wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

AZ-900 Practice Test 5

Total questions: 51

Worksheet time: 51mins

Name
Class
Date
1.

You have an Azure subscription named Subscription1. You sign in to the Azure portal and create a resource group named RG1. From Azure documentation, you have the following command that creates a virtual machine named VM1. “az vm create --resource-group RG1 --name VM1 --image UbuntuLTS --generate-ssh-keys”

You need to create VM1 in Subscription1 by using the command.

Solution: From the Azure portal, launch Azure Cloud Shell and select Bash. Run the command in Cloud Shell. Does this meet the goal?

a)

Yes

b)

No

2.

Your company has several business units. Each business unit requires 20 different Azure resources for daily operation. All the business units require the same type of Azure resources. You need to recommend a solution to automate the creation of the Azure resources. What should you include in the recommendations?

a)

Azure Resource Manager templates

b)

virtual machine scale sets

c)

the Azure API Management service

d)

management groups

3.

You need to configure an Azure solution that meets the following requirements:

· Secures websites from attacks

· Generates reports that contain details of attempted attacks

What should you include in the solution?

a)

Azure Firewall

b)

a network security group (NSG)

c)

Azure Information Protection

d)

DDoS protection

4.

You plan to implement several security services for an Azure environment. You need to identify which Azure services must be used to meet the following security requirements:

· Monitor threats by using sensors

· Enforce Azure Multi-Factor Authentication (MFA) based on a condition

Which Azure service should you identify for each requirement?

Monitor threats by using sensors:

a)

Azure Monitor

b)

Azure Security Center

c)

Azure Active Directory Identity Protection

d)

Azure Advanced Threat Protection

5.

You plan to implement several security services for an Azure environment. You need to identify which Azure services must be used to meet the following security requirements:

· Monitor threats by using sensors

· Enforce Azure Multi-Factor Authentication (MFA) based on a condition

Which Azure service should you identify for each requirement?

Enforce Azure Multi-Factor Authentication (MFA) based on a condition:

a)

Azure Monitor

b)

Azure Security Center

c)

Azure Active Directory Identity Protection

d)

Azure Advanced Threat Protection

6.

Your Azure environment contains multiple Azure virtual machines. You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP. What are two possible solutions?

a)

Modify an Azure Traffic Manager profile

b)

Modify a network security group (NSG)

c)

Modify a DDoS protection plan

d)

Modify an Azure firewall

7.

You can enable just in time (JIT) VM access by using:

a)

Azure Bastion

b)

Azure Firewall

c)

Azure Front Door

d)

Azure Security Center

8.

You can associate a network security group (NSG) to a virtual network subnet.

a)

Yes

b)

No

9.

You can associate a network security group (NSG) to a virtual network.

a)

Yes

b)

No

10.

You can associate a network security group (NSG) to a network interface.

a)

Yes

b)

No

11.

You have an Azure environment that contains 10 virtual networks and 100 virtual machines. You need to limit the amount of inbound traffic to all the Azure virtual networks. What should you create?

a)

one application security group (ASG)

b)

10 virtual network gateways

c)

10 Azure ExpressRoute circuits

d)

one Azure firewall

12.

Azure Key Vault is used to store secrets for Azure Active Directory (Azure AD) user accounts. Does the underlined phrase need to be changed?

a)

No change is needed

b)

Azure Active Directory Administrative Accounts

c)

Personally Identifiable Information (PII)

d)

Server applications

13.

Your company plans to automate the deployment of servers to Azure. Your manager is concerned that you may expose administrative credentials during the deployment. You need to recommend an Azure solution that encrypts the administrative credentials during the deployment. What should you include in the recommendation?

a)

Azure Key Vault

b)

Azure Information Protection

c)

Azure Security Center

d)

Azure Multi-Factor Authentication (MFA)

14.

You plan to deploy several Azure virtual machines. You need to control the ports that devices on the Internet can use to access the virtual machines. What should you use?

a)

a network security group (NSG)

b)

an Azure Active Directory (Azure AD) role

c)

an Azure Active Directory group

d)

an Azure key vault

15.

After you create a virtual machine, you need to modify the _____________ to allow connections to TCP port 8080 on the virtual machine.

a)

Network security group (NSG)

b)

Virtual network gateway

c)

Virtual network

d)

Route table

16.

You can create custom Azure roles to control access to resources.

a)

Yes

b)

No

17.

A user account can be assigned to multiple Azure roles.

a)

Yes

b)

No

18.

A resource group can have the Owner role assigned to multiple users.

a)

Yes

b)

No

19.

Your Azure environment contains multiple Azure virtual machines. You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP.

Solution: You modify a network security group (NSG). Does this meet the goal?

a)

Yes

b)

No

20.

Your Azure environment contains multiple Azure virtual machines. You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP.

Solution: You modify a DDoS protection plan. Does this meet the goal?

a)

Yes

b)

No

21.

You need to collect and automatically analyze security events from Azure Active Directory (Azure AD). What should you use?

a)

Azure Sentinel

b)

Azure Synapse Analytics

c)

Azure AD Connect

d)

Azure Key Vault

22.

Your Azure environment contains multiple Azure virtual machines. You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP.

Solution: You modify an Azure firewall. Does this meet the goal?

a)

Yes

b)

No

23.

Your Azure environment contains multiple Azure virtual machines. You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP.

Solution: You modify an Azure Traffic Manager profile. Does this meet the goal?

a)

Yes

b)

No

24.

Your company plans to deploy several web servers and several database servers to Azure. You need to recommend an Azure solution to limit the types of connections from the web servers to the database servers. What should you include in the recommendation?

a)

network security groups (NSGs)

b)

Azure Service Bus

c)

a local network gateway

d)

a route filter

25.

From ___________ you can view which user turned off specific virtual machine during the last 14 days.

a)

Azure Access Control IAM

b)

Azure Event Hubs

c)

Azure Activity Log

d)

Azure Service Health

26.

Which service provides network traffic filtering across multiple Azure subscriptions and virtual networks?

a)

Azure Firewall

b)

an application security group

c)

Azure DDoS protection

d)

a network security group (NSG)

27.

Which Azure service should you use to store certificates?

a)

Azure Security Center

b)

an Azure Storage account

c)

Azure Key Vault

d)

Azure Information Protection

28.

Which Azure service can you use as a security information and event management (SIEM) solution?

a)

Azure Analysis Services

b)

Azure Sentinel

c)

Azure Information Protection

d)

Azure Cognitive Services

29.

Azure Sentinel stores collected events in an Azure Storage account.

a)

Yes

b)

No

30.

Azure Sentinel can remediate incidents automatically.

a)

Yes

b)

No

31.

Azure Sentinel can collect Windows Defender Firewall logs from Azure virtual machines.

a)

Yes

b)

No

32.

Match the Azure Services service to the correct descriptions.


Analyze security log files from azure virtual machine

a)

Azure Active Directory

b)

Azure Key Vault

c)

Azure Lighthouse

d)

Azure Security Center

e)

Azure Sentinel

33.

Match the Azure Services service to the correct descriptions.


Display secure score for an Azure subscription

a)

Azure Active Directory

b)

Azure Key Vault

c)

Azure Lighthouse

d)

Azure Security Center

e)

Azure Sentinel

34.

Match the Azure Services service to the correct descriptions.


Store passwords for use by Azure Function applications

a)

Azure Active Directory

b)

Azure Key Vault

c)

Azure Lighthouse

d)

Azure Security Center

e)

Azure Sentinel

35.

Azure Firewall will encrypt all the network traffic sent from Azure to the Internet.

a)

Yes

b)

No

36.

A network security group (NSG) will encrypt all the network traffic sent from Azure to the Internet.

a)

Yes

b)

No

37.

Azure virtual machines that run Windows Server 2016 can encrypt network traffic sent to the Internet.

a)

Yes

b)

No

38.

Azure Security Center can monitor Azure resources and on-premises resources.

a)

Yes

b)

No

39.

All Azure Security Center features are free.

a)

Yes

b)

No

40.

From Azure Security Center, you can download a Regulatory Compliance report.

a)

Yes

b)

No

41.

Your company implements __________ to automatically add a watermark to Microsoft Word documents that contain credit card information.

a)

Azure policies

b)

DDoS protection

c)

Azure Information Protection

d)

Azure Active Directory Identity Protection

42.

You have an Azure virtual network named VNET1 in a resource group named RG1. You assign the Azure policy definition of Not Allowed Resource Type and specify that virtual networks are not an allowed resource type in RG1. VNET1 ________.

a)

Is deleted automatically

b)

Is moved automatically to another resource group

c)

Continues to function normally

d)

Is now a read-only object

43.

Your company has an Azure subscription that contains resources in several regions. A company policy states that administrators must only be allowed to create additional Azure resources in a region in the country where their office is located. You need to create the Azure resource that must be used to meet the policy requirement. What should you create?

a)

a read-only lock

b)

an Azure policy

c)

a management group

d)

a reservation

44.

From Azure Cloud Shell, you can track your company’s regulatory standards and regulations, such as ISO 27001. Does the underlined phrase need to be changed?

a)

No change is needed.

b)

the Microsoft Cloud Partner Portal

c)

Compliance Manager

d)

the Trust Center

45.

You can create Group Polices in Azure Active Directory (Azure AD).

a)

Yes

b)

No

46.

You can join Windows 10 devices to Azure Active Directory (Azure AD).

a)

Yes

b)

No

47.

You can join Android devices to Azure Active Directory (Azure AD).

a)

Yes

b)

No

48.

The ________________ explains what data Microsoft processes, how Microsoft processes the data, and the purpose of processing the data.

a)

Microsoft Online Services Privacy Statement

b)

Microsoft Product Terms

c)

Microsoft Online Service Level Agreement

d)

Online Subscription Agreement for Microsoft Azure

49.

_____________ is the process of verifying a user's credentials.

a)

Authorization

b)

Authentication

c)

Federation

d)

Ticketing

50.

An Azure Policy initiative definition is a ______________.

a)

collection of policy definitions

b)

collection of Azure Policy definition assignments

c)

group of Azure Blueprints definitions

d)

group of role-based access control (RBAC) role assignments

51.

_______________ provide organizations with the ability to manager the compliance of Azure resources across multiple subscriptions.

a)

Resource groups

b)

Management groups

c)

Azure policies

d)

Azure app service plans