Microsoft Certified: Azure Security Engineer Associate practice questions

209 free questions with answers and explanations.

Practice test
  1. 1.A security engineer is configuring a new Azure subscription and needs to ensure that all resources deployed within it meet specific organizational security standards, such as requiring encryption at rest for all storage accounts and restricting network access to virtual machines. They want to define a set of rules that apply uniformly across the subscription. Which Azure service is primarily used to define and enforce these security standards?Manage security operations
  2. 2.A security administrator is setting up a new Azure subscription for a development team. They need to ensure that all virtual machines provisioned in this subscription automatically have Microsoft Defender for Cloud's endpoint protection enabled. Manual configuration for each VM is not feasible due to the dynamic nature of the environment. Which Azure Policy effect should they use to achieve this?Manage security operations
  3. 3.A security engineer is configuring Azure Monitor to detect unusual administrative activities within their Azure subscription. They want to receive an alert whenever a 'Delete Virtual Machine' operation is initiated by any user, excluding specific automated service principals. The alert should trigger within 5 minutes of the event occurring. Which type of alert rule should be created in Azure Monitor to meet these requirements?Manage security operations
  4. 4.A security engineer is investigating a potential data exfiltration incident. They need to analyze diagnostic logs from an Azure Storage Account that contains sensitive data. Specifically, they want to filter the logs to show only 'Read' operations performed by non-trusted IP addresses and project only the 'time', 'caller IP address', and 'operation name' fields. Which Kusto Query Language (KQL) operator should be used to select specific columns for display?Manage security operations
  5. 5.A security engineer is investigating a potential data exfiltration incident. They need to identify all network connections from a specific virtual machine (VM) to external IP addresses over the past 24 hours. The VM's network interface has Network Watcher NSG Flow Logs enabled, sending data to a Log Analytics workspace. Which Kusto Query Language (KQL) operator should be used to extract only the source IP, destination IP, and destination port from the raw flow log data?Manage security operations
  6. 6.A global organization uses Azure Monitor and Log Analytics across multiple Azure regions. They want to centralize security event collection from all resources into a single Log Analytics workspace for easier monitoring and threat hunting. What is the most significant challenge they will face with this centralized approach, especially for resources in distant regions?Manage security operations
  7. 7.A security operations center (SOC) team uses Microsoft Sentinel for threat detection and response. They want to ensure that all security incidents generated by Sentinel are automatically forwarded to their existing third-party ITSM (IT Service Management) system for ticketing and workflow management. Which Sentinel feature should they configure to achieve this automation?Manage security operations
  8. 8.A company is using Microsoft Sentinel for SIEM and SOAR. They have configured analytic rules to detect suspicious activities. They now want to automatically enrich incidents with threat intelligence data from a third-party feed and then send a notification to a Microsoft Teams channel. Which type of automated response should they implement?Manage security operations
  9. 9.A security engineer is investigating a series of suspicious activities detected in Azure. They need to correlate events across different Azure services, such as virtual machine logs, network security group flow logs, and Azure Active Directory sign-in events, to build a comprehensive timeline of the attack. Which service provides the centralized log collection and powerful query language necessary for this multi-source correlation?Manage security operations
  10. 10.A company is implementing Microsoft Defender for Cloud for their Azure environment. They need to ensure that all newly provisioned virtual machines are automatically configured with a specific set of security extensions, including a vulnerability assessment solution. The security team wants this to be enforced across all subscriptions and resource groups without manual intervention. Which Azure Policy effect should they use in conjunction with Defender for Cloud recommendations to achieve this?Manage security operations
  11. 11.A security engineer needs to analyze security logs from various Azure resources, such as virtual machines, network security groups, and Azure Key Vaults, in a centralized location. They want to perform complex queries to correlate events and identify potential threats. Which Azure service is best suited for collecting, storing, and efficiently querying these diverse security logs?Manage security operations
  12. 12.A security analyst is investigating a suspected data exfiltration incident from an Azure Storage Account. They need to analyze access logs to identify who accessed specific blobs, when, and from what IP address. The logs are currently being sent to a Log Analytics workspace. Which Kusto Query Language (KQL) operator should the analyst use to extract these specific fields while discarding all other columns from the query results for clarity and performance?Manage security operations
  13. 13.A security engineer needs to configure Azure Monitor to detect when a specific security event ID (e.g., Event ID 4625 for failed logins) appears more than 50 times within a 15-minute window from any server connected to a Log Analytics workspace. Which type of alert rule should the engineer create?Manage security operations
  14. 14.A company is migrating its on-premises servers to Azure and needs to ensure consistent security monitoring and threat detection for both cloud and hybrid environments. They want to use Azure Security Center (now Microsoft Defender for Cloud) to achieve this. Which component of Defender for Cloud is essential for extending security monitoring to non-Azure (on-premises and other cloud) machines?Manage security operations
  15. 15.A security administrator needs to ensure that all virtual machines in a specific Azure subscription have their diagnostic settings configured to send audit logs to a Log Analytics workspace. This requirement must be enforced automatically for new VMs and audited for existing ones. Which Azure service should be used to implement this requirement?Manage security operations
  16. 16.A global organization uses Azure Monitor to collect logs from various Azure resources and on-premises servers. They have a strict requirement to retain security-related logs for 7 years for compliance purposes. However, due to cost considerations, they want to retain performance metrics and non-security diagnostic logs for only 90 days. How can this requirement be met efficiently within a single Log Analytics workspace?Manage security operations
  17. 17.A company uses Azure Security Center (now Microsoft Defender for Cloud) to manage its security posture. They have several Azure subscriptions and want to ensure that all virtual machines across these subscriptions are configured with a specific set of security recommendations. Which feature should they use to centrally define and apply these security recommendations?Manage security operations
  18. 18.A company has implemented Microsoft Defender for Cloud for server protection. They receive an alert labeled 'High severity - Anomalous SSH activity detected on VM-Prod-01'. The security team needs to quickly understand the scope of the attack, including other potentially affected resources and the attacker's tactics, techniques, and procedures (TTPs). Where in Microsoft Defender for Cloud should they look first for this consolidated information?Manage security operations
  19. 19.A company is using Azure Monitor and Log Analytics to collect security logs from various Azure resources. They want to create a custom alert that triggers when more than 5 failed login attempts occur within a 10-minute window from the same source IP address against any virtual machine. Which component of Azure Monitor is best suited for defining and managing this type of alert?Manage security operations
  20. 20.A security operations team uses Microsoft Sentinel for threat detection and response. They have configured analytic rules to generate incidents based on suspicious activities. The team wants to ensure that critical incidents, specifically those related to 'High Severity Malware Detections' on production servers, trigger an immediate notification to the on-call security engineer via Microsoft Teams. Which feature in Microsoft Sentinel should be used to automate this notification?Manage security operations
  21. 21.A security operations team uses Microsoft Sentinel for SIEM. They want to automate the response to a high-severity alert indicating a brute-force attack against an Azure Active Directory user. The desired automated action is to block the compromised user account. Which Sentinel feature should they configure to achieve this automation?Manage security operations
  22. 22.A financial institution requires strict compliance with PCI DSS for its Azure-hosted payment processing applications. They use Azure Security Center (now Microsoft Defender for Cloud) to monitor their environment. To demonstrate compliance, they need to regularly assess their resources against the PCI DSS standard and generate reports. Which Security Center feature should be configured for this purpose?Manage security operations
  23. 23.A security analyst is investigating a series of suspicious activities in Azure. They need to find all 'Delete' operations performed on Azure Key Vaults within the last 7 days across multiple subscriptions. Which Azure service should the analyst primarily use to query this information?Manage security operations
  24. 24.A security engineer is tasked with investigating a series of suspicious activities reported on several Azure virtual machines. The incidents indicate potential unauthorized access and privilege escalation. To effectively analyze the sequence of events and identify the root cause, the engineer needs to collect detailed system performance, process creation, and network connection data from these VMs. Which Azure Monitor agent should be deployed to these virtual machines to capture this comprehensive set of security-relevant data?Manage security operations
  25. 25.A security architect is designing a monitoring solution for a highly sensitive application running on Azure Kubernetes Service (AKS). They need to ensure that all security events, container logs, and network flow data from the AKS cluster are collected and sent to a central security information and event management (SIEM) solution, which is Azure Sentinel. What is the most comprehensive and recommended approach to achieve this data collection?Manage security operations
