0% found this document useful (0 votes)
103 views1 page

Expert Veri Ed, Online, Free.: Microsoft AZ-104 Exam Actual Questions

This document provides a summary of questions from the Microsoft AZ-104 exam, including multiple choice and hotspot questions about Azure roles, policies, and access management. It begins with an introduction to ExamTopics and a notice about an upcoming sale. The questions cover topics like assigning roles for load balancer management, configuring access to an AKS cluster, setting expiration policies for Azure Active Directory groups, reviewing access using access reviews, applying policies at different scopes in Azure, and how tags are applied from resource group policies.

Uploaded by

adipt1660
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
103 views1 page

Expert Veri Ed, Online, Free.: Microsoft AZ-104 Exam Actual Questions

This document provides a summary of questions from the Microsoft AZ-104 exam, including multiple choice and hotspot questions about Azure roles, policies, and access management. It begins with an introduction to ExamTopics and a notice about an upcoming sale. The questions cover topics like assigning roles for load balancer management, configuring access to an AKS cluster, setting expiration policies for Azure Active Directory groups, reviewing access using access reviews, applying policies at different scopes in Azure, and how tags are applied from resource group policies.

Uploaded by

adipt1660
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 1

 Welcome to ExamTopics  adipt_60 | Logout     

HOME UNLIMITED ACCESS POPULAR EXAMS VIEW ALL EXAMS DOWNLOAD FREE CONTACT FORUM 
MAIL US
- Expert Veri ed, Online, Free.  [email protected]

* Autumn Sale *
We hope you're enjoying a well-deserved weekend and holiday.
We're offering a special promotion of limited time 20% off on annual contributor access.
Use coupon code SALE2023 to apply during checkout .
* Offer will expire at midnight November 17th 2023

To get full access and more features, please consider getting Contributor Access.

Microsoft AZ-104 Exam Actual Questions (P. 5)

The questions for AZ-104 were last updated on Nov. 13, 2023.

Viewing page 5 out of 56 pages.


Viewing questions 41-50 out of 567 questions

 Custom View Settings



Topic 2 - Question Set 2

Question #1 Topic 2

HOTSPOT -
You have an Azure subscription named Subscription1 that contains a resource group named RG1.
In RG1, you create an internal load balancer named LB1 and a public load balancer named LB2.
You need to ensure that an administrator named Admin1 can manage LB1 and LB2. The solution must follow the principle of least privilege.
Which role should you assign to Admin1 for each task? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Hide Solution  Discussion 111

Correct Answer:

The Network Contributor role lets you manage networks, but not access them.
Reference:
https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles

Question #2 Topic 2

You have an Azure subscription that contains an Azure Active Directory (Azure AD) tenant named contoso.com and an Azure Kubernetes Service (AKS) cluster named
AKS1.
An administrator reports that she is unable to grant access to AKS1 to the users in contoso.com.
You need to ensure that access to AKS1 can be granted to the contoso.com users.
What should you do rst?

A. From contoso.com, modify the Organization relationships settings.

B. From contoso.com, create an OAuth 2.0 authorization endpoint. Most Voted

C. Recreate AKS1.

D. From AKS1, create a namespace.

Hide Solution  Discussion 40

Correct Answer: B 🗳
Reference:
https://kubernetes.io/docs/reference/access-authn-authz/authentication/

Community vote distribution


B (92%) 7%

Question #3 Topic 2

You have a Microsoft 365 tenant and an Azure Active Directory (Azure AD) tenant named contoso.com.
You plan to grant three users named User1, User2, and User3 access to a temporary Microsoft SharePoint document library named Library1.
You need to create groups for the users. The solution must ensure that the groups are deleted automatically after 180 days.
Which two groups should you create? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

A. a Microsoft 365 group that uses the Assigned membership type Most Voted

B. a Security group that uses the Assigned membership type

C. a Microsoft 365 group that uses the Dynamic User membership type Most Voted

D. a Security group that uses the Dynamic User membership type

E. a Security group that uses the Dynamic Device membership type

Hide Solution  Discussion 66

Correct Answer: AC 🗳
You can set expiration policy only for O ce 365 groups in Azure Active Directory (Azure AD).
Note: With the increase in usage of O ce 365 Groups, administrators and users need a way to clean up unused groups. Expiration policies can help remove inactive
groups from the system and make things cleaner.
When a group expires, all of its associated services (the mailbox, Planner, SharePoint site, etc.) are also deleted.
You can set up a rule for dynamic membership on security groups or O ce 365 groups.
Incorrect Answers:
B, D, E: You can set expiration policy only for O ce 365 groups in Azure Active Directory (Azure AD).
Reference:
https://docs.microsoft.com/en-us/o ce365/admin/create-groups/o ce-365-groups-expiration-policy?view=o365-worldwide

Community vote distribution


AC (93%) 7%

Question #4 Topic 2

HOTSPOT -
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table:

User3 is the owner of Group1.


Group2 is a member of Group1.
You con gure an access review named Review1 as shown in the following exhibit:

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Hide Solution  Discussion 92

Correct Answer:

Reference:
https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review

Question #5 Topic 2

HOTSPOT -
You have the Azure management groups shown in the following table:

You add Azure subscriptions to the management groups as shown in the following table:

You create the Azure policies shown in the following table:

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Hide Solution  Discussion 207

Correct Answer:

Box 1: No -
Virtual networks are not allowed at the root and is inherited. Deny overrides allowed.

Box 2: Yes -
Virtual Machines can be created on a Management Group provided the user has the required RBAC permissions.

Box 3: Yes -
Subscriptions can be moved between Management Groups provided the user has the required RBAC permissions.
Reference:
https://docs.microsoft.com/en-us/azure/governance/management-groups/overview https://docs.microsoft.com/en-us/azure/governance/management-
groups/manage#moving-management-groups-and-subscriptions

Question #6 Topic 2

You have an Azure policy as shown in the following exhibit:

What is the effect of the policy?

A. You are prevented from creating Azure SQL servers anywhere in Subscription 1.

B. You can create Azure SQL servers in ContosoRG1 only. Most Voted

C. You are prevented from creating Azure SQL Servers in ContosoRG1 only.

D. You can create Azure SQL servers in any resource group within Subscription 1.

Hide Solution  Discussion 91

Correct Answer: B 🗳
You are prevented from creating Azure SQL servers anywhere in Subscription 1 with the exception of ContosoRG1

Community vote distribution


B (100%)

Question #7 Topic 2

HOTSPOT -
You have an Azure subscription that contains the resources shown in the following table:

You assign a policy to RG6 as shown in the following table:

To RG6, you apply the tag: RGroup: RG6.


You deploy a virtual network named VNET2 to RG6.
Which tags apply to VNET1 and VNET2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Hide Solution  Discussion 111

Correct Answer:

VNET1: Department: D1, and Label:Value1 only.


Tags applied to the resource group or subscription are not inherited by the resources.
Note: Azure Policy allows you to use either built-in or custom-de ned policy de nitions and assign them to either a speci c resource group or across a whole
Azure subscription.
VNET2: Label:Value1 only.
Incorrect Answers:

RGROUP: RG6 -
Tags applied to the resource group or subscription are not inherited by the resources.
Reference:
https://docs.microsoft.com/en-us/azure/azure-resource-manager/management/tag-policies

Question #8 Topic 2

You have an Azure subscription named AZPT1 that contains the resources shown in the following table:

You create a new Azure subscription named AZPT2.


You need to identify which resources can be moved to AZPT2.
Which resources should you identify?

A. VM1, storage1, VNET1, and VM1Managed only

B. VM1 and VM1Managed only

C. VM1, storage1, VNET1, VM1Managed, and RVAULT1 Most Voted

D. RVAULT1 only

Hide Solution  Discussion 80

Correct Answer: C 🗳
You can move a VM and its associated resources to a different subscription by using the Azure portal.
You can now move an Azure Recovery Service (ASR) Vault to either a new resource group within the current subscription or to a new subscription.
Reference:
https://docs.microsoft.com/en-us/azure/azure-resource-manager/management/move-resource-group-and-subscription

Community vote distribution


C (95%) 5%

Question #9 Topic 2

You recently created a new Azure subscription that contains a user named Admin1.
Admin1 attempts to deploy an Azure Marketplace resource by using an Azure Resource Manager template. Admin1 deploys the template by using Azure
PowerShell and receives the following error message: `User failed validation to purchase resources. Error message: `Legal terms have not been accepted for this item on
this subscription. To accept legal terms, please go to the Azure portal (http://go.microsoft.com/fwlink/?LinkId=534873) and con gure programmatic deployment for the
Marketplace item or create it there for the rst time.`
You need to ensure that Admin1 can deploy the Marketplace resource successfully.
What should you do?

A. From Azure PowerShell, run the Set-AzApiManagementSubscription cmdlet

B. From the Azure portal, register the Microsoft.Marketplace resource provider

C. From Azure PowerShell, run the Set-AzMarketplaceTerms cmdlet Most Voted

D. From the Azure portal, assign the Billing administrator role to Admin1

Hide Solution  Discussion 70

Correct Answer: C 🗳
Reference:
https://docs.microsoft.com/en-us/powershell/module/az.marketplaceordering/set-azmarketplaceterms?view=azps-4.1.0

Community vote distribution


C (100%)

Question #10 Topic 2

You have an Azure Active Directory (Azure AD) tenant that contains 5,000 user accounts.
You create a new user account named AdminUser1.
You need to assign the User administrator administrative role to AdminUser1.
What should you do from the user account properties?

A. From the Licenses blade, assign a new license

B. From the Directory role blade, modify the directory role Most Voted

C. From the Groups blade, invite the user account to a new group

Hide Solution  Discussion 68

Correct Answer: B 🗳
Assign a role to a user -
1. Sign in to the Azure portal with an account that's a global admin or privileged role admin for the directory.
2. Select Azure Active Directory, select Users, and then select a speci c user from the list.
3. For the selected user, select Directory role, select Add role, and then pick the appropriate admin roles from the Directory roles list, such as Conditional access
administrator.
4. Press Select to save.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-users-assign-role-azure-portal

Community vote distribution


B (100%)

 Previous Questions Next Questions 

 
Social Media Email Address
Facebook , Twitter [email protected]
YouTube , Reddit www.examtopics.com
Pinterest

RECENT ARTICLES SITEMAP

New Version GCP  Home  All Exams


We are the biggest and most updated IT Professional Cloud
13  News  About
certi cation exam material website. Architect Certi cate &
June Helpful Information  Contact  Forum

Using our own resources, we strive to IT Certi cations  DMCA  Logout


strengthen the IT professionals
 Terms & Privacy
community for free. The 5 Most In-
Policy
Demand Project
20
Management
September Certi cations of 2019
IT Certi cations

    

© 2023 ExamTopics
ExamTopics doesn't offer Real Microsoft Exam Questions. ExamTopics doesn't offer Real Amazon Exam Questions. ExamTopics Materials do not contain actual questions and answers
from Cisco's Certi cation Exams.
CFA Institute does not endorse, promote or warrant the accuracy or quality of ExamTopics. CFA® and Chartered Financial Analyst® are registered trademarks owned by CFA Institute.

You might also like