Font size
WorksheetsAzure 104 TOPIC 2 40-62
Total questions: 55
Worksheet time: 29mins
To add a health probe to LB2:
Contributor on LB2
Network Contributor on LB2
Network Contributor on RG1
Owner on LB2
From contoso.com, modify the Organization relationships settings.
From contoso.com, create an OAuth 2.0 authorization endpoint.
Recreate AKS1.
From AKS1, create a namespace.
Microsoft 365 group that uses the Assigned membership type
Security group that uses the Assigned membership type
Microsoft 365 group that uses the Dynamic User membership type
Security group that uses the Dynamic User membership type
Security group that uses the Dynamic Device membership type
You are prevented from creating Azure SQL servers anywhere in Subscription 1.
You can create Azure SQL servers in ContosoRG1 only.
You are prevented from creating Azure SQL Servers in ContosoRG1 only.
. You can create Azure SQL servers in any resource group within Subscription 1.
VNET 1:
none
Department:
D1 only
Department:
D1, and RGroup: RG6 only
Department:
D1, and Label: Value1 only
Department:
D1, RGroup: RG6, and Label:
Value1
VNET2:
none
RGroup:
RG6 only
Label:
Value1 only
RGroup:
RG6, and Label:
Value1
VM1, STORAGE1, VNET1, AND VM1MANAGED ONLY
VM1 AND VM1MANAGED ONLY
VM1, STORAGE1, VNET1, VM1MANAGED, AND RVAULT1
RVAULT1 ONLY
From Azure PowerShell, run the Set-AzApiManagementSubscription cmdlet
From the Azure portal, register the Microsoft.Marketplace resource provider
From Azure PowerShell, run the Set-AzMarketplaceTerms cmdlet
From the Azure portal, assign the Billing administrator role to Admin1
From the Licenses blade, assign a new license
. From the Directory role blade, modify the directory role
From the Groups blade, invite the user account to a new group
You have an Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com that contains 100 user accounts.You purchase 10 Azure AD Premium P2 licenses for the tenant.You need to ensure that 10 users can use all the Azure AD Premium features.What should you do?
From the Licenses blade of Azure AD, assign a license
From the Groups blade of each user, invite the users to a group
From the Azure AD domain, add an enterprise application
From the Directory role blade of each user, modify the directory role
You have an Azure subscription named Subscription1 and an on-premises deployment of Microsoft System Center Service Manager.Subscription1 contains a virtual machine named VM1.You need to ensure that an alert is set in Service Manager when the amount of available memory on VM1 is below 10 percent.What should you do first?
CREATE AN AUTOMATION RUNBOOK
DEPLOY A FUNCTION APP
DEPLOY THE IT SERVICE MANAGEMENT CONNECTOR (ITSM)
CREATE A NOTIFICATION
You sign up for Azure Active Directory (Azure AD) Premium.You need to add a user named admin1@contoso.com as an administrator on all the computers that will be joined to the Azure AD domain.What should you configure in Azure AD?
Device settings from the Devices blade
Providers from the MFA Server blade
User settings from the Users blade
General settings from the Groups blade
USER1 CAN ADD DEVICE2 TO GROUP1
YES
NO
USER2 CAN ADD DEVICE1 TO GROUP1
YES
NO
USER2 CAN ADD DEVICE2 TO GROUP2
YES
NO
DELETE VM1
STOP VM1
STOP THE BACKUP OF SQLDB01
DELETE sa001
. Remove User1 from the Security Reader and Reader roles for Subscription1.
Assign User1 the User Access Administrator role for VNet1.
Assign User1 the Network Contributor role for VNet1.
Assign User1 the Network Contributor role for RG1.
You have an Azure Active Directory (Azure AD) tenant named contosocloud.onmicrosoft.com.Your company has a public DNS zone for contoso.com.You add contoso.com as a custom domain name to Azure AD.You need to ensure that Azure can verify the domain name.Which type of DNS record should you create?
MX
NSEC
PTR
RRSIG
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Azure Directory (Azure AD) tenant named Adatum and an Azure Subscription named Subscription1. Adatum contains a group named Developers.Subscription1 contains a resource group named Dev.You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group.Solution: On Subscription1, you assign the DevTest Labs User role to the Developers group.Does this meet the goal?
YES
NO
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Azure Directory (Azure AD) tenant named Adatum and an Azure Subscription named Subscription1. Adatum contains a group named Developers.Subscription1 contains a resource group named Dev.You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group.Solution: On Subscription1, you assign the Logic App Operator role to the Developers group.Does this meet the goal?
YES
NO
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Azure Directory (Azure AD) tenant named Adatum and an Azure Subscription named Subscription1. Adatum contains a group named Developers.Subscription1 contains a resource group named Dev.You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group.Solution: On Dev, you assign the Contributor role to the Developers group.Does this meet the goal?
