You have an on-premises server that runs Windows Server and contains a Microsoft SQL Server database named DB1.
You plan to migrate DB1 to Azure.
You need to recommend an encrypted Azure database solution that meets the following requirements:
• Minimizes the risks of malware that uses elevated privileges to access sensitive data
• Prevents database administrators from accessing sensitive data
• Enables pattern matching for server-side database operations
• Supports Microsoft Azure Attestation
• Uses hardware-based encryption
What should you include in the recommendation?
A. SQL Server on Azure Virtual Machines with virtualization-based security (VBS) enclaves
B. Azure SQL Database with virtualization-based security (VBS) enclaves
C. Azure SQL Managed Instance that has Always Encrypted configured
D. Azure SQL Database with Intel Software Guard Extensions (Intel SGX) enclaves
Show Answer
Correct Answer: D
Explanation: The requirements point to Always Encrypted with secure enclaves backed by Intel SGX in Azure SQL Database. Intel SGX provides hardware-based trusted execution, Microsoft Azure Attestation is supported, secure enclaves enable richer server-side operations such as pattern matching on encrypted data, and Always Encrypted prevents DBAs from accessing plaintext sensitive data while reducing exposure even from privileged malware.
Question 127
You have a Microsoft 365 tenant that contains two groups named Group1 and Group2.
You use Microsoft Defender XDR to manage the tenants of your company’s customers.
You need to ensure that the users in Group1 can perform security tasks in the tenant of each customer. The solution must meet the following requirements:
• The Group1 users must only be assigned the Security Operator role for the customer tenants.
• The users in Group2 must be able to assign the Security Operators role to the Group1 users for the customer tenants.
• The use of quest accounts must be minimized.
• Administrative effort must be minimized.
What should you include in the solution?
A. multi-user authorization (MUA)
B. Azure Lighthouse
C. Privileged Identity Management (PIM)
D. Microsoft Entra B2B collaboration
Show Answer
Correct Answer: B
Explanation: Azure Lighthouse is designed for cross-tenant delegated administration, allowing a managing tenant to administer customer tenants without creating guest accounts for each customer. It supports assigning built-in roles such as Security Operator to delegated users and allows delegated administrators with appropriate permissions to manage those assignments, minimizing guest accounts and administrative effort. MUA is for approval workflows, PIM is primarily for privileged access management rather than cross-tenant delegation, and Entra B2B relies on guest accounts.
Question 128
HOTSPOT -
You have a Microsoft Entra tenant that is linked to a Microsoft 365 subscription and an Azure subscription. The tenant contains service principals that are used to access applications in the Azure subscription.
You need to recommend a solution to detect risky sign-ins and other risky activities performed by the service principals in the tenant. The solution must minimize costs.
What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Service: Microsoft Entra ID Protection
License type: Microsoft Entra Workload ID Premium
Explanation: Risk detection for service principals (workload identities) is provided by Microsoft Entra ID Protection. Viewing risky workload identities and workload identity detections requires Microsoft Entra Workload ID Premium, which is the targeted and lower-cost licensing compared to broader identity licenses.
Question 129
You have an on-premises network that has several legacy applications. The applications perform LDAP queries against an existing directory service.
You are migrating the on-premises infrastructure to a cloud-only infrastructure.
You need to recommend an identity solution for the infrastructure that supports the legacy applications. The solution must minimize the administrative effort to maintain the infrastructure.
Which identity service should you include in the recommendation?
A. Microsoft Entra External ID
B. Microsoft Entra Domain Services
C. Microsoft Entra ID
D. Active Directory Domain Services (AD DS)
Show Answer
Correct Answer: B
Explanation: Microsoft Entra Domain Services provides managed domain services including LDAP, Kerberos, NTLM, domain join, and Group Policy compatibility for legacy applications without requiring you to deploy and manage domain controllers. This best supports legacy LDAP-dependent applications while minimizing administrative overhead in a cloud-only environment.
Question 130
You have an Azure subscription that contains 100 virtual machines, a virtual network named VNet1, and 20 users. The virtual machines run Windows Server and are connected to VNet1. The users work remotely and access Azure resources from Linux workstations.
You need to ensure that the users can connect to the virtual machines from the workstations by using Secure Shell (SSH). The solution must meet the following requirements:
• Ensure that the users authenticate by using their Microsoft Entra credentials.
• Prevent the users from transferring files from the virtual machines by using SSH.
• Prevent the users from directly accessing the virtual machines by using the public IP address of the virtual machines.
What should you include in the solution?
A. Azure NAT Gateway
B. just-in-time (JIT) VM access
C. Azure Bastion
D. Point-to-Site (P2S) VPN
Show Answer
Correct Answer: C
Explanation: Azure Bastion supports native SSH access to Azure VMs without exposing public IP access. It integrates with Microsoft Entra ID authentication for supported SSH scenarios and provides a controlled proxy connection rather than direct VM access. Bastion's SSH session does not support SCP/SFTP file transfer, satisfying the requirement to prevent file transfers over SSH. NAT Gateway only provides outbound connectivity, JIT still relies on public access, and P2S VPN does not prevent direct public IP access or file transfers.
Question 131
You have an on-premises app named App1.
Remote users access App1 by using VPN connections.
You have a third-party software as a service (SaaS) app named App2.
You need to deploy Global Secure Access to manage access to App1 and App2.
What should you use for each app?
A. Microsoft Entra Private Access for App2 and Microsoft Entra Internet Access for App1
B. Microsoft Entra Private Access for App1 and Microsoft Entra Internet Access for App2
C. Microsoft Entra Internet Access for App1 and App2
D. Microsoft Entra Private Access for App1 and App2
Show Answer
Correct Answer: B
Explanation: Microsoft Entra Private Access is designed to provide secure access to private, on-premises applications without requiring a traditional VPN. Microsoft Entra Internet Access is intended to secure access to internet and SaaS applications. Therefore, use Private Access for the on-premises App1 and Internet Access for the SaaS App2.
Question 132
You have a Microsoft 365 tenant that uses Microsoft SharePoint Online and Microsoft Purview. Microsoft Purview has a sensitivity
label named Label1 that is applied to the files stored on SharePoint Online sites.
You need to recommend a Microsoft Purview Data Loss Prevention (DLP) policy that meets the following requirements:
• Prevents users from uploading the files to third-party external websites
• Allows users to upload the files to Microsoft OneDrive for Business
To which location should you apply the DLP policy?
A. Devices
B. OneDrive accounts
C. SharePoint sites
D. Microsoft Defender for Cloud Apps
Show Answer
Correct Answer: A
Explanation: Apply the DLP policy to the Devices location (Endpoint DLP). Endpoint DLP can prevent users from uploading files with a specified sensitivity label to third-party websites while allowing uploads to trusted Microsoft services such as OneDrive for Business. SharePoint or OneDrive locations govern content at rest in those services rather than controlling web uploads from endpoints, and Microsoft Defender for Cloud Apps is a separate product rather than a Purview DLP policy location.
Question 133
You have a Microsoft Entra tenant named contoso.com and use Microsoft Intune. Each user in contoso.com has a Microsoft Entra ID P1 license and a Windows 11 device that has the Global Secure Access client deployed.
You plan to deploy the following configuration of Microsoft Entra Internet Access:
• Enable a baseline profile.
• Create a security profile named Profile1 that has a priority of 300 and contains a single web content filtering policy named
WCFPolicy1. Configure WCFPolicy1 as follows:
o Set Action to allow.
o Include a single rule that has a fully qualified domain name (FQDN) destination of *.adatum.com.
• Link Profile1 to a Conditional Access policy named CAPolicy1, apply CAPolicy1 to all users, and grant access unless a user's device is noncompliant.
You need to evaluate the impact of the planned deployment on traffic to the following resources:
• https://www.adatum.com:8433
• https://www.fabrikam.com
Which two traffic scenarios will occur? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. Traffic to https://www.fabrikam.com will be allowed from all the devices.
B. Traffic to https://www.adatum.com:8433 will be blocked from all the devices.
C. Traffic to https://www.adatum.com:8433 will be allowed from all the devices.
D. Traffic to https://www.fabrikam.com will be allowed from compliant devices only.
E. Traffic to https://www.adatum.com:8433 will be allowed from compliant devices only.
F. Traffic to https://www.fabrikam.com will be blocked from noncompliant devices only.
Show Answer
Correct Answer: A, E
Explanation: The security profile with an allow rule for *.adatum.com applies only when targeted through its linked Conditional Access policy, which grants access only from compliant devices. Thus traffic to https://www.adatum.com:8433 matches the FQDN wildcard and is allowed only from compliant devices. Fabrikam is not targeted by the linked security profile; the enabled baseline profile has no described blocking rule, so traffic to https://www.fabrikam.com remains allowed for all devices.
Sources:
https://learn.microsoft.com/en-us/entra/global-secure-access/concept-internet-access
https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-configure-web-content-filtering
Question 134
You have a Microsoft 365 subscription that contains 1,000 Microsoft Exchange Online mailboxes.
Incoming email from the internet is scanned for security threats by using a third-party cloud service.
You are evaluating whether to replace the third-party service with Microsoft Defender for Office 365.
What should you modify to ensure that all the incoming email is scanned by Defender for Office 365 only?
A. the accepted domains in Exchange Online
B. the DNS records
C. the Exchange Online transport rule
D. the Exchange Online connectors
Show Answer
Correct Answer: B
Explanation: To have Microsoft Defender for Office 365 perform the inbound filtering instead of a third-party cloud filtering service, inbound internet mail must be delivered directly to Exchange Online Protection (EOP), which underpins Defender for Office 365. This is achieved by changing the public MX/DNS records to point to Microsoft 365 (yourdomain.mail.protection.outlook.com). Accepted domains, transport rules, and connectors do not change where internet senders initially deliver mail.
Question 135
You have an Azure subscription that contains multiple network security groups (NSGs), multiple virtual machines, and an Azure Bastion host named bastion1.
Several NSGs contain rules that allow direct RDP access to the virtual machines by bypassing bastion1.
You need to ensure that the virtual machines can be accessed only by using bastion1. The solution must prevent the use of NSG rules to bypass bastion1.
What should you include in the solution?
A. Azure Virtual Network Manager security admin rules
B. Azure Virtual Network Manager connectivity configurations
C. Azure Firewall application rules
D. Azure Firewall network rules
Show Answer
Correct Answer: A
Explanation: Azure Virtual Network Manager security admin rules are enforced before NSG rules and can centrally allow or deny traffic across managed virtual networks. This prevents NSG rules from being used to re-enable direct RDP access that bypasses Azure Bastion. Connectivity configurations manage network topology, not traffic filtering, and Azure Firewall rules require deploying and routing through Azure Firewall, which is not part of the scenario.
$19
Get all 314 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.