Tüm alıştırma soruları
1198 soru
An enterprise is designing a centralized monitoring and log routing architecture for its Azure environment. The architecture must accommodate various auditing, security, and networking logs while satisfying constraints around operational cost, real-time analysis, administrative access control, and long-term retention.
Match each log routing requirement scenario on the left with the most appropriate Azure destination or architectural configuration on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A cloud architecture team is implementing a monitoring strategy for a set of new Azure workloads. The team needs to configure diagnostic settings to satisfy two compliance conditions:
1. Stream resource logs immediately to an external Security Information and Event Management (SIEM) platform.
2. Retain all log data for five years in a secure archive at the lowest possible cost.
Which two Azure destinations should be selected in the diagnostic settings to meet these requirements? (Select TWO)
Geçerli olan tümünü seçin
You are designing a log routing and monitoring strategy for an Azure infrastructure solution. Match each Azure destination to its primary use case.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization wants to restrict the deployment of specific virtual machine sizes in a test resource group. If an administrator attempts to deploy a virtual machine with a size that is not on the allowed list, the deployment must be immediately blocked. Which Azure Policy effect should you recommend to meet this requirement?
You are designing a centralized monitoring and log routing architecture for an enterprise with multiple Azure subscriptions. You need to map each corporate log management requirement to its optimal Azure service architecture. Each configuration must satisfy the constraints while minimizing administrative overhead and cost.
Match each operational requirement on the left to the most appropriate Azure architecture design on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A financial services firm designs an Azure Landing Zone. The Azure hierarchy contains a management group named Production-MG, which contains 15 subscriptions.
You need to design a governance solution for Azure Key Vault instances deployed across all subscriptions in Production-MG. The solution must meet the following requirements:
- Ensure all Key Vaults automatically send audit logs to a central Log Analytics workspace.
- Allow developers to provision Key Vaults immediately, even if they do not define diagnostic settings in their templates.
- Prevent compliance validation and logging for two specific subscriptions within Production-MG that host isolated sandboxes.
- Minimize administrative overhead.
Which of the following policy designs should you recommend?
An organization has two departments, Finance and HR, that run workloads in separate Azure subscriptions. Regulatory compliance requires that HR administrators must not have access to Finance security logs, and Finance administrators must not have access to HR security logs. You need to design an Azure Monitor log routing architecture that enforces this boundary. Which architecture should you recommend?
A multinational enterprise runs application workloads in the East US and Germany West Central regions. The German operations collect diagnostic logs containing metadata subject to strict European Union data sovereignty regulations, which mandate that all telemetry must remain resident within Germany. To manage these environments, the enterprise requires automated configuration of diagnostic logging for new resources, and the German security auditing team must be granted exclusive access to the German log files.
Which design strategy should you recommend to meet these requirements?
A financial services company is establishing its presence in two Azure regions: Germany West Central and North Europe. The compliance department mandates that all logs containing customer financial data from the German region must remain within Germany to satisfy national data residency regulations. Workloads in North Europe have no data residency restrictions, and the company wants to optimize operational efficiency and reduce storage costs. Additionally, the security operations center requires that all newly created Azure Virtual Machines in both regions automatically configure their diagnostic logs to route to the designated Log Analytics workspaces without manual intervention. You need to design a monitoring, log routing, and access governance architecture that meets these requirements while adhering to Azure best practices.
Which architecture should you recommend?
A financial services company is designing the migration of an on-premises database cluster to Azure. The cluster hosts several databases that perform cross-database transactions using Distributed Transaction Coordinator (DTC) and run scheduled data extraction jobs using SQL Server Agent. The database security policy dictates that the data store must not be accessible via the public internet and must reside within a private network. The design must minimize administrative overhead.
Which two components should you include in the recommended design? (Select TWO.)
Geçerli olan tümünü seçin
An organization is designing a log routing and monitoring solution for application workloads deployed across two Azure regions: West US and North Europe. The design must meet the following requirements:
- Logs containing personally identifiable information (PII) from resources in North Europe must remain within the European Union (EU) to comply with data sovereignty regulations.
- Any newly deployed resource must be automatically configured to route its diagnostic logs without manual intervention.
- The monitoring logs must be retained for seven years, minimizing costs for long-term storage.
- Administrative access must follow the principle of least privilege, ensuring European operators can only access European logs, while central administrators can query logs across both regions.
Which two configurations should you include in the monitoring design?
Geçerli olan tümünü seçin
A retail company's cloud architecture includes a parent Management Group named Enterprise-MG that contains three subscriptions: Prod-Sub-01, Prod-Sub-02, and Dev-Sub-01. The governance team establishes the following design requirements:
- All virtual machines deployed in any subscription must use managed disks. Any attempt to deploy a virtual machine with unmanaged disks must be blocked.
- The development resource group Sandbox-RG, located in Dev-Sub-01, must be allowed to deploy virtual machines with unmanaged disks.
- All storage accounts deployed in any subscription must have diagnostic settings configured to send logs to a central Log Analytics workspace. If a storage account is deployed without diagnostic settings, the settings must be created automatically.
You need to design an Azure Policy solution that meets these requirements with the minimum administrative overhead.
Which two policy configurations should you include in the design?
Geçerli olan tümünü seçin
An enterprise uses a multi-tier Azure landing zone structure under a single Root Management Group (RMG). One of the child management groups is named Legacy-Workloads. The security compliance team requires that all Azure Storage accounts enforce double encryption (infrastructure encryption).
You must design a policy governance strategy to meet the following requirements:
* All new and updated storage accounts must have infrastructure encryption enabled. If not, the deployment must be prevented.
* Existing storage accounts that do not have infrastructure encryption enabled must be flagged as non-compliant for reporting, but their current configurations must remain unaltered, and no automatic remediation tasks should be executed.
* For subscriptions tagged with environment: sandbox, the infrastructure encryption requirement must be recommended but not enforced, ensuring that deployments can succeed even if non-compliant, while their compliance status continues to be monitored and reported.
* The policy must not apply to any resources within the Legacy-Workloads management group.
* The strategy must minimize administrative overhead by using the fewest policy definitions.
Which policy design strategy should you recommend?
An enterprise company has an Azure environment with a management group structure consisting of a root management group named Contoso-MG and a child management group named Workloads-MG. You are designing an Azure Policy strategy to satisfy the following compliance requirements:
1. All Azure Key Vaults deployed in any subscription under Contoso-MG must have diagnostic settings automatically enabled to route all audit logs to a central Log Analytics workspace.
2. All Azure Storage accounts deployed in any subscription under Workloads-MG must have public network access blocked. Any attempt by administrators to deploy a storage account with public network access enabled must be prevented.
3. The public network access restriction for storage accounts must not apply to a specific resource group named dev-public-rg in the App-Sub-01 subscription under Workloads-MG.
You need to design the governance solution to meet these requirements with the least administrative effort.
Which two Azure Policy configurations should you include in your design? (Select TWO.)
Geçerli olan tümünü seçin
Your company is designing a governance strategy for Azure resources. You need to implement Azure Policies that satisfy the following requirements:
- Prevent the deployment of virtual machines that do not use approved VM sizes.
- Automatically add a default department tag to resource groups when they are created without one.
Which two Azure Policy effects should you select to meet these requirements?
Geçerli olan tümünü seçin
Your company is designing a monitoring solution for resources deployed in Azure. You need to ensure that all newly created Azure Key Vaults automatically have diagnostic settings enabled to route logs to a centralized Log Analytics workspace. If a Key Vault is deployed without diagnostic settings, the settings must be created automatically without preventing the deployment of the Key Vault itself. Which Azure Policy effect should you select to meet these requirements?
An enterprise is designing a monitoring and log routing architecture for a healthcare application deployed across two Azure regions: UK South and Switzerland North. The application generates regional database diagnostic logs containing patient health information, and virtual machine performance metrics. The architecture must meet the following requirements:
- All database diagnostic logs must remain strictly within their region of origin due to regional data residency compliance regulations.
- Virtual machine performance metrics must be aggregated centrally in a single workspace in North Europe to facilitate global performance dashboards.
- Diagnostic settings must be automatically applied to any new database or virtual machine resource deployed in these regions.
Which two configurations should you include in the monitoring design? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise is designing a centralized monitoring and log routing architecture for its Azure environment. The architecture must accommodate several workloads with distinct security, compliance, and retention constraints. Match each operational log routing requirement on the left with its most appropriate Azure routing and destination configuration on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization has multiple application workloads deployed across separate resource groups in a single Azure region. Each workload is managed by a different support team. You are designing a monitoring and log routing architecture that must satisfy the following requirements:
* All resource diagnostic logs must be collected and stored for centralized compliance analysis.
* If a new or existing resource is deployed without diagnostic settings, they must be automatically configured to route logs to the destination.
* Support teams must only be allowed to view the diagnostic logs of the resources within their respective resource groups.
* The administrative overhead for managing log access and workspace configurations must be minimized.
Which design solution should you recommend?
An organization manages its cloud resources using an Azure Management Group hierarchy. A management group named CoreServices-MG contains subscriptions used for shared network infrastructure. The security team mandates that all virtual networks deployed within CoreServices-MG must have diagnostic settings configured to send traffic metrics to a central Log Analytics workspace. The deployment of virtual networks must proceed without interruption even if the diagnostic settings are not defined during creation, but the diagnostic settings must be automatically configured immediately after deployment. Which Azure Policy effect should you specify in the policy definition to meet these requirements?