← All AZ-300 Flashcard Decks

Azure Identity & Security Flashcards

6 cards from real AZ-300 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Azure Identity & Security flashcards as text
  1. Which Azure AD feature allows you to control access to applications based on user, device, location, and risk signals?

    Answer: Conditional Access

    Conditional Access policies evaluate signals like user identity, device compliance, and location to grant, block, or require additional verification for app access.

  2. What is the purpose of Azure AD Privileged Identity Management (PIM)?

    Answer: Provide just-in-time elevation of privileged roles with approval and time limits

    PIM enables just-in-time privileged access, requiring users to activate elevated roles for a limited time with optional approval and MFA.

  3. Which Azure RBAC role allows full management of all Azure resources but does not allow assignment of roles to others?

    Answer: Contributor

    The Contributor role grants full create/read/update/delete access to resources but cannot assign Azure roles to others — that requires Owner or User Access Administrator.

  4. What is a Managed Identity in Azure?

    Answer: An Azure AD identity automatically managed by Azure for authenticating to services without credentials in code

    Managed Identities provide Azure resources with an automatically rotated identity in Azure AD, allowing them to authenticate to other Azure services without storing credentials.

  5. Which Azure service stores secrets, keys, and certificates with hardware security module (HSM) backing and fine-grained access control?

    Answer: Azure Key Vault

    Azure Key Vault securely stores and manages secrets, encryption keys, and certificates, with optional HSM-backed key protection and RBAC-based access control.

  6. Which Azure AD feature detects risky sign-ins and compromised user accounts using machine learning and threat intelligence?

    Answer: Identity Protection

    Azure AD Identity Protection uses ML-based risk detection to identify compromised accounts and risky sign-in behaviors, triggering automated remediation policies.