2024年更新のMicrosoft Certified: Cybersecurity Architect Expertが有効なSC-100日本語問題集を無料提供しています [Q94-Q111]

Share

2024年更新のMicrosoft Certified: Cybersecurity Architect Expertが有効なSC-100日本語問題集を無料提供しています

最新のFast2test SC-100日本語のPDF問題集をダウンロードしちゃおう:https://jp.fast2test.com/SC-100J-premium-file.html(178問題と解答)

質問 # 94
あなたの会社には、Microsoft Defender for Cloud のセキュリティが強化された Azure サブスクリプションがあります。
同社は米国政府と契約を締結しました。
NIST 800-53 に準拠するために現在のサブスクリプションを確認する必要があります。
まず何をすべきでしょうか?

  • A. Defender for Cloud から、セキュリティ スコアの推奨事項を確認します。
  • B. Microsoft Sentinel から、Microsoft Defender for Cloud データ コネクタを構成します。
  • C. Defender for Cloud から、監査レポートの Azure セキュリティ ベースラインを確認します。
  • D. Defender for Cloud から、規制遵守標準を追加します。

正解:D

解説:
https://docs.microsoft.com/en-us/azure/defender-for-cloud/update-regulatory-compliance-packages#what-regulatory-compliance-standards-are-available-in-defender-for-cloud


質問 # 95
あなたの会社には、Microsoft 365 サブスクリプション、Azure サブスクリプション、アマゾン ウェブ サービス (AWS) 実装を含むマルチクラウド環境があります。次のコンポーネントに対してセキュリティ体制管理ソリューションを推奨する必要があります。
* Azure LOT Edge デバイス
* AWS EC2 インスタンス
どのサービスを推奨事項に含めるべきですか? 回答するには、回答内の適切な選択肢を選択してください。注: 正しく選択するたびに 1 ポイントの価値があります。

正解:

解説:

Explanation:

https://docs.microsoft.com/en-us/azure/defender-for-iot/organizations/architecture
https://docs.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-aws?pivots=env-settings
https://docs.microsoft.com/en-us/azure/azure-arc/servers/overview#supported-cloud-operations


質問 # 96
Microsoft 365 サブスクリプションと Azure サブスクリプションをお持ちです。Microsoft 365 Defender と Microsoft Defender for Cloud が有効になっています。
Azure サブスクリプションには Microsoft Sentinel ワークスペースが含まれています。Microsoft Sentinel データ コネクタは、Microsoft 365、Microsoft 365 Defender、Defender for Cloud、および Azure 用に構成されています。
Windows Server を実行する Azure 仮想マシンをデプロイする予定です。
Microsoft Sentinel の拡張検出と応答 (EDR) およびセキュリティ オーケストレーション、自動化、および応答 (SOAR) 機能を有効にする必要があります。
各機能を有効にすることをどのように推奨しますか? 回答するには、回答領域で適切なオプションを選択してください。
注: 正しく選択するたびに 1 ポイントの価値があります。

正解:

解説:


質問 # 97
Azure リソースの保存データの暗号化標準を設計している場合、保存データが AES-256 キーを使用して暗号化されるようにするための推奨事項を提供する必要があります。ソリューションは、暗号化キーの毎月のローテーションをサポートする必要があります。
解決策: Azure Storage の BLOB コンテナーの場合は、暗号化スコープ内で Microsoft マネージド キーを使用する暗号化をお勧めします。
これは目標を達成していますか?

  • A. いいえ
  • B. はい

正解:A

解説:
https://docs.microsoft.com/en-us/azure/key-vault/keys/how-to-configure-key-rotation


質問 # 98
あなたの会社では Microsoft Defender for Cloud と Microsoft Sentinel を使用しています。同社は、次の展示に示すアーキテクチャを持つアプリケーションを設計しています。

あなたは、提案されたアーキテクチャ用のログ記録および監査ソリューションを設計しています。ソリューションは次の要件を満たしている必要があります。
* Azure Web アプリケーション ファイアウォール (WAF) ログを Microsoft Sentinel と統合します。
* Defender for Cloud を使用して、仮想マシンからのアラートを確認します。
ソリューションには何を含めるべきでしょうか? 回答するには、回答内の適切な選択肢を選択してください。注: 正しく選択するたびに 1 ポイントの価値があります。

正解:

解説:


質問 # 99
あなたの会社は、すべてのオンプレミス仮想マシンを Azure に移行することを計画しています。ネットワーク エンジニアは、次の表に示す Azure 仮想ネットワーク設計を提案します。

すべての仮想マシンへの安全なリモート アクセスを提供するには、Azure Bastion デプロイを推奨する必要があります。仮想ネットワーク設計に基づいて、Azure Bastion サブネットはいくつ必要ですか?

  • A. 0
  • B. 1
  • C. 2
  • D. 3
  • E. 4

正解:B

解説:
https://docs.microsoft.com/en-us/azure/bastion/vnet-peering
https://docs.microsoft.com/en-us/learn/modules/connect-vm-with-azure-bastion/2-what-is-azure-bastion


質問 # 100
ハイブリッド クラウド インフラストラクチャがあります。
次の表に示す Azure アプリケーションをデプロイする予定です。

各アプリの要件を満たすには何を使用する必要がありますか? 回答するには、回答内の適切な選択肢を選択してください。注: 正しく選択するたびに 1 ポイントの価値があります。

正解:

解説:

Explanation:
Text Description automatically generated with medium confidence


質問 # 101
ジャンプ サーバーをホストする、動的にスケーリングする Linux ベースの Azure 仮想マシン スケール セットをデプロイする予定です。ジャンプ サーバーは、インターネット経由で個人デバイスとキオスク デバイスを接続するサポート スタッフによって使用されます。ジャンプ サーバーのサブネットは、ネットワーク セキュリティ グループ (NSG) に関連付けられます。Azure 仮想マシン スケール セットのアクセス ソリューションを設計する必要があります。ソリューションは次の要件を満たす必要があります。
* サポート スタッフがジャンプ サーバーに接続するたびに確認します。サーバーへのアクセスを要求する必要があります。
* 認可されたサポート スタッフのみがジャンプ サーバーへの SSH 接続を開始できるようにしてください。
* 内部ネットワークやインターネットからのブルートフォース攻撃に対する保護を最大限に高めます。
* ユーザーがインターネットからのみジャンプ サーバーに接続できるようにします。
* 管理労力を最小限に抑える
ソリューションには何を含めるべきでしょうか? 回答するには、回答領域で適切なオプションを選択してください。
注: 正しく選択するたびに 1 ポイントの価値があります。

正解:

解説:

Explanation:


質問 # 102
Windows Server を実行する次のオンプレミス サーバーがあります。
* Active Directory ドメイン サービス (AD DS) ドメイン内の 2 つのドメイン コントローラー
* ASP.NET Web アプリを実行する Server1 および Server2 という名前の 2 つのアプリケーション サーバー
* RADIUS と AD DS を使用して認証する Server3 という名前の VPN サーバー エンド ユーザーは、VPN を使用してインターネット経由で Web アプリにアクセスします。
Web アプリへの接続のセキュリティを強化するには、ユーザー アクセス ソリューションを再設計する必要があります。ソリューションは攻撃対象領域を最小限に抑え、Microsoft サイバーセキュリティ リファレンス アーキテクチャ (MCRA) のゼロトラスト原則に従う必要があります。
推奨事項には何を含めるべきですか?

  • A. Microsoft Defender for Cloud Apps でコネクタとルールを構成します。
  • B. Azure AD アプリケーション プロキシを使用して Web アプリを公開します。
  • C. Azure AD 認証を使用するように VPN を構成します。
  • D. Microsoft Defender for Endpoint で Web 保護を構成します。

正解:B


質問 # 103
Microsoft 365 テナントがあります。
あなたの会社では、Azure AD テナントと統合されている App1 という名前のサードパーティのサービスとしてのソフトウェア (SaaS) アプリを使用しています。次の要件を満たすセキュリティ戦略を設計する必要があります。
* ユーザーは、セルフサービス リクエストを使用して App1 へのアクセスをリクエストできる必要があります。
* ユーザーが App1 へのアクセスをリクエストする場合、リクエストに関する追加情報の提供を求めるプロンプトが表示される必要があります。
* 3 か月ごとに、管理者はユーザーが依然として Appl へのアクセスを必要としているかどうかを確認する必要があります。
デザインには何を含めるべきですか?

  • A. Microsoft Defender for Cloud Apps の接続されたアプリ
  • B. Microsoft Entra Identity Governance
  • C. Azure AD アプリケーション プロキシ
  • D. Microsoft Defender for Cloud Apps のアクセス ポリシー

正解:B


質問 # 104
オンプレミス ネットワークには、Angular と Node.js で開発された e コマース Web アプリが含まれています。Web アプリは MongoDB データベースを使用します。Web アプリを Azure に移行する予定です。ソリューション アーキテクチャ チームは、Azure ランディング ゾーンとして次のアーキテクチャを提案します。

Web アプリとデータベース間の接続を保護するための推奨事項を提供する必要があります。ソリューションはゼロトラスト モデルに従う必要があります。
解決策: Azure Web アプリケーション ファイアウォール (WAF) を使用して Azure Front Door を実装することをお勧めします。
これは目標を達成していますか?

  • A. いいえ
  • B. はい

正解:A

解説:
https://www.varonis.com/blog/securing-access-azure-webapps
Topic 2, Fabrikam, Inc Case Study 1
OverView
Fabrikam, Inc. is an insurance company that has a main office in New York and a branch office in Paris.
On-premises Environment
The on-premises network contains a single Active Directory Domain Services (AD DS) domain named corp.fabrikam.com.
Azure Environment
Fabrikam has the following Azure resources:
* An Azure Active Directory (Azure AD) tenant named fabrikam.onmicrosoft.com that syncs with corp.fabnkam.com
* A single Azure subscription named Sub1
* A virtual network named Vnet1 in the East US Azure region
* A virtual network named Vnet2 in the West Europe Azure region
* An instance of Azure Front Door named FD1 that has Azure Web Application Firewall (WAR enabled
* A Microsoft Sentinel workspace
* An Azure SQL database named ClaimsDB that contains a table named ClaimDetails
* 20 virtual machines that are configured as application servers and are NOT onboarded to Microsoft Defender for Cloud
* A resource group named TestRG that is used for testing purposes only
* An Azure Virtual Desktop host pool that contains personal assigned session hosts All the resources in Sub1 are in either the East US or the West Europe region.
Partners
Fabrikam has contracted a company named Contoso, Ltd. to develop applications. Contoso has the following infrastructure-.
* An Azure AD tenant named contoso.onmicrosoft.com
* An Amazon Web Services (AWS) implementation named ContosoAWS1 that contains AWS EC2 instances used to host test workloads for the applications of Fabrikam Developers at Contoso will connect to the resources of Fabrikam to test or update applications. The developers will be added to a security Group named Contoso Developers in fabrikam.onmicrosoft.com that will be assigned to roles in Sub1.
The ContosoDevelopers group is assigned the db.owner role for the ClaimsDB database.
Compliance Event
Fabrikam deploys the following compliance environment:
* Defender for Cloud is configured to assess all the resources in Sub1 for compliance to the HIPAA HITRUST standard.
* Currently, resources that are noncompliant with the HIPAA HITRUST standard are remediated manually.
* Qualys is used as the standard vulnerability assessment tool for servers.
Problem Statements
The secure score in Defender for Cloud shows that all the virtual machines generate the following recommendation-. Machines should have a vulnerability assessment solution.
All the virtual machines must be compliant in Defender for Cloud.
ClaimApp Deployment
Fabrikam plans to implement an internet-accessible application named ClaimsApp that will have the following specification
* ClaimsApp will be deployed to Azure App Service instances that connect to Vnetl and Vnet2.
* Users will connect to ClaimsApp by using a URL of https://claims.fabrikam.com.
* ClaimsApp will access data in ClaimsDB.
* ClaimsDB must be accessible only from Azure virtual networks.
* The app services permission for ClaimsApp must be assigned to ClaimsDB.
Application Development Requirements
Fabrikam identifies the following requirements for application development:
* Azure DevTest labs will be used by developers for testing.
* All the application code must be stored in GitHub Enterprise.
* Azure Pipelines will be used to manage application deployments.
* All application code changes must be scanned for security vulnerabilities, including application code or configuration files that contain secrets in clear text. Scanning must be done at the time the code is pushed to a repository.
Security Requirement
Fabrikam identifies the following security requirements:
* Internet-accessible applications must prevent connections that originate in North Korea.
* Only members of a group named InfraSec must be allowed to configure network security groups (NSGs} and instances of Azure Firewall, VJM. And Front Door in Sub1.
* Administrators must connect to a secure host to perform any remote administration of the virtual machines.
The secure host must be provisioned from a custom operating system image.
AWS Requirements
Fabrikam identifies the following security requirements for the data hosted in ContosoAWSV.
* Notify security administrators at Fabrikam if any AWS EC2 instances are noncompliant with secure score recommendations.
* Ensure that the security administrators can query AWS service logs directly from the Azure environment.
Contoso Developer Requirements
Fabrikam identifies the following requirements for the Contoso developers;
* Every month, the membership of the ContosoDevelopers group must be verified.
* The Contoso developers must use their existing contoso.onmicrosoft.com credentials to access the resources in Sub1.
* The Comoro developers must be prevented from viewing the data in a column named MedicalHistory in the ClaimDetails table.
Compliance Requirement
Fabrikam wants to automatically remediate the virtual machines in Sub1 to be compliant with the HIPPA HITRUST standard. The virtual machines in TestRG must be excluded from the compliance assessment.


