(2021) AZ-104 Dumps and Practice Test (465 Questions) [Q117-Q133]

Share

(2021) AZ-104 Dumps and Practice Test (465 Questions)

Guide (New 2021) Actual Microsoft AZ-104 Exam Questions


Format of Microsoft AZ-104 Test

The applicants should take their time and go through the certification webpage to read the exam policies and all that is required of the potential test-takers. This includes the number of questions, which may be from 40 to 60, with the allocated time that is 180 minutes. All the questions may be based on multiple-choice, active screen, case studies, and lab format if to name just a few. The passing score for AZ-104 exam is 700 points and luckily, there is no negative marking for the wrong answers. You also need to know that AZ-104 exam costs $165 and is available in Simplified Chinese, English, Japanese, and Korean.

 

NEW QUESTION 117
You have the Azure virtual machines shown in the following table.

You have a Recovery Services vault that protects VM1 and VM2.
You need to protect VM3 and VM4 by using Recovery Services.
What should you do first?

  • A. Create a storage account.
  • B. Create a new Recovery Services vault.
  • C. Create a new backup policy.
  • D. Configure the extensions for VM3 and VM4.

Answer: B

Explanation:
Explanation
A Recovery Services vault is a storage entity in Azure that houses data. The data is typically copies of data, or configuration information for virtual machines (VMs), workloads, servers, or workstations. You can use Recovery Services vaults to hold backup data for various Azure services References: https://docs.microsoft.com/en-us/azure/site-recovery/azure-to-azure-tutorial-enable-replication

 

NEW QUESTION 118
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You manage a virtual network named VNet1 that is hosted in the West US Azure region.
VNet1 hosts two virtual machines named VM1 and VM2 that run Windows Server.
You need to inspect all the network traffic from VM1 to VM2 for a period of three hours.
Solution: From Azure Network Watcher, you create a connection monitor.
Does this meet the goal?

  • A. No
  • B. Yes

Answer: A

Explanation:
https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-packet-capture- manage-portal

 

NEW QUESTION 119
You need to meet the connection requirements for the New York office.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

Box 1: Create a virtual network gateway and a local network gateway.
Azure VPN gateway. The VPN gateway service enables you to connect the VNet to the on-premises network through a VPN appliance. For more information, see Connect an on-premises network to a Microsoft Azure virtual network. The VPN gateway includes the following elements:
* Virtual network gateway. A resource that provides a virtual VPN appliance for the VNet. It is responsible for routing traffic from the on-premises network to the VNet.
* Local network gateway. An abstraction of the on-premises VPN appliance. Network traffic from the cloud application to the on-premises network is routed through this gateway.
* Connection. The connection has properties that specify the connection type (IPSec) and the key shared with the on-premises VPN appliance to encrypt traffic.
* Gateway subnet. The virtual network gateway is held in its own subnet, which is subject to various requirements, described in the Recommendations section below.
Box 2: Configure a site-to-site VPN connection
On premises create a site-to-site connection for the virtual network gateway and the local network gateway.

Scenario: Connect the New York office to VNet1 over the Internet by using an encrypted connection.

 

NEW QUESTION 120
You have a hybrid deployment of Azure Active Directory (Azure AD) that contains the users shown in the following table.

You need to modify the JobTitle and UsageLocation attributes for the users.
For which users can you modify the- attributes from Azure AD? To answer, select the appropriate options in the answer area.

Answer:

Explanation:

Explanation:
Box 1: User1 and User3 only
You must use Windows Server Active Directory to update the identity, contact info, or job info for users whose source of authority is Windows Server Active Directory.
Box 2: User1, User2, and User3
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-users-profile-azure-portal

 

NEW QUESTION 121
You have an Azure subscription named Subscription1.
You create an Azure Storage account named contosostorage, and then you create a file share named data.
Which UNC path should you include in a script that references files from the data file share? To answer, drag the appropriate values to the correct targets. Each value may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: contosostorage
The name of account
Box 2: file.core.windows.net
Box 3: data
The name of the file share is data.
Example:

References: https://docs.microsoft.com/en-us/azure/storage/files/storage-how-to-use-files-windows

 

NEW QUESTION 122
You have an Azure subscription that contains the resources shown in the following table.

