Search Header Logo

ICC1 - Ada AZ-900 - Azure Fundamentals quiz 5

Authored by Steve Rich

Computers

University

Used 6+ times

ICC1 - Ada AZ-900 - Azure Fundamentals quiz 5
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

8 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which Microsoft Entra tool can vary the credentials needed to log in based on signals, such as where the user is located?

Conditional Access

Guest Access

Passwordless

Answer explanation

Conditional Access is a tool that Microsoft Entra ID uses to allow (or deny) access to resources based on identity signals. Conditional Access might challenge you for a second authentication factor if your sign-in signals are unusual or from an unexpected location.

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which security model assumes the worst-case security scenario, and protects resources accordingly?

Zero Trust

Defense-in-depth

Role-based access control

Answer explanation

Zero Trust is a security model that assumes the worst case scenario and protects resources with that expectation.

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

A user is simultaneously assigned multiple roles that use role-based access control. What are their actual permissions? The role permissions are: Role 1 - read || Role 2 - write || Role 3 - read and write.

Read only

Write only

Read and write

Answer explanation

Role-based access control, using an allow model, grants all of the permissions assigned in all of the assigned roles.

4.

MULTIPLE CHOICE QUESTION

2 mins • 1 pt

A company uses a cloud platform for its customer relationship management (CRM) system. The CRM stores sensitive customer data, and the company needs to ensure that only authorized employees can access this data and perform specific actions within the system.

Encryption

Authorisation

Auditing

Authentication

Answer explanation

Authorisation (Correct Answer): This determines what actions a user can perform within the system. Even after successful authentication, only authorized users with the appropriate permissions should be able to access specific customer data or perform actions like editing or deleting records.

Authentication verifies a user's identity through credentials like username and password. It ensures only valid users can log in to the CRM system.

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Your company is implementing Microsoft Entra for Single Sign-On (SSO) across its cloud applications. Different departments utilize various Microsoft 365 services and cloud-based productivity tools.

Entra eliminates the need for user passwords entirely

Entra allows users to manage all application passwords from a central location

Entra simplifies user access by authenticating users once for all authorized cloud applications.

Entra encrypts user data at rest within all connected cloud applications.

Answer explanation

This is the core benefit of SSO. Users authenticate once with Entra, and then access all authorized applications without further login prompts.

6.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of the following statements BEST defines Role-Based Access Control (RBAC)?

A security model that grants access permissions based on a user's location.

A system where users manage their own access controls to resources.

A method that assigns permissions to users based on their job functions and responsibilities.

A security approach that relies solely on strong user passwords for access control.

Answer explanation

RBAC groups users into roles with predefined permissions. Users inherit the access controls associated with their assigned roles. This simplifies administration and ensures access aligns with job duties.

7.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of the following statements BEST defines the concept of defense in depth in cybersecurity?

A security approach that relies on a single, very strong perimeter security measure.

Implementing multiple layers of security controls to mitigate various cyber threats.

Focusing security efforts solely on preventing unauthorized access to systems.

Regularly patching software vulnerabilities to address security risks.

Answer explanation

This concept advocates for layered security controls. If one layer is breached, others can help mitigate the attack. Firewalls, intrusion detection, data encryption, and access controls are all examples of defense in depth strategies.

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?