Microsoft Certified: Azure Security Engineer Associate practice questions

209 free questions with answers and explanations.

Practice test
  1. 51.A security architect is designing the network security for a multi-tier application deployed across several Azure Virtual Networks (VNets). The application includes web servers, application servers, and database servers, each in its own subnet. Communication between these tiers must be restricted to only the necessary ports and protocols. Additionally, communication from the application servers to external APIs must be filtered. Which Azure networking security component is most suitable for enforcing granular, stateful packet filtering between subnets and for outbound internet traffic from the application servers?Implement platform protection
  2. 52.A development team is using Azure DevOps to build and deploy containerized applications to Azure Kubernetes Service (AKS). To ensure the integrity and security of the deployed images, the security team requires that all container images stored in Azure Container Registry (ACR) must be regularly scanned for vulnerabilities. If a critical vulnerability is found, the deployment pipeline should be blocked. Which Azure service integration provides this capability?Implement platform protection
  3. 53.An organization is deploying a highly critical web application in Azure that requires protection against common web vulnerabilities such as SQL injection, cross-site scripting, and other OWASP Top 10 threats. The application is exposed via an Azure Application Gateway. Which specific feature of Application Gateway should be enabled and configured to provide this protection?Implement platform protection
  4. 54.A security architect is designing the network topology for a highly sensitive application in Azure. The application's virtual machines (VMs) must not have direct internet access but still need to connect to Azure services like Azure Storage and Azure SQL Database securely, using the Azure backbone network instead of public endpoints. Which network security feature should be implemented to achieve this secure and private connectivity to Azure services?Implement platform protection
  5. 55.A security auditor requires that all new Azure Virtual Machines (VMs) deployed within a specific subscription automatically have their OS and data disks encrypted using platform-managed keys by default. The auditor also specifies that if a VM is deployed without encryption, it should be flagged for non-compliance, and ideally, the deployment should be prevented. Which Azure service should the security team use to enforce this requirement?Implement platform protection
  6. 56.A compliance officer needs to ensure that all Azure Virtual Machines (VMs) deployed in a specific subscription use managed disks and are encrypted with customer-managed keys (CMK) stored in Azure Key Vault. Furthermore, any attempt to deploy a VM without CMK encryption or with unmanaged disks must be explicitly denied. Which Azure Policy effect would achieve the strict denial requirement?Implement platform protection
  7. 57.A company is deploying a new set of Azure Virtual Machines that will host critical business applications. The security policy dictates that these VMs must have their operating system and data disks encrypted at rest to protect against unauthorized access to data, even if the underlying storage is compromised. The company also needs to manage the encryption keys centrally. Which Azure service combination provides disk encryption and central key management for these VMs?Implement platform protection
  8. 58.A development team is deploying a new microservices application using Azure Kubernetes Service (AKS). Each microservice runs in a separate container, and the team needs to ensure that network traffic between containers within the same cluster is securely segmented based on their roles. For instance, the frontend service should only communicate with the API gateway, and the API gateway should only communicate with specific backend services. Which Kubernetes networking construct should be implemented to enforce these communication policies?Implement platform protection
  9. 59.A security architect is designing the network topology for a highly sensitive application hosted in Azure. The application's backend database, an Azure SQL Database, must not be accessible via the public internet, even from within the Azure VNet where the application servers reside. All traffic to the database must traverse a private endpoint within the VNet. Which Azure networking feature should the architect implement?Implement platform protection
  10. 60.A company is hosting a critical web application in Azure App Service. This application needs to retrieve database connection strings, API keys, and other sensitive configuration values at runtime. The security team insists that these secrets must be stored securely, centrally, and be accessible only by the application, without being hardcoded or exposed in configuration files. Which Azure service is the most appropriate for managing these application secrets?Implement platform protection
  11. 61.A global company uses Azure Front Door to route traffic to its web applications deployed in various Azure regions. They need to restrict access to their web applications based on the geographic location of the client, allowing only users from specific countries to access the services. Which Azure Front Door feature should be configured to achieve this geo-filtering requirement?Implement platform protection
  12. 62.An organization is deploying containerized applications to Azure Container Registry (ACR). Before deploying any container image to production, they need to ensure that the images are free of known vulnerabilities. The security team requires automated scanning of all new and existing images in ACR for security flaws and wants to receive alerts for critical vulnerabilities. Which Azure service should be integrated with ACR to meet this requirement?Implement platform protection