質問 # 105
あなたの会社はデータを Azure に移行しています。データには個人を特定できる情報 (Pll) が含まれています。同社は、Azure の Pll データ ストアに Microsoft Information Protection を使用する予定です。Azure リソース内でリスクにさらされている PLL データを検出するソリューションを推奨する必要があります。
推奨事項には何を含めるべきですか? 回答するには、回答内の適切な選択肢を選択してください。注: 正しく選択するたびに 1 ポイントの価値があります。

正解:

解説:


質問 # 106
仮想デスクトップ インフラストラクチャ (VDI) を含む Active Directory ドメイン サービス (AD DS) ドメインがあります。VDI は、非永続イメージとクローン作成された仮想マシン テンプレートを使用します。VDI デバイスはドメインのメンバーです。
Azure Virtual Desktop 環境を含む Azure サブスクリプションを持っています。この環境には、カスタム ゴールデン イメージを使用するホスト プールが含まれています。すべての Azure Virtual Desktop デプロイは、単一の Azure Active Directory Domain Services (Azure AD DS) ドメインのメンバーです。
Microsoft Defender for Endpoint をホストに展開するためのソリューションを推奨する必要があります。ソリューションは次の要件を満たす必要があります。
* 最初の起動シーケンス中にホストが Defender for Endpoint にオンボードされていることを確認します。
* Microsoft Defender 365 ポータルに、展開された VDI ホストごとに 1 つのエントリが含まれていることを確認します。
* 管理労力を最小限に抑えます。
何を勧めるべきですか? 回答するには、回答内の適切な選択肢を選択してください。注: 正しく選択するたびに 1 ポイントの価値があります。

正解:

解説:


