DRAG DROP
You have an Azure subscription named Sub1 that contains a storage account named storage1. storage1 hosts a blob container named container1.
Sub1 is linked to a Microsoft Entra tenant that contains a security group named Group1.
You need to ensure that Group1 can use the Azure portal to view the blobs in container1. The solution must follow the principle of least privilege.
Which roles should you assign to Group1. To answer, drag the appropriate roles to the correct objects. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: For container1: Storage Blob Data Reader
For storage1: Reader
Explanation: Storage Blob Data Reader grants read access to the blobs. Reader grants the management-plane access needed to navigate the storage account in the Azure portal.
Question 32
You have an Azure subscription that contains a virtual network named VNet1.
VNet1 contains an Azure VPN gateway named Gateway1 that is configured for Point-to-Site (P2S) connections.
You have a Microsoft 365 E5 subscription.
You need to configure a VPN authentication method for Gateway1. The solution must enforce Conditional Access policies during VPN sign-ins.
Which authentication method should you configure?
A. a custom IPsec/IKE policy
B. Microsoft Entra authentication
C. certificate authentication
D. forced tunneling
Show Answer
Correct Answer: B
Explanation: Configure Microsoft Entra authentication. Azure VPN Gateway P2S sign-ins using Entra ID can be evaluated against Conditional Access policies. The other options do not provide Conditional Access enforcement.
Question 33
You have a virtual network named VNet1 that contains a subnet named Subnet1. Azure App Service is integrated with VNet1. You have an Azure SQL Database logical server named Server1 that contains a database named DB1. Server1 is accessible only by using a public IP address.
You need to ensure that Server does NOT use a public IP address and Azure App Service can still access Server1.
What should you create?
A. a routing table
B. an Azure Private Link service
C. a private endpoint
D. a service endpoint
Show Answer
Correct Answer: C
Explanation: Create a private endpoint for Server1. It assigns the Azure SQL service a private IP address in VNet1, allowing the VNet-integrated App Service to connect privately. You can then disable public network access to the SQL server.
Question 34
HOTSPOT
You have a Microsoft Entra tenant that contains the users shown in the following table.
You have a location named HQ-Trusted that contains the IP address of the corporate network.
The tenant contains a Conditional Access policy named CA1 that has the following settings:
• Assignments:
o Users or agents:
- Include: All users
- Exclude: Group1
• Target resources:
o Resources (formerly cloud apps):
- Include: Office 365
• Conditions:
o Client apps: Not configured
• Access controls:
o Grant:
- Require multifactor authentication
o Grant:
- Require device to be marked as compliant
o For multiple controls:
- Require all the selected controls
The tenant contains a Conditional Access policy named CA2 that has the following settings:
• Assignments:
o Users or agents:
- Include: All users
- Exclude: Group2
• Target resources:
o Resources (formerly cloud apps):
- Include: All resources
• Conditions:
o Locations:
- Configure: Yes
- Include: Any network or location
- Exclude: HQ-Trusted
• Access controls:
o Grant:
- Block access
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User2: Yes
User3: No
User1: No
Explanation: User2 is excluded from the home-network block but must satisfy CA1’s MFA and compliant-device requirements. CA2 blocks User3 on public Wi-Fi, regardless of device compliance. User1 is excluded from CA1, and CA2 does not apply at HQ-Trusted.
Question 35
HOTSPOT
You are implementing security controls for an Azure Storage account by using infrastructure as code (IaC).
You deploy the following Bicep code.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
No
Explanation: Anonymous blob access is disabled. The specified subnet is allowed by a virtual network rule. The default network action denies connections from unlisted public IP addresses, even when they use TLS 1.2.
Question 36
HOTSPOT
You have a Microsoft Entra tenant that contains the users shown in the following table.
