Courseiva

CCNA Secops Identity Compliance Questions

5 of 155 questions · Page 3/3 · Secops Identity Compliance topic · Answers revealed

151
MCQmedium

Refer to the exhibit. A KQL query is used in Microsoft Sentinel to detect brute-force attacks. The query returns no results despite known brute-force attempts. What is the most likely issue?

A.The EventID 4625 may not cover all authentication failures
B.The query lacks a time filter
C.The 'IPAddress' field does not exist in SecurityEvent
D.The 'count()' aggregation is incorrect
AnswerA

While EventID 4625 captures Windows failed logon attempts, it does not include all authentication failure scenarios, such as Kerberos pre-authentication failures (EventID 4771), credential validation failures (EventID 4776), or failures from non-Windows sources like Azure AD sign-in logs. Additionally, certain failure conditions may generate different event IDs depending on the logon type or protocol, so a detection rule based solely on 4625 will have blind spots for those authentication failures.

Why this answer

EventID 4625 in Windows Security logs specifically records failed logon attempts, but brute-force attacks may target other authentication protocols (e.g., RDP, SMB, or network-level authentication) that generate different EventIDs (such as 4648, 4776, or 5156). Additionally, some brute-force attempts might be blocked at the network layer or use non-Windows authentication methods, so relying solely on EventID 4625 will miss those events. Therefore, the query returns no results because it does not capture all authentication failure scenarios.

Exam trap

Microsoft often tests the misconception that a single EventID (like 4625) covers all authentication failures, when in reality different protocols and authentication methods generate distinct EventIDs, and candidates must consider the broader log source landscape.

How to eliminate wrong answers

Option B is wrong because the absence of a time filter would cause the query to return results from all available data, not zero results; a missing time filter might cause performance issues or overly broad results, but it would not suppress known brute-force attempts. Option C is wrong because if the 'IPAddress' field did not exist in the SecurityEvent table, the query would fail with a schema error or return no results for that field, but the question states the query returns no results at all, implying the field exists but the filter is too narrow. Option D is wrong because the 'count()' aggregation is syntactically correct and commonly used in KQL to count events; an incorrect aggregation would cause a syntax error or unexpected counts, but it would not cause the query to return zero results for known brute-force attempts.

152
MCQhard

Your organization uses Microsoft Defender for Endpoint (MDE) and Microsoft Sentinel. You need to create an analytics rule in Sentinel that triggers an incident when a device is reported as 'high risk' by MDE. Which data source and rule type should you use?

A.Microsoft Sentinel's Anomalous Activity rule
B.Microsoft 365 Defender connector with an NRT query rule
C.Microsoft Defender XDR connector with a Scheduled query rule
D.Microsoft Defender for Cloud connector with a Fusion rule
AnswerC

The Microsoft Defender XDR connector brings Microsoft Defender for Endpoint's DeviceInfo table into Sentinel, including fields such as RiskScore and ExposureLevel. Running a Scheduled query rule on that connector lets you use KQL to filter where DeviceRiskScore equals 'High', map entities, and create an incident. This is the supported pattern because scheduled rules allow complex joins, longer time ranges, and robust entity mapping—essential for turning a live risk score into a reliable security alert.

Why this answer

The Microsoft Defender XDR connector ingests alerts from Microsoft Defender for Endpoint (MDE) into Sentinel. A Scheduled query rule is required to run a KQL query at a defined interval (e.g., every 5 minutes) that checks for devices with a 'high risk' severity level in the ingested alert data. This combination allows you to create an incident when MDE reports a device as high risk.

Exam trap

The trap here is confusing the Microsoft Defender XDR connector (which covers MDE, MDO, MDI, and MDCA) with the Microsoft 365 Defender connector (which is deprecated or used for legacy scenarios), leading candidates to incorrectly choose Option B.

How to eliminate wrong answers

Option A is wrong because Anomalous Activity rules use machine learning to detect unusual patterns in time-series data, not to trigger on a specific static alert severity like 'high risk' from MDE. Option B is wrong because the Microsoft 365 Defender connector is used for Microsoft 365 Defender (formerly Microsoft Threat Protection) alerts, not for MDE alerts directly; also, NRT (near-real-time) query rules are designed for low-latency scenarios but require a specific connector (Microsoft Defender XDR) for MDE data. Option D is wrong because the Microsoft Defender for Cloud connector ingests security alerts from Azure and hybrid workloads, not from MDE endpoint devices; Fusion rules correlate multiple alert types across different products, not a single static condition.

153
Multi-Selecthard

A company uses Microsoft Intune to manage devices. They need to ensure that only compliant devices can access corporate email. They plan to use Conditional Access in Microsoft Entra ID. Which THREE components must be configured?

Select 3 answers
A.Device registration in Entra ID
B.Conditional Access policy in Entra ID
C.Windows Autopilot deployment profile
D.Compliance policy in Intune
E.Configuration profile in Intune
AnswersA, B, D

Devices must be registered to be evaluated.

Why this answer

Device registration in Entra ID (A) is required because Conditional Access policies evaluate device compliance based on the device's identity in Entra ID. Without registration, the device lacks a unique identity that Entra ID can assess for compliance status, making it impossible to enforce access controls based on device state.

Exam trap

The trap here is that candidates often confuse Configuration profiles (which apply settings) with Compliance policies (which define security requirements), leading them to incorrectly select Configuration profile instead of Compliance policy for enforcing device-based access control.

154
MCQeasy

Refer to the exhibit. You configure this mail flow rule in Exchange Online. What happens to emails with 'FREE' in the subject?

A.Emails are deleted
B.Emails have a custom header added
C.Emails are moved to the Junk Email folder
D.Emails are blocked and not delivered
AnswerC

This is the correct behavior. The 'mark as spam' action sets the message's SCL to 6, which is the threshold used by Exchange Online to route the email to the recipient's Junk Email folder (depending on the mailbox's safe sender settings). It does not delete or reject the email; instead, it delivers it to the spam quarantine location within the mailbox, allowing the user to review it later.

Why this answer

The mail flow rule is configured to add the header 'X-CustomHeader' with the value 'Free' to emails that have 'FREE' in the subject. However, the rule also has the action 'Increase the spam confidence level (SCL) to 9', which causes Exchange Online to treat the message as high-confidence spam. When the SCL is set to 9, Exchange Online automatically moves the email to the Junk Email folder for the recipient, unless a transport rule or mailbox setting overrides this behavior.

Therefore, the emails are not deleted, blocked, or simply have a header added; they are moved to the Junk Email folder due to the SCL increase.

Exam trap

The trap here is that candidates see the 'add a custom header' action and assume that is the only effect, overlooking that the subsequent 'increase SCL to 9' action takes precedence and causes the email to be moved to the Junk Email folder, making the header addition secondary.

How to eliminate wrong answers

Option A is wrong because the rule does not include a 'Delete the message without notifying anyone' action; it only adds a header and increases the SCL, which does not result in deletion. Option B is wrong because while the rule does add a custom header ('X-CustomHeader: Free'), this is not the final outcome—the SCL increase to 9 overrides this action by causing the message to be moved to Junk Email, so the primary effect is the junking, not just header addition. Option D is wrong because the rule does not use a 'Reject the message' action (such as with a non-delivery report or 550 status code); increasing the SCL to 9 does not block delivery but instead routes the message to the Junk Email folder.

155
Multi-Selecthard

Your organization uses Microsoft Entra ID and needs to implement a Zero Trust identity strategy. Which THREE principles should you apply?

Select 3 answers
A.Use least privilege access
B.Verify explicitly
C.Trust implicitly
D.Use a single authentication method
E.Assume breach
AnswersA, B, E

In Microsoft Entra ID, least privilege means assigning identities only the permissions required for their specific job, using built-in roles like Global Reader or custom roles instead of broad Global Administrator. Privileged Identity Management (PIM) provides time-bound, just-in-time role activation, further reducing standing access and the attack surface. This principle directly limits the blast radius if an account is compromised, making it a correct answer for Zero Trust.

Why this answer

The Zero Trust identity model in Microsoft Entra ID is built on three core principles, and option B (Verify explicitly) is correct because every access request must be authenticated and authorized based on all available signals—user identity, device health, location, and risk—rather than trusting based on network location. Option A (Use least privilege access) is correct because Zero Trust requires granting just-enough, just-in-time access using tools like Privileged Identity Management (PIM) and conditional access so users only get the permissions needed for the task. Option E (Assume breach) is correct because Zero Trust assumes the network is already compromised and therefore uses micro-segmentation, end-to-end encryption, and analytics to minimize blast radius and detect threats.

Option C (Trust implicitly) is incorrect because it is the opposite of Zero Trust—implicit trust based on being inside the corporate network is exactly what Zero Trust eliminates. Option D (Use a single authentication method) is incorrect because Zero Trust favors strong, phishing-resistant multi-factor authentication (such as FIDO2 or Windows Hello for Business) rather than relying on a single authentication factor.

Exam trap

The trap here is that candidates often confuse 'Trust implicitly' with the legacy perimeter-based security model and select it as a valid principle, or mistakenly think a single authentication method simplifies management, but Zero Trust explicitly rejects both for continuous verification and defense-in-depth.

← PreviousPage 3 of 3 · 155 questions total

Ready to test yourself?

Try a timed practice session using only Secops Identity Compliance questions.