wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

sc900

Total questions: 64

Worksheet time: 35mins

Name
Class
Date
1.

Which provides best practices from Microsoft employees, partners, and customers, including tools and guidance to assist in an Azure deployment?

a)

Azure Blueprints

b)

Azure Policy

c)

The Microsoft Cloud Adoption Framework for Azure

d)

A resource lock

2.

Which is used to identify, hold and export electronic information that might be used in an investigation?

a)

Customer Lockbox

b)

Data loss prevention

c)

eDiscovery

d)

A resource lock

3.

You can manage Microsoft intune by using which of these

a)

Azure Active Directory admin center

b)

Microsoft 3665 compliance center

c)

Microsoft 365 Defender portal

d)

Microsoft Endpoint Manager admin center

4.

A federation is used to established ------ between organizations.

a)

Multi-factor authentication (MFA)

b)

A trust relationship

c)

user account synchronization

d)

a VPN connection

5.

Which score measures an organization's progress in completing actions that help reduce risks associated to data protection and regulatory standards?

a)

Microsoft Secure Score

b)

Productivity Score

c)

Secure score in Azure Security Center

d)

Compliance score

6.

What do you use to provide real-time integration between Azure Sentinel and another security source?

a)

Azure AD Connect

b)

a Log Analytics workspace

c)

Azure Information Protection

d)

a connector

7.

Which Microsoft portal provides information about how Microsoft cloud services comply with regulatory standard, such as International Organization for
Standardization (ISO)?

a)

the Microsoft Endpoint Manager admin center

b)

Azure Cost Management + Billing

c)

Microsoft Service Trust Portal

d)

the Azure Active Directory admin center

8.

In the shared responsibility model for an Azure deployment, what is Microsoft solely responsible for managing?

a)

the management of mobile devices

b)

the permissions for the user data stored in Azure

c)

the creation and management of user accounts

d)

the management of the physical hardware

9.

(answer) a file makes the data in the file readable and usable to viewers that have the appropriate key.

a)

Archiving

b)

Compressing

c)

Deduplicating

d)

Encrypting

10.

When users sign in to the Azure portal, they are first

a)

assigned permissions.

b)

authenticated.

c)

authorized.

d)

resolved.

11.

is the process of identifying whether a signed in user can access a specific resource.

a)

Authentication

b)

Authorization

c)

Federation

d)

Single sign-on (SSO)

12.

enables collaboration with business partners from external organizations such as suppliers, partners, and vendors. External users appear as guest users in the directory

a)

Active Directory Domain Services (AD DS)

b)

Active Directory forest trusts

c)

Azure Active Directory (Azure AD) business-to-business (B2B)

d)

Azure Active Directory (Azure AD) business-to-consumer B2C (Azure AD B2C)

13.

Enables collaboration with business partners from external organizations such as suppliers, partners, and vendors. External users appear as guests users in the directory.

a)

Active Directory Domain Services ( AD DS)

b)

Active Directory forest trusts

c)

Azure Active Directory (Azure AD) business-to-business (B2B)

d)

Azure Active Directory business-to-consumer B2C (Azure AD B2C)

14.

n the Microsoft Cloud Adoption Framework for Azure, which two phases are addressed before the Ready phase? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

a)

Plan

b)

Manage

c)

Adopt

d)

Govern

e)

Define Strategy

15.

Provides benchmark recommendations and guidance for protecting Azure services

a)

Azure Application insights

b)

Azure Network Watcher

c)

Log Analytics Workspaces

d)

Security baselines for Azure

16.

What is an example of encryption at rest?

a)

encrypting communications by using a site-to-site VPN

b)

encrypting a virtual machine disk

c)

accessing a website by using an encrypted HTTPS connection

d)
  • sending an encrypted email


17.

Which three statements accurately describe the guiding principles of Zero Trust? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

a)

Define the perimeter by physical locations.

b)

Use identity as the primary security boundary.

c)

Always verify the permissions of a user explicitly.

d)

Always assume that the user system can be breached.

e)

Use the network as the primary security boundary.

18.

Which service should you use to view your Azure secure score? To answer, select the appropriate service in the answer area.

a)

Alerts

b)

Applications Insights

c)

Advisor

d)

Monitor

e)

Security Center

19.

Compliance Manager can be directly accessed from the...

a)

Microsoft 365 admin center

b)

Microsoft 365 Defender portal

c)

Microsoft 365 Compliance Center

d)

Microsoft Support portal

20.

What can you use to provide a user with a two-hour window to complete an administrative task in Azure?

a)

Azure Active Directory (Azure AD) Privileged Identity Management (PIM)

b)

Azure Multi-Factor Authentication (MFA)

c)

Azure Active Directory (Azure AD) Identity Protection

d)

conditional access policies

21.

In a hybrid identity model, what can you use to sync identities between Active Directory Domain Services (AD DS) and Azure Active Directory (Azure AD)?

a)

Active Directory Federation Services (AD FS)

b)

Microsoft Sentinel

c)

Azure AD Connect

d)

Azure AD Privileged Identity Management (PIM)

22.

With Windows Hello for Business, a user's biometric data for authentication

a)

Is stored on an external device.

b)

Is stored on a local device only

c)

Is stored in Azure Active Directory (Azure AD)

d)

Is replicated to all the devices designated by the user

23.

bWhat is the purpose of Azure Active Directory (Azure AD) Password Protection?

a)

to control how often users must change their passwords

b)

to identify devices to which users can sign in without using multi-factor authentication (MFA)

c)

to encrypt a password by using globally recognized encryption standards

d)

to prevent users from using specific words in their passwords

24.

Which Azure Active Directory (Azure AD) feature can you use to evaluate group membership and automatically remove users that no longer require membership in a group?

a)

access reviews

b)

managed identities

c)

conditional access policies

d)

Azure AD Identity Protection

25.

requires additional verification, such as a verification code sent to a mobile phone.

a)

Multi-factor authentication (MFA)

b)

Pass-through authentication

c)

Password writeback

d)

Single sign-on (SSO)

26.

is a cloud-based solution that leverages on-premises Active Directory signals to identify, detect, and investigate advanced threats.

a)

Microsoft Defender for Cloud Apps

b)

Microsoft Defender for Endpoint

c)

Microsoft Defender for Identity

d)

Microsoft Defender for Office 365

27.

Microsoft Defender for Identity can identify advanced threats from -------- signals

a)

Azure Active Directory (Azure AD)

b)

Azure AD connect

c)

on-premises Active Directory Domain Services (AD DS)

28.

Microsoft Defender for Identity can identify advanced threats from -------- signals

a)

Azure Active Directory (Azure AD)

b)

Azure AD connect

c)

on-premises Active Directory Domain Services (AD DS)

29.

Azure Active Directory (Azure AD) is --------------- used for authentication and authorization

a)

an extended detection and response (XDR) system

b)

an identity provider

c)

a management group

d)

a security information and event management (SIEM) system

30.

Which Azure Active Directory (Azure AD) feature can you use to provide just-in-time (JIT) access to manage Azure resources?

a)

conditional access policies

b)

Azure AD Identity Protection

c)

Azure AD Privileged Identity Management (PIM)

d)

authentication method policies

31.

Which three authentication methods can be used by Azure Multi-Factor Authentication (MFA)? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

a)

text message (SMS)

b)

Microsoft Authenticator app

c)

email verification

d)

phone call

e)

security question

32.

Which Microsoft 365 feature can you use to restrict communication and the sharing of information between members of two departments at your organization?

a)

sensitivity label policies

b)

Customer Lockbox

c)

information barriers

d)

Privileged Access Management (PAM)

33.

Applications registered in Azure Active Directory (Azure AD) are associated automatically to a

a)

guest account

b)

managed identity

c)

service principal

d)

user account

34.

Which three authentication methods does Windows Hello for Business support? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

a)

fingerprint

b)

facial recognition

c)

PIN

d)

email verification

e)

security questions

35.

When you enable security defaults in Azure Active Directory (Azure AD), -------- will be enabled for all Azure AD users.

a)

Azure AD Identity protection

b)

Azure AD Privileged Identity Management (PIM)

c)

Multi-factor authentication

36.

You have an Azure subscription.
You need to implement approval-based, time-bound role activation.
What should you use?

a)

Windows Hello for Business

b)

Azure Active Directory (Azure AD) Identity Protection

c)

access reviews in Azure Active Directory (Azure AD)

d)

Azure Active Directory (Azure AD) Privileged Identity Management (PIM)

37.

When security defaults are enabled for an Azure Active Directory (Azure AD) tenant, which two requirements are enforced? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

a)

All users must authenticate from a registered device.

b)

Administrators must always use Azure Multi-Factor Authentication (MFA).

c)

Azure Multi-Factor Authentication (MFA) registration is required for all users.

d)

All users must authenticate by using passwordless sign-in.

e)

All users must authenticate by using Windows Hello.

38.

Which type of identity is created when you register an application with Active Directory (Azure AD)?

a)

a user account

b)
  • a user-assigned managed identity

c)

a system-assigned managed identity

d)

a service principal

39.

Which three tasks can be performed by using Azure Active Directory (Azure AD) Identity Protection? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

a)

Configure external access for partner organizations.

b)

Export risk detection to third-party utilities.

c)

Automate the detection and remediation of identity based-risks.

d)

Investigate risks that relate to user authentication

e)

Create and automatically assign sensitivity labels to data.

40.

When using multi-factor authentication (MFA), a password is considered something you

a)

are

b)

have

c)

know

d)

share

41.

An Azure resource can use a system-assigned ------- to access Azure services

a)

Azure Active Directory (Azure AD) joined device

b)

managed identity

c)

service principal

d)

user identity

42.

