Skip to content

Design security solutions for applications and data Questions

Practice questions for Design security solutions for applications and data topic in Microsoft Certified: Cybersecurity Architect Expert. 45 questions covering this domain.

45 questions12 easy22 medium11 hard
Q1
medium

An architect is reviewing a business-critical application portfolio and needs a structured way to identify likely threats before choosing controls. Wh...

Q2
easy

Which Microsoft service catalogs and classifies data assets for discovery and governance scenarios?

Q3
hard

A Microsoft 365 security design must combine SaaS risk visibility, shadow IT discovery, and adaptive control over cloud app usage. Which product shoul...

Q4
hard

A data platform stores information across Azure Storage, Azure SQL, Synapse Analytics, and Azure Cosmos DB. The architect must propose one cohesive se...

Q5
hard

A team plans to secure an API estate and wants centralized publishing, access governance, and protection controls aligned to application security requ...

Q6
easy

Which Microsoft product should be evaluated for protecting email and collaboration workloads in Microsoft 365?

Q7
medium

A team wants Azure-hosted applications to authenticate to Azure resources without storing credentials in code. Which design should be used?

Q8
easy

Which Microsoft product is used for device management and compliance controls in Microsoft 365 security designs?

Q9
medium

A web application must be protected against common web attack patterns while still allowing organization-specific blocking logic. Which design best fi...

Q10
medium

A compliance team asks how to secure data in Microsoft 365 and apply classification and protection controls across documents and emails. Which Microso...

Q11
medium

An architect needs centralized management of cryptographic keys with support for customer-controlled keys and key rotation. Which Azure service should...

Q12
medium

Which approach is documented for protecting an Azure App Service web app from common L7 attacks while still allowing custom rules?

Q13
medium

An architect wants AI-aware data security and posture for generative AI applications using sensitive data. Which Microsoft Purview capability is docum...

Q14
medium

A team wants to scan Azure DevOps and GitHub repos for secret leaks and code vulnerabilities, integrated with Defender for Cloud. Which capability is ...

Q15
medium

An architect must protect Azure SQL data so DBAs can't view PII in plaintext. Which feature should be used?

Q16
easy

Which Azure feature lets developers retrieve secrets, keys, and certificates from Azure Key Vault using a workload identity without storing credential...

Q17
medium

An organization wants its developers to consume secrets and certificates from Azure Key Vault with regular rotation and audit. Which design is recomme...

Q18
easy

Which Microsoft Purview capability detects and prevents unauthorized sharing of sensitive data across endpoints, M365 apps, and cloud services?

Q19
easy

Which Microsoft Purview capability classifies, labels, and protects sensitive content (e.g., credit card data) across Microsoft 365 and beyond?

Q20
medium

A team designs an API estate that needs centralized authentication, throttling, transformation, and OAuth-protected access. Which Azure service should...

Sign in to see all 45 questions

Create a free account to browse all questions — completely free during our launch phase.