Microsoft SC-500 Security Copilot practice questions
Microsoft · SC-500 · 300 questions
Original practice questions for Microsoft SC-500 Security Copilot.
This course contains the use of artificial intelligence.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
Domain 1: Microsoft Defender for AI & Copilot Security · 47 questions
- A security engineer is configuring Azure AI Content Safety for a company's customer-facing chatbot built on Azure OpenAI Service. The engineer needs to detect and block prompt injection attacks where end users attempt to override the system prompt. Which feature should be enabled in Azure AI Content Safety?
- An organization has deployed Microsoft Copilot for Microsoft 365. The security team wants to ensure that Copilot cannot surface files labeled 'Confidential - Finance' to users who do not have the appropriate sensitivity label permissions. Which configuration achieves this outcome?
- A security operations team is using Microsoft Security Copilot to investigate a suspected phishing campaign. The analyst wants Security Copilot to automatically retrieve related indicators from Microsoft Defender Threat Intelligence. Which Security Copilot capability enables this integration?
- Microsoft Defender for Cloud has detected potential threats against an Azure OpenAI Service deployment. The security team wants to enable AI-specific threat protection plans in Defender for Cloud. Which Defender plan must be enabled to receive AI workload security alerts?
- A company's security team needs to review all interactions users have with Microsoft Copilot for Microsoft 365, including the prompts submitted and responses generated, to investigate a potential policy violation. Which Microsoft service provides access to this audit data?
- An organization is deploying an AI workload on Azure and wants to use Microsoft Defender for Cloud's AI security posture management capabilities. The security team needs to identify misconfigurations in their Azure OpenAI deployments. Which Defender for Cloud feature surfaces AI-specific security recommendations?
- A red team has demonstrated that an attacker can embed hidden instructions inside a document that a user uploads to a Copilot-powered assistant, causing the assistant to perform unauthorized actions. What type of attack is this, and what Azure AI Content Safety feature mitigates it?
- A security engineer is configuring Microsoft Security Copilot and needs to ensure that analyst-created promptbooks are only accessible to members of the Security Operations Center team. Which feature in Security Copilot supports this access control?
- A security engineer is using Microsoft Security Copilot to investigate a ransomware incident that impacted several endpoints and may have exfiltrated data through an AI-connected pipeline. The engineer wants to use Security Copilot to generate a full incident summary, extract IOCs, and check threat intelligence in one workflow. Which Security Copilot feature should the engineer use to run this predefined multi-step investigation?
- An organization has purchased Microsoft Security Copilot and wants to restrict which analysts can submit prompts, while allowing managers to view all session outputs. Which role assignments in Microsoft Security Copilot provide these access levels?
- Microsoft Defender for Cloud has generated an alert titled 'Jailbreak attempt detected on Azure OpenAI model deployment.' A security engineer needs to investigate this alert. Which data source contains the full prompt content that triggered the alert?
- An enterprise's IT administrator needs to prevent specific Microsoft 365 user groups from accessing Microsoft Copilot for Microsoft 365. Only users in the 'AI-Approved' Entra ID group should be able to use Copilot. What is the correct administrative approach?
- A security team using Microsoft Defender for Cloud receives an alert indicating 'Credential theft from Azure OpenAI resource via metadata service.' This alert suggests an attacker on a compute resource is attempting to steal the managed identity token to call Azure OpenAI. Which Defender for Cloud plan generates this AI workload security alert?
- A SOC team wants to integrate Microsoft Security Copilot with a third-party SOAR platform (Splunk SOAR) so that Copilot can be invoked from Splunk playbooks during incident response. Which integration mechanism supports this?
- An organization in the European Union is deploying Microsoft Security Copilot and must ensure that all prompt and response data is processed and stored within EU data boundaries. Which Security Copilot configuration satisfies this requirement?
- A developer built a Copilot Studio agent that connects to enterprise data via Microsoft Graph connectors. The security team wants to ensure that the agent cannot retrieve or output content from SharePoint sites where the calling user does not have read access. Which foundational design principle ensures this?
- A security engineer wants to use Microsoft Security Copilot to identify attack paths targeting Azure OpenAI resources in the organization's environment. The engineer uses the Security Exposure Management integration within Security Copilot. What does this integration provide?
- A Defender for Cloud recommendation states that an Azure OpenAI resource has 'Public network access enabled.' The recommendation severity is 'High.' The security engineer wants to understand what specific risk this creates before remediating. Which Defender for Cloud feature provides the contextual risk reasoning for this recommendation?
- An organization uses Microsoft Copilot for Microsoft 365 and wants to generate usage reports showing which users are actively using Copilot, which Microsoft 365 apps they use it in, and how many prompts were submitted per week. Where are these reports available?
- An organization has configured Azure AI Content Safety with a custom blocklist to prevent their Azure OpenAI-powered application from generating content containing competitor brand names. A user submits a prompt containing a competitor name. The content safety API should block the response before it reaches the user. Which Azure AI Content Safety configuration step creates this custom blocking behavior?
- A security team notices that Microsoft Defender for Cloud has raised an alert for 'Anomalous access to Azure OpenAI' for a service principal that normally calls the API with consistent token counts between 500-1,000 per hour but suddenly made 50,000 calls in one hour. The team needs to determine whether this is a legitimate batch job or an attack. Which initial investigation step uses Microsoft Security Copilot most effectively?
- An organization wants to detect when Microsoft Purview AI Hub shows that users are sharing sensitive files marked with the 'Confidential' sensitivity label as inputs to Microsoft Copilot for Microsoft 365 prompts with external recipients. Which Purview AI Hub capability surfaces this oversharing risk?
- An enterprise has deployed Microsoft 365 Copilot for its legal team but wants to prevent Copilot from accessing and synthesizing content from the 'Mergers & Acquisitions' SharePoint site, which contains deal information restricted to a small subset of users. The legal team members do not have access to this site. What ensures Copilot cannot access this site for legal team users?
- An organization's compliance officer wants to implement Microsoft Security Copilot to help analysts respond to compliance questions about AI usage policies. The officer wants to create a custom promptbook with 5 sequential prompts that walk analysts through an AI compliance review checklist. After creating the promptbook, it should be available to all security analysts. Which sharing option makes the promptbook available organization-wide?
- A security engineer is reviewing Microsoft Copilot for Microsoft 365 usage logs and notices that users are submitting prompts containing customer PII. The engineer needs to prevent sensitive data from being included in Copilot prompts without blocking Copilot entirely. Which feature should the engineer configure?
- An organization has deployed Microsoft Copilot Studio to build a custom enterprise chatbot. The security team discovers the bot can be manipulated via crafted user messages to reveal internal SharePoint document contents. Which Microsoft service provides runtime protection against this type of prompt injection attack targeting Copilot Studio bots?
- A security operations team wants to use Microsoft Copilot for Security to accelerate incident triage. A new analyst asks which built-in promptbook they should use to quickly summarize a Microsoft Sentinel incident and recommend next steps. What is the correct promptbook to use?
- An organization is evaluating the risk of Microsoft 365 Copilot oversharing sensitive files with employees who lack the appropriate permissions. The CISO wants to assess which files Copilot could surface to users before deployment. Which tool provides a pre-deployment oversharing assessment?
- A security engineer is configuring Microsoft Defender for Cloud to protect an Azure OpenAI resource. They want to receive alerts when the OpenAI endpoint is accessed from a Tor exit node or anonymous proxy. Which Microsoft Defender plan must be enabled?
- During a security review of Copilot for Microsoft 365, an engineer discovers that users are using Copilot to summarize emails from external parties that contain potential phishing content. The engineer needs to ensure Copilot does not process emails flagged as phishing. What should be configured?
- A company wants to monitor how employees use Microsoft 365 Copilot and generate reports showing prompt topics and response categories for compliance review. Which Microsoft service provides this Copilot interaction audit data?
- A security engineer is tasked with assessing whether Microsoft Copilot for Security has access to the right data sources for investigating cloud threats. The engineer needs to add a plugin to connect Copilot for Security to Microsoft Defender for Cloud. Where in the Copilot for Security portal are plugins managed?
- An organization needs to restrict Microsoft 365 Copilot from returning results based on files stored in a specific SharePoint site containing merger and acquisition data. The data cannot be labeled with sensitivity labels due to technical constraints. What is the most effective approach?
- A security engineer configures Microsoft Defender for Cloud Defender for AI plan. After enabling it, alerts appear for 'Jailbreak attempt detected on Azure OpenAI endpoint.' Which underlying technology enables this detection?
- A security engineer is configuring Microsoft Copilot for Security to integrate with an on-premises SIEM. The engineer wants Copilot for Security to query on-premises security event data. Which mechanism allows Copilot for Security to access data from a non-Microsoft SIEM?
- An organization enables Microsoft Copilot for Microsoft 365 and receives reports that Copilot is surfacing confidential HR documents to non-HR employees in Teams. After investigation, the security team determines the HR documents are stored in SharePoint without proper access controls. What is the ROOT CAUSE of the oversharing issue?
