You have a Microsoft 365 E5 subscription and an Azure subscription.
You need to recommend a solution to enforce the Zero Trust principle of explicit verification for the subscriptions. The solution must be based on Zero Trust guidance in the Microsoft Cybersecurity Reference Architectures (MCRA).
What should you include in the recommendation?
A. Conditional Access
B. Microsoft Defender for Identity
C. Microsoft Defender for Cloud
D. Microsoft Entra ID Identity Governance
Show Answer
Correct Answer: A
Explanation: Zero Trust explicit verification requires authenticating and authorizing access based on all available signals such as user identity, device health, location, and risk, as defined in the Microsoft Cybersecurity Reference Architectures. Microsoft Entra Conditional Access is the control that enforces these real-time authentication and authorization decisions across Microsoft 365 and Azure. Defender for Identity and Defender for Cloud provide security signals but do not enforce access, and Identity Governance focuses on lifecycle management rather than explicit verification.
Question 42
You have two Azure subscriptions named Sub1 and Sub2 that contain the vaults shown in the following table.
You need to design a multi-user authorization (MUA) solution for security operations on the vaults. The solution must meet the following requirements:
• RSVault1 and RSVault2 must require MUA for disabling soft delete, removing MUA protection, and disabling immutability.
• BackupVault1 and BackupVault2 must require MUA for disabling soft delete and removing MUA protection.
What is the minimum number of Resource Guard resources required?
A. 1
B. 2
C. 3
D. 4
Show Answer
Correct Answer: B
Explanation: A Resource Guard can protect multiple Recovery Services vaults and Backup vaults, even across subscriptions and tenants, but it must be in the same Azure region as the vaults it protects. In the given scenario, the vaults are spread across two regions, so a single Resource Guard cannot cover all of them. Therefore, one Resource Guard is required per region, resulting in a minimum of two Resource Guard resources.
Question 43
HOTSPOT
-
You have an Azure DevOps organization that is used to manage the development and deployment of internal apps to multiple Azure subscriptions.
You need to implement a DevSecOps strategy based on Microsoft Cloud Adoption Framework for Azure principles. The solution must meet the following requirements:
• All pull requests must be enforced.
• All deployments to production must be approved.
What should you include in the solution for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Protected branches
Environments
Explanation: Pull request enforcement in Azure DevOps is implemented through branch policies on protected branches. Mandatory approval for production deployments is implemented by using Azure DevOps Environments with pre-deployment approvals and checks.
Question 45
Your network contains an Active Directory Domain Services (AD DS) domain.
You need to ensure that the built-in administrator account for the domain can be used only for interactive sign-ins to domain controllers.
What should you configure?
A. the Protected Users group
B. authentication policies
C. the User Rights Assignment security policy settings
D. an authentication policy silo
Show Answer
Correct Answer: C
Explanation: The built-in domain Administrator account (RID 500) is exempt from authentication policies and authentication policy silos, so those cannot restrict where it can sign in. The Protected Users group also does not apply the needed restriction to this account. To ensure it can sign in only interactively on domain controllers, you must use User Rights Assignment in a GPO scoped to domain controllers (e.g., allow/deny interactive or RDP logon appropriately).
Question 46
HOTSPOT
-
You have a Microsoft Entra tenant named contoso.com. You have 30 Azure subscriptions that are linked to contoso.com. The tenant contains the management groups shown in the following table.
You need to design a governance solution to manage access to all the Azure Storage accounts across the subscriptions. The solution must meet the following requirements:
• Use custom role-based access control (RBAC) to provide granular access to control plane and data plane operations.
• Minimize administrative effort.
At which scope should you assign the roles, and what is the minimum number of assignments per role? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Scope:
/providers/Microsoft.Management/managementGroups/<Entra Tenant GUID>
Minimum number of assignments:
1
Explanation: Assigning the custom RBAC role at the root management group scope applies it to all child management groups and subscriptions. This provides centralized governance across all storage accounts while minimizing administrative effort by requiring only a single role assignment per role.
Question 47
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Serve1 that runs Windows Server 2022.
You have an Azure subscription that is linked to a hybrid Microsoft Entra tenant and contains a user named User1. User1 works remotely.
You need to ensure that User1 can establish RDP connections to Server1 via the internet. The solution must ensure that User1 authenticates by using multifactor authentication (MFA).
What should you include in the solution?
A. Windows Admin Center
B. Microsoft Entra Internet Access
C. Azure Bastion
D. Microsoft Entra Private Access
Show Answer
Correct Answer: D
Explanation: User1 must connect from the internet to an on‑premises server and be required to authenticate with MFA. Azure Bastion applies only to Azure VMs, not on‑premises servers. Windows Admin Center does not provide secure internet exposure with MFA. Microsoft Entra Internet Access is for outbound SaaS access. Microsoft Entra Private Access (part of Entra Global Secure Access) publishes on‑premises resources like RDP via application proxy and integrates with Conditional Access, allowing MFA enforcement for remote RDP access.
Question 48
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have a Microsoft 365 subscription that uses Microsoft Defender XDR. The subscription contains 500 devices that are enrolled in Microsoft Intune. The subscription contains 500 users that connect to external software as a service (SaaS) apps by using the devices.
You need to implement a solution that meets the following requirements:
• Allows user access to SaaS apps that Microsoft has identified as low risk
• Blocks user access to SaaS apps that Microsoft has identified as high risk
Solution: You configure app protection policies in Intune, and you create a Conditional Access policy.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: Intune app protection policies control data usage within apps, not access to SaaS apps based on Microsoft risk ratings. Conditional Access cannot dynamically allow or block SaaS apps by Microsoft’s low/high risk classification. That capability is provided by Microsoft Defender for Cloud Apps (Defender XDR) using app discovery and access policies. Therefore, the solution does not meet the goal.
Question 49
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have a Microsoft 365 subscription that uses Microsoft Defender XDR. The subscription contains 500 devices that are enrolled in Microsoft Intune. The subscription contains 500 users that connect to external software as a service (SaaS) apps by using the devices.
You need to implement a solution that meets the following requirements:
• Allows user access to SaaS apps that Microsoft has identified as low risk
• Blocks user access to Saas apps that Microsoft has identified as high risk
Solution: From Microsoft Defender for Cloud Apps, you configure a cloud discovery policy and unsanction risky apps.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: A
Explanation: Microsoft Defender for Cloud Apps Cloud Discovery identifies SaaS apps and assigns Microsoft risk ratings. By unsanctioning high‑risk apps, access can be blocked when MDCA is integrated with enforcement points such as Microsoft Defender for Endpoint or supported network controls. Low‑risk apps can remain sanctioned and accessible. Therefore, the solution meets the stated goals.
Question 50
HOTSPOT
-
You have an Azure subscription. The subscription contains 20 App Service web apps that provide services to external customers. Each web app has a unique certificate and key.
You need to recommend a solution to manage the keys and certificates of the web apps. The solution must meet the follow requirements:
• Provide a single tenancy to store the keys and certificates.
• Maintain FIPS 140-2 Level 3 compliance.
• Follow the principle of least privilege.
• Minimize costs.
• Minimize administrative effort.
What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Azure Key Vault Managed HSM
A single vault with role-based access control (RBAC) authorization
Explanation: Managed HSM provides FIPS 140-2 Level 3 compliance and centralized key and certificate storage. Using a single vault minimizes cost and administrative effort, while RBAC enforces least-privilege access and modern authorization without legacy access policies.
Question 51
Your network contains an Active Directory Domain Services (AD DS) domain named Domain1.
You have a Microsoft Entra tenant.
Domain1 syncs with the tenant by using Microsoft Entra Connect.
You need to monitor Domain1 for privilege escalation attacks.
What should you use?
A. Microsoft Entra ID Protection
B. Microsoft Defender for Servers
C. Microsoft Defender for Identity
D. Privileged Identity Management (PIM)
Show Answer
Correct Answer: C
Explanation: The requirement is to monitor an on-premises Active Directory Domain Services (AD DS) environment for privilege escalation attacks. Microsoft Defender for Identity is specifically designed to monitor on-prem AD DS by analyzing signals from domain controllers to detect suspicious activities such as privilege escalation, lateral movement, and credential theft. Entra ID Protection focuses on cloud identities, Defender for Servers protects server workloads, and PIM manages privileged role activation rather than detecting attacks.
$19
Get all 316 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.