Courseiva

CCNA Security Best Practices Priorities Questions

67 of 142 questions · Page 2/2 · Security Best Practices Priorities topic · Answers revealed

76
MCQhard

Contoso is a large enterprise with a complex Azure environment. They have multiple management groups, subscriptions, and a hub-spoke network topology. The security team wants to implement a consistent security baseline across all subscriptions using Azure Policy. They need to ensure that: 1) All resources must be deployed in approved regions only. 2) Network security groups must have specific rules to block high-risk ports. 3) All storage accounts must enforce HTTPS traffic. 4) The policies must be applied at the management group level to ensure inheritance. 5) Non-compliant resources must be automatically remediated where possible. What should you do?

A.Use Azure Policy Guest Configuration to enforce region and NSG rules. Assign policies at each subscription. Use Azure Automation runbooks for remediation.
B.Create custom Azure Policy definitions for the required configurations (allowed locations, NSG rule blocking ports, storage HTTPS). Assign the policies at the root management group. Enable 'deployIfNotExists' effect for automatic remediation of non-compliant resources. Use Azure Policy remediation tasks to fix existing non-compliant resources.
C.Use Azure Blueprints to define the environment. Include Azure Policy assignments in the blueprint. Assign blueprint to each management group. Remediate manually.
D.Create a custom script using Azure PowerShell to check compliance daily. Use Azure Logic Apps to send alerts for non-compliance. Have IT staff manually fix issues.
AnswerB

This is the correct approach because Azure Policy is the native, continuous compliance service for resource-level configurations. By creating custom policy definitions for allowed locations, NSG rules, and storage HTTPS and assigning them at the root management group, the policies inherit to all child subscriptions and resource groups, providing a single, central governance baseline. Enabling the DeployIfNotExists effect makes Azure Policy automatically deploy the required configuration (e.g., a compliant NSG or secure storage setting) whenever a non-compliant resource is created or updated, and remediation tasks then correct pre-existing non-compliant resources, closing the compliance gap without manual intervention.

Why this answer

It uses Azure Policy at the root management group to enforce inheritance across all subscriptions, with custom policy definitions for allowed locations, NSG rules blocking high-risk ports, and storage HTTPS. The 'deployIfNotExists' effect enables automatic remediation of non-compliant resources, and remediation tasks fix existing non-compliant resources, meeting all requirements without manual intervention.

Exam trap

The trap here is confusing Azure Policy's 'deployIfNotExists' effect with manual remediation or third-party automation, leading candidates to choose options that lack native, automatic, and inherited policy enforcement at the management group level.

How to eliminate wrong answers

Option A is wrong because Azure Policy Guest Configuration is designed for in-guest machine settings (e.g., OS configuration), not for enforcing region, NSG rules, or storage HTTPS; assigning policies at each subscription breaks inheritance, and Azure Automation runbooks are not the native remediation mechanism for Azure Policy. Option C is wrong because Azure Blueprints are used for orchestrating resource deployments (including policy assignments) but do not provide automatic remediation; manual remediation violates the requirement for automatic remediation where possible. Option D is wrong because a custom PowerShell script with Logic Apps alerts and manual fixes is not a scalable, automated, or policy-driven solution; it lacks inheritance, automatic remediation, and centralized enforcement at the management group level.

77
Multi-Selectmedium

Which TWO Microsoft security solutions should be integrated to provide a comprehensive Zero Trust architecture that includes identity protection, endpoint detection, and response? (Select exactly two correct options.)

Select 2 answers
A.Microsoft 365 E5
B.Microsoft Defender XDR
C.Microsoft Entra ID
D.Microsoft Sentinel
E.Microsoft Purview
AnswersB, C

Microsoft Defender XDR is a core security solution because it correlates signals across endpoints, email, identities, and cloud apps, enabling extended detection and response. In a Zero Trust architecture, it serves as the enforcement and detection plane that consumes identity and endpoint telemetry. Integrating it with Entra ID lets suspicious identity behavior trigger automated response actions such as blocking a sign-in.

Why this answer

Microsoft Defender XDR (B) is correct because it is the extended detection and response platform that unifies signals across endpoints (Defender for Endpoint), identities (Defender for Identity), email and collaboration (Defender for Office 365), and cloud apps (Defender for Cloud Apps), delivering automated endpoint detection and response capabilities required by the scenario. Microsoft Entra ID (C) is correct because it provides the identity protection pillar of Zero Trust, including Conditional Access, risk-based sign-in and user risk detection via Entra ID Protection, and phishing-resistant authentication such as FIDO2 and Windows Hello for Business. Together, Entra ID secures and verifies identities while Defender XDR detects, investigates, and responds to threats across endpoints and other workloads, satisfying the identity protection plus endpoint detection and response requirement.

Microsoft 365 E5 (A) is a licensing bundle rather than a distinct security solution, so it does not itself constitute the integration of identity protection and XDR. Microsoft Sentinel (D) is a SIEM/SOAR platform for centralized log ingestion and orchestration, not the endpoint detection and response engine, and Microsoft Purview (E) focuses on data governance, compliance, and information protection rather than identity or endpoint threat response.

Exam trap

The trap here is that candidates often confuse Microsoft 365 E5 (a licensing bundle) with a specific security solution, or they mistakenly think Microsoft Sentinel (a SIEM) fulfills the endpoint detection requirement, when in fact Sentinel is for log analysis and not for real-time endpoint detection and response.

78
Multi-Selecthard

A company is deploying Microsoft Entra ID Governance. They need to implement a least privilege access model for their Azure resources. Which TWO features should they use? (Choose two.)

Select 2 answers
A.Privileged Identity Management (PIM)
B.Identity Protection
C.Conditional Access policies
D.Microsoft Intune compliance policies
E.Entitlement Management
AnswersA, E

PIM provides just-in-time, time-bound, and approval-based activation of privileged roles across Azure AD, Azure resources, and other Microsoft services. It eliminates permanent standing admin access by requiring users to request activation for a limited window, with MFA and policy-based approvals. In an Entra ID governance deployment, PIM directly governs the assignment and activation of privileged roles, making it the correct answer for the scenario.

Why this answer

Privileged Identity Management (PIM) is correct because it provides just-in-time (JIT) privileged access to Azure resources, enabling time-bound and approval-based role activation. This directly supports a least privilege model by ensuring users only have elevated permissions when needed, reducing standing access.

Exam trap

The trap here is confusing Identity Protection (a risk-detection tool) or Conditional Access (an access-enforcement tool) with governance features that directly manage role assignments and time-bound access, leading candidates to overlook the two specific features designed for least privilege in Azure resources.

79
Multi-Selectmedium

Which TWO actions align with the Zero Trust principle of 'verify explicitly'? (Select two.)

Select 2 answers
A.Deploy a VPN for remote access
B.Use conditional access policies to evaluate user and device risk before granting access
C.Encrypt all data at rest
D.Require multifactor authentication for all users
E.Implement network segmentation to limit lateral movement
AnswersB, D

Conditional Access policies in Microsoft Entra ID act on real-time signals such as user risk, device compliance state, sign-in location, and session risk to allow access, block it, or trigger step-up authentication. This is a direct implementation of 'verify explicitly' because every access attempt is evaluated against multiple context-aware criteria before a token is issued or access is granted. The same user can be permitted on a compliant managed device but blocked or challenged when the same request originates from an unmanaged personal device, embodying never-trust-always-verify.

Why this answer

Option B is correct because conditional access policies in Microsoft Entra ID evaluate signals such as user risk, sign-in risk, device compliance, and location at the moment of each access request, which is the essence of 'verify explicitly' — authenticating and authorizing based on all available contextual signals rather than a one-time check. Option D is correct because requiring multifactor authentication for all users forces verification of identity through multiple independent credential factors (something you know plus something you have or are), directly implementing the 'verify explicitly' tenet instead of trusting a single password. The unmarked options do not belong: A (VPN for remote access) primarily establishes a secure tunnel and perimeter-style access, which is more aligned with network-based trust than explicit per-request verification; C (encrypting data at rest) supports the 'assume breach' tenet by protecting data confidentiality, not identity verification; and E (network segmentation) limits lateral movement, which also maps to 'assume breach' rather than 'verify explicitly'.

Exam trap

Microsoft often tests the misconception that encryption or network segmentation are forms of verification, but they are actually data protection and containment controls, respectively, and do not satisfy the 'verify explicitly' requirement of Zero Trust.

80
Multi-Selecteasy

Your organization is implementing a Zero Trust network architecture in Azure. Which TWO principles are foundational to Zero Trust?

Select 2 answers
A.Use network segmentation
B.Verify explicitly
C.Assume breach
D.Rely on perimeter security
E.Trust but verify
AnswersB, C

Verifying explicitly is the core zero trust principle: every access request is authenticated and authorized based on all available data points, including user identity, device posture, location, data classification, and anomaly signals. This eliminates implicit trust and ensures that access decisions are made for each session and each request, even for previously authenticated entities. It is the primary principle that distinguishes zero trust from traditional perimeter models.

Why this answer

Option B, 'Verify explicitly,' is correct because Zero Trust requires that every access request be authenticated and authorized based on all available data points—user identity, device health, location, and workload—rather than granting implicit trust based on network location. Option C, 'Assume breach,' is correct because Zero Trust operates on the assumption that the environment is already compromised, so organizations must minimize blast radius through micro-segmentation, end-to-end encryption, and continuous monitoring to detect and respond to threats. These two principles, along with 'Use least privilege access,' form the three core Zero Trust principles as defined by Microsoft and NIST SP 800-207.

Option A, 'Use network segmentation,' is a technique or implementation control that supports Zero Trust rather than a foundational principle itself. Option D, 'Rely on perimeter security,' contradicts Zero Trust, which explicitly rejects the castle-and-moat model of trusting everything inside the corporate firewall. Option E, 'Trust but verify,' is a traditional security adage that still implies initial trust, which is incompatible with Zero Trust's requirement to never trust implicitly.

Exam trap

The trap here is that candidates often confuse network segmentation (a tactical control) with the strategic Zero Trust principle of 'Assume breach', or mistakenly think 'Trust but verify' is acceptable when the exam requires the explicit 'Verify explicitly' and 'Assume breach' as the two foundational pillars.

81
MCQmedium

Refer to the exhibit. You are reviewing an ARM template that deploys a network security group (NSG) for a web application. The NSG allows inbound HTTP traffic from any source and then denies all other inbound traffic. However, after deployment, you find that HTTP traffic is being blocked. What is the most likely cause?

A.The AllowHTTP rule uses sourcePortRange '*' which conflicts with the DenyAll rule.
B.The NSG is not associated with the subnet or network interface where the web server is deployed.
C.The DenyAll rule has a higher priority than the AllowHTTP rule, so it takes precedence.
D.The DenyAll rule uses protocol '*' which blocks all traffic including HTTP.
AnswerC

In Azure, NSG rules are evaluated in ascending priority order, where smaller numbers are processed first and the first matching rule determines the outcome. If DenyAll has a numerically lower priority (e.g., 100) than AllowHTTP (e.g., 200), then incoming TCP port 80 HTTP traffic matches DenyAll first, and since its action is Deny, the packet is dropped before AllowHTTP is ever considered. This explicit numeric precedence is the direct cause of the HTTP failure, making the higher priority of DenyAll the definitive reason.

Why this answer

The DenyAll rule has a higher priority (lower priority number) than the AllowHTTP rule, so it is evaluated first and blocks all traffic, including HTTP. To fix this, the AllowHTTP rule should have a higher priority (lower number) than the DenyAll rule.

Exam trap

Candidates often overlook that NSG rules are evaluated in priority order (lower number = higher priority). A deny-all rule with a priority lower than the allow rule will block the intended traffic.

How to eliminate wrong answers

Option A is wrong because sourcePortRange '*' is the default wildcard that matches any source port and does not conflict with the DenyAll rule; port ranges are evaluated independently, and a wildcard source port does not cause blocking. Option C is wrong because the DenyAll rule must have a higher priority number (lower precedence) than the AllowHTTP rule to be effective; if the DenyAll rule had a higher priority (lower number), it would override the Allow rule, but the question implies the Allow rule is correctly prioritized, so this is not the cause. Option D is wrong because protocol '*' matches all protocols, including HTTP (TCP port 80), but the DenyAll rule is intended to block all traffic; the issue is not the protocol wildcard but the lack of NSG association, as the DenyAll rule would only block traffic if the NSG were applied.

82
MCQmedium

Fabrikam is a healthcare organization that uses Microsoft 365 E5 and Azure. They have a hybrid identity environment with Active Directory on-premises synced to Microsoft Entra ID. The security team wants to implement a Zero Trust strategy following the 'verify explicitly' principle. They need to ensure that all access to Microsoft 365 services and Azure applications is conditionally enforced based on real-time risk signals. Additionally, they want to block legacy authentication protocols that do not support modern authentication. The solution must integrate with Microsoft Defender XDR and Microsoft Sentinel for threat intelligence. Which combination of technologies should you recommend?

A.Implement Azure AD Identity Governance with access reviews. Use Conditional Access to require hybrid Azure AD joined devices. Block legacy authentication by disabling protocols in Exchange Online. Use Azure Sentinel without Defender XDR.
B.Use Azure AD B2B for external users only. Configure Conditional Access with MFA for all users. Use Azure AD Identity Protection for risk. Block legacy authentication at the firewall level.
C.Deploy Microsoft Intune for mobile device management and require compliant devices. Use Conditional Access to block legacy protocols. Rely on Azure ATP (now Microsoft Defender for Identity) for risk signals.
D.Use Microsoft Entra Conditional Access policies with session controls from Microsoft Defender for Cloud Apps. Enable Microsoft Entra ID Protection to feed risk signals into Conditional Access. Block legacy authentication via a Conditional Access policy targeting 'Exchange Active Sync' and 'Other clients'. Integrate Microsoft Sentinel to ingest alerts from Defender XDR.
AnswerD

This solution combines real-time risk assessment from Microsoft Entra ID Protection with adaptive Conditional Access policies, allowing sign-in risk to trigger MFA, block, or session restrictions dynamically. Session controls from Microsoft Defender for Cloud Apps enable granular cloud app session monitoring and policy enforcement, such as blocking download of sensitive files based on user risk. Blocking legacy authentication explicitly via a Conditional Access policy on client apps 'Exchange ActiveSync' and 'Other clients' is the documented method to prevent credential replay attacks. Finally, integrating Microsoft Sentinel with Defender XDR centralizes alerts from across the identity, endpoint, and cloud app domains, enabling advanced hunting and a unified incident response workflow.

Why this answer

It directly implements the 'verify explicitly' principle by using Microsoft Entra ID Protection to feed real-time risk signals into Conditional Access policies, which then enforce session controls via Microsoft Defender for Cloud Apps. It blocks legacy authentication through a targeted Conditional Access policy (not just disabling protocols in Exchange Online or at the firewall), and integrates Microsoft Sentinel to ingest alerts from Defender XDR for centralized threat intelligence. This combination ensures all access to Microsoft 365 and Azure applications is conditionally enforced based on dynamic risk, while also addressing the requirement to block legacy protocols that lack modern authentication support.

Exam trap

The trap here is that candidates often think blocking legacy authentication must be done at the protocol level (e.g., disabling in Exchange Online or firewall) rather than using a Conditional Access policy, which is the recommended and more comprehensive method in a Zero Trust architecture.

How to eliminate wrong answers

Option A is wrong because it relies on disabling legacy protocols in Exchange Online (which is incomplete—does not block protocols like POP3/IMAP/SMTP across all services) and uses Azure Sentinel without Defender XDR, violating the requirement to integrate both. Option B is wrong because it blocks legacy authentication at the firewall level (which is not granular enough and does not address protocol-level blocking within Microsoft 365), and Azure AD B2B is only for external users, not the core Zero Trust strategy for internal access. Option C is wrong because it relies on Azure ATP (now Microsoft Defender for Identity) for risk signals, but the correct modern approach is Microsoft Entra ID Protection, which provides real-time risk detection and feeds directly into Conditional Access; also, Intune for compliant devices is not the primary mechanism for risk-based conditional access.

