Question 26

Your company finalizes the adoption of Azure and is implementing Microsoft Defender for Cloud.
You receive the following recommendations in Defender for Cloud
* Access to storage accounts with firewall and virtual network configurations should be restricted,
* Storage accounts should restrict network access using virtual network rules.
* Storage account should use a private link connection.
* Storage account public access should be disallowed.
You need to recommend a service to mitigate identified risks that relate to the recommendations. What should you recommend?
  • Question 27

    Your company plans to move all on-premises virtual machines to Azure. A network engineer proposes the Azure virtual network design shown in the following table.

    You need to recommend an Azure Bastion deployment to provide secure remote access to all the virtual machines. Based on the virtual network design, how many Azure Bastion subnets are required?
  • Question 28

    Your on-premises network contains an e-commerce web app that was developed in Angular and Nodejs. The web app uses a MongoDB database. You plan to migrate the web app to Azure. The solution architecture team proposes the following architecture as an Azure landing zone.

    You need to provide recommendations to secure the connection between the web app and the database. The solution must follow the Zero Trust model.
    Solution: You recommend creating private endpoints for the web app and the database layer.
    Does this meet the goal?
  • Question 29

    You are creating the security recommendations for an Azure App Service web app named App1.
    App1 has the following specifications:
    * Users will request access to App1 through the My Apps portal. A human resources manager will approve the requests.
    * Users will authenticate by using Azure Active Directory (Azure AD) user accounts.
    You need to recommend an access security architecture for App1.
    What should you include in the recommendation? To answer, select the appropriate options in the answer are a. NOTE: Each correct selection is worth one point.

    Question 30

    Your company has an Azure App Service plan that is used to deploy containerized web apps. You are designing a secure DevOps strategy for deploying the web apps to the App Service plan. You need to recommend a strategy to integrate code scanning tools into a secure software development lifecycle. The code must be scanned during the following two phases:
    Uploading the code to repositories Building containers
    Where should you integrate code scanning for each phase? To answer, select the appropriate options in the answer area.