Sub2에서 VM1, VM2, VM3의 보안을 평가하고 있습니다.
다음 각 문장에 대해, 문장이 사실이라면 '예'를 선택하세요. 그렇지 않으면 '아니요'를 선택하세요.
참고: 정답 1개당 1점입니다.


Explanation:

Topic 3, Fabrikam inc
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
General Overview
Fabrikam, Inc. is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. Fabrikam has IT, human resources (HR), and finance departments.
Existing Environment
Network Environment
Fabrikam has a Microsoft 365 subscription and an Azure subscription named subscription1.
The network contains an on-premises Active Directory domain named Fabrikam.com. The domain contains two organizational units (OUs) named OU1 and OU2. Azure AD Connect cloud sync syncs only OU1.
The Azure resources hierarchy is shown in the following exhibit.

The Azure Active Directory (Azure AD) tenant contains the users shown in the following table.

Azure AD contains the resources shown in the following table.

Subscription1 Resources
Subscription1 contains the virtual networks shown in the following table.

Subscription1 contains the network security groups (NSGs) shown in the following table.

Subscription1 contains the virtual machines shown in the following table.

Subscription1 contains the Azure key vaults shown in the following table.

Subscription1 contains a storage account named storage1 in the West US Azure region.
Planned Changes and Requirements
Planned Changes
Fabrikam plans to implement the following changes:
* Create two application security groups as shown in the following table.

* Associate the network interface of VM1 to ASG1.
* Deploy SecPol1 by using Azure Security Center.
* Deploy a third-party app named App1. A version of App1 exists for all available operating systems.
* Create a resource group named RG2.
* Sync OU2 to Azure AD.
* Add User1 to Group1.
Technical Requirements
Fabrikam identifies the following technical requirements:
* The finance department users must reauthenticate after three hours when they access SharePoint Online.
* Storage1 must be encrypted by using customer-managed keys and automatic key rotation.
* From Sentinel1, you must ensure that the following notebooks can be launched:
* Entity Explorer - Account
* Entity Explorer - Windows Host
* Guided Investigation Process Alerts
VM1, VM2, and VM3 must be encrypted by using Azure Disk Encryption.
Just in time (JIT) VM access for VM1, VM2, and VM3 must be enabled.
App1 must use a secure connection string stored in KeyVault1.
KeyVault1 traffic must NOT travel over the internet.
Appl이라는 Azure 웹앱이 포함된 Azure 구독이 있습니다.
Appl에 대한 조건부 액세스 정책을 구성하려고 합니다. 솔루션은 다음 요구 사항을 충족해야 합니다.
* Windows 기기에서만 App1에 대한 액세스를 허용합니다.
* 규정을 준수하는 것으로 표시된 장치만 Appl에 액세스하도록 허용합니다.
어떤 조건부 액세스 정책 설정을 구성해야 할까요? 답을 얻으려면 적절한 설정을 올바른 요구 사항에 맞게 드래그하세요. 각 설정은 한 번, 여러 번 또는 전혀 사용되지 않을 수 있습니다. 콘텐츠를 보려면 창 사이의 분할 막대를 드래그하거나 스크롤해야 할 수도 있습니다.
참고: 정답 1개당 1점입니다.


Explanation:

Azure Active Directory(Azure AD) 테넌트와 루트 관리 그룹이 있습니다.
Azure 구독 10개를 만들고 해당 구독을 라우팅 관리 그룹에 추가합니다.
루트 관리 그룹에 저장될 Azure Blueprints 정의를 만들어야 합니다.
가장 먼저 무엇을 해야 하나요?
Azure Active Directory(Azure AD) 데이터 커넥터가 있는 Azure Sentinel 작업 영역이 있습니다.
특정 IP 주소에서 발생하는 의심스러운 트래픽에 대한 위협을 사냥하고 있습니다.
작업 공간에 저장된 중간 이벤트에 주석을 달고 조사 그래프를 탐색할 때 IP 주소를 참조할 수 있어야 합니다.
어떤 세 가지 동작을 순서대로 수행해야 할까요? 답하려면 동작 목록에서 해당 동작을 정답 영역으로 옮겨 올바른 순서대로 정리하세요.


Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/sentinel/bookmarks
참고: 이 섹션에는 동일한 시나리오와 문제를 다루는 하나 이상의 문제 세트가 포함되어 있습니다. 각 문제는 해당 문제에 대한 고유한 해결책을 제시합니다. 해결책이 명시된 목표를 충족하는지 판단해야 합니다.
집합에 있는 두 개 이상의 해가 문제를 해결할 수 있습니다. 또한 집합에 있는 해 중 아무것도 문제를 해결하지 못할 수도 있습니다.
이 섹션의 질문에 답변한 후에는 다시 돌아올 수 없습니다. 따라서 해당 질문은 검토 화면에 표시되지 않습니다.
다음 표에 표시된 리소스가 포함된 Azure 구독이 있습니다.

다음 표에 사용자가 나와 있습니다.

SQL1이라는 이름의 Azure SQL 관리 인스턴스를 만들고 Microsoft Entra 전용 인증을 활성화합니다.
User1과 User2가 모두 SQL1에 대한 Microsoft Entra 관리자로 설정되어 있는지 확인해야 합니다.
해결 방법: MM을 SQL1의 Microsoft Entra 관리자로 설정합니다.
이것이 목표를 달성하는가?
온프레미스 네트워크에는 Active Directory 도메인 서비스(AD DS) 도메인과 다음 표에 표시된 장치가 포함되어 있습니다.
User1이라는 동기화된 사용자가 포함된 하이브리드 Microsoft Entra 테넌트가 있습니다.
다음 표에 표시된 Azure Files 공유가 포함된 Azure 구독이 있습니다.
storage1과 storage2에 저장 파일 데이터 SMB 공유 기여자 역할이 할당되었습니다.
Share!의 보안 설정은 다음 그림과 같이 구성됩니다.

다음 각 문장에 대해, 문장이 참이면 '예'를 선택하세요. 그렇지 않으면 '아니요'를 선택하세요.
참고: 정답 1개당 1점입니다.


Explanation:

Vault1이라는 이름의 Azure Key Vault가 포함된 Azure 구독이 있습니다.
Vault1에서 Secret1이라는 이름의 비밀을 생성합니다.
애플리케이션 개발자는 Azure Active Directory(Azure AD)에 애플리케이션을 등록합니다.
애플리케이션이 Secret1을 사용할 수 있는지 확인해야 합니다.
어떻게 해야 할까요?
네트워크에는 Azure Active Directory(Azure AD)와 동기화되는 adatum.com이라는 온-프레미스 Active Directory 도메인이 포함되어 있습니다.
Azure AD 테넌트에는 다음 표에 표시된 사용자가 포함되어 있습니다.

다음 그림과 같이 adatum.com에 대한 인증 방법 - 비밀번호 보호 설정을 구성합니다.

다음 각 문장에 대해, 문장이 사실이라면 '예'를 선택하세요. 그렇지 않으면 '아니요'를 선택하세요.
참고: 정답 1개당 1점입니다.


Explanation:
Text Description automatically generated

Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-ban-bad-on-premises-deploy
https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-password-ban-bad
Azure 구독이 있습니다. 구독에는 Windows Server를 실행하는 Azure 가상 머신이 포함되어 있습니다.
2016년
각 가상 머신에 사용자 지정 맬웨어 방지 가상 머신 확장 프로그램이 설치되도록 정책을 구현해야 합니다.
정책을 어떻게 작성해야 하나요? 답변하려면 답변 영역에서 적절한 옵션을 선택하세요.
참고: 정답 1개당 1점입니다.


Explanation:

Box 1: DeployIfNotExists
DeployIfNotExists executes a template deployment when the condition is met.
Box 2: Template
The details property of the DeployIfNotExists effects has all the subproperties that define the related resources to match and the template deployment to execute.
Deployment [required]
This property should include the full template deployment as it would be passed to the Microsoft.Resources
/deployment
References:
https://docs.microsoft.com/en-us/azure/governance/policy/concepts/effects