TechNuggets Academy

Manage identity, access, and governance

Free Microsoft Certified: Azure Security Engineer Associate practice — 6 questions on Manage identity, access, and governance, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Manage identity, access, and governance
A security team configures Privileged Identity Management (PIM) so that the 'Cloud App Administrator' role is eligible for assignment to 5 admins. Activation must require Azure MFA, a business justification, and approval from a designated security lead before the role becomes active, and no admin should ever hold the role permanently. Which PIM configuration satisfies ALL of these requirements?
PIM eligible assignments combined with activation settings (require MFA, require justification, require approval with a named approver) are the only configuration that enforces just-in-time, approved, justified activation while never granting permanent standing access.
Question 2 of 6 · Manage identity, access, and governance
An organization's CI/CD pipeline running in GitHub Actions must deploy resources to Azure. Security policy prohibits storing any client secrets, certificates, or long-lived credentials in the pipeline. Which solution meets this requirement?
Workload identity federation lets GitHub Actions exchange a short-lived OIDC token for an Azure AD access token via a federated identity credential, eliminating the need to store any secret or certificate in the pipeline.
Question 3 of 6 · Manage identity, access, and governance
You must ensure that all users assigned the Global Administrator and Exchange Administrator roles authenticate using only phishing-resistant methods (FIDO2 security key, certificate-based authentication, or Windows Hello for Business) — SMS and standard push MFA must NOT satisfy this requirement. Which Conditional Access grant control should you configure?
Authentication strength lets you restrict which specific combinations of authentication methods satisfy a Conditional Access policy; the built-in 'Phishing-resistant MFA' strength includes only FIDO2, certificate-based auth, and Windows Hello for Business, excluding SMS and standard push.
Question 4 of 6 · Manage identity, access, and governance
A tenant has multiple Global Administrators. One Global Administrator needs to modify Azure RBAC role assignments at the root management group scope to grant Owner access on a subscription, but currently receives an 'Insufficient privileges' error when attempting this in the Azure portal. What is the cause and correct fix?
Entra ID roles like Global Administrator do not automatically grant Azure resource (subscription/management group) permissions; a Global Admin must explicitly elevate access, which temporarily assigns User Access Administrator at the tenant root management group scope to manage Azure RBAC.
Question 5 of 6 · Manage identity, access, and governance
Your organization enforces an Azure Policy at the tenant root management group that denies resource deployment outside the 'East US' and 'West Europe' regions. A compliance testing team in a specific subscription has an approved, time-boxed exception to deploy a single resource type in 'North Europe' for 30 days. What should you configure to allow this without weakening the policy for any other subscription?
Policy exemptions allow a specific scope (subscription, resource group, or resource) to be excluded from a policy or initiative assignment for a defined reason and time period without altering the underlying policy definition or assignment for everyone else.
Question 6 of 6 · Manage identity, access, and governance
External auditors from a partner organization need temporary access to a finance application for a 90-day engagement. Access must require approval from the finance resource owner, automatically expire after 90 days, and be subject to a recurring access review to confirm continued need. Guest accounts should be created only when access is approved, not in advance. Which capability should you configure?
Entitlement management access packages combine automated B2B guest provisioning on approval, time-bound expiration policies, and integrated access reviews — exactly matching the approval, auto-expiry, and review requirements in a single governed workflow.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →