You have an on-premises network and an Azure subscription.
You have the Microsoft SQL Server instances shown in the following table.
You plan to implement Microsoft Defender for SQL.
Which SQL Server instances will be protected by Microsoft Defender for SQL?
A. sql1 and sql2 only
B. sql1, sql2, and sql3 only
C. sql1, sql2, and sql4 only
D. sql1, sql2, sql3, and sql4
Show Answer
Correct Answer: B
Explanation: Microsoft Defender for SQL Servers on Machines protects SQL Server on Azure VMs and Azure Arc-enabled SQL Server instances. On-premises SQL Servers require Azure Arc onboarding to be protected. Based on the typical exam scenario, SQL Server on Azure VMs (sql1 and sql2) and the Arc-enabled/server-supported instance (sql3) are protected, while a plain on-premises/non-Arc instance (sql4) is not.
Sources:
https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-sql-usage
Question 184
From Microsoft Defender for Cloud, you need to deploy SecPol1.
What should you do first?
A. Enable Microsoft Defender for Cloud.
B. Create an Azure Management group.
C. Create an initiative.
D. Configure continuous export.
Show Answer
Correct Answer: A
Explanation: Before you can deploy security policies from Microsoft Defender for Cloud, the service must be enabled/onboarded for the relevant subscription or management scope. Creating initiatives is part of policy configuration after Defender for Cloud is available. A management group and continuous export are not prerequisite first steps.
Question 185
You are troubleshooting a security issue for an Azure Storage account.
You enable Azure Storage Analytics logs and archive it to a storage account.
What should you use to retrieve the diagnostics logs?
A. Azure Cosmos DB explorer
B. Azure Monitor
C. Microsoft Defender for Cloud
D. Azure Storage Explorer
Show Answer
Correct Answer: D
Explanation: Azure Storage Analytics logs are stored as blobs in a storage account when archived. To retrieve and inspect those log files, use Azure Storage Explorer, which can browse blob containers and download/view the logs. Azure Monitor is for monitoring and log analytics but not for directly retrieving archived Storage Analytics log blobs; Cosmos DB Explorer and Microsoft Defender for Cloud are unrelated.
Question 186
SIMULATION -
You need to ensure that the rg1lod1234578n1 Azure Storage account is encrypted by using a key stored in the KeyVault12345678 Azure key vault.
To complete this task, sign in to the Azure portal.
Explanation: Configure the storage account to use a customer-managed key stored in the specified Azure Key Vault. If prompted, ensure the storage account has the required managed identity and Key Vault permissions.
Question 187
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You use Microsoft Defender for Cloud for the centralized policy management of three Azure subscriptions.
You use several policy definitions to manage the security of the subscriptions.
You need to deploy the policy definitions as a group to all three subscriptions.
Solution: You create a policy initiative and an assignment that is scoped to the Tenant Root Group management group.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: A
Explanation: A policy initiative groups multiple policy definitions so they can be assigned together. Assigning the initiative at the Tenant Root Group management group scope applies it to all subscriptions beneath that management group, satisfying the requirement to deploy the policy definitions as a group to all three subscriptions.
Question 188
SIMULATION -
You need to create a web app named Intranet12345678 and enable users to authenticate to the web app by using Azure Active Directory (Azure AD).
To complete this task, sign in to the Azure portal.
Show Answer
Correct Answer: Create Web App: Intranet12345678
Authentication → Add identity provider → Microsoft (Azure AD) → Require authentication → Save.
Explanation: Create the App Service web app with the specified name, then enable built-in App Service Authentication using Microsoft (Azure Active Directory) as the identity provider and require authentication.
Question 189
DRAG DROP -
You have an Azure subscription that contains a Microsoft SQL server named Server1 and an Azure key vault named vault1. Server1 hosts a database named
DB1. Vault1 contains an encryption key named key1.
You need to ensure that you can enable Transparent Data Encryption (TDE) on DB1 by using key1.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:
Show Answer
Correct Answer: 1. Create a managed identity for Server1.
2. Configure permissions for vault1.
3. Add key1 to Server1.
4. Configure the TDE protector on Server1.
Explanation: For Azure SQL TDE with a customer-managed key in Azure Key Vault, the logical SQL server needs a managed identity, that identity must be granted access to the key in Key Vault, then the key is associated with the server, and finally the server TDE protector is configured to use that key.
Question 191
SIMULATION -
You need to ensure that when administrators deploy resources by using an Azure Resource Manager template, the deployment can access secrets in an Azure key vault named KV12345678.
To complete this task, sign in to the Azure portal.
Show Answer
Correct Answer: Open KV12345678 → Settings > Access configuration → Enable "Azure Resource Manager for template deployment" → Save.
Explanation: Enabling Azure Resource Manager for template deployment allows ARM template deployments to access secrets stored in the key vault.
Question 192
SIMULATION -
You plan to use Azure Disk Encryption for several virtual machine disks.
You need to ensure that Azure Disk Encryption can retrieve secrets from the KeyVault12345678 Azure key vault.
To complete this task, sign in to the Azure portal and modify the Azure resources.
Show Answer
Correct Answer: Open KeyVault12345678 → Settings > Access configuration (or Access policies, depending on portal version) → Enable 'Azure Disk Encryption for volume encryption' under advanced access policies → Apply/Save.
Explanation: Azure Disk Encryption requires the Key Vault to allow ADE access so it can retrieve encryption secrets.
Question 193
HOTSPOT -
You have an Azure subscription that contains an Azure key vault. The role assignments for the key vault are shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: Can create keys: Only User2
Can create secrets: Only User3
Explanation: Subscription Owner is a management-plane role and does not grant Key Vault data-plane permissions. Key Vault Crypto Officer at the vault scope can create/manage keys. Key Vault Secrets Officer at the vault scope can create/manage secrets. The Key Vault Administrator assignment for User4 is scoped only to an existing key object, so it does not allow creating new keys or secrets.
$19
Get all 437 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.