Free AZ-104 Exam Dumps

No Installation Required, Instantly Prepare for the AZ-104 exam and please click the below link to start the AZ-104 Exam Simulator with a real AZ-104 practice exam questions.
Use directly our on-line AZ-104 exam dumps materials and try our Testing Engine to pass the AZ-104 which is always updated.

  • Exam Code: AZ-104
  • Exam Title: Microsoft Azure Administrator
  • Vendor: Microsoft
  • Exam Questions: 454
  • Last Updated: September 27th,2024

Question 1

- (Exam Topic 5)
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource groups.
Another administrator plans to create several network security groups (NSGs) in the subscription.
You need to ensure that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks.
Solution: You configure a custom policy definition, and then you assign the policy to the subscription. Does this meet the goal?

Correct Answer:A
Resource policy definition used by Azure Policy enables you to establish conventions for resources in your organization by describing when the policy is enforced and what effect to take. By defining conventions, you can control costs and more easily manage your resources.
References: https://docs.microsoft.com/en-us/azure/azure-policy/policy-definition

Question 2

- (Exam Topic 4)
You have an Azure subscription that contains the resource groups shown in the following table.
AZ-104 dumps exhibit
RG1 contains the resources shown in the following table.
AZ-104 dumps exhibit
RG2 contains the resources shown in the following table.
AZ-104 dumps exhibit
You need to identify which resources you can move from RG1 to RG2, and which resources you can move from RG2 to RG1.
Which resources should you identify? To answer, select the appropriate options in the answer area.
AZ-104 dumps exhibit
Solution:
Read only and Delete lock won't prevent you from moving resources in different resource groups. It will prevent you to do the operations in the resource group where the resources are there.
So the correct answer should be
RG1 --> RG2 = IP1, vnet1 and storage1 RG2 --> RG1 = IP2, vnet2 and storage2 Reference:
https://docs.microsoft.com/en-us/azure/governance/blueprints/concepts/resource-locking

Does this meet the goal?

Correct Answer:A

Question 3

- (Exam Topic 6)
You create an Azure subscription that is associated to a basic Azure Active Directory (Azure AD) tenant. You need to receive an email notification when any user activates an administrative role.
What should you do?

Correct Answer:A
When key events occur in Azure AD Privileged Identity Management (PIM), email notifications are sent. For example, PIM sends emails for the following events:
AZ-104 dumps exhibit When a privileged role activation is pending approval
AZ-104 dumps exhibit When a privileged role activation request is completed
AZ-104 dumps exhibit When a privileged role is activated
AZ-104 dumps exhibit When a privileged role is assigned
AZ-104 dumps exhibit When Azure AD PIM is enabled
References:
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-email-notifications

Question 4

- (Exam Topic 6)
You onboard 10 Azure virtual machines to Azure Automation State Configuration.
You need to use Azure Automation State Configuration to manage the ongoing consistency of the virtual machine configurations.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
NOTE: More than one order of answer choices is correct. You will receive credit for any of the correct orders you select.
AZ-104 dumps exhibit
Solution:
Step 1: Upload a configuration to Azure Automation State Configuration. Import the configuration into the Automation account.
Step 2: Compile a configuration into a node configuration.
A DSC configuration defining that state must be compiled into one or more node configurations (MOF document), and placed on the Automation DSC Pull Server.
Step 3: Assign the node configuration
Step 4: Check the compliance status of the node
Each time Azure Automation State Configuration performs a consistency check on a managed node, the node sends a status report back to the pull server. You can view these reports on the page for that node.
On the blade for an individual report, you can see the following status information for the corresponding consistency check:
The report status — whether the node is "Compliant", the configuration "Failed", or the node is "Not
Compliant" Reference:
https://docs.microsoft.com/en-us/azure/automation/automation-dsc-getting-started

Does this meet the goal?

Correct Answer:A

Question 5

- (Exam Topic 4)
You have an Azure subscription that contains the resources in the following table.
AZ-104 dumps exhibit
VM1 and VM2 are deployed from the same template and host line-of-business applications accessed by using Remote Desktop. You configure the network security group (NSG) shown in the exhibit. (Click the Exhibit button.)
AZ-104 dumps exhibit
You need to prevent users of VM1 and VM2 from accessing websites on the Internet.
What should you do?

Correct Answer:A
You can associate or dissociate a network security group from a network interface or subnet.
The NSG has the appropriate rule to block users from accessing the Internet. We just need to associate it with Subnet1.
References: https://docs.microsoft.com/en-us/azure/virtual-network/manage-network-security-group