All practice questions
1198 questions
A retail company's e-commerce platform consists of Azure App Service instances and Azure SQL databases. The compliance and operations teams establish the following requirements for diagnostic data:
- Database audit logs and Web Application Firewall (WAF) logs must be retained for seven years in a cost-optimized storage tier.
- The Security Operations Center (SOC) must receive real-time streams of all security events in an on-premises SIEM.
- Database administrators (DBAs) must be able to query database performance logs without viewing application transaction or security logs.
Which design should you recommend for log routing and access control?
An organization needs to enforce a governance requirement where all newly created virtual machines must be automatically registered with Azure Backup using a specific Recovery Services vault. If a virtual machine is deployed without backup configuration, Azure must automatically deploy the required backup extension and protection settings. Which Azure Policy effect should you use to design this solution?
A financial services company is designing the governance strategy for its Azure landing zone. The management group hierarchy has a root management group named Enterprise-MG, with two child management groups: Production-MG and Sandbox-MG. You need to implement a policy governance strategy that satisfies the following requirements:
1. All Azure Key Vaults deployed within Production-MG must automatically have diagnostic logging configured to send logs to a central Log Analytics workspace upon resource creation.
2. No virtual machines within Enterprise-MG are allowed to have public IP addresses, and any deployment attempt that includes a public IP must be blocked. However, this restriction must not apply to resources within a specific subscription under Sandbox-MG named Dev-Sandbox-Sub.
Which policy configuration should you design to meet these requirements with the minimum administrative overhead?
HealthFirst Solutions is implementing Microsoft Entra ID to secure their cloud resources. The security team wants to enforce multi-factor authentication (MFA) for all administrative logins. To prevent tenant-wide administrative lockout during a potential MFA service outage, the IT team must safeguard two newly created emergency access accounts.
Which policy configuration should you recommend?
An organization is designing a hybrid identity and security governance strategy for its Microsoft Entra ID tenant. The organization has 10,000 users across multiple on-premises offices. The architecture must meet the following requirements:
1. On-premises Active Directory Domain Services (AD DS) user passwords must never be stored in the cloud in any form, including reversible or irreversible hashes, to comply with local financial regulations.
2. Users must be prompted for multi-factor authentication (MFA) when accessing cloud resources, except when they are working from physical corporate offices.
3. Access to privileged administrative roles in Entra ID must follow a zero-trust model requiring justification and manager approval, and administrators must be protected against tenant lockout in the event of an MFA service outage.
Which identity and access management design should the organization recommend?
An organization is designing a monitoring solution for its Azure environment. Match each Azure Monitor data type or source to its primary description.
Click a left item, then click its matching right item
Items
Matches
Your company has an Azure environment with a management group hierarchy. You are designing a governance strategy to enforce the following compliance requirements:
1. All newly created or updated Azure Storage accounts must have 'Minimum TLS version' set to 'TLS 1.2'. If a storage account is deployed without this configuration, Azure must automatically configure it to TLS 1.2 during deployment.
2. Any attempt to deploy a Virtual Machine without a cost center tag named 'CostCenter' must be blocked.
You need to design the Azure Policy definitions to meet these requirements.
Which two policy effects should you recommend?
Select all that apply
A global financial technology enterprise is designing a logging and auditing architecture for a new payment processing platform. The platform is deployed across two Azure regions: France Central (primary) and Qatar Central (secondary).
The compliance department mandates the following strict constraints:
1. Administrative and operational log data from France Central must remain within the European Union (EU) borders to satisfy regional sovereignty laws, while logs from Qatar Central must be stored within the Middle East region.
2. Data security policies require that developers can only query logs for resources they are explicitly authorized to manage, without having read access to the underlying Log Analytics workspace settings or other workloads' logs.
3. Diagnostic logging configuration must be automatically enforced and deployed for all current and future Azure SQL databases and App Service instances within the target subscriptions.
4. The architectural design must minimize overall Log Analytics workspace operational overhead while satisfying all regulatory boundaries.
Which log routing and workspace configuration strategy should you recommend to meet these requirements?
You are designing a monitoring and log routing architecture for a large Azure enterprise environment. You need to route different types of Azure logs and metrics to the appropriate destinations to meet specific operational and compliance requirements.
Which destination should you match with each log source to meet the requirements?
Click a left item, then click its matching right item
Items
Matches
An organization is designing a governance strategy for Azure resources. You need to recommend Azure Policy configurations to meet the following requirements:
* Block the deployment of any virtual machine that does not use an approved SKU.
* Automatically deploy a diagnostics extension if a virtual machine is created without one.
Which two Azure Policy effects should you recommend?
Select all that apply
Your company, Litware Inc., plans to migrate workloads to Azure and must sync its on-premises Active Directory Domain Services (AD DS) to a Microsoft Entra ID tenant. The solution must meet the following requirements:
- Users must sign in to cloud services using their on-premises password.
- Authentication must remain operational even during a complete on-premises network outage.
