100% 高得点合格保証SC-100日本語無制限335解答で[2026]
SC-100日本語問題集でPDF、SC-100日本語最速合格したいならここ
質問 # 70
Microsoft 365 E5 サブスクリプションをお持ちです。
機密データを含む電子メールの添付ファイルにウォーターマークを追加するソリューションを推奨する必要があります。推奨事項には何を含めるべきですか?
- A. Microsoft 情報保護
- B. インサイダーリスク管理
- C. アズール・パービュー
- D. クラウド アプリ向け Microsoft Defender
正解:A
解説:
https://docs.microsoft.com/en-us/microsoft-365/compliance/sensitivity-labels?view=o365-worldwide You can use sensitivity labels to: Provide protection settings that include encryption and content markings.
For example, apply a "Confidential" label to a document or email, and that label encrypts the content and applies a "Confidential" watermark. Content markings include headers and footers as well as watermarks, and encryption can also restrict what actions authorized people can take on the content. Protect content in Office apps across different platforms and devices. Supported by Word, Excel, PowerPoint, and Outlook on the Office desktop apps and Office on the web. Supported on Windows, macOS, iOS, and Android. Protect content in third-party apps and services by using Microsoft Defender for Cloud Apps. With Defender for Cloud Apps, you can detect, classify, label, and protect content in third-party apps and services, such as SalesForce, Box, or DropBox, even if the third-party app or service does not read or support sensitivity labels.
質問 # 71
Azure Automation アカウントで Runbook のセキュリティを設計しています。Runbook はデータを Azure Data Lake Storage Gen2 にコピーします。
コピー プロセスのコンポーネントを保護するソリューションを推奨する必要があります。
各コンポーネントの推奨事項には何を含める必要がありますか? 回答するには、回答内の適切な選択肢を選択してください。注: 正しく選択するたびに 1 ポイントの価値があります。
正解:
解説:
質問 # 72
Microsoft Defender for Cloud が Azure 管理グループに割り当てられています。
Microsoft Sentinel を展開しています。
アラートのトリアージ中に、修復の提案など、セキュリティ イベントに関する追加情報が必要になります。目標を達成するために使用できる 2 つのコンポーネントはどれですか? それぞれの正解は完全な解決策を示します。
注: 正しく選択するたびに 1 ポイントの価値があります。
- A. Microsoft Sentinel ノートブック
- B. Defender for Cloud のワークロード保護
- C. Defender for Cloud の脅威インテリジェンス レポート
- D. Microsoft Sentinel 脅威インテリジェンス ワークブック
正解:C、D
解説:
https://docs.microsoft.com/en-us/azure/sentinel/understand-threat-intelligence https://docs.microsoft.com/en-us/azure/defender-for-cloud/defender-for-cloud-introduction https://docs.microsoft.com/en-us/azure/defender-for-cloud/threat-intelligence-reports https://docs.microsoft.com/en-us/azure/sentinel/notebooks
質問 # 73
あなたは、Azure Front Door インスタンスを通じて Azure App Service Web アプリへのアクセスを提供するためのセキュリティ戦略を設計しています。
Web アプリが Front Door インスタンスを介したアクセスのみを許可するようにするソリューションを推奨する必要があります。
解決策: Front Door サービス タグからのトラフィックを許可するアクセス制限をお勧めします。
これは目標を達成していますか?
- A. いいえ
- B. はい
正解:B
解説:
https://docs.microsoft.com/en-us/azure/app-service/app-service-ip-restrictions#restrict-access-to-a-specific-azure
質問 # 74
Microsoft 365 E5 サブスクリプションと Azure サブスクリプトを持っている。次のコンポーネントの全体的なセキュリティ体制を強化するには、既存の環境を評価する必要があります。
* Microsoft Intune によって管理される Windows 11 デバイス
* Azure ストレージ アカウント
* Azure仮想マシン
コンポーネントを評価するには何を使用する必要がありますか? 回答するには、回答領域で適切なオプションを選択してください。
正解:
解説:
Explanation:
Selection 1: Microsoft 365 Defender (Microsoft Defender for Endpoint is part of it).
Selection 2: Microsoft Defender for Cloud.
Selection 3: Microsoft Defender for Cloud.
https://docs.microsoft.com/en-us/learn/modules/design-strategy-for-secure-paas-iaas-saas-services/8-specify-secu
質問 # 75
Microsoft 365 サブスクリプションがあり、1,000 人のユーザーと Group1 というグループが含まれています。すべてのユーザーは Windows 11 デバイスを所有しています。ユーザーは Microsoft Entra アカウントを使用してデバイスにサインインします。ユーザーにはデバイスの管理者権限がありません。
グループ1のメンバーは、ユーザーセッションを制御することで、ユーザーをリモートでサポートします。リモートコントロールセッションは、サポート対象ユーザーのセキュリティコンテキスト内で実行されます。
グループ1のメンバーがユーザーのデバイスに対して管理者権限を必要とするアプリを実行できるようにするソリューションを推奨する必要があります。このソリューションでは、サインインしている各標準ユーザーのコンテキストでアプリが実行されるようにする必要があります。
推薦書には何を含めるべきでしょうか?
- A. Microsoft Intune エンドポイント権限管理
- B. Microsoft Entra ID の特権 ID 管理 (PIM)
- C. Microsoft Entra 権限管理
- D. Windows ローカル管理者パスワード ソリューション (Windows LAPS)
正解:A
解説:
With Microsoft Intune Endpoint Privilege Management (EPM) your organization's users can run as a standard user (without administrator rights) and complete tasks that require elevated privileges. Tasks that commonly require administrative privileges are application installs (like Microsoft 365 Applications), updating device drivers, and running certain Windows diagnostics.
Endpoint Privilege Management supports your Zero Trust journey by helping your organization achieve a broad user base running with least privilege, while allowing users to still run tasks allowed by your organization to remain productive. For more information, see Zero Trust with Microsoft Intune.
Reference:
https://learn.microsoft.com/en-us/mem/intune/protect/epm-overview
質問 # 76
Microsoft 365 サブスクリプションと Azure サブスクリプションをお持ちです。Microsoft Defender XDR と Microsoft Defender for Cloud が有効になっています。
Azureサブスクリプションには50台の仮想マシンが含まれています。各仮想マシンはWindows Server 2019上で異なるアプリケーションを実行します。
仮想マシン上で許可されたアプリケーションのみが実行できるようにするソリューションを推奨する必要があります。許可されていないアプリケーションが実行またはインストールされようとした場合、管理者が承認するまで、そのアプリケーションは自動的にブロックされる必要があります。
どのセキュリティ制御を推奨すべきでしょうか?
- A. Microsoft Entra テナント内のアプリ登録
- B. Microsoft Defender for Endpoint のアプリケーション制御ポリシー
- C. Microsoft Defender for Cloud Apps の OAuth アプリ ポリシー
- D. Microsoft Endpoint Manager のアプリ保護ポリシー
正解:B
解説:
Microsoft Defender for Endpoint includes application control policies that allow you to define which applications are authorized to run on a machine.
This can help block any unauthorized applications and provide an approval mechanism, ensuring that only approved software is allowed to run.
The solution aligns with the requirement to block unauthorized applications from running on the virtual machines automatically until approved by an administrator.
質問 # 77
Contoso 開発者の要件を満たすには、Azure AD で何を作成する必要がありますか?
正解:
解説:
質問 # 78
Azure Pipelines と Azure Repos を使用して、アプリケーションを Azure にデプロイするための継続的インテグレーションおよび継続的デプロイメント (O/CD) ワークフローを実装します。Microsoft Cloud Adoption Framework for Azure の原則に基づいて、動的アプリケーション セキュリティ テスト (DAST) に何を含めるべきかを推奨する必要があります。何を勧めるべきですか?
- A. 単体テスト
- B. 依存関係のテスト
- C. 脅威モデリング
- D. 侵入テスト
正解:B
解説:
Topic 2, Fabrikam, Inc
On-premises Environment
The on-premises network contains a single Active Directory Domain Services (AD DS) domain named corp.fabrikam.com.
Azure Environment
Fabrikam has the following Azure resources:
* An Azure Active Directory (Azure AD) tenant named fabrikam.onmicrosoft.com that syncs with corp.fabnkam.com
* A single Azure subscription named Sub1
* A virtual network named Vnet1 in the East US Azure region
* A virtual network named Vnet2 in the West Europe Azure region
* An instance of Azure Front Door named FD1 that has Azure Web Application Firewall (WAR enabled
* A Microsoft Sentinel workspace
* An Azure SQL database named ClaimsDB that contains a table named ClaimDetails
* 20 virtual machines that are configured as application servers and are NOT onboarded to Segment Microsoft Defender for Cloud
* A resource group named TestRG that is used for testing purposes only
* An Azure Virtual Desktop host pool that contains personal assigned session hosts All the resources in Sub1 are in either the East US or the West Europe region.
Partners
Fabrikam has contracted a company named Contoso, Ltd. to develop applications. Contoso has the following infrastructure-.
* An Azure AD tenant named contoso.onmicrosoft.com
* An Amazon Web Services (AWS) implementation named ContosoAWS1 that contains AWS EC2 instances used to host test workloads for the applications of Fabrikam Developers at Contoso will connect to the resources of Fabrikam to test or update applications. The developers will be added to a security Group named Contoso Developers in fabrikam.onmicrosoft.com that will be assigned to roles in Sub1.
The ContosoDevelopers group is assigned the db.owner role for the ClaimsDB database.
Compliance Event
Fabrikam deploys the following compliance environment:
* Defender for Cloud is configured to assess all the resources in Sub1 for compliance to the HIPAA HITRUST standard.
* Currently, resources that are noncompliant with the HIPAA HITRUST standard are remediated manually.
* Qualys is used as the standard vulnerability assessment tool for servers.
Problem Statements
The secure score in Defender for Cloud shows that all the virtual machines generate the following recommendation-. Machines should have a vulnerability assessment solution.
All the virtual machines must be compliant in Defender for Cloud.
ClaimApp Deployment
Fabrikam plans to implement an internet-accessible application named ClaimsApp that will have the following specification
* ClaimsApp will be deployed to Azure App Service instances that connect to Vnetl and Vnet2.
* Users will connect to ClaimsApp by using a URL of https://claims.fabrikam.com.
* ClaimsApp will access data in ClaimsDB.
* ClaimsDB must be accessible only from Azure virtual networks.
* The app services permission for ClaimsApp must be assigned to ClaimsDB.
Application Development Requirements
Fabrikam identifies the following requirements for application development:
* Azure DevTest labs will be used by developers for testing.
* All the application code must be stored in GitHub Enterprise.
* Azure Pipelines will be used to manage application deployments.
* All application code changes must be scanned for security vulnerabilities, including application code or configuration files that contain secrets in clear text. Scanning must be done at the time the code is pushed to a repository.
Security Requirement
Fabrikam identifies the following security requirements:
* Internet-accessible applications must prevent connections that originate in North Korea.
* Only members of a group named InfraSec must be allowed to configure network security groups (NSGs} and instances of Azure Firewall, VJM. And Front Door in Sub1.
* Administrators must connect to a secure host to perform any remote administration of the virtual machines. The secure host must be provisioned from a custom operating system image.
AWS Requirements
Fabrikam identifies the following security requirements for the data hosted in ContosoAWSV.
* Notify security administrators at Fabrikam if any AWS EC2 instances are noncompliant with secure score recommendations.
* Ensure that the security administrators can query AWS service logs directly from the Azure environment.
Contoso Developer Requirements
Fabrikam identifies the following requirements for the Contoso developers;
* Every month, the membership of the ContosoDevelopers group must be verified.
* The Contoso developers must use their existing contoso.onmicrosoft.com credentials to access the resources in Sub1.
* The Comoro developers must be prevented from viewing the data in a column named MedicalHistory in the ClaimDetails table.
Compliance Requirement
Fabrikam wants to automatically remediate the virtual machines in Sub1 to be compliant with the HIPPA HITRUST standard. The virtual machines in TestRG must be excluded from the compliance assessment.
質問 # 79
あなたの会社では、Azure Active Directory (Azure AD) でカスタム エンタープライズ アプリケーションとしてアクセスされるいくつかのアプリケーションを開発しています。特定の国のリストに含まれるユーザーがアプリケーションに接続できないようにするソリューションを推奨する必要があります。推奨事項には何を含めるべきですか?
- A. Microsoft エンドポイント マネージャーのデバイス コンプライアンス ポリシー
- B. Microsoft Defender for Cloud Apps のアクティビティ ポリシー
- C. Azure AD 条件付きアクセス ポリシー
- D. Azure AD Identity Protection のサインイン リスク ポリシー
- E. Azure AD Identity Protection のユーザー リスク ポリシー
正解:C
解説:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy- location
https://docs.microsoft.com/en-us/power-platform/admin/restrict-access-online-trusted-ip-rules
質問 # 80
ホットスポットに関する質問
ネットワークには、Domain1 という名前の Active Directory ドメイン サービス (AD DS) ドメインが含まれています。
Microsoft Entra テナントがあります。
Domain1 は、Microsoft Entra Connect を使用してテナントと同期します。
次のアカウント ロックアウトの考慮事項をテストして、Microsoft Entra スマート ロックアウトを評価する必要があります。
- ロックアウトを引き起こす失敗したサインイン試行回数
- ロックアウトの期間
それぞれの考慮事項をテストするには何を使用すればよいですか? 回答するには、回答領域で適切なオプションを選択してください。
注意: 正しい選択ごとに 1 ポイントが付与されます。
正解:
解説:
Explanation:
Box 1: AD DS and Microsoft Entra ID
The number of failed sign-in attempts that trigger a lockout.
Smart lockout can be integrated with hybrid deployments that use password hash sync or pass- through authentication to protect on-premises Active Directory Domain Services (AD DS) accounts from being locked out by attackers. By setting smart lockout policies in Microsoft Entra ID appropriately, attacks can be filtered out before they reach on-premises AD DS.
When using pass-through authentication, the following considerations apply:
* The Microsoft Entra lockout threshold must be less than the AD DS account lockout threshold.
Set the values so that the AD DS account lockout threshold is at least two or three times greater than the Microsoft Entra lockout threshold.
* The Microsoft Entra lockout duration must be longer than the AD DS account lockout duration.
