HOTSPOT -
Select the answer that correctly completes the sentence.
Hot Area:
Show Answer
Correct Answer: automatically respond to threats
Explanation: In Microsoft Sentinel, playbooks are built on Azure Logic Apps and are used to automate and orchestrate responses to alerts or incidents, enabling automatic actions when threats are detected.
Question 106
You need to collect and automatically analyze security events from Azure Active Directory (Azure AD).
What should you use?
A. Microsoft Sentinel
B. Azure Synapse Analytics
C. Azure AD Connect
D. Azure Key Vault
Show Answer
Correct Answer: A
Explanation: Microsoft Sentinel is a cloud-native SIEM/SOAR solution designed to collect, aggregate, and automatically analyze security events from sources such as Azure Active Directory. The other options do not provide security event monitoring and analysis capabilities.
Question 107
You need to start Azure Cloud Shell.
What should you use?
A. the Azure portal
B. Azure Command-Line Interface (CLI)
C. Azure PowerShell
D. an Azure Resource Manager (ARM) template
Show Answer
Correct Answer: A
Explanation: Azure Cloud Shell is launched directly from the Azure portal by selecting the Cloud Shell icon. It is not started from the standalone Azure CLI, PowerShell, or an ARM template; those tools run within Cloud Shell after it is started.
Question 108
HOTSPOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: Yes
Yes
No
Explanation: Private cloud provides dedicated resources and full control over configuration and security for the organization.
Hybrid cloud allows organizations to choose where workloads run (on‑premises or public cloud).
Public cloud scaling uses operational expenditure (pay‑as‑you‑go), not capital expenditure.
Question 109
HOTSPOT -
Select the answer that correctly completes the sentence.
Hot Area:
Show Answer
Correct Answer: excluded from the Service Level Agreements.
Explanation: Azure services in public preview are offered for evaluation only and do not carry formal SLAs, as stated in Azure preview terms.
Question 110
HOTSPOT -
Select the answer that correctly completes the sentence.
Hot Area:
Explanation: The scenario requires a user to provide more than one authentication input during sign-in. Among the options, only MFA describes using multiple authentication checks at sign-in. B2C, managed identities, and RBAC are unrelated to user sign-in verification.
Question 111
What should you use to evaluate whether your company's Azure environment meets regulatory requirements?
A. Azure Service Health
B. Azure Knowledge Center
C. Microsoft Defender for Cloud
D. Azure Advisor
Show Answer
Correct Answer: C
Explanation: Microsoft Defender for Cloud provides regulatory compliance assessments and security posture management, allowing you to evaluate whether your Azure environment meets industry standards and regulatory requirements. The other options do not offer compliance evaluation capabilities.
Question 112
You have an Azure subscription.
You need to review your secure score.
What should you use?
A. Azure Monitor
B. Azure Advisor
C. Help + support
D. Microsoft Defender for Cloud
Show Answer
Correct Answer: D
Explanation: The secure score for an Azure subscription is provided by Microsoft Defender for Cloud. Defender for Cloud continuously assesses security posture and presents a Secure Score with recommendations to improve it. Azure Monitor, Azure Advisor, and Help + support do not provide the Secure Score feature.
Question 113
How many copies of data are maintained by an Azure Storage account that uses locally-redundant storage (LRS)?
A. 3
B. 4
C. 6
D. 9
Show Answer
Correct Answer: A
Explanation: Azure locally-redundant storage (LRS) maintains three synchronous copies of data within a single datacenter to protect against hardware failures. Therefore, the correct answer is 3.
Question 114
HOTSPOT -
Select the answer that correctly completes the sentence.
Hot Area:
Show Answer
Correct Answer: network security group (NSG)
Explanation: An NSG controls inbound and outbound traffic rules for Azure resources. To allow TCP port 8080 access to a virtual machine, you must add or modify an inbound rule in the associated NSG.
$19
Get all 428 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.