Ngân hàng đề — Microsoft Azure Administrator
Tìm thấy 456 câu.
You need to ensure that Plan1 will scale automatically when the CPU usage of the web app exceeds 80 percent.
What should you select for Plan1?
- A Automatic in the Scale out method settings
- B Rules Based in the Scale out method settings
- C Premium P1 in the Scale up (App Service plan) settings
- D Standard S1 in the Scale up (App Service plan) settings
- E Manual in the Scale out method settings
Xem giải thích
🧩 Phân tích chi tiết nội dung câu hỏi
Câu hỏi tập trung vào việc cấu hình tự động mở rộng (autoscaling) cho một Azure App Service Plan ở mức Standard có tên Plan1. Cụ thể, yêu cầu là đảm bảo Plan1 tự động scale out (mở rộng ngang - thêm instances) khi CPU usage của web app vượt quá 80%.
- Scale out ở đây nghĩa là tăng số lượng instances (máy ảo) để xử lý tải cao hơn, dựa trên metric như CPU.
- Azure App Service Plan ở tier Standard hỗ trợ Autoscale, nhưng cần cấu hình đúng phương thức trong phần Scale out settings (thường truy cập qua Azure Portal > App Service Plan > Scale out (App Service plan)).
- Mục tiêu là tự động hóa dựa trên quy tắc (rules) như CPU threshold 70-80%, không phải thủ công hoặc scale up (nâng cấp tier plan).
Đây là tính năng cốt lõi của Azure Autoscale (cập nhật đến 2026: vẫn giữ nguyên mô hình rules-based scaling với hỗ trợ metric như CPU, Memory, HTTP queue length; tích hợp AI predictions ở Premium tiers nhưng cơ bản dùng rules cho Standard).
✅ Đáp án đúng và lý do lựa chọn
Đáp án đúng: Rules Based in the Scale out method settings
Lý do:
- Trong Azure Portal, để scale out tự động dựa trên metric CPU >80%, bạn chọn Autoscale > Scale out method: Rules Based.
- Sau đó, tạo scaling rules (ví dụ: Scale out khi CPU >80% trong 10 phút, scale in khi <60%).
- Tier Standard hỗ trợ đầy đủ tính năng này 🛠️. Không dùng "Automatic" vì Azure ưu tiên rules-based cho metric chính xác, giúp kiểm soát chi phí và tránh over-scaling.
📋 Giải thích tất cả các phương án (đúng/sai)
Dưới đây là phân tích từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), kèm giải thích chi tiết bằng tiếng Việt:
-
❌ Automatic in the Scale out method settings
Phương án này sai vì Azure không có tùy chọn "Automatic" trực tiếp trong Scale out method. Thay vào đó, dùng "Rules Based" để định nghĩa rules cụ thể (như CPU threshold). "Automatic" có thể nhầm với predictive scaling (chỉ ở Premium/Isolation tiers), không phù hợp cho Standard và không đảm bảo chính xác 80% CPU. -
✅ Rules Based in the Scale out method settings
Phương án này đúng như đã giải thích ở trên. Đây là cách chuẩn để thiết lập rules metric-based autoscaling (CPU >80% → scale out). Hỗ trợ đầy đủ ở Standard tier, dễ cấu hình qua Portal/CLI/PowerShell. -
❌ Premium P1 in the Scale up (App Service plan) settings
Phương án này sai vì Scale up là mở rộng dọc (vertical scaling) - nâng cấp tier plan (từ Standard lên Premium P1 để có CPU/RAM cao hơn). Không phải scale out tự động dựa trên CPU, và Premium P1 dùng cho nhu cầu cao hơn (hỗ trợ custom domains, slots tốt hơn), không giải quyết yêu cầu scale instances. -
❌ Standard S1 in the Scale up (App Service plan) settings
Phương án này sai tương tự trên: Scale up chỉ thay đổi SKU trong cùng tier (Standard S1 là mức thấp hơn Standard), không tạo autoscaling instances. Yêu cầu là scale out (thêm instances), không phải nâng cấp plan. -
❌ Manual in the Scale out method settings
Phương án này sai vì Manual yêu cầu can thiệp thủ công để thay đổi số instances (không tự động khi CPU >80%). Không đáp ứng "scale automatically" như câu hỏi đòi hỏi.
📘 Tài liệu tham khảo (cập nhật mới nhất đến 2026)
- Azure Docs chính thức: Autoscale App Service & Scale out rules (xác nhận Rules Based cho metric scaling ở Standard tier).
- Azure Portal Guide: Truy cập App Service Plan > Scaling > Scale out > Chọn "Rules-based" và add CPU rule.
- Cập nhật 2024-2026: Không thay đổi core mechanism; thêm hỗ trợ serverless ở Premium v3/v4 nhưng Standard vẫn rules-based 🛠️.
Nếu cần demo CLI/PowerShell hoặc cấu hình cụ thể, hãy cho tôi biết nhé! 🚀
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study -
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview -
ADatum Corporation is consulting firm that has a main office in Montreal and branch offices in Seattle and New York.
Existing Environment -
Azure Environment -
ADatum has an Azure subscription that contains three resource groups named RG1, RG2, and RG3.
The subscription contains the storage accounts shown in the following table.
The subscription contains the virtual machines shown in the following table.
The subscription has an Azure container registry that contains the images shown in the following table.
The subscription contains the resources shown in the following table.
Azure Key Vault -
The subscription contains an Azure key vault named Vault1.
Vault1 contains the certificates shown in the following table.
Vault1 contains the keys shown in the following table.
Microsoft Entra Environment -
ADatum has a Microsoft Entra tenant named adatum.com that is linked to the Azure subscription and contains the users shown in the following table.
The tenant contains the groups shown in the following table.
The adatum.com tenant has a custom security attribute named Attribute1.
Planned Changes -
ADatum plans to implement the following changes:
•Configure a data collection rule (DCR) named DCR1 to collect only system events that have an event ID of 4648 from VM2 and VM4.
•In storage1, create a new container named cont2 that has the following access policies: oThree stored access policies named Stored1, Stored2, and Stored3 oA legal hold for immutable blob storage
•Whenever possible, use directories to organize storage account content.
•Grant User1 the permissions required to link Zone1 to VNet1.
•Assign Attribute1 to supported adatum.com resources.
•In storage2, create an encryption scope named Scope1.
•Deploy new containers by using Image1 or Image2.
Technical Requirements -
ADatum must meet the following technical requirements:
•Use TLS for WebApp1.
•Follow the principle of least privilege.
•Grant permissions at the required scope only.
•Ensure that Scope1 is used to encrypt storage services.
•Use Azure Backup to back up cont1 and share1 as frequently as possible.
•Whenever possible, use Azure Disk Encryption and a key encryption key (KEK) to encrypt the virtual machines.
You need to configure WebApp1 to meet the technical requirements.
Which certificate can you use from Vault1?
- A Cert1 only
- B Cert1 or Cert2 only
- C Cert1 or Cert3 only
- D Cert3 or Cert4 only
- E Cert1, Cert2 Cert3, or Cert4
Xem giải thích
🧩 Phân tích chi tiết nội dung câu hỏi
📖 Tóm tắt case study:
ADatum Corporation có môi trường Azure với subscription chứa các resource groups (RG1, RG2, RG3), storage accounts (storage1: StorageV2, West US, hierarchical namespace = Yes, cont1/share1; storage2: StorageV2, West US, hierarchical = No, cont2/share2), VMs (VM1: A/RHEL/ephemeral OS; VM2: D/Win2022/basic volume; VM3: B/RHEL/standard SSD; VM4: M/Win2022/Write Accelerator; VM5: E/Win2022/dynamic volume), Azure Container Registry (Image1: Windows Server; Image2: Linux), resources khác (WebApp1 ở RG1 - là Azure App Service; VNet1 ở RG2; zone1.com Private DNS Zone ở RG3), Key Vault Vault1 với certs (Cert1: PKCS#12/RSA/2048; Cert2: PKCS#12/RSA/2048; Cert3: PEM/RSA/2048; Cert4: PEM/RSA/2048) và keys (Key1: RSA/4096; Key2: EC/P-256), Microsoft Entra (users: Admin1/Global Admin; Admin2/Attribute Def Admin; Admin3/Attribute Assignment Admin; User1/Reader RG2-RG3; groups: Group1 Security; Group2 M365).
🎯 Yêu cầu câu hỏi:
Cần cấu hình WebApp1 (Azure App Service) để đáp ứng technical requirements: "Use TLS for WebApp1" (sử dụng TLS/HTTPS). Câu hỏi hỏi certificate nào từ Vault1 có thể sử dụng để enable TLS trên WebApp1.
- WebApp1 nằm ở RG1, là dịch vụ web app cần certificate từ Key Vault để bind SSL/TLS (custom domain HTTPS).
- Theo nguyên tắc least privilege và scope chỉ khi cần, nhưng trọng tâm là certificate phải phù hợp để App Service tham chiếu từ Key Vault.
🛠️ Kiến thức cốt lõi (cập nhật Azure 2026):
Để enable TLS trên Azure App Service từ Key Vault:
- Certificate phải chứa private key (để server decrypt TLS traffic).
- Định dạng PKCS#12 (.pfx): Bao gồm cert + private key (import từ file PFX).
- Định dạng PEM/CER: Chỉ public certificate (không private key), chỉ dùng cho public cert validation hoặc client auth, KHÔNG dùng cho TLS server binding.
- Key type RSA/2048 hoặc lớn hơn đều hỗ trợ TLS 1.2+ (không giới hạn EC cho certs ở đây).
- App Service hỗ trợ reference cert từ KV qua managed identity (least privilege).
✅ Đáp án đúng: Cert1 or Cert2 only
Lý do lựa chọn (chi tiết):
🛡️ Cert1 và Cert2 đều là định dạng PKCS#12 (RSA/2048), chứa private key đầy đủ, phù hợp để App Service bind TLS/SSL từ Key Vault (upload/bind custom TLS certificate).
- Azure App Service cho phép reference cert từ KV chỉ khi cert có private key (PKCS#12).
- Không phụ thuộc key size (2048 ok cho TLS 1.3), location, hoặc các req khác.
- Đáp ứng "Use TLS for WebApp1" + least privilege (KV access via RBAC).
❌ Cert3/Cert4 (PEM) thiếu private key, không dùng được cho server TLS.
📋 Giải thích tất cả các phương án
-
❌ Cert1 only
Sai vì bỏ sót Cert2 cũng là PKCS#12/RSA/2048, có private key đầy đủ và tương đương Cert1 để enable TLS trên WebApp1. Không có lý do loại trừ Cert2 (cùng format/key spec). -
✅ Cert1 or Cert2 only
Đúng hoàn toàn! Chỉ 2 cert này (PKCS#12) chứa private key cần thiết cho App Service TLS binding từ Vault1. PEM không hỗ trợ server-side TLS decryption. -
❌ Cert1 or Cert3 only
Sai vì Cert3 (PEM/RSA/2048) chỉ là public cert, thiếu private key. App Service không thể dùng PEM từ KV cho TLS/HTTPS binding (chỉ public validation). -
❌ Cert3 or Cert4 only
Sai toàn bộ! Cả Cert3 và Cert4 đều PEM/RSA (Cert4 có thể 4096 nhưng vẫn PEM), không chứa private key, không dùng cho TLS server trên WebApp1. -
❌ Cert1, Cert2, Cert3, or Cert4
Sai vì bao gồm Cert3/Cert4 (PEM) không hợp lệ cho TLS. Chỉ PKCS#12 mới đáp ứng req, tránh over-permission.
📘 Tài liệu tham khảo (Azure docs cập nhật 2026)
- Azure App Service SSL/TLS certs from Key Vault ✅ (Yêu cầu private key certs PKCS#12).
- Key Vault certificate formats 🛡️ (PKCS#12 vs PEM).
- AZ-104 exam reference (case study tương tự) 📚.
- Không thay đổi lớn đến 2026 (TLS 1.3 enforced, nhưng format cert giữ nguyên).
💡 Lời khuyên từ Azure Admin: Sử dụng managed identity cho WebApp1 access Vault1 (Contributor on cert), enable HTTPS Only + Custom TLS binding!
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure virtual machine named VM1. VM1 was deployed by using a custom Azure Resource Manager template named ARM1.json.
You receive a notification that VM1 will be affected by maintenance.
You need to move VM1 to a different host immediately.
Solution: From the resource group blade, move VM1 to another subscription.
Does this meet the goal?
- A Yes
- B No
Xem giải thích
🧩 Giải thích nội dung câu hỏi
Câu hỏi thuộc dạng series questions trong kỳ thi chứng chỉ (như AZ-104 Microsoft Azure Administrator), nơi mỗi câu hỏi trình bày cùng một tình huống nhưng đề xuất giải pháp khác nhau. Tình huống cụ thể:
Bạn có một máy ảo Azure tên VM1, được triển khai bằng template Azure Resource Manager (ARM) tên ARM1.json. Bạn nhận thông báo rằng VM1 sắp bị ảnh hưởng bởi bảo trì (maintenance) từ Azure (thường là bảo trì phần cứng host).
Mục tiêu: Di chuyển VM1 sang một host khác ngay lập tức (immediately) để tránh gián đoạn.
Giải pháp đề xuất: Từ blade resource group, di chuyển VM1 sang một subscription khác.
Câu hỏi: Giải pháp này có đạt mục tiêu không? (Yes/No).
📘 Lưu ý: Đây là câu hỏi kiểu "Does this meet the goal?", yêu cầu đánh giá xem giải pháp có giải quyết vấn đề ngay lập tức không. Kiến thức dựa trên Azure cập nhật đến 2026: Azure hỗ trợ live migration tự động cho maintenance, nhưng nếu cần can thiệp thủ công, phải dùng tính năng chuyên biệt như Migrate to new host hoặc Redeploy.
✅ Đáp án đúng: No
Lý do chọn đáp án đúng 🛠️:
Giải pháp move VM sang subscription khác KHÔNG đạt mục tiêu vì:
- Việc di chuyển resource giữa các subscription là quy trình không ngay lập tức (có thể mất vài phút đến hàng giờ, tùy độ phức tạp VM và validation).
- Nó không đảm bảo VM được di chuyển sang host vật lý khác; VM vẫn có thể ở cùng cluster/datacenter và bị ảnh hưởng maintenance.
- Move subscription chỉ thay đổi ownership/quản lý tài nguyên, không phải physical host migration. Azure sẽ validate dependencies (như VNet, storage) trước khi cho phép, và VM có thể downtime ngắn.
- Cách đúng cho maintenance: Sử dụng Azure Portal > VM > Operations > Migrate to a new host (live migration không downtime) hoặc Redeploy (có thể có downtime ngắn). Đây là tính năng dành riêng cho host maintenance (cập nhật Azure 2024-2026).
📋 Giải thích tất cả các phương án
-
Yes ❌ SAI: Phương án này sai vì move subscription không phải là hành động để "move to different host immediately". Nó không giải quyết maintenance host (physical server), mà chỉ thay đổi billing/ownership. Quá trình có validation nghiêm ngặt (VM phải detached từ Load Balancer/ASG, storage phải compatible), và không có SLA "immediately" (có thể fail nếu cross-region). Không phù hợp với yêu cầu ngay lập tức.
-
No ✅ ĐÚNG: Phương án này đúng vì giải pháp đề xuất KHÔNG đáp ứng mục tiêu. Nó không trigger live migration host, VM vẫn có nguy cơ downtime maintenance. Azure docs khuyến cáo dùng VM resilience features như Availability Zones/VMSS cho high availability, hoặc Migrate host cụ thể (không phải move subscription).
📚 Tài liệu tham khảo
- Azure Docs: Move Azure resources to new resource group or subscription (cập nhật 2025: Xác nhận không dành cho host migration).
- Azure Docs: Maintenance for virtual machines (2026: Khuyến nghị "Migrate to a new host" cho immediate action).
- Azure Portal: VM Operations - Migrate host (tính năng live migration không downtime).
🛡️ Lời khuyên: Trong thực tế admin Azure, luôn kiểm tra Host Maintenance Status qua Azure Monitor trước khi hành động!
You need to ensure that Bastion1 can support 100 concurrent SSH users. The solution must minimize administrative effort.
What should you do first?
- A Resize the subnet of Bastion1
- B Configure host scaling.
- C Create a network security group (NSG)
- D Upgrade Bastion1 to the Standard SKU
Xem giải thích
🧩 Phân tích chi tiết nội dung câu hỏi
Câu hỏi yêu cầu đảm bảo rằng Bastion1 (một dịch vụ Azure Bastion host) có thể hỗ trợ 100 người dùng SSH đồng thời (concurrent SSH users), đồng thời giảm thiểu nỗ lực quản trị (minimize administrative effort). Đây là tình huống thực tế trong Azure, nơi Azure Bastion cung cấp kết nối SSH/RDP an toàn vào VM mà không cần IP public.
Bối cảnh chính từ câu hỏi và hình ảnh:
- Có 10 VM trong subscription.
- Hình ảnh (bảng tài nguyên):
- VNET1: Virtual Network (không có mô tả đặc biệt).
- Bastion1: Basic SKU Azure Bastion host, nằm trong subnet size /26 (tức là subnet có 64 địa chỉ IP khả dụng, phù hợp cho Bastion).
- Vấn đề cốt lõi: Basic SKU chỉ hỗ trợ tối đa 5 kết nối đồng thời (SSH/RDP), không đủ cho 100 users. Cần nâng cấp để scale up sessions.
Mục tiêu: Thực hiện bước đầu tiên (what should you do first) để đạt yêu cầu, ưu tiên ít nỗ lực nhất.
📸 Phân tích hình ảnh (bảng tài nguyên)
Hình ảnh là bảng liệt kê: | Name | Type | Description | |--------|-----------------------|-------------------------| | VNET1 | Virtual network | none | | Bastion1 | Basic SKU Azure Bastion host | Subnet size /26 |
✅ Bastion1 đang dùng Basic SKU (giới hạn sessions thấp).
✅ Subnet /26 đã đạt yêu cầu tối thiểu cho Bastion (theo docs Azure).
❌ Không có NSG hoặc scaling hiện tại.
✅ Đáp án đúng: Upgrade Bastion1 to the Standard SKU
Lý do lựa chọn (theo phiên bản Azure Bastion mới nhất 2026):
- Basic SKU: Chỉ hỗ trợ 5 concurrent sessions (SSH/RDP), không scale. Không đáp ứng 100 users.
- Standard SKU (cập nhật mới nhất): Hỗ trợ scale-up đến 300 concurrent sessions, host scaling (tự động scale số host), và native client cho SSH. Subnet /26 đã đủ (tối thiểu /26 cho Standard).
- Đây là bước đầu tiên và ít nỗ lực nhất 🛠️: Chỉ cần upgrade SKU qua portal/CLI, Bastion tự động hỗ trợ 100+ users mà không cần resize subnet hay config thêm. Sau upgrade, có thể enable host scaling nếu cần.
- Minimize effort: Không cần tạo resource mới, chỉ modify existing Bastion.
Dẫn nguồn:
- Azure Bastion SKUs (cập nhật 2025-2026: Standard hỗ trợ 300 sessions, host groups up to 1000).
- Bastion limits/quotas (/26 subnet required for Standard).
❌ Giải thích tất cả các phương án (đúng/sai)
-
Resize the subnet of Bastion1
❌ Sai: Subnet hiện tại /26 đã đủ (tối thiểu /26 cho Standard SKU). Resize không giải quyết vấn đề concurrent users (vẫn kẹt ở Basic SKU limit 5 sessions). Chỉ cần nếu subnet nhỏ hơn /26, nhưng ở đây không phải. Thêm effort không cần thiết. -
Configure host scaling
❌ Sai: Host scaling chỉ khả dụng sau khi upgrade sang Standard SKU. Basic SKU không hỗ trợ. Đây không phải bước đầu tiên, và sẽ fail nếu config trên Basic. -
Create a network security group (NSG)
❌ Sai: NSG kiểm soát traffic inbound/outbound, không ảnh hưởng đến concurrent sessions limit của Bastion (là quota SKU-based). Bastion đã có security built-in, NSG không giúp scale users. -
Upgrade Bastion1 to the Standard SKU
✅ Đúng: Như giải thích trên, đây là bước first & optimal để unlock 100+ sessions với effort thấp nhất 🏆.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure virtual machine named VM1. VM1 was deployed by using a custom Azure Resource Manager template named ARM1.json.
You receive a notification that VM1 will be affected by maintenance.
You need to move VM1 to a different host immediately.
Solution: From the VM1 Redeploy + reapply blade, you select Redeploy.
Does this meet the goal?
- A Yes
- B No
Xem giải thích
🧩 Phân tích chi tiết câu hỏi trắc nghiệm
📘 Nội dung câu hỏi:
Câu hỏi này thuộc dạng series (chuỗi câu hỏi) với cùng một kịch bản, mỗi câu đưa ra giải pháp riêng để kiểm tra xem có đạt mục tiêu hay không. Kịch bản cụ thể:
- Bạn có một máy ảo Azure tên VM1, được triển khai bằng template Azure Resource Manager (ARM) tùy chỉnh tên ARM1.json.
- Bạn nhận thông báo rằng VM1 sẽ bị ảnh hưởng bởi bảo trì (maintenance) từ Azure (thường là bảo trì phần cứng định kỳ).
- Mục tiêu: Di chuyển VM1 ngay lập tức sang một host phần cứng khác để tránh gián đoạn.
- Giải pháp đề xuất: Từ blade Redeploy + reapply của VM1, chọn Redeploy.
Câu hỏi: Giải pháp này có đạt mục tiêu không? (Yes/No).
🛠️ Lưu ý quan trọng: Đây là tình huống bảo trì planned maintenance trên Azure VM, nơi Azure thông báo trước để admin hành động. Redeploy là tính năng chính thức giúp di chuyển VM sang hardware mới ngay lập tức, chỉ gây downtime ngắn (vài phút để stop/start và migrate).
✅ Đáp án đúng: Yes
Lý do lựa chọn: Giải pháp Redeploy chính xác đạt mục tiêu vì nó di chuyển VM1 sang host phần cứng khác ngay lập tức, tránh maintenance event. Theo tài liệu Azure mới nhất (cập nhật đến 2024-2026), Redeploy là phương pháp khuyến nghị cho trường hợp này, chỉ downtime ~5-15 phút, không yêu cầu thay đổi cấu hình lớn. VM được stop tạm thời, migrate sang node mới, rồi start lại – hoàn hảo cho "immediately".
🔍 Giải thích tất cả các phương án (giữ nguyên văn bản gốc bằng tiếng Anh)
-
Yes ✅
Giải thích đúng: Phương án này đúng vì tính năng Redeploy trong Azure Portal (blade Redeploy + reapply) được thiết kế chuyên biệt để xử lý maintenance hardware. Nó tự động: (1) Stop VM, (2) Di chuyển sang host mới trong cùng availability set/zone, (3) Start lại VM mà giữ nguyên public IP, disk, network. Không ảnh hưởng template ARM gốc. Áp dụng cho VM trên Azure Compute mới nhất (Gen2, confidential VM).
📘 Nguồn: Azure Docs - Planned maintenance for virtual machines & Redeploy and reapply features (cập nhật 2024, vẫn áp dụng 2026). -
No ❌
Giải thích sai: Phương án này sai vì Redeploy không phải là hành động chậm chạp hay không hiệu quả. Nó là giải pháp "immediate" chính thức từ Microsoft, khác với các option như chờ auto-healing (chậm hơn) hoặc migrate manual (phức tạp). Nếu chọn No, bạn bỏ lỡ tính năng core của Azure VM management, dẫn đến downtime dài hơn trong maintenance window. Không có thay đổi nào đến 2026 làm Redeploy kém hiệu quả.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure virtual machine named VM1. VM1 was deployed by using a custom Azure Resource Manager template named ARM1.json.
You receive a notification that VM1 will be affected by maintenance.
You need to move VM1 to a different host immediately.
Solution: From the VM1 Updates blade, select One-time update.
Does this meet the goal?
- A Yes
- B No
Xem giải thích
🧩 Phân tích chi tiết nội dung câu hỏi
Câu hỏi thuộc dạng series questions trong kỳ thi chứng chỉ (có thể là AZ-104 hoặc tương tự), nơi mỗi câu đưa ra một tình huống giống nhau nhưng giải pháp khác nhau. Tình huống cụ thể:
- Bạn có một máy ảo Azure tên VM1, được triển khai bằng template Azure Resource Manager (ARM) tùy chỉnh tên ARM1.json.
- Bạn nhận thông báo rằng VM1 sắp bị ảnh hưởng bởi hoạt động bảo trì (maintenance) từ Azure (thường là planned maintenance để cập nhật host hardware).
- Mục tiêu: Di chuyển VM1 sang một host khác ngay lập tức (move to a different host immediately) để tránh gián đoạn.
Giải pháp đề xuất (Solution): Từ blade VM1 Updates (trong Azure Portal), chọn One-time update.
Câu hỏi chính: Giải pháp này có đạt được mục tiêu không? (Does this meet the goal?)
📘 Lưu ý từ câu hỏi gốc: Sau khi trả lời, không thể quay lại, và một số bộ câu có thể có >1 đáp án đúng hoặc không có đáp án đúng nào.
✅ Đáp án đúng: No
Lý do lựa chọn đáp án đúng 🛠️:
- Giải pháp "From the VM1 Updates blade, select One-time update" KHÔNG đạt mục tiêu vì blade Updates (Azure Update Manager) chỉ dùng để quản lý và áp dụng các bản cập nhật phần mềm (như Windows Updates, security patches) cho VM, không liên quan đến việc di chuyển VM sang host vật lý khác.
- Để di chuyển VM sang host khác ngay lập tức khi có maintenance, cần sử dụng tính năng "Migrate" hoặc "Redeploy" từ blade Overview hoặc Maintenance status của VM trong Azure Portal (tính năng này được cập nhật trong Azure Resilience và VM Scale Sets đến năm 2026, hỗ trợ live migration mà không downtime cho một số workload).
- Giải pháp này chỉ trigger một lần cập nhật phần mềm, có thể gây restart VM nhưng KHÔNG đảm bảo di chuyển host, và không giải quyết planned maintenance.
📋 Giải thích tất cả các phương án
-
Yes ❌
Sai vì chọn "One-time update" từ Updates blade chỉ áp dụng bản cập nhật phần mềm một lần (như patch OS), không có chức năng di chuyển VM sang host khác. Điều này không đáp ứng yêu cầu "move VM1 to a different host immediately" và có thể làm tình hình tệ hơn nếu update gây restart trong lúc maintenance. (Không liên quan đến host migration theo docs Azure Update Manager 2026). -
No ✅
Đúng vì giải pháp đề xuất không đạt mục tiêu. Updates blade không hỗ trợ live migration hoặc redeploy host. Thay vào đó, cần dùng VM Migration từ Portal (Support > Redeploy) hoặc PowerShell (Restart-AzVM -Redeploy), được khuyến nghị cho planned maintenance (Azure cập nhật tính năng này trong Availability Zones và Ultra Disks đến 2026).
📚 Tài liệu tham khảo (cập nhật mới nhất đến 2026)
- Azure Virtual Machines Planned Maintenance ✅ (Hướng dẫn migrate/redeploy VM).
- Azure Update Manager Overview ❌ (Chỉ updates, không migration).
- Azure VM Redeploy and Reimage 🛠️ (Giải pháp đúng thay thế).
- Microsoft Docs AZ-104 Exam Guide (2026 edition): Xác nhận pattern series questions về VM maintenance.
Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần giải thích thêm series questions khác, hãy cho biết.
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study -
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview -
ADatum Corporation is consulting firm that has a main office in Montreal and branch offices in Seattle and New York.
Existing Environment -
Azure Environment -
ADatum has an Azure subscription that contains three resource groups named RG1, RG2, and RG3.
The subscription contains the storage accounts shown in the following table.
The subscription contains the virtual machines shown in the following table.
The subscription has an Azure container registry that contains the images shown in the following table.
The subscription contains the resources shown in the following table.
Azure Key Vault -
The subscription contains an Azure key vault named Vault1.
Vault1 contains the certificates shown in the following table.
Vault1 contains the keys shown in the following table.
Microsoft Entra Environment -
ADatum has a Microsoft Entra tenant named adatum.com that is linked to the Azure subscription and contains the users shown in the following table.
The tenant contains the groups shown in the following table.
The adatum.com tenant has a custom security attribute named Attribute1.
Planned Changes -
ADatum plans to implement the following changes:
•Configure a data collection rule (DCR) named DCR1 to collect only system events that have an event ID of 4648 from VM2 and VM4.
•In storage1, create a new container named cont2 that has the following access policies: oThree stored access policies named Stored1, Stored2, and Stored3 oA legal hold for immutable blob storage
•Whenever possible, use directories to organize storage account content.
•Grant User1 the permissions required to link Zone1 to VNet1.
•Assign Attribute1 to supported adatum.com resources.
•In storage2, create an encryption scope named Scope1.
•Deploy new containers by using Image1 or Image2.
Technical Requirements -
ADatum must meet the following technical requirements:
•Use TLS for WebApp1.
•Follow the principle of least privilege.
•Grant permissions at the required scope only.
•Ensure that Scope1 is used to encrypt storage services.
•Use Azure Backup to back up cont1 and share1 as frequently as possible.
•Whenever possible, use Azure Disk Encryption and a key encryption key (KEK) to encrypt the virtual machines.
You need to meet the technical requirements for the KEK.
Which PowerShell cmdlet and key should you use?
- A Set-AzVMDiskEncryptionExtension and Key2.
- B Set-AzDiskEncryptionKey and Key2.
- C Set-AzDiskDiskEncryptionKey and Key1.
- D Set-AzVMDiskEncryptionExtension and Key1.
Xem giải thích
🧩 Phân tích chi tiết nội dung câu hỏi
Câu hỏi thuộc phần case study của kỳ thi AZ-104 (Microsoft Azure Administrator), mô tả môi trường Azure của công ty ADatum với các tài nguyên như subscription chứa 3 resource groups (RG1, RG2, RG3), storage accounts (storage1 và storage2), VMs (VM1 đến VM5), Azure Container Registry với Image1 (Windows Server) và Image2 (Linux), các resources khác (WebApp1, VNet1, zone1.com), Azure Key Vault (Vault1) chứa certificates (Cert1-4) và keys (Key1: RSA 4096-bit, Key2: EC P-256), Microsoft Entra tenant (adatum.com) với users (Admin1-3, User1) và groups (Group1 Security, Group2 M365).
Yêu cầu kỹ thuật liên quan (Technical Requirements):
✅ "Whenever possible, use Azure Disk Encryption and a key encryption key (KEK) to encrypt the virtual machines."
→ Nghĩa là cần áp dụng Azure Disk Encryption (ADE) cho các VM càng nhiều càng tốt, sử dụng KEK (Key Encryption Key) từ Key Vault để mã hóa BitLocker (Windows) hoặc dm-crypt (Linux) trên OS/data disks.
Câu hỏi tập trung vào cmdlet PowerShell và key phù hợp để đáp ứng yêu cầu KEK. Dựa trên hình ảnh:
- VMs đa dạng OS (RHEL/Linux và Windows Server 2022), kích thước A-E, đặc điểm đặc biệt (ephemeral OS, basic volume, standard SSD, Write Accelerator, dynamic volume). ADE áp dụng được cho hầu hết VMs (trừ ephemeral OS disks ở VM1).
- Vault1 có Key1 (RSA 4096-bit, hỗ trợ KEK) và Key2 (EC P-256, không hỗ trợ).
📘 Dẫn nguồn:
- Azure Disk Encryption Overview (cập nhật 2024-2026): KEK phải là RSA key (≥2048-bit, software hoặc HSM-backed); EC keys không hỗ trợ.
- Set-AzVMDiskEncryptionExtension PowerShell (Az.Compute module, v12+): Cmdlet chính để enable ADE với KEK từ Key Vault.
- Azure Key Vault Keys Requirements.
✅ Đáp án đúng và lý do lựa chọn
Đáp án đúng: Set-AzVMDiskEncryptionExtension and Key1.
🛠️ Lý do chi tiết:
- Set-AzVMDiskEncryptionExtension là cmdlet chuẩn (Az PowerShell module) để enable ADE trên VM, chỉ định Key Vault URI, Key URL cho KEK, và Key Encryption Algorithm (RSA-OAEP). Nó mã hóa toàn bộ VM (OS/data disks) sử dụng KEK để bảo vệ BEK (BitLocker Encryption Key).
- Key1 (RSA 4096-bit) đáp ứng yêu cầu KEK: RSA ≥2048-bit, tương thích ADE (Windows/Linux).
- Tuân thủ principle of least privilege và "grant permissions at required scope" (technical reqs). Áp dụng cho VMs khả dụng (VM2-5), ưu tiên KEK từ Vault1. Không thay đổi đến 2026 (ADE v2.2+ hỗ trợ Gen2 VMs).
📋 Giải thích tất cả các phương án
🧩 Phân tích từng lựa chọn (giữ nguyên text gốc, giải thích bằng tiếng Việt):
-
❌ Set-AzVMDiskEncryptionExtension and Key2
Sai vì Key2 là EC (Elliptic Curve P-256), không hỗ trợ làm KEK trong ADE (chỉ RSA ≥2048-bit). Cmdlet đúng nhưng key sai → Không mã hóa được VM, vi phạm req "use KEK". -
❌ Set-AzDiskEncryptionKey and Key2
Sai hoàn toàn: Set-AzDiskEncryptionKey không tồn tại trong Az PowerShell (lỗi tên cmdlet). Key2 cũng không hợp lệ. Không dùng được cho ADE trên VM. -
❌ Set-AzDiskDiskEncryptionKey and Key1
Sai vì Set-AzDiskDiskEncryptionKey không tồn tại (tên sai, có lẽ nhầm lẫn). Key1 đúng nhưng cmdlet giả → Không enable ADE. -
✅ Set-AzVMDiskEncryptionExtension and Key1
Đúng 100%: Cmdlet chuẩn enable ADE với KEK=Key1 (RSA 4096-bit từ Vault1), mã hóa VMs (VM2-VM5 khả thi nhất). Đáp ứng "whenever possible" và least privilege (Key Vault access policy cần Key Vault Crypto Officer role).
🔍 Lưu ý bổ sung: Không ảnh hưởng bởi storage/images/users vì focus KEK cho VM encryption. Sử dụng Set-AzVMDiskEncryptionExtension -ResourceGroupName <RG> -VMName <VM> -KeyEncryptionKeyUrl <Key1-URL> -KeyEncryptionKeyVaultId <Vault1-ID> -KeyEncryptionAlgorithm 'RSA-OAEP'.
You plan to deploy an Azure Bastion Basic SKU host named Bastion1.
Which IP addresses can you use?
- A IP1 only
- B IP1 and IP2 only
- C IP3, IP4, and IP5 only
- D IP1, IP2, IP4, and IP5 only
- E IP1, IP2, IP3, IP4, and IP5
Xem giải thích
🧩 Phân tích chi tiết câu hỏi trắc nghiệm về Azure Bastion
📘 Nội dung câu hỏi được giải thích rõ ràng:
Câu hỏi mô tả một subscription Azure chứa các public IP addresses được liệt kê trong bảng hình ảnh. Bảng bao gồm 5 IP với các thuộc tính:
- IP1: IPv4, Standard SKU, Regional Tier, Static assignment.
- IP2: IPv4, Standard SKU, Global Tier, Static assignment.
- IP3: IPv4, Basic SKU, Regional Tier, Dynamic assignment.
- IP4: IPv4, Basic SKU, Regional Tier, Static assignment.
- IP5: IPv6, Basic SKU, Regional Tier, Dynamic assignment.
Bạn đang lập kế hoạch triển khai Azure Bastion host với Basic SKU, tên Bastion1. Câu hỏi yêu cầu xác định các IP nào có thể sử dụng làm public IP cho Bastion.
🛠️ Yêu cầu kỹ thuật cho Public IP của Azure Bastion (cập nhật đến 2026):
Azure Bastion Basic SKU yêu cầu public IP phải đáp ứng tất cả các điều kiện sau (theo tài liệu Microsoft Azure mới nhất):
- SKU: Standard (không hỗ trợ Basic SKU).
- Tier: Regional (không hỗ trợ Global Tier).
- Assignment: Static (không hỗ trợ Dynamic).
- IP version: IPv4 (không hỗ trợ IPv6).
Bastion sử dụng public IP này để expose dịch vụ RDP/SSH an toàn qua portal Azure hoặc native client. Nếu không khớp, việc assign IP sẽ thất bại.
✅ Đáp án đúng: IP1 only
Lý do lựa chọn: Chỉ IP1 thỏa mãn toàn bộ yêu cầu: IPv4 + Standard SKU + Regional Tier + Static. Các IP khác thiếu ít nhất một điều kiện, nên không thể sử dụng cho Bastion Basic SKU.