  13. 63.An organization is deploying a highly critical web application in Azure that requires protection against common web-based attacks such as SQL injection, cross-site scripting, and other OWASP Top 10 vulnerabilities. The application is hosted on Azure App Service, and traffic needs to be load-balanced and routed securely. Which Azure service should be implemented to provide this specific layer 7 protection?Implement platform protection
  14. 64.A company is deploying a new web application to Azure App Service. The application needs to securely store connection strings, API keys, and other sensitive configuration data. The security team mandates that these secrets must be centrally managed, encrypted at rest, and accessible only by authorized Azure services. Which Azure service should be used to meet these requirements?Implement platform protection
  15. 65.A development team is deploying a new microservices application using Azure Kubernetes Service (AKS). They need to ensure that traffic between different microservices within the AKS cluster is restricted based on specific rules, allowing only authorized communication paths. Which Kubernetes resource should they use to define these communication restrictions?Implement platform protection
  16. 66.A company is hosting several critical applications in Azure Virtual Networks (VNets). They need to implement a centralized network security solution that can filter traffic between VNets, to the internet, and on-premises, using stateful inspection and threat intelligence. This solution must also support Source Network Address Translation (SNAT) and Destination Network Address Translation (DNAT). Which Azure service should they deploy?Implement platform protection
  17. 67.A company is deploying a new web application that uses Azure Front Door as a global load balancer and Web Application Firewall (WAF). To comply with regional data residency laws and prevent access from sanctioned countries, the security team needs to restrict access to the web application based on the geographical location of the client. Which specific WAF feature in Azure Front Door should be configured?Implement platform protection
  18. 68.A financial institution uses Azure Kubernetes Service (AKS) to host sensitive microservices. They need to ensure that container images deployed to AKS are scanned for vulnerabilities before they are run. If critical vulnerabilities are found, the deployment should be blocked. Which Microsoft Defender for Cloud capability should be integrated with their AKS clusters to achieve this?Implement platform protection
  19. 69.A company is using Azure Container Instances (ACI) to run several short-lived, batch processing jobs. These containers handle sensitive data and require isolation from other containers and the underlying host operating system. The security team wants to ensure that the containers are running in a highly isolated environment, preventing any potential side-channel attacks or compromise from other workloads on the same host. Which ACI feature provides the strongest isolation for these containers?Implement platform protection
  20. 70.A development team is using Azure DevOps to build and deploy containerized applications to Azure Kubernetes Service (AKS). They need to ensure that container images stored in their Azure Container Registry (ACR) are regularly scanned for vulnerabilities before deployment. Which Azure service should be integrated with ACR to provide continuous vulnerability assessment for container images?Implement platform protection
  21. 71.A global e-commerce company operates several web applications in Azure. They need to protect these applications from common web-based attacks such as SQL injection, cross-site scripting (XSS), and bot attacks. Additionally, they require centralized management of these protections with the ability to define custom rules and geo-filtering. Which Azure service should they implement?Implement platform protection
  22. 72.A company is hosting several critical applications in Azure Virtual Networks. They need to ensure that all inbound and outbound network traffic to and from these applications is inspected and filtered by a centralized, stateful firewall service. This firewall must also provide threat intelligence-based filtering and integrate seamlessly with Azure's networking ecosystem. Which Azure service is best suited for this requirement?Implement platform protection
  23. 73.A developer is creating a new Azure Function App that needs to securely store connection strings for a backend database and API keys for a third-party service. These secrets must not be hardcoded in the application's source code or configuration files. The solution must also support automatic rotation of these secrets. Which Azure service should the developer use?Implement platform protection
  24. 74.A company is using Azure Container Instances (ACI) to run several short-lived, batch processing jobs. These jobs handle highly sensitive data and require the strongest possible isolation from other containers running on the same underlying host, even from other containers within the same ACI resource group. Which isolation mode should be selected for these ACI containers to meet the stringent security requirement?Implement platform protection
  25. 75.A company is migrating an application that uses a custom-built certificate authority (CA) to sign internal certificates. They need to manage these certificates securely within Azure and integrate them with Azure-hosted applications without exposing the private keys. Which Azure service should be used to import and manage these custom CA-signed certificates?Implement platform protection
