Preview real exam questions, verified answers and available explanations before choosing a study plan.
Question 1
Hotspot
HOTSPOT
Select the answer that correctly completes the sentence.
Reveal answer detailsClose answer details
Explanation
Box: Azure Active Directory (Azure AD) You can enable single sign-on for an enterprise application through Azure Active Directory (Azure AD.
Azure Active Directory enables users to authenticate to multiple applications by using single sign-on.
Incorrect: Application security groups enable you to configure network security as a natural extension of an application's structure, allowing you to group virtual machines and define network security policies based on those groups. References: https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/add-application-portal-setup-sso
Question 2
Single choice
What is the function of a Site-to-Site VPN?
A
provides a secure connection between a computer on a public network and the corporate network
B
provides a connection from an on-premises VPN device to an Azure VPN gateway
C
provides a dedicated private connection to Azure that does NOT travel over the internet
Reveal answer detailsClose answer details
Correct answerB
Question 3
Multiple choice
Your company has an on-premises network that contains multiple servers.
The company plans to reduce the following administrative responsibilities of network administrators:
1. Backing up application data 2. Replacing failed server hardware 3. Managing physical server security 4. Updating server operating systems 5. Managing permissions to shared documents
The company plans to migrate several servers to Azure virtual machines.
You need to identify which administrative responsibilities will be eliminated after the planned migration.
Which two responsibilities should you identify? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A
Replacing failed server hardware
B
Backing up application data
C
Managing physical server security
D
Updating server operating systems
E
Managing permissions to shared documents
Reveal answer detailsClose answer details
Correct answersA, C
Explanation
Azure virtual machines run on Hyper-V physical servers. The physical servers are owned and managed by Microsoft. As an Azure customer, you have no access to the physical servers. Microsoft manage the replacement of failed server hardware and the security of the physical servers so you don't need to.
Incorrect Answers: B: Microsoft have no control over the applications you run on the virtual machines. Therefore, it is your responsibility to ensure that application data is backed up. D: Microsoft do not manage the operating systems you run on the virtual machines. Therefore, it is your responsibility to ensure that the operating systems are updated. E: Microsoft have no control over the shared folders you host on the virtual machines. Therefore, it is your responsibility to ensure that folder permissions are configured appropriately.
https://learn.microsoft.com/azure/security/fundamentals/shared-responsibility Azure Virtual Machines Overview: https://learn.microsoft.com/azure/virtual-machines/overview Physical Security in Azure Datacenters: https://learn.microsoft.com/azure/security/fundamentals/physical-security VM Operating System Responsibilities: https://learn.microsoft.com/azure/virtual-machines/maintenance-and-updates Azure Backup Overview: https://learn.microsoft.com/azure/backup/backup-overview
Question 4
Hotspot
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
A platform as a service solution provides full control of operating systems that host applications. No
Question 5
Hotspot
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Box 1: Yes Azure security center can monitor azure resources and on-premises resources. Azure Security Center is a unified infrastructure security management system that strengthens the security posture of your data centers, and provides advanced threat protection across your hybrid workloads in the cloud - whether they're in Azure or not - as well as on premises.
Box 2: No Only two features: Continuous assessment and security recommendations, and Azure secure score, are free.
Box 3: Yes The advanced monitoring capabilities in Security Center also let you track and manage compliance and governance over time. The overall compliance provides you with a measure of how much your subscriptions are compliant with policies associated with your workload.
This question requires that you evaluate the underlined text to determine if it is correct.
Azure Site Recovery can be used to migrate on-premises SQL databases to Azure SQL Database.
Instructions: Review the underlined text.
A
No change is needed
B
Azure Migrate
C
Azure Backup
D
Azure Database Migration Service
Reveal answer detailsClose answer details
Correct answerD
Explanation
Database Migration Service (DMS) is used for migrating SQL databases to Azure SQL. Site Recovery is for disaster recovery replication. Azure Migrate assists with assessment but not full SQL migration.
Question 7
Hotspot
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
You can install the Az PowerShell module locally on Windows, macOS, and Linux. It can also be used from a browser through Azure Cloud Shell or inside a Docker container. Azure powershell modules can be installed on macOS. Yes
Match the Azure service to the correct description.
Instructions: To answer, drag the appropriate Azure service from the column on the left to its description on the right. Each service may be used once, more than once, or not at all.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Box 1: Azure AI bot provides a digital online assistant that provides speech support. Bots provide an experience that feels less like using a computer and more like dealing with a person - or at least an intelligent robot. They can be used to shift simple, repetitive tasks, such as taking a dinner reservation or gathering profile information, on to automated systems that may no longer require direct human intervention. Users converse with a bot using text, interactive cards, and speech. A bot interaction can be a quick question and answer, or it can be a sophisticated conversation that intelligently provides access to services.
Box 2: Azure Machine Learning uses past trainings to provide predictions that have high probability. Machine learning is a data science technique that allows computers to use existing data to forecast future behaviors, outcomes, and trends. By using machine learning, computers learn without being explicitly programmed. Forecasts or predictions from machine learning can make apps and devices smarter. For example, when you shop online, machine learning helps recommend other products you might want based on what you've bought.
Box 3:
Azure Functions provides serverless computing functionalities. Azure Functions is a serverless compute service that lets you run event-triggered code without having to explicitly provision or manage infrastructure.
Box 4: IoT Hub (Internet of things Hub) provides data from millions of sensors. IoT Hub is a managed service, hosted in the cloud, that acts as a central message hub for bi-directional communication between your IoT application and the devices it manages. You can use Azure IoT Hub to build IoT solutions with reliable and secure communications between millions of IoT devices and a cloud-hosted solution backend. You can connect virtually any device to IoT Hub.
Your company hosts an accounting application named App1 that is used by all the customers of the company.
App1 has low usage during the first three weeks of each month and very high usage during the last week of each month.
Which benefit of Azure Cloud Services supports cost management for this type of usage pattern?
A
high availability
B
high latency
C
elasticity
D
load balancing
Reveal answer detailsClose answer details
Correct answerC
Explanation
Elasticity in this case is the ability to provide additional compute resource when needed and reduce the compute resource when not needed to reduce costs. Autoscaling is an example of elasticity.
Elastic computing is the ability to quickly expand or decrease computer processing, memory and storage resources to meet changing demands without worrying about capacity planning and engineering for peak usage. Typically controlled by system monitoring tools, elastic computing matches the amount of resources allocated to the amount of resources actually needed without disrupting operations. With cloud elasticity, a company avoids paying for unused capacity or idle resources and doesn't have to worry about investing in the purchase or maintenance of additional resources and equipment.
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your Azure environment contains multiple Azure virtual machines.
You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP.
Solution: You modify an Azure firewall.
Does this meet the goal?
A
Yes
B
No
Reveal answer detailsClose answer details
Correct answerB
Explanation
Reason Why This Answer Is Correct:
Although Azure Firewall can allow HTTP traffic, modifying it alone does not guarantee that VM1 will be accessible from the Internet.
To expose a VM over HTTP, ALL of the following must be true: The VM must have a Public IP address. An NSG (Network Security Group) must allow inbound TCP port 80. Traffic must be routed through Azure Firewall.
The solution only states that Azure Firewall is modified. It does NOT verify: That the VM has a public IP address That an NSG allows port 80 That the firewall is in the traffic path
Because none of those are guaranteed, modifying Azure Firewall alone does not meet the goal.
Why Azure Firewall Is Not the Correct Answer Here:
Azure Firewall protects networks when traffic is routed through it. However, many VMs are directly exposed using: Public IP address NSG rules
For most scenarios, the correct method to allow HTTP access is: Assigning a public IP to the VM Configuring an NSG to allow inbound TCP port 80
References: Azure Firewall: (https://learn.microsoft.com/en-us/azure/firewall/overview) "Azure Firewall is a managed firewall service that filters traffic when deployed in the network path." Network Security Groups: (https://learn.microsoft.com/en-us/azure/virtual-network/network-security-groups-overview) "Network security groups allow or deny inbound and outbound traffic to Azure resources." Public IP addresses: (https://learn.microsoft.com/en-us/azure/virtual-network/ip-services/public-ip-addresses) "A public IP allows Azure resources to communicate with the Internet."
Question 11
Hotspot
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Box 1: No The cost of outbound traffic from azure is the same for all azure regions. No Within most of the areas, there are clearly more expensive regions and less expensive regions. The least expensive regions, on average across these instance types are us-west-2, us-west-central, and korea-south. The most expensive regions are asia-pacific-east, japan-east, and australia-east.
Box 2: Yes Many organizations with Microsoft Enterprise Agreements (EA) are adding Azure to their EA to enjoy the benefits it offers, such as: Minimizing Azure upfront costs by locking in pricing with consumption pre-commitment Using Azure EA Portal to manage Azure Subscriptions easily and organize them under a single billing account
Box 3: No The commercial marketplace operates on an agency model, whereby publishers set prices, Microsoft bills customers, and Microsoft pays revenue to publishers while withholding an agency fee.
Match the Azure storage services to the appropriate descriptions.
To answer, drag the appropriate storage service from the column on the left to its description on the right. Each service may be used once, more than once, or not at all.
Simple, cost-effective, durable message queueing for large workloads Rich client libraries for .NET, Java, Android, C++, Node.js, PHP, Ruby, and Python Data accessible via the REST API
Box 2: Azure Files You can map a Network File Share to an Azure Windows VM.
Box 3: Azure Blob Storage Azure Archive Storage is yet another storage tier available for blob storage. Hot, cool, and archive objects can all exist side by side in the same account. And with the introduction of blob-level tiering, you can change an object's tier with a single click in the Azure portal, or you can use the REST API (or .NET, Java, Python, and a number of other SDKs) to programmatically change as many objects as needed.
Premium block blobs storage accounts only support: __________________
Select the answer that correctly completes the sentence.
Reveal answer detailsClose answer details
Question 14
Hotspot
HOTSPOT
Several support engineers plan to manage Azure by using the computers shown in the following table:
You need to identify which Azure management tools can be used from each computer.
What should you identify for each computer? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Previously, the Azure CLI (or x-plat CLI) was the only option for managing Azure subscriptions and resources from the command-line on Linux and macOS. Now with the open source and cross-platform release of PowerShell, you'll be able to manage all your Azure resources from Windows, Linux and macOS using your tool of choice, either the Azure CLI or Azure PowerShell cmdlets. The Azure portal runs in a web browser so can be used in either operating system.
If an Azure virtual machine has a status of Stopped (deallocated), you will continue to pay for (_______________)
Reveal answer detailsClose answer details
Accepted answerSTORAGE
Question 17
Drag & drop
DRAG DROP
Match the Azure Services service to the correct description.
Instructions: To answer, drag the appropriate service from the column on the left to its description on the right. Each service may be used once, more than once, or not at all.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Question 18
Hotspot
HOTSPOT
Select the answer that correctly completes the sentence.
Reveal answer detailsClose answer details
Explanation
Authentication is the process of establishing the identity of a user or service that wants to access a resource.
Question 19
Hotspot
HOTSPOT
You plan to use Azure to host two apps named App1 and App2 The apps must meet the following requirements:
1. You must be able to modify the code of App1 2. Administrative effort to manage the operating system of App1 must be minimized. 3. App2 must run interactively with the operating system of the server.
Which type of cloud service should you use for each app?
Reveal answer detailsClose answer details
Explanation
Box 1: Azure Platform as a service (PaaS) Organizations typically use PaaS for these scenarios: Development framework. PaaS provides a framework that developers can build upon to develop or customize cloud-based applications. Similar to the way you create an Excel macro, PaaS lets developers create applications using built-in software components. Cloud features such as scalability, high-availability, and multi-tenant capability are included, reducing the amount of coding that developers must do.
Box 2: Software as a service (SaaS) allows users to connect to and use cloud-based apps over the Internet. Common examples are email, calendaring, and office tools (such as Microsoft Office 365). SaaS provides a complete software solution that you purchase on a pay-as-you-go basis from a cloud service provider. You rent the use of an app for your organization, and your users connect to it over the Internet, usually with a web browser. All of the underlying infrastructure, middleware, app software, and app data are located in the service provider's data center. The service provider manages the hardware and software, and with the appropriate service agreement, will ensure the availability and the security of the app and your data as well. SaaS allows your organization to get quickly up and running with an app at minimal upfront cost. References: https://azure.microsoft.com/en-us/overview/what-is-paas/
Question 20
Single choice
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
An Azure administrator plans to run a PowerShell script that creates Azure resources.
You need to recommend which computer configuration to use to run the script.
Solution: Run the script from a computer that runs Chrome OS and uses Azure Cloud Shell.
Does this meet the goal?
A
Yes
B
No
Reveal answer detailsClose answer details
Correct answerA
Explanation
A PowerShell script is a file that contains PowerShell cmdlets and code. A PowerShell script needs to be run in PowerShell.
With the Azure Cloud Shell, you can run PowerShell cmdlets and scripts in a Web browser. You log in to the Azure Portal and select the Azure Cloud Shell option. This will open a PowerShell session in the Web browser. The Azure Cloud Shell has the necessary Azure PowerShell module installed.
Note: to run a PowerShell script in the Azure Cloud Shell, you need to change to the directory where the PowerShell script is stored.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
An azure subscription can have multiple account administrators.No References: https://k21academy.com/microsoft-azure/az-900/az-900-azure-subscriptions/ https://azure.microsoft.com/en-us/blog/organizing-subscriptions-and-resource-groups-within-the-enterprise/
Question 22
Hotspot
HOTSPOT
You can use the azure file sync agent to sync on-premises data to an azure________________
Select the answer that correctly completes the sentence.
Reveal answer detailsClose answer details
Explanation
You can use the Azure File Sync agent to sync on-premises data to an Azure file share.
Question 23
Single choice
In which type of cloud model are all the hardware resources owned by a third-party and shared between multiple tenants?
A
private
B
hybrid
C
public
Reveal answer detailsClose answer details
Correct answerC
Explanation
Public Cloud: Hardware resources are owned and managed by a third-party cloud provider (e.g., Microsoft Azure).- Resources are shared between multiple tenants.- Services are accessed over the Internet, typically with pay-as-you-go pricing. Incorrect Options: Private Cloud: Resources are dedicated to a single organization.-Hardware is not shared between multiple tenants. Hybrid Cloud: Combines private and public cloud resources.-Not fully shared, third-party-owned hardware. References (Microsoft Learn): Public, private, and hybrid cloud models overview https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/strategy/plan-cloud-models
Question 24
Single choice
How many copies of data are maintained by an Azure Storage account that uses georedundant storage (GRS)?
A
3
B
4
C
6
D
9
Reveal answer detailsClose answer details
Correct answerC
Question 25
Single choice
You have a virtual machine named VM1 that runs Windows Server 2016. VM1 is in the East US Azure region.
Which Azure service should you use from the Azure portal to view service failure notifications that can affect the availability of VM1?
A
Azure Service Fabric
B
Azure Monitor
C
Azure virtual machines
D
Azure Advisor
Reveal answer detailsClose answer details
Correct answerB
Explanation
Azure Monitor includes the Azure Service Health feature, which provides personalized dashboards for viewing service failure notifications, planned maintenance, and health advisories that can affect the availability of resources like VM1. Azure Advisor provides best practice recommendations but does not provide real-time service failure notifications. Azure Service Fabric is for deploying and managing microservices, not for monitoring platform health. Azure virtual machines is a resource management blade, not a service for platform failure notifications. References: Microsoft Learn: (https://learn.microsoft.com/en-us/azure/service-health/service-health-overview) "Azure Service Health provides personalized alerts and guidance when Azure service issues like outages or maintenance affect your resources."-Microsoft Learn: (https://learn.microsoft.com/en-us/azure/azure-monitor/overview) "Azure Monitor collects, analyzes, and acts on telemetry from your cloud and on-premises environments. It integrates Azure Service Health to notify you of platform incidents and planned maintenance."
Question 26
Hotspot
HOTSPOT
To complete the sentence, select the appropriate option in the answer area.
Reveal answer detailsClose answer details
Explanation
An organization that hosts its infrastructure in the public cloud no longer requires a data center.
Question 27
Single choice
What can you use to identify underutilized or unused Azure virtual machines?
A
Azure Advisor
B
Azure Cost Management + Billing
C
Azure reservations
D
Azure Policy
Reveal answer detailsClose answer details
Correct answerA
Explanation
Azure Advisor provides personalized recommendations to optimize Azure resources. For virtual machines, it identifies underutilized or unused VMs and recommends actions such as resizing, stopping, or deleting them to reduce costs.-Helps improve cost efficiency and resource utilization. Incorrect Options: Azure Cost Management + Billing: Focuses on analyzing costs, budgeting, and spending trends.- Does not specifically identify underutilized or unused VMs.-Azure Reservations: Used to pre-purchase capacity for cost savings.- Does not provide insights on VM utilization.-Azure Policy: Enforces compliance and governance rules.- Does not automatically identify underutilized or unused VMs. References (Microsoft Learn): Azure Advisor overview https://learn.microsoft.com/en-us/azure/advisor/advisor-overview Optimize and manage costs for Azure VMs using Azure Advisor https://learn.microsoft.com/en-us/azure/advisor/advisor-cost-recommendations References: https://docs.microsoft.com/en-us/azure/advisor/advisor-overview
Question 28
Hotspot
HOTSPOT
Select the answer that correctly completes the sentence.
Reveal answer detailsClose answer details
Explanation
Box: contains one or more data centers that are connected by using a low-latency network.
An azure region contains one or more data centers that are connected by using a low-latency network.
Each Azure region features datacenters deployed within a latency-defined perimeter. They're connected through a dedicated regional low-latency network. This design ensures that Azure services within any region offer the best possible performance and security. References: https://docs.microsoft.com/en-us/azure/availability-zones/az-overview
Question 29
Single choice
Your network contains an Active Directory forest. The forest contains 5,000 user accounts.
Your company plans to migrate all network resources to Azure and to decommission the on-premises data center.
You need to recommend a solution to minimize the impact on users after the planned migration.
What should you recommend?
A
Implement Azure Multi-Factor Authentication (MFA)
B
Sync all the Active Directory user accounts to Azure Active Directory (Azure AD)
C
Instruct all users to change their password
D
Create a guest user account in Azure Active Directory (Azure AD) for each user
Reveal answer detailsClose answer details
Correct answerB
Explanation
To migrate to Azure and decommission the on-premises data center, you would need to create the 5,000 user accounts in Azure Active Directory. The easy way to do this is to sync all the Active Directory user accounts to Azure Active Directory (Azure AD). You can even sync their passwords to further minimize the impact on users. The tool you would use to sync the accounts is Azure AD Connect. The Azure Active Directory Connect synchronization services (Azure AD Connect sync) is a main component of Azure AD Connect. It takes care of all the operations that are related to synchronize identity data between your on-premises environment and Azure AD.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
You can create custom azure roles to control access to resources.Yes
Question 31
Single choice
Your company is planning a deployment using Azure Database for PostgreSQL. The deployment should meet the following requirements:
1. Up to 10 TB storage 2. Azure Premium Storage 3. Point-in-time-restore for up to 35 days
You need to select the appropriate deployment and pricing tier to meet these requirements and minimize costs.
What should you select?
A
Azure Database for PostgreSQL Single Server Memory Optimized tier
B
Azure Database for PostgreSQL Hyperscale (Citus)
C
Azure Database for PostgreSQL Single Server General Purpose tier
D
Azure Database for PostgreSQL Single Server Basic tier
Reveal answer detailsClose answer details
Correct answerC
Explanation
1. Storage: Supports up to 16 TiB, sufficient for 10 TB. 2. Premium Storage: Uses Premium SSD/v2. 3. PITR: Supports backup retention up to 35 days.-Minimizes costs compared to Memory Optimized and Hyperscale (Citus) tiers.
1. Azure Database for PostgreSQL Single Server Memory Optimized tier: Meets technical requirements (storage, Premium SSD, 35-day PITR). Fails the cost requirement: more expensive than General Purpose, so not optimal for minimizing costs. 2. Azure Database for PostgreSQL Single Server Basic tier: Storage limitation: Maximum 1 TB, far below 10 TB requirement. Storage type: Standard storage, does not meet Premium SSD requirement. PITR limitation: Only 7 days, insufficient for the required 35 days.-Conclusion: Fails all three technical requirements. 3. Azure Database for PostgreSQL Hyperscale (Citus)): Meets storage and PITR requirements. Cost: Designed for distributed workloads, significantly more expensive than General Purpose. Overkill for single-server deployment; fails the "minimize costs" objective.
References (Microsoft Learn): Flexible Server compute tiers https://learn.microsoft.com/en-us/azure/postgresql/flexible-server/concepts-compute Flexible Server storage limits https://learn.microsoft.com/en-us/azure/postgresql/flexible-server/concepts-limits Flexible Server storage concepts https://learn.microsoft.com/en-us/azure/postgresql/flexible-server/concepts-storage
Question 32
Hotspot
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Box 1: Yes Azure advisor provides personalized recommendations. Advisor is a personalized cloud consultant that helps you follow best practices to optimize your Azure deployments. It analyzes your resource configuration and usage telemetry and then recommends solutions that can help you improve the cost effectiveness, performance, Reliability (formerly called High availability), and security of your Azure resources.
Box 2: Yes Advisor provides recommendations for Application Gateway, App Services, availability sets, Azure Cache, Azure Data Factory, Azure Database for MySQL, Azure Database for PostgreSQL, Azure Database for MariaDB, Azure ExpressRoute, Azure Cosmos DB, Azure public IP addresses, Azure Synapse Analytics, SQL servers, storage accounts, Traffic Manager profiles, and virtual machines.
Box 3: Yes The Advisor dashboard displays personalized recommendations for all your subscriptions. You can apply filters to display recommendations for specific subscriptions and resource types.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Box 1: Yes Most services go to private preview then public preview before being released to general availability. The private preview is only available to certain Azure customers for evaluation purposes. The public preview is available to all Azure customers.
Box 2: No Azure services in public preview can be managed using the regular management tools: Azure Portal, Azure CLI and PowerShell.
Box 3: No Services in private or public preview are usually offered at reduced costs. However, the costs increase, not decrease when the services are released to general availability.
Question 34
Single choice
What can you use to automatically send an alert if an administrator stops an Azure virtual machine?
A
Azure Advisor
B
Azure Service Health
C
Azure Monitor
D
Azure Network Watcher
Reveal answer detailsClose answer details
Correct answerC
Explanation
Azure Monitor can create Activity Log alerts on administrative actions. For example, when an administrator stops a VM (deallocate action), Azure Monitor can detect it and send an email, SMS, or trigger other automated actions.-This allows proactive monitoring of critical resources. Incorrect options: Azure Advisor: Provides recommendations for cost, performance, security, and reliability. Does not send real-time alerts for VM actions. Azure Service Health: Notifies about Azure service outages or planned maintenance. Does not alert on administrator actions. Azure Network Watcher: Monitors network connectivity and traffic. Does not track VM power state changes. References (Microsoft Learn): Create Activity Log alerts in Azure Monitor https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/alerts-activity-log Azure Advisor overview https://learn.microsoft.com/en-us/azure/advisor/advisor-overview Azure Service Health overview https://learn.microsoft.com/en-us/azure/service-health/service-health-overview Azure Network Watcher overview https://learn.microsoft.com/en-us/azure/network-watcher/network-watcher-monitoring-overview
Question 35
Hotspot
HOTSPOT
You plan to extend your company's network to Azure.
The network contains a VPN appliance that uses an IP address of 131.107.700.1.
You need to create an Azure resource that defines the VPN appliance In Azure.
Which Azure resource should you create? To answer, select the appropriate resource in the answer area.
Reveal answer detailsClose answer details
Explanation
A Local Network Gateway is an object in Azure that represents your on-premise VPN device. A Virtual Network Gateway is the VPN object at the Azure end of the VPN. A 'connection' is what connects the Local Network Gateway an the Virtual Network Gateway to bring up the VPN.
The local network gateway typically refers to your on-premises location. You give the site a name by which Azure can refer to it, then specify the IP address of the on-premises VPN device to which you will create a connection. You also specify the IP address prefixes that will be routed through the VPN gateway to the VPN device. The address prefixes you specify are the prefixes located on your on-premises network. If your on-premises network changes or you need to change the public IP address for the VPN device, you can easily update the values later.
If a resource group named RG1 has a delete lock, ______________________ can delete RG1.
Select the answer that correctly completes the sentence.
Reveal answer detailsClose answer details
Question 38
Hotspot
HOTSPOT
Autoscaling is an example of: _______________
Select the answer that correctly completes the sentence.
Reveal answer detailsClose answer details
Explanation
An Azure virtual machine scale set can automatically increase or decrease the number of VM instances that run your application. This automated and elastic behavior reduces the management overhead to monitor and optimize the performance of your application.
Also: Azure elasticity as a service is referred to a cloud service that enables in automatically scaling Azure hosted resources in par with the demand and configured parameters. It provides Azure Administrators with the ability to auto scale Azure infrastructure and resources as and when needed.
You have a set of Azure policies. You need to group related policies together.
What should you use?
A
exemptions
B
metadata
C
parameters
D
initiatives
Reveal answer detailsClose answer details
Correct answerD
Question 40
Single choice
This question requires that you evaluate the underlined text to determine if it is correct.
An Azure region contains one or more data centers that are connected by using a low-latency network.
Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct.
A
No change is needed
B
Is found in each country where Microsoft has a subsidiary office
C
Can be found in every country in Europe and the Americas only
D
Contains one or more data centers that are connected by using a high-latency network
Reveal answer detailsClose answer details
Correct answerA
Explanation
A region is a set of data centres deployed within a latency-defined perimeter and connected through a dedicated regional low-latency network. Microsoft Azure currently has 55 regions worldwide. Regions are divided into Availability Zones. Availability Zones are physically separate locations within an Azure region. Each Availability Zone is made up of one or more datacenters equipped with independent power, cooling, and networking.
Your company implements ________________________________ to automatically add a watermark to microsoft word documents that contain credit card information
To complete the sentence, select the appropriate option in the answer area.
Reveal answer detailsClose answer details
Question 42
Single choice
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your company plans to migrate all its data and resources to Azure.
The company's migration plan states that only Platform as a Service (PaaS) solutions must be used in Azure.
You need to deploy an Azure environment that supports the planned migration.
Solution: You create an Azure App Service and Azure Storage accounts.
Does this meet the goal?
A
Yes
B
No
Reveal answer detailsClose answer details
Correct answerA
Explanation
Azure App Service is a PaaS web-hosting service that runs applications without managing virtual machines or operating systems. Azure Storage is also a PaaS service that provides fully managed storage services.
Both services are managed by Microsoft and do not require infrastructure management. Since no IaaS services (such as virtual machines) are used, the solution complies with the PaaS-only policy.
Incorrect solutions would include: Azure Virtual Machines Self-managed databases Custom operating systems
All of these would violate the PaaS-only requirement.
REFERENCES (Microsoft Learn):
Azure App Service overview https://learn.microsoft.com/en-us/azure/app-service/overview
PaaS definition and examples https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/strategy/cloud-service-models
IaaS vs PaaS vs SaaS (comparison guide) https://learn.microsoft.com/en-us/azure/architecture/framework/technology-choices/compute-decision-tree
Question 43
Single choice
Your company plans 10 migrate all its data and resources to Azure.
The company's migration plan states that only Platform as a Service (PaaS) solutions must be used in Azure
You need to deploy an Azure environment that meets the company's migration plan
What should you create?
A
an Azure App Service and Azure SQL databases
B
Azure storage accounts and web server in Azure virtual machines
C
Azure virtual machines. Azure SQL databases, and Azure Storage accounts
D
an Azure App Service and Azure virtual machines that have Microsoft SQL Server installed
Reveal answer detailsClose answer details
Correct answerA
Explanation
Azure App Service and Azure SQL databases are examples of Azure PaaS solutions. Therefore, this solution does meet the goal. **Azure App Service** is a PaaS offering for hosting web apps without managing the VM or OS. **Azure SQL Database** is a fully managed PaaS database service. This combination satisfies the requirement to use only PaaS solutions.
Incorrect Options: 1. Azure storage accounts and web server in Azure virtual machines: Using a VM for the web server is **IaaS**, not PaaS. 2. Azure virtual machines, Azure SQL databases, and Azure Storage accounts: Virtual machines are **IaaS**, violating the migration plan requirement. 3. Azure App Service and Azure virtual machines with SQL Server installed: Using a VM for SQL Server is **IaaS**, which is not allowed per the plan.
What should you use to track the costs of Azure resources?
A
Tags
B
usage and quotas
C
Azure Quickstart templates
D
budgets
Reveal answer detailsClose answer details
Correct answerD
Explanation
Azure Budgets allows you to monitor and track costs for Azure resources and subscriptions.
You can set a budget for a specific scope (subscription, resource group, or management group) and receive alerts when spending approaches or exceeds the budgeted amount. This is the recommended way to track and control Azure costs over time. Incorrect Options: Tags: Help organize and categorize Azure resources, but do not track costs directly. Usage and quotas: Provide information about resource usage limits and consumption but do not provide cost tracking or alerts. Azure Quickstart templates: Used to deploy resources quickly in Azure; they do not track costs. References: https://learn.microsoft.com/en-us/azure/cost-management-billing/costs/tutorial-acm-create-budgets https://learn.microsoft.com/en-us/azure/cost-management-billing/costs/cost-analysis-overview
Question 45
Hotspot
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Box 1: No Authorization to access azure resources can be provided only to azure active directory users. No Authorization to access Azure resources can be provided by other identity providers by using federation. A commonly used example of this is to federate your on-premises Active Directory environment with Azure AD and use this federation for authentication and authorization.
Box 2: Yes As described above, third-party cloud services and on-premises Active Directory can be used to access Azure resources. This is known as 'federation'. Federation is a collection of domains that have established trust. The level of trust may vary, but typically includes authentication and almost always includes authorization. A typical federation might include a number of organizations that have established trust for shared access to a set of resources.
Box 3: Yes Azure Active Directory (Azure AD) is a centralized identity provider in the cloud. This is the primary built-in authentication and authorization service to provide secure access to Azure resources.
You need to identify which blades in the Azure portal must be used to perform the following tasks:
1. View security recommendations. 2. Monitor the health of Azure services. 3. Browse available virtual machine images.
Which blade should you identify for each task? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Box 1: Azure Monitor is used to monitor the health of Azure services. Azure Monitor maximizes the availability and performance of your applications and services by delivering a comprehensive solution for collecting, analyzing, and acting on telemetry from your cloud and on-premises environments. It helps you understand how your applications are performing and proactively identifies issues affecting them and the resources they depend on.
Box 2: You can browse available virtual machine images in the Azure Marketplace. Azure Marketplace provides access and information on solutions and services available from Microsoft and their partners. Customers can discover, try, or buy cloud software solutions built on or for Azure. The catalog of 8,000+ listings provides Azure building blocks, such as Virtual Machines (VMs), APIs, Azure apps, Solution Templates and managed applications, SaaS apps, containers, and consulting services.
Box 3. Azure Advisor displays security recommendations. Azure Advisor provides you with a consistent, consolidated view of recommendations for all your Azure resources. It integrates with Azure Security Center to bring you security recommendations. You can get security recommendations from the Security tab on the Advisor dashboard.
Security Center helps you prevent, detect, and respond to threats with increased visibility into and control over the security of your Azure resources. It periodically analyzes the security state of your Azure resources. When Security Center identifies potential security vulnerabilities, it creates recommendations. The recommendations guide you through the process of configuring the controls you need.
Your company has an Azure environment that contains resources in several regions.
A company policy states that administrators must only be allowed to create additional Azure resources in a region in the country where their office is located.
You need to create the Azure resource that must be used to meet the policy requirement.
What should you create?
A
a read-only lock
B
an Azure policy
C
a management group
D
a reservation
Reveal answer detailsClose answer details
Correct answerB
Explanation
Azure policies can be used to define requirements for resource properties during deployment and for already existing resources. Azure Policy controls properties such as the types or locations of resources.
Azure Policy is a service in Azure that you use to create, assign, and manage policies. These policies enforce different rules and effects over your resources, so those resources stay compliant with your corporate standards and service level agreements. Azure Policy meets this need by evaluating your resources for non-compliance with assigned policies. All data stored by Azure Policy is encrypted at rest.
Azure Policy offers several built-in policies that are available by default. In this question, we would use the `Allowed Locations' policy to define the locations where resources can be deployed.
The company plans to implement an Azure environment.
You need to ensure that each department can use a different payment option for the Azure services it consumes.
What should you create for each department?
A
a reservation
B
a subscription
C
a resource group
D
a container instance
Reveal answer detailsClose answer details
Correct answerB
Explanation
There are different payment options in Azure including pay-as-you-go (PAYG), Enterprise Agreement (EA), and Microsoft Customer Agreement (MCA) accounts.
Your Azure costs are `per subscription'. You are charged monthly for all resources in a subscription. Therefore, to use different payment options per department, you will need to create a separate subscription per department. You can create multiple subscriptions in a single Azure Active Directory tenant.
Incorrect Answers: A: A reservation is where you commit to a resource (for example a virtual machine) for one or three years. This gives you a discounted price on the resource for the reservation period. Reservations do not provide a way to use different payment options per department. C: A resource group is a logical container for Azure resources. You can view the total cost of all the resources in a resource group. However, resource groups do not provide a way to use different payment options per department. D: A container instance is an Azure resource used to run an application. Container instances do not provide a way to use different payment options per department.
In which Azure support plans can you open a new support request?
A
Premier and Professional Direct only
B
Premier, Professional Direct, and Standard only
C
Premier, Professional Direct, Standard, and Developer only
D
Premier, Professional Direct, Standard, Developer, and Basic
Reveal answer detailsClose answer details
Correct answerD
Explanation
All Azure support plans allow you to open a support request. The difference between plans is the type of support, response times, and access to support engineers. - Basic: Limited support, includes billing and subscription support.- Developer: Technical support during business hours.- Standard: 24x7 support for production workloads. Professional Direct: 24x7 support with faster response times and access to ProDirect delivery manager. Premier: Enterprise-level support with prioritized response and dedicated support resources. Reasons why other answers are incorrect: Limiting to only Premier and Professional Direct, or Standard and Developer, is incorrect because even the Basic and Developer plans can open support requests, though with different response times and severity levels.
Your company plans to migrate all its network resources to Azure.
You need to start the planning process by exploring Azure.
What should you create first?
A
a subscription
B
a resource group
C
a virtual network
D
a management group
Reveal answer detailsClose answer details
Correct answerA
Explanation
The first thing you create in Azure is a subscription. You can think of an Azure subscription as an `Azure account'. You get billed per subscription. A subscription is an agreement with Microsoft to use one or more Microsoft cloud platforms or services, for which charges accrue based on either a per-user license fee or on cloud-based resource consumption.
Microsoft's Software as a Service (SaaS)-based cloud offerings (Office 365, Intune/EMS, and Dynamics 365) charge per-user license fees. Microsoft's Platform as a Service (PaaS) and Infrastructure as a Service (IaaS) cloud offerings (Azure) charge based on cloud resource consumption.
You can also use a trial subscription, but the subscription expires after a specific amount of time or consumption charges. You can convert a trial subscription to a paid subscription. Organizations can have multiple subscriptions for Microsoft's cloud offerings.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Availability zones expand the level of control you have to maintain the availability of the applications and data on your VMs. Availability Zones are unique physical locations within an Azure region. Each zone is made up of one or more datacenters equipped with independent power, cooling, and networking. To ensure resiliency, there are a minimum of three separate zones in all enabled regions. The physical separation of Availability Zones within a region protects applications and data from datacenter failures. With Availability Zones, Azure offers industry best 99.99% VM uptime SLA. By architecting your solutions to use replicated VMs in zones, you can protect your applications and data from the loss of a datacenter. If one zone is compromised, then replicated apps and data are instantly available in another zone.
You can use availability zones in azure to protect azure virtual machines from a datacenter failure. Yes You can use availability zones in azure to protect azure virtual machines from a region failure. No You can use availability zones in azure to protect azure managed disks from a datacenter failure. Yes
Which two features or services can be integrated with Azure Monitor? Each correct answer presents part of the solution.
NOTE: Each correct answer is worth one point.
A
Azure status
B
Application Insights
C
Azure Advisor
D
Log Analytics
E
Azure Service Health
Reveal answer detailsClose answer details
Correct answersB, D
Explanation
Application Insights: An application performance monitoring service that collects telemetry and integrates with Azure Monitor to provide insights into application health, performance, and usage. Log Analytics: A service that collects and analyzes log data from Azure resources and integrates with Azure Monitor for advanced query and alerting capabilities.
Incorrect Options:
Azure Status: Provides the current health of Azure services globally; it does not integrate directly with Azure Monitor. Azure Service Health: Provides notifications and guidance about Azure service issues; while it complements Azure Monitor, it is not a data integration point for monitoring. Azure Advisor: Provides recommendations for cost, performance, and security optimization; it does not provide telemetry data to Azure Monitor.
Match the cloud computing benefits to the correct descriptions.
To answer, drag the appropriate benefit from the column on the left to its description on the right. Each benefit may be used once, more than once, or not at all.
You plan to deploy a service to Azure virtual machines.
You need to ensure that the service will be available if a datacenter fails.
What should you use as part of the virtual machine deployment?
A
availability sets
B
proximity placement groups
C
host groups
D
availability zones
Reveal answer detailsClose answer details
Correct answerD
Explanation
Azure availability zones are physically separate locations within each Azure region that are tolerant to local failures. Failures can range from software and hardware failures to events such as earthquakes, floods, and fires. Tolerance to failures is achieved because of redundancy and logical isolation of Azure services. To ensure resiliency, a minimum of three separate availability zones are present in all availability zone-enabled regions.
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You plan to deploy several Azure virtual machines.
You need to ensure that the services running on the virtual machines are available if a single data center fails.
Solution: You deploy the virtual machines to two or more resource groups.
Does this meet the goal?
A
Yes
B
No
Reveal answer detailsClose answer details
Correct answerB
Explanation
A resource group is a logical container for Azure resources. When you create a resource group, you specify which location to create the resource group in. However, when you create a virtual machine and place it in the resource group, the virtual machine can still be in a different location (different datacenter). Therefore, creating multiple resource groups, even if they are in separate datacenters does not ensure that the services running on the virtual machines are available if a single data center fails.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
You must install Azure Cloud Shell on your computer before you can use it. No
Question 57
Drag & drop
DRAG DROP
You need to complete the defense-in-depth strategy used in a datacenter.
