NEW
Font size
WorksheetsAZ-900 Practice Test 5
Total questions: 51
Worksheet time: 51mins
You have an Azure subscription named Subscription1. You sign in to the Azure portal and create a resource group named RG1. From Azure documentation, you have the following command that creates a virtual machine named VM1. “az vm create --resource-group RG1 --name VM1 --image UbuntuLTS --generate-ssh-keys”
You need to create VM1 in Subscription1 by using the command.
Solution: From the Azure portal, launch Azure Cloud Shell and select Bash. Run the command in Cloud Shell. Does this meet the goal?
Yes
No
Your company has several business units. Each business unit requires 20 different Azure resources for daily operation. All the business units require the same type of Azure resources. You need to recommend a solution to automate the creation of the Azure resources. What should you include in the recommendations?
Azure Resource Manager templates
virtual machine scale sets
the Azure API Management service
management groups
You need to configure an Azure solution that meets the following requirements:
· Secures websites from attacks
· Generates reports that contain details of attempted attacks
What should you include in the solution?
Azure Firewall
a network security group (NSG)
Azure Information Protection
DDoS protection
You plan to implement several security services for an Azure environment. You need to identify which Azure services must be used to meet the following security requirements:
· Monitor threats by using sensors
· Enforce Azure Multi-Factor Authentication (MFA) based on a condition
Which Azure service should you identify for each requirement?
Monitor threats by using sensors:
Azure Monitor
Azure Security Center
Azure Active Directory Identity Protection
Azure Advanced Threat Protection
You plan to implement several security services for an Azure environment. You need to identify which Azure services must be used to meet the following security requirements:
· Monitor threats by using sensors
· Enforce Azure Multi-Factor Authentication (MFA) based on a condition
Which Azure service should you identify for each requirement?
Enforce Azure Multi-Factor Authentication (MFA) based on a condition:
Azure Monitor
Azure Security Center
Azure Active Directory Identity Protection
Azure Advanced Threat Protection
Your Azure environment contains multiple Azure virtual machines. You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP. What are two possible solutions?
Modify an Azure Traffic Manager profile
Modify a network security group (NSG)
Modify a DDoS protection plan
Modify an Azure firewall
You can enable just in time (JIT) VM access by using:
Azure Bastion
Azure Firewall
Azure Front Door
Azure Security Center
You can associate a network security group (NSG) to a virtual network subnet.
Yes
No
You can associate a network security group (NSG) to a virtual network.
Yes
No
You can associate a network security group (NSG) to a network interface.
Yes
No
You have an Azure environment that contains 10 virtual networks and 100 virtual machines. You need to limit the amount of inbound traffic to all the Azure virtual networks. What should you create?
one application security group (ASG)
10 virtual network gateways
10 Azure ExpressRoute circuits
one Azure firewall
Azure Key Vault is used to store secrets for Azure Active Directory (Azure AD) user accounts. Does the underlined phrase need to be changed?
No change is needed
Azure Active Directory Administrative Accounts
Personally Identifiable Information (PII)
Server applications
Your company plans to automate the deployment of servers to Azure. Your manager is concerned that you may expose administrative credentials during the deployment. You need to recommend an Azure solution that encrypts the administrative credentials during the deployment. What should you include in the recommendation?
Azure Key Vault
Azure Information Protection
Azure Security Center
Azure Multi-Factor Authentication (MFA)
You plan to deploy several Azure virtual machines. You need to control the ports that devices on the Internet can use to access the virtual machines. What should you use?
a network security group (NSG)
an Azure Active Directory (Azure AD) role
an Azure Active Directory group
an Azure key vault
After you create a virtual machine, you need to modify the _____________ to allow connections to TCP port 8080 on the virtual machine.
Network security group (NSG)
Virtual network gateway
Virtual network
Route table
You can create custom Azure roles to control access to resources.
Yes
No
A user account can be assigned to multiple Azure roles.
Yes
No
A resource group can have the Owner role assigned to multiple users.
Yes
No
Your Azure environment contains multiple Azure virtual machines. You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP.
Solution: You modify a network security group (NSG). Does this meet the goal?
Yes
No
Your Azure environment contains multiple Azure virtual machines. You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP.
Solution: You modify a DDoS protection plan. Does this meet the goal?
Yes
No
You need to collect and automatically analyze security events from Azure Active Directory (Azure AD). What should you use?
Azure Sentinel
Azure Synapse Analytics
Azure AD Connect
Azure Key Vault
Your Azure environment contains multiple Azure virtual machines. You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP.
