Microsoft AZ-305 Entra Identity Governance Practice Test
Topic 07 focuses on Microsoft Entra Identity Governance for the Microsoft Certified: Azure Solutions Architect Expert certification and the AZ-305 exam, using Microsoft Azure solution-architecture scenarios. For broader exam preparation, review the Microsoft Azure Solutions Architect Expert AZ-305 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
For PIM eligible assignment, which statement is accurate?
Correct Answer: B
Correct Answer
Answer B is correct because PIM eligible assignment makes a user eligible to activate a privileged role when needed instead of granting permanent active access.
Incorrect Answers
Answer A is incorrect because that description belongs to Access review, whose purpose is to remove stale or unnecessary access through recurring governance reviews.
Answer C is incorrect because that description belongs to Access package, whose purpose is to offer a controlled set of resources to employees or external collaborators.
Answer D is incorrect because that description belongs to Privileged access group, whose purpose is to govern privileged group membership with time-bound elevation.
Question 2
To analyze user and workload sign-in activity for security and troubleshooting, which Azure design option should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Microsoft Entra sign-in logs record authentication attempts, results, applications, locations, devices, and policy evaluation details. It directly meets the requirement to analyze user and workload sign-in activity for security and troubleshooting.
Incorrect Answers
Answer A is incorrect because Access review is used to remove stale or unnecessary access through recurring governance reviews; that does not directly satisfy the requirement in this scenario.
Answer C is incorrect because Access package is used to offer a controlled set of resources to employees or external collaborators; that does not directly satisfy the requirement in this scenario.
Answer D is incorrect because Microsoft Entra Privileged Identity Management (PIM) is used to reduce standing privileged access and govern administrator elevation; that does not directly satisfy the requirement in this scenario.
Question 3
To minimize persistent administrator privileges, which Azure design option should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because PIM eligible assignment is designed to minimize persistent administrator privileges. PIM eligible assignment makes a user eligible to activate a privileged role when needed instead of granting permanent active access.
Incorrect Answers
Answer A is incorrect because Access review can be useful in Azure architectures, but its primary role is to remove stale or unnecessary access through recurring governance reviews; it is not the best match for the stated priority.
Answer B is incorrect because Privileged access group can be useful in Azure architectures, but its primary role is to govern privileged group membership with time-bound elevation; it is not the best match for the stated priority.
Answer D is incorrect because Access package can be useful in Azure architectures, but its primary role is to offer a controlled set of resources to employees or external collaborators; it is not the best match for the stated priority.
Question 4
To record user acceptance of legal or acceptable-use conditions, which Azure design option should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Terms of Use is designed to record user acceptance of legal or acceptable-use conditions. Terms of Use presents organizational terms that users may be required to accept before access under supported policies.
Incorrect Answers
Answer B is incorrect because Access review can be useful in Azure architectures, but its primary role is to remove stale or unnecessary access through recurring governance reviews; it is not the best match for the stated priority.
Answer C is incorrect because Microsoft Entra Privileged Identity Management (PIM) can be useful in Azure architectures, but its primary role is to reduce standing privileged access and govern administrator elevation; it is not the best match for the stated priority.
Answer D is incorrect because Microsoft Entra audit logs can be useful in Azure architectures, but its primary role is to investigate and audit identity-governance changes; it is not the best match for the stated priority.
Question 5
An organization wants to minimize persistent administrator privileges. Which design choice most directly meets the requirement?
Correct Answer: D
Correct Answer
Answer D is correct because PIM eligible assignment makes a user eligible to activate a privileged role when needed instead of granting permanent active access. It directly meets the requirement to minimize persistent administrator privileges.
Incorrect Answers
Answer A is incorrect because Privileged access group is used to govern privileged group membership with time-bound elevation; that does not directly satisfy the requirement in this scenario.
Answer B is incorrect because Access review is used to remove stale or unnecessary access through recurring governance reviews; that does not directly satisfy the requirement in this scenario.
Answer C is incorrect because Access package is used to offer a controlled set of resources to employees or external collaborators; that does not directly satisfy the requirement in this scenario.
Question 6
Users must acknowledge acceptable-use conditions during access, and the organization needs a record of their acceptance. Which Microsoft Entra governance feature fits this requirement?
Correct Answer: B
Correct Answer
Answer B is correct because Terms of Use presents organizational terms that users may be required to accept before access under supported policies. It directly meets the requirement to record user acceptance of legal or acceptable-use conditions.