The Microsoft Entra duration is set in seconds, while the AD DS duration is set in minutes.
Tip
This configuration ensures Microsoft Entra smart lockout stops your on-premises AD DS accounts from being locked out by brute force attacks, like password spray attacks on your Microsoft Entra accounts.
Box 2: AD DS and Microsoft Entra ID
The duration of the lockout.
Reference:
https://learn.microsoft.com/en-us/entra/identity/authentication/howto-password-smart-lockout
質問 # 81
あなたは、Azure にオンボードされたコンテナー化されたアプリケーションのセキュリティ標準を設計しています。Microsoft Defender for Containers の使用を評価しています。
Defender for Containers を使用して既知の脆弱性をスキャンできるのは、どの 2 つの環境ですか? それぞれの正解は完全な解決策を示します。注: 正しく選択するたびに 1 ポイントの価値があります。
- A. Azure Container Instances にデプロイされた Linux コンテナー
- B. Azure Container Registry にデプロイされた Windows コンテナー
- C. Azure Kubernetes Service (AKS) にデプロイされた Windows コンテナー
- D. Azure Kubernetes Service (AKS) にデプロイされた Linux コンテナー
- E. Azure Container Registry にデプロイされた Linux コンテナー
正解:B、E
解説:
https://docs.microsoft.com/en-us/learn/modules/design-strategy-for-secure-paas-iaas-saas-services/9-specify-security-requirements-for-containers
https://docs.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-introduction#view-vulnerabilities-for-running-images
質問 # 82
オンプレミス ネットワークには、Angular と Nodejs で開発された e コマース Web アプリが含まれています。Web アプリは MongoDB データベースを使用します。Web アプリを Azure に移行する予定です。ソリューション アーキテクチャ チームは、Azure ランディング ゾーンとして次のアーキテクチャを提案します。
Web アプリとデータベース間の接続を保護するための推奨事項を提供する必要があります。ソリューションはゼロトラスト モデルに従う必要があります。
解決策: 資格情報を保存するには、Azure Key Vault を実装することをお勧めします。
- A. いいえ
- B. はい
正解:A
解説:
When using Azure-provided PaaS services (e.g., Azure Storage, Azure Cosmos DB, or Azure Web App, use the PrivateLink connectivity option to ensure all data exchanges are over the private IP space and the traffic never leaves the Microsoft network.
質問 # 83
オンプレミスサーバー Server1 があります。Server1 は、社内のユーザーのみがアクセスできる FTP サーバーです。
Azure サブスクリプションをお持ちです。
ユーザーがインターネットから Server1 にアクセスするときに条件付きアクセス ポリシーを適用するには、ゼロ トラスト ネットワーク アクセス (ZTNA) ソリューションを推奨する必要があります。
推薦書には何を含めるべきでしょうか?
- A. Microsoft Entra プライベート アクセス
- B. Azure アプリケーション ゲートウェイ
- C. Microsoft Entra アプリケーション プロキシ
- D. 蒼き要塞
- E. Microsoft Entra インターネット アクセス
正解:A
解説:
To enforce Conditional Access for an on-premises FTP server accessed from the internet, you should integrate it with Microsoft Entra Private Access, install a Private Network Connector on your network, define the FTP server as an "Enterprise Application," and then create Conditional Access policies that target this application. This setup allows Microsoft Entra ID to enforce multi- factor authentication, device compliance, and other access controls before users can connect to your FTP server, providing a consistent security layer for your on-premises resources.
Reference:
https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/operations/configure-device-based-conditional-access-on-premises
質問 # 84
注: この問題は、同じシナリオを提示する一連の問題の一部です。一連の問題にはそれぞれ、定められた目標を満たす可能性のある独自の解答が含まれています。問題セットによっては、複数の正解が存在する場合もあれば、正解がない場合もあります。
このセクションの質問に回答した後は、その質問に戻ることはできません。そのため、これらの質問はレビュー画面に表示されません。
Azure Front Door インスタンスを通じて Azure App Service Web アプリへのアクセスを提供するためのセキュリティ戦略を設計しています。
Web アプリが Front Door インスタンス経由のアクセスのみを許可するようにするためのソリューションを推奨する必要があります。
解決策: Front Door サービス タグからのトラフィックを許可するアクセス制限を推奨します。
これは目標を満たしていますか?
- A. いいえ
- B. はい
正解:B
解説:
Restrict access to a specific Azure Front Door instance.
Traffic from Azure Front Door to your application originates from a well-known set of IP ranges defined in the AzureFrontDoor.Backend service tag. Using a service tag restriction rule, you can restrict traffic to only originate from Azure Front Door. To ensure traffic only originates from your specific instance, you will need to further filter the incoming requests based on the unique http header that Azure Front Door sends.
Reference:
https://docs.microsoft.com/en-us/azure/app-service/app-service-ip-restrictions#managing-access- restriction-rules
質問 # 85
あなたは、クラウドのみの環境用のセキュリティ アーキテクチャを設計しています。
あなたは、Microsoft サイバーセキュリティ リファレンス アーキテクチャ (MCRA) に基づいて、Microsoft 365 Defender と他の Microsoft クラウド サービスの間の統合ポイントを検討しています。
どの Microsoft クラウド サービスが Microsoft 365 Defender と直接統合され、次の要件を満たすかを推奨する必要があります。
* Microsoft 365 Defender ポータルから直接管理できるデータ損失防止 (DLP) ポリシーを適用します。
* 統合アラートによるユーザーおよびエンティティ行動分析 (UEBA) に基づいてセキュリティ脅威を検出し、対応します。
各要件の推奨事項には何を含める必要がありますか? 回答するには、回答内の適切な選択肢を選択してください。注: 正しく選択するたびに 1 ポイントの価値があります。
正解:
解説:
Explanation:
質問 # 86
ケーススタディ1 - Fabrikam, Inc
概要
Fabrikam, Inc. は、ニューヨークに本社、パリに支店を持つ保険会社です。
既存の環境
オンプレミス環境
オンプレミス ネットワークには、corp.fabrikam.com という名前の単一の Active Directory ドメイン サービス (AD DS) ドメインが含まれています。
Azure環境
Fabrikam には次の Azure リソースがあります。
- corp.fabrikam.com と同期する fabrikam.onmicrosoft.com という名前の Microsoft Entra テナント
- Sub1 という名前の単一の Azure サブスクリプション
- 米国東部 Azure リージョンの Vnet1 という仮想ネットワーク
- 西ヨーロッパの Azure リージョンにある Vnet2 という仮想ネットワーク
- Azure Web アプリケーション ファイアウォール (WAF) が有効になっている FD1 という名前の Azure Front Door インスタンス
- Microsoft Sentinel ワークスペース
- ClaimDetails というテーブルを含む ClaimsDB という Azure SQL データベース
- アプリケーション サーバーとして構成され、Microsoft Defender for Cloud にオンボードされていない仮想マシン 20 台
- テスト目的のみに使用される TestRG という名前のリソース グループ
- 個人に割り当てられたセッションホストを含む Azure Virtual Desktop ホストプール
- Sub1 のすべてのリソースは、米国東部または西ヨーロッパのいずれかのリージョンにあります。
パートナー
Fabrikamは、アプリケーション開発をContoso, Ltd.という会社と契約しています。Contosoは以下のインフラストラクチャを保有しています。
- contoso.onmicrosoft.com という名前の Microsoft Entra
- ContosoAWS1 という名前の Amazon Web Services (AWS) 実装。これには、Contoso の Fabrikam 開発者のアプリケーションのテスト ワークロードをホストするために使用される AWS EC2 インスタンスが含まれており、アプリケーションをテストまたは更新するために Fabrikam のリソースに接続します。
開発者は、fabrikam.onmicrosoft.com 内の Contoso Developers というセキュリティ グループに追加され、Sub1 のロールに割り当てられます。ContosoDevelopers グループには、ClaimsDB データベースの db.owner ロールが割り当てられます。
コンプライアンスイベント
Fabrikam は次のコンプライアンス環境を展開しています。
- Defender for Cloud は、Sub1 内のすべてのリソースが HIPAA HITRUST 標準に準拠しているかどうかを評価するように構成されています。
- 現在、HIPAA HITRUST 標準に準拠していないリソースは手動で修復されます。
- Qualys は、サーバーの標準的な脆弱性評価ツールとして使用されます。
問題ステートメント
Defender for Cloud のセキュリティスコアは、すべての仮想マシンが以下の推奨事項を生成していることを示しています。マシンには脆弱性評価ソリューションが必要です。すべての仮想マシンは Defender for Cloud に準拠している必要があります。
ClaimAppの展開
Fabrikamは、ClaimsAppというインターネットアクセス可能なアプリケーションを実装する予定です。その仕様は次のとおりです。
- ClaimsApp は、Vnet1 および Vnet2 に接続する Azure App Service インスタンスにデプロイされます。
- ユーザーは、https://claims.fabrikam.com の URL を使用して ClaimsApp に接続します。
- ClaimsApp は ClaimsDB 内のデータにアクセスします。
- ClaimsDB は、Azure 仮想ネットワークからのみアクセスできる必要があります。
- ClaimsApp のアプリ サービス権限を ClaimsDB に割り当てる必要があります。
アプリケーション開発要件
Fabrikam は、アプリケーション開発に次のような要件があると考えています。
- Azure DevTest ラボは開発者がテストに使用します。
- すべてのアプリケーション コードは GitHub Enterprise に保存する必要があります。
- アプリケーションのデプロイを管理するために Azure Pipelines が使用されます。