質問 # 107
Azure Pipelines と Azure Repos を使用して、継続的インテグレーションと継続的デプロイ (CI/CO) ワークフローを実装します。
Microsoft Cloud Adoption Framework for Azure に基づいて、CI/CD ワークフローの段階を保護するためのベスト プラクティスを推奨する必要があります。
各段階の推奨事項には何を含めるべきですか? 回答するには、回答領域で適切なオプションを選択してください。
注: 正しく選択するたびに 1 ポイントの価値があります。

正解:

解説:

Explanation:


質問 # 108
Microsoft 365 E5 サブスクリプションをお持ちです。
あなたは、100 万を超えるドキュメントを含む Microsoft SharePoint Online サイトの機密データを保護するソリューションを設計しています。
個人識別情報 (Pll) の共有を防ぐソリューションを推奨する必要があります。
推奨事項に含めるべき 2 つのコンポーネントはどれですか? それぞれの正解は、解決策の一部を示しています。
注: 正しく選択するたびに 1 ポイントの価値があります。

  • A. 機密ラベルポリシー
  • B. データ損失防止 (DLP) ポリシー
  • C. 保持ラベルポリシー
  • D. 電子情報開示ケース

正解:A、B

解説:
Data loss prevention in Office 365. Data loss prevention (DLP) helps you protect sensitive information and prevent its inadvertent disclosure. Examples of sensitive information that you might want to prevent from leaking outside your organization include financial data or personally identifiable information (PII) such as credit card numbers, social security numbers, or health records. With a data loss prevention (DLP) policy, you can identify, monitor, and automatically protect sensitive information across Office 365.
Sensitivity labels from Microsoft Purview Information Protection let you classify and protect your organization's data without hindering the productivity of users and their ability to collaborate. Plan for integration into a broader information protection scheme. On top of coexistence with OME, sensitivity labels can be used along-side capabilities like Microsoft Purview Data Loss Prevention (DLP) and Microsoft Defender for Cloud Apps.
https://motionwave.com.au/keeping-your-confidential-data-secure-with-microsoft-office-365/ https://docs.microsoft.com/en-us/microsoft-365/solutions/information-protection-deploy-protect-information?view=o365-worldwide#sensitivity-labels


質問 # 109
Microsoft 365 Defender を使用して保護された Microsoft 365 サブスクリプションがある。 Microsoft Sentinel を使用して Microsoft 365 および Microsoft 365 Defender からのイベントを監視するセキュリティ運用戦略を設計している。 次の要件を満たすソリューションを推奨する必要があります。
* Microsoft Sentinel をサードパーティのセキュリティ ベンダーと統合して、既知のマルウェアに関する情報にアクセスします
* イベント内でコマンド アンド コントロール サーバーの IP アドレスが検出されると、インシデントが自動的に生成されます。各要件を満たすには、Microsoft Sentinel で何を構成する必要がありますか? 回答するには、回答領域で適切なオプションを選択してください。
注: 正しく選択するたびに 1 ポイントの価値があります。

正解:

解説:

Explanation:


質問 # 110
Azure サブスクリプションをお持ちです。サブスクリプションには、Windows Server を実行する 100 台の仮想マシンが含まれています。仮想マシンは、Azure Policy と Microsoft Defender for Servers を使用して管理されます。
仮想マシンのセキュリティを強化する必要があります。ソリューションは次の要件を満たす必要があります。
* 許可リストにあるアプリのみを実行できるようにしてください。
* 管理者は許可リストに追加された各アプリを確認する必要があります。
* 不正なアプリを起動しようとすると、自動的にブロックリストに追加されます。
* アプリをブロックリストから許可リストに移動するには、管理者がアプリを承認する必要があります。
ソリューションには何を含めるべきでしょうか?

  • A. Azure Policy のコンピューティング ポリシー
  • B. Microsoft Defender for Cloud Apps のアプリ ガバナンス
  • C. Defender for Servers の適応型アプリケーション コントロール
  • D. Azure AD のエンタープライズ アプリケーションの管理者の同意設定

正解:C


質問 # 111
......

実験された試験材料はSC-100日本語:https://jp.fast2test.com/SC-100J-premium-file.html


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어