Ngân hàng đề — Microsoft Azure Developer

Tìm thấy 409 câu.

Câu 391 Chọn nhiều đáp án
You are a developer for a company that recently transitioned to using workspace-based Application Insights for a C# .NET web application that runs on Azure.

The application has intermittent performance issues.

You need to use the AI-powered code analysis feature in Application Insights to help diagnose the problem.

What should you do?
  1. A Enable and configure smart detection.
  2. B Enable and configure availability tests.
  3. C Use the Application Map to visualize dependencies and interactions, then trace the performance issues through the map.
  4. D Enable the profiler and snapshot debugger.
  5. E Configure continuous export of telemetry data to Azure Storage.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi

Câu hỏi gốc:
You are a developer for a company that recently transitioned to using workspace-based Application Insights for a C# .NET web application that runs on Azure.
The application has intermittent performance issues.
You need to use the AI-powered code analysis feature in Application Insights to help diagnose the problem.
What should you do?

📝 Giải thích nội dung câu hỏi:
Câu hỏi mô tả tình huống một lập trình viên làm việc cho công ty đã chuyển sang sử dụng Application Insights dựa trên workspace (mô hình mới hơn, tích hợp với Log Analytics workspace trong Azure) cho ứng dụng web C# .NET chạy trên Azure. Ứng dụng gặp vấn đề hiệu suất gián đoạn (intermittent performance issues), nghĩa là hiệu suất không ổn định, lúc tốt lúc kém.
Nhiệm vụ là sử dụng tính năng phân tích mã nguồn hỗ trợ AI (AI-powered code analysis feature) trong Application Insights để chẩn đoán vấn đề.
🛠️ Workspace-based Application Insights là phiên bản cập nhật (từ năm 2020 trở đi, vẫn là chuẩn đến 2026), cho phép truy vấn dữ liệu telemetry qua Kusto Query Language (KQL) và hỗ trợ các công cụ AI/ML tiên tiến hơn. Vấn đề tập trung vào performance issues, nên cần các tính năng tự động phát hiện bất thường và phân tích sâu mã nguồn.

✅ Đáp án đúng (Multiple Choice - Chọn tất cả phù hợp):
Có hai phương án đúng vì câu hỏi yêu cầu sử dụng tính năng AI-powered code analysis để chẩn đoán performance issues gián đoạn:

  1. Enable and configure smart detection.
  2. Enable the profiler and snapshot debugger.

🔍 Lý do chọn các đáp án đúng (dựa trên tài liệu Azure mới nhất 2026):

  • Smart Detection (nay tích hợp trong Anomaly Detection) sử dụng AI/ML để tự động phát hiện các bất thường hiệu suất (performance anomalies) như thời gian phản hồi chậm đột ngột, phù hợp hoàn hảo với "intermittent performance issues". Nó phân tích dữ liệu telemetry thời gian thực và gửi cảnh báo mà không cần cấu hình phức tạp.
  • Profiler và Snapshot Debugger cung cấp phân tích mã nguồn chi tiết (code-level analysis) với AI hỗ trợ: Profiler thu thập traces hiệu suất (CPU, memory), còn Snapshot Debugger chụp ảnh trạng thái code khi có vấn đề, giúp xác định bottlenecks chính xác. Đây là các tính năng AI-powered trong Application Insights cho developer.
    💡 Lưu ý cập nhật 2026: Theo Azure Monitor docs, các tính năng này được tối ưu cho workspace-based, với ML models cải tiến (như trong Azure AI services integration).

📘 Giải thích tất cả các phương án (với phân loại đúng/sai)

  • ✅ Enable and configure smart detection.
    Giải thích đúng: Đây là tính năng AI/ML cốt lõi của Application Insights, tự động phát hiện và phân tích các vấn đề hiệu suất gián đoạn qua Smart Detection panels (Performance anomalies, Failure anomalies). Khi enable, nó sử dụng machine learning để baseline hành vi bình thường và alert bất thường, giúp diagnose nhanh mà không cần can thiệp thủ công. Hoàn toàn phù hợp với yêu cầu "AI-powered code analysis".

  • ❌ Enable and configure availability tests.
    Giải thích sai: Availability Tests (hay Synthetic Tests) chỉ kiểm tra tính khả dụng (uptime) bằng cách ping URL định kỳ từ các vị trí toàn cầu, không liên quan đến phân tích mã nguồn hoặc performance issues nội bộ. Nó không sử dụng AI cho code analysis mà chỉ báo cáo downtime.

  • ❌ Use the Application Map to visualize dependencies and interactions, then trace the performance issues through the map.
    Giải thích sai: Application Map là công cụ visualization dependencies (hiển thị dịch vụ, endpoints tương tác), hữu ích để trace end-to-end nhưng không phải AI-powered code analysis. Nó dựa trên telemetry traces thủ công, không tự động detect anomalies ở mức code-level.

  • ✅ Enable the profiler and snapshot debugger.
    Giải thích đúng: Profiler thu thập dữ liệu hiệu suất chi tiết (hot path analysis với AI optimization), còn Snapshot Debugger chụp snapshot code khi exception/performance drop xảy ra. Cả hai đều là AI-powered features trong Application Insights (tích hợp ML để prioritize issues), lý tưởng cho intermittent performance trên .NET apps. Enable qua portal hoặc SDK.

  • ❌ Configure continuous export of telemetry data to Azure Storage.
    Giải thích sai: Continuous Export chỉ xuất dữ liệu telemetry (logs, metrics) ra Storage để lưu trữ dài hạn hoặc tích hợp bên thứ ba, không phải công cụ phân tích AI hay diagnose performance. Nó là passive export, không có code analysis tự động.

📚 Tài liệu tham khảo (cập nhật mới nhất 2026)

Hy vọng phân tích này giúp bạn chẩn đoán hiệu quả! 🚀 Nếu cần code sample, hãy hỏi thêm.

Câu 392
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You deploy an Azure Container Apps app and disable ingress on the container app.

Users report that they are unable to access the container app. You investigate and observe that the app has scaled to 0 instances.

You need to resolve the issue with the container app.

Solution: Enable ingress, create an TCP scale rule, and apply the rule to the container app.

Does the solution meet the goal?
  1. A Yes
  2. B No
Xem giải thích

🧩 Giải thích chi tiết nội dung câu hỏi

Câu hỏi thuộc dạng case study (series of questions) trong kỳ thi chứng chỉ Azure (như AZ-204 hoặc AZ-305), nơi mỗi câu đưa ra một tình huống và một giải pháp cụ thể, yêu cầu đánh giá xem giải pháp đó có đạt được mục tiêu hay không.

Tình huống (Scenario):

  • Bạn đã triển khai một ứng dụng Azure Container Apps và tắt ingress (disable ingress) trên ứng dụng container.
  • Người dùng báo lỗi không thể truy cập ứng dụng.
  • Khi kiểm tra, bạn thấy ứng dụng đã scale xuống 0 instances (không có instance nào đang chạy).

Mục tiêu (Goal): Giải quyết vấn đề để người dùng có thể truy cập ứng dụng (tức là đảm bảo ứng dụng có instances chạy và có thể tiếp nhận traffic).

Giải pháp đề xuất (Solution):

  • Bật ingress (Enable ingress).
  • Tạo một TCP scale rule (create a TCP scale rule).
  • Áp dụng rule đó vào container app (apply the rule to the container app).

Câu hỏi chính: Giải pháp này có đạt được mục tiêu không? (Does the solution meet the goal?)

Nguyên nhân gốc rễ vấn đề 🛠️:

  • Disable ingress ngăn chặn tất cả traffic vào ứng dụng (bao gồm HTTP/HTTPS hoặc TCP), dẫn đến không có metric trigger scaling (như concurrent requests hoặc connections).
  • Azure Container Apps sử dụng KEDA (Kubernetes Event-Driven Autoscaling) để scale dựa trên rules (HTTP, TCP, CPU, memory, v.v.). Nếu không có traffic và minReplicas = 0 (mặc định), app sẽ scale xuống 0 để tiết kiệm chi phí.
  • Kết quả: Ứng dụng "ngủ đông" (cold start), người dùng không truy cập được vì không có instance xử lý request đầu tiên.

Phiên bản kiến thức cập nhật (tính đến 2026): Dựa trên tài liệu Azure Container Apps mới nhất (GA từ 2022, cập nhật scaling KEDA v2.x), ingress hỗ trợ HTTP/HTTPS (Layer 7) hoặc TCP (Layer 4). Scaling rules bao gồm HTTP (concurrent requests), TCP (concurrent connections), và các loại khác. Giải pháp phải chính xác loại rule để trigger scale đúng workload (thường là HTTP cho web apps).

✅ Đáp án đúng: No

Lý do lựa chọn 📝:
Giải pháp KHÔNG đạt mục tiêu vì:

  • Enable ingress là bước đúng để cho phép traffic vào, nhưng không giải quyết triệt để scaling to 0.
  • TCP scale rule chỉ phù hợp với workload TCP thuần (ví dụ: TCP proxy, database connections), scale dựa trên concurrent TCP connections đến một port cụ thể. Tuy nhiên, hầu hết Container Apps (web apps) sử dụng HTTP traffic (Layer 7), nên TCP rule không trigger đúng khi có HTTP requests.
  • Kết quả: App vẫn có thể scale to 0 nếu traffic là HTTP, dẫn đến cold start timeout. Giải pháp đúng cần HTTP scale rule (concurrent HTTP requests) hoặc minReplicas >=1 để luôn có instance sẵn sàng.
  • Theo docs Azure 2026: TCP rule yêu cầu expose TCP port cụ thể qua ingress, không xử lý HTTP paths/headers như HTTP rule.

🔍 Phân tích tất cả các phương án (Giữ nguyên văn bản gốc bằng tiếng Anh)

  • Yes ❌ SAI - Phương án này sai vì giải pháp đề xuất không hoàn chỉnh và không phù hợp. Enable ingress chỉ mở đường traffic, nhưng TCP scale rule không trigger scale cho traffic HTTP thông thường (phổ biến ở Container Apps web). App vẫn scale to 0 khi không có TCP connections, người dùng vẫn gặp lỗi cold start. Không đạt goal resolve access issue.

  • No ✅ ĐÚNG - Phương án này đúng vì giải pháp không meet the goal. TCP scale rule không phải lựa chọn chuẩn cho vấn đề (scale to 0 do thiếu HTTP traffic sau disable ingress). Cần HTTP scale rule (ví dụ: scale trên concurrent requests >0) hoặc cấu hình minReplicas=1 để app luôn chạy. Giải pháp chỉ partial fix (ingress), thiếu scale trigger chính xác.

📘 Tài liệu tham khảo (Nguồn chính thức AWS? Lưu ý: Đây là Azure, không phải AWS)

Câu 393
Case study -

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.


To start the case study -
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.


Background -

Fourth Coffee is a global coffeehouse chain and coffee company recognized as one of the world’s most influential coffee brands. The company is renowned for its specialty coffee beverages, including a wide range of espresso-based drinks, teas, and other beverages. Fourth Coffee operates thousands of stores worldwide.


Current environment -

The company is developing cloud-native applications hosted in Azure.


Corporate website -
The company hosts a public website located at http://www.fourthcoffee.com/. The website is used to place orders as well as view and update inventory items.


Inventory items -
In addition to its core coffee offerings, Fourth Coffee recently expanded its menu to include inventory items such as lunch items, snacks, and merchandise. Corporate team members constantly update inventory. Users can customize items. Corporate team members configure inventory items and associated images on the website.


Orders -
Associates in the store serve customized beverages and items to customers. Orders are placed on the website for pickup.

The application components process data as follows:

1. Azure Traffic Manager routes a user order request to the corporate website hosted in Azure App Service.
2. Azure Content Delivery Network serves static images and content to the user.
3. The user signs in to the application through a Microsoft Entra ID for customers tenant.
4. Users search for items and place an order on the website as item images are pulled from Azure Blob Storage.
5. Item customizations are placed in an Azure Service Bus queue message.
6. Azure Functions processes item customizations and saves the customized items to Azure Cosmos DB.
7. The website saves order details to Azure SQL Database.
8. SQL Database query results are cached in Azure Cache for Redis to improve performance.

The application consists of the following Azure services:




Requirements -

The application components must meet the following requirements:

•Azure Cosmos DB development must use a native API that receives the latest updates and stores data in a document format.
•Costs must be minimized for all Azure services.
•Developers must test Azure Blob Storage integrations locally before deployment to Azure. Testing must support the latest versions of the Azure Storage APIs.


Corporate website -
•User authentication and authorization must allow one-time passcode sign-in methods and social identity providers (Google or Facebook).
•Static web content must be stored closest to end users to reduce network latency.


Inventory items -
•Customized items read from Azure Cosmos DB must maximize throughput while ensuring data is accurate for the current user on the website.
•Processing of inventory item updates must automatically scale and enable updates across an entire Azure Cosmos DB container.
•Inventory items must be processed in the order they were placed in the queue.
•Inventory item images must be stored as JPEG files in their native format to include exchangeable image file format (data) stored with the blob data upon upload of the image file.
•The Inventory Items API must securely access the Azure Cosmos DB data.


Orders -
•Orders must receive inventory item changes automatically after inventory items are updated or saved.


Issues -

•Developers are storing the Azure Cosmos DB credentials in an insecure clear text manner within the Inventory Items API code.
•Production Azure Cache for Redis maintenance has negatively affected application performance.


