Font size
S
M
L
XL
WorksheetsAZ900-05
Total questions: 39
Worksheet time: 20mins
Name
Class
Date
1.
Which of the following are some of the layers of Defense In Depth
a)
Physical Security
b)
Identify Access
c)
Perimeter Security
d)
Network Security
e)
Firewall
2.
This is the rules for who and what can access a resource
a)
Network Security Group
b)
Application Security Group
c)
Service Endpoints
d)
Private Endpoint
3.
Network security group rules are applied where
a)
at the resource
b)
at the subscription
c)
at the user
d)
at the application
4.
With this, you can group VMs and networks into policies
a)
Application Security Group
b)
Network Security Group
c)
Service Endpoints
d)
Private Endpoint
5.
This is used to connect a private VNET to an Azure service
a)
Service Endpoint
b)
Private Endpoint
c)
Application Security Group
d)
Network Security Group
6.
When creating a resource and setting the service endpoints, the options for Public Network Access are
a)
Enable from all networks
b)
Disabled
c)
Enabled from select vNET and IP Address
d)
Enable from Load Balancers
7.
With this, you can share a connection across a VPN
a)
Private Endpoint
b)
Service Endpoint
c)
Application Security Group
d)
Network Security Group
8.
You have a home office and must access Azure SQL privately AND disable public internet exposure
a)
Private Endpoint
b)
Service Endpoint
c)
Application Security Group
d)
Network Security Group
9.
Microsoft Defender for Cloud was previously known as
a)
Azure Security Center
b)
Azure Sentinel
c)
Azure Monitor
d)
Azure Service HEalth
e)
Azure Compliance Manager
10.
With Microsoft Defender for Cloud you CAN/CAN NOT monitor onprem
a)
Can with agents
b)
Can without agents
c)
Can Not
11.
Microsoft Defender for Cloud makes decisions based on
a)
Rules within Policies
b)
Subscription Limitations
c)
Machine Learning
d)
Event Management
12.
Microsoft Defender for Cloud will perform which of the following
a)
Alert
b)
Remediate
13.
Which Azure service provides password management
a)
Key Vault
b)
Information Protection
c)
Defender for Identity
d)
Sentinel
14.
Which Azure service provides data classifiation
a)
Information Protection
b)
Key Vault
c)
Defender for Identity
d)
Sentinel
15.
This service provides a baseline for user activity and notifies when a user does something unusual
a)
Defender for Identity
b)
Key Vault
c)
Information Protection
d)
Sentinel
16.
This service is an event management tool that uses AI
a)
Sentinel
b)
Key Vault
c)
Information Protection
d)
Defender for Identity
17.
An HSM Key is a __
a)
hardware key
b)
RSA Token
c)
SSL Certificate
d)
A Public Secret
18.
This defines which users can do what
a)
Role Based Access Control
b)
Locks
c)
Blue Prints
d)
GIT
19.
Under RBAC, An object representing an entity (User or group) is called __
a)
Security Principal
b)
Role Definition
c)
Scope
20.
Under RBAC, the collection of permissions (Read/write/delete) is called __
a)
Role Definition
b)
Security Principal
c)
Scope
21.
Under RBAC, __ tells what resources this applies to
a)
scope
b)
Security Principal
c)
Role Definition
22.
This assures a resource can not be changed or can not be deleted
a)
Locks
b)
Role Based Access Control
c)
Blue Prints
d)
GIT
23.
Locks can be assigned to which
a)
subscription
b)
resource group
c)
resource
d)
blade
24.
This provides guidance for moving to the cloud
a)
Cloud Adoption Framework
b)
Governance
c)
Azure Compliance Manager
d)
Azure Cost Manager
25.
__ is the visualization elements used to describe a resource
a)
blade
b)
locks
c)
Blue Prints
d)
GIT
26.
A collection of mesasurements and data at remote points
a)
telemtry
b)
monitor
c)
trust center
d)
Arc
27.
Azure Monitor includes which of the following
a)
query language
b)
machine learning
c)
log analystics
d)
monitor alerts
e)
compliance manager
28.
T/F Azure Monitor's Log Analytics uses the Kusto Query Language (KQL)
a)
"True"
b)
"False"
29.
With Azure Monitor Alerts, this defines what happens AFTER the trigger
a)
Action Group
b)
Alert Rule
c)
Insites
d)
Analytics
30.
This reports on Azure outages and maintenance
a)
Azure Service Health
b)
Azure Compliance Manager
c)
Azure ARC
d)
Azure Monitor
e)
Trust Center
31.
Azure Compliance Manager will report compliance for which of the following
a)
GPDR
b)
ISO
c)
NIST
d)
PMI
32.
The Azure Government Cloud is for
a)
Government Employees
b)
Government Contractors
c)
RBAC
d)
GIT
33.
T/F The China Region is ran by a Chineese company and can not connet to any other Azure region
a)
"True"
b)
"False"
34.
This has links that tell you standards Microsoft is compliant with
a)
Trust Center
b)
Azure Service Health
c)
Azure Compliance Manager
d)
Azure ARC
e)
Azure Monitor
35.
This will manage and apply governance to non-Azure environments
a)
Azure Arc
b)
Defender for Identify Management
c)
Azure Compliance Manager
d)
Ansure Monitor
e)
Trust Center
36.
T/F Azure Arc is protected with Defender For Cloud
a)
"True"
b)
"False"
37.
Azure costs are effected by which
a)
Hours of use
b)
Size
c)
Tier of Service
d)
Location
e)
Bandwidth Used
38.
T/F all services and resources must live within a subscription
a)
"True"
b)
"False"
39.
Accounts can/can not have multiple subscriptions
a)
CAN
b)
CAN NOT
Reset
