Free Microsoft AZ-104 Exam Braindumps (page: 43)

HOTSPOT (Drag and Drop is not supported)
You have a Microsoft Entra tenant that contains the groups shown in the following table.


The tenant contains the users shown in the following table.


Which users and groups can you delete? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Box 1: User1 and User4 only Users:
User4 - Yes
User1 - Yes
User1 is not a member of group. User1 has a direct assigned license.
When you use direct assignment, the following operations are allowed:
Licenses not already assigned through group-based licensing can be changed for an individual user. Other services can be enabled, as part of a directly assigned license.
Directly assigned licenses can be removed and don’t affect a user's inherited licenses.
User2 - No
User2 is a member of Group1.
Direct licenses coexist with group licenses
When a user inherits a license from a group, you can't directly remove or modify that license in the user's properties.
Box 2: Group2 and Group4 only Groups:
Group1 - No
Group3 is a Security group and it has an assigned license.
It isn't possible to delete a group with an active license assigned.
Group2 - Yes
Group2 is a security group and has no assigned license.
Group3 - No
Group3 is a Microsoft 365 group and it has an assigned license. It isn't possible to delete a group with an active license assigned.
Group4 - Yes
Group4 has no assigned license.


Reference:

https://learn.microsoft.com/en-us/entra/identity/users/licensing-group-advanced



You have an Azure subscription that contains the resources shown in the following table.


You need to ensure that data transfers between storage1 and VM1 do NOT traverse the internet What should you configure for storage1?

  1. data protection
  2. a private endpoint
  3. Public network access in the Firewalls and virtual networks settings
  4. a shared access signature (SAS)

Answer(s): B

Explanation:

You can use private endpoints for your Azure Storage accounts to allow clients on a virtual network (VNet) to securely access data over a Private Link. The private endpoint uses a separate IP address from the VNet address space for each storage account service. Network traffic between the clients on the VNet and the storage account traverses over the VNet and a private link on the Microsoft backbone network, eliminating exposure from the public internet.


Reference:

https://learn.microsoft.com/en-us/azure/storage/common/storage-private-endpoints



HOTSPOT (Drag and Drop is not supported)
You have a Microsoft Entra tenant that is linked to the subscriptions shown in the following table.


You have the resource groups shown in the following table.


You assign roles to users as shown in the following table.


For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Box 1: Yes
Yes - User1 can resize VM1.
User1 is Contributor with scope MG2. MG2 is a management group in Sub3. MG2 is a Tenant route group.
RG3, in Sub3, contains VM1.
Note: Each Microsoft Entra tenant is given a single top-level management group called the root management group. This root management group is built into the hierarchy to have all management groups and subscriptions fold up to it.
Note 2: Contributor:
Grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC, manage assignments in Azure Blueprints, or share image galleries.
Box 2: No
No - User2 can create a new storage account in RG1.
User2 is Storage account Contributor with scope storage1. RG1 is in Sub1 and contains storage1.
Scope for User2 is Storage1 only, not RG1. Note: Storage Account Contributor
Permits management of storage accounts. Provides access to the account key, which can be used to access data via Shared Key authorization.
Actions include:
Create and manage storage accounts
Box 3: Yes
Yes - User3 can assign User1 the Owner role for RG3.
User3 is User Access Administrator for the Tenant Root Group.
Note: The User Access Administrator role enables the user to grant other users access to Azure resources. Manage user access to Azure resources
Assign roles in Azure RBAC
Assign themselves or others the Owner role


Reference:

https://learn.microsoft.com/en-us/azure/defender-for-cloud/management-groups-roles https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles



Your on-premises network contains a VPN gateway.
You have an Azure subscription that contains the resources shown in the following table.


You need to ensure that all the traffic from VM1 to storage1 travels across the Microsoft backbone network. What should you configure?

  1. a network security group (NSG)
  2. private endpoints
  3. Microsoft Entra Application Proxy
  4. Azure Virtual WAN

Answer(s): B

Explanation:

For this question with different alternatives:
Correct answers:
* private endpoints
service endpoints
Incorrect answers include:
* a network security group (NSG)
* Microsoft Entra Application Proxy
* Azure Application Gateway
* Azure Firewall
* Azure Peering Service
Azure Virtual WAN
Explanations for correct answers:
private endpoints-
You can use private endpoints for your Azure Storage accounts to allow clients on a virtual network (VNet) to securely access data over a Private Link. The private endpoint uses a separate IP address from the VNet address space for each storage account service. Network traffic between the clients on the VNet and the storage account traverses over the VNet and a private link on the Microsoft backbone network, eliminating exposure from the public internet.
* service endpoints-
Private endpoints can be created in subnets that use Service Endpoints. Clients in a subnet can thus connect to one storage account using private endpoint, while using service endpoints to access others.


Reference:

https://learn.microsoft.com/en-us/azure/storage/common/storage-private-endpoints






Post your Comments and Discuss Microsoft AZ-104 exam prep with other Community members:

AZ-104 Exam Discussions & Posts