83
MCQmedium

Your organization uses Microsoft Defender for Office 365 to protect against phishing attacks. The security team wants to implement a custom advanced phishing threshold policy that blocks suspicious emails more aggressively. Which policy type should they modify?

A.ATP policy
B.Safe Attachments policy
C.Safe Links policy
D.Anti-phishing policy
AnswerD

Anti-phishing policies in Microsoft Defender for Office 365 contain the 'Phishing email threshold' setting, which adjusts the sensitivity of the machine-learning models that detect phishing attempts. These policies also include features like impersonation protection, mailbox intelligence, and spoof intelligence, all relevant to phishing defense. This is the correct policy selection because it directly modifies the advanced threshold that controls how many phishing candidates are flagged.

Why this answer

The Anti-phishing policy in Microsoft Defender for Office 365 includes the Advanced Phishing Threshold (APT) settings that allow administrators to control the aggressiveness of phishing detection. By modifying the anti-phishing policy, you can set the phishing threshold to 'Aggressive' or 'Most Aggressive,' which applies more stringent machine learning models to block suspicious emails earlier. This is the correct policy type because it directly governs the phishing threshold level, not attachment or link scanning.

Exam trap

The trap here is that candidates confuse the outdated 'ATP policy' term with the modern anti-phishing policy, or they mistakenly think Safe Attachments or Safe Links control phishing thresholds, when in fact only the anti-phishing policy contains the Advanced Phishing Threshold settings.

How to eliminate wrong answers

Option A is wrong because 'ATP policy' is an outdated term; Microsoft Defender for Office 365 no longer uses 'ATP' as a policy name—it has been rebranded, and the correct policy for phishing thresholds is the anti-phishing policy. Option B is wrong because Safe Attachments policy controls the scanning of email attachments for malware, not the phishing threshold or aggressiveness of phishing detection. Option C is wrong because Safe Links policy protects users from malicious URLs in emails and Office documents, but it does not control the phishing threshold level or the aggressiveness of email filtering.

84
Multi-Selectmedium

Which TWO of the following are key components of a Zero Trust architecture according to Microsoft? (Choose two.)

Select 2 answers
A.Trust but verify
B.Implicit trust for internal traffic
C.Use least privilege access
D.Verify explicitly
E.Rely on a strong perimeter
AnswersC, D

Least privilege access is a cornerstone of Zero Trust because it directly reduces the potential blast radius of any compromised identity or device. Access is granted strictly on a need-to-know basis, often enforced with just-in-time (JIT) elevation and just-enough-access (JEA) scoping. This applies not only to human users but also to workloads, services, and APIs via fine-grained conditional access policies and microsegmentation. Implementing least privilege ensures that a single credential theft does not automatically grant access to downstream systems.

Why this answer

Option D, 'Verify explicitly,' is correct because Microsoft's Zero Trust model requires that every access request be authenticated and authorized based on all available data points, including user identity, device health, location, and data sensitivity, rather than assuming trust based on network location. Option C, 'Use least privilege access,' is correct because Zero Trust limits user access with just-in-time and just-enough-access (JIT/JEA) principles, risk-based adaptive policies, and data protection to minimize lateral movement and exposure. The three guiding principles Microsoft defines are verify explicitly, use least privilege access, and assume breach, so these two options align directly with that framework.

Option A, 'Trust but verify,' is not a Zero Trust principle; it reflects a traditional perimeter mindset where trust is initially granted. Option B, 'Implicit trust for internal traffic,' contradicts Zero Trust, which removes implicit trust based on network location. Option E, 'Rely on a strong perimeter,' is also contrary to Zero Trust, which assumes the perimeter can be breached and therefore does not rely on it for security.

Exam trap

The trap here is that candidates often confuse 'trust but verify' (a legacy model) with Zero Trust's 'never trust, always verify' principle, leading them to incorrectly select Option A as a key component.

85
MCQhard

Your organization uses Microsoft Defender for Cloud to assess the security posture of Azure resources. The compliance team wants to ensure that all storage accounts have secure transfer required enabled. Which action should you take in Defender for Cloud?

A.Configure the regulatory compliance dashboard
B.Review the secure score
C.Implement the 'Secure transfer to storage accounts should be enabled' recommendation
D.Enable the 'Cloud Security Posture Management' plan
AnswerC

In Microsoft Defender for Cloud, each security recommendation—including 'Secure transfer to storage accounts should be enabled'—is backed by an Azure Policy definition. Implementing this recommendation executes a remediation task that applies the policy effect (typically 'Audit' or 'DeployIfNotExists') to the identified storage accounts, setting the 'supportsHttpsTrafficOnly' property to true. This is the only option that directly enforces the required configuration, as it modifies the resource to meet the policy's compliance criteria, unlike assessment-only features.

Why this answer

The correct action is to implement the 'Secure transfer to storage accounts should be enabled' recommendation because Microsoft Defender for Cloud provides built-in security recommendations that map to specific controls. This recommendation directly checks whether the 'Secure transfer required' property is enabled on each storage account, and if not, it provides remediation steps to enforce HTTPS-only traffic, which aligns with the compliance team's requirement.

Exam trap

The trap here is that candidates confuse viewing compliance or score metrics (options A and B) with taking direct action to enforce a specific security control, or they mistakenly think enabling a higher-level plan (option D) automatically applies all underlying recommendations.

How to eliminate wrong answers

Option A is wrong because the regulatory compliance dashboard is used to view compliance posture against standards (e.g., PCI DSS, ISO 27001) and track progress, but it does not directly enforce or implement a specific security setting like secure transfer required. Option B is wrong because the secure score is a numerical summary of your overall security posture based on implemented recommendations; reviewing it shows the score impact but does not itself enable the secure transfer setting. Option D is wrong because enabling the 'Cloud Security Posture Management' plan is a prerequisite for receiving certain recommendations and advanced features, but it does not directly implement the 'Secure transfer to storage accounts should be enabled' recommendation; it only enables the capability to assess and recommend.

86
Multi-Selectmedium

Which TWO Microsoft security solutions can help enforce Zero Trust principles by verifying identity and device health before granting access to resources?

Select 2 answers
A.Microsoft Intune
B.Microsoft Purview
C.Microsoft Entra ID Conditional Access
D.Microsoft Defender for Cloud Apps
E.Microsoft Sentinel
AnswersA, C

Microsoft Intune is a unified endpoint management solution that enforces zero trust by ensuring devices are compliant and healthy before they access resources. It does this through device compliance policies (e.g., required OS versions, disk encryption, and jailbreak detection) that integrate with Entra ID Conditional Access, blocking or limiting access for non-compliant devices.

Why this answer

Microsoft Entra ID Conditional Access (C) is correct because it is the policy engine that evaluates signals such as user identity, group membership, and device compliance state to grant, block, or require MFA before access to resources, directly enforcing the Zero Trust 'verify explicitly' principle. Microsoft Intune (A) is correct because it manages device enrollment, configuration, and compliance policies, producing the device health and compliance signals that Conditional Access consumes to ensure only healthy, trusted devices get access. Together they implement the identity-plus-device verification required by Zero Trust.

Microsoft Purview (B) is a data governance, compliance, and information-protection suite, not an access-decision enforcement point. Microsoft Defender for Cloud Apps (D) is a CASB for discovering and controlling cloud app usage, and Microsoft Sentinel (E) is a SIEM/SOAR platform for threat detection and response; neither verifies identity and device health at the point of granting resource access.

Exam trap

The trap here is that candidates often confuse Microsoft Purview (data governance) or Microsoft Defender for Cloud Apps (CASB) with pre-access enforcement, but neither performs the identity and device health verification that is the core of Zero Trust's 'never trust, always verify' principle at the authentication stage.

87
Multi-Selectmedium

Which TWO should you implement to protect privileged accounts in Microsoft Entra ID?

Select 2 answers
A.Microsoft Purview Data Loss Prevention
B.Conditional Access policies requiring MFA for privileged roles
C.Microsoft Defender for Cloud security score
D.Microsoft Defender Vulnerability Management
E.Microsoft Entra Privileged Identity Management (PIM)
AnswersB, E

Conditional Access policies requiring MFA for privileged roles are a cornerstone identity protection control. These policies enforce an additional authentication factor at sign-in for users assigned to highly privileged directory roles, such as Global Administrator or Application Administrator, irrespective of location or device state. This directly thwarts stolen-password and password-spraying attacks, because an attacker lacking the second factor cannot gain access. For robust defense, such policies should be paired with device compliance checks and session controls to further harden privileged access.

Why this answer

Option B is correct because Conditional Access policies that require multifactor authentication for privileged directory roles (such as Global Administrator) enforce strong authentication at sign-in, directly reducing the risk of credential compromise for high-impact accounts. Option E is correct because Microsoft Entra Privileged Identity Management (PIM) provides just-in-time role activation, approval workflows, time-bound assignments, and access reviews, which minimize standing privileged access and its exposure window. Together, B and E address both authentication strength and the elimination of permanent admin rights, which are core controls for protecting privileged accounts in Entra ID.

Option A (Microsoft Purview Data Loss Prevention) is incorrect because it protects sensitive data in motion/at rest rather than securing privileged identities. Option C (Microsoft Defender for Cloud security score) is incorrect because it is a posture assessment metric, not an access control for privileged accounts. Option D (Microsoft Defender Vulnerability Management) is incorrect because it identifies and remediates software vulnerabilities, not privileged identity protection.

Exam trap

The trap here is that candidates often confuse a measurement or monitoring tool (like security score or vulnerability management) with an actual security control that directly protects privileged accounts, leading them to select options that are only indirectly related.

88
MCQmedium

Refer to the exhibit. You are reviewing a conditional access policy JSON in Microsoft Entra ID. The policy is enabled but users with the Global Administrator role are not being prompted for MFA. What is the most likely reason?

A.The policy does not include any users except by role.
B.The policy does not include any applications.
C.The grant control requires a compliant device instead of MFA.
D.The policy state is disabled.
AnswerA

The conditional access policy defines user targeting exclusively through the includeRoles array and omits the includeUsers array entirely. This means the policy only applies to sign-ins from users assigned to the specified directory roles, leaving every non-role user outside the policy scope. The absence of an includeUsers entry, such as the shortcut value 'All', prevents the policy from being universally enforced and is the root cause of the misconfiguration.

Why this answer

The Conditional Access policy JSON shows that the 'users' object does not include an 'includeUsers' property for all users or specific groups; instead, users are only included by directory role (e.g., through 'includeRoles'). If the 'includeRoles' array is either empty or does not contain the 'Global Administrator' role, then Global Administrators are not targeted by the policy. Therefore, they are not prompted for MFA despite the policy being enabled.

This is the most likely reason because the other options are incorrect: the policy may include applications (option B), the grant control could be set to MFA (not requiring compliant device) (option C), and the policy is enabled (option D).

Exam trap

The trap here is that candidates assume 'All users' includes all users regardless of role, but they overlook that the exclusion of specific roles or users can completely bypass the policy, and the exam tests whether you understand that exclusion rules override inclusion rules in Conditional Access policies.

How to eliminate wrong answers

Option B is wrong because the policy does not need to include any specific applications; if no applications are selected, the policy applies to all applications by default, which would still trigger MFA for included users. Option C is wrong because the grant control in the policy explicitly requires MFA ('mfa' in the grantControls), not a compliant device, so that does not explain why Global Administrators are not prompted. Option D is wrong because the policy state is set to 'enabled' (as shown in the JSON), so it is active and should enforce MFA for users who are not excluded.

89
MCQhard

You are designing a Zero Trust strategy for Fabrikam Inc., which uses Microsoft Entra ID, Microsoft Intune, and Microsoft Defender for Endpoint. The security team wants to enforce the principle of least privilege for administrative access to Azure resources. They require that administrators use dedicated, cloud-only accounts with no permanent role assignments. You need to recommend a solution that provides just-in-time (JIT) privileged access with approval workflows and full auditing. What should you include in your design?

A.Microsoft Defender for Cloud just-in-time (JIT) VM access
B.Azure role-based access control (RBAC) with custom roles
C.Microsoft Entra Privileged Identity Management (PIM)
D.Microsoft Entra ID Conditional Access with device compliance
AnswerC

Microsoft Entra Privileged Identity Management (PIM) provides just-in-time privileged access to Azure AD and Azure resources, requiring activation with approval and MFA. It supports eligible assignments, time-bound activations, and comprehensive audit logs, directly fulfilling the requirement for JIT access with approval workflows and auditing.

Why this answer

Microsoft Entra Privileged Identity Management (PIM) is the designated solution for just-in-time privileged access in Microsoft Entra ID and Azure. It enables eligible role assignments, requires approval and MFA for activation, and logs all activations for auditing. This aligns with Zero Trust principles of least privilege and verifies explicitly.

Exam trap

The trap here is assuming that Azure RBAC alone provides just-in-time access, when in fact RBAC assignments are persistent unless combined with PIM for time-bound activation.

90
MCQmedium

Your organization is implementing a secure DevOps pipeline for a critical application. You need to design a solution that scans container images for vulnerabilities before they are deployed to production. Which Azure service should you integrate into the pipeline?

A.Azure Key Vault
B.Azure Policy
C.Microsoft Defender for Cloud
D.Azure Security Center
AnswerC

Microsoft Defender for Cloud is the correct choice because it includes built-in vulnerability scanning for container images in Azure Container Registry and other supported registries. It continuously scans images when they are pushed, detects known vulnerabilities using integrated CVE databases, and provides actionable remediation recommendations. Integrating this into a secure DevOps pipeline allows automated gating to block vulnerable images from reaching production.

Why this answer

Microsoft Defender for Cloud (formerly Azure Security Center) provides integrated vulnerability assessment for container images stored in Azure Container Registry (ACR). When integrated into a DevOps pipeline, Defender for Cloud can scan images on push or on demand, using the Qualys scanner to detect CVEs and generate detailed security reports. This allows the pipeline to block or flag vulnerable images before they reach production, directly addressing the requirement for pre-deployment vulnerability scanning.

Exam trap

The trap here is that candidates may confuse the old name 'Azure Security Center' with the current service 'Microsoft Defender for Cloud', or assume that Azure Policy can perform vulnerability scanning when it only enforces configuration compliance, not image-level security analysis.

How to eliminate wrong answers

Option A is wrong because Azure Key Vault is a secrets management service for storing keys, certificates, and passwords, not a container image vulnerability scanner. Option B is wrong because Azure Policy enforces compliance rules on Azure resources (e.g., requiring ACR to use private endpoints) but does not perform runtime or image-level vulnerability scanning. Option D is wrong because Azure Security Center was the previous name for what is now Microsoft Defender for Cloud; the current service name is Defender for Cloud, and the exam expects the updated terminology.

91
MCQmedium

Your organization uses Microsoft Entra ID and plans to implement a Zero Trust security model. You need to ensure that all access requests to corporate applications are continuously evaluated based on user risk, device compliance, and location. Which Microsoft Entra ID feature should you configure?

A.Identity Governance
B.Privileged Identity Management (PIM)
C.Identity Protection
D.Conditional Access
AnswerD

Conditional Access evaluates each access request against signals — user risk, device compliance and location — and enforces grant or session controls accordingly, delivering the continuous, context-aware evaluation Zero Trust demands rather than relying on a one-off authentication event.

Why this answer

Conditional Access is the correct feature because it enables real-time policy evaluation of access requests based on signals such as user risk (from Identity Protection), device compliance (via Microsoft Intune), and location (IP address ranges or named locations). This aligns directly with the Zero Trust principle of 'never trust, always verify' by continuously re-evaluating each access attempt rather than relying on static permissions.

Exam trap

The trap here is that candidates often confuse Identity Protection (which only detects risk) with Conditional Access (which enforces policies based on that risk), leading them to select Option C instead of D.

