Tüm alıştırma soruları
1198 soru
A company has Azure workloads deployed across the East US and North Europe regions. Regulatory compliance mandates that log data originating from North Europe must remain within the European Union (EU) boundaries. The security team must be able to perform central security analytics across all regions using Microsoft Sentinel. Regional operations teams must only access logs from their respective regions. Furthermore, the configuration of diagnostic log routing to the correct regional destination must be automated for all new resources to minimize administrative overhead. Which architecture should you design to meet the requirements?
You are designing a secure, resilient identity architecture for a global corporation with an on-premises Active Directory Domain Services (AD DS) directory and a Microsoft Entra ID tenant. The design must meet the following requirements:
* On-premises users must be synced to Microsoft Entra ID and must be able to authenticate to cloud services even during an on-premises WAN link outage.
* Administrative roles must be secured using Microsoft Entra Privileged Identity Management (PIM) with just-in-time (JIT) activation.
* All administrative actions must require multi-factor authentication (MFA) and a compliant device via a Conditional Access policy.
* The design must include a mitigation plan to prevent tenant lockout in the event of an outage of the Azure MFA service.
Which design strategy should you recommend?
A logistics company needs to grant five IT support technicians the capability to manage Azure resources, but only when they are actively resolving support tickets. You need to design a privileged access strategy using Microsoft Entra Privileged Identity Management (PIM) that ensures administrative access is time-bound and adheres to identity governance best practices. Which of the following configurations should you include in your design? (Select TWO.)
Geçerli olan tümünü seçin
An organization has workloads deployed in the East US and North Europe regions. Regulatory requirements mandate that log data generated in North Europe must reside and be stored within North Europe to comply with data sovereignty regulations. Similarly, logs from East US must remain in the United States. A centralized security audit team based in the United States requires the ability to run ad-hoc compliance queries across the log data of both regions.
You need to design a monitoring and log routing architecture that satisfies these requirements.
Which two configurations should you include in the design?
Geçerli olan tümünü seçin
Valerius Logistics is designing a hybrid identity solution to integrate their on-premises Active Directory Domain Services (AD DS) forest, which contains 22,000 users, with a new Microsoft Entra ID tenant.
The design must satisfy the following constraints:
- Authentication: Users must sign in to cloud applications using their on-premises credentials.
- Business Continuity: Cloud authentication must remain functional if the on-premises datacenter experiences an internet connectivity outage.
- Self-Service: Users must be able to reset their expired passwords via the Azure portal, and the changes must immediately update on-premises AD DS.
- Governance: To prevent administrator lockout during a tenant-wide Conditional Access policy deployment, at least two emergency access (break-glass) accounts must be created and excluded from all Multi-Factor Authentication (MFA) policies.
Which solution should you recommend to meet these requirements with the lowest administrative and infrastructure overhead?
A digital payments processor is architecting a compliance and access framework for its cloud platform to align with PCI-DSS requirements. The security architecture team must enforce the following access policies:
- External compliance assessors require temporary, time-bound read access to subscription resources. This access must be restricted to a maximum window of four hours, require multi-factor authentication (MFA) upon elevation, and depend on explicit approval from the internal security lead.
- The administrative access footprint must be minimized, avoiding any permanent or standing assignment of privileged permissions to individual users or groups.
- Emergency break-glass accounts must be protected against service-level lockouts (such as an outage affecting the Entra ID multi-factor authentication service) while remaining under strict monitoring.
- All administrative role allocations must be audited regularly, with an automated mechanism to strip access if reviewers do not explicitly approve retention.
Which of the following actions should you recommend in the architectural design to meet these requirements? (Select THREE.)
Geçerli olan tümünü seçin
A company is planning the migration of two on-premises SQL Server databases to Azure. The databases have the following requirements:
* Database A hosts a customer management system that requires SQL Server Agent for scheduling maintenance tasks, Database Mail for system alerts, and cross-database queries. The company wants to minimize administrative overhead for managing the operating system and database patches.
* Database B hosts a legacy financial auditing tool. The application requires access to the underlying operating system registry to validate system configuration keys and must run a specialized host-based security agent directly on the database server operating system.
Which two design recommendations should you include? (Choose two.)
Geçerli olan tümünü seçin
An enterprise plans to integrate a newly acquired subsidiary's standalone Azure subscription into its corporate Management Group structure under a single Microsoft Entra tenant.
The corporate architecture team defines the following requirements:
- A custom Azure RBAC role named 'FinancialAuditor' must be created for the subsidiary's audit team.
- The 'FinancialAuditor' role must only be assignable within the '/providers/Microsoft.Management/managementGroups/Corp-Finance-MG' Management Group hierarchy.
- The subsidiary's subscription must be moved under 'Corp-Finance-MG' and inherit all governance controls.
- To maintain security best practices, direct RBAC assignments to individual user accounts are prohibited.
You need to configure the subscription transition and access controls.
Arrange the steps in the correct logical sequence to meet the requirements.
Öğeleri doğru sıraya koymak için sürükleyin
Solaris Heavy Industries is designing a hybrid identity and collaboration solution. The company has an on-premises Active Directory Domain Services (AD DS) forest named solaris.local that contains 12,500 user accounts. They recently acquired a subsidiary that uses an independent Microsoft Entra ID tenant named aurora-aviation.onmicrosoft.com.
You need to design a solution that meets the following requirements:
- Users in solaris.local must be synchronized to the primary Microsoft Entra tenant (solaris-heavy.onmicrosoft.com) and must be able to authenticate to Azure resources even if the on-premises network link to Azure is temporarily offline.
- On-premises users must be able to change their passwords using Microsoft Entra Self-Service Password Reset (SSPR), and the changes must update the on-premises AD DS immediately.
- Guest users from aurora-aviation.onmicrosoft.com must be allowed to access shared resources in solaris-heavy.onmicrosoft.com securely.
- You must minimize administrative overhead and avoid hosting extra on-premises federation servers.
Which two components should you include in the hybrid identity design? (Select two.)
Geçerli olan tümünü seçin
You are designing an identity governance solution for a company's Azure environment. You need to grant support staff temporary, time-bound access to administrative roles. The solution must prevent permanent standing access and follow administrative best practices for identity delegation. Which configuration should you recommend?
You are designing an Azure storage solution for critical database backups. The backups must remain available and survive the physical failure of a primary Azure datacenter. To minimize costs, you must avoid replicating data across different Azure regions. Which storage redundancy option should you recommend?
An enterprise is designing a hybrid identity and access management solution. The enterprise currently synchronizes its on-premises Active Directory Domain Services (AD DS) environment to Microsoft Entra ID.
The design must satisfy the following requirements:
- Ensure that users can authenticate to cloud resources even if the on-premises network or AD DS domain controllers become unavailable.
- Require multi-factor authentication (MFA) for all administrative access to the Azure portal.
- Prevent administrative lockout of the tenant if there is a regional Microsoft Entra MFA service outage.
- Restrict administrative roles for standard IT administrators to just-in-time (JIT) access.
Which authentication and access control configuration should you recommend?
Veridian Finance is designing a governance and security strategy for its Azure environment. The security team establishes the following compliance mandates for all Azure Key Vault instances:
1. Every Key Vault must have diagnostic logs enabled. If a Key Vault is deployed without diagnostic logs, a Diagnostic Setting must be automatically created to forward the logs to a central Log Analytics workspace.
2. Every Key Vault must have public network access disabled. Any deployment attempt of a Key Vault with public network access enabled must be blocked.
You need to select the Azure Policy effects that meet these compliance mandates while minimizing administrative overhead.
Which policy effects should you recommend?
Your enterprise is designing a monitoring and log routing solution. You need to match each monitoring requirement to the correct Azure service or configuration that satisfies the requirement at the lowest cost and complexity.
