Skip to Content

Exam AZ-104 Microsoft Azure Administrator Questions and Answers – Page 4

The latest Microsoft AZ-104 Azure Administrator certification actual real practice exam question and answer (Q&A) dumps are available free, which are helpful for you to pass the Microsoft AZ-104 Azure Administrator exam and earn Microsoft AZ-104 Azure Administrator certification.

AZ-104 Microsoft Azure Administrator Exam Questions and Answers

Exam Question 331

You have an Azure subscription that contains the resource groups shown in the following table.

Name Location
RG1 West US
RG2 East US

RG1 contains the resources shown in the following table.

Name Type Location
storage1 Storage account West US
VNet1 Virtual network West US
NIC1 Network interface West US
Disk1 Disk West US
VM1 Virtual machine West US

VM1 is running and connects to NIC1 and Disk1. NIC1 connects to VNET1.
RG2 contains a public IP address named IP2 that is in the East US location. IP2 is not assigned to a virtual machine.
Choose all that apply:

A. You can move storage1 to RG2
B. You can move NIC1 to RG2
C. If you move IP2 to RG1, the location of IP2 will change

Correct Answer:
A. You can move storage1 to RG2

Answer Explanation:
You can move storage
You can’t move to a new resource group a NIC that is attached to a virtual machine.
Azure Public IPs are region specific and can’t be moved from one region to another.

Reference:
Microsoft Docs > Move operation support for resources
Microsoft Docs > Move Azure Public IP configuration to another region using Azure PowerShell

Exam Question 332

You have an Azure subscription that contains an Azure Storage account named storage1 and the users shown in the following table.

Name Member of
User1 Group1
User2 Group
User3 Group1

You plan to monitor storage1 and to configure email notifications for the signals shown in the following table.

Name Type Users to notify
Ingress Metric User1 and User3 only
Engress Metric User1 only
Delete storage account Activity log User1, User2, and User3
Restore blob ranges Activity log User1 and User3 only

You need to identify the minimum number of alert rules and action groups required for the planned monitoring.
How many alert rules and action groups should you identify?
Alert rules:

  • 1
  • 2
  • 3
  • 4

Action groups:

  • 1
  • 2
  • 3
  • 4

Correct Answer:
Alert rules: 4
Action groups: 3

Exam Question 333

You have an Azure subscription that contains an Azure file share.

You have an on-premises server named Server1 that runs Windows Server 2016.

You plan to set up Azure File Sync between Server1 and the Azure file share.

You need to prepare the subscription for the planned Azure File Sync.

Which two actions should you perform in the Azure subscription? To answer, drag the appropriate actions to the correct targets. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Actions:

  • Create a Storage Sync Service
  • Install the Azure File Sync agent
  • Create a sync group
  • Run Server Registration

Answer Area:

  • First action:
  • Second action:

Correct Answer:
First action: Create a Storage Sync Service
Second action: Install the Azure File Sync agent

Answer Explanation:
First action: Create a Storage Sync Service. The deployment of Azure File Sync starts with placing a Storage Sync Service resource into a resource group of your selected subscription.
Second action: Install the Azure File Sync agent. The Azure File Sync agent is a downloadable package that enables Windows Server to be synced with an Azure file share.

Reference:
Microsoft Docs > Deploy Azure File Sync

Exam Question 334

You plan to automate the deployment of a virtual machine scale set that uses the Windows Server 2016 Datacenter image.

You need to ensure that when the scale set virtual machines are provisioned, they have web server components installed.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A. Upload a configuration script
B. Create an automation account
C. Create an Azure policy
D. Modify the extensionProfile section of the Azure Resource Manager template
E. Create a new virtual machine scale set in the Azure portal

Correct Answer:
D. Modify the extensionProfile section of the Azure Resource Manager template
E. Create a new virtual machine scale set in the Azure portal

Answer Explanation:
Virtual Machine Scale Sets can be used with the Azure Desired State Configuration (DSC) extension handler. Virtual machine scale sets provide a way to deploy and manage large numbers of virtual machines, and can elastically scale in and out in response to load. DSC is used to configure the VMs as they come online so they are running the production software.

Reference:
Microsoft Docs > Using Virtual Machine Scale Sets with the Azure DSC Extension

Exam Question 335

You have an Azure subscription that contains two virtual networks named VNet1 and VNet2. Virtual machines connect to the virtual networks.

The virtual networks have the address spaces and the subnets configured as shown in the following table.

Virtual network Address space Subnet Peering
VNet1 10.1.0.0/16 10.1.0.0/24
10.1.1.0/26
VNet2
VNet2 10.2.0.0/16 10.2.0.0/24 VNet1

You need to add the address space of 10.33.0.0/16 to VNet1. The solution must ensure that the hosts on VNet1 and VNet2 can communicate.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Actions:

  • Remove VNet1.
  • Add the 10.33.0.0/16 address space to VNet1.
  • Create a new virtual network named VNet1.
  • On the peering connection in VNet2, allow gateway transit.
  • Recreate peering between VNet1 and VNet2.
  • On the peering connection in VNet1, allow gateway transit.
  • Remove peering between VNet1 and VNet2.

