✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Describe the concepts of security, compliance, and identity
A company uses a fully SaaS-based email and collaboration suite hosted by a cloud provider. Under the shared responsibility model, who retains responsibility for classifying data and managing user identities and access, regardless of the service model used?
In the shared responsibility model, the customer always retains responsibility for data classification, accountability, endpoints, accounts, and identities — this never shifts to the provider, even in SaaS, where the provider takes on the most responsibility overall.
Question 2 of 12 · Describe the capabilities of Microsoft Entra
A company wants employees to sign in to their Windows 11 laptops using facial recognition or a PIN that is tied to the specific device, eliminating the need to type a password. Which Microsoft Entra authentication capability BEST meets this requirement?
Windows Hello for Business provides passwordless sign-in using biometrics (face/fingerprint) or a PIN that is cryptographically tied to the specific device, replacing password entry.
Question 3 of 12 · Describe the capabilities of Microsoft security solutions
An administrator needs to allow secure RDP and SSH access to Azure virtual machines directly through the Azure portal, without exposing the VMs to public IP addresses or requiring a VPN client. Which Azure service BEST meets this requirement?
Azure Bastion is a fully managed PaaS service that provides secure RDP and SSH connectivity to VMs directly through the Azure portal over TLS, eliminating the need for public IPs on the VMs or a client-side VPN.
Question 4 of 12 · Describe the capabilities of Microsoft compliance solutions
A compliance officer opens the Microsoft Purview compliance portal and sees an overall percentage score along with a list of recommended improvement actions grouped by control. Which Purview capability is being used?
Compliance Manager calculates a compliance score based on completed improvement actions across Microsoft-managed, technical, and organizational controls, giving a percentage score and prioritized recommendations.
Question 5 of 12 · Describe the concepts of security, compliance, and identity
A network engineer configures a firewall to trust all traffic originating from inside the corporate network and only inspects traffic that crosses the network perimeter. This design assumes that being on the internal network is sufficient proof of trustworthiness. Which Zero Trust guiding principle does this design violate?
Verify explicitly means every access request should be authenticated and authorized based on all available data points (identity, device, location, etc.), never granted implicit trust just because traffic originates from inside a network boundary.
Question 6 of 12 · Describe the capabilities of Microsoft Entra
An organization wants to grant a user the Global Administrator role only for a scheduled 4-hour maintenance window, requiring manager approval before activation and automatic removal of the role after the window ends. Which Microsoft Entra capability should be used?
Privileged Identity Management provides just-in-time, time-bound activation of privileged roles, including approval workflows and automatic expiration of the elevated access.
Question 7 of 12 · Describe the capabilities of Microsoft security solutions
A company hosts a public-facing e-commerce web application on Azure and wants to protect it specifically from SQL injection and cross-site scripting attacks at the HTTP layer. Which Microsoft security capability should they deploy?
Web Application Firewall, available with Azure Application Gateway or Azure Front Door, inspects HTTP/HTTPS traffic and uses managed rule sets (based on OWASP core rules) to block common web exploits such as SQL injection and cross-site scripting.
Question 8 of 12 · Describe the capabilities of Microsoft compliance solutions
A company wants to automatically detect and block emails that contain credit card numbers from being sent to external recipients, while still allowing internal transfers of the same data. Which Purview capability should they configure?
DLP policies detect sensitive information types like credit card numbers and can enforce different actions (block, warn, allow) based on context such as the recipient being internal or external.
Question 9 of 12 · Describe the concepts of security, compliance, and identity
A user attempts to open a company application and is prompted to enter a username and password before being granted any access to the system. Which security concept does this prompt represent?
Authentication is the process of proving a user's identity, typically through credentials such as a username and password, before any access decision is made.
Question 10 of 12 · Describe the capabilities of Microsoft Entra
An administrator wants a Conditional Access policy that requires multifactor authentication only when a Global Administrator signs in from outside the corporate network, while allowing normal sign-in from trusted network locations. Which combination of Conditional Access settings achieves this?
Targeting the Global Administrator directory role, using a Locations condition that excludes the trusted corporate network, and applying a Require MFA grant control precisely matches the described requirement.
Question 11 of 12 · Describe the capabilities of Microsoft security solutions
In Microsoft Defender for Cloud, what does the 'secure score' represent?
Secure score in Microsoft Defender for Cloud aggregates security recommendations across your environment into a single percentage score, giving an at-a-glance measure of your current security posture and showing the impact of remediating specific recommendations.
Question 12 of 12 · Describe the capabilities of Microsoft compliance solutions
An administrator creates a sensitivity label named 'Confidential' and wants any document with this label applied to automatically be encrypted so only members of the Finance group can open it. Which sensitivity label setting enables this?
Sensitivity labels support encryption settings where you can assign specific users or groups permissions (e.g., view, edit) so only those users can open protected content, regardless of where the file is sent.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code FREETEST33 — valid through Oct 6.
The exam fee is approximately $99 and varies by region — confirm current pricing with the certification vendor before you book.
What topics are on the exam?
It covers 4 domains: Describe the concepts of security, compliance, and identity (10-15%), Describe the capabilities of Microsoft Entra (25-30%), Describe the capabilities of Microsoft security solutions (35-40%), Describe the capabilities of Microsoft compliance solutions (15-20%). The full course has a dedicated chapter, lab and practice-test coverage for each.
Is this practice test really free?
Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.
How do I get the discount?
Use code FREETEST33 at checkout for $34.99 (list undefined) through Oct 6 — the enroll button applies it automatically.
Will this prepare me for the real exam?
The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.