How to eliminate wrong answers

Option A is wrong because Identity Governance focuses on managing user lifecycle, access reviews, and entitlement management, not on real-time risk-based access evaluation. Option B is wrong because Privileged Identity Management (PIM) provides just-in-time privileged role activation and approval workflows, but it does not evaluate device compliance or location for general application access. Option C is wrong because Identity Protection detects and reports user and sign-in risks (e.g., leaked credentials, anonymous IP addresses) but does not enforce access decisions itself; it requires integration with Conditional Access to block or require MFA based on those risks.

92
Multi-Selectmedium

Your organization is implementing Microsoft Intune for mobile device management. You need to design a solution that ensures corporate data on mobile devices is protected if the device is lost or stolen. Which TWO actions should you configure?

Select 2 answers
A.Enforce a minimum PIN length on devices
B.Configure a compliance policy that requires device encryption
C.Deploy a selective wipe policy that removes corporate data
D.Require app protection policies (MAM) for all apps
E.Enable jailbreak detection in a device compliance policy
AnswersB, C

A compliance policy that mandates device encryption ensures that the storage medium (e.g., internal flash) is encrypted, typically using the hardware security module and a recovery key managed by the device, so that if the device is lost, the data is unreadable without the decryption key. This is a protective measure at rest; in addition, the compliance policy can trigger conditional access to block non-compliant devices, but the encryption itself is the core safeguard that prevents data exposure from physical access.

Why this answer

A compliance policy requiring device encryption ensures that if a device is lost or stolen, the data stored on it is unreadable without the decryption key. Intune compliance policies evaluate encryption status (e.g., BitLocker on Windows, FileVault on macOS, or device encryption on iOS/Android) and mark noncompliant devices for conditional access blocking, preventing unauthorized access to corporate data.

Exam trap

The trap here is that candidates often confuse device-level encryption (compliance policy) with app-level protection (MAM) or access controls (PIN, jailbreak detection), failing to recognize that only encryption and selective wipe directly address data protection on a lost or stolen device.

93
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that devices that are not compliant with your organization's security policies are blocked from accessing corporate resources. Which Intune feature should you configure?

A.App protection policies
B.Device configuration profiles
C.Compliance policies
D.Enrollment restrictions
AnswerC

Compliance policies in Intune define the specific conditions a device must meet to be considered compliant, such as required OS versions, password requirements, encryption status, and threats detected by Mobile Threat Defense. Each device periodically uploads its health and configuration to the Intune service, which computes a compliant/non-compliant state. This state can then be consumed by Azure AD Conditional Access to allow or block access to emails, apps, and data based on real-time compliance. When a policy is combined with a Conditional Access policy requiring device compliance, non-compliant devices are blocked from accessing protected resources—making this the correct answer.

Why this answer

Compliance policies in Microsoft Intune define the rules and settings that devices must meet to be considered compliant (e.g., requiring a minimum OS version, encryption, or a healthy device health attestation). When a device is marked as non-compliant, Intune can automatically block access to corporate resources such as Exchange Online, SharePoint, or VPN by integrating with Conditional Access in Microsoft Entra ID. This is the correct feature because it directly evaluates device compliance and enforces access control.

Exam trap

The trap here is that candidates confuse device configuration profiles (which apply settings) with compliance policies (which evaluate settings and enforce access), leading them to select Option B when the question specifically asks about blocking access based on non-compliance.

How to eliminate wrong answers

Option A is wrong because App protection policies (MAM) manage how data is accessed and shared within apps on devices that may not be enrolled in Intune, but they do not block device-level access to corporate resources based on device compliance. Option B is wrong because Device configuration profiles push settings (e.g., Wi-Fi, VPN, email) to devices but do not evaluate or enforce compliance; they are separate from the compliance evaluation and conditional access workflow. Option D is wrong because Enrollment restrictions control which devices can enroll in Intune (e.g., by platform or OS version), but they do not block access for devices that are already enrolled and become non-compliant after enrollment.

94
MCQhard

You are a security architect for a large enterprise that is migrating to Microsoft 365. The organization has 50,000 users across multiple regions. They have recently experienced a ransomware attack that encrypted files on SharePoint Online and OneDrive for Business. The security team wants to implement a comprehensive protection strategy. Requirements: 1. Automatically detect and block ransomware-like behavior in real-time. 2. Provide users with self-service recovery of files encrypted by ransomware. 3. Ensure that all files in SharePoint and OneDrive are scanned for malware upon upload. 4. Minimize administrative overhead. Which combination of Microsoft 365 security features should you recommend?

A.Use Microsoft Entra ID Protection to detect compromised accounts and automatically block access.
B.Enable Microsoft Endpoint DLP and configure file policies to block encrypted files.
C.Enable Microsoft Defender for Office 365 to scan files on upload and use version history and recycle bin for recovery.
D.Configure Microsoft Purview auto-labeling to apply a 'Ransomware' label and then block all labeled files.
AnswerC

Defender for Office 365 runs anti-malware and detonation-in-sandbox scanning on files uploaded to SharePoint, OneDrive, and Microsoft Teams, immediately removing known malicious files. It also continuously monitors for ransomware activity with heuristic and machine-learning rules, then alerts you to impacted files. Version history and the recycle bin act as a self-service recovery mechanism, letting you restore a previous unencrypted version of a file with a few clicks, even after mass encryption. This combines prevention, detection, and remediation—exactly what the question asks for.

Why this answer

Microsoft Defender for Office 365 provides real-time scanning of files uploaded to SharePoint and OneDrive, detecting and blocking known malware. Combined with version history and the recycle bin, users can self-recover files encrypted by ransomware without administrative intervention, satisfying all requirements with minimal overhead.

Exam trap

The trap here is that candidates may confuse Microsoft Defender for Office 365 with Microsoft Defender for Cloud Apps or Microsoft Purview, but only Defender for Office 365 provides both upload scanning and native version history/recycle bin recovery for SharePoint and OneDrive.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Protection detects compromised accounts and can block access, but it does not scan files for malware upon upload, nor does it provide self-service recovery of encrypted files. Option B is wrong because Microsoft Endpoint DLP focuses on preventing data loss via policies (e.g., blocking sensitive data sharing), not on detecting ransomware behavior or scanning files for malware in real-time. Option D is wrong because Microsoft Purview auto-labeling applies labels based on content, but it cannot block files in real-time based on ransomware behavior, and it does not provide file scanning or self-service recovery.

95
MCQmedium

You are designing a Zero Trust architecture for a company that uses Microsoft Entra ID and Microsoft Intune. The security team wants to enforce device compliance before granting access to cloud apps. Which policy should you implement?

A.Microsoft Entra Identity Protection user risk policy
B.Microsoft Defender for Cloud Apps session policy
C.Microsoft Entra Conditional Access policy requiring compliant device
D.Azure AD Identity Protection sign-in risk policy
AnswerC

An Entra Conditional Access policy requiring a compliant device is the correct mechanism because it directly checks the device's compliance state as reported by Microsoft Intune at sign-in time. The policy evaluates device health attributes like encryption, jailbreak status, and threat detection, and can block access or grant access only when compliant. This is the standard zero trust control that enforces device compliance before granting access to applications or resources.

Why this answer

Microsoft Entra Conditional Access policies can require that devices are marked as compliant by Microsoft Intune before granting access to cloud apps. This directly enforces device compliance as a condition for access, which is a core Zero Trust principle of verifying every access request based on device health.

Exam trap

The trap here is that candidates confuse risk-based policies (Identity Protection) with device compliance policies, assuming any policy that checks 'risk' or 'session' can enforce device health, but only Conditional Access with the compliant device grant control directly ties Intune compliance to access decisions.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Identity Protection user risk policy evaluates the likelihood that a user's identity has been compromised, not the compliance state of the device. Option B is wrong because Microsoft Defender for Cloud Apps session policy controls app behavior in real-time (e.g., blocking downloads) but does not enforce device compliance before access is granted. Option D is wrong because Azure AD Identity Protection sign-in risk policy assesses the risk of the authentication attempt (e.g., from an anonymous IP), not the device's compliance with security policies.

96
Multi-Selecthard

Which THREE components are essential for implementing a successful SIEM strategy using Microsoft Sentinel?

Select 3 answers
A.Automation rules
B.Workbooks
C.Analytics rules
D.Watchlists
E.Data connectors
AnswersA, C, E

Automation rules are central to Sentinel's SOAR capabilities because they let you define automated incident orchestration—such as assigning ownership, changing status, or running a playbook—when an alert is triggered or an incident is created. They close the gap between detection and response by turning analytics alerts into coordinated actions across Office 365, Microsoft Entra ID, and third-party systems. Without automation rules, alerts would require manual triage and response, reducing Sentinel to a passive monitoring tool rather than an active, automated security operations platform.

Why this answer

Data connectors (E) are essential because Microsoft Sentinel must first ingest telemetry from sources such as Microsoft 365, Azure, AWS, and third-party systems via connectors like the Azure Activity or Syslog connector before any detection or response can occur. Analytics rules (C) are essential because they correlate the ingested events and generate alerts/incidents based on scheduled, NRT, or Microsoft security rules, forming the core detection engine of the SIEM. Automation rules (A) are essential because they provide the orchestration and response layer, allowing Sentinel to automatically triage, assign, tag, or trigger playbooks on incidents to reduce response time.

Workbooks (B) are valuable for visualization and reporting but are not required for the core detect-and-respond SIEM pipeline, and watchlists (D) are an optional enrichment feature for importing reference data such as IPs or VIP users, not a foundational component of a Sentinel SIEM strategy.

Exam trap

The trap here is that candidates often confuse 'nice-to-have' features like Workbooks and Watchlists with 'essential' components, but Microsoft defines the three pillars of a successful SIEM strategy as data ingestion (connectors), detection (analytics rules), and automated response (automation rules).

97
MCQhard

A multinational corporation is implementing a privileged access strategy. They need to ensure that all users with permanent administrative roles sign in using phishing-resistant authentication methods. Which Microsoft Entra ID feature should they enforce?

A.Privileged Identity Management (PIM) with access reviews
B.Multifactor authentication (MFA) with Conditional Access
C.Authentication Strengths in Conditional Access
D.Conditional Access policies requiring MFA for all admins
AnswerC

Authentication Strengths is a Conditional Access grant control that lets an administrator define a policy requiring a specific set of acceptable authentication methods, such as FIDO2 security keys or certificate-based authentication. It evaluates the method actually used at sign-in and blocks sessions that do not meet the configured strength, making it the correct mechanism for enforcing phishing-resistant MFA on privileged accounts.

Why this answer

Authentication Strengths in Conditional Access allows organizations to enforce specific authentication methods, such as FIDO2 security keys or certificate-based authentication, which are phishing-resistant. This directly meets the requirement to ensure users with permanent administrative roles use phishing-resistant methods, unlike general MFA policies that may allow weaker methods like SMS or OTP.

Exam trap

The trap here is that candidates confuse general MFA enforcement with the ability to enforce specific authentication method types, assuming any MFA policy is sufficient for phishing resistance, whereas Authentication Strengths provides granular control over which methods are allowed.

How to eliminate wrong answers

Option A is wrong because Privileged Identity Management (PIM) with access reviews manages just-in-time access and recertification, not the enforcement of specific authentication methods. Option B is wrong because standard MFA with Conditional Access can enforce MFA but does not restrict to phishing-resistant methods; it may allow SMS, voice, or OATH tokens that are vulnerable to phishing. Option D is wrong because a Conditional Access policy requiring MFA for all admins is too broad and does not specify phishing-resistant methods; it could still permit weaker MFA factors.

98
MCQhard

An organization uses Microsoft Purview Information Protection. They want to automatically apply a sensitivity label to documents containing credit card numbers. Which policy should they configure?

A.Retention policy
B.Sensitivity label policy
C.Auto-labeling policy
D.Data loss prevention policy
AnswerC

Auto-labeling policies in Microsoft Purview scan items in SharePoint, OneDrive, and Exchange, and when they detect defined sensitive information types—such as credit card numbers—they automatically apply the specified sensitivity label to that content. These policies can first run in simulation mode to assess impact and then be enforced, ensuring consistent, touchless labeling across the organization. This is the correct answer because the question describes automatically labeling documents containing credit card data.

Why this answer

Auto-labeling policies in Microsoft Purview Information Protection automatically apply sensitivity labels to documents and emails that match specified conditions, such as the presence of credit card numbers. This policy uses sensitive information types (e.g., Credit Card Number) to scan content and apply the label without user intervention, meeting the requirement for automatic labeling.

Exam trap

The trap here is confusing sensitivity label policies (which require user action or default labeling) with auto-labeling policies (which automatically scan and apply labels based on sensitive data patterns), leading candidates to choose option B incorrectly.

How to eliminate wrong answers

Option A is wrong because retention policies manage how long content is kept or deleted, not the application of sensitivity labels. Option B is wrong because sensitivity label policies publish labels for manual or default application by users, but they do not automatically scan for sensitive data like credit card numbers. Option D is wrong because data loss prevention (DLP) policies detect and block sharing of sensitive data, but they do not apply sensitivity labels to content.

99
MCQhard

A company uses Microsoft Sentinel and wants to prioritize incidents using user risk scores from Microsoft Entra ID Protection. Which configuration should they use to automatically assign a Sentinel severity based on the user's risk level?

A.Create a custom analytics rule that uses the RiskLevel field to set severity
B.Configure an automation rule to set severity when risk is high
C.Use a watchlist to map risk levels to severity
D.Create a playbook that assigns severity based on risk
AnswerA

Creating a custom analytics rule is the technically correct approach because analytics rules in Microsoft Sentinel evaluate telemetry at ingestion time and can dynamically assign incident severity by referencing data fields such as the RiskLevel attribute from Microsoft Entra ID Protection. By setting the Alert Severity to a value derived from RiskLevel (e.g., High if risk is medium, Higher if risk is high), the incident is created with the appropriate priority immediately, enabling efficient triage without further post-processing. This native, rule-based mapping is the only option among the listed alternatives that directly controls initial incident severity as the incident is generated from raw log data.

Why this answer

A is correct because Microsoft Sentinel's custom analytics rules can directly reference the `RiskLevel` field from Microsoft Entra ID Protection user risk data ingested via the UEBA connector. By writing a KQL query that checks the user's risk level (e.g., `RiskLevel == 'high'`) and mapping it to a Sentinel severity (e.g., High, Medium, Low) within the rule's incident creation settings, you automate severity assignment without external dependencies. This native integration ensures real-time synchronization of risk levels to incident priority.

Exam trap

The trap here is that candidates often assume automation rules or playbooks are required for any custom severity assignment, overlooking that custom analytics rules can directly map query results to severity fields without additional automation layers.

How to eliminate wrong answers

Option B is wrong because automation rules can set severity based on conditions like incident properties or entities, but they cannot directly read the `RiskLevel` field from Entra ID Protection user risk data; they operate on incident metadata after creation, not on raw risk signals. Option C is wrong because watchlists are static reference tables used for enrichment or correlation, not for dynamic, real-time mapping of continuously changing user risk levels to severity. Option D is wrong because playbooks (Azure Logic Apps) can assign severity, but they introduce latency and complexity compared to a native analytics rule, and they require additional permissions and orchestration, making them less efficient for this straightforward mapping.

100
MCQeasy

A company wants to use Microsoft Defender XDR to correlate alerts across endpoints, email, and identities. Which component enables this correlation?

A.Microsoft 365 Defender
B.Microsoft Defender XDR
C.Microsoft Sentinel
D.Microsoft Defender for Cloud
AnswerB

Microsoft Defender XDR is the correct answer because it is the integrated, cloud-native extended detection and response (XDR) platform that natively correlates alerts from Microsoft Defender for Endpoint, Office 365, Identity, and Cloud Apps. By combining signals across domains into a single incident queue, it performs the automatic cross-product correlation the company requires. Its machine-learning-driven analytics unify threat hunting and response without needing external SIEM logic.

Why this answer

Microsoft Defender XDR (the new name for Microsoft 365 Defender) is the unified pre- and post-breach enterprise defense suite that natively correlates signals from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps. Its correlation engine uses machine learning and the Microsoft Intelligent Security Graph to fuse alerts across these domains into a single incident, enabling security teams to see the full attack chain from email to endpoint to identity.

Exam trap

The trap here is that candidates confuse the old branding (Microsoft 365 Defender) with the new branding (Microsoft Defender XDR) and pick the outdated name, or they mistake Microsoft Sentinel's broader SIEM capabilities for the native cross-domain correlation engine that Defender XDR provides.

How to eliminate wrong answers

Option A is wrong because 'Microsoft 365 Defender' is the previous name for the same product now called Microsoft Defender XDR; the question explicitly uses the current name, so selecting the old name would be technically inaccurate. Option C is wrong because Microsoft Sentinel is a cloud-native SIEM and SOAR solution that ingests logs from many sources, including Defender XDR, but it does not perform the native, real-time cross-domain alert correlation that Defender XDR's built-in engine does; Sentinel correlates at a higher level using analytics rules and is not the component that directly correlates alerts across endpoints, email, and identities. Option D is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) focused on securing Azure, AWS, and GCP resources, not on correlating alerts across endpoints, email, and identities.

101
MCQeasy

Your organization plans to use Microsoft Defender for Cloud to secure Azure resources. The security team wants to continuously assess compliance against the CIS Azure Foundations Benchmark. What should you do?

A.Create a custom Azure Blueprint for CIS
B.Deploy Azure Security Center (legacy)
C.Enable the CIS Azure Foundations Benchmark in Defender for Cloud regulatory compliance dashboard
D.Assign Azure Policy for all CIS controls manually
AnswerC

Enabling the CIS Azure Foundations Benchmark in Defender for Cloud's regulatory compliance dashboard is the correct action because it automatically attaches a curated Azure Policy initiative containing the required policies and controls. The dashboard continuously assesses your Azure environment against CIS controls, provides a compliance score, and surfaces remediation recommendations. This directly supports the benchmark with minimal manual effort and ongoing visibility, fulfilling your organization's compliance monitoring requirement.

Why this answer

Microsoft Defender for Cloud's regulatory compliance dashboard includes built-in support for the CIS Azure Foundations Benchmark. By enabling this standard in the dashboard, Defender for Cloud continuously assesses your Azure resources against all CIS controls, providing automated compliance scores and remediation recommendations without requiring custom definitions or manual policy assignments.

Exam trap

The trap here is that candidates may think they need to create custom Azure Blueprints or manually assign Azure Policies for CIS compliance, overlooking that Defender for Cloud's regulatory compliance dashboard already includes a pre-configured, continuously updated CIS benchmark initiative that automates the entire assessment process.

How to eliminate wrong answers

Option A is wrong because Azure Blueprints are used to define a repeatable set of Azure resources and policies for deployment, not to continuously assess compliance against a specific benchmark like CIS; the CIS benchmark is already available as a built-in standard in Defender for Cloud. Option B is wrong because Azure Security Center (legacy) has been superseded by Microsoft Defender for Cloud, and the legacy version does not include the regulatory compliance dashboard with CIS Azure Foundations Benchmark support; you must use the current Defender for Cloud. Option D is wrong because manually assigning Azure Policy for all CIS controls is inefficient, error-prone, and unnecessary since Defender for Cloud provides a pre-built, automatically updated CIS benchmark initiative that maps policies to controls and continuously evaluates compliance.

102
MCQhard

A company uses Microsoft Entra ID with P2 licenses. They want to implement a Zero Trust approach that requires step-up authentication for accessing high-value data in SharePoint. The solution must use risk-based policies and minimize user friction. Which combination should you recommend?

A.Microsoft Entra Conditional Access with trusted locations policy
B.Microsoft Entra Conditional Access with sign-in risk policy and authentication context for sensitive data
C.Azure AD Conditional Access with MFA for all SharePoint access
D.Microsoft Entra Identity Protection user risk policy with MFA
AnswerB

This is correct because the Conditional Access policy uses Microsoft Entra Identity Protection's real-time sign-in risk score to trigger step-up (for example MFA or restricted session) only when anomalous behavior is detected. Adding an authentication context makes the requirement granular: the risk-based control can be attached to SharePoint sites or files with a specific sensitivity label rather than to every resource. This combines risk assessment with data sensitivity, which is exactly the requirement. It is also the only option that pairs a per-sign-in risk signal with a context-aware session control.

Why this answer

It combines Conditional Access with a sign-in risk policy (from Identity Protection) and an authentication context that is applied to sensitive SharePoint data. This enforces step-up authentication only when risk is detected and the user accesses high-value data, minimizing friction for low-risk sessions while meeting Zero Trust requirements.

Exam trap

The trap here is that candidates often confuse user risk policies (which are based on historical user behavior) with sign-in risk policies (which evaluate the current session in real time), and they overlook the role of authentication context in scoping enforcement to specific data rather than all SharePoint access.

How to eliminate wrong answers

Option A is wrong because a trusted locations policy only checks the network location (e.g., corporate IP range) and does not evaluate user or sign-in risk, nor does it enforce step-up authentication based on data sensitivity. Option C is wrong because requiring MFA for all SharePoint access is not risk-based; it applies friction to every session regardless of risk level, violating the 'minimize user friction' requirement. Option D is wrong because a user risk policy with MFA triggers based on user-level risk (e.g., leaked credentials) but does not use authentication context to scope enforcement to specific high-value data in SharePoint, and it does not leverage sign-in risk for real-time step-up.

103
MCQmedium

A company is using Microsoft Intune to manage devices. They need to ensure that only devices with a specific operating system version can access corporate resources. Which Intune policy should they use?

A.App protection policy
B.Enrollment restriction
C.Compliance policy
D.Device configuration policy
AnswerC

A compliance policy evaluates device attributes against defined rules, including a minimum OS version, and marks the device compliant or non-compliant. Conditional Access then blocks resource access for non-compliant devices, directly satisfying the requirement that only devices running the specified OS version reach corporate resources.

Why this answer

Compliance policies in Microsoft Intune define the rules that devices must meet to be considered compliant, such as requiring a specific operating system version. When a device is marked non-compliant, Conditional Access policies can block access to corporate resources. This directly enforces the requirement that only devices with the correct OS version can access company data.

Exam trap

The trap here is confusing the purpose of Compliance policies (which enforce ongoing access rules based on device health) with Enrollment restrictions (which only gate initial enrollment) or Device configuration policies (which apply settings but do not evaluate compliance).

How to eliminate wrong answers

Option A is wrong because App protection policies (MAM) manage how apps handle data (e.g., preventing copy/paste) and do not enforce device-level OS version requirements. Option B is wrong because Enrollment restrictions control which devices can enroll in Intune (e.g., by platform or manufacturer) but do not enforce ongoing compliance with OS version after enrollment. Option D is wrong because Device configuration policies push settings (e.g., Wi-Fi, VPN, certificates) to devices but do not evaluate or enforce OS version compliance; they are not used for access control decisions.

104
MCQmedium

A company uses Microsoft Defender for Cloud to assess the security posture of their Azure subscriptions. They need to ensure that all resources are compliant with the Payment Card Industry Data Security Standard (PCI DSS). What should they do?

A.Create Azure Policy initiatives to enforce PCI DSS controls
B.Use Microsoft Purview to classify data and apply PCI DSS labels
C.Deploy Azure Blueprints that include PCI DSS policies
D.Enable the PCI DSS regulatory compliance standard in Microsoft Defender for Cloud
AnswerD

Microsoft Defender for Cloud includes built-in regulatory compliance standards, including PCI DSS 3.2.1 (and newer versions), directly under the 'Regulatory compliance' blade. When you enable the PCI DSS standard, Defender for Cloud automatically maps your Azure Policy and security configurations to the applicable PCI controls, provides a compliance score, and generates prioritized recommendations with remediation steps, all updated continuously as your environment changes.

Why this answer

Microsoft Defender for Cloud includes built-in regulatory compliance standards, such as PCI DSS, that can be enabled directly. Once enabled, Defender for Cloud continuously assesses your Azure subscriptions against the PCI DSS controls and provides a compliance score with detailed remediation steps. This is the simplest and most effective method to monitor compliance without creating custom policies or blueprints.

Exam trap

The trap here is that candidates often confuse Azure Policy or Blueprints as the primary tool for compliance assessment, when in fact Defender for Cloud's built-in regulatory compliance standards are the correct, out-of-the-box solution for monitoring against frameworks like PCI DSS.

How to eliminate wrong answers

Option A is wrong because Azure Policy initiatives enforce custom or built-in policies for resource configuration, but they do not natively map to PCI DSS controls; you would need to create or import a custom initiative, which is more complex and less accurate than using the built-in standard. Option B is wrong because Microsoft Purview is a data governance and classification service, not a compliance assessment tool for PCI DSS; it cannot evaluate resource configurations or provide a compliance score against PCI DSS. Option C is wrong because Azure Blueprints can include policies and resource templates, but they are used for deploying consistent environments, not for ongoing compliance assessment; the PCI DSS standard in Defender for Cloud already provides the necessary policy mappings and continuous monitoring.

105
MCQmedium

Your company is migrating on-premises Active Directory to Microsoft Entra ID. The security team requires that users must use passwordless authentication methods for all sign-ins. Which Microsoft Entra ID feature should you enable to support passwordless authentication?

A.Microsoft Entra ID passwordless authentication methods
B.Password hash synchronization
C.Seamless Single Sign-On (Seamless SSO)
D.Pass-through authentication
AnswerA

These methods replace the password with a device-bound cryptographic key (e.g., Windows Hello for Business, FIDO2 security keys) or a biometric gesture in the Microsoft Authenticator app. By requiring proof of possession and user presence, they eliminate the password secret entirely and are inherently phishing-resistant, which aligns with the passwordless goal of the migration.

Why this answer

Microsoft Entra ID passwordless authentication methods (such as Windows Hello for Business, FIDO2 security keys, and Microsoft Authenticator) are the native features designed to eliminate passwords entirely. These methods satisfy the security team's requirement by enabling users to sign in without a password, using biometrics or cryptographic keys instead.

Exam trap

The trap here is that candidates often confuse 'passwordless authentication' with features that reduce password usage (like Seamless SSO or PHS) rather than understanding that only the dedicated passwordless methods in Entra ID actually remove the password requirement entirely.

How to eliminate wrong answers

Option B is wrong because Password hash synchronization (PHS) synchronizes password hashes from on-premises AD to Entra ID for authentication, but it does not enable passwordless methods; it still relies on passwords. Option C is wrong because Seamless SSO provides automatic sign-in when users are on domain-joined devices connected to the corporate network, but it does not eliminate the need for passwords—it just skips the password prompt in certain scenarios. Option D is wrong because Pass-through authentication (PTA) validates passwords directly against on-premises AD, but it still requires a password to be entered and does not support passwordless authentication.

106
MCQhard

Your organization is deploying Microsoft Copilot for Security and wants to ensure that the AI model does not expose sensitive data in its responses. You need to configure data loss prevention (DLP) policies that apply to Copilot interactions. Which Microsoft Purview capability should you use?

A.eDiscovery
B.Data Loss Prevention policies
C.Information Protection and sensitivity labels
D.Communication Compliance
AnswerB

DLP policies in Microsoft Purview inspect prompts and responses during Copilot interactions, detecting sensitive information types and blocking or auditing exposure. This directly satisfies the requirement to prevent sensitive data appearing in AI-generated responses, since the policy evaluates content at the interaction layer rather than relying on model training.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies for Copilot are designed to prevent sensitive data from being exposed in AI interactions. These policies can scan prompts and responses for sensitive information and take actions like blocking or alerting. Communication Compliance (Option D) is intended for monitoring communications, such as emails and Teams messages, but not specifically for DLP in AI interactions.

Therefore, DLP policies are the correct capability for this requirement.

Exam trap

The trap is that candidates may confuse Communication Compliance as the DLP solution for Copilot, but Microsoft has specifically extended DLP policies to cover Copilot interactions, making standard DLP policies the correct choice.

How to eliminate wrong answers

Option A is wrong because eDiscovery is used for legal and investigative searches of content across Microsoft 365, not for real-time data loss prevention in AI interactions. Option B is wrong because standard Data Loss Prevention policies apply to traditional data-at-rest and data-in-transit scenarios (e.g., email, SharePoint), but they do not natively extend to Copilot for Security interactions without Communication Compliance integration. Option C is wrong because Information Protection and sensitivity labels classify and protect data through encryption and labeling, but they do not provide the real-time scanning and policy enforcement needed to prevent sensitive data exposure in Copilot responses.

107
MCQhard

Your organization is migrating to Microsoft 365 and wants to implement a data classification strategy. The compliance team needs to automatically detect and label documents containing personal data (e.g., Social Security numbers) in SharePoint Online. Which Microsoft Purview solution should you use?

A.Auto-labeling policies
B.Records Management
C.eDiscovery
D.Data Loss Prevention policies
AnswerA

Auto-labeling policies in Microsoft Purview scan SharePoint Online content using sensitive information types, such as Social Security numbers, and apply sensitivity labels automatically without user input. This satisfies the compliance team's requirement for automatic detection and labelling of personal data at scale.

Why this answer

Auto-labeling policies in Microsoft Purview are designed to automatically detect sensitive data types (e.g., Social Security numbers) using built-in or custom sensitive information types and apply sensitivity labels to documents in SharePoint Online. This meets the requirement for automatic detection and labeling without user intervention, as the compliance team needs.

Exam trap

The trap here is confusing Data Loss Prevention (DLP) policies with auto-labeling policies, as both can detect sensitive data, but DLP policies enforce protective actions (block/alert) while auto-labeling policies apply sensitivity labels for classification and downstream protection.

How to eliminate wrong answers

Option B (Records Management) is wrong because it focuses on managing retention and disposition of content, not on automatic detection and labeling of sensitive data. Option C (eDiscovery) is wrong because it is used for searching and exporting content for legal or investigative purposes, not for applying classification labels. Option D (Data Loss Prevention policies) is wrong because DLP policies are designed to prevent unauthorized sharing or leakage of sensitive data by blocking or alerting on activities, not to automatically apply sensitivity labels to documents at rest.

108
MCQmedium

A company deploys Microsoft Defender for Cloud Apps. They need to detect anomalous behavior in user activities across multiple cloud apps. Which feature should they enable?

A.Session policies
B.Anomaly detection policies
C.Data loss prevention policies
D.App governance
AnswerB

Anomaly detection policies in Microsoft Defender for Cloud Apps baseline each user's normal activity across connected apps, then alert on deviations such as impossible travel or mass downloads. This directly satisfies the requirement to detect anomalous behaviour spanning multiple cloud apps.

Why this answer

Anomaly detection policies in Microsoft Defender for Cloud Apps are specifically designed to identify unusual patterns in user activities across connected cloud apps, such as impossible travel, mass file downloads, or ransomware-like behavior. These policies leverage machine learning and behavioral analytics to establish a baseline of normal user behavior and trigger alerts when deviations occur, making them the correct choice for detecting anomalous behavior.

Exam trap

The trap here is that candidates often confuse session policies (which enforce real-time access controls) with anomaly detection policies (which analyze historical patterns), leading them to select session policies when the question specifically asks for detecting anomalous behavior rather than controlling it.

How to eliminate wrong answers

Option A is wrong because session policies are used for real-time control of user sessions based on risk level, not for detecting anomalous behavior patterns over time. Option C is wrong because data loss prevention policies focus on preventing unauthorized sharing or leakage of sensitive data, not on detecting behavioral anomalies in user activities. Option D is wrong because app governance provides visibility and control over app permissions and compliance, but it does not include the behavioral anomaly detection capabilities needed for user activity monitoring.

109
MCQmedium

Your organization is migrating on-premises applications to Azure and needs to secure secrets (database connection strings, API keys) used by these applications. You are required to rotate secrets automatically without downtime. Which Azure service should you use?

A.Microsoft Purview Information Protection
B.Azure App Configuration with feature flags
C.Azure Key Vault with managed identity and certificate auto-rotation
D.Azure AD Application Proxy
AnswerC

Azure Key Vault is the appropriate service for securely storing and managing sensitive information such as certificates, keys, and secrets. By combining it with a managed identity, an application authenticates to Key Vault without any hardcoded credentials, and the built-in certificate auto-rotation ensures certificates are renewed and renewed versions are made available transparently. This integrated approach fully addresses secret storage, access control, and lifecycle management for your migration.

Why this answer

Azure Key Vault with managed identity and certificate auto-rotation is correct because it provides a centralized, secure store for secrets like database connection strings and API keys, supports automatic rotation of certificates and secrets via Event Grid notifications or lifecycle policies, and integrates with Azure resources using managed identities to enable zero-downtime rotation without exposing credentials in code or configuration.

Exam trap

The trap here is that candidates confuse Azure App Configuration (which can store configuration values but not secrets securely with rotation) with Azure Key Vault, or mistakenly think Purview Information Protection handles secrets management, when only Key Vault provides the required secure storage and automated rotation capabilities.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Protection is a data classification and labeling service for protecting sensitive data at rest and in transit, not a secrets management or rotation service. Option B is wrong because Azure App Configuration with feature flags is designed for managing application configuration settings and feature toggles, not for securely storing or rotating secrets like connection strings or API keys. Option D is wrong because Azure AD Application Proxy provides secure remote access to on-premises web applications by publishing them through Azure AD, not for storing or rotating secrets.

110
MCQmedium

Refer to the exhibit. You are reviewing a conditional access policy. What is the effect of this policy?

A.The policy is disabled and has no effect
B.Blocks access for all users
C.Requires multifactor authentication for all users
D.Requires multifactor authentication for Global Administrators and Security Administrators
AnswerD

The policy configuration targets the directory roles Global Administrators and Security Administrators, and its grant control is set to 'Require multi-factor authentication'. When a user who holds either of these roles attempts to access a protected resource, the policy is triggered and MFA is enforced. This correctly matches the statement that MFA is required for both administrator roles.

Why this answer

The exhibit shows a conditional access policy that targets the 'Global Administrators' and 'Security Administrators' directory roles, and the policy is configured to 'Require multifactor authentication' for those roles. The policy is enabled (as indicated by the 'On' toggle), so it actively enforces MFA for members of those two admin roles, blocking access if they do not complete MFA. This aligns with the principle of securing high-privilege roles with stronger authentication.

Exam trap

The trap here is that candidates may overlook the specific role targeting in the policy and assume it applies to all users, leading them to choose option C, or they may mistakenly think the policy is disabled because they misread the toggle state, choosing option A.

How to eliminate wrong answers

Option A is wrong because the policy is enabled (the 'On' toggle is visible in the exhibit), so it is not disabled and does have an effect. Option B is wrong because the policy targets only specific directory roles (Global Administrators and Security Administrators), not all users, so it does not block access for everyone. Option C is wrong because the policy does not apply to all users; it is scoped to only the two specified admin roles, so it does not require MFA for all users.

111
MCQmedium

A company uses Microsoft Entra ID Governance. They need to automate the process of granting access to a SaaS application based on the user's department attribute. Which feature should they use?

A.Lifecycle workflows
B.Entitlement management
C.Access reviews
D.Privileged identity management
AnswerB

Entitlement management in Microsoft Entra ID Governance provides access packages that bundle resources, roles, and policies. It can automate assignment based on member attributes through dynamic membership rules or by connecting to a source like an HR system, and it supports time-bound assignments, self-service requests, and approvals. This makes it the appropriate tool for automatically granting access to applications based on an attribute such as the user's department, aligning directly with the stated need.

Why this answer

Entitlement management in Microsoft Entra ID Governance allows you to create access packages that define collections of resources (like SaaS apps) and policies for who can request access. By configuring a dynamic membership rule based on the user's department attribute, you can automate granting access to the SaaS application without manual intervention. This directly meets the requirement to automate access based on a user attribute.

Exam trap

The trap here is that candidates confuse Lifecycle workflows (which automate HR-driven provisioning events) with Entitlement management (which automates attribute-based access requests), leading them to choose Option A incorrectly.

How to eliminate wrong answers

Option A is wrong because Lifecycle workflows automate joiner, mover, and leaver processes (e.g., account provisioning, email forwarding) but do not handle attribute-based access requests to SaaS applications. Option C is wrong because Access reviews are periodic attestation processes to review existing access, not an automated mechanism to grant access based on a user attribute. Option D is wrong because Privileged identity management (PIM) provides just-in-time privileged access to Azure AD roles and Azure resources, not automated entitlement to a SaaS application based on a department attribute.

112
MCQeasy

Your security team needs to receive alerts when a user is assigned a privileged role in Microsoft Entra ID. Which service should you use to create an alert for privileged role assignments?

A.Microsoft Entra ID Privileged Identity Management (PIM)
B.Microsoft Defender for Identity
C.Microsoft Sentinel
D.Microsoft Defender for Cloud Apps
AnswerA

PIM is the native Microsoft Entra ID identity governance engine that delivers built-in, out-of-the-box alerting for privileged role assignments and activations. It monitors for suspicious activities such as permanent privileged assignments, off-hours role activation, or activation attempts that bypass just-in-time access policies, and can trigger email notifications or integrate with SIEM tools. These alerts are natively scoped to Entra ID roles, requiring no additional log ingestion or custom rule authoring, making it the correct choice for this requirement.

Why this answer

Microsoft Entra ID Privileged Identity Management (PIM) is the correct service because it provides built-in alerting capabilities specifically for privileged role assignments in Microsoft Entra ID. PIM can generate alerts when a user is assigned a privileged role, such as Global Administrator, without requiring additional configuration or external data sources. This aligns directly with the requirement to receive alerts for privileged role assignments within the identity platform.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Identity or Microsoft Sentinel as the primary alerting tool for Entra ID role assignments, but PIM is the native, purpose-built service for this specific identity governance task.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Identity is a security solution that monitors on-premises Active Directory signals and hybrid identities for threats like lateral movement and compromised accounts, not for generating alerts on Entra ID role assignments. Option C is wrong because Microsoft Sentinel is a SIEM/SOAR platform that ingests logs from multiple sources, including Entra ID, but it requires custom analytics rules and log ingestion to create alerts for role assignments, making it an indirect and more complex solution compared to PIM's native alert. Option D is wrong because Microsoft Defender for Cloud Apps focuses on cloud application discovery, session controls, and anomaly detection for SaaS apps, not on monitoring Entra ID privileged role assignments.

113
MCQeasy

A company uses Microsoft Defender for Endpoint (MDE) and needs to ensure that all devices report their security configuration to Microsoft Defender XDR. Which setting should they verify?

A.Devices are enrolled in Microsoft Intune
B.Microsoft Sentinel is connected to Defender for Endpoint
C.Microsoft Purview Information Protection is enabled
D.Devices are onboarded to Microsoft Defender XDR
AnswerD

Onboarding to Microsoft Defender XDR is the act of enrolling each device with the Defender for Endpoint agent, which then establishes the connection to the XDR backend and begins submitting raw sensor data, process events, network signals, and security alerts. This is the required technical prerequisite for a device to appear in the Defender XDR device inventory and to contribute to the unified incident story. Without onboarding, no other Microsoft service can cause the endpoint to report its security state to the XDR experience.

Why this answer

Devices must be onboarded to Microsoft Defender XDR to report their security configuration. Onboarding registers the device with the Defender for Endpoint service, enabling the collection and forwarding of security telemetry to the Microsoft 365 Defender portal. Without onboarding, the device cannot communicate its security state, regardless of other integrations.

Exam trap

The trap here is that candidates confuse Intune enrollment with Defender for Endpoint onboarding, but Intune only manages policies and compliance, while onboarding is the specific process that enables security telemetry reporting to Defender XDR.

How to eliminate wrong answers

Option A is wrong because Intune enrollment manages device compliance and configuration policies but does not automatically onboard devices to Defender for Endpoint; a separate onboarding step is required. Option B is wrong because connecting Microsoft Sentinel to Defender for Endpoint ingests alerts and incidents into Sentinel for SIEM purposes, but it does not cause devices to report their security configuration to Defender XDR. Option C is wrong because Microsoft Purview Information Protection focuses on data classification and labeling, not device-level security configuration reporting.

114
MCQeasy

A company is implementing a Zero Trust security model. Which principle requires verifying every access request as if it originates from an uncontrolled network?

A.Least privilege
B.Micro-segmentation
C.Assume breach
D.Verify explicitly
AnswerD

Verify explicitly is the foundational Zero Trust principle mandating that every access request is continuously authenticated and authorized based on all available data points, including user identity, device compliance, location, data sensitivity, and behavioral anomalies. No implicit trust is granted, even for requests originating from internal networks or previously trusted endpoints. This principle directly addresses the 'always verify' core by evaluating each request dynamically at the policy enforcement point.

Why this answer

The 'Assume breach' principle is not about verifying requests. 'Verify explicitly' is the Zero Trust principle that mandates authenticating and authorizing every access request. 'Least privilege' limits access rights. 'Micro-segmentation' is a network isolation technique.

115
MCQhard

Your organization has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You need to design a solution that ensures all user authentication requests are evaluated by Conditional Access policies before granting access to cloud apps. However, some legacy apps still require basic authentication. What should you recommend?

A.Enable authentication policies in Microsoft Entra ID to block legacy authentication
B.Configure Active Directory Federation Services (AD FS) as the identity provider
C.Deploy Microsoft Entra Application Proxy for all legacy apps
D.Enable pass-through authentication (PTA) to forward authentication requests
AnswerA

Enabling authentication policies in Microsoft Entra ID, such as the legacy authentication block, is the correct approach because legacy protocols like POP3, IMAP4, and SMTP do not support modern authentication and thus cannot be evaluated against Conditional Access policies. Blocking these protocols forces clients to use modern authentication (OAuth 2.0, OpenID Connect, SAML), ensuring multi-factor authentication and device compliance checks are enforced on every sign-in.

Why this answer

Enabling authentication policies in Microsoft Entra ID to block legacy authentication ensures that all user authentication requests are evaluated by Conditional Access policies before granting access to cloud apps. Legacy authentication protocols (e.g., POP3, IMAP, SMTP, basic auth) bypass modern authentication and Conditional Access, so blocking them forces clients to use modern protocols (OAuth 2.0, OpenID Connect) that are subject to Conditional Access evaluation. This directly addresses the requirement while allowing legacy apps to be updated or replaced over time.

Exam trap

The trap here is that candidates often confuse 'blocking legacy authentication' with 'disabling basic authentication' in Exchange Online or other services, but the correct approach is to use the tenant-wide Conditional Access policy to block all legacy authentication protocols, which is a distinct setting in Microsoft Entra ID.

How to eliminate wrong answers

Option B is wrong because configuring AD FS as the identity provider does not inherently block legacy authentication; AD FS can still accept legacy authentication requests unless explicitly configured to block them, and it does not enforce Conditional Access policies for cloud apps as effectively as Entra ID. Option C is wrong because deploying Microsoft Entra Application Proxy for all legacy apps provides secure remote access but does not block legacy authentication protocols; the apps themselves may still use basic authentication, which bypasses Conditional Access. Option D is wrong because enabling pass-through authentication (PTA) forwards authentication requests to on-premises AD but does not block legacy authentication; PTA works with modern authentication but legacy protocols still bypass Conditional Access unless explicitly blocked.

116
MCQhard

Fabrikam uses Microsoft Entra ID P2 and Microsoft Defender for Identity. The security operations team wants to detect and respond to suspicious activities such as pass-the-hash attacks and reconnaissance attempts against on-premises Active Directory Domain Services (AD DS) domain controllers. They need a solution that provides behavioral analytics and integrates with Microsoft Sentinel for incident correlation. What should you include in the design?

A.Deploy Microsoft Defender for Identity sensors on domain controllers and configure Microsoft Sentinel to ingest Defender for Identity alerts.
B.Configure Microsoft Entra ID Protection risk policies and stream risk detections to Microsoft Sentinel.
C.Enable Microsoft Defender for Cloud Apps anomaly detection policies and connect them to Microsoft Sentinel.
D.Install Microsoft Monitoring Agent on domain controllers and create custom log queries in Microsoft Sentinel to detect suspicious activity.
AnswerA

This is correct because Microsoft Defender for Identity sensors installed on domain controllers monitor AD DS traffic and use behavioral analytics to detect advanced attacks like pass-the-hash and reconnaissance. Integrating with Microsoft Sentinel allows centralized incident correlation and response. This directly meets the requirement for detecting on-premises AD DS threats and integrating with Sentinel.

Why this answer

Microsoft Defender for Identity sensors on domain controllers provide deep behavioral analytics and detect advanced on-premises AD DS attacks such as pass-the-hash and reconnaissance. Integrating Defender for Identity with Microsoft Sentinel enables centralized incident correlation and automated response. This combination directly satisfies the requirement for detecting on-premises threats and integrating with Sentinel for a comprehensive security operations solution.

Exam trap

The trap here is confusing Microsoft Entra ID Protection, which focuses on cloud identity risks, with Microsoft Defender for Identity, which monitors on-premises Active Directory Domain Services for advanced attacks.

117
MCQhard

A company uses Microsoft Defender for Endpoint to protect endpoints. They want to configure attack surface reduction rules to block executable files from running unless they meet a specific prevalence, age, or trust level. Which ASR rule should they enable?

A.Block Office communication application from creating child processes
B.Block credential stealing from the Windows local security authority subsystem
C.Block untrusted and unsigned processes that run from USB
D.Block executable files from running unless they meet a prevalence, age, or trusted list criteria
AnswerD

This is the exact Microsoft Defender for Endpoint ASR rule that uses cloud-delivered reputation to block executable files that lack sufficient prevalence, are too new (low age), or do not appear on a trusted list. Before allowing the process to run, the endpoint consults Microsoft's reputation service and enforces the decision based on those collective metadata signals. This behavior directly matches the scenario in the question, making it the correct choice.

Why this answer

The ASR rule 'Block executable files from running unless they meet a prevalence, age, or trusted list criteria' (GUID: 01443614-cd74-433a-b99e-2ecdc07bfc25) is specifically designed to block executables that do not meet Microsoft's cloud-based prevalence, age, or trustworthiness criteria. This rule uses the Microsoft Intelligent Security Graph to evaluate files against global telemetry, blocking those that are new, rare, or unsigned, which directly matches the requirement to block executables based on prevalence, age, or trust level.

Exam trap

The trap here is that candidates confuse the USB-specific rule (Option C) with the global executable prevalence rule (Option D), because both mention 'untrusted' or 'unsigned', but only Option D explicitly includes prevalence, age, and trusted list criteria as stated in the question.

How to eliminate wrong answers

Option A is wrong because 'Block Office communication application from creating child processes' (GUID: 26190899-1602-49e8-8b27-eb1d0a1ce869) targets child processes spawned by Office communication apps (e.g., Outlook, Skype) to prevent lateral movement via macro-based attacks, not executable file prevalence or trust. Option B is wrong because 'Block credential stealing from the Windows local security authority subsystem' (GUID: 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2) protects LSASS memory from credential theft tools like Mimikatz, not executable file execution policies. Option C is wrong because 'Block untrusted and unsigned processes that run from USB' (GUID: b2b3f03d-6a4c-4b7e-8c97-3f0e5c7b8a9d) only applies to USB-removable media, not all executable files, and does not consider prevalence or age criteria.

