Ngân hàng đề — Microsoft Azure Architect Expert

Tìm thấy 100 câu.

Câu 81 Design identity, governance & monitoring solutions (25–30%)

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals.

You are tasked with recommending a solution that centralizes key management and securely isolates database secrets, ensuring the safeguarding of cryptographic keys for cloud applications in compliance with FIPS 140-2 Level 3.

The solution must adhere to the following criteria:

  • Each cluster must utilize an individual customer-specific security domain for cryptographic isolation of each customer.

  • It should be highly available and resilient across zones.

  • The solution requires a fully managed service.

Solution: You can deploy a Key Vault Managed HSM with a private endpoint enabled, and select the Vault access policy as the permission model in the Access Configuration section.

Does this fulfill the objective?

  1. A

    Yes

  2. B

    No

Xem giải thích

Đáp án

A — Có

Vì sao đúng

Key Vault Managed HSM là dịch vụ khớp chính xác với các yêu cầu khó nhất của đề:

Yêu cầu Managed HSM đáp ứng thế nào
FIPS 140-2 Level 3 Module phần cứng được chứng nhận ở đúng mức này
Security domain riêng cho từng khách hàng Mỗi instance có security domain riêng — đây là khái niệm chỉ tồn tại ở Managed HSM
Sẵn sàng cao, chịu lỗi theo zone Có sẵn
Dịch vụ được quản lý hoàn toàn Microsoft vận hành phần cứng, bạn không đụng tới

Thêm private endpoint thì lưu lượng không đi qua Internet công cộng.

Vì sao phương án còn lại sai

  • B. Không — Managed HSM chính là dịch vụ được thiết kế cho nhóm yêu cầu này.

Một chi tiết đáng chú ý

Giải pháp nhắc tới việc chọn "vault access policy" làm mô hình phân quyền. Trên thực tế Managed HSM dùng hệ RBAC cục bộ riêng của nó, không dùng access policy như Key Vault thường. Chi tiết này không làm hỏng phương án về mặt kiến trúc, nhưng đáng biết khi triển khai thật.

Câu 82 Design identity, governance & monitoring solutions (25–30%)

You have set up an Azure App Service web app using the default settings, which requires a connection to a SQL Database to access necessary data.

As a Cloud Consultant, you are tasked with suggesting a solution that can retrieve the database’s connection string and password as secrets from an Azure Key Vault.

The proposed solution must adhere to the following criteria:

  • Adhere to the principle of least privilege.

  • Limit modifications to the application code.

  • Avoid hardcoding the database password in the application code.

What would be your recommendation under these conditions?

  1. A

    Enable system-assigned Managed Identities in App Services and grant permissions to access the Key Vault secrets.

  2. B

    Enable system-assigned Managed Identity in App Services. Grant Contributor role permissions at the Key Vault level.

  3. C

    Grant the "Reader" role permission in the IAM section at the Key Vault level.

  4. D

    Enable the system-assigned Management Identity in App Services and grant it permissions to get and list secrets from the Key Vault Access Policy.

Xem giải thích

Đáp án

A — Bật system-assigned managed identity cho App Service và cấp quyền trên chính SQL Database

Vì sao đúng

Managed identity gỡ bỏ hoàn toàn việc phải giữ chuỗi kết nối có mật khẩu: Azure cấp cho web app một danh tính do nền tảng quản lý, ứng dụng lấy token từ điểm cuối cục bộ, và bạn tạo một người dùng trong cơ sở dữ liệu ứng với danh tính đó. Không có bí mật nào trong mã, trong cấu hình, hay trong biến môi trường — nên không có gì để rò rỉ và không có gì phải xoay vòng.

Phần thứ hai cũng quan trọng: quyền được cấp ở chính cơ sở dữ liệu, đúng phạm vi cần.

Vì sao các phương án khác sai

  • B. Cấp vai Contributor — vai này quản lý tài nguyên Azure (tạo, sửa, xoá máy chủ), nhưng không tự động cho đọc dữ liệu bên trong cơ sở dữ liệu. Đây là nhầm lẫn phổ biến giữa quyền ở mặt phẳng quản lý và quyền ở mặt phẳng dữ liệu.
  • C. Cấp vai Reader ở Key Vault — sai tài nguyên; đề nói về kết nối tới SQL Database.
  • D — cấp quyền sai phạm vi tương tự phương án B.
Câu 83 Design identity, governance & monitoring solutions (25–30%)

A sports entertainment company has deployed critical workloads in different resource groups, comprising important components such as Key Vault, Application Gateway, Private DNS Zones, App Services, Cosmos Databases, and AKS.

Unfortunately, one of the DevOps team members accidentally deleted an Application Gateway, leading to an outage that impacted the company's reputation and resulted in a significant financial loss.

As a cloud consultant, you need to suggest a solution that can prevent human errors like this in the future and improve the company's processes.

Which Azure feature can help prevent such errors in any of the Azure components deployed in different resource groups?

  1. A

    Restrict Azure access using IAM roles with fewer privileges.

  2. B

    A Conditional Access policy that has the cloud apps assignment set to Microsoft Azure Management.

  3. C

    Azure Lock at Resource Group Level.

  4. D

    A Conditional Access policy that forces the use of Multi-Factor Authentication (MFA) for all DevOps team members.

Xem giải thích

Đáp án

C — Azure Lock ở mức resource group

Vì sao đúng

Đề nói về việc bảo vệ thành phần trọng yếu khỏi bị xoá hay sửa nhầm. Resource lock làm đúng điều đó, và điểm mạnh của nó là áp cho tất cả, kể cả tài khoản có vai Owner — khoá nằm ở tầng Azure Resource Manager chứ không ở tầng phân quyền.

Vì vậy muốn xoá thật thì phải gỡ khoá trước, và chính bước thêm đó là thứ ngăn tai nạn. Đặt ở mức resource group thì mọi tài nguyên bên trong đều được bảo vệ.

Vì sao các phương án khác sai

  • A. Giảm bớt quyền IAM — giúp giảm rủi ro nhưng người có quyền hợp lệ vẫn xoá nhầm được; và luôn phải có ai đó giữ quyền quản trị.
  • B và D. Conditional Access policy — kiểm soát điều kiện đăng nhập (thiết bị, vị trí, xác thực đa yếu tố); chúng không ngăn được thao tác xoá của người đã đăng nhập hợp lệ.
Câu 84 Design data storage solutions (20–25%)

An Oil and Gas company has a core application that offers Business Intelligence (Bl) and Analytics features for several clients. However, to implement new features and improve performance, the application needs to utilize hierarchical namespace (HNS) capabilities such as file and directory-level security and faster operations. These capabilities are essential for big data analytics workloads.

The client's data currently resides in fewer than 10 storage accounts, with large amounts of data.

What recommendations do you have to unblock new planned features for the application?

  1. A

    Enable the HNS toggle on Storage Accounts configuration in Portal

  2. B

    Enable the HNS through the "az storage account" CLI command

  3. C

    Create an HNS enabled Storage Account and migrate the data

  4. D

    Upgrade current Storage accounts to Data Lake Gen2

Xem giải thích

Đáp án

D — Nâng cấp tài khoản lưu trữ hiện có lên Data Lake Gen2

Vì sao đúng

Data Lake Gen2 không phải một dịch vụ tách rời mà là một tập tính năng bật thêm trên tài khoản lưu trữ, mà cốt lõi là hierarchical namespace (HNS) — cho phép thao tác thư mục thật sự thay vì mô phỏng bằng tiền tố tên. Nhờ đó việc đổi tên hay xoá cả cây thư mục trở thành thao tác nguyên tử, và phân quyền theo thư mục cũng khả thi.

Microsoft cung cấp đường nâng cấp tại chỗ, nên dữ liệu hiện có không phải di chuyển đi đâu.

Vì sao các phương án khác sai

  • A và B. Bật công tắc HNS trên tài khoản đang chạy qua Portal hoặc CLI — mô tả đúng ý tưởng nhưng không phải là cách thao tác được trình bày; việc bật HNS cho tài khoản đã có dữ liệu đi qua quy trình nâng cấp chứ không phải một công tắc đơn giản.
  • C. Tạo tài khoản mới rồi di trú dữ liệu — làm được nhưng tốn thời gian và rủi ro hơn hẳn khi đã có đường nâng cấp tại chỗ.
Câu 85 Design data storage solutions (20–25%)

You have uploaded 3D assets to an Azure Storage Account and Blob Containers, and initially enabled public access. This means that anyone can access the 3D assets from the Internet. However, you need to improve the security by adding an additional layer to prevent unauthorized access to company documents.

You have decided to implement the most secure approach, which is to change the public access to private access at the Storage Account level. However, there is a challenge: one of the stakeholders needs access to a specific 3D assets content for 24 hours every month.

You need to recommend the best security solution that will allow temporary access to a private blob container for that stakeholder, but only during the 24 hours they require access. This solution should ensure that the stakeholder has read-only access.

What storage account solution would you recommend?

  1. A

    Share the Storage Account Access Keys with the Stakeholder.

  2. B

    Add IAM permissions to the Stakeholder with the reader role at storage account level

  3. C

    Shared access signatures (SAS)

  4. D

    Enable Service Endpoint

Xem giải thích

Đáp án

C — Shared Access Signature (SAS)

Vì sao đúng

Đề mô tả việc chuyển từ truy cập công khai cho mọi người sang cấp quyền có kiểm soát cho một bên cụ thể. SAS đúng cho việc đó: bạn khai chính xác tài nguyên nào, quyền gì, hiệu lực từ lúc nào tới lúc nào, và chấp nhận từ dải IP nào — rồi gửi cho bên liên quan một đường dẫn duy nhất.

Điểm quan trọng: bên nhận không cần tài khoản Azure nào, và quyền tự hết hiệu lực khi tới hạn.

Vì sao các phương án khác sai

  • A. Chia sẻ khoá tài khoản lưu trữ — trao "chìa khoá vạn năng": toàn quyền trên toàn bộ tài khoản, không có thời hạn, và thu hồi nghĩa là tạo lại khoá làm gãy mọi thứ khác. Đây là phương án nguy hiểm nhất.
  • B. Cấp vai Reader qua IAM — đòi bên kia phải có danh tính trong tổ chức của bạn, và quyền không tự hết hạn.
  • D. Bật service endpoint — kiểm soát theo mạng, không phù hợp khi bên nhận ở ngoài.
Câu 86 Design data storage solutions (20–25%)

Book Your Flight is a US-based company that offers flight, taxi, and hotel booking services through its self-service portal. The company's business is growing exponentially and it needs to enhance its portal to keep up with the demand. The company currently has an on-premises data center located in the eastern part of the US. Its passenger information management system is a legacy Java/Tomcat application that is functional but needs major improvements.

The current state of the system includes the following features:

  • The ability to search for available flights

  • Book and cancel flights, hotels, and taxis

  • Make payments

  • Track flight status

Current state (pain points)

The application is currently running on a VMware VM in the customer's private cloud. Since the company is growing some paint points came up:

  • Difficulty in changing the legacy code, leading to a lack of agility

  • Deployment requiring downtime, negatively impacting the customer experience

  • Poor performance during peak loads, which is a significant issue

  • No application for big data analytics

  • A shared database for the legacy application

  • No disaster recovery site

  • A backup strategy based on a homegrown script with high administrative overhead

Desired target state

The company's CIO, J.K. Smith, has a future vision for the company, including the following desired target state:

  • Migrating all on-premises resources to the Azure cloud, with business-critical applications given top priority

  • Transforming all business-critical functionality into microservices (MLS)

  • Provisioning an analytic system for both data warehousing and big data analytics in the Azure cloud

  • Building a BCDR site on a priority basis

  • Creating a backup strategy for faster backup and recovery with low administrative overhead

Jordi is the solution architect responsible for ensuring that the desired target state is achieved in a logical order. Jordi is considering the best approach for creating a data warehouse and big data analytics system.

  1. A

    Azure Data factory

  2. B

    Azure Databricks

  3. C

    Azure Synapse Analytics service

  4. D

    Azure HDInsight

  5. E

    Azure event hub

Xem giải thích

Đáp án

C — Azure Synapse Analytics

Vì sao đúng

Khi đề mô tả nhu cầu phân tích của một doanh nghiệp đang tăng trưởng nhanh với nhiều nguồn dữ liệu, Synapse là nền tảng gộp nhiều mảnh vào một không gian làm việc: nạp và điều phối dữ liệu, kho dữ liệu dạng cột, xử lý Spark, và truy vấn không máy chủ trực tiếp trên data lake.

Nguyên tắc chọn: khi câu hỏi mô tả cả một giải pháp chứ không phải một khâu, câu trả lời là nền tảng gộp chứ không phải công cụ riêng lẻ.

Vì sao các phương án khác sai

Bốn phương án còn lại đều là một mảnh của bức tranh:

  • A. Data Factory — chỉ khâu nạp và điều phối.
  • B. Databricks — chỉ khâu xử lý bằng Spark.
  • D. HDInsight — cụm Hadoop được quản lý, cần vận hành nhiều hơn.
  • E. Event Hub — chỉ khâu nhận dữ liệu theo luồng.
Câu 87 Design data storage solutions (20–25%)

A company has on-premises data centers located in different countries in South America. The on-premises network is based on MPLS and has several branch offices in each country.

A data center situated in Colombia hosts a Windows Virtual Machine that has a configured file server. All the users from South America access the shared files on Virtual Machines as part of their critical business activities and mount them as drives on their computers.

However, the leadership is concerned because if the Colombia data center experiences an outage, the company would be unable to access the shared files, which would severely impact their operations.

As a Microsoft consultant, the company seeks your recommendation for an Azure solution that can enhance the high availability and resilience of the shared file access in case of any region outage.

What solution would you recommend?

  1. A

    A Storage Account, LRS enabled, and containing Blob Containers.

  2. B

    A Storage Account, GRS enabled, and containing Blob Containers.

  3. C

    A Storage Account, GRS enabled, containing File shares and Azure File sync enabled.

  4. D

    A Storage Account, ZRS enabled, containing File shares and Azure File sync enabled.

Xem giải thích

Đáp án

C — Storage Account bật GRS, chứa File share và bật Azure File Sync.

Vì sao đúng

⚠ Ba yêu cầu ngầm trong đề khớp ba lựa chọn: | Yêu cầu | Lựa chọn | |---|---| | ⚠ Người dùng MOUNT ổ đĩa | ⚠ File share (SMB), không phải blob | | ⚠ Nhiều chi nhánh nhiều nước | ⚠ Azure File Sync — bản sao cục bộ ở mỗi site | | ⚠ Nghiệp vụ trọng yếu | ⚠ GRS — nhân bản sang vùng ghép đôi |

⚠ Azure File share (nguồn sự thật)
        ↓ ⚠ Azure File Sync
⚠ Máy chủ tệp ở Colombia
⚠ Máy chủ tệp ở chi nhánh khác
        ↓
⚠ Người dùng truy cập bản CỤC BỘ, nhanh
⚠ Dữ liệu đồng bộ về đám mây
        ↓ ⚠ GRS
⚠ Sống sót khi mất cả một vùng

Vì sao các phương án khác sai

  • D (ZRS + File Sync) — ⚠ gần đúng nhưng yếu hơn: ⚠ ZRS chỉ chịu được mất ⚠ một zone trong CÙNG vùng, ⚠ không chịu được mất cả vùng.

  • A và B (Blob container) — ⚠ SAI về giao thức: ⚠ blob ⚠ không mount được như ổ đĩa mạng; ⚠ B còn dùng LRS cho dữ liệu trọng yếu.

Ghi nhớ

⚠ Bốn mức nhân bản của Storage Account — bảng phải thuộc: | Mức | Chịu được | |---|---| | ⚠ LRS | ⚠ hỏng ổ đĩa, hỏng rack — rẻ nhất | | ⚠ ZRS | ⚠ mất một availability zone | | ⚠ GRS | ⚠ mất cả VÙNG | | ⚠ GZRS | ⚠ mất zone VÀ mất vùng — mạnh nhất | | ⚠ Thêm RA- | ⚠ RA-GRS, RA-GZRS cho phép ĐỌC từ vùng phụ |

Từ khoá nhận diện:

"mount ổ đĩa, SMB, NFS" → ⚠ Azure Files "lưu ảnh, video, sao lưu" → ⚠ Blob "máy chủ tệp ở nhiều chi nhánh" → ⚠ Azure File Sync "chịu được mất cả vùng" → ⚠ GRS hoặc GZRS

⚠ Azure File Sync — điều làm nó đặc biệt Điều
⚠ Cloud tiering ⚠ tệp ít dùng chỉ giữ con trỏ trên máy chủ
⚠ Máy chủ chi nhánh chỉ cần đĩa nhỏ
⚠ Mở tệp cũ thì tự kéo về ⚠ người dùng không thấy khác biệt
⚠ Nhiều máy chủ đồng bộ cùng một share
⚠ Khôi phục nhanh ⚠ máy chủ hỏng, dựng máy mới và đồng bộ lại metadata trước
⚠ Cảnh báo: đồng bộ KHÔNG phải sao lưu Cảnh báo
⚠ Xoá ở một nơi sẽ lan ra mọi nơi
⚠ Mã độc mã hoá tệp cũng lan theo
⚠ Vẫn cần Azure Backup cho file share
⚠ Đây là ⚠ hiểu lầm phổ biến nhất về File Sync
⚠ GRS — điều cần biết về failover Điều
⚠ Nhân bản sang vùng phụ là BẤT ĐỒNG BỘ ⚠ có thể mất dữ liệu gần nhất
⚠ Failover do BẠN kích hoạt hoặc Microsoft kích hoạt
⚠ Sau failover, tài khoản chuyển sang LRS ở vùng mới
⚠ Phải nhớ ⚠ bật lại nhân bản sau khi failover

Ba việc kiểm chứng: | Việc | Cách | |---|---| | Người dùng cần mount hay chỉ cần tải tệp | ⚠ Files hay Blob | | Cần chịu mất zone hay mất cả vùng | ⚠ ZRS hay GRS | | Đã có sao lưu riêng cho file share chưa | ⚠ File Sync không thay thế được |

Và điều dễ hiểu nhầm nhất về Azure File Sync, đủ để mất dữ liệu thật: nó là công cụ đồng bộ, không phải công cụ sao lưu. Một lệnh xoá nhầm ở chi nhánh Colombia sẽ lan tới mọi máy chủ khác trong vài phút.

Câu 88 Design data storage solutions (20–25%)

As a Microsoft consultant, you have been asked to deploy Azure Synapse Analytics to store private, classified, and sensitive data of bank accounts.

The security team is concerned about unauthorized access to this information by level 3 support, developers, DevOps profiles, and some stakeholders who have Azure access. They want a solution that allows sensitive data to be hidden on SQL query outputs.

Your task is to advise an Azure solution that ensures only authorized and privileged users can view the Personally Identifiable Information (PII).

What should you include in the solution?

  1. A

    Grating IAM Role Database Reader only to a few authorized and privileged users

  2. B

    Dynamic data masking

  3. C

    SQL Advanced Threat Protection

  4. D

    Enable Private Endpoints on Azure Synapse

Xem giải thích

Đáp án

B — Dynamic data masking

Vì sao đúng

Đề cần che dữ liệu nhạy cảm khi hiển thị cho những người không có quyền xem đầy đủ, mà vẫn để họ truy vấn được phần còn lại. Dynamic data masking làm đúng điều đó: dữ liệu vẫn nằm nguyên dạng thường trong cơ sở dữ liệu, nhưng kết quả trả về được che tuỳ theo quyền của người truy vấn.

Ưu điểm lớn nhất là không phải sửa ứng dụng — cùng một câu truy vấn, hai người khác nhau nhận hai kết quả khác nhau.

Vì sao các phương án khác sai

  • D. Bật private endpoint — kiểm soát ai kết nối được tới dịch vụ, nhưng người đã kết nối vẫn thấy toàn bộ dữ liệu.
  • A. Chỉ cấp vai Database Reader cho vài người — mức quá thô: hoặc thấy hết hoặc không thấy gì.
  • C. Advanced Threat Protection — phát hiện hoạt động bất thường, không che dữ liệu.
Câu 89 Design data storage solutions (20–25%)

You have a Data Center on premises that is connected to Azure through a redundant express route circuit. There is a legacy application that uses an Oracle database, and the leadership wants to keep it on the premises. However, you need to transfer and load data from the Oracle database to Synapse Analytics to utilize the Azure tools for data analysis and generate useful reports.

The solution should have the following key service capabilities:

  • Large-scale data processing for both batch and streaming workloads

  • Simplify and expedite data science on large datasets

  • Optimized spark engine

  • Support for Scala R language

Which service should you include in the solution?

  1. A

    Azure Data Factory

  2. B

    Azure Machine Learning

  3. C

    Azure Data Lake Gen 2

  4. D

    Azure Databricks

Xem giải thích

Đáp án

D — Azure Databricks

Vì sao đúng

Khi bài toán là xử lý và biến đổi dữ liệu ở quy mô lớn — kể cả dữ liệu kéo từ hệ thống cũ như Oracle — Databricks là công cụ mạnh nhất trong danh sách: nền tảng Spark được quản lý, tự co giãn cụm theo tải, xử lý được cả dữ liệu có cấu trúc lẫn phi cấu trúc, và có notebook cho đội dữ liệu làm việc cùng nhau.

Vì sao các phương án khác sai

  • A. Azure Data Factory — mạnh ở di chuyển và điều phối; với phần biến đổi phức tạp thì nó thường gọi sang Databricks.
  • C. Data Lake Gen2 — là nơi lưu trữ, không xử lý gì.
  • B. Azure Machine Learning — dựng cho việc huấn luyện và triển khai mô hình, không phải công cụ xử lý dữ liệu tổng quát.
Câu 90 Design data storage solutions (20–25%)

Your company is in the process of migrating its on-premise SQL databases to Azure SQL databases as the final step in its cloud journey. Overall, the company is satisfied with the cloud migration because it has resulted in significant infrastructure cost savings and offers greater flexibility to pay as you use.

The migration of around 20 databases that store confidential and critical business data is crucial, and one of the most important considerations is ensuring that backups are taken and retained for at least 30 days. The DTIJ purchasing model was selected based on the type of workload.

Considering the cost-effectiveness, what would be the best SQL tier for this solution?

  1. A

    Basic S0

  2. B

    Basic S1

  3. C

    Basic S2

  4. D

    Standard

Xem giải thích

Đáp án

D — Standard

Vì sao đúng

Đây là câu kiểm tra bạn có nắm đúng cách đặt tên các bậc dịch vụ của Azure SQL Database hay không. Trong mô hình DTU có ba bậc:

Bậc Service objective Dùng cho
Basic B Cơ sở dữ liệu rất nhỏ, phát triển và thử nghiệm
Standard S0, S1, S2, S3… Phần lớn khối lượng công việc sản xuất
Premium P1, P2, P4… Đòi hiệu năng và độ trễ cao nhất

S0, S1, S2 là các mức bên trong bậc Standard, không phải bên trong Basic. Vì vậy ba phương án "Basic S0", "Basic S1", "Basic S2" đều là tổ hợp không tồn tại.

Vì sao các phương án khác sai

  • A, B, C — ghép sai tên bậc với tên service objective, như đã nêu ở trên.