Microsoft Certification Exam Answers
Verified answers and clear explanations for every Microsoft certification exam. Browse by exam below, or practice the full set on ExamRoll.io.
Microsoft Advertising Display & Video Certification All exam questions
- A customer is searching for a new pair of running shoes. They add a pair of shoes to their cart but then leave the site. Which scenario occurs as a result of dynamic remarketing?
- A publisher is a source of display advertising inventory.
- Amanda is applying targeting to her Microsoft Audience Network campaign. Which types of bidding are available? Select al that apply.
- Anica is using Dynamic Remarketing and wants to treat product viewers and cart abandoners differently. Anica can use different bid modifiers for each of these audiences.
- Ayushi is creating a dynamic remarketing list for the Microsoft Audience Network. What is the membership duration range Ayushi can specify?
- Claudine wants to import campaigns from Facebook into the Microsoft Audience Network. Which targets can be imported using the Facebook Import tool? Select all that apply.
- Contoso Carpets have previously run search campaigns, but now want to get started with native ads. What actions should they take before getting started on a Microsoft Audience Network campaign? Select all that apply.
- Contoso Cars run search campaigns that they want to extend to the Microsoft Audience Network. They will need to create new campaigns to do this.
- Contoso Fresh Food is running a Microsoft Audience Network campaign. When you click on one of their ads, where are you redirected?
- Contoso Furniture is creating online video ads. What is the typical file type for video ads that they should use?
- Contoso Furniture is running an online campaign with video ads and paying on a cCPV basis. What does "cCPV" stand for?
- Contoso Investments are bidding for individual display impressions in a real time auction. This is an example of which sales model?
- Contoso Investments are bidding for individual display impressions in an action. This is an example of which sales model?
- Denise is running dynamic remarketing campaigns on the Microsoft Audience Network. She can also use this feature for her search campaigns.
- Erica wants to add dynamic remarketing to a Microsoft Audience Network campaign. Which steps must Erica take before implementing dynamic remarketing?
- Frank is creating a shopping feed-based audience campaign for his online store, Frank's Tools. After selecting 'Create Campaign' in the Microsoft Advertising User Interface, what should Frank select next?
- In dynamic remarketing, which of the following statements are true regarding past buyers lists?
- In the programmatic method of selling display advertising, which statements describe pricing? Select all that apply.
- In which pricing model does an advertiser pay for every thousand impressions?
- Marco is interested in tracking when people who were shown an ad and didn't click on it, but still went on to purchase at a later date. Using which feature in the Microsoft Audience Network can Marco track this?
- Monica wants to view the performance of her Microsoft Audience Network campaiqns. What are ways in which Monica can do this? Select al that apply.
- On the Microsoft Audience Network, which products do not require age targeting?
- Online video ads are not classified as display advertising.
- Richard is creating a dynamic remarketing campaign on the Microsoft Audience Network and is setting the membership duration to 30 days for shopping cart abandoners. What is the minimum number of abandoners needed in this period for the remarketing to work?
- Tailspin Toys are creating their first Microsoft Audience Network campaign. What is the minimum number of images they will need in order to do this?
- The Microsoft Audience Network has a partnership with Shutterstock to make images available for advertisers that do or do not have their own assets to use for their ads.
- To get started with the Microsoft Audience Network, Contoso Snacks will need a minimum of 3 images: a 1200 x 628, a 300 x 250, and a 728 x 90.
- What are the primary lengths, or durations, of video ads? Select all that apply.
- What are the recommended minimum image dimensions for Microsoft Audience Ads images?
- What are the standard dimensions of a leaderboard ad?
- What are the ways in which you can add images to your ads that are extended to the Microsoft Audience Network through your search campaigns? Select all that apply.
- What content is disallowed in the Microsoft Audience Network creative acceptance policy but allowed in the Search policy? Select all that apply.
- What is the aspect ratio of an ad?
- When creating your audience campaigns which the Microsoft Audience Network, it is best practice to use more than one image.
- When expanding search campaigns to the Microsoft Audience Network, ad copy will be generated using approved search text ads.
- When extending a search campaign to the Microsoft Audience Network, what is the maximum audience ads negative bid adjustment?
- When is a customer removed from a dynamic remarketing list?
- When is a customer removed from a product searchers dynamic remarketing list?
- When using the Audience Network Planner how does it describe the audience size? Estimated overall figures: the estimated monthly audience (number of people, per month, in the audience you defined).
- When using the Facebook Import tool, you can import multiple campaigns at a time.
- Where can you use the Facebook Import tool?
- Which of the following are best practices when setting up your campaign?
- Which of the following are components of ad unit specifications?
- Which of the following are forms of display advertising? Select all that apply.
- Which of the following is a way to gather images for your Microsoft Audience Network campaign?
- Which of the following statements are true of view through conversions? Select al that apply.
- Which parameters are required in universal event tracking for dynamic remarketing in audience ads?
- Which signals are used to anchor relevancy for search campaigns expanded to the Microsoft Audience Network? Select all that apply.
- Which statement best describes native ads?
- Why is the Microsoft Audience Network brand safe? Select all that apply.
- With Microsoft Advertising, you can use dynamic remarketing for which of the following?
- You can obtain images for your Microsoft Audience Network campaigns using which resources? Select all that apply.
Microsoft advertising Native & Display All exam questions
- A customer is searching for a new pair of running shoes.They add a pair of shoes to their cart but then leave the site.Which scenario occurs as a result of dynamic re marketing?
- A nica is using Dynamic Re marketing and wants to treat product viewers and cart abandon ers differently.A nica can use different bid modifiers for each of these audiences.
- A unique audience target on the Microsoft Audience Network is Linked In Profile Targeting.
- A yushi is creating a dynamic re marketing list for the Microsoft Audience Network.Whatis the membership duration range A yushi can specify?
- Adding image extensions is a key element in optimizing your campaigns for multi-channel success.What is the imagesize you need to get started?
- Adjusting bid strategies to your desired KP Is is away of optimizing your campaigns for multi-channel success.
- Con to so Cameras wants to run image based ads across the brand safe properties of the MSNwebsite,the Microsoft Edge browser,andOutlook.com.Which ad solution from Microsoft Advertising should Con to so Cameras use?
- Con to so Fitness Company's new Microsoft Audience Network campaign has been running for a few weeks and they want to review its performance.What are the ways in which they candothis?
- Con to so Insurance is running a Microsoft Audience Network campaign and wants to see howthey're performing across a variety of devices.For which devices can they pull this performance data?
- Con to so Investments are bidding for individual display impressions in a realtime auction. This is an example of which sales model?
- Con to so Phones is planning a digital marketing campaign and is buying display advertising on aC PM basis.In this instance,whatdoes"CPM"mean?
- Customers who have seen a brand’sad on both the search and audience network visit the site2.8 x more than those who are only exposed to an a don Bing.
- Erica wants to add dynamic re marketing to a Microsoft Audience Network campaign.Which steps must Erica take before implementing dynamic re marketing?
- Fernando is creating ad copy for his Microsoft Audience Network Ad for a newline of blazers he is marketing.What is the character limit for the long headline Fernando can write?
- For reporting,which column should you add to see separate rows for search,content,and audience ad metrics?
- Francois is going to use the Microsoft Audience Network planner to gather more information for his campaign.Which areas can Francois get insights into using the tool?
- If you are already advertising on Google or Facebook,you can import those campaigns into Microsoft Advertising.Which of the following statements are true when importing accounts from these publishers?
- If your campaign,adgroup,or asset group does not have an ad schedule,the ad will serve based on the last schedule you set.
- In display advertising,whatdoes"M"or"mille"indicate?
- In dynamic re marketing,which of the following statements are true regarding past buyers lists?
- In order for a report file to display rows for Search,Content,and Audience Ads in your Microsoft Audience Network campaign,which column must be selected?
- In the director guaranteed method of selling display advertising,how is pricing set?
- In which of the following places are display ads shown?
- Marco is interested in tracking when people who were shown an ad and didn'tclickonit, but still went on to purchase at a later date.Using which feature in the Microsoft Audience Network can Marco track this?
- Mario is looking to collect audience data on his recent Video Ads campaign using the Audience Network Planner.Mario sees that there is no current data available eventhough the audience segments elected has been active for 2 weeks.What are the steps he should take to find data on the ad?
- Martha is looking to optimize their search campaigns to achieve multi-channel success. What are steps Martha can take in order to achieve this goal?
- Microsoft Audience Network Ads are based on animage or video.When using images,what is the minimum number needed to begin?
- Microsoft Audience Network brand-safe sites include MSN,Outlook.com,and Microsoft.com.
- Microsoft Audience Network Campaign performance data can be viewed by day and hour in the ad schedule tab in the Microsoft Advertising UI.
- Richard is creating a dynamic re marketing campaign on the Microsoft Audience Network and is setting the membership duration to 30 days for shopping cart abandon ers.Whatis the minimum number of abandon ers needed in this period for there marketing to work?
- Tailspin Toys wants to use a CPA metric to measure the effectiveness of its display advertising campaigns.Whatdoes"CPA"standfor?
- The Con to so Daily News newspaper is selling display ads on its website using the director guaranteed method of selling display advertising.Which statements describe this selling model?
- The website administrator for'Taylor's Hiking Equipment'is customizing their U ET tag to pass parameters for Dynamic Re marketing on a new hiking boot ad.In what order should the following steps betaken to complete this task?
- URL Tracking is only available in English speaking markets for the Microsoft Audience Network.
- Video captions area supported video asset in the Microsoft Advertising Audience Network.
- What are common display advertising key performance indicators?
- What are the standard dimensions of a leader board ad?
- What are the standard dimensions of amid-page unit or rectangle ad?
- What does CPC stand for?
- What does vC PM stand for?
- What is best practice when gathering your images for multi-channel success?
- What is the minimum video duration requirement for your video asset to serve on the Microsoft Audience Network?
- What is the number of data points Microsoft Advertising processes on a daily basis?
- When creating a new campaign on the Microsoft Audience Network,in what order are the 4 steps completed?
- When creating an audience ads campaign you need to decide the keywords you want your ad to appear for.
- When is a customer removed from a product searchers dynamic re marketing list?
- When using the Audience Network Planner how does it describe the audience size? Estimated overall figures:the estimated monthly audience(number of people,permonth,in the audience you defined).
- Where do Connected TV ads reach their audiences?
- Which buying models are used in the Microsoft Audience Network?
- Which elements are mandatory when setting up your Microsoft Audience Network Ad?
- Which of the following are best practices for tagging your website to prepare for multi-channel management?
- Which of the following are image requirements when creating an Audience Ad campaign?
- Which of the following are true for U ET?
- Which of the following audience segments can you target or exclude with the Audience Network Planner?
- Which parameters are required in universal event tracking for dynamic re marketing in audience ads?
- Which set of ad dimensions represent common standard interactive advertising bureau (IAB)ad specifications?
- Which types of feed-based ads are supported in the Microsoft Audience Network?
- Which video ad type appears in the video player pre-roll,mid-roll,orpost-roll?
- With Microsoft Advertising,you can use dynamic re marketing for which of the following?
- With the Audience Planner you can view the makeup of the audience you defined,broken down by Interest(in-market audience).
- You are creating a Connected TV Ad campaign and are at the step where you need to create your ad groups.You decide that you want to use the advertiser’s own data to target and engage their existing customers.Which audience option should you choose?
- You can take advantage of audience ads with the Microsoft Audience Network by importing native&display campaigns from Facebook.
- You need atleast 2 images(wide/rectangle images,sized at 1200 x 628 pixels)to get started with Microsoft Audience Ads.
Microsoft Advertising Retail Certification All exam questions
- Contoso Cameras is seeing that their products are being rejected and want to learn why. Where can they go to find this information?
- Contoso Shoes wants to explore which websites their product ads have appeared on. Which report should they run?
- How is it generally recommended you bid on product SKU product groups?
- Julian has been hired as a consultant by Contoso Kitchens to help run PromoteIQ ads. Julian recommends running a banner ad for their newest product on a home appliance store site. What type of advertising is this?
- What is the warning symbol when looking at product issues in the store summary page?
- Which of the following bid strategies allow you to set your own bids? Select al that apply.
- Which of the following statements is true about shopping campaigns? Select all that apply.
Microsoft advertising shopping All exam questions
- A brand advertiser has strong ROA Son are tail media campaign but wants to get more valuestill.If the campaign is not capped by budget,what are the best optimization strategies to apply?
- A product appears in both a high priority(campaignA)withabidof$1,and low priority (campaignB)withabidof$10.Which will be used for a relevant query?
- Brian has a new product and wants to setup a Smart Shopping campaign.Whatisthe correct sequence of steps Brian needs to follow in order to do this?
- Clicks on product ads are charged on what basis with Microsoft Advertising?
- Con to so Bikes have forgotten to update,orre-upload,their product feed file.After how long will their feed file expire if it's not updated or re-uploaded?
- Con to so Cameras are collecting images and image links for their product feed file.Whatare some product image best practices they should adhere to?
- Con to so Cameras Inc.is adding a merchant promotion to it sad for 10%off.What clickable text will be added to Con to so Cameras'ad to highlight the promotion?
- Con to so Cameras is seeing that their products are being rejected and want to learn why. Where can they goto find this information?
- Con to so Cameras is setting up a new Smart Shopping campaign.What is the recommended amount of time they should keep their Return On Advertising Spend(ROAS)targetas-is during the algorithm's learning period?
- Con to so Cameras wants to group their products into the following sets:highmargin products,special offers,and seasonal offers.Which feed field can they use to do this?
- Con to so Cameras wants to run ads that have rich product information,including a product image and store name.What types of ads should they create?
- Con to so Cameras wants to submit local product information for their local inventory ads. How do they do this?
- Con to so Cameras'campaigns have been running for six weeks.Where can they find reporting and analysis for their shopping campaigns?
- Con to so Candies wants to change its store name in the Microsoft Merchant Center.Who can amend the store name?
- Con to so Clothing has frequent updates to the sale price and product availability attributes for specific products in their campaign.They also do not have an API setup.Whichofthe following is Con to so Clothing's best option?
- Con to so Films wants to filter their products.Which of the following attributes cannot be used to filter their products in a shopping campaign?
- Con to so Foods are creating a shopping feed and completing the product category field. Microsoft Advertising supports the use of both string such as Electronics> Communications>Telephony>Mobile Phones and Product Category IDs such as'267'.
- Con to so Hair Supplies wants to run a report that shows performance data such as clicks, impressions,and conversions for each product group in their feed.Which report should theyrun?
- Con to so Jewelry store wants to review the import status of their mostrecent Google Merchant Center import.Where will they find this in the Microsoft Advertising User Interface?
- Con to so Jewelry Store wants to start using product ads and Microsoft Shopping Campaigns from scratch.What is the correct sequence of steps they need to follow in order todothis?
- Con to so Kitchen Supplies are running product ads.When a searcher clicks on their ad, which of the following happens?
- Con to so Kitchens is a company running Sponsored Brands on a home appliance store site. What role does the store site play?
- Con to so Kitchens wants to implement product ratings but do not have a feed file for this. They've heard that ratings from one supplier do not require an additional feed.Which supplier is this?
- Con to so Lighting wants to setup Local Inventory Ads(LIAs)for their Microsoft Shopping Campaigns.In what order should the following steps betaken to setup them up?
- Con to so Pet Supplies has noticed a recent dip in impressions in their shopping campaign and want to explore.Where can they do this?
- Con to so Pet Supplies wants to run a report that shows negative keywords and the products they are preventing from showing.Which report should they run?
- Con to so Shoes want to explore which websites their product ads have appeared on.Which report should they run?
- Con to so Toys has decided to create a"catch-all"campaign with an all-products product groupinit.As a best practice,how should they bid in this scenario?
- Con to so Widget s is a new advertiser creating a new store in Microsoft Merchant Center and their store is rejected.What are possible reasons for this?
- E lodie is running shopping campaigns for her new website.Which bid strategies are available to her?
- How does Microsoft Advertising define impression share?
- How is it generally recommended you bid on productS KU product groups?
- How many custom label attributes can you add for each product?
- Hugo is setting up a new shopping campaign for a new product line.Which bid strategy can Hugo use if using a third party bid management tool?
- Julian has been hired as a consultant by Con to so Kitchens to help run Promote IQ ads. Julian recommends running a banner ad for their newest product on a home appliance storesite.What type of advertising is this?
- Microsoft Shopping Campaigns pull which of the following from the advertiser'sfeed?
- Product ads contain which of the following?
- Smart Shopping Campaigns take precedence over standard shopping campaigns.
- Ted wants to create astore in the Microsoft Advertising User Interface(UI).Where does Ted need togo in the UI to do this?
- The products rating feed file is contained in the shopping feed file.
- The store name in a product ad is taken from the advertiser's product feed.
- What are benefits of using the onsite Product Listing Ads(PLAs)solution in are tail media program?
- What are some best practices when trying to optimize your description in the product feed?
- What are the benefits to opting-into the automatic item updates in your Microsoft Shopping Campaigns'feeds?
- What are two ways you can create a Microsoft Shopping campaign?
- What does the non-targeted report in'store issues'tellyou?
- What is the Microsoft Advertising product ad maximum file size for the product image?
- When Con to so Clothing is submitting partial feed updates,which of the following attributes can be updated without editing their full feed?
- When creating a new shopping campaign you select'sell products from your catalog'as your campaign goal.After this you select your campaign subtype,and can choose between Smart Shopping,Standard Shopping,or Dynamic Shopping.
- When looking at product issues in the store summary,what is the symbol for a warning?
- Where do you go in the Microsoft Advertising User Interface to carryout a merchant center import?
- Which of the following advertisers would NOT be eligible to use Microsoft Shopping Campaigns?
- Which of the following are benefits of utilizing local inventory ads?
- Which of the following are required attributes when creating a shopping feed?
- Which of the following are the values of offsite advertising?
- Which of the following are useful Microsoft Advertising reports for your shopping campaigns?
- Which of the following is a best practice for shopping campaign structures?
- Which of the following is an optional attribute when creating your product feed?
- Which of the following is away to verify your domain when setting up Microsoft Advertising shopping?
- Which of the following statements are true about Smart Shopping?
- Which of the following statements describe the benefits of setting up a Smart Shopping campaign?
- Which of the following statements is true about shopping campaigns?
- Which report should you run to see what your audience is searching for when your product ads are shown?
- Zoe is setting up Microsoft Advertising Shopping.Select three ways in which Zoe can verify herdomain.
Microsoft Azure Administrator Associate AZ-104 Certification All exam questions
- A container group (Group1) contains two container instances. Ensure container2 can use CPU resources without negatively affecting container1. What should you do?
- A DNS service runs on VM1. Each virtual network’s DNS settings are configured as shown. You want all VMs across the virtual networks to resolve names using the DNS server on VM1. What should you do?
- A Microsoft Entra tenant contains the identities shown in the provided list. After purchasing a Microsoft Fabric license, to which identity or identities can the license be assigned?
- A new subscription user (Admin1) fails to deploy an Azure Marketplace item via an ARM template with the error that legal terms have not been accepted. What should you do to allow programmatic deployment of that Marketplace item?
- A public load balancer is distributing traffic for ports 80 and 443 across three VMs (VM1, VM2, VM3). You must ensure that all RDP connections are forwarded only to VM3. Which configuration should you use?
- A route table RT1 is created in the East US region. Given the resources in the subscription, which resource(s) can RT1 be associated with?
- A service running on VM1 needs to manage the resources in resource group RG1 using VM1's identity. What should you do first in the Azure portal?
- A storage account contains 5,000 blobs accessed by many users. To ensure users can view only specific blobs based on blob index tags, what should you include in the solution?
- A storage account hosts website content. Ensure inbound user traffic is routed to the Microsoft point-of-presence (POP) nearest the user's location. Which configuration should you use?
- A storage account named storage contains a blob of images. Client access is granted using shared access signatures (SAS). You need to ensure users receive a warning when they create a SAS that exceeds a seven-day validity period. What setting should you change on the storage account?
- A subnet named Subnet1 has VMs and an NSG (NSG1) with only the default rules. You need to add an NSG rule that prevents Subnet1 hosts from connecting to the Azure portal while still allowing connections to other internet hosts. What should the rule's Destination be set to?
- A VM in an Azure virtual network can resolve names in the private DNS zone contoso.com but cannot resolve names in the public Azure DNS zone adatum.com. You created a public Azure DNS zone named adatum.com and a private Azure DNS zone named contoso.com, and you linked contoso.com to the virtual network. VM1 can resolve internet hosts. What should you do to allow VM1 to resolve names in adatum.com?
- A Windows Server 2016 VM backed up daily with Azure Backup Instant Restore becomes infected with ransomware and must be restored. Which action should you take to restore the VM?
- A Windows Server 2016 VM is backed up daily using Azure Backup Instant Restore. After a data-encrypting ransomware infection, which statement about file recovery is TRUE?
- Admin1 (assigned the User administrator role) tries to invite an external Microsoft account (user1@outlook.com) to the contoso.onmicrosoft.com Azure AD tenant but receives a 'Generic authorization exception'. What should you change so Admin1 can invite the external user?
- After App1 is migrated, you must implement a backup solution. Which resource should you create first?
- After enabling Azure AD Premium P2, you need admin1@contoso.com to be an administrator on every device that is joined to the Azure AD domain. Which Azure AD setting should you configure?
- All resources are connected to VNet1. You will deploy an Azure Bastion host named Bastion1 into VNet1. Which of the following resources can Bastion1 provide protection for?
- All virtual machines are in resource group RG1. You need to associate each VM with its corresponding department. What should you do?
- An administrator created a custom role scoped to a resource group RG1 in Sub1. You need to make that custom role assignable to any resource group in Sub1 and Sub2 while minimizing administrative effort. What should you do?
- An administrator deployed VM1 and an Azure Storage account named storage2 together by using a single ARM template. From which Azure blade can you view the deployment template that was used?
- An AKS cluster (AKS1) must have access granted to users in the contoso.com Azure AD tenant, but currently you cannot grant those users access. What should you do first to enable granting access to contoso.com users?
- An AKS cluster named Cluster1 uses the IP addresses listed. Which IP address should be used in the DNS record to allow internet users to reach the applications in Cluster1?
- An Azure AD tenant is connected to 10 Azure subscriptions. You need a centralized way to monitor user activity across all subscriptions. Which service should you use?
- An Azure policy 'Not allowed resource types' is assigned to RG1 with parameters Microsoft.Network/virtualNetworks and Microsoft.Compute/virtualMachines and policy enforcement enabled. In RG1 you need to create VM2 and connect it to VNET1. What should you do first?
- An Azure policy is applied that restricts where Azure SQL servers can be created. What is the effect of this policy?
- An Azure subscription contains a storage account named storage1 that holds blob data. You must assign a role to User1 that allows access to the blob data and supports conditional role assignments. Which two roles can you assign to User1?
- An Azure subscription contains a storage account storage1 with a file share share1. The subscription is linked to a hybrid Azure AD tenant that has a security group Group1. You must give Group1 the Storage File Data SMB Share Elevated Contributor role for share1. What is the first step you should take?
- An Azure subscription contains Bastion1. You must support 100 concurrent SSH users on Bastion1 while minimizing management overhead. What should you do first?
- An Azure subscription contains storage account storage1 with a file share share1. You need to assign User1 the Storage File Data SMB Share Contributor role for share1. What should you do first?
- An Azure subscription includes storage account storage1 and a workspace Workspace1. You need to grant Workspace1 permission to read, write, and delete the data in storage1's containers. Which role should you assign to Workspace1?
- An Azure VM has a single data disk that must be attached to another Azure VM. To minimize the amount of time VMs are offline, which action should you take first?
- An Azure web app named webapp1 returns frequent HTTP 500 errors. You must give the webapp developers real-time access to the connection errors with full details. What should you enable first?
- An on-premises SMB share (Share1) must be accessible by a web app (webapp1) in your Azure subscription. Given webapp1 and a virtual network VNET1, what should you deploy to enable webapp1 to connect to Share1?
- App1 has deployment slots webapp1-test and webapp1-prod. After swapping webapp1-test into production, App1 experiences performance issues. What is the quickest way to revert to the previous running version of App1?
- App1 is an App Service app running on two instances and has an autoscale rule with the Instance limits Maximum set to 5. If App1 consumes 80% of available memory over a 30-minute period, what is the maximum number of instances App1 can reach during that period?
- App1 runs on two VMs (VM1 and VM2). You will place them in an Azure Availability Set and must keep App1 available during planned hardware maintenance. What should you include in the Availability Set?
- As you plan App1's migration, you create a network security group (NSG). What configuration do you recommend so users can access App1?
- Based on the public IP addresses shown, which addresses can be assigned to an Azure Firewall Premium (FW1)?
- Based on the storage accounts in the provided table, which storage account can be converted to zone-redundant storage (ZRS) replication?
- Before adding VM1 and VM2 to LB1’s backend pool, what must you do first?
- Before preparing drives for an Azure Import job to copy files into a storage account, which two files must you create?
- Developers pushed an update to App1 into Git1. webapp1 has deployment slots. To test the update before making it available to users, which two actions should you take?
- Five Azure virtual machines running Windows Server 2016 host web sites and are balanced by an Azure load balancer named LB1. Ensure each visitor is served by the same web server for every request. Which setting should you configure?
- Five Azure VMs (Windows Server 2016) are web servers behind load balancer LB1. Ensure visitors are always served by the same backend server for each request. What setting should you change?
- Five Azure VMs (Windows Server 2016) host websites and are fronted by Azure load balancer LB1. To make sure a visitor always reaches the same backend server across requests, what should you configure?
- Five Azure VMs host web services behind load balancer LB1. Which configuration guarantees a client is sent to the same backend VM for repeated requests?
- Five Azure VMs run IIS behind an Azure load balancer LB1. To ensure a client is consistently routed to the same server across requests, which configuration is required?
- Five Azure VMs run Windows Server 2016 as web servers behind load balancer LB1. You must ensure a visitor is served by the same web server for each request. What setting should you configure?
- Five Azure VMs running Windows Server 2016 act as web servers behind an Azure Load Balancer named LB1. Ensure that each visitor is routed to the same web server for all their requests. What should you configure?
- Five Azure VMs running Windows Server 2016 are configured as web servers behind an Azure load balancer named LB1. To ensure each visitor is served by the same web server for all their requests, which setting should you configure?
- Five Azure web-server VMs are behind load balancer LB1. To ensure a client is served by the same backend VM for the duration of their session, what should you configure?
- Five VMs behind an Azure Load Balancer host a web application. You need to ensure each visitor’s requests are sent to the same backend VM across requests. Which load balancer configuration should you use?
- Five Windows Server 2016 Azure VMs are acting as web servers behind an Azure load balancer (LB1). How do you ensure each visitor is routed to the same web server for all requests?
- Five Windows Server 2016 VMs host websites behind an Azure load balancer named LB1. To make sure each visitor is always directed to the same web server, which setting should you apply?
- Five Windows Server 2016 VMs run as web servers behind an Azure load balancer LB1. Ensure that each visitor is consistently routed to the same backend server for their requests. Which configuration is required?
- For storage account storage1 you create an encryption scope named Scope1. Which storage type(s) can you encrypt using an encryption scope?
- For the Azure web apps listed in the table, what is the minimum number of App Service plans you must create?
- From an on-premises server that contains D:\\Folder1, you need to copy the contents to the public container in the Azure Storage account contosodata. Which command should you run?
- From VM2 you perform a reverse DNS lookup for IP address 10.0.0.4. Which fully qualified domain name will the lookup return?
- Given multiple virtual networks across two subscriptions tied to different Microsoft Entra tenants, which of the listed VNets can be peered with VNet1?
- Given several Azure virtual networks including VNet1, which of the other virtual networks can be peered with VNet1?
- Given the Azure virtual networks in the table, which virtual networks can VNet1 peer with?
- Given the listed resources and required tasks (see associated tables), which of those tasks can be completed using Azure Storage Explorer?
- Given the planned Azure container instances listed in the table, which of those instances can be deployed together in a single container group?
- Given the resources in Subscription1 and the virtual machines you created, which virtual machines can be backed up to Vault1?
- Given the resources shown in the table, to which subnets can NSG1 be applied?
- Given the storage accounts listed in the accompanying table, which storage account can be converted to zone-redundant storage (ZRS) replication?
- Given the subscription resources shown, you need to create a network interface named NIC1. In which location can NIC1 be created?
- Given the subscription’s resources (as shown), which proximity placement group should be assigned to VMSS1?
- Identify which storage account to use for capturing IP flow logs from VM5 while meeting the retention requirements. Which storage account do you select?
- In Azure Log Analytics workspace Workspace1 you want to view error events from the Event table. Which query should you run?
- In the contoso.com tenant you have an App Service web app App1 and a Key Vault KV1 containing a wildcard certificate for contoso.com. User1 is Owner of both App1 and KV1. What should you do first to configure App1 to use the wildcard certificate stored in KV1?
- In Workspace1 (Log Analytics), which query should you run to view error events from the Event table?
- In your subscription certain identities (User1, Principal1, and Group1) are assigned the Monitoring Reader role. An action group AG1 is configured to email the Monitoring Reader role and is used by an alert rule. Who will receive an email from AG1 when the alert fires?
- LB1 will host inbound NAT rules to provide RDP (port 3389) from the internet to VM1 and VM2. What must be created on LB1 before you can add those inbound NAT rules?
- Multiple virtual networks are all peered; each contains nine VMs. To provide secure RDP access via Azure Bastion to all VMs, what is the minimum number of Bastion hosts required?
- On-premises clients connect to an app by using the pod IP addresses in an AKS cluster. Which AKS networking option should you choose so on-premises clients can reach pod IPs directly?
- Plan1 is a Standard App Service plan. To have Plan1 automatically scale when the web app’s CPU usage exceeds 80%, which Scale out method setting should you choose?
- Recommend an automated configuration solution for finance department users that meets the technical requirements. What should you include?
- Recovery Services vault RSV1 keeps instant snapshots for 5 days and daily backups for 14 days. RSV1 performs daily backups of VM1. VM1 hosts a static website last updated eight days ago. To recover VM1 to the state from eight days ago while minimizing downtime, what should you do first?
- RG26 (West Europe) contains temporary resources including SQLDB01, which is backed up to RGV1. Deleting RG26 from the portal fails. What should you do first to allow deletion of RG26?
- Same network setup as above. Solution: download and reinstall the VPN client configuration package on the Windows 10 workstation. Does this enable the workstation to reach VirtualNetworkB?
- Same network setup as above. Solution: enable Allow gateway transit on VirtualNetworkB. Will this allow the Windows 10 point-to-site client connected to VirtualNetworkA to access VirtualNetworkB?
- Same scenario as above. Solution: Open the Container (blob container) blade to view the ARM template Jon Ross used. Does this solution meet the goal?
- Same scenario as above. Solution: Open the Resource Group blade to view the ARM template Jon Ross used. Does this solution meet the goal?
- Same SQL Always On scenario. Solution: enable Floating IP (direct server return) on the internal load balancer. Does this meet the requirement?
- Same SQL Always On scenario. Solution: set the load balancer's Session persistence to Client IP. Does this satisfy the requirement for the AG listener?
- Server1 hosts a primary DNS zone adatum.com with ~1,000 records. You manage Server1 and Subscription1 from Server2, which has DNS Manager, Azure PowerShell, and Azure CLI 2.0 installed. To move the adatum.com zone into an Azure DNS zone in Subscription1 with minimal administrative effort, which tool should you use?
- Storage account storage1 has the lifecycle management rules shown. File1 is placed in the Hot access tier on June 1. What is the state of File1 on June 7?
- Store1 contains a file share named data with 5,000 files. You need to synchronize the files in that Azure file share to an on-premises server named Server1. Which three actions should you perform?
- Subnet1 is associated to VNet1 and NIC1 connects VM1 to Subnet1. You need to apply ASG1 to VM1. What action will accomplish this?
- Subscription1 (in tenant A) contains VNet1 (10.0.0.0/16) with VM1. Subscription2 (in tenant B) contains VNet2 (10.10.0.0/24) with VM2. You need to connect VNet1 and VNet2. What should you do first?
- Subscription1 contains a Log Analytics workspace named Workspace1. You need to show error events from the Event table. Which query should you run in Workspace1?
- Subscription1 contains a virtual network VNet1 in resource group RG1. User1 currently has Reader, Security Admin, and Security Reader roles. What action lets User1 assign the Reader role for VNet1 to others?
- Subscription1 contains a virtual network VNet1 in resource group RG1. User1 currently has Reader, Security Admin, and Security Reader roles at the subscription scope. You need to allow User1 to assign the Reader role for VNet1 to other users. What should you do?
- Subscription1 contains a virtual network VNet1 in resource group RG1. User1 has the Reader, Security Admin, and Security Reader roles. To allow User1 to grant the Reader role on VNet1 to other users, what should you do?
- Subscription1 contains the listed resources and virtual machines (as shown). You plan to use Vault1 to back up as many virtual machines as possible. Which virtual machines can Vault1 back up?
- Subscription1 contains VM1. From your Windows 10 PC (Computer1) on the Internet you added a network interface vm1173 to VM1. RDP to VM1 fails. To enable Remote Desktop access to VM1, what should you do first?
- Subscription1 contains VNet1 and VNet2. VNet1 has a static-route VPN gateway (VPNGW1) and a site-to-site VPN to your on-premises network. Client1 (Windows 10) has a point-to-site VPN to VNet1. VNet1 and VNet2 are peered, and on-premises clients can reach VNet2, but Client1 cannot. What should you do to allow Client1 to connect to VNet2?
- Subscription1 contains VNet1 in RG1 and User1 has Reader, Security Admin, and Security Reader roles at the subscription. What change lets User1 assign the Reader role on VNet1 to others?
- Subscription1 contains VNet1 in RG1. User1 currently has the Reader, Security Admin, and Security Reader roles. You need to allow User1 to assign the Reader role on VNet1 to other users. What should you do?
- Subscription1 contains VNet1 in RG1. User1 has Reader, Security Admin, and Security Reader roles. To permit User1 to assign the Reader role on VNet1 to other users, what should you assign?
- Subscription1 contains VNet1 in RG1. User1 has Reader, Security Admin, and Security Reader roles. To allow User1 to grant the Reader role on VNet1 to others, which action is required?
- Subscription1 contains VNet1 in RG1. User1 has Reader, Security Admin, and Security Reader roles. What should you do so User1 can assign the Reader role for VNet1 to other users?
- Subscription1 has VNet1 and VNet2. VNet1 has a VPN gateway (VPNGW1) using static routing and a site‑to‑site connection to on‑premises. Client1 (Windows 10) has a point‑to‑site connection to VNet1. VNet1 and VNet2 are peered. On‑premises can reach VNet2, but Client1 cannot reach VNet2. What should you do to allow Client1 to connect to VNet2?
- Subscription1 includes a Log Analytics workspace named Workspace1. To view error events from the Event table, which query should you run in Workspace1?
- Subscription1 includes a VM named VM1 and you have an on-premises System Center Service Manager deployment. To have Service Manager create an alert when VM1’s available memory falls below 10%, what should you do first?
- Template1 will deploy 10 Azure web apps. To minimize cost, which resource should you create before deploying the template?
- Template1's variables specify "location": "westeurope", and the resources section currently deploys the VM to that location. To deploy the virtual machine to West US using Template1, what should you do?
- Ten Windows Server VMs each host IIS and have the Azure Monitor Agent installed. To collect IIS logs from each VM and store them in a Log Analytics workspace, what should you configure first?
- Three virtual machines are in a single availability set. Attempting to resize one VM fails with an allocation error, and the resize must succeed. Which action should you take?
- Three virtual networks (VNET1, VNET2, VNET3) are peered and connected to your on-premises network. You have several virtual machines across these networks and need to monitor connectivity between the VMs and the on-premises network using Connection Monitor. What is the minimum number of Connection Monitor instances required?
- To allow User1 to deploy virtual machines and manage virtual networks while following the principle of least privilege, which RBAC role should you assign?
- To collect and monitor metrics and logs from the Linux VM named VM1, which of the following should you use?
- To ensure virtual machines use only VNet1 to communicate with Azure Monitor when enabling VM Insights, which resource should you create first?
- To run Connection Monitor and measure network latency between VM1 and the on-premises domain controller DC1, which agent or extension must be installed on DC1?
- To satisfy Admin1’s requirement, which action should you perform in the Azure portal?
- Two Windows Server VMs, VM1 and VM2, reside in Subnet1 of VNet1. Prevent VM1 from accessing VM2 on TCP port 3389. What should you do?
- User1 must be able to assign a policy to the tenant root management group. What should you do to enable this?
- Users connect to Azure from home via point-to-site VPN and from customer sites via site-to-site VPNs. App1 runs on multiple Windows Server 2016 VMs. Which two Azure services can distribute incoming connections across all the VMs? (Choose two.)
- Using an Azure Import/Export job to transfer 5 TB into Subscription1, which of the following can you use as the destination for the imported data?
- VM1 and VM2 were deployed from the same template and run line-of-business apps. An NSG is configured as shown. You need to block VM1 and VM2 users from reaching websites on the Internet over TCP port 80. What action should you take?
- VM1 is an Azure virtual machine that sends event logs to Azure. You are creating an Azure Monitor alert to notify an administrator when an error appears in VM1's System event log. Which target resource should the alert monitor?
- VM1 runs a 24/7 line-of-business app and you plan these changes: change size from D4s v3 to D8s v3; add a 500-GB managed disk; install the Puppet Agent extension; enable Desired State Configuration. Which of these changes will cause VM1 to experience downtime?
- VM1 runs a single-instance financial app App1 and experiences CPU spikes at month end. You will create a scheduled runbook to increase VM1's processor performance at month end. What action should the runbook perform?
- VM3 fails to meet the technical requirements. To determine whether network security groups are causing the issue, which tool should you use?
- VNET1 contains multiple subnets and each VM uses a static IP. Requirements: allow web requests from the Internet to VM3–VM6; allow all connections between VM1 and VM2; allow RDP to VM1; block all other traffic to VNET1. What is the minimum number of network security groups (NSGs) required?
- VNet1 contains Subnet1 with three VMs, each with a public IP. Apps are available to Internet users over port 443. There is a site-to-site VPN from on-premises to VNet1. VMs are reachable by RDP from both the Internet and on-premises. You must block RDP from the Internet but allow RDP from the on-premises network, while keeping the apps available to Internet users. What should you implement?
- VNet1 contains subnets Gateway, Perimeter, NVA, and Production. Two NVAs in the NVA subnet inspect traffic between Perimeter and Production. You must deploy an Azure load balancer so the NVAs run active‑active with automatic failover and load balance traffic to two services on the Production subnet that use different IP addresses. Which three actions should you perform?
- VNet1 currently has no connected resources. You plan to peer VNet1 with VNet2, and VNet2 uses the 10.2.0.0/16 address space. What should you do first to create the peering?
- VNet1 is linked to a private DNS zone contoso.com that contains several records. From VM1 you need to ping VM2. Which DNS name(s) can you use to reach VM2?
- VNet1 uses ExpressRoute to connect to on-premises. You want automatic failover to a site-to-site VPN if ExpressRoute fails and you must minimize cost. Which three actions should you perform? (Choose three.)
- VNet1 uses IPv4 172.16.10.0/24 and Subnet1 is 172.16.10.0/25. What is the maximum number of virtual machines that can be assigned IPs in Subnet1?
- VNet1 uses two ExpressRoute circuits to connect to two on-premises datacenters. You need a dashboard that shows detailed metrics and a visual network topology. Which service should you use?
- WebApp1 in RG1 is located in West Europe. You move WebApp1 to RG2. What happens to the App Service plan’s region and which policy is applied to WebApp1 after the move?
- What change is required so you can grant Group4 Azure RBAC read-only permissions to all Azure file shares?
- When deploying multiple VMs in a single availability set via ARM templates you want to maximize how many VMs remain available during fabric failure or maintenance. What value should you set for the platformUpdateDomainCount property?
- When deploying multiple Windows Server 2022 virtual machines in a VM scale set via an ARM template, how can you ensure NGINX is present and running on every VM after deployment?
- When deploying route-based site-to-site VPN connections from multiple on-premises locations to an Azure virtual network, which tunneling protocol should you use?
- When using Bulk delete in the Azure AD admin center to delete multiple users, which user attribute(s) must be included in the uploaded file?
- When using the Azure Monitor Agent and a data collection rule to collect only Windows System event log entries with event ID 1001, which query type should you use for the data source?
- Which Azure Stream Analytics metric shows the count of input events that were not processed by the job?
- Which components must you configure to create an Azure Monitor activity log alert that emails you when a resource lock is removed from any resource in the subscription?
- Which diagnostic destination should you configure for DB1 so you can run queries and analyze its log data in Azure Monitor?
- Which storage account from the subscription can be converted to zone-redundant storage (ZRS) replication by requesting a live migration from Azure support?
- Which two tools can you use to configure the cluster autoscaler for AKS1? (Each correct answer is a complete solution.)
- With Traffic Analytics enabled and a new VM1 placed in VNet1 using NIC NSG1, which settings must you configure to monitor VM1 traffic with Traffic Analytics?
- You add contoso.com as a custom domain to Azure AD and need Azure to verify ownership. Which DNS record type should you create in your public DNS zone?
- You are troubleshooting performance problems and need to investigate metrics related to Azure infrastructure. Which tool should you use to examine those metrics?
- You backed up a folder named Folder1 on VM1. To restore that backup to a different VM (VM2), what should you do first?
- You backed up an Azure VM named VM1 (backup named Backup1). After the backup you changed VM1 as follows: changed its VM size, copied Budget.xls into a Data folder, reset the built-in administrator password, and attached a new data disk. An administrator restores VM1 using the Replace existing option from Backup1. To ensure all modifications are present after the restore, which change must you perform again?
- You configure Azure Site Recovery to replicate VM1 from US East to West US and perform a test failover specifying VNET2 as the target virtual network. When the test VM1 is created, which subnet will the test VM be connected to?
- You create a public IP address IP1. Which two of the following resources can you associate with IP1?
- You create a storage account and will add 10 blob containers. For one container you need to use a different key for encrypting data at rest. What must you do before creating that container?
- You created a load balancer to distribute HTTPS traffic between two VMs (VM1 and VM2). Which two additional load balancer resources must you create before you can create the load balancing rule?
- You created a new subscription (AZPT2) and need to determine which resources from subscription AZPT1 can be moved to AZPT2. Which resources can be moved?
- You created a route in route table RT1 and must specify the next hop by IP address. Which next hop type should you choose?
- You created a storage account contosostorage and a file share named data. Users will map a drive to that file share from Windows 10 home computers. Which outbound port must be opened between the home computers and the file share?
- You created a VM (VM1) running Windows Server 2019 and you need to enable Desired State Configuration (DSC) for VM1. What should you do first?
- You created an App Service plan named Plan1 and a web app webapp1, but the option to create a staging slot is not available. What should you do first to enable a staging slot for Plan1?
- You created VM1 (Windows Server 2019) and need to enable Desired State Configuration on it. What is the first action you must take?
- You deploy an AKS cluster in an Azure subscription with multiple pods using Kubernetes networking. To restrict network traffic between the pods, which network policy should you configure on the AKS cluster?
- You deployed a web app named App1 to the West US region. To back up App1 while minimizing cost, which of the following storage accounts should you use as the backup target?
- You deployed a web server on an Azure VM and configured a secure HTTPS site (port 443). The VM’s network interface has existing NSG rules as shown. The VM is used only as a web server. What change will allow users on the Internet to connect to the site?
- You deployed VMs to three regions with virtual networks peered in a full mesh. Each subnet has an NSG with rules. A user cannot connect on port 33000 from a VM in one region to a VM in another region. Which two options can you use to diagnose this issue?
- You downloaded an Azure Resource Manager template based on an existing VM to deploy 100 VMs. You must modify the template so the admin password is referenced without storing it in plain text. What should you create to securely store the password?
- You enabled the Admin user for the Azure container registry named ContReg1. Which username should you use to sign in to ContReg1?
- You generalized a reference VM in your on-premises environment to create an image and need to upload that image to Azure so it appears as a selectable option when creating new Azure VMs. Which PowerShell cmdlet uploads the VHD to Azure?
- You have 10 NSGs each attached to a virtual machine and a Log Analytics workspace named Workspace1. To enable an Azure Monitor Network Insights alert that triggers on suspicious network traffic, what should you configure first?
- You have 10 VMs, a Key Vault Vault1, and an NSG named NSG1 that blocks all outbound internet traffic. All resources are in East US. You need the VMs to access Vault1 while using least privilege and minimal effort. What should you set as the destination in NSG1's outbound security rule?
- You have 15 Azure subscriptions and an Azure AD tenant with a security group named Group1. You will buy additional subscriptions. Ensure Group1 can manage role assignments for all existing and future subscriptions while following least privilege and minimizing administrative effort. What should you do?
- You have a Bicep file (File1) to deploy a storage account named storage1 into resource group RG1. Which Bicep property should you change so the file deploys storage1 to RG1?
- You have a general-purpose v1 storage account (storage1) using locally-redundant storage (LRS). You must ensure data is protected if an availability zone fails, while minimizing cost and management effort. What should you do first?
- You have a Microsoft Entra tenant and plan to bulk-import users. You want imported accounts to be automatically added to a specific group based on each user's department, with minimal administrative effort. Which two actions should you take?
- You have a Microsoft Entra tenant contoso.com and collaborate with fabrikam.com. You will invite fabrikam.com users to contoso.com and must allow invitations only to fabrikam.com accounts. Which setting in the Microsoft Entra admin center should you configure?
- You have a policy-based virtual network gateway (GW1) for VNet1. You must be able to configure a point-to-site connection from an on-premises computer to VNet1. Which two actions should you perform?
- You have a Recovery Services vault (Vault1). To enable multi-user authorization (MAU) for the vault, which resource must you create first?
- You have a Recovery Services vault used for testing backups; the test backups include two protected virtual machines. You need to delete the Recovery Services vault. What should you do first?
- You have a Standard SKU Azure Container Registry named ContReg1. To enable geo-replication for ContReg1, what should you do first?
- You have a storage account named account1. You will upload VM disk files from an on-premises network with public IP range 131.107.1.0/24 and then attach those disks to VM1 in VNet1 (192.168.0.0/24). Configure account1 so you can upload the disks, attach them to VM1, and block all other access. Which two actions should you take on account1?
- You have a storage account named storage1 in North Europe. You need a secondary copy of blob data to be created in East US when blobs are added, with minimal administrative effort. Which feature should you configure?
- You have a storage account named storage1 that contains a blob container named container1. You must ensure new blobs added to container1 cannot be modified for one year. Which setting should you configure?
- You have a VM named VM1 and an Azure Function named App1. You need an alert rule that will invoke App1 if VM1 stops. What should the alert rule use?
- You have an ARM template file named Template.json. Which PowerShell cmdlet should you run from Azure Cloud Shell to deploy Template.json at the subscription scope?
- You have an ARM template that creates a resource group and deploys an Azure Storage account to it. Which PowerShell cmdlet should you run to deploy the template?
- You have an Azure AD subscription and must require Global Administrators to use MFA and an Azure AD–joined device when connecting from untrusted locations. Solution: you modify the session controls of the Azure AD conditional access policy in the Azure portal. Does this solution meet the requirement?
- You have an Azure AD subscription and must require members of the Global Administrators group to use MFA and an Azure AD–joined device when they sign in from untrusted locations. Solution: you change user settings on the Multi-Factor Authentication page. Does this solution meet the requirement?
- You have an Azure AD tenant adatum.com where 'Users may join devices to Azure AD' is set to User1 and 'Additional local administrators on Azure AD joined devices' is set to None. User1 joins Computer1 to adatum.com. Which users will be members of the local Administrators group on Computer1?
- You have an Azure App Service web app named App1. Which tool should you use to collect performance traces for App1?
- You have an Azure DNS zone named adatum.com and need to delegate the subdomain research.adatum.com to a different DNS server in Azure. What should you create in the adatum.com zone?
- You have an Azure Storage account named storage1 and plan to use AzCopy to transfer data to it. Which storage services in storage1 can AzCopy copy data to?
- You have an Azure subscription named Sub1 that contains the resources shown in the table. You create a user named Admin1. To which of the following can you add Admin1 as a co-administrator?
- You have an Azure subscription named Subscription1 and must import 5 TB using an Azure Import/Export job. Which of the following can be the destination for the imported data?
- You have an Azure subscription named Subscription1 and need to import 5 TB using an Azure Import/Export job. Which of the following can be the destination for the imported data?
- You have an Azure subscription that contains a storage account, a resource group, a blob container and a file share. A colleague deployed a virtual machine and an additional storage account using a single ARM template. You need to view the ARM template Jon Ross used. Solution: Open the Virtual Machine blade. Does this solution meet the goal?
- You have an Azure subscription that contains a storage account named storageacct1234 and two users, User1 and User2. User1 has specific roles assigned (as shown). Which two actions can User1 perform? Choose two.
- You have an Azure subscription with 10 virtual machines. You need to monitor latency between your on-premises network and those virtual machines. Which tool should you use?
- You have an Azure subscription with 100 virtual machines. Which Azure portal blade should you use to quickly find underutilized VMs that could be moved to a less expensive service tier?
- You have an Azure subscription with a storage account named storage1 and several devices listed in the accompanying table. From which devices can you run AzCopy to copy data to storage1?
- You have an Azure subscription with virtual networks and virtual machines (all VMs have only private IP addresses). You deployed an Azure Bastion host named Bastion1 into VNet1. Which virtual machines can you connect to through Bastion1?
- You have an Azure VM named VM1 and an Azure Key Vault named Vault1. You plan to enable Azure Disk Encryption on VM1 using a key encryption key (KEK). What two actions must you perform on Vault1 to prepare it for Azure Disk Encryption?
- You have an Azure VM named VM1 running Windows Server 2019 deployed with default drive settings. Signed in as User1 you create files on C:, create files on D:, change the screen saver timeout, and change the desktop background. You plan to redeploy VM1. Which of these changes will be lost after redeploy?
- You have an Azure web app (webapp1) and a virtual network VNET1 that contains VM1 hosting MySQL. VM1 is connected to VNET1. What should you do so webapp1 can access the data on VM1?
- You have an on-premises virtual machine VM1 and you need to make its attached disks usable as a template for Azure virtual machines. Which setting on VM1 should you modify?
- You have datacenters in Miami, Los Angeles, and New York and an Azure subscription with virtual networks in East US and West US (peered). To connect the datacenters to the subscription while minimizing network latency, what should you create?
- You have Registry1 (an Azure Container Registry) and Cluster1 (an AKS cluster). You created a container image named App1 on your workstation. What should you do first to deploy App1 to Cluster1?
- You have several Azure virtual machines where a Recovery Services vault currently protects VM1 and VM2. You need to protect VM3 and VM4 with Recovery Services. What is the first action you should take?
- You have Subscription1 and need to import 5 TB using an Azure Import/Export job. Which of these can you use as the import destination?
- You have Subscription1 with 5 TB to import using Azure Import/Export. Which of these can be the destination for the imported data?
- You have three virtual machines (VM1, VM2, VM3) in an availability set named AVSet1. You need to resize VM1 to a new VM size, but the desired size is not available. What should you do first?
- You have two Log Analytics workspaces (Workspace1 and Workspace2) and 100 Windows Server VMs. You must collect performance counters and events from the VMs, send logs to both workspaces, and capture all Windows and security events. Which agent or extension should you install and configure on each VM?
- You have two peered virtual networks named VNet1 and VNet2 and a Network Virtual Appliance (NVA) named NetVA1. You want all traffic from VNet1 to VNet2 to be inspected by NetVA1. Which mechanism should you use?
- You have two virtual networks, VNet1 and VNet2. You need to ensure that all traffic between them travels over the Microsoft backbone network. Which feature should you configure?
- You have VMs in two peered virtual networks (VM1 in VNet1 and VM2 in VNet2). To view the average round-trip time (RTT) for packets from VM1 to VM2, which Azure Network Watcher feature should you use?
- You have VMs VM1 and VM2 and two Recovery Services vaults RSV1 and RSV2. VM2 is currently backed up to RSV1. You need to back up VM2 to RSV2. What should you do first?
- You have web apps in West US, Central US, and East US and several App Service plans. You want to create a new Linux App Service plan named ASP5. In which of the currently used regions can you deploy ASP5?
- You host VMs in a single Azure virtual network named VNet1 and have remote users who need access to those VMs. Which of the following should you configure?
- You manage three branch offices and an Azure subscription with an Azure Active Directory tenant. You must grant a local administrator in each office permission to manage users. Which feature should you use?
- You must allow access to a storage account (storage1) from selected networks and your home office while minimizing administrative effort. What should you modify first on storage1?
- You must configure access for VNET1 so its virtual machines can communicate with VNET2 over the Microsoft backbone and can access storage1, storage2, and Azure AD over the Microsoft backbone. What is the minimum number of service endpoints you need to add to VNET1?
- You must deploy a virtual machine scale set containing five instances as quickly as possible. Which approach should you use?
- You must deploy five virtual machines into a single virtual network subnet. Each VM will have both a public and a private IP address, and all VMs must use identical inbound and outbound security rules. What is the minimum number of network/security groups required for this setup?
- You must deploy five VMs to a subnet; each VM will have a public and a private IP and all VMs must share identical inbound and outbound security rules. What is the minimum number of network interfaces required?
- You must enable communication between VM1 and VM4 while minimizing administrative effort. What action should you take?
- You need an ExpressRoute gateway that supports up to 10 Gbps, availability zones, FastPath, and minimizes cost. Which gateway SKU should you deploy?
- You need to add the custom domain name www.contoso.com to an Azure web app named webapp1. What is the first action you must take?
- You need to assign a proximity placement group for VMSS1. Which proximity placement group(s) should you use?
- You need to configure the web app contoso.azurewebsites.net to host the custom domain www.contoso.com. What should you do first?
- You need to create a storage account named storage1 with these requirements: support Azure Data Lake Storage, minimize cost for infrequently accessed data, and automatically replicate data to a secondary region. Which three settings should you configure for storage1?
- You need to enable communication between VM1 and VM4 with minimal administrative overhead. Which step should you perform?
- You need to grant three users temporary access to a SharePoint document library and ensure the groups are automatically deleted after 180 days. Which two group types should you create?
- You need to import 5 TB into Subscription1 by using an Azure Import/Export job. Which of the following can be the destination for the imported data?
- You need to import 5 TB into Subscription1 by using an Azure Import/Export job. Which of these can be the import destination?
- You need to log all successful and failed connection attempts to VM1. Which three steps should you perform?
- You need to manage outbound traffic from VNet1 via Firewall1. What is the first step you should take?
- You need to monitor the availability of an Azure web app named App1 using a multi-step web test. Which feature in Azure Monitor should you use?
- You need to move VM1 from subscription Sub1 to Sub2. VM1 uses Disk1, NetInt1, and VNet1; Sub1 also contains storage1. Which resources must you move to Sub2 to successfully relocate VM1?
- You need to transfer the blueprint files to Azure. Which method should you use?
- You operate datacenters in Los Angeles and New York and must choose an Azure storage redundancy option. Requirements: data must be stored on multiple nodes, on nodes in different geographic locations, and data must be readable from the secondary location as well as the primary. Which redundancy option satisfies these requirements?
- You plan to apply lifecycle management rules to manage data in several storage accounts. To which of the listed storage accounts can you apply lifecycle management rules?
- You plan to apply role-based access control (RBAC) role assignments with conditions to storage account storage1. Which storage services in storage1 support conditional role assignments?
- You plan to automate deployment of a virtual machine scale set using the Windows Server 2016 Datacenter image. You need the scale set instances to have web server components installed when provisioned. Which two actions should you perform?
- You plan to back up an Azure VM named VM1 but the Backup Pre-Check shows a status of Warning. Which of the following is a possible cause of the Warning?
- You plan to create a blob container named container1 in storage1 and want to use customer-managed key encryption for that container. Which key type and size should you use?
- You plan to create a storage account named storage1 with these settings: Performance: Standard; Replication: ZRS; Access tier (default): Cool; Hierarchical namespace: Disabled. To allow Account kind to be set to BlockBlobStorage, which setting must you change first?
- You plan to create the web apps shown in the table. What is the minimum number of App Service plans required to host those web apps?
- You plan to create VM1 with the disk configuration shown. To guarantee VM1 can be deployed into an Availability Zone, which two settings must you change? (Choose two.)
- You plan to deploy a container and need services that can scale the container automatically. Which Azure services can provide automatic scaling for the container?
- You plan to deploy an App Service web app App1 via Web Deploy. Developers should be able to deploy using their Azure AD credentials while following least privilege. What should you do?
- You plan to deploy an Azure Bastion Basic SKU host named Bastion1 and have a list of public IPs. Which of the following public IP choices is valid for Bastion Basic?
- You plan to deploy an Azure Bastion Basic SKU host named Bastion1 into VNET1. To allow inbound access to virtual machines through Bastion1, which port must an inbound rule in NSG1 permit?
- You plan to deploy an Azure Container Instance named container1 and need the ability to reuse DNS name labels. Which networking option should container1 use?
- You plan to export data using an Azure Import/Export job named Export1. Given the available data items DB1, container1, share1, and Table1, which item can be exported with Export1?
- You plan to migrate 50 virtual machines from VMware vSphere to an Azure subscription and you have already created a Recovery Services vault. What should you do next to prepare the migration?
- You plan to migrate two on-premises servers to Azure VMs on the same subnet and the application requires static internal IP addresses. What should you do to assign static private IPs to the two Azure VMs?
- You plan to use an Azure Import/Export job to transfer 5 TB into Subscription1. Which of these can be the destination for the imported data?
- You plan to use the Azure Import/Export service to export data from a subscription that contains several storage accounts. Which of the storage accounts can be used to export data with the Import/Export service?
- You registered contoso.com and created a public Azure DNS zone named contoso.com. What must you update so the records in that Azure DNS zone are resolvable from the internet?
- You saved VM1 as an ARM template named Template1 and will deploy VM2 from Template1. Which of these settings can you specify at deployment time for VM2?
- You want to delete the TestRG resource group. Which actions must you perform first?
- You will create a storage account named storage1 with a file share named share1. Ensure share1 supports SMB Multichannel while minimizing cost. Which storage configuration should you choose?
- You will create an Azure container instance (container1) that uses an image (Image1) containing SQL Server, and it requires persistent storage. Which Azure storage service should you configure for container1?
- You will create an Azure container registry named ContReg1 and need to be able to push and pull signed images. What must you enable for ContReg1?
- You will deploy an Azure Firewall AF1 to resource group RG1 in the West US region. Given the virtual networks in the subscription, to which virtual networks can AF1 be deployed?
- You will deploy an Ubuntu Server VM and must include a specific trusted root CA as part of the custom deployment. Which command should you use to create the VM?
- You will deploy multiple Windows Server 2019 virtual machines in a VM scale set by using an ARM template. How can you ensure NGINX is available on every VM after deployment?
- You will deploy multiple Windows Server 2019 VMs in a virtual machine scale set using an Azure Resource Manager template. To ensure NGINX is available on every VM after deployment, which should you use?
- You will deploy several resources with a single ARM template. Which resource should be included in the dependsOn list for VM1?
- You will deploy several Windows Server 2019 VMs in a scale set using an ARM template. To ensure NGINX is present on every VM after deployment, which should you use?
- You will deploy three Azure VMs in separate availability zones and configure a site-to-site VPN gateway so those VMs can connect to an on-premises database server. Which public IP address SKU and assignment should you use for the VPN gateway?
- You will deploy three VMs (VM1, VM2, VM3) to host a web app and must ensure at least two VMs remain available if a single Azure datacenter becomes unavailable. How should you distribute the virtual machines?
- You will move a distributed on-premises application to Azure and run it across multiple VMs. To guarantee the application always runs on at least eight VMs during planned Azure maintenance, what should you create?
- You're enabling Azure AD authentication for storage1 and need members of Group1 to be able to upload files via the Azure portal while following least privilege. Which two roles should you assign for storage1?
- Your Azure AD tenant adatum.com contains several groups and users. You assign the Azure AD Premium P2 license to Group1 and to User4. Which users end up with the Azure AD Premium P2 license?
- Your Azure AD tenant contains 5,000 users. You create a new account named AdminUser1. From the user account properties, which action will assign the User administrator role to AdminUser1?
- Your Azure AD tenant contoso.onmicrosoft.com has 100 users and you purchase 10 Azure AD Premium P2 licenses. To enable all Azure AD Premium features for 10 users, what should you do?
- Your Azure AD tenant has the groups listed in the table and you have Azure AD Premium P2 licenses available. Which groups can you assign a license to?
- Your Azure AD tenant weyland.com is synced with on-premises AD using a DirSync server named DirSync1. You create a new on-premises user and need the user replicated to Azure AD immediately. Solution: you run Start-ADSyncSyncCycle -PolicyType Initial. Does this solution meet the requirement?
- Your Azure AD tenant weyland.com is synced with on-premises AD using a DirSync server named DirSync1. You create a new on-premises user and need the user replicated to Azure AD immediately. Solution: you force replication of the Global Catalog on a domain controller via Active Directory Sites and Services. Does this solution meet the requirement?
- Your Azure subscription contains 100 virtual machines and you frequently create and delete VMs. You need to find unattached disks that you can delete. What should you do?
- Your Azure subscription contains the Microsoft Entra identities shown in the table. For which identities can you enable self-service password reset (SSPR) through the Azure portal?
- Your Azure subscription contains the resources shown in the table. How do you ensure data transferred between storage1 and VM1 does NOT go over the public internet?
- Your Azure VMs host a SQL Server Always On availability group and you need an internal Azure load balancer to act as the AG listener. Solution: create an HTTP health probe that checks port 1433. Does this meet the requirement?
- Your company requires all personal and corporate devices to be registered or joined to Azure AD. A remote user, User1, cannot join a personal device to Azure AD from their home network, although they could previously. What should you change to allow User1 to join the device to Azure AD?
- Your on-premises network includes a VPN gateway and your Azure subscription contains the resources shown in the table. What should you configure to force VM1-to-storage1 traffic to use the Microsoft backbone?
- Your on-premises network includes a VPN gateway. In your Azure subscription (resources shown in the table), what should you configure so traffic from VM1 to storage1 stays on the Microsoft backbone?
- Your on-premises network includes a VPN gateway. You have Azure resources including VM1 and storage1. To ensure all traffic from VM1 to storage1 uses the Microsoft backbone network, which configuration should you use?
- Your on-premises network includes a VPN gateway. Your Azure subscription contains the resources shown in the table. How do you ensure that all traffic from VM1 to storage1 travels over the Microsoft backbone network?
- Your on-premises network includes a VPN gateway. Your Azure subscription contains the resources shown in the table. How can you ensure that traffic between VM1 and storage1 flows across the Microsoft backbone?
- Your on-premises virtual environment runs Windows Server 2012 R2 VMs on Hyper-V. You have PowerShell scripts to configure new VMs and want those scripts to run automatically on newly created VMs. Which is the best solution?
- Your organization has an Azure AD tenant (weyland.com) configured for hybrid coexistence with on-premises Active Directory. A DirSync server named DirSync1 is deployed. After creating a new user in the on-premises AD, you need the user information replicated to Azure AD immediately. Solution: Restart the NetLogon service on a domain controller. Does this solution meet the requirement?
- Your organization uses MFA with the Per Authentication usage model. After onboarding acquired-company users, they must use the Per Enabled User usage model. Solution: you create a new MFA provider and restore it from a backup of the existing MFA provider data. Does this solution meet the requirement?
- Your organization uses MFA with the Per Authentication usage model. After adding acquired-company users to Azure AD, they must be switched to the Per Enabled User usage model. Solution: you change the existing usage model using the Azure CLI. Does this solution meet the requirement?
- Your organization uses MFA with the Per Authentication usage model. After acquiring another company and adding their users to Azure AD, you need those users to be covered by the Per Enabled User usage model. Solution: you change the existing usage model through the Azure portal. Does this solution meet the requirement?
- Your subscription contains a storage account storage1 with a container named container1. You need to configure access to container1 so that: only read access is allowed, both HTTP and HTTPS are permitted, and the permission applies to all content in the container. Which mechanism should you use?
- Your subscription contains a VM named VM1 and a key vault named KV1. You must configure encryption for VM1 so that the encryption key is stored and used from KV1, encryption remains intact if VM1 is downloaded from Azure, and both the OS disk and data disks are encrypted. Which encryption method meets these requirements?
- Your subscription contains several public IP addresses. You must create a Standard public Azure Load Balancer. Which of the available public IP addresses can you associate with the Standard Load Balancer?
- Your subscription contains VirtualNetworkA (which has a static-routing VPN gateway and a site-to-site VPN to your on-premises network) and VirtualNetworkB. You configured a point-to-site VPN from a Windows 10 workstation to VirtualNetworkA and peered VirtualNetworkA with VirtualNetworkB. On-premises systems can reach VirtualNetworkB, but the Windows 10 workstation cannot. You must allow the workstation to connect to VirtualNetworkB. Solution: enable Allow gateway transit on VirtualNetworkA. Does this meet the requirement?
- Your subscription has a Recovery Services vault named Vault1 and several virtual machines. You plan to schedule backups nightly at 23:00. Which virtual machines can be protected by Azure Backup under this configuration?
- Your subscription includes a storage account named storage1. How can you ensure storage1's access keys are rotated automatically?
- Your subscription includes several devices shown in the table. On which devices can Azure Storage Explorer be installed?
Microsoft Azure Developer Associate AZ-204 Certification All exam questions
- A .NET application must receive a message whenever an Azure virtual machine finishes processing data. Messages must not persist after the receiver processes them. Which .NET client object should the receiver use?
- A .NET web app uses the Cosmos DB Core API and must support millions of reads/writes with the account configured for multiple write regions. The app is deployed in East US2 and Central US. What two client-side changes can enable multi-region writes from the application?
- A company has multiple web and mobile apps that rely on both in-house and social identity providers. You need to implement single sign-on (SSO) across all applications. Which solution should you use?
- A company requires periodic checks for websites hosted in Azure App Service: every five minutes verify responsiveness, enforce a response-time threshold, ensure dependent assets (images, JS) load, generate alerts on issues, and retry loading up to three additional times if a page fails. Which approach requires the least effort to meet these requirements?
- A company requires that all data in an Azure Blob Storage account remain in the archive tier. How can you ensure that data copied into the account is immediately placed into the archive tier?
- A deployment to your Azure Web App is failing, and the app won’t start. You need to inspect running processes, view environment variables, and obtain the generated deployment script that App Service would use for your runtime stack, all from the platform tools. Which Kudu actions should you use?
- A developer accidentally deleted a blob that had several snapshots. You must be able to recover deleted blobs for up to 14 days, including their snapshots, with minimal operational overhead. What should you do?
- A developer built a mobile app that acquires Azure AD access tokens using the OAuth 2.0 implicit grant flow. The app must be registered in Azure AD. The developer asks you what value is required for registration. Is the original statement that you require a redirect URI correct?
- A development team is building a REST API that stores data in Azure Blob Storage and will be deployed to Azure App Service. Developers need access to the storage account for two months only, and must not have access after that period. How should you grant the developers temporary access?
- A diving company requires that divers complete a health questionnaire every 15 days after each dive start. You need autoscaling rules so instances increase while divers fill out the form and decrease afterward. Which two autoscale configurations would satisfy this requirement?
- A production incident is in progress. You need to watch near real-time request rate, failure rate, and dependency calls for a single App Service instance in the production slot without waiting for data to be stored. You also want to filter to only failed requests and dependencies to reduce noise. What should you use?
- A retailer tracks inventory in real time and sends events to Azure Event Grid. You need a subscription filter that can adapt dynamically to seasonal shifts in product demand. Which type of Event Grid filter should you use?
- A web app hosted on Azure App Service must connect to an on-premises SQL Server over TCP 1433. You cannot expose SQL Server publicly, and you do not want to integrate the App Service with an Azure VNet. The on-premises network has outbound internet access. Which steps should you take to enable connectivity?
- A web app in Azure App Service reads large blob data from an Azure Storage account. All resources are deployed in one region. You must move the storage account and copy all blob data to a different region. What should you do first?
- A web application goes offline periodically for offline processing and generates many Azure Monitor alerts that page the on-call engineer. The app must always log when it is offline, but you do not want to page the on-call person during planned offline processing. What should you do to avoid paging during offline runs?
- A worker processes messages from a Service Bus queue (QueueA). For each message, it must send a notification to a topic (TopicB) and a command to another queue (QueueC), then complete the original message. All three operations must succeed or fail together. What should you do?
- An App Service plan hosts a web API that experiences unpredictable traffic spikes during business hours. You need to minimize cost overnight while ensuring the API scales out quickly when either CPU exceeds 70% or memory exceeds 75% for 10 minutes. During business hours (8 AM–6 PM), maintain a minimum of 3 instances; off-hours maintain 1 instance; and never exceed 10 instances. What configurations should you implement?
- An App Service web app is deployed to multiple regions behind Azure Traffic Manager with Application Insights enabled. You need monthly uptime analysis per month. Which two solutions will provide that data?
- An application receives phone-submitted cell-tower data via Azure Web PubSub, processed by Azure Functions and delivered through a CDN. The Azure Function must be protected against misconfigured or unauthorized invocations. Which HTTP header should you allow through the CDN to support the function protection?
- An application stores multiple documents per username and must support updating multiple documents for the same username in a single ACID transaction. How should you configure Azure Cosmos DB to meet this requirement?
- An ASP.NET application instrumented with the Application Insights SDK sends a large burst of telemetry, causing ingestion errors and dropped events. You must reduce telemetry volume and costs while keeping statistically valid telemetry and preserving client-server correlation. What action should you take?
- An ASP.NET application using the Application Insights SDK sends very high telemetry rates and experiences ingestion throttling. To lower telemetry volume and keep correct correlation while controlling per-second throughput, what should you do?
- An ASP.NET Core app connects to Azure Database for MySQL, but connections fail intermittently and the code doesn't handle transient failures. Which three approaches can you use in code to implement retry handling for transient connection errors? (Each correct answer is part of the solution.)
- An ASP.NET Core app in Azure App Service requires custom claims from Microsoft Entra ID in the user access token. The claims should be removed automatically if the app registration is deleted. How should you include the custom claims in the access token?
- An ASP.NET Core app uses Azure App Configuration with 100 settings. You must ensure all configuration values remain consistent when individual settings change, support dynamic updates without restarting the app, and reduce calls to the App Configuration APIs. Which two steps help implement dynamic configuration updates?
- An ASP.NET Core app with the Application Insights SDK is producing bursts of telemetry that cause ingestion errors. You need to reduce telemetry volume and costs while ensuring HTTP request/response correlation remains possible. Which approach should you use?
- An Azure Cosmos DB account is configured with session consistency. An application (App1) will have multiple nodes that must share the same session token so reads and writes participate in the same session. Which SDK object should you use to store and share the session token between nodes?
- An Azure Cosmos DB deployment must update its index whenever items are created, updated, or deleted. Which setting ensures the index is updated immediately on write operations?
- An Azure Function needs to call external APIs using an access token stored as a secret named 'token' in an Azure Key Vault named 'mykeyvault'. What value should you place in the Azure Function App configuration to reference that secret?
- An Azure Function triggered by a Storage queue connects to an Azure SQL Database and is throwing System.InvalidOperationException: timeout acquiring connection from the pool (max pool size reached). What should you change to prevent this exception?
- An inventory tracking solution needs Cosmos DB settings so reads return the most recent committed version of an item and writes provide ordering guarantees. Which consistency level should you choose?
- An organization runs web apps in Azure and uses Azure Monitor. You discover that some web apps had configuration changes. Which Azure Monitor log should you inspect to find those configuration changes?
- Blobs are protected with version-level immutability, time-based retention policies (AllowProtectedAppendWrites enabled), and legal hold policies. You want to prevent users from attempting operations that would only fail when a legal hold is active (but all other policies have expired). Which two operations should you block in the application?
- Designing an Azure Cosmos DB (SQL API) container that will hold millions of documents, each with many properties and no single property that provides a clear partitioning key. To evenly distribute traffic across partitions over time, which two partition key approaches are acceptable?
- Each department in your company has its own Service Bus queue in the same namespace. Compliance requires that every message be automatically forwarded to a central audit topic without writing custom code. What should you configure?
- How can you audit retail store sales transactions? Choose two complete approaches.
- How can you reduce read latency for the retail store solution? Select two complete solutions.
- How should you address the log capacity issue for the function app?
- How should you fix the RequestUserApproval Function app error?
- How should you inspect the Azure Function app error in the development environment?
- In a microservices-based e-commerce system you need a messaging backplane for transactional messages between components. Messages must be delivered in first-in, first-out (FIFO) order. Which Azure service should you select?
- In subscription Sub1 you created a custom Event Grid topic Topic1 and an event subscription EventSub1 that uses Topic1 as the source and a Web Hook as the endpoint. You plan to enable dead-lettering for EventSub1. What must you do first to enable dead-lettering?
- Multiple applications currently use storage account access keys for blob access. You must rotate keys with zero downtime and begin moving apps to Azure AD–based authorization. What should you do?
- Multiple producer services publish Avro-encoded events to Azure Event Hubs. You need to validate payloads and evolve schemas without breaking existing consumers. Producers and consumers should automatically fetch and apply schema versions at runtime. What should you implement?
- Scenario: Same streaming web app with CI/CD, requiring high availability, consistent streaming, and data stored near users. Solution: Add an Azure Content Delivery Network (CDN) to the design. Does this solution meet the requirements?
- Scenario: Same streaming web app with CI/CD, requiring high availability, consistent streaming, and data stored near users. Solution: Add a Storage Area Network (SAN) to the design. Does this solution meet the requirements?
- Scenario: You are building a public-facing API whose backend is hosted in an Azure App Service and exposes a RESTful service. You must configure backend authentication for the API Management instance. Solution: Configure Basic gateway credentials for the Azure resource. Does this solution meet the requirement?
- Scenario: You are configuring a web application that streams video and uses continuous integration/deployment. You need the app to be highly available, provide a consistent streaming experience, and store data in regions closest to users. Solution: Add Azure Redis Cache to the design. Does this solution meet the requirements?
- Several App Services currently use APPINSIGHTS_INSTRUMENTATIONKEY. You plan to migrate to connection strings so you can target regional ingestion endpoints and support failover to a secondary Application Insights resource in another region without code redeploys. What should you do?
- Several legacy VMs use unmanaged disks stored in Standard_LRS storage accounts and are hitting storage account IOPS limits. A new database workload requires predictable high performance on data disks. You want to eliminate storage account throttling risk and meet the performance needs. What should you do?
- To address the retail store location data issue, which three Azure Blob features should you enable? Each correct answer is part of the solution.
- To authenticate a user to the corporate website according to the architecture, which two values should be used? (Choose two.)
- To diagnose the order workflow, which two actions should you take? Each correct answer is part of the solution.
- To ensure every message from Azure Event Grid is processed, which option should you choose?
- To fix the notification latency problem, which two steps should you perform? Each correct answer is part of the solution.
- To read data from the user claim object in the e-commerce web app, what should you do first?
- To secure the Shipping Logic App in the architecture, which of the following should you use?
- Using the Azure SDK for .NET, you need a simple way to retrieve an approximate count of messages in a queue named queue1. Which method requires the least development effort to get that approximate number?
- Virtual machines run code that needs access to resources in an Azure resource group. You granted the VM a system-assigned managed identity in Resource Manager. To obtain an access token that uses the VM's managed identity, which two actions should you take? (Each correct answer is part of the solution.)
- What change will resolve the capacity problem in the Azure Function processing loop?
- What should you use to prevent concurrency conflicts during receipt processing with blobs?
- What two changes should you make to configure the ContentUploadService deployment? Each correct answer is part of the solution.
- When creating an Azure Key Vault with PowerShell, deleted objects must be retained for 90 days. Which two parameters must you set together to enforce this retention? (Choose two.)
- When deploying multiple VMs in a single Availability Set via an ARM template, you want to maximize how many VMs remain available during a host-level (fabric) failure. What value should you set for the platformFaultDomainCount property?
- When deploying multiple VMs in one Availability Set using an ARM template, you want to ensure the template allows the greatest number of VMs to remain available during maintenance events. What value should you configure for the platformUpdateDomainCount property?
- When implementing a permission classification for applications that integrate with a Microsoft Entra tenant, which type of permissions should be included?
- When using the Azure Cosmos DB .NET SDK v3 for NoSQL you get a “413 Entity too large” error while uploading a set of files. Based on that error, which of the provided file sets can be uploaded to the Azure Cosmos DB for NoSQL container?
- Where should completed user agreements be stored?
- Which Application Insights data type should you use to satisfy the scaling telemetry requirement for Policy Service?
- Which az CLI command should you use to create the required alert for ContentUploadService?
- Which command should you run first to inspect the containerized ContentUploadService http server logs?
- Which component should you use to meet the Shipping Logic App requirements?
- Which hosting model satisfies the security and cost requirements for deploying the CheckUserContent Azure Function?
- Which permission string should be added at line CS07 of ConfigureSSE.ps1 to meet the security policy?
- You added REST endpoints (secured by SSL) to an Azure Function app running in a Consumption plan. You need to alert when any endpoint is unavailable or slow. What should you implement to monitor availability and responsiveness?
- You administer an Azure SQL Database that supports Azure AD authentication. You must enable database developers to connect with Microsoft SQL Server Management Studio (SSMS) using their on-premises Active Directory credentials, while minimizing sign-in prompts. Which option should you implement?
- You are a developer and must update the definitions for an existing Logic App. Which of the following should you use to update the Logic App definition?
- You are building a Cosmos DB solution deployed to multiple Azure regions. Requirements: read operations must never observe writes out of order, and you want to maximize read concurrency in all regions. Which Cosmos DB consistency level satisfies these requirements?
- You are building a cross-platform live dashboard that requires low-latency, bidirectional, real-time messaging over WebSocket. Clients must be able to join groups and the backend should scale without sticky sessions or custom WebSocket server management. What should you implement?
- You are building a Durable Functions workflow that receives a list of 50,000 image URLs and must extract EXIF metadata for each image in parallel, then return a single aggregated list. The orchestrator must remain deterministic and be able to resume correctly after replays or restarts. What should you do in the orchestrator function to implement the fan-out/fan-in pattern?
- You are building a Java app that stores sensitive data in Azure Cosmos DB and want to configure Always Encrypted so the application encrypts data. What is the first step you should take?
- You are building a Java app that uses Cassandra (via the Cassandra API) on a new Azure Cosmos DB resource. You create an Azure AD group named Cosmos DB Creators to allow provisioning of Cosmos DB accounts, databases, and containers, but members must not be able to access the database keys. Which RBAC role should you assign to restrict the group's access appropriately?
- You are building a Microsoft Entra ID–integrated app that calls Microsoft Graph and must accept future unknown enumeration members (support evolvable enumerations) on GET operations. Which HTTP request header enables that behavior?
- You are building a multi-tenant Web API secured by Azure AD. The API must authorize users based on roles (for user-delegated access) and also allow background services to call it with app-only permissions using roles. Tokens should carry role claims that your API can evaluate. What should you implement?
- You are building a premium-tier Azure Event Hubs solution to track road toll events. Each road requires its own throttling policy. How should you configure the event hub to allow per-road throttling?
- You are building a public API whose backend is hosted in an Azure App Service and exposes a REST API. You must configure backend authentication for an API Management instance. Solution: configure client certificate gateway credentials for the Azure resource. Does this solution achieve the requirement?
- You are building a public API whose backend is hosted in an Azure App Service and exposes a REST API. You must configure backend authentication for an API Management instance. Solution: configure client certificate gateway credentials for the HTTP(s) endpoint. Does this solution achieve the requirement?
- You are building a public API whose backend is hosted in an Azure App Service and exposes a REST API. You must configure backend authentication for an API Management instance. Solution: configure Basic gateway credentials for the HTTP(s) endpoint. Does this solution achieve the requirement?
- You are building a solution that uses a multi-partition Azure Cosmos DB database and the latest Cosmos DB SDK. Requirements: send insert and update operations to Azure Blob Storage, process changes from all partitions immediately, and allow parallel processing of change handling. Which two approaches will let you process the Cosmos DB operations? (Each correct answer is a complete solution.)
- You are building a stock inventory system that must maintain a per-item count with high concurrency and guarantee that updates for the same item are serialized. Multiple clients will increment and decrement inventory and occasionally read the current count. Which two actions should you take using Durable Functions?
- You are building an application that moves data between on-premises file servers and Azure Blob Storage. The app stores keys, secrets, and certificates in Azure Key Vault and calls the Key Vault APIs. You want to ensure accidental deletion of a key vault or its objects can be recovered for 90 days after deletion. What should you do?
- You are building an Azure Durable Function that orchestrates an online ordering workflow and must call an external API to obtain product discount data. Which Durable Function types should you use?
- You are building an Azure Function App to process images uploaded to Blob storage. Images must be handled as quickly as possible with minimal latency. How should you configure the Function App and trigger?
- You are building an e-commerce web app and plan to use Azure Key Vault so App Service authentication with Azure AD secures sign-ins. What should you enable on the e-Commerce Web App to allow it to access Key Vault securely?
- You are building multiple APIs hosted in Azure API Management and must examine how APIM processes requests, including calls made from REST clients. The inspection must show: the requests APIM forwarded to the backend and the responses received, the policies applied to responses before returning to the caller, any errors and the policies applied to them, and the original caller requests and the policies applied to those requests. What three steps should you perform? (Choose three.)
- You are configuring Azure Front Door (Standard/Premium) with two origins: East US and West Europe. You want both origins active, client requests to prefer the lowest latency origin, and unhealthy origins automatically removed from rotation. Each origin exposes an HTTPS /healthz endpoint that returns 200 when healthy. How should you configure the origin group?
- You are creating a .NET Core MVC application that uses Azure Cognitive Search to find holiday accommodations by multiple criteria, including a price range and proximity to an airport. Which property of the SearchParameters class should you set to restrict results by price and distance?
- You are deploying a one-off data processing job to Azure Container Instances. The container should run to completion. If the process exits with code 0, it should not restart. If it fails with a non-zero exit code, it should automatically restart to retry. Which restart policy should you set?
- You are deploying an Orders microservice to Azure Container Apps. You need to send 10% of external HTTP traffic to a new v2 revision while keeping 90% on v1. You also want your microservices to share the same VNet integration and Log Analytics workspace. What should you do?
- You are deploying multiple microservices to Azure Container Apps with external HTTP ingress enabled. The services must share the same virtual network and send logs to the same Log Analytics workspace. How should you deploy them?
- You are designing a solution that uses Azure messaging. The system must follow a publish–subscribe pattern and avoid continuous polling. Which two choices accomplish this? (Each correct answer is a complete solution.)
- You are designing an order-processing workflow on Azure Service Bus. All messages for the same OrderID must be processed in strict FIFO order, and you need to maintain per-order state across messages to track the workflow stage. What should you do?
- You are developing a .NET Core MVC app that lets customers search listings for independent holiday accommodations using Azure Search. You need to allow customers to run searches using regular expressions. What should you configure?
- You are developing an Azure App Service REST API that will be called by an App Service web app. The API needs to read and update user profile data in Azure AD. Which two components should you use to implement this functionality? (Pick two.)
- You are developing microservices running on Azure Container Apps with external TCP ingress enabled. The company requires scaling the services based on an Azure Event Hub trigger using a custom KEDA scaling rule. Which two KEDA trigger fields are required? (Choose two.)
- You are implementing a data lake for analytics and must restrict a group named DataScientists to read-only access on the path /raw/sales within a single container. They must not see data in other folders. New files under /raw/sales should inherit the same permissions. What should you do?
- You are implementing Azure AD B2C for a consumer-facing app. Requirements: integrate a corporate SAML identity provider (IdP), enrich tokens with attributes from your REST API during sign-in, and enforce MFA only when users sign in via the corporate IdP. What should you do?
- You are implementing several APIs in Azure API Management with these requirements: all APIs require a subscription key, subscribers must accept terms of use, administrators must approve or reject subscription requests, and you must limit multiple simultaneous subscriptions. What should you implement?
- You are implementing user identification for a web app that uses the Microsoft identity platform. Which claim type should you use to uniquely identify a user?
- You are instrumenting an e-commerce site with Application Insights. You must: 1) record when a user clicks AddToCart with the productId and userTier, 2) track the numeric basketValue at checkout for custom alerting, and 3) measure calls to an external payment gateway including latency and success/failure. Which telemetry calls should you add?
- You are onboarding api.contoso.com as a custom domain on an Azure CDN Standard (Microsoft) endpoint. Corporate security requires using a certificate issued by your approved CA and managing the private key lifecycle in Azure Key Vault, including manual rotation on your schedule. What should you configure for HTTPS on the custom domain?
- You are preparing to host a website in Azure that will receive high traffic after launch. You must keep it available and responsive while minimizing cost. How should you deploy the site?
- You are recording purchase events from 100 retailers into Azure Event Hubs for a loyalty program. Each retailer has a unique identifier and can be added or removed at any time. Retailers must only be allowed to record events for themselves. How should you enable retailers to submit sales events securely?
- You are securing several APIs hosted in Azure API Management and need to hide backend implementation details and technology stack across all APIs. Which policy and scope should you apply?
- You are selecting a messaging tier for Azure Service Bus. Requirements: sustained low-latency with dedicated capacity, support for VNET integration via private endpoints, and messages up to 60 MB. Which option should you choose?
- You are starting a new HTTP API project on .NET 8 with Azure Functions. You need full control over the .NET hosting pipeline, the ability to add custom middleware for request/response logging, and isolation from the Functions runtime so you can adopt new .NET versions independently. What hosting model and setup should you choose?
- You are writing a .NET Azure Function that validates Azure AD JWT access tokens for your custom API. The API is single-tenant and uses the v2.0 endpoint. Which validations should you implement to ensure tokens are accepted only if issued for your API by your tenant and are not expired or tampered with? Select three answers.
- You cache player positions in Azure Cache for Redis and prioritize players based on how recently they moved; players who log out must not be prioritized. Which eviction policy should you select?
- You created a Standard availability test in Application Insights (AI1) pointing to an App Service (App1). To ensure failed test runs send email notifications to the subscription owners, what must you do?
- You customized the APIM developer portal by editing pages and adding a custom theme. Developers should be able to self-register and subscribe to a public product from the portal without admin approval. After your edits, anonymous visitors still see the old portal. What should you do? (Choose two)
- You deploy a GPU-accelerated Python rendering app to an Azure Container Instance (ACI) Linux container. The app requires a secret value at container start, and the secret must be accessible only from inside the container. Which two methods will satisfy this requirement? (Each correct answer is a complete solution.)
- You deploy a Node.js app on Linux App Service using the built-in runtime. Before the app starts, you must run database migrations, then launch the app with a custom command. How should you configure startup so this sequence runs on every app start?
- You deploy an Azure Cosmos DB SQL API account in two write regions. For the Profiles container, if concurrent updates occur, the most recent change (by a timestamp property) should win. For the Orders container, on conflict you must automatically merge line items rather than losing an update. What should you configure?
- You deployed a Logic App that invokes an Azure Function (with an OpenAPI definition) which accesses an Azure Blob storage account. All resources are protected by Azure AD. The Logic App must securely access the Blob storage, and any Azure AD identities should persist even if the Logic App is deleted. Which option should you choose?
- You deployed a new Azure App Service web app that must use Azure Active Directory for user authentication and authorization. What is the first configuration step you should take?
- You deployed a stateful ASP.NET Core web app (PolicyApp) to an App Service that reacts to Azure Event Grid events. Requirements: all authentication events (sign-ins and sign-outs) must be handled by PolicyApp, and sign-outs must be processed as quickly as possible. What should you implement?
- You deployed a web app on Azure App Service (Basic plan, single region). Users report slow responses. You need to capture complete call stacks correlated across instances to diagnose performance, while minimizing cost and user impact. Which three actions should you take?
- You deployed an Azure App Service web app and registered it in both Azure AD and Twitter. The app authenticates users, requires SSL, and uses Twitter as the identity provider. To validate the Azure AD request in your application code, which element should you validate?
- You deployed an Azure App Service web app named App1 and created an Azure Key Vault named Vault1 containing API keys, passwords, certificates, and keys. You must grant App1 access to Vault1, support automatic credential rotation, and avoid storing credentials in code. What should you do?
- You deployed an Azure App Service web app, enabled Always On and the Application Insights site extension, then deployed a code update that produced many failed requests and exceptions. Which Application Insights tool lets you validate performance and failure counts in near real time?
- You design a hazard notification system where a central signaling server publishes alarm messages to Azure Service Bus. Each alarm controller receives messages in a transaction and every transaction must be audited including which alarm type fired. To implement a reply-trail audit, which two actions should you take?
- You enabled Application Insights for a deployed App Service web app that is throwing many exceptions. To inspect the code state and variable values at the moment exceptions occur, which Application Insights feature should you enable?
- You expose a back-end web service through Azure API Management. The back-end enforces HSTS and requires every request to include a valid HTTP Authorization header. Which two API Management authentication policies can you apply to supply credentials to the back-end? (Pick two.)
- You have 100 Azure VMs with system-assigned managed identities enabled and need to obtain each identity's objectId value. Which command should you run?
- You have a B2B web app that uses Azure AD B2B collaboration. Trial users can sign up with any email; when a trial user becomes a paying customer they must keep their data but switch to federated authentication. Which Microsoft Graph parameter is used to change a user's authentication from one-time passcodes to federation?
- You have a Linux container-based console application that uploads images from customer sites worldwide to be processed via the Azure Blobs API by a backend on Azure VMs. You cannot modify the application, and some sites only have phone-based internet connections. Which technology should you use to enable the console app to access the blobs?
- You have a microservice on Azure Container Apps with external HTTP ingress. Updates to the service must not cause downtime. Which deployment configuration should you use to update the service?
- You have a new Azure subscription and are building an internal site that uses Azure AD for authentication. You must implement multifactor authentication (MFA) for the site. Which two actions are required? (Each correct answer is part of the solution.)
- You have a Service Bus–triggered Azure Function that calls a throttled downstream API. On transient failures, you want up to 5 retries using exponential backoff with delays from 2 seconds to 1 minute. After retries, the message should be dead-lettered by Service Bus. How should you configure retries?
- You have a single-page application (SPA) that calls an Azure App Service Web API (API A). API A must call a downstream API (API B) on behalf of the signed-in user and enforce the user’s permissions in API B. API B already exposes scopes in its app registration. You need to preserve the user’s identity when calling API B and avoid granting API A broad application permissions. Which two actions should you perform?
- You have a Standard-tier Azure Cache for Redis (redis1) with default settings and need to adjust the Maxmemory policy so more memory is available for serving reads. How should you change the maxmemory-reserved configuration?
- You have a web app (contoso.azurewebsites.net) protected by Azure WAF. All traffic is routed through a shared Azure Application Gateway and must use SSL. What two steps should you perform to configure the Application Gateway for this App Service?
- You have a Web App on a D1 App Service plan. During peak traffic page load times increase. You want automatic scaling when CPU usage exceeds 80% and to keep costs low. What should you do first?
- You have a web app, WebApp1, and you want a triggered App Service background task that runs your code whenever new items arrive in a queue. Which of the following services should you use to implement this behavior?
- You have a Windows App Service in West Europe that must access two back-end networks: (A) an Azure SQL Database private endpoint in a VNet also in West Europe, and (B) an application server in a VNet located in North Europe that can be reached only via that VNet’s VPN gateway. The app should not require inbound connectivity from those VNets. What VNet integration approach should you use for each back end?
- You have an API Management (Standard) instance using a managed gateway and plan to publish API1 whose backend database enforces a strict requests-per-minute limit. Which APIM policy should you apply to API1 to minimize the chance that requests from a specific IP address exceed the backend's per-minute limit?
- You have an ASP.NET Core web app using Microsoft.Identity.Web to sign in users and acquire tokens to call a downstream API. The app runs on multiple App Service instances behind a load balancer and frequently scales out. Users are prompted to sign in more often than expected, and AcquireToken calls are hitting the network frequently after scale events. What should you implement to improve token reuse across instances? Choose two.
- You have an Azure Cosmos DB SQL API container partitioned by /customerId. When an order is placed, your service must atomically: (1) create the order document, (2) update the customer profile’s openOrderCount, and (3) delete the customer’s cart document. All three documents share the same customerId value. You want all operations to succeed or fail together without using server-side stored procedures. What should you do?
- You have an Azure Event Grid system topic that delivers events to an HTTPS endpoint on an Azure Function. Occasionally the endpoint is throttled, and events are dropped. You must (1) capture undeliverable events for later inspection in a blob container and (2) reduce unnecessary retries when the endpoint is unhealthy. What should you do?
- You have an Azure Key Vault kv1 (Standard SKU) and will programmatically store an asymmetric key pair there for encryption/decryption. Which client object should your application use to retrieve the key pair from the vault?
- You have an Azure Queue Storage queue named queue1 and need to implement an operation that sets the visibility timeout for individual messages. Which two operations can accomplish this? (Choose two.)
- You have an Azure Web App and multiple Azure Function apps that need to load secrets (connection strings, certificates) from Azure Key Vault. Secrets must not be stored in app code or environment, and you want to minimize changes in Azure AD. What approach should you use for accessing Key Vault from the apps?
- You have microservices on an AKS cluster that use Cosmos DB and Blob storage protected with customer-managed keys in Azure Key Vault. Keys must rotate automatically every three months, allow manual rotation, and send notifications before keys expire. Which two actions should you take to enable rotation and expiry notifications?
- You have two Hyper-V hosts, Host1 and Host2. Host1 contains an Azure VM named VM1 that was deployed from a custom ARM template. You must move VM1 from Host1 to Host2. What action should you take?
- You have two microservices in Azure Container Apps: service-a and service-b. You want service-a to call service-b without hardcoding IPs and to benefit from retries/timeouts. You also need to persist shopping cart state using a managed backend without writing storage SDK code. Which two actions should you take?
- You host a Function App on the Premium plan and must perform zero-downtime deployments. You already created a staging slot and plan to swap after validation. During validation in staging, no production Event Hub or Service Bus messages must be consumed. Which two configurations should you implement?
- You implement a Durable Functions workflow for expense approvals. The orchestrator must wait up to 48 hours for a manager’s approval, then proceed. If no approval is received within 48 hours, it must auto-reject and send a notification. The solution must be resilient to restarts and replays. What should you implement in the orchestrator?
- You implement Azure Durable Functions for a vehicle loan workflow that requires multiple steps in sequence and includes a credit-check step that can take several days. Which Durable Function type is appropriate for this workflow?
- You imported an OpenAPI definition into APIM that includes example responses. The backend is not yet available, but frontend teams must be able to call GET /orders and receive a 200 response with the documented example payload without invoking any backend. What should you configure?
- You ingest high-throughput telemetry into an Azure Event Hub and must automatically archive all incoming events to long-term storage with minimal operational overhead. The archive should be written directly by the service without running custom code. What should you configure?
- You ingest telemetry from 100,000 devices into an Azure Event Hub. You must preserve per-device message order while maintaining high throughput across multiple partitions. What should you do when sending events?
- You issued a user delegation SAS token for Azure Blob storage and it has been compromised. Which two actions can revoke or disable that SAS token? (Pick two.)
- You lock down a storage account to Selected networks. Requirements: (1) Allow access from your on-premises public IP ranges, (2) allow an Azure VM in a specific subnet to access the account, and (3) permit Azure Data Factory (a trusted Microsoft service) to continue operating. Which configuration meets all requirements?
- You maintain two APIM products: PublicAPI and InternalAPI. Requirements: PublicAPI should be discoverable by anyone in the developer portal and allow immediate self-service subscriptions; InternalAPI must only be visible to an Employees group and require manual approval for subscriptions. How should you configure product visibility and subscriptions? (Choose two)
- You manage 100 Azure virtual machines that have system-assigned managed identities. You must obtain the objectId value for each managed identity. Which command should you run?
- You manage a line-of-business app protected by Azure AD. Requirements: allow access only from devices marked as compliant when users are outside trusted corporate networks; block access when sign-in risk is High. You maintain an egress IP list for corporate offices and VPN. Which two configurations should you implement?
- You manage a read-heavy product catalog in Azure Cosmos DB SQL API. The app issues many identical read and query requests repeatedly. You can tolerate results up to 60 seconds stale to reduce RU costs and latency. Currently, clients use Direct mode. What should you do? (Select two)
- You manage an AKS cluster from an Azure AD–joined device and need to deploy MyApp using a provided Kubernetes YAML. You install the Docker client on the device and run docker run -it microsoft/azure-cli:0.10.17. Does this accomplish the deployment goal?
- You manage an AKS cluster from an Azure AD–joined machine. Developers packaged an application named MyApp into a container image and provided a Kubernetes YAML manifest. To deploy that manifest, you install the Azure CLI on the machine and run kubectl apply -f myapp.yaml. Will this deploy the application as intended?
- You manage an application that processes messages from an Azure Storage queue. Requirements: allow other applications access to the queue, be able to revoke access without regenerating storage account keys, and specify access at the queue level rather than the account level. Which SAS type meets these requirements?
- You manage an Azure API Management (APIM) instance and need to centralize two values for policies: (1) a non-secret base URL used by multiple APIs, and (2) a database password that rotates monthly. Security mandates that APIM must not store the password and that rotation should not require any policy changes. What should you do? (Choose two)
- You manage an Azure Cosmos DB SQL API container that stores event documents. By default, events must be deleted after 7 days. Certain audit events must be kept for 90 days, and a small set of documents must never expire. What should you configure to meet all requirements with minimal code?
- You manage many App Service apps, each linked to an Application Insights instance, and want to remove Classic availability tests via PowerShell. Which condition should replace $condition in: Get-AzApplicationInsightsWebTest | Where-Object { $condition } ?
- You manage TLS certificates for an Azure App Service. Certificates must be issued by DigiCert, auto-renew 30 days before expiration, and alert your operations team when renewal occurs. You will store and manage the certificates in Azure Key Vault. Which actions should you take? Select all that apply.
- You must centralize platform logs from several Azure Key Vaults. Requirements: 1) query logs with KQL, 2) retain raw logs for 7 years to meet regulatory needs, and 3) stream logs to a third-party SIEM via Event Hubs. You want to minimize the number of configuration objects. What should you configure on each Key Vault?
- You must give the inventory service development team access to retail store location data. Which method should you use to grant that access?
- You must migrate 200 million JSON documents into an existing Azure Cosmos DB SQL API container and perform upserts if documents already exist. The goal is to maximize throughput, handle throttling automatically, and minimize code changes in a .NET service. Which two actions should you take?
- You must protect a production Web App by configuring daily backups that include site content and a connected Azure SQL Database. Backups must be stored in your organization’s general-purpose v2 storage account in a specific container. What should you do?
- You must protect business-critical blobs so they cannot be modified or deleted for a customer-defined retention period, prevent overwrites and deletes, and support write-once/read-many behavior. Which two actions should you take on the storage account?
- You must provision a high-throughput NFS file share for a Linux-based HPC workload in Azure. The mount points must be accessible only from a specific VNet subnet. Which prerequisites and configurations are required?
- You must run a Timer-triggered function at 7:00 AM every Monday through Friday in Pacific Time, including daylight saving time adjustments. The Function App runs on Windows. How should you configure the schedule?
- You must test an ASP.NET web app using Application Insights to ensure it is available and responsive from multiple global locations at regular intervals, and alert support if it’s unresponsive. Which two test types are appropriate?
- You need a single public endpoint that routes requests to multiple backends without provisioning additional infrastructure. Requests to /v1/orders/* must be forwarded to a legacy API in another App Service, and /v1/images/* should be served from a Blob Storage static website. You must hide backend URLs, support simple path rewrites, and keep costs minimal. What should you do?
- You need an at-scale inventory of all public IP addresses and their DDoS protection state across all subscriptions in a management group. Results must be near real-time without first ingesting data into a Log Analytics workspace. What should you use?
- You need an Azure messaging solution that supports transactions, duplicate detection, and indefinite message retention. Which two technologies satisfy all requirements?
- You need detailed troubleshooting data from APIM into Log Analytics while controlling cost. Requirements: send gateway logs and request traces to a Log Analytics workspace; sample at approximately 50% of traffic; and temporarily include request/response bodies to diagnose issues. What should you configure? (Choose two)
- You need persistent shared storage for an AKS Deployment named reports that runs 6 replicas across multiple nodes. Each replica must be able to read and write the same files concurrently. Data must persist across pod restarts and be backed by an Azure-managed service. What should you configure?
- You need the APIM developer portal’s console to obtain tokens via OAuth 2.0 client credentials from Azure AD when testing calls to a secured backend. You will configure an OAuth 2.0 authorization server in APIM. Which settings are required? (Choose three)
- You need to asynchronously replicate only a subset of block blobs from a source storage account in region A to a destination account in region B, preserving version history and using prefix filters. What should you configure?
- You need to broadcast live pricing updates from your service to tens of thousands of connected clients. Clients that disconnect temporarily do not need to receive missed messages. Which approach should you use with Azure Cache for Redis?
- You need to connect to a globally distributed NoSQL database from .NET and create the object used to configure and execute database requests. Which code line should you use to create the client object?
- You need to connect to a globally distributed NoSQL database from .NET and create the object used to configure and execute requests against the database. Which code construct should you use?
- You need to copy all data from an existing Azure Storage account (many containers and large volumes) into a new storage account. The migration must be automated, require minimal user interaction, and be recoverable if interrupted. Which tool or approach should you use?
- You need to deliver an interactive, shareable view to an application team that combines: 1) metrics charts (CPU, requests), 2) KQL query results from Log Analytics, 3) parameters to select resource group and time range, and 4) the ability to export and version-control the artifact for deployment to other subscriptions. What should you build?
- You need to deploy two tightly coupled containers to Azure Container Instances: an API container and a sidecar that reads/writes shared data. The containers must share a lifecycle, have a single public IP/port, communicate over localhost, and share a persistent volume. What should you do?
- You need to expose a public RESTful news API (which has an OpenAPI/Swagger specification) through an Azure API Management instance. Which Azure PowerShell command imports the API specification into API Management?
- You need to make several small, non-breaking updates to an existing API hosted in APIM. Requirements: do not disrupt existing callers, be able to roll back changes if needed, provide documentation for developers about the changes, and allow testing prior to publishing. What should you do?
- You need to modify the workflows for an existing Logic App. Which tool should you use to edit them?
- You need to onboard thousands of IoT devices that publish and subscribe over MQTT using a cloud-native broker. Each device must be restricted to a topic subtree that includes its own device ID. You also want to define topic patterns once and apply them to all devices. What should you configure?
- You need to produce a report listing employees who are subject matter experts on specific topics and ensure administrators have full control and consent over the data. Which Microsoft technology should you use?
- You need to protect a critical container from accidental overwrites and deletes and be able to quickly recover a blob to a prior state while controlling storage costs. Which three actions or statements are correct?
- You need to secure Azure Functions to meet the security requirements. Which two actions should you take? (Choose two.)
- You operate a single APIM API that must route traffic to one of two regional backends based on the X-Region request header (values: eu or us). The backends are preconfigured in APIM with backend-ids orders-eu and orders-us. You must keep a single API surface and route dynamically per request. What should you do?
- You operate a Windows App Service hosting an ASP.NET Core app. During incidents, you need to tail application logs in real time. For compliance, you must also retain HTTP access logs for 30 days in Azure Storage. Long-term retention of application logs is not required. What should you configure?
- You operate an AKS cluster with a user node pool that runs a Deployment for an API. An HPA is already configured to scale the Deployment from 2 to 20 replicas based on CPU. During peak events, the HPA raises desired replicas, but several new pods remain Pending with the message 'Insufficient cpu'. You want the cluster to automatically add capacity so the pods can be scheduled without manual intervention. What should you do?
- You operate the same shopping-cart API in East US and West Europe. Each region must write to and read from a local Redis cache with very low latency. If the regions become temporarily isolated, writes should still be accepted in both regions and data should automatically converge when connectivity is restored. You also need automatic failover without promoting a read replica. What should you implement?
- You plan to add a new Azure Function with a Cosmos DB trigger to build a fresh analytics index from an existing container. The function must process all historical documents from the container exactly once and then continue with live changes. Other change feed processors already use an existing lease container. What should you configure for the new function?
- You plan to upload 1 million blobs and must assign key-value pairs to blobs so both keys and values are automatically indexed and searchable by the storage account’s native services. Which command should you run to set those tags?
- You plan to use Azure Cache for Redis and expect the cache to frequently reach capacity and require evictions. Access patterns show a small subset of items will be accessed far more often than others. Which two eviction policies should you choose to optimize performance for this pattern?
- You plan to use Azure Cosmos DB for storing application data that will be processed as batches of relational data. Which Cosmos DB API should you choose?
- You run a Deployment with 5 replicas for a critical API on AKS. You must ensure that at least 4 replicas remain available during planned disruptions such as node OS upgrades and during rolling updates of the Deployment. What should you configure?
- You run a Node.js app that uses the official MongoDB driver against MongoDB Atlas. You plan to move to Azure while keeping code changes minimal and minimizing downtime during migration. What should you do?
- You run a single Azure Container Registry (ACR) in East US on the Basic SKU. AKS clusters in East US and West Europe pull images from it, but image pulls in West Europe are slow and incur egress. You want a single login server name and automatic regional replication to minimize latency. What should you do?
- You run a Web App in Azure App Service with production and staging deployment slots. For routine CI/CD releases, the app should automatically promote the staging slot to production after the deployment completes and the app is warmed up. Occasionally during maintenance windows, you want to validate and warm up the staging slot with production settings, test it under production traffic mappings, and then decide whether to complete or cancel the swap. What should you do?
- You run a web app that uses Application Insights for monitoring and must alert operators when a technical fault is preventing camp sales. What type of alert should you create to detect these technical issues?
- You run an ASP.NET Core 6 API on Windows App Service with Application Insights auto-instrumentation enabled. You need code-level snapshots when exceptions occur, with minimal performance overhead and no code changes. What should you do?
- You run an Azure App Service with production and staging slots. The app reads secrets from Azure Key Vault using Key Vault references in app settings. You need both slots to use the same identity when accessing Key Vault so that slot swaps do not require Key Vault access changes. What should you do?
- You run Azure Cache for Redis Enterprise and want a worker to react when keys expire or are evicted due to memory pressure. The worker subscribes to __keyevent@0__:* channels. What configuration change is required to publish these events?
- You run Azure Functions processing Service Bus messages that can take up to 30 minutes per message and must access a SQL database over a private endpoint. Startup latency must be minimal during sudden bursts. Which hosting configuration should you choose?
- You set Azure Blob lifecycle to move objects to the archive tier after 30 days. Customers ask for an SLA for accessing data older than 30 days. What is the minimum recovery SLA you should document for retrieving archived blobs?
- You store globally distributed data in multiple Azure Blob Storage containers, enabled blob versioning and soft delete, and need the ability to restore blob data to a previous day for testing. How should you configure the storage account to support point-in-time restore?
- You use Azure AD–based role assignments for data-plane access to Azure Cosmos DB SQL API. A microservice must read and query items and execute stored procedures in a single container, but it must not create, update, or delete items. How should you grant access?
- You use Azure Cache for Redis Enterprise as a session store for a multi-tenant web app. The business requires that, after a node restart or failover, recovered data must lose no more than one second of writes while minimizing write latency overhead. Which persistence configuration should you use?
- You use Azure CDN Standard from Microsoft in front of a web app. Requirements: 1) Force HTTPS by redirecting all HTTP requests with a 301, and 2) Internally rewrite requests from /blog/... to /content/blog/... while preserving the remaining path and query string. How should you configure the Rules Engine?
- You use Azure CDN Standard from Verizon in front of an App Service. You want the CDN to compress text-based assets and dynamic JSON API responses to reduce bandwidth. Clients already send Accept-Encoding headers. Which two actions should you take?
- You use Azure Front Door to serve an ASP.NET Core site that provides CSV data files refreshed every 10 hours. You must purge specific files from the Front Door cache based on Response Header values. Which purge type should you use to remove individual assets?
- You use Azure Redis Cache to avoid reprocessing expensive image-analysis uploads. To minimize metadata loss during a regional outage, which two configuration actions should you perform on the Azure Redis instance?
- You want to publish a single GraphQL API in APIM. For inventory data, you already have a GraphQL backend and want APIM to proxy it. For orders, you only have REST endpoints and need to resolve GraphQL fields by calling those REST services and shaping the response. What should you do?
- You will deploy a website from GitHub to an Azure Web App and need to run a static content generation script before the site begins serving traffic. Which two approaches will ensure the script runs prior to serving? (Choose two.)
- You're building an Azure App Service web application that must securely persist session data in Azure Cache for Redis. To configure the web app to connect to the Redis instance, which three Redis properties are required?
- You're implementing the first subscriber application for an Azure Service Bus topic. The portal shows that messages arrive at the subscription, and you initialized a subscription client with correct parameters, but the app still isn't consuming messages. Which code snippet will ensure the subscription client processes incoming messages?
- Your .NET 7 web API uses Application Insights SDK on each microservice. During traffic spikes, ingestion costs rise rapidly and your team struggles to preserve end-to-end transaction diagnostics across services. You want telemetry volume to automatically scale down during spikes without changing Azure portal rules, while keeping request/exception counts accurate and maintaining distributed tracing correlation. What should you implement?
- Your AKS-hosted application needs a TLS certificate and a database password. The values must be sourced from Azure Key Vault at pod startup via a mounted volume rather than stored in etcd. For select environments, you also want these values available as Kubernetes Secrets for use as environment variables. What should you configure?
- Your APIM gateway forwards requests to a backend that intermittently returns 500 or 504. You must retry failed calls up to three times with a one-second delay, but only for those two status codes. Which policy configuration should you use?
- Your app uploads photos and videos to blob storage in account Account1. Containers are Container1 and Container2. Video uploads are infrequent. When a new video is uploaded, you need to copy specific blobs from Container1 to Container2. What should you implement?
- Your application must read ordered transaction logs of all changes to blobs and blob metadata (create, update, delete, copy only), retain them for compliance, and process the logs asynchronously. What should you do?
- Your application uses keys stored in Azure Key Vault and you must enforce a particular cryptographic algorithm and key size for keys placed in the vault. Which mechanism enforces these constraints?
- Your ASP.NET Core Web API uses Application Insights for telemetry and tracks dependencies to a non-SQL Server database. To enable proper dependency tracking for that database, which two dependency telemetry properties should you set?
- Your Azure Cosmos DB account uses the continuous backup (v2) policy. A bug corrupted a container 4 hours ago. You must recover the container’s state from 4 hours ago without overwriting the current data so you can compare and validate fixes. What should you do? (Select two)
- Your Azure Front Door (Standard/Premium) protects an app with a WAF policy using the managed rule set. After enabling WAF, legitimate GraphQL POST requests are blocked by a SQL injection rule inspecting the JSON body field named query. You must keep SQL injection protection for other requests and also rate limit the login endpoint to 100 requests per minute. What should you do?
- Your Azure subscription includes a Log Analytics workspace that collects security-related performance counters from 100 on-premises Windows servers. You need to create alert rules based on that data. Alerts must support dimensions, be quick to create, and generate a single notification when an alert fires and when it resolves. Which signal type should you use when creating the alerts?
- Your company hosts an Azure API that needs to authenticate to other Azure resources. Requirements: every API call must be authenticated, and API callers must not send credentials to the API. Which authentication mechanism meets these requirements?
- Your company runs an on-premises Kubernetes cluster and wants to enforce APIM policies close to backends to reduce latency. The network only allows outbound traffic to Azure over HTTPS. You must keep a single API surface in Azure while processing calls locally. What should you do?
- Your compliance team requires an ordered, durable history of blob create, modify, and delete events for all containers in a storage account, and your .NET worker must be able to resume processing from the last processed position after restarts. What should you implement?
- Your finance team writes audit logs as append blobs to a container named audit. Regulations require Write Once, Read Many (WORM) protection for six years, but the application must continue appending to the existing append blobs during the retention period. After initial testing, the policy must be enforced so it can’t be shortened. What should you configure to meet these requirements?
- Your Log Analytics workspace ingests 80–120 GB/day. You must retain data for 120 days, ensure no logs are dropped even on peak days, and reduce cost variability. Which configurations should you apply?
- Your organization runs MongoDB on-premises and has an Azure Cosmos DB account configured with the MongoDB API. You are planning the migration and currently include the Data Management Gateway tool in the plan. Evaluate that statement: which replacement makes it correct?
- Your production Key Vault stores secrets and keys used by multiple services. You must ensure that accidental deletion of secrets/keys can be recovered for a defined period and that no one can permanently delete them during that period, even subscription owners. What should you configure?
- Your Redis workload has outgrown a single node. You need to scale horizontally and still perform multi-key operations like MGET on related keys (for example, user and cart for the same customer). What should you do?
- Your retail app writes heavy OLTP traffic to Azure Cosmos DB. The analytics team wants near-real-time dashboards and ad hoc queries without impacting transactional throughput or building ETL pipelines. What should you do to enable this HTAP scenario?
- Your SaaS company exposes many web services and requires: access via API Management, OpenID Connect authentication, and no anonymous calls. A security audit found some services allow unauthenticated calls. Which API Management policy should you add to enforce OpenID Connect tokens and block anonymous requests?
- Your security team requires that apps run privately with no public inbound access and that all outbound traffic from the hosting environment use exactly one dedicated public IP that can be allowlisted on partner firewalls. You also need zone-redundant high availability. Which Azure App Service deployment option meets these requirements?
- Your SRE team manages an AKS cluster. They want node and pod performance metrics and container logs in a Log Analytics workspace. They also want to scrape custom Prometheus metrics from applications without running their own Prometheus, and visualize them in Grafana with Azure AD authentication. You want the least operational overhead. Which two actions should you take?
- Your team develops locally on Windows and runs CI pipelines in a Linux Docker environment. You need local Azure Cosmos DB development with secure connections and the ability to inspect partition key distribution to validate query patterns. What should you do? (Select three)
- Your team wants to standardize Azure infrastructure as code. Requirements: reduce verbosity vs ARM JSON, keep features like conditions, loops, outputs, and dependency management, and publish reusable building blocks for other teams. CI/CD should still produce ARM JSON artifacts transparently. What should you recommend?
- Your web app runs on multiple instances in Azure App Service. Occasionally, one instance becomes unresponsive. You want the platform to automatically detect an unhealthy instance and remove it from the load balancer, then replace it without manual intervention. What should you do?
- Your web app uses the Microsoft identity platform and calls REST APIs that require an access token. Which three application properties are required when requesting a token?
- Your web app uses the Microsoft identity platform to authenticate users and calls multiple REST APIs. One API must read the user's calendar and the app needs permission to send mail as the user. Which OAuth/OpenID Connect parameter should you request to obtain these permissions?
Microsoft Azure Fundamentals (AZ-900) Certification All exam questions
- A bank must comply with regional data storage laws while serving customers globally. Which cloud capability addresses this requirement?
- A biotech firm launches a service on Azure and is billed for compute time and data usage. Which pricing model is this?
- A biotech firm must meet strict data residency rules. Which Azure feature helps enforce this?
- A business continuity plan requires storage data to be replicated across regions. Which Azure storage option provides this capability?
- A business wants its mission-critical application to handle increased user traffic by adding more instances of its web server. Which cloud concept describes adding more instances of a resource?
- A CIO is comparing IaaS and PaaS. Which characteristic best distinguishes PaaS?
- A CIO is concerned that critical applications take too long to recover. Which cloud capability improves business continuity?
- A CIO wants a single pane of glass to manage governance across multiple tenants and subscriptions. Which Azure service enables this?
- A CIO wants an example of operational expenditure (OpEx) when moving to the cloud instead of capital expenditure (CapEx). Which is an OpEx example?
- A client's application must remain operational even if an entire Azure datacenter goes offline. What should they implement?
- A company adopts Azure to avoid buying new data center equipment. Which cloud computing benefit does this demonstrate?
- A company deployed a web app to Azure and manages user identities, permissions, and multi-factor authentication for app access. Under the Shared Responsibility Model, which customer responsibility does this represent?
- A company hosts its ERP system in Azure and needs controlled user access. Which Azure service should they use?
- A company is evaluating a cloud provider's continuous operation and built-in redundancy across multiple physical locations in a region to keep services accessible if a component or data center fails. Which benefit are they primarily considering?
- A company is moving data center applications to Azure Virtual Machines. Under the Shared Responsibility Model for Infrastructure as a Service (IaaS), who is primarily responsible for patching the guest virtual machine's operating system?
- A company migrating an on-premises application to Azure wants the app to remain accessible even if a single physical server or a small group of servers fails. Which cloud computing benefit primarily addresses this concern?
- A company needs a virtual machine to run a legacy application that requires custom OS configuration. Which cloud model is most appropriate?
- A company needs services to remain available even if a data center fails. What should they implement?
- A company needs to create a standardized environment that contains role assignments, policies, and ARM templates. Which Azure service should they use?
- A company needs to group Azure subscriptions by business unit and apply policies across those groups. Which Azure feature should they use?
- A company operating in multiple countries must meet data residency requirements. Which cloud capability supports this need?
- A company plans to lift-and-shift its legacy accounting application to the cloud but continue managing the operating system. Which service model should they choose?
- A company plans to move from an on-premises data center to Azure. The CTO wants to avoid large upfront capital spending and instead pay monthly based on resource use. Which cloud benefit does this best describe?
- A company requires a deployment model dedicated solely to them, hosted either on-premises or by a provider. Which model fits this requirement?
- A company runs its e-commerce platform in Azure but keeps HR systems on-premises. Which deployment model does this represent?
- A company uses cloud tools to respond quickly to changing market demands. Which cloud benefit enables that responsiveness?
- A company wants its applications to remain available during a regional outage. Which cloud characteristic should it prioritize?
- A company wants to chart performance trends and trigger alerts when CPU usage exceeds 80%. Which Azure service should they implement?
- A company wants to ensure its Azure subscriptions remain compliant with internal standards. Which service provides compliance tracking?
- A company wants to host a customer-facing app that requires high availability and automatic scaling. Which Azure service best meets this need?
- A company wants to run its application across both public and private clouds to keep sensitive data under their control. What is this deployment model called?
- A company's on-premises disaster recovery solution is expensive because it requires a separate fully equipped data center. They want to use the cloud to simplify and reduce DR costs. Which cloud computing benefit directly addresses this need?
- A consultant managing multiple client tenants needs centralized visibility and control. What should they implement?
- A consulting firm manages multiple clients' Azure environments and needs visibility and control without switching accounts. What is the best solution?
- A CTO is comparing cloud service models to balance control and responsibility and wants to manage only applications, not infrastructure. Which model is best?
- A CTO requires full control of the infrastructure layer when moving to the cloud. Which service model satisfies this requirement?
- A data analyst needs to visualize VM performance over time. Which Azure service supports this?
- A data analytics firm needs guaranteed availability for critical apps even if one data center fails. What should they look for from a cloud provider?
- A developer accidentally deleted a virtual machine. Which feature would help prevent accidental deletions?
- A developer creates a test environment and deletes it after testing. Which cloud benefit does this best demonstrate?
- A developer is automating daily shutdown and startup of non-production VMs to lower costs. Which tool should they use?
- A developer must securely manage application secrets and keys in Azure. Which service is designed for this?
- A developer needs a serverless compute option to run backend code in response to database updates. Which service should they use?
- A developer wants to know the main benefit of using the cloud for test environments. What is the primary advantage?
- A developer wants to run code in response to events without managing infrastructure. Which Azure service is best?
- A developer wants to test a new app version without affecting current users. Which deployment strategy in Azure App Service supports this?
- A development team does not want to handle patching or infrastructure and only wants to focus on writing code. Which cloud model fits?
- A development team must rapidly provision and de-provision virtual machines and databases for short-lived testing. Which cloud computing benefit best supports their ability to respond quickly?
- A development team needs to provision test environments without involving the IT department. Which cloud feature allows that?
- A development team needs to rapidly test a new feature in an environment that mirrors production. Which cloud benefit supports this requirement?
- A development team uses Azure services shared with other tenants, with logical isolation. What type of cloud is this?
- A development team wants to enable autoscaling to handle variable loads for their Azure-hosted application. Which component provides this capability?
- A development team wants to see dependencies between Azure resources in their application. Which tool provides that capability?
- A development team will deploy and then delete 50 customized virtual machines each week. Thirty VMs run Windows Server 2016 and twenty run Ubuntu Linux. Which Azure service should you recommend to minimize the administrative effort of deploying and removing these VMs?
- A development team will deploy and then remove 50 virtual machines each week. All VMs are configured with Azure Resource Manager templates. Which Azure service minimizes the administrative effort to deploy and remove these VMs?
- A DevOps engineer needs to deploy multiple Azure resources consistently across test and production environments. Which approach should they use?
- A DevOps team must create and destroy test environments rapidly. Which cloud concept provides that flexibility?
- A DevOps team needs to automatically detect and remediate noncompliant resources. Which Azure feature should they configure?
- A DevOps team rapidly deploys features and rolls back changes when necessary. Which cloud benefit enables this approach?
- A DevOps team will deploy virtual machines while managing networking, storage, and runtime. Which cloud service model does this describe?
- A finance company is moving sensitive data to the cloud. Under the Shared Responsibility Model, which security task is primarily the customer's responsibility regardless of IaaS, PaaS, or SaaS?
- A finance company runs virtual machines in Azure but manages the operating system and networking itself. Which cloud service model is this?
- A finance director needs to analyze Azure costs across multiple departments. Which service should they use?
- A finance startup wants to minimize upfront hardware investment and pay only for monthly usage. Which pricing model does this describe?
- A financial firm must restrict VM deployments to a single Azure region to meet regulatory requirements. Which service should they use?
- A financial firm wants to innovate faster without waiting for new hardware. Which cloud computing feature enables this?
- A financial institution uses cloud services hosted by third-party providers and accessed over the internet. Which deployment model describes this?
- A firm must keep customer data within specific countries to meet regulations. Which Azure capability enforces this?
- A global company needs to provide low-latency access to their Azure-hosted app for users in different countries. What should they deploy?
- A global company requires DNS name resolution within its virtual networks. Which service should they configure?
- A global e-commerce company uses both Azure and AWS for redundancy and to avoid dependence on a single vendor. What approach is this?
- A global enterprise must enforce data residency by restricting resources to specific Azure regions. Which tool should they use?
- A global enterprise needs its application to stay available if a single data center fails. Which cloud concept provides this?
- A global enterprise wants centralized management of user access and authentication across Azure services. Which feature should they implement?
- A global retailer deploys identical systems in multiple regions so customers get fast service no matter where they are. Which cloud concept is this?
- A government agency must retain full control over its cloud infrastructure because of data sovereignty laws. Which deployment model is most appropriate?
- A government agency needs a report of all resources with public IP addresses across subscriptions. Which service should they use?
- A government agency with strict security rules builds its own data center using cloud technologies. What deployment model is this?
- A healthcare app team wants to focus solely on writing application code and avoid managing servers. Which Azure offering should they choose?
- A healthcare company must ensure all storage accounts are encrypted. Which Azure governance feature enforces this across subscriptions?
- A healthcare organization must isolate traffic between Dev, Test, and Prod environments while staying under a single subscription. What should they implement?
- A healthcare provider keeps sensitive data on-premises but uses Azure services for extra capacity during peak periods. Which deployment model describes this setup?
- A healthcare provider wants to prevent deletion of critical Azure resources. What should they configure?
- A healthcare provider wants virtual machines to remain operational if one datacenter fails. What should they implement?
- A healthcare startup wants to avoid large upfront server purchases and instead rent infrastructure that can scale as patient demand grows. Which cloud benefit best fits this need?
- A healthcare startup wants to minimize upfront IT infrastructure costs while scaling quickly to meet HIPAA requirements. Which cloud benefit best fits this need?
- A hospital IT team needs virtual machines with full control over the operating system and networking. Which Azure compute option should they use?
- A hospital replaces aging infrastructure with cloud services but needs to keep control of patient data. Which deployment model is most suitable?
- A hospital system needs a centralized view of performance metrics and logs across all Azure services. Which tool should they use?
- A hospital wants the patient intake application to scale automatically with demand. Which Azure benefit supports that?
- A law firm uses Office 365 for email and document collaboration. Which cloud service model is this?
- A law firm wants to use Azure services but must keep some applications on-premises for compliance. Which cloud model is best?
- A logistics company must process millions of IoT sensor events in real time. Which Azure service is designed for that scenario?
- A logistics company must rapidly increase resources for peak seasons without overprovisioning year-round. Which cloud capability enables this?
- A logistics company wants to enforce tagging on all deployed resources. What should they implement?
- A logistics company wants to reduce disaster recovery time from days to minutes by using Azure. Which cloud concept supports this goal?
- A logistics firm needs to automate deploying identical virtual machines across multiple regions. Which Azure feature should they use?
- A manager wants a dashboard to visualize the health and performance of cloud resources. Which service should they use?
- A manufacturing company moving to the cloud must keep sensitive data on-premises to meet regulations. Which cloud deployment model should they choose?
- A manufacturing company plans to move its workloads from on-premises servers to Azure. Which term best describes this move?
- A marketing team needs to deploy a web application quickly without managing servers, operating systems, or middleware, and wants to focus only on the application code. Which cloud service type is most suitable?
- A media company must deploy services across continents to provide low latency to global users. Which cloud benefit enables this?
- A media company needs a global content delivery network to stream video to users with minimal latency. Which Azure service meets this need?
- A multinational business needs to deploy Azure resources in specific geographic locations to meet compliance. Which Azure concept applies?
- A multinational company needs to manage policies and compliance across several Azure subscriptions from a single location. Which service should they use?
- A non-profit must support seasonal events that cause short spikes in web traffic. Which cloud feature is most helpful?
- A nonprofit wants to avoid buying hardware and instead pay for compute as they use it. Which economic model are they choosing?
- A project lead worries about unexpected cloud charges. Which cloud principle helps prevent surprise billing?
- A project manager is comparing CapEx versus OpEx in the cloud. What is a primary characteristic of OpEx?
- A project manager wants to tag Azure resources by department and environment to simplify reporting. Which feature should they use?
- A research group needs to grant read-only access to a storage blob. What should they use?
- A retail company needs infrastructure that automatically scales up for holiday shopping peaks and scales down afterward. Which cloud benefit is most relevant?
- A retail company needs load-balanced traffic across multiple data centers within the same Azure region. Which solution should they implement?
- A retail company sees massive website traffic spikes during holiday sales and large drops afterward. They want to avoid over-provisioning hardware and only pay for resources used during peak demand. Which cloud computing benefit directly addresses this need?
- A retail startup wants to avoid buying costly servers but needs capacity that grows during seasonal spikes. Which cloud benefit applies?
- A retailer experiences fluctuating traffic during sales events. Which cloud feature should be used to handle the variable load?
- A retailer hosts applications in Azure but keeps its ERP system on-premises. Which deployment model is this?
- A retailer wants to distribute incoming traffic across multiple Azure web servers to improve performance during peak times. Which service should they use?
- A security administrator needs to detect and monitor suspicious activity across Azure workloads. Which service provides this capability?
- A small startup is considering the cloud to host a new application and wants to minimize upfront IT capital costs. Which financial model associated with cloud computing is most appealing?
- A software company needs to create and tear down development environments within minutes. Which cloud benefit is most relevant?
- A software company wants a fully managed platform for a web app that handles patching and scaling automatically. Which Azure service fits best?
- A software company wants to deliver its application globally with low latency. Which Azure service best achieves this?
- A software company wants to offer a productivity suite over the internet as a ready-to-use application so customers don't install or manage infrastructure. Which cloud service type represents this delivery model?
- A software team is deploying a web app and does not want to manage the underlying OS or hardware. Which Azure service model fits this use case?
- A startup chooses Azure to avoid buying servers and to scale as users grow. Which cloud characteristic describes this?
- A startup needs to deploy services quickly and scale with customer demand without managing hardware. Which cloud characteristic enables this?
- A startup plans to launch a web application without buying physical servers. Which cloud benefit does this illustrate?
- A startup wants a service model where they don't manage any infrastructure or applications. Which should they use?
- A startup wants to deploy a highly scalable web application without managing the underlying servers. Which Azure compute option should they choose?
- A startup wants to deploy a scalable container solution with minimal infrastructure management. Which Azure service should they choose?
- A startup wants to organize all resources for a new web app so they can manage and delete them together. What should they use?
- A startup’s cloud-hosted mobile app stays responsive during traffic spikes without manual intervention. Which feature explains this behavior?
- A streaming service runs workloads in both AWS and Azure. What is this strategy called?
- A support engineer will perform several Azure management tasks using the Azure CLI. You install the CLI on a computer. Which two tools should you tell the engineer to use to run the CLI? Each correct answer is a complete solution. NOTE: Each correct selection is worth one point.
- A team wants a model where the provider manages everything from servers to applications. Which service model should they choose?
- A team wants to apply the same set of policies, resource groups, and RBAC settings to new Azure subscriptions. Which service should they use?
- A technology company needs to deploy resources quickly in North America and Europe. Which Azure concept supports this requirement?
- A transportation app automatically scales compute resources as ride requests arrive in real time. Which cloud characteristic enables this behavior?
- A university needs to increase CPU and RAM on existing virtual servers without adding more servers. Which scaling approach describes this?
- A user accidentally deletes a critical virtual machine. Which Azure feature can prevent that action?
- A web agency used to buy all development servers, causing high upfront costs and idle capacity. After moving to the cloud, they pay monthly for VMs and storage. This represents a shift from which type of expenditure to which other type?
- An application sees heavy traffic during holidays and low traffic afterward. What capability should the architecture support?
- An application team wants to securely connect to VMs without exposing public IP addresses. Which service should they deploy?
- An auditor requests a complete history of changes to a storage account. Which Azure feature provides that information?
- An Azure administrator plans to run a PowerShell script that creates Azure resources. You need to recommend which computer configuration to use to run the script. Which three computers can run the script? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
- An Azure administrator will run a PowerShell script that creates Azure resources. Which three computer configurations can run the script? Each correct answer is a complete solution. NOTE: Each correct selection is worth one point.
- An Azure application uses the services shown in the table. How do you calculate the application's composite SLA?
- An e-commerce site requires both web hosting and a relational database in Azure. Which combination should they use?
- An educational institution wants to avoid buying hardware while providing students access to virtual labs. Which cloud advantage does this describe?
- An engineer needs recommendations to identify unused virtual machines to cut unnecessary costs. Which tool provides those recommendations?
- An enterprise requires a private, dedicated network link between its on-premises data center and Azure. What should they configure?
- An HR team uses Microsoft 365 for email, file storage, and collaboration. What type of cloud service is this?
- An insurance company needs customer data to remain available during regional outages. Which cloud feature should it prioritize?
- An IT director compares cloud costs to buying traditional servers. Which advantage does cloud computing offer?
- An IT manager explains that using cloud services aligns IT spending with actual usage and reduces costs during low demand. Which core financial principle of cloud computing is being described?
- An organization must separate development and production workloads and manage billing independently. Which Azure concept supports this scenario?
- An organization plans to improve disaster recovery by replicating services across data centers in different regions. Which cloud concept supports this approach?
- An organization plans to move its internal email system to a cloud solution and wants to avoid managing servers, patching OSs, and ensuring email server uptime. Which cloud service model best fits this goal?
- An organization provides resources hosted and managed by its IT team for internal departments in a dedicated environment. Which deployment model is this?
- An organization wants to automatically deploy resources that comply with internal standards. Which tool should they use?
- An organization wants to host a high-traffic web application that automatically scales based on demand. Which service best fits?
- App1 has low usage during the first three weeks of each month and very high usage during the last week. Which benefit of Azure Cloud Services helps manage costs for this usage pattern?
- At which layer of the OSI model does ExpressRoute operate?
- Azure App Service is an example of which cloud service model?
- Evaluate the underlined statement: "Azure Germany can be used by legal residents of Germany only." If the underlined text is correct, select No change is needed. If it is incorrect, choose the option that makes the statement correct.
- Evaluate the underlined statement: "One of the benefits of Azure SQL Data Warehouse is that high availability is built into the platform." If the statement is correct, select 'No change is needed'. If incorrect, choose the option that corrects it.
- Evaluate the underlined text for correctness: "From Azure Cloud Shell, you can track your company's regulatory standards and regulations, such as ISO 27001." If the text is correct, choose 'No change is needed.' If it is incorrect, choose the option that corrects it.
- Evaluate the underlined text to determine whether it is correct: "Resource groups provide organizations with the ability to manage the compliance of Azure resources across multiple subscriptions." If the statement is correct, select No change is needed. If it is incorrect, select the option that makes the statement correct.
- Evaluate the underlined text: 'If Microsoft plans to end support for an Azure service that does NOT have a successor service, Microsoft will provide notification at least 12 months before.' Instructions: Review the underlined text. If it makes the statement correct, select `No change is needed`. If the statement is incorrect, choose the answer that corrects it.
- Evaluate the underlined text: "A support plan solution that gives you best practice information, health status and notifications, and 24/7 access to billing information at the lowest possible cost is a Standard support plan." If the underlined text is correct, select `No change is needed`. If it is incorrect, select the option that makes the statement correct.
- Evaluate the underlined text: "Azure Key Vault is used to store secrets for Azure Active Directory (Azure AD) user accounts." If the underlined text is correct, select 'No change is needed'. If it is incorrect, choose the option that corrects the statement.
- Evaluate the underlined text: "The Azure Standard support plan is the lowest cost option to receive 24x7 access to support engineers by phone." If the underlined text is correct, select `No change is needed`. If it is incorrect, select the option that makes the statement correct.
- Evaluate the underlined text: "You can create an Azure support request from support.microsoft.com." If the underlined text is correct, select `No change is needed.` If it is incorrect, select the answer that makes the statement correct.
- How can a company limit developers so they can manage only virtual machines but not storage or networking resources in Azure?
- How can an administrator prevent accidental deletion of important Azure resources while still allowing modifications?
- How can an organization apply role-based restrictions to Azure subscriptions while managing billing access separately?
- How can an organization prevent users from accidentally deleting production resources?
- How does OpEx differ from CapEx in cloud spending?
- How does Premium SSD differ from Standard HDD in Azure Disk Storage?
- How many copies of data are stored in geo-zone-redundant storage (GZRS)?
- How many copies of data does an Azure Storage account keep when using geo-redundant storage (GRS)?
- How many copies of data does an Azure Storage account using locally-redundant storage (LRS) maintain?
- How should a healthcare organization enforce naming conventions and tags across all Azure resources?
- If a website runs on Azure App Service and needs routing based on HTTP request attributes, which Azure service should be added?
- In a hybrid cloud, what enables seamless movement of data and applications?
- In a software as a service (SaaS) model, which of the following does the customer provide?
- In an IaaS deployment, who is responsible for configuring a virtual machine's firewall?
- In Azure IaaS, who is responsible for applying guest OS updates on a VM?
- In Azure's organizational hierarchy, which level is directly above Subscriptions?
- In every PaaS offering, which responsibility does Microsoft retain?
- In RBAC, which element defines "what permissions" are granted?
- In the infrastructure as a service (IaaS) model, which two components are the responsibility of the cloud service provider? Each correct answer is a complete solution. NOTE: Each correct selection is worth one point.
- In which format are Azure Resource Manager (ARM) templates defined?
- In which location does Azure Monitor store event data?
- Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure subscription named Subscription1. You sign in to the Azure portal and create a resource group named RG1. From Azure documentation, you have the following command that creates a virtual machine named VM1: az vm create --resource-group RG1 --name VM1 --image UbuntuLTS --generate-ssh-keys. You need to create VM1 in Subscription1 by using that command. Solution: On a computer running Windows 10, install the Azure CLI. From a command prompt, sign in to Azure and run the command. Does this meet the goal?
- Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. An Azure administrator plans to run a PowerShell script that creates Azure resources. You need to recommend which computer configuration to use to run the script. Solution: Run the script from a computer that runs Windows 10 and has the Azure PowerShell module installed. Does this meet the goal?
- Note: This question is part of a series that presents the same scenario. Each question contains a unique solution that might meet the goals. Some sets may have more than one correct solution, and some may have none. After you answer a question in this section, you cannot return to it and it will not appear on the review screen. You have an Azure environment. You must create a new Azure virtual machine from a tablet running Android. Solution: You use PowerShell in Azure Cloud Shell. Does this meet the goal?
- Note: This question is part of a series that presents the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some sets might have more than one correct solution, while others might not have any correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. The company plans to purchase an Azure subscription. The company's support policy requires that the Azure environment provide a way to contact support engineers by phone or email. You need to recommend which support plan meets this requirement. Solution: Recommend a Professional Direct support plan. Does this meet the goal?
- Note: This question is part of a series that presents the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets may have more than one correct solution, while others may have no correct solution. After you answer a question in this section, you will NOT be able to return to it. These questions will not appear on the review screen. An Azure administrator plans to run a PowerShell script that creates Azure resources. You need to recommend which computer configuration to use to run the script. Solution: Run the script from a computer that runs Chrome OS and uses Azure Cloud Shell. Does this meet the goal?
- Note: This question is part of a series that presents the same scenario. Each question contains a unique solution that might meet the stated goals. Some sets may have more than one correct solution, while others might have none. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear on the review screen. Your Azure environment contains multiple virtual machines. You need to ensure that VM1 is accessible from the Internet over HTTP. Solution: You modify an Azure Traffic Manager profile. Does this meet the goal?
- Note: This question is part of a series that presents the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets may have more than one correct solution, while others may have no correct solution. After you answer a question in this section, you will NOT be able to return to it. These questions will not appear on the review screen. An Azure administrator plans to run a PowerShell script that creates Azure resources. You need to recommend which computer configuration to use to run the script. Solution: Run the script from a macOS computer that has PowerShell Core 6.0 installed. Does this meet the goal?
- Note: This question is part of a series that presents the same scenario. Each question in the series offers a unique solution that might meet the stated goals. Some sets might have more than one correct solution, while others might have none. After you answer a question in this section, you will NOT be able to return to it. These questions will not appear in the review screen. You plan to deploy several Azure virtual machines. You need to ensure the services running on the virtual machines remain available if a single data center fails. Solution: You deploy the virtual machines to two or more regions. Does this meet the goal?
- Note: This question is part of a series that presents the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets may have more than one correct solution, while others may have no correct solution. After you answer a question in this section, you will NOT be able to return to it. These questions will not appear on the review screen. You have an Azure environment. You need to create a new Azure virtual machine from a tablet that runs Android. Solution: Use Bash in Azure Cloud Shell. Does this meet the goal?
- Note: This question is part of a series that uses the same scenario. Each question presents a different solution that might or might not meet the stated goals. After you answer, you cannot return to the question. You plan to deploy several Azure virtual machines. You need to ensure the services on the virtual machines remain available if a single data center fails. Solution: You deploy the virtual machines to two or more resource groups. Does this meet the goal?
- Note: This question is part of a series that uses the same scenario. Each question presents a unique solution. After you answer, you cannot return. Your company has an Azure subscription with these unused resources: 20 user accounts in Azure Active Directory (Azure AD); five groups in Azure AD; 10 public IP addresses; and 10 network interfaces. You need to reduce the company's Azure costs. Solution: You remove the unused network interfaces. Does this meet the goal?
- Note: This question is part of a series that uses the same scenario. Each question in the series presents a different solution that may or may not meet the goals. After you answer, you cannot return to the question. Your company plans to migrate all data and resources to Azure and requires that only Platform as a Service (PaaS) solutions be used. You need to deploy an Azure environment that meets the migration requirement. Solution: You create Azure virtual machines, Azure SQL databases, and Azure Storage accounts. Does this meet the goal?
- Note: This question is part of a series. Each question presents the same scenario but a different solution. After you answer, you cannot return to this question. Your company plans to purchase an Azure subscription. Company policy requires the Azure environment to provide a way to contact support engineers by phone or email. You must recommend which support plan meets this requirement. Solution: Recommend a Standard support plan. Does this meet the goal?
- Several business units each require many identical Azure resources for daily operations. You must define a strategy to create those Azure resources automatically. Solution: Include management groups in the strategy. Does this solution meet the goal?
- Several business units each require many identical Azure resources for daily operations. You must define a strategy to create those Azure resources automatically. Solution: Include Azure Resource Manager templates in the strategy. Does this solution meet the goal?
- The company has 10 departments and plans to implement an Azure environment. You must ensure each department can use a different payment option for the Azure services it consumes. What should you create for each department?
- The company plans to migrate all virtual machines to an Azure pay-as-you-go subscription from Hyper-V hosts. Ensure the recommended Azure expenditure model is correct. The proposed solution is to use the elastic expenditure model. Does this solution meet the requirement?
- The company's Azure subscription currently has Basic support, and they want Microsoft to provide an assessment of their Azure environment design, which Basic does not include. To enable this while keeping costs minimal, you propose upgrading to the Professional Direct support plan. Does this solution meet the goal?
- To achieve high availability across multiple Azure data centers within the same region, which feature should a company deploy?
- To deploy a highly available e-commerce app that distributes load across multiple VMs, which Azure service manages incoming traffic?
- To enforce compliance automatically across all subscriptions, what should a security administrator apply at the management group level?
- To implement DevSecOps by adding policy checks into deployment pipelines, which should a DevOps engineer use?
- To manage multiple Azure subscriptions with a single set of access controls and policies, what should they implement first?
- To meet compliance requiring encryption on every deployed VM, which Azure feature should enforce this requirement?
- Under the SaaS shared-responsibility model, what does the customer mainly manage?
- What architecture pattern ensures a global application remains available if an entire Azure region becomes unavailable?
- What Azure construct should you use to group and isolate resources by workload or project?
- What Azure feature defines inbound and outbound network rules to restrict traffic to a specific virtual machine?
- What Azure feature enforces that only approved virtual machine types are used in an environment?
- What Azure solution should a development team use to automatically stop underutilized virtual machines outside business hours?
- What Azure structure enables unified governance across multiple subscriptions?
- What category of expenditure applies to purchasing on-premises servers?
- What deployment benefit do ARM templates provide?
- What design strategy keeps an application online during datacenter-level outages within a region?
- What does a Site-to-Site VPN do?
- What does the Secure Score in Microsoft Defender for Cloud represent?
- What effect does a "CanNotDelete" lock have?
- What feature provides fine-grained access control to specific resources for a development team?
- What is a correct distinction between IaaS and PaaS?
- What is a defining feature of Azure Functions?
- What is a key characteristic of the consumption-based pricing model?
- What is a primary advantage of disaster recovery in the cloud?
- What is a primary advantage of using the Azure CLI?
- What is a primary benefit of Azure Firewall?
- What is a primary disadvantage of using a private cloud model?
- What is a primary use case for Azure Virtual Machines?
- What is the best approach in Azure App Service to test a new app version without affecting end users?
- What is the best way to apply security policies consistently across multiple Azure subscriptions for a global enterprise?
- What is the main financial advantage of using cloud computing for organizations?
- What is the main purpose of Azure Blueprints?
- What is the main purpose of Azure Geographies?
- What is the maximum term you can purchase for Azure Reserved VM instances?
- What is the most likely cause when a user receives a "quota exceeded" error while creating a resource in a subscription?
- What is the primary purpose of the Azure Pricing Calculator?
- What kind of data does Azure Monitor Logs collect?
- What kind of data is Azure Blob Storage best suited for?
- What kind of interface is the Azure Portal?
- What provides a unified way to project and manage non-Azure resources in Azure Resource Manager (ARM)?
- What Service Level Agreement (SLA) applies to Azure services that are in public preview?
- What should a company use to let a consulting firm manage its Azure subscriptions without granting global admin rights?
- What should a company use to organize and manage Azure resources (such as VMs and storage accounts) for a specific project?
- What should a compliance officer use to evaluate how well Azure resources comply with organizational policies?
- What should a developer use to configure auto-healing and CPU-based scale-out actions for a web app?
- What should a developer use to ensure only authorized identities can deploy Azure resources?
- What should a finance team use to view and analyze logs and metrics from multiple resources in one place?
- What should a multinational company configure to ensure consistent governance, access control, and deployments across new subscriptions?
- What should a multinational company create to manage multiple subscriptions and apply consistent governance across them?
- What should a retail company configure to restrict administrative access to specific time windows?
- What should a team configure to send email alerts when virtual machine CPU usage exceeds 80%?
- What should an administrator enforce to prevent any public IP assignments on network interfaces?
- What should be implemented to restrict inbound traffic to specific IP address ranges?
- What type of redundancy do Azure Availability Zones provide?
- What types of items can Azure Information Protection encrypt?
- What unique capability does Azure Virtual Desktop offer?
- What's the best way to grant a team permission to only start and stop VMs in a specific resource group?
- When creating several managed Microsoft SQL Server instances in Azure, you receive a message that your subscription limits must be increased. What should you do to raise those limits?
- When designing a cloud solution, who is responsible for securing the physical data centers (buildings, gates, security personnel) under the Shared Responsibility Model?
- When should you choose Azure Container Instances (ACI) instead of AKS?
- Where can a project manager view the compliance status of Azure policies?
- Where should a CIO look to audit who modified an Azure resource and when the modification occurred?
- Where should an application connect to retrieve security tokens?
- Where should you acquire a third-party virtual security appliance to deploy into an Azure subscription?
- Where should you obtain a third-party virtual security appliance that you will deploy to an Azure subscription?
- Which additional resource is required for an Azure virtual machine?
- Which App Service feature enables a web app to scale automatically based on demand?
- Which App Service feature lets a developer push updates to a staging environment without affecting production?
- Which authentication method removes the use of passwords entirely?
- Which Azure AD feature lets users sign in once to access multiple applications?
- Which Azure capability can automatically remediate virtual machine assignments of public IP addresses?
- Which Azure compute service is designed for running parallel batch-processing jobs on demand?
- Which Azure compute service is ideal for event-driven tasks with no infrastructure to manage?
- Which Azure concept supports regulatory requirements for physical data isolation within a region?
- Which Azure construct allows an enterprise to group related resources (VMs, storage, networking) for lifecycle management?
- Which Azure construct allows policies and access controls to be inherited according to an organization's hierarchy?
- Which Azure construct ensures a production app is deployed identically across dev, test, and production environments?
- Which Azure construct lets you apply governance across multiple subscriptions?
- Which Azure construct should a lead architect use to group related resources for deployment, billing, and management?
- Which Azure database offers global, low-latency access with automatic multi-region replication for a mobile app?
- Which Azure DDoS tier offers custom mitigation policies and analytics?
- Which Azure feature can automate shutting down unused VMs to reduce costs?
- Which Azure feature can automatically block virtual machine deployments that violate the company's allowed-region policy?
- Which Azure feature could have prevented accidental deletion of critical resources?
- Which Azure feature enables publishing and deploying preconfigured virtual machine images for testing?
- Which Azure feature ensures all data is encrypted at rest?
- Which Azure feature ensures virtual machines are spread across multiple fault domains?
- Which Azure feature lets a CIO visualize spending trends and forecast future cloud expenses?
- Which Azure feature lets a team apply policies, RBAC assignments, and ARM templates together?
- Which Azure feature lets a university track and control resource costs per department?
- Which Azure feature lets an organization classify resources by department, environment, and cost center?
- Which Azure feature provides continuous data availability across multiple geographic locations?
- Which Azure feature provides high availability inside a single region?
- Which Azure feature provides personalized recommendations to reduce costs and improve performance?
- Which Azure feature should a security manager use to ensure only specific roles can deploy virtual machines?
- Which Azure governance feature can enforce resource tagging and restrict allowed virtual machine sizes?
- Which Azure governance service enforces tag naming conventions?
- Which Azure governance tool creates consistent deployment environments?
- Which Azure networking service enables secure VNet-to-VNet communication over the Microsoft backbone?
- Which Azure offering delivers a managed database with built-in high availability and automatic backups for a healthcare deployment?
- Which Azure offering provides a formal uptime guarantee for services?
- Which Azure option is best for a backend that must handle unpredictable workloads with minimal management?
- Which Azure product is best for a globally distributed NoSQL database with low-latency access for a fintech startup?
- Which Azure region type should a government agency use to meet strict isolation and compliance requirements?
- Which Azure security model lets a team assign permissions at the resource group level without affecting other users?
- Which Azure service best supports rapid deployment of consistent environments across multiple subscriptions?
- Which Azure service can restrict resource access based on a user's department and role?
- Which Azure service can route user traffic based on geographic location to optimize latency across regions?
- Which Azure service can you use as a security information and event management (SIEM) solution?
- Which Azure service enables a consultant to obtain cross-tenant, role-based access to multiple clients' Azure environments?
- Which Azure service enables repeatable infrastructure deployment with JSON templates?
- Which Azure service enables students to access virtual desktops from any device?
- Which Azure service enforces rules like "deny VMs in unsupported regions"?
- Which Azure service evaluates an environment and provides recommendations for best practices?
- Which Azure service helps deploy infrastructure that must meet compliance requirements using predefined templates?
- Which Azure service is best for creating a runbook to automate patching of virtual machines?
- Which Azure service is best for running cost-effective, short-lived background tasks triggered by events?
- Which Azure service is best for storing large volumes of unstructured data such as images and videos?
- Which Azure service is recommended for securely storing and managing secrets used in a CI/CD pipeline?
- Which Azure service lets a developer run containerized web apps without managing the underlying infrastructure?
- Which Azure service lets a financial company inspect and control HTTP(S) traffic to internal applications?
- Which Azure service manages user identities and offers SSO and MFA?
- Which Azure service model gives you the greatest control over infrastructure?
- Which Azure service offers a globally distributed, multi-model database with automatic failover and low-latency access?
- Which Azure service offers a managed file share that integrates with on-premises Windows servers?
- Which Azure service provides a centralized view of system health and performance across resources?
- Which Azure service provides a cloud-native, key-value store with sub-millisecond latency?
- Which Azure service provides a managed SQL relational database with minimal administration and built-in high availability for a finance company?
- Which Azure service provides a scalable message queue to decouple application components and handle traffic spikes?
- Which Azure service provides a secure global entry point that routes HTTP traffic to different Azure services?
- Which Azure service provides a security information and event management (SIEM) solution?
- Which Azure service provides a virtual firewall to control inbound and outbound traffic between subnets?
- Which Azure service provides alerts for configuration changes across Azure resources?
- Which Azure service provides automated deployment as part of a CI/CD pipeline using Azure-native tools?
- Which Azure service provides best-practice recommendations for cost and performance?
- Which Azure service provides container orchestration and scalable deployment for microservices?
- Which Azure service provides cost analysis, budgets, and spending alerts?
- Which Azure service provides custom dashboards to monitor the performance of multiple Azure services?
- Which Azure service provides dedicated physical servers for hosting sensitive patient data?
- Which Azure service provides fast content delivery to users around the world for a global retailer?
- Which Azure service provides monitoring of performance metrics and logs across resources?
- Which Azure service provides version control tools to manage source code?
- Which Azure service provides visibility into resource performance metrics and logs across multiple regions?
- Which Azure service securely stores secrets (API keys, connection strings) and restricts access to authorized applications?
- Which Azure service should a DevOps team use to apply infrastructure-as-code and automate version-controlled resource deployment?
- Which Azure service should a financial institution use to automatically apply a set of approved policies and role assignments when deploying resources to new subscriptions?
- Which Azure service should a financial services firm use to run containers and orchestrate their deployment at scale?
- Which Azure service should a security analyst use to store application secrets and enforce access policies?
- Which Azure service should a software company use to receive recommendations for cost savings and high availability?
- Which Azure service should an IT team use to define and enforce organization-wide standards for new resources?
- Which Azure service should host a legacy application that requires full operating system access and custom software installations?
- Which Azure service should you use so that Azure Active Directory (Azure AD) users who connect from the Internet using an anonymous IP address are automatically prompted to change their password?
- Which Azure service should you use to collect events from multiple resources into a centralized repository?
- Which Azure service should you use to store certificates?
- Which Azure service stores API keys, passwords, and certificates securely?
- Which Azure service supports CI/CD pipelines to automate building, testing, and deploying code to Azure?
- Which Azure solution gives you a secure, isolated virtual network environment for your workloads?
- Which Azure solution provides a platform-as-a-service hosting model with minimal management overhead for an application?
- Which Azure solution provides near-instant failover for mission-critical applications across different regions?
- Which Azure storage service provides file shares over SMB or NFS?
- Which Azure storage solution is best for securely storing unstructured log files from multiple applications?
- Which Azure storage tier is optimized for infrequently accessed data?
- Which Azure support plans allow you to open a new support request?
- Which Azure tool automates tasks such as stopping idle virtual machines to reduce costs?
- Which Azure tool can enforce that virtual machines are created only in the East US region?
- Which Azure tool helps a startup track and reduce cloud spending and assign budgets to individual departments?
- Which Azure tool lets you build no-code workflows that integrate Azure services and third-party APIs?
- Which Azure tool provides a centralized way to manage and deploy updates across multiple subscriptions and resource groups?
- Which Azure tool provides a real-time dashboard for monitoring application health and performance?
- Which Azure tool provides proactive recommendations to optimize cost, performance, and availability?
- Which Azure tool should a CIO use to display cost, performance, and compliance metrics on a single dashboard?
- Which Azure tool should the finance department use to gain visibility into cloud costs and to create budgets and spending thresholds?
- Which benefit helps organizations avoid wasting resources on idle infrastructure?
- Which built-in role should be assigned to give interns read-only access when defining RBAC policies?
- Which capability enables organizations to recover from a regional Azure outage?
- Which capability lets cloud customers add more VMs behind a load balancer as needed?
- Which characteristic enables a cloud service to adapt quickly to changing requirements?
- Which cloud benefit enables building, testing, and deploying an app in hours?
- Which cloud benefit enables companies to react quickly to changing market conditions?
- Which cloud capability allows a database to automatically scale during seasonal traffic spikes?
- Which cloud computing benefit ensures users have continuous access to a cloud-based application with minimal downtime?
- Which cloud computing benefit increases uptime by routing traffic around failures?
- Which cloud computing model includes both on-premises and cloud-based resources?
- Which cloud deployment model is best when an organization needs full control over sensitive workloads?
- Which cloud feature lets a developer deploy a test environment quickly with minimal configuration?
- Which cloud model has all hardware owned by a third party and shared among multiple tenants?
- Which cloud model is most appropriate for a highly regulated financial institution?
- Which cloud model is typically used to host a public-facing e-commerce website?
- Which cloud models allow you to deploy physical servers?
- Which cloud service model describes Microsoft 365?
- Which cloud service model reduces the customer's management responsibilities the most?
- Which component should be deployed to securely extend an on-premises network to Azure?
- Which compute option is best for running code triggered by messages arriving in a queue?
- Which computing model is most suitable for deploying IoT sensors that require very low latency?
- Which concept explains how cloud computing reduces the amount of IT management an organization must perform?
- Which control should a manager apply to prevent a VM from being accidentally deleted or modified?
- Which defense-in-depth layer includes Network Security Groups?
- Which deployment model integrates public and private cloud environments?
- Which example best demonstrates vertical scaling?
- Which factor has the greatest effect on Azure pricing?
- Which feature delivers real-time cost insights and budget alerts across Azure subscriptions?
- Which feature enables auditing of historical changes to Azure resources for compliance purposes?
- Which feature enforces tag requirements so resources cannot remain untagged across the environment?
- Which feature ensures Azure database backups are encrypted and stored with geo-redundancy?
- Which feature ensures that only approved users can access specific Azure services based on defined roles?
- Which feature helps prevent accidental deletion of a critical resource?
- Which feature helps prevent accidental deletion of production resources?
- Which feature lets an enterprise centrally define and deploy a compliant Azure environment including RBAC, policies, and ARM templates?
- Which feature lets individual departments view their own Azure cost usage?
- Which feature should you use to track the costs of Azure resources?
- Which financial model best describes how cloud services are billed?
- Which financial model describes paying monthly for computing usage instead of making large upfront purchases?
- Which governance feature can restrict which regions are allowed for deploying Azure resources?
- Which governance service indirectly helps ensure high availability and automated failover by enforcing policies?
- Which governance tool enforces a maximum VM size of Standard_D2s_v3 within a resource group?
- Which governance tool enforces naming conventions for resource groups?
- Which governance tool enforces that resources are deployed only to allowed Azure regions for a healthcare organization?
- Which governance tool lets an organization manage policies and compliance across multiple Azure subscriptions?
- Which is a key characteristic of Azure Resource Groups?
- Which is the first stage of the Microsoft Cloud Adoption Framework for Azure?
- Which lock type would prevent a VM from being modified or deleted?
- Which logging tool records changes made to Azure resources, such as deletions or modifications?
- Which mechanism is used to grant permissions to Azure Virtual Desktop resources?
- Which mechanism should a compliance team use to restrict resource deployment to specific Azure regions?
- Which method should a desktop application use to interact with Azure and manage resources?
- Which of the following does an Azure Service Level Agreement (SLA) for virtual machines guarantee?
- Which of the following failures is the most severe one that an Azure Availability Zone can protect an Azure service from?
- Which of the following is a feature of an Azure virtual network?
- Which of the following is an example of vertical scaling in a cloud environment?
- Which of the following is NOT a recommendation category in Azure Advisor?
- Which of the following is required to use Azure Cost Management?
- Which offering lets you use existing Windows Server licenses in Azure?
- Which option describes a characteristic of the public cloud model?
- Which option lets a developer run containers for testing without provisioning underlying infrastructure?
- Which option provides a dedicated private connection from on-premises to Azure?
- Which option should you use to assess whether your company's Azure environment meets regulatory requirements?
- Which option should you use to stop traffic from an Azure virtual network being routed to an Azure Storage account over the internet?
- Which protocol layer does Azure Load Balancer operate on?
- Which redundancy option replicates data across regions and allows read access to the secondary?
- Which resources can be used as the source for an inbound rule in a Network Security Group?
- Which responsibility always remains with the customer across all cloud models?
- Which responsibility does Azure handle across all service models (IaaS, PaaS, SaaS)?
- Which security control functions as a virtual firewall for Azure Virtual Networks?
- Which service best provides database encryption at rest plus built-in automatic patching for a healthcare startup?
- Which service can automatically recreate a resource lock if the lock is removed?
- Which service can automatically send an alert if an administrator stops an Azure virtual machine?
- Which service can create alert rules based on CPU threshold breaches?
- Which service can filter network traffic across multiple Azure subscriptions and virtual networks?
- Which service can you use to find underutilized or idle Azure virtual machines?
- Which service compares a company's cloud usage to industry-standard best practices?
- Which service enables a logistics company to automate workflows between Azure services and external applications using a visual designer?
- Which service enforces standards like naming conventions and allowed VM SKUs across Azure resources?
- Which service enforces tagging standards automatically during resource deployment?
- Which service helps define and deploy a compliant environment that includes ARM templates, RBAC, and policies?
- Which service helps deploy governance, security controls, and resource configuration standards as a single package?
- Which service helps identify risky sign-ins and threats across Azure tenants?
- Which service is best for a startup that needs a globally distributed, multi-model database with low latency for user data?
- Which service is best for running scheduled scripts and background tasks without managing virtual machines?
- Which service is suitable for hosting REST APIs with automatic scaling and minimal server maintenance?
- Which service lets a DevOps team deploy role-based access control settings together with infrastructure templates?
- Which service lets a team audit who performed specific operations on Azure resources?
- Which service lets an organization analyze cost data using tags like "GrantID" and "Department"?
- Which service notifies you about Azure outages in your region?
- Which service offers a web app that auto-scales and supports HTTPS and custom domains?
- Which service packages role-based access control (RBAC) and policy rules together?
- Which service provides a centralized dashboard to monitor performance metrics and alerts across all Azure resources?
- Which service provides a fast, in-memory caching layer for an app that performs frequent queries?
- Which service provides a private, high-throughput connection between an on-premises data center and Azure?
- Which service provides a real-time summary of security posture across subscriptions?
- Which service provides centralized visibility into potential threats across Azure and on-premises environments?
- Which service provides granular access control to restrict access to sensitive Azure resources?
- Which service provides logging and telemetry for diagnosing issues with an Azure web app?
- Which service provides serverless computing in Azure?
- Which service runs event-driven code in response to Azure Storage changes without requiring you to manage infrastructure?
- Which service should a company use to analyze and query large volumes of log data from its Azure resources?
- Which service should a customer use to provision infrastructure consistently across environments using predefined templates?
- Which service should a data team use to process very large datasets with distributed processing and integrated visualization?
- Which service should a developer use to query the latest inventory and properties of virtual machines for reporting?
- Which service should a development team use to run containerized applications without managing the underlying infrastructure?
- Which service should a DevOps team configure to send proactive alerts when a specific web app becomes unavailable?
- Which service should a DevOps team use to deploy a multi-tier application and automate infrastructure creation?
- Which service should a startup use to track and forecast monthly spending on Azure services?
- Which service should an administrator use to receive alerts about misconfigurations or security risks in their Azure environment?
- Which service should an enterprise configure to enforce conditional access policies based on user sign-in risk?
- Which service should an organization use to collect, analyze, and visualize metrics and logs from its Azure resources?
- Which service should be used to distribute HTTP traffic across multiple VMs within the same Azure region?
- Which service should be used to distribute traffic across multiple VMs for performance and redundancy?
- Which service should route incoming HTTP requests to the nearest regional deployment of a web app?
- Which service should you use to assess whether your company's Azure environment complies with regulatory requirements?
- Which solution lets a team centrally manage access across multiple Azure subscriptions?
- Which statement best describes Azure Reserved Instances?
- Which statement correctly describes the Modern Lifecycle Policy for Azure services?
- Which storage redundancy option replicates data across three Availability Zones within a region?
- Which task can you perform using Azure Advisor?
- Which term describes dynamically adjusting cloud resources to meet real-time demand?
- Which term describes increasing a virtual machine's computing capacity by adding memory or CPUs?
- Which tool automates the daily provisioning and deprovisioning of test environments for a DevOps engineer?
- Which tool can a security compliance team use to automatically report all resources that are missing encryption at rest?
- Which tool can automate stopping a VM if CPU usage drops below 5% for one hour?
- Which tool can validate that a virtual network's firewall configuration meets corporate standards?
- Which tool can you use to get recommendations that will reduce Azure costs?
- Which tool compares on-premises costs with Azure over time?
- Which tool ensures consistent infrastructure deployment across multiple subscriptions using templates?
- Which tool gives detailed insights into application performance and failures across multiple Azure services?
- Which tool helps a compliance officer demonstrate that required policies are implemented for regulatory compliance?
- Which tool lets a developer query and analyze metadata for Azure resources across multiple subscriptions?
- Which tool lets a developer quickly locate all VMs without tags across subscriptions for cleanup?
- Which tool lets a system architect run complex queries across metadata for all Azure resources?
- Which tool lets you enforce rules like permitted VM sizes or required regions in Azure?
- Which tool monitors a VM's CPU and memory usage over time?
- Which tool provides a pre-authenticated command shell in a browser?
- Which tool scans and catalogs enterprise data sources?
- Which tool should a DevOps team use to provision and manage Azure resources as infrastructure-as-code?
- Which tool should an administrator use to find all resources across subscriptions that are missing a cost center tag?
- Which tool should an Azure administrator use to allow only a predefined set of virtual machine sizes in production?
- Which tool should an IT manager use to query metadata for all VMs across multiple subscriptions?
- Which tool should you use to discover and classify sensitive data in Azure storage?
- Which tool should you use to start Azure Cloud Shell?
- Which two are benefits of cloud computing? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
- Which two characteristics describe the public cloud? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
- Which two customer types may use Azure Government to build a cloud solution? Each correct selection is worth one point.
- Which two features help organize resources by cost center and automate cleanup of unused resources?
- Which two features or services can be integrated with Azure Monitor? Select two. Each correct answer is worth one point.
- Which type of Azure data transfer is generally free?
- Which type of Azure service requires the least management from end users?
- Which type of failure can an Azure Availability Zone protect against to maintain access to Azure services?
- Who can use the Azure Total Cost of Ownership (TCO) calculator?
- Within the software as a service (SaaS) model, which responsibility is shared between Microsoft and the customer?
- You are planning to deploy many web servers and database servers to Azure. The design must allow control over the types of connections between the web servers and the database servers. Solution: you include a local network gateway. Does this solution meet the goal?
- You are planning to deploy many web servers and database servers to Azure. The design must allow control over the types of connections between the web servers and the database servers. Solution: you include network security groups (NSGs). Does this solution meet the goal?
- You have 1,000 virtual machines running on Hyper-V hosts in a datacenter and plan to migrate them to an Azure pay-as-you-go subscription. Which type of expenditure model applies to this Azure solution?
- You have 50 virtual machines hosted on-premises and 50 virtual machines hosted in Azure. The on-premises VMs and the Azure VMs connect to each other. Which cloud model describes this configuration?
- You have a resource group named RG1. Prevent the creation of virtual machines in RG1 while still allowing other resources to be created. What should you use?
- You have a virtual machine named VM1 running Windows Server 2016 in the East US region. From the Azure portal, which service shows service-failure notifications that could affect VM1's availability?
- You have a web app hosted in Azure. Which tool should you use to measure how long web pages take to load in a user's browser?
- You have an accounting application named App1 that depends on a legacy database. You're planning to move App1 to the cloud. Which cloud service model should you use?
- You have an Active Directory forest containing 5,000 user accounts. Your company will migrate all network resources to Azure and decommission the on-premises datacenter. To minimize user impact after the migration, what should you recommend?
- You have an Azure environment and must create a new Azure virtual machine from an Android tablet. Which three methods could you use? Each correct answer is worth one point.
- You have an Azure Sentinel workspace and need to automate responses to threats detected by Azure Sentinel. What should you use?
- You have an Azure Storage account named storage1. You need to allow containers to be created but prevent them from being deleted in storage1. What should you do?
- You have an Azure subscription and 100 Windows 10 devices. Ensure only users on devices with the latest security patches can access Azure Active Directory (Azure AD)-integrated applications. What should you implement?
- You have an Azure subscription and must run a deployment script using Azure Cloud Shell. How should you access Cloud Shell?
- You have an Azure subscription and need to view your secure score. Which service should you use?
- You have an Azure subscription and plan to create a virtual machine. Where in Azure will the virtual machine be placed?
- You have an Azure subscription named Subscription1. You sign in to the Azure portal and create a resource group named RG1. From documentation you have this command to create a VM: az vm create --resource-group RG1 --name VM1 --image UbuntuLTS --generate-ssh-keys. You need to create VM1 in Subscription1 by using this command. Solution: From the Azure portal, launch Azure Cloud Shell and select PowerShell, then run the command in Cloud Shell. Does this meet the goal?
- You have an Azure subscription. Where can you find information about the personal data Microsoft collects, how Microsoft uses it, and the purposes for that data?
- You have an Azure virtual machine named VM1 and plan to encrypt it using Azure Disk Encryption. Which Azure resource must you create first?
- You have an Azure web app and need to manage its settings from an iPhone. Which two Azure management tools can you use? Each correct answer is worth one point.
- You have an Azure web app and need to manage its settings from an iPhone. Which two Azure management tools can you use? Each correct answer is a complete solution. NOTE: Each correct selection is worth one point.
- You have an on-premises application that automatically sends email notifications based on a rule. You plan to migrate the application to Azure. You need to recommend a serverless computing solution for the application. What should you include in your recommendation?
- You have an on-premises network with several servers and plan to migrate them all to Azure. Recommend a solution to ensure some servers remain available if a single Azure data center goes offline for an extended period. What should you include in the recommendation?
- You have multiple Azure virtual machines and want on-premises clients to communicate with them. Which Azure resources must you create? Select two. Each correct answer is part of the solution. NOTE: Each correct selection is worth one point.
- You have on-premises servers running Windows Server. What should you implement so you can manage those servers from the Azure portal?
- You have virtual machines in a single Azure virtual network named VNet1. Remote workers need access to the VMs on VNet1. What should you configure?
- You must configure an Azure solution that meets these requirements: ✑ Protect websites from attacks ✑ Produce reports that detail attempted attacks. Which service should you include?
- You must deploy a critical line-of-business application on a virtual machine in Azure with a required SLA of 99.99% availability, using as few virtual machines and availability zones as possible. Solution: Use one virtual machine across two availability zones. Does this solution meet the goal?
- You must deploy Azure virtual machines for your company and choose the appropriate cloud service model. The proposed solution is to use Software as a Service (SaaS). Does this solution meet the requirement?
- You must deploy Azure virtual machines for your company and choose the appropriate cloud service model. The proposed solution is to use Infrastructure as a Service (IaaS). Does this solution meet the requirement?
- You must deploy Azure virtual machines for your company and choose the appropriate cloud service model. The proposed solution is to use Platform as a Service (PaaS). Does this solution meet the requirement?
- You need to be notified when Microsoft schedules maintenance that might affect resources in an Azure subscription. Which service should you use?
- You need to collect and automatically analyze security events from Azure Active Directory (Azure AD). Which service should you use?
- You need to deploy an AI solution in Azure and must be able to build, test, and deploy predictive analytics. Solution: Use Azure Machine Learning Studio. Does this solution meet the goal?
- You need to deploy an AI solution in Azure and must be able to build, test, and deploy predictive analytics. Solution: Use Azure Cosmos DB. Does this solution meet the goal?
- You need to manage containers. Which two Azure services can you use? Each correct answer is a complete solution. NOTE: Each correct selection is worth one point.
- You need to migrate an on-premises server using a lift-and-shift approach. To which cloud service model should you migrate?
- You plan to collect and analyze event details from five Azure virtual machines. You need to run queries to compare the event details collected across all virtual machines. Which two tools should you use? Each correct answer is part of the solution. NOTE: Each correct selection is worth one point.
- You plan to deploy a service to Azure virtual machines and need the service to remain available if a datacenter fails. Which option should you include in the virtual machine deployment?
- You plan to deploy a website to Azure that will be accessed by users worldwide and will host large video files. Which Azure feature should you use to provide the best video playback experience?
- You plan to deploy multiple Azure virtual machines and must ensure their services remain available if a single data center fails. Solution: You deploy the virtual machines to two or more scale sets. Does this meet the goal?
- You plan to deploy multiple Azure virtual machines. How can you ensure the services they run remain available if a single data center fails? Choose two solutions. Each correct answer is a complete solution.
- You plan to deploy several Azure virtual machines and must control which Internet ports can be used to access them. Which service should you use?
- You plan to deploy several Azure virtual machines and need to ensure the services on them remain available if a single data center fails. Solution: Deploy the virtual machines to two or more availability zones. Does this meet the goal?
- You plan to map a network drive from several Windows 10 computers to Azure Storage. Which storage solution should you create?
- You plan to migrate a web application accessed by external users. To minimize the administrative effort required to manage the application, which cloud deployment model should you recommend?
- You plan to migrate several servers from an on-premises network to Azure. What is an advantage of using a public cloud service for the servers instead of an on-premises network?
- You plan to migrate the company to Azure. Each division will have an administrator to manage that division's Azure resources. You want the Azure deployment to be segmented by division while minimizing administrative overhead. The proposed solution is to use multiple Azure Active Directory (Azure AD) directories. Does this solution meet the goal?
- You plan to provision Infrastructure as a Service (IaaS) resources in Azure. Which of the following is an example of IaaS?
- You plan to store 20 TB of data in Azure. The data will be accessed infrequently and visualized using Microsoft Power BI. You need to recommend a storage solution. Which two solutions should you recommend? Each correct answer is a complete solution. NOTE: Each correct selection is worth one point.
- You want to reduce ongoing Azure costs. Which three factors affect the cost of a resource? Each correct answer is a complete solution. NOTE: Each correct selection is worth one point.
- You will host a publicly accessible portal web app on Azure for the Miami branch to retrieve customer and product information. The app is currently in an on-premises test environment. The web tier plan must meet these requirements: use the miami.weyland.com URL, deploy to two instances, include SSL support, provide 12 GB storage, and minimize cost. Which web tier plan should you use?
- You're deploying a critical line-of-business application to Azure on virtual machines. The deployment must guarantee 99.99% availability while using as few virtual machines and availability zones as possible. Solution: Use two virtual machines across two availability zones. Does this solution meet the requirement?
- Your Active Directory forest contains thousands of user accounts. All network resources will be migrated to Azure and the on-premises data center will be retired. You must minimize user impact after migration. Solution: Sync all Active Directory user accounts to Azure Active Directory (Azure AD). Does this solution meet the goal?
- Your Azure environment contains 10 virtual networks and 100 virtual machines. You need to limit inbound traffic to all virtual networks. What should you create?
- Your Azure environment contains multiple virtual machines. You must make the VM named VM1 accessible from the Internet over HTTP. Solution: You modify an Azure Firewall. Does this meet the requirement?
- Your Azure environment contains multiple virtual machines. You must make the VM named VM1 accessible from the Internet over HTTP. Solution: You modify a network security group (NSG). Does this meet the requirement?
- Your Azure environment has multiple virtual machines. You must make VM1 accessible from the Internet over HTTP. Which two solutions would accomplish this? Each correct answer is a complete solution. NOTE: Each correct selection is worth one point.
- Your Azure subscription contains these unused resources: 20 Azure AD user accounts, five Azure AD groups, 10 public IP addresses, and 10 network interfaces. To reduce costs, which unused resources should you remove?
- Your company has a Software Assurance agreement that includes Microsoft SQL Server licenses. You plan to deploy SQL Server on Azure virtual machines. What should you do to minimize licensing costs for the deployment?
- Your company has an Azure subscription and three business units. You will deploy new resources for each unit and need a repeatable, reliable method that applies the same configuration to every resource. What should you use?
- Your company has datacenters in Los Angeles and New York and is configuring them as geo-clustered sites for resiliency. You must recommend an Azure storage redundancy option given these requirements: data stored on multiple nodes; nodes in separate geographic locations; data must be readable from the secondary location as well as the primary. Which Azure storage redundancy option should you recommend?
- Your company has multiple business units. Each business unit needs 20 identical Azure resources for daily operations. You must recommend a way to automate creating these Azure resources. What should you recommend?
- Your company has ten offices. You will create several billing reports in the Azure portal, each showing Azure resource usage for an office. Which Azure Resource Manager feature should you use before generating the reports?
- Your company is incurring unexpected charges from idle virtual machines left running. Which service can help identify and shut down unused resources?
- Your company plans to automate server deployments to Azure. Your manager is concerned administrative credentials might be exposed during deployment. Which Azure solution should you recommend to encrypt those credentials during deployment?
- Your company plans to deploy several custom invoicing applications to Azure. Each application depends on several prerequisite applications and services. Which cloud deployment model should you recommend?
- Your company plans to migrate all data and resources to Azure and requires using only Platform as a Service (PaaS) solutions. You deploy an Azure App Service and Azure virtual machines with Microsoft SQL Server installed. Does this meet the requirement?
- Your company plans to migrate all data and resources to Azure and requires using only Platform as a Service (PaaS) solutions. You deploy an Azure App Service and Azure Storage accounts. Does this meet the requirement?
- Your company plans to migrate all data and resources to Azure and requires using only Platform as a Service (PaaS) solutions. You deploy an Azure App Service and Azure SQL databases. Does this meet the requirement?
- Your company plans to migrate all on-premises data to Azure. You must determine whether Azure meets the company's regional compliance requirements. Which resource should you use?
- Your company plans to migrate all virtual machines from on-premises Hyper-V hosts to an Azure pay-as-you-go subscription. You must ensure the migration uses the correct expenditure model. Solution: Recommend the use of the operational expenditure model. Does this solution meet the goal?
- Your company plans to migrate to Azure. Each department's Azure resources will be managed by a department administrator. What are two possible ways to segment Azure for the departments? Each correct answer is a complete solution. NOTE: Each correct selection is worth one point.
- Your company runs multiple on-premises servers and wants to reduce these administrative tasks: backing up application data; replacing failed server hardware; managing physical server security; updating server OSs; and managing permissions to shared documents. The company will migrate the servers to Azure virtual machines. Which two administrative responsibilities will be removed after the migration? (Select two.)
- Your company wants Microsoft to perform an architectural review of its Azure environment. The company currently has a Basic support plan. Recommend the lowest-cost support plan that provides an architectural review.
- Your company wants to check whether Azure virtual machines follow secure baseline configurations. Which service provides that assessment?
- Your company will automate server deployment to Azure, but you're concerned administrative credentials might be exposed during deployment. You must ensure credentials are encrypted during deployment. Solution: Use Azure Multi-Factor Authentication (MFA). Does this meet the requirement?
- Your company will automate server deployment to Azure, but you're concerned administrative credentials might be exposed during deployment. You must ensure credentials are encrypted during deployment. Solution: Use Azure Information Protection. Does this meet the requirement?
- Your company will automate server deployments to Azure and you must avoid exposing administrative credentials during deployment. Which Azure solution should you recommend to encrypt those administrative credentials during deployment?
- Your company will begin using Azure and migrate all network resources there. To start planning and exploring Azure, what should you create first?
- Your company will deploy an AI solution in Azure. Which service should be used to build, test, and deploy predictive analytics solutions?
- Your company will deploy millions of sensors that upload data to Azure. Which two Azure resources must you create to support this solution? Each correct answer is worth one point.
- Your company will deploy multiple web servers and multiple database servers to Azure. Which Azure solution should you recommend to restrict the types of connections web servers can make to the database servers?
- Your company will migrate all data and resources to Azure and requires only Platform as a Service (PaaS) solutions. Which Azure resources should you deploy to meet this requirement?
- Your company will migrate several servers to Azure. Compliance requires that the server named FinServer be placed on a separate network segment. Which Azure solution should you recommend?
- Your company's Active Directory forest contains thousands of user accounts. All network resources will be migrated to Azure and the on-premises datacenter will be retired. You must use a strategy that minimizes the impact on users after the migration. Solution: you require Azure Multi-Factor Authentication (MFA). Does this solution meet the goal?
- Your company's Azure subscription contains resources across multiple regions. You must ensure administrators can only create resources in those regions. What should you use?
- Your company’s Azure subscription contains multiple resources. How can you identify which department is responsible for the cost of each resource?
- Your developers created 10 web applications to host on Azure. The web tier plan must meet these requirements: custom domains, 10 GB storage per app, each app runs in dedicated compute instances, built-in load balancing between instances, and minimal cost. Which web tier plan should you use?
- Your developers provision many custom virtual machines each week and delete them within the same week. 60% run Windows Server 2016 and 40% run Ubuntu. You need to reduce administrative effort by using an appropriate Azure service. Solution: Recommend Azure DevTest Labs. Does this meet the goal?
- Your developers provision many custom virtual machines each week and delete them within the same week. 60% run Windows Server 2016 and 40% run Ubuntu. You need to reduce administrative effort by using an appropriate Azure service. Solution: Recommend Azure Reserved Virtual Machine Instances. Does this meet the goal?
- Your DevOps team needs a single place to analyze logs and metrics from Azure resources. Which service should they use?
- Your on-premises network contains 100 servers. Recommend a solution that provides additional resources to users while minimizing capital and operational expenditure.
- Your organization uses Azure Active Directory. Users sometimes sign in from the internet. You need users who sign in from an unfamiliar IP address to be automatically prompted to change their passwords. Solution: Configure Azure AD Identity Protection. Does this meet the requirement?
- Your organization uses Azure Active Directory. Users sometimes sign in from the internet. You need users who sign in from an unfamiliar IP address to be automatically prompted to change their passwords. Solution: Configure Azure AD Privileged Identity Management. Does this meet the requirement?
- Your subscription contains resources in multiple Azure regions. Which Azure resource should you create to satisfy the policy requirement?
- Your team is designing a global app that must route users to the closest regional instance to minimize latency. Which Azure service provides this routing?
Microsoft Azure Network Engineer Associate AZ-700 Certification All exam questions
- (Case study excerpt) Proseware requires that all connections routed via APPGW1 use end-to-end encryption and that the company use its internal CA whenever possible. APPGW1 currently routes traffic for App2 and must be configured to meet the end-to-end encryption requirement. Which of the following actions should you take to configure APPGW1 for end-to-end encryption and comply with the security requirements?
- (Same environment as an earlier question) Your subscription contains VNet Vnet1 with subnet1 and AzureFirewallSubnet, a public Azure Firewall FW1, and RT1 associated to subnet1 with a 0.0.0.0/0 route to FW1. After you deploy 10 Windows Server VMs into subnet1, none of the VMs activate. What should you do to allow the VMs to activate?
- A bank uses SQL Server Always On availability groups across three VMs in a subnet and needs a listener IP that receives client requests while the responding replica performs Direct Server Return (DSR) for high throughput. Which Load Balancer configuration is appropriate to implement DSR for the internal Always On listener?
- A cloud engineer is enabling NSG flow logs for subscription 'prod-sub' and must choose a storage account and retention policy. Which TWO of the following statements about NSG flow logs and storage/retention are correct? (Select TWO)
- A customer currently has an ExpressRoute circuit using the Local service tier. They need to access other Azure regions and additional services that require a higher tier. What is the supported upgrade path to allow cross‑region reachability and access to global services?
- A customer has an S2S VPN using a VpnGw1 gateway (gw-prod) and reports the tunnel is down. You need to run Azure Network Watcher diagnostics specific to VPN gateway and connection to rapidly identify root causes such as BGP status, IKE/IPSec negotiation failures, or gateway health. Which approach is most appropriate?
- A distributed development team at AlpineApps wants to replace jump boxes with Azure Bastion Standard. Their requirements: support for multiple concurrent sessions, scale to handle up to 50 simultaneous RDP/SSH sessions, allow connecting from known developer laptop public IPs, and provide shareable session links for contractors without exposing VM public IPs. How should they configure Azure Bastion Standard and related settings?
- A finance team at Mercury Systems wants to use Just-in-Time (JIT) VM Access for a set of Windows VMs. They require that RDP (TCP 3389) is only opened for approved engineer public IPs for a maximum of 2 hours per access request, and that only port 3389 is ever opened. How should JIT be configured in Azure Security Center (Defender) to meet these constraints?
- A financial customer plans to use ExpressRoute Direct and requires a single physical port with the maximum throughput plus hardware encryption on the physical link. Which combination of port speeds and MACsec support accurately reflects Azure ExpressRoute Direct options?
- A financial services firm wants all internet-bound traffic from VMs in a spoke VNet to be routed back to their on-premises security stack (forced tunneling) over an existing Site-to-Site VPN. Which Azure configuration pattern will accomplish forced tunneling while preserving route propagation from the VPN connection?
- A global admin for BlueNova enabled Traffic Analytics but sees data aggregated every 5 minutes while they expect hourly aggregates for billing-level reports. They have Traffic Analytics configured to use workspace 'net-ws-01' in West US and flow logs are version 2. How can they change Traffic Analytics to produce hourly aggregates?
- A global media company needs DNS-based traffic distribution that prefers lowest latency globally but, within a single region, distributes traffic to different datacenters using weights for capacity testing. They also want immediate geographic blocking of specific countries for compliance. How should Traffic Manager profiles be structured to implement performance-based global routing, weighted regional distribution, and geographic blocking?
- A global SaaS provider, BlueSun, has an internal web app on 10.1.2.10:443 in the hub VNet and wants to publish it to the internet using a single public IP on Azure Firewall DNAT. They require the external endpoint to be https://app.bluesun.com and want the firewall to terminate TLS for IDPS inspection, then re-encrypt to the backend using the existing internal certificate. Which DNAT and firewall configuration accomplishes this?
- A global services team asks about Azure Private DNS zone scalability before they consolidate 30,000 hosts into a single zone. What are the documented practical limits they should consider for a single Azure Private DNS zone regarding maximum virtual network links and maximum record sets (record sets = distinct DNS record names)?
- A global workforce at Contoso uses Windows, macOS, and Linux laptops. The security team requires Azure AD-based authentication (so Conditional Access and MFA are enforced) for Point-to-Site VPN. Which authentication method should you choose, and what is a reason you would choose certificate authentication instead?
- A multinational customer will connect their SD-WAN appliances to an Azure Virtual WAN VPN site. The network team must configure BGP so on-premises routes are learned by the virtual hub. Which of the following is the correct set of fields to configure on the Virtual WAN VPN site to enable BGP peering with their CPE?
- A multinational firm must configure ExpressRoute Private Peering with Azure and the provider asks them to specify the primary and secondary prefix values to be used for the two BGP sessions. Select TWO IPv4 subnets from the choices below that meet Azure ExpressRoute Private Peering requirements (primary and secondary).
- A partner subscription owns the ExpressRoute circuit and your subscription owns the VNet that must connect to that circuit. You need to attach the VNet to the partner's circuit. What sequence of steps and constraints correctly describes how to establish this cross‑subscription connection using ExpressRoute circuit authorization?
- A private endpoint for storage1 is deployed in Subnet1 of VNet1. Site1 (on-premises) is connected to VNet1 over a Site-to-Site VPN. You want to control access from Site1 to storage1 by using network security groups (NSGs). What is the first action you should take?
- A regulated customer must implement an IKEv2 custom policy on their Azure VPN gateway requiring strong encryption and Perfect Forward Secrecy (PFS). Which statements are true for successfully configuring an IKEv2 custom policy so the tunnel comes up with PFS enforced?
- A remote office has a macOS device named Device1 that uses an IKEv2 VPN client. Your Azure subscription includes a VPN gateway (VPNGW1) that provides VPN connections to VNet1. To allow Device1 to access resources on VNet1 via VPNGW1 and minimize administrative effort, what should you do first?
- A service endpoint policy is configured with these settings: associated subnets = Subnet1, service = Microsoft.Storage, scope = Single account, resource = storage1. Given those settings, which storage resources can a VM located in Subnet1 (VM1) access?
- A service provider wants to connect customer SD-WAN CPE devices to their Virtual WAN using IPsec with BGP so each customer site advertises site routes dynamically. Which sequence of Virtual WAN objects and configuration settings is required to establish BGP over IPsec for each SD-WAN site?
- A Site-to-Site VPN tunnel from your main office to an Azure virtual network fails to establish. You need to inspect a diagnostic log that helps determine why the IPsec tunnel negotiation failed. Which diagnostic log should you review?
- A software vendor, CloudPatch, uses Azure Firewall to manage outbound OS updates for hundreds of Windows servers. They want to allow Windows Update, Microsoft Update, and Windows Defender update traffic but deny all other internet egress. Which Azure Firewall configuration using FQDN tags is the most maintainable and secure approach?
- A system integrator is connecting a legacy VPN appliance from 2010 that only supports policy-based VPN (static crypto maps) to an Azure VPN Gateway. The appliance also does not support BGP. Which Azure VPN Gateway mode/feature should the integrator select to ensure the VPN can be established and what are the trade-offs?
- A utilities customer wants all spoke-to-spoke traffic to traverse a central NVA deployed in the Virtual WAN hub. They tried creating UDRs in the spoke VNets with a next hop pointing to the hub firewall IP, but the spoke subnets do not honor those UDRs. Why does this happen and what is the correct way to force spoke-to-spoke traffic through the hub NVA?
- A WAF policy in prevention mode is associated with an Azure Front Door instance. You must implement these requirements: log all requests originating from Australia; block all requests from New Zealand; and if the network 131.107.100.0/24 exceeds 100 requests within one minute, block further requests from that network. What is the minimum number of WAF custom rule objects you should create to satisfy these requirements?
- A Woodgrove Bank VM (app-nic01) in subnet svc-subnet is unexpectedly routing outbound traffic for 10.1.20.0/24 to a peered VNet instead of Internet. You need to inspect the effective routes applied to the NIC to determine which route (system, UDR, or propagated) is taking precedence. Which of the following is the correct way to get the effective routes for that VM NIC using portal and CLI?
- Adatum requires end-to-end TLS: clients use HTTPS to the Application Gateway and the gateway must authenticate backend App Service certificates to prevent MITM inside their VNet. Which configuration achieves end-to-end TLS with Application Gateway validating the backend certificate chain?
- AdventureWorks is deploying Private Endpoints for Azure SQL and Azure Storage in a spoke VNet. The networking team must create the correct Private DNS zones so the services resolve to the private endpoint IP addresses inside the VNet. Which of the following sets contains the proper Private DNS zone names to cover Azure SQL and Blob storage private endpoints?
- AdventureWorks plans a dual-stack VNet in West Europe with both IPv4 (10.50.0.0/16) and IPv6 (2001:db8:abcd::/48) address spaces. They deployed two VMs but the team cannot ping over IPv6 between the VMs. Which requirement or limitation most likely explains the lack of IPv6 connectivity?
- AdventureWorks wants Azure Front Door Premium to securely reach internal App Service and Storage accounts over Private Link so origins are not exposed to the public internet. Which steps are required to create Private Link origins for Front Door Premium to use the App Service and Storage account?
- AeroParts wants to deploy Azure Firewall in a Secured Virtual Hub using Azure Firewall Manager so the security team can manage policies centrally. What is the correct deployment approach to use Azure Firewall Manager for a secured virtual hub?
- After provisioning a Site-to-Site VPN between Contoso Azure VNet and an on-premises edge firewall, the connection status in the Azure portal shows 'NotConnected'. The on-premises firewall logs indicate an IKE_AUTH failure due to 'pre-shared key mismatch'. Which sequence of troubleshooting steps is most appropriate to resolve the problem?
- AGW1 is an Application Gateway that has a routing rule (Rule1) sending requests for http://www.contoso.com to backend pool Pool1. Pool1 targets VMSS1. You deployed a new virtual machine scale set VMSS2 and must configure AGW1 so that all requests for http://www.adatum.com go to VMSS2, while requests for http://www.contoso.com continue to reach Pool1. Which three actions should you perform?
- All virtual machines are connected to a single virtual network and you must expose the hosted applications to the internet while ensuring the VMs share one public IP address. Which Azure resource should you use?
- AlpineApps needs to restrict which Microsoft services are reachable over their ExpressRoute Microsoft Peering session. They plan to use route filters with BGP communities. What is the correct way to implement this filtering?
- An application server (app-db-01) cannot reach an external analytics service on TCP 9000. The team suspects an NSG rule is blocking outbound traffic but there are multiple NSGs (subnet and NIC level) and Azure Firewall in the path. Which Network Watcher artifact will show the aggregated effective security rules and let you identify which specific rule (name and priority) is blocking that traffic for the NIC?
- An Azure Application Gateway named AppGW1 is load-balancing requests to a backend web app App1. You need to modify server variables included in App1's response headers. Which feature of AppGW1 should you configure?
- An Azure Firewall is deployed to AzureFirewallSubnet and all traffic from Subnet2 is routed through that firewall. Hosts in Subnet2 must be able to access an external site at https://*.contoso.com. Which change should you make to the firewall policy to allow this access?
- An Azure Front Door instance FD1, protected by Azure Web Application Firewall (WAF), uses the frontend host app1.contoso.com to front Azure web apps hosted in East US and West US. You need to configure FD1 so that requests to app1.contoso.com are blocked from all countries except the United States. What should you add to the WAF policy?
- An Azure Private Link service PL1 is fronted by an Azure Load Balancer named LB1. PL1 needs to support a larger volume of outbound connections. What change will increase PL1's outbound capacity?
- An Azure Virtual Desktop deployment contains 500 session host VMs. All outbound internet traffic from those VMs goes through a NAT gateway. During peak hours some users cannot reach internet resources, and Azure Monitor reports many failed SNAT connections. You need to increase the number of available SNAT connections for outbound from the session hosts. What should you do?
- An international SaaS provider is evaluating Traffic Manager routing methods. They need a concise mapping of behaviors: which method picks the lowest network latency from the user, which distributes according to configured endpoint weights, which routes users based on their geographic location, and which returns multiple healthy endpoints in DNS responses for client-side selection?
- Azure Front Door instance FD contains an origin group OG1. You need to configure OG1's health probe so it generates the least possible amount of probe traffic. Which HTTP method should the probe use?
- BingCo is configuring a Local Network Gateway (LNG) resource to represent its on-prem environment for a Site-to-Site VPN. The on-prem team has provided multiple networks (10.1.0.0/16 for datacenter, 10.2.0.0/16 for branch) and a BGP ASN of 65020 with a peering IP of 192.0.2.5. Which configuration in the Local Network Gateway is required to correctly represent the on‑prem environment for BGP-enabled S2S?
- BlueYonder has a parent public DNS zone 'example.com' in subscription A and needs to delegate the subdomain 'eu.example.com' to a child private/public DNS zone authored in subscription B (different Azure AD tenant is not involved). What steps are required to delegate the subdomain so DNS queries for eu.example.com resolve using the child zone name servers?
- BlueYonder wants to publish some public IP prefixes to reach Office 365 and Azure PaaS from their ExpressRoute circuit, and also connect their on‑premises routers to VNets using private IPs. How should they use Private Peering vs Microsoft Peering to achieve both needs?
- Case study (Litware): Vnet1 is peered bidirectionally with Vnet2 and Vnet3. Vnet2 and Vnet3 must communicate via Vnet1, meet the virtual networking and business requirements (including routing default 0.0.0.0/0 from Vnet2 and Vnet3 to on-prem via ExpressRoute), and minimize costs. Which two changes should you apply to the peerings to allow Vnet2 and Vnet3 to communicate through Vnet1? (Choose two.)
- Contoso configures an Azure Front Door origin group containing two origins in different regions. They want Front Door to fail over an origin after two consecutive health probe failures. Which health probe settings should they modify in the origin group to meet this requirement?
- Contoso intends to peer an East US VNet with a West Europe VNet. They are evaluating cross-region peering for an application with heavy inter-region traffic. Which statement accurately reflects bandwidth, latency, and cost considerations for global VNet peering?
- Contoso is evaluating whether to use Virtual WAN Basic or Standard SKU. They need hub-to-hub transit, support for Secured Virtual Hubs (Azure Firewall via Firewall Manager), and higher scale for VPN and ExpressRoute. Which statement correctly describes the feature difference and recommended migration path?
- Contoso Ltd. has a hub-spoke topology in East US: a hub VNet (Hub-VNet) with an NVA and two spoke VNets (Spoke-A and Spoke-B). Spoke-A is peered to Hub-VNet and Spoke-B is peered to Hub-VNet. Engineers notice VMs in Spoke-A cannot reach VMs in Spoke-B over the peering connections. Which explanation best describes why direct spoke-to-spoke traffic does not traverse the hub peering, and what Contoso must do to enable spoke-to-spoke communication without re-architecting all peers?
- Contoso Ltd. has a Virtual WAN with a hub in West US. They deployed three spoke VNets (app-spoke, db-spoke, mgmt-spoke) attached to the hub. The security team requires that db-spoke prefixes (10.10.2.0/24) are never learned by app-spoke and mgmt-spoke, but app-spoke must still be reachable from on-prem via a Site-to-Site VPN connection attached to the same hub. How should you configure the Virtual WAN hub route tables to accomplish this?
- Contoso Ltd. has a web VM (appvm01) in resource group web-rg connected to NIC appvm01-nic protected by NSG nsg-web. Clients report that HTTPS traffic from a specific client IP 203.0.113.45 to the VM's private IP 10.2.1.4:443 is failing. You need to determine whether an NSG is allowing or denying that specific flow and which rule matched. What is the fastest correct way to diagnose this from Azure's Network Watcher features?
- Contoso Ltd. has deployed Azure Firewall Premium in a hub virtual network to protect inbound and outbound traffic for multiple VNets. The security team must detect and block SQL injection attacks over TLS for traffic passing through the firewall. They require signature-based IDPS and TLS inspection for east-west and north-south traffic, but must not decrypt traffic to backend SQL servers that use client certificate authentication. Which configuration meets the requirement with minimal risk to client-certificate-protected flows?
- Contoso Ltd. has two ExpressRoute circuits: one provisioned at the New York Equinix NY7 location and another at the London Equinix LD8 location. Their networking team wants on-premises branches connected to the New York circuit to talk directly to branches connected to the London circuit over Microsoft’s backbone (no public Internet, no site-to-site VPN). What action must Contoso take to enable branch‑to‑branch connectivity across the Microsoft global network?
- Contoso Ltd. operates a hub virtual network in Azure that contains a third-party Palo Alto firewall NVA in the hub subnet. You deployed Azure Route Server in the hub and want the Palo Alto to dynamically exchange routes so the NVA can program routes into the UDRs for all spoke VNets. Which configuration on the Palo Alto is required to establish BGP peering with Azure Route Server and allow dynamic route exchange?
- Contoso Retail has a hybrid network: a campus on-premises network connected to an Azure hub VNet via an ExpressRoute private peering. Network team must allow on-premises DNS clients to resolve Azure Private DNS zones (for private endpoints and custom private zones) without opening DNS to the internet. They want to use Azure Private DNS Resolver. Which configuration achieves inbound resolution of on-premises queries into Azure DNS using the Private DNS Resolver?
- Contoso Retail has two Azure regions (EastUS and WestEurope). They must publish a single public IP that provides global client connectivity and forwards traffic to regionally deployed backend pools (VM Scale Sets) while keeping backend health and NAT rules regional. You plan to use Azure Load Balancer. Which configuration meets this requirement with minimal changes to the existing regional backend setups?
- Contoso uses an ExpressRoute circuit (er-circuit-prod) and wants to be notified if the circuit becomes unavailable for more than 10 minutes. Which Azure Monitor alert approach most directly and reliably triggers when the ExpressRoute resource's availability becomes Unavailable for the specified duration?
- Contoso wants to ensure only two specific Storage Accounts (stg01 and stg02) in their subscription can be accessed from a finance subnet over the Microsoft backbone. They plan to use Service Endpoints with an additional restriction. Which configuration will restrict access from the subnet to only those storage accounts?
- Contoso wants to publish the same domain 'app.contoso.com' publicly to the internet (resolving to Front Door) but inside their VNets they need 'app.contoso.com' to resolve to internal private endpoint IPs. They consider using Azure DNS public zone and a Private DNS zone of the same name. Will Azure support this split-horizon (same zone name public + private) design and how will resolution behave?
- Contoso's network operations team needs to use Azure Monitor Network Insights to investigate intermittent VNet-to-VNet latency and to view flow maps across peered VNets. The subscription currently has Network Watcher enabled but no Log Analytics workspace for network monitoring. What must the team enable/configure to get VNet health, flow map visualization, and diagnostic insights in Network Insights?
- ConvergeTech deploys custom DNS server VMs inside a spoke VNet and wants Azure VM agents and DHCP clients to receive the proper DNS suffix and resolver behavior. Which DHCP option and Azure recursive resolver IP should they configure/forward to ensure Azure-internal name resolution still works and clients get the correct domain suffix?
- Delta E-Commerce uses Application Gateway v2 with WAF_v2 to protect checkout endpoints. They observe false positives from the OWASP CRS 3.2 SQLi rule for a legitimate JSON payload that contains '=' and 'or' strings. They want to keep the global OWASP rule set active but exclude the specific rule for the /api/checkout path without disabling the rule globally. What configuration will accomplish this?
- EagleBank plans to deploy an ExpressRoute gateway with zone redundancy. Which gateway SKU and deployment requirement should they choose to get a zone‑redundant ExpressRoute gateway across three availability zones?
- EdgeSolutions anticipates growth to thousands of spokes. Their current single hub VNet design uses peering for spoke connectivity but they are approaching the subscription peer limits. What is the recommended scalable alternative to support tens of thousands of spokes while preserving transitive routing and centralized security?
- Epoch Analytics needs to enable NSG Flow Logs v2 for several subscription VNets and ingest logs into a central Log Analytics workspace for Traffic Analytics. Which sequence of actions and configuration is required to enable Flow Logs v2 and Traffic Analytics correctly?
- Fabrikam has a hub-and-spoke design. The hub contains an Azure Route Server and an NVA. One on-prem branch connects via an ExpressRoute circuit to the hub and another branch connects via a Site-to-Site VPN to the same hub. Fabrikam wants branch-to-branch connectivity (traffic between the two on-prem branches) to be routed through Azure without hairpinning back to a colo. Which statement accurately describes a limitation and the recommended approach for enabling branch-to-branch routing in this scenario?
- Fabrikam has a storage account named fabrikamfiles in rg-storage-eastus and creates a Private Endpoint for the blob service in a spoke VNet. The networking team wants DNS resolution within the spoke VNet to resolve fabrikamfiles.blob.core.windows.net to the private IP of the Private Endpoint. Which Private DNS zone name should they create and link to the VNet so the Auto-registered record is created correctly?
- Fabrikam requires encryption of VM-to-VM traffic between two VNets (VNet-EASTUS and VNet-WESTEU) in different regions. The VNets are currently peered. The security requirement is that traffic must be encrypted in transit without modifying the application. What is the most straightforward Azure solution and its prerequisites to meet this requirement?
- Fabrikam runs a multi-tier app in vnet-prod with a route table rtb-azure routing 0.0.0.0/0 to a virtual appliance at 10.0.100.4. A backend VM (dbvm01) in subnet db-subnet cannot reach an external API at 52.160.0.8 — traffic appears to be dropped (black hole). Which Network Watcher action should you run to identify the router/next hop being chosen for traffic from dbvm01 to 52.160.0.8 and detect if the packet is being sent to an unexpected next hop (black hole)?
- Fabrikam runs a Secured Virtual Hub in Central US with Azure Firewall. They want all private spoke-to-spoke traffic to route normally between spokes, but require all internet-bound traffic from spokes to be inspected by the hub Azure Firewall before egress. Which Virtual WAN configuration achieves this?
- Fabrikam runs multiple third-party network virtual appliances (NVAs) in an availability set to perform stateful inspection. Each NVA needs to receive the original destination TCP port for many concurrent sessions (not one-to-one NAT port translations). Which Azure Load Balancer feature should Fabrikam enable to support full-port, many-to-one NAT to the NVAs for high availability?
- Fabrikam runs services in Azure and needs to forward DNS queries from Azure VNets for on-premises-only namespaces (e.g., corp.fabrikam.local) back to on-premises DNS servers. They plan to use Azure Private DNS Resolver's outbound capabilities and a forwarding ruleset. What is the correct architecture to ensure queries from Azure are forwarded to on-premises authoritative servers?
- Fabrikam's web app relies on a CDN for static assets. They must cache responses separately when the 'q' query parameter changes, but ignore transient 'sessionid' query parameters when determining cache keys. They also want automatic origin failover if the primary origin is unhealthy. Which Azure CDN configuration satisfies these requirements?
- FinServices has an ExpressRoute circuit that must connect to their Virtual WAN ExpressRoute gateway in East US. They plan for large bandwidth and expect to grow capacity. How should the Virtual WAN ExpressRoute gateway be configured to scale capacity and support multiple ExpressRoute circuits?
- For outbound traffic originating from VNet1 you must: perform transparent proxying to external web servers, inspect all outbound TLS, and minimize cost. Which resource should you include?
- Four virtual machines host an application named App1. You deployed an Azure Standard Load Balancer named LB1 to distribute incoming HTTPS requests to App1. You want LB1 to stop sending traffic to unhealthy instances faster, while minimizing administrative effort. Which setting should you change?
- Gateway1 currently provides access to App1 at https://app1.contoso.com. You have deployed a new web app App2 and need Gateway1 to route https://app2.contoso.com to App2 while minimizing administrative effort. What should you add or configure on Gateway1?
- Given multiple virtual networks and Azure Firewall deployed to VNet3, you must force traffic from Subnet1-1 to Subnet2-1 to traverse the firewall. Which configuration accomplishes that?
- GlobalLogistics needs to insert a third-party NVA (virtual appliance) into their Virtual WAN transit to perform deep packet inspection for spoke-to-spoke traffic. They plan to use an NVA from the marketplace which requires a fixed private IP. How should they integrate the NVA so hub-transit traffic flows through it?
- GlobalMart wants centralized name resolution for private zones: private DNS zones will be managed in a hub subscription and should resolve for spokes without creating identical zones in each spoke. What's the recommended configuration to provide centralized resolution from the hub to all spoke VNets?
- GreenCloud wants to block a small set of malicious IP addresses and also limit abusive clients by rate on their WAF policy for an Application Gateway v2. They also want to block requests coming from certain countries. Which combination of custom WAF rules should they implement to meet rate limiting, IP blocklist, and geo-filtering requirements efficiently?
- Horizon Retail wants to continuously track their ExpressRoute circuit availability and be alerted when on‑prem → Azure connectivity degrades. Which Azure feature combination gives best visibility into circuit health and path availability?
- Innovate Bank needs to restrict which certificate authorities can issue certs for their public domain 'banking-innovate.com'. They want to publish DNS records that explicitly authorize only DigiCert to issue certificates. Which Azure DNS change achieves this requirement?
- MedTech Inc. has deployed DDoS Protection Standard on their virtual network for a public-facing API. They observed a volumetric attack and want to minimize false positives from legitimate traffic spikes from a global CDN. Which DDoS Standard feature should they rely on, and what telemetry will help them tune the protection?
- MetroBank needs to capture packets from a production VM (payment-vm) for a short troubleshooting window. Company policy forbids storing captures in a shared storage account outside the VM's subscription, and they prefer local VM storage for the capture, but size is limited. Which statement correctly describes Network Watcher packet capture storage options and trade-offs?
- MetroPay has mission‑critical traffic and has ordered two ExpressRoute circuits from different providers: one at Equinix DC1 and one at an AT&T location DC2 in the same metro. They want to ensure high availability if a peering location or provider router fails. What design will provide resilient connectivity to their Azure VNets?
- Nimbus Cloud runs a network security perimeter (NSP) architecture and needs to include Platform-as-a-Service (PaaS) resources such as Azure Storage and Azure SQL in the perimeter. The security requirement is that all management plane and data-plane access to these PaaS services must either originate from the NSP hub or be blocked. Which approach ensures PaaS resources are associated with the NSP while allowing secure access from the hub?
- Noble Electronics is onboarding several acquired companies and must plan IP addressing across new VNets and the on-premises HQ. They will connect everything with VPN and ExpressRoute. What is the best address planning practice to avoid connectivity issues when VNets and on-premises networks are interconnected?
- Norstar Telecom is configuring ExpressRoute Private Peering and must provide the Azure‑facing primary and secondary IPv4 subnets for the peering session. Which pair of subnet sizes and characteristics should they provide to satisfy Azure requirements for Private Peering primary/secondary subnets?
- NorthStar IT manages a public DNS zone contoso.com in Azure DNS and wants the apex (contoso.com) to point to an Azure Traffic Manager profile and to Azure Front Door in separate deployment scenarios. What is the supported and recommended method to implement apex redirection with Azure DNS in these cases?
- Northwind Electronics has two Virtual WAN hubs: one in West Europe and one in East US. Hosts in West Europe need to initiate TCP connections to services in East US spokes over the Azure backbone. Current configuration has hubs in the same Virtual WAN but traffic takes indirect routes. What must be true to allow hub-to-hub traffic to traverse the Virtual WAN global transit and reach spokes in the other region without creating VNet peering between regions?
- Northwind Inc. needs an Azure VPN Gateway SKU that can support up to approximately 10 Gbps of aggregate IPsec throughput for a high-throughput cross-region hub. Which VPN gateway SKU should the network team select?
- Northwind IT must host Azure Container Instances (ACI) container groups and an App Service Environment v3 (ASEv3) within their virtual network. They want both services in the same subnet and have started creating a subnet with delegation. What is the correct subnet-delegation approach for hosting these services?
- Northwind Logistics wants automatic failover to a site‑to‑site VPN if their ExpressRoute circuit fails. They already have an S2S VPN gateway (route‑based) with BGP and an ExpressRoute circuit. Which configuration will provide fastest and most reliable failover while preserving route propagation to VNets?
- Northwind Pharmaceuticals wants VM hosts in 6 spoke VNets to automatically register their hostnames into a shared Azure Private DNS zone 'prod.internal.northwind.com' created in the hub subscription. The team also needs to control which VNets can perform registrations. What is the correct sequence and configuration to enable auto-registration and restrict registration to a single VNet?
- NorthWind runs Application Gateway v2 (Standard_v2) and must ensure zone-level fault tolerance. They also want autoscaling with a minimum of 1 instance for cost savings and a maximum of 10. What is the correct configuration to enable zone redundancy and autoscale while meeting zone fault-tolerance requirements?
- Northwind Services has an application VM (web-vm02 in RG app-rg) that intermittently cannot establish a TCP connection to an Azure SQL instance on 1433. You need a Network Watcher tool to test TCP connectivity from web-vm02 to the SQL FQDN:1433 and report reachability and end-to-end latency from Azure's control plane. Which Network Watcher feature should you use?
- Note: This item is part of a series that uses the same scenario. Each question in the series tests a different solution; some sets may have multiple correct solutions and some none. After you answer a question here you cannot return to it. You manage an Azure Application Gateway that has Web Application Firewall (WAF) enabled. The gateway is configured to route requests to its own URL. When you browse to the gateway URL you receive an HTTP 403 response. Diagnostics show a WAF block for the request. You must allow the URL to be reachable through the Application Gateway from any client IP. Solution: Add a WAF policy exclusion for request headers that contain the value 137.135.10.24. Does this meet the requirement?
- Note: This question is part of a series that share the same scenario. Each question proposes a distinct solution that might meet the goals. After you answer, you cannot return to this question. You have an Azure subscription that contains: • A virtual network named Vnet1 • A subnet named Subnet1 in Vnet1 • A virtual machine named VM1 connected to Subnet1 • Three storage accounts named storage1, storage2, and storage3 You must allow VM1 to access storage1 but prevent VM1 from accessing any other storage accounts. Solution: Create a network security group (NSG) and associate it with Subnet1. Does this solution achieve the requirement?
- Note: This question is part of a series that share the same scenario. Each question proposes a distinct solution that might meet the goals. After you answer, you cannot return to this question. You have an Azure subscription that contains: • A virtual network named Vnet1 • A subnet named Subnet1 in Vnet1 • A virtual machine named VM1 connected to Subnet1 • Three storage accounts named storage1, storage2, and storage3 You must allow VM1 to access storage1 but prevent VM1 from accessing any other storage accounts. Solution: Configure the firewall settings on storage1 to only allow connections originating from Vnet1. Does this solution achieve the requirement?
- NovaBank requires all internet-bound traffic from Azure VNets to be inspected by an on-premises security appliance. They deployed Azure Firewall in the hub and want to force-tunnel outbound traffic through an ExpressRoute circuit to the appliance, while still allowing Azure service traffic (e.g., Azure SQL) to go directly to Azure without hairpinning through on-prem. What combination of Azure Firewall and routing features meets this requirement?
- NSG1 is associated to the NIC of VM1 and contains the rules shown. You collected NSG flow logs for five minutes capturing these activities: two RDP sessions originating from VM1 to VM2 (each from a different TCP source port), and three SSH sessions originating from VM2 to VM1 (each from a different TCP source port). When Traffic Analytics aggregates the flows from these events, how many aggregated flow entries will it report?
- One of your on-prem routers advertises some static prefixes that must be present in the Virtual WAN hub route table for proper routing to an NVA. How do you add those on-prem prefixes to the hub routing so spokes learn them via the hub?
- Orion Retail is evaluating two deployment models using Azure Firewall Manager: 'secured virtual hub' (SVH) with Azure Virtual WAN Hub and the traditional 'hub VNet' model with a VNet-based firewall. They need centralized policy, automated spoke onboarding, and native hub-to-hub transitive routing. Which statement correctly contrasts the secured virtual hub with the hub VNet model?
- Refer to the environment described: VM1 has an instance-level public IP (ILPIP). A Basic Load Balancer uses a public IP. VM1 and VM2 are in the backend pool. A NAT Gateway has a public IP named IP3 and is associated with SubnetA. VNet1 also has a virtual network gateway with public IP IP4. When VM1 initiates outbound traffic to the internet, which public IP address will be used for that outbound connection?
- RetailCo runs a hub-spoke design using a Secured Virtual Hub with Azure Firewall. They want all internet-bound traffic from spokes to be inspected centrally. Which hub route table configuration will ensure centralized egress and avoid hairpinning or bypass from the spokes?
- RetailCorp wants to monitor connectivity from three front-end VMs to five backend APIs. They require 60-second monitoring intervals, group-based configuration to manage the five endpoints as one logical set, and alerts when more than three consecutive tests fail within five minutes. Which configuration using Connection Monitor v2 and Azure Monitor is the correct approach?
- Same scenario: Client1 uses P2S IKEv2 to VNet1; VNet1 peered to VNet2 with gateway transit enabled. Client1 cannot reach VNet2. Solution: enable BGP on VNet1's gateway. Does this solution meet the requirement?
- Same VNet1/VNet2/P2S scenario: Client1 cannot reach VNet2. Solution: download and reinstall the VPN client configuration on Client1. Will this allow Client1 to communicate with VNet2?
- select TWO - Fabrikam runs a multi-subscription environment with Azure Firewall Policy hierarchy: a global parent policy and per-hub child policies applied via Firewall Manager. They need to ensure a high-priority DENY rule for traffic from a suspicious /24 IP range is enforced across two specific hubs but allowed in others. Which TWO configurations will achieve this goal while preserving local allow rules in other hubs?
- select TWO - Litware operates a subnet with a NAT Gateway (NAT-GW) providing outbound for 40 Linux VMs. The team sees SNAT port exhaustion during large scale concurrent outbound connections. Which two steps will increase the available SNAT ports for outbound connections from that subnet?
- Select TWO protocols that best meet the following Contoso requirements for Point-to-Site VPN: 1) cross-platform support (Windows, macOS, Linux), 2) support for Azure AD authentication (to enforce Conditional Access/MFA), and 3) NAT traversal support for users behind home routers.
- Site1 (on-premises) is connected to VNet1 via a Site-to-Site VPN. You have a storage account named storage1 in the Azure subscription. You want servers in Site1 to connect to storage1 over the S2S VPN with the least administrative effort. What should you create in VNet1?
- Subnet1 is associated to NSG1, which blocks all outbound traffic not explicitly allowed. VMs in Subnet1 must communicate with Azure Cosmos DB. To allow outbound access to Cosmos DB via NSG1, which configuration element should you reference in the outbound security rule?
- Subnet1 is associated with a service endpoint policy named Policy1 that includes a single resource referencing storage1. An Azure Batch pool (Pool1) is deployed into Subnet1. To ensure the compute nodes in Pool1 can access storage1, what should you do?
- SummitCo is choosing between Metered and Unlimited data plans for their ExpressRoute circuit. Their anticipated egress to Azure is 45 TB/month and ingress is 5 TB/month. Which billing plan should they choose and why?
- Tailspin Toys is deploying an active-active VPN Gateway in Azure for high availability and BGP peering with their on-prem edge routers. The network team created two custom BGP peer IP addresses for the Azure side that come from an IP range outside the gateway subnet (they used 10.10.100.0/29 while the gateway subnet is 10.10.0.0/27). After deployment the BGP sessions never establish. What is the most likely cause and the correct fix?
- Tailspin Toys wants to expose a custom NFV-based inspection service running in their Hub VNet so partner VNets can connect privately using Private Endpoints. Which sequence of actions is required to create a Private Link Service backed by their internal load-balanced application so external consumers can create Private Endpoints that connect to it?
- Tailwind Airlines needs an Application Gateway to route requests to /images/* to a blob-serving backend pool and /api/* to API VMs. They plan to use a single multi-site listener on app.contoso.com. What Application Gateway configuration will accomplish this with the least complexity?
- Tailwind Logistics is evaluating two options to allow on-premises DNS clients to resolve Azure Private DNS names: (A) deploy a pair of HA VMs running BIND in the hub VNet and configure on-premises forwarders to send queries to those VMs; (B) deploy Azure Private DNS Resolver with inbound endpoints. From an operational and supportability standpoint which statement correctly compares these options?
- Tailwind Traders needs a zone-redundant VPN Gateway deployed in a region that supports Availability Zones. Which of the following steps is required to implement a zone-redundant VPN gateway (example VpnGw2AZ) and ensure it remains highly available across zones?
- Tailwind Traders needs sub‑20 ms latency from their on‑premises routers to VMs in a connected VNet. They plan to use ExpressRoute FastPath to reduce datapath hops. Which statement correctly describes a prerequisite and how traffic flows when FastPath is enabled?
- Tailwind Traders plans secure connectivity from application servers in a VNet to an Azure SQL Database. The security team is comparing Service Endpoints and Private Endpoints. Which statement accurately describes a key security and routing difference?
- The exam scenario shows several Azure virtual networks and several Azure resources in tables (not shown here). You need to measure latency between those resources using connection monitors in Azure Network Watcher. What is the minimum number of connection monitors you must create?
- This is part of a scenario set. You have an Azure Application Gateway with Web Application Firewall (WAF) enabled. The gateway is configured to route requests to the gateway's own URL. When you attempt to browse the URL you get an HTTP 403 response. Diagnostics show the traffic is blocked by a WAF rule with ruleId 920300. To make the URL accessible through the Application Gateway, you disable the WAF rule with ruleId 920300. Does this change achieve the goal?
- To satisfy the virtual network requirements for the virtual machines that need to connect to Vnet4 and Vnet5, which implementation should you deploy?
- Two virtual networks in East US are peered. Each virtual network contains four subnets. You will deploy a single virtual machine VM1 that must inspect and route traffic between every subnet across both virtual networks. What is the minimum number of IP addresses you must assign to VM1?
- Users on a workstation HP1 access App1 by using the URL https://app1.contoso.com. You need to ensure the intrusion detection and prevention system (IDPS) on FW1 can detect threats in connections from HP1 to Server1. Which two actions should you perform? (Choose two.)
- Virtual machines need to access three resources—storage1, storage2, and DB1—using service endpoints. Assuming storage1 and storage2 are Azure Storage accounts and DB1 is an Azure SQL resource, what is the minimum number of distinct service endpoints you must create?
- VNet1 (10 web-server VMs) is peered with VNet2 (5 database-server VMs). You must enforce: database servers accept connections only from the web servers; web servers initiate connections only to the database servers; all NSGs are associated only with subnets; and use application security groups (ASGs) to implement the controls. What is the minimum number of application security groups required?
- VNet1 contains an Azure Firewall (FW1) and 150 virtual machines. VNet1 is linked to a private DNS zone contoso.com, and all VMs are registered in that zone. VNet1 is connected to on-premises via ExpressRoute. You need on-premises DNS servers to resolve names in the contoso.com private zone. Which two actions should you take? (Choose two.)
- VNet1 contains multiple subnets (names shown elsewhere). You must deploy an Azure Application Gateway named AppGW1 into VNet1. Which subnet or subnets are valid deployment targets for AppGW1?
- VNet1 contains subnet1 and AzureFirewallSubnet. A public Azure Firewall (FW1) is deployed and RT1 is a route table associated to Subnet1 with a 0.0.0.0/0 route pointing to FW1. After deploying 10 Windows Server VMs into Subnet1, none of them were activated. To allow the VMs to activate, what should you do?
- VNet1 has a subnet named Subnet1. You must ensure that the resources connected to Subnet1 can access only storage1 and storage3 while minimizing administrative overhead. Which configuration should you implement?
- VNet1 hosts an Azure Virtual Desktop host pool named Pool1. You need to ensure all outbound traffic from Pool1 passes through Azure Firewall and that TLS inspection is applied. Which two resources must you configure? (Each correct answer is one point.)
- VNet1's virtual machines must be able to access only Azure SQL resources in the East US region and must be prevented from accessing any Azure Storage resources. Which two outbound NSG rules should you create to meet these requirements? (Choose two.)
- When designing IP addressing for Azure virtual network subnets, which resource type must be assigned IP addresses from the subnet range?
- When planning IP addressing for Azure virtual network subnets, which of the following resource types requires assigning IP addresses within the subnets?
- When planning IP addressing for Azure virtual network subnets, which resource type requires IP addresses assigned from the subnet?
- When planning IP addressing for Azure virtual network subnets, which type of resource requires individual IP addresses assigned within the subnets?
- When planning IP addressing for subnets in Azure virtual networks, which type of resource requires individual IP addresses allocated from the subnet's address range?
- While planning IP addressing for Azure virtual network subnets, which of these resource types must have IP addresses allocated from the subnet?
- Wingtip Toys wants to enable NSG flow logs for all subnets and keep logs for 365 days in the most cost-effective way while retaining query capability for troubleshooting. Which configuration meets the requirements?
- Woodgrove Bank runs a three-tier application: WEB, APP, and DB. Each tier runs on multiple VMs in the same subnet group. The security team wants NSG rules that allow WEB to APP and APP to DB traffic while minimizing the number of NSG rules and future changes as instances scale. Which approach best accomplishes this using Azure features?
- You are deploying two network virtual appliances (NVAs) inside an Azure virtual network to inspect all traffic within the VNet. The solution must provide high availability for the NVAs while minimizing administrative overhead. Which Azure service should you include to meet these requirements?
- You are designing a hub-and-spoke topology using virtual network peering and plan to make VNet1 the hub. The design must allow transitive routing between spokes and maximize network throughput. Which Azure service should you include in the hub?
- You are designing an Azure Point-to-Site (P2S) VPN that will use the OpenVPN protocol. Users will authenticate against your on-premises Active Directory domain. Which additional component should you deploy to validate VPN authentication requests?
- You are designing subnet architecture for Azure virtual networks. Which three of the following resources require their own dedicated subnet? (Choose three.)
- You are planning a Site-to-Site VPN between your on-premises datacenter and an Azure virtual network. Which two resources should be included in your design to support the connection? Each correct answer is part of the solution. (NOTE: Each correct selection is worth one point.)
- You configured storage1 to allow access from the subnet in VNet1 by using a service endpoint. You must ensure you can use that service endpoint to reach the read-only endpoint of storage1 in the paired Azure region. What should you do first?
- You create an Azure subscription and plan to deploy the resources listed. You must add an NSG rule named Rule1 for NSG1 with these requirements: allow the App1 search servers to make outbound HTTP requests to internet services, minimize administrative work when new search servers are added, and follow least privilege. Which source type should you choose for Rule1?
- You created a new ExpressRoute circuit with your service provider and now must provision it. What piece of information must you give to the service provider so they can complete provisioning?
- You created Vnet2 in West US and will peer it with an existing Vnet1 that contains VM1, VM2 and a load balancer LB1. Virtual machines in Vnet2 must be able to reach VM1 and VM2 through LB1. Which action will allow VMs in Vnet2 to connect to VM1 and VM2 via LB1?
- You deployed Azure Application Gateway v2 (AppGw1) into Subnet1 of VNet1 and associated a network security group NSG1 to Subnet1. You want AppGw1 to load balance only traffic that originates from resources inside VNet1 while minimizing impact to AppGw1 functionality. Which rule should you add to NSG1?
- You deployed several web apps configured with private endpoints on VNet1. Which DNS zone will contain the DNS records that the web apps automatically register?
- You have 10 Azure App Service instances hosting the same web app, each deployed in a different Azure region. You need to configure Azure Traffic Manager so that clients are routed to the app instance with the lowest network latency. Which Traffic Manager routing method should you choose?
- You have 10 on-premises sites connected with a third‑party SD‑WAN solution and five Azure virtual networks. You plan to connect the Azure virtual networks and on-premises networks using a single Azure Virtual WAN hub. To allow the Azure Virtual WAN hub to act as a node within the third‑party SD‑WAN fabric, what should you deploy?
- You have a hub-and-spoke network where multiple on-premises sites connect to a hub virtual network in Azure using ExpressRoute circuits. An Azure Application Gateway named GW1 serves as the single internet ingress point. You plan to move the hub-and-spoke design to Azure Virtual WAN while preserving a single point of ingress. Which three changes must you include in the migration? Select three.
- You have a network security group named NSG1 and you need to enable NSG flow logs for NSG1. Your solution must support retention policies for the logs. Which resource should you create first?
- You have a private AKS cluster AKS1 connected to VNet1, and VNet1 is connected to your on-premises network via ExpressRoute. You need an off-cluster ingress controller for AKS1 that provides connectivity from the on-premises environment to containerized workloads in AKS1. Which Azure service should host the off-cluster ingress?
- You have a resource group RG1 and a virtual network VNet1. You must deploy Azure Firewall into RG1 with minimal administrative effort. What should you do first?
- You have a subnet (Subnet1) that contains three virtual machines hosting an application named App1. App1 is accessed over SFTP. In NSG1 you created an inbound security rule named Rule2 that allows SFTP connections to ASG1. You must ensure that inbound SFTP connections are enforced using ASG1 and minimize administrative effort. What should you do?
- You have a virtual network Vnet1 that contains a virtual machine VM1 and an Azure Firewall FW1. An Azure Firewall Policy named FP1 is associated with FW1. You need to ensure that RDP requests sent to FW1's public IP are forwarded to VM1. What type of rule should you configure in FP1?
- You have a virtual network Vnet1 with 20 subnets and 500 virtual machines. Each subnet contains a virtual machine that runs network monitoring software. An NSG named NSG1 is associated with every subnet. When a new subnet is created, an automated process creates the monitoring VM in that subnet and associates the subnet with NSG1. You need to add an inbound security rule to NSG1 that allows connections from the IP address 131.107.1.15 to the monitoring virtual machines. Requirements: • Only the monitoring virtual machines should receive connections from 131.107.1.15. • When a new subnet is created, you should minimize changes required to NSG1. For the inbound rule, which destination type should you use?
- You have a virtual network VNet1 with these subnets: AzureFirewallSubnet, GatewaySubnet, Subnet1, Subnet2 (delegated to Microsoft.Web/serverfarms), and Subnet3. You must deploy an Application Gateway AG1 with WAF integration to publish VMSS1. To which subnet should you attach AG1?
- You have a website with the FQDN www.contoso.com that currently resolves to an on-premises web server. You will migrate the site to an Azure Web App named Web1, and publish it through an Azure Front Door instance named ContosoFD1. You’ve built the site on Web1 and plan to configure ContosoFD1 for testing without disrupting users who still go to the on-premises server. When you try to add a custom domain for www.contoso.com to ContosoFD1 you receive a verification error. Which DNS record should you add to the contoso.com zone to allow testing without changing the live www.contoso.com record?
- You have an application (App1) that accepts traffic on a fixed set of 50 TCP ports and 50 UDP ports. App1 runs on 10 Azure VMs. You need to load-balance App1 across the VMs while minimizing the number of load-balancing rules you must create. Which of the following should you use?
- You have an Application Gateway named AppGW1 that forwards requests to a backend web app App1. You need to change or add server variables in the HTTP response headers returned by App1. Which Application Gateway configuration item should you modify?
- You have an Application Gateway with the Web Application Firewall (WAF) enabled. The gateway is configured to route traffic to its own URL, but when you try to open that URL you receive HTTP 403 and the diagnostics indicate WAF blocking. You need the URL to be reachable through the application gateway from any client IP. The proposed solution is to configure a custom cookie and add an exclusion rule. Does this solution achieve the requirement?
- You have an Application Gateway with WAF enabled. The gateway is configured to route traffic to its own URL, but accessing that URL returns HTTP 403 and diagnostics show WAF blocking. You propose adding a rewrite rule that changes the Host header. Will adding a rewrite rule for the Host header ensure the URL is accessible through the application gateway from any client IP?
- You have an Azure App Service web app WebApp1 and an Azure Front Door profile FDProfile1 that forwards requests for https://www.contoso.com to WebApp1. You need to ensure only requests matching https://www.contoso.com/users/* are forwarded to WebApp1. Which part of FDProfile1 should you change?
- You have an Azure Application Gateway configured for a single site at https://www.contoso.com. The gateway has one backend pool with two backend servers and a single routing rule. Each backend server also hosts another site that listens on port 8080. You must ensure that if port 8080 on one backend server becomes unavailable, all traffic for https://www.contoso.com is sent to the remaining healthy backend server. What should you configure?
- You have an Azure Application Gateway that load-balances traffic to a web app named App1 and you require end-to-end encryption (TLS) from client to backend. You configured an HTTPS listener by uploading an enterprise-signed certificate to the listener. What additional step is required so the Application Gateway can terminate and then establish TLS to the App1 backend (end-to-end encryption)?
- You have an Azure Front Door instance (FD1) configured as shown. Before enabling Azure Private Link for FD1, what is the first action you must take?
- You have an Azure Front Door Premium profile AFD1 associated with a WAF policy WAF1. You need to apply a rate limit on incoming requests to AFD1. Solution: Create a custom rule in WAF1. Does this meet the requirement?
- You have an Azure Front Door Premium profile AFD1 associated with an Azure WAF policy WAF1. You must configure rate limiting for requests to AFD1. Solution: Change the policy settings of WAF1. Does this achieve the requirement?
- You have an Azure Front Door with a single frontend host Frontend1 and an associated WAF policy Policy1. Policy1 currently redirects requests containing a header value "string1" to https://www.contoso.com/redirect1. You need to add a rule so that requests containing a header value "string2" are redirected to https://www.contoso.com/redirect2. Which three steps should you take? (Choose three.)
- You have an Azure Load Balancer (LB2) with backend pools shown in the exhibit; VM scale set VMSS1 exists but LB2 is not sending traffic to all VMSS1 instances. What two actions will ensure LB2 distributes traffic to every instance in VMSS1? (Choose two.)
- You have an Azure subscription with a user named Admin1 and a resource group RG1. RG1 contains an Azure Network Watcher instance named NW1. You must allow Admin1 to place a lock on NW1 while following the principle of least privilege. Which built-in role should you assign to Admin1?
- You have an Azure subscription with a virtual network named VNet1 that contains a subnet called Subnet1. You plan to create a private endpoint in Subnet1. To be able to route traffic between the private endpoint and the Azure Private Link service using a user-defined route (UDR), what must you do first on Subnet1?
- You have an Azure subscription with an Azure Front Door Premium profile named AFD1 that is associated with an Azure Web Application Firewall policy named WAF1. You need to enforce a rate limit on incoming requests to AFD1. Solution: Configure a managed rule in WAF1. Does this meet the goal?
- You have an Azure subscription with an Azure Virtual WAN named VWAN1 that contains a hub Hub1. Hub1 currently has a security status of Unsecured. You need Hub1's security status to be Secured. Solution: Deploy an Azure Front Door profile. Does this satisfy the requirement?
- You have an Azure virtual network (Vnet1) and an on-premises network with policy-based VPN devices. In Vnet1 you deployed a virtual network gateway named GW1 using SKU VpnGw1 and configured as route-based. Before creating the Site-to-Site connection so the on-premises network can connect to the route-based GW1, what must you configure?
- You have an Azure virtual network named Vnet1 that contains a single subnet. Vnet1 and an Azure App Service app named App1 are both deployed to the West Europe region. You must give App1 access to resources in Vnet1 while keeping costs as low as possible. What should you do first?
- You have an Azure Virtual WAN hub Hub1 in VWAN1 with a security status of Unsecured. You need to change Hub1's status to Secured. Solution: Deploy Azure Firewall. Does this meet the requirement?
- You have an Azure VM named VM1 and need to capture all of its network traffic using Azure Network Watcher. To which destinations can the capture be written?
- You have an ExpressRoute Standard gateway named GW1. You need to upgrade GW1 so it supports ExpressRoute FastPath while minimizing downtime. Which gateway SKU should you choose for the upgrade?
- You have an internal Basic Azure Load Balancer named LB1 that has two frontend IP addresses. The backend pool contains two virtual machines, VM1 and VM2. For the load-balancing rules on LB1, which setting should you choose?
- You have an on-premises datacenter in Seattle and an Azure subscription that contains a Network Watcher resource in West US 2. You must document latency between your datacenter and West US 2 and between your datacenter and the East US 2 public Azure region while minimizing administrative effort. What should you do first?
- You have an on-premises DNS server Server1 hosting fabrikam.com. Virtual networks connect to on-premises via S2S VPNs. You must deploy Azure DNS Private Resolver so: virtual network resources can resolve fabrikam.com, Server1 can resolve contoso.com, and costs/administrative effort are minimized. What is the minimum number of resolvers required?
- You have an on-premises Windows Server named Server1 and an Azure subscription with a virtual network named VNet1. You plan to connect Server1 to VNet1 by using Azure Network Adapter. To minimize the time required to deploy the adapter to Server1, which resource should you create first?
- You have Azure Front Door Premium profile AFD1 linked to WAF policy WAF1. You must enforce a request rate limit for AFD1. Solution: Add a rule to AFD1's rule set. Does this meet the goal?
- You have Azure Front Door with a Web Application Firewall (WAF). You want to create a WAF rule that blocks high request rates from a single IP address and need to examine Log Analytics to determine an appropriate threshold. Which Log Analytics table should you query?
- You have five Windows Server VMs, each hosting a different web application. You plan to use an Azure Application Gateway to serve all apps using the same hostname (www.contoso.com) and distinct URL paths (for example, https://www.contoso.com/app1 for the first app). You need to route traffic based on the URL path. Which Application Gateway configuration should you create or modify?
- You have multiple virtual machines in the West US region and want to enable Traffic Analytics. Which two Azure resources must you create to use Traffic Analytics? (Choose two.)
- You have on-premises networks connected to an Azure Virtual WAN (VWAN1) and VNet1. VWAN1 is in a full-mesh with the on-premises sites and VNet1. The virtual hub routing preference for VWAN1 is AS Path. To route traffic from VNet1 to 10.61.1.5, which path will the traffic take?
- You have resources in an Azure subscription. Configure FW1 so it filters traffic that originates from VNet1 and is destined to the fully qualified domain name (FQDN) of SQLDB1. Which type of Azure Firewall rule should you create?
- You have several App Service apps deployed in the West US region (details shown in a table). You need to ensure every app can access resources in a virtual network named VNet1 without routing traffic over the internet. How many integration subnets must you create?
- You have several virtual networks; each virtual network contains 20 internet-accessible resources assigned public IP addresses. You need to protect these resources using Azure DDoS Network Protection while minimizing cost. What is the minimum number of DDoS Network Protection plans you should deploy?
- You have the virtual machines shown in the provided resources table. You must protect these VMs using Azure DDoS Network Protection plans. What is the minimum number of DDoS Network Protection plans required?
- You have three on-premises networks connected to a Basic Azure Virtual WAN that contains one virtual hub and a VPN gateway limited to 1 Gbps throughput. Site-to-Site VPN connections from on-premises use this Virtual WAN. You must increase total throughput to 3 Gbps while minimizing administrative overhead. What should you do?
- You have two subscriptions: Sub1 contains VM1 and Sub2 will host resources that need access to VM1 via Azure Private Link. To enable creation of a Private Link service that exposes VM1 to Sub2, what must you first configure in Sub1?
- You have two virtual networks named VNet1 and VNet2. A Windows 10 client (Client1) connects to VNet1 using a Point-to-Site (P2S) IKEv2 VPN. VNet1 and VNet2 are peered. VNet1 is configured to allow gateway transit and VNet2 is set to use the remote gateway. Client1 cannot reach resources in VNet2. You try resizing the VNet1 gateway to a larger SKU. Does resizing the gateway fix the connectivity issue?
- You have VM1 and VM2 that must be allowed to connect only to storage1 and must be prevented from accessing any other storage accounts. Storage1 must still be reachable from the internet. Which solution should you use?
- You have VNet1 and VNet2. Client1 (Windows 10) connects to VNet1 through a Point-to-Site (P2S) IKEv2 VPN. You peer VNet1 and VNet2. VNet1 allows gateway transit and VNet2 is configured to use the remote gateway. Client1 cannot reach VNet2. Solution: reset the gateway in VNet1. Does this solution achieve the goal?
- You have VWAN1 with a hub Hub1 whose security status is Unsecured. To change Hub1's status to Secured, Solution: Deploy an Azure Web Application Firewall (WAF). Does this satisfy the requirement?
- You have VWAN1 with hub Hub1 marked Unsecured. To mark Hub1 as Secured, Solution: Deploy an Azure NAT Gateway. Does this meet the requirement?
- You must configure gateway GW1 to satisfy the network security requirements for point-to-site (P2S) VPN users. In GW1's Point-to-site configuration, which Tunnel type should you select?
- You must configure the default route on Vnet2 and Vnet3 to meet the virtual networking requirements. Which mechanism should you use to configure that default route?
- You must deploy Azure Traffic Manager so that traffic to https://www.fabrikam.com is directed to App1eu, and if App1eu becomes unresponsive all traffic should fail over to App1us. Which two resources should you create to meet these requirements? (Choose two.)
- You must provide App1 with a private endpoint and ensure internet requests to App1 are routed through Front Door instance FD1. What configuration should you add to FD1 to enable this behavior?
- You need to enable connectivity between Vnet2 and Vnet3 while meeting the virtual networking and business requirements. Which two actions should you perform? (Choose two.)
- You need to provide access to storage1 while satisfying the PaaS networking and business requirements. Which of the following should you include in the design?
- You need to provide access to storage2 and meet the stated PaaS networking and business requirements. Which connectivity method should you choose?
- You plan an Azure deployment that includes three virtual networks in East US. Vnet1 will connect to your on-premises network by a Site-to-Site VPN. To ensure VMs in all three virtual networks can reach the on-premises network while minimizing cost, what should you recommend for Vnet2 and Vnet3?
- You plan an Azure virtual network with 10 IPv6 subnets, each hosting up to 200 load-balanced VMs. Which IPv6 subnet prefix length should you recommend?
- You plan an IPv6-only virtual network with 10 subnets. Each subnet will host up to 200 VMs behind a load balancer. The VMs and the load balancer must be reachable only from inside the virtual network, and you must minimize costs. Which load-balancing solution should you recommend?
- You plan to deploy an Azure Firewall named AF1 into resource group RG1 in the West US region. Given the virtual networks in your subscription (as shown in the scenario table), into which virtual network(s) can AF1 be deployed?
- You plan to deploy an Azure Virtual Network NAT gateway (Gateway1) to VNet1. VM1 and VM2 must each use their own public IP addresses to access the internet, and administrative effort should be minimized. What is the minimum number of subnets that must exist in VNet1 to allow deployment of Gateway1 given these requirements?
- You plan to deploy an Azure Virtual Network NAT gateway named Gateway1 to Vnet1. The requirements are: VM1 must use its own public IP when accessing the internet, VM2 must also use its own public IP, and administrative effort should be minimized. What is the minimum number of subnets that Vnet1 must contain so Gateway1 can be deployed to satisfy these requirements?
- You plan to deploy an Azure VPN gateway in a subscription that contains a virtual network and require 90 Site-to-Site VPN connections. The design must keep those Site-to-Site connections available if a single Azure datacenter fails and must minimize costs. Which VPN gateway SKU should you choose?
- You plan to deploy Azure Firewall Premium, enable all Premium features, and configure both network and application rules. Which rule type does the firewall evaluate first?
- You plan to enable BGP for a Site-to-Site VPN between your datacenter and Azure. Which two Azure resources must you configure to support this BGP-enabled connection? (Choose two.)
- You plan to implement Azure Virtual WAN as shown in the exhibit. What is the minimum number of route tables you must create for this Virtual WAN deployment?
- You plan to implement ExpressRoute FastPath between your on-premises datacenter and Azure. When creating the ExpressRoute gateway, you must minimize downtime in the event of a single Azure datacenter failure. Which ExpressRoute gateway SKU should you use?
- You plan to publish a site at www.contoso.com using two App Service apps (AS1 and AS2). You will use Azure Traffic Manager with a profile named TMprofile1 that uses the Weighted routing method to distribute traffic between AS1 and AS2. To have Traffic Manager handle requests for www.contoso.com, which DNS record should you create for the www.contoso.com name?
- You plan to use Traffic Analytics to monitor application usage on Azure virtual machines. Which Azure Network Watcher capability should you enable first to provide Traffic Analytics data?
- You will deploy an App Service app named App1 and use an existing Azure Front Door FD1 as the only way users should reach App1. Users must not be able to access App1 directly from the internet. What should you configure on App1 to meet these requirements?
- You will deploy an Azure Application Gateway with: 1 public endpoint, 1 private endpoint, minimum instances = 1, maximum instances = 10. VNet1 uses a /24. What is the minimum number of assignable IP addresses the Application Gateway subnet must provide (minimize allocated IPs)?
- Your Azure subscription contains a storage account named storage1 that is deployed in the US East region and currently uses locally-redundant storage (LRS). storage1 has a Microsoft.Storage service endpoint. You changed the redundancy for storage1 to Read-access geo-redundant storage (RA-GRS). You must ensure the contents of storage1 can be accessed via a service endpoint in the paired region while minimizing administrative effort. What should you do first?
- Your Azure subscription includes 100 network security groups (NSGs). You need to capture logs that show when specific NSG rules are applied to traffic. Which type of log should you enable?
- Your Azure subscription is associated with the Azure AD tenant contoso.onmicrosoft.com. The subscription contains: an App Service app named App1, a public DNS zone contoso.com, a private DNS zone private.contoso.com, and a virtual network Vnet1. You create a private endpoint for App1; the private endpoint record is automatically registered in Azure DNS. Which DNS name is registered for the private endpoint?
- Your company has a single on-premises datacenter in Washington, D.C. The East US Azure region has a peering location in Washington, D.C. All Azure resources are in East US. You must implement ExpressRoute supporting up to 1 Gbps, use only ExpressRoute Unlimited data plans, and minimize cost. Which type of ExpressRoute circuit should you create?
- Your company has an office in New York and an Azure subscription containing multiple virtual networks. You must connect those virtual networks to the office using ExpressRoute. Requirements: up to 1 Gbps bandwidth, the office must access all virtual networks, and costs must be minimized. How many ExpressRoute circuits should you provision, and which ExpressRoute SKU should you enable?
- Your company has an on-premises network and three Azure subscriptions (Subscription1, Subscription2, Subscription3). All resources are deployed only in West US or West US 2. You plan to connect all three subscriptions to the on-premises network using ExpressRoute. What is the minimum number of ExpressRoute circuits required?
- Your company has four branch offices that each connect to an Azure VPN gateway named GW1 using Site-to-Site VPNs; each branch router also provides internet access. Users in Branch1 can reach internet sites but cannot access Azure resources. You must restore Branch1 users' access to Azure while minimizing user downtime and administrative effort. What should you do first?
- Your company has offices in London, Tokyo, and New York. A Traffic Manager profile is configured as shown. You plan to deploy an additional endpoint in Asia that will host an updated version of App1. During testing you need to route 10% of traffic originating from the Tokyo office to this new endpoint. What Traffic Manager configuration should you use?
- Your company has offices in New York and Amsterdam. Both offices already use Site-to-Site VPN to connect to Azure. Amsterdam uses resources in North Europe; New York uses resources in East US. You will deploy ExpressRoute circuits from each office to the nearest Azure region. After these circuits are connected, on-premises computers in Amsterdam must be able to reach on-premises servers in New York over ExpressRoute. Which ExpressRoute capability should you use?
- Your company offices in Montreal, Seattle, and Paris each send outbound traffic from fixed public IP addresses. Front Door FD1 uses a WAF policy Policy1 that contains Rule1 enforcing a rate limit of 100 requests for traffic originating from Montreal. You must enforce the same 100-request rate limit for traffic that originates from each of the other offices as well. What should you change to apply the rate limit for each office?
- Your environment uses ExpressRoute to connect on-premises and Azure. You need to periodically record uptime and latency of the connection using a VM in Azure and a VM on-premises. Which tool should you use?
- Your on-premises datacenter Site1 has a firewall FW1 that provides internet connectivity. In Azure you have a virtual WAN (VWAN1) and a hub (Hub1). You plan a site-to-site connection from Site1 to Hub1 and need to configure the connection to FW1. What should you create in VWAN1 to represent the on-premises Site1 for the site-to-site connection?
- Your on-premises network has a DNS server named Server1. An S2S VPN connects the on-premises network to VNet1 in your Azure subscription. You need Server1 to resolve the DNS name of storage1 in Azure while keeping cost and administrative overhead to a minimum. Which solution should you use?
- Your organization has five offices, each with a local internet connection and a firewall device. The offices currently connect through a third-party SD-WAN. In Azure you have VNet1 with a virtual network gateway (Gateway1), and each office connects to Gateway1 via Site-to-Site VPN. You need to replace the third-party SD-WAN with Azure Virtual WAN. Which action should you include in the migration plan?
- Your organization uses an SD-WAN across 40 branch offices that runs BGP. In Azure you have 20 virtual networks in a hub-and-spoke layout; the hub virtual network Vnet1 connects to the SD-WAN through a network virtual appliance (NVA) deployed in Vnet1. To allow BGP route advertisements to propagate between the Azure virtual networks and the SD-WAN with minimal administrative overhead, which solution should you implement?
- Your subscription contains a VM named VM1 that has a single NIC (NIC1) associated with an NSG named NSG1 (default rules present). VM1 runs Windows Server 2022. You need to block access from VM1 to the Azure Instance Metadata Service (IMDS) REST API while minimizing administrative overhead. What should you add to NSG1?
- Your subscription contains an Azure App Service app that uses the hostname https://www.contoso.com. You must configure a custom domain on Azure Front Door for www.contoso.com, and the custom domain must use a certificate issued by an allowed certification authority (CA). Which service or component should you include in the solution to supply or manage the required certificate?
- Your subscription contains an Azure Firewall Standard instance named AzFW1. You plan to enable the following features: TLS inspection, Threat intelligence, and a network intrusion detection and prevention system (IDPS). Which of these can you enable with AzFW1?
- Your subscription contains several public IP addresses (listed in a table). You plan to deploy a NAT gateway named NAT1. Which of the listed public IP addresses can be used as the public IP address for NAT1?
- Your subscription contains several public IPv4 addresses (IP1, IP2, IP3, IP4, IP5). You plan to create a Standard SKU, public Azure Load Balancer named LB1 in West US. Which of the listed public IPv4 addresses can be assigned to LB1?
- Your subscription contains VM1 and a private endpoint for azsql1.database.windows.net. You need to ensure the apps on VM1 can resolve the private endpoint's IP address. Which DNS zone should you create first?
- Your subscription contains VNet1 with subnet1 and AzureFirewallSubnet, a public Azure Firewall FW1, and a route table RT1 associated to subnet1 containing a 0.0.0.0/0 route to FW1. After deploying 10 Windows Server VMs to subnet1, none of the VM OSes activated. What should you do to allow the virtual machines to activate?
- Your subscription contains Vnet1 with subnets Subnet1 and AzureFirewallSubnet, a public Azure Firewall FW1, and a route table RT1 associated to Subnet1 that routes 0.0.0.0/0 to FW1. After you deploy 10 Windows Server VMs to Subnet1, none of the VMs activated. What change will allow the VMs to complete Windows activation?
- Your subscription contains: VNet Vnet1 with subnets subnet1 and AzureFirewallSubnet, a public Azure Firewall FW1, and route table RT1 associated to subnet1 with a 0.0.0.0/0 route pointing to FW1. After you deploy 10 Windows Server VMs into subnet1, none of the VMs successfully activate (Windows activation fails). What should you do to allow the VMs to activate?
Microsoft Azure Security Engineer Associate AZ-500 Certification All exam questions
- A developer receives an error when trying to register an app in the tenant. What tenant setting should you change so the developer can register the app?
- A mobile application uses the OAuth 2.0 implicit grant to obtain Azure AD access tokens. What information should you obtain from the developer to register the application in Azure AD?
- A new company policy requires all Azure virtual machines in the subscription to use managed disks. Prevent users from creating virtual machines that use unmanaged disks. Which service should you use?
- A newly created Azure subscription needs a specific user to be able to configure Azure AD Privileged Identity Management (PIM). Which role should you assign to that user?
- A PIM user assigned the User Access Administrator role receives authorization errors when managing role assignments. To resolve this, which role should be assigned to the PIM service principal on the subscription, following least privilege?
- A resource group contains 100 virtual machines. An initiative named Initiative1, which contains multiple policy definitions, is assigned to the resource group. To determine which resources do NOT match the policy definitions in Initiative1, which action should you take?
- A user with the User administrator role attempts to invite an external partner who signs in with a Microsoft account (user1@outlook.com) and receives the error: "Unable to invite user user1@outlook.com Generic authorization exception." What change allows the User administrator to invite the external partner?
- A virtual network contains several subnets and your subscription contains multiple virtual machines (details in the tables). You enabled Just-In-Time (JIT) VM access for all virtual machines. Based on the provided subnet and VM configuration, which virtual machines are protected by JIT?
- A VM deployed from an ARM template is listed as Unsupported on the Just-in-time (JIT) VM access blade in Azure Security Center. An administrator reports they cannot enable JIT for the VM. What should you do to allow JIT VM access to be enabled?
- Admin1 (assigned the Application developer role) registered a purchased cloud app App1 but cannot enable token encryption for the app in the Azure portal. What must be done so Admin1 can enable token encryption for App1?
- Advanced Threat Protection is enabled for an Azure SQL Database server and configured to detect all threat types. If an application generates a malformed SQL statement in the database, which alert will be triggered?
- After creating a new Azure subscription, synced on-premises user accounts cannot be assigned roles in that subscription. To enable assigning Azure and Microsoft 365 roles to those synced accounts, what should you do first?
- After creating a new Defender EASM instance to discover externally facing assets, what is the next action you should take?
- After creating an Azure subscription and an Azure Storage account, what additional action is required to enable creation of custom alert rules in Azure Security Center?
- After disabling HTTP application routing in an AKS cluster, you need a replacement that provides reverse proxy and TLS termination for AKS services using a single IP address. Which of the following should you create?
- After enabling Azure Storage Analytics and archiving the logs to a storage account, which tool should you use to retrieve those diagnostics logs?
- After enabling diagnostic logging for an Azure Storage account, which tool should you use to retrieve the storage diagnostics logs?
- After registering an enterprise application in a subscription linked to an Azure AD tenant, which additional Azure AD resource is automatically created?
- After synchronizing on-premises identities to Azure AD, you must prevent users whose givenName attribute begins with "LAB" from syncing. Which action should you take?
- AKS1 cannot be accessed using accounts from the Contoso.com Microsoft Entra tenant. To enable access by Contoso.com accounts with minimal administrative effort, what should you do first?
- All users have Windows 10 devices that are hybrid Azure AD joined. An Azure SQL database supports Azure AD authentication. Developers will connect from SQL Server Management Studio using their on-premises Active Directory accounts and you must minimize authentication prompts. Which authentication method should they use?
- An administrator (Admin1) has the following account types: an OpenID-enabled user account, a Hotmail account, an account in contoso.com, and an account in an Azure AD tenant fabrikam.com. You plan to transfer ownership of the subscription Sub1 to Admin1 using Azure Account Center. To which accounts can ownership of Sub1 be transferred?
- An AKS cluster will connect to an Azure Container Registry. Use the AKS cluster's automatically generated service principal to authenticate to the registry. What resource should you create to enable this authentication?
- An application registered in Azure AD must access Azure Key Vault secrets on behalf of users. If you configure a delegated permission and grant admin consent, does this meet the requirement?
- An Azure AD tenant contains a group named Group1. You must ensure that members of Group1 sign in using passwordless authentication. What should you configure?
- An Azure AD tenant contains several users. You must prevent the users from creating app passwords, while ensuring that User1 can continue to use the Mail and Calendar app. What should you do?
- An Azure Files share named share1 is configured for identity-based authentication. User1 connects to share1 from a Windows 10 device using SMB. Which type of token will Azure Files use to authorize the request?
- An Azure Key Vault contains customer-managed keys and a Storage account is configured to use those keys. Which two Azure Storage services support encryption using keys stored in the Key Vault?
- An Azure SQL database uses Always Encrypted. What two items must you provide application developers so they can retrieve and decrypt the data?
- An Azure SQL logical server named SQL1 and a virtual machine VM1 (which uses only a private IP) exist. The firewall and virtual network settings for SQL1 are configured as shown. To allow VM1 to connect to SQL1 while adhering to the principle of least privilege, what should you do?
- An Azure subscription contains several virtual machines across peered virtual networks. Azure Bastion is deployed to VNET2. Which virtual machines can be protected by the Bastion host?
- An Azure subscription contains User1 and an Azure Container Registry named ContReg1. Content trust is enabled for ContReg1. To allow User1 to create trusted images in ContReg1 using least privilege, which two roles should you assign to User1? (Choose two.)
- An Azure Web App connects to an Azure Cosmos DB account Cosmos1 through a private endpoint named Endpoint1 that uses default settings. To validate name resolution for Cosmos1, which DNS zone should you query?
- An on-premises Hyper-V VM named VM1 will be onboarded to Defender for Cloud via Azure Arc. Which agent must be installed first on VM1?
- App1 is registered in Azure AD. You need App1 to access Azure Key Vault secrets on behalf of application users. What permission configuration is required?
- App1 needs permission to read all user calendars and create appointments. To grant least-privilege access via the app registration, what should you add?
- App1 serves product images from Pool1 and product videos from Pool2. To minimize TLS processing on Pool1 and Pool2 and route requests to pools based on request path, which service should you include?
- Azure Container Registry ContReg1 stores a container image named image1. After enabling content trust, you push two images to ContReg1 as shown. Which of the pushed images are trusted images?
- Azure Defender for SQL is enabled on SQL1 with all threat detection types turned on. Which of the following actions will Defender for SQL flag as a threat?
- Azure Storage Analytics logging is enabled and the logs are archived to a storage account. Which tool should you use to retrieve those archived diagnostics logs?
- Azure Storage Analytics logging was enabled and archived to a storage account. Which tool should you use to retrieve the archived diagnostics logs?
- Based on the provided list of computers, which of them can be scanned by Microsoft Defender for Cloud's vulnerability scanning feature?
- Before creating a workflow automation in Microsoft Defender for Cloud (Azure Security Center) to automatically remediate a vulnerability, which resource should you create first?
- Before creating security alerts with Azure Monitor in the subscription, which Azure resource should you create first?
- Before deploying an application that will modify Azure AD user properties via Microsoft Graph, what should you configure first so the app can access Azure AD?
- Before deploying SecPol1 from Microsoft Defender for Cloud, what should you do first?
- Configure WebApp1 to satisfy the application's data and operational requirements. Which two actions should you perform?
- Construct an Azure Log Analytics query that finds failed user sign-in attempts from the last several days and returns only users with more than five failed attempts. Which elements should be included in the query?
- Decide whether the following statement is correct: A mobile application that obtains Azure AD access tokens using the OAuth 2.0 implicit grant must be registered in Azure AD and requires a redirect URI for registration. If the statement is correct, select 'No adjustment required'; otherwise select the correction.
- Events from Azure virtual machines are collected into an Azure Log Analytics workspace and you plan to create alerts based on those events. Which two Azure services can be used to create alerts from the collected data?
- For an AWS account already connected to Defender for Cloud, how should you enable AWS Foundational Security Best Practices while minimizing administrative effort?
- For cross-tenant B2B collaboration between contoso.com and fabrikam.com, which of fabrikam.com's identity providers support cross-tenant access?
- From Azure Security Center you enable Auto Provisioning. After deploying the virtual machines shown in the following table, on which virtual machines is the Log Analytics Agent installed?
- From Azure Security Center you enable Auto Provisioning. After deploying the virtual machines shown in the following table, on which virtual machines is the Microsoft Monitoring Agent installed?
- Given the Azure virtual machines listed in the accompanying table, for which virtual machines can you enable Update Management?
- Given the list of users in the referenced table, which users can enable Azure AD Privileged Identity Management (PIM)?
- Given the listed subscription resources, which combination can be protected by Azure Defender?
- Given the management group hierarchy and the created definitions (Policy1, Initiative1, Initiative2, Initiative3), which of these definitions can be added as a Defender for Cloud security policy?
- Given the policy definitions available in the subscription, which definitions can be assigned as a Defender for Cloud security policy?
- Given the requirements that internet-facing virtual machines must be protected by network security groups and all virtual machines must have disk encryption enabled, what is the minimum number of Microsoft Defender for Cloud security policies required?
- Given the subscription state shown and the plan to enable multi-factor authentication for five subscription owners and five resource owners, by how many points will the secure score increase?
- Given the tenant's App registrations settings and following the principle of least privilege, which role should be assigned to User1 so they can register an application?
- Given VNet1's subnets and the listed virtual machines, for which virtual machines can you enable just-in-time (JIT) VM access while minimizing administrative effort?
- How can you ensure NSG1 permits RDP connections to the virtual machines for no more than 60 minutes when a member of ServerAdmins requests access?
- How can you ensure the virtual machines in resource group RG1 have their Remote Desktop port closed until an authorized user requests temporary access?
- HTTP application routing was disabled on an AKS test cluster. To provide reverse proxy and TLS termination for AKS services using a single IP address, what should you implement?
- Identity1 has key permissions (Get, List, Wrap, Unwrap) on KeyVault1. To grant Identity1 the same key permissions on KeyVault2 using least privilege, which role should you assign?
- In an Azure Sentinel workspace, which two events can trigger a playbook?
- In the contoso.com tenant, you need to allow users to use a selected set of cloud apps from the fabrikam.com tenant. Which setting in the Microsoft Entra admin center should you configure for contoso.com?
- In the Defender EASM Attack Surface Summary dashboard, which section lists deprecated technologies and infrastructure that will soon expire?
- Just-in-time VM access is enabled for all virtual machines. To connect to a VM by using Remote Desktop, what should you do first?
- Multiple development teams will deploy a standard development environment for each team. Recommend a solution that enforces resource locks across those environments and ensures the locks are applied consistently. Which option should you include in the recommendation?
- On virtual machine VM1, Microsoft Defender for Cloud shows a high-severity recommendation: 'Install endpoint protection solutions on virtual machine.' What action should you take to resolve this recommendation for VM1?
- Policy1 is defined at the Tenant Root Group with the Category set to Monitoring. To have resources noncompliant with Policy1 appear in the Microsoft Defender for Cloud / Security Center dashboard, what should you do first?
- Same environment and requirements as above. Solution: use federation with Active Directory Federation Services (AD FS). Does this solution meet the requirements?
- Same environment and requirements as above. Solution: use password hash synchronization and seamless single sign-on. Does this solution meet the requirements?
- Same setup as above. Before deploying containers, you perform the following on the VM: create an AKS Ingress controller. Does this action meet the requirement to allow containers to access Azure Storage and Azure SQL via the subnet's service endpoint?
- Same setup as above. Before deploying containers, you perform the following on the VM: install the container network interface (CNI) plugin. Does this action meet the requirement to allow containers to access Azure Storage and Azure SQL via the subnet's service endpoint?
- ServerAdmins must be allowed to create virtual machines only in resource group RG1 and to connect those VMs to existing virtual networks only in resource group RG2. Using least privilege, which two RBAC role assignments satisfy these requirements?
- Subscription1 and RG1 have the following role assignments: User1 is Network Contributor at the subscription level, and User2 is Contributor for RG1. A policy requiring removal of external accounts with write permissions is assigned to both Subscription1 and RG1. What is the compliance state for each policy assignment?
- The on-premises domain adatum.com syncs to Azure AD and Azure AD Connect is installed on Server1. To allow an adatum.com domain administrator to modify the synchronization settings using least privilege, which Azure AD role should you assign?
- The subscription contains resource group RG1 and the NSGs shown in the table. After assigning the displayed Azure policy to RG1, what will be the flow log status for NSG1 and NSG2?
- The subscription contains VNet1 with the listed subnets and the function apps shown in the table. Which app's outbound traffic is controlled by NSG1?
- To add a custom security recommendation in Defender for Cloud that uses the subscription's custom severity rating, which resource should you create?
- To add Google as an identity provider in Azure AD so users can sign in to App1 with Google, which two pieces of information must you provide?
- To allow User1 to configure contoso.com to use Microsoft Entra Verified ID and to register App1 in contoso.com, which two least-privilege roles should you assign?
- To allow users to access VM0 while meeting platform protection requirements, what action should you take?
- To create a custom sensitivity label, you start by changing the Azure Security Center pricing tier. Does this action enable creation of the custom sensitivity label?
- To create a custom sensitivity label, you start by creating a custom sensitive information type. Does this action enable creation of the custom sensitivity label?
- To create a custom sensitivity label, you start by integrating Azure Security Center with Microsoft Cloud App Security. Does this action enable creation of the custom sensitivity label?
- To enable Azure Security Center vulnerability scanning for ten on-premises Windows Server 2019 machines, which agent should be installed on the servers first?
- To ensure the Microsoft Defender for Servers agent is automatically installed on new AWS EC2 instances, which component should you configure first?
- To investigate security events generated by a Windows Server 2016 virtual machine, which Azure Monitor capability should you use?
- To meet the technical requirements for VNetwork1, what should you do first?
- To review regulatory compliance against the Azure CIS 1.4.0 standard in Defender for Cloud while minimizing administrative effort, what should you do first?
- To secure Azure AD roles using Azure AD Privileged Identity Management (PIM) in a new subscription, what should you do first?
- Two virtual machines, VirMac1 and VirMac2, are Stopped (Deallocated). VirMac1 is in ResGroup1 and VirMac2 is in ResGroup2. ResGroup1 has an Azure Policy using the virtualMachines resource type with the definition 'Not allowed resource types'. ResGroup2 has an Azure Policy using the virtualMachines resource type with the definition 'Allowed resource types'. You apply a Read-only resource lock to VirMac1 and a Read-only resource lock to ResGroup2. Which of the following statements are true? (Choose all that apply.)
- User1 is eligible for the Billing administrator role in Azure AD Privileged Identity Management. To ensure the role can only be used for up to two hours, which action should you take?
- Vault1 must allow access only from VM1, which is connected to VNet1. In Vault1's Networking settings, which action restricts access to only VM1?
- VM1 and VM2 are connected to VNET1 and use NSG1. You need to ensure that only VM1 and VM2 can access DB1. What should you do?
- WebApp1 (West US) uses VNet integration with outbound subnet Subnet11 and runs on ASP1. You will deploy WebApp2 (West US) on the same plan with VNet integration enabled. To which subnet(s) can you integrate WebApp2?
- WebApp1 uses OAuth 2.0 client secrets and Application Insights. Developers will run multi-step synthetic web tests that emulate user traffic and must run unattended. What should you do first to allow the web tests to run unattended?
- WF1 is a Defender for Cloud workflow automation that currently sends email to User1. You need to modify WF1 so it sends email to a distribution group named Alerts. Which tool should you use to edit WF1?
- What should you do first to allow User2 to implement Privileged Identity Management (PIM)?
- When configuring an Azure Kubernetes Service (AKS) cluster to connect to an Azure Container Registry, you want the cluster to use its auto-generated service principal to authenticate to the registry. What should you create?
- When configuring Conditional Access risk policies, which risk level should be assigned for users with leaked credentials?
- When configuring Conditional Access risk policies, which risk level should be assigned for sign-ins originating from IP addresses with suspicious activity?
- When configuring the Intranet Zone via Group Policy for users to support Azure AD SSO, which GPO setting should you configure?
- When creating a custom RBAC role that grants read access to an Azure Storage account, which property in the role definition must be configured?
- When creating a scheduled query rule in Azure Sentinel (Rule1), which language or query format defines the rule logic?
- Which action should you perform first to meet the security operations requirements?
- Which authentication method should you include to require number matching and display the sign-in geographical location?
- Which Azure Monitor feature should you use to identify the user account that deleted a virtual machine 15 days ago?
- Which Azure Security Center pricing tier is required to allow modification of operating system security configurations?
- Which Azure service can identify Azure configurations and workloads that are non-compliant with ISO 27001:2013 requirements?
- Which Azure solution should you use to map external infrastructure and perform vulnerability scanning for ASNs, hostnames, IP addresses, and SSL certificates?
- Which Defender External Attack Surface Management (EASM) dashboard shows inventory assets vulnerable to the most critical web application security risks?
- Which feature should you configure to prevent users from creating passwords that contain variations of the word "contoso"?
- Which least-privilege role should be assigned to User1 so they can create groups, create access reviews for role-assignable groups, and assign Azure AD roles to groups?
- Which mechanism should you use to grant User1 time-limited access to the blob container blob1 that expires after six days?
- Which of the following statements about Azure DevOps branch policies are true? (Select all that apply.)
- Which of the listed resources can be assigned the Contributor role for VM1?
- Which role grants a user only the permissions required to download images from an Azure Container Registry?
- Which role grants a user only the permissions required to upload images to an Azure Container Registry?
- Which setting in CAPolicy1 should you modify to meet the finance department's technical requirements?
- Which virtual machines support Just-In-Time (JIT) VM access?
- While configuring an Azure policy in the Azure portal, you need to include an effect that requires a managed identity to be assigned. Which effect requires a managed identity?
- While troubleshooting a security issue for an Azure Storage account you enable diagnostic logs. Which tool should you use to retrieve the diagnostic logs?
- While troubleshooting a storage account, you enabled Azure Storage Analytics and archived logs to a storage account. Which tool should you use to retrieve the archived diagnostics logs?
- You are creating an access review within a new review set and must allow resource owners to perform the reviews. After creating the access review program and control, what should you set for the Reviewers setting?
- You are creating an Azure Key Vault by using PowerShell and must ensure that deleted objects are retained for 90 days. Which two parameters must you specify to meet this requirement? (Choose two.)
- You are creating an Azure Kubernetes Service (AKS) cluster that must access an Azure Container Registry. You want the AKS cluster to authenticate to the registry using the cluster's auto-generated service principal. Solution: create an Azure Active Directory role assignment. Does this solution meet the requirement?
- You are migrating an on-premises web app that uses a custom public hostname to Azure and will keep that hostname. To enable HTTPS on the Azure web app, what should you do first with the certificate from the on-premises server?
- You are the Global Administrator for the contoso.com tenant and you manage Azure Security Center settings. You need to create a custom sensitivity label. What should you do?
- You change an Azure subscription to use a different Azure Active Directory (Azure AD) tenant. Which two effects can occur?
- You create a custom role named Role1 for the contoso.com Azure AD tenant. At which scopes can Role1 be used for delegating permissions?
- You create a new Azure subscription. To be able to create custom alert rules in Azure Security Center, which two actions must you perform?
- You created a custom alert rule in Azure Security Center. You need to specify which users receive email notifications when the alert triggers. What should you configure?
- You created a Log Analytics workspace named Analytics1 in resource group RG1 in the East US region. Given the information about the virtual machines (shown in the table), which virtual machines can be enrolled in Analytics1?
- You created a virtual machine named VM1 (DS2v2, RG1, West Europe, Windows Server 2016). You plan to enable Azure Disk Encryption on VM1. In which of the listed key vaults can you store the encryption key for VM1?
- You created an Azure DDoS Protection plan named DDoS1 in the West US region. Given the listed resources in the subscription, which resources can you add to DDoS1?
- You created an Azure Key Vault named Vault5 (West US, resource group RG1). You must use Vault5 to enable Azure Disk Encryption on VM1 and ensure the VM can be backed up using Azure Backup. Which Key Vault setting should you configure?
- You created an Azure policy and assigned it to RG1. If you instead assign that policy directly to NSG1 and NSG2, what will occur?
- You created an Azure Web App named Contoso1812 on an S1 App Service plan and will add a CNAME record for a custom public hostname. To enable HTTPS access through that hostname, which two actions should you perform?
- You created storage1 and plan to store data in Azure Files, Blob storage, Table storage, and Queue storage. For which two services can you configure encryption using keys stored in an Azure Key Vault?
- You deploy Azure virtual machines using Azure Resource Manager templates. You need a solution that automatically disables unused Windows features as each VM instance is provisioned. Which option should you use?
- You deploy Windows virtual machines using Azure Resource Manager templates and need unused Windows features to be automatically disabled during provisioning. Which action should you use?
- You deployed a Linux virtual machine named VM1. Which tool or extension should you use to collect and monitor metrics and logs from VM1?
- You deployed an Azure virtual machine named VM1 to inspect network traffic. Ensure that all network traffic is routed through VM1. Which configuration should you apply?
- You enabled diagnostic logging for an Azure Storage account. Which tool should you use to retrieve the diagnostic logs?
- You have 10 virtual machines on a single subnet protected by one network security group (NSG). You need to log the network traffic to an Azure Storage account. What should you do?
- You have 100 virtual machines with Azure Defender enabled and plan to deploy the vulnerability scanner extension to each VM using an Azure Resource Manager template. Which two values should you include in the deployment code? (Choose two.)
- You have 15 identical Azure virtual machines in resource group RG1. Prevent unauthorized applications and malware from running on these VMs. Which action should you take?
- You have a Blob storage account named blob1 and need to configure attribute-based access control (ABAC) for it. Which attributes can be used in access conditions for blob1?
- You have a hybrid Azure AD environment with SSO enabled and an Azure SQL Database configured for Azure AD authentication. Developers on domain-joined devices must connect using their on-premises AD accounts with minimal authentication prompts. Which authentication method should they use in SQL Server Management Studio?
- You have a Microsoft Entra tenant named contoso.com and a partner tenant named fabrikam.com. Ensure that when a user from fabrikam.com accesses resources in contoso.com they see only one Microsoft Entra Multi-Factor Authentication (MFA) prompt while minimizing administrative effort. What should you do?
- You have a Standard Key Vault containing a 2048-bit RSA key. To ensure that this key is rotated every 90 days, what should you do first?
- You have a storage account named storage1 and two web apps named app1 and app2. Both apps will write data to storage1. Ensure that each app can read only the data it has written. What should you do?
- You have a subscription that contains a user named User1. You need to allow User1 to create managed identities while applying the principle of least privilege. What should you do?
- You have a virtual network VNet1 with a single subnet and a VM named VM1 connected to it. You plan to deploy an Azure SQL Managed Instance named SQL1. Which three components should you create so VM1 can access SQL1?
- You have a web app named WebApp1 and a web application firewall policy named WAF1. What should you deploy first to protect WebApp1 with the WAF policy?
- You have accounts for Alibaba Cloud, AWS, and Google Cloud Platform. Which of these cloud provider accounts can be integrated into Defender for Cloud?
- You have an AKS cluster AKS1 and a container registry with images that were pushed by Azure DevOps Microsoft-hosted agents. You need administrators to be able to access AKS1 only from specified networks while minimizing administrative effort. What should you configure for AKS1?
- You have an Azure Active Directory tenant and a root management group. Ten subscriptions are added to the root management group. Before creating an Azure Blueprints definition that will be stored at the root management group level, which action must you perform first?
- You have an Azure AD tenant named Contoso.com and an AKS cluster named AKS1. AKS1 is not accessible using accounts from Contoso.com. To allow Contoso.com accounts to access AKS1 while minimizing administrative effort, what should you do first?
- You have an Azure AD tenant named contoso.com. You must configure diagnostic settings to retain logs for two years, query logs using Kusto Query Language, and minimize administrative effort. Where should you store the logs?
- You have an Azure Data Lake Storage Gen2 account named storage1 and an Azure Synapse workspace named synapsews1 deployed to a managed virtual network. To allow synapsews1 to access storage1, which networking construct should you configure?
- You have an Azure key vault named Vault1 and a VM named VM1 that has the Key Vault VM extension installed. After you rotate keys, secrets, and certificates in Vault1, which items on VM1 will be updated automatically?
- You have an Azure Log Analytics workspace collecting security-related performance counters from on-premises servers. You need alert rules that support dimensions, minimize creation time, and send a single notification both when the alert fires and when it is resolved. Which signal type should you use when creating the alert rules?
- You have an Azure Log Analytics workspace that collects security-related performance counters from 100 on-premises Windows servers. You must create alerts that support dimensions, minimize time to generate an alert, and produce a single notification when the alert is created and one when it is resolved. Which signal type should you use for the alert rules?
- You have an Azure subscription and you want to view which security settings are applied to the subscription by default. Which Azure policy or initiative definition should you review?
- You have an Azure subscription containing resources shown in a table. Which initiatives and policies can you add to the subscription using Azure Security Center?
- You have an Azure subscription linked to an Azure AD tenant licensed with Azure AD Premium P1. You plan to enable Azure AD Identity Protection so you can configure a user risk policy and a sign-in risk policy. What must you do first?
- You have an Azure subscription Sub1 with VNet1 and Subnet1 containing an Ubuntu Server 18.04 VM (VM1). A service endpoint for Microsoft.Storage is created on Subnet1. Before deploying Docker containers to VM1, what must you do so containers can access Azure Storage via the service endpoint?
- You have an Azure subscription that contains resources shown in a table. You plan to enable Microsoft Defender for Cloud. Which of the listed resources can be protected by Defender for Cloud?
- You have an Azure subscription with an Azure Key Vault named Vault1 that contains a secret named Secret1. An application is registered in Azure Active Directory. Which action grants the application permission to use Secret1?
- You have an Azure subscription with existing resources and plan to deploy several virtual machines. Assign managed identities to the virtual machines so that each VM receives only the roles it requires, following the principle of least privilege. What is the minimum number of managed identities required?
- You have an Azure subscription with several Azure SQL databases and an Azure Sentinel workspace. To create a saved query in the workspace that finds events reported by Azure Defender for SQL, where should you create the query?
- You have an Azure subscription with the virtual machines shown in the table. When enabling Microsoft Defender for Servers adaptive application controls to create an allowlist of known-safe applications, which virtual machines support adaptive application controls?
- You have an on-premises network and an Azure subscription that include several Microsoft SQL Server instances. You plan to implement Microsoft Defender for SQL. Which SQL Server instances will be protected by Microsoft Defender for SQL?
- You have Azure Firewall Standard AzFW1. Which of the following features can you use with AzFW1: TLS inspection, threat intelligence, and the network intrusion detection and prevention system (IDPS)?
- You have deleted Azure AD objects shown in a table. On a given date you attempt to restore them using the Azure Active Directory admin center. Which two objects can be restored?
- You have four Azure SQL managed instances and need to assess their vulnerability to SQL injection attacks. What should you enable first to perform this evaluation?
- You have several virtual machines and multiple Log Analytics workspaces. You plan to use Azure Sentinel to monitor Windows Defender Firewall on the virtual machines. Which virtual machines can you connect to Azure Sentinel?
- You have several virtual machines, each with a single network interface. The network interface of VM1 has been added to an application security group (ASG1). Which other virtual machines' network interfaces can you add to ASG1?
- You have SQL1 and KeyVault1 that contains several keys. You will configure Transparent Data Encryption (TDE) for SQL1 to use a customer-managed key. Which keys can you use?
- You have storage1 and VM1. VM1 is on VNet1 (one subnet) and uses Azure DNS. To ensure VM1 connects to storage1 using a private IP address with minimal administrative effort, what should you do?
- You have three on-premises Windows Server 2019 machines: Server1 and Server2 on the internal network, and Server3 on the perimeter network. All servers have access to Azure. After installing the Windows Firewall data connector in Azure Sentinel, what must you do to collect Microsoft Defender Firewall data from these servers?
- You have two Windows Server 2019 VMs (VM1 and VM2) and are creating an Update Management deployment named Update1 in Azure Automation. Update1 must automatically apply updates to VM1 and VM2 and automatically include any new Windows Server 2019 VMs. What should you include in Update1?
- You must encrypt storage1 to satisfy the technical requirements. Which Key Vaults can you use?
- You must enforce a maximum number of days that new keys in an Azure Key Vault can be valid while minimizing administrative effort. Which service should you use?
- You need a method in Azure DevOps to validate that code meets the company's quality and code review standards. What should you implement?
- You need to allow a specific user to add and delete certificates in an Azure Key Vault while following the principle of least privilege. Which option should you use?
- You need to deploy an Azure virtual WAN with three secured virtual hubs in East US, West US, and North Europe and ensure security rules synchronize across regions. Which service should you use?
- You need to grant a user administrative access to an Azure Key Vault so they can configure advanced access policies, following the principle of least privilege. Which option should you use?
- You need to prevent nonprivileged Azure AD users from creating service principals. Which setting in the Azure AD admin center should you change?
- You need to prevent the blobs in container1 of storage1 from being modified. Which action should you take on container1?
- You need to provide VM1 with secure access to a database on SQL1 by using a contained database user. Which action should you perform?
- You onboard Azure Sentinel and connect it to Azure Security Center. You want to automate mitigation of incidents while minimizing administrative effort. What should you create?
- You plan a Site-to-Site VPN between your on-premises network and VNet1. The VPN gateway must support 1 Gbps throughput and minimize cost. Which Azure VPN Gateway SKU should you recommend?
- You plan to assign policies that use DeployIfNotExist, AuditIfNotExist, Append, and Deny effects. Which policy effect requires a managed identity on the policy assignment?
- You plan to audit an Azure SQL database named sql1. The audit destination must allow querying events with the Kusto query language and require minimal administrative effort. Which audit destination should you configure?
- You plan to create an Azure Kubernetes Service (AKS) cluster and have the registered server application's manifest available. To integrate the AKS cluster with Azure Active Directory (Azure AD), which manifest property must you modify?
- You plan to create Azure Monitor security alerts for your Azure subscription. What resource should you create first to support those alerts?
- You plan to create separate subscriptions for each division under a single Azure AD tenant and ensure each subscription has identical role assignments. The underlined approach is: use Azure AD Privileged Identity Management (PIM). Indicate whether the underlined segment is correct; if not, choose the correct alternative.
- You plan to deploy an Azure Private Link service named APL1 for the resources shown. Which resource should you reference when creating APL1?
- You plan to enable Azure Disk Encryption for a Linux virtual machine running Ubuntu 16.04. Which of the following statements about Azure Disk Encryption for Linux VMs is true?
- You plan to enable Azure Disk Encryption for a Windows virtual machine. Which of the following statements about Azure Disk Encryption for Windows VMs is true?
- You plan to enable Azure Disk Encryption for VM4. Which Key Vault can store the encryption key for VM4?
- You plan to enable passwordless authentication in an Azure AD tenant and need User1 to be able to enable the combined registration experience using least privilege. Which role should you assign to User1?
- You plan to implement Azure AD Identity Protection in a tenant that contains the identities shown in an accompanying table. What is the maximum number of user risk policies you can configure?
- You plan to publish several applications in an Azure AD tenant. Which two user roles can be assigned to a user so they can grant admin consent for those published applications?
- You purchased an application App1. A user named User1 must publish App1 using Azure AD Application Proxy. Which role should you assign to User1?
- You synchronize on-premises identities to Azure AD and must prevent users whose givenName attribute begins with TEST from being synchronized. The solution should require minimal administrative effort. Which tool should you use?
- You tested an AKS cluster and disabled HTTP application routing. For production, you need application routing that provides reverse proxy and TLS termination for AKS services using a single IP address. What should you implement?
- You uploaded a certificate to WebApp1 and need the app code to access the certificate. What should you do?
- You uploaded a private key certificate named Cert1.pfx to App1. Which apps can use Cert1?
- You use Azure Resource Manager templates to deploy Azure virtual machines and need to automatically disable unused Windows features as VMs are provisioned. Which solution should you use?
- You use Azure Resource Manager templates to deploy Azure virtual machines and need to automatically disable unused Windows features as VMs are provisioned. Which of the following should you use?
- You use Azure Resource Manager templates to deploy virtual machines and need to automatically disable unused Windows features during provisioning. Which of the following should you use?
- You want to onboard an AWS account into Microsoft Defender for Cloud. What should you configure first?
- You will deploy a new Conditional Access policy named CAPolicy1 and use the What If tool to evaluate its impact while minimizing effect on users. What should the Enable policy setting for CAPolicy1 be set to?
- You will deploy an app App1 that must access an Azure Data Lake Storage account sa1 and perform Read, List, Create Directory, and Delete Directory operations via a private endpoint. What is the minimum number of private endpoints required for sa1?
- You will deploy an App Service named App1 that must use VNet1 and be reachable by private IP addresses, supporting both inbound and outbound traffic. Which deployment option should you choose?
- You will deploy Azure Container Instances for an application composed of two containers: an application container and a validation container that monitors the application by sending requests and awaiting responses after each transaction. Ensure both containers are scheduled together and may communicate only over ports that are not exposed externally. What should you include in the deployment?
- You will deploy identical Azure VMs via Resource Manager templates, where each deployment’s administrator password is stored as a secret in a different Key Vault. The Key Vault name and secret name will be provided as inline parameters. Which method lets you dynamically construct the resource ID that identifies the appropriate Key Vault during each deployment?
- You will deploy the Microsoft Monitoring Agent to many Windows Server 2016 machines using an Azure Resource Manager template to collect logs in Azure Log Analytics. Which template values should be included? (Choose all that apply.)
- You will use the Express Settings option in Azure AD Connect to synchronize a contoso.com Active Directory forest to Azure AD. Following least privilege, which two roles/groups are required to perform this configuration?
- Your Azure AD tenant contains 500 users and an administrative unit named AU1. From the Azure AD admin center you plan to add members to AU1 using Bulk add members. What should the uploaded file contain?
- Your Azure AD tenant contains Azure AD Premium P2 licenses. A partner company owns fabrikam.com and has a user User1 with the email user1@fabrikam.com. You must grant User1 access to resources in your tenant so that User1 can sign in with user1@fabrikam.com credentials, you can assign access to resources, and administrative effort is minimized. What should you do?
- Your Azure subscription contains an Azure SQL Database named DB1 in the East US region and multiple storage accounts. You plan to enable auditing for DB1. Which storage accounts can be used as the auditing destination for DB1?
- Your Azure subscription contains several virtual machines (details shown in the table). You created a Mobile Device Management (MDM) Security Baseline profile named Profile1. Which virtual machines can Profile1 be applied to?
- Your Azure subscription uses Microsoft Defender for Cloud and contains an Azure Database for PostgreSQL instance. Ensure an email alert is triggered when a suspected brute-force attack against the database is detected while minimizing administrative effort. What should you configure?
- Your environment has an Active Directory forest contoso.com and an Azure AD tenant contoso.com. You will deploy Azure AD Connect and need an integration approach that enforces on-premises password policies and sign-on restrictions for synced accounts while minimizing the number of required servers. Which authentication method should you recommend?
- Your Microsoft Entra tenant contains three users: User1, User2, and User3. Microsoft Entra Password Protection is configured as shown. The users attempt the following password resets: User1 -> C0nt0s0; User2 -> F@brikamHQ; User3 -> Pr0duct123. Which password reset attempts fail?
- Your Microsoft Entra tenant uses Entra Permissions Management and contains the accounts shown in the table. Which accounts will appear as assigned to highly privileged roles on the Azure AD insights tab in the Entra Permissions Management portal?
- Your organization has an on-premises Active Directory domain weylandindustries.com and an Azure AD tenant with the same name. You will use Azure AD Connect. Requirements: password policies and account logon restrictions must apply to synced accounts, and the number of required servers should be minimized. Solution: use pass-through authentication and seamless single sign-on together with password hash synchronization. Does this solution meet the requirements?
- Your organization requires administrator accounts to use MFA, 20-character complex passwords rotated every 180 days, and management via Privileged Identity Management (PIM). You receive alerts about administrators who have not changed their password in the last 90 days. Which PIM alert should you modify to reduce those alerts?
- Your organization uses hybrid Azure AD and all users sign in on hybrid Azure AD–joined Windows 10 devices. An Azure SQL Database supports Azure AD authentication. Developers must connect to the database from SQL Server Management Studio using their on-premises AD accounts while minimizing authentication prompts. Which authentication method should they use?
- Your organization will create separate Azure subscriptions per department, all associated with the same Azure AD tenant. You need each subscription to have identical role assignments. Which service should you use to apply the same role configuration across subscriptions?
- Your subscription contains a resource group named RG1 and the identities shown in an accompanying table. You assign Group4 the Contributor role for RG1. Which identities can you add to Group4 as members?
- Your subscription contains a virtual network with a single subnet and a service endpoint configured for that subnet. The subnet contains an Azure VM running Ubuntu Server 18.04 where you will deploy Docker containers. You must ensure containers can access Azure Storage and Azure SQL via the subnet's service endpoint. Before deploying containers, you perform the following on the VM: create an application security group. Does this action meet the requirement?
- Your subscription contains an Azure Container Registry named Registry1 and Microsoft Defender for Cloud is enabled. You uploaded container images to Registry1 but vulnerability scans did not run. What should you do to ensure images are scanned for vulnerabilities when uploaded?
- Your subscription contains an Azure SQL server SQL1 with a database DB1. To run a vulnerability assessment for DB1 using Microsoft Defender for Cloud, what must you do first?
- Your subscription contains an Azure Web App named App1 and a VM named VM1. VM1 runs SQL Server and is connected to virtual network VNet1. All resources are in the US Central region. To allow App1 to connect to VM1 while minimizing cost, which of the following should you include?
- Your subscription contains storage1. You need to configure storage1 to automatically regenerate keys every 90 days. Which PowerShell cmdlet should you run?
- Your subscription contains virtual machines shown in the environment. Which of the listed computers will support file integrity monitoring?
- Your subscription contains virtual networks and virtual machines as shown. You configured an application security group named ASG1 on NIC1. On which other network interfaces can you assign ASG1?
- Your subscription includes Windows Server 2016 Azure VMs. Each VM must have a custom antimalware VM extension installed. You are authoring an Azure Policy to enforce this. Which policy effect should you include?
Microsoft Azure Solutions Architect Expert AZ-305 Certification All exam questions
- A bank requires integration workflows that: run in an isolated virtual network with private inbound and outbound connectivity, access SAP and SQL Server systems over ExpressRoute without using an on-premises data gateway, use managed connectors, and provide predictable performance at scale. Which hosting model should you recommend for these workflows?
- A blob container in an Azure subscription must be accessible to ten finance department users only for the month of April. Which security mechanism should you recommend to provide access limited to that period?
- A branch office in Toronto hosts a VM (VM1) as a file server accessed by users at multiple offices. You must ensure users can access the shared files with minimal delay if the Toronto office becomes inaccessible. Which solution should you recommend?
- A company has two datacenters, each with redundant VPN devices. They require highly available active-active VPN termination in an Azure hub VNet with dynamic routing. They plan to add ExpressRoute later, using ExpressRoute as primary and keeping VPN as failover, all on the same hub. What gateway design should you recommend?
- A company requires outbound TLS inspection for SaaS access and intrusion detection/prevention for east-west traffic between VNets. A central security team must enforce global rules while allowing regional teams to add exceptions. What Azure Firewall design should you recommend?
- A financial analytics platform must protect sensitive data in use. Some workloads run as Linux containers on AKS, while others run on VMs. You must use hardware-based Trusted Execution Environments, support remote attestation before workloads run, and minimize code changes. What should you implement?
- A global content site runs on Azure App Service with Azure Database for PostgreSQL Flexible Server. Users report slow downloads for images and CSS from distant regions, and the database CPU is high due to read-heavy queries. The web tier averages 40% CPU. You must reduce end-user latency worldwide and offload the database without changing the application code significantly. Which two actions should you take first?
- A global enterprise wants to automatically label and protect documents containing PII in SharePoint Online and OneDrive, and encrypt emails in Exchange Online based on content. External recipients must be able to read but not print or download protected files. Users should see and apply labels in Office apps, and on-prem file shares must also be scanned and labeled. What should you implement?
- A global enterprise wants to bring their on-premises Windows and Linux servers and an existing Amazon EKS cluster under Azure governance for inventory, policy, and GitOps-based configuration. They will not move these resources to Azure. Which two actions should you perform?
- A governance team assigns an 'Allowed locations' policy at a management group. Some legacy resource groups must be temporarily exempted until a migration completes in six months. You must: 1) Mark those resources as exempt with an expiration date, 2) Continue evaluating other resources for compliance, and 3) Track remediation task progress for non-compliant resources where a deployIfNotExists policy fixes configuration drift. What should you do?
- A large enterprise is setting up a new Azure tenant to host hundreds of workloads across regulated and non-regulated business units. They need centralized identity, management, and networking, standardized guardrails, and clear separation between platform services and application subscriptions. What should you implement?
- A legacy monolith runs behind an internal load balancer on Azure VMs. You must incrementally migrate endpoints to microservices with zero downtime and preserve a single public API endpoint. The plan is to move one route at a time to new services while keeping the rest on the monolith. What should you implement?
- A legacy service uses Azure Table Storage. New requirements include global distribution with low-latency reads and writes in multiple regions, automatic indexing of all properties, RU/s-based throughput control, and minimal code changes. What should you do?
- A line-of-business application consists of a web/API tier on Azure App Service and a data tier on Azure SQL Database. The business requires an RPO of 5 minutes and an RTO of 15 minutes in case of a regional outage. What should you implement to meet these objectives?
- A manufacturing company needs to move data to Azure from multiple locations within three weeks. The main datacenter holds 700 TB of file data. Twelve branch offices each have about 5 TB of file data. Internet bandwidth to all sites is limited and unreliable; an offline transfer is required. Which two actions should you recommend?
- A marketplace app must react to partner-sent order.created events, fan out those events to internal services, and run a long-running orchestration that calls multiple SaaS APIs, waits for human approval, and finally sends a command to a warehouse system. You want minimal custom code and loose coupling. Which two Azure services should you use together?
- A media company ingests daily video files into Azure Blob Storage. Videos are read heavily for 7 days, occasionally for the next 3 months, and then must be retained for 5 years at the lowest cost. Only the ‘critical’ container needs to be replicated to a secondary region. The secondary copy will have a longer retention policy than the primary. What should you design?
- A media platform stores hot content in Azure Storage and serves it globally. Requirements: sustain a zone failure without data unavailability, allow read access from a secondary region during a primary region outage without initiating a failover, and be able to perform a planned account failover if a prolonged regional outage occurs. Which two design choices meet these requirements? Choose two.
- A mission-critical web application is published through Azure Application Gateway (WAF) and protected by Azure Firewall in a hub-and-spoke topology. You must achieve automatic L3/L4 DDoS mitigation for the app’s public endpoints, collect detailed attack telemetry for investigations, and improve blocking of known malicious IPs. What should you implement?
- A multi-tenant analytics platform uses AKS for two workloads: (1) an always-on API tier with steady traffic and (2) large, nightly batch jobs that can tolerate restarts. Azure SQL Database and an App Service-based admin portal run 24x7 and have predictable usage. Leadership mandates a 30% reduction in compute cost without impacting SLOs. Which two recommendations best meet the goal?
- A payments microservice on AKS calls an external provider that intermittently returns 5xx and timeouts under load. Spikes cause thread pool exhaustion and cascading failures in other services that share the same node pool. You must prevent cascading failures and keep unrelated services responsive when the provider degrades. Which two resiliency patterns should you implement?
- A retail platform processes multi-step order workflows. Each order generates a conversation of related messages (order created, payment authorized, items reserved) that must be processed in order per OrderId across multiple subscribers. When a worker processes an 'order created' message, it must atomically send two commands to downstream services or roll back if processing fails. Poison messages must be isolated without losing them. Which messaging design should you recommend?
- A retail platform runs on an Azure Virtual Machine Scale Set (VMSS) for its API tier, an App Service for the web front end, and Azure SQL Database. You must: 1) Alert when the VMSS average CPU exceeds 80% for 5 minutes (notify on-call via SMS) and when it exceeds 95% for 5 minutes (page SRE via PagerDuty). 2) Stream App Service and SQL diagnostic logs to a Log Analytics workspace and archive them to Azure Storage for 365 days. 3) Trigger an alert when the App Service logs contain 'OrderTimeoutException' more than 10 times in 5 minutes. What should you implement?
- A retailer must exit its datacenter in 12 weeks. Its core Java EE monolith runs on WebSphere and uses an Oracle database with many PL/SQL packages. Testing capacity is limited; the business requires feature parity on day one. A broader modernization to microservices on containers is planned for next year. What migration approach should you recommend now?
- A sales application consists of multiple Azure services handling orders, billing, payments, inventory, and shipping. You need to enable asynchronous exchange of transaction information in XML format between services. Which Azure service should you recommend?
- A sales application consists of multiple cloud services that handle different transaction components (orders, billing, payment, inventory, shipping). The services must asynchronously exchange transaction information using XML messages. Which Azure messaging service should you recommend to reliably support asynchronous XML message exchange between services?
- A sales application consists of multiple cloud services that handle different transaction components (orders, billing, payment, inventory, shipping). The services must asynchronously exchange transaction information using XML messages. Which Azure storage-based queuing solution should you recommend as a simple, cost-effective way to queue messages between services?
- A SOC team needs to detect risky sign-in behaviors (such as impossible travel) based on Azure AD sign-in logs and Microsoft 365 audit data, and to correlate endpoint alerts from Microsoft Defender for Endpoint. When a high-fidelity alert fires, the account should be disabled automatically and a ServiceNow incident opened. You are designing Microsoft Sentinel for this scenario. Which two configurations should you implement? Each correct answer presents part of the solution.
- A telemetry system must ingest 100 MB/s into Azure Event Hubs from 100,000 devices. Three downstream teams need independent reads: a real-time analytics job, a monitoring service, and a cold-path archive. Data must be automatically persisted to Azure Data Lake Storage Gen2 every 5 minutes, and downstream reads must not interfere with each other. Which two configurations should you recommend?
- A workload in Tenant A must privately access a Storage account in Tenant B. The VNet in Tenant A must resolve the storage endpoint to a private IP and continue enforcing NSGs on workload subnets. What two actions should you perform? Choose two.
- After migrating App1 to Azure, you must enforce controls to prevent unauthorized modification of stored data in order to satisfy security and compliance requirements. Which action should you take?
- An App Service web app (App1) in subscription Sub1 is configured to use Azure AD as a single-tenant application; users in contoso.com can sign in. What should you recommend to allow users from the fabrikam.com tenant to authenticate to App1?
- An App Service web app (App1) in subscription Sub1 uses Azure AD single-tenant authentication and currently accepts users from contoso.com. You must enable users from fabrikam.com to authenticate to App1. Which of the following should you recommend to manage these external users?
- An App Service web app (App1) is registered as a single-tenant Azure AD application and currently accepts sign-ins from contoso.com users only. What configuration change should you recommend to permit users from fabrikam.com to sign in to App1?
- An application sometimes writes duplicate files to a storage account. A PowerShell script identifies and deletes duplicates, but it is run manually after approval. Recommend a serverless solution that performs these steps: runs the script hourly, sends an approval email to the operations manager, processes the manager's email response, and executes the deletion if approved.
- An application used by 6,000 users validates vacation requests and currently maintains its own username/password credential store. The application does not support external identity providers. You plan to enable single sign-on (SSO) by registering the application in Azure Active Directory. Which SSO method is appropriate given the application's constraints?
- An Azure AD tenant synchronizes with on-premises Active Directory. An internal web application (WebApp1) hosted on-premises uses Integrated Windows Authentication. Some remote users do not have VPN access but require single sign-on (SSO) to WebApp1. Which two Azure features should you include in the solution? (Choose two.)
- An Azure Cosmos DB for NoSQL account contains a container (Contained) with the analytical store enabled. You need to process Contained’s data in near‑real‑time and write results to a data warehouse in an Azure Synapse Analytics workspace using a runtime engine in the workspace, minimizing data movement. Which Synapse pool should you use?
- An Azure subscription contains a custom application (Application1) developed by an external company (Fabrikam, Ltd.). Fabrikam developers were granted role-based access to components of Application1. Propose a low-development solution that: (1) sends the developers' manager a monthly email listing access permissions to Application1, and (2) automatically revokes any permission the manager does not confirm. Which should you recommend?
- An Azure virtual machine named VM1 runs Windows Server 2019 and holds 500 GB of data files. You will use Azure Data Factory to transform these files and then load them into Azure Data Lake Storage. What should you deploy on VM1 to support this design?
- An enterprise is migrating data integrations to Azure. They have: (a) dozens of existing SSIS packages that must be lifted-and-shifted with minimal changes; (b) new cloud-native transformations using mapping data flows; (c) secure connectivity to on-prem Oracle through a firewall. You plan to orchestrate with Azure Data Factory pipelines. Which two integration runtimes should you provision?
- An enterprise plans to connect 80 branch offices using SD-WAN appliances to Azure and provide local internet breakout through a managed security stack in Azure. They also want to connect multiple VNets to the same hubs and steer branch-to-internet and branch-to-VNet traffic through Azure Firewall with central control. Which Virtual WAN design meets the requirements with least operational overhead?
- An IoT vendor exposes a custom events service to partners. Partners provide HTTPS webhook endpoints that may be intermittently offline. You must publish events using a standard cross-language schema, filter events by eventType prefix, retry for up to 24 hours with exponential backoff, and if delivery ultimately fails, store undelivered events in a storage account for audit. What should you implement?
- An on-premises Active Directory syncs to Azure AD. App1 on Server1 uses LDAP against the on-premises domain. Server1 will be migrated to a VM in Subscription1, but the subscription must be prevented from accessing the on-premises network. Which solution ensures App1 continues to function while complying with the security policy?
- An on-premises application references database tables using server, database, and table names. You need to migrate the application data to Azure without modifying the app’s table references. To which two Azure services can you migrate the data so the application continues to reference tables by server/database/table? (Select two.)
- An order fulfillment system needs FIFO processing per OrderId, scheduled delivery of messages, automatic dead-lettering after 5 failed processing attempts, duplicate detection within 10 minutes, and the ability to atomically receive a message and publish two commands. Which messaging service should you choose?
- App1 in Sub1 is a single-tenant Azure AD application used by contoso.com users. You need to enable users from fabrikam.com to authenticate to App1 while governing external user access. Which solution should you recommend?
- App1 is a single-tenant Azure AD application that only allows contoso.com users to sign in. Which action will enable users in the fabrikam.com tenant to authenticate to App1?
- App1 is a single-tenant Azure AD application used by contoso.com. You need to enable fabrikam.com users to access App1 while governing and managing external user access lifecycle. Which solution should you propose?
- App1 is an on-premises application that uses an Oracle database. You will use Azure Databricks to transform and load App1 data into an Azure Synapse Analytics instance. Which two Azure services should you include so that Databricks can access App1 data? (Choose two.)
- App1 posts shipping-request messages to an Azure Storage queue that App2 currently processes. Future additional applications must be able to receive only the messages relevant to them. Which messaging solution should you recommend to enable multiple subscribers to receive relevant transactions?
- App1 uploads a cumulative transaction log named File1.txt to a block blob in container app1data once per hour; File1.txt contains only the current day's transactions. You must be able to restore the most recent uploaded version of File1.txt from any previous day for up to 30 days after it was overwritten, while minimizing storage usage. What feature should you enable?
- As part of a governance design, you plan to use Azure Policy across a large environment with many subscriptions. To which three scopes can you assign Azure Policy definitions? (Choose three.)
- CDB1 hosts a container that receives continual operational updates. You must run daily analytics in AS1 against this operational data without degrading the performance of the operational store. Which technology should you recommend to support analytics without impacting the operational workload?
- CDB1 hosts a container that stores continuously updated operational data. You need to analyze that operational data daily with AS1 without degrading the performance of the operational data store. Which solution should you include in the design?
- Contoso exposes several on-premises services through Azure Logic Apps with HTTP triggers. A partner organization (Fabrikam) uses a third-party OAuth 2.0 identity provider (no Azure AD tenant) and its developers need programmatic access to a subset of Contoso's logic apps. The solution must: (1) allow Fabrikam developers to use their existing OAuth 2.0 provider, (2) apply stricter rate limits for partner requests than for Contoso users, (3) require no changes to the existing logic apps, and (4) not use Azure AD guest accounts. Which service should you include in the design?
- Contoso has an Azure AD tenant and an Azure subscription. Fabrikam is a partner organization with its own on-premises Active Directory and Microsoft 365 tenant. Ten developers from Fabrikam need Contributor access to a resource group in Contoso's subscription and must use their existing Fabrikam credentials. What should Contoso do to enable this?
- Contoso needs to control access to Microsoft 365 as follows: (1) SharePoint Online must allow web-only, view-only access from unmanaged devices; (2) Exchange Online must be accessible only from compliant devices; (3) Sign-ins from the corporate egress IP ranges should be exempt from both restrictions. Which design should you implement?
- Contoso plans a phased migration of 600 VMware VMs, 80 SQL Server instances, and 120 IIS web apps to Azure. They want a single Azure-native solution to: perform agentless discovery and dependency mapping for servers; assess VM right-sizing/readiness; assess SQL Server migration readiness to Azure SQL Managed Instance; and assess IIS web apps for compatibility with Azure App Service. What should you implement?
- Design a highly available Azure SQL database deployment that meets the following: failover between replicas must occur without any data loss, the database must remain available during a zone outage, and costs should be minimized. Which deployment option should you select?
- Design a highly available Azure SQL database subject to these requirements: failover must occur without data loss; the database must remain available during a zone outage; and cost should be minimized. Which deployment option is most appropriate?
- Design a highly available Azure SQL database that ensures failover between replicas without data loss, remains available during a zone outage, and minimizes cost. Which deployment option meets these constraints?
- Design a highly available Azure SQL database that fails over between replicas with no data loss, remains available during a zone outage, and minimizes cost. Which deployment option should you choose?
- Design a highly available Azure SQL database that meets these requirements: failover between replicas must occur without data loss; the database must remain available if a zone fails; and costs must be minimized. Which deployment option should you choose?
- Design a highly available Azure SQL database that meets these requirements: failover between replicas must occur without any data loss, the database must remain available during an availability zone outage, and costs must be minimized. Which Azure SQL deployment option best meets these requirements?
- Design a highly available Azure SQL database that must (1) fail over between replicas without any data loss, (2) remain available in the event of a zone outage, and (3) minimize costs. Which deployment option should you use?
- Design a highly available Azure SQL database that must (1) fail over between replicas with no data loss, (2) remain available during a zone outage, and (3) minimize cost. Which deployment option should you choose?
- Design a highly available Azure SQL database that must fail over between replicas with no data loss, remain available during an availability zone outage, and minimize costs. Which deployment option should you select?
- Design a highly available Azure SQL Database that requires failover with no data loss, availability during a zone outage, and minimized cost. Which deployment option should you choose?
- Design a highly available Azure SQL database with the following requirements: failover between replicas must be lossless, the database must remain available during a zone outage, and costs must be minimized. Which deployment option should you select?
- Design a highly available Azure SQL database with these requirements: failover between replicas must be lossless; the database must remain accessible during a zone outage; and cost should be minimized. Which deployment option meets these requirements?
- Design a highly available Azure SQL database with these requirements: lossless replica failover, availability during a zone outage, and minimal cost. Which deployment option should you choose?
- Design a highly available Azure SQL Database with these requirements: failover between replicas must occur with no data loss, the database must remain available during a zone outage, and costs should be minimized. Which deployment option should you select?
- Design a highly available Azure SQL deployment that meets these requirements: failover between replicas must be lossless, the database must remain available during a zone outage, and costs must be minimized. Which deployment option should you choose?
- Design a highly available Azure SQL solution that meets these requirements: (1) failover between replicas must occur with zero data loss, (2) the database must remain available during a single availability zone outage, and (3) cost should be minimized. Which deployment option satisfies these requirements?
- For the distributed sales application (orders, billing, payment, inventory, shipping), recommend a mechanism to enable asynchronous XML message exchange between services. Which Azure service should you propose?
- For the same distributed sales application (orders, billing, payment, inventory, shipping), recommend a solution that enables asynchronous communication of transaction messages using XML. Which of the following would be appropriate?
- Given an environment where incoming traffic for VMSS1 must be distributed across two network virtual appliances (NVA1 and NVA2) with minimal administrative overhead, which load-balancing solution should you recommend?
- In an Azure AD tenant (contoso.com) Group1 uses assigned membership and contains 50 members (including 20 guest users). You must implement a recurring evaluation of Group1 membership that: repeats automatically every three months; allows each member to indicate whether they should remain in the group; automatically removes users who say they do not need membership; and automatically removes users who fail to respond. What should you implement?
- Intermittent latency is reported from a VM in a spoke VNet to an Azure SQL Database reached via Private Endpoint in the hub. You must (1) continuously monitor reachability and latency, (2) capture packets on the VM NIC during incidents without logging into the VM, (3) confirm which NSG rules allow/deny flows, and (4) visualize the involved topology. What set of Network Watcher capabilities best meets the requirements?
- One hundred devices write performance data to Azure Blob Storage. You plan to store and analyze that data in an Azure SQL Database and need a continuous process to copy the Blob data into the database. Which service should you recommend?
- Recommend a data-storage approach that satisfies all of the following: supports REST access, hosts 20 independent tables with varying sizes and usage patterns, automatically replicates data to a secondary Azure region, and minimizes cost. Which option meets these requirements?
- Recommend a solution to generate a monthly report listing all new Azure Resource Manager (ARM) resource deployments in your subscription. Which service should you include in your recommendation?
- Recommend a solution to generate a monthly report of all new ARM resource deployments in your subscription. Which service is appropriate for collecting and querying deployment activity data for reporting?
- Recommend a solution to generate a monthly report of all new Azure Resource Manager (ARM) resource deployments in the subscription. Which service should be used to collect and analyze deployment data for reporting?
- Recommend a solution to produce a monthly report of all new Azure Resource Manager (ARM) resource deployments in your subscription. Which Azure service should be used to collect and query deployment activity for this report?
- Recommend a solution to produce a monthly report that lists all new Azure Resource Manager (ARM) resource deployments in a subscription. Which service should be included in your recommendation?
- Recommend a storage solution for a mission-critical application that requires an SLA covering write-operation latency and write throughput. Which service should you include in the recommendation?
- Recommend an Azure Storage configuration that meets these requirements: stores 1 PB of blob data, supports three levels of subfolders, and supports access control lists (ACLs). Which configuration should you use?
- SQL Server runs on an Azure virtual machine and databases are written nightly by a batch job. Design a disaster recovery solution that provides automated recovery for a regional outage, supports an RTO of 15 minutes and an RPO of 24 hours, and minimizes cost. Which solution should you include?
- Sub1 contains an Azure App Service web app named App1. App1 is configured for single-tenant Azure AD authentication and currently accepts sign-ins from users in contoso.com. You need to enable users from the fabrikam.com tenant to authenticate to App1. Which solution should you recommend to govern and enable external user access?
- To meet the application development requirements for App1, which capability should you include in your recommendation?
- To meet the data requirements for App1, what should be deployed into each availability zone that contains an instance of App1?
- To satisfy the database retention requirements, which configuration should you recommend?
- What should you include in the identity management strategy to support the planned changes to the environment?
- Which Azure service should you use to generate a monthly report of all new Azure Resource Manager (ARM) resource deployments in a subscription?
- Which Azure service should you use to produce a monthly report that lists all new Azure Resource Manager (ARM) resource deployments in a subscription?
- Which data storage approach should be included in your recommendation for WebApp1?
- Which monitoring solution should you recommend to satisfy the monitoring requirements for App2?
- You are building a multi-tenant SaaS platform that sends push notifications for each customer's mobile app. Each customer brings their own APNs/FCM credentials and requires isolation of registrations and tags. You want to minimize operational overhead while keeping environments (Dev/Test/Prod) separate. What Azure Notification Hubs design should you implement?
- You are building a sales application composed of multiple Azure cloud services that handle order processing, billing, payment, inventory, and shipping. You need to enable asynchronous exchange of transaction data using XML messages between the services. Which Azure service should you recommend?
- You are building a sales application composed of multiple Azure services that handle orders, billing, payments, inventory, and shipping. You need an approach to enable these services to exchange transaction information asynchronously using XML messages. Which service should you recommend?
- You are building a sales application using multiple Azure cloud services for orders, billing, payments, inventory, and shipping. The services need to exchange transaction information asynchronously using XML messages. Which Azure service should you include in your recommendation?
- You are building a secure enterprise data lake that must enforce fine-grained folder-level permissions and integrate with Azure Databricks and Azure Synapse serverless SQL. Access must be granted via Azure AD and managed identities. Which two design decisions should you implement?
- You are deploying a multi-tenant web app on Azure App Service. Requirements: inbound access must be private from the corporate network only; outbound calls to Azure SQL Database must use private endpoints; use blue/green deployments with no downtime; and scale out automatically based on load. Which two configurations are required?
- You are deploying Azure Database for PostgreSQL for an e-commerce platform in a region with multiple availability zones. The solution must provide automatic failover with zero data loss within the region and support read-only analytics in another region without impacting OLTP performance. What should you implement?
- You are designing a distributed cache for a global gaming platform. The cache must allow active-active writes in two Azure regions, support >100 GB of data with sharding, and provide sub-millisecond latency. Which option should you choose?
- You are designing a distributed sales application where different Azure services process orders, billing, payments, inventory, and shipping. These services must communicate asynchronously using XML messages. Which Azure messaging service should you recommend?
- You are designing a globally distributed order processing system on Azure Cosmos DB for the Core (SQL) API. The system must accept writes in both East US and West Europe with no data loss during a single-region outage and fail over automatically. Read latency should be minimized for local users. What should you configure?
- You are designing a globally distributed social app that stores user timelines and comments as JSON documents. Users must see their own writes immediately, while cross-region latency must remain low. Writes are evenly distributed by user. What Cosmos DB design should you choose?
- You are designing a microservices platform on AKS for an e-commerce site. Requirements: a single public endpoint for clients, centralized authentication and throttling, service-to-service decoupling for domain events (e.g., OrderCreated), and internal service discovery. Which two components should you include to meet the external access and event-driven communication requirements?
- You are designing a point-of-sale (POS) solution to be deployed across multiple locations. Each location will host several on-premises applications that must authenticate to an Azure Databricks workspace in the Standard tier. The solution should minimize administrative overhead related to staff turnover and credential management. Which authentication method should you configure for the on-premises application to access the workspace?
- You are designing a sales application composed of several Azure cloud services responsible for customer orders, billing, payments, inventory, and shipping. The services must asynchronously exchange transaction information formatted as XML. Which Azure service should you recommend?
- You are designing a sales application composed of multiple Azure cloud services that handle different parts of a transaction (orders, billing, payments, inventory, shipping). You need to enable asynchronous exchange of transaction information using XML messages between these services. Which Azure service should you include in your recommendation?
- You are designing a sales application comprised of multiple Azure cloud services that handle orders, billing, payments, inventory, and shipping. These services must exchange transaction information asynchronously using XML messages. Which Azure service should you recommend?
- You are designing a sales application comprised of multiple Azure services for orders, billing, payments, inventory, and shipping. To enable asynchronous exchange of transaction information in XML format between services, which Azure component should you include?
- You are designing a sales application made of multiple Azure services that handle orders, billing, payments, inventory, and shipping. The services must asynchronously exchange XML-based transaction messages. Which Azure offering should you include in your recommendation?
- You are designing a sales system composed of multiple cloud services that handle order, billing, payment, inventory, and shipping functions. The services must exchange transaction information asynchronously using XML messages. Which Azure solution should you recommend to enable this messaging pattern?
- You are designing a Service Fabric application for a trading platform that maintains user session state with sub-millisecond access and must survive node failures. Upgrades must be performed with zero downtime and automatic rollback if health degrades. Which two design choices should you make?
- You are designing a single-region three-tier application on Azure VMs. The solution must achieve a 99.99% VM uptime SLA and minimize east–west latency between the web, application, and database tiers. The database requires Ultra Disk. What should you design? Choose two.
- You are designing a Zero Trust approach for a multi-tier application consisting of a web front end on App Service, microservices on AKS, and a database on Azure SQL Managed Instance. You must enforce micro-segmentation between tiers, require strong identity verification for users and admins, and ensure least-privilege access for administrative roles. Which two actions should you implement? Each correct answer presents part of the solution.
- You are designing a zone-resilient architecture for a high-throughput API hosted on virtual machines behind a layer 7 gateway. The solution must survive a single availability zone failure without changing the public IP, distribute compute across zones, and terminate TLS at the gateway. What should you design? Choose two.
- You are designing an AKS cluster for a platform that runs Linux system components and Windows-based .NET line-of-business services. Pods must receive routable IPs inside the VNet for inspection by a virtual network appliance. The cluster must scale nodes automatically with demand. Which design should you implement?
- You are designing an AKS-based microservices architecture accessible from consumer VMs on the same virtual network. Requirements: ingress must be restricted to a single private IP and protected using mutual TLS, incoming calls must be rate-limited, and costs should be minimized. Which solution meets these requirements?
- You are designing an application composed of two components that communicate by sending messages through a queue. Messages must be processed in strict First-In, First-Out (FIFO) order. Which queueing solution should you include to ensure FIFO processing?
- You are designing an application that aggregates content for users. The database solution must support SQL queries, allow multi-master (multi-region) writes, and guarantee low-latency read operations. Which database should you recommend?
- You are designing an application that uses Azure Cosmos DB to consolidate sales data from multiple countries. The chosen API must support SQL-style queries, geo-replication, and relational storage and access. Which API should you recommend?
- You are designing an application to aggregate content for users. Recommend a database solution that supports SQL commands, allows multi-master writes, and ensures low-latency read operations. Which service should you include in the recommendation?
- You are designing an Azure-based order processing system that uses the resources described. Transaction flow: a customer places an order via App1; App1 sends messages to check product availability at Vendor1 and Vendor2; an integration component processes those messages and invokes either Function1 or Function2 based on order type; after a vendor confirms availability, Function1 or Function2 generates a status message for App1; all transaction steps are logged to storage1. Which type of resource should you recommend for the integration component?
- You are designing an event-driven processing platform. It must handle bursty traffic (millions of events/day), perform long-running orchestrations, and access resources over private endpoints in a VNet without cold starts. Triggers include Service Bus and HTTP. Which hosting option and features should you use?
- You are designing an internet-facing application hosted in Azure that will store video files ranging from 50 MB to 12 GB. The application will use certificate-based authentication. Recommend the Azure storage option that provides the fastest read performance while minimizing storage costs.
- You are designing Azure AD B2C for a mobile app that must support local accounts, Google, and a partner’s SAML IdP. During sign-up/sign-in, you must call a REST API to validate a customer number and include the returned tier as a custom claim in the access token. Which approach should you recommend?
- You are designing Azure Batch for a rendering workload. Job sizes vary widely, and you want to minimize cost using preemptible capacity but maintain a small always-on baseline. Tasks have dependencies and must be orchestrated per job submission. What should you implement? Choose two.
- You are designing Azure governance so that every resource is easily identifiable by environment, owner, department, and cost center. You must ensure these operational attributes are available for inclusion in reporting. Which mechanism should you include in the design?
- You are designing disaster recovery for a two-tier payroll application running on on-premises VMware hosts. You plan to use Azure Site Recovery (ASR) to replicate the database VM and the application VM to Azure. Requirements: you must be able to conduct a non-disruptive DR test in Azure without impacting on-premises workloads, and you must ensure the database VM starts before the application VM during failover. Which two actions should you implement in the Recovery Services vault? Choose two.
- You are designing private connectivity from on-premises to VNets in two Azure regions across different geopolitical areas. You also need Microsoft 365 reachability via the circuit, want the two on-premises sites to communicate with each other through Azure, and require the shortest data path to VMs over private peering. Which ExpressRoute design should you recommend?
- You are developing a distributed sales application in Azure with separate services for orders, billing, payments, inventory, and shipping. You require asynchronous exchange of transaction information using XML messages between services. Which Azure service should you include?
- You are developing a distributed sales system consisting of multiple Azure cloud services (orders, billing, payment, inventory, shipping). You need a recommendation for enabling asynchronous, XML-based message exchange between services. Which Azure messaging service should you include?
- You are developing a sales application composed of multiple Azure cloud services that handle orders, billing, payments, inventory, and shipping. The services must exchange transaction information asynchronously using XML messages. Which messaging solution should you recommend?
- You are developing a sales application with multiple Azure cloud services for orders, billing, payments, inventory, and shipping. The services must asynchronously exchange transaction information in XML format. Which Azure service should you recommend to support this asynchronous messaging?
- You are developing an Azure Functions app that will read activity logs for a subscription. You want an authentication approach for the function app that minimizes administrative overhead. Which authentication option should you recommend?
- You are implementing CQRS and Event Sourcing for a high-throughput order system. Commands store events in an append-only stream per aggregate in Azure Cosmos DB. You must build multiple read models (searchable orders in Azure SQL and a hot cache) and also publish a subset of events to external consumers for analytics with replay capability. Which two components should you use?
- You are migrating 30 Spring Boot microservices (packaged as JARs) from on-premises VMs. The apps use Spring Cloud Config (Git backend), Netflix Eureka for service discovery, MySQL, and Redis. You must minimize code changes and adopt managed services. What should you recommend?
- You are planning an Azure IoT Hub deployment with 50,000 devices that stream temperature, device ID, and timestamp data at about 50,000 records per second, and you require near real-time visualization. Which two services would you recommend to store and query this data for that workload? (Select two.)
- You are planning an Azure IoT Hub solution with 50,000 devices, each streaming temperature, device ID, and timestamp data. Approximately 50,000 records per second will be written and the data must be visualized in near real time. Which two services would you recommend to store and query this data? (Select two.)
- You are planning cost-optimized migrations. The company owns Windows Server Datacenter and SQL Server Enterprise core licenses with active Software Assurance. It also runs 50 Ubuntu VMs with Canonical support contracts. You will deploy 200 Azure VMs (Windows), a 32-vCore Azure SQL Managed Instance, and several Ubuntu VMs. Which two workloads can apply Azure Hybrid Benefit to reduce compute licensing costs in Azure?
- You are securing a tiered web application that handles customer PII. In phase one, you must minimize blast radius, restrict privileged access, and assume breach. A formal data classification rollout will start next quarter. Which two design decisions should you implement now?
- You back up 100 Azure virtual machines to a Recovery Services vault in East US. You must be able to restore VMs in the paired region during a regional outage and protect backup items from accidental or malicious deletion. The vault currently uses GRS. What should you configure? Choose two.
- You deploy Azure Front Door (Standard/Premium) in front of two multi-region web workloads: /api and /web. Requirements: route /api/* to Origin Group A and /web/* to Origin Group B; each origin exposes a health endpoint at /healthz returning HTTP 200; apply a WAF policy with a custom rule that blocks specific user-agents only for requests to /api. Which two configurations should you implement? Choose two.
- You have 100 SQL Server Integration Services (SSIS) packages configured to use 10 on-premises SQL Server databases as their destinations. You plan to migrate those 10 databases to Azure SQL Database. Recommend a solution that allows the existing SSIS packages to target Azure SQL Database as their destinations. What should you include in the recommendation?
- You have 12 Azure subscriptions and three projects that use resources across multiple subscriptions. You need to track costs per project using Microsoft Cost Management while minimizing administrative overhead. Which two features should you use? (Choose two.)
- You have 12 on-premises data sources containing customer information (SQL Server, MySQL, Oracle). You will consolidate this data into an Azure Data Lake Storage account for analysis and reporting. To automatically extract, transform, and load new data into the lake while minimizing administrative effort, which service should you use?
- You have a .NET web service named Service1 that performs the following tasks: reads and writes temporary files on the local file system and writes entries to the Windows Application event log. You must recommend an Azure hosting option for Service1 that minimizes both maintenance overhead and cost. Which option do you recommend?
- You have a Basic Azure Virtual WAN (VirtualWAN1) and an ExpressRoute circuit in the US East region. Before you can create an ExpressRoute association to VirtualWAN1, what is the required first step?
- You have a multi-tier application (App1) whose backend service writes to an Azure SQL database (SQL1). Client users read data via the App1 client and experience significant delays retrieving data during peak load. Which service should you include to minimize data retrieval latency for the users?
- You have an AKS cluster (AKS1) hosting microservice APIs that listen on non‑default HTTP ports. You will deploy a Standard tier API Management instance (APIM1) to expose the APIs externally. You must enable mTLS authentication between APIM1 and AKS1, while minimizing development effort and cost. What should you do?
- You have an application that currently uses two on-premises SQL Server databases (DB1 and DB2). You will migrate both databases to Azure. The solution must support server-side transactions that span DB1 and DB2 and minimize administrative effort for updates. Which hosting option should you recommend?
- You have an Azure Functions microservice named App1 running on the Consumption plan that uses an Azure Queue Storage trigger. You will migrate App1 to an Azure Kubernetes Service (AKS) cluster. The AKS environment must (a) use the same event-driven scaling behavior as the current deployment and (b) support both kubenet and Azure CNI networking. Which two actions should you perform? (Select two.)
- You have an on-premises SQL Server instance named SQL1 that hosts 50 databases and plan to migrate it to an Azure SQL Managed Instance using an offline migration. The solution must minimize administrative effort. Which service or tool should you include in the migration plan?
- You have data files stored in Azure Blob Storage that you must transform and move into Azure Data Lake Storage. The transformation will use a mapping data flow. Which Azure service should you use to perform the mapping data flow and move the transformed data to Data Lake Storage?
- You manage 10 Azure web apps integrated with Azure AD. Users move frequently between project teams. Project managers must be able to review and remove users from their project’s app, and must receive an automated prompt every 30 days to verify assignments. Which Azure capability meets these requirements?
- You manage 200 Windows and Linux VMs across three regions. Requirements: 1) Security and operations teams need role-based access to logs per region, yet you require the ability to run centralized queries across all VMs. 2) Retain SecurityEvent for 180 days but keep performance counters (Perf) only 30 days. 3) Collect only specific Windows event IDs and filter noisy data at collection time. What workspace and data collection design should you recommend?
- You manage a mission-critical SaaS using Azure SQL Database. You need automatic cross-region failover with a single read-write listener and a separate read-only listener for reporting. Within each region, you also require high availability across Availability Zones. Which solution should you implement?
- You manage an Azure subscription that contains 1,000 resources. You must produce compliance reports that allow grouping resources by department. Which combination of tools should you use to organize and classify the resources for reporting?
- You manage hybrid name resolution. Requirements: (1) Split-horizon DNS for contoso.com with public records for the website and private records for internal services; (2) Auto-registration of Azure VM private A records; (3) Azure VMs must resolve on-prem contoso.local names and on-prem clients must resolve private contoso.com names hosted in Azure; (4) Avoid running custom DNS servers in Azure. Which two components should you deploy/configure? Choose two.
- You manage three Azure subscriptions under a management group. Leadership wants to raise Microsoft Defender for Cloud Secure Score and track PCI DSS compliance across those subscriptions. They also want threat protection enabled for VMs and AKS clusters, using native capabilities with minimal custom policy authoring. Which two actions should you perform? Each correct answer presents part of the solution.
- You manage Windows and Linux servers in Azure and on-premises. Requirements: 1) Patch both Azure and on-prem servers monthly within defined maintenance windows, with reboots coordinated. 2) Ensure the IIS Windows feature remains installed and configured on specific servers. 3) When an Azure Monitor alert fires, execute a PowerShell script on an on-prem file server to archive logs locally. What should you implement?
- You must create a monthly report of every new ARM resource deployment in your Azure subscription. Which service should you use to centrally gather and query deployment logs for the report?
- You must deploy a new Azure Firewall policy that contains mandatory rules to apply across all existing Azure Firewall deployments by configuring it as a parent policy. Given the current set of firewall policies in your environment (as shown in an accompanying table), what is the minimum number of additional Azure Firewall policies you need to create?
- You must deploy an Azure Kubernetes Service (AKS) cluster that uses Linux nodes. The solution must minimize the time required to provision compute resources during scale‑out operations, support autoscaling of Linux containers, and minimize administrative effort. Which scaling option should you recommend?
- You must deploy an Azure Kubernetes Service (AKS) cluster that uses Windows Server 2019 nodes. The solution must minimize the time required to provision compute resources during scale‑out operations and must support autoscaling of Windows Server containers. Which AKS scaling option should you recommend?
- You must design a highly available Azure SQL Database meeting these constraints: failover with no data loss, availability during a zonal outage, and minimized cost. Which deployment option satisfies these requirements?
- You must expose an on-premises WCF SOAP service that uses NetTcpBinding and WS-Security to applications running in Azure. Inbound firewall ports on-premises cannot be opened. You need request-reply semantics and want to avoid a full site-to-site VPN. Which connectivity option should you choose?
- You must grant a partner organization’s users access to a Microsoft Teams team, a SharePoint site, and an internal line-of-business app. Requirements: requests require approval by a Contoso sponsor, assignments expire after 60 days if not renewed, access is available only to users from the partner’s verified domain, and external guest accounts should be removed from the tenant when they lose all assignments. What should you implement? (Choose two)
- You must implement Azure RBAC assignments for the Network Contributor role and meet authentication and authorization constraints. What is the minimum number of role assignments required?
- You must migrate a 50-GB on-premises SQL Server 2008 database to an Azure SQL managed instance with minimal downtime. Which tool should you use?
- You must propose an App Service architecture for App1 that satisfies requirements while minimizing cost. Which of the following is the most appropriate recommendation?
- You must provision an Azure storage account that can handle at least 500 requests per second and store large images, videos, and audio streams. Which type of storage account should you provision?
- You must publish a legacy IIS application that uses Windows Integrated Authentication to internet users via Azure AD Application Proxy. The app is hosted in two different on-premises sites. Requirements: use Azure AD pre-authentication with Conditional Access MFA, route each published app to connectors in its local site, and provide SSO to the backend via Kerberos Constrained Delegation (KCD). Which configuration should you choose?
- You must run a short-lived data processing job using two tightly coupled containers: a worker and a log-forwarding sidecar. Both containers need to share files and securely connect to a private Redis cache hosted in an Azure virtual network. You want the simplest compute option with minimal management. What should you do? Choose two.
- You need to copy 500 GB of files from an on-premises Windows Server 2016 file server to an Azure Blob Storage account (store1). Which two Azure services can accomplish this? (Choose two.)
- You need to deliver a single Azure Monitor Workbook for operations that: 1) Displays CPU and memory metrics and key logs for resources selected by the user. 2) Allows filtering by an 'Environment' parameter (Prod, UAT, Dev) used within KQL queries. 3) Is accessible read-only by the Operations AAD group across multiple subscriptions, while you maintain edit access. Which two configurations should you implement? (Choose two.)
- You need to deploy an Azure Storage account that will: store data for multiple users, encrypt each user's data with a separate key, and ensure all data in the account is encrypted using customer-managed keys. Which storage option should you deploy?
- You need to enable developers to provision Azure virtual machines while enforcing the following constraints: they may create VMs only in specific Azure regions and only of specific VM sizes. Which Azure capability should you use to enforce these restrictions?
- You need to execute custom C# code in response to events delivered by Azure Event Grid. The executed code must be able to access the private IP address of an SQL Server instance running on an Azure VM, and costs should be minimized. Which hosting option should you include?
- You need to generate a monthly report listing all new Azure Resource Manager (ARM) resource deployments in your subscription. Which service should you use to obtain this information?
- You need to migrate a 2 TB on-premises SQL Server 2016 OLTP database to Azure SQL Database with near-zero downtime. You will provision Azure Database Migration Service (DMS) in Azure. Which two prerequisites must you meet to use an online migration with DMS?
- You need to migrate a web application that depends on a custom COM component to Azure. The solution must remain available if an Azure datacenter becomes unavailable and minimize cost. Which deployment should you recommend?
- You need to migrate an on-premises SQL Server 2016 instance with multiple databases to Azure with minimal code changes. The solution must support SQL Agent jobs, cross-database queries, and CLR. The databases must be accessible only over private networking via existing ExpressRoute and the cutover must incur minimal downtime. Which two actions should you take?
- You need to migrate an on-premises storage solution to Azure, and the migrated storage must support the Hadoop Distributed File System (HDFS). Which Azure service should you use?
- You need to produce a monthly report listing all new Azure Resource Manager (ARM) resource deployments in an Azure subscription. Which Azure service should you use to obtain this deployment activity?
- You need to produce a monthly report summarizing all new Azure Resource Manager (ARM) resource deployments in a subscription. Which source should you query to obtain deployment events and details?
- You need to produce a monthly report that lists all new Azure Resource Manager (ARM) resource deployments in your Azure subscription. Which service should you use to collect and report on these deployment events?
- You need to provide developers with the ability to provision Azure virtual machines while enforcing these constraints: only allow creation in specific regions, and only allow creation of specific VM sizes. Which Azure capability should you use?
- You need to recommend a maintenance solution for App1 that minimizes operational cost. Which of the following should you recommend?
- You need to recommend a notification solution for the IT Support distribution group to receive health and synchronization alerts. Which solution should you include in your recommendation?
- You need to reduce account takeover risk using Microsoft Entra ID Protection. Requirements: block or interrupt risky sessions, require password change when a user is confirmed high-risk, and require MFA for medium and above sign-in risk. What should you implement? (Choose two)
- You need to standardize new subscriptions for a data analytics platform. Baseline requirements include: deploy two resource groups, assign RBAC roles for platform ops, assign policies for allowed locations and diagnostic settings, and prevent deletion of baseline resources by subscription owners. What should you recommend?
- You operate a microservices application running in AKS with .NET and Node.js services. You need to: 1) Reduce Application Insights ingestion costs while preserving full end-to-end transaction details whenever an operation fails. 2) Test external availability of the public API endpoint from three regions at 1-minute intervals. 3) Automatically detect anomalies like sudden increases in dependency failures. What should you implement?
- You operate a multi-region retail platform experiencing frequent configuration drift and hard-to-diagnose incidents. Deployments are still manual for the next quarter, but you must immediately improve operational excellence by ensuring consistent environments and actionable insights into failures and SLOs. What two steps should you implement first?
- You operate a VM scale set and multiple Function Apps that must access Azure Key Vault and Azure Storage with a common, reusable identity across resources and regions. The identity must outlive any single resource. The workloads also need to obtain OAuth tokens to call a partner API that trusts Entra ID, without storing secrets. What should you do? Each correct answer presents part of the solution.
- You operate multiple public endpoints for an e-commerce platform in different regions. You must ensure users are directed to endpoints based on the country or region they originate from to meet data sovereignty requirements. Which Azure Traffic Manager routing method should you use?
- You operate two identical regional services behind Standard SKU Azure Load Balancers in East US and West Europe. You need a single anycast public IP that distributes traffic across regions and fails over based on regional health. Health probes should check an HTTP /health endpoint in each region. Which two configurations should you implement? Choose two.
- You plan to automate deployments of resources to Azure subscriptions. Which statement describes a difference between Azure Blueprints and Azure Resource Manager (ARM) templates?
- You plan to back up the keys from an Azure Key Vault named KeyVault1 located in West US. To which locations can you restore that backup?
- You plan to deploy an Azure Kubernetes Service (AKS) cluster that includes Windows Server 2019 nodes. Requirements: minimize the time to provision compute resources during scale-out and support autoscaling of Windows Server containers. Which scaling option should you recommend?
- You plan to grant specific Azure AD user accounts read access to Azure Cosmos DB databases that use the SQL API. Which of the following should you use to provide that access?
- You plan to migrate 5 TB of infrequently accessed company files from an on-premises file server to Azure. Files must be retrievable within 24 hours when requested, and storage costs should be minimized. Which two storage deployment options meet these requirements? (Select two.)
- You plan to migrate an on‑premises Linux server that hosts a Java application (App1) to Azure. App1 is an interactive HTTPS application whose connection count varies significantly during the day, runs multiple concurrent instances, and would require major changes to run in a container. The solution must run multiple instances of App1, automatically adjust the instance count based on load, and minimize administrative overhead. Which Azure compute service should you recommend?
- You plan to migrate App1 to Azure and need to recommend a network connectivity solution for the Azure Storage account that will host App1 data while meeting security and compliance requirements. Which option should you recommend?
- You plan to migrate on-premises MySQL databases to Azure Database for MySQL Flexible Server. To ensure the databases remain accessible if a datacenter fails while minimizing cost, which compute tier should you select?
- You plan to provision an HPC cluster in Azure that will use a third‑party job scheduler. You need to recommend a solution to provision and manage the cluster nodes and integrate with the scheduler. Which Azure service should you include in the recommendation?
- You plan to use an Azure Storage account to house data assets. The solution must support immutable storage, disable anonymous access to the account, and support ACL-based Azure AD permissions. Which storage offering should you choose?
- You plan to use the Azure Import/Export service to seed 20 TB of data into an Azure Storage account by sending your own disks. Which two actions are required to ensure the import job is processed correctly and that you can track its status?
- You publish time-limited download links for blobs to external partners. You must be able to revoke any issued links immediately if needed. The storage account must use encryption with customer-managed keys stored in Azure Key Vault. Which two actions should you take?
- You run a critical OLTP workload on a single Azure SQL Database (Business Critical). You need automatic cross-region failover with minimal connection string changes and want reporting queries to run against the secondary by default. Which two configurations should you implement?
- You run a hub-and-spoke architecture. The hub VNet contains an ExpressRoute gateway to on-premises and a pair of third-party NVAs. Spokes use gateway transit. You need dynamic route exchange between the NVAs and the ExpressRoute gateway so on-prem routes are learned by NVAs and NVA-learned prefixes reach the gateway, enabling branch-to-branch and spoke-to-spoke flows without manual UDRs. What should you implement?
- You run a stateless API on Azure Virtual Machine Scale Sets. Traffic is highly variable. You must minimize cost by using preemptible capacity for burst traffic, scale out based on CPU and queue depth, and roll out application updates safely with health probes and surge. Which approach should you use?
- You store web access log files in Azure Blob Storage and need an automated monthly process to load that data into Azure SQL Database for reporting. Which service should you use to orchestrate and perform the monthly upload?
- You support mission-critical workloads across several subscriptions in North Europe and West Europe. You must: 1) Receive alerts for Azure-wide service issues impacting your selected services in those regions. 2) Be notified about planned maintenance affecting your VM hosts. 3) Track service health advisories such as feature deprecations. 4) Route different Service Health notifications to different action groups (email vs. ITSM). What should you configure?
- You will deploy 10 applications across two AKS clusters, each in a different Azure region. The deployment must keep applications available if a single AKS cluster fails and must encrypt internet-facing traffic using SSL without configuring SSL in each container. Which service should you include in the design?
- You will deploy a monitoring solution that includes Azure Monitor Network Insights, Application Insights, Microsoft Sentinel, and VM insights, all managed by a single team. What is the minimum number of Azure Monitor (Log Analytics) workspaces required?
- You will deploy an application (App1) on multiple Azure virtual machines now and in the future. Requirements for these VMs: they must authenticate with Azure AD to access an Azure Key Vault, Azure Logic Apps, and an Azure SQL Database; you must avoid assigning new roles or credentials each time new VMs are added; secrets and certificates must not be stored on the VMs; and identity management overhead should be minimized. Which type of identity should you use?
- You will deploy an Azure App Service web application with instances across multiple Azure regions. The load-balancing solution must: remain available during a regional outage; support Azure Web Application Firewall (WAF); support cookie-based affinity; and support URL-based routing. Which Azure service should you recommend?
- You will deploy an Azure Database for MySQL Flexible Server named Server1 in the East US region and must implement business continuity that minimizes downtime if a failover to the paired region is required. Which action should you perform?
- You will deploy an Azure SQL Database that will store personally identifiable information (PII). You must ensure that only privileged users can view the PII values while minimizing operational complexity. Which capability should you include?
- You will deploy containerized workloads to AKS clusters distributed across four Azure regions. Which storage solution ensures that updated container images are automatically replicated to all regions hosting the AKS clusters?
- You will migrate an on-premises SQL Server database to an Azure SQL Managed Instance and must enable customer-managed Transparent Data Encryption (TDE). To maximize encryption strength for the TDE protector, which algorithm and key length should you choose?
- You will migrate databases from SQL Server 2014 on Windows Server 2012 R2 (largest database 3 TB, none exceeding 4 TB) to Azure. Requirements: minimize management overhead, support Azure AD authentication, and minimize database changes. Which service should you recommend to host the databases?
- You will monitor a multi-tier application (App1) deployed across containers in Azure Container Instances. The monitoring solution must provide synthetic transaction monitoring between application components and require minimal development effort. Which Azure Monitor capability should you include?
- You will use Azure Functions to process events from Azure Event Hubs. Individual request processing is expected to take between five and twenty minutes. The hosting solution must support estimates of request processing runtimes and provide event-driven autoscaling. Which Functions hosting plan should you recommend?
- You’re designing a spoke virtual network in Azure to host a multi-tier application. Corporate IP strategy reserves 10.0.0.0/8 for on-premises and existing hub VNets. The new spoke must avoid overlap to allow peering to the hub. The app will use an Azure Storage account that must never be reachable via its public endpoint. You expect about 500 VMs with room to scale. What should you design?
- Your Azure AD tenant (contoso.com) has a security group (Group1) with assigned membership containing 50 members, including 20 guest users. You must implement an automated membership review that runs every three months, lets each member indicate whether they still require membership, and automatically removes members who either indicate they do not need membership or fail to respond. What should you include in the recommendation?
- Your Azure AD tenant is synchronized with an on-premises Active Directory. A custom line-of-business application requires SAML single sign-on and must enforce multi-factor authentication when users sign in from an unknown location. Which two Azure features should you include to meet these requirements? (Choose two.)
- Your company has 300 subscriptions split across three divisions: Retail, Manufacturing, and R&D. You need to enforce an organization-wide policy that denies public IP creation, apply different allowed-location policies per division, grant tenant-wide Reader access to Auditors, and allow subscription owners to manage their own resources. What management group and assignment design should you implement?
- Your company has 50 on-premises IIS web apps running on Windows Server 2012 R2 using .NET Framework 4.7. You must quickly evaluate App Service compatibility, including use of 32-bit components, ISAPI filters, and URL Rewrite rules, and then migrate the compatible apps with minimal manual steps. What should you do?
- Your company is rewriting an application (App1) as an Azure Web App. App1 uses data from on-premises Microsoft SQL Server databases that are accessed only on the first day of each month. Data growth is expected to remain under 3% per year. You must migrate the data to Azure SQL Database and ensure the database is available only on the first day of each month. Which Azure SQL Database service tier should you choose?
- Your company offers public APIs with two tiers: Starter (1,000 calls/day per client) and Enterprise (10,000 calls/day per client). Developers must self-serve sign-up to obtain keys, pending approval. Each request should automatically receive a correlation ID header. What Azure API Management configuration meets these requirements with minimal overhead?
- Your company operates 300 virtual machines in a VMware environment with varying sizes and utilization. You plan to migrate all VMs to Azure and need to determine how many and what sizes of Azure virtual machines will be required, while minimizing administrative effort. Which Azure tool should you use to generate this sizing and migration recommendation?
- Your company plans to migrate hundreds of on-premises vSphere VMs to Azure with minimal downtime. Some applications must retain their IP addresses during migration. The VMs will need private access to Azure PaaS services from the migrated environment. Which two actions should you include in the design?
- Your compliance team needs a weekly report across all subscriptions listing: 1) Public IP addresses not associated with any NIC, load balancer, or VM; 2) Changes to Network Security Groups (NSGs) that altered the number of security rules in the last 14 days. The solution should scale with minimal overhead and require no agents. What should you implement?
- Your finance team wants tighter control over monthly Azure spend and better purchase planning. Requirements: 1) Trigger email to on-call and a webhook to an automation endpoint when 80% of the monthly budget is reached. 2) Provide the CFO a daily breakdown of costs grouped by resource group and by the 'CostCenter' tag. 3) After observing 30 days of usage, obtain recommendations for VM reservations. What should you do?
- Your organization has offices in North America and Europe and is migrating to Azure. Requirements: mobile users' point-to-site VPN connections must automatically connect to the nearest Azure region; each region's offices must connect to their local Azure region via ExpressRoute; transitive routing between virtual networks and on-premises networks must be supported; and traffic between virtual networks must be filterable by FQDN. Which networking solution should you recommend?
- Your organization is standardizing on Spring Boot microservices. You need Azure-native centralized configuration, service discovery, an integrated API gateway for routing, and out-of-the-box distributed tracing/metrics. You also want a fully managed experience without standing up separate OSS components. Which service design should you choose?
- Your organization needs to enforce two standards across all subscriptions under the Corp management group: (1) resources must have a CostCenter tag (auto-add a default when missing), and (2) resources must be deployed only in approved regions. Existing resources must be remediated where possible. What should you do? (Choose two)
- Your organization operates 150 D4as_v5 production VMs spread across three subscriptions. The workloads are expected to run steadily for at least three years. You need to maximize savings, apply discounts across subscriptions, and retain some flexibility if 10% of the fleet is retired midterm. What should you recommend?
- Your organization operates workloads across Azure, AWS, and GCP. You must discover all human and workload identities, inventory their effective permissions, identify unused permissions across clouds, and automatically right-size roles to least privilege with approval workflows. What should you implement?
- Your organization wants a weekly, automated summary of Azure Advisor recommendations across all subscriptions, grouped by category (cost, security, reliability, performance, operational excellence). The summary must be saved to a Storage account and posted to a Microsoft Teams channel without writing custom code. Which two services should you combine to implement this at scale? (Choose two.)
- Your platform team wants to remove long-lived credentials for CI/CD and in-cluster access to Azure resources. GitHub Actions must deploy Bicep templates to Azure without a client secret, and AKS workloads must access Key Vault and Storage without storing service principal secrets. What should you configure? Each correct answer presents part of the solution.
- Your SaaS platform hosts 200 small tenant databases. Each tenant experiences brief, unpredictable spikes in activity, while aggregate utilization remains moderate. You want to minimize compute cost, use reserved capacity discounts, and avoid managing per-database scaling. Which deployment should you choose?
- Your security team needs to: prevent data exfiltration from sanctioned SaaS apps (Salesforce and Box) on unmanaged devices with real-time session controls; discover shadow IT from network and endpoint signals; and monitor/remediate risky OAuth apps in Microsoft 365 that request excessive permissions. What should you implement?
- Your security team wants to grant engineers temporary Owner rights on a production subscription only when needed. Requirements: assignments must be time-bound (maximum 8 hours), require approval by a duty manager and MFA at activation, and be re-certified quarterly. What should you configure? (Choose two)
- Your subscription contains three peered VNets. Virtual machines host an HTTPS-based client/server application and are accessible only by their private IP addresses. You must implement a load balancing solution for VM2 and VM3 such that if one VM fails, requests are automatically routed to the other VM. Which Azure service should you include in the solution?
- Your subscription has three public IPs: one on Application Gateway v2 for a customer portal, one on a Standard Load Balancer for AKS, and one test IP. Budget is limited. You must protect only the two critical IPs against volumetric DDoS attacks and obtain attack metrics and mitigation reports. What should you do?
- Your team must perform a continuous architectural review of a mission-critical Azure workload across all five pillars of the Azure Well-Architected Framework (reliability, security, cost optimization, operational excellence, performance efficiency). Leadership wants pillar-aligned findings, prioritized recommendations, and an easy way to track improvements over time across multiple subscriptions with minimal setup. What should you recommend?
Microsoft Azure Virtual Desktop Specialty AZ-140 Certification All exam questions
- 600 concurrent users report slow logons and sluggish Outlook performance. FSLogix Profile Containers are stored on an Azure Files Standard (GPv2) share in the same region as the session hosts. Network and CPU utilization on hosts are normal. Which two actions will most directly improve profile performance? (Choose two)
- A company has 1,200 users in Germany and 400 users in South Africa. All applications are SaaS and accessed over the internet. You must minimize interactive latency for users when deploying Azure Virtual Desktop. What should you design?
- A GPO named Policy1 contains only user settings but is linked to the OU (WVDHostsOU) that contains session host computer accounts, so users' settings aren't applied at logon. What should you configure so the GPO user settings apply when users sign in to the session hosts?
- A host pool contains ten session host VMs. You need to grant a pilot user group access to those VMs. What should you do?
- A host pool has 10 session hosts built from a custom image and using ephemeral OS disks. To deploy OneDrive for Business, which two actions should you perform on each session host? (Choose two.)
- A host pool has 15 session hosts with FSLogix installed. To configure the path where user profiles are stored while minimizing administrative effort, which registry setting should you use?
- A Hyper-V VM to upload to Azure has these properties: Generation 1, dynamically expanding disk, VHDX format, 2 TB disk. Which two actions should you perform before uploading? (Choose two.)
- A line-of-business tool writes 10 GB of transient data under %LOCALAPPDATA%\ContosoDev\Logs during sessions. This data should stay on the local VM and not be placed in users’ FSLogix profile containers. What should you do?
- A new session host shows Unavailable in the host pool and users cannot connect. You need to validate whether the Azure Virtual Desktop agent initialized and registered, and whether the RDP transport is listening. Which two event logs on the VM should you check? (Choose two.)
- A personal host pool contains 20 Azure AD–joined session hosts. To ensure only approved VM extensions are installed on those hosts while minimizing administration, which solution should you use?
- A pooled host pool (Pool1) contains four Microsoft Entra–joined session hosts. Users receive an error that their account is not configured to sign in. Which RBAC role provides the least privilege required to allow them to sign in to the session hosts?
- A pooled host pool contains 20 session hosts with Max sessions per host set to 10. During peak, 65 users are connected. The scaling plan’s capacity threshold is 60% and the minimum percentage of hosts is 20%. Assuming autoscale breadth-first behavior, how many session hosts will autoscale keep powered on during this period?
- A pooled host pool uses breadth-first load balancing. To support QoS policies for RDP connections to two session hosts, what must you enable?
- A pooled host pool uses the depth-first load-balancing algorithm. The Max session limit is set to 10 per session host. The pool has three identical session hosts (Host1, Host2, Host3). Twenty-five users connect during peak hours. How will sessions be distributed?
- A RemoteApp group publishes App1; each month a new MSI-based version with a different executable name is installed on each session host. To automate publishing the new version while keeping the same user experience in the Windows Desktop client, which two PowerShell cmdlets should you run?
- A session host is Azure AD–joined. To verify whether a Windows license is assigned to the VM, which action should you take?
- A session host shows Unavailable and NotRegistered in the host pool. The last heartbeat was 45 minutes ago. You need to restore registration without redeploying the VM. What are two appropriate first actions? (Choose two.)
- A shared image gallery contains versions 1.0.0, 1.1.0, and 1.2.0. Ensure new VMs created from the gallery default to version 1.1.0. What should you do?
- A single team of power users must be able to launch both a full desktop and specific RemoteApps from their AVD client. The same underlying image and application set should be used. What is a supported way to meet this requirement?
- After adding a French language pack to each session host, the language pack was later removed and hosts reverted to English. To ensure the French language pack remains available on session hosts, what should you do?
- All session hosts are Microsoft Entra joined. Fifty users will connect from Linux devices. Which custom RDP property should you configure to allow these users to sign in?
- All session hosts in host pool Pool1 have private IP addresses only. Administrators must be able to connect remotely to those session hosts using the Azure CLI and the Windows Remote Desktop client. What should you include in the solution?
- An AVD host pool has Teams installed on each session host but only chat/collaboration works; calling and meeting features are disabled. What should you do so users can use calling and meeting features in Teams?
- An AVD host pool uses FSLogix profile containers. To prevent specific folders from syncing to the FSLogix profile container at sign-out, what must you name the configuration file?
- An eight-node Storage Spaces Direct cluster stores FSLogix profiles for a host pool. What is the maximum number of nodes that can fail simultaneously without users losing access to their profiles?
- An on-prem AD user has logon name user1@contoso.com and pre-Windows 2000 name CONTOSO\User1. For per-user FSLogix profile configuration on a domain-joined session host, how should you reference this user in the FSLogix registry settings?
- An on-prem universal security group AVDusers is synced to Azure AD. You have an AVD host pool of four Windows 10 multi-session hosts. How do you ensure only AVDusers members can establish AVD sessions to the host pool?
- Azure Advisor recommends enabling a validation environment for an impacted host pool. Implementing this recommendation allows you to validate which of the following?
- Based on the provided user table (not shown), which users can connect to Azure Virtual Desktop using their preferred web browser?
- Compliance requires BitLocker encryption of the OS and data disks for all Azure Virtual Desktop session hosts. Encryption keys must be stored in Azure Key Vault with purge protection. You need to implement this for an existing host pool without redeploying the VMs. What should you do?
- Configure autoscaling for a Windows 10 Enterprise multi-session host pool to (a) distribute new sessions across all running hosts and (b) automatically add a host when concurrent sessions exceed 30 per host. What should you include?
- Contoso needs to quickly scale a pooled host pool across two Azure regions while maintaining a consistent, monthly-patched baseline that includes FSLogix and a line-of-business app. Administrators want to control updates centrally and publish new image releases on a predictable cadence. Which image source should they use for deploying new session hosts?
- Create a host pool where VMs can accumulate credits during low CPU usage and use them to exceed baseline performance during spikes. Which VM series supports this behavior?
- Deploy a host pool of 20 Windows 11 session hosts that each require a Windows client license and minimal administrative effort. Which method should you use to deploy the session hosts?
- Deploy host pool Pool1 in East US using FSLogix Profile Containers and Office Containers. Which storage accounts can Pool1 use?
- Fifty users connect to an Intune-managed Azure Virtual Desktop host pool from Windows 10 devices. To prevent users from copying files between their local computers and AVD sessions with minimal administrative effort, what should you do?
- For an Azure Virtual Desktop deployment where you will deploy Update Management for server-based session hosts, which two prerequisites must you configure?
- For FSLogix profile containers that must reside on SSDs while minimizing administrative effort and cost, which storage solution should you recommend?
- From the generalized Windows 10 VHDs stored in the Azure storage account, which disk should you use to create an image for deploying an Azure Virtual Desktop session host?
- From the Windows 10 images in the Azure Compute Gallery, which image(s) can be used for session hosts in a Personal host pool named Pool1 located in West US?
- Given an AVD deployment with the host pools shown in the table, you plan to use MSIX app attach. In which host pools can the session hosts use app attach?
- Given on-premises AD contoso.com synchronized to contoso.onmicrosoft.com and a partner tenant fabrikam.com, Pool1 contains 10 session hosts joined to contoso.com and Group1 is assigned to the application group for Pool1. Which users will be able to sign in to the session hosts in Pool1?
- Given planned host pools (as provided), for which host pools can you configure a load-balancing algorithm?
- Given Pool1 (pooled, East US) and the listed workspaces, in which workspace(s) can you register AppGroup1 (a RemoteApp application group for Pool1)?
- Given the AAD Domain Services GPO settings shown for computers and users, how long after connecting to a session host will User1 be disconnected?
- Given the resources shown in the subscription table, which resources can be backed up using Azure Backup?
- Given the subscription resources listed in the referenced table (not shown), which account should host the SMB share for FSLogix profiles for AVDPool1 to maximize read/write performance and use contoso.com users/groups for SMB access control?
- Helpdesk engineers occasionally need local administrator rights on Azure Virtual Desktop session hosts to troubleshoot issues. You must meet these requirements: provide just-in-time, time-bound elevation for helpdesk engineers, and ensure each session host’s built-in local Administrator account has a unique, automatically rotated password backed up to Microsoft Entra ID. Which two actions should you implement? Each correct answer presents part of the solution.
- Host pool Pool1 configuration: Pooled, Load balancing algorithm: Breadth-first, Max session limit: 5, Start VM on connect: Yes. Given the current session hosts (as provided), how many additional users must connect to Pool1 to start Host3?
- Host1 can reach the on-premises 192.168.10.0/24 network but cannot reach App1 on the new on-premises 192.168.11.0/24 network. Which setting should you modify to allow Host1 to access App1?
- HostPool1 contains Windows 10 session hosts and various application groups. To assign a Windows 11 Desktop application group to users, what should you do first?
- How should you ensure that all session hosts deployed from Image1 are onboarded to Microsoft Defender for Endpoint?
- In a hybrid Microsoft Entra tenant with users shown in the table, you deploy Entra-joined AVD session hosts. Which users support FSLogix application rule sets?
- In an Azure AD DS managed domain (contoso.com) you created Pool1. Admin1 has the Virtual Machine Contributor role at the subscription level. To let Admin1 add session hosts to Pool1 using least privilege, which two actions are required?
- In an Azure Virtual Desktop deployment (host pool Pool1 with Host1 and Host2 and RemoteAppGroup1 containing RemoteApp App1), how do you prevent users from copying and pasting between App1 and their local device?
- Main office and two branch offices each connect directly to the internet. Branch routers are endpoints for a VPN to the main office and a site-to-site VPN to Azure. QoS rules on branch routers are shown in the table. Users report slow responses and connection errors to Azure Virtual Desktop. Which rule should have its bandwidth allocation increased to improve Azure Virtual Desktop performance?
- New session hosts show a Not Registered status. The environment uses custom DNS servers, outbound internet is restricted through a web proxy that performs TLS inspection, and you are not using Private Link. Which two checks or actions should you perform to resolve registration? (Select two answers.)
- On an Azure Virtual Desktop session host named Host1, which PowerShell cmdlet reports the status of Microsoft Defender Antivirus?
- On session host Host1, configure Windows Defender Firewall to allow inbound network traffic for RDP Shortpath. Which program under C:\Windows\System32 should the inbound firewall rule target?
- On-premises Active Directory contoso.com syncs to Azure AD. Host pool Pool1 is Personal with 3 VMs running Windows 10 Enterprise and joined to the on-prem contoso.com domain. To manage security updates on the session hosts with Microsoft Endpoint Manager, what should you do?
- Pool1 contains session hosts Host1 and Host2. You need to enable screen capture protection for the deployment. What should you do?
- Pool1 contains two Microsoft Entra–joined session hosts. You must enable SSO for RDP using Microsoft Entra authentication. Which application requires modifying the remoteDesktopSecurityConfiguration object?
- Pool1 is joined to an Azure AD DS managed domain (contoso.com). You will use Azure Automation runbooks to scale Pool1 and need to authorize the runbooks with minimal administrative effort. What should you configure?
- Pool1 session hosts use FSLogix profile containers. To configure FSLogix Cloud Cache on the session hosts, what action should you take?
- Pool1 uses Storage1\share1 to store FSLogix profile containers. You created Group1 and granted it sign-in permission to Pool1. To allow Group1 members to write FSLogix containers to share1 using least privilege, which two privileges should you assign?
- Recommend an authentication solution that meets the performance requirements. Which two actions should you include?
- Server1 (Windows Server) is deployed in West US and HostPool1 is deployed in East US. To ensure all traffic between HostPool1 and Server1 is routed across the Microsoft backbone, which should you use?
- Session hosts are joined to the on-premises contoso.com Active Directory. To limit user sessions to three hours, where should you configure the session time limit?
- Some users intermittently receive temporary local profiles or errors stating their FSLogix profile is in use. You want to reduce profile lock conflicts and avoid local-profile fallback when the container should mount. Which two configurations should you implement? (Choose two)
- Subscription linked to a hybrid Entra tenant. All session hosts are Microsoft Entra joined. FSLogix profile containers will be stored on an Azure Files share named share1. Which host pools contain session hosts that can access share1?
- Subscription linked to hybrid Entra tenant contoso.com. You created host pool HP01 and will deploy session hosts to VNet01 that must join contoso.com. To minimize administrative effort, what should you configure first?
- Subscription Sub1 contains VNet1 and a host pool Pool1 with session hosts connected to VNet1. To add a private endpoint connection to Pool1, what should you do first?
- Tenant contains internal users with Microsoft 365 E5 licenses and partner Fabrikam users with no licenses. Sub1 has host pool Pool1 with RemoteApp App1. Fabrikam users must be licensed via Per-user access pricing, App1 must be accessible to all internal and Fabrikam users, and costs must be minimized. What should you do first?
- To deploy the session hosts per the requirements, which PowerShell cmdlet should you run first?
- To enable just-in-time (JIT) VM access for all session hosts in the deployment, what should you do first?
- To enable screen capture protection on all session hosts in Pool1 while minimizing administrative effort, what should you do?
- To ensure resilient, high-performance user profiles for the Boston office, what should you implement?
- To monitor an Azure Virtual Desktop host pool with Azure Virtual Desktop Insights in Azure Monitor, which destination should you select in the host pool Diagnostic settings?
- To require administrators to access session hosts using the Azure portal, which service should you include in the solution?
- To require Azure Virtual Desktop users to reauthenticate every six hours, what should you do first?
- Two Azure regions host an AVD deployment. To ensure users retain their profiles if one region fails and minimize administrative effort, which profile solution should you recommend?
- Two business units use separate workspaces. You published a RemoteApp application group (AppGroupA) from a pooled host pool and registered it to Workspace1. You must make the same published applications appear in Workspace2 without adding more session hosts and with minimal administrative overhead. What should you do?
- User1 modifies their desktop but the changes do not appear after reconnecting. FSLogix profile include/exclude and local group memberships are defined as shown. To ensure User1 sees the modified desktop while minimizing impact on other user profiles, what should you do?
- Users connect to a host pool using the Azure Virtual Desktop Windows client. You must require reauthentication every eight hours while minimizing administrative effort. What should you do?
- Users connect to AVD from Windows 10 using the Remote Desktop client. To support AV and Microsoft Teams calling/meeting features in AVD, which three actions should you perform? (Choose three.)
- Users connecting from hotel Wi‑Fi report degraded Azure Virtual Desktop experience. The network blocks UDP egress. What will occur and how will user experience likely be affected? (Select two answers.)
- Users intermittently receive the message "We couldn't connect to the remote PC" when launching desktops from a pooled host pool. You need to quickly determine whether failures are due to no available session hosts or transport negotiation issues. Which two actions should you take first? (Choose two.)
- Users report long sign-in times when FSLogix Profile Containers are mounted on your Azure Virtual Desktop session hosts. You suspect Microsoft Defender Antivirus scanning is adding latency. To optimize FSLogix without broadly reducing protection, which two exclusions should you configure on the session hosts? Each correct answer presents part of the solution.
- Users report that Microsoft Teams calls from Azure Virtual Desktop sessions consume high CPU on the session hosts and show no "AVD optimized" indicator. You must enable Teams media optimization. Which two actions should you take? Choose two answers.
- Users report the error "The user's profile failed to attach" when signing in. FSLogix profile containers are hosted on Azure Files using Active Directory authentication. You need detailed evidence of mount failures to share with the storage team. Which two data sources should you collect from an affected session host? (Choose two.)
- Users running RemoteApp App1 can launch arbitrary executables from the Save As dialog on session hosts. To restrict users so they can run only published applications, what should you implement?
- Users’ FSLogix profile VHDX files are growing due to large Outlook OST files and OneDrive cached content. You want to reduce profile bloat and improve logon times without losing Microsoft 365 app functionality. What should you configure?
- Using Azure AD Domain Services with a personal host pool of five session hosts, you plan to add two new session hosts. What must you do before deploying the new hosts?
- Using the Start/Stop VMs during off-hours feature, you must specify which VMs should never be stopped by the automation. Which setting do you configure?
- VNet1, VNet2, and VNet3 are peered. You will use Azure Bastion to provide secure administrative access to all session hosts while minimizing cost. How many Azure Bastion hosts should you deploy?
- VNet1’s single subnet currently covers the entire 10.10.0.0/16 address space. Before you can deploy a VPN gateway to VNet1, what should you modify first?
- What change to Admin1's settings meets the FSLogix user profile requirements?
- When creating a host pool with Windows 11 session hosts, how should you configure the VM security settings to enable secure boot and vTPM?
- Where should you configure the device redirection settings to satisfy the technical requirements?
- Which license is required for just-in-time (JIT) VM access to manage Azure Virtual Desktop session host VMs while minimizing cost?
- Which Performance Monitor counter should you use to troubleshoot poor frame quality for a current user session on Windows 11 Enterprise multi-session session hosts?
- Which role assignment for Operator2 satisfies the technical requirements?
- Which service should you use to configure the virtual machines that have the Pool1 prefix?
- Which setting should you modify for VNET4 before you can deploy Pool4?
- Which three PowerShell modules must be installed on Server1 to meet the technical requirements?
- Which two actions should be included in an authentication solution to meet the performance requirements?
- Which two roles should be assigned to Admin1 to meet the security requirements?
- Which two roles should be assigned to Admin2 to meet the security requirements?
- Which virtual machine(s) can be used as the source OS for new Azure Virtual Desktop session host deployments, given the OS must be generalized (user- and machine-specific information removed)?
- While connected to a session on a host pool running Windows 10 Enterprise multi-session, users report poor screen update frequency. To quickly determine if the cause is server, network, or client resources, what should you do from within the current session?
- While investigating user complaints about slow performance, you want to confirm whether bottlenecks are CPU, memory, disk, or network on Windows 11 Enterprise multi-session hosts. Which four Windows performance counters provide the most direct indicators for each of these areas? (Choose four.)
- While troubleshooting a Remote Desktop client that stopped responding, you need to restore the client's default settings and unsubscribe from all workspaces. Which command should you run?
- While troubleshooting low frame quality for a current user session on a Windows 10 Enterprise multi-session host pool, which command retrieves the user session ID for use with Performance Monitor?
- You are authoring a Bicep template to deploy a pooled host pool, its default desktop application group, and register that application group to an existing workspace in one deployment. Which property must you set on the application group resource to create the registration to the workspace?
- You are building a golden image with Azure VM Image Builder. The template already uses a marketplace source for Windows 11 Enterprise multi-session Gen2. You must ensure FSLogix and a line-of-business MSI are installed during the build and that the output image is published as a new version to an existing Azure Compute Gallery image definition replicated to North Europe and West Europe. Which two template elements should you add or update? (Choose two.)
- You are deploying Storage Spaces Direct for FSLogix profile containers without using Cloud Witness. What is the minimum number of virtual machines required for the cluster?
- You are designing connectivity so Azure Virtual Desktop session hosts in a spoke virtual network can access on‑premises file servers and license servers over private IPs with predictable latency and an SLA. Which two options meet the requirement? (Select two answers.)
- You are designing cross-region disaster recovery for an Azure Virtual Desktop deployment in North Europe. The business requires an RTO under 2 hours and an RPO under 15 minutes for user profiles. Session hosts run Windows 11 Enterprise multi-session. Which two design decisions meet the requirements with the least operational complexity? (Select two answers.)
- You are designing NTFS and share permissions for an FSLogix Profile Containers share used by Azure Virtual Desktop hosts joined to AD DS. You must ensure users can create their own folder and VHDX file but cannot view or modify other users’ folders. Which configuration meets the requirement?
- You are implementing MSIX app attach for a pooled host pool. ContosoApp.msix is expanded into a VHDX stored on an Azure Files share that uses Active Directory authentication. Users sign in but do not see the app; the package shows Not registered. Which two actions are required to allow the package to be staged and registered? Choose two answers.
- You are migrating an on-premises Remote Desktop Services deployment that uses User Profile Disks (UPD) and RemoteApps published through RD Gateway. You will publish the same apps through Azure Virtual Desktop RemoteApp. You must preserve users’ settings and provide secure external access with minimal new infrastructure. Which two actions should you take? (Select two answers.)
- You are planning FSLogix Profile Containers for Windows 11 Enterprise multi-session hosts in Azure Virtual Desktop. Which is a hard requirement for the profile storage location?
- You are standardizing FSLogix Profile Container disk settings for 1,000 users with moderate Microsoft 365 usage on Azure Files Premium. You need to balance storage efficiency with resiliency against corruption. Which configuration should you choose?
- You attempt to deploy host pools, application groups, and workspaces to a new subscription by using an ARM template. The deployment fails with an error stating that the resource type is not registered. Which resource provider must you register in the subscription to resolve the issue?
- You built a custom Windows Server VM named Server2 and need to add it to an existing host pool Pool1. Which two actions should you perform?
- You configured a personal host pool with Start VM on Connect enabled. A user shut down their assigned VM from inside Windows, and the VM now shows a power state of Stopped (allocated) in Azure. What happens when the user attempts to connect?
- You configured Azure Virtual Desktop resource Diagnostic settings to send logs to a Log Analytics workspace using the AzureDiagnostics table. You need to identify, by host pool, the number of failed connection attempts during the last 24 hours, grouped per hour. Which Kusto Query Language (KQL) query should you run?
- You create a Recovery Services vault named Vault1. Given the resources in the subscription (as in the referenced table), which resources can you back up to Vault1 using Azure Backup?
- You created a custom Azure role (Role1) that can start VMs on demand. To enable Start VM on connect for Pool1 session hosts, to which service principal should you assign Role1?
- You created a host pool and generated a registration token that expires tomorrow. Some session hosts are already registered. You plan to add more session hosts next week. What should you do so you can add the new session hosts?
- You created a RemoteApp application group for a host pool and assigned users to the app group. Users have already subscribed to a workspace but do not see the published apps in their AVD client feed. What must you configure to make the apps appear?
- You created a VM named Host3 running Windows 11 and need to add it as a third session host to host pool Pool1. What should you do first?
- You created an Azure Files share share1 in storage1 to store FSLogix profile containers for Microsoft Entra–joined session hosts. What must you enable on share1 to support FSLogix containers?
- You created FSLogix Application Masking rule and assignment files on a management computer. To apply Application Masking to the three session hosts in Pool1, what should you do?
- You deployed 10 session hosts via an ARM template and discovered Windows licenses were not applied. Which PowerShell cmdlet should you use to update the VM licenses?
- You deployed AVD in a secondary region and plan a test failover, but users still have active sessions in the primary region. Which PowerShell cmdlet signs out users from session hosts in the primary region?
- You deployed Azure AD DS (aaddscontoso.com) to VNET1 using Admin1. To deploy Windows 10 Enterprise session hosts into a host pool on VNET1 using Admin1, what must you do first?
- You deployed Azure Virtual Desktop and all session hosts are domain-joined. Which storage accounts can you use to store FSLogix profile containers?
- You deployed multiple AVD session hosts that have only private IP addresses. Administrators need to initiate RDP sessions to those hosts from the Azure portal. What should you implement?
- You enabled Azure Virtual Desktop Insights but the workbooks show no performance or event data from session hosts created from a custom image. You need to meet the prerequisites for Insights on all hosts. Which two actions should you take? (Choose two.)
- You enabled Private Link for Azure Virtual Desktop by creating private endpoints in a hub virtual network. Session hosts reside in a spoke virtual network and use on‑premises DNS servers via a site‑to‑site VPN. Session hosts fail to register. What should you configure to ensure the session hosts resolve the Azure Virtual Desktop service to private IPs? (Select two answers.)
- You enabled RDP Shortpath for managed networks, but connections still use TCP fallback. Azure Firewall sits between corporate clients and the session host subnet, and NSGs are applied to the subnet. What changes are required to allow Shortpath traffic? (Select two answers.)
- You have 1,200 named users. Peak concurrency is estimated at 50%. A pilot determined that a D8s v5 session host (8 vCPUs) can reliably support 30 active sessions at approximately 70% CPU. You require at least 10% spare capacity at peak based on the pilot result. What is the minimum number of session hosts you should plan in a single pooled host pool?
- You have 500 users with Office 365 E1 licenses using Windows 10 multi-session hosts to stream a custom remote app (App1). Which license minimizes cost while allowing users to stream App1?
- You have a custom VM image named Image1. To update Image1 with Azure VM Image Builder, what must you do first?
- You have a host pool in East US and need a disaster recovery solution so users can connect to equivalent resources in West US by selecting a single Remote Desktop client icon. Failover must be initiated manually and failover times minimized. What should you do?
- You have a pooled host pool (Pool1) with five session hosts. Two apps, App1 and App2, must be installed on all session hosts. All users connect to a full desktop session. Only sales users may use App1; only research users may use App2. To ensure each department’s users see only their assigned app when connecting to Pool1, which solution should you use?
- You have a pooled host pool and a RemoteApp application group named Finance-Apps. A Microsoft Entra security group named AVD-Finance should be granted access to Finance-Apps. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two answers.)
- You have a production Azure Virtual Desktop deployment and want a safe way for a small pilot group to test new Azure Virtual Desktop service updates early without risking production stability. You must isolate pilot users from production tenants’ service updates. Which two actions should you perform? (Select two answers)
- You have a single office with 40 employees. Estimated user workloads are provided; half of each workload type work from home and remote users do not use a VPN to the office. Approximately how much bandwidth is required between the office and Azure to support these workloads?
- You have a subscription with an Azure Virtual Desktop host pool (Pool1) whose session hosts are Microsoft Entra joined. A user (User1) must be able to connect to the session hosts from multiple devices. To enable connectivity from all devices while minimizing administrative effort, what should you do?
- You have a VM (VM1) with the FSLogix agent installed and FSLogix registry keys configured. VM1 is in RG2 and connected to Subnet2; your host pool uses session hosts in RG1 on Subnet1. You will use VM1 to create a gold image for deploying multiple session hosts. What must you do on VM1 before capturing the image?
- You have an ARM template named AVD.json that defines an Azure Virtual Desktop deployment. Which PowerShell cmdlet should you use to provision the deployment from the template?
- You have an AVD host pool (Pool1) with three session hosts and need to implement a private endpoint connection for the pool. Which two actions should you perform?
- You have an AVD host pool with 100 session hosts running Windows 10 on general-purpose VMs. You plan to implement Quality of Service (QoS) for the deployment. What should you implement first?
- You have an Azure AD tenant contoso.com and VNET1. An Azure AD DS managed domain litwareinc.com is deployed to VNET1. You plan to deploy an Azure Virtual Desktop host pool Pool1 to VNET1 and need to deploy Windows 10 Enterprise session hosts. What should you do first?
- You have an Azure Compute Gallery named Gallery1 and a VM named Template1 that contains custom apps and settings. You will deploy Azure Virtual Desktop session hosts using a custom VM image that must: be stored in Gallery1, be based on Template1, and ensure each new session host has a unique computer name and identifier. In the Azure portal, what action should you take to create this custom image?
- You have an Azure Virtual Desktop deployment in East US and a disaster recovery location in West US. You must perform controlled failover/failback tests every six months while minimizing administrative effort and cost. Which disaster recovery approach do you recommend?
- You have an Azure Virtual Desktop host pool in the East US region. To enable failover of the host pool to the West US region, what should you do first?
- You have five session hosts and users who connect over the internet from Seattle and Vancouver offices. To ensure only connections from those two offices are allowed, which control should you use?
- You have Shared Image Gallery SIG1 in East US containing Image1 used for Pool1. You plan a new host pool Pool2 in South India. Image1 must be replicated to South India, Pool2 session hosts must be based on Image1, and updates to Image1 must be available in both regions. What should you include in the solution?
- You have storage1 hosting share1 with AD DS (contoso.com) authentication and a host pool using Windows 10 multi-session + Microsoft 365 Apps. What is the next step to configure an FSLogix profile container for the pool?
- You have subscription Sub1 and user Admin1 assigned the Desktop Virtualization Contributor role for Sub1. You need to ensure Admin1 can assign Scaling1 to Pool1. Solution: Assign the Azure Virtual Desktop service principal the User Access Administrator role for Sub1. Does this meet the goal?
- You have subscription Sub1 and user Admin1 assigned the Desktop Virtualization Contributor role for Sub1. You need to ensure Admin1 can assign Scaling1 to Pool1. Solution: Assign the Azure Virtual Desktop service principal the Owner role for Sub1. Does this meet the goal?
- You have the devices shown in the following table. You plan to deploy Azure Virtual Desktop for client access to virtualized apps. Which devices support the Remote Desktop client?
- You have two host pools: Pool1 (10 session hosts, supports 100 concurrent users) and Pool2 (2 session hosts, supports 20 concurrent users). All service updates must be tested before GA, testing must have minimal organizational impact, and you cannot create new host pools. What should you include in the recommendation?
- You installed ContosoApp on the session host image for a pooled host pool. When you try to publish it as a RemoteApp in the Azure portal using the Start menu picker, the application does not appear in the list. You need to make the app discoverable via Start menu discovery. Choose two answers.
- You manage a single pooled host pool. Marketing users require webcam and microphone redirection for video creation, but Finance users must be blocked from redirecting any devices. You must meet the requirements without creating a new host pool. Which two actions should you perform? Choose two answers.
- You manage two host pools: PoolA runs Windows 11 Enterprise multi-session; PoolB runs Windows Server 2022 Datacenter: Azure Edition. You must: (a) automatically apply monthly quality updates to PoolA after hours, allowing reboots; (b) minimize reboots on PoolB by using hotpatch for security updates. Which two configurations should you implement? (Choose two.)
- You manage two pooled host pools: one for production and one for project-based contractors. You need to minimize compute cost by powering down idle session hosts after hours and allow the first user who connects in the morning to start deallocated VMs automatically. What should you configure?
- You manage two pooled host pools: Pool-US in East US and Pool-EU in West Europe. You need autoscale to start session hosts at 08:00 local time for each region using native Azure Virtual Desktop scaling plans. You want to minimize objects while ensuring each region follows its own local time. What should you do?
- You measured network latency between user locations and candidate Azure regions for host pools. Which tool should you use to identify the best Azure region for the host pool based on latency?
- You must add a new application to a RemoteApp application group so the application is available only during an active user session. What should you use as the application source?
- You must configure a scaling plan schedule for a pooled host pool so that hosts start gradually before 09:00, run at full capacity from 09:00–17:00, scale down between 17:00–18:30, and then remain at minimum overnight on weekdays. Which configuration meets this requirement?
- You must create a disaster recovery environment for existing host pools in West US while minimizing cost and administration. What should you do?
- You must deliver a legacy engineering application that installs kernel-mode drivers and shell extensions to users in a pooled Windows 11 Enterprise multi-session host pool. Updates are infrequent, performance is critical, and sign-in time must be minimized. What should you do?
- You must deploy pooled Windows 11 Enterprise multi-session hosts for a 3D design team in West Europe that requires NVIDIA GPU acceleration and CUDA support. Which two actions are required? (Choose two.)
- You must deploy session hosts to a subnet with no network line-of-sight to domain controllers. Users are cloud-only Microsoft Entra ID accounts. You want the VMs to join during provisioning without any on-premises dependencies. What should you configure during deployment?
- You must deploy the Microsoft Remote Desktop client (MSRDC) to 20 Windows 10 devices so the client is available to every user who signs in. How should you install the MSI?
- You must design profile storage for a single-region Azure Virtual Desktop deployment that spans three availability zones. The solution must tolerate a zone failure with zero data loss (RPO=0) and target an RTO under 30 minutes with minimal administrative actions. Which option should you choose?
- You must ensure that both user connection attempts and assignment changes to RemoteApp application groups are logged to a Log Analytics workspace for your Azure Virtual Desktop deployment. Which two Diagnostic settings do you need to configure? (Choose two.)
- You must give external users (Windows 10 Pro and Windows 10 Enterprise) who cannot install applications access to the AVD deployment. Which client should you recommend they use to connect?
- You must implement proactive notifications when a session host becomes Unregistered for more than 5 minutes, when users are denied sign-in due to insufficient capacity, and when the Azure Virtual Desktop service has an outage in the region. You want to minimize configuration objects. Which two actions should you take? (Choose two.)
- You must install Microsoft Antimalware for Azure on Azure Virtual Desktop session hosts. What should you do?
- You must patch several session hosts without disrupting active users and want each VM to deallocate after the last user signs out. What should you do? (Choose two.)
- You must provide 50 temporary contractors with dedicated Windows 11 Enterprise desktops. The first time a contractor signs in, they should be permanently mapped to a specific VM without an administrator manually choosing the VM. Which host pool configuration should you use?
- You must provide desktops for 700 seasonal agents working Monday–Friday, 9 AM–5 PM. Expected concurrency is 60%. Users do not require persistent customizations, and the goal is to minimize compute cost. Which design should you choose?
- You must require multifactor authentication only when users launch Azure Virtual Desktop resources from outside named corporate locations. Other cloud apps should not be affected. Which Conditional Access configuration meets the requirement with the least scope change?
- You must restrict all outbound internet traffic from Azure Virtual Desktop session hosts while still allowing host registration and user sign‑in to Azure AD. Which two Azure service tags should you allow over TCP 443 from the session hosts to meet this requirement? (Select two answers.)
- You must right-size new pooled Windows 11 Enterprise multi-session host pools by assessing current on-premises RDS servers. You want realistic density and performance assumptions. Which two Azure Migrate assessment steps or settings should you use? (Select two answers.)
- You must standardize session-host builds in East US and West Europe. New host pools in both regions must use the same image version, and VM provisioning should be fast in each region even during peak hours. Which two actions should you perform? (Choose two.)
- You need a ramp-down configuration that begins at 19:00, warns users, then forces logoff at 19:15, and ensures only 10% of hosts remain available overnight with unused hosts deallocated. Which two settings should you configure in the scaling plan? (Choose two.)
- You need profile resiliency across two Azure regions for Azure Virtual Desktop. FSLogix must write to Azure Files Premium shares in both East US and West US and use a fast local cache on each session host. Which two actions should you take? (Choose two)
- You need to allow users to restore files saved to their FSLogix profiles. Which action should you take in the Azure portal?
- You need to attach a new data disk to an existing Azure Virtual Desktop session host. Which object should you modify?
- You need to automatically grant Azure Virtual Desktop access to any new employee whose department attribute equals Finance. The application group is named Finance-Apps. You want to avoid manual user assignments. Which two configurations should you implement? (Each correct answer presents part of the solution. Choose two answers.)
- You need to create a pooled host pool that supports multiple concurrent user sessions per VM and requires Windows 11 features. Which base image should you select when creating the session hosts?
- You need to dynamically scale resources for a pooled host pool based on the number of sessions per host. What should you create?
- You need to ensure every current and future virtual machine in resource group RG-AVD used for Azure Virtual Desktop session hosts has a system-assigned managed identity enabled and carries the tags Role=AVD and Environment=Prod. Enforcement must auto-remediate existing noncompliant VMs. What should you do?
- You need to grant your help desk the minimum permissions to: view and manage user sessions (send message, log off, disconnect) in a specific host pool and restart affected session host VMs when needed. They must not create or modify Azure resources. Which two role assignments should you configure? (Each correct answer presents part of the solution. Choose two answers.)
- You need to implement network security to meet the security and performance requirements. Which two actions should you perform?
- You need to modify the custom virtual machine images to meet the deployment requirements. What should you install?
- You need to optimize both HTML5 video playback from specific streaming sites in Microsoft Edge within Azure Virtual Desktop sessions and Microsoft Teams calling quality. Which two configurations must you implement on the session hosts? Choose two answers.
- You need to power on all session hosts in a specific resource group at 07:30 on weekdays and deallocate them at 20:00 if a scaling plan isn’t used. You will use Azure Automation. What should you implement? (Choose two.)
- You need to prevent FSLogix profile containers from applying to specific users. What should you change on each session host?
- You need to run containerized applications for AVD without installing the apps on session hosts. Which packaging format should you recommend?
- You operate a pooled host pool and want to spread user sessions evenly across all available session hosts to minimize memory pressure on any single VM. Which load-balancing algorithm should you configure?
- You operate pooled host pools with stateless session hosts using ephemeral OS disks. FSLogix profiles are on Azure Files Premium. You need to implement backup and disaster recovery while avoiding unnecessary protection of ephemeral resources. Which two actions should you take? (Select two answers.)
- You operate three Azure Virtual Desktop host pools across two subscriptions. You want to use Azure Virtual Desktop Insights to view connections, session host health, and utilization for all pools in a single Log Analytics workspace. Which two actions must you perform so that the Insights workbook populates with both service logs and host performance data for every pool? (Choose two.)
- You plan to deploy a new Azure Virtual Desktop host pool but cannot complete the deployment. What should you do to enable the deployment?
- You plan to deploy FSLogix Application Masking to 20 Windows 10 Enterprise multi-session session hosts and want to minimize administrative effort when distributing rule sets. Where should you copy the rule sets?
- You plan to deploy Windows 11 session hosts that will be domain-joined to an on-premises Active Directory forest and hybrid Microsoft Entra joined. Which two prerequisites must you configure before deploying the host pool? (Each correct answer presents part of the solution. Choose two answers.)
- You plan to implement FSLogix profile containers for the Seattle office. Which storage account should you use?
- You plan to provide external users access to several host pools. Which host pools will be billed using per-user access pricing?
- You plan to sign users out of a specific Azure Virtual Desktop session host from a PowerShell script before maintenance. Which PowerShell module must the script load?
- You plan to standardize guest monitoring for all Azure Virtual Desktop session hosts across three subscriptions. Requirements: collect Windows Event logs for AVD agent and RDP, capture CPU, memory, disk, and network performance, and centralize to a single Log Analytics workspace using the Azure Monitor Agent only. What two configurations should you implement? (Choose two.)
- You plan to use existing virtual machines in an Azure Virtual Desktop deployment and have created a host pool. To add the existing VMs to the host pool, what must you do first?
- You plan to use the Start/Stop VMs during off-hours feature and need automatic shutdown of session hosts based on CPU utilization. What must you configure on the session hosts?
- You prepared a template VM with FSLogix and required applications for Azure Virtual Desktop. You plan to capture it as a generalized image and create a new image version in an Azure Compute Gallery. Which two steps must you complete before creating the image version? (Choose two.)
- You published a RemoteApp named AppVersion1. Which PowerShell cmdlet will update the Remote Desktop client display name to Sales Contact Application?
- You published image version 2.1.0 in an Azure Compute Gallery and your ARM templates reference version "latest". After deploying new session hosts, you discover a regression in 2.1.0. You must prevent further deployments from using 2.1.0 when "latest" is specified but keep it available for limited testing, and plan a rollback for affected hosts. Which two actions should you take? (Choose two.)
- You use storage account store1 with a file share named profiles for FSLogix profile containers. Which path should you configure on the session hosts?
- You want alerting when host availability is low and when user load per available host is high in a pooled host pool connected to a Log Analytics workspace with Azure Virtual Desktop Insights. Which two alert rules should you create? (Choose two.)
- You want to minimize FSLogix profile growth while ensuring users’ Desktop, Documents, and Pictures roam across Azure Virtual Desktop sessions. Which two actions should you take? (Choose two)
- You will configure Start VM on Connect for three host pools whose session host VMs reside in two different subscriptions. You will use a single Microsoft Entra app registration (service principal) for all pools and want the least privilege required to start VMs. What RBAC assignment should you apply to the service principal?
- You will create session hosts from a master VM (Image1) stored in a shared image gallery. What must you run on Image1 before adding it to the gallery so new session hosts have unique names and SIDs?
- You will deploy 1,000 vCPUs worth of Dv5-series session hosts in West Europe at 08:00 on a specific go-live date. You must guarantee capacity at that time and avoid deployment failures due to limits. Which two actions should you complete well in advance? (Select two answers.)
- You will deploy 10 session hosts that will use MSIX app attach. Which directory service supports MSIX app attach?
- You will deploy a personal host pool of 15 Windows 10 Enterprise VMs joined to the on-prem AD for users in domain group Department1. Ensure each user is automatically added to the local Administrators group on the VM they sign in to. What should you configure?
- You will deploy Azure Virtual Desktop host pools with load balancing and autoscaling to meet departmental requirements (minimize cost). What is the minimum number of host pools required?
- You’re designing session hosts for a line-of-business app that uses on-premises SMB shares and requires Group Policy enforcement. The Azure VMs will access a Windows Server file server on-premises over a site-to-site VPN. Which join type should you choose for the session hosts?
- You’re sizing a pooled host pool for 180 concurrent knowledge workers using Windows 11 Enterprise multi-session and Microsoft 365 Apps. Your testing indicates a medium workload of roughly 6 users per vCPU. You plan to target about 70% CPU utilization at capacity. How many D8as v5 VMs should you provision?
- Your AVD host pool uses FSLogix user profiles stored in an Azure Files share named share1. You need to back up share1 with Azure Backup. Which resource should you create first?
- Your Azure AD-joined Windows 11 Enterprise multi-session session hosts are enrolled in Microsoft Intune. You must centrally enforce Microsoft Defender Antivirus settings and also deploy several custom security-related registry values. Which two Intune policy types should you use? Each correct answer presents part of the solution.
- Your Azure Virtual Desktop environment uses MSIX app attach and FSLogix profiles hosted on Azure Files Premium LRS in a region with three availability zones. A recent zone failure caused users to be unable to sign in or launch apps. You need to improve business continuity for applications, profiles, and user access without adding a second region. Which two actions directly address the issue? (Select two answers.)
- Your Azure Virtual Desktop environment uses Windows 11 Enterprise multi-session session hosts. You maintain a steady baseline of 200 vCPUs 24x7, but you often change VM sizes within the same region due to capacity. You want to reduce cost for the baseline without locking to a specific size. Which two statements are correct? (Select two answers.)
- Your Azure Virtual Desktop host pool is on a virtual network connected to on-premises via site-to-site VPN. To ensure only on-premises users can access the managed AVD resources with minimal administrative effort, what should you configure?
- Your Azure Virtual Desktop session hosts will be Azure AD-joined only. No Active Directory Domain Services (AD DS) or Azure AD DS will be available. You must use FSLogix Profile Containers with identity-based access to the share. Which storage option should you use?
- Your company has 60,000 users. For FSLogix profile containers, recommend the storage solution that delivers the highest IOPS and lowest latency for the best desktop experience.
- Your company is evaluating Azure Virtual Desktop for three branch offices with different ISPs. You must measure expected user round‑trip latency to the Azure Virtual Desktop service and verify whether UDP can be used before choosing target Azure regions. Which two actions should you perform? (Select two answers.)
- Your company must meet strict audit requirements for Azure Virtual Desktop: capture connection, host, and management logs centrally for seven years, and reduce the risk of data exfiltration from sessions. Which two actions should you implement? Each correct answer presents part of the solution.
- Your company runs Azure Virtual Desktop with pooled Windows 11 Enterprise multi-session session hosts across three subscriptions. Security requires all existing and newly created session hosts to be onboarded to Microsoft Defender for Endpoint automatically at deployment time without modifying the golden image or running post-logon scripts. What should you configure?
- Your DevOps team deploys Azure Virtual Desktop host pools and session hosts through Bicep. Domain-join credentials and an SSL certificate for reverse connect must be supplied at deployment time without putting secrets in source code or parameter files. Auditors require that secrets be recoverable if accidentally deleted. Which two actions should you take? Each correct answer presents part of the solution.
- Your Microsoft Entra tenant contoso.com hosts an Azure Virtual Desktop deployment with a RemoteApp app group named RemoteApp1. A partner company (Fabrikam) has 200 users who need access to RemoteApp1. Which pricing type applies to providing RemoteApp1 access to those Fabrikam users?
- Your on-premises Active Directory syncs with Microsoft Entra. You have an Azure virtual network VNet1 and will deploy an AVD host pool (Pool1) with session hosts joined to the on-premises AD domain. Which three networking resources should you include to provide connectivity between Azure and on-premises?
- Your on-premises AD domain (syncs to Azure AD) has the domain controllers listed. DNS servers forward to an external DNS service. You create VNET2 peered to VNET1 with gateway transit and will place an Azure Virtual Desktop host pool in VNET2; session hosts will join the AD domain. To ensure AVD users can resolve on-premises and Azure resources, maintain operation if a DNS server fails, and minimize admin effort, what should you configure?
- Your operations team wants a single-pane view showing per-host registration status, CPU/memory utilization trends, and user sign-in failures across all host pools in a specific resource group. The view must auto-refresh on a shared Azure dashboard. What should you do?
- Your organization uses ExpressRoute private peering between the corporate network and Azure. You want to reduce latency and jitter for Azure Virtual Desktop by enabling RDP Shortpath for managed networks between corporate devices and session hosts. Which two changes are required? (Select two answers.)
- Your organization wants a Microsoft-recommended security configuration that can be pinned to a specific version and upgraded in a controlled manner for Azure AD-joined Windows 11 Enterprise multi-session session hosts managed by Intune. What should you deploy?
- Your organization wants to delegate Azure Virtual Desktop object management (create and manage host pools, application groups, and workspaces) to the EUC engineering team without granting permissions to create, modify, or delete virtual machines, networks, or storage. You will scope the role at the resource group that contains only Azure Virtual Desktop resources. Which built-in Azure role should you assign?
- Your organization will allow Azure Virtual Desktop access only from corporate-managed Windows devices that are both hybrid Azure AD joined and Intune-compliant. Which two Conditional Access grant controls should you require to enforce this? (Each correct answer presents part of the solution. Choose two answers.)
- Your security policy requires that local drive redirection and clipboard redirection be disabled for a pooled host pool, but users must be able to print to their locally installed printers. Which host pool RDP properties should you configure?
- Your security team blocks all unsolicited inbound traffic to session hosts and plans to deny general internet egress. Users must connect to Azure Virtual Desktop without exposing RDP on the public internet. Which two configurations enable connectivity while honoring these constraints? (Select two answers.)
- Your security team mandates phishing-resistant MFA for a group of Azure Virtual Desktop administrators, but standard users may continue using any MFA method. You will enforce this via Conditional Access. Which setting should you use in the grant controls of the admin-targeted policy?
- Your session hosts run Windows 11 Enterprise multi-session, are Azure AD joined, and are enrolled in Microsoft Intune. You need to deliver a Microsoft Store app and a line-of-business Win32 application to all session hosts with centralized updates and without rebuilding images. Choose two answers.
- Your subscription Sub1 contains an Azure Virtual Desktop deployment. To enable Azure Virtual Desktop per-user access pricing for a specific user (User1), at which scope should you enable per-user access pricing?
- Your Windows Server 2022 Azure Virtual Desktop session hosts appear in Microsoft Defender for Cloud with the recommendation "A vulnerability assessment solution should be enabled on your virtual machines." You want to clear this recommendation at scale with minimal manual steps and without replacing the VMs. Which two actions would satisfy the recommendation? Each correct answer presents a complete solution.
- Your Windows users must have multi-monitor support and Microsoft Teams media optimization when accessing Azure Virtual Desktop. Which client application should they use?
Microsoft DevOps Engineer Expert AZ-400 Certification All exam questions
- A branch policy requires that code builds succeed before merging. To allow a specific user to always merge changes into the master branch regardless of build status while following least-privilege principles, what should you do?
- A build pipeline in Azure Pipelines runs separate jobs to compile an application for 10 different architectures and currently requires about 24 hours to complete. Which two actions should you take to reduce the total pipeline execution time?
- A build pipeline intermittently fails because a test that measures an API endpoint’s response time is unstable. You need to prevent the pipeline from failing due to that test. Which two actions should you take?
- A build pipeline uses approximately 50 open source libraries. You must ensure all open source libraries comply with your organization's licensing standards. Which service should you use?
- A commit to a public repository Public1 contains a pattern that matches a regular expression for secret scanning. Which party receives the first notification when the commit is made?
- A company has 60 developers divided into four teams of 15, using agile methodology. To let each team own their work while collaborating toward common goals, which parts of the work-item taxonomy should teams be allowed to manage autonomously?
- A company is developing a Java solution and uses a SonarQube server to analyze .NET code. To analyze and monitor the Java code quality, which build pipeline task type should be added?
- A company is developing a Java solution and uses a SonarQube server to analyze .NET code. Which build pipeline task type should be added to support Java builds?
- A company uses GitHub and has a team that performs code reviews. You must automate review assignment to prioritize reviewers with the fewest outstanding assignments, equalize the number of reviews over any 30-day period, and exclude the team leader from assignments. Which two configuration actions should you perform? (Choose two.)
- A containerized solution in Azure Container Instances includes a frontend container (App1) and a backend container (DB1). DB1 performs a lengthy data load on startup. You need to ensure DB1 is ready to handle requests before App1 accepts user traffic. Which container health mechanism should you configure?
- A development team using Visual Studio must have a custom package centrally managed and automatically available to all developers with the latest version. Which three actions should be performed? (Choose three.)
- A Git repository in Azure Repos uses protected master branch and feature work is developed in topic branches. To consolidate commit history and ensure changes are merged as a single commit, which pull request merge strategy should be enforced in the branch policy?
- A GitHub Actions workflow requires a 256-KB secret that must be accessible only to the workflow and with minimal administrative overhead. Which approach do you recommend?
- A GitHub repository contains multiple workflows and an environment-level secret. To make the secret available to all workflows, what should you do first?
- A GitHub repository uses GitHub Actions and stores access keys as encrypted secrets. You plan to update the secrets via the GitHub REST API. Which encryption library should you use to encrypt the secrets before including them in the API call?
- A globally accessed ASP.NET Core web app requires a URL ping test every five minutes and an alert when the app is unavailable from specific Azure regions. The solution should minimize development time. What should you implement?
- A large file was accidentally committed to a GitHub repository and you need to remove it to reduce repository size. Which tool should you use?
- A mobile app targeting Android and iOS requires: collecting crash reports, distributing beta builds to testers, and obtaining user feedback on new features. Which solution should you recommend?
- A multi-tier application has its front end hosted in Azure App Service. Which service should you use to determine the average page load times for the application?
- A multi-tier application uses Azure Web Apps for the front end and Azure SQL Database for the back end. You must capture and centrally store telemetry to allow ad-hoc queries for baselines, trigger alerts when metrics exceed those baselines, and retain application and database metrics in one location. Which service should you recommend?
- A pipeline builds a container image (Image1) and pushes it to an Azure Container Registry (ACR1). Image1 is based on a base image stored in Docker Hub. Ensure Image1 is rebuilt automatically whenever the base image is updated. What should you do?
- A project in Azure DevOps must restore a NuGet package from a feed that requires authentication. What should the project use to automate authentication for package restore?
- A project uses an Azure Boards board and a GitHub repository containing README.md. You need README.md to display the board's work item status with minimal administrative effort. What should you do first?
- A repository contains multiple versions of an Azure Pipelines template, and you will deploy multiple pipelines that use a stored template. To guarantee each pipeline uses a fixed template version, which reference should you use?
- A security review shows too many users have privileged access. You must implement privileged access management that enforces time limits on privileged access and requires approval to activate roles while minimizing cost. What should you do first?
- A sensitive file was accidentally committed to a GitHub repository. Which tools can be used to remove the file and its history from the repository? (Choose two.)
- A user pushed a sensitive file Data.txt to a GitHub repository. You must purge the file from the repository history. Which command (or command sequence) can you use to accomplish this?
- A web application hosted in Azure App Service stores its data in an Azure SQL Database. You must generate an alert when the database has 10,000 concurrent connections with minimal development effort. Which Diagnostics setting for the database should you select?
- After adding virtual machines as managed nodes in Azure Automation State Configuration, what is the next step to configure the managed computers in Pool7?
- After creating Project3 in Azure DevOps, what is the first action required to meet the project's requirements?
- An application is deployed to Production-A and Production-B via Azure Pipelines. Before marking the application as complete and ready for release to Production-B, you must ensure there are no active Azure Monitor alerts in Production-A and minimize administrative effort. What should you add to the pipeline?
- An Azure Automation account contains a runbook whose source code is stored in an Azure DevOps repository in Project1. You need every commit to automatically update and publish the runbook to Azure Automation. Which setting should you configure?
- An Azure Boards team dashboard monitors progress and work items for App1. You need a metric widget that measures how long it takes to close a work item after work on it has started. Which widget type should you add?
- An Azure Boards work item has the ID 715 and is linked to your GitHub repository. What text should you include in a commit message so the work item is updated automatically?
- An Azure Container Registry contains an ACR Tasks task named Task1 configured to run every five days. Which az CLI command will trigger Task1 to run immediately?
- An Azure DevOps project contains a Git repository and a release pipeline that triggers a build and release whenever code is committed. Ensure that release information for the pipeline is automatically added to the work items associated with the related Git commit. Which action should you take?
- An Azure DevOps project produces npm packages consumed by multiple projects. Configure Azure Artifacts so both latest and prerelease package versions are available for consumers. What should you do?
- An Azure Monitor alert is generated for server-side errors from your web app and currently sends email notifications. To receive those alerts in Microsoft Teams, which two actions should you perform?
- An Azure Pipelines build job for App1 runs on a Microsoft-hosted Windows agent and intermittently times out. To ensure the build completes while minimizing administrative effort, what should you do?
- An Azure Pipelines build occasionally experiences delays before the pipeline begins execution. Which action will reduce the time it takes for the build pipeline to start?
- An Azure Policy is assigned to the Tenant root group. What effect does the policy enforce?
- An Azure virtual machine is monitored by Azure Monitor and has the Log Analytics agent installed. You plan to deploy the Service Map solution from the Azure Marketplace. Which agent must you install on the VM to support Service Map?
- An Azure virtual machine scale set (VMSS1) is behind a Standard Load Balancer (LB1). A web app deployed to VMSS1 requires HTTPS and mutual TLS client certificates. You must recommend a minimal-administration health check solution that also identifies whether individual VMSS1 instances are eligible for upgrade operations. What should you include in your recommendation?
- An Azure VM scale set (VMSS1) hosts a stateful web application (WebApp1) that is deployed via the Custom Script extension. The deployment script is stored in an Azure Storage account (sa1). You will make a minor UI change and run limited user testing of the new version on VMSS1. Which three actions should you perform?
- An Azure web app named webapp1 running on .NET Core sends telemetry to an Application Insights resource named AppInsights1. You must enforce a fixed sampling rate for telemetry from webapp1. Which file should you modify in the webapp1 codebase?
- An existing production application (App1) will receive an update that introduces a new service which depends on another application (App2) still in development. You must deploy the App1 update before App2 is available and be able to enable the new service in App1 once App2 is deployed. What should you implement?
- App1 is built with Azure Pipelines and its source code in Azure Repos includes open-source libraries. Which tool should you use to detect security vulnerabilities in those open-source dependencies?
- As part of a security validation strategy in Azure DevOps, you need to identify package dependencies that have known security issues which can be resolved by updating the packages. Which tool should you use?
- As part of Agile retrospectives at the end of each sprint, which three questions should the team address?
- Assess the statement: "The Burnup widget measures the elapsed time from work item creation to completion." If the statement is accurate, select 'No adjustment required.' If it is inaccurate, select the correct term.
- Dependabot has detected a dependency update for App1 stored in GitHub, and your organization uses Azure Pipelines for CI. What is the first action you should take to apply the dependency update delivered by Dependabot?
- DepPipeline1 and ADFPipeline1 share a credential stored in Vault1. To configure ADFPipeline1 to retrieve the credential from Vault1, which Azure Data Factory activity type should you use?
- Determine whether the following statement is accurate. Black Duck can be used to ensure that all open-source libraries comply with your company's licensing criteria.
- Determine whether the following statement is accurate. For a multi-tier application whose front end is hosted in Azure App Service, you should use Azure Event Hubs to measure average page load times.
- During a code review of a Java application you find unused variables and empty catch blocks. Which build task setting do you recommend to detect these quality issues?
- During a code review you find many issues such as unused variables and empty catch blocks. Which build task configuration should you recommend to detect these issues?
- Evaluate the statement: "To build an IIS web application that runs in Docker, you should use the Default build agent pool." If the statement is accurate, select 'No adjustment required.' If it is inaccurate, select the correct option.
- For a Git branching strategy that allows parallel work on independent tasks, keeps the mainline always releasable, allows features to be abandoned at any time, and encourages experimentation, which approach do you recommend?
- For a Java-based application build in Azure DevOps, which code coverage format/tool should you use to collect coverage and publish results when the supported option is Cobertura?
- For a monitoring solution that parses logs from multiple sources and helps identify root causes of issues in Azure Pipelines, which advanced monitoring feature should be included?
- For an Azure DevOps organization, which authentication mechanism should you recommend to support Git authentication while minimizing the need to repeatedly provide credentials?
- From a Windows system you will use Terraform to deploy an Azure resource group. Which two frameworks should you install to support this deployment? (Select two.)
- GitHub and Azure Boards are integrated. When creating a pull request in GitHub you want to automatically link the pull request to an existing Azure Boards work item by including the text AB#. To which two pull request elements can you add that text so the link is created? (Select two.)
- Given the services shown in the table and a project managed with Azure Boards, which of the listed services can receive build status change notifications via a webhook?
- How should the Register-AzureRmAutomationDscNode command be modified to resolve the technical issue?
- If a client-side commit-msg Git hook enforces a work item tag in commit messages, which git commit option allows you to make a commit without running the hook?
- In a private Azure DevOps project, a project manager needs permission to create custom work item queries for reporting while following the principle of least privilege. To which security group should you add the project manager?
- In Azure Boards, itemA is dependent on itemB. Using the web portal, how do you define itemA’s dependency on itemB?
- In Azure DevOps web portal, work item itemA depends on work item itemB. From the Backlogs view, how do you add the proper dependency link so itemA depends on itemB?
- In Azure DevOps web portal, you have a work item itemA that depends on another work item itemB. How should you represent this dependency on itemA?
- In GitHub you currently receive email notifications for every team discussion. You want to receive email only for discussions in which you commented or were mentioned. Which two notification settings should you disable?
- In Project1, ensure that every new pipeline executes three specific tasks during pipeline runs. What should you create to enforce this?
- In Project1, what is the first step required to create a published wiki?
- Multiple teams work on multiple projects in Azure DevOps. You need to plan and manage the consumers and producers for each project and provide an overview across all projects. What should you do?
- New releases must meet specified performance baselines in the staging environment before deployment to production. Which Azure Pipelines mechanism prevents deployment when staging performance baselines are not satisfied?
- On an Azure Boards dashboard, which widget type visualizes the time elapsed from when work starts on a work item until the work item is closed?
- Pipeline1 contains a temporary final stage named final1. To allow User1 to delete final1 when testing is complete while following least-privilege principles, at which permission level should you grant User1 access?
- Pipeline1 deploys Azure resources defined by Bicep modules. To ensure all releases comply with Azure Policy before production deployment, what should you configure?
- Project teams publish npm packages to Feed1 in Azure Artifacts and multiple projects consume those packages. To ensure only tested packages are available for consumption while minimizing development effort, what should you do?
- Project1 contains a published wiki in Azure DevOps. You need to change the order of pages displayed in the wiki navigation pane in the Azure DevOps portal. What should you do?
- Project1 in Azure DevOps references an Azure Artifacts feed (Feed1) that contains multiple versions of Package1. Which version of Package1 will be consumed during the build of Project1?
- Project1 uses two environments: environment1 receives the previous release and environment2 receives the latest release. You must expose new releases to only a subset of users and progressively increase the proportion of users routed to environment2. Which deployment approach should you use?
- Recommend a solution that automatically sends a daily summary of application exceptions to Microsoft Teams. Which two Azure services should be used?
- Recommend an application to provide communication for a globally distributed development team that meets these requirements: separate project team channels with persistent chat history; client apps for Windows 10, macOS, iOS, and Android; ability to add external contractors and suppliers; and direct integration with Azure DevOps. Which application should you recommend?
- Release pipelines store secrets as pipeline variables and agent command logging is enabled. What change will prevent the secrets' values from being written to the agent logs?
- Subscription1 contains a custom audit policy (Policy1) that verifies resource naming conventions. Pipeline1 deploys ARM resources to Subscription1. To ensure resources deployed by Pipeline1 comply with Policy1, what should you add to the pipeline?
- The organization uses Azure DevOps for Java project build and release pipelines. Which action should be included to manage technical debt effectively?
- To authenticate users of an ASP.NET application using Azure Active Directory, what is the first configuration step to perform in Azure AD?
- To compare how much time is spent troubleshooting issues discovered during development versus issues discovered after release, which KPI should you use?
- To deploy an application to multiple Azure virtual machines, which type of group should you create? (Select the correct replacement for the term "universal" if it is inaccurate.)
- To detect when common open-source libraries are introduced into the codebase, which tool should be integrated into the build pipeline?
- To distribute a new iOS app release via Microsoft Visual Studio App Center for devices in a private distribution group, which certificate file type must you upload?
- To distribute an iOS application to a private distribution group that includes unprovisioned devices via App Center, what step is required on the Apple side?
- To enable Azure Pipelines for Microsoft Teams notifications, which Organization Settings option in Azure DevOps must be enabled to allow the integration to operate?
- To enable fast rollback to the previous version with minimal downtime for an Azure Web App deployed via Azure Pipelines, which deployment configuration should you use?
- To ensure a pull request can be merged into the main branch only when test coverage exceeds 90%, what should you configure?
- To ensure new releases of App1 are deployed only if they exceed defined performance baselines, with minimal administrative overhead, which feature should you configure?
- To implement Project4, what should you do first?
- To integrate work item tracking with an Agile project management tool so developers can determine whether their commits are deployed, report deployment status, and minimize integration effort, which system should you choose?
- To meet the monitoring requirements for App1, which service should you use?
- To migrate from Team Foundation Server 2013 to Azure DevOps while preserving TFVC changeset dates and work item revision dates and minimizing migration effort, you propose upgrading TFS to the latest RTW release. What additional action should you recommend?
- To reduce the likelihood that infrastructure credentials are leaked from an Azure DevOps pipeline, which of the following should you recommend?
- To upgrade an on-premises application to use an Azure service principal for programmatic sign-in to Azure AD, which three values are required by the application?
- User1 is currently assigned the Contributors role for Pipeline1. To allow User1 to provision an Azure Deployment Environments environment while following least-privilege principles, which role should you assign?
- Using Azure Boards with Azure Repos, you have a bug work item with ID 123. You want a commit to automatically set the work item state to Resolved. What should you include in the commit message?
- Using Azure Boards with Azure Repos, you have a bug work item with ID 123. You want a commit to set the work item state to Resolved. What text should you add to the commit message?
- Using Azure Repos and Azure Pipelines, require that all comments on pull requests be resolved before the pull request is included in a build. To minimize administrative effort, what should you include in the solution?
- Using Calendar Versioning (CalVer) for code assets, you need to include an optional 'beta' tag as part of the version. Which component of the version should contain this tag?
- When automating a Java build in Azure DevOps, you need to collect code coverage metrics and publish the results to the pipeline. Which tool should you use?
- When configuring an upstream source in Azure Artifacts for Python packages, which repository type should you select?
- When deploying a multi-tier application with an Azure Resource Manager template, which mechanism prevents the user performing the deployment from viewing account credentials and connection strings used by the application?
- When deploying a self-hosted Azure Pipelines agent using an unattended configuration script, which two values must be specified in the script?
- When granting an ASP.NET Core application access to secrets in Azure Key Vault using least privilege, which secret permission should be assigned in the Key Vault access policy?
- When integrating GitHub as the repository for an existing Azure DevOps project, which authentication mechanism ensures Azure Pipelines runs under the Azure Pipelines identity?
- When migrating the ARM template expression [if(parameters('isComplete'), '1a', '2a')] to Bicep, which of the following expressions is equivalent?
- When migrating to Azure DevOps, which Azure DevOps service should replace JIRA for issue and project tracking? (Select the correct replacement if the original statement is inaccurate.)
- When multiple builds are pending deployment, you need to ensure that only the most recent build is deployed. Which feature should you use?
- When provisioning a self-hosted Linux agent for Azure DevOps, which authentication mechanism should be used to register the agent?
- When proxying a private upstream MyGet feed into your MyGet feed while using GitHub, which two advantages can this proxying provide? (Select two.)
- When scanning a Node.js project with WhiteSource Bolt, you want only production dependencies scanned so development-only libraries are excluded. Which npm command should you run to ensure production dependencies are installed?
- Which authentication method should Azure Pipelines use to authenticate and control App2 builds?
- Which automated tool should you add to the build pipeline to detect common open-source libraries and address licensing compliance concerns?
- Which Azure AD capability should you configure to require multi-factor authentication for users accessing applications from untrusted networks?
- Which Azure DevOps chart widget reports the elapsed time required for a work item to be completed after it transitions to the Active state?
- Which Azure DevOps process template should you choose to support tracking of requirements, change requests, risks, and reviews?
- Which Azure feature provides security recommendations for Azure App Service web apps and Azure Functions?
- Which branching strategy should be recommended for the investment planning applications suite?
- Which framework should you use to automate UI testing of a web application?
- Which mechanism should be used to enforce the code quality restriction on the release pipeline for the investment planning applications suite?
- Which method should you use to control access to Azure DevOps according to the technical requirements?
- Which of the following user and license management tasks cannot be automated in Azure DevOps?
- Which service should you use to verify that the approximately 50 open-source libraries used by an Azure DevOps build pipeline comply with your company's licensing requirements?
- Which tool should be used to migrate the repository to GitHub while supporting the planned DevOps changes?
- Which tool should you add to the build pipeline to automatically detect when commonly used open-source libraries are introduced to the codebase for licensing compliance?
- Which two components are required to integrate Azure DevOps with an on-premises Bitbucket Server that is protected by a firewall blocking inbound Internet traffic?
- Which two projects qualify for free parallel jobs in Azure Pipelines? Select two.
- Which type of Azure Pipelines check should be configured to query Azure Boards and confirm there are no active work items before deploying a build to production?
- Which type of security tool is most appropriate to integrate into the Continuous Integration (CI) pipeline to detect code-level security issues early?
- Which version control system should you use when multiple developers will work offline frequently and require access to the full project history while offline?
- WhiteSource Bolt scanned a Node.js project and flagged many libraries with invalid licenses. Those libraries are development-only and not part of production deployment. To ensure WhiteSource Bolt scans only production dependencies, which two actions should you perform?
- With Azure Pipelines integrated to GitHub and continuous integration enabled, which setting ensures the system waits for a running build to complete before queuing another build for the same branch?
- Work item itemA is dependent on itemB. Which action in the Azure DevOps web portal defines this dependency correctly?
- You administer an Azure DevOps project that includes package feeds. To allow developers to unlist and deprecate packages while adhering to the principle of least privilege, which access level should you grant them?
- You are assessing your development team's technical debt and want a metric that reflects the amount of technical debt. Which metric should you recommend?
- You are automating UI testing for a web application and need a framework suited to browser automation. Which framework should you use?
- You are building a Docker image that will contain a .NET Core application. The Dockerfile includes numbered lines for reference. To ensure the final image is as small as possible, which line number in the Dockerfile should you modify?
- You are building a mobile app for Android and iOS and manage work items and release cycles in Azure DevOps. You need crash reporting, beta distribution to testers, and a way to collect user feedback on new functionality. Which of the following must be included in your solution?
- You are configuring an Azure Pipelines build task (Task1) that will authenticate using an Azure AD service principal. Which three values must you provide for Task1? Select three.
- You are deploying a server application on Windows Server 2019 Server Core. You created an Azure Key Vault and stored a secret. To secure API secrets for third-party integrations using the Key Vault, which three actions should you perform?
- You are designing a build pipeline that requires a self-hosted agent. The build runs once per day and takes 30 minutes. To minimize cost, which compute option is most appropriate for the agent?
- You are designing a YAML template for Azure Pipelines that includes a parameter named outputfile. Which two syntaxes can be used to reference this parameter in the template? (Select two.)
- You are designing your development process and need a solution for continuous inspection of the codebase to locate common problematic code patterns. What should you include in the recommendation?
- You are developing a multi-tier application that uses Azure App Service web apps as the front end, Azure SQL Database as the back end, and Azure Functions that write to Azure Storage. You need to notify the Azure DevOps team by email when the front end does not return an HTTP 200 status. Which feature should you use?
- You are developing an ASP.NET Core application and must capture telemetry to establish an application utilization baseline while minimizing storage costs. Which two actions should you perform in the application code?
- You are developing an iOS application in Azure DevOps and need to test it manually on 10 devices without publishing it publicly. Which two actions are required? (Select two.)
- You are developing an open-source solution stored in a GitHub repository and have created a public project in Azure DevOps. You plan to use Azure Pipelines and the GitHub Checks API. Which authentication method should you use?
- You are implementing a branching strategy in Azure DevOps. Pull requests must include linked work items, pass build validation, and require at least three reviewers. What should you include in the solution?
- You are integrating an Azure Boards project with a GitHub repository. Which two methods can be used to authenticate Azure Boards to GitHub? Select two.
- You are preparing a database export for deployment to a new environment. Which export format should you use to include schema and data for deployment to Azure SQL?
- You are setting up Azure Pipelines for project PROJ-01 and need a version control system that stores source code on a managed Windows server inside the company network. Which version control solution should you use?
- You are using Azure SQL Database Intelligent Insights and Azure Application Insights for monitoring and need to run ad-hoc queries against the monitoring data. Which query language should you use?
- You built an iOS application and receive crash reports via Crashlytics. You need to capture crash-free user metrics, custom events, and breadcrumbs. Which action should you take?
- You collect metrics for an Azure Kubernetes Service (AKS) cluster (AKS1) using the Azure Monitor managed service for Prometheus. Which query language should you use to analyze AKS1 performance?