YES
NO
ASSIGN A TAG TO EACH RESOURCE GROUP
ASSIGN A TAG TO EACH RESOURCE
DOWNLOAD THE USAGE REPORT
FROM THE COST ANALYSIS BLADE, FILTER THE VIEW BY TAG
OPEN THE RESOURCE COSTS BLADE OF EACH RESOURCE GROUP
You have an Azure subscription named Subscription1 that contains an Azure Log Analytics workspace named Workspace1.You need to view the error events from a table named Event.Which query should you run in Workspace1?
Get-Event Event | where {$_.EventType == "error"}
search in (Event) "error"
select * from Event where EventType == "error"
search in (Event) * | where EventType -eq "error"
VM1 AND VM2 CAN CONNECT TO VNET1
YES
NO
IF AN AZURE DATACENTER BECOMES UNAVAILABLE, VM1 OR VM2 WILL BE AVAILABLE
YES
NO
IF THE EAST US 2 REGION BECOMES UNAVAILABLE, VM1 OR VM2 WILL BE AVAILABLE
YES
NO
The App Service plan for WebApp1 remains in West Europe. Policy2 applies to WebApp1.
The App Service plan for WebApp1 moves to North Europe. Policy2 applies to WebApp1.
The App Service plan for WebApp1 remains in West Europe. Policy1 applies to WebApp1.
The App Service plan for WebApp1 moves to North Europe. Policy1 applies to WebApp1.
DROP DOWN 1
DROP DOWN 2
CHOOSE TWO ANSWERS:
"/"
"/SUBSCRIPTIONS/C276FC76-9CD4-44C9-99A7-4FD71546436E"
"/SUBSCRIPTIONS/C276FC76-9CD4-44C9-99A7-4FD71546436E/RESOURCEGROUPS"
"MICROSOFT.AUTHORIZATION/*"
"MICROSOFT.RESOURCES/*"
You have an Azure subscription.Users access the resources in the subscription from either home or from customer sites. From home, users must establish a point-to-site VPN to access the Azure resources. The users on the customer sites access the Azure resources by using site-to-site VPNs.You have a line-of-business-app named App1 that runs on several Azure virtual machine. The virtual machines run Windows Server 2016.You need to ensure that the connections to App1 are spread across all the virtual machines.What are two possible Azure services that you can use? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point.
AN INTERNAL LOAD BALANCER
A PUBLIC LOAD BALANCER
AN AZURE CONTENT DELIVERY NETWORK (CDN)
TRAFFIC MANAGER
AN AZURE APPLICATION GATEWAY
You have an Azure subscription.You have 100 Azure virtual machines.You need to quickly identify underutilized virtual machines that can have their service tier changed to a less expensive offering.Which blade should you use?
MONITOR
ADVISOR
METRICS
CUSTOMER INSIGHTS
USER AND GROUPS
CLOUD APPS
CONDITIONS
GRANT
SESSION
You have an Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com.The User administrator role is assigned to a user named Admin1.An external partner has a Microsoft account that uses the user1@outlook.com sign in.Admin1 attempts to invite the external partner to sign in to the Azure AD tenant and receives the following error message: ג€Unable to invite user user1@outlook.com ג€" Generic authorization exception.ג€You need to ensure that Admin1 can invite the external partner to sign in to the Azure AD tenant.What should you do?
From the Users blade, modify the External collaboration settings.
From the Custom domain names blade, add a custom domain.
From the Organizational relationships blade, add an identity provider.
From the Roles and administrators blade, assign the Security administrator role to Admin1.
Reveal Solution Discussion 29
You have an Azure subscription linked to an Azure Active Directory tenant. The tenant includes a user account named User1.You need to ensure that User1 can assign a policy to the tenant root management group.What should you do?
Assign the Owner role for the Azure Subscription to User1, and then modify the default conditional access policies.
Assign the Owner role for the Azure subscription to User1, and then instruct User1 to configure access management for Azure resources.
Assign the Global administrator role to User1, and then instruct User1 to configure access management for Azure resources.
Create a new management group and delegate User1 as the owner of the new management group.
Reveal Solution
USER1:
GROUP1 ONLY
GROUP2 ONLY
GROUP3 ONLY
GROUP1 AND GROUP2 ONLY
GROUP1, GROUP2, GROUP3
USER2:
GROUP1 ONLY
GROUP2 ONLY
GROUP3 ONLY
GROUP1 AND GROUP2 ONLY
GROUP1 AND GROUP3 ONLY
JOBTITLE:
USER1 ONLY
USER1 AND USER2 ONLY
USER1 AND USER3 ONLY
USER1, USER2, AND USER3
USAGELOCATION:
USER1 ONLY
USER1 AND USER2 ONLY
USER1 AND USER3 ONLY
USER1, USER2, AND USER3
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You need to ensure that an Azure Active Directory (Azure AD) user named Admin1 is assigned the required role to enable Traffic Analytics for an Azure subscription.Solution: You assign the Network Contributor role at the subscription level to Admin1.Does this meet the goal?
