SC-500 Cheat Sheet
Manage identity, access, and governance
Secure access to resources by using Microsoft Entra ID
Read full chapterCheat sheet
Sharp facts the exam loves — scan these before test day.
- Eligible PIM assignments require activation before privileges become usable
An eligible assignment supplies no standing role access until the assignee completes its configured activation steps; an active assignment supplies the role without activation. Use eligible assignments when privileged access should exist only just in time.
Trap Create a permanent active assignment and rely on an access review to make each use temporary.
9 questions test this
- Your Microsoft Entra tenant contains a role-assignable group named ElevationGroup that is assigned the Application Administrator role. Engineers hold eligible member assignments for ElevationGroup, an
- Your Microsoft Entra tenant uses Privileged Identity Management (PIM). Yesterday you created an eligible assignment to the Exchange Administrator role for a user named User1, and the role's PIM role s
- You have an Azure subscription named Sub1 and use Privileged Identity Management (PIM) for Azure resource roles. A contractor named User1 joins a six-week data migration project and must manage the st
- You have an Azure subscription named Sub1 that uses Privileged Identity Management (PIM) for Azure resource roles. Resource administrators keep creating permanent active Contributor assignments on Sub
- You have an Azure subscription named Sub1 that contains a resource group named RG1. In Privileged Identity Management (PIM), eight engineers hold eligible User Access Administrator assignments that ar
- Your Microsoft Entra tenant uses Privileged Identity Management (PIM). Every Global Administrator and Privileged Role Administrator in the tenant holds an eligible assignment only, and no active assig
- Your Microsoft Entra tenant uses Privileged Identity Management (PIM). The Cloud Application Administrator role requires approval to activate, and two members of the security team are its designated a
- Your company has a Microsoft Entra tenant that uses Privileged Identity Management (PIM). Ten security engineers hold permanent active assignments to the Security Administrator role, so they carry the
- You have an Azure subscription named Sub1 that contains a resource group named RG1, which hosts Microsoft Foundry resources. A cloud engineer named User1 must be able to manage every resource in RG1,
- PIM approval settings make another administrator authorize elevation
Enable Require approval to activate and designate approvers when an eligible user's request must be explicitly approved before the role becomes active. Requiring justification records a reason but does not create an approval gate.
Trap Require justification on activation.
5 questions test this
- Your Microsoft Entra tenant contains a role-assignable group named ElevationGroup that is assigned the Application Administrator role. Engineers hold eligible member assignments for ElevationGroup, an
- You have an Azure subscription named Sub1 that contains a resource group named RG1. In Privileged Identity Management (PIM), eight engineers hold eligible User Access Administrator assignments that ar
- Your Microsoft Entra tenant uses Privileged Identity Management (PIM). Every Global Administrator and Privileged Role Administrator in the tenant holds an eligible assignment only, and no active assig
- Your Microsoft Entra tenant uses Privileged Identity Management (PIM). The Intune Administrator role requires approval to activate, and a security lead named Admin1 is the only designated approver for
- Your Microsoft Entra tenant uses Privileged Identity Management (PIM). The Cloud Application Administrator role requires approval to activate, and two members of the security team are its designated a
- Activation maximum duration automatically ends each PIM elevation
Set Activation maximum duration to limit how long an approved activation remains active before expiring. Assignment expiration controls how long an eligible or active assignment exists, not the duration of each activation.
Trap Configure Expire eligible assignments after for a four-hour elevation window.
5 questions test this
- Your Microsoft Entra tenant uses Privileged Identity Management (PIM). An engineer named User1 activated an eligible Microsoft Entra role and, when prompted for a duration, accepted the maximum that t
- You have an Azure subscription named Sub1 that contains a resource group named RG-Prod. In Privileged Identity Management (PIM), you configured the Owner role settings on Sub1 to require approval to a
- Your Microsoft Entra tenant uses Privileged Identity Management (PIM). Security engineers hold eligible assignments to a Microsoft Entra role that they activate before a monthly patching window that r
- Your Microsoft Entra tenant uses Privileged Identity Management (PIM). A security engineer named User1 activated an eligible Microsoft Entra role, and the activation reached its maximum duration and e
- You have an Azure subscription named Sub1. In Privileged Identity Management (PIM), an engineer named User1 holds an eligible Owner assignment on a resource group named RG-Web, and the role's Activati
- Azure resource PIM settings are isolated by role and resource
PIM role settings apply to one role at one Azure resource scope, and every assignment for that role at that resource follows them. Settings configured at a subscription do not inherit to the same role at a child resource group.
Trap Configure the role policy once at the management group and expect child-resource policies to inherit it.
4 questions test this
- Your Microsoft Entra tenant uses Privileged Identity Management (PIM). An engineer named User1 activated an eligible Microsoft Entra role and, when prompted for a duration, accepted the maximum that t
- You have an Azure subscription named Sub1 that contains a resource group named RG-Prod. In Privileged Identity Management (PIM), you configured the Owner role settings on Sub1 to require approval to a
- Your Azure environment contains a management group named MG-Core that contains subscriptions named Sub1 and Sub2. In Privileged Identity Management (PIM), engineers hold eligible Owner assignments and
- Your Azure environment contains a management group named MG1 that contains subscriptions named Sub1 and Sub2. In Privileged Identity Management (PIM), an engineer named User1 holds an eligible Contrib
- Use an authentication context when PIM activation must force policy-controlled reauthentication
PIM role settings can require MFA or a Conditional Access authentication context when an eligible user activates a role. A prior strong or MFA authentication in the session can satisfy the ordinary MFA setting; to require reauthentication for each activation, target the authentication context with a Conditional Access sign-in frequency of Every time, noting that a 10-minute reauthentication window still applies across eligible role activations.
2 questions test this
- Your company has a Microsoft Entra tenant that uses Privileged Identity Management (PIM). Security engineers hold eligible assignments to the Cloud Device Administrator role, and the role settings alr
- Your Microsoft Entra tenant uses Privileged Identity Management (PIM). Engineers hold eligible assignments to the Authentication Policy Administrator role, and the role settings require Conditional Ac
- Scope PIM access reviews to the privileged assignment types that require recertification
Create PIM access reviews for Microsoft Entra or Azure resource roles to confirm that privileged access is still required. Select eligible assignments only, active assignments only, or all active and eligible assignments according to which grants must be recertified, then apply the review decisions to remove access that is no longer justified.
4 questions test this
- Your Azure environment contains a subscription named Sub2 that uses Privileged Identity Management (PIM) for Azure resource roles. Engineers and two workload identities hold Virtual Machine Contributo
- Your Microsoft Entra tenant uses Privileged Identity Management (PIM). Each quarter you run an access review of the eligible assignments to the Helpdesk Administrator role. In the last cycle, reviewer
- Your Microsoft Entra tenant uses Privileged Identity Management (PIM). Thirty users hold assignments to the Security Reader role: some can use the role's permissions as soon as they sign in, while the
- You have an Azure subscription named Sub1 that uses Privileged Identity Management (PIM) for Azure resource roles. A quarterly access review of the User Access Administrator role on Sub1 is scheduled
- PIM role settings control activation-notification recipients and urgency filtering
Configure each role's activation notifications by selecting its default recipients and adding other recipient email addresses as needed. Select Critical emails only when those recipients should receive messages requiring immediate action rather than every message of that notification type.
- Use PIM audit history as evidence of privileged role activity
Review or download PIM audit history when evidence of privileged-role assignments and activations is required. PIM makes this history available for internal or external audit.
- A sign-in must satisfy every applicable Conditional Access policy
Microsoft Entra evaluates all Conditional Access policies that apply to the identity and target resource and grants access only when all applicable requirements are met. A block control in any applicable policy prevents access rather than being canceled by a grant in another policy.
Trap Place a permissive grant policy at higher priority so it overrides a separate block policy.
7 questions test this
- You have a Microsoft Entra tenant that contains 45 enabled Conditional Access policies and 6 policies in report-only mode. A user named User1 reports that a sign-in to a SharePoint site was interrupte
- You have a Microsoft Entra tenant. You create a Conditional Access policy named CA20 that includes the Finance group, targets an app named App1, uses a named location called HighRisk-Countries as its
- You are designing a Conditional Access policy for a Microsoft Entra tenant that must require an authentication strength of phishing-resistant multifactor authentication for all users and all resources
- Your Microsoft Entra tenant contains an app named Payroll and a group named Finance. A Conditional Access policy named CA40 targets the Finance group and the Payroll app and grants access when multifa
- Your Microsoft Entra tenant contains two enabled Conditional Access policies that both target the Sales group and all resources: CA10 grants access and requires multifactor authentication, and CA11 gr
- Your company has a Microsoft Entra tenant. A Conditional Access policy named CA01 targets all users and all resources and grants access when multifactor authentication is completed. A second policy na
- You have a Microsoft Entra tenant that contains 30 Conditional Access policies. You plan to onboard an app named App1 for a group named Engineers. Before anyone signs in to App1, you must determine ev
- Broad Conditional Access policies must preserve emergency access
For policies targeting all users, exclude emergency or break-glass accounts so administrators can recover from a lockout. Within one policy, an explicit identity exclusion overrides that identity's inclusion.
Trap Include every Global Administrator so no privileged identity can bypass the policy.
7 questions test this
- Your Microsoft Entra tenant has an enabled Conditional Access policy that targets all users and all resources and requires a device marked as compliant. A group named EmergencyAccess that contains you
- Your company federates its Microsoft Entra tenant to an on-premises Active Directory Federation Services farm. Two emergency access accounts are synchronized from on-premises Active Directory and are
- Your Microsoft Entra tenant contains two emergency access accounts in a security group named EmergencyAccess that is excluded from all 20 enabled Conditional Access policies. Several engineers hold th
- You are designing a Conditional Access policy for a Microsoft Entra tenant that must require an authentication strength of phishing-resistant multifactor authentication for all users and all resources
- Your Microsoft Entra tenant contains an app named Payroll and a group named Finance. A Conditional Access policy named CA40 targets the Finance group and the Payroll app and grants access when multifa
- Your Microsoft Entra tenant contains two emergency access accounts that hold permanently active Global Administrator assignments and are excluded from every enabled Conditional Access policy. Microsof
- Your Microsoft Entra tenant uses Privileged Identity Management. Two emergency access accounts are excluded from every enabled Conditional Access policy, and each account holds an eligible Global Admi
- Report-only mode evaluates a Conditional Access policy without enforcing it
Use report-only mode and inspect the Conditional Access results in sign-in logs to validate expected impact before switching a policy on. Report-only evaluation neither blocks users nor prompts them to satisfy grant or session controls.
Trap Enable the policy for all users and use the audit logs only after enforcement begins.
5 questions test this
- Your Microsoft Entra tenant contains 31 Conditional Access policies. One of them, named CA61, targets the Finance group and all resources and requires multifactor authentication. CA61 has had the Enab
- Your company has a Microsoft Entra tenant that has Microsoft Entra ID P1 licenses and a Microsoft Security Copilot deployment with provisioned security compute units. New users and applications are on
- You have a Microsoft Entra tenant that contains 32 enabled Conditional Access policies and six policies in report-only mode. An internal audit requires a file that covers the past two weeks of sign-in
- You have a Microsoft Entra tenant that contains 40 enabled Conditional Access policies. You must measure the impact of a new policy that targets the user action Register security information and block
- Your company has a Microsoft Entra tenant that contains 25 enabled Conditional Access policies. You create a policy named CA50 that targets the Engineering group and all resources and requires a devic
- User-scoped Conditional Access does not govern service-principal calls
Calls made by service principals are not blocked by Conditional Access policies scoped to users. Use Conditional Access for workload identities when a policy must target service principals, and replace script credentials with managed identities where supported.
Trap Add the application's owner account to an all-users policy and assume the service principal is covered.
3 questions test this
- Your Microsoft Entra tenant has Workload Identities Premium licenses and uses Microsoft Entra ID Protection. A single-tenant line-of-business application named App2 authenticates with its own service
- Your company deploys Azure resources from a GitHub Actions workflow that signs in to Microsoft Entra ID as an app registration named Deploy1 by using a client secret that is stored as a GitHub reposit
- Your Microsoft Entra tenant contains a single-tenant line-of-business application named App3 that calls Microsoft Graph with its own service principal. A Conditional Access policy assigned to App3's s
- Build Conditional Access as an identity-and-resource if-then decision
Assign a Conditional Access policy to the intended users, groups, or workload identities and target resources, then refine applicability with signals such as IP location, device platform or state, and user or sign-in risk. Choose block access or grant access with the required controls, such as MFA, authentication strength, or a compliant device.
6 questions test this
- Your company has enabled adaptive protection in Microsoft Purview, which continuously classifies employees as Minor, Moderate, or Elevated based on data-exfiltration behavior such as bulk downloads be
- Your Microsoft Entra tenant has Microsoft Entra ID P2 licenses. A policy named Microsoft-managed: Multifactor authentication for all users appears in the Conditional Access policy list with Microsoft
- Your company has a Microsoft Entra tenant that uses Privileged Identity Management. Several cloud security engineers hold eligible assignments to the Security Administrator role, and that role current
- In your Microsoft Entra tenant, all users may join and register their own devices, and the device setting Require multifactor authentication to register or join devices with Microsoft Entra is set to
- Your Microsoft Entra tenant contains a group named CloudAdmins whose members administer Azure subscriptions. Every corporate laptop is enrolled in Microsoft Intune and can be marked as compliant, and
- Your company has a Microsoft Entra tenant. A group named PortalOps contains staff who use a browser to work in the Azure portal, the Exchange admin center, and the Microsoft 365 admin center. The same
- Authentication strengths restrict which method combinations satisfy Conditional Access
A Conditional Access authentication strength can require the built-in multifactor, passwordless MFA, or phishing-resistant MFA strength, or a custom set of allowed combinations. Requiring generic MFA does not guarantee that a phishing-resistant method was used.
Trap Use the Require multifactor authentication grant control when only phishing-resistant credentials are acceptable.
8 questions test this
- Your company has a line-of-business web application named App5 that is registered in Microsoft Entra ID and developed in house. Most work in App5 is routine, but approving a wire transfer is highly se
- Your company invited 40 engineers from a partner Microsoft Entra tenant as B2B collaboration guests. A Conditional Access policy in your tenant requires the built-in Phishing-resistant MFA strength fo
- Your company has 900 field technicians who use company-owned iOS and Android phones that have Microsoft Authenticator installed. The technicians sign in with a password and then approve a push notific
- Your company issues smart cards, and Microsoft Entra certificate-based authentication is enabled for all users. Users sign in successfully with their smart cards, and the sign-in logs confirm that the
- Your company has 5,000 users. Every user is registered for a password plus a text message, and 200 executives also carry FIDO2 security keys. A new standard states that a document repository named Rep
- Your company has a design team of 60 users who work only on Intune-managed Mac computers that run macOS 14. A Conditional Access policy requires the built-in Phishing-resistant MFA strength for a medi
- Your company protects all employee sign-ins with a non-Microsoft multifactor authentication provider that is integrated with Microsoft Entra ID as an external authentication method. No employee has re
- A user named User1 has a Windows 11 laptop that is joined to Microsoft Entra ID and is registered for Windows Hello for Business. A Conditional Access policy for a payroll application requires a custo
- Passkeys, Windows Hello, and multifactor CBA can satisfy phishing-resistant strength
The built-in phishing-resistant MFA strength includes passkeys such as FIDO2 security keys, Windows Hello for Business or platform credentials, and multifactor certificate-based authentication. Password plus an SMS code can satisfy MFA strength but not phishing-resistant MFA strength.
Trap Microsoft Authenticator push notification with number matching.
6 questions test this
- Your company invited 40 engineers from a partner Microsoft Entra tenant as B2B collaboration guests. A Conditional Access policy in your tenant requires the built-in Phishing-resistant MFA strength fo
- Your company has 900 field technicians who use company-owned iOS and Android phones that have Microsoft Authenticator installed. The technicians sign in with a password and then approve a push notific
- Your company issues smart cards, and Microsoft Entra certificate-based authentication is enabled for all users. Users sign in successfully with their smart cards, and the sign-in logs confirm that the
- Your company has 5,000 users. Every user is registered for a password plus a text message, and 200 executives also carry FIDO2 security keys. A new standard states that a document repository named Rep
- Your company has a design team of 60 users who work only on Intune-managed Mac computers that run macOS 14. A Conditional Access policy requires the built-in Phishing-resistant MFA strength for a medi
- A user named User1 has a Windows 11 laptop that is joined to Microsoft Entra ID and is registered for Windows Hello for Business. A Conditional Access policy for a payroll application requires a custo
- Temporary Access Pass bootstraps passwordless credential registration
Issue a Temporary Access Pass so a user can perform initial sign-in or recover access and register a passwordless method such as a passkey. A TAP can satisfy MFA strength, but it is not included in the passwordless or phishing-resistant built-in strengths.
Trap Send the user a permanent password and exempt the registration session from MFA.
9 questions test this
- A user named User2 in your Microsoft Entra tenant signs in with a passkey on a FIDO2 security key and has no other registered authentication method. Your organization never issues passwords to its use
- A user named User2 in your Microsoft Entra tenant signs in with a passkey on a FIDO2 security key and has no other registered authentication method. Your organization never issues passwords to its use
- Your company has a Microsoft Entra tenant in which the Temporary Access Pass method is enabled and targeted at a group named AllStaff. A service desk team named Desk1 must be able to create and delete
- Last month your service desk issued Temporary Access Passes that could be used more than once to a group of field employees who were setting up new tablets. This week, to close an audit finding, you e
- A user named User1 has a Windows 11 laptop that is joined to Microsoft Entra ID. User1 signs in only with a FIDO2 security key and Windows Hello for Business and has never been issued a password. Afte
- Your company has 3,000 users who complete multifactor authentication with a text message. Passkey (FIDO2) is enabled for all users and Allow self-service set up is set to Yes, but almost nobody has re
- Your Microsoft Entra tenant contains a group named Contractors, and Passkey (FIDO2) is enabled and targeted at that group with self-service set up allowed. A service desk agent who holds the Authentic
- Your company gives each new hire a Windows 11 laptop that the hire joins to Microsoft Entra ID during setup. New hires are never given a password, so the service desk issues each one a Temporary Acces
- Your company issues a Temporary Access Pass with a one-hour lifetime to each contractor so that the contractor can register a passkey. During a review you find that a contractor who signed in to a web
- Authentication methods policy controls which users can register each method
Enable an authentication method in the Microsoft Entra authentication methods policy and target the intended groups before users can register and use it. Configuring a Conditional Access authentication strength does not itself enable or provision the underlying credentials.
Trap Create a phishing-resistant authentication strength and skip enabling passkeys for the target users.
8 questions test this
- Your Microsoft Entra tenant has Passkey (FIDO2) enabled with All users added as a target and a passkey profile that allows device-bound passkeys. A group named ShopFloor was added to the excluded targ
- Every user in your Microsoft Entra tenant has registered a passkey, and most users also kept a text message as a backup method that the business wants to remain available. Users report that Microsoft
- Your company has 3,000 users who complete multifactor authentication with a text message. Passkey (FIDO2) is enabled for all users and Allow self-service set up is set to Yes, but almost nobody has re
- Your Microsoft Entra tenant contains a group named Contractors, and Passkey (FIDO2) is enabled and targeted at that group with self-service set up allowed. A service desk agent who holds the Authentic
- The Authentication methods policy in your Microsoft Entra tenant is in the Migration in Progress state. In that policy you enabled Passkey (FIDO2) and Microsoft Authenticator for all users, and you ne
- Over two years your team enabled Microsoft Authenticator and Passkey (FIDO2) in the Authentication methods policy and targeted each method at a separate group for every department, so the policy now t
- Your Microsoft Entra tenant verifies sign-ins with Microsoft Authenticator push notifications, and a small group uses voice calls. Attackers have begun sending repeated verification requests to users,
- Your Microsoft Entra tenant uses passkey profiles. A profile named Profile1 targets a group named Admins, allows device-bound passkeys only, restricts registration to the Microsoft Authenticator AAGUI
- Select authentication methods by their documented sign-in, MFA, and recovery capabilities
Choose a method only for the roles its capability table supports: primary authentication, secondary MFA, SSPR, or account recovery. Microsoft Authenticator passwordless supports primary authentication but not secondary MFA or recovery, whereas Authenticator push notifications support primary authentication, MFA, and SSPR; Verified ID supplies account-recovery proof but cannot perform sign-in or MFA.
4 questions test this
- A government agency has a Microsoft Entra tenant and an internal public key infrastructure that already issues smart card certificates to every employee. Employees must complete first factor sign-in t
- Your company operates 60 retail stores, and each store keeps five shared Android tablets that associates use for a shift application registered in your Microsoft Entra tenant. Associates switch tablet
- Your company acquires a subsidiary that already runs a non-Microsoft multifactor authentication service with an OpenID Connect discovery endpoint. A group named Pilot contains 50 subsidiary staff who
- Your company has a Microsoft Entra tenant in which every employee signs in with a passkey and no employee is ever issued a password. A remote engineer named User1 loses both of the devices that hold U
- An app registration defines the application while its service principal represents a tenant instance
The application object stores the global definition configured under App registrations. An enterprise application is the service principal in a tenant, where administrators manage local access settings, assignments, and consent for that tenant instance.
Trap Edit the enterprise application's service principal to change the multitenant application's global definition.
3 questions test this
- Your company has a Microsoft Entra tenant named contoso.onmicrosoft.com. A vendor's multitenant SaaS application named App2 was added to the tenant when an administrator granted admin consent, and App
- Your company, Adatum, develops a multitenant application named App1 that is registered in the Adatum Microsoft Entra tenant. Two customers, Contoso and Fabrikam, have each granted admin consent to App
- You have a Microsoft Entra tenant with Workload Identities Premium licenses. The tenant contains an application named App3 that your team registered. App3 is single-tenant, runs as an unattended daemo
- Delegated permissions act with a user while application permissions act as the app
Use delegated permissions when an application accesses an API on behalf of a signed-in user; effective access is constrained by both the grant and the user's authorization. Use application permissions for app-only background access, and obtain administrator consent because no user context exists.
Trap Convert an interactive on-behalf-of workload to application permissions merely to suppress its user prompt.
4 questions test this
- Your Microsoft Entra tenant has the user consent for applications setting configured as Do not allow user consent. Users report that when they first open a new line-of-business application, they recei
- Your Microsoft Entra tenant has the user consent for applications setting configured as Do not allow user consent. Users report that when they first open a new line-of-business application, they recei
- You have a Microsoft Entra tenant that contains an application named App7 that runs as an unattended background service. App7's registration requests the Microsoft Graph application permissions Mail.S
- Your company has a Microsoft Entra tenant named contoso.onmicrosoft.com. A vendor's multitenant SaaS application named App2 was added to the tenant when an administrator granted admin consent, and App
- Tenant-wide admin consent can preauthorize delegated permissions for all users
When user consent is disabled, grant tenant-wide administrator consent to the required delegated Microsoft Graph permissions so users can sign in without an interactive consent prompt. Adding permissions to the registration alone does not create the OAuth permission grant.
Trap Configure the delegated permissions and rely on each user to consent during sign-in.
7 questions test this
- Your Microsoft Entra tenant allows users to consent to applications from verified publishers for the permissions that you classify as low impact. Your team registered an OpenID Connect application nam
- Your company plans to deploy a vendor's multitenant SaaS application named App23 to all employees next Monday. The vendor supplies the application (client) ID for App23 and states that the application
- Your company is standing up a new Microsoft Entra tenant in which user consent for applications is disabled. A deployment pipeline will register 25 internal line-of-business applications, and each one
- You have a Microsoft Entra tenant named fabrikam.onmicrosoft.com in which user consent for applications is disabled. Your team registered an application named App21 that reads Microsoft Graph data on
- Your Microsoft Entra tenant contains a web application named App22 that your team registered and that was granted tenant-wide admin consent for three delegated Microsoft Graph permissions. A new relea
- Your Microsoft Entra tenant contains an enterprise application named App25 that is configured for SAML-based single sign-on. App25 has the Assignment required property set to Yes, and you assigned a s
- Your Microsoft Entra tenant contains a SaaS application named App24 that appears in Enterprise applications. Some employees use App24 without ever seeing a consent prompt, while others are prompted th
- Requiring assignment restricts who can sign in to an enterprise application
Set Assignment required to Yes and assign permitted users or groups when only selected identities may use an enterprise application. This access control is not a substitute for granting API consent; applications that require assignment need administrator consent rather than user consent.
Trap Require user assignment and assume the setting grants the application's Microsoft Graph scopes.
6 questions test this
- Your Microsoft Entra tenant contains an enterprise application named App28 that hosts a self-service benefits portal. Every employee must be able to open App28 from the user access URL that is shown o
- Your Microsoft Entra tenant allows users to consent to applications from verified publishers for the permissions that you classify as low impact. Your team registered an OpenID Connect application nam
- You have a Microsoft Entra tenant named fabrikam.onmicrosoft.com in which user consent for applications is disabled. Your team registered an application named App21 that reads Microsoft Graph data on
- Your Microsoft Entra tenant contains an enterprise application named App25 that is configured for SAML-based single sign-on. App25 has the Assignment required property set to Yes, and you assigned a s
- Your Microsoft Entra tenant is licensed for Microsoft Entra ID P1 and contains an enterprise application named App29 that uses OpenID Connect. App29 has Assignment required set to Yes, and only a grou
- Your Microsoft Entra tenant contains a SaaS application named App24 that appears in Enterprise applications. Some employees use App24 without ever seeing a consent prompt, while others are prompted th
- Use nonsecret credentials for production confidential clients
Use a certificate or federated identity credential instead of a client secret for a production confidential client; federation lets supported external workloads obtain tokens without managing a secret. If a client secret is temporarily unavoidable, set and track its expiration for replacement before it expires: its lifetime cannot exceed 24 months, and Microsoft recommends less than 12 months.
2 questions test this
- Your datacenter hosts a Windows service named Service1 that runs unattended on physical servers and calls Microsoft Graph as an app registration named App32 in your Microsoft Entra tenant. No external
- You have an Azure subscription that contains a virtual machine named VM1, and a Microsoft Entra tenant that contains an app registration named App33. An application on VM1 must call Microsoft Graph as
- Constrain user consent and escalate disallowed grants for administrator review
Apply the low-impact user-consent policy so users can consent only to selected low-impact permissions for verified-publisher applications or applications registered in the tenant. Enable the admin-consent workflow so requests outside that policy can be submitted for administrator review instead of being granted by the user.
4 questions test this
- Your Microsoft Entra tenant restricts user consent to low-impact delegated permissions for verified-publisher applications, and the admin consent workflow is not yet enabled. The help desk is receivin
- Your Microsoft Entra tenant lets users consent to applications from verified publishers and to applications registered in the tenant, for the delegated permissions that you classify as low impact. A s
- Your Microsoft Entra tenant has the admin consent workflow enabled, and three named administrators are listed as the reviewers for admin consent requests that involve delegated Microsoft Graph permiss
- Your Microsoft Entra tenant currently allows users to consent to applications from verified publishers for the delegated permissions that you classify as low impact. A new security policy states that
- Assign nested group members explicitly when an enterprise application requires assignment
An enterprise application's group assignment grants access only to users directly in the assigned group; it does not cascade through nested groups. Assign a nested group or its intended users directly when they must receive the application's access or app role.
- Managed identities obtain Microsoft Entra tokens without application-held credentials
Code running on a supported Azure host can use its managed identity through Azure Identity or MSAL to request a token without storing a client secret or certificate. The target service must support Microsoft Entra authentication, and the identity still needs authorization to the target resource.
Trap Create an app registration and store its client secret in the workload configuration.
7 questions test this
- You have an Azure subscription that contains an API Management instance named APIM1 and a Microsoft Foundry resource that hosts a model deployment. Client applications reach the model only through API
- Your company has an Azure subscription that contains a virtual machine named VM1 with a user-assigned managed identity named UMI1. An application on VM1 must call a partner company's REST API that acc
- You have an Azure subscription that contains a web app named App1 in Azure App Service. App1 has a system-assigned managed identity and must read the profiles of all users in your Microsoft Entra tena
- You have an Azure subscription that contains an Automation account named AA1. A PowerShell runbook in AA1 stops virtual machines every night by signing in with a Microsoft Entra service principal whos
- Your company has an Azure subscription that contains an Azure Kubernetes Service (AKS) Standard cluster named cluster1 and a key vault named KV1 that uses the Azure RBAC permission model. Pods in thre
- Your on-premises datacenter contains a Windows Server named Server1 that is connected to Azure Arc-enabled servers in a subscription named Sub1. A scheduled, unattended process on Server1 must retriev
- You have an Azure subscription that contains a virtual machine named VM1. Two user-assigned managed identities named UMI1 and UMI2 are assigned to VM1, and no system-assigned identity is enabled on VM
- A system-assigned managed identity follows one resource's lifecycle
Enabling a system-assigned identity creates a service principal tied to that Azure resource, and deleting the resource causes Azure to delete the identity. Only its parent resource can use that identity to request tokens.
Trap Share one system-assigned identity across a web app and a virtual machine.
7 questions test this
- You have an Azure subscription that contains a virtual machine named VM1 in a resource group named RG-Pay. VM1 hosts two applications: a payments service that uses the system-assigned managed identity
- You have an Azure subscription named Sub1 that contains five virtual machines in a resource group named RG-Ingest. All five share a user-assigned managed identity named UMI1 that holds the Azure Event
- You have an Azure subscription named Sub1 that contains a resource group named RG-Dev in which several application teams deploy their own workloads. Your organization requires that every workload iden
- You have an Azure subscription named Sub1 in which 40 virtual machines that each had a system-assigned managed identity were decommissioned last quarter. Access control (IAM) for several storage accou
- You have an Azure subscription named Sub1 that contains a resource group named RG-App. A platform team pre-creates a user-assigned managed identity named UMI-App in a separate resource group and grant
- Your company completed a merger and transferred an Azure subscription named Sub1 from one Microsoft Entra directory to another. Sub1 contains a web app named App1 in Azure App Service that read blobs
- You have an Azure subscription that contains an Azure App Service web app named App1 and a storage account named storage1. App1 has a system-assigned managed identity that holds a data role on storage
Create a user-assigned identity as an independent Azure resource when several hosts need the same permissions or authorization must exist before workload deployment. Removing or deleting a host does not automatically delete this identity.
Trap Enable a separate system-assigned identity on every ephemeral instance when permissions must be precreated and shared.
7 questions test this
- You have an Azure subscription named Sub1 in which a deployment pipeline creates a function app named func1 in a resource group named RG-App. The pipeline runs as a service principal that holds the Co
- You have an Azure subscription named Sub1 that contains two virtual machines and two App Service web apps that all run the same processing tier. Each of the four resources must read the same reference
- You have an Azure subscription named Sub1 in which an automated test pipeline creates and deletes about 200 virtual machines every night in a resource group named RG-Test. Each virtual machine is depl
- You have an Azure subscription named Sub1 that contains three App Service web apps that read messages from a Service Bus namespace named sb1. All three apps were configured to use a user-assigned mana
- You have an Azure subscription named Sub1 that contains a key vault named KV1 that has soft delete and purge protection enabled. KV1 contains an RSA key named key1. You plan to deploy a new storage ac
- You have an Azure subscription named Sub1 that contains a resource group named RG-Batch and a resource group named RG-Identity. RG-Batch contained 12 virtual machines that used a user-assigned managed
- You have an Azure subscription named Sub1 that contains a premium container registry named acr1 and a resource group named RG-Jobs. A scheduled process deploys container groups to Azure Container Inst
- A managed identity needs a least-privilege role on every downstream resource
Assign the managed identity a role that permits the required data operation at the narrowest target scope; enabling the identity on the source host authenticates it but grants no target access. Anyone able to run code on the source can exercise permissions of identities attached to that source.
Trap Grant Contributor on the source application and expect it to read a destination key vault automatically.
5 questions test this
- You have an Azure subscription named Sub1 that contains a resource group named RG-App and a resource group named RG-Sec. RG-Sec contains a Log Analytics workspace named Workspace1. From the Azure port
- You have an Azure subscription that contains an Azure App Configuration store named appcs1 and a web app named App1 in Azure App Service. Access key authentication is disabled on appcs1. App1 has a sy
- You have an Azure subscription named Sub1 that contains an Azure Cosmos DB for NoSQL account named cosmos1 and a function app named func1. func1 has a system-assigned managed identity that holds the C
- You have an Azure subscription that contains a Key Vault Managed HSM named HSM1 and a virtual machine named VM1. HSM1 holds an RSA key named signkey1 along with several other keys. A payment applicati
- You have an Azure subscription that contains an Event Grid custom topic named topic1, a Service Bus namespace named sb1 that contains a queue named queue1, and a storage account named storage1. Compan
Secure secrets and keys by using Azure Key Vault
Read full chapterCheat sheet
Sharp facts the exam loves — scan these before test day.
- Key Vault separates secrets, keys, and managed certificates from application code
Deploy Azure Key Vault to centrally store secrets such as connection strings, cryptographic keys, and certificates with their private keys. Applications should reference vault objects instead of embedding sensitive values in source code or configuration.
Trap Store the connection string in an App Service setting and protect only the deployment slot.
7 questions test this
- You have an Azure subscription that contains a key vault named KV1 and a web app named App1. App1 presents a TLS certificate that is stored as a password-protected PFX file in App1's source control re
- Your company deploys an Azure SQL Database logical server by using an Azure Resource Manager template that a release pipeline runs. The administrator password is written into the parameter file that i
- You have an Azure subscription that contains a key vault named KV1 and a function app named Func1. KV1 uses the Azure RBAC permission model and stores a secret that holds a third-party API key. Func1
- You have an Azure subscription that contains an App Service web app named App1 and a key vault named KV1. App1 reads a database connection string from an app setting that stores the value in plaintext
- You have an Azure subscription that contains a key vault named KV1 and an internal document service that runs on Azure App Service. The service must apply RSA digital signatures to documents by using
- Your company has an Azure subscription that contains an Azure Application Gateway v2 instance named AppGw1 and a key vault named KV1 that uses the Azure RBAC permission model. AppGw1 publishes a custo
- Your company publishes a Microsoft Foundry model deployment through an Azure API Management instance named APIM1 that acts as an AI gateway. An inbound policy adds the model endpoint's API key to a he
- Separate vaults reduce the blast radius across applications and environments
Use separate key vaults for different applications, regions, and environments such as development and production when their security boundaries differ. Combining unrelated secrets in one vault broadens the impact of an identity or network compromise.
Trap Place every environment in one vault and separate access only by secret name prefixes.
6 questions test this
- Your Azure subscription named Sub1 contains a key vault named KV1 that holds the secrets of a regulated payroll application. A platform team holds the Key Vault Administrator role at the Sub1 scope so
- Your company has an Azure subscription that contains a key vault named KV1. KV1 stores the API keys that are used by a production Microsoft Foundry deployment and by a development sandbox in which the
- You have an Azure subscription that contains a key vault named KV1 that has its firewall enabled. KV1 stores the secrets of a production web app that runs in a virtual network named VNet1, and it also
- Your Azure subscription contains a key vault named KV1 that stores the secrets of a business-critical web app. KV1 is in a region for which Microsoft provides no replication or failover to a paired re
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure RBAC permission model. KV1 holds the RSA key that encrypts three storage accounts with customer-managed keys, and
- Your Azure subscription contains a key vault named KV1 in the East US region. A line-of-business application runs in East US, West Europe, and Southeast Asia, and every instance of the application ret
- Soft delete preserves deleted vaults and objects for recovery
Key Vault soft delete retains deleted vaults and objects during a configurable 7-to-90-day retention period so they can be recovered. A normal delete does not immediately make the name reusable because the item remains in the deleted state.
Trap Use a resource lock as the mechanism for recovering a deleted secret version.
6 questions test this
- Your company has a management group named MG1 that contains all of the Azure subscriptions used by the application teams, and more subscriptions will join MG1 during the next year. A compliance requir
- You have an Azure subscription named Sub1 that contains a key vault named KV-Prod in the West Europe region. Soft delete and purge protection are both enabled on KV-Prod, and the vault has a retention
- Your company has an Azure subscription named Sub1 that contains a key vault named KV1 in the East US region. KV1 has a soft-delete retention period of 90 days, and purge protection is disabled on the
- Your company has an Azure subscription named Sub1 that contains a sandbox environment which a release pipeline tears down and redeploys every night in the East US region. The environment includes a ke
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure RBAC permission model. An administrator deleted KV1 by mistake, and a member of the platform team recovered the v
- You have an Azure subscription named Sub1 in which several decommissioned projects left key vaults in the soft-deleted state. Purge protection was never enabled on any of those vaults. A platform engi
- Purge protection blocks permanent deletion during retention
Enable purge protection after soft delete when even highly privileged callers must be unable to purge deleted vault content before retention expires. Purge protection protects against malicious or accidental permanent deletion; soft delete alone still permits an authorized purge.
Trap Enable soft delete only and grant purge permission to the vault administrators.
6 questions test this
- You have an Azure subscription named Sub1 that contains a key vault named KV-Prod. A release pipeline redeploys KV-Prod every night from an Azure Resource Manager template in which the vault's purge p
- You have an Azure subscription named Sub1 that contains a key vault named KV1. KV1 uses the Azure RBAC permission model, has soft delete and purge protection enabled, and holds the customer-managed ke
- You have an Azure subscription named Sub1 that contains a soft-deleted key vault named KV-Fin in the East US region. Purge protection was enabled on KV-Fin before the vault was deleted, and 45 days of
- Your company has an Azure subscription named Sub1 in which project teams create their own key vaults for short-lived projects. A new data-retention standard states that after a vault is deleted, its c
- You have an Azure subscription named Sub1 that contains a key vault named KV-Legacy that was created several years ago. Soft delete is disabled on KV-Legacy, and the vault stores the certificates of a
- Your company has a management group named MG1 that contains an Azure subscription named Sub1. A policy assignment at MG1 denies the creation of any key vault that does not have purge protection enable
- Use a separate Key Vault for each tenant in a multitenant solution
Deploy a separate Key Vault for each tenant in a multitenant SaaS solution. A per-tenant vault boundary preserves isolation between customer data and workloads.
- Keep customer content and general configuration outside Key Vault
Use Key Vault for keys, secrets, and certificates, not as a scalable store for customer content or general service configuration. Place customer content in a data service such as Azure Storage or Azure Cosmos DB and use an appropriate configuration store for nonsensitive settings.
- Managing a vault does not inherently grant access to its contents
Key Vault control-plane permissions manage the vault resource, while data-plane permissions operate on keys, secrets, and certificates. A principal can therefore create or configure a vault yet remain unable to read a secret unless separately authorized for the data plane.
Trap Assign Key Vault Contributor to an application that only needs to retrieve secret values.
5 questions test this
- You have an Azure subscription named Sub1 that contains a key vault named KV1. KV1 uses the Azure role-based access control permission model, and no role assignments exist on KV1. You are assigned the
- You have an Azure subscription that contains a storage account named storage1 and a key vault named KV1. KV1 uses the Azure role-based access control permission model, has purge protection enabled, an
- Your company deploys infrastructure by using a pipeline whose service principal, SP1, holds the Key Vault Contributor role at the scope of a subscription named Sub1. A new pipeline stage creates a key
- You have an Azure subscription that contains a key vault named KV1 and a function app named Func1. KV1 uses the Azure role-based access control permission model. A user-assigned managed identity named
- You have an Azure subscription that contains a key vault named KV1. KV1 uses the Azure role-based access control permission model and stores the keys, secrets, and certificates of a production workloa
- Azure RBAC is the recommended Key Vault data authorization model
With the RBAC permission model, grant data access through Azure role assignments at the vault or narrower object scope; legacy vault access policies are a different authorization model. Do not create an access policy for a vault configured to use RBAC authorization.
Trap Add a legacy access policy to repair access on an RBAC-authorized vault.
6 questions test this
- You have an Azure subscription that contains a key vault named KV1 that uses the vault access policy permission model. KV1 has 14 access policies that grant key and secret permissions to applications
- Your company has a management group named MG1 that contains 30 Azure subscriptions, and application teams frequently create key vaults that use the vault access policy permission model. You must preve
- You have an Azure subscription that contains a key vault named KV1 that uses the vault access policy permission model. Three engineers hold standing access policies that grant them full key and secret
- Your company has an Azure subscription that contains a key vault named KV1 that uses the Azure role-based access control permission model. Two application teams store their secrets in KV1. Each team m
- You have an Azure subscription that contains a key vault named KV1 and a function app named Func1. KV1 uses the Azure role-based access control permission model. A user-assigned managed identity named
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure role-based access control permission model. KV1 was deleted by mistake and was then recovered from the soft-delet
- Object-specific Key Vault roles enforce least privilege
Assign Key Vault Secrets User to read secret contents, Key Vault Crypto User to perform cryptographic operations with keys such as sign, verify, encrypt, decrypt, wrap, and unwrap, or Key Vault Certificates Officer to manage certificates, according to the required object type. An Officer role performs any action on its object class, so Key Vault Crypto Officer is the role for managing keys, not for using them, and broad management roles are not required merely to consume one class of vault data.
Trap Assign Owner at the resource-group scope to every application that retrieves one secret.
5 questions test this
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure role-based access control permission model and an Azure Data Factory instance named ADF1. A pipeline in ADF1 copi
- You have an Azure subscription named Sub1 that contains a Premium key vault named KV1 that uses the Azure role-based access control permission model. KV1 stores an exportable HSM-protected RSA key nam
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure role-based access control permission model. KV1 holds 40 secrets that belong to different workloads. Three applic
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure role-based access control permission model and an Azure Application Gateway v2 instance named AGW1 that is deploy
- Your company has an Azure subscription that contains a resource group named RG1. RG1 contains a key vault named KV1 that uses the Azure role-based access control permission model. To let three applica
- Credential-free vault access requires both a managed identity and data permission
Enable a managed identity on the Azure workload and assign that identity the required Key Vault data role when an application must retrieve objects without stored credentials. Network reachability alone, including a private endpoint, does not authenticate or authorize the application.
Trap Create only a private endpoint because the application already resides in the connected virtual network.
6 questions test this
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure role-based access control permission model and an Azure Data Factory instance named ADF1. A pipeline in ADF1 copi
- You have an Azure subscription that contains an API Management instance named APIM1 and a key vault named KV1 that uses the Azure role-based access control permission model. APIM1 uses a user-assigned
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure role-based access control permission model and a container app named App1 in Azure Container Apps. App1 has a sys
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure role-based access control permission model and an Azure Application Gateway v2 instance named AGW1 that is deploy
- Your company has an Azure subscription that contains a resource group named RG1. RG1 contains a key vault named KV1 that uses the Azure role-based access control permission model. To let three applica
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure role-based access control permission model. A stateless workload runs on a virtual machine scale set that is rede
- Grant Key Vault administrative object operations at vault scope
Use a vault-level Azure RBAC assignment for Key Vault administrative operations such as object management, monitoring, and network access control. An object-scope assignment is not read-only - it grants the role's full data actions on the one key, secret, or certificate it names, so a Key Vault Secrets Officer scoped to a single secret can update or delete that secret - but it cannot reach operations that have no object path, such as creating a new secret, enumerating the vault's objects, or changing vault resource settings. Microsoft therefore states that assigning roles on individual keys, secrets, and certificates is not recommended, with exceptions such as a user who must read their own SSH private key to authenticate to a virtual machine through Azure Bastion.
4 questions test this
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure role-based access control permission model. Four application teams hold Key Vault Secrets Officer role assignment
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure role-based access control permission model. KV1 stores 60 secrets that belong to several workloads. A support eng
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure role-based access control permission model. KV1 stores the SSH private key of each of 40 engineers as a separate
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure role-based access control permission model. A deployment pipeline signs in with a user-assigned managed identity
- Key Vault networking filters requests before identity authorization
A vault with its firewall disabled accepts requests from public networks by default, but each caller must still authenticate with Microsoft Entra ID and pass data-plane authorization. Enabling a firewall narrows network reachability and does not replace RBAC or access policies.
Trap Leave public access open because a firewall is unnecessary once the application has a managed identity.
7 questions test this
- You have an Azure subscription that contains a key vault named KV1 and a virtual network named VNet1 that contains a subnet named Subnet1. Virtual machines in Subnet1 read secrets from KV1 by using ma
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure RBAC permission model. The KV1 firewall allows the two public IP address ranges from which your corporate network
- You have an Azure subscription that contains a key vault named KV1 and a virtual machine named VM1 that resides in a subnet named Subnet1. KV1 uses the Azure RBAC permission model. You set the KV1 fir
- You have an Azure subscription that contains a key vault named KV1 and an Azure SQL Database logical server named Server1. Server1 uses transparent data encryption with a customer-managed key that is
- You have an Azure subscription that contains a key vault named KV1 that stores the connection strings of a web app named App1. KV1 uses the Azure RBAC permission model, and App1 authenticates to KV1 w
- You have an Azure subscription named Sub1 in which 40 application teams create their own key vaults. Because the Key Vault firewall is disabled when a vault is created, several vaults in Sub1 currentl
- You have an Azure subscription that contains a key vault named KV1. KV1 stores a customer-managed key that a Recovery Services vault uses to encrypt backups, and the option to allow trusted Microsoft
- Key Vault firewall virtual-network rules require the Key Vault service endpoint
To permit a subnet through a Key Vault virtual-network firewall rule over the public endpoint, enable the Microsoft.KeyVault service endpoint on that subnet and add the subnet rule. An NSG allow rule by itself does not place the subnet on the vault firewall allowlist.
Trap Add only an outbound HTTPS NSG rule from the subnet to the vault's public address.
5 questions test this
- You have an Azure subscription that contains a key vault named KV1 and a virtual machine named VM1 that resides in a subnet named Subnet1. The KV1 firewall denies access by default and contains one IP
- You have an Azure subscription that contains a key vault named KV1 and a virtual network named VNet1 that contains a subnet named Subnet1. Virtual machines in Subnet1 read secrets from KV1 by using ma
- You have an Azure subscription that contains a key vault named KV1 and a virtual machine named VM1 that resides in a subnet named Subnet1. KV1 uses the Azure RBAC permission model. You set the KV1 fir
- You have an Azure subscription in which a central networking team owns a virtual network named VNet1 and its subnet named Subnet1, and your team owns a key vault named KV1. You hold the Key Vault Cont
- You have an Azure subscription that contains a new key vault named KV1 and a virtual network named VNet1 that contains a subnet named Subnet1. Ten virtual machines in Subnet1 must read secrets from KV
- Disable public access when a vault must be reachable only through Private Link
Create a private endpoint, integrate name resolution with the privatelink.vaultcore.azure.net private DNS zone, and disable public network access for private-only data-plane connectivity. A private endpoint does not by itself disable the vault's public endpoint.
Trap Create the private endpoint but leave public network access enabled for all networks.
4 questions test this
- You have an Azure subscription that contains a key vault named KV1 in the West Europe region. An application team runs virtual machines in a subnet named Subnet1 of a virtual network named VNet1 in th
- You have an Azure subscription that contains a key vault named KV1 that has public network access disabled. A partner organization in a different Microsoft Entra tenant runs an application that must r
- You have an Azure subscription that contains a key vault named KV1 and a virtual network named VNet1. To meet a compliance requirement, you create a private endpoint for KV1 in a subnet of VNet1, the
- You have an Azure subscription that contains a key vault named KV1 and a function app named Func1 that runs on Linux in an Elastic Premium plan. KV1 has public network access disabled and a private en
- Trusted-services bypass admits only explicitly listed Microsoft services
Allow trusted Microsoft services to bypass the Key Vault firewall only when the required integration appears on the documented trusted-services list. The option is not a blanket allow for every Azure service; for example, Azure DevOps still needs another permitted network path.
Trap Enable trusted-services bypass and assume any Microsoft-hosted build agent can reach the vault.
5 questions test this
- You have an Azure subscription that contains a key vault named KV1 in the East US region and 20 virtual machines that run Windows Server in the same region. The KV1 firewall denies access by default,
- Your company has an Azure subscription that contains a key vault named KV1. The KV1 firewall denies access by default, and the exception that allows trusted Microsoft services to bypass the firewall i
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure RBAC permission model and an Application Gateway v2 instance named AGW1. KV1 stores the TLS certificate that an H
- You have an Azure subscription that contains a key vault named KV1. You enable the KV1 firewall, set it to deny access by default, and select the exception that allows trusted Microsoft services to by
- You have an Azure subscription that contains a key vault named KV1 that uses the Azure RBAC permission model. You enable the KV1 firewall, add virtual network rules for the application subnets in a vi
- Allow required static public clients with Key Vault IPv4 firewall rules
When a required client must use the public endpoint and has a public static IPv4 address or known CIDR range, enable access from selected networks, add that address or range to the Key Vault firewall allowlist, and keep the default action set to Deny. Sources not matched by an allowed IP, virtual-network rule, trusted-service exception, or other permitted path remain blocked.
6 questions test this
- You have an Azure subscription that contains a key vault named KV7 that stores production secrets. KV7 currently allows public access from all networks. A new standard requires that KV7 accept data-pl
- You have an Azure subscription that contains a key vault named KV9 that stores the secrets of an internal payroll application. The payroll application reaches KV9 through a virtual network rule, and p
- You have an Azure subscription that contains a key vault named KV4 that stores API credentials for a public-facing service. The KV4 networking page lists IP address rules for the two published egress
- Your company has an Azure subscription that contains a key vault named KV5 that several application teams share. The KV5 firewall is disabled, so any network can send requests to the vault. Before you
- Your company has an Azure subscription that contains a key vault named KV2 and a multitenant App Service web app named App4 that must read connection strings from KV2. KV2 allows public access only fr
- Your company has an Azure subscription that contains an App Service web app named App7 that runs on a Premium v4 plan. App7 must read secrets from a key vault named KV8 that a partner security team ad
- Use Network Security Perimeter rules to isolate public PaaS access
Associate Key Vault with a Network Security Perimeter when it must share a logical isolation boundary with supported PaaS resources and admit public inbound access only through explicit perimeter rules. In Secure by perimeter mode, perimeter rules govern all non-private-endpoint traffic and override the Key Vault trusted-services firewall bypass.
- Key rotation creates a new version rather than replacing old key material
A per-key rotation policy can automatically generate a fresh version at a configured interval or before expiration. Consumers should use a versionless key URI to discover the newest version while retaining versioned references needed to decrypt or unwrap data protected by older material.
Trap Delete every previous key version immediately after automatic rotation completes.
10 questions test this
- You have an Azure key vault named KV7 that stores the customer-managed keys for several Azure storage accounts. Soft delete is enabled on KV7 with a 90-day retention period, and several operators hold
- Your company runs a custom payroll service on Azure that generates a data encryption key for every stored document and wraps that key with an RSA key named Key4 in an Azure key vault named KV4. Key4 h
- You have an Azure SQL Database logical server named Server1 whose transparent data encryption (TDE) protector is a customer-managed key named Key10 in an Azure key vault named KV10. Auto-rotate key is
- You have an Azure key vault named KV5 that uses the Azure RBAC permission model and contains a key named Key5. Key5 has a rotation policy that renews the key every two years, and the next scheduled re
- You have an Azure storage account named storage2 that is encrypted with a customer-managed key named Key8 in an Azure key vault named KV8. The encryption settings of storage2 omit the key version. An
- You have an Azure key vault named KV3 that uses the Azure role-based access control (RBAC) permission model. KV3 stores the customer-managed keys for several production storage accounts, and it also s
- Your company stores an RSA key named Key2 in an Azure key vault named KV2. Key2 is generated in an on-premises hardware security module and imported into KV2, and a corporate standard requires that al
- You are configuring an Azure storage account named storage4 to use a customer-managed key named Key14 that is stored in an Azure key vault named KV14. Key14 has a rotation policy that creates a new ve
- You have an Azure key vault named KV12 that an administrator has just converted from vault access policies to the Azure role-based access control (RBAC) permission model. KV12 contains a customer-mana
- Your Azure subscription contains 60 virtual machines whose OS and data disks are encrypted with a customer-managed key named Key9 through a disk encryption set named DES1. Key9 has a Key Vault rotatio
- Rotating a key does not re-encrypt the protected payload
Key Vault rotation creates new wrapping-key material; the target service must rewrap its data-encryption keys with the new version. Keep old and new versions enabled until rewrapping finishes because existing data can still depend on the prior version.
Trap Assume Key Vault automatically decrypts and re-encrypts all application data when the key version changes.
9 questions test this
- Your company runs a custom payroll service on Azure that generates a data encryption key for every stored document and wraps that key with an RSA key named Key4 in an Azure key vault named KV4. Key4 h
- You have an Azure SQL Database logical server named Server1 whose transparent data encryption (TDE) protector is a customer-managed key named Key10 in an Azure key vault named KV10. Auto-rotate key is
- You have an Azure key vault named KV5 that uses the Azure RBAC permission model and contains a key named Key5. Key5 has a rotation policy that renews the key every two years, and the next scheduled re
- You have an Azure storage account named storage2 that is encrypted with a customer-managed key named Key8 in an Azure key vault named KV8. The encryption settings of storage2 omit the key version. An
- Your company has a line-of-business application that stores every customer file with its own data encryption key, and each data encryption key is wrapped by an RSA key named Key13 in an Azure key vaul
- You are configuring an Azure storage account named storage4 to use a customer-managed key named Key14 that is stored in an Azure key vault named KV14. Key14 has a rotation policy that creates a new ve
- You have an Azure key vault named KV12 that an administrator has just converted from vault access policies to the Azure role-based access control (RBAC) permission model. KV12 contains a customer-mana
- Your company has a Microsoft Foundry resource named Foundry1 that encrypts its data at rest with a customer-managed key named Key11 in an Azure key vault named KV11. KV11 is in the same region as Foun
- Your Azure subscription contains 60 virtual machines whose OS and data disks are encrypted with a customer-managed key named Key9 through a disk encryption set named DES1. Key9 has a Key Vault rotatio
- A Key Vault certificate policy governs issuance and renewal across versions
Configure the certificate policy with issuer, validity, key, and lifetime-action settings to control creation and renewal. Integrated certificate authorities and self-signed certificates can support automatic renewal; renewing an integrated-CA certificate creates a new secret version and identifier.
Trap Store the PFX as a generic secret and expect Key Vault certificate autorenewal to manage it.
5 questions test this
- You have an Azure web app named App4 that serves the custom domain www.contoso.com. The TLS certificate bound to App4 was imported from an Azure key vault named KV4, and the certificate renews automat
- Your company has an Azure subscription named Sub5 that contains 30 key vaults owned by different application teams. A new security standard states that any TLS certificate created in a key vault in Su
- Your company has an Azure key vault named KV2 that stores a TLS certificate named Cert2 for an internal web application. Cert2 was issued by your organization's own certificate authority, which is not
- You have an Azure key vault named KV1 that uses the Azure role-based access control permission model. KV1 contains a certificate named Cert1 that was created through a DigiCert issuer object configure
- Your company centralizes public key infrastructure in an Azure key vault named KV-PKI, where the security team created a certificate issuer object named DigiCertIssuer that holds the DigiCert account
- Secrets need explicit expiration and rotation procedures
Set expiration metadata, monitor approaching expiry, and create a new secret version when a credential changes; Key Vault does not automatically rotate arbitrary application secrets. Update or reload consumers before disabling the old version to avoid an outage.
Trap Enable a cryptographic key rotation policy and expect it to rotate database passwords stored as secrets.
3 questions test this
- You have an Azure web app named App10 whose app settings use Key Vault references to read a database connection string from an Azure key vault named KV10. The system-assigned managed identity of App10
- You have an Azure Kubernetes Service cluster named AKS11 that uses the Azure Key Vault provider for Secrets Store CSI Driver add-on. Pods mount an API key from an Azure key vault named KV11 as a file
- You have an Azure key vault named KV12 that uses the Azure role-based access control permission model and stores application credentials as secrets, keys, and certificates. You deploy a function app n
- Store managed certificates as Key Vault certificate objects
Store a service-owned certificate as a Key Vault certificate object, not as a generic secret, when Key Vault must manage issuance and autorenewal. A generic secret can hold certificate data but does not provide the managed certificate lifecycle.
5 questions test this
- You have an Azure Application Gateway v2 instance named AGW1 that terminates TLS for an internal web app. A premium key vault named KV3 stores the site's certificate, which the security team created w
- Your company has an Azure API Management instance named APIM1 in the Premium tier whose gateway calls an internal AI backend that requires mutual TLS. The client certificate is stored in a key vault n
- Your company protects outbound traffic with an Azure Firewall Premium instance named FW1 that uses a firewall policy named FWPolicy1. You must enable TLS inspection on FWPolicy1 by using the intermedi
- Your company has an Azure Key Vault Managed HSM instance named HSM1 and a premium key vault named KV4 in the same subscription. You must obtain the TLS certificate for an internal service from the cor
- You have an Azure subscription that contains a key vault named KV5 and an internal application named App5 that signs outbound messages with an X.509 certificate stored in KV5. KV5 contains a GlobalSig
- Back up irreplaceable vault objects and test their restoration
Use Key Vault native backup for keys, secrets, and certificates that cannot be recreated from another source. Regularly restore test copies to verify the recovery procedure; object backup is a separate recoverability control from retaining a deletion through soft delete.
- Defender CSPM can discover plaintext secrets without an installed VM agent
Enable agentless machine scanning in Defender CSPM to identify supported exposed credentials on Azure, AWS, and GCP virtual-machine disks without installing an agent or affecting machine performance. Defender for Servers Plan 2 can also provide machine secrets scanning, but Defender CSPM is required for the broader posture scenario.
Trap Deploy the Log Analytics agent and search only Key Vault diagnostic logs for secrets embedded on VM disks.
9 questions test this
- You have an Azure subscription named Sub1 that has the Microsoft Defender Cloud Security Posture Management (CSPM) plan enabled and Agentless scanning for machines turned on. The Recommendations page
- Your company has an Azure subscription and an AWS account that are both connected to Microsoft Defender for Cloud, and the Defender Cloud Security Posture Management (CSPM) plan is enabled on both env
- Your company has an Amazon Web Services (AWS) account that is connected to Microsoft Defender for Cloud through a connector named AWSConn1, and the Defender Cloud Security Posture Management (CSPM) pl
- You have an Azure subscription named Sub1 that contains 30 virtual machines and has the Microsoft Defender for Servers Plan 2 plan enabled, and secrets findings are already reported for the virtual ma
- You have an Azure subscription named Sub1 that contains 25 virtual machines that run Windows Server. Only the Microsoft Defender for Servers Plan 1 plan is currently enabled on Sub1. Your security tea
- You have an Azure subscription named Sub1 that contains 60 virtual machines. Sub1 has the Microsoft Defender Cloud Security Posture Management (CSPM) plan enabled, and Agentless scanning for machines
- You have an Azure subscription named Sub1 that contains 80 virtual machines. Sub1 has the Microsoft Defender Cloud Security Posture Management (CSPM) plan enabled, and Agentless scanning for machines
- You have an Azure subscription named Sub1 that contains 40 virtual machines. Sub1 has the Microsoft Defender Cloud Security Posture Management (CSPM) plan enabled, and Agentless scanning for machines
- Your company uses Microsoft Defender for Cloud to protect an Azure subscription, an AWS account, and a GCP project. The Defender Cloud Security Posture Management (CSPM) plan and agentless machine sca
- Defender CSPM extends secret discovery beyond running machines
Use cloud-deployment resource scanning to find secrets in multicloud infrastructure-as-code deployment resources and code-repository scanning for connected DevOps repositories. These scanning surfaces complement, rather than duplicate, Key Vault's storage protections.
Trap Enable Defender for Key Vault and expect it to inspect plaintext credentials committed to a repository.
4 questions test this
- Your company has an Azure subscription and an AWS account that are both connected to Microsoft Defender for Cloud, and the Defender Cloud Security Posture Management (CSPM) plan is enabled on both env
- You have an Azure subscription named Sub1 that contains 30 virtual machines and has the Microsoft Defender for Servers Plan 2 plan enabled, and secrets findings are already reported for the virtual ma
- Your company connects an Azure DevOps organization to Microsoft Defender for Cloud by using a connector that is deployed to a resource group named RG-Sec in a subscription named Sub1. An internal audi
- Your company stores all of its application code in an Azure DevOps organization named Contoso1 that is connected to Microsoft Defender for Cloud, and the Defender Cloud Security Posture Management (CS
- Secrets findings feed recommendations, inventory, graph queries, and attack paths
Review discovered secrets through affected-resource inventory and Defender for Cloud recommendations, then use cloud security explorer or attack-path analysis to understand reachable assets and lateral-movement risk. Merely moving a detected credential into Key Vault is insufficient if the exposed value remains valid elsewhere.
Trap Dismiss the finding after deleting the plaintext file without rotating the exposed credential.
6 questions test this
- You have an Azure subscription named Sub1 that contains a key vault named KV1. Microsoft Defender for Key Vault raised an alert for KV1, and your review of the alert confirms that an unauthorized call
- You have an Azure subscription named Sub1 that contains a key vault named KV1. Microsoft Defender for Key Vault raised an alert for KV1, and your review of the alert confirms that an unauthorized call
- A machine secrets finding in Microsoft Defender for Cloud reports that a virtual machine named VM1 keeps a plaintext Azure Cosmos DB connection string that carries the primary key of an account named
- You have an Azure subscription named Sub1 that has the Defender Cloud Security Posture Management (CSPM) plan enabled and Agentless scanning for machines turned on. The Defender for Cloud asset invent
- You have an Azure subscription named Sub1 that has the Defender Cloud Security Posture Management (CSPM) plan enabled and Agentless scanning for machines turned on. The Machines should have secrets fi
- You have an Azure subscription named Sub1 that has the Defender Cloud Security Posture Management (CSPM) plan enabled. Agentless secrets scanning discovers a plaintext Azure App Service deployment pas
- Defender for Key Vault alerts on suspicious data-plane behavior
Enable Microsoft Defender for Key Vault to detect unusual or potentially harmful attempts to access vaults and produce contextual security alerts. It adds threat detection, not network prevention, so firewall restrictions, least-privilege authorization, and diagnostic logging remain separate controls.
Trap Use Defender for Key Vault instead of configuring the vault firewall because alerts block suspicious requests automatically.
