MB-800 Microsoft Dynamics 365 Business Central Functional Consultant (beta)
Exam
Welcome to MB-800: Microsoft Dynamics 365 Business Central Functional Consultant
- 3 practice tests - Pass guarantee
(Same duration the official exam)
Answers & Resources included 1 official exam = (40-60 questions - 120 mins)
1 practice test = (40 questions - 120 mins) Total number of questions = 108 questions
- if you solve these tests, you will be able to solve the official exam easily.
because these tests have the same difficulty of the official exam or higher
(slightly higher difficulty) to strengthen you against the official exam
Points covered in the Exams (Same points of the official exam):
● Set up Business Central (20-25%)
● Configure financials (25-30%)
● Configure sales and purchasing (10-15%)
● Perform Business Central operations (30-35%)
The Objectives are distributed among the practice tests with answers and
detailed explanations and resource links – (If available) for every question
These practice tests allow you to attempt Three Times within the same duration
of the official exam with the same number of questions and same topics to adjust
your focus-areas and cut down on study time and prove your readiness to take the
official exam.
you can use all Three Exams in whatever way suits your preparation workflow.
These exams are time-limited exactly like the official exam to make you stronger
at solving the exam.
Different types of questions including scenario-based questions and normal
multiple-choice questions similar to the questions you find in the official
exam.
Hotspot questions and the most common questions which are more likely to be
found in the official exam.
Join students who found these practice tests useful and sent me a thank you
message after passing the official exam.
What you’ll learn
Learn answers to 107 Questions distributed on 3 Official-like Practice Exams
understand Hotspot questions and the most common questions which are more likely
to be found in the official exam.
Solving all Exam questions before the time ends
Take & pass the Exam MB-800: Microsoft Dynamics 365 Business Central Functional
Consultant
Are there any course requirements or prerequisites?
Basic knowledge of Microsoft Dynamics 365 Business Central Functional Consultant
Every question is answered with detailed explanation and resources
Who this course is for: Students want to pass Exam MB-800: Microsoft Dynamics 365 Business Central
Functional Consultant
Students who want to train on Official-like Practice certification Exams
Question 1: You configure a cloud-based printer in Dynamics 365 Business Central.
Purchase orders printed by users must automatically print to the cloud-based
printer. You need to create a setup record for the user, report, and printer
combination. On which page should you create the setup record?
A. Printer Selections
B. Printer Management
C. Report Layout Selection
D. Report Selection ג€" Purchase
E. Document Sending Profiles
Question 2: You are implementing Dynamics 365 Business Central Online. Users must be
added to Business Central for the first time. You need to add the users. Which
action should you use?
A. Get New Users from Microsoft 365
B. Create a new entry on the User Setup page
C. Update Users from Microsoft 365
D. Import User Groups
Question 3: A company uses Dynamics 365 Business Central. The company wants to print
financial statements by using a cloud-based printer. You need to recommend the
type of printer the customer should install. Which type of printer should you
recommend?
A. Email
B. System
C. Client default
D. Server default
Correct Answer: A
Question 4: You create a test instance of Dynamics 365 Business Central and enter
transactions for testing purposes. You create a production company instance in
the same Business Central environment. You need to copy the setup and master
data from the test instance to the production instance without copying
transaction data. What are two possible ways to achieve the goal?
A. Use the Run Migration Now function from Cloud Migration Management
B. Create and export a configuration package from the source company. Next,
import into the destination company
C. Use the Copy Data from Company function from the Configuration Worksheet page
D. Use the Copy function from the Companies page
Correct Answer: B,D
Question 5: You are implementing Dynamics 365 Business Central for a customer. The
customer wants to upload starting entries for all master data through a general
journal on the last day of the current month. You need to upload the data
according to this requirement. Which three functions should you select?
A. Vendors Opening balance
B. G/L Accounts Opening balance
C. Calculate Inventory
D. Get Standard Journals
E. Customers Opening balance
Description This practice tests course provides practice for taking the real exam and
this practice test will help you prepare for the real exam test environment.
This course will give you lots of practice tests on all topics covered in the
PL200 exam
PL-200 exam covered topics. Configure Microsoft Dataverse (25-30%
Create apps by using Microsoft Power Apps (20-25%)
Create and Manage Microsoft Power Automate (15-20%)
Implement Microsoft Power Virtual Agents chatbots (10-15%)
Manage solutions Integrate Microsoft Power Apps with other apps and services
(15-20%)
Who this course is for: Who want to pass PL200 Exam
Students preparing for the PL200 Exam
Students who want to assess their exam by testing their exam skills under real
(PL200) exam simulation.
For anyone who want to take their career to a whole new level with an Microsoft
certification! pass the PL200 exam you must know the theory very well but also
have high level hands-on skills. The element most students forget it drilling
their knowledge with a ton of practice exams. Practice exams help you learn to
apply theory to questions as well as expose weak areas in your knowledge.
The practice tests are constructed to enhance your confidence to sit for real
exam as you will be testing your knowledge and skills for the above-mentioned
topics.
Upon enrollment, you will receive unlimited access to the tests as well as
regular updates.
Official exam information: Test taking options: Online / Local test center
Time to complete: 120 mins
Total number of questions asked: 40-60
Total Marks: 1000
Passing Score: 700
Question types: multiple choice and multi-response questions
What you’ll learn PL-200 Practice Test
Testing exam skills under real exam simulation.
Anyone who are preparing for the PL-200
Anyone who wants to test their knowledge in Microsoft Power Platform Functional
Consultant
Are there any course requirements or prerequisites?
No
Who this course is for:
PL-200 Exam takers
Anyone interested in Microsoft Power Platform Functional Consultant
Question 1:
Note: This question is part of a series of questions that present the same
scenario. Each question in the series contains a unique solution that might meet
the stated goals. Some question sets might have more than one correct solution,
while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to
it. As a result, these questions will not appear in the review screen.
You are creating Power Virtual Agents chatbot that captures demographic
information about customers.
The chatbot must determine the group a customer belongs to based on their age.
The age groups are:
✑ 0 - 17
✑ 18 - 25
✑ 26 - 35
✑ 36 - 55
✑ 55 - 100
You need to configure the chatbot to ask a question that can be used to
determine the correct age group.
Solution: Use multiple choice options for Identify in the question and create
options that represent each of the age groups.
Does this meet the goal?
A. Yes
B. No
Correct Answer: B
Question 2: You have a form that displays a custom field from an entity.
A customer wants to restrict users from filtering on the custom field.
You need to prevent users from filtering the field in Advanced Find.
What should you modify?
A. a searchable field on the Field Properties form
B. Fields in the Edit Filter Criteria option of the Quick Find view
C. Fields in the Add Find Columns option of the Quick Find view
Correct Answer: A
Explanation
Setting Searchable property to No, makes the field disappear from the available
fields for the Filter configuration, but it wonג€™t hide the field when adding
columns to the view. This property has no impact on behaviour of the Global and
Quick Find Search.
Question 3: Note: This question is part of a series of questions that present the same
scenario. Each question in the series contains a unique solution that might meet
the stated goals. Some question sets might have more than one correct solution,
while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to
it. As a result, these questions will not appear in the review screen.
You are creating Power Virtual Agents chatbot that captures demographic
information about customers.
The chatbot must determine the group a customer belongs to based on their age.
The age groups are:
✑ 0 - 17
✑ 18 - 25
✑ 26 - 35
✑ 36 - 55
✑ 55 - 100
You need to configure the chatbot to ask a question that can be used to
determine the correct age group.
Solution: Create a custom Age group entity and synonyms for each individual age
in the corresponding item. Use Age group for Identify in the question.
