Question 31

You have a customer that has a Microsoft 365 subscription and uses the Free edition of Azure Active Directory (Azure AD) The customer plans to obtain an Azure subscription and provision several Azure resources.
You need to evaluate the customer's security environment.
What will necessitate an upgrade from the Azure AD Free edition to the Premium edition?
  • Question 32

    You are evaluating an Azure environment for compliance.
    You need to design an Azure Policy implementation that can be used to evaluate compliance without changing any resources.
    Which effect should you use in Azure Policy?
  • Question 33

    Your company has a Microsoft 365 E5 subscription.
    The Chief Compliance Officer plans to enhance privacy management in the working environment. You need to recommend a solution to enhance the privacy management. The solution must meet the following requirements:
    * Identify unused personal data and empower users to make smart data handling decisions.
    * Provide users with notifications and guidance when a user sends personal data in Microsoft Teams.
    * Provide users with recommendations to mitigate privacy risks.
    What should you include in the recommendation?
  • Question 34

    You need to recommend a SIEM and SOAR strategy that meets the hybrid requirements, the Microsoft Sentinel requirements, and the regulatory compliance requirements.
    What should you recommend? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 35

    You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.
    The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.
    You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application.
    Which security control should you recommend?