Azure Identity and Access Management Design Flashcards
6 cards from real AZ-305 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Azure Identity and Access Management Design flashcards as text
What is the recommended way to assign the same RBAC role to a resource across multiple subscriptions under a management group?
Answer: Assign the role at the management group scope
Role assignments at the management group scope inherit down to all subscriptions, resource groups, and resources within it.
A developer needs read access to a specific Azure Storage account but must not have any permissions on other resources in the resource group. Which scope should you use for the role assignment?
Answer: Resource scope
Assigning a role at the individual resource scope limits the permissions to only that specific Storage account.
You need to design a solution to detect and alert when users sign in from locations that are anomalous for their profile. Which feature should you enable?
Answer: Azure AD Identity Protection sign-in risk policies
Azure AD Identity Protection uses machine learning to compute sign-in risk scores and can automatically block or require MFA for risky sign-ins.
Which Azure AD feature allows you to require users to re-authenticate or meet additional controls when accessing highly sensitive applications even if they already have an active session?
Answer: Conditional Access authentication context
Authentication context in Conditional Access lets apps trigger step-up authentication requirements for sensitive operations mid-session.
Your company is implementing a Zero Trust architecture. Which Azure AD capability most directly supports the 'verify explicitly' principle?
Answer: Conditional Access with device compliance, location, and risk signals
Conditional Access 'verify explicitly' by evaluating all available signals (user identity, device state, location, risk) before granting access.
A hybrid organization needs users to sign in to on-premises and cloud applications with the same password without syncing password hashes to Azure AD. Which sync method should you choose?
Answer: Pass-through Authentication (PTA)
Pass-through Authentication validates passwords directly against on-premises AD in real time without storing any credential data in Azure AD.