You have an Azure subscription. The subscription contains 100 virtual machines that run Linux on Windows Server. The subscription uses Microsoft Defender for Servers Plan 1.
You need to recommend a solution to identify and remediate virtual machines that have the following characteristics:
• Are NOT onboarded to Defender for Servers
• Are missing critical updates
• Have risky apps installed
The solution must minimize administrative effort.
What should you include in the recommendation?
A. Microsoft Defender External Attack Surface Management (Defender EASM)
B. Microsoft Defender Vulnerability Management
C. Microsoft Defender Threat Intelligence (Defender TI)
D. Microsoft Intune Advanced Analytics
Show Answer
Correct Answer: B
Explanation: Microsoft Defender Vulnerability Management provides centralized visibility across virtual machines to identify whether machines are onboarded to Defender for Servers, assess missing critical OS and software updates, and detect risky or vulnerable applications. It also supports built-in remediation workflows and recommendations, minimizing administrative effort compared to the other options, which do not provide comprehensive vulnerability assessment and remediation for servers.
Question 17
HOTSPOT
-
Your company has offices in New York City and London. The London office contains an on-premises app named App1.
You have a Microsoft Entra tenant named contoso.com that is hosted in North America.
You plan to manage access to App1 for the users in the London office by using Microsoft Entra Private Access. You will deploy Private Access by performing the following actions in the London office:
• Deploy Microsoft Entra application proxy connectors.
• Provision an ExpressRoute circuit to the closest peering location.
You need to optimize the network for the planned deployment. The solution must meet the following requirements:
• Maximize redundancy for connectivity to App1.
• Minimize network latency when accessing App1.
• Maximize security.
• Minimize costs.
What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Two connectors to a new connector group
ExpressRoute with Microsoft peering
Explanation: Using two connectors in a dedicated connector group provides local high availability and redundancy for App1 while keeping latency low for London users. ExpressRoute with Microsoft peering optimizes connectivity from the connectors to Microsoft Entra Private Access over the Microsoft backbone, maximizing security and performance without the extra cost of the premium add-on.
Question 18
You have an Azure subscription. The subscription contains 200 virtual machines that run Windows Server 2022 and are protected by using Microsoft Defender for Servers Plan 1. You have an Amazon Web Services (AWS) subscription.
To the AWS subscription, you plan to deploy 100 virtual machines that run Windows Server 2022.
You need to recommend which agent to deploy to the virtual machines in the AWS subscription. The solution must meet the following requirements:
• Provide consistent workload protection across all cloud platforms.
• Minimize the number of agents deployed to each virtual machine.
What should you recommend?
A. the log Analytics agent
B. the Azure Connected Machine agent
C. the Microsoft Defender for Endpoint agent
D. the Azure Monitor Agent
Show Answer
Correct Answer: C
Explanation: To provide consistent workload protection across Azure and AWS while minimizing the number of agents, deploy the Microsoft Defender for Endpoint (MDE) agent. Defender for Servers Plan 1 integrates with MDE and supports direct onboarding of non-Azure (including AWS) Windows Server machines, giving unified threat protection without requiring additional agents like Azure Arc, Log Analytics, or Azure Monitor.
Question 18
HOTSPOT
-
You have a Microsoft 365 subscription.
Microsoft Purview is configured to protect data in only Microsoft Exchange Online and SharePoint Online. Custom sensitive information types (SITs) have been created to identify confidential data.
You discover that users access third-party generative AI websites from their Windows devices. You need to recommend a solution to block AI prompts that contain confidential data and scan the AI prompts submitted to the third-party websites.
What should you recommend for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Data loss prevention
Onboard each device to Microsoft Purview
Explanation: Microsoft Purview Data Loss Prevention can inspect and block sensitive content in outbound web activity, including AI prompts sent to third-party sites. Onboarding Windows devices to Microsoft Purview (endpoint DLP) enables inspection and scanning of prompts entered from those devices using custom sensitive information types.
Question 19
You have a Microsoft 365 tenant.
You have an Azure subscription that contains Azure App Service web apps. The apps have the following characteristics:
• The apps use third-party and open-source components.
• The apps were developed by using C#, Python, and Java.
• The app deployment process is managed by using Azure DevOps.
• The source code for the apps is stored in GitHub Enterprise Cloud repositories and protected by using GitHub Advanced Security.
You need to reduce the risk of supply chain attacks during the application lifecycle.
What should you implement?
A. secret scanning
B. Dependabot alerts
C. app governance in Microsoft Defender for Cloud Apps
D. NuGet Audit
Show Answer
Correct Answer: B
Explanation: Reducing supply chain attack risk focuses on securing third‑party and open‑source dependencies throughout development and deployment. Dependabot alerts continuously monitor GitHub repositories for known vulnerabilities in dependencies across multiple languages (C#, Python, Java), alerting on insecure components and automatically proposing updates via pull requests. This directly addresses supply chain risks in the application lifecycle. The other options either focus on secrets exposure, SaaS governance, or a single ecosystem (NuGet) and are less comprehensive for this scenario.
Question 19
HOTSPOT
-
You are designing new Azure applications based on security best practices from the Microsoft Cloud Adoption Framework for Azure. Each application will be deployed to a dedicated and secure environment that will contain isolated instances of the following key Azure security resources:
• Azure Key Vault
• Virtual networks
• An Azure subscription
• Azure Policy assignments
• Network security groups (NSGs)
• Role-based access control (RBAC) assignments
You need to recommend which type of environment and which module to use to deploy the applications. The solution must use infrastructure as code (IaC) to deploy each application environment.
What should you recommend? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Environment type:
Landing zone
Module:
Azure Resource Manager (ARM) or Bicep
Explanation: The Cloud Adoption Framework recommends deploying isolated, secure application environments as Azure landing zones. Landing zones include subscriptions, networking, policy, RBAC, and security resources. ARM or Bicep are the native IaC modules aligned with CAF reference implementations for deploying and governing these environments.
Question 20
DRAG DROP
-
You have a Microsoft 365 subscription that contains a Microsoft SharePoint Online site named Site1.
You have a Conditional Access policy named Policy1 that only allows workload identities from trusted locations to access SharePoint Online.
You plan to move all business-sensitive information to Site1.
You need to ensure that CAPolicy1 applies to Site1 only.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
NOTE: More than one order of answer choices is correct. You will receive credit for any of the correct orders you select.
Show Answer
Correct Answer: For the Microsoft Entra tenant, create an authentication context.
Modify the target resources of Policy1.
Configure a sensitivity label for Site1.
Explanation: Authentication contexts allow Conditional Access to target specific SharePoint sites. Create the authentication context, scope Policy1 to that context (target resources), then apply the context to Site1 via a sensitivity label so the policy applies only to that site.
Question 20
You have a Microsoft 365 subscription that contains 500 users. Each user is assigned a Microsoft 365 E5 license and uses a Windows device.
Microsoft Purview data loss prevention (DLP) policies are applied to Microsoft Exchange Online email and SharePoint Online sites.
You plan to monitor the usage of third-party generative AI apps by using Microsoft Purview Data Security Posture Management for AI (DSPM for AI).
What should you do first?
A. Enable Microsoft Purview insider risk management for all the users.
B. Onboard all endpoint devices to Microsoft Purview.
C. Configure Microsoft Purview data connectors for the generative AI apps.
D. License all the users for Microsoft 365 Copilot.
Show Answer
Correct Answer: B
Explanation: Microsoft Purview DSPM for AI relies on endpoint visibility to detect and analyze interactions with third-party generative AI apps. Before monitoring usage, devices must be onboarded so Purview can collect endpoint signals. Other options (insider risk, data connectors, Copilot licensing) are not prerequisites for initial DSPM for AI monitoring.
Question 21
You have a Microsoft Entra tenant named contoso.onmicrosoft.com and an Azure subscription named Sub1.
You need to implement Microsoft Entra Verified ID by using Quick Verified ID setup.
What should you create first?
A. a security principal in contoso.onmicrosoft.com
B. a custom domain in contoso.onmicrosoft.com
C. a user-assigned managed identity in Sub1
D. an Azure key vault in Sub1
Show Answer
Correct Answer: B
Explanation: Quick Verified ID setup requires a verified custom domain in the Microsoft Entra tenant to establish trust and issue verifiable credentials. You must add and verify a custom domain before the Quick setup can proceed; the other resources are created or configured later as part of the process.
Question 21
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You need to recommend a security solution that meets the following requirements:
• Automatically identifies and stops external, brute force attacks against accounts in the subscription
• Automatically identifies and stops external attacks that use an internal account to exfiltrate data from Microsoft SharePoint Online sites in the subscription
What should you include in the recommendation for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Automatically identifies and stops external, brute force attacks against accounts:
Microsoft Entra ID Protection
Automatically identifies and stops external attacks that use an internal account to exfiltrate data from SharePoint Online sites:
Microsoft Defender for Cloud Apps
Explanation: Microsoft Entra ID Protection detects and automatically responds to risky sign-ins and brute force attacks against identities. Microsoft Defender for Cloud Apps monitors user activity in SaaS apps like SharePoint Online and can detect and block data exfiltration using compromised internal accounts.
$19
Get all 316 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.