TechNuggets Academy

Design solutions that align with security best practices and priorities

Free Microsoft Certified: Cybersecurity Architect Expert practice — 6 questions on Design solutions that align with security best practices and priorities, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 1: Design solutions that align with security best practices and priorities
A financial services company was previously hit by human-operated ransomware in which attackers obtained Domain Admin credentials and deleted all backups before encrypting production data. The CISO wants a design that ensures recovery is possible even if attackers gain full Active Directory control again. Which design BEST meets this requirement?
Microsoft's ransomware resilience guidance recommends backup isolation using immutability (WORM/time-based retention) so backups cannot be deleted or encrypted even by an attacker with Domain Admin rights, combined with a recovery environment that is not dependent on the compromised identity infrastructure (a 'clean source' principle) to prevent re-compromise during restore.
Question 2 of 6 · Domain 1: Design solutions that align with security best practices and priorities
An enterprise is executing the Zero Trust Rapid Modernization Plan (RaMP) for identity and adopting the 'assume breach' principle. The security architect must decide the sequencing of initiatives. According to Microsoft's RaMP guidance, which initiative should be prioritized IMMEDIATELY after establishing baseline strong authentication (MFA) for all users, and BEFORE deploying granular network micro-segmentation?
In Microsoft's RaMP identity track, after establishing strong authentication (MFA/passwordless), the next initiative is to enforce Conditional Access policies that evaluate signals such as user risk, sign-in risk, and device compliance to make explicit, per-request access decisions -- a core Zero Trust tenet -- before moving on to segmentation of the network layer.
Question 3 of 6 · Domain 1: Design solutions that align with security best practices and priorities
A multinational retailer must demonstrate compliance with GDPR, PCI DSS, and ISO 27001 simultaneously across its Azure and Microsoft 365 environments, and wants continuous visibility into control gaps mapped to each framework without building custom mapping spreadsheets. Which solution BEST meets this requirement?
Microsoft Purview Compliance Manager provides built-in assessment templates mapped to multiple regulatory frameworks (GDPR, PCI DSS, ISO 27001, etc.), continuously tracks control implementation status, and produces a compliance score, eliminating the need for manual mapping.
Question 4 of 6 · Domain 1: Design solutions that align with security best practices and priorities
During a strategy workshop, business stakeholders ask the security architect to 'secure everything to the same maximum level' following a recent breach at a competitor. The architect must translate this into a workable security strategy aligned with Microsoft best practices. What is the MOST appropriate architectural response?
A cybersecurity architect must translate business goals into a strategy grounded in actual risk, using a risk-based approach that prioritizes protection of the highest-value/most sensitive assets aligned with the organization's defined risk appetite -- uniform maximum security everywhere is neither cost-effective nor operationally sustainable.
Question 5 of 6 · Domain 1: Design solutions that align with security best practices and priorities
A security architect is designing a modernized Security Operations Center aligned with the Microsoft Cybersecurity Reference Architecture (MCRA). The organization currently uses disconnected point tools: a legacy on-premises SIEM, a separate endpoint antivirus console, and a manual email-based alert triage process. Which design change aligns BEST with MCRA guidance for SecOps modernization?
MCRA's SecOps guidance recommends consolidating detection and response through an integrated SIEM+XDR approach (e.g., Microsoft Sentinel paired with Microsoft Defender XDR) to enable automated signal correlation across identity, endpoint, and cloud layers, reducing manual triage overhead and improving detection/response speed.
Question 6 of 6 · Domain 1: Design solutions that align with security best practices and priorities
Within the Microsoft Cloud Security Benchmark (MCSB), which statement BEST describes its primary purpose and relationship to industry frameworks?
MCSB defines cloud-agnostic security control domains and provides mappings to widely recognized frameworks like CIS Controls, NIST SP 800-53, and PCI DSS, giving architects a consistent way to assess and design security postures across multiple cloud providers, not just Azure.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →