Free Microsoft AZ-104 Exam Questions (page: 6)

HOTSPOT (Drag and Drop is not supported)
You have a hybrid deployment of Microsoft Entra ID that contains the users shown in the following table.


You need to modify the JobTitle and UsageLocation attributes for the users.
For which users can you modify the attributes from Microsoft Entra ID? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Box 1: User1 and User3 only
You must use Windows Server Active Directory to update the identity, contact info, or job info for users whose source of authority is Windows Server Active Directory.
Box 2: User1, User2, and User3 Reference:
https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-users-profile-azure-portal



Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You need to ensure that a Microsoft Entra user named Admin1 is assigned the required role to enable Traffic Analytics for an Azure subscription.
Solution: You assign the Network Contributor role at the subscription level to Admin1. Does this meet the goal?

  1. Yes
  2. No

Answer(s): A

Explanation:

Your account must meet one of the following to enable traffic analytics:
Your account must have any one of the following Azure roles at the subscription scope: owner, contributor, reader, or network contributor.


Reference:

https://docs.microsoft.com/en-us/azure/network-watcher/traffic-analytics-faq



Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You need to ensure that a Microsoft Entra user named Admin1 is assigned the required role to enable Traffic Analytics for an Azure subscription.
Solution: You assign the Owner role at the subscription level to Admin1. Does this meet the goal?

  1. Yes
  2. No

Answer(s): A

Explanation:

Your account must meet one of the following to enable traffic analytics:
Your account must have any one of the following Azure roles at the subscription scope: owner, contributor, reader, or network contributor.


Reference:

https://docs.microsoft.com/en-us/azure/network-watcher/traffic-analytics-faq



Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You need to ensure that a Microsoft Entra user named Admin1 is assigned the required role to enable Traffic Analytics for an Azure subscription.
Solution: You assign the Reader role at the subscription level to Admin1. Does this meet the goal?

  1. Yes
  2. No

Answer(s): B



You have an Azure subscription that contains a user named User1.
You need to ensure that User1 can deploy virtual machines and manage virtual networks. The solution must use the principle of least privilege.
Which role-based access control (RBAC) role should you assign to User1?

  1. Owner
  2. Virtual Machine Contributor
  3. Contributor
  4. Virtual Machine Administrator Login

Answer(s): C

Explanation:

Contributor: Grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC
Incorrect Answers:
A: Owner: Grants full access to manage all resources, including the ability to assign roles in Azure RBAC.
B: Virtual Machine Contributor: Lets you manage virtual machines, but not access to them, and not the virtual network or storage account they're connected to.
D: Virtual Machine Administrator Login: View Virtual Machines in the portal and login as administrator.


Reference:

https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles



HOTSPOT (Drag and Drop is not supported)
You have a Microsoft Entra tenant that contains three global administrators named Admin1, Admin2, and Admin3.
The tenant is associated to an Azure subscription. Access control for the subscription is configured as shown in the Access control exhibit. (Click the Access Control tab.)


You sign in to the Azure portal as Admin1 and configure the tenant as shown in the Tenant exhibit. (Click the
Tenant tab.)


For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Box 1: No
Only Admin3, the owner, can assign ownership. Box 2: Yes
Box 3: No


Reference:

https://docs.microsoft.com/en-us/azure/cost-management-billing/manage/add-change-subscription- administrator



You have an Azure subscription named Subscription1 that contains an Azure virtual machine named VM1. VM1 is in a resource group named RG1.
VM1 runs services that will be used to deploy resources to RG1.
You need to ensure that a service running on VM1 can manage the resources in RG1 by using the identity of VM1.
What should you do first?

  1. From the Azure portal, modify the Managed Identity settings of VM1
  2. From the Azure portal, modify the Access control (IAM) settings of RG1
  3. From the Azure portal, modify the Access control (IAM) settings of VM1
  4. From the Azure portal, modify the Policies settings of RG1

Answer(s): A

Explanation:

Managed identities for Azure resources provides Azure services with an automatically managed identity in Microsoft Entra ID. You can use this identity to authenticate to any service that supports Microsoft Entra authentication, without having credentials in your code.
You can enable and disable the system-assigned managed identity for VM using the Azure portal.


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/qs-configure-
portal-windows-vm



You have an Azure subscription that contains a resource group named TestRG. You use TestRG to validate an Azure deployment.
TestRG contains the following resources:


You need to delete TestRG. What should you do first?

  1. Modify the backup configurations of VM1 and modify the resource lock type of VNET1
  2. Remove the resource lock from VNET1 and delete all data in Vault1
  3. Turn off VM1 and remove the resource lock from VNET1
  4. Turn off VM1 and delete all data in Vault1

Answer(s): B



Viewing page 6 of 69



Post your Comments and Discuss Microsoft AZ-104 exam prep with other Community members:

AZ-104 Exam Discussions & Posts