All practice questions

1186 questions

Question 21Question

An organization is migrating its on-premises workloads to Microsoft Azure. Instead of purchasing physical servers and networking hardware upfront, the organization will pay a monthly bill based on the exact amount of cloud resources consumed. Which expenditure model does this monthly consumption-based billing represent?

Show answer & explanation

Answer: Operational Expenditure (OpEx)

Answer

Operational Expenditure (OpEx)
The operational expenditure model represents ongoing day-to-day costs where businesses pay for services or resources as they consume them, without any upfront physical hardware purchases.

Step-by-Step Solution

1
Analyze the financial characteristics of the scenario.
The organization is paying monthly based on consumption without purchasing physical assets upfront.
This establishes that the expenses are ongoing operational costs rather than upfront investments in physical property.
2
Differentiate between CapEx and OpEx definitions.
Operational Expenditure (OpEx) aligns with consumption-based billing models, whereas Capital Expenditure (CapEx) aligns with upfront physical infrastructure purchases.
To select the correct cloud expenditure model that avoids upfront costs.

Key Concept

Consumption-Based Model (CapEx vs OpEx)
Estimated Time:45s
Question 22Question

A company decides to migrate its on-premises email and collaboration tools to a cloud-based service where the cloud provider manages all infrastructure, virtualization, operating systems, and the application itself. The company's employees will access their mailboxes through web browsers. Which cloud service model is the company adopting?

Show answer & explanation

Answer: Software as a Service (SaaS)

Answer

Software as a Service (SaaS)
The correct service model is Software as a Service (SaaS). In this model, the cloud provider hosts and manages the software application, its underlying infrastructure, and any maintenance such as software upgrades and security patching. Users connect to and use the application over the internet, which matches the scenario of accessing email through a web browser.

Step-by-Step Solution

1
Examine the cloud management responsibilities outlined in the scenario.
The cloud provider manages all layers of the stack, including infrastructure, operating systems, and the actual application, while the customer only uses the software.
Determining who manages the application and underlying infrastructure determines the correct cloud service model.
2
Map the management model to the correct definition of cloud service models.
A model where the provider delivers a fully functional, hosted application that users access directly over the internet is defined as Software as a Service (SaaS).
This matches the definition and responsibilities of the SaaS model.

Key Concept

Software as a Service (SaaS)
Estimated Time:45s
Question 23Question

A company plans to migrate its e-commerce platform from an on-premises data center to Azure. The website experiences highly variable traffic, with major spikes during seasonal sales events and minimal traffic otherwise. By moving to Azure's consumption-based model, which of the following describes the financial impact on the company?

Show answer & explanation

Answer: The company transitions from Capital Expenditure (CapEx) to Operational Expenditure (OpEx), paying only for the computing resources they actively consume.

Answer

The company transitions from Capital Expenditure (CapEx) to Operational Expenditure (OpEx), paying only for the computing resources they actively consume.
Migrating to a consumption-based model in Azure allows the company to eliminate upfront infrastructure costs (CapEx) and instead pay for cloud resources as they are consumed (OpEx). This aligns their operational costs directly with the demand spikes and valleys of their e-commerce website.

Step-by-Step Solution

1
Analyze the financial characteristics of the current on-premises data center model.
On-premises infrastructure requires buying physical hardware upfront, which is classified as Capital Expenditure (CapEx).
To establish the baseline financial model before migration.
2
Analyze the financial characteristics of the Azure consumption-based model.
Azure resources do not require upfront hardware purchases. Instead, they are billed based on actual usage, which is classified as Operational Expenditure (OpEx).
To identify the target financial model after migration.
3
Compare the on-premises model with the Azure consumption-based model under a variable workload.
The company shifts spending from upfront hardware (CapEx) to a pay-as-you-go model (OpEx), aligning costs directly with traffic peaks and valleys.
To determine the correct financial impact described in the choices.

Key Concept

Under a consumption-based model, organizations do not pay upfront costs for physical infrastructure. Instead, they classify cloud spending as Operational Expenditure (OpEx), aligning costs directly with resource consumption.
Estimated Time:1m 0s
Question 24Question

An administrator is planning the deployment of a new application in Azure. The application requires virtual machines to be deployed in the East US region and a storage account to be deployed in the West US region. The administrator wants to manage all of these resources together as a single logical unit and is considering nesting resource groups to represent different application tiers. Which of the following statements correctly describes how Azure resource groups can be used to meet these requirements?

Show answer & explanation

Answer: The administrator can place all resources in a single resource group regardless of their region, but resource groups cannot be nested.

Answer

The administrator can place all resources in a single resource group regardless of their region, but resource groups cannot be nested.
The statement expressing that resources can be placed in a single resource group regardless of their region, while noting that resource groups cannot be nested, is correct. Azure Resource Groups provide a flat logical container structure that does not support nesting. However, they allow resources from different geographical regions to be grouped together for lifecycle management.

Step-by-Step Solution

1
Evaluate the requirement for nesting resource groups in Azure.
Azure does not support nesting resource groups; a resource group cannot contain another resource group.
This is a fundamental design limitation of Azure Resource Manager (ARM) resources.
2
Evaluate the requirement for deploying resources in different regions within the same resource group.
Resources in a resource group can reside in any Azure region; they do not need to match the resource group's location.
The resource group location is used to store metadata about the resources, not to restrict the deployment region of the resources themselves.
3
Combine these constraints to identify the correct administrative approach.
All application resources (in East US and West US) can be grouped into one resource group, but the tiers cannot be organized using nested resource groups.
This configuration respects both the flat structure of resource groups and the regional flexibility of individual resources.

Key Concept

Azure Resource Group structure, nesting constraints, and resource location independence.
Estimated Time:1m 30s
Question 25Question

A company currently hosts a legacy web application on Azure Virtual Machines. To reduce administrative overhead, the IT team plans to migrate the application to Azure App Service.

How does the responsibility for operating system patching change after this migration is complete?

Show answer & explanation

Answer: The responsibility for patching the operating system shifts entirely from the customer to Microsoft.

Answer

The responsibility for patching the operating system shifts entirely from the customer to Microsoft.
In the Shared Responsibility Model, the boundary of responsibility shifts depending on the cloud service type. In Infrastructure as a Service (IaaS), such as Azure Virtual Machines, the customer has control over and is responsible for patching and configuring the operating system. In Platform as a Service (PaaS), such as Azure App Service, Microsoft manages the operating system, middleware, and runtime, shifting the responsibility of patching the operating system entirely to Microsoft.

Step-by-Step Solution

1
Identify the service models involved in the transition.
The application is migrating from Azure Virtual Machines (Infrastructure as a Service, or IaaS) to Azure App Service (Platform as a Service, or PaaS).
Understanding the service models is necessary to apply the Shared Responsibility Model rules.
2
Analyze the responsibility for operating system patching in IaaS.
In IaaS, the customer is responsible for managing and patching the guest operating system.
Determines the baseline responsibility before migration.
3
Analyze the responsibility for operating system patching in PaaS.
In PaaS, the cloud provider (Microsoft) manages the operating system, including patching, while the customer manages applications and data.
Determines the new responsibility allocation after migration.
4
Compare the change in responsibility to identify the correct description.
Responsibility for patching shifts from the customer to Microsoft.
Selects the option that correctly describes this shift.

Key Concept

Shared Responsibility Model
Estimated Time:1m 0s
Question 26Question

A multinational enterprise is transitioning its legacy customer relationship management (CRM) system and corporate email to a cloud-based Software as a Service (SaaS) model. As part of this migration, the Chief Information Security Officer (CISO) is updating the company's compliance registry to map operational responsibilities. Under the Microsoft shared responsibility model for SaaS, which of the following sets of tasks remains the sole responsibility of the enterprise's IT department?

Show answer & explanation

Answer: Configuring user access controls, managing device enrollment policies for corporate endpoints, and classifying data stored within the cloud applications.

