Topic 5: Misc. Questions

You plan to deploy a custom database solution that will have multiple instances as shown in the following table.


Your company plans to deploy various Azure App Service instances that will use Azure SQL databases. The App Service instances will be deployed at the same time as the Azure SQL databases.

The company has a regulatory requirement to deploy the App Service instances only to specific Azure regions. The resources for the App Service instances must reside in the same region.

You need to recommend a solution to meet the regulatory requirement.
Solution: You recommend using an Azure policy to enforce the location of resource groups.

Does this meet the goal?

A.

Yes

B.

No

A.   

Yes



What should you recommend lo meet the monitoring requirements for App2?

A.

Azure Application Insights

B.

Container insights

C.

Microsoft Sentinel

D.

VM insights

A.   

Azure Application Insights



You have an Azure subscription that contains the resources shown in the following table.

You need to recommend a load balancing solution that will distribute incoming traffic for VMSS1 across NVA1 and NVA2. The solution must minimize administrative effort.
What should you include in the recommendation?

A.

Gateway Load Balancer

B.

Azure Front Door

C.

Azure Application Gateway

D.

Azure Traffic Manager

B.   

Azure Front Door



What should you implement to meet the identity requirements? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


You have an application that is used by 6,000 users to validate their vacation requests. The application manages its own credential
Users must enter a username and password to access the application. The application does NOT support identity providers.
You plan to upgrade the application to use single sign-on (SSO) authentication by using an Azure Active Directory (Azure AD) application registration.
Which SSO method should you use?

A.

password-based

B.

OpenID Connect

C.

header-based

D.

SAML

A.   

password-based



You plan to deploy an Azure SQL database that will store Personally Identifiable Information (Pll). You need to ensure that only privileged users can view the Pll. What should you include in the solution?

A.

Transparent Data Encryption (TDE)

B.

Data Discovery & Classification

C.

dynamic data masking

D.

role-based access control (RBAC)

C.   

dynamic data masking



You are evaluating whether to use Azure Traffic Manager and Azure Application Gateway to meet the connection requirements for App1.
What is the minimum numbers of instances required for each service? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


Your company has the infrastructure shown in the following table.

The on-premises Active Directory domain syncs to Azure Active Directory (Azure AD).
Server1 runs an application named Appl that uses LDAP queries to verify user identities in the on-premises Active Directory domain.
You plan to migrate Server1 to a virtual machine in Subscription1.
A company security policy states that the virtual machines and services deployed to Subscription1 must be prevented from accessing the on-premises network.
You need to recommend a solution to ensure that Appl continues to function after the migration. The solution must meet the security policy.
What should you include in the recommendation?

A.

Azure AD Domain Services (Azure AD DS)

B.

an Azure VPN gateway

C.

the Active Directory Domain Services role on a virtual machine

D.

Azure AD Application Proxy

A.   

Azure AD Domain Services (Azure AD DS)



Explanation: https://docs.microsoft.com/en-us/azure/active-directory-domainservices/overview

Azure Active Directory Domain Services (Azure AD DS) provides managed domain services such as domain join, group policy, lightweight directory access protocol (LDAP), and Kerberos/NTLM authentication.

Azure AD Domain Services (Azure AD DS) - This one could work since AAD DS will bring in the existing accounts from Azure AD which in turn are synchronised from on-premise AD over AD connect. However, you would probably need to reconfigure the app and update the LDAP connection.

Azure Active Directory (Azure AD) supports LDAP Authentication via Azure AD Domain Services (AD DS).

https://docs.microsoft.com/en-us/azure/activedirectory/fundamentals/auth-ldap
https://docs.microsoft.com/en-us/azure/active-directory-domain-services/synchronization

You are designing a storage solution that will ingest, store, and analyze petabytes (PBs) of structured, semi-structured and unstructured text data. The analyzed data will be offloaded to Azure Data Lake Storage Gen2 for long-term retention. You need to recommend a storage and analytics solution that meets the following requirements:

• Stores the processed data
• Provides interactive analytics
• Supports manual scaling, built-in autoscaling. and custom autoscaling

What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE Each correct selection is worth one point.


Page 9 out of 28 Pages