7 questions test this
- You have an Azure subscription named Sub1 that contains a key vault named KV1. Microsoft Defender for Key Vault is enabled on Sub1 and raises a Suspicious secret listing and query in a key vault alert
- You have an Azure subscription named Sub1 that contains a key vault named KV1. Microsoft Defender for Key Vault raised an alert for KV1, and your review of the alert confirms that an unauthorized call
- You have an Azure subscription named Sub1 that contains a key vault named KV1. Microsoft Defender for Key Vault is enabled on Sub1 and raises a Suspicious secret listing and query in a key vault alert
- You have an Azure subscription named Sub1 that contains a key vault named KV1. Microsoft Defender for Key Vault raised an alert for KV1, and your review of the alert confirms that an unauthorized call
- Your security operations team monitors an Azure subscription named Sub1 in which Microsoft Defender for Key Vault protects eight key vaults. The team has just configured a continuous export rule that
- You have an Azure subscription named Sub1 that contains a key vault named KV1 that uses Azure role-based access control (RBAC) authorization. Microsoft Defender for Key Vault raises an Unusual applica
- You have an Azure subscription named Sub1 that contains a key vault named KV1 that stores production credentials for several applications. Microsoft Defender for Key Vault is enabled on Sub1. During a
- Use the appropriate Key Vault channel for audit, security, and lifecycle signals
Enable Key Vault audit logging to record vault operations and configure log alerts for security-relevant events such as access failures or secret deletions. Use Event Grid subscriptions for change notifications about keys, secrets, and certificates; lifecycle events do not replace operation audit logs or security alerts.
2 questions test this
- You have an Azure subscription named Sub1 that contains a key vault named KV1. Your security operations team runs a third-party SIEM platform outside Azure that already consumes data from an Azure Eve
- You have an Azure subscription named Sub1 that contains 14 key vaults and a Log Analytics workspace named Workspace1. None of the vaults currently records the operations that callers perform on its ke
Implement governance to enforce security and regulatory compliance
Read full chapterCheat sheet
Sharp facts the exam loves — scan these before test day.
- Use built-in policy definitions unless the required rule needs a custom definition
A policy definition contains the condition and effect applied to matching resources; Microsoft supplies built-ins for common controls, while custom definitions implement organization-specific requirements. Group related definitions into an initiative when they should be assigned and tracked together.
Trap Create separate role assignments for every resource instead of defining a repeatable configuration rule.
4 questions test this
- Your company has an Azure subscription named Sub1. A new internal standard requires that the name of every Azure Storage account created in Sub1 begin with the string sec, and that a request submittin
- You have a custom policy definition named AllowedRegions that restricts the Azure regions in which resources can be created. Three business units each use a separate Azure subscription, and each unit
- Your company has a management group named MG-AI that contains four Azure subscriptions. Your security baseline for AI workloads consists of 12 policy definitions: nine Microsoft built-ins and three cu
- You have an Azure subscription named Sub1 that contains several Azure Storage accounts. A new control states that a storage account in Sub1 must never be created or updated with public blob access ena
- Policy assignment scope determines which descendants are evaluated
Assign a policy at the management group or subscription that is the common ancestor of all intended resources, and use notScopes to exclude a resource group that must remain outside applicability. Assigning at one subscription cannot cover sibling subscriptions in the management group.
Trap Assign the definition to one subscription and expect it to govern every subscription under the same management group.
5 questions test this
- Your tenant root group contains a management group named MG-Landing and two subscriptions that are direct children of the root group. MG-Landing contains two child management groups named MG-Corp and
- A policy initiative that audits storage account network configuration is assigned to a management group named MG1, which contains a subscription named Sub2. One storage account in Sub2 must keep publi
- An initiative that contains a deployIfNotExists definition is assigned to a management group named MG1 with a system-assigned managed identity, and MG1 contains four subscriptions. Compliance results
- A management group named MG-Corp contains five production subscriptions and a new sandbox subscription named Sub6. The built-in Allowed resource types definition is assigned to MG-Corp with the deny e
- Your Azure environment contains a management group named MG-Prod that contains three subscriptions named Sub1, Sub2, and Sub3. A policy definition that requires private endpoints on Microsoft Foundry
- Azure Policy effects distinguish prevention from assessment and correction
Use deny to reject noncompliant create or update requests, audit to record noncompliance without blocking, and modify or deployIfNotExists when Azure should alter or deploy a related configuration. A policy's effect, not merely its assignment, determines whether a new deployment is prevented.
Trap Choose Audit when a prohibited public endpoint must be blocked at deployment time.
2 questions test this
- Your Azure environment contains a management group named MG-Sec that contains four Azure subscriptions. The subscriptions hold the Azure key vaults that store the customer-managed keys for production
- Your Azure environment contains a management group named MG1 whose subscriptions host the resources of 30 application teams. A policy definition that requires the DataClassification tag to hold one of
- Resource locks override role permissions for control-plane changes
A CanNotDelete lock allows authorized modifications but blocks deletion, whereas ReadOnly also blocks updates; parent-scope locks are inherited and the most restrictive lock wins. Locks affect Azure control-plane operations, not service data-plane writes or deletes.
Trap Apply a ReadOnly lock to a storage account to prevent deletion of blobs through the data-plane endpoint.
4 questions test this
- Your Azure environment contains a management group named MG-Sec that contains four Azure subscriptions. The subscriptions hold the Azure key vaults that store the customer-managed keys for production
- You have an Azure subscription named Sub1 that contains a resource group named RG-IR. RG-IR holds the disks of a quarantined virtual machine and an Azure key vault named KV-Forensics. Until an investi
- You have an Azure subscription named Sub1 that contains a resource group named RG-Test. A service principal named SP1 runs a nightly pipeline that deletes and recreates the test resources in RG-Test.
- You have an Azure subscription named Sub1 that contains a resource group named RG-Prod. RG-Prod holds an Azure key vault, two storage accounts, and a Log Analytics workspace, and the platform team add
- Use policy exclusions for permanent bypasses and exemptions for tracked exceptions
Use an assignment's notScopes for a permanent, broad bypass such as an environment that does not require the governance rule. Use a policy exemption for a waiver or mitigation that must remain visible as Exempted in compliance reporting and can expire through expiresOn without modifying the assignment.
4 questions test this
- Your Azure environment contains a management group named MG-Prod. A policy assignment on MG-Prod uses the deny effect to block the creation of virtual machines that use unapproved sizes. During a majo
- You have an Azure subscription named Sub1 that contains a storage account named storage1 that holds legal-hold evidence. storage1 must keep public network access enabled until the case closes at the e
- Your company has a management group named MG-Corp that contains four production subscriptions and a subscription named Sub-Dev that hosts short-lived developer sandboxes. A policy initiative that enfo
- Your company has a management group named MG-AI that contains three Azure subscriptions. An initiative that contains nine policy definitions is assigned to MG-AI to enforce your AI workload baseline.
- Authorize the policy assignment identity before remediating existing resources
A modify or deployIfNotExists assignment needs a system-assigned or user-assigned managed identity with the minimum Azure roles required by the policy's roleDefinitionIds. After assignment, create a remediation task to apply the modify operations or deployment template to existing noncompliant resources; assignment alone corrects resources only when the effect is triggered during applicable create or update activity.
5 questions test this
- You have an Azure subscription named Sub1. An initiative that contains three deployIfNotExists definitions is assigned to Sub1 with a system-assigned managed identity that already holds every role the
- You have an Azure subscription named Sub1 that contains 60 Azure key vaults. An initiative assigned to Sub1 includes a definition that checks whether each key vault sends its logs to a Log Analytics w
- You have an Azure subscription named Sub1. A deployIfNotExists assignment on Sub1 deploys a diagnostic setting to every new Azure key vault, and its system-assigned managed identity holds the roles th
- Your company creates every Azure Policy assignment from an Azure DevOps pipeline that calls the Azure CLI, and never from the Azure portal. An initiative that contains deployIfNotExists definitions is
- You have an Azure subscription named Sub1 that contains 200 virtual machines. To preview the impact of a new baseline, you assigned a deployIfNotExists definition to Sub1 with the enforcement mode set
- Save a custom policy definition above every intended assignment scope
Save a custom policy definition at a subscription or management group that is an ancestor of every intended assignment target, because the definition can target only resources within its location's hierarchy. Use a shared management group as the definition location when assignments must span multiple descendant subscriptions.
- Supply business-specific policy parameter values at assignment time
Define variable compliance values as parameters in a policy or initiative definition, then provide the required values in each assignment. This keeps the rule logic reusable while allowing different assignment scopes to enforce different business values or outcomes.
- Defender for Cloud evaluates regulatory standards through policy initiatives
Regulatory compliance standards in Defender for Cloud are backed by Azure Policy initiatives and are continuously assessed at their assigned scopes. The dashboard reports compliant and noncompliant resources by standard and links failed assessments to remediation guidance.
Trap Treat a displayed compliance score as an external certification issued by Microsoft.
8 questions test this
- You have an Azure subscription named Sub1 that Microsoft Defender for Cloud assesses against two regulatory standards. A compliance officer must be emailed within minutes whenever any regulatory compl
- Your company has workloads in an Azure subscription named Sub1, in an Amazon Web Services (AWS) account, and in a Google Cloud Platform (GCP) project, and all three are onboarded to Microsoft Defender
- You have an Azure subscription named Sub1 that Microsoft Defender for Cloud assesses against three regulatory standards. Your company's third-party governance platform must consume a weekly point-in-t
- You have an Azure subscription named Sub1 where Microsoft Defender for Cloud is enabled but no Defender plan is turned on, so the Regulatory compliance dashboard shows only the Microsoft Cloud Securit
- Your company has an Azure subscription named Sub1 that Microsoft Defender for Cloud assesses against two regulatory standards. The risk committee wants a view in the Azure portal showing how Sub1's co
- Your company has a management group named MG1 that contains 12 Azure subscriptions, and two more subscriptions are moved into MG1 each quarter. Every subscription has a paid Microsoft Defender for Clo
- You have an Azure subscription that Microsoft Defender for Cloud assesses against a regulatory standard, and the Regulatory compliance dashboard currently reports that most of the standard's controls
- You have an Azure subscription named Sub1 that contains 30 virtual machines. Microsoft Defender for Cloud assesses Sub1 against the Microsoft Cloud Security Benchmark, and one recommendation reports 8
- Assign each security standard at the highest applicable governance scope
Enable a standard on the relevant management group or subscription so nested resources are aggregated and assessed consistently, supplying any required initiative parameters. Owner or Policy Contributor permission is required to add a standard.
Trap Enable the standard independently on every resource group to obtain management-group aggregation.
5 questions test this
- Your company has a management group named MG1 that contains 12 Azure subscriptions. The PCI DSS v4.0.1 standard is turned on for MG1, and the Regulatory compliance page aggregates the control results
- Your company has a management group named MG-Corp with two child management groups: MG-Prod, which contains eight Azure subscriptions, and MG-Divest, which contains three subscriptions that belong to
- Your Microsoft Entra tenant contains a management group named MG-Prod that holds 15 Azure subscriptions, and the NIST CSF v2.0 standard is turned on for MG-Prod. Application teams create new Azure sub
- Your company manages its Amazon Web Services (AWS) estate with AWS Organizations: one management account and 45 member accounts, with two or three member accounts added every quarter. The AWS security
- You have a Microsoft Entra tenant with a management group named MG1 that contains nine Azure subscriptions, and three further subscriptions sit outside MG1. Over the past year several engineers turned
- Microsoft Cloud Security Benchmark supplies the default Defender posture baseline
When cloud accounts are onboarded, Defender for Cloud enables the Microsoft Cloud Security Benchmark and assesses resources against its controls. Add regulatory or custom standards when the organization needs mappings beyond that default security baseline.
6 questions test this
- Your company has an Azure subscription named Sub1 that contains Microsoft Foundry resources used by a customer-facing AI assistant. Microsoft Defender for Cloud is enabled on Sub1 with the Defender Cl
- Your company has a management group named MG1 that contains an Azure subscription named Sub1. Microsoft Defender for Cloud assesses Sub1 against the Microsoft Cloud Security Benchmark, and your compli
- Your company has an Azure subscription named Sub1 and an Amazon Web Services account named AWS1. A colleague created a security connector for AWS1 in Microsoft Defender for Cloud and enabled the Defen
- You have an Azure subscription named Sub2 that is onboarded to Microsoft Defender for Cloud with the Defender Cloud Security Posture Management (CSPM) plan. Last month you turned the SWIFT Customer Se
- You have an Azure subscription named Sub1 that is onboarded to Microsoft Defender for Cloud. A Microsoft Cloud Security Benchmark recommendation repeatedly reports storage accounts in Sub1 that allow
- Your company has an Azure subscription named Sub1 that is onboarded to Microsoft Defender for Cloud with the Defender Cloud Security Posture Management (CSPM) plan. The compliance team recently turned
- Defender recommendations prioritize remediation using resource context
Security recommendations provide actionable fixes from continuous assessments and rank risk using factors such as internet exposure, sensitive data, lateral movement, and attack paths. Review affected resources and business impact before remediating or granting an exemption; severity alone is not the full contextual risk score.
7 questions test this
- You have a Microsoft Entra tenant that contains three Azure subscriptions named Sub1, Sub2, and Sub3, all onboarded to Microsoft Defender for Cloud with the Defender Cloud Security Posture Management
- You have a Microsoft Entra tenant that contains three Azure subscriptions named Sub1, Sub2, and Sub3, all onboarded to Microsoft Defender for Cloud with the Defender Cloud Security Posture Management
- You have an Azure subscription named Sub1 and a management group named MG1 that are onboarded to Microsoft Defender for Cloud. An internal auditor asks for one list of every exemption rule that is cur
- You have an Azure subscription named Sub1 that is onboarded to Microsoft Defender for Cloud. A recommendation for Sub1 reports 40 unhealthy production resources and offers a Fix option that can remedi
- You have an Azure subscription named Sub1 that is onboarded to Microsoft Defender for Cloud with the Defender Cloud Security Posture Management (CSPM) plan. The Recommendations page lists more than 60
- Your company has a management group named MG-Lab that contains six Azure subscriptions used only for an isolated training lab. Microsoft Defender for Cloud reports one Microsoft Cloud Security Benchma
- Your company has an Azure subscription named Sub1 and an Amazon Web Services account named AWS1 that are onboarded to Microsoft Defender for Cloud. Overnight, the secure score of the environment dropp
- An Azure role assignment binds a principal, role definition, and scope
Select the narrowest built-in role that contains the required actions, assign it to the user, group, service principal, or managed identity, and scope it no higher than necessary. Assignments at management group, subscription, and resource-group levels flow to descendant Azure resources.
Trap Grant Owner at the subscription because the task spans two resources in one resource group.
6 questions test this
- Your company has an Azure subscription named Sub1 that contains a Microsoft Foundry resource named Foundry1. A Foundry project named Project1 hosts four published agents, and a partner web application
- Your Azure environment contains a management group named MG-Sec that currently holds two subscriptions, and finance plans to add three more subscriptions to MG-Sec next quarter. A Microsoft Entra grou
- Your Azure environment contains a management group named MG-Gov that holds two subscriptions named Sub1 and Sub2. Sub1 contains two resource groups named RG-AI and RG-Data. A workload identity named S
- You have an Azure subscription named Sub1 that contains a resource group named RG-Images with a container registry named acr1. To cover a combination of operations that no built-in role provides, you
- You have an Azure subscription named Sub1 that contains a resource group named RG1. RG1 contains three key vaults named KV1, KV2, and KV3, and an Azure Functions app named Func1 that has a system-assi
- You have an Azure subscription named Sub1 that contains a resource group named RG-AI. A team lead named User1 must be able to add and remove Azure role assignments for the developers who work on the r
- Create an Azure custom role only when built-in roles cannot express the required permissions
Define control-plane permissions in Actions and data-plane permissions in DataActions, then constrain where the role can be assigned with AssignableScopes. NotActions and NotDataActions subtract from wildcard grants in that role definition; they are not explicit deny rules against permissions obtained from another assignment.
Trap Add an operation to NotActions and expect it to override the same operation granted by another role.
