TechNuggets Academy

Design identity, governance, and monitoring solutions

Free Microsoft Certified: Azure Solutions Architect Expert practice — 6 questions on Design identity, governance, and monitoring solutions, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Design identity, governance, and monitoring solutions
Contoso requires that access to Azure resources by IT administrators be restricted to compliant, Intune-managed devices with MFA enforced. Two emergency-access 'break-glass' accounts must remain fully accessible without these restrictions in case Microsoft Entra ID Conditional Access misconfigures access for everyone else. What should you implement?
Conditional Access policies support granular targeting (all users/admins) with explicit exclusions, allowing MFA and device-compliance enforcement while keeping break-glass accounts exempt from those controls.
Question 2 of 6 · Design identity, governance, and monitoring solutions
You must create a custom Azure RBAC role allowing members to read and restart virtual machines and view their metrics, while explicitly preventing them from managing VM extensions or reading boot diagnostics blob data in the storage account. Which role definition structure is correct?
This structure grants only the required management-plane Actions, uses NotActions to remove extension management, and leaves DataActions empty with NotDataActions explicitly blocking blob read, correctly separating management-plane and data-plane permissions.
Question 3 of 6 · Design identity, governance, and monitoring solutions
A global company enforces an Azure Policy initiative with a Deny effect requiring an 'Owner' tag on all resources, assigned at the root management group and inherited by every subscription. A subsidiary migrating a legacy ERP system needs a 60-day exclusion from just this tag requirement for one resource group, without weakening enforcement anywhere else. What should you do?
Azure Policy exemptions provide a scoped, time-bound way to exclude a specific resource or resource group from one or more policy effects without altering the parent assignment, and support an automatic expiration date and exemption category for auditability.
Question 4 of 6 · Design identity, governance, and monitoring solutions
A multinational retailer must keep diagnostic and security logs from EU and US resources within their respective regions to satisfy data-residency law, but the central SOC team needs a single set of workbooks and alert rules correlating events across all regions in near real time. What should you implement?
Deploying a workspace per region satisfies data-residency requirements since ingestion stays local, while cross-workspace Log Analytics queries allow the central SOC to build unified workbooks and alerts spanning all regional workspaces.
Question 5 of 6 · Design identity, governance, and monitoring solutions
The security team wants users eligible for the Global Administrator role via Privileged Identity Management to activate the role only after providing a business justification and receiving manager approval, for a maximum of 4 hours per activation, with an alert sent to security operations whenever activation occurs. Which PIM configuration meets these requirements?
PIM role settings support requiring justification, requiring approval from specified approvers, setting a maximum activation duration, and configuring notifications/alerts on activation — matching every stated requirement exactly.
Question 6 of 6 · Design identity, governance, and monitoring solutions
You create an Azure Policy assignment using a DeployIfNotExists effect that must automatically remediate non-compliant resources by deploying a diagnostic setting. Which identity does the remediation task require, and how is it typically provisioned?
DeployIfNotExists and Modify policy effects require a managed identity on the policy assignment — either system-assigned or user-assigned — which must be granted the role(s) listed in roleDefinitionIds so it can deploy the remediation resources on the assignment's behalf.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code 00651DDA8F57721374B8 — valid through Sep 23.

Get my $34.99 deal →