Microsoft Certified: Identity and Access Administrator Associate practice questions
207 free questions with answers and explanations.
- 151.A company is implementing Azure AD Identity Protection. They want to ensure that all users who are detected with a 'High' sign-in risk are immediately blocked from accessing any resources. Additionally, users with a 'Medium' sign-in risk should be prompted to perform multi-factor authentication (MFA). They have configured two separate Conditional Access policies: one for 'High' sign-in risk (Block access) and another for 'Medium' sign-in risk (Require MFA). A user attempts to sign in, and this particular sign-in is simultaneously detected with both 'High' and 'Medium' sign-in risk. What will be the outcome of this sign-in attempt?Implement an identity management solution
- 152.A global manufacturing company has multiple Azure subscriptions, each managed by a different regional team. A central logging service, hosted in Subscription A, needs to collect logs from Azure resources across all other subscriptions (Subscription B, C, D, etc.). All regional teams want to maintain control over their subscriptions but need to grant the central logging service access. Which approach should be used to enable the central logging service to access resources in other subscriptions?Implement and manage workload identities
- 153.A company is implementing Azure AD Connect for the first time to synchronize identities from their on-premises Active Directory to Azure AD. They have a strict security policy requiring that no user passwords ever leave the on-premises environment in any form. Which authentication method should they choose during the Azure AD Connect configuration to meet this requirement?Implement an identity management solution
- 154.A company is migrating several of its applications to Azure. One critical legacy application is hosted on an Azure Virtual Machine (VM) and requires access to secrets stored in an Azure Key Vault. The security team insists that the application should not store any credentials or secrets directly in its code or configuration files. Which Azure AD feature should be used to grant the VM secure access to the Key Vault?Implement an identity management solution
- 155.A development team is building a new microservices application that will consist of multiple Azure Functions. Each Azure Function needs to access a specific Azure Storage account and an Azure Cosmos DB database. To ensure granular access control and simplify management, each Azure Function should have its own distinct identity. Which type of Managed Identity should you recommend?Implement and manage workload identities
- 156.A company is developing a serverless application using Azure Functions. The application needs to securely access resources in a different Azure subscription within the same Azure AD tenant. You want to implement a solution that allows the Azure Function to authenticate to these cross-subscription resources without hardcoding credentials and with minimal configuration. Which approach should you use?Implement and manage workload identities
- 157.An organization uses Azure AD for all user accounts. They want to implement a security policy that requires all users to register for multi-factor authentication (MFA) within 14 days of their account creation. If a user fails to register within this timeframe, they should be blocked from accessing resources until registration is complete. Which Azure AD Identity Protection policy should be configured to enforce this requirement?Implement an identity management solution
- 158.A company uses Azure AD for identity management. They have several guest users from partner organizations who regularly access specific SharePoint Online sites. The security team mandates that these guest users' access rights must be periodically reviewed and confirmed by the site owners. Which Azure AD feature should be used to automate this process?Implement an identity management solution
- 159.A company is onboarding a new application that will be hosted as an Azure App Service. This application needs to securely access Azure Key Vault to retrieve secrets (e.g., database connection strings) without requiring any hardcoded credentials in its configuration or code. The application itself will be the identity accessing Key Vault. Which type of managed identity should be configured for the Azure App Service?Implement an identity management solution
- 160.A company is implementing a new web application that needs to securely access Microsoft Graph API to retrieve user profiles. The application is hosted on an Azure App Service. The development team wants to avoid managing client secrets or certificates for authentication. The solution must ensure that the application's identity is automatically managed by Azure. Which type of identity should be assigned to the Azure App Service to meet these requirements?Implement an identity management solution
- 161.A company is implementing a new HR application that requires user provisioning and deprovisioning to be automated based on user lifecycle events in Azure AD. This application supports the System for Cross-domain Identity Management (SCIM) protocol. Which Azure AD feature should be configured to automatically create, update, and delete user accounts in the HR application?Implement an identity management solution
- 162.A company is redesigning its CI/CD pipeline. The pipeline runs on self-hosted GitHub Actions runners outside of Azure and needs to deploy resources to an Azure subscription. The security team wants to eliminate the use of long-lived secrets (like service principal client secrets) and ensure that GitHub Actions can authenticate to Azure securely and with minimal credential management. Which Azure AD feature should you implement?Implement and manage workload identities
- 163.A company uses Azure DevOps for its CI/CD pipelines. These pipelines need to frequently update Azure resource tags, which requires the 'Contributor' role on resource groups. To enhance security, the company wants to ensure that the service principal used by Azure DevOps only has elevated permissions during the brief period of deployment and automatically reverts to minimal permissions afterward. Which Azure AD feature, in conjunction with an Azure AD service principal, would best meet this requirement?Implement and manage workload identities
- 164.A company is integrating a new third-party Software-as-a-Service (SaaS) application into its environment. This SaaS application is listed in the Azure AD application gallery. The company wants to enable single sign-on (SSO) for its users to this application using their existing Azure AD credentials and ensure that user provisioning and deprovisioning are automated. Which type of Azure AD object should be created to represent this SaaS application within the company's Azure AD tenant?Implement and manage workload identities
- 165.A development team is building a new microservices application composed of several Azure Functions and Azure App Services. All these services need to access a shared Azure Key Vault to retrieve application secrets. The team wants a solution that allows them to manage a single identity for all these services, simplifying permissions management and ensuring consistent access control. Which type of managed identity should they use?Implement and manage workload identities
- 166.A company is migrating its legacy applications to Azure. One critical application, currently running on an on-premises server, uses a service account with a password for authentication to an LDAP directory. When migrating this application to an Azure Virtual Machine, the security team insists on eliminating hardcoded passwords and secrets. Additionally, the application needs to interact with other Azure services like Azure SQL Database and Azure Key Vault. Which Azure AD feature provides the most secure and manageable solution for this application's authentication needs?Implement and manage workload identities
- 167.A new web application is being developed that needs to authenticate users and access data from Microsoft Graph (e.g., read user profiles, send emails). The application is hosted on an Azure App Service. The development team wants to ensure that the application only requests the minimum necessary permissions from users and adheres to the principle of least privilege. What type of permissions should the application primarily request for user-driven actions?Implement and manage workload identities
- 168.A company uses a third-party CI/CD pipeline, hosted outside of Azure, to deploy applications to an Azure Kubernetes Service (AKS) cluster. The pipeline needs to authenticate to Azure AD to obtain tokens for deploying resources and managing the AKS cluster. The security team wants to eliminate the need for long-lived client secrets or certificates for this external pipeline. The solution should leverage modern authentication practices. Which Azure AD feature should be configured?Implement and manage workload identities
- 169.A large enterprise has enabled an Azure AD tenant-wide setting that requires administrator consent for all applications requesting certain high-privilege delegated permissions. A new line-of-business application developed in-house requires the 'User.ReadWrite.All' delegated permission to manage user profiles. A standard user attempts to sign into this application. What will happen?Implement and manage workload identities
- 170.A company has an Azure Function App that needs to access files in an Azure Storage Account. The security team wants to apply a granular access policy for the Function App, allowing it to only read blobs from a specific container within the Storage Account. They also want to avoid storing any credentials in the Function App code or configuration. How should you configure access for the Function App?Implement and manage workload identities
- 171.A development team is building a new microservices application that will consist of multiple Azure Function Apps, Azure Logic Apps, and Azure Web Apps. All of these services need to access a shared set of resources, including an Azure Key Vault and an Azure Storage Account. The security team requires a consistent identity across all these services for simplified management and access control. Which type of identity should be implemented?Implement and manage workload identities
- 172.A global FinTech company uses Azure Kubernetes Service (AKS) clusters across multiple regions. Each AKS cluster needs to access an Azure Key Vault to retrieve sensitive secrets like database connection strings and API keys. The security team requires a solution that allows consistent access control across all clusters and simplifies credential management, avoiding the need to manually distribute and rotate secrets to each cluster. Which type of workload identity should you recommend?Implement and manage workload identities
- 173.A global manufacturing company has multiple Azure subscriptions, each managed by a different department. A central automation script, running on an Azure Automation Account in Subscription A, needs to access and update resources (e.g., start/stop VMs) in Subscription B and Subscription C. The security team insists on using managed identities for authentication and wants to simplify the management of this identity across subscriptions. How should the identity for the automation account be configured?Implement and manage workload identities
- 174.A company is developing a new serverless application using Azure Functions. This application needs to access data stored in an Azure SQL Database. The security team has mandated that no connection strings or secrets should be stored directly in the Function App configuration or code. You need to recommend the most secure and efficient way for the Azure Function to authenticate to Azure SQL Database.Implement and manage workload identities
- 175.A software development company is building a multi-tenant SaaS application that will be consumed by various customer organizations, each with its own Azure Active Directory tenant. The application needs to access Microsoft Graph to read user profiles in the customer's tenant after a customer administrator grants consent. Which type of application registration is required for this scenario?Implement and manage workload identities
- 176.A financial institution is developing a highly sensitive internal application that will process confidential customer data. This application runs on an Azure Virtual Machine. The security policy mandates that the application must use a unique, non-sharable identity for authentication to Azure Key Vault to retrieve secrets, and this identity must be automatically removed when the VM is deleted. Which type of managed identity should be configured for this application?Implement and manage workload identities
- 177.A security team wants to enforce a policy that all certificates used by Azure AD application registrations for authentication must have a maximum validity period of one year. After this period, the certificates should automatically expire, forcing a rotation. Which Azure AD feature allows administrators to define and enforce such a policy for workload identities?Implement and manage workload identities
- 178.A company is developing a new serverless application using Azure Functions. This application needs to securely access data stored in an Azure SQL Database. The security team mandates that no secrets or connection strings should be hardcoded or stored in application settings. The solution must ensure that the function app can authenticate to the SQL Database without manual credential management. Which type of identity should be used?Implement and manage workload identities
- 179.A security auditor has identified that an Azure AD application registration used by a critical line-of-business application has a client secret configured to expire in 10 years. The company's security policy dictates that all application secrets must be rotated at least every 90 days. You need to enforce this policy for all future and existing application registrations that use client secrets.Implement and manage workload identities
- 180.A software development company is building a multi-tenant SaaS application that will be consumed by various customer organizations, each with their own Azure AD tenant. The application needs to authenticate users from these customer tenants and access basic user profile information (e.g., user's name, email). The company wants to ensure that the application can be easily onboarded by new customers without requiring manual configuration in each customer's tenant beyond user consent. Which type of application registration is required?Implement and manage workload identities
- 181.A global manufacturing company has multiple Azure subscriptions, each managed by a different regional team. A central IT team manages a set of shared Azure Key Vaults in a 'central' subscription that contain configuration secrets for applications deployed across all regional subscriptions. An Azure Function App in a 'Europe' subscription needs to access a secret in a Key Vault located in the 'central' subscription. Which workload identity solution allows the Function App to securely access the Key Vault without sharing credentials between subscriptions?Implement and manage workload identities
- 182.A company is developing a new cloud-native application that will be deployed across multiple Azure Kubernetes Service (AKS) clusters in different regions. Each AKS cluster needs to securely access Azure Key Vault to retrieve secrets. The security team requires a solution that minimizes credential management overhead and allows for consistent identity management across all clusters.Implement and manage workload identities
- 183.A company is integrating a new third-party Software-as-a-Service (SaaS) application into its Azure AD tenant. This application requires users to sign in using their Azure AD credentials. The company wants to ensure that all user access to this application is managed centrally through Azure AD, including single sign-on (SSO) and conditional access policies. Which Azure AD object type should be used to represent this third-party application in the tenant?Implement and manage workload identities
- 184.A development team is building a new web application that needs to access user-specific data in Microsoft Graph, such as calendar events and emails. The application will authenticate users directly. The security team requires that the application only accesses data on behalf of the signed-in user and never with its own identity. Which type of permission should the application request?Implement and manage workload identities
- 185.A company uses Azure DevOps for its CI/CD pipelines. These pipelines need to frequently update Azure resource configurations, including deploying new Azure Functions and modifying Azure Key Vault access policies. The security team wants to ensure that the CI/CD pipelines authenticate to Azure AD using a method that eliminates the need for manually managed secrets or certificates, and also allows for fine-grained, temporary elevation of privileges when performing sensitive operations.Implement and manage workload identities
- 186.A company is implementing a new internal web application that needs to authenticate users from its Azure Active Directory (Azure AD). The application development team requires a solution that minimizes credential management overhead for both users and administrators, and allows users to access the application seamlessly after logging into their Windows devices joined to Azure AD. Which authentication method should be recommended?Implement an authentication and access management solution
- 187.A global consulting firm uses Azure Active Directory (Azure AD) and has recently acquired a smaller company. The acquired company has its own on-premises Active Directory Domain Services (AD DS) and requires its users to authenticate against their existing AD DS for all applications, including those integrated with Azure AD. The acquired company's security policy prohibits synchronizing password hashes to the cloud. Which authentication method should be implemented to integrate the acquired company's users with Azure AD while respecting their security policy?Implement an authentication and access management solution
- 188.A company is implementing a new security policy that requires all users to register for multi-factor authentication (MFA) within 14 days of their account creation or first sign-in. If they fail to register within this period, they should be prompted to register until they complete the process. Which Azure AD Identity Protection policy should be configured to enforce this requirement efficiently?Implement an identity management solution
