wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AZ-900T0x_Module 04: Security

Total questions: 7

Worksheet time: 5mins

Name
Class
Date
1.

How can Tailwind Traders enforce having only certain applications run on its VMs?

a)

Connect your VMs to Azure Sentinel.

b)

Create an application control rule in Azure Security Center.

c)

Periodically run a script that lists the running processes on each VM. The IT manager can then shut down any applications that shouldn't be running.

2.

What's the easiest way for Tailwind Traders to combine security data from all of its monitoring tools into a single report that it can take action on?

a)

Collect security data in Azure Sentinel.

b)

Build a custom tool that collects security data, and displays a report through a web application.

c)

Look through each security log daily and email a summary to your team.

3.

Which is the best way for Tailwind Traders to safely store its certificates so that they're accessible to cloud VMs?

a)

Place the certificates on a network share.

b)

Store them on a VM that's protected by a password.

c)

Store the certificates in Azure Key Vault.

4.

How can Tailwind Traders ensure that certain VM workloads are physically isolated from workloads being run by other Azure customers?

a)

Configure the network to ensure that VMs on the same physical host are isolated.

b)

Configure the network to ensure that VMs on the same physical host are isolated.

c)

Run the VMs on Azure Dedicated Host.

5.

An attacker can bring down your website by sending a large volume of network traffic to your servers. Which Azure service can help Tailwind Traders protect its App Service instance from this kind of attack?

a)

Azure Firewall

b)

Network security groups

c)

Azure DDoS Protection

6.

What's the best way for Tailwind Traders to limit all outbound traffic from VMs to known hosts?

a)

Configure Azure DDoS Protection to limit network access to trusted ports and hosts.

b)

Create application rules in Azure Firewall.

c)

Ensure that all running applications communicate with only trusted ports and hosts.

7.

How can Tailwind Traders most easily implement a deny by default policy so that VMs can't connect to each other?

a)

Allocate each VM on its own virtual network.

b)

Create a network security group rule that prevents access from another VM on the same network.

c)

Configure Azure DDoS Protection to limit network access within the virtual network.