Which three authentication methods can Azure AD users use to reset their password? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. mobile app notification
B. text message to a phone
C. security questions
D. certificate
E. picture password
Show Answer
Correct Answer: A, B, C
Explanation: Azure AD Self-Service Password Reset (SSPR) supports authentication methods such as mobile app notification, text message (SMS) to a phone, and security questions for verifying a user's identity during password reset. Certificate-based authentication and picture passwords are not supported methods for Azure AD SSPR.
Question 94
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
Yes
Explanation: Hybrid identity commonly uses on‑premises Active Directory synchronized to Azure AD.
By default, synchronization is one‑way from on‑premises AD to Azure AD, not the reverse.
In a hybrid model, authentication can be handled by Azure AD or another identity provider (e.g., federated authentication).
Question 95
What can you use to ensure that all the users in a specific group must use multi-factor authentication (MFA) to sign to Azure Active Directory (Azure AD)?
A. Azure Policy
B. a communication compliance policy
C. a Conditional Access policy
D. a user risk policy
Show Answer
Correct Answer: C
Explanation: To require that all users in a specific group use multi-factor authentication when signing in to Azure AD, you use a Conditional Access policy. Conditional Access allows you to target users or groups and enforce access controls such as requiring MFA. Azure Policy governs Azure resource configuration, communication compliance policies relate to Microsoft 365 communications, and user risk policies are part of Identity Protection and are risk-based rather than group-based enforcement.
Question 96
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
Yes
Explanation: 1) Identity Protection does not add users to groups based on risk; risk level is not a dynamic group attribute.
2) Identity Protection can detect leaked credentials using risk detections.
3) Identity Protection integrates with Conditional Access to require MFA based on user or sign-in risk.
Question 97
What is a function of Conditional Access session controls?
A. enforcing device compliance
B. enforcing client app compliance
C. enable limited experiences, such as blocking download of sensitive information
D. prompting multi-factor authentication (MFA)
Show Answer
Correct Answer: C
Explanation: Conditional Access session controls apply after authentication and are used to control what a user can do during a session. They enable limited experiences within applications, such as blocking downloads, restricting access, or applying app-enforced restrictions. MFA prompting, device compliance, and client app compliance are handled by Conditional Access conditions or grant controls, not session controls.
Question 98
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
No
Explanation: Authorization defines the level of access to a resource. Authentication verifies a user's identity. Read/write permissions are determined by authorization, not authentication.
Question 99
HOTSPOT
-
Select the answer that correctly completes the sentence.
Show Answer
Correct Answer: authentication
Explanation: Authentication verifies a user’s credentials during sign-in to prove their identity. Authorization determines access after identity is verified, auditing records actions, and administration manages accounts.
Question 100
What can be created in Active Directory Domain Services (AD DS)?
A. line-of-business (LOB) applications that require modern authentication
B. computer accounts
C. software as a service (SaaS) applications that require modern authentication
D. mobile devices
Show Answer
Correct Answer: B
Explanation: Active Directory Domain Services stores and manages directory objects such as users, groups, and computer accounts within a domain. It does not create SaaS apps, LOB applications, or mobile devices themselves—only directory objects representing resources. Therefore, computer accounts can be created in AD DS.
Question 101
DRAG DROP
-
Match the types of compliance score actions to the appropriate tasks.
To answer, drag the appropriate action type from the column on the left to its task on the right. Each type may be used once, more than once, or not at all.
NOTE: Each correct match is worth one point.
Show Answer
Correct Answer: Preventative → Use encryption to protect data at rest.
Detective → Actively monitor systems to identify irregularities that might represent risks.
Explanation: Encryption is a preventative control that reduces the likelihood of data exposure. Active monitoring is a detective control used to identify and alert on potential security or compliance issues.
Question 102
Which pillar of identity relates to tracking the resources accessed by a user?
A. authorization
B. auditing
C. administration
D. authentication
Show Answer
Correct Answer: B
Explanation: The pillar concerned with tracking and recording which resources a user accesses is auditing. Auditing focuses on logging, monitoring, and reviewing user activities, whereas authentication verifies identity, authorization grants permissions, and administration manages identities and roles.
$19
Get all 224 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.