You need to support local development testing for developers.

Which tool should you use?
  1. A Azurite
  2. B Azure Storage Emulator
  3. C SQL Server Management Studio (SSMS)
  4. D Azure Storage Explorer
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm

📖 Nội dung câu hỏi:
Câu hỏi thuộc phần case study về công ty Fourth Coffee, một chuỗi cà phê toàn cầu đang phát triển ứng dụng cloud-native trên Azure. Kiến trúc hệ thống bao gồm các dịch vụ như Azure Traffic Manager, Azure App Service (corporate website), Azure Content Delivery Network, Microsoft Entra ID, Azure Service Bus (queue cho inventory items), Azure Functions (xử lý inventory), Azure Cosmos DB (lưu inventory items), Azure SQL Database (lưu orders), Azure Cache for Redis (cache query results), và Azure Blob Storage (lưu inventory item images - hình ảnh sản phẩm).

Hình ảnh kiến trúc (đã phân tích kỹ) minh họa luồng dữ liệu:

  • Web browser → Azure CDN → Azure Traffic Manager → Corporate website (App Service).
  • Website kết nối Microsoft Entra ID (xác thực), Azure Blob Storage (hình ảnh items).
  • Orders/customizations → Azure Service Bus queue → Azure Functions → Azure Cosmos DB (items) và Azure SQL DB (orders).
  • Cache: Azure Cache for Redis.

Vấn đề chính (Issues & Requirements liên quan):

  • Developers cần test tích hợp Azure Blob Storage locally trước khi deploy lên Azure.
  • Testing phải hỗ trợ phiên bản mới nhất của Azure Storage APIs (theo kiến thức cập nhật đến 2026, bao gồm Azure Storage Client Library v12+ và các tính năng mới như hierarchical namespace trong Data Lake Gen2).
  • Mục tiêu: Hỗ trợ local development testing cho developers, tập trung vào Blob Storage (lưu JPEG images với metadata EXIF native).

Câu hỏi yêu cầu chọn tool phù hợp để hỗ trợ testing local này.

✅ Đáp án đúng: Azurite
Lý do chọn (chi tiết):
Azurite là công cụ emulator mã nguồn mở chính thức từ Microsoft, thay thế cho Azure Storage Emulator cũ, dành riêng cho local development và testing Azure Storage services (Blob, Queue, Table, v.v.). Nó hỗ trợ đầy đủ latest Azure Storage APIs (v12+), bao gồm các tính năng mới nhất đến 2026 như Blob versioning, soft delete, customer-managed keys, và hierarchical namespaces. Trong case study, developers cần test Blob Storage integrations (hình ảnh inventory items) locally mà không cần tài khoản Azure thật, giúp giảm chi phí và tăng tốc dev. Azurite chạy như Docker container hoặc standalone, tích hợp dễ dàng với Visual Studio Code, Azure Functions local, và SDKs mới nhất.

🛠️ Giải thích tất cả các phương án (đúng/sai):

  • Azurite ✅ Đúng
    Như đã giải thích, Azurite là lựa chọn tối ưu cho local testing Blob Storage với hỗ trợ APIs mới nhất, phù hợp yêu cầu "Developers must test Azure Blob Storage integrations locally before deployment to Azure. Testing must support the latest versions of the Azure Storage APIs." Nó emulator chính xác Blob endpoints (http://127.0.0.1:10000/devstoreaccount1 cho blob).

  • Azure Storage Emulator ❌ Sai
    Đây là công cụ emulator cũ (deprecated từ 2017), chỉ hỗ trợ APIs cũ (v2017-07-29 trở về trước), không tương thích với Storage Library v12+ và các tính năng mới (như Data Lake Gen2 full). Microsoft khuyến nghị migrate sang Azurite. Không phù hợp cho testing latest APIs trong case study.

  • SQL Server Management Studio (SSMS) ❌ Sai
    SSMS là GUI tool quản lý SQL Server (bao gồm Azure SQL DB), dùng để query, thiết kế database. Không liên quan đến testing Blob Storage locally; case study dùng Azure SQL DB cho orders, nhưng yêu cầu là Blob Storage (images), không phải SQL.

  • Azure Storage Explorer ❌ Sai
    Đây là công cụ GUI desktop để quản lý và khám phá Azure Storage accounts (kết nối cloud hoặc local emulator), không phải emulator để chạy local server thay thế Blob Storage. Nó chỉ hỗ trợ browse data, không simulate APIs cho code testing như Azurite.

📘 Tài liệu tham khảo (cập nhật mới nhất 2026):

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! ☕🚀

Câu 394
Case study -

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.


To start the case study -
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.


Background -

Munson’s Pickles and Preserves Farm is an agricultural cooperative corporation based in Washington, US, with farms located across the United States. The company supports agricultural production resources by distributing seeds fertilizers, chemicals, fuel, and farm machinery to the farms.


Current Environment -

The company is migrating all applications from an on-premises datacenter to Microsoft Azure. Applications support distributors, farmers, and internal company staff.


Corporate website -
•The company hosts a public website located at http://www.munsonspicklesandpreservesfarm.com. The site supports farmers and distributors who request agricultural production resources.


Farms -
•The company created a new customer tenant in the Microsoft Entra admin center to support authentication and authorization for applications.


Distributors -
•Distributors integrate their applications with data that is accessible by using APIs hosted at http://www.munsonspicklesandpreservesfarm.com/api to receive and update resource data.


Requirements -

The application components must meet the following requirements:


Corporate website -
•The site must be migrated to Azure App Service.
•Costs must be minimized when hosting in Azure.
•Applications must automatically scale independent of the compute resources.
•All code changes must be validated by internal staff before release to production.
•File transfer speeds must improve, and webpage-load performance must increase.
•All site settings must be centrally stored, secured without using secrets, and encrypted at rest and in transit.
•A queue-based load leveling pattern must be implemented by using Azure Service Bus queues to support high volumes of website agricultural production resource requests.


Farms -
•Farmers must authenticate to applications by using Microsoft Entra ID.


Distributors -
•The company must track a custom telemetry value with each API call and monitor performance of all APIs.
•API telemetry values must be charted to evaluate variations and trends for resource data.


Internal staff -
•App and API updates must be validated before release to production.
•Staff must be able to select a link to direct them back to the production app when validating an app or API update.
•Staff profile photos and email must be displayed on the website once they authenticate to applications by using their Microsoft Entra ID.


Security -
•All web communications must be secured by using TLS/HTTPS.
•Web content must be restricted by country/region to support corporate compliance standards.
•The principle of least privilege must be applied when providing any user rights or process access rights.
•Managed identities for Azure resources must be used to authenticate services that support Microsoft Entra ID authentication.


Issues -


Corporate website -
•Farmers report HTTP 503 errors at the same time as internal staff report that CPU and memory usage are high.
•Distributors report HTTP 502 errors at the same time as internal staff report that average response times and networking traffic are high.
•Internal staff report webpage load sizes are large and take a long time to load.
•Developers receive authentication errors to Service Bus when they debug locally.


Distributors -
•Many API telemetry values are sent in a short period of time. Telemetry traffic, data costs, and storage costs must be reduced while preserving a statistically correct analysis of the data points sent by the APIs.


You need to secure the corporate website to meet the security requirements.

What should you do?
  1. A Create an Azure Cache for Redis instance. Update the code to support the cache.
  2. B Create an Azure Content Delivery Network profile and endpoint. Configure the endpoint.
    С. Create an App Service instance with a standard plan. Configure the custom domain with a TLS/SSL certificate.
  3. C Create an Azure Application Gateway with a Web Application Firewall (WAF). Configure end-to-end TLS encryption and the WAF.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm

📖 Nội dung câu hỏi:
Câu hỏi thuộc phần case study về công ty Munson’s Pickles and Preserves Farm, đang di chuyển ứng dụng từ on-premises sang Microsoft Azure. Cụ thể, câu hỏi tập trung vào việc bảo mật trang web công ty (corporate website) để đáp ứng các yêu cầu bảo mật (Security requirements):

  • Tất cả giao tiếp web phải được bảo mật bằng TLS/HTTPS.
  • Nội dung web phải bị hạn chế theo quốc gia/vùng (country/region) để tuân thủ tiêu chuẩn tuân thủ doanh nghiệp.
  • Áp dụng nguyên tắc quyền hạn tối thiểu (principle of least privilege).
  • Sử dụng Managed Identities cho các tài nguyên Azure để xác thực dịch vụ hỗ trợ Microsoft Entra ID.

Vấn đề hiện tại bao gồm lỗi HTTP 503/502, tải trang chậm, nhưng câu hỏi chính là "You need to secure the corporate website to meet the security requirements. What should you do?" – Nghĩa là cần chọn giải pháp bảo mật tốt nhất cho trang web đã migrate sang Azure App Service, với các tính năng như end-to-end TLS, WAF (Web Application Firewall), và geo-filtering.

✅ Đáp án đúng:
Create an Azure Application Gateway with a Web Application Firewall (WAF). Configure end-to-end TLS encryption and the WAF.

Lý do lựa chọn (chi tiết):
🛡️ Azure Application Gateway (v2, phiên bản mới nhất đến 2026) là dịch vụ load balancer layer 7 tích hợp WAF (dựa trên OWASP ruleset cập nhật), hỗ trợ end-to-end TLS/HTTPS (bao gồm TLS termination và re-encryption), geo-filtering (hạn chế truy cập theo quốc gia/vùng qua policy), và tuân thủ nguyên tắc least privilege qua managed identities. Giải pháp này đặt trước App Service, bảo vệ toàn diện trang web công ty (http://www.munsonspicklesandpreservesfarm.com), giảm thiểu rủi ro tấn công web, đồng thời giải quyết vấn đề HTTP 502/503 bằng autoscaling và session affinity. Đây là best practice cho security gateway trong Azure (không cần code changes lớn).

📘 Tài liệu tham khảo:

🔍 Giải thích tất cả các phương án trả lời

  • ❌ Create an Azure Cache for Redis instance. Update the code to support the cache.
    Phương án này sai vì Azure Cache for Redis chỉ dùng để caching dữ liệu nhằm cải thiện hiệu suất (giảm tải CPU/memory, tăng tốc file transfer và webpage load), không liên quan đến bảo mật TLS/HTTPS, WAF, hay geo-restriction. Nó không đáp ứng bất kỳ security requirement nào, chỉ giải quyết phần Issues về tải chậm chứ không phải secure website.

  • ❌ Create an Azure Content Delivery Network profile and endpoint. Configure the endpoint.
    Phương án này sai vì Azure CDN (Azure Front Door hoặc CDN Standard/Premium) chủ yếu cải thiện performance (tăng tốc webpage load, giảm latency toàn cầu), hỗ trợ HTTPS nhưng không có WAF đầy đủ (CDN Premium có một phần OWASP nhưng kém linh hoạt hơn Application Gateway), và geo-filtering chỉ cơ bản (không mạnh bằng policy của App Gateway). Không đảm bảo end-to-end TLS toàn diện hay least privilege cho Entra ID, chỉ phù hợp cho content delivery chứ không phải secure gateway chính.

  • ❌ C. Create an App Service instance with a standard plan. Configure the custom domain with a TLS/SSL certificate.
    Phương án này sai vì Azure App Service (Standard plan) hỗ trợ TLS/SSL binding cho custom domain và autoscaling, nhưng thiếu geo-filtering built-in (phải dùng IP restrictions hạn chế, không theo country chính xác), không có WAF native (phải tích hợp ngoài), và không phải là lớp bảo mật layer 7 toàn diện. Website đã migrate sang App Service rồi, thêm cái này chỉ duplicate mà không giải quyết đầy đủ security requirements như restrict by region hay advanced WAF.

  • ✅ Create an Azure Application Gateway with a Web Application Firewall (WAF). Configure end-to-end TLS encryption and the WAF.
    Như đã giải thích ở trên, đây là đúng vì bao quát toàn bộ security needs: WAF chống tấn công, end-to-end TLS, geo-filtering, managed identities, đặt trước App Service để bảo vệ traffic inbound. Hoàn hảo cho case study này! 🎯

Câu 395
You have an on-premises, public-facing website named www.contoso.com.

You plan to test availability of www.contoso.com by using Application Insights availability tests.

You need to configure a test that will generate HTTP POST requests that include custom headers. Your solution must minimize development effort.

Which type of test should you configure?
  1. A Multi-step web test
  2. B Standard test
  3. C URL ping test
  4. D Custom TrackAvailability test
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc kiểm tra tính khả dụng (availability tests) của một website công khai on-premises có tên www.contoso.com bằng công cụ Application Insights trong Azure Monitor.

  • Bối cảnh: Website đang chạy on-premises (không phải cloud), nhưng bạn muốn sử dụng Application Insights để test từ xa qua internet công khai.
  • Yêu cầu cụ thể: Cấu hình một loại test gửi HTTP POST requests kèm custom headers (tiêu đề tùy chỉnh).
  • Ràng buộc quan trọng: Giải pháp phải tối thiểu hóa nỗ lực phát triển (minimize development effort), nghĩa là ưu tiên cấu hình qua giao diện Azure Portal mà không cần viết code phức tạp.

🛠️ Mục tiêu: Chọn loại availability test phù hợp nhất trong Application Insights (phiên bản cập nhật mới nhất đến 2026, theo tài liệu Azure Monitor), hỗ trợ POST + custom headers mà dễ cấu hình nhất.

📘 Tài liệu tham khảo:

✅ Đáp án đúng: Standard test

Lý do lựa chọn:

  • Standard test (hay Standard web test) là loại test cơ bản nhưng mạnh mẽ trong Application Insights, cho phép cấu hình HTTP POST requests kèm custom headers trực tiếp qua Azure Portal mà không cần code.
  • Bạn chỉ cần nhập URL, chọn method POST, thêm headers (ví dụ: Authorization: Bearer token), body request, và các thông số khác qua giao diện wizard – hoàn toàn zero-code, giảm thiểu nỗ lực phát triển tối đa.
  • Test sẽ chạy từ nhiều vị trí toàn cầu (25+ locations), gửi POST định kỳ (mỗi 5 phút), và cảnh báo nếu thất bại.
  • Phù hợp hoàn hảo với yêu cầu "public-facing website" vì test từ internet ra ngoài.

📋 Giải thích chi tiết tất cả các phương án

  • Multi-step web test ❌
    Sai vì: Loại test này dùng để mô phỏng chuỗi hành động phức tạp (nhiều steps như login → navigate → submit form), yêu cầu ghi lại (record) script qua browser hoặc code chi tiết. Nó hỗ trợ POST + headers, nhưng tăng nỗ lực phát triển cao (phải xây dựng multi-step logic), không "minimize development effort". Phù hợp cho UX phức tạp, không phải test đơn giản POST.

  • Standard test ✅
    Đúng vì: Như đã giải thích ở trên, hỗ trợ đầy đủ HTTP POST + custom headers qua Portal UI đơn giản (chọn Parse user input → Request → Headers). Không cần code, test nhanh chóng từ nhiều locations. Đây là lựa chọn tối ưu cho yêu cầu.

  • URL ping test ❌
    Sai vì: Chỉ gửi HTTP GET đơn giản (ping URL), không hỗ trợ POST hay custom headers. Rất cơ bản và dễ cấu hình, nhưng không đáp ứng yêu cầu POST. Chỉ dùng cho kiểm tra uptime cơ bản.

  • Custom TrackAvailability test ❌
    Sai vì: Yêu cầu viết code SDK (gọi TrackAvailability() trong app code của website), tăng nỗ lực phát triển lớn (phải instrument code on-premises). Không cấu hình qua Portal, mà phụ thuộc dev deploy code – trái ngược yêu cầu "minimize development effort".

🛠️ Lời khuyên thực tế: Sau khi tạo Standard test, theo dõi metrics như Availability %, Response time trong Azure Portal. Nếu cần scale, kết hợp với Alerts & Action Groups! 🚀

Câu 396
You have a workspace-based Azure Application Insights resource named Insights1 and an Azure App Service Web App named App1. Insights1 collects telemetry generated by App1.

You plan to test the availability of App1 by using Insights1. The test must include the following tasks:

•Parse dependent requests.
•Validate TLS certificates.
•Configure custom request headers.

You must minimize development and implementation efforts.

You need to implement the Application Insights availability test that will deliver the required functionality.

Which availability test should you implement?
  1. A Custom TrackAvailability test
  2. B Standard test
  3. C URL ping test
  4. D Multi-step web test
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm về Azure Application Insights

📘 Nội dung câu hỏi được giải thích rõ ràng:
Câu hỏi mô tả tình huống bạn đang sử dụng một tài nguyên Azure Application Insights dựa trên workspace (Insights1) để thu thập telemetry từ một Azure App Service Web App (App1). Bạn cần triển khai availability test (kiểm tra tính sẵn sàng) cho App1 bằng Insights1, với các yêu cầu cụ thể sau:

  • Parse dependent requests 🛤️: Phân tích và theo dõi các request phụ thuộc (như redirects hoặc các liên kết con từ trang chính).
  • Validate TLS certificates 🔒: Xác thực chứng chỉ TLS/SSL để đảm bảo kết nối an toàn.
  • Configure custom request headers 📤: Cấu hình các header request tùy chỉnh (ví dụ: Authorization, User-Agent).
    Quan trọng nhất là phải minimize development and implementation efforts ⏱️, nghĩa là ưu tiên giải pháp sẵn có, không cần code tùy chỉnh nhiều.
    Câu hỏi yêu cầu chọn loại availability test phù hợp nhất trong Application Insights (phiên bản mới nhất đến 2026, theo tài liệu Azure Monitor).

✅ Đáp án đúng: Standard test
Lý do lựa chọn:
Standard test là loại kiểm tra sẵn có (built-in) trong Azure Application Insights, hỗ trợ đầy đủ tất cả 3 yêu cầu mà không cần phát triển code phức tạp. Nó cho phép:

  • Parse dependent requests tự động (theo dõi redirects và requests con).
  • Validate TLS certificates qua tùy chọn tích hợp.
  • Configure custom request headers dễ dàng qua giao diện portal.
    Cách triển khai chỉ mất vài phút trên Azure Portal, hoàn toàn không cần code, giúp giảm thiểu efforts tối đa. Đây là lựa chọn tối ưu theo best practices Azure (cập nhật 2026).

🛠️ Giải thích tất cả các phương án (đúng/sai):
Tôi sẽ giữ nguyên văn bản gốc bằng tiếng Anh cho từng lựa chọn, sau đó phân tích chi tiết bằng tiếng Việt với lý do đúng/sai dựa trên tính năng Application Insights mới nhất.

  • Custom TrackAvailability test ❌ (SAI)
    Phương án này yêu cầu code tùy chỉnh trong ứng dụng (sử dụng TrackAvailability() API từ SDK). Nó linh hoạt nhưng không hỗ trợ tự động parse dependent requests, validate TLS, hay custom headers mà không cần dev efforts lớn (viết code xử lý). Vi phạm yêu cầu minimize efforts.

  • Standard test ✅ (ĐÚNG)
    Như đã giải thích, hỗ trợ đầy đủ 3 yêu cầu qua UI portal: parse dependents (tùy chọn "Parse dependent requests"), validate TLS (checkbox "Validate SSL certificate"), custom headers (thêm key-value pairs). Triển khai nhanh, không code.

  • URL ping test ❌ (SAI)
    Đây là test cơ bản nhất (chỉ ping URL đơn giản), không hỗ trợ parse dependent requests (không theo dõi links con), không validate TLS chi tiết, và custom headers hạn chế (không đầy đủ như Standard). Phù hợp test đơn giản nhưng không đáp ứng yêu cầu.

  • Multi-step web test ❌ (SAI)
    Test nâng cao yêu cầu ghi lại steps qua browser recorder (nhiều bước tương tác). Hỗ trợ custom headers và parse dependents, nhưng validate TLS cơ bản và efforts cao (phát triển/test steps phức tạp). Không minimize efforts so với Standard test.

📚 Tài liệu tham khảo (cập nhật mới nhất đến 2026):

Là một Microsoft Azure Developer 🧑‍💻, tôi khuyên nên triển khai ngay Standard test qua Azure Portal để test App1 hiệu quả! Nếu cần hỗ trợ config cụ thể, hãy cung cấp thêm chi tiết. 🚀

Câu 397 Chọn nhiều đáp án
Case study -

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.


To start the case study -
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.


Background -

Munson’s Pickles and Preserves Farm is an agricultural cooperative corporation based in Washington, US, with farms located across the United States. The company supports agricultural production resources by distributing seeds fertilizers, chemicals, fuel, and farm machinery to the farms.


Current Environment -

The company is migrating all applications from an on-premises datacenter to Microsoft Azure. Applications support distributors, farmers, and internal company staff.


Corporate website -
•The company hosts a public website located at http://www.munsonspicklesandpreservesfarm.com. The site supports farmers and distributors who request agricultural production resources.


Farms -
•The company created a new customer tenant in the Microsoft Entra admin center to support authentication and authorization for applications.


Distributors -
•Distributors integrate their applications with data that is accessible by using APIs hosted at http://www.munsonspicklesandpreservesfarm.com/api to receive and update resource data.


Requirements -

The application components must meet the following requirements:


Corporate website -
•The site must be migrated to Azure App Service.
•Costs must be minimized when hosting in Azure.
•Applications must automatically scale independent of the compute resources.
•All code changes must be validated by internal staff before release to production.
•File transfer speeds must improve, and webpage-load performance must increase.
•All site settings must be centrally stored, secured without using secrets, and encrypted at rest and in transit.
•A queue-based load leveling pattern must be implemented by using Azure Service Bus queues to support high volumes of website agricultural production resource requests.


Farms -
•Farmers must authenticate to applications by using Microsoft Entra ID.


Distributors -
•The company must track a custom telemetry value with each API call and monitor performance of all APIs.
•API telemetry values must be charted to evaluate variations and trends for resource data.


Internal staff -
•App and API updates must be validated before release to production.
•Staff must be able to select a link to direct them back to the production app when validating an app or API update.
•Staff profile photos and email must be displayed on the website once they authenticate to applications by using their Microsoft Entra ID.


Security -
•All web communications must be secured by using TLS/HTTPS.
•Web content must be restricted by country/region to support corporate compliance standards.
•The principle of least privilege must be applied when providing any user rights or process access rights.
•Managed identities for Azure resources must be used to authenticate services that support Microsoft Entra ID authentication.


Issues -


Corporate website -
•Farmers report HTTP 503 errors at the same time as internal staff report that CPU and memory usage are high.
•Distributors report HTTP 502 errors at the same time as internal staff report that average response times and networking traffic are high.
•Internal staff report webpage load sizes are large and take a long time to load.
•Developers receive authentication errors to Service Bus when they debug locally.


Distributors -
•Many API telemetry values are sent in a short period of time. Telemetry traffic, data costs, and storage costs must be reduced while preserving a statistically correct analysis of the data points sent by the APIs.


You need to configure all site configuration settings for the corporate website.

Which three actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.
  1. A Create a managed identity.
  2. B Update the role assignments for the Azure Key Vault.
  3. C Create an Azure App Configuration store.
  4. D Update the role assignments for the Azure App Configuration store.
  5. E Create an Azure Key Vault.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi thuộc phần case study về công ty Munson’s Pickles and Preserves Farm, đang migrate ứng dụng từ on-premises sang Microsoft Azure. Tập trung vào corporate website (host tại http://www.munsonspicklesandpreservesfarm.com), cần migrate sang Azure App Service với các yêu cầu chính liên quan đến site configuration settings:

  • Tất cả site settings phải được lưu trữ tập trung (centrally stored).
  • Bảo mật mà không sử dụng secrets (secured without using secrets).
  • Mã hóa tại chỗ (encrypted at rest) và trong quá trình truyền (in transit).
  • Website phải tự động scale, giảm chi phí, cải thiện tốc độ load trang và file transfer.
  • Sử dụng managed identities để authenticate services với Microsoft Entra ID (trước đây là Azure AD).
  • Áp dụng nguyên tắc least privilege cho quyền truy cập.

Vấn đề hiện tại: Lỗi authentication khi debug Service Bus, load chậm, HTTP 503/502 do high CPU/memory/network.

Nhiệm vụ: Chọn 3 actions để configure all site configuration settings cho website trên Azure App Service. Giải pháp phải đáp ứng lưu trữ config tập trung, an toàn, không dùng secrets trực tiếp (sử dụng Azure App Configuration thay vì Key Vault), và sử dụng managed identity để App Service truy cập config một cách bảo mật.

📘 Kiến thức cập nhật (tính đến 2026): Theo tài liệu Azure mới nhất (Azure App Service v2024+, App Configuration GA features), Azure App Configuration là dịch vụ lý tưởng cho app settings (không phải secrets), hỗ trợ encryption at rest/in transit, integration với managed identities qua role-based access control (RBAC). Không khuyến nghị Key Vault cho non-secrets config để tránh phức tạp hóa.

✅ Đáp án đúng và lý do lựa chọn

Ba actions đúng là:

  • Create a managed identity.
  • Create an Azure App Configuration store.
  • Update the role assignments for the Azure App Configuration store.

Lý do 🛠️:

  • Azure App Configuration store lưu trữ settings tập trung, hỗ trợ feature flags, encryption tự động (at rest bằng Azure Storage encryption, in transit qua HTTPS/TLS 1.3+), và không lưu secrets (phù hợp "without using secrets").
  • Managed identity (System-assigned hoặc User-assigned) cho App Service authenticate không cần credentials, tuân thủ security requirements (managed identities for Entra ID auth) và least privilege.
  • Update role assignments (ví dụ: App Configuration Data Reader role) cấp quyền cho managed identity truy cập App Config mà không dùng secrets, đảm bảo config được load an toàn vào App Service. Kết hợp 3 bước này hoàn thiện cấu hình settings, giảm chi phí (pay-per-use), hỗ trợ auto-scale, và giải quyết authentication issues (như debug Service Bus liên quan managed identity).

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn (giữ nguyên text gốc bằng tiếng Anh). Mỗi phương án được đánh dấu ✅ (đúng - là phần giải pháp) hoặc ❌ (sai - không cần thiết hoặc không phù hợp).

  • ✅ Create a managed identity.
    🛠️ Đúng: App Service cần managed identity (system-assigned) để authenticate với các dịch vụ Azure như App Configuration hoặc Entra ID mà không lưu secrets. Tuân thủ "Managed identities for Azure resources must be used" và giải quyết authentication errors khi debug. (Nguồn: Azure Managed Identities docs).

  • ❌ Update the role assignments for the Azure Key Vault.
    🚫 Sai: Không cần vì requirements nhấn mạnh "secured without using secrets", Key Vault dành cho secrets (như passwords, keys). Sử dụng Key Vault sẽ vi phạm yêu cầu và tăng complexity không cần thiết. Role assignments chỉ áp dụng sau khi có Key Vault.

  • ✅ Create an Azure App Configuration store.
    🛠️ Đúng: Dịch vụ chuyên lưu centrally stored settings (app settings, connection strings), encryption at rest/in transit tự động, hỗ trợ App Service integration qua managed identity. Giảm load local config, cải thiện performance (như webpage load). Không lưu secrets, phù hợp chính xác requirements. (Nguồn: Azure App Configuration overview).

  • ✅ Update the role assignments for the Azure App Configuration store.
    🛠️ Đúng: Sau khi tạo App Config và managed identity, cần assign RBAC roles (ví dụ: "App Configuration Data Reader") cho identity của App Service để đọc settings theo least privilege. Đảm bảo config load an toàn, không secrets. (Nguồn: App Config RBAC integration).

  • ❌ Create an Azure Key Vault.
    🚫 Sai: Key Vault chỉ cho secrets (không phải site settings thông thường). Requirements rõ "without using secrets", nên không tạo Key Vault để tránh chi phí thừa và không khớp (App Config mới là giải pháp cho config tập trung). (Nguồn: Key Vault vs App Config comparison).

Tóm tắt lợi ích giải pháp 🎯: 3 actions đúng tạo luồng: App Service (với managed identity) → RBAC roles → App Config store → Load settings an toàn, scale tự động, performance cao. Không cần Key Vault giúp minimize costs và tuân thủ security.

📘 Tài liệu tham khảo chính (Azure docs 2024-2026):

Câu 398
You manage an Azure Storage account named storage1.

You plan to load 1 million blobs into storage1.

You must assign key-value pairs to blobs so that both keys and their values are automatically indexed and searchable by using the built-in services of storage1.

You need to run the command to assign key-value pairs.

Which command should you run?
  1. A az storage blob tag set
  2. B az storage blob service-properties update
  3. C az storage blob directory metadata update
  4. D New-AzStorageBlobQueryConfig
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc quản lý tài khoản Azure Storage account có tên storage1. Bạn cần tải lên 1 triệu blobs vào tài khoản này và gán các cặp key-value (nhãn hoặc tags) cho các blobs sao cho:

  • Các keys và values được tự động index (chỉ mục hóa).
  • Có thể tìm kiếm dễ dàng bằng các dịch vụ built-in của Azure Storage (như Blob Index Tags hoặc tích hợp với Azure AI Search).

Mục tiêu là chạy lệnh CLI phù hợp để gán key-value pairs này. Đây là tính năng Blob Tags trong Azure Blob Storage (hỗ trợ từ năm 2020 và cập nhật liên tục đến 2026 với cải tiến indexing hiệu suất cao hơn cho hàng triệu blobs). Blob Tags cho phép query, index và search metadata mà không cần dịch vụ bên ngoài. 📘

✅ Đáp án đúng: az storage blob tag set

Lý do lựa chọn:

  • Lệnh này được thiết kế chuyên biệt để gán (set) các tags dưới dạng key-value pairs cho một blob cụ thể trong Azure Storage.
  • Tags được tự động index bởi Azure Blob Storage, cho phép tìm kiếm nhanh chóng qua các built-in services như Blob Inventory, Blob Query Language (SQL-like) hoặc tích hợp Azure AI Search mà không cần công cụ ngoài.
  • Phù hợp hoàn hảo với quy mô 1 triệu blobs, vì tags hỗ trợ lên đến 10 tags/blob, dung lượng 2KB/tag, và indexing hiệu quả (cập nhật 2026: hỗ trợ tag-based partitioning cho large-scale workloads). 🛠️

Ví dụ sử dụng: az storage blob tag set --account-name storage1 --container-name mycontainer --name myblob --tags "key1=value1 key2=value2".

📋 Giải thích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể dựa trên tài liệu Azure CLI/PowerShell mới nhất (2026).

  • az storage blob tag set ✅
    Đúng: Như đã giải thích ở trên, đây là lệnh chính thức để gán tags (key-value) cho blob, tự động index và searchable. Hoàn toàn khớp yêu cầu. (Nguồn: Azure CLI Docs - az storage blob tag set).

  • az storage blob service-properties update ❌
    Sai: Lệnh này dùng để cập nhật thuộc tính dịch vụ cấp account (như CORS, static web, soft delete), không liên quan đến gán key-value cho các blob riêng lẻ. Không hỗ trợ indexing/search cho tags. Không dùng cho 1 triệu blobs cá nhân.

  • az storage blob directory metadata update ❌
    Sai: Lệnh này chỉ cập nhật metadata cho thư mục ảo (directory) trong hierarchical namespace (ADLS Gen2), không phải tags cho blobs. Metadata không được tự động index/searchable như tags, và không áp dụng cho blobs thông thường. (Nguồn: Azure CLI Docs - az storage blob directory).

  • New-AzStorageBlobQueryConfig ❌
    Sai: Đây là cmdlet PowerShell để tạo cấu hình query cho Blob Analytics/Inventory, dùng cho việc truy vấn dữ liệu lớn chứ không phải gán key-value pairs. Không tạo tags hay index chúng. (Đây là PowerShell, không phải CLI thuần). (Nguồn: PowerShell Docs - New-AzStorageBlobQueryConfig).

📚 Tài liệu tham khảo chính

Hy vọng phân tích này giúp bạn nắm vững! 🚀 Nếu cần ví dụ code chi tiết, hãy hỏi thêm nhé! 😊

Câu 399
You are developing an application that uses keys stored in Azure Key Vault.

You need to enforce a specific cryptographic algorithm and key size for keys stored in the vault.

What should you use?
  1. A Secret versioning
  2. B Azure Policy
  3. C Key Vault Firewall
  4. D Access policies
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc phát triển ứng dụng sử dụng khóa (keys) lưu trữ trong Azure Key Vault – một dịch vụ quản lý bí mật, khóa mã hóa và chứng chỉ của Microsoft Azure.
Yêu cầu cụ thể là ép buộc (enforce) một thuật toán mã hóa (cryptographic algorithm) và kích thước khóa (key size) nhất định cho các khóa được lưu trong vault.
Ví dụ: Đảm bảo tất cả khóa phải sử dụng RSA 2048-bit hoặc AES-256, tránh sử dụng các thuật toán yếu hoặc kích thước nhỏ.
Điều này nhằm tuân thủ tiêu chuẩn bảo mật cao (như NIST, PCI-DSS) và kiểm soát governance trên toàn tổ chức.
Phiên bản cập nhật: Theo tài liệu Azure mới nhất (tính đến 2026), Azure Policy hỗ trợ các chính sách chi tiết cho Key Vault qua Azure Policy Guest Configuration và built-in policies cho crypto requirements.

