Microsoft
AZ-305 中文考古題練習
Microsoft Designing Microsoft Azure Infrastructure Solutions
共 153 題 · 中英對照 · 讀書模式 + 模擬考 + 正解對照 · NT$249 永久使用
題目試閱
Q1. Litware, Inc. 是一家中型的財務公司。Litware 的主要辦公室位於 Boston。網路中包含一個名為 Litware.com 的 Active Directory 樹系,並連結到一個名為 Litware.com 的 Microsoft Entra ID(前稱 Azure AD)租用戶。所有使用者都擁有 Microsoft Entra ID P2 授權。Litware 有第二個名為 dev.Litware.com 的 Microsoft Entra ID 租用戶,作為開發環境使用。Litware.com 租用戶有一個名為 capolicy1 的條件式存取原則。capolicy1 要求:當使用者透過 Azure portal 管理生產環境的 Azure 訂閱時,必須從 Microsoft Entra hybrid joined 裝置連線。Litware 有 10 個連結到 Litware.com 租用戶的 Azure 訂閱,以及五個連結到 dev.Litware.com 租用戶的 Azure 訂閱。所有訂閱都屬於一份 Enterprise Agreement (EA)。Litware.com 租用戶包含一個名為 Role1 的自訂 Azure role-based access control (Azure RBAC) 角色,該角色授予對 Azure Storage 中 blob 與檔案的 DataActions 讀取權限。Litware 的內部部署 (on-premises) 網路包含下表所示的資源。Litware 具有連往 Azure 的 ExpressRoute 連線。Litware 計劃實施下列變更:將 DB1 與 DB2 移轉到 Azure。將 App1 移轉到 Azure 虛擬機器。將裝載 App1 的 Azure 虛擬機器部署到 Azure 專用主機 (dedicated hosts)。Litware 定義下列驗證與授權需求:管理生產環境並使用 Azure portal 的使用者,必須從 Microsoft Entra hybrid joined 裝置連線,並使用 Azure Multi-Factor Authentication (MFA) 進行驗證。必須使用 Network Contributor 內建 RBAC 角色,來授予所有 Azure 訂閱中所有虛擬網路的權限。為了存取 Azure 中的資源,App1 必須使用裝載該應用程式的虛擬機器的受控識別 (managed identity)。必須使用 Role1 來為所有 Azure 訂閱的儲存體帳戶指派權限。RBAC 角色必須套用在盡可能最高的層級。Litware 定義下列復原能力 (resiliency) 需求:移轉到 Azure 後,DB1 與 DB2 必須符合下列需求:在本地 Azure 區域中的兩個可用性區域 (availability zone) 失效時仍維持可用性。自動容錯移轉 (fail over)。將 I/O 延遲降到最低。App1 必須符合下列需求:裝載於支援可用性區域的 Azure 區域。裝載於支援自動調整 (automatic scaling) 的 Azure 虛擬機器。在本地 Azure 區域中的兩個可用性區域失效時仍維持可用性。Litware 定義下列安全性與合規需求:App1 移轉到 Azure 後,必須確保新資料可以寫入應用程式,並且在三年期間內防止對新資料與既有資料進行修改。內部部署的使用者與服務必須能夠存取將裝載 App1 資料的 Azure Storage 帳戶。必須防止對將裝載 App1 資料的 Azure Storage 帳戶的公用端點 (public endpoint) 進行存取。生產環境中所有 Azure SQL 資料庫都必須啟用 Transparent Data Encryption (TDE)。App1 不得與其他工作負載共用實體硬體。Litware 定義下列商業需求:將管理工作降到最低。將成本降到最低。您計劃將 App1 移轉到 Azure。您需要為 App1 建議一個符合安全性與合規需求的儲存體解決方案。您應該建議哪一種儲存體類型,以及應該如何建議設定該儲存體?<br><img src="/qimg/az-305/question1_17_19_20_30_41.jpg" alt="題目圖表" style="max-width:100%;margin-top:8px;border-radius:6px"><br><img src="/qimg/az-305/question1.jpg" alt="題目圖表" style="max-width:100%;margin-top:8px;border-radius:6px">
Litware, Inc. is a medium-sized finance company. Litware has a main office in Boston. The network contains an Active Directory forest named Litware.com that is linked to an Microsoft Entra tenant named Litware.com. All users have Microsoft Entra ID P2 licenses. Litware has a second Microsoft Entra tenant named dev.Litware.com that is used as a development environment. The Litware.com tenant has a conditional acess policy named capolicy1. Capolicy1 requires that when users manage the Azure subscription for a production environment by using the Azure portal, they must connect from a Microsoft Entra hybrid joined device. Litware has 10 Azure subscriptions that are linked to the Litware.com tenant and five Azure subscriptions that are linked to the dev.Litware.com tenant. All the subscriptions are in an Enterprise Agreement (EA). The Litware.com tenant contains a custom Azure role-based access control (Azure RBAC) role named Role1 that grants the DataActions read permission to the blobs and files in Azure Storage. The on-premises network of Litware contains the resources shown in the following table. Litware has ExpressRoute connectivity to Azure. Litware plans to implement the following changes: Migrate DB1 and DB2 to Azure. Migrate App1 to Azure virtual machines. Deploy the Azure virtual machines that will host App1 to Azure dedicated hosts. Litware identifies the following authentication and authorization requirements: Users that manage the production environment by using the Azure portal must connect from a Microsoft Entra hybrid joined device and authenticate by using Azure Multi-Factor Authentication (MFA). The Network Contributor built-in RBAC role must be used to grant permission to all the virtual networks in all the Azure subscriptions. To access the resources in Azure, App1 must use the managed identity of the virtual machines that will host the app. Role1 must be used to assign permissions to the storage accounts of all the Azure subscriptions. RBAC roles must be applied at the highest level possible. Litware identifies the following resiliency requirements: Once migrated to Azure, DB1 and DB2 must meet the following requirements: Maintain availability if two availability zones in the local Azure region fail. Fail over automatically. Minimize I/O latency. App1 must meet the following requirements: Be hosted in an Azure region that supports availability zones. Be hosted on Azure virtual machines that support automatic scaling. Maintain availability if two availability zones in the local Azure region fail. Litware identifies the following security and compliance requirements: Once App1 is migrated to Azure, you must ensure that new data can be written to the app, and the modification of new and existing data is prevented for a period of three years. On-premises users and services must be able to access the Azure Storage account that will host the data in App1. Access to the public endpoint of the Azure Storage account that will host the App1 data must be prevented. All Azure SQL databases in the production environment must have Transparent Data Encryption (TDE) enabled. App1 must not share physical hardware with other workloads. Litware identifies the following business requirements: Minimize administrative effort. Minimize costs. You plan to migrate App1 to Azure. You need to recommend a storage solution for App1 that meets the security and compliance requirements. Which type of storage should you recommend, and how should you recommend configuring the storage?<br><img src="/qimg/az-305/question1_17_19_20_30_41.jpg" alt="題目圖表" style="max-width:100%;margin-top:8px;border-radius:6px"><br><img src="/qimg/az-305/question1.jpg" alt="題目圖表" style="max-width:100%;margin-top:8px;border-radius:6px">
Q2. 內部部署網路包含一個名為 contoso.com 的單一 Active Directory 網域。Contoso 有單一 Azure 訂閱。Contoso 與 Fabrikam, Inc. 有商業合作關係。Fabrikam 使用者透過網際網路,使用 Microsoft Entra ID(前稱 Azure AD)來賓帳戶 (guest account) 存取部分 Contoso 應用程式。Contoso 計劃將兩個名為 App1 與 App2 的應用程式部署到 Azure。App1 將是一個裝載於 Azure App Service 的 Python 網頁應用程式,需要 Linux 執行階段 (runtime)。Contoso 與 Fabrikam 的使用者都會存取 App1。App1 會存取數個需要第三方認證與存取字串的服務。這些認證與存取字串儲存在 Azure Key Vault 中。App1 將有六個執行個體:三個位於 East US Azure 區域,三個位於 West Europe Azure 區域。App1 有下列資料需求:每個執行個體會將資料寫入與該執行個體位於相同可用性區域的資料存放區。任一 App1 執行個體寫入的資料必須對所有 App1 執行個體可見。App1 只能從網際網路存取。App1 有下列連線需求:連往 App1 的連線必須通過 web application firewall (WAF)。連往 App1 的連線必須在執行個體之間進行 active-active 負載平衡。所有來自北美的 App1 連線都必須導向 East US 區域。所有其他連線都必須導向 West Europe 區域。每小時,您會透過叫用一個從所有 App1 執行個體複製檔案的 PowerShell 指令碼來執行維護工作。該 PowerShell 指令碼會從一個集中位置執行。App2 將是一個裝載於 App Service 的 .NET 應用程式,需要 Windows 執行階段。App2 有下列檔案儲存需求:將檔案儲存到 Azure Storage 帳戶。將檔案複寫到內部部署位置。確保內部部署用戶端可以使用 SMB 通訊協定透過 LAN 讀取檔案。您需要監控 App2 以分析在應用程式內執行不同交易所需的時間。此解決方案不得要求變更應用程式程式碼。應用程式開發人員會持續開發 App1 與 App2 的新版本。開發流程必須符合下列需求:在生產環境使用新版本之前,必須先將新應用程式版本的暫存 (staging) 執行個體部署到應用程式主機。測試新版本之後,應用程式的暫存版本會取代生產版本。從暫存切換到生產的新應用程式版本切換,必須在應用程式沒有任何停機時間的情況下進行。Contoso 定義下列管理 Fabrikam 存取資源的需求:每個月,Fabrikam 的一位客戶經理必須檢閱哪些 Fabrikam 使用者擁有 App1 的存取權限。不再需要權限的帳戶必須以來賓身分移除。此解決方案必須將開發工作降到最低。Azure 服務使用的所有密碼 (secret) 都必須儲存在 Azure Key Vault 中。需要認證的服務必須將認證繫結至該服務執行個體。認證不得在服務之間共用。您應該實作什麼來符合身分識別需求?<br><img src="/qimg/az-305/question2.jpg" alt="題目圖表" style="max-width:100%;margin-top:8px;border-radius:6px">
