HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
No
Explanation: Asymmetric encryption uses a public/private key pair.
Symmetric encryption uses a single shared secret key, not a key pair.
Hashing is one-way; original content cannot be retrieved by decryption.
Question 63
HOTSPOT
-
Select the answer that correctly completes the sentence.
Show Answer
Correct Answer: integrity.
Explanation: This describes data integrity: ensuring data remains accurate and unchanged between storage and retrieval.
Question 64
What should you use to associate the same identity to more than one Azure virtual machine?
A. an Azure AD user account
B. a user-assigned managed identity
C. a system-assigned managed identity
D. an Azure AD security group
Show Answer
Correct Answer: B
Explanation: To associate the same identity with more than one Azure virtual machine, you must use a user-assigned managed identity. User-assigned managed identities are standalone Azure AD identities that can be created independently and assigned to multiple Azure resources. In contrast, system-assigned managed identities are tied to a single resource and cannot be shared, and Azure AD users or security groups are not designed for managed identity authentication from Azure resources.
Question 65
You have an Azure subscription that contains a Log Analytics workspace.
You need to onboard Microsoft Sentinel.
What should you do first?
A. Create a hunting query.
B. Correlate alerts into incidents.
C. Connect to your security sources.
D. Create a custom detection rule.
Show Answer
Correct Answer: C
Explanation: After enabling Microsoft Sentinel on a Log Analytics workspace, the first essential step is to connect your security data sources using data connectors. Sentinel cannot generate alerts, incidents, hunting queries, or detection rules until log data is ingested from security sources.
Question 66
Microsoft 365 Endpoint data loss prevention (Endpoint DLP) can be used on which operating systems?
A. Windows 10 and newer only
B. Windows 10 and newer and Android only
C. Windows 10 and newer and macOS only
D. Windows 10 and newer, Android, and macOS
Show Answer
Correct Answer: C
Explanation: Microsoft 365 Endpoint Data Loss Prevention supports onboarded Windows 10 and Windows 11 devices, as well as onboarded macOS devices (supported versions). It does not support Android or iOS for Endpoint DLP, which are covered by other mobile management or app protection capabilities. Therefore, the correct option is Windows 10 and newer and macOS only.
Question 67
Which three forms of verification can be used with Azure AD Multi-Factor Authentication (MFA)? Each correct answer presents a complete solution.
NOTE: Each correct answer is worth one point.
A. security questions
B. the Microsoft Authenticator app
C. SMS messages
D. a smart card
E. Windows Hello for Business
Show Answer
Correct Answer: B, C, E
Explanation: Azure AD Multi-Factor Authentication supports multiple additional verification methods. Valid options include the Microsoft Authenticator app, SMS messages, and Windows Hello for Business. Security questions are used for self-service password reset (SSPR), not MFA, and smart cards are not an Azure AD MFA verification method.
Question 68
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
No
Yes
Explanation: Azure DDoS Protection focuses on volumetric, protocol, and resource-layer DDoS attacks—not MITM attacks. It is not enabled by default and must be explicitly configured. It does provide protection against protocol attacks.
Question 69
HOTSPOT
-
Select the answer that correctly completes the sentence.
Show Answer
Correct Answer: access and application control
Explanation: Access and application control in Microsoft Defender for Cloud blocks malware and unwanted applications using allowlists/blocklists and reduces the network attack surface through just-in-time and controlled access to Azure VM management ports.
Question 70
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
No
Explanation: SSPR supports multiple authentication methods, including email (which can be an external email address) and Microsoft Authenticator app notifications. SSPR is designed for users who cannot sign in, so prior authentication to Azure AD is not required.
Question 71
HOTSPOT
-
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
No
Yes
Explanation: Information Barriers restrict or prevent communication between users or groups; they do not detect inappropriate language.
Communication Compliance monitors communications (emails, Teams, etc.), not files stored directly in SharePoint Online.
Communication Compliance can scan both internal and external emails in Exchange Online for policy violations.
$19
Get all 224 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.