YES
NO
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You need to ensure that an Azure Active Directory (Azure AD) user named Admin1 is assigned the required role to enable Traffic Analytics for an Azure subscription.Solution: You assign the Owner role at the subscription level to Admin1.Does this meet the goal?
YES
NO
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You need to ensure that an Azure Active Directory (Azure AD) user named Admin1 is assigned the required role to enable Traffic Analytics for an Azure subscription.Solution: You assign the Reader role at the subscription level to Admin1.Does this meet the goal?
YES
NO
You have an Azure subscription that contains a user named User1.You need to ensure that User1 can deploy virtual machines and manage virtual networks. The solution must use the principle of least privilege.Which role-based access control (RBAC) role should you assign to User1?
OWNER
VIRTUAL MACHINE
CONTRIBUTOR
VIRTUAL MACHINE ADMINISTRATOR LOGIN
You have an Azure subscription named Subscription1 that contains an Azure virtual machine named VM1. VM1 is in a resource group named RG1.VM1 runs services that will be used to deploy resources to RG1.You need to ensure that a service running on VM1 can manage the resources in RG1 by using the identity of VM1.What should you do first?
From the Azure portal, modify the Managed Identity settings of VM1
From the Azure portal, modify the Access control (IAM) settings of RG1
From the Azure portal, modify the Access control (IAM) settings of VM1
From the Azure portal, modify the Policies settings of RG1
Reveal Solution Discussion 27
Modify the backup configurations of VM1 and modify the resource lock type of VNET1
Remove the resource lock from VNET1 and delete all data in Vault1
Turn off VM1 and remove the resource lock from VNET1
Turn off VM1 and delete all data in Vault1
You have an Azure DNS zone named adatum.com.You need to delegate a subdomain named research.adatum.com to a different DNS server in Azure.What should you do?
Create an NS record named research in the adatum.com zone.
Create a PTR record named research in the adatum.com zone.
Modify the SOA record of adatum.com.
Create an A record named *.research in the adatum.com zone.
ADD A RECORD TO THE PUBLIC CONTOSO.COM DNS ZONE
ADD AN AZURE AD TENANT
CONFIGURE COMPANY BRANDING
ADD A CUSTOM NAME
VERIFY THE DOMAIN
You have an Azure subscription named Subscription1 that contains an Azure Log Analytics workspace named Workspace1.You need to view the error events from a table named Event.Which query should you run in Workspace1?
Get-Event Event | where {$_.EventType == "error"}
Event | search "error"
select * from Event where EventType == "error"
Event | where EventType is "error"
You have a registered DNS domain named contoso.com.You create a public Azure DNS zone named contoso.com.You need to ensure that records created in the contoso.com zone are resolvable from the internet.What should you do?
Create NS records in contoso.com.
Modify the SOA record in the DNS domain registrar.
Create the SOA record in contoso.com.
Modify the NS records in the DNS domain registrar.
YOU CAN ASSIGN THE STORAGE FILE DATA SMB SHARE CONTRIBUTOR ROLE TO USER1 FOR SHARE1
YES
NO
YOU CAN ASSIGN THE STORAGE FILE DATA SMB SHARE READER ROLE TO COMPUTER1 FOR SHARE1
YES
NO
YOU CAN ASSIGN THE STORAGE FILE DATA SMB SHARE ELEVATED CONTRIBUTOR ROLE TO USER2 FOR SHARE1
YES
NO
ADD A SUBNET TO VNET1:
USER1 ONLY
USER3 ONLY
USER1 AND USER3 ONLY
USER2 AND USER3 ONLY
USER1, USER2, AND USER3
ASSIGN A USER THE READER ROLE TO VNET1:
USER1 ONLY
USER2 ONLY
USER3 ONLY
USER1 AND USER2 ONLY
USER2 AND USER3 ONLY
LOCKS:
RG1 AND VM1 ONLY
SUB1 AND RG1 ONLY
SUB1, RG1, AND VM1 ONLY
MG1, SUB1, RG1, AND VM1 ONLY
TENANT ROOT GROUP, MG1, SUB1, RG1, AND VM1
TAGS:
RG1 AND VM1 ONLY
SUB1 AND RG1 ONLY
SUB1, RG1, AND VM1 ONLY
MG1, SUB1, RG1, AND VM1 ONLY
TENANT ROOT GROUP, MG1, SUB1, RG1, AND VM1
To add a backend pool to LB1:
Contributor on LB1
Network Contributor on LB1
Network Contributor on RG1
Owner on LB1
