← All AZ-300 Flashcard Decks

Azure Identity & Security Flashcards

6 cards from real AZ-300 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Azure Identity & Security flashcards as text
  1. What is the difference between Azure AD tenant-level and subscription-level RBAC roles?

    Answer: Tenant-level roles manage Azure AD resources; subscription-level roles manage Azure resource access

    Azure AD roles (e.g., Global Administrator) control identity and directory resources, while Azure RBAC roles (e.g., Contributor) control Azure resource access — they operate independently.

  2. Which feature in Azure Key Vault protects against accidental deletion by requiring an additional purge step after a soft delete?

    Answer: Purge Protection

    Purge Protection prevents a soft-deleted Key Vault or its objects from being permanently purged for the retention period, protecting against malicious or accidental deletion.

  3. What type of Managed Identity is scoped to a single Azure resource and deleted when that resource is deleted?

    Answer: System-Assigned Managed Identity

    A System-Assigned Managed Identity is tied to the lifecycle of a single Azure resource and is automatically created and deleted with that resource.

  4. Which Azure AD feature lets you periodically review and certify user access to applications and Azure roles to enforce least privilege?

    Answer: Access Reviews

    Azure AD Access Reviews allow administrators or resource owners to periodically recertify user access rights, removing unnecessary permissions automatically if not confirmed.

  5. What is the purpose of Azure Policy?

    Answer: Enforce organizational standards and assess compliance of Azure resources at scale

    Azure Policy evaluates resources against defined rules (policies) and enforces compliance, denying non-compliant deployments or auditing existing resources.

  6. Which Azure AD B2C feature allows external customers to use their existing social or enterprise identities to sign in to your applications?

    Answer: Identity Federation / Social Identity Providers

    Azure AD B2C supports federating with social identity providers (Google, Facebook, etc.) and enterprise IdPs, letting external users sign in with existing accounts.