The tenant contains a Conditional Access policy named CA1 that has the following settings:
• Assignments:
o Users or agents:
- Include: Directory roles: Global Administrator
• Target resources:
o Resources (formerly cloud apps):
- Include: All resources
• Conditions:
o Locations:
- Configure: Yes
- Include: Any network or location
• Access controls:
o Grant:
- Require multifactor authentication
o Grant:
- Require device to be marked as compliant
o For multiple controls:
- Require all the selected controls
The tenant contains a Conditional Access policy named CA2 that has the following settings:
• Assignments:
o Users or agents:
- Include: Users and groups: Group1
• Target resources:
o Resources (formerly cloud apps)
- Include: Select resources: Office 365
• Conditions:
o Locations:
- Configure: Yes
- Include: Any network or location
• Access controls:
o Grant:
- Require multifactor authentication
o Grant:
- Require app protection policy
o For multiple controls:
- Require one of the selected controls
The users perform the following tasks:
• User1 signs in to Microsoft 365 from a home network by using Microsoft Outlook on a noncompliant device.
• User2 signs in to Microsoft 365 without an app protection policy by using a noncompliant device.
• User3 signs in to the Azure portal from a home network by using a compliant device.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User1: No
User2: Yes
User3: Yes
Explanation: User1 is subject to CA1, which requires both MFA and a compliant device. User2 satisfies CA2 by completing MFA; a compliant device is not required. User3 satisfies CA1 by completing MFA on a compliant device.
Question 37
HOTSPOT
You have an Azure key vault named KV1 that uses role-based access control (RBAC) for data plane authorization.
You have multiple Azure App Service web apps that retrieve a SQL connection string stored as a secret in KV1.
You need to ensure that the web apps can access KV1. The solution must minimize the number of required identities and follow the principle of least privilege.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Type of workload identity: User-assigned managed identity
Data plane role: Key Vault Secrets User
Explanation: One user-assigned identity can be shared by multiple web apps, minimizing identities. The Key Vault Secrets User role allows them to read secret values without broader administrative permissions.
Question 38
You have an Azure Storage account named storage1 that hosts a blob container used by an internal application.
You plan to enable a third-party workflow system to upload blobs to storage1.
You need to provide time-bound, least-privilege upload access to the third-party system.
Which authorization method should you use?
A. Configure the workflow system to use a user delegation shared access signature (SAS).
B. Enable a managed identity for the workflow system and assign a role for storage1.
C. Enable anonymous public read access for the blob container.
D. Configure the workflow system to use Shared Key authorization.
Show Answer
Correct Answer: A
Explanation: A user delegation SAS can grant upload/write permissions to a specific blob or container for a limited time, providing least-privilege access without sharing the storage account key.
Question 39
You have a Microsoft Entra tenant that contains a group named Group1.
You plan to target Group1 to use the Microsoft Authenticator authentication method.
You need to ensure that the members in Group1 can use the Authenticator app as their primary authentication method.
What should you do?
A. Enable one-time passcodes in Authenticator for Group1.
B. Revoke the sessions for the Group1 members.
C. Enable Authenticator push authentication mode for Group1.
D. Enable the Authenticator passwordless authentication method for Group1.
Show Answer
Correct Answer: D
Explanation: Enable the Microsoft Authenticator passwordless authentication method for Group1. Passwordless phone sign-in lets members use Authenticator as their primary authentication method; push authentication is generally a second-factor approval.
Question 40
You have a virtual network named VNet1 that contains a subnet named Subnet1 and a virtual machine named VM1. VM1 uses only dynamic IP addresses from Subnet1.
You have an Azure key vault named KV1.
You enable a firewall on KV1 and allow access to KV1 from only select virtual networks and IP addresses.
VM1 receives 403 errors when it attempts to access KV1.
You need to enable VM1 to access KV1, while maintaining the current restrictions on KV1.
What should you do?
A. Create a routing rule on Subnet1.
B. Allow trusted Microsoft services to bypass the firewall on KV1.
C. Add a Microsoft.KeyVault service endpoint for Subnet1.
D. Add the current IPv4 address of VM1 to the firewall allowlist of KV1.
Show Answer
Correct Answer: C
Explanation: Enable the Microsoft.KeyVault service endpoint on Subnet1. Then add the subnet to KV1’s allowed virtual networks. This permits VM1 to reach the vault through the subnet while preserving KV1’s network restrictions. VM1’s changing dynamic IP does not need to be added to the firewall allowlist.
$19
Get all 100 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.