Microsoft Azure Security Technologies (AZ-500日本語版) - AZ-500日本語무료 덤프문제 풀어보기
Vault1 という名前の Azure キー コンテナーと VM1 という名前の仮想マシンを含む Azure サブスクリプションがあります。VM1 には Key Vault VM 拡張機能がインストールされています。
Vault1 では、キー、シークレット、証明書をローテーションします。
VM1 で自動的に更新されるものは何ですか?
Vault1 では、キー、シークレット、証明書をローテーションします。
VM1 で自動的に更新されるものは何ですか?
정답: E
次の表に示すように、米国東部2リージョンに2つのAzure仮想マシンがあります。

Azure Key Vaultをデプロイして構成します。
VM1およびVM2でAzure Disk Encryptionを有効にできることを確認する必要があります。
各仮想マシンで何を変更する必要がありますか?回答するには、回答エリアで適切なオプションを選択します。
注:それぞれの正しい選択には1ポイントの価値があります。


Azure Key Vaultをデプロイして構成します。
VM1およびVM2でAzure Disk Encryptionを有効にできることを確認する必要があります。
各仮想マシンで何を変更する必要がありますか?回答するには、回答エリアで適切なオプションを選択します。
注:それぞれの正しい選択には1ポイントの価値があります。

정답:

Explanation:
VM1: The Tier
The Tier needs to be upgraded to standard.
Disk Encryption for Windows and Linux IaaS VMs is in General Availability in all Azure public regions and Azure Government regions for Standard VMs and VMs with Azure Premium Storage.
VM2: the operating system
References:
https://docs.microsoft.com/en-us/azure/virtual-machines/windows/generation-2#generation-1-vs-generation-2-capabilities
アクセスレビューを設定する必要があります。レビューは新しいレビューのコレクションに割り当てられ、リソース所有者によってレビューされます。
順番に実行する必要がある3つのアクションはどれですか?回答するには、適切なアクションをアクションのリストから回答エリアに移動し、正しい順序に並べます。

順番に実行する必要がある3つのアクションはどれですか?回答するには、適切なアクションをアクションのリストから回答エリアに移動し、正しい順序に並べます。

정답:

Explanation:

Step 1: Create an access review program
Step 2: Create an access review control
Step 3: Set Reviewers to Group owners
In the Reviewers section, select either one or more people to review all the users in scope. Or you can select to have the members review their own access. If the resource is a group, you can ask the group owners to review.

References:
https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review
https://docs.microsoft.com/en-us/azure/active-directory/governance/manage-programs-controls
Server1、Server2、およびServer3という名前の3つのオンプレミスサーバーがあり、Windows Server1およびServer2を実行し、内部ネットワーク上に配置されています。 Server3はオンプレミスネットワークにあります。すべてのサーバーがAzureにアクセスできます。
Azure Sentinelから、Windowsファイアウォールデータコネクタをインストールします。
Azure SentinelのサーバーからMicrosoft Defender Firewallデータを収集する必要があります。
あなたは何をするべきか?
Azure Sentinelから、Windowsファイアウォールデータコネクタをインストールします。
Azure SentinelのサーバーからMicrosoft Defender Firewallデータを収集する必要があります。
あなたは何をするべきか?
정답: A
설명: (Fast2test 회원만 볼 수 있음)
Azure サブスクリプションがあります。サブスクリプションには、次の表に示すサブネットを含む VNet1 という名前の仮想ネットワークが含まれています。

サブスクリプションには、次の表に示す関数アプリが含まれています。

NSG1 を使用して制御されるアプリの送信トラフィックはどれですか?

サブスクリプションには、次の表に示す関数アプリが含まれています。

NSG1 を使用して制御されるアプリの送信トラフィックはどれですか?
정답: A
sqlsrv1 という名前の Azure SQL サーバーと DB1 という名前の Azure SQL データベースを含む Azure サブスクリプションがあります。sqlsrv1 は Microsoft Entra 認証のみ用に構成されています。
次の表に示す Microsoft Entra ID があります。

どのユーザーが DB1 のスコープ付き資格情報を作成できますか?
次の表に示す Microsoft Entra ID があります。

どのユーザーが DB1 のスコープ付き資格情報を作成できますか?
정답: B
image1という名前のコンテナーイメージを含むContReg1という名前のAzureコンテナーレジストリがあります。
ContReg1のコンテンツの信頼を有効にします。
コンテンツの信頼を有効にしたら、次の表に示すように2つの画像をContReg1にプッシュします。

どの画像が信頼できる画像ですか?
ContReg1のコンテンツの信頼を有効にします。
コンテンツの信頼を有効にしたら、次の表に示すように2つの画像をContReg1にプッシュします。

どの画像が信頼できる画像ですか?
정답: A
설명: (Fast2test 회원만 볼 수 있음)
Azure サブスクリプションに Azure Kubernetes Service (AKS) クラスターを作成する予定です。
登録されたサーバー アプリケーションのマニフェストを次の図に示します。

AKS クラスターと Azure Active Directory (Azure AD) が統合されていることを確認する必要があります。
マニフェストでどのプロパティを変更する必要がありますか?
登録されたサーバー アプリケーションのマニフェストを次の図に示します。

AKS クラスターと Azure Active Directory (Azure AD) が統合されていることを確認する必要があります。
マニフェストでどのプロパティを変更する必要がありますか?
정답: C
설명: (Fast2test 회원만 볼 수 있음)
ラボのタスク
タスク 3
Danny-31330471 という名前のユーザーが、SQL Server Management Studio (SSMS) と Azure AD 資格情報を使用して、web31330471 という名前の Microsoft SQL サーバー上の任意の SQL データベースにサインインできることを確認する必要があります。
タスク 3
Danny-31330471 という名前のユーザーが、SQL Server Management Studio (SSMS) と Azure AD 資格情報を使用して、web31330471 という名前の Microsoft SQL サーバー上の任意の SQL データベースにサインインできることを確認する必要があります。
정답:
see the task answer with step by step below:
* Create and register an Azure AD application. You can use the Azure portal, Azure PowerShell, or the Azure CLI to do this. You need to specify a name, such as SQLServerCTP1, and select the supported account types, such as Accounts in this organization directory only.
* Grant application permissions. You can use the Azure portal, Azure PowerShell, or the Azure CLI to do this. You need to assign the Directory.Read.All permission to the application and grant admin consent for your organization.
* Create and assign a certificate. You can use the Azure portal, Azure PowerShell, or the Azure CLI to do this. You need to create a self-signed certificate and upload it to the application. You also need to store the certificate in Azure Key Vault and grant access policies to the application and your SQL Server.
* Configure Azure AD authentication for SQL Server through Azure portal. You can use the Azure portal to do this. You need to select your SQL Server resource and enable Azure AD authentication. You also need to select your Azure AD application as the Azure AD admin for your SQL Server.
* Create logins and users. You can use SSMS or Transact-SQL to do this. You need to connect to your SQL Server as the Azure AD admin and create a login for Danny-31330471. You also need to create a user for Danny-31330471 in each database that he needs access to.
* Connect with a supported authentication method. You can use SSMS or SqlClient to do this. You need to specify the Authentication connection property in the connection string as Active Directory Password or Active Directory Integrated. You also need to provide the username and password of Danny-31330471.
* Create and register an Azure AD application. You can use the Azure portal, Azure PowerShell, or the Azure CLI to do this. You need to specify a name, such as SQLServerCTP1, and select the supported account types, such as Accounts in this organization directory only.
* Grant application permissions. You can use the Azure portal, Azure PowerShell, or the Azure CLI to do this. You need to assign the Directory.Read.All permission to the application and grant admin consent for your organization.
* Create and assign a certificate. You can use the Azure portal, Azure PowerShell, or the Azure CLI to do this. You need to create a self-signed certificate and upload it to the application. You also need to store the certificate in Azure Key Vault and grant access policies to the application and your SQL Server.
* Configure Azure AD authentication for SQL Server through Azure portal. You can use the Azure portal to do this. You need to select your SQL Server resource and enable Azure AD authentication. You also need to select your Azure AD application as the Azure AD admin for your SQL Server.
* Create logins and users. You can use SSMS or Transact-SQL to do this. You need to connect to your SQL Server as the Azure AD admin and create a login for Danny-31330471. You also need to create a user for Danny-31330471 in each database that he needs access to.
* Connect with a supported authentication method. You can use SSMS or SqlClient to do this. You need to specify the Authentication connection property in the connection string as Active Directory Password or Active Directory Integrated. You also need to provide the username and password of Danny-31330471.
Group1 という名前のグループを含む Azure Active Directory (Azure AD) テナントがあります。Group1 のメンバーがパスワードなしの認証を使用してサインインしていることを確認する必要があります。どうすればよいですか?
정답: C
注:この質問は、同じシナリオを提示する一連の質問の一部です。シリーズの各質問には、述べられた目標を達成する可能性のある独自の解決策が含まれています。一部の質問セットには複数の正しい解決策がある場合がありますが、他の質問セットには正しい解決策がない場合があります。
このセクションの質問に回答した後は、その質問に戻ることはできません。その結果、これらの質問はレビュー画面に表示されません。
Sub1という名前のAzureサブスクリプションがあります。
RG1という名前のリソースグループにsa1という名前のAzureストレージアカウントがあります。
ユーザーとアプリケーションは、いくつかの共有アクセス署名(SAS)と保存されたアクセスポリシーを使用して、sa1のblobサービスとファイルサービスにアクセスします。
許可されていないユーザーがファイルサービスとblobサービスの両方にアクセスしたことがわかりました。
sa1へのすべてのアクセスを取り消す必要があります。
解決策:Azureストレージアカウントのアクセスキーを再生成します。
これは目標を達成していますか?
このセクションの質問に回答した後は、その質問に戻ることはできません。その結果、これらの質問はレビュー画面に表示されません。
Sub1という名前のAzureサブスクリプションがあります。
RG1という名前のリソースグループにsa1という名前のAzureストレージアカウントがあります。
ユーザーとアプリケーションは、いくつかの共有アクセス署名(SAS)と保存されたアクセスポリシーを使用して、sa1のblobサービスとファイルサービスにアクセスします。
許可されていないユーザーがファイルサービスとblobサービスの両方にアクセスしたことがわかりました。
sa1へのすべてのアクセスを取り消す必要があります。
解決策:Azureストレージアカウントのアクセスキーを再生成します。
これは目標を達成していますか?
정답: B
설명: (Fast2test 회원만 볼 수 있음)
注:この質問は、同じシナリオを提示する一連の質問の一部です。シリーズの各質問には、記載された目標を達成する可能性のある独自のソリューションが含まれています。一部の質問セットには複数の正しい解決策がある場合もあれば、正しい解決策がない場合もあります。
このセクションの質問に回答すると、その質問に戻ることはできません。その結果、これらの質問はレビュー画面に表示されません。
Azureサブスクリプションがあります。サブスクリプションには、Windows Serverを実行する50台の仮想マシンが含まれています
2012 R2またはWindows Server 2016。
仮想マシンにMicrosoft Antimalwareを展開する必要があります。
解決策:各仮想マシンに接続し、Windows機能を追加します。
これは目標を達成していますか?
このセクションの質問に回答すると、その質問に戻ることはできません。その結果、これらの質問はレビュー画面に表示されません。
Azureサブスクリプションがあります。サブスクリプションには、Windows Serverを実行する50台の仮想マシンが含まれています
2012 R2またはWindows Server 2016。
仮想マシンにMicrosoft Antimalwareを展開する必要があります。
解決策:各仮想マシンに接続し、Windows機能を追加します。
これは目標を達成していますか?
정답: A
설명: (Fast2test 회원만 볼 수 있음)