What feature supports email as a method of authenticating users?
A. Microsoft Entra ID Protection
B. Microsoft Entra Multi-Factor Authentication (MFA)
C. self-service password reset (SSPR)
D. Microsoft Entra Password Protection
Show Answer
Correct Answer: C
Explanation: Email can be used as a verification method during self-service password reset, where a reset link or code is sent to the user’s registered email address to validate their identity. The other options focus on risk detection, password policy enforcement, or MFA methods that do not support email as an authentication factor.
Question 23
When a user authenticates by using passwordless sign-in, what should the user select in the Microsoft Authenticator app?
A. an answer to a security question
B. a number
C. an alphanumeric key
D. a passphrase
Show Answer
Correct Answer: B
Explanation: With Microsoft Authenticator passwordless sign-in, the user is prompted to match a displayed number by selecting the correct number in the app to approve the sign-in. This number matching improves security against push notification attacks.
Question 24
Which service includes Microsoft Secure Score for Devices?
A. Microsoft Defender for IoT
B. Microsoft Defender for Endpoint
C. Microsoft Defender for Identity
D. Microsoft Defender for Office 365
Show Answer
Correct Answer: B
Explanation: Microsoft Secure Score for Devices is part of Microsoft Defender Vulnerability Management, which is integrated into Microsoft Defender for Endpoint. It provides a device-focused security posture score within the Microsoft Defender portal, and is not a feature of Defender for IoT, Identity, or Office 365.
Question 25
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
No
Explanation: Microsoft Entra Permissions Management is administered from the Microsoft Entra admin center, not the Microsoft Purview compliance portal.
It supports managing permissions across multicloud environments, including Amazon Web Services (AWS).
Microsoft Secure Score is reviewed in Microsoft Defender and Entra portals, not within Entra Permissions Management.
Question 26
What can you use to protect against malicious links sent in email messages, chat messages, and channels?
A. Microsoft Defender for Cloud Apps
B. Microsoft Defender for Office 365
C. Microsoft Defender for Endpoint
D. Microsoft Defender for Identity
Show Answer
Correct Answer: B
Explanation: Microsoft Defender for Office 365 provides protection against malicious links through features like Safe Links, which scan and rewrite URLs in email messages and perform time-of-click verification in emails, Microsoft Teams chats, and channels. The other options focus on cloud app control, endpoint protection, or identity protection rather than link protection in messaging.
Question 27
HOTSPOT
-
Select the answer that correctly completes the sentence.
Show Answer
Correct Answer: access
Explanation: Azure AD dynamic groups automatically add or remove users or devices based on rules, which is used to automate the access lifecycle process.
Question 28
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
Yes
Explanation: Microsoft Defender for Cloud combines multiple security capabilities. It includes DevSecOps features by integrating security into development pipelines, provides core Cloud Security Posture Management (CSPM) to assess and improve configurations, and delivers Cloud Workload Protection Platform (CWPP) protections for servers, containers, databases, and other workloads.
Question 29
What is Azure Key Vault used for?
A. to deploy a cloud-based network security service that protects Azure virtual network resources
B. to protect cloud-based applications from cyber threats and vulnerabilities
C. to safeguard cryptographic keys and other secrets used by cloud apps and services
D. to provide secure and seamless RDP/SSH connectivity to Azure virtual machines via TLS from the Azure portal
Show Answer
Correct Answer: C
Explanation: Azure Key Vault is a service designed to securely store and manage sensitive information such as cryptographic keys, secrets, and certificates used by cloud applications and services. It is not a network security appliance, threat protection service, or remote access solution.
Question 30
You have an Azure subscription that contains a Log Analytics workspace.
You need to onboard Microsoft Sentinel.
What should you do first?
A. Create a hunting query.
B. Correlate alerts into incidents.
C. Connect to your data sources.
D. Create a custom detection rule.
Show Answer
Correct Answer: C
Explanation: Onboarding Microsoft Sentinel starts by connecting it to data sources via data connectors so it can ingest logs and events into the Log Analytics workspace. Detection rules, hunting queries, and incident correlation all depend on having data available first.
Question 31
HOTSPOT
-
Select the answer that correctly completes the sentence.
Show Answer
Correct Answer: override
Explanation: Default NSG rules cannot be deleted, but you can override them by creating higher-priority custom rules that take precedence.
$19
Get all 224 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.