AZ-500 Korean試験無料問題集「Microsoft Azure Security Technologies (AZ-500 Korean Version) 認定」
Azure 구독이 있습니다.
다음과 같은 사용자 정의 역할 기반 액세스 제어(RBAC) 역할 정의가 있습니다.

다음 각 문장에 대해, 문장이 사실이라면 '예'를 선택하세요. 그렇지 않으면 '아니요'를 선택하세요.
참고사항: 정답 1개당 1점입니다.

다음과 같은 사용자 정의 역할 기반 액세스 제어(RBAC) 역할 정의가 있습니다.

다음 각 문장에 대해, 문장이 사실이라면 '예'를 선택하세요. 그렇지 않으면 '아니요'를 선택하세요.
참고사항: 정답 1개당 1점입니다.

正解:

Explanation:

참고: 이 문제는 동일한 시나리오를 제시하는 일련의 문제 중 하나입니다. 각 문제는 명시된 목표를 충족할 수 있는 고유한 답안을 포함하고 있습니다. 일부 문제 세트에는 정답이 두 개 이상 있을 수 있고, 다른 문제 세트에는 정답이 없을 수 있습니다.
이 섹션의 질문에 답변한 후에는 해당 섹션으로 돌아갈 수 없습니다. 따라서 해당 질문은 복습 화면에 표시되지 않습니다.
AKS1이라는 Azure Kubernetes Service(AKS) 클러스터와 AZCR1이라는 Azure 컨테이너 레지스트리를 포함하는 Azure 구독이 있습니다.
AKS1이 AZCR1에 저장된 컨테이너 이미지를 배포할 수 있는지 확인해야 합니다.
해결 방법: AKS1의 시스템이 할당한 관리 ID에 AcrPush 역할 기반 액세스 제어(RBAC) 역할을 할당합니다.
이것이 요구 사항을 충족합니까?
이 섹션의 질문에 답변한 후에는 해당 섹션으로 돌아갈 수 없습니다. 따라서 해당 질문은 복습 화면에 표시되지 않습니다.
AKS1이라는 Azure Kubernetes Service(AKS) 클러스터와 AZCR1이라는 Azure 컨테이너 레지스트리를 포함하는 Azure 구독이 있습니다.
AKS1이 AZCR1에 저장된 컨테이너 이미지를 배포할 수 있는지 확인해야 합니다.
해결 방법: AKS1의 시스템이 할당한 관리 ID에 AcrPush 역할 기반 액세스 제어(RBAC) 역할을 할당합니다.
이것이 요구 사항을 충족합니까?
正解:A
解答を投票する
contoso.com이라는 Microsoft Entra 테넌트가 있습니다.
귀하는 fabrikam.com이라는 Microsoft Entra 테넌트를 보유한 파트너 조직과 협업합니다.
com은 모든 사용자에 대해 다중 요소 인증(MFA)을 활성화했습니다.
Contoso.com의 교차 테넌트 액세스 설정은 교차 테넌트 액세스 설정 표에 표시된 대로 구성되어 있습니다. (교차 테넌트 액세스 설정을 클릭하세요.

Contoso.com의 외부 협업 설정은 외부 협업 설정 표에 표시된 대로 구성되어 있습니다. (외부 협업 설정 탭을 클릭하세요.)

다음 설정을 포함하는 조건부 액세스 정책을 만듭니다.
* 이름: CAPolicy1
* 과제
o 게스트 또는 외부 사용자: B2B 협업 게스트 사용자
o 목표 자원
# 포함: 모든 클라우드 앱 o 액세스 제어
# 접근 권한 부여
# 장치가 규정을 준수하는 것으로 표시되어야 함
# 다중 인증 요소 요구
# 정책 활성화: 켜짐
다음 각 문장에 대해, 문장이 사실이라면 '예'를 선택하고, 그렇지 않으면 '아니요'를 선택하세요.
참고: 정답을 맞힌 섹션 하나당 1점입니다.

귀하는 fabrikam.com이라는 Microsoft Entra 테넌트를 보유한 파트너 조직과 협업합니다.
com은 모든 사용자에 대해 다중 요소 인증(MFA)을 활성화했습니다.
Contoso.com의 교차 테넌트 액세스 설정은 교차 테넌트 액세스 설정 표에 표시된 대로 구성되어 있습니다. (교차 테넌트 액세스 설정을 클릭하세요.

Contoso.com의 외부 협업 설정은 외부 협업 설정 표에 표시된 대로 구성되어 있습니다. (외부 협업 설정 탭을 클릭하세요.)

다음 설정을 포함하는 조건부 액세스 정책을 만듭니다.
* 이름: CAPolicy1
* 과제
o 게스트 또는 외부 사용자: B2B 협업 게스트 사용자
o 목표 자원
# 포함: 모든 클라우드 앱 o 액세스 제어
# 접근 권한 부여
# 장치가 규정을 준수하는 것으로 표시되어야 함
# 다중 인증 요소 요구
# 정책 활성화: 켜짐
다음 각 문장에 대해, 문장이 사실이라면 '예'를 선택하고, 그렇지 않으면 '아니요'를 선택하세요.
참고: 정답을 맞힌 섹션 하나당 1점입니다.

正解:

Explanation:

SQL1이라는 Azure SQL 데이터베이스가 포함된 Azure 구독이 있습니다.
App1이라는 이름의 웹 앱을 배포할 계획입니다.
App1에 SQL1에 대한 읽기 및 쓰기 권한을 제공해야 합니다. 솔루션은 다음 요구 사항을 충족해야 합니다.
* 비밀번호를 저장하지 않고도 App1에 SQL1에 대한 액세스 권한을 제공합니다.
* 최소 권한의 원칙을 사용하세요.
* 행정적 노력을 최소화합니다.
App1은 SQL1에 액세스하는 데 어떤 유형의 계정을 사용해야 하며, App1에 어떤 데이터베이스 역할을 할당해야 할까요? 답변하려면 답변 영역에서 적절한 옵션을 선택하세요.
참고: 정답 1개당 1점입니다.

App1이라는 이름의 웹 앱을 배포할 계획입니다.
App1에 SQL1에 대한 읽기 및 쓰기 권한을 제공해야 합니다. 솔루션은 다음 요구 사항을 충족해야 합니다.
* 비밀번호를 저장하지 않고도 App1에 SQL1에 대한 액세스 권한을 제공합니다.
* 최소 권한의 원칙을 사용하세요.
* 행정적 노력을 최소화합니다.
App1은 SQL1에 액세스하는 데 어떤 유형의 계정을 사용해야 하며, App1에 어떤 데이터베이스 역할을 할당해야 할까요? 답변하려면 답변 영역에서 적절한 옵션을 선택하세요.
참고: 정답 1개당 1점입니다.

正解:

Explanation:
Graphical user interface, text, application Description automatically generated

Reference:
https://docs.microsoft.com/en-us/azure/app-service/tutorial-connect-msi-sql-database?tabs=windowsclient%
2Cdotnet
온프레미스 네트워크에는 다음 표에 표시된 서버가 포함되어 있습니다.

Windows Server 2019 또는 SLES를 실행하는 여러 가상 머신이 포함된 Azure 구독이 있습니다. Microsoft Defender for Cloud에서 적응형 애플리케이션 제어를 구현할 계획입니다. 어떤 운영 체제와 플랫폼을 모니터링할 수 있나요? 답변하려면 답변 영역에서 적절한 옵션을 선택하세요.


Windows Server 2019 또는 SLES를 실행하는 여러 가상 머신이 포함된 Azure 구독이 있습니다. Microsoft Defender for Cloud에서 적응형 애플리케이션 제어를 구현할 계획입니다. 어떤 운영 체제와 플랫폼을 모니터링할 수 있나요? 답변하려면 답변 영역에서 적절한 옵션을 선택하세요.

正解:

월요일에 Azure Security Center에서 이메일 알림을 구성하여 사용자 [email protected]에게 알립니다.
화요일에 보안 센터는 다음 표에 표시된 보안 알림을 생성합니다.

[email protected]은 화요일에 몇 개의 이메일 알림을 받게 되나요? 답변하려면 답변 영역에서 적절한 옵션을 선택하세요.
참고: 정답 1개당 1점입니다.

화요일에 보안 센터는 다음 표에 표시된 보안 알림을 생성합니다.

[email protected]은 화요일에 몇 개의 이메일 알림을 받게 되나요? 답변하려면 답변 영역에서 적절한 옵션을 선택하세요.
참고: 정답 1개당 1점입니다.

