Design security operations, identity, and compliance capabilities
Free Microsoft Certified: Cybersecurity Architect Expert practice — 6 questions on Design security operations, identity, and compliance capabilities, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Domain 2: Design security operations, identity, and compliance capabilities
A global MSSP manages Microsoft Sentinel for 40 customer tenants. The MSSP requires a single pane of glass to hunt across all customer workspaces without duplicating data into a central workspace, while each customer retains full data sovereignty over their own workspace. Which design should the architect recommend?
Azure Lighthouse delegated access combined with Sentinel's cross-workspace query capability (union() across workspaces in hunting queries and workbooks) is the documented MSSP multi-tenant pattern — it provides centralized visibility without moving or duplicating customer data, preserving sovereignty.
Question 2 of 6 · Domain 2: Design security operations, identity, and compliance capabilities
A company grants external B2B guest users access to project resources via entitlement management access packages. Compliance requires that guest access be reviewed on a recurring 90-day cadence AND that guest accounts with no sign-in activity for 90 days be automatically disabled and removed, without manual admin intervention. Which configuration best satisfies both requirements?
Recurring Access Reviews on the access package satisfy the review requirement, and Lifecycle Workflows' inactive-guest offboarding template (triggered on sign-in inactivity) automates disabling/removal without admin effort — matching both stated requirements.
Question 3 of 6 · Domain 2: Design security operations, identity, and compliance capabilities
A financial services firm must detect when employees with sensitive M&A document access attempt exfiltration via screenshots, printing, or copying files to personal cloud storage, and must correlate these activities with HR signals such as resignation notices to prioritize investigation. Which Microsoft Purview capability should the architect recommend?
Insider Risk Management correlates behavioral signals (screenshots, printing, cloud upload activity) with HR connector data (resignation, termination) to score and prioritize insider risk cases — precisely the described requirement.
Question 4 of 6 · Domain 2: Design security operations, identity, and compliance capabilities
An architect must ensure that activation of the Global Administrator role in Microsoft Entra PIM requires justification, approval by a second administrator, a maximum activation duration of 4 hours, and blocks activation entirely unless the user authenticates with a phishing-resistant method from a compliant device. Which PIM role setting configuration achieves this?
PIM role settings support an Authentication Context requirement at activation, which is enforced via a linked Conditional Access policy — this is the supported mechanism to require phishing-resistant authentication strength and device compliance beyond basic MFA, while also meeting the 4-hour duration and approval requirements.
Question 5 of 6 · Domain 2: Design security operations, identity, and compliance capabilities
A SOC currently manages incidents separately in Microsoft Sentinel and Microsoft Defender XDR, resulting in duplicated alerts and fragmented cross-domain investigations. The architect must design a unified incident queue with cross-domain correlation across identity, endpoint, email, and cloud apps, plus automated response from a single console. Which architecture should be recommended?
The Microsoft Defender portal's unified security operations platform connects a Sentinel workspace so incidents, entities, hunting, and automation are consolidated into a single console with native cross-domain correlation — the current recommended architecture.
Question 6 of 6 · Domain 2: Design security operations, identity, and compliance capabilities
An admin disables a compromised user's account in Microsoft Entra ID at 10:00 AM. Continuous Access Evaluation (CAE) is enabled for supported services. Approximately how quickly is the user's existing access token revoked, and what distinguishes this from standard token lifetime enforcement?
CAE's core value is near real-time revocation (typically within minutes) triggered by critical security signals, rather than waiting for the access token's normal lifetime to expire — this is the exam-relevant distinction from standard token lifetime enforcement.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.