TechNuggets Academy

Manage and monitor security posture

Free Microsoft Certified: Azure Security Engineer Associate practice — 6 questions on Manage and monitor security posture, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Manage and monitor security posture
A security engineer connects an AWS account to Microsoft Defender for Cloud using the native cloud connector with the Defender CSPM plan enabled. Six hours later, no AWS resources appear under Inventory. The engineer confirms the connector shows a 'Connected' status. What is the MOST likely cause?
Even when the connector status shows 'Connected', the CloudFormation (or Terraform) template must be deployed in AWS to create the cross-account IAM role that grants Defender for Cloud read/scan permissions. Without it, discovery and recommendations never populate even though the connector object itself exists.
Question 2 of 6 · Manage and monitor security posture
A CISO wants specific Defender for Cloud recommendations automatically assigned to named resource owners with a 14-day remediation deadline, and wants email reminders sent as the deadline approaches. Which feature should be configured?
Governance rules in Defender for Cloud let you define owner assignment logic, remediation SLAs (deadlines), and automated reminder notifications directly tied to specific recommendations or recommendation severities — this is exactly the scenario described.
Question 3 of 6 · Manage and monitor security posture
Your organization deployed Azure OpenAI-based generative AI applications through Azure AI Foundry. Security needs real-time detection of prompt injection attempts and sensitive data leakage happening at the model prompt/response layer. Which capability should be enabled?
Defender for Cloud's AI threat protection (part of the Defender for AI Services / Defender CSPM for AI capability) monitors Azure OpenAI and AI Foundry workloads for prompt injection, jailbreak attempts, and sensitive data exposure in real time, generating security alerts specific to generative AI usage.
Question 4 of 6 · Manage and monitor security posture
A SOC lead wants an automation rule in Microsoft Sentinel that automatically closes incidents as 'False Positive' ONLY when they originate from a specific analytic rule named 'Test Detection - Dev Sandbox' AND have a severity of Informational. Where must this logic be configured?
Automation rules support condition blocks that can filter on specific properties like the triggering analytic rule name and incident severity. Only when both conditions match does the rule execute its action (Change status to Closed, classification False Positive) — no playbook or code is needed for this simple conditional logic.
Question 5 of 6 · Manage and monitor security posture
During a Defender for Cloud review, an analyst wants to see which internet-exposed VM could be used by an attacker to laterally move to a VM hosting a database containing sensitive data, based on network configuration, identity permissions, and vulnerability data combined. Which Defender for Cloud capability provides this?
Attack path analysis (available with Defender CSPM enabled) uses the cloud security graph to correlate exposure, permissions, vulnerabilities, and network reachability, visually mapping exploitable paths from an internet-facing resource to a sensitive data store.
Question 6 of 6 · Manage and monitor security posture
A resource owner insists a flagged Defender for Cloud recommendation for a legacy VM is a known, accepted risk that should stop lowering the subscription's secure score, while still remaining visible for audit purposes with a documented justification and expiry date. What should the security engineer configure?
Exemptions let you exclude a specific resource (or subscription/management group) from a recommendation's score impact while keeping it visible with a documented reason (e.g., 'Risk accepted') and optional expiration date — exactly matching the audit-with-justification requirement.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →