Q: 11
In a hybrid identity model, what can you use to sync identities between Active Directory Domain
Services (AD DS) and Azure Active Directory (Azure AD)?
Options
Discussion
A
Be respectful. No spam.
Q: 12
What feature in Microsoft Defender for Endpoint provides the first line of defense against
cyberthreats by reducing the attack surface?
Options
Discussion
Option D is right here since network protection is actually part of attack surface reduction. Automated remediation and hunting kick in later, not as first defense. Ran into a similar question in some practice sets. Anybody see a scenario where this flips?
Be respectful. No spam.
Q: 13
What can you use to provide threat detection for Azure SQL Managed Instance?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
What is a characteristic of a sensitivity label in Microsoft 365?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
What can you use to ensure that all the users in a specific group must use multi-factor authentication
(MFA) to sign in to Azure AD?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
Which three authentication methods can be used by Azure Multi-Factor Authentication (MFA)? Each
correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
Options
Discussion
It’s A, B, and D. Azure MFA supports phone calls, SMS messages, and the Microsoft Authenticator app for the second factor, but not email or security questions. Saw a similar question on some practice tests. I think these are the only three listed as valid methods per Microsoft docs. Anyone disagree?
Be respectful. No spam.
Q: 17
Which two types of resources can be protected by using Azure Firewall? Each correct answer
presents a complete solution.
NOTE: Each correct selection is worth one point.
Options
Discussion
Not E, A and D. Only virtual machines and virtual networks are protected by Azure Firewall, the others are SaaS not IaaS.
Honestly wish Microsoft would standardize their terminology here... D imo: Azure Firewall protects both virtual machines and entire virtual networks since it's deployed at the VNet level. It doesn't directly secure SaaS resources like Exchange or SharePoint. So A and D are the picks, pretty sure.
Be respectful. No spam.
Q: 18
Which solution performs security assessments and automatically generates alerts when a
vulnerability is found?
Options
Discussion
CSPM is the one that does continuous assessments and pops alerts for vulnerabilities. A
Be respectful. No spam.
Q: 19
Which Microsoft 365 feature can you use to restrict communication and the sharing of information
between members of two departments at your organization?
Options
Discussion
Ugh, Microsoft always confuses me with these. I’m saying A since sensitivity label policies control access and sharing, right?
Probably C, info barriers are for restricting comms between groups.
Be respectful. No spam.
Question 11 of 20 · Page 2 / 2