Incorrect Answers
Answer A is incorrect because Access review is used to remove stale or unnecessary access through recurring governance reviews; that does not directly satisfy the requirement in this scenario.
Answer C is incorrect because Microsoft Entra audit logs is used to investigate and audit identity-governance changes; that does not directly satisfy the requirement in this scenario.
Answer D is incorrect because Microsoft Entra Privileged Identity Management (PIM) is used to reduce standing privileged access and govern administrator elevation; that does not directly satisfy the requirement in this scenario.
Question 7
For Privileged access group, which statement is accurate?
Correct Answer: A
Correct Answer
Answer A is correct because Privileged access group is a group governed through PIM so membership or ownership can be activated just in time.
Incorrect Answers
Answer B is incorrect because that description belongs to PIM eligible assignment, whose purpose is to minimize persistent administrator privileges.
Answer C is incorrect because that description belongs to Microsoft Entra sign-in logs, whose purpose is to analyze user and workload sign-in activity for security and troubleshooting.
Answer D is incorrect because that description belongs to Terms of Use, whose purpose is to record user acceptance of legal or acceptable-use conditions.
Question 8
When considering PIM eligible assignment, which requirement supports that choice?
Correct Answer: D
Correct Answer
Answer D is correct because PIM eligible assignment makes a user eligible to activate a privileged role when needed instead of granting permanent active access.
Incorrect Answers
Answer A is incorrect because that outcome is more directly associated with Access review, not PIM eligible assignment.
Answer B is incorrect because that outcome is more directly associated with Access package, not PIM eligible assignment.
Answer C is incorrect because that outcome is more directly associated with Privileged access group, not PIM eligible assignment.
Question 9
To standardize identity lifecycle operations such as onboarding and offboarding, which Azure design option should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Lifecycle Workflows is designed to standardize identity lifecycle operations such as onboarding and offboarding. Lifecycle Workflows automate joiner, mover, and leaver identity tasks based on user lifecycle events and conditions.
Incorrect Answers
Answer A is incorrect because Microsoft Entra audit logs can be useful in Azure architectures, but its primary role is to investigate and audit identity-governance changes; it is not the best match for the stated priority.
Answer B is incorrect because Privileged access group can be useful in Azure architectures, but its primary role is to govern privileged group membership with time-bound elevation; it is not the best match for the stated priority.
Answer C is incorrect because Microsoft Entra Privileged Identity Management (PIM) can be useful in Azure architectures, but its primary role is to reduce standing privileged access and govern administrator elevation; it is not the best match for the stated priority.
Question 10
Which Azure capability bundles resources with request, approval, expiration, and review policies for governed access?
Correct Answer: D
Correct Answer
Answer D is correct because Access package matches the described capability and is intended to offer a controlled set of resources to employees or external collaborators.
Incorrect Answers
Answer A is incorrect because Microsoft Entra sign-in logs is intended to analyze user and workload sign-in activity for security and troubleshooting, which is a different architectural function.
Answer B is incorrect because Lifecycle Workflows is intended to standardize identity lifecycle operations such as onboarding and offboarding, which is a different architectural function.
Answer C is incorrect because Terms of Use is intended to record user acceptance of legal or acceptable-use conditions, which is a different architectural function.
Question 11
To investigate and audit identity-governance changes, which Azure design option should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Microsoft Entra audit logs is designed to investigate and audit identity-governance changes. Microsoft Entra audit logs record directory changes, role operations, policy updates, and other administrative identity events.
Incorrect Answers
Answer B is incorrect because PIM eligible assignment can be useful in Azure architectures, but its primary role is to minimize persistent administrator privileges; it is not the best match for the stated priority.
Answer C is incorrect because Microsoft Entra sign-in logs can be useful in Azure architectures, but its primary role is to analyze user and workload sign-in activity for security and troubleshooting; it is not the best match for the stated priority.
Answer D is incorrect because Entitlement management can be useful in Azure architectures, but its primary role is to govern request, approval, assignment, expiration, and review of access packages; it is not the best match for the stated priority.
Question 12
When considering Privileged access group, which requirement supports that choice?
Correct Answer: C
Correct Answer
Answer C is correct because Privileged access group is a group governed through PIM so membership or ownership can be activated just in time.
Incorrect Answers
Answer A is incorrect because that outcome is more directly associated with Terms of Use, not Privileged access group.
Answer B is incorrect because that outcome is more directly associated with PIM eligible assignment, not Privileged access group.
