Microsoft Designing and Implementing Microsoft Azure Networking Solutions (AZ-700 Korean Version) - AZ-700 Korean Exam Practice Test
Vaultl という名前の Azure キー コンテナーと、App1 という名前の Azure AD アプリのアプリ登録が含まれる Azure サブスクリプションがあります。
サードパーティの DNS プロバイダーによってホストされている contoso.com という名前の DNS ドメインがあります。
Azure App Service を使用して App1 をデプロイする予定です。App1 の構成は次のようになります。
* App1 は 5 つの App Service アプリでホストされます。
* ユーザーは、https://app1.contoso.com の URL を使用して App1 にアクセスします。
* App1 のユーザー トラフィックは、Azure Front Door を使用して管理されます。
* Front Door と App Service アプリ間のトラフィックは、HTTP を使用して送信されます。
* App1 は、サードパーティの証明機関 (CA) からの SSL 証明書を使用して保護されます。
Front Door の展開をサポートする必要があります。
どの 2 つの DNS レコードを作成し、App1 の SSL 証明書をどこにインポートする必要がありますか? 回答するには、回答領域で適切なオプションを選択してください。
注意: 正しい選択ごとに 1 ポイントが加算されます。

サードパーティの DNS プロバイダーによってホストされている contoso.com という名前の DNS ドメインがあります。
Azure App Service を使用して App1 をデプロイする予定です。App1 の構成は次のようになります。
* App1 は 5 つの App Service アプリでホストされます。
* ユーザーは、https://app1.contoso.com の URL を使用して App1 にアクセスします。
* App1 のユーザー トラフィックは、Azure Front Door を使用して管理されます。
* Front Door と App Service アプリ間のトラフィックは、HTTP を使用して送信されます。
* App1 は、サードパーティの証明機関 (CA) からの SSL 証明書を使用して保護されます。
Front Door の展開をサポートする必要があります。
どの 2 つの DNS レコードを作成し、App1 の SSL 証明書をどこにインポートする必要がありますか? 回答するには、回答領域で適切なオプションを選択してください。
注意: 正しい選択ごとに 1 ポイントが加算されます。

Correct Answer:

Explanation:

次の図に示すような Azure 環境があります。

ドロップダウン メニューを使用して、グラフィックに表示された情報に基づいて各ステートメントを完成させる回答の選択肢を選択します。
注意: 正しい選択ごとに 1 ポイントが加算されます。


ドロップダウン メニューを使用して、グラフィックに表示された情報に基づいて各ステートメントを完成させる回答の選択肢を選択します。
注意: 正しい選択ごとに 1 ポイントが加算されます。

