What happens when you enable Azure Security Center's auto provisioning for VMs?
AAll VMs are automatically deleted
BVMs become part of a security group
CSecurity policies are applied automatically
DAlerts are sent for every action
Explanation
Auto provisioning configures security policies on VMs automatically.
Q52
A company needs to secure sensitive data in its Azure Storage account. Which feature should they enable?
AStorage Service Encryption
BBlob Versioning
CPublic Access Level
DAzure Files Sync
Explanation
Storage Service Encryption automatically encrypts data at rest; the other options do not directly encrypt data.
Q53
What happens when a conditional access policy is assigned in Azure AD?
AAll users are always blocked
BSpecific applications are always accessible
CUser access is evaluated based on conditions
DPolicies apply to the entire Azure tenant
Explanation
Conditional access evaluates the specified conditions before granting access; the other options misrepresent how policies function.
Q54
You are configuring an Azure Web Application Firewall (WAF) for a web app. Which scenario would directly benefit from this configuration?
AIncreased server storage space
BProtection against SQL injection attacks
CFaster database queries
DEnhanced application performance
Explanation
WAF specifically guards against application layer attacks, such as SQL injection; the other options are unrelated benefits.
Q55
Which Azure service provides DDoS protection?
AAzure DDoS Protection
BAzure Firewall
CAzure Security Center
DAzure Sentinel
Explanation
Azure DDoS Protection is specifically designed to mitigate DDoS attacks, while others serve different purposes.
Q56
A company needs to restrict access to sensitive data based on user location. What should they implement?
AAzure Policies
BConditional Access Policies
CNetwork Security Groups
DAzure Blueprints
Explanation
Conditional Access Policies allow location-based access restrictions, while the others focus on different controls.
Q57
You are configuring Azure Key Vault. What happens when you enable soft delete?
AKeys are permanently deleted.
BDeleted items can be recovered.
CNo items can be deleted.
DAccess is revoked immediately.
Explanation
Enabling soft delete allows recovery of deleted items within a retention period, unlike permanent deletion.
Q58
Which Azure service provides unified security management and advanced threat protection?
AMicrosoft Sentinel
BAzure Policy
CAzure Security Center
DAzure Monitor
Explanation
Azure Security Center offers comprehensive security management, while others focus on different aspects like monitoring or policy enforcement.
Q59
A company has sensitive data stored in Azure Blob Storage. What should they use to secure access?