A company needs to implement self-service password reset (SSPR) for users. What must be configured to achieve this?
APassword policies only
BMFA for all users
CAzure AD user settings
DAlerts for password changes
Explanation
Only Azure AD user settings provide the SSPR functionality effectively.
Q42
What happens when a user is removed from an Azure AD group?
AUser loses access to all resources
BUser retains specific resource access
CUser can still manage the group
DUser is removed from the tenant
Explanation
The user retains access to resources not tied to the group, while options A, C, and D are incorrect based on Azure AD behavior.
Q43
Which Azure service allows for centralized identity management?
AAzure Active Directory
BAzure Blob Storage
CAzure Kubernetes Service
DAzure Virtual Machines
Explanation
Azure Active Directory provides centralized identity management, while the others serve different purposes.
Q44
A company needs to ensure non-repudiation for its Azure AD access logs. What should it implement?
AAudit log retention policies
BMulti-Factor Authentication
CRole-Based Access Control
DPrivileged Identity Management
Explanation
Audit log retention policies ensure logs are preserved for non-repudiation, unlike the other options which focus on security controls and permissions.
Q45
What happens when you add a user outside of an organization to Azure AD as a guest?
AThey can be assigned licenses
BThey cannot access any resources
CThey can participate in teams
DThey automatically gain admin rights
Explanation
Guest users can participate in teams but lack full access to resources like licensed users and don’t gain admin rights automatically.
Q46
Which Azure service is primarily used for managing access policies?
AAzure Active Directory
BAzure Key Vault
CAzure Storage
DAzure Backup
Explanation
Azure Active Directory manages user access, while the others serve different purposes.
Q47
A company needs to restrict access to resources based on user attributes; what feature should they use?
AConditional Access
BAuthentication Flow
CRole-Based Access Control
DPrivileged Identity Management
Explanation
Conditional Access policies enforce restrictions based on user attributes, unlike the other options.
Q48
What happens when you configure an Azure AD application with the 'User Consent' option enabled?
AAdmins must approve all access requests.
BUsers can grant permissions themselves.
CNo permissions are granted automatically.
DServices access is automatically revoked.
Explanation
User Consent allows users to grant permissions, while other options are misleading.
Q49
Which service is used for managing user identities?
AAzure Active Directory
BAzure Blob Storage
CAzure Kubernetes Service
DAzure Functions
Explanation
Azure Active Directory is specifically designed for identity management.
Q50
A company needs to enforce conditional access based on user location. What should they use?
AManagement Groups
BUser Roles
CAccess Policies
DConditional Access
Explanation
Conditional Access is specifically designed for enforcing access based on multiple conditions.