- すべてのアプリケーションコードの変更は、セキュリティ脆弱性がないかスキャンする必要があります。これには、平文で機密情報を含むアプリケーションコードや設定ファイルも含まれます。スキャンは、コードをリポジトリにプッシュする時点で実施する必要があります。
セキュリティ要件
Fabrikam では、次のセキュリティ要件を特定しています。
- インターネットにアクセス可能なアプリケーションは、北朝鮮からの接続を防ぐ必要があります。
- InfraSec というグループのメンバーのみが、ネットワーク セキュリティ グループ (NSG) と、Sub1 の Azure Firewall、VJM、および Front Door のインスタンスを構成できるようにする必要があります。
- 管理者は、仮想マシンのリモート管理を実行するために、セキュアホストに接続する必要があります。セキュアホストは、カスタムオペレーティングシステムイメージからプロビジョニングする必要があります。
AWS 要件
Fabrikam は、ContosoAWSV でホストされるデータに対して次のセキュリティ要件を特定しています。
- AWS EC2 インスタンスがセキュア スコアの推奨事項に準拠していない場合は、Fabrikam のセキュリティ管理者に通知します。
- セキュリティ管理者が Azure 環境から AWS サービス ログを直接クエリできることを確認します。
Contoso 開発者の要件
Fabrikam は、Contoso 開発者に対して次の要件を特定しています。
- 毎月、ContosoDevelopers グループのメンバーシップを検証する必要があります。
- Contoso の開発者は、Sub1 のリソースにアクセスするために、既存の contoso.onmicrosoft.com 資格情報を使用する必要があります。
- Comoro の開発者が ClaimDetails テーブルの MedicalHistory という列のデータを表示できないようにする必要があります。
コンプライアンス要件
Fabrikam は、Sub1 の仮想マシンを HIPPA HITRUST 標準に準拠させるため、自動的に修復したいと考えています。TestRG の仮想マシンはコンプライアンス評価から除外する必要があります。
仮想マシンの問題を解決するためのソリューションを推奨する必要があります。
推薦書には何を含めるべきでしょうか?
- A. Microsoft Endpoint Manager でデバイス コンプライアンス ポリシーを作成します。
- B. 仮想マシンを Azure Arc にオンボードします。
- C. Defender for Cloud で Qualys スキャナーを有効にします。
- D. 仮想マシンを Microsoft Defender for Endpoint にオンボードします。
正解:D
解説:
Scenario: 20 virtual machines that are configured as application servers and are NOT onboarded to Microsoft Defender for Cloud.
Existing Environment. Problem Statements
The secure score in Defender for Cloud shows that all the virtual machines generate the following recommendation: Machines should have a vulnerability assessment solution.
All the virtual machines must be compliant in Defender for Cloud.
Note: Deploying Microsoft Defender for Endpoint is a two-step process.
Onboard devices to the service -
Configure capabilities of the service
Reference:
https://docs.microsoft.com/en-us/azure/defender-for-cloud/deploy-vulnerability-assessment-vm
質問 # 87
あなたの会社は Microsoft 365 E5 ライセンスと Azure サブスクリプションを持っています。
同社は、次の場所に保存されている機密データに自動的にラベルを付けることを計画しています。
* Microsoft SharePoint Online
* Microsoft Exchange Online
*マイクロソフトチーム
機密データを特定して保護するための戦略を推奨する必要があります。
機密ラベル ポリシーにはどの範囲を推奨する必要がありますか? 答えるには、適切なスコープを正しい場所にドラッグします。各スコープは 1 回使用することも、複数回使用することも、まったく使用しないこともできます。コンテンツを表示するには、ペイン間で分割バーをドラッグするか、スクロールする必要がある場合があります。
注: 正しく選択するたびに 1 ポイントの価値があります。
正解:
解説:
質問 # 88
顧客情報を含む DB1 という名前の Azure SQL データベースがあります。
データベース管理者のチームは DB1 への完全なアクセス権を持っています。
顧客からの問い合わせに対応するために、顧客サービス部門のオペレーターは App1 という名前のカスタム Web アプリを使用して顧客情報を表示します。
D81 のセキュリティ戦略を設計する必要があります。ソリューションは次の要件を満たす必要があります。
* データベース管理者が SQL 管理ツールを使用して DB1 にアクセスする場合、各顧客レコードのクレジット カード属性の内容を表示できないようにする必要があります。
* オペレーターが App1 で顧客レコードを表示する場合、クレジット カード属性の最後の 4 桁のみを表示する必要があります。
デザインには何を含めるべきですか? 回答するには、回答内の適切な選択肢を選択してください。注: 正しく選択するたびに 1 ポイントの価値があります。
正解:
解説:
Explanation:
質問 # 89
あなたの会社にはハイブリッド クラウド インフラストラクチャがあります。
データとアプリケーションはクラウド環境間で定期的に移動されます。
同社のオンプレミス ネットワークは、次の図に示すように管理されています。
あなたは、ハイブリッド クラウド インフラストラクチャをサポートするセキュリティ運用を設計しています。ソリューションは次の要件を満たす必要があります。
複数の環境にわたる仮想マシンとサーバーを管理します。
Azure ポリシー全体で、すべての環境のすべてのリソースに標準を適用します。
オンプレミス ネットワークに推奨する 2 つのコンポーネントはどれですか? それぞれの正解は、解決策の一部を示しています。
注意 正しい選択はそれぞれ 1 ポイントの価値があります。
- A. Azure VPN ゲートウェイ
- B. オンプレミス データ ゲートウェイ
- C. Azure Policy のゲスト構成
- D. アズールバスティオン
- E. アズールアーク
正解:C、E
解説:
https://docs.microsoft.com/en-us/azure/governance/machine-configuration/overview
質問 # 90
セキュリティ アクセス戦略のセキュリティ レベルを計画しています。
どのジョブの役割をどのセキュリティ レベルで構成するかを特定する必要があります。ソリューションは、Microsoft サイバーセキュリティ リファレンス アーキテクチャ (MCRA) のセキュリティのベスト プラクティスを満たしている必要があります。
各職務にどのセキュリティ レベルを設定する必要がありますか? 回答するには、回答領域で適切なオプションを選択してください。
注: 正しく選択するたびに 1 ポイントの価値があります。
正解:
解説:
Explanation:
質問 # 91
ケーススタディ1 - Fabrikam, Inc
概要
Fabrikam, Inc. は、ニューヨークに本社、パリに支店を持つ保険会社です。
既存の環境
オンプレミス環境
オンプレミス ネットワークには、corp.fabrikam.com という名前の単一の Active Directory ドメイン サービス (AD DS) ドメインが含まれています。
Azure環境
Fabrikam には次の Azure リソースがあります。
- corp.fabrikam.com と同期する fabrikam.onmicrosoft.com という名前の Microsoft Entra テナント
- Sub1 という名前の単一の Azure サブスクリプション
- 米国東部 Azure リージョンの Vnet1 という仮想ネットワーク
- 西ヨーロッパの Azure リージョンにある Vnet2 という仮想ネットワーク
- Azure Web アプリケーション ファイアウォール (WAF) が有効になっている FD1 という名前の Azure Front Door インスタンス
- Microsoft Sentinel ワークスペース
- ClaimDetails というテーブルを含む ClaimsDB という Azure SQL データベース
- アプリケーション サーバーとして構成され、Microsoft Defender for Cloud にオンボードされていない仮想マシン 20 台
- テスト目的のみに使用される TestRG という名前のリソース グループ
- 個人に割り当てられたセッションホストを含む Azure Virtual Desktop ホストプール
- Sub1 のすべてのリソースは、米国東部または西ヨーロッパのいずれかのリージョンにあります。
パートナー
Fabrikamは、アプリケーション開発をContoso, Ltd.という会社と契約しています。Contosoは以下のインフラストラクチャを保有しています。
- contoso.onmicrosoft.com という名前の Microsoft Entra
- ContosoAWS1 という名前の Amazon Web Services (AWS) 実装。これには、Contoso の Fabrikam 開発者のアプリケーションのテスト ワークロードをホストするために使用される AWS EC2 インスタンスが含まれており、アプリケーションをテストまたは更新するために Fabrikam のリソースに接続します。
開発者は、fabrikam.onmicrosoft.com 内の Contoso Developers というセキュリティ グループに追加され、Sub1 のロールに割り当てられます。ContosoDevelopers グループには、ClaimsDB データベースの db.owner ロールが割り当てられます。
コンプライアンスイベント
Fabrikam は次のコンプライアンス環境を展開しています。
- Defender for Cloud は、Sub1 内のすべてのリソースが HIPAA HITRUST 標準に準拠しているかどうかを評価するように構成されています。
- 現在、HIPAA HITRUST 標準に準拠していないリソースは手動で修復されます。
- Qualys は、サーバーの標準的な脆弱性評価ツールとして使用されます。
問題ステートメント
Defender for Cloud のセキュリティスコアは、すべての仮想マシンが以下の推奨事項を生成していることを示しています。マシンには脆弱性評価ソリューションが必要です。すべての仮想マシンは Defender for Cloud に準拠している必要があります。
ClaimAppの展開
Fabrikamは、ClaimsAppというインターネットアクセス可能なアプリケーションを実装する予定です。その仕様は次のとおりです。
- ClaimsApp は、Vnet1 および Vnet2 に接続する Azure App Service インスタンスにデプロイされます。
- ユーザーは、https://claims.fabrikam.com の URL を使用して ClaimsApp に接続します。
- ClaimsApp は ClaimsDB 内のデータにアクセスします。
- ClaimsDB は、Azure 仮想ネットワークからのみアクセスできる必要があります。
- ClaimsApp のアプリ サービス権限を ClaimsDB に割り当てる必要があります。
アプリケーション開発要件
Fabrikam は、アプリケーション開発に次のような要件があると考えています。
- Azure DevTest ラボは開発者がテストに使用します。
- すべてのアプリケーション コードは GitHub Enterprise に保存する必要があります。
- アプリケーションのデプロイを管理するために Azure Pipelines が使用されます。
- すべてのアプリケーションコードの変更は、セキュリティ脆弱性がないかスキャンする必要があります。これには、平文で機密情報を含むアプリケーションコードや設定ファイルも含まれます。スキャンは、コードをリポジトリにプッシュする時点で実施する必要があります。
セキュリティ要件
Fabrikam では、次のセキュリティ要件を特定しています。
- インターネットにアクセス可能なアプリケーションは、北朝鮮からの接続を防ぐ必要があります。
- InfraSec というグループのメンバーのみが、ネットワーク セキュリティ グループ (NSG) と、Sub1 の Azure Firewall、VJM、および Front Door のインスタンスを構成できるようにする必要があります。
- 管理者は、仮想マシンのリモート管理を実行するために、セキュアホストに接続する必要があります。セキュアホストは、カスタムオペレーティングシステムイメージからプロビジョニングする必要があります。
AWS 要件
Fabrikam は、ContosoAWSV でホストされるデータに対して次のセキュリティ要件を特定しています。
- AWS EC2 インスタンスがセキュア スコアの推奨事項に準拠していない場合は、Fabrikam のセキュリティ管理者に通知します。
- セキュリティ管理者が Azure 環境から AWS サービス ログを直接クエリできることを確認します。
Contoso 開発者の要件
Fabrikam は、Contoso 開発者に対して次の要件を特定しています。
- 毎月、ContosoDevelopers グループのメンバーシップを検証する必要があります。
- Contoso の開発者は、Sub1 のリソースにアクセスするために、既存の contoso.onmicrosoft.com 資格情報を使用する必要があります。
- Comoro の開発者が ClaimDetails テーブルの MedicalHistory という列のデータを表示できないようにする必要があります。
コンプライアンス要件
Fabrikam は、Sub1 の仮想マシンを HIPPA HITRUST 標準に準拠させるため、自動的に修復したいと考えています。TestRG の仮想マシンはコンプライアンス評価から除外する必要があります。
ホットスポットに関する質問
AWS 要件を満たすソリューションを推奨する必要があります。
推奨事項には何を含めるべきですか? 回答するには、回答エリアで適切なオプションを選択してください。
注意: 正しい選択ごとに 1 ポイントが付与されます。
正解:
解説:
Explanation:
Box 1: Defender for Cloud
The requirement is to identify EC2 instances which are noncompliant with secure score recommendations.
Box 2: Microsoft Sentinel
Use the Amazon Web Services (AWS) connectors to pull AWS service logs into Microsoft Sentinel. These connectors work by granting Microsoft Sentinel access to your AWS resource logs. Setting up the connector establishes a trust relationship between Amazon Web Services and Microsoft Sentinel. This is accomplished on AWS by creating a role that gives permission to Microsoft Sentinel to access your AWS logs.
Reference:
https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-aws?pivots=env-settings
https://docs.microsoft.com/en-us/azure/sentinel/connect-aws?tabs=s3
質問 # 92
Azure Pipelines と Azure Repos を使用して、継続的インテグレーションと継続的デプロイ (CI/CO) ワークフローを実装します。
Microsoft Cloud Adoption Framework for Azure に基づいて、CI/CD ワークフローの段階を保護するためのベスト プラクティスを推奨する必要があります。
各段階の推奨事項には何を含めるべきですか? 回答するには、回答領域で適切なオプションを選択してください。
注: 正しく選択するたびに 1 ポイントの価値があります。
正解:
解説:
Explanation:
質問 # 93
あなたの会社では、いくつかの Azure App Service Web アプリを展開する予定です。Web アプリは西ヨーロッパの Azure リージョンにデプロイされます。Web アプリには、ヨーロッパと米国の顧客のみがアクセスできます。
悪意のあるボットが Web アプリの脆弱性をスキャンするのを防ぐソリューションを推奨する必要があります。ソリューションでは、取り付け面を最小限に抑える必要があります。
推奨事項には何を含めるべきですか?
- A. Azure Traffic Manager and application security groups
- B. Azure Application Gateway Web Application Firewall (WAF)
- C. Azure Firewall Premium
- D. network security groups (NSGs)
正解:A
解説:
https://docs.microsoft.com/en-us/azure/web-application-firewall/ag/bot-protection
質問 # 94
......
最新の検証済みSC-100日本語問題と解答合格保証:https://www.jpntest.com/shiken/SC-100J-mondaishu