All practice questions
1198 questions
Your company is designing the subscription governance and access control model for a new Azure subscription. You need to grant a team of ten developers the ability to manage virtual machines in the subscription. The solution must adhere to the principles of least privilege, minimize administrative overhead, and ensure that administrative access is granted only when required. Which two configurations should you implement? (Select two.)
Select all that apply
An organization is designing a Microsoft Entra Conditional Access policy to require multi-factor authentication (MFA) for all administrative roles. The organization wants to ensure that administrators do not get locked out of the tenant in the event of a tenant-wide disruption or MFA service outage. Which of the following recommendations should you include in the identity security design?
Your organization has an Azure management group hierarchy consisting of a root management group and several child management groups. You are designing a governance strategy and need to implement a custom Azure RBAC role named 'Billing Reader Custom' for a specific child management group named 'Finance-MG'. The role must be assignable only within 'Finance-MG' and its descendants. You need to create this custom role and assign it to a Microsoft Entra security group named 'Finance Auditors' for a specific subscription under 'Finance-MG'. Which sequence of steps should you perform to create and assign the custom role?
Drag items to arrange them in the correct order
An international shipping company, Pacific Cargo Enterprises, is designing an identity and access management solution for its Microsoft Entra ID tenant. The tenant contains several custom administrative roles and standard built-in roles. The security architecture must meet the following requirements:
1. All users assigned to administrative roles must be prompted for multi-factor authentication (MFA) and must connect from a compliant device when accessing Azure management portals.
2. The risk of administrative lockout due to an emergency or a misconfigured Conditional Access policy must be mitigated.
3. Access to high-privilege roles, such as Global Administrator, must be limited to just-in-time (JIT) activation and subject to approval.
Which two configurations should you include in the design to satisfy these requirements? (Select two.)
Select all that apply
Your company is designing a Microsoft Entra Conditional Access policy to secure administrative access. The policy must require multi-factor authentication (MFA) for all users with privileged roles. You also need to ensure that administrators are not locked out of the tenant if a cloud-based MFA service outage occurs.
Which two configurations should you include in the design?
Select all that apply
An enterprise manages its Azure resources using a management group structure. Under the root management group, there is a parent management group named Corp-MG, which has two child management groups named Corp-Prod-MG and Corp-Dev-MG.
You are designing an Azure Policy governance solution to meet the following requirements:
1. All virtual machines deployed to Corp-Prod-MG must have the Azure Monitor Agent extension automatically installed.
2. All Azure Storage accounts deployed to Corp-Dev-MG must have public network access disabled. Any attempts to deploy a storage account with public network access enabled must be blocked, except for resources deployed within a specific resource group named Dev-Sandbox-RG.
You need to configure the policies to enforce these compliance requirements while minimizing administrative overhead.
Which two configuration actions should you include in the design? (Select TWO.)
Select all that apply
An enterprise wants to secure administrative access to their production Azure subscriptions. You are designing an identity governance solution for system administrators who require the Owner role. To comply with security best practices, the administrators must not have permanent Owner privileges, but must be able to request and activate the role for a maximum of 4 hours when performing changes. Which configuration should you design to meet this requirement?
A medical group is planning to migrate a local relational database to the cloud. The database contains several legacy features, including SQL Server Agent jobs and cross-database queries across two databases. You need to recommend a fully managed database solution that minimizes management overhead while supporting these features. Which Azure SQL deployment option should you select?
A financial services company is designing a monitoring and log routing architecture for its Azure environment, which spans the East US and North Europe regions. The architecture must meet the following requirements:
- Diagnostic logs from resources in both regions must be collected.
- To comply with local data residency regulations, logs generated in East US must remain within the United States, and logs generated in North Europe must remain within the European Union.
- A centralized security operations team requires real-time access to security-related logs from both regions using a third-party SIEM tool.
- Internal audit teams must have read-only access to log data originating from their respective regions only, without the ability to view logs from other regions.
- Management overhead and the number of Log Analytics workspaces must be minimized.
Which log routing and workspace configuration should you recommend?
Kestrel Dynamics has an on-premises Active Directory Domain Services (AD DS) forest. You are designing a hybrid identity solution that integrates the AD DS forest with a new Microsoft Entra ID tenant. The solution must meet the following requirements:
* Users must be able to sign in to cloud services using their on-premises credentials.
* Users must be able to authenticate to Microsoft Entra ID even if the on-premises network or AD DS domain controllers are completely offline.
* Users must be able to reset their passwords in the cloud, and the changes must immediately write back to the on-premises AD DS.
* Administrative overhead and infrastructure costs must be minimized.
Which two components should you include in the hybrid identity design? (Select two).
Select all that apply
A company plans to migrate a legacy on-premises database to Azure. The database relies on SQL Server Agent for scheduled maintenance tasks and uses SQL Server Common Language Runtime (CLR) integration. Which of the following Azure relational database solutions natively support both SQL Server Agent and CLR? (Select TWO).
Select all that apply
Your organization is designing an identity governance and privileged access strategy for a newly acquired Azure tenant that hosts critical financial workloads. You must implement administrative access for a cloud engineering team according to the following requirements:
- Members of the cloud engineering team must be able to request Subscription Owner permissions on demand for a maximum duration of 4 hours, subject to manager approval.
- Administrative permissions must be managed at a group level rather than assigned to individual user accounts to minimize management overhead and ensure scalable governance.
- Multi-Factor Authentication (MFA) must be enforced for all administrative sessions.
- An emergency access account (break-glass account) must be protected from accidental lockouts that could be caused by MFA service disruptions or configuration issues.
Which two configurations should you recommend to meet these requirements?
Select all that apply
A logistics company is designing the migration of an on-premises tracking application to Azure. The application database requires Common Language Runtime (CLR) integration, SQL Server Agent for scheduling internal tasks, and cross-database queries using three-part naming conventions. Additionally, the solution must survive the outage of a primary datacenter and minimize the administrative overhead of managing operating system updates and database backups. Which Azure SQL deployment option should you recommend?
Your company has a Microsoft Entra tenant. You are designing a privileged access solution for a group of helpdesk operators. The operators must be able to reset user passwords, but they should only have these administrative privileges when actively responding to support tickets, up to a maximum of 4 hours per session. Additionally, their identity must be verified using multi-factor authentication (MFA) each time they request these privileges.
Which two configurations should you recommend to meet these requirements? (Choose two.)
Select all that apply
An organization is planning to host a legacy vendor application in Azure. The application requires a relational database backend using SQL Server. The vendor documentation states that the application installer must run directly on the database server operating system to configure local registry keys and file path structures.
Which Azure SQL deployment option should you recommend to meet these requirements?
An organization is designing a security and access control strategy for its Microsoft Entra ID tenant to protect sensitive cloud resources and workloads. The security team has defined several key access requirements for their environment. Match each security requirement to the corresponding Microsoft Entra ID or Conditional Access feature that best satisfies it.
Click a left item, then click its matching right item
Items
Matches
Vortex Media is designing a governance and compliance strategy for its Azure environment. The resources are organized under a management group hierarchy. The company has the following key compliance requirements:
1. All virtual machines deployed in the production subscriptions must have the Azure Monitor agent installed and configured automatically during deployment.
2. In the development subscriptions, if a virtual machine is deployed without the Azure Monitor agent, it should be allowed to deploy but must be flagged as non-compliant for auditing purposes.
3. No resource groups in any subscription should be created without a 'CostCenter' tag. If the tag is missing, the deployment must be blocked. However, an exception must be made for the 'Sandbox-Subscriptions' management group, where tags are not enforced.
You need to recommend the Azure Policy design to meet these requirements with minimal administrative overhead. Which of the following recommendations should you include in the design? (Select TWO options.)
Select all that apply
A multinational healthcare organization requires external vendor consultants to manage specific Azure resource groups containing protected health information (PHI) across multiple subscriptions. You are designing a privileged access solution that meets the following security requirements:
- Vendor consultants must only receive administrative permissions on-demand.
- Permission activation must require multi-factor authentication (MFA) and manager approval.
- The solution must minimize administrative overhead and scale as vendor personnel change.
- A strict tenant-wide Conditional Access policy must enforce MFA for all administrative roles, while ensuring that the organization's emergency access accounts are never locked out under any circumstance.
Which design strategy should you recommend to meet these requirements?
A financial services firm plans to migrate its core transactional and reporting database system to Microsoft Azure. The system consists of three databases that regularly perform cross-database transactions and query each other using standard three-part naming conventions. The application requires SQL Server Agent for automated scheduling, database mail services, and must be deployed with private IP addresses within a dedicated Azure Virtual Network. The firm has a primary operational driver to minimize the administrative overhead of managing the underlying operating system and database clustering for high availability. Which database solution should you recommend to meet these requirements?
Apex Pharma has a multi-subscription Azure environment. The security team has the following compliance requirements for all resources in a production subscription:
1. Automatically apply a tag named 'SecurityReview' with the value 'Approved' to all newly created resource groups, without blocking the deployment if the tag is missing in the request.
2. Block the deployment of virtual machines that do not use Premium SSD storage, except for those deployed within a specific development resource group.
You need to design an Azure Policy solution to meet the requirements with the least administrative effort.
Which two of the following actions should you perform? (Select two)
Select all that apply