Does this meet the goal?
A. Yes
B. No
Correct Answer: A
Question 4 You are creating a new business process flow to qualify leads.
You create an action. The action is not available inside the Action Step.
You need to make the action available to the Action Step.
Which two steps must you perform? Each correct answer presents part of the
solution.
A. Activate the action.
B. Select Run as an on-demand process.
C. Ensure that the entity for the action matches the corresponding entity for
the business process flow stage.
D. Add at least one step to the action.
Question 5 You are using Power BI to build a dashboard for a company.
You must make the dashboard available to a specific set of users, including
employees and five external users. The number of employees that require access
to the dashboard varies, but usually less than 100.
Employees and external users must not be permitted to share the dashboard with
other users.
You need to share the dashboard with the employees and external users.
Which three actions should you perform? Each correct answer presents part of the
solution.
A. Sign into Power BI Desktop. Open the dashboard and select Share.
B. Create a dynamic distribution list. Add all users to the distribution list
and use the list to share the dashboard.
C. Sign into the Power BI service. Open the dashboard and select Share.
D. Clear the Allow recipients to share your dashboard (or report) option.
E. Enter the individual email address of internal and external users.
F. Create a distribution list. Add all users to the distribution list and use
the list to share the dashboard.
CompTIA A+ is the industry standard for establishing a career in
IT.
CompTIA A+ certified professionals are proven problem solvers. They support
today’s core technologies from security to networking to virtualization and
more. CompTIA A+ is the industry standard for launching IT careers into today’s
digital world.
CompTIA A+ is the only industry recognized credential with performance testing
to prove pros can think on their feet to perform critical IT support tasks. It
is trusted by employers around the world to identify the go-to person in end
point management & technical support roles. CompTIA A+ appears in more tech
support job listings than any other IT credential.
The CompTIA A+ Core Series requires candidates to pass two exams: Core 1
(220-1101) and Core 2 (220-1102) covering the following new content, emphasizing
the technologies and skills IT pros need to support a hybrid workforce.
Increased reliance on SaaS applications for remote work
More on troubleshooting and how to remotely diagnose and correct common
software, hardware, or connectivity problems
Changing core technologies from cloud virtualization and IoT device security to
data management and scripting
Multiple operating systems now encountered by technicians on a regular basis,
including the major systems, their use cases, and how to keep them running
properly
Reflects the changing nature of the job role, where many tasks are sent to
specialized providers as certified personnel need to assess whether it’s best to
fix something on site, or to save time and money by sending proprietary
technologies directly to vendors
9 skills that you master and validate with CompTIA A+ artboard-6
HARDWARE Identifying, using, and connecting hardware components and devices,
including the broad knowledge about different devices that is now necessary to
support the remote workforce
artboard-7
OPERATING SYSTEMS Install and support Windows OS including command line & client support.
System configuration imaging and troubleshooting for Mac OS, Chrome OS, Android
and Linux OS.
artboard-5
SOFTWARE TROUBLESHOOTING Troubleshoot PC and mobile device issues including common OS, malware and
security issues.
artboard-8
NETWORKING Explain types of networks and connections including TCP/IP, WIFI and SOHO
artboard-19
TROUBLESHOOTING Troubleshoot real-world device and network issues quickly and efficiently
artboard-3
SECURITY Identify and protect against security vulnerabilities for devices and their
network connections
artboard-11
MOBILE DEVICES Install & configure laptops and other mobile devices and support
applications to ensure connectivity for end- users
artboard-13
VIRTUALIZATION & CLOUD COMPUTING Compare & contrast cloud computing concepts & set up client-side
virtualization
artboard-9
OPERATIONAL PROCEDURES Follow best practices for safety, environmental impacts, and communication
and professionalism
Jobs that use A+
Help Desk Tech Desktop Support Specialist
Field Service Technician
Help Desk Technician
Associate Network Engineer
System Support Technician
Junior Systems Administrator
CompTIA A+ 220-1101 (Core 1) and 220-1102 (Core 2)
Candidates must complete both 1101 and 1102 to earn certification. Exams
cannot be combined across the series. Launch Date : April 2022
Exam Description : CompTIA A+ 220-1101 covers mobile devices, networking
technology, hardware, virtualization and cloud computing.
Number of Questions : Maximum of 90 questions per exam
Length of Test : 90 Minutes per exam
Languages : English at launch. German, Japanese, Portuguese, Thai and Spanish
English at launch. German, Japanese, Portuguese, Thai and Spanish
Retirement : TBD - Usually three years after launch
Testing Provider: Pearson VUE: Testing Centers : Online Testing
We cover all five domains of the 220-1101 exam, including: 1.0 Mobile Devices (15%)
2.0 Networking (20%)
3.0 Hardware (25%)
4.0 Virtualization and Cloud Computing (11%)
5.0 Hardware and Network Troubleshooting (29%)
Question 1:
A customer called the service desk and complained that they could not reach the
internet on their computer. You ask the customer to open their command prompt,
type in ipconfig, and read you the IP address. The customer reads the IP as
169.254.12.45. What is the root cause of the customer's issue based on what you
know so far?
A. Their workstation cannot reach the DNS server
B. Their workstation cannot reach the default gateway
C. Their workstation cannot reach the web server
D. Their workstation cannot reach the DHCP server
Correct Answer: D
Explanation
OBJ-5.7: Since the customer's IP address is 169.254.12.45, it is an APIPA
address. Since the workstation has an APIPA address, it means the DHCP server
was unreachable. Automatic Private IP Addressing (APIPA) is a feature of
Windows-based operating systems that enables a computer to automatically assign
itself an IP address when there is no Dynamic Host Configuration Protocol (DHCP)
server available to perform that function. APIPA serves as a DHCP server
failover mechanism and makes it easier to configure and support small local area
networks (LANs). If no DHCP server is currently available, either because the
server is temporarily down or because none exists on the network, the computer
selects an IP address from a range of addresses (from 169.254.0.0 -
169.254.255.255) reserved for that purpose.
Question 2: Your company is currently using a 5 GHz wireless security system, so your
boss has asked you to install a 2.4 GHz wireless network to use for the
company's computer network to prevent interference. Which of the following can
NOT be installed to provide a 2.4 GHz wireless network?
A. 802.11g
B. 802.11b
C. 802.11ac
D. 802.11n
Correct Answer: C
Explanation
OBJ-2.3: Wireless networks are configured to use either 2.4 GHz or 5.0 GHz
frequencies, depending on the network type. 802.11a and 802.11ac both utilize a
5.0 GHz frequency for their communications. 802.11b and 802.11g both utilize a
2.4 GHz frequency for their communications. 802.11n and 802.11ax utilize either
2.4 GHz, 5.0 GHz, or both, depending on the Wi-Fi device's manufacturer. The
802.11b (Wireless B) standard utilizes a 2.4 GHz frequency to provide wireless
networking at speeds up to 11 Mbps. The 802.11g (Wireless G) standard utilizes a
2.4 GHz frequency to provide wireless networking at speeds up to 54 Mbps. The
802.11n (Wireless N) standard utilizes a 2.4 GHz frequency to provide wireless
networking at speeds up to 108 Mbps or a 5.0 GHz frequency to provide wireless
networking at speeds up to 600 Mbps. Wireless N supports the use of
multiple-input-multiple-output (MIMO) technology to use multiple antennas to
transmit and receive data at higher speeds. Wireless N supports channel bonding
by combining two 20 MHz channels into a single 40 MHz channel
to provide additional bandwidth. The 802.11ac (Wireless AC or Wi-Fi 5) standard
utilizes a 5 GHz frequency to provide wireless networking at theoretical speeds
up to 5.5 Gbps. Wireless AC uses channel bonding to create a single channel of
up to 160 MHz to provide additional bandwidth. Wireless AC uses multi-user
multiple-input-
Question 3: Which of the following resources is used by virtual machines to communicate
with other virtual machines on the same network but prevents them from
communicating with resources on the internet?
A. DNS
B. Virtual internal network
C. Virtual external network
D. Network address translation
Correct Answer: B
Explanation
OBJ-4.2: Most virtual machines running on a workstation will have their own
virtual internal network to communicate within the virtual environment while
preventing them from communicating with the outside world. You may also
configure a shared network address for the virtual machine to have the same IP
address as the physical host that it is running on. This usually relies on
network address translation to communicate from the virtual environment (inside)
to the physical world (outside/internet). If you are communicating internally in
the virtual network, there is no need for DNS or an external network.
Question 4:
A technician needs to upgrade the RAM in a database server. The server's memory
must support maintaining the highest levels of integrity. Which of the following
type of RAM should the technician install?
A. ECC
B. Non-Parity
C. SODIMM
D. VRAM
Correct Answer: A
Explanation
OBJ-3.2: Error checking and correcting or error correcting code (ECC) is a type
of system memory that has built-in error correction security. ECC is more
expensive than normal memory and requires support from the motherboard. ECC is
commonly used in production servers and not in standard desktops or laptops.
Non-parity memory is a type of system memory that does not perform error
checking except when conducting the initial startup memory count. VRAM (video
RAM) refers to any type of random access memory (RAM) specifically used to store
image data for a computer display. A small outline dual inline memory module (SODIMM)
can be purchased in various types and sizes to fit any laptop, router, or other
small form factor computing device.
Question 5: You just replaced a failed motherboard in a corporate workstation and
returned it to service. About an hour later, the customer complained that the
workstation is randomly shutting down and rebooting itself. You suspect the
memory module may be corrupt, and you perform a memory test, but the memory
passes all of your tests. Which of the following should you attempt NEXT in
troubleshooting this problem?
A. Remove and reseat the RAM
B. Verify the case fans are clean and properly connected
C. Reset the BIOS
D. Replace the RAM with ECC modules
Correct Answer: B
Explanation
OBJ-5.2: If a workstation overheats, it will shut down or reboot itself to
protect the processor. This can occur if the case fans are clogged with dust or
become unplugged. By checking and reconnecting the case fans, the technician can
rule out an overheating issue causing this problem. Since the memory was already
tested successfully, it does not need to be removed and reseated, or replaced
with ECC modules. The BIOS is not the issue since the computer booted up into
Windows successfully before rebooting.
Introduction The AWS Certified Solutions Architect - Associate (SAA-C03) exam is intended
for individuals who perform in a solutions architect role. The exam validates a
candidate’s ability to use AWS technologies to design solutions based on the AWS
Well-Architected Framework.
The exam also validates a candidate’s ability to complete the following
tasks: • Design solutions that incorporate AWS services to meet current business
requirements and future projected needs
• Design architectures that are secure, resilient, high-performing, and
cost-optimized
• Review existing solutions and determine improvements
Target candidate description The target candidate should have at least 1 year of hands-on experience
designing cloud solutions that use AWS services.
For a detailed list of specific tools and technologies that might be covered on
the exam, as well as lists of in-scope and out-of-scope AWS services, refer to
the Appendix.
Exam content Response types There are two types of questions on the exam:
• Multiple choice: Has one correct response and three incorrect responses (distractors)
• Multiple response: Has two or more correct responses out of five or more
response options
Select one or more responses that best complete the statement or answer the
question. Distractors, or incorrect answers, are response options that a
candidate with incomplete knowledge or skill might choose. Distractors are
generally plausible responses that match the content area.
Unanswered questions are scored as incorrect; there is no penalty for guessing.
The exam includes 50 questions that will affect your score.
Unscored content The exam includes 15 unscored questions that do not affect your score. AWS
collects information about candidate performance on these unscored questions to
evaluate these questions for future use as scored questions. These unscored
questions are not identified on the exam.
Exam results The AWS Certified Solutions Architect - Associate exam is a pass or fail
exam. The exam is scored against a minimum standard established by AWS
professionals who follow certification industry best practices and guidelines.
Your results for the exam are reported as a scaled score of 100–1,000. The
minimum passing score is 720. Your score shows how you performed on the exam as
a whole and whether or not you passed. Scaled scoring models help equate scores
across multiple exam forms that might have slightly different difficulty levels.
Your score report could contain a table of classifications of your performance
at each section level. This information provides general feedback about your
exam performance. The exam uses a compensatory scoring model, which means that
you do not need to achieve a passing score in each section. You need to pass
only the overall exam.
Each section of the exam has a specific weighting, so some sections have more
questions than other sections have. The table contains general information that
highlights your strengths and weaknesses. Use caution when interpreting
section-level feedback. Candidates who pass the exam will not receive this
additional information.
Content outline
This exam guide includes weightings, test domains, and task statements for the
exam. It is not a comprehensive listing of the content on the exam. However,
additional context for each of the task statements is available to help guide
your preparation for the exam. The following table lists the main content
domains and their weightings. The table precedes the complete exam content
outline, which includes the additional context. The percentage in each domain
represents only scored content.
Knowledge of: • Access controls and management across multiple accounts
• AWS federated access and identity services (for example, AWS Identity and
Access Management [IAM], AWS Single Sign-On [AWS SSO])
• AWS global infrastructure (for example, Availability Zones, AWS Regions)
• AWS security best practices (for example, the principle of least privilege)
• The AWS shared responsibility model
Skills in: • Applying AWS security best practices to IAM users and root users (for
example, multi-factor authentication [MFA])
• Designing a flexible authorization model that includes IAM users, groups,
roles, and policies
• Designing a role-based access control strategy (for example, AWS Security
Token Service [AWS STS], role switching, cross-account access)
• Designing a security strategy for multiple AWS accounts (for example, AWS
Control Tower, service control policies [SCPs])
• Determining the appropriate use of resource policies for AWS services
• Determining when to federate a directory service with IAM roles
Task Statement 2: Design secure workloads and applications.
Knowledge of:
• Application configuration and credentials security
• AWS service endpoints
• Control ports, protocols, and network traffic on AWS
• Secure application access
• Security services with appropriate use cases (for example, Amazon Cognito,
Amazon GuardDuty, Amazon Macie)
• Threat vectors external to AWS (for example, DDoS, SQL injection)
Skills in: • Designing VPC architectures with security components (for example,
security groups, route tables, network ACLs, NAT gateways)
• Determining network segmentation strategies (for example, using public subnets
and private subnets)
• Integrating AWS services to secure applications (for example, AWS Shield, AWS
WAF, AWS SSO, AWS Secrets Manager)
• Securing external network connections to and from the AWS Cloud (for example,
VPN, AWS Direct Connect)
Task Statement 3: Determine appropriate data security controls.
Knowledge of: • Data access and governance
• Data recovery
• Data retention and classification
• Encryption and appropriate key management
Skills in: • Aligning AWS technologies to meet compliance requirements
• Encrypting data at rest (for example, AWS Key Management Service [AWS KMS])
• Encrypting data in transit (for example, AWS Certificate Manager [ACM] using
TLS)
• Implementing access policies for encryption keys
• Implementing data backups and replications
• Implementing policies for data access, lifecycle, and protection
• Rotating encryption keys and renewing certificates
Domain 2: Design Resilient Architectures
Task Statement 1: Design scalable and loosely coupled architectures.
