HOTSPOT -
You have an Azure subscription that contains the resources shown in the following table.
The subscription contains the virtual machines shown in the following table.
Which identities can be assigned the Owner role for RG1, and to which virtual machines can you assign Managed2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Identities with Owner role:
Managed1, Managed2, VM1, and VM2 only
Virtual machines assigned to Managed2:
VM1, VM2, VM3, and VM4
Explanation: System-assigned managed identities (VM1, VM2) and user-assigned managed identities (Managed1, Managed2) are security principals that can receive RBAC roles regardless of region. VM3 uses the existing user-assigned identity Managed1, so it does not represent a separate identity. VM4 has no identity. A user-assigned managed identity can be attached to VMs in any region, including VMs that already have a system-assigned identity.
Question 188
You have an Azure subscription that contains a user named User1.
The App registration settings for the Azure AD tenant are configured as shown in the following exhibit.
User1 builds an ASP.NET web app named App1.
You need to ensure that User1 can register App1. The solution must use the principle of least privilege.
Which role should you assign to User1?
A. Application Developer
B. Cloud App Security Administrator
C. Cloud Application Administrator
D. Application Administrator
Show Answer
Correct Answer: A
Explanation: When the tenant setting 'Users can register applications' is disabled, the least-privileged built-in Microsoft Entra role that allows a user to create app registrations is Application Developer. Cloud Application Administrator and Application Administrator grant broader application management permissions than necessary, while Cloud App Security Administrator is unrelated to app registration.
Question 189
You have an Azure AD tenant that contains the external user shown in the following exhibit.
You update the email address of the user.
You need to ensure that the user can authenticate by using the updated email address.
What should you do for the user?
A. Modify the Authentication methods settings.
B. Reset the password.
C. Revoke the active sessions.
D. Reset the redemption status.
Show Answer
Correct Answer: D
Explanation: For an Azure AD (Microsoft Entra ID) B2B guest user, simply changing the email address on the guest object does not change the identity the guest uses to sign in. To allow the guest to authenticate with a new email address or identity provider while retaining the existing guest object, memberships, and assignments, you must reset the guest user's redemption status and reinvite them. This updates the guest's sign-in information without recreating the account.
Question 190
You have an Azure AD tenant.
You need to ensure that only users from specific external domains can be invited as guests to the tenant.
Which settings should you configure?
A. External collaboration settings
B. All identity providers
C. Cross-tenant access settings
D. Linked subscriptions
Show Answer
Correct Answer: A
Explanation: External collaboration settings include Collaboration restrictions, where you can allow invitations only to specified domains or deny specified domains. This is the setting used to restrict which external domains can be invited as guest users. Cross-tenant access settings govern B2B collaboration behavior with specific organizations but do not provide the domain allow/deny invitation restriction described in the question.
Question 192
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Amazon Web Services (AWS) account, a Google Workspace subscription, and a GitHub account.
You deploy an Azure subscription and enable Microsoft 365 Defender.
You need to ensure that you can monitor OAuth authentication requests by using Microsoft Defender for Cloud Apps.
Solution: From the Microsoft 365 Defender portal, you add the GitHub app connector.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: Adding only the GitHub app connector does not satisfy the overall requirement to monitor OAuth authentication requests across the relevant connected cloud services in the scenario. OAuth monitoring in Defender for Cloud Apps relies on connecting the appropriate supported platforms (such as Google Workspace for OAuth app auditing), and a GitHub connector alone is insufficient.
Question 193
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.
You plan to increase app security for the subscription.
You need to identify which apps do NOT require user authentication.
What should you do in the Microsoft 365 Defender portal?
A. Review the cloud app catalog.
B. Create an OAuth policy and review alerts.
C. Create a snapshot Cloud Discovery report.
D. Create a discovered app query.
Show Answer
Correct Answer: D
Explanation: Create a discovered app query and use the suggested query for cloud apps that allow anonymous use. This identifies discovered apps that don't require user authentication (and allow uploads), matching the requirement to identify apps that do not require user authentication. The cloud app catalog contains app metadata and risk factors, but the task in the Defender portal for identifying such discovered apps is performed through discovered app queries.
Question 194
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 tenant.
All users must use the Microsoft Authenticator app for multi-factor authentication (MFA) when accessing Microsoft 365 services.
Some users report that they received an MFA prompt on their Microsoft Authenticator app without initiating a sign-in request.
You need to block the users automatically when they report an MFA request that they did not initiate.
Solution: From the Azure Active Directory admin center, you configure the Block/unblock users settings for multi-factor authentication (MFA).
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: The proposed solution does not meet the goal. The 'Block/unblock users' settings are used to manually manage users who have already been blocked. To automatically block users when they report an unexpected MFA prompt, you need to enable the Fraud Alert/Report suspicious activity feature with automatic blocking, not simply configure the Block/unblock users page.
Question 195
You have an Azure AD tenant.
You deploy a new enterprise application named App1.
When users attempt to provide App1 with access to the tenant, the attempt fails.
You need to ensure that the users can request admin consent for App1. The solution must follow the principle of least privilege.
What should you do first?
A. Enable admin consent requests for the tenant.
B. Designate a reviewer of admin consent requests for the tenant.
C. From the Permissions settings of App1, grant App1 admin consent for the tenant.
D. Create a Conditional Access policy for App1.
Show Answer
Correct Answer: A
Explanation: To allow users to request administrator approval for an enterprise application, the tenant-level Admin consent requests feature must first be enabled. Designating reviewers is part of configuring the feature, but it cannot function until admin consent requests are enabled. Granting admin consent directly violates least privilege, and Conditional Access is unrelated to enabling admin consent requests.
Question 196
HOTSPOT
-
You have an Azure AD tenant.
You need to configure the following External Identities features:
• B2B collaboration
• Monthly active users (MAU)-based pricing
Which two settings should you configure? To answer, select the settings in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: B2B collaboration with external Microsoft Entra tenants is configured through Cross-tenant access settings. MAU-based pricing is enabled by linking an Azure subscription under Linked subscriptions.
Question 197
You have an Azure AD tenant that contains a user named User1 and a Microsoft 365 group named Group1. User1 is the owner of Group1.
You need to ensure that User1 is notified every three months to validate the guest membership of Group1.
What should you do?
A. Configure the External collaboration settings.
B. Create an access review.
C. Configure an access package.
D. Create a group expiration policy.
Show Answer
Correct Answer: B
Explanation: Access reviews in Microsoft Entra ID (Azure AD) are designed to periodically review and validate access, including guest membership in Microsoft 365 groups. You can schedule the review to recur every three months and notify the group owner (User1) to confirm whether guest users should retain membership. External collaboration settings govern B2B behavior, access packages are for entitlement management scenarios rather than simple group guest validation, and group expiration policies manage inactive groups rather than reviewing guest membership.
$19
Get all 387 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.