Free Microsoft AZ-104 Exam Braindumps (page: 11)

You have an Azure subscription that contains a user named User1.
You need to ensure that User1 can deploy virtual machines and manage virtual networks. The solution must use the principle of least privilege.
Which role-based access control (RBAC) role should you assign to User1?

  1. Owner
  2. Virtual Machine Contributor
  3. Contributor
  4. Virtual Machine Administrator Login

Answer(s): C

Explanation:

Contributor: Grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC
Incorrect Answers:
A: Owner: Grants full access to manage all resources, including the ability to assign roles in Azure RBAC.
B: Virtual Machine Contributor: Lets you manage virtual machines, but not access to them, and not the virtual network or storage account they're connected to.
D: Virtual Machine Administrator Login: View Virtual Machines in the portal and login as administrator.


Reference:

https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles



HOTSPOT (Drag and Drop is not supported)
You have a Microsoft Entra tenant that contains three global administrators named Admin1, Admin2, and Admin3.
The tenant is associated to an Azure subscription. Access control for the subscription is configured as shown in the Access control exhibit. (Click the Access Control tab.)


You sign in to the Azure portal as Admin1 and configure the tenant as shown in the Tenant exhibit. (Click the
Tenant tab.)


For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Box 1: No
Only Admin3, the owner, can assign ownership. Box 2: Yes
Box 3: No


Reference:

https://docs.microsoft.com/en-us/azure/cost-management-billing/manage/add-change-subscription- administrator



You have an Azure subscription named Subscription1 that contains an Azure virtual machine named VM1. VM1 is in a resource group named RG1.
VM1 runs services that will be used to deploy resources to RG1.
You need to ensure that a service running on VM1 can manage the resources in RG1 by using the identity of VM1.
What should you do first?

  1. From the Azure portal, modify the Managed Identity settings of VM1
  2. From the Azure portal, modify the Access control (IAM) settings of RG1
  3. From the Azure portal, modify the Access control (IAM) settings of VM1
  4. From the Azure portal, modify the Policies settings of RG1

Answer(s): A

Explanation:

Managed identities for Azure resources provides Azure services with an automatically managed identity in Microsoft Entra ID. You can use this identity to authenticate to any service that supports Microsoft Entra authentication, without having credentials in your code.
You can enable and disable the system-assigned managed identity for VM using the Azure portal.


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/qs-configure-
portal-windows-vm



You have an Azure subscription that contains a resource group named TestRG. You use TestRG to validate an Azure deployment.
TestRG contains the following resources:


You need to delete TestRG. What should you do first?

  1. Modify the backup configurations of VM1 and modify the resource lock type of VNET1
  2. Remove the resource lock from VNET1 and delete all data in Vault1
  3. Turn off VM1 and remove the resource lock from VNET1
  4. Turn off VM1 and delete all data in Vault1

Answer(s): B



Viewing page 11 of 137
Viewing questions 41 - 44 out of 553 questions



Post your Comments and Discuss Microsoft AZ-104 exam prep with other Community members:

AZ-104 Exam Discussions & Posts