Ngân hàng đề — Microsoft Azure Architect Expert

Tìm thấy 100 câu.

Câu 31 Chọn nhiều đáp án Design identity, governance & monitoring solutions (25–30%)

You have been assigned the task of synchronizing Active Directory (AD) and Entra ID. This synchronization will ensure that users can access corporate machines within their corporate network without the need to enter a password.

Which synchronization method(s) would you select to fulfill this requirement? Please select all appropriate options.

  1. A

    PHS (Password Hash Synchronization)

  2. B

    PTA (Pass-Through Authentication)

  3. C

    AD FS (Federation services)

  4. D

    OpenID Connect

Xem giải thích

Đáp án

A và B — PHS (Password Hash Synchronization) và PTA (Pass-Through Authentication)

Vì sao đúng

Đề cần người dùng truy cập được máy trong mạng công ty bằng cùng bộ thông tin đăng nhập, tức là Active Directory tại chỗ vẫn phải là nguồn danh tính. Cả PHS và PTA đều giữ được điều đó, chỉ khác ở chỗ mật khẩu được kiểm ở đâu:

Phương thức Xác thực diễn ra ở Đặc điểm
PHS Trên đám mây, dùng hàm băm của hàm băm mật khẩu Đơn giản nhất, vẫn đăng nhập được khi AD tại chỗ mất kết nối
PTA Chuyển về AD tại chỗ qua agent Mật khẩu không rời khỏi tổ chức dưới bất kỳ dạng nào

Vì sao các phương án khác sai

  • C. AD FS — cũng đạt được mục tiêu nhưng đòi dựng và vận hành cả một hạ tầng liên kết danh tính; Microsoft khuyến nghị dùng PHS hoặc PTA trừ khi có yêu cầu đặc thù.
  • D. OpenID Connect — là giao thức xác thực, không phải phương thức đồng bộ danh tính.
Câu 32 Design identity, governance & monitoring solutions (25–30%)

Your company has a group of Azure Web Apps that use access keys to connect with databases. You are required to transfer the access keys to the Azure Key Vault and ensure that the application authenticates using Entra ID to access the keys.

What do you need to create in Azure to ensure that the application can access the access keys?

  1. A

    Managed Identities

  2. B

    Managed applications

  3. C

    Azure policies

  4. D

    App Service Plan

Xem giải thích

Đáp án

A — Managed Identity

Vì sao đúng

Managed identity giải quyết đúng cái vòng luẩn quẩn của việc quản lý bí mật: nếu ứng dụng cần một thông tin đăng nhập để lấy khoá từ Key Vault, thì thông tin đăng nhập đó lại nằm ở đâu?

Với managed identity, câu trả lời là không ở đâu cả. Azure cấp cho Web App một danh tính do nền tảng quản lý, ứng dụng lấy token từ điểm cuối metadata cục bộ, và bạn cấp cho danh tính đó quyền đọc bí mật trong Key Vault. Không có chuỗi bí mật nào trong mã, trong cấu hình, hay trong biến môi trường — nên không có gì để rò rỉ và không có gì phải xoay vòng.

Vì sao các phương án khác sai

  • C. Azure Policy — có thể bắt buộc ứng dụng phải bật managed identity, nhưng không phải cơ chế xác thực.
  • B. Managed application — mô hình đóng gói giải pháp để phân phối cho khách hàng, không liên quan.
  • D. App Service Plan — quyết định tài nguyên tính toán cho Web App.
Câu 33 Design identity, governance & monitoring solutions (25–30%)

A company plans to deploy a .Net Core-based application onto Azure using Azure Web apps. The application has several requirements, including:

  • Providing the testing team with the ability to view the different components of the application and see the calls being made between them.

  • Allowing businesses to analyze how many users return to the application.

  • Ensuring IT administrators receive alerts when critical conditions are met in the application.

Which Azure service is best suited for fulfilling the requirement:

Providing the testing team with the ability to view the different components of the application and see the calls being made between them.

  1. A

    Application Insights

  2. B

    Azure Service Health

  3. C

    Azure Advisor

  4. D

    Azure Communication Services

Xem giải thích

Đáp án

A — Application Insights

Vì sao đúng

Đề nói tới việc cung cấp cho đội kiểm thử dữ liệu về hành vi và hiệu năng ứng dụng, và đó chính là phạm vi của Application Insights: nó theo dõi thời gian phản hồi từng yêu cầu, tỷ lệ lỗi, lời gọi tới dịch vụ phụ thuộc, ngoại lệ kèm ngăn xếp lời gọi, và cả hành vi người dùng trên giao diện. Với ứng dụng .NET Core trên Azure Web Apps thì việc bật nó gần như không phải sửa mã.

Vì sao các phương án khác sai

  • B. Azure Service Health — thông báo về sự cố của chính Azure, không nói gì về ứng dụng của bạn.
  • C. Azure Advisor — đưa ra khuyến nghị về chi phí và cấu hình.
  • D. Azure Communication Services — dịch vụ nhắn tin, gọi thoại và video cho ứng dụng; hoàn toàn không liên quan.
Câu 34 Design data storage solutions (20–25%)

Which Azure service is best suited for storing semi-structured data in the form of JSON documents with a globally distributed scalable architecture?

  1. A Azure SQL Database
  2. B

    Azure App services

  3. C Azure Cosmos DB
  4. D Azure Table Storage
Xem giải thích

Đáp án

C — Azure Cosmos DB

Vì sao đúng

Ba yêu cầu trong đề đều là đặc điểm định danh của Cosmos DB: tài liệu JSON bán cấu trúc, phân tán toàn cầu, và kiến trúc co giãn. Nó cho nhân bản dữ liệu sang bất kỳ khu vực Azure nào chỉ bằng vài cú bấm, với năm mức nhất quán để bạn chọn điểm cân bằng giữa độ trễ và tính chính xác.

Vì sao các phương án khác sai

  • D. Azure Table Storage — cũng là kho NoSQL và rẻ hơn nhiều, nhưng dùng mô hình khoá–giá trị đơn giản; nó không truy vấn được sâu vào cấu trúc lồng nhau của tài liệu JSON, và không có phân tán toàn cầu ở mức như Cosmos DB. Đây là phương án nhiễu gần nhất.
  • A. Azure SQL Database — cơ sở dữ liệu quan hệ; lưu được JSON trong cột nhưng đó không phải mô hình dữ liệu tự nhiên của nó.
  • B. Azure App Services — nền tảng chạy ứng dụng, không phải kho dữ liệu.
Câu 35 Design identity, governance & monitoring solutions (25–30%)

Your company has an existing Azure tenant and subscription. It has more than 10,000 licensed users and 50 mission-critical applications. It is looking to enhance its endpoint threat detection and remediation capabilities.

What would you suggest a solution that could meet this requirement?

  1. A

    Entra ID authentication

  2. B

    Entra Connect

  3. C

    Azure Active Directory Federation Services

  4. D

    Entra ID Protection

Xem giải thích

Đáp án

D — Entra ID Protection

Vì sao đúng

Identity Protection dùng tín hiệu và học máy trên quy mô toàn cầu của Microsoft để chấm mức rủi ro của từng lần đăng nhập và từng người dùng: đăng nhập từ địa điểm bất thường, từ IP ẩn danh, kiểu di chuyển bất khả thi, hoặc thông tin đăng nhập đã xuất hiện trong dữ liệu rò rỉ. Dựa trên điểm rủi ro đó, nó tự động yêu cầu xác thực đa yếu tố, bắt đổi mật khẩu, hoặc chặn hẳn.

Với tổ chức hơn 10.000 người dùng, cách tự động này là lựa chọn duy nhất khả thi — không ai rà tay được ở quy mô đó.

Vì sao các phương án khác sai

  • A. Xác thực Entra ID — là nền tảng đã có sẵn, không phải lớp tăng cường bảo mật thêm.
  • B. Entra Connect — đồng bộ danh tính từ AD tại chỗ.
  • C. AD FS — dịch vụ liên kết danh tính, thế hệ cũ hơn và không có phần chấm điểm rủi ro.
Câu 36 Design data storage solutions (20–25%)

Your task is to architect a data engineering solution for your organization. The organization already possesses an Azure subscription and houses its application data in a Microsoft SQL Server located in its on-premises data center. They wish to fulfill the following criteria:

  • Migrate transactional data from the on-site SQL server to an Azure data warehouse.

  • The data transfer should be automated to occur nightly as a scheduled task.

  • A managed Spark cluster should be established for data engineers to examine the data housed in the SQL data warehouse. In this environment, the data engineers should have the capability to create notebooks in Scala, R, and Python.

  • They require a data lake store to ingest data from a variety of sources.

Which Azure service would you utilize to host the data warehouse?

  1. A

    Azure Data Factory

  2. B

    Azure Databricks

  3. C

    Azure Data Lake Gen2 Storage accounts

  4. D

    Azure Synapse Analytics

Xem giải thích

Đáp án

D — Azure Synapse Analytics

Vì sao đúng

Đề yêu cầu một giải pháp kỹ thuật dữ liệu hoàn chỉnh, và Synapse là nền tảng gộp nhiều mảnh lại trong một không gian làm việc: nạp và điều phối dữ liệu (pipeline dựa trên Data Factory), kho dữ liệu dạng cột với SQL pool, xử lý dữ liệu lớn bằng Spark, và truy vấn không máy chủ trực tiếp trên data lake.

Khi câu hỏi mô tả cả một giải pháp chứ không phải một khâu, câu trả lời là nền tảng gộp chứ không phải một công cụ riêng lẻ.

Vì sao các phương án khác sai

Ba phương án còn lại đều là một mảnh của bức tranh:

  • A. Data Factory — chỉ lo khâu nạp và điều phối.
  • B. Databricks — chỉ lo khâu xử lý và phân tích bằng Spark.
  • C. Data Lake Gen2 — chỉ lo khâu lưu trữ.
Câu 37 Design data storage solutions (20–25%)

Your company is currently hosting an application on-premises that connects to two databases: mydb1 and mydb2.

However, you have decided to move these databases to Azure while ensuring that they support server-side transactions across both.

To achieve this, you plan to deploy the databases to an Azure SQL database-managed instance.

Does this solution meet the requirement?

  1. A

    Yes

  2. B

    No

Xem giải thích

Đáp án

A — Có, giải pháp đáp ứng yêu cầu

Vì sao đúng

Điều kiện quyết định là giao dịch phía máy chủ trải trên hai cơ sở dữ liệu. Azure SQL Managed Instance hỗ trợ truy vấn xuyên cơ sở dữ liệu và giao dịch phân tán giữa các cơ sở dữ liệu trong cùng một instance, nhờ nó giữ được mức tương thích rất cao với SQL Server tại chỗ.

Đây chính là lý do Managed Instance tồn tại: dành cho ứng dụng cũ phụ thuộc vào những tính năng ở mức instance mà Azure SQL Database đơn lẻ không có.

Vì sao phương án còn lại sai

  • B. Không — sẽ đúng nếu giải pháp đề xuất là Azure SQL Database dạng đơn lẻ, vì mỗi cơ sở dữ liệu ở đó là một đơn vị độc lập và không có giao dịch xuyên cơ sở dữ liệu. Khác biệt giữa hai lựa chọn này chính là điểm mà câu hỏi kiểm tra.
Câu 38 Design data storage solutions (20–25%)

Overview

GetCloudSkills is an online training provider. They have several main offices and a couple of branch offices.

Existing Environment

The company currently has the following Active Directory Environment in place.

  • Two Active Directory forests - One is quiz.getcloudskills.com, and the other is research.getcloudskills.com.

  • Currently, there is no relationship of trust between the forests.

  • The quiz.getcloudskills.com is the production forest that hosts all the identities required for internal user and computer authentication.

  • The research.getcloudskills.com forest is only used by the research department.

The company currently has the following Networking Environment in place

  • The offices currently contain at least one domain controller from the quiz.getcloudskills.com forest.

  • The main head office contains the domain controller of the research.getcloudskills.com forest.

  • All of the offices have high-speed internet connections.

Applications

The company has a web application running on-premise named getcloudskills-app.

  • Applications The company has a web application running on-premise named getcloudskills-app.

  • The application is running on Microsoft Internet Information Services.

  • The application stores its data on Microsoft SQL Server 2016.

  • The servers are all running on Hyper-V.

  • The same Hyper-V environment also hosts a staging environment to test all updates to the web application.

  • All Microsoft-based licenses have been purchased via a Microsoft Enterprise.

Planned Changes

  • The company wants to migrate its workloads to Azure.

  • They also want to create a hybrid identity model and a Microsoft Office 365 deployment.

  • The research department will continue to use the infrastructure in the on-premise environment.

Following are the critical requirements for the migration to Azure

  • The Web application "getcloudskills-app" needs to be migrated to Azure.

  • Existing licenses should be used wherever possible to minimize costs.

  • Users need always to authenticate using their quiz.getcloudskills.com UPN identity.

  • All new deployments to Azure must be redundant in the case of an Azure region failure.

  • PaaS deployments are preferred wherever possible.

  • Directory Synchronization must be established between Azure AD and the quiz.getcloudskills.com forest. A link failure between Azure and the on-premise network must not affect this synchronization.

The following requirements need to be met in terms of the database

  • When the database is migrated to Azure, it needs to be ensured that metrics are recorded for the database. The database administrators should be able to analyze the metrics to suggest any further improvements to the database environment

  • Database downtime must be minimized when the database is being migrated onto Azure

  • Database backups must be maintained for five year

The following requirements need to be met in terms of security

  • Administrators should be able to authenticate to Azure by using the quiz.getcloudskills.com credentials

  • Any administrative access to Azure must be complemented by multi-factor authentication

You need to recommend setting up the data store to host the SQL database in Azure.

Which of the following would you recommend?

  1. A

    An Azure SQL database elastic pool

  2. B

    A Virtual machine running a SQL server

  3. C

    A fixed size DTU based Azure SQL database

  4. D

    A vCore-based Azure SQL Database

Xem giải thích

Đáp án

D — Azure SQL Database dựa trên vCore

Vì sao đúng

Các yêu cầu trong tình huống này đều kéo về mô hình vCore:

  • Ghi và phân tích số liệu để tinh chỉnh — vCore cho thấy rõ tài nguyên tính toán và lưu trữ tách bạch, nên việc phân tích và điều chỉnh mới có ý nghĩa.
  • Giữ bản sao lưu trong năm năm — lưu giữ dài hạn cấu hình được ở đây.
  • Giảm thiểu thời gian dừng khi di chuyển — dịch vụ được quản lý, không phải tự dựng.

Ngoài ra vCore cho phép dùng Azure Hybrid Benefit để mang giấy phép SQL Server sẵn có sang, và đặt trước dung lượng để giảm chi phí.

Vì sao các phương án khác sai

  • C. Azure SQL Database theo DTU cố định — DTU gộp tính toán, bộ nhớ và vào ra thành một đơn vị, nên không chỉnh riêng được và khó phân tích để tối ưu.
  • B. Máy ảo chạy SQL Server — quay lại việc tự vá hệ điều hành, tự cấu hình sao lưu và tự lo tính sẵn sàng.
  • A. Elastic pool — hợp khi có nhiều cơ sở dữ liệu dùng chung tài nguyên, không phải cho một cơ sở dữ liệu đơn lẻ.
Câu 39 Design business continuity solutions (15–20%)

To deploy an Azure SQL database named "mydb" for the company, certain security requirements must be met. These requirements include the following:

  • When IT help desk supervisors query a database table called "customers," they should be able to view the complete credit card number.

  • When IT help desk operators query the same database table, they should only be able to see the last four digits of each credit card number.

  • The "Credit Card rating" column in the "customers" table should never appear in plain text within the database system. Only client applications should be able to decrypt the information stored in this column.

Which of the following can be implemented for the IT help desk operator's security requirement?

  1. A

    Row-level security

  2. B

    Azure Advanced Threat Protection

  3. C

    Transparent Data Encryption

  4. D

    Dynamic Data Masking

Xem giải thích

Đáp án

D — Dynamic Data Masking

Vì sao đúng

Đọc kỹ câu hỏi: nó hỏi riêng về yêu cầu của nhân viên hỗ trợ (operator) — người này chỉ được thấy bốn số cuối của số thẻ, trong khi cấp trên của họ thấy đầy đủ.

Đó chính là định nghĩa của Dynamic Data Masking: dữ liệu vẫn nằm nguyên dạng thường trong cơ sở dữ liệu, nhưng khi truy vấn thì được che lại tuỳ theo quyền của người truy vấn. Người có quyền UNMASK thấy đầy đủ, người khác thấy bản đã che. Không phải sửa ứng dụng và không phải mã hoá gì.

Vì sao các phương án khác sai

  • C. Transparent Data Encryption — mã hoá tệp trên đĩa; khi truy vấn thì mọi người đều thấy dữ liệu như nhau, nên không phân biệt được theo vai.
  • A. Row-level security — lọc theo dòng (ai thấy được bản ghi nào), còn ở đây cần che theo cột.
  • B. Advanced Threat Protection — phát hiện hoạt động bất thường, không che dữ liệu.

So sánh với câu cùng tình huống

Có một câu khác dùng chung tình huống này nhưng hỏi về cột "Credit Card rating" với yêu cầu không bao giờ ở dạng văn bản thường trong cơ sở dữ liệu, và đáp án ở đó là Always Encrypted. Điểm phân biệt: masking chỉ đổi cách hiển thị, còn Always Encrypted đổi cách lưu trữ.

Câu 40 Design data storage solutions (20–25%)

Your company has an Azure subscription that includes a blob container. The finance department users need access to the blobs only for the month of March.

What is the appropriate security access solution for this requirement?

  1. A

    Shared Access Signatures

  2. B

    Conditional Access Policies

  3. C

    Certificates

  4. D

    Access Keys

Xem giải thích

Đáp án

A — Shared Access Signature (SAS)

Vì sao đúng

Yêu cầu có một đặc điểm rất rõ: quyền truy cập chỉ trong tháng Ba. SAS là cơ chế duy nhất trong danh sách cho khai thời điểm bắt đầu và thời điểm hết hạn ngay trong bản thân chuỗi uỷ quyền — hết ngày là tự mất hiệu lực, không cần ai nhớ đi thu hồi.

Bạn còn khai được cụ thể quyền gì (đọc, ghi, liệt kê) và giới hạn theo dải IP.

Vì sao các phương án khác sai

  • D. Access keys — khoá tài khoản là "chìa khoá vạn năng": toàn quyền, không có thời hạn, và thu hồi nghĩa là tạo lại khoá làm gãy mọi thứ khác đang dùng nó.
  • B. Conditional Access policies — áp cho việc đăng nhập bằng danh tính Entra ID; đây là hướng khác và nặng hơn nhiều cho nhu cầu tạm thời này.
  • C. Certificates — dùng để xác thực ứng dụng, không phải cơ chế cấp quyền có hạn cho blob.