Solution: You modify an Azure firewall. Does this meet the goal?
Yes
No
Your Azure environment contains multiple Azure virtual machines. You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP.
Solution: You modify an Azure Traffic Manager profile. Does this meet the goal?
Yes
No
Your company plans to deploy several web servers and several database servers to Azure. You need to recommend an Azure solution to limit the types of connections from the web servers to the database servers. What should you include in the recommendation?
network security groups (NSGs)
Azure Service Bus
a local network gateway
a route filter
From ___________ you can view which user turned off specific virtual machine during the last 14 days.
Azure Access Control IAM
Azure Event Hubs
Azure Activity Log
Azure Service Health
Which service provides network traffic filtering across multiple Azure subscriptions and virtual networks?
Azure Firewall
an application security group
Azure DDoS protection
a network security group (NSG)
Which Azure service should you use to store certificates?
Azure Security Center
an Azure Storage account
Azure Key Vault
Azure Information Protection
Which Azure service can you use as a security information and event management (SIEM) solution?
Azure Analysis Services
Azure Sentinel
Azure Information Protection
Azure Cognitive Services
Azure Sentinel stores collected events in an Azure Storage account.
Yes
No
Azure Sentinel can remediate incidents automatically.
Yes
No
Azure Sentinel can collect Windows Defender Firewall logs from Azure virtual machines.
Yes
No
Match the Azure Services service to the correct descriptions.
“Analyze security log files from azure virtual machine”
Azure Active Directory
Azure Key Vault
Azure Lighthouse
Azure Security Center
Azure Sentinel
Match the Azure Services service to the correct descriptions.
“Display secure score for an Azure subscription”
Azure Active Directory
Azure Key Vault
Azure Lighthouse
Azure Security Center
Azure Sentinel
Match the Azure Services service to the correct descriptions.
“Store passwords for use by Azure Function applications”
Azure Active Directory
Azure Key Vault
Azure Lighthouse
Azure Security Center
Azure Sentinel
Azure Firewall will encrypt all the network traffic sent from Azure to the Internet.
Yes
No
A network security group (NSG) will encrypt all the network traffic sent from Azure to the Internet.
Yes
No
Azure virtual machines that run Windows Server 2016 can encrypt network traffic sent to the Internet.
Yes
No
Azure Security Center can monitor Azure resources and on-premises resources.
Yes
No
All Azure Security Center features are free.
Yes
No
From Azure Security Center, you can download a Regulatory Compliance report.
Yes
No
Your company implements __________ to automatically add a watermark to Microsoft Word documents that contain credit card information.
Azure policies
DDoS protection
Azure Information Protection
Azure Active Directory Identity Protection
You have an Azure virtual network named VNET1 in a resource group named RG1. You assign the Azure policy definition of Not Allowed Resource Type and specify that virtual networks are not an allowed resource type in RG1. VNET1 ________.
Is deleted automatically
Is moved automatically to another resource group
Continues to function normally
Is now a read-only object
Your company has an Azure subscription that contains resources in several regions. A company policy states that administrators must only be allowed to create additional Azure resources in a region in the country where their office is located. You need to create the Azure resource that must be used to meet the policy requirement. What should you create?
a read-only lock
an Azure policy
a management group
a reservation
From Azure Cloud Shell, you can track your company’s regulatory standards and regulations, such as ISO 27001. Does the underlined phrase need to be changed?
No change is needed.
the Microsoft Cloud Partner Portal
Compliance Manager
the Trust Center
You can create Group Polices in Azure Active Directory (Azure AD).
Yes
No
You can join Windows 10 devices to Azure Active Directory (Azure AD).
Yes
No
You can join Android devices to Azure Active Directory (Azure AD).
Yes
No
The ________________ explains what data Microsoft processes, how Microsoft processes the data, and the purpose of processing the data.
Microsoft Online Services Privacy Statement
Microsoft Product Terms
Microsoft Online Service Level Agreement
Online Subscription Agreement for Microsoft Azure
_____________ is the process of verifying a user's credentials.
Authorization
Authentication
Federation
Ticketing
An Azure Policy initiative definition is a ______________.
collection of policy definitions
collection of Azure Policy definition assignments
group of Azure Blueprints definitions
group of role-based access control (RBAC) role assignments
_______________ provide organizations with the ability to manager the compliance of Azure resources across multiple subscriptions.
Resource groups
Management groups
Azure policies
Azure app service plans
