Ngân hàng đề — Microsoft Azure Administrator
Tìm thấy 456 câu.
You have an autoscale rule configured as shown in the following exhibit.
Criteria
Metric namespace: Standard metrics
Metric name: Memory Percentage
Dimension Name: Instance
Operator: =
Dimension Values: All values
1 minute time grain
If you select multiple values for a dimension, autoscale will aggregate the metric across the selected values, not evaluate the metric for each values individually.
MemoryPercentage (Average): 39.28%
Enable metric divide by instance count: False
Operator: Greater than
Metric threshold to trigger scale action: 70
Duration (minutes): 15
Time grain (minutes): 1
Time grain statistic: Average
Time aggregation: Average
Action
Operation: Increase count by
Cool down (minutes): 5
instance count: 1
For the Instance limits scale condition setting, you set Maximum to 5.
During a 30-minute period, App1 uses 80 percent of the available memory.
What is the maximum number of instances for App1 during the 30-minute period?
- A 2
- B 3
- C 4
- D 5
Xem giải thích
🧩 Phân tích chi tiết nội dung câu hỏi:
Câu hỏi mô tả một ứng dụng Azure App Service tên App1 đang chạy với 2 instances ban đầu. Có một quy tắc autoscale được cấu hình cụ thể dựa trên metric Memory Percentage (tỷ lệ phần trăm bộ nhớ sử dụng):
- Metric namespace: Standard metrics.
- Metric name: Memory Percentage.
- Dimension: Instance với Operator "=" và Dimension Values = All values (nghĩa là tính toán trên tất cả các instances, aggregate metric theo trung bình, không đánh giá riêng lẻ từng instance theo ghi chú trong exhibit).
- Enable metric divide by instance count: False (không chia giá trị metric cho số lượng instances hiện tại, sử dụng giá trị trung bình trực tiếp).
- Operator: Greater than 70%.
- Duration: 15 phút (metric phải duy trì vượt ngưỡng trong 15 phút liên tục để kích hoạt scale).
- Time grain: 1 phút, Statistic: Average, Time aggregation: Average.
- Action: Increase count by 1 instance, Cooldown: 5 phút (thời gian chờ sau scale action để tránh scale liên tục).
- Instance limits: Maximum = 5.
Trong khoảng thời gian 30 phút, App1 sử dụng 80% bộ nhớ khả dụng (available memory – ám chỉ trung bình Memory % trên tất cả instances là 80%, do aggregate trên All values và load duy trì cao).
🛠️ Cách hoạt động autoscale:
- Metric được đánh giá là trung bình Memory % trên tất cả instances (vì dimension All values).
- Giả sử Memory % trung bình duy trì 80% > 70% liên tục suốt 30 phút (load cao persistent, không giảm sau scale do giả định workload giữ average 80%).
- Timeline scale (dựa trên docs Azure: evaluation liên tục, không reset duration sau scale/cooldown; chỉ block action trong cooldown):
- t=0: 2 instances.
- t=15 phút: Đủ duration 15 phút >70% → Scale to 3 instances, cooldown đến t=20.
- t=20: Cooldown hết, last 15 phút (t=5 đến t=20) vẫn >70% → Scale to 4 instances, cooldown đến t=25.
- t=25: Cooldown hết, last 15 phút (t=10 đến t=25) vẫn >70% → Scale to 5 instances, cooldown đến t=30.
- t=30: Kết thúc period, đạt max limit 5.
- 📈 Kết quả: Số instances tăng dần, đạt tối đa 5 instances trong 30 phút.
✅ Đáp án đúng: 5
Lý do: Như timeline trên, quy tắc kích hoạt 3 lần scale out (tăng 1 mỗi lần) sau lần chờ đầu tiên 15 phút, với cooldown 5 phút cho phép scale tiếp ngay sau mỗi cooldown vì metric duy trì cao (lookback duration vẫn thỏa mãn). Đạt đúng giới hạn Maximum 5. Không vượt vì limit và hết 30 phút.
Giải thích tất cả các phương án (giữ nguyên text Anh, phân tích bằng tiếng Việt):
❌ 2: Sai vì chỉ giữ nguyên số instances ban đầu. Quy tắc sẽ kích hoạt scale out ngay sau 15 phút do 80% >70%, không dừng ở 2.
❌ 3: Sai vì chỉ scale 1 lần (sau 15 phút đầu). Thực tế scale tiếp sau cooldown 5 phút (t=20) và t=25, lên 4 rồi 5.
❌ 4: Sai vì scale 2 lần (to 3 và to 4). Còn 1 lần scale nữa tại t=25 lên 5 trong 30 phút.
✅ [ĐÚNG] 5: Đúng như giải thích chi tiết ở trên – đạt max instances sau 3 scale actions trong 30 phút.
📘 Tài liệu tham khảo (kiến thức cập nhật Azure đến 2026, không thay đổi lớn ở tính năng này):
- Azure App Service autoscale overview 🛤️
- Autoscale common metrics & rules 📊 (xem Duration, Cooldown, aggregate dimensions).
- App Service metrics details 🔍 (Memory % là per-instance %, aggregate average khi All dimensions).
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study -
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview -
ADatum Corporation is consulting firm that has a main office in Montreal and branch offices in Seattle and New York.
Existing Environment -
Azure Environment -
ADatum has an Azure subscription that contains three resource groups named RG1, RG2, and RG3.
The subscription contains the storage accounts shown in the following table.
The subscription contains the virtual machines shown in the following table.
The subscription has an Azure container registry that contains the images shown in the following table.
The subscription contains the resources shown in the following table.
Azure Key Vault -
The subscription contains an Azure key vault named Vault1.
Vault1 contains the certificates shown in the following table.
Vault1 contains the keys shown in the following table.
Microsoft Entra Environment -
ADatum has a Microsoft Entra tenant named adatum.com that is linked to the Azure subscription and contains the users shown in the following table.
The tenant contains the groups shown in the following table.
The adatum.com tenant has a custom security attribute named Attribute1.
Planned Changes -
ADatum plans to implement the following changes:
•Configure a data collection rule (DCR) named DCR1 to collect only system events that have an event ID of 4648 from VM2 and VM4.
•In storage1, create a new container named cont2 that has the following access policies: oThree stored access policies named Stored1, Stored2, and Stored3 oA legal hold for immutable blob storage
•Whenever possible, use directories to organize storage account content.
•Grant User1 the permissions required to link Zone1 to VNet1.
•Assign Attribute1 to supported adatum.com resources.
