{"id":11807,"date":"2026-09-14T12:14:26","date_gmt":"2026-09-14T12:14:26","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=11807"},"modified":"2026-09-14T12:14:26","modified_gmt":"2026-09-14T12:14:26","slug":"microsoft-az-104-practice-test-questions-and-exam-dumps-part-18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-104-practice-test-questions-and-exam-dumps-part-18-q341-360\/","title":{"rendered":"Microsoft AZ-104 Practice Test Questions and Exam Dumps Part 18 (Q341\u2013360)"},"content":{"rendered":"<h2><b>View Full\u00a0<a href=\"https:\/\/www.examlabs.com\/az-104-exam-dumps\">Microsoft AZ-104 Exam Dumps<\/a>\u00a0and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 341<\/b><\/h3>\n<p><b>Which security principle ensures that sensitive information is accessible only to authorized individuals?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Integrity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Non-repudiation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Confidentiality is the security principle that ensures sensitive information is accessible only to authorized individuals, systems, or processes. Organizations protect confidentiality through access controls, encryption, authentication, data classification, and security policies. For example, confidential employee records should only be available to authorized personnel. A confidentiality breach can occur when attackers steal credentials, intercept communications, or gain unauthorized access to databases. Confidentiality is one of the three components of the CIA triad, along with integrity and availability, and is essential for protecting private and sensitive information.<\/span><\/p>\n<h3><b>Question 342<\/b><\/h3>\n<p><b>Which type of attack attempts to use previously stolen usernames and passwords on multiple online services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute force<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Credential stuffing occurs when attackers use previously stolen username and password combinations to attempt logins on multiple websites and services. This attack takes advantage of password reuse, because users sometimes use the same credentials across different accounts. Attackers can automate large numbers of login attempts using lists obtained from previous data breaches. Organizations can reduce credential stuffing risks through multifactor authentication, breached-password detection, rate limiting, bot detection, and encouraging users to use unique passwords. Password managers can also help users create and maintain different passwords for different services.<\/span><\/p>\n<h3><b>Question 343<\/b><\/h3>\n<p><b>Which security technology can detect suspicious network traffic and alert administrators without automatically blocking it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An intrusion detection system (IDS) monitors network or system activity for suspicious patterns and generates alerts when potentially malicious behavior is detected. Unlike an intrusion prevention system, an IDS normally does not automatically block the detected traffic. Security teams can investigate alerts and determine whether an incident has occurred. IDS solutions can use signatures, anomaly detection, or behavioral analysis to identify threats. They are valuable for security monitoring and incident detection, especially when deployed at strategic network locations where suspicious traffic can be observed.<\/span><\/p>\n<h3><b>Question 344<\/b><\/h3>\n<p><b>Which security technology can automatically block malicious network traffic after detecting an intrusion?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Honeypot<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An intrusion prevention system (IPS) monitors network traffic for malicious or suspicious activity and can automatically take action to block or prevent the detected threat. An IPS may use signatures, behavioral analysis, or anomaly detection to identify attacks. Unlike an IDS, which primarily generates alerts, an IPS is designed to actively respond to detected threats. It can help stop exploits, malicious connections, and other attacks before they reach protected systems. Proper configuration is important because overly aggressive rules can block legitimate traffic and create false positives.<\/span><\/p>\n<h3><b>Question 345<\/b><\/h3>\n<p><b>Which authentication method requires users to provide two or more different types of authentication factors?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Federation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication (MFA) requires users to provide two or more authentication factors from different categories, such as something they know, something they have, or something they are. For example, a password combined with a hardware security token provides two different factors. MFA significantly reduces the risk of account compromise because stealing one authentication factor is generally not enough to gain access. Organizations commonly use MFA to protect email, cloud services, administrative accounts, remote access, and other systems containing sensitive information.<\/span><\/p>\n<h3><b>Question 346<\/b><\/h3>\n<p><b>Which attack tricks a user into visiting a fraudulent website by manipulating domain name resolution?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS poisoning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shoulder surfing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tailgating<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS poisoning occurs when an attacker corrupts DNS information so that users are directed to an incorrect or malicious destination. A victim may enter the correct website address but receive the IP address of an attacker-controlled server instead. The fraudulent website may attempt to steal credentials, payment information, or other sensitive data. DNS security mechanisms, secure DNS services, monitoring, and proper validation can reduce this risk. Users should also verify secure connections and avoid entering sensitive information on unexpected or suspicious websites.<\/span><\/p>\n<h3><b>Question 347<\/b><\/h3>\n<p><b>Which security control is used to prevent sensitive information from leaving an organization&#8217;s environment without authorization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data loss prevention (DLP) solutions monitor, detect, and help prevent unauthorized transmission or disclosure of sensitive information. DLP policies can identify data such as financial records, personal information, intellectual property, or confidential documents. Depending on the configuration, a DLP system may block email attachments, prevent copying data to removable devices, or restrict uploads to unauthorized websites. DLP can operate at endpoints, networks, email systems, and cloud platforms. It helps organizations reduce accidental data leakage as well as intentional attempts to steal sensitive information.<\/span><\/p>\n<h3><b>Question 348<\/b><\/h3>\n<p><b>Which security concept uses decoy systems or resources to attract attackers and observe their behavior?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Honeypot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Jump box<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A honeypot is a deliberately deployed decoy system designed to attract attackers and provide security teams with information about malicious activity. It may imitate a real server, application, database, or network resource while containing no legitimate business data. Any unexpected interaction with a honeypot can be considered suspicious and investigated. Honeypots can help organizations study attacker techniques, identify intrusion attempts, and improve defensive controls. Because legitimate users generally have no reason to access the decoy, activity involving it can provide useful security indicators with relatively low noise.<\/span><\/p>\n<h3><b>Question 349<\/b><\/h3>\n<p><b>Which security principle prevents a user from denying that they performed a particular action?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Non-repudiation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Redundancy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Obfuscation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Non-repudiation provides evidence that a specific individual or system performed a particular action and makes it difficult for that party to deny the action later. Digital signatures are commonly used to support non-repudiation because they can demonstrate that a message or document was associated with a specific private key. Audit logs and trusted timestamps can also contribute to accountability. Non-repudiation is important for financial transactions, legal documents, sensitive communications, and other situations where organizations need reliable evidence of who performed an action.<\/span><\/p>\n<h3><b>Question 350<\/b><\/h3>\n<p><b>Which security control requires visitors to be escorted while inside a restricted facility?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Visitor management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application allowlisting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Visitor management controls help organizations track and control individuals who are not regular employees or authorized personnel. Visitors may be required to sign in, provide identification, receive temporary badges, and remain accompanied by an authorized employee while inside restricted areas. These procedures reduce the risk of unauthorized physical access to sensitive facilities and equipment. Visitor records can also support investigations if a security incident occurs. Physical security controls such as cameras, access cards, guards, and locked doors can work together with visitor management to protect facilities.<\/span><\/p>\n<h3><b>Question 351<\/b><\/h3>\n<p><b>Which type of attack exploits a vulnerability in a web application by injecting malicious scripts into pages viewed by other users?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site scripting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directory traversal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cross-site scripting (XSS) is a web application attack in which an attacker injects malicious script content into a webpage that is then executed by a victim&#8217;s browser. Depending on the vulnerability, an attacker may attempt to steal session information, modify webpage content, or perform actions using the victim&#8217;s browser session. Developers can reduce XSS risks through input validation, output encoding, secure application frameworks, and appropriate content security policies. Regular application security testing can also identify vulnerable input fields and unsafe handling of user-generated content.<\/span><\/p>\n<h3><b>Question 352<\/b><\/h3>\n<p><b>Which access control model assigns permissions according to a user&#8217;s job responsibilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Discretionary access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rule-based routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role-based access control (RBAC) assigns permissions according to predefined job roles rather than individually configuring every user&#8217;s access. For example, employees in an accounting role may receive access to financial applications, while members of an IT administrator role may receive system-management permissions. RBAC simplifies administration and helps organizations enforce least privilege consistently. When an employee changes departments, administrators can modify the assigned role instead of manually changing many individual permissions. Proper role design and regular access reviews are important to prevent excessive privileges.<\/span><\/p>\n<h3><b>Question 353<\/b><\/h3>\n<p><b>Which type of security control is designed to restore systems to normal operation after a security incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Corrective control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deterrent control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preventive control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directive control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Corrective controls are designed to restore systems or processes after a security incident, failure, or other unwanted event has occurred. Examples include restoring data from backups, reinstalling compromised software, repairing damaged systems, and applying patches after vulnerabilities are discovered. Corrective controls generally operate after an incident rather than preventing it from happening in the first place. They are an important part of incident response and recovery planning. Organizations should test corrective procedures regularly to ensure they can restore critical systems effectively when required.<\/span><\/p>\n<h3><b>Question 354<\/b><\/h3>\n<p><b>Which type of control is implemented as an alternative when the preferred security control cannot be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compensating control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preventive control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detective control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deterrent control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compensating control is an alternative security measure used when the preferred control cannot be implemented or is not practical. For example, if an older system cannot support modern multifactor authentication, an organization might implement stronger network restrictions, additional monitoring, or other controls to reduce the risk. Compensating controls should provide an appropriate level of protection for the specific risk. They are commonly used when technical limitations, compatibility requirements, operational constraints, or legacy systems prevent organizations from implementing the original security requirement.