Microsoft AZ-305 Entra Identity Governance Practice Test

 

Topic 07 focuses on Microsoft Entra Identity Governance for the Microsoft Certified: Azure Solutions Architect Expert certification and the AZ-305 exam, using Microsoft Azure solution-architecture scenarios. For broader exam preparation, review the Microsoft Azure Solutions Architect Expert AZ-305 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

For PIM eligible assignment, which statement is accurate?

  1. Periodically asks designated reviewers to confirm whether users or groups still require access.
  2. Makes a user eligible to activate a privileged role when needed instead of granting permanent active access.
  3. Bundles resources with request, approval, expiration, and review policies for governed access.
  4. Is a group governed through PIM so membership or ownership can be activated just in time.

Correct Answer: B

 

Correct Answer

Answer B is correct because PIM eligible assignment makes a user eligible to activate a privileged role when needed instead of granting permanent active access.

Incorrect Answers

Answer A is incorrect because that description belongs to Access review, whose purpose is to remove stale or unnecessary access through recurring governance reviews.

Answer C is incorrect because that description belongs to Access package, whose purpose is to offer a controlled set of resources to employees or external collaborators.

Answer D is incorrect because that description belongs to Privileged access group, whose purpose is to govern privileged group membership with time-bound elevation.

 

Question 2

To analyze user and workload sign-in activity for security and troubleshooting, which Azure design option should be selected?

  1. Access review
  2. Microsoft Entra sign-in logs
  3. Access package
  4. Microsoft Entra Privileged Identity Management (PIM)

Correct Answer: B

 

Correct Answer

Answer B is correct because Microsoft Entra sign-in logs record authentication attempts, results, applications, locations, devices, and policy evaluation details. It directly meets the requirement to analyze user and workload sign-in activity for security and troubleshooting.

Incorrect Answers

Answer A is incorrect because Access review is used to remove stale or unnecessary access through recurring governance reviews; that does not directly satisfy the requirement in this scenario.

Answer C is incorrect because Access package is used to offer a controlled set of resources to employees or external collaborators; that does not directly satisfy the requirement in this scenario.

Answer D is incorrect because Microsoft Entra Privileged Identity Management (PIM) is used to reduce standing privileged access and govern administrator elevation; that does not directly satisfy the requirement in this scenario.

 

Question 3

To minimize persistent administrator privileges, which Azure design option should be selected?

  1. Access review
  2. Privileged access group
  3. PIM eligible assignment
  4. Access package

Correct Answer: C

 

Correct Answer

Answer C is correct because PIM eligible assignment is designed to minimize persistent administrator privileges. PIM eligible assignment makes a user eligible to activate a privileged role when needed instead of granting permanent active access.

Incorrect Answers

Answer A is incorrect because Access review can be useful in Azure architectures, but its primary role is to remove stale or unnecessary access through recurring governance reviews; it is not the best match for the stated priority.

Answer B is incorrect because Privileged access group can be useful in Azure architectures, but its primary role is to govern privileged group membership with time-bound elevation; it is not the best match for the stated priority.

Answer D is incorrect because Access package can be useful in Azure architectures, but its primary role is to offer a controlled set of resources to employees or external collaborators; it is not the best match for the stated priority.

 

Question 4

To record user acceptance of legal or acceptable-use conditions, which Azure design option should be selected?

  1. Terms of Use
  2. Access review
  3. Microsoft Entra Privileged Identity Management (PIM)
  4. Microsoft Entra audit logs

Correct Answer: A

 

Correct Answer

Answer A is correct because Terms of Use is designed to record user acceptance of legal or acceptable-use conditions. Terms of Use presents organizational terms that users may be required to accept before access under supported policies.

Incorrect Answers

Answer B is incorrect because Access review can be useful in Azure architectures, but its primary role is to remove stale or unnecessary access through recurring governance reviews; it is not the best match for the stated priority.

Answer C is incorrect because Microsoft Entra Privileged Identity Management (PIM) can be useful in Azure architectures, but its primary role is to reduce standing privileged access and govern administrator elevation; it is not the best match for the stated priority.

Answer D is incorrect because Microsoft Entra audit logs can be useful in Azure architectures, but its primary role is to investigate and audit identity-governance changes; it is not the best match for the stated priority.

 

Question 5

An organization wants to minimize persistent administrator privileges. Which design choice most directly meets the requirement?

  1. Privileged access group
  2. Access review
  3. Access package
  4. PIM eligible assignment

Correct Answer: D

 

Correct Answer

Answer D is correct because PIM eligible assignment makes a user eligible to activate a privileged role when needed instead of granting permanent active access. It directly meets the requirement to minimize persistent administrator privileges.

Incorrect Answers

Answer A is incorrect because Privileged access group is used to govern privileged group membership with time-bound elevation; that does not directly satisfy the requirement in this scenario.

Answer B is incorrect because Access review is used to remove stale or unnecessary access through recurring governance reviews; that does not directly satisfy the requirement in this scenario.

Answer C is incorrect because Access package is used to offer a controlled set of resources to employees or external collaborators; that does not directly satisfy the requirement in this scenario.

 

Question 6

Users must acknowledge acceptable-use conditions during access, and the organization needs a record of their acceptance. Which Microsoft Entra governance feature fits this requirement?

  1. Access review
  2. Terms of Use
  3. Microsoft Entra audit logs
  4. Microsoft Entra Privileged Identity Management (PIM)

Correct Answer: B

 

Correct Answer

Answer B is correct because Terms of Use presents organizational terms that users may be required to accept before access under supported policies. It directly meets the requirement to record user acceptance of legal or acceptable-use conditions.

Incorrect Answers

Answer A is incorrect because Access review is used to remove stale or unnecessary access through recurring governance reviews; that does not directly satisfy the requirement in this scenario.

Answer C is incorrect because Microsoft Entra audit logs is used to investigate and audit identity-governance changes; that does not directly satisfy the requirement in this scenario.

Answer D is incorrect because Microsoft Entra Privileged Identity Management (PIM) is used to reduce standing privileged access and govern administrator elevation; that does not directly satisfy the requirement in this scenario.

 

Question 7

For Privileged access group, which statement is accurate?

  1. Is a group governed through PIM so membership or ownership can be activated just in time.
  2. Makes a user eligible to activate a privileged role when needed instead of granting permanent active access.
  3. Record authentication attempts, results, applications, locations, devices, and policy evaluation details.
  4. Presents organizational terms that users may be required to accept before access under supported policies.

Correct Answer: A

 

Correct Answer

Answer A is correct because Privileged access group is a group governed through PIM so membership or ownership can be activated just in time.

Incorrect Answers

Answer B is incorrect because that description belongs to PIM eligible assignment, whose purpose is to minimize persistent administrator privileges.

Answer C is incorrect because that description belongs to Microsoft Entra sign-in logs, whose purpose is to analyze user and workload sign-in activity for security and troubleshooting.

Answer D is incorrect because that description belongs to Terms of Use, whose purpose is to record user acceptance of legal or acceptable-use conditions.

 

Question 8

When considering PIM eligible assignment, which requirement supports that choice?

  1. To remove stale or unnecessary access through recurring governance reviews.
  2. To offer a controlled set of resources to employees or external collaborators.
  3. To govern privileged group membership with time-bound elevation.
  4. To minimize persistent administrator privileges.

Correct Answer: D

 

Correct Answer

Answer D is correct because PIM eligible assignment makes a user eligible to activate a privileged role when needed instead of granting permanent active access.

Incorrect Answers

Answer A is incorrect because that outcome is more directly associated with Access review, not PIM eligible assignment.

Answer B is incorrect because that outcome is more directly associated with Access package, not PIM eligible assignment.

Answer C is incorrect because that outcome is more directly associated with Privileged access group, not PIM eligible assignment.

