AZ-303試験無料問題集「Microsoft Azure Architect Technologies 認定」
You have a virtual network named VNet1 as shown in the exhibit.

No devices are connected to VNet1.
You plan to peer VNet1 to another virtual network named Vnet2 in the same region. VNet2 has an address space of 10.2.0.0/16.
You need to create the peering.
What should you do first?

No devices are connected to VNet1.
You plan to peer VNet1 to another virtual network named Vnet2 in the same region. VNet2 has an address space of 10.2.0.0/16.
You need to create the peering.
What should you do first?
正解:C
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
You have a network security group (NSG) named nsg1 that has the rules shown in the following exhibit.

Users on the internet report that they fail to connect to the servers on the virtual network.
You need to ensure that the users can connect to the servers by using the Remote Desktop client.

Users on the internet report that they fail to connect to the servers on the virtual network.
You need to ensure that the users can connect to the servers by using the Remote Desktop client.
正解:D
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
You have an Azure Storage account named storage! that is accessed by several applications.
An administrator manually rotates me access keys for storage1.
After the rotation the applications fail to access the storage account
A developer manually modifies the applications to resolve the issue.
You need to implement a solution to rotate the access keys automatically. The solution must minimize the need to update the applications once the solution is implemented.
What should you include in the solution?
An administrator manually rotates me access keys for storage1.
After the rotation the applications fail to access the storage account
A developer manually modifies the applications to resolve the issue.
You need to implement a solution to rotate the access keys automatically. The solution must minimize the need to update the applications once the solution is implemented.
What should you include in the solution?
正解:D
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
You have an Azure subscription that contains a virtual machine named VM1 and a Recovery Services vault named Vault 1. VM1 runs Linux.
VM1 is backed up to Vault1 daily.
You need to ensure that you can perform application-consistent backups of VM1.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
VM1 is backed up to Vault1 daily.
You need to ensure that you can perform application-consistent backups of VM1.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
正解:A,D
解答を投票する
You have an Azure subscription that contains 20 virtual machines. The virtual machines require authenticated access to several Azure resources.
You need to ensure that the virtual machines can authenticate by using Azure Active Directory (Azure AD).
Solution: You create and configure an app registration in the Azure AD tenant.
Does this meet the goal?
You need to ensure that the virtual machines can authenticate by using Azure Active Directory (Azure AD).
Solution: You create and configure an app registration in the Azure AD tenant.
Does this meet the goal?
正解:B
解答を投票する
You have an on-premises data center and an Azure subscription. The data center contains two VPN devices. The subscription contains an Azure virtual network named VNet1. VNet1 contains a gateway subnet.
You need to create a site-to-site VPN. The solution must ensure that is a single instance of an Azure VPN gateway fails, or a single on-premises VPN device fails, the failure will not cause an interruption that is longer than two minutes.
What is the minimum number of public IP addresses, virtual network gateways, and local network gateways required in Azure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You need to create a site-to-site VPN. The solution must ensure that is a single instance of an Azure VPN gateway fails, or a single on-premises VPN device fails, the failure will not cause an interruption that is longer than two minutes.
What is the minimum number of public IP addresses, virtual network gateways, and local network gateways required in Azure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

Reference:
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-highlyavailable
You have an Azure subscription that contains the web apps shown in the following table.

App Service plans use the premium service tier.
Which web apps support WebJobs, and which web apps support deployment slots? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


App Service plans use the premium service tier.
Which web apps support WebJobs, and which web apps support deployment slots? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

Reference:
https://docs.microsoft.com/en-us/azure/app-service/webjobs-create
https://medium.com/@vedkoditkar/deploy-azure-web-job-on-docker-c2d91e5ad68f
https://docs.microsoft.com/en-us/azure/app-service/deploy-staging-slots
You need to design an authentication solution that will integrate on-premises Active Directory and Azure Active Directory (Azure AD). The solution must meet the following requirements:
Active Directory users must not be able to sign in to Azure AD-integrated apps outside of the sign-in hours configured in the Active Directory user accounts.
Active Directory users must authenticate by using multi-factor authentication (MFA) when they sign in to Azure AD-integrated apps.
Administrators must be able to obtain Azure AD-generated reports that list the Active Directory users who have leaked credentials.
The infrastructure required to implement and maintain the solution must be minimized.
What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Active Directory users must not be able to sign in to Azure AD-integrated apps outside of the sign-in hours configured in the Active Directory user accounts.
Active Directory users must authenticate by using multi-factor authentication (MFA) when they sign in to Azure AD-integrated apps.
Administrators must be able to obtain Azure AD-generated reports that list the Active Directory users who have leaked credentials.
The infrastructure required to implement and maintain the solution must be minimized.
What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

Reference:
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/choose-ad-authn
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it As a result, these questions will not appear in the review screen.
You have an Azure Active Directory {Azure AD) tenant named contoso.com.
A user named Admin1 attempts to create an access review from the Azure Active Directory admin center and discovers that the Access reviews settings are unavailable. Admin 1 discovers that all the other Identity Governance settings are available.
Admin1 is assigned The User administrator. Compliance administrator, and Security administrator roles.
You need to ensure that Admin1 can create access reviews in contoso.com.
Solution: You assign the Global administrator role to Admin1.
Does this meet the goal?
After you answer a question in this section, you will NOT be able to return to it As a result, these questions will not appear in the review screen.
You have an Azure Active Directory {Azure AD) tenant named contoso.com.
A user named Admin1 attempts to create an access review from the Azure Active Directory admin center and discovers that the Access reviews settings are unavailable. Admin 1 discovers that all the other Identity Governance settings are available.
Admin1 is assigned The User administrator. Compliance administrator, and Security administrator roles.
You need to ensure that Admin1 can create access reviews in contoso.com.
Solution: You assign the Global administrator role to Admin1.
Does this meet the goal?
正解:A
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