You can use ----- in the Microsoft 365 Defender portal to identify devices that are affected by an alert

a)

classifications

b)

incidents

c)

policies

d)

Secure score

43.

What are two capabilities of Microsoft Defender for Endpoint? Each correct selection presents a complete solution.
NOTE: Each correct selection is worth one point.

a)

automated investigation and remediation

b)

transport encryption

c)

shadow IT detection

d)

attack surface reduction

44.

<---

a)

Azure Advisor

b)

Azure Bastion

c)

Azure Monitor

d)

Azure Sentinel

45.

you can use ---- in the Microsoft 365 security center to view an aggregation of alerts that relate to the same attack.

a)

Reports

b)

Hunting

c)

Attack simulator

d)

Incidents

46.

What feature in Microsoft Defender for Endpoints provides the first line of defense against cyberthreats by reducing the attack surface?

a)

automated remediation

b)

automated investigation

c)

advanced hunting

d)

network protection

47.

In Microsoft Sentinel, you can automate common tasks by using

a)

deep investigation tools

b)

hunting search and query tools

c)

playbooks

d)

workbooks

48.

Which two types of resources can be protected by using Azure Firewall? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

a)

Azure virtual machines

b)

Azure Active Directory (Azure AD) users

c)

Microsoft Exchange Online inboxes

d)

Azure virtual networks

e)

Microsoft SharePoint Online sites

49.

You plan to implement a security strategy and place multiple layers of defense throughout a network infrastructure.
Which security methodology does this represent?

a)

threat modeling

b)

identity as the security perimeter

c)

defense in depth

d)

the shared responsibility model

50.

What can you use to scan email attachments and forward the attachments to recipients only if the attachments are free from malware?

a)

Microsoft Defender for Office 365

b)

Microsoft Defender Antivirus

c)

Microsoft Defender for Identity

d)

Microsoft Defender for Endpoint

51.

Which feature provides the extended detection and response (XDR) capability of Azure Sentinel?

a)

integration with the Microsoft 365 compliance center

b)

support for threat hunting

c)

integration with Microsoft 365 Defender

d)

support for Azure Monitor Workbooks

52.

What can you use to provide threat detection for Azure SQL Managed Instance?

a)

Microsoft Secure Score

b)

application security groups

c)

Microsoft Defender for Cloud

d)

Azure Bastion

53.

Which Azure Active Directory (Azure AD) feature can you use to restrict Microsoft Intune-managed devices from accessing corporate resources?

a)

network security groups (NSGs)

b)

Azure AD Privileged Identity Management (PIM)

c)

conditional access policies

d)

resource locks

54.

(answer) can use conditional access policies to control sessions in real time.

a)

Azure Active Directory (Azure AD) Privileged Identity Management (PIM)

b)

Azure Defender

c)

Azure Sentinel

d)

Microsoft Cloud App Security

55.

Azure DDos Protection standard can be used to protect

a)

Azure Active Directory (Azure AD) applications

b)

Azure Active Directory (Azure AD) users

c)

resource groups

d)

virtual networks

56.

What should you use in the Microsoft 365 Defender portal to view security trends and track the protection status of identities?

a)

Attack simulator

b)

Reports

c)

Hunting

d)

Incidents

57.

You have a Microsoft 365 E3 subscription.
You plan to audit user activity by using the unified audit log and Basic Audit.
For how long will the audit records be retained?

a)

15 days

b)

30 days

c)

90 days

d)

180 days

58.

To which type of resource can Azure Bastion provide secure access?

a)

Azure Files

b)

Azure SQL Managed Instances

c)

Azure virtual machines

d)

Azure virtual machines

59.

What are three uses of Microsoft Cloud App Security? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

a)

to discover and control the use of shadow IT

b)

to provide secure connections to Azure virtual machines

c)

to protect sensitive information hosted anywhere in the cloud

d)

to provide pass-through authentication to on-premises applications

e)

to prevent data leaks to noncompliant apps and limit access to regulated data

60.

In the Microsoft 365 Defender portal, an incident is a collection of correlated ----

a)

Alerts

b)

Events

c)

Vulnerabilities

d)

Microsoft Secure Score improvement actions

61.

You need to connect to an Azure virtual machine by using Azure Bastion.
What should you use?

a)

PowerShell remoting

b)

the Azure portal

c)

the Remote Desktop Connection client

d)

an SSH client

62.

Which service includes the Attack simulation training feature?

a)
  • Microsoft Defender for Cloud Apps

b)

Microsoft Defender for Identity

c)

Microsoft Defender for SQL

d)

Microsoft Defender for Office 365

63.

Which type of alert can you manage from the Microsoft 365 Defender portal?

a)

Microsoft Defender for Storage

b)

Microsoft Defender for SQL

c)

Microsoft Defender for Endpoint

d)

Microsoft Defender for IoT

64.

Which two Azure resources can a network security group (NSG) be associated with? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

a)

a virtual network subnet

b)

a network interface

c)

a resource group

d)

a virtual network

e)

an Azure App Service web app