Which setting enables auditing of Azure SQL databases?
AAdvanced Data Security
BSQL Database Firewall
CAzure Monitor Alerts
DData Encryption at Rest
Explanation
Advanced Data Security provides auditing capabilities, while others deal with security or performance.
Q2
A company needs to ensure all APIs are accessed securely. What should they implement?
APublic IP Whitelisting
BAzure API Management
CShared Access Signatures
DNetwork Security Groups
Explanation
Azure API Management allows secure API access, unlike the others.
Q3
You are configuring Azure Security Center. What happens if you disable the security policy?
AImmediate threat protection stops
BSecurity recommendations are disabled
CAll monitoring functionalities cease
DData is automatically encrypted
Explanation
Disabling the security policy halts recommendations but not monitoring or protection.
Q4
Which Azure service provides DDoS protection automatically?
AAzure DDoS Protection
BAzure Firewall
CAzure Front Door
DAzure Application Gateway
Explanation
Azure DDoS Protection automatically mitigates DDoS attacks; others do not provide this feature automatically.
Q5
A company needs to ensure that their data is encrypted both in transit and at rest. Which Azure solution should they implement?
AAzure SQL Database
BAzure Key Vault
CAzure Storage Service Encryption
DAzure VPN Gateway
Explanation
Azure Storage Service Encryption provides encryption at rest, while others focus on encryption in transit or key management.
Q6
You are configuring security for an Azure subscription. What happens when you assign a role to a user at the resource group level?
AUser can manage all resources
BUser can only view resources
CUser can manage resources within group
DUser gains subscription-wide access
Explanation
Assigning a role at the resource group level grants access only to that group’s resources, not all resources or subscription-wide access.
Q7
Which service provides Azure Active Directory identity protection?
AAzure AD Identity Protection
BAzure Monitor
CAzure Firewall
DAzure Security Center
Explanation
Azure AD Identity Protection is specifically designed for identity security, while other options serve different purposes.
Q8
A company needs to restrict public access to their Azure Storage account but enables public blob access. What is the consequence of that configuration?
ABlobs are publicly accessible.
BOnly private containers accessible.
CContainers are private only.
DPublic access is completely blocked.
Explanation
Enabling public blob access allows public access to blobs, the container’s restriction doesn’t impact blobs.
Q9
You are configuring Azure Security Center's recommendations. What happens when a recommendation is marked as 'resolved'?
AIt removes all alerts.
BThe issue is permanently fixed.
CIt's hidden from the dashboard.
DThe issue may be revisited later.
Explanation
Marking a recommendation as resolved does not mean it is permanently fixed and can be revisited based on new assessments.
Q10
Which Azure service provides centralized policy management for resources?
AAzure Policy
BAzure Security Center
CAzure Sentinel
DAzure Monitor
Explanation
Azure Policy allows you to create, assign, and manage policies to enforce rules over your resources; the other services have different focuses.