Risk Assessment & Management Flashcards
7 cards from real AZ-301 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
A healthcare organization must perform a risk assessment before migrating to Azure. Which Azure document describes the shared responsibility model that defines Microsoft's vs. the customer's risk obligations?
Answer: Azure Trust Center / Service Trust Portal
The Azure Service Trust Portal (trust.microsoft.com) hosts compliance documentation including the shared responsibility model and audit reports.
An architect is performing threat modeling for an Azure-hosted web application. Which Microsoft methodology is specifically designed for structuring threat identification in application design?
Answer: STRIDE
STRIDE (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege) is Microsoft's threat modeling methodology used in Azure design.
A company's risk assessment indicates that insider threats are a significant concern for their Azure environment. Which Azure feature provides behavioral analytics to detect anomalous internal user activity?
Answer: Microsoft Sentinel with User and Entity Behavior Analytics (UEBA)
Microsoft Sentinel's UEBA feature creates behavioral baselines and flags anomalous activities by insiders that deviate from normal patterns.
During risk quantification, a team needs to calculate the Annual Loss Expectancy (ALE) for an Azure workload. ALE is calculated as:
Answer: Single Loss Expectancy (SLE) × Annualized Rate of Occurrence (ARO)
ALE = SLE × ARO, where SLE is the loss from a single incident and ARO is how often the incident is expected per year.
An organization wants to reduce the risk of Azure subscription sprawl and uncontrolled resource creation. Which management hierarchy feature enforces governance across multiple subscriptions?
Answer: Azure Management Groups with Azure Policy
Azure Management Groups allow you to apply Azure Policy and RBAC across multiple subscriptions, enforcing consistent governance to control sprawl risk.
A risk assessment identifies that data exfiltration via Azure Storage is a high risk. Which Azure network control BEST prevents data from leaving the trusted network boundary?
Answer: Storage Account firewall with selected virtual networks
Azure Storage firewall configured with selected virtual networks restricts access so that storage traffic stays within the trusted network, mitigating exfiltration risk.
An architect must assess the impact of a potential Azure region outage on a mission-critical application. What is the PRIMARY metric used to quantify the acceptable data loss risk?
Answer: Recovery Point Objective (RPO)
RPO defines the maximum acceptable amount of data loss measured in time, directly quantifying the data loss risk from an outage.