- 189.A financial institution uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for managing access to sensitive Azure resources. They have a custom Azure role, 'Financial Data Auditor', which requires an additional layer of verification upon activation. The policy states that users activating this role must securely confirm their identity using a certificate-based authentication method, in addition to their standard password. Which PIM setting, when configured for the 'Financial Data Auditor' role, would enforce this requirement?Implement access governance
- 190.A security administrator is investigating a series of suspicious sign-in attempts targeting several high-value accounts in Azure Active Directory (Azure AD). The attempts originate from unusual geographic locations and exhibit characteristics of credential stuffing attacks. The administrator needs to configure a policy that automatically blocks these suspicious sign-ins and alerts the security team. Which Azure AD feature provides the most effective solution for this scenario?Implement an authentication and access management solution
- 191.A global consulting firm uses Azure Active Directory (Azure AD) and has recently acquired a smaller company. The acquired company uses its own on-premises Active Directory Domain Services (AD DS) and requires its users to continue authenticating against their existing infrastructure while accessing cloud resources in the consulting firm's Azure AD tenant. The consulting firm wants to minimize the operational overhead for both organizations and avoid synchronizing user passwords to Azure AD. Which authentication method should be implemented to meet these requirements?Implement an authentication and access management solution
- 192.A software vendor is developing a new multi-tenant SaaS application that will be published to the Azure AD application gallery. The application needs to read basic user profiles (display name, email) from customer tenants' Azure AD. The vendor wants to ensure that customers can easily grant the necessary permissions without requiring a tenant administrator for every single customer. Which combination of permission type and consent model should the vendor implement?Implement an authentication and access management solution
- 193.A company is integrating a new custom-developed web application with Azure AD for single sign-on (SSO). The application requires specific user attributes, including an employee ID (which is stored as an extension attribute in Azure AD Connect) and the user's manager's email address, to be included in the ID token. Which Azure AD feature should be used to configure these additional attributes in the ID token?Implement an authentication and access management solution
- 194.A software development company uses Microsoft Entra ID and has implemented access reviews for several critical groups that grant access to source code repositories. The security team wants to ensure that these access reviews are conducted quarterly and that any users whose access is not explicitly approved by the reviewer are automatically removed from the group. Which two settings should be configured in the access review to meet these requirements?Implement access governance
- 195.A financial services company uses Microsoft Entra ID (formerly Azure Active Directory) and has implemented entitlement management. They have a new project requiring external auditors to access a specific SharePoint Online site and a custom line-of-business application. Access should be granted for exactly 90 days, and then automatically removed. Auditors from different firms will need access, but the company wants to streamline the invitation process while maintaining strict control over who can request access. Which type of connected organization should be configured to best meet these requirements?Implement access governance
- 196.A global conglomerate uses Microsoft Entra ID and has several business units, some of which operate as separate Microsoft Entra tenants. They want to implement entitlement management to allow users from these other internal Microsoft Entra tenants to request access to specific resources hosted in the main corporate tenant. The goal is to avoid manual guest invitations for each user and enable self-service access requests. Which entitlement management concept is most suitable for this scenario?Implement access governance
- 197.A development team is building a new multi-tenant SaaS application that needs to access user profiles and read calendar events from Microsoft Graph for users across various customer tenants. The application will primarily run as a background service without a signed-in user. Which type of permission and permission consent model should the application use?Implement an authentication and access management solution
- 198.A client is migrating an on-premises application to Azure. The application currently uses an on-premises SQL Server database and authenticates using Windows Integrated Authentication. The new architecture will host the application on an Azure App Service and the database on Azure SQL Database. The security team insists that the application should not store any credentials. How should the application authenticate to Azure SQL Database while adhering to the security team's requirement?Implement an authentication and access management solution
- 199.A healthcare provider uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure AD roles. They have a strict policy that all 'User Administrator' role activations must be reviewed by a specific security team. The review process should involve two distinct stages: an initial review by a Tier 1 Security Analyst, followed by a final approval from a Tier 2 Security Operations Lead. Both stages must be completed successfully before the role is activated. Which PIM setting should be configured to meet this multi-stage approval requirement?Implement access governance
- 200.A company policy mandates that all users accessing sensitive financial applications must re-authenticate every hour, regardless of their activity. This policy applies even if they are already signed in to other applications. Which Azure AD Conditional Access feature should be used to enforce this continuous re-authentication requirement?Implement an authentication and access management solution