Soru

Zorluk: OrtaAzure Arc

A global financial services firm operates a legacy banking application on physical Windows servers in their private data center, along with several containerized microservices hosted on Google Cloud Platform (GCP). The IT department wants to apply consistent corporate compliance rules and security monitoring to these non-Azure workloads using Azure Policy and Microsoft Defender, without migrating any resources to Azure. Which of the following Azure services should they use to achieve this goal?

  1. A
    Azure Stack Hub
  2. Azure ArcCevap
  3. C
    Azure Policy without any additional services
  4. D
    Azure Role-Based Access Control (RBAC)

Cevap

Azure Arc
Azure Arc is designed to extend Azure management and services to any infrastructure, including virtual machines, physical servers, and Kubernetes clusters running on-premises or in other clouds (such as GCP). By registering these resources with Azure Arc, they appear as resource objects inside Azure, allowing the IT department to apply Azure Policy and Microsoft Defender just as they would with native Azure resources.

Adım Adım Çözüm

1
Identify the organization's requirements
The firm needs to govern and monitor existing workloads (physical Windows servers on-premises and containerized microservices on Google Cloud Platform) using Azure Policy and Microsoft Defender without migrating them.
Understanding the operational constraints helps determine which Azure services can bridge the management plane across diverse environments.
2
Evaluate the capabilities of the proposed services
Azure Arc projects non-Azure resources into Azure Resource Manager (ARM). Once registered, these resources can be organized, monitored, and governed using Azure-native tools such as Azure Policy and Microsoft Defender.
This matches the requirement to extend Azure management to multi-cloud and on-premises environments without migrating the workloads.

Anahtar Kavram

Azure Arc extends the Azure Resource Manager control plane, enabling the management, governance, and security of resources running on-premises, at the edge, or in multi-cloud environments.
Bu soruyu puanla

Konular