Risk Assessment & Management Flashcards
7 cards from real AZ-301 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
An organization is using the FAIR (Factor Analysis of Information Risk) model in their Azure risk assessment. FAIR primarily focuses on quantifying risk in terms of:
Answer: Probable frequency and probable magnitude of loss in financial terms
FAIR quantifies risk by estimating the probable frequency of loss events and the probable magnitude of financial loss, enabling data-driven risk prioritization.
A risk assessment identifies that an Azure subscription has excessive Owner role assignments, violating least-privilege principles. Which Azure tool provides a report of over-provisioned permissions to guide remediation?
Answer: Microsoft Defender for Cloud – Identity Recommendations
Microsoft Defender for Cloud provides identity and access recommendations that flag over-provisioned permissions including excessive Owner assignments.
A multi-tenant SaaS company on Azure needs to assess the risk of one tenant accessing another tenant's data. Which Azure architecture pattern BEST mitigates this data isolation risk?
Answer: Separate Azure subscriptions per tenant with dedicated databases
Separate subscriptions and dedicated databases per tenant provide strong isolation boundaries, reducing cross-tenant data access risk to near-zero.
During an Azure risk assessment, the team must distinguish between inherent risk and residual risk. Residual risk is BEST defined as:
Answer: The risk remaining after security controls have been implemented
Residual risk is the level of risk that remains after all planned security controls have been applied to an inherent risk.
A financial institution requires that all Azure resource changes be tracked with full audit trails to satisfy risk and compliance requirements. Which service provides an immutable log of all control-plane operations?
Answer: Azure Activity Log
Azure Activity Log records all control-plane operations (who did what, when) and can be retained and exported to provide immutable audit trails.
An architect must recommend a risk treatment option for an Azure workload where the residual risk is too high to accept but the cost of additional controls exceeds the risk value. What is the MOST appropriate treatment?
Answer: Risk transfer — purchase cyber liability insurance
When control costs exceed risk value, risk transfer (e.g., cyber insurance) shifts the financial impact of the risk to a third party, which is the appropriate treatment.
A company's Azure risk assessment flags that secrets are being stored in Azure DevOps pipeline variables in plain text. Which combination BEST mitigates this secret exposure risk?
Answer: Reference secrets from Azure Key Vault in pipelines using Key Vault task or variable groups linked to Key Vault
Linking Azure DevOps variable groups to Azure Key Vault ensures secrets are fetched at runtime from a secure vault rather than stored in plain text in pipelines.