Tüm alıştırma soruları
1198 soru
A logistics company requires an external customs broker to upload shipping manifests to a specific Azure Blob Storage container named 'customs-docs' for a period of 90 days. The access method must satisfy the following requirements:
- Access must be limited strictly to the 'customs-docs' container.
- If the broker's contract is terminated early, access must be immediately revocable without changing storage account access keys or impacting other applications.
- The customs broker must not be required to authenticate via Microsoft Entra ID.
Which of the following access control methods should you implement?
An enterprise named Vertex Holdings has an on-premises Active Directory Domain Services (AD DS) forest with 8,500 users. You are designing a hybrid identity solution to integrate the on-premises environment with a new Microsoft Entra ID tenant.
The solution must meet the following requirements:
- Users must be able to sign in to cloud services using their on-premises credentials.
- Users must be able to sign in even if the on-premises network connection or on-premises domain controllers are temporarily unavailable.
- Users must be allowed to reset their own passwords in the cloud, and these changes must immediately synchronize back to the on-premises AD DS.
- You must minimize on-premises infrastructure requirements and administrative overhead.
Which two actions should you include in the design to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
A company needs to grant an external consultancy temporary read-only access to a specific container in an Azure Storage account. The access must be valid for 14 days, and the security team must be able to revoke this access immediately if a security anomaly is detected. Which two security controls should you recommend? (Select two.)
Geçerli olan tümünü seçin
An organization plans to migrate an on-premises line-of-business application to Azure. The application currently runs on a cluster of VMware vSphere virtual machines (VMs) and connects to a Microsoft SQL Server database cluster. The database relies on SQL Server Agent jobs and performs cross-database queries. The organization needs to discover server dependencies, analyze database compatibility with Azure SQL deployment options, and plan the migration strategy. Which two actions should you include in the migration assessment strategy? (Choose two.)
Geçerli olan tümünü seçin
You are designing the storage infrastructure for a business-critical SQL Server database running on an Azure Virtual Machine. The database transaction logs require a dedicated disk that supports up to IOPS and sub-millisecond latency. The architecture must survive a zone failure in the primary region. Additionally, database backup exports must be securely stored in an Azure Blob Storage container and accessed by a third-party auditing application using a Shared Access Signature (SAS) token that can be revoked immediately if compromised.
Which storage configuration should you recommend?
You are designing a globally distributed data storage solution for a delivery tracking platform. The solution has the following requirements:
- A NoSQL database must store real-time package delivery telemetry. The telemetry ingestion is write-heavy ( writes, reads) with an expected load of millions of updates daily.
- The telemetry database must support a read and write availability SLA and sub- latency.
- Delivery confirmation images must be stored in object storage. External delivery agents must be granted temporary access to upload confirmation images directly to the storage.
- The entire solution must be resilient to regional datacenter outages.
Which of the following configurations should you select to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A global healthcare research institution plans to store clinical trial genomic datasets in an Azure Blob Storage account named genomedata. You are designing a security and access control strategy to meet the following requirements:
1. External pharmaceutical research partners must be granted temporary, read-only access to specific blobs in a container named trial-results.
2. Access for partners must be restricted to a specific IP address range and must support immediate revocation before the planned 7-day expiration period.
3. Storage administrators must manage these access policies following the principle of least privilege, ensuring that administrator roles can only be activated for a maximum of 4 hours at a time and require manager approval.
4. Access permissions must not be assigned directly to individual admin accounts to ensure scalable governance.
Which three actions should you include in the storage security design? (Select THREE.)
Geçerli olan tümünü seçin
An enterprise database hosting platform is migrating its critical transactional database to Azure Virtual Machines. The virtual machines are deployed in a high-availability configuration across multiple Availability Zones in a single Azure region.
The database transaction log drive requires a storage solution that meets the following requirements:
- Must sustain at least IOPS.
- Must provide consistent low latency.
- Must remain online and accessible to virtual machines in another availability zone if the primary availability zone suffers a complete power outage.
Which storage configuration should you recommend?
You are designing a backup solution for critical Azure Virtual Machines. The solution must meet the following requirements:
1. Backups must be protected against a regional outage of the primary Azure region.
2. You must be able to perform instant restores of the virtual machines from local snapshots for the last 2 days.
3. You must retain the backup data in the vault for a total of 30 days.
Which configuration should you recommend?
You are designing the security and access control architecture for an Azure Storage account named mfgtelemetry. The storage account contains two blob containers: firmware-updates and telemetry-logs.
You need to recommend a solution that meets the following security requirements:
- Internal operational administrators must have temporary, request-based read and write access to firmware-updates. Access must require approval, expire automatically, and be fully audited.
- An external partner must be granted read-only access to telemetry-logs. This access must be restricted to the partner's public IP range, must expire within 24 hours, and must support immediate revocation without rotating the storage account access keys or impacting other active access tokens.
- Administrative overhead must be minimized.
Which solution should you recommend?
An organization stores of sales log files in CSV format within an Azure Data Lake Storage Gen2 account. Data analysts need to run occasional, ad-hoc SQL queries against these files to inspect anomalies. You need to recommend an Azure Synapse Analytics query solution that minimizes costs by ensuring there are no ongoing compute charges when queries are not executing. Which resource type should you recommend?
An organization deploys a critical application that uses a single database on Azure SQL Database. The disaster recovery requirements specify that:
- In the event of a regional outage, the database must fail over to a secondary Azure region automatically.
- The application must reconnect automatically without needing any modifications to its connection strings.
Which Azure SQL Database feature should you recommend to meet these requirements?
You are designing an Azure Backup solution for a critical application hosted on Azure Virtual Machines. The solution must satisfy the following requirements:
* For any data loss events occurring within the last days, virtual machine restoration must be performed with the absolute minimum recovery time objective (RTO).
* Backups must be resilient to regional disasters, with the capability to initiate restores in the secondary paired region at any time, regardless of the primary region's status.
* Monthly backups must be kept for years at the lowest possible storage cost.
Which two configuration options should you include in the backup design? (Select TWO)
Geçerli olan tümünü seçin
An organization is designing a high availability and disaster recovery solution for a web application that uses Azure SQL Database. The solution must support automatic failover to a secondary Azure region, provide a single connection endpoint for the application, and allow read-scale operations in the secondary region. Which two features or capabilities should you recommend to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
A healthcare organization is onboarding a team of four external security audit consultants to perform a two-week assessment of critical Azure subscription resources. The consultants require temporary, time-bound administrative access to the resources. To comply with security policies, the consultants must only have access when actively performing audit tasks, all role elevations must require multi-factor authentication (MFA), and administrative overhead must be minimized. The organization also needs to ensure that emergency access break-glass accounts are never locked out of the tenant by any Conditional Access policies enforced during role activation. Which of the following designs should you recommend to meet these requirements?
An educational institution is restructuring its Azure administration model. The institution needs to delegate temporary access to a team of eight junior DevOps engineers who require the Subscription Contributor role to perform deployment tasks. The design must satisfy the following security and governance requirements:
- The junior DevOps engineers must only have administrative permissions when actively working on scheduled deployments.
- Administrative access must be managed using a group-based model to minimize administrative overhead.
- Multi-Factor Authentication (MFA) must be enforced for all administrative tasks.
- Two dedicated emergency-access (break-glass) accounts must be exempt from tenant lockout risks and maintain access if MFA services are unavailable.
Which two actions should you include in the identity and governance design? (Select TWO.)
Geçerli olan tümünü seçin
You are designing a backup solution for an Azure virtual machine. The solution must meet the following requirements:
- Backups must be available in a secondary region to protect against a primary region outage.
- You must be able to perform instant recovery from snapshots for up to 14 days.
Which two configurations should you choose? (Choose two.)
Geçerli olan tümünü seçin
An energy utility company is designing an identity governance and privileged access strategy for its production Azure subscription. The subscription contains critical infrastructure resources. The design must meet the following requirements:
- Provide just-in-time (JIT) administrative access for the network operations team.
- Require multi-factor authentication (MFA) and manager approval for JIT role activation.
- Ensure that administrative permissions are governed at a group level rather than assigned to individual accounts.
- Maintain a recovery path using emergency access (break-glass) accounts that can bypass MFA in case of a tenant-wide identity outage.
Which design strategy should you recommend to meet these requirements?
A company is planning to migrate an on-premises enterprise resource planning (ERP) application to Azure. The application's database layer has the following requirements:
- Must support SQL Server Agent jobs and cross-database queries.
- Must achieve a Recovery Point Objective (RPO) of less than 5 seconds and a Recovery Time Objective (RTO) of less than 30 seconds.
- In the event of a regional disaster, database failover to the secondary region must happen automatically.
- Reporting workloads in the secondary region must run on a read-only replica and must automatically route to the active replica's secondary endpoint without application connection string modifications during failover.
- All network traffic between the database replicas must remain isolated from the public internet.
Which database configuration should you recommend?
An enterprise is designing a telemetry analytics platform on Azure to ingest and store clickstream logs from regional applications. The platform must meet the following requirements:
* Storage and Volume: Ingest and store of historical logs in CSV format within a hierarchical namespace storage account, with a nightly batch pipeline appending of new data at a rate of .
* Exploratory Queries: Enable data analysts to run ad-hoc, exploratory SQL queries on the raw files with a target query latency of under . Compute cost must only be incurred during query execution.
* Resilience: The underlying storage must remain available for read access during a primary Azure region outage.
* Security: Grant third-party partners read-only access to a specific directory in the data lake, with the ability to instantly revoke access if credentials are compromised.
Which storage configuration, analytics service, and authorization mechanism should you recommend to meet these requirements?