VM1 connects to VNET1.
You need to connect VM1 to VNET2.
Solution: You create a new network interface, and then you add the network interface to VM1.
Does this meet the goal?

  • A. No
  • B. Yes

Answer: A

Explanation:
Explanation
Instead you should delete VM1. You recreate VM1, and then you add the network interface for VM1.
Note: When you create an Azure virtual machine (VM), you must create a virtual network (VNet) or use an existing VNet. You can change the subnet a VM is connected to after it's created, but you cannot change the VNet.
References:
https://docs.microsoft.com/en-us/azure/virtual-machines/windows/network-overview

 

NEW QUESTION 123
You have several Azure virtual machines on a virtual network named VNet1.
You configure an Azure Storage account as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

Box 1: always
Endpoint status is enabled.
Box 2: Never
After you configure firewall and virtual network settings for your storage account, select Allow trusted Microsoft services to access this storage account as an exception to enable Azure Backup service to access the network restricted storage account.

Reference:
https://docs.microsoft.com/en-us/azure/storage/files/storage-how-to-use-files-windows
https://azure.microsoft.com/en-us/blog/azure-backup-now-supports-storage-accounts-secured-with-azure-storage

 

NEW QUESTION 124
You have an Azure subscription that contains the virtual machines shown in the following table.
VM1 and VM2 use public IP addresses. From Windows Server 2019 on VM1 and VM2, you allow inbound Remote Desktop connections.
Subnet1 and Subnet2 are in a virtual network named VNET1.
The subscription contains two network security groups (NSGs) named NSG1 and NSG2. NSG1 uses only the default rules.
NSG2 uses the default and the following custom incoming rule:
* Priority: 100
* Name: Rule1
* Port: 3389
* Protocol: TCP
* Source: Any
* Destination: Any
* Action: Allow
NSG1 connects to Subnet1. NSG2 connects to the network interface of VM2.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Answer:

Explanation:

Explanation
Box 1: No
The default port for RDP is TCP port 3389. A rule to permit RDP traffic must be created automatically when you create your VM.
Box 2: Yes
NSG2 will allow this.
Box 3: Yes
NSG2 will allow this.
Note on NSG-Subnet1: Azure routes network traffic between all subnets in a virtual network, by default.
References:
https://docs.microsoft.com/en-us/azure/virtual-machines/troubleshooting/troubleshoot-rdp-connection

 

NEW QUESTION 125
You have an Azure Active Directory tenant named Contoso.com that includes following users:

Contoso.com includes following Windows 10 devices:

You create following security groups in Contoso.com:

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Yes
User1 is a Cloud Device Administrator.
Device2 is Azure AD joined.
Group1 has the assigned to join type. User1 is the owner of Group1.
Note: Assigned groups - Manually add users or devices into a static group.
Azure AD joined or hybrid Azure AD joined devices utilize an organizational account in Azure AD Box 2: No User2 is a User Administrator.
Device1 is Azure AD registered.
Group1 has the assigned join type, and the owner is User1.
Note: Azure AD registered devices utilize an account managed by the end user, this account is either a Microsoft account or another locally managed credential.
Box 3: Yes
User2 is a User Administrator.
Device2 is Azure AD joined.
Group2 has the Dynamic Device join type, and the owner is User2.
References:
https://docs.microsoft.com/en-us/azure/active-directory/devices/overview

 

NEW QUESTION 126
You have an app named App1 that runs on an Azure web app named webapp1.
The developers at your company upload an update of App1 to a Git repository named GUI.
Webapp1 has the deployment slots shown in the following table.
You need to ensure that the App1 update is tested before the update is made available to users. Which two actions should you perform? Each correct answer presents part of the solution.
NOTE Each correct selection is worth one point.

  • A. Stop webapp1 prod.
  • B. Stop webapp1-test
  • C. Swap the slots.
  • D. Deploy the App1 update to webapp1-test, and then test the update.
  • E. Deploy the App1 update to webapp1-prod, and then test the update.

Answer: C,D

Explanation:
Explanation
You can validate web app changes in a staging deployment slot before swapping it with the production slot.
Deploying an app to a slot first and swapping it into production makes sure that all instances of the slot are warmed up before being swapped into production. This eliminates downtime when you deploy your app. The traffic redirection is seamless, and no requests are dropped because of swap operations. You can automate this entire workflow by configuring auto swap when pre-swap validation isn't needed.
After the swap you can deploy the App1 update to webapp1-test, and then test the update. If the changes swapped into the production slot aren't as per your expectation then you can perform the same swap immediately to get your "last known good site" back.
Reference:
https://docs.microsoft.com/en-us/azure/app-service/deploy-staging-slots

 

NEW QUESTION 127
You have an Azure subscription that contains a virtual network named VNET1 in the East US 2 region. You have the following resources in an Azure Resource Manager template.




For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Answer:

Explanation:
Explanation

Box 1: Yes
Box 2: Yes
VM1 is in Zone1, while VM2 is on Zone2.
Box 3: No
Reference:
https://docs.microsoft.com/en-us/azure/architecture/resiliency/recovery-loss-azure-region

 

NEW QUESTION 128
You have an Azure App Service plan named AdatumASP1 that uses the P2v2 pricing tier.
AdatunASP1 hosts an Azure web app named adatumwebapp1.
You need to delegate the management of adatumwebapp1 to a group named Devs.
Devs must be able to perform the following tasks:
- Add deployment slots.
- View the configuration of AdatunASP1.
- Modify the role assignment for adatumwebapp1.
Which role should you assign to the Devs group?

  • A. Owner
  • B. Website Contributor
  • C. Contributor
  • D. Web Plan Contributor

Answer: A

Explanation:
https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles

 

NEW QUESTION 129
You need to meet the connection requirements for the New York office.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Create a virtual network gateway and a local network gateway.
Azure VPN gateway. The VPN gateway service enables you to connect the VNet to the on-premises network through a VPN appliance. For more information, see Connect an on-premises network to a Microsoft Azure virtual network. The VPN gateway includes the following elements:
* Virtual network gateway. A resource that provides a virtual VPN appliance for the VNet. It is responsible for routing traffic from the on-premises network to the VNet.
* Local network gateway. An abstraction of the on-premises VPN appliance. Network traffic from the cloud application to the on-premises network is routed through this gateway.
* Connection. The connection has properties that specify the connection type (IPSec) and the key shared with the on-premises VPN appliance to encrypt traffic.
* Gateway subnet. The virtual network gateway is held in its own subnet, which is subject to various requirements, described in the Recommendations section below.
Box 2: Configure a site-to-site VPN connection
On premises create a site-to-site connection for the virtual network gateway and the local network gateway.

Scenario: Connect the New York office to VNet1 over the Internet by using an encrypted connection.
Incorrect Answers:
Azure ExpressRoute: Established between your network and Azure, through an ExpressRoute partner. This connection is private. Traffic does not go over the internet.
References:
https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/hybrid-networking/vpn

 

NEW QUESTION 130
You have an Azure subscription that is used by four departments in your company. The subscription contains 10 resource groups. Each department uses resources in several resource groups.
You need to send a report to the finance department. The report must detail the costs for each department. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation:
Box 1: Assign a tag to each resource.
You apply tags to your Azure resources giving metadata to logically organize them into a taxonomy. After you apply tags, you can retrieve all the resources in your subscription with that tag name and value. Each resource or resource group can have a maximum of 15 tag name/value pairs. Tags applied to the resource group are not inherited by the resources in that resource group.
Box 2: From the Cost analysis blade, filter the view by tag
After you get your services running, regularly check how much they're costing you. You can see the current spend and burn rate in Azure portal.
Visit the Subscriptions blade in Azure portal and select a subscription.
You should see the cost breakdown and burn rate in the popup blade.
Click Cost analysis in the list to the left to see the cost breakdown by resource. Wait 24 hours after you add a service for the data to populate.
You can filter by different properties like tags, resource group, and timespan. Click Apply to confirm the filters and Download if you want to export the view to a Comma-Separated Values (.csv) file.
Box 3: Download the usage report
References:
https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-group-using-tags
https://docs.microsoft.com/en-us/azure/billing/billing-getting-started

 

NEW QUESTION 131
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains the virtual machines shown in the following table.
You deploy a load balancer that has the following configurations:
* Name: LB1
* Type: Internal
* SKU: Standard
* Virtual network: VNET1
You need to ensure that you can add VM1 and VM2 to the backend pool of LB1.
Solution: You create a Standard SKU public IP address, associate the address to the network interface of VM1, and then stop VM2.
Does this meet the goal?

  • A. No
  • B. Yes

Answer: A

Explanation:
Explanation
A Backend Pool configured by IP address has the following limitations:
* Standard load balancer only
Reference:
https://docs.microsoft.com/en-us/azure/load-balancer/backend-pool-management

 

NEW QUESTION 132
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription named Subscription1. Subscription1 contains a resource group named RG1.
RG1 contains resources that were deployed by using templates.
You need to view the date and time when the resources were created in RG1.
Solution: From the RG1 blade, you click Automation script.
Does this meet the goal?

  • A. No
  • B. Yes

Answer: A

Explanation:
Explanation
From the RG1 blade, click Deployments. You see a history of deployment for the resource group.
Reference:
https://docs.microsoft.com/en-us/azure/azure-resource-manager/templates/template-tutorial-create-first-template?
Through activity logs, you can determine:
* what operations were taken on the resources in your subscription
* who started the operation
* when the operation occurred
* the status of the operation
* the values of other properties that might help you research the operation
1. On the Azure portal menu, select Monitor, or search for and select Monitor from any page
2. Select Activity Log.
3. You see a summary of recent operations. A default set of filters is applied to the operations. Notice the information on the summary includes who started the action and when it happened.
Reference:
https://docs.microsoft.com/en-us/azure/azure-resource-manager/management/view-activity-logs

 

NEW QUESTION 133
......


Main Topics and Subtopics of Microsoft AZ-104 Exam

There are a few different objectives included in the AZ-104 certification test, so the candidates will need to work hard on them. These topics cover the following areas:

  • Manage and Configure Virtual Networking (30-35%)

    In this topic, the candidates must confirm that they have expertise in implementing and managing virtual networking (designing and customizing VNET peering; customizing private and public IP addresses, subnets, network routes, virtual network, and network interface); customizing name resolution (customizing Azure DNS; customizing custom DNS settings; customizing a private or public DNS zone); securing access to virtual networks (designing security rules; associating an NSG to network interface or a subnet; assessing effective security rules; deploying and configuring Azure Firewall; deploying and customizing Azure Bastion Service); customizing load balancing (customizing Application Gateway; customizing an internal load balancer; customizing load balancing rules; customizing a public load balancer; fixing load balancing); monitoring and fixing virtual networking (monitoring on-premises connectivity; utilizing Network Performance Monitor; utilizing Network Watcher; fixing external networking; troubleshooting virtual network connectivity); integrating an on-premises network with an Azure virtual network (designing and customizing Azure VPN Gateway; designing and customizing VPNs; customizing ExpressRoute; customizing Azure Virtual WAN).

  • Manage Azure Governance and Identities (15-20%)

    This objective encompasses the following competencies: managing Azure Active Directory objects (designing users and groups; managing group and user properties; managing device settings; executing bulk user updates; managing guest accounts; customizing Azure AD Join; customizing self-service password reset); managing role-based access control (designing a custom role; accessing Azure resources through assigning roles; interpreting access assignments; managing multiple directories); managing governance and subscriptions (customizing Azure policies; customizing resource locks; applying tags; designing and managing resource groups; managing subscriptions; customizing Cost Management; customizing management groups).

