All practice questions
1252 questions
Your team is setting up a high-traffic web platform in the North Europe region. You deploy a Standard Load Balancer named `lb-retail-prod`. The backend pool will consist of two virtual machines, `vm-app-01` and `vm-app-02`, both running in the same virtual network subnet.
You need to configure the public-facing frontend IP configuration and the backend pool for `lb-retail-prod`.
Which two configurations must you apply? (Select two.)
Select all that apply
You manage a Microsoft Entra ID tenant. You configure Self-Service Password Reset (SSPR) with the following settings:
* Self-service password reset enabled: All
* Number of methods required to reset: 1
* Methods available to users: Email, Mobile phone
You have two users in the tenant:
* User1: A standard user who has registered their mobile phone number.
* User2: A user assigned the User Administrator directory role who has registered their mobile phone number.
Both users attempt to reset their password using the SSPR portal.
Which of the following describes the outcome of their password reset attempts?
Your organization has an Azure subscription that contains a resource group named rg-dev-apps. To control costs, you configure an Azure budget at the subscription scope with a monthly limit of . You configure a budget alert threshold at that triggers an Action Group. The Action Group is configured to run an Azure Automation runbook that automatically deallocates all virtual machines in rg-dev-apps. You need to ensure that the runbook can successfully deallocate the virtual machines when the budget threshold is met, while still preventing users from accidentally deleting any virtual machines in rg-dev-apps. Which lock configuration should you apply to rg-dev-apps?
An administrator configures a virtual network named `VNet-Prod` with an address space of . The virtual network contains a subnet named `AzureBastionSubnet` with an address space of , and a subnet named `Subnet-App` with an address space of . `Subnet-App` must support at least 60 virtual machines. Statement: The proposed configuration is valid and provides enough usable IP addresses for the virtual machines in `Subnet-App`. Is the statement true?
You are deploying a database schema migration task to Azure Container Instances (ACI). If the migration script fails during execution, running it a second time automatically could result in data corruption. You must ensure that the container does not restart under any circumstances once it stops. Which restart policy should you configure for the container group?
You are preparing to host a corporate web application on Azure. The application must satisfy the following criteria:
- Associate the web application with a custom DNS domain name.
- Provide a minimum of one deployment slot to perform staging tests.
You need to identify the most cost-effective App Service plan tier that supports these requirements.
Which App Service plan tier should you choose?
You are creating a new Azure virtual machine named VM1 in a resource group named RG1. You need to ensure VM1 is protected against datacenter-wide power outages. During the deployment, you also plan to configure VM1 to use an existing Recovery Services vault named Vault1 for daily backups. Vault1 is located in the East US region. Which deployment settings should you select for VM1?
An administrator is configuring a Virtual Machine Scale Set (VMSS) named `vmss-prod` that uses a Rolling upgrade policy. You need to configure the rolling upgrade settings to meet the following requirements:
* Ensure that a maximum of 25% of the total virtual machine instances are upgraded simultaneously.
* Configure a 10-minute delay after each batch of upgrades is completed to allow the application to stabilize.
Which two properties of the rolling upgrade policy should you configure? (Select two.)
Select all that apply
A company hosts a web application on an Azure virtual machine named VM-AppServer1. The virtual machine has a single network interface named nic-app1 connected to a subnet named Subnet1. To host a second web service on VM-AppServer1 that requires its own public IP entry point, you plan to add a new IP configuration named ipconfig-tenant2 to nic-app1. Which of the following configuration actions are required to successfully add the new configuration and associate a Standard SKU public IP address? (Select TWO)
Select all that apply
A user who is assigned only the Billing Reader role at the Azure subscription scope can create and configure budget alerts in Azure Cost Management for that subscription.
An administrator is configuring a virtual machine named VM-Prod1 in the East US region. VM-Prod1 has a single network interface named nic-prod1 connected to a subnet with the address prefix 10.10.1.0/24. VM-Prod1 is currently a member of the backend pool of an active Standard Load Balancer.
The administrator needs to associate an additional public IP address named pip-mgmt to VM-Prod1 to allow direct administrative access to a secondary service running on the virtual machine.
Which of the following configuration steps must the administrator perform to support this design? (Select two.)
Select all that apply
An administrator manages an Azure subscription that contains two resource groups: `RG-Shared-Services` (which hosts core virtual networks) and `RG-Dev-Test` (which hosts development virtual machines).
The administrator must implement the following controls:
1. Prevent the accidental deletion of any resources within `RG-Shared-Services`.
2. Automatically trigger a script to deallocate virtual machines in `RG-Dev-Test` when the subscription's monthly spend reaches .
3. Allow a junior analyst named User1 to view cost analysis reports for the entire subscription, while ensuring they cannot view or modify the configuration of the virtual machines or network resources.
To achieve this, the administrator applies a CanNotDelete resource lock to `RG-Shared-Services`, configures an Azure Cost Management budget for the subscription with a limit and a threshold alert without an action group, and assigns the Billing Reader role to User1 at the `RG-Dev-Test` resource group scope.
Which of the following adjustments must be made to fully satisfy all requirements?
You need to create a public IP address to be used by a Standard Load Balancer. Which combination of SKU and allocation method must be selected for the new public IP address?
A web application named `app-shop` is currently deployed on a Basic (B1) App Service plan. The management wants to establish a pre-production environment using a staging deployment slot and schedule automatic daily backups of the application to a container in an Azure Storage account. Which configuration action should be performed to enable these features?
Your company is designing a secure hub-and-spoke network topology in Azure. The hub virtual network, named `vnet-prod-us`, is allocated the address space . The following subnets must be provisioned within `vnet-prod-us`:
- A subnet for Azure Bastion to secure administrative access.
- A subnet for a VPN Gateway to connect with an on-premises datacenter.
- A subnet named `snet-web-api` to host public web API endpoints that require at least 28 usable IP addresses.
- A subnet named `snet-microservices` to host application microservices that require at least 120 usable IP addresses.
Additionally, you deploy a Private DNS Zone named `private.contoso.com` for internal name resolution, and you peer `vnet-prod-us` with a spoke virtual network named `vnet-spoke-01` that has no gateway of its own. Spoke VMs must be able to resolve records in `private.contoso.com` and access the on-premises datacenter via the hub's VPN Gateway.
Which of the following configurations meets the subnet sizing requirements while ensuring valid name resolution and routing?
An administrator is planning the deployment of two containerized workloads to Azure Container Instances (ACI):
- A web application container that must run continuously to process incoming HTTP requests.
- A daily data processing container that runs once every 24 hours to aggregate logs, write them to an Azure Storage account, and then exit.
The administrator must minimize ACI compute costs and administrative overhead.
Which deployment architecture and configuration should the administrator implement?
Your company is planning to deploy Azure Bastion inside a virtual network named `VNet-Core`, which has an address space of . An administrator proposes the following candidate subnets to host the Bastion service:
| Proposed Subnet Name | Address Range | Purpose |
|---|---|---|
| `Bastion-Subnet` | Azure Bastion | |
| `AzureBastionSubnet` | Azure Bastion | |
| `AzureBastionSubnet` | Azure Bastion | |
| `BastionSubnet` | Azure Bastion |
Which of the proposed subnets in the table is configured correctly to support the Azure Bastion deployment?
Your company is migrating an on-premises file share to Azure. You plan to use Azure File Sync to centralize file sharing in Azure Files, while maintaining local access to frequently accessed files on a Windows Server named SRV-Share01. You have already created a storage account and an Azure file share. You need to deploy Azure File Sync and establish synchronization. In which sequence should you perform the configuration steps?
Drag items to arrange them in the correct order
You have an Azure Storage account named `datashareeast` that contains a blob container named `reports`.
You need to grant an external partner read-only access to the `reports` container. The access must meet the following requirements:
- Allow access only from the IP address range .
- Allow access only via HTTPS.
- Expire in days.
- Support the ability to immediately revoke access to the partner without rotating the storage account access keys or impacting other active SAS tokens.
Which configuration should you use?
An administrator is configuring a new virtual network named `vnet-shared` in an Azure subscription. The virtual network is assigned the address space . The administrator must create three subnets within this virtual network:
- `subnet-app`: Must host a backend API service that requires a minimum of usable IP addresses for virtual machines.
- `AzureBastionSubnet`: Must support the deployment of Azure Bastion using the minimum possible address space.
- `GatewaySubnet`: Must connect to an on-premises network via a VPN Gateway, using a prefix size of exactly .
The administrator wants to define the subnets sequentially starting from the beginning of the virtual network's address space without leaving any unassigned gaps or overlapping ranges. Which of the following subnet configurations should the administrator deploy?
`GatewaySubnet`:
`AzureBastionSubnet`:
`AzureBastionSubnet`:
`GatewaySubnet`:
`AzureBastionSubnet`:
`subnet-app`:
`AzureBastionSubnet`:
`GatewaySubnet`: