Question 126

You have a customer that has a Microsoft 365 subscription and uses the Free edition of Azure Active Directory (Azure AD) The customer plans to obtain an Azure subscription and provision several Azure resources.
You need to evaluate the customer's security environment.
What will necessitate an upgrade from the Azure AD Free edition to the Premium edition?
  • Question 127

    You are designing security for an Azure landing zone. Your company identifies the following compliance and privacy requirements:
    * Encrypt cardholder data by using encryption keys managed by the company.
    * Encrypt insurance claim files by using encryption keys hosted on-premises.
    Which two configurations meet the compliance and privacy requirements? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
  • Question 128

    You have an Azure subscription. The subscription contains an Azure application gateway that use Azure Web Application Firewall (WAF).
    You deploy new Azure App Services web apps. Each app is registered automatically in the DNS domain of your company and accessible from the Internet.
    You need to recommend a security solution that meets the following requirements:
    * Detects vulnerability scans of the apps
    * Detects whether newly deployed apps are vulnerable to attack
    What should you recommend using? To answer, select the appropriate options in the answer are a. NOTE: Each correct selection is worth one point.

    Question 129

    Your company plans to deploy several Azure App Service web apps. The web apps will be deployed to the West Europe Azure region. The web apps will be accessed only by customers in Europe and the United States.
    You need to recommend a solution to prevent malicious bots from scanning the web apps for vulnerabilities. The solution must minimize the attach surface.
    What should you include in the recommendation?
  • Question 130

    A customer is deploying Docker images to 10 Azure Kubernetes Service (AKS) resources across four Azure subscriptions. You are evaluating the security posture of the customer.
    You discover that the AKS resources are excluded from the secure score recommendations. You need to produce accurate recommendations and update the secure score.
    Which two actions should you recommend in Microsoft Defender for Cloud? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.