Courseiva

CCNA Security Apps Data Solutions Questions

46 of 121 questions · Page 2/2 · Security Apps Data Solutions topic · Answers revealed

76
Multi-Selecthard

You are designing a secure access strategy for Azure App Service web applications. The requirements are: use Azure AD for authentication, restrict access to specific IP ranges, and require multi-factor authentication (MFA) for all users. Which two components should you configure? (Choose two.)

Select 2 answers
A.Apply a network security group (NSG) to the App Service subnet
B.Configure Azure App Service authentication with Microsoft Entra ID
C.Create a Conditional Access policy in Microsoft Entra ID that requires MFA and restricts IP ranges
D.Deploy Azure Firewall to filter inbound traffic
E.Register the application in Microsoft Entra ID
AnswersB, C

Azure App Service authentication can be configured to use Microsoft Entra ID, which is required for user authentication.

Why this answer

Option B is correct because configuring App Service authentication with Microsoft Entra ID (formerly Azure AD) enables the built-in Easy Auth middleware to authenticate users against the Entra ID identity provider, satisfying the requirement to use Azure AD for authentication. Option C is correct because a Conditional Access policy in Microsoft Entra ID can enforce MFA for all users and apply named locations or IP-based conditions to restrict access to specific IP ranges, meeting both the MFA and IP restriction requirements at the identity layer. Option A is not correct because an NSG applied to the App Service subnet only filters network traffic by IP/port at the network layer and does not provide Azure AD authentication or MFA.

Option D is not correct because Azure Firewall filters inbound/outbound traffic but does not perform user authentication or MFA enforcement. Option E is not correct because registering the application in Microsoft Entra ID only creates the identity object/service principal; it does not by itself enable authentication, IP restrictions, or MFA.

Exam trap

SC-100 often tests the layering of identity vs. network controls — candidates pick NSG or Azure Firewall for IP restriction when the requirement is user-level access with MFA, which only Conditional Access can enforce.

77
MCQeasy

You are designing a solution for a healthcare organization that needs to share patient health information (PHI) with a partner organization. The partner must be able to query the data but should not be able to modify it. Both organizations use Microsoft Entra ID. What should you use?

A.Azure Active Directory B2C (now part of Entra) to allow the partner to authenticate and access data via a custom API.
B.Microsoft Entra entitlement management with an access package that grants read-only access to a SharePoint Online site.
C.Microsoft Purview Information Protection to label the data and allow the partner to decrypt it.
D.Azure DevOps for sharing the data in a repository with read-only permissions.
AnswerB

Microsoft Entra entitlement management is the correct approach because it is purpose-built for governing external access to resources in a B2B scenario. An access package can be created that contains a SharePoint Online site; when a partner user is assigned the package, they receive precisely the permissions defined — in this case read-only — and those permissions are enforced by SharePoint and Entra. The solution also provides built-in lifecycle management, such as expiration, approval workflows, and access reviews, ensuring access is time-bound and auditable, which aligns with a healthcare organization's privacy and compliance obligations.

Why this answer

The correct option is B: Microsoft Entra entitlement management with an access package that grants read-only access to a SharePoint Online site. Entitlement management is designed for B2B collaboration, allowing external partner users from another Entra ID tenant to request and receive governed access to resources, and an access package can assign a read-only permission level (e.g., SharePoint Visitors/Read) so the partner can query but not modify PHI. Option A is wrong because Entra ID B2C is for customer-facing identity scenarios, not partner B2B collaboration, and a custom API would require you to build and enforce read-only authorization yourself.

Option C is wrong because Purview Information Protection labels and encrypts data but does not provide the partner query access or enforce read-only permissions. Option D is wrong because Azure DevOps repositories are for source code, not for sharing PHI with a partner organization.

78
MCQhard

Refer to the exhibit. You are evaluating a custom Azure Policy definition for storage accounts. The policy is assigned with effect set to 'Deny'. An administrator attempts to create a new storage account with network rules configured to allow all traffic (defaultAction set to Allow). What will happen?

A.The storage account creation is denied.
B.The storage account is created, and the network rules are automatically changed to deny all traffic.
C.The storage account is created, and an audit event is generated.
D.The storage account is created successfully, and no action is taken.
AnswerA

The Azure Policy definition uses a condition that checks the storage account's networkAcls.defaultAction property, and because the effect is set to 'Deny', the resource provider rejects the create request before any storage account is provisioned. The deployment fails with a policy violation error, and no resource is created.

Why this answer

The correct answer is A: the storage account creation is denied. Because the Azure Policy definition is assigned with the effect set to 'Deny', Azure Policy evaluates the resource request before deployment and blocks any storage account whose network rules use defaultAction set to Allow, so the create operation fails with a policy violation. Deny is a preventive enforcement effect, not a remediation or audit effect, so it stops the request rather than modifying the resource.

Option B is wrong because Azure Policy does not automatically rewrite network rules to deny all traffic, and option C is wrong because audit events are produced by the Audit effect, not Deny. Option D is wrong because Deny actively blocks the noncompliant creation instead of allowing it with no action.

79
MCQmedium

You are designing a CI/CD pipeline for a containerized application using Azure DevOps. You need to ensure that container images are scanned for vulnerabilities before being deployed to production. Which service should you integrate?

A.Azure Policy
B.Azure Key Vault
C.Microsoft Defender for Cloud
D.Azure Monitor
AnswerC

Microsoft Defender for Cloud is the correct choice because it includes a built-in, agentless vulnerability scanner for container images stored in Azure Container Registry (ACR). When an image is pushed or pulled, Defender for Cloud automatically scans it using the Qualys scanner and matches findings against a continuously updated CVE database. The results provide severity levels, remediation guidance, and can be integrated into CI/CD gates via Defender for Cloud APIs or CLI to block deployment of images above a certain risk threshold. It also re-scans images on a regular basis to detect newly discovered vulnerabilities, providing both pre-deployment and ongoing protection.

Why this answer

Microsoft Defender for Cloud [CORRECT] is the right choice because it provides container image vulnerability scanning for images stored in Azure Container Registry and can be integrated into CI/CD workflows to gate deployments before production. It continuously assesses images and surfaces findings that Azure DevOps pipelines can act on. Azure Policy is for enforcing governance and compliance rules on resources, not for scanning container images for vulnerabilities.

Azure Key Vault manages secrets and keys, and Azure Monitor collects telemetry and logs, so neither performs vulnerability scanning.

80
MCQeasy

A retail company uses Microsoft Purview to protect customer data across Microsoft 365 and Azure. The compliance team wants to detect when sensitive information such as credit card numbers is uploaded to SharePoint Online and automatically apply a sensitivity label that encrypts the content. The label must be applied without user interaction. You need to recommend the Purview capability to use. What should you recommend?

A.An Insider Risk Management policy that flags credit card numbers in SharePoint.
B.A sensitivity label with user-defined permissions and mandatory labeling in SharePoint.
C.An auto-labeling policy for sensitive information types in Microsoft Purview.
D.A data loss prevention policy that blocks uploads containing credit card numbers.
AnswerC

Auto-labeling policies in Microsoft Purview scan locations such as SharePoint Online for sensitive information types like credit card numbers and apply the configured sensitivity label automatically, with no user action. This directly matches the requirement to detect and encrypt sensitive content at rest without interaction.

Why this answer

The scenario requires automatic detection of sensitive information and automatic application of an encrypting sensitivity label, with no user involvement. Microsoft Purview auto-labeling policies are purpose-built for this: they use sensitive information types and trainable classifiers to find content in SharePoint Online and other locations and apply the designated label. DLP, mandatory labeling, and Insider Risk Management serve different purposes and do not apply encryption labels automatically.

Exam trap

The trap here is conflating DLP, which blocks or warns, with auto-labeling, which applies the label and encryption.

81
MCQeasy

You are reviewing an ARM template snippet that creates a blob container. The security team requires that the container be accessible only via authorized Azure AD identities, not via anonymous access. Based on the exhibit, is the configuration correct?

A.Yes, but you also need to disable shared key access
B.No, you need to set 'publicAccess' to 'Blob' to restrict access
C.Yes, the setting 'publicAccess': 'None' prevents anonymous access, and Azure AD authentication is available by default
D.No, you must also configure a firewall rule to restrict access to Azure AD users
AnswerC

With `publicAccess: None`, Azure Storage rejects any anonymous request to the container, so unauthenticated clients cannot read or write data. Azure AD authentication is natively enabled for Blob Storage, meaning authorized users and applications can authenticate via their Azure AD identities without any additional configuration. This satisfies the requirement to block anonymous access while still allowing authenticated access.

Why this answer

Option C is correct because setting 'publicAccess' to 'None' on a blob container disables anonymous read access, and Azure AD (Microsoft Entra ID) authorization is always available for Blob Storage data-plane operations when a caller presents a valid OAuth 2.0 token with the appropriate RBAC role. No additional template property is required to enable Azure AD authentication; it is a service-level capability. Option A is wrong because disabling shared key access is an optional hardening step, not a prerequisite for Azure AD-only access.

Option B is wrong because 'Blob' or 'Container' publicAccess values actually permit anonymous read access, the opposite of the requirement. Option D is wrong because firewall rules restrict network origin, not the authentication method, and are not required to enforce Azure AD authorization.

82
MCQhard

Refer to the exhibit. A security analyst is reviewing a Windows security event log from a domain controller. The event indicates an attempted logon failure. Which type of attack is most likely being attempted?

A.Kerberos golden ticket attack
B.DCSync attack
C.Pass-the-hash attack
D.Brute-force password guessing attack
AnswerD

Event 4625 with Logon Type 3 is generated when a network logon attempt (e.g., SMB/NetBIOS) fails due to an invalid username or password, which is the classic signature of a brute-force password guessing attack. The combination of multiple sequential failed logon attempts originating from a single source IP and targeting a privileged account such as a domain administrator indicates that the attacker is systematically trying many passwords to crack the account. This is distinct from opportunistic scanning because the failures are concentrated on one high-value account, and if successful, the attacker could move laterally using the compromised credentials.

Why this answer

The correct answer is D, a brute-force password guessing attack, because a logon failure event on a domain controller most directly indicates repeated or attempted authentication with incorrect credentials, which is the signature of password guessing. Brute-force attacks generate failed logon events (e.g., Windows Security Event ID 4625) as the attacker tries multiple passwords against an account. In contrast, a Kerberos golden ticket attack (A) forges a TGT using the KRBTGT hash and typically does not produce logon failures, and a DCSync attack (B) abuses directory replication permissions to extract password hashes, not to guess passwords.

A pass-the-hash attack (C) authenticates using a stolen NTLM hash and usually succeeds without failed logon attempts, so it does not match the failed-logon scenario.

83
Multi-Selectmedium

Your organization is designing a solution to protect sensitive data in Microsoft 365. You need to implement Microsoft Purview Data Loss Prevention (DLP) policies. Which TWO actions can a DLP policy take when a match occurs? (Choose TWO.)

Select 2 answers
A.Encrypt the file with Azure Information Protection.
B.Quarantine the file for administrator review.
C.Automatically apply a sensitivity label.
D.Block the sharing of sensitive information.
E.Show a policy tip to the user.
AnswersD, E

Blocking the sharing of sensitive information is a core DLP enforcement action. In Microsoft Purview, you can configure DLP policies to block sharing via email (e.g., 'Block only people outside your organization'), block uploads to external sites, or block copy/paste to unsanitized apps. This action can be configured with an override option or a policy tip, directly preventing data loss. It is the definitive 'enforce' behavior for DLP scenarios.

Why this answer

Option D is correct because Microsoft Purview DLP policies can block sharing of sensitive information across workloads such as Exchange Online, SharePoint, OneDrive, and Teams, preventing users from sending or sharing content that matches a DLP rule. Option E is correct because DLP policies can display policy tips to users in supported apps (for example, Outlook, Word, Excel, and Teams), notifying them that content matches a rule and offering override or report options. Option A is not a native DLP action; encryption with Azure Information Protection is typically achieved through sensitivity labels or auto-labeling policies, not directly as a DLP policy action.

Option B is not a standard DLP action in Microsoft Purview; DLP can block, restrict access, or notify, but it does not quarantine files for administrator review. Option C is not a DLP policy action; automatically applying a sensitivity label is performed by auto-labeling policies in Microsoft Purview, not by DLP policies.

84
MCQmedium

You are the security architect for a financial services company that stores customer PII in an Azure SQL Database. The database currently uses service-managed Transparent Data Encryption (TDE). A new regulatory requirement mandates that the company controls and rotates the encryption keys used to protect the database, and that all key operations are auditable. You need to recommend a solution that meets the requirement with the least administrative overhead. What should you recommend?

A.Enable Always Encrypted with secure enclaves on the sensitive columns.
B.Use service-managed TDE keys and enable Azure Policy to audit key rotation.
C.Configure TDE with a customer-managed key stored in Azure Key Vault (BYOK).
D.Store the database in an Azure Disk Encryption–protected VM-hosted SQL Server instance.
AnswerC

Customer-managed TDE keys in Azure Key Vault give the organization full control over key lifecycle, including rotation and revocation, and Key Vault logging records every key operation for audit. This directly satisfies the regulatory requirement for controlled, auditable key management without requiring application changes or additional infrastructure.

Why this answer

The requirement is customer control and auditability of the keys that protect data at rest in Azure SQL Database. Transparent Data Encryption with a customer-managed key in Azure Key Vault is the native Azure SQL feature that satisfies this: the customer owns the key, controls rotation and revocation, and Key Vault diagnostics provide the audit trail. Other options either protect a different data state or shift to an unsupported platform.

Exam trap

The trap here is assuming Always Encrypted is required whenever a regulation mentions customer-controlled keys, when the actual control point is the TDE key hierarchy.

85
MCQhard

Refer to the exhibit. You run the PowerShell script to protect high-confidentiality resources. After execution, you find that some resources with tag 'Confidentiality=High' are still unprotected. What is the most likely reason?

A.Some resources are in a different resource group than expected.
B.The script does not check for existing locks properly.
C.Tags are not inherited from resource groups.
D.The script overwrites existing locks.
AnswerA

When the script enumerates Azure resources, it derives the target resource group from the `ResourceGroupName` property of each resource object. This property is accurate for resources inside a resource group, but some resources (e.g., subscription-level policy or role assignments) return a null value, and if the script falls back to a variable or default group, those resources are processed against the wrong resource group. As a result, the lock is created on a scope that does not match the actual resource, leaving the resource unprotected. This is the root cause that also makes the existence-check behavior misleading.

Why this answer

The correct answer is A: some resources are in a different resource group than expected. If the PowerShell script scopes its protection (for example, applying locks or policies) to a specific resource group, any resource tagged 'Confidentiality=High' that resides in another resource group is outside the script's scope and remains unprotected, which matches the symptom of some tagged resources still being unprotected. Option B is not the likely cause because the failure is about scope, not lock-detection logic.

Option C is incorrect because tag inheritance from resource groups is not the issue here—the resources already carry the tag. Option D is irrelevant because overwriting existing locks would not leave tagged resources unprotected.

86
MCQhard

Your company uses Microsoft Purview to manage data governance. You need to create a data classification rule that scans Azure Data Lake Storage for personally identifiable information (PII) such as email addresses. The rule must also apply a sensitivity label automatically. Which approach should you use?

A.Create an Azure Policy to detect and label PII.
B.Create a custom scan rule in Microsoft Purview and configure auto-labeling.
C.Use a Power Automate flow to scan files and apply labels.
D.Use Microsoft Defender for Cloud to scan for PII.
AnswerB

Microsoft Purview provides native scanning that discovers data assets across on-premises and cloud sources, and you can define custom classification rules using regex or keyword patterns to identify PII such as SSNs or credit card numbers. Once the scan classifies content, Purview's auto-labeling automatically applies Microsoft 365 sensitivity labels to the assets based on the custom rule's classifier, enabling consistent data governance and protection. This directly matches the requirement to detect and label PII.

Why this answer

The correct option is B: create a custom scan rule in Microsoft Purview and configure auto-labeling. Microsoft Purview is the data governance service that supports scanning Azure Data Lake Storage with custom classification rules (using regex or dictionaries) to detect PII such as email addresses, and its auto-labeling policies can then apply sensitivity labels automatically to matching content. Option A is wrong because Azure Policy enforces resource configuration and compliance, not content-level PII detection or sensitivity labeling.

Option C is wrong because Power Automate is a workflow automation tool and does not provide Purview's built-in classification scanning for Data Lake Storage. Option D is wrong because Microsoft Defender for Cloud focuses on security posture and threat protection, not data classification or sensitivity labeling.

87
MCQhard

You are designing a solution to securely store and manage secrets for a cloud-native application deployed on Azure Kubernetes Service (AKS). The application needs to retrieve database connection strings and API keys at runtime without hardcoding them. The solution must minimize administrative overhead and integrate with Azure Active Directory (now Microsoft Entra ID) for access control. Which service should you use?

A.Kubernetes Secrets
B.HashiCorp Vault on AKS
C.Azure Key Vault with managed identities
D.Azure App Configuration
AnswerC

Azure Key Vault stores secrets centrally, and managed identities give the AKS workload a Microsoft Entra ID-backed identity that authenticates to Key Vault without stored credentials. This removes secret rotation and credential management overhead while enforcing access control through Microsoft Entra ID.

Why this answer

Azure Key Vault with managed identities (option C) is correct because it provides a fully managed, cloud-native secrets store that integrates natively with Microsoft Entra ID, and managed identities let the AKS pods authenticate to Key Vault without storing credentials, minimizing administrative overhead. The application can retrieve database connection strings and API keys at runtime via the Key Vault SDK or the Secrets Store CSI Driver, so nothing is hardcoded. Kubernetes Secrets (A) are only base64-encoded and stored in etcd, lack Entra ID-based access control, and require manual rotation and RBAC management.

HashiCorp Vault on AKS (B) is powerful but self-managed, adding significant operational and administrative overhead. Azure App Configuration (D) is designed for application settings and feature flags, not for secure secret storage with Entra ID access control.

88
MCQeasy

Your application uses Azure Key Vault to store secrets. You need to ensure that the application rotates secrets automatically without downtime. Which feature should you enable?

A.Key Vault automatic rotation with Event Grid integration
B.Key Vault manual rotation
C.Key Vault soft-delete
D.Key Vault RBAC
AnswerA

This solution enables near-real-time secret rotation by publishing events to Event Grid whenever a secret nears its expiration date or is updated, triggering an Azure Function or Logic App to generate a new secret version and update dependent applications. It removes human intervention, aligns with security best practices, and ensures business continuity with minimal downtime. The Event Grid integration supports both time-based and manual rotation triggers, making it the only option that fully automates the secret lifecycle.

Why this answer

Key Vault automatic rotation with Event Grid integration (option A) is correct because it lets Key Vault rotate secrets on a schedule and emit near-real-time events (e.g., Microsoft.KeyVault.SecretNewVersionCreated) that the application can subscribe to, so it can fetch the new secret version before the old one expires and avoid downtime. Manual rotation (option B) requires an operator to create new secret versions, which cannot guarantee timely, zero-downtime rotation. Soft-delete (option C) only retains deleted vaults/secrets for recovery and does not rotate anything.

RBAC (option D) governs authorization to Key Vault operations but provides no rotation mechanism.

89
MCQmedium

Refer to the exhibit. A security architect is reviewing an Azure Policy definition. What is the effect of this policy?

A.Modifies storage accounts to enable HTTPS traffic only
B.Audits storage accounts that do not require HTTPS traffic
C.Denies creation or update of storage accounts that do not require HTTPS traffic
D.Deploys a remediation task to enable HTTPS traffic only
AnswerC

The 'deny' effect is the correct behavior for this policy definition. When a request to create or update a storage account arrives at Azure Resource Manager, the policy engine checks whether the property 'supportsHttpsTrafficOnly' is set to 'true'. If the property is false or omitted, the entire create or update operation is rejected with a policy violation error. This ensures that no new or updated storage account can be deployed without requiring HTTPS traffic, providing a strong security control.

Why this answer

The correct answer is C: the policy denies creation or update of storage accounts that do not require HTTPS traffic. In Azure Policy, a Deny effect blocks the request at the resource provider during create or update operations when the resource does not satisfy the condition, so a storage account with supportsHttpsTrafficOnly set to false would be rejected. Option A is incorrect because Modify effects change properties via remediation and do not block the request.

Option B is incorrect because Audit only records non-compliance without preventing deployment. Option D is incorrect because DeployIfNotExists remediation tasks are triggered after evaluation and do not deny the original request.

90
MCQhard

A healthcare organization is designing a zero-trust application security strategy. They use Microsoft Entra ID for identity and plan to deploy a legacy on-premises web application with no modern authentication support. The solution must ensure that only authorized users can access the app and that access is logged for auditing. Which Microsoft security service should they use to secure access?

A.Azure AD B2C
B.Microsoft Entra application proxy
C.Microsoft Defender for Cloud Apps
D.Microsoft Intune
AnswerB

Microsoft Entra Application Proxy is a cloud reverse proxy that publishes on-premises legacy web applications under an Entra ID external URL, using a lightweight connector installed on the internal network that initiates outbound connections only. Users authenticate through Entra ID first, which enables Conditional Access, MFA, and device compliance policies before the connector forwards the request via Kerberos Constrained Delegation to the app. Since it requires no VPN or code modifications, it directly supports zero trust for apps that lack modern authentication.

Why this answer

Microsoft Entra application proxy (option B) is correct because it is designed to publish on-premises web applications, including legacy apps without modern authentication support, and enforce Entra ID pre-authentication plus conditional access before traffic reaches the app, while also providing access logging for auditing. It fits the zero-trust scenario by brokering remote access through the Application Proxy connector without exposing the app directly to the internet. Azure AD B2C (option A) is for customer identity and access management for consumer-facing apps, not for securing internal legacy on-premises apps.

Microsoft Defender for Cloud Apps (option C) is a CASB for discovering, monitoring, and controlling cloud app usage, not for publishing and pre-authenticating on-premises web apps. Microsoft Intune (option D) is for device and mobile application management, not for brokering authenticated access to legacy on-premises web applications.

91
Multi-Selectmedium

A financial institution, Contoso Bank, is deploying a new application on Azure Kubernetes Service (AKS) that processes credit card transactions (PCI DSS). The application uses Azure SQL Database and Azure Redis Cache. You need to design a security solution that meets PCI DSS requirements. Which THREE of the following should you implement?

Select 3 answers
A.Deploy AKS as a private cluster with no public endpoint.
B.Configure Always Encrypted for sensitive columns in Azure SQL Database.
C.Enable Azure RBAC for Kubernetes authorization.
D.Use private endpoints for Azure SQL Database and Azure Cache for Redis.
E.Disable TLS for Azure Cache for Redis to improve performance.
AnswersA, B, D

Deploying AKS as a private cluster with no public endpoint is essential because the Kubernetes API server is placed behind a private IP address on a virtual network, using Azure Private Link. This prevents the control plane from being reachable from the internet, directly satisfying PCI DSS network compartmentalization requirements for cardholder data environments. Unlike merely disabling public access, this design ensures administrative and operational traffic to the API server also traverses the private network.

Why this answer

Option A is correct because deploying AKS as a private cluster with no public endpoint removes the API server's public exposure, ensuring all control-plane communication stays on the private network and reducing the PCI DSS attack surface. Option B is correct because Always Encrypted protects sensitive cardholder data columns in Azure SQL Database by keeping encryption keys outside the database engine, so even DBAs or compromised SQL instances cannot read plaintext data. Option D is correct because private endpoints for Azure SQL Database and Azure Cache for Redis route traffic over Azure Private Link, keeping data off the public internet and satisfying PCI DSS network segmentation and encryption-in-transit expectations.

Option C is not among the required three because Azure RBAC for Kubernetes authorization is a general access-control hardening measure, not a PCI DSS-specific control for protecting cardholder data in this scenario. Option E is incorrect because disabling TLS on Azure Cache for Redis exposes data in transit and directly violates PCI DSS encryption requirements for cardholder data.

Exam trap

Candidates may mistakenly believe that enabling Azure RBAC for Kubernetes is sufficient for PCI DSS compliance, but it only addresses authorization, not network isolation. Additionally, disabling TLS may be considered for performance but violates encryption requirements.

92
MCQmedium

Your organization is deploying a customer-facing web application in Azure. The application must authenticate users via Microsoft Entra ID and access Microsoft Graph to read user profiles. The security team requires that the application never has access to user passwords. Which authentication flow should you recommend?

A.OAuth 2.0 implicit grant flow
B.OAuth 2.0 device authorization flow
C.OAuth 2.0 client credentials grant flow
D.OAuth 2.0 authorization code flow with PKCE
AnswerD

Authorization code flow with PKCE is the recommended OAuth 2.0 flow for customer-facing web applications. The user authenticates and consents, and the app receives an authorization code rather than a token; this code is then exchanged for tokens using a PKCE verifier, ensuring that even if the code is intercepted it cannot be redeemed. The flow supports refresh tokens and never exposes the user's password to the app, making it secure for JavaScript and server-based web apps alike.

Why this answer

The correct option is D, OAuth 2.0 authorization code flow with PKCE, because it is the recommended flow for customer-facing web applications that authenticate users interactively via Microsoft Entra ID and call Microsoft Graph on their behalf. With PKCE, the client proves possession of a one-time code verifier, and the user authenticates directly against Entra ID, so the application never handles or sees user passwords. The resulting delegated access token also allows reading user profiles through Microsoft Graph with the appropriate scopes.

Option A (implicit grant) is deprecated and exposes tokens in the browser URL fragment, while option B (device authorization flow) is intended for input-constrained devices and is not suited to a normal web app. Option C (client credentials grant) is app-only authentication with no user context, so it cannot authenticate users or read their profiles as required.

93
MCQhard

Refer to the exhibit. A security administrator is reviewing a Conditional Access policy JSON. They want to ensure that users with medium risk level are prompted for multi-factor authentication (MFA), while high-risk users are blocked. The policy is not working as expected. Which issue is present in the policy?

A.The policy mode should be 'report-only'
B.The policy requires both user and sign-in risk to be high to block, but a user with high user risk and low sign-in risk would not be blocked
C.The JSON syntax is invalid
D.The conditions are combined with 'Or' instead of 'And'
AnswerB

In Microsoft Entra Conditional Access, conditions are evaluated cumulatively; a user must satisfy every condition for the 'Block access' grant to be applied. With user risk set to High and sign-in risk set to High, a user whose user risk is High but whose sign-in risk is Low will not match both conclusions, so the block is skipped. This leaves a predictable gap that an attacker with a compromised account and low sign-in risk could exploit. The correct fix would be to treat high user risk OR high sign-in risk as sufficient, either by using separate policies or by adjusting the controls.

Why this answer

The correct answer is B: the policy's block condition requires both user risk and sign-in risk to be high, so a user with high user risk but low sign-in risk would not be blocked as intended. In Microsoft Entra Conditional Access, user risk and sign-in risk are separate conditions, and if the JSON combines them so that both must be 'high' for the block to apply, the policy fails to block all high-risk users. The intended design should block when user risk is high, regardless of sign-in risk, or use separate grant controls for medium-risk MFA and high-risk block.

Option A is wrong because report-only mode would not enforce MFA or blocking at all. Option C is wrong because the scenario describes a logic problem, not invalid JSON syntax. Option D is wrong because combining conditions with 'Or' would make the policy broader, not narrower, and would not explain the failure to block high-risk users.

94
Multi-Selectmedium

Your organization uses Azure Data Lake Storage Gen2 for big data analytics. You need to secure access to the data using Azure RBAC and ACLs. Which two methods can you use to authorize access? (Choose two.)

Select 2 answers
A.Configure IP firewall rules to restrict access.
B.Assign Azure RBAC roles such as Storage Blob Data Contributor to security principals.
C.Set POSIX-like access control lists (ACLs) on directories and files.
D.Use managed identities for Azure resources.
E.Generate shared access signatures (SAS) for delegated access.
AnswersB, C

Azure RBAC role assignments are the recommended, identity-based authorization method for controlling access to Azure Data Lake Storage Gen2. Roles like Storage Blob Data Contributor grant a security principal (user, group, service principal, or managed identity) permissions at the storage account, container, or directory/file scope using Azure's centralized control plane. When a principal makes a request, Azure evaluates RBAC assignments, integrating with Microsoft Entra ID, to determine coarse-grained access such as read, write, delete, and list, making this the go-to choice for broad or automated access control.

Why this answer

Option B is correct because Azure Data Lake Storage Gen2 supports Azure RBAC role assignments, such as Storage Blob Data Contributor, Storage Blob Data Reader, and Storage Blob Data Owner, to authorize security principals (users, groups, service principals, managed identities) at the container or account scope. Option C is correct because ADLS Gen2 implements a POSIX-like ACL model at the directory and file level, allowing fine-grained read, write, and execute permissions for named users and groups in addition to RBAC. Option A is not a valid authorization method here; IP firewall rules are network-level access restrictions, not an authorization mechanism for data access.

Option D is not itself an authorization method—managed identities are an identity type that must still be granted access via RBAC or ACLs. Option E is not the intended answer because SAS tokens are a delegation mechanism primarily associated with Blob Storage and are not the standard authorization approach for ADLS Gen2 hierarchical namespace access via RBAC and ACLs.

95
Multi-Selecthard

Your organization is implementing a secure DevOps pipeline for Azure. You need to ensure that secrets (e.g., API keys) are not stored in source code and that access to production resources is controlled. Which THREE practices should you implement?

Select 3 answers
A.Store secrets in Azure DevOps pipeline variables with encryption enabled
B.Use Azure Key Vault to store secrets and retrieve them at deployment time
C.Use Azure DevOps variable groups linked to Azure Key Vault
D.Store secrets in a configuration file in a private Git repository
E.Use managed identities for Azure resources to authenticate to Key Vault
AnswersB, C, E

Azure Key Vault is the centralized, hardware-backed secret store that offers fine-grained access policies, automated certificate/secret rotation, and comprehensive audit logs. Retrieving secrets at deployment time—via tasks like the Azure Key Vault task or by referencing Key Vault in ARM templates—ensures releases always use the current secret version and never hardcode credentials in code or config files. This pattern also enables legitimate emergency credential rollover without pipeline modifications.

Why this answer

Option B is correct because Azure Key Vault is the dedicated Azure service for centrally storing and managing secrets such as API keys, with encryption at rest and fine-grained access policies, so pipeline code never contains the secret values. Option C is correct because Azure DevOps variable groups can be linked to Azure Key Vault, which lets pipelines consume Key Vault secrets as variables at runtime without duplicating or hardcoding them in the pipeline definition. Option E is correct because managed identities for Azure resources give the pipeline or compute an automatically managed identity in Microsoft Entra ID, allowing it to authenticate to Key Vault without storing credentials, which directly supports controlled access to production resources.

Option A is not correct because pipeline variables with encryption enabled still store the secret within Azure DevOps rather than in a dedicated vault, lacking Key Vault's centralized governance, rotation, and auditing. Option D is not correct because a configuration file in a private Git repository still places secrets in source control, which is exactly the practice the scenario requires avoiding.

Exam trap

SC-100 often tests the misconception that encrypted pipeline variables or private Git repos are acceptable secret stores, when only a dedicated secrets manager with managed identity authentication meets the zero-trust bar.

96
MCQeasy

Your company uses Microsoft Defender for Cloud Apps to discover shadow IT. You need to ensure that data exfiltration from sanctioned cloud apps is blocked in real-time. Which control should you configure?

A.Conditional Access App Control
B.IP address ranges
C.Cloud discovery
D.App connector
AnswerA

Conditional Access App Control is a reverse-proxy based capability that integrates with Azure AD Conditional Access to enforce session policies on sanctioned cloud apps in real time. When a user accesses a configured app, the session is routed through Microsoft Defender for Cloud Apps, giving it the ability to inspect each request and response. This allows granular controls such as blocking downloads, preventing copy/paste, or forcing step-up authentication, which directly mitigates data exfiltration during the active session.

Why this answer

Conditional Access App Control is the correct answer because it enables real-time session monitoring and control over sanctioned cloud apps, allowing you to block data exfiltration actions such as downloads, copy/paste, and uploads via reverse proxy integration with Azure AD Conditional Access. It is specifically designed for inline enforcement on user sessions, which matches the requirement to block exfiltration in real time. IP address ranges are used for defining corporate network boundaries in Cloud Discovery, not for session-level blocking.

Cloud discovery only identifies shadow IT usage from logs and does not enforce real-time controls. App connectors provide API-based visibility and governance for sanctioned apps but do not block user actions in real time.

97
MCQmedium

A security architect is designing a data protection strategy for a Microsoft 365 tenant. The company must prevent users from sharing sensitive documents with external users via SharePoint Online. They want to apply a policy that automatically detects sensitive content and blocks external sharing. Which Microsoft Purview solution should they use?

A.Sensitivity labels
B.Retention policies
C.Data Loss Prevention (DLP) policy
D.Microsoft Purview Information Protection
AnswerC

Data Loss Prevention (DLP) policies are purpose-built to detect sensitive information (e.g., credit card numbers, PII) using sensitive info types and then take protective actions including blocking external sharing. In Microsoft Purview, a DLP policy can be scoped to SharePoint/OneDrive and configured with a rule that blocks sharing outside your organization while allowing users to override with justification, making it the correct control for this scenario.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies can detect sensitive data and block external sharing. Option C is correct. Option A is wrong because sensitivity labels require manual application or automatic classification, but blocking external sharing is typically done by DLP.

Option B is wrong because retention policies are for data retention, not blocking sharing. Option D is wrong because Microsoft Purview Information Protection is the umbrella, but the specific policy is DLP.

98
Multi-Selectmedium

You need to design a secure solution for a web application that authenticates users via Microsoft Entra ID and calls a downstream API. Which TWO should you implement to secure the application? (Choose TWO.)

Select 2 answers
A.Use the OAuth 2.0 authorization code flow with PKCE.
B.Store application secrets in Azure Key Vault.
C.Store application secrets in app configuration files.
D.Use the OAuth 2.0 client credentials flow.
E.Use shared access signatures (SAS) for API authentication.
AnswersA, B

The OAuth 2.0 authorization code flow with PKCE is the recommended authentication flow for web applications that need to authenticate users and obtain access tokens for downstream APIs. It provides proof of possession and mitigates interception attacks.

Why this answer

Option A is correct because the OAuth 2.0 authorization code flow with PKCE is the recommended pattern for interactive web applications that sign users in through Microsoft Entra ID and then call a downstream API on the user's behalf; PKCE protects the authorization code exchange against interception, and the resulting access token is presented to the API. Option B is correct because confidential client applications still need credentials (client secrets or certificates), and Azure Key Vault provides centralized, access-controlled, audited storage for those secrets instead of leaving them in code or config. Option C is wrong because storing secrets in app configuration files exposes them to anyone with file or repository access and is not a secure secret-management practice.

Option D is wrong for this scenario because the client credentials flow is a daemon/app-only flow with no user context, so it cannot authenticate interactive users. Option E is wrong because shared access signatures are an Azure Storage authorization mechanism, not an authentication protocol for a Microsoft Entra ID-protected web API.

99
MCQeasy

Your company uses Microsoft Purview to classify and protect sensitive data. You need to ensure that when a user sends an email containing a credit card number, the email is automatically encrypted and a notification is sent to the user. Which Microsoft Purview feature should you configure?

A.Sensitivity labels
B.Audit log policies
C.Insider risk management policies
D.Data Loss Prevention (DLP) policies
AnswerD

Microsoft Purview Data Loss Prevention (DLP) policies inspect email messages and attachments in transit against sensitive information types and trainable classifiers. When a matching sensitive item is detected, DLP can automatically enforce actions such as applying encryption (via Azure Rights Management), blocking delivery, or sending policy tips and notifications to users. This makes DLP the correct control for content-triggered automated encryption of outbound emails.

Why this answer

Data Loss Prevention (DLP) policies in Microsoft Purview are the correct choice because they can inspect email content for sensitive information types such as credit card numbers and trigger protective actions like encryption and user notifications. DLP rules support conditions based on sensitive info types and actions including encrypting messages and sending policy tips or notifications to the sender. Sensitivity labels apply protection based on manual or auto-labeling, but they do not natively detect credit card numbers in transit and send user notifications in the same rule-based way.

Audit log policies only record activity for later review, and insider risk management policies focus on detecting risky user behavior rather than automatically encrypting an email containing a credit card number.

100
MCQmedium

Your organization is deploying a new line-of-business application on Azure App Service. The app must authenticate users from Microsoft Entra ID and also access a downstream API that requires a client secret. You need to recommend the most secure method for managing the client secret. What should you use?

A.Store the secret in the Azure AD app registration manifest.
B.Store the secret in an App Service application setting.
C.Store the secret in Azure Key Vault and use a Key Vault reference in App Service.
D.Store the secret in the application code as a constant.
AnswerC

Correct. Azure Key Vault provides secure, centralized storage for secrets with encryption and access auditing. App Service can reference Key Vault secrets via Key Vault references, using a managed identity to authenticate without exposing the secret.

Why this answer

Storing the client secret in Azure Key Vault and referencing it from App Service via a Key Vault reference is the most secure method. Key Vault provides centralized secret management, access control via Entra ID, auditing, rotation capabilities, and hardware-backed protection (HSM) for keys. App Service can resolve Key Vault references at runtime using its managed identity, so the secret never appears in application settings or code.

Exam trap

SC-100 often tests the misconception that App Service application settings are secure because they are 'encrypted' — candidates may pick option B, but the exam expects Key Vault with managed identity as the only answer that provides centralized, auditable, rotatable secret management.

How to eliminate wrong answers

Option A is wrong because storing a secret in the app registration manifest exposes it in a readable configuration file and lacks rotation/audit controls. Option B is wrong because App Service application settings are stored in plaintext (or encrypted at rest but visible to anyone with portal/API access) and do not provide centralized rotation or auditing. Option D is wrong because hardcoding a secret in application code embeds it in source control and build artifacts, making rotation and leak remediation extremely difficult.

101
MCQmedium

Your organization uses Microsoft Sentinel to centralize security monitoring. You need to detect anomalous access to a critical Azure SQL Database from unusual geographic locations. Which data connector and analytic rule should you use?

A.Azure SQL Database connector and a custom scheduled query rule with geo-location
B.Azure Active Directory connector and an anomaly rule for sign-ins
C.Windows Security Events connector and a rule for failed logins
D.Azure Activity connector and a rule for resource deletion
AnswerA

The Azure SQL Database connector ingests diagnostic telemetry such as SQLInsights and QueryStoreRuntimeStatistics, which include the client IP address for every connection. A custom scheduled query rule can run KQL to map these IPs to geographic locations (using the GeoIP enrichment or a watchlist) and alert when a connection originates from a country that is abnormal for your environment. This directly captures data-plane connection attempts to Azure SQL, so it is the correct pairing of source and detection logic.

Why this answer

The correct option is A: Azure SQL Database connector and a custom scheduled query rule with geo-location. The Azure SQL Database connector ingests SQL audit and diagnostic logs into Microsoft Sentinel, which include client IP addresses, so a custom scheduled analytics rule can parse those IPs, enrich them with geo-location data (e.g., via the GeoIP watchlist or built-in functions), and alert on access from unusual regions. Option B does not fit because Azure AD sign-in anomaly rules cover identity authentication events, not direct database access.

Option C is wrong because Windows Security Events cover OS-level logons on Windows hosts, not Azure SQL Database access. Option D is wrong because Azure Activity logs track control-plane operations like resource deletion, not data-plane SQL connections.

102
MCQmedium

Your organization uses Microsoft Defender for Cloud to assess security posture. You need to ensure that your Azure App Service web applications are protected against common web vulnerabilities like SQL injection. What should you enable?

A.Web Application Firewall (WAF) on Azure Front Door
B.Just-in-time (JIT) VM access
C.Adaptive Application Controls
D.Azure DDoS Protection
AnswerA

Web Application Firewall (WAF) on Azure Front Door is the correct choice because it operates at the application layer (Layer 7) and uses managed rule sets (e.g., OWASP Core Rule Set) to inspect incoming HTTP/HTTPS requests for malicious payloads like SQL injection and cross-site scripting. By enforcing these rules at the edge, it blocks attacks before they reach the origin web server. Unlike network-level controls, WAF deeply inspects request bodies and headers, directly mitigating the vulnerability described in the question.

Why this answer

The correct option is A: Web Application Firewall (WAF) on Azure Front Door. A WAF inspects incoming HTTP/HTTPS traffic and applies managed rule sets (such as the OWASP Core Rule Set) to block common web exploits like SQL injection and cross-site scripting before they reach the App Service. Just-in-time (JIT) VM access (B) only brokers temporary, approved RDP/SSH access to virtual machines and has no bearing on web application layer attacks.

Adaptive Application Controls (C) are an Azure Security Center/Defender for Cloud feature that whitelists processes on VMs to detect anomalous execution, not HTTP payloads. Azure DDoS Protection (D) mitigates volumetric and protocol-level network floods, not application-layer injection attacks.

103
MCQmedium

Your company uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. You need to prevent users from sharing credit card numbers via email in Outlook on the web. The policy should notify users when they try to send such data and allow them to override with a business justification. What should you configure?

A.Create a DLP policy with the action 'Audit only' for credit card numbers
B.Create a DLP policy with the action 'Block with override' and enable 'Business justification'
C.Create a DLP policy that encrypts emails containing credit card numbers
D.Create a DLP policy with the action 'Block' for credit card numbers
AnswerB

'Block with override' in Purview DLP halts the sharing of credit card numbers by default, but when 'Business justification' is enabled, users can bypass the block if they provide a reason. This balances security with operational continuity, and because overrides are audited, it maintains accountability while preventing accidental data exposure.

Why this answer

The correct option is B: create a DLP policy with the action 'Block with override' and enable 'Business justification'. This is the only configuration that both prevents users from sending credit card numbers in Outlook on the web and lets them override the block by supplying a business justification, which is exactly what the scenario requires. Option A ('Audit only') merely logs activity without stopping the email, so it does not prevent sharing.

Option C (encrypting emails) addresses confidentiality but does not block or notify the sender with an override path. Option D ('Block') stops the email but provides no override mechanism, so users cannot proceed with a justification.

104
MCQmedium

Your team develops a web application hosted on Azure App Service. You need to secure the application against common web vulnerabilities like SQL injection and cross-site scripting. What should you implement?

A.Enable Azure Web Application Firewall (WAF) on Azure Front Door or Application Gateway.
B.Store application secrets in Azure Key Vault and enable managed identity.
C.Configure Network Security Groups (NSGs) on the App Service subnet to restrict inbound traffic.
D.Enable Azure DDoS Protection on the virtual network.
AnswerA

Azure WAF on Front Door or Application Gateway is the correct solution because it inspects incoming HTTP(S) requests at Layer 7, specifically filtering for SQL injection, cross-site scripting (XSS), and other OWASP Top 10 attack patterns before they reach the App Service backend. Using managed rule sets such as the OWASP CRS, it provides continuous, low-maintenance adaptability to new attack signatures. This directly addresses the described application vulnerabilities, unlike network- or secret-management controls.

Why this answer

The correct option is A: enabling Azure Web Application Firewall (WAF) on Azure Front Door or Application Gateway, because WAF provides managed rule sets (OWASP Core Rule Set) that inspect HTTP/HTTPS traffic and block layer 7 attacks such as SQL injection and cross-site scripting before they reach the App Service. Options B, C, and D do not address application-layer attacks: Key Vault with managed identity only protects secrets and credentials, NSGs filter traffic by IP/port/protocol at layers 3-4 and cannot detect SQLi or XSS payloads, and Azure DDoS Protection mitigates volumetric network-layer floods rather than web application vulnerabilities.

105
MCQmedium

You are reviewing the ARM template snippet for an Azure Storage container. What does the 'denyEncryptionScopeOverride' property set to 'true' ensure?

A.Double encryption is enabled for the container.
B.Encryption at rest is required for all blobs in the container.
C.The container automatically uses a customer-managed key for encryption.
D.Users cannot override the default encryption scope for blobs in this container.
AnswerD

Setting `denyEncryptionScopeOverride` to `true` on a container blocks any client from supplying an encryption scope different from the container's default scope on a per-blob request. As a result, every blob uploaded to this container is encrypted exactly with the default encryption scope, which administrators centrally define and manage. This is essential for compliance scenarios where data must always be encrypted with an approved key or key management policy.

Why this answer

Option D is correct because setting denyEncryptionScopeOverride to true on a container prevents clients from specifying a different encryption scope when uploading blobs, forcing them to use the container's default encryption scope. This property is specifically about locking the encryption scope at the container level, not about enabling or requiring encryption itself. Option A is wrong because double encryption is configured via infrastructure encryption settings, not this property.

Option B is wrong because encryption at rest is always enabled for Azure Storage blobs by default and is not controlled by denyEncryptionScopeOverride. Option C is wrong because customer-managed keys are configured through the account's encryption key source settings, not through this container property.

106
MCQeasy

Your organization is implementing Microsoft Defender for Cloud Apps to protect against malicious OAuth app permissions. Users have been granting permissions to third-party apps that request excessive scopes. What should you configure to automatically revoke such permissions?

