AZ-104 Microsoft Azure Administrator Dumps

If you are looking for free AZ-104 dumps than here we have some sample question answers available. You can prepare from our Microsoft AZ-104 exam questions notes and prepare exam with this practice test. Check below our updated AZ-104 exam dumps.

DumpsGroup are top class study material providers and our inclusive range of AZ-104 Real exam questions would be your key to success in Microsoft Azure Administrator Associate Certification Exam in just first attempt. We have an excellent material covering almost all the topics of Microsoft AZ-104 exam. You can get this material in Microsoft AZ-104 PDF and AZ-104 practice test engine formats designed similar to the Real Exam Questions. Free AZ-104 questions answers and free Microsoft AZ-104 study material is available here to get an idea about the quality and accuracy of our study material.


discount banner

Sample Question 4

You deploy Azure virtual machines to three Azure regions.Each region contains a virtual network. Each virtual network contains multiple subnetspeered in a full mesh topology.Each subnet contains a network security group (NSG) that has defined rules.A user reports that he cannot use port 33000 to connect from a virtual machine in oneregion to a virtual machine in another region.Which two options can you use to diagnose the issue? Each correct answer presents acomplete solution.NOTE: Each correct selection is worth one point.

A. Azure Virtual Network Manager
B. IP flow verify
C. Azure Monitor Network Insights
D. Connection troubleshoot
E. elective security rules


Sample Question 5

Note: This question is part of a series of questions that present the same scenario. Eachquestion in the series contains a unique solution that might meet the stated goals. Somequestion sets might have more than one correct solution, while others might not have acorrect solution.After you answer a question in this section, you will NOT be able to return to it. As a result,these questions will not appear in the review screen.You have an Azure subscription that contains the virtual machines shown in the followingtable.You deploy a load balancer that has the following configurations:•Name: LB1•Type: Internal•SKU: Standard•Virtual network: VNET1You need to ensure that you can add VM1 and VM2 to the backend pool of LB1.Solution: You create a Standard SKU public IP address, associate the address to thenetwork interface of VM1, and then stop VM2.Does this meet the goal?

A. Yes
B. No


Sample Question 6

Note: This question is part of a series of questions that present the same scenario. Eachquestion in the series contains a unique solution that might meet the stated goals. Somequestion sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result,thesequestions will not appear in the review screen.You manage a virtual network named VNet1 that is hosted in the West US Azure region.VNet1 hosts two virtual machines named VM1 and VM2 that run Windows Server.You need to inspect all the network traffic from VM1 to VM2 for a period of three hours.Solution: From Performance Monitor, you create a Data Collector Set (DCS).Does this meet the goal?

A. Yes
B. No


Sample Question 7

Note: This question is part of a series of questions that present the same scenario. Eachquestion in the series contains a unique solution that might meet the stated goals. Somequestion sets might have more than one correct solution, while others might not have acorrect solution.After you answer a question in this section, you will NOT be able to return to it. As a result,these questions will not appear in the review screen.You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource groups.Another administrator plans to create several network security groups (NSGs) in thesubscription.You need to ensure that when an NSG is created, it automatically blocks TCP port 8080between the virtual networks.Solution: You create a resource lock, and then you assign the lock to the subscription.Does this meet the goal?

A. Yes
B. No


Sample Question 8

You have an Azure DNS zone named adatum.com. You need to delegate a subdomainnamed research.adatum.com to a different DNS server in Azure. What should you do?

A. Create an PTR record named research in the adatum.com zone.
B. Create an NS record named research in the adatum.com zone.
C. Modify the SOA record of adatum.com.
D. Create an A record named *. research in the adatum.com zone


Sample Question 9

Note: This question is part of a series of questions that present the same scenario. Eachquestion in the series contains a unique solution that might meet the stated goals. Somequestion sets might have more than one correct solution, while others might not have acorrect solution.After you answer a question in this section, you will NOT be able to return to it. As a result,these questions will not appear in the review screen.You have an Azure Active Directory (Azure AD) tenant named Adatum and an AzureSubscription named Subscription1. Adatum contains a group named Developers.Subscription1 contains a resource group named Dev.You need to provide the Developers group with the ability to create Azure logic apps in theDev resource group.Solution: On Dev, you assign the Logic App Operator role to the Developers group.Does this meet the goal?

A. Yes
B. No


Sample Question 10

You have an Azure virtual machine named VM1 and an Azure key vault named Vault1. On VM1, you plan to configure Azure Disk Encryption to use a key encryption key (KEK)You need to prepare Vault! for Azure Disk Encryption.Which two actions should you perform on Vault1? Each correct answer presents part of thesolution.NOTE: Each correct selection is worth one point.

A. Create a new key.
B. Select Azure Virtual machines for deployment
C. Configure a key rotation policy.
D. Create a new secret.
E. Select Azure Disk Encryption for volume encryption


Sample Question 11

You have an Azure subscription that contains a storage account named account1.You plan to upload the disk files of a virtual machine to account! from your on-premisesnetwork. The on-premises network uses a public IP address space of 131.107.1.0/24.You plan to use the disk files to provision an Azure virtual machine named VM1. VM1 willbe attached to a virtual network named VNet1. VNet1 uses an IP address space of192.168.0.0/24.You need to configure account1 to meet the following requirements:• Ensure that you can upload the disk files to account1.• Ensure that you can attach the disks to VM1.• Prevent all other access to account1.Which two actions should you perform? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.

A. From the Networking blade of account1, select Selected networks
B. From the Service endpoints blade of VNet1, add a service endpoint.
C. From the Networking blade of account11, add the 131.107.1.0/24 IP address range.
D. From the Networking blade of account1. select Allow trusted Microsoft services toaccess this storage account
E. From the Networking blade of account1, add VNet1.


Sample Question 12

Note: This question is part of a series of questions that present the same scenario. Eachquestion in the series contains a unique solution that might meet the stated goals. Somequestion sets might have more than one correct solution, while others might not have acorrect solution.After you answer a question in this section, you will NOT be able to return to it. As a result,these questions will not appear in the review screen.You have an Azure virtual machine named VM1. VM1 was deployed by using a customAzure Resource Manager template named ARM1.json.You receive a notification that VM1 will be affected by maintenance. You need to move VM1 to a different host immediately.Solution: From the Update management blade, you click Enable.Does this meet the goal?

A. Yes
B. No


Sample Question 13

You have an Azure Active Directory (Azure AD) tenant named contoso.com.You have a CSV file that contains the names and email addresses of 500 external users.You need to create a quest user account in contoso.com for each of the 500 externalusers.Solution: from Azure AD in the Azure portal, you use the Bulk create user operation.Does this meet the goal?

A. Yes
B. No


Sample Question 14

You have an Azure subscription that contains 20 virtual machines, a network security group(NSG) named NSG1, and two virtual networks named VNET1 and VNET2 that are peered.You plan to deploy an Azure Bastion Basic SKU host named Bastion1 to VNET1.You need to configure NSG1 to allow inbound access from the internet to Bastion1.Which port should you configure for the inbound security rule?

A. 22
B. 443
C. 3389
D. 8080


Sample Question 15

You have an Azure Storage account named storage1. You plan to use AzCopy to copy data to storage1. You need to identify the storage services in storage1 to which you can copy the data. What should you identify?

A. blob, file, table, and queue 
B. blob and file only
 C. file and table only 
D. file only 
E. blob, table, and queue only 


Sample Question 16

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure subscription named Subscription1. Subscription1 contains a resource group named RG1. RG1 contains resources that were deployed by using templates. You need to view the date and time when the resources were created in RG1. Solution: From the Subscriptions blade, you select the subscription, and then click Programmatic deployment. Does this meet the goal?

A. Yes 
B. No 


Sample Question 17

You plan to deploy several Azure virtual machines that will run Windows Server 2019 in a virtual machine scale set by using an Azure Resource Manager template. You need to ensure that NGINX is available on all the virtual machines after they are deployed. What should you use? 

A. a Desired State Configuration (DSC) extension 
B. thePublish-AzVMDscConfigurationCmdlet 
C. a Microsoft Intune device configuration profile 
D. Deployment Center in Azure App Service 


Sample Question 18

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You deploy an Azure Kubernetes Service (AKS) cluster named AKS1. You need to deploy a YAML file to AKS1. Solution: From the Azure CLI, you run the kubectl client. Does this meet the goal?

A. Yes 
B. No 


Sample Question 19

You have two Azure virtual networks named VNet1 and VNet2. VNet1 contains an Azure virtual machine named VM1. VNet2 contains an Azure virtual machine named VM2. VM1 hosts a frontend application that connects to VM2 to retrieve data. Users report that the frontend application is slower than usual. You need to view the average round-trip time (RTT) of the packets from VM1 to VM2. Which Azure Network Watcher feature should you use?

A. NSG flow logs 
B. Connection troubleshoot 
C. IP flow verify 
D. Connection monitor 


Sample Question 20

You have an on-premises server that contains a folder named D:\Folder1. You need to copy the contents of D:\Folder1 to the public container in an Azure Storage account named contoso data. Which command should you run?

A. https://contosodata.blob.core.windows.net/public 
B. azcopy sync D:\folder1 https://contosodata.blob.core.windows.net/public --snapshot 
C. azcopy copy D:\folder1 https://contosodata.blob.core.windows.net/public --recursive 
D. az storage blob copy start-batch D:\Folder1 https:// contosodata.blob.core.windows.net/public


Sample Question 21

You have an Azure virtual machine named VM1 that runs Windows Server 2019. You save VM1 as a template named Template1 to the Azure Resource Manager library. You plan to deploy a virtual machine named VM2 from Template1. What can you configure during the deployment of VM2?

A. virtual machine size 
B. operating system 
C. administrator username 
D. resource group 


Sample Question 22

You have an app named App1 that runs on two Azure virtual machines named VM1 and VM2. You plan to implement an Azure Availability Set for App1. The solution must ensure that App1 is available during planned maintenance of the hardware hosting VM1 and VM2. What should you include in the Availability Set?

A. one update domain 
B. two fault domains 
C. one fault domain 
D. two update domains 


Sample Question 23

Your company has three offices. The offices are located in Miami, Los Angeles, and New York. Each office contains a datacenter. You have an Azure subscription that contains resources in the East US and West US Azure regions. Each region contains a virtual network. The virtual networks are peered. You need to connect the datacenters to the subscription. The solution must minimize network latency between the datacenters. What should you create? 

A. three virtual WANs and one virtual hub 
B. three virtual hubs and one virtual WAN 
C. three On-premises data gateways and one Azure Application Gateway 
D. three Azure Application Gateways and one On-premises data gateway 


Sample Question 24

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure subscription named Subscription1. Subscription1 contains a resource group named RG1. RG1 contains resources that were deployed by using templates. You need to view the date and time when the resources were created in RG1. Solution: From the RG1 blade, you click Deployments. Does this meet the goal? 

A. Yes 
B. No 


Sample Question 25

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure Active Directory (Azure AD) tenant named Adatum and an Azure Subscription named Subscription1. Adatum contains a group named Developers. Subscription1 contains a resource group named Dev. You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group. Solution: On Subscription1, you assign the Logic App Operator role to the Developers group. Does this meet the goal? 

A. Yes 
B. No 


Sample Question 26

You have five Azure virtual machines that run Windows Server 2016. The virtual machines are configured as web servers. You have an Azure load balancer named LB1 that provides load balancing services for the virtual machines. You need to ensure that visitors are serviced by the same web server for each request. What should you configure? 

A. Floating IP (direct server return) to Enabled
 B. Idle Time-out (minutes) to 20 
C. Protocol to UDP 
D. Session persistence to Client IP and Protocol 


Sample Question 27

You have an Azure subscription that contains a policy-based virtual network gateway named GW1 and a virtual network named VNet1. You need to ensure that you can configure a point-to-site connection from an on-premises computer to VNet1. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

A. Add a service endpoint to VNet1 
B. Reset GW1 
C. Create a route-based virtual network gateway
 D. Add a connection to GW1 
E. Delete GW1 
F. Add a public IP address space to VNet1 


Sample Question 28

You have an Azure subscription named Subscription1. You deploy a Linux virtual machine named VM1 to Subscription1. You need to monitor the metrics and the logs of VM1. What should you use?

A. Linux Diagnostic Extension (LAD) 3.0 
B. Azure Analysis Services 
C. the AzurePerformanceDiagnostics extension 
D. Azure HDInsight 


Sample Question 29

You plan to deploy several Azure virtual machines that will run Windows Server 2019 in a virtual machine scale set by using an Azure Resource Manager template. You need to ensure that NGINX is available on all the virtual machines after they are deployed. What should you use?

A. Azure Active Directory (Azure AD) Application Proxy 
B. Azure Application Insights 
C. Azure Custom Script Extension 
D. the New-AzConfigurationAssignement cmdlet 


Sample Question 30

Your on-premises network contains an SMB share named Share1. You have an Azure subscription that contains the following resources: A web app named webapp1 A virtual network named VNET1 You need to ensure that webapp1 can connect to Share1. What should you deploy?

A. an Azure Application Gateway 
B. an Azure Active Directory (Azure AD) Application Proxy 
C. an Azure Virtual Network Gateway 


Sample Question 31

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure virtual machine named VM1 that runs Windows Server 2016. You need to create an alert in Azure when more than two error events are logged to the System log on VM1 within an hour. Solution: You create an Azure Log Analytics workspace and configure the data settings. You install the Microsoft Monitoring Agent on VM1. You create an alert in Azure Monitor and specify the Log Analytics workspace as the source. Does this meet the goal?

A. Yes 
B. No 


Sample Question 32

You have an Azure Active Directory (Azure AD) tenant named contoso.com. Multi-factor authentication (MFA) is enabled for all users. You need to provide users with the ability to bypass MFA for 10 days on devices to which they have successfully signed in by using MFA. What should you do?

A. From the multi-factor authentication page, configure the users’ settings. 
B. From Azure AD, create a conditional access policy. 
C. From the multi-factor authentication page, configure the service settings. 
D. From the MFA blade in Azure AD, configure the MFA Server settings. 


Sample Question 33

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure subscription that contains the following resources: A virtual network that has a subnet named Subnet1 Two network security groups (NSGs) named NSG-VM1 and NSG-Subnet1 A virtual machine named VM1 that has the required Windows Server configurations to allow Remote Desktop connections NSG-Subnet1 has the default inbound security rules only. NSG-VM1 has the default inbound security rules and the following custom inbound security rule: Priority: 100 Source: Any Source port range: * Destination: * Destination port range: 3389 Protocol: UDP Action: Allow VM1 connects to Subnet1. NSG1-VM1 is associated to the network interface of VM1. NSGSubnet1 is associated to Subnet1. You need to be able to establish Remote Desktop connections from the internet to VM1. Solution: You modify the custom rule for NSG-VM1 to use the internet as a source and TCP as a protocol. Does this meet the goal?

A. Yes 
B. No 


Sample Question 34

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure virtual machine named VM1 that runs Windows Server 2016. You need to create an alert in Azure when more than two error events are logged to the System log on VM1 within an hour. Solution: You create an event subscription on VM1. You create an alert in Azure Monitor and specify VM1 as the source. Does this meet the goal?

A. Yes
 B. No 


Sample Question 35

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure subscription that contains the following resources: A virtual network that has a subnet named Subnet1 Two network security groups (NSGs) named NSG-VM1 and NSG-Subnet1 A virtual machine named VM1 that has the required Windows Server configurations to allow Remote Desktop connections NSG-Subnet1 has the default inbound security rules only. NSG-VM1 has the default inbound security rules and the following custom inbound security rule: Priority: 100 Source: Any Source port range: * Destination: * Destination port range: 3389 Protocol: UDP Action: Allow VM1 connects to Subnet1. NSG1-VM1 is associated to the network interface of VM1. NSGSubnet1 is associated to Subnet1. You need to be able to establish Remote Desktop connections from the internet to VM1. Solution: You add an inbound security rule to NSG-Subnet1 and NSG-VM1 that allows connections from the internet source to the VirtualNetwork destination for port range 3389 and uses the TCP protocol. Does this meet the goal?

A. Yes 
B. No 


Sample Question 36

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a computer named Computer1 that has a point-to-site VPN connection to an Azure virtual network named VNet1. The point-to-site connection uses a self-signed certificate. From Azure, you download and install the VPN client configuration package on a computer named Computer2. You need to ensure that you can establish a point-to-site VPN connection to VNet1 from Computer2. Solution: On Computer2, you set the Startup type for the IPSec Policy Agent service to Automatic. Does this meet the goal?

A. Yes 
B. No 


Sample Question 37

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure Active Directory (Azure AD) tenant named Adatum and an Azure Subscription named Subscription1. Adatum contains a group named Developers. Subscription1 contains a resource group named Dev. You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group. Solution: On Subscription1, you assign the DevTest Labs User role to the Developers group. Does this meet the goal?

A. Yes 
B. No 


Sample Question 38

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a computer named Computer1 that has a point-to-site VPN connection to an Azure virtual network named VNet1. The point-to-site connection uses a self-signed certificate. From Azure, you download and install the VPN client configuration package on a computer named Computer2. You need to ensure that you can establish a point-to-site VPN connection to VNet1 from Computer2. Solution: You modify the Azure Active Directory (Azure AD) authentication policies. Does this meet this goal? 

A. Yes 
B. No 


Sample Question 39

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure subscription that contains the following resources: A virtual network that has a subnet named Subnet1 Two network security groups (NSGs) named NSG-VM1 and NSG-Subnet1 A virtual machine named VM1 that has the required Windows Server configurations to allow Remote Desktop connections NSG-Subnet1 has the default inbound security rules only. NSG-VM1 has the default inbound security rules and the following custom inbound security rule: Priority: 100 Source: Any Source port range: * Destination: * Destination port range: 3389 Protocol: UDP Action: Allow VM1 connects to Subnet1. NSG1-VM1 is associated to the network interface of VM1. NSG Subnet1 is associated to Subnet1. You need to be able to establish Remote Desktop connections from the internet to VM1. Solution: You add an inbound security rule to NSG-Subnet1 that allows connections from the Internet source to the VirtualNetwork destination for port range 3389 and uses the UDP protocol. Does this meet the goal?

A. Yes 
B. No 


Sample Question 40

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure subscription that contains the following resources: A virtual network that has a subnet named Subnet1 Two network security groups (NSGs) named NSG-VM1 and NSG-Subnet1 A virtual machine named VM1 that has the required Windows Server configurations to allow Remote Desktop connections NSG-Subnet1 has the default inbound security rules only. NSG-VM1 has the default inbound security rules and the following custom inbound security rule: Priority: 100 Source: Any Source port range: * Destination: * Destination port range: 3389 Protocol: UDP Action: Allow VM1 connects to Subnet1. NSG1-VM1 is associated to the network interface of VM1. NSGSubnet1 is associated to Subnet1. You need to be able to establish Remote Desktop connections from the internet to VM1. Solution: You add an inbound security rule to NSG-Subnet1 that allows connections from the Any source to the VirtualNetwork destination for port range 3389 and uses the TCP protocol. You remove NSG-VM1 from the network interface of VM1. Does this meet the goal?

A. Yes 
B. No 


Sample Question 41

Your company has an Azure subscription named Subscription1. The company also has two on-premises servers named Server1 and Server2 that run Windows Server 2016. Server1 is configured as a DNS server that has a primary DNS zone named adatum.com. Adatum.com contains 1,000 DNS records. You manage Server1 and Subscription1 from Server2. Server2 has the following tools installed: The DNS Manager console Azure PowerShell Azure CLI 2.0 You need to move the adatum.com zone to Subscription1. The solution must minimize administrative effort What should you use?

A. Azure PowerShell 
B. Azure CLI 
C. the Azure portal 
D. the DNS Manager console 


Sample Question 42

You need to ensure that you can grant Group4 Azure RBAC read-only permissions to all the A2ure file shares. What should you do? 

A. On storagel and storage4, change the Account kind type to StorageV2 (general purpose v2). 
B. Recreate storage2 and set Hierarchical namespace to Enabled. 
C. On storage2, enable identity-based access for the file shares. 
D. Create a shared access signature (SAS) for storagel, storage2, and storage4. 


Sample Question 43

You have a Microsoft 365 tenant and an Azure Active Directory (Azure AD) tenant named contoso.com. You plan to grant three users named User1, User2, and User3 access to a temporary Microsoft SharePoint document library named Library1. You need to create groups for the users. The solution must ensure that the groups are deleted automatically after 180 days. Which two groups should you create? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point. 

A. a Security group that uses the Assigned membership type 
B. an Office 365 group that uses the Assigned membership type 
C. an Office 365 group that uses the Dynamic User membership type 
D. a Security group that uses the Dynamic User membership type 
E. a Security group that uses the Dynamic Device membership type 


Sample Question 44

You create an App Service plan named plan1 and an Azure web app named webapp1. You discover that the option to create a staging slot is unavailable. You need to create a staging slot for plan1. What should you do first?

A. From webapp1, modify the Application settings.
 B. From webapp1, add a custom domain. 
C. From plan1, scale up the App Service plan. 
D. From plan1, scale out the App Service plan. 


Sample Question 45

You have an Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com. The User administrator role is assigned to a user named Admin1. An external partner has a Microsoft account that uses the [email protected] sign in. Admin1 attempts to invite the external partner to sign in to the Azure AD tenant and receives the following error message: “Unable to invite user [email protected] – Generic authorization exception.” You need to ensure that Admin1 can invite the external partner to sign in to the Azure AD tenant. What should you do?

A. From the Roles and administrators blade, assign the Security administrator role to Admin1. 
B. From the Organizational relationships blade, add an identity provider. 
C. From the Custom domain names blade, add a custom domain. 
D. From the Users settings blade, modify the External collaboration settings. 


Sample Question 46

You have an Azure subscription. Users access the resources in the subscription from either home or from customer sites. From home, users must establish a point-to-site VPN to access the Azure resources. The users on the customer sites access the Azure resources by using site-to-site VPNs. You have a line-of-business app named App1 that runs on several Azure virtual machine. The virtual machines run Windows Server 2016. You need to ensure that the connections to App1 are spread across all the virtual machines. What are two possible Azure services that you can use? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

A. a public load balancer 
B. Traffic Manager 
C. an Azure Content Delivery Network (CDN) 
D. an internal load balancer 
E. an Azure Application Gateway 


Sample Question 47

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure Active Directory (Azure AD) tenant named Adatum and an Azure Subscription named Subscription1. Adatum contains a group named Developers. Subscription1 contains a resource group named Dev. You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group. Solution: On Dev, you assign the Logic App Contributor role to the Developers group. Does this meet the goal?

A. Yes 
B. No 


Sample Question 48

You have an Azure subscription that contains a user account named User1. You need to ensure that User1 can assign a policy to the tenant root management group. What should you do?

A. Assign the Owner role to User1, and then instruct User1 to configure access management for Azure resources.
 B. Assign the Global administrator role to User1, and then instruct User1 to configure access management for Azure resources. 
C. Assign the Global administrator role to User1, and then modify the default conditional access policies. 
D. Assign the Owner role to User1, and then modify the default conditional access policies. 


Sample Question 49

You have two Azure virtual machines named VM1 and VM2. You have two Recovery Services vaults named RSV1 and RSV2. VM2 is protected by RSV1. You need to use RSV2 to protect VM2. What should you do first?

A. From the RSV1 blade, click Backup items and stop the VM2 backup. 
B. From the RSV1 blade, click Backup Jobs and export the VM2 backup. 
C. From the RSV1 blade, click Backup. From the Backup blade, select the backup for the virtual machine, and then click Backup. 
D. From the VM2 blade, click Disaster recovery, click Replication settings, and then select RSV2 as the Recovery Services vault. 


Sample Question 50

You need to identify which storage account to use for the flow logging of IP traffic from VM5. The solution must meet the retention requirements. Which storage account should you identify?

A. storage4 
B. storage1
 C. storage2 
D. storage3 


Sample Question 51

You have an Azure subscription named Subscription1. You have 5 TB of data that you need to transfer to Subscription1. You plan to use an Azure Import/Export job. What can you use as the destination of the imported data?

A. Azure Data Lake Store 
B. a virtual machine 
C. the Azure File Sync Storage Sync Service 
D. Azure Blob storage 



Exam Code: AZ-104
Exam Name: Microsoft Azure Administrator
Last Update: May 07, 2024
Questions: 320