Microsoft Certified: Azure Security Engineer Associate practice questions
209 free questions with answers and explanations.
- 201.A healthcare organization stores patient records in an Azure Storage account. To meet strict regulatory compliance requirements, all stored data must be immutable for a specific duration, preventing any modification or deletion, even by administrators. After this duration, the data can be modified or deleted. Which Azure Storage feature should be configured?Secure data and applications
- 202.A startup is deploying a multi-tier application to Azure Kubernetes Service (AKS). The application consists of a web frontend, an API backend, and a database service, all running as separate pods. The security team requires that the web frontend can only communicate with the API backend, and the API backend can only communicate with the database service. No direct communication should be allowed between the web frontend and the database service, or between pods within the same tier (e.g., frontend-to-frontend). Which AKS security feature should be configured to enforce these communication restrictions?Secure data and applications
- 203.A global e-commerce company uses Azure App Service to host its regional web applications. The company mandates that all outbound traffic from these web applications to backend services (e.g., databases, other APIs) must be filtered and secured using network security groups (NSGs). The App Service instances are not integrated with a Virtual Network (VNet). Which App Service feature must be configured to meet this requirement?Secure data and applications
- 204.A financial institution is migrating its legacy database to Azure SQL Database. Due to strict compliance policies, all connections to the database must exclusively use Azure Active Directory (AAD) authentication, and local SQL authentication (username/password) must be completely disabled. How can this be enforced for the Azure SQL Database server?Secure data and applications
- 205.A large enterprise uses Azure Kubernetes Service (AKS) to host mission-critical applications. The security team mandates that all outbound traffic from the AKS cluster to external endpoints (e.g., external APIs, SaaS services) must be centrally inspected and filtered by a stateful firewall. This firewall should also integrate with threat intelligence feeds. Which Azure networking service should be deployed for this purpose?Secure data and applications
- 206.A global manufacturing company uses Azure Synapse Analytics dedicated SQL pools for large-scale data warehousing. Due to strict industry regulations, all connections to the Synapse SQL pools must enforce Transport Layer Security (TLS) 1.2 or higher. How can you ensure this requirement is met for all client connections?Secure data and applications
- 207.A financial services company is deploying a new web application to Azure App Service that will process sensitive customer data. The application needs to connect securely to an Azure SQL Database. The security team mandates that all traffic between the App Service and the SQL Database must remain within the Azure backbone network and not traverse the public internet. Additionally, they require that the SQL Database is not publicly accessible. Which security feature should you configure for the Azure SQL Database to meet these requirements?Secure data and applications
- 208.A global media company uses Azure Blob Storage to store large volumes of video assets. They require that encryption for these assets uses a customer-managed key (CMK) stored in Azure Key Vault. Furthermore, the company mandates that the CMK should automatically rotate without requiring manual intervention or downtime for the storage account. Which configuration combination ensures these requirements are met?Secure data and applications
- 209.A security operations center (SOC) analyst is investigating a series of suspicious activities reported across several Azure subscriptions. The analyst needs to quickly identify all administrative actions performed by a specific user account across these subscriptions within the last 24 hours. Which Azure service should the analyst primarily use to achieve this efficiently?Manage security operations