Font size
WorksheetsAZ-900_Azure_Architecture_and_Services_MCQs P2
Total questions: 100
Worksheet time: 2hrs 40mins
What is Microsoft Entra ID primarily used for?
Managing Azure resources
Running containerized applications
Identity and access management
Hosting web APIs
Which Azure service provides cloud-based directory services without the need for domain controllers?
Azure DNS
Microsoft Entra Domain Services
Azure Functions
Azure Monitor
What is the purpose of Single Sign-On (SSO)?
Automatically encrypts all data
Prevents access to unauthorized networks
Allows users to authenticate once and access multiple resources
Synchronizes cloud storage
What does multifactor authentication (MFA) require?
Two or more authentication factors
Repeated login attempts
Admin approval
Single password
What type of authentication method is considered 'something you have'?
Password
Security token
Fingerprint
PIN
What is the difference between authentication and authorization?
Authentication grants access; authorization checks identity
Authentication checks identity; authorization grants permissions
Authentication is used for storage; authorization for networking
There is no difference
What service allows external users to access company resources securely?
Azure VPN
Microsoft Entra External ID (B2B)
Azure DevOps
Azure Files
What does Conditional Access evaluate before granting access?
File type
User's browser version
Signals like location, device, and user risk
File size
Which model assumes breach and verifies every access request?
Zero Trust
Least Privilege
Public Access
Shared Responsibility
What Azure feature provides fine-grained control over who can do what with Azure resources?
Virtual Machine Scale Sets
Azure Monitor
Role-Based Access Control (RBAC)
Azure CLI
Which of these is NOT a valid Conditional Access signal?
Device compliance
Network IP address
Cost of subscription
User location
What security model recommends 'assume breach' and verify explicitly?
Shared access
Defense in Depth
Zero Trust
Passwordless Access
What is the purpose of Microsoft Defender for Cloud?
Network configuration
Data migration
Security monitoring and recommendations
DNS routing
What is a benefit of using Just-In-Time VM access in Defender for Cloud?
Creates VMs automatically
Reduces the number of active ports open
Deletes inactive VMs
Prevents DNS spoofing
What feature helps enforce MFA based on user location or device risk?
RBAC
Azure Firewall
Conditional Access
Storage Tiers
What type of authentication uses fingerprints or facial recognition?
Something you know
Something you are
Something you have
Something you see
What is the main benefit of Entra Domain Services?
Requires user passwords
Allows non-cloud applications to use domain features
Provides on-premises backups
Forces passwordless access
Microsoft Entra External ID B2C is used for:
Developer environments
Employee login only
Customer-facing identity access
App registration
What is NOT a benefit of RBAC?
Enforces least privilege
Controls billing across subscriptions
Allows role assignments by scope
Separates duties within a team
Which term describes the ability to define what data a user can access after authentication?
Authorization
Verification
Identification
Federation
Which role in RBAC can manage all Azure resources?
Contributor
Reader
Owner
Storage Admin
What's the first step in the Zero Trust model?
Secure data
Verify identity explicitly
Configure firewalls
Enable access keys
Which of the following is part of defense-in-depth?
One-time password
Multiple layers of security
Storage tiering
DNS filtering
What does Microsoft Defender for Cloud monitor?
Only Azure Virtual Desktop
Only on-premises data
Azure and hybrid environments
Billing configurations
Conditional Access can block access based on:
Storage tier
Subscription size
Risk detected
VM size
MFA provides protection by:
Blocking all unrecognized devices
Checking billing tiers
Requiring multiple authentication methods
Restricting read access
Entra Domain Services is ideal for:
File sharing
Running legacy apps in the cloud
VPN tunneling
Monitoring costs
What RBAC role can view all resources but not modify them?
Contributor
Reader
Owner
Billing admin
A password is considered:
Something you have
Something you are
Something you know
Something you trust
What access model is built on the principle of least privilege?
DNS Security
Role-Based Access Control (RBAC)
Azure Firewall
Entra External ID
Which of the following is NOT an identity management service?
Microsoft Entra ID
Azure AD B2B
Azure DNS
Microsoft Entra Domain Services
How does Conditional Access enhance security?
By blocking all guest users
By dynamically enforcing policies based on context
By enabling local firewall rules
By enforcing DNS encryption
Which Entra solution allows third-party users to collaborate with your organization?
