← All AZ-301 Flashcard Decks

Risk Assessment & Management Flashcards

7 cards from real AZ-301 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Assessment & Management flashcards as text
  1. A company performs a risk assessment and determines that their Azure workloads face significant DDoS risk. Which Azure service provides adaptive DDoS mitigation with attack analytics and telemetry?

    Answer: Azure DDoS Protection Standard

    Azure DDoS Protection Standard provides adaptive tuning, attack mitigation reports, and telemetry specifically designed to counter volumetric DDoS attacks.

  2. An organization's risk policy requires that all privileged Azure AD role assignments be time-limited. Which Azure AD feature enforces just-in-time privileged access to reduce standing access risk?

    Answer: Azure AD Privileged Identity Management (PIM)

    Azure AD PIM provides just-in-time privileged access, requiring users to activate roles for a limited time, reducing the risk from persistent privileged accounts.

  3. A risk register entry states: 'Risk of using deprecated TLS versions on Azure App Service.' Which Azure Policy built-in initiative directly addresses this risk?

    Answer: Azure Security Benchmark – Restrict minimum TLS version

    The Azure Security Benchmark includes a built-in policy to enforce minimum TLS versions on App Service, directly mitigating deprecated protocol risk.

  4. During a risk assessment workshop, your team identifies that Azure Logic Apps could be exploited to exfiltrate data via connectors. What is the BEST control to mitigate this risk?

    Answer: Use ISE (Integration Service Environment) with private endpoints and restrict connector use via Azure Policy

    Deploying Logic Apps in an ISE with private endpoints isolates them from the public internet, and Azure Policy can restrict which connectors are permitted.

  5. A risk assessment requires you to categorize residual risk after applying controls. If a risk has a likelihood of Medium and an impact of High after controls, how should it be treated?

    Answer: Escalate it and apply additional controls to reduce it further

    A Medium × High residual risk typically falls into the 'High' zone on a risk matrix and requires escalation and additional control investment, not acceptance.

  6. An architect designing an Azure solution must assess the risk of certificate expiration causing service outages. Which Azure service automates certificate lifecycle management to mitigate this risk?

    Answer: Azure Key Vault Certificates with auto-renewal

    Azure Key Vault Certificates support automatic renewal with configured issuers, eliminating the manual processes that lead to expiration risk.

  7. A company's cloud risk assessment identifies 'configuration drift' — where Azure resources deviate from their secure baseline — as an ongoing risk. Which tool continuously evaluates and can auto-remediate drift?

    Answer: Azure Automation State Configuration (DSC)

    Azure Automation State Configuration uses PowerShell DSC to continuously assess and remediate configuration drift on Azure VMs and servers.