πŸ”

AZ-900 β€” questions

Page 7 of 11 Β· 209 total questions.

Topic 1 Β· Question 232

You have an Azure subscription. You need to review your secure score. What should you use?

  • AAzure Monitor
  • BAzure Advisor
  • CHelp + support
  • DMicrosoft Defender for Cloud (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Microsoft Defender for Cloud

Explanation

Microsoft Defender for Cloud provides security posture management and threat protection across resources.

Topic 1 Β· Question 235

You need to collect and automatically analyze security events from Azure Active Directory (Azure AD). What should you use?

  • AMicrosoft Sentinel (correct answer)
  • BAzure Synapse Analytics
  • CAzure AD Connect
  • DAzure Key Vault
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Microsoft Sentinel.

Topic 1 Β· Question 239

Your company plans to automate the deployment of servers to Azure. Your manager is concerned that you may expose administrative credentials during the deployment. You need to recommend an Azure solution that encrypts the administrative credentials during the deployment. What should you include in the recommendation?

  • AAzure Key Vault (correct answer)
  • BAzure Information Protection
  • CMicrosoft Defender for Cloud
  • DAzure Multi-Factor Authentication (MFA)
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Azure Key Vault

Explanation

Azure Key Vault securely stores and manages secrets, keys, and certificates with access policies.

Topic 1 Β· Question 243

You need to configure an Azure solution that meets the following requirements: β€’ Secures websites from attacks β€’ Generates reports that contain details of attempted attacks What should you include in the solution?

  • AAzure Firewall
  • Ba network security group (NSG)
  • CAzure Information Protection
  • DDDoS protection (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: DDoS protection.

Topic 1 Β· Question 245

Your Azure environment contains multiple Azure virtual machines. You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP. What are two possible solutions? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

  • AModify an Azure Traffic Manager profile
  • BModify a network security group (NSG) (correct answer)
  • CModify a DDoS protection plan
  • DModify an Azure firewall
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Modify a network security group (NSG)

Explanation

A Network Security Group (NSG) filters inbound and outbound traffic to subnets and NICs with allow/deny rules. A Network Security Group (NSG) applies allow/deny rules to control traffic at the subnet or NIC level.

Topic 1 Β· Question 248

You have an Azure environment that contains 10 virtual networks and 100 virtual machines. You need to limit the amount of inbound traffic to all the Azure virtual networks. What should you create?

  • Aone application security group (ASG)
  • B10 virtual network gateways
  • C10 Azure ExpressRoute circuits
  • Done Azure firewall (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: one Azure firewall

Explanation

Azure Firewall is a managed, stateful network firewall for centralized traffic filtering and threat protection.

Topic 1 Β· Question 249

This question requires that you evaluate the underlined text to determine if it is correct. Azure Key Vault is used to store secrets for Azure Active Directory (Azure AD) user accounts. Instructions: Review the underlined text. If it makes the statement correct, select `No change is needed`. If the statement is incorrect, select the answer choice that makes the statement correct.

  • ANo change is needed
  • BAzure Active Directory (Azure AD) administrative accounts
  • CPersonally Identifiable Information (PII)
  • Dserver applications (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: server applications.

Topic 1 Β· Question 250

Your company plans to automate the deployment of servers to Azure. Your manager is concerned that you may expose administrative credentials during the deployment. You need to recommend an Azure solution that encrypts the administrative credentials during the deployment. What should you include in the recommendation?

  • AAzure Key Vault (correct answer)
  • BAzure Information Protection
  • CAzure Security Center
  • DAzure Multi-Factor Authentication (MFA)
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Azure Key Vault

Explanation

Azure Key Vault securely stores and manages secrets, keys, and certificates with access policies.

Topic 1 Β· Question 251

You plan to deploy several Azure virtual machines. You need to control the ports that devices on the Internet can use to access the virtual machines. What should you use?

  • Aa network security group (NSG) (correct answer)
  • Ban Azure Active Directory (Azure AD) role
  • Can Azure Active Directory group
  • Dan Azure key vault
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: a network security group (NSG)

Explanation

A Network Security Group (NSG) filters inbound and outbound traffic to subnets and NICs with allow/deny rules. A Network Security Group (NSG) applies allow/deny rules to control traffic at the subnet or NIC level.

Topic 1 Β· Question 254

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your Azure environment contains multiple Azure virtual machines. You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP. Solution: You modify a network security group (NSG). Does this meet the goal?

  • AYes (correct answer)
  • BNo
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Yes.