  26. 26.A security operations team uses Microsoft Sentinel. They have configured several analytic rules that generate incidents. The team observes that a significant number of low-fidelity incidents are being created, which are often benign but require manual review, leading to alert fatigue. They want to automatically close these low-fidelity incidents if they meet specific criteria (e.g., source IP is from an allow-list, or the alert name contains 'informational'). What Microsoft Sentinel feature should they use to achieve this automation?Manage security operations
  27. 27.A security team needs to ensure that all virtual machines in a specific Azure subscription are configured with a particular Network Security Group (NSG) and that this NSG enforces a set of specific inbound and outbound rules. If a VM is deployed without the correct NSG or if the NSG rules deviate from the standard, it should be flagged as non-compliant. Which Azure Policy feature should be used to define and enforce this requirement?Manage security operations
  28. 28.A company is using Microsoft Defender for Cloud for their Azure environment. They have a custom security policy that requires all virtual machines to have a specific anti-malware solution installed. After deploying a new VM, Defender for Cloud shows a 'Not Compliant' status for this policy. What is the most immediate action a security engineer should take to understand why the VM is non-compliant?Manage security operations
  29. 29.An organization is using Azure Security Center (now Microsoft Defender for Cloud) to manage its security posture. They have observed that certain virtual machines consistently report high-severity security recommendations, but these recommendations are already addressed by external security tools or organizational policies not recognized by Defender for Cloud. To avoid skewing their security score and focus on relevant recommendations, which action should they take?Manage security operations
  30. 30.A global organization uses Azure Sentinel (now Microsoft Sentinel) across multiple Azure regions. They need to ensure that security data collected from each region remains within its geographical boundaries to comply with data residency regulations, while still allowing a central security operations center (SOC) to have a consolidated view of all incidents. Which Sentinel architecture approach best addresses this requirement?Manage security operations
  31. 31.A security engineer is configuring Azure Monitor to detect unusual network traffic patterns within a Virtual Network (VNet). They want to be alerted if the average inbound and outbound traffic for any VM within the VNet exceeds a specific threshold over a 5-minute period. Which type of alert rule should the engineer create?Manage security operations
  32. 32.A security analyst is monitoring security alerts in Azure Security Center (now Microsoft Defender for Cloud). They notice a high-severity alert indicating 'Suspicious process executed in a container'. They need to quickly understand the scope of the attack, including affected resources and related events, to determine the appropriate response. Which feature in Security Center provides this consolidated view?Manage security operations
  33. 33.A security architect is designing a monitoring solution for a highly sensitive application hosted on Azure Kubernetes Service (AKS). They need to collect detailed security-related audit logs from the AKS control plane and worker nodes, specifically focusing on API server access and container runtime events, and send them to Microsoft Sentinel for analysis. Which data connector should be configured in Sentinel for this purpose?Manage security operations
  34. 34.A company is implementing a zero-trust security model and needs to enforce granular access policies for administrative roles. They want to ensure that privileged users only have access to specific resources for a limited time when performing critical tasks, and their access is automatically revoked afterward. Which Azure AD PIM feature should be configured to meet this requirement?Manage security operations
  35. 35.A security auditor needs to verify that all Azure Key Vaults in a subscription are configured to enable purge protection, which prevents immediate deletion of the vault or its contents. They want to quickly identify any non-compliant Key Vaults. Which service in Azure should the auditor use to assess this configuration against a predefined security standard?Manage security operations
  36. 36.A company is implementing Microsoft Defender for Cloud and needs to ensure that all Azure subscriptions within their tenant are continuously monitored for security posture, regulatory compliance, and threat protection, even newly created ones. They want to avoid manually onboarding each subscription. How should they configure Defender for Cloud to meet this requirement?Manage security operations
  37. 37.A security engineer is configuring Azure Monitor to detect suspicious login activities. They need to create an alert rule that triggers when more than five failed login attempts occur from the same IP address within a 10-minute window. Which type of alert rule should the engineer configure?Manage security operations
