Staff Aug: Interview Questions

0.0(0)
studied byStudied by 0 people
0.0(0)
full-widthCall with Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/32

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No study sessions yet.

33 Terms

1
New cards

What is the first area you assess in a Microsoft cloud environment?

Identity and access (Entra ID) because it represents the largest attack surface.

2
New cards

Why is identity considered the primary attack surface?

Because most modern breaches involve credential theft rather than infrastructure exploits.

3
New cards

What is Entra ID?

Microsoft’s identity and access management platform (formerly Azure AD).

4
New cards

Why should Global Admin accounts not have E3 licenses?

To eliminate exposure to phishing

5
New cards

What is the purpose of separate admin accounts?

To reduce blast radius and prevent compromise of privileged access through daily-use accounts.

6
New cards

What is Conditional Access?

A policy engine that enforces access decisions based on identity

7
New cards

What is the goal of Conditional Access?

Reduce risk without disrupting legitimate business access.

8
New cards

Why block legacy authentication?

Legacy protocols bypass MFA and are commonly exploited in credential-based attacks.

9
New cards

What is a break-glass account?

An emergency admin account excluded from Conditional Access to prevent tenant lockout.

10
New cards

How many break-glass accounts are recommended?

At least two

11
New cards

When should device compliance be required for admins?

Only after endpoint management maturity is confirmed to avoid lockouts.

12
New cards

Why not enforce all security controls immediately?

Over-enforcement can cause outages and disrupt business operations.

13
New cards

How do you balance security and usability?

By phasing controls

14
New cards

What is Microsoft 365 governance?

Policies and standards that control access

15
New cards

Why is Teams governance important?

To prevent sprawl

16
New cards

What is a common Teams governance risk?

Unrestricted guest access and uncontrolled team creation.

17
New cards

Why is Exchange Online important from a security perspective?

Email remains a primary phishing and attack vector.

18
New cards

What is licensing considered from a security standpoint?

A security control that can reduce exposure when applied correctly.

19
New cards

What should be reviewed in an identity assessment?

MFA coverage

20
New cards

What is admin role separation?

Using privileged roles only when necessary and minimizing standing access.

21
New cards

How do you communicate risk to an IT Director?

By explaining impact

22
New cards

How do you handle pushback from internal teams?

By presenting options

23
New cards

What is the purpose of a 30-60-90 day plan?

To show structured onboarding

24
New cards

What is the focus of the first 30 days?

Learning the environment

25
New cards

What is the focus of days 31–60?

Prioritizing recommendations and aligning with leadership.

26
New cards

What is the focus of days 61–90?

Implementing approved changes and enabling the internal team.

27
New cards

Why is documentation important?

It ensures consistency

28
New cards

What is governance cadence?

Regular reviews of access

29
New cards

How do you avoid becoming a bottleneck?

By empowering the internal team through documentation and knowledge transfer.

30
New cards

What defines senior-level troubleshooting?

Understanding systems holistically and resolving root causes

31
New cards

What is the role of an advisory engineer?

Guide

32
New cards

Why is soft skill communication critical?

Because technical changes require leadership buy-in and user trust.

33
New cards

What does success look like in a staff augmentation role?

Reduced risk