Font size
WorksheetsAZ-900 Questions 2
Total questions: 40
Worksheet time: 1hrs 18mins
Your company plans to move several servers to Azure.
The company's compliance policy states that a server named FinServer must be on a separate
network segment.You are evaluating which Azure services can be used to meet the compliance policy
requirements.
Which Azure solution should you recommend?
a resource group for FinServer and another resource group for all the other servers
a virtual network for FinServer and another virtual network for all the other servers
a VPN for FinServer and a virtual network gateway for each other server
one resource group for all the servers and a resource lock for FinServer
Your company plans to migrate all its network resources to Azure.
You need to start the planning process by exploring Azure.
What should you create first?
a subscription
a resource group
a virtual network
a management group
You have an on-premises application that sends email notifications automatically based on a rule.
You plan to migrate the application to Azure.
You need to recommend a serverless computing solution for the application.
What should you include in the recommendation?
a web app
a server image in Azure Marketplace
a logic app
an API app
You plan to deploy a website to Azure. The website will be accessed by users worldwide and will
host large video files.
You need to recommend which Azure feature must be used to provide the best video playback
experience.
What should you recommend?
an application gateway
an Azure ExpressRoute circuit
a content delivery network (CDN)
an Azure Traffic Manager profile
Your company plans to automate the deployment of servers to Azure.
Your manager is concerned that you may expose administrative credentials during the
deployment.
You need to recommend an Azure solution that encrypts the administrative credentials during the
deployment.
Azure Key Vault
Azure Information Protection
Azure Security Center
Azure Multi-Factor Authentication (MFA)
This question requires that you evaluate the underlined text to determine if it is correct.
After you create a virtual machine, you need to modify the network security group (NSG) to allow
connections from TCP port 8080.
Instructions: Review the underlined text. If it makes the statement correct, select "No change is
needed". If the statement is incorrect, select the answer choice that makes the statement correct.
No change is needed
virtual network gateway
virtual network
route table
Which Azure service should you use to store certificates?
Azure Security Center
an Azure Storage account
Azure Key Vault
Azure Information Protection
You have a resource group named RG1.
You plan to create virtual networks and app services in RG1.
You need to prevent the creation of virtual machines only in RG1.
What should you use?
a lock
an Azure role
a tag
an Azure policy
You plan to deploy several Azure virtual machines.
You need to control the ports that devices on the internet can use to access the virtual machines.
What should you use?
an Azure Active Directory (AzureAD) role
an Azure key vault
an Azure Active Directory group
a network security group (NSG)
An Azure administrator plans to run a PowerShell script that creates Azure resources.
You need to recommend which computer configuration to use to run the script.
Which three computers can run the script? Each correct answer presents a complete solution NOTE: Each correct
selection is worth one point.
a computer that runs macOS and has PowerShell Core 6.0 installed
a computer that runs Windows 10 and has the Azure PowerShell module installed
a computer that runs Chrome OS and uses Azure Cloud Shell
a computer that runs Linux and has the Azure CLI tools installed
Your Azure environment contains multiple Azure virtual machines. You need to ensure that a virtual machine named
VM1 is accessible from the Internet over HTTP.
What are two possible solutions? Each correct answer presents a complete solution.
Modify a DDoS protection plan.
Modify an Azure firewall.
Modify an Azure Traffic Manager profile.
Modify a network security group (NGS)
Your company has an Azure subscription that contains the following unused resources:
- 20 user accounts in Azure Active Directory (Azure AD)
- Five groups in Azure AD
- 10 public IP addresses
- 10 network interfaces
You need to reduce the Azure costs for the company.
Which unused resources should you remove?
the user accounts
the network interfaces
the public IP addresses
the groups
Which task can you perform by using Azure Advisor?
Integrate Active Directory and Azure Active Directory (Azure AD).
Estimate the costs of an Azure solution.
Confirm that Azure subscription security follows best practices.
Evaluate which on-premises resources can be migrated to Azure.
Your company uses management groups to manage resources in your Azure tenant more efficiently. User1 should be
able to assign access and assign policies to management groups. You need to determine to which role-based access
control (RBAC) role User1 should be added.
Your solution should follow the principle of least privilege. To which role should you add User1?
User Access Administrator
Owner
Management Group Contributor
Contributor
Which service provides serverless computing in Azure?
Azure Virtual Machines
Azure Functions
Azure storage account
Azure Container Instances
To complete the sentence, select the appropriate option in the answer area: _____ is the process of verifying a user's credentials.
Authorization
Authentication
Federation
Ticketing
To complete the sentence, select the appropriate option in the answer area: From _____ you can view which user turned off a specific virtual machine during the last 14 days.
Azure Control IAM
Azure Event Hubs
Azure Activity Log
Azure Service Health
To complete the sentence, select the appropriate option in the answer area: If a resource group named RG1 has a delete lock, _____ can delete RG1.
only a member of the global administrators group
the delete lock must be removed before an administrator
an Azure policy must be modified before an administrator
an Azure tag must be added before an administrator
To complete the sentence, select the appropriate option in the answer area: Your company implements _____ to automatically add a watermark to Microsoft Word documents that contain credit card information.
Azure policies
DDos protection
Azure Information Protection
Azure Active Directory (Azure AD) Identity Protection
Yes or No: From Azure Service Health, an administrator can view the health of all the services in an Azure environment.
Yes
No
Yes or No: From Azure Service Health, an administrator can create a rule to be alerted if an Azure service fails.
Yes
No
Yes or No: From Azure Service Health, an administrator can prevent a service failure.
Yes
No
To complete the sentence, select the appropriate option in the answer area: You have an Azure virtual network named VNET1 in a resource group named RG1. You assign the Azure Policy definition of Not Allowed Resource Type and specify that virtual networks are not an allowed resource type in RG1. VNET1_____.
is deleted automatically
is moved automatically to another resource group
continues to function normally
is now a read-only object
Yes or No: An Azure subscription can have multiple account administrators.
Yes
No
Yes or No: An Azure subscription can be managed by using a Microsoft account only.
Yes
No
Yes or No: An Azure resource group can contain multiple Azure subscriptions.
Yes
No
Yes or No: Azure Active Directory Premium P2 guarantees at least 99.9% availability.
Yes
No
Yes or No: The Service Level Agreement (SLA) for Azure Active Directory Premium P2 is the same as the SLA for Azure Active Directory Free.
Yes
No
Yes or No: All paying Azure customers receive a credit if their monthly uptime % is below the guaranteed amount in the Service Level Agreement (SLA).
Yes
No
To complete the sentence, select the appropriate option in the answer area: You deploy an Azure resource. The resource becomes unavailable for an extended period due to a service outage. Microsoft will _____.
refund your bank account
migrate the resources to another subscription
credit your Azure account
send you a coupon code that you can redeem for Azure credits
Yes or No: Adding resource groups in an Azure subscription generates additional costs.
Yes
No
Yes or No: Copying 10 GB of data to Azure from an on-premises network over a VPN generates additional Azure data transfer costs.
Yes
No
Yes or No: Copying 10 GB of data from Azure to an on-premises network over a VPN generates additional Azure data transfer costs.
Yes
No
You have several virtual machines in an Azure subscription. You create a new subscription. Which of the following is true?
The virtual machines cannot be moved to the new subscription.
The virtual machines can be moved to the new subscription.
The virtual machines can be moved to the new subscription only if they are all in the same resource group.
The virtual machines can be moved to the new subscription only if they run Windows Server 2016.
To complete the sentence, select the appropriate option in the answer area: You can enable just in time (JIT) VM access by using _____.
Azure Bastion
Azure Firewall
Azure Front Door
Azure Security Center
You plan to create an Azure virtual machine.
You need to identify which storage service must be used to store the data disks of the virtual machine.
What should you identify? To answer, select the appropriate service in the answer area.
Containers - (Scalable, cost-effective storage for unstructured data)
File Shares - (Serverless SMB file shares)
Tables - (Tabular Data Storage)
Queues - (Effectively scale apps according to traffic)
Yes or No: All the Azure resources deployed to a resource group must use the same Azure region.
Yes.
No.
Yes or No: If you assign a tag to a resource group, all the Azure resources in that resource group are assigned to the same tag.
Yes.
No.
Yes or No: If you assign permissions for a user to manage a resource group, the user can manage all the Azure resources in that resource group.
Yes.
No.
To complete the sentence, select the appropriate option in the answer area: You plan to deploy 20 virtual machines to an Azure environment. To ensure that a virtual machine named VM1 cannot connect to the other virtual machines, VM1 must _____.
be deployed to a separate virtual network
run a different operating system than the other virtual machines
be deployed to a seperate resource group
have 2 network interfaces
