MS Azure D320 ITCL 3202 Mnaging Cloud
Security
Objective Assessment Review (Qns & Ans)
2025
Multiple Choice Questions
What is Azure Active Directory (AAD) primarily used for?
A) Storage solutions
B) Identity and access management
C) Network configuration
D) Machine Learning services Correct ANS: B) Identity and
access management Rationale: Azure Active Directory is
designed for identity and access management in cloud
environments.
©2025
,Which Azure service provides security for cloud applications by
managing cryptographic keys?
A) Azure DevOps
B) Azure Key Vault
C) Azure Security Center
D) Azure Firewall Correct ANS: B) Azure Key Vault Rationale:
Azure Key Vault allows for the secure storage and management
of keys used for cryptography.
In Microsoft Azure, what does the term “Defense in Depth” refer
to?
A) A single security solution
B) Layered security strategies
C) A mandatory compliance check
D) Obsolete security practices Correct ANS: B) Layered security
strategies Rationale: Defense in Depth involves multiple
defensive layers to secure an environment.
What does Azure Security Center primarily focus on?
A) Enhancing network bandwidth
B) Monitoring security posture
©2025
,C) Data storage management
D) Application performance Correct ANS: B) Monitoring
security posture Rationale: Azure Security Center provides
insights into the security status of resources.
Which of the following is NOT a valid Azure Network Security
Group (NSG) rule action?
A) Allow
B) Deny
C) Subnet
D) Permit Correct ANS: D) Permit Rationale: NSG rules only
have actions for Allow or Deny.
Fill-in-the-Blank Questions
The secure management of cloud resources in Azure can be
achieved using __________ to segment and control network
traffic.
Correct ANS: Network Security Groups (NSGs)
Rationale: NSGs allow the segmentation of network traffic to
enhance security.
__________ is a service that provides a framework for
understanding and managing compliance in Azure, helping
organizations meet regulatory demands.
Correct ANS: Azure Policy
©2025
, Rationale: Azure Policy helps organizations enforce rules for
compliance.
In Azure, __________ is used to manage security for applications
through threat detection and response.
Correct ANS: Azure Security Center
Rationale: Azure Security Center monitors applications for
security vulnerabilities.
For identity verification, Azure implements a feature called
__________ which allows for multi-factor authentication.
Correct ANS: Azure Multi-Factor Authentication (MFA)
Rationale: MFA enhances security through additional verification
methods.
The tool used in Azure for automating the deployment of security-
related resources is called __________.
Correct ANS: Azure Resource Manager (ARM)
Rationale: ARM templates can automate the deployment of
security resources.
True/False Questions
©2025
Security
Objective Assessment Review (Qns & Ans)
2025
Multiple Choice Questions
What is Azure Active Directory (AAD) primarily used for?
A) Storage solutions
B) Identity and access management
C) Network configuration
D) Machine Learning services Correct ANS: B) Identity and
access management Rationale: Azure Active Directory is
designed for identity and access management in cloud
environments.
©2025
,Which Azure service provides security for cloud applications by
managing cryptographic keys?
A) Azure DevOps
B) Azure Key Vault
C) Azure Security Center
D) Azure Firewall Correct ANS: B) Azure Key Vault Rationale:
Azure Key Vault allows for the secure storage and management
of keys used for cryptography.
In Microsoft Azure, what does the term “Defense in Depth” refer
to?
A) A single security solution
B) Layered security strategies
C) A mandatory compliance check
D) Obsolete security practices Correct ANS: B) Layered security
strategies Rationale: Defense in Depth involves multiple
defensive layers to secure an environment.
What does Azure Security Center primarily focus on?
A) Enhancing network bandwidth
B) Monitoring security posture
©2025
,C) Data storage management
D) Application performance Correct ANS: B) Monitoring
security posture Rationale: Azure Security Center provides
insights into the security status of resources.
Which of the following is NOT a valid Azure Network Security
Group (NSG) rule action?
A) Allow
B) Deny
C) Subnet
D) Permit Correct ANS: D) Permit Rationale: NSG rules only
have actions for Allow or Deny.
Fill-in-the-Blank Questions
The secure management of cloud resources in Azure can be
achieved using __________ to segment and control network
traffic.
Correct ANS: Network Security Groups (NSGs)
Rationale: NSGs allow the segmentation of network traffic to
enhance security.
__________ is a service that provides a framework for
understanding and managing compliance in Azure, helping
organizations meet regulatory demands.
Correct ANS: Azure Policy
©2025
, Rationale: Azure Policy helps organizations enforce rules for
compliance.
In Azure, __________ is used to manage security for applications
through threat detection and response.
Correct ANS: Azure Security Center
Rationale: Azure Security Center monitors applications for
security vulnerabilities.
For identity verification, Azure implements a feature called
__________ which allows for multi-factor authentication.
Correct ANS: Azure Multi-Factor Authentication (MFA)
Rationale: MFA enhances security through additional verification
methods.
The tool used in Azure for automating the deployment of security-
related resources is called __________.
Correct ANS: Azure Resource Manager (ARM)
Rationale: ARM templates can automate the deployment of
security resources.
True/False Questions
©2025