AZ-500 exam dumps

AZ-500 practice question 17 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 17

Single answer

You are a Security Engineer at Contoso, responsible for protecting administrative access to Azure resources. To reduce risks, the company wants to require multi-factor authentication (MFA) for privileged users and block legacy authentication methods that do not support modern MFA prompts. Which action should you take to meet this requirement?

  1. A

    Enable Security Defaults in Azure AD for the entire tenant

  2. B

    Create an Azure AD Conditional Access policy that specifically targets privileged roles, requires MFA, and blocks legacy authentication

  3. C

    Assign MFA to each privileged user individually through the MFA service settings

  4. D

    Implement a custom script that checks user sign-ins and manually enforces MFA every time

Show answer and explanation

Correct answer: B

Explanation

Using Azure AD Conditional Access policies is the most effective way to enforce MFA for privileged roles and block legacy authentication. You can configure policies that target specific roles (e.g., Global Administrator, Owner, or Contributor), require MFA, and deny older protocols that do not support modern authentication. This aligns with Microsoft best practices for securing cloud environments as detailed in the Azure Active Directory documentation on Conditional Access (https://learn.microsoft.com/azure/active-directory/conditional-access/).

  • A. Incorrect.

    Option 1: Enable Security Defaults in Azure AD. While Security Defaults do enforce MFA, they are broader in scope and do not allow granular targeting of privileged roles nor specific blocking of legacy authentication. This might disrupt other user scenarios in your environment.

  • B. Correct.

    Option 2: Create an Azure AD Conditional Access policy that specifically targets privileged roles, requires MFA, and blocks legacy authentication. This is correct because it provides precise control over which roles need MFA and explicitly blocks older protocols, ensuring only modern clients that support MFA are used.

  • C. Incorrect.

    Option 3: Assign MFA to each privileged user individually through the MFA service settings. This approach can become cumbersome at scale, lacks advanced conditions, and does not inherently block legacy authentication methods.

  • D. Incorrect.

    Option 4: Implement a custom script that checks user sign-ins and manually enforces MFA every time. Custom scripts are not a recommended or scalable approach for enforcing MFA. Azure AD Conditional Access is the built-in solution with robust controls and reporting.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam