All practice questions
1252 questions
An administrator needs to transfer of data from an on-premises datacenter to Azure storage. The administrator wants to use physical shipping but does not want to purchase or prepare local hard drives, requiring Microsoft to provide the encrypted SSDs for the transfer. Which service should the administrator configure?
An administrator is configuring a dynamic user group in a Microsoft Entra ID tenant. The group must automatically include all internal employees assigned to the Sales department. The group must exclude guest users and must not include any device objects. Which dynamic membership rule should the administrator use?
A healthcare company, HealthPulse Diagnostics, uses the following Azure Management Group (MG) hierarchy to organize its subscriptions:
- Tenant Root Group
- HealthPulse-MG (Management Group)
- Clinical-MG (Management Group)
- SubscriptionA
- ResourceGroup1
- Research-MG (Management Group)
- SubscriptionB
The following settings are configured:
1. At HealthPulse-MG, an Azure Policy is assigned that denies the deployment of virtual machines unless they use the 'Standard_D2s_v3' SKU.
2. At Clinical-MG, an Azure Policy is assigned that denies the deployment of virtual machines unless they use the 'Standard_D4s_v3' SKU.
3. At SubscriptionA, User1 is assigned the Contributor role.
User1 attempts to deploy a new virtual machine using the 'Standard_D4s_v3' SKU into ResourceGroup1.
What is the outcome of the deployment attempt?
For a new production deployment, an administrator configures the following Azure resource hierarchy:
- Management Group: `MG-Production`
- Subscription: `Sub-AppStore`
- Resource Group: `RG-Services`
- App Service: `api-service-01`
A developer named DevUser1 is assigned the Reader role at the `Sub-AppStore` subscription level. DevUser1 is also assigned the Contributor role at the `RG-Services` resource group level.
Which of the following describes the effective permission of DevUser1 for `api-service-01`?
Your company has a Microsoft Entra ID tenant. The tenant contains an Administrative Unit named Sales-AU and a dynamic security group named Sales-Dynamic-Group. Sales-Dynamic-Group is a member of Sales-AU.
You assign a user named Admin1 the Groups Administrator role scoped to Sales-AU.
Admin1 attempts to perform the following tasks:
1. Modify the membership of an assigned security group named Sales-Manual-Group that is a member of Sales-AU.
2. Modify the dynamic membership rule of Sales-Dynamic-Group.
Which tasks can Admin1 successfully perform?
An administrator manages an Azure storage account named `storage1` that is configured to use Geo-Redundant Storage (GRS). Due to a severe regional outage in the primary region, the administrator decides to initiate a customer-managed failover for `storage1`. Which replication configuration will `storage1` have immediately after the failover completes?
A company implements a governance strategy for its Azure resources. The environment includes a user account named Admin-User who is assigned the Global Administrator directory role in Microsoft Entra ID. No Azure Role-Based Access Control (RBAC) assignments have been made for Admin-User at any resource scope.
The resource hierarchy is structured as follows:
- Management Group: MG-Shared
- Subscription: Sub-Development
- Resource Group: RG-Web
Admin-User needs to assign the Virtual Machine Contributor role to a developer at the RG-Web scope.
Which configuration must be completed to enable Admin-User to assign this role?
A company has an Azure subscription containing a standard General Purpose v2 (GPv2) storage account named `storeprodwest2` in the West US 2 region. The storage account is configured with locally redundant storage (LRS) and contains a single blob container with of data. A lifecycle management rule is currently active that transitions blobs older than days to the Archive tier, resulting in of archived blobs. The company wants to migrate the storage account to zone-redundant storage (ZRS) with zero data loss and no downtime. You plan to request a live migration from Microsoft support. Which of the following actions must you perform before Microsoft can initiate the live migration?
Your company has an Azure environment structured with the following resource hierarchy:
* Management Group: `MG-Retail`
* Subscription: `Sub-Retail-Prod`
* Resource Group: `RG-Store-Prod`
* Resource: Virtual Machine named `VM-Web-01`
A user named Admin1 is assigned the Microsoft Entra ID Global Administrator role, but currently has no explicit Azure RBAC role assignments. Admin1 needs to assign the Contributor role to a developer named User2 for the Virtual Machine `VM-Web-01`.
What must Admin1 do first to accomplish this?
Your organization needs to import of on-premises data to an Azure Storage account. You have ordered an Azure Data Box device, and it has just been delivered to your datacenter. Which of the following shows the correct sequence of steps you must perform to configure the device, copy the data, and complete the import process?
Drag items to arrange them in the correct order
A logistics company, Zenith Freight Services, is migrating a multi-tier workload to the Sweden Central region. The deployment must adhere to the following strict requirements:
- The database layer ( virtual machines) requires a VM-level compute uptime SLA of at least .
- The application layer ( virtual machines) requires protection against localized hardware failures and updates within a single datacenter, while ensuring network latency between the instances is minimized.
- The web layer ( existing standalone virtual machines: WebVM-Prod1 and WebVM-Prod2) must be integrated into a configuration that guarantees a compute SLA.
Which configuration strategy should the administrator implement to meet all requirements?
An organization has a Microsoft Entra ID tenant and the following Azure resource hierarchy:
* Management Group: MG-Root
* Azure Subscription: Sub-Ops
* Resource Group: RG-Prod-Shared
* Storage Account: sa-prod-logs (contains a blob container named `security-logs`)
The following settings and assignments are configured:
1. A user named User1 is assigned the Security Reader role in Microsoft Entra ID.
2. The tenant-level directory setting Access management for Azure resources is set to No.
3. User1 is assigned the User Access Administrator role at the Sub-Ops subscription scope.
4. User1 is assigned the Reader role at the RG-Prod-Shared scope.
5. A resource lock of type ReadOnly is applied directly to the sa-prod-logs storage account.
Which of the following describes the effective permissions of User1?
An organization has of data stored on an on-premises network-attached storage (NAS) system. The organization needs to migrate this data to an Azure Blob Storage account. The local network has a restricted outbound internet connection, providing only of dedicated bandwidth for the migration. The migration must be completed within . The organization's security policy strictly prohibits the shipment of customer-owned physical drives and requires that all data copied to temporary physical transport media be accessible directly via standard network protocols (SMB or NFS) without requiring staging hosts. Which migration solution should you recommend to meet these requirements?
An administrator needs to configure temporary access to a blob container named invoices within an Azure Storage account named corpfinance2026. The configuration must satisfy the following security requirements:
- Prevent exposure of the storage account's primary and secondary access keys.
- Authenticate the client using a Microsoft Entra ID security principal.
- Limit the validity of the temporary access to exactly two hours.
- Enforce the use of the HTTPS protocol only.
Which two actions should the administrator perform to meet these requirements? (Select two.)
Select all that apply
You have a General Purpose v2 (GPv2) storage account named `storagedata` in the East US region. The storage account is configured with Geo-Redundant Storage (GRS). A lifecycle management policy is active on the account, which automatically transitions block blobs in a container named `logs` to the Archive tier 30 days after they are created.
Due to a disaster in the primary region, you initiate a customer-managed failover for the storage account.
What is the state of the storage account replication and the archived blobs after the failover completes?
An organization named Meridian Vanguard configures the following Azure Management Group (MG) hierarchy:
* Tenant Root Group
* Corporate-MG
* Production-MG
* App-Sub-01 (Subscription)
* Development-MG
* Dev-Sub-01 (Subscription)
An administrator named Alice needs to reorganize the environment by moving the subscription App-Sub-01 from Production-MG to Development-MG.
Alice has the following Azure role assignments:
* Owner role on the App-Sub-01 subscription
* Reader role on both Corporate-MG and Production-MG
* Contributor role on Development-MG
What is the outcome when Alice attempts to move the subscription?
An administrator is reviewing replication options for standard General Purpose v2 (GPv2) storage accounts in an Azure subscription.
Which of the following statements about Azure Storage replication options are correct? (Select TWO.)
Select all that apply
An administrator configures the network firewall for an Azure Storage account named storagedata1 that contains a blob container named container1 and an Azure file share named share1.
The firewall settings for storagedata1 are configured as follows:
- Public network access: Enabled from selected virtual networks and IP addresses
- Virtual networks: None
- Firewall (IP ranges): None
- Exceptions: "Allow Azure services on the trusted services list to access this storage account" is enabled
The administrator needs to support the following administrative tasks:
- Task 1: Backup share1 using Azure Backup.
- Task 2: Allow a developer named User1 to upload blobs to container1 using the Azure CLI from an on-premises computer with the public IP address 203.0.113.5. User1 is assigned the Owner role at the subscription level.
- Task 3: Allow an Azure Data Factory instance named ADF1 to copy data from container1. ADF1 has been assigned the Storage Blob Data Contributor role on storagedata1.
Which of the tasks will succeed under the current configuration without any further modifications?
An administrator is configuring network security for an Azure storage account named `mystorage2026`. The storage account must allow traffic from `Subnet-A` of `VNet-A`, but block all other public internet traffic. Additionally, Azure Virtual Machine backup operations must continue to succeed.
Which two settings must be configured on the firewalls and virtual networks blade of the storage account to meet these requirements?
Select all that apply
An administrator is planning the deployment of two Azure virtual machines named VM-Web1 and VM-Web2 in the North Europe region. To meet high availability requirements, the administrator decides to deploy both virtual machines in a single Availability Set. Which of the following statements describe the features or configuration requirements of Azure Availability Sets? (Select two.)
Select all that apply