TechNuggets Academy

Design security solutions for infrastructure

Free Microsoft Certified: Cybersecurity Architect Expert practice — 6 questions on Design security solutions for infrastructure, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 3: Design security solutions for infrastructure
A manufacturing company operates an OT network with SCADA and PLC devices following the Purdue model. Security must gain visibility into ICS protocol traffic (Modbus, DNP3) between Purdue levels 0-3 without installing any software on the legacy devices and without risking disruption to production availability. Which design BEST meets these requirements?
Defender for IoT OT sensors perform agentless, passive deep packet inspection of ICS/SCADA protocols via port mirroring (SPAN/TAP), giving full visibility into east-west and north-south OT traffic without touching legacy devices or risking availability impact — the standard recommended architecture for Purdue-model segmentation monitoring.
Question 2 of 6 · Domain 3: Design security solutions for infrastructure
An enterprise runs workloads across Azure, AWS, and GCP. The security team wants vulnerability assessment coverage for AWS EC2 instances and GCP Compute Engine VMs without deploying and maintaining agents on every instance, while still surfacing findings in Microsoft Defender for Cloud's unified recommendations. What should the architect configure?
The Defender CSPM plan provides agentless scanning that takes disk snapshots of AWS and GCP VMs to perform vulnerability and secrets scanning without any agent footprint, and the results appear as native recommendations inside Defender for Cloud across all connected clouds — exactly matching the requirement.
Question 3 of 6 · Domain 3: Design security solutions for infrastructure
A hybrid environment has VMs in Azure, AWS, and an on-premises datacenter, all requiring occasional RDP/SSH administrative access. The CISO mandates that management ports be closed by default across all environments, with access granted only for a limited time window after an approved request, and full auditability of who requested access and when. Which solution should the architect design?
Just-in-Time VM access in Defender for Cloud is purpose-built for this scenario: it keeps inbound management ports closed by default, requires an explicit access request, applies time-bound NSG/firewall rules only when approved, and logs all requests for auditing — extending to hybrid/Arc-enabled machines.
Question 4 of 6 · Domain 3: Design security solutions for infrastructure
An organization runs production workloads on AKS. Security wants to prevent container images with unresolved critical vulnerabilities from ever being deployed to the cluster, rather than only detecting the issue after the pod is already running. Which design achieves this 'shift-left' enforcement?
Defender for Containers integrates with the Azure Policy add-on for AKS to provide Kubernetes admission control, which can be configured to actively block deployment of pods using images with unresolved vulnerabilities above a defined severity — true preventive, shift-left enforcement at deploy time.
Question 5 of 6 · Domain 3: Design security solutions for infrastructure
A company has 400 on-premises Windows and Linux servers that are not managed by Azure. Leadership wants these servers to receive Microsoft Defender for Endpoint protection, vulnerability assessment, and inclusion in the Defender for Cloud regulatory compliance dashboard, using the same experience as native Azure VMs. What should the architect design first?
Azure Arc projects on-premises (and multicloud) servers as first-class Azure resources, which is the prerequisite that allows Defender for Servers to be enabled on them, extending Defender for Endpoint integration, vulnerability assessment, and regulatory compliance dashboard coverage identically to native Azure VMs.
Question 6 of 6 · Domain 3: Design security solutions for infrastructure
A security team wants to reduce the attack surface of a fleet of Azure VMs by allowing only trusted, previously observed executables to run, minimizing false positives without manually building and maintaining allowlists per server. Which Defender for Cloud capability should the architect recommend?
Adaptive Application Controls, part of Defender for Servers Plan 2, use machine learning to analyze applications running on VMs and automatically recommend intelligent, per-group allowlists, reducing manual maintenance while enforcing execution control — directly matching the stated requirement.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →