Skip to content

Secure storage, databases, and networking Questions

Practice questions for Secure storage, databases, and networking topic in Microsoft Certified: Cloud and AI Security Engineer Associate. 58 questions covering this domain.

58 questions18 easy28 medium12 hard
Q1
medium

A call center application should hide most of a customer's email address from nonprivileged users, but the actual values must remain unchanged in the ...

Q2
medium

You want Azure Storage to use a customer-managed key stored in Azure Key Vault. Which configuration is required on the key vault or managed HSM?

Q3
easy

Two inbound network security group rules match the same traffic. Which rule is processed first?

Q4
medium

A private endpoint is configured for an Azure service, but clients still resolve the service's public IP address. What should you change?

Q5
hard

A user creates a private endpoint to a resource they don't own and selects manual approval. The endpoint shows Pending. Which statement is correct?

Q6
hard

Your organization uses Azure Virtual Network Manager security admin rules. What happens when traffic matches an Always allow security admin rule?

Q7
medium

A subnet is granted access to an Azure Storage account by using a virtual network service endpoint. How does the source IP appear to the storage servi...

Q8
easy

You need protection against a volumetric Layer 3 or Layer 4 attack and also protection against Layer 7 web exploits. Which combination should you depl...

Q9
medium

Which Azure Firewall SKU adds signature-based intrusion detection and prevention?

Q10
medium

A security engineer wants administrators to connect to Azure VMs without assigning public IP addresses to the VMs. Which service should be used?

Q11
easy

How is Transparent Data Encryption configured for newly created Azure SQL databases?

Q12
medium

Blob versioning and blob soft delete are both enabled on a storage account. What happens when the current version of a blob is deleted?

Q13
easy

Which retention range can be configured for Azure Blob soft delete?

Q14
easy

A private endpoint connection was created by using manual approval. Which connection status must the endpoint reach before it can send traffic to the ...

Q15
hard

A storage team locks a time-based immutable storage policy after testing. Which change is still allowed after the policy is locked?

Q16
medium

An organization wants to filter outbound traffic from a virtual network and require centralized public IP egress (e.g., for SaaS allowlisting). Which ...

Q17
medium

A security engineer must restrict Azure Storage account access from a specific subnet to only the storage accounts that belong to a chosen list. Which...

Q18
hard

An architect needs east-west traffic between on-prem and many spoke VNets to traverse a centralized firewall through ExpressRoute, while spoke-to-spok...

Q19
medium

A team must view all NSG rules applied to a NIC across subnet and NIC NSGs and identify why a connection is failing. Which Network Watcher tool gives ...

Q20
hard

A regulated workload must keep all PaaS connectivity off the public internet, including DNS resolution from on-prem. Which design element is required ...

Sign in to see all 58 questions

Create a free account to browse all questions — completely free during our launch phase.