Tüm alıştırma soruları
1198 soru
You are designing a governance strategy for an Azure environment. You need to implement an Azure Policy that enforces secure transport settings on Azure Cache for Redis instances. The policy must meet the following compliance requirements:
- Ensure that the minimum TLS version for all Redis instances is set to 1.2.
- If a new instance is deployed with an older version, or without specifying the version, the deployment must succeed, but the configuration must be automatically updated to enforce TLS 1.2.
- Existing non-compliant resources must be flagged in compliance reports but not modified automatically.
Which Azure Policy effect should you include in the policy definition to meet these requirements?
A healthcare provider, MedVitals Systems, operates a hierarchical Azure resource structure. The Root Management Group contains a child Management Group named Shared-Services. A subscription named Archive-Billing is placed within the Shared-Services Management Group. You need to design an Azure governance architecture to meet the following requirements:
- Ensure that any newly deployed virtual machines (VMs) automatically have the dependency agent installed.
- Ensure that the Archive-Billing subscription is not subject to the VM agent requirement to prevent unnecessary agent installations on archived workloads.
- Ensure that all storage accounts enforce secure transfer (HTTPS). Existing non-compliant storage accounts must be flagged in compliance reports but must not be modified or blocked.
- Minimize administrative overhead.
Which design should you recommend?
Solas Renewable Solutions is designing a hybrid and multi-tenant identity solution to support its growing infrastructure. The company has an on-premises Active Directory Domain Services (AD DS) forest and has recently acquired a subsidiary with its own Microsoft Entra ID tenant.
Solas has the following identity and access management requirements:
- Ensure that users from the corporate office can sign in to Microsoft Entra ID services even if the on-premises datacenter goes offline.
- Enable automatic account lifecycle management and Global Address List (GAL) visibility for users from the acquired subsidiary's tenant.
- Allow external suppliers to securely access internal resources using their existing corporate credentials.
- Ensure that certain security-sensitive on-premises users have their login credentials validated in real-time against on-premises domain controllers, without storing password hashes in the cloud.
You need to recommend the appropriate identity technology for each requirement.
Match the identity requirements on the left with the correct Microsoft Entra feature or configuration on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Zenith Retail Systems is designing a governance strategy for its Azure subscriptions. The security team requires that all virtual machines deployed to a resource group named 'PCI-DSS-Production' are automatically registered with Azure Backup. If a virtual machine is created without a backup configuration, the system must automatically configure the backup protection and deploy the required recovery services resources without preventing the virtual machine from being created. Which Azure Policy effect should you recommend to meet this requirement?
A financial services firm, FinSecure Corp, is designing an Azure governance framework for its production subscriptions. The security team establishes two compliance mandates:
1. Prevent the deployment of any virtual machines that have public IP addresses directly associated with their network interfaces.
2. Ensure that all newly deployed virtual networks are automatically configured with diagnostic settings that send all network metrics to a central Log Analytics workspace.
You need to recommend the appropriate Azure Policy effects to satisfy these mandates with the least administrative effort.
Which two policy effects should you recommend?
Geçerli olan tümünü seçin
An organization has multiple application teams deploying resources to separate resource groups within a single Azure subscription. You are designing a monitoring and log routing solution. The solution must meet the following requirements:
- Minimize administrative overhead by using the fewest Log Analytics workspaces possible.
- Allow developers to query diagnostic logs only for the specific resources they own.
- Prevent developers from viewing logs of resources owned by other teams.
Which of the following designs should you recommend?
Zephyr Energy Services has an on-premises Active Directory Domain Services (AD DS) domain. The company is designing a hybrid identity solution to integrate AD DS with a Microsoft Entra ID tenant. The solution must meet the following requirements:
- Users must be able to authenticate to cloud services using their on-premises credentials.
- User password hashes must not be synchronized or stored in the cloud under any circumstances due to regulatory compliance policies.
- Authentication requests must be validated directly against on-premises Active Directory domain controllers.
- The deployment must avoid the infrastructure overhead and complexity of Active Directory Federation Services (AD FS).
Which authentication sync method should you include in the design to meet these requirements?
A retail company operates a multi-tier e-commerce platform deployed in the East US 2 and UK South regions. The company's compliance policy dictates that all auditing and diagnostic data generated in UK South must remain within the UK geographic boundary. Regional administrators in each region must only be able to view logs for resources within their administrative scope. The security team must be able to run queries across logs from both regions. Which of the following log routing and workspace architectures should you recommend?
An enterprise is scaling its Azure footprint and needs to grant a newly formed team of developers permission to restart virtual machines in a development resource group. To ensure scalable management and adhere to the principle of least privilege, how should you assign the required permissions?
Vanguard Retailers has an on-premises Active Directory Domain Services (AD DS) domain. You are designing a hybrid identity solution to sync user accounts to a single Microsoft Entra ID tenant. The solution must meet the following requirements:
- Users must sign in to cloud services using their on-premises credentials.
- Users must be able to change their passwords in the cloud and have them update on-premises.
- Authentication must succeed even during an on-premises network outage.
- On-premises infrastructure footprint must be minimized.
Which synchronization method should you recommend?
Your organization, Contoso Global Investments, uses an Azure Management Group hierarchy consisting of a Root Management Group (Root-MG), under which sit the Core-Services Management Group (Core-MG) and the Business-Line Management Group (Business-MG). Under Business-MG, you have two child management groups: Production (Prod-MG) and Development (Dev-MG). You need to design an Azure Policy governance strategy to meet the following compliance requirements:
1. All Azure Storage Accounts deployed within Business-MG and its descendants must only allow HTTPS traffic. Any deployment attempt of a storage account that allows HTTP traffic must be blocked.
2. All virtual machines deployed in Prod-MG must be configured for Azure Backup. If a virtual machine is deployed without a backup configuration, Azure must automatically deploy the backup association after the virtual machine is successfully created, without blocking the deployment itself.
3. To control costs, G-series virtual machines must be prohibited from being deployed anywhere under Root-MG, except for a single subscription named HPC-Prod-Sub under Prod-MG, which hosts a specialized risk analysis engine.
Which set of Azure Policy assignments and effects should you recommend to meet these requirements while minimizing administrative overhead?
A multinational manufacturing company operates workloads in the Germany West Central and East US regions. The compliance and security teams mandate the following requirements:
- Virtual machine resource logs must be stored regionally to comply with strict data residency laws, and regional operations teams must only access logs generated within their respective region.
- Diagnostic logs of Azure Key Vaults containing cryptographic keys must be retained for at least 7 years in a tamper-proof state.
- Azure Activity logs and Microsoft Entra ID sign-in logs must be forwarded to a third-party SIEM tool located in the on-premises datacenter.
- Administrative access to monitoring settings must be automatically enforced for new resources, and role assignments must scale without administrative overhead.
Which two components or configurations should you include in the log routing and monitoring design?
Geçerli olan tümünü seçin
Apex Biologics has an on-premises Active Directory Domain Services (AD DS) forest named ad.apexbiologics.com and two Microsoft Entra ID tenants: a corporate tenant (apexbiologics.com) and a research tenant (apexresearch.com).
You are designing a hybrid identity and multi-tenant solution with the following requirements:
- Users in the corporate tenant must be able to authenticate to Azure resources using their on-premises credentials.
- If the on-premises network or AD DS domain controllers go offline, users must still be able to sign in to Azure resources.
- Users must be able to reset their own passwords from the web, and these password changes must immediately write back to the on-premises AD DS.
- Corporate administrators must be able to collaborate securely with guest users in the research tenant without managing their accounts directly.
Which of the following configurations should you include in the hybrid identity design? (Select two.)
Geçerli olan tümünü seçin
An enterprise is designing a centralized monitoring and log routing architecture for their Azure workloads. The architecture must satisfy specific storage, analytics, and cost requirements. Match each log source and business requirement on the left to its correct Azure destination or configuration on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
You are designing the identity security strategy for a Microsoft Entra ID tenant. You need to map specific identity requirements to their correct Microsoft Entra ID configurations. Match each Microsoft Entra ID feature to its correct primary function.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Your organization has ten Azure subscriptions organized under a single management group. A new team of security auditors needs to inspect the configuration of all resources across all ten subscriptions. You must design an access control solution that minimizes administrative overhead, adheres to the principle of least privilege, and ensures scalability.
Which approach should you recommend?
AuraPharma Group has an on-premises Active Directory Domain Services (AD DS) forest named corp.aurapharma.com and two Microsoft Entra ID tenants: aurapharma.com (primary tenant) and auraresearch.com (research division tenant). You are designing a hybrid and multi-tenant identity solution to meet the following requirements:
* Users in the on-premises forest must authenticate to Azure resources using their local credentials.
* In the event of an on-premises network or domain controller outage, users must still be able to sign in to cloud applications.
* Users must be able to change their passwords in Microsoft Entra ID and have those changes apply immediately to the on-premises AD DS.
* To prevent administrative lockout under extreme conditions, emergency break-glass accounts must bypass Multi-Factor Authentication (MFA).
* Research division users must be able to access line-of-business applications registered in the primary tenant without registering new credentials, while using their own tenant's MFA state.
Which hybrid identity and access design should you recommend?
NovaSpire Logistics is designing an Azure governance solution. The compliance team outlines the following security requirements:
1. All Azure virtual machines must automatically have the Azure Monitor Agent installed upon deployment without manual intervention.
2. Any attempt to deploy an Azure Storage Account that does not enforce secure transit (HTTPS) must be blocked immediately.
Which two Azure Policy effects should you recommend to implement these requirements?
Geçerli olan tümünü seçin
An enterprise has Azure workloads deployed in the Australia East and Japan East regions. You are designing a monitoring and log routing solution that must satisfy the following requirements:
* Data Sovereignty: All diagnostic and activity logs generated by resources in Australia East must remain stored within Australia. All logs generated in Japan East must remain stored within Japan.
* Central Security Operations: A global security team based in the United States must have a unified, real-time interface to run security analytics and threat-hunting queries using Microsoft Sentinel across all regional logs.
* Operational Access: Regional operations teams must only access diagnostic logs and performance metrics for the resources they manage within their respective regions.
* Governance and Security: Access controls must follow the principle of least privilege and be managed at scale using security groups.
Which log routing and workspace architecture should you recommend?
Vespera Financial Services has an on-premises Active Directory Domain Services (AD DS) forest named corp.vesperafin.com containing 14,200 user accounts. The company is designing a hybrid identity solution to integrate with a new Microsoft Entra ID tenant.
The solution must meet the following requirements:
- Users must sign in to cloud services using their on-premises passwords.
- Remote users must be able to authenticate to cloud services even during an extended internet outage at the corporate offices.
- Users on domain-joined devices within the corporate network must experience automatic sign-in without credential prompts or redirections to on-premises login pages.
- Users must be able to reset their passwords using Microsoft Entra Self-Service Password Reset (SSPR), with the changes synchronized on-premises in near real-time.
- On-premises infrastructure footprint and management overhead must be minimized.
Which hybrid identity and authentication configuration should you recommend?