📘 Tài liệu tham khảo:

✅ Đáp án đúng: Azure Policy

Lý do chọn:
Azure Policy là dịch vụ governance của Azure cho phép định nghĩa và áp dụng quy tắc ở mức subscription/resource group, bao gồm ép buộc thuộc tính khóa như thuật toán (RSA, EC, AES) và kích thước (2048-bit, 4096-bit).
Ví dụ: Sử dụng built-in policy "Cryptographic keys should have X bits key size" hoặc custom policy để deny việc tạo khóa không đạt chuẩn.
🛠️ Cách triển khai: Tạo policy assignment qua Azure Portal/CLI, audit hoặc deny operations như create/update key nếu vi phạm. Điều này đảm bảo compliance tự động, không phụ thuộc vào developer.

📋 Giải thích tất cả các phương án

  • Secret versioning ❌
    Sai vì: Secret versioning chỉ quản lý các phiên bản của secret (không phải key), tự động rotate và track changes, nhưng không enforce thuật toán hoặc kích thước khóa. Nó chỉ lưu lịch sử, không kiểm soát thuộc tính crypto khi tạo mới.

  • Azure Policy ✅
    Đúng vì: Như giải thích trên, đây là công cụ chính để enforce quy tắc crypto (algorithm như RSA/EC, key size cụ thể) qua deny/audit trên Key Vault operations. Hỗ trợ tích hợp RBAC và compliance reporting.

  • Key Vault Firewall ❌
    Sai vì: Key Vault Firewall kiểm soát network access (IP, VNet), ngăn chặn truy cập từ nguồn không tin cậy, nhưng không liên quan đến thuộc tính khóa như algorithm hay size. Nó chỉ bảo vệ truy cập, không governance nội dung.

  • Access policies ❌
    Sai vì: Access policies định nghĩa quyền truy cập (get, list, create, delete) cho principal (user/app), dựa trên RBAC. Nó kiểm soát ai làm gì, nhưng không enforce đặc tính kỹ thuật của khóa như algorithm/key size khi tạo. (Lưu ý: Từ 2021, Azure khuyến nghị dùng RBAC thay access policies).

Câu 400
You manage an Azure App Service Web App named App1 and an associated Azure Application Insights resource named AppInsights1.

You require alerts about any unusual rate increase of failed HTTP requests targeting App1.

You need to implement push notifications.

What should you do?
  1. A Deploy an Azure Resource Manager template that configures AppInsights1.
  2. B From the Azure portal, modify an action group of Azure Monitor.
  3. C From the Azure portal, modify diagnostic settings of AppInsights1.
  4. D Deploy an Azure Resource Manager template that configures the analyticsItems child resource of AppInsights1.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc quản lý một ứng dụng web Azure App Service có tên App1, được liên kết với tài nguyên Azure Application Insights tên AppInsights1.
Yêu cầu chính là thiết lập cảnh báo (alerts) khi có sự gia tăng bất thường về tỷ lệ yêu cầu HTTP thất bại (failed HTTP requests) nhắm đến App1. Đồng thời, cần triển khai thông báo đẩy (push notifications) để nhận cảnh báo kịp thời.

🔍 Bối cảnh kỹ thuật:

  • Azure Application Insights thu thập dữ liệu telemetry (metrics, logs) từ App1, bao gồm các chỉ số như failed requests (ví dụ: tỷ lệ 4xx/5xx errors).
  • Để phát hiện "unusual rate increase" (tăng bất thường), sử dụng tính năng Smart Detection trong Application Insights hoặc custom metric alerts trong Azure Monitor.
  • Push notifications được xử lý qua Action Groups của Azure Monitor, hỗ trợ gửi thông báo đến mobile app (Azure portal app), email, SMS, webhook, v.v.
    (Kiến thức cập nhật đến 2026: Azure Monitor và Application Insights phiên bản mới nhất hỗ trợ AI-driven anomaly detection cho failed requests qua metric Failed Requests Availability hoặc custom queries, tích hợp seamless với Action Groups cho push notifications.)

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: From the Azure portal, modify an action group of Azure Monitor.

Lý do:
🛠️ Action Groups trong Azure Monitor là nơi cấu hình các hành động (actions) cho alerts, bao gồm push notifications đến ứng dụng di động Azure hoặc các kênh khác. Khi thiết lập alert rule trên metric "Failed Requests" từ AppInsights1 (qua Azure Monitor > Alerts), bạn gắn Action Group để kích hoạt push notifications khi phát hiện anomaly. Đây là cách trực tiếp, nhanh chóng từ Azure Portal mà không cần code hay template phức tạp.
📘 Nguồn tham khảo:

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá với lý do chi tiết:

  • Deploy an Azure Resource Manager template that configures AppInsights1.
    ❌ Sai: ARM template chỉ dùng để triển khai/cấu hình tài nguyên AppInsights1 (như instrumentation key, sampling), nhưng không xử lý alerts hay push notifications. Nó không gắn kết với Azure Monitor alerts hoặc action groups. Sử dụng template này chỉ deploy resource, không config anomaly detection hay notifications.

  • From the Azure portal, modify an action group of Azure Monitor.
    ✅ Đúng: Như đã giải thích ở trên, đây là bước chính để kích hoạt push notifications cho alerts về failed requests. Từ Portal > Azure Monitor > Action Groups, chỉnh sửa để thêm receiver (push/mobile), rồi gắn vào alert rule của AppInsights1 metric.

  • From the Azure portal, modify diagnostic settings of AppInsights1.
    ❌ Sai: Diagnostic settings dùng để route logs/metrics đến destinations như Log Analytics, Storage, Event Hubs (export data), chứ không tạo alerts hay push notifications. Nó chỉ hỗ trợ data streaming, không phát hiện "unusual rate increase" hay gửi thông báo real-time.

  • Deploy an Azure Resource Manager template that configures the analyticsItems child resource of AppInsights1.
    ❌ Sai: analyticsItems là child resource cho saved queries hoặc analytic rules trong AppInsights (như KQL queries), dùng cho analysis chứ không config alerts/actions/push notifications. Template này chỉ lưu queries tĩnh, không liên kết với Azure Monitor Action Groups để gửi push.

🧠 Lời khuyên thực hành: Để triển khai đầy đủ, vào Azure Portal > AppInsights1 > Alerts > Create alert rule > chọn metric "Failed Requests" > gắn Action Group có push notification. Test với failure simulation để verify!
📘 Tài liệu bổ sung: Azure App Service monitoring (2026 preview features cho AI alerts).