5 questions test this
- Your Microsoft Entra tenant contains two Azure subscriptions named Sub1 and Sub2 that belong to different management groups. An Azure custom role named AI Guardrail Operator was created with Sub1 as t
- Your Microsoft Entra tenant contains two Azure subscriptions named Sub1 and Sub2 that belong to different management groups. An Azure custom role named AI Guardrail Operator was created with Sub1 as t
- Your Azure environment contains a management group named MG-Data that holds four subscriptions. A monitoring team needs a set of storage permissions that no built-in role expresses, so you create an A
- You have an Azure subscription named Sub1 that contains a resource group named RG-Images with a container registry named acr1. To cover a combination of operations that no built-in role provides, you
- Your company has a Microsoft Entra tenant that includes Microsoft Entra ID P1 licenses, and an Azure subscription named Sub1. A developer named User1 must be able to manage the credentials and the red
- Microsoft Entra custom roles and Azure custom roles govern different resource planes
Use a Microsoft Entra custom role for supported directory permissions and object scopes, and an Azure custom role for Azure Resource Manager and service data actions. A custom directory role does not become assignable at an Azure subscription or resource group.
Trap Create a Microsoft Entra custom role containing Storage blob DataActions.
5 questions test this
- You have an Azure subscription named Sub1 that contains a Microsoft Foundry resource named Foundry1 with a project named Project1. A workload identity named SP-Ops runs a release pipeline that must pu
- Your company has a Microsoft Entra tenant and an Azure subscription named Sub1 that contains a resource group named RG-AI. A platform team must be able to restart the container apps in RG-AI and read
- Your company has a Microsoft Entra tenant that includes Microsoft Entra ID P1 licenses, an app registration named App1, and a group named Agent-Devs whose members build AI agents. You create a Microso
- You have an Azure subscription named Sub1 that contains a Microsoft Foundry agent and an Azure AI Search service named Search1. The agent grounds its answers on a single index in Search1 and currently
- Your Microsoft Entra tenant contains an app registration named App1 and a workload identity named SP-Rotate that a nightly job uses to replace the expiring client secrets of App1. You create a Microso
- Identity recommendations should drive removal of unnecessary administrative access
Use Defender for Cloud identity and access recommendations to identify risky patterns such as service principals holding administrative roles at subscription or resource-group scope. Validate the workload's required operations, replace the assignment with the least-privileged role and scope, and remove unused privileged grants.
Trap Leave the administrative assignment in place and add Reader because the combined roles include least privilege.
5 questions test this
- You have an Azure subscription named Sub1 that is onboarded to Microsoft Defender for Cloud with the Defender CSPM plan enabled. The identity and access recommendations flag a service principal named
- Your company has three Azure subscriptions in a management group named MG-Prod, all onboarded to Microsoft Defender for Cloud with the Defender CSPM plan enabled. The identity and access recommendatio
- You have an Azure subscription named Sub1 that contains a Microsoft Foundry resource named Foundry1. Microsoft Defender for Cloud raises the recommendation that service principals should not be assign
- Your Azure subscription named Sub1 contains three service principals named SP1, SP2, and SP3 that each hold the Contributor role at the Sub1 scope, and the Microsoft Defender for Cloud identity and ac
- You have an Azure subscription named Sub1 that contains a resource group named RG-Sec, and your tenant has Microsoft Entra ID P2 licenses. Four security engineers hold the User Access Administrator ro
- Elevate a Global Administrator only temporarily for Azure access recovery
Microsoft Entra Global Administrator does not itself grant access to Azure resources because directory roles and Azure RBAC are separate authorization systems. For emergency recovery, enabling Azure resource access assigns that administrator User Access Administrator at root scope (/); remove the root assignment or turn the setting off as soon as the required role assignments are repaired.
5 questions test this
- Your company has a Microsoft Entra tenant that uses Microsoft Entra ID P2 licenses and an Azure subscription named Sub1. A security engineer named Admin1 holds an eligible Global Administrator assignm
- Your company has a Microsoft Entra tenant that contains 12 Azure subscriptions. A compliance investigation requires you to establish which administrator account elevated its access to the root scope (
- Your company has a Microsoft Entra tenant that contains 25 Azure subscriptions. Project teams created most of the subscriptions, and no administrator currently has access to all of them. A third-party
- Your company has a Microsoft Entra tenant that contains 30 Azure subscriptions and a Microsoft Sentinel workspace named Workspace1. During an incident review, you discover that a Global Administrator
- You are the security engineer for a Microsoft Entra tenant that contains 40 Azure subscriptions organized in several management groups. During a quarterly privileged access review, you must produce a
- Azure Backup roles separate backup operations from broad resource ownership
Use Azure Backup built-in roles and narrow vault scopes to grant only the backup management operations each operator needs. Subscription Owner is unnecessary for routine backup or restore duties and expands the impact of compromised credentials.
Trap Assign Owner on the subscription to every backup operator so all vault actions succeed.
6 questions test this
- You have an Azure subscription that contains a Backup vault named Vault2, which protects the managed disks of several virtual machines, and an empty resource group named RG-Restore that serves as the
- Your company has an Azure subscription named Sub1 that contains three Recovery Services vaults named VaultA, VaultB, and VaultC. Each vault protects the workloads of a different application team, and
- You have an Azure subscription that contains a Recovery Services vault named Vault1. A senior engineer named Admin1 must create new backup policies for Vault1, change the retention settings of existin
- Your company has an Azure subscription named Sub1 that contains a Recovery Services vault named Vault1, which protects 40 Azure virtual machines. A new operations team must be able to trigger on-deman
- You have an Azure subscription that contains a Recovery Services vault named Vault1, which protects 60 production virtual machines. The backup administrators hold the Backup Contributor role on Vault1
- You have an Azure subscription that contains a Backup vault named Vault3 and a storage account named storage1 that hosts blob containers of regulated data. An engineer named Eng1 holds the Backup Oper
- Multi-user authorization protects critical backup operations with Resource Guard
Enable multi-user authorization on a Recovery Services vault or Backup vault so protected operations also require applicable authorization on a separate Resource Guard. A backup administrator who lacks sufficient permissions on that guard cannot perform those critical actions despite vault permissions.
Trap Use a CanNotDelete lock on the backup vault as a substitute for independent approval of security-setting changes.
5 questions test this
- You have a Recovery Services vault named Vault1 that is protected by multi-user authorization through a Resource Guard named Guard1 in a separate Microsoft Entra tenant. A backup administrator must st
- Your company has an Azure subscription that contains a Recovery Services vault named Vault1 in the East US region. A security administrator created a Resource Guard named Guard1 in the West Europe reg
- Your company uses two Microsoft Entra tenants: a production tenant that contains a Recovery Services vault named Vault1, and a security tenant in which a security administrator created a Resource Guar
- You have an Azure subscription that contains a Recovery Services vault named Vault1, which protects 60 production virtual machines. The backup administrators hold the Backup Contributor role on Vault1
- Your company has a Resource Guard named Guard1 that provides multi-user authorization for six Backup vaults: five production vaults and a vault named Vault-Dev that a development team uses for short-l
- Always-on enhanced soft delete prevents attackers from disabling recovery retention
Use secure-by-default soft delete when deleted backup data must remain recoverable for the retention period even after an account compromise. All newly created vaults have soft delete permanently enabled, and it cannot be disabled in regions where secure-by-default assurance is in preview or general availability.
Trap Assume soft delete can still be disabled before deleting backup data in a secure-by-default region.
5 questions test this
- You have an Azure subscription that contains a Backup vault named Vault2 and a storage account named storage1 that stores regulated block blob data. Operational backup of blobs is configured for stora
- You have an Azure subscription named Sub1 that contains a Recovery Services vault named Vault1. An attacker who obtained the Backup Contributor role on Vault1 deleted the backup data of a protected vi
- Your company has an Azure subscription that contains a Recovery Services vault named Vault1. Vault1 protects files and folders on 15 on-premises servers that run the Microsoft Azure Recovery Services
- You have an Azure subscription named Sub1 that contains a Recovery Services vault named Vault1 in a resource group named RG-Legacy. Vault1 protects five virtual machines for a project that has ended,
- You have an Azure subscription that contains a Recovery Services vault named Vault1. A junior engineer selected Stop backup and then Delete backup data for a virtual machine named VM1, and the Backup
- Locked vault immutability prevents protected recovery points from being changed
Enable vault immutability to block operations that could shorten retention or delete protected backup data, and lock the setting when the protection must be irreversible. Pair immutable or always-on soft-delete protection with MUA for Azure Backup's maximum security posture.
Trap Rely on encryption at rest to prevent a privileged operator from deleting recovery points.
2 questions test this
- Your company has an Azure subscription that contains a Recovery Services vault named Vault1. Vault immutability is enabled and locked on Vault1. Three months ago, backups of a virtual machine named VM
- Your company has an Azure subscription that contains a Recovery Services vault named Vault1, and immutability is enabled and locked on Vault1. An application named App1 has been retired and its two vi
- Choose Azure Backup encryption keys according to required key control
Azure Backup encrypts backup data at rest with platform-managed keys by default and requires no enablement action for that baseline. Configure customer-managed keys stored in Azure Key Vault when the organization must control the encryption key for workloads backed up to a Recovery Services vault.
4 questions test this
- You have an Azure subscription that contains a Backup vault named Vault2 whose encryption settings use a customer-managed key stored in a key vault named KV1. During a cleanup of KV1, an administrator
- You have an Azure subscription that contains a newly created Recovery Services vault named Vault1 in the East US region and a key vault named KV1 in the same region. KV1 stores an enabled RSA key name
- You have an Azure subscription that contains a Backup vault named Vault2 and a key vault named KV1 that uses the Azure role-based access control permission model. KV1 stores an enabled RSA key, and so
- Your company has an Azure subscription that contains a key vault named KV1, which stores an enabled RSA key and has soft delete and purge protection turned on. A new internal standard requires that ba
- Use Azure Backup private endpoints only for supported protected workloads
Use a Recovery Services vault private endpoint when supported servers in a virtual network must back up and restore without exposing that virtual network to public IP addresses. Supported scenarios include SQL and SAP HANA databases in Azure VMs and on-premises servers using the MARS agent; do not assume every Azure Backup workload uses this private-endpoint path.
- Monitor Azure Backup operations for suspicious recovery activity
Configure Azure Backup's built-in monitoring and alerts for backup events, and use Backup Reports to audit backup and restore activity, track usage, and identify trends. These monitoring and reporting channels help surface unauthorized, suspicious, or malicious administrative and recovery activity.
- Policy as Code makes definitions and assignments reviewable and repeatable
Store custom policy and initiative definitions, assignments, parameters, and exemptions in source control and deploy them through a controlled pipeline. This approach provides change history and consistent promotion across environments instead of one-off portal edits.
Trap Export only a compliance report after manually recreating each policy assignment in production.
6 questions test this
- You have a management group named MG1 that contains a subscription named Sub-Dev, which exists only to validate governance changes. A pipeline deploys an updated version of a custom policy definition
- Your Azure Policy repository contains a policies folder with three new custom policy definitions and an initiatives folder with a new initiative that references all three by policyDefinitionReferenceI
- Your company keeps its Bicep templates in an Azure Repos Git repository that is connected to Microsoft Defender for Cloud through a DevOps security connector. The Microsoft Security DevOps extension a
- Your company deploys all Azure Policy definitions, initiatives, assignments, and exemptions to a management group named MG1 from an Azure Repos Git repository through an Azure Pipelines service connec
- Your governance repository holds the JSON for a custom initiative named Init1 and for its assignment at a management group named MG1, and Azure Pipelines deploys every change. A legacy resource group
- Your Azure Policy repository contains a custom definition that uses the deployIfNotExists effect and an assignment file that requests a system-assigned managed identity. An Azure Pipelines job deploys
- Policy changes should be validated at a limited scope before enforcement expands
Deploy a changed definition to a test assignment, use enforcement mode disabled where appropriate to evaluate impact, and inspect compliance results before promoting it to broad production scope. Versioned rollout avoids turning an untested deny rule into an organization-wide deployment outage.
Trap Assign a new custom deny definition directly at the tenant root management group.
9 questions test this
- You manage 60 Azure Arc-enabled servers in a subscription named Sub1. A Bicep deployment in your release pipeline assigns a custom machine configuration definition that uses the deployIfNotExists effe
- Your Azure tenant has a tenant root management group with two child management groups named MG-Corp and MG-Sandbox. MG-Sandbox contains only a subscription named Sub-Val that exists to trial governanc
- Your team stores Azure Policy definitions and assignments in a GitHub repository and deploys them with GitHub Actions. A trial assignment already evaluates a new definition in a subscription named Sub
- Your governance repository contains a custom policy definition that uses the deny effect. A trial assignment of it exists in a subscription named Sub-Val, which contains a storage account named stg1 t
- Your governance repository holds a custom policy definition that uses the deployIfNotExists effect to add a diagnostic setting to storage accounts, and a pipeline has assigned it to a resource group n
- Your company assigns a built-in Azure Policy initiative at a management group named MG-All from a Git repository through Azure Pipelines, and the assignment pins the definition version it evaluates. M
- Your company has an Azure subscription named Sub1 that contains an Azure Kubernetes Service cluster named cluster1 with the Azure Policy add-on installed. A GitHub Actions workflow deploys governance
- A built-in policy definition that uses the deployIfNotExists effect is assigned at a management group named MG-All to deploy a required diagnostic setting, and the assignment's managed identity alread
- Your company deploys every Azure Policy artifact from a GitHub repository, and write permissions to policy resources are held only by the workflow's deployment identity. A commit changed a custom defi
- IaC scanning finds security misconfigurations before resources reach production
Run Microsoft Security DevOps in GitHub Actions or Azure Pipelines with the IaC category to analyze supported ARM, Bicep, Terraform, Kubernetes, and related templates. Resolve the resulting infrastructure-as-code findings in the repository rather than waiting only for postdeployment assessment.
Trap Enable runtime threat alerts and omit template scanning because both controls inspect deployed resources.
7 questions test this
- Your company stores the Bicep and Terraform templates for its Azure landing zone in a GitHub Enterprise Cloud repository named Repo1. The GitHub organization is already connected to Microsoft Defender
- Your Azure DevOps pipeline runs the Microsoft Security DevOps task for the IaC category against a repository that contains ARM templates, Bicep files, Terraform configurations, and Kubernetes manifest
- Your company's GitHub Enterprise Cloud organization contains 40 repositories that store the ARM and Bicep templates for its Azure workloads. A workflow in each repository already runs the Microsoft Se
- Your company keeps the infrastructure as code templates for several projects in GitLab SaaS. A security engineer connected the GitLab group to Microsoft Defender for Cloud, and the Defender CSPM plan
- Your company has an Azure DevOps organization named Org1 that contains 300 repositories holding ARM, Bicep, and Terraform templates. Org1 is connected to Microsoft Defender for Cloud, and each reposit
- You have an Azure DevOps organization connected to Microsoft Defender for Cloud. The Defender CSPM plan is enabled, the Microsoft Security DevOps extension scans the ARM templates in every pipeline, a
- You have an Azure DevOps project named Project1 whose repository stores the Bicep templates that deploy a production subscription. The organization is connected to Microsoft Defender for Cloud, the Mi
- Security-relevant resource properties belong in the declarative deployment
Express controls such as managed identities, private access, diagnostic settings, purge protection, and role or policy assignments in the ARM, Bicep, or Terraform deployment so repeated environments converge on the intended posture. Keep plaintext secrets out of templates and parameter files; use secure parameters with Key Vault references or a credential-free deployment identity.
Trap Pass production passwords as plain-text Terraform variables so the same template can configure every environment.
6 questions test this
- Your team deploys a Bicep file from Azure Pipelines to a resource group named RG1. The file accepts a third-party API key as a string parameter, and the pipeline supplies the value at deployment time.
- A Bicep file deploys a key vault for each of your production workloads, and those vaults hold the keys that encrypt customer data. During a tabletop exercise you find that a highly privileged operator
- Your release pipeline deploys the same Bicep file to a production resource group every week to create and update a key vault named KV1. A private endpoint for KV1 already exists, and a security engine
- You have a Bicep file that deploys a function app and a key vault named KV1 to each of your environments. KV1 uses the Azure role-based access control permission model, and the function app has a user
- Your company has an Azure DevOps organization named Org1 that contains a project named Project1. A release pipeline in Project1 deploys Bicep files to a subscription named Sub1 through an Azure Resour
- Your platform team deploys Azure resources with Terraform from a pipeline. The administrator password for a database is committed to the repository as a plain-text value in a variables file so that th
Secure storage, databases, and networking
Implement security for storage accounts
Read full chapterCheat sheet
Sharp facts the exam loves — scan these before test day.