118
MCQmedium

A global retail company, Northwind Traders, is adopting a cloud-first strategy using Azure and Microsoft 365. They have a large number of temporary seasonal workers who need access to specific applications and data for limited periods. The security team wants to minimize the risk of standing privileges and ensure that access is granted only when needed and for a limited duration. They also need to audit all privileged access actions. The environment includes Microsoft Entra ID, Azure resources, and Microsoft 365 services. You need to design a privileged access strategy that follows the principle of least privilege and aligns with Microsoft's best practices for privileged identity management. What should you recommend?

A.Use Microsoft Entra Privileged Identity Management (PIM) to grant just-in-time access to Azure AD roles and Azure resources. Configure approval workflows for high-privilege roles. Set maximum activation durations. For non-Azure resources, use Privileged Access Groups (PAG) to manage access. Enable audit logging to a Log Analytics workspace for monitoring.
B.Create a custom role in Azure AD with limited permissions. Assign the role to a security group. Have users request access via a manual email process. The IT team approves and assigns the group membership temporarily.
C.Assign permanent roles to seasonal workers for the duration of their contract. Use Azure AD access reviews to periodically confirm access. Enable Azure AD audit logs. Use Conditional Access to require MFA for privileged roles.
D.Create separate Azure AD roles for each seasonal worker with granular permissions. Use Azure AD Identity Governance to automate access requests. Do not enable PIM to reduce complexity.
AnswerA

This is correct because Microsoft Entra Privileged Identity Management (PIM) provides just-in-time (JIT) administrative access, meaning users get the rights only when needed and for a limited, configurable duration. For high-privilege roles, you can require approval workflows so that activations are explicitly authorized, and setting maximum activation durations enforces a time-bound window that minimizes standing privilege. For non-Azure resources such as on-premises apps or Azure AD-joined groups, Privileged Access Groups (PAG) extend PIM's JIT and approval controls to group membership. Additionally, routing audit logs to a Log Analytics workspace centralizes monitoring and enables alerting on suspicious activations, which satisfies both security and compliance requirements.

Why this answer

It leverages Microsoft Entra Privileged Identity Management (PIM) to enforce just-in-time (JIT) access for Azure AD roles and Azure resources, aligning with the principle of least privilege and minimizing standing privileges. It includes approval workflows for high-privilege roles, maximum activation durations to limit exposure, and Privileged Access Groups (PAG) to manage access to non-Azure resources like Microsoft 365 workloads. Audit logging to a Log Analytics workspace provides comprehensive monitoring of all privileged actions, meeting the auditing requirement.

Exam trap

The trap here is that candidates may assume permanent role assignments with periodic access reviews are sufficient, but this fails to eliminate standing privileges between reviews, which is the core risk the question targets.

How to eliminate wrong answers

Option B is wrong because a manual email process for access requests is insecure, lacks automation, and does not enforce just-in-time activation or time-bound access, violating the requirement to minimize standing privileges. Option C is wrong because assigning permanent roles to seasonal workers for the duration of their contract creates standing privileges, which contradicts the goal of granting access only when needed and for a limited duration; access reviews alone do not prevent persistent access between reviews. Option D is wrong because creating separate Azure AD roles for each seasonal worker is administratively unsustainable and violates least privilege by not using PIM, which is essential for JIT activation and approval workflows; disabling PIM increases complexity and risk.

119
MCQeasy

A company wants to enforce that all administrators use just-in-time (JIT) access to privileged roles in Microsoft Entra ID. Which feature should they enable?

A.Microsoft Entra ID Conditional Access
B.Microsoft Entra ID Privileged Identity Management (PIM)
C.Microsoft Entra ID Access Reviews
D.Microsoft Entra ID Protection
AnswerB

PIM is the Entra ID service purpose-built for just-in-time, time-bound privileged role activation. Administrators are made eligible for roles, and when they need access they activate for a requested duration—optionally with MFA, business justification, and an approval workflow—after which the role expires automatically. This directly replaces permanent 'standing' admin access with auditable, as-needed elevation.

Why this answer

Microsoft Entra ID Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access by enabling time-bound and approval-based role activation. This directly meets the requirement to enforce JIT access for administrators, as PIM allows roles to be activated only when needed and for a limited duration, reducing standing access.

Exam trap

The trap here is that candidates often confuse Conditional Access (which controls access to apps) with PIM (which controls privileged role activation), leading them to select Option A because they think JIT access is a policy-based access control feature.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID Conditional Access enforces access policies based on signals like location or device state, but it does not provide time-bound role activation or JIT privileged access. Option C is wrong because Microsoft Entra ID Access Reviews are used to periodically audit and recertify group memberships or role assignments, not to grant or activate privileged roles on demand. Option D is wrong because Microsoft Entra ID Protection detects and responds to identity-based risks (e.g., leaked credentials) but does not manage privileged role activation or JIT access.

120
MCQmedium

Refer to the exhibit. You are reviewing a KQL query in Microsoft Sentinel. What is the primary purpose of this query?

A.To identify accounts with multiple failed logon attempts from a single IP.
B.To list all successful logon events in the last 7 days.
C.To calculate the total number of failed logons per hour.
D.To detect account lockout events.
AnswerA

The query aggregates failed sign-in events, grouping by account and source IP address, then filters for counts exceeding a threshold. This surfaces accounts experiencing multiple failed logon attempts from a single IP, indicating possible brute-force or password-spray activity.

Why this answer

The query uses the `SecurityEvent` table and filters for `EventID == 4625`, which indicates a failed logon attempt. By summarizing `count()` by `IPAddress` and `Account` and filtering for `FailedAttempts > 5`, the query identifies accounts with multiple failed logon attempts from a single IP address. This is typical for detecting brute-force or password-spray attacks, making option A correct.

Exam trap

Candidates may confuse EventID 4625 with successful logon (EventID 4624) or account lockout (EventID 4740). They might also overlook that the query groups by both IP and account, not by time, leading them to select options B, C, or D.

How to eliminate wrong answers

Option B is wrong because the query filters for `ResultType == 50057`, which is a failed logon event, not a successful one; successful logons would use `ResultType == 0`. Option C is wrong because the query summarizes by `IPAddress` and `UserPrincipalName`, not by time bins (e.g., `bin(TimeGenerated, 1h)`), so it cannot calculate failed logons per hour. Option D is wrong because account lockout events are represented by a different `ResultType` value (e.g., 50053 or 50074 in Azure AD), and the query does not filter for those codes.

121
Multi-Selectmedium

Which TWO of the following are benefits of using Microsoft Defender XDR (Extended Detection and Response)? (Choose two.)

Select 2 answers
A.Scans for vulnerabilities in VMs
B.Provides compliance assessments
C.Cross-domain correlation of alerts
D.Replaces the need for a firewall
E.Automated investigation and response
AnswersC, E

Cross-domain correlation of alerts is a core benefit of Microsoft Defender XDR because it ingests signals from Microsoft Defender for Endpoint, Identity, Office 365, and Cloud Apps, and fuses them into a unified incident. This correlation enables security teams to see the full attack chain—such as a phishing email leading to credential theft and lateral movement—rather than investigating disjointed alerts. This is exactly the value that differentiates XDR from single-vector security tools.

Why this answer

Option C is correct because Microsoft Defender XDR is specifically designed to correlate signals and alerts across multiple security domains — endpoints (Defender for Endpoint), identities (Defender for Identity), email and collaboration (Defender for Office 365), and cloud apps (Defender for Cloud Apps) — into unified incidents, which is the core value of an XDR platform. Option E is correct because Defender XDR includes automated investigation and response (AIR) capabilities that use playbooks and automation to investigate alerts, remediate threats, and reduce analyst workload. Option A is not correct because vulnerability scanning of VMs is a function of Microsoft Defender for Cloud (or Defender Vulnerability Management), not the defining benefit of Defender XDR.

Option B is not correct because compliance assessments are provided by Microsoft Purview Compliance Manager and Microsoft Defender for Cloud regulatory compliance dashboards, not by Defender XDR itself. Option D is not correct because Defender XDR is a detection and response platform and does not replace a network firewall, which remains necessary for perimeter and network-layer filtering.

Exam trap

The trap here is that candidates confuse the broad capabilities of the Microsoft security portfolio (e.g., Defender for Cloud, Purview) with the specific scope of Defender XDR, leading them to select features that belong to other services.

122
MCQmedium

Litware, a software development company, has adopted a DevOps culture and uses Azure DevOps for CI/CD pipelines. They deploy applications to Azure Kubernetes Service (AKS) and Azure App Services. The security team wants to ensure that secrets (API keys, connection strings) are not exposed in source code or pipeline logs. They also need to scan container images for vulnerabilities before deployment and ensure that only approved images are used in production. The solution must integrate with Microsoft Defender for Cloud and follow security best practices. What should you include in the design?

A.Use Azure App Configuration to store secrets with encryption. Run vulnerability scans using a third-party tool integrated into the pipeline. Create a custom script to check image registry location.
B.Store secrets in Azure Key Vault and use Azure DevOps Variable Groups linked to Key Vault for retrieval during pipelines. Enable Microsoft Defender for Containers on AKS to scan container images for vulnerabilities. Use Azure Policy (specifically Azure Policy for AKS with Gatekeeper) to enforce that only images from approved registries are deployed.
C.Store secrets as encrypted pipeline variables in Azure DevOps. Use Azure Container Registry (ACR) tasks to scan images. Implement manual approval gates in release pipelines to verify image source.
D.Store secrets in Azure Key Vault but use a custom task to retrieve them. Scan images using Microsoft Defender for Cloud after deployment. Use role-based access control to restrict registry access.
AnswerB

Azure Key Vault is the correct service for secrets because it offers centralized management, access policies, rotation, and auditing; linking Azure DevOps Variable Groups to Key Vault retrieves secrets securely at pipeline runtime without exposing them in logs. Enabling Microsoft Defender for Containers on AKS automatically scans container images in ACR for vulnerabilities and provides runtime threat detection. Azure Policy with Gatekeeper (the AKS admission controller) enforces that only images from approved registries are deployed, providing governance and preventing unauthorized or malicious image usage.

Why this answer

It aligns with security best practices by using Azure Key Vault to securely store secrets and linking them to Azure DevOps Variable Groups for secure retrieval during pipelines, preventing exposure in source code or logs. It enables Microsoft Defender for Containers on AKS to scan container images for vulnerabilities before deployment, and uses Azure Policy with Gatekeeper to enforce that only images from approved registries are deployed, ensuring compliance and integration with Microsoft Defender for Cloud.

Exam trap

The trap here is that candidates often confuse Azure App Configuration with Azure Key Vault for secret storage, or assume that post-deployment scanning is acceptable, but the requirement explicitly demands scanning before deployment and integration with Microsoft Defender for Cloud.

How to eliminate wrong answers

Option A is wrong because Azure App Configuration is not designed for secret storage (it lacks native key rotation and access policies compared to Key Vault), and using a third-party tool for vulnerability scanning and a custom script for registry checks does not integrate with Microsoft Defender for Cloud as required. Option C is wrong because storing secrets as encrypted pipeline variables in Azure DevOps still exposes them in pipeline logs and does not provide centralized secret management or rotation, and ACR tasks scan images only after push, not before deployment, while manual approval gates do not enforce policy-based image source control. Option D is wrong because using a custom task to retrieve secrets from Key Vault bypasses the secure, native integration of Variable Groups linked to Key Vault, and scanning images after deployment (post-deployment) violates the requirement to scan before deployment, while RBAC alone does not enforce that only approved images are used.

123
MCQhard

Your organization uses Microsoft Sentinel for security operations. You need to design a solution to automatically respond to a DDoS attack detected by Azure DDoS Protection. The response should include blocking the attacker's IP address in Azure Firewall and sending an alert to the security team. Which approach should you use?

A.Configure an alert rule in Azure Monitor to send an email to the security team
B.Use Azure Policy to deny network traffic from the attacker's IP range
C.Configure a resource lock on the Azure Firewall to prevent changes
D.Create an automation rule in Microsoft Sentinel that triggers a playbook to block the IP in Azure Firewall
AnswerD

Automation rules in Microsoft Sentinel continuously run on incident creation, updating, or closing events and can invoke an Azure Logic Apps playbook when an incident is triggered. The playbook can use the Azure Firewall connector to add a deny rule for the specific IP, directly modifying the firewall's network rule collection to stop the attack at the network layer. This combines SIEM threat detection with SOAR-driven response, enabling real-time, automated IP blocking without manual intervention and with full audit trail.

Why this answer

Microsoft Sentinel automation rules can trigger a playbook (an Azure Logic App) when a DDoS attack detection alert fires. The playbook can execute an action to block the attacker's IP address in Azure Firewall via its REST API or PowerShell cmdlets, and simultaneously send an alert to the security team (e.g., via email or Teams). This provides an automated, orchestrated response directly from the SIEM, aligning with security operations best practices.

Exam trap

The trap here is that candidates may confuse Azure Monitor alert rules (which only notify) with Sentinel automation rules (which can trigger remediation playbooks), or think Azure Policy can dynamically block IPs when it is actually a static compliance enforcement tool.

How to eliminate wrong answers

Option A is wrong because an Azure Monitor alert rule can only send notifications (e.g., email) and cannot perform remediation actions like blocking an IP in Azure Firewall; it lacks the orchestration capability needed for automated response. Option B is wrong because Azure Policy is a governance tool for enforcing compliance rules on resource configurations (e.g., denying creation of certain resources), not for dynamically blocking network traffic from a specific attacker IP in real time. Option C is wrong because a resource lock on Azure Firewall prevents accidental deletion or modification of the firewall itself, but does not block attacker IPs or send alerts; it actually hinders the automated response by locking the resource.

124
MCQmedium

Refer to the exhibit. You are reviewing an ARM template for an Azure storage account. Which security best practice is implemented?

A.Enforce HTTPS traffic only
B.Restrict network access by IP address
C.Deny all network traffic by default
D.Enable soft delete for blobs
AnswerC

Deny all network traffic by default is correct because the storage account template sets the networkAcls.defaultAction property to Deny. With this configuration, any request that does not match an explicitly permitted rule (such as a service endpoint or virtual network rule) is blocked at the network layer. This enforces a strict zero-trust baseline: all inbound traffic is denied unless an exception is explicitly defined, making it the primary network hardening control in the template.

Why this answer

The ARM template snippet shows the 'defaultAction' property set to 'Deny' under 'networkAcls', which explicitly denies all network traffic by default. This is a security best practice because it implements a zero-trust network model, ensuring that only explicitly allowed traffic (via IP rules or virtual network rules) can access the storage account. Option C correctly identifies this as the default deny behavior.

Exam trap

The trap here is that candidates may confuse 'defaultAction: Deny' with 'restrict network access by IP address' (Option B), but the default deny does not itself restrict by IP—it simply blocks everything until explicit allow rules are added.

How to eliminate wrong answers

Option A is wrong because the template does not include the 'supportsHttpsTrafficOnly' property or set it to true; enforcing HTTPS traffic only is a separate best practice not shown here. Option B is wrong because while IP rules can be added to allow specific addresses, the template only shows the default deny action, not any IP-based restrictions. Option D is wrong because soft delete for blobs is configured via the 'deleteRetentionPolicy' property on blob services, which is absent from this storage account-level network ACL configuration.

125
MCQeasy

Your organization is a small business with 50 employees that uses Microsoft 365 Business Premium. You need to design a security baseline that protects against common threats like phishing, ransomware, and data leakage. The solution must be easy to manage and require minimal ongoing effort. You have the following requirements: 1. Block malicious emails and links. 2. Protect sensitive data from being shared externally. 3. Require multi-factor authentication for all users. 4. Keep devices healthy. Which combination of policies should you implement?

A.Enable Microsoft Defender for Office 365 for phishing protection. Use Microsoft Purview Information Protection to automatically label sensitive emails. Create a Conditional Access policy to require MFA for admins only. Use Azure Information Protection scanner.
B.Enable Exchange Online Protection (EOP) for spam and malware filtering. Create a Conditional Access policy to require MFA for all users. Enable device compliance policies in Microsoft Intune.
C.Enable Microsoft Defender for Office 365 Safe Links and Safe Attachments. Create a Microsoft Purview DLP policy to prevent external sharing of sensitive data. Create a Conditional Access policy to require MFA and device compliance.
D.Enable Microsoft Defender for Office 365 Safe Links and Safe Attachments. Create a Microsoft Purview DLP policy to block sharing of credit card numbers. Enable security defaults in Microsoft Entra ID to enforce MFA.
AnswerC

This is the correct solution because it layers the three essential controls: Defender for Office 365 Safe Links and Safe Attachments protect users from sophisticated phishing payloads in real time, while a Microsoft Purview DLP policy detects and blocks external sharing of sensitive data at the point of exfiltration. The Conditional Access policy requiring MFA and device compliance ties identity and device trust together, ensuring that only healthy, authenticated devices can access corporate resources. Together these address email security, data exfiltration prevention, strong authentication for all users, and device health—the four core requirements.

Why this answer

It directly addresses all four requirements: Microsoft Defender for Office 365 Safe Links and Safe Attachments blocks malicious emails and links; a Microsoft Purview DLP policy prevents external sharing of sensitive data, protecting against data leakage; a Conditional Access policy requiring MFA and device compliance enforces multi-factor authentication for all users and ensures devices are healthy. This combination is easy to manage with minimal ongoing effort, as it leverages built-in Microsoft 365 Business Premium capabilities without complex custom configurations.

Exam trap

The trap here is that candidates often confuse Exchange Online Protection (EOP) with Defender for Office 365, not realizing that EOP lacks advanced link and attachment protection, and they may overlook the need for device compliance policies when only security defaults are used for MFA.

How to eliminate wrong answers

Option A is wrong because it requires MFA for admins only, not all users, and uses Azure Information Protection scanner (which is not included in Business Premium and requires additional licensing) instead of a DLP policy for data leakage protection. Option B is wrong because Exchange Online Protection (EOP) alone does not block malicious links in emails or attachments at the same level as Defender for Office 365 Safe Links and Safe Attachments, and it lacks a DLP policy to prevent external sharing of sensitive data. Option D is wrong because it blocks only credit card numbers via DLP, not all sensitive data types, and security defaults in Microsoft Entra ID enforce MFA but do not include device compliance checks, failing the 'keep devices healthy' requirement.

126
MCQmedium

A company plans to implement a Zero Trust security model. Which of the following is the primary principle that should guide their strategy?

A.Assume breach and verify explicitly
B.Use a strong perimeter firewall as the primary defense
C.Grant trusted users full access to all resources
D.Trust but verify all internal traffic
AnswerA

Zero Trust rejects implicit trust from network location; every request is authenticated and authorised against policy using identity, device and context signals. Assuming breach drives least-privilege access and continuous verification, which is the guiding principle the strategy requires.

Why this answer

The primary principle of Zero Trust is 'never trust, always verify,' which is operationalized as 'assume breach and verify explicitly.' This means every access request—regardless of source (internal or external)—must be authenticated, authorized, and encrypted before granting access. It eliminates implicit trust based on network location and enforces least-privilege access, which is foundational to the Zero Trust architecture.

Exam trap

The trap here is that candidates often confuse 'trust but verify' (Option D) with Zero Trust, but Zero Trust explicitly rejects any pre-established trust and requires verification at every access attempt, making 'assume breach and verify explicitly' the correct guiding principle.

How to eliminate wrong answers

Option B is wrong because relying on a strong perimeter firewall as the primary defense violates Zero Trust's core tenet of eliminating implicit trust based on network location; Zero Trust assumes the network is already compromised and requires micro-segmentation and per-request verification instead. Option C is wrong because granting trusted users full access to all resources contradicts the least-privilege principle of Zero Trust, which mandates that access be limited to only what is necessary for a specific task, regardless of user trust level. Option D is wrong because 'trust but verify' is the opposite of Zero Trust; Zero Trust requires 'never trust, always verify'—verification must occur before access is granted, not after trust is assumed.

127
Multi-Selecteasy

A company is implementing Microsoft Defender for Cloud to protect their Azure environment. Which TWO of the following are security best practices that should be enabled? (Choose two.)

Select 2 answers
A.Cloud Security Posture Management (CSPM)
B.Microsoft Defender for Cloud workload protection
C.Microsoft Defender for Office 365
D.Microsoft Defender for Endpoint onboarding
E.Microsoft Sentinel integration
AnswersA, B

Cloud Security Posture Management (CSPM) is a foundational capability of Microsoft Defender for Cloud that continually scans resource configurations across Azure, AWS, and GCP, comparing them against standards like the Azure Security Benchmark. It generates a Secure Score, highlights misconfigurations, and offers step-by-step remediation, enabling security teams to prevent vulnerabilities before exploitation. Because it directly targets the cloud control plane and configuration drift, CSPM is the best practice for continuous security assessment.

Why this answer

Option A, Cloud Security Posture Management (CSPM), is correct because Defender for Cloud's foundational CSPM continuously assesses Azure resources against security benchmarks like Microsoft Cloud Security Benchmark, surfaces secure score recommendations, and detects misconfigurations and external attack surface risks — the core best practice for hardening an Azure environment. Option B, Microsoft Defender for Cloud workload protection, is correct because enabling the Defender plans (e.g., Defender for Servers, Storage, SQL, Containers, App Service, Key Vault) adds threat detection, vulnerability assessment, and advanced protection for running workloads, which is the recommended complement to CSPM. Option C, Microsoft Defender for Office 365, is not part of Defender for Cloud's Azure protection scope; it protects Exchange Online, SharePoint, Teams, and email against phishing and malware.

Option D, Microsoft Defender for Endpoint onboarding, is a separate endpoint security product (though Defender for Servers can auto-provision it), not a Defender for Cloud best-practice toggle itself. Option E, Microsoft Sentinel integration, is an optional SIEM/SOAR data-connector scenario for centralized detection and response, not a required Defender for Cloud security best practice.

Exam trap

The trap here is that candidates often confuse 'security best practices that should be enabled' with 'all available security products,' leading them to select options like Defender for Office 365 or Sentinel, which are valuable but not mandatory foundational practices for Azure environment protection in the context of Defender for Cloud.

128
MCQhard

Your organization is adopting Microsoft Copilot for Security. You need to ensure that the AI model does not expose sensitive data during interactions. What is the primary security control you should implement?

A.Microsoft Entra Conditional Access policies
B.Microsoft Entra Privileged Identity Management
C.Microsoft Purview Information Protection sensitivity labels
D.Microsoft Purview Data Loss Prevention policies for Copilot
AnswerD

Data Loss Prevention policies for Copilot are specifically designed to detect sensitive information types—such as credit card numbers or personally identifiable information—within Copilot prompts and responses, and can take automatic actions like blocking or warning the user. These policies integrate with the Microsoft Purview console and apply contextual constraints based on the data being processed, making them a content-aware control that mitigates exposure at the point of interaction. Unlike identity or classification-only controls, DLP actively prevents exfiltration by interrupting the prompt/response flow when a violation is matched.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies for Copilot for Security are the primary control to prevent sensitive data exposure because they can inspect and block sensitive information (e.g., credit card numbers, health records) in real-time during Copilot interactions. DLP policies integrate directly with Copilot to enforce data protection rules on both prompts and responses, ensuring that sensitive data is not leaked through the AI model. This is the most direct and effective control for preventing data exposure in AI interactions.

Exam trap

The trap here is that candidates often confuse data classification (sensitivity labels) with data loss prevention (DLP), assuming that labeling data is sufficient to prevent exposure, but DLP is the active enforcement mechanism required for real-time AI interactions.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Conditional Access policies control access to resources based on conditions like location or device compliance, but they do not inspect or block sensitive data within Copilot interactions. Option B is wrong because Microsoft Entra Privileged Identity Management (PIM) manages just-in-time privileged role assignments and does not have any capability to scan or prevent data leakage in AI conversations. Option C is wrong because Microsoft Purview Information Protection sensitivity labels classify and protect data at rest (e.g., documents, emails) but do not enforce real-time data loss prevention rules during active Copilot sessions.

129
MCQmedium

You are designing a security solution for a hybrid identity environment that uses Microsoft Entra ID and on-premises Active Directory. The company wants to enforce Zero Trust principles by continuously verifying user access. Which feature should you implement?

A.Implement Microsoft Entra Hybrid Join for all devices
B.Implement Conditional Access policies that evaluate session risk in real time using continuous access evaluation
C.Implement Microsoft Entra Seamless Single Sign-On
D.Implement Microsoft Entra ID Protection to require multi-factor authentication for all users
AnswerB

Continuous Access Evaluation (CAE) is the correct mechanism because it forces Microsoft Entra ID to re-evaluate Conditional Access policies when critical events occur, such as user account disablement, password reset, or session revocation, rather than waiting for token expiration. It uses a multi-party token that carries a time-limited claim, and resource providers listen for cancellation signals, allowing access to be cut off within minutes. This is true continuous verification because both the token lifetime is shortened and the risk or compliance state is rechecked proactively.

Why this answer

Continuous access evaluation (CAE) is the correct feature because it enforces Zero Trust by evaluating access decisions in real time when critical events occur (e.g., user risk changes, device compliance loss, or token revocation), rather than relying on token lifetime. This ensures that session risk is continuously verified, aligning with the Zero Trust principle of 'never trust, always verify'.

Exam trap

The trap here is that candidates often confuse 'Conditional Access policies' (which are static, policy-based controls evaluated at sign-in) with 'continuous access evaluation' (which dynamically re-evaluates access during an active session), leading them to choose a generic MFA or device join option instead of the real-time evaluation feature.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra Hybrid Join only registers devices in both on-premises AD and Entra ID, enabling device-based Conditional Access, but it does not provide continuous real-time session risk evaluation. Option C is wrong because Seamless SSO only eliminates password prompts for users on domain-joined devices; it does not enforce continuous verification or evaluate session risk. Option D is wrong because requiring MFA for all users via Identity Protection is a static, policy-based control that does not continuously re-evaluate access during an active session based on real-time risk changes.

130
MCQeasy

A company is designing a Zero Trust architecture for their hybrid identity environment. They plan to require multifactor authentication (MFA) for all users accessing sensitive applications. Which Microsoft Entra ID capability should they use to enforce MFA based on risk level?

A.Self-service password reset
B.Microsoft Entra Privileged Identity Management
C.Conditional Access
D.Microsoft Entra ID Protection
AnswerC

Conditional Access is the correct enforcement point because it lets you build policies that require MFA based on any combination of signals—user, group, device compliance, location, application, or session risk—from the Entra Identity Protection feed and other sources. A policy such as 'Require MFA for all users' directly enforces a second factor on every authentication attempt, and can also apply step-up auth or session controls conditionally. This policy-driven control is the core of a zero trust architecture, ensuring authentication is continuously verified per access request.

Why this answer

Conditional Access is the correct choice because it is the Microsoft Entra ID policy engine that evaluates signals such as user, device, location, and sign-in risk, and can then require MFA for access to sensitive applications. In a Zero Trust hybrid identity design, Conditional Access policies are where you enforce MFA based on risk level, including integration with risk detections from Microsoft Entra ID Protection. Self-service password reset only lets users reset or unlock their own accounts and does not enforce MFA for application access.

Privileged Identity Management governs just-in-time role activation and approvals for privileged roles, not general MFA enforcement for sensitive apps. Microsoft Entra ID Protection detects and reports risk but does not itself enforce the MFA requirement; that enforcement is done through Conditional Access.

131
Multi-Selecthard

Which THREE components are included in Microsoft Defender XDR?

Select 3 answers
A.Microsoft Defender for Office 365
B.Microsoft Defender for IoT
C.Microsoft Defender for Identity
D.Microsoft Defender for Endpoint
E.Microsoft Defender for Cloud
AnswersA, C, D

Microsoft Defender for Office 365 is one of the core workload products natively integrated into Microsoft Defender XDR. It protects email and collaboration services such as Exchange Online, SharePoint, Teams, and OneDrive for Business by detecting phishing, malware, malicious links, and business email compromise. Its telemetry is shared with the XDR unified incident engine, enabling cross-domain correlation with endpoint and identity signals for automated investigation and response.

Why this answer

Microsoft Defender XDR is the unified extended detection and response suite that correlates signals across Microsoft's first-party security workloads, and its core components include Microsoft Defender for Office 365 (A), which protects email, collaboration tools, and Office apps against phishing, malware, and business email compromise; Microsoft Defender for Identity (C), which monitors on-premises Active Directory Domain Services signals via domain controllers to detect identity-based attacks like lateral movement and credential theft; and Microsoft Defender for Endpoint (D), which provides endpoint detection and response, threat and vulnerability management, and automated investigation on devices. These three feed alerts and incidents into the Defender XDR portal alongside Defender for Cloud Apps to enable cross-domain correlation. Microsoft Defender for IoT (B) is a separate offering for operational technology and IoT/OT environments, and Microsoft Defender for Cloud (E) is a cloud security posture management and workload protection solution (CSPM/CWPP) that, while integrated with the Defender portal, is not one of the three named Defender XDR components tested here.

Exam trap

The trap here is that candidates often assume all 'Defender' branded products are automatically part of Microsoft Defender XDR, but Microsoft Defender for IoT and Microsoft Defender for Cloud are separate services that integrate via connectors rather than being core components of the unified XDR suite.

132
Multi-Selecteasy

Which THREE are components of Microsoft's Zero Trust model?

Select 3 answers
A.Data
B.Assume breach
C.Microsoft Defender for Cloud
D.Identities
E.Endpoints
AnswersA, D, E

Data is the ultimate security target and is protected at rest, in transit, and in use through classification, encryption, and rights management. Zero Trust enforces granular access policies based on data sensitivity, with DLP and DRM ensuring protection even after access is granted. Without data protection, all other components become moot, making data one of the central pillars of the model.

Why this answer

Microsoft's Zero Trust model is built on three foundational principles—verify explicitly, use least privilege access, and assume breach—and it organizes its architecture around six core components: identities, devices (endpoints), applications, data, infrastructure, and networks. Option A (Data) is correct because data is one of those six pillars, protected through classification, labeling, and encryption so that access is granted based on sensitivity and policy. Option D (Identities) is correct because identities are the primary control plane in Zero Trust, verified with strong authentication (such as MFA and conditional access) before any resource is reached.

Option E (Endpoints) is correct because devices/endpoints are a core component, validated for health and compliance before being trusted to access corporate resources. Option B (Assume breach) is not a component but one of the three guiding principles of Zero Trust, and Option C (Microsoft Defender for Cloud) is a specific product/CNAPP offering rather than a structural component of the model.

Exam trap

The trap here is that candidates confuse the Zero Trust guiding principles (like 'Assume breach') with the architectural components (identities, endpoints, data, apps, infrastructure, network), leading them to select 'Assume breach' as a component rather than a principle.

133
MCQhard

You are a security architect for a large multinational organization that uses Microsoft 365, Azure, and third-party SaaS applications. The organization has recently experienced a breach where an attacker compromised a user account via a phishing email and then used that account to access sensitive data in SharePoint Online and exfiltrate it via email. The security team wants to implement a comprehensive solution that aligns with the Zero Trust principles of 'verify explicitly', 'use least privilege', and 'assume breach'. You need to design a solution that includes identity protection, conditional access, data protection, and continuous monitoring. You have the following requirements: 1. Block phishing attacks in real time. 2. Enforce least privilege access to sensitive data. 3. Detect and respond to anomalous user behavior. 4. Protect data at rest and in transit. 5. Enable automated response to incidents. Which combination of Microsoft security services and configurations should you recommend?

