Tüm alıştırma soruları
1252 soru
An administrator is configuring a standard General Purpose v2 (GPv2) storage account named `mystorage` that currently uses locally-redundant storage (LRS). The administrator needs to configure blob lifecycle management rules and plan for replication upgrades.
Which two configurations are valid or represent correct behaviors for this storage account?
Geçerli olan tümünü seçin
An administrator needs to restrict access to an Azure Storage account named storage1 so that it only accepts traffic originating from a specific subnet in a virtual network. What is the correct sequence of steps to configure this network restriction in the Azure portal?
Öğeleri doğru sıraya koymak için sürükleyin
You manage a Microsoft Entra ID tenant. The tenant contains an administrative unit named HQ-AU and a user named Admin1. Admin1 is assigned the User Administrator role scoped to HQ-AU.
The tenant contains the following two groups:
* Group1: A security group that has the isAssignableToRole property set to Yes and the membership type set to Assigned. Group1 is in the scope of HQ-AU.
* Group2: A security group that has the isAssignableToRole property set to No and the membership type set to Dynamic User. Group2 is in the scope of HQ-AU.
You need to ensure that Admin1 can perform the following tasks:
* Add and remove members in Group1.
* Modify the dynamic membership rule of Group2.
Which two actions should you perform? Each correct answer presents a part of the solution.
Geçerli olan tümünü seçin
An administrator applies a CanNotDelete lock to an Azure resource group named RG-Prod. A virtual machine named VM1 is deployed inside RG-Prod. Is the following statement true or false: VM1 cannot be deleted because it inherits the CanNotDelete lock from RG-Prod?
Your company has an Azure environment structured with the following resource hierarchy:
* Management Group: `MG-Finance`
* Subscription: `Sub-Finance-Prod`
* Resource Group: `RG-Treasury`
* Storage Account: `sttreasurydata`
* Key Vault: `kv-treasury-keys`
You configure the following security settings:
1. A user named `User1` is assigned only the Microsoft Entra ID Global Administrator directory role.
2. A user named `User2` is assigned the Contributor role at the `MG-Finance` scope.
3. A user named `User3` is assigned the Reader role at the `Sub-Finance-Prod` scope and the Storage Blob Data Owner role at the `sttreasurydata` scope.
4. A user named `User4` is assigned the User Access Administrator role at the `RG-Treasury` scope.
Which of the following statements correctly describe the permissions and access levels of these users? (Select two.)
Geçerli olan tümünü seçin
You have a standard General Purpose v2 (GPv2) storage account named storagedatagh in the North Europe region. The storage account is currently configured to use Locally-Redundant Storage (LRS).
You need to change the replication strategy of storagedatagh to Geo-Zone-Redundant Storage (GZRS) to protect against both zonal and regional failures. The solution must minimize administrative effort and avoid any data loss or storage downtime.
Which of the following actions should you perform?
An organization has a Microsoft Entra ID tenant and the following Azure resource hierarchy:
* Management Group: `MG-Production`
* Azure Subscription: `Sub-App1`
* Resource Group: `RG-Database`
* Azure SQL Database: `db-prod`
A user named User1 is a member of an Entra ID security group named `Group-DataOps`.
The following role assignments are configured:
1. `Group-DataOps` is assigned the Contributor role at the `MG-Production` scope.
2. User1 is assigned the Reader role at the `Sub-App1` scope.
3. User1 is assigned the User Access Administrator role at the `RG-Database` scope.
4. User1 is assigned the Global Administrator directory role in Microsoft Entra ID.
Which statement describes the effective permissions of User1?
You manage a Microsoft Entra ID tenant. You configure a security group named Dev-Staff that uses a dynamic user membership rule. You need to delegate the ability to modify the dynamic membership rule of Dev-Staff to a user named Admin1. The solution must follow the principle of least privilege. Which role should you assign to Admin1?
NovaApp Corp. plans to deploy two new virtual machines named VM-Web11 and VM-Web12 in the East US region. The deployment must minimize downtime caused by localized hardware failures or scheduled maintenance within the Azure infrastructure.
Which of the following configuration options can you use to achieve this goal? Select two.
Geçerli olan tümünü seçin
An enterprise administrator configures the following Azure environment hierarchy for a logistics project:
* Management Group: `Logistics-MG`
* Subscription: `Logistics-Prod-Sub`
* Resource Group: `RG-Logistics-Data`
* Storage Account: `salogisticsimages`
User Admin1 is assigned the following roles:
* Microsoft Entra ID role: Global Administrator
* Azure RBAC role: Reader assigned at the `Logistics-MG` scope
Admin1 needs to assign the Contributor role to a developer at the resource group `RG-Logistics-Data` level.
