Microsoft Certified: Azure Security Engineer Associate practice questions

209 free questions with answers and explanations.

Practice test
  1. 101.A large enterprise is migrating several critical line-of-business applications to Azure. These applications historically relied on service accounts with embedded credentials for accessing other services and databases. The security team wants to eliminate hardcoded credentials and implement a more secure, automated authentication method for these applications when running on Azure Virtual Machines. Which Azure AD feature should be recommended?Manage identity and access
  2. 102.A company uses Azure AD for identity management and has several critical applications hosted in Azure. They want to ensure that if a user's account is compromised, the access token issued to that user for these critical applications is immediately revoked, rather than waiting for its normal expiration. Which security feature should be implemented?Manage identity and access
  3. 103.A company is developing a new multi-tenant SaaS application that needs to integrate with various customer Azure AD tenants for user authentication. The application will need to read basic user profiles and potentially update specific user attributes (e.g., phone number) in the customer's Azure AD. The development team wants to ensure that customers can easily grant the necessary permissions to the application without requiring a Global Administrator for every single tenant, while still maintaining control over the consented permissions. Which Azure AD feature facilitates this requirement?Manage identity and access
  4. 104.A global enterprise has a highly distributed IT team. They need to delegate administrative control over specific user groups and their associated applications to regional administrators, without granting them tenant-wide administrative privileges. For example, the European team should only manage European users and applications. Which Azure AD feature is best suited for this requirement?Manage identity and access
  5. 105.An organization is deploying a new web application in Azure that will display user-specific data from Microsoft Graph API. The application needs to authenticate users and then obtain an access token to call Microsoft Graph on behalf of the user. The application itself will handle user interaction and token storage securely. Which OAuth 2.0 grant flow is most appropriate for this scenario?Manage identity and access
  6. 106.A global software company maintains a complex Azure environment with numerous subscriptions, resource groups, and resources. They need to ensure that administrative access to specific resources, such as production SQL Databases and virtual networks, is restricted to only authorized personnel and that permissions are applied at the lowest possible scope to prevent excessive privileges. Which principle and corresponding Azure feature should be primarily used to enforce this security requirement?Manage identity and access
  7. 107.A client organization uses Azure AD and has a critical business application that processes highly sensitive customer data. They want to implement a security measure that ensures users accessing this application are not only authenticated but also that their sign-in session is continuously monitored for anomalous behavior. If any suspicious activity is detected during the session, access to the application should be immediately revoked. Which combination of Azure AD features should be implemented?Manage identity and access
  8. 108.A global enterprise is implementing a new policy for managing administrative access to Azure subscriptions. They want to ensure that 'Global Administrator' roles are never permanently assigned to any user. Instead, administrators should be able to request elevated privileges for a limited time and with justification. Which Azure AD feature should be configured to meet this requirement?Manage identity and access
  9. 109.A client is deploying a new web application in Azure that needs to authenticate employees using their existing Azure AD identities. The application will also need to securely obtain an access token to call an Azure API Management instance on behalf of the user. Which industry-standard protocol is best suited for this scenario, allowing the web application to securely delegate user consent for accessing the API?Manage identity and access
  10. 110.A global consulting firm uses Azure AD. They need to ensure that external contractors can access specific project-related resources in Azure AD, but their access must be automatically revoked after 90 days. The contractors do not have accounts in the firm's on-premises Active Directory. Which Azure AD feature should be used to manage this requirement?Manage identity and access
  11. 111.A client is integrating a custom-built Line-of-Business (LOB) application with Azure AD for single sign-on (SSO). The application expects user attributes like 'department' and 'employee ID' to be sent in the SAML token during the authentication process. Which part of the Azure AD application registration configuration needs to be modified to include these custom attributes in the SAML token?Manage identity and access
  12. 112.A global consulting firm uses Azure AD for its identity management. They have a requirement to allow certain external users, specifically contractors from partner organizations, to access specific internal applications. These contractors do not have Microsoft accounts or Azure AD accounts in their own organizations. You need to implement a solution that allows these contractors to authenticate using their existing Google identities to access the firm's Azure AD-integrated applications. Which Azure AD feature should you configure?Manage identity and access
  13. 113.A regulated financial institution uses Azure AD and has a strict requirement to ensure that all administrative access to Azure resources (subscriptions, resource groups) is logged, approved, and time-limited. They also need to ensure that administrators only have elevated privileges when absolutely necessary. Which combination of Azure AD features should be implemented?Manage identity and access
  14. 114.A client organization uses Azure AD Connect to synchronize user identities from its on-premises Active Directory to Azure AD. They are concerned about accidentally deleting a large number of user accounts from Azure AD if a misconfiguration or malicious activity occurs on the on-premises directory. They want a safeguard that prevents such bulk deletions from immediately propagating to Azure AD, providing a window to detect and remediate the issue. Which feature of Azure AD Connect should be configured?Manage identity and access
  15. 115.A company has implemented Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure AD. They want to ensure that if a local administrator accidentally deletes a large number of user accounts on-premises, these deletions do not immediately synchronize to Azure AD, potentially causing widespread data loss. What Azure AD Connect feature should be enabled to prevent this scenario?Manage identity and access
  16. 116.A company is implementing Azure AD Connect to synchronize user identities from its on-premises Active Directory to Azure AD. They need to ensure that password hash synchronization (PHS) is enabled and configured correctly for all synchronized users. Which of the following components is primarily responsible for transmitting the password hashes securely to Azure AD?Manage identity and access
  17. 117.A company is using Azure AD and wants to ensure that all user sign-ins are secure. They need to monitor and detect potential identity-based threats, such as impossible travel or sign-ins from unfamiliar locations. Additionally, they want to automatically respond to these risks by blocking or challenging suspicious sign-ins. Which Azure AD feature provides these capabilities?Manage identity and access
  18. 118.A company is integrating a new third-party SaaS application with Azure AD for single sign-on (SSO). The application requires specific user attributes (e.g., employee ID, department) to be sent as claims within the security token during the authentication process. Which part of the Azure AD application configuration allows an administrator to define and map these custom user attributes to claims for the SaaS application?Manage identity and access
  19. 119.A company is developing a new multi-tenant SaaS application that needs to authenticate users from various Azure AD tenants. The application must be able to securely access resources on behalf of the authenticated users, such as reading their profiles from their respective Azure AD tenants. Which authentication and authorization framework should the application use?Manage identity and access
  20. 120.A company is using Azure AD and wants to standardize their approach to giving applications permissions to access other Azure AD-protected resources (e.g., Microsoft Graph API, custom APIs). They need to ensure that these application permissions are centrally managed, auditable, and adhere to the principle of least privilege. Which type of identity should be used to represent these applications in Azure AD and manage their permissions?Manage identity and access
  21. 121.A company is utilizing Azure AD to manage user identities. They have a critical business application that needs to be accessible only by users who are part of a specific security group, and only from corporate-managed devices. Furthermore, access should be blocked if any sign-in risk is detected for the user. Which combination of Azure AD features should be configured to enforce these granular access controls?Manage identity and access
  22. 122.A manufacturing company uses Azure AD for its workforce identities. They have a specific requirement to enforce multi-factor authentication (MFA) for all users accessing applications tagged as 'High Sensitivity'. Additionally, if a user attempts to sign in from an unfamiliar location, they must be blocked entirely. Which two Azure AD features, when used together, can achieve these specific requirements?Manage identity and access
  23. 123.A company is developing a new customer-facing web application that needs to authenticate users using their social media accounts (e.g., Google, Facebook) or their existing email addresses. They want to integrate this authentication process seamlessly with Azure AD while also allowing for custom user attributes to be collected during sign-up. Which Azure AD service should they use?Manage identity and access
  24. 124.A company has several legacy on-premises web applications that use Integrated Windows Authentication (IWA) and are not directly accessible from outside the corporate network. They want to enable secure remote access to these applications for their employees without exposing the internal network directly to the internet or rewriting the applications. Which Azure AD service should be used?Manage identity and access
  25. 125.A company is implementing a new policy that requires all users to provide explicit consent before any third-party application can access their Azure AD data. They want to ensure that only administrators can grant consent for applications on behalf of all users. Which Azure AD setting should be configured to achieve this?Manage identity and access
  26. 126.A company is implementing a new policy that requires all users accessing sensitive applications to use multi-factor authentication (MFA) regardless of their location or device. They want to enforce this policy using Azure Active Directory. Which feature should they configure?Manage identity and access
  27. 127.A client organization uses Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure AD. They need to ensure that user password changes made on-premises are immediately effective for cloud applications without requiring additional synchronization cycles or agents. Which authentication method should be configured in Azure AD Connect to achieve this requirement?Manage identity and access
  28. 128.An organization is deploying a new web application in Azure that needs to authenticate employees using their existing Azure AD identities. The application developers want to implement a secure and standardized authentication protocol that supports single sign-on (SSO) and can also acquire access tokens for calling other Azure AD-protected APIs (e.g., Microsoft Graph). Which modern authentication protocol is most suitable for this scenario?Manage identity and access
  29. 129.A company is migrating its on-premises Active Directory to Azure Active Directory (Azure AD). They need to ensure that all user accounts and their associated attributes are synchronized securely and efficiently to Azure AD. The solution must support password hash synchronization and single sign-on for cloud applications. Which Azure AD tool should be used for this synchronization?Manage identity and access
  30. 130.A financial services company is concerned about unauthorized access to highly sensitive data by administrators. They want to implement a solution that grants administrators just-in-time (JIT) access to specific Azure resources and requires approval for these elevated privileges. The solution should also provide auditing and review capabilities for all privilege activations. Which Azure AD feature should be implemented?Manage identity and access
  31. 131.A company is developing a new customer-facing application that requires users to sign up and sign in using their social media accounts (e.g., Google, Facebook) or by creating a local account within the application's identity system. The company needs a scalable and secure identity solution that integrates seamlessly with Azure and allows for customization of the user experience. Which Azure AD service should they use?Manage identity and access
  32. 132.A company is implementing a new policy where all users must re-authenticate every 8 hours, even if their session is still active, to access highly sensitive applications. This policy needs to apply regardless of the user's location or device. Which Azure AD feature, when configured with a specific setting, can enforce this re-authentication frequency?Manage identity and access
  33. 133.A large organization uses Azure AD to manage its identities. They have a policy that all users must use Multi-Factor Authentication (MFA) for cloud application access, but they want to allow exceptions for known, trusted network locations (e.g., corporate offices) to improve user experience. Which Azure AD feature provides the capability to define and enforce this policy?Manage identity and access
  34. 134.A global organization uses Azure AD for its workforce identities. They have several departments, each with its own IT administrators responsible for managing user accounts and groups within their department. The central IT team wants to delegate these administrative tasks without granting global administrator privileges or custom roles that span the entire directory. They need a solution that allows departmental IT admins to manage users and groups only within their specific department's scope. Which Azure AD feature should be used?Manage identity and access
  35. 135.A company is implementing a new line-of-business application that will be hosted in Azure. This application needs to access data stored in an Azure Storage Account. To enhance security, the company wants to avoid storing credentials within the application's code or configuration files. This solution should also allow for automated credential rotation and simplified management. Which Azure AD feature should be implemented to securely manage the application's access to the storage account?Manage identity and access
  36. 136.A client is configuring Azure AD for a new enterprise application. This application requires a service principal to interact with Azure resources on its behalf. The security team insists that the service principal should have the minimum necessary permissions and that these permissions should be reviewed regularly. Which method ensures the principle of least privilege and supports regular access reviews for the service principal's permissions?Manage identity and access
  37. 137.A large organization uses Azure AD and has delegated the management of user accounts to several department-level administrators. They want to ensure that these department administrators, when performing sensitive actions like resetting passwords for their users, are always prompted for multi-factor authentication (MFA), even if their regular sign-in session did not require it. Which Conditional Access feature should be used?Manage identity and access
  38. 138.A large enterprise has a hybrid identity environment with Azure AD Connect synchronizing identities from on-premises Active Directory. They observe that some users are experiencing slow sign-in times when accessing cloud applications, and they want to improve the authentication experience by allowing users to sign in using the same password they use on-premises, without storing password hashes in Azure AD or deploying ADFS. Which authentication method should be configured?Manage identity and access
  39. 139.A global enterprise uses Azure AD for identity management. Due to regulatory compliance, all employees accessing sensitive applications must use a FIDO2 security key as their second factor of authentication. However, some legacy applications only support username/password. The security team needs to implement a solution that enforces FIDO2 for sensitive applications while allowing employees to use other MFA methods for legacy applications, all managed within Azure AD. Which Azure AD feature should be configured to achieve this granular control?Manage identity and access
  40. 140.A global manufacturing company uses Azure AD for identity management. Due to recent security audits, they need to implement a solution that prevents users from accessing sensitive applications from untrusted devices or locations. This solution must also enforce multi-factor authentication (MFA) when users attempt to access these applications from outside the corporate network. Which Azure AD feature is best suited to meet these requirements?Manage identity and access
  41. 141.A financial services company uses Azure AD and has deployed several mission-critical applications. They need to ensure that access to these applications is only granted from devices that are compliant with their security policies (e.g., up-to-date antivirus, encrypted hard drive). Which Azure AD feature should be used to enforce this device compliance requirement?Manage identity and access
  42. 142.A security auditor needs to review all administrative actions performed by users with the Global Administrator role in Azure AD. This review must include who performed the action, what action was taken, and when it occurred. Which Azure AD feature should the auditor use to retrieve this information?Manage identity and access
  43. 143.A client is developing a new serverless application in Azure that uses Azure Functions and needs to access data stored in Azure Storage Accounts. The security team wants to eliminate the use of connection strings and hardcoded credentials in the application code. They need a solution that allows the Azure Function to securely authenticate to the Azure Storage Account without managing any secrets. Which Azure AD feature should the client implement?Manage identity and access
  44. 144.A client is migrating several on-premises applications that use Integrated Windows Authentication (IWA) to Azure. These applications are critical and must remain accessible to users who are primarily working remotely. The client wants to avoid exposing their internal network directly to the internet. Which Azure AD feature can securely provide remote access to these on-premises IWA applications?Manage identity and access
  45. 145.A client organization wants to ensure that all user sign-ins to their Azure AD tenant are protected against replay attacks. They are particularly concerned about tokens being intercepted and reused. Which security feature directly addresses this concern by ensuring that each authentication request is unique and cannot be replayed?Manage identity and access
  46. 146.A software development company uses Azure AD to manage access for its developers. They want to ensure that developers can only access specific source code repositories from devices that are marked as 'compliant' by Microsoft Intune. If a device is non-compliant, access should be blocked. Which type of Conditional Access policy should be configured?Manage identity and access
  47. 147.A company is planning to implement a new security measure to protect its Azure AD tenant from advanced attacks like token replay and session hijacking. They want to ensure that access tokens issued by Azure AD are protected even if compromised, by limiting their validity and tying them more closely to the user's session context. Which advanced Azure AD security feature addresses this concern by enabling real-time revocation and re-evaluation of access?Manage identity and access
  48. 148.A security architect is designing an authentication solution for a new internal web application hosted on Azure App Service. The application needs to authenticate users from the company's Azure AD tenant. The architect wants to leverage Azure AD's built-in authentication capabilities for App Service to minimize development effort and ensure secure token validation. Which authentication provider should be configured directly within the Azure App Service Authentication / Authorization settings?Manage identity and access
  49. 149.A software development company is migrating an older, on-premises ASP.NET web application to Azure. This application uses Integrated Windows Authentication (IWA) and needs to remain accessible to users who are currently in the corporate network. The company wants to avoid re-writing the application's authentication logic. Which Azure AD feature should be used to enable secure remote access to this application?Manage identity and access
  50. 150.A startup is deploying its new web application to Azure App Service. The application is designed to be highly scalable and uses a serverless backend with Azure Functions. To minimize the attack surface and ensure that only trusted traffic can reach the App Service, the security team wants to restrict inbound access to the App Service to only specific IP addresses belonging to their corporate network and Azure Front Door. Which Azure App Service networking feature should be configured?Secure data and applications