1/31
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced |
---|
No study sessions yet.
You are assigning Azure AD roles. Which role will allow the user to manage all the groups in your Teams tenants and be able to assign other administrator roles? Select one.
Global administrator
You are configuring Self-service Password Reset. Which of the following is not a validation method? Select one.
A paging service.
If you delete a user account by mistake, can it be restored? Select one.
The user account can be restored, but only when it’s deleted within the last 30 days.
Your company hires a new IT administrator. She needs to manage a resource group with first-tier web servers including assigning permissions. However, she should not have access to other resource groups inside the subscription. You need to configure role-based access. What should you do? Select one.
Assign her as a Resource Group Owner.
Suppose a team member can’t view resources in a resource group. Where would the administrator go to check the team member’s access? Select one.
Go to the resource group and select Access control (IAM) Role assignments.
A user who had Owner access to a subscription is leaving the company. No one else has access to this subscription. How can you grant another employee access to this subscription? Select one.
Use the Azure portal to elevate your own access.
Your company wants to allow some users to control the virtual machines in each environment. These users should be prevented from modifying networking and other resources in the same resource group or Azure subscription. What should you do? Select one.
Create a role assignment through Azure RBAC
What’s included in a custom Azure role definition? Select one.
Operations allowed for Azure resources and the scope of permission
In a typical project, when would you create your storage account(s)?
At the beginning, during project setup.
Which of the following replicates your data to a secondary region, maintains six copies of your data, and is the default replication option? Select one.
Read-access geo-redundant storage
You are using blob storage. Which of the following is true? Select one.
You can switch between hot and cool performance tiers at any time.
You are planning a delegation model for your Azure storage. The company has issued the following requirement for Azure storage access: -Apps in the non-production environment must have automated time-limited access. You need to configure storage access to meet the requirements. What should you do?
Use shared access signatures for the non-production apps.
You need to provide a contingent staff employee temporary read-only access to the contents of an Azure storage account container named media. It is important that you grant access while adhering to the security principle of least-privilege. What should you do? Select one.
Generate a shared access signature (SAS) token for the container.
What does the term identity mean? Select one.
Something that can be authenticated. It can be a user, application, service, or anything that needs to be identified.
A dedicated and trusted instance of Microsoft Entra ID is referred to as:
An Azure tenant
You would like to add a user who has a Microsoft account to your subscription. Which type of user account is this? Select one.
Guest Use
You are planning to deploy several Linux VMs in Azure. The security team issues a policy that Linux VMs must use an authentication system other than passwords. You need to deploy an authentication method for the Linux VMs to meet the requirement. Which authentication method should you use? Select one.
SSH key pair
Allow inbound coming from any VM to any other VM within the subnet