Correct Answer:

  1. Remove peering between VNet1 and VNet2.
  2. Add the 10.33.0.0/16 address space to VNet1.
  3. Recreate peering between VNet1 and VNet2.

Answer Explanation:
Step 1: Remove peering between Vnet1 and VNet2. You can’t add address ranges to, or delete address ranges from a virtual network’s address space once a virtual network is peered with another virtual network. To add or remove address ranges, delete the peering, add or remove the address ranges, then re-create the peering.

Step 2: Add the 10.44.0.0/16 address space to VNet1.

Step 3: Recreate peering between VNet1 and VNet2

Reference:
Microsoft Docs > Create, change, or delete a virtual network peering

Exam Question 336

You have an on-premises network that you plan to connect to Azure by using a site-so-site VPN.

In Azure, you have an Azure virtual network named VNet1 that uses an address space of 10.0.0.0/16 VNet1 contains a subnet named Subnet1 that uses an address space of 10.0.0.0/24.

You need to create a site-to-site VPN to Azure.

Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

NOTE: More than one order of answer choice is correct. You will receive credit for any of the correct orders you select.

Actions:

  • Create a local gateway.
  • Create a VPN gateway.
  • Create a gateway subnet.
  • Create a custom DNS server.
  • Create a VPN connection.
  • Create an Azure Content Delivery Network (CDN) profile.

Correct Answer:

  • Create a gateway subnet.
  • Create a VPN gateway.
  • Create a local gateway.
  • Create a VPN connection.

Exam Question 337

You have an Azure subscription that contains the resources shown in the following table.

Name Type Location
VNET1 Virtual network East US
IP1 Public IP address West Europe
RT1 Route table North Europe

You need to create a network interface named NIC1.
In which location can you create NIC1?

A. East US and North Europe only
B. East US only
C. East US, West Europe, and North Europe
D. East US and West Europe only

Correct Answer:
B. East US only

Answer Explanation:
Before creating a network interface, you must have an existing virtual network in the same location and subscription you create a network interface in.

Reference:
Microsoft Docs > Azure > Networking > Virtual Network > Create, change, or delete a network interface

Exam Question 338

You have an Azure subscription that contains the virtual machines shown in the following table.

Name Public IP SKU Connected to Status
VM1 None VNET1/Subnet1 Stopped (deallocated)
VM2 Basic VNET1/Subnet2 Running

You deploy a load balancer that has the following configurations:

  • Name: LB1
  • Type: Internal
  • SKU: Standard
  • Virtual network: VNET1

You need to ensure that you can add VM1 and VM2 to the backend pool of LB1.

Solution: You disassociate the public IP address from the network interface of VM2.

Does this meet the goal?

A. Yes
B. No

Correct Answer:
B. No

Exam Question 339

You need to recommend a solution to automate the configuration for the finance department users. The solution must meet the technical requirements. What should you include in the recommended?

A. Azure AP B2C
B. Azure AD Identity Protection
C. an Azure logic app and the Microsoft Identity Management (MIM) client
D. dynamic groups and conditional access policies

Correct Answer:
D. dynamic groups and conditional access policies

Answer Explanation:
Technically, the finance department needs to migrate their users from AD to AAD using AADC based on the finance OU, and need to enforce MFA use. This is conditional access policy. Employees also often get promotions and/or join other departments and when that occurs, the user’s OU attribute will change when the admin puts the user in a new OU, and the dynamic group conditional access exception (OU= [Department Name Value]) will move the user to the appropriate dynamic group on next AADC delta sync.

Reference:
Microsoft Docs > Azure > Active Directory > Dynamic membership rules for groups in Azure Active Directory
Microsoft Docs > Azure > Active Directory > Conditional Access > What is Conditional Access?
Microsoft Docs > Azure > Active Directory > Authentication > Enable per-user Azure AD Multi-Factor Authentication to secure sign-in events

Exam Question 340

Your company has serval departments. Each department has a number of virtual machines (VMs).
The company has an Azure subscription that contains a resource group named RG1.
All VMs are located in RG1.
You want to associate each VM with its respective department.
What should you do?

A. Create Azure Management Groups for each department.
B. Create a resource group for each department.
C. Assign tags to the virtual machines.
D. Modify the settings of the virtual machines.

Correct Answer:
C. Assign tags to the virtual machines.

Reference:
Microsoft Docs > Azure > Resource Manager > Management > Use tags to organize your Azure resources and management hierarchy

    Ads Blocker Image Powered by Code Help Pro

    Ads Blocker Detected!!!

    This site depends on revenue from ad impressions to survive. If you find this site valuable, please consider disabling your ad blocker.