最新的Microsoft Azure Administrator (AZ-104 Korean Version) - AZ-104 Korean免費考試真題

귀하의 Azure 구독에는 다음 표에 표시된 가상 네트워크가 포함되어 있습니다.
구독에는 다음 표에 표시된 가상 머신이 포함되어 있습니다.
모든 가상 머신은 사설 IP 주소만 사용합니다.
VNet1에 Bastion1이라는 이름의 Azure Bastion 호스트를 배포합니다.
Bastion1을 통해 어떤 가상 머신에 연결할 수 있습니까?

전시하다

전시하다

正確答案: B
說明:(僅 Fast2test 成員可見)
VM1이라는 Azure 가상 머신이 VNet1이라는 가상 네트워크에 연결되어 있습니다. VM1의 구성은 다음과 같습니다.
서브넷: 10.0.0.0/24
가용성 세트: AVSet
네트워크 보안 그룹(NSG): 없음
사설 IP 주소: 10.0.0.4 (동적)
공용 IP 주소: 40.90.219.6 (동적)
slb1이라는 이름의 표준 인터넷 연결 로드 밸런서를 배포합니다.
VM1에 대한 연결을 허용하도록 slb1을 구성해야 합니다.
slb1을 구성할 때 VM1에 어떤 변경 사항을 적용해야 합니까? 답변하려면 답변 영역에서 적절한 옵션을 선택하십시오.
참고: 정답 하나당 1점입니다.

전시하다
正確答案:

Explanation:
Detailed Explanation
Standard SKU resources cannot mix with Basic SKU resources on the same NIC - a VM whose NIC already carries a (Basic SKU) public IP cannot be added to a Standard Load Balancer ' s backend pool until that public IP is removed (or replaced with a Standard SKU one, but removal is the option offered here).
Separately, Standard Load Balancer and Standard public IPs are secure by default: unlike Basic SKU, all inbound traffic is implicitly denied unless an NSG explicitly allows it. Since VM1 currently has no NSG at all, no traffic reaching it through slb1 will succeed until an NSG is created and configured with the appropriate allow rules. Both selections reflect Microsoft ' s documented Standard Load Balancer prerequisites and match the source document ' s answer key.
Official Reference
Azure Standard Load Balancer overview - closed to inbound traffic by default - https://learn.microsoft.com
/en-us/azure/load-balancer/load-balancer-standard-overview
Scope1에 대해 계획된 변경 사항을 구현합니다.
Scope1이 기술 요구 사항을 충족하는지 확인해야 합니다.
Scope1을 사용하면 무엇을 암호화할 수 있나요?

正確答案: A
說明:(僅 Fast2test 成員可見)
contoso.onmicrosoft.com이라는 이름의 Azure Active Directory(Azure AD) 테넌트가 있습니다.
사용자 관리자 역할은 Admin1이라는 이름의 사용자에게 할당되었습니다.
외부 파트너가 [email protected] 로그인을 사용하는 Microsoft 계정을 가지고 있습니다.
관리자1이 외부 파트너를 Azure AD 테넌트에 로그인하도록 초대하려고 시도했지만 "사용자 [email protected]을 초대할 수 없습니다. 일반 권한 부여 예외가 발생했습니다."라는 오류 메시지를 받았습니다. 관리자1이 외부 파트너를 Azure AD 테넌트에 로그인하도록 초대할 수 있는지 확인해야 합니다.
어떻게 해야 할까요?

正確答案: C
說明:(僅 Fast2test 成員可見)
귀하는 contoso.com이라는 이름의 Microsoft 365 테넌트와 Azure Active Directory(Azure AD) 테넌트를 보유하고 있습니다.
User1, User2, User3이라는 세 명의 사용자에게 Library1이라는 이름의 임시 Microsoft SharePoint 문서 라이브러리에 대한 액세스 권한을 부여할 계획입니다.
사용자 그룹을 생성해야 합니다. 생성된 그룹은 180일 후 자동으로 삭제되어야 합니다.
어떤 두 그룹을 만들어야 할까요? 각 정답은 완전한 해결책을 제시합니다.
참고: 정답 하나당 1점입니다.

正確答案: B,C
說明:(僅 Fast2test 成員可見)
귀하는 storageaccount1이라는 이름의 Azure Storage 계정이 포함된 Azure 구독을 보유하고 있습니다.
storageaccount1을 Azure Resource Manager 템플릿으로 내보냅니다. 템플릿에는 다음 섹션이 포함되어 있습니다.
다음 각 문장에 대해, 문장이 사실이면 '예'를 선택하고, 그렇지 않으면 '아니요'를 선택하십시오.
참고: 정답 하나당 1점입니다.

전시하다

전시하다
正確答案:

Explanation:
Detailed Explanation
The exported template ' s networkAcls.defaultAction is ' Allow, ' meaning the storage firewall is not restricting any network (no ' Selected networks ' allowlist is in effect), so any public IP, including
131.107.103.10, can reach the account - Yes. The account kind is StorageV2 (general-purpose v2), which fully supports blob-level tiering to Hot, Cool, and Archive - Yes. Being a Microsoft Entra Global Administrator grants no implicit data-plane access to Azure Storage resources; Global Administrator is a directory-management role and does not, by itself, satisfy Azure Files ' identity-based authentication requirements (which additionally require configuring azureFilesIdentityBasedAuthentication and assigning an explicit RBAC data role such as Storage File Data SMB Share Contributor) - none of which are present in this template, so Global Administrators cannot access the file share using Azure AD credentials - No. All three selections match the source document ' s answer key.
Official Reference
Configure Azure Storage firewalls / Enable identity-based authentication for Azure Files - https://learn.
microsoft.com/en-us/azure/storage/files/storage-files-identity-auth-active-directory-enable
contoso.com이라는 이름의 Azure Directory(Azure AD) 테넌트가 포함된 Azure 구독이 있습니다.
테넌트는 온프레미스 Active Directory 도메인과 동기화됩니다. 해당 도메인에는 다음 표에 표시된 사용자가 포함되어 있습니다.
모든 사용자에 대해 셀프 서비스 암호 재설정(SSPR)을 활성화하고 SSPR에 다음과 같은 인증 방법을 구성합니다.
재설정에 필요한 방법 수: 2
사용자가 이용할 수 있는 방법: 휴대폰, 보안 질문
등록에 필요한 질문 수: 3개
재설정에 필요한 문제 수: 3
다음 보안 질문을 선택하십시오.
가장 좋아하는 음식은 무엇인가요?
당신의 첫 직장은 어느 도시였나요?
당신의 첫 반려동물 이름은 무엇이었나요?
다음 각 문장에 대해, 문장이 사실이면 '예'를 선택하고, 그렇지 않으면 '아니요'를 선택하십시오.
참고: 정답 하나당 1점입니다.

전시하다

전시하다
正確答案:

Explanation:
Detailed Explanation
Microsoft Entra ID explicitly excludes the ' Security questions ' authentication method from any account that holds an administrative directory role -- administrators (such as a Security Administrator or Billing Administrator) can never register or use security questions for SSPR, regardless of tenant-wide SSPR policy, because that method is considered too weak for privileged accounts. SecAdmin1 and BillAdmin1 therefore cannot be required to answer a security question (No, No), even though the tenant policy lists it as an available method. A standard, non-administrative user such as User1 has no such restriction; since only two methods are enabled tenant-wide (mobile phone and security questions) and two are required to reset, User1 must use both enabled methods, including the security question (Yes). This matches the source document ' s key.
Official Reference
Microsoft Entra self-service password reset authentication methods - https://learn.microsoft.com/en-us/entra
/identity/authentication/concept-sspr-howitworks
App1에 대한 해결책을 제시해야 합니다. 제시된 해결책은 기술 요구 사항을 충족해야 합니다. 해결책 제시에는 어떤 내용을 포함해야 할까요? 답변란에서 적절한 옵션을 선택하세요.
참고: 정답 하나당 1점입니다.

전시하다
正確答案:

Explanation:
Detailed Explanation
App1 ' s three tiers (web front end, processing middle tier, SQL database) sit in the same Azure region
/subscription with no stated requirement for network isolation across regions, hybrid connectivity boundaries, or separate address spaces, so a single virtual network is sufficient and keeps the design simple and cost- effective, consistent with the " minimize administrative effort " requirement. The binding constraint is instead
" minimize the number of open ports between the App1 tiers, " which is achieved by placing each tier in its own subnet and then applying a network security group per subnet that permits only the specific ports each tier legitimately needs from its neighboring tier (for example, HTTPS from the Internet to the web subnet, and only the application port from web to middle tier, and only the SQL port from middle tier to the database subnet). That calls for three subnets - one per tier - inside one VNet. This is a standard three-tier network segmentation pattern and matches Microsoft ' s reference architecture guidance for multi-tier applications on Azure.
Official Reference
Network security groups overview - https://learn.microsoft.com/en-us/azure/virtual-network/network- security-groups-overview
가상 네트워크 서브넷에 가상 머신 5대를 배포할 계획입니다.
각 가상 머신은 공용 IP 주소와 사설 IP 주소를 갖게 됩니다.
각 가상 머신은 동일한 인바운드 및 아웃바운드 보안 규칙을 필요로 합니다.
필요한 최소 네트워크 인터페이스 및 네트워크 보안 그룹 수는 몇 개입니까? 답변하려면 답변 영역에서 적절한 옵션을 선택하십시오.
참고: 정답 하나당 1점입니다.

전시하다
正確答案:

Explanation:
Detailed Explanation
Each virtual machine requires exactly one NIC to carry both its private IP address and an associated public IP address (a NIC IP configuration supports one private and one public IP simultaneously), so five VMs require a minimum of five NICs - you cannot share a NIC across VMs. Because all five VMs require identical inbound and outbound security rules, a single NSG is sufficient: that one NSG can be associated with either the subnet or all five NICs, and its rule set applies uniformly to every attached resource. There is no requirement to create a separate NSG per VM when the rule sets are identical, so the minimum is 1, not 5.
Official Reference
Network security groups overview - https://learn.microsoft.com/en-us/azure/virtual-network/network- security-groups-overview
Azure 구독을 보유하고 계십니다.
Azure Bastion을 사용할 VNET1이라는 가상 네트워크를 배포하기 위해 Azure Resource Manager 템플릿을 사용할 계획입니다.
이 양식을 어떻게 작성해야 할까요? 답변하려면 답변란에서 적절한 옵션을 선택하세요.
참고: 정답 하나당 1점입니다.

전시하다
正確答案:

Explanation:
CORRECTED ANSWER: Subnet name: AzureBastionSubnet | Address prefix: 10.10.10.0/27) Detailed Explanation Azure Bastion requires a dedicated subnet with the exact, case-sensitive reserved name AzureBastionSubnet
- Azure will not deploy Bastion into a subnet with any other name, ruling out AzureFirewallSubnet (reserved for Azure Firewall instead), LAN01, and RemoteAccessSubnet. CURRENCY UPDATE: Microsoft Learn ' s current Azure Bastion configuration settings documentation states the subnet size " must be /26 or larger (/25, /24, etc.) " for Bastion resources deployed on or after 2 November 2021, with /26 specifically recommended to support host-scaling features - the older /27 minimum has been retired for new deployments. None of this question ' s offered address prefixes (/27, /29, /30) actually satisfies the current /26- or-larger requirement: /29 and /30 are far too small to ever have been valid, and /27, while it was the historical minimum before November 2021, no longer meets today ' s requirement for a new deployment. If forced to choose only among the given options, /27 is the closest/least-wrong, but administrators building a new template today should size AzureBastionSubnet at /26 or larger, which is not represented among this question
' s choices.
Official Reference
About Azure Bastion configuration settings - https://learn.microsoft.com/en-us/azure/bastion/configuration- settings
귀하의 Azure 구독에는 다음 표에 표시된 스토리지 계정이 포함되어 있습니다.

어떤 스토리지 계정이 수명주기 관리를 지원하는지, 그리고 어떤 스토리지 계정이 데이터를 아카이브 액세스 계층으로 이동하는 것을 지원하는지 파악해야 합니다.
각 요구사항에 대해 무엇을 파악해야 할까요?
正確答案:

Explanation:
Lifecycle management: storage1, storage2, and storage3
The Archive access tier: storage2 only
Azure Blob Storage lifecycle management policies are supported for block blobs and append blobs in general-purpose v2 (StorageV2) accounts and premium BlockBlobStorage accounts. Therefore, storage1 and storage2 support lifecycle management because both are StorageV2 accounts, while storage3 also supports lifecycle management because it is a premium block blob account. Microsoft specifically lists lifecycle management policy support for these account types. However, premium BlockBlobStorage has an important limitation: lifecycle policies can perform supported operations such as deletion, but tiering to cool, cold, or archive is not supported for premium block blob storage.
Archive-tier eligibility is further restricted by the account ' s redundancy configuration. Microsoft states that the Archive tier supports only LRS, GRS, and RA-GRS . It does not support ZRS, GZRS, or RA-GZRS .
Consequently, storage1 cannot use Archive because it uses GZRS. storage3 cannot use Archive because it is both premium BlockBlobStorage and configured with ZRS. storage2 uses StorageV2 with RA-GRS , which satisfies both the account-type and redundancy requirements for Archive.
Reference topics: Azure Storage account types, Blob lifecycle management, access tiers, Archive tier, redundancy options, StorageV2 and premium BlockBlobStorage .
Azure Backup으로 보호되는 Azure Linux 가상 머신이 있습니다.
일주일 전, 가상 머신에서 파일 두 개가 삭제되었습니다.
클라이언트가 사내 컴퓨터에 최대한 빨리 연결되도록 해야 합니다.
어떤 네 가지 행동을 순서대로 수행해야 할까요? 정답을 고르려면, 행동 목록에서 적절한 행동을 골라 답란에 옮겨 올바른 순서대로 배열하세요.

전시하다
正確答案:

Explanation:
Detailed Explanation
Azure Backup ' s File Recovery feature (used to restore individual files without performing a full VM restore) is initiated from the Recovery Services vault ' s backup item by clicking File Recovery, then selecting the desired restore point, which generates a downloadable script/executable and an access password. Running that script mounts the recovery point as an accessible volume. For a Linux VM specifically, Microsoft ' s documentation directs users to copy the recovered files using command-line tools such as AzCopy or rsync
/scp, since a graphical File Explorer is a Windows-only concept and not applicable to a Linux source VM ' s recovered volume -- confirming AzCopy, not File Explorer, is the correct final step here. This sequence matches the source key exactly.
Official Reference
Recover files from an Azure virtual machine backup - https://learn.microsoft.com/en-us/azure/backup
/backup-azure-restore-files-from-vm
Azure 구독에 VNet1이라는 가상 네트워크가 있습니다. VNet1은 10.0.0.0/16 IP 주소 공간을 사용하며 다음 표에 나와 있는 서브넷을 포함합니다.
서브넷1에는 라우터 역할을 하는 VM1이라는 가상 어플라이언스가 포함되어 있습니다.
RT1이라는 이름의 라우팅 테이블을 생성합니다.
VNet1으로 들어오는 모든 트래픽은 VM1을 통해 라우팅해야 합니다.
RT1을 어떻게 구성해야 합니까? 답변하려면 답변 영역에서 적절한 옵션을 선택하십시오.
참고: 정답 하나당 1점입니다.

전시하다

전시하다
正確答案:

Explanation:
Detailed Explanation
To force all inbound traffic entering VNet1 (via the VPN/ExpressRoute gateway) through the network virtual appliance VM1, the route table must be associated with the GatewaySubnet - that is where traffic first lands after crossing the gateway, so a route there intercepts it before it reaches any workload subnet. The route ' s address prefix must cover the entire VNet1 address space (10.0.0.0/16) so that traffic destined for any subnet is redirected, and the next hop type must be Virtual appliance (pointing at VM1 ' s private IP), since Virtual network or Virtual network gateway next hop types would simply use default system routing rather than sending traffic to VM1. This matches Azure ' s documented user-defined route (UDR) pattern for forced tunneling through an NVA.
Official Reference
Virtual network traffic routing - https://learn.microsoft.com/en-us/azure/virtual-network/virtual-networks- udr-overview
다음 그림과 같이 Policy1이라는 이름의 복구 서비스 볼트 백업 정책을 생성합니다.

전시하다

전시하다
正確答案:

Explanation:
Detailed Explanation
Azure Backup creates only one physical recovery point per scheduled run, but tags it with every retention rule that matches the day it falls on, and keeps that single recovery point for the longest of all matching retention periods. March 1 matches four rules simultaneously: it is a daily backup (30 days), it falls on a Sunday matching the weekly rule (10 weeks), it is the 1st of the month matching the day-based monthly rule (36 months), and - critically - it falls in March on day 1, exactly matching the day-based yearly rule (10 years).
The longest of these is 10 years, so the March 1 backup is retained for 10 years. November 1 matches the daily (30 days), weekly (10 weeks, since it is also a Sunday), and monthly (36 months, being the 1st of the month) rules, but it does not match the yearly rule, which is scoped specifically to March - so its longest applicable retention is 36 months. This reflects the standard " longest matching tag wins " behavior of GFS (grandfather-father-son) retention in Azure Backup policies.
Official Reference
Configure Azure VM backups with the enhanced policy - https://learn.microsoft.com/en-us/azure/backup
/backup-azure-vms-enhanced-policy

聯系我們

如果您有任何問題,請留下您的電子郵件地址,我們將在12小時內回复電子郵件給您。

我們的工作時間:( GMT 0:00-15:00 )
週一至週六

技術支持: 立即聯繫 

English 日本語 Deutsch 한국어