You need to deploy an Azure Kubernetes Service (AKS) cluster that will contain an initial node pool named Pool1 for general workloads and an additional node pool named Pool2 for sensitive workloads. Each node pool must be assigned to a subnet, and pod IP addresses will be allocated directly from that subnet. The solution must support future node pools and minimize administrative effort.
Which type of subnet should you assign for each node pool? To answer, drag the appropriate subnet types to the correct node pools. Each subnet type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.


Explanation:

You have an Azure subscription that contains an Azure SQL Database logic server named SQL! and an Azure virtual machine named VM1. VM1 uses a private IP address only.
The Firewall and virtual networks settings for SQL1 are shown in the following exhibit.

You need to ensure that VM1 can connect to SQL1. The solution must use the principle of least privilege.
What should you do?
You have a Microsoft Entra tenant that contains the users shown in the following table.

AII the users have devices that contain certificates issued by a certification authority (CA) named ContosoCA.
You create a Conditional Access policy that has the following settings:
* Name: CAPoltcy1
* Assignments
o Users and groups: Group1
o Target resources
* Include: All cloud apps
o Access controls
* Grant access: Require multi-factor authentication
o Enable policy: On
You enable and target certificate-based authentication as shown in the Enable and Target exhibit. (Click the Enable and Target tab.)

You configure certificate-based authentication as shown in the Configure exhibit. (Click the Configure tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.


Explanation:

You need to delegate a user to implement the planned change for Defender for Cloud.
The solution must follow the principle of least privilege.
Which user should you choose?
You assign User8 the Owner role for RG4, RG5, and RG6.
In which resource groups can User8 create virtual networks and NSGs? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


Explanation:
Box1: RG6 only as there is not option for RG5 & RG6 which it should be.
Box2: RG4 & RG6
You have an Azure subscription that contains an Azure SQL server named sqlsrv1 and an Azure SQL database named DB1. Sqlsrv1 is configured for Microsoft Entra authentication only.
You have the Microsoft Entra identities shown in the following table.

Which users can create scoped credentials for DB1?
You have an Azure subscription.
You need to deploy an Azure virtual WAN to meet the following requirements:
* Create three secured virtual hubs located in the East US, West US, and North Europe Azure regions.
* Ensure that security rules sync between the regions.
What should you use?
You have an Azure subscription that contains virtual machines. The subscription uses Microsoft Defender for Cloud with the Foundational Cloud Security Posture Management (CSPM) plan.
You need to enable agentless scanning for the virtual machines.
What should you do in Defender for Cloud?
You have an Azure subscription that contains multiple virtual machines.
You have Amazon Web Services (AWS) workloads. The AWS accounts are onboarded to Microsoft Defender for Cloud.
You need to recommend a solution to ensure that the security team at your company receives security alerts in a central location for all the Azure and AWS resources The solution must meet the following requirements:
* Ensure that only critical alerts are received.
* Minimize costs.
What should you recommend?
You have an Azure subscription named Subscription1 that contains the resources shown in the following table.

You need to identify which initiatives and policies you can add to Subscription1 by using Azure Security Center.
What should you identify?
You have an Azure subscription that contains an Azure SQL database named sql1.
You plan to audit sql1.
You need to configure the audit log destination. The solution must meet the following requirements:
* Support querying events by using the Kusto query language.
* Minimize administrative effort.
What should you configure?
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company has an Active Directory forest with a single domain, named weylandindustries.com. They also have an Azure Active Directory (Azure AD) tenant with the same name.
You have been tasked with integrating Active Directory and the Azure AD tenant. You intend to deploy Azure AD Connect.
Your strategy for the integration must make sure that password policies and user logon limitations affect user accounts that are synced to the Azure AD tenant, and that the amount of necessary servers are reduced.
Solution: You recommend the use of pass-through authentication and seamless SSO with password hash synchronization.
Does the solution meet the goal?
You have an Azure subscription that contains the virtual machines shown in the following table.

VNET1, VNET2, and VNET3 are peered with each other. You perform the following actions:
* Create two application security groups named ASG1 and ASG2 in the West US region.
* Add the network interface of VM1 to ASG1.

Explanation:
Answer as below.
