CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 34: SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads

Overview -Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas. Contoso has a hybrid environment that contains on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1. Existing Environment. Microsoft Entra tena…

Nội dung câu hỏi

Overview -Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas. Contoso has a hybrid environment that contains on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1. Existing Environment. Microsoft Entra tenantContoso has a Microsoft Entra tenant named contoso.com that contains the users shown in the following table. Existing Environment. On-premises environmentThe on-premises network contains an Active Directory Domain Services (AD DS) forest that syncs with contoso.com. The forest contains a server named Server1 that runs Windows Server. Existing Environment. Azure subscriptionSub1 contains the storage accounts shown in the following table. Sub1 contains the virtual networks shown in the following table. Sub1 contains the virtual machines shown in the following table. The network interface of VM1 is associated with an application security group named ASG1.Sub1 contains the resources shown in the following table. Vault1 stores the objects shown in the following table. Existing Environment. Privileged Identity Management (PIM) configurationYou manage privileged roles by using Privileged Identity Management (PIM). The PIM role settings are configured as shown in the following table. Existing Environment. Microsoft Sentinel configurationContoso has a Microsoft Sentinel workspace that contains the following tables. Requirements. Planned changes -Contoso plans to implement the following changes:Integrate AKS1 with Vault1. Enable Microsoft Entra Kerberos authentication for all supported storage. Configure auditing for sql1 by using the Azure portal and store audit logs in a centralized location.Requirements. Technical requirementsContoso identifies the following technical requirements:Protect Server1 by using file integrity monitoring. Protect AKS1 by using Microsoft Defender for Cloud. Configure Microsoft Sentinel to retain data for the maximum supported duration without changing the tier. Store objects used for authentication and encryption in Vault1 and ensure that Vault1 regenerates the objects every 30 days, whenever possible. You need to protect the applications hosted on AKS1. The solution must meet the technical requirements. Which Defender for Cloud plan should you enable?

Minh họa câu hỏi Minh họa câu hỏi Minh họa câu hỏi Minh họa câu hỏi Minh họa câu hỏi Minh họa câu hỏi Minh họa câu hỏi Minh họa câu hỏi

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Microsoft Defender for Servers
  2. B. Microsoft Defender for App Service
  3. C. Microsoft Defender for Containers — đáp án hiện tại
  4. D. Microsoft Defender for Resource Manager
  5. E. Microsoft Defender for Storage

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề