Scenario 01 A company has funds for one ransomware-resilience project this quarter. What should the architect establish first?
A new endpoint vendor Business-critical processes, dependencies, RTOs and RPOs A larger SIEM retention tier A quarterly phishing simulation
Scenario 02 Which evidence most strongly demonstrates that a ransomware recovery design works?
A documented backup policy A successful backup job A timed restore exercise including identity, network and application dependencies An immutable-storage product license
Scenario 03 A hybrid organization has fragmented incident queues across Microsoft security products. What is the most important architecture outcome?
Copy every alert into email Centralize incident correlation and response ownership in the security operations workflow Retain every log indefinitely Give all analysts Global Administrator
Scenario 04 Administrators permanently hold broad roles because emergency changes are common. Which design best reduces risk without blocking urgent work?
Shared administrator accounts Permanent roles protected only by passwords Just-in-time elevation, approval where appropriate, strong authentication and emergency-access accounts Disable audit logging during emergencies
Scenario 05 A company needs one view of security posture across Azure, AWS and on-premises servers. What should guide the recommendation?
Use Azure Policy alone for every environment Connect supported environments to a posture-management plane and define ownership for remediation Export screenshots monthly Move every workload to Azure first
Scenario 06 A sensitive PaaS workload must not be reachable over the public internet. Which architecture direction is strongest?
Rely on a long random hostname Use private connectivity, controlled name resolution and explicit egress paths Allow public access from every corporate IP Hide the service behind a client-side secret
Scenario 07 Which decision best reflects Zero Trust for access to an administrative application?
Trust all devices on the office network Verify identity, device and risk signals for each access decision and limit the resulting session Require one annual password change Permit access whenever the source IP is familiar
Scenario 08 A team wants to apply protection according to data sensitivity. What must happen before selecting encryption and DLP controls?
Classify and discover the data and map its flows Buy the highest product tier Encrypt only archived data Block every external recipient
Scenario 09 An API is moving from pilot to production. Which recommendation best addresses lifecycle risk?
Run a penetration test once and make no further changes Combine identity, secrets management, gateway policy, logging and repeatable security testing in delivery Store a shared API key in the mobile app Depend only on the cloud provider default settings
Scenario 10 A generative-AI application can retrieve internal documents. What is the most important architecture principle?
The model should see all documents to improve accuracy Retrieval must enforce the requesting user’s authorization and preserve data classification boundaries Prompt instructions replace access controls Logging should store every retrieved document in full
Answered 0 of 10
Score my readiness