Tüm alıştırma soruları
1252 soru
You manage a Premium storage account named saeastprod01 that hosts an SMB file share named sharesmbprod. The storage account has its firewall enabled, restricting access to selected networks. You need to configure Azure Backup using a Recovery Services vault named rsv-eastus-prod to back up the SMB file share.
Arrange the steps in the correct sequence to configure and run the first backup.
Öğeleri doğru sıraya koymak için sürükleyin
Your company has a public website hosted externally with the domain name `www.contoso.com` and its DNS records managed in a public Azure DNS zone. You plan to configure split-horizon DNS by deploying an Azure Private DNS zone named `contoso.com` to resolve internal hostnames for virtual machines in a virtual network named `VNet1`. You must ensure that virtual machines in `VNet1` can resolve `www.contoso.com` without service interruption, and that new virtual machines deployed to `VNet1` automatically register their hostnames in the private DNS zone. In which sequence should you perform the configuration steps?
Öğeleri doğru sıraya koymak için sürükleyin
You have an Azure Bastion host named `bastion-corp-east` that is used to manage virtual machines. You must configure diagnostic logging for the Bastion host to meet the following requirements:
* Capture audit logs for all user remote sessions.
* Retain the session logs for 180 days.
* Ensure the logs can be queried directly using the Kusto Query Language (KQL).
Which diagnostic setting configuration should you implement?
Your company has an Azure subscription named Sub-Ops-01 that contains the resources shown in the following table:
| Resource Group | Resource Name | Resource Type | Region |
|---|---|---|---|
| RG-Core-Resources | VM-HR-01 | Virtual Machine | East US |
| RG-Core-Resources | VM-Finance-01 | Virtual Machine | West US 3 |
| RG-Core-Resources | sahrdepot | Storage Account (Azure Files) | East US |
| RG-Backup-Resources | RSV-East | Recovery Services Vault | East US |
| RG-Backup-Resources | BV-East | Backup Vault | East US |
You need to configure backup solutions for the resources using the existing vaults.
Which two configurations can you successfully implement? (Select two.)
Geçerli olan tümünü seçin
An organization deploys a hub-and-spoke network topology in Azure containing three virtual networks:
* `VNet-Hub` () containing a subnet with `VM-Hub` deployed.
* `VNet-SpokeA` () containing a subnet with `VM-SpokeA` deployed.
* `VNet-SpokeB` () containing a subnet with `VM-SpokeB` deployed.
Virtual network peering is configured between `VNet-Hub` and `VNet-SpokeA`, and between `VNet-Hub` and `VNet-SpokeB`. The settings 'Allow forwarded traffic', 'Use remote gateways', and 'Allow gateway transit' are currently left at their default values of disabled.
An administrator reports that `VM-SpokeA` cannot communicate with `VM-SpokeB` over the peered networks.
Which of the following actions should the administrator take to establish direct network connectivity between `VM-SpokeA` and `VM-SpokeB` with the minimum administrative effort?
You manage a Premium storage account named stcorpfiles01 in the East US 2 region. The storage account hosts an SMB file share named sharesmbcore and has its firewall configured to restrict access to selected virtual networks. You configure a Recovery Services vault named rsv-corp-backup in the same region to back up the file share. When you attempt to configure the backup, the operation fails because the vault cannot access the storage account. Which configuration is required on the storage account to resolve this issue?
An administrator is configuring connectivity for an Azure environment containing the following resources:
* `VNet-Hub` () with a virtual network gateway and virtual machines deployed in its subnets.
* `VNet-SpokeA` () with virtual machines deployed in its subnets.
You configure virtual network peering between `VNet-Hub` and `VNet-SpokeA`. Virtual machines in `VNet-SpokeA` must be able to use the virtual network gateway in `VNet-Hub` to communicate with an on-premises network.
Which of the following configuration settings must be enabled on the peerings to achieve this goal? (Select two.)
Geçerli olan tümünü seçin
You are setting up Azure Backup Reports to analyze the historical backup compliance of several workloads protected by multiple Recovery Services vaults. You need to ensure that the backup report data is populated and accessible for reporting via the Azure portal. Which of the following configuration actions should you perform? (Select two)
Geçerli olan tümünü seçin
An administrator is configuring backups for the resources in an Azure subscription named Sub-CloudAdmin-Prod. The subscription contains the resources shown in the following table:
| Resource Name | Resource Type | Region |
|---|---|---|
| vm-billing-ne | Virtual machine | North Europe |
| vm-shipping-we | Virtual machine | West Europe |
| rsv-billing-ne | Recovery Services vault | North Europe |
| bv-shipping-we | Backup vault | West Europe |
| sa-shipping-data | Storage account (contains share-shipping) | West Europe |
The administrator needs to configure backups for vm-shipping-we and the Azure file share named share-shipping.
Which backup configuration should the administrator use?
Your company is setting up a secure hybrid cloud environment in Azure. You have deployed a virtual network named `Prod-VNet-01` in the East US 2 region. The virtual network contains multiple virtual machines that host a line-of-business application.
You need to deploy Azure Bastion to enable secure administrative access to the virtual machines. You must ensure that the subnet used by Azure Bastion is secured with a Network Security Group (NSG) before the Bastion host starts receiving traffic.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Öğeleri doğru sıraya koymak için sürükleyin
You have an Azure Application Gateway named `appgw-prod` that has Web Application Firewall (WAF) enabled.
You need to collect the WAF firewall logs to meet the following requirements:
- Run interactive KQL queries on the logs inside the Azure portal.
- Stream the logs to an external, third-party Security Information and Event Management (SIEM) system in real-time.
Which diagnostic settings configuration should you implement for `appgw-prod`?
An administrator configures three Azure virtual networks named `VNet1` (), `VNet2` (), and `VNet3` (). Virtual machines are deployed in the subnets of each virtual network to run active workloads. Peering is configured between `VNet1` and `VNet2`, and between `VNet2` and `VNet3`. The peering links have 'Allow forwarded traffic' enabled on both sides, but 'Allow gateway transit' and 'Use remote gateways' are disabled. No user-defined routes (UDRs) or virtual network gateways exist in any of the networks. Which of the following describes the network connectivity between the virtual machines?
An organization is designing a disaster recovery virtual network named `DR-VNet` with an address space of . To allow administrators to securely connect to recovery virtual machines, the organization plans to deploy an Azure Bastion host. The administrator needs to create the dedicated subnet for Azure Bastion.
Which configuration must the administrator use for the new subnet?
An administrator is designing a monitoring strategy for several Azure resources. You need to route diagnostic logs to the appropriate destination based on the monitoring requirements.
Match each monitoring requirement to the correct Azure Monitor diagnostic setting destination.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Your company has an Azure environment that contains the resources shown in the following table:
| Resource Name | Resource Type | Azure Region | Resource Group | Subscription |
|---|---|---|---|---|
| VM-Billing-01 | Virtual machine | East US | RG-Finance-Prod | Sub-FinOps-Prod |
| VM-Tax-02 | Virtual machine | West US | RG-Finance-Prod | Sub-FinOps-Prod |
| Share-Ledger | Azure File Share | East US | RG-Finance-Prod | Sub-FinOps-Prod |
| Disk-Archive | Managed disk | West US | RG-Finance-Prod | Sub-FinOps-Prod |
You also have the following vaults:
- A Recovery Services Vault named RSV-Finance-East located in the East US region.
- A Backup Vault named BV-Finance-West located in the West US region.
You need to configure backups for the resources using the existing vaults with the correct vault type and regional requirements.
Which two actions can you perform? (Select two options)
Geçerli olan tümünü seçin
An organization has multiple Recovery Services vaults in different regions. To enable centralized backup reporting, an administrator configures diagnostic settings on each vault to send data to a central Log Analytics workspace. When viewing the Backup Reports in the Azure Portal, the administrator notices that while the backup jobs, policies, and active alerts are fully populated, the reports contain no data regarding backup storage consumption or monthly storage trends. Which log category must the administrator add to the diagnostic settings of the Recovery Services vaults to resolve this issue?
An administrator is creating a custom Log Analytics query to report on failed backup jobs and identify the specific Azure virtual machines associated with those failures. The diagnostic settings on the Recovery Services Vaults are configured to use the resource-specific destination tables. Which two tables must the administrator query and join to retrieve this information? Select two.
Geçerli olan tümünü seçin
An administrator is preparing to deploy Azure Bastion to secure administrative access to virtual machines in a virtual network named `TransitHub-VNet`. The virtual network has an address space of .
Which of the following configuration settings must be applied to ensure a successful deployment and operation of the Azure Bastion host? (Select TWO)
Geçerli olan tümünü seçin
Your company plans to implement secure, browser-based administrative access to Azure virtual machines in a virtual network named `VNet-Corp-01`. The virtual network is configured with an address space of . You need to create a dedicated subnet for the Azure Bastion resource. What is the correct subnet name and the minimum subnet mask required for this deployment?
You have an Azure Key Vault named `kv-finance`.
You need to configure diagnostic logging for `kv-finance` to satisfy the following requirements:
- All key vault access logs (`AuditEvent`) must be queryable using KQL.
- The logs must be archived for 365 days to meet compliance regulations.
- Storage costs for the archived logs must be minimized.
Which configuration should you implement?