โ† All AZ-305 Flashcard Decks

Azure Identity and Access Management Design Flashcards

6 cards from real AZ-305 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Azure Identity and Access Management Design flashcards as text
  1. What is the recommended way to assign the same RBAC role to a resource across multiple subscriptions under a management group?

    Answer: Assign the role at the management group scope

    Role assignments at the management group scope inherit down to all subscriptions, resource groups, and resources within it.

  2. A developer needs read access to a specific Azure Storage account but must not have any permissions on other resources in the resource group. Which scope should you use for the role assignment?

    Answer: Resource scope

    Assigning a role at the individual resource scope limits the permissions to only that specific Storage account.

  3. You need to design a solution to detect and alert when users sign in from locations that are anomalous for their profile. Which feature should you enable?

    Answer: Azure AD Identity Protection sign-in risk policies

    Azure AD Identity Protection uses machine learning to compute sign-in risk scores and can automatically block or require MFA for risky sign-ins.

  4. Which Azure AD feature allows you to require users to re-authenticate or meet additional controls when accessing highly sensitive applications even if they already have an active session?

    Answer: Conditional Access authentication context

    Authentication context in Conditional Access lets apps trigger step-up authentication requirements for sensitive operations mid-session.

  5. Your company is implementing a Zero Trust architecture. Which Azure AD capability most directly supports the 'verify explicitly' principle?

    Answer: Conditional Access with device compliance, location, and risk signals

    Conditional Access 'verify explicitly' by evaluating all available signals (user identity, device state, location, risk) before granting access.

  6. A hybrid organization needs users to sign in to on-premises and cloud applications with the same password without syncing password hashes to Azure AD. Which sync method should you choose?

    Answer: Pass-through Authentication (PTA)

    Pass-through Authentication validates passwords directly against on-premises AD in real time without storing any credential data in Azure AD.