HOTSPOT
-
You have a Microsoft Entra tenant that contains the user shown in the following table.
You configure a Conditional Access policy that has the following settings:
• Name:CAPolicy1
• Assignments
o Users or workload identities: Group1
o Target resources: All cloud apps
• Access controls
o Grant access: Require multifactor authentication
From Microsoft Authenticator settings for the tenant, the Enable and Target settings are configured as shown in the Enable and Target exhibit. (Click the Enable and Target tab.)
From Microsoft Authenticator settings for the tenant, the Configure settings are configured as shown in the Configure exhibit. (Click the Configure tab.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
Yes
Explanation: Conditional Access requiring MFA applies only to Group1. Number matching is configured for Group2 in Microsoft Authenticator. User1 is not in Group2, so number matching is not required. User2 is in Group2, so number matching is required. User3 is also in Group2; although CA MFA does not target them, whenever Microsoft Authenticator push MFA is used, number matching is required.
Question 13
HOTSPOT
-
You have a Microsoft Entra tenant that contains the groups shown in the following table.
From the Azure portal, you configure a group expiration policy that has a lifetime of 180 days.
Which groups will be deleted after 180 days of inactivity, and what is the maximum amount of time you have to restore a deleted group? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Group3 only
30 days
Explanation: Group expiration policies apply only to Microsoft 365 groups, not security or mail-enabled security groups. Deleted Microsoft 365 groups can be restored for up to 30 days.
Question 14
You have a Microsoft Entra tenant named contoso.com.
You collaborate with a partner organization that has a Microsoft Entra tenant named fabrikam.com.
You need to create an allow list of cloud apps from fabrikam.com that can be used by the users in contoso.com.
What should you do for contoso.com in the Microsoft Entra admin center?
A. From Inbound access settings in Cross-tenant access settings, configure the B2B direct connect settings.
B. From External collaboration settings, configure the Collaboration restrictions settings.
C. From External collaboration settings, configure the Guest invite settings.
D. From Outbound access settings in Cross-tenant access settings, configure the B2B collaboration settings.
Show Answer
Correct Answer: D
Explanation: To allow users in contoso.com to access resources and cloud applications in the external fabrikam.com tenant, configure Cross-tenant access settings for Outbound access. Outbound B2B collaboration settings govern what your internal users can access in an external Microsoft Entra organization and support allowing specific applications. Inbound settings control external users accessing your tenant, while External collaboration settings manage invitation and collaboration policies rather than per-partner app allow lists.
Question 15
You have a Microsoft Entra tenant that contains three users named User1, User2, and User3.
You configure Microsoft Entra Password Protection as shown in the following exhibit.
The users perform the following tasks:
• User1 attempts to reset her password to C0nt0s0.
• User2 attempts to reset her password to F@brikamHQ.
• User3 attempts to reset her password to Pr0duct123.
Which password reset attempts fail?
A. User1 only
B. User2 only
C. User3 only
D. User1 and User 3 only
E. User1, User2, and User3
Show Answer
Correct Answer: E
Explanation: Microsoft Entra Password Protection normalizes passwords (for example, common character substitutions such as 0→o and @→a) and checks them against the global and configured custom banned password lists. If the exhibit's custom banned list contains the corresponding terms (Contoso, FabrikamHQ, Product), then C0nt0s0, F@brikamHQ, and Pr0duct123 all match banned terms after normalization and do not achieve an acceptable score, so each password reset is rejected.
Question 17
You have an Azure subscription that uses Microsoft Defender for Cloud.
You have an Amazon Web Services (AWS) account.
You need to add the AWS account to Defender for Cloud.
What should you do first?
A. From Defender for Cloud, configure the Environment settings.
B. From the AWS account, enable a security hub.
C. From Defender for Cloud, configure the Security solutions settings.
D. From the Azure portal, add the AWS enterprise application.
Show Answer
Correct Answer: A
Explanation: To onboard an AWS account into Microsoft Defender for Cloud using the native connector, the first step is to go to Defender for Cloud and open Environment settings, then choose Add environment > Amazon Web Services. This initiates the connection and onboarding workflow. Enabling AWS Security Hub can be part of recommended protections, but it is not the first step. Security solutions settings and adding an Azure enterprise application are not used as the initial onboarding action.
Question 18
You are testing an Azure Kubernetes Service (AKS) cluster. The cluster is configured as shown in the exhibit. (Click the Exhibit tab.)
You plan to deploy the cluster to production. You disable HTTP application routing.
You need to implement application routing that will provide reverse proxy and TLS termination for AKS services by using a single IP address.
What should you do?
A. Create an AKS Ingress controller.
B. Create an Azure Standard Load Balancer.
C. Install the container network interface (CNI) plug-in.
D. Create an Azure Basic Load Balancer.
Show Answer
Correct Answer: A
Explanation: An AKS Ingress controller is designed to provide HTTP/HTTPS application routing, reverse proxy functionality, and TLS termination for Kubernetes services behind a single external IP address. Azure Load Balancers operate at Layer 4 and do not provide TLS termination or URL-based routing. Installing the Azure CNI plugin affects networking but does not implement application routing.
Question 19
You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains the subnets shown in the following table.
You create the virtual machines shown in the following table.
You plan to configure just-in-time (JIT) VM access for the virtual machines. The solution must minimize administrative effort.
For which virtual machines can you configure JIT VM access?
A. VM1 only
B. VM1 and VM2 only
C. VM1 and VM3 only
D. VM1, VM2, and VM3 only
E. VM1, VM2, VM3, and VM4
Show Answer
Correct Answer: D
Explanation: Just-in-time VM access in Microsoft Defender for Cloud requires the VM to be protected by a Network Security Group (NSG) associated either with the subnet or the VM's network interface. VMs in subnets with an NSG qualify, and a VM with an NSG on its NIC also qualifies. A VM without any applicable NSG cannot be configured for JIT.
Question 20
You have an Azure subscription that uses Microsoft Defender for Cloud. The subscription contains an instance of Azure Database for PostgreSQL.
You need to ensure that an email alert is triggered when a suspected brute force attack on the database is detected. The solution must minimize administrative effort.
What should you configure?
A. the Azure Monitor activity log
B. an Azure Monitor alert rule
C. Microsoft Defender for open-source relational databases
D. the PostgreSQL Audit extension (pgAudit)
Show Answer
Correct Answer: C
Explanation: Microsoft Defender for open-source relational databases provides built-in threat protection for Azure Database for PostgreSQL, including detection of suspected brute force attacks and generation of security alerts with email notifications through Microsoft Defender for Cloud. This requires the least administrative effort compared to creating custom Azure Monitor alerts or configuring pgAudit, which only provides audit logs rather than threat detection.
Question 21
You have an on-premises network.
You have an Azure subscription that contains the resources shown in the following table.
You plan to deploy a Site-to-Site (S2S) VPN between the on-premises network and VNet1.
You need to recommend an Azure VPN Gateway SKU that meets the following requirements:
• Supports 1-Gbps throughput
• Minimizes costs
What should you recommend?
A. VpnGw1
B. VpnGw2
C. VpnGw1AZ
D. VpnGw2AZ
Show Answer
Correct Answer: B
Explanation: VpnGw1 supports up to approximately 650 Mbps aggregate throughput, which does not meet the 1-Gbps requirement. VpnGw2 supports up to 1 Gbps and is less expensive than the availability zone-enabled VpnGw2AZ. Since zone redundancy is not a stated requirement, VpnGw2 minimizes cost while meeting the throughput requirement.
Question 22
HOTSPOT
-
You have an Azure subscription that contains a virtual machine named VM1.
You have a network security group (NSG) named NSG1 that is associated to the network interface of VM1 and is configured as shown in the following exhibit.
Just-in-time (JIT) VM access is enabled on VM1 and has the following configurations:
• Management ports: 3389, 22
• Maximum time range: 3 hours
• Allowed source IP addresses: Any
You activate the JIT rule and connect to VM1 by using SSH.
For each of the following statements, select Yes if the statement is true, otherwise select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
No
No
Explanation: Existing explicit allow rules on a managed port are not overridden by JIT; the JIT window remains active for its duration so you can reconnect within it; expiration blocks new connections but does not terminate an already established SSH session.
$19
Get all 437 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.