Question 11

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.
The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.
You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application.
Which security control should you recommend?
  • Question 12

    Your company has a Microsoft 365 E5 subscription.
    Users use Microsoft Teams, Exchange Online, SharePoint Online, and OneDrive for sharing and collaborating. The company identifies protected health information (PHI) within stored documents and communications. What should you recommend using to prevent the PHI from being shared outside the company?
  • Question 13

    You open Microsoft Defender for Cloud as shown in the following exhibit.

    Use the drop-down menus to select the answer choice that complete each statements based on the information presented in the graphic.
    NOTE: Each correct selection is worth one point.

    Question 14

    You have an Azure subscription that contains virtual machines, storage accounts, and Azure SQL databases. All resources are backed up multiple times a day by using Azure Backup. You are developing a strategy to protect against ransomware attacks.
    You need to recommend which controls must be enabled to ensure that Azure Backup can be used to restore the resources in the event of a successtu\ ransonvwaTe attack.
    Which two controls should you include in the recommendation? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
  • Question 15

    You have an Azure subscription that has Microsoft Defender for Cloud enabled.
    You are evaluating the Azure Security Benchmark V3 report.
    In the Secure management ports controls, you discover that you have 0 out of a potential 8 points.
    You need to recommend configurations to increase the score of the Secure management ports controls.
    Solution: You recommend enabling just-in-time (JIT) VM access on all virtual machines.
    Does this meet the goal?