[2025] Pass Microsoft AZ-140 Exam Updated 264 Questions
Get 2025 Updated Free Microsoft AZ-140 Exam Questions and Answer
Microsoft AZ-140 exam is designed for professionals who want to validate their skills and knowledge in configuring and operating Microsoft Azure Virtual Desktop. Configuring and Operating Microsoft Azure Virtual Desktop certification exam is designed to test the ability of the candidates to manage, deploy, and support virtual desktop infrastructure on Azure. AZ-140 exam covers various topics such as configuring host pools, managing user access, deploying and managing apps, and monitoring and maintaining virtual desktop infrastructure.
Microsoft AZ-140 is a certification exam that is designed for professionals who want to expand their skills and expertise in configuring and operating Microsoft Azure Virtual Desktop. Configuring and Operating Microsoft Azure Virtual Desktop certification exam is aimed at individuals who are responsible for managing and deploying virtual desktop infrastructure in a cloud environment. The AZ-140 exam tests the candidate's ability to implement, manage, and monitor a virtual desktop infrastructure on Microsoft Azure. Configuring and Operating Microsoft Azure Virtual Desktop certification exam covers a range of topics, including virtual desktop infrastructure architecture, desktop image management, user profile management, and virtual desktop monitoring and maintenance.
NEW QUESTION # 59
You have an Azure Virtual Desktop host pool named Pool1 that contains three session hosts. The session hosts are configured to use FSLogix profiles.
On a management computer, you create an Application Masking rule and assignment files.
You need to apply Application Masking to the session hosts in Pool1.
What should you do?
- A. Copy the files to the session hosts in Pool1.
- B. Generate a registration token.
- C. Compile the rule and assignment files.
- D. Install the FSLogix agent on the session hosts in Pool1.
Answer: A
Explanation:
https://docs.microsoft.com/en-us/fslogix/application-masking-rules-ht#deploying-rule-sets
NEW QUESTION # 60
You have an Azure subscription that contains the resources shown in the following table.
You have a virtual machine named Server1 that runs Windows Server and is connected to VNet3.
You need to deploy the Azure Virtual Desktop host pools shown in the following table.
The solution must meet the following requirements:
* The session hosts in Pool1 must access Server1 via the Microsoft backbone network.
* The session hosts in Pool2 must access storage1 via the Microsoft backbone network.
What should you configure on the virtual networks? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 61
You have an Azure Virtual Desktop deployment.
You are configuring the outbound firewall settings for the host pool.
Which outbound URL and outbound port should you configure to ensure that the host machines maintain Windows activation? To answer, select the appropriate options In the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
NEW QUESTION # 62
You plan to deploy Windows Virtual Desktop.
Users have the devices shown in the following table.
From which device types can the users connect to Windows Virtual Desktop resources by using the Remote Desktop client app and the Remote Desktop web client? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/virtual-desktop/connect-web
https://docs.microsoft.com/en-us/azure/virtual-desktop/connect-android
https://docs.microsoft.com/en-us/azure/virtual-desktop/connect-macos
NEW QUESTION # 63
Your company has the offices shown in the following table.
The company has an Azure Active Directory (Azure AD) tenant named contoso.com that contains a user named User1.
Users connect to a Windows Virtual Desktop deployment named WVD1. WVD1 contains session hosts that have public IP addresses from the 52.166.253.0/24 subnet.
Contoso.com has a conditional access policy that has the following settings:
* Name: Policy1
* Assignments:
* Users and groups: User1
* Cloud apps or actions: Windows Virtual Desktop
Access controls:
* Grant: Grant access, Require multi-factor authentication
Enable policy: On
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-azure-mfa
NEW QUESTION # 64
You have an Azure Virtual Desktop deployment that contains two users named User1 and User2 and the storage accounts shown in the following table.
The File share settings for storage1 are configured as shown in the following exhibit.
The File share settings for storage2 are configured as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Answer:
Explanation:
NEW QUESTION # 65
You have an Azure Virtual Desktop deployment that contains a session host named Host1.
You need to configure Windows Defender Firewall to allow inbound network traffic for RDP Shortpath on Host1.