- Users must be able to change their passwords in the cloud using self-service password reset (SSPR), and the changes must sync back to the on-premises AD DS environment.
- Administrative and infrastructure overhead must be minimized.
Which identity synchronization and authentication method should you recommend?
An enterprise is designing a governance strategy for its Azure environment. The resource hierarchy consists of a root management group with two child management groups: MG-Production and MG-Development. You must implement Azure Policies to enforce compliance according to the following requirements:
- All virtual machines deployed in MG-Production must have Azure Backup enabled automatically. If a VM is deployed without backup configured, Azure Backup must be configured automatically.
- To control costs, any attempt to deploy virtual machines outside of the Dv3-series in MG-Development must be blocked immediately.
- A specific resource group named rg-legacy within MG-Production hosts legacy workloads and must be exempted from the backup requirement.
- Existing and new SQL databases in MG-Production must be monitored for SQL auditing configuration, but deployments must not be blocked or auto-remediated.
You need to design the Azure Policy solution to meet these requirements with the least administrative overhead. Which two of the following policy assignments should you recommend? (Select TWO.)
Select all that apply
An organization has several virtual machines and web applications running in Azure. The security operations team requires all application transaction logs to be streamed to a third-party Security Information and Event Management (SIEM) system located on-premises in near real-time. Which destination should you configure in the Azure Monitor diagnostic settings to meet this requirement?
AeroLine Dynamics is designing an administrative access security solution for its Microsoft Entra ID tenant. The solution must enforce Multi-Factor Authentication (MFA) and require a compliant device for all global administrators who access the Azure portal. The design must also ensure that administrators can still access the tenant if the MFA service or the device compliance validation service experiences a global outage. Which of the following strategies should you include in the design?
An enterprise is designing a comprehensive monitoring and log routing architecture to support workloads across multiple Azure regions. Match each specific logging requirement to its correct Azure architectural design configuration.
Click a left item, then click its matching right item
Items
Matches
VeloSpire Logistics has an on-premises Active Directory Domain Services (AD DS) domain that syncs to a single Microsoft Entra ID tenant. You are designing a hybrid identity solution. The solution must meet the following requirements:
- Users must be able to authenticate to cloud resources using their on-premises credentials.
- If the on-premises network or domain controllers experience an outage, users must still be able to sign in to cloud services.
- Cloud-initiated password changes via self-service password reset (SSPR) must be written back to the on-premises AD DS environment.
- The on-premises infrastructure footprint and management overhead must be minimized.
Which hybrid identity synchronization and authentication method should you recommend?
A pharmaceutical company is designing a log routing and governance strategy for its Azure resources deployed across the East US and West Europe regions. The design must meet the following requirements:
- Diagnostic logs from Azure Key Vault instances must be automatically collected and routed immediately upon resource deployment.
- Key Vault logs must remain within their region of origin to comply with regional data sovereignty regulations.
- A global security team must be able to view logs from both regions, whereas regional IT administrators must only be able to view logs from their respective region.
- Permitted access must be assigned to groups rather than individual users to simplify identity management.
Which design should you recommend?
Aether Dynamics has an on-premises Active Directory Domain Services (AD DS) forest named corp.aetherdynamics.com and a Microsoft Entra ID tenant. You are designing a hybrid identity and secure access solution. The solution must meet the following requirements:
- Users must be able to sign in to cloud applications using their on-premises credentials, even if the on-premises datacenter suffers a complete network outage.
- Users must be able to reset their own passwords from the cloud portal, and the changes must update on-premises AD DS.
- On-premises infrastructure and administrative overhead must be kept to a minimum.
- Multi-factor authentication (MFA) must be enforced for all administrative roles, but the design must prevent administrator lockout in the event of a Microsoft Entra MFA service outage.
- Administrative roles must be managed using Privileged Identity Management (PIM) to ensure just-in-time (JIT) access.
Which hybrid identity and access configuration should you recommend?
A financial services firm is designing a secure identity infrastructure. The lead architect must map specific security compliance requirements to the correct Microsoft Entra ID and Conditional Access features. Match each requirement to the appropriate Microsoft Entra ID or Conditional Access feature.
Click a left item, then click its matching right item
Items
Matches
An enterprise has the following Azure management group and subscription hierarchy:
- Tenant Root Group
- Corp-Production (Management Group)
- Sub-App1 (Subscription for Production Application 1)
- Sub-App2 (Subscription for Production Application 2)
- Sub-HubNet (Subscription for Core Hybrid Networking Services)
You are designing a governance and identity strategy that must meet the following requirements:
1. A team of external security auditors must have read-only access to view configurations across Sub-App1, Sub-App2, and all future production application subscriptions.
2. The auditors must have absolutely no access to Sub-HubNet due to strict network security compliance.
3. Access management must minimize administrative overhead and ensure that new production application subscriptions automatically inherit the auditor permissions.
4. Any new production subscription must automatically deploy a standard diagnostic setting that streams activity logs to a central Log Analytics workspace.
Which governance and access control design should you recommend?