โ† All AZ-301 Flashcard Decks

Identity & Security Solutions Flashcards

6 cards from real AZ-301 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Identity & Security Solutions flashcards as text
  1. A company must ensure Azure resources can only be created in specific regions and that certain resource types like public IP addresses are prohibited. Which Azure feature enforces these governance constraints?

    Answer: Azure Policy

    Azure Policy enforces organizational standards by defining and applying rules that audit or deny resource configurations such as allowed regions or prohibited resource types.

  2. An architect needs to deploy a consistent set of Azure resources including RBAC assignments, policy assignments, and ARM templates across multiple subscriptions simultaneously. Which Azure service enables this?

    Answer: Azure Blueprints

    Azure Blueprints packages role assignments, policy assignments, ARM templates, and resource groups into a single reusable artifact deployable across multiple subscriptions.

  3. A security architect must implement a solution where Azure AD users can only access Azure portal resources from compliant, hybrid Azure AD-joined devices on the corporate network. Which feature enforces this?

    Answer: Azure AD Conditional Access

    Azure AD Conditional Access policies can enforce device compliance, hybrid join status, and network location as conditions before granting access.

  4. A company wants to implement defense in depth for their Azure SQL Database to detect SQL injection attacks and anomalous access patterns in real time. Which feature should be enabled?

    Answer: Microsoft Defender for SQL (Advanced Threat Protection)

    Microsoft Defender for SQL provides Advanced Threat Protection that detects anomalous activities and SQL injection attempts in real time with actionable alerts.

  5. An architect needs to ensure that all Azure resource deployments across an organization comply with security baselines and that non-compliant resources are automatically remediated. Which combination should be used?

    Answer: Azure Policy with DeployIfNotExists effect and remediation tasks

    Azure Policy with DeployIfNotExists effect combined with remediation tasks automatically brings non-compliant resources into compliance by deploying required configurations.

  6. A company needs to implement privileged access workstations (PAW) for Azure administrators and ensure admin activities are only performed from these dedicated devices. Which Azure AD feature enforces this?

    Answer: Conditional Access with device filter for privileged roles

    Conditional Access policies with device filters can restrict privileged role assignments to specific compliant or dedicated PAW devices only.