QuestionQ5

Manage and monitor security posture

HOTSPOT -

Overview -

Contoso, Ltd. is a consulting company with a main office in San Francisco and a branch office in Dallas. Contoso has a hybrid environment that includes on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1.

Existing Environment. Microsoft Entra tenant

Contoso has a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.

Question Image

Existing Environment. On-premises environment

The on-premises network contains an Active Directory Domain Services (AD DS) forest that syncs with contoso.com. The forest includes a server named Server1 that runs Windows Server.

Existing Environment. Azure subscription

Sub1 contains the storage accounts shown in the following table.

Question Image

Sub1 contains the virtual networks shown in the following table.

Question Image

Sub1 contains the virtual machines shown in the following table.

Question Image

The network interface of VM1 is associated with an application security group named ASG1.

Sub1 contains the resources shown in the following table.

Question Image

Vault1 stores the objects shown in the following table.

Question Image

Existing Environment. Privileged Identity Management (PIM) configuration

You manage privileged roles by using Privileged Identity Management (PIM). The PIM role settings are configured as shown in the following table.

Question Image

Existing Environment. Microsoft Sentinel configuration

Contoso has a Microsoft Sentinel workspace that contains the following tables.

Question Image

Requirements. Planned changes -

Contoso plans to implement the following changes:

  • Integrate AKS1 with Vault1.
  • Enable Microsoft Entra Kerberos authentication for all supported storage.
  • Configure auditing for sql1 by using the Azure portal and store audit logs in a centralized location.

Requirements. Technical requirements

Contoso identifies the following technical requirements:

  • Protect Server1 by using file integrity monitoring.
  • Protect AKS1 by using Microsoft Defender for Cloud.
  • Configure Microsoft Sentinel to retain data for the maximum supported duration without changing the tier.
  • Store objects used for authentication and encryption in Vault1 and ensure that Vault1 regenerates the objects every 30 days, whenever possible.

You need to configure Server1 to meet the technical requirements. What should you do?

Community Discussion

No comments yet. Be the first to start the discussion!