Which role assignment represents the minimum privilege required to enable Admin1 to perform this task?
You have an Azure General Purpose v2 (GPv2) storage account. You need to configure a lifecycle management policy to optimize storage costs. Which two actions can you perform by using lifecycle management rules? (Select two.)
Geçerli olan tümünü seçin
An administrator needs to import of data from an on-premises Windows Server to an Azure Storage account using the Azure Import/Export service. The administrator has purchased three internal 3.5-inch SATA hard drives to perform the transfer. Which of the following tasks must the administrator perform to prepare the drives and configure the import job? (Select TWO)
Geçerli olan tümünü seçin
An administrator is managing an Azure subscription that includes a virtual network named VNet1. VNet1 contains two subnets: Subnet1 and Subnet2. The administrator configures a storage account named storageapp2026 with the firewall set to allow access from 'Selected networks'. Subnet1 has the 'Microsoft.Storage' service endpoint enabled, and the storage account firewall explicitly allows access from Subnet1. Subnet2 contains a private endpoint for the blob service of storageapp2026, which is integrated with a private DNS zone named privatelink.blob.core.windows.net. When the administrator configures Azure Backup to protect the blob containers in storageapp2026, the backup jobs fail with network connectivity errors. Which configuration change should the administrator implement to resolve the backup failure while maintaining the highest level of network security?
Veridian Manufacturing manages its Azure resources using the following Management Group (MG) hierarchy:
* Tenant Root Group (Policy assigned: Audit public IP addresses)
* Infrastructure-MG (User1 assigned Reader role)
* Security-MG
* Subscription-A
* Core-Services-MG
* Operations-MG
* Subscription-B
An administrator relocates Subscription-A from Security-MG to Operations-MG.
What is the status of User1's RBAC role assignment and the audit policy for resources inside Subscription-A after the move?
You manage a Microsoft Entra ID tenant that contains a security group named Sales-Group. You need to delegate the management of Sales-Group to a user named User1, allowing them to add and remove members. The solution must minimize the administrative privileges assigned to User1. Which action should you perform?
Your company is migrating a critical line-of-business application to Azure. You plan to deploy three virtual machines named VM-Prod1, VM-Prod2, and VM-Prod3 to the East US 2 region. The deployment must meet the following requirements:
- Protect the application against localized datacenter outages.
- Provide a SLA for the virtual machines.
- Automatically distribute incoming traffic across the virtual machines.
You need to configure the high availability and load balancing strategy.
Which two actions should you perform? Select two.
Geçerli olan tümünü seçin
You have an Azure General Purpose v2 (GPv2) storage account named logsstore104 in the East US region. The storage account is currently configured to use locally-redundant storage (LRS). You need to configure replication and a blob lifecycle policy to meet the following requirements:
- All data must be replicated to a secondary region and must remain readable even if the primary region experiences an outage.
- Blobs must automatically transition to the Archive storage tier 180 days after they are created.
- Blobs must be deleted automatically 365 days after they are created.
Which two actions should you perform to meet these requirements?
Geçerli olan tümünü seçin
You plan to configure a new dynamic user group in Microsoft Entra ID. The group must automatically include all users who are members of an existing security group named Marketing-All (which has an Object ID of 11111111-2222-3333-4444-555555555555) and also have their department attribute set to Marketing. You write the following dynamic membership rule for the group:
`user.memberof -any (group.objectId -in ['11111111-2222-3333-4444-555555555555']) -and user.department -eq 'Marketing'`
Will Microsoft Entra ID successfully validate and save this dynamic membership rule?
An organization has an Azure standard General Purpose v2 (GPv2) storage account named corpstoreupload in West US 2. The account currently uses Locally-redundant storage (LRS) and contains a blob container named invoices.
You need to meet the following requirements:
1. Provide read-only access to the data in a secondary region without waiting for a failover to be initiated if the primary region becomes unavailable.
2. Automatically move blobs in the invoices container to the Archive tier if they have not been modified for more than 90 days.
3. Automatically delete blobs in the invoices container if they have not been modified for more than 365 days.
Which of the following statements describe correct configurations or behaviors for this scenario? (Select TWO.)
Geçerli olan tümünü seçin
Your company has an Azure environment with a subscription named sub-logistics. The subscription contains a resource group named rg-shipping, which contains a storage account named stshippinglogs. You need to grant a user named User1 the ability to view the configuration of stshippinglogs in the Azure portal and read blob data stored in its containers. The solution must use the principle of least privilege. Which two role assignments should you configure?
Geçerli olan tümünü seçin