- A security engineer needs to monitor all interactions between employees and Microsoft 365 Copilot for signs of policy violations, including employees attempting to get Copilot to produce content that violates the acceptable use policy. Which Microsoft service should be configured?
- An organization's security team wants to understand which Microsoft Copilot for Security capabilities require Security Compute Units (SCUs) versus which are included in existing Microsoft licenses. A new analyst asks about the billing model. What is the correct understanding?
- A healthcare organization deploys Microsoft Copilot for Microsoft 365. The legal team requires that all Copilot interactions involving Protected Health Information (PHI) be flagged for legal review before the interaction data can be deleted. Which Microsoft 365 feature achieves this?
- A security engineer configures Microsoft Defender for AI to protect an Azure OpenAI deployment. The engineer wants to ensure that the protection covers both the prompt inputs and the model responses. Which configuration in Defender for AI achieves bidirectional monitoring?
- A security engineer is configuring Copilot for Security to assist with threat hunting for AI-targeted attacks. The engineer wants to use Copilot to run a custom KQL query against Microsoft Sentinel and then analyze the results. Which Copilot for Security capability enables this workflow?
- A security engineer is reviewing the Microsoft Defender for Cloud security posture for an Azure AI Foundry deployment. Defender for Cloud shows a recommendation to 'Enable Microsoft Defender for AI.' After enabling the plan, the engineer wants to verify that the protection is active. Where can the engineer confirm that Azure OpenAI resources are being protected?
- A company wants to use Microsoft Copilot for Security to analyze a suspicious PowerShell script discovered on a server that may have been used to exfiltrate Azure OpenAI API keys. Which Copilot for Security capability allows direct analysis of the script content?
- An organization has enabled Microsoft 365 Copilot and the security team wants to understand the data residency model. A compliance officer asks where Microsoft stores Copilot for Microsoft 365 interaction data (prompts and responses). What is the correct answer?
- A security engineer is deploying Microsoft Copilot Studio with custom connectors that access internal APIs. The security team requires that authentication between Copilot Studio bots and internal APIs must use OAuth 2.0 with Entra ID, not API keys. How should the custom connector be configured?
- A security engineer discovers that Microsoft Copilot for Security is generating responses that reference stale threat intelligence that is over 12 months old. The engineer needs to ensure Copilot for Security uses the most current threat intelligence. Which configuration should be verified?
- A company's security team wants to leverage Microsoft Copilot for Security to generate a comprehensive summary of all security incidents involving Azure OpenAI resources over the past 30 days, including common attack patterns and recommended mitigations. Which Copilot for Security feature is best suited for this retrospective analysis?
Domain 2: Microsoft Entra & Identity Security · 52 questions
- A global enterprise wants to enforce Multi-Factor Authentication for all users accessing Azure AI Studio. The policy must exclude break-glass emergency accounts. The company uses Microsoft Entra ID. Which Conditional Access policy configuration is correct?
- An organization uses Azure OpenAI Service and wants to ensure that only specific service principals can call the Azure OpenAI API. The developer team should be blocked from accessing the API key directly. Which combination of controls achieves this?
- A security engineer is implementing Microsoft Entra Privileged Identity Management (PIM) for roles that grant access to sensitive AI resources. The engineer wants to require users to provide a justification and receive manager approval before being assigned the 'Cognitive Services OpenAI Contributor' role. Which PIM setting configures this?
- Microsoft Entra ID Protection has flagged a high-risk sign-in for a user who regularly accesses Azure Machine Learning Studio. The security engineer wants to automatically block high-risk sign-ins without requiring manual intervention. Which policy type in Entra ID Protection achieves this?
- An organization's AI platform team uses a user-assigned managed identity to authenticate Azure Functions to Azure OpenAI Service. A security review finds that the managed identity also has Contributor access at the subscription level from a previous misconfiguration. What is the correct remediation?
- An organization wants to implement periodic reviews of which users have access to an AI model access group in Microsoft Entra ID. If a reviewer does not respond, access should be automatically removed. Which feature implements this?
- A developer needs to authenticate an application to Azure AI Search without storing credentials. The application runs on an Azure VM. Which identity approach should be used, and which Azure AI Search role grants read-only index query access?
- A company is implementing Microsoft Entra External Identities to allow partner organizations' researchers to access an AI experimentation portal. The security team requires that partner users must satisfy the home organization's MFA before accessing the portal. Which Entra External Identities trust setting achieves this?
- An organization wants to require a secondary approval before any user can delete an Azure Machine Learning workspace or remove a private endpoint from an Azure OpenAI resource—even if that user has Owner or Contributor permissions. Which Microsoft Entra ID feature enables this approval gate for specific sensitive Azure management operations?
- A company deploys an AI application on Azure App Service. The application uses a service principal to authenticate to Azure AI services. The security team wants to prevent this service principal's tokens from being used from outside the corporate network. Which Entra ID feature enforces this restriction?
- An organization wants to prevent phishing-resistant authentication bypass for users accessing Azure Machine Learning. They require authentication methods that cannot be intercepted by adversary-in-the-middle attacks. Which Conditional Access setting enforces this requirement?
- An AI platform team uses a system-assigned managed identity for an Azure Functions app that calls Azure OpenAI. The function app has been decommissioned, and a new function app with a different managed identity will replace it. Which Entra ID access control step must be completed to ensure the old identity cannot continue calling Azure OpenAI?
- A company's AI research team regularly has visiting researchers who need temporary access to Azure ML workspace resources for 48-hour engagements. The security team wants just-in-time access with automatic expiration. Which Microsoft Entra ID capability is most appropriate?
- An enterprise is implementing Continuous Access Evaluation (CAE) for applications that consume Azure AI services. A user's account is disabled in Microsoft Entra ID while they have an active session with Azure AI services. How does CAE affect the user's session?
- A security architect is designing identity controls for a multi-tenant SaaS AI application built on Azure. The application uses Microsoft Entra External ID (B2C) for customer authentication. The architect wants to enforce MFA for all customer sign-ins through a standard policy. Which Entra External ID feature provides this?
- An organization is implementing token protection in Microsoft Entra ID Conditional Access for users accessing Azure AI Foundry. Token protection binds the token to the device. Which scenario is prevented by enabling token protection?
- A company wants to ensure that Entra ID guests (external collaborators) who access Microsoft 365 Copilot are subjected to the same MFA and compliant device requirements as internal employees. Which Entra ID Conditional Access configuration achieves this?
- A company's Microsoft Entra ID administrator wants to protect the action of removing a Conditional Access policy that enforces MFA for Azure AI Foundry, so that even Global Administrators cannot remove the policy without satisfying an additional authentication challenge. Which Entra ID feature enables this protection for administrative actions?
- A security administrator needs to create a Conditional Access policy that requires a higher authentication assurance (step-up authentication) only when users attempt to perform model deployment operations in Azure AI Foundry—not for regular read access. Which Conditional Access feature implements this step-up authentication for a specific operation?
- A company uses Azure Machine Learning with a managed online endpoint that authenticates callers using a key. The security team wants to migrate to token-based authentication using managed identities. The endpoint will be called by an Azure App Service. Which steps correctly implement this migration?
- An organization uses Microsoft Entra Permissions Management (CIEM - Cloud Infrastructure Entitlement Management) to monitor Azure AI service permissions. The security team wants to identify service principals with unused permissions to Azure OpenAI resources that have not been exercised in the past 90 days. Which Permissions Management capability provides this analysis?
- A company wants to implement Microsoft Entra Lifecycle Workflows to automatically provision and deprovision access to Azure AI Foundry resources for new hires and terminated employees. Which Lifecycle Workflow trigger and task combination correctly automates this?
- An organization needs to federate a GitHub Actions CI/CD pipeline identity with Microsoft Entra ID so the pipeline can deploy Azure OpenAI models without storing any Azure credentials in GitHub secrets. Which Entra ID feature enables this credential-free federation?
- A large enterprise uses a Microsoft Entra ID Governance access package for AI platform access. The access package includes Azure Machine Learning workspace member role, Azure OpenAI user role, and AI data store access. A business partner organization needs access to the same resources for a 6-month project. Which Entitlement Management feature allows external users to request the access package?
- A security team is implementing Entra ID PIM access reviews for the 'Cognitive Services Contributor' role. The review is quarterly, and active role assignments that are not reviewed within 30 days should be automatically removed. The security team also wants to require a justification from the reviewers. Which PIM access review settings achieve this?
- An organization's Azure OpenAI deployment is experiencing intermittent authentication failures from a legitimate application. The security team suspects the issue is caused by the application's Azure AD token expiring during long-running operations. Which application authentication best practice prevents this?
- A security engineer needs to implement Privileged Identity Management (PIM) for a group of Azure subscription owners. The requirement states that activation must require approval and must generate an approval request to two specific managers. How should PIM be configured?
- Microsoft Entra ID Protection reports a 'Leaked credentials' risk detection for a user account. The organization has a Conditional Access policy that requires MFA for medium and high user risk. The compromised user successfully authenticates with MFA and continues working. What additional remediation step should the security team take?
