Font size
WorksheetsMicrosoft Security Fundamentals Quiz
Total questions: 106
Worksheet time: 53mins
Which of the following is NOT a Zero Trust guiding principle?
Verify explicitly
Least privileged access
Assume breach.
Multi factor authentication
Which of the following is NOT a type of identity?
Users
Services
Devices
Networks
The human resources organization want to ensure that stored employee data is encrypted. Which security mechanism would they use?
Encryption in transit
Digital signing
Encryption at rest
Which of the following measures might an organization implement as part of the defense in-depth security methodology?
Locating all its servers in a single physical location.
Multi-factor authentication for all users.
Ensuring there's no segmentation of your corporate network.
A compliance admin is looking for regulatory information relevant to a specific region, which one link will provide the needed information?
Microsoft Privacy Principles.
Service Trust Portal.
Microsoft Compliance Manager.
Among the 4 pillars of identity, which pillar tells the story of how much assurance for a particular identity is enough.
Administration
Authentication
Authorization
Auditing
T/F: With federation, trust is always bidirectional.
True
False
How many editions of the azure active directory (AAD) are available?
1
2
3
4
An organization is launching a new app for its customers. Customers will use a sign-in screen that is customized with the organization's brand identity. Which type of Azure External identity solution should the organization use?
Azure AD B2B
Azure AD B2C
Azure AD Hybrid identities
True/False: "A system-assigned managed identity can be associated with more than one Azure resource."
True
False
A company's IT organization has been asked to find ways to reduce IT costs, without compromising security. Which feature should they consider implementing?
Self-service password reset.
Bio-metric sign-in on all devices.
FIDO2.
IT admins have been asked to review Azure AD roles assigned to users, to improve organizational security. Which of the following should they implement?
Remove all global admin roles assigned to users.
Create custom roles.
Replace global admin roles with specific Azure AD roles.
Your IT organization recently discovered that several user accounts in the finance department have been compromised. The CTO has asked for a solution to reduce the impact of compromised user accounts. The IT admin team is looking into Azure AD features. Which one should they recommend?
Identity Protection.
Conditional Access.
Entitlement management.
A company wants to make use of Windows Hello for Business when it comes to authentication. Which of the following authentication techniques are available in Windows Hello for Business?
PIN
Password
Facial Recognition
Email message
Fingerprint recognition
You are planning to make use of Azure Bastion service. Can you use the Azure Bastion service to restrict traffic from the Internet onto an Azure Virtual Machine?
Yes
No
Which of the following is a scalable, cloud-native security event management and security orchestration automated response solution?
Azure Sentinel
Azure Security Centre
Azure Active Directory
Azure AD Identity Protection
Your company is planning on using Azure Active Directory. They already have user identities stored in their on-premise Active Directory. They want to sync the user identities from the on-premise Active Directory onto Azure Active Directory. Which of the following could be used?
Azure Blueprints
Azure AD Connect
Azure Identity Protection
Azure Privileged Identity Management
The security admin wants to increase the priority of a network security group, what five sources of information will the admin need to provide?
source, source port, destination, destination port, and network layer.
source, source port, destination, destination port, and protocol.
source, source port, destination, destination port, and target resource.
An organization is using Azure and wants to improve their security best practices. Which Azure specific benchmark would the IT security team need to consider?
Azure Security Benchmark.
Center for Internet Security.
As the lead admin, it's important to convince your team to start using Azure Sentinel. You’ve put together a presentation. What are the four security operation areas of Azure Sentinel that cover this area?
Collect, Detect, Investigate, and Redirect.
Collect, Detect, Investigate, and Respond.
Collect, Detect, Investigate, and Repair.
Which of the following can be used to provide just-in-time access to resources?
Azure AD Identity Protection
Azure AD Privileged Identity Management
Azure Multi-Factor Authentication
Azure Blueprints
Which of the following provides "Network Address Translation"?
Azure Bastion
Azure Firewall
Network Security Group
Azure DDoS protection
Which of the following provides XDR (Extended Detection & Response) capabilities that helps to protect multi-cloud and hybrid workloads?
Azure Policy
Azure Defender
Azure Blueprints
Azure Identity Protection
Can Microsoft Defender for Endpoint be used for Windows 2016-based Azure Virtual Machine?
Yes
No
What is the maximum time frame for which you can retain audit logs in Microsoft 365?
1 month
1 year
5 year
10 year
Can Azure Bastion be used to restrict traffic from the Internet onto an Azure Virtual machine?
Yes
No
Azure Sentinel provides intelligent security analytics across your enterprise. The data for this analysis is stored in ___________________ ?
Azure Monitor
Azure Blob Storage
Azure DataLake
Azure Log Analytics Workspace
Which of the following are examples of Microsoft Trust principle?
Control
Privacy
Transparency
Security
Strong legal protections
Which of the following Azure Active Directory license type provides ability to perform "self-service password reset" for both cloud and on-premise users?
Azure Active Directory Free
Office 365 Apps
Azure Active Directory Premium P1
Azure Active Directory Premium P2
A lead admin for an organization is looking to protect against malicious threats posed by email messages, links (URLs), and collaboration tools. Which solution from the Microsoft 365 Defender suite is best suited for this purpose?
Microsoft Defender for Office 365.
Microsoft Defender for Endpoint.
Microsoft Defender for Identity.
Which of the following describes what an admin would need to select to view security cards grouped by risk, detection trends, configuration, and health, among others?
Group by topic.
Group by risk
Group by category
Your new colleagues on the admin team are unfamiliar with the concept of shared controls in Compliance Manager. How would the concept of shared controls be explained?
Controls that both external regulators and Microsoft share responsibility for implementing.
Controls that both your organization and external regulators share responsibility for implementing.
Controls that both your organization and Microsoft share responsibility for implementing.
Which part of the concept of know your data, protect your data, and prevent data loss addresses the need for organizations to automatically retain, delete, store data and records in a compliant manner?
Know your data
Prevent data loss
Govern your data
Due to a certain regulation, your organization must now keep hold of all documents in a specific SharePoint site that contains customer information for five years. How can this requirement be implemented?
Use sensitivity labels
Use the content explorer
Use retention policies
Which tool can enable an organization's development team to rapidly provision and run new resources, in a repeatable way that is in line with the organization’s compliance requirements?
Azure Policy
Azure Rapid Build
Azure Blueprints
A hold has been placed on content relevant to a case. The hold has not taken effect yet, what has happened?
It may take up to seven days after you create a hold for it to take effect.
It may take up to 24 hours after you create a hold for it to take effect.
It may take up to one hour after you create a hold for it to take effect.
To comply with corporate policies, the compliance admin needs to be able to identify and scan for offensive language across the organization. What solution can the admin implement to address this need?
Use Policy Compliance in Microsoft 365.
Use Communication Compliance
Use information barriers.
Select Yes/No : If a user uses incorrect credentials, it will not be flagged by Identity Protection since there is not of risk of credential compromise unless a bad actor uses the correct credentials.
Yes
No
Select Yes/No : Can you add delete lock to a resource that has a read-only lock?
Yes
No
Select Yes/No : Can Azure Policy service be used to check the compliance of existing resources?
Yes
No
In the following situation, who is responsible for ensuring security and compliance? "Operating system for a Platform as a service (PaaS) application'
User
Microsoft
Both
Which out of the following requires the least management by the cloud customer.
SaaS
PaaS
IaaS
There is no difference, all require similar management
_______ attack attempts to exhaust an application's resources, making the application unavailable to legitimate users.
Distributed Denial of Service (DDoS)
Ransomware
Data breach
An organization has deployed Microsoft 365 applications to all employees. Who is responsible for the security of the personal data relating to these employees?
The organization
Microsoft, the SaaS provider
There's shared responsibility between an organization and Microsoft.
The security perimeter can no longer be viewed as the on-premises network. It now extends to?
SaaS applications for business-critical workloads that might be hosted outside the corporate network.
IoT devices installed throughout your corporate network and inside customer locations.
The personal devices of employees
The unmanaged devices used by partners or customers when interacting with corporate data or collaborating with employees
Among the 4 pillars of Identity, which is about tracking who does what, when, where, and how?
Administration
Authentication.
Authorization.
Auditing
What type of security risk does a phishing scam pose?
Ethical risk.
Physical risk.
Identity risk.
Which of the following Azure active directory (AAD) is available along with Office 365 E1 & E3
Free
Office 365 Apps
Premium P1
Premium P2
All users in an organization have Microsoft 365 cloud identities. Which identity model applies?
Hybrid
Cloud-only
On-premises only
In which type of authentication, Azure AD hands off the authentication process to a separate trusted authentication system to validate the user’s password.
Password hash synchronization.
Pass-through authentication (PTA).
Federated authentication
True/False: "Custom roles require an Azure AD Premium P1 or P2 license.
True
False
An organization has recently merged with a competitor, nearly doubling the number of employees. The organization needs to implement an access life cycle system that won't add a significant amount of work for its IT administrators. Which Azure AD feature should they implement?
Dynamic groups.
Conditional Access policies.
Azure AD Terms of Use.
Which of the following can be used to provide a secure score for the resources defined as a part of your Azure Account?
Security Centre
Key Vault
Azure Information Protection
Azure Active Directory
Application Security Groups
You are looking at the capabilities of Azure Active Directory. Can AAD be used to manage device registrations?
Yes
No
Which of the following provides advanced and intelligent protection of Azure and hybrid resources and workloads?
Azure Defender
Azure Policies
Azure Blueprints
Azure Active Directory
Your company is planning on using Azure Cloud services. They are looking at the different security aspects when it comes to Microsoft privacy. Is Shared Responsibility Model a key Microsoft privacy principal?
True
False
Do all versions of Azure Active Directory have the same set of features?
Yes
No
The security admin wants to protect Azure resources from DDoS attacks, which Azure DDoS Protection tier will the admin use to target Azure Virtual Network resources?
Basic
Standard
Advanced
An organization is using Security Center to assess its resources and subscriptions for security issues. The organization's overall secure score is low and needs to improve. How could a security admin try to improve the score?
Close old security recommendations.
Remediate security recommendations.
Move security recommendations to resolved.
Your estate has many different data sources where data is stored. Which tool should be used with Azure Sentinel to quickly gain insights across your data as soon as a data source is connected?
Azure Monitor Workbooks.
Playbooks.
Microsoft 365 Defender.
Can Azure AD Identity Protection be used to provide access to resources in Azure?
Yes
No
Which of the following will provide "a secure way to RDP/SSH into Azure Virtual Machines"
Azure Bastion
Azure Virtual Machines
Network Security Group
Azure DDoS Protection
Can Microsoft Defender For Endpoint be used to protect SharePoint Online?
Yes
No
Can Microsoft Intune be used for a Windows 10 device?
Yes
No
Which of the following allows you to invite guest users and provide them access to Azure resources within your organization?
Azure Identity Protection
Azure Privileged Identity Management
Azure Active Directory B2B
Azure AD Connect
Can AAD be used to ensure user does not have the product's name as part of the password defined by the user?
Yes
No
__________________ are the types of resources you can manage user's access to with entitlement management?
Azure AD security groups
Azure AD enterprise applications
SharePoint Online sites
Microsoft 365 Groups and Teams
Can Microsoft Defender for Endpoint service be used to protect Windows10 machines?
Yes
No
Which of the following is NOT one of the benefits of Microsoft Compliance Manager?
Pre-built assessments based on common regional and industry regulations and standards.
Step-by-step improvement actions that admins can take to help meet regulations and standards
contains compliance information about Microsoft Cloud services organized by industry and region.
Translating complicated regulations, standards, company policies, or other control frameworks into a simple language.
A team admin is asked to provide a short presentation on the use and benefit of Microsoft Cloud App Security. Which of the four MCAS pillars is responsible for identifying and controlling sensitive information?
Threat protection
Compliance
Data security
An admin wants to get a comprehensive view of an attack including where it started, what tactics were used, and how far it has gone in the network. What can the admin use to view this type of information?
Alerts
Reports
Incidents
A customer has requested a presentation on how the Microsoft 365 Compliance Center can help improve their organization’s compliance posture. The presentation will need to cover Compliance Manager and compliance score. What is the difference between Compliance Manager and compliance score?
Compliance Manager is an end-to-end solution in Microsoft 365 Compliance Center to enable admins to manage and track compliance activities. Compliance score is a calculation of the overall compliance posture across the organization.
Compliance Manager is an end-to-end solution in Microsoft 365 Compliance Center to enable admins to manage and track compliance activities. Compliance score is a score the organization receives from regulators for successful compliance.
Compliance Manager is the regulator who will manage your compliance activities. Compliance score is a calculation of the overall compliance posture across the organization.
As part of a new data loss prevention policy, the compliance admin needs to be able to identify important information such as credit card numbers, across the organization's data. How can the admin address this requirement?
Use activity explorer
Use sensitivity labels
Use sensitive information types
How can the admin address this requirement?
Use activity explorer
Use sensitivity labels
Use sensitive information types
What capability can the admin use?
Turn on Microsoft Teams settings search and ensure you've been assigned the appropriate role to perform the search.
