Microsoft Azure Fundamentals (AZ-900) practice questions
243 free questions with answers and explanations.
- 51.A global manufacturing company uses Azure IoT Hub to collect telemetry data from thousands of devices. They need to analyze this streaming data in real-time to detect anomalies and trigger alerts for potential equipment failures on the factory floor. Which Azure service is best suited for real-time analytics of streaming data?Describe Azure management and governance
- 52.A global enterprise needs to ensure that all virtual machines deployed in Azure have disk encryption enabled by default to comply with internal security policies. They want to prevent the creation of any new VM that does not meet this encryption requirement. Which Azure feature should they use?Describe Azure management and governance
- 53.A small non-profit organization uses Azure to host its website and a few backend services. They have a limited IT budget and want to ensure they are not overspending on resources. Which Azure tool should they use to get personalized recommendations for optimizing costs and performance?Describe Azure management and governance
- 54.A software development company uses Azure DevOps for its CI/CD pipelines. They want to ensure that all resources deployed through these pipelines, such as virtual machines and storage accounts, are tagged consistently with department, project, and environment information. This tagging is crucial for cost allocation and resource management. Which Azure governance feature can help them achieve this consistent tagging enforcement?Describe Azure management and governance
- 55.A company is developing a new application that will process highly sensitive personal identifiable information (PII). They are concerned about potential data breaches and need to ensure that their Azure SQL Database instances are configured with the highest level of security, including vulnerability assessments and advanced threat protection. Which Azure feature should they enable for their SQL Databases?Describe Azure management and governance
- 56.A global company is planning to deploy a new mission-critical application on Azure. They need to collect and analyze telemetry data from all application components, including VMs, databases, and web apps, to monitor performance, identify potential issues, and troubleshoot errors. They require a unified platform for metrics, logs, and traces. Which Azure service is best suited for this comprehensive monitoring requirement?Describe Azure management and governance
- 57.A financial services company needs to monitor its Azure environment for security threats and abnormal behaviors across all its subscriptions and connected on-premises infrastructure. They require a centralized platform for security information and event management (SIEM) that can collect data from various sources, detect threats using AI, and automate responses. Which Azure service meets these requirements?Describe Azure management and governance
- 58.A financial services company needs to monitor its Azure environment for security threats and respond automatically to detected incidents. They require a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that integrates with various Azure services and third-party security tools. Which Azure service should they use?Describe Azure management and governance
- 59.A media company uses Azure Blob Storage to store large video files. They want to prevent accidental deletion or modification of these critical files, especially by administrators who might have broad access permissions. Which Azure governance feature should they use to protect these storage accounts from unintended changes, even by users with owner roles?Describe Azure management and governance
- 60.A large enterprise has hundreds of Azure subscriptions across various departments. They need a way to efficiently manage access, enforce policies, and ensure compliance across all these subscriptions, treating them as a single, unified hierarchy. Which Azure governance feature is designed for this overarching management structure?Describe Azure management and governance
- 61.A global consulting firm uses Azure to host various client projects. They need to ensure that resources deployed within specific subscriptions adhere to a set of predefined security and compliance standards, automatically remediating any non-compliant resources. Which Azure governance feature should they use?Describe Azure management and governance
- 62.A healthcare organization is migrating patient records to Azure. They must adhere to strict regulatory compliance standards like HIPAA and GDPR, which require comprehensive reporting on data access, retention, and processing. They need a tool that can help them assess their current compliance posture against these complex regulations and provide a measurable score and actionable recommendations. Which service should they utilize?Describe Azure management and governance
- 63.A company is implementing a new security policy that requires all data at rest in Azure Storage accounts to be encrypted using customer-managed keys (CMK) from Azure Key Vault. They need to ensure this policy is consistently applied to all new and existing storage accounts. Which Azure feature helps enforce this specific encryption standard?Describe Azure management and governance
- 64.A company is deploying a new application to Azure that requires specific network configurations, including virtual networks, subnets, and network security groups. They want to ensure that these configurations are consistently applied across all development, testing, and production environments. Which Azure governance feature should they use to define and enforce these network settings as reusable templates?Describe Azure management and governance
- 65.A global e-commerce company uses Azure to host its customer-facing applications. Due to the sensitive nature of customer payment information, they must adhere to PCI DSS (Payment Card Industry Data Security Standard). They need to demonstrate compliance to auditors. Which Azure feature provides a dashboard-like view of their current compliance posture against various regulatory standards, including PCI DSS, and offers actionable recommendations?Describe Azure management and governance
- 66.A development team is deploying a new application that processes sensitive customer data. They need to ensure that the data is protected against potential loss due to accidental deletion, corruption, or cyberattacks. The solution must allow for point-in-time recovery and long-term retention of data. Which Azure data protection service should they utilize?Describe Azure management and governance
- 67.A global e-commerce company uses Azure to host its customer-facing applications. Due to the sensitive nature of customer data and various international regulations, they need a centralized way to manage and report on their compliance posture across all Azure services. Which Azure service is designed to help with this requirement?Describe Azure management and governance
- 68.An e-commerce company is experiencing a significant increase in malicious login attempts and potential data exfiltration from their Azure Blob Storage accounts. They need a security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution that can collect security data from across their Azure environment, detect advanced threats using AI, and automate responses to security incidents. Which Azure service should they implement?Describe Azure management and governance
- 69.A software development company is using Azure DevOps for their CI/CD pipelines. They want to ensure that all deployed Azure resources automatically adhere to internal security standards, such as requiring all storage accounts to enforce HTTPS-only access and all virtual machines to be deployed with specific antivirus extensions. Which Azure governance feature allows them to define and enforce these rules at scale?Describe Azure management and governance
- 70.A global manufacturing company uses Azure to host its IoT solutions, which collect vast amounts of telemetry data from factory sensors. They need a centralized logging solution to collect, store, and analyze all operational logs and metrics from their IoT devices, Azure services, and custom applications for monitoring, troubleshooting, and auditing purposes. Which Azure service is best suited for this comprehensive log management?Describe Azure management and governance
- 71.A development team is deploying a new application that processes sensitive customer data. They need to ensure that the data at rest in Azure Storage accounts is always encrypted using customer-managed keys (CMK) for enhanced control. Which Azure feature allows them to mandate this requirement across all relevant storage accounts?Describe Azure management and governance
- 72.A pharmaceutical company is storing highly sensitive patient data in Azure Blob Storage. They need to ensure that this data remains immutable for a legally mandated period of seven years, meaning it cannot be altered or deleted, even by administrators. Which Azure storage feature should they configure?Describe Azure management and governance
- 73.A global consulting firm uses Azure to host various client projects. They need to ensure that all virtual machines deployed for client projects automatically have a specific set of tags (e.g., ClientName, ProjectID, CostCenter) applied at creation time to facilitate accurate cost allocation and reporting. Which Azure governance feature should they use to enforce this tagging policy?Describe Azure management and governance
- 74.A global company needs to monitor its Azure environment for security threats, collect security events from various sources (Azure, on-premises, and other clouds), and automate responses to common security incidents. They are looking for a unified security operations platform. Which Azure service is designed for this comprehensive SIEM and SOAR functionality?Describe Azure management and governance
- 75.An e-commerce company is experiencing a significant increase in malicious login attempts and potential data exfiltration from their Azure resources. They need a cloud-native Security Information and Event Management (SIEM) solution that can collect security data from various sources (Azure logs, Microsoft 365, on-premises firewalls), detect advanced threats using AI and machine learning, and automate responses to security incidents. Which Azure service is best suited for this advanced threat detection and automated response?Describe Azure management and governance
- 76.A small non-profit organization uses Azure to host its website and a few backend services. They want to ensure that their Azure spending does not exceed a predefined monthly limit. Which Azure feature should they use to receive alerts when their spending approaches or exceeds this limit?Describe Azure management and governance
- 77.A global company uses multiple Azure subscriptions across different departments. They need to apply a consistent set of compliance policies, security baselines, and cost management rules across all subscriptions within a specific business unit. They want to avoid assigning these policies individually to each subscription. Which Azure governance feature should they use to group and manage these subscriptions effectively?Describe Azure management and governance
- 78.A global manufacturing company uses Azure to host its IoT solutions, which collect vast amounts of telemetry data from factory equipment. They need a centralized logging solution that can ingest, store, and analyze data from various Azure services and custom applications to monitor performance, diagnose issues, and ensure operational efficiency. Which Azure monitoring service should they use?Describe Azure management and governance
- 79.A development team is deploying a new application that processes highly sensitive personal identifiable information (PII). They need to ensure that all data stored in the Azure SQL Database for this application is encrypted at rest and that all access attempts are audited for compliance purposes. Which Azure database security features should they implement?Describe Azure management and governance
- 80.A global software company maintains highly confidential intellectual property in Azure Blob Storage. They require that all data, both at rest and in transit, is encrypted using strong encryption standards. They need to ensure that encryption is automatically applied and managed by Azure where possible, without requiring extensive manual configuration. Which Azure Storage encryption capabilities meet these requirements?Describe Azure management and governance
- 81.A healthcare organization is migrating patient records to Azure. They must adhere to strict compliance standards like HIPAA and GDPR. They need a centralized view of their compliance posture against these regulations and guidance on how to improve it. Which Microsoft Purview service specifically provides this capability?Describe Azure management and governance
- 82.A financial institution is implementing a strict data residency policy, requiring that all customer data must remain within a specific geographical boundary (e.g., Europe). They are planning to deploy new Azure services. Which core Azure concept must they prioritize when selecting where to deploy their resources to meet this requirement?Describe Azure management and governance
- 83.An e-commerce company is experiencing a significant increase in malicious login attempts and potential data exfiltration from their Azure Blob Storage accounts. They need a service that can provide real-time threat detection, anomaly behavior analysis, and automated responses across their cloud and on-premises resources. Which Azure service should they implement?Describe Azure management and governance
- 84.A global company uses Azure and needs to ensure that all data stored in Azure meets the requirements of GDPR (General Data Protection Regulation) for their European customers and HIPAA (Health Insurance Portability and Accountability Act) for their US healthcare data. Which Azure feature provides a centralized view of compliance offerings and helps assess compliance against these regulations?Describe Azure management and governance
- 85.A healthcare organization is migrating patient records to Azure. They must adhere to strict compliance standards such as HIPAA (Health Insurance Portability and Accountability Act) and GDPR (General Data Protection Regulation). They need a service to help them track their compliance posture, identify gaps, and provide actionable insights for improvement. Which Azure service is designed to help organizations meet these complex regulatory requirements?Describe Azure management and governance
- 86.A global manufacturing company uses Azure IoT Hub to collect telemetry data from thousands of devices. They need to analyze this data in real-time to detect anomalies and trigger alerts for potential equipment failures on the factory floor. Which Azure service is best suited for real-time stream processing and analytics?Describe Azure management and governance
- 87.A global enterprise uses Azure for various business units, each with its own subscription. They need to apply common governance policies, such as requiring specific tags on all resources and restricting resource deployments to certain regions, across all these subscriptions in an organized and hierarchical manner. Which Azure feature is best suited for this requirement?Describe Azure management and governance
- 88.A media company uses Azure Blob Storage to store large video files. They want to prevent accidental deletion or modification of critical production assets, even by users with high privileges. While they need to retain the ability to make planned changes, they want to ensure an extra layer of protection. Which Azure governance feature should they implement?Describe Azure management and governance
- 89.A small non-profit organization wants to implement a solution to automatically identify and tag all Azure resources that lack a 'Department' tag. This will help them track resource ownership and allocate costs more accurately. Which Azure governance feature should they use?Describe Azure management and governance
- 90.A company is reviewing its Azure spending and notices that several virtual machines (VMs) are consistently underutilized, leading to unnecessary costs. They want to receive proactive, actionable recommendations on how to optimize costs for these VMs and other Azure resources. Which Azure service is designed to provide personalized recommendations for cost optimization?Describe Azure management and governance
- 91.A financial services company needs to ensure that all sensitive customer data stored in Azure Blob Storage is protected against accidental deletion or modification for a period of seven years, even by administrators. Which Azure storage feature should they implement?Describe Azure management and governance
- 92.A company is planning to deploy several new applications to Azure. They need a way to ensure that all resources deployed by different teams adhere to a set of predefined corporate standards, such as resource tagging, allowed locations, and VM sizes. Which Azure governance feature should they use to enforce these standards?Describe Azure management and governance
- 93.A global company needs to ensure that all data stored in Azure meets the regulatory requirements of various international standards, such as GDPR and HIPAA. They require a centralized dashboard to track their compliance posture, receive recommendations for improvement, and generate compliance reports. Which Azure service provides these capabilities?Describe Azure management and governance
- 94.A global company needs to manage access to its Azure resources, ensuring that users only have the minimum necessary permissions to perform their job functions. They also want to periodically review and grant temporary elevated access for administrators when required. Which Azure identity and access management service should they use to achieve this?Describe Azure identity, security, and networking
- 95.A global organization is deploying an application across multiple Azure regions to ensure low latency for users worldwide. They need a service that can route user requests to the closest available endpoint based on geographic location. Which Azure service should they use?Describe Azure identity, security, and networking
- 96.An organization is deploying several web applications in Azure and wants to protect them from common web-based attacks such as SQL injection and cross-site scripting. They also need to ensure that traffic is load-balanced across their backend web servers. Which Azure service combines these functionalities?Describe Azure identity, security, and networking
- 97.A security team needs a centralized solution to collect, store, and correlate security logs and events from various sources across their Azure environment and on-premises infrastructure. They also require advanced threat detection, investigation, and automated response capabilities. Which Azure service is designed for this purpose?Describe Azure identity, security, and networking
- 98.A company is planning to deploy several applications to Azure. They need a service that can manage and secure access to these applications for both internal employees and external partners, ensuring single sign-on (SSO) capabilities. Which Azure identity service should they choose?Describe Azure identity, security, and networking
- 99.A company is implementing a hybrid cloud solution and needs to extend its on-premises Active Directory to Azure Active Directory (Azure AD) to synchronize user identities. This will allow users to use their existing on-premises credentials to access Azure resources. Which Azure AD tool should be used for this synchronization?Describe Azure identity, security, and networking
- 100.A company has several virtual machines (VMs) deployed in an Azure Virtual Network. They want to control inbound and outbound network traffic to these VMs based on IP addresses, ports, and protocols. Which Azure networking component should they use to achieve this granular control at the subnet or VM network interface level?Describe Azure identity, security, and networking