正解:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/security-center/security-center-provide-security-contact-details
실험실 과제
과제 4
관리자가 Azure Resource Manager 템플릿을 사용하여 리소스를 배포하는 경우 배포가 KV31330471이라는 Azure Key Vault의 비밀에 액세스할 수 있는지 확인해야 합니다.
과제 4
관리자가 Azure Resource Manager 템플릿을 사용하여 리소스를 배포하는 경우 배포가 KV31330471이라는 Azure Key Vault의 비밀에 액세스할 수 있는지 확인해야 합니다.
正解:
see the task answer with step by step below:
* Grant permission to the application that is used to deploy the resources to access the secrets in the key vault. You can use the Azure portal, Azure PowerShell, or the Azure CLI to do this. You need to assign the Key Vault Secrets User role to the application at the scope of the key vault or individual secrets.
* Enable template deployment for the key vault. You can use the Azure portal, Azure PowerShell, or the Azure CLI to do this. You need to set the enabledForTemplateDeployment property of the key vault to true.
* Reference the secrets in the template by using their resource ID. You can use the listSecrets function to get the resource ID of a secret in the key vault. You need to specify the name of the key vault and the name of the secret as parameters.
* Deploy the template by using Azure PowerShell, Azure CLI, or REST API. You can use the New- AzResourceGroupDeployment cmdlet, the az deployment group create command, or the Deployments - Create Or Update REST API to do this. You need to provide the template file or URI and any required parameters.
* Grant permission to the application that is used to deploy the resources to access the secrets in the key vault. You can use the Azure portal, Azure PowerShell, or the Azure CLI to do this. You need to assign the Key Vault Secrets User role to the application at the scope of the key vault or individual secrets.
* Enable template deployment for the key vault. You can use the Azure portal, Azure PowerShell, or the Azure CLI to do this. You need to set the enabledForTemplateDeployment property of the key vault to true.
* Reference the secrets in the template by using their resource ID. You can use the listSecrets function to get the resource ID of a secret in the key vault. You need to specify the name of the key vault and the name of the secret as parameters.
* Deploy the template by using Azure PowerShell, Azure CLI, or REST API. You can use the New- AzResourceGroupDeployment cmdlet, the az deployment group create command, or the Deployments - Create Or Update REST API to do this. You need to provide the template file or URI and any required parameters.
계획된 ExpressRoute 구현을 위한 암호화 솔루션을 추천해야 합니다. 해당 솔루션은 기술 요구 사항을 충족해야 합니다.
각 암호화 유형에 대해 어떤 ExpressRoute 회선을 권장해야 합니까? 답변하려면 답변 영역에서 적절한 옵션을 선택하세요.
참고: 정답 1개당 1점입니다.

각 암호화 유형에 대해 어떤 ExpressRoute 회선을 권장해야 합니까? 답변하려면 답변 영역에서 적절한 옵션을 선택하세요.
참고: 정답 1개당 1점입니다.

正解:

Explanation:

참고: 이 문제는 동일한 시나리오를 제시하는 일련의 문제 중 하나입니다. 각 문제는 명시된 목표를 충족할 수 있는 고유한 답안을 포함하고 있습니다. 일부 문제 세트에는 정답이 두 개 이상 있을 수 있고, 다른 문제 세트에는 정답이 없을 수 있습니다.
이 섹션의 질문에 답변한 후에는 해당 섹션으로 돌아갈 수 없습니다. 따라서 해당 질문은 복습 화면에 표시되지 않습니다.
Azure Security Center를 사용하면 세 개의 Azure 구독에 대한 중앙 집중식 정책 관리가 가능합니다.
구독의 보안을 관리하려면 여러 가지 정책 정의를 사용합니다.
세 개의 구독 모두에 정책 정의를 그룹으로 배포해야 합니다.
해결책: 리소스 그룹에 범위가 지정된 정책 이니셔티브와 할당을 만듭니다.
이것이 목표를 달성하는가?
이 섹션의 질문에 답변한 후에는 해당 섹션으로 돌아갈 수 없습니다. 따라서 해당 질문은 복습 화면에 표시되지 않습니다.
Azure Security Center를 사용하면 세 개의 Azure 구독에 대한 중앙 집중식 정책 관리가 가능합니다.
구독의 보안을 관리하려면 여러 가지 정책 정의를 사용합니다.
세 개의 구독 모두에 정책 정의를 그룹으로 배포해야 합니다.
해결책: 리소스 그룹에 범위가 지정된 정책 이니셔티브와 할당을 만듭니다.
이것이 목표를 달성하는가?
正解:A
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
플랫폼 보호 요구 사항을 충족하려면 AKS1을 배포해야 합니다.
어떤 네 가지 동작을 순서대로 수행해야 할까요? 답하려면 동작 목록에서 해당 동작을 정답 영역으로 옮겨 올바른 순서대로 정리하세요.
참고: 정답 순서가 두 개 이상일 수 있습니다. 정답 순서를 선택하면 그에 따라 크레딧이 지급됩니다.

어떤 네 가지 동작을 순서대로 수행해야 할까요? 답하려면 동작 목록에서 해당 동작을 정답 영역으로 옮겨 올바른 순서대로 정리하세요.
참고: 정답 순서가 두 개 이상일 수 있습니다. 정답 순서를 선택하면 그에 따라 크레딧이 지급됩니다.

正解:

Explanation:

Scenario: Azure AD users must be to authenticate to AKS1 by using their Azure AD credentials.
Litewire plans to deploy AKS1, which is a managed AKS (Azure Kubernetes Services) cluster.
Step 1: Create a server application
To provide Azure AD authentication for an AKS cluster, two Azure AD applications are created. The first application is a server component that provides user authentication.
Step 2: Create a client application
The second application is a client component that ' s used when you ' re prompted by the CLI for authentication. This client application uses the server application for the actual authentication of the credentials provided by the client.
Step 3: Deploy an AKS cluster.
Use the az group create command to create a resource group for the AKS cluster.
Use the az aks create command to deploy the AKS cluster.
Step 4: Create an RBAC binding.
Before you use an Azure Active Directory account with an AKS cluster, you must create role-binding or cluster role-binding. Roles define the permissions to grant, and bindings apply them to desired users. These assignments can be applied to a given namespace, or across the entire cluster.
Reference:
https://docs.microsoft.com/en-us/azure/aks/azure-ad-integration
Topic 1, Litware, inc
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other question on this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next sections of the exam. After you begin a new section, you cannot return to this section.
To start the case study
To display the first question on this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview
Litware, Inc. is a digital media company that has 500 employees in the Chicago area and 20 employees in the San Francisco area.
Existing Environment
Litware has an Azure subscription named Sub1 that has a subscription ID of 43894a43-17c2-4a39-8cfc-
3540c2653ef4.
Sub1 is associated to an Azure Active Directory (Azure AD) tenant named litwareinc.com. The tenant contains the user objects and the device objects of all the Litware employees and their devices. Each user is assigned an Azure AD Premium P2 license. Azure AD Privileged Identity Management (PIM) is activated.
The tenant contains the groups shown in the following table.

The Azure subscription contains the objects shown in the following table.

Azure Security Center is set to the Free tier.
Planned changes
Litware plans to deploy the Azure resources shown in the following table.

Litware identifies the following identity and access requirements:
* All San Francisco users and their devices must be members of Group1.
* The members of Group2 must be assigned the Contributor role to Resource Group2 by using a permanent eligible assignment.
* Users must be prevented from registering applications in Azure AD and from consenting to applications that access company information on the users' behalf.
Platform Protection Requirements
Litware identifies the following platform protection requirements:
* Microsoft Antimalware must be installed on the virtual machines in Resource Group1.
* The members of Group2 must be assigned the Azure Kubernetes Service Cluster Admin Role.
* Azure AD users must be to authenticate to AKS1 by using their Azure AD credentials.
* Following the implementation of the planned changes, the IT team must be able to connect to VM0 by using JIT VM access.
* A new custom RBAC role named Role1 must be used to delegate the administration of the managed disks in Resource Group1. Role1 must be available only for Resource Group1.
Security Operations Requirements
Litware must be able to customize the operating system security configurations in Azure Security Center.
사용자 User1과 User2라는 두 명의 사용자와 App1이라는 등록된 앱이 있는 Azure Active Directory(Azure AD) 테넌트가 있습니다.
앱별 역할을 Role1이라는 이름으로 생성합니다.
User1에게 Role1을 할당하고 User2가 App1에 대한 액세스 권한을 요청할 수 있도록 설정해야 합니다.
어떤 두 가지 설정을 수정해야 할까요? 정답을 선택하려면 답변란에서 적절한 설정을 고르세요. 참고: 각 정답은 1점입니다.

앱별 역할을 Role1이라는 이름으로 생성합니다.
User1에게 Role1을 할당하고 User2가 App1에 대한 액세스 권한을 요청할 수 있도록 설정해야 합니다.
어떤 두 가지 설정을 수정해야 할까요? 정답을 선택하려면 답변란에서 적절한 설정을 고르세요. 참고: 각 정답은 1점입니다.

正解:

Explanation:
Graphical user interface, application Description automatically generated