A.OAuth app policies in Defender for Cloud Apps
B.Microsoft Intune app protection policies
C.Conditional Access policies
D.Azure AD app permissions management
AnswerA

OAuth app policies in Defender for Cloud Apps are the correct choice because they specifically enable automated governance for third-party applications that have been granted consent in Azure AD. These policies can continuously monitor the app's activity, user involvement, and permissions, and automatically revoke access or apply a quarantine action when the app is deemed risky or exceeds a preset threshold. Unlike manual remediation, these policies execute the revocation directly on the OAuth application, removing its granted permissions without requiring a user to revoke consent manually.

Why this answer

The correct option is A, OAuth app policies in Defender for Cloud Apps. These policies are purpose-built to detect risky or over-privileged OAuth apps and can automatically revoke user-granted permissions or disable the app when it matches conditions such as excessive scopes or low community use. Intune app protection policies (B) govern mobile app data handling (MAM) and do not revoke OAuth consent grants.

Conditional Access policies (C) control sign-in conditions and session access, not OAuth permission revocation. Azure AD app permissions management (D) allows reviewing and revoking consent grants manually but does not provide the automated, risk-based revocation that Defender for Cloud Apps OAuth app policies deliver.

107
MCQhard

Refer to the exhibit. A security administrator needs to ensure that the storage account 'securestore' is compliant with the company policy that requires encryption at rest using customer-managed keys and network access restricted to a specific virtual network. Which of the following statements is correct?

A.The storage account is compliant only if encryption is enabled for blob and file services.
B.The storage account is non-compliant because it uses Microsoft-managed keys for encryption.
C.The storage account is compliant because it uses customer-managed keys from Key Vault and network access is restricted to a specific virtual network.
D.The storage account is non-compliant because network access is allowed from any virtual network.
AnswerC

The storage account is compliant because encryption is configured with customer-managed keys from Key Vault, as shown by 'keySource': 'Microsoft.Keyvault', and the network rule 'defaultAction': 'Deny' is overridden only for a specific virtualNetworkResourceGroup and subnet. This combination ensures data at rest is encrypted with controlled keys and access is restricted to a designated virtual network, meeting policy requirements.

Why this answer

Option C is correct because it states that the storage account uses customer-managed keys from Key Vault for encryption at rest and restricts network access to a specific virtual network, which exactly matches the company policy requirements. Customer-managed keys stored in Azure Key Vault satisfy the encryption-at-rest requirement, and a virtual network rule or service endpoint scoped to one VNet satisfies the network restriction. Option A is wrong because enabling encryption for blob and file services does not by itself address the customer-managed key or network restriction requirements.

Option B is wrong because it assumes Microsoft-managed keys, which contradicts the scenario where customer-managed keys are used. Option D is wrong because it claims network access is open to any virtual network, which is not the case when access is restricted to a specific VNet.

108
MCQmedium

Your organization uses Microsoft Defender for Cloud to protect Azure resources. You need to ensure that only authorized applications can access Azure Key Vault secrets. The solution must use managed identities and least privilege. What should you configure?

A.Use a shared access signature (SAS) token stored in an environment variable
B.Assign a system-assigned managed identity to the application and grant it Key Vault Secrets User role
C.Enable public network access on Key Vault and restrict inbound IP addresses
D.Install a client certificate on the application server and use it to authenticate to Key Vault
AnswerB

A system-assigned managed identity creates an Azure Active Directory-backed identity directly tied to the application resource, so no credentials are stored in code or configuration. Granting only the Key Vault Secrets User role on the key vault enables least-privilege read access to secrets, and Azure automatically rotates the backing principal's credentials, which eliminates secret management and reduces the risk of credential leakage.

Why this answer

Option B is correct because assigning a system-assigned managed identity to the application and granting it the Key Vault Secrets User role provides an Azure AD-backed identity that can be authorized via RBAC to read secrets, eliminating stored credentials and enforcing least privilege. The Key Vault Secrets User role grants only read access to secret contents, which matches the requirement that only authorized applications access secrets. Option A is wrong because SAS tokens are not the managed identity mechanism for Key Vault and storing a token in an environment variable introduces a shared secret.

Option C is wrong because restricting inbound IP addresses controls network reachability, not application identity or least-privilege authorization. Option D is wrong because client certificate authentication does not use managed identities and requires certificate lifecycle management rather than Azure RBAC.

109
MCQeasy

You are designing security for a web application that will be developed by an external vendor. The vendor will have access to the source code repository and the development environment. You need to ensure that no secrets (e.g., API keys, connection strings) are stored in the source code. What is the best approach to manage secrets for this application?

A.Use Azure Key Vault to store secrets and configure the application to use managed identity to retrieve them.
B.Store secrets in environment variables on the application server.
C.Store secrets in Azure App Service application settings encrypted at rest.
D.Embed secrets in the compiled code using obfuscation.
AnswerA

Azure Key Vault provides centralized, hardware-backed secret storage with granular access policies and full audit logging. Pairing it with a managed identity means the application authenticates to Azure AD using a workload identity token, never needing a secret or connection string in code or configuration. This enables seamless secret rotation and supports the zero-standing-credentials principle, making it the only option that meets cloud-native security best practices.

Why this answer

Using Azure Key Vault to store secrets and referencing them from the application is the standard best practice. The application can use managed identity to authenticate to Key Vault securely. Storing secrets in app settings is not secure if the repository is accessible.

Using environment variables is better but still not as secure as Key Vault. Hardcoding is unacceptable.

110
MCQhard

Wide World Importers is deploying a critical line-of-business application on Azure Kubernetes Service (AKS). The application processes financial transactions and must meet SOX compliance. You need to design a security solution that includes: encryption of secrets (e.g., database connection strings) using Azure Key Vault, automatic certificate rotation for TLS termination, network isolation of the AKS cluster, and audit logging of all access to secrets. The solution should use a managed identity for the AKS cluster to access Key Vault. Which of the following designs meets the requirements?

A.Enable managed identity for the AKS cluster, integrate Key Vault with AKS using the Secrets Store CSI driver, deploy the cluster as a private cluster, and enable diagnostic settings on Key Vault to send logs to a Log Analytics workspace.
B.Use a service principal for AKS to access Key Vault, store secrets as Kubernetes secrets, configure a private cluster, and enable audit logging on Key Vault.
C.Enable managed identity for the AKS cluster, store secrets in the cluster's native Kubernetes secrets, use a private endpoint for the AKS API server, and enable Azure Monitor for containers.
D.Use a service principal to access Key Vault, store secrets as encrypted Kubernetes secrets with a customer-managed key, deploy a public cluster with network policies, and enable Key Vault logging.
AnswerA

Managed identity eliminates long-lived service principal credentials by providing an Azure AD-backed identity automatically rotated, which AKS uses to authenticate to Key Vault. The Secrets Store CSI driver mounts selected Key Vault items directly into pods as ephemeral volumes, so secret material never persists in etcd and supports rotation without pod restarts. Deploying AKS as a private cluster ensures the Kubernetes API server receives only private IP addresses, preventing exposure to the public internet. Enabling diagnostic settings on Key Vault streams audit event logs to Log Analytics, giving the security operations team a centralized, queryable trail of access and modifications.

Why this answer

Option A meets all requirements: using managed identity for AKS to access Key Vault (secure, no credentials), integrating Key Vault with AKS via the Secrets Store CSI driver (enables encryption and automatic certificate rotation), deploying as a private cluster (network isolation), and enabling diagnostic settings on Key Vault to send logs to Log Analytics (audit logging). This design leverages Azure-native integrations for security and compliance.

Exam trap

SC-100 often tests the preference for managed identity over service principals and the use of Azure Key Vault integration with AKS, causing candidates to overlook the need for the Secrets Store CSI driver and diagnostic settings for comprehensive compliance.

How to eliminate wrong answers

Option B is wrong because it uses a service principal instead of managed identity, which requires managing credentials and is less secure; also, storing secrets as Kubernetes secrets does not provide encryption with Key Vault or automatic rotation. Option C is wrong because it stores secrets in native Kubernetes secrets (not encrypted with Key Vault) and uses a private endpoint for the API server, which provides network isolation but does not address secret encryption or rotation; Azure Monitor for containers does not audit Key Vault access. Option D is wrong because it uses a service principal, stores secrets as encrypted Kubernetes secrets with customer-managed key (not Key Vault integration for secrets), deploys a public cluster (not network isolated), and Key Vault logging alone does not ensure audit logging of all access to secrets in the context of AKS.

111
Multi-Selecteasy

Your organization wants to enable Microsoft Defender for Cloud Apps to monitor and control the use of Box and Dropbox. Which TWO steps must you perform?

Select 2 answers
A.Connect the app using an app connector
B.Add Box and Dropbox to the unsanctioned list
C.Deploy a forward proxy
D.Configure Conditional Access App Control
E.Run a cloud discovery report
AnswersA, D

App connectors in Microsoft Defender for Cloud Apps leverage the cloud provider's native APIs (e.g., Box and Dropbox REST APIs) to pull metadata, activities, and file content for continuous, near-real-time monitoring. This allows you to enforce data loss prevention policies, detect user anomalies, and apply governance actions without relying on traffic interception. This is the correct method because it integrates directly with the apps you want to monitor and control, giving you full visibility and control over sanctioned usage.

Why this answer

Option A is correct because Defender for Cloud Apps monitors and governs sanctioned SaaS apps such as Box and Dropbox by connecting them through an app connector (API connector), which uses the app's APIs and OAuth to pull activity logs, files, and user data for governance and control. Option D is correct because Conditional Access App Control (session control) uses Azure AD Conditional Access policies and a reverse proxy to enforce real-time session controls like block download, block upload, and read-only access for Box and Dropbox. Option B is incorrect because adding apps to the unsanctioned list only tags them in Cloud Discovery as unsanctioned; it does not enable monitoring or control of the apps.

Option C is incorrect because a forward proxy is not required; Cloud Discovery can use log upload or Defender for Cloud Apps log collectors, and session control uses a reverse proxy, not a forward proxy. Option E is incorrect because running a Cloud Discovery report only provides visibility into discovered apps and does not by itself enable monitoring and control of Box and Dropbox.

112
MCQeasy

Your organization is using Microsoft Defender for Cloud to assess the security posture of your Azure resources. You need to ensure that all storage accounts have secure transfer required enabled. Which Defender for Cloud feature should you use?

A.Security policies and initiatives
B.File integrity monitoring
C.Adaptive network hardening
D.Just-In-Time VM access
AnswerA

Security policies and initiatives in Microsoft Defender for Cloud are built on Azure Policy and include regulatory compliance frameworks like the Microsoft cloud security benchmark. These initiatives contain policy definitions that can audit, deny, or deploy settings such as 'Secure transfer to storage accounts should be enabled' (supportsHttpsTrafficOnly). When assigned to a subscription, Defender for Cloud continuously evaluates storage account compliance and can enforce secure transfer automatically via a DeployIfNotExists effect, directly addressing the requirement to enable secure transfer.

Why this answer

Security policies and initiatives in Microsoft Defender for Cloud are the correct choice because they let you define and assign Azure Policy definitions—such as the built-in 'Secure transfer to storage accounts should be enabled' policy—that continuously assess storage accounts and flag any that lack Secure transfer required (HTTPS-only). This directly addresses the requirement to ensure all storage accounts have secure transfer enabled. File integrity monitoring is incorrect because it tracks changes to OS files and registry keys on VMs, not storage account configuration.

Adaptive network hardening is incorrect because it generates NSG rules based on traffic analysis, and Just-In-Time VM access is incorrect because it restricts inbound VM ports on demand—neither evaluates storage account encryption-in-transit settings.

113
MCQeasy

Your organization is adopting Microsoft Copilot for Microsoft 365. You need to ensure that Copilot respects the existing sensitivity labels when processing data. What should you configure?

A.Create Data Loss Prevention (DLP) policies.
B.Configure sensitivity labels in Microsoft Purview Information Protection.
C.Use Azure Information Protection.
D.Apply retention labels to documents.
AnswerB

Sensitivity labels in Microsoft Purview Information Protection apply persistent, tamper-proof metadata to content—such as confidentiality, encryption, and visual markings—which Copilot for Microsoft 365 explicitly consumes to determine whether it may summarize, extract, or generate from the underlying data. Because the labels are honored inside the Microsoft 365 ecosystem, they provide the granular, per-item control needed to govern AI responses. This is the correct answer as it establishes classification at the source.

Why this answer

The correct option is B: Configure sensitivity labels in Microsoft Purview Information Protection. Copilot for Microsoft 365 honors the sensitivity labels applied to content, so labels must be defined and published through Microsoft Purview Information Protection (the current unified labeling platform) for Copilot to respect classification and protection settings such as encryption and content marking. DLP policies (A) enforce rules on sharing or handling of sensitive data but do not provide the classification metadata Copilot uses to respect sensitivity.

Azure Information Protection (C) is the legacy labeling client/service being retired in favor of Purview Information Protection, so it is not the configuration target. Retention labels (D) govern lifecycle and retention, not sensitivity-based protection, so they do not control how Copilot treats sensitive content.

114
MCQmedium

You are designing a solution to protect an Azure App Service web app that authenticates users via Microsoft Entra ID. The app needs to ensure that only users from specific external partner organizations can access it. You do not want to create user objects for each partner user in your tenant. What should you configure?

A.Configure a Conditional Access policy that restricts access to partners' IP ranges.
B.Enable Microsoft Entra B2B collaboration and configure the application to accept tokens from partner tenants.
C.Create guest user accounts for each external user and assign them to a group.
D.Use Azure AD B2C custom policies to allow partner authentication.
AnswerB

Enabling Microsoft Entra B2B collaboration is the correct approach because it lets external partners authenticate with their own home tenant credentials while the application is configured to accept tokens from those partner tenants. A B2B guest object is created in your directory for authorization, but no full user object or local credential exists, keeping your tenant clean and reducing password management. This supports true federation, single sign-on, and lifecycle management via the partner's identity provider. The application can use tenant allowlists to trust tokens from specific partner tenants, aligning with zero-trust principles.

Why this answer

Option B is correct because Microsoft Entra B2B collaboration lets partner users authenticate with their own organizational credentials and receive tokens from their home tenant, which the app can accept without creating user objects in your tenant. This directly satisfies the requirement to allow only specific external partner organizations while avoiding per-user objects in your directory. Option A is insufficient because IP-range restrictions do not identify or validate partner organizations and can be bypassed or misapplied.

Option C contradicts the requirement by creating guest user objects for each external user. Option D is wrong because Azure AD B2C is intended for customer-facing identity scenarios with local or social accounts, not for federating access with specific partner Microsoft Entra tenants.

115
MCQmedium

A company is implementing Microsoft Priva to manage subject rights requests. Users submit requests to access their personal data stored in Exchange Online, SharePoint, and Teams. The privacy team needs to automate the retrieval of data from these sources. Which Priva capability should they use?

A.Subject Rights Requests
B.Consent Management
C.Data Inventory
D.Data Breach Notifications
AnswerA

Subject Rights Requests in Microsoft Priva is the automated workflow that locates, retrieves, and packages personal data stored across Microsoft 365 services to fulfill data subject requests such as access, export, and deletion. It uses data profiles and content search to identify relevant records, then facilitates review in a centralized case management experience, making it the correct module for managing subject rights requests.

Why this answer

Microsoft Priva's Subject Rights Requests capability is purpose-built to automate the intake, search, and fulfillment of data subject access requests (DSARs) across Microsoft 365 workloads including Exchange Online, SharePoint, OneDrive, and Teams. It provides templates, automated searches, and review workflows that map directly to the scenario described.

Exam trap

The trap is confusing Priva's privacy risk management features (Data Inventory, Consent Management) with the DSAR-specific Subject Rights Requests capability; only the latter automates personal data retrieval across M365 workloads.

How to eliminate wrong answers

Option B is wrong because Consent Management in Priva handles tracking and managing user consent for data processing, not retrieving personal data for DSARs. Option C is wrong because Data Inventory (part of Priva Privacy Risk Management) maps and classifies personal data across the tenant for visibility, but does not fulfill subject access requests. Option D is wrong because Data Breach Notifications is not a distinct Priva capability for DSAR automation — breach response is handled through other compliance tooling.

116
Multi-Selecteasy

Your company, Fabrikam, is designing a solution to securely store and manage secrets (e.g., API keys, database passwords) for cloud applications. The solution must use Azure Key Vault and support automatic rotation of secrets. The applications will run on Azure VMs and Azure App Service. Which TWO of the following should you include in your design?

Select 2 answers
A.Use service principals with client secrets to authenticate to Key Vault.
B.Rotate secrets manually using Azure Automation runbooks on a schedule.
C.Store secrets in application configuration files encrypted with Azure Key Vault.
D.Implement automatic secret rotation using Key Vault with Event Grid and Azure Functions.
E.Use managed identities for Azure resources to authenticate to Key Vault.
AnswersD, E

Implementing automatic secret rotation using Key Vault with Event Grid and Azure Functions uses an event-driven model: Key Vault emits SecretNearExpiry events to Event Grid when a secret approaches expiration, and Event Grid triggers an Azure Function to generate a new secret version and store it back in the vault. This approach reacts in near real-time to actual secret lifecycle states, avoids manual scheduling, and is serverless and scalable, requiring no custom infrastructure. It automatically keeps secrets fresh, reduces the risk of expiration-related service outages, and eliminates the need for human-initiated rotation scripts.

Why this answer

Option E is correct because managed identities for Azure resources let Azure VMs and App Service apps authenticate to Key Vault without storing any credentials in code or configuration, which is the recommended, most secure authentication method for this scenario. Option D is correct because Key Vault's secret rotation can be automated by emitting near-expiration events to Event Grid, which triggers an Azure Function to generate and write a new secret version back into Key Vault, satisfying the automatic rotation requirement. Option A is not appropriate because service principals with client secrets require you to store and manage a credential, reintroducing the secret-management problem managed identities solve.

Option B is wrong because manual rotation via Azure Automation runbooks is not automatic rotation and adds operational overhead. Option C is wrong because storing secrets in application configuration files, even if encrypted with Key Vault, does not use Key Vault as the secret store and undermines centralized secure storage and rotation.

117
MCQeasy

Your organization is planning to use Microsoft Sentinel for security information and event management (SIEM). You need to ingest security logs from on-premises Active Directory. What should you deploy?