  • Implement and Manage Storage (10-15%)

    Within this domain, the applicants need to demonstrate the abilities, such as managing storage accounts (customizing network access to storage accounts; designing and customizing storage accounts; generating shared access signature; managing access keys; executing Azure storage replication; customizing Azure AD Authentication for a storage account); managing data in Azure Storage (exporting from Azure job; importing into Azure job; installing and utilizing Azure Storage Explorer; copying data with the help of AZCopy); customizing Azure files and Azure blob storage (designing an Azure file share; designing and customizing Azure File Sync service; customizing Azure blob storage; customizing storage tiers for Azure blobs).

  • Monitor and Back Up Azure Resources (10-15%)

    This subject area is designed to check the examinees’ knowledge and skills in the following areas: monitoring resources with the help of Azure Monitor (customizing and interpreting metrics; customizing Log Analytics; querying and analyzing logs; setting up actions and alerts; customizing Application Insights); implementing recovery and backup (customizing and reviewing backup reports; executing backup and restore operations with the help of Azure Backup; designing a Recovery Services Vault; designing and customizing backup policy; executing site-to-site recovery with the help of Azure Site Recovery).

  • Deploy and Manage Azure Compute Resources (25-30%)

    In the framework of this topic, the test takers are required to show that they have a grasp of the following skills: monitoring resources with the help of Azure Monitor (monitoring a network; customizing and interpreting metrics; customizing Log Analytics; querying and analyzing logs; setting up actions and alerts; customizing Application Insights); executing recovery and backup (customizing and reviewing backup reports; executing restore and backup operations with the help of Azure Backup; designing Recovery Services Vault; designing and customizing backup policy; executing site-to-site recovery with the help of Azure Site Recovery).


Microsoft AZ-104 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Automate configuration management with extension-specific script extensions
  • Create Azure file sharing
Topic 2
  • Azure Identity Management and Management
  • Configure Igure self-service password reset
Topic 3
  • Automate the deployment and configuration of virtual machines
  • High availability configuration
Topic 4
  • Manage Membership to configure cost management
  • Create, manage, move resources, or remove resource group rotation groups
Topic 5
  • Settings Manage device settings
  • Apply bulk user update
  • Manage Azure AD objects
Topic 6
  • Configure network access for storage accounts
  • Storage implementation and management
Topic 7
  • Provide access to Azure resources by specifying roles and memberships or resource groups
  • Manage guest accounts
Topic 9
  • Configure Azure AD authentication for the storage account
  • Create a group administration group
Topic 10
  • Moving virtual machines from one resource group to another
  • Publish and create a metric group
Topic 11
  • Configure the VM for high availability and scalability
  • Deploy and manage Azure account resources
Topic 12
  • Create and configure K Azure Governorate Service (AKS)
  • Create and configure the Service plan for the Plan application
Topic 13
  • Manage group users and group properties
  • Create group users and groups
  • Configure joining Azure AD
Topic 14
  • Ure Azure Repository Replication Application
  • Create and configure storage accounts
Topic 15
  • Data Management Azure Storage
  • Create a shared access signature
  • Manage storage accounts
Topic 16
  • Configure large binary digit storage layers
  • Configure Igure Azure Big Data Storage
Topic 17
  • Install and use Azure Storage Explorer
  • Export from Azure functionality
Topic 18
  • Modify the Azure Resource Manager (ARM) template
  • Create a VHD template. Deploy from template
Topic 19
  • Create Azure files and Azure Blob storage
  • Create and configure the Azure File Sync service
Topic 20
  • Investment and Management Department
  • Role-based access control management
Topic 21
  • Explain registration tasks Manage multiple directories
  • Configure resource locking

 

AZ-104 Exam Dumps Pass with Updated 2021 Certified Exam Questions: https://www.dumpstests.com/AZ-104-latest-test-dumps.html

AZ-104 Exam Questions - Real & Updated Questions PDF: https://drive.google.com/open?id=128t2Vt1kamiCjHz-lSdCetIgofPjR-gN