wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

SC-100 Parte 4

Total questions: 78

Worksheet time: 41mins

Name
Class
Date
1.

A customer has a Microsoft 365 E5 subscription and an Azure subscription. The customer wants to centrally manage security incidents, analyze logs, audit activities, and search for potential threats across all deployed services You need to recommend a solution for the customer. What should you include in the recommendation?

a)

A. Microsoft Defender for Cloud

b)

B. Microsoft Defender for Cloud Apps

c)

C. Microsoft 365 Defender

d)

D. Microsoft Sentinel

2.

HOTSPOT - Your company plans to follow DevSecOps best practices of the Microsoft Cloud Adoption Framework for Azure to integrate DevSecOps processes into continuous integration and continuous deployment (CI/CD) DevOps pipelines. You need to recommend which security-related tasks to integrate into each stage of the DevOps pipelines. What should recommend? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

a)

Build and test

Commit the code

b)

Commit the code

Build and test

c)

Operate

Plan and develop

d)

Build and test

Go to production

3.

For a Microsoft cloud environment, you are designing a security architecture based on the Microsoft Cloud Security Benchmark. What are three best practices for identity management based on the Azure Security Benchmark? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point

a)

A. Manage application identities securely and automatically.

b)

B. Manage the lifecycle of identities and entitlements.

c)

C. Protect identity and authentication systems.

d)

D. Enable threat detection for identity and access management.

e)

E. Use a centralized identity and authentication system.

4.

Your company plans to follow DevSecOps best practices of the Microsoft Cloud Adoption Framework for Azure. You need to perform threat modeling by using a top-down approach based on the Microsoft Cloud Adoption Framework for Azure. What should you use to start the threat modeling process?

a)

A. the STRIDE model

b)

B. the DREAD model

c)

C. OWASP threat modeling

5.

Your company has on-premises Microsoft SQL Server databases. The company plans to move the databases to Azure. You need to recommend a secure architecture for the databases that will minimize operational requirements for patching and protect sensitive data by using dynamic data masking. The solution must minimize costs. What should you include in the recommendation?

a)

A. SQL Server on Azure Virtual Machines

b)

B. Azure Synapse Analytics dedicated SQL pools

c)

C. Azure SQL Database

6.

You are designing a new Azure environment based on the security best practices of the Microsoft Cloud Adoption Framework for Azure. The environment will contain one subscription for shared infrastructure components and three separate subscriptions for applications. You need to recommend a deployment solution that includes network security groups (NSGs), Azure Firewall, Azure Key Vault, and Azure Bastion. The solution must minimize deployment effort and follow security best practices of the Microsoft Cloud Adoption Framework for Azure. What should you include in the recommendation?

a)

A. the Azure landing zone accelerator

b)

B. the Azure Well-Architected Framework

c)

C. Azure Security Benchmark v3

d)

D. Azure Advisor

7.

Your company uses Azure Pipelines and Azure Repos to implement continuous integration and continuous deployment (CI/CD) workflows for t deployment of applications to Azure. You are updating the deployment process to align with DevSecOps controls guidance in the Microsoft Cloud Adoption Framework for Azure. You need to recommend a solution to ensure that all code changes are submitted by using pull requests before being deployed by the CI/CD workflo What should you include in the recommendation?

a)

A. custom roles in Azure Pipelines

b)

B. branch policies in Azure Repos

c)

C. Azure policies

d)

D. custom Azure roles

8.

You have an Azure subscription that contains a Microsoft Sentinel workspace. Your on-premises network contains firewalls that support forwarding event logs in the Common Event Format (CEF). There is no built-in Microsoft Sentinel connector for the firewalls. You need to recommend a solution to ingest events from the firewalls into Microsoft Sentinel. What should you include in the recommendation?

a)

A. an Azure logic app

b)

B. an on-premises Syslog server

c)

C. an on-premises data gateway

d)

D. Azure Data Factory

9.

You have an on-premises datacenter and an Azure Kubernetes Service (AKS) cluster named AKS1. You need to restrict internet access to the public endpoint of AKS1. The solution must ensure that AKS1 can be accessed only from the public IP addresses associated with the on-premises datacenter. What should you use?

a)

A. a private endpoint

b)

B. a network security group (NSG)

c)

C. a service endpoint

d)

D. an authorized IP range

10.

You have a multi-cloud environment that contains an Azure subscription and an Amazon Web Services (AWS) account. You need to implement security services in Azure to manage the resources in both subscriptions. The solution must meet the following requirements:

• Automatically identify threats found in AWS CloudTrail events.

• Enforce security settings on AWS virtual machines by using Azure policies.

What should you include in the solution for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

a)

Microsoft Sentinel

Azure Arc

b)

Azure Arc

Microsoft Sentinel

c)

Azure log analytics

Microsoft defender for cloud

11.

You have an Azure subscription. The subscription contains 50 virtual machines that run Windows Server and 50 virtual machines that run Linux. You need to perform vulnerability assessments on the virtual machines. The solution must meet the following requirements:

• Identify missing updates and insecure configurations.

• Use the Qualys engine.

What should you use?

a)

A. Microsoft Defender for Servers

b)

B. Microsoft Defender Threat Intelligence (Defender TI)

c)

C. Microsoft Defender for Endpoint

d)

D. Microsoft Defender External Attack Surface Management (Defender EASM)

12.

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled. The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.

You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application. Which security control should you recommend?

a)

A. app registrations in Azure Active Directory (Azure AD)

b)

B. OAuth app policies in Microsoft Defender for Cloud Apps

c)

C. Azure Security Benchmark compliance controls in Defender for Cloud

d)

D. application control policies in Microsoft Defender for Endpoint

13.

Your company plans to provision blob storage by using an Azure Storage account. The blob storage will be accessible from 20 application servers on the internet. You need to recommend a solution to ensure that only the application servers can access the storage account. What should you recommend using to secure the blob storage?

a)

A. managed rule sets in Azure Web Application Firewall (WAF) policies

b)

B. inbound rules in network security groups (NSGs)

c)

C. firerewall rules for the storage account

d)

D. inbound rules in Azure Firewall

e)

E. service tags in network security groups (NSGs)

14.

Your company is developing a modern application that will un as an Azure App Service web app. You plan to perform threat modeling to identity potential security issues by using the Microsoft Threat Modeling Tool. Which type of diagram should you create?

a)

A. system flow

b)

B. data flow

c)

C. process flow

d)

D. network flow

15.

Your company has an on-premises network and an Azure subscription. The company does NOT have a Site-to-Site VPN or an ExpressRoute connection to Azure. You are designing the security standards for Azure App Service web apps. The web apps will access Microsoft SQL Server databases on the network.

You need to recommend security standards that will allow the web apps to access the databases. The solution must minimize the number of open internet- accessible endpoints to the on-premises network. What should you include in the recommendation?

a)

A. virtual network NAT gateway integration

b)

B. hybrid connections

c)

C. virtual network integration

d)

D. a private endpoint

16.

You are creating an application lifecycle management process based on the Microsoft Security Development Lifecycle (SDL). You need to recommend a security standard for onboarding applications to Azure. The standard will include recommendations for application design, development, and deployment. What should you include during the application design phase?

a)

A. software decomposition by using Microsoft Visual Studio Enterprise

b)

B. dynamic application security testing (DAST) by using Veracode

c)

C. threat modeling by using the Microsoft Threat Modeling Tool

d)

D. static application security testing (SAST) by using SonarQube

17.

Your company is developing a new Azure App Service web app. You are providing design assistance to verify the security of the web app. You need to recommend a solution to test the web app for vulnerabilities such as insecure server con gurations, cross-site scripting (XSS), and SQL injection. What should you include in the recommendation?

a)

A. dynamic application security testing (DAST)

b)

B. static application security testing (SAST)

c)

C. interactive application security testing (IAST)

d)

D. runtime application self-protection (RASP)

18.

Your company develops several applications that are accessed as custom enterprise applications in Azure Active Directory (Azure AD). You need to recommend a solution to prevent users on a speci c list of countries from connecting to the applications. What should you include in the recommendation?

a)

A. activity policies in Microsoft Defender for Cloud Apps

b)

B. sign-in risk policies in Azure AD Identity Protection

c)

C. Azure AD Conditional Access policies

d)

D. device compliance policies in Microsoft Endpoint Manager

e)

E. user risk poticies in Azure AD Identity Protection

19.

