
Explanation/Reference:
References:
http://www.rebeladmin.com/2018/09/step-step-guide-configure-risk-based-azure-conditional-access-policies/
https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-policies
https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks Implement platform protection Testlet 1 This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other question on this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next sections of the exam. After you begin a new section, you cannot return to this section.
To start the case study
To display the first question on this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview
Litware, Inc. is a digital media company that has 500 employees in the Chicago area and 20 employees in the San Francisco area.
Existing Environment
Litware has an Azure subscription named Sub1 that has a subscription ID of 43894a43-17c2-4a39-8cfc-
3540c2653ef4.
Sub1 is associated to an Azure Active Directory (Azure AD) tenant named litwareinc.com. The tenant contains the user objects and the device objects of all the Litware employees and their devices. Each user is assigned an Azure AD Premium P2 license. Azure AD Privileged Identity Management (PIM) is activated.
The tenant contains the groups shown in the following table.

The Azure subscription contains the objects shown in the following table.

Identity and Access Requirements
Azure Security Center is set to the Standard tier.
Requirements
計画された変更
Litware は、次の表に示す Azure リソースを展開する予定です。

Litware では、次の ID およびアクセス要件が特定されています。
* すべてのサンフランシスコ ユーザーとそのデバイスは、Group1 のメンバーである必要があります。
* グループ 2 のメンバーには、永続的な適格割り当てを使用して、リソース グループ 2 への共同作成者ロールを割り当てる必要があります。
* ユーザーが Azure AD にアプリケーションを登録したり、ユーザーに代わって会社の情報にアクセスするアプリケーションに同意したりできないようにする必要があります。
プラットフォーム保護要件
Litware では、次のプラットフォーム保護要件が特定されています。
* リソース グループ 1 の仮想マシンに Microsoft Antimalware をインストールする必要があります。
* Group2 のメンバーには、Azure Kubernetes Service クラスター管理者ロールを割り当てる必要があります。
* Azure AD ユーザーは、Azure AD 資格情報を使用して AKS1 に対して認証する必要があります。
* 計画された変更の実装後、IT チームは JIT VM アクセスを使用して VM0 に接続できる必要があります。
* リソースグループ1内のマネージドディスクの管理を委任するには、「Role1」という新しいカスタムRBACロールを使用する必要があります。Role1はリソースグループ1でのみ使用可能である必要があります。
セキュリティ運用要件
Litware は、Azure Security Center でオペレーティング システムのセキュリティ構成をカスタマイズできる必要があります。
データとアプリケーションの要件
Litware では、次のデータとアプリケーションの要件が特定されています。
* Group2 のユーザーは、Azure AD 資格情報を使用して SQLDB1 に対して認証できる必要があります。
* WebApp1 は相互認証を強制する必要があります。
一般的な要件
Litware では、次の一般的な要件が特定されています。
* 可能な限り、管理上の労力は最小限に抑える必要があります。
* 可能な限り、自動化を最大限に活用する必要があります。