Microsoft Certified Security Compliance And Identity Fundamentals · Free Practice Question Easy

Question 21

Scenario: Mercs for Money is a collection of mercenaries gathered together by Wade Wilson who organized the group and is now a successful Professional Services enterprise. Looking to improve the operations of the organization, Wade has contracted you to assist with several IT projects.

The IT lead is telling Wade that he should consider using Azure AD but Wade is not clear on the purpose of Azure Active Directory (Azure AD) Password Protection.

Which of the following is the statement you should use to explain its purpose?

  • A

    To encrypt a password by using globally recognized encryption standards

  • B

    To identify devices to which users can sign in without using multi-factor authentication (MFA)

  • C

    To prevent users from using specific words in their passwords

  • D

    To control how often users must change their passwords

Reveal correct answer

Correct answer: C

Explanation

Azure AD Password Protection detects, and blocks known weak passwords and their variants and can also block additional weak terms that are specific to your organization.
With Azure AD Password Protection, default global banned password lists are automatically applied to all users in an Azure AD tenant. To support your own business and security needs, you can define entries in a custom banned password list.

Enforce on-premises Azure AD Password Protection for Active Directory Domain Services

Azure AD Password Protection detects, and blocks known weak passwords and their variants and can also block additional weak terms that are specific to your organization. On-premises deployment of Azure AD Password Protection uses the same global and custom banned password lists that are stored in Azure AD and does the same checks for on-premises password changes as Azure AD does for cloud-based changes. These checks are performed during password changes and password reset events against on-premises Active Directory Domain Services (AD DS) domain controllers.

https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-password-ban-bad-on-premises

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need