Font size
WorksheetsAz-900 Prep 2
Total questions: 50
Worksheet time: 3hrs 30mins
An IT Engineer needs to create a Virtual Machine in Azure. Currently, the IT Engineer has a Windows desktop along with the Azure Command Line Interface (CLI). Which of the following would allow the IT Engineer to use the CLI? Choose 2 answers from the options given below.
Powershell
File and Print Explorer
Command Prompt
Control Panel
A company is planning on creating several Azure Free Accounts. Can a customer have an allowance of a maximum of 10 Azure Free Accounts?
Yes
No
Your company is planning on hosting resources in Azure. Can an administrator give access to partners who do not have an Azure AD account to access resources in Azure?
Yes
No
A company is planning on purchasing Azure AD Premium for their Azure account. Does the Azure AD Premium tier come with an SLA of 99.9%?
Yes
No
A company wants to try out some services which are being offered by Azure in Public Preview. Should the company deploy resources which are part of Public Preview in their production environment?
Yes
No
A company is planning on using Azure Synapse Analytics for hosting their sales historical data. Which of the following is a feature of the Azure SQL Data warehouse architecture?`
High Availability
Scalability
Disaster Recovery
Visualization
A company is planning on creating several SQL Databases in Azure. They will be using the Azure SQL Database service. Which of the following is the right category to which the Azure SQL Database service belongs to?
IaaS
PaaS
SaaS
FaaS
A company is planning on using Azure Storage Accounts. They have the following requirement. 1. Storage of 2TB of data 2. Storage of a million files. Would using Azure Storage fulfil these requirements?
Yes
No
A company is planning on using Azure Storage Accounts. They have the following requirement. 1. Option in Azure portal to automatically replicate data to another region. Can Azure storage account atomically replicate data to another region?
Yes
No
A company wants to make use of Azure for the deployment of various solutions. They want to ensure that suspicious attacks and threats to resources in their Azure account are prevented. Which of the following helps prevent such attacks by using built-in sensors in Azure?
Azure AD Identity Protection
Azure DDoS attacks
Azure Privileged Identity Management
Azure Advances Threat Protection
A company deploys an Azure virtual machine in the North Central region. The company adds the VM and its resource group in the same region. As part of a reorganization, the company needs to move the VM and its data to a different region. This must be accomplished with as little downtime as possible. Solution: The company configures site recovery with another region in the same geographic cluster. Does this solution meet the goal?
Yes
No
A company deploys an Azure virtual machine in the North Central region. The company adds the VM and its resource group in the same region. As part of a reorganization, the company needs to move the VM and its data to a different region. This must be accomplished with as little downtime as possible. Solution: The company moves the VM to a different resource group located in a different region. Does this solution meet the goal?
Yes
No
A company deploys an Azure virtual machine in the North Central region. The company adds the VM and its resource group in the same region. As part of a reorganization, the company needs to move the VM and its data to a different region. This must be accomplished with as little downtime as possible. Solution: The company backs up the VM, deletes the original VM, and recreates the VM in a different region. Does this solution meet the goal?
Yes
No
Your Azure deployment is configured with a virtual network (VNet) consisting of multiple subnets. All outgoing traffic from Azure to your on-prim network should be routed through a specific Azure Firewall. The Firewall is pre-configured on your network. You need to reconfigure network traffic controls to meet this requirement. Solution: Create a Network Security Group (NSG), configure filter parameters, apply the NSG to each subnet in the virtual network (VNet). Does this solution meet the goal?
Yes
No
Your Azure deployment is configured with a virtual network (VNet) consisting of multiple subnets. All outgoing traffic from Azure to your on-prim network should be routed through a specific Azure Firewall. The Firewall is pre-configured on your network. You need to reconfigure network traffic controls to meet this requirement. Solution: Create an Application Security Group, define security rules, and add all VM network adapters to the security group. Does this solution meet the goal?
Yes
No
Your Azure deployment is configured with a virtual network (VNet) consisting of multiple subnets. All outgoing traffic from Azure to your on-prim network should be routed through a specific Azure Firewall. The Firewall is pre-configured on your network. You need to reconfigure network traffic controls to meet this requirement. Solution: Configure user-defined routes (UDRs) as a custom routing table and apply the custom routing table to each subnet in the virtual network (VNet). Does this solution meet the goal?
Yes
No
You need to understand Azure monitoring options. Which monitoring feature should you use for the following scenario? You want to allow developers to send telemetry data to Azure
Alerts
Application Insights
Resource Health
Metrics
You need to understand Azure monitoring options. Which monitoring feature should you use for the following scenario? You want to receive an email whenever the number of request to a web app exceed 10000 within an hour.
Alerts
Application Insights
Resource Health
Metrics
You need to understand Azure monitoring options. Which monitoring feature should you use for the following scenario? You want to view the number of virtual machines (VMs) that are currently down.
Alerts
Application Insights
Resource Health
Metrics
What is the purpose of the Load Balancer resource?
It adds or removes virtual machine (VM) instances as demand increases
It uses URL-based routing to route web traffic across multiple instances
It distributes virtual machine (VM) traffic evenly across multiple instances
It delivers Internet traffic to the datacenter that is geographically closest to the user
You can transfer an existing subscription to a new Azure Active Directory tenant.
Yes
No
Quotas for resources in Azure Resource Groups are per region rather than per subscription.
Yes
No
A user can be given access to only one subscription and resources can belong to only one subscription.
Yes
No
A company wants to expand its cloud presence by deploying additional resources to Azure. The company plans to use templates based on existing resources to automate the deployment process. Ensuring consistent deployment is critical. Which should the company use?
Azure Resource Manager
Azure Security Center
Azure Resource Groups
Azure Monitor
What is the advantage of moving your company's infrastructure to Azure by using a public cloud deployment model?
There are no operational expenditure (OpEx) cost
The company has complete control of resources that are used by the operation system
The company is able to scale up as needed with no capital expenditure (CapEx) required
Legacy applications are easier to support
You are planning to use Azure Advanced Threat Protection (ATP). You want to be notified of an attacker stealing the Kerberos data of an authenticated user on one computer to access other computers. Which alert should you monitor?
Honeytoken activity
Suspected identity theft (pass-the-ticket)
User and group membership reconnaissance (SAMR)
You are planning to use Azure Advanced Threat Protection (ATP). You wanted to be notified of an attacker stealing the NTLM data of an authenticated user on one computer to access other computers Which alert should you monitor?
Suspected brute force attack
Suspected identity theft (pass-the-hash)
You are planning to use Azure Advanced Threat Protection (ATP). You want to be notified of multiple attempts to guess a user's password. Which alert should you monitor?
Suspected brute force attack
Suspected identity theft (pass-the-hash)
Your company is planning to build a solution for an automobile manufacturing company. The solution should allow vehicles to send on-board diagnostic (OBD) sensory and vehicle telemetry data to the cloud for analysis. You need to be able to identify individual vehicles from the data that is sent. What would be the most appropriate Azure solution?
IoT Hub
Event Hub
Notification Hub
IoT Central
Your Azure tenant includes an Azure Virtual Network (VNet) with several internet-facing web servers. The web servers experience attacks that exhaust server resources and make the servers unavailable to legitimate users. You determine that the attacks are being launched from multiple locations. You need to implement an Azure solution that: 1. Detects and automatically tries to mitigate attacks. 2. Generates alerts when an active attack is underway. What is the BEST option to implement your solution?
Azure Firewall
Azure DDoS Protection Standard
Azure Information Protection (AIP)
Azure Application Security Groups (ASG)
You deployed a web app and Cosmos DB instance to Azure. The web app stores and retrieves data from the Cosmos DB instance. The service level agreement (SLA) for the web app is 99.95 percent, while that of the Cosmos DB instance is 99.99 percent. The combined SLA is lower than each individual SLA.
True
False
You deployed a web app and Cosmos DB instance to Azure. The web app stores and retrieves data from the Cosmos DB instance. The service level agreement (SLA) for the web app is 99.95 percent, while that of the Cosmos DB instance is 99.99 percent. You can increase the composite SLA by having the web app access a fallback queue.
True
False
You deployed a web app and Cosmos DB instance to Azure. The web app stores and retrieves data from the Cosmos DB instance. The service level agreement (SLA) for the web app is 99.95 percent, while that of the Cosmos DB instance is 99.99 percent. The combined probability of failure is lower than each individual SLA value.
True
False
What is the purpose of a resource group?
It serves as a container for Azure resources like virtual machines (VMs) and web apps
It specifies the subscriptions that are allowed to create Azure resources
It is a collection of user and group accounts
It defines initiatives that allow you to control the type of resources that can be deployed
Which statement describes a benefit that is unique to Azure Government?
Azure Government provides a portal experience different than the one that is provided to nongovernment subscribers
Azure Government enforces the policies and initiatives for all the resources that are deployed to the government region
Compliance Manager automatically sends detailed information to auditors and regulators regarding the resources that are deployed in Azure Government
Resources in Azure Government are deployed to datacenters that are separate from nongovernment resources
A virtual machine scale set atomically creates and integrates Azure Load Balancer or Application Gateway.
True
False
A virtual machine scale set automates the distribution of virtual machine (VM) instances across Availability Sets, Availability Zones, and Regions.
True
False
A virtual machine scale set can rapidly create hundreds of identical VMs from a central configuration.
True
False
A company needs to deploy a Ubuntu Linux virtual machine (VM) to run a resource-intensive data analysis application. What is the appropriate cloud service model for each scenario?
IaaS
SaaS
PaaS
A company needs to make productivity applications available to employees, including those that work from home, on a pay-as-you-go basis. What is the appropriate cloud service model for each scenario?
IaaS
SaaS
PaaS
A company needs to develop a Web app designed to run on both computers and mobile devices and manage the application lifecycle. What is the appropriate cloud service model for each scenario?
IaaS
SaaS
PaaS
A company needs to transition an on-premises data center to the cloud with minimal impact on users. What is the appropriate cloud service model for each scenario?
IaaS
SaaS
PaaS
You are directed to determine Service Level Agreement (SLA) support for Azure services. You need to identify which Azure services have a financially-backed SLA. Which three Azure services have a financially-backed SLA? Each correct answer presents part of the solution.
Security Center Standard tier
Azure Advisor
Multi-factor authentication
Azure Policy
Azure DNS
Your company is considering using Azure DevTest Labs to help with new development activities. You need to identify the functionality provided through DevTest Labs. DevTest Labs can be used to quickly provision Windows and Linux virtual machines (VMs).
True
False
Your company is considering using Azure DevTest Labs to help with new development activities. You need to identify the functionality provided through DevTest Labs. DevTest Labs can provision environments based on Azure Resource Manager (ARM) templates and pre-configured bases.
True
False
Your company is considering using Azure DevTest Labs to help with new development activities. You need to identify the functionality provided through DevTest Labs. DevTest Labs includes tools to support monitoring, managing actionable alerts, and gaining insights from logs and telemetry.
True
False
Which statement best describes what a resource lock does to a virtual machine?
It prevents the VM from being deleted
It allows the VM to be deleted, but not modified
It forces the VM to be deleted within a specific time period
It forces the VM to be deleted immediately
Your company is deploying an application that relies on multiple Azure services. You need to determine the composite service level agreement (SLA) for the application. On what is the composite SLA based?
The product of the SLAs of each of the services used in the application
The value of the service SLA with the highest uptime guarantee
The value of the service SLA with the lowest uptime guarantee
A value negotiated with Microsoft Azure on a cuctom SLA contract
A private cloud requires...
the use of custom developed software
each tenant to access applications and data through a different URL
data to be stored in an on-premises datacenter
the infrastructure to be on a private network
Management groups let you organize multiple..
resources as a single management entity to facilitate easier management
resource groups as a single management entity to facilitate easier management
subscriptions as a single management entity to facilitate easier management
Azure Active Directory (Azure AD) tenants as a single management entity to facilitate easier management
