Microsoft

AZ-900 Free Practice Questions — Page 19

Question 198

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Hot Area:

Illustration for AZ-900 question 198
Show Answer
Correct Answer: Trust Center is part of the Azure Security Center: No Trust Center can only be accessed by users that have an Azure subscription: No Trust Center provides information about the Azure compliance offerings: Yes
Explanation:
Microsoft Trust Center is a public-facing portal, separate from Azure Security Center (now Microsoft Defender for Cloud). It is accessible without an Azure subscription and provides compliance and security information, including Azure compliance offerings.

Question 199

You have an Azure subscription. Where will you find details on the personal data collected by Microsoft, how Microsoft uses the data, and what the data is used for?

A. the Data Protection Addendum
B. the Microsoft Online Services Terms
C. the Microsoft Privacy Statement
D. Azure Security Center
Show Answer
Correct Answer: C
Explanation:
The Microsoft Privacy Statement specifically explains what personal data Microsoft collects, how it is used, and for what purposes. The Data Protection Addendum and Online Services Terms focus on contractual and compliance obligations, while Azure Security Center is a security management service, not a privacy disclosure document.

Question 200

Which resources can be used as a source for a Network security group inbound security rule?

A. Service Tags only
B. IP Addresses, Service tags and Application security groups
C. Application security groups only
D. IP Addresses only
Show Answer
Correct Answer: B
Explanation:
Azure Network Security Group inbound security rules allow the source to be defined using IP addresses (or CIDR ranges), Service Tags, or Application Security Groups. This capability is explicitly supported in NSG security rules and is documented by Microsoft. Therefore, the option that includes all three is correct.

Question 201

Who can use the Azure Total Cost of Ownership (TCO) calculator?

A. billing readers for an Azure subscription only
B. owners for an Azure subscription only
C. anyone
D. all users who have an account in Azure Active Directory (Azure AD) that is linked to an Azure subscription only
Show Answer
Correct Answer: C
Explanation:
The Azure Total Cost of Ownership (TCO) calculator is a publicly available, web-based tool. It does not require an Azure subscription, specific roles, or Azure AD access. Therefore, anyone can use it to estimate and compare on-premises versus Azure costs.

Question 202

HOTSPOT - To complete the sentence, select the appropriate option in the answer area. Hot Area:

Illustration for AZ-900 question 202
Show Answer
Correct Answer: automatically respond to threats.
Explanation:
Azure Sentinel playbooks use Azure Logic Apps to automate and orchestrate responses to alerts or incidents, enabling automatic actions when threats are detected.

Question 203

Your company has an Azure subscription that contains resources in several regions. You need to create the Azure resource that must be used to meet the policy requirement. What should you create?

A. a read-only lock
B. an Azure policy
C. a management group
D. a reservation
Show Answer
Correct Answer: B
Explanation:
A policy requirement in Azure is implemented by creating an Azure Policy, which defines and enforces rules across resources and regions. The other options do not define or enforce compliance rules: locks prevent changes, management groups organize subscriptions, and reservations are for cost savings.

Question 204

You have an Azure virtual machine named VM1. You plan to encrypt VM1 by using Azure Disk Encryption. Which Azure resource must you create first?

A. an Azure Storage account
B. an Azure Key Vault
C. an Azure Information Protection policy
D. an Encryption key
Show Answer
Correct Answer: B
Explanation:
Azure Disk Encryption relies on Azure Key Vault to store and manage the disk encryption keys and secrets. Before enabling disk encryption on an existing virtual machine, a Key Vault must be created and configured. Other options, such as a storage account or encryption key, are either already associated with the VM or are managed through Key Vault.

Question 205

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Hot Area:

Illustration for AZ-900 question 205
Show Answer
Correct Answer: Yes Yes Yes
Explanation:
Azure AD can manage access to on-premises applications via Azure AD Application Proxy. Azure AD provides single sign-on (SSO) for cloud and on-premises apps. iOS devices can be registered (not joined) in Azure AD.

Question 206

HOTSPOT - To complete the sentence, select the appropriate option in the answer area. Hot Area:

Illustration for AZ-900 question 206
Show Answer
Correct Answer: Network Address Translation (NAT) rules
Explanation:
Inbound access from the internet to a server in a virtual network is enabled by Azure Firewall DNAT, which translates a public IP and port to a private IP and port inside the VNet. NAT rules are evaluated first for inbound traffic.

Question 207

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Hot Area:

Illustration for AZ-900 question 207
Show Answer
Correct Answer: 1) No 2) Yes 3) No
Explanation:
Archive tier can only be set at the blob level, not the storage account level. Hot tier is intended for data that is accessed and modified frequently. Cool tier is for infrequently accessed, short-term data; long-term backups are better suited to Archive.

$19

Get all 428 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.