A.Microsoft Monitoring Agent (MMA)
B.Log Analytics agent
C.Microsoft Defender for Cloud agent
D.Azure Monitor Agent
AnswerD

Azure Monitor Agent (AMA) is the correct modern agent for Microsoft Sentinel because it unifies data collection across the entire Azure Monitor platform. It uses data collection rules (DCRs) to define exactly which data sources to collect, enabling granular filtering, multi-homing to multiple workspaces, and support for both Windows and Linux without the overhead of separate agents. AMA is the only forward-looking agent that Microsoft is actively investing in, with rich features like network isolation, Azure Arc support, and the ability to handle all log types Sentinel consumes.

Why this answer

The correct option is D, Azure Monitor Agent (AMA). AMA is the current, supported agent for collecting data into Log Analytics workspaces, which back Microsoft Sentinel, and it supports Data Collection Rules (DCRs) to ingest Windows security events from on-premises Active Directory domain controllers via the Azure Arc-enabled servers or the AMA extension. The Microsoft Monitoring Agent (A) and the Log Analytics agent (B) are legacy agents that are deprecated for Sentinel data collection and are being replaced by AMA.

The Microsoft Defender for Cloud agent (C) is not a standalone log-ingestion agent for Sentinel; Defender for Cloud uses the Log Analytics/AMA agents for data collection, so it does not fit the requirement directly.

118
MCQhard

Your company, Lucerne Publishing, is migrating its on-premises SQL Server databases to Azure SQL Managed Instance. The databases contain sensitive customer data subject to GDPR. You need to design a security solution that includes: (1) Always Encrypted for sensitive columns, (2) dynamic data masking for non-privileged users, (3) auditing of all data access, and (4) encryption at rest using customer-managed keys stored in Azure Key Vault. Which of the following configurations should you implement?

A.Enable Always Encrypted for sensitive columns, configure dynamic data masking, enable auditing via Azure Policy, and enable TDE with a customer-managed key stored in Azure Key Vault.
B.Enable Always Encrypted for sensitive columns, configure dynamic data masking, disable TDE to improve performance, and use row-level security to restrict access.
C.Enable Always Encrypted for sensitive columns, configure dynamic data masking, enable SQL Server auditing to Azure Blob Storage, and enable Transparent Data Encryption (TDE) with a service-managed key.
D.Enable Always Encrypted for sensitive columns, configure dynamic data masking, enable Azure SQL auditing to a Log Analytics workspace, and enable TDE with a customer-managed key stored in Azure Key Vault.
AnswerD

This is the correct combination because each service maps to a distinct requirement: Always Encrypted protects sensitive columns cryptographically so database administrators and compromised servers cannot read plaintext; Dynamic Data Masking limits unauthorized display of sensitive data; Azure SQL auditing sends fine-grained query and security logs to Log Analytics for centralized monitoring; and TDE with a customer-managed key in Azure Key Vault gives you control over encryption keys for at-rest protection, including rotation and revocation. Together they form a layered defense without conflicting overrides, and all are native to Azure SQL Managed Instance.

Why this answer

The correct configuration must satisfy all four requirements: Always Encrypted for sensitive columns, dynamic data masking for non-privileged users, auditing of all data access, and encryption at rest with customer-managed keys in Azure Key Vault. Option D meets all four by enabling Azure SQL auditing to a Log Analytics workspace and TDE with a customer-managed key stored in Azure Key Vault, alongside Always Encrypted and dynamic data masking.

Exam trap

SC-100 often tests whether candidates conflate Azure Policy with SQL auditing, or accept service-managed keys when customer-managed keys are explicitly required.

How to eliminate wrong answers

Option A is wrong because enabling auditing via Azure Policy does not by itself configure SQL auditing of all data access; auditing must be enabled on the SQL resource. Option B is wrong because disabling TDE violates the encryption-at-rest requirement and row-level security does not replace TDE. Option C is wrong because using a service-managed key for TDE violates the customer-managed key requirement, even though auditing to Blob Storage is acceptable.

119
MCQmedium

Your organization is designing a new application that will store sensitive customer data in Azure Cosmos DB. You need to ensure that data at rest is encrypted using a customer-managed key (CMK) stored in Azure Key Vault. What should you configure?

A.Enable Transparent Data Encryption (TDE) on the Cosmos DB account.
B.Enable Azure Storage Service Encryption (SSE) on the Cosmos DB account.
C.Use Always Encrypted with Azure SQL Database.
D.Configure a customer-managed key in Azure Key Vault and assign it to the Cosmos DB account.
AnswerD

To meet a bring-your-own-key (BYOK) requirement on Azure Cosmos DB, you must configure a customer-managed key in Azure Key Vault and associate it with the Cosmos DB account. This uses envelope encryption where the Key Vault key wraps the account's data encryption keys, allowing you to independently rotate, revoke, or audit key usage. You can establish this by assigning a key URI from Key Vault to the Cosmos DB account (typically via a managed identity and appropriate Key Vault access policy), which gives you control over at-rest encryption.

Why this answer

Option D is correct because Azure Cosmos DB supports encryption at rest with customer-managed keys (CMKs), which are created and stored in Azure Key Vault and then assigned to the Cosmos DB account via its encryption settings. This satisfies the requirement to control the key used for data-at-rest encryption rather than relying on Microsoft-managed keys. Option A is incorrect because Transparent Data Encryption (TDE) is an Azure SQL feature, not a Cosmos DB configuration.

Option B is incorrect because Azure Storage Service Encryption (SSE) applies to Azure Storage services, not Cosmos DB. Option C is incorrect because Always Encrypted is an Azure SQL Database/client-side encryption feature and does not configure CMK encryption for Cosmos DB.

120
MCQmedium

A healthcare organization is using Microsoft Purview to govern its data estate. They have multiple Azure Data Lake Storage accounts and Azure SQL Databases. They need to classify sensitive data such as patient health information (PHI) and apply protection automatically when data is exported from these sources to an external location. The organization also wants to prevent unauthorized users from accessing sensitive data in Azure SQL Database by using built-in security features. The compliance team requires that any access to sensitive data be logged and auditable. You need to design a solution that meets these requirements. What should you implement?

A.Use Microsoft Purview to scan and classify data. Auto-apply sensitivity labels. Implement Azure AD authentication and row-level security in Azure SQL Database. Enable auditing and send to Log Analytics.
B.Use Microsoft Purview to scan and classify data. Apply sensitivity labels manually. Configure Azure SQL Database firewall to block all but admin. Use Azure SQL auditing.
C.Use Microsoft Defender for Cloud to identify sensitive data. Implement Azure SQL Database always encrypted. Use Azure Monitor to log queries.
D.Use Microsoft Purview to classify data. Apply data masking in Azure SQL Database for PHI columns. Use Azure SQL Database threat detection.
AnswerA

This option is correct because it combines Purview's scanning with auto-applied sensitivity labels, ensuring consistent classification without manual effort. Azure AD authentication replaces SQL logins with identity-based access, and row-level security (RLS) filters PHI at the query level so authorized users only see rows they are permitted to access. Enabling auditing to Log Analytics creates an immutable, queryable record of all data access and label changes, satisfying auditability requirements that are essential for healthcare compliance.

Why this answer

Microsoft Purview can scan data sources like Azure Data Lake Storage and Azure SQL Database, classify sensitive data such as PHI, and auto-apply sensitivity labels. Azure SQL Database supports Azure AD authentication and row-level security (RLS) to restrict access to sensitive data based on user identity. Auditing logs can be sent to Log Analytics for compliance.

Option B is incorrect because it requires manual labeling and does not use row-level security. Option C uses Defender for Cloud (not Purview) and Always Encrypted (which does not prevent access to authorized users). Option D uses data masking (obfuscation) rather than access control and lacks auto-labeling and auditing integration.

121
MCQhard

Refer to the exhibit. A security architect is reviewing the network configuration of an Azure App Service app named 'finance-app'. The app needs to be accessible from a backend subnet via private endpoint. Which additional configuration is required?

A.Set publicNetworkAccess to Enabled
B.Configure regional VNet integration for the app
C.Create a private endpoint and associate it with the App Service
D.Enable IP-based SSL for the app
AnswerC

A private endpoint creates a network interface with a private IP address in the virtual network, allowing clients inside the VNet (or connected via peering/VPN) to reach the App Service without traversing the public internet. Simply associating the private endpoint with the App Service, however, does not automatically remove the public endpoint; you must also set publicNetworkAccess to Disabled and apply access restrictions to block all public traffic. This combination gives true private inbound connectivity and satisfies the requirement.

Why this answer

The correct option is C: Create a private endpoint and associate it with the App Service. For an Azure App Service app to be reachable from a backend subnet over a private IP, a private endpoint must be created and linked to the app, which provisions a private IP in the target subnet via Azure Private Link. Option A is wrong because setting publicNetworkAccess to Enabled exposes the app publicly rather than providing private access.

Option B is wrong because regional VNet integration enables outbound traffic from the app into a VNet, not inbound private access to the app. Option D is wrong because IP-based SSL only binds a certificate to an IP address and does not create private connectivity.

← PreviousPage 2 of 2 · 121 questions total

Ready to test yourself?

Try a timed practice session using only Security Apps Data Solutions questions.