•In storage2, create an encryption scope named Scope1.
•Deploy new containers by using Image1 or Image2.
Technical Requirements -
ADatum must meet the following technical requirements:
•Use TLS for WebApp1.
•Follow the principle of least privilege.
•Grant permissions at the required scope only.
•Ensure that Scope1 is used to encrypt storage services.
•Use Azure Backup to back up cont1 and share1 as frequently as possible.
•Whenever possible, use Azure Disk Encryption and a key encryption key (KEK) to encrypt the virtual machines.
You need to configure encryption for the virtual machines. The solution must meet the technical requirements.
Which virtual machines can you encrypt?
- A VM1 and VM3
- B VM4 and VM5
- C VM2 and VM3
- D VM2 and VM4
Xem giải thích
🧩 Phân tích chi tiết nội dung câu hỏi
Câu hỏi thuộc phần case study của kỳ thi AZ-104 (Microsoft Azure Administrator), mô tả môi trường Azure của công ty ADatum với các tài nguyên như subscription, resource groups (RG1, RG2, RG3), storage accounts (storage1, storage2), virtual machines (VM1 đến VM5), Azure Container Registry (images), Key Vault (Vault1 với keys và certificates), Microsoft Entra (users và groups).
📌 Yêu cầu chính của câu hỏi: "You need to configure encryption for the virtual machines. The solution must meet the technical requirements. Which virtual machines can you encrypt?"
- Technical requirements liên quan: "Whenever possible, use Azure Disk Encryption and a key encryption key (KEK) to encrypt the virtual machines."
Nghĩa là phải sử dụng Azure Disk Encryption (ADE) kết hợp Key Encryption Key (KEK) từ Key Vault (Vault1 có Key1 RSA và Key2 EC, hỗ trợ KEK) để mã hóa OS disk và data disks của VM khi có thể (theo nguyên tắc least privilege và scope phù hợp). - Dữ liệu từ hình ảnh case study (dựa trên 8 bảng/hình):
- Storage accounts: storage1 (StorageV2, West US, Hierarchical namespace: Yes, cont1, share1); storage2 (StorageV2, West US, Hierarchical: No, cont2, share2). Không trực tiếp liên quan nhưng hỗ trợ backup.
- Virtual machines:
| Tên | Size | OS | Mô tả |
|-----|------|----|-------|
| VM1 | A | RHEL | Uses ephemeral OS disks |
| VM2 | D | Windows Server 2022 | Has a basic volume |
| VM3 | B | RHEL | Uses a standard SSDs |
| VM4 | M | Windows Server 2022 | Uses Write Accelerator disks |
| VM5 | E | Windows Server 2022 | Has a dynamic volume | - Các tài nguyên khác (WebApp1, VNet1, Zone1, Log Analytics, ACR images: Image1-Windows, Image2-Linux, Key Vault certs/keys, users/groups) hỗ trợ context nhưng tập trung vào VM encryption.
🔍 Kiến thức cốt lõi (cập nhật đến 2026): ADE sử dụng BitLocker (Windows) / dm-crypt (Linux), mã hóa toàn bộ VM disks với KEK từ Key Vault. Hạn chế hỗ trợ (Azure Disk Encryption v2.2+):
- Hỗ trợ: Generation 1/2 VMs, Standard/Premium SSD/HDD (không ephemeral), basic disks/volumes (nếu persistent), Linux/Windows hiện đại (RHEL, Win Server 2022).
- KHÔNG hỗ trợ: Ephemeral OS disks (temporary, không persistent), Write Accelerator disks (premium feature cho SQL/IO cao), dynamic volumes/disks (không tương thích BitLocker).
(Nguồn: Azure Docs - Disk Encryption Overview & ADE Limitations, cập nhật 2024-2026 không thay đổi cốt lõi).
✅ Đáp án đúng: VM2 and VM3
Lý do chọn (chi tiết):
🛡️ VM2 (Windows Server 2022, basic volume): Hỗ trợ ADE đầy đủ vì basic volume (Standard HDD tier) là persistent disk, tương thích BitLocker + KEK từ Vault1. OS Windows 2022 hỗ trợ ADE v2.
🛡️ VM3 (RHEL, standard SSDs): Standard SSD là managed disk persistent, hỗ trợ dm-crypt + KEK. RHEL tương thích ADE.
✅ Hai VM này đáp ứng "whenever possible" vì không có hạn chế kỹ thuật, tuân thủ least privilege (sử dụng KEK từ Vault1). Các VM khác bị loại do không hỗ trợ ADE.
📋 Giải thích tất cả các phương án (đúng/sai)
-
✅ [ĐÚNG] VM2 and VM3
🟢 Lý do đúng: Như trên, cả hai VM sử dụng persistent disks (basic volume cho VM2, standard SSD cho VM3) hỗ trợ ADE + KEK. Không ephemeral, không Write Accelerator, không dynamic. Tuân thủ technical requirements hoàn hảo. -
❌ [SAI] VM1 and VM3
🔴 Lý do sai: VM1 sử dụng ephemeral OS disks (temporary, không persistent, tự xóa khi VM stop/deallocate) → KHÔNG hỗ trợ ADE (Azure cấm mã hóa ephemeral vì dữ liệu mất khi restart). VM3 đúng nhưng kết hợp sai. -
❌ [SAI] VM4 and VM5
🔴 Lý do sai: VM4 sử dụng Write Accelerator disks (premium SSD v2/Ultra cho workload cao như SQL) → KHÔNG hỗ trợ ADE (Azure docs xác nhận Write Accelerator xung đột với encryption). VM5 có dynamic volume (dynamic disk Windows) → BitLocker/ADE không hỗ trợ (chỉ fixed/basic disks). Cả hai không mã hóa được. -
❌ [SAI] VM2 and VM4
🔴 Lý do sai: VM2 đúng (basic volume hỗ trợ), nhưng VM4 Write Accelerator disks không tương thích ADE (hạn chế I/O encryption). Không đáp ứng "use ADE + KEK whenever possible".
💡 Lưu ý cuối: Để triển khai, dùng Azure Portal/CLI: az vm encryption enable --resource-group RG --name VM --disk-encryption-keyvault KeyVault --key-encryption-key Key1 (Key1 RSA phù hợp KEK). Kiểm tra VM size (A/B/D/M/E tương ứng Basic/Standard) không ảnh hưởng hỗ trợ ADE. (Nguồn bổ sung: Enable ADE with KEK).
