wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Az500

Total questions: 10

Worksheet time: 5mins

Name
Class
Date
1.

Which Azure AD role allows resetting passwords for non-admin users only?

a)

Global Administrator

b)

User Administrator

c)

Password Administrator

d)

Helpdesk Administrator

2.

You need to enforce MFA for users only when they sign in from outside your trusted IP ranges. Which feature should you use?

a)

Conditional Access

b)

Privileged Identity Management

c)

Access Reviews

d)

Azure AD Identity Protection

3.

An app needs to read users’ email without requiring them to be signed in. Which permission type should you assign?

a)

Delegated permissions

b)

Application permissions

c)

Device permissions

d)

Role-based permissions

4.

To enforce “just-in-time” privileged role activation in Azure AD, you should use:

a)

Conditional Access Policies

b)

Azure AD Access Reviews

c)

Privileged Identity Management (PIM)

d)

Role-based Access Control (RBAC)

5.

To automatically remove inactive guest users after 90 days, you should configure:

a)

Conditional Access + MFA

b)

Access Reviews with recurrence

c)

Azure AD B2C Policies

d)

Privileged Identity Management

6.

Azure Disk Encryption uses:

a)

BitLocker & DM-Crypt with keys in Key Vault

b)

SSL/TLS certificates only

c)

Azure Backup service only

d)

Application Gateway

7.

To allow RDP/SSH access to VMs only when required, you should use:

a)

Azure Bastion

b)

Network Security Group rules with Any/Any

c)

Always-on NSG rules

d)

Virtual Network Peering

8.

To detect risky sign-ins and compromised accounts, you use:

a)

Azure Front Door

b)

Azure AD Identity Protection

c)

Azure Monitor Alerts

d)

Azure Advisor

9.

To automatically remediate non-compliant resources, you should use:

a)

Azure Blueprints

b)

Azure Monitor

c)

Azure Policy with Remediation Tasks

d)

Role-Based Access Control

10.

You want to allow an Azure AD application to authenticate to Azure resources without storing credentials in code. Which feature should you use?

a)

Service Principals with client secrets

b)

Managed Identities

c)

Role Assignments only

d)

Conditional Access