Which service enables temporary elevated access for Azure resources?
AAzure AD Privileged Identity Management
BAzure Resource Manager
CAzure Security Center
DAzure Monitor
Explanation
Azure AD Privileged Identity Management provides just-in-time access, while others offer different resource management functionalities.
Q62
A company needs to ensure all Azure virtual machines are continuously monitored for end-of-life and vulnerability assessments. Which service should they implement?
AAzure Information Protection
BAzure Security Center
CAzure Automation
DAzure Active Directory
Explanation
Azure Security Center provides comprehensive security management and monitoring, while the others serve different purposes.
Q63
You are configuring Azure Firewall. What happens if you set the 'DenyAll' rule at the top of your rules collection?
ATraffic is allowed unless denied later
BAll traffic is denied
COnly HTTPS traffic is denied
DOnly IPsec traffic is denied
Explanation
Setting 'DenyAll' will deny all incoming traffic, overriding other rules if applied first.
Q64
Which service provides advanced threat protection for Azure resources?
AAzure Sentinel
BAzure Security Center
CAzure Firewall
DAzure Policy
Explanation
Azure Security Center offers threat protection; Sentinel focuses on SIEM.
Q65
A company needs to restrict user permissions to only necessary resources in Azure. What should they implement?
You are configuring a data retention policy in Azure Security Center. What happens if you set a retention period of 90 days?
AData is retained for 90 days.
BData is stored indefinitely.
CData is deleted after 90 days.
DData is archived after 90 days.
Explanation
Data will be deleted after the configured period if not retained longer.
Q67
Which service monitors for suspicious activities in Azure resources?
AAzure Security Center
BAzure Logic Apps
CAzure Storage Accounts
DAzure DevOps
Explanation
Azure Security Center provides monitoring for security threats, while the other options do not primarily focus on security monitoring.
Q68
A company needs to prevent sensitive data exfiltration from Azure Blob Storage. Which feature should they implement?
AAzure Role-Based Access Control
BAzure Private Links
CAzure Storage Firewalls
DAzure Data Loss Prevention
Explanation
Azure Data Loss Prevention specifically helps prevent data exfiltration, while the other features primarily focus on permissions and access.
Q69
You are configuring alert rules in Azure Sentinel; what happens when a 'fusion' rule triggers?
ASingle alerts are escalated.
BMultiple alerts are correlated.
CUser accounts are locked.
DData is removed from storage.
Explanation
'Fusion' rules correlate multiple alerts into a single one, while the other options describe incorrect functions.
Q70
Which Azure service provides DDoS protection?
AAzure DDoS Protection
BAzure Firewall
CAzure Sentinel
DAzure Application Gateway
Explanation
Azure DDoS Protection specifically safeguards against DDoS attacks; the others focus on different security aspects.