 

Question 9

To standardize identity lifecycle operations such as onboarding and offboarding, which Azure design option should be selected?

  1. Microsoft Entra audit logs
  2. Privileged access group
  3. Microsoft Entra Privileged Identity Management (PIM)
  4. Lifecycle Workflows

Correct Answer: D

 

Correct Answer

Answer D is correct because Lifecycle Workflows is designed to standardize identity lifecycle operations such as onboarding and offboarding. Lifecycle Workflows automate joiner, mover, and leaver identity tasks based on user lifecycle events and conditions.

Incorrect Answers

Answer A is incorrect because Microsoft Entra audit logs can be useful in Azure architectures, but its primary role is to investigate and audit identity-governance changes; it is not the best match for the stated priority.

Answer B is incorrect because Privileged access group can be useful in Azure architectures, but its primary role is to govern privileged group membership with time-bound elevation; it is not the best match for the stated priority.

Answer C is incorrect because Microsoft Entra Privileged Identity Management (PIM) can be useful in Azure architectures, but its primary role is to reduce standing privileged access and govern administrator elevation; it is not the best match for the stated priority.

 

Question 10

Which Azure capability bundles resources with request, approval, expiration, and review policies for governed access?

  1. Microsoft Entra sign-in logs
  2. Lifecycle Workflows
  3. Terms of Use
  4. Access package

Correct Answer: D

 

Correct Answer

Answer D is correct because Access package matches the described capability and is intended to offer a controlled set of resources to employees or external collaborators.

Incorrect Answers

Answer A is incorrect because Microsoft Entra sign-in logs is intended to analyze user and workload sign-in activity for security and troubleshooting, which is a different architectural function.

Answer B is incorrect because Lifecycle Workflows is intended to standardize identity lifecycle operations such as onboarding and offboarding, which is a different architectural function.

Answer C is incorrect because Terms of Use is intended to record user acceptance of legal or acceptable-use conditions, which is a different architectural function.

 

Question 11

To investigate and audit identity-governance changes, which Azure design option should be selected?

  1. Microsoft Entra audit logs
  2. PIM eligible assignment
  3. Microsoft Entra sign-in logs
  4. Entitlement management

Correct Answer: A

 

Correct Answer

Answer A is correct because Microsoft Entra audit logs is designed to investigate and audit identity-governance changes. Microsoft Entra audit logs record directory changes, role operations, policy updates, and other administrative identity events.

Incorrect Answers

Answer B is incorrect because PIM eligible assignment can be useful in Azure architectures, but its primary role is to minimize persistent administrator privileges; it is not the best match for the stated priority.

Answer C is incorrect because Microsoft Entra sign-in logs can be useful in Azure architectures, but its primary role is to analyze user and workload sign-in activity for security and troubleshooting; it is not the best match for the stated priority.

Answer D is incorrect because Entitlement management can be useful in Azure architectures, but its primary role is to govern request, approval, assignment, expiration, and review of access packages; it is not the best match for the stated priority.

 

Question 12

When considering Privileged access group, which requirement supports that choice?

  1. To record user acceptance of legal or acceptable-use conditions.
  2. To minimize persistent administrator privileges.
  3. To govern privileged group membership with time-bound elevation.
  4. To analyze user and workload sign-in activity for security and troubleshooting.

Correct Answer: C

 

Correct Answer

Answer C is correct because Privileged access group is a group governed through PIM so membership or ownership can be activated just in time.

Incorrect Answers

Answer A is incorrect because that outcome is more directly associated with Terms of Use, not Privileged access group.

Answer B is incorrect because that outcome is more directly associated with PIM eligible assignment, not Privileged access group.

Answer D is incorrect because that outcome is more directly associated with Microsoft Entra sign-in logs, not Privileged access group.

 

Question 13

For Microsoft Entra sign-in logs, which statement is accurate?

