exam questions

Exam SC-100 All Questions

View all questions & answers for the SC-100 exam

Exam SC-100 topic 3 question 4 discussion

Actual exam question from Microsoft's SC-100
Question #: 4
Topic #: 3
[All SC-100 Questions]

HOTSPOT -
You are designing security for a runbook in an Azure Automation account. The runbook will copy data to Azure Data Lake Storage Gen2.
You need to recommend a solution to secure the components of the copy process.
What should you include in the recommendation for each component? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Alex_Burlachenko
Highly Voted 2 years, 9 months ago
wrong one, I would select - Key Vault for box1 and for box 2 is Private Link
upvoted 109 times
prabhjot
2 years, 9 months ago
Ans is wrong - Azure key vault is for Application ad Data Security so key vault - Box1 and Private link is for Vnet security so Box2 =Private link
upvoted 18 times
Ramye
1 year, 4 months ago
Yes, Private Link is for VNet security, but there's no reference to VNet here. What am I missing? thx
upvoted 1 times
...
...
...
HardcodedCloud
Highly Voted 2 years, 9 months ago
Data Security : Access Keys stored in Azure Key Vault Network access control : Azure Private Link with network service tags
upvoted 49 times
...
6c0ca3d
Most Recent 1 month, 1 week ago
access keys stored.. azure private link appear to be the correct response
upvoted 1 times
...
orrery
11 months ago
Data security: Access keys stored in Azure Key Vault: This ensures that sensitive keys are securely stored and managed, reducing the risk of unauthorized access. Network access control: Azure Private Link with network service tags: This provides secure and private connectivity to Azure services, ensuring that data transfer occurs over a private network rather than the public internet.
upvoted 1 times
...
Arockia
1 year, 5 months ago
• Data safety: Lock keys in Key Vault, network isolation with Private Link & service tags for secured Azure Data Lake Gen2 copy via Automation runbook. • Network control: Private Link & service tags shield your Azure Data Lake Gen2 copy process from the public internet for enhanced security.
upvoted 2 times
...
Murtuza
1 year, 5 months ago
App GW with WAF cant play a role because it applies to client facing which is not the ASK in the question.
upvoted 2 times
...
JG56
1 year, 6 months ago
in exam Nov 23, Agree with Alex
upvoted 4 times
...
smanzana
1 year, 7 months ago
Box1:Key Vault Box2:Private Link
upvoted 3 times
...
ian2387
1 year, 7 months ago
Have we managed to figure out the correct answer? Data: Azure key vault Network: Private link with service tags. I have my doubts if service tags are supported by azure private links.
upvoted 2 times
...
rahulnair
1 year, 8 months ago
A & C - Secure the assets in Azure Automation including credentials, certificates, connections and encrypted variables. These assets are protected in Azure Automation using multiple levels of encryption. By default, data is encrypted with Microsoft-managed keys. For additional control over encryption keys, you can supply customer-managed keys to use for encryption of Automation assets. These keys must be present in Azure Key Vault for Automation service to be able to access the keys. Use Azure Private Link to securely connect Hybrid runbook workers to Azure Automation. Azure Private Endpoint is a network interface that connects you privately and securely to a an Azure Automation service powered by Azure Private Link. Private Endpoint uses a private IP address from your Virtual Network (VNet), to effectively bring the Automation service into your VNet. https://learn.microsoft.com/en-us/azure/automation/automation-security-guidelines
upvoted 2 times
...
ConanBarb
1 year, 8 months ago
Hey all, Lets exclude the nonsensical options first: Automation Contributor role is the RBAC role for working with the Automation service, "design-time" if you will, and hence has nothing to do with securing data run-time. Private link with network service tags is nonse for N/W security. There is no such thing. Network service tags is used in NSGs and firewall rules. Hence, even though these options seem strange as well but in theory relevant: Data Security: Key vault N/W Security: App GW with WAF
upvoted 3 times
...
uffman
2 years, 1 month ago
Box1: Key Vault Box2: Private Link
upvoted 1 times
...
KrisDeb
2 years, 4 months ago
Azure Automation Run As Account will retire on September 30, 2023 and will be replaced with Managed Identities. Before that date, you'll need to start migrating your runbooks to use managed identities. For more information, see migrating from an existing Run As accounts to managed identity to start migrating the runbooks from Run As account to managed identities before 30 September 2023.
upvoted 3 times
Toschu
2 years, 2 months ago
Note: This has nothing to do with the question
upvoted 4 times
...
...
janesb
2 years, 5 months ago
Data Security : Access Keys stored in Azure Key Vault Network access control : Azure Private Link with network service tags https://learn.microsoft.com/en-us/azure/automation/automation-security-guidelines
upvoted 6 times
...
Azzzurrre
2 years, 5 months ago
None of the answers provided is a good answer. They are fragmentary or just wrong. Key Vault with access keys is a bad answer because using shared access keys is only recommended if a service accessing the storage cannot use a managed identity or a certificate to authenticate. "Azure Private Link with network service tags" doesn't mean anything. Network Service Tags can be used in NSG rules, and in routing rules, if either were specified, but they aren't.
upvoted 6 times
EM1234
2 years, 1 month ago
these are both good points. I was also confused how everyone keeps saying to use private link with service tags. Service tags are not used with private links / endpoints. I would still go with A for data security since key vault can be very explicitly secured but the point you made is great. For the second question, I would go with the app gateway with WAF since it is at least controlling network access. Honestly though, I think something has been written wrong here. The answers dont make sense.
upvoted 1 times
...
...
TJ001
2 years, 5 months ago
Data Security : Access Keys stored in Azure Key Vault Network access control : Azure Private Link with network service tags
upvoted 3 times
...
cychoia
2 years, 7 months ago
https://learn.microsoft.com/en-us/azure/automation/automation-security-guidelines
upvoted 6 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...