TechNuggets Academy

Secure compute

Free Microsoft Certified: Azure Security Engineer Associate practice — 6 questions on Secure compute, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Secure compute
A company runs an AKS cluster where multiple pods need to retrieve secrets from Azure Key Vault without embedding any credentials in container images or Kubernetes Secrets objects. Microsoft Entra Pod Identity has already been retired. Which approach should you implement?
Azure AD Workload Identity is the supported, GA replacement for the retired Pod Identity project. It federates a Kubernetes service account's OIDC token with a Microsoft Entra app/managed identity, and when paired with the Secrets Store CSI Driver's Key Vault provider, secrets are mounted as volumes at runtime with per-pod, least-privilege identity — no credentials ever touch the image or etcd.
Question 2 of 6 · Secure compute
A financial services company requires that all managed disks attached to its Azure VMs be encrypted twice at rest — once with a Microsoft platform-managed key and once with a customer-managed key stored in Azure Key Vault — with no changes required inside the guest operating system. Which feature should you enable?
SSE with customer-managed keys handles the CMK layer at the platform/storage level, and enabling infrastructure (double) encryption adds a second, independent encryption layer using a platform-managed key — together satisfying a double-encryption-at-rest requirement entirely outside the guest OS.
Question 3 of 6 · Secure compute
You configure an Azure App Service web app to retrieve a database connection string from Key Vault using a Key Vault reference in an app setting. The app has a system-assigned managed identity enabled and the setting is formatted as @Microsoft.KeyVault(SecretUri=https://contoso-kv.vault.azure.net/secrets/dbConn/). The reference fails to resolve at runtime. What is the most likely missing configuration?
Key Vault references require the App Service identity (system- or user-assigned) to have get/list permission on secrets, granted either via Key Vault access policies or the RBAC role "Key Vault Secrets User" (when the vault uses the Azure RBAC permission model). Without this grant, App Service cannot decrypt/read the secret and the reference stays unresolved even though the syntax is correct.
Question 4 of 6 · Secure compute
Your organization has 200 on-premises Windows servers with no existing connection to Azure. They must be enrolled in Microsoft Defender for Endpoint and appear in Microsoft Defender for Cloud with vulnerability assessment and unified security recommendations. What should you do first?
Azure Arc projects non-Azure machines into the Azure Resource Manager control plane, which is the prerequisite for Defender for Cloud to manage, assess, and monitor them the same way as native Azure VMs. Enabling Defender for Servers Plan 2 on the Arc-connected machines then provisions Microsoft Defender for Endpoint integration, vulnerability assessment, and full recommendation coverage.
Question 5 of 6 · Secure compute
Which statement accurately differentiates "Encryption at Host" from "Azure Disk Encryption (ADE)" on Azure VMs?
Encryption at Host encrypts data at the Azure host level — including temporary disks, disk caches, and data flowing between the VM and storage — without any in-guest agent or OS dependency. ADE, by contrast, uses BitLocker (Windows) or DM-Crypt (Linux) running inside the guest OS via a VM extension.
Question 6 of 6 · Secure compute
A company runs Azure VMs and on-premises Azure Arc-enabled servers across several subscriptions. They need centralized, schedule-based patch orchestration with cross-environment compliance reporting, replacing the retired Azure Automation Update Management solution. Which service should they adopt?
Azure Update Manager is the Microsoft-recommended, Azure-native replacement for the retired Automation Update Management solution. It provides unified patch orchestration, scheduling, and compliance reporting across both Azure VMs and Arc-enabled hybrid servers from a single pane.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →