Azure Identity & Security Flashcards
6 cards from real AZ-300 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Azure Identity & Security flashcards as text
Which Azure AD feature allows you to control access to applications based on user, device, location, and risk signals?
Answer: Conditional Access
Conditional Access policies evaluate signals like user identity, device compliance, and location to grant, block, or require additional verification for app access.
What is the purpose of Azure AD Privileged Identity Management (PIM)?
Answer: Provide just-in-time elevation of privileged roles with approval and time limits
PIM enables just-in-time privileged access, requiring users to activate elevated roles for a limited time with optional approval and MFA.
Which Azure RBAC role allows full management of all Azure resources but does not allow assignment of roles to others?
Answer: Contributor
The Contributor role grants full create/read/update/delete access to resources but cannot assign Azure roles to others — that requires Owner or User Access Administrator.
What is a Managed Identity in Azure?
Answer: An Azure AD identity automatically managed by Azure for authenticating to services without credentials in code
Managed Identities provide Azure resources with an automatically rotated identity in Azure AD, allowing them to authenticate to other Azure services without storing credentials.
Which Azure service stores secrets, keys, and certificates with hardware security module (HSM) backing and fine-grained access control?
Answer: Azure Key Vault
Azure Key Vault securely stores and manages secrets, encryption keys, and certificates, with optional HSM-backed key protection and RBAC-based access control.
Which Azure AD feature detects risky sign-ins and compromised user accounts using machine learning and threat intelligence?
Answer: Identity Protection
Azure AD Identity Protection uses ML-based risk detection to identify compromised accounts and risky sign-in behaviors, triggering automated remediation policies.