Question 96

Your company develops several applications that are accessed as custom enterprise applications in Azure Active Directory (Azure AD). You need to recommend a solution to prevent users on a specific list of countries from connecting to the applications. What should you include in the recommendation?
  • Question 97

    Your on-premises network contains an e-commerce web app that was developed in Angular and Nodejs. The web app uses a MongoDB database. You plan to migrate the web app to Azure. The solution architecture team proposes the following architecture as an Azure landing zone.

    You need to provide recommendations to secure the connection between the web app and the database. The solution must follow the Zero Trust model.
    Solution: You recommend implementing Azure Key Vault to store credentials.
  • Question 98

    You are designing the encryption standards for data at rest for an Azure resource You need to provide recommendations to ensure that the data at rest is encrypted by using AES-256 keys. The solution must support rotating the encryption keys monthly.
    Solution: For blob containers in Azure Storage, you recommend encryption that uses customer-managed keys (CMKs).
    Does this meet the goal?
  • Question 99

    You have 50 Azure subscriptions.
    You need to monitor resource in the subscriptions for compliance with the ISO 27001:2013 standards. The solution must minimize the effort required to modify the list of monitored policy definitions for the subscriptions.
    NOTE: Each correct selection is worth one point.
  • Question 100

    You are designing the security architecture for a cloud-only environment.
    You are reviewing the integration point between Microsoft 365 Defender and other Microsoft cloud services based on Microsoft Cybersecurity Reference Architectures (MCRA).
    You need to recommend which Microsoft cloud services integrate directly with Microsoft 365 Defender and meet the following requirements:
    * Enforce data loss prevention (DLP) policies that can be managed directly from the Microsoft 365 Defender portal.
    * Detect and respond to security threats based on User and Entity Behavior Analytics (UEBA) with unified alerting.
    What should you include in the recommendation for each requirement? To answer, select the appropriate options in the answer are a. NOTE: Each correct selection is worth one point.