Skip to content

Secure identity and access Questions

Practice questions for Secure identity and access topic in Microsoft Certified: Azure Security Engineer Associate. 36 questions covering this domain.

36 questions9 easy18 medium9 hard
Q1
medium

You are registering an internal business application that should be usable only by employees in your own tenant. Which supported account type should y...

Q2
hard

A workload currently uses a system-assigned managed identity. The virtual machine is deleted and recreated with the same name. What happens to the ori...

Q3
medium

A user has the Reader role on a resource group and the Contributor role at the subscription scope. What are the user's effective permissions in that r...

Q4
hard

A security team wants to stop sign-ins that use legacy authentication protocols while keeping modern authentication available. What should they config...

Q5
easy

A user is marked as eligible for the User Access Administrator role in Microsoft Entra Privileged Identity Management. What must the user do before us...

Q6
medium

An organization wants to require multifactor authentication only when users access cloud apps from unmanaged devices or from outside the corporate net...

Q7
easy

When are Microsoft Entra Conditional Access policies enforced during sign-in?

Q8
easy

An administrator wants an automation account to read secrets from only one Azure Key Vault and nowhere else. At what scope should the role assignment ...

Q9
medium

Several Azure resources must share the same identity so they can all access the same downstream service without storing secrets. Which managed identit...

Q10
medium

An app registration must call Microsoft Graph to read mail in any user's mailbox without an interactive user. Which permission type should be granted?

Q11
hard

A break-glass strategy requires two emergency-access accounts that can sign in even when normal Conditional Access fails. What is Microsoft's document...

Q12
hard

Microsoft Entra Identity Protection flags a user as high risk after credential leak detection. The Conditional Access policy requires secure password ...

Q13
medium

A security architect needs guests from partner organizations to use their own credentials to sign in to a SharePoint site, while remaining managed in ...

Q14
easy

Which Microsoft Entra license is required to use Privileged Identity Management?

Q15
easy

Which Microsoft Entra feature evaluates real-time and offline sign-in and user risk and can feed risk signals into Conditional Access?

Q16
medium

An administrator needs Microsoft Entra users to be required to register security info (MFA and SSPR) within a defined period using a single combined e...

Q17
medium

A team wants on-prem AD passwords to be checked against Microsoft's banned password list before they are accepted. Which capability provides this?

Q18
medium

Which Microsoft Entra Conditional Access control requires a successful authentication attempt against an allowed combination of methods (e.g., FIDO2, ...

Q19
medium

A security team wants to ensure that any user who requests the Global Administrator role must provide a written justification and have a second admini...

Q20
easy

Which Microsoft Entra feature allows an administrator to review and certify that users still require their current group memberships or application as...

Sign in to see all 36 questions

Create a free account to browse all questions — completely free during our launch phase.