- An organization uses Microsoft Entra ID Governance Access Packages to manage external partner access. A security engineer needs to ensure that external users automatically lose access when their access package assignment expires, without requiring manual intervention. Which feature should be configured?
- A company has hybrid identity with Microsoft Entra Connect. The security team detects a Golden Ticket attack against the on-premises Active Directory. After remediating the on-premises compromise, which Microsoft Entra ID action is required to prevent the attacker from using synced credentials?
- A security engineer is configuring Microsoft Entra Conditional Access for an application that processes financial data. The policy must enforce that access is granted only when users are on compliant devices AND connecting from a named location AND have low sign-in risk. What grant controls and conditions must be set?
- A security engineer reviews Microsoft Entra ID Protection and sees multiple 'Anonymous IP address' sign-in risk detections for a service account used by an on-premises application for API calls. What is the most likely cause and appropriate remediation?
- An organization needs to implement Microsoft Entra ID entitlement management so that when an employee transfers from the Sales department to Engineering, their Sales access is automatically removed and Engineering access is granted. Which entitlement management feature enables this automation?
- A security engineer is investigating a Microsoft Entra ID sign-in log and notices a user has a 'Token issuer anomaly' risk detection. What does this detection indicate?
- A global organization needs to configure Microsoft Entra External ID for their AI-powered customer portal. External customers must authenticate using their Google or Facebook identities. The security team requires that all external user sign-ins are subject to risk evaluation. How should this be configured?
- A security engineer needs to configure Microsoft Entra ID to require re-authentication for all users when they access a sensitive AI application after being inactive for more than 30 minutes. Which Conditional Access feature should be configured?
- An organization uses Microsoft Entra Verified ID for its AI hiring platform. External candidates must present verifiable credentials from their educational institution before accessing the platform. A security engineer needs to ensure that the issuer (university) of the credential is trusted. How is trust established in Microsoft Entra Verified ID?
- A security engineer is implementing Microsoft Entra ID Protection for a financial institution. The engineer needs to configure the user risk remediation to allow users to self-remediate high user risk by performing password reset and MFA, rather than requiring IT helpdesk involvement. What must be configured?
- A company implements Microsoft Entra ID Cross-Tenant Synchronization to share identities between its parent company and a recently acquired subsidiary's Entra ID tenant. The security team needs to ensure that only the subsidiary's AI research team is synchronized to the parent tenant. What must be configured?
- A security engineer is reviewing an Entra ID application registration used by an AI model training pipeline. The application has the 'Application.ReadWrite.All' permission granted as an application permission (not delegated). A security review flags this as high risk. What is the specific risk this permission poses?
- A security engineer needs to configure Microsoft Entra ID to prevent service accounts used by AI workloads from being modified or deleted by Azure subscription owners. The service accounts are represented as workload identities (service principals). Which Microsoft Entra ID feature prevents unauthorized modification of these service principals?
- A security engineer needs to implement Microsoft Entra ID Application Proxy to publish an internal AI web application securely for remote workers, without requiring a VPN. The AI application uses Windows Integrated Authentication (WIA) for on-premises users. How should Kerberos Constrained Delegation (KCD) be configured for Application Proxy?
- A security team needs to implement Microsoft Entra Permissions Management (CIEM) to identify and remediate over-privileged AI service identities across their Azure subscriptions. After a permissions discovery scan, the team finds several managed identities with unused permissions. Which Permissions Management action remediates over-privileged identities while maintaining operational continuity?
- A security engineer is implementing the Microsoft Cloud Security Benchmark (MCSB) controls for an Azure AI platform deployment. The MCSB control 'IM-1: Use centralized identity and authentication system' requires all service-to-service authentication to use Entra ID. A legacy AI service component uses username/password authentication with a local account. Which migration path aligns with the MCSB IM-1 control?
- An organization implements Microsoft Entra ID Governance entitlement management for a partner company that needs access to an AI analytics portal. The partner company does not have Microsoft Entra ID. How should external access be configured?
- A security engineer needs to configure Microsoft Entra ID to prevent AI automation service accounts from being used interactively (by humans logging in with the service account credentials). Which Microsoft Entra ID feature directly blocks interactive sign-in for service accounts?
- A security engineer is implementing Microsoft Entra ID Password Protection to prevent users and AI automation scripts from using weak or organization-specific banned passwords when rotating credentials. The organization has an on-premises Active Directory. Which component must be deployed to extend Entra ID Password Protection to on-premises AD?
- An organization uses Microsoft Entra ID to manage access to their Azure AI Foundry environments (development, staging, production). The security team needs to ensure that changes to production AI model deployments require approval from two members of the AI Security Review team. Which Microsoft Entra feature provides this approval workflow for Azure resource modifications?
- An organization's AI operations team wants to implement a self-service model to allow data scientists to request access to production AI model deployment permissions via Microsoft Entra ID Governance. The request must trigger an automated security review that checks whether the requester has completed required AI security training. Which Microsoft Entra ID Governance capability supports this requirement?
- A security engineer is implementing Microsoft Entra ID Application Proxy for an internal AI dashboard application. The application uses OAuth 2.0 for authentication. The engineer needs to configure pre-authentication so that only authenticated Entra ID users can reach the application. Which Application Proxy pre-authentication mode should be configured?
- A security engineer needs to configure Microsoft Entra ID to enforce that all OAuth 2.0 applications accessing Azure OpenAI must use the authorization code flow with PKCE (Proof Key for Code Exchange) instead of the implicit flow. Which Entra ID configuration enforces this requirement?
- A security engineer is reviewing Microsoft Entra ID sign-in logs for an AI pipeline service account. The logs show sign-ins using 'Seamless Single Sign-On' from an IP address in an unexpected country. The service account is supposed to run only in Azure datacenters. What is the most appropriate immediate action?
Domain 3: Microsoft Purview for AI Compliance · 47 questions
- An organization is using Microsoft Purview AI Hub to monitor Microsoft Copilot for Microsoft 365 interactions. The security team wants to identify instances where users are submitting prompts that contain credit card numbers. Which Purview capability within AI Hub provides this detection?
- A healthcare organization needs to prevent Microsoft 365 Copilot from generating responses that include patient health information (PHI) when users ask Copilot to summarize documents. Which Microsoft Purview feature should be configured?
- A compliance officer needs to assess the organization's readiness against the NIST AI Risk Management Framework using Microsoft tools. Which Microsoft Purview feature provides pre-built assessments mapped to AI-specific regulatory frameworks?
- An organization wants to apply mandatory sensitivity labels to all content generated by Microsoft 365 Copilot. The policy should inherit the highest sensitivity label of any documents referenced during a Copilot session. Which Purview feature enables label inheritance for Copilot-generated content?
- A financial services company uses Microsoft 365 Copilot and must prevent the AI from surfacing salary data stored in SharePoint to users outside the Human Resources department. Users in HR have a specific Microsoft Entra ID group. Which combination of controls enforces this restriction?
- A company needs to configure Microsoft Purview Information Barriers to prevent Microsoft 365 Copilot from surfacing information between two business units that must remain informationally separated due to regulatory requirements. Which Purview feature implements this separation for Copilot?
- An organization needs to implement eDiscovery on Copilot for Microsoft 365 interactions for a legal hold related to a regulatory investigation. An in-scope employee used Copilot extensively. Where are Copilot interaction logs stored for eDiscovery purposes?
- A security engineer is configuring a Microsoft Purview Communication Compliance policy to detect when employees use Microsoft Copilot for Microsoft 365 to generate content that contains discriminatory language. Which configuration is required?
- A data governance team needs to catalog all datasets used for training AI models in Azure Machine Learning to track data lineage, ownership, and sensitivity classification. Which Microsoft service provides data catalog capabilities that integrate with Azure Machine Learning for lineage tracking?
- An organization must retain all Microsoft 365 Copilot interaction logs for 7 years to satisfy financial industry regulatory requirements. Which Microsoft Purview feature enforces this retention period?
- A healthcare organization needs to automatically detect medical record numbers (MRN) in content processed by Azure OpenAI Service via the Azure OpenAI REST API. The organization has a proprietary MRN format that does not match any built-in Microsoft sensitive information types. Which Purview feature enables this custom detection?
- A security team has configured Microsoft Purview Insider Risk Management to detect when employees in the AI research division download unusually large volumes of AI model files and scripts near their resignation date. Which insider risk policy template is most appropriate for this scenario?
- An organization wants to apply sensitivity labels directly to Azure Machine Learning models (model artifacts) stored in Azure Blob Storage. What is the correct approach using Microsoft Purview?
- A financial services organization has configured Microsoft Purview Data Loss Prevention to prevent Azure OpenAI from returning responses that contain credit card numbers. The DLP policy is in test mode and the security team wants to verify it is detecting credit card numbers correctly before switching to enforcement mode. Where can the team view DLP policy match reports?
- An organization needs to implement Microsoft Purview Customer Key for Microsoft 365 to encrypt Copilot interaction data with organization-managed keys. What is a prerequisite for configuring Customer Key?
- A compliance team needs to review all Microsoft 365 Copilot prompts containing the word 'acquisition' to ensure no material non-public information (MNPI) is being shared with AI. Which Purview tool provides this capability?
- An organization uses Microsoft Purview Audit (Premium) and needs to retain Copilot interaction audit logs for 3 years to comply with internal AI governance policies. The default retention period for Purview Audit (Standard) logs is 90 days. What must the organization configure to achieve 3-year retention?
- An organization wants to use Microsoft Purview Exact Data Match (EDM) to prevent Azure OpenAI from generating responses that contain specific patient identifiers from their patient database (patient IDs, SSNs, and date-of-birth combinations). How does EDM differ from a standard sensitive information type for this use case?
- A security team has configured Microsoft Purview Adaptive Protection to dynamically adjust DLP policy enforcement based on a user's current insider risk level. When a user's insider risk score increases to 'Elevated,' their Copilot interactions should be restricted to prevent sensitive data from being included in prompts. How does Adaptive Protection achieve this?
- A compliance team needs to retrieve all Microsoft 365 Copilot interaction records for a specific user ([email protected]) for the period January 1–January 31, 2025, as part of an HR investigation. Which Microsoft Purview tool and configuration correctly scopes this search?
- An organization's security team has configured sensitivity labels and wants to ensure that documents stored on-premises (Windows file servers and SharePoint Server 2019) that contain AI model weights and research data are automatically classified before the data is migrated to Azure. Which Purview tool scans and classifies on-premises repositories?
- An organization wants to prevent employees from using unauthorized consumer AI tools (like public ChatGPT) on corporate devices. They want to block uploads of sensitive files to these services while allowing approved enterprise AI tools. Which Microsoft solution enforces this endpoint-level control?
- A compliance officer needs to create a custom compliance assessment in Microsoft Purview Compliance Manager to track the organization's implementation of internal AI governance controls that are not part of any standard regulatory framework. Which Compliance Manager feature enables this?
- A healthcare organization is using Microsoft Purview Communication Compliance to detect when employees share patient information through Microsoft Teams. The policy should also cover Microsoft 365 Copilot interactions for the same employees. Which communication compliance policy configuration scope includes both Teams messages and Copilot interactions?
- An organization wants to automatically apply sensitivity labels to new files uploaded to a SharePoint Online document library that is used to store AI training datasets. The labels should be applied based on sensitive information type detection (SSN, financial account numbers). Without requiring users to manually label files. Which Purview feature achieves this?
- An organization uses Microsoft Purview to classify data processed by Azure OpenAI. A security engineer must configure a DLP policy that prevents Azure OpenAI API responses containing credit card numbers from being returned to the calling application. Which Microsoft Purview capability supports this scenario?
- A compliance officer needs to demonstrate to auditors that the organization's use of Microsoft 365 Copilot complies with GDPR data residency requirements. Which Microsoft Purview capability provides the evidence needed?
- A data engineer builds a pipeline that feeds customer data to an Azure Machine Learning model for churn prediction. The security team needs to ensure that training data containing personal information is identified and tracked for data lineage purposes. Which Microsoft Purview feature should be used?
- A security engineer is configuring Microsoft Purview sensitivity labels for documents that will be used as grounding data for an Azure OpenAI RAG solution. The requirement is that documents labeled 'Highly Confidential' cannot be retrieved and used as grounding context by the AI. How should this be enforced?
- A compliance team needs to create a retention policy in Microsoft Purview that ensures AI-generated content from Microsoft Copilot for Microsoft 365 is retained for 7 years for regulatory compliance. Where in Microsoft Purview should this policy be configured?
- A security engineer configures the Microsoft Purview AI Hub and notices that some AI interactions are categorized as 'Sensitive information detected' but no policy action was taken. What is the most likely reason?
- An organization requires that AI-generated content used in regulatory filings must be immutably preserved as a record. A compliance engineer needs to configure Microsoft Purview so that these documents cannot be modified or deleted during the retention period. Which Microsoft Purview feature should be used?
- A security engineer needs to configure Microsoft Purview Information Protection to automatically classify and label documents generated by an Azure OpenAI GPT-4 model when they contain financial projections, without user interaction. Which Microsoft Purview feature enables automatic labeling of AI-generated content stored in SharePoint?
- An organization processes financial data using Azure Machine Learning. Microsoft Purview must be configured to automatically classify files uploaded to Azure Data Lake Storage Gen2 that contain International Bank Account Numbers (IBANs). The classification must happen within 24 hours of file upload. How should this be configured?
- A compliance team needs to implement Microsoft Purview Information Barriers to prevent the AI research team from communicating with the trading floor team to avoid insider trading risks. After configuring information barrier policies, users report that Microsoft Teams channel creation is failing. What is the most likely cause?
- An organization uses Azure Machine Learning to build AI models that process employee performance data. The legal team requires that any model trained on this data must have a documented data processing impact assessment. Which Microsoft Purview feature helps create and track this documentation?
- A security engineer needs to configure a Microsoft Purview DLP policy to prevent employees from pasting content from documents labeled 'Confidential' into Microsoft 365 Copilot prompts. Which DLP policy scope achieves this?
- A compliance team needs to search across all Microsoft 365 Copilot interaction data for a specific employee's prompts and responses as part of an HR investigation. The investigation requires content from the past 60 days. Which Microsoft tool should be used?
- A security engineer is configuring Microsoft Purview to track the consent and purpose limitation for personal data used in AI model training. The GDPR requires that data is only used for purposes consented to by data subjects. Which Microsoft Purview feature helps manage and demonstrate consent-based data processing compliance?
- A security team needs to implement Microsoft Purview Insider Risk Management to detect when data scientists are exfiltrating AI model training data before departing the company. Which insider risk policy template is most appropriate, and what triggering event should be configured?
- A compliance team is configuring Microsoft Purview to generate reports demonstrating that the organization's Azure OpenAI usage complies with the EU AI Act. The reports must show that high-risk AI systems have human oversight enabled. Which Microsoft Purview capability should be used to create this compliance report?
- An organization's AI system processes employee performance reviews. The HR team and legal counsel require that this data be classified as 'Highly Confidential - HR' in Microsoft Purview and that any access to this data must be logged. Which combination of Microsoft Purview capabilities achieves both requirements?
- A security engineer is configuring Microsoft Purview to automatically apply sensitivity labels to Azure OpenAI-generated reports stored in SharePoint Online. The reports contain financial forecasts. The engineer creates an auto-labeling policy with a trainable classifier for financial reports. The policy has been active for 14 days but no labels have been applied. What is the most likely reason?
- A compliance officer needs to demonstrate to regulators that the organization's AI training data for a credit scoring model does not contain prohibited personal attributes (race, gender, religion) that could lead to discriminatory model outcomes. Which Microsoft Purview capability can identify these attributes in the training data?
- A compliance engineer is configuring Microsoft Purview for a banking organization that uses AI for loan underwriting decisions. The EU AI Act requires that high-risk AI systems maintain logs sufficient for post-hoc auditability of individual decisions. Which combination of Azure services provides the required audit trail for each AI-driven loan decision?
- A security engineer is auditing an organization's Microsoft Purview DLP policies for AI coverage. The engineer discovers that employees are using a third-party AI chatbot (not Microsoft 365 Copilot) accessed through a web browser to submit sensitive work documents. Which Microsoft Purview and Defender feature combination should be configured to detect and block this behavior?
- A security engineer is implementing Microsoft Purview for an organization using Azure Machine Learning. The team needs to scan Azure ML datasets and automatically classify them as 'Confidential' if they contain more than 100 records with Social Security Numbers. Which Microsoft Purview component provides this threshold-based classification?
Domain 4: Azure AI Security Controls · 50 questions
- An Azure AI engineer needs to deploy Azure OpenAI Service so that it is not accessible over the public internet. All traffic must travel over the Microsoft backbone network from the application tier. Which network control achieves this?
- A company stores Azure OpenAI Service API keys in Azure Key Vault. An automated pipeline needs to retrieve the key at runtime. The pipeline runs on an Azure Container Apps environment. What is the most secure method to grant the container app access to Key Vault?
- An organization requires that all data stored in Azure AI Search be encrypted with keys managed by the organization rather than Microsoft-managed keys. Which Azure feature provides this capability?
- A security engineer needs to enforce that only identities within a specific Microsoft Entra ID tenant can access an Azure OpenAI resource. The organization wants to prevent cross-tenant token misuse. Which Azure OpenAI network and identity control should be implemented?
- A developer must grant a data science team read and write access to datasets in Azure Machine Learning but must not allow them to create or delete compute clusters. Which built-in Azure RBAC role assignment is most appropriate at the Azure Machine Learning workspace level?
- An organization wants to prevent Azure AI services (Cognitive Services) resources from being deployed outside of approved Azure regions. The governance policy should also prevent deploying AI resources without enabling private endpoints. Which Azure service enforces these requirements at scale?
- A security team needs to implement network segmentation for Azure AI services to ensure that Azure AI Search, Azure OpenAI, and Azure Machine Learning can communicate with each other privately, while remaining isolated from the internet. Which combination of controls achieves this?
- A company wants to enforce that Azure AI Content Safety content filtering is enabled and configured to block high-severity content for all Azure OpenAI deployments across the organization. Which approach enforces this at scale?
- A security engineer is hardening an Azure OpenAI resource and wants to ensure that if someone gains access to the Azure portal and attempts to delete the resource, they cannot do so without additional approval. Which Azure feature prevents accidental or unauthorized deletion?
- An Azure Machine Learning workspace must authenticate to an Azure Container Registry (ACR) to pull custom Docker images for compute environments. The security team requires that no service principal secrets are used. Which authentication method should be configured?
- An organization needs to configure Azure AI Services to use a virtual network service endpoint and restrict access to resources only within a specific subnet. After enabling the service endpoint, requests from on-premises networks connected via ExpressRoute should still be permitted. Which configuration supports this topology?
- A security team needs to audit all access to Azure Key Vault secrets used by Azure AI services. They want to generate alerts when a secret is accessed more than 100 times within one minute, which may indicate unauthorized automated secret scraping. Which Azure service combination achieves this monitoring and alerting?
- An organization is deploying an Azure OpenAI model to internal users and wants to ensure that all content filtering settings cannot be modified by the AI development team once set. Only the security team should be able to change content filter configurations. Which RBAC approach enforces this?
- A company deploys Azure AI Foundry for an internal AI application development team. The security team needs to ensure the team can create and manage AI projects within a hub but cannot modify the hub's network settings or add new connected resources. Which Azure AI Foundry role assignment is correct?
- A security engineer is configuring Azure OpenAI Service and needs to enforce that all connections use TLS 1.2 or higher. The organization also wants to disable older cipher suites. Which Azure feature controls the minimum TLS version for Azure OpenAI Service?
- An organization deploys Azure API Management (APIM) as an AI gateway in front of Azure OpenAI Service. The security team wants to enforce that no single application can consume more than 60,000 tokens per minute (TPM) across all Azure OpenAI calls routed through APIM. Which APIM policy implements this token-based rate limiting?
- A security engineer needs to implement a rotation policy for the customer-managed key (CMK) used to encrypt an Azure AI Search index. The organization requires key rotation every 90 days and automatic disabling of old key versions after 180 days. Which Azure Key Vault feature automates this lifecycle?
- An organization needs to grant a specific application identity the ability to call Azure OpenAI's chat completions API and submit batch jobs, but not the ability to view or modify resource configurations, deployments, or quotas. Which RBAC configuration achieves this least-privilege access?
- A security team wants to implement network isolation for Azure Machine Learning compute instances to prevent them from accessing the public internet while still allowing them to communicate with Azure Container Registry and Azure Blob Storage. Which Azure ML workspace configuration achieves this?
- An organization uses Azure OpenAI Service with content filtering and needs to configure the content filter to allow medical and clinical content that would normally be blocked at the default severity settings (because it contains descriptions of injuries and medication effects for a legitimate clinical decision support tool). Which approach allows this content type while maintaining safety controls?
- A company's security team wants to ensure that all Azure AI services in the organization's subscriptions have diagnostic settings configured to send logs to a central Log Analytics workspace. Which Azure tool enforces this requirement across all current and future AI service deployments?
- An organization is deploying Azure AI Foundry with a private hub that uses private endpoints. The development team reports that they can access the Azure AI Foundry portal from within the VNet but cannot access it from their home offices. The security team needs to enable remote access without exposing the hub to the public internet. Which solution achieves this?
- A security engineer wants to configure an Azure Monitor alert that fires whenever the latency of Azure OpenAI API responses exceeds 10 seconds for more than 5 consecutive minutes. This would indicate a potential denial-of-service condition or resource exhaustion. Which Azure Monitor resource provides the Azure OpenAI latency metric?
- A Defender for Cloud recommendation shows that an Azure AI Services resource has 'Managed identity not enabled,' rated as medium severity. The security team wants to remediate this across 20 Azure AI Services resources at once. Which Defender for Cloud feature enables bulk remediation?
- A security engineer is deploying an Azure OpenAI service for a healthcare application that processes PHI. The requirement mandates that the service must not use Microsoft-managed keys and all model data must be encrypted with customer-managed keys. What must be configured?
- A security architect needs to deploy an Azure AI Foundry workspace so that all training compute and inference endpoints are accessible only from within the corporate virtual network. No public endpoint exposure is acceptable. Which combination of configurations achieves this?
- A developer asks a security engineer why their Azure AI services application is getting 403 errors when using a managed identity to call Azure OpenAI. The managed identity is assigned the 'Cognitive Services OpenAI User' role on the Azure OpenAI resource. What is the most likely cause?
- A security engineer is hardening an Azure AI Search instance used in a RAG pipeline. The requirement is that data indexed by Azure AI Search must be encrypted at rest using a key that can be revoked instantly if a breach is detected. What must be configured?
- An organization needs to implement network isolation for an Azure AI Foundry hub deployed in a managed virtual network. The AI models need to access an Azure Storage account but all access must remain private. What should be configured?
- A security engineer is reviewing the access control configuration for an Azure Machine Learning workspace. Multiple data scientists need to run experiments and deploy models but should not be able to modify workspace-level settings or manage other users' permissions. Which built-in role should be assigned?
- An organization's AI application stores conversation history in Azure Cosmos DB. A security engineer must ensure the application's managed identity can only read conversation data and cannot write or delete records. Which approach achieves least-privilege access to Cosmos DB?
- A company deploys an AI chatbot on Azure that uses Retrieval-Augmented Generation. The security team wants to implement output validation to prevent the chatbot from responding with content that contradicts the organization's official policies. Which Azure AI Foundry capability enables this output guardrail?
- An organization wants to use Azure AI Language service for sentiment analysis of customer feedback. The security team requires that the service is accessed via a private endpoint and API keys are stored securely. The application runs in Azure App Service with a managed identity. What is the recommended secure configuration?
- A security engineer must configure Azure Policy to enforce that all Azure AI services (Cognitive Services, Azure OpenAI, Azure AI Search) in the organization must disable public network access. Which Azure Policy effect should be used to enforce this requirement on existing and new resources?
- A developer team needs to access an Azure OpenAI model deployment for development and testing. The security team wants to grant time-limited access that automatically expires after 8 hours without requiring manual revocation. Which approach achieves this?
- A security architect is reviewing an Azure AI Foundry deployment. The AI hub uses a user-assigned managed identity. The architect discovers the managed identity has 'Owner' rights on the resource group. What is the security risk and recommended remediation?
- An organization deploys an Azure Machine Learning workspace with a compute cluster for model training. The security team requires that all outbound traffic from training jobs must be inspected by Azure Firewall. How should this network architecture be configured?
- An organization needs to implement continuous compliance monitoring for all Azure AI resources against a custom compliance framework. The framework requires that all Azure OpenAI resources must have diagnostic logging enabled, use private endpoints, and be encrypted with customer-managed keys. Which Azure service provides continuous compliance monitoring and remediation for these requirements?
- An organization is deploying a large language model inference endpoint using Azure Machine Learning managed online endpoints. The security team requires that inference requests containing PII must be detected and logged separately for compliance purposes. What is the recommended approach to implement this within the Azure ML inference pipeline?
- A security engineer is deploying Azure AI Speech service for a customer call center transcription application. The transcribed audio contains sensitive customer PII. The security team requires that transcriptions are stored in a customer-owned storage account rather than Microsoft's storage. Which Azure AI Speech configuration achieves this?
- A security engineer needs to configure an Azure AI Language resource used for document analysis to accept requests only from a specific Azure Virtual Network subnet. Which two resources must be configured to achieve this network restriction?
- A company builds a chatbot using Azure OpenAI with a system prompt containing proprietary business logic. The security team is concerned that users could extract this system prompt through carefully crafted questions. Beyond Prompt Shield, which Azure OpenAI feature can be configured to add a layer of protection against system prompt extraction?
- An organization is implementing Azure Machine Learning with sensitive training data in Azure Data Lake Storage Gen2. The security team requires that the AML workspace's managed identity can only access specific containers in the Data Lake, not the entire storage account. How should this access be configured?
- A security engineer is configuring Azure Content Safety for a customer-facing AI application. The application serves users in multiple regions and must comply with regional content regulations. The engineer needs to configure content filtering thresholds that are stricter for the EU region compared to the US region. How should this be implemented?
- An organization wants to implement a proactive security control for their Azure OpenAI deployment that automatically blocks known malicious IP addresses identified by Microsoft threat intelligence. Which Azure native service enforces this at the network level?
- A security engineer is reviewing the access control model for a multi-model Azure AI Foundry hub that manages separate AI projects for the HR team and the Finance team. The engineer needs to ensure that HR project data scientists cannot access Finance project models and vice versa, while allowing the platform admin to manage all projects. Which Azure AI Foundry access control configuration achieves this?
- A security engineer is integrating Microsoft Defender for Cloud recommendations for Azure AI services into the organization's vulnerability management program. Defender for Cloud shows a high-severity recommendation: 'Azure AI services resources should have key access disabled (disable local authentication).' What is the security benefit of implementing this recommendation?
