โ† All AZ-204 Flashcard Decks

Risk Assessment & Management Flashcards

7 cards from real AZ-204 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Management flashcards as text
  1. You are designing an Azure solution where multiple microservices share a single Azure SQL database. What risk does this architecture introduce and what is the recommended mitigation?

    Answer: Schema coupling and shared fate risk; mitigate by giving each service its own schema or database

    Sharing a database couples microservices through the schema, and a bad migration or load spike from one service can impact all others; separate schemas or databases enforce service boundaries.

  2. A security audit finds that your Azure Container Registry allows anonymous pull access. What is the immediate risk and correct remediation?

    Answer: Risk: unauthorized access to proprietary container images; remediation: disable anonymous pull and enforce Entra ID authentication

    Anonymous pull allows any unauthenticated user on the internet to pull your container images, exposing proprietary code; disabling it and requiring Entra ID authentication prevents unauthorized access.

  3. When using Azure Application Insights to assess application health risk, which metric best indicates that the application is approaching a memory exhaustion condition?

    Answer: Process private bytes / performanceCounters/processPrivateBytes

    The performanceCounters/processPrivateBytes metric tracks the private memory allocated to the process, and a steadily increasing trend indicates a potential memory leak.

  4. Your organization requires that all Azure resource deployments adhere to approved configurations (e.g., no public IP addresses on VMs). Which Azure service enforces this policy risk control continuously?

    Answer: Azure Policy with Deny and DeployIfNotExists effects

    Azure Policy continuously evaluates resources against defined rules; the Deny effect prevents non-compliant deployments and DeployIfNotExists can auto-remediate missing configurations.

  5. A Cosmos DB container uses the default indexing policy. What risk does this introduce for a write-heavy workload?

    Answer: Higher RU consumption per write because all properties are indexed by default

    The default Cosmos DB indexing policy indexes all properties, consuming additional RU/s on every write operation; for write-heavy workloads, a custom policy excluding unnecessary paths reduces this cost and latency risk.

  6. You need to ensure that a compromised Azure Function cannot escalate privileges to access other Azure resources beyond its intended scope. Which control enforces this?

    Answer: Assign the Function's managed identity only the specific RBAC roles it needs, scoped to the minimum resource

    Scoping the managed identity to the minimum required RBAC roles on specific resources limits the blast radius if the Function is compromised, preventing privilege escalation to other resources.

  7. During a risk review, it's found that an Azure Logic App makes HTTP calls to an external webhook without validating the response. Which defensive coding practice should be added?

    Answer: Add a response schema validation action and configure error handling branches for non-2xx status codes

    Validating the webhook response schema and handling non-2xx status codes explicitly prevents the Logic App from silently accepting malformed or error responses as successful operations.