Topic 1 Β· Question 255

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your Azure environment contains multiple Azure virtual machines. You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP. Solution: You modify a DDoS protection plan. Does this meet the goal?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 1 Β· Question 256

You need to collect and automatically analyze security events from Azure Active Directory (Azure AD). What should you use?

  • AAzure Sentinel (correct answer)
  • BAzure Synapse Analytics
  • CAzure AD Connect
  • DAzure Key Vault
Reveal answer & explanation
Correct answer: A

Azure Sentinel (Microsoft Sentinel) is the cloud-native SIEM/SOAR service that collects and automatically analyzes security events, including sign-in and audit events from Azure AD, and raises alerts. Synapse is analytics, AD Connect is directory sync, and Key Vault stores secrets.

Topic 1 Β· Question 257

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your Azure environment contains multiple Azure virtual machines. You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP. Solution: You modify an Azure firewall. Does this meet the goal?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 1 Β· Question 258

This question requires that you evaluate the underlined text to determine if it is correct. Azure Germany can be used by legal residents of Germany only. Instructions: Review the underlined text. If it makes the statement correct, select `No change is needed`. If the statement is incorrect, select the answer choice that makes the statement correct.

  • Ano change is needed
  • Bonly enterprises that are registered in Germany
  • Conly enterprises that purchase their azure licenses from a partner based in Germany
  • Dany user or enterprise that requires its data to reside in Germany (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: any user or enterprise that requires its data to reside in Germany.

Topic 1 Β· Question 263 Β· Select all that apply

Which two types of customers are eligible to use Azure Government to develop a cloud solution? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

  • Aa Canadian government contractor
  • Ba European government contractor
  • Ca United States government entity (correct answer)
  • Da United States government contractor (correct answer)
  • Ea European government entity
Reveal answer & explanation
Correct answer: C, D

The correct answer is C, D. Option C: a United States government entity Option D: a United States government contractor.

Topic 1 Β· Question 265

You need to ensure that when Azure Active Directory (Azure AD) users connect to Azure AD from the Internet by using an anonymous IP address, the users are prompted automatically to change their password. Which Azure service should you use?

  • AAzure AD Connect Health
  • BAzure AD Privileged Identity Management
  • CAzure Advanced Threat Protection (ATP)
  • DAzure AD Identity Protection (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Azure AD Identity Protection

Explanation

Azure Active Directory (Microsoft Entra ID) provides identity, single sign-on, and conditional access.

Topic 1 Β· Question 267

To what should an application connect to retrieve security tokens?

  • Aan Azure Storage account
  • BAzure Active Directory (Azure AD) (correct answer)
  • Ca certificate store
  • Dan Azure key vault
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Azure Active Directory (Azure AD)

Explanation

Azure Active Directory (Microsoft Entra ID) provides identity, single sign-on, and conditional access.

Topic 1 Β· Question 268

Your network contains an Active Directory forest. The forest contains 5,000 user accounts. Your company plans to migrate all network resources to Azure and to decommission the on-premises data center. You need to recommend a solution to minimize the impact on users after the planned migration. What should you recommend?

  • AImplement Azure Multi-Factor Authentication (MFA)
  • BSync all the Active Directory user accounts to Azure Active Directory (Azure AD) (correct answer)
  • CInstruct all users to change their password
  • DCreate a guest user account in Azure Active Directory (Azure AD) for each user
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Sync all the Active Directory user accounts to Azure Active Directory (Azure AD)

Explanation

Azure Active Directory (Microsoft Entra ID) provides identity, single sign-on, and conditional access.

Topic 1 Β· Question 271

You have a resource group named RG1. You need to prevent the creation of virtual machines in RG1. The solution must ensure that other objects can be created in RG1. What should you use?

  • Aa lock
  • Ban Azure role
  • Ca tag
  • Dan Azure policy (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: an Azure policy

Explanation

Azure Policy enforces organizational rules and compliance across resources at scale.

Topic 1 Β· Question 272

You have an Azure subscription and 100 Windows 10 devices. You need to ensure that only users whose devices have the latest security patches installed can access Azure Active Directory (Azure AD)-integrated applications. What should you implement?

  • Aa conditional access policy (correct answer)
  • BAzure Bastion
  • CAzure Firewall
  • DAzure Policy
Reveal answer & explanation
Correct answer: A

A Conditional Access policy can require devices to be marked compliant (for example, having the latest security patches via Intune) before granting access to Azure AD-integrated applications. Azure Bastion, Azure Firewall, and Azure Policy do not gate application sign-in based on device compliance.

Showing questions 121–140 of 209 Β· Page 7 of 11