What should you do? To answer, drag the appropriate layers to the correct positions in the model. Each layer may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Defence in depth layers (from bottom to top): Data - In almost all cases attackers are after data. - Data can be in database, stored on disk inside VMs, on a SaaS application such as Office 365 or in cloud storage. - Those storing and controlling access to data to ensures that it's properly secured - Often regulatory requirements dictates controls & processes - to ensure confidentiality, integrity, and availability. Application - Ensure applications are secure and free of vulnerabilities. - Store sensitive application secrets in a secure storage medium. - Make security a design requirement for all application development. - Integrate security into the application development life cycle. Compute - Secure access to virtual machines. - Implement endpoint protection and keep systems patched and current. - Malware, unpatched systems, and improperly secured systems open your environment to attacks. Networking - Limit communication between resources. - Deny by default. - Allow only what is required - Restrict inbound internet access and limit outbound, where appropriate. - Implement secure connectivity to on-premises networks. Perimeter - Use distributed denial of service (DDoS) protection to filter large-scale attacks before they can cause a denial of service for end users. - Use perimeter firewalls to identify and alert on malicious attacks against your network. Identity and access - Control access to infrastructure and change control. - Access granted is only what is needed - Use single sign-on and multi-factor authentication. - Audit events and changes. Physical security - Building security & controlling access to computing hardware. - First line of defense.
This question requires that you evaluate the underlined text to determine if it is correct.
Your company implements Azure policies to automatically add a watermark to Microsoft Word documents that contain credit card information.
Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct.
A
No change is needed.
B
DDoS protection
C
Azure Information Protection
D
Azure Active Directory (Azure AD) Identity Protection
Reveal answer detailsClose answer details
Correct answerC
Explanation
Azure Information Protection is used to automatically add a watermark to Microsoft Word documents that contain credit card information.
You use Azure Information Protection labels to apply classification to documents and emails. When you do this, the classification is identifiable regardless of where the data is stored or with whom it's shared. The labels can include visual markings such as a header, footer, or watermark.
Labels can be applied automatically by administrators who define rules and conditions, manually by users, or a combination where users are given recommendations. In this question, we would configure a label to be automatically applied to Microsoft Word documents that contain credit card information. The label would then add the watermark to the documents.
Match the Azure service to the correct definition.
Instructions: To answer, drag the appropriate Azure service from the column on the left to its description on the right. Each service may be used once, more than once, or not at all.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Box 1: Azure Functions provides the platform for serverless code. Azure Functions is a serverless compute service that lets you run event-triggered code without having to explicitly provision or manage infrastructure.
Box 2: Azure Databricks is a big analysis service for machine learning. Azure Databricks is an Apache Spark-based analytics platform. The platform consists of several components including 'MLib'. Mlib is a Machine Learning library consisting of common learning algorithms and utilities, including classification, regression, clustering, collaborative filtering, dimensionality reduction, as well as underlying optimization primitives.
Box 3: Azure Application Insights detects and diagnoses anomalies in web apps. Application Insights, a feature of Azure Monitor, is an extensible Application Performance Management (APM) service for developers and DevOps professionals. Use it to monitor your live applications. It will automatically detect performance anomalies, and includes powerful analytics tools to help you diagnose issues and to understand what users actually do with your app.
Box 4: Azure App Service hosts web apps. Azure App Service is an HTTP-based service for hosting web applications, REST APIs, and mobile back ends. You can develop in your favorite language, be it .NET, .NET Core, Java, Ruby, Node.js, PHP, or Python. Applications run and scale with ease on both Windows and Linux-based environments.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Box 1: No Adding more ram to a virtual machine is an example of horizontal scaling. No Horizontal scaling refers to adding more instances, or removing instances, of resources used by a workload. For example, extending an application from one compute instance to five compute instances. The Microsoft Azure cloud supports automatic horizontal scaling for compute instances, called virtual machines (VMs).
Horizontal scaling is flexible in a cloud situation because you can use it to run a large number of VMs to handle load. In contrast, scaling up and down, or vertical scaling, keeps the same number of resource instances constant but gives them more capacity in terms of memory, CPU speed, disk space, and network.
Box 2: No
Box 3: Yes Autoscale scales in and out, or horizontally. Scaling horizontally is an increase or decrease of the number of resource instances.
Select the answer that correctly completes the sentence.
Reveal answer detailsClose answer details
Question 63
Single choice
This question requires that you evaluate the underlined text to determine if it is correct.
Data that is stored in the Archive access tier of an Azure Storage account can be accessed at any time by using azcopy.exe.
Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct.
A
No change is needed.
B
can only be read by using Azure Backup
C
must be restored before the data can be accessed
D
must be rehydrated before the data can be accessed
Reveal answer detailsClose answer details
Correct answerD
Explanation
Corrected Statement: Data that is stored in the Archive access tier of an Azure Storage account (must be rehydrated before the data can be accessed).
Reasoning: The **Archive access tier** in Azure Storage is intended for long-term, infrequently accessed data. Data in the Archive tier is **offline** and must be **rehydrated** to an online tier (Hot or Cool) before it can be read or accessed. Other options: "No change is needed" Incorrect. Data cannot be accessed immediately; it must be rehydrated first. "Can only be read by using Azure Backup" Incorrect. Azure Backup is a separate service; Archive data can be restored via any supported storage access method after rehydration. "Must be restored before the data can be accessed" Partially correct but vague; the technical term is **rehydration**.
References: Microsoft Learn: (https://learn.microsoft.com/en-us/azure/storage/blobs/storage-blob-storage-tiers#archive) "Data in the Archive tier is offline and cannot be read or modified. To access the data, you must first rehydrate it to the Hot or Cool tier." Microsoft Learn: (https://learn.microsoft.com/en-us/azure/storage/blobs/storage-blob-rehydration-overview) "Rehydration is the process of moving data from the Archive tier to an online tier so it can be accessed or read."
Question 64
Hotspot
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Reveal answer detailsClose answer details
Explanation
Azure pay-as-you-go pricing is an example of capex. No
Question 65
Hotspot
HOTSPOT
To complete the sentence, select the appropriate option in the answer area.
Reveal answer detailsClose answer details
Explanation
One of the benefits of zure sql data warehouse is that high availability is built into the platform
Question 66
Single choice
What is used to grant permission to Azure Virtual Desktop resources?
A
tags
B
role-based access control (RBAC) roles
C
resource groups
D
application security groups
Reveal answer detailsClose answer details
Correct answerB
Explanation
RBAC roles: Role-Based Access Control (RBAC) in Azure is used to grant users, groups, or applications specific permissions to Azure resources. For Azure Virtual Desktop, you assign RBAC roles to control access to host pools, application groups, and workspaces. This ensures that only authorized users can manage or access resources. Incorrect Answers: Tags: Tags are used for organizing resources and tracking costs; they do not grant access permissions. Resource groups: Resource groups are containers for Azure resources; they do not control permissions themselves, although you can assign RBAC roles at the resource group level. Application security groups: These are used to group virtual machines for network security purposes, not for granting access permissions. https://learn.microsoft.com/en-us/azure/role-based-access-control/overview https://learn.microsoft.com/en-us/azure/virtual-desktop/manage-rbac
This question requires that you evaluate the underlined text to determine if it is correct.
You deploy an Azure resource. The resource becomes unavailable for an extended period due to a service outage. Microsoft will automatically refund your bank account.
Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct.
A
No change is needed.
B
automatically migrate the resource to another subscription
C
automatically credit your account
D
send you a coupon code that you can redeem for Azure credits
Reveal answer detailsClose answer details
Correct answerC
Explanation
If the SLA for an Azure service is not met, you receive credits for that service and that service only. The credits are deducted from your monthly bill for that service. If you stopped using the service where the SLA was not met, your account would remain in credit for that service. The credits would not be applied to any other services that you may be using.
Service Credits apply only to fees paid for the particular Service, Service Resource, or Service tier for which a Service Level has not been met. In cases where Service Levels apply to individual Service Resources or to separate Service tiers, Service Credits apply only to fees paid for the affected Service Resource or Service tier, as applicable. The Service Credits awarded in any billing month for a particular Service or Service Resource will not, under any circumstance, exceed your monthly service fees for that Service or Service Resource, as applicable, in the billing month.
From __________________ you can view which user turned off a specific virtual machine during the last 14 days.
To complete the sentence, select the appropriate option in the answer area.
Reveal answer detailsClose answer details
Question 69
Single choice
Your company plans to deploy several custom applications to Azure.
The applications will provide invoicing services to the customers of the company.
Each application will have several prerequisite applications and services installed.
You need to recommend a cloud deployment solution for all the applications.
What should you recommend?
A
Software as a Service (SaaS)
B
Platform as a Service (PaaS)
C
Infrastructure as a Service (laaS)
Reveal answer detailsClose answer details
Correct answerC
Explanation
Infrastructure as a service (IaaS) is an instant computing infrastructure, provisioned and managed over the internet. The IaaS service provider manages the infrastructure, while you purchase, install, configure, and manage your own software
Incorrect Answers: A: Software as a service (SaaS) allows users to connect to and use cloud-based apps over the Internet. Common examples are email, calendaring, and office tools. In this scenario, you need to run your own apps, and therefore require an infrastructure.
B:Platform as a service (PaaS) is a complete development and deployment environment in the cloud. PaaS includes infrastructure--servers, storage, and networking--but also middleware, development tools, business intelligence (BI) services, database management systems, and more. PaaS is designed to support the complete web application lifecycle: building, testing, deploying, managing, and updating.
You need to be notified when Microsoft plans to perform maintenance that can affect the resources deployed to an Azure subscription.
What should you use?
A
Azure Monitor
B
Azure Service Health
C
Azure Advisor
D
Microsoft Trust Center
Reveal answer detailsClose answer details
Correct answerB
Explanation
Azure Service Health provides a personalized view of the health of the Azure services and regions you're using. This is the best place to look for service impacting communications about outages, planned maintenance activities, and other health advisories because the authenticated Service Health experience knows which services and resources you currently use.
The cool access tier is optimized ________________________
Select the answer that correctly completes the sentence.
Reveal answer detailsClose answer details
Explanation
Box: for data that is accessed infrequently and stored for at least 30 days Cool tier - An online tier optimized for storing data that is infrequently accessed or modified. Data in the cool tier should be stored for a minimum of 30 days. The cool tier has lower storage costs and higher access costs compared to the hot tier.
Incorrect: * for data that is accessed rarely, is stored for at least 180 days, ..
Select the answer that correctly completes the sentence.
Correct Answer:
Explanation
Explanation/Reference:
Box: Azure Active Directory (Azure AD) You can enable single sign-on for an enterprise application through Azure Active Directory (Azure AD.
Azure Active Directory enables users to authenticate to multiple applications by using single sign-on.
Incorrect: Application security groups enable you to configure network security as a natural extension of an application's structure, allowing you to group virtual machines and define network security policies based on those groups. References: https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/add-application-portal-setup-sso
QUESTION 2
What is the function of a Site-to-Site VPN?
A.
provides a secure connection between a computer on a public network and the corporate network
B.
provides a connection from an on-premises VPN device to an Azure VPN gateway
C.
provides a dedicated private connection to Azure that does NOT travel over the internet
Correct Answer: B
QUESTION 3
Your company has an on-premises network that contains multiple servers.
The company plans to reduce the following administrative responsibilities of network administrators:
1. Backing up application data 2. Replacing failed server hardware 3. Managing physical server security 4. Updating server operating systems 5. Managing permissions to shared documents
The company plans to migrate several servers to Azure virtual machines.
You need to identify which administrative responsibilities will be eliminated after the planned migration.
Which two responsibilities should you identify? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A.
Replacing failed server hardware
B.
Backing up application data
C.
Managing physical server security
D.
Updating server operating systems
E.
Managing permissions to shared documents
Correct Answer: AC
Explanation
Explanation/Reference:
Azure virtual machines run on Hyper-V physical servers. The physical servers are owned and managed by Microsoft. As an Azure customer, you have no access to the physical servers. Microsoft manage the replacement of failed server hardware and the security of the physical servers so you don't need to.
Incorrect Answers: B: Microsoft have no control over the applications you run on the virtual machines. Therefore, it is your responsibility to ensure that application data is backed up. D: Microsoft do not manage the operating systems you run on the virtual machines. Therefore, it is your responsibility to ensure that the operating systems are updated. E: Microsoft have no control over the shared folders you host on the virtual machines. Therefore, it is your responsibility to ensure that folder permissions are configured appropriately.
https://learn.microsoft.com/azure/security/fundamentals/shared-responsibility Azure Virtual Machines Overview: https://learn.microsoft.com/azure/virtual-machines/overview Physical Security in Azure Datacenters: https://learn.microsoft.com/azure/security/fundamentals/physical-security VM Operating System Responsibilities: https://learn.microsoft.com/azure/virtual-machines/maintenance-and-updates Azure Backup Overview: https://learn.microsoft.com/azure/backup/backup-overview
QUESTION 4
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
A platform as a service solution provides full control of operating systems that host applications. No
QUESTION 5
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Box 1: Yes Azure security center can monitor azure resources and on-premises resources. Azure Security Center is a unified infrastructure security management system that strengthens the security posture of your data centers, and provides advanced threat protection across your hybrid workloads in the cloud - whether they're in Azure or not - as well as on premises.
Box 2: No Only two features: Continuous assessment and security recommendations, and Azure secure score, are free.
Box 3: Yes The advanced monitoring capabilities in Security Center also let you track and manage compliance and governance over time. The overall compliance provides you with a measure of how much your subscriptions are compliant with policies associated with your workload.
This question requires that you evaluate the underlined text to determine if it is correct.
Azure Site Recovery can be used to migrate on-premises SQL databases to Azure SQL Database.
Instructions: Review the underlined text.
A.
No change is needed
B.
Azure Migrate
C.
Azure Backup
D.
Azure Database Migration Service
Correct Answer: D
Explanation
Explanation/Reference:
Database Migration Service (DMS) is used for migrating SQL databases to Azure SQL. Site Recovery is for disaster recovery replication. Azure Migrate assists with assessment but not full SQL migration.
QUESTION 7
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
You can install the Az PowerShell module locally on Windows, macOS, and Linux. It can also be used from a browser through Azure Cloud Shell or inside a Docker container. Azure powershell modules can be installed on macOS. Yes
Match the Azure service to the correct description.
Instructions: To answer, drag the appropriate Azure service from the column on the left to its description on the right. Each service may be used once, more than once, or not at all.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Box 1: Azure AI bot provides a digital online assistant that provides speech support. Bots provide an experience that feels less like using a computer and more like dealing with a person - or at least an intelligent robot. They can be used to shift simple, repetitive tasks, such as taking a dinner reservation or gathering profile information, on to automated systems that may no longer require direct human intervention. Users converse with a bot using text, interactive cards, and speech. A bot interaction can be a quick question and answer, or it can be a sophisticated conversation that intelligently provides access to services.
Box 2: Azure Machine Learning uses past trainings to provide predictions that have high probability. Machine learning is a data science technique that allows computers to use existing data to forecast future behaviors, outcomes, and trends. By using machine learning, computers learn without being explicitly programmed. Forecasts or predictions from machine learning can make apps and devices smarter. For example, when you shop online, machine learning helps recommend other products you might want based on what you've bought.
Box 3:
Azure Functions provides serverless computing functionalities. Azure Functions is a serverless compute service that lets you run event-triggered code without having to explicitly provision or manage infrastructure.
Box 4: IoT Hub (Internet of things Hub) provides data from millions of sensors. IoT Hub is a managed service, hosted in the cloud, that acts as a central message hub for bi-directional communication between your IoT application and the devices it manages. You can use Azure IoT Hub to build IoT solutions with reliable and secure communications between millions of IoT devices and a cloud-hosted solution backend. You can connect virtually any device to IoT Hub.
Your company hosts an accounting application named App1 that is used by all the customers of the company.
App1 has low usage during the first three weeks of each month and very high usage during the last week of each month.
Which benefit of Azure Cloud Services supports cost management for this type of usage pattern?
A.
high availability
B.
high latency
C.
elasticity
D.
load balancing
Correct Answer: C
Explanation
Explanation/Reference:
Elasticity in this case is the ability to provide additional compute resource when needed and reduce the compute resource when not needed to reduce costs. Autoscaling is an example of elasticity.
Elastic computing is the ability to quickly expand or decrease computer processing, memory and storage resources to meet changing demands without worrying about capacity planning and engineering for peak usage. Typically controlled by system monitoring tools, elastic computing matches the amount of resources allocated to the amount of resources actually needed without disrupting operations. With cloud elasticity, a company avoids paying for unused capacity or idle resources and doesn't have to worry about investing in the purchase or maintenance of additional resources and equipment.
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your Azure environment contains multiple Azure virtual machines.
You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP.
Solution: You modify an Azure firewall.
Does this meet the goal?
A.
Yes
B.
No
Correct Answer: B
Explanation
Explanation/Reference:
Reason Why This Answer Is Correct:
Although Azure Firewall can allow HTTP traffic, modifying it alone does not guarantee that VM1 will be accessible from the Internet.
To expose a VM over HTTP, ALL of the following must be true: The VM must have a Public IP address. An NSG (Network Security Group) must allow inbound TCP port 80. Traffic must be routed through Azure Firewall.
The solution only states that Azure Firewall is modified. It does NOT verify: That the VM has a public IP address That an NSG allows port 80 That the firewall is in the traffic path
Because none of those are guaranteed, modifying Azure Firewall alone does not meet the goal.
Why Azure Firewall Is Not the Correct Answer Here:
Azure Firewall protects networks when traffic is routed through it. However, many VMs are directly exposed using: Public IP address NSG rules
For most scenarios, the correct method to allow HTTP access is: Assigning a public IP to the VM Configuring an NSG to allow inbound TCP port 80
References: Azure Firewall: (https://learn.microsoft.com/en-us/azure/firewall/overview) "Azure Firewall is a managed firewall service that filters traffic when deployed in the network path." Network Security Groups: (https://learn.microsoft.com/en-us/azure/virtual-network/network-security-groups-overview) "Network security groups allow or deny inbound and outbound traffic to Azure resources." Public IP addresses: (https://learn.microsoft.com/en-us/azure/virtual-network/ip-services/public-ip-addresses) "A public IP allows Azure resources to communicate with the Internet."
QUESTION 11
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Box 1: No The cost of outbound traffic from azure is the same for all azure regions. No Within most of the areas, there are clearly more expensive regions and less expensive regions. The least expensive regions, on average across these instance types are us-west-2, us-west-central, and korea-south. The most expensive regions are asia-pacific-east, japan-east, and australia-east.
Box 2: Yes Many organizations with Microsoft Enterprise Agreements (EA) are adding Azure to their EA to enjoy the benefits it offers, such as: Minimizing Azure upfront costs by locking in pricing with consumption pre-commitment Using Azure EA Portal to manage Azure Subscriptions easily and organize them under a single billing account
Box 3: No The commercial marketplace operates on an agency model, whereby publishers set prices, Microsoft bills customers, and Microsoft pays revenue to publishers while withholding an agency fee.
Match the Azure storage services to the appropriate descriptions.
To answer, drag the appropriate storage service from the column on the left to its description on the right. Each service may be used once, more than once, or not at all.
Simple, cost-effective, durable message queueing for large workloads Rich client libraries for .NET, Java, Android, C++, Node.js, PHP, Ruby, and Python Data accessible via the REST API
Box 2: Azure Files You can map a Network File Share to an Azure Windows VM.
Box 3: Azure Blob Storage Azure Archive Storage is yet another storage tier available for blob storage. Hot, cool, and archive objects can all exist side by side in the same account. And with the introduction of blob-level tiering, you can change an object's tier with a single click in the Azure portal, or you can use the REST API (or .NET, Java, Python, and a number of other SDKs) to programmatically change as many objects as needed.
Premium block blobs storage accounts only support: __________________
Select the answer that correctly completes the sentence.
Correct Answer:
QUESTION 14
HOTSPOT
Several support engineers plan to manage Azure by using the computers shown in the following table:
You need to identify which Azure management tools can be used from each computer.
What should you identify for each computer? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Previously, the Azure CLI (or x-plat CLI) was the only option for managing Azure subscriptions and resources from the command-line on Linux and macOS. Now with the open source and cross-platform release of PowerShell, you'll be able to manage all your Azure resources from Windows, Linux and macOS using your tool of choice, either the Azure CLI or Azure PowerShell cmdlets. The Azure portal runs in a web browser so can be used in either operating system.
If an Azure virtual machine has a status of Stopped (deallocated), you will continue to pay for (_______________)
Correct Answer: STORAGE
QUESTION 17
DRAG DROP
Match the Azure Services service to the correct description.
Instructions: To answer, drag the appropriate service from the column on the left to its description on the right. Each service may be used once, more than once, or not at all.
NOTE: Each correct selection is worth one point.
Correct Answer:
QUESTION 18
HOTSPOT
Select the answer that correctly completes the sentence.
Correct Answer:
Explanation
Explanation/Reference:
Authentication is the process of establishing the identity of a user or service that wants to access a resource.
QUESTION 19
HOTSPOT
You plan to use Azure to host two apps named App1 and App2 The apps must meet the following requirements:
1. You must be able to modify the code of App1 2. Administrative effort to manage the operating system of App1 must be minimized. 3. App2 must run interactively with the operating system of the server.
Which type of cloud service should you use for each app?
Correct Answer:
Explanation
Explanation/Reference:
Box 1: Azure Platform as a service (PaaS) Organizations typically use PaaS for these scenarios: Development framework. PaaS provides a framework that developers can build upon to develop or customize cloud-based applications. Similar to the way you create an Excel macro, PaaS lets developers create applications using built-in software components. Cloud features such as scalability, high-availability, and multi-tenant capability are included, reducing the amount of coding that developers must do.
Box 2: Software as a service (SaaS) allows users to connect to and use cloud-based apps over the Internet. Common examples are email, calendaring, and office tools (such as Microsoft Office 365). SaaS provides a complete software solution that you purchase on a pay-as-you-go basis from a cloud service provider. You rent the use of an app for your organization, and your users connect to it over the Internet, usually with a web browser. All of the underlying infrastructure, middleware, app software, and app data are located in the service provider's data center. The service provider manages the hardware and software, and with the appropriate service agreement, will ensure the availability and the security of the app and your data as well. SaaS allows your organization to get quickly up and running with an app at minimal upfront cost. References: https://azure.microsoft.com/en-us/overview/what-is-paas/
QUESTION 20
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
An Azure administrator plans to run a PowerShell script that creates Azure resources.
You need to recommend which computer configuration to use to run the script.
Solution: Run the script from a computer that runs Chrome OS and uses Azure Cloud Shell.
Does this meet the goal?
A.
Yes
B.
No
Correct Answer: A
Explanation
Explanation/Reference:
A PowerShell script is a file that contains PowerShell cmdlets and code. A PowerShell script needs to be run in PowerShell.
With the Azure Cloud Shell, you can run PowerShell cmdlets and scripts in a Web browser. You log in to the Azure Portal and select the Azure Cloud Shell option. This will open a PowerShell session in the Web browser. The Azure Cloud Shell has the necessary Azure PowerShell module installed.
Note: to run a PowerShell script in the Azure Cloud Shell, you need to change to the directory where the PowerShell script is stored.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
An azure subscription can have multiple account administrators.No References: https://k21academy.com/microsoft-azure/az-900/az-900