Answer

Configuring user access controls, managing device enrollment policies for corporate endpoints, and classifying data stored within the cloud applications.
Under the Microsoft shared responsibility model for SaaS, the cloud customer always retains responsibility for three areas: information and data, devices (mobile and PCs), and accounts and identities. Configuring user access controls, managing device enrollment policies, and classifying data directly map to these three customer-owned areas.

Step-by-Step Solution

1
Analyze the cloud service model presented in the scenario.
The scenario specifies a migration to a Software as a Service (SaaS) model.
Responsibilities vary significantly depending on whether the service model is IaaS, PaaS, or SaaS.
2
Apply the shared responsibility model rules for SaaS.
Identify that in a SaaS model, the cloud provider manages the physical hosts, network, datacenter, operating system, middleware, and application runtime.
This narrows down the customer's responsibility to data, endpoints, accounts, and identities.
3
Evaluate the options against the customer's SaaS responsibilities.
The option containing user access controls, device enrollment, and data classification falls entirely within the customer's scope of responsibility.
Information/data, devices, and accounts/identities are always managed by the customer regardless of the cloud model.

Key Concept

Under the Microsoft shared responsibility model for Software as a Service (SaaS), the customer always retains responsibility for data classification, endpoints (devices), and accounts and access management, while the cloud provider manages the physical infrastructure, operating system, middleware, and application layer.
Question 27Question

A multinational retail company is planning to migrate its on-premises customer ordering platform to Microsoft Azure. The platform experiences highly volatile demand: it requires a steady baseline of 10 virtual machines year-round, but spikes to over 50 virtual machines during seasonal sales events. The Chief Financial Officer (CFO) mandates that the migration must minimize Capital Expenditure (CapEx) to preserve cash flow, maximize cost savings for the predictable baseline, and maintain flexibility for temporary demand spikes without any long-term financial commitments for those spikes.

Which of the following cloud migration and billing strategies best satisfies the CFO's requirements while ensuring all cloud resources are classified under the operational expenditure (OpEx) model?

Show answer & explanation

Answer: Deploy the baseline workload using 3-year Azure Reserved VM Instances with monthly payment terms, and scale out using Pay-As-You-Go Virtual Machines for seasonal spikes.

Answer

Deploy the baseline workload using 3-year Azure Reserved VM Instances with monthly payment terms, and scale out using Pay-As-You-Go Virtual Machines for seasonal spikes.
The correct strategy combines 3-year Azure Reserved VM Instances with monthly payments for the baseline workload and Pay-As-You-Go for the dynamic spikes. This satisfies all constraints: Reserved Instances reduce the cost of the steady baseline, monthly billing preserves cash flow, Pay-As-You-Go handles the seasonal spikes flexibly, and all resources are billed as operational expenditures (OpEx) since Microsoft owns and maintains the physical assets.

Step-by-Step Solution

1
Analyze the financial constraints and operational demands of the workload.
The baseline workload (10 VMs) needs cost predictability and maximum savings. The peak workload (40 additional VMs) requires high flexibility with no long-term commitment. All resources must be classified as OpEx (no physical asset ownership).
This establishes the criteria for selecting the appropriate Azure billing mechanisms.
2
Evaluate the financial classification of cloud consumption models.
Cloud expenditures are operational expenditures (OpEx) because the customer pays for a service and does not own the physical servers or infrastructure, which avoids capital expenditures (CapEx).
This eliminates options involving physical hardware ownership or leasing.
3
Select the optimal combination of Azure pricing models.
Azure Reserved VM Instances (with monthly payment options) provide the necessary discount for the baseline workload while remaining OpEx. Pay-As-You-Go virtual machines are ideal for dynamic spikes because they charge only for active usage without upfront fees.
This identifies the correct combination of Reserved Instances and Pay-As-You-Go billing.

Key Concept

Consumption-Based Model (CapEx vs OpEx)
Question 28Question

A company is designing its cloud governance strategy to manage cost and resource compliance. An administrator needs to organize resources and control where developers can deploy virtual machines. Which of the following describes a valid governance or resource organization configuration in the cloud?

Show answer & explanation

Answer: A resource group can contain resources located in different regions than the resource group itself, allowing centralized metadata storage in one region while deploying resources globally.

Answer

A resource group can contain resources located in different regions than the resource group itself, allowing centralized metadata storage in one region while deploying resources globally.
A resource group's location only determines where the metadata about the resources is stored. The actual resources within that resource group can be located in any supported cloud region, allowing for flexible global deployment and centralized metadata management.

Step-by-Step Solution

1
Determine the relationship between a resource group's location and the location of the resources it contains.
A resource group's location determines where its metadata is stored, but does not restrict the location of the resources placed inside it.
This establishes that resources can reside in different regions than their containing resource group.
2
Evaluate the architectural limits of resource groups regarding nesting.
Resource groups cannot be nested inside other resource groups.
This rules out organizational structures that assume resource group hierarchy.
3
Evaluate the enforcement behavior of compliance policies on existing resources.
New policy enforcement is not retroactive and does not automatically delete or modify existing resources.
This clarifies how governance rules affect already deployed infrastructure.

Key Concept

Cloud governance and resource organization properties
Estimated Time:1m 0s
Question 29Question

An organization has an Azure environment with a Management Group hierarchy where a parent Management Group named Corp-MG contains two subscriptions: Sub-Prod and Sub-Dev.

An administrator must design a deployment for a new application. The deployment must meet the following requirements:
1. The application's database and web server resources must be managed together as a single lifecycle unit.
2. The database must be physically located in the West US region, and the web server must be physically located in the East US region.
3. A security compliance policy must be applied at a level that automatically enforces compliance across both the Sub-Prod and Sub-Dev subscriptions.

Which configuration should the administrator implement to meet these requirements?

Show answer & explanation

Answer: Apply the security policy at the Corp-MG level. Create a single resource group in the Sub-Prod subscription, and deploy the web server to East US and the database to West US within that resource group.

Answer

Apply the security policy at the Corp-MG level. Create a single resource group in the Sub-Prod subscription, and deploy the web server to East US and the database to West US within that resource group.
The correct configuration applies the security compliance policy at the Corp-MG level, ensuring that both Sub-Prod and Sub-Dev inherit the policy. It then uses a single resource group within the Sub-Prod subscription to group the resources for lifecycle management. Since Azure allows resources to reside in different regions than their parent resource group, the web server can be deployed in East US and the database in West US within the same resource group.

Step-by-Step Solution

1
Determine the correct scope for the security policy.
The security policy must be applied at the management group (Corp-MG) level.
Applying a policy at a management group ensures that all subscriptions underneath it (both Sub-Prod and Sub-Dev) automatically inherit and enforce the policy.
2
Determine the resource group configuration to manage the application resources as a single lifecycle unit.
All resources (web server and database) must be deployed into a single resource group.
A resource group serves as a logical container for resources that share the same lifecycle. Resources cannot be nested, so they must reside in the same group to be managed together.
3
Determine the region configuration for the resources within the resource group.
Deploy the web server to East US and the database to West US within the single resource group.
An Azure resource group is a logical container and can hold resources located in different geographical regions. The location of the resource group itself only specifies where its metadata is stored, not where the resources inside it must be deployed.

Key Concept

Azure resource hierarchy, inheritance of policies from management groups, and the decoupled relationship between resource locations and resource group locations.
Estimated Time:3m 0s
Question 30Question

An organization is migrating its custom inventory management system from Azure Virtual Machines (IaaS) to Azure App Service and Azure SQL Database (PaaS). Under the Microsoft Shared Responsibility Model, which responsibility shifts from the customer to Microsoft as a result of this transition?

Show answer & explanation

Answer: Applying security updates and patches to the guest operating system and database engine

Answer

Applying security updates and patches to the guest operating system and database engine
Migrating from Infrastructure as a Service (IaaS) to Platform as a Service (PaaS) reduces the customer's administrative overhead. In an IaaS model (Virtual Machines), the customer is responsible for maintaining and patching the guest operating system and database engine. When migrating to PaaS (App Service and Azure SQL Database), Microsoft assumes full responsibility for patching the operating system and database software.