- Secure transfer rejects unencrypted storage requests
Enabling Secure transfer required makes Azure Storage REST operations require HTTPS and rejects HTTP requests. The setting is enabled by default for newly created storage accounts.
Trap Setting the minimum TLS version alone, which controls protocol version but does not replace the secure-transfer requirement.
9 questions test this
- You have an Azure subscription that contains a storage account named storage2 in a resource group named RG1. After you enable Secure transfer required on storage2, an internal reporting tool that read
- You have a management group named MG1 that contains three Azure subscriptions holding 60 storage accounts. A compliance scan reports that 14 of those accounts have Secure transfer required disabled. Y
- Your company has an Azure subscription that contains 30 storage accounts inherited through an acquisition. Before you tighten transport security on them, you must establish which client applications a
- You have an Azure subscription that contains a storage account named storage5 hosting an NFS Azure file share named share5, and Require encryption in transit for NFS is enabled on storage5. Linux virt
- You have a management group named MG1 that contains two Azure subscriptions named Sub1 and Sub2, and more subscriptions will be added to MG1 next quarter. A resource group named RG-Legacy in Sub1 hold
- You have a management group named MG1 that contains three Azure subscriptions in which application teams create their own storage accounts. Company policy states that no storage account under MG1 may
- You have an Azure subscription that contains a storage account named storage3 on which Secure transfer required is already enabled. Blob request logs show that a partner application still reaches stor
- Your company provisions storage accounts with an Azure CLI pipeline. One of them, storage4, hosts SMB Azure file shares for a finance application, and its Require encryption in transit for SMB setting
- You have an Azure subscription that contains a storage account named storage6, which currently accepts both HTTP and HTTPS requests because several internal applications have not been migrated yet. Yo
- Azure Storage can enforce TLS 1.2 but not TLS 1.3 as its minimum
Azure Storage supports TLS 1.2 and TLS 1.3, but a storage account can currently enforce only TLS 1.2 as the recommended minimum. Compatible clients can still negotiate TLS 1.3 automatically.
Trap Configuring TLS 1.3 as the account minimum because the service supports TLS 1.3 negotiation.
5 questions test this
- Your company deploys storage accounts from an Azure Pipelines release that uses an Azure Resource Manager template. An audit finds that the accounts created by the pipeline return no value for their m
- You have an Azure subscription that contains a storage account named storage16 in a resource group named RG1. The account receives HTTPS writes from an Azure service in the same subscription and from
- You have an Azure subscription that contains a storage account named storage13. You set the minimum TLS version of storage13 to TLS 1.2, and the account's Configuration page confirms the value. An ext
- You have an Azure subscription that contains a storage account named storage14. The blob containers in storage14 are used by a web application, and a table in the same account is read by an on-premise
- Your company has an Azure subscription that contains a storage account named storage11. After you set the minimum TLS version of storage11 to TLS 1.2, an internal reporting application that runs on a
- Customer-managed storage keys change key control, not the encryption-at-rest baseline
Azure Storage encrypts persisted data at rest by default with Microsoft-managed keys. Configure a customer-managed key in Azure Key Vault or Managed HSM when the organization must control rotation and revocation of the account or encryption-scope key.
Trap Enabling Secure transfer required, which protects requests in transit rather than changing ownership of the at-rest encryption key.
9 questions test this
- You have an Azure subscription that contains a general-purpose v2 storage account named storage10 that was created last year and whose data at rest is protected by a customer-managed key in a key vaul
- You have an Azure subscription in which a deployment pipeline creates storage accounts from an Azure Resource Manager template. A new standard requires that every account be protected by a customer-ma
- You have an Azure subscription that contains a storage account named storage5 whose data at rest is protected by a customer-managed key in a key vault named KV5. A security incident requires that ever
- Your company is a software vendor that hosts a service in an Azure subscription in your own Microsoft Entra tenant. Every customer requires that the storage accounts holding their data be protected by
- You have an Azure subscription that contains a storage account named storage3 whose data at rest is protected by a customer-managed key in a key vault named KV3. A key rotation policy on that key crea
- You have an Azure subscription that contains a storage account named storage6 that is protected by Microsoft-managed keys and holds data for several internal teams. You must create a container named l
- You have an Azure subscription that contains a storage account named storage1 and a key vault named KV1 that was created with default settings and uses the Azure role-based access control permission m
- You have an Azure subscription that contains a general-purpose v2 storage account named storage4 that was created two years ago with default settings. The data at rest in the blob containers and the f
- You have an Azure subscription that contains a storage account named storage2 and a key vault named KV2 that uses the Azure role-based access control permission model and has purge protection enabled.
- Infrastructure encryption adds a second independent encryption layer
Infrastructure encryption causes Azure Storage data to be encrypted twice, once at the service level and again at the infrastructure level with different keys. Use it when policy requires double encryption rather than merely customer ownership of one encryption key.
Trap A customer-managed key by itself, which changes control of the service-level key but does not add the infrastructure-encryption layer.
8 questions test this
- Your company has an Azure subscription that contains a resource group named RG1. You are provisioning a new general-purpose v2 storage account named storage20 in RG1 for regulated blob data that will
- You have an Azure subscription named Sub1 that contains a resource group named RG1. A regulated finance workload requires a new SMB file share named share1 that must run on premium performance storage
- You have an Azure subscription named Sub1 that contains 45 general-purpose v2 storage accounts that different teams created over the past three years. A new control requires the accounts that hold reg
- Your company has an Azure subscription named Sub1 and a key vault named KV7 that has soft delete and purge protection enabled. You must provision a new general-purpose v2 storage account named storage
- You have an Azure subscription that contains a general-purpose v2 storage account named storage24 that holds regulated blob data. An auditor asks for evidence that the data at rest in storage24 is enc
- You have an Azure subscription that contains a general-purpose v2 storage account named storage22 that was created without infrastructure encryption. A container named legal2 uses a default encryption
- Your company deploys every Azure storage account from an Azure Pipelines release that uses an Azure Resource Manager template. A new standard states that all data at rest in storage accounts created f
- You have an Azure subscription that contains a general-purpose v2 storage account named storage21 that was created 18 months ago and holds several blob containers for internal reporting. A new regulat
- Blob soft delete preserves deleted data for a configured retention period
Blob soft delete retains a deleted or overwritten blob so it can be restored during the retention interval. It is a recoverability control, not a write-once retention control.
Trap A time-based immutability policy, which prevents protected versions from being modified or deleted instead of making ordinary deletions recoverable.
8 questions test this
- You have an Azure Storage account named legal1 that contains a container named case772. The container holds documents that your legal department must preserve for pending litigation, and nobody can pr
- You have an Azure subscription that contains a general-purpose v2 storage account named sa1. Blob soft delete is enabled for sa1 with a 14-day retention interval, and blob versioning is enabled. A dev
- You have an Azure Storage account named sa2 that has both blob versioning and blob soft delete enabled. A user deleted a blob named report.pdf and separately deleted two of its previous versions. Duri
- You have an Azure Storage account named files1 that contains an SMB Azure file share named share1. Soft delete for file shares is enabled for files1, and a nightly automated job creates a share snapsh
- You have an Azure subscription that contains a general-purpose v2 storage account named app1data. A line-of-business application overwrites the same set of block blobs many times each day by calling P
- You have an Azure subscription that contains a storage account named prod1. Blob soft delete, container soft delete, and blob versioning are all enabled for prod1 with generous retention intervals. Du
- You have an Azure Storage account named audit1 that contains a container named logs1. An unlocked time-based retention policy at container scope keeps the audit records in logs1 in a WORM state, and y
- Your company has an Azure subscription that contains a storage account named datalake1. The account has the hierarchical namespace feature enabled and is used by an Azure Data Lake Storage workload. A
- Blob versioning preserves earlier object states as separate versions
When blob versioning is enabled, Azure Storage automatically creates and retains previous versions as a blob changes. Versioning protects blob revisions, but container soft delete must be enabled separately to recover a deleted container.
Trap Container soft delete alone, which can recover a removed container but does not retain every prior version of each changing blob.
7 questions test this
- You have an Azure subscription that contains a general-purpose v2 storage account named media5 that has blob versioning enabled. A container named renders holds thousands of previous versions of image
- You have an Azure subscription that contains a general-purpose v2 storage account named claims7 that has blob versioning enabled. A forensic examiner who works for an outside firm must read two specif
- You have an Azure subscription that contains two general-purpose v2 storage accounts named telemetry1 and telemetry2. An object replication policy copies block blobs from telemetry1 to telemetry2, blo
- Your company has two general-purpose v2 storage accounts named ordersprod in the East US region and ordersdr in the West Europe region, and both accounts store block blobs only. A reporting workload i
- You have an Azure subscription that contains a general-purpose v2 storage account named auditlog5 that has blob versioning enabled. An application writes compliance events to append blobs in a contain
- You have an Azure subscription that contains a general-purpose v2 storage account named records1 that has no data protection features turned on. Three containers in records1 hold contract documents th
- You have an Azure subscription that contains a general-purpose v2 storage account named streams3 that has blob versioning enabled. A container named feeds holds a block blob named feed.dat that has se
- Time-based retention and legal holds enforce different immutable-storage conditions
Immutable storage for blobs provides WORM protection through time-based retention policies and legal holds. A locked time-based policy remains enforced until its retention period expires, whereas a legal hold remains until its tags are explicitly cleared.
Trap Blob soft delete, which permits recovery after deletion but does not prevent an authorized deletion from occurring.
7 questions test this
- You have a general-purpose v2 storage account named partnerdrop1 that has the hierarchical namespace feature enabled and SFTP support turned on. External partners upload settlement files as SFTP local
- Your company keeps clinical trial records in a container named trials2 in a general-purpose v2 storage account named research6. trials2 is protected by a locked container-level time-based retention po
- You have a general-purpose v2 storage account named opsdata4 that was created three months ago. Blob versioning, change feed, blob soft delete, and point-in-time restore are all enabled on opsdata4 fo
- You have a general-purpose v2 storage account named legalarch7 that has blob versioning and version-level immutability support enabled. A container named matters holds several million blobs, and a lif
- You have an Azure Data Lake Storage account named lakeaudit3 that has the hierarchical namespace feature enabled. A pipeline writes raw files into a directory of a container named curated and renames
- You have an Azure subscription that contains a general-purpose v2 storage account named records2. A container named claims2019 is protected by a locked container-level time-based retention policy whos
- You have a geo-redundant general-purpose v2 storage account named archive8 whose primary region is East US. A container named ledgers is protected by a locked container-level time-based retention poli
- Point-in-time blob restore depends on versioning, change feed, and soft delete
Point-in-time restore for block blob data requires blob versioning, blob change feed, and blob soft delete to be enabled. Its restore window must be shorter than the soft-delete retention period.
Trap Geo-redundant replication, which provides regional durability but does not rewind a container to a selected earlier time.
8 questions test this
- You have an Azure subscription that contains a standard general-purpose v2 storage account named assets4. Point-in-time restore is enabled for assets4 with a 14-day maximum restore point, and a lifecy
- You have an Azure subscription that contains a standard general-purpose v2 storage account named crm7 that stores block blobs. Blob versioning, the change feed, blob soft delete, container soft delete
- You have an Azure subscription that contains a standard general-purpose v2 storage account named billing3 that stores block blobs only. Blob versioning, the blob change feed, and blob soft delete with
- You have an Azure subscription that contains a standard general-purpose v2 storage account named logs8 that stores block blobs. Point-in-time restore is enabled for logs8 with a 25-day maximum restore
- You have an Azure subscription that contains a standard general-purpose v2 storage account named ingest2 that stores block blobs. Point-in-time restore is enabled for ingest2 with a 14-day maximum res
- You have an Azure subscription that contains a standard general-purpose v2 storage account named reports5 that is configured for read-access geo-redundant storage (RA-GRS). Point-in-time restore is en
- You have an Azure subscription that contains a standard general-purpose v2 storage account named custdata6 that holds eight containers of block blobs. Point-in-time restore is enabled for custdata6 wi
- You have an Azure subscription that contains a standard general-purpose v2 storage account named trading2 that was configured for geo-redundant storage. Blob versioning, the change feed, blob soft del
- Storage allow rules take effect only with a default-deny public endpoint
To restrict a storage account public endpoint to selected networks, set the default network action to Deny and then add the required virtual network, public IPv4, resource-instance, or trusted-service allowances. Merely adding allow entries while the default action is Allow does not create a restrictive firewall boundary.
Trap Creating an NSG rule on an unrelated subnet, which does not change who can reach the storage account public endpoint.
10 questions test this
- Your company has an Azure subscription that contains a storage account named storage1. A colleague configured the networking settings of storage1 by adding a virtual network rule for a subnet named Su
- You have an Azure subscription that contains a storage account named storage6 and an Azure Synapse Analytics workspace named Workspace6. Public network access on storage6 is set to Enabled from select
- You have an Azure subscription that contains a storage account named storage8. Public network access on storage8 was previously set to Enabled from selected networks, with two resource instance rules
- You have an Azure subscription that contains a storage account named storage10. Public network access on storage10 is set to Enabled from selected networks, and one virtual network rule allows an appl
- Your company has an Azure subscription that contains a storage account named storage4. Public network access on storage4 is set to Enabled from selected networks, and a virtual network rule allows one
- Your company deploys every storage account from a Bicep template that sets the publicNetworkAccess property of the account to Disabled. Each account is reachable only through a private endpoint, and t
- You have an Azure subscription that contains a storage account named storage7. Public network access on storage7 is set to Enabled from selected networks, one virtual network rule allows an applicatio
- You have an Azure subscription that contains a storage account named storage3 in the North Europe region and a virtual network named VNet2 in the West Europe region. A subnet in VNet2 named DataSubnet
- You have an Azure subscription that contains a storage account named storage11 in the North Europe region and a virtual network named VNet4 in the West Europe region. Public network access on storage1
- You have an Azure subscription that contains a storage account named storage2 and a virtual network named VNet1 in the same Azure region. VNet1 contains a subnet named AppSubnet that hosts several vir
- A storage virtual-network rule requires the matching service endpoint on the subnet
Allowing a subnet through the Azure Storage firewall requires a virtual-network rule on the account and a Microsoft.Storage or Microsoft.Storage.Global service endpoint on that subnet. The portal can create the endpoint while the rule is added, but command-line deployments must ensure both sides are configured.
Trap Adding only the Microsoft.Storage service endpoint to the subnet, which does not by itself authorize that subnet on the account firewall.
9 questions test this
- You have an Azure subscription that contains a storage account named storage18 and a virtual network named VNet8 in the same Azure region. A subnet named ReportSubnet has an Azure Storage service endp
- You have an Azure subscription that contains a storage account named storage18 and a virtual network named VNet8 in the same Azure region. A subnet named ReportSubnet has an Azure Storage service endp
- You have an Azure subscription that contains a storage account named storage14 that holds research datasets in a blob container. Public network access on storage14 is set to Enabled from selected netw
- You have an Azure subscription that contains a virtual network named VNet7 whose subnet named ScienceSubnet has an Azure Storage service endpoint enabled. Virtual network rules on two corporate storag
- You have an Azure subscription that contains a storage account named storage21 and a virtual network named VNet10 in the same Azure region. A subnet named WebSubnet has an Azure Storage service endpoi
- You have an Azure subscription that contains a storage account named storage13. Public network access on storage13 is set to Enabled from selected networks, and a virtual network rule authorized a sub
- You have an Azure subscription that contains a storage account named storage16 in the West Europe region and a virtual network named VNet6 in the same region. VNet6 contains a subnet named AppSubnet a
- You have an Azure subscription that contains two storage accounts named storage19 and storage20 in the North Europe region. A virtual network named VNet9 contains a subnet named LabSubnet that has an
- You have an Azure subscription that contains a storage account named storage15 and a virtual network named VNet5 in the same Azure region. VNet5 contains a subnet named IngestSubnet whose virtual mach
- Storage IP rules cannot select same-region Azure clients
Azure Storage IP firewall rules accept public IPv4 addresses and do not restrict requests from Azure clients in the same region as the storage account. Use a virtual-network rule or private connectivity when same-region Azure workload access must be selected.
Trap Adding the workload's private RFC 1918 address to an IP rule, because storage IP rules require public internet addresses.
9 questions test this
- Your company has an Azure subscription that contains a storage account named storage23 in the West Europe region. Public network access on storage23 is set to Enabled from selected networks, and the d
- You have an Azure subscription that contains a storage account named storage30 in the West Europe region. Public network access on storage30 is set to Enabled from selected networks, the default actio
- You have an Azure subscription that contains a storage account named storage24 in the North Europe region. Public network access on storage24 is set to Enabled from selected networks, the default acti
- You have an Azure subscription that contains a storage account named storage31 in the Central US region. Public network access on storage31 is set to Enabled from selected networks, and the default ac
- You have an Azure subscription that contains a storage account named storage22 and a virtual machine named VM1, both in the East US region. Public network access on storage22 is set to Enabled from se
- You have an Azure subscription that contains a storage account named storage29 in the North Europe region. A partner organization runs a nightly export job on a server in its own datacenter, and all t
- You have an Azure subscription that contains a storage account named storage27 and an Azure AI Search service named Search1, both in the East US region. Public network access on storage27 is set to En
- You have an Azure subscription that contains a storage account named storage28 in the East US region. Public network access on storage28 is set to Enabled from selected networks, and the default actio
- You have an Azure subscription that contains a storage account named storage25 and a function app named Func2 that runs on an Elastic Premium plan, both in the East US region. Public network access on
- Storage firewall rules govern data-plane operations rather than control-plane management
Azure Storage firewall rules are enforced for data-plane protocols such as REST and SMB, but they do not restrict Azure Resource Manager control-plane operations. Network admission also does not grant data authorization; an allowed caller still needs valid credentials and permissions.
Trap Treating a trusted-service exception as an RBAC assignment, even though the exception permits a network path rather than a data operation.
- Storage management roles do not inherently grant data access through Microsoft Entra ID
To authorize blob, queue, table, or file data operations with Microsoft Entra ID, assign an appropriate Storage data role at the narrowest required scope. A control-plane role such as Contributor can manage the account but does not by itself authorize data access through Microsoft Entra credentials.
Trap Storage Account Contributor, which manages storage accounts but is not a Storage data-plane role.
9 questions test this
- You have an Azure subscription that contains a storage account named storage9. storage9 contains a table named Telemetry, and Shared Key authorization is disallowed on the account. A user named User2
- Your Azure environment contains a management group named MG1 that holds two subscriptions, each with several storage accounts that store analytics data. Shared Key authorization is disallowed on every
- You have an Azure subscription that contains a storage account named storage7 that has the hierarchical namespace feature enabled. A container named lake holds directories and files created by a servi
- You have an Azure subscription that contains a storage account named storage6 and an App Service web API named api1 that brokers blob downloads for partner applications. api1 authenticates by using a
- You have an Azure subscription that contains a storage account named storage3 and an Azure Kubernetes Service cluster that runs an order intake service. The service authenticates to Azure by using a w
- You have an Azure subscription that contains a storage account named storage10 that is configured for Active Directory Domain Services authentication and hosts an SMB file share named archive. Several
- You have an Azure subscription that contains a storage account named storage8 that does not use a hierarchical namespace. storage8 holds hundreds of containers, and the blobs that belong to one projec
- Your company has an Azure subscription that contains a storage account named storage5 configured with Active Directory Domain Services authentication for SMB. storage5 contains a file share named proj
- You have an Azure subscription that contains a storage account named storage2 with a container named reports. A user named User1 is assigned the Storage Blob Data Contributor role scoped to reports. W
- A user delegation SAS avoids signing blob access with the account key
For Blob Storage, a user delegation SAS is secured with Microsoft Entra credentials and a user delegation key. Microsoft recommends it over a service SAS or account SAS when delegated blob access can use Microsoft Entra authorization.
Trap An account SAS, which is signed with a storage account key and can delegate service-level operations across supported services.
8 questions test this
- You have an Azure subscription that contains a storage account named storage14. A support engineer used user delegation SAS links to share blobs in a container named exports, and one of those links wa
- You have an Azure subscription that contains a storage account named storage12 and a web app named app2. app2 generates time-limited download links for the blobs in a container named invoices2 and sen
- You have an Azure subscription that contains a storage account named storage11 with a container named telemetry. Allow storage account key access is set to Disabled on storage11. An external analytics
- Your company has a management group named MG-Data that contains three Azure subscriptions with a combined 40 storage accounts. All application teams have migrated to Microsoft Entra authorization and
- You have an Azure subscription that contains a storage account named storage16 that holds blob data for several internal applications. Your security baseline states that requests to storage16 must be
- You have an Azure subscription that contains a storage account named storage17 that is used by several in-house applications. Before you migrate those applications to Microsoft Entra authorization and
- You have an Azure subscription that contains a storage account named storage15 with a container named reports2. A vendor holds service SAS links for reports2 that reference a stored access policy name
- You have an Azure subscription that contains a storage account named storage19. Partners download blobs through user delegation SAS links that a broker app issues, and developers also sign ad hoc toke
- Stored access policies provide revocable constraints only for service SAS tokens
A stored access policy can define start time, expiry, and permissions for one or more service SAS tokens and allows those constraints to be changed or revoked centrally. Stored access policies are not supported for account SAS or user delegation SAS tokens.
Trap Associating a user delegation SAS with a stored access policy, which that SAS type does not support.
5 questions test this
- You have an Azure subscription that contains a storage account named storage21 with a container named drawings. A build service issues SAS links so that a partner engineering firm can download blobs f
- You have an Azure subscription that contains a storage account named storage22 with a container named payroll. A contractor currently holds an account SAS for storage22 that expires in six months. An
- You have an Azure subscription that contains a storage account named storage29 with a container named feeds. The feeds container already carries five stored access policies, one for each data supplier
- You have an Azure subscription that contains a storage account named storage26 with a container named logs2. A service SAS token that referenced a stored access policy named ops-read on logs2 leaked,
- You have an Azure subscription that contains a storage account named storage27 with a container named catalog. A partner's on-premises automation downloads blobs from catalog by using a service SAS th
Setting AllowSharedKeyAccess to false rejects requests authorized with the storage account keys, including service SAS and account SAS requests. Microsoft Entra authorization and user delegation SAS remain the preferred alternatives for supported Blob Storage operations.
Trap Rotating both account keys, which replaces credentials but continues to permit Shared Key authorization.
6 questions test this
- You have an Azure subscription named Sub1 that contains a storage account named storage30. storage30 holds blob containers that analysts read from managed laptops, and an SMB file share named plant th
- You have an Azure subscription that contains a storage account named storage36. Allow storage account key access is set to Disabled on storage36. An inventory application that runs on a physical Windo
- You have an Azure subscription that contains 30 storage accounts. You disallow Shared Key authorization on 27 of them. The remaining three accounts serve a vendor appliance that accepts only a connect
- You have an Azure subscription named Sub1 that contains a resource group named RG-Data with 12 storage accounts. A governance engineer named Eng1 must be able to set Allow storage account key access t
- You have an Azure subscription that contains a storage account named storage31 that holds several blob containers. Three in-house applications still authorize their requests to storage31 with a connec
- You have an Azure subscription that contains 60 storage accounts. You run an Azure Resource Graph query that projects the allowSharedKeyAccess property of every storage account in the subscription. Th
- Subscription-level Defender for Storage protects existing and future accounts
Enable Defender for Storage at subscription scope when all current and newly created storage accounts should inherit protection. Turn on Override Defender for Storage subscription-level settings on an individual account before giving that account different feature or malware-cap settings.
Trap Changing the subscription-wide malware cap to customize one account, which also changes the inherited setting for every other account.
3 questions test this
- You have an Azure subscription named Sub1 that contains 40 storage accounts, and your application teams deploy several new storage accounts in Sub1 every week. Microsoft Defender for Cloud is already
- You have an Azure subscription named Sub1 in which Defender for Storage is enabled at the subscription level with on-upload malware scanning turned on for every storage account. Sub1 contains a storag
- You have an Azure subscription named Sub1 that contains 25 storage accounts, all protected by Defender for Storage with on-upload malware scanning. Every account uses the default monthly scanning limi
- Event Grid drives immediate malware response while Log Analytics retains scan records
Configure an Event Grid custom topic to deliver every Defender for Storage malware scan result for near-real-time automation. Configure a Log Analytics workspace when every result must instead be retained centrally for query, audit, or compliance.
Trap Azure Event Hubs as the native malware-result automation destination, rather than the documented Event Grid custom topic.
5 questions test this
- You have an Azure subscription that contains a storage account named storage6 with on-upload malware scanning enabled. Your organization's SIEM pipeline already ingests telemetry from an Azure event h
- You have an Azure subscription that contains a storage account named storage4 protected by Defender for Storage with on-upload malware scanning. Compliance requires that every scan result for storage4
- You have an Azure subscription that contains a storage account named storage2 with Defender for Storage and on-upload malware scanning enabled. An external auditor requires evidence that every blob up
- Your company has an Azure subscription that contains a storage account named storage3 with on-upload malware scanning enabled. When malware scanning was enabled, an Event Grid system topic was created
- You have two Azure subscriptions named Sub1 and Sub2 in the same Microsoft Entra tenant. Sub1 contains a storage account named storage8 that has on-upload malware scanning enabled. Sub2 contains your
- The malware scanning cap is monthly and evaluated per storage account
On-upload malware scanning uses a per-storage-account monthly data cap, with 10,000 GB as the default. Set an account override for a different local cap, or use -1 in supported deployment interfaces for unlimited scanning.
Trap A Microsoft Sentinel workspace daily cap, which limits analytics ingestion rather than Defender for Storage scanning volume.
3 questions test this
- You have an Azure subscription named Sub1 that contains a storage account named storage10 used for regulated claim documents. Defender for Storage is enabled on Sub1 with on-upload malware scanning, a
- You have an Azure subscription that contains a storage account named storage13 that Defender for Storage protects with on-upload malware scanning. On-upload scanning halted for storage13 in mid-month
- You have an Azure subscription named Sub1 that contains a storage account named storage11 holding 30 TB of partner documents that were uploaded before Defender for Storage was enabled. Defender for St
- Built-in malware remediation quarantines detected blobs through soft delete
When the optional soft-delete-malicious-blobs setting is enabled, Defender for Storage soft deletes blobs found malicious by on-upload or on-demand scanning and keeps them recoverable for investigation. The feature is off by default and enables blob soft delete if the account did not already have it.
Trap Blob index tags alone, which record scan results but do not remove access to a malicious blob.
3 questions test this
- You have an Azure subscription that contains a storage account named storage15 protected by Defender for Storage with on-upload malware scanning and the soft deletion of malicious blobs turned on. To
- You have an Azure subscription that contains a storage account named storage16 that receives millions of small blobs each day. Defender for Storage with on-upload malware scanning protects storage16,
- You have an Azure subscription that contains a storage account named storage17 with Defender for Storage, on-upload malware scanning, and the soft deletion of malicious blobs enabled. Blob versioning
- Sensitive data threat detection enriches storage alerts without scanning every object
Defender for Storage sensitive data threat detection uses agentless smart sampling and Microsoft Purview sensitive information types and labels to add data-sensitivity context to suspicious activity. It is a configurable feature separate from malware scanning.
Trap On-upload malware scanning, which examines uploaded objects for malware rather than classifying sensitive business data.
2 questions test this
- You have an Azure subscription named Sub1 that contains a general-purpose v2 storage account named storage35 that a claims application uses. Microsoft Defender for Storage protects Sub1, sensitive dat
- You have an Azure subscription named Sub1 that contains 13 storage accounts and has Microsoft Defender for Storage enabled at the subscription level with sensitive data threat detection turned on. Twe
- Defender for Storage activity monitoring does not require resource logs
Defender for Storage continuously analyzes data-plane and control-plane telemetry from protected storage accounts to detect suspicious access patterns and behavior. Resource logs do not need to be enabled for this activity-monitoring protection.
4 questions test this
- You have an Azure subscription named Sub1 that contains a storage account named storage24 that holds customer documents. Microsoft Defender for Storage is enabled on Sub1, but storage24 has no diagnos
- You have an Azure subscription named Sub1 that contains a storage account named storage24 that holds customer documents. Microsoft Defender for Storage is enabled on Sub1, but storage24 has no diagnos
- You have an Azure subscription named Sub1 that contains 25 storage accounts that Microsoft Defender for Storage protects. None of the storage accounts has a diagnostic setting, and the storage securit
- Your company has an Azure subscription named Sub1 in which Microsoft Defender for Storage is enabled at the subscription level. The onboarding runbook of the platform team states that resource logs mu
- Full malware scanning is deeper and narrower in plan availability than hash reputation
Full malware scanning uses Microsoft Defender Antivirus to inspect Blob content and includes hash reputation analysis, but it is a paid feature available only with the new Defender for Storage plan. Hash reputation compares newly uploaded Blob storage and Azure Files object hashes with known malware, is available in all plans, and can miss unsupported operations such as SMB uploads and Put Block with Put Block List.
- ABAC can gate blob access on Defender malware scan-result tags
Apply Microsoft Entra ABAC role-assignment conditions to Defender for Storage malware scan-result blob index tags when users and applications must access only blobs whose scan result is clean. This preventive pattern blocks unscanned or malicious blobs instead of waiting for a later remediation workflow.
5 questions test this
- You have an Azure subscription that contains a storage account named storage26 that is protected by Microsoft Defender for Storage with on-upload malware scanning. To reduce blob indexing charges, a c
- You have an Azure subscription that contains a storage account named storage28 that is protected by Microsoft Defender for Storage, and malware scan results are stored in blob index tags. An applicati
- You have an Azure subscription that contains a storage account named storage29 that is protected by Microsoft Defender for Storage, and malware scan results are stored in blob index tags. You created
- You have an Azure subscription that contains a storage account named storage27. Microsoft Defender for Storage stores malware scan results in blob index tags, and you added a Microsoft Entra ABAC cond
- You have an Azure subscription that contains a general-purpose v2 storage account named storage25 that receives partner uploads. Microsoft Defender for Storage protects storage25 with on-upload malwar
- Defender malware events require a regional, publicly reachable custom topic
Create the Event Grid custom topic for Defender for Storage malware results in the same region as the protected storage account because cross-region delivery is unsupported. The topic must allow public IP access; a private-endpoint-only topic cannot receive Defender for Storage events.
5 questions test this
- You have an Azure subscription that contains a storage account named storage32 and an Event Grid custom topic named topic2, both in the West US 3 region. Microsoft Defender for Storage protects storag
- You have an Azure subscription that contains a storage account named storage33 and an Event Grid custom topic named topic3 that is deployed in the same region as the account. Microsoft Defender for St
- You have an Azure subscription that contains a storage account named storage30 in the North Europe region. Microsoft Defender for Storage protects storage30 with on-upload malware scanning. You must d
- Your company has an Azure subscription that contains nine storage accounts that receive customer uploads: three in East US, three in West Europe, and three in Southeast Asia. Microsoft Defender for St
- You have an Azure subscription that contains a storage account named storage31 in the East US region and an Event Grid custom topic named topic1 in the Central US region. Microsoft Defender for Storag
Implement security for databases
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Implement security for Azure network services
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Secure compute
Implement security for AI
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Implement security for servers and virtual machines (VMs)
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Implement security for application platform services
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Manage and monitor security posture
Manage security posture by using Defender for Cloud
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Implement activity and event collection in Microsoft Sentinel
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Implement Microsoft Security Copilot
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.