Correct Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-peering-gateway-transit?toc=/azure/virtual-network/toc.json
https://docs.microsoft.com/en-ca/azure/virtual-network/ip-services/ipv6-overview#capabilities
タスク4
仮想ネットワーク上で管理操作が実行された場合、VNET3 の所有者がアラートを受信するようにする必要があります。
仮想ネットワーク上で管理操作が実行された場合、VNET3 の所有者がアラートを受信するようにする必要があります。
Correct Answer:
See the Explanation below for step by step instructions.
Explanation:
To ensure that the owner of VNET3 receives an alert whenever an administrative operation is performed on the virtual network, you can set up an Activity Log Alert in Azure Monitor. Here's how you can do it:
Step-by-Step Solution
Step 1: Create an Activity Log Alert
Navigate to the Azure Portal.
Search for "Monitor" and select it.
In the Monitor blade, select "Alerts" from the left-hand menu.
Click on "New alert rule".
Step 2: Configure the Alert Rule
Select the Scope:
Click on "Select resource".
Choose "Virtual Network" as the resource type.
Select VNET3 from the list of virtual networks.
Define the Condition:
Click on "Add condition".
In the "Signal type" dropdown, select "Activity Log".
Choose "Administrative" as the category.
Select the specific operations you want to monitor (e.g., Microsoft.Network/virtualNetworks/write for any write operations on the virtual network).
Set the Alert Details:
Enter a name for the alert rule (e.g., VNET3 Admin Operations Alert).
Provide a description if needed.
Configure the Action Group:
Click on "Add action group".
Enter a name for the action group.
Select the action type (e.g., Email/SMS/Push/Voice).
Enter the details of the recipient (e.g., the email address of the owner of VNET3).
Review and Create:
Review the alert rule settings.
Click on "Create alert rule".
Explanation:
Activity Log Alerts: These alerts notify you when specific operations are performed on your Azure resources.
By setting up an alert for administrative operations, you ensure that any changes to VNET3 are promptly reported.
Action Groups: These define the actions to take when an alert is triggered. You can configure notifications via email, SMS, or other methods to ensure the owner of VNET3 is informed immediately.
Administrative Operations: Monitoring these operations helps in tracking changes and maintaining the security and integrity of your virtual network.
By following these steps, you can ensure that the owner of VNET3 receives timely alerts for any administrative operations performed on the virtual network, helping to maintain oversight and security.
Explanation:
To ensure that the owner of VNET3 receives an alert whenever an administrative operation is performed on the virtual network, you can set up an Activity Log Alert in Azure Monitor. Here's how you can do it:
Step-by-Step Solution
Step 1: Create an Activity Log Alert
Navigate to the Azure Portal.
Search for "Monitor" and select it.
In the Monitor blade, select "Alerts" from the left-hand menu.
Click on "New alert rule".
Step 2: Configure the Alert Rule
Select the Scope:
Click on "Select resource".
Choose "Virtual Network" as the resource type.
Select VNET3 from the list of virtual networks.
Define the Condition:
Click on "Add condition".
In the "Signal type" dropdown, select "Activity Log".
Choose "Administrative" as the category.
Select the specific operations you want to monitor (e.g., Microsoft.Network/virtualNetworks/write for any write operations on the virtual network).
Set the Alert Details:
Enter a name for the alert rule (e.g., VNET3 Admin Operations Alert).
Provide a description if needed.
Configure the Action Group:
Click on "Add action group".
Enter a name for the action group.
Select the action type (e.g., Email/SMS/Push/Voice).
Enter the details of the recipient (e.g., the email address of the owner of VNET3).
Review and Create:
Review the alert rule settings.
Click on "Create alert rule".
Explanation:
Activity Log Alerts: These alerts notify you when specific operations are performed on your Azure resources.
By setting up an alert for administrative operations, you ensure that any changes to VNET3 are promptly reported.
Action Groups: These define the actions to take when an alert is triggered. You can configure notifications via email, SMS, or other methods to ensure the owner of VNET3 is informed immediately.
Administrative Operations: Monitoring these operations helps in tracking changes and maintaining the security and integrity of your virtual network.
By following these steps, you can ensure that the owner of VNET3 receives timely alerts for any administrative operations performed on the virtual network, helping to maintain oversight and security.
VNet1 という名前の仮想ネットワークを含む Azure サブスクリプションがあります。VNet1 には次のサブネットが含まれています。
* Azureファイアウォールサブネット
* ゲートウェイサブネット
* サブネット 1
* サブネット2
* サブネット3
Subnet2 は Microsoft.Web/serverfarms サービスへの委任を持っています。サブスクリプションには、次の表に示すリソースが含まれています。

Azure Web アプリケーション ファイアウォール (WAF) と統合される AG1 という名前の Azure アプリケーション ゲートウェイを実装する必要があります。AG1 は VMSS1 を公開するために使用されます。
AG1 をどのサブネットに接続する必要がありますか?
* Azureファイアウォールサブネット
* ゲートウェイサブネット
* サブネット 1
* サブネット2
* サブネット3
Subnet2 は Microsoft.Web/serverfarms サービスへの委任を持っています。サブスクリプションには、次の表に示すリソースが含まれています。

Azure Web アプリケーション ファイアウォール (WAF) と統合される AG1 という名前の Azure アプリケーション ゲートウェイを実装する必要があります。AG1 は VMSS1 を公開するために使用されます。
AG1 をどのサブネットに接続する必要がありますか?
Correct Answer: E
タスク6
ニューヨークとドイツにそれぞれ異なるサービスプロバイダーがホストする2つのサーバーがあります。ニューヨークでホストされているサーバーには、ホスト名ny.contoso.comでアクセスできます。ドイツでホストされているサーバーには、ホスト名de.contoso.comでアクセスできます。
両方のサーバーにアクセスするには、単一のホスト名を指定する必要があります。このソリューションでは、ドイツから発信されるトラフィックがde contoso.comにルーティングされるようにする必要があります。その他のトラフィックはすべてny.contoso.comにルーティングする必要があります。
ニューヨークとドイツにそれぞれ異なるサービスプロバイダーがホストする2つのサーバーがあります。ニューヨークでホストされているサーバーには、ホスト名ny.contoso.comでアクセスできます。ドイツでホストされているサーバーには、ホスト名de.contoso.comでアクセスできます。
両方のサーバーにアクセスするには、単一のホスト名を指定する必要があります。このソリューションでは、ドイツから発信されるトラフィックがde contoso.comにルーティングされるようにする必要があります。その他のトラフィックはすべてny.contoso.comにルーティングする必要があります。
Correct Answer:
See the Explanation below for step by step instructions.
Explanation:
To provide a single host name that routes traffic based on the origin, you can use Azure Traffic Manager. This service allows you to route traffic to different endpoints based on various routing methods, including geographic routing.
Navigate to the Azure Portal.
Search for "Traffic Manager profiles" and select it.
Click on "Create".
Enter the following details:
Name: Enter a name for the Traffic Manager profile (e.g., ContosoTrafficManager).
Routing method: Select Geographic.
Subscription: Select your subscription.
Resource group: Select an existing resource group or create a new one.
Resource group location: Choose a location (this does not affect the routing).
Click on "Create".
Navigate to the newly created Traffic Manager profile.
Select "Endpoints" from the left-hand menu.
Click on "Add" to add a new endpoint.
Enter the following details:
Type: Select External endpoint.
Name: Enter a name for the endpoint (e.g., NewYorkEndpoint).
FQDN: Enter ny.contoso.com.
Geographic region: Select "World" (this will be adjusted later).
Click on "Add" to save the endpoint.
Repeat the process to add the second endpoint:
Type: Select External endpoint.
Name: Enter a name for the endpoint (e.g., GermanyEndpoint).
FQDN: Enter de.contoso.com.
Geographic region: Select Europe.
Navigate to the Traffic Manager profile.
Select "Configuration" from the left-hand menu.
Under "Geographic routing", adjust the regions:
For the GermanyEndpoint, ensure that the geographic region is set to Europe.
For the NewYorkEndpoint, ensure that the geographic region is set to World (excluding Europe).
Use a DNS query tool to test the routing.
From a location in Germany, query the Traffic Manager profile's DNS name and ensure it resolves to de.
contoso.com.
From a location outside Europe, query the Traffic Manager profile's DNS name and ensure it resolves to ny.
contoso.com.
Azure Traffic Manager: This service uses DNS to direct client requests to the most appropriate endpoint based on the routing method you choose. Geographic routing ensures that traffic is directed based on the origin of the request.
Geographic Routing: This method allows you to route traffic based on the geographic location of the DNS query origin, ensuring that users are directed to the nearest or most appropriate endpoint.
Step-by-Step SolutionStep 1: Create a Traffic Manager ProfileStep 2: Configure EndpointsStep 3: Adjust Geographic RoutingStep 4: Test the ConfigurationExplanationBy following these steps, you can provide a single host name that routes traffic to de.contoso.com for users in Germany and to ny.contoso.com for users from other locations, ensuring efficient and appropriate traffic management.
Explanation:
To provide a single host name that routes traffic based on the origin, you can use Azure Traffic Manager. This service allows you to route traffic to different endpoints based on various routing methods, including geographic routing.
Navigate to the Azure Portal.
Search for "Traffic Manager profiles" and select it.
Click on "Create".
Enter the following details:
Name: Enter a name for the Traffic Manager profile (e.g., ContosoTrafficManager).
Routing method: Select Geographic.
Subscription: Select your subscription.
Resource group: Select an existing resource group or create a new one.
Resource group location: Choose a location (this does not affect the routing).
Click on "Create".
Navigate to the newly created Traffic Manager profile.
Select "Endpoints" from the left-hand menu.
Click on "Add" to add a new endpoint.
Enter the following details:
Type: Select External endpoint.
Name: Enter a name for the endpoint (e.g., NewYorkEndpoint).
FQDN: Enter ny.contoso.com.
Geographic region: Select "World" (this will be adjusted later).
Click on "Add" to save the endpoint.
Repeat the process to add the second endpoint:
Type: Select External endpoint.
Name: Enter a name for the endpoint (e.g., GermanyEndpoint).
FQDN: Enter de.contoso.com.
Geographic region: Select Europe.
Navigate to the Traffic Manager profile.
Select "Configuration" from the left-hand menu.
Under "Geographic routing", adjust the regions:
For the GermanyEndpoint, ensure that the geographic region is set to Europe.
For the NewYorkEndpoint, ensure that the geographic region is set to World (excluding Europe).
Use a DNS query tool to test the routing.
From a location in Germany, query the Traffic Manager profile's DNS name and ensure it resolves to de.
contoso.com.
From a location outside Europe, query the Traffic Manager profile's DNS name and ensure it resolves to ny.
contoso.com.
Azure Traffic Manager: This service uses DNS to direct client requests to the most appropriate endpoint based on the routing method you choose. Geographic routing ensures that traffic is directed based on the origin of the request.
Geographic Routing: This method allows you to route traffic based on the geographic location of the DNS query origin, ensuring that users are directed to the nearest or most appropriate endpoint.
Step-by-Step SolutionStep 1: Create a Traffic Manager ProfileStep 2: Configure EndpointsStep 3: Adjust Geographic RoutingStep 4: Test the ConfigurationExplanationBy following these steps, you can provide a single host name that routes traffic to de.contoso.com for users in Germany and to ny.contoso.com for users from other locations, ensuring efficient and appropriate traffic management.
次の表に示すリソースを含む Azure サブスクリプションがあります。

HP1 のユーザーは、https://app1 .comoso.com という URL を使用して App1 に接続します。
FW1 上の IDPS が HP1 から Server1 への接続におけるセキュリティ脅威を識別できることを確認する必要があります。
実行すべき 2 つのアクションはどれですか。それぞれの正解は解決策の一部を示しています。
注意: 正しい選択ごとに 1 ポイントが加算されます。

HP1 のユーザーは、https://app1 .comoso.com という URL を使用して App1 に接続します。
FW1 上の IDPS が HP1 から Server1 への接続におけるセキュリティ脅威を識別できることを確認する必要があります。
実行すべき 2 つのアクションはどれですか。それぞれの正解は解決策の一部を示しています。
注意: 正しい選択ごとに 1 ポイントが加算されます。
Correct Answer: A,D
App1 という名前の Web アプリと、FD1 という名前の Azure Front Door インスタンス上の Azure Web アプリケーション ファイアウォール (WAF) を含む Azure サブスクリプションがあります。FD1 は、App1 のトラフィックを管理します。
App1への高レベルのトラフィックを検知し、自動的にブロックするソリューションを提供します。このソリューションは、管理作業を最小限に抑える必要があります。
ソリューションには何を含めるべきですか?
App1への高レベルのトラフィックを検知し、自動的にブロックするソリューションを提供します。このソリューションは、管理作業を最小限に抑える必要があります。
ソリューションには何を含めるべきですか?
Correct Answer: D
単一の仮想ネットワークと仮想ネットワーク ゲートウェイを含む Azure サブスクリプションがあります。
管理者がポイント対サイト (P2S) VPN 接続を使用して仮想ネットワーク内のリソースにアクセスできるようにする必要があります。接続は Azure Active Directory (Azure AD) によって認証される必要があります。
何を設定する必要がありますか? 回答するには、回答領域で適切なオプションを選択してください。
注意: 正しい選択ごとに 1 ポイントが加算されます。

管理者がポイント対サイト (P2S) VPN 接続を使用して仮想ネットワーク内のリソースにアクセスできるようにする必要があります。接続は Azure Active Directory (Azure AD) によって認証される必要があります。
何を設定する必要がありますか? 回答するには、回答領域で適切なオプションを選択してください。
注意: 正しい選択ごとに 1 ポイントが加算されます。

Correct Answer:

VM1 という名前の Azure 仮想マシンがあります。
Azure Network Watcher を使用して、VM1 のすべてのネットワーク トラフィックをキャプチャする必要があります。
キャプチャはどの場所に書き込むことができますか?
Azure Network Watcher を使用して、VM1 のすべてのネットワーク トラフィックをキャプチャする必要があります。
キャプチャはどの場所に書き込むことができますか?
Correct Answer: E
次の表に示す Azure 仮想ネットワークがあります。

次の表に示す Azure リソースがあります。

Azure Network Watcher の接続モニターを使用して、リソース間の待機時間を確認する必要があります。
作成する必要がある接続モニターの最小数は何ですか?

次の表に示す Azure リソースがあります。

Azure Network Watcher の接続モニターを使用して、リソース間の待機時間を確認する必要があります。
作成する必要がある接続モニターの最小数は何ですか?
Correct Answer: B