defender for Cloud regulatory compliance dashboard
C.Microsoft Defender for Cloud security alerts
D.Azure Policy definition to audit or deny resources without encryption
AnswerD

An Azure Policy definition with audit or deny effects is the correct enforcement mechanism because it evaluates resource properties (such as encryption settings) against rules during provisioning and continuously thereafter. A deny effect blocks deployment of any resource that violates the encryption policy, while an audit effect marks the resource as non-compliant for reporting and follow-up. This approach ensures encryption requirements are consistently applied across new and existing resources, directly closing the configuration gap.

Why this answer

Azure Policy with a custom policy definition can audit or deny resources without encryption. Defender for Cloud's regulatory compliance dashboard shows compliance status. Security alerts are for threats, not configuration drift.

Azure Blueprints are for packaging resources.

14
MCQeasy

Your company uses Microsoft Entra ID for identity management. You need to implement a solution to automatically detect and remediate risky sign-ins using machine learning. What should you configure?

A.Configure Microsoft Entra Connect to sync on-premises identities.
B.Configure Conditional Access policies with session controls.
C.Configure Microsoft Entra ID Protection and enable risk-based policies.
D.Configure Privileged Identity Management (PIM) for admin roles.
AnswerC

Microsoft Entra ID Protection actively monitors user and sign-in risk using machine learning, heuristic analysis, and Microsoft's threat intelligence feeds. Enabling risk-based policies (which are a type of Conditional Access policy using risk as a condition) allows automatic remediation, such as requiring MFA, blocking the sign-in, or forcing a secure password change. This directly addresses the need to detect risky identities and respond without manual intervention, making it the correct choice for identity-based threat detection and auto-remediation.

Why this answer

Microsoft Entra ID Protection is the correct choice (Option C) because it uses machine learning to detect risky sign-ins and user risk events, and it lets you enable risk-based Conditional Access policies that automatically remediate those risks (for example, requiring MFA or blocking access). It is purpose-built for identity risk detection and automated remediation, matching the scenario's requirement exactly. Option A, Entra Connect, only synchronizes on-premises identities to Entra ID and does not perform risk detection.

Option B, Conditional Access with session controls, enforces access and session restrictions but does not itself provide the machine-learning risk detection engine. Option D, PIM, manages just-in-time privileged role activation and approvals, not risky sign-in detection or remediation.

15
MCQmedium

Refer to the exhibit. You run the PowerShell command to retrieve information about a Managed HSM in Azure. The output shows that the HSM is in 'Provisioned' state and has two security domains. What is the purpose of the security domains?

A.To manage the HSM's private endpoint connections.
B.To back up and restore the HSM's key material and configuration.
C.To enable role-based access control (RBAC) for the HSM.
D.To define the HSM's network access and firewall rules.
AnswerB

The security domain contains the encrypted material needed to reconstruct the HSM's master key, which in turn wraps all keys and protects the HSM's configuration. Downloading it creates a backup that, along with the quorum of security domain keys, can restore the HSM to a usable state after a disaster. This is why the security domain is essential for disaster recovery of the managed HSM.

Why this answer

The correct answer is B: security domains in Azure Managed HSM are used to back up and restore the HSM's key material and configuration. A security domain is a specially encrypted blob containing the HSM's full key material and configuration, and it is the only way to restore an HSM to a new instance or recover from a total loss of the HSM. Options A, C, and D are incorrect because private endpoint connections, RBAC, and network/firewall rules are managed through Azure networking and Azure RBAC features, not through security domains.

16
MCQmedium

Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to design a solution to detect brute-force attacks against Azure virtual machines. The solution should use Azure Activity Logs and Windows Security Events. What should you configure in Sentinel?

A.Create a threat intelligence watchlist
B.Create a workbook
C.Create a scheduled analytics rule
D.Create a playbook
AnswerC

A scheduled analytics rule is the core detection primitive in Microsoft Sentinel. It defines a KQL query, a query frequency (how often to run), a lookback period (how much historical data to examine), and an alert threshold or result condition. When the query returns results on the schedule, the rule creates a security alert, optionally with entity mapping for investigation and automated responses. This is precisely the mechanism Sentinel uses for always-on, time-based threat detection across your workspace.

Why this answer

Sentinel can ingest Azure Activity Logs and Windows Events, and then use analytics rules to detect brute-force patterns. Option A is wrong because watchlists are for reference data, not detection logic. Option B is wrong because workbooks visualize data, not detect.

Option D is wrong because playbooks automate responses, not detect.

17
MCQmedium

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that devices must have a minimum OS version and cannot be jailbroken. Which configuration profile type should you assign?

A.Device configuration policy.
B.Device restrictions profile.
C.Enrollment restriction.
D.Compliance policy.
AnswerD

Intune Device Compliance policies for iOS/iPadOS evaluate a device against rules such as minimum OS version, jailbreak/root detection, and required encryption to determine a compliant or non-compliant state. This assessment runs on an ongoing basis (check-in) and integrates directly with Conditional Access for blocking access to cloud resources until compliant. That's why a compliance policy is the correct choice for assessing conditions like minimum OS version and jailbreak status.

Why this answer

A compliance policy (option D) is the correct choice because Intune compliance policies are specifically designed to evaluate device health and posture, including defining a minimum OS version for iOS/iPadOS and detecting jailbroken devices via the device compliance check. When a device fails these conditions, it is marked noncompliant, which can then drive Conditional Access or other remediation actions. Device configuration policies (A) and device restrictions profiles (B) push settings to devices but do not evaluate jailbreak status or enforce a minimum OS version as a compliance condition.

Enrollment restrictions (C) only control which devices or platforms are allowed to enroll, not the ongoing OS version or jailbreak state of already-enrolled devices.

18
MCQmedium

Your organization plans to use Microsoft Defender for Cloud to protect a hybrid environment with servers in Azure and on-premises. You need to ensure that security policies are consistently applied across all servers. What should you configure?

A.Onboard all servers to Azure Arc and assign Defender for Cloud policies.
B.Deploy Azure Automation State Configuration (DSC) to all servers.
C.Connect all servers to Microsoft Sentinel and use analytics rules.
D.Use Azure Policy with guest configuration on all servers.
AnswerA

Onboarding servers to Azure Arc registers them as Azure resources, allowing Defender for Cloud policies to be assigned and enforced consistently across on-premises and multi-cloud workloads. This enables security posture assessments, vulnerability management, and Microsoft Defender plans on non-Azure machines. Arc is the required control plane for applying Azure security policy to servers outside Azure.

Why this answer

Option A is correct because onboarding on-premises and Azure servers to Azure Arc makes them manageable as connected machine resources in Azure, allowing Defender for Cloud policies and plans (such as Defender for Servers) to be applied consistently across the hybrid estate. Azure Arc is the supported mechanism for extending Azure management and Defender for Cloud coverage to non-Azure servers. Option B is wrong because Azure Automation State Configuration (DSC) enforces configuration state, not Defender for Cloud security policies.

Option C is wrong because Microsoft Sentinel is a SIEM/SOAR solution for analytics and detection, not policy assignment. Option D is wrong because Azure Policy guest configuration audits/configures in-guest settings but does not itself onboard servers to Defender for Cloud or apply its security plans.

19
MCQhard

A company uses Microsoft Sentinel for SIEM and SOAR. You need to design a solution to detect and automatically respond to ransomware attacks involving mass file encryption on Windows servers. The response must include isolating the compromised server from the network, creating a backup of affected files, and resetting the user account's password. Which automation approach minimizes manual intervention?

A.Use a Logic Apps playbook to create a VM snapshot and send an email to the security team.
B.Create an alert rule that triggers an Azure Automation runbook to isolate the VM.
C.Set up an automation rule that runs a playbook to isolate the VM, trigger a backup, and reset the user password.
D.Configure a manual incident response plan that includes password reset.
AnswerC

This solution uses a Sentinel automation rule to invoke a Logic Apps playbook that orchestrates three complementary actions: VM isolation, a backup/snapshot, and a user password reset. That sequence provides containment to impede lateral movement, evidence preservation for forensics, and credential remediation to revoke attacker access. Because it is fully automated and runs on incident trigger, it minimizes manual intervention and meets the goal of a single co-ordinated response.

Why this answer

Option C is correct because Microsoft Sentinel automation rules can automatically trigger a Logic Apps playbook in response to an incident, and that playbook can orchestrate the full response chain: isolating the compromised VM (e.g., via network security group changes or Microsoft Defender for Endpoint isolation), initiating a backup/snapshot of affected files, and resetting the user's password through Microsoft Graph or Azure AD—all with minimal manual intervention. Option A is incomplete because it only creates a snapshot and emails the team, providing no isolation or password reset. Option B only isolates the VM and does not address backup or password reset, and an alert rule alone is not the full SOAR orchestration.

Option D is manual and therefore does not minimize intervention.

20
MCQeasy

You are designing a secure remote access solution for on-premises web applications using Microsoft Entra ID. The solution must support multifactor authentication (MFA) and conditional access. Which service should you use?

A.Microsoft Entra application proxy
B.Windows Server DirectAccess
C.VPN gateway with RADIUS authentication
D.Microsoft Entra ID (Azure AD)
AnswerA

Microsoft Entra Application Proxy publishes internal web applications through an outbound connector, so remote users access the app via an external URL without opening inbound firewall ports. It relies on Entra ID for pre-authentication, which lets you enforce MFA, Conditional Access, and device compliance before a session is established, and it supports Kerberos Constrained Delegation for seamless SSO to the backend app. This is the only option that delivers identity-aware, application-level access control specifically for on-premises web apps.

Why this answer

Microsoft Entra application proxy (option A) is correct because it is the service designed to publish on-premises web applications for secure remote access through Microsoft Entra ID, and it natively supports Entra ID authentication, multifactor authentication (MFA), and conditional access policies. It works via a lightweight connector on the on-premises network, so users authenticate to Entra ID before reaching the internal web app, satisfying the MFA and conditional access requirements. Windows Server DirectAccess (B) provides seamless intranet connectivity for domain-joined Windows clients but does not integrate with Entra ID conditional access for publishing web apps.

A VPN gateway with RADIUS authentication (C) provides network-level access and can use MFA via RADIUS, but it does not natively enforce Entra ID conditional access for individual web applications. Microsoft Entra ID (D) is the identity provider itself, not the remote-access publishing service, so it alone cannot expose on-premises web applications.

21
MCQmedium

Your company has an Azure subscription that contains multiple virtual machines (VMs) running Windows Server. You need to ensure that all VMs are compliant with your organization's security baseline. The security baseline includes specific registry key settings, password policies, and service configurations. You want to continuously monitor and automatically remediate non-compliant VMs. What should you implement?

A.Deploy Azure Automation State Configuration to apply Desired State Configuration (DSC) to the VMs.
B.Use Azure Policy with Guest Configuration extension to audit and remediate the VM settings.
C.Use Azure Update Manager to ensure VMs are up to date.
D.Enable Microsoft Defender for Cloud and review the security recommendations.
AnswerB

Azure Policy with the Guest Configuration extension delivers exactly this capability: it installs an agent inside the VM that evaluates settings like registry keys, security policies, and installed software against built-in or custom policy definitions. The resulting compliance state is continuously reported to Azure Policy, and when the policy effect is 'DeployIfNotExists' or 'Modify', a remediation task can automatically fix non-compliant VMs. This gives both the needed audit trail and the auto-remediation loop for VM configuration, unlike the other options.

Why this answer

Azure Policy with the Guest Configuration extension is the correct choice because it is designed to audit and remediate OS-level settings inside Azure VMs, including registry keys, password policies, and service configurations, using built-in or custom guest configuration packages. It continuously evaluates compliance and supports remediation tasks (DeployIfNotExists) to automatically bring non-compliant VMs back into the baseline. Azure Automation State Configuration (option A) can apply DSC, but it is a legacy approach and does not provide the same policy-driven continuous compliance and automatic remediation integration as Azure Policy Guest Configuration.

Azure Update Manager (option C) only handles OS and software patching, not security baseline settings, and Microsoft Defender for Cloud (option D) provides recommendations and alerts but does not automatically remediate these specific configuration items by itself.

Exam trap

Candidates often confuse Azure Automation State Configuration (DSC) with Azure Policy Guest Configuration. While both can manage VM configurations, Azure Policy Guest Configuration provides continuous compliance monitoring and automatic remediation directly integrated with Azure Policy, whereas DSC requires additional scripting and does not natively report compliance in Azure Policy.

22
MCQhard

You are designing a secure DevOps pipeline for a critical application using GitHub Actions and Microsoft Defender for Cloud. You need to ensure that container images are scanned for vulnerabilities before being deployed to Azure Kubernetes Service (AKS). What should you implement?

A.Integrate Microsoft Defender for Containers with the CI/CD pipeline to scan images in Azure Container Registry.
B.Enable GitHub Advanced Security for the repository.
C.Configure Azure Policy to require vulnerability assessment.
D.Use Azure Container Registry Tasks to build images.
AnswerA

Microsoft Defender for Containers natively provides vulnerability assessment for Azure Container Registry through its integration with CI/CD workflows. When an image is pushed to ACR, Defender automatically scans it using a continuously updated vulnerability database and exposes the findings in Microsoft Defender for Cloud. In a DevOps pipeline, you can query these scan results (e.g., using the Defender API or a pipeline step) to fail the release if high-severity vulnerabilities exceed a threshold, thus preventing vulnerable images from reaching AKS. This direct, artifact-level scanning makes it the correct choice for the security requirement.

Why this answer

The correct option is A: integrating Microsoft Defender for Containers with the CI/CD pipeline to scan images in Azure Container Registry. Defender for Containers provides image vulnerability scanning for ACR, and integrating it into the GitHub Actions pipeline lets you detect vulnerabilities before deployment to AKS, matching the requirement to scan images pre-deployment. Option B, GitHub Advanced Security, focuses on code and secret scanning rather than container image vulnerability assessment.

Option C, Azure Policy, can audit or deny deployments based on vulnerability findings but does not itself perform image scanning in the pipeline. Option D, ACR Tasks, builds images but does not provide vulnerability scanning.

23
Multi-Selecthard

Which TWO actions should you take to improve the security posture of an Azure subscription using Microsoft Defender for Cloud? (Select two.)

Select 2 answers
A.Assign Azure Policy to enforce resource compliance
B.Enable Azure Defender plans for all supported resource types
C.Implement the top security recommendations from the Secure Score
D.Create custom security policies
E.Deploy vulnerability assessment solution to all VMs
AnswersB, C

Enabling Azure Defender plans for all supported resource types activates integrated threat protection, including endpoint detection, vulnerability scanning, and security alerts across workloads. This directly strengthens security posture by providing continuous monitoring and automated responses to attacks, while also feeding findings into Secure Score to guide further improvements. It is a foundational action that covers multiple aspects of security simultaneously.

Why this answer

Option B is correct because enabling Microsoft Defender (Azure Defender) plans for all supported resource types activates the advanced threat protection and workload protection capabilities in Microsoft Defender for Cloud, such as Defender for Servers, Defender for Storage, and Defender for SQL, which provide detection and alerting beyond the free Secure Score recommendations. Option C is correct because acting on the top security recommendations surfaced by Secure Score directly remediates the highest-impact misconfigurations and control gaps, which is the intended workflow for measurably improving the subscription's security posture. Option A is not the best choice because Azure Policy enforces compliance with organizational standards but does not itself provide the threat protection and prioritized remediation that Defender for Cloud is designed to deliver.

Option D is not correct because custom security policies are a governance customization rather than a Defender for Cloud posture-improvement action. Option E is not correct because deploying a vulnerability assessment solution is only one specific recommendation within Defender for Servers and is narrower than enabling the full Defender plans and acting on top recommendations.

24
MCQeasy

Your company uses Azure DevOps to deploy infrastructure. You need to ensure that all deployed resources have specific tags for cost tracking. Which Azure policy effect should you use to prevent deployment of untagged resources?

A.Disabled
B.Deny
C.DeployIfNotExists
D.Audit
AnswerB

The Deny effect prevents the creation or modification of non-compliant resources during deployment. When a resource request is evaluated, if it fails compliance, the request is denied with a 403 error, and the deployment fails before any resource is provisioned. This is the only effect that actively blocks the requested action, making it the correct choice for enforcing compliance in Azure DevOps deployments.

Why this answer

The correct option is B, Deny, because a Deny policy effect actively blocks any deployment request that does not include the required tags, which is exactly what is needed to prevent untagged resources from being created. Deny evaluates the resource payload during deployment and returns a non-compliant error, so the resource is never provisioned. In contrast, Audit (D) only logs a non-compliance warning without stopping deployment, and DeployIfNotExists (C) remediates by deploying a related resource or applying tags after the fact rather than preventing the untagged deployment.

Disabled (A) turns the policy assignment off entirely, so it has no effect at all.

25
MCQmedium

Your organization is deploying Microsoft Defender for Cloud to secure a hybrid environment with workloads in Azure and on-premises. You need to ensure that all servers are covered by Defender for Cloud's plans. Which two actions should you take?

A.Install the Azure Connected Machine agent (Azure Arc) on on-premises servers.
B.Enable only the foundational cloud security posture management (CSPM) on the subscription.
C.Enable the Defender for Cloud plans (e.g., Defender for Servers) on the Azure subscription.
D.Deploy the Azure Monitor Agent to all on-premises servers.
AnswerA, C

Azure Arc's Connected Machine agent projects non-Azure servers into Azure Resource Manager, making them visible to Microsoft Defender for Cloud so its server protection plans can be enabled and billed against them. This satisfies the stem's requirement to cover on-premises servers, which Defender for Cloud cannot natively discover without Arc enrolment.

Why this answer

The correct actions are A and C. Installing the Azure Connected Machine agent (Azure Arc) on on-premises servers is required to project non-Azure machines into Azure so Defender for Cloud can see and manage them, and enabling the Defender for Cloud plans (e.g., Defender for Servers) on the Azure subscription activates the actual protection plans that cover those servers. Option B is insufficient because foundational CSPM only provides posture assessment and does not enable workload protection plans such as Defender for Servers.

Option D is not sufficient by itself because the Azure Monitor Agent collects monitoring data but does not onboard on-premises servers into Defender for Cloud without Azure Arc and the relevant Defender plan.

26
MCQmedium

Refer to the exhibit. You are reviewing an ARM template that deploys a storage account. The compliance team requires that all storage accounts use TLS 1.2 or higher. Does this template meet the requirement?

A.Yes, because Standard_GRS automatically enforces TLS 1.2.
B.Yes, because minimumTlsVersion is set to TLS1_2.
C.No, because supportsHttpsTrafficOnly only allows HTTPS but does not enforce TLS 1.2.
D.No, because the apiVersion is outdated and does not support TLS setting.
AnswerB

The ARM template explicitly sets the 'minimumTlsVersion' property to 'TLS1_2', which instructs Azure Storage to reject any client requests made with TLS 1.0 or TLS 1.1. This property is the definitive control that enforces TLS 1.2 as the minimum allowed protocol, so the template does meet the stated security requirement.

Why this answer

The template meets the requirement because the storage account resource explicitly sets the minimumTlsVersion property to TLS1_2, which enforces TLS 1.2 as the minimum accepted version for all connections. This is the exact ARM property Microsoft.Storage/storageAccounts exposes for controlling the minimum TLS version, and TLS1_2 satisfies the compliance team's 'TLS 1.2 or higher' rule. Option A is wrong because the SKU Standard_GRS controls replication and redundancy, not the TLS version.

Option C is wrong because supportsHttpsTrafficOnly is a separate setting that only redirects/rejects HTTP traffic; it does not by itself set the minimum TLS version, and the template already sets minimumTlsVersion. Option D is wrong because the apiVersion does support the minimumTlsVersion property, so the setting is valid.

27
MCQmedium

You are designing a secure hybrid network connectivity solution between an on-premises datacenter and Azure. The requirement is to have encrypted traffic and high availability. Which service should you use?

A.Azure Front Door
B.Azure ExpressRoute
C.Azure VPN Gateway
D.Azure Bastion
AnswerC

Azure VPN Gateway is the correct choice because it natively supports site-to-site IPsec/IKE tunnels, which encrypt all traffic traversing the public internet between your on-premises network and Azure. It supports active-active configuration for high availability and failover, ensuring resilient encrypted connectivity. This meets the requirement for secure hybrid network connectivity without additional encryption layers or a dedicated private circuit.

Why this answer

Azure VPN Gateway (option C) is correct because it establishes encrypted IPsec/IKE site-to-site tunnels between on-premises networks and Azure, and it supports high availability through active-active configurations, multiple gateway instances, and zone-redundant SKUs. This directly satisfies the stated requirements of encrypted traffic and high availability for hybrid connectivity. Azure ExpressRoute (option B) provides private, dedicated connectivity but does not natively encrypt traffic over the circuit, so it does not meet the encryption requirement by itself.

Azure Front Door (option A) is a global HTTP/HTTPS application delivery and load-balancing service, not a hybrid network tunnel, and Azure Bastion (option D) provides secure RDP/SSH access to VMs over the Azure portal without exposing public IPs, not site-to-site hybrid connectivity.

28
MCQmedium

A multinational corporation uses Microsoft Entra ID with hybrid identities. They need to design a solution that automatically remediates risky sign-ins without user intervention. Which feature should you enable?

A.Entra ID Governance (Access Reviews)
B.Privileged Identity Management (PIM)
C.Microsoft Defender for Identity
D.Identity Protection with Conditional Access policies
AnswerD

Identity Protection continuously evaluates sign-in and user risk using signals like impossible travel, leaked credentials, and anonymous IP addresses, assigning a risk level (low, medium, high). Conditional Access policies consume that risk score and automatically enforce actions such as blocking the sign-in, requiring MFA, or forcing a password reset in real time. This is a native, automatic remediation mechanism for risky sign-ins.

Why this answer

The correct option is D: Identity Protection with Conditional Access policies, because Entra ID Identity Protection detects risky sign-ins and risk detections, and Conditional Access can automatically enforce remediation actions such as requiring MFA, blocking access, or forcing password reset without user intervention. This directly addresses the requirement for automatic remediation of risky sign-ins in a hybrid identity environment. Option A, Entra ID Governance Access Reviews, is for periodic attestation of access rights, not sign-in risk remediation.

Option B, Privileged Identity Management, manages just-in-time privileged role activation and approvals, not risky sign-in response. Option C, Microsoft Defender for Identity, detects identity threats on-premises but does not itself automatically remediate Entra ID sign-in risk through Conditional Access.

29
MCQhard

You are designing a secure access solution for an on-premises application that uses legacy authentication protocols. The organization plans to migrate to Microsoft Entra ID but the application vendor has not yet provided a modern authentication update. The solution must enable single sign-on (SSO) and support multifactor authentication (MFA) for this application without modifying the application code. Which approach should you recommend?

A.Integrate the application with the Microsoft Authentication Library (MSAL)
B.Federate the on-premises Active Directory with Microsoft Entra ID
C.Use Microsoft Entra Conditional Access policies to require MFA
D.Deploy Microsoft Entra Application Proxy with pre-authentication
AnswerD

Deploying Microsoft Entra Application Proxy with pre-authentication works by exposing the legacy on-premises application through an external HTTPS URL that terminates the user's authentication in Entra ID before any request reaches the app. The user first signs in to Entra ID and can be subject to MFA and Conditional Access; only after successful pre-authentication does the Application Proxy connector relay the request to the on-premises app, typically using Kerberos constrained delegation to present the user's identity to the legacy application. This approach adds secure remote access and modern identity controls without requiring changes to the application itself.

Why this answer

Microsoft Entra Application Proxy with pre-authentication (option D) is correct because it publishes the on-premises legacy application externally while enforcing Microsoft Entra ID authentication and MFA at the proxy before traffic reaches the app, enabling SSO without changing application code. Pre-authentication means users authenticate against Microsoft Entra ID first, so legacy protocols inside the app are shielded and MFA/Conditional Access can be applied. MSAL (A) requires modifying the application to use modern auth libraries, which the vendor has not provided.

Federating on-premises AD with Entra ID (B) only enables identity synchronization/federation and does not by itself provide SSO or MFA for a legacy on-premises app. Conditional Access policies (C) require the app to already authenticate with Entra ID and cannot protect an app that still uses legacy authentication directly.

30
MCQhard

Your organization uses Microsoft Sentinel to monitor security events. You need to design a solution that alerts when a user account is created and then used to log in from a different country within 1 hour. Which KQL query structure should you use?

A.Use a single table filter with where clause
B.Use summarize with timechart
C.Use a join operation on AccountName with a time window
D.Use union to combine events
AnswerC

A join operation on AccountName with a time window is the correct approach because it lets you match account creation events (e.g., from AuditLogs) to login events (e.g., from SigninLogs) for the same user, with a constraint like the login time being after the creation time and within a specific window (e.g., 1 hour). Using join kind=inner with a condition such as `AccountName == AccountName` and `TimeGenerated between (CreationTime .. CreationTime+1h)` allows you to correlate the two event streams directly. This is a canonical KQL pattern for detecting 'new account, then login' sequences, enabling you to flag potential compromised accounts or insider threats. The time window is critical to avoid joining unrelated logins from days later, and it makes the correlation meaningful and actionable.

Why this answer

The correct option is C: use a join operation on AccountName with a time window. In Microsoft Sentinel, correlating two different event types (account creation and subsequent sign-in) across tables such as AuditLogs/SecurityEvent and SigninLogs requires joining on a common key like AccountName and constraining the time delta (e.g., using a join with a time window or a where clause on TimeGenerated difference) to detect the login within 1 hour from a different country. A single table filter (A) cannot correlate two distinct event sources, summarize with timechart (B) aggregates counts over time rather than linking creation to login, and union (D) merely concatenates rows without matching the account or enforcing the 1-hour window.

31
MCQhard

A multinational corporation uses Microsoft Entra ID for identity and Microsoft Defender for Cloud Apps for SaaS app governance. The security team wants to deploy a conditional access policy that blocks access from untrusted locations for all cloud apps except Microsoft 365, which should only be blocked if the device is not compliant. How should you configure the policy?

A.Use a session policy in Defender for Cloud Apps to monitor non-compliant devices.
B.Create two conditional access policies: one for all cloud apps except Microsoft 365 blocking untrusted locations, and one for Microsoft 365 requiring compliant device.
C.Create one conditional access policy that includes all cloud apps and requires compliant device for Microsoft 365 only.
D.Configure a conditional access policy that blocks access from untrusted locations for all apps.
AnswerB

Create two separate Conditional Access policies to achieve the required granularity. The first policy targets 'All cloud apps' but excludes Microsoft 365 and uses the 'Block' grant control for untrusted locations, preventing access to non-Microsoft 365 apps from risky networks. The second policy targets Microsoft 365 and requires a compliant device, allowing compliant devices to reach M365 even from untrusted locations. Since the policies are evaluated separately, they cooperate to enforce distinct requirements per app group.

Why this answer

Option B is correct because Conditional Access policies apply to either all cloud apps or specific apps, and Microsoft 365 cannot be excluded from one policy while having different conditions applied within the same policy. The scenario requires two separate policies: one targeting all cloud apps with Microsoft 365 excluded that blocks untrusted locations, and a second targeting Microsoft 365 that requires a compliant device. Option A is wrong because Defender for Cloud Apps session policies monitor or control sessions but do not block sign-ins from untrusted locations.

Option C is wrong because a single policy cannot apply a compliant-device requirement only to Microsoft 365 while including all other cloud apps with different conditions. Option D is wrong because it blocks Microsoft 365 from untrusted locations unconditionally, ignoring the compliant-device exception.

32
Multi-Selectmedium

You are designing a secure access solution for on-premises applications using Microsoft Entra ID. The solution must support modern authentication, single sign-on (SSO), and Conditional Access. Which TWO technologies should you implement?

Select 2 answers
A.Azure AD B2C
B.Microsoft Entra Domain Services
C.Microsoft Entra application proxy
D.Microsoft Entra ID as the identity provider
E.Site-to-Site VPN
AnswersC, D

Microsoft Entra Application Proxy is a reverse proxy service that publishes on-premises web applications to remote users via the Entra ID cloud endpoint, without requiring inbound firewall ports. It integrates with Microsoft Entra ID to enforce Conditional Access, MFA, and SSO, making it the correct choice for securely accessing on-premises apps with modern authentication.

Why this answer

Microsoft Entra application proxy (C) is correct because it publishes on-premises web applications to the internet and enforces Microsoft Entra ID pre-authentication, which enables modern authentication, SSO, and Conditional Access for those apps without opening inbound firewall ports. Microsoft Entra ID as the identity provider (D) is correct because it is the cloud identity service that issues tokens, performs authentication, and evaluates Conditional Access policies for the published applications. Together, application proxy and Entra ID as the IdP provide the required modern authentication, SSO, and Conditional Access for on-premises apps.

Azure AD B2C (A) is for customer-facing identity scenarios with local or social accounts, not for securing internal on-premises enterprise applications. Microsoft Entra Domain Services (B) provides managed domain services such as domain join and Group Policy, but it does not by itself publish on-premises apps or deliver the required modern auth/SSO/Conditional Access. Site-to-Site VPN (E) only provides network connectivity and does not deliver identity-based authentication, SSO, or Conditional Access.

33
MCQhard

You are designing a security solution for an Azure environment that includes several storage accounts containing sensitive data. The company requires that all data in transit to the storage accounts be encrypted and that access be restricted to specific virtual networks. You need to recommend a solution that enforces these requirements and provides visibility into any non-compliant storage accounts. What should you recommend?

A.Enable secure transfer required on all storage accounts and configure network rules to allow access only from selected virtual networks and IP addresses. Use Azure Policy to deny creation of storage accounts that do not meet these settings.
B.Deploy a network virtual appliance (NVA) to inspect all traffic to storage accounts and enforce encryption. Use Azure Policy to audit compliance.
C.Configure Azure Policy to audit storage accounts that do not require secure transfer and that allow access from all networks. Enable Defender for Storage to detect anomalies.
D.Use Azure Private Link to create private endpoints for all storage accounts and disable public access. Enable Microsoft Defender for Storage for threat detection.
AnswerA

Enabling secure transfer required enforces encryption in transit, and network rules restrict access to specific virtual networks. Azure Policy with a deny effect prevents the creation of non-compliant storage accounts, ensuring enforcement. This combination meets both the encryption and network restriction requirements while providing preventive control.

Why this answer

The requirements are to enforce encryption in transit and restrict network access to specific virtual networks. Enabling secure transfer required ensures that all requests to the storage account use HTTPS, enforcing encryption in transit. Network rules can be configured to allow access only from selected virtual networks and IP addresses.

Azure Policy with a deny effect ensures that new storage accounts cannot be created without these settings, providing preventive enforcement.

Exam trap

The trap here is assuming that Azure Private Link alone satisfies encryption in transit requirements, when in fact secure transfer must be explicitly enabled to enforce HTTPS for all connections.

34
MCQmedium

A company uses Azure Front Door to publish a web application globally. They need to protect against DDoS attacks and web application attacks (SQL injection, XSS). Which two services should they enable in combination?

A.Azure DDoS Protection Standard and Azure Firewall
B.Azure WAF on Application Gateway and Network Security Groups
C.Azure Firewall and Azure DDoS Protection Basic
D.Azure DDoS Protection Standard and Azure WAF policy on Front Door
AnswerD

Azure DDoS Protection Standard detects and scales to absorb volumetric (L3/L4) attacks against the application, while the Azure WAF policy applied directly to Front Door inspects every request at the L7 edge—matching rules such as the Microsoft managed rule sets and the OWASP CRS to block SQLi, XSS, and bot traffic before it nears your origin. Deploying both on Front Door gives you a single global policy plane that follows the anycast edge, enabling consistent protection with no regional split. This layered control covers the full attack chain from network flood to HTTP payload, making it the correct answer.

Why this answer

Azure DDoS Protection protects against volumetric DDoS attacks. Azure Web Application Firewall (WAF) in Front Door protects against application-layer attacks. Azure Firewall is for network-layer filtering.

Network Security Groups (NSGs) are for subnet-level filtering. Azure DDoS Protection Standard is the correct tier.

35
MCQhard

You are designing a zero-trust network architecture for a hybrid environment using Azure Virtual WAN. You need to secure all traffic between on-premises sites and Azure virtual networks using Microsoft's security services. The solution should include next-generation firewall capabilities and TLS inspection. What should you deploy?

A.Deploy a third-party NVA in a spoke virtual network and route traffic through it.
B.Deploy Azure Firewall Standard as the secured hub in Virtual WAN.
C.Deploy Azure Application Gateway with WAF in each virtual network.
D.Deploy Azure Firewall Premium as the secured hub in Virtual WAN.
AnswerD

Azure Firewall Premium is the right choice because it integrates natively as the secured hub in Virtual WAN, enabling centralized routing and policy enforcement for all traffic through the hub. It provides TLS inspection, IDPS, FQDN filtering, and threat intelligence — capabilities essential for a zero trust architecture. As a fully managed, auto-scalable service, it removes the operational burden of third-party NVAs while ensuring encrypted traffic is decrypted, inspected, and re-encrypted to enforce allowlisting and detect malicious activity.

Why this answer

Azure Firewall Premium is the correct choice because it is the only Azure Firewall SKU that provides next-generation firewall capabilities such as TLS inspection, IDPS, and URL filtering, and it can be deployed directly as the secured hub in Azure Virtual WAN to protect all on-premises-to-Azure and inter-hub traffic. Azure Firewall Standard lacks TLS inspection and IDPS, so it cannot meet the stated requirement. A third-party NVA in a spoke virtual network would require custom routing and does not natively integrate as the Virtual WAN secured hub, adding complexity and not using Microsoft's security services as requested.

Application Gateway with WAF is a Layer 7 web traffic load balancer for HTTP/HTTPS applications, not a network firewall for securing all hybrid traffic.

36
MCQmedium

Your organization uses Microsoft Defender for Cloud to assess security posture. You need to design a solution that automatically applies a security baseline to new Azure VMs. Which feature should you use?

A.Microsoft Defender for Cloud regulatory compliance dashboard
B.Azure Update Management
C.Azure Automation State Configuration (DSC)
D.Azure Policy with Guest Configuration
AnswerD

Azure Policy with Guest Configuration automatically applies and enforces security baselines inside VMs by deploying the Guest Configuration extension and evaluating OS settings against built-in policy definitions. It provides continuous compliance assessment, can proactively remediate non-compliant resources, and integrates with Microsoft Defender for Cloud's recommendations. This native, scalable solution directly meets the requirement to automatically apply baselines without custom scripting.

Why this answer

Azure Policy with Guest Configuration is the correct choice because it uses the Guest Configuration extension (via the Azure Connected Machine/VM agent) to audit and enforce OS-level settings inside Azure VMs, including applying security baselines such as the Windows or Linux security baseline definitions. It continuously evaluates machines against the policy and can deploy configuration assignments to new VMs automatically, which directly matches the requirement to apply a baseline to new Azure VMs. The regulatory compliance dashboard (A) only reports compliance status against standards and does not apply baselines.

Azure Update Management (B) handles OS patch orchestration, not security baseline configuration. Azure Automation State Configuration (C) can apply DSC configurations but is a separate, more manual pull/push mechanism and is not the Defender for Cloud-integrated baseline enforcement feature.

37
MCQeasy

Your company uses Microsoft 365 Defender (XDR) for endpoint detection and response. You need to design a solution to automatically remediate malware infections on Windows 10 devices. The solution should isolate the device from the network, run a full antivirus scan, and reset the device if the infection cannot be cleaned. What should you configure?

A.Create a manual incident response process where analysts remotely connect and run scripts.
B.Enable automated investigation and remediation in Microsoft Defender for Endpoint with action settings: isolate, run AV, and reset.
C.Deploy a third-party EDR tool that integrates with Microsoft Sentinel.
D.Configure Intune compliance policies to mark infected devices as non-compliant and require user action.
AnswerB

Automated investigation and remediation in Microsoft Defender for Endpoint executes response actions automatically. Configuring the action settings to isolate the device, run a full antivirus scan, and reset it when cleaning fails satisfies all three remediation requirements without manual intervention.

Why this answer

The correct answer is B: enabling automated investigation and remediation in Microsoft Defender for Endpoint with action settings for isolate, run AV, and reset. This directly satisfies the scenario because Defender for Endpoint's AIR capabilities can automatically isolate a compromised Windows 10 device, trigger a full antivirus scan, and reset the device when remediation cannot clean the infection. Option A is manual and does not provide automatic remediation, while option C introduces a third-party tool that is unnecessary and not specified as available.

Option D only marks devices non-compliant and requires user action, so it does not isolate, scan, or reset the device automatically.

38
Multi-Selecthard

Which TWO Azure services can you use to implement a zero-trust network architecture that verifies identity and device compliance before granting access to on-premises applications? (Choose two.)

Select 2 answers
A.Microsoft Entra Application Proxy
B.Microsoft Entra Conditional Access
C.Azure VPN Gateway
D.Azure Firewall
E.Azure Bastion
AnswersA, B

Microsoft Entra Application Proxy acts as a reverse proxy for on-premises web applications, intercepting the initial request and pre-authenticating the user against Microsoft Entra ID. It then evaluates Conditional Access policies—like MFA, device compliance, or sign-in risk—before leaving the cloud boundary to reach the on-prem app. This makes it an ideal companion to Conditional Access for enabling zero trust across hybrid application environments.

Why this answer

Microsoft Entra Application Proxy (A) is correct because it publishes on-premises web applications to the cloud and enforces Microsoft Entra ID authentication and Conditional Access before any request is forwarded to the internal app, which directly supports verifying identity and device compliance for on-premises access. Microsoft Entra Conditional Access (B) is correct because it is the policy engine that evaluates signals such as user identity, group membership, and device compliance state (via Intune) and then grants, blocks, or challenges access, which is the core of a zero-trust verification step. Azure VPN Gateway (C) only establishes encrypted network tunnels and does not itself verify user identity or device compliance.

Azure Firewall (D) is a network-layer traffic filtering and inspection service, not an identity or device-compliance gate. Azure Bastion (E) provides secure RDP/SSH access to Azure VMs over TLS without exposing public IPs, but it does not publish or broker access to on-premises applications based on identity and device compliance.

39
MCQmedium

You are designing a security solution for containers in Azure Kubernetes Service (AKS). The solution must scan container images for vulnerabilities before deployment and enforce runtime security. Which combination of Microsoft Defender for Cloud features should you enable?

A.Microsoft Defender for Containers
B.Microsoft Defender for App Service
C.Microsoft Defender for Cloud regulatory compliance dashboard
D.Microsoft Defender for Servers
AnswerA

Defender for Containers is the dedicated plan that directly scans container images in ACR (and other registries) for vulnerabilities, provides Kubernetes runtime threat detection by analyzing audit logs and node telemetry, and gives by-pod recommendations and drift prevention. It is the only Microsoft Defender for Cloud plan that natively covers the full container lifecycle on AKS, including cluster, node, and workload visibility.

Why this answer

Microsoft Defender for Containers (option A) is correct because it is the Defender for Cloud plan specifically designed for Kubernetes and container workloads, providing image vulnerability scanning in registries and at deployment, plus runtime threat detection for AKS clusters via the Defender sensor and admission control. It also delivers Kubernetes-native hardening recommendations and attack-path analysis, matching both the pre-deployment scanning and runtime enforcement requirements. Microsoft Defender for App Service (option B) protects web apps and App Service plans, not container images or AKS runtime.

The regulatory compliance dashboard (option C) only reports against standards and does not perform vulnerability scanning or runtime protection. Microsoft Defender for Servers (option D) covers VMs and server OS workloads, not container image scanning or Kubernetes runtime security.

40
MCQeasy

Your company uses Microsoft Sentinel for security operations. You need to detect brute-force attacks against Azure VMs by correlating failed sign-in events from multiple sources. Which data connector should you enable?

A.Azure Active Directory (now Microsoft Entra ID) sign-in logs connector.
B.Syslog connector.
C.Windows Security Events via AMA (Azure Monitor Agent) connector.
D.Azure Activity log connector.
AnswerC

The Windows Security Events via AMA connector is purpose-built to stream Windows Security log entries, including Event ID 4625 (failed sign-in), from Azure VMs and other Windows machines. It uses Azure Monitor Agent (AMA) to collect specified security event IDs and send them to Sentinel, enabling near-real-time detection and investigation of brute-force or credential-stuffing attempts. This connector also supports filtering by event ID, so you can efficiently ingest only 4625 and other high-value security events without overwhelming log storage.

Why this answer

The Windows Security Events via AMA connector is correct because it collects Windows security event logs—including failed logon events (Event ID 4625)—from Azure VMs into Microsoft Sentinel, enabling correlation of brute-force attempts across multiple sources. The Azure Active Directory (Microsoft Entra ID) sign-in logs connector only ingests Entra ID authentication events, not local or VM-level Windows logon failures. The Syslog connector targets Linux/network device logs (e.g., via rsyslog) and does not capture Windows Security event data.

The Azure Activity log connector records Azure control-plane operations (resource changes), not sign-in or authentication events.

41
MCQmedium

You are designing a secure access solution for a manufacturing company's IoT devices that send telemetry to Azure IoT Hub. The devices run on a private network with no internet access except through a firewall. You need to ensure that device-to-cloud communication is authenticated and encrypted, and that device credentials are rotated regularly. What should you include in the design?

A.Configure Azure Firewall to authenticate and encrypt device traffic.
B.Use X.509 certificates with Azure Device Provisioning Service (DPS) for automatic enrollment and certificate rotation.
C.Use shared access signature (SAS) tokens with a central key management system.
D.Assign managed identities to each IoT device.
AnswerB

X.509 certificates, when integrated with Azure Device Provisioning Service (DPS), enable automatic enrollment of IoT devices and support certificate rotation through DPS's built-in lifecycle management. DPS uses the certificate's common name (CN) to map devices to IoT Hub identities, and you can configure certificate renewal by attaching new certificates to the same enrollment group or individual enrollment. This meets all three requirements—authentication, encryption (via TLS with the certificate), and automated rotation—without manual per-device intervention.

Why this answer

Option B is correct because X.509 certificates provide mutual TLS authentication and encryption for device-to-cloud traffic to IoT Hub, and Azure Device Provisioning Service (DPS) supports automatic enrollment plus certificate rotation workflows (for example, via enrollment groups and rolling certificate updates), which directly meets the requirement for regularly rotated device credentials. Azure Firewall (A) is a network security control and does not authenticate or encrypt IoT device application traffic end-to-end. SAS tokens (C) can authenticate devices but are symmetric shared secrets that are harder to rotate safely at scale and do not provide the same certificate-based identity lifecycle as DPS-managed X.509.

Managed identities (D) are for Azure resources accessing Azure services and cannot be assigned to external IoT devices.

42
MCQeasy

Your company is deploying Microsoft Sentinel to centralize security logs from Azure, on-premises, and other clouds. You need to ensure logs are ingested cost-effectively while maintaining search performance for the last 30 days. What should you configure?

A.Store logs in Azure Blob Storage and use Azure Data Explorer for queries.
B.Use Log Analytics workspace with 30-day interactive retention and set long-term retention for older data.
C.Use Sentinel's free tier for 30 days and then move to paid tier.
D.Ingest logs into Azure Event Hubs and then into Sentinel.
AnswerB

A Log Analytics workspace with 30-day interactive retention provides Sentinel-native KQL query performance for the most recent month of security data, while long-term retention (archiving) keeps older telemetry in the same workspace at a lower storage cost without losing access—you can run search jobs to triage historical events. This configuration aligns with Sentinel’s architecture: Log Analytics is the underlying data store, interactive retention is optimized for frequent incident-hunting queries, and archived data remains queryable when needed, balancing cost and operational efficiency.

Why this answer

Option B is correct because Microsoft Sentinel stores ingested data in a Log Analytics workspace, where the interactive retention setting controls how long data remains available for fast KQL queries and analytics rules. Setting 30-day interactive retention satisfies the search-performance requirement for the last 30 days, while configuring long-term retention for older data keeps historical logs at a lower cost. The other options do not fit: Azure Blob Storage with Azure Data Explorer (A) is not Sentinel's native ingestion and query path, Sentinel has no 30-day free tier that then converts to paid (C), and Event Hubs (D) is only an ingestion pipeline, not a retention or query configuration.

43
MCQmedium

Your company plans to use Microsoft Sentinel to detect threats across multiple Azure subscriptions. You need to design a cost-effective solution that ingests logs from all subscriptions. What should you use?

A.Use Azure Lighthouse to manage cross-subscription connectivity
B.Deploy a single Sentinel workspace and configure data collection rules to collect logs from all subscriptions
C.Create a separate Sentinel workspace for each subscription
D.Use Azure Policy to assign a Log Analytics workspace to each subscription
AnswerB

A single Microsoft Sentinel workspace, deployed once in a Log Analytics workspace, can serve as the central aggregation point for all subscriptions by configuring data collection rules (DCRs) and diagnostic settings to route resource logs, activity logs, and security signals into that one workspace. This design minimizes cost by avoiding duplicate ingestion and separate retention, simplifies querying and incident correlation across the entire environment, and allows you to manage one set of analytics rules, workbooks, and automation. For example, you can use Azure Policy to ensure all subscriptions apply the same DCR, pointing to the central workspace, thus combining enforcement with truly centralized ingestion.

Why this answer

Option B is correct because Microsoft Sentinel is built on a Log Analytics workspace, and a single workspace can ingest data from multiple Azure subscriptions via data collection rules (DCRs) and diagnostic settings, avoiding duplicated workspace and Sentinel costs. This centralized design is the most cost-effective since Sentinel pricing (ingestion and retention) applies per workspace, so consolidating into one workspace prevents paying for multiple Sentinel instances. Azure Lighthouse (A) is for delegated resource management across tenants, not for log ingestion into Sentinel.

Creating a separate workspace per subscription (C) multiplies Sentinel and Log Analytics costs and fragments detection. Azure Policy (D) can assign a workspace via DeployIfNotExists, but assigning a workspace per subscription still results in multiple workspaces rather than the single cost-effective workspace the scenario requires.

44
MCQeasy

Your company uses Azure Virtual Machines (VMs) running Windows Server. You need to ensure that only approved applications can run on the VMs. Which Azure security feature should you use?

A.Azure Firewall
B.Azure Policy with application control
C.Microsoft Defender for Cloud
D.Just-in-Time VM access
AnswerB

Azure Policy with application control is the correct choice because it can enforce host-level application allowlisting on Azure VMs through Windows Defender Application Control (WDAC) or AppLocker via custom policy definitions. These policies are assigned across management groups or subscriptions, and they evaluate and enforce which executables are allowed to run, denying everything else. Since Azure Policy continuously audits and can remediate noncompliant resources, it provides the necessary governance and enforcement mechanism required for application control.

Why this answer

Azure Policy with application control is correct because it lets you enforce that only approved applications run on your Windows Server VMs by using the Guest Configuration extension to audit or deploy Windows Defender Application Control (WDAC) / AppLocker policies at scale. This directly addresses the requirement to restrict execution to approved applications. Azure Firewall (A) filters network traffic, not which applications execute on the VM.

Microsoft Defender for Cloud (C) provides security posture and threat protection but does not itself enforce an application allowlist. Just-in-Time VM access (D) restricts inbound management ports, not application execution.

45
MCQhard

You are designing a security solution for an Azure Kubernetes Service (AKS) cluster that runs containerized workloads. The cluster must be integrated with Microsoft Defender for Cloud for threat detection, and you need to ensure that container images are scanned for vulnerabilities before deployment. What should you configure?

A.Enable Microsoft Defender for Cloud Apps to discover and assess container vulnerabilities.
B.Deploy Azure Policy for Kubernetes with built-in policies to enforce image scanning.
C.Enable Azure Defender for Containers in Microsoft Defender for Cloud and integrate with Azure Container Registry for image scanning.
D.Configure Microsoft Sentinel to collect container logs and detect vulnerabilities.
AnswerC

Enable Azure Defender for Containers in Microsoft Defender for Cloud, which natively integrates with Azure Container Registry to provide vulnerability assessment for AKS workloads. When this option is enabled, Defender for Cloud scans every image in ACR using a Qualys-based scanner, which detects OS and package-level CVEs and provides remediation recommendations. This is the only option that directly provides image vulnerability scanning for containers, and it also adds runtime threat detection for AKS clusters, making it the correct and comprehensive answer for the security solution design.

Why this answer

The correct option is C: enabling Azure Defender for Containers in Microsoft Defender for Cloud and integrating it with Azure Container Registry provides native vulnerability scanning of container images and threat detection for AKS workloads. Defender for Containers specifically includes image scanning in ACR (on push and periodic rescanning) and surfaces findings in Defender for Cloud, which matches the requirement to scan images before deployment. Option A is wrong because Microsoft Defender for Cloud Apps is a CASB for SaaS discovery and governance, not container image scanning.

Option B is wrong because Azure Policy for Kubernetes enforces configuration and admission controls but does not itself perform vulnerability scanning of images. Option D is wrong because Microsoft Sentinel is a SIEM/SOAR platform for log collection and analytics, not an image vulnerability scanner.

46
MCQhard

Your organization is designing a secure network infrastructure for a multi-cloud environment that includes Azure, AWS, and on-premises datacenters. The security team requires that all traffic between these environments be inspected for threats and that any malicious traffic be automatically blocked. The solution must minimize complexity and use a single pane of glass for policy management. Which Azure service should you use as the central hub?

A.Azure Front Door
B.Network Security Groups (NSGs)
C.Azure DDoS Protection
D.Azure Firewall
AnswerD

Azure Firewall is a fully stateful, centrally managed firewall-as-a-service that provides both network and application-level filtering (including FQDN rules and threat intelligence) for Azure virtual networks and hybrid connections over ExpressRoute or VPN. Deployed in a hub virtual network, it can inspect all inter-environment traffic via user-defined routes and forced tunneling, with native integration into Azure Monitor for centralized logging and alerting. This combination of centralized policy management, advanced inspection, and hybrid/multi-cloud applicability makes it the correct choice for a secure network infrastructure.

Why this answer

Azure Firewall (option D) is the correct choice because it provides a centralized, cloud-native firewall service that can inspect and filter traffic across Azure, AWS, and on-premises connections through a hub-and-spoke or Virtual WAN topology, with a single management plane via Azure Firewall Manager for policy and threat intelligence-based blocking. It supports FQDN filtering, threat intelligence, and IDPS, making it suitable for multi-cloud traffic inspection and automatic malicious traffic blocking while minimizing complexity. Azure Front Door (A) is a global HTTP/HTTPS load balancer and WAF for web applications, not a general network traffic inspection hub for multi-cloud and on-premises traffic.

Network Security Groups (B) are stateful packet filters at the subnet/NIC level with no central management pane or advanced threat inspection. Azure DDoS Protection (C) only mitigates volumetric DDoS attacks against Azure resources and does not inspect or block general malicious traffic across hybrid and multi-cloud environments.

47
Multi-Selecteasy

Which TWO of the following are features of Microsoft Defender for Cloud that help secure infrastructure? (Choose two.)

Select 2 answers
A.Secure Score
B.Incident investigation
C.Just-in-time VM access
D.Privileged Identity Management
E.User and Entity Behavior Analytics (UEBA)
AnswersA, C

Secure Score is a core feature of Microsoft Defender for Cloud that aggregates security findings and provides a numeric score based on the implementation of security controls and best practices. It helps organizations prioritize remediation actions by comparing current posture against benchmarks like Azure Security Benchmark and CIS. The score reflects the percentage of healthy security recommendations, and improving it directly reduces attack surface across compute, network, storage, and identity resources. It is not a separate product but an actionable dashboard within Defender for Cloud's Cloud Security Posture Management (CSPM) capability.

Why this answer

Secure Score (A) is a core Microsoft Defender for Cloud capability that continuously assesses your Azure resources and subscriptions against security recommendations and benchmarks, aggregating the results into a numeric score so you can prioritize hardening actions for your infrastructure. Just-in-time (JIT) VM access (C) is also a Defender for Cloud feature that reduces the attack surface of virtual machines by blocking inbound management ports (RDP 3389, SSH 22) by default and opening them only for approved, time-limited requests from authorized IPs. Both directly serve Defender for Cloud's mission of strengthening and monitoring infrastructure security posture.

Incident investigation (B) and User and Entity Behavior Analytics (E) are capabilities of Microsoft Sentinel (the SIEM/SOAR solution), not Defender for Cloud. Privileged Identity Management (D) is a separate Microsoft Entra ID (Azure AD) service for just-in-time privileged role activation and access reviews, not a Defender for Cloud infrastructure feature.

Exam trap

The trap here is that candidates confuse Defender for Cloud's posture management features (Secure Score, JIT) with Microsoft Sentinel's investigation and analytics capabilities (Incident investigation, UEBA), or with Azure AD's identity governance features (PIM), because all are part of the Microsoft security portfolio but serve distinct roles.

48
MCQeasy

You are designing a secure access solution for an Azure Kubernetes Service (AKS) cluster that hosts a critical application. You need to ensure that only authorized users can access the Kubernetes API server. Which authentication method should you use?

A.Use Kubernetes service account tokens.
B.Use AKS managed identities for each user.
C.Use Azure RBAC for Kubernetes authorization.
D.Integrate AKS with Microsoft Entra ID for authentication.
AnswerD

AKS can be integrated with Microsoft Entra ID so that the Kubernetes API server delegates authentication to the Entra ID tenant. Users obtain an Entra ID token (e.g., via device code or OIDC) and present it to the API server; the server validates the token and maps the user to a cluster role. This solves the problem of managing separate Kubernetes identities for each human user, provides multi-factor authentication, conditional access, and centralized lifecycle management, and enables per-user auditing. Without this integration, AKS simply can't natively authenticate human users to the API server, so this is the correct approach for a secure access solution centered on user authentication.

Why this answer

The correct option is D: integrate AKS with Microsoft Entra ID for authentication, because this scenario requires authenticating human users who access the Kubernetes API server, and Entra ID integration provides centralized identity-based authentication with conditional access, MFA, and group-based access. AKS supports Entra ID integration so that kubectl and other clients obtain Entra ID tokens that the API server validates, ensuring only authorized users can authenticate. Option A is not suitable because service account tokens are for workloads and automation inside the cluster, not for authenticating external users.

Option B is incorrect because managed identities are Azure resource identities for services, not per-user Kubernetes API authentication. Option C is incorrect because Azure RBAC for Kubernetes authorization controls what an already-authenticated principal can do, not how users are authenticated.

49
MCQhard

A financial services company is designing a secure infrastructure for their Azure SQL Database. They need to encrypt data at rest using customer-managed keys (CMK) stored in a key vault with soft-delete and purge protection enabled. The encryption must be transparent to applications. What should they configure?

A.Azure Information Protection
B.Dynamic Data Masking
C.Always Encrypted
D.Transparent Data Encryption (TDE) with Azure Key Vault
AnswerD

Transparent Data Encryption (TDE) with Azure Key Vault is the correct choice because it performs real-time encryption and decryption of the entire database, including backups and transaction logs, at the storage layer. Using customer-managed keys in Azure Key Vault provides advanced key control and separation of duties, satisfying compliance requirements without requiring any application changes. TDE is a transparent, whole-database encryption solution ideales for financial services environments.

Why this answer

Azure SQL Database supports Transparent Data Encryption (TDE) with CMK in Azure Key Vault. Always Encrypted is for column-level encryption. Dynamic Data Masking is for masking, not encryption.

Azure Information Protection is for classification.

50
Multi-Selectmedium

Which TWO of the following are valid methods to secure Azure Kubernetes Service (AKS) workloads?

Select 2 answers
A.Integrate Azure AD for cluster authentication
B.Apply Network Security Groups to pod subnets
C.Deploy Azure Firewall in front of the AKS cluster
D.Use Azure Front Door to protect API endpoints
E.Use Azure Policy with Azure Policy for AKS (Gatekeeper)
AnswersA, E

Integrating Azure AD for AKS cluster authentication authenticates Kubernetes identities against Azure AD, enabling identity-based access control. It supports assigning Kubernetes RBAC roles to Azure AD users, groups, or service principals, and allows conditional access policies to protect the cluster API server. This provides a control-plane security mechanism that centrally manages access and audits via Azure AD sign-in logs, rather than relying on local Kubernetes accounts.

Why this answer

Option A is correct because integrating Azure Active Directory (Azure AD) with AKS enables cluster authentication and authorization via Azure RBAC, allowing you to control who can access the Kubernetes API server and manage workloads using identity-based controls rather than static credentials. Option E is correct because Azure Policy for AKS uses the Gatekeeper admission controller (Open Policy Agent) to enforce policies on pods and cluster resources at admission time, preventing non-compliant workloads from being deployed and thus hardening the workload configuration. Option B is not the intended answer because Network Security Groups apply at the subnet/NIC level for network traffic filtering, not specifically for securing AKS workloads at the pod or admission level, and pod-level security typically uses Kubernetes Network Policies.

Option C is not correct in this context because Azure Firewall provides network perimeter protection and egress filtering but does not directly secure AKS workloads themselves. Option D is not correct because Azure Front Door is a global HTTP/HTTPS load balancer and WAF for web applications, not a mechanism for securing AKS workloads internally.

51
MCQhard

Your company is migrating to a cloud-native security operations center (SOC) using Microsoft Sentinel. You need to design a solution that automatically investigates and remediates common incidents like brute-force attacks on Azure VMs. The solution should use playbooks triggered by analytics rules. Which Microsoft service should you use to create the playbooks, and what is the recommended authentication method?

A.Power Automate with user account
B.Azure Automation with service principal
C.Azure Logic Apps with managed identity
D.Azure Functions with API key
AnswerC

Azure Logic Apps is the underlying service for Sentinel playbooks, offering a native Microsoft Sentinel trigger that provides incident context to workflow actions. When a Logic Apps workflow uses a managed identity, it accesses Azure AD-protected resources without storing secrets, simplifying credential management and enabling granular role assignments; this aligns with cloud-native security principles and is the recommended authentication model.

Why this answer

Azure Logic Apps is the recommended platform for Sentinel playbooks. Managed identity is the preferred authentication method because it avoids credential management and supports automation. Azure Automation is for runbooks, not playbooks.

Service principal is possible but not recommended due to credential management.

52
MCQmedium

Refer to the exhibit. You are reviewing an Azure Policy definition. What does this policy accomplish?

A.Requires that all network security rules have destination port range between 22 and 3389
B.Denies all inbound traffic except SSH and RDP
C.Allows only SSH and RDP inbound traffic
D.Denies creation of network security rules that allow traffic to ports other than 22 and 3389
AnswerD

This is correct because the policy definition uses the 'deny' effect on Microsoft.Network/networkSecurityGroups/securityRules whose destinationPortRange or destinationPortRanges include values not in ['22', '3389']. When a user or service attempts to create or update an NSG rule that permits traffic to any port other than 22 or 3389, the Resource Manager deployment is rejected before the rule is applied, making it impossible to add such a rule to an NSG. The policy does not, however, automatically delete existing noncompliant rules; it applies at deployment time, so already-existing rules that violate the condition remain until manually changed or removed.

Why this answer

The correct option is D: the policy denies creation of network security rules that allow traffic to ports other than 22 and 3389. Azure Policy definitions with a deny effect evaluate the properties of a resource being deployed—here, the destinationPortRange of a network security rule—and block the deployment when the condition is met, so rules permitting any port outside 22 and 3389 are rejected. Option A is wrong because the policy does not require ports to fall within a range; it blocks rules that allow ports other than the two specified.

Option B is wrong because the policy targets NSG rule definitions in Azure Resource Manager, not live inbound traffic flows. Option C is wrong because the policy does not permit or allow traffic; it only denies noncompliant rule creation.

53
MCQmedium

You are designing a hybrid identity solution for an organization that uses Microsoft Entra ID and an on-premises Active Directory. The organization requires that users who are located in a remote office without a direct VPN connection to the main office can authenticate against on-premises resources using their Entra ID credentials. The solution must minimize latency and support passwordless authentication. Which feature should you implement?

A.Configure Microsoft Entra Application Proxy
B.Implement Microsoft Entra Kerberos authentication
C.Enable Microsoft Entra Conditional Access policies
D.Deploy Microsoft Entra Connect Sync with password hash synchronization
AnswerB

Implement Microsoft Entra Kerberos authentication is the correct approach because it lets Entra ID issue a Kerberos ticket-granting ticket (TGT) for a synchronized user, enabling access to on-premises Kerberos-protected resources without the user authenticating directly against local Active Directory. This works with passwordless credentials such as FIDO2 security keys and Windows Hello for Business, and it reduces latency by avoiding a separate on-premises authentication round-trip. The Entra ID instance effectively acts as a cloud-based KDC, but it still relies on on-premises domain controllers to issue service tickets.

Why this answer

Microsoft Entra Kerberos authentication enables users to authenticate to on-premises resources using their Entra ID credentials without requiring a VPN, and it supports passwordless methods like FIDO2 and Windows Hello for Business. Option A is incorrect because Entra Application Proxy is designed for publishing on-premises web applications, not for general authentication. Option C is incorrect because Conditional Access policies enforce access controls but do not provide authentication or passwordless capabilities.

Option D is incorrect because Entra Connect Sync with password hash synchronization only syncs password hashes and does not support real-time passwordless authentication without a VPN.

54
MCQeasy

A small business uses Microsoft 365 Business Premium and wants to secure their Windows 10 devices with Microsoft Intune. They need to ensure that only devices compliant with the company's security policies can access corporate email. What should they configure?

A.Azure AD Application Proxy
B.Windows Defender Firewall rules
C.Microsoft Defender for Cloud Apps session policy
D.Conditional Access policy requiring compliant device
AnswerD

A Conditional Access policy requiring a compliant device blocks sign-in from devices that are not Intune-enrolled and verified against compliance policies, such as requiring disk encryption or an up-to-date OS. When the user attempts to access Exchange Online, Azure AD evaluates the device's compliance claim from Intune and either grants, blocks, or triggers remediation in real time. For Microsoft 365 Business Premium, Intune is included, so this is the appropriate mechanism to prevent non-compliant devices from reading email.

Why this answer

Conditional Access in Microsoft Entra ID can require device compliance before granting access to Exchange Online. Device compliance policies in Intune define the security requirements. Azure AD Application Proxy is for on-prem apps.

Microsoft Defender for Cloud Apps is for cloud app security. Windows Defender Firewall is for network security.

55
MCQmedium

You are the security architect for a company that uses Azure Virtual Machines (VMs) running Windows Server and Linux. The company has a regulatory requirement that all VM disks must be encrypted at rest, including temporary disks and disk caches. You need to recommend a solution that meets the requirement and minimizes administrative overhead. What should you recommend?

A.Enable Azure Disk Encryption (ADE) on each VM.
B.Use Azure Storage Service Encryption (SSE) for all VM disks.
C.Configure BitLocker on Windows VMs and DM-Crypt on Linux VMs.
D.Enable encryption at host for all VMs.
AnswerD

Encryption at host encrypts all data written to the VM, including temporary disks and disk caches, at the host level. It is enabled per VM or VM scale set and does not require managing encryption keys inside the guest OS, reducing administrative overhead. This meets the requirement for all disks and caches to be encrypted at rest.

Why this answer

Encryption at host is the only option that encrypts all VM data, including temporary disks and disk caches, at the host level. It requires no guest OS configuration and simplifies key management compared to Azure Disk Encryption. The other options either do not cover temporary disks and caches or add unnecessary administrative complexity.

Exam trap

The trap here is confusing Azure Disk Encryption with encryption at host, assuming both cover temporary disks and caches.

56
MCQhard

Refer to the exhibit. You are deploying an ARM template for a Windows VM. The adminPassword parameter references a secret in Key Vault. However, the deployment fails with an access denied error. What is the most likely cause?

A.The secret value contains special characters that need to be escaped.
B.The template should use the secret's URI directly instead of a parameter reference.
C.The deployment principal lacks 'Get' and 'List' permissions on the Key Vault secret.
D.The Key Vault is in a different resource group than the deployment.
AnswerC

The ARM template engine uses the deployment principal's Azure AD token to authenticate to Key Vault and must have `Get` and `List` permissions on the referenced secret; `List` is required to resolve the latest version when no specific version is provided, and `Get` is required to actually read the secret value. Without these in the Key Vault access policy (or RBAC role), the deployment returns an `AccessDenied` error. This is precisely the condition seen in the exhibit, where the template and parameter file are syntactically correct but the deployment fails.

Why this answer

When referencing a Key Vault secret in an ARM template parameter, the user or service principal deploying the template must have 'Get' and 'List' permissions on the secret. If the deployment principal does not have those permissions, access is denied. Option A is wrong because special characters in secrets are supported, but the deployment still requires permissions.

Option B is wrong because the template uses a parameter reference to the secret, not the secret's URI directly; that is the correct approach. Option D is wrong because the Key Vault can be in a different resource group than the deployment, as long as the deployment principal has the necessary permissions.

57
MCQhard

You are designing a security solution for Azure API Management. The requirements include: protecting APIs from abuse, throttling requests, and validating JSON payloads. Which combination of features should you use?

A.Managed Identities and Azure AD authentication
B.Azure Web Application Firewall (WAF) on Application Gateway
C.Rate limiting policies, validate-json policy, and OAuth 2.0
D.Azure Firewall and Network Security Groups
AnswerC

The correct combination applies API Management inbound policies in sequence: rate-limit or quota policies throttle requests per subscription, key, or IP address; validate-json verifies the JSON request body against a defined schema and rejects malformed payloads; and OAuth 2.0 with validate-jwt ensures access tokens are signed, unexpired, and carry the required scopes. Together these policies directly satisfy throttling, validation, and secure access control at the API gateway level.

Why this answer

Option C is correct because API Management natively provides rate limiting and quota policies to throttle requests and protect against abuse, the validate-json policy to validate JSON payloads against a schema, and OAuth 2.0 support to secure API access via authorization servers. These features directly satisfy the stated requirements within the APIM gateway itself. Option A addresses identity and authentication but does not provide throttling or JSON schema validation.

Option B offloads protection to Application Gateway WAF, which handles web attack patterns but not APIM-level rate limiting or JSON payload schema validation. Option D provides network-layer filtering with Azure Firewall and NSGs, which cannot inspect JSON payloads or apply API-level throttling.

58
MCQhard

Refer to the exhibit. You run the PowerShell command against an Azure SQL Database. The command returns a baseline object for rule VA2108. What does this indicate about the database's vulnerability assessment configuration?

A.The vulnerability assessment scan is automatically remediating findings for rule VA2108
B.The security team has approved the current state of rule VA2108 as acceptable
C.Vulnerability assessment is disabled for this database
D.The database has no vulnerability findings
AnswerB

When you set a baseline, you are formally recording the security team's decision that the current state of the rule is an accepted risk. The PowerShell cmdlet stores the current scan result for VA2108 as the expected baseline for future scans, so any deviation from this approved configuration would be flagged. It is a governance process of waiver approval, not a technical remediation.

Why this answer

The correct answer is B: the security team has approved the current state of rule VA2108 as acceptable. In Azure SQL Database vulnerability assessment, a baseline object returned for a rule such as VA2108 means a baseline has been set for that rule, which records the current scan results as the accepted/approved state so those results are no longer flagged as findings. It does not mean automatic remediation is occurring, so A is wrong; vulnerability assessment being disabled would prevent baseline objects from being returned, so C is wrong; and a baseline does not mean there are no findings, only that the baselined results are treated as acceptable, so D is wrong.

59
MCQmedium

You are designing a security solution for containers running on Azure Kubernetes Service (AKS). The requirements include: scanning container images for vulnerabilities, enforcing runtime security, and generating alerts for suspicious activities. Which combination of services should you use?

A.Azure Security Center and Azure Policy
B.Azure Container Registry and Azure Monitor
C.Azure Policy and Azure Firewall
D.Microsoft Defender for Cloud with Defender for Containers plan
AnswerD

Microsoft Defender for Cloud with the Defender for Containers plan is purpose-built for container security, offering continuous image vulnerability scanning, runtime threat detection using eBPF and audit logs, and Kubernetes hardening all in one solution. It detects suspicious activities like privilege escalations, cryptocurrency mining, or unauthorized cross-namespace communication and raises alerts with automated response capabilities. This plan fully addresses both pre-deployment image risks and post-deployment runtime security, matching the question's requirement for alerts and real-time protection.

Why this answer

Microsoft Defender for Cloud with the Defender for Containers plan (option D) is correct because it is the purpose-built Azure solution that provides image vulnerability scanning (via the integrated Qualys/registry scanner), runtime threat detection using the Defender sensor on AKS nodes, and security alerts for suspicious container activity in a single integrated service. It also supports Kubernetes-native hardening recommendations and integrates with AKS and Azure Container Registry out of the box. Option A is incomplete because Azure Security Center is the former name of Defender for Cloud and Azure Policy alone only enforces governance, not runtime detection or image scanning.

Option B does not fit because Azure Container Registry only stores images and Azure Monitor provides telemetry, not vulnerability scanning or container threat alerts. Option C is incorrect because Azure Policy and Azure Firewall address compliance and network filtering, not image scanning or runtime container security.

60
MCQmedium

You are designing a security solution for Azure Kubernetes Service (AKS). You need to ensure that only authorized container images from a private container registry can run in the cluster. What should you configure?

A.Use Azure Policy to enforce that containers run only from allowed registries.
B.Implement Azure Container Registry tasks to scan images.
C.Configure network policies in AKS to block outbound traffic to public registries.
D.Enable Microsoft Defender for Containers to block unauthorized images.
AnswerA

Azure Policy's built-in 'Ensure only allowed container images' initiative works with the Azure Policy add-on for AKS, which installs Gatekeeper as a validating admission webhook. At pod creation or update, the policy evaluates the image repository against an allowed list of fully qualified registry names, rejecting any non-conforming pod spec before it is persisted to etcd. This provides deterministic, cluster-wide, preventive enforcement rather than relying on runtime detection or network filtering.

Why this answer

Azure Policy is the correct choice (A) because it can enforce admission-time constraints on an AKS cluster, such as an allowed-registries policy that denies pods whose images do not originate from the specified private Azure Container Registry. This directly satisfies the requirement that only authorized images from a private registry can run. Option B is incorrect because ACR Tasks scan images for vulnerabilities but do not restrict which registries pods may pull from.

Option C is incorrect because network policies control pod-level traffic, not image provenance, and blocking outbound traffic does not enforce registry allowlisting. Option D is incorrect because Microsoft Defender for Containers provides threat detection and posture management, not admission control that blocks unauthorized images.

61
MCQhard

Your company is designing a Zero Trust network for a hybrid workforce. Remote users connect via VPN to on-premises resources, while cloud apps use Microsoft Entra ID. You need to enforce conditional access based on device compliance and user risk. Which Microsoft security solution should you integrate with Entra ID to provide real-time device posture signals?

A.Microsoft Purview
B.Microsoft Intune
C.Microsoft Defender for Cloud Apps
D.Microsoft Sentinel
AnswerB

Microsoft Intune supplies real-time device compliance and posture signals directly into Microsoft Entra ID conditional access policies, satisfying the requirement to evaluate device state alongside user risk. Its compliance engine continuously reports encryption, OS patch level and jailbreak status, enabling hybrid workers on VPN and cloud apps to be granted or blocked access per Zero Trust policy.

Why this answer

Microsoft Intune provides device compliance policies and can send device posture signals to Entra ID Conditional Access. With Intune, you can enforce device health and compliance requirements before granting access. Option A is wrong because Microsoft Purview focuses on data governance and compliance, not device management.

Option C is wrong because Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) and does not directly manage device compliance. Option D is wrong because Microsoft Sentinel is a security information and event management (SIEM) solution and does not provide device posture signals.

62
MCQhard

You are designing a secure access strategy for a manufacturing plant using Azure IoT Hub and Azure Defender for IoT. The plant has unpatched legacy PLCs that cannot be updated. What is the best approach to prevent these devices from being compromised and used as an entry point into the corporate network?

A.Use Azure VPN Gateway to connect PLCs to the virtual network.
B.Implement network micro-segmentation using Azure Firewall and NSGs to isolate the PLCs from the corporate network.
C.Install the Microsoft Defender for IoT micro-agent on each PLC.
D.Enforce TLS 1.2 for all PLC communications.
AnswerB

Micro-segmentation with Azure Firewall and NSGs is a compensating control that works even when PLCs cannot be patched or updated. By placing PLCs in a dedicated subnet, applying NSG rules to deny inbound/outbound traffic except allowed industrial protocols, and centralizing policy in Azure Firewall, you enforce least-privilege communication. This containment limits the blast radius so a compromised PLC cannot reach corporate systems or other OT zones.

Why this answer

The correct option is B: implementing network micro-segmentation with Azure Firewall and NSGs to isolate the PLCs from the corporate network. Since the legacy PLCs cannot be patched, the most effective mitigation is to limit their attack surface and blast radius by placing them in a segmented network zone with strict allow-list rules, so a compromised PLC cannot pivot laterally into corporate systems. Azure Firewall provides centralized Layer 3–7 filtering and NSGs enforce subnet/NIC-level traffic control, which directly addresses the unpatched-device risk.

Option A is wrong because a VPN gateway only provides encrypted connectivity, not isolation or traffic restriction. Option C is wrong because the Defender for IoT micro-agent requires installation and support on the device, which unpatched legacy PLCs typically cannot accommodate. Option D is wrong because TLS 1.2 only protects data in transit and does not prevent compromise or lateral movement from an unpatched PLC.

63
Multi-Selecthard

Your organization is implementing Microsoft Defender for Identity to protect on-premises Active Directory. Which THREE activities does Defender for Identity monitor?

Select 3 answers
A.Privilege escalation attempts
B.Lateral movement paths using Pass-the-Hash
C.File integrity changes on domain controllers
D.Reconnaissance attacks using LDAP queries
E.Network traffic to external IP addresses
AnswersA, B, D

Defender for Identity monitors domain controller traffic for privilege escalation attempts, detecting techniques such as adding accounts to privileged groups or exploiting unpatched escalation paths, which satisfies the stem's requirement to identify on-premises Active Directory attack activity.

Why this answer

Defender for Identity is designed to detect advanced threats against on-premises Active Directory by analyzing signals from domain controllers and AD FS. Option A is correct because it identifies privilege escalation attempts, such as unauthorized additions to privileged groups or abuse of AdminSDHolder, by monitoring directory changes and authentication events. Option B is correct because it detects lateral movement techniques like Pass-the-Hash by correlating NTLM authentication anomalies and suspicious logon patterns across domain controllers.

Option D is correct because it flags reconnaissance attacks that use LDAP queries to enumerate users, groups, and privileged accounts, which is a common precursor to AD attacks. Option C is not correct because file integrity monitoring on domain controllers is not a Defender for Identity capability; that is handled by other tools such as Microsoft Defender for Endpoint or File Integrity Monitoring in Defender for Cloud. Option E is not correct because Defender for Identity focuses on identity and directory signals rather than monitoring outbound network traffic to external IP addresses, which is covered by network security solutions.

Exam trap

SC-100 often tests the boundary between Defender for Identity (identity/AD attack detection) and Defender for Servers/Endpoint (file integrity, host monitoring) — candidates pick file integrity or network monitoring because those sound security-relevant but belong to other products.

64
MCQeasy

Your organization is deploying a new application on Azure Kubernetes Service (AKS). You need to ensure that only authorized containers can run in the cluster and that any unauthorized containers are automatically blocked. What should you configure?

A.Implement network policies to restrict communication between pods.
B.Apply an Azure Policy that restricts container images to only those from approved registries.
C.Enable Azure AD integration for the AKS cluster.
D.Configure Azure RBAC roles to limit who can deploy containers.
AnswerB

Azure Policy for AKS integrates with the Gatekeeper admission controller, enabling enforcement of built-in policies such as 'Ensure only allowed container images'. At pod creation or update time, the admission webhook evaluates each container's image repository and rejects any deployment that references a registry not on the approved list. This is a preventive control at the point of scheduling, directly addressing the requirement to restrict container images to approved registries only.

Why this answer

The correct option is B: applying an Azure Policy that restricts container images to only those from approved registries. Azure Policy for AKS uses the Gatekeeper admission controller to evaluate requests against policy definitions at admission time, so any pod or deployment referencing a non-approved image is automatically denied and blocked from running in the cluster. This directly enforces the requirement that only authorized containers can run.

Option A does not fit because network policies only control pod-to-pod traffic, not which images are allowed to run. Option C does not fit because Azure AD integration handles authentication of users to the cluster, not image authorization. Option D does not fit because Azure RBAC controls who can perform deployment actions, but it does not validate or block unauthorized container images.

65
Multi-Selecteasy

Which TWO features of Microsoft Defender for Cloud help you identify and remediate misconfigurations in your Azure environment? (Choose two.)

Select 2 answers
A.File integrity monitoring (FIM).
B.Security recommendations.
C.Just-in-time (JIT) VM access.
D.Adaptive application controls.
E.Secure score.
AnswersB, E

Security recommendations are Defender for Cloud's core mechanism for surfacing misconfigurations and insecure settings in supported resources, such as VMs, storage accounts, and databases. Each recommendation results from a policy-driven assessment against Azure Security Benchmark, CIS, or other standards, and includes affected resources, impact, and remediation steps. They directly answer the question 'what is misconfigured?' and are the underlying data that drives the secure score, making them the primary feature for identifying configuration errors.

Why this answer

Security recommendations (B) is correct because Microsoft Defender for Cloud continuously assesses Azure resources against built-in and regulatory benchmarks (e.g., Azure Security Benchmark, CIS, PCI DSS) and surfaces specific, actionable remediation steps for each misconfiguration it detects. Secure score (E) is correct because it aggregates the results of those assessments into a measurable score and highlights the highest-impact misconfigurations and improvement actions, letting you prioritize and track remediation progress over time. Together, recommendations identify the misconfigurations and secure score quantifies and prioritizes them.

File integrity monitoring (A) is wrong because FIM detects changes to critical OS files and registry keys on VMs, not Azure resource misconfigurations. Just-in-time VM access (C) is wrong because it reduces the attack surface by opening management ports only on demand, rather than identifying configuration issues. Adaptive application controls (D) is wrong because it uses machine-learning allowlists to control which applications can run on VMs, which is workload protection, not misconfiguration assessment.

66
Multi-Selecteasy

Which TWO Azure services should you use to implement a defense-in-depth strategy for protecting Azure virtual machines?

Select 2 answers
A.Network Security Groups (NSGs)
B.Azure Logic Apps
C.Azure Backup
D.Azure Automation
E.Azure Front Door
AnswersA, C

Network Security Groups (NSGs) are stateful packet-filtering controls that protect Azure virtual networks by enforcing allow/deny rules on inbound and outbound traffic to subnets and NICs. They operate at layers 3 and 4, matching source/destination IPs, ports, and protocols, with a default-deny rule at the end. NSGs provide essential network segmentation and perimeter defense, forming a fundamental preventive layer in a defense-in-depth strategy against lateral movement and unauthorized access.

Why this answer

Network Security Groups (NSGs) are correct because they enforce network-layer defense-in-depth by filtering inbound and outbound traffic to and from Azure VMs using allow/deny security rules based on source/destination IP, port, and protocol, effectively segmenting and restricting access at the subnet or NIC level. Azure Backup is correct because it provides the data-recovery layer of defense-in-depth, protecting VM data against accidental deletion, corruption, or ransomware by creating recoverable recovery points stored in a Recovery Services vault. Azure Logic Apps is not a security control for VMs; it is a workflow-orchestration service for integrating apps and automating business processes.

Azure Automation is a configuration-management and process-automation service (runbooks, DSC, update management) and does not itself provide a protective security boundary for VM traffic or data. Azure Front Door is a global layer-7 web application delivery and CDN/WAF service for HTTP/HTTPS workloads, not a mechanism for protecting Azure VMs directly.

67
MCQeasy

Your organization uses Microsoft Intune to manage endpoints. The security team wants to ensure that devices that cannot be enrolled in Intune (e.g., unmanaged BYOD devices) are still subject to security policies when accessing corporate resources. Which Microsoft Entra ID feature should you use?

A.Microsoft Entra Conditional Access policies
B.Microsoft Intune enrollment policies
C.Windows Defender Application Control
D.Microsoft Defender for Endpoint
AnswerA

Microsoft Entra Conditional Access is the correct policy layer because it acts as the decision engine that evaluates the full signal stack—user, application, device compliance, location, and risk—to enforce access controls like requiring MFA, requiring a compliant device, or blocking unmanaged endpoints. Under the hood, Conditional Access policies can leverage Intune compliance rules as one input, but its true power is that it applies globally to every device (managed or not) and runs before tokens are issued. Unlike Intune enrollment or MDE, it is the authoritative gatekeeper that translates 'is this device managed and compliant?' into an allow/deny decision.

Why this answer

Microsoft Entra Conditional Access policies (option A) are correct because they evaluate signals such as user, device state, and location at authentication time and can enforce controls like requiring MFA or compliant devices even for unmanaged BYOD endpoints that cannot be enrolled in Intune. Conditional Access can block or restrict access to corporate resources for devices that don't meet policy, which directly addresses the scenario. Intune enrollment policies (B) only apply to devices being enrolled and cannot govern unenrolled devices.

Windows Defender Application Control (C) is an application control mechanism on Windows endpoints, not an access policy for corporate resources. Microsoft Defender for Endpoint (D) is an endpoint detection and response platform, not the feature that enforces access policy for unmanaged devices.

68
MCQeasy

Refer to the exhibit. You need to ensure that the storage account 'seccorpstorage' is only accessible from a specific Azure virtual network. What should you do?

A.Add a virtual network rule for the specific VNet
B.Enable the service endpoint for Microsoft.Storage on the VNet subnet
C.Enable firewall and add an IP rule for the VNet's public IP
D.Enable public network access and add a firewall rule
AnswerA

Adding a virtual network rule for the specific VNet is the correct action because it explicitly authorizes traffic from that VNet's subnet(s) to the storage account. When the storage firewall is set to 'Selected networks', all traffic is denied by default, and a VNet rule carves out an exception that allows inbound requests from the trusted VNet only. This aligns with the requirement to restrict access to a single VNet while keeping public network access disabled.

Why this answer

The correct answer is A: Add a virtual network rule for the specific VNet. In Azure Storage, network access restrictions are configured on the storage account's Networking blade, where you can add virtual network rules that allow access only from selected VNets and subnets; this directly satisfies the requirement that 'seccorpstorage' be accessible only from a specific Azure virtual network. Option B is incomplete because enabling the Microsoft.Storage service endpoint on the subnet is a prerequisite that makes the subnet eligible, but the storage account still needs the corresponding virtual network rule to actually restrict access.

Option C is wrong because an IP-based firewall rule uses public IP addresses and does not restrict access to a specific VNet's private traffic. Option D is wrong because enabling public network access opens the account to public connectivity rather than limiting it to one VNet.

69
Multi-Selecthard

Which THREE components are required to implement a secure hybrid network architecture using Azure VPN Gateway? (Choose three.)

Select 3 answers
A.A local network gateway resource in Azure.
B.A connection resource with a shared key.
C.An ExpressRoute circuit.
D.A virtual network gateway in Azure.
E.An Azure Firewall.
AnswersA, B, D

The local network gateway is a logical Azure object that points to your on-premises VPN device by its public IP address and defines the on-premises address space(s) that Azure should advertise over the tunnel. Without it, the Azure virtual network gateway has no remote endpoint to establish an IPsec session with, nor any knowledge of which on-premises routes should be reachable. It is therefore a mandatory configuration item for a Site-to-Site VPN.

Why this answer

Option A (a local network gateway resource in Azure) is required because it defines the on-premises VPN device's public IP address and address spaces, which Azure uses as the remote endpoint for the site-to-site tunnel. Option B (a connection resource with a shared key) is required because the connection object links the virtual network gateway to the local network gateway and carries the pre-shared key (PSK) used for IKE/IPsec authentication. Option D (a virtual network gateway in Azure) is required because it is the Azure-side VPN Gateway (VpnGw SKU) that terminates the IPsec/IKE tunnel and routes traffic into the virtual network.

Option C (an ExpressRoute circuit) does not belong because ExpressRoute is a private dedicated-circuit connectivity model, not a VPN Gateway component, and the scenario specifies VPN Gateway. Option E (an Azure Firewall) does not belong because it is a managed network security service for traffic filtering and is not a prerequisite for establishing a VPN Gateway site-to-site connection.

70
MCQeasy

Your organization is deploying Microsoft Intune to manage Windows 11 devices. You need to ensure that devices automatically receive security updates and that users cannot defer updates. Which configuration profile setting should you configure?

A.Create a device configuration profile to enable automatic updates.
B.Create a Windows 10/11 Update Rings policy with a deadline for quality and feature updates.
C.Create a compliance policy that requires the device to have the latest updates installed.
D.Create an endpoint security policy for Windows Defender Antivirus to enforce update installation.
AnswerB

A Windows 10/11 Update Rings policy in Intune is the correct tool because it maps directly to Windows Update for Business settings, allowing you to configure deferral periods for quality and feature updates, set installation deadlines, and define grace periods. Deadlines force the device to install updates after the specified period even if the user has delayed them, ensuring automatic installation. This is the only option that controls the actual update scheduling behavior rather than just checking or reporting on it.

Why this answer

The correct option is B: a Windows 10/11 Update Rings policy with a deadline for quality and feature updates. Update Rings in Intune are the purpose-built mechanism for controlling Windows Update behavior on managed devices, and configuring a deadline forces installation of quality and feature updates by a set time, preventing users from deferring them indefinitely. Option A is too vague and device configuration profiles do not provide the update-ring deadline enforcement needed here.

Option C only evaluates and reports compliance; it does not install updates or block deferrals. Option D concerns Defender Antivirus security settings, not Windows Update ring scheduling or deadlines.

71
MCQeasy

A company plans to use Microsoft Defender for Cloud to secure a multi-cloud environment including Azure, AWS, and GCP. What is the first step to enable multi-cloud visibility?

A.Enable all Defender plans for subscription
B.Connect AWS and GCP accounts using the cloud connectors in Defender for Cloud
C.Create custom compliance policies
D.Deploy Azure Arc agents on all cloud VMs
AnswerB

The Defender for Cloud multi-cloud connectors establish the onboarding bridge between Azure and AWS or GCP, synchronizing security configurations, threat indicators, and resource inventory into the unified Azure dashboard. This connector-level integration, which leverages read-only credentials from the foreign cloud, is the mandatory first step because all subsequent security policies, recommendations, and Defender plan coverage depend on the cloud accounts being visible to Azure. Without this connector, Defender for Cloud has no access to the AWS or GCP workloads.

Why this answer

The correct answer is B: connect AWS and GCP accounts using the cloud connectors in Defender for Cloud. Defender for Cloud's native multi-cloud support requires onboarding non-Azure environments through the AWS and GCP connectors, which establish the necessary trust and inventory so that resources, recommendations, and alerts from those clouds become visible in the portal. Only after this connection can Defender plans, compliance policies, or agent-based extensions be applied to those resources.

Option A is premature because enabling subscription-level Defender plans only affects Azure resources, not AWS or GCP. Option C is a later configuration step that depends on data already being collected, and Option D is not the onboarding mechanism for multi-cloud visibility, since Azure Arc is used for connecting specific servers rather than enabling cloud-wide AWS/GCP visibility.

72
MCQeasy

Your company uses Microsoft Sentinel as a SIEM. You need to ensure that all Azure subscription activity logs are ingested into Sentinel. What is the most efficient way to configure this?

A.Configure diagnostic settings on the subscription to send logs to a Log Analytics workspace.
B.Create an Azure Logic App to periodically pull activity logs.
C.Enable the 'Azure Activity' data connector in Sentinel.
D.Manually export activity logs to a storage account and connect to Sentinel.
AnswerC

Enabling the Azure Activity data connector in Microsoft Sentinel automatically configures the required diagnostic settings at the subscription level and begins near-real-time streaming of control-plane events into the AzureActivity table within your Sentinel workspace. It is the supported, turnkey method for this integration: the connector handles schema mapping, enrichment, and provides out-of-the-box detection rules, workbooks, and hunting queries. Once enabled, all operations such as resource creation, policy changes, and security alerts are immediately visible in Sentinel.

Why this answer

The Azure Activity data connector is specifically designed to ingest subscription-level activity logs into Microsoft Sentinel. Option A is incorrect because although diagnostic settings can send activity logs to a Log Analytics workspace, Sentinel requires the data connector to properly collect and correlate the data. Option B is incorrect because an Azure Logic App would be an inefficient custom solution when a built-in connector exists.

Option D is incorrect because manually exporting to a storage account is not efficient or automated.

73
MCQmedium

An organization uses Microsoft Sentinel to monitor their hybrid infrastructure. They need to detect brute-force attacks against their on-premises Windows servers. Which data source should they connect to Sentinel?

A.Azure Activity Log
B.Windows Security Events via Azure Monitor Agent
C.DNS Events
D.Sysmon Events
AnswerB

The Windows Security event log via the Azure Monitor Agent (AMA) is the standard and authoritative source for logon audit events, specifically Event ID 4625, which logs every failed account logon attempt. For hybrid machines, configuring a data collection rule (DCR) to forward Security events to Microsoft Sentinel enables detection of password-spraying and brute-force attempts. AMA is the current agent replacing the Log Analytics agent and preserves the necessary event details, such as source IP and target account, for high-fidelity analytics.

Why this answer

Windows Security Events from Event ID 4625 (failed logon) are the primary source for detecting brute-force attacks. Azure Activity Log is for resource management events. DNS events are for DNS queries.

Sysmon is for process activity, not logon failures.

74
Multi-Selectmedium

Which TWO Azure policies should you assign to enforce secure configuration of Azure SQL Database? (Select two.)

Select 2 answers
A.Ensure that 'Auditing' is set to 'On' for SQL Database
B.Ensure that 'TDE' is enabled for SQL Server VMs
C.Audit SQL Server level audit setting
D.Ensure that 'Firewall and virtual network settings' for SQL Database are configured
E.Ensure secure transfer to storage accounts is enabled
AnswersA, D

Enabling SQL Database auditing satisfies the secure-configuration requirement by recording all database events to a storage, Log Analytics or Event Hub destination, giving the detective evidence trail that Azure Policy's Auditing effect enforces at scale across every server and database in scope.

Why this answer

Option A is correct because the built-in Azure Policy 'Auditing on SQL Database should be enabled' enforces that auditing is set to 'On' for Azure SQL Database, ensuring database activity is logged for security and compliance monitoring. Option D is correct because the policy 'Firewall and virtual network settings for SQL Database should be configured' enforces that Azure SQL Database has network-level access controls (firewall rules or virtual network service endpoints/private endpoints) in place, restricting access to authorized networks only. Option B is incorrect because it targets TDE on SQL Server running on VMs (IaaS), not Azure SQL Database (PaaS), so it does not apply to this scenario.

Option C is incorrect because it audits the SQL Server-level audit setting rather than enforcing a secure configuration on Azure SQL Database itself. Option E is incorrect because it concerns secure transfer for storage accounts, which is unrelated to Azure SQL Database configuration.

Exam trap

The trap here is that candidates confuse SQL Server VM policies (like TDE or SQL Server-level audit settings) with Azure SQL Database policies, or they mistakenly apply storage account policies to SQL Database, which is a separate Azure service with its own security controls.

75
MCQeasy

Refer to the exhibit. A security analyst runs the following KQL query in Microsoft Sentinel. What is the purpose of this query?

A.List all accounts that have been locked out
B.Identify successful logins from multiple IP addresses
C.Detect brute-force attacks against Windows servers
D.Find users who logged in after hours
AnswerC

This query detects brute-force attacks by identifying patterns of repeated failed logon attempts (EventID 4625) originating from the same source IP address or targeting a single account. In a brute-force attack, an attacker systematically tries many username/password combinations against Windows servers, generating a high volume of 4625 events with a common Source Network Address. The query likely aggregates failed logon counts and thresholds, making it directly suitable for surfacing brute-force activity.

Why this answer

The query filters Windows Security Events for failed logon attempts (EventID 4625) in the last hour, groups by user account, computer, and IP address, and then shows only those with more than 10 failures. This is used to detect brute-force attacks.

Page 1 of 2 · 128 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Design security solutions for infrastructure questions.