  38. 38.A security operations center (SOC) uses Azure Sentinel for monitoring. They have configured a custom analytics rule that uses a Kusto Query Language (KQL) query to detect unusual administrative logins. This rule generates a high volume of false positives due to legitimate, but infrequent, administrative activities. Which of the following is the most effective way to reduce false positives without missing actual threats?Manage security operations
  39. 39.A security operations center (SOC) team uses Microsoft Sentinel for SIEM. They want to create a custom rule to detect a specific type of attack pattern involving multiple failed login attempts followed by a successful login from a new, untrusted IP address within a 10-minute window. This requires correlating events from Azure AD sign-in logs. Which type of analytic rule in Microsoft Sentinel is best suited for this scenario?Manage security operations
  40. 40.A company is implementing a Zero Trust security model in Azure. They need to configure a mechanism that automatically revokes a user's administrative role assignment after a predefined time, requiring them to re-request access. This is essential for highly privileged roles. Which Azure Active Directory feature should be used to achieve this?Manage security operations
  41. 41.A security operations team uses Azure Monitor to collect diagnostic logs from Azure Key Vault. They need to create an alert that triggers specifically when a 'SecretGet' operation fails due to insufficient permissions. This alert should contain details about the caller, the Key Vault name, and the specific secret involved. Which Kusto Query Language (KQL) operator is most effective for extracting specific fields from a log entry and then filtering based on custom criteria?Manage security operations
  42. 42.A security engineer is setting up a new Azure subscription for a development team. They need to ensure that all new storage accounts created in this subscription automatically enable advanced threat protection (Microsoft Defender for Storage). How can this be achieved with the least administrative effort?Manage security operations
  43. 43.A security operations team uses Azure Sentinel (now Microsoft Sentinel) for SIEM. They have integrated various data sources, including Azure Active Directory (Azure AD) sign-in logs and activity logs. To detect sophisticated threats that involve multiple stages and different data sources, they need to create custom detection rules that correlate events. Which type of rule in Sentinel is designed for this advanced correlation?Manage security operations
  44. 44.A global organization uses Microsoft Defender for Cloud to manage its security posture across multiple Azure subscriptions and AWS accounts. They need to ensure that their custom regulatory compliance standards, which include specific controls not covered by default standards, are continuously assessed. What is the most efficient way to incorporate these custom standards into Defender for Cloud?Manage security operations
  45. 45.A security engineer is configuring Azure Security Center (now Microsoft Defender for Cloud) to protect SQL databases. They want to ensure that all SQL servers are continuously monitored for suspicious database activities, such as SQL injection attempts or unusual access patterns. Which specific Defender for Cloud plan should be enabled to provide this advanced threat protection for SQL databases?Manage security operations
  46. 46.A security engineer is investigating a potential insider threat. They need to analyze changes made to Azure resources by a specific user account over the last week, focusing on any resource deletions, role assignment changes, or modifications to network security group (NSG) rules. Which Azure Monitor log source should the engineer query to find this information?Manage security operations
  47. 47.A security engineer needs to configure Azure Monitor to alert when the CPU utilization of any virtual machine within a specific resource group exceeds 90% for more than 5 minutes. The alert should be sent to a specific email distribution list. Which alert type and configuration combination should the engineer use?Manage security operations
  48. 48.A security administrator needs to ensure that all virtual machines deployed in a specific Azure subscription automatically have Microsoft Defender for Cloud's endpoint protection solution (e.g., Microsoft Defender for Endpoint) enabled. This must be enforced without requiring manual configuration by developers. Which Azure Policy definition effect, when combined with a Defender for Cloud recommendation, is best suited to achieve this continuous enforcement?Manage security operations
  49. 49.A security operations center (SOC) analyst is investigating a series of suspicious activities reported across multiple Azure subscriptions within the organization. They need a centralized view of security alerts, incidents, and threat intelligence to efficiently triage and respond to these threats. Which Azure service is specifically designed to provide this comprehensive security information and event management (SIEM) and security orchestration, automation, and response (SOAR) capability?Manage security operations
  50. 50.A company is deploying a new set of Azure Virtual Machines that will host critical business applications. These VMs will store sensitive customer data on their data disks. The company's compliance policy mandates that all data at rest, including OS and data disks, must be encrypted using customer-managed keys (CMK) stored in Azure Key Vault. Which Azure encryption solution should be implemented to meet this requirement?Implement platform protection