Microsoft Certified: Azure Security Engineer Associate practice questions

209 free questions with answers and explanations.

Practice test
  1. 151.A healthcare organization stores patient records in an Azure Storage account. To meet strict HIPAA compliance requirements, they must ensure that once a blob is written, it cannot be modified or deleted for a period of seven years, even by administrators. This policy needs to apply to specific containers within the storage account. Which Azure Storage feature should be implemented?Secure data and applications
  2. 152.A software development company uses Azure App Service to host several RESTful APIs. These APIs need to securely access data from an Azure SQL Database. The security team mandates that the APIs should not store any credentials directly and should use a managed identity for authentication to the SQL Database. Which type of managed identity should be configured for the App Service?Secure data and applications
  3. 153.A software development company uses Azure App Service to host several RESTful APIs. These APIs need to securely access secrets (e.g., database connection strings, API keys) stored in Azure Key Vault. The company wants to implement the most secure and recommended method for App Service to authenticate to Key Vault without storing any credentials in the application code or configuration files. Which method should be used?Secure data and applications
  4. 154.A global logistics company uses Azure Synapse Analytics for real-time analytics on supply chain data. They require that all data processing within the Synapse Workspace occurs in a highly secure, isolated network environment that does not expose any data to the public internet. Furthermore, all outbound connections from the Synapse Spark and SQL pools must be routed through a private endpoint to other Azure services. Which network configuration should be implemented?Secure data and applications
  5. 155.A security architect is designing the network security for a highly sensitive Azure Storage account that stores critical financial data. The requirement is to ensure that the storage account is only accessible from a specific subnet within a corporate Azure Virtual Network, and absolutely no access should be permitted from the public internet, even if accidentally misconfigured. Which combination of security features provides the strongest network isolation for the storage account?Secure data and applications
  6. 156.A compliance officer needs to ensure that all Azure SQL Databases are configured to automatically identify and report potential database vulnerabilities, such as misconfigurations, excessive permissions, and unencrypted sensitive data. The solution must also provide actionable steps to remediate these findings. Which Azure security feature should be enabled on the SQL Databases?Secure data and applications
  7. 157.A global e-commerce company uses Azure App Service to host its regional web applications. Each application needs to access a separate Azure SQL Database instance. To minimize the attack surface and ensure that applications can only connect to their designated database, the security team wants to prevent the App Services from initiating connections to any other Azure SQL Database instances or public endpoints. The solution must utilize Managed Identities for authentication. Which security configuration should be applied to the App Services?Secure data and applications
  8. 158.A large enterprise uses Azure Kubernetes Service (AKS) to host mission-critical applications. The security team requires that all outbound traffic from the AKS cluster to the internet is filtered and audited according to corporate security policies. They also need to ensure that specific FQDNs are allowed or denied. Which Azure networking service should be deployed and configured for this purpose?Secure data and applications
  9. 159.A media company uses Azure Blob Storage to store large volumes of video assets. They require that all new blobs uploaded to a specific container are automatically encrypted using a customer-managed key (CMK) from Azure Key Vault. Additionally, they need to ensure that the encryption key used for these blobs is automatically rotated every 90 days without manual intervention. Which Azure Storage feature should be utilized?Secure data and applications
  10. 160.A data analytics team is using Azure Synapse Analytics dedicated SQL pools. They need to ensure that specific sensitive columns, such as 'SocialSecurityNumber' and 'CreditCardNumber', are always encrypted at the column level within the database, even when accessed by database administrators. The encryption and decryption process must be handled transparently by the client application using keys managed by the application owners. Which encryption technology should be used?Secure data and applications
  11. 161.A global e-commerce company uses Azure App Service to host its regional web applications. To enhance security and ensure that only authorized traffic from specific internal networks can reach the App Service, they need to restrict inbound access. The solution must allow for IP address-based filtering and VNet Service Endpoints. Which Azure App Service networking feature should be configured?Secure data and applications
  12. 162.A financial institution uses Azure SQL Database to store highly sensitive customer transaction data. Regulatory compliance requires that all data at rest and in transit be encrypted, and that cryptographic keys are managed by the customer. Additionally, the solution must support a mechanism for transparent key rotation without service interruption. Which encryption method and key management strategy should be implemented?Secure data and applications
  13. 163.An e-commerce company uses Azure Kubernetes Service (AKS) for a production workload. They require a security solution that can continuously monitor vulnerabilities in container images, detect runtime threats in running pods, and enforce security best practices across their AKS clusters. Which Azure security service should they implement?Secure data and applications
  14. 164.A healthcare organization is migrating a legacy on-premises application to Azure App Service. The application uses a custom domain name and requires HTTP Strict Transport Security (HSTS) to enforce secure communication with clients. Which of the following is the most efficient way to enable HSTS for the Azure App Service application?Secure data and applications
  15. 165.A global manufacturing company uses Azure Synapse Analytics dedicated SQL pools for large-scale data warehousing. They need to ensure that data in transit to and from the dedicated SQL pools is encrypted, even for client applications that might not explicitly enforce encryption. Which network security measure should be implemented to guarantee this encryption?Secure data and applications
  16. 166.A software development company uses Azure App Service to host several RESTful APIs. These APIs need to securely access data in an Azure SQL Database. To avoid hardcoding credentials and manage identities centrally, the company wants to use a managed identity for authentication between the App Service and the SQL Database. Which type of managed identity should be assigned to the Azure App Service?Secure data and applications
  17. 167.A media company uses Azure Blob Storage to store large volumes of video assets. They require that all new and existing blobs are encrypted using a customer-managed key (CMK) from Azure Key Vault. This CMK must be automatically rotated every 90 days to meet compliance requirements, and the encryption scope should apply to the entire storage account. Which configuration should you implement?Secure data and applications
  18. 168.A company is migrating its legacy applications to Azure App Service. These applications require client certificates for mutual TLS authentication to backend systems. The security team mandates that these client certificates must be securely stored, automatically renewed, and seamlessly presented by the App Service to the backend systems without requiring manual intervention from developers. Which Azure service combination should be used to manage and deploy these client certificates?Secure data and applications
  19. 169.A global e-commerce company uses Azure App Service to host its regional web applications. The company requires that all outbound traffic from these App Services to on-premises resources, which are connected via a VPN Gateway, must be routed through a specific Azure Virtual Network (VNet) and inspected by a Network Virtual Appliance (NVA) within that VNet. Which App Service networking feature, combined with appropriate VNet configuration, will ensure this outbound traffic flow?Secure data and applications
  20. 170.A global logistics company uses Azure Synapse Analytics for real-time analytics on supply chain data. To meet stringent data sovereignty requirements, they need to ensure that all data processing, including Spark pool computations, occurs exclusively within a specific Azure region and that data never leaves that region, even for management or monitoring traffic. What combination of Azure Synapse Analytics features should be used to achieve this strict data residency and network isolation for the Spark pools?Secure data and applications
  21. 171.A company is hosting a critical web application on Azure App Service. The application processes sensitive customer data, and the security team requires that all network traffic to and from the App Service be strictly isolated within the company's virtual network, preventing any exposure to the public internet. Furthermore, the App Service must be able to securely access resources within the virtual network without traversing public endpoints. Which Azure App Service networking feature should be configured?Secure data and applications
  22. 172.A financial services company uses Azure SQL Database to store highly sensitive customer transaction data. The company needs to enforce strict access controls, ensuring that database administrators (DBAs) can manage the database but cannot view the actual sensitive data in plain text, even if they have elevated permissions. Which Azure SQL Database security feature should be implemented to meet this requirement?Secure data and applications
  23. 173.A manufacturing company uses Azure Synapse Analytics dedicated SQL pools to store sensitive intellectual property data. The security team mandates that all data at rest within these SQL pools must be encrypted using a customer-managed key stored in Azure Key Vault. Furthermore, the solution must support automatic key rotation. Which encryption solution should the company implement?Secure data and applications
  24. 174.A financial services company is deploying a new web application to Azure App Service that will process sensitive customer data. The company requires that all network traffic to and from the App Service instance is routed exclusively through a private network, without exposure to the public internet. Which Azure networking feature should be implemented to meet this requirement?Secure data and applications
  25. 175.A global logistics company uses Azure Synapse Analytics for real-time analytics on supply chain data. To comply with data residency rules and minimize latency, they need to ensure that all network traffic between their Azure Synapse workspace and its associated storage accounts (Azure Data Lake Storage Gen2) remains entirely within the Microsoft Azure backbone network, without traversing the public internet. Which networking configuration should be implemented?Secure data and applications
  26. 176.A startup is deploying its new web application to Azure App Service. The application is designed to be highly scalable and uses a serverless backend with Azure Functions. To minimize the attack surface and ensure that only trusted traffic can reach the App Service, the security team wants to restrict inbound access to the App Service to only specific IP addresses belonging to their corporate network and Azure Front Door. Which Azure App Service networking feature should be configured?Secure data and applications
  27. 177.A financial services company is deploying a new web application to Azure App Service that will process sensitive customer financial data. The application must establish a private and secure connection to an Azure SQL Database, ensuring that traffic between the App Service and the SQL Database does not traverse the public internet. Which networking feature should be configured for the App Service?Secure data and applications
  28. 178.A development team is deploying a new containerized application to Azure Kubernetes Service (AKS). The application processes financial transactions and requires strict isolation between different microservices within the same cluster. Specifically, the payment processing microservice should only be able to communicate with the database microservice, and no other microservices or external endpoints. Which Kubernetes resource should be used to enforce these communication restrictions?Secure data and applications
  29. 179.A large enterprise uses Azure Kubernetes Service (AKS) to host mission-critical applications. To comply with corporate security policies, all outbound traffic from the AKS cluster must be inspected and filtered by a centralized firewall appliance. This includes traffic to both public internet endpoints and other Azure services. Which Azure networking service should be implemented to meet this requirement?Secure data and applications
  30. 180.A financial institution is migrating its legacy database to Azure SQL Database. Due to stringent regulatory requirements, all access to the database must be authenticated using Azure Active Directory (Azure AD) and enforce multi-factor authentication (MFA) for all users, including administrators. Which authentication method should be configured for the Azure SQL Database?Secure data and applications
  31. 181.A company is using Azure Kubernetes Service (AKS) for a production workload. They require a solution to analyze container images for known vulnerabilities before deployment, enforce security policies at runtime, and monitor for suspicious activities within the cluster. The solution must integrate seamlessly with AKS and provide a unified security management experience. Which Azure security service should be implemented?Secure data and applications
  32. 182.A security auditor needs to regularly assess the security posture and compliance of an Azure SQL Database. The assessment should automatically identify vulnerabilities, misconfigurations, and deviations from best practices, providing actionable recommendations. Which Azure security feature is designed for this purpose?Secure data and applications
  33. 183.A security auditor needs to regularly assess the security posture and compliance of an Azure SQL Database. The auditor requires automated recommendations for security improvements, vulnerability findings, and the ability to track compliance against industry benchmarks. Which Azure security service provides these capabilities for Azure SQL Database?Secure data and applications
  34. 184.A company uses Azure Kubernetes Service (AKS) to host several microservices. To comply with internal security policies, all network traffic between pods within the same namespace must be restricted to specific services, and traffic between different namespaces must be blocked by default. Which AKS networking feature should be implemented to enforce these rules?Secure data and applications
  35. 185.A manufacturing company uses Azure Storage accounts to store sensor data from IoT devices. They need to ensure that this data is immutable and cannot be modified or deleted for a period of seven years to comply with regulatory requirements. Which Azure Storage feature should be configured to meet this retention and immutability requirement?Secure data and applications
  36. 186.A development team is deploying a new web application to Azure App Service. The application needs to securely store connection strings, API keys, and other secrets. These secrets must be accessible by the App Service application but should not be hardcoded in the application's configuration files or source code. Which Azure service should be used to manage and provide secure access to these secrets?Secure data and applications
  37. 187.A development team is deploying a new containerized application to Azure Kubernetes Service (AKS). The application consists of several microservices, and each microservice needs to communicate only with specific other microservices and the database. The security team wants to enforce these communication restrictions at the network layer within the AKS cluster. Which AKS security feature should be used?Secure data and applications
  38. 188.A media company uses Azure Blob Storage to store large volumes of video assets. They need to ensure that all data written to the storage account is encrypted using a customer-managed key (CMK) from Azure Key Vault. This key must be rotated annually. Which configuration should be implemented for the Azure Storage account?Secure data and applications
  39. 189.An e-commerce company uses Azure Kubernetes Service (AKS) to host its containerized microservices. They want to ensure that all container images deployed to AKS are scanned for vulnerabilities before being allowed to run. If critical vulnerabilities are found, the deployment should be blocked automatically. Which Azure security service should be integrated with AKS to achieve this?Secure data and applications
  40. 190.A software company is developing a new serverless application using Azure Functions. The application needs to securely retrieve secrets (e.g., API keys, database connection strings) from a centralized, highly secure repository. These secrets must be accessible to the Function App at runtime without being hardcoded or stored in configuration files. Which Azure service should be used to store and manage these secrets?Secure data and applications
  41. 191.A security auditor needs to regularly assess the security posture of an Azure Storage account, including identifying misconfigurations, missing security updates, and potential vulnerabilities. The auditor requires a centralized solution that provides actionable recommendations. Which Azure security service should be configured for the storage account?Secure data and applications
  42. 192.A startup is deploying a multi-tier application to Azure Kubernetes Service (AKS). The application consists of a front-end web service and a back-end API service, each running in separate namespaces. The security team requires that the front-end service can only communicate with the back-end service, and the back-end service cannot initiate outbound connections to the internet. Which Kubernetes security construct should be used to enforce these communication restrictions?Secure data and applications
  43. 193.A global manufacturing company uses Azure Synapse Analytics dedicated SQL pools for large-scale data warehousing. They need to ensure that all client connections to the dedicated SQL pools are secured using Transport Layer Security (TLS) with a minimum version of 1.2. This must be enforced at the server level. Which setting should be configured?Secure data and applications
  44. 194.A development team is deploying a new containerized application to Azure Kubernetes Service (AKS). The application consists of a web frontend, an API backend, and a database service, each running in separate pods. To enhance security, they need to restrict communication between these pods based on their roles, ensuring that only the web frontend can communicate with the API backend, and only the API backend can communicate with the database service. Which Kubernetes resource should be implemented?Secure data and applications
  45. 195.A healthcare organization stores patient records in an Azure Storage account. To meet HIPAA compliance requirements, all access to the storage account must be logged, and these logs must be immutable for auditing purposes. Additionally, the organization needs to detect any unusual access patterns or potential data exfiltration attempts. Which Azure Storage security features should be implemented?Secure data and applications
  46. 196.A financial institution is migrating its on-premises data warehouse to Azure Synapse Analytics. Due to strict regulatory compliance requirements, all data in Azure Synapse Analytics must be encrypted using customer-managed keys (CMK) stored in Azure Key Vault. The solution must ensure that encryption keys never leave the FIPS 140-2 Level 2 validated hardware security modules (HSMs). Which specific encryption configuration must be implemented for Azure Synapse Analytics?Secure data and applications
  47. 197.A healthcare organization stores patient records in an Azure Storage account. To meet strict compliance regulations, they must ensure that all data written to a specific container is immutable for a period of 7 years, preventing any deletion or modification during this time. Which Azure Storage feature should be configured?Secure data and applications
  48. 198.A software company is developing a new serverless application using Azure Functions. The application needs to securely store connection strings, API keys, and other sensitive configuration data. These secrets must be accessible by the Azure Function, but should not be stored directly in the application code or configuration files. Additionally, the solution must support secret rotation without redeploying the function. Which Azure service should be used to manage these secrets?Secure data and applications
  49. 199.A compliance officer needs to ensure that all Azure SQL Databases in their subscription are configured to automatically identify and report potential security vulnerabilities and misconfigurations. The solution must provide actionable recommendations and integrate with a centralized security posture management platform. Which Azure Defender for Cloud capability should be enabled for Azure SQL Databases?Secure data and applications
  50. 200.A software development company uses Azure App Service to host several RESTful APIs. These APIs need to securely access data stored in an Azure Storage Account. The company wants to avoid hard-coding credentials or managing secrets directly in the application code. They also require that the identity used to access the storage account is automatically managed by Azure. Which authentication mechanism should be implemented?Secure data and applications