Entra Domain Services
Entra External ID B2B
Azure File Sync
Azure Web App
What is required for a Zero Trust approach?
Trust all internal devices
Block external traffic
Always verify user and device before granting access
Use of only local authentication
Defense-in-depth prevents:
All malware
Cost overruns
Breach of multiple layers easily
Password reuse
What security model recommends validating identity at every access request?
SSO
Zero Trust
Traditional perimeter-based
Layered Authentication
MFA combines something you know with:
Something you forgot
Something you possess or are
Something encrypted
Something shared
Which is true about Microsoft Defender for Cloud?
Prevents account creation
Offers insights into security posture
Works only with Azure Blob Storage
Applies only to containers
Conditional Access includes:
Virtual machine resizing
User risk evaluation
Storage replication
Blob encryption
What is a typical use of Microsoft Entra ID in hybrid environments?
Blocking guest access
Managing on-premises files
Synchronizing identities from on-premises to cloud
Setting up DNS zones
Role-based access control uses:
Password expiration dates
Roles assigned to users and groups
Container names
Billing reports
Which of the following services supports legacy applications that don't support modern auth?
Microsoft Entra ID
Microsoft Entra Domain Services
Azure Firewall
Azure Resource Manager
Which Entra feature allows managing external customer access?
Domain Services
Conditional Access
Entra External ID B2C
RBAC
The 'defense in depth' model includes all EXCEPT:
Network controls
Physical security
User behavior policies
Unfiltered external access
A common component of Zero Trust is:
Central DNS
Trust internal networks
Verify explicitly
Role inheritance
Microsoft Entra ID supports SSO to:
Only internal websites
Only Microsoft services
Both Microsoft and third-party SaaS applications
Azure Monitor only
Microsoft Defender for Cloud helps block:
Unused storage
Malware
Large files
IPs over VPN
What ensures that only necessary permissions are granted to users?
DNS zoning
Least privilege principle via RBAC
Storage account policies
Azure Automation
What is a key benefit of Azure Conditional Access?
Unlimited admin rights
Setting up webhooks
Enforcing access policies based on risk
Automatically deleting users
Zero Trust security is based on:
Implicit trust within networks
Static rules
Dynamic verification of all requests
Limited subscription access
What are the key components of an Azure Virtual Machine?
Networking only
Storage and identity services
Virtual processor, memory, storage, and networking
DNS and containers
What Azure compute option is best for microservices architectures?
Virtual Machines
Virtual Desktop
Containers
Azure DNS
What service provides full OS-level control in the Azure compute model?
Azure App Services
Azure Virtual Machines
Azure DNS
Azure Functions
What's the purpose of virtual network subnets in Azure?
Monitor billing usage
Enforce firewall rules
Segment networks into smaller address spaces
Host blob containers
What role does Azure DNS play in a cloud network?
Virtual machine management
Resource monitoring
Resolving domain names to IP addresses
File storage
Azure ExpressRoute is used to:
Encrypt Azure backups
Create public endpoints
Provide private, dedicated connections to Azure
Host external identities
Azure region pairs offer:
Higher cost but more control
Manual replication
Disaster recovery support
Backup for DNS services
Which service lets you quickly deploy and scale web apps and APIs?
Azure Functions
Azure Web Apps (App Services)
Azure DNS
Azure Virtual Machines
Which Azure compute model is fully managed and ideal for running code in response to events?
Azure Virtual Desktop
Azure Functions
Azure Blob Storage
Azure SQL
Azure Virtual Desktop provides:
DNS resolution
Traditional desktop deployments
Cloud-hosted multi-session desktops
Container deployment tools
Azure storage accounts allow you to:
Create container instances
Host network peering
Define storage redundancy and access levels
Manage user identities
Azure Cool access tier is ideal for:
Daily data access
Archiving rarely accessed data
Machine learning models
Frequently modified files
Microsoft Entra ID enables:
DNS record resolution
VM scaling
Identity and access management
Private endpoint management
Which statement is true about Azure subscriptions?
Subscriptions can't be moved
Subscriptions manage storage tiers
They act as billing and access boundaries
Subscriptions control DNS names
What is a resource group in Azure?
A physical server location
A group of storage accounts
A logical container for related Azure resources
A subscription plan
What is a key advantage of Azure scale sets?