Knowledge of: • API creation and management (for example, Amazon API Gateway, REST API)
• AWS managed services with appropriate use cases (for example, AWS Transfer
Family, Amazon Simple Queue Service [Amazon SQS], Secrets Manager)
• Caching strategies
• Design principles for microservices (for example, stateless workloads compared
with stateful workloads)
• Event-driven architectures
• Horizontal scaling and vertical scaling
• How to appropriately use edge accelerators (for example, content delivery
network [CDN])
• How to migrate applications into containers
• Load balancing concepts (for example, Application Load Balancer)
• Multi-tier architectures
• Queuing and messaging concepts (for example, publish/subscribe)
• Serverless technologies and patterns (for example, AWS Fargate, AWS Lambda)
• Storage types with associated characteristics (for example, object, file,
block)
• The orchestration of containers (for example, Amazon Elastic Container Service
[Amazon ECS], Amazon Elastic Kubernetes Service [Amazon EKS])
• When to use read replicas
• Workflow orchestration (for example, AWS Step Functions)
Skills in: • Designing event-driven, microservice, and/or multi-tier architectures
based on requirements
• Determining scaling strategies for components used in an architecture design
• Determining the AWS services required to achieve loose coupling based on
requirements
• Determining when to use containers
• Determining when to use serverless technologies and patterns
• Recommending appropriate compute, storage, networking, and database
technologies based on requirements
• Using purpose-built AWS services for workloads
Task Statement 2: Design highly available and/or fault-tolerant architectures.
Knowledge of:
• AWS global infrastructure (for example, Availability Zones, AWS Regions,
Amazon Route 53)
• AWS managed services with appropriate use cases (for example, Amazon
Comprehend, Amazon Polly)
• Basic networking concepts (for example, route tables)
• Disaster recovery (DR) strategies (for example, backup and restore, pilot
light, warm standby, active-active failover, recovery point objective [RPO],
recovery time objective [RTO])
• Distributed design patterns
• Failover strategies
• Immutable infrastructure
• Load balancing concepts (for example, Application Load Balancer)
• Proxy concepts (for example, Amazon RDS Proxy)
• Service quotas and throttling (for example, how to configure the service
quotas for a workload in a standby environment)
• Storage options and characteristics (for example, durability, replication)
• Workload visibility (for example, AWS X-Ray)
Skills in:
• Determining automation strategies to ensure infrastructure integrity
• Determining the AWS services required to provide a highly available and/or
fault-tolerant architecture across AWS Regions or Availability Zones
• Identifying metrics based on business requirements to deliver a highly
available solution
• Implementing designs to mitigate single points of failure
• Implementing strategies to ensure the durability and availability of data (for
example, backups)
• Selecting an appropriate DR strategy to meet business requirements
• Using AWS services that improve the reliability of legacy applications and
applications not built for the cloud (for example, when application changes are
not possible)
• Using purpose-built AWS services for workloads
Domain 3: Design High-Performing Architectures
Task Statement 1: Determine high-performing and/or scalable storage solutions.
Knowledge of: • Hybrid storage solutions to meet business requirements
• Storage services with appropriate use cases (for example, Amazon S3, Amazon
Elastic File System [Amazon EFS], Amazon Elastic Block Store [Amazon EBS])
• Storage types with associated characteristics (for example, object, file,
block)
Skills in: • Determining storage services and configurations that meet performance
demands
• Determining storage services that can scale to accommodate future needs
Task Statement 2: Design high-performing and elastic compute solutions.
Knowledge of:
• AWS compute services with appropriate use cases (for example, AWS Batch,
Amazon EMR, Fargate)
• Distributed computing concepts supported by AWS global infrastructure and edge
services
• Queuing and messaging concepts (for example, publish/subscribe)
• Scalability capabilities with appropriate use cases (for example, Amazon EC2
Auto Scaling, AWS Auto Scaling)
• Serverless technologies and patterns (for example, Lambda, Fargate)
• The orchestration of containers (for example, Amazon ECS, Amazon EKS)
Skills in:
• Decoupling workloads so that components can scale independently
• Identifying metrics and conditions to perform scaling actions
• Selecting the appropriate compute options and features (for example, EC2
instance types) to meet business requirements
• Selecting the appropriate resource type and size (for example, the amount of
Lambda memory) to meet business requirements
Task Statement 3: Determine high-performing database solutions.
Knowledge of: • AWS global infrastructure (for example, Availability Zones, AWS Regions)
• Caching strategies and services (for example, Amazon ElastiCache)
• Data access patterns (for example, read-intensive compared with
write-intensive)
• Database capacity planning (for example, capacity units, instance types,
Provisioned IOPS)
• Database connections and proxies
• Database engines with appropriate use cases (for example, heterogeneous
migrations, homogeneous migrations)
• Database replication (for example, read replicas)
• Database types and services (for example, serverless, relational compared with
non-relational, in-memory)
Skills in: • Configuring read replicas to meet business requirements
• Designing database architectures
• Determining an appropriate database engine (for example, MySQL compared with
PostgreSQL)
• Determining an appropriate database type (for example, Amazon Aurora, Amazon
DynamoDB)
• Integrating caching to meet business requirements
Task Statement 4: Determine high-performing and/or scalable network
architectures.
Knowledge of: • Edge networking services with appropriate use cases (for example, Amazon
CloudFront, AWS Global Accelerator)
• How to design network architecture (for example, subnet tiers, routing, IP
addressing)
• Load balancing concepts (for example, Application Load Balancer)
• Network connection options (for example, AWS VPN, Direct Connect, AWS
PrivateLink)
Skills in: • Creating a network topology for various architectures (for example,
global, hybrid, multi-tier)
• Determining network configurations that can scale to accommodate future needs
• Determining the appropriate placement of resources to meet business
requirements
• Selecting the appropriate load balancing strategy
Task Statement 5: Determine high-performing data ingestion and transformation
solutions.
Knowledge of:
• Data analytics and visualization services with appropriate use cases (for
example, Amazon Athena, AWS Lake Formation, Amazon QuickSight)
• Data ingestion patterns (for example, frequency)
• Data transfer services with appropriate use cases (for example, AWS DataSync,
AWS Storage Gateway)
• Data transformation services with appropriate use cases (for example, AWS
Glue)
• Secure access to ingestion access points
• Sizes and speeds needed to meet business requirements
• Streaming data services with appropriate use cases (for example, Amazon
Kinesis)
Skills in: • Building and securing data lakes
• Designing data streaming architectures
• Designing data transfer solutions
• Implementing visualization strategies
• Selecting appropriate compute options for data processing (for example, Amazon
EMR)
• Selecting appropriate configurations for ingestion
• Transforming data between formats (for example, .csv to .parquet)
Domain 4: Design Cost-Optimized Architectures
Task Statement 1: Design cost-optimized storage solutions.
Knowledge of: • Access options (for example, an S3 bucket with Requester Pays object
storage)
• AWS cost management service features (for example, cost allocation tags,
multi-account billing)
• AWS cost management tools with appropriate use cases (for example, AWS Cost
Explorer, AWS Budgets, AWS Cost and Usage Report)
• AWS storage services with appropriate use cases (for example, Amazon FSx,
Amazon EFS, Amazon S3, Amazon EBS)
• Backup strategies
• Block storage options (for example, hard disk drive [HDD] volume types, solid
state drive [SSD] volume types)
• Data lifecycles
• Hybrid storage options (for example, DataSync, Transfer Family, Storage
Gateway)
• Storage access patterns
• Storage tiering (for example, cold tiering for object storage)
• Storage types with associated characteristics (for example, object, file,
block)
Skills in:
• Designing appropriate storage strategies (for example, batch uploads to Amazon
S3 compared with individual uploads)
• Determining the correct storage size for a workload
• Determining the lowest cost method of transferring data for a workload to AWS
storage
• Determining when storage auto scaling is required
• Managing S3 object lifecycles
• Selecting the appropriate backup and/or archival solution
• Selecting the appropriate service for data migration to storage services
• Selecting the appropriate storage tier
• Selecting the correct data lifecycle for storage
• Selecting the most cost-effective storage service for a workload
Task Statement 2: Design cost-optimized compute solutions.
Knowledge of:
• AWS cost management service features (for example, cost allocation tags,
multi-account billing)
• AWS cost management tools with appropriate use cases (for example, Cost
Explorer, AWS Budgets, AWS Cost and Usage Report)
• AWS global infrastructure (for example, Availability Zones, AWS Regions)
• AWS purchasing options (for example, Spot Instances, Reserved Instances,
Savings Plans)
• Distributed compute strategies (for example, edge processing)
• Hybrid compute options (for example, AWS Outposts, AWS Snowball Edge)
• Instance types, families, and sizes (for example, memory optimized, compute
optimized, virtualization)
• Optimization of compute utilization (for example, containers, serverless
computing, microservices)
• Scaling strategies (for example, auto scaling, hibernation)
Skills in: • Determining an appropriate load balancing strategy (for example,
Application Load Balancer [Layer 7] compared with Network Load Balancer [Layer
4] compared with Gateway Load Balancer)
• Determining appropriate scaling methods and strategies for elastic workloads
(for example, horizontal compared with vertical, EC2 hibernation)
• Determining cost-effective AWS compute services with appropriate use cases
(for example, Lambda, Amazon EC2, Fargate)
• Determining the required availability for different classes of workloads (for
example, production workloads, non-production workloads)
• Selecting the appropriate instance family for a workload
• Selecting the appropriate instance size for a workload
Task Statement 3: Design cost-optimized database solutions.
Knowledge of:
• AWS cost management service features (for example, cost allocation tags,
multi-account billing)
• AWS cost management tools with appropriate use cases (for example, Cost
Explorer, AWS Budgets, AWS Cost and Usage Report)
• Caching strategies
• Data retention policies
• Database capacity planning (for example, capacity units)
• Database connections and proxies
• Database engines with appropriate use cases (for example, heterogeneous
migrations, homogeneous migrations)
• Database replication (for example, read replicas)
• Database types and services (for example, relational compared with
non-relational, Aurora, DynamoDB)
Skills in: • Designing appropriate backup and retention policies (for example, snapshot
frequency)
• Determining an appropriate database engine (for example, MySQL compared with
PostgreSQL)
• Determining cost-effective AWS database services with appropriate use cases
(for example, DynamoDB compared with Amazon RDS, serverless)
• Determining cost-effective AWS database types (for example, time series
format, columnar format)
• Migrating database schemas and data to different locations and/or different
database engines
Task Statement 4: Design cost-optimized network architectures.
Knowledge of:
• AWS cost management service features (for example, cost allocation tags,
multi-account billing)
• AWS cost management tools with appropriate use cases (for example, Cost
Explorer, AWS Budgets, AWS Cost and Usage Report)
• Load balancing concepts (for example, Application Load Balancer)
• NAT gateways (for example, NAT instance costs compared with NAT gateway costs)
• Network connectivity (for example, private lines, dedicated lines, VPNs)
• Network routing, topology, and peering (for example, AWS Transit Gateway, VPC
peering)
• Network services with appropriate use cases (for example, DNS)
Skills in: • Configuring appropriate NAT gateway types for a network (for example, a
single shared NAT gateway compared with NAT gateways for each Availability Zone)
• Configuring appropriate network connections (for example, Direct Connect
compared with VPN compared with internet)
• Configuring appropriate network routes to minimize network transfer costs (for
example, Region to Region, Availability Zone to Availability Zone, private to
public, Global Accelerator, VPC endpoints)
• Determining strategic needs for content delivery networks (CDNs) and edge
caching
• Reviewing existing workloads for network optimizations
• Selecting an appropriate throttling strategy
• Selecting the appropriate bandwidth allocation for a network device (for
example, a single VPN compared with multiple VPNs, Direct Connect speed)
Question 1:
A software development company is using serverless computing with AWS Lambda to
build and run applications without having to set up or manage servers. They have
a Lambda function that connects to a MongoDB Atlas, which is a popular Database
as a Service (DBaaS) platform and also uses a third party API to fetch certain
data for their application. One of the developers was instructed to create the
environment variables for the MongoDB database hostname, username, and password
as well as the API credentials that will be used by the Lambda function for DEV,
SIT, UAT, and PROD environments.
Considering that the Lambda function is storing sensitive database and API
credentials, how can this information be secured to prevent other developers in
the team, or anyone, from seeing these credentials in plain text? Select the
best option that provides maximum security.
A. Enable SSL encryption that leverages on AWS CloudHSM to store and encrypt the
sensitive information.
B. AWS Lambda does not provide encryption for the environment variables. Deploy
your code to an EC2 instance instead.
C. There is no need to do anything because, by default, AWS Lambda already
encrypts the environment variables using the AWS Key Management Service.
D. Create a new KMS key and use it to enable encryption helpers that leverage on
AWS Key Management Service to store and encrypt the sensitive information.
Correct Answer: D
Explanation
When you create or update Lambda functions that use environment variables, AWS
Lambda encrypts them using the AWS Key Management Service. When your Lambda
function is invoked, those values are decrypted and made available to the Lambda
code.
The first time you create or update Lambda functions that use environment
variables in a region, a default service key is created for you automatically
within AWS KMS. This key is used to encrypt environment variables. However, if
you wish to use encryption helpers and use KMS to encrypt environment variables
after your Lambda function is created, you must create your own AWS KMS key and
choose it instead of the default key. The default key will give errors when
chosen. Creating your own key gives you more flexibility, including the ability
to create, rotate, disable, and define access controls, and to audit the
encryption keys used to protect your data.
Question 2: A company hosted an e-commerce website on an Auto Scaling group of EC2
instances behind an Application Load Balancer. The Solutions Architect noticed
that the website is receiving a large number of illegitimate external requests
from multiple systems with IP addresses that constantly change. To resolve the
performance issues, the Solutions Architect must implement a solution that would
block the illegitimate requests with minimal impact on legitimate traffic.
Which of the following options fulfills this requirement?
A. Create a regular rule in AWS WAF and associate the web ACL to an Application
Load Balancer.
B. Create a rate-based rule in AWS WAF and associate the web ACL to an
Application Load Balancer.
C. Create a custom rule in the security group of the Application Load Balancer
to block the offending requests.
D. Create a custom network ACL and associate it with the subnet of the
Application Load Balancer to block the offending requests.
Correct Answer: B
Question 4: There was an incident in your production environment where the user data
stored in the S3 bucket has been accidentally deleted by one of the Junior
DevOps Engineers. The issue was escalated to your manager and after a few days,
you were instructed to improve the security and protection of your AWS
resources.
What combination of the following options will protect the S3 objects in your
bucket from both accidental deletion and overwriting? (Select TWO.)
A. Enable Versioning
B. Enable Amazon S3 Intelligent-Tiering
C. Provide access to S3 data strictly through pre-signed URL only
D. Enable Multi-Factor Authentication Delete
E. Disallow S3 Delete using an IAM bucket policy
Correct Answer: B,D
Question 5: A popular social media website uses a CloudFront web distribution to serve
their static contents to their millions of users around the globe. They are
receiving a number of complaints recently that their users take a lot of time to
log into their website. There are also occasions when their users are getting
HTTP 504 errors. You are instructed by your manager to significantly reduce the
user's login time to further optimize the system.
Which of the following options should you use together to set up a
cost-effective solution that can improve your application's performance? (Select
TWO.)
A. Customize the content that the CloudFront web distribution delivers to your
users using Lambda@Edge, which allows your Lambda functions to execute the
authentication process in AWS locations closer to the users.
B. Deploy your application to multiple AWS regions to accommodate your users
around the world. Set up a Route 53 record with latency routing policy to route
incoming traffic to the region that provides the best latency to the user.
C. Configure your origin to add a Cache-Control max-age directive to your
objects, and specify the longest practical value for max-age to increase the
cache hit ratio of your CloudFront distribution.
D. Set up an origin failover by creating an origin group with two origins.
Specify one as the primary origin and the other as the second origin which
CloudFront automatically switches to when the primary origin returns specific
HTTP status code failure responses.
E. Use multiple and geographically disperse VPCs to various AWS regions then
create a transit VPC to connect all of your resources. In order to handle the
requests faster, set up Lambda functions in each region using the AWS Serverless
Application Model (SAM) service.
Correct Answer: A,D
Question 6: A company is using Amazon S3 to store frequently accessed data. When an
object is created or deleted, the S3 bucket will send an event notification to
the Amazon SQS queue. A solutions architect needs to create a solution that will
notify the development and operations team about the created or deleted objects.
Which of the following would satisfy this requirement?
A. Create a new Amazon SNS FIFO topic for the other team. Grant Amazon S3
permission to send the notification to the second SNS topic.
B. Set up another Amazon SQS queue for the other team. Grant Amazon S3
permission to send a notification to the second SQS queue.
C. Set up an Amazon SNS topic and configure two Amazon SQS queues to poll the
SNS topic. Grant Amazon S3 permission to send notifications to Amazon SNS and
update the bucket to use the new SNS topic.
D. Create an Amazon SNS topic and configure two Amazon SQS queues to subscribe
to the topic. Grant Amazon S3 permission to send notifications to Amazon SNS and
update the bucket to use the new SNS topic.
Correct Answer: D
Appendix Which key tools, technologies, and concepts might be covered on the exam?
The following is a non-exhaustive list of the tools and technologies that could
appear on the exam. This list is subject to change and is provided to help you
understand the general scope of services, features, or technologies on the exam.
The general tools and technologies in this list appear in no particular order.
AWS services are grouped according to their primary functions. While some of
these technologies will likely be covered more than others on the exam, the
order and placement of them in this list is no indication of relative weight or
importance:
• Compute
• Cost management
• Database
• Disaster recovery
• High performance
• Management and governance
• Microservices and component decoupling
• Migration and data transfer
• Networking, connectivity, and content delivery
• Resiliency
• Security
• Serverless and event-driven design principles
• Storage
Candidates for this exam set up and use the application functionality in
Dynamics 365 Commerce and provide support for the application.
Candidates have a strong understanding of unified commerce business operations.
They may have experience configuring, deploying, and maintaining Dynamics 365
Commerce.
Part of the requirements for: Microsoft Certified: Dynamics 365 Commerce
Functional Consultant Associate
Related exams: 1 related exam
Important: See details
Exam MB-340: Microsoft Dynamics 365 Commerce Functional Consultant (beta)
Languages: English
Retirement date: none
This exam measures your ability to accomplish the following technical tasks:
configure Dynamics 365 Commerce Headquarters; configure products, prices,
discounts, loyalty, and affiliations; manage Point of Sales (POS) in Dynamics
365 Commerce; configure and manage Dynamics 365 Commerce call centers; and
manage e-commerce.
Skills measured Configure Dynamics 365 Commerce Headquarters (20-25%)
Configure products, prices, discounts, loyalty, and affiliations (20-25%)
Manage Point of Sales (POS) in Dynamics 365 Commerce (15-20%)
Configure and manage Dynamics 365 Commerce call centers (10-15%)
Manage e-commerce (15-20%)
Audience Profile
Candidates for this exam design, configure, and manage Dynamics 365 Commerce and
provide ongoing support for the app.
Candidates have a strong understanding of unified commerce business operations.
They may have experience deploying, using, and maintaining Dynamics 365
Commerce.
Skills Measured
NOTE: The bullets that appear below each of the skills measured are intended to
illustrate how we are assessing that skill. This list is NOT definitive or
exhaustive.
NOTE: Most questions cover features that are general availability (GA). The exam
may contain questions on Preview features if those features are commonly used.
Configure Dynamics 365 Commerce Headquarters (25-30%) Configure prerequisites and commerce parameters
create employee and customer address books
configure and manage retail workers
assign address books to customers, channels, and workers
create email templates and email notification profiles
configure organizational hierarchies and hierarchy purposes
configure Commerce shared parameters
configure company-specific Commerce parameters
Describe and configure additional functionality
create and configure channel and sales order attributes
configure commissions and sales representatives
configure payment methods and card types
configure and manage gift cards
describe Omni-channel capabilities including payments, orders, and returns
configure data distribution
create info codes, sub-codes, and info code groups
describe Dynamics 365 Fraud Protection purchase protection, loss prevention,
and account protection
Manage statements
describe advantages of using trickle feed-based posting
validate retail transactions by using the transaction consistency checker
configure and manage retail statement calculations and posting
troubleshoot statement posting issues
Configure Distributed Order Management (DOM)
configure fulfillment profiles
configure cost components including shipping, handling, and packaging costs
configure management rules and parameters
monitor fulfillment plans and order exceptions
Configure order fulfillment
configure modes of delivery including shipments, pick up, and carry out
configure curbside customer order pickup
configure charge codes, charge groups, and automatic charges
configure and assign order fulfillment groups
Configure products, prices, discounts, loyalty, and
affiliations (25-30%) Configure products and merchandising
configure product category hierarchies
configure product attributes and attribute groups
configure assortments and product catalogs
manage product labels and shelf labels
describe uses cases for recommendation types including product, personalized,
Shop similar looks, and Shop similar descriptions recommendations
configure recommendations
configure warranty settings
configure inventory buffers and inventory levels
configure products and variants including configuring barcodes
Manage Point of Sale (POS) in Dynamics 365 Commerce (15-20%) Configure retail stores
create a retail store
configure POS registers and devices
configure retail profiles
configure sales tax overrides
configure Task Management lists and parameters
define cash management processes
define shifts and shift management processes
configure channel return policies
describe offline capabilities and limitations
Manage store inventory
configure availability calculations for products
manage inbound and outbound inventory operations
process customer pick-up and shipment orders
manage inventory processes including stock counts
look up product inventory
process serialized items
Perform POS operations
perform sales and order processes
perform end of day processes
reconcile store cash
monitor store productivity by using task management and reporting features
Configure and Manage Dynamics 365 Commerce call centers
(10-15%) Configure call centers
create a call center
configure and publish product catalogs
create product catalog scripts
configure fraud conditions, rules, and variables to trigger order holds
configure fraud alerts
Configure continuity orders and installment billing
set up continuity programs and parameters
configure continuity order batch jobs
manage continuity child orders
Manage call centers
create, modify, and process sales orders
process call center payments
manage order holds
create return merchandise authorizations (RMAs)
process returns, exchanges, and replacements
Manage e-commerce (15-20%) Configure an e-commerce channel
create an online store
configure an e-commerce site
configure channel assignments for an e-commerce site
configure ratings and reviews
Manage e-commerce content
configure URLs and aliases
configure product detail pages and category pages
manage site themes, page fragments, templates, layouts, and pages
upload and manage digital assets including videos and images
set focal points and attribute values for media assets
configure publish groups
Operate an e-commerce channel
create e-commerce orders
synchronize e-commerce orders
moderate ratings and reviews
Configure business-to-business (B2B) e-commerce
describe differences between B2B and business-to-consumer (B2C) solutions
describe use cases for organizational modeling hierarchies
manage business partners and business partner users
configure product quantity limits
QUESTION 1
A company has recently deployed Microsoft Dynamics 365 Finance. You have been
hired as a Systems
Administrator. Your role will include the management of the Dynamics 365 system.
The company has several departments. You need to configure allocations for the
departments. The company
has the following requirements for the allocations:
The allocations should be fixed or variable.
Allocation journal entries must be automatically created for review before
posting.
You need to configure the system to meet the requirements.
What should you configure?
A. Transfer balance
B. Allocation terms
C. Ledger settlements
D. Ledger allocation rules
Correct Answer: D
QUESTION 2
Your role of Systems Administrator includes the management of your company’s
Microsoft Dynamics 365 Finance system.
You need to configure posting definitions and posting profiles. You need to
determine under which
circumstance you should configure a posting definition or a posting profile.
Which two of the following statements are true? (Choose two).
A. You should use posting definitions when you need to support encumbrance
accounting for purchase orders and pre-encumbrance accounting for purchase
requisitions.
B. You should use posting profiles when you need to support encumbrance
accounting for purchase orders and pre-encumbrance accounting for purchase
requisitions.
C. You should use posting definitions when you need to generate multiple,
balanced ledger entries based on attributes such as transaction types and
accounts.
D. You should use posting definitions when you need only one offset ledger
entry.
Correct Answer: A,C
QUESTION 3
A company has recently deployed Microsoft Dynamics 365 Finance. You have been
hired as a Systems
Administrator. Your role will include the management of the Dynamics 365 Finance
system.
You need to configure fiscal calendars to be used with fixed asset depreciation,
financial transactions, and budget cycles.
Which two of the following statements are true? (Choose two)
A. A fiscal calendar can contain multiple fiscal years.
B. A fiscal calendar is limited to a maximum of one year.
C. A fiscal calendar can be used by multiple legal entities.
D. A fiscal period can contain multiple fiscal calendars.
The English language version of this exam was updated on April 25,
2022.
Following the current exam guide, we have included a table that compares the
previous study guide to the new one by functional group, showing the changes
that were made to the exam on that date. We have also included the previous
study guide for reference purposes.
The table below shows the changes that were implemented on April 25, 2022 to the
English language version of this exam. Following the comparison table, the
previous study guide is included for reference
Old objective number
Subtask changes and new location
1.1 Describe
security and compliance concepts & methodologies
Revised title and
subtasks
1.2 Define identity
concepts
Revised subtasks
2.1 Describe the
basic identity services and identity types of Azure AD
Revised subtasks
2.2 Describe the
authentication capabilities of Azure AD
Revised subtasks
2.3 Describe access
management capabilities of Azure AD
Revised subtasks
2.4 Describe the
identity protection & governance capabilities of Azure AD
Revised subtasks
3.1 Describe basic
security capabilities in Azure
Revised subtasks
3.2 Describe
security management capabilities of Azure
Revised subtasks
3.3 Describe
security capabilities of Azure Sentinel
Revised subtasks
3.4 Describe threat
protection with Microsoft 365 Defender
Revised subtasks
3.5 Describe
security management capabilities of Microsoft 365
Deleted; moved to
3.4
3.6
Describe endpoint security with Microsoft Intune
Deleted
4.1
Describe the compliance management capabilities in Microsoft
Revised title and subtasks, split into 4.1 and 4.2
4.2
Describe information protection and governance capabilities of Microsoft 365
Revised title and subtasks
4.3
Describe insider risk capabilities in Microsoft 365
Revised subtasks
4.4
Describe resource governance capabilities in Azure
Revised title and subtasks
Audience Profile This certification is targeted to those looking to familiarize themselves
with the fundamentals of security, compliance, and identity (SCI) across
cloud-based and related Microsoft services.
This is a broad audience that may include business stakeholders, new or existing
IT professionals, or students who have an interest in Microsoft security,
compliance, and identity solutions.
Candidates should be familiar with Microsoft Azure and Microsoft 365 and want to
understand how Microsoft security, compliance, and identity solutions can span
across these solution areas to provide a holistic and end-to-end solution.
Skills Measured NOTE: The bullets that follow each of the skills measured are intended to
illustrate how we are assessing that skill. Related topics may be covered in the
exam.
NOTE: Most questions cover features that are general availability (GA). The exam
may contain questions on Preview features if those features are commonly used.
Describe the concepts of security, compliance, and identity (5-10%)
Describe security and compliance concepts & methodologies • describe the Zero-Trust methodology
• describe the shared responsibility model
• define defense in depth
• describe common threats
• describe encryption and hashing
• describe cloud adoption framework
Define identity concepts • define identity as the primary security perimeter
• define authentication
• define authorization
• describe what identity providers are
• describe what Active Directory is
• describe the concept of Federated services
• define common Identity Attacks
Describe the capabilities of Microsoft identity and access management solutions
(25-30%)
Describe the basic identity services and identity types of Azure AD
• describe what Azure Active Directory is
• describe Azure AD identity types (users, devices, groups, service
principals/applications)
• describe what hybrid identity is
• describe the different external identity types (Guest Users)
Describe the authentication capabilities of Azure AD • describe the different authentication methods
• describe self-service password reset
• describe password protection and management capabilities
• describe Multi-factor Authentication
• describe Windows Hello for Business
Describe access management capabilities of Azure AD
• describe what conditional access is
• describe uses and benefits of conditional access
• describe the benefits of Azure AD roles
Describe the identity protection & governance capabilities of Azure AD • describe what identity governance is
• describe what entitlement management and access reviews is
• describe the capabilities of PIM
• describe Azure AD Identity Protection
Describe the capabilities of Microsoft Security solutions (30-35%)
Describe basic security capabilities in Azure
• describe Azure Network Security groups
• describe Azure DDoS protection
• describe what Azure Firewall is
• describe what Azure Bastion is
• describe what Web Application Firewall is
• describe ways Azure encrypts data
Describe security management capabilities of Azure • describe Cloud security posture management (CSPM)
• describe Microsoft Defender for Cloud
• describe secure score in Microsoft Defender Cloud
• describe enhanced security of Microsoft Defender for Cloud
• describe security baselines for Azure
Describe security capabilities of Microsoft Sentinel
• define the concepts of SIEM, SOAR, XDR
• describe how of Microsoft Sentinel provides integrated threat protection
Describe threat protection with Microsoft 365 Defender • describe Microsoft 365 Defender services
• describe Microsoft Defender for Identity (formerly Azure ATP)
• describe Microsoft Defender for Office 365 (formerly Office 365 ATP)
• describe Microsoft Defender for Endpoint (formerly Microsoft Defender ATP)
• describe Microsoft Defender for Cloud Apps
Describe security management capabilities of Microsoft 365 • describe the Microsoft 365 Defender portal
• describe how to use Microsoft Secure Score
• describe security reports and dashboards
• describe incidents and incident management capabilities
Describe endpoint security with Microsoft Intune
• describe what Intune is
• describe endpoint security with Intune
• describe the endpoint security with the Microsoft Endpoint Manager admin
center
Describe the capabilities of Microsoft compliance solutions (25-30%)
Describe the compliance management capabilities in Microsoft • describe the offerings of the Service Trust portal
• describe Microsoft’s privacy principles
• describe the compliance center
• describe compliance manager
• describe use and benefits of compliance score
Describe information protection and governance capabilities of Microsoft 365 • describe data classification capabilities
• describe the value of content and activity explorer
• describe sensitivity labels
• describe Retention Polices and Retention Labels
• describe Records Management
• describe Data Loss Prevention
Describe insider risk capabilities in Microsoft 365
• describe Insider risk management solution
• describe communication compliance
• describe information barriers
• describe privileged access management
• describe customer lockbox
Describe the eDiscovery and audit capabilities of Microsoft 365 • describe the purpose of eDiscovery
• describe the capabilities of the content search tool
• describe the core eDiscovery workflow
• describe the advanced eDiscovery workflow
• describe the core audit capabilities of M365
• describe purpose and value of Advanced Auditing
Describe resource governance capabilities in Azure • describe the use of Azure Resource locks
• describe what Azure Blueprints is
• define Azure Policy and describe its use cases
QUESTION 1
Which score measures an organization's progress in completing actions that help reduce risks associated to
data protection and regulatory standards?