❌ Phân tích tất cả các phương án (giữ nguyên nội dung gốc bằng tiếng Anh):
-
IP1 only ✅
Giải thích đúng: IP1 hoàn hảo khớp yêu cầu (IPv4, Standard SKU, Regional Tier, Static). Đây là lựa chọn duy nhất có thể assign thành công cho Bastion Basic SKU mà không gặp lỗi. -
IP1 and IP2 only ❌
Giải thích sai: IP2 có Standard SKU và Static nhưng dùng Global Tier – Bastion không hỗ trợ Global Tier (chỉ Regional). Global Tier dành cho các dịch vụ toàn cầu như Azure Front Door, không tương thích với Bastion. -
IP3, IP4, and IP5 only ❌
Giải thích sai:- IP3: Basic SKU + Dynamic → Cả hai đều không hỗ trợ.
- IP4: Basic SKU → Không hỗ trợ (Bastion yêu cầu Standard).
- IP5: IPv6 + Basic SKU + Dynamic → Không hỗ trợ IPv6 và các thuộc tính khác.
-
IP1, IP2, IP4, and IP5 only ❌
Giải thích sai: Bao gồm IP1 (đúng) nhưng lẫn IP2 (Global Tier sai), IP4 (Basic SKU sai), IP5 (IPv6 + Dynamic sai). Chỉ IP1 đúng, các IP còn lại loại trừ. -
IP1, IP2, IP3, IP4, and IP5 ❌
Giải thích sai: Gồm tất cả IP, nhưng chỉ IP1 đúng; 4 IP còn lại vi phạm ít nhất một yêu cầu (Basic SKU, Global Tier, Dynamic, IPv6).
📚 Tài liệu tham khảo (Microsoft Azure Docs - cập nhật 2026):
- Azure Bastion prerequisites ✅ (Xác nhận yêu cầu Standard SKU, Regional, Static IPv4).
- Public IP address SKUs and tiers 🛠️ (Chi tiết Basic/Standard và Regional/Global).
- AZ-104 exam guide: Bastion deployment labs (ExamTopics & Microsoft Learn).
💡 Lưu ý thực hành: Khi deploy Bastion qua Portal/ARM, hệ thống sẽ validate IP tự động. Nên tạo IP mới Standard/Regional/Static để tránh lỗi! 🚀
Sub1 contains a virtual machine named VM1 and a storage account named storage1.
VM1 is associated to the resources shown in the following table.
You need to move VM1 to Sub2.
Which resources should you move to Sub2?
- A VM1, Disk1, and NetInt1 only
- B VM1, Disk1, and VNet1 only
- C VM1, Disk1, and storage1 only
- D VM1, Disk1, NetInt1, and VNet1
Xem giải thích
🧩 Phân tích nội dung câu hỏi
Câu hỏi này thuộc chủ đề Azure Resource Manager (ARM), cụ thể là quy trình di chuyển tài nguyên (Move resources) giữa các Azure subscriptions.
-
Tình huống: Bạn có hai subscription Sub1 và Sub2. Trong Sub1, có một Virtual Machine (VM) tên VM1 và một storage account tên storage1.
-
Hình ảnh đính kèm (bảng tài nguyên liên kết với VM1): | Tên | Loại | |---------|-------------------------------| | Disk1 | Operating system disk (Ổ đĩa hệ điều hành, là managed disk được gắn trực tiếp vào VM1) | | NetInt1 | Network interface (Network Interface Card - NIC, dùng để kết nối mạng cho VM1) | | VNet1 | Virtual network (Mạng ảo chứa subnet mà NIC NetInt1 được gắn vào) |
📸 Phân tích hình ảnh chi tiết: Bảng này liệt kê chính xác các tài nguyên phụ thuộc trực tiếp vào VM1. Disk1 là OS disk (không phải storage account), NetInt1 là NIC gắn VM với mạng, VNet1 là Virtual Network chứa subnet của NIC. Storage1 không xuất hiện trong bảng, chứng tỏ nó không phải tài nguyên phụ thuộc trực tiếp (có thể là storage cho snapshots hoặc dữ liệu khác, không bắt buộc di chuyển cùng VM).
-
Yêu cầu nhiệm vụ: Di chuyển VM1 sang Sub2. Để thành công, phải di chuyển VM1 + tất cả tài nguyên phụ thuộc (dependencies) để tránh lỗi như mất kết nối mạng, mất disk, hoặc VM không boot được. Quy trình move yêu cầu các tài nguyên phải ở cùng resource group ban đầu và tương thích (không move public IP, NSG độc lập, v.v., nhưng ở đây tập trung vào các item liệt kê).
🛠️ Kiến thức cập nhật Azure (phiên bản 2024-2026): Theo docs Microsoft, để move VM cross-subscription, cần move VM + managed disks + NIC + VNet (nếu NIC phụ thuộc subnet trong VNet đó). Storage account như storage1 không bắt buộc vì không phải dependency trực tiếp của VM (VM dùng managed disks, không phải unmanaged disks từ storage account).
✅ Đáp án đúng và lý do chọn
Đáp án đúng: VM1, Disk1, NetInt1, and VNet1
Lý do chi tiết (✅):
- VM1 là tài nguyên chính cần move.
- Disk1 (OS disk): Managed disk gắn trực tiếp vào VM, phải move cùng để VM boot và truy cập dữ liệu.
- NetInt1 (NIC): Gắn vào VM để kết nối mạng; nếu không move, VM mất IP/private IP sau move.
- VNet1: NIC NetInt1 nằm trong subnet của VNet1; Azure yêu cầu move cả VNet để giữ cấu hình mạng (subnet, address space) nguyên vẹn. Không move VNet sẽ lỗi dependency.
- Kết quả: Move đầy đủ này đảm bảo VM hoạt động ngay sau khi di chuyển sang Sub2 mà không cần reconfigure.
📋 Giải thích tất cả các phương án (đúng/sai)
Dưới đây là phân tích từng lựa chọn dựa trên quy trình Azure Move (Resource.Moves). Giữ nguyên văn bản gốc tiếng Anh, chỉ giải thích bằng tiếng Việt. Sử dụng kiến thức mới nhất từ Azure Portal/CLI/PowerShell (2026 vẫn giữ nguyên logic dependency).
