Tüm alıştırma soruları
1198 soru
A retail company plans to migrate two on-premises SQL Server workloads to Azure. The migration requirements are as follows:
* Workload A: Runs an inventory application that requires cross-database queries across three databases and uses SQL Server Agent for automated maintenance tasks. The solution must minimize database administration effort.
* Workload B: Runs a customer feedback application that experiences highly unpredictable traffic patterns, with long periods of inactivity. Compute costs must be minimized during inactive periods, and the data must remain resilient against a local datacenter outage.
Which two Azure SQL options should you recommend?
Geçerli olan tümünü seçin
A company is setting up a development environment on an Azure virtual machine that runs a database. The database transaction logs require high-speed performance, and the database backups must be stored in a storage account that remains available if a single datacenter in the region fails.
Which disk type and storage replication option should be selected?
Kestrel BioPharma has an on-premises Active Directory Domain Services (AD DS) forest containing 8,500 users. The company is designing a hybrid identity solution to integrate their AD DS forest with a new Microsoft Entra ID tenant. The solution must meet the following requirements:
- Users must sign in to cloud services using their on-premises credentials.
- The company must use Microsoft Entra ID Protection to identify compromised credentials that are leaked on the public internet.
- User authentication must succeed even if the on-premises network connection is temporarily unavailable.
- On-premises infrastructure requirements for authentication must be minimized.
Which identity synchronization and authentication method should you recommend?
You are designing an Azure Cosmos DB solution for a global retail application that manages product inventory. The application requires global replication across three Azure regions to support low-latency reads and writes, and it must scale to handle a read-to-write ratio. The database must achieve a write availability SLA and prevent hot partitions.
Which configuration should you recommend?
You are designing an identity security strategy for a manufacturing enterprise named Fabrikam, Inc. The enterprise has a Microsoft Entra ID tenant and wants to protect its Azure management interfaces. You must design a solution that meets the following requirements:
- All users assigned to highly privileged roles must use multi-factor authentication (MFA) to access the Azure portal.
- Privileged access must follow the principle of least privilege, ensuring roles are activated only when needed for a maximum of 4 hours.
- In the event of an unexpected Microsoft Entra MFA service outage, administrators must be able to log in to resolve the issue.
- The design must minimize administrative overhead and local infrastructure dependencies.
Which identity and access design should you recommend?
A retail company plans to reorganize its Azure subscription governance. You are designing a strategy to delegate subscription-level billing and resource group management permissions using a custom Azure RBAC role. The custom role must be applied across multiple new subscriptions that will be grouped under a new management group hierarchy. You need to recommend the correct sequence of steps to implement this strategy while ensuring that administrators have immediate, inherited access to the subscriptions as soon as they are governed by the new hierarchy, and that no invalid scope references are created. Which sequence of actions should you recommend?
Öğeleri doğru sıraya koymak için sürükleyin
An organization is designing a shared storage architecture for a hybrid application. The application components are deployed in an Azure Kubernetes Service (AKS) cluster and on-premises virtual machines. The solution must meet the following requirements:
- Provide a shared file system that can be mounted concurrently by multiple AKS pods (ReadWriteMany) and the on-premises virtual machines using the SMB protocol.
- Ensure that the storage can survive a physical zone outage in the primary Azure region without data loss or service disruption.
- Provide access to on-premises users using their existing on-premises Active Directory Domain Services (AD DS) credentials.
- Secure the storage access; if Shared Access Signatures (SAS) are used for any ad-hoc diagnostic transfers, they must support easy revocation.
Which two actions should you include in the storage design?
Geçerli olan tümünü seçin
An enterprise organization is designing a privileged access solution for Microsoft Entra ID. The solution must secure administrative access to the User Administrator role. The design must ensure that administrators only have access when needed, direct assignment of roles to individual user accounts is avoided, and activation requires approval. In the event of an identity service disruption, emergency break-glass accounts must remain functional and not be locked out. Which two of the following configuration steps should you include in the design?
Geçerli olan tümünü seçin
You are designing an Azure storage solution for a company that is deploying a new logging application and a critical backup system. You have the following requirements:
1. The logging application requires high-performance managed disk storage to support continuous, low-latency write operations.
2. The critical backup files must remain highly available even if an entire Azure data center in the primary region suffers a complete power outage.
Which two storage configurations should you recommend to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
An organization is designing the storage infrastructure for a mission-critical financial application hosted on Azure Virtual Machines. The application has the following storage requirements:
1. Database transaction logs: Must support up to IOPS and less than latency. The storage must remain available even if an entire Azure Availability Zone suffers an outage.
2. Long-term database backups: Must be stored in blob storage, retain high durability, be resilient against a regional disaster, and allow immediate read access to the secondary region at all times.
3. Temporary ETL files: Will be accessed via Shared Access Signatures (SAS) by external partners. The SAS tokens must be valid for months, but the security team must have the ability to immediately revoke access if a token is compromised.
Which three storage configurations should you recommend to meet these requirements? (Select three.)
Geçerli olan tümünü seçin
A global retail firm is designing a privileged access and identity governance strategy for their Azure environment. The firm has the following requirements:
- External developers must be granted temporary, just-in-time (JIT) Contributor access to specific resource groups. This access must be assigned and managed collectively to simplify auditing and onboarding/offboarding.
- The IT department must enforce a tenant-wide Conditional Access policy requiring Multi-Factor Authentication (MFA) for all administrative roles, while ensuring that the organization does not get locked out of the tenant in the event of an MFA service outage.
Which of the following designs meets these requirements while adhering to the principle of least privilege?
An enterprise is designing the storage architecture for a transaction database hosted on Azure Virtual Machines and its associated backups. The architecture must meet the following requirements:
* Database Data Volume: Requires 65,000 IOPS and 900 MB/s throughput. The storage must survive a zone outage within the primary region without data loss.
* Database Log Volume: Requires guaranteed sub-millisecond write latency and 10,000 IOPS. Application-level replication provides cross-zone disaster recovery.
* Backups: Must be stored in Azure Blob Storage. An external auditor requires read access to these backups for 48 hours. This access must be immediately revocable at any time without rotating the primary storage account keys.
Which configuration should you recommend?
Tailwind Traders is designing an identity and access management solution for their Microsoft Entra ID tenant. The tenant is synchronized with an on-premises Active Directory Domain Services (AD DS) environment.
The solution must meet the following requirements:
- Enforce Multi-Factor Authentication (MFA) for all administrative roles.
- Ensure that administrators can access privileged roles only when required, using a Just-In-Time (JIT) access model that enforces justification and MFA.
- Mitigate the risk of tenant lockout in the event of a Microsoft Entra ID MFA service outage.
- Minimize infrastructure complexity and administrative overhead.
Which identity and access design should you recommend?
An enterprise is designing a subscription governance and identity delegation strategy for a hybrid environment organized under a single management group hierarchy. The design must accommodate two distinct administrative requirements:
- A third-party audit team requires read-only access to view all resources and security configurations across all subscriptions under the Root Management Group, but only during scheduled quarterly audit windows.
- The cloud operations team must be able to deploy, start, stop, and delete virtual machines within the Prod-Compute-RG resource group under the Production subscription, without being able to modify access control settings or delegate roles.
The design must minimize administrative overhead and enforce the principle of least privilege.
Which two actions should you include in the identity and governance design?
Geçerli olan tümünü seçin
An international company hosts application workloads in Azure across two regions: East US and North Europe. The company's compliance policy dictates that all log data must remain within the region where it was generated. You need to design a monitoring and log routing solution that automatically configures diagnostic logging for newly deployed resources, complies with regional data residency, and minimizes administrative overhead for user access management. Which of the following configurations should you include in the design? (Select TWO.)
Geçerli olan tümünü seçin
An organization is migrating several legacy workloads to Azure and plans to use Azure Cosmos DB. You need to recommend the appropriate Azure Cosmos DB API for each workload based on their technical requirements.
Match each workload pattern to its corresponding Azure Cosmos DB API.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization named Litware, Inc. is designing an identity and access management solution for their Microsoft Entra ID tenant. The organization has an on-premises Active Directory Domain Services (AD DS) environment.
The solution must meet the following requirements:
- Ensure that users can authenticate to cloud services even if the on-premises network or AD DS domain controllers are offline, with minimal configuration overhead and without requiring on-premises server infrastructure.
- Require multi-factor authentication (MFA) for all administrative roles.
- Prevent administrative lockout in the event of an MFA service outage or misconfiguration.
- Implement Privileged Identity Management (PIM) for the Global Administrator role to enforce just-in-time (JIT) access.
Which two actions should you recommend to meet the requirements?
Geçerli olan tümünü seçin
A company is planning a new database deployment on Azure for two internal applications. The design must accommodate the following requirements:
- Application 1: Requires a database that supports SQL Server Agent for automated job scheduling and SQL Server Common Language Runtime (CLR) integration. You must minimize operational overhead.
- Application 2: Requires a database that experiences highly unpredictable query volume, with long periods of inactivity and sudden brief spikes in demand. You must minimize compute costs during idle periods.
Which two database solutions should you recommend?
Geçerli olan tümünü seçin
A company is designing the storage architecture for a health informatics application hosted on Azure Linux virtual machines. The design must meet the following requirements:
- The application requires a shared filesystem that is POSIX-compliant, supports concurrent read/write access from multiple VMs with sub-millisecond metadata latency, and can survive a datacenter zone outage.
- Database transaction logs must be stored on VM disk storage that guarantees sub-millisecond write latency and supports scaling IOPS and throughput dynamically without virtual machine deallocation.
- System audit logs must be stored in a WORM (Write Once, Read Many) state for seven years. External auditors must be granted access to these logs for exactly 30 days using a token that can be revoked immediately if a security compromise is suspected.
Which three storage configurations should you include in the design? (Select three.)
Geçerli olan tümünü seçin
An enterprise is designing a privileged access governance model for its Microsoft Entra ID tenant to align with corporate security guidelines. The design must satisfy the following requirements:
- Administrative privileges must be granted on a temporary, just-in-time (JIT) basis.
- Privileged access management must scale efficiently without causing high administrative overhead as the team grows.
- All administrative access to cloud resources must be protected by Multi-Factor Authentication (MFA).
- The enterprise must ensure that administrators can still access the tenant in the event of a widespread MFA service disruption or identity provider outage.
Which identity and access management design should you recommend?