wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Microsoft Security Fundamentals Quiz

Total questions: 106

Worksheet time: 53mins

Name
Class
Date
1.

Which of the following is NOT a Zero Trust guiding principle?

a)

Verify explicitly

b)

Least privileged access

c)

Assume breach.

d)

Multi factor authentication

2.

Which of the following is NOT a type of identity?

a)

Users

b)

Services

c)

Devices

d)

Networks

3.

The human resources organization want to ensure that stored employee data is encrypted. Which security mechanism would they use?

a)

Encryption in transit

b)

Digital signing

c)

Encryption at rest

4.

Which of the following measures might an organization implement as part of the defense in-depth security methodology?

a)

Locating all its servers in a single physical location.

b)

Multi-factor authentication for all users.

c)

Ensuring there's no segmentation of your corporate network.

5.

A compliance admin is looking for regulatory information relevant to a specific region, which one link will provide the needed information?

a)

Microsoft Privacy Principles.

b)

Service Trust Portal.

c)

Microsoft Compliance Manager.

6.

Among the 4 pillars of identity, which pillar tells the story of how much assurance for a particular identity is enough.

a)

Administration

b)

Authentication

c)

Authorization

d)

Auditing

7.

T/F: With federation, trust is always bidirectional.

a)

True

b)

False

8.

How many editions of the azure active directory (AAD) are available?

a)

1

b)

2

c)

3

d)

4

9.

An organization is launching a new app for its customers. Customers will use a sign-in screen that is customized with the organization's brand identity. Which type of Azure External identity solution should the organization use?

a)

Azure AD B2B

b)

Azure AD B2C

c)

Azure AD Hybrid identities

10.

True/False: "A system-assigned managed identity can be associated with more than one Azure resource."

a)

True

b)

False

11.

A company's IT organization has been asked to find ways to reduce IT costs, without compromising security. Which feature should they consider implementing?

a)

Self-service password reset.

b)

Bio-metric sign-in on all devices.

c)

FIDO2.

12.

IT admins have been asked to review Azure AD roles assigned to users, to improve organizational security. Which of the following should they implement?

a)

Remove all global admin roles assigned to users.

b)

Create custom roles.

c)

Replace global admin roles with specific Azure AD roles.

13.

Your IT organization recently discovered that several user accounts in the finance department have been compromised. The CTO has asked for a solution to reduce the impact of compromised user accounts. The IT admin team is looking into Azure AD features. Which one should they recommend?

a)

Identity Protection.

b)

Conditional Access.

c)

Entitlement management.

14.

A company wants to make use of Windows Hello for Business when it comes to authentication. Which of the following authentication techniques are available in Windows Hello for Business?

a)

PIN

b)

Password

c)

Facial Recognition

d)

Email message

e)

Fingerprint recognition

15.

You are planning to make use of Azure Bastion service. Can you use the Azure Bastion service to restrict traffic from the Internet onto an Azure Virtual Machine?

a)

Yes

b)

No

16.

Which of the following is a scalable, cloud-native security event management and security orchestration automated response solution?

a)

Azure Sentinel

b)

Azure Security Centre

c)

Azure Active Directory

d)

Azure AD Identity Protection

17.

Your company is planning on using Azure Active Directory. They already have user identities stored in their on-premise Active Directory. They want to sync the user identities from the on-premise Active Directory onto Azure Active Directory. Which of the following could be used?

a)

Azure Blueprints

b)

Azure AD Connect

c)

Azure Identity Protection

d)

Azure Privileged Identity Management

18.

The security admin wants to increase the priority of a network security group, what five sources of information will the admin need to provide?

a)

source, source port, destination, destination port, and network layer.

b)

source, source port, destination, destination port, and protocol.

c)

source, source port, destination, destination port, and target resource.

19.

An organization is using Azure and wants to improve their security best practices. Which Azure specific benchmark would the IT security team need to consider?

a)

Azure Security Benchmark.

b)

Center for Internet Security.

20.

As the lead admin, it's important to convince your team to start using Azure Sentinel. You’ve put together a presentation. What are the four security operation areas of Azure Sentinel that cover this area?

a)

Collect, Detect, Investigate, and Redirect.

b)

Collect, Detect, Investigate, and Respond.

c)

Collect, Detect, Investigate, and Repair.

21.

Which of the following can be used to provide just-in-time access to resources?

a)

Azure AD Identity Protection

b)

Azure AD Privileged Identity Management

c)

Azure Multi-Factor Authentication

d)

Azure Blueprints

22.

Which of the following provides "Network Address Translation"?

a)

Azure Bastion

b)

Azure Firewall

c)

Network Security Group

d)

Azure DDoS protection

23.

Which of the following provides XDR (Extended Detection & Response) capabilities that helps to protect multi-cloud and hybrid workloads?

a)

Azure Policy

b)

Azure Defender

c)

Azure Blueprints

d)

Azure Identity Protection

24.

Can Microsoft Defender for Endpoint be used for Windows 2016-based Azure Virtual Machine?

a)

Yes

b)

No

25.

What is the maximum time frame for which you can retain audit logs in Microsoft 365?

a)

1 month

b)

1 year

c)

5 year

d)

10 year

26.

Can Azure Bastion be used to restrict traffic from the Internet onto an Azure Virtual machine?

a)

Yes

b)

No

27.

Azure Sentinel provides intelligent security analytics across your enterprise. The data for this analysis is stored in ___________________ ?

a)

Azure Monitor

b)

Azure Blob Storage

c)

Azure DataLake

d)

Azure Log Analytics Workspace

28.

Which of the following are examples of Microsoft Trust principle?

a)

Control

b)

Privacy

c)

Transparency

d)

Security

e)

Strong legal protections

29.

Which of the following Azure Active Directory license type provides ability to perform "self-service password reset" for both cloud and on-premise users?

a)

Azure Active Directory Free

b)

Office 365 Apps

c)

Azure Active Directory Premium P1

d)

Azure Active Directory Premium P2

30.

A lead admin for an organization is looking to protect against malicious threats posed by email messages, links (URLs), and collaboration tools. Which solution from the Microsoft 365 Defender suite is best suited for this purpose?

a)

Microsoft Defender for Office 365.

b)

Microsoft Defender for Endpoint.

c)

Microsoft Defender for Identity.

31.

Which of the following describes what an admin would need to select to view security cards grouped by risk, detection trends, configuration, and health, among others?

a)

Group by topic.

b)

Group by risk

c)

Group by category

32.

Your new colleagues on the admin team are unfamiliar with the concept of shared controls in Compliance Manager. How would the concept of shared controls be explained?

a)

Controls that both external regulators and Microsoft share responsibility for implementing.

b)

Controls that both your organization and external regulators share responsibility for implementing.

c)

Controls that both your organization and Microsoft share responsibility for implementing.

33.

Which part of the concept of know your data, protect your data, and prevent data loss addresses the need for organizations to automatically retain, delete, store data and records in a compliant manner?

a)

Know your data

b)

Prevent data loss

c)

Govern your data

34.

Due to a certain regulation, your organization must now keep hold of all documents in a specific SharePoint site that contains customer information for five years. How can this requirement be implemented?

a)

Use sensitivity labels

b)

Use the content explorer

c)

Use retention policies

35.

Which tool can enable an organization's development team to rapidly provision and run new resources, in a repeatable way that is in line with the organization’s compliance requirements?

a)

Azure Policy

b)

Azure Rapid Build

c)

Azure Blueprints

36.

A hold has been placed on content relevant to a case. The hold has not taken effect yet, what has happened?

a)

It may take up to seven days after you create a hold for it to take effect.

b)

It may take up to 24 hours after you create a hold for it to take effect.

c)

It may take up to one hour after you create a hold for it to take effect.

37.

To comply with corporate policies, the compliance admin needs to be able to identify and scan for offensive language across the organization. What solution can the admin implement to address this need?

a)

Use Policy Compliance in Microsoft 365.

b)

Use Communication Compliance

c)

Use information barriers.

38.

Select Yes/No : If a user uses incorrect credentials, it will not be flagged by Identity Protection since there is not of risk of credential compromise unless a bad actor uses the correct credentials.

a)

Yes

b)

No

39.

Select Yes/No : Can you add delete lock to a resource that has a read-only lock?

a)

Yes

b)

No

40.

Select Yes/No : Can Azure Policy service be used to check the compliance of existing resources?

a)

Yes

b)

No

41.

In the following situation, who is responsible for ensuring security and compliance? "Operating system for a Platform as a service (PaaS) application'

a)

User

b)

Microsoft

c)

Both

42.

Which out of the following requires the least management by the cloud customer.

a)

SaaS

b)

PaaS

c)

IaaS

d)

There is no difference, all require similar management

43.

_______ attack attempts to exhaust an application's resources, making the application unavailable to legitimate users.

a)

Distributed Denial of Service (DDoS)

b)

Ransomware

c)

Data breach

44.

An organization has deployed Microsoft 365 applications to all employees. Who is responsible for the security of the personal data relating to these employees?

a)

The organization

b)

Microsoft, the SaaS provider

c)

There's shared responsibility between an organization and Microsoft.

45.

The security perimeter can no longer be viewed as the on-premises network. It now extends to?

a)

SaaS applications for business-critical workloads that might be hosted outside the corporate network.

b)

IoT devices installed throughout your corporate network and inside customer locations.

c)

The personal devices of employees

d)

The unmanaged devices used by partners or customers when interacting with corporate data or collaborating with employees

46.

Among the 4 pillars of Identity, which is about tracking who does what, when, where, and how?

a)

Administration

b)

Authentication.

c)

Authorization.

d)

Auditing

47.

What type of security risk does a phishing scam pose?

a)

Ethical risk.

b)

Physical risk.

c)

Identity risk.

48.

Which of the following Azure active directory (AAD) is available along with Office 365 E1 & E3

a)

Free

b)

Office 365 Apps

c)

Premium P1

d)

Premium P2

49.

All users in an organization have Microsoft 365 cloud identities. Which identity model applies?

a)

Hybrid

b)

Cloud-only

c)

On-premises only

50.

In which type of authentication, Azure AD hands off the authentication process to a separate trusted authentication system to validate the user’s password.

a)

Password hash synchronization.

b)

Pass-through authentication (PTA).

c)

Federated authentication

51.

True/False: "Custom roles require an Azure AD Premium P1 or P2 license.

a)

True

b)

False

52.

An organization has recently merged with a competitor, nearly doubling the number of employees. The organization needs to implement an access life cycle system that won't add a significant amount of work for its IT administrators. Which Azure AD feature should they implement?

a)

Dynamic groups.

b)

Conditional Access policies.

c)

Azure AD Terms of Use.

53.

Which of the following can be used to provide a secure score for the resources defined as a part of your Azure Account?

a)

Security Centre

b)

Key Vault

c)

Azure Information Protection

d)

Azure Active Directory

e)

Application Security Groups

54.

You are looking at the capabilities of Azure Active Directory. Can AAD be used to manage device registrations?

a)

Yes

b)

No

55.

Which of the following provides advanced and intelligent protection of Azure and hybrid resources and workloads?

a)

Azure Defender

b)

Azure Policies

c)

Azure Blueprints

d)

Azure Active Directory

56.

Your company is planning on using Azure Cloud services. They are looking at the different security aspects when it comes to Microsoft privacy. Is Shared Responsibility Model a key Microsoft privacy principal?

a)

True

b)

False

57.

Do all versions of Azure Active Directory have the same set of features?

a)

Yes

b)

No

58.

The security admin wants to protect Azure resources from DDoS attacks, which Azure DDoS Protection tier will the admin use to target Azure Virtual Network resources?

a)

Basic

b)

Standard

c)

Advanced

59.

An organization is using Security Center to assess its resources and subscriptions for security issues. The organization's overall secure score is low and needs to improve. How could a security admin try to improve the score?

a)

Close old security recommendations.

b)

Remediate security recommendations.

c)

Move security recommendations to resolved.

60.

Your estate has many different data sources where data is stored. Which tool should be used with Azure Sentinel to quickly gain insights across your data as soon as a data source is connected?

a)

Azure Monitor Workbooks.

b)

Playbooks.

c)

Microsoft 365 Defender.

61.

Can Azure AD Identity Protection be used to provide access to resources in Azure?

a)

Yes

b)

No

62.

Which of the following will provide "a secure way to RDP/SSH into Azure Virtual Machines"

a)

Azure Bastion

b)

Azure Virtual Machines

c)

Network Security Group

d)

Azure DDoS Protection

63.

Can Microsoft Defender For Endpoint be used to protect SharePoint Online?

a)

Yes

b)

No

64.

Can Microsoft Intune be used for a Windows 10 device?

a)

Yes

b)

No

65.

Which of the following allows you to invite guest users and provide them access to Azure resources within your organization?

a)

Azure Identity Protection

b)

Azure Privileged Identity Management

c)

Azure Active Directory B2B

d)

Azure AD Connect

66.

Can AAD be used to ensure user does not have the product's name as part of the password defined by the user?

a)

Yes

b)

No

67.

__________________ are the types of resources you can manage user's access to with entitlement management?

a)

Azure AD security groups

b)

Azure AD enterprise applications

c)

SharePoint Online sites

d)

Microsoft 365 Groups and Teams

68.

Can Microsoft Defender for Endpoint service be used to protect Windows10 machines?

a)

Yes

b)

No

69.

Which of the following is NOT one of the benefits of Microsoft Compliance Manager?

a)

Pre-built assessments based on common regional and industry regulations and standards.

b)

Step-by-step improvement actions that admins can take to help meet regulations and standards

c)

contains compliance information about Microsoft Cloud services organized by industry and region.

d)

Translating complicated regulations, standards, company policies, or other control frameworks into a simple language.

70.

A team admin is asked to provide a short presentation on the use and benefit of Microsoft Cloud App Security. Which of the four MCAS pillars is responsible for identifying and controlling sensitive information?

a)

Threat protection

b)

Compliance

c)

Data security

71.

An admin wants to get a comprehensive view of an attack including where it started, what tactics were used, and how far it has gone in the network. What can the admin use to view this type of information?

a)

Alerts

b)

Reports

c)

Incidents

72.

A customer has requested a presentation on how the Microsoft 365 Compliance Center can help improve their organization’s compliance posture. The presentation will need to cover Compliance Manager and compliance score. What is the difference between Compliance Manager and compliance score?

a)

Compliance Manager is an end-to-end solution in Microsoft 365 Compliance Center to enable admins to manage and track compliance activities. Compliance score is a calculation of the overall compliance posture across the organization.

b)

Compliance Manager is an end-to-end solution in Microsoft 365 Compliance Center to enable admins to manage and track compliance activities. Compliance score is a score the organization receives from regulators for successful compliance.

c)

Compliance Manager is the regulator who will manage your compliance activities. Compliance score is a calculation of the overall compliance posture across the organization.

73.

As part of a new data loss prevention policy, the compliance admin needs to be able to identify important information such as credit card numbers, across the organization's data. How can the admin address this requirement?

a)

Use activity explorer

b)

Use sensitivity labels

c)

Use sensitive information types

74.

How can the admin address this requirement?

a)

Use activity explorer

b)

Use sensitivity labels

c)

Use sensitive information types

75.

What capability can the admin use?

a)

Turn on Microsoft Teams settings search and ensure you've been assigned the appropriate role to perform the search.

b)

Verify that Auditing is enabled and ensure that you've been assigned the appropriate role to perform the search.

c)

Block Microsoft Teams from being used and ensure that you've been assigned the appropriate role to perform the search.

76.

What guidance can they use to help them transition to the cloud?

a)

They should use Azure Policy for guidance on moving to the cloud.

b)

They should use the Microsoft Cloud Adoption Framework for guidance on moving to the cloud.

c)

They should use the Azure Cloud Succeed Framework.

77.

What can enable the team to do more complex search tasks?

a)

Use the Microsoft 365 autocontent search client.

b)

Use the continuous eDiscovery autosearch client.

c)

Use the PowerShell scripts provided by Microsoft.

78.

What solution can address this need?

a)

Use Communication Compliance.

b)

Use Customer Lockbox.

c)

Use information barriers.

79.

Can Azure Policy be used to remediate issues that get detected via its compliance checks?

a)

Yes

b)

No

80.

Can Azure Blueprints be used to create Role assignments for an Azure Subscription?

a)

True

b)

False

81.

Can Blueprints be used to create Management Groups?

a)

True

b)

False

82.

Which out of the following requires the most management by the cloud customer.

a)

Infrastructure as a Service (IaaS)

b)

Platform as a Service (PaaS)

c)

Software as a Service (SaaS)

d)

All require the same effort

83.

Which of the following are not responsibilities always retained by the customer organization?

a)

Information and data

b)

Devices (mobile and PCs)

c)

Accounts and identities

d)

Identity and directory infrastructure

84.

Malware can give attackers unauthorized access, which allows them to use system resources, lock you out of your computer, and ask for ransom.

a)

Malware

b)

Data breach

c)

dictionary attack

d)

disruptive attacks

85.

"When Microsoft does collect data, it is used to benefit you, the customer, and to make your experiences better"

a)

True

b)

False

86.

Which pillar in the 4 pillar identification system is about the creation and management of identities for users, devices, and services.

a)

Administration

b)

Authentication

c)

Authorization

d)

Auditing

87.

What is a benefit of single sign-on?

a)

A central identity provider can be used.

b)

The user signs in once and can then access many applications or resources.

c)

Passwords always expire after 72 days.

88.

Authentication is the process of doing what?

a)

Verifying that a user or device is who they say they are.

b)

The process of profiling user behavior.

c)

Enabling federated services.

89.

Which edition of the Azure active directory gives you Privileged Identity Management to help discover, restrict, and monitor administrators?

a)

Free

b)

Office 365

c)

Premium P1

d)

Premium P2

90.

An organization has developed an app to allow users to be able to sign in with their Facebook, Google, or Twitter credentials. What type of authentication is being used?

a)

Service principal authentication

b)

Azure AD B2C

c)

User assigned identities

91.

After hearing of a breach at a competitor, the security team wants to improve identity security within their organization. What should they implement immediately to provide the greatest protection to user identities?

a)

Multi-factor authentication.

b)

Require bio-metrics for all sign-ins.

c)

Require strong passwords for all identities

92.

An organization plans to implement Conditional Access. What do admins need to do?

a)

Create policies that enforce organizational rules.

b)

Check that all users have multi-factor authentication enabled.

c)

Amend your apps to allow Conditional Access.

93.

An organization is project-oriented with employees often working on more than one project at a time. Which solution is best suited to managing user access to this organization’s resources?

a)

Azure Terms of Use.

b)

Dynamic groups.

c)

Entitlement management.

94.

Which of the following can be used to fulfill requirement (2) above?

a)

Azure Policy

b)

Azure Blueprints

c)

Azure Resource Locks

d)

Azure AD Identity Protection

95.

Which of the following can be used to fulfill requirement (1) above?

a)

Azure Resource Locks

b)

Azure Policy

c)

Azure Blueprints

d)

Azure Identity Protection

96.

Which of the following can be used to fulfill requirement (3) above?

a)

Azure Policy

b)

Azure Blueprints

c)

Azure Resource Locks

d)

Azure Identity Protection

97.

Which 3 of the following authentication methods are available for self service password reset?

a)

Email

b)

passport identification number

c)

picture message

d)

mobile app code

e)

mobile app notification

98.

Which of the following is available for the Azure Application Gateway service that helps to protect web applications from common exploits and vulnerabilities?

a)

Azure Firewall

b)

Azure Web Application Firewall

c)

Azure Policy

d)

Azure Identity Protection

99.

Is Control a key Microsoft privacy principal?

a)

True

b)

False

100.

Select all which is an example of Zero Trust Guiding principle?

a)

Verify explicitly

b)

Assume Breach

c)

Shared responsibility

101.

Which of the following is the process of checking if a signed-in user has access to a particular resource in Azure?

a)

Authentication

b)

Authorization

c)

Conditional Access

d)

Resource Locks

102.

Can you make use of Network Security Groups to deny all inbound traffic from the Internet?

a)

Yes

b)

No

103.

What Security Center tool would they use?

a)

Continuous assessment.

b)

Network map.

c)

Network assessment.

104.

Which of the following would provide "Protection against large scale internet attacks"?

a)

Azure Bastion

b)

Azure Firewall

c)

Network Security Groups

d)

Azure DDoS Protection

105.

Can Microsoft Intune be used for Android devices?

a)

Yes

b)

No

106.

Can Azure Bastion be used to securely RDP into an Azure Windows virtual machine via the browser and the Azure portal?

a)

Yes

b)

No