Step-by-Step Solution

1
Analyze the starting model (IaaS - Virtual Machines)
In IaaS, the customer is fully responsible for managing the guest operating system, database software configurations, network security groups, application code, and data. Microsoft is only responsible for the physical host, physical network, and hypervisor.
Establishing the baseline of responsibilities before the migration.
2
Analyze the target model (PaaS - Azure App Service and Azure SQL Database)
In PaaS, Microsoft takes over the management of the operating system, database engine software, physical hardware, and virtualization layers. The customer retains responsibility for applications, data, identities, and network configurations (such as firewalls and access rules).
Identifying the target state of responsibilities under the Platform as a Service model.
3
Identify the delta (responsibility that shifts from customer to Microsoft)
The management, updating, and patching of the guest operating system and the database engine software shift from the customer (responsible in IaaS) to Microsoft (responsible in PaaS).
Matching the shift to find the correct answer.

Key Concept

Under the Azure Shared Responsibility Model, migrating from IaaS to PaaS shifts the responsibility of operating system maintenance, database engine patching, and middleware management from the customer to the cloud provider (Microsoft).
Estimated Time:1m 30s
Question 31Question

An enterprise is migrating its legacy retail system from Azure Virtual Machines (IaaS) to Azure App Service (PaaS) for the front-end web application and Azure SQL Database (PaaS) for the relational database. Under the Microsoft Azure Shared Responsibility Model, which responsibility transitions from being the sole responsibility of the customer to being managed entirely by Microsoft?

Show answer & explanation

Answer: Patching and maintaining the operating systems hosting the application runtime and the database engine.

Answer

Patching and maintaining the operating systems hosting the application runtime and the database engine transitions from the customer to Microsoft.
The correct option stating that patching and maintaining the operating systems transitions to Microsoft is correct. In IaaS (Virtual Machines), the customer has full control and administrative responsibility over the guest operating system, including applying patches. When migrating to PaaS (Azure App Service and Azure SQL Database), Microsoft abstracts the operating system layer, meaning they take over all maintenance, patching, and OS-level security updates.

Step-by-Step Solution

1
Identify the baseline of responsibilities for Azure Virtual Machines (IaaS).
The customer is responsible for the operating system, middleware, and applications, while Microsoft is responsible for physical infrastructure.
This establishes what the customer was responsible for before the migration.
2
Identify the target responsibilities for Azure App Service and Azure SQL Database (PaaS).
Microsoft manages the physical infrastructure, operating system, and runtime/database engine, while the customer manages applications, network firewalls, and identity/data.
This determines the new distribution of responsibilities post-migration.
3
Compare the change in responsibilities to find which one shifted from the customer to Microsoft.
Operating system patching, which was a customer responsibility under IaaS, becomes Microsoft's responsibility under PaaS.
This identifies the correct boundary transition.

Key Concept

The shift of operational responsibilities from the customer to Microsoft when transitioning from Infrastructure as a Service (IaaS) to Platform as a Service (PaaS).
Question 32Question

An administrator is planning the deployment of a new multi-tier application in Azure and proposes the following resource configuration:

1. Create a parent resource group named RG-Prod in the North Europe region.
2. Create a child resource group named RG-DB nested inside RG-Prod to isolate database resources.
3. Deploy an Azure SQL Database to the West Europe region, but place it within the RG-DB resource group.
4. Apply cost-center tags to RG-DB and rely on the database to automatically inherit these tags.

Which statement correctly identifies the validity of this proposed configuration?

Show answer & explanation

Answer: Only the deployment of the SQL database to a different region than its resource group is valid; resource groups cannot be nested, and resources do not inherit tags from their resource group.

Answer

Only the deployment of the SQL database to a different region than its resource group is valid; resource groups cannot be nested, and resources do not inherit tags from their resource group.
The correct option is valid because Azure allows resources to reside in a different region than their resource group. Resource group nesting is not supported, and resources do not automatically inherit tags applied to their resource group.