Your company has an Azure subscription that uses Azure Storage. The company plans to share speci c blobs with vendors. You need to recommend a solution to provide the vendors with secure access to speci c blobs without exposing the blobs publicly. The access must be time- limited. What should you include in the recommendation?

a)

A. Con gure private link connections.

b)

B. Con gure encryption by using customer-managed keys (CMKs).

c)

C. Share the connection string of the access key.

d)

D. Create shared access signatures (SAS).

20.

Your company is developing an invoicing application that will use Azure Active Directory (Azure AD) B2C. The application will be deployed as an App Service web app. You need to recommend a solution to the application development team to secure the application from identity-related attacks. Which two con gurations should you recommend? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

a)

A. Azure AD workbooks to monitor risk detections

b)

B. Azure AD Conditional Access integration with user ows and custom policies

c)

C. smart account lockout in Azure AD B2C

d)

D. access packages in Identity Governance

e)

E. custom resource owner password credentials (ROPC) ows in Azure AD B2C

21.

Your company has a Microsoft 365 E5 subscription. Users use Microsoft Teams, Exchange Online, SharePoint Online, and OneDrive for sharing and collaborating. The company identi es protected health information (PHI) within stored documents and communications. What should you recommend using to prevent the PHI from being shared outside the company?

a)

A. sensitivity label policies

b)

B. data loss prevention (DLP) policies

c)

C. insider risk management policies

d)

D. retention policies

22.

Your company has a Microsoft 365 E5 subscription. The company wants to identify and classify data in Microsoft Teams, SharePoint Online, and Exchange Online. You need to recommend a solution to identify documents that contain sensitive information. What should you include in the recommendation?

a)

A. data classification content explorer

b)

B. data loss prevention (DLP)

c)

C. eDiscovery

d)

D. Information Governance

23.

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are designing a security strategy for providing access to Azure App Service web apps through an Azure Front Door instance. You need to recommend a solution to ensure that the web apps only allow access through the Front Door instance. Solution: You recommend con guring gateway-required virtual network integration. Does this meet the goal?

a)

A. Yes

b)

B. No

24.

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are designing a security strategy for providing access to Azure App Service web apps through an Azure Front Door instance. You need to recommend a solution to ensure that the web apps only allow access through the Front Door instance. Solution: You recommend access restrictions that allow tra c from the Front Door service tags. Does this meet the goal?

a)

A. Yes

b)

B. No

25.

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are designing a security strategy for providing access to Azure App Service web apps through an Azure Front Door instance. You need to recommend a solution to ensure that the web apps only allow access through the Front Door instance. Solution: You recommend access restrictions based on HTTP headers that have the Front Door ID. Does this meet the goal?

a)

A. Yes

b)

B. No

26.

Your company has an on-premises network, an Azure subscription, and a Microsoft 365 E5 subscription. The company uses the following devices:

✑ Computers that run either Windows 10 or Windows 11

✑ Tablets and phones that run either Android or iOS

You need to recommend a solution to classify and encrypt sensitive Microsoft O ce 365 data regardless of where the data is stored. What should you include in the recommendation?

a)

A. eDiscovery

b)

B. Microsoft Information Protection

c)

C. Compliance Manager

d)

D. retention policies

27.

You have a Microsoft 365 E5 subscription. You are designing a solution to protect con dential data in Microsoft SharePoint Online sites that contain more than one million documents. You need to recommend a solution to prevent Personally Identi able Information (PII) from being shared. Which two components should you include in the recommendation? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

a)

A. data loss prevention (DLP) policies

b)

B. retention label policies

c)

C. eDiscovery cases

d)

D. sensitivity label policies

28.

Your company has the virtual machine infrastructure shown in the following table. The company plans to use Microsoft Azure Backup Server (MABS) to back up the virtual machines to Azure. You need to provide recommendations to increase the resiliency of the backup strategy to mitigate attacks such as ransomware. What should you include in the recommendation?

a)

A. Use geo-redundant storage (GRS).

b)

B. Maintain multiple copies of the virtual machines.

c)

C. Encrypt the backups by using customer-managed keys (CMKS).

d)

D. Require PINs to disable backups.

29.

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.

The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.

You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application.

Which security control should you recommend?

a)

A. adaptive application controls in Defender for Cloud

b)

B. app protection policies in Microsoft Endpoint Manager

c)

C. OAuth app policies in Microsoft Defender for Cloud Apps

d)

D. Azure Active Directory (Azure AD) Conditional Access App Control policies

30.

You have a hybrid cloud infrastructure. You plan to deploy the Azure applications shown in the following table.

What should you use to meet the requirement of each app? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point

a)

Azure aplication gateway web aplication firewall policies

Azure AD B2C custom policies with Conditional Access

b)

Azure AD B2C custom policies with Conditional Access

Azure aplication gateway web aplication firewall policies

c)

Azure AD B2C authentication with Conditional Access

Azure Firewall

31.

Your company wants to optimize ransomware incident investigations. You need to recommend a plan to investigate ransomware incidents based on the Microsoft Detection and Response Team (DART) approach. Which three actions should you recommend performing in sequence in the plan? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order

a)

A

b)

B

c)

C

d)

D

e)

E

32.

You have a Microsoft 365 subscription that syncs with Active Directory Domain Services (AD DS). You need to define the recovery steps for a ransomware attack that encrypted data in the subscription. The solution must follow Microsoft Security Best Practices. What is the first step in the recovery plan?

a)

A. From Microsoft Defender for Endpoint, perform a security scan.

b)

B. Recover files to a cleaned computer or device.

c)

C. Contact law enforcement.

d)

D. Disable Microsoft OneDrive sync and Exchange ActiveSync.

33.

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled. The Azure subscription contains 50 virtual machines.

Each virtual machine runs different applications on Windows Server 2019.

You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application. Which security control should you recommend?

a)

A. OAuth app policies in Microsoft Defender for Cloud Apps

b)

B. Azure Security Benchmark compliance controls in Defender for Cloud

c)

C. application control policies in Microsoft Defender for Endpoint

d)

D. app discovery anomaly detection policies in Microsoft Defender for Cloud Apps

34.

Your company is developing an invoicing application that will use Azure AD B2C. The application will be deployed as an App Service web app. You need to recommend a solution to the application development team to secure the application from identity-related attacks. Which two con gurations should you recommend? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

a)

A. Azure AD Conditional Access integration with user flows and custom policies

b)

B. smart account lockout in Azure AD B2C

c)

C. access packages in Identity Governance

d)

D. custom resource owner password credentials (ROPC) ows in Azure AD B2C

35.

Your company plans to evaluate the security of its Azure environment based on the principles of the Microsoft Cloud Adoption Framework for Azure. You need to recommend a cloud-based service to evaluate whether the Azure resources comply with the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF). What should you recommend?

a)

A. Compliance Manager in Microsoft Purview

b)

B. Microsoft Defender for Cloud

c)

C. Microsoft Sentinel

d)

D. Microsoft Defender for Cloud Apps

36.

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled. The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019. You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application. Which security control should you recommend?

a)

A. app discovery anomaly detection policies in Microsoft Defender for Cloud Apps

b)

B. Azure AD Conditional Access App Control policies

c)

C. adaptive application controls in Defender for Cloud

d)

D. app protection policies in Microsoft Endpoint Manager

37.

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.

The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.

You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application.

Which security control should you recommend?

a)

A. Azure AD Conditional Access App Control policies

b)

B. Azure Security Benchmark compliance controls in Defender for Cloud

c)

C. app protection policies in Microsoft Endpoint Manager

d)

D. application control policies in Microsoft Defender for Endpoint

38.

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.

The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.

You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application.

Which security control should you recommend?

a)

A. app registrations in Azure AD

b)

B. application control policies in Microsoft Defender for Endpoint

c)

C. app discovery anomaly detection policies in Microsoft Defender for Cloud Apps

d)

D. Azure AD Conditional Access App Control policies

39.

You have a Microsoft 365 subscription. You need to design a solution to block le downloads from Microsoft SharePoint Online by authenticated users on unmanaged devices. Which two services should you include in the solution? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

a)

A. Azure AD Conditional Access

b)

B. Azure Data Catalog

c)

C. Microsoft Purview Information Protection

d)

D. Azure AD Application Proxy

e)

E. Microsoft Defender for Cloud Apps

40.

You have an Azure SQL database named DB1 that contains customer information. A team of database administrators has full access to DB1. To address customer inquiries, operators in the customer service department use a custom web app named App1 to view the customer information. You need to design a security strategy for DB1. The solution must meet the following requirement:

• When the database administrators access DB1 by using SQL management tools, they must be prevented from viewing the content of the CreditCard attribute of each customer record.

• When the operators view customer records in App1, they must view only the last four digits of the CreditCard attribute. What should you include in the design?

To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

a)

Always Encrypted

Dynamic data masking

b)

Dynamic data masking

Always Encrypted

c)

Row-level security RLS

Transparent Data Encryption TDE

41.

You have a Microsoft 365 tenant. Your company uses a third-party software as a service (SaaS) app named App1. App1 supports authenticating users by using Azure AD credentials. You need to recommend a solution to enable users to authenticate to App1 by using their Azure AD credentials. What should you include in the recommendation?

a)

A. Azure AD Application Proxy

b)

B. Azure AD B2C

c)

C. an Azure AD enterprise application

d)

D. a relying party trust in Active Directory Federation Services (AD FS)

42.

You have a Microsoft 365 tenant. Your company uses a third-party software as a service (SaaS) app named App1 that is integrated with an Azure AD tenant. You need to design a security strategy to meet the following requirements:

• Users must be able to request access to App1 by using a self-service request.

• When users request access to App1, they must be prompted to provide additional information about their request.

• Every three months, managers must verify that the users still require access to App1.

What should you include in the design?

a)

A. Microsoft Entra Identity Governance

b)

B. connected apps in Microsoft Defender for Cloud Apps

c)

C. access policies in Microsoft Defender for Cloud Apps

d)

D. Azure AD Application Proxy

43.

You have an Azure subscription. You have a DNS domain named contoso.com that is hosted by a third-party DNS registrar. Developers use Azure DevOps to deploy web apps to App Service Environments. When a new app is deployed, a CNAME record for the app is registered in contoso.com. You need to recommend a solution to secure the DNS record for each web app. The solution must meet the following requirements:

• Ensure that when an app is deleted, the CNAME record for the app is removed also.

• Minimize administrative effort.

What should you include in the recommendation?

a)

A. Microsoft Defender for Cloud Apps

b)

B. Microsoft Defender for DevOps

c)

C. Microsoft Defender for App Service

d)

D. Microsoft Defender for DNS

44.

You have an on-premises datacenter named Site1. You have an Azure subscription that contains a virtual network named VNet1 and multiple Azure App Service apps. Site1 is connected to VNet1 by using a Site-to-Site (P2S) VPN connection. The apps are accessed by using public internet connections. You need to recommend a solution for providing secure access to the apps. The solution must meet the following requirements:

• Servers on Site1 must use a VPN connection to access the apps.

• Access to the apps must be restricted to speci c servers on Site1.

• Security administrators for VNet1 must be able to control which servers can access the apps.

• Costs must be minimized. What should you include in the recommendation?

To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

a)

Service endpoints

App Service Static IP address restrictions

b)

App Service Static IP address restrictions

Service endpoints

c)

Azure private link

Azure firewall

45.

You have a Microsoft 365 subscription. You need to recommend a security solution to monitor the following activities:

• User accounts that were potentially compromised

• Users performing bulk le downloads from Microsoft SharePoint Online What should you include in the recommendation for each activity?

To answer, drag the appropriate components to the correct activities. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

a)

B

D

b)

C

B

c)

A

D

d)

D

C

46.

You plan to automate the development and deployment of a Node.js-based app by using GitHub. You need to recommend a DevSecOps solution for the app. The solution must meet the following requirements:

• Automate the generation of pull requests that remediate identi ed vulnerabilities.

• Automate vulnerability code scanning for public and private repositories.

• Minimize administrative effort.

• Minimize costs. What should you recommend using?

To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point

a)

GitHub Enterprise Cloud

Dependabot

b)

Dependabot

GitHub Enterprise Cloud

c)

GitHub Team

Codespaces

47.

Your company wants to optimize using Microsoft Defender for Endpoint to protect its resources against ransomware based on Microsoft Security Best Practices.

You need to prepare a post-breach response plan for compromised computers based on the Microsoft Detection and Response Team (DART) approach in Microsoft Security Best Practices.

What should you include in the response plan?

a)

A. controlled folder access

b)

B. application isolation

c)

C. memory scanning

d)

D. machine isolation

e)

E. user isolation

48.

You have an operational model based on the Microsoft Cloud Adoption Framework for Azure.

You need to recommend a solution that focuses on cloud-centric control areas to protect resources such as endpoints, databases, les, and storage accounts.

What should you include in the recommendation?

a)

A. business resilience

b)

B. modem access control

c)

C. network isolation

d)

D. security baselines in the Microsoft Cloud Security Benchmark

49.

You use Azure Policy with Azure Repos to implement continuous integration and continuous deployment (CI/CD) work ows. You need to recommend best practices to secure the stages of the CI/CD work ows based on the Microsoft Cloud Adoption Framework for Azure. What should you include in the recommendation for each stage?

To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

a)

Azure key vault

Protected branches

b)

Protected branches

Azure key vault

c)

Resouce locks in Azure

Custom roles for build agents

50.

Your company wants to optimize using Azure to protect its resources from ransomware. You need to recommend which capabilities of Azure Backup and Azure Storage provide the strongest protection against ransomware attacks.

The solution must follow Microsoft Security Best Practices. What should you recommend?

To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point

a)

A security PIN

Encryption by using platform-managed keys

b)

Encryption by using platform-managed keys

A security PIN

c)

Access policies

Access tiers

51.

You have an Azure AD tenant that syncs with an Active Directory Domain Services (AD DS) domain. You have an on-premises datacenter that contains 100 servers. The servers run Windows Server and are backed up by using Microsoft Azure Backup Server (MABS). You are designing a recovery solution for ransomware attacks.

The solution follows Microsoft Security Best Practices. You need to ensure that a compromised administrator account cannot be used to delete the backups.

What should you do?

a)

A. From Azure Backup, con gure multi-user authorization by using Resource Guard.

b)

B. From Microsoft Azure Backup Setup, register MABS with a Recovery Services vault.

c)

C. From a Recovery Services vault, generate a security PIN for critical operations.

d)

D. From Azure AD Privileged Identity Management (PIM), create a role assignment for the Backup Contributor role.

52.

You are designing a ransomware response plan that follows Microsoft Security Best Practices. You need to recommend a solution to limit the scope of damage of ransomware attacks without being locked out. What should you include in the recommendation?

a)

A. device compliance policies

b)

B. Privileged Access Workstations (PAWs)

c)

C. Customer Lockbox for Microsoft Azure

d)

D. emergency access accounts

53.

You design cloud-based software as a service (SaaS) solutions. You need to recommend a recovery solution for ransomware attacks. The solution must follow Microsoft Security Best Practices. What should you recommend doing first?

a)

A. Develop a privileged identity strategy.

b)

B. Implement data protection.

c)

C. Develop a privileged access strategy.

d)

D. Prepare a recovery plan.

54.

You need to recommend a security methodology for a DevOps development process based on the Microsoft Cloud Adoption Framework for Azure. During which stage of a continuous integration and continuous deployment (CI/CD) DevOps process should each security-related task be performed? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

a)

plan and develop

Operate

Build and Test

b)

Operate

Build and Test

plan and develop

c)

Go to production

Operate

Build and Test

d)

Build and Test

Operate

Go to production

55.

You need to recommend a security methodology for a DevOps development process based on the Microsoft Cloud Adoption Framework for Azure.

During which stage of a continuous integration and continuous deployment (CI/CD) DevOps process should each security-related task be performed? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

a)

Plan and develop

Operate

Build and test

b)

Build and test

Operate

Plan and develop

c)

Operate

Plan and develop

Build and test

56.

You use Azure Pipelines with Azure Repos to implement continuous integration and continuous deployment (CI/CD) workflows for the deployme of applications to Azure. You need to recommend what to include in dynamic application security testing (DAST) based on the principles of the Microsoft Cloud Adoption Framework for Azure. What should you recommend?

a)

A. unit testing

b)

B. penetration testing

c)

C. dependency checks

d)

D. threat modeling

57.

You have a Microsoft 365 subscription.

You are designing a user access solution that follows the Zero Trust principles of the Microsoft Cybersecurity Reference Architectures (MCRA).

You need to recommend a solution that automatically restricts access to Microsoft Exchange Online, SharePoint Online, and Teams in near-realtime (NRT) in response to the following Azure AD events:

• A user account is disabled or deleted.

• The password of a user is changed or reset. • All the refresh tokens for a user are revoked.

• Multi-factor authentication (MFA) is enabled for a user.

Which two features should you include in the recommendation? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

a)

A. continuous access evaluation

b)

B. Azure AD Application Proxy

c)

C. a sign-in risk policy

d)

D. Azure AD Privileged Identity Management (PIM)

e)

E. Conditional Access

58.

You have an Azure subscription and an on-premises datacenter. The datacenter contains 100 servers that run Windows Server. All the servers are backed up to a Recovery Services vault by using Azure Backup and the Microsoft Azure Recovery Services (MARS) agent.

You need to design a recovery solution for ransomware attacks that encrypt the on-premises servers. The solution must follow Microsoft Security Best Practices and protect against the following risks:

• A compromised administrator account used to delete the backups from Azure Backup before encrypting the servers

• A compromised administrator account used to disable the backups on the MARS agent before encrypting the servers

What should you use for each risk? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

a)

Soft delete of backups

Multi-user authorization by using Resource Guard

b)

Multi-user authorization by using Resource Guard

Soft delete of backups

c)

A security PIN for critical operations

Soft delete of backups

59.

CASO DE USO PAGINA 146

You need to recommend a strategy for securing the litware.com forest. The solution must meet the identity requirements. What should you include in the recommendation?

To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

a)

Microsoft defender for cloud

An account lockout policy in AD DS

b)

Azure AD identuty Protection

Microsoft defender for identity

c)

Microsoft defender for cloud

Microsoft defender for identity

60.

CASO DE ESTUDIO PAGINA 149

You need to recommend a SIEM and SOAR strategy that meets the hybrid requirements, the Microsoft Sentinel requirements, and the regulatory compliance requirements. What should you recommend? To answer, select the appropriate options in the answer area.

a)

Azure AD tenant

The azure Lighthouse subscri`tion onboarding process

b)

Enterprise

The azure Lighthouse subscri`tion onboarding process

c)

Azure AD tenant

Self-service sing-up user flows for azure AD B2C

61.

CASO DE ESTUDIO PAGINA 153

You need to recommend a multi-tenant and hybrid security solution that meets to the business requirements and the hybrid requirements. What should you recommend? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

a)

Azure AD B2C

Azure ARC

b)

Azure AD B2C

Azure Stack Hub

c)

Azure lighthouse

Azure Arc

62.

CASO DE ESTUDIO PAGINA 156

You need to recommend a solution for securing the landing zones. The solution must meet the landing zone requirements and the business requirements. What should you configure for each landing zone?

a)

A. an ExpressRoute gateway

b)

B. Microsoft Defender for Cloud

c)

C. an Azure Private DNS zone

d)

D. Azure DDoS Protection Standard

63.

CASO DE ESTUDIO PAGINA 159

What should you create in Azure AD to meet the Contoso developer requirements?

a)

A synced user account in the corp.fabrikam.com domain

An access review

b)

A user account in the fabrikam.onmicrosoft.com tenant

An Azure AD role

c)

A synced user account in the corp.fabrikam.com domain

An azure resource role

64.

You need to recommend a solution to meet the security requirements for the InfraSec group. What should you use to delegate the access?

a)

A. a subscription

b)

B. a custom role-based access control (RBAC) role

c)

C. a resource group

d)

D. a management group

65.

CASO DE ESTUDIO PAGINA 166

You need to recommend a solution to meet the AWS requirements. What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

a)

Microsoft Defender for servers

Microsoft Sentinel

b)

Azure blueprints

Defender for cloud

c)

Microsoft sentinel

Microsoft endpoint manager

66.

CASO DE ESTUDIO PAGINA 170

You need to recommend a solution to resolve the virtual machine issue. What should you include in the recommendation?

a)

A. Enable the Qualys scanner in Defender for Cloud.

b)

B. Onboard the virtual machines to Microsoft Defender for Endpoint.

c)

C. Create a device compliance policy in Microsoft Endpoint Manager.

d)

D. Onboard the virtual machines to Azure Arc.

67.

CASO DE ESTUDIO 173

You need to recommend a solution to meet the security requirements for the virtual machines. What should you include in the recommendation?

a)

A. just-in-time (JIT) VM access

b)

B. an Azure Bastion host

c)

C. Azure Virtual Desktop

d)

D. a network security group (NSG)

68.

CASO DE USO PAGINA 176

You need to recommend a solution to meet the compliance requirements. What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

a)

A blueprint

Modify an Azure policy definition

b)

A managed identity

Edit an Azure blueprint

c)

Workflow automation

Update an Azure policy assignment

69.

CASO DE ESTUDIO PAGINA 179

You need to recommend a solution to evaluate regulatory compliance across the entire managed environment. The solution must meet the regulatory compliance requirements and the business requirements. What should you recommend? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

a)

Azure Policy initiatives to managment groups

Azure Arc

b)

Azure Policy definitions to managment groups

Group Policy

c)

Azure Policy initiatives to managment groups

PowerShell desired state configuration DSC

70.

CASO DE ESTUDIO PAGINA 182

You need to recommend a strategy for routing internet-bound traffic from the landing zones. The solution must meet the landing z requirements. What should you recommend as part of the landing zone deployment?

a)

A. local network gateways

b)

B. forced tunneling

c)

C. service chaining

71.

You need to recommend a strategy for App Service web app connectivity. The solution must meet the landing zone requirements. What should you recommend? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

a)

Virtual network integration

Private endpoints

b)

Private endpoints

Virtual network integration

c)

Services endpoints

Virtual network integration

72.

CASO DE ESTUDIO PAGINA 188

You need to recommend an identity security solution for the Azure AD tenant of Litware. The solution must meet the identity requirements and the regulatory compliance requirements. What should you recommend? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

a)

Azure AD administrative units

Enable password has synchronization in the Azure AD Connect deployment

b)

Custom Azure AD roles

Replace pass-throught authentication with Active Directory Federation Services

73.

CASO DE ESTUDIO PAGINA 191

You are evaluating the security of ClaimsApp. For each of the following statements, select Yes if the statement is true. Otherwise, select No.

a)

NO

YES

YES

b)

YES

YES

YES

c)

NO

NO

YES

74.

CASO DE ESTUDIO PAGINA 194

You need to recommend a solution to scan the application code. The solution must meet the application development requirements. What should you include in the recommendation?

a)

A. GitHub Advanced Security

b)

B. Azure Key Vault

c)

C. Azure DevTest Labs

d)

D. Application Insights in Azure Monitor

75.

CASO DE ESTUDIO PAGINA 197

You need to design a strategy for securing the SharePoint Online and Exchange Online data. The solution must meet the application security requirements. Which two services should you leverage in the strategy? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

a)

A. Azure AD Conditional Access

b)

B. access reviews in Azure AD

c)

C. Microsoft Defender for Cloud

d)

D. Microsoft Defender for Cloud Apps

e)

E. Microsoft Defender for Endpoint

76.

CASO DE ESTUDIO PAGINA 200

To meet the application security requirements, which two authentication methods must the applications support? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

a)

A. Security Assertion Markup Language (SAML)

b)

B. NTLMv2

c)

C. certificate-based authentication

d)

D. Kerberos

77.

CASO DE ESTUDIO PAGINA 203

You need to recommend a solution to secure the MedicalHistory data in the ClaimsDetail table. The solution must meet the Contoso developer requirements. What should you include in the recommendation?

a)

A. row-level security (RLS)

b)

B. Transparent Data Encryption (TDE)

c)

C. Always Encrypted

d)

D. data classification

e)

E. dynamic data masking

78.

CASO DE ESTUDIO PAGINA 206

You need to recommend a solution to meet the requirements for connections to ClaimsDB. What should you recommend using for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

a)

A private endpoint

A managed identity

b)

A service endpoint

An access package

c)

A NAT gateway

A managed identity