-
❌ [SAI] VM1, Disk1, and NetInt1 only
Giải thích sai: Thiếu VNet1 – NIC (NetInt1) phụ thuộc subnet trong VNet1. Nếu chỉ move 3 cái này, Azure báo lỗi "Network interface depends on virtual network" khi validate move. VM sẽ mất kết nối mạng sau di chuyển. -
❌ [SAI] VM1, Disk1, and VNet1 only
Giải thích sai: Thiếu NetInt1 (NIC). VNet1 chỉ là mạng ảo, nhưng NIC mới là thành phần gắn VM vào subnet của VNet. Không move NIC, VM không có interface mạng, dẫn đến lỗi "Virtual machine depends on network interface". -
❌ [SAI] VM1, Disk1, and storage1 only
Giải thích sai: Storage1 không phải dependency của VM1 (hình ảnh không liệt kê, VM dùng managed Disk1 chứ không phải blob từ storage account). Move storage1 thừa thãi và không giải quyết NIC/VNet. VM sẽ mất mạng và có thể lỗi disk nếu storage1 chỉ là auxiliary. -
✅ [ĐÚNG] VM1, Disk1, NetInt1, and VNet1
Giải thích đúng: Đầy đủ dependencies từ bảng hình ảnh. Move qua Azure Portal (Resource groups > Move > Move to another subscription) hoặc PowerShell (Move-AzResource). Validate thành công 100%, VM giữ nguyên config.
📘 Tài liệu tham khảo (cập nhật 2026)
- Chính thức Microsoft: Move Azure VMs to another subscription ✅ (Chi tiết dependencies: disk, NIC, VNet).
- Tổng quát Move resources: Move resources to a new subscription 🛠️ (Validate dependencies trước move).
- Azure Updates (2024+): Không thay đổi logic VM move; hỗ trợ preview cross-region move từ 2023.
- Thực hành: Sử dụng Azure CLI:
az resource move --ids <id-vm>,<id-disk>,<id-nic>,<id-vnet> --destination-subscription-id <sub2-id>.
Hy vọng phân tích này giúp bạn ôn thi AZ-104 hiệu quả! 🚀 Nếu cần demo PowerShell, hỏi thêm nhé!
You have an Azure load balancer named LB1 that provides load balancing services for the virtual machines.
You need to ensure that visitors are serviced by the same web server for each request.
What should you configure?
- A Session persistence to Client IP
- B Idle Time-out (minutes) to 20
- C Session persistence to None
- D Protocol to UDP
Xem giải thích
🧩 Phân tích chi tiết nội dung câu hỏi
Câu hỏi này thuộc chủ đề Azure Load Balancer trong Microsoft Azure, tập trung vào việc cấu hình session persistence (hay còn gọi là session affinity/sticky sessions).
- Tình huống: Bạn có 5 máy ảo Azure (VMs) chạy Windows Server 2016 được cấu hình làm web servers. Chúng được quản lý bởi một Azure Load Balancer tên LB1 để phân tải (load balancing).
- Yêu cầu chính: Đảm bảo mỗi visitor (người dùng) luôn được phục vụ bởi cùng một web server cho mỗi request của họ. Điều này có nghĩa là các request từ cùng một client phải được "dính" (persist) vào backend server cố định, tránh tình trạng request bị phân tán ngẫu nhiên dẫn đến mất session (ví dụ: giỏ hàng mua sắm bị reset).
- Ngữ cảnh kỹ thuật: Azure Load Balancer (Standard SKU) hỗ trợ session persistence dựa trên Client IP để hash IP nguồn của client và định tuyến nhất quán đến cùng backend pool member. Điều này đặc biệt quan trọng cho ứng dụng web stateful như session-based authentication hoặc shopping carts. (Kiến thức cập nhật đến 2026: Azure Load Balancer v2 vẫn giữ nguyên tính năng này, với cải tiến hỗ trợ IPv6 và zone redundancy).
📘 Tài liệu tham khảo:
- Azure Load Balancer TCP Reset and Idle Timeout (cập nhật 2024).
- Load balancer distribution modes (session persistence options).
✅ Đáp án đúng và lý do lựa chọn
Đáp án đúng: Session persistence to Client IP
Lý do 🛠️:
- Đây là cấu hình chính xác để đạt session persistence dựa trên IP của client. Azure Load Balancer sẽ sử dụng source IP (IPv4/IPv6) của visitor để hash và luôn route request đến cùng một VM backend trong pool. Điều này đảm bảo "sticky sessions" cho mọi request từ client đó, phù hợp hoàn hảo với yêu cầu "serviced by the same web server for each request".
- Không có tùy chọn nào khác trực tiếp giải quyết vấn đề persistence theo client. Tính năng này hoạt động ở Layer 4 (Transport), hỗ trợ TCP/UDP mà không cần Application Gateway (Layer 7).
📋 Giải thích tất cả các phương án (đúng và sai)
Dưới đây là phân tích từng lựa chọn một cách chi tiết. Tôi giữ nguyên nội dung văn bản gốc bằng tiếng Anh, nhưng giải thích hoàn toàn bằng tiếng Việt với lý do đúng/sai rõ ràng:
-
✅ Session persistence to Client IP
Đúng 🏆: Như đã giải thích ở trên, đây là tùy chọn chuẩn của Azure Load Balancer để enable client IP affinity. Khi cấu hình, LB1 sẽ duy trì session cho tất cả request từ cùng IP nguồn, tránh phân tán load ngẫu nhiên (default là hash-based distribution). Hoàn hảo cho web servers stateful. -
❌ Idle Time-out (minutes) to 20
Sai 🚫: Idle Time-out chỉ kiểm soát thời gian TCP connection idle trước khi LB reset (mặc định 4 phút, max 30 phút). Nó không liên quan đến session persistence hay "dính" request vào server cụ thể. Tăng lên 20 phút chỉ giữ connection lâu hơn, nhưng request vẫn có thể route đến VM khác nếu load balance. -
❌ Session persistence to None
Sai ❌: Đây là mặc định (None hoặc Client IP and protocol ở một số mode), nơi LB sử dụng 5-tuple hash (source IP, source port, dest IP, dest port, protocol) để phân tải 5-way hash. Không đảm bảo cùng server cho mọi request từ client (vì source port thay đổi), dẫn đến session bị mất – ngược hoàn toàn yêu cầu. -
❌ Protocol to UDP
Sai 🔒: Chuyển protocol sang UDP chỉ thay đổi từ TCP sang UDP cho load balancing (phù hợp real-time apps như VoIP). Nhưng UDP không hỗ trợ session persistence tốt như TCP vì stateless, và không giải quyết sticky sessions cho web servers (thường dùng HTTP/TCP port 80/443). Web traffic cần TCP để reliable delivery.
Hy vọng phân tích này giúp bạn nắm vững Azure Load Balancer! Nếu cần config thực tế qua Portal/CLI, hãy hỏi thêm nhé 🚀.