A company needs to provide multi-factor authentication (MFA) for Azure AD users. What should they implement?
AAzure AD Conditional Access
BAzure Security Center
CAzure Subscriptions
DAzure Blob Storage
Explanation
Azure AD Conditional Access can enforce MFA, while the others do not manage authentication requirements.
Q72
What happens when Azure AD Connect is misconfigured?
AAll users are deleted.
BSynchronization fails or is stopped.
CUser roles are automatically updated.
DService runs optimally without issues.
Explanation
A misconfiguration in Azure AD Connect leads to failures in syncing between directories; the other options do not accurately describe outcomes of misconfiguration.
Q73
Which service is used for identity protection in Azure?
AAzure AD Identity Protection
BAzure Security Center
CAzure Sentinel
DAzure Information Protection
Explanation
Azure AD Identity Protection specifically addresses identity risks, while the others focus on different security aspects.
Q74
A company needs to implement Conditional Access policies based on user location. What should they configure?
AMulti-Factor Authentication
BLocation-based conditions
CDynamic Groups
DRoles and permissions
Explanation
Conditional Access policies can leverage user location for access decisions, unlike the other options which serve different purposes.
Q75
What happens when a user is assigned multiple roles in Azure AD?
ATotal permissions are aggregated
BLast role assigned wins
CPermissions are denied
DOnly one role is active
Explanation
Azure AD aggregates the permissions of all assigned roles, while the other options incorrectly suggest exclusive or conflicting outcomes.
Q76
Which Azure service provides identity protection for users?
AAzure Active Directory Identity Protection
BAzure Information Protection
CAzure Security Center
DAzure Monitor
Explanation
Azure Active Directory Identity Protection specifically identifies and protects identities; the others focus on different aspects of security.
Q77
A company needs to manage user access to applications based on dynamic attributes. Which feature should they use?
AConditional Access
BDynamic Groups
CRole-Based Access Control
DPrivileged Identity Management
Explanation
Dynamic Groups automatically adjust membership based on attributes; the others do not provide dynamic membership changes.
Q78
What happens when you enable self-service password reset for users in Azure AD?
AUsers must contact IT for reset
BUsers can reset passwords themselves
COnly admins can reset passwords
DPasswords never expire for users
Explanation
Enabling self-service password reset allows users to reset their passwords independently; the other options misstate the functionality.
Q79
What is Azure AD Conditional Access used for?
AEnforcing risk-based access policies
BCreating user accounts in bulk
CManaging on-premises servers
DMonitoring network traffic
Explanation
Conditional Access enhances security by enforcing policies based on user, device, and location, unlike the other options.
Q80
A company needs to ensure users can't access corporate resources outside working hours. Which feature should they implement?
AMulti-Factor Authentication
BConditional Access Policies
CSelf-Service Password Reset
DIdentity Protection
Explanation
Conditional Access Policies can restrict access based on time, while the other options do not provide this function.