The latest Microsoft AZ-104 Azure Administrator certification actual real practice exam question and answer (Q&A) dumps are available free, which are helpful for you to pass the Microsoft AZ-104 Azure Administrator exam and earn Microsoft AZ-104 Azure Administrator certification.
Question 331
You have an Azure subscription that contains the resource groups shown in the following table.
Name | Location |
---|---|
RG1 | West US |
RG2 | East US |
RG1 contains the resources shown in the following table.
Name | Type | Location |
---|---|---|
storage1 | Storage account | West US |
VNet1 | Virtual network | West US |
NIC1 | Network interface | West US |
Disk1 | Disk | West US |
VM1 | Virtual machine | West US |
VM1 is running and connects to NIC1 and Disk1. NIC1 connects to VNET1.
RG2 contains a public IP address named IP2 that is in the East US location. IP2 is not assigned to a virtual machine.
Choose all that apply:
*A. You can move storage1 to RG2
B. You can move NIC1 to RG2
C. If you move IP2 to RG1, the location of IP2 will change
Explanation:
You can move storage
You can’t move to a new resource group a NIC that is attached to a virtual machine.
Azure Public IPs are region specific and can’t be moved from one region to another.
Question 332
You have an Azure subscription that contains an Azure Storage account named storage1 and the users shown in the following table.
Name | Member of |
---|---|
User1 | Group1 |
User2 | Group |
User3 | Group1 |
You plan to monitor storage1 and to configure email notifications for the signals shown in the following table.
Name | Type | Users to notify |
---|---|---|
Ingress | Metric | User1 and User3 only |
Engress | Metric | User1 only |
Delete storage account | Activity log | User1, User2, and User3 |
Restore blob ranges | Activity log | User1 and User3 only |
You need to identify the minimum number of alert rules and action groups required for the planned monitoring.
How many alert rules and action groups should you identify?
Alert rules:
- 1
- 2
- 3
- 4
Action groups:
- 1
- 2
- 3
- 4
Answer:
Alert rules: 4
Action groups: 3
Question 333
You have an Azure subscription that contains an Azure file share.
You have an on-premises server named Server1 that runs Windows Server 2016.
You plan to set up Azure File Sync between Server1 and the Azure file share.
You need to prepare the subscription for the planned Azure File Sync.
Which two actions should you perform in the Azure subscription? To answer, drag the appropriate actions to the correct targets. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Actions:
- Create a Storage Sync Service
- Install the Azure File Sync agent
- Create a sync group
- Run Server Registration
Answer Area:
- First action:
- Second action:
Answer:
First action: Create a Storage Sync Service
Second action: Install the Azure File Sync agent
Explanation:
First action: Create a Storage Sync Service. The deployment of Azure File Sync starts with placing a Storage Sync Service resource into a resource group of your selected subscription.
Second action: Install the Azure File Sync agent. The Azure File Sync agent is a downloadable package that enables Windows Server to be synced with an Azure file share.
Question 334
You plan to automate the deployment of a virtual machine scale set that uses the Windows Server 2016 Datacenter image.
You need to ensure that when the scale set virtual machines are provisioned, they have web server components installed.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Upload a configuration script
B. Create an automation account
C. Create an Azure policy
*D. Modify the extensionProfile section of the Azure Resource Manager template
*E. Create a new virtual machine scale set in the Azure portal
Explanation:
Virtual Machine Scale Sets can be used with the Azure Desired State Configuration (DSC) extension handler. Virtual machine scale sets provide a way to deploy and manage large numbers of virtual machines, and can elastically scale in and out in response to load. DSC is used to configure the VMs as they come online so they are running the production software.
Question 335
You have an Azure subscription that contains two virtual networks named VNet1 and VNet2. Virtual machines connect to the virtual networks.
The virtual networks have the address spaces and the subnets configured as shown in the following table.
Virtual network | Address space | Subnet | Peering |
---|---|---|---|
VNet1 | 10.1.0.0/16 | 10.1.0.0/24 10.1.1.0/26 |
VNet2 |
VNet2 | 10.2.0.0/16 | 10.2.0.0/24 | VNet1 |
You need to add the address space of 10.33.0.0/16 to VNet1. The solution must ensure that the hosts on VNet1 and VNet2 can communicate.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Actions:
- Remove VNet1.
- Add the 10.33.0.0/16 address space to VNet1.
- Create a new virtual network named VNet1.
- On the peering connection in VNet2, allow gateway transit.
- Recreate peering between VNet1 and VNet2.
- On the peering connection in VNet1, allow gateway transit.
- Remove peering between VNet1 and VNet2.
Answer:
- Remove peering between VNet1 and VNet2.
- Add the 10.33.0.0/16 address space to VNet1.
- Recreate peering between VNet1 and VNet2.
Explanation:
Step 1: Remove peering between Vnet1 and VNet2. You can’t add address ranges to, or delete address ranges from a virtual network’s address space once a virtual network is peered with another virtual network. To add or remove address ranges, delete the peering, add or remove the address ranges, then re-create the peering.
Step 2: Add the 10.44.0.0/16 address space to VNet1.
Step 3: Recreate peering between VNet1 and VNet2
Question 336
You have an on-premises network that you plan to connect to Azure by using a site-so-site VPN.
In Azure, you have an Azure virtual network named VNet1 that uses an address space of 10.0.0.0/16 VNet1 contains a subnet named Subnet1 that uses an address space of 10.0.0.0/24.
You need to create a site-to-site VPN to Azure.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
NOTE: More than one order of answer choice is correct. You will receive credit for any of the correct orders you select.
Actions:
- Create a local gateway.
- Create a VPN gateway.
- Create a gateway subnet.
- Create a custom DNS server.
- Create a VPN connection.
- Create an Azure Content Delivery Network (CDN) profile.
Answer:
- Create a gateway subnet.
- Create a VPN gateway.
- Create a local gateway.
- Create a VPN connection.
Question 337
You have an Azure subscription that contains the resources shown in the following table.
Name | Type | Location |
---|---|---|
VNET1 | Virtual network | East US |
IP1 | Public IP address | West Europe |
RT1 | Route table | North Europe |
You need to create a network interface named NIC1.
In which location can you create NIC1?
A. East US and North Europe only
*B. East US only
C. East US, West Europe, and North Europe
D. East US and West Europe only
Explanation:
Before creating a network interface, you must have an existing virtual network in the same location and subscription you create a network interface in.
Question 338
You have an Azure subscription that contains the virtual machines shown in the following table.
Name | Public IP SKU | Connected to | Status |
---|---|---|---|
VM1 | None | VNET1/Subnet1 | Stopped (deallocated) |
VM2 | Basic | VNET1/Subnet2 | Running |
You deploy a load balancer that has the following configurations:
- Name: LB1
- Type: Internal
- SKU: Standard
- Virtual network: VNET1
You need to ensure that you can add VM1 and VM2 to the backend pool of LB1.
Solution: You disassociate the public IP address from the network interface of VM2.
Does this meet the goal?
A. Yes
*B. No
Question 339
You need to recommend a solution to automate the configuration for the finance department users. The solution must meet the technical requirements. What should you include in the recommended?
A. Azure AP B2C
B. Azure AD Identity Protection
C. an Azure logic app and the Microsoft Identity Management (MIM) client
*D. dynamic groups and conditional access policies
Explanation:
Technically, the finance department needs to migrate their users from AD to AAD using AADC based on the finance OU, and need to enforce MFA use. This is conditional access policy. Employees also often get promotions and/or join other departments and when that occurs, the user’s OU attribute will change when the admin puts the user in a new OU, and the dynamic group conditional access exception (OU= [Department Name Value]) will move the user to the appropriate dynamic group on next AADC delta sync.
Question 340
Your company has serval departments. Each department has a number of virtual machines (VMs).
The company has an Azure subscription that contains a resource group named RG1.
All VMs are located in RG1.
You want to associate each VM with its respective department.
What should you do?
A. Create Azure Management Groups for each department.
B. Create a resource group for each department.
*C. Assign tags to the virtual machines.
D. Modify the settings of the virtual machines.