AZ-305 Exam Question 11

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your company has deployed several virtual machines (VMs) on-premises and to Azure. Azure ExpressRoute has been deployed and configured for on-premises to Azure connectivity.
Several VMs are exhibiting network connectivity issues.
You need to analyze the network traffic to determine whether packets are being allowed or denied to the VMs.
Solution: Use the Azure Traffic Analytics solution in Azure Log Analytics to analyze the network traffic.
Does the solution meet the goal?
  • AZ-305 Exam Question 12

    You have an Azure subscription named Subscription1 that is linked to a hybrid Azure Active Directory (Azure AD) tenant.
    You have an on-premises datacenter that does NOT have a VPN connection to Subscription1. The datacenter contains a computer named Server1 that has Microsoft SQL Server 2016 installed. Server1 is prevented from accessing the internet.
    An Azure logic app named LogicApp1 requires write access to a database on Server1.
    You need to recommend a solution to provide LogicApp1 with the ability to access Server1.
    What should you recommend deploying on-premises and in Azure? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    AZ-305 Exam Question 13

    You have an Azure subscription that contains a custom application named Application was developed by an external company named fabric, Ltd. Developers at Fabrikam were assigned role-based access control (RBAV) permissions to the Application components. All users are licensed for the Microsoft 365 E5 plan.
    You need to recommends a solution to verify whether the Faricak developers still require permissions to Application1. The solution must the following requirements.
    * To the manager of the developers, send a monthly email message that lists the access permissions to Application1.
    * If the manager does not verify access permission, automatically revoke that permission.
    * Minimize development effort.
    What should you recommend?
  • AZ-305 Exam Question 14

    You are designing a microservices architecture that will be hosted in an Azure Kubernetes Service (AKS) cluster. Apps that will consume the microservices will be hosted on Azure virtual machines. The virtual machines and the AKS cluster will reside on the same virtual network.
    You need to design a solution to expose the microservices to the consumer apps. The solution must meet the following requirements:
    * Ingress access to the microservices must be restricted to a single private IP address and protected by using mutual TLS authentication.
    * The number of incoming microservice calls must be rate-limited.
    * Costs must be minimized.
    What should you include in the solution?
  • AZ-305 Exam Question 15

    You need to configure an Azure policy to ensure that the Azure SQL databases have TDE enabled. The solution must meet the security and compliance requirements.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.