Beranda
›
Sertifikasi Teknologi
›
Latihan Azure Security Engineer AZ-500
Pilih mode latihan, jawab setiap soal, lalu tinjau penjelasan. Jawaban salah disimpan secara lokal.
Waktu tersisa: 00:00
Belum ada jawaban salah tersimpan.
Tidak ada soal yang cocok dengan filter.
Soal 1
What is Microsoft Entra ID?
Pilih jawaban
A DNS service A cloud identity and access management service A firewall A storage service
★ Simpan
! Tandai salah
Microsoft Entra ID provides identity and access management. Firewalls, storage, and DNS are different services.
Soal 2
What is multi-factor authentication?
Pilih jawaban
Requiring two or more verification factors Using one password only Disabling logins Storing files
★ Simpan
! Tandai salah
MFA requires multiple verification factors such as password and phone. One password, disabled logins, and storage are different.
Soal 3
What is Conditional Access?
Pilih jawaban
A storage policy A DNS record Policies that evaluate signals before granting access A firewall rule
★ Simpan
! Tandai salah
Conditional Access evaluates user, device, location, and risk signals. Firewall rules, storage policies, and DNS are different.
Soal 4
What is Azure RBAC?
Pilih jawaban
A virtual network A database A CDN Role-based access control for Azure resources
★ Simpan
! Tandai salah
RBAC grants permissions through roles. Networks, databases, and CDNs are different.
Soal 5
What is a managed identity?
Pilih jawaban
A user account A DNS record A firewall An automatic Azure identity for a resource
★ Simpan
! Tandai salah
Managed identities give Azure resources an identity without managing credentials. User accounts, DNS, and firewalls are different.
Soal 6
What is a service principal?
Pilih jawaban
An identity used by an application A virtual machine A storage account A network security group
★ Simpan
! Tandai salah
Service principals represent applications. VMs, storage accounts, and NSGs are resources.
Soal 7
What is a custom role?
Pilih jawaban
A firewall rule A user-defined set of permissions A built-in role only A DNS record
★ Simpan
! Tandai salah
Custom roles define specific permissions. Built-in roles, DNS records, and firewall rules are different.
Soal 8
What is Privileged Identity Management?
Pilih jawaban
A storage policy A load balancer Time-bound access for privileged roles A firewall
★ Simpan
! Tandai salah
PIM provides just-in-time privileged access. Firewalls, storage, and load balancers are different.
Soal 9
What is a guest user?
Pilih jawaban
A virtual machine A service principal An external collaborator in your directory An administrator
★ Simpan
! Tandai salah
Guest users are external collaborators. Administrators, VMs, and service principals are different.
Soal 10
Match each identity concept to its purpose.
Entra ID Pilih jawaban Identity service Second factor Access policies Role permissions MFA Pilih jawaban Identity service Second factor Access policies Role permissions Conditional Access Pilih jawaban Identity service Second factor Access policies Role permissions RBAC Pilih jawaban Identity service Second factor Access policies Role permissions
★ Simpan
! Tandai salah
Entra ID is the identity service, MFA adds factors, Conditional Access evaluates policies, and RBAC grants role permissions.
Soal 11
What is Microsoft Defender for Cloud?
Pilih jawaban
A DNS service A storage service A CDN Security posture management and workload protection
★ Simpan
! Tandai salah
Defender for Cloud improves posture and protects workloads. DNS, storage, and CDN are different.
Soal 12
What is Azure Firewall?
Pilih jawaban
A load balancer A managed network firewall service A database A DNS zone
★ Simpan
! Tandai salah
Azure Firewall filters network traffic. Databases, DNS zones, and load balancers are different.
Soal 13
What is Azure DDoS Protection?
Pilih jawaban
Protection against distributed denial-of-service attacks A backup service A DNS service A monitoring alarm
★ Simpan
! Tandai salah
DDoS Protection mitigates volumetric attacks. Backups, DNS, and alarms are different.
Soal 14
What is Azure WAF?
Pilih jawaban
A storage account A database A web application firewall A virtual machine
★ Simpan
! Tandai salah
WAF protects web applications from common attacks. VMs, storage, and databases are resources.
Soal 15
What is a security baseline?
Pilih jawaban
A storage container A recommended configuration for security A firewall rule A DNS record
★ Simpan
! Tandai salah
Security baselines define recommended settings. Firewall rules, DNS records, and containers are different.
Soal 16
What is secure score?
Pilih jawaban
A network route A database A backup A measure of security posture
★ Simpan
! Tandai salah
Secure score measures how well an environment follows security recommendations. Routes, databases, and backups are different.
Soal 17
What is just-in-time VM access?
Pilih jawaban
Always open ports Disabling VMs Creating DNS records Temporarily opening required ports for a limited time
★ Simpan
! Tandai salah
JIT access opens ports only when needed. Always-open ports, disabled VMs, and DNS are different.
Soal 18
What is adaptive application control?
Pilih jawaban
A load balancer An allowlist of applications that can run on VMs A firewall A DNS service
★ Simpan
! Tandai salah
Adaptive application control builds application allowlists. Firewalls, DNS, and load balancers are different.
Soal 19
What is a vulnerability assessment?
Pilih jawaban
Scanning systems for weaknesses Storing data Resolving DNS Load balancing traffic
★ Simpan
! Tandai salah
Vulnerability assessments find weaknesses. Storage, DNS, and load balancing are different.
Soal 20
Match each platform protection concept to its purpose.
Defender for Cloud Pilih jawaban Security posture Network firewall DDoS defense Web app protection Azure Firewall Pilih jawaban Security posture Network firewall DDoS defense Web app protection DDoS Protection Pilih jawaban Security posture Network firewall DDoS defense Web app protection WAF Pilih jawaban Security posture Network firewall DDoS defense Web app protection
★ Simpan
! Tandai salah
Defender manages posture, Firewall filters traffic, DDoS Protection defends against attacks, and WAF protects web apps.
Soal 21
What is Azure Key Vault?
Pilih jawaban
A DNS service A CDN A secure store for secrets, keys, and certificates A database
★ Simpan
! Tandai salah
Key Vault stores secrets, keys, and certificates. Databases, DNS, and CDNs are different.
Soal 22
What is a secret in Key Vault?
Pilih jawaban
A model A firewall rule A network route A sensitive value such as a password or connection string
★ Simpan
! Tandai salah
Secrets are sensitive strings like passwords. Models, firewall rules, and routes are different.
Soal 23
What is transparent data encryption?
Pilih jawaban
Encrypting database files at rest Encrypting network packets Creating backups Filtering traffic
★ Simpan
! Tandai salah
TDE encrypts database files at rest. Network encryption, backups, and filtering are different.
Soal 24
What is encryption at rest?
Pilih jawaban
A firewall Encrypting stored data Encrypting data in transit A DNS record
★ Simpan
! Tandai salah
Encryption at rest protects stored data. Transit encryption, DNS, and firewalls are different.
Soal 25
What is encryption in transit?
Pilih jawaban
Filtering traffic Encrypting data while it moves between systems Encrypting stored files Creating backups
★ Simpan
! Tandai salah
Transit encryption protects moving data, usually with TLS. At-rest encryption, backups, and filters are different.
Soal 26
What is a certificate used for?
Pilih jawaban
Establishing trust for TLS and authentication Storing files Filtering traffic Creating reports
★ Simpan
! Tandai salah
Certificates support TLS and authentication. Files, traffic filters, and reports are different.
Soal 27
What is a customer-managed key?
Pilih jawaban
A Microsoft-managed key only A DNS record A firewall rule An encryption key you control in Key Vault
★ Simpan
! Tandai salah
Customer-managed keys are controlled by the customer. Microsoft-managed keys, DNS, and firewall rules are different.
Soal 28
What is data masking?
Pilih jawaban
Deleting data Creating backups Hiding sensitive data in query results Encrypting all data
★ Simpan
! Tandai salah
Data masking hides sensitive values in results. Encryption, deletion, and backups are different.
Soal 29
What is Defender for Storage?
Pilih jawaban
Threat detection for Azure Storage A DNS service A load balancer A backup
★ Simpan
! Tandai salah
Defender for Storage detects threats in storage accounts. DNS, load balancers, and backups are different.
Soal 30
Match each data protection concept to its purpose.
Key Vault Pilih jawaban Secure store Sensitive value Database encryption Your own key Secret Pilih jawaban Secure store Sensitive value Database encryption Your own key TDE Pilih jawaban Secure store Sensitive value Database encryption Your own key Customer-managed key Pilih jawaban Secure store Sensitive value Database encryption Your own key
★ Simpan
! Tandai salah
Key Vault stores secrets, secrets are sensitive values, TDE encrypts databases, and customer-managed keys are owned by you.
Soal 31
What is a network security group?
Pilih jawaban
A database A DNS zone A load balancer Rules that filter traffic to and from resources
★ Simpan
! Tandai salah
NSGs filter traffic with allow and deny rules. Databases, DNS zones, and load balancers are different.
Soal 32
What is a private endpoint?
Pilih jawaban
A DNS record A firewall Private access to an Azure service from your VNet A public website
★ Simpan
! Tandai salah
Private endpoints give services private IP addresses in a VNet. Public sites, DNS, and firewalls are different.
Soal 33
What is Azure VPN Gateway?
Pilih jawaban
A CDN An encrypted tunnel between networks A database A storage service
★ Simpan
! Tandai salah
VPN Gateway sends encrypted traffic over the internet. Databases, storage, and CDNs are different.
Soal 34
What is ExpressRoute?
Pilih jawaban
A private connection to Azure A public internet route A DNS record A load balancer
★ Simpan
! Tandai salah
ExpressRoute provides private connectivity to Azure. Public internet, DNS records, and load balancers are different.
Soal 35
What is network segmentation?
Pilih jawaban
Deleting firewalls Creating DNS records Isolating workloads into separate networks Merging all networks
★ Simpan
! Tandai salah
Segmentation isolates workloads to limit blast radius. Merging, deleting firewalls, and DNS are different.
Soal 36
What is a service tag?
Pilih jawaban
A VM name A database A storage account A group of IP prefixes for an Azure service
★ Simpan
! Tandai salah
Service tags represent Azure service IP ranges. VM names, databases, and storage accounts are different.
Soal 37
What is an application security group?
Pilih jawaban
A load balancer Groups VMs by application for security rules A DNS record A firewall
★ Simpan
! Tandai salah
ASGs group VMs by application. DNS records, firewalls, and load balancers are different.
Soal 38
What is Azure Bastion?
Pilih jawaban
Managed RDP and SSH access without public IPs A public website A database A storage service
★ Simpan
! Tandai salah
Bastion provides secure remote access without exposing public IPs. Websites, databases, and storage are different.
Soal 39
What is a private DNS zone?
Pilih jawaban
A public DNS record A firewall A load balancer DNS resolution within a virtual network
★ Simpan
! Tandai salah
Private DNS zones resolve names inside a VNet. Public records, firewalls, and load balancers are different.
Soal 40
Match each network security concept to its purpose.
NSG Pilih jawaban Traffic filter Private access Encrypted tunnel Secure remote access Private endpoint Pilih jawaban Traffic filter Private access Encrypted tunnel Secure remote access VPN Gateway Pilih jawaban Traffic filter Private access Encrypted tunnel Secure remote access Bastion Pilih jawaban Traffic filter Private access Encrypted tunnel Secure remote access
★ Simpan
! Tandai salah
NSGs filter traffic, private endpoints provide private access, VPN Gateway tunnels traffic, and Bastion enables secure remote access.
Soal 41
What is Microsoft Sentinel?
Pilih jawaban
A cloud SIEM and SOAR service A DNS service A storage service A CDN
★ Simpan
! Tandai salah
Sentinel provides security information and event management plus orchestration. DNS, storage, and CDN are different.
Soal 42
What is a detection rule in Sentinel?
Pilih jawaban
A DNS record A load balancer A rule that triggers alerts from data A firewall rule
★ Simpan
! Tandai salah
Detection rules generate alerts from analytics. Firewall rules, DNS records, and load balancers are different.
Soal 43
What is an incident in Sentinel?
Pilih jawaban
A VM A storage account A group of related alerts A single log
★ Simpan
! Tandai salah
Incidents group related alerts for investigation. Logs, VMs, and storage accounts are different.
Soal 44
What is an automation rule?
Pilih jawaban
A load balancer Automates incident response tasks A firewall A DNS record
★ Simpan
! Tandai salah
Automation rules run response actions on incidents. Firewalls, DNS, and load balancers are different.
Soal 45
What is a workbook in Sentinel?
Pilih jawaban
A database A firewall A DNS zone Interactive visualizations of security data
★ Simpan
! Tandai salah
Workbooks display interactive charts and dashboards. Databases, firewalls, and DNS zones are different.
Soal 46
What is a data connector?
Pilih jawaban
Connects data sources to Sentinel A network cable A storage account A DNS record
★ Simpan
! Tandai salah
Data connectors bring logs into Sentinel. Cables, storage accounts, and DNS records are different.
Soal 47
What is a playbook?
Pilih jawaban
A firewall An automated response workflow using Logic Apps A report A dashboard
★ Simpan
! Tandai salah
Playbooks automate responses with Logic Apps. Reports, dashboards, and firewalls are different.
Soal 48
What is Azure Monitor?
Pilih jawaban
A DNS service A CDN A storage service Collects logs and metrics from Azure resources
★ Simpan
! Tandai salah
Azure Monitor collects monitoring data. DNS, CDN, and storage are different.
Soal 49
What is KQL?
Pilih jawaban
A firewall A DNS protocol A query language for Azure logs A programming framework
★ Simpan
! Tandai salah
KQL queries log data in Azure Monitor and Sentinel. Frameworks, firewalls, and DNS protocols are different.
Soal 50
Match each security operations concept to its purpose.
Sentinel Pilih jawaban SIEM/SOAR Trigger alerts Automated response Visualization Detection rule Pilih jawaban SIEM/SOAR Trigger alerts Automated response Visualization Playbook Pilih jawaban SIEM/SOAR Trigger alerts Automated response Visualization Workbook Pilih jawaban SIEM/SOAR Trigger alerts Automated response Visualization
★ Simpan
! Tandai salah
Sentinel is SIEM/SOAR, detection rules trigger alerts, playbooks automate responses, and workbooks visualize data.
Soal 51
What is Azure Policy?
Pilih jawaban
A load balancer Rules that enforce compliance on resources A database A DNS service
★ Simpan
! Tandai salah
Azure Policy enforces organizational rules. Databases, DNS, and load balancers are different.
Soal 52
What is an initiative?
Pilih jawaban
A single policy A storage account A DNS zone A group of related Azure policies
★ Simpan
! Tandai salah
Initiatives group policies for a common goal. Single policies, storage accounts, and DNS zones are different.
Soal 53
What is Azure Blueprints?
Pilih jawaban
Packages of governance artifacts for environments A firewall A database A CDN
★ Simpan
! Tandai salah
Blueprints package policies, roles, and resources. Firewalls, databases, and CDNs are different.
Soal 54
What is a compliance standard?
Pilih jawaban
A DNS record A storage container A regulatory framework that resources must meet A firewall rule
★ Simpan
! Tandai salah
Compliance standards are frameworks like ISO or NIST. Firewall rules, DNS records, and containers are different.
Soal 55
What is Microsoft Purview?
Pilih jawaban
A load balancer A CDN Data governance and compliance solutions A DNS service
★ Simpan
! Tandai salah
Purview provides data governance and compliance. DNS, load balancers, and CDNs are different.
Soal 56
What is a resource tag?
Pilih jawaban
A database A metadata label for organization and billing A firewall rule A DNS record
★ Simpan
! Tandai salah
Tags organize resources and support cost tracking. Firewall rules, DNS records, and databases are different.
Soal 57
What is a management group?
Pilih jawaban
A virtual machine A storage account A DNS zone A hierarchy for applying policies and governance
★ Simpan
! Tandai salah
Management groups create a hierarchy for policy and governance. VMs, storage, and DNS zones are resources.
Soal 58
What is an audit policy?
Pilih jawaban
A policy that monitors and logs compliance A policy that blocks resources A firewall A load balancer
★ Simpan
! Tandai salah
Audit policies monitor and log noncompliance. Deny policies block resources, and firewalls or load balancers are different.
Soal 59
What is a deny policy?
Pilih jawaban
A storage container A policy that blocks noncompliant resource creation A policy that only logs A DNS record
★ Simpan
! Tandai salah
Deny policies prevent noncompliant resources. Logging-only policies, DNS records, and containers are different.
Soal 60
Match each governance concept to its purpose.
Azure Policy Pilih jawaban Enforce rules Policy group Governance package Data governance Initiative Pilih jawaban Enforce rules Policy group Governance package Data governance Blueprint Pilih jawaban Enforce rules Policy group Governance package Data governance Purview Pilih jawaban Enforce rules Policy group Governance package Data governance
★ Simpan
! Tandai salah
Azure Policy enforces rules, initiatives group policies, Blueprints package governance, and Purview governs data.