A.Implement Microsoft Defender for Cloud Apps to discover and control SaaS apps. Use Conditional Access with app control. Deploy Microsoft Purview Data Lifecycle Management. Use Azure Sentinel for monitoring.
B.Implement Microsoft Entra ID Protection to detect and block risky sign-ins. Use Conditional Access policies to require MFA and block legacy authentication. Use Microsoft Purview sensitivity labels to classify data and Azure Monitor to collect logs.
C.Implement Microsoft Defender for Office 365 to block phishing emails. Use Conditional Access policies with session risk to enforce access controls. Deploy Microsoft Purview DLP and sensitivity labels to protect data. Use Microsoft Sentinel with automation rules and playbooks to detect and respond to incidents.
D.Implement Microsoft Defender for Identity to detect on-premises threats. Use Conditional Access with device compliance policies. Deploy Microsoft Purview Information Protection. Use Azure Security Center for monitoring.
AnswerC

Defender for Office 365 blocks phishing emails at the mail gateway using threat intelligence and safe attachments/links. Conditional Access with session risk enforces least-privilege access based on real-time risk, while Purview DLP and sensitivity labels protect data across workloads. Sentinel integrates these signals and uses automation rules and playbooks for rapid, automated incident response, fulfilling all stated requirements. This layered approach covers email security, identity, data protection, and security operations.

Why this answer

Option C is correct because it directly maps to all five requirements: Defender for Office 365 provides real-time anti-phishing protection, Conditional Access with session risk enforces least-privilege and adaptive access, Microsoft Purview DLP and sensitivity labels protect data at rest and in transit, and Microsoft Sentinel with automation rules and playbooks delivers continuous monitoring plus automated incident response. This combination also aligns with Zero Trust by verifying explicitly through risk-based Conditional Access, applying least privilege via DLP and labels, and assuming breach through Sentinel detection and automated response. Option A lacks identity risk detection and phishing blocking, and Azure Sentinel alone does not provide the required automated response without playbooks.

Option B omits phishing protection and automated response, and Azure Monitor is not a SIEM/SOAR platform for incident automation. Option D focuses on on-premises identity threats, which does not address the cloud-based phishing and SaaS exfiltration scenario, and Azure Security Center is not the right tool for Microsoft 365 data protection and automated response.

134
MCQeasy

A security architect is designing a solution to detect and respond to advanced threats across email, endpoints, and identities. Which Microsoft security solution should they use?

A.Microsoft Purview
B.Microsoft Sentinel
C.Microsoft Defender XDR
D.Microsoft Intune
AnswerC

Microsoft Defender XDR is the correct choice because it is a true XDR solution that unifies detection, investigation, and response across endpoints, email, identities, applications, and data. It natively collects signals from Microsoft Defender for Endpoint, Office 365, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps, and combines them into a single incident view with automated self-healing actions. This enables security teams to detect and respond to sophisticated multi-stage attacks across the entire attack surface, which is exactly the goal of an XDR architecture.

Why this answer

Microsoft Defender XDR (Extended Detection and Response) is the correct solution because it provides unified pre- and post-breach detection, investigation, and response across email, endpoints, and identities. It correlates signals from Microsoft Defender for Endpoint, Defender for Office 365, and Defender for Identity into a single incident queue, enabling automated remediation of advanced multi-vector attacks.

Exam trap

The trap here is that candidates confuse Microsoft Sentinel (a SIEM) with Microsoft Defender XDR (an XDR), but Sentinel is a log aggregation and analysis tool requiring manual correlation, while Defender XDR provides native, automated cross-domain detection and response across email, endpoints, and identities.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview is a data governance, compliance, and risk management solution (e.g., data loss prevention, eDiscovery, insider risk), not a threat detection and response platform. Option B is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR that ingests logs from multiple sources for broad security analytics, but it is not purpose-built for unified cross-domain detection and automated response across email, endpoints, and identities; it requires custom correlation rules and playbooks. Option D is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) service for endpoint configuration and compliance, not a threat detection or response tool.

135
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that only devices with a specific minimum OS version can access corporate resources. Which configuration should you use?

A.Device compliance policy with minimum OS version rule
B.Device configuration profile
C.Enrollment restrictions
D.App protection policy
AnswerA

A device compliance policy with a minimum OS version rule is correct because Intune evaluates the installed OS version against this rule during each compliance check. If the device falls below the threshold, it is marked non-compliant, which can trigger conditional access blocks or end-user remediation prompts. This rule directly enforces that devices remain on a supported OS version as a condition of accessing organizational resources.

Why this answer

A device compliance policy with a minimum OS version rule is the correct choice because Intune compliance policies evaluate device attributes—including OS version—against defined rules before granting access to corporate resources. When a device fails the minimum OS version check, Conditional Access blocks access until the device is updated or remediated, ensuring only compliant devices can connect.

Exam trap

The trap here is confusing enrollment restrictions (which only check OS version at the point of enrollment) with compliance policies (which enforce OS version continuously after enrollment), leading candidates to pick enrollment restrictions as a one-time gate rather than an ongoing control.

How to eliminate wrong answers

Option B is wrong because a device configuration profile manages settings and features on the device (e.g., Wi-Fi, VPN, restrictions) but does not enforce access control based on OS version; it lacks the conditional access integration needed to block non-compliant devices. Option C is wrong because enrollment restrictions control which devices can enroll in Intune (e.g., by platform, manufacturer, or OS version at enrollment time), but they do not enforce ongoing compliance after enrollment—a device could be enrolled with a compliant OS and later be downgraded or fail to update. Option D is wrong because an app protection policy (APP) manages data protection within applications (e.g., preventing copy/paste or requiring PIN) and does not evaluate device-level OS version; APP applies to apps on both managed and unmanaged devices, not to device compliance for resource access.

136
MCQeasy

You are a security architect at Tailwind Traders. The company uses Microsoft 365 E5 and has a hybrid identity environment with Microsoft Entra Connect. The CIO wants to reduce the risk of credential theft and phishing attacks for all employees. You need to recommend an authentication method that eliminates passwords for users and aligns with Zero Trust principles. What should you recommend?

A.Certificate-based authentication
B.Microsoft Authenticator with phone sign-in
C.Windows Hello for Business
D.Security questions as a secondary authentication factor
AnswerB

Microsoft Authenticator with phone sign-in enables passwordless authentication for users by allowing them to sign in with their mobile device using biometrics or PIN. It works across applications and platforms, integrates with Microsoft Entra ID, and supports phishing-resistant methods, directly reducing credential theft risk and eliminating passwords.

Why this answer

Microsoft Authenticator with phone sign-in provides a passwordless authentication method that works across devices and applications. It uses biometrics or PIN on the mobile device, reducing the risk of phishing and credential theft. This aligns with Zero Trust principles by verifying explicitly and eliminating passwords.

Exam trap

The trap here is assuming that Windows Hello for Business is the universal passwordless solution, when it only works on Windows devices and does not cover all employee scenarios.

137
MCQeasy

A company is implementing Microsoft Purview to protect sensitive data in SharePoint Online. They need to automatically apply a 'Highly Confidential' label to documents that contain credit card numbers. What should they create?

A.A communication compliance policy
B.A data loss prevention (DLP) rule
C.A manual labeling policy
D.An auto-labeling policy for sensitivity labels
AnswerD

An auto-labeling policy for sensitivity labels in Microsoft Purview lets you define rules that automatically inspect documents and emails for sensitive content (e.g., sensitive info types, patterns, or trainable classifiers) and apply the appropriate sensitivity label without user intervention. These policies run in simulation mode initially to gauge accuracy, then can be enforced in production to assign the label, enforce encryption, and trigger subsequent DLP. This is the only option that directly and automatically classifies content at scale, meeting the stated goal.

Why this answer

Microsoft Purview auto-labeling policies for sensitivity labels can automatically detect sensitive data types (e.g., credit card numbers) in SharePoint Online documents and apply a 'Highly Confidential' label without user intervention. This meets the requirement for automatic, policy-driven labeling based on content inspection.

Exam trap

The trap here is that candidates confuse DLP rules (which detect and protect data) with auto-labeling policies (which apply sensitivity labels), but the question specifically asks for automatic label application, not just detection or blocking.

How to eliminate wrong answers

Option A is wrong because communication compliance policies are designed to detect and remediate inappropriate communications (e.g., harassment, insider trading) in Exchange Online and Teams, not to automatically label documents based on sensitive data patterns. Option B is wrong because a data loss prevention (DLP) rule can detect credit card numbers and block or alert, but it does not apply sensitivity labels; DLP rules and sensitivity labels are separate controls. Option C is wrong because manual labeling requires users to apply the label themselves, which contradicts the requirement for automatic application.

138
MCQhard

A company plans to use Microsoft Purview to manage data governance across their on-premises SQL Server databases and Azure SQL databases. They need to classify sensitive data and create a unified data map. Which resource should they deploy?

A.Microsoft Purview
B.Azure Synapse Analytics
C.Azure Data Factory
D.Azure SQL Database
AnswerA

Microsoft Purview is the correct choice because it is Microsoft's unified data governance and compliance platform, providing automated scanning, classification, and labeling of data assets across cloud and on-premises sources. It includes the Data Map, Data Catalog, and Data Estate Insights to give a central inventory, track lineage, and enforce sensitivity labels via Microsoft Information Protection, which aligns directly with the company's data governance requirement.

Why this answer

Microsoft Purview is the correct choice because it provides a unified data governance service that can scan both on-premises SQL Server and Azure SQL databases, automatically classify sensitive data using built-in classifiers (e.g., PII, financial info), and build a centralized data map. This aligns with the requirement to manage data governance across hybrid environments with a single pane of glass.

Exam trap

The trap here is that candidates often confuse Azure Data Factory's data movement capabilities with Purview's governance role, or mistakenly think Azure Synapse Analytics can perform classification because it includes data warehousing and some security features.

How to eliminate wrong answers

Option B (Azure Synapse Analytics) is wrong because it is an analytics service for large-scale data warehousing and big data processing, not a data governance or classification tool. Option C (Azure Data Factory) is wrong because it is a data integration and orchestration service for ETL/ELT pipelines, lacking native data classification and data map capabilities. Option D (Azure SQL Database) is wrong because it is a specific database platform, not a governance service; it cannot unify metadata or classify data across multiple sources like on-premises SQL Server.

139
Multi-Selecthard

You are designing a Microsoft Purview data security solution for a multinational organization subject to GDPR and CCPA. Which THREE Purview capabilities should you include to meet regulatory requirements?

Select 3 answers
A.Data Loss Prevention (DLP) policies
B.Advanced eDiscovery
C.Microsoft Purview Audit (Premium) and Activity Explorer
D.Data classification and sensitivity labels
E.Data Lifecycle Management (retention policies)
AnswersA, C, D

Prevents unauthorized sharing of personal data.

Why this answer

Data Loss Prevention (DLP) policies are correct because they allow the organization to detect and prevent the accidental or intentional sharing of sensitive data—such as personally identifiable information (PII) covered under GDPR and CCPA—across email, SharePoint, OneDrive, and endpoints. By scanning content for sensitive information types (e.g., credit card numbers, EU passport numbers) and applying protective actions (e.g., blocking transmission, showing policy tips), DLP directly enforces data protection mandates required by these regulations.

Exam trap

The trap here is that candidates often confuse 'detective' controls (like eDiscovery) with 'preventive' controls (like DLP and sensitivity labels), or they mistakenly think retention policies alone satisfy data security requirements, when in fact GDPR and CCPA demand active protection against data breaches and unauthorized disclosure.

140
MCQeasy

Your organization wants to implement a security information and event management (SIEM) solution that can ingest logs from multiple sources, including on-premises servers, Azure resources, and third-party SaaS applications. Which Microsoft service should you choose?

A.Microsoft Purview
B.Microsoft Defender for Cloud
C.Microsoft Sentinel
D.Azure Monitor
AnswerC

Microsoft Sentinel is the correct answer because it is a scalable, cloud-native SIEM and SOAR service that ingests logs from a wide range of sources, including Microsoft 365, Azure, third-party apps, and on-premises systems. It uses Kusto Query Language (KQL) for advanced hunting and custom analytics, and it provides built-in connectors for many security products. Sentinel centralizes security data, triggers alerts based on correlation rules, and supports automated response playbooks for end-to-end incident management.

Why this answer

Microsoft Sentinel is the correct choice because it is a cloud-native SIEM solution specifically designed to ingest logs from diverse sources, including on-premises servers, Azure resources, and third-party SaaS applications, using built-in connectors for over 100 data sources. It provides centralized security analytics, threat detection, and incident response, making it the appropriate service for this multi-source log ingestion requirement.

Exam trap

The trap here is that candidates often confuse Azure Monitor with a SIEM because it collects logs and metrics, but it lacks the security-specific correlation, threat intelligence integration, and incident management features that define a true SIEM like Microsoft Sentinel.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview is a data governance and compliance solution focused on data classification, labeling, and risk management, not a SIEM for ingesting and analyzing security logs. Option B is wrong because Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform that provides security recommendations and alerts for Azure and hybrid resources, but it lacks the comprehensive log ingestion and SIEM capabilities needed for multi-source log aggregation. Option D is wrong because Azure Monitor is a monitoring and diagnostics service for Azure resources and applications, primarily collecting metrics and logs for performance and operational health, not a SIEM solution designed for security event correlation and threat hunting across diverse sources.

141
Multi-Selecteasy

Which TWO of the following are best practices for securing Microsoft 365 tenants? (Choose two.)

Select 2 answers
A.Enable security defaults in Microsoft Entra ID
B.Use Conditional Access policies to enforce MFA
C.Enable basic authentication for all apps
D.Disable modern authentication for legacy protocols
E.Allow all external sharing in SharePoint
AnswersA, B

Security defaults in Microsoft Entra ID are a preset group of identity security policies that automatically enforce MFA, require administrators to authenticate with MFA, and block legacy authentication. This is a best practice because it provides a robust baseline security posture out-of-the-box, drastically reducing account compromise risk without requiring per-user configuration or Premium licensing. For organizations that lack the licensing for Conditional Access, security defaults are the recommended way to ensure consistent enforcement of strong authentication across all users.

Why this answer

Enabling security defaults provides a baseline of security. Using Conditional Access policies allows granular access control. These are best practices.

Disabling modern authentication is counterproductive. Allowing all external sharing is risky. Using basic authentication is insecure.

So the correct two are A and B.

142
MCQeasy

A company wants to protect sensitive email data from being exfiltrated by malicious insiders. They need a solution that can detect and block anomalous outbound email traffic in real time. Which Microsoft solution should they use?

A.Microsoft Purview Information Protection
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Office 365
D.Microsoft Sentinel
AnswerC

Microsoft Defender for Office 365 is the correct choice because it is the email security service built into Exchange Online Protection and Microsoft 365. It inspects every inbound and outbound message in near real time with anti-phishing, anti-spam, anti-malware, Safe Links, and Safe Attachments, and can quarantine suspicious messages before they reach mailboxes. Its outbound spam and mail-flow rules also allow administrators to block or restrict internal users from sending messages containing sensitive content, directly preventing data exfiltration.

Why this answer

Microsoft Defender for Office 365 (MDO) is the correct solution because it provides real-time detection and blocking of anomalous outbound email traffic through its outbound spam filtering and anti-phishing policies. MDO uses machine learning models to analyze email sending patterns, such as sudden spikes in volume or unusual recipient domains, and can automatically quarantine or block suspicious outbound messages to prevent data exfiltration by malicious insiders.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps (a CASB for cloud app activity monitoring) with Defender for Office 365, which is specifically built to protect email traffic at the transport layer, including outbound anomaly detection.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview Information Protection focuses on classifying, labeling, and encrypting data at rest or in transit, but it does not provide real-time detection or blocking of anomalous outbound email traffic. Option B is wrong because Microsoft Defender for Cloud Apps is a CASB that monitors cloud app usage and can detect anomalous behavior, but it is not designed to inspect and block outbound email traffic in real time at the email transport layer. Option D is wrong because Microsoft Sentinel is a SIEM/SOAR solution that aggregates and analyzes security logs for threat detection and response, but it does not natively perform real-time email traffic inspection or blocking at the mail flow level.

← PreviousPage 2 of 2 · 142 questions total

Ready to test yourself?

Try a timed practice session using only Security Best Practices Priorities questions.