- A security engineer at a company using Azure OpenAI for document analysis needs to ensure that the application properly handles authentication token expiration without service disruption. The application uses a managed identity. Which Azure SDK pattern implements proper token lifecycle management?
- An organization deploys Azure AI Content Safety to moderate user inputs to a consumer-facing AI application. The content safety API returns categories including Hate, Violence, Sexual, and SelfHarm with severity levels 0-6. The security team must configure the application to block any content with Violence severity 4 or higher while allowing Violence severity 0-2 for general users, but allow all violence categories up to severity 6 for verified security researchers. How should this be implemented?
- A security engineer is implementing a Bring Your Own Key (BYOK) strategy for an Azure AI Foundry deployment. The customer-managed key is stored in Azure Key Vault. The security team requires that the key must be rotated every 90 days. Which configuration ensures automatic key rotation without service disruption to the AI Foundry workspace?
Domain 5: Threat Detection & Response for AI · 49 questions
- A security operations analyst is using Microsoft Sentinel to detect anomalous usage of Azure OpenAI Service. The analyst wants to create an analytics rule that alerts when the number of Azure OpenAI API calls from a single IP address exceeds 10,000 within one hour. Which Sentinel analytics rule type is most appropriate?
- A Microsoft Sentinel playbook must automatically isolate an Azure VM when Microsoft Defender for Endpoint detects that the VM has been used to exfiltrate data from an Azure OpenAI deployment. The playbook should trigger automatically when an incident is created. Which Sentinel feature enables automatic playbook execution?
- A threat hunter is investigating potential data exfiltration from Azure OpenAI Service. Azure OpenAI diagnostic logs are ingested into Microsoft Sentinel. The hunter wants to find all instances where the token count in a single completion response exceeded 10,000 tokens in the last 24 hours. Which KQL query correctly retrieves this data?
- An organization's security team has identified a pattern where threat actors are using compromised developer credentials to enumerate Azure OpenAI model deployments and extract prompt configurations. Which Microsoft Sentinel data connector and analytic approach best detects this reconnaissance activity?
- A security team uses Microsoft Sentinel to monitor AI-related threats. They need to create a hunting query to find users who interacted with Azure OpenAI but whose IP addresses are listed in a threat intelligence watchlist. Which Sentinel feature links the watchlist to the query?
- The security operations team receives a Microsoft Defender XDR alert indicating that an Azure OpenAI resource has been accessed using a token that originated from an IP address in a high-risk country. The team needs to contain the threat immediately. Which response action should be taken first?
- A security analyst is investigating a Microsoft Sentinel incident involving suspicious Azure OpenAI usage. The analyst wants to correlate this incident with related Microsoft Defender XDR alerts to build a complete attack timeline. Which Sentinel feature provides this cross-product correlation?
- A Microsoft Sentinel analytics rule fires an alert for a suspected Azure OpenAI abuse incident. The security team wants to ensure that entity information (the source IP address and the Azure OpenAI resource name) is automatically mapped and enriched in the incident so analysts can pivot to entity pages immediately. Which Sentinel analytics rule configuration enables this?
- A Microsoft Sentinel analytics rule for Azure OpenAI threats generates 500 false positive alerts per day for legitimate high-volume API usage from a known batch processing service. The security team wants to suppress these alerts without disabling the rule. Which Sentinel feature should be used?
- A security engineer needs to configure Microsoft Sentinel to ingest Azure OpenAI Service diagnostic logs for threat detection. What are the two required steps to enable this data flow?
- A Microsoft Sentinel analytics rule needs to detect when Azure OpenAI API calls are made using tokens from accounts that are simultaneously flagged as risky in Microsoft Entra ID Protection. Which Sentinel feature enables correlation across these two data sources?
- A Sentinel playbook is triggered when a high-severity Azure OpenAI abuse incident is created. The playbook must automatically disable the Azure OpenAI deployment that is being abused to stop ongoing data exfiltration. Which Logic Apps action accomplishes this containment?
- A Microsoft Sentinel incident involves a threat actor performing model extraction by repeatedly querying an Azure OpenAI deployment with carefully crafted inputs to reconstruct the model's behavior. The security team wants to map this attack to the MITRE ATT&CK framework. Which MITRE ATT&CK for Enterprise tactic best describes model extraction?
- An organization's SOC team wants to proactively hunt for signs that an AI model API key has been leaked and is being used from external IP addresses. Azure OpenAI diagnostic logs are in Sentinel. Which KQL hunting query approach identifies calls from IPs not seen in the previous 30 days?
- A security team is implementing a SOAR playbook to automatically enrich Microsoft Sentinel AI security incidents with threat intelligence. When a new incident is created involving an external IP address, the playbook should look up the IP in Microsoft Defender Threat Intelligence (MDTI) and add the result as a comment to the Sentinel incident. Which Logic Apps connector enables the MDTI lookup?
- A Microsoft Sentinel analytics rule needs to be created to detect when an Azure OpenAI API key stored in Azure Key Vault is accessed by a service principal that is not in a pre-approved list. The analyst has a Sentinel watchlist named 'ApprovedAIServicePrincipals' with the approved ObjectIds. Which KQL approach correctly implements this detection?
- A security engineer is building a Microsoft Sentinel hunting notebook to detect anomalous patterns in Azure OpenAI usage using machine learning-based time-series analysis. Which KQL function enables detecting statistical anomalies in the number of Azure OpenAI API calls per hour over the past 30 days?
- A Microsoft Sentinel analytics rule generates an incident when Azure OpenAI Service returns a very high number of completion tokens in a short time, potentially indicating data exfiltration. The incident response team needs to automatically notify the AI security team via Microsoft Teams when such an incident is created. Which component in the playbook sends the Teams notification?
- A security analyst is using Microsoft Sentinel's User and Entity Behavior Analytics (UEBA) to investigate an Azure AI service account that has been flagged as having anomalous activity. The UEBA engine has raised an 'Anomalous Azure resource access' insight for this service principal. Where in Sentinel can the analyst see the full UEBA profile for this entity including timeline, peer comparison, and risk score?
- An organization's Microsoft Sentinel deployment needs to detect when an Azure OpenAI model is being queried with system prompt override attempts (jailbreak patterns) in near real-time (latency under 1 minute). Which Sentinel analytics rule type provides the lowest detection latency?
- A security team is investigating a Microsoft Defender XDR incident where a device used for AI model development shows signs of compromise. The device has Azure ML SDK and Azure CLI installed. The team is concerned that the attacker may have exfiltrated Azure credentials from the development environment. Which Defender XDR investigation step directly identifies if cached Azure credentials were accessed?
- A security team wants to set up a custom threat intelligence feed of Azure OpenAI endpoint abuse indicators (malicious IP addresses that have been observed submitting jailbreak prompts at scale) and use it in Sentinel analytics rules. Which Sentinel feature is the most direct mechanism for ingesting this custom threat intelligence?
- A security team is conducting an incident response exercise for a scenario where an organization's AI model used for loan approval may have been manipulated through data poisoning to approve fraudulent applications. Which artifact should the incident response team prioritize collecting to determine if poisoning occurred?
- An organization uses Azure AI Content Safety and wants to receive real-time alerts in Microsoft Sentinel when Azure AI Content Safety detects and blocks high-severity hate content in their AI application. Azure AI Content Safety metrics and logs are sent to a Log Analytics workspace connected to Sentinel. Which Sentinel component generates these alerts?
- A Microsoft Sentinel investigation reveals that an attacker used a compromised service principal to call the Azure OpenAI management API and enumerate all model deployments, then used that information to target specific gpt-4 deployments for abuse. The analyst wants to investigate the full attack chain using Sentinel's investigation graph. Which Sentinel feature provides this visual attack chain analysis?
- A Microsoft Sentinel workspace receives alerts from Microsoft Defender for AI about anomalous usage of an Azure OpenAI endpoint. A security engineer wants to automate the response by adding the source IP to a watchlist for 24 hours. Which Microsoft Sentinel feature should be used to automate this response?
- A security analyst is threat hunting for potential model inversion attacks against an Azure OpenAI deployment. The analyst wants to find API calls where the request body contains an unusually large number of tokens compared to the average. Which Microsoft Sentinel query approach should be used?
- A security team is building a Microsoft Sentinel analytics rule to detect when an AI application service principal authenticates from an unusual geographic location. The rule should correlate Entra ID sign-in logs with a watchlist of expected service principal locations. Which KQL approach is correct?
- An organization deploys a SOAR playbook in Microsoft Sentinel triggered when a Defender for AI alert fires for suspicious Azure OpenAI usage. The playbook must automatically revoke the API key used in the suspicious request. Which Logic App connector action should be used?
- A security analyst is investigating a potential data exfiltration via an AI chatbot. The analyst suspects a user is using the chatbot to extract information from an internal knowledge base by crafting specific questions. Which Microsoft Sentinel hunting query would best identify this behavior?