The on-premises network contains a single Active Directory domain named contoso.com. Contoso has a single Azure subscription. Contoso has a business partnership with Fabrikam, Inc. Fabrikam users access some Contoso applications over the internet by using Microsoft Entra ID (formerly Azure AD) guest accounts. Contoso plans to deploy two applications named App1 and App2 to Azure. App1 will be a Python web app hosted in Azure App Service that requires a Linux runtime. Users from Contoso and Fabrikam will access App1. App1 will access several services that require third-party credentials and access strings. The credentials and access strings are stored in Azure Key Vault. App1 will have six instances: three in the East US Azure region and three in the West Europe Azure region. App1 has the following data requirements: Each instance will write data to a data store in the same availability zone as the instance. Data written by any App1 instance must be visible to all App1 instances. App1 will only be accessible from the internet. App1 has the following connection requirements: Connections to App1 must pass through a web application firewall (WAF). Connections to App1 must be active-active load balanced between instances. All connections to App1 from North America must be directed to the East US region. All other connections must be directed to the West Europe region. Every hour, you will run a maintenance task by invoking a PowerShell script that copies files from all the App1 instances. The PowerShell script will run from a central location. App2 will be a NET app hosted in App Service that requires a Windows runtime. App2 has the following file storage requirements: Save files to an Azure Storage account. Replicate files to an on-premises location. Ensure that on-premises clients can read the files over the LAN by using the SMB protocol. You need to monitor App2 to analyze how long it takes to perform different transactions within the application. The solution must not require changes to the application code. Application developers will constantly develop new versions of App1 and App2. The development process must meet the following requirements: A staging instance of a new application version must be deployed to the application host before the new version is used in production. After testing the new version, the staging version of the application will replace the production version. The switch to the new application version from staging to production must occur without any downtime of the application. Contoso identifies the following requirements for managing Fabrikam access to resources: Every month, an account manager at Fabrikam must review which Fabrikam users have access permissions to App1. Accounts that no longer need permissions must be removed as guests. The solution must minimize development effort. All secrets used by Azure services must be stored in Azure Key Vault. Services that require credentials must have the credentials tied to the service instance. The credentials must NOT be shared between services. What should you implement to meet the identity requirements?<br><img src="/qimg/az-305/question2.jpg" alt="題目圖表" style="max-width:100%;margin-top:8px;border-radius:6px">
Q3. 您計劃將資料從內部部署 (on-premises) 環境匯入到 Azure。資料如下表所示。您應該建議使用什麼來移轉資料?<br><img src="/qimg/az-305/question4_1.jpg" alt="題目圖表" style="max-width:100%;margin-top:8px;border-radius:6px"><br><img src="/qimg/az-305/question4_2.jpeg" alt="題目圖表" style="max-width:100%;margin-top:8px;border-radius:6px">
You plan to import data from your on-premises environment to Azure. The data Is shown in the following table. What should you recommend using to migrate the data?<br><img src="/qimg/az-305/question4_1.jpg" alt="題目圖表" style="max-width:100%;margin-top:8px;border-radius:6px"><br><img src="/qimg/az-305/question4_2.jpeg" alt="題目圖表" style="max-width:100%;margin-top:8px;border-radius:6px">
…完整 153 題請點上方免費試做或購買。
關於 AZ-305 中文題庫
Microsoft Designing Microsoft Azure Infrastructure Solutions 的中文考古題練習題庫,共 153 題,全程繁體中文並提供中英對照。 兩種練習模式:讀書模式逐題作答、立即對答案(附正解對照);模擬考模式抽題計時、交卷自動計分(70% 及格)並回顧錯題。 可先免費試做 30 題再決定,購買序號後永久使用、進度雲端同步,手機與電腦皆可練習。
常見問題
AZ-305 中文題庫是免費的嗎?
可免費試做前 30 題。完整 153 題與模擬考、正解對照需購買序號解鎖,NT$249 永久使用、無訂閱。
AZ-305 題目是中文嗎?
是繁體中文,並提供中英對照可一鍵切換原文;產品名與技術縮寫(如 IAM、MFA)保留英文,與官方文件用語一致。
AZ-305 這份題庫有幾題?
共 153 題,附讀書模式(逐題作答、即時對答案)與模擬考模式(抽題計時、自動計分、70% 及格線、錯題回顧)。
可以用手機練習 AZ-305 嗎?
可以。手機、平板、電腦皆可,作答進度雲端記錄,換裝置能接續練習。
AZ-305 要怎麼購買與使用?
於蝦皮下單後收到實體序號卡,至 quiz.mltech.tw 用 Email 收驗證碼登入、輸入序號即永久解鎖。