Secure identity and accessSecure networkingSecure compute, storage, and databasesSecure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You have an Azure subscription containing the virtual networks shown in the following table.
The subscription includes the virtual machines shown in the following table.
All virtual machines have private IP addresses only.
You deploy Azure Bastion to VNet1 as shown in the following exhibit.
For each statement below, select Yes if it is true. Otherwise, select No.
Yes or No
Yes
No
Statements
You can connect to VM1 through Bastion1 by using the Remote Desktop Connection client.
You can connect to VM2 through Bastion1 by using SSH.
You can connect to VM3 through Bastion1 by using the Azure portal.
You have a Microsoft Entra tenant named contoso.com.
You plan to collaborate with a partner organization that has a Microsoft Entra tenant named fabrikam.com.
Fabrikam.com uses these identity providers:
Google Cloud Platform (GCP)
Microsoft accounts
Microsoft Entra ID
You need to configure the Cross-tenant access settings for B2B collaboration.
Which identity providers support cross-tenant access?
AMicrosoft Entra ID only
BGCP and Microsoft Entra ID only
CMicrosoft accounts and Microsoft Entra ID only
DGCP, Microsoft accounts, and Microsoft Entra ID
After creating a new Azure subscription, you are tasked with ensuring that custom alert rules can be created in Azure Security Center.
You have created an Azure Storage account.
Which action should you take?
AYou should make sure that Azure Active Directory (Azure AD) Identity Protection is removed.
BYou should create a DLP policy.
CYou should create an Azure Log Analytics workspace.
DYou should make sure that Security Center has the necessary tier configured.
Your company uses an Azure Container Registry.
You must assign a user a role that permits uploading images to the Azure Container Registry. The assigned role must provide no more privileges than necessary.
Which of the following roles should you assign?
AOwner
BContributor
CAcrPush
DAcrPull
QuestionQ7
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ8
Secure networking
QuestionQ9
Secure compute, storage, and databases
QuestionQ10
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
QuestionQ11
Secure networking
QuestionQ12
Secure identity and access
QuestionQ13
Secure networking
QuestionQ14
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
QuestionQ15
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
QuestionQ16
Secure networking
QuestionQ17
Secure identity and access
QuestionQ18
Secure identity and access
QuestionQ19
Secure identity and access
QuestionQ20
Secure compute, storage, and databases
QuestionQ21
Secure compute, storage, and databases
QuestionQ22
Secure identity and access
QuestionQ23
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
QuestionQ25
Secure identity and access
QuestionQ27
Secure networking
QuestionQ28
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
HOTSPOT -
You have an Azure subscription containing the alerts shown in the following exhibit.
Use the drop-down menus to choose the answer that completes each statement based on the information in the graphic.
Select
The state of Alert1 that was fired at 11:23:52
The state of Alert2 that was fired at 11:23:24
HOTSPOT -
You have an Azure subscription named Sub1.
You create a virtual network containing one subnet. You provision the virtual machines on that subnet as shown in the following table.
No network security groups (NSGs) have been provisioned yet. You need to implement network security that meets these requirements:
Allow traffic to VM4 only from VM3.
Allow Internet traffic only to VM1 and VM2.
Minimize the number of NSGs and network security rules.
How many NSGs and network security rules should you create?
Select
NSGs:
Network security rules:
You have an Azure subscription containing an Azure SQL database named SQLDB1. SQLDB1 includes the columns shown in the following table.
For the Email and Birthday columns, dynamic data masking is implemented by using the default masking function. Which value will users see in each column?
Each value may be used once, more than once, or not at all.
Drag & Drop
1900-01-01
1900-01-01 00:00:00.0000
2010-XX-XX
XXXX
aXXXX@XXXX.com
XXXX@XXXX.com
XXXX@XXXX.XXX
Email:
Birthday:
You have an Azure environment.
You need to identify Azure configurations and workloads that do not comply with ISO 27001:2013 standards.
What should you use?
AAzure Sentinel
BAzure Active Directory (Azure AD) Identity Protection
CMicrosoft Defender for Cloud
DMicrosoft Defender for Identity
You have an Azure subscription containing an Azure web app named App1 and a virtual machine named VM1. VM1 runs Microsoft SQL Server and connects to a virtual network named VNet1. App1, VM1, and VNet1 are located in the US Central Azure region.
You need to make sure that App1 can connect to VM1. The solution must minimize costs.
What should you include in the solution?
Aregional virtual network integration
Bgateway-required virtual network integration
CAzure Front Door
DAzure Application Gateway integration
ENAT gateway integration
You have an Azure subscription.
You plan to deploy a new Conditional Access policy named CAPolicy1.
You need to use the What If tool to evaluate how CAPolicy1 will affect users. The solution must minimize CAPolicy1's impact on users.
What should you set the Enable policy setting for CAPolicy1 to?
AOff
BOn
CReport only
You have an Azure subscription.
You create an Azure web app named Contoso1812 that uses an S1 App Service plan.
You plan to:
Create a CNAME DNS record for www.contoso.com that points to Contoso1812.
You need to ensure that users can access Contoso1812 by using the https://www.contoso.com URL.
Which two actions should you take? Each correct answer provides part of the solution.
NOTE: Each correct selection is worth one point.
Choose two
ATurn on the system-assigned managed identity for Contoso1812.
BAdd a hostname to Contoso1812.
CScale out the App Service plan of Contoso1812.
DAdd a deployment slot to Contoso1812.
