deck-1 (m) Flashcards

1
Q

License and Access Review

A

P2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

ACR accessing from SF office vnet and using MFA. 2 things for access control?

A

Disable admin and Set Firewall rule

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Storage Account V1 supported by AD authentication? need to upgrade to V2?

A

Yes, No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

VM update management and 2 related resources

A

Log Analytics workspace, Automation Account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Enterprise App running non-interactive mode. What permission? Admin or User consent? Where to review the enterprise app? MDC or AD

A

App Permission, Admin consent. AD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

SQL injection attack. What to implement? ATP?

A

Advanced Threat Protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

TLS certificate format for Web App to upload and Min Service plan

A

PFX and Basic. CRT for public key certificate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

3 encryptions in SQL: at rest, column encryption, and in transit

A

TDE (Transparent Data Encryption), Always Encrypted, TLS/SSL encryption. DDM is not a encryption.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

cmd to create a spn (Service principal name) in AKS

A

az ad sp create-for-rbac

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Web app reading a secret from KV on behalf of users. What permission and consent?

A

Delegated permission + no admin consent (why? no write).

and no user consent either since it is not reading from user’s profile.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Enterprise App reading all user profile within the tenant. Graph API scope, scope type, consent

A

Directory.Read.All, app-only (not app.only), and admin consent - Yes.

  • why? running as a service
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Payroll manager reviews group membership. What implementation? Licenses?

A

Access Review, P2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

traffic going thru NVA. what routing solution?

A

UDR (User Defined Route)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

NSG migration to AKS environment. What implementation? NetworkPolicy or NetworkRule? What sub-elements?

A

NetworkPolicy

with ingress and port

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Locate the trusted data? Purview what?

A

Catalog

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

a set of cloud-based experience at scale? Purview what?

A

Policy App

14
Q

discover what kinds of data? Purview what?

A

Data Estate Insights App

15
Q

Failed Login. Which KQL table?

A

SecurityEvent

16
Q

MDC logs to KQL what table? for example, Virus detection on a VM

A

SecurityAlert

17
Q

VM is power-off or resized. Which KQL table?

A

Operation

18
Q

KQL syntax for 5 days ago?

A

ago(5d)

ago(-5) XXX

(Get-Date).AddDays(-5) is not allowed powershell syntax in KQL

19
Q

A firewall in a vnet. 2 resources needed?

A

AzureFirewallSubnet, and a public IP

20
Q

webapp accessing a storage account. Authentication implementation?

A

managed identity

RBAC assignment is not for authentication.

21
Q

SPA with personal account login. which grant flow and account type, single or multi-tenant?

A

Implicit

to get token without performing server credential exchange. authorization code grant requires stores a client secrete or certificate. SPA cannot store it.

no tenant account type. Pick Personal only type.

22
Q

3 levels of KV

A

managed HSM, HSM-protected KV, software-protected KV

23
Q

what resource can trigger what NearExpiry?

A

EventGrid and Certificate

24
Q

Two KV key related roles?

A

Crypto Officer, Crypto Service Encryption user

25
Q

3 file share-level permissions and roles

A

SMB share reader
SMB share contributor
SMB share Elevated contributor

diff: to modify ACL

26
Q

MDC 2 roles for Regulatory Compliance Access

A

Resource Policy Contributor,
Security Admin

27
Q

PIM needs a consent?

A

No. It is automatically activated when visiting PIM portal page. To activate PIM, user needs to be in
a priv role (e.g. Global admin) and with P2 license.

28
Q

can set “Create remediate task” to Yes by doing what?

A

Creating/modifying policy your assignment

29
Q

For access review, P2 license needs to be assigned to all group members or group owner only?

A

group owner only