Free Microsoft AZ-104 Exam Braindumps (page: 19)

You have an Azure subscription that contains 10 virtual machines, a key vault named Vault1, and a network security group (NSG) named NSG1. All the resources are deployed to the East US Azure region.
The virtual machines are protected by using NSG1. NSG1 is configured to block all outbound traffic to the internet.
You need to ensure that the virtual machines can access Vault1. The solution must use the principle of least privilege and minimize administrative effort.
What should you configure as the destination of the outbound security rule for NSG1?

  1. an application security group
  2. a service tag
  3. an IP address range

Answer(s): B

Explanation:

Virtual network service tags
A service tag represents a group of IP address prefixes from a given Azure service. Microsoft manages the address prefixes encompassed by the service tag and automatically updates the service tag as addresses change, minimizing the complexity of frequent updates to network security rules.
Available service tags
The following table includes all the service tags available for use in network security group rules. The columns indicate whether the tag:
Is suitable for rules that cover inbound or outbound traffic. Supports regional scope.
Is usable in Azure Firewall rules as a destination rule only for inbound or outbound traffic.
Service Tag AzureKeyVault Purpose Azure Key Vault.
Suitable for Outbound traffic Can be regional
Can use Azure Firewall
Etc. Reference:
https://learn.microsoft.com/en-us/azure/virtual-network/service-tags-overview



You have a Microsoft Entra tenant named adatum.com that contains the groups shown in the following table.


Adatum.com contains the users shown in the following table.


You assign the Microsoft Entra ID P2 license to Group1 and User4. Which users are assigned the Microsoft Entra ID P2 license?

  1. User4 only
  2. User1 and User4 only
  3. User1, User2, and User4 only
  4. User1, User2, User3, and User4

Answer(s): B

Explanation:

* User1 is member of Group1, which has Microsoft Entra ID P2 license directly assigned to it.
* User4 has license directly assigned to it.
Note: Assign licenses to users or groups
Make sure that anyone needing to use a licensed Microsoft Entra service has the appropriate license. You can add the licensing rights to users or to an entire group.


Reference:

https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/license-users-groups



HOTSPOT (Drag and Drop is not supported)
You have a Microsoft Entra tenant named contoso.com.
You have two external partner organizations named fabrikam.com and litwareinc.com. Fabrikam.com is configured as a connected organization.
You create an access package as shown in the Access package exhibit. (Click the Access package tab.)


You configure the external user lifecycle settings as shown in the Lifecycle exhibit. (Click the Lifecycle tab.)


For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Box 1: Yes
Access package include the setting: Users who can request access: All configured connected organizations This allow users in connected organizations (other directories and domains) to request this access package.
Box 2: No
From the first exhibit we see that Access package assignments expires after 365 days.
From the second exhibit, however, we see that there is a further delay of 30 days before users are removed from Group1.
Box 3: Yes
365+30 days is 395 days. Users will be removed after 395 days.


Reference:

https://learn.microsoft.com/en-us/azure/active-directory/governance/entitlement-management-access- package-first



You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. VNet1 is in a resource group named RG1.
Subscription1 has a user named User1. User1 has the following roles: Reader
Security Admin Security Reader
You need to ensure that User1 can assign the Reader role for VNet1 to other users. What should you do?

  1. Assign User1 the Network Contributor role for VNet1.
  2. Remove User1 from the Security Reader role for Subscription1. Assign User1 the Contributor role for RG1.
  3. Assign User1 the Owner role for VNet1.
  4. Assign User1 the Network Contributor role for RG1.

Answer(s): C

Explanation:

Owner role - Grants full access to manage all resources, including the ability to assign roles in Azure RBAC.
Incorrect:
Not A, Not D:
Network Contributor
Lets you manage networks, but not access to them. Actions:
Microsoft.Authorization/*/read - Read roles and role assignments Microsoft.Insights/alertRules/*- Create and manage a classic metric alert Microsoft.Network/* - Create and manage networks
Microsoft.ResourceHealth/availabilityStatuses/read - Gets the availability statuses for all resources in the specified scope
Microsoft.Resources/deployments/* - Create and manage a deployment Microsoft.Resources/subscriptions/resourceGroups/read - Gets or lists resource groups. Microsoft.Support/*- Create and update a support ticket
Not B:
Contributor role - Grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC, manage assignments in Azure Blueprints, or share image galleries.


Reference:

https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles



Viewing page 19 of 137
Viewing questions 73 - 76 out of 553 questions



Post your Comments and Discuss Microsoft AZ-104 exam prep with other Community members:

AZ-104 Exam Discussions & Posts