All practice questions
1198 questions
An enterprise is designing a monitoring and log routing architecture for a multi-region workload deployed in East US and West Europe. The architecture must meet the following requirements:
- Logs generated by resources in West Europe must remain resident within the European Union (EU) to comply with data sovereignty regulations.
- Access to logs must be restricted so that application developers can only view diagnostic data for the specific resources they own, without having access to other resources' logs stored in the same workspace.
- Diagnostic logs from Azure Key Vault and Azure SQL Database instances must be streamed in real-time to a third-party SIEM platform in each respective region.
- Administrative overhead for managing log access permissions must be minimized.
Which two components or configurations should you include in the design to meet these requirements? (Choose two.)
Select all that apply
An organization is designing a hybrid identity architecture to connect their on-premises Active Directory Domain Services (AD DS) environment to Microsoft Entra ID. How should you match each security or authentication requirement to the correct Microsoft Entra ID authentication or Conditional Access feature?
Click a left item, then click its matching right item
Items
Matches
Your organization has a new Azure subscription. You need to grant administrative access to five new cloud engineers. The solution must minimize administrative overhead and align with Azure governance best practices. How should you assign the required access?
A healthcare provider hosts a telehealth application with Azure resources deployed in both the East US and West Europe regions. To satisfy regulatory requirements, diagnostic logs from the West Europe resources must be stored strictly within the European Union, while logs from East US resources must reside within the United States. The access to these logs must be restricted to regional auditing teams, and administrative management overhead for the monitoring infrastructure must be minimized. Which log routing and workspace configuration should you recommend to meet these requirements?
A company is designing a new relational database solution in Azure. The database has the following requirements:
* Must support SQL Server Agent for scheduling internal database maintenance tasks.
* Must be deployed with a private IP address within an Azure Virtual Network (VNet).
Which two Azure SQL deployment options meet these requirements?
Select all that apply
An enterprise is designing a security and subscription governance strategy for its Azure environment. Which two of the following configurations align with Microsoft best practices for scalable access control and the principle of least privilege?
Select all that apply
An enterprise is designing a secure identity governance strategy for its cloud administration team. The strategy must satisfy the following requirements:
- Administrators must only hold highly privileged directory roles on a temporary, just-in-time (JIT) basis.
- When administrators activate and use these roles, they must be prompted for multi-factor authentication (MFA) and must connect from a compliant device.
- The design must guarantee that the organization does not lose administrative access to the Microsoft Entra tenant if a widespread multi-factor authentication outage or device compliance system failure occurs.
- On-premises infrastructure footprint and configuration complexity must be minimized.
Which design should you recommend?
You are designing a privileged access solution for a team of support staff who require temporary, time-bound access to administrative roles in Azure. You also need to configure a tenant-wide emergency access (break-glass) account. Which configuration should you recommend to ensure secure administrative access and prevent tenant lockout?
Apex Orion Logistics is designing a hybrid identity and multi-tenant access solution to integrate their on-premises Active Directory Domain Services (AD DS) forest, apex-orion.internal (containing 8,400 users), with a new Microsoft Entra ID tenant. The design must satisfy the following constraints:
- Authentication: Users must log in to cloud resources using their on-premises credentials. Under normal conditions, password validation must occur on-premises, and passwords or password hashes must not be stored in the cloud.
- Business Continuity: The authentication solution must support an automated standby mechanism that allows cloud logins to succeed even if the on-premises domain controllers or network connections become completely unavailable.
- Self-Service: Hybrid users must be able to reset their own passwords using self-service password reset (SSPR) in the cloud, and the changes must immediately update the on-premises AD DS.
- External Collaboration: Users from partner organizations who use their own Microsoft Entra ID tenants must be able to access internal resources securely, governed by granular inbound and outbound trust policies.
Match each business or technical requirement of the Apex Orion Logistics hybrid architecture to the most appropriate Microsoft Entra ID feature.
Click a left item, then click its matching right item
Items
Matches
Luminary Financials is designing a hybrid identity solution to integrate their on-premises Active Directory Domain Services (AD DS) forest, corp.luminaryfinancials.com, with a new Microsoft Entra ID tenant. The forest contains approximately 35,000 user accounts.
The solution must meet the following requirements:
- On-premises users must be able to authenticate to cloud resources.
- If the connection between the on-premises network and Azure is lost, users must still be able to authenticate to cloud resources.
- Users must be able to change their passwords in the cloud using self-service password reset (SSPR), and these changes must immediately synchronize back to the on-premises AD DS forest.
- Emergency access accounts must be protected against accidental lockout during tenant-wide Multi-Factor Authentication (MFA) enforcement.
Which two configuration actions should you include in the hybrid identity design? (Select two.)
Select all that apply
A company is planning to migrate a legacy on-premises electronic health record (EHR) application to Azure. The relational database for the application has the following requirements:
- Must support SQL Server Agent to run nightly maintenance jobs.
- Must support Database Mail to send automated notifications to administrators.
- Must be deployed into a private, delegated subnet within an Azure Virtual Network.
- In the event of a regional disaster, all database backups must remain available.
- The administrative overhead for managing operating system patching and hardware updates must be minimized.
Which Azure SQL deployment option should you recommend?
An organization is planning to migrate an on-premises payroll application to Azure. The application database relies on SQL Server Agent for scheduled data reconciliation and executes cross-database queries. The database must be deployed in a secure environment with native Azure Virtual Network (VNet) integration. To meet disaster recovery requirements, all backups must survive a regional outage, and the database administration team must minimize administrative effort for operating system and database engine patching. Which Azure SQL deployment option should you recommend?
A startup is deploying a new web application that requires a relational database to store user profiles. The database will run as a standalone database and has no requirements for instance-level features such as SQL Server Agent, cross-database queries, or Common Language Runtime (CLR). The startup requires a fully managed solution that minimizes administrative effort and overhead. Which Azure SQL deployment option should you recommend?
An organization is designing the relational database tier for a new multi-tenant software-as-a-service (SaaS) application in Azure. The design must meet the following requirements:
- Host 80 separate databases, one for each tenant, to ensure data isolation.
- Manage unpredictable workload spikes dynamically across all databases by sharing a single pool of compute resources.
- Run scheduled administrative queries and schema updates across all databases without managing virtual machines, operating systems, or configuring individual database connections.
- Minimize overall monthly costs.
Which two Azure SQL options or features should you recommend?
Select all that apply
Vortex Cloud Solutions has an on-premises Active Directory Domain Services (AD DS) forest named internal.vortexcloud.net with 5,800 users. You are designing a hybrid identity and security solution to integrate the on-premises forest with a new Microsoft Entra ID tenant.
The solution must satisfy the following requirements:
- Users must sign in to Microsoft Entra ID using their on-premises credentials.
- If the on-premises domain controllers or network connectivity is lost, users must still be able to authenticate to cloud services using their current passwords.
- Users must be allowed to reset their own passwords in Microsoft Entra ID, and these changes must be reflected immediately in the on-premises AD DS.
- To secure administrative access, a Conditional Access policy must enforce multi-factor authentication (MFA) for all global administrators, while mitigating the risk of tenant lockout during an MFA service outage.
- On-premises infrastructure requirements must be minimized.
Which solution should you recommend?
Your company has an Azure subscription containing multiple resource groups. You need to grant administrative permissions to three new IT support engineers to manage virtual machines within a specific resource group. The solution must minimize administrative overhead and follow Azure governance best practices.
Which of the following approaches should you implement?
An enterprise is designing a governance and identity strategy for its multi-subscription Azure environment. The environment is organized under a single management group hierarchy with separate production and non-production management groups.
The strategy must meet the following requirements:
- A security audit team must be able to view all resource configurations and compliance logs across all subscriptions.
- The database administration team requires permissions to manage Azure SQL databases across all subscriptions, but these permissions must only be active during approved maintenance windows.
- All administrative privileges must scale efficiently as employees join or leave the organization.
Which of the following configurations should you include in the design to meet these requirements while following the principle of least privilege? (Select TWO.)
Select all that apply
An enterprise is designing an Azure governance solution. The security team mandates that all Azure Key Vaults in the production subscriptions must have diagnostic settings configured to send logs to a central Log Analytics workspace. The solution must ensure that when developers create new Key Vaults, the diagnostic settings are automatically created if they are missing, without preventing the creation of the Key Vaults. Which Azure Policy effect should you recommend in the policy design to meet these requirements?
An organization is designing a hybrid identity, access, and governance solution for their Microsoft Entra ID tenant. The organization currently uses an on-premises Active Directory Domain Services (AD DS) directory and plans to synchronize identities to Entra ID. The solution must satisfy the following design requirements:
- Minimize the on-premises infrastructure footprint and runtime dependencies required for user authentication.
- Enable users to authenticate directly in the cloud.
- Enforce time-bound, just-in-time access for administrative roles using Microsoft Entra Privileged Identity Management (PIM).
- Enforce Multi-Factor Authentication (MFA) via Conditional Access for administrative roles while ensuring that the organization can always access the tenant in the event of a service outage or configuration error.
Which two of the following components should you include in the identity and access design? (Select TWO.)
Select all that apply
A financial services firm is designing its hybrid identity infrastructure using Microsoft Entra ID. The firm has an on-premises Active Directory Domain Services (AD DS) environment and requires a secure, resilient access management design. Which Microsoft Entra ID authentication methods and Conditional Access features should you select to meet each business and security requirement?
Click a left item, then click its matching right item
Items
Matches