A. Microsoft Secure Score
B. Productivity Score
C. Secure score in Azure Security Center
D. Compliance score
Answer: D
QUESTION 2
What do you use to provide real-time integration between Azure Sentinel and another security source?
A. Azure AD Connect
B. a Log Analytics workspace
C. Azure Information Protection
D. a connector
Answer: D
QUESTION 3
Which Microsoft portal provides information about how Microsoft cloud services comply with regulatory
standard,
such as International Organization for Standardization (ISO)?
A. the Microsoft Endpoint Manager admin center
B. Azure Cost Management + Billing
C. Microsoft Service Trust Portal
D. the Azure Active Directory admin center
Answer: C
QUESTION 4
In the shared responsibility model for an Azure deployment, what is Microsoft solely responsible for managing?
A. the management of mobile devices
B. the permissions for the user data stored in Azure
C. the creation and management of user accounts
D. the management of the physical hardware
Answer: D
QUESTION 5
In the Microsoft Cloud Adoption Framework for Azure, which two phases are addressed before the Ready
phase?
Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. Plan
B. Manage
C. Adopt
D. Govern
E. Define Strategy
Certification Overview This entry level certification is intended for administrators who can
demonstrate basic support and technical knowledge of IBM Security QRadar SIEM
V7.3.2, including implementation and management of an IBM Security QRadar SIEM
V7.3.2 solution.
Overall, these administrators are familiar with product functionality and the
security policies. They plan, install, configure, implement, deploy, migrate,
upgrade, monitor and troubleshoot the IBM Security QRadar SIEM V7.3.2 software.
Note: The function of specific apps, apart from the two bundled with the
product, is out of scope, but the concept of extending the capability of using
apps is in scope.
Recommended Skills
Basic knowledge in: RedHat
Networking
Basic Query Language
Regular Expressions
System architecture design
Security platforms
Requirements Exam C1000-026: IBM Security QRadar SIEM V7.3.2 Fundamental Administration
The test: contains questions requiring single and multiple answers. For
multiple-answer questions, you need to choose all required options to get the
answer correct. You will be advised how many options make up the correct answer.
is designed to provide diagnostic feedback on the Examination Score Report,
correlating back to the test objectives, informing the test taker how he or she
did on each section of the test. As a result, to maintain the integrity of each
test, questions and answers are not distributed.
Exam Objectives The test consists of 5 sections containing a total of approximately 60
multiple-choice questions. The percentages after each section title reflect the
approximate distribution of the total question set across the sections.
Number of questions: 60
Number of questions to pass: 40
Time allowed: 90 minutes
Status: Withdrawn
Section 1: Implementing
Plan and design QRadar deployment.
Implement and install QRadar.
Add Managed Hosts.
Section2: Migrating and upgrading Plan QRadar upgrade and migration.
Review documentation and release notes.
Perform QRadar updates, patches and upgrades.
Perform migration (e.g., backup and restore, import and export content).
Section3: Configuring and Administering task
Configure event flow sources and custom properties.
Maintain configuration and data backups.
Create and administer users, user roles, and security profiles.
Manage the license per allocation.
Create, review and modify rules, building blocks and reference sets.
Configure and manage retention policies (i.e., data and assets).
Create and manage saved searches, index, global views, dashboards and reports.
Deploy and manage applications and content packages.
Configure global system notifications.
Configure and apply network hierarchy.
Configure and manage domain and tenants.
Use the asset database.
Schedule and run a VA scan.
Section4: Monitoring Monitor QRadar Notifications and error messages.
Review and interpret system monitoring dashboards.
Verify QRadar processes and services.
Monitor QRadar performance.
Use apps and tools for monitoring (e.g., QDI, assistant app, incident overview,
DrQ).
Check system maintenance and health of appliances.
Monitor offenses and detect anomalies.
Section5: Troubleshooting
Exam Resources To prepare for the test, take the first self-study course listed below. It
is free-of-charge and covers all the knowledge and skills measured on the test.
The second course listed (BQ103), alone will not adequately help you prepare for
the test. BQ103 can, however, be used as a supplement to the first self-study
course. To register for the second course, click here to contact one of IBM's
Global Training Providers.
(*) Notes:
These learning sources are recommended, but not required before taking this
test.
Every effort has been made to make the recommended learning sources as complete
and as accurate as possible, but no warranty of fitness is implied. The learning
sources provided are on an 'as is' basis. IBM shall have neither liability nor
responsibility to any person or entity with respect to any loss or damages
arising from course or publication content.
You must be logged in to the Security Learning Academy for the link to the
self-study course to work properly. If you see an error message after clicking a
link, log in and retry the link.
QUESTION 1 An administrator needs to import data into QRadar for a specific use case.
The data that has been provided to the administrator is stored in records that
map a key to a value.
Which type of data collection must the administrator create?
A. Reference set
B. Reference map of sets
C. Reference map
D. Reference map of maps
Answer: B
QUESTION 2 An administrator needs to know if a custom rule is being correlated
correctly.
Which QRadar component is responsible for this process?
A. QRadar Event Collector
B. QRadar Console
C. Magistrate
D. QRadar Event Processor
Answer: D
QUESTION 3 An administrator needs to collect logs from the Command Line Interface (CLI).
Which command should the administrator use?
A. /opt/bin/qradar/support/get_logs.sh
B. /opt/support/get_logs.sh
C. /opt/support/qradar/get_logs.sh
D. /opt/qradar/support/get_logs.sh
Answer: D
QUESTION 4 To comply with specific regulations, an administrator has been requested to
increase asset retention to 365 days.
In which QRadar section can the administrator find the asset retention settings?
A. Admin Tab / Asset Retention
B. Assets Tab / Retention settings
C. Admin Tab / System settings
D. Assets Tab / Asset Retention
Answer: C
QUESTION 5 A QRadar administrator added High Availability (HA) to the Event Processor
and needs to verify the crossover
link status between the primary and secondary hosts.
Which commands can be used to verify the crossover status? (Choose two.)
A. /opt/qradar/ha/bin/ha_getstate.sh
B. /opt/qradar/ha/bin/getStatus crossover
C. /opt/qradar/ha/bin/qradar_nettune.pl crossover status
D. /opt/qradar/ha/bin/qradar_nettune.pl linkaggr <interface> status
E. /opt/qradar/ha/bin/ha cstate
F. cat /proc/drbd