- A company's Microsoft Sentinel workspace ingests Azure OpenAI diagnostic logs. The security team wants a scheduled analytics rule that fires when the same prompt is submitted more than 20 times in 1 hour from different user sessions, which could indicate automated probing. Which Microsoft Sentinel feature should be used to detect near-duplicate prompts?
- An Azure Machine Learning pipeline uses a managed online endpoint to serve a fraud detection model. The security team discovers that model prediction logs are being retained for only 30 days, insufficient for forensic investigations requiring 1-year retention. What is the most efficient solution?
- A Microsoft Sentinel analytics rule needs to detect when an Azure OpenAI model is being used to generate large volumes of similar requests in a short period, potentially indicating automated abuse. A security engineer writes a KQL query to detect this. Which KQL operator is most appropriate for identifying time-windowed frequency anomalies?
- A security engineer is building a Microsoft Sentinel playbook to respond to a Defender for AI alert about a potential data exfiltration via Azure OpenAI. The playbook must enrich the alert with information about the source IP reputation before escalating. Which Logic App connector action provides IP reputation data?
- A security team discovers that an Azure OpenAI deployment is experiencing a credential stuffing attack where attackers cycle through many API keys attempting to find valid ones. Which combination of controls in Azure API Management (APIM) and Microsoft Entra ID provides the most comprehensive protection?
- A security engineer needs to create a Microsoft Sentinel workbook that shows the geographic distribution of Azure OpenAI API calls over the past 7 days, highlighting calls from countries outside the expected usage regions. Which Microsoft Sentinel feature provides geographic visualization capabilities?
- An organization wants to implement automated threat hunting for AI systems using Microsoft Sentinel. The security team wants to schedule hunting queries to run weekly and automatically create incidents when the query returns results indicating potential AI model abuse. Which Microsoft Sentinel feature converts a hunting query into scheduled incident creation?
- A security engineer is analyzing Microsoft Sentinel incidents related to AI workloads. The engineer notices that many incidents are false positives because the Azure OpenAI diagnostic logs show legitimate batch processing jobs that spike token usage. Which Microsoft Sentinel feature allows the engineer to tune detection rules to reduce false positives from known legitimate behavior?
- A security team is responding to an incident where an attacker has stolen an Azure OpenAI API key and is making unauthorized API calls. The team has already regenerated the key. However, they need to understand what was done with the stolen key. Which data source provides the most detailed forensic information about the API calls made using the compromised key?
- An organization deploys Microsoft Sentinel to detect threats against their AI platform. The security team wants to create a detection for when an Azure OpenAI fine-tuned model is modified or deleted without proper change management. Which Microsoft Sentinel data source captures these events?
- A security engineer needs to implement continuous monitoring for configuration drift in Azure AI security controls. Specifically, the engineer needs to detect when Azure OpenAI resources have their public network access re-enabled after being configured as private-only. Which Azure service provides real-time drift detection and alerting?
- A security architect is reviewing the disaster recovery plan for an AI security monitoring system built on Microsoft Sentinel. The Sentinel workspace is in the East US region. If East US becomes unavailable, the team needs to continue ingesting AI security alerts. Which Sentinel feature supports this requirement?
- A security engineer is investigating a Microsoft Sentinel incident that correlates multiple low-severity alerts into a high-confidence incident via the Fusion detection engine. The incident involves an anomalous Azure OpenAI usage spike following a compromised service principal sign-in. The engineer wants to understand how Fusion determined these alerts are related. Where can the engineer review the Fusion correlation logic?
- A Microsoft Sentinel playbook is triggered when a Defender for AI alert fires for 'Sensitive data exposed in AI response.' The playbook must automatically post a notification to a Microsoft Teams channel with the alert details. Which Logic App action step is required for this Teams notification?
- A security engineer builds a Microsoft Sentinel analytics rule that queries AzureDiagnostics for Azure OpenAI API calls and joins with SigninLogs to identify cases where a user accesses Azure OpenAI within 5 minutes of a suspicious sign-in. The KQL query has performance issues with high query times. Which KQL optimization should be applied first?
- A security engineer is configuring Microsoft Sentinel to detect when Azure OpenAI API usage occurs outside of approved business hours (8 AM to 6 PM, Monday through Friday, UTC). The engineer writes a KQL query using AzureDiagnostics logs. Which KQL function correctly extracts the hour and day of week from TimeGenerated to filter business hours?
- A security engineer needs to configure Microsoft Sentinel to automatically close a Defender for AI incident as a false positive when the source is a known internal penetration testing team's IP addresses. The pen test team's IPs are stored in a Sentinel watchlist. Which Microsoft Sentinel feature handles incident disposition automation?
- A security engineer needs to configure Microsoft Sentinel to detect when an Azure Machine Learning model training job accesses data outside its approved dataset scope. The engineer wants to detect when the training job service principal reads data from a storage account container not in the approved list. Which data source in Sentinel captures this activity?
- An organization is building a Microsoft Sentinel analytics rule to detect potential training data exfiltration from an Azure Machine Learning workspace. The analyst wants to alert when a data scientist downloads more than 1 GB of data from the training data storage account in a single day. Which KQL approach correctly implements this volume-based detection?
Domain 6: AI Security Architecture · 55 questions
- An organization is designing a Zero Trust architecture for an internal AI assistant built on Azure OpenAI Service. The AI assistant processes confidential business data. Which Zero Trust principle is most critical to apply when a user request reaches the AI inference layer?
- A company is preparing to deploy a large language model-powered customer service bot and wants to conduct AI red-teaming before production launch. The security team is using PyRIT (Python Risk Identification Toolkit for generative AI) developed by Microsoft. What is the primary purpose of using PyRIT in this context?
- A financial institution is implementing Responsible AI governance across its enterprise AI deployments. The institution needs to ensure that AI models producing credit decisions do not exhibit unfair bias against protected demographic groups. Which Microsoft tool provides fairness assessment capabilities for AI models?
- An enterprise is establishing an AI Trust, Risk, and Security Management (AI TRiSM) program. As part of this program, the security team needs to implement continuous monitoring of AI model outputs for concept drift and anomalous behavior changes post-deployment. Which Azure service provides model monitoring capabilities for production AI models?
- An organization is developing an AI security architecture review process. When evaluating a new AI-powered application, the security team needs to assess threats specific to AI systems, such as data poisoning, model inversion, and adversarial examples. Which threat modeling methodology is most applicable to AI systems?
- A security architect is designing secure model deployment pipelines for an organization that fine-tunes foundation models using proprietary training data. The architect is concerned about supply chain attacks where a malicious actor injects backdoors into pre-trained model weights downloaded from public repositories. Which control mitigates this risk?
- An organization's AI governance committee needs to implement a structured review process before any AI system can be deployed in production. The review must assess legal and regulatory compliance, data privacy, security risks, and ethical implications. Which Microsoft framework provides guidance for structuring this governance process?
- A security team is tasked with implementing data poisoning defenses for an AI model used in fraud detection that is retrained weekly on new transaction data. Which control most directly prevents poisoned data from corrupting the model during retraining?
- A company is establishing an AI red team program and needs to define the scope of a red team exercise against their customer-facing Azure OpenAI-powered chatbot. Which elements must the scope document include to ensure a safe and legally authorized test?
- An organization's security architecture team is designing a secure AI inference infrastructure where the AI model inference API must only be accessible to a specific set of microservices within a Kubernetes cluster, and not to any other workloads. Which Zero Trust network control pattern achieves this microsegmentation?
- A company is implementing a Secure AI Development Lifecycle (SDL) for its AI products. At which phase of the SDL should threat modeling for AI-specific threats (such as prompt injection, training data poisoning, and model inversion) be performed?
- An enterprise AI governance team wants to implement a model versioning and approval process to ensure that only vetted AI models are deployed to production. Before a model is promoted, it must pass security scans, bias evaluations, and compliance checks. Which Azure service best supports implementing this approval gate in an MLOps pipeline?
- A company's AI security team is evaluating the risk of adversarial examples—inputs crafted to fool an image classification AI model used for security camera analysis. The team wants to test the model's robustness to adversarial perturbations. Which approach assesses this robustness?
- A multinational corporation is deploying AI models and must comply with the EU AI Act. The organization's AI security architect needs to classify the risk level of an AI system used for resume screening in the hiring process. Which EU AI Act risk category applies, and what are the resulting compliance obligations?
- A company purchases a third-party AI model API service to power an internal HR tool. The security team needs to assess the risk of using this external AI service. Which element is most critical to evaluate in the vendor security review for an AI API service?
- An AI security architect is implementing a privacy-preserving ML pipeline for a healthcare AI model that must learn from patient data across multiple hospitals without the data leaving each hospital's premises. Which privacy-preserving technique achieves this?
- A company has experienced a security incident where an AI model in production was found to be generating harmful outputs after what appears to be a model update. The incident response team needs to quickly roll back to the previously known-good model version. Which Azure Machine Learning feature supports this rollback?
- A company is deploying a Retrieval Augmented Generation (RAG) AI system that retrieves documents from Azure AI Search and uses Azure OpenAI to generate responses. The security team needs to implement defense-in-depth for this architecture. Which combination of controls provides comprehensive protection across the retrieval and generation layers?
- An organization is using Microsoft Counterfit to assess the security of an image recognition AI model before production deployment. The security team wants to evaluate the model's resilience to black-box adversarial attacks—where the attacker can only query the model and observe outputs, without access to model weights or architecture. Which Counterfit attack configuration represents a black-box attack?
- An enterprise AI governance committee requires that all AI models deployed in production have explainability reports generated that explain why the model made specific high-stakes decisions (e.g., loan denial, hiring rejection). Which Azure Machine Learning capability generates these explanations?
- A company is designing an AI security architecture for a multi-tenant SaaS application where different enterprise customers' data must be strictly isolated. The application uses a shared Azure OpenAI deployment. Which architectural pattern ensures tenant data isolation at the AI layer?
- A security architect is designing the identity layer for an AI system that must serve as a trusted reference for other downstream systems' security decisions. The AI system attests to its configuration state (model version, content filter settings, and security controls enabled) before downstream systems consume its outputs. Which Microsoft technology enables cryptographic attestation of a system's security configuration?
- An organization wants to implement a centralized AI API Gateway pattern to govern all AI API traffic flowing from applications to Azure OpenAI Service. The gateway must enforce rate limiting per application, centralize logging of all AI interactions, and apply content safety screening before requests reach the model. Which Azure service is best suited to implement this AI API Gateway?
- An enterprise has deployed multiple AI systems and is building an AI governance framework aligned with Microsoft's Responsible AI principles. The security team needs to define the process for reporting AI safety incidents—cases where an AI system produces harmful or unexpected outputs that affect users. Which element of the governance framework should specify the incident classification, escalation path, and post-incident review process for AI safety incidents?
- A security architect needs to implement transparency controls for an AI system that makes automated credit decisions. Regulators require that the organization be able to explain to any affected individual why they received a specific credit decision from the AI system, in plain language. Which combination of Azure services supports meeting this regulatory transparency requirement?
- An organization's AI security team wants to implement cryptographic watermarking of AI-generated content so that any text produced by their Azure OpenAI deployment can be traced back to their system if it appears in external channels without authorization. Which approach is most technically sound for implementing AI output watermarking?
- An organization is implementing a Zero Trust architecture for their AI platform on Azure. An application uses a chain of AI services where each service calls the next. The security team needs to ensure each service-to-service hop is authenticated. What is the correct approach?
- A company is conducting a red-team exercise against their internal LLM-based customer service chatbot. The red team successfully exfiltrates the system prompt by asking the model to 'repeat all previous instructions.' This represents which category of AI attack?
- An organization's AI governance framework requires implementing AI TRiSM (Trust, Risk, and Security Management). A security architect must identify which control specifically addresses the risk that an AI model's decisions cannot be explained or audited. Which AI TRiSM pillar addresses this risk?
- A security architect is designing a defense-in-depth strategy for an Azure AI solution that processes healthcare records. The architect needs to identify which control most directly addresses the risk that a malicious insider with Azure subscription Owner role could extract training data.
- A security team is implementing responsible AI governance controls for a financial services organization deploying predictive AI models. The governance framework requires a human review process for all AI-driven decisions that exceed a certain financial impact threshold. Which Azure capability best supports implementing this human-in-the-loop control?
- An organization is performing an AI security risk assessment. A security architect identifies that their RAG system could be manipulated through malicious content injected into documents that are indexed in the knowledge base. What type of attack is this, and which control should be implemented?
- A security architect is reviewing the network architecture for an Azure AI solution. The solution includes an Azure OpenAI private endpoint in a spoke VNet, APIM in a hub VNet, and on-premises clients connected via ExpressRoute. The security team requires that DNS resolution for the Azure OpenAI private endpoint works correctly for on-premises clients. What DNS configuration is required?
- A financial services company is building an AI-powered loan approval system. The AI governance team requires a formal AI risk tiering process before deployment. According to responsible AI principles and EU AI Act alignment, what risk tier would an automated loan approval AI system typically fall under?
- A company is evaluating AI security architecture for a new generative AI application. The security architect needs to implement a secure AI gateway pattern. Which architectural component sits between client applications and AI model endpoints to provide centralized security enforcement including rate limiting, authentication, content filtering, and logging?
- A security team is designing a red team exercise for an enterprise AI chatbot. The red team lead asks which category of adversarial testing specifically evaluates whether the AI model produces harmful, biased, or unsafe outputs regardless of whether the prompt was adversarial. What is this testing approach called?
- A security architect is implementing the OWASP Top 10 for LLM Applications controls for an enterprise AI application. The application is at risk of 'LLM02: Insecure Output Handling' which could lead to XSS or SQL injection via AI-generated content. Which control addresses this risk?
- An organization's AI governance policy requires that all AI models deployed in production must have documented model cards that include fairness metrics, known limitations, and intended use cases. Where in Microsoft's AI platform should these model cards be stored and managed to be discoverable by the security and compliance teams?
- A security engineer is designing the authentication architecture for a multi-tenant SaaS AI application built on Azure. Each customer tenant must be isolated and their AI interactions must not be visible to other tenants. Which Azure architecture pattern best achieves tenant isolation for the AI components?
- A security architect is implementing controls to protect against training data poisoning attacks on a machine learning pipeline in Azure. The attacker model assumes that adversaries could inject malicious records into the data lake used for training. Which combination of controls provides the most comprehensive defense?
- An enterprise AI platform team needs to implement a secure software supply chain for their AI models. The team wants to ensure that model artifacts (trained model files, ONNX exports) have not been tampered with between training and deployment. Which Azure capability supports model artifact integrity verification?
- A security engineer is reviewing the security posture of an Azure AI Foundry deployment. The Responsible AI (RAI) evaluation results show that the deployed model occasionally produces responses with high 'Groundedness' violation scores when processing certain user queries. What does this indicate about the model's behavior?
- A security engineer is implementing secure AI development practices using Azure DevOps. The organization requires that AI model training code must be scanned for hardcoded credentials and sensitive data before merging to the main branch. Which Azure DevOps feature provides this capability natively?
- A security architect is reviewing the network security design for an Azure OpenAI deployment. The organization has an on-premises proxy server that all internet traffic must pass through for inspection. The AI application running on Azure App Service needs to call Azure OpenAI via the private endpoint. How should the network route be configured?
- A compliance officer asks a security engineer about the Microsoft model for shared responsibility for AI security. The engineer needs to explain what security responsibilities remain with the customer when using Azure OpenAI as a PaaS service. Which of the following is a customer responsibility when using Azure OpenAI?
- A security architect is designing a Zero Trust architecture for an AI pipeline that processes sensitive healthcare data. The AI models must be trained in a network-isolated environment where no internet access is permitted. Which Azure Machine Learning network configuration provides a fully isolated training environment with no public internet connectivity?
- A security team is implementing the MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) framework to categorize AI-specific threats to their Azure AI platform. Which MITRE ATLAS tactic corresponds to an attacker querying a deployed model with many inputs to understand its decision boundary and reconstruct proprietary training data?
- A security engineer is implementing Microsoft's Secure Future Initiative (SFI) principles for an AI platform. The SFI principle of 'Secure by Default' requires that all security controls are enabled automatically without customer action. For Azure OpenAI, which control is an example of a 'Secure by Default' implementation?
- A financial services firm is implementing AI governance for an automated trading signal generation system. The governance board requires that all AI-generated trading signals above a certain risk threshold must be reviewed by a licensed trader before execution. This is an example of which responsible AI principle?
- A security architect needs to design a solution for detecting and preventing model theft (model extraction attacks) against an Azure OpenAI deployment used in a commercial SaaS product. Which combination of controls provides the most effective defense?
- A security engineer at a company that built a custom AI application needs to test whether their application is vulnerable to prompt injection through uploaded documents. The engineer wants to use Microsoft's open-source AI red teaming tool. Which Microsoft tool provides automated red teaming capabilities for generative AI applications?
- A security team is designing the logging strategy for an AI application built on Azure OpenAI. The application processes sensitive legal documents. The team needs to balance security visibility (logging prompt content for forensics) against privacy (not logging PII in legal documents). What approach achieves this balance?
- A security engineer is implementing threat modeling for a new Azure AI Foundry application using the STRIDE methodology. The engineering team is concerned that an attacker could submit specially crafted inputs that cause the AI model to produce outputs bypassing the organization's safety guidelines. Which STRIDE category does this threat fall under?
- A security engineer is implementing Microsoft Defender for Cloud's governance capabilities to track remediation of AI security recommendations. The CISO wants to assign owners to each AI-related recommendation and track remediation within a 30-day SLA. Which Defender for Cloud feature provides this governance workflow?
- A company's AI security team is implementing the NIST AI Risk Management Framework (AI RMF) for their Azure AI platform. The team needs to identify which AI RMF function maps to the activity of continuously monitoring deployed AI model performance for unexpected behavior changes. Which AI RMF function does this activity belong to?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by the exam vendor.