Sample questions
Microsoft Cybersecurity Architect practice questions
Refer to the exhibit. A KQL query is used in Microsoft Sentinel to detect brute-force attacks. The query returns no results despite known brute-force attempts. What is the most lik…
Design security operations, identity, and compliance capabilitiesmediumSee the answer and why each option is right or wrong →A startup, Alpine Ski House, is developing a mobile app that allows users to book ski lessons. The app communicates with an Azure Function App backend via REST APIs. The function a…
Design security solutions for applications and dataeasySee the answer and why each option is right or wrong →A company needs to design a secure DevOps pipeline using GitHub Actions and Microsoft Defender for Cloud. They want to scan infrastructure-as-code (IaC) templates for misconfigurat…
Design solutions that align with security best practices and prioritieshardSee the answer and why each option is right or wrong →Your organization is migrating to Microsoft 365 and wants to implement a data classification strategy. The compliance team needs to automatically detect and label documents contain…
Design solutions that align with security best practices and prioritieshardSee the answer and why each option is right or wrong →Your company is migrating to a cloud-native security operations center (SOC) using Microsoft Sentinel. You need to design a solution that automatically investigates and remediates…
Design security solutions for infrastructurehardSee the answer and why each option is right or wrong →Your organization is planning to deploy Microsoft Purview Information Protection to classify and protect sensitive data. You need to design a solution that automatically applies se…
Design solutions that align with security best practices and prioritiesmediumSee the answer and why each option is right or wrong →Your company is migrating on-premises Active Directory to Microsoft Entra ID. The security team requires that users must use passwordless authentication methods for all sign-ins. W…
Design solutions that align with security best practices and prioritiesmediumSee the answer and why each option is right or wrong →A company is designing a data security strategy using Microsoft Purview. They need to identify sensitive data across their data estate, including on-premises SQL Server, Azure SQL…
Design solutions that align with security best practices and prioritiesmediumSee the answer and why each option is right or wrong →Your organization uses Microsoft Sentinel and wants to automatically respond to high-severity incidents. Which feature should you configure?
Design security operations, identity, and compliance capabilitieseasySee the answer and why each option is right or wrong →Your company uses Microsoft Defender for Cloud Apps and wants to prevent users from uploading sensitive files to personal cloud storage apps. What should you configure?
Design security operations, identity, and compliance capabilitiesmediumSee the answer and why each option is right or wrong →You are designing a Microsoft Purview data security solution for a multinational organization subject to GDPR and CCPA. Which THREE Purview capabilities should you include to meet…
Design solutions that align with security best practices and prioritieshardSee the answer and why each option is right or wrong →A company deploys Azure App Service with a custom domain and SSL certificate. They want to enforce HTTPS only. Which configuration setting should they enable?
A company is planning their cloud governance strategy. They have multiple business units with varying compliance requirements. They need to enforce policies consistently across sub…
Refer to the exhibit. You are investigating a security incident in Microsoft Sentinel. The KQL query above is used to identify potential brute-force attacks. What does the query re…
Design security solutions for applications and datamediumSee the answer and why each option is right or wrong →Your organization uses Microsoft Defender for Endpoint (MDE) and Microsoft Sentinel. You need to create an analytics rule in Sentinel that triggers an incident when a device is rep…
Design security operations, identity, and compliance capabilitieshardSee the answer and why each option is right or wrong →Your company uses Microsoft Sentinel as a SIEM. You need to ensure that all Azure subscription activity logs are ingested into Sentinel. What is the most efficient way to configure…
Design security solutions for infrastructureeasySee the answer and why each option is right or wrong →An organization uses Microsoft Sentinel to monitor their hybrid infrastructure. They need to detect brute-force attacks against their on-premises Windows servers. Which data source…
Design security solutions for infrastructuremediumSee the answer and why each option is right or wrong →Refer to the exhibit. A security analyst runs the following KQL query in Microsoft Sentinel. What is the purpose of this query?
Design security solutions for infrastructureeasySee the answer and why each option is right or wrong →A company is implementing a cloud security governance strategy. They need to ensure that all Azure resources are compliant with internal security policies before deployment. Which…
Your company uses Microsoft Sentinel for security operations. You need to design a solution that automatically remediates a detected threat by blocking a malicious IP address on Az…
Design security solutions for applications and datamediumSee the answer and why each option is right or wrong →A company has a hybrid identity deployment using Azure AD Connect. They want to ensure that if a user's on-premises account is disabled, the corresponding Azure AD account is also…
A company is designing a Zero Trust network strategy. They want to ensure that all network traffic between on-premises and Azure is inspected and logged, regardless of source or de…
Your organization is using Microsoft Sentinel for security information and event management (SIEM). You need to ensure that data from Azure Activity Logs is ingested into Sentinel.…
Design security solutions for applications and dataeasySee the answer and why each option is right or wrong →A company uses Microsoft Intune to manage devices. They need to ensure that only compliant devices can access corporate email. They plan to use Conditional Access in Microsoft Entr…
Design security operations, identity, and compliance capabilitieshardSee the answer and why each option is right or wrong →