TechNuggets Academy

Design security solutions for applications and data

Free Microsoft Certified: Cybersecurity Architect Expert practice — 6 questions on Design security solutions for applications and data, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 4: Design security solutions for applications and data
A financial services company uses GitHub Actions to deploy infrastructure to Azure. The security architect must eliminate all long-lived credentials and secrets from the pipeline while still allowing GitHub Actions to authenticate to Azure AD (Microsoft Entra ID) and provision resources. Which design BEST meets this requirement?
Workload identity federation lets GitHub Actions present a short-lived OIDC token that Azure AD trusts via a federated credential, issuing a short-lived access token in exchange. No secret or certificate is ever stored in GitHub, eliminating credential leakage risk while still enabling automated deployment.
Question 2 of 6 · Domain 4: Design security solutions for applications and data
A pharmaceutical company stores highly sensitive intellectual property in Microsoft 365 documents. Compliance requires that even Microsoft cannot decrypt these documents under any circumstance, including during eDiscovery, and the organization must retain sole control of one encryption key stored entirely outside Microsoft's cloud. Which capability should the architect design into the sensitivity label solution?
Double Key Encryption requires two keys to decrypt content: one managed by Microsoft in Azure and one kept entirely under the customer's control on-premises (or in a location Microsoft never accesses). Because Microsoft never has both keys simultaneously, it cannot decrypt the content under any circumstance, satisfying the strict 'sole control' requirement.
Question 3 of 6 · Domain 4: Design security solutions for applications and data
A conglomerate needs to automatically discover, classify, and catalog sensitive data residing in Azure SQL Database, an AWS S3 data lake, on-premises file shares, and Power BI datasets, and present a unified view of data sensitivity and lineage across all of these sources. Which solution should the architect recommend?
Microsoft Purview's Data Map and unified catalog is purpose-built for cross-platform discovery, classification, and lineage tracking, with native scanning connectors for Azure services, AWS S3, on-premises file shares, and Power BI, giving the single unified sensitivity view required.
Question 4 of 6 · Domain 4: Design security solutions for applications and data
Employees are copying confidential source code and customer PII into public consumer generative AI websites accessed through the corporate browser. The CISO wants visibility into these actions and wants to block the paste action for sensitive content specifically, without blocking access to the AI sites entirely for other uses. Which design BEST meets this requirement?
Microsoft Purview DLP for endpoints, combined with Defender for Cloud Apps' visibility into browser-based generative AI app usage, can specifically detect and block sensitive information being pasted into these sites while leaving general access to the sites untouched, matching the requirement precisely.
Question 5 of 6 · Domain 4: Design security solutions for applications and data
An organization stores application secrets in Azure Key Vault. The security architect wants to grant a specific managed identity permission to read only one designated secret, have that permission auditable through Azure RBAC role assignments, and avoid the vault's legacy access policy model. Which configuration should be implemented?
The RBAC authorization model allows Azure role assignments to be scoped down to an individual secret, key, or certificate, and every assignment is recorded as a standard Azure RBAC role assignment, giving both the granularity and native auditability the architect requires, while moving away from the legacy access policy model.
Question 6 of 6 · Domain 4: Design security solutions for applications and data
During a STRIDE-based threat modeling session for a new customer-facing API, the team identifies a threat where a user could deny having authorized a financial transaction, since the API currently has no way to prove which identity initiated the call. Which STRIDE category does this threat fall under, and what design control best mitigates it?
A user denying they performed an authorized action, with no verifiable proof of who initiated it, is the definition of Repudiation in STRIDE. The correct mitigation is establishing non-repudiation through signed audit trails and identity-bound digital signatures so the action can be conclusively attributed.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →