โ† All AZ-204 Flashcard Decks

Risk Assessment & Management Flashcards

7 cards from real AZ-204 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Management flashcards as text
  1. You need to ensure that a Cosmos DB container's throughput is never overwhelmed by a single tenant in a multi-tenant app. Which approach best isolates this risk?

    Answer: Create a dedicated container per tenant with provisioned RU/s

    Dedicated containers per tenant with provisioned RU/s provide hard isolation so one tenant's traffic cannot consume another tenant's throughput budget.

  2. Your Azure Function uses a Blob trigger to process uploaded files. To avoid data loss risk if the function fails mid-processing, which pattern should you implement?

    Answer: Write a poison-message handler using the Azure Function's retry policy with a Blob lease

    Configuring an explicit retry policy and using blob leases prevents duplicate processing while ensuring failed messages are retried, protecting against data loss on transient failures.

  3. When assessing risk for an Azure application that uses managed identity to access Azure SQL, which scenario represents a residual risk that managed identity does NOT eliminate?

    Answer: SQL injection in application query logic

    Managed identity removes credential management risk but does not protect against SQL injection, which is an application-layer vulnerability in how queries are constructed.

  4. Your team must demonstrate to auditors that all changes to Azure resource configurations are logged. Which service provides an immutable audit trail of management-plane operations?

    Answer: Azure Activity Log

    The Azure Activity Log captures all control-plane (management-plane) operations such as resource creation, deletion, and modification with user identity and timestamps.

  5. A security review flags that your App Service can be accessed over plain HTTP. What is the lowest-effort mitigation to enforce HTTPS-only access?

    Answer: Enable the HTTPS Only toggle in App Service TLS/SSL settings

    The HTTPS Only setting in App Service automatically redirects all HTTP requests to HTTPS with a single toggle, requiring no infrastructure changes.

  6. You are using Azure Event Hubs to ingest IoT telemetry. To mitigate the risk of data loss when a consumer application is down, which feature should you configure?

    Answer: Enable Capture to write events to Azure Blob Storage

    Event Hubs Capture automatically writes ingested events to Azure Blob or Data Lake Storage, ensuring no data is lost even if downstream consumers are offline.

  7. Which Azure Security Center (Defender for Cloud) capability directly helps developers identify misconfigured Azure resources that introduce security risk at the code/IaC stage?

    Answer: DevSecOps integration with IaC scanning

    Defender for Cloud's DevSecOps integration scans Infrastructure-as-Code templates in CI/CD pipelines, surfacing misconfigurations before they reach production.