HOTSPOT
-
You plan to deploy a custom policy initiative for Microsoft Defender for Cloud.
You need to identify all the resource groups that have a Delete lock.
How should you complete the policy definition? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: The policy targets resource groups, so the resource type is Microsoft.Resources/subscriptions/resourceGroups. With auditIfNotExists, existenceCondition checks that a Microsoft.Authorization/locks resource exists with level equal to CanNotDelete.
Question 78
You have an Azure subscription that uses Microsoft Defender for Cloud.
You have an Amazon Web Services (AWS) account named AWS1 that is connected to Defender for Cloud.
You need to ensure that AWS1 uses AWS Foundational Security Best Practices. The solution must minimize administrative effort.
What should you do in Defender for Cloud?
A. Assign a built-in compliance standard.
B. Create a new custom standard.
C. Assign a built-in assessment.
D. Create a new custom assessment.
Show Answer
Correct Answer: A
Explanation: AWS Foundational Security Best Practices is a built-in regulatory compliance standard in Microsoft Defender for Cloud for connected AWS accounts. To enable it with minimal administrative effort, assign the built-in compliance standard rather than creating custom standards or assessments. Built-in assessments are individual checks, not the full benchmark.
Question 79
HOTSPOT
-
You have an Azure subscription that contains a Microsoft Defender External Attack Surface Management (Defender EASM) resource named EASM1. EAMS1 contains the inventory assets shown in the following table.
Which assets are scanned daily, and which assets will display in the default dashboard charts? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Scanned daily: VM1 only
Display in the default dashboard charts: VM1 only
Explanation: Only assets in the Approved Inventory state are explicitly scanned daily and included in default dashboard charts. Dependency and Monitor Only assets are not shown by default, and Candidate assets are scanned only during discovery.
Question 80
HOTSPOT
-
You have an Azure subscription that uses Microsoft Defender for Cloud.
You plan to use the Secure Score Over Time workbook.
You need to configure the Continuous export settings for the Defender for Cloud data.
Which two settings should you configure? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: The Secure Score Over Time workbook requires continuous export to a Log Analytics workspace with Security recommendations and Secure score exported, and both Streaming updates and Snapshots enabled so historical trend data is available.
Question 81
You have an Azure subscription.
You plan to map an online infrastructure and perform vulnerability scanning for the following:
• ASNs
• Hostnames
• IP addresses
• SSL certificates
What should you use?
A. Microsoft Defender for Cloud
B. Microsoft Defender External Attack Surface Management (Defender EASM)
C. Microsoft Defender for Identity
D. Microsoft Defender for Endpoint
Show Answer
Correct Answer: B
Explanation: Microsoft Defender External Attack Surface Management (Defender EASM) is designed to discover, map, and continuously assess an organization's internet-facing assets, including ASNs, hostnames, IP addresses, and SSL certificates, and perform external attack surface and vulnerability assessment.
Question 82
You have an Azure subscription that uses Microsoft Defender for Cloud.
You have accounts for the following cloud services:
• Alibaba Cloud
• Amazon Web Services (AWS)
• Google Cloud Platform (GCP)
What can you add to Defender for Cloud?
A. AWS only
B. Alibaba Cloud and AWS only
C. Alibaba Cloud and GCP only
D. AWS and GCP only
E. Alibaba Cloud, AWS, and GCP
Show Answer
Correct Answer: D
Explanation: Microsoft Defender for Cloud supports multicloud onboarding for Amazon Web Services (AWS) and Google Cloud Platform (GCP). It does not support onboarding Alibaba Cloud as a connected multicloud environment.
Question 83
SIMULATION
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Azure Username:
Azure Password: Gp0Ae4@!Dg
-
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance: 28681041
-
You need to configure Azure to allow RDP connections from the Internet to a virtual machine named VM1. The solution must minimize the attack surface of VM1.
To complete this task, sign in to the Azure portal.
Show Answer
Correct Answer: Enable Just-in-Time (JIT) VM access for VM1 in Microsoft Defender for Cloud, configuring RDP (TCP 3389) as a JIT-controlled port.
Explanation: JIT keeps RDP closed by default and opens it only for approved, time-limited requests, minimizing the VM's Internet attack surface while still allowing RDP access when needed.
Question 84
SIMULATION
-
You need to create a new Azure AD directory named 28681041.onmicrosoft.com. The new directory must contain a new user named
.
To complete this task, sign in to the Azure portal.
Show Answer
Correct Answer: Cannot be completed here. In the Azure portal, create a new Microsoft Entra ID (Azure AD) directory named 28681041.onmicrosoft.com, then create the specified new user in that directory.
Explanation: This is a hands-on Azure portal simulation that requires access to the Azure environment, which cannot be performed within this chat.
Question 85
SIMULATION
-
You need to ensure that a user named user2-28681041 can manage the properties of the virtual machines in the RG1lod28681041 resource group. The solution must use the principle of least privilege.
To complete this task, sign in to the Azure portal.
Show Answer
Correct Answer: Assign the Virtual Machine Contributor role to user2-28681041 at the RG1lod28681041 resource group scope.
Explanation: Virtual Machine Contributor allows management of virtual machine properties without granting broader resource group ownership, satisfying least privilege.
Question 86
SIMULATION
-
You need to prevent HTTP connections to the rg1lod28681041n1 Azure Storage account.
To complete this task, sign in to the Azure portal.