wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AZ-900 Module 5

Total questions: 28

Worksheet time: 15mins

Name
Class
Date
1.

Authentication is a ...

a)

Process of granting user access to the system

b)

Process of creation of new user identities

c)

Process of verification of user's permissions

d)

Process of verification of user's identity

e)

Process of verification that only authenticated identities

get access to get the resources for which they were

granted access to by the owners

2.

Which two core functionalities does Azure Active Directory deliver?

a)

Identity Management

b)

Access Management

c)

Resource Management

d)

Subscription Management

e)

Identitfication Services

3.

Security Principal objects (identities) can represent. Choose 4.

a)

User

b)

Group

c)

Role Assignment

d)

Service Principal

e)

Managed Identity

4.

Azure Active Directory _____ automatically signs in users when they are on their corporate devices connected to the corporate network.

a)

Seamless SSO

b)

PIM

c)

AIP

d)

SSA

5.

Azure RBAC is an authorization system built on Azure Resource Manager that provides fine-grained access management of Azure resources.

a)

True

b)

False

6.

Role assignment represents a ...

a)

Combination of a scope and role definition

b)

Combination of a security principal, and role definition

c)

Combination of a scope, security principal, and role definition

d)

Combination of a scope and role definition

7.

Colloquially Speaking SCOPE assignment answers to a question ...

a)

Where can it be done?

b)

What can be done?

c)

Who can do it?

8.

Colloquially Speaking SERVICE PRINCIPAL assignment answers to a question ...

a)

Where can it be done?

b)

What can be done?

c)

Who can do it?

9.

Colloquially Speaking ROLE DEFINITION assignment answers to a question ...

a)

Where can it be done?

b)

What can be done?

c)

Who can do it?

10.

Jessica works for Contoso company as an Azure administrator. As part of her role, she needs to be able to view all Azure resources in the Azure subscription called AZ-SUB-01.

But additionally, she needs to be able to perform any actions on a resource group named AZ-ADMIN-RG within that subscription. What is the best strategy to grant her appropriate privileges to perform her tasks?

a)

Grant a owner role on Azure subscription AZ-SUB-01

b)

Grant a owner role on Azure subscription AZ-SUB-01 and owner role on AZ-ADMIN-RG resource group

c)

Grant a owner role on Azure subscription AZ-SUB-01 and reader role on AZ-ADMIN-RG resource group

d)

Grant a reader role on AZ-ADMIN-RG resource group

e)

Grant a reader role on Azure subscription AZ-SUB-01 and owner role on AZ-ADMIN-RG resource group

11.

Which statement describes Azure Resource Locks? Resource Locks are ...

a)

Read-only permissions from Role-based Access Control

b)

A feature of Azure that allows customers to protect their resources from human-error accidents like modification or deletion of the resources

c)

A feature of Azure that allows customers to protect their data from being deleted by human-error accidents

12.

Read-only locks only allow read actions on resources. Every other action is blocked. True or false?

a)

True

b)

False

13.

Delete locks only allows resources to be deleted but not created or updated.

True or false?

a)

True

b)

False

14.

Which statement correctly describes Azure Resource Tags? Azure Resource Tags are ...

a)

Labels for Azure SQL tables to indicate their data classification

b)

Labels for Azure Resources allowing customers to save any additional information they need

c)

Key-value pairs for associating Azure applications with organizational units

15.

The Contoso Company wants to apply the Owner tag to all resources inside of the Resource Group called Appl_RG. To do this, they navigated to the Appl_RG Tags blade and created a new tag with the name Owner. Will this solve their need?

a)

Yes

b)

No

16.

Azure Policy is a service within Azure platform designed to help customers with ...

a)

rovisioning of Azure resources using Infrastructure as a Code approach

b)

Managing network security rules for Azure virtual networks

c)

Governance, security, compliance and cost management of Azure resources

17.

Azure Policy primarily works by ...

a)

Defining roles/permissions and assigning those roles to users/applications

b)

Inspecting resource properties and allowing to chose different effects based on property values

c)

Creating approval flow during resource deployment and ensuring only approved resources will be created

18.

A single object that defines properties, conditions, and effects in Azure Policy service is called a ...

a)

Policy Assignment

b)

Policy Definition

c)

Policy Initiative

d)

Policy Scope

e)

Policy Group

19.

Azure Blueprints service is designed to provide a ...

a)

Centralized repository of approved design patterns for effective management of Azure environments

b)

Per project repostiory for project deliverables and components

c)

Repository for resource manager templates for application teams

20.

Azure Blueprints Definition is a ...

a)

Collection of blueprint assignments

b)

Singular deployment of a blueprint within Azure subscription

c)

Generic package (collection) of various Azure components pre-configured and ready for the deployment

21.

Which of the following Azure component types can be a part of Azure Blueprints Definition? Choose 4.

a)

Azure Resource Manager Template

b)

Azure Role Assignment

c)

Azure Policy Assignment

d)

Azure Role Definition

e)

User or Group object

22.

Your company has 10 offices. You plan to generate several billing reports from the Azure portal. Each report will contain the Azure resource utilization of each office. Which Azure Resource Manager feature should you use before you generate the reports?

a)

Tags

b)

Templates

c)

Locks

d)

Policies

23.

Your network contains an Active Directory forest. The forest contains 5,000 user accounts.Your company plans to migrate all network resources to Azure and to decommission the on-premises data center.You need to recommend a solution to minimize the impact on users after the planned migration.What should you recommend?

a)

Implement Azure Multi-Factor Authentication (MFA)

b)

Sync all the Active Directory user accounts to Azure Active Directory (Azure AD)

c)

Instruct all users to change their password

d)

Create a guest user account in Azure Active Directory (Azure AD) for each user

24.

Your company has an Azure environment that contains resources in several regions.A company policy states that administrators must only be allowed to create additional Azure resources in a region in the country where their office is located. You need to create the Azure resource that must be used to meet the policy requirement.

What should you create?

a)

a read-only lock

b)

an Azure policy

c)

a management group

d)

a reservation

25.

ABC Organization plans to become a cloud solution provider for Microsoft Azure in the United States. As the ABC IT administrator and solution architect, you need to recommend a set of Azure cloud architecture best practices. What should you recommend?

a)

Service Trust Portal

b)

Compliance Manager

c)

Cloud Adoption Framework

d)

Microsoft Trust Center

26.

ABC Organization’s IT security and privacy policy states that Azure administrators are only allowed to create new Azure resources in a region in the country where the ABC IT help desk is located. Which of the following can help seamlessly enable the organization to enforce the policy globally?

a)

ARM Templates

b)

Azure Remote Management

c)

Azure Policy

d)

Azure Marketplace

27.

ABC Organization maintains an Azure resource group named PROD_US_WEST in ABC’s Azure subscription. As the IT administrator, you need to protect the resources in this resource group against accidental modification or deletion. What should you use?

a)

An Azure AD PIM access

b)

A tag named do-not-delete

c)

A deny RBAC role assignment

d)

Resource locks

28.

Your company plans to migrate all on-premises data to Azure. You need to identify whether Azure complies with the company’s regional requirements.What should you use?

a)

the Knowledge Center

b)

Azure Marketplace

c)

the Azure portal

d)

the Trust Center