Step-by-Step Solution

1
Evaluate the feasibility of nesting resource groups in Azure.
Creating RG-DB inside RG-Prod is invalid.
Azure does not support hierarchical nesting of resource groups; all resource groups exist flatly under a subscription.
2
Evaluate the geographical region compatibility between a resource and its resource group.
Deploying a SQL database in West Europe inside a resource group in North Europe is valid.
A resource group's location only determines where its metadata is stored, and resources can be deployed to any supported Azure region regardless of their resource group's region.
3
Evaluate the tag inheritance rule between resource groups and resources.
Expecting the SQL database to automatically inherit tags from RG-DB is invalid.
Azure does not support automatic tag inheritance from a resource group to its resources; tags must be applied directly or enforced via Azure Policy.

Key Concept

Azure resource groups are flat, non-nested logical containers that can hold resources from different regions, and they do not automatically propagate tags to the resources they contain.
Question 33Question

A company is migrating its custom client-facing applications and an off-the-shelf customer relationship management (CRM) tool to Microsoft Azure. For the CRM tool, the company chooses a cloud-hosted solution where Microsoft manages all infrastructure, runtime environments, and application updates. The company's security team needs to document the cloud service model and the customer's security boundaries for this CRM solution. Which cloud service model represents the CRM solution, and what is a primary security responsibility of the company under this model?

Show answer & explanation

Answer: Software as a Service (SaaS); the customer must manage user identities and protect the data stored within the CRM.

Answer

Software as a Service (SaaS); the customer must manage user identities and protect the data stored within the CRM.
The correct option is the one stating 'Software as a Service (SaaS); the customer must manage user identities and protect the data stored within the CRM.' This is because a fully hosted CRM where Microsoft manages all application updates and infrastructure represents SaaS. Under the Shared Responsibility Model, the customer always retains ownership of their data and user identities.

Step-by-Step Solution

1
Evaluate the management and hosting characteristics of the CRM solution where Microsoft manages infrastructure, runtime, and updates.
Determine that a ready-made application fully hosted and updated by the provider represents the Software as a Service (SaaS) model.
SaaS applications require no management of underlying operating systems, middleware, or hardware by the consumer.
2
Determine the user's security responsibilities under the Shared Responsibility Model for SaaS.
Identify that the customer is responsible for user accounts, identities, and the data uploaded to the service.
Regardless of the cloud model (IaaS, PaaS, or SaaS), data governance and identity/access management always remain the customer's responsibility.

Key Concept

Shared Responsibility Model and SaaS boundaries
Estimated Time:2m 0s
Question 34Question

A company plans to deploy a standard web application to Azure. The company wants to minimize administrative effort by ensuring that the cloud provider automatically manages the operating system patching, hardware provisioning, and software runtime environment. The application does not require containerization. Which Azure service should the company use to host the web application?

Show answer & explanation

Answer: Azure App Service

Answer

Azure App Service
Azure App Service is a Platform as a Service (PaaS) offering that allows developers to host web applications without managing the underlying servers. Microsoft automatically handles the operating system patching, hardware provisioning, and runtime updates, minimizing administrative overhead.

Step-by-Step Solution

1
Analyze the hosting requirements.
The application is a standard web application that does not require containerization or container orchestration.
This rules out container-specific services like Azure Kubernetes Service (AKS) and Azure Container Instances.
2
Evaluate the administrative overhead constraints.
The company wants Microsoft to handle operating system patching and hardware maintenance, which points to a Platform as a Service (PaaS) model.
This rules out Infrastructure as a Service (IaaS) options like Azure Virtual Machines, where the customer is responsible for operating system patching.
3
Identify the matching PaaS service.
Azure App Service is the primary PaaS offering for hosting web applications where Microsoft manages the infrastructure, OS, and runtime.
It aligns perfectly with the requirements of low administrative overhead and web application hosting.

Key Concept

Azure App Service provides a fully managed Platform as a Service (PaaS) hosting environment for web applications, removing the customer's responsibility for OS patching and hardware management.
Estimated Time:1m 0s
Question 35Question

A company has virtual machines running on-premises and on a third-party cloud platform. The company wants to apply Azure governance and management tools, such as Azure Policy, to these external virtual machines. Which Azure service should the company use to meet this requirement?

Show answer & explanation

Answer: Azure Arc

Answer

Azure Arc is the correct service because it is designed to extend Azure management, security, and governance to resources that live outside of Azure.
Azure Arc is specifically designed to extend Azure management, governance, and services to hybrid and multi-cloud environments. By registering external servers with Azure Arc, they appear as resource objects inside Azure, allowing the use of Azure Resource Manager, Azure Policy, and guest configuration tools.

Step-by-Step Solution

1
Analyze the company's requirement: managing and governing virtual machines that are running on-premises and on a third-party cloud platform using Azure services.
The target resources are located outside of Azure's native cloud environment.
Identifying the location of the resources helps select the correct hybrid management tool.
2
Evaluate which Azure service acts as a bridge to extend Azure Resource Manager (ARM) and Azure Policy to non-Azure resources.
Azure Arc is identified as the service that projects external resources into Azure as native ARM resources.
This matches the requirement of applying Azure management and governance to external virtual machines.

Key Concept

Azure Arc is a service that simplifies governance and management by delivering a consistent multi-cloud and on-premises management platform, projecting non-Azure resources into Azure Resource Manager.
Question 36Question

An Azure administrator applies a ReadOnly resource lock to an Azure resource group. Which of the following describes the effect of this lock on the resources inside the resource group?

Show answer & explanation

Answer: Authorized users can read the resource configurations, but they cannot modify or delete the resources.

Answer

Authorized users can read the resource configurations, but they cannot modify or delete the resources.
Applying a ReadOnly lock to a resource group prevents any changes to the configurations of the resources within that group, and also prevents the resources from being deleted. Authorized users can still read and view the resource settings.

Step-by-Step Solution

1
Identify the type of resource lock applied.
The lock is a ReadOnly lock applied at the resource group level.
Understanding the lock type is necessary to determine the specific restrictions enforced.
2
Analyze how locks are inherited.
The lock is inherited by all resources within the resource group.
Azure resource locks applied at a parent scope (like a resource group) apply to all resources contained within that scope.
3
Determine the restrictions of a ReadOnly lock.
A ReadOnly lock prevents all delete and write/update operations.
This matches the definition of a ReadOnly lock, which is more restrictive than a CanNotDelete lock.

Key Concept

Azure Resource Locks (ReadOnly vs CanNotDelete)
Question 37Question

An organization is designing a hybrid cloud network to connect its on-premises database to resources in Azure. The network connection must support database replication with predictable, low-latency performance and must ensure that data is never routed over the public internet. Which Azure service should the organization deploy to meet these requirements?

Show answer & explanation

Answer: Azure ExpressRoute

Answer

Azure ExpressRoute
The correct service is Azure ExpressRoute because it establishes a private, dedicated physical connection between the on-premises datacenter and Azure through a connectivity partner. Since this connection does not use the public internet, it meets the requirements of predictable latency and complete isolation from public internet routing.

Step-by-Step Solution

1
Analyze the requirements for hybrid connectivity: the connection must bypass the public internet and require predictable, low-latency performance.
Connections that rely on the public internet (such as VPNs) are eliminated from the correct solution path.
Public internet routing introduces unpredictable latency and does not satisfy the requirement to completely bypass the public internet.
2
Evaluate the remaining options to identify which service establishes a private, dedicated connection from on-premises to Azure.
Azure ExpressRoute matches the requirements because it uses a private fiber connection established through a connectivity provider.
ExpressRoute ensures that traffic travels directly to Microsoft's edge environment without traversing the public internet, meeting both the performance and security constraints.

Key Concept

Azure ExpressRoute provides a dedicated, private connection to Microsoft cloud services that bypasses the public internet, offering higher reliability, faster speeds, and lower latencies than typical VPN connections.
Question 38Question

A company is planning to deploy a web application and needs a database service. The application requires a non-relational (NoSQL) database to store unstructured user profile documents. A developer proposes using Azure SQL Database to meet this requirement. Why is this proposal incorrect?

Show answer & explanation

Answer: Azure SQL Database is a relational database service, not a non-relational (NoSQL) database service.

Answer

Azure SQL Database is a relational database service, not a non-relational (NoSQL) database service.
The correct option is correct because Azure SQL Database is a relational database service built on SQL Server. It is designed for structured tables and relations, not for storing non-relational (NoSQL) document data models. For NoSQL document workloads, Azure Cosmos DB is the appropriate service.

Step-by-Step Solution

1
Analyze the application requirements.
The application requires a non-relational (NoSQL) database for unstructured document storage.
Identifying the data structure requirement (non-relational/NoSQL) is the first step in selecting the correct database service.
2
Evaluate Azure SQL Database against the requirements.
Azure SQL Database is a relational database engine.
Evaluating the proposed service shows it is designed for relational tabular data, making it unsuitable for a pure NoSQL document database requirement.

Key Concept

Azure SQL Database is a relational database service (PaaS) designed for structured data with relationships, whereas Azure Cosmos DB is a non-relational (NoSQL) database service designed for unstructured and semi-structured data.
Question 39Question

Your company has an Azure subscription containing a resource group named Dev-RG. You need to grant a junior administrator the ability to create and manage all resources within Dev-RG. The junior administrator must not be allowed to assign roles or grant permissions to other users. Which of the following should you assign to the junior administrator's account for Dev-RG?

Show answer & explanation

Answer: The Contributor role

Answer

The Contributor role
The Contributor role allows the user to manage all resources within the specified scope, including creating and deleting resources, but it does not allow the user to assign roles in Azure RBAC or grant permissions to others. This perfectly aligns with the security requirements of the scenario.

Step-by-Step Solution

1
Analyze the access control requirements for the junior administrator.
The administrator needs permissions to create and manage all resources within the specific resource group (Dev-RG) but must be restricted from delegating access or assigning roles to other users.
This establishes the scope (Resource Group) and the required actions (create and manage resources, but no access management).
2
Evaluate the capabilities of Azure Role-Based Access Control (RBAC) roles against the requirements.
The Contributor role allows managing all resources but prevents role assignment. The Owner role allows both resource management and role assignment. The Reader role only allows viewing resources.
This matches the requirements to the correct built-in Azure RBAC role.
3
Differentiate between Azure RBAC and Azure Policy.
Azure Policy regulates resource configuration compliance rather than user permissions, making it unsuitable for granting access.
This eliminates the policy-related distractor.

Key Concept

Azure Role-Based Access Control (RBAC) built-in roles and scope
Estimated Time:1m 0s
Question 40Question

A company wants to connect its on-premises head office to an Azure virtual network. The network traffic must be encrypted during transit, setup costs must be kept minimal, and the connection can run over the public internet. Which Azure service should the company use to meet these requirements?

Show answer & explanation

Answer: Azure VPN Gateway

Answer

Azure VPN Gateway
Azure VPN Gateway is correct because it establishes an encrypted VPN tunnel over the public internet to connect on-premises environments to Azure virtual networks, making it a cost-effective option for hybrid networking.

Step-by-Step Solution

1
Analyze the requirements for connecting the on-premises network to Azure.
The connection needs to be encrypted, have a low setup cost, and utilize the public internet.
Identifying these parameters filters out services that rely on dedicated private paths or serve different routing purposes.
2
Evaluate the available Azure services against the requirements.
Azure VPN Gateway fits all requirements because it creates encrypted tunnels over the public internet. Azure ExpressRoute uses private circuits, Virtual Network peering connects networks within Azure, and Azure Bastion manages secure VM access.
Matching the requirements to service capabilities determines the correct choice.

Key Concept

Azure VPN Gateway provides secure, encrypted hybrid connectivity over the public internet.
Estimated Time:45s
PreviousPage 2 / 60Next
All practice questions — Microsoft Azure Fundamentals (AZ-900) | Examkin