Valid AZ-301 Dumps shared by PassLeader for Helping Passing AZ-301 Exam! PassLeader now offer the newest AZ-301 VCE dumps and AZ-301 PDF dumps, the PassLeader AZ-301 exam questions have been updated and ANSWERS have been corrected, get the newest PassLeader AZ-301 dumps with VCE and PDF here: https://www.passleader.com/az-301.html (277 Q&As Dumps)
BTW, DOWNLOAD part of PassLeader AZ-301 dumps from Cloud Storage: https://drive.google.com/open?id=1ah1U5ZfTQkd7hMRDhnN0gFL7q8qMqtUl
NEW QUESTION 263
You have an Azure SQL database named DB1 that contains multiple tables. You need to improve the performance of DB1. The solution must minimize administrative effort. What should you use?
A. Azure Monitor
B. Azure Advisor
C. Query Performance Insight
D. Automatic Tuning
Answer: D
Explanation:
Azure SQL Database and Azure SQL Managed Instance automatic tuning provides peak performance and stable workloads through continuous performance tuning based on AI and machine learning. Automatic tuning is a fully managed intelligent performance service that uses built-in intelligence to continuously monitor queries executed on a database, and it automatically improves their performance.
https://docs.microsoft.com/en-us/azure/azure-sql/database/automatic-tuning-overview
NEW QUESTION 264
A company has a hybrid ASP.NET Web API application that is based on a software as a service (SaaS) offering. Users report general issues with the data. You advise the company to implement live monitoring and use ad hoc queries on stored JSON data. You also advise the company to set up smart alerting to detect anomalies in the data. You need to recommend a solution to set up smart alerting. What should you recommend?
A. Azure Security Center and Azure Data Lake Store
B. Azure Data Lake Analytics and Azure Monitor Logs
C. Azure Application Insights and Azure Monitor Logs
D. Azure Site Recovery and Azure Monitor Logs
Answer: B
Explanation:
Application Insights, a feature of Azure Monitor, is an extensible Application Performance Management (APM) service for developers and DevOps professionals. Use it to monitor your live applications. It will automatically detect performance anomalies, and includes powerful analytics tools to help you diagnose issues and to understand what users actually do with your app.
https://docs.microsoft.com/en-us/azure/azure-monitor/app/app-insights-overview
NEW QUESTION 265
Your company has an on-premises data center and an Azure subscription. The on-premises data center contains a Hardware Security Module (HSM). Your network contains an Active Directory domain that is synchronized to an Azure Active Directory (Azure AD) tenant. The company is developing an application named Application1. Application1 will be hosted in Azure by using 10 virtual machines that run Windows Server 2016. Five virtual machines will be in the West Europe Azure region and five virtual machines will be in the East US Azure region. The virtual machines will store sensitive company information. All the virtual machines will use managed disks. You need to recommend a solution to encrypt the virtual machine disks by using BitLocker Drive Encryption (BitLocker).
Solution: Deploy one Azure Key Vault to each region. Configure virtual machines to use Azure Disk Encryption. Use a different Key Vault for encrypting virtual machine disks in each region.
Does this meet the goal?
A. Yes
B. No
Answer: B
Explanation:
The security key from the on-premises HSM need to be exported.
https://docs.microsoft.com/en-us/azure/security/azure-security-disk-encryption-prerequisites-aad
NEW QUESTION 266
Your company has an on-premises data center and an Azure subscription. The on-premises data center contains a Hardware Security Module (HSM). Your network contains an Active Directory domain that is synchronized to an Azure Active Directory (Azure AD) tenant. The company is developing an application named Application1. Application1 will be hosted in Azure by using 10 virtual machines that run Windows Server 2016. Five virtual machines will be in the West Europe Azure region and five virtual machines will be in the East US Azure region. The virtual machines will store sensitive company information. All the virtual machines will use managed disks. You need to recommend a solution to encrypt the virtual machine disks by using BitLocker Drive Encryption (BitLocker).
Solution:
– Deploy one Azure Key Vault to each region.
– Export two security keys from the on-premises HSM.
– Import the security keys from the HSM into each Azure Key Vault.
– Configure the virtual machines to use Azure Disk Encryption.
– Use a different Key Vault for encrypting virtual machine disks in each region.
Does this meet the goal?
A. Yes
B. No
Answer: A
Explanation:
We use the Azure Premium Key Vault with Hardware Security Modules (HSM) backed keys. The Key Vault has to be in the same region as the VM that will be encrypted. Note: If you want to use a key encryption key (KEK) for an additional layer of security for encryption keys, add a KEK to your key vault. Use the Add-AzKeyVaultKey cmdlet to create a key encryption key in the key vault. You can also import a KEK from your on-premises key management HSM.
https://docs.microsoft.com/en-us/azure/security/azure-security-disk-encryption-prerequisites-aad
NEW QUESTION 267
A company named Contoso, Ltd. has an Azure Active Directory (Azure AD) tenant that is integrated with Microsoft Office 365 and an Azure subscription. Contoso has an on-premises identity infrastructure. The infrastructure includes servers that run Active Directory Domain Services (AD DS), Active Directory Federation Services (AD FS), Azure AD Connect, and Microsoft Identity Manager (MIM). Contoso has a partnership with a company named Fabrikam, Inc. Fabrikam has an Active Directory forest and an Office 365 tenant. Fabrikam has the same on-premises identity infrastructure as Contoso. A team of 10 developers from Fabrikam will work on an Azure solution that will be hosted in the Azure subscription of Contoso. The developers must be added to the Contributor role for a resource group in the Contoso subscription. You need to recommend a solution to ensure that Contoso can assign the role to the 10 Fabrikam developers. The solution must ensure that the Fabrikam developers use their existing credentials to access resources. What should you recommend?
A. Configure an AD FS claims provider trust between the AD FS infrastructures of Fabrikam and Contoso.
B. Configure an organization relationship between the Office 365 tenants of Fabrikam and Contoso.
C. In the Azure AD tenant of Contoso, create guest accounts for the Fabrikam developers.
D. Configure a forest trust between the on-premises Active Directory forests of Contoso and Fabrikam.
Answer: D
Explanation:
Trust configurations – Configure trust from managed forests(s) or domain(s) to the administrative forest A one-way trust is required from production environment to the admin forest. Selective authentication should be used to restrict accounts in the admin forest to only logging on to the appropriate production hosts.
https://docs.microsoft.com/en-us/windows-server/identity/securing-privileged-access/securing-privileged-access-reference-material
NEW QUESTION 268
You have an Azure Active Directory (Azure AD) tenant. You plan to deploy Azure Cosmos DB databases that will use the SQL API. You need to recommend a solution to provide specific Azure AD user accounts with read access to the Cosmos DB databases. What should you include in the recommendation?
A. a resource token and an Access control (IAM) role assignment
B. shared access signatures (SAS) and conditional access policies
C. master keys and Azure Information Protection policies
D. certificates and Azure Key Vault
Answer: A
Explanation:
The Access control (IAM) pane in the Azure portal is used to configure role-based access control on Azure Cosmos resources. The roles are applied to users, groups, service principals, and managed identities in Active Directory. You can use built-in roles or custom roles for individuals and groups.
https://docs.microsoft.com/en-us/azure/cosmos-db/role-based-access-control
NEW QUESTION 269
You use Azure Application Insights. You plan to use continuous export. You need to store Application Insights data for five years. Which Azure service should you use?
A. Azure SQL Database
B. Azure Storage
C. Azure Monitor Logs
D. Azure Backup
Answer: B
Explanation:
Create a Continuous Export.
https://docs.microsoft.com/en-us/azure/azure-monitor/app/export-telemetry#continuous-export-advanced-storage-configuration
NEW QUESTION 270
You have data files in Azure Blob storage. You plan to transform the files and move them to Azure Data Lake Storage. You need to transform the data by using mapping data flow. Which Azure service should you use?
A. Azure Storage Sync
B. Azure Databricks
C. Azure Data Box Gateway
D. Azure Data Factory
Answer: D
Explanation:
You can use Copy Activity in Azure Data Factory to copy data from and to Azure Data Lake Storage Gen2, and use Data Flow to transform data in Azure Data Lake Storage Gen2.
https://docs.microsoft.com/en-us/azure/data-factory/connector-azure-data-lake-storage
NEW QUESTION 271
You need to recommend a solution to generate a monthly report of all the new Azure Resource Manager resource deployments in your subscription. What should you include in the recommendation?
A. Azure Log Analytics
B. Application Insights
C. the Change Tracking management solution
D. Azure Monitor Metrics
Answer: C
Explanation:
Azure Automation now supports update management, inventory, and change tracking. Update management delivers visibility of update compliance across Azure, on-premises, and other clouds for both Windows and Linux. Create scheduled deployments to orchestrate the installation of updates within a defined maintenance window. Exclude specific updates and get detailed troubleshooting logs to identify any issues during the deployment.
Incorrect:
Not D: Azure Monitor metrics include:
– Model Deploy Started: Number of model deployments started in this workspace.
– Model Deploy Succeeded: Number of model deployments that succeeded in this workspace.
– Model Deploy Failed: Number of model deployments that failed in this workspace.
https://azure.microsoft.com/en-us/blog/update-management-inventory-and-change-tracking-in-azure-automation-now-generally-available/
NEW QUESTION 272
You are planning to deploy an application named App1 that will run in containers on Azure Kubernetes Service (AKS) clusters. The AKS clusters will be distributed across four Azure regions. You need to recommend a storage solution for App1. Updated container images must be replicated automatically to all the AKS clusters. Which storage solution should you recommend?
A. Azure Content Delivery Network (CDN)
B. Premium SKU Azure Container Registry
C. Azure Cache for Redis
D. geo-redundant storage (GRS) accounts
Answer: B
Explanation:
https://docs.microsoft.com/en-us/azure/aks/operator-best-practices-multi-region
NEW QUESTION 273
Your company purchases an app named App1. You plan to run App1 on seven Azure virtual machines in an Availability Set. The number of fault domains is set to 3. The number of update domains is set to 20. You need to identify how many App1 instances will remain available during a period of planned maintenance. How many App1 instances should you identify?
A. 1
B. 2
C. 6
D. 7
Answer: C
Explanation:
Only one update domain is rebooted at a time. Here there are 7 update domain with one VM each (and 13 update domain with no VM).
https://docs.microsoft.com/en-us/azure/virtual-machines/windows/manage-availability
NEW QUESTION 274
You plan to deploy 10 applications to Azure. The applications will be deployed to two Azure Kubernetes Service (AKS) clusters. Each cluster will be deployed to a separate Azure region. The application deployment must meet the following requirements:
– Ensure that the applications remain available if a single AKS cluster fails.
– Ensure that the connection traffic over the internet is encrypted by using SSL without having to configure SSL on each container instance.
Which Azure service should you include in the recommendation?
A. Azure Front Door
B. Azure Traffic Manager
C. Azure Load Balancer
D. AKS ingress controller
Answer: A
Explanation:
Azure Front Door enables you to define, manage, and monitor the global routing for your web traffic by optimizing for best performance and instant global failover for high availability. With Front Door, you can transform your global (multi-region) consumer and enterprise applications into robust, high-performance personalized modern applications, APIs, and content that reaches a global audience with Azure. Front Door works at Layer 7 or HTTP/HTTPS layer and uses anycast protocol with split TCP and Microsoft’s global network for improving global connectivity.
Incorrect:
Not B: Azure Traffic Manager uses DNS (layer 3) to shape traffic. SSL works at Layer 6. Azure Traffic Manager can direct customers to their closest AKS cluster and application instance. For the best performance and redundancy, direct all application traffic through Traffic Manager before it goes to your AKS cluster.
https://docs.microsoft.com/en-us/azure/frontdoor/front-door-overview
NEW QUESTION 275
You have 100 devices that write performance data to Azure Blob storage. You plan to store and analyze the performance data in an Azure SQL database. You need to recommend a solution to move the performance data to the SQL database. What should you include in the recommendation?
A. Azure Data Box
B. Azure Data Factory
C. Azure Database Migration Service
D. Data Migration Assistant
Answer: B
Explanation:
You can copy data from Azure Blob to Azure SQL Database using Azure Data Factory.
https://docs.microsoft.com/en-us/azure/data-factory/tutorial-copy-data-dot-net
NEW QUESTION 276
……
Get the newest PassLeader AZ-301 VCE dumps here: https://www.passleader.com/az-301.html (277 Q&As Dumps)
And, DOWNLOAD the newest PassLeader AZ-301 PDF dumps from Cloud Storage for free: https://drive.google.com/open?id=1ah1U5ZfTQkd7hMRDhnN0gFL7q8qMqtUl