HOTSPOT You need to create Role1 to meet the platform protection requirements. How should you complete the role definition of Role1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Correct Answer: A
Explanation:
Explanation: 1) Microsoft.Compute/ 2) disks 3) /subscrption/{subscriptionId}/resourceGroups/{Resource Group Id} A new custom RBAC role named Role1 must be used to delegate the administration of the managed disks in Resource Group1. Role1 must be available only for Resource Group1.
Question 2
You need to meet the identity and access requirements for Group1. What should you do?
Correct Answer: D
Explanation:
https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/groups-dynamicmembership Scenario: Litware identifies the following identity and access requirements: All San Francisco users and their devices must be members of Group1. The tenant currently contain this group:
Question 3
You need to provide connectivity to storage1. The solution must meet the PaaS networking requirements and the business requirements. What should you include in the solution? HOTSPOT You need to recommend a configuration for the ExpressRoute connection from the Boston datacenter. The solution must meet the hybrid networking requirements and business requirements. What should you recommend? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Correct Answer: A
Explanation:
The correct answer is A. a service endpoint. A service endpoint extends the private address space of an Azure virtual network to an Azure PaaS service such as Azure Storage. This allows resources in the virtual network to access storage1 directly over the Microsoft backbone network while maintaining secure connectivity and meeting PaaS networking requirements. Service endpoints are commonly used when access to a storage account must be restricted to specific virtual networks without requiring a private IP address for the storage service. The other options do not fit the requirement: Azure Front Door and Azure Traffic Manager are used for application delivery and traffic routing, while a private endpoint would be chosen only if the requirement specifically called for private IP-based access to the storage account. Therefore, a service endpoint is the correct solution.
Demo Practice Mode
You are viewing only the questions marked as Demo.