All practice questions
1252 questions
An administrator configures a monthly budget of $5,000 for a resource group named rg-experimental-workloads. To prevent unauthorized changes to the resource group's configuration, the administrator applies a ReadOnly resource lock to rg-experimental-workloads. A budget alert is configured at a 90% threshold to trigger an Azure Automation runbook via an Action Group to deallocate all running virtual machines (VMs) in the resource group. When the budget threshold is reached, the alert fires, but the VMs remain running and continue to incur costs. What is the cause of this issue?
Sienna Foods plans to deploy a new inventory management system consisting of two virtual machines, VM-Inv1 and VM-Inv2, in the UK South region. The company has a service level agreement (SLA) requirement that guarantees virtual machine uptime of at least to protect against localized datacenter failures. Which deployment configuration should you recommend?
Your company is implementing Azure File Sync to centralize file shares in Azure while maintaining local caching to optimize access latency. You need to configure cloud tiering on an on-premises Windows Server named FileServer1 to minimize local storage usage on volume F: while keeping active files cached.
Volume F: has a total capacity of . You enable Cloud Tiering on the server endpoint with the following settings:
- Volume free space policy:
- Date policy: Tier files that have not been accessed within the last days.
Currently, the local volume F: contains of files cached locally (resulting in free space). The cached files consist of:
- of files that have not been accessed for more than days.
- of files that were accessed within the last days.
Which of the following describes the resulting tiering behavior on volume F: when Azure File Sync evaluates the cloud tiering policies?
You manage an Azure App Service web app named WebApp1 that has a deployment slot named Staging. WebApp1 currently connects to a production database, and Staging connects to a testing database. The database connection settings are stored as an application setting named DB_CONNECTION.
You need to ensure that when Staging is swapped to production, the production slot continues to connect to the production database and the Staging slot continues to connect to the testing database.
Which configuration should you apply?
An organization's Azure environment is configured with the following resource hierarchy:
- Tenant Root Group (Management Group)
- Group-MG (Management Group)
- Billing-Sub (Subscription)
- Data-RG (Resource Group)
- storage1 (Storage Account)
A security administrator needs to delegate authority to a user named Admin-User1. Admin-User1 must be able to assign the Reader role to external auditors for resources within Data-RG. Admin-User1 must not be able to modify the resources themselves, nor assign roles for any resources outside of Data-RG.
Which of the following actions should the administrator perform to meet these requirements with the least privilege?
You are configuring backups for an Azure App Service web app. Which two configurations are required to enable custom backups for the web app? (Select two.)
Select all that apply
You need to use the AzCopy command-line utility to upload data from an on-premises client computer to a blob container in an Azure Storage account. The storage account has public network access enabled from selected networks.
Which of the following configurations will allow you to successfully authenticate and execute the upload? (Select two.)
Select all that apply
An administrator is configuring a new Azure virtual machine named VM-APP-10 in the West US region using the Azure portal. The administrator intends to enable Azure Backup on the Management tab during the creation process and associate the virtual machine with an existing Recovery Services Vault named RSV-Backup. However, RSV-Backup does not appear as an option in the Recovery Services vault dropdown list.
What is the most likely reason RSV-Backup is unavailable for selection?
An administrator manages a standard General Purpose v2 (GPv2) storage account named stbackup2026 in the East US region. The storage account currently uses Locally Redundant Storage (LRS). To meet new corporate policies, the administrator must ensure the storage account is protected against regional outages. Additionally, any logs stored in a container named 'temp-logs' must be automatically deleted 30 days after they are created. Which two actions should the administrator perform to meet these requirements?
Select all that apply
An organization has a Microsoft Entra ID tenant. The tenant contains a user named Admin1, a security group named Europe-Sales that has 50 member users, and an administrative unit named Europe-AU. Europe-AU contains the Europe-Sales group as its only member.
You assign the User Administrator role to Admin1 with Europe-AU as the scope.
Which action is Admin1 permitted to perform?
You manage an Azure environment. You create a new resource group named rg-finance-prod to hold production database resources. You apply a tag with the key CostCenter and value Finance-101 to rg-finance-prod. Additionally, you configure a CanNotDelete resource lock on rg-finance-prod. Afterwards, you deploy an Azure SQL database named db-finance into rg-finance-prod. Which of the following statements correctly describe the resource governance settings applied to the database? Select two.
Select all that apply
You have an existing Availability Set named AvSet1 in the East US region. You need to deploy a new virtual machine named VM2 and configure it to be part of AvSet1. Which configuration must be applied during the creation of VM2?
An administrator is configuring access control for an Azure environment where the Prod-MG management group contains the Sub1 subscription, which in turn contains the Data-RG resource group. A storage account named storage1 is deployed in Data-RG. A developer needs to upload and read blobs in storage1. The developer must not have permissions to modify the configuration of the storage account or any other resources in the subscription. Which built-in role and scope should the administrator assign to the developer to meet these requirements while adhering to the principle of least privilege?
An organization's Azure environment contains a resource group named RG-Data that hosts a storage account named storageapp2026. An administrator needs to configure permissions so that a user named Jordan can download files from a blob container named 'logs'. The configuration must use Microsoft Entra ID authentication and follow the principle of least privilege, ensuring Jordan cannot modify any data or change storage account settings. Which Azure role-based access control (RBAC) role should the administrator assign to Jordan?
You have an Azure App Service web app named WebApp1 and an Azure Key Vault named Vault1. You need to store a database connection string in Vault1 as a secret and configure WebApp1 to securely retrieve the connection string without exposing the raw secret value in the App Service configuration. Which sequence of steps should you perform to complete this configuration?
Drag items to arrange them in the correct order
Your organization has an on-premises Windows Server named Server1. You need to configure Azure File Sync to synchronize a local folder on Server1 with a new Azure file share. You have already created a resource group and a storage account in Azure. Which sequence of actions should you perform to establish synchronization? To answer, move the appropriate actions to the answer area and arrange them in the correct order.
Drag items to arrange them in the correct order
You manage an Azure App Service web app that is hosted on a Free (F1) App Service plan. You need to configure a custom domain and bind a custom TLS/SSL certificate to the web app. What is the minimum App Service plan pricing tier you must select to support these requirements?
An administrator is deploying a high-availability application that consists of three virtual machines in the East US region. The virtual machines are placed in a resource group named RG-Prod. A ReadOnly resource lock is applied to RG-Prod.
The deployment requirements and configurations are:
- The virtual machines must be protected against datacenter-wide failures, so they are deployed across three Availability Zones in East US.
- The virtual machines must be backed up daily, so a Recovery Services vault is created in the East US 2 region.
- Boot diagnostics for the virtual machines must be written to an Azure storage account that restricts public access. The storage account firewall is configured to allow access from selected networks only, and the 'Allow trusted Microsoft services to access this storage account' option is disabled.
You need to identify the configuration issues and operational limitations of this setup.
Which of the following statements are correct? (Select two.)
Select all that apply
An administrator successfully logs in to AzCopy using a Microsoft Entra ID account. However, when the administrator attempts to copy files to an Azure Blob storage container, the copy operation fails with an authorization error. The administrator's user account has the Contributor role for the storage account. Which action should the administrator perform to resolve the authorization error?
An administrator is planning the deployment of several Azure virtual machines (VMs) to support different enterprise workloads. Each workload has specific performance, placement, or security requirements.
Match each workload requirement to the most appropriate Azure VM configuration feature or option.
Click a left item, then click its matching right item
Items
Matches