All practice questions
1198 questions
Ignite Energy Partners has an on-premises Active Directory Domain Services (AD DS) forest. You are designing a hybrid identity solution to integrate the AD DS forest with a Microsoft Entra ID tenant. The design must meet the following requirements:
- Users must be able to sign in using their on-premises passwords.
- If the connection between the on-premises datacenter and Azure is lost, users must still be able to sign in to Azure resources.
- Users must be able to reset their passwords in Microsoft Entra ID using self-service password reset (SSPR), and the new passwords must write back to the on-premises AD DS.
- On-premises infrastructure requirements and administrative complexity must be minimized.
Which hybrid identity synchronization and authentication method should you recommend?
A logistics organization stores historical delivery logs in CSV format within an Azure Data Lake Storage Gen2 account. You need to design an analytical query solution that enables data analysts to run occasional, ad-hoc SQL queries on these files. The solution must meet the following requirements:
- Minimize costs by utilizing a pay-per-query model rather than provisioning persistent database compute resources.
- Ensure the underlying storage account can survive a primary datacenter outage.
- Ensure that the shared access signatures (SAS) used for external analyst access can be revoked immediately if compromised.
Which solution should you recommend?
An enterprise is designing a secure storage solution for a multi-tenant SaaS application that processes highly sensitive financial transactions in Azure. The solution must satisfy the following architectural requirements:
1. Operations team members must only be granted temporary, time-bound, just-in-time (JIT) access to manage the storage account's networking and security configurations.
2. An external audit firm requires read-only access to a specific blob container named 'audits' for a period of days. This access must be immediately revocable at any point without impacting other active applications or changing the storage account keys.
3. On-premises applications must authenticate to read blobs without storing credentials or access keys locally, ensuring all data plane access is audited.
4. Administrative overhead must be minimized by managing role assignments at scale, avoiding direct user-to-role or service principal-to-role mappings.
Which design strategy meets all these requirements while adhering to the principle of least privilege?
A digital media company is designing a subscription governance strategy for a dedicated rendering subscription in Azure. The strategy must satisfy the following requirements:
* A team of external editors must be able to manage virtual machines and storage accounts within the subscription.
* The editors' access must be restricted to scheduled editing windows and must not be permanently active.
* Administrative overhead must be minimized by avoiding permissions assigned directly to individual user accounts.
* Any new storage account deployed in the subscription must be automatically configured to use customer-managed keys (CMKs) to satisfy compliance audits.
Which governance configuration should you recommend to meet these requirements?
Vortex Quantum Systems is designing an identity and access governance solution for its Microsoft Entra ID tenant. The design must satisfy the following security requirements:
- All administrators must be prompted for multi-factor authentication (MFA) when accessing administrative portals.
- Members of the Global Administrator role must activate their role on-demand, and role activation must require MFA.
- The design must prevent administrative lockout in the event of an Azure MFA service outage.
Which two configurations should you include in the design to meet these requirements?
Select all that apply
You are designing an Azure Storage solution for storing virtual machine backups. The compliance requirements state that the backup data must remain available even in the event of a catastrophic disaster that causes an entire Azure region to become offline. Which storage redundancy option should you recommend to meet the requirements while minimizing costs?
A company is designing the subscription governance structure for its multi-region Azure environment. The environment includes a Production management group that currently contains 15 subscriptions. A centralized operations team requires permissions to start, restart, and monitor virtual machines across all subscriptions within this management group, but they must not be allowed to delete resources or modify virtual machine configurations. The configuration must automatically apply to any new subscriptions added to the Production management group in the future. Additionally, you must ensure that all new virtual machines deployed in these subscriptions are automatically configured with the Azure Monitor agent. Which strategy should you implement to meet the requirements?
A multinational logistics company is designing an Azure-based data integration and analytical storage solution for real-time fleet telemetry. The system must meet the following requirements:
- Ingest telemetry data at a velocity of events per second, peaking at events per second.
- Process a total daily volume of of raw JSON telemetry.
- Store the raw telemetry in an Azure Data Lake Storage Gen2 (ADLS Gen2) account with a retention period of , ensuring the storage survives a primary datacenter outage.
- Enable data analysts to run ad-hoc, exploratory SQL queries on the raw JSON files with a target latency of under for the last of data, without incurring the cost of running persistent compute clusters.
- Grant external auditing firms temporary, read-only access to specific raw data folders for up to , ensuring that access can be revoked immediately if needed.
Which two configurations or services should you recommend to meet these requirements? (Select TWO)
Select all that apply
An organization is migrating a legacy multi-tier web application and its backend database to Azure. The application runs on Linux virtual machines. The design has the following requirements:
* The web application servers require a shared file system that supports POSIX-compliant operations, including hard links, and must remain available in the event of an Azure availability zone outage.
* The database virtual machines require a dedicated high-performance disk for transaction logs that provides high write IOPS and sub-millisecond latency.
Which two storage configurations should you include in the design? (Select two.)
Select all that apply
A company stores transaction log files in an Azure Data Lake Storage Gen2 account. You need to design an analytical query solution that allows data analysts to perform ad-hoc SQL queries directly on these files with minimal operational overhead. The data must remain available even if the primary Azure region suffers a datacenter outage. Which two configurations should you include in the design? (Select TWO.)
Select all that apply
ValoSpan Logistics is planning the deployment of a security model for their Microsoft Entra ID tenant. The security team wants to apply a Conditional Access policy that enforces Multi-Factor Authentication (MFA) for all administrative roles to protect privileged identities. However, the system design must guarantee that administrators can access the tenant if the primary MFA cloud service becomes completely unavailable. Which option should you recommend to prevent administrator lockout while maintaining a secure posture?
You are designing the storage architecture for a global multiplayer online game. The solution must store player profiles and dynamic inventories, and also provide access to large game asset files, such as character textures and game replays. The solution must meet the following requirements:
* Player profiles and inventories: Must support sub-10ms write latency for active players in East US, West Europe, and East Asia, and must prevent hot partition bottlenecks when players gather for large in-game events.
* Game asset files: Must be secured using time-constrained, revocable tokens.
* High Availability: The storage of game assets must survive a regional datacenter outage with zero data loss.
Which database and storage configuration should you recommend?
Kestrel Healthcare Services is designing a hybrid identity and access management solution for a new Microsoft Entra ID tenant. The on-premises Active Directory Domain Services (AD DS) domain will synchronize with Microsoft Entra ID. The design must satisfy the following requirements:
- Users must be able to authenticate to cloud services even if the connection between the on-premises network and Azure is completely lost.
- The security team must be able to detect if user credentials synchronized from on-premises have been posted to the dark web.
- Multi-factor authentication (MFA) must be enforced for all administrative tasks performed by the IT support team.
- The organization must prevent administrative lockout of the tenant if the Entra ID multi-factor authentication service or the Privileged Identity Management (PIM) service experiences an outage.
Which of the following infrastructure designs should you recommend?
A utility company is designing a secure storage solution for smart grid telemetry data stored in Azure Blob Storage. The solution must meet the following requirements:
- Support temporary, read-only access to specific blob containers for external auditors. This access must automatically expire after hours and must be capable of being revoked immediately if a security compromise is suspected.
- Restrict network access to only allow traffic from the company's on-premises office IP range () and a dedicated Azure Virtual Network (VNet).
- Minimize administrative effort and adhere to the principle of least privilege.
Which two configurations should you include in the design?
Select all that apply
Zenith Retail Global is designing a secure identity and access strategy using Microsoft Entra ID. The solution must map specific access control and threat mitigation requirements to the correct Microsoft Entra ID features. Match each security requirement on the left to its corresponding Microsoft Entra ID or Conditional Access feature on the right.
Click a left item, then click its matching right item
Items
Matches
A manufacturing corporation uses an Azure Storage account to store telemetry logs from industrial IoT devices. You are designing a security and access control strategy that meets the following requirements:
1. External maintenance technicians require read-only access to a specific blob container for a 24-hour maintenance window.
2. The access must be immediately revocable at any time without rotating the storage account access keys or impacting other active applications.
3. Internal security administrators responsible for configuring storage access must use Microsoft Entra Privileged Identity Management (PIM) to activate their privileges on a just-in-time (JIT) basis.
4. All administrative assignments and roles must be scalable and avoid direct assignment to individual user identities.
Which of the following designs should you recommend?
An enterprise is designing the storage infrastructure for a financial analytics application that is migrating to Azure. The application has the following requirements:
- A database running on an Azure Virtual Machine requires a dedicated managed disk for write-heavy transaction logs with a performance target of IOPS and sub-millisecond write latency.
- A shared volume must be mounted concurrently by ten Linux servers to process incoming CSV files via the NFS v4.1 protocol with sub-millisecond latency.
- Telemetry logs must be stored cost-effectively for five years. The logs are rarely accessed but must be available for immediate, sub-second query execution when requested.
Which two storage configurations should you include in the design?
Select all that apply
A financial services firm is onboarding an external auditing agency to review its Azure subscription resources. The agency has five auditors who need temporary, approved access to the 'Reader' role on a production subscription. The firm's security policy requires:
- Access must be delegated and managed via groups rather than assigning roles directly to individual user accounts.
- Access must be activated on-demand (Just-In-Time) and require approval.
- The firm must also implement a Conditional Access policy to enforce multi-factor authentication (MFA) for all administrative access, but must prevent tenant lockout of their emergency-access accounts.
Which solution should you recommend to meet these requirements?
An organization needs to set up a backup strategy for their Azure Virtual Machines hosting development and testing workloads. The design must meet the following requirements:
- Minimize storage costs for the backup data.
- Retain daily backups for 30 days.
- Provide the fastest possible restore speed for the last 5 days of backups.
Which of the following configurations should you include in the backup design? (Select TWO).
Select all that apply
An enterprise is designing a high-availability SQL Server Failover Cluster Instance (FCI) on Azure Virtual Machines. The virtual machines are distributed across two Availability Zones within a single region. The database requires a shared storage volume that supports SCSI Persistent Reservations. The storage solution must sustain high IOPS with low latency for transactional workloads and must remain online even if a single datacenter zone experiences an outage. Which storage solution should you recommend?