Automatic scaling based on demand
Faster DNS resolution
Lower storage costs
Higher authentication speeds
Azure sovereign regions are designed to:
Offer higher performance globally
Enable regional billing
Comply with specific government regulations
Extend DNS zones
Which of the following services is best for reducing VM attack surfaces?
Azure Storage Explorer
Microsoft Defender for Cloud
Azure DNS
Azure Functions
Microsoft Entra Domain Services enables legacy app support by:
Supporting custom DNS zones
Synchronizing files
Providing domain services without on-premises controllers
Deploying storage blobs
Conditional Access is enforced:
After a security breach
During resource creation
Based on real-time evaluation of user context
On subscription purchase
Azure File Sync helps you:
Encrypt backup data
Sync DNS zones
Sync files between on-prem and cloud
Restrict user access to storage
What is a key benefit of Azure Migrate?
Role-based access control
On-demand compute scaling
Assessing and moving on-prem workloads to Azure
Creating backup policies
Azure Blob Storage is designed for:
Storing virtual machines
Object-based storage for large unstructured data
Secure token management
Network peering
In Azure networking, peering allows:
DNS zone resolution
Storage account migration
Direct private connectivity between VNets
Free resource movement
MFA is an example of:
Conditional networking
Strong identity protection
File tiering
Billing control
Azure Virtual Network allows communication between:
Only local devices
Azure AD tenants
Azure resources, on-premises, and internet
Entra identity providers
Which service should you use to transfer 70 TB of data to Azure securely?
AzCopy
Azure VPN Gateway
Azure Data Box
Azure Migrate
What does Azure App Service support for app development?
Only .NET
Only Java
Only containers
Multiple languages like .NET, Java, Node.js, Python
Which is a core concept of Zero Trust?
Trust all traffic inside the firewall
Verify explicitly and assume breach
Store credentials on devices
Always allow VPN access
Azure Web Apps is classified as:
IaaS
PaaS
SaaS
FaaS
What is the purpose of virtual machine availability sets?
Provide public IPs
Isolate workloads to reduce single point of failure
Speed up DNS requests
Block unauthorized users
Azure storage redundancy that copies data across three zones in a region is called:
LRS
GRS
ZRS
PRS
The Archive tier is best used for:
Operating system files
Files needed daily
Long-term compliance storage
Web application code
Azure DNS supports which feature?
Passwordless login
Alias record sets
Identity federation
Storage migration
Which of the following supports least privilege access?
Azure Storage Explorer
Conditional Access
RBAC
Azure Backup
Microsoft Defender for Cloud gives:
Container orchestration
Recommendations for securing workloads
Subscription management
DNS resolution
What is required to use Entra Conditional Access?
Azure DNS setup
External users
Defined signals and policies
Global storage replication
Azure region pairs help by:
Reducing identity theft
Providing failover in major outages
Segmenting containers
Enabling read access from all data centers
Azure App Services allows deployment via:
Only FTP
Azure DevOps, GitHub, CLI
DNS records
Azure Storage Sync
In RBAC, a contributor can:
Only view resources
Delete subscriptions
Manage resources without granting access to others
Add billing details
Which tool is best for copying files to/from blob storage?
Azure File Sync
Microsoft Defender
AzCopy
Azure DNS
Microsoft Entra B2C is used for:
VM deployment
External customer authentication
Peering configuration
Blob file sharing
Which Azure compute service supports event-driven code execution?
Azure App Services
Azure DNS
Azure Functions
Azure Migrate
What is a key benefit of Azure ExpressRoute?
Lower latency via the public internet
Managed identity
Dedicated private network connection
Faster storage tiering
What feature is used to manage external partners and vendors securely?
Azure AD B2B (External ID)
Azure Storage Explorer
App Service plans
Virtual subnets
Microsoft Entra ID supports which type of user account?
DNS account
Storage admin account
Organizational and guest accounts
Azure billing account
What does the defense in depth model include?
One-time user check
Application, network, and physical security layers
External DNS only
Password complexity
Role assignments in RBAC are applied at:
Resource, resource group, or subscription level
Virtual network only
Storage account only
DNS zone only
Azure storage accounts support which redundancy type for geo-replication?
LRS
ZRS
GRS
PFS
Azure Container Instances are best suited for:
Always-on web applications
Event-driven microservices with lightweight dependencies
VM-level backups
Domain controller emulation
