Skip to content

Manage and monitor security posture Questions

Practice questions for Manage and monitor security posture topic in Microsoft Certified: Cloud and AI Security Engineer Associate. 46 questions covering this domain.

46 questions14 easy24 medium8 hard
Q1
medium

A Key Vault firewall is enabled and a user can browse to the vault in the Azure portal but can't list secrets. What best explains this behavior?

Q2
hard

A policy assignment uses the deployIfNotExists effect to add a missing diagnostic setting to existing resources. What additional requirement must be s...

Q3
easy

A security team wants to understand the effect of a new Azure Policy before it starts blocking deployments. Which effect should be used first?

Q4
hard

A company still uses the Key Vault access policy model. Why does Microsoft recommend moving to Azure RBAC for Key Vault data plane access?

Q5
medium

Security analysts want to extend Microsoft Security Copilot with additional capabilities and external systems. Which Security Copilot component should...

Q6
medium

Your SOC wants ready-made data connectors, analytics, and monitoring content for Microsoft Sentinel. Where should analysts start?

Q7
medium

Which Defender for Cloud plan provides protections such as just-in-time VM access, file integrity monitoring, and advanced server defenses?

Q8
easy

What platform are Microsoft Sentinel playbooks built on?

Q9
medium

A security architect wants to use Cloud Security Explorer and attack path analysis in Defender for Cloud. Which plan is required?

Q10
medium

For Azure Key Vault data plane authorization, which access model does Microsoft recommend?

Q11
easy

Which Defender for Cloud capability summarizes your organization's security posture based on recommendations?

Q12
medium

In a scheduled Microsoft Sentinel analytics rule, which relationship between the query interval and the lookback period is valid?

Q13
medium

A custom scheduled analytics rule in Microsoft Sentinel returns zero results even though matching events exist in the workspace. The rule query omits ...

Q14
easy

Which Defender for Cloud feature shows a graph of how an attacker could move from initial access to a critical asset?

Q15
hard

A subscription administrator can enable or disable Defender for Cloud plans, but some plan capabilities still cannot be fully turned on. Which role is...

Q16
easy

Microsoft Sentinel ingests logs into which underlying Azure service?

Q17
hard

Your team is planning its long-term Microsoft Sentinel portal strategy. According to Microsoft guidance, when will Microsoft Sentinel no longer be sup...

Q18
easy

Which Microsoft Sentinel construct converts repeated alerts on the same entity into a single investigatable container?

Q19
easy

Which Defender for Cloud role can view recommendations, alerts, and policies but cannot make changes?

Q20
medium

Where can administrators review Microsoft Security Copilot administrative activity for auditing purposes?

Sign in to see all 46 questions

Create a free account to browse all questions — completely free during our launch phase.