- You create an Azure Monitor alert rule for the resource named ASP-9bb7. Which action will cause the alert to fire?
- You created a new Azure DevOps team and will use Azure DevOps for sprint planning. To visualize workflow using an Agile approach, which Azure DevOps feature should you use?
- You created an Azure DevOps project for an application to be deployed to multiple Windows Server 2016 Azure virtual machines. You need a deployment solution that enforces a uniform VM configuration and minimizes administrative effort. Which of the following should be included in your solution? (Choose two.)
- You created an Azure Logic App to send email notifications when an Application Insights availability test detects degraded availability. Which type of Logic App trigger should you use to invoke the workflow from the availability test?
- You deploy a containerized application (App1) to an Azure Container Instance (ACI1). You need ACI1 to automatically restart the container when App1 becomes unresponsive. What should you add to App1's YAML configuration?
- You deploy a heavily used web app (App1) to a virtual machine scale set (VMSS1) configured for autoscaling. Usage varies weekly. You need a low-administration solution to detect an abnormal increase in failed request rate for App1. What should you recommend?
- You enabled GitHub code scanning and opened a pull request from a non-default branch, but the scanning report shows “Analysis not found.” Which two actions will ensure code scanning completes successfully for the pull request?
- You enabled Smart Detection in Application Insights for a web app on the shared service plan tier. Standard metrics appear in logs, but a test failure did not generate a Smart Detection notification. What is preventing the Smart Detection notification from being sent?
- You fixed a bug that was introduced in version 3.4.3 of App1. Which version number should you assign to the new release?
- You have a custom test task with inputs testResultsFiles: **/TEST-*.trx, searchFolder: $(System.DefaultWorkingDirectory), mergeTestResults: true. Which test result format should be used for testResultsFiles?
- You have a pipeline named Pipeline1 in Azure Pipelines and you need to create a service connection that will allow Pipeline1 to download a public container image. Which type of service connection should you create?
- You have a private distribution group that contains both provisioned and unprovisioned iOS devices. You need to distribute a new iOS application to the distribution group using Visual Studio App Center. What should you do?
- You have a private distribution group with provisioned and unprovisioned iOS devices and need to distribute a new iOS app via Visual Studio App Center. Which option should you choose in App Center to proceed with distribution?
- You have a private GitHub repository and want to display its commit status in Azure Boards. What is the first action you should take?
- You have a project Board1 (a Kanban board) in Azure DevOps and have added the Azure Boards app to a Microsoft Teams channel. You need to enable users to create work items on Board1 from within Microsoft Teams. Which command should you run?
- You have a project in Azure DevOps. Template1.yml contains the following steps: npm install, yarn install, and npm run compile. File1.yml currently defines a parameter usersteps and includes tasks MyTask@1 and a script to echo Done. You must ensure that Template1.yml is executed before File1.yml. How should you update File1.yml?
- You have a repository on GitHub and need to clone it into Azure DevOps. Which procedure should you use to import the repository into Azure DevOps?
- You have a self-hosted Windows Server 2019 agent in an agent pool used by a build pipeline for App1. A new project will add a second pipeline that builds App2, which has conflicting dependencies with App1. You must minimize conflicts between the two pipelines while keeping infrastructure costs low. What should you do?
- You have an agent pool (Pool1) with a Windows Server 2022 self-hosted agent used by Pipe1. Project2 will add Pipe2 and App1 and App2 have conflicting dependencies. To minimize the risk of build conflicts while keeping infrastructure costs low, what should you do?
- You have an app deployed with Azure Pipelines to Staging and Production environments. You need to validate app performance in Staging before deploying to Production while minimizing administrative effort. What should you configure in the Azure DevOps project?
- You have an Azure App Service instance named App1. You need to determine when App1 experienced downtime while minimizing administrative effort. Which troubleshooting category in App Service diagnostics should you use?
- You have an Azure DevOps organization named Contoso and a project named Project1. You provisioned an Azure Key Vault named Keyvault1. To reference Keyvault1 secrets in a build pipeline for Project1, what should you do first?
- You have an Azure DevOps project named Project1 and an Azure subscription Sub1. You need to prevent releases from being deployed unless they comply with the Azure Policy rules assigned to Sub1. What should you add to the release pipeline in Project1 to enforce this?
- You have an Azure DevOps project named Project1, an Azure subscription Sub1, and an Azure Key Vault named vault1. You must reference secret values from vault1 in all pipelines of Project1 while preventing those secret values from being stored in the pipelines. What should you do?
- You have an Azure DevOps project that uses multiple package feeds. You want to consolidate to a single feed that stores packages produced internally and consumes packages from remote feeds. The solution must support both public feeds and authenticated feeds. Which feature should you enable in Azure DevOps?
- You have an Azure Key Vault named KV1 and three web servers where you will deploy an application named App1. To allow App1 to retrieve a secret from KV1 while minimizing the number of permission grants and following least privilege, what should you include in the solution?
- You have an Azure Pipelines build and a Slack app integration. To send build notifications to the #development Slack channel, what is the first action you should take?
- You have an Azure subscription and two Bicep templates (Template1 and Template2) that deploy a virtual machine and a website. You will create a third template (Template3) that reuses logic from Template1 and Template2. What should you define first?
- You have an Azure subscription with 50 virtual machines managed by Azure Automation State Configuration. When authoring Desired State Configuration (DSC) files, what is the correct hierarchical order of DSC code blocks?
- You have an Azure subscription with an Azure Pipelines pipeline named Pipeline1 that builds an app named App1. A Slack channel App1chat has an incoming webhook configured. Which mechanism should you use to send a notification to App1chat when a successful build of App1 completes?
- You have an Azure subscription with four virtual machines. You need the VMs to share a single identity whose credentials are managed automatically and to which privileges can be assigned. Which type of identity should you use?
- You have an existing Azure Pipelines build and want to support incremental builds without cleaning or purging the build environment between runs. What should you use?
- You have source code in an on-premises repository and an on-premises build server. You plan to use Azure DevOps with a self-hosted agent to control the build process on that server. After downloading and installing the agent software on the build server, which two actions should you perform next? Select two.
- You have work items 456, 457, and 458. You must create a pull request linked to all three and indicate in the commit message that the PR verifies work item 456. Which commit message should you use?
- You have work items 456, 457, and 458. You need a pull request linked to all three and to mark work item 456 as Done via the commit message. Which commit message achieves this?
- You have work items with IDs 456, 457, and 458. You must create a pull request linked to all three items and automatically set work item 456 to Done. What should you include in the commit message?
- You host container packages that follow Semantic Versioning. App1 is currently version 11.2.0. You apply a code fix for a bug that originated in version 10.5.1. Which version number should you assign to the release?
- You host NuGet packages in Azure Artifacts and need to make a package available to anonymous users outside your organization while minimizing publication points. What should you do?
- You installed the Azure Pipelines app in Microsoft Teams and subscribed to an Azure DevOps project. You want Teams to only notify you about failed builds. What is the first command you should run from Microsoft Teams?
- You maintain a multi-tier web application hosted in production on Azure VMs. You have an ARM template for the VM configuration to test new features. You need a staging environment that minimizes Azure hosting cost, provisions VMs automatically, and uses the custom ARM template. Which approach meets these requirements?
- You manage a GitHub Enterprise account and must enable push protection for secret scanning across the organization’s repositories. What should you do first?
- You manage an Azure web app for e-commerce and need to increase logging when usage exceeds normal patterns while minimizing administrative overhead. Which two resources should you include in the solution?
- You manage build and release pipelines in Azure DevOps for a team of 500 developers with frequent new hires. You want to automate user and license management wherever possible. Which task must be performed manually?
- You manage code in GitHub and must ensure repository owners are notified if a new vulnerable dependency or malware is detected. What should you configure?
- You manage GitHub Enterprise repositories that store C# code. You need to enable CodeQL scanning across the repositories. What should you do?
- You manage package feeds with Azure Artifacts and plan a new feed with the following views: @Local, @Latest, @Release, @Prerelease. Which view must you create manually?
- You manage project code in Azure Repos and have a bug work item with ID 123. To set the work item's state to Resolved via a commit message, what text should you include in the commit message?
- You manage project work items in Azure Boards and code in GitHub. You have work items with IDs 456, 457, and 458. You must create a pull request that links all three work items and sets work item 456 to Done. What should you add to the commit message?
- You manage repositories with GitHub and need a PowerShell script to run automatically before rebase operations. Which mechanism should you use to trigger the script?
- You monitor an application App1 with Application Insights and need to determine how frequently a specific page in the application is accessed. Which pane in Application Insights provides this information?
- You monitor an Azure web app with Application Insights and must trigger an alert when the application experiences a sudden increase in performance issues and failures. Which feature should you use?
- You must choose a deployment strategy that minimizes deployment time and provides the fastest possible rollback. Which strategy meets these requirements?
- You must clone a 1 TB Azure Repos repository named repo1. You need to be able to search the commit history under the /src directory while minimizing clone time. Which git command should you run?
- You must design a configuration management solution for five apps running in development, test, and production that supports feature flags, retains 30 days of change history, stores hierarchical configuration values, enforces RBAC, and provides shared key/value pairs. Which Azure service meets these requirements?
- You must distribute a new iOS app to a private distribution group that contains both provisioned and unprovisioned devices using Visual Studio App Center. What action should you take?
- You must ensure that every code change is validated by the company's security team before the main branch is deployed. Which two actions can you take to enforce this? (Select two.)
- You must send an SMS alert when scheduled maintenance is announced for Azure services. Which two actions should you perform to implement this? (Select two.)
- You need a consolidated monitoring view across resources in multiple resource groups that meets these requirements: supports Azure AD-based RBAC, includes Azure Monitor visuals generated by Kusto Query Language, supports markdown documentation, and displays the most current data for each visual. Which solution should you use to create that consolidated view?
- You need a development environment that integrates with GitHub, provides integrated debugging tools, supports remote and hot-desking users, and works on browsers, tablets, and Chromebooks. Which should you recommend?
- You need to collect detailed information about processes running inside Windows Server virtual machines in Azure to monitor baseline metrics. Which two agents should you install?
- You need to commit a 3 GB ZIP file (VM images used for testing) to Git so that the file is versioned and associated with the corresponding code commits. Which two actions should you take? (Select two.)
- You need to configure GitHub to use Azure Active Directory (Azure AD) for authentication. What should you do first?
- You need to create a release pipeline that updates an Azure SQL Database (DB1) using the Azure SQL Database Deployment task. Which artifact type should the pipeline deploy?
- You need to create a tag named v3.0.5 in a local Git repository and make that tag available in the remote repository. Which two commands should you run? (Select two.)
- You need to ensure that all code in a GitHub repository is scanned for vulnerabilities. Which feature should you use?
- You need to implement static code analysis to improve code quality. During which phase of the development pipeline should you run static code analysis?
- You need to perform inline testing in an Azure DevOps pipeline that uses a Docker deployment model, and you must ensure the test results are not published to the pipeline. Which of the following should you use for inline testing?
- You need to post pull request notifications from an Azure DevOps project to a Microsoft Teams channel while minimizing development effort. What is the simplest solution?
- You notice increased pipeline cycle times and want to determine whether agent-pool exhaustion is the cause. Which of the following actions can help you diagnose agent-pool exhaustion? (Select two.)
- You plan to deploy multiple microservices and need a deployment strategy that allows testing and monitoring changes during a gradual rollout and lets you control the portion of users who receive new releases. Which strategy should you recommend?
- You plan to deploy to an Azure Kubernetes Service (AKS) cluster using the Helm 'package and deploy' task. Which component must be installed in the AKS namespace to support this deployment?
- You plan to publish and share packages using Azure Artifacts. You must release multiple builds of each package through a single feed while restricting access to packages that are still in development. Which feature should you use?
- You plan to use Azure DevOps to build and deploy an application to a Kubernetes cluster. To scan the container image for vulnerabilities before deployment to the cluster, which solution should you include?
- You require that all GitHub Actions changes be reviewed by code owners using a CODEOWNERS file. In which location of the repository should you place the CODEOWNERS file?
- You run Register-AzureRmAutomationDscNode for your test servers and want to ensure they remain correctly configured despite configuration drift. Does setting the -ConfigurationMode parameter to ApplyAndAutocorrect meet this requirement?
- You scan 50 Node.js projects using WhiteSource. Each project contains package.json, package-lock.json, and npm-shrinkwrap.json files. You want WhiteSource to report only the libraries that your projects explicitly reference. What action should you take?
- You store Markdown documentation in a GitHub repository and need changes to trigger recompilation into a static website accessible to users. Which two tools can be used to compile the static documentation website?
- You store source code in Azure Repos but use a third-party CI tool to run builds. Which mechanism does Azure DevOps use to authenticate with the external tool?
- You use a Git repository in Azure DevOps. You need to create a new branch from an existing pull request and later merge the new branch and the pull request’s target branch. The new branch should contain only a subset of the changes from the pull request. Which pull request action should you use?
- You use a single Azure Artifacts feed to publish multiple package versions and need to restrict access to packages that are still in development. Which Azure Artifacts feature should you use?
- You use Azure Boards and GitHub repositories. You have a work item with ID 123 and want to link a GitHub commit to that work item on the Azure Boards board. Which two methods will accomplish this? (Choose two.)
- You use Azure Boards for work items and GitHub for source control. You have a work item with ID 123 and need to link it to a new pull request. Which two of the following are valid ways to create that link? (Choose two.)
- You use Azure Pipelines to build and deploy an application named App1 and created an Application Insights instance AI1. Which file in App1 should you modify to configure the application to use AI1?
- You use Azure Pipelines to build and deploy App1 and must ensure that, before deployment, all code passes a security validation performed by a custom tool. What should you do?
- You use Azure Pipelines to build and test code and need to analyze agent pool usage. Which two of the following accomplish this?
- You use Azure Pipelines to build, test, and deploy an application and need to reduce the time required for unit and integration tests while preserving code coverage metrics. What should you enable?
- You use Azure SQL Database Intelligent Insights and Azure Application Insights for monitoring and must run ad-hoc queries against that monitoring data. Does using Azure Log Analytics meet this requirement?
- You use Azure SQL Database Intelligent Insights and Azure Application Insights for monitoring and must run ad-hoc queries against that monitoring data. Does using the Contextual Query Language (CQL) meet this requirement?
- You use Bicep templates to deploy websites and Azure SQL and will automate deployments with Azure Pipelines using a self-hosted agent on two virtual machines. To minimize administrative effort, what should you do first?
- You use cloud-hosted Jenkins to build code stored in Azure Repos. Which three actions are required so Jenkins can retrieve source from Azure Repos? (Choose three.)
- You use Dependabot to scan dependencies in a GitHub repository. Which two actions will automatically trigger a Dependabot scan? Each correct answer is a complete solution.
- You use GitHub for source control and Microsoft Teams for collaboration. You must post a notification to a Teams channel for every commit while minimizing development effort. What is the simplest solution?
- You use PowerShell Desired State Configuration (DSC) to configure application infrastructure. To perform unit and integration testing of the DSC configuration before deployment, which tool should you use?
- You want Microsoft Teams to receive notifications whenever work items are updated in an Azure DevOps organization. What action should you take?
- You want to ensure new releases are deployed to production only if they meet predefined performance baseline criteria in a staging environment. Which Azure Pipelines feature should you use to block deployments that do not meet the performance baseline?
- You will deploy an application to multiple Azure virtual machines running Windows Server 2019. The deployment must ensure virtual machines maintain a consistent configuration while minimizing administrative effort. Which combination should you recommend?
- You will use AzLog to export virtual machine logs and push them to an Azure Storage account for ingestion by LogRhythm. In which format should you export the logs?
- You will use Microsoft-hosted agents to build container images that will host full Microsoft .NET Framework applications in a YAML pipeline. Which two Microsoft-hosted virtual machine images can you use for the agent?
- Your Azure DevOps build pipeline depends on about fifty open-source libraries. You need to scan these libraries for common security issues. Which approach should you take?
- Your Azure DevOps environment is restricted to users in Azure AD. To ensure only devices connected to the on-premises network can access Azure DevOps, what should you configure?
- Your Azure DevOps free-tier organization has 10 private projects and multiple independent jobs per project. Builds require access to files on an on-premises file system. You run jobs on five self-hosted agents but experience long queues and slow build completion. What should you do to reduce queued builds and decrease build time?
- Your Azure DevOps organization is accessible only to Azure Active Directory users. You must ensure access is allowed only from devices on the company’s on-premises network. Which action should you take?
- Your Azure DevOps project produces npm packages. To reduce the disk space consumed by older packages in Azure Artifacts, which setting should you modify?
- Your Azure subscription contains a Log Analytics workspace WS1 and a virtual machine VM1. You need to install the Microsoft Enterprise Cloud Monitoring extension on VM1. Which two values are required to configure the extension?
- Your build pipeline defines several tests that may fail when third-party applications are unavailable. Ensure the pipeline can still complete successfully if those third-party applications are unavailable. What should you do?
- Your company runs a hybrid environment across Azure and Azure Stack and uses Azure DevOps for CI/CD. Some applications are built with Erlang and Hack. You need a build execution approach that ensures support for these languages across the hybrid cloud while minimizing management overhead. Which option should you use to run the build pipeline?
- Your company runs several Azure App Service web apps and Azure Functions. To view security recommendations for those web apps and functions via the Compute and Apps area, which Azure service should you access?
- Your company uses Azure DevOps for build and deployment pipelines for Java projects. Which two actions should you include in a strategy to manage technical debt? Each correct answer is part of the solution.
- Your environment includes Windows Server 2019 container images in Azure Container Registry, Azure VMs running Ubuntu, a Log Analytics workspace, Azure AD, and an Azure Key Vault. For which two resources can Azure Security Center provide vulnerability assessments?
- Your microservices-based applications use various tracing libraries (OpenTelemetry, OpenCensus, OpenTracing, Honeycomb, Jaeger). After implementing Application Insights in Azure Monitor, you want to centralize distributed tracing. Which two libraries can integrate directly with Application Insights?
- Your organization deploys applications as Docker containers and you want to detect known vulnerabilities in the Docker images used for provisioning. You need to integrate image scanning into the application lifecycle and surface vulnerabilities as early as possible. What should you configure?
- Your organization is developing a Java solution and currently uses SonarQube to analyze .NET code. To analyze and monitor Java code quality in the build pipeline, which task type should you add?
- Your organization uses ServiceNow for change management. You must ensure a change request is processed before any components are deployed to the production environment. What are two ways to integrate ServiceNow into the Azure DevOps release pipeline? (Select two.)
- Your organization uses ServiceNow for incident management and you must create a ServiceNow ticket when an Azure-hosted application fails to authenticate. Which Azure Log Analytics solution should you use?
- Your repository has multiple branches. You make several changes on an experimental branch and need to update the main branch to include those changes while overriding the repository history. Which Git operation should you use?
- Your team uses an Azure Repos Git repository and developers commit directly to the default branch. You must protect the default branch so that new changes are built in feature branches first, each merge is reviewed and approved by at least one release manager, and changes are merged into the default branch using pull requests. What should you configure in Azure Repos?
- Your team uses Azure Pipelines to deploy applications. You must notify all team members in Microsoft Teams when a build or release fails, while minimizing development effort. What should you do?
microsoft display and video All exam questions
- A customer is searching for a new pair of running shoes. They add a pair of shoes to their cart but then leave the site. Which scenario occurs as a result of dynamic re marketing?
- A unique audience target on the Microsoft Audience Network is LinkedIn Profile Targeting
- Adding image extensions is a key element in optimizing your campaigns for multi-channel success. What is the image size you need to get started?
- Adjusting bid strategies to your desired KPIs is a way of optimizing your campaigns for multi-channel success.
- Anica is using Dynamic Re marketing and wants to treat product viewers and cart abandoners differently. Anica can use different bid modifiers for each of these audiences.
- At which levels can you add images to your search campaigns?
- Ayushi is creating a dynamic re marketing list for the Microsoft Audience Network. What is the membership duration range Ayushi can specify?
- Contoso Cameras wants to run image based ads across the brand safe properties of the MSN website, the Microsoft Edge browser, and Outlook.com. Which ad solution from Microsoft Advertising should Contoso Cameras use?
- Contoso Fitness Company's new Microsoft Audience Network campaign has been running for a few weeks and they want to review its performance. What are the ways in which they can do this?
- Contoso Insurance is running a Microsoft Audience Network campaign and wants to see how they're performing across a variety of devices. For which devices can they pull this performance data?
- Contoso Phones is planning a digital marketing campaign and is buying display advertising on a CPM basis. In this instance, what does "CPM" mean?
- Customers who have seen a brand's ad on both the search and audience network visit the site 2.8x more than those who are only exposed to an ad on Bing.
- don't manage their ad campaigns, and It is sold through an agreement, contract, or insertion order, are correct because they Contoso Investments are bidding for individual display impressions in a real time auction. This is an example of which sales model?
- Erica wants to add dynamic re marketing to a Microsoft Audience Network campaign. Which steps must Erica take before implementing dynamic re marketing?
- extending search campaigns to Audience Ads with Multi-Channel Management, and By creating audience ads campaigns from When using the Audience Network Planner how does it describe the audience size? Estimated overall figures: the estimated monthly audience (number of people, per month, in the audience you defined).
- Fernando is creating ad copy for his Microsoft Audience Network Ad for a new line of blazers he is marketing. What is the character limit for the long headline Fernando can write?
- Gabriella is using inline performance reports for her Microsoft Audience Network campaigns. Which of the following can Gabriella see inline?
- If your campaign, ad group, or asset group does not have an ad schedule, the ad will serve based on the last schedule you set.
- Images are the only format of Display advertising.
- In display advertising,what does "M"or "mille"indicate?
- In dynamic re marketing,which of the following statements are true regarding past buyers lists?
- In the direct or guaranteed method of selling display advertising, how is pricing set?
- In the programmatic method of selling display advertising, how is pricing set?
- Mario is looking to collect audience data on his recent Video Ads campaign using the Audience Network Planner. Mario sees that there is no current data available even though the audience segment selected has been active for 2 weeks. What are the steps he should take to find data on the ad?
- Microsoft Audience Network Ads are based on an image or video. When using images, what is the minimum number needed to begin?
- Microsoft Audience Network Campaign performance data can be viewed by day and hour in the ad schedule tab in the Microsoft Advertising Ul.
- Microsoft Audience Network offers a detailed publisher report showing every domain driving traffic to your campaigns.
- Microsoft Audience Network Video Ads can run up to how many seconds?
- Miguel is currently running search and product ads with Microsoft Advertising and wants to understand the ways to take advantage of audience ads. Which of the following are ways in which Miguel can do this?
- Mike wants to use filters in reports to be able to view the performance of Audience Ads in the campaign performance report. Which column is added to be able to view this?
- product ID and page type parameters, 3. Customize additional UET code to include product ID and page type parameter values, 4. Paste customized UET code into all website pages, and 5. Validate with UET tag helper, are correct because they represent the Which buying models are used in the Microsoft Audience Network?
- re marketing without a Microsoft Merchant Center Store or without customizing the standard universal event tracking tag, are In dynamic re marketing, which of the following statements are true regarding past buyers lists?
- Richard is creating a dynamic re marketing campaign on the Microsoft Audience Network and is setting the membership duration to 30 days for shopping cart abandoners. What is the minimum number of abandoners needed in this period for the re marketing to work?
- shown. The statement With audience ads, you decide which keywords you want your ads to appear for is incorrect because Which parameters are required in universal event tracking for dynamic re marketing in audience ads?
- Tailspin Toys wants to use a CPA metric to measure the effectiveness of its display advertising campaigns. What does “CPA" stand for?
- The Contoso Daily News newspaper is selling display ads on its website using the direct or guaranteed method of selling display advertising. Which statements describe this selling model?
- the UET (Universal Event Tracking) tag is implemented on all pages on your website is another best practice because it enables You can take advantage of audience ads with the Microsoft Audience Network by importing native & display campaigns from Facebook.
- The website administrator for Taylor's Hiking Equipment’ is customizing their UET tag to pass parameters for Dynamic Re marketing on a new hiking boot ad. In what order should the following steps be taken to complete this task?
- They require customized universal event tracking set up correctly for that product, are correct because they describe key aspects Marco is interested in tracking when people who were shown an ad and didn't click on it, but still went on to purchase at a later date.Using which feature in the Microsoft Audience Network can Marco track this?
- UET is not recommended when extending search campaigns to Audience Ads, are correct for the following reasons. UET stands for With the Audience Planner you can view the makeup of the audience you defined, broken down by Interest (in-market audience).
- Video captions are a supported video asset in the Microsoft Advertising Audience Network.
- What are the benefits of extending your search campaigns to Audience Ads?
- What are the standard dimensions of a leader board ad?
- What are the standard dimensions of a mid-page unit or rectangle ad?
- What does vCPM stand for?
- What is a difference between audience marketing and search marketing?
- What is optional when setting your bid and budget when creating an Audience Ad campaign?
- What is the correct order of steps to create an online video ad campaign?
- When advertising on the Microsoft Audience Network, you have the ability to exclude selected publisher partners where your ad appears.
- When creating a new campaign on the Microsoft Audience Network, in what order are the 4 steps completed? Organize the options in the correct order.
- When is a customer removed from a product searchers dynamic re marketing list?
- Which of the following are benefits of using the Audience Network Planner?
- Which of the following are best practices for images for the Microsoft Audience Network?
- Which of the following are display advertising metrics?
- Which of the following are image specifications for the Microsoft Audience Network?
- Which of the following are true for UET?
- Which of the following brand safe sites are included in the Microsoft Audience Network?
- Which of the following can you apply to your Microsoft Audience Network campaign?
- Which statement best describes an ad impression?
- Which video ad type appears in the video player pre-roll, mid-roll, or post-roll?
- Who does Microsoft partner with to provide over 300 million free, commercially licensed images for use when creating audience ads?
- Why is display advertising effective?
- With Microsoft Advertising, you can use dynamic re marketing for which of the following?
- You are advertising multiple new hair products your salon has begun to sell. Your goal is to boost the amount of traffic to your site to showcase these products. Which of the following bid models should you use to achieve this?
- You need at least 2 images (wide/rectangle images, sized at 1200 x 628 pixels) to get started with Microsoft Audience Ads.
Microsoft Endpoint Admin Associate MD-102 Certification All exam questions
- A Hyper-V host contains virtual machines described in the accompanying table. On which of these virtual machines is Windows 11 supported for installation?
- A user will connect to Computer1 (running Windows 11) by Remote Desktop. You want the connecting user's device to be authenticated before the Remote Desktop sign-in screen is shown. Which setting should you enable on Computer1?
- A Windows 11 device (Device1) enrolled in Intune has been offline for 30 days. You must remove Device1 from Intune immediately and ensure that if it later checks in, any Intune-provisioned apps and data are removed, while user-installed apps, personal data, and OEM apps remain. Which action should you use?
- Admin1 must use the Microsoft Intune admin center to (1) create and assign apps and policies to users and devices and (2) create, assign, and delete Windows 365 Cloud PC provisioning policies. To follow least privilege and minimize administrative effort, which role assignment is appropriate for Admin1?
- After you apply a Windows 10 feature update, how many days are available to roll back to the previous build?
- All devices (Windows 11, Android, and iOS) are enrolled in Intune. You want to deploy applications from the Enterprise App Catalog using Intune. Which device platform(s) can receive apps from the Enterprise App Catalog?
- All devices are enrolled in Intune. You want devices that haven’t checked in for 30 days to be removed from Intune automatically. Which setting should you configure in the Intune admin center?
- All devices are in the same time zone. You create and assign an update rings policy to all Windows devices, then pause the update rings policy on November 1 while devices stay online. Without changing the policy further, on what date will the devices next try to install updates?
- All Windows devices are enrolled in Microsoft Intune in a Microsoft 365 E5 tenant. You need to deploy the Remote Help application to every device while minimizing administrative overhead. Which app type should you deploy?
- Client1 is a workgroup Windows 11 PC on a public network. You must enable PowerShell remoting and allow connections only from the local subnet. Which PowerShell command should you run?
- Computer1 (Windows 10) is enrolled in Intune and must be set up as a public kiosk device that runs a single full-screen customer-facing app. Which configuration profile template should you use in the Intune admin center?
- Computer2 (Windows 10) has Remote Desktop enabled. From Computer1 (Windows 10) you establish an RDP session to Computer2. To make Computer1’s local drives available inside the Remote Desktop session, what should you change?
- Computers run Windows 11 Pro, are Azure AD–joined, and enrolled in Intune. You need to upgrade these machines to Windows 11 Enterprise. Which Intune setting should you configure?
- Device1 (Windows 10) is joined to Active Directory and enrolled in Intune. It's managed by both Group Policy and Intune. To ensure Intune settings take precedence over Group Policy, what should you configure?
- Device1 is 64-bit Windows 10 Enterprise with Microsoft Office 2019 installed. Given the available Windows 11 Enterprise images (not shown), which image(s) can perform an in-place upgrade of Device1?
- Device1 is Microsoft Entra joined and managed by Intune. You need to apply a remote action that resets the device as quickly as possible and, if the device is powered off, the action should resume after it boots. Which remote action accomplishes this?
- Devices in your company are enrolled in Microsoft Intune (details shown in a referenced table). You define the corporate network as a location named Location1 in the Intune admin center. Which device(s) can apply network location–based compliance policies?
- Finance users bring personal iOS and Android devices enrolled in Intune. A new mobile app (App1) is developed for finance users, and the finance department gains new users monthly. To restrict App1 so only finance users can download it, what is the first action you should take?
- Given devices listed in a table (Device1, Device2, Device3, Device4) that are enrolled in Intune, which of those devices can have their performance analyzed with Endpoint analytics?
- Given the devices enrolled in Microsoft Intune (as shown in the accompanying table), to which device(s) can you apply app configuration policies?
- Given the devices enrolled in Microsoft Intune shown in the table, which of the listed devices can have their updates managed through Intune?
- Given the devices shown in the table, which devices can be onboarded to Microsoft Defender for Endpoint?
- Given the enrolled devices (table provided) where App1 is installed on each device, what is the minimum number of app configuration policies required to manage App1?
- In a hybrid Azure AD environment, Group Policy is taking precedence over Intune settings on 50 Windows 10 devices. What should you do so Intune settings override Group Policy?
- In a Microsoft 365 E5 subscription you create an Office customization in the Microsoft 365 Apps admin center. Given the users shown in the referenced table, which users can download the Office customization file from the admin center?
- In a Microsoft 365 tenant using Intune Suite to manage Windows 11, you create a policy set named Set1 that contains five device configuration profiles (Windows 10 and later) and you also create a device compliance policy named Policy1. To ensure that users who receive the configuration profiles in Set1 always receive Policy1 as well, which setting should you change?
- In a Microsoft 365 tenant using Intune Suite you need to remove User1 from the local Administrators group on all enrolled Windows 11 devices. Which policy type should you configure?
- In an MDT deployment share (DS1) you organized Out-of-Box Drivers into folders per hardware model. To have the Inject Drivers task use Plug-and-Play detection to install drivers for one model, what should you do first?
- In an on-premises AD domain with 10 Windows 10 computers used by finance, you will run a script from Computer1 that executes PowerShell commands remotely on the finance computers. What must you enable on the finance department computers to allow remote PowerShell commands to run from Computer1?
- In Deployment Workbench you modified WinPE settings and added PowerShell support for MDT-managed Windows 11 deployments. What action generates new WinPE boot image files that include those updated settings?
- In Microsoft Defender for Office 365 you automate an attack simulation campaign and require users who fail the simulation to complete follow-up training. What is the maximum number of days that the training remains available to users after the simulation?
- In the contoso.com Active Directory domain you have Computer1 and Computer2 (both Windows 10). From Computer1 you need to run Invoke-Command to execute PowerShell commands on Computer2. What must you do first?
- In the contoso.com Azure AD tenant you will use Windows Autopilot to provision several Windows 10 devices (details in a referenced table). Which device(s) can be configured using Windows Autopilot self-deploying mode?
- In the MDT Deployment Workbench you create a new task sequence using the Standard Client Upgrade Task Sequence template, but no operating system images appear on the Select OS page. You need to be able to choose an OS image to perform a Windows 11 in-place upgrade. What should you do?
- In the Microsoft Intune admin center you are creating a Microsoft 365 Apps application named App1. Based on the objects shown in the referenced table, to which objects can you assign App1?
- In your Active Directory domain all machines run Windows 10 and PowerShell remoting is enabled. You need to allow the user Admin1 to establish remote PowerShell sessions on the computers while following the principle of least privilege. Which group should Admin1 be added to?
- In your Microsoft 365 tenant you are creating a compliance policy called Compliance1. Which of the listed objects can you add to Compliance1 as additional recipients for noncompliance notifications?
- On a Hyper-V host you have virtual machines running Windows 10 as listed. Which of these VMs meets the requirements to be upgraded to Windows 11?
- On Computer5 (running Windows 10) you created a PowerShell script named config.ps1. You need config.ps1 to run after feature updates are applied on Computer5. Which file on Computer5 should you edit?
- Server1 hosts an on-premises MDT deployment share (MDT1). To enable MDT1 to support multicast deployments, which Windows role or service must be installed on Server1?
- Several devices are enrolled in Intune and each has App1 installed. What is the minimum number of app configuration policies required to manage App1 across those devices?
- Ten Windows 10 computers are enrolled in Intune. To deploy Microsoft 365 Apps for enterprise to all these machines, what should you do from the admin centers?
- To compare your Microsoft Defender for Endpoint configuration with Microsoft’s recommended baseline, which tool provides that assessment?
- To set up a service-to-service integration between Microsoft Intune and Microsoft Defender for Endpoint, which configuration area in the Intune admin center do you use?
- Users buy retail PCs that run Windows 10 Pro but your company standard is Windows 10 Enterprise. You must upgrade those PCs to Windows 10 Enterprise, join them to Azure AD, and install several Microsoft Store apps while preserving any user-installed applications and minimizing user interaction. Which solution is the best recommendation?
- Using Microsoft Defender for Cloud Apps, you will perform a security audit of all applications discovered by Cloud Discovery and need to mark which apps were audited so that the audited list appears in the cloud app catalog. What should you do?
- Using Microsoft Intune Suite, you plan to use Microsoft Cloud PKI for email signing and encryption. What is the first step you should take?
- Using Windows Autopilot to provision Windows 11 devices, you must show app and profile configuration progress and prevent users from using devices until all apps and profiles finish installing. Which Autopilot feature should you configure?
- When creating a device configuration profile in Microsoft Intune and you need to add specific OMA-URI settings, which profile template should you choose?
- When you connect to Windows Admin Center to manage Windows 10 machines remotely, you see a certificate-related message (as shown). To stop that message from appearing when connecting, into which certificate store should you import the certificate?
- Windows 10 computers managed by Intune have users storing files in D:\Folder1. Ensure that only a trusted list of applications is allowed to write to D:\Folder1. Which setting should you enable in the device configuration profile?
- Windows 10 computers send all available Windows event logs to an Azure Log Analytics workspace. Given the logged events listed in the table, which of those events are captured in the Log Analytics workspace?
- With a Microsoft 365 E5 subscription and 100 iOS devices enrolled in Intune, you must defer iOS update notifications for 30 days after release. Which configuration should you create?
- With a Microsoft 365 E5 subscription and 100 Windows 10 devices enrolled in Intune, you plan to use Endpoint analytics and need to establish baseline metrics. What must you do first?
- With a Microsoft 365 E5 subscription and all Windows devices enrolled in Intune, you create an app protection policy named Policy1 and target the devices. Which of these apps can Policy1 protect?
- You add a new Windows 10 PC named Computer1 that is in a workgroup to an Azure Log Analytics workspace. What action should you perform on Computer1 so Log Analytics can query its events?
- You add a policy set named Set1 and include Comply1 in it. Given the available resources, which additional resources are permitted to be added to Set1?
- You are replacing 100 company-owned Windows devices and must use MDT to securely wipe and decommission them. The process must back up user state and minimize administrative effort. Which MDT task sequence template should you use?
- You assign a compliance policy named Policy1 to Group1, and Policy1 marks devices Compliant only when their security settings match the policy. Devices not in Group1 are appearing as Compliant. To ensure only devices assigned a compliance policy can be shown as Compliant and all others appear Not compliant, what should you configure in the Intune admin center?
- You assigned an Attack Surface Reduction profile (Profile1) to all Windows 11 devices and now an Adobe Reader plug-in is blocked. To allow that plug-in, what should you configure in Profile1?
- You configure an Intune update ring and then choose Uninstall for its feature updates. When will managed devices begin uninstalling those feature updates?
- You configured Intune to send data to Log Analytics. To investigate devices that failed to enroll in Intune, which Log Analytics category should you examine?
- You created a Conditional Access policy (Policy1) that requires MFA. You want Policy1 to apply only to devices marked noncompliant. Which part of Policy1 should you configure to achieve this?
- You have 1,000 Windows 11 devices enrolled in Intune and plan to deploy an application (App1) that includes multiple installer files. What is the first step you should take to prepare App1 for deployment with Intune?
- You have 10 Windows 10 computers enrolled in MDM. You need to deploy Microsoft 365 Apps for enterprise to all of them. Which action should you take?
- You have 100 iOS devices managed by Intune and need to deploy a custom line-of-business (LOB) app to them. Which file extension should you use for the app package?
- You have 100 Windows 10 computers and want to deploy Microsoft Office Professional Plus 2019 using the Office Deployment Tool (ODT). Which portal should you use to create the ODT customization XML file?
- You have 100 Windows 10 Pro devices joined to Microsoft Entra and purchased Microsoft 365 E5 licenses for all users. To upgrade the devices to Windows 10 Enterprise with minimal administrative effort, which upgrade method should you use?
- You have 150 hybrid Azure AD–joined Windows devices enrolled in Microsoft Intune. You must configure Delivery Optimization so devices can download from the internet and from other local computers, and so that bandwidth usage is limited to 50%. Which method should you use?
- You have 200 Azure AD–joined Windows 10 PCs enrolled in Intune. To enable self-service password reset from the sign-in screen, which section in the Intune admin center should you modify?
- You have 25 Windows 10 Pro PCs and a Microsoft 365 E5 subscription managed by Intune. You need to perform an in-place upgrade to Windows 11 Enterprise while minimizing administrative effort. Which method should you use?
- You have 25 Windows 11 computers enrolled in Microsoft Intune under a Microsoft 365 E5 subscription. To onboard these devices to Microsoft Defender for Endpoint, what should you create in the Microsoft Intune admin center?
- You have 500 Windows 11 PCs that are Microsoft Entra joined and enrolled in Intune. You will manage Microsoft Defender for Endpoint on these devices and need to stop users from disabling Defender for Endpoint. Which action should you take?
- You have a Microsoft 365 E5 subscription and 25 Apple iPads. You plan to enroll the iPads in Microsoft Intune using the Apple Configurator enrollment method. What should you do first?
- You have a Microsoft 365 E5 subscription and a Windows device named Device1 that is enrolled in Microsoft Intune. On January 1, 2024, you assign an app called App1 to Device1 as a required app, but the installation fails. On which date will Intune next try to install App1?
- You have a Microsoft 365 E5 subscription and acquire Windows, Android, and iOS devices that you plan to enroll in Microsoft Intune. When configuring enrollment restrictions, for which device platform(s) can you set restrictions by device manufacturer?
- You have a Microsoft 365 E5 subscription and must enroll Android Enterprise devices into Microsoft Intune using zero‑touch enrollment. What should you perform first?
- You have a Microsoft 365 E5 subscription and need to manage OS updates for corporate-owned Android Enterprise devices enrolled in Microsoft Intune. Which mechanism should you use?
- You have a Microsoft 365 E5 subscription and want to use Device query to collect information from all devices managed by Microsoft Intune. What must you do first?
- You have a Microsoft 365 E5 subscription that contains a group named Group1. You need to restrict device join permission so that only members of Group1 can join devices to the Microsoft Entra tenant. Which setting should you configure in the Microsoft Entra admin center?
- You have a Microsoft 365 E5 subscription with 500 macOS devices enrolled in Microsoft Intune. You must apply Microsoft Defender for Endpoint antivirus policies to those macOS devices while minimizing administrative effort. What should you do?
- You have a Microsoft 365 E5 subscription with devices enrolled in Microsoft Intune. You plan to use Device query to get on‑demand information about device state and must minimize costs. What should you do first?
- You have a Microsoft 365 E5 subscription. You must create a dynamic device group that includes any device whose name contains the word Marketing. Which device membership rule should you use?
- You have a Microsoft 365 E5 subscription. You need devices to be automatically enrolled in Microsoft Intune when a Windows device is joined to the Microsoft Entra tenant. Which setting should you configure?
- You have a Microsoft 365 subscription and every user has a Windows 365 Enterprise license. You need to provision Cloud PCs that will be Microsoft Entra hybrid joined. What is the first action you should take?
- You have a Microsoft 365 subscription and use Microsoft Intune Suite. The subscription includes devices enrolled in Intune as shown in the accompanying table. Which devices support Device query?
- You have a Microsoft 365 subscription with 1,000 iOS devices managed by Intune. You need to block printing of corporate data from managed apps on those devices. Which configuration should you apply?
- You have a Microsoft 365 subscription with 500 Windows 11 computers that are Microsoft Entra joined and enrolled in Microsoft Intune. You will manage Microsoft Defender for Endpoint on these machines and must stop users from turning it off. What action should you take?
- You have a Microsoft 365 tenant with devices enrolled in Microsoft Intune. A conditional access policy named Policy1 is assigned to Group1 and blocks noncompliant devices from accessing OneDrive for Business. How can you determine which noncompliant devices tried to access OneDrive for Business?
- You have a user (User1) and a web app (App1). App1 must accept only modern authentication. You create a Conditional Access policy (CAPolicy1) targeting User1 and App1 and set Grant to Block access. To block only legacy authentication attempts to App1, which condition should you add to CAPolicy1?
- You have a workgroup PC named Computer1 running Windows 11 that you need to join to your Microsoft Entra tenant contoso.com. Which tool should you use?
- You have a workgroup PC named Computer1 running Windows 11 that you want to add to the contoso.com Azure AD tenant. Which tool should you use on the PC to accomplish this?
- You have an Azure AD group named Group1 that contains two Windows 10 Enterprise devices, Device1 and Device2. You assigned a device configuration profile named Profile1 to Group1. You need Profile1 to apply only to Device1. Which part of Profile1 should you change?
- You have an Azure AD tenant with the devices listed in the accompanying table. After purchasing Windows 11 Enterprise E5 licenses, which device(s) can upgrade to Windows 11 Enterprise using Subscription Activation?
- You have an Azure subscription and an on-premises Windows 11 device named Device1 that you want to monitor with Azure Monitor. You create a data collection rule (DCR) named DCR1 in the subscription. To which target should you associate DCR1?
- You have an Intune Android Enterprise enrollment profile named Profile1 configured as Corporate-owned, fully managed. Which method should you use to enroll a new Android device with Profile1?
- You have an MDT deployment share and will deploy Windows 11 using the Standard Client Task Sequence template. You must modify the task sequence so disks are formatted for UEFI and a recovery partition is created. Which task sequence phase should you change?
- You have corporate-owned Android Enterprise devices with work profiles enrolled in Intune and must configure them to run a single app in kiosk mode. Which category in the device restrictions profile should you modify?
- You have corporate-owned, fully managed Android Enterprise devices and will deploy a device restrictions profile (Profile1) that sets maintenance windows for system updates. Which section in the Configuration settings should you edit for Profile1?
- You have devices enrolled in Intune listed in a table. You need to run a bulk device action to send custom notifications. To which device set(s) can you send those custom notifications?
- You have devices enrolled in Microsoft Intune as detailed in the table. To which of these devices is it possible to deploy applications using Intune?
- You have Intune Suite with auto-enrollment enabled and 100 Windows 11 devices in a workgroup. You must connect those devices to the corporate Wi‑Fi and enroll 100 new Windows 11 devices into Intune. Which method should you use?
- You have Microsoft 365 Business Standard and 100 Windows 10 Pro PCs, and you purchase Microsoft 365 E5. To upgrade those devices to Windows 10 Enterprise with the least administrative effort, which upgrade method should you use?
- You have Microsoft 365 E5 subscription devices enrolled in Microsoft Intune. You need to review security tasks in the Microsoft Intune admin center. What should you do first?
- You have over 500 enrolled Android and iOS devices and need policies targeted by OS version. What should you configure first so devices can be targeted by their Android or iOS version?
- You have several Windows 10 devices shown in the referenced table and plan to upgrade them to Windows 11 Enterprise. On which devices can you perform a direct in-place upgrade to Windows 11 Enterprise?
- You have Windows 10, Android, and iOS devices enrolled in Microsoft Intune. For which of these device platforms can you create VPN profiles in the Intune admin center?
- You have Windows 11 devices enrolled in Intune, and three groups named Department1, Department2, and Department3. You need to deploy Microsoft 365 Apps so that: Department1 and Department2 get the full suite including Project and Visio; Department3 gets the full suite including Project but excluding Visio; all other users get the full suite without Project or Visio. What is the minimum number of deployments required?
- You have Windows 11 devices onboarded to Microsoft Defender for Endpoint and need to compare their configurations against industry-standard benchmarks. Which Defender for Endpoint feature should you use?
- You installed MDT and prepared a customized Windows 11 reference computer. Before capturing an image that will be deployed to multiple machines, which command should you run on the reference computer?
- You manage 1,000 devices with Microsoft Intune and look at the Device compliance trends report. For what period will that report show trend data?
- You manage 1,000 Windows 10 computers enrolled in Intune and control their servicing channel via Intune. To check the servicing status for a specific computer, which action should you take?
- You manage 500 Android Enterprise devices that are enrolled in Microsoft Intune. You need to push bookmarks to the Chrome browser on those devices. What type of policy should you create?
- You manage 500 Windows 11 computers in Intune and must deploy monthly security updates with these requirements: deploy to a test group for QA, then automatically deploy to all devices 15 days after QA. Which object should you create in the Intune admin center to meet these requirements?
- You manage devices with Intune. Which of the devices listed can be upgraded to Windows 11 Enterprise using subscription activation?
- You manage iOS devices with Microsoft apps via Microsoft Intune. To prevent users from cutting, copying, and pasting data between Microsoft Excel and other apps on those iOS devices, which configuration should you apply?
- You manage iOS devices with Microsoft Intune and have a compliance policy that blocks jailbroken devices. To turn on Enhanced jailbreak detection, which item should you configure?
- You manage Microsoft Defender Antivirus on 500 Azure AD–joined Windows 11 devices via Intune. To stop users from disabling Microsoft Defender for Endpoint, which action should you take?
- You manage Windows 11 devices in Microsoft Intune and need to determine whether a critical security update is present on a device by using Device query. Which Intune table should you query?
- You manage Windows 11 devices with Intune and need to add User1 to the Remote Desktop Users group on every device in the marketing department so they can provide remote support. What type of policy should you deploy?
- You manage Windows 11 devices with Microsoft Intune in your Microsoft 365 tenant. You must implement Windows Local Administrator Password Solution (Windows LAPS). Which Intune setting type should you configure?
- You manage Windows devices with Intune and have 100 machines from departed employees that must be repurposed by wiping user data and apps with minimal admin effort. Which action should you take?
- You manage Windows devices with Intune and will deploy two Win32 apps, App1 and App2, to all Windows machines. App1 must be installed before App2. You created and deployed both apps in the Intune admin center. Which setting should you configure to ensure App1 is installed prior to App2 on every device?
- You must implement MDM for personal Windows 11 devices so they can be managed by Microsoft Intune, users access company data seamlessly, and users sign in to those devices only with their personal accounts. How should these devices be added to Azure AD?
- You need the Automated Investigation and Response (AIR) remediation level for Device1 set so that all remediation actions require approval. What should you create to target Device1?
- You need to capture startup performance data for managed Windows 11 devices and make that data available in the Intune admin center. Which setting or policy should you enable?
- You need to deploy a custom Android app (APK) to devices using Microsoft Intune. Which app type should you choose for the deployment?
- You need to download a report that lists devices that are NOT enrolled in Microsoft Intune but are assigned an app protection policy. In the Microsoft Intune admin center, which menu path should you select?
- You need to examine details for device wipe operations initiated through Intune. Which Intune report should you check?
- You need to let a user manage Security defaults and create Conditional Access policies while following least-privilege principles. Which Azure AD role should you assign to that user?
- You need to prepare a Win32 application file named App1.exe for deployment with Microsoft Intune. What is the first step you should perform?
- You need to review devices' startup times and how often they restart. Which Microsoft service should you use to obtain these insights?
- You plan to distribute certificates to 500 Windows 10 devices using SCEP. NDES issues certificates from a subordinate CA. Based on the server topology shown, on which server is the required root CA certificate located?
- You plan to implement Microsoft Cloud PKI to deploy personal user certificates to all Windows devices using Microsoft Intune. What is the minimum number of configuration profiles required to support this deployment?
- You plan to provision 25 Windows 11 devices by using Windows Autopilot. To set the Out-of-box experience (OOBE) behaviors, what should you create in the Intune admin center?
- You plan to run remediation script packages with Intune. In the Intune admin center, what must you enable first to allow running remediation scripts on Windows devices?
- You plan to use a Hyper-V virtual machine (VM1) as the source for a custom Cloud PC image for Windows 365. VM1 is Gen 2 with a 64 GB fixed-size VHDX disk. What is the first change you should make on VM1 so it can be used as the custom image source?
- You use app protection policies to safeguard corporate data on Android devices. To ensure that Android users can access corporate data only when they use apps that support mobile application management (MAM), which configuration should you apply?
- You use Microsoft Intune and need to be able to deploy apps to Android Enterprise devices. What is the first action you should take?
- You use Microsoft Intune to deploy two Win32 apps, App1 and App2, to all Windows devices. App1 must install before App2. What setting should you configure so App1 is installed first on every device?
- You use Microsoft Intune together with the Intune Data Warehouse. You need to produce a device inventory report that includes data from the Data Warehouse. which tool should you use to build the report?
- You use the Microsoft Deployment Toolkit (MDT) and created a Standard Client Task Sequence to deploy Windows 11 Enterprise to new machines that each have a single disk. You need to update the task sequence so it creates separate system and data volumes. Which task sequence phase should you edit?
- You want to run the Sync bulk device action on all corporate-owned Windows devices via Intune. What is the maximum number of devices you can include in that action?
- You will deploy Windows 11 Pro to 200 new PCs using MDT and WDS. You have volume licensing and must set the product key during installation. What should you configure to ensure the correct product key is applied during deployment?
- Your Active Directory domain contoso.com contains a computer named Computer1 that runs Windows 10 and several groups as shown in the table. Which of the listed groups can be added to Group4?
- Your AD DS domain has 100 Windows 10 client PCs and no deployment infrastructure. The company bought Windows 11 licenses via volume licensing. To upgrade the PCs while keeping licensing costs minimal, what do you recommend?
- Your Azure AD tenant contains several devices (table not shown). Which devices can be activated using subscription activation?
- Your Azure AD tenant contoso.com should prevent users from being automatically added to the local Administrators group when they join their Windows 11 device. Which setting should you configure?
- Your environment has an Active Directory domain contoso.com with 25 Windows 11 PCs. An Azure AD tenant is synchronized with contoso.com and hybrid Azure AD join is enabled, but some machines show a registration state of Pending. What must you confirm to allow the devices to finish joining?
- Your environment includes an Active Directory domain with a computer named Computer1 running Windows 11. You must enable Windows Remote Management (WinRM) on Computer1 and apply these settings: set the WinRM service startup type to Automatic; create a listener that accepts requests from any IP address; and allow WS-Management traffic through the firewall. Which PowerShell cmdlet performs these actions?
- Your environment includes an on-premises Active Directory domain and an Azure AD tenant. You want to migrate the settings from the existing Default Domain Policy GPO into a device configuration profile in Intune. Which device configuration profile template type should you use?
- Your environment uses an RD Gateway and Server1 is accessible via Remote Desktop Services through that gateway. To configure a Remote Desktop connection to route through the RD Gateway, which Remote Desktop setting must you configure?
- Your Intune tenant (contoso.com) accepts sign-ins using us.contoso.com, eu.contoso.com, or contoso.com. To avoid asking users for the MDM enrollment URL during enrollment and minimize changes, which DNS records should you create?
- Your Microsoft 365 E5 subscription contains devices (details shown in a separate table). All devices are enrolled in Microsoft Intune and have Microsoft 365 Apps for enterprise installed. Which of the following device groups can use the Cloud Policy service for Microsoft 365 to manage Microsoft 365 Apps for enterprise?
- Your Microsoft 365 E5 subscription includes the devices shown in the table; all have Microsoft Edge installed. You create an Edge baseline profile named Edge1 in the Intune admin center. To which devices should you deploy Edge1 so it applies to every supported device?
- Your Microsoft 365 subscription contains 500 Windows 11 computers that are Azure AD joined and enrolled in Intune. You need to prevent users from disabling Microsoft Defender Antivirus. What should you do?
- Your Microsoft 365 subscription contains devices enrolled in Microsoft Intune (details shown in a table). On which of those devices is Device query available to run?
- Your Microsoft 365 subscription includes 100 devices enrolled in Intune. You need to inspect startup processes and how often each device reboots. Which Intune feature should you use?
- Your Microsoft 365 subscription includes a user (User1) assigned a Windows 10/11 Enterprise E3 license and managed with Microsoft Intune Suite. User1 has activated these devices: Device1 — Windows 11 Enterprise; Device2 — Windows 10 Enterprise; Device3 — Windows 11 Enterprise. How many additional devices can User1 activate?
- Your Microsoft 365 subscription includes Intune. You created an Android app protection policy (Policy1) that blocks screenshots in Microsoft apps, but an unmanaged Android email client can still take screenshots. To force users to use only Microsoft apps for email, which action should you take?
- Your Microsoft 365 subscription includes the Intune Suite and you use Intune and Windows Autopilot to deploy Windows 11. A support engineer cannot collect deployment logs from a device when an Autopilot deployment fails. What should you configure so deployment logs can be collected on failure?
- Your Microsoft 365 subscription uses Intune and you add apps as shown in the table. You must create an app configuration policy named Policy1 for the Android Enterprise platform. Which app(s) can Policy1 manage?
- Your Microsoft 365 tenant includes the Microsoft Intune Suite and you manage Windows 11 devices with Intune. You must implement passwordless sign-in that enforces number-matching. Which authentication method should you choose?
- Your Microsoft Entra tenant contains a device named Device1 that is Microsoft Entra joined. To validate the Microsoft Entra ID primary refresh token (PRT) for Device1, which command should you run on the device?
- Your Microsoft Entra tenant contains the devices listed in the table. On which devices can you deploy Endpoint Privilege Management (EPM)?
- Your Microsoft Entra tenant contoso.com contains a group named Contoso Help Desk. You need Contoso Help Desk to be added to the local Administrators group whenever a Windows device is joined to contoso.com. What should you do?
- Your Microsoft Entra tenant contoso.com contains a Windows 11 device (Device1) and a user (User1). User1 registers Device1 in contoso.com. Which capability does Device1 gain after registration?
- Your network has an Active Directory domain with 2,000 Windows 10 computers and you implement hybrid Azure AD join and Microsoft Intune. To automatically register all existing computers with Azure AD and enroll them in Intune while minimizing administrative effort, which method should you use?
- Your network includes an on-premises AD DS domain synced to the contoso.com Microsoft Entra tenant. You must deploy 100 Windows 11 devices to contoso.com while ensuring users can access on-premises file shares without credential prompts and minimizing dependence on on-premises identity infrastructure. Which join type should you choose?
- Your network uses an on-premises Active Directory domain. Computer1 and Computer2 run Windows 10, and Windows Admin Center is installed on Computer1. To allow Windows Admin Center on Computer1 to manage Computer2, what action must you perform on Computer2?
- Your on-premises environment has an AD DS domain contoso.com with a domain controller dc1.contoso.com. In Azure you have several virtual networks (details in the scenario). You plan to deploy Windows 365 Enterprise Cloud PCs using Microsoft Entra hybrid join. Which virtual network can be used for the Azure network connection (ANC)?
- Your on-premises network has an AD DS domain synchronized to a Microsoft Entra tenant. You want users to sign in to Microsoft 365 from their personal Windows devices using single sign-on while minimizing organizational control over those devices. Which device join type should you use?
- Your organization has 200 Windows 10 PCs managed with Intune. Windows updates are currently downloaded without using Delivery Optimization. Which type of object should you create in Intune to enable Delivery Optimization?
- Your organization uses Azure AD, Microsoft 365, Intune, and Azure Information Protection. The security requirements state: personal devices do not need Intune enrollment; users must enter a PIN before accessing corporate email; personal iOS and Android devices may access corporate cloud services; and users must be prevented from copying corporate email content to cloud storage services other than OneDrive for Business. Which configuration should you create to enforce these rules?
microsoft retail All exam questions
- A brand advertiser has strong ROAS on a retail media campaign but wants to get more value still. If the campaign is not capped by budget, what are the best optimization strategies to apply?
- A product appears in both a high priority (campaign A) with a bid of $1, and low priority (campaign B) with a bid of $10. Which will be used for a relevant query?
- Amelia wants to run a report that shows performance data such as clicks, impressions, and conversions for each product in the feed. Which report should Amelia run?
- and Enables an advertiser to use one feed file for Google and Microsoft Advertising, are correct because they outline the key enabling an advertiser to use one feed file for Google and Microsoft Advertising simplifies campaign management by allowing the What is the Microsoft Advertising product ad maximum file size for the product image?
- Both Product_Type and Product_Category attributes recognize which sign as their delimiter
- Brian has a new product and wants to set up a Smart Shopping campaign. What is the correct sequence of steps Brian needs to follow in order to do this?
- Contoso Bikes have forgotten to update, or re-upload, their product feed file. After how long will their feed file expire if it's not updated or re-uploaded?
- Contoso Cameras are collecting images and image links for their product feed file. What are some product image best practices they should adhere to?
- Contoso Cameras Inc. is adding a merchant promotion to its ad for 10% off. What clickable text will be added to Contoso Cameras' ad to highlight the promotion?
- Contoso Cameras is setting up a new Smart Shopping campaign. What is the recommended amount of time they should keep their Return On Advertising Spend (ROAS) target as-is during the algorithm's learning period?
- Contoso Cameras wants to group their products into the following sets: high margin products, special offers, and seasonal offers. Which feed field can they use to do this?
- Contoso Cameras wants to run ads that have rich product information, including a product image and store name. What types of ads should they create?
- Contoso Cameras wants to submit local product information for their local inventory ads. How do they do this?
- Contoso Cameras’ campaigns have been running for six weeks. Where can they find reporting and analysis for their shopping campaigns?
- Contoso Candies wants to change its store name in the Microsoft Merchant Center. Who can amend the store name?
- Contoso Clothing has frequent updates to the sale price and product availability attributes for specific products in their campaign. They also do not have an API set up. Which of the following is Contoso Clothing's best option?
- Contoso Films wants to filter their products. Which of the following attributes cannot be used to filter their products in a shopping campaign?
- Contoso Foods are creating a shopping feed and completing the product category field. Microsoft Advertising supports the use of both string such as Electronics > Communications > Telephony > Mobile Phones and Product Category IDs such as ‘267.
- Contoso Hair Supplies wants to run a report that shows performance data such as clicks, impressions, and conversions for each product group in their feed. Which report should they run?
- Contoso Jewelry store wants to review the import status of their most recent Google Merchant Center import. Where will they find this in the Microsoft Advertising User Interface?
- Contoso Jewelry Store wants to start using product ads and Microsoft Shopping Campaigns from scratch. What is the correct sequence of step: they need to follow in order to do this?
- Contoso Kitchen Supplies are running product ads. When a searcher clicks on their ad, which of the following happens?
- Contoso Kitchens is a company running Sponsored Brands on a home appliance store site. What role does the store site play?
- Contoso Kitchens wants to implement product ratings but do not have a feed file for this. They've heard that ratings from one supplier do not require an additional feed. Which supplier is this?
- Contoso Lighting wants to set up Local Inventory Ads (LIAs) for their Microsoft Shopping Campaigns. In what order should the following steps be taken to set up them up?
- Contoso Pet Supplies has noticed a recent dip in impressions in their shopping campaign and want to explore. Where can they do this?
- Contoso Pet Supplies wants to run a report that shows negative keywords and the products they are preventing from showing.Which report should they run?
- Contoso Shoes want to explore which websites their product ads have appeared on. Which report should they run?
- Contoso Toys has decided to create a "catch-all" campaign with an all-products product group in it. As a best practice, how should they bid in this scenario?
- Contoso Widgets is a new advertiser creating a new store in Microsoft Merchant Center and their store is rejected. What are possible reasons for this?
- Elodie is running shopping campaigns for her new website. Which bid strategies are available to her?
- How can using the Google Merchant Center import tool benefit an advertiser?
- In a shopping campaign, bidding should be higher when reaching a more granular level.
- increase click through and sell-through of products and Brand advertisers only pay when a shopper clicks on a PLA, are correct How is it generally recommended you bid on product SKU product groups?
- Julian has been hired as a consultant by Contoso Kitchens to help run PromotelQ ads. Julian recommends running a banner ad for their newest product on a home appliance store site. What type of advertising is this?
- Microsoft Shopping Campaigns pull which of the following from the advertiser's feed?
- Microsoft Shopping Campaigns serve on mobile devices.
- Nicole has verified her domain with universal event tagging for other Microsoft Advertising products, but will still need to verify her domain again for Microsoft Shopping.
- of products.
- optimization at the query level, and Serves product ads on search and responsive ads on native, are correct because they highlight Combining a streamlined and simple campaign structure with automated optimization at the query level is also a key benefit, as Hugo is setting up a new shopping campaign for a new product line. Which bid strategy can Hugo use if using a third party bid management tool?
- optimization at the query level, and Serves product ads on search and responsive ads on native, are correct because they highlight Combining a streamlined and simple campaign structure with automated optimization at the query level is also a key benefit, as Which of the following statements are true about Smart Shopping?
- Price drop extensions work on both search and product ads.
- properties.
- reach shoppers using third-party properties and Brands can target shoppers at the awareness and consideration stages of the Smart Shopping Campaigns take precedence over standard shopping campaigns.
- Shopping', 4. Choose your store market, 5. Select 'Campaign settings', and 6. Create Responsive Ad, are correct because they Contoso Cameras is seeing that their products are being rejected and want to learn why. Where can they go to find this information?
- similar to the description of the product on the page, and Include all relevant keywords in the description, are correct because platform policies. Ensuring the ad product description is similar to the description on the product page is important for consistency Which of the following are benefits of utilizing local inventory ads?
- Ted wants to create a store in the Microsoft Advertising User Interface (UI). Where does Ted need to go in the UI to do this?
- What are benefits of using the onsite Product Listing Ads (PLAs) solution in a retail media program?
- What are the benefits to opting-in to the automatic item update in your Microsoft Shopping Campaigns' feeds?
- What are the benefits to opting-in to the automatic item updates in your Microsoft Shopping Campaigns' feeds?
- What does the non-targeted report in ‘store issues’ tell you?
- When a new shopping campaign is created, an ad group with a product group is created by default. What type of product group is this?
- When Contoso Clothing is submitting partial feed updates, which of the following attributes can be updated without editing their full feed?
- When looking at product issues in the store summary, what is the symbol for an error?
- Where do you go in the Microsoft Advertising User Interface to carry out a merchant center import?
- Which of the following are acceptable feed file types?
- Which of the following are examples of product ad enhancements?
- Which of the following is a way to verify your domain when setting up Microsoft Advertising shopping?
- Which of the following Share of Voice attributes can you include in the product dimension report?
- Which of the following statements about the redirect URL attributes in a product feed file is true?
- You can use the search term report for shopping campaigns.
- Your shopping feed file expires after 30 days unless refreshed or updated.
- Zoe is setting up Microsoft Advertising Shopping. Select three ways in which Zoe can verify her domain.
microsoft retail media All exam questions
- advertisers to easily gather campaign insights and make in-flight optimization s, which allows brands to monitor their campaign spend and maximizing ROI. Secondly, Retail Media Offsite empowers brands to reach retailers' first-party shoppers wherever they Contoso Running Shoes sells their products through retailers and has a primary focus of increasing brand awareness of new products onsite. Contoso Running Shoes should run a Banner Display Ad. True or false?
- Auction Banners are a CPM, impression-based on-site solution for brands who want to increase brand awareness. True or false?
- Contoso Kitchen Appliances sells their products through retailers and wants to better promote their products to in-market shoppers. Why should their advertisers consider using Microsoft Retail Media? Select all that apply.
- Digital signage and audio promoted in the retailer stores by brand advertisers are not considered part of the omni channel Retail Media ecosystem. True or false?
- For a brand selling lots of products with a budget, what is the ideal number of products per category to start with in a PLA campaign?
- for how many times shoppers click into your ads after being shown to it (= Clicks / Impressions). CTR, or Click-Through Rate, is a What does "Report Interval" refer to in the campaign reporting?
- How is Retail Media best defined? Select all that apply.
- How is using retail media beneficial to brand advertisers? Select all that apply.
- In addition to ROAS, what additional metrics should you consider when analyzing campaign performance? Select all that apply.
- Media offer several key benefits. Firstly, they are cost effective as you only pay when shoppers view it instead of paying a flat fee, Auction Banners may appear within product carousels on highly visible pages across a retailer's site. True or false?
- Microsoft Retail Media offers both Impressions and Views (also known as Viewable Impressions). What does Impressions mean in the Microsoft Retail Media platform (powered by PromotelQ)?
- Microsoft Retail Media platform's (powered by PromotelQ) PLAs use category as their primary targeting to serve ads to onsite shoppers. True or false?
- of products.
- Onsite retail media programs allow brands to interact with shoppers through a retailer's digital properties. True or false?
- PLAs and Auction Banner Ads are served based on auctions, competing with other advertisers' corresponding ads. True or false?
- Retail Media is considered a closed loop ecosystem because it provides clear and proven attribution and reporting that draw a direct line from advertising back to product sales and Return-On-Ad-Spend (ROAS). True or false?
- Retail Media is considered the third and biggest wave of digital advertising after search and social media. True or False?
- Retail Media is only considered a lower-funnel media strategy that only helps with conversions (i.e., product sales) rather than awareness, consideration, retention, or loyalty in a shopper journey. True or false?
- The preset report "Sales Report" provides impressions and clicks by SKU.True or false?
- their campaigns are automatically extended to Microsoft properties only when the ad can't be served onsite, which ensures that privacy, offering a compliant alternative. Finally, they show targeted ads where shoppers browse off of a retailer's website to drive What are the benefits of Auction Banners (also know as display banners) with Microsoft Retail Media? Select all that apply.
- Using retail media, both retailers and brand advertisers can increase product sales by enabling brand advertisers to promote their products. True or false?
- What are the key benefits of Retail Media offsite advertising? Select all that apply.
- What are the key benefits of retail media onsite advertising compared to offsite advertising? Select all that apply.
- What are the main metrics to monitor when optimizing retail media campaigns? Select all that apply.
- What does "Campaign Budget Interval" mean in the Microsoft Retail Media platform(powered by PromotelQ)?
- What does "Campaign Flight Date" refer to in the Microsoft PromotelQ platform?
- What does "Campaign Type" refer to in the campaign reporting?
- What does "CTR” mean in the Microsoft Retail Media platform (powered by PromotelQ)?
- What does "Report Period" refer to in the campaign reporting?
- What does "Vendors" refer to in the campaign reporting?
- What does “CPC” mean in the Microsoft Retail Media platform (powered by PromotelQ)?
- What does “CPM” mean in the Microsoft Retail Media platform (powered by PromotelQ)?
- What does “PLA” mean in the Microsoft Retail Media platform (powered by PromotelQ)?
- What does “Total Sales” mean in the Microsoft Retail Media platform (powered by PromotelQ)?
- What is considered a good benchmark ROAS for the Microsoft Retail Media onsite campaigns?
- What is the recommended minimum campaign flight time to ensure that your onsite retail media ads can deliver results?
- What is true about Product Listing Ad extensions? Select all that apply.
- What type of auction can the Microsoft Retail Media platform ( powered by PromotelQ) platform offer?
- When creating a PLA campaign, after selecting your desired SKUs, the category targets must be manually applied to the campaign. True or false?
- Which are the primary pacing methods available in the Microsoft Retail Media platform (powered by PromotelQ)? Select all that apply.
- Which campaign optimization strategies should you take when your PLA campaigns have high spend-through but a low ROAS? Select all that apply.
- Which campaigns can you set up in the Microsoft Retail Media platform (powered by PromotelQ)? Select all that apply.
- Which key different i at or would make retail media more attractive to brand advertisers to invest?
- Which of the following factors influence the likelihood for PLA campaigns to win auctions? Select all that apply.
- Which of the preset reports in the Microsoft Retail Media platform (powered by PromotelQ) can you use to get ROAS within a certain time frame? Select all that apply.
- Which retail media ad formats can brands use to reach their shoppers? Select all that apply.
- Which shopper engagement will trigger charge for Auction Banner Ads campaigns in most cases?
- Which shopper engagements will trigger charges for PLA campaigns in most cases?
Microsoft Retail Media Certification All exam questions
- Auction Banners may appear within product carousels on highly visible pages across a retailer's site. True or false?
- Contoso Running Shoes sells their products through retailers and has a primary focus of increasing brand awareness of new products onsite. Contoso Running Shoes should run a Banner Display Ad. True or false?
- Digital signage and audio promoted in the retailer stores by brand advertisers are not considered part of the omnichannel Retail Media ecosystem. True or false?
- Microsoft Retail Media platform’s (powered by PromoteIQ) PLAs use category as their primary targeting to serve ads to onsite shoppers. True or false?
- What are benefits of using the onsite PLA solution in a retail media program? Select all that apply.
- What are the benefits of Auction Banners (also know as display banners) with Microsoft Retail Media? Select all that apply.
- What does "Report Interval” refer to in the campaign reporting?
- What does “Campaign Budget Interval” mean in the Microsoft Retail Media platform(powered by PromoteIQ)?
- What does “PLA” mean in the Microsoft Retail Media platform (powered by PromoteIQ)?
- What does “Total Sales” mean in the Microsoft Retail Media platform (powered by PromoteIQ)?
- What type of auction can the Microsoft Retail Media platform ( powered by PromoteIQ) platform offer?
- Which are the primary pacing methods available in the Microsoft Retail Media platform (powered by PromoteIQ)? Select all that apply.
- Which campaigns can you set up in the Microsoft Retail Media platform (powered by PromoteIQ)? Select all that apply.
- Which key differentiator would make retail media more attractive to brand advertisers to invest?
- Which of the preset reports in the Microsoft Retail Media platform (powered by PromoteIQ) can you use to get ROAS within a certain time frame? Select all that apply.
microsoft search advertising All exam questions
- A bid is the maximum amount an advertiser is willing to pay for a click.
- A click on an ad extension incurs an additional charge to a normal click.
- Ad group settings must inherit settings from the campaign level.
- additional opportunities to re-engage with customers who have abandoned their shopping cart. Re marketing can specifically target Gail's Gifts is choosing an automated bidding strategy. They want to have confidence that their bids are driving as much traffic to their website as possible while staying within their budget. Which bid strategy should they choose?
- An ad extension, if present, will always serve.
- An ad title can contain three parts, each up to 30 characters long.
- An event goal conversion can be best defined as which of the following?
- Anna notices one device type performing poorly. What is the maximum negative bid adjustment Anna can use for a device?
- Arlo has applied targeting at both the campaign level and ad group level to his campaign. Which level will take priority?
- Ashley's Autos has placed a Universal Event Tracking (UET) tag on each of the pages on its website. Which of the following features needs this tag to function?
- At what level is auto-tagging with Microsoft Click ID enabled when creating a new Universal Event Tracking (UET) conversion goal?
- Broad match keywords have the most potential for high impressions.
- Campaigns are the lowest level in the account structure hierarchy.
- Cathleen wants to check that her Universal Event Tracking (UET) tag is functioning correctly on the website, 'Cathleen's Musical Instruments'. Which of the following options would enable Cathleen to do this?
- Cathleen wants to check that three Universal Event Tracking (UET) tag is functioning correctly on the website, 'Cathleen's Musical Instruments'. Which of the following options would enable Cathleen to do this?
- Celine is a camera retailer who wants to create engaging ads with images of what products are sold from the catalog. What ad type should Celine use?
- Cesar's online Jewelry Store is choosing an automated bidding strategy. Without constantly managing their bids, they want to specify the percentage of times their ad is displayed compared to their competitors in a given position on the search engine results page. Which bid strategy should they choose?
- Complete the following sentence by selecting two correct answers: With Microsoft Advertising, you can use Dynamic Re marketing…
- Complete the following sentence by selecting two correct answers: With Microsoft Advertising, you can use Dynamic Remarketing…
- Contoso Bikes wants to ensure that if one campaign is attracting a lot of traffic on a given day, it CAN take budget from other campaigns. Which budget type should they select?
- Contoso Clothing is new to Microsoft Advertising and wants to track how many people buy a shirt online after clicking on their ad. What feature must they implement?
- Contoso Coffee chain of coffee shops is eager to ensure they bid on the brand keyword 'Contoso Coffee. Why?
- Contoso Desserts is new to Microsoft Advertising and wants to implement conversion tracking. What is the first step?
- Contoso Foods wants to track each time a searcher who has clicked on their ad watches a video on their site as a conversion. Which Microsoft Advertising feature do they need to implement?
- Contoso Hotels wants to ensure that excessive spend on one campaign does not take budget from other campaigns. Which budget type should they select?
- Contoso Pet Supplies wants their ad for the keyword 'Cat Snaxxx' triggered when a user searches either of the individual words in any order, or words related to Cat or Snaxxx. Which match option should they choose?
- Contoso Shoes' campaign reached its budget limit for the day, so it has been automatically paused. What could Contoso Shoes do to make its ads go live again?
- Contoso Ski House wants its keyword 'winter vacations' to match to queries such as 'winter vacations discount' but not 'Hawaii vacations'. Which keyword match option should it select?
- Contoso Vacations sells experiences in Mexico. Which of the following targeting opportunities are available to them with Microsoft Advertising?
- Dynamic Search Ads automatically target relevant search queries based on the content of your keyword list, and are dynamically created to respond to these keywords.
- Dynamic Search Ads automatically target relevant search queries based on the content of your website, and are dynamically created to respond to these search queries.
- Each sponsored search ad that a user sees is called a(n):
- Emily is creating a campaign for a large insurance company's auto insurance and is choosing an automated bid strategy. The aim is to use Microsoft Advertising’s data-driven bidding to get as many online purchases as possible. Which bid strategy should Emily choose?
- Exact match can also match to search queries that are minor variations of the keyword, or ‘close variants’.
- For enhanced cost per click, which of the following is true about Universal Event Tracking (UET) with a conversion goal?
- Franz sells a wide variety of apparel. Franz's goal is to dynamically insert data into text ads from a feed depending on certain circumstances. What ad type should Franz use?
- Gaby is marketing luxury vacations and notices ads are being triggered by queries for 'cheap vacations'. What should Gaby do to prevent this?
- Gregory wants to set up billing information in a new account. Gregory can use Google Import to copy this over from his Google Ads account.
- Hitesh wants to see the number of impressions for each headline and description combination for his Responsive Search Ad (RSA). What type of report should Hitesh run?
- How do you calculate average cost-per click?
- How is a click-through rate defined?
- How is a conversion rate defined?
- How many sales an advertiser is getting per number of clicks is known as:
- How many types of Dynamic Re marketing lists are available to an advertiser?
- How many types of Dynamic Remarketing lists are available to an advertiser?
- How many Universal Event Tracking (UET) tags are needed per advertiser website?
- In general, the higher up on the SERP your ad is the less likely it will be to clicked.
- Jack wants to provide a variety of headlines and descriptions so Microsoft Artificial Intelligence can automatically select the best combination. What ad type should Jack create?
- Jane knows that her campaigns will be more efficient if she improves her quality score. How can Jane do this?
- Kari's Clothes online store has a re marketing list of site visitors applied to a campaign. For this campaign, they only want their ads to appear to customers on the re marketing list. Which targeting option should they choose?
- Kari’s Clothes online store has a remarketing list of site visitors applied to a campaign. For this campaign, they only want their ads to appear to customers on the remarketing list. Which targeting option should they choose?
- Kat's Clothes online store has a re marketing list of site visitors applied to a campaign. They want their ads to appear to all potential customers, but apply a positive bid adjustment for customers on the re marketing list. Which targeting option should they choose?
- Kat’s Clothes online store has a remarketing list of site visitors applied to a campaign. They want their ads to appear to all potential customers, but apply a positive bid adjustment for customers on the remarketing list. Which targeting option should they choose?
- Lilly currently has a standard Universal Event Tracking (UET) tag implemented, but wants to start using dynamic re marketing on the campaigns. What 2 additional parameters required in UET will Lilly need to add?
- Lilly currently has a standard Universal Event Tracking (UET) tag implemented, but wants to start using dynamic remarketing on the campaigns. What 2 additional parameters required in UET will Lilly need to add?
- Louis running a search campaign for a major retailer and wants to remarket to previous site visitors. When doing this, Louis can target site visitors or cart abandoners, but not people who have actually made a purchase.
- Maria has noticed that her ads are not appearing as high on the search engine results page as they used to. Which of the following could Maria do to improve her ads' position?
- Maria-Jose wants to run a report to see impressions, impression percentage, and impression percentage lost to budget and lost to bid. Which report should Maria-Jose run?
- Microsoft Advertising allows you to import a keyword list from Google.
- Microsoft Advertising Editor allows you to work and make changes online only.
- Microsoft Advertising saves your Google Ads sign-in information for easier access with other Google Imports.
- Nick's Shirts and Ties wants to track a conversion each time someone makes a purchase on their website using a destination URL conversion goal. Which page should they specify as the destination URL to track this type of conversion?
- Norman's Hardware wants to remarket to people who have visited Normans hardware.com. They have already implemented the Universal Event Tracking (UET) tag on the site and created a re marketing list. At what point will Microsoft Advertising add a site visitor to their re marketing list?
- Norman’s Hardware wants to remarket to people who have visited Normanshardware.com. They have already implemented the Universal Event Tracking (UET) tag on the site and created a remarketing list. At what point will Microsoft Advertising add a site visitor to their remarketing list?
- Paid search follows a Pay Per Click, or PPC, advertising model. Using this system, an advertiser only pays when a consumer clicks on their delivered ad.
- Phuong wants to see details of which queries have been triggering the ads in a campaign that has been running for a few weeks. Which report should Phuong run?
- Ravleen wants to run a report to see financial documents, including invoices and credit memos. Which report should Ravleen run?
- Report templates can be saved and scheduled to run automatically.
- Reporting is offered on the syndicated search partner domains where your ads have served.
- Responsive Search Ads can be imported from your Google Ads campaign.
- Sarbjit wants to research keywords, compare impression share, and customize bids. Which Microsoft Advertising tool should Sarbjit use?
- Saskia is running a search campaign for a major retailer and is writing ad copy. With re marketing, Saskia has the ability to show previous website visitors different ad copy to other people.
- Saskia is running a search campaign for a major retailer and is writing ad copy. With remarketing, Saskia has the ability to show previous website visitors different ad copy to other people.
- Shani's Shoes is an online store where customers can buy running shoes. À number of customers are adding shoes to their cart, but then leave the site. Which of the following is a characteristic of Dynamic Marketing which Shani's Shoes can take avantage of?
- stage is to access the publisher report to identify and exclude domains with poor performance on the desired KPI, where When is a customer removed from the Dynamic Re marketing list?
- Susana has recently implemented Responsive Search Ads (RSAs) on search campaigns. To best understand the full impact of her RSAs, how soon after implementation should Susana measure their performance?
- Tailspin Fences and Gates Inc. does not want its ad to display when a customer searches for ‘Bill Gates’. To avoid displaying an ad when a customer searches for ‘Bill Gates’, which Microsoft Advertising option should they select?
- The 'Target and Bid' audience target setting does not narrow your ad's audience.
- The Microsoft Search Partner Network is comprised of partner-managed properties powered by Bing. They have their own brands, but search results and ads are served by Bing.
- The words or phrases a user types into a search box are often referred to as:
- There are two ad distribution settings in the Microsoft Advertising network. Which setting does Microsoft Advertising recommend?
- To pay with monthly invoicing, you will need to have a live insertion order set up.
- user lands on the advertiser's site after clicking on their ad and when a user lands on the advertiser's site who has not clicked Contoso Holidays wants their ad to display for the keyword ‘Flights to New York only when a customer search query matches their keyword precisely- induding some close variants- with no extra words. Which keyword match option should they select?
- What an advertiser defines as a sale – could be a sign up or a purchase is known as:
- What are impressions?
- What are some benefits of using re marketing in your paid search campaign?
- What are some benefits of using remarketing in your paid search campaign?
- What are some reasons why you would use page feeds for dynamic search ads?
- What are the benefits of using in-market audiences?
- What are the ways in which you can import your Google Ads search campaign data?
- What are the ways in which you can target your ads?
- What are the words or phrases a user types into a search box referred to as?
- What can a Sitelink ad extension provide?
- What do past buyers lists do in a dynamic re marketing campaign?
- What do past buyers lists do in a dynamic remarketing campaign?
- What does a Callout ad extension provide?
- What does SERP stand for?
- What is the maximum number of ad descriptions an advertiser can provide for their Responsive Search Ads?
- What is the maximum number of headlines an advertiser can provide for their Responsive Search Ads?
- What level or levels can ad targets be set?
- What should you know before importing a file in Microsoft Advertising Editor?
- When using Google Import, which of the following may be modified automatically as part of the import process?
- When will changes made in Microsoft Advertising Editor be reflected in your Microsoft Advertising account?
- Which column is required as mandatory when uploading your Dynamic Search Ads page feed?
- Which domains are included in the "Microsoft sites and select partner traffic” ad distribution setting?
- Which of the following are Microsoft Advertising budgeting options?
- Which of the following are the three stages of Microsoft Advertising search partner optimization?
- Which of the following is not considered in calculating quality score?
- Which of the following is true about Universal Event Tracking (UET)?
- Which of the following payment methods are allowed if using a post-pay threshold?
- Which of the following will not import using the Google Import tool?
- Why is it important to group relevant keywords together in an ad group?
- Willow Sporting Goods are concerned that a lot of their ads are being blocked from showing. They believe this is due to keywords that have been set up to prevent ads from being triggered by a certain word or phrase. Which report should they run?
- With conversion tracking, the only thing possible to track is when a customer actually purchases a product.
- Yandi's online Bike Store is choosing an automated bidding strategy. They want to get as much conversion value and revenue as possible for given return on ad spend objective. Which bid strategy should they choose?
- Yani is creating a search campaign and is choosing an automated bid strategy. The aim is to ensure an average spend to get a customer to take action on their website over 30 days is less than $10. Which bid strategy should Yani choose?
- You can use the Google Import feature to import an in-market udience to your campaign.
Microsoft Windows Server Hybrid Admin Associate AZ-801 Certification All exam questions
- A department requires EFS to protect data in a shared folder on a Windows Server 2022 file server. Users already have EFS certificates via autoenrollment. You must ensure recoverability by administrators and encrypt existing files in the folder and all subfolders. What should you do? Choose two actions.
- A domain controller DC1 (Windows Server 2019) experienced disk corruption. You have a recent Windows Server Backup System State backup for DC1. An OU named ‘Projects’ was deleted 40 days ago (Recycle Bin retention is 30 days). SYSVOL on DC1 is now empty, but other DCs have healthy SYSVOL. You must: 1) restore the ‘Projects’ OU and 2) recover SYSVOL on DC1 without impacting healthy DCs. What should you do on DC1? (Choose two)
- A Group Policy Object linked to OU1 defines Windows Defender SmartScreen behavior (details in the policy). Given the listed applications, which application(s) are permitted to be installed on Server1?
- A hosting provider runs Windows Server 2022 Hyper-V hosts in a fabric domain. Some hosts lack TPM 2.0. A tenant requires shielded VMs so that fabric administrators cannot inspect the VMs’ disks or memory. You need to allow deployment of shielded VMs to all hosts, including those without TPM, while ensuring the tenant retains control of the keys protecting the VMs. What should you do? (Choose two)
- A legacy environment uses Network Access Protection (NAP) with DHCP enforcement. Clients must have Windows Firewall enabled and antivirus installed and up to date. Noncompliant clients should be placed on a restricted network where they can reach WSUS and antivirus update servers for remediation. Which two actions should you take on the NPS?
- A multi-tier on-premises application must recover in Azure with an RPO of 5 minutes and an RTO under 30 minutes. The app consists of several VMs that require consistent recovery. Which approach best meets the objectives while optimizing cost and complexity?
- A ransomware incident targeted a Windows Server 2019 file server. You must enable Controlled folder access in block mode, add D:\Shares\Payroll and E:\FinanceData as protected folders, and allow C:\Program Files\LegacyBackup\agent.exe to write to those folders. Which set of PowerShell commands should you run?
- A server is configured to encrypt all incoming traffic using a connection security rule. You need to allow that server (Server1) to reply to unencrypted tracert commands from hosts on the same network. What should you configure in Windows Defender Firewall with Advanced Security?
- A server running Windows Server hosts an application App1. You must block App1 from reaching external SMTP servers while minimizing impact on App1's access to external HTTP, minimizing effects on other applications on the server, and minimizing administrative effort. Which Windows Defender Firewall configuration should you implement?
- A server runs Windows Server 2025 Standard with the Hyper-V role installed. You must upgrade it to Windows Server 2025 Datacenter while minimizing downtime. Which command should you run?
- A server shows 'Password must meet complexity requirements: Disabled' in Local Security Policy. A domain GPO linked to the server’s OU sets this policy to Enabled. You need to confirm which setting is effective on the server and identify the GPO providing it, storing the result for audit. Which two tools/commands should you use?
- A single Hyper-V host with one physical NIC runs VMs for two tenants (TenantA and TenantB). All VMs must access the external network, TenantA VMs must be isolated from TenantB at Layer 2, and you must block one VM in TenantA from reaching the public IP 203.0.113.10. What two configurations should you implement?
- A Site-to-Site VPN between your on-premises network and an Azure virtual network disconnects frequently. To troubleshoot the IPsec tunnel from the Azure side, which Azure VPN Gateway diagnostic log should you check?
- A SQL Server Always On Availability Group has two replicas in the primary datacenter and one replica in a secondary region. The business requires automatic failover with zero data loss within the primary datacenter and accepts potential data loss and manual intervention for the regional DR. How should you configure the replicas?
- A three-node Windows Server Failover Cluster currently runs Windows Server 2022. You plan a rolling upgrade of the nodes to Windows Server 2025. To assess cluster status before the rolling upgrade while minimizing node impact and administrative effort, which two cmdlets should you run?
- A user object (User1) in your AD DS forest has these attributes: whenCreated, distinguishedName, objectGUID, and objectSID. After migrating User1 to the fabrikam.com forest with ADMT, which attributes will change?
- A VM (VM1) shows the error "Boot failure. Reboot and Select proper Boot Device or Insert Boot Media in selected Boot Device." You need to detach the OS disk from VM1 and attach it offline to a temporary VM for troubleshooting. Which Azure CLI command should you run?
- A VM named VM1 has its Ethernet adapter disabled. In the Azure portal, which setting should you use to enable the adapter from the VM1 blade?
- A web application on WEB1 (Windows Server 2022) runs under a gMSA named gmsaWeb and must access CIFS shares on FILE1 (Windows Server 2022) by delegating user credentials. Security requires the resource owner (FILE1) to control which services can act on its behalf and to avoid unconstrained delegation. What should you do? (Choose two)
- A Windows Server 2012 R2 VM on a Windows Server 2012 R2 Hyper-V host shows time drift and application-consistent backups are failing. Internet access is blocked for the VM. You need to update Hyper-V Integration Services in the guest and enable host-to-guest file copy for troubleshooting. What should you do? (Choose two)
- A Windows Server 2019 VM runs an application that the vendor states cannot be captured in a saved state. You need to use checkpoints to create application-consistent restore points and store checkpoint files on a dedicated volume D:\Checkpoints. What should you configure? (Choose two)
- After enabling Microsoft Defender for Servers Plan 2, which resource must you create first to implement File Integrity Monitoring (FIM)?
- After installing an application on an Azure VM named VM1 and restarting it, VM1 shows: "Boot failure. Reboot and Select proper Boot Device or Insert Boot Media in selected Boot Device." You need to mount VM1's OS disk offline on a temporary VM to troubleshoot. Which Azure CLI command should you run?
- All Windows Server 2019 machines are onboarded to Microsoft Defender for Endpoint. A legacy app causes heavy CPU during scans. You must: 1) exclude C:\ProgramData\LegacyApp\Data and the process C:\Program Files\LegacyApp\app.exe from scans, 2) run a daily quick scan and a weekly full scan on a schedule, 3) prevent local admins from disabling Microsoft Defender Antivirus, and 4) enable cloud-delivered protection with aggressive blocking. Which option meets all requirements?
- An AD DS forest has the Active Directory Recycle Bin enabled. A user account named User1 was accidentally deleted. Which tool should you use to recover User1 from the Active Directory Recycle Bin?
- An Azure VM (VM1) running Windows Server fails to fully initialize its network stack, so you cannot connect over the network. You need an interactive shell session to troubleshoot the VM. Which service should you use?
- An Azure VM (VM1) running Windows Server is configured for Azure Site Recovery. From the VM1 blade in the Azure portal, which pane or option should you open to run a test failover?
- An on-premises AD domain syncs to Azure AD using password hash synchronization. Devices are hybrid Azure AD–joined, but users must repeatedly type their password to access Microsoft 365. What should you enable to reduce password prompts?
- An on-premises AD DS domain hosts Server1, which runs an app (App1) that uses Active Directory authentication. You configured Microsoft Entra Connect with password sync, and a Microsoft Entra user named User1 cannot authenticate to App1. What must you do to allow User1 to authenticate to App1?
- An on-premises file server Server1 (Windows Server) contains a share Share1. You must migrate Share1 to an Azure VM. Which tool should you use to perform this migration?
- An on-premises server Server1 (Windows Server) has a shared folder Share1. You deploy a new VM Server2 and must move Share1 to Server2 so users can still reach the share at the UNC path \\server1\share1 after Server1 is retired, while minimizing admin effort. Which tool should you use to perform the migration?
- An on-premises Server1 hosts an ASP.NET app App1 under IIS. You plan to containerize App1 and deploy it to Azure App Service; the container image will be stored in an Azure Container Registry named ACR1. Using Azure Migrate's App Containerization tool, you must grant the tool the minimum necessary privilege to push the image to ACR1. Which credential type should the tool use?
- An on-premises Windows Server 2019 was backing up files and folders to a Recovery Services vault using the MARS agent. The server has failed. You need to restore a folder to a new replacement server using an online recovery from the vault. What should you do on the replacement server?
- An on‑premises server (Server1) runs Windows Server with the Hyper‑V role. You plan to back up Server1 to Azure using Azure Backup. Which two backup options require deploying Microsoft Azure Backup Server (MABS)? (Choose two.)
- As part of the on-premises migration plan for Archive1, what is the minimum number of IP addresses required for the node and cluster roles on Cluster3?
- Cluster1 is a failover cluster that hosts highly available Hyper‑V VMs. You have a member server Server3 and must implement Cluster‑Aware Updating (CAU) on Cluster1 and have Server3 manage CAU while minimizing administrative effort. Which feature or role should you install on Server3?
- Cluster1 is a failover cluster with 6 nodes, dynamic quorum, and a file-share witness using dynamic witness. What is the maximum number of node failures the cluster can tolerate while still maintaining quorum?
- Given a Storage Spaces Direct setup that includes persistent memory and several data volumes, on which volumes can direct access (DAX) be used?
- Helpdesk was delegated ‘Reset password’ on the ‘Users’ OU. They can reset most users’ passwords but cannot reset the password for a user who is a member of Domain Admins, even though that user account resides in the same OU. You need to allow the Helpdesk group to reset passwords for protected accounts while keeping AdminSDHolder protections in place. What should you do?
- Host1 and Host2 are workgroup servers running Hyper‑V; Host1 hosts three VMs. Each server is in a different site connected by a high‑speed WAN. You need to replicate Host1’s VMs to Host2 for disaster recovery. Which three actions should you take?
- Host1 has a VM named VM1 and Host2 is configured as a replica server. You plan to replicate VM1 to Host2 using Hyper‑V Replica and later restore a replica to a specific point in time within the past eight hours. What should you configure to enable that capability?
- How many built-in System Insights capabilities are available by default for performing capacity forecasting?
- In a 4-node Hyper-V failover cluster using Cluster Shared Volumes (CSV), you observe high read latency during maintenance windows when a CSV enters redirected I/O. You want to reduce read impact for VMs during these periods and in general. What should you configure?
- In a Storage Spaces Direct deployment, which tool should you use to view the available storage in a Storage Spaces Direct storage pool?
- In an AD domain you have Server1 and Server2 (both Windows Server). To manage Server2 with the Computer Management console while following least privilege, which two Windows Defender Firewall with Advanced Security rules should be enabled on Server2?
- In an AD DS domain you must set a ticket-granting ticket (TGT) lifetime for specific user and computer accounts. The change should affect as few other accounts as possible and require minimal administrative effort. Which configuration should you apply?
- In an AD DS forest (forest functional level Windows Server 2012 R2) that contains multiple domains, you create a user account named Admin1. You need to grant Admin1 only the privileges required to install a Windows Server 2022 domain controller in the east.contoso.com domain. To which group(s) should you add Admin1?
- In an AD DS forest contoso.com you have a user User1 with attributes including distinguishedName CN=User1,OU=OU1,DC=contoso,DC=com, objectGUID, and objectSID. You plan to move User1 to OU3 using the Active Directory Migration Tool (ADMT). Which attribute(s) will change as a result of the move?
- In an AD DS forest you deployed a read-only domain controller (RODC1). You need to make User1 a local administrator on RODC1 while following the principle of least privilege. Which tool should you use?
- In an AD DS forest you deployed a read-only domain controller (RODC1). You need to make User1 a local administrator on RODC1 using the principle of least privilege. Which tool should you use?
- In Storage Spaces Direct, which management tool should you use to view the available storage in a storage pool?
- In the contoso.com domain (FFL: Windows Server 2016), two fine-grained password policies exist: PSO_User (msDS-PasswordSettingsPrecedence=10) is directly applied to user Alice, and PSO_GG (msDS-PasswordSettingsPrecedence=20) is applied to the global security group GG_Sales. Alice is a member of GG_Sales. Security requires that the group-based PSO_GG becomes the effective password policy for Alice without removing the direct PSO assignment. You also need to verify the resultant PSO for Alice. Which two actions should you perform?
- In your Microsoft Sentinel workspace, analysts report many separate incidents generated from the same host during a 24-hour brute-force campaign. They also want a fast way to visualize related alerts, users, hosts, and IPs tied to an incident. What two actions should you take?
- Installing the Azure Performance Diagnostics extension on VM1 fails. Which two approaches will help identify the cause? (Choose two.)
- On a three-node failover cluster, you need to run pre- and post-scripts when Cluster-Aware Updating (CAU) applies updates while minimizing administrative effort. Which mechanism should you use?
- On a Windows Server you need a rolling text log that records both dropped packets and successful connections for the active firewall profile, written to the default path, with a maximum size of 32 MB. What should you configure?
- On Server1 in an AD DS domain you need to block registration of particular COM objects. Which technology should you use to prevent those COM objects from being registered?
- On Server1 you installed System Insights but some capabilities are missing. Which two capabilities must be installed manually? (Choose two.)
- On Server1, which tool do you use to change the schedule for the storage consumption forecast provided by System Insights?
- On VM1 (Windows Server) you plan to use Azure Disk Encryption to protect the VM's disks. Which prerequisite is required before enabling Azure Disk Encryption?
- On VM1 (Windows Server) you will install a line-of-business application that needs to be able to launch child processes. Which feature should you enable on VM1?
- Server1 (on-premises) has multiple file shares and uses IP address 192.168.10.12. You will migrate the shares to an Azure VM with Storage Migration Service but must ensure on-premises clients can continue to access the shares using the same IP 192.168.10.12. What Azure component should you include in the solution?
- Server1 (Windows Server 2019 with Hyper-V) hosts several virtual machines. You add Server2 (Windows Server 2025 with Hyper-V) and want to distribute the VMs across the two hosts. Which virtual machines can be imported to Server2?
- Server1 is a Remote Desktop Session Host that runs five custom applications and is experiencing sustained CPU usage above 90%. You want to create a Performance Monitor Data Collector Set to identify the resources used by each application. Which performance object should you add?
- Server1 is an on-premises Windows Server with the Web Server (IIS) role hosting an ASP.NET application (App1). You plan to migrate App1 into a container in Azure and must export App1 to a ZIP file. What should you install on Server1?
- Server1 is running Windows Server with the Hyper-V role. You have a Hyper-V failover cluster named Cluster1 and all machines are in the same domain. You want to replicate VMs from Cluster1 to Server1 using Hyper-V Replica with Kerberos authentication on the default port. What change should you make on Server1?
- Server1 runs Windows Server 2016 with IIS and hosts an ASP.NET 3.5 application. Before using the Azure Migrate App Containerization tool to move the app to Azure App Service, which two actions should you perform on Server1 to minimize administrative effort? (Choose two.)
- Server1 runs Windows Server 2022 and is a member of a three‑node failover cluster. You must upgrade Server1 to Windows Server 2025 while minimizing cluster downtime. What should you perform first?
- Several VMs behind NSGs allow broad inbound access from the Internet. You want to minimize exposed ports using Defender for Cloud intelligence and apply the tightened rules directly to the NSGs. What should you do?
- Ten Windows Server machines are in a workgroup and you must encrypt all network traffic between them with the strongest security. Which authentication method should a connection security rule use?
- The domain uses Microsoft Entra Connect sync and Entra Password Protection with a custom banned password list. After deploying a new domain controller (DC2), the custom banned list is enforced inconsistently. To ensure the banned-password list is always enforced on DC2, what should you install on DC2?
- Three Azure virtual machines (VM1, VM2, VM3) run a multi‑tier application and you plan to use Azure Site Recovery. You need to ensure these three VMs fail over together as a single unit. What should you configure?
- To allow Server1 to verify network connectivity to Server2 using ping, what is the first action you should take?
- To create an alert that triggers when an Azure virtual machine is turned off, which type of signal should the alert rule use?
- To inspect available storage in a Storage Spaces Direct storage pool, which of the following should you use?
- To meet the technical requirements for Cluster3, which element should be included in the solution?
- To meet the technical requirements for User1, to which contoso.com group should User1 be added?
- To satisfy the technical requirements for backing up Server4, what should you do first?
- Two domain-joined Windows Server 2022 hosts (App1 and App2) are on the same subnet. You must ensure that only SMB traffic between App1 and App2 is encrypted with IPsec; all other traffic between the hosts should be unaffected. What should you configure? Choose two.
- Two servers, Server1 and Server2, run Windows Server with the Hyper‑V role. Server1 hosts VM1, VM2, and VM3, and those VMs replicate to Server2. After a hardware failure on Server1, you must bring VM1, VM2, and VM3 online as quickly as possible from Server2’s Hyper‑V Manager. Which action should you run for each VM?
- Two Windows Server 2022 Hyper-V hosts, HV-Primary and HV-Replica, are in the same Active Directory domain over a WAN link. You must configure Hyper-V Replica without deploying certificates, and support planned failover from HV-Primary to HV-Replica. What should you do? (Choose two)
- Two Windows Server machines are shown in the table. You must copy all data from volume E on Server1 to Server2, ensuring that files currently in use are also copied and that administrative effort is minimized. Which option should you use?
- User1 connects from home to gateway GW1 by using a Point-to-Site VPN from Computer1 (Windows 11) to access AppSvr1. After adding the listed resources, User1 cannot reach AppSvr2. What action will allow User1 to access AppSvr2?
- Users frequently move between pooled workstations in an AD DS domain and need their user certificates and private keys to follow them automatically. You do not use roaming profiles. How should you enable certificate and credential synchronization across machines?
- VM1 (IIS hosting a critical LOB app) becomes unresponsive after a new security baseline is applied and you suspect the baseline caused networking issues. To capture a network trace for VM1, what should you do?
- VM1 experienced a stop error and will not boot. To examine the memory dump for the failure, what should you do first?
- VM1 fails to start correctly. Which option on the VM1 blade in the Azure portal shows the serial log you can review to diagnose the startup issue?
- VM1 has crash dumps enabled for Process1. When process1.exe on VM1 crashes, a technician must retrieve the memory dump files but must not be given access to the VM. To which resource should you provide the technician access?
- When creating data collection rules to collect Application and System logs from virtual machines, which query language should you use to filter events with custom criteria?
- When evaluating technical requirements for Cluster2, what is the minimum number of Azure Site Recovery Providers you must install?
- When importing server inventory into Azure Migrate using a CSV file, which fields are required for each record?
- When planning the Microsoft Sentinel deployment to meet the security requirements, which type of Sentinel data connector should you choose?
- When you install the Azure Monitor agent on 100 on-premises Windows Server machines, which credentials or identifiers must you provide?
- Which domain controller must be online to meet the technical requirements for DC4?
- Which tool provides a way to view available storage in a Storage Spaces Direct storage pool via a management UI?
- Which tool should be used to perform the data share migration for the on-premises migration plan?
- Which tool should you use to fulfill the technical requirements for Share1?
- While threat hunting in Microsoft Sentinel, you run a KQL query that identifies suspicious PowerShell download activity on five hosts. You want to preserve each finding with its associated entities and then open a single case that groups all of them for the incident response team. What two actions should you take?
- You administer WSUS and want clients to install all security fixes published on Patch Tuesday and any emergency out-of-band security releases. You do not want clients to install optional preview (C/D week) quality updates. What should you approve (or auto-approve) in WSUS?
- You are deploying Storage Spaces Direct on four Windows Server 2022 nodes: two nodes per rack. Each node has NVMe and HDD devices. You must ensure: (1) copies of data span racks for fault domain awareness, (2) the VM workload can tolerate a single-node failure with good write performance, and (3) NVMe devices are used for caching. What should you configure? (Choose two)
- You are designing a 5-node Windows Server Failover Cluster stretched across two sites: Site A (3 nodes) and Site B (2 nodes). You must maintain cluster service in Site B if Site A is lost entirely. Internet connectivity is available at both sites. Which quorum configuration should you implement?
- You are hardening a Windows Server 2022 management node. WinRM (HTTP/HTTPS) must accept connections only from two management subnets (10.10.20.0/24 and 10.10.30.0/24) and only when the traffic is authenticated with IPsec using Kerberos. No WinRM access is allowed on the Public profile. Which two configurations should you create in Windows Defender Firewall with Advanced Security?
- You are migrating from the deprecated Log Analytics agent (MMA) to the Azure Monitor Agent (AMA) on Arc-enabled Linux servers. You must send syslog to WorkspaceA and performance counters to WorkspaceB. How should you configure data routing?
- You are onboarding a new SAML-based SaaS application (AppX) that will use your AD FS farm for authentication. Tokens must include the user’s email address as the Name ID and a custom claim sourced from the employeeType AD attribute. Users must be able to access AppX from outside the corporate network. What should you do? (Choose two)
- You are onboarding Windows Server 2019 and 2012 R2 machines to Microsoft Defender for Endpoint using Microsoft Defender for Cloud. A third‑party antivirus remains the primary AV. You must enable EDR in block mode to remediate post‑breach activity. What should you do? (Choose two)
- You are protecting on-premises Hyper-V VMs with Azure Site Recovery. The business requires up to 24 hours of recovery point retention with application-consistent recovery points every hour. You must run a Test Failover quarterly without impacting production networking. What should you do? (Choose two)
- You are remediating firewall-related security risks to satisfy the security requirements. Which configuration should you apply to reduce these risks?
- You are standardizing vault usage. Requirements: (1) Protect on-premises Windows Servers with MARS agent and System State; (2) Use Site Recovery for on-premises to Azure DR; (3) Enable immutable, at-scale backups for Azure Disks. Which statements describe the correct vault type for each workload? (Choose two)
- You created a computer certificate template for mutual TLS on application servers. Clients are domain-joined Windows 10/11 devices, but they are not autoenrolling. You need to enable automatic enrollment and issuance without manual steps. What should you configure? Choose two actions.
- You created a new Log Analytics workspace (Workspace1) and have a Windows Server VM named Server1. To collect performance metrics from Server1 using Azure Monitor, what should you do next?
- You deployed an RD Gateway at rdgw.contoso.com. Members of the RemoteUsers group must be able to connect only to servers in the RD-Targets security group. Users report certificate warnings when connecting externally using the rdgw.contoso.com name. You already created an RD CAP that allows the RemoteUsers group. What two actions should you take?
- You deployed an RODC named RODC1 and need User1 to be a local administrator on that RODC, using the principle of least privilege. Which tool or method should you use?
- You deployed two Online Responders to provide OCSP for your issuing enterprise CA. A hardware load balancer distributes traffic between them. You must ensure consistent revocation responses and proper scaling. What should you do? Choose two actions.
- You enabled Azure AD Seamless Single Sign-On with Password Hash Synchronization. Users signed in to domain-joined Windows 10 devices get SSO in Microsoft Edge, but Google Chrome and Mozilla Firefox still prompt for credentials. You need to minimize prompts in Chrome and Firefox for on-premises users. What should you do?
- You enabled hybrid Azure AD join in Azure AD Connect. On several Windows 10 domain-joined devices, dsregcmd /status shows DomainJoined = YES and AzureAdJoined = NO. The output also indicates "SCP not found." You need these devices to automatically complete hybrid Azure AD join. What should you do?
- You enabled Microsoft Defender SmartScreen on VM1. You need SmartScreen popup messages shown to users to be recorded in logs. Which action will enable logging of those SmartScreen notifications?
- You exported a tested Exploit protection baseline to \\fileshare\EPBase.xml. On server APP1, the legacy process C:\Program Files\Legacy\AppLegacy.exe crashes unless Export Address Filtering (EAF) is disabled for that process. You must import the baseline and disable EAF only for AppLegacy.exe. Which two PowerShell commands should you run on APP1?
- You have 20 on-premises Windows Server virtual machines and an Azure subscription with a Microsoft Sentinel workspace (Workspace1). You need to collect and forward events from the on-prem VMs to Workspace1 and be able to apply filters to reduce collected event volume. Which two components should you install on each VM?
- You have 200 Azure VMs and a recovery plan that fails them over to another Azure region. The recovery plan contains three manual actions; you want to replace one manual action with an automated process. Which of the following should you use to automate that action?
- You have 200 on-premises Windows and Linux servers connected via Azure Arc. You want to ingest Windows Security Events and Syslog into a Microsoft Sentinel workspace using the Azure Monitor Agent, avoiding the legacy Log Analytics agent. What two actions should you take?
- You have a Hyper-V host (Server1) running Windows Server 2019 hosting VM1 with a static IP (192.168.10.15), configuration version 8.0, virtual network VNet1, and Generation 1. After exporting VM1 from Server1 and importing it into Server2 (Windows Server 2025) using Hyper-V Manager, which VM settings will be retained?
- You have a Hyper-V host with the Azure Migrate appliance imported as VM1. To register VM1 with Azure Migrate, which actions should you perform in the Azure Migrate service? (Each correct option is part of the required steps.)
- You have a Log Analytics workspace (Workspace1) and 100 Windows Server VMs. Microsoft Defender for Servers Plan 2 is enabled and configured to monitor Windows file and registry changes on the VMs. Which Log Analytics table should you query to retrieve the detected file and registry change events?
- You have a Microsoft Sentinel workspace collecting logs from 100 Windows Server virtual machines. To find failed sign-in (logon) events in the collected data, which table should you query?
- You have a Remote Desktop Services deployment currently running Windows Server 2022 (servers listed). You plan to upgrade the RDS deployment to Windows Server 2025. Which server should you upgrade first?
- You have a Site-to-Site VPN (no BGP) between on-premises and an Azure VPN gateway. Vnet1 had Subnet1 with Server1 reachable from on-premises. You extended Vnet1’s address space, added Subnet2 (in the new range) and deployed Server2 to Subnet2. Server1 can reach Server2, but on-premises cannot. What must you do so on-premises can reach Subnet2?
- You have a VM named VM1 in the East US region and several storage accounts (storage1–storage4). You plan to configure Diagnostic settings for VM1. Which storage accounts should you select for the diagnostic data?
- You have an Active Directory domain and all domain-joined devices run Microsoft Defender Credential Guard with UEFI lock enabled. You deploy a Windows Server named Server1 and disable Credential Guard on that server. To ensure Server1 is not subject to Credential Guard restrictions, what should you do next?
- You have an Azure subscription that uses Microsoft Defender for Cloud and 50 Azure VMs running Windows Server. To forward any detected security exploits from the VMs to Defender for Cloud, which VM extension should you enable?
- You have an Azure subscription with a VM named VM1 (Windows Server). The subscription contains several storage accounts (storage1–storage4). You plan to enable boot diagnostics for VM1. Which storage account should you specify for storing the boot diagnostics logs and screenshots?
- You have an Azure subscription with several Key Vaults and you create a Windows Server VM (VM1) in resource group RG1 in East US. To enable Azure Disk Encryption for VM1, which key vault from the choices can store the encryption key for VM1?
- You have an Azure subscription with several Windows Server virtual machines. The subscription includes the Azure VM backup policies listed in the table. You are assessing which policies can automatically move recovery points to the vault-archive tier. For which policies is tiering to the vault-archive tier supported?
- You have an Azure VM (VM1) that uses Azure Disk Encryption. To determine which Azure Key Vault contains the VM's encryption keys with minimal administrative effort, which PowerShell cmdlet should you run?
- You have an on-prem file server (Server1) and an Azure subscription. You will migrate Server1's files to Azure using an Azure Data Box gateway. Which Azure storage types can receive the migrated files?
- You have an on-prem server Server1 (Windows Server 2025 Standard) and several Azure virtual machines. A Microsoft Sentinel instance (Sentinel1) exists in the Central US region. When implementing Windows Firewall Events using the AMA connector, which servers can send Windows Firewall events to Sentinel1?
- You have an on-premises AD DS domain with a Windows Server named Server1 that runs IIS and hosts a web app App1 using Windows authentication. You want to migrate App1 to Azure App Service and enable Windows authentication there. Which setting should you configure first?
- You have an on-premises AD DS domain with five domain-joined Windows Server machines and two Windows Server machines in a workgroup. To create a connection security rule between the domain-member servers and the workgroup servers, which authentication method should you select?
- You have an on-premises Hyper-V environment and an Azure Migrate project named Project1. To discover all Hyper-V hosts and virtual machines with the least administrative effort, what should you do first?
- You have an on-premises Server1 (Windows Server 2022) and several Azure VMs. Microsoft Sentinel1 is deployed in Central US. Which of the listed machines can send Windows Firewall logs to Sentinel1?
- You have an on‑premises server (Server1) and an Azure subscription. You plan to back up Server1’s files and folders to Azure using Azure Backup. Which component should you use to configure how long backups are retained?
- You have an on‑premises, two‑node, hyperconverged Windows Server Failover Cluster named Cluster1 and an Azure subscription. To configure a cloud witness for Cluster1, which type of Azure Storage must you use?
- You have five Azure VMs and a dedicated Azure Storage account to receive performance data directly. Which component should you install on the VMs to send the collected metrics and logs straight to the storage account?
- You have five Azure VMs and must gather performance counters and Windows Event logs from them, then write that data to an Azure Storage account. Which agent or extension should you install on the VMs?
- You have Microsoft Sentinel and 100 on-premises servers connected via Azure Arc, all in one resource group. To onboard those servers into Sentinel with minimal admin effort, which method should you use?
- You have several on-premises servers and plan to migrate them to Azure Generation 2 virtual machines. Which of the servers can be migrated to Generation 2 VMs using Azure Migrate?
- You have Sub1 with RG1 and the listed resources and Microsoft Defender for Servers enabled. You have Contributor permissions on Sub1. To enable just-in-time (JIT) access for VM1, what is the first task you must perform?
- You have three Hyper-V hosts (Server1, Server2, Server3) configured as a Storage Spaces Direct cluster named Cluster1. Cluster1 runs a VM (VM1) that has Windows Admin Center installed, and you manage the infrastructure through Windows Admin Center. You purchased an Azure subscription and must configure Azure Monitor email alerts for a set of cluster and VM metrics/events with minimal administrative effort. What should you do?
- You have three Hyper-V servers (Server1, Server2, Server3). Server1 hosts an Azure Migrate appliance named Migrate1. You will migrate VMs to Azure and need any new VMs created on Server1–Server3 to be discovered by Azure Migrate. What action should you take on the appliance?
- You have two AD DS forests, contoso.com and fabrikam.com. Using ADMT, you need to migrate resources from contoso.com to fabrikam.com. Which of the following resources can be migrated?
- You have two file servers, Server1 and Server2. Server1 hosts a shared folder Data with 10 TB of content. You are decommissioning Server1 and must move Data to a new share on Server2. Requirements: preserve share, file, and folder permissions; after the initial transfer, synchronize changes from \\Server1\Data to the destination without re-copying everything; and minimize administrative effort. Which tool should you use?
- You have two on-premises Hyper-V hosts: Server1 (hosting VM1 and VM2) and Server2 (hosting VM21, VM22, VM23). You will use Azure Site Recovery to replicate all VMs to Azure. What is the minimum number of Microsoft Azure Site Recovery Provider installations required on the on-premises environment?
- You have two Windows Server VMs, VM1 and VM2. VM1’s OS disk is encrypted with Azure Disk Encryption and is backed up daily with Azure Backup. Several files on VM1’s OS disk are corrupted. To restore the corrupted files from the latest recovery point while minimizing total restore time, what should you do first?
- You host multiple IIS sites: contoso.com, app1.contoso.com, app2.contoso.com, and api.contoso.com. You want a single certificate to secure all names and plan to renew it with minimal downtime. What should you do? Choose two actions.
- You host several .NET applications on an on-premises IIS web server and plan to migrate them (not containerized) to Azure App Service. Which migration tool should you use?
- You manage 100 Azure VMs onboarded to Microsoft Defender for Cloud. If Defender for Cloud raises the "Antimalware disabled in the virtual machine" alert, you want the affected VM to be shut down automatically. Which Defender for Cloud capability should you use?
- You manage 350 servers (Azure VMs and Azure Arc–connected on‑premises). All are already onboarded to Microsoft Defender for Endpoint. Due to strict change control, you must avoid deploying additional VM extensions while getting vulnerability findings surfaced in Microsoft Defender for Cloud. What should you do?
- You manage a DFS Replication deployment with one hub server at HQ and 12 branch servers. Branch users frequently edit the same files as HQ users, causing conflicts, and replication backlogs occur when large files are changed. You must reduce conflicts and minimize backlogs. What should you do? (Choose two)
- You manage a set of Azure Windows Server VMs. Requirement: Azure must automatically assess missing updates daily and install only security updates every Sunday from 01:00 to 03:00 local time, rebooting VMs only if required. Which configuration should you choose in Update Management Center?
- You manage a single WSUS server for an AD DS domain. New servers are added to OUs based on their role (e.g., OU=Web, OU=SQL). You want each server to automatically appear in the matching WSUS computer group (Web, SQL) without manual assignment. Which two configurations should you implement?
- You manage a standalone Windows Server 2022 file server that must have nightly System State backups and a weekly Bare Metal Recovery backup to a local disk, using minimal storage. What should you do?
- You manage an AD DS domain with 20 sites; user management is centralized. After adding users to a group, the change does not appear on a domain controller in a remote site. To determine whether the group modification has replicated to other domain controllers, which tool should you use?
- You manage an internal AD-integrated zone, corp.contoso.com, hosted on DNS1. Your internal recursive DNS servers (DNS-REC1 and DNS-REC2) must validate responses for this zone even though there is no parent trust chain. You also need to prevent zone enumeration. What two actions should you take?
- You manage an OU named Tier0 that contains Windows Server 2022 domain controllers running on physical hardware. All machines currently boot in legacy BIOS mode. Your security team requires Windows Defender Credential Guard to be enabled and locked so local administrators cannot disable it. You will deploy the change using Group Policy. What two actions must you perform to meet the requirement?
- You manage certificates for workloads in Azure. You need to use Azure Key Vault to store an existing PFX for immediate use and also enable automatic renewal and rotation for future certificates issued by a public CA. What should you configure? Choose two actions.
- You manage FileSrv1 (Windows Server 2022) hosting multiple SMB shares. For a share named Sensitive, you must ensure all SMB traffic is encrypted without affecting other shares. You must also prevent the use of SMBv1 on FileSrv1. What two actions should you take?
- You manage hybrid Windows Server machines onboarded with Azure Arc. You want to standardize patching using Update Management Center: assess compliance every Sunday and automatically patch only servers tagged PatchRing=Prod during a defined window, without creating or linking a Log Analytics workspace or Automation account. Which two actions should you take?
- You manage MG1 with subscription Sub1 and the shown resources. From the Azure portal, on which two resources can you enable Microsoft Defender for Servers? (Choose two.)
- You manage Windows Server 2019 file servers in an AD DS domain. Security policy requires BitLocker for OS volumes with TPM-based protection and a startup PIN. Compliance also requires that recovery information be automatically backed up to AD DS before BitLocker is enabled. Servers have TPM 2.0. What should you configure to meet both requirements? Choose two actions.
- You manage Windows Server 2022 servers that use Windows Update for Business. Requirements: pilot servers receive quality updates immediately; production servers receive the same quality updates 7 days later; during an incident, admins must be able to temporarily halt quality updates across production for up to 35 days. What should you configure?
- You must audit the following in your domain: new user creations (4720), account lockouts (4740), and failed logons (4625). Additionally, you need to detect attempts to modify objects within the ‘Service Accounts’ OU. All domain controllers run Windows Server 2019. Which two configurations should you implement?
- You must capture traffic on a Windows Server 2022 Core host and later analyze SMB 3.1.1 and TLS 1.3 handshakes with up-to-date protocol decoders. Which toolset should you use?
- You must deploy a new Windows Server 2022 VM that will use BitLocker inside the guest and enforce Secure Boot. An existing template is Generation 1. What two configuration changes are required for the VM?
- You must design an internal PKI that supports autoenrollment for domain users and computers and maximizes protection of the trust anchor. The design must include an offline root and permit normal enrollment operations from a domain-joined CA. Which deployment approach should you implement?
- You must enforce that all Arc-enabled Windows Server machines have the Local Administrator Password Solution (LAPS) policy configured and remediate drift automatically. What should you configure to ensure both audit and remediation occur at scale?
- You must patch 120 Arc-enabled Windows Server machines monthly on the second Saturday. Requirements: a 120-minute maintenance window, reboot if required, exclude optional/preview updates, and produce compliance reports showing missing updates and installation results. What should you configure?
- You must prevent unsigned code from running on Windows Server 2022 file servers, allow only Microsoft-signed and Contoso-signed binaries/drivers, and begin in audit mode for a week before enforcing. What should you do?
- You must publish an on-premises HR web application that uses Integrated Windows Authentication to the internet. Users should authenticate with Microsoft Entra ID and get single sign-on to the app using their Kerberos identity. The organization has two datacenters and wants to minimize latency by using connectors closest to the app servers. What should you do? (Select three)
- You must restrict RDP access to an Azure VM to on‑demand requests for up to 3 hours and only from the requester’s public IP. You also need an auditable record of all access requests retained in Log Analytics. What should you do? (Choose two)
- You need a single query that lists all Arc-enabled servers missing the Azure Monitor Agent extension and shows the compliance status of any Guest Configuration assignments on those servers. Which Azure Resource Graph query should you use?
- You need endpoint detection and response for your Windows and Linux servers with alerting in Microsoft Defender for Cloud. You do not require just‑in‑time VM access, file integrity monitoring, adaptive controls, or integrated vulnerability assessment. Which plan should you enable to meet requirements at the lowest cost?
- You need to capture all DNS queries and responses from a busy Windows Server DNS resolver for one hour with minimal performance impact and then analyze the data centrally. What should you configure?
- You need to deploy a Storage Spaces Direct cluster that uses nested resiliency. What is the minimum number of cluster nodes required?
- You need to detect and alert on changes to C:\Windows\System32 and to the HKLM\Software\Company registry path on Windows Servers. You use Microsoft Defender for Servers Plan 2 and want alerts to appear in Defender for Cloud and logs in a Log Analytics workspace. What should you configure?
- You need to enforce that only devices that are either compliant (Intune) or hybrid Azure AD joined can access Exchange Online. Additionally, sign-ins assessed as High risk must be blocked. What should you configure? (Choose two)
- You need to ensure members of the Domain Admins group can authenticate only to two privileged access workstations (PAW1 and PAW2) and not to any other computer in the domain. The forest functional level is Windows Server 2012 R2, and all DCs are Windows Server 2019. What should you configure to meet the requirement with centralized enforcement?
- You need to grant external contractors from fabrikam.com self-service access to a SharePoint Online site and a line-of-business app for 90 days. Requests must require approval by the site owner, and access should automatically expire and be removed. You do not want to pre-create guest accounts. What should you configure? (Choose two)
- You need to onboard security logs into Microsoft Sentinel from 12 on-premises Windows Server domain controllers and several Linux firewalls. All servers are Azure Arc–enabled, and you must avoid the legacy Log Analytics agent. You must collect Windows Security Events (including 4688) from the domain controllers and CEF-formatted events from the firewalls. What two actions should you take?
- You need to prevent users from setting weak passwords in on-premises Active Directory. The solution must block commonly used and organization-specific terms and apply across all writable domain controllers in the forest. What should you do? (Choose two)
- You need to provide administrators SSH access to Arc-enabled Linux servers located on a private network with no public IPs or inbound firewall holes. Access must use Azure AD authentication with short-lived credentials. What should you do?
- You need update compliance reporting in Azure for 200 Windows Server 2019 and 2022 machines currently configured to use WSUS. You want to use Windows Update for Business reports to track quality update compliance and safeguard holds. Which two steps are required?
- You operate 300 on-premises Windows Server machines that are Arc-enabled. Leadership wants a consistent, Microsoft-recommended baseline applied and kept compliant with minimal manual configuration of underlying services (monitoring, updates, security). What should you implement?
- You operate a group of Windows Server web servers running a custom app from D:\Apps. You want to initially observe allowed processes, then enforce an allowlist that includes the custom app’s path, using Microsoft Defender for Cloud. What should you do?
- You operate three Microsoft Sentinel workspaces in different regions. You need a single SOC dashboard that shows incident counts by severity and sign-in failure trends across all workspaces, with a time range and workspace selector, and you must grant analysts read-only access without giving them write permissions to the workspaces. What two actions should you take?
- You piloted Attack Surface Reduction (ASR) and now need production settings on Windows Server 2019: 1) Block Office from creating child processes, but allow a signed helper at C:\Program Files\Contoso\XLLHelper.exe; 2) Keep 'Block process creations originating from PSExec and WMI' in audit to monitor admin tool usage. Which command meets the requirement?
- You plan to deploy 802.1X authentication for wired access using NPS. You do not want to deploy client certificates and you require users to authenticate with their AD credentials while protecting the authentication inside a TLS tunnel. What should you configure on the NPS?
- You plan to enforce LDAP signing and LDAP channel binding on all domain controllers. Before enforcing, you want to identify incompatible clients without breaking them. What should you deploy first? (Choose two)
- You plan to migrate an on-premises IIS web app (which connects to an on-premises SQL Server database) to Azure App Service, while leaving the database on-premises. What Azure component should you configure so the migrated App Service app can reach the on-premises database?
- You plan to onboard 25 on-premises Windows Server and Linux machines to Azure Arc for a pilot this week, and then hundreds more next quarter with no interactive sign-ins. You also want governance to ensure any new servers brought online in the future are automatically onboarded. What should you do?
- You plan to replicate an on‑premises VM (VM1) to Azure using an Azure Site Recovery replication policy. To have changes replicated as frequently as possible, what should you set the policy’s Copy frequency to?
- You plan to replicate on-premises VMware VMs to Azure using Azure Site Recovery and must support failback to the on-premises site. What should you deploy and where?
- You plan to standardize member servers with the Windows Server 2022 security baseline and regularly report deviations per server. What should you do?
- You plan to use an Azure Storage account as the cloud witness for a two-node failover cluster hosting two Azure VMs. To maximize resiliency, which storage account redundancy option should you choose?
- You plan to use Print Management to migrate the printers from Server1 to Server2. Which printers can be migrated and keep their existing configuration?
- You plan to use the legacy Azure Automation Update Management solution to patch 20 on-premises Windows Server 2019 machines. Requirements: centralize update assessment data in a single Log Analytics workspace; stop a custom service before patching and restart it afterward; enforce a 60-minute maintenance window. What should you configure?
- You plan to use VM insights in Azure Monitor to monitor 500 on-premises Windows servers and will onboard them to Azure Arc using the template script. To satisfy least privilege and reduce admin work, what should you create first?
- You run a mission-critical workload on Azure VMs and want to minimize reboots by using Hotpatch. Which two configurations meet the requirement?
- You run a Windows Server 2022 Hyper-V host. You need a lab VM (LabHost) to run Docker Windows containers with Hyper-V isolation and also host nested VMs for testing. What must you do on LabHost’s configuration before installing the Hyper-V role inside it? (Choose two)
- You run AKS clusters and store images in Azure Container Registry (ACR). You need image vulnerability scanning on push to ACR and runtime threat detection from the clusters. What should you do?
- You run one Azure AD Connect server, two AD FS servers, and two Web Application Proxy (WAP) servers. You need to be alerted if directory synchronization stops or error rates spike, and you want to view AD FS usage analytics (for example, sign-in success rates and top apps) in the Azure portal. What should you do? (Choose two)
- You want Microsoft Sentinel to surface user anomalies such as rare RDP logons and unusual data access patterns, and to display user insights within incidents. Your environment already streams Azure AD sign-in logs, Windows Security Events, and Microsoft 365 audit logs to Sentinel. What two actions should you perform?
- You want to minimize standing privileges for Global Administrator. Admins should request just-in-time elevation, be prompted for MFA and approval by the security team, and automatically lose the elevation after two hours. You also want a monthly validation that only necessary users retain eligibility. What should you configure? (Choose two)
- You want to onboard an on-premises Windows Server (Server1) to Microsoft Defender for Cloud. Which agent or component must be installed on Server1?
- You will deploy a converged Storage Spaces Direct solution on an Ethernet fabric and want to avoid requiring Data Center Bridging (DCB). Which RDMA networking technology should you choose?
- You will deploy a new line-of-business application to an Azure VM running Windows Server and need to prevent that application from spawning child processes. Which protection feature should you enable on the VM?
- You will deploy Hyper‑V Replica between Server1 and Server2 using certificate‑based authentication. What two prerequisite steps must you perform on each server?
- Your AD DS domain contains Server1 (Windows Server 2019) hosting multiple printers and Server2 (Windows Server 2025), both have the Print and Document Services role. You need to migrate the printers from Server1 to Server2 with minimal administrative effort. Which tool(s) should you use?
- Your AD DS domain contains two VMs (VM1 and VM2) that will be nodes in a failover cluster named Cluster1. You need Cluster1 to be able to use floating IP addresses. Which two components should you deploy?
- Your AD DS domain contoso.com contains a member server named server1.contoso.com. You cannot resolve the server's FQDN, although you can successfully ping the server by its IP address and the Windows Defender Firewall is configured correctly. To confirm whether the DNS record for server1.contoso.com exists, which command should you run?
- Your AD DS domain has three domain controllers (DC1, DC2, DC3). You connect Microsoft Defender for Identity to the domain. To onboard all domain controllers to Defender for Identity, which installer should you run on each domain controller?
- Your AD DS domain includes multiple domain controllers running Windows Server 2019 with configurations shown in an accompanying table. Before you run adprep /domainprep, which domain controller must be available for the command to succeed?
- Your AD DS environment (Windows Server 2016 forest functional level) includes a domain controller DC1 that is experiencing SYSVOL replication problems. Which service should you stop to halt the service that replicates SYSVOL?
- Your AD DS forest currently has a Windows Server 2008 R2 forest functional level. You need to perform an in-place upgrade of the domain controllers in east.contoso.com to Windows Server 2025 with minimal administrative effort. What should you do first?
- Your Azure subscription contains several storage accounts shown in a table. You will enable Azure Site Recovery replication for Server1. The replication must support backing up high-churn workloads and keep costs low. Which storage account should you designate as the Cache storage?
- Your Azure subscription contains several virtual machines listed in a table. You plan to use Azure Site Recovery to replicate supported virtual machines to a secondary Azure region. Which of these virtual machines can be replicated by Azure Site Recovery?
- Your Azure subscription contains several Windows Server virtual machines (listed in a table). You plan to use Azure Site Recovery. Which of the listed VMs are supported for replication by Site Recovery?
- Your company has a hub-and-spoke topology with a central WSUS server (WSUS01) in the hub and a WSUS server (WSUS02) in a branch office. Branch clients must download updates from WSUS02, but all approvals and computer group structure must be controlled only from WSUS01 and mirrored on WSUS02. You also want WSUS02 to sync on a schedule without branch admin involvement. Which two actions should you take?
- Your company has branch wireless controllers that send RADIUS requests to a local NPS server named Branch-NPS. Corporate policy requires that all authentication and accounting be processed on a central NPS at headquarters (HQ-NPS). Branch-NPS must only forward requests based on the NAS-IP-Address of the branch controllers and must not perform local authentication. Which two actions should you perform on Branch-NPS?
- Your contoso.com AD DS domain was created using domain controllers that run Windows Server 2025. You must add a domain controller running an older Windows Server release for a custom application. What is the oldest Windows Server version you can use for a domain controller in contoso.com?
- Your datacenter servers must be connected to Azure Arc through a corporate proxy that requires authentication. The estate includes Windows Server 2012 R2, Ubuntu 14.04, and RHEL 8. You need to ensure successful onboarding while meeting agent and network requirements. Which two actions should you take?
- Your domain contoso.com was deployed using Windows Server 2022 domain controllers. You need to add a domain controller that runs an older version of Windows Server for a custom application. What is the oldest Windows Server release you can run as a domain controller in contoso.com?
- Your domain controllers run Windows Server 2019. Security wants to prevent helpdesk admin accounts from authenticating with NTLM, block credential delegation, and limit Kerberos to strong encryption while maintaining normal sign-in. What should you do for these helpdesk accounts? (Choose two)
- Your domain is at the Windows Server 2012 R2 forest and domain functional level. You need to be able to deploy a new domain controller that runs Windows Server 2025 while minimizing administrative work. Which two actions should you take? (Choose two.)
- Your environment has an AD DS domain with two Windows Server Failover Clusters: Cluster1 (hosts Hyper‑V virtual machines) and Cluster2 (no high‑availability roles). You will create a Storage Spaces Direct cluster on Cluster2 to hold the virtual machine disk files for Cluster1. Which role(s) should be configured on Cluster2?
- Your forest has the AD Recycle Bin enabled and a tombstone lifetime of 180 days. An OU named ‘Apps’ (containing 40 groups and 200 service accounts) was deleted 10 days ago. You must restore the OU and all child objects to their original locations with the least administrative effort. What should you do?
- Your forest is Windows Server 2016. Autoenrollment is already enabled via GPO. You must issue user encryption certificates using CNG keys that support key archival for recovery. What two configurations are required?
- Your on-premises network connects to Azure through a VPN gateway named VPN1. To monitor the Azure gateway health probe for VPN1, which TCP port should the probe use?
- Your on-premises network has a 200 Mbps link to Azure and a server holding 70 TB of data. Copying the files to an Azure blob container with azcopy would take about 35 days. You want to minimize total migration time. Which solution should you use?
- Your on-premises network has two subnets with Windows servers. Server4's IP settings are: IPv4 Address 192.168.0.10, Subnet Mask 255.255.255.0, Default Gateway 192.168.0.1. From Server4 you can ping Server1 and Server2, but pinging Server3 times out. From Server2 you can ping Server1 and Server3. Which misconfigured setting on Server3 would cause the ping from Server4 to time out?
- Your on-premises network is connected to Azure and the subscription contains a VM named VM1 (Windows Server). You need to measure the latency between the on-premises network and VM1. Which Azure Network Watcher feature should you use?
- Your on-premises network is connected to VNet1 by a site-to-site VPN. Traffic from Server1 to VM1 is failing to reach VM1. To inspect the contents of the traffic sent from Server1 to VM1, what should you do first?
- Your onboarding automation needs permission to connect new servers to Azure Arc, and your operations team needs to manage extensions and guest configuration on Arc-enabled servers but must not delete resources. How should you assign roles and organize resources?
- Your organization adopts an AD tiering model: Tier 0 (DCs, forest-level services), Tier 1 (member servers/apps), and Tier 2 (user workstations). You must prevent Tier 0 admin credentials from being exposed on Tier 1 and Tier 2 devices and ensure credential isolation between tiers. Which two actions align with the model?
- Your organization already uses MBAM to escrow BitLocker recovery keys for Windows clients. After a recent incident, you must enable automatic unlock of OS volumes when domain-joined systems boot on a trusted wired network, and you want to accelerate encryption during imaging. What should you do? Choose two actions.
- Your organization currently backs up only System State of several on-premises Windows Server 2016 domain controllers using the MARS agent to a Recovery Services vault. You must add the capability to perform a full bare-metal recovery (BMR) to dissimilar hardware or a new VM at an alternate location. What should you implement?
- Your organization is implementing Privileged Access Workstations (PAWs) for Tier 0 admins. Requirements: Tier 0 accounts must sign in only from PAWs, and PAWs must not be able to browse the Internet or run email clients. Which two configurations should you implement?
- Your organization synchronizes a single on-premises Active Directory forest to Microsoft Entra ID using Azure AD Connect. You want users to be able to reset their passwords in the cloud and have those changes written back to on-premises AD. You also plan to use AD FS device authentication to enable device-based access control for on-premises web apps. Which two Azure AD Connect optional features should you enable? (Choose two)
- Your organization uses a single Microsoft Sentinel workspace. Compliance requires Windows SecurityEvent data be retained for 180 days in hot storage and then archived, while Syslog data should be retained for 30 days. To reduce ingestion, only Windows event IDs 4624, 4625, and 4688 should be collected. What two actions should you take?
- Your security team requires Windows Security event collection from Arc-enabled Windows servers and a one-time hardening script to run on 30 Arc-enabled Linux servers in a segmented network. No inbound ports can be opened. Which two extensions should you deploy?
- Your security team wants the following automation: when Microsoft Defender for Cloud raises a High‑severity alert, open a ServiceNow incident and email the SOC; when a specific recommendation that supports policy remediation appears, automatically start a remediation task. What should you configure?
- Your SOC maintains a daily CSV with IPAddress and Action (Allow/Deny). You need to use it in Microsoft Sentinel to enrich analytics rules so they alert when a Deny IP appears in sign-in data, and the list must update automatically every morning from a secure storage location. What two actions should you take?
- Your SOC needs to detect excessive failed sign-ins within one minute and also detect sophisticated multi-stage attacks across signals from multiple Microsoft security products without writing custom correlation logic. What two configurations in Microsoft Sentinel should you implement?
- Your subscription shows a Secure Score of 35% in Microsoft Defender for Cloud with dozens of recommendations. Several recommendations don’t apply to a specific resource group that hosts third‑party appliances. You must rapidly raise the Secure Score by fixing items at scale and prevent non‑applicable recommendations in that resource group from impacting the score. What should you do? (Choose two)
- Your subscription uses Microsoft Defender for Cloud and you have 50 Windows Server Azure VMs. To ensure security exploit detections on the VMs are forwarded into Defender for Cloud, which VM extension should you install?
- Your team wants high-severity “Impossible travel” incidents to automatically disable the affected user in Microsoft Entra ID, add the source IP to a Sentinel watchlist, and post a message to a SOC Microsoft Teams channel. You will use a Logic App playbook with a managed identity. What two actions should you perform?
- Your Windows Server 2019 Hyper-V host must enable virtualization-based security (VBS) with Credential Guard and HVCI. The server currently boots in legacy BIOS mode and the firmware does not have IOMMU (VT-d/AMD-Vi) enabled. Attempts to enable VBS report that the system does not meet requirements. What two changes are required before enabling VBS?
- Your WSUS server’s SUSDB has grown large, the console is slow, and the Content folder is consuming excessive disk space. You need to reclaim space and improve performance without losing necessary approvals. Which two actions should you perform?
Pass your Microsoft exam — faster
Every verified answer and explanation in one place. Practice the full exam and save hours of prep — free to start.
Pass your exam →Guides & tips
- Microsoft AZ-140: Applications and End-User Experience — Study Guide
- Microsoft AZ-140: Azure Virtual Desktop Architecture and Service Design — Study Guide
- Microsoft AZ-140: FSLogix, Profiles and User Data — Study Guide
- Microsoft AZ-140: Identity, Access and Governance — Study Guide
- Microsoft AZ-140: Monitoring, Diagnostics and Troubleshooting — Study Guide
- Microsoft AZ-140: Networking, Connectivity and Transport — Study Guide