To add or delete users from your Azure Active Directory (Azure AD) organization, you must be
a user administrator or Global Administrator.
1. In RG-01,
... [Show More] you create an internal load balancer named LB-01. You need to ensure that an
administrator named Admin-01 can manage LB-01 and is allowed to add a backend pool
to LB-01. The solution must follow the principle of least privilege.
Which role should you assign to Admin-01?
A. Network Contributor on RG-01.
2. You have an Azure subscription named Subscription-Prod that contains a
resource group named RG-01.
In RG-01, you create a public load balancer named LB-02. You need to ensure that an
administrator named Admin-01 can manage LB-02 and is allowed to add a health probe
to LB-02. The solution must follow the principle of least privilege.
A. Network Contributor on RG-01.
3. You need to create groups for the users. The solution must ensure that the groups are
deleted automatically after 180 days.
Which two groups should you create? (SELECT TWO) Each correct answer presents a
complete solution.
A. Assigned membership type for office 365 and dynamic user membership type
4. You have an Azure Storage account named storage-01. You plan to use AzCopy to copy data
to storage-01.
Which of the following are valid storage services in storage-01 that you can copy data to?
A.Blob and file only
5. You have an Azure Storage account named storage-01 that uses Azure Blob storage. You need
to use AzCopy to copy data to blob storage, in storage account storage-01.
Which authentication method should you use for blob storage?
A. Azure AD and SAS shared access signatures only token
6. You have an Azure subscription that contains an Azure Storage account. You need to create an
Azure container instance that will use a Docker image. The image contains a Microsoft SQL
Server instance that requires persistent storage.
You need to configure a storage service for your container. What Azure service should you use?
A Azure files
7. You have deployed in Azure an application App1, on two Azure virtual machines named VM1
and VM2. You plan to implement an Azure Availability Set for App1. The solution must ensure
that App1 is available during planned maintenance of the servers hosting VM1 and VM2.
What should you include in the Availability Set?
A. Two update domains
8. You want to monitor the metrics and the logs of your Linux virtual machine VM-01.
Which of the following Azure services would you use for this task?
A. Linux diagnostic extension LAD 3.0
9. You have an Azure virtual machine named VM-01 that runs Windows Server 2019. You save
VM-01 as a template named VM-Template to the Azure Resource Manager library. You plan to
deploy a virtual machine named VM-02 from VM_Template, using Azure Portal
What can you configure during the deployment of VM-02?
A.Resource groups
10. You have an Azure subscription that contains an Azure virtual machine named VM-01. VM01 runs an application that does not support multiple active instances.
At the end of each month, CPU usage for VM-01 peaks when the application runs. You need to
create a scheduled runbook to increase the processor performance of VM-01 at the end of each
month.
What task should you include in the runbook?
A. Modify VM size property of VM-01
11. You have a computer named Computer-01 that has a point-to-site VPN connection to an
Azure virtual network named AZ-104-vNET. The point-to-site connection uses a self-signed
certificate.
From Azure, you download and install the VPN client configuration package on a computer
named Computer-02. You need to ensure that you can establish a point-to-site VPN connection
to AZ-104-vNET from Computer-02.
Solution: You modify the Azure Active Directory (Azure AD) authentication policies.
No we should use certificates
12. You create the following resources in an Azure subscription:
- An Azure Container Registry instance named Registry1
- An Azure Kubernetes Service (AKS) cluster named Cluster1
You create a container image named App1 on your administrative workstation.
You need to deploy App1 to Cluster1.
What should you do first?
A. Run AZ ACr build
1: Upload a configuration to Azure Automation State Configuration. Import the configuration
into the Automation account.
Step 2: Compile a configuration into a node configuration. A DSC configuration defining that
state must be compiled into one or more node configurations (MOF document), and placed on
the Automation DSC Pull Server.
Step 3: Onboard the virtual machines to Azure Automation State Configuration. Onboard the
Azure VM for management with Azure Automation State Configuration
Step 4: Assign the node configuration
Step 5: Check the compliance status of the node Each time Azure Automation State
Configuration performs a con
...........................................................................................................................................................................................CONTINUE [Show Less]