You have an Azure subscription that contains the resources shown in the following table.
You need to ensure that all the traffic from VM1 to storage1 travels across the Microsoft backbone network.
What should you configure?
- A Azure Application Gateway
- B service endpoints
- C a network security group (NSG)
- D Azure Peering Service
Xem giải thích
🧩 Giải thích chi tiết nội dung câu hỏi
Câu hỏi thuộc kỳ thi AZ-104: Microsoft Azure Administrator, tập trung vào việc tối ưu hóa luồng traffic trong môi trường hybrid Azure (kết nối on-premises với Azure qua VPN).
Tình huống cụ thể:
- Mạng on-premises có VPN gateway, kết nối với Azure qua Site-to-Site VPN sử dụng Virtual Network Gateway (vgw1).
- Trong Azure subscription:
- VNet1 (Virtual Network): Đã enabled forced tunneling – nghĩa là tất cả traffic outbound từ VNet1 (bao gồm internet và Azure services) bị buộc route qua VPN gateway (vgw1) đến on-premises, thay vì đi trực tiếp qua public internet. Điều này thường do User-Defined Route (UDR) hoặc BGP advertisement từ on-premises đẩy route 0.0.0.0/0 ưu tiên cao.
- VM1 (Virtual Machine): Nằm trong VNet1 (cụ thể là một subnet của VNet1).
- storage1 (Storage Account): Tier Standard performance, là dịch vụ Azure Storage (có địa chỉ IP public).
- Yêu cầu: Đảm bảo tất cả traffic từ VM1 đến storage1 đi qua Microsoft backbone network (mạng backbone riêng tư của Microsoft, không qua public internet hoặc on-premises).
Vấn đề cốt lõi 📈: Với forced tunneling trên VNet1, traffic từ VM1 đến storage1 sẽ bị route qua VPN → on-premises → public internet (vì storage1 có endpoint public), dẫn đến latency cao và không an toàn. Cần cấu hình để traffic này "bypass" forced tunneling và đi trực tiếp qua backbone Microsoft (private path).
Phân tích hình ảnh 📸 (dựa trên bảng tài nguyên được cung cấp):
| Tên | Loại | Mô tả |
|---------|-----------------------|------------------------------------|
| vgw1 | Virtual Network Gateway | Gateway for Site-to-Site VPN to the on-premises network |
| storage1 | Storage account | Standard performance tier |
| VNet1 | Virtual network | Enabled forced tunneling |
| VM1 | Virtual machine | Connected to VNet1 |
- Hình minh họa topology hybrid: VM1 → VNet1 (forced tunneling) → vgw1 → On-prem VPN gateway.
- Không có private endpoint hoặc VNet integration cho storage1, nên traffic mặc định public.
✅ Đáp án đúng: service endpoints
Lý do lựa chọn 🛠️:
- Service Endpoints (nay gọi là VNet Service Endpoints) cho phép traffic từ subnet của VNet1 (chứa VM1) đến Azure Storage (storage1) đi trực tiếp qua Microsoft backbone, bỏ qua forced tunneling và public internet.
- Cách triển khai: Trên subnet của VM1 trong VNet1, enable Service Endpoint cho Microsoft.Storage. Traffic sẽ match service tag Microsoft.Storage và route private (system route ưu tiên cao hơn UDR forced tunneling).
- Kết quả: Traffic VM1 → storage1 100% qua backbone, an toàn, low-latency, không phụ thuộc on-premises.
- Cập nhật 2026: Tính năng vẫn chuẩn (Azure hỗ trợ từ 2017, cải tiến với Private Link ưu tiên hơn, nhưng Service Endpoints phù hợp nhất cho yêu cầu này).
🔍 Giải thích tất cả các phương án
-
Azure Application Gateway ❌
❌ Sai: Application Gateway là L7 load balancer/WAF cho web traffic (HTTP/HTTPS), không kiểm soát route traffic đến Storage Account (không phải web app). Không giải quyết forced tunneling hoặc private routing qua backbone. -
service endpoints ✅
✅ Đúng: Như giải thích trên, đây là giải pháp chính xác để override forced tunneling cho Azure PaaS services như Storage. Traffic sử dụng system route private qua Microsoft global network (backbone). Hiệu quả ngay lập tức sau enable trên subnet. -
a network security group (NSG) ❌
❌ Sai: NSG chỉ kiểm soát allow/deny traffic dựa trên rules (security), không thay đổi route path (routing). Không thể buộc traffic đi backbone; forced tunneling vẫn áp dụng. -
Azure Peering Service ❌
❌ Sai: Azure Peering Service kết nối on-premises đến Microsoft cloud peering locations (cho ISP peering), dùng cho inbound/outbound lớn từ on-prem. Không áp dụng cho traffic nội bộ Azure (VM1 → storage1), và không override forced tunneling trong VNet.
📘 Tài liệu tham khảo (cập nhật mới nhất 2026)
- Microsoft Docs: Virtual network service endpoints in Azure – Xác nhận ưu tiên system route cho Storage.
- Forced Tunneling: About forced tunneling – Giải thích bypass bằng Service Endpoints.
- AZ-104 Exam Reference: ExamTopics AZ-104 Q768 (hình ảnh khớp), AWS không liên quan (có thể nhầm lẫn, nhưng toàn bộ là Azure).
- Azure Updates 2025-2026: Private Link khuyến nghị cho production, nhưng Service Endpoints vẫn optimal cho legacy forced tunneling scenarios.
Kết luận 🎯: Service Endpoints là cách đơn giản, chi phí thấp nhất để đạt yêu cầu! Nếu cần lab, dùng Azure Portal → VNet1 → Subnets → Service endpoints.
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study -
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview -
ADatum Corporation is consulting firm that has a main office in Montreal and branch offices in Seattle and New York.
Existing Environment -
Azure Environment -
ADatum has an Azure subscription that contains three resource groups named RG1, RG2, and RG3.
The subscription contains the storage accounts shown in the following table.
The subscription contains the virtual machines shown in the following table.
The subscription has an Azure container registry that contains the images shown in the following table.
The subscription contains the resources shown in the following table.
Azure Key Vault -
The subscription contains an Azure key vault named Vault1.
Vault1 contains the certificates shown in the following table.
Vault1 contains the keys shown in the following table.
Microsoft Entra Environment -
ADatum has a Microsoft Entra tenant named adatum.com that is linked to the Azure subscription and contains the users shown in the following table.
The tenant contains the groups shown in the following table.