<\/span><\/p>\n<h3><b>Question 355<\/b><\/h3>\n<p><b>Which security technique replaces sensitive information with a non-sensitive substitute value?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Steganography<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tokenization replaces sensitive information with a randomly generated or otherwise non-sensitive value called a token. The token can be used in systems that do not need access to the original sensitive information. The actual data is stored separately in a protected system or token vault. Tokenization is commonly used to reduce exposure of payment card information and other sensitive data. Because the token itself does not normally contain the original information, it can reduce the amount of sensitive data stored throughout an organization&#8217;s systems.<\/span><\/p>\n<h3><b>Question 356<\/b><\/h3>\n<p><b>Which physical security control uses two doors that cannot normally be opened at the same time to prevent unauthorized entry?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mantrap<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bollard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Turnstile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A mantrap is a physical security area containing two or more doors that are controlled so that only one door can normally be opened at a time. This arrangement helps prevent unauthorized individuals from following an authorized person into a restricted area. Mantraps are commonly used in high-security facilities such as data centers, laboratories, and secure government locations. They may also incorporate badge readers, biometric authentication, cameras, or security guards. Mantraps provide stronger physical access control than ordinary doors because they create an additional verification point.<\/span><\/p>\n<h3><b>Question 357<\/b><\/h3>\n<p><b>Which security concept ensures that an organization&#8217;s security controls continue to function effectively over time?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Continuous monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data destruction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Continuous monitoring involves regularly observing systems, networks, configurations, vulnerabilities, and security events to identify changes or emerging threats. It helps organizations determine whether security controls are still operating as expected and whether new vulnerabilities or suspicious activities have appeared. Continuous monitoring can include SIEM alerts, endpoint telemetry, vulnerability scanning, configuration checks, and network monitoring. Rather than relying only on occasional assessments, organizations can use ongoing monitoring to identify problems more quickly and respond before they become major security incidents.<\/span><\/p>\n<h3><b>Question 358<\/b><\/h3>\n<p><b>Which incident response phase focuses on limiting the spread and impact of an active security incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Containment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eradication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lessons learned<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Containment is the incident response phase focused on limiting the spread and impact of an active security incident. Security teams may isolate compromised systems, disable affected accounts, block malicious network traffic, or disconnect infected devices from the network. Containment can be short-term or long-term depending on the situation. Its primary purpose is to prevent the incident from causing additional damage while investigators determine the root cause and prepare for eradication. Effective containment reduces the attacker&#8217;s ability to move laterally and limits further compromise.<\/span><\/p>\n<h3><b>Question 359<\/b><\/h3>\n<p><b>Which security assessment method identifies weaknesses by examining systems without actively exploiting them?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Social engineering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Red-team exercise<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability scanning uses automated tools to examine systems, applications, networks, and devices for known security weaknesses. Scanners may identify missing patches, insecure configurations, outdated software, exposed services, and other vulnerabilities. Unlike penetration testing, vulnerability scanning generally does not attempt to fully exploit identified weaknesses. Organizations can perform vulnerability scans regularly to maintain visibility into their security posture and prioritize remediation. Scan results should be reviewed by qualified security personnel because automated tools can produce false positives and may not understand the business impact of every finding.<\/span><\/p>\n<h3><b>Question 360<\/b><\/h3>\n<p><b>Which backup strategy keeps multiple historical versions of data so that an organization can recover from accidental deletion or corruption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Versioned backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Versioned backups maintain multiple historical copies or versions of files and data rather than keeping only the latest backup. This allows an organization to restore an earlier version when current data has been accidentally deleted, corrupted, overwritten, or encrypted by malware. Versioning can be especially useful against ransomware and accidental file changes because the most recent copy may already contain damaged or encrypted data. Organizations should establish appropriate retention periods, protect backups from unauthorized modification, and regularly test restoration procedures to ensure historical versions remain usable.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full\u00a0Microsoft AZ-104 Exam Dumps\u00a0and Practice Test Dumps. &nbsp; Question 341 Which security principle ensures that sensitive information is accessible only to authorized individuals? Availability Integrity Confidentiality Non-repudiation Correct Answer: 3 Explanation Confidentiality is the security principle that ensures sensitive information is accessible only to authorized individuals, systems, or processes. Organizations protect confidentiality through access [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11807"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=11807"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11807\/revisions"}],"predecessor-version":[{"id":11808,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11807\/revisions\/11808"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=11807"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=11807"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=11807"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}