HOTSPOT
-
Select the answer that correctly completes the sentence.
Show Answer
Correct Answer: Microsoft Defender for Cloud
Explanation: Microsoft Defender for Cloud provides cloud workload protection (CWPP) and cloud security posture management for Azure and hybrid cloud resources.
Question 93
HOTSPOT
-
Select the answer that correctly completes the sentence.
Show Answer
Correct Answer: Azure Key Vault
Explanation: Azure Key Vault is the Azure cloud service designed to securely store and manage application secrets, keys, and certificates.
Question 94
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
Yes
Explanation: Defender for Cloud provides threat protection for Azure Storage, foundational CSPM is available for onboarded Azure subscriptions, and Defender for Cloud assesses the security posture of Azure and on-premises/hybrid workloads.
Question 96
Which security feature is available in the free mode of Microsoft Defender for Cloud?
A. threat protection alerts
B. just-in-time (JIT) VM access to Azure virtual machines
C. vulnerability scanning of virtual machines
D. secure score
Show Answer
Correct Answer: D
Explanation: The free (foundational/CSPM) capabilities of Microsoft Defender for Cloud include Secure Score, which provides a measurement of an organization's security posture and recommendations. Threat protection alerts, just-in-time VM access, and integrated vulnerability assessment are Defender plan (paid) capabilities.
Question 97
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
Yes
Explanation: In the Microsoft Entra ID/Azure AD context, passwordless authentication methods include Microsoft Authenticator (a software-based authenticator for passwordless phone sign-in), Windows Hello for Business, and FIDO2 security keys.
Question 98
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
Yes
Explanation: Azure AD B2C supports social and enterprise identity providers for external users. B2C users are stored in a separate Azure AD B2C tenant, not the organization's Azure AD directory. Azure AD B2C supports custom branding of authentication pages.
Question 99
Which three authentication methods can Azure AD users use to reset their password? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. mobile app notification
B. text message to a phone
C. security questions
D. certificate
E. picture password
Show Answer
Correct Answer: A, B, C
Explanation: Azure AD (Microsoft Entra ID) Self-Service Password Reset supports authentication methods including mobile app notification, text message to a phone, and security questions (where enabled). Certificate authentication and picture passwords are not supported SSPR verification methods.
Question 100
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
Yes
Explanation: Hybrid identity supports syncing on-premises Active Directory identities to Azure AD (Microsoft Entra ID). Accounts created in Azure AD do not automatically sync back to on-premises Active Directory. In hybrid environments, authentication can be handled by Azure AD or a federated identity provider.
Question 101
What can you use to ensure that all the users in a specific group must use multi-factor authentication (MFA) to sign to Azure Active Directory (Azure AD)?
A. Azure Policy
B. a communication compliance policy
C. a Conditional Access policy
D. a user risk policy
Show Answer
Correct Answer: C
Explanation: Conditional Access policies can target specific users or groups and require multi-factor authentication as a sign-in control. Azure Policy governs Azure resource compliance, communication compliance policies relate to Microsoft Purview, and user risk policies respond to identity risk rather than generally enforcing MFA for a group.
Question 102
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
Yes
Explanation: Identity Protection detects leaked credentials and can trigger MFA through risk-based Conditional Access policies. It does not add users to groups based on risk level.
$19
Get all 230 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.