Answer D is incorrect because that outcome is more directly associated with Microsoft Entra sign-in logs, not Privileged access group.
Question 13
For Microsoft Entra sign-in logs, which statement is accurate?
Correct Answer: C
Correct Answer
Answer C is correct because Microsoft Entra sign-in logs record authentication attempts, results, applications, locations, devices, and policy evaluation details.
Incorrect Answers
Answer A is incorrect because that description belongs to Access package, whose purpose is to offer a controlled set of resources to employees or external collaborators.
Answer B is incorrect because that description belongs to Access review, whose purpose is to remove stale or unnecessary access through recurring governance reviews.
Answer D is incorrect because that description belongs to Microsoft Entra Privileged Identity Management (PIM), whose purpose is to reduce standing privileged access and govern administrator elevation.
Question 14
An Azure architect needs to investigate and audit identity-governance changes. Which Azure service or capability is the best fit?
Correct Answer: A
Correct Answer
Answer A is correct because Microsoft Entra audit logs record directory changes, role operations, policy updates, and other administrative identity events. It directly meets the requirement to investigate and audit identity-governance changes.
Incorrect Answers
Answer B is incorrect because Microsoft Entra sign-in logs is used to analyze user and workload sign-in activity for security and troubleshooting; that does not directly satisfy the requirement in this scenario.
Answer C is incorrect because Entitlement management is used to govern request, approval, assignment, expiration, and review of access packages; that does not directly satisfy the requirement in this scenario.
Answer D is incorrect because PIM eligible assignment is used to minimize persistent administrator privileges; that does not directly satisfy the requirement in this scenario.
Question 15
To govern privileged group membership with time-bound elevation, which Azure design option should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Privileged access group is designed to govern privileged group membership with time-bound elevation. Privileged access group is a group governed through PIM so membership or ownership can be activated just in time.
Incorrect Answers
Answer A is incorrect because Microsoft Entra sign-in logs can be useful in Azure architectures, but its primary role is to analyze user and workload sign-in activity for security and troubleshooting; it is not the best match for the stated priority.
Answer B is incorrect because Terms of Use can be useful in Azure architectures, but its primary role is to record user acceptance of legal or acceptable-use conditions; it is not the best match for the stated priority.
Answer D is incorrect because PIM eligible assignment can be useful in Azure architectures, but its primary role is to minimize persistent administrator privileges; it is not the best match for the stated priority.
Question 16
Which Azure capability automates identity and access lifecycle for packages of groups, applications, and SharePoint resources?
Correct Answer: B
Correct Answer
Answer B is correct because Entitlement management matches the described capability and is intended to govern request, approval, assignment, expiration, and review of access packages.
Incorrect Answers
Answer A is incorrect because Privileged access group is intended to govern privileged group membership with time-bound elevation, which is a different architectural function.
Answer C is incorrect because Access package is intended to offer a controlled set of resources to employees or external collaborators, which is a different architectural function.
Answer D is incorrect because Microsoft Entra audit logs is intended to investigate and audit identity-governance changes, which is a different architectural function.
Question 17
Which Azure capability presents organizational terms that users may be required to accept before access under supported policies?
Correct Answer: B
Correct Answer
Answer B is correct because Terms of Use matches the described capability and is intended to record user acceptance of legal or acceptable-use conditions.
Incorrect Answers
Answer A is incorrect because Microsoft Entra audit logs is intended to investigate and audit identity-governance changes, which is a different architectural function.
Answer C is incorrect because Microsoft Entra Privileged Identity Management (PIM) is intended to reduce standing privileged access and govern administrator elevation, which is a different architectural function.
Answer D is incorrect because Access review is intended to remove stale or unnecessary access through recurring governance reviews, which is a different architectural function.
Question 18
For Entitlement management, which statement is accurate?
Correct Answer: A
Correct Answer
Answer A is correct because Entitlement management automates identity and access lifecycle for packages of groups, applications, and SharePoint resources.
Incorrect Answers
Answer B is incorrect because that description belongs to Access package, whose purpose is to offer a controlled set of resources to employees or external collaborators.
Answer C is incorrect because that description belongs to Privileged access group, whose purpose is to govern privileged group membership with time-bound elevation.
Answer D is incorrect because that description belongs to Microsoft Entra audit logs, whose purpose is to investigate and audit identity-governance changes.
Question 19
Which Azure capability is a group governed through PIM so membership or ownership can be activated just in time?
Correct Answer: B
Correct Answer
Answer B is correct because Privileged access group matches the described capability and is intended to govern privileged group membership with time-bound elevation.
Incorrect Answers
Answer A is incorrect because Microsoft Entra sign-in logs is intended to analyze user and workload sign-in activity for security and troubleshooting, which is a different architectural function.
Answer C is incorrect because PIM eligible assignment is intended to minimize persistent administrator privileges, which is a different architectural function.
Answer D is incorrect because Terms of Use is intended to record user acceptance of legal or acceptable-use conditions, which is a different architectural function.
Question 20
When considering Access review, which requirement supports that choice?
Correct Answer: A
Correct Answer
Answer A is correct because Access review periodically asks designated reviewers to confirm whether users or groups still require access.
Incorrect Answers
Answer B is incorrect because that outcome is more directly associated with Lifecycle Workflows, not Access review.
Answer C is incorrect because that outcome is more directly associated with Entitlement management, not Access review.
Answer D is incorrect because that outcome is more directly associated with Terms of Use, not Access review.
Question 21
When considering Access package, which requirement supports that choice?
Correct Answer: C
Correct Answer
Answer C is correct because Access package bundles resources with request, approval, expiration, and review policies for governed access.
Incorrect Answers
Answer A is incorrect because that outcome is more directly associated with Microsoft Entra sign-in logs, not Access package.
Answer B is incorrect because that outcome is more directly associated with Terms of Use, not Access package.
Answer D is incorrect because that outcome is more directly associated with Lifecycle Workflows, not Access package.
Question 22
To govern request, approval, assignment, expiration, and review of access packages, which Azure design option should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Entitlement management is designed to govern request, approval, assignment, expiration, and review of access packages. Entitlement management automates identity and access lifecycle for packages of groups, applications, and SharePoint resources.
Incorrect Answers
Answer A is incorrect because Privileged access group can be useful in Azure architectures, but its primary role is to govern privileged group membership with time-bound elevation; it is not the best match for the stated priority.
Answer B is incorrect because Access package can be useful in Azure architectures, but its primary role is to offer a controlled set of resources to employees or external collaborators; it is not the best match for the stated priority.
Answer C is incorrect because Microsoft Entra audit logs can be useful in Azure architectures, but its primary role is to investigate and audit identity-governance changes; it is not the best match for the stated priority.
Question 23
For Lifecycle Workflows, which statement is accurate?
Correct Answer: A
Correct Answer
Answer A is correct because Lifecycle Workflows automate joiner, mover, and leaver identity tasks based on user lifecycle events and conditions.
Incorrect Answers
Answer B is incorrect because that description belongs to Privileged access group, whose purpose is to govern privileged group membership with time-bound elevation.
Answer C is incorrect because that description belongs to Microsoft Entra Privileged Identity Management (PIM), whose purpose is to reduce standing privileged access and govern administrator elevation.
Answer D is incorrect because that description belongs to Microsoft Entra audit logs, whose purpose is to investigate and audit identity-governance changes.
Question 24
To remove stale or unnecessary access through recurring governance reviews, which Azure design option should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Access review is designed to remove stale or unnecessary access through recurring governance reviews. Access review periodically asks designated reviewers to confirm whether users or groups still require access.
Incorrect Answers
Answer A is incorrect because Lifecycle Workflows can be useful in Azure architectures, but its primary role is to standardize identity lifecycle operations such as onboarding and offboarding; it is not the best match for the stated priority.
Answer B is incorrect because Terms of Use can be useful in Azure architectures, but its primary role is to record user acceptance of legal or acceptable-use conditions; it is not the best match for the stated priority.
Answer C is incorrect because Entitlement management can be useful in Azure architectures, but its primary role is to govern request, approval, assignment, expiration, and review of access packages; it is not the best match for the stated priority.
Question 25
For Microsoft Entra Privileged Identity Management (PIM), which statement is accurate?
Correct Answer: C
Correct Answer
Answer C is correct because Microsoft Entra Privileged Identity Management (PIM) provides just-in-time, time-bound, approval-based, and audited privileged role activation for supported roles.
Incorrect Answers
Answer A is incorrect because that description belongs to Lifecycle Workflows, whose purpose is to standardize identity lifecycle operations such as onboarding and offboarding.
Answer B is incorrect because that description belongs to PIM eligible assignment, whose purpose is to minimize persistent administrator privileges.
Answer D is incorrect because that description belongs to Entitlement management, whose purpose is to govern request, approval, assignment, expiration, and review of access packages.
Popular posts
Recent Posts