Which program in the C:\Windows\System32 folder should you specify in the inbound firewall rule?
- A. Rdpshell.exe
- B. Raserver.exe
- C. Svchost.exe
- D. Mstsc.exe
Answer: C
Explanation:
New-NetFirewallRule -DisplayName 'Remote Desktop - RDP Shortpath (UDP-In)' -Action Allow
-Description 'Inbound rule for the Remote Desktop service to allow RDP Shortpath traffic. [UDP 3390]'
-Group '@FirewallAPI.dll,-28752' -Name 'RemoteDesktop-UserMode-In-RDPShortpath-UDP' -PolicyStore PersistentStore -Profile Domain, Private -Service TermService -Protocol UDP -LocalPort 3390 -Program
'%SystemRoot%\system32\svchost.exe' -Enabled:True
https://learn.microsoft.com/en-us/azure/virtual-desktop/configure-rdp-shortpath?tabs=managed-networks
NEW QUESTION # 66
You have a Azure Virtual Desktop host pool.
You need to install Microsoft Antimalware for Azure on the session hosts.
What should you do?
- A. Configure the RDP Properties of the host pool.
- B. Add an extension to each session host.
- C. From a Group Policy Object (GPO), enable Windows 10 security features.
- D. Sign in to each session host and install a Windows feature.
Answer: B
Explanation:
https://docs.microsoft.com/en-us/azure/virtual-machines/extensions/iaas-antimalware-windows
NEW QUESTION # 67
You have an Azure Virtual Desktop deployment that contains a host pool named Pool1. Pool1 has the following settings:
* Host pool type: Pooled
* Load balancing algorithm: Breadth-first
* Max session limit: 5
* Start VM on connect: Yes
Pool1 contains the session hosts shown in the following table.
How many additional users must connect to Pool1 to start Host3?
- A. 0
- B. 1
- C. 2
- D. 3
- E. 4
Answer: D
NEW QUESTION # 68
Case Study 2 - Litware, Inc
Overview
Litware, Inc. is a pharmaceutical company that has a main office in Boston, United States, and a remote office in Chennai, India.
Existing Environment. Identity Environment
The network contains an on-premises Active Directory domain named litware.com that syncs to an Azure Active Directory (Azure AD) tenant named litware.com.
The Azure AD tenant contains the users shown in the following table.
All users are registered for Azure Multi-Factor Authentication (MFA).
Existing Environment. Cloud Services
Litware has a Microsoft 365 E5 subscription associated to the Azure AD tenant. All users are assigned Microsoft 365 Enterprise E5 licenses.
Litware has an Azure subscription associated to the Azure AD tenant. The subscription contains the resources shown in the following table.
Litware uses custom virtual machine images and custom scripts to automatically provision Azure virtual machines and join the virtual machines to the on-premises Active Directory domain.
Network and DNS
The offices connect to each other by using a WAN link. Each office connects directly to the internet.
All DNS queries for internet hosts are resolved by using DNS servers in the Boston office, which point to root servers on the internet. The Chennai office has caching-only DNS servers that forward queries to the DNS servers in the Boston office.
Requirements. Planned Changes
Litware plans to implement the following changes:
* Deploy Azure Virtual Desktop environments to the East US Azure region for the users in the Boston office and to the South India Azure region for the users in the Chennai office.
* Implement FSLogix profile containers.
* Optimize the custom virtual machine images for the Azure Virtual Desktop session hosts.
* Use PowerShell to automate the addition of virtual machines to the Azure Virtual Desktop host pools.
Requirements. Performance Requirements
Litware identifies the following performance requirements:
* Minimize network latency of the Azure Virtual Desktop connections from the Boston and Chennai offices.
* Minimize latency of the Azure Virtual Desktop host authentication in each Azure region.
* Minimize how long it takes to sign in to the Azure Virtual Desktop session hosts.
Requirements. Authentication Requirements
Litware identifies the following authentication requirements:
* Enforce Azure MFA when accessing Azure Virtual Desktop apps.
* Force users to reauthenticate if their Azure Virtual Desktop session lasts more than eight hours.
Requirements. Security Requirements
Litware identifies the following security requirements:
* Explicitly allow traffic between the Azure Virtual Desktop session hosts and Microsoft 365.
* Explicitly allow traffic between the Azure Virtual Desktop session hosts and the Azure Virtual Desktop infrastructure.
* Use built-in groups for delegation.
* Delegate the management of app groups to Admin2, including the ability to publish app groups to users and user groups.
* Grant Admin1 permissions to manage workspaces, including listing which apps are assigned to the app groups.
* Minimize administrative effort to manage network security.
* Use the principle of least privilege.
Requirements. Deployment Requirements
Litware identifies the following deployment requirements:
* Use PowerShell to generate the token used to add the virtual machines as session hosts to a Azure Virtual Desktop host pool.
* Minimize how long it takes to provision the Azure Virtual Desktop session hosts based on the custom virtual machine images.
* Whenever possible, preinstall agents and apps in the custom virtual machine images.
User Profile Requirements
Litware identifies the following user profile requirements:
* In storage1, store user profiles for the Boston office users.
* Ensure that the user profiles for the Boston office users replicate synchronously between two Azure regions.
* Ensure that Admin1 uses a local profile only when signing in to the Azure Virtual Desktop session hosts.
You need to deploy the session hosts to meet the deployment requirements.
Which PowerShell cmdlet should you run first?
- A. Update-AzWvdSessionHost
- B. Set-AzVMADDomainExtension
- C. Get-AzApiManagementSsoToken
- D. New-AzWvdRegistrationInfo
Answer: D
Explanation:
New-AzWvdRegistrationInfo -SubscriptionId "<Value>" -ResourceGroupName "<Value>" - HostPoolName "<Value>" -ExpirationTime (Get-Date).AddDays(14)
https://docs.microsoft.com/en-us/azure/virtual-desktop/create-host-pools-powershell?tabs=azure- powershell
NEW QUESTION # 69
You have an Azure Virtual Desktop deployment that contains the resources shown in the following table.
You plan to enable Start VM on connect for Pool1.
You create a custom Azure role named Role1 that has sufficient permissions to start virtual machines on demand.
You need to ensure that the session hosts in Pool1 can start on demand.
To which service principal should you assign Role1?
- A. Azure Compute
- B. Host1
- C. Managed1
- D. Azure Automation
- E. Azure Virtual Desktop
Answer: E
NEW QUESTION # 70
You have an Azure Virtual Desktop deployment that contains the resources shown in the following table.
You need to enable just-in-time (JIT) VM access for all the session hosts.
What should you do first?
- A. Configure Access control (IAM) for HostPool1.
- B. Deploy Azure Bastion to VNET1.
- C. Assign a network security group (NSG) to Subnet1.
- D. Assign network security groups (NSGs) to the network interfaces of the five session hosts.
Answer: D
NEW QUESTION # 71
You have a new Azure subscription that uses Azure Virtual Desktop.
You need to ensure that users who connect to Azure Virtual Desktop sessions reauthenticate every six hours. What should you do first?
- A. Disable Security defaults.
- B. Create a Conditional Access policy.
- C. Configure multi-factor authentication (MFA).
- D. Configure an authentication methods policy.
Answer: C
NEW QUESTION # 72
You have a Windows Virtual Desktop deployment.
You plan to create the host pools shown in the following table.
You need to recommend the virtual machine size for each host pool. The solution must minimize costs.
Which size should you recommend for each pool? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/azure/virtual-machines/sizes
https://docs.microsoft.com/en-us/azure/virtual-machines/nvv3-series
https://docs.microsoft.com/en-us/azure/virtual-machines/dv4-dsv4-series
NEW QUESTION # 73
Hotspot Question
You plan to deploy Azure Virtual Desktop.
Users have the devices shown in the following table.
From which device types can the users connect to Azure Virtual Desktop resources by using the Remote Desktop client app and the Remote Desktop web client? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
There are RDC apps in Windows, Android, and MacOS stores.
For the web client, you'll need a PC running Windows, macOS, ChromeOS, or Linux. Mobile devices aren't supported at this time.
https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/remote- desktop-web-client
NEW QUESTION # 74
-
You have an Azure Virtual Desktop deployment that contains the session hosts shown in the following table.
You have the users shows in the following table.
Users connect to Azure from the locations shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Text, letter Description automatically generated
NEW QUESTION # 75
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have the following:
A Microsoft 365 E5 tenant
An on-premises Active Directory domain
A hybrid Azure Active Directory (Azure AD) tenant
An Azure Active Directory Domain Services (Azure AD DS) managed domain
An Azure Virtual Desktop deployment
The Azure Virtual Desktop deployment contains personal desktops that are hybrid joined to the on-premises domain and enrolled in Microsoft Intune.
You need to configure the security settings for the Microsoft Edge browsers on the personal desktops.
Solution: You configure a Group Policy Object (GPO) in the Azure AD DS managed domain.
Does this meet the goal?
- A. Yes
- B. No
Answer: B
Explanation:
Reference:
https://www.compete366.com/blog-posts/eight-tips-on-how-to-manage-azure-virtual-desktop-avd/
NEW QUESTION # 76
You have a Windows Virtual Desktop deployment.
You need to ensure that all the connections to the managed resources in the host pool require multi-factor authentication (MFA).
Which two settings should you modify in a conditional access policy? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-azure-mfa
NEW QUESTION # 77
You need to deploy the session hosts to meet the deployment requirements Which PowerShell cmdlel should you run first?
- A. New-AzwvdRegistratrationinfo
- B. Update-AZwvdSessionHost
- C. Get-AzApiManagementSsoToken
- D. Set-AzWMADDomainExtension
Answer: A
Explanation:
Reference:
https://rozemuller.com/avd-automation-cocktail-avd-automated-with-powershell/
NEW QUESTION # 78
You have an Azure Virtual Desktop deployment.
The session hosts are joined to an on-premises Active Directory domain named contoso.com.
You need to limit user sessions to three hours.
What should you configure?
- A. the properties of the workspace
- B. the RDP Properties of a host pool
- C. just-in-time (JIT) VM access
- D. a Group Policy Object (GPO) in contoso.com.
Answer: D
Explanation:
Configure a Group Policy Object (GPO) and set the LimitSecondsToForceLogOffUser parameter to zero. This allows the session configuration setting in specified group policies to handle signing off user sessions.
https://docs.microsoft.com/en-gb/learn/modules/automate-azure-virtual-desktop-management- tasks/6-knowledge-check
NEW QUESTION # 79
You have an Azure Virtual Desktop deployment and the users shown in the following table.
All the users plan to use a web browser to access Azure Virtual Desktop resources.
Which users can connect to Azure Virtual Desktop by using their preferred browser?
- A. User2 and User3 only
- B. User2 only
- C. User1 and User2 only
- D. User1 only
- E. User1, User2, and User3
Answer: E
Explanation:
https://learn.microsoft.com/en-us/azure/virtual-desktop/users/connect-web
NEW QUESTION # 80
You have an Azure Virtual Desktop Deployment that contains a workspace named Workspace1 and a user named User1. Workspace1 contains a Desktop application group named Pool1Desktop.
At 09:00, you create a conditional access policy that has the following settings:
* Assignments:
- Users and groups: User1
- Cloud apps or actions: Azure Virtual Desktop
- Conditions: 0 conditions selected
* Access controls
- Grant: Grant access, Require multi-factor authentication
- Sessions: Sign-in frequency 1 hour
User1 performs the actions shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Text Description automatically generated
Reference:
https://docs.microsoft.com/en-us/azure/virtual-desktop/set-up-mfa
NEW QUESTION # 81
......
Verified AZ-140 exam dumps Q&As with Correct 264 Questions and Answers: https://www.passtestking.com/Microsoft/AZ-140-practice-exam-dumps.html
AZ-140 Dumps PDF and Test Engine Exam Questions: https://drive.google.com/open?id=1aw1NgOlj6vYZr0pPOhY3QRs8a9GlOZxb