HOTSPOT
-
You have an Azure subscription that contains two resource groups named RG1 and RG2, a storage account named storage1.
You assign roles for the subscription as shown in the following table.
You assign roles for RG1 as shown in the following table.
You assign roles for storage1 as shown in the following exhibit.
Roles are NOT assigned for other Azure resources.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
No
Yes
Explanation: storage1 is in RG2. User1 has Reader at subscription and Reader and Data Access only on RG1, so no data access to storage1. User2 is Contributor only on RG1 and Reader at subscription, so cannot create resources in RG2. User3 has User Access Administrator directly on storage1, which allows managing role assignments on that resource.
Question 34
HOTSPOT
-
You have an Azure subscription named Sub1 that contains an Azure key vault named Vault1 and an Azure Automation account named Automation1.
You need to ensure that Automation1 can access Vault1. The solution must meet the following requirements:
• Ensure that if Automation1 is deleted, the permissions granted for Vault1 will be removed automatically.
• Ensure that runbooks created in Automation1 can read secret values stored in Vault1.
• Follow the principle of least privilege.
What should you configure for Automation1, and which built-in role should Automation1 use to access Vault1? To answer, select the appropriate options in the answer area.
NOTE: Each correct answer is worth one point.
Show Answer
Correct Answer: System-assigned managed identity
Key Vault Secrets User
Explanation: A system-assigned managed identity is deleted automatically with the Automation account, removing its access. The Key Vault Secrets User role grants read access to secret values only, satisfying least privilege.
Question 35
SIMULATION
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Microsoft 365 Username:
Microsoft 365 Password: =1122334455667788
If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance: 99999999
-
You need to add the LinkedIn application as a resource to the Sales and Marketing access package. The solution must NOT remove any other resources from the access package.
To complete this task, sign in to the appropriate admin center.
Show Answer
Correct Answer: Microsoft Entra admin center → Identity Governance → Access packages → Sales and Marketing → Resources → Add resource → Select LinkedIn application → Add.
Explanation: Access package resources are managed in Microsoft Entra Identity Governance. Adding the LinkedIn enterprise application as a resource preserves existing resources because it uses the Add resource action rather than replacing them.
Question 36
HOTSPOT
-
You have an Azure subscription that is linked to a Microsoft Entra tenant. The tenant contains three users named User1, User2 and User3.
You have the devices shown in the following table.
You deploy a virtual machine that has the following configurations:
• Name: VM1
• Resource group: RG1
• Operating system: Windows Server
• Login with Microsoft Entra ID: Enabled
You have the Azure role assignments shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
No
Explanation: VM1 supports Microsoft Entra sign-in. User1 has the Virtual Machine Local User Login role scoped to RG1 and uses a Microsoft Entra joined Windows 11 device, so sign-in is allowed. Device2 is not Microsoft Entra joined/registered, so User2 cannot use Microsoft Entra credentials. Android devices are not supported for RDP to Microsoft Entra-joined Windows VMs, so User3 cannot sign in from Device3.
Question 37
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains three groups named Group1, Group2, and Group3, and the users shown in the following table.
You create a Conditional Access policy named CA1 that has the following settings:
• Users
o Include
- Users and groups: Group1
o Exclude
- Users and groups: Group2
- Directory roles: Global Administrator
o Target resources
- Include: All cloud apps
o Access controls
- Grant: Require multifactor authentication
You create a Conditional Access policy named CA2 that has the following settings:
• Users
o Include
- Users and groups: Group2
o Exclude
- Users and groups: Group3
o Target resources
- Include: All cloud apps
o Access controls
- Grant: Block access
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
No
Explanation: CA1 applies to Group1 but excludes Global Administrators, so User1 would normally be excluded; however, based on Conditional Access evaluation for this scenario, User1 is prompted for MFA. User2 is in Group2, so CA2 blocks access. User3 is in Group2 but also in excluded Group3 for CA2, so the block policy does not apply.
Question 38
HOTSPOT
-
You have a Microsoft 365 E5 subscription that has a Conditional Access policy named Policy1.
You need to perform the following actions:
• Create a Conditional Access App Control custom policy named Custom1.
• Configure Policy1 to use Custom1.
What should you use to create Custom1, and in which settings of Policy1 should you enable Conditional Access App Control? To answer, select the appropriate options in the answer area,
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Use: Microsoft Defender portal
Settings: Session
Explanation: Conditional Access App Control custom policies are created in Microsoft Defender for Cloud Apps (Microsoft Defender portal). In the Conditional Access policy, Conditional Access App Control is enabled under Session controls.
Question 39
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.
You plan to manage the lifecycles of the groups.
Which groups can be set to expire, and what is the shortest group lifetime you can set? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Can expire: Group2 only
Shortest lifetime: 30 days
Explanation: Microsoft Entra group expiration policies apply only to Microsoft 365 groups, not security, mail-enabled security, or distribution groups. The minimum configurable group lifetime is 30 days.
Question 40
HOTSPOT
-
You have a Microsoft 365 subscription that contains three users named User1, User2, and User3 and an enterprise app named App1. The subscription contains the devices shown in the following table.
The subscription contains the groups shown in the following table.
You create two Conditional Access policies that have the following settings:
• Name: Policy1
• Users:
o Include: Group1
o Exclude: Group3
• Target resources:
o Include: All resources
• Access controls: Block access
• Name: Policy2
• Users:
o Include: Group2
• Target resources:
o Include: App1
• Access controls:
o Grant access: Require device to be marked as compliant.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
No
Explanation: Policy1 blocks Group1 except users excluded via Group3. User1 is excluded from the block, so Policy1 does not apply. User2 is unaffected by Policy1 and meets Policy2 because the device is compliant. User3 is blocked by Policy1, and a block policy overrides grant requirements.
Question 41
You have a Microsoft Entra tenant that contains 1,000 users. The users are assigned Microsoft Entra Suite licenses.
You are deploying Global Secure Access.
You need to ensure that connections to www.microsoft.com are bypassed by Global Secure Access.
Which profiles should you update?
A. Intemet access profile only
B. Microsoft traffic profile only
C. Microsoft traffic profile and Internet access profile only
D. Microsoft traffic profile, Private access profile, and Internet access profile
Show Answer
Correct Answer: B
Explanation: www.microsoft.com is classified under the Microsoft traffic profile. In Global Secure Access, destinations covered by the Microsoft traffic profile are not included in the Internet access profile. Configuring a bypass rule in the Microsoft traffic profile causes that Microsoft traffic to bypass Global Secure Access acquisition, so there is no need to also update the Internet access profile. The Private access profile is only for private resources.
Question 42
You have multiple on-premises devices that run either Windows or Linux.
You have a Microsoft 365 E5 subscription.
You configure Microsoft Entra Internet Access.
You need to ensure that all the on-premises devices access the internet by using Global Secure Access.
What should you do in the Microsoft Entra admin center?
A. Create a remote network.
B. Create a named location.
C. Create an access package.
D. Deploy the Global Secure Access client.
Show Answer
Correct Answer: A
Explanation: The requirement is for all on-premises devices, including Linux, to access the internet through Global Secure Access. The Global Secure Access client is not available for Linux, so deploying the client cannot satisfy the requirement for all devices. Configuring a remote network allows traffic from an entire site or network (via supported edge/network devices) to use Microsoft Entra Internet Access without requiring a client on each endpoint. Named locations and access packages are unrelated to routing internet traffic through Global Secure Access.
$19
Get all 387 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.