Question 101

You have a Microsoft 365 E5 subscription and an Azure subscripts You need to evaluate the existing environment to increase the overall security posture for the following components:
* Windows 11 devices managed by Microsoft Intune
* Azure Storage accounts
* Azure virtual machines
What should you use to evaluate the components? To answer, select the appropriate options in the answer area.

Question 102

Your company has an office in Seattle.
The company has two Azure virtual machine scale sets hosted on different virtual networks.
The company plans to contract developers in India.
You need to recommend a solution provide the developers with the ability to connect to the virtual machines over SSL from the Azure portal. The solution must meet the following requirements:
* Prevent exposing the public IP addresses of the virtual machines.
* Provide the ability to connect without using a VPN.
* Minimize costs.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
  • Question 103

    You have an Azure subscription.
    Your company has a governance requirement that resources must be created in the West Europe or North Europe Azure regions.
    What should you recommend using to enforce the governance requirement?
  • Question 104

    You are designing a security strategy for providing access to Azure App Service web apps through an Azure Front Door instance.
    You need to recommend a solution to ensure that the web apps only allow access through the Front Door instance.
    Solution: You recommend access restrictions to allow traffic from the backend IP address of the Front Door instance.
    Does this meet the goal?
  • Question 105

    For a Microsoft cloud environment, you are designing a security architecture based on the Microsoft Cybersecurity Reference Architectures (MCRA). You need to protect against the following external threats of an attack chain:
    * An attacker attempts to exfiltrate data to external websites.
    * An attacker attempts lateral movement across domain-joined computers.
    What should you include in the recommendation for each threat? To answer, select the appropriate options in the answer area.