โ† All AZ-301 Flashcard Decks

Risk Assessment & Management Flashcards

7 cards from real AZ-301 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Management flashcards as text
  1. A financial services company needs to assess the risk of storing sensitive customer data in Azure Blob Storage. Which Azure service provides continuous compliance assessment and security score?

    Answer: Microsoft Defender for Cloud

    Microsoft Defender for Cloud provides a continuous security assessment with a Secure Score that tracks your compliance posture and identifies risks.

  2. An architect is designing a risk management strategy for an Azure deployment. Which framework does Microsoft recommend for evaluating cloud risks aligned with industry standards?

    Answer: Cloud Adoption Framework (CAF)

    Microsoft's Cloud Adoption Framework (CAF) includes governance and risk management guidance aligned with industry standards for Azure deployments.

  3. A company wants to ensure that only compliant Azure resources are deployed. Which Azure feature allows you to define rules that evaluate resource properties against business requirements?

    Answer: Azure Policy

    Azure Policy defines and enforces rules that evaluate resource properties to ensure they meet organizational compliance and risk standards.

  4. During a risk assessment, a team identifies that a critical VM could be unavailable due to Azure datacenter failure. What is the BEST architecture mitigation for this availability risk?

    Answer: Deploy VMs across Availability Zones

    Deploying VMs across Availability Zones distributes them across physically separate datacenters, protecting against single-datacenter failures.

  5. An organization's risk register identifies unauthorized access to Azure Key Vault secrets as a high-risk item. Which control BEST mitigates this risk?

    Answer: Use Key Vault firewall and virtual network service endpoints

    Key Vault firewall and virtual network service endpoints restrict access to Key Vault to specific trusted networks, directly mitigating unauthorized access risk.

  6. A risk assessment identifies that accidental deletion of Azure SQL Database is a critical threat. Which TWO features should be implemented to mitigate this risk? (Choose the answer that represents both.)

    Answer: Apply a resource lock (CanNotDelete) and enable Point-in-Time Restore

    A CanNotDelete resource lock prevents accidental deletion, while Point-in-Time Restore enables recovery if deletion does occur despite the lock.

  7. Which Azure tool generates a risk assessment report tailored to your specific cloud environment, helping organizations understand their security posture relative to the Azure Security Benchmark?

    Answer: Microsoft Defender for Cloud (Regulatory Compliance dashboard)

    Microsoft Defender for Cloud's Regulatory Compliance dashboard maps your environment against benchmarks like Azure Security Benchmark, generating risk assessment insights.