The adatum.com tenant has a custom security attribute named Attribute1.
Planned Changes -
ADatum plans to implement the following changes:
•Configure a data collection rule (DCR) named DCR1 to collect only system events that have an event ID of 4648 from VM2 and VM4.
•In storage1, create a new container named cont2 that has the following access policies: oThree stored access policies named Stored1, Stored2, and Stored3 oA legal hold for immutable blob storage
•Whenever possible, use directories to organize storage account content.
•Grant User1 the permissions required to link Zone1 to VNet1.
•Assign Attribute1 to supported adatum.com resources.
•In storage2, create an encryption scope named Scope1.
•Deploy new containers by using Image1 or Image2.
Technical Requirements -
ADatum must meet the following technical requirements:
•Use TLS for WebApp1.
•Follow the principle of least privilege.
•Grant permissions at the required scope only.
•Ensure that Scope1 is used to encrypt storage services.
•Use Azure Backup to back up cont1 and share1 as frequently as possible.
•Whenever possible, use Azure Disk Encryption and a key encryption key (KEK) to encrypt the virtual machines.
You need to implement the planned changes for the storage account content.
Which containers and file shares can you use to organize the content?
- A share1 only
- B cont1 and share1 only
- C share1 and share2 only
- D cont1, share1, and share2 only
- E cont1, cont2, share1, and share2
Xem giải thích
🧩 Phân tích chi tiết nội dung câu hỏi
📘 Tóm tắt case study:
ADatum Corporation có Azure subscription với các resource groups (RG1, RG2, RG3), storage accounts (storage1 và storage2), VMs, container registry, Key Vault (Vault1), Microsoft Entra tenant (adatum.com).
🛠️ Existing Environment - Storage Accounts (từ hình ảnh):
- storage1: StorageV2 (General Purpose v2), West US, Hierarchical namespace: Yes (hỗ trợ Azure Data Lake Storage Gen2 - ADLS Gen2), có Container: cont1, File share: share1.
- storage2: StorageV2, West US, Hierarchical namespace: No (Blob storage thông thường), có Container: cont2, File share: share2.
✅ Planned Changes liên quan:
- Trong storage1, tạo container mới tên cont2 với stored access policies và legal hold.
- Whenever possible, use directories to organize storage account content (Sử dụng directories để tổ chức nội dung storage account bất cứ khi nào có thể).
🔍 Nội dung câu hỏi cụ thể:
Câu hỏi yêu cầu triển khai planned changes cho storage account content, tập trung vào việc sử dụng directories để organize content (tổ chức nội dung).
- Directories ở đây ám chỉ cấu trúc thư mục phân cấp thực sự (true hierarchical directories).
- Azure Files (file shares): Luôn hỗ trợ directories đầy đủ (SMB/NFS).
- Blob containers:
- Nếu account có Hierarchical namespace = Yes (ADLS Gen2): Hỗ trợ true directories (như file system thực thụ).
- Nếu Hierarchical namespace = No (Blob storage V2): Chỉ hỗ trợ "virtual directories" qua prefix (không phải thư mục thật, không khuyến khích cho organize phức tạp).
- Câu hỏi kiểm tra những containers và file shares hiện có nào có thể sử dụng directories để organize content theo planned changes ("whenever possible"). Lưu ý: Container cont2 mới (planned trong storage1) chưa tồn tại, nên không tính vào lựa chọn; cont2 ở lựa chọn ám chỉ cái hiện có trong storage2.
📈 Kiến thức cập nhật (Azure Storage đến 2026):
Azure StorageV2 hỗ trợ ADLS Gen2 với hierarchical namespace cho blob storage (từ 2019, ổn định đến 2026). Directories chỉ "true" khi hierarchical enabled. Backup cho cont1/share1 (technical req) không ảnh hưởng trực tiếp.
📚 Tài liệu tham khảo:
- Azure Storage account overview (hierarchical namespace).
- Azure Data Lake Storage Gen2 (true directories).
- Azure Files hierarchy.
- AZ-104 exam guide (Microsoft Learn, updated 2024-2026).
✅ Đáp án đúng: cont1, share1, and share2 only
Lý do lựa chọn (chi tiết):
🟢 cont1 (container trong storage1 - Hierarchical: Yes): Hỗ trợ true directories (ADLS Gen2), phù hợp organize content.
🟢 share1 (file share trong storage1): Azure Files luôn hỗ trợ directories đầy đủ.
🟢 share2 (file share trong storage2): Azure Files hỗ trợ directories, bất kể hierarchical namespace.
❌ cont2 (container trong storage2 - Hierarchical: No): Chỉ virtual prefixes, không phải true directories → không "possible" theo planned ("whenever possible").
Điều này tuân thủ principle of least privilege và technical req (backup cont1/share1, nhưng organize ưu tiên hierarchical).
🧩 Giải thích tất cả các phương án
-
❌ share1 only
Sai vì bỏ sót cont1 (hỗ trợ directories trong ADLS Gen2) và share2 (Azure Files hỗ trợ). Không đầy đủ để organize toàn bộ content possible. -
❌ cont1 and share1 only
Sai vì bỏ sót share2 (file share trong storage2 hỗ trợ directories đầy đủ, dù storage2 không hierarchical cho blobs). Có thể organize share2. -
❌ share1 and share2 only
Sai vì bỏ sót cont1 (container trong storage1 hỗ trợ true directories). Không tận dụng hết storage1 (ADLS Gen2). -
✅ cont1, share1, and share2 only
Đúng như giải thích trên: Chính xác các items hỗ trợ directories thật sự, loại cont2 (storage2) vì chỉ prefix. Phù hợp "whenever possible". -
❌ cont1, cont2, share1, and share2
Sai vì bao gồm cont2 (storage2 - No hierarchical): Không hỗ trợ true directories cho blobs, vi phạm planned changes (chỉ dùng khi possible).
💡 Kết luận: Câu hỏi kiểm tra hiểu biết sâu về hierarchical namespace trong Azure Storage để organize content hiệu quả! 🎯
You have an Azure subscription that contains an Azure App Service web app named App1 and an Azure key vault named KV1. KV1 contains a wildcard certificate for contoso.com.
You have a user named user1@contoso.com that is assigned the Owner role for App1 and KV1.
You need to configure App1 to use the wildcard certificate of KV1.
What should you do first?
- A Create an access policy for KV1 and assign the Microsoft Azure App Service principal to the policy.
- B Assign a managed user identity to App1.
- C Configure KV1 to use the role-based access control (RBAC) authorization system.
