Identity & Security Solutions Flashcards
6 cards from real AZ-301 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Identity & Security Solutions flashcards as text
An architect is designing a solution where encryption keys must be managed by the customer and stored on-premises, never uploaded to Azure. Which Azure storage encryption option supports this requirement?
Answer: Customer-provided keys (SSE-C)
Customer-provided keys (SSE-C) allows clients to supply their own encryption keys with each storage request, keeping keys entirely under their control outside Azure.
A financial company needs to detect and prevent sensitive data (PII, credit card numbers) from leaving their Azure environment via emails or uploads. Which Azure service provides this Data Loss Prevention capability?
Answer: Microsoft Purview (Information Protection)
Microsoft Purview Information Protection provides DLP policies to detect and prevent sensitive data exfiltration across Microsoft 365 and Azure services.
An architect needs to implement network micro-segmentation within an Azure virtual network to control traffic between individual VMs without using separate subnets. Which feature enables this?
Answer: Application Security Groups
Application Security Groups (ASGs) allow logical grouping of VMs and define NSG rules based on application workloads rather than explicit IP addresses.
A company requires that all Azure virtual machine OS and data disks are encrypted using customer-managed keys stored in Azure Key Vault. Which service provides this OS-level disk encryption?
Answer: Azure Disk Encryption (ADE)
Azure Disk Encryption uses BitLocker (Windows) or DM-Crypt (Linux) to encrypt VM OS and data disks with keys stored in Azure Key Vault.
An architect is designing a security solution for Azure and needs centralized threat detection, security alerts, and automated response across all Azure subscriptions. Which service provides a SIEM/SOAR solution?
Answer: Microsoft Sentinel
Microsoft Sentinel is Azure's cloud-native SIEM and SOAR solution that provides intelligent security analytics, threat detection, and automated incident response.
When designing a secure API solution, an architect needs to validate OAuth 2.0 tokens and enforce scope-based authorization at the API gateway level. Which Azure service provides this capability natively?
Answer: Azure API Management with OAuth 2.0 policy
Azure API Management includes OAuth 2.0 token validation policies that can validate JWT tokens and enforce scope-based access control at the gateway.