EScale up the App Service plan of Contoso1812.
FUpload a PFX file to Contoso1812.
You have 15 Azure virtual machines in a resource group called RG1.
All of the virtual machines run the same applications.
You need to stop unauthorized applications and malware from running on the virtual machines.
What should you do?
AApply an Azure policy to RG1.
BFrom Azure Security Center, configure adaptive application controls.
CConfigure Azure Active Directory (Azure AD) Identity Protection.
DApply a resource lock to RG1.
You have an Azure Container Registry named Registry1.
From Azure Security Center, you enable Azure Container Registry vulnerability scanning for the images in Registry1.
You perform the following actions:
Push a Windows image named Image1 to Registry1.
Push a Linux image named Image2 to Registry1.
Push a Windows image named Image3 to Registry1.
Modify Image1 and push the new image as Image4 to Registry1.
Modify Image2 and push the new image as Image5 to Registry1.
Which two images will be scanned for vulnerabilities? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
Choose two
AImage4
BImage2
CImage1
DImage3
EImage5
HOTSPOT -
You have an Azure subscription containing the virtual machines listed in the following table.
Subnet1 and Subnet2 are configured with a Microsoft.Storage service endpoint.
You have an Azure Storage account named storageacc1, configured as shown in the following exhibit.
For each of the following statements, select Yes if it is true. Otherwise, select No.
Yes or No
Yes
No
Statements
From VM1, you can upload a blob to storageacc1.
From VM2, you can upload a blob to storageacc1.
From VM3, you can upload a blob to storageacc1.
You must evaluate the underlined segment to determine whether it is correct.
You have been assigned to create a separate subscription for every division in your company. However, all subscriptions will be associated with one Azure Active Directory (Azure AD) tenant.
You need to ensure that every subscription has the same role assignments.
You use Azure AD Privileged Identity Management (PIM).
Select No adjustment required if the underlined segment is correct. If it is incorrect, select the correct option.
ANo adjustment required
BAzure Blueprints
CConditional access policies
DAzure DevOps
You have the Azure resource hierarchy shown in the following exhibit.
RG1, RG2, and RG3 are resource groups. RG2 contains a virtual machine named VM2. You assign Azure role-based access control (RBAC) roles to the users shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Yes or No
Yes
No
Statements
User1 can deploy virtual machines to RG1.
User2 can delete VM2.
User3 can reset the password of the built-in Administrator account of VM2.
You have five Azure subscriptions linked to one Azure Active Directory (Azure AD) tenant.
You create an Azure Policy initiative named SecurityPolicyInitiative1.
You determine the standard role assignments that must be configured on all new resource groups.
You need to enforce SecurityPolicyInitiative1 and the role assignments whenever a new resource group is created.
Which three actions should you perform, in sequence?
Drag & Drop
Publish an Azure Blueprints version
Assign an Azure blueprint.
Create a policy assignment.
Create a custom role-based access control (RBAC) role
Create a dedicated management subscription.
Create an Azure Blueprints definition.
Create an initiative assignment.
You have an Azure subscription that contains the Azure App Service web apps displayed in the following table.
You upload a private-key certificate named Cert1.pfx to App1.
Which apps can use Cert1?
AApp1 only
BApp1 and App2 only
CApp1 and App4 only
DApp1, App2, and App3 only
EApp1, App2, App3, and App4
You have an Azure SQL database and implement Always Encrypted.
You need to ensure that application developers can retrieve and decrypt data in the database.
Which two pieces of information should you give the developers? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
Choose two
Aa stored access policy
Ba shared access signature (SAS)
Cthe column encryption key
Duser credentials
Ethe column master key
Your network has an on-premises Active Directory domain named adatum.com that synchronizes with a Microsoft Entra tenant.
The Microsoft Entra tenant includes the users in the following table.
You configure Microsoft Entra Password Protection for adatum.com as shown in the following exhibit.
For each statement, select Yes if it is true; otherwise, select No.
Yes or No
Yes
No
Statements
User1 will be prompted to change the password on the next sign-in.
User2 can change the password to @d@tum_C0mpleX123.
User3 can change the password to Adatum123!.
You are investigating a security issue with an Azure Storage account.
You enable Azure Storage Analytics logs and archive them to a storage account. What should you use to retrieve the diagnostic logs?
AAzure Cosmos DB explorer
BSQL query editor in Azure
CAzCopy
Dthe Security admin center
Your company has an Azure subscription named Sub1 that is associated with an Azure Active Directory (Azure AD) tenant named contoso.com.
The company develops a mobile application named App1. App1 uses the OAuth 2 implicit grant type to acquire Azure AD access tokens.
You need to register App1 in Azure AD.
Which information should you obtain from the developer to register the application?
Aa redirect URI
Ba reply URL
Ca key
Dan application ID
You have the Azure virtual machines shown in the following table.
Each virtual machine has one network interface.
You add VM1's network interface to an application security group named ASG1.
You need to identify the virtual machines whose network interfaces can be added to ASG1.
What should you identify?
AVM2 only
BVM2 and VM3 only
CVM2, VM3, VM4, and VM5
DVM2, VM3, and VM5 only
In Azure Security Center, you create a custom alert rule.
You need to configure the users who receive an email message when the alert is triggered.
What should you do?
AFrom Azure Monitor, create an action group.
BFrom Security Center, modify the Security policy settings of the Azure subscription.
CFrom Azure Active Directory (Azure AD), modify the members of the Security Reader role group.
Community Discussion