Microsoft Azure Administrator - AZ-104 Exam Practice Test

You have two Azure virtual machines named VM1 and VM2 that run Windows Server. The virtual machines are in a subnet named Subnet1. Subnet1 is in a virtual network named VNet1. You need to prevent VM1 from accessing VM2 on port 3389.
What should you do?
Correct Answer: B Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
You configure the custom role shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE Each correct selection is worth one point.

Exhibit

Exhibit
Correct Answer:

Explanation:
CORRECTED ANSWER: To ensure that users can sign in to virtual machines that are assigned role1, modify the: dataActions section. To ensure that role1 can be assigned only to a resource group named RG1, modify the: assignableScopes section.
Detailed Explanation
Signing in to an Azure VM via Microsoft Entra ID authentication (Azure AD login) is controlled by a data- plane permission -- specifically the Microsoft.Compute/virtualMachines/login/action (or loginAsAdmin) dataAction, corresponding to the built-in Virtual Machine User Login / Virtual Machine Administrator Login roles. Role1 ' s dataActions array is currently empty, so no sign-in permission is granted no matter how broad its management-plane actions array is; the fix is to add the login dataAction to dataActions, not to the actions array (which only governs ARM control-plane operations like start/stop/resize) and not to roletype, which is merely a descriptive metadata string with no effect on permissions. The source key ' s selection of ' roletype ' for the first blank does not accomplish the stated goal and is corrected to ' dataActions. ' For the second statement, assignableScopes is the property that restricts which scopes (subscriptions, resource groups) a custom role can be assigned at, so setting it to RG1 ' s resource group ID is correct and matches the original key.
Official Reference
Azure custom roles - actions, dataActions, and assignableScopes - https://learn.microsoft.com/en-us/azure
/role-based-access-control/custom-roles
You have an Azure subscription that contains two Log Analytics workspaces named Workspace 1 and Workspace? and 100 virtual machines that run Windows Server.
You need to collect performance data and events from the virtual machines. The solution must meet the following requirements:
* Logs must be sent to Workspace! and Workspace?
* All Windows events must be captured
* All security events must be captured.
What should you install and configure on each virtual machine?
Correct Answer: B Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
You have an Azure subscription that contains the virtual machines shown in the following table.
You deploy a load balancer that has the following configurations:
* Name: LB 1
* Type: Internal
* SKU: Standard
* Virtual network: VNET1
You need to ensure that you can add VM1 and VM2 to the backend pool of L81.
Solution: You create two Standard SKU public IP addresses and associate a Standard SKU public IP address to the network interface of each virtual machine.
Does this meet the goal?
Correct Answer: A Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft Entra tenant named Adatum.com and an Azure Subscription named Subscription1.
Adatum.com contains a group named Developers. Subscription1 contains a resource group named Dev.
You need to provide the Developers group with the ability to create Azure Logic Apps in the Dev resource group.
Solution: On Subscription1, you assign the DevTest Labs User role to the Developers group.
Does this meet the goal?
Correct Answer: A Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You manage a virtual network named VNet1 that is hosted in the West US Azure region.
VNet1 hosts two virtual machines named VM1 and VM2 that run Windows Server.
You need to inspect all the network traffic from VM1 to VM2 for a period of three hours.
Solution: From Azure Monitor, you create a metric on Network in and Network Out.
Does this meet the goal?
Correct Answer: A Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
You purchase a new Azure subscription.
You create an Azure Resource Manager (ARM) template named deployjson as shown in the following exhibit.
You connect to the subscription and run the following command.
New-AzDeploynent -Location westus -TeaplateFile " deploy.json "
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit
Correct Answer:

Explanation:
CORRECTED ANSWER: Three resource groups are created when you run the script: No (four are created - RGS0, RGS1, ResGrp8, RGroup4). A resource group named RGroup5 is created: No (length(parameters( ' obj1 ' )) evaluates to 4, so the name is RGroup4, not RGroup5). All the resource groups are created in the East US Azure region: Yes.
Detailed Explanation
Microsoft.Resources/resourceGroups can only be deployed via a subscription-level deployment such as New- AzDeployment, matching the command shown; the -Location parameter only stores deployment metadata and does not set any resource ' s location. The ' copy ' element on resource 1 with count=2 creates two separate resource group instances using copyIndex() (0 and 1), producing RGS0 and RGS1 - combined with the two standalone resources (ResGrp8 and RGroup-with-length), that totals four resource groups, not three, so statement 1 is No. The ARM length() function applied to an object returns its count of top-level properties; obj1 has exactly four (propA, propB, propC, propD), so the third resource is named RGroup4, not RGroup5
- statement 2 is No. Every resource ' s location resolves to eastus (explicit literal, last(var1), and par1 ' s default), so statement 3 is Yes.
Official Reference
Resource iteration in ARM templates (copy) and template functions - https://learn.microsoft.com/en-us/azure
/azure-resource-manager/templates/copy-resources
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft Entra tenant named contoso.com.
You have a CSV file that contains the names and email addresses of 500 external users.
You need to create a guest user account in contoso.com for each of the 500 external users.
Solution; From Microsoft Entra ID in the Azure portal, you use the Bulk invite users ' operation.
Does this meet the goal?
Correct Answer: B Vote an answer
You have an Azure subscription that contains a web app named webapp1. You need to add a custom domain named www.contoso.com to webapp1. What should you do first?
Correct Answer: C Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
You have an Azure virtual machine named VM1.
You use Azure Backup to create a backup of VM1 named Backup1.
After creating Backup1, you perform the following changes to VM1:
Modify the size of VM1.
Copy a file named Budget.xls to a folder named Data.
Reset the password for the built-in administrator account.
Add a data disk to VM1.
An administrator uses the Replace existing option to restore VM1 from Backup1.
You need to ensure that all the changes to VM1 are restored.
Which change should you perform again?
Correct Answer: C Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an app named App1 that is installed on two Azure virtual machines named VM1 and VM2.
Connections to Appl are managed by using an Azure Load Balancer.
The effective network security configurations for VM2 are shown in the following exhibit.
You discover that connections 10 App1 from 131.107.100.50 over TCP port 443 fail.
You verity that the Load Balancer rules are configured correctly.
You need to ensure that connections to App1 can be established successfully from 131.107.100.50 over TCP port 443.
Solution: You create an inbound security rule that allows any traffic from the Azureload Balancer source and has a priority of 150.
Does this meet the goal?

Exhibit
Correct Answer: A Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
You have an Azure subscription.
You need to use an Azure Resource Manager (ARM) template to create a virtual machine that will have multiple data disks.
How should you complete the template? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Correct Answer:

Explanation:
Detailed Explanation
ARM templates use the ' copy ' element to iterate resource sub-properties such as dataDisks a variable number of times, driven by a ' count ' expression referencing the numberOfDataDisks parameter. Within each iteration, copyIndex( ' dataDisks ' ) returns the current 0-based iteration index, which is exactly what ' s needed to assign a unique, sequential ' lun ' (logical unit number) to each generated data disk. ' copyIndex ' alone (without the loop name) would be ambiguous when multiple copy loops exist in the same resource, and ' dependsOn ' is an unrelated property used to declare deployment ordering, not iteration. The exhibit ' s highlighted selections ( " copy " :[ and " [copyIndex) correctly implement this standard multiple-data-disk template pattern, so no correction is needed.
Official Reference
Resource iteration in ARM templates (copy) - https://learn.microsoft.com/en-us/azure/azure-resource- manager/templates/copy-resources