  26. 76.A company is deploying a new web application to Azure App Service. The application needs to securely store connection strings, API keys, and other sensitive configuration data. Developers should be able to retrieve these secrets programmatically without hardcoding them into the application code. Which Azure service should you recommend to meet these requirements?Implement platform protection
  27. 77.A security engineer is designing a secure network architecture for a multi-tier application in Azure. The application consists of a web tier, an application tier, and a database tier, each residing in its own subnet within an Azure Virtual Network. The requirement is to restrict network traffic flow between these subnets to only the necessary ports and protocols (e.g., web tier to app tier on port 8080, app tier to database tier on port 1433). Which Azure network security control should be implemented at the subnet level to enforce these granular traffic restrictions?Implement platform protection
  28. 78.A security engineer is tasked with securing an Azure Virtual Network (VNet) that hosts several critical backend services. These services should only be accessible from a specific set of Azure Virtual Machines (VMs) within the same VNet and from a highly restricted on-premises network. All other inbound and outbound traffic to these backend services must be blocked by default. Which Azure networking security feature provides the most granular control at the subnet or network interface level to enforce these traffic flow rules?Implement platform protection
  29. 79.A company is migrating an application that uses a custom-built certificate authority (CA) for issuing SSL/TLS certificates to its internal services. They want to integrate this existing CA with Azure to provision and manage certificates for Azure resources, such as Azure Application Gateways and Azure Front Door, while maintaining control over the private keys. Which Azure Key Vault feature enables this integration?Implement platform protection
  30. 80.A security engineer is configuring a highly secure Azure Virtual Network (VNet) for a government client. The client stipulates that all outbound internet access from any subnet within this VNet must be explicitly filtered and logged, and only approved FQDNs (Fully Qualified Domain Names) and service tags should be allowed. Additionally, they need Intrusion Detection and Prevention System (IDPS) capabilities for deep packet inspection. Which Azure service is designed to provide these advanced network security features?Implement platform protection
  31. 81.A financial institution is migrating its on-premises virtual machines (VMs) to Azure. They need to ensure that these VMs are continuously monitored for security vulnerabilities, misconfigurations, and threats, and receive recommendations for remediation. Which Azure service should be deployed to achieve this comprehensive security posture management for their Azure VMs?Implement platform protection
  32. 82.A global company uses Azure Front Door to route traffic to its web applications deployed in multiple Azure regions. The security team needs to ensure that only traffic originating from specific countries is allowed to reach the application, while traffic from all other countries is blocked at the edge. Which Azure Front Door security feature should be configured to achieve this geographical filtering?Implement platform protection
  33. 83.A company is migrating several legacy applications to Azure Virtual Machines (VMs). These applications run on Windows Server and require specific security configurations and monitoring for compliance. The security team wants to ensure that all VMs automatically receive endpoint protection, vulnerability assessments, and just-in-time (JIT) VM access. Which Azure service should be used to achieve this comprehensive host security for the VMs?Implement platform protection
  34. 84.A security engineer is designing a secure network architecture for a multi-tier application deployed in an Azure Virtual Network. The application consists of a web tier, an application tier, and a database tier, each residing in its own subnet. The requirement is to restrict traffic flow between these subnets, allowing only necessary communication (e.g., web server to app server, app server to database). Which Azure networking resource should be used to enforce these granular subnet-level traffic filtering rules?Implement platform protection
  35. 85.A development team is deploying several containerized microservices to Azure Container Instances (ACI). These microservices process highly sensitive data and require the strongest possible isolation from other containers and the underlying host operating system. Standard shared-kernel isolation is deemed insufficient. Which specific isolation mode for ACI should the team choose to meet this stringent security requirement?Implement platform protection
  36. 86.A security engineer is tasked with ensuring that all newly provisioned Azure Virtual Machines (VMs) in a specific subscription automatically have Microsoft Defender for Cloud enabled and configured for server protection. This must be enforced consistently across all new VM deployments without manual intervention. Which Azure service should the engineer use to implement this automated enforcement?Implement platform protection
  37. 87.A company is deploying a new set of Azure Virtual Machines that will host critical business applications. These VMs will store sensitive customer data on their data disks. The company's compliance policy mandates that all data at rest, including OS and data disks, must be encrypted using customer-managed keys (CMK) stored in Azure Key Vault. Which Azure encryption solution should be implemented to meet this requirement?Implement platform protection
  38. 88.A company is deploying a new web application to Azure App Service. The application needs to perform outbound network calls to an on-premises database through an Azure Virtual Network (VNet) gateway. To ensure that these outbound calls originate from a static, known IP address for firewall whitelisting on-premises, which Azure networking feature should be implemented?Implement platform protection
  39. 89.A financial institution is migrating its on-premises virtual machines (VMs) to Azure. The security policy requires that all VMs must be protected against malicious software, unauthorized system changes, and unpatched vulnerabilities. Additionally, the institution needs to ensure that only approved software is allowed to run on these VMs. Which Azure security service should be configured on the VMs to address these requirements comprehensively?Implement platform protection
  40. 90.A client organization uses Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure AD. They need to ensure that user password changes made on-premises are immediately effective for cloud applications without requiring additional synchronization cycles or agents. Which authentication method should be configured in Azure AD Connect to achieve this requirement?Manage identity and access
  41. 91.An organization is deploying a new web application in Azure that needs to authenticate employees using their existing Azure AD identities. The application developers want to implement a secure and standardized authentication protocol that supports single sign-on (SSO) and can also acquire access tokens for calling other Azure AD-protected APIs (e.g., Microsoft Graph). Which modern authentication protocol is most suitable for this scenario?Manage identity and access
  42. 92.A company is migrating its on-premises Active Directory to Azure Active Directory (Azure AD). They need to ensure that all user accounts and their associated attributes are synchronized securely and efficiently to Azure AD. The solution must support password hash synchronization and single sign-on for cloud applications. Which Azure AD tool should be used for this synchronization?Manage identity and access
  43. 93.A financial services company is concerned about unauthorized access to highly sensitive data by administrators. They want to implement a solution that grants administrators just-in-time (JIT) access to specific Azure resources and requires approval for these elevated privileges. The solution should also provide auditing and review capabilities for all privilege activations. Which Azure AD feature should be implemented?Manage identity and access
  44. 94.A company is developing a new customer-facing application that requires users to sign up and sign in using their social media accounts (e.g., Google, Facebook) or by creating a local account within the application's identity system. The company needs a scalable and secure identity solution that integrates seamlessly with Azure and allows for customization of the user experience. Which Azure AD service should they use?Manage identity and access
  45. 95.A company is implementing a new policy where all users must re-authenticate every 8 hours, even if their session is still active, to access highly sensitive applications. This policy needs to apply regardless of the user's location or device. Which Azure AD feature, when configured with a specific setting, can enforce this re-authentication frequency?Manage identity and access
  46. 96.A large organization uses Azure AD to manage its identities. They have a policy that all users must use Multi-Factor Authentication (MFA) for cloud application access, but they want to allow exceptions for known, trusted network locations (e.g., corporate offices) to improve user experience. Which Azure AD feature provides the capability to define and enforce this policy?Manage identity and access
  47. 97.A global organization uses Azure AD for its workforce identities. They have several departments, each with its own IT administrators responsible for managing user accounts and groups within their department. The central IT team wants to delegate these administrative tasks without granting global administrator privileges or custom roles that span the entire directory. They need a solution that allows departmental IT admins to manage users and groups only within their specific department's scope. Which Azure AD feature should be used?Manage identity and access
  48. 98.A company is implementing a new line-of-business application that will be hosted in Azure. This application needs to access data stored in an Azure Storage Account. To enhance security, the company wants to avoid storing credentials within the application's code or configuration files. This solution should also allow for automated credential rotation and simplified management. Which Azure AD feature should be implemented to securely manage the application's access to the storage account?Manage identity and access
  49. 99.A client is configuring Azure AD for a new enterprise application. This application requires a service principal to interact with Azure resources on its behalf. The security team insists that the service principal should have the minimum necessary permissions and that these permissions should be reviewed regularly. Which method ensures the principle of least privilege and supports regular access reviews for the service principal's permissions?Manage identity and access
  50. 100.A large organization uses Azure AD and has delegated the management of user accounts to several department-level administrators. They want to ensure that these department administrators, when performing sensitive actions like resetting passwords for their users, are always prompted for multi-factor authentication (MFA), even if their regular sign-in session did not require it. Which Conditional Access feature should be used?Manage identity and access