- D Create an access policy for KV1 and assign the policy to User1.
Xem giải thích
🧩 Phân tích chi tiết nội dung câu hỏi
Câu hỏi này thuộc lĩnh vực Azure App Service và Azure Key Vault (không phải AWS như đề cập, có thể là nhầm lẫn). Tình huống cụ thể:
- Bạn có Azure AD tenant contoso.com.
- Azure subscription chứa App1 (một Azure App Service web app) và KV1 (Azure Key Vault) với wildcard certificate cho contoso.com.
- User user1@contoso.com được gán vai trò Owner cho cả App1 và KV1.
- Mục tiêu: Cấu hình App1 để sử dụng wildcard certificate từ KV1.
- Yêu cầu: Xác định bước đầu tiên cần thực hiện.
🛠️ Quy trình tổng quát để App Service sử dụng certificate từ Key Vault (dựa trên tài liệu Azure cập nhật 2024-2026):
- Gán Managed Identity (hệ thống hoặc người dùng) cho App Service để nó có thể xác thực với Key Vault mà không cần secret.
- Cấp quyền truy cập (Get/List certificates) cho Managed Identity trên KV1 qua Access Policy hoặc RBAC.
- Cấu hình TLS/SSL binding trong App Service để tham chiếu certificate từ KV1.
Vì user1 là Owner, họ có quyền thực hiện tất cả. Bước đầu tiên là kích hoạt Managed Identity cho App1!
📘 Tài liệu tham khảo:
- Use Key Vault with Azure App Service (Azure Docs, cập nhật 2025).
- Managed identities for Azure resources (Azure Entra ID Docs).
✅ Đáp án đúng: Assign a managed user identity to App1.
Lý do chọn:
- Đây là bước đầu tiên bắt buộc! Azure App Service cần Managed Identity (user-assigned hoặc system-assigned) để xác thực an toàn với Key Vault mà không dùng service principal thủ công hay secret.
- Sau khi gán identity, App1 có thể được cấp quyền Get secrets/certificates từ KV1. User1 (Owner) dễ dàng thực hiện qua Portal/CLI.
- Phiên bản mới nhất (2026): Managed Identity là phương pháp khuyến nghị, hỗ trợ RBAC và Access Policy.
❌ Giải thích tất cả các phương án
-
Create an access policy for KV1 and assign the Microsoft Azure App Service principal to the policy.
❌ Sai: Không tồn tại "Microsoft Azure App Service principal" cụ thể để gán trực tiếp. App Service không có service principal mặc định; phải dùng Managed Identity trước. Tạo access policy mà không có identity hợp lệ sẽ thất bại. -
Assign a managed user identity to App1.
✅ Đúng: Như giải thích ở trên, đây là bước first step để App1 có identity xác thực với KV1. Hỗ trợ cả user-assigned (linh hoạt) và system-assigned. -
Configure KV1 to use the role-based access control (RBAC) authorization system.
❌ Sai: KV1 mặc định dùng Access Policy (Vault Access Policy), không cần chuyển sang RBAC trước. RBAC là tùy chọn (enable từ 2021), nhưng không phải bước đầu tiên – phải gán identity cho App1 trước rồi mới cấp role như "Key Vault Certificate User". -
Create an access policy for KV1 and assign the policy to User1.
❌ Sai: User1 đã là Owner (quyền cao nhất), không cần access policy thêm. Vấn đề là App1 cần quyền truy cập, không phải User1. Gán cho User1 không giúp App1 lấy certificate.
You have an Azure subscription that contains the following resources:
✑ A web app named webapp1
✑ A virtual network named VNET1
You need to ensure that webapp1 can connect to Share1.
What should you deploy?
- A an Azure Application Gateway
- B an Azure Active Directory (Azure AD) Application Proxy
- C an Azure Virtual Network Gateway
Xem giải thích
🧩 Phân tích chi tiết câu hỏi trắc nghiệm
📘 Nội dung câu hỏi được giải thích rõ ràng:
Câu hỏi mô tả một kịch bản thực tế trong môi trường hybrid cloud của Microsoft Azure. Bạn có một mạng nội bộ (on-premises) chứa chia sẻ tệp SMB tên là Share1 (SMB là giao thức chia sẻ file phổ biến trên Windows). Trong subscription Azure, bạn có:
- Một web app tên webapp1 (ứng dụng web chạy trên Azure App Service).
- Một virtual network tên VNET1 (mạng ảo Azure).
Mục tiêu: Đảm bảo webapp1 có thể kết nối đến Share1 từ on-premises. Điều này đòi hỏi kết nối hybrid giữa Azure VNet và mạng nội bộ, vì webapp1 cần truy cập tài nguyên SMB qua mạng riêng tư, không qua public internet. Azure Web Apps hỗ trợ tích hợp VNet (VNet Integration) để truy cập tài nguyên trong VNet, nhưng để VNet kết nối on-premises, cần cơ chế gateway VPN hoặc tương tự. Câu hỏi yêu cầu chọn giải pháp deploy (triển khai) để đạt được điều này.
(Kiến thức cập nhật: Theo tài liệu Azure 2024-2026, Web Apps hỗ trợ Regional VNet Integration từ năm 2021, và hybrid connectivity qua VPN Gateway là chuẩn cho SMB access).
✅ Đáp án đúng: an Azure Virtual Network Gateway
Lý do lựa chọn chi tiết: 🛠️ Azure Virtual Network Gateway (cụ thể là VPN Gateway) là thành phần cốt lõi để thiết lập kết nối Site-to-Site VPN hoặc Point-to-Site giữa VNET1 và mạng on-premises. Sau khi deploy gateway này vào VNET1 và cấu hình tunnel VPN (sử dụng IPsec), webapp1 có thể tích hợp VNet Integration để truy cập Share1 qua đường hầm an toàn. Đây là giải pháp chuẩn cho hybrid networking, hỗ trợ SMB traffic (port 445). Không có gateway, VNET1 không thể route traffic đến on-premises.
(Nguồn: Microsoft Docs - Azure VPN Gateway, Azure App Service VNet Integration).
❌ Giải thích tất cả các phương án trả lời
-
an Azure Application Gateway
❌ Sai. Application Gateway là dịch vụ load balancer layer 7 (HTTP/HTTPS) dùng để quản lý traffic web vào/ra cho các ứng dụng như webapp1, hỗ trợ WAF và routing URL-based. Nó không hỗ trợ kết nối hybrid đến on-premises SMB share, vì không tạo tunnel VPN và chỉ xử lý public traffic, không route private traffic đến Share1. -
an Azure Active Directory (Azure AD) Application Proxy
❌ Sai. Azure AD App Proxy dùng để publish (expose) ứng dụng on-premises ra internet một cách an toàn qua Azure AD authentication (reverse proxy). Ở đây, nhu cầu ngược lại: Azure webapp1 cần truy cập vào on-premises Share1, không phải expose Share1 ra ngoài. Nó không tạo kết nối VNet-to-onprem và không hỗ trợ SMB protocol trực tiếp. -
an Azure Virtual Network Gateway
✅ Đúng. Như đã giải thích ở trên, đây là giải pháp chính xác để thiết lập kết nối an toàn giữa VNET1 và on-premises network, cho phép webapp1 (qua VNet Integration) truy cập Share1 qua VPN tunnel. Hỗ trợ đầy đủ SMB và các protocol private khác.
(Nguồn bổ sung: Microsoft Learn - Hybrid Connectivity, cập nhật 2025 với hỗ trợ Gateway Scale Units mới).
🛡️ Lưu ý cuối cùng: Giải pháp này yêu cầu cấu hình thêm như User-Defined Routes (UDR) nếu cần, và kiểm tra NSG/Firewall cho port 445 (SMB). Nếu dùng ExpressRoute, có thể thay thế nhưng câu hỏi tập trung vào Gateway VPN phổ biến nhất!
You create a user named Admin1.
To what can you add Admin1 as a co-administrator?
- A RG1
- B MG1
- C Sub1
- D VM1
Xem giải thích
🧩 Phân tích chi tiết câu hỏi
📖 Nội dung câu hỏi:
Câu hỏi thuộc kỳ thi chứng chỉ AZ-104 Microsoft Azure Administrator, tập trung vào quản lý quyền truy cập trong Azure. Cụ thể:
- Bạn có một Azure subscription tên Sub1 chứa các tài nguyên được liệt kê trong bảng (dựa trên hình ảnh đính kèm):
| Name | Type |
|------|-----------------------|
| MG1 | Management group |
| RG1 | Resource group |
| VM1 | Virtual machine | - Bạn tạo một user tên Admin1.
- Câu hỏi chính: Bạn có thể thêm Admin1 làm co-administrator (quản trị viên đồng cấp - khái niệm legacy từ Azure Classic, vẫn hỗ trợ ở Azure Resource Manager) vào đối tượng nào trong số các lựa chọn?
🛠️ Bối cảnh kỹ thuật (cập nhật đến 2026):
- Co-administrator là vai trò cổ điển (classic role), chỉ áp dụng ở mức subscription (Sub1). Nó cấp quyền Owner-like đầy đủ trên subscription, bao gồm cả tài nguyên bên trong. Không áp dụng cho Resource Group, Management Group hay VM.
- Trong Azure hiện đại (RBAC/AzAD), khuyến nghị dùng Role Assignments thay thế, nhưng câu hỏi tập trung vào tính năng legacy này.
- Hình ảnh xác nhận: MG1 là Management Group (quản lý hierarchy subscriptions), RG1 là Resource Group (nhóm tài nguyên), VM1 là Virtual Machine (máy ảo). Sub1 là subscription chứa chúng.
✅ Đáp án đúng: Sub1
Lý do chọn:
- Trong Azure, bạn chỉ có thể thêm co-administrator trực tiếp vào Subscription (Sub1). Vai trò này cho phép Admin1 quản lý toàn bộ subscription, bao gồm tất cả tài nguyên con (như RG1, VM1).
- Thực hiện qua Azure Portal > Subscriptions > Access control (IAM) > Classic administrators > Add co-administrator.
- ✅ Xác nhận: Đây là tính năng chuẩn, không thay đổi đến phiên bản Azure 2026.
🔍 Giải thích tất cả các phương án
Dưới đây là phân tích từng lựa chọn (giữ nguyên văn bản gốc), đánh dấu ✅ đúng hoặc ❌ sai, với lý do chi tiết bằng tiếng Việt:
-
RG1 ❌ SAI
🧩 Resource Group (RG1) không hỗ trợ thêm co-administrator. RG chỉ dùng RBAC roles (như Owner/Contributor) qua Access control (IAM). Co-admin là legacy, chỉ dành cho subscription cha. -
MG1 ❌ SAI
🧩 Management Group (MG1) dùng để quản lý quyền ở mức hierarchy (subscriptions con), nhưng KHÔNG hỗ trợ co-administrator. Quyền trên MG dùng Azure AD roles hoặc RBAC assignments, không phải classic co-admin. -
Sub1 ✅ ĐÚNG
🧩 Subscription (Sub1) là đúng duy nhất. Bạn có thể thêm Admin1 làm co-admin qua Azure Portal hoặc PowerShell (Add-AzureAccount -Credential), cấp quyền full control trên toàn subscription và tài nguyên con. -
VM1 ❌ SAI
🧩 Virtual Machine (VM1) là tài nguyên cấp thấp, KHÔNG hỗ trợ co-administrator. Quyền trên VM chỉ qua RBAC trên RG/subscription chứa nó, không có khái niệm co-admin riêng.
📘 Tài liệu tham khảo (cập nhật mới nhất 2026)
- Azure Docs: Classic subscription administrators – Giải thích co-admin chỉ áp dụng cho subscriptions.
- Azure Docs: Manage access to Azure subscriptions – Khuyến nghị migrate sang RBAC.
- AZ-104 Exam Guide – Chủ đề Identity & Governance.
💡 Lưu ý: Tránh dùng co-admin vì legacy; ưu tiên RBAC để an toàn hơn! Nếu cần thực hành, dùng Azure Portal demo subscription.
You plan to deploy the resources shown in the following table.
You need to create a single Azure Resource Manager (ARM) template that will be used to deploy the resources.
Which resource should be added to the dependsOn section for VM1?
- A VNET1
- B NIC1
- C IP1
- D NSG1
Xem giải thích
🧩 Phân tích chi tiết câu hỏi
📘 Nội dung câu hỏi:
Câu hỏi thuộc chứng chỉ AZ-104 (Microsoft Azure Administrator), liên quan đến việc triển khai tài nguyên Azure bằng Azure Resource Manager (ARM) template. Bạn có một subscription Azure và lập kế hoạch triển khai các tài nguyên được liệt kê trong bảng hình ảnh.
🖼️ Phân tích hình ảnh đính kèm:
Hình ảnh là một bảng liệt kê 5 tài nguyên chính sẽ được deploy:
- IP1: Microsoft.Network/publicIPAddresses (Public IP Address).
- NSG1: Microsoft.Network/networkSecurityGroups (Network Security Group).
- VNET1: Microsoft.Network/virtualNetworks (Virtual Network).
- NIC1: Microsoft.Network/networkInterfaces (Network Interface Card).
- VM1: Microsoft.Compute/virtualMachines (Virtual Machine).
Mục tiêu: Tạo một ARM template duy nhất để deploy tất cả. Câu hỏi yêu cầu xác định tài nguyên nào phải thêm vào phần dependsOn của VM1 để đảm bảo thứ tự triển khai đúng (VM chỉ deploy sau khi tài nguyên phụ thuộc sẵn sàng).
🛠️ Nguyên tắc dependsOn trong ARM template (cập nhật đến 2026):
dependsOnchỉ rõ dependency ngầm định (implicit dependency) giữa các resource.- VM luôn phụ thuộc trực tiếp vào NIC vì VM cần NIC để attach network interface (osProfile.networkProfile.networkInterfaces).
- Các tài nguyên khác (VNet, NSG, Public IP) là dependency gián tiếp của NIC, không trực tiếp của VM.
- ARM tự động detect một số dependency (như reference ID), nhưng phải khai báo rõ
dependsOncho VM-NIC để tránh lỗi deploy (VM fail nếu NIC chưa ready).
✅ Đáp án đúng: NIC1
Lý do lựa chọn (bằng tiếng Việt):
VM1 phải dependsOn NIC1 vì NIC là thành phần bắt buộc và trực tiếp gắn vào VM (qua thuộc tính networkProfile.networkInterfaces). Nếu NIC chưa deploy, VM sẽ fail khi cố gắng attach interface. Đây là quy tắc chuẩn của Azure ARM (không thay đổi đến 2026).
🔍 Giải thích tất cả các phương án (sử dụng emoji để phân biệt)
-
❌ VNET1 (Microsoft.Network/virtualNetworks):
Sai vì VNET1 là dependency gián tiếp của VM1 (qua NIC subnet). NIC sẽ dependsOn VNET1, nhưng VM1 không cần trực tiếp dependsOn VNET (ARM tự detect qua reference). Thêm VNET1 vào dependsOn VM1 là thừa và không giải quyết dependency cốt lõi. -
✅ NIC1 (Microsoft.Network/networkInterfaces):
Đúng vì NIC1 là dependency trực tiếp và duy nhất bắt buộc cho VM1. VM tham chiếu ID của NIC trong template (ví dụ:[resourceId('Microsoft.Network/networkInterfaces', 'NIC1')]). Phải khai báodependsOn: [resourceId('NIC1')]để VM chờ NIC ready trước khi provision. -
❌ IP1 (Microsoft.Network/publicIPAddresses):
Sai vì IP1 là optional dependency của NIC (nếu associate public IP). NIC có thể dependsOn IP1 nếu dùng, nhưng VM1 không trực tiếp phụ thuộc IP1. VM chỉ cần NIC, không cần biết IP. -
❌ NSG1 (Microsoft.Network/networkSecurityGroups):
Sai vì NSG1 là security dependency của NIC hoặc subnet (associate rules). VM1 không phụ thuộc trực tiếp NSG, ARM tự handle nếu reference đúng. Thêm NSG vào dependsOn VM1 không cần thiết và có thể gây loop dependency.
📚 Tài liệu tham khảo (cập nhật mới nhất 2026)
- Azure Docs - ARM Templates Dependencies: docs.microsoft.com/en-us/azure/azure-resource-manager/management/resource-dependency ✅ (Giải thích rõ VM dependsOn NIC).
- Quickstart VM ARM Template: docs.microsoft.com/en-us/azure/virtual-machines/windows/quick-create-template 🛠️ (Ví dụ mẫu với dependsOn NIC cho VM).
- AZ-104 Exam Guide: ExamTopics AZ-104 Question ~767 (hình ảnh khớp), Microsoft Learn AZ-104 module "Deploy and manage resources" 📘.
💡 Lưu ý thực hành: Trong ARM template thực tế, code cho VM1 sẽ như:
{
"type": "Microsoft.Compute/virtualMachines",
"dependsOn": ["NIC1"], // ← Chính xác!
...
}
Hy vọng phân tích giúp bạn nắm vững! 🚀
You create a public IP address named IP1.
Which two resources can you associate to IP1? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
- A VM1
- B LB1
- C NIC1
- D VPN1
- E VNet1
Xem giải thích
🧩 Giải thích nội dung câu hỏi
Câu hỏi thuộc kỳ thi chứng chỉ AZ-104: Microsoft Azure Administrator, tập trung vào việc quản lý địa chỉ IP công khai (Public IP) trong Azure. Bạn có một subscription Azure chứa các tài nguyên được liệt kê trong bảng (từ hình ảnh):
- VM1: Virtual machine (máy ảo).
- VNet1: Virtual network (mạng ảo).
- NIC1: Network interface (giao diện mạng, thường gắn với VM).
- LB1: Load balancer (bộ cân bằng tải).
- VPN1: Virtual network gateway (cổng mạng ảo, dùng cho VPN).
Bạn tạo một Public IP address mới tên IP1 (mặc định là SKU Basic hoặc Standard, tùy theo phiên bản Azure cập nhật đến 2026). Câu hỏi yêu cầu chọn hai tài nguyên có thể gắn kết (associate) trực tiếp với IP1. Đây là câu hỏi multi-select (mỗi lựa chọn đúng đáng 1 điểm).
Lưu ý từ hình ảnh: Bảng chỉ liệt kê tên và loại tài nguyên, không hiển thị cấu hình chi tiết (như IP hiện tại của chúng). Tuy nhiên, các tài nguyên này đã tồn tại sẵn trong subscription, nên việc associate phải tuân thủ quy tắc Azure cho tài nguyên existing (không thể thay đổi một số config mà không xóa/tái tạo). Kiến thức dựa trên Azure Virtual Network docs phiên bản mới nhất 2026 (hỗ trợ IPv6 dual-stack, SKU Standard cho high availability).
✅ Đáp án đúng: LB1 và NIC1
- Lý do chọn: Trong Azure, Public IP có thể gắn trực tiếp với Network Interface (NIC) qua IP configuration, và với Load Balancer qua Frontend IP Configuration. Các tài nguyên này linh hoạt, cho phép associate IP mới mà không cần tái tạo. Điều này giúp expose dịch vụ ra Internet an toàn (NAT, security groups).
📘 Nguồn: Microsoft Docs - Public IP addresses (cập nhật 2024-2026).
🛠️ Giải thích chi tiết tất cả các phương án
Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Phân tích dựa trên khả năng associate Public IP IP1 với tài nguyên existing:
-
✅ LB1 (Load balancer)
Đúng: Load Balancer (Standard hoặc Basic SKU) hỗ trợ associate Public IP mới vào Frontend IP Configuration (IPv4/IPv6). Bạn có thể thêm rule mới hoặc update config mà không downtime lớn. Ví dụ: Tạo frontend config và assign IP1 để cân bằng tải public traffic. Hoàn hảo cho HA scenarios. -
✅ NIC1 (Network interface)
Đúng: NIC là resource cốt lõi để attach Public IP trực tiếp qua IP configurations (primary/secondary). Với NIC existing (gắn VM1), bạn detach IP cũ (nếu có) và associate IP1 ngay lập tức. Điều này expose VM ra Internet (kết hợp NSG cho bảo mật). SKU Standard hỗ trợ zone-redundancy từ 2023+. -
❌ VM1 (Virtual machine)
Sai: VM không hỗ trợ associate Public IP trực tiếp. IP phải gắn qua NIC của VM. VM chỉ quản lý metadata, không có IP config riêng. Nếu cố attach, Azure sẽ báo lỗi "Invalid resource type". -
❌ VPN1 (Virtual network gateway)
Sai: Virtual Network Gateway (VPN type) đã tồn tại nên không thể associate Public IP mới. Khi tạo VNG, Public IP được lock vào Gateway IP Configuration (trong gateway subnet của VNet1). Để thay đổi, phải xóa và tái tạo gateway (downtime cao, mất kết nối VPN). Docs xác nhận: "Can't change public IP after gateway creation". -
❌ VNet1 (Virtual network)
Sai: Virtual Network không hỗ trợ associate Public IP. VNet quản lý subnets, peering, không có IP config public. Public IP chỉ dùng cho endpoints như NIC/LB, không phải VNet itself (dùng cho private IP ranges).
Tóm tắt nhanh: Chỉ NIC và LB linh hoạt cho existing resources. Sử dụng Azure Portal/CLI: az network public-ip show để verify trước associate! 🚀
You create the following Azure Resource Manager (ARM) template named Template.json.
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {},
"variables": {},
"resources": [
{
"type": "Microsoft.Resources/resourceGroups",
"apiVersion": "2022-12-01",
"location": "eastus",
"name": "Marketing"
}
],
"outputs": {}
}
You need to deploy Template.json.
Which PowerShell cmdlet should you run from Azure Cloud Shell?
- A New-AzSubscriptionDeployment
- B New-AzManagementGroupDeployment
- C New-AzResourceGroupDeployment
- D New-AzTenantDeployment
Xem giải thích
🧩 Phân tích chi tiết nội dung câu hỏi
Câu hỏi tập trung vào việc triển khai (deploy) một Azure Resource Manager (ARM) template có tên Template.json trong một Azure subscription. Template này được thiết kế để tạo một resource group mới có tên "Marketing", nằm ở vị trí "eastus".
📋 Các đặc điểm chính của template:
- Sử dụng schema mới nhất:
"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#". - Resource duy nhất:
{ "type": "Microsoft.Resources/resourceGroups", "apiVersion": "2022-12-01", // Phiên bản API cập nhật đến 2026 "location": "eastus", "name": "Marketing" } - Template không yêu cầu parameters hoặc variables, và không có outputs.
🎯 Yêu cầu cụ thể: Chạy lệnh PowerShell cmdlet từ Azure Cloud Shell để deploy template này. Lưu ý rằng việc tạo resource group phải diễn ra ở scope (phạm vi) phù hợp, vì resource group là tài nguyên con trực tiếp của subscription (không phải của resource group khác).
🛠️ Kiến thức cốt lõi (cập nhật đến 2026): Trong Azure (Az PowerShell module phiên bản mới nhất ~12.x+), ARM deployments hỗ trợ các scope khác nhau: Tenant, Management Group, Subscription, và Resource Group. Template tạo resource group chỉ có thể deploy ở subscription scope hoặc cao hơn, vì resource group không tồn tại trước để làm scope.
📘 Tài liệu tham khảo:
- Azure Docs: Deployment scopes (cập nhật 2024-2026).
- Az PowerShell Reference: New-AzSubscriptionDeployment.
- ARM Template for Resource Groups.
✅ Đáp án đúng và lý do lựa chọn
Đáp án đúng: New-AzSubscriptionDeployment
🟢 Lý do: Cmdlet này deploy ARM template ở subscription scope, phù hợp hoàn hảo để tạo resource group mới (vì resource group thuộc subscription). Lệnh chạy từ Azure Cloud Shell sẽ như:New-AzSubscriptionDeployment -Location eastus -TemplateFile Template.json. Không cần chỉ định resource group hiện có, và apiVersion "2022-12-01" hỗ trợ đầy đủ.
📝 Giải thích tất cả các phương án (đúng/sai)
-
New-AzSubscriptionDeployment
✅ Đúng: Deploy ở subscription scope, cho phép tạo resource group trực tiếp mà không cần RG cha. Đây là lựa chọn chuẩn cho template chỉ tạo RG (không deploy resources vào RG cụ thể). Hỗ trợ incremental/complete mode, cập nhật đến Az module 2026. -
New-AzManagementGroupDeployment
❌ Sai: Cmdlet này deploy ở management group scope (nhóm quản lý cao cấp hơn subscription). Template tạo RG không hợp lệ ở scope này, vì RG chỉ tồn tại trong subscription con. Sẽ báo lỗi scope mismatch. -
New-AzResourceGroupDeployment
❌ Sai: Deploy ở resource group scope (yêu cầu RG đã tồn tại để target). Template tạo RG mới nên không thể dùng scope này – sẽ lỗi vì "target RG không tồn tại" hoặc vòng lặp logic (chicken-egg problem). -
New-AzTenantDeployment
❌ Sai: Deploy ở tenant scope (toàn bộ Azure AD tenant, cao nhất). Chỉ dùng cho policies/blueprints toàn tenant, không phù hợp tạo RG cụ thể trong subscription. Sẽ lỗi vì RG không hỗ trợ scope tenant trực tiếp.