Free AZ-305 Exam Braindumps (page: 10)

Page 10 of 67

HOTSPOT (Drag and Drop is not supported)
You have an Azure subscription that contains a virtual network named VNET1 and 10 virtual machines. The virtual machines are connected to VNET1.

You need to design a solution to manage the virtual machines from the internet. The solution must meet the following requirements:

-Incoming connections to the virtual machines must be authenticated by using Azure Multi-Factor Authentication (MFA) before network connectivity is allowed.
-Incoming connections must use TLS and connect to TCP port 443.
-The solution must support RDP and SSH.

What should you include in the solution? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

  1. See Explanation section for answer.

Answer(s): A

Explanation:





Box 1: Just-in-time (JIT) VN access
Lock down inbound traffic to your Azure Virtual Machines with Microsoft Defender for Cloud's just-in-time (JIT) virtual machine (VM) access feature. This reduces exposure to attacks while providing easy access when you need to connect to a VM.

Note: Threat actors actively hunt accessible machines with open management ports, like RDP or SSH. Your legitimate users also use these ports, so it's not practical to keep them closed.
When you enable just-in-time VM access, you can select the ports on the VM to which inbound traffic will be blocked.
To solve this dilemma, Microsoft Defender for Cloud offers JIT. With JIT, you can lock down the inbound traffic to your VMs, reducing exposure to attacks while providing easy access to connect to VMs when needed.

Box 2: A conditional Access policy that has Cloud Apps assignment set to Azure Windows VM Sign-In
You can enforce Conditional Access policies such as multi-factor authentication or user sign-in risk check before authorizing access to Windows VMs in Azure that are enabled with Azure AD sign in. To apply Conditional Access policy, you must select the "Azure Windows VM Sign-In" app from the cloud apps or actions assignment option and then use Sign-in risk as a condition and/or require multi-factor authentication as a grant access control.


Reference:

https://docs.microsoft.com/en-us/azure/defender-for-cloud/just-in-time-access-overview
https://docs.microsoft.com/en-us/azure/active-directory/devices/howto-vm-sign-in-azure-ad-windows



You are designing an Azure governance solution.

All Azure resources must be easily identifiable based on the following operational information: environment, owner, department and cost center.

You need to ensure that you can use the operational information when you generate reports for the Azure resources.

What should you include in the solution?

  1. an Azure data catalog that uses the Azure REST API as a data source
  2. an Azure management group that uses parent groups to create a hierarchy
  3. an Azure policy that enforces tagging rules
  4. Azure Active Directory (Azure AD) administrative units

Answer(s): C

Explanation:

You apply tags to your Azure resources, resource groups, and subscriptions to logically organize them into a taxonomy. Each tag consists of a name and a value pair.

You use Azure Policy to enforce tagging rules and conventions. By creating a policy, you avoid the scenario of resources being deployed to your subscription that don't have the expected tags for your organization. Instead of manually applying tags or searching for resources that aren't compliant, you create a policy that automatically applies the needed tags during deployment.


Reference:

https://docs.microsoft.com/en-us/azure/azure-resource-manager/management/tag-policies



A company named Contoso, Ltd. has an Azure Active Directory (Azure AD) tenant that is integrated with Microsoft 365 and an Azure subscription.

Contoso has an on-premises identity infrastructure. The infrastructure includes servers that run Active Directory Domain Services (AD DS) and Azure AD Connect.

Contoso has a partnership with a company named Fabrikam. Inc. Fabrikam has an Active Directory forest and a Microsoft 365 tenant. Fabrikam has the same on-premises identity infrastructure components as Contoso.

A team of 10 developers from Fabrikam will work on an Azure solution that will be hosted in the Azure subscription of Contoso. The developers must be added to the Contributor role for a resource group in the Contoso subscription.

You need to recommend a solution to ensure that Contoso can assign the role to the 10 Fabrikam developers. The solution must ensure that the Fabrikam developers use their existing credentials to access resources

What should you recommend?

  1. In the Azure AD tenant of Contoso. create cloud-only user accounts for the Fabrikam developers.
  2. Configure a forest trust between the on-premises Active Directory forests of Contoso and Fabrikam.
  3. Configure an organization relationship between the Microsoft 365 tenants of Fabrikam and Contoso.
  4. In the Azure AD tenant of Contoso, create guest accounts for the Fabnkam developers.

Answer(s): D

Explanation:

You can use the capabilities in Azure Active Directory B2B to collaborate with external guest users and you can use Azure RBAC to grant just the permissions that guest users need in your environment.

Incorrect:
Not B: Forest trust is used for internal security, not external access.


Reference:

https://docs.microsoft.com/en-us/azure/role-based-access-control/role-assignments-external-users



Your company has the divisions shown in the following table.



Sub1 contains an Azure App Service web app named App1. App1 uses Azure AD for single-tenant user authentication. Users from contoso.com can authenticate to App1.

You need to recommend a solution to enable users in the fabrikam.com tenant to authenticate to App1.

What should you recommend?

  1. Configure the Azure AD provisioning service.
  2. Enable Azure AD pass-through authentication and update the sign-in endpoint.
  3. Use Azure AD entitlement management to govern external users.
  4. Configure Azure AD join.

Answer(s): C

Explanation:

Govern access for external users in Azure AD entitlement management
Azure AD entitlement management uses Azure AD business-to-business (B2B) to share access so you can collaborate with people outside your organization. With Azure AD B2B, external users authenticate to their home directory, but have a representation in your directory. The representation in your directory enables the user to be assigned access to your resources.

Incorrect:
Not A: You can enable automatic user provisioning for your multi-tenant application in Azure Active Directory.

Automatic user provisioning is the process of automating the creation, maintenance, and removal of user identities in target systems like your software-as-a-service applications.

Azure AD provides several integration paths to enable automatic user provisioning for your application.

* The Azure AD Provisioning Service manages the provisioning and deprovisioning of users from Azure AD to your application (outbound provisioning) and from your application to Azure AD (inbound provisioning). The service connects to the System for Cross-Domain Identity Management (SCIM) user management API endpoints provided by your application.
* Microsoft Graph
* The Security Assertion Markup Language Just in Time (SAML JIT) user provisioning.


Reference:

https://learn.microsoft.com/en-us/azure/active-directory/governance/entitlement-management-external-users
https://docs.microsoft.com/en-us/azure/active-directory/app-provisioning/isv-automatic-provisioning-multi-tenant-apps



Page 10 of 67



Post your Comments and Discuss Microsoft AZ-305 exam with other Community members:

Emma Martin 5/4/2024 3:57:10 AM
I highly recommend Xcerts.com's Microsoft AZ-305 Dumps PDF for anyone preparing for the AZ-305 certification exam. The content is well-organized, comprehensive, and up-to-date, covering all key topics effectively. The inclusion of real-world scenarios and practice questions makes it a valuable resource for honing Azure solutions skills. Passexam4sure's AZ-305 Dumps PDF is a must-have for achieving success in Azure solutions architecture!
UNITED STATES
upvote

Komar 4/14/2024 5:57:28 AM
Practice Questions seem very relevant and the price is quite affordable compare to other sites where they charge for study guides and the software separately.
UNITED STATES
upvote

Ken 3/27/2024 4:55:12 PM
I wanted to say thank you for the set of study guides and practice questions. They turned out to be very helpful. I pass the exam.
ITALY
upvote

Sushant 2/2/2024 9:49:29 PM
The question are very relevant to real exam. Some are word by word. However some answers are not 100% correct. So if you have some knowledge of the topics like me then it is an easy pass with these questions.
Anonymous
upvote

Žarko 9/5/2023 3:35:00 AM
@t it seems like azure service bus message quesues could be the best solution
UNITED KINGDOM
upvote

Santhi 1/1/2024 8:23:00 AM
passed today.40% questions were new.litwere case study,lots of new questions on afd,ratelimit,tm,lb,app gatway.got 2 set series of questions which are not present here.questions on azure cyclecloud, no.of vnet/vms required for implimentation,blueprints assignment/management group etc
INDIA
upvote

T 7/28/2023 9:06:00 PM
this question is keep repeat : you are developing a sales application that will contain several azure cloud services and handle different components of a transaction. different cloud services will process customer orders, billing, payment, inventory, and shipping. you need to recommend a solution to enable the cloud services to asynchronously communicate transaction information by using xml messages. what should you include in the recommendation?
NEW ZEALAND
upvote

alaska 10/24/2023 5:48:00 AM
i scored 87% on the az-204 exam. thanks! i always trust
GERMANY
upvote

Chere 9/15/2023 4:21:00 AM
found it good
Anonymous
upvote

Santhi 1/1/2024 8:23:07 AM
Passed Today.40% questions were new.Litwere case study,Lots of new Questions on AFD,Ratelimit,TM,LB,App gatway.Got 2 set series of questions which are not present here.Questions on Azure CycleCloud, No.of vnet/vm's required for implimentation,Blueprints assignment/management group etc
INDIA
upvote

alaska 10/24/2023 5:48:44 AM
I scored 87% on the AZ-204 exam. Thanks! I always trust
GERMANY
upvote

luvinit 9/27/2023 3:42:22 PM
purfect happy to be here
UNITED STATES
upvote

Chere 9/15/2023 4:21:27 AM
Found it good
Anonymous
upvote

Chere 9/15/2023 4:11:49 AM
I am.just visiting the website, it looks good and valid.
Anonymous
upvote

Žarko 9/5/2023 5:37:18 AM
Q42: Shouldn't Answer be Access Review?!!
UNITED KINGDOM
upvote

Žarko 9/5/2023 3:35:05 AM
@T It seems like Azure Service Bus message quesues could be the best solution
UNITED KINGDOM
upvote

Computers Student 8/18/2023 9:49:08 AM
I am planning to take this exam soon. I will share the results.
SOUTH AFRICA
upvote

T 7/28/2023 9:06:29 PM
This question is keep repeat : You are developing a sales application that will contain several Azure cloud services and handle different components of a transaction. Different cloud services will process customer orders, billing, payment, inventory, and shipping. You need to recommend a solution to enable the cloud services to asynchronously communicate transaction information by using XML messages. What should you include in the recommendation?
NEW ZEALAND
upvote

avread09 6/10/2023 11:07:44 PM
good set of questions
Anonymous
upvote

chopra 4/27/2023 10:27:30 PM
These questions cover a wide range of topics and are very helpful.
INDIA
upvote

Isaac 4/24/2023 10:50:33 PM
The dumps covered all the important topics. Very helpful for passing the exam.
UNITED KINGDOM
upvote

Rez 4/23/2023 1:03:57 AM
This is a good shortcut to passing. Questions are very similar to what I saw in my exam. That is what helped me pass.
GERMANY
upvote

George 3/27/2023 10:04:31 PM
This exam question and answer guide was an absolute lifesaver - I felt prepared and confident going into my exam and passed it.
CANADA
upvote

Pradhan 3/14/2023 12:10:40 AM
Real questions and answers in this exam dumps... helped me maximize my study time and pass my exam.
UNITED STATES
upvote

Amit 9/5/2022 10:54:10 PM
The good thing about this site is that they provide free updates. The latest upddate has the new exam questions.
INDIA
upvote

Ranjeet 6/29/2022 10:08:58 PM
Second attemp and managed to pass with the help of this exam dumps questions. What relief.
INDIA
upvote

Manish 6/25/2022 11:51:25 PM
I only needed one exam but as part of the 50% discount me and my friend got 2 exams. This is a win win for both of us since we split the cost.
INDIA
upvote