Tüm alıştırma soruları
1198 soru
An enterprise is migrating a legacy, stateful transaction processing application to Azure. The application has the following requirements:
- It requires physical isolation at the hardware host level to meet compliance and licensing standards.
- The steady-state workload requires 32 vCPUs and 256 GiB of RAM, running continuously 24/7.
- The virtual machines must have a guaranteed 99.95% availability SLA.
- The database log drive requires 20,000 IOPS and sub-millisecond latency.
- The application cannot be containerized due to kernel-level licensing checks.
Which of the following compute and storage designs should you recommend to meet the requirements while minimizing costs?
A multi-region retail enterprise is establishing a new environment in Azure for its inventory forecasting service. The service is hosted within a dedicated subscription. The operations team consists of 15 system administrators who require contributor permissions at the subscription scope to troubleshoot infrastructure issues. The company's security policy mandates that administrators must not hold permanent high-privilege access, and all access assignments must minimize administrative overhead while ensuring full auditability of elevated permissions.
Which approach should you recommend to meet these requirements?
You are an Azure Solutions Architect designing a data storage solution for a global media streaming platform. The platform must store real-time user playback progress and watch history. The workload has a read-to-write ratio of approximately . The solution must be distributed across three regions (East US, West Europe, and East Asia) to achieve sub-10ms write latency at the 99th percentile and support an active-active setup. The platform requires a 99.999% availability SLA for both reads and writes. High availability and regional disaster resilience must be guaranteed for all data, including database backups.
Which two configuration options should you include in the architectural design to meet these requirements? (Select TWO)
Geçerli olan tümünü seçin
An enterprise is designing a hub-and-spoke virtual network topology in Azure to secure traffic between application tiers.
The hub virtual network, `vnet-useast-hub` (), hosts an Azure Firewall with the private IP address .
The app spoke virtual network, `vnet-useast-app` (), contains two subnets:
* `web-subnet` ()
* `api-subnet` ()
The database spoke virtual network, `vnet-useast-db` (), contains one subnet:
* `db-subnet` ()
Both spoke virtual networks are peered with `vnet-useast-hub`. No direct peering exists between the spokes.
You need to design a routing solution that meets the following requirements:
1. All outbound traffic from `web-subnet` to `db-subnet` must be routed through the Azure Firewall in the hub.
2. All return traffic from `db-subnet` to `web-subnet` must also traverse the Azure Firewall.
3. Traffic between `web-subnet` and `api-subnet` within the app spoke must remain local and route directly without traversing the firewall.
Which of the following configurations should you implement to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A financial technology enterprise is designing a global, multi-region traffic routing and failover solution for its payment processing platform deployed in the East US 2 and West Europe regions. The solution must accommodate the following incoming traffic streams:
* Stream 1: HTTPS-based web API traffic requiring SSL termination at the network edge, path-based routing (routing `/charge` and `/refund` requests to different backend pools), and integrated Web Application Firewall (WAF) protection.
* Stream 2: A proprietary, latency-sensitive TCP-based client application communicating over port . This stream does not support HTTP encapsulation and must be routed to the closest healthy regional endpoint.
Which traffic routing configuration should you recommend to meet these requirements?
An organization is designing a disaster recovery (DR) solution from the East US region to the West US region for an inventory management system. The system consists of two Web tier VMs (each with a Premium SSD and a write churn of ), two App tier VMs (each with a Premium SSD and a write churn of ), and one Database tier VM running SQL Server on an Azure VM. The Database VM has one OS disk with a write churn of , one data disk with a write churn of , and one transaction log disk with a write churn of . All disks on the Database VM are Premium SSDs. The organization requires a target recovery point objective (RPO) of and a recovery time objective (RTO) of . Which disaster recovery design should you recommend?
A conglomerate has an on-premises Active Directory Domain Services (AD DS) forest and three Microsoft Entra ID tenants. You are designing a hybrid and multi-tenant identity solution that must satisfy constraints regarding hybrid synchronization footprints, external collaboration types, self-service governance, and multi-tenant synchronization. Match each business and technical requirement to the most appropriate Microsoft Entra ID technology.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization needs to collect Azure diagnostic logs for resources deployed across two distinct regulatory jurisdictions (Europe and the US). The requirements are:
1. Europe diagnostic logs must remain resident in Europe.
2. US diagnostic logs must remain resident in the US.
3. Access to the logs must be granted to the security team using the most scalable and maintainable administrative model.
Which two configurations should you include in the monitoring and governance design?
Geçerli olan tümünü seçin
You are designing a monitoring and log routing solution for an enterprise Azure environment. Match each log ingestion or routing requirement to its most appropriate Azure Monitor destination or configuration component.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Your company wants to enforce tagging standards for Azure storage accounts. You need to design an Azure Policy strategy that meets the following compliance requirements:
* If a storage account is deployed without the 'Environment' tag, the deployment must be blocked.
* If a storage account is deployed without the 'CostCenter' tag, the policy should automatically add the tag with a default value of 'Unassigned' during creation.
Which two Azure Policy effects should you recommend to meet these compliance requirements?
Geçerli olan tümünü seçin
FinSecure Corp has multiple subscriptions organized under a single Azure tenant. The compliance team mandates that all Azure Key Vaults must have diagnostic settings configured to route audit logs to a central Log Analytics workspace. Developer teams frequently deploy new Key Vaults using infrastructure as code (IaC) templates that often omit the diagnostic settings. The proposed governance solution must ensure that diagnostic settings are configured automatically upon vault creation, must not block developer deployments, and must minimize administrative overhead. Which of the following governance strategies should you recommend?
An organization is designing a monitoring and log routing architecture for application workloads deployed across two Azure regions: East US and North Europe. The solution must meet the following requirements:
- Regulatory compliance mandates that operational logs generated in North Europe must reside within the North Europe region and must not be accessible from the East US region.
- Resource owners must only be able to query logs for the specific Azure resources they own, without having access to other operational logs in the same workspace.
- Diagnostic settings for all newly created virtual machines must be configured automatically to route logs to the appropriate regional workspace.
Which two configurations should you include in the design to meet the requirements?
Geçerli olan tümünü seçin
VoltGrid Power operates a multi-region grid telemetry network in Azure. The resource hierarchy consists of a root management group named VoltGrid-Root, which contains two child management groups: VoltGrid-Americas and VoltGrid-Eurasia. Under VoltGrid-Americas, you have two subscriptions: Telemetry-Prod-Sub and Grid-Dev-Sub.
You need to design a governance strategy to enforce the following compliance requirements:
1. All Azure Virtual Machines deployed to Telemetry-Prod-Sub must have the Azure Monitor Agent (AMA) installed automatically upon deployment.
2. All Azure SQL Databases deployed within the VoltGrid-Americas management group must be blocked from creation if transparent data encryption (TDE) is not configured to use a customer-managed key (CMK).
3. The SQL Database TDE restriction must not apply to resources in a development resource group named Sandbox-RG located inside Grid-Dev-Sub.
The solution must minimize administrative overhead and avoid manual remediation processes.
Which two configurations should you include in your Azure Policy design?
Geçerli olan tümünü seçin
Zephyr Health designs its Azure environment using a management group hierarchy. Under the root management group, a production management group named Zephyr-Prod contains multiple subscriptions, including Prod-App1. A security requirement states that all Azure Virtual Machines deployed to subscriptions under Zephyr-Prod must be automatically configured to back up to a Recovery Services vault. If a virtual machine is deployed without backup, it must be automatically remediated by deploying the required backup extension. However, virtual machines deployed in a specific resource group named In-Memory-DB-RG within Prod-App1 must be exempted from this backup requirement due to performance and latency constraints. Which Azure Policy strategy should you recommend to meet these compliance requirements while minimizing administrative overhead?
An enterprise manages its Azure resources using a Management Group hierarchy consisting of a Root Management Group, under which sit a Production Management Group (containing production subscriptions) and a Non-Production Management Group (containing Dev and Test subscriptions).
You need to design a governance strategy using Azure Policy to meet the following requirements:
1. All virtual networks deployed within the Production Management Group must have Azure Network Watcher flow logs enabled and configured to send data to a central Log Analytics workspace. Non-compliant virtual networks must be automatically remediated during deployment without blocking the resource creation.
2. Virtual machines of the G-series must be blocked from deployment within the Test subscription to control costs. However, developers must be allowed to deploy these virtual machines within a specific resource group named PerfTesting-RG inside the Test subscription.
3. Administrative overhead for managing policy assignments and compliance must be minimized.
Which policy design should you recommend?
An enterprise operates a web application deployed in both the East US and North Europe regions. European Union (EU) data sovereignty regulations mandate that all monitoring logs containing EU user activity must remain physically within Europe and be accessible only by European administrators. US operations logs have no such restrictions. You need to design an Azure Monitor log routing solution that complies with these regulations while adhering to Microsoft security and administrative best practices. Which design should you recommend?
Contoso Pharmaceuticals has an on-premises Active Directory Domain Services (AD DS) environment and multiple Microsoft Entra ID tenants. The company needs to design a hybrid and multi-tenant identity solution to satisfy various connectivity, security, and partnership requirements. Match each operational requirement to the most appropriate Microsoft Entra ID synchronization or collaboration feature.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Your organization is designing a security strategy for a Microsoft Entra ID tenant. You plan to deploy a Conditional Access policy that requires Multi-Factor Authentication (MFA) for all users assigned directory role administrator privileges. To prevent administrative lockout during a service outage or configuration error, which design decision should you implement?
Aetherius Logistics has an on-premises Active Directory Domain Services (AD DS) domain. The company is designing a hybrid identity solution using a single Microsoft Entra ID tenant. The solution must meet the following requirements:
- Users must be able to sign in to cloud resources using their on-premises credentials.
- If the network connection between the on-premises datacenter and Azure is temporarily lost, users must still be able to authenticate to cloud resources.
- Users must be able to reset their passwords using Microsoft Entra Self-Service Password Reset (SSPR), and the changes must immediately update on-premises AD DS.
- On-premises infrastructure footprint and management overhead must be minimized.
Which hybrid identity synchronization and authentication solution should you recommend?
An enterprise has Azure resources deployed in the East US and West Europe regions. To meet regulatory requirements, resource diagnostic logs from West Europe must remain within the European Union (EU) borders, while logs from East US must reside within the United States. Regional administrators must be able to query logs for their respective regions only, while a global security audit team requires access to all logs across both regions. You need to design the Azure Monitor log architecture to support this configuration with minimum administrative overhead. Which two configurations should you include in the design?
Geçerli olan tümünü seçin