Match each log routing requirement on the left to its most appropriate Azure resource or configuration on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A company is planning to migrate a legacy inventory application to Azure. The application's database relies heavily on SQL Server Agent for automated job scheduling and requires cross-database queries between multiple databases on the same server instance. The company wants to minimize administrative overhead and avoid managing the underlying operating system. Which Azure SQL deployment option should you recommend?
Aethelgard Manufacturing has an on-premises Active Directory Domain Services (AD DS) forest named internal.aethelgard.net with 14,000 users. The company has a primary Microsoft Entra ID tenant (aethelgard.com) and recently acquired a subsidiary that uses a separate Entra ID tenant (subsidiary.aethelgard.com). You are designing a hybrid identity and multi-tenant access solution to meet the following requirements:
1. On-premises users must be able to sign in to Microsoft 365 services.
2. The authentication method must support user logins even during a complete outage of the on-premises network or domain controllers.
3. Users must be able to reset their own passwords in the cloud, and these resets must be immediately written back to the on-premises AD DS.
4. You must enforce Multi-Factor Authentication (MFA) via Conditional Access for all standard users, but you must prevent a tenant lockout if the MFA service suffers an outage.
5. Users in the subsidiary tenant must be able to access shared line-of-business applications in the primary tenant using their existing credentials.
Which of the following designs should you recommend?
A global pharmaceutical firm is designing the cloud architecture for its new drug discovery and manufacturing platform. The architecture requires deploying two distinct relational database workloads:
* Workload 1 runs a proprietary legacy control application. It requires a relational database that executes scheduled tasks via SQL Server Agent, requires operating system-level registry modifications, and must run a proprietary third-party assembly that requires access to the local host filesystem.
* Workload 2 runs an analytics ingestion application. It requires cross-database queries across three databases, SQL Server Agent for scheduled data consolidation, and native Common Language Runtime (CLR) integration. Operating system management must be fully offloaded to Azure to minimize administrative overhead.
Which two Azure SQL solutions should you recommend to support these workloads?
Geçerli olan tümünü seçin
An organization named Litware, Inc. has an Azure environment structured with a management group hierarchy. The hierarchy includes a parent management group named TenantRoot, with two child management groups named Production-MG and Development-MG.
The security compliance team mandates the following requirements:
* All virtual machines deployed within Production-MG must have the Azure Monitor Agent installed automatically.
* Any attempt to deploy a storage account within Production-MG that does not enforce secure transit (HTTPS) must be blocked at deployment.
* Development-MG must not be subjected to these compliance rules.
You need to design an Azure Policy solution to meet these requirements with the least amount of administrative overhead.
Which two configurations should you recommend? (Select two.)
Geçerli olan tümünü seçin
An organization is designing an identity and access management architecture for its new Microsoft Entra ID tenant. The organization currently has an on-premises Active Directory Domain Services (AD DS) environment.
The design must satisfy the following technical requirements:
- Synchronize hybrid user accounts to Microsoft Entra ID while minimizing on-premises infrastructure footprint, maintenance overhead, and licensing costs.
- Secure highly privileged administrative roles by enforcing Just-In-Time (JIT) access, requiring Multi-Factor Authentication (MFA) upon role activation.
- Safeguard against accidental administrative lockout from the tenant during a widespread MFA service disruption or policy misconfiguration.
Which two of the following design recommendations should you include to meet these requirements?
Geçerli olan tümünü seçin
An organization is migrating a media processing application to Azure and has identified two key storage requirements:
1. A shared file system to store active media assets. This file system must support the NFS protocol, deliver sub-millisecond latency, and survive a zone-wide datacenter outage.
2. A long-term repository for historical project logs. These logs must be stored at the lowest possible storage cost, but they must be accessible within minutes when requested by compliance auditors.
Which two storage configurations should you recommend to meet these requirements?
Geçerli olan tümünü seçin