AZ-104 | Most Recent AZ-104 Preparation Exams 2020

We provide real AZ-104 exam questions and answers braindumps in two formats. Download PDF & Practice Tests. Pass Microsoft AZ-104 Exam quickly & easily. The AZ-104 PDF type is available for reading and printing. You can print more and practice many times. With the help of our Microsoft AZ-104 dumps pdf and vce product and material, you can easily pass the AZ-104 exam.

Check AZ-104 free dumps before getting the full version:

NEW QUESTION 1

You have an Azure subscription that contains the storage accounts shown in the following table.
AZ-104 dumps exhibit
You need to identify which storage account can be converted to zone-redundant storage (ZRS) replication by requesting a live migration from Azure support.
What should you identify?

  • A. Storage1
  • B. Storage2
  • C. Storage3
  • D. Storage4

Answer: B

Explanation:
ZRS currently supports standard general-purpose v2, FileStorage and BlockBlobStorage storage account types.

NEW QUESTION 2

You download an Azure Resource Manager template based on an existing virtual machine. The template will be used to deploy 100 virtual machines.
You need to modify the template to reference an administrative password. You must prevent the password from being stored in plain text.
What should you create to store the password?

  • A. Azure Active Directory (AD) Identity Protection and an Azure policy
  • B. a Recovery Services vault and a backup policy
  • C. an Azure Key Vault and an access policy
  • D. an Azure Storage account and an access policy

Answer: C

Explanation:
You can use a template that allows you to deploy a simple Windows VM by retrieving the password that is stored in a Key Vault. Therefore the password is never put in plain text in the template parameter file.
References: https://azure.microsoft.com/en-us/resources/templates/101-vm-secure-password/

NEW QUESTION 3

You manage two Azure subscriptions named Subscription1 and Subscription2. Subscription1 has the following virtual networks:
AZ-104 dumps exhibit
The virtual networks contain the following subnets:
AZ-104 dumps exhibit
Subscription2 contains the following virtual network:
AZ-104 dumps exhibit Name: VNETA
AZ-104 dumps exhibit Address space: 10.10.128.0/17
AZ-104 dumps exhibit Location: Canada Central
VNETA contains the following subnets:
AZ-104 dumps exhibit
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
AZ-104 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
Box 1: Yes
With VNet-to-VNet you can connect Virtual Networks in Azure across Different regions. Box 2: Yes
Azure supports the following types of peering:
Virtual network peering: Connect virtual networks within the same Azure region. Global virtual network peering: Connecting virtual networks across Azure regions. Box 3: No
The virtual networks you peer must have non-overlapping IP address spaces. References:
https://azure.microsoft.com/en-us/blog/vnet-to-vnet-connecting-virtual-networks-in-azure-across-different-regio https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-manage-peering#requirements-and-cons

NEW QUESTION 4

You need to resolve the Active Directory issue. What should you do?

  • A. From Active Directory Users and Computers, select the user accounts, and then modify the User Principal Name value.
  • B. Run idfix.exe, and then use the Edit action.
  • C. From Active Directory Domains and Trusts, modify the list of UPN suffixes.
  • D. From Azure AD Connect, modify the outbound synchronization rule.

Answer: B

Explanation:
IdFix is used to perform discovery and remediation of identity objects and their attributes in an on-premises Active Directory environment in preparation for migration to Azure Active Directory. IdFix is intended for the Active Directory administrators responsible for directory synchronization with Azure Active Directory.
Scenario: Active Directory Issue
Several users in humongousinsurance.com have UPNs that contain special characters. You suspect that some of the characters are unsupported in Azure AD.
References: https://www.microsoft.com/en-us/download/details.aspx?id=36832

NEW QUESTION 5

You have an Azure subscription named Subscription1 that contains the resources shown in the following table.
AZ-104 dumps exhibit
You plan to configure Azure Backup reports for Vault1.
You are configuring the Diagnostics settings for the AzureBackupReports log.
Which storage accounts and which Log Analytics workspaces can you use for the Azure Backup reports of Vault1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
AZ-104 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
Box 1: storage3 only
Vault1 and storage3 are both in West Europe. Box 2: Analytics3
Vault1 and Analytics3 are both in West Europe. References:
https://docs.microsoft.com/en-us/azure/backup/backup-azure-configure-reports

NEW QUESTION 6

You have an Azure Active Directory (Azure AD) tenant named contoso.com that is synced to an Active Directory domain. The tenant contains the users shown in the following table.
AZ-104 dumps exhibit
The users have the attributes shown in the following table.
AZ-104 dumps exhibit
You need to ensure that you can enable Azure Multi-Factor Authentication (MFA) for all four users. Solution: You add an office phone number for User2.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

Explanation:
User3 requires a user account in Azure AD.
Note: Your Azure AD password is considered an authentication method. It is the one method that cannot be disabled.
References:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-methods

NEW QUESTION 7

You create a virtual machine scale set named Scale1. Scale1 is configured as shown in the following exhibit.
AZ-104 dumps exhibit
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
AZ-104 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
Box 1:
The Autoscale scale out rule increases the number of VMs by 2 if the CPU threshold is 80% or higher. The initial instance count is 4 and rises to 6 when the 2 extra instances of VMs are added.
Box 2:
The Autoscale scale in rule decreases the number of VMs by 4 if the CPU threshold is 30% or lower. The initial instance count is 4 and thus cannot be reduced to 0 as the minimum instances is set to 2. Instances are only added when the CPU threshold reaches 80%.
References:
https://docs.microsoft.com/en-us/azure/azure-monitor/platform/autoscale-overview https://docs.microsoft.com/en-us/azure/azure-monitor/platform/autoscale-best-practices https://docs.microsoft.com/en-us/azure/azure-monitor/platform/autoscale-common-scale-patterns

NEW QUESTION 8

You have an Azure Linux virtual machine that is protected by Azure Backup. One week ago, two files were deleted from the virtual machine.
You need to restore the deleted files to an on-premises computer as quickly as possible.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
AZ-104 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
To restore files or folders from the recovery point, go to the virtual machine and choose the desired recovery point.
Step 0. In the virtual machine's menu, click Backup to open the Backup dashboard. Step 1. In the Backup dashboard menu, click File Recovery.
Step 2. From the Select recovery point drop-down menu, select the recovery point that holds the files you want. By default, the latest recovery point is already selected.
Step 3: To download the software used to copy files from the recovery point, click Download Executable (for Windows Azure VM) or Download Script (for Linux Azure VM, a python script is generated).
Step 4: Copy the files by using AzCopy
AzCopy is a command-line utility designed for copying data to/from Microsoft Azure Blob, File, and Table storage, using simple commands designed for optimal performance. You can copy data between a file system and a storage account, or between storage accounts.
References:
https://docs.microsoft.com/en-us/azure/backup/backup-azure-restore-files-from-vm https://docs.microsoft.com/en-us/azure/storage/common/storage-use-azcopy

NEW QUESTION 9

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription named Subscription1 that contains the resources shown in the following table.
AZ-104 dumps exhibit
VM1 connects to a virtual network named VNET2 by using a network interface named NIC1. You need to create a new network interface named NIC2 for VM1.
Solution: You create NIC2 in RG2 and Central US. Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

Explanation:
The virtual machine you attach a network interface to and the virtual network you connect it to must exist in the same location, here West US, also referred to as a region.
References:
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-network-interface

NEW QUESTION 10

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains the following resources:
AZ-104 dumps exhibit A virtual network that has a subnet named Subnet1
AZ-104 dumps exhibit Two network security groups (NSGs) named NSG-VM1 and NSG-Subnet1
AZ-104 dumps exhibit A virtual machine named VM1 that has the required Windows Server configurations to allow Remote Desktop connections
NSG-Subnet1 has the default inbound security rules only.
NSG-VM1 has the default inbound security rules and the following custom inbound security rule:
AZ-104 dumps exhibit Priority: 100
AZ-104 dumps exhibit Source: Any
AZ-104 dumps exhibit Source port range: *
AZ-104 dumps exhibit Destination: *
AZ-104 dumps exhibit Destination port range: 3389
AZ-104 dumps exhibit Protocol: UDP
AZ-104 dumps exhibit Action: Allow
VM1 connects to Subnet1. NSG1-VM1 is associated to the network interface of VM1. NSG-Subnet1 is associated to Subnet1.
You need to be able to establish Remote Desktop connections from the internet to VM1.
Solution: You add an inbound security rule to NSG-Subnet1 that allows connections from the Internet source to the VirtualNetwork destination for port range 3389 and uses the UDP protocol.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

NEW QUESTION 11

You have an Azure subscription that contains a storage account named account1.
You plan to upload the disk files of a virtual machine to account1 from your on-premises network. The on-premises network uses a public IP address space of 131.107.1.0/24.
You plan to use the disk files to provision an Azure virtual machine named VM1. VM1 will be attached to a virtual network named VNet1. VNet1 uses an IP address space of 192.168.0.0/24.
You need to configure account1 to meet the following requirements:
AZ-104 dumps exhibit Ensure that you can upload the disk files to account1.
AZ-104 dumps exhibit Ensure that you can attach the disks to VM1.
AZ-104 dumps exhibit Prevent all other access to account1.
Which two actions should you perform? Each correct selection presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. From the Firewalls and virtual networks blade of account1, add the 131.107.1.0/24 IP address range.
  • B. From the Firewalls and virtual networks blade of account1, select Selected networks.
  • C. From the Firewalls and virtual networks blade of acount1, add VNet1.
  • D. From the Firewalls and virtual networks blade of account1, select Allow trusted Microsoft services to access this storage account.
  • E. From the Service endpoints blade of VNet1, add a service endpoint.

Answer: BE

Explanation:
B: By default, storage accounts accept connections from clients on any network. To limit access to selected networks, you must first change the default action.
Azure portal
AZ-104 dumps exhibit Navigate to the storage account you want to secure.
AZ-104 dumps exhibit Click on the settings menu called Firewalls and virtual networks.
AZ-104 dumps exhibit To deny access by default, choose to allow access from 'Selected networks'. To allow traffic from all networks, choose to allow access from 'All networks'.
AZ-104 dumps exhibit Click Save to apply your changes. E: Grant access from a Virtual Network
Storage accounts can be configured to allow access only from specific Azure Virtual Networks.
By enabling a Service Endpoint for Azure Storage within the Virtual Network, traffic is ensured an optimal route to the Azure Storage service. The identities of the virtual network and the subnet are also transmitted with each request.
References: https://docs.microsoft.com/en-us/azure/storage/common/storage-network-security

NEW QUESTION 12

You have Azure subscriptions named Subscription1 and Subscription2. Subscription1 has following resource groups:
AZ-104 dumps exhibit
RG1 includes a web app named App1 in the West Europe location. Subscription2 contains the following resource groups:
AZ-104 dumps exhibit
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
AZ-104 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/azure-resource-manager/management/move-limitations/app-service-mov

NEW QUESTION 13

You have an Azure subscription that contains the resources shown in the following table.
AZ-104 dumps exhibit
All virtual machines run Windows Server 2016.
On VM1, you back up a folder named Folder1 as shown in the following exhibit.
AZ-104 dumps exhibit
You plan to restore the backup to a different virtual machine. You need to restore the backup to VM2.
What should you do first?

  • A. From VM2, install the Microsoft Azure Recovery Services Agent
  • B. From VM1, install the Windows Server Backup feature
  • C. From VM2, install the Windows Server Backup feature
  • D. From VM1, install the Microsoft Azure Recovery Services Agent

Answer: A

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/backup/backup-azure-restore-windows-server

NEW QUESTION 14

You have an Azure subscription that contains an Azure Storage account named storage1 and the users shown in the following table.
AZ-104 dumps exhibit
You plan to monitor storage1 and to configure email notifications for the signals shown in the following table.
AZ-104 dumps exhibit
You need to identify the minimum number of alert rules and action groups required for the planned monitoring.
How many alert rules and action groups should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
AZ-104 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
AZ-104 dumps exhibit

NEW QUESTION 15

You have an Azure policy as shown in the following exhibit.
AZ-104 dumps exhibit
What is the effect of the policy?
Which of the following statements are true?

  • A. You can create Azure SQL servers in ContosoRG1.
  • B. You are prevented from creating Azure SQL servers anywhere in Subscription 1.
  • C. You are prevented from creating Azure SQL Servers in ContosoRG1 only.
  • D. You can create Azure SQL servers in any resource group within Subscription 1.

Answer: A

Explanation:
You are prevented from creating Azure SQL servers anywhere in Subscription 1 with the exception of ContosoRG1

NEW QUESTION 16

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a computer named Computer1 that has a point-to-site VPN connection to an Azure virtual network named VNet1. The point-to-site connection uses a self-signed certificate.
From Azure, you download and install the VPN client configuration package on a computer named Computer2.
You need to ensure that you can establish a point-to-site VPN connection to VNet1 from Computer2. Solution: You export the client certificate from Computer1 and install the certificate on Computer2. Does this meet this goal?

  • A. Yes
  • B. No

Answer: A

Explanation:
Each client computer that connects to a VNet using Point-to-Site must have a client certificate installed. You generate a client certificate from the self-signed root certificate, and then export and install the client certificate. If the client certificate is not installed, authentication fails.
References:
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-certificates-point-to-site

NEW QUESTION 17

You need to prepare the environment to meet the authentication requirements.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Allow inbound TCP port 8080 to the domain controllers in the Miami office.
  • B. Addhttp://autogon.microsoftazuread-sso.com to the intranet zone of each client computer in the Miami office.
  • C. Join the client computers in the Miami office to Azure AD.
  • D. Install the Active Directory Federation Services (AD FS) role on a domain controller in the Miami office.
  • E. Install Azure AD Connect on a server in the Miami office and enable Pass-through Authentication.

Answer: BE

Explanation:
B: You can gradually roll out Seamless SSO to your users. You start by adding the following Azure AD URL to all or selected users' Intranet zone settings by using Group Policy in Active Directory: https://autologon.microsoftazuread-sso.com
E: Seamless SSO works with any method of cloud authentication - Password Hash Synchronization or Pass-through Authentication, and can be enabled via Azure AD Connect.
References:
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso-quick-start

NEW QUESTION 18

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription named Subscription1 that contains the resources shown in the following table.
AZ-104 dumps exhibit
VM1 connects to a virtual network named VNET2 by using a network interface named NIC1. You need to create a new network interface named NIC2 for VM1.
Solution: You create NIC2 in RG1 and West US. Does this meet the goal?

  • A. Yes
  • B. NO

Answer: A

Explanation:
The virtual machine you attach a network interface to and the virtual network you connect it to must exist in the same location, here West US, also referred to as a region.
References:
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-network-interface

NEW QUESTION 19

You have an Azure subscription named Sub1.
You plan to deploy a multi-tiered application that will contain the tiers shown in the following table.
AZ-104 dumps exhibit
You need to recommend a networking solution to meet the following requirements:
AZ-104 dumps exhibit Ensure that communication between the web servers and the business logic tier spreads equally across the virtual machines.
AZ-104 dumps exhibit Protect the web servers from SQL injection attacks.
Which Azure resource should you recommend for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
AZ-104 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
Box 1: an internal load balancer
Azure Internal Load Balancer (ILB) provides network load balancing between virtual machines that reside inside a cloud service or a virtual network with a regional scope.
Box 2: an application gateway that uses the WAF tier
Azure Web Application Firewall (WAF) on Azure Application Gateway provides centralized protection of your web applications from common exploits and vulnerabilities. Web applications are increasingly targeted
by malicious attacks that exploit commonly known vulnerabilities. References:
https://docs.microsoft.com/en-us/azure/web-application-firewall/ag/ag-overview

NEW QUESTION 20

You have an Azure Active Directory (Azure AD) tenant named contoso.com. Multi-factor authentication (MFA) is enabled for all users.
You need to provide users with the ability to bypass MFA for 10 days on devices to which they have successfully signed in by using MFA.
What should you do?

  • A. From the multi-factor authentication page, configure the users’ settings.
  • B. From Azure AD, create a conditional access policy.
  • C. From the multi-factor authentication page, configure the service settings.
  • D. From the MFA blade in Azure AD, configure the MFA Server settings.

Answer: C

Explanation:
Enable remember Multi-Factor Authentication
AZ-104 dumps exhibit Sign in to the Azure portal.
AZ-104 dumps exhibit On the left, select Azure Active Directory > Users.
AZ-104 dumps exhibit Select Multi-Factor Authentication.
AZ-104 dumps exhibit Under Multi-Factor Authentication, select service settings.
AZ-104 dumps exhibit On the Service Settings page, manage remember multi-factor authentication, select the Allow users to remember multi-factor authentication on devices they trust option.
AZ-104 dumps exhibitSelect Save.
References:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings

NEW QUESTION 21

You have an Azure subscription.
Users access the resources in the subscription from either home or from customer sites. From home, users must establish a point-to-site VPN to access the Azure resources. The users on the customer sites access the Azure resources by using site-to-site VPNs.
You have a line-of-business app named App1 that runs on several Azure virtual machine. The virtual machines run Windows Server 2016.
You need to ensure that the connections to App1 are spread across all the virtual machines.
What are two possible Azure services that you can use? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  • A. a public load balancer
  • B. Traffic Manager
  • C. an Azure Content Delivery Network (CDN)
  • D. an internal load balancer
  • E. an Azure Application Gateway

Answer: DE

NEW QUESTION 22

You need to meet the connection requirements for the New York office.
What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
AZ-104 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
Box 1: Create a virtual network gateway and a local network gateway.
Azure VPN gateway. The VPN gateway service enables you to connect the VNet to the on-premises network through a VPN appliance. For more information, see Connect an on-premises network to a Microsoft Azure virtual network. The VPN gateway includes the following elements:
AZ-104 dumps exhibit Virtual network gateway. A resource that provides a virtual VPN appliance for the VNet. It is responsible for routing traffic from the on-premises network to the VNet.
AZ-104 dumps exhibit Local network gateway. An abstraction of the on-premises VPN appliance. Network traffic from the cloud application to the on-premises network is routed through this gateway.
AZ-104 dumps exhibit Connection. The connection has properties that specify the connection type (IPSec) and the key shared with the on-premises VPN appliance to encrypt traffic.
AZ-104 dumps exhibit Gateway subnet. The virtual network gateway is held in its own subnet, which is subject to various requirements, described in the Recommendations section below.
Box 2: Configure a site-to-site VPN connection
On premises create a site-to-site connection for the virtual network gateway and the local network gateway.
AZ-104 dumps exhibit
Scenario: Connect the New York office to VNet1 over the Internet by using an encrypted connection.

NEW QUESTION 23
......

P.S. Certshared now are offering 100% pass ensure AZ-104 dumps! All AZ-104 exam questions have been updated with correct answers: https://www.certshared.com/exam/AZ-104/ (0 New Questions)