QuestionQ15

Manage and monitor security posture

HOTSPOT -

Overview -

Contoso, Ltd. is a consulting company with its main office in San Francisco and a branch office in Dallas.

Contoso has a hybrid environment containing on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1.

Existing Environment. Microsoft Entra tenant

Contoso has a Microsoft Entra tenant named contoso.com that includes the users shown in the following table.

Question Image

Existing Environment. On-premises environment

The on-premises network has an Active Directory Domain Services (AD DS) forest that synchronizes with contoso.com. The forest includes Server1, which runs Windows Server.

Existing Environment. Azure subscription

Sub1 contains the storage accounts shown in the following table.

Question Image

Sub1 includes the virtual networks shown in the following table.

Question Image

Sub1 includes the virtual machines shown in the following table.

Question Image

VM1's network interface is associated with an application security group named ASG1.

Sub1 contains the resources shown in the following table.

Question Image

Vault1 stores the objects shown in the following table.

Question Image

Existing Environment. Privileged Identity Management (PIM) configuration

You manage privileged roles by using Privileged Identity Management (PIM). The PIM role settings are configured as shown in the following table.

Question Image

Existing Environment. Microsoft Sentinel configuration

Contoso has a Microsoft Sentinel workspace containing the following tables.

Question Image

Requirements. Planned changes -

Contoso plans to make the following changes:

  • Integrate AKS1 with Vault1.
  • Enable Microsoft Entra Kerberos authentication for all supported storage.
  • Configure auditing for sql1 by using the Azure portal and store audit logs in a centralized location.

Requirements. Technical requirements

Contoso identifies the following technical requirements:

  • Protect Server1 by using file integrity monitoring.
  • Protect AKS1 by using Microsoft Defender for Cloud.
  • Configure Microsoft Sentinel to retain data for the maximum supported duration without changing the tier.
  • Store objects used for authentication and encryption in Vault1 and make Vault1 regenerate the objects every 30 days whenever possible.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Yes or No
StatementsYesNo
Admin1 must approve requests for the Agent ID Developer role.
Admin2 can approve requests for the AI Administrator role.
Admin3 can assign User1 a two-day active assignment for the Agent ID Developer role.
Explanation

Agent ID Developer activation does not require approval, so no approval by Admin1 is needed. AI Administrator activation requires approval, but no approvers are configured, and holding that role does not grant approver status. A Privileged Role Administrator can manage role assignments; the two-day administrator-created active assignment is within the configured 15-day active-assignment expiration. The one-day maximum controls activation duration.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!