Describe the capabilities of Microsoft security solutions
Free Microsoft Certified: Security, Compliance, and Identity Fundamentals practice — 6 questions on Describe the capabilities of Microsoft security solutions, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Describe the capabilities of Microsoft security solutions
A company runs several Azure virtual machines with no public IP addresses assigned. Administrators need to connect to these VMs via RDP and SSH directly through the Azure portal, over TLS, without deploying a VPN client, opening any inbound ports on the VMs, or exposing them to the public internet at any time. Which service should they deploy?
Azure Bastion is a fully managed PaaS service that provides secure RDP/SSH connectivity to VMs directly through the Azure portal over TLS on port 443, without requiring a public IP on the VM, a VPN client, or any open inbound management ports.
Question 2 of 6 · Describe the capabilities of Microsoft security solutions
By default, what level of DDoS protection does every Azure virtual network automatically receive, and what must be explicitly enabled to add adaptive tuning, near-real-time attack telemetry/metrics, and cost protection guarantees during an attack?
Azure DDoS Protection Basic is automatically enabled for every Azure resource at no additional cost and provides always-on network-layer traffic monitoring and real-time mitigation of common attacks. DDoS Protection Standard is an additional paid tier enabled per virtual network that adds adaptive tuning based on the network's traffic patterns, near-real-time attack metrics and telemetry via Azure Monitor, and a cost protection SLA guarantee for scale-out costs incurred during a documented attack.
Question 3 of 6 · Describe the capabilities of Microsoft security solutions
A public-facing web application hosted behind Azure Application Gateway is being targeted by SQL injection and cross-site scripting (XSS) attempts embedded in HTTP request bodies and query strings. Which Azure security capability is purpose-built to inspect and block these Layer 7 web-based attack patterns?
Web Application Firewall (WAF) provides centralized, Layer 7 protection for web applications using rule sets (including the OWASP Core Rule Set) specifically designed to detect and block common web exploits such as SQL injection and XSS, and can be deployed with Azure Application Gateway or Azure Front Door.
Question 4 of 6 · Describe the capabilities of Microsoft security solutions
What does the secure score shown in Microsoft Defender for Cloud represent?
Secure score is a percentage measurement that aggregates the findings of security recommendations across your subscriptions and resources into a single number, weighted by potential impact, so organizations can quickly gauge and prioritize their overall security posture and track improvement over time.
Question 5 of 6 · Describe the capabilities of Microsoft security solutions
A SOC wants Microsoft Sentinel to automatically isolate a compromised device and disable the associated user account the moment a specific high-severity alert fires, without waiting for an analyst to take manual action. Which Sentinel capability enables this automated response?
Microsoft Sentinel's SOAR (Security Orchestration, Automation, and Response) capability is delivered through automation rules that respond to incidents by triggering playbooks — workflows built on Azure Logic Apps — which can perform actions like isolating a device or disabling a user account automatically without manual analyst intervention.
Question 6 of 6 · Describe the capabilities of Microsoft security solutions
A security team detects suspicious pass-the-hash activity and lateral movement originating from on-premises Active Directory domain controllers. Which Microsoft Defender XDR component is purpose-built to detect this type of on-premises, identity-based attack using signals collected directly from domain controllers?
Microsoft Defender for Identity monitors on-premises Active Directory signals — including domain controller traffic and events — to detect identity-based attacks such as pass-the-hash, pass-the-ticket, reconnaissance, and lateral movement, making it the correct choice for this on-premises AD-focused scenario.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code FREETEST33 — valid through Oct 6.