Verify that Auditing is enabled and ensure that you've been assigned the appropriate role to perform the search.
Block Microsoft Teams from being used and ensure that you've been assigned the appropriate role to perform the search.
What guidance can they use to help them transition to the cloud?
They should use Azure Policy for guidance on moving to the cloud.
They should use the Microsoft Cloud Adoption Framework for guidance on moving to the cloud.
They should use the Azure Cloud Succeed Framework.
What can enable the team to do more complex search tasks?
Use the Microsoft 365 autocontent search client.
Use the continuous eDiscovery autosearch client.
Use the PowerShell scripts provided by Microsoft.
What solution can address this need?
Use Communication Compliance.
Use Customer Lockbox.
Use information barriers.
Can Azure Policy be used to remediate issues that get detected via its compliance checks?
Yes
No
Can Azure Blueprints be used to create Role assignments for an Azure Subscription?
True
False
Can Blueprints be used to create Management Groups?
True
False
Which out of the following requires the most management by the cloud customer.
Infrastructure as a Service (IaaS)
Platform as a Service (PaaS)
Software as a Service (SaaS)
All require the same effort
Which of the following are not responsibilities always retained by the customer organization?
Information and data
Devices (mobile and PCs)
Accounts and identities
Identity and directory infrastructure
Malware can give attackers unauthorized access, which allows them to use system resources, lock you out of your computer, and ask for ransom.
Malware
Data breach
dictionary attack
disruptive attacks
"When Microsoft does collect data, it is used to benefit you, the customer, and to make your experiences better"
True
False
Which pillar in the 4 pillar identification system is about the creation and management of identities for users, devices, and services.
Administration
Authentication
Authorization
Auditing
What is a benefit of single sign-on?
A central identity provider can be used.
The user signs in once and can then access many applications or resources.
Passwords always expire after 72 days.
Authentication is the process of doing what?
Verifying that a user or device is who they say they are.
The process of profiling user behavior.
Enabling federated services.
Which edition of the Azure active directory gives you Privileged Identity Management to help discover, restrict, and monitor administrators?
Free
Office 365
Premium P1
Premium P2
An organization has developed an app to allow users to be able to sign in with their Facebook, Google, or Twitter credentials. What type of authentication is being used?
Service principal authentication
Azure AD B2C
User assigned identities
After hearing of a breach at a competitor, the security team wants to improve identity security within their organization. What should they implement immediately to provide the greatest protection to user identities?
Multi-factor authentication.
Require bio-metrics for all sign-ins.
Require strong passwords for all identities
An organization plans to implement Conditional Access. What do admins need to do?
Create policies that enforce organizational rules.
Check that all users have multi-factor authentication enabled.
Amend your apps to allow Conditional Access.
An organization is project-oriented with employees often working on more than one project at a time. Which solution is best suited to managing user access to this organization’s resources?
Azure Terms of Use.
Dynamic groups.
Entitlement management.
Which of the following can be used to fulfill requirement (2) above?
Azure Policy
Azure Blueprints
Azure Resource Locks
Azure AD Identity Protection
Which of the following can be used to fulfill requirement (1) above?
Azure Resource Locks
Azure Policy
Azure Blueprints
Azure Identity Protection
Which of the following can be used to fulfill requirement (3) above?
Azure Policy
Azure Blueprints
Azure Resource Locks
Azure Identity Protection
Which 3 of the following authentication methods are available for self service password reset?
passport identification number
picture message
mobile app code
mobile app notification
Which of the following is available for the Azure Application Gateway service that helps to protect web applications from common exploits and vulnerabilities?
Azure Firewall
Azure Web Application Firewall
Azure Policy
Azure Identity Protection
Is Control a key Microsoft privacy principal?
True
False
Select all which is an example of Zero Trust Guiding principle?
Verify explicitly
Assume Breach
Shared responsibility
Which of the following is the process of checking if a signed-in user has access to a particular resource in Azure?
Authentication
Authorization
Conditional Access
Resource Locks
Can you make use of Network Security Groups to deny all inbound traffic from the Internet?
Yes
No
What Security Center tool would they use?
Continuous assessment.
Network map.
Network assessment.
Which of the following would provide "Protection against large scale internet attacks"?
Azure Bastion
Azure Firewall
Network Security Groups
Azure DDoS Protection
Can Microsoft Intune be used for Android devices?
Yes
No
Can Azure Bastion be used to securely RDP into an Azure Windows virtual machine via the browser and the Azure portal?
Yes
No
