WorksheetsAZ-900 Module 5
Total questions: 28
Worksheet time: 15mins
Authentication is a ...
Process of granting user access to the system
Process of creation of new user identities
Process of verification of user's permissions
Process of verification of user's identity
Process of verification that only authenticated identities
get access to get the resources for which they were
granted access to by the owners
Which two core functionalities does Azure Active Directory deliver?
Identity Management
Access Management
Resource Management
Subscription Management
Identitfication Services
Security Principal objects (identities) can represent. Choose 4.
User
Group
Role Assignment
Service Principal
Managed Identity
Azure Active Directory _____ automatically signs in users when they are on their corporate devices connected to the corporate network.
Seamless SSO
PIM
AIP
SSA
Azure RBAC is an authorization system built on Azure Resource Manager that provides fine-grained access management of Azure resources.
True
False
Role assignment represents a ...
Combination of a scope and role definition
Combination of a security principal, and role definition
Combination of a scope, security principal, and role definition
Combination of a scope and role definition
Colloquially Speaking SCOPE assignment answers to a question ...
Where can it be done?
What can be done?
Who can do it?
Colloquially Speaking SERVICE PRINCIPAL assignment answers to a question ...
Where can it be done?
What can be done?
Who can do it?
Colloquially Speaking ROLE DEFINITION assignment answers to a question ...
Where can it be done?
What can be done?
Who can do it?
Jessica works for Contoso company as an Azure administrator. As part of her role, she needs to be able to view all Azure resources in the Azure subscription called AZ-SUB-01.
But additionally, she needs to be able to perform any actions on a resource group named AZ-ADMIN-RG within that subscription. What is the best strategy to grant her appropriate privileges to perform her tasks?
Grant a owner role on Azure subscription AZ-SUB-01
Grant a owner role on Azure subscription AZ-SUB-01 and owner role on AZ-ADMIN-RG resource group
Grant a owner role on Azure subscription AZ-SUB-01 and reader role on AZ-ADMIN-RG resource group
Grant a reader role on AZ-ADMIN-RG resource group
Grant a reader role on Azure subscription AZ-SUB-01 and owner role on AZ-ADMIN-RG resource group
Which statement describes Azure Resource Locks? Resource Locks are ...
Read-only permissions from Role-based Access Control
A feature of Azure that allows customers to protect their resources from human-error accidents like modification or deletion of the resources
A feature of Azure that allows customers to protect their data from being deleted by human-error accidents
Read-only locks only allow read actions on resources. Every other action is blocked. True or false?
True
False
Delete locks only allows resources to be deleted but not created or updated.
True or false?
True
False
Which statement correctly describes Azure Resource Tags? Azure Resource Tags are ...
Labels for Azure SQL tables to indicate their data classification
Labels for Azure Resources allowing customers to save any additional information they need
Key-value pairs for associating Azure applications with organizational units
The Contoso Company wants to apply the Owner tag to all resources inside of the Resource Group called Appl_RG. To do this, they navigated to the Appl_RG Tags blade and created a new tag with the name Owner. Will this solve their need?
Yes
No
Azure Policy is a service within Azure platform designed to help customers with ...
rovisioning of Azure resources using Infrastructure as a Code approach
Managing network security rules for Azure virtual networks
Governance, security, compliance and cost management of Azure resources
Azure Policy primarily works by ...
Defining roles/permissions and assigning those roles to users/applications
Inspecting resource properties and allowing to chose different effects based on property values
Creating approval flow during resource deployment and ensuring only approved resources will be created
A single object that defines properties, conditions, and effects in Azure Policy service is called a ...
Policy Assignment
Policy Definition
Policy Initiative
Policy Scope
Policy Group
Azure Blueprints service is designed to provide a ...
Centralized repository of approved design patterns for effective management of Azure environments
Per project repostiory for project deliverables and components
Repository for resource manager templates for application teams
Azure Blueprints Definition is a ...
Collection of blueprint assignments
Singular deployment of a blueprint within Azure subscription
Generic package (collection) of various Azure components pre-configured and ready for the deployment
Which of the following Azure component types can be a part of Azure Blueprints Definition? Choose 4.
Azure Resource Manager Template
Azure Role Assignment
Azure Policy Assignment
Azure Role Definition
User or Group object
Your company has 10 offices. You plan to generate several billing reports from the Azure portal. Each report will contain the Azure resource utilization of each office. Which Azure Resource Manager feature should you use before you generate the reports?
Tags
Templates
Locks
Policies
Your network contains an Active Directory forest. The forest contains 5,000 user accounts.Your company plans to migrate all network resources to Azure and to decommission the on-premises data center.You need to recommend a solution to minimize the impact on users after the planned migration.What should you recommend?
Implement Azure Multi-Factor Authentication (MFA)
Sync all the Active Directory user accounts to Azure Active Directory (Azure AD)
Instruct all users to change their password
Create a guest user account in Azure Active Directory (Azure AD) for each user
Your company has an Azure environment that contains resources in several regions.A company policy states that administrators must only be allowed to create additional Azure resources in a region in the country where their office is located. You need to create the Azure resource that must be used to meet the policy requirement.
What should you create?
a read-only lock
an Azure policy
a management group
a reservation
ABC Organization plans to become a cloud solution provider for Microsoft Azure in the United States. As the ABC IT administrator and solution architect, you need to recommend a set of Azure cloud architecture best practices. What should you recommend?
Service Trust Portal
Compliance Manager
Cloud Adoption Framework
Microsoft Trust Center
ABC Organization’s IT security and privacy policy states that Azure administrators are only allowed to create new Azure resources in a region in the country where the ABC IT help desk is located. Which of the following can help seamlessly enable the organization to enforce the policy globally?
ARM Templates
Azure Remote Management
Azure Policy
Azure Marketplace
ABC Organization maintains an Azure resource group named PROD_US_WEST in ABC’s Azure subscription. As the IT administrator, you need to protect the resources in this resource group against accidental modification or deletion. What should you use?
An Azure AD PIM access
A tag named do-not-delete
A deny RBAC role assignment
Resource locks
Your company plans to migrate all on-premises data to Azure. You need to identify whether Azure complies with the company’s regional requirements.What should you use?
the Knowledge Center
Azure Marketplace
the Azure portal
the Trust Center
