Tüm alıştırma soruları
1252 soru
Apex Retail plans to deploy two new virtual machines named VM-App1 and VM-App2 in the Germany West Central region. The deployment must protect the application from datacenter-wide outages by utilizing Availability Zones. Which of the following actions should you perform to meet this requirement? Select two.
Geçerli olan tümünü seçin
An organization's Microsoft Entra ID tenant contains an administrative unit named Branch-AU. A user named Admin1 is assigned the Groups Administrator role, with the scope of the assignment restricted to Branch-AU. Within Branch-AU, there is a security group named Branch-Support that currently has a membership type of Assigned. Admin1 attempts to convert Branch-Support to a dynamic group and configure a dynamic membership rule based on user attributes. However, Admin1 is unable to change the group's membership type. You need to identify the cause of this issue. What is the cause of the issue?
You plan to configure a budget named `Budget1` for an Azure subscription. You want to ensure that when actual spending reaches of the budget, email notifications are sent to the billing team. Which of the following settings must you configure when defining the budget alert? (Select TWO.)
Geçerli olan tümünü seçin
Apex Global Logistics configures the following Azure Management Group (MG) hierarchy:
* Tenant Root Group
* Logistics-MG
* Operations-MG
* Subscription-Ops1
* Archive-MG
* Subscription-Arch1
The following assignments and configurations are in place:
* An Azure Policy assignment that restricts resource deployment regions is applied to Logistics-MG.
* A user named User1 is assigned the Contributor role at the Operations-MG level.
* A Resource Lock of type CanNotDelete is applied directly to Subscription-Ops1.
You move Subscription-Ops1 from Operations-MG to Archive-MG.
Which of the following describes the impact of this move on User1's permissions and the policy and lock configurations of Subscription-Ops1?
Veloce Systems needs to deploy a two-tier application in the Germany West Central region. The web tier consists of two virtual machines named VM-Web1 and VM-Web2. To meet a uptime SLA, you plan to deploy the virtual machines in an Availability Set named AvSet-Web.
Which two configuration requirements must be met to deploy this high-availability solution? (Select two.)
Geçerli olan tümünü seçin
You manage an Azure Storage account named `sa-finance-prod` that stores sensitive financial documents. You are configuring network security for `sa-finance-prod` to meet the following requirements:
- Only virtual machines in a subnet named `Subnet-Web` within a virtual network named `VNet-Prod` must be allowed to access the storage account over the Azure network backbone.
- System administrators working from an on-premises office must be able to access the storage account. The office uses the public IP address range .
- Azure Backup must be able to back up the files in `sa-finance-prod` successfully.
- All other public internet access to the storage account must be blocked.
Which of the following configurations should you implement?
You manage a Microsoft Entra ID tenant. You have an existing security group named Group1. During the creation of Group1, the option 'Microsoft Entra roles can be assigned to the group' was set to Yes. You now need to configure Group1 to automatically add users who have their department attribute set to 'Engineering'. What should you do?
Your company wants to delegate user administration tasks, such as resetting passwords, for users in the marketing department only. The delegated administrator must not have administrative privileges over users in other departments.
Which two of the following actions should you perform? (Select TWO.)
Geçerli olan tümünü seçin
You have an on-premises Windows Server named Server1 and an Azure file share named share1 in a storage account named storage1. You plan to deploy Azure File Sync. All synchronization traffic must travel over a private network connection, and public network access to both storage1 and the Storage Sync Service must be disabled. Which sequence of steps should you perform to configure Azure File Sync under these security constraints? Arrange the steps in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
Your organization has a Microsoft Entra ID tenant and the following Azure resource hierarchy:
* Management Group: `MG-Finance`
* Subscription: `Sub-Finance-Prod`
* Resource Group: `RG-Finance-Sec`
* Storage Account: `safinancedata`
A user named Admin1 is assigned the Microsoft Entra ID Global Administrator role.
A user named User2 is assigned the Reader role at the `Sub-Finance-Prod` subscription level.
You need to configure the environment to meet the following requirements:
1. Admin1 must be able to assign the Reader role to new users at the `RG-Finance-Sec` resource group level.
2. User2 must be able to read and write blob data in a container within the `safinancedata` storage account, but must not have control plane write permissions to any resource in the subscription.
Which of the following actions should you perform to meet these requirements?
Vanguard Retail plans to deploy a new critical business application in the Germany West Central region. The application will run on two virtual machines named vm-sales-prod1 and vm-sales-prod2. The deployment must satisfy the following requirements:
- Provide a virtual machine uptime SLA of 99.99%.
- Protect the application against datacenter-level outages within the region.
- Distribute incoming network traffic across both virtual machines.
Which of the following configuration options should you implement to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
You need to restrict network access to an Azure Storage account named `store77` so that it is only accessible from a subnet named `Subnet1` within a virtual network named `VNet1` using the Azure backbone network. Which two configurations should you implement?
Geçerli olan tümünü seçin
Your company has branch offices in Seattle and London. You need to configure Azure File Sync to synchronize files from an on-premises Windows Server named Server1 to an Azure file share. You have already created a Storage Sync Service resource in Azure. What must you do next on Server1 to prepare it for file synchronization?
An administrator configures the following resource hierarchy and role assignments in an Azure environment:
* Microsoft Entra Tenant: The Access management for Azure resources property is set to No.
* Management Group: `MG-CoreServices`
* Subscription: `Sub-SharedServices`
* Resource Group: `rg-networking` (contains a Virtual Network named `vnet-prod`)
* Resource Group: `rg-identity`
A user named User1 is assigned the following roles:
* Global Administrator in the Microsoft Entra tenant
* Reader at the `MG-CoreServices` management group scope
* Network Contributor at the `rg-networking` resource group scope
You need to identify the effective permissions of User1.
Which of the following statements are correct? (Select TWO.)
Geçerli olan tümünü seçin
You manage an Azure subscription. You need to ensure that detailed cost and usage data is automatically saved to an Azure Storage account every day for external analysis. What should you configure in Azure Cost Management?
An enterprise manages its Azure resource hierarchy with a Management Group named Production-MG, which contains a subscription named Prod-Sub-01. Prod-Sub-01 contains two resource groups named RG-Core-App and RG-Core-Data.
The following Azure Policy assignments are active:
- An initiative definition named Corp-Governance-Initiative is assigned at Production-MG. The assignment contains an exclusion for the resource group RG-Core-App. The initiative contains two policy definitions: Policy-Tag (denies resource creation if the Environment tag is missing) and Policy-SKU-A (denies VM deployment unless the size is Standard_D2s_v5 or Standard_D8s_v5).
- A policy definition named Policy-SKU-B is assigned directly to Prod-Sub-01. This policy denies VM deployment unless the size is Standard_D2s_v5 or Standard_D4s_v5.
- A policy definition named Policy-SKU-C is assigned directly to RG-Core-App. This policy denies VM deployment unless the size is Standard_D4s_v5.
Which of the following deployments will successfully complete?
Your company has a Microsoft Entra ID tenant containing an Azure subscription named Sub1. The tenant includes a support team named London-Support and an Administrative Unit named London-AU that contains users from the London office.
You need to meet the following requirements:
1. Members of the London-Support group must be able to update the department and profile information of only the users within London-AU.
2. Members of London-Support must have no administrative permissions over other users in the tenant or resources in Sub1.
3. You must automatically assign Microsoft 365 Enterprise licenses to all users who belong to London-AU.
Which two actions should you perform? (Select two.)
Geçerli olan tümünü seçin
An administrator needs to configure temporary access for an external application to upload and read blobs in a container named incoming in an Azure Storage account named corpstore2026. The configuration must meet the following security and access requirements:
- The external application must only be allowed to read and write blobs in the incoming container.
- The external application's access must be restricted to the IP range .
- The access token must remain valid for a maximum of hours.
- Access must not be interrupted when the storage account access keys ( and ) are rotated.
- The administrator must adhere to the principle of least privilege for their own administrative account when generating the SAS.
Which two actions should the administrator perform? (Select two.)
Geçerli olan tümünü seçin
You are configuring permissions in a Microsoft Entra ID tenant. You plan to assign the Helpdesk Administrator role to a user named AdminA. You must ensure that AdminA can only perform helpdesk operations, such as password resets, for users located in the Munich branch office. Which Microsoft Entra ID resource or configuration should you implement to restrict the scope of this role?
ZeniSphere Logistics is planning to deploy two new virtual machines, VM-Ship1 and VM-Ship2, in the East US region. The deployment must protect the application from localized hardware failures on a single physical host, such as disk or power supply failures, by ensuring the VMs are placed on different physical hardware racks within the same datacenter. Which Azure feature should you configure for the virtual machines?