wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AZ-900_Azure_Architecture_and_Services_MCQs P2

Total questions: 100

Worksheet time: 2hrs 40mins

Name
Class
Date
1.

What is Microsoft Entra ID primarily used for?

a)

Managing Azure resources

b)

Running containerized applications

c)

Identity and access management

d)

Hosting web APIs

2.

Which Azure service provides cloud-based directory services without the need for domain controllers?

a)

Azure DNS

b)

Microsoft Entra Domain Services

c)

Azure Functions

d)

Azure Monitor

3.

What is the purpose of Single Sign-On (SSO)?

a)

Automatically encrypts all data

b)

Prevents access to unauthorized networks

c)

Allows users to authenticate once and access multiple resources

d)

Synchronizes cloud storage

4.

What does multifactor authentication (MFA) require?

a)

Two or more authentication factors

b)

Repeated login attempts

c)

Admin approval

d)

Single password

5.

What type of authentication method is considered 'something you have'?

a)

Password

b)

Security token

c)

Fingerprint

d)

PIN

6.

What is the difference between authentication and authorization?

a)

Authentication grants access; authorization checks identity

b)

Authentication checks identity; authorization grants permissions

c)

Authentication is used for storage; authorization for networking

d)

There is no difference

7.

What service allows external users to access company resources securely?

a)

Azure VPN

b)

Microsoft Entra External ID (B2B)

c)

Azure DevOps

d)

Azure Files

8.

What does Conditional Access evaluate before granting access?

a)

File type

b)

User's browser version

c)

Signals like location, device, and user risk

d)

File size

9.

Which model assumes breach and verifies every access request?

a)

Zero Trust

b)

Least Privilege

c)

Public Access

d)

Shared Responsibility

10.

What Azure feature provides fine-grained control over who can do what with Azure resources?

a)

Virtual Machine Scale Sets

b)

Azure Monitor

c)

Role-Based Access Control (RBAC)

d)

Azure CLI

11.

Which of these is NOT a valid Conditional Access signal?

a)

Device compliance

b)

Network IP address

c)

Cost of subscription

d)

User location

12.

What security model recommends 'assume breach' and verify explicitly?

a)

Shared access

b)

Defense in Depth

c)

Zero Trust

d)

Passwordless Access

13.

What is the purpose of Microsoft Defender for Cloud?

a)

Network configuration

b)

Data migration

c)

Security monitoring and recommendations

d)

DNS routing

14.

What is a benefit of using Just-In-Time VM access in Defender for Cloud?

a)

Creates VMs automatically

b)

Reduces the number of active ports open

c)

Deletes inactive VMs

d)

Prevents DNS spoofing

15.

What feature helps enforce MFA based on user location or device risk?

a)

RBAC

b)

Azure Firewall

c)

Conditional Access

d)

Storage Tiers

16.

What type of authentication uses fingerprints or facial recognition?

a)

Something you know

b)

Something you are

c)

Something you have

d)

Something you see

17.

What is the main benefit of Entra Domain Services?

a)

Requires user passwords

b)

Allows non-cloud applications to use domain features

c)

Provides on-premises backups

d)

Forces passwordless access

18.

Microsoft Entra External ID B2C is used for:

a)

Developer environments

b)

Employee login only

c)

Customer-facing identity access

d)

App registration

19.

What is NOT a benefit of RBAC?

a)

Enforces least privilege

b)

Controls billing across subscriptions

c)

Allows role assignments by scope

d)

Separates duties within a team

20.

Which term describes the ability to define what data a user can access after authentication?

a)

Authorization

b)

Verification

c)

Identification

d)

Federation

21.

Which role in RBAC can manage all Azure resources?

a)

Contributor

b)

Reader

c)

Owner

d)

Storage Admin

22.

What's the first step in the Zero Trust model?

a)

Secure data

b)

Verify identity explicitly

c)

Configure firewalls

d)

Enable access keys

23.

Which of the following is part of defense-in-depth?

a)

One-time password

b)

Multiple layers of security

c)

Storage tiering

d)

DNS filtering

24.

What does Microsoft Defender for Cloud monitor?

a)

Only Azure Virtual Desktop

b)

Only on-premises data

c)

Azure and hybrid environments

d)

Billing configurations

25.

Conditional Access can block access based on:

a)

Storage tier

b)

Subscription size

c)

Risk detected

d)

VM size

26.

MFA provides protection by:

a)

Blocking all unrecognized devices

b)

Checking billing tiers

c)

Requiring multiple authentication methods

d)

Restricting read access

27.

Entra Domain Services is ideal for:

a)

File sharing

b)

Running legacy apps in the cloud

c)

VPN tunneling

d)

Monitoring costs

28.

What RBAC role can view all resources but not modify them?

a)

Contributor

b)

Reader

c)

Owner

d)

Billing admin

29.

A password is considered:

a)

Something you have

b)

Something you are

c)

Something you know

d)

Something you trust

30.

What access model is built on the principle of least privilege?

a)

DNS Security

b)

Role-Based Access Control (RBAC)

c)

Azure Firewall

d)

Entra External ID

31.

Which of the following is NOT an identity management service?

a)

Microsoft Entra ID

b)

Azure AD B2B

c)

Azure DNS

d)

Microsoft Entra Domain Services

32.

How does Conditional Access enhance security?

a)

By blocking all guest users

b)

By dynamically enforcing policies based on context

c)

By enabling local firewall rules

d)

By enforcing DNS encryption

33.

Which Entra solution allows third-party users to collaborate with your organization?

a)

Entra Domain Services

b)

Entra External ID B2B

c)

Azure File Sync

d)

Azure Web App

34.

What is required for a Zero Trust approach?

a)

Trust all internal devices

b)

Block external traffic

c)

Always verify user and device before granting access

d)

Use of only local authentication

35.

Defense-in-depth prevents:

a)

All malware

b)

Cost overruns

c)

Breach of multiple layers easily

d)

Password reuse

36.

What security model recommends validating identity at every access request?

a)

SSO

b)

Zero Trust

c)

Traditional perimeter-based

d)

Layered Authentication

37.

MFA combines something you know with:

a)

Something you forgot

b)

Something you possess or are

c)

Something encrypted

d)

Something shared

38.

Which is true about Microsoft Defender for Cloud?

a)

Prevents account creation

b)

Offers insights into security posture

c)

Works only with Azure Blob Storage

d)

Applies only to containers

39.

Conditional Access includes:

a)

Virtual machine resizing

b)

User risk evaluation

c)

Storage replication

d)

Blob encryption

40.

What is a typical use of Microsoft Entra ID in hybrid environments?

a)

Blocking guest access

b)

Managing on-premises files

c)

Synchronizing identities from on-premises to cloud

d)

Setting up DNS zones

41.

Role-based access control uses:

a)

Password expiration dates

b)

Roles assigned to users and groups

c)

Container names

d)

Billing reports

42.

Which of the following services supports legacy applications that don't support modern auth?

a)

Microsoft Entra ID

b)

Microsoft Entra Domain Services

c)

Azure Firewall

d)

Azure Resource Manager

43.

Which Entra feature allows managing external customer access?

a)

Domain Services

b)

Conditional Access

c)

Entra External ID B2C

d)

RBAC

44.

The 'defense in depth' model includes all EXCEPT:

a)

Network controls

b)

Physical security

c)

User behavior policies

d)

Unfiltered external access

45.

A common component of Zero Trust is:

a)

Central DNS

b)

Trust internal networks

c)

Verify explicitly

d)

Role inheritance

46.

Microsoft Entra ID supports SSO to:

a)

Only internal websites

b)

Only Microsoft services

c)

Both Microsoft and third-party SaaS applications

d)

Azure Monitor only

47.

Microsoft Defender for Cloud helps block:

a)

Unused storage

b)

Malware

c)

Large files

d)

IPs over VPN

48.

What ensures that only necessary permissions are granted to users?

a)

DNS zoning

b)

Least privilege principle via RBAC

c)

Storage account policies

d)

Azure Automation

49.

What is a key benefit of Azure Conditional Access?

a)

Unlimited admin rights

b)

Setting up webhooks

c)

Enforcing access policies based on risk

d)

Automatically deleting users

50.

Zero Trust security is based on:

a)

Implicit trust within networks

b)

Static rules

c)

Dynamic verification of all requests

d)

Limited subscription access

51.

What are the key components of an Azure Virtual Machine?

a)

Networking only

b)

Storage and identity services

c)

Virtual processor, memory, storage, and networking

d)

DNS and containers

52.

What Azure compute option is best for microservices architectures?

a)

Virtual Machines

b)

Virtual Desktop

c)

Containers

d)

Azure DNS

53.

What service provides full OS-level control in the Azure compute model?

a)

Azure App Services

b)

Azure Virtual Machines

c)

Azure DNS

d)

Azure Functions

54.

What's the purpose of virtual network subnets in Azure?

a)

Monitor billing usage

b)

Enforce firewall rules

c)

Segment networks into smaller address spaces

d)

Host blob containers

55.

What role does Azure DNS play in a cloud network?

a)

Virtual machine management

b)

Resource monitoring

c)

Resolving domain names to IP addresses

d)

File storage

56.

Azure ExpressRoute is used to:

a)

Encrypt Azure backups

b)

Create public endpoints

c)

Provide private, dedicated connections to Azure

d)

Host external identities

57.

Azure region pairs offer:

a)

Higher cost but more control

b)

Manual replication

c)

Disaster recovery support

d)

Backup for DNS services

58.

Which service lets you quickly deploy and scale web apps and APIs?

a)

Azure Functions

b)

Azure Web Apps (App Services)

c)

Azure DNS

d)

Azure Virtual Machines

59.

Which Azure compute model is fully managed and ideal for running code in response to events?

a)

Azure Virtual Desktop

b)

Azure Functions

c)

Azure Blob Storage

d)

Azure SQL

60.

Azure Virtual Desktop provides:

a)

DNS resolution

b)

Traditional desktop deployments

c)

Cloud-hosted multi-session desktops

d)

Container deployment tools

61.

Azure storage accounts allow you to:

a)

Create container instances

b)

Host network peering

c)

Define storage redundancy and access levels

d)

Manage user identities

62.

Azure Cool access tier is ideal for:

a)

Daily data access

b)

Archiving rarely accessed data

c)

Machine learning models

d)

Frequently modified files

63.

Microsoft Entra ID enables:

a)

DNS record resolution

b)

VM scaling

c)

Identity and access management

d)

Private endpoint management

64.

Which statement is true about Azure subscriptions?

a)

Subscriptions can't be moved

b)

Subscriptions manage storage tiers

c)

They act as billing and access boundaries

d)

Subscriptions control DNS names

65.

What is a resource group in Azure?

a)

A physical server location

b)

A group of storage accounts

c)

A logical container for related Azure resources

d)

A subscription plan

66.

What is a key advantage of Azure scale sets?

a)

Automatic scaling based on demand

b)

Faster DNS resolution

c)

Lower storage costs

d)

Higher authentication speeds

67.

Azure sovereign regions are designed to:

a)

Offer higher performance globally

b)

Enable regional billing

c)

Comply with specific government regulations

d)

Extend DNS zones

68.

Which of the following services is best for reducing VM attack surfaces?

a)

Azure Storage Explorer

b)

Microsoft Defender for Cloud

c)

Azure DNS

d)

Azure Functions

69.

Microsoft Entra Domain Services enables legacy app support by:

a)

Supporting custom DNS zones

b)

Synchronizing files

c)

Providing domain services without on-premises controllers

d)

Deploying storage blobs

70.

Conditional Access is enforced:

a)

After a security breach

b)

During resource creation

c)

Based on real-time evaluation of user context

d)

On subscription purchase

71.

Azure File Sync helps you:

a)

Encrypt backup data

b)

Sync DNS zones

c)

Sync files between on-prem and cloud

d)

Restrict user access to storage

72.

What is a key benefit of Azure Migrate?

a)

Role-based access control

b)

On-demand compute scaling

c)

Assessing and moving on-prem workloads to Azure

d)

Creating backup policies

73.

Azure Blob Storage is designed for:

a)

Storing virtual machines

b)

Object-based storage for large unstructured data

c)

Secure token management

d)

Network peering

74.

In Azure networking, peering allows:

a)

DNS zone resolution

b)

Storage account migration

c)

Direct private connectivity between VNets

d)

Free resource movement

75.

MFA is an example of:

a)

Conditional networking

b)

Strong identity protection

c)

File tiering

d)

Billing control

76.

Azure Virtual Network allows communication between:

a)

Only local devices

b)

Azure AD tenants

c)

Azure resources, on-premises, and internet

d)

Entra identity providers

77.

Which service should you use to transfer 70 TB of data to Azure securely?

a)

AzCopy

b)

Azure VPN Gateway

c)

Azure Data Box

d)

Azure Migrate

78.

What does Azure App Service support for app development?

a)

Only .NET

b)

Only Java

c)

Only containers

d)

Multiple languages like .NET, Java, Node.js, Python

79.

Which is a core concept of Zero Trust?

a)

Trust all traffic inside the firewall

b)

Verify explicitly and assume breach

c)

Store credentials on devices

d)

Always allow VPN access

80.

Azure Web Apps is classified as:

a)

IaaS

b)

PaaS

c)

SaaS

d)

FaaS

81.

What is the purpose of virtual machine availability sets?

a)

Provide public IPs

b)

Isolate workloads to reduce single point of failure

c)

Speed up DNS requests

d)

Block unauthorized users

82.

Azure storage redundancy that copies data across three zones in a region is called:

a)

LRS

b)

GRS

c)

ZRS

d)

PRS

83.

The Archive tier is best used for:

a)

Operating system files

b)

Files needed daily

c)

Long-term compliance storage

d)

Web application code

84.

Azure DNS supports which feature?

a)

Passwordless login

b)

Alias record sets

c)

Identity federation

d)

Storage migration

85.

Which of the following supports least privilege access?

a)

Azure Storage Explorer

b)

Conditional Access

c)

RBAC

d)

Azure Backup

86.

Microsoft Defender for Cloud gives:

a)

Container orchestration

b)

Recommendations for securing workloads

c)

Subscription management

d)

DNS resolution

87.

What is required to use Entra Conditional Access?

a)

Azure DNS setup

b)

External users

c)

Defined signals and policies

d)

Global storage replication

88.

Azure region pairs help by:

a)

Reducing identity theft

b)

Providing failover in major outages

c)

Segmenting containers

d)

Enabling read access from all data centers

89.

Azure App Services allows deployment via:

a)

Only FTP

b)

Azure DevOps, GitHub, CLI

c)

DNS records

d)

Azure Storage Sync

90.

In RBAC, a contributor can:

a)

Only view resources

b)

Delete subscriptions

c)

Manage resources without granting access to others

d)

Add billing details

91.

Which tool is best for copying files to/from blob storage?

a)

Azure File Sync

b)

Microsoft Defender

c)

AzCopy

d)

Azure DNS

92.

Microsoft Entra B2C is used for:

a)

VM deployment

b)

External customer authentication

c)

Peering configuration

d)

Blob file sharing

93.

Which Azure compute service supports event-driven code execution?

a)

Azure App Services

b)

Azure DNS

c)

Azure Functions

d)

Azure Migrate

94.

What is a key benefit of Azure ExpressRoute?

a)

Lower latency via the public internet

b)

Managed identity

c)

Dedicated private network connection

d)

Faster storage tiering

95.

What feature is used to manage external partners and vendors securely?

a)

Azure AD B2B (External ID)

b)

Azure Storage Explorer

c)

App Service plans

d)

Virtual subnets

96.

Microsoft Entra ID supports which type of user account?

a)

DNS account

b)

Storage admin account

c)

Organizational and guest accounts

d)

Azure billing account

97.

What does the defense in depth model include?

a)

One-time user check

b)

Application, network, and physical security layers

c)

External DNS only

d)

Password complexity

98.

Role assignments in RBAC are applied at:

a)

Resource, resource group, or subscription level

b)

Virtual network only

c)

Storage account only

d)

DNS zone only

99.

Azure storage accounts support which redundancy type for geo-replication?

a)

LRS

b)

ZRS

c)

GRS

d)

PFS

100.

Azure Container Instances are best suited for:

a)

Always-on web applications

b)

Event-driven microservices with lightweight dependencies

c)

VM-level backups

d)

Domain controller emulation