01. Client users at a marine engineering firm cannot reach one internal application, while every other internal application on the same private path works for them. Staff behind the branch site onramp reach the application normally, and their sessions are allowed by a rule that names it. For the client users, no decision of any kind is recorded for their attempts.
What explains the difference?
a) The private path in front of the application is reachable only from the site onramp so client sessions are dropped.
b) The client sessions carry no posture information so the rule naming the application is never selected for them.
c) That destination sits outside what the client tunnel carries, so nothing they send to it ever enters the service to be evaluated.
d) The rule permitting the application does not include the client population, so their sessions are refused by default.
02. An architecture practice has moved its drawing-file collaboration to a hosted service. Its designers say that saving and reloading drawings crawls, while browser applications and voice calls over the same site connection stay fine. The site is served from the nearest placement available to it, its connection is nowhere near exhausted, and the drawing traffic follows the route the design intends.
What does this evidence indicate, and what class of remedy follows?
a) The drawing traffic is taking an unintended route, so the remedy corrects how it is steered.
b) That site's connection is too small for files this large, so the remedy adds more bandwidth.
c) These designers are served from the wrong placement, so the remedy changes where they are served.
d) One application suffers on an otherwise healthy path, so the remedy is better path use.
03. Two complaints arrive at a media agency's service desk on the same morning. A designer can suddenly open a finance reporting application she has never been entitled to use, and a finance analyst is refused that same application. Both connected shortly after two other staff disconnected. The record shows each session attributed to a named user, and in each case the rule that matched behaved exactly as written for the user it names.
What is the fault?
a) The sessions are attributed to the wrong people, so each decision is correct for the identity it names.
b) The finance rule sits above the rule written for the design team, so the narrower rule never matches at all.
c) The identity source has not yet reflected the changes made to both users' group memberships in the directory.
d) Authentication succeeded for both users, so the identity provider returned the wrong entitlements to the service.
04. A university has brought its research records system into scope for staff working away from campus. The connection into the data centre is established, routes toward that system are present in both directions, and an administrator can reach it by address from the service side. Staff report that they cannot find the server at all.
What should be established before anything is changed?
a) Whether the staff's own onramp is still delivering their traffic into the service.
b) Whether the service is attributing these staff to the correct group as their traffic arrives.
c) Whether the system's name resolves for those staff, since a route does not supply resolution.
d) Whether a second connection into that data centre is available to these staff.
05. Users behind one automotive parts factory report that an internal application fails intermittently. No other site is affected. A manager notices that the deployment's latest posture assessment has several findings open and asks the team to close those first.
What is the best response to that request?
a) Close the findings first, because an assessment enumerates the configuration defects a fault arises from.
b) Pursue the site-shaped symptom as the diagnostic lead, and treat the findings as separate remediation work.
c) Re-run the assessment against the affected site alone, so that only relevant findings remain.
d) Treat the open findings as the cause and return the deployment to its last assessed state.
06. Over the course of a month, a university closed a set of assessment findings. Its operations lead now reports to the risk committee that the deployment's posture has improved, citing the completed remediation plan as the evidence.
What is required before that claim holds?
a) A fresh measurement of the configuration now in force, which the earlier result cannot describe.
b) Nothing further, since the findings were the measurement and closing them is the improvement.
c) Confirmation from the external compliance review that all of its requirements are now met.
d) A record showing that each remediation change was applied by an authorised administrator.
07. A logistics operator's dispatcher cannot reach any application once her VPN client reports a connection, and this happens from her home network and from a hotel alike. Her authentication succeeds every time, and colleagues running the same client build report nothing unusual. When she works at the depot, where her traffic enters through the site's own connection and the client is disabled, everything works.
Which conclusion does this combination of evidence support?
a) Her client build keeps those applications out of the tunnel, which the depot's connection does not do.
b) This device's client path is at fault, since the same identity succeeds when the same traffic arrives by another onramp.
c) Her user account's group membership has not yet propagated from the identity source into the service.
d) The place serving her mobile sessions has lost its path to those applications, and the depot avoids it.
08. Six subsidiaries of a manufacturing group are each supported by their own small IT team. Someone proposes giving each subsidiary its own tenant for that reason alone; the security policy the six run today is close to identical.
Which consequence should weigh most heavily in that decision?
a) Tenants have to be decided before the deployment is built, because a split cannot be introduced afterwards.
b) The split removes any need for administrative roles inside it, since each team already sees only its own work.
c) Each tenant is inspected separately, so the split multiplies the inspection work the deployment must perform.
d) Policy common to all six then has to be maintained in each tenant separately, and it drifts apart.
09. The security operations team at an online travel company wants a subset of the deployment's records delivered to its own analytics platform. The investigative surfaces in the management plane must keep working exactly as they do today.
What does that requirement describe?
a) Selecting which records go onward while they are still retained for the deployment's own surfaces.
b) Replicating the traffic itself to the analytics platform so that it can be inspected there instead.
c) Extending how long the records are kept so that the analytics platform can query them directly.
d) Moving the deployment's records to the analytics platform, which then becomes where they are kept.
10. Across every location an insurance underwriter serves, users on both onramps begin receiving access their groups do not grant. Rules written without user or group criteria continue to behave normally, and users still authenticate and connect without complaint. No configuration change was applied in the period concerned.
What does the scope of this symptom identify?
a) The onramp serving most of the workforce stopped attaching identity to the sessions it carries.
b) A recently applied estate-wide change removed the group criteria from the rules in question.
c) Each affected user's attribution mapping lapsed at the moment their connection was last re-established.
d) The identity source is unavailable or incomplete, so no rule can resolve the users and groups it names.