  1. Bundles resources with request, approval, expiration, and review policies for governed access.
  2. Periodically asks designated reviewers to confirm whether users or groups still require access.
  3. Record authentication attempts, results, applications, locations, devices, and policy evaluation details.
  4. Provides just-in-time, time-bound, approval-based, and audited privileged role activation for supported roles.

Correct Answer: C

 

Correct Answer

Answer C is correct because Microsoft Entra sign-in logs record authentication attempts, results, applications, locations, devices, and policy evaluation details.

Incorrect Answers

Answer A is incorrect because that description belongs to Access package, whose purpose is to offer a controlled set of resources to employees or external collaborators.

Answer B is incorrect because that description belongs to Access review, whose purpose is to remove stale or unnecessary access through recurring governance reviews.

Answer D is incorrect because that description belongs to Microsoft Entra Privileged Identity Management (PIM), whose purpose is to reduce standing privileged access and govern administrator elevation.

 

Question 14

An Azure architect needs to investigate and audit identity-governance changes. Which Azure service or capability is the best fit?

  1. Microsoft Entra audit logs
  2. Microsoft Entra sign-in logs
  3. Entitlement management
  4. PIM eligible assignment

Correct Answer: A

 

Correct Answer

Answer A is correct because Microsoft Entra audit logs record directory changes, role operations, policy updates, and other administrative identity events. It directly meets the requirement to investigate and audit identity-governance changes.

Incorrect Answers

Answer B is incorrect because Microsoft Entra sign-in logs is used to analyze user and workload sign-in activity for security and troubleshooting; that does not directly satisfy the requirement in this scenario.

Answer C is incorrect because Entitlement management is used to govern request, approval, assignment, expiration, and review of access packages; that does not directly satisfy the requirement in this scenario.

Answer D is incorrect because PIM eligible assignment is used to minimize persistent administrator privileges; that does not directly satisfy the requirement in this scenario.

 

Question 15

To govern privileged group membership with time-bound elevation, which Azure design option should be selected?

  1. Microsoft Entra sign-in logs
  2. Terms of Use
  3. Privileged access group
  4. PIM eligible assignment

Correct Answer: C

 

Correct Answer

Answer C is correct because Privileged access group is designed to govern privileged group membership with time-bound elevation. Privileged access group is a group governed through PIM so membership or ownership can be activated just in time.

Incorrect Answers

Answer A is incorrect because Microsoft Entra sign-in logs can be useful in Azure architectures, but its primary role is to analyze user and workload sign-in activity for security and troubleshooting; it is not the best match for the stated priority.

Answer B is incorrect because Terms of Use can be useful in Azure architectures, but its primary role is to record user acceptance of legal or acceptable-use conditions; it is not the best match for the stated priority.

Answer D is incorrect because PIM eligible assignment can be useful in Azure architectures, but its primary role is to minimize persistent administrator privileges; it is not the best match for the stated priority.

 

Question 16

Which Azure capability automates identity and access lifecycle for packages of groups, applications, and SharePoint resources?

  1. Privileged access group
  2. Entitlement management
  3. Access package
  4. Microsoft Entra audit logs

Correct Answer: B

 

Correct Answer

Answer B is correct because Entitlement management matches the described capability and is intended to govern request, approval, assignment, expiration, and review of access packages.

Incorrect Answers

Answer A is incorrect because Privileged access group is intended to govern privileged group membership with time-bound elevation, which is a different architectural function.

Answer C is incorrect because Access package is intended to offer a controlled set of resources to employees or external collaborators, which is a different architectural function.

Answer D is incorrect because Microsoft Entra audit logs is intended to investigate and audit identity-governance changes, which is a different architectural function.

 

Question 17

Which Azure capability presents organizational terms that users may be required to accept before access under supported policies?

  1. Microsoft Entra audit logs
  2. Terms of Use
  3. Microsoft Entra Privileged Identity Management (PIM)
  4. Access review

Correct Answer: B

 

Correct Answer

Answer B is correct because Terms of Use matches the described capability and is intended to record user acceptance of legal or acceptable-use conditions.

Incorrect Answers

Answer A is incorrect because Microsoft Entra audit logs is intended to investigate and audit identity-governance changes, which is a different architectural function.

Answer C is incorrect because Microsoft Entra Privileged Identity Management (PIM) is intended to reduce standing privileged access and govern administrator elevation, which is a different architectural function.

Answer D is incorrect because Access review is intended to remove stale or unnecessary access through recurring governance reviews, which is a different architectural function.

 

Question 18

For Entitlement management, which statement is accurate?

  1. Automates identity and access lifecycle for packages of groups, applications, and SharePoint resources.
  2. Bundles resources with request, approval, expiration, and review policies for governed access.
  3. Is a group governed through PIM so membership or ownership can be activated just in time.
  4. Record directory changes, role operations, policy updates, and other administrative identity events.

Correct Answer: A

 

Correct Answer

Answer A is correct because Entitlement management automates identity and access lifecycle for packages of groups, applications, and SharePoint resources.

Incorrect Answers

Answer B is incorrect because that description belongs to Access package, whose purpose is to offer a controlled set of resources to employees or external collaborators.

Answer C is incorrect because that description belongs to Privileged access group, whose purpose is to govern privileged group membership with time-bound elevation.

Answer D is incorrect because that description belongs to Microsoft Entra audit logs, whose purpose is to investigate and audit identity-governance changes.

 

Question 19

Which Azure capability is a group governed through PIM so membership or ownership can be activated just in time?

  1. Microsoft Entra sign-in logs
  2. Privileged access group
  3. PIM eligible assignment
  4. Terms of Use

Correct Answer: B

 

Correct Answer

Answer B is correct because Privileged access group matches the described capability and is intended to govern privileged group membership with time-bound elevation.

Incorrect Answers

Answer A is incorrect because Microsoft Entra sign-in logs is intended to analyze user and workload sign-in activity for security and troubleshooting, which is a different architectural function.

Answer C is incorrect because PIM eligible assignment is intended to minimize persistent administrator privileges, which is a different architectural function.

Answer D is incorrect because Terms of Use is intended to record user acceptance of legal or acceptable-use conditions, which is a different architectural function.

 

Question 20

When considering Access review, which requirement supports that choice?

  1. To remove stale or unnecessary access through recurring governance reviews.
  2. To standardize identity lifecycle operations such as onboarding and offboarding.
  3. To govern request, approval, assignment, expiration, and review of access packages.
  4. To record user acceptance of legal or acceptable-use conditions.

Correct Answer: A

 

Correct Answer

Answer A is correct because Access review periodically asks designated reviewers to confirm whether users or groups still require access.

Incorrect Answers

Answer B is incorrect because that outcome is more directly associated with Lifecycle Workflows, not Access review.

Answer C is incorrect because that outcome is more directly associated with Entitlement management, not Access review.

Answer D is incorrect because that outcome is more directly associated with Terms of Use, not Access review.

 

Question 21

When considering Access package, which requirement supports that choice?

  1. To analyze user and workload sign-in activity for security and troubleshooting.
  2. To record user acceptance of legal or acceptable-use conditions.
  3. To offer a controlled set of resources to employees or external collaborators.
  4. To standardize identity lifecycle operations such as onboarding and offboarding.

Correct Answer: C

 

Correct Answer

Answer C is correct because Access package bundles resources with request, approval, expiration, and review policies for governed access.

Incorrect Answers

Answer A is incorrect because that outcome is more directly associated with Microsoft Entra sign-in logs, not Access package.

Answer B is incorrect because that outcome is more directly associated with Terms of Use, not Access package.

Answer D is incorrect because that outcome is more directly associated with Lifecycle Workflows, not Access package.

 

Question 22

To govern request, approval, assignment, expiration, and review of access packages, which Azure design option should be selected?

  1. Privileged access group
  2. Access package
  3. Microsoft Entra audit logs
  4. Entitlement management

Correct Answer: D

 

Correct Answer

Answer D is correct because Entitlement management is designed to govern request, approval, assignment, expiration, and review of access packages. Entitlement management automates identity and access lifecycle for packages of groups, applications, and SharePoint resources.

Incorrect Answers

Answer A is incorrect because Privileged access group can be useful in Azure architectures, but its primary role is to govern privileged group membership with time-bound elevation; it is not the best match for the stated priority.

Answer B is incorrect because Access package can be useful in Azure architectures, but its primary role is to offer a controlled set of resources to employees or external collaborators; it is not the best match for the stated priority.

Answer C is incorrect because Microsoft Entra audit logs can be useful in Azure architectures, but its primary role is to investigate and audit identity-governance changes; it is not the best match for the stated priority.

 

Question 23

For Lifecycle Workflows, which statement is accurate?

  1. Automate joiner, mover, and leaver identity tasks based on user lifecycle events and conditions.
  2. Is a group governed through PIM so membership or ownership can be activated just in time.
  3. Provides just-in-time, time-bound, approval-based, and audited privileged role activation for supported roles.
  4. Record directory changes, role operations, policy updates, and other administrative identity events.

Correct Answer: A

 

Correct Answer

Answer A is correct because Lifecycle Workflows automate joiner, mover, and leaver identity tasks based on user lifecycle events and conditions.

Incorrect Answers

Answer B is incorrect because that description belongs to Privileged access group, whose purpose is to govern privileged group membership with time-bound elevation.

Answer C is incorrect because that description belongs to Microsoft Entra Privileged Identity Management (PIM), whose purpose is to reduce standing privileged access and govern administrator elevation.

Answer D is incorrect because that description belongs to Microsoft Entra audit logs, whose purpose is to investigate and audit identity-governance changes.

 

Question 24

To remove stale or unnecessary access through recurring governance reviews, which Azure design option should be selected?

  1. Lifecycle Workflows
  2. Terms of Use
  3. Entitlement management
  4. Access review

Correct Answer: D

 

Correct Answer

Answer D is correct because Access review is designed to remove stale or unnecessary access through recurring governance reviews. Access review periodically asks designated reviewers to confirm whether users or groups still require access.

Incorrect Answers

Answer A is incorrect because Lifecycle Workflows can be useful in Azure architectures, but its primary role is to standardize identity lifecycle operations such as onboarding and offboarding; it is not the best match for the stated priority.

Answer B is incorrect because Terms of Use can be useful in Azure architectures, but its primary role is to record user acceptance of legal or acceptable-use conditions; it is not the best match for the stated priority.

Answer C is incorrect because Entitlement management can be useful in Azure architectures, but its primary role is to govern request, approval, assignment, expiration, and review of access packages; it is not the best match for the stated priority.

 

Question 25

For Microsoft Entra Privileged Identity Management (PIM), which statement is accurate?

  1. Automate joiner, mover, and leaver identity tasks based on user lifecycle events and conditions.
  2. Makes a user eligible to activate a privileged role when needed instead of granting permanent active access.
  3. Provides just-in-time, time-bound, approval-based, and audited privileged role activation for supported roles.
  4. Automates identity and access lifecycle for packages of groups, applications, and SharePoint resources.

Correct Answer: C

 

Correct Answer

Answer C is correct because Microsoft Entra Privileged Identity Management (PIM) provides just-in-time, time-bound, approval-based, and audited privileged role activation for supported roles.

Incorrect Answers

Answer A is incorrect because that description belongs to Lifecycle Workflows, whose purpose is to standardize identity lifecycle operations such as onboarding and offboarding.

Answer B is incorrect because that description belongs to PIM eligible assignment, whose purpose is to minimize persistent administrator privileges.

Answer D is incorrect because that description belongs to Entitlement management, whose purpose is to govern request, approval, assignment, expiration, and review of access packages.

img