Tüm alıştırma soruları
1198 soru
A company plans to migrate an on-premises SQL Server database to Azure. The database requires the use of SQL Server Agent to run scheduled maintenance jobs, and cross-database queries are heavily utilized. The database administration team wants to minimize administrative overhead for managing the underlying operating system. Which Azure SQL deployment option should you recommend?
You are designing a hybrid and multi-tenant identity solution for an organization that has an on-premises Active Directory Domain Services (AD DS) forest and a Microsoft Entra ID tenant. Match each technical requirement on the left to the correct identity technology or configuration on the right. Each technology or configuration may be used once, more than once, or not at all.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A financial services organization is designing an identity and access management solution for its Microsoft Entra ID tenant and hybrid Active Directory Domain Services (AD DS) environment. The design must satisfy the following requirements:
- Users must be able to authenticate to cloud services even during an on-premises WAN outage, without relying on on-premises infrastructure or authentication traffic routing.
- Privileged administrative roles must require Just-in-Time (JIT) activation, and users must be prompted for multi-factor authentication (MFA) when activating these roles.
- The configuration must guarantee that administrators can access the tenant and recover control in the event of a tenant-wide MFA service failure or Conditional Access policy misconfiguration.
- Standard employees must only access corporate applications from compliant, corporate-managed devices.
Which of the following authentication and access management strategies should you recommend?
Zephyr Logistics is designing a hybrid identity solution to integrate its on-premises Active Directory Domain Services (AD DS) forest, internal.zephyrlogistics.com, with a Microsoft Entra ID tenant. The solution must meet the following requirements:
- Users must be able to sign in to cloud services using their on-premises credentials.
- Authentication to cloud services must continue to function even if all on-premises Active Directory domain controllers or the corporate network connection become completely unavailable.
- Users on domain-joined corporate devices inside the corporate network must experience seamless single sign-on (SSO).
- Multi-factor authentication (MFA) must be enforced for all users when accessing cloud applications, but the design must guarantee that administrators are not locked out of the tenant in the event of an MFA service disruption.
- Users must be able to change their passwords in the cloud, and these changes must be reflected on-premises immediately.
Which two actions should you include in the hybrid identity design? (Select two.)
Geçerli olan tümünü seçin
Solas Energy Systems is designing a governance and compliance strategy for its Azure environment. The resource hierarchy consists of a root management group named Solas-Root, with a child management group named Solas-Prod. Under Solas-Prod, there are multiple subscriptions, including 'Solas-Prod-Sub-02'. You must design an Azure Policy solution that meets the following compliance requirements:
1. All storage accounts deployed under Solas-Prod must use HTTPS only. If a storage account is deployed without HTTPS enabled, Azure Policy must automatically enable it during resource creation.
2. Virtual machines in all subscriptions under Solas-Prod must not be deployed with public IP addresses.
3. Virtual machines in a resource group named 'Legacy-App-RG' under 'Solas-Prod-Sub-02' must be allowed to have public IP addresses to support a legacy telemetry service. However, storage accounts in 'Legacy-App-RG' must still be forced to use HTTPS.
4. The solution must minimize administrative overhead for policy assignment and compliance reporting.
Which design should you recommend?
An enterprise is designing a diagnostic log routing solution for a workload consisting of Azure Key Vault instances and Azure SQL Database instances. The solution must satisfy the following constraints:
- Audit logs for all key operations and access attempts in Azure Key Vault must be routed to an external, third-party security information and event management (SIEM) system with sub-minute latency.
- Azure SQL Database transaction logs must be stored cost-effectively in a Write Once, Read Many (WORM) format for 5 years within the same region.
- Access control configuration must adhere to the principle of least privilege, preventing the assignment of permissions directly to individual administrator user accounts.
Which two destination resources and configurations should you include in the diagnostic settings design? (Select two.)
Geçerli olan tümünü seçin
An enterprise is designing a monitoring and log routing architecture for its Azure workloads to meet various operational and compliance requirements. Match each logging scenario to the most appropriate Azure Monitor routing configuration.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A company is deploying a new retail application in Azure that requires a relational database backend. The database design must satisfy the following requirements:
- Cost-effectively manage resource allocation for 20 databases that experience short, unpredictable spikes in usage.
- Ensure that database backups remain available even if a single datacenter within the primary region suffers a complete outage.
Which two options should you include in the design? (Select two.)
Geçerli olan tümünü seçin
Zephyr Global Services has an on-premises Active Directory Domain Services (AD DS) domain. You are designing a hybrid identity solution to sync on-premises user accounts to a single Microsoft Entra ID tenant. The solution must meet the following requirements:
- Users must be able to sign in to cloud services using their on-premises passwords.
- Users must be able to reset their passwords in the cloud, and the new passwords must immediately apply to their on-premises accounts.
- Users must be able to authenticate to cloud services even if the network connection between the on-premises datacenter and Azure is temporarily unavailable.
Which two features should you include in the hybrid identity design? (Select two.)
Geçerli olan tümünü seçin
Zephyr Aerospace has an on-premises Active Directory Domain Services (AD DS) forest named corp.zephyraero.com. The company is designing a hybrid identity solution using Microsoft Entra Connect to integrate with a new Microsoft Entra ID tenant.
You need to select the identity synchronization and authentication design that meets the following requirements:
- Users must use their existing on-premises credentials to sign in to cloud resources.
- Users must be able to reset their passwords using the Microsoft Entra self-service password reset (SSPR) portal, and the updated passwords must immediately update on-premises AD DS.
- Users must be able to authenticate to cloud services even during an extended on-premises network outage.
Which identity solution should you recommend?
A logistics company runs application workloads in Azure across two regions: East US 2 and UK South. The compliance department mandates that all log data generated by resources in UK South must reside in the United Kingdom due to data sovereignty laws. The operations team needs to query these logs to monitor health, but engineers must only be allowed to view logs for the specific Azure resources they have permission to manage. You need to design a monitoring and log routing architecture that meets these requirements while minimizing administrative overhead for access control. Which solution should you recommend?
A financial enterprise manages its Azure resources across multiple production subscriptions using a root management group named Finance-Root. The compliance team mandates that all Azure storage accounts must enforce secure transfer (HTTPS traffic only). If a developer attempts to deploy a storage account with secure transfer disabled, the deployment must succeed, but Azure Policy must automatically enable secure transfer during resource creation. You need to design a governance solution that enforces this requirement with the least administrative effort. Which Azure Policy design should you recommend?
Krypton Global Systems is designing a hybrid identity and multi-tenant access solution. The company has an on-premises Active Directory Domain Services (AD DS) forest named corp.kryptonglobal.com containing 28,500 user accounts. The company has a primary Microsoft Entra ID tenant named kryptonglobal.onmicrosoft.com and has recently acquired a subsidiary company that uses a separate tenant named kryptonsub.onmicrosoft.com.
You must design a solution that satisfies the following requirements:
- On-premises security policies, specifically logon hours restrictions, must be evaluated in real-time when users log in. The solution must minimize the on-premises infrastructure footprint and avoid deploying federation servers.
- Users must be able to perform self-service password resets (SSPR) that are immediately updated in the on-premises AD DS.
- In the event of a total WAN outage at the on-premises datacenters, administrators must have a pre-configured mechanism to quickly transition authentication to the cloud to maintain user access.
- Users in the subsidiary tenant must be allowed to access resources in the primary tenant without registering for Multi-Factor Authentication (MFA) in the primary tenant.
- All administrative access to the primary tenant must require MFA, but the design must guarantee that administrators can access the tenant even if the primary authentication or MFA service suffers a global outage.
Which of the following designs should you recommend?
An enterprise manages its resources using a multi-level Azure management group hierarchy under a single Microsoft Entra tenant:
* Root Management Group
* Corporate (Management Group)
* Production (Management Group)
* Subscription-A
* Subscription-B
* Non-Production (Management Group)
* Subscription-C
You are designing a security and governance solution for a group of database administrators (DBAs). The solution must meet the following requirements:
1. The DBAs must be able to create, modify, and delete Azure SQL databases and SQL elastic pools across all subscriptions under the Production management group.
2. The DBAs must be able to view Azure SQL Server configurations but must not be able to create or delete SQL Servers, nor modify database firewall rules or virtual network rules.
3. The solution must minimize administrative overhead and enforce the principles of least privilege and scalable identity governance.
Which design should you recommend?
An organization is designing a governance strategy for an Azure environment consisting of a root management group and several production subscriptions. You need to implement Azure Policy definitions to enforce compliance for the following requirements:
- All newly deployed Azure storage accounts must have shared key access disabled. If a deployment template attempts to create a storage account with shared key access enabled, the deployment must be blocked.
- All virtual machines must be automatically configured with backup protection. If a virtual machine is deployed without a backup configuration, the policy must deploy the required resources and configure the backup.
Which two policy effects should you recommend to meet these requirements?
Geçerli olan tümünü seçin
Nebula Diagnostics is designing an Azure governance solution. The compliance team mandates that all newly created Azure Virtual Machines must have the Azure Monitor Agent installed. The virtual machine deployment must not be blocked if the agent is missing at the time of creation; instead, the agent must be deployed and configured automatically post-deployment.
Which Azure Policy effect should you recommend to meet these requirements?
Arrange the levels of the Azure resource hierarchy in order from the highest scope (broadest access) to the lowest scope (most granular access).
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is designing a comprehensive monitoring and log routing architecture for various workloads across Azure subscriptions. You need to match the administrative and operational requirements with the most appropriate Azure Monitor destination or feature to minimize costs and administrative overhead.
Match the requirements on the left to their corresponding destinations or features on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Vanguard Retail Group has an on-premises Active Directory Domain Services (AD DS) forest named corp.vanguardretail.com that contains 14,200 users. You are designing a hybrid identity and governance solution to integrate the on-premises environment with a new Microsoft Entra ID tenant.
The solution must meet the following requirements:
- Users must be able to sign in to cloud services using their on-premises passwords, even if the connection between the on-premises network and Azure is temporarily lost.
- Users must have the ability to reset their passwords in the cloud, with the new passwords synchronizing back to the on-premises AD DS.
- All user accounts must be subject to Conditional Access policies that require Multi-Factor Authentication (MFA), but the design must prevent administrative lockout during an MFA service disruption.
- Privileged administrative roles must not be permanently assigned to users, and access permissions for Azure subscriptions must be managed to minimize administrative overhead.
Which design solution should you recommend?
Novasphere Solutions has an on-premises Active Directory Domain Services (AD DS) forest named novasphere.local with 3,200 user accounts. You are designing a hybrid identity solution to integrate the on-premises directory with a new Microsoft Entra ID tenant. The solution must meet the following requirements:
- Users must be able to sign in to Azure resources using their on-premises credentials.
- In the event of an on-premises datacenter or internet connectivity outage, users must still be able to authenticate to cloud services.
- Users must have the ability to reset their own passwords in the cloud, and these changes must immediately reflect in the on-premises directory.
- The administrative overhead of the identity infrastructure must be minimized.
Which hybrid identity synchronization and configuration strategy should you recommend?