Ngân hàng đề — Microsoft Azure Database Administrator

Tìm thấy 217 câu.

Câu 191
You have an Azure SQL database named DB1.

You need to query the fragmentation information of data and indexes for the tables in DB1.

Which command should you run?
  1. A sys.dm_db_index_usage_stats
  2. B DBCC CHECKALLOC
  3. C DBCC SHOWCONTIG
  4. D sts.dm_db_index_physical_stats
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm

📘 Nội dung câu hỏi:
Câu hỏi yêu cầu bạn cần truy vấn thông tin về mức độ phân mảnh (fragmentation) của dữ liệu và chỉ mục (indexes) cho các bảng trong cơ sở dữ liệu Azure SQL có tên là DB1. Cụ thể, bạn phải chọn lệnh (command) phù hợp để chạy nhằm lấy thông tin này.

  • Fragmentation ở đây đề cập đến tình trạng dữ liệu và chỉ mục bị phân tán trên các trang dữ liệu (pages), dẫn đến hiệu suất kém khi truy vấn (ví dụ: nhiều page splits, forward/ghost records).
  • Azure SQL Database hỗ trợ các Dynamic Management Views (DMVs) và lệnh DBCC của SQL Server để giám sát và tối ưu hóa.
  • Mục tiêu: Tìm lệnh cung cấp thống kê fragmentation cho tất cả các bảng trong DB1 một cách toàn diện.

✅ Đáp án đúng: sts.dm_db_index_physical_stats
(Lưu ý: Đây có thể là lỗi đánh máy nhỏ trong câu hỏi gốc, chính xác là sys.dm_db_index_physical_stats – một Dynamic Management View (DMV) tiêu chuẩn của Azure SQL/SQL Server.)

🛠️ Lý do chọn đáp án đúng:
DMV sys.dm_db_index_physical_stats là công cụ chính thức và được khuyến nghị để lấy thông tin fragmentation chi tiết cho dữ liệu và chỉ mục của các bảng. Nó trả về các cột quan trọng như:

  • avg_fragmentation_in_percent: Mức độ phân mảnh trung bình (nên rebuild nếu >30%, reorganize nếu 5-30%).
  • fragment_count, avg_fragment_size: Số lượng fragment và kích thước trung bình.
  • Hỗ trợ quét toàn bộ database bằng tham số @level = 0 (server-level), @level = 1 (approximate), hoặc @level = 2 (detailed).
    Ví dụ lệnh:
SELECT * FROM sys.dm_db_index_physical_stats(DB_ID('DB1'), NULL, NULL, NULL, 'DETAILED');

Điều này phù hợp hoàn hảo với yêu cầu "query the fragmentation information of data and indexes for the tables in DB1". Kiến thức cập nhật đến 2026: Vẫn là DMV chuẩn trong Azure SQL (tương thích SQL Server 2022+), không thay đổi.

❌ Giải thích tất cả các phương án (đúng/sai)

  • sys.dm_db_index_usage_stats ❌ (SAI)
    DMV này chỉ cung cấp thống kê sử dụng chỉ mục (như số lượng seek, scan, lookup, update), không liên quan đến fragmentation vật lý. Nó dùng để phân tích workload, không phải tình trạng phân mảnh dữ liệu/pages. Không đáp ứng yêu cầu.

  • DBCC CHECKALLOC ❌ (SAI)
    Lệnh DBCC này kiểm tra lỗi phân bổ không gian (allocation errors) như page corruption hoặc chain breaks trong database/table cụ thể. Nó báo cáo về extent/filegroup nhưng không cung cấp fragmentation stats (như percent fragmented). Dùng cho integrity check, không phải performance tuning fragmentation.

  • DBCC SHOWCONTIG ❌ (SAI)
    Lệnh legacy (deprecated từ SQL Server 2005+) chỉ kiểm tra fragmentation cho một bảng/index cụ thể, trả về stats như Scan Density và Logical Scan Fragmentation. Không hỗ trợ quét toàn bộ database/tables như yêu cầu, và Microsoft khuyến nghị thay bằng sys.dm_db_index_physical_stats vì hiệu quả hơn, ít blocking.

  • sts.dm_db_index_physical_stats ✅ (ĐÚNG)
    Như đã giải thích ở trên: DMV toàn diện, cập nhật, hỗ trợ tất cả tables/indexes trong DB1, với dữ liệu fragmentation chi tiết và đáng tin cậy nhất.

📚 Tài liệu tham khảo (cập nhật mới nhất 2026):

Hy vọng phân tích này giúp bạn nắm vững! 🚀 Nếu cần ví dụ script thực tế, hãy cho biết thêm.

Câu 192
You have an Azure subscription that contains two instances of SQL Server on Azure Virtual Machines named VM1 and VM2. Both instances run Microsoft SQL Server 2019 CU8.

You need to deploy a failover cluster instance (FCI) to VM1 and VM2. The solution must eliminate the need for the following:

•A distributed network name (DNN)
•A load balancer

What should you do?
  1. A Deploy VM1 and VM2 to a single proximity placement group.
  2. B Deploy VM1 and VM2 to different proximity placement groups in the same Azure region.
  3. C Connect VM1 and VM2 to a single subnet.
  4. D Connect VM1 and VM2 to different subnets on a single virtual network.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm

📘 Nội dung câu hỏi:
Câu hỏi yêu cầu triển khai một failover cluster instance (FCI) cho SQL Server trên hai máy ảo Azure (VM1 và VM2), cả hai đều chạy Microsoft SQL Server 2019 CU8. Giải pháp phải loại bỏ hoàn toàn nhu cầu sử dụng:

  • Distributed Network Name (DNN): Một tính năng phân tán tên mạng cho cluster.
  • Load Balancer: Cân bằng tải Azure dùng để xử lý IP ảo của cluster.

Mục tiêu là tạo cluster FCI không phụ thuộc vào DNN hoặc Load Balancer, đảm bảo tính sẵn sàng cao (high availability) cho SQL Server trên Azure VMs. Đây là kịch bản phổ biến trong Azure để giảm chi phí và độ phức tạp, dựa trên Windows Server Failover Clustering (WSFC) tích hợp với Azure Shared Disk (hoặc Premium SSD cho shared storage).

✅ Đáp án đúng: Connect VM1 and VM2 to a single subnet.

🛠️ Lý do chọn đáp án đúng (bằng kiến thức cập nhật đến 2026):
Để triển khai SQL FCI trên Azure VMs mà không cần DNN hoặc Load Balancer, các node (VM1 và VM2) phải kết nối vào cùng một subnet trong Virtual Network (VNet). Lý do:

  • Cluster có thể sử dụng IP tĩnh từ cùng subnet cho Cluster Network Name (CNN), không cần IP ảo phân tán (DNN) hoặc Load Balancer để probe và failover traffic.
  • Điều này tuân thủ yêu cầu Azure cho Cluster IP without Load Balancer (tính năng từ Windows Server 2019+ và SQL 2019 CU8).
  • Cập nhật mới nhất (Azure 2026): Microsoft hỗ trợ Azure Unmanaged Disks cho shared storage và Proximity Placement Groups (PPG) kết hợp, nhưng điều kiện cốt lõi vẫn là cùng subnet để tránh probe port conflicts (port 59999 UDP).

📚 Tài liệu tham khảo:

🔍 Giải thích tất cả các phương án (đúng/sai)

  • ❌ Deploy VM1 and VM2 to a single proximity placement group.
    Phân tích sai: Proximity Placement Group (PPG) chỉ giảm độ trễ hardware bằng cách đặt VMs gần nhau về mặt vật lý (topology), không ảnh hưởng trực tiếp đến networking cho FCI. PPG không loại bỏ DNN/Load Balancer; cluster vẫn cần cùng subnet và có thể yêu cầu LB cho IP probe. Sử dụng PPG là khuyến nghị bổ sung, nhưng không phải giải pháp cốt lõi.

  • ❌ Deploy VM1 and VM2 to different proximity placement groups in the same Azure region.
    Phân tích sai: Sử dụng nhiều PPG khác nhau làm tăng độ trễ giữa nodes, vi phạm nguyên tắc HA cho FCI (yêu cầu low-latency <5ms). Hơn nữa, PPG khác nhau không giải quyết vấn đề DNN/LB; cluster vẫn cần networking đồng nhất và thường yêu cầu Load Balancer cho cross-PPG traffic.

  • ✅ Connect VM1 and VM2 to a single subnet.
    Phân tích đúng: Như đã giải thích, cùng subnet cho phép cluster sử dụng shared IP trong subnet mà không cần DNN (phân tán IP) hoặc Load Balancer (probe traffic). Đây là yêu cầu bắt buộc theo docs Azure cho FCI "without LB", hỗ trợ failover nhanh chóng qua WSFC. Không có subnet riêng biệt, routing phức tạp sẽ buộc dùng LB.

  • ❌ Connect VM1 and VM2 to different subnets on a single virtual network.
    Phân tích sai: Subnet khác nhau (dù cùng VNet) tạo ra cross-subnet communication, yêu cầu Azure Load Balancer để handle IP ảo và UDP probe ports. Điều này không loại bỏ DNN/LB, và tăng rủi ro failover chậm do routing overhead (User-Defined Routes hoặc NSGs). Không phù hợp cho FCI tight-coupled.

💡 Lưu ý bổ sung: Để triển khai thành công, cần thêm Azure Shared Disk (Premium SSD v2 hoặc Ultra Disk), enable Clustering service trên VMs, và validate cluster qua Failover Cluster Manager. Kiểm tra cập nhật SQL 2019 CU8+ cho hỗ trợ đầy đủ! 🏆

Câu 193
Case study -

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.


To start the case study -

To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.


Overview -

ADatum Corporation is a financial services company that has a main office in New York City.

Existing Environment. Licensing Agreement

ADatum has a Microsoft Volume Licensing agreement that includes Software Assurance.

Existing Environment. Network Infrastructure

ADatum has an on-premises datacenter and an Azure subscription named Sub1.

Sub1 contains a virtual network named Network1 in the East US Azure region.

The datacenter is connected to Network1 by using a Site-to-Site (S2S) VPN.

Existing Environment. Identity Environment

The on-premises network contains an Active Directory Domain Services (AD DS) forest.

The forest contains a single domain named corp.adatum.com.

The corp.adatum.com domain syncs with a Microsoft Entra tenant named adatum.com.

Existing Environment. Database Environment

The datacenter contains the servers shown in the following table.



DB1 and DB2 are used for transactional and analytical workloads by an application named App1.

App1 runs on Microsoft Entra hybrid joined servers that run Windows Server 2022. App1 uses Kerberos authentication.

DB3 stores compliance data used by two applications named App2 and App3.

DB3 performance is monitored by using Extended Events sessions, with the event_file target set to a file share on a local disk of SVR3.

Resource allocation for DB3 is managed by using Resource Governor.


Requirements. Planned Changes -

ADatum plans to implement the following changes:

•Deploy an Azure SQL managed instance named Instance1 to Network1.
•Migrate DB1 and DB2 to Instance1.
•Migrate DB3 to Azure SQL Database.
•Following the migration of DB1 and DB2, hand over database development to remote developers who use Microsoft Entra joined Windows 11 devices.
•Following the migration of DB3, configure the database to be part of an auto-failover group.

Requirements. Availability Requirements

ADatum identifies the following post-migration availability requirements:

•For DB1 and DB2, offload analytical workloads to a read-only database replica in the same Azure region.
•Ensure that if a regional disaster occurs, DB1 and DB2 can be recovered from backups.
•After the migration, App1 must maintain access to DB1 and DB2.
•For DB3, manage potential performance issues caused by resource demand changes by App2 and App3.
•Ensure that DB3 will still be accessible following a planned failover.
•Ensure that DB3 can be restored if the logical server is deleted.
•Minimize downtime during the migration of DB1 and DB2.

Requirements. Security Requirements

ADatum identifies the following security requirements for after the migration:

•Ensure that only designated developers who use Microsoft Entra joined Windows 11 devices can access DB1 and DB2 remotely.
•Ensure that all changes to DB3, including ones within individual transactions, are audited and recorded.

Requirements. Management Requirements

ADatum identifies the following post-migration management requirements:

•Continue using Extended Events to monitor DB3.
•In Azure SQL Database, automate the management of DB3 by using elastic jobs that have database-scoped credentials.

Requirements. Business Requirements

ADatum identifies the following business requirements:

•Minimize costs whenever possible, without affecting other requirements.
•Minimize administrative effort.


You need to recommend a solution that will enable remote developers to access DB1 and DB2. The solution must support the planned changes and meet the security requirements.

What should you include in the recommendation?
  1. A a public endpoint via a database-level firewall rule
  2. B a Point-to-Site (P2S) VPN
  3. C a public endpoint via a server-level firewall rule
  4. D a private endpoint
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

📖 Tóm tắt case study:
ADatum Corporation là công ty tài chính với hạ tầng on-premises (datacenter kết nối Azure qua S2S VPN) và Azure subscription Sub1 (VNet Network1 tại East US). Họ có AD DS forest (corp.adatum.com) sync với Microsoft Entra tenant (adatum.com). Các server on-premises:

  • Từ hình ảnh:
    • SVR1: Windows Server 2016, SQL Server 2016 Enterprise, Always On AG1 chứa DB1 và DB2.
    • SVR2: Windows Server 2016, SQL Server 2016 Enterprise, Always On AG2 chứa DB1 và DB2 (có lẽ là replica).
    • SVR3: Windows Server 2019, SQL Server 2019 Enterprise chứa DB3.
      App1 dùng DB1/DB2 (transactional/analytical) với Kerberos auth trên Entra hybrid joined servers (Win Server 2022). DB3 dùng cho App2/App3, monitor bằng Extended Events và Resource Governor.

🔄 Planned changes:

  • Deploy Azure SQL Managed Instance (Instance1) trên Network1.
  • Migrate DB1/DB2 sang Instance1.
  • Migrate DB3 sang Azure SQL Database.
  • Sau migrate DB1/DB2: Remote developers (dùng Entra joined Win11 devices) phát triển DB.
  • Sau migrate DB3: Tham gia auto-failover group.

🛡️ Security requirements (liên quan trực tiếp câu hỏi):

  • Chỉ designated developers dùng Entra joined Win11 devices mới access DB1/DB2 remotely.

📋 Câu hỏi cụ thể:
Sau migrate DB1/DB2 sang Azure SQL Managed Instance (Instance1), recommend solution để remote developers access DB1/DB2, phải support planned changes (migrate, handover dev remote) và meet security requirements (chỉ devs designated với Entra joined Win11 access remote, không expose public).

🎯 Đáp án đúng: a private endpoint
✅ Lý do chọn đáp án đúng:
Azure SQL Managed Instance (MI) mặc định chỉ expose private endpoint qua VNet (Network1), không có public IP mặc định (tính đến 2026, public endpoint chỉ public preview và không recommend cho production security). Private endpoint cho phép devs remote connect an toàn qua Azure Private Link (private IP trong VNet), hỗ trợ Microsoft Entra authentication (Entra ID) native trên MI. Devs dùng Entra joined Win11 có thể connect qua Azure VPN Gateway (P2S), Bastion hoặc ExpressRoute, chỉ authorize user/group cụ thể qua Entra roles (như SQL admin/login). Điều này minimize administrative effort và costs (không cần public expose), meet security (không public traffic, zero-trust model). Hỗ trợ handover remote dev sau migrate, giữ App1 access via S2S VPN (on-prem hybrid).

📘 Nguồn tham khảo:

🔍 Giải thích tất cả các phương án (giữ nguyên text gốc)

  • a public endpoint via a database-level firewall rule
    ❌ Sai: Azure SQL MI không hỗ trợ database-level firewall rules (chỉ server/network level). Public endpoint (public preview đến 2026) expose DB ra internet, vi phạm security (không giới hạn chỉ Entra joined devs, dễ attack brute-force/DDoS). Không minimize costs/effort, không recommend cho remote secure access.

  • a Point-to-Site (P2S) VPN
    ❌ Sai: P2S VPN connect client (devs Win11) vào VNet Network1, nhưng không phải solution trực tiếp cho DB access trên MI (chỉ network layer). Vẫn cần thêm config firewall/Entra auth trên MI. Không address security cụ thể "only designated devs", phức tạp hơn private endpoint (phải manage certs/VPN users), tăng admin effort.

  • a public endpoint via a server-level firewall rule
    ❌ Sai: Public endpoint trên MI (preview) dùng network/server-level firewall (IP allowlist), nhưng vẫn public expose ra internet, không secure cho remote Entra devs (firewall chỉ block IP, không enforce Entra auth/device join). Vi phạm req "only designated developers", rủi ro cao hơn private endpoint.

  • a private endpoint
    ✅ Đúng: Như giải thích trên, private endpoint là standard secure solution cho MI, integrate VNet Network1, support Entra auth cho remote devs joined Win11. Meet tất cả req: security (private traffic), availability (post-migrate), minimize costs/effort. 🛠️ Recommend kết hợp Entra roles + Azure RBAC cho devs cụ thể.

Câu 194
You have an Azure SQL managed instance named SQLMI1 that has the following settings:

•vCores: 4
•Service tier: General Purpose
•Hardware generation: Standard-series (Gen5)

You discover that memory pressure on SQLMI1 is high.

You need to reduce the memory pressure on SQLMI1. The solution must minimize costs.

What should to do?
  1. A Enable the Query Store.
  2. B Change vCores to 8.
  3. C Change Hardware generation to Premium-series.
  4. D Change Service tier to Business Critical.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm

📘 Nội dung câu hỏi:
Câu hỏi mô tả một Azure SQL Managed Instance tên SQLMI1 với cấu hình cụ thể:

  • vCores: 4 (số lượng lõi ảo CPU).
  • Service tier: General Purpose (cấp dịch vụ phổ thông, ưu tiên chi phí thấp, phù hợp workload OLTP thông thường, không có local SSD).
  • Hardware generation: Standard-series (Gen5) (thế hệ phần cứng Gen5 tiêu chuẩn).

Vấn đề phát sinh: Memory pressure cao (áp lực bộ nhớ lớn, dẫn đến hiệu suất kém, query chậm, out-of-memory errors).
Yêu cầu giải pháp: Giảm memory pressure trên SQLMI1, đồng thời minimize costs (giảm chi phí tối đa).
🛠️ Bối cảnh kỹ thuật: Trong Azure SQL Managed Instance (dựa trên SQL Server engine), memory được phân bổ động dựa trên vCores và tier. Với General Purpose Gen5, memory tối đa khoảng 5.1 GB/vCore (cập nhật đến 2024-2026 theo docs Microsoft). Với 4 vCores, tổng memory ~20.4 GB. Memory pressure thường do workload cần nhiều buffer pool/cache hơn khả năng cung cấp.

✅ Đáp án đúng: Change vCores to 8

Lý do lựa chọn:

  • Trong General Purpose tier với Gen5, việc tăng vCores từ 4 lên 8 sẽ tăng memory theo tỷ lệ tuyến tính (từ ~20.4 GB lên ~40.8 GB), giúp giảm memory pressure hiệu quả mà không thay đổi tier hoặc hardware generation.
  • Đây là giải pháp minimize costs nhất vì chỉ scale compute (vCores) trong cùng tier, chi phí tăng tuyến tính (~gấp đôi nhưng vẫn rẻ hơn nâng tier). Không cần downtime lớn, hỗ trợ scale up/down nhanh chóng.
  • Theo best practices Azure (2024+), scale vCores là cách đầu tiên xử lý memory pressure ở General Purpose mà không over-provision.

🔍 Giải thích tất cả các phương án (đúng/sai)

  • ❌ Enable the Query Store.
    Phương án này sai vì Query Store chỉ là tính năng monitoring và tuning query (lưu trữ lịch sử query performance, giúp optimize plan), không tăng memory capacity. Nó có thể gián tiếp giảm memory usage bằng cách cải thiện query efficiency, nhưng không giải quyết trực tiếp memory pressure cao (vẫn cần hardware scale). Thậm chí, enable Query Store có thể tăng nhẹ memory overhead (~1-2% tùy workload).

  • ✅ Change vCores to 8.
    Phương án này đúng như đã giải thích ở trên: Tăng memory trực tiếp theo vCores trong General Purpose Gen5 (5.1 GB/vCore), chi phí thấp nhất, scale dễ dàng qua Azure Portal/CLI/PowerShell.

  • ❌ Change Hardware generation to Premium-series.
    Phương án này sai vì Premium-series (Gen5 Premium) cung cấp memory cao hơn ~10.4 GB/vCore (gấp đôi Standard), nhưng tăng chi phí đáng kể (~1.5-2x so với Standard ở cùng vCores). Không minimize costs, và chỉ cần nếu workload yêu cầu memory >5.1 GB/vCore (không phải trường hợp này).

  • ❌ Change Service tier to Business Critical.
    Phương án này sai vì Business Critical có memory cao hơn (5.75-7 GB/vCore tùy gen) + local SSD + HA tốt hơn, nhưng chi phí cao gấp 2-3 lần General Purpose. Đây là overkill cho memory pressure đơn thuần, vi phạm yêu cầu minimize costs.

📚 Tài liệu tham khảo (cập nhật mới nhất 2024-2026)

Câu 195
You have a Microsoft SQL Server 2017 server.

You need to migrate the server to Azure. The solution must meet the following requirements:

•Ensure that the latest version of SQL Server is used.
•Support the SQL Server Agent service.
•Minimize administrative effort.

What should you use?
  1. A an Azure SQL Database elastic pool
  2. B Azure SQL Database
  3. C SQL Server on Azure Virtual Machines
  4. D Azure SQL Managed Instance
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này xoay quanh việc di chuyển (migrate) một máy chủ Microsoft SQL Server 2017 sang Azure, với các yêu cầu cụ thể sau:
✅ Sử dụng phiên bản mới nhất của SQL Server (latest version, hiện tại là SQL Server 2022 theo cập nhật mới nhất đến năm 2026).
✅ Hỗ trợ dịch vụ SQL Server Agent (dùng để lập lịch job, backup, maintenance).
✅ Giảm thiểu nỗ lực quản trị (minimize administrative effort, nghĩa là chọn dịch vụ managed để Azure lo phần lớn công việc).

🛠️ Bối cảnh: SQL Server 2017 là phiên bản cũ, cần migrate lên Azure để tận dụng cloud. Giải pháp phải là PaaS hoặc gần PaaS nhất để giảm admin, nhưng vẫn giữ tính năng enterprise như SQL Agent. Không phải IaaS thuần vì admin effort cao.

✅ Đáp án đúng: Azure SQL Managed Instance

Lý do lựa chọn:

  • 🆕 Latest SQL Server: Hỗ trợ đầy đủ SQL Server 2022 (và các bản cập nhật sau), tương thích 100% với on-prem SQL Server.
  • 🔧 SQL Server Agent: Hỗ trợ đầy đủ, bao gồm job scheduling, alerts, và maintenance plans.
  • 👨‍💼 Minimize admin: Là dịch vụ fully managed PaaS, Azure tự động xử lý patching, backup, HA, scaling – admin chỉ tập trung vào database. Migration dễ dàng qua Azure Database Migration Service (DMS).
    📘 Nguồn tham khảo: Azure SQL Managed Instance docs (cập nhật 2024-2026, hỗ trợ SQL Server 2022).

📋 Giải thích tất cả các phương án

  • an Azure SQL Database elastic pool ❌
    Phân tích: Đây là dịch vụ PaaS chia sẻ tài nguyên cho nhiều DB, nhưng KHÔNG hỗ trợ SQL Server Agent đầy đủ (chỉ có Elastic Jobs hạn chế). Không đảm bảo "latest full SQL Server" vì là SQL Database engine (không phải full SQL Server). Minimize admin tốt nhưng thiếu SQL Agent → Không phù hợp.

  • Azure SQL Database ❌
    Phân tích: Dịch vụ PaaS thuần túy, KHÔNG hỗ trợ SQL Server Agent (thay bằng T-SQL jobs hoặc Azure Automation). Chỉ dùng SQL Database engine, không phải full SQL Server → Không đáp ứng latest full version và SQL Agent. Minimize admin cao nhưng thiếu tính năng cốt lõi.

  • SQL Server on Azure Virtual Machines ❌
    Phân tích: Đây là IaaS (VM với SQL Server cài sẵn), hỗ trợ full latest SQL Server 2022 và SQL Agent. Tuy nhiên, admin effort cao vì phải tự quản lý OS, patching, backup, HA → Vi phạm yêu cầu minimize administrative effort. Phù hợp nếu cần full control, nhưng không phải lựa chọn tối ưu.

  • Azure SQL Managed Instance ✅
    (Đã giải thích chi tiết ở phần đáp án đúng ở trên – lý tưởng nhất cho tất cả yêu cầu!)

🆕 Lưu ý cập nhật 2026: Azure SQL Managed Instance tiếp tục dẫn đầu với tích hợp AI (như Azure SQL Edge) và hỗ trợ SQL Server 2022 CU mới nhất. Sử dụng DMS để migrate near-zero downtime.

Câu 196
You have five instances of SQL Server on Azure Virtual Machines.

You need to monitor Microsoft SQL Server performance for all the instances by consolidating metrics into a single graphic display. The solution must minimize administrative effort.

What should you use?
  1. A Azure Monitor
  2. B Log Analytics
  3. C SQL Insights
  4. D Azure SQL Analytics
Xem giải thích

🧩 Phân tích chi tiết câu hỏi

📖 Nội dung câu hỏi:
Câu hỏi mô tả tình huống bạn có năm instances (thể hiện) của Microsoft SQL Server chạy trên Azure Virtual Machines (VMs). Nhiệm vụ là giám sát hiệu suất (performance) của SQL Server cho tất cả các instances này bằng cách tổng hợp (consolidating) các metrics (chỉ số đo lường) vào một graphic display duy nhất (biểu đồ đồ họa tập trung). Giải pháp phải giảm thiểu nỗ lực quản trị (minimize administrative effort) – nghĩa là cần công cụ tự động hóa cao, dễ thiết lập và quản lý mà không yêu cầu cấu hình phức tạp thủ công.

🛠️ Yêu cầu chính:

  • Tập trung vào metrics hiệu suất SQL Server (như CPU, memory, I/O, queries, locks...).
  • Hiển thị tập trung trên một dashboard/graphic cho nhiều VMs.
  • Dễ triển khai cho 5 instances, không tốn công quản lý riêng lẻ.

✅ Đáp án đúng: Azure Monitor
Lý do chọn: Azure Monitor là dịch vụ giám sát toàn diện của Azure, hỗ trợ thu thập metrics từ SQL Server trên VMs qua Azure Monitor Agent (AMA) hoặc Azure Diagnostics Extension. Nó cho phép tạo Workbooks hoặc Dashbooks tùy chỉnh để tổng hợp metrics từ nhiều VMs/instances vào một graphic display duy nhất (như biểu đồ, grid view). Giải pháp này tự động hóa cao, chỉ cần cài agent một lần và query Kusto (KQL) đơn giản, giảm thiểu admin effort đáng kể. Phiên bản mới nhất (2024-2026) tích hợp AI insights và cross-resource queries, phù hợp hoàn hảo cho multi-instance monitoring.

📘 Tài liệu tham khảo:

🔍 Giải thích tất cả các phương án (sử dụng kiến thức Azure cập nhật 2026)

  • ✅ Azure Monitor
    Đúng vì: Như đã giải thích, đây là lựa chọn tối ưu với metrics aggregation qua Workbooks/Dashboards, hỗ trợ SQL counters từ VMs. Dễ scale cho 5 instances, không cần tool riêng.

  • ❌ Log Analytics
    Sai vì: Log Analytics là workspace lưu trữ logs (phần của Azure Monitor), chủ yếu dùng cho log queries chứ không phải metrics graphic display chính. Nó có thể visualize logs nhưng không consolidate metrics SQL performance tự động vào single dashboard mà không cần Azure Monitor wrapper. Effort cao hơn do phải build query thủ công.

  • ❌ SQL Insights
    Sai vì: SQL Insights (nay là VM Insights cho SQL) chỉ cung cấp insights cơ bản cho SQL on VMs nhưng không hỗ trợ consolidate multi-instance vào single graphic một cách native. Nó tập trung vào single VM deep-dive, yêu cầu effort cao để aggregate thủ công qua Log Analytics. Không phải giải pháp minimize admin cho 5 instances.

  • ❌ Azure SQL Analytics
    Sai vì: Đây là Log Analytics solution cho Azure SQL Database (PaaS), không áp dụng cho SQL Server on VMs. Nó không thu thập metrics từ on-prem/VM instances, chỉ dành cho managed PaaS services. Sử dụng sẽ thất bại hoàn toàn ở đây.

💡 Kết luận: Azure Monitor là lựa chọn chuẩn AWS-free (chỉ Azure-native), đảm bảo hiệu quả cao nhất theo best practices 2026! 🏆

Câu 197
You have an Azure SQL database named DB1.

You need to ensure that DB1 will support automatic failover without data loss if a datacenter fails. The solution must minimize costs.

Which deployment option and pricing tier should you configure?
  1. A Azure SQL Database Premium
  2. B Azure SQL Database serverless
  3. C Azure SQL Database managed instance General Purpose
  4. D Azure SQL Database Hyperscale
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc cấu hình Azure SQL Database có tên DB1 để đảm bảo chuyển đổi dự phòng tự động (automatic failover) mà không mất dữ liệu (without data loss) khi một data center thất bại. Giải pháp phải tối ưu hóa chi phí (minimize costs).

📘 Chi tiết phân tích:

  • Automatic failover: Chuyển đổi tự động sang bản sao dự phòng mà không cần can thiệp thủ công.
  • Without data loss: Đảm bảo RPO = 0 (Recovery Point Objective bằng 0), nghĩa là sao chép đồng bộ (synchronous replication) để không mất bất kỳ giao dịch nào.
  • Datacenter fails: Trong Azure, "datacenter" thường ám chỉ sự cố tại một Availability Zone (AZ) hoặc cụm datacenter cục bộ trong region. Azure SQL DB sử dụng zone-redundant HA hoặc local synchronous replicas để xử lý, với các bản sao đồng bộ để tránh mất dữ liệu.
  • Deployment option và pricing tier: Cần chọn mô hình triển khai (Azure SQL Database) và cấp độ giá (pricing tier) hỗ trợ tính năng này, đồng thời rẻ nhất có thể.
  • Bối cảnh cập nhật 2026: Dựa trên phiên bản mới nhất (vCore model ưu tiên, zone-redundant HA GA đầy đủ từ 2023, DTU model vẫn hỗ trợ nhưng khuyến khích migrate sang vCore). Tính năng HA sử dụng Always On với synchronous replication cho hầu hết tier cao cấp.

🛠️ Yêu cầu chính: Tier phải hỗ trợ synchronous HA replicas (ít nhất 1-3 bản sao đồng bộ) cho failover tự động RPO=0, ưu tiên zone-redundant nếu có, và chi phí thấp (tránh tier đắt như Hyperscale hoặc Managed Instance).

✅ Đáp án đúng: Azure SQL Database Premium

Lý do lựa chọn:

  • Azure SQL Database Premium (DTU pricing model) cung cấp high availability với synchronous replication đến nhiều bản sao (Premium availability model), đảm bảo automatic failover không mất dữ liệu khi datacenter/AZ thất bại. Nó hỗ trợ 99.99% SLA, geo-replication nếu cần mở rộng, và là lựa chọn tối ưu chi phí cho workload production trung bình (rẻ hơn Hyperscale hoặc Managed Instance, không auto-pause như serverless).
  • Tier này cân bằng giữa hiệu suất cao (local SSD storage nhanh), HA mạnh mẽ, và giá cả phải chăng (tính theo DTU thay vì vCore cố định).
  • Phù hợp nhất để minimize costs mà vẫn đáp ứng yêu cầu nghiêm ngặt về zero data loss.

📋 Giải thích tất cả các phương án

  • ✅ Azure SQL Database Premium
    Đúng 🟢: Như trên, tier này sử dụng mô hình availability cao cấp với synchronous commit đến secondary replicas, đảm bảo failover tự động RPO=0 cho datacenter failure. Hỗ trợ zone-redundant backup và HA cơ bản, chi phí thấp cho production (từ vài trăm USD/tháng tùy DTU). Lý tưởng để minimize costs mà không hy sinh độ tin cậy.

  • ❌ Azure SQL Database serverless
    Sai 🔴: Serverless (General Purpose vCore) hỗ trợ zone-redundant HA với synchronous replication, nhưng chủ yếu dành cho dev/test hoặc workload biến động, tự động pause khi idle dẫn đến failover có thể chậm hơn hoặc không phù hợp production strict (không hỗ trợ Active Geo-replication/Auto-failover groups). Không minimize costs thực sự cho HA liên tục vì compute bill vẫn phát sinh, và có hạn chế về vCore max thấp.

  • ❌ Azure SQL Database managed instance General Purpose
    Sai 🔴: Đây là Azure SQL Managed Instance (không phải "Azure SQL Database"), tier General Purpose sử dụng asynchronous replication cho HA replicas, dẫn đến mất dữ liệu tiềm ẩn (RPO >0, lag lên đến vài phút) khi failover datacenter failure. Chi phí cao hơn (Managed Instance đắt hơn SQL DB PaaS), không đáp ứng "without data loss" và không tối ưu costs.

  • ❌ Azure SQL Database Hyperscale
    Sai 🔴: Hyperscale hỗ trợ zone-redundant HA synchronous tốt (RPO=0), nhưng chi phí rất cao (dành cho DB >1TB, tính theo storage scale-out), không minimize costs. Phù hợp big data chứ không phải giải pháp tiết kiệm cho DB1 thông thường.

📚 Tài liệu tham khảo (cập nhật mới nhất 2026)

Hy vọng phân tích giúp bạn hiểu rõ! Nếu cần cấu hình thực tế, tôi có thể hướng dẫn script PowerShell/Portal. 🚀

Câu 198
You have an Azure subscription that contains an Azure SQL database named DB1.

You need to host elastic jobs by using DB1. DB1 will also be configured as a job target. The solution must support the use of location-based Conditional Access policies.

What should the elastic jobs use to access DB1?
  1. A a system-assigned managed identity
  2. B Azure SQL sign-in credentials
  3. C database-scoped credentials
  4. D a user-assigned managed identity
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai Elastic Jobs trong Azure SQL Database. Cụ thể:

  • Bạn có một Azure subscription chứa Azure SQL database tên DB1.
  • Yêu cầu: Sử dụng DB1 để host elastic jobs (chạy các công việc đàn hồi trên nhiều database), đồng thời DB1 cũng là job target (mục tiêu thực thi job).
  • Giải pháp phải hỗ trợ location-based Conditional Access policies (chính sách truy cập có điều kiện dựa trên vị trí địa lý/IP, được quản lý bởi Azure AD).
  • Câu hỏi yêu cầu xác định cơ chế xác thực mà elastic jobs nên sử dụng để truy cập DB1, đảm bảo tính bảo mật và tuân thủ chính sách Conditional Access (cập nhật theo tài liệu Microsoft Azure đến năm 2026, phiên bản Azure SQL Elastic Jobs preview/general availability mới nhất).

Mục tiêu chính: Elastic Jobs cần một managed identity linh hoạt để authenticate với Azure AD, hỗ trợ kiểm soát truy cập dựa trên vị trí mà không bị ràng buộc bởi resource cụ thể.

📘 Tài liệu tham khảo:

✅ Đáp án đúng

a user-assigned managed identity
Lý do lựa chọn:
🛠️ Elastic Jobs yêu cầu một user-assigned managed identity (được tạo riêng biệt và gán cho job agent database như DB1) để truy cập targets. Điều này cho phép Azure AD Conditional Access policies dựa trên vị trí (location-based) áp dụng hiệu quả, vì user-assigned identity hoạt động như service principal độc lập, hỗ trợ kiểm tra IP/địa lý khi authenticate. System-assigned không hỗ trợ tính năng này do ràng buộc với resource cụ thể. Đây là yêu cầu bắt buộc theo docs Azure SQL (cập nhật 2026).

🧩 Giải thích tất cả các phương án

  • ❌ a system-assigned managed identity
    Sai vì system-assigned managed identity được gắn cố định với một resource cụ thể (như DB1), không hỗ trợ location-based Conditional Access policies. Nó chỉ dùng cho authenticate nội bộ đơn giản, không linh hoạt cho Elastic Jobs khi DB1 vừa là host vừa là target, dẫn đến vi phạm chính sách vị trí địa lý.

  • ❌ Azure SQL sign-in credentials
    Sai vì đây là phương thức xác thực SQL truyền thống (username/password), không tích hợp với Azure AD hay Conditional Access. Elastic Jobs yêu cầu managed identity để bảo mật cao, không dùng SQL auth vì thiếu hỗ trợ MFA/CA và không phù hợp với job agent.

  • ❌ database-scoped credentials
    Sai vì database-scoped credentials chỉ dùng để truy cập external data sources (như storage/file), không dành cho Elastic Jobs authenticate với Azure SQL targets. Nó không liên kết với Azure AD, nên không hỗ trợ bất kỳ Conditional Access policy nào.

  • ✅ a user-assigned managed identity
    Đúng như đã giải thích ở trên. Đây là lựa chọn duy nhất đáp ứng đầy đủ yêu cầu: host/target trên DB1 + hỗ trợ location-based CA (kiểm soát truy cập dựa trên IP/vị trí qua Azure AD).

🛠️ Lưu ý bổ sung: Để triển khai, tạo user-assigned MI qua Azure Portal/CLI, gán cho DB1 làm job agent, và cấp role Sql Elastic Jobs Executor trên targets. Kiểm tra CA policies trong Entra ID (trước đây là Azure AD).

Câu 199
You have an instance of SQL Server on Azure Virtual Machines named SQL1.

SQL1 contains an Extended Events session named session1 that captures Microsoft SQL Server events.

You need to correlate the session events with events captured by Event Tracing for Windows (ETW).

What should you do for session1?
  1. A Modify the Set Session Event Filters settings.
  2. B Add a target.
  3. C Add an action.
  4. D Modify the Specify Session Data Storage settings.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm

📘 Nội dung câu hỏi:
Câu hỏi mô tả một tình huống thực tế trong môi trường Azure Virtual Machines (VM) chạy SQL Server (phiên bản mới nhất hỗ trợ Extended Events, như SQL Server 2022 trở lên). Bạn có một instance SQL Server tên SQL1 trên Azure VM, và trong đó có một Extended Events session tên session1 đang thu thập các sự kiện (events) từ Microsoft SQL Server.
Yêu cầu chính: Cần tương quan (correlate) các sự kiện từ session1 này với các sự kiện được thu thập bởi Event Tracing for Windows (ETW) – một công cụ tracing hệ thống của Windows dùng để theo dõi hoạt động kernel và ứng dụng.
Mục tiêu là liên kết dữ liệu từ Extended Events (XEvents) của SQL Server với dữ liệu ETW để phân tích sâu hơn, chẳng hạn như debug performance hoặc troubleshooting.
Bối cảnh kỹ thuật: Extended Events là tính năng mạnh mẽ trong SQL Server (từ SQL Server 2008 trở lên, cập nhật mới nhất đến 2026 vẫn giữ nguyên cơ chế), cho phép thu thập events với ít overhead hơn SQL Trace. Để correlate với ETW, cần cấu hình đặc biệt để xuất events ra ETW stream.

✅ Đáp án đúng: Add a target.
Lý do lựa chọn:
Trong Extended Events, để correlate events với ETW, bạn phải thêm một target đặc biệt gọi là ETW target (etw_classic_sync_target hoặc tương tự). Target này sẽ xuất các events từ session1 ra ETW session, cho phép công cụ như XPerf hoặc WPA (Windows Performance Analyzer) correlate chúng với ETW traces. Đây là bước duy nhất và chính xác theo tài liệu Microsoft. Không làm vậy, events chỉ lưu nội bộ trong session mà không liên kết được với ETW.
(Kiến thức cập nhật: SQL Server 2022/2024 trên Azure VM hỗ trợ đầy đủ ETW target cho correlation, không thay đổi đến 2026).

🛠️ Giải thích tất cả các phương án (đúng/sai):

  • ❌ Modify the Set Session Event Filters settings.
    Phương án này sai vì Set Session Event Filters chỉ dùng để lọc events (filter theo điều kiện như database_id, sql_text, v.v.) trước khi thu thập. Nó không liên quan đến việc xuất hoặc correlate dữ liệu ra ETW. Nếu sửa filters, bạn chỉ thay đổi events được capture, không tạo liên kết với ETW traces.

  • ✅ Add a target.
    Đúng như đã giải thích ở trên. Thêm ETW target (qua T-SQL: ADD TARGET package0.etw_classic_sync_target hoặc qua SSMS wizard) sẽ push events từ session1 vào ETW provider, cho phép correlation thời gian thực hoặc offline. Đây là cách chuẩn để integrate XEvents với ETW.

  • ❌ Add an action.
    Phương án này sai vì actions chỉ thu thập dữ liệu bổ sung (như sql_text, session_id, timestamp) gắn kèm với mỗi event khi nó fire. Actions giúp enrich data trong session nhưng không export ra ETW hay tạo correlation. Chúng chỉ hoạt động nội bộ trong XEvents.

  • ❌ Modify the Specify Session Data Storage settings.
    Phương án này sai vì Specify Session Data Storage chỉ cấu hình nơi lưu trữ data của session (như ring_buffer, file target, histogram). Nó kiểm soát storage nội bộ của XEvents, không liên kết hay xuất ra ETW. Sửa setting này chỉ ảnh hưởng đến cách lưu events trong SQL Server, không correlate với Windows ETW.

📚 Tài liệu tham khảo:

💡 Lời khuyên từ Azure DBA: Nếu triển khai trên Azure VM, hãy dùng Azure Monitor hoặc Log Analytics để collect ETW traces kết hợp, và test session bằng T-SQL: ALTER EVENT SESSION [session1] ON SERVER ADD TARGET package0.etw_classic_sync_target(SET buffering_mode=drop_if_full);. Luôn ALTER EVENT SESSION trước khi start để tránh data loss! 🚀

Câu 200
You have an on-premises Microsoft SQL Server 2019 database named SQL1 that uses merge replication.

You need to migrate SQL1 to Azure.

Which service should you use?
  1. A Azure SQL Edge
  2. B Azure SQL Database
  3. C SQL Server on Azure Virtual Machines
  4. D Azure SQL Managed Instance
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi yêu cầu chọn dịch vụ Azure phù hợp để migrate (di chuyển) một cơ sở dữ liệu Microsoft SQL Server 2019 on-premises có tên SQL1, đang sử dụng merge replication sang Azure.
Merge replication là một tính năng replication nâng cao của SQL Server, cho phép đồng bộ hóa dữ liệu hai chiều giữa publisher và subscriber, hỗ trợ giải quyết xung đột dữ liệu (conflict resolution), thường dùng cho môi trường phân tán như mobile hoặc offline sync.
Vấn đề chính: Không phải tất cả dịch vụ Azure SQL đều hỗ trợ đầy đủ merge replication (chỉ hỗ trợ trên SQL Server full-featured). Việc migrate phải giữ nguyên tính năng này mà không cần thay đổi lớn về kiến trúc. ✅

✅ Đáp án đúng: SQL Server on Azure Virtual Machines

Lý do chọn đáp án này:

  • Đây là dịch vụ IaaS (Infrastructure as a Service), cho phép chạy SQL Server 2019 đầy đủ tính năng (on-premises like) trên máy ảo Azure VM.
  • Merge replication được hỗ trợ 100% giống như on-premises, không có hạn chế. Bạn có thể migrate bằng Azure Database Migration Service (DMS) hoặc backup/restore, sau đó cấu hình replication trực tiếp.
  • Phù hợp cho workload phức tạp cần full SQL Server engine, bao gồm replication, agent jobs, v.v. 🛠️
    (Cập nhật 2024-2026: SQL Server 2022/2025 trên Azure VM vẫn hỗ trợ merge replication không thay đổi - Microsoft xác nhận không deprecated).

📋 Giải thích tất cả các phương án (đúng/sai)

  • ✅ [ĐÚNG] SQL Server on Azure Virtual Machines
    Phương án này hoàn toàn đúng vì cung cấp môi trường SQL Server đầy đủ trên VM, hỗ trợ merge replication native mà không cần chỉnh sửa schema hoặc topology. Lý tưởng cho lift-and-shift migration.

  • ❌ [SAI] Azure SQL Edge
    Phương án này sai vì Azure SQL Edge là phiên bản lightweight của SQL Server dành cho IoT/edge computing (như Raspberry Pi, containerized edge devices). Nó không hỗ trợ merge replication (chỉ hỗ trợ snapshot/transactional replication hạn chế), và không phù hợp migrate database lớn on-premises.

  • ❌ [SAI] Azure SQL Database
    Phương án này sai vì Azure SQL Database là PaaS serverless/hyperscale, không hỗ trợ merge replication (chỉ hỗ trợ transactional replication outbound). Merge replication yêu cầu SQL Agent đầy đủ, mà Azure SQL DB không có. Phải refactor ứng dụng lớn.

  • ❌ [SAI] Azure SQL Managed Instance
    Phương án này sai vì dù là PaaS gần on-premises nhất (hỗ trợ 90% features SQL Server), nhưng không hỗ trợ merge replication (chỉ hỗ trợ transactional/snapshot replication). Microsoft liệt kê rõ ràng trong limitations: merge bị loại trừ do phụ thuộc Distributor phức tạp.

📘 Tài liệu tham khảo (cập nhật mới nhất 2024-2026)

Hy vọng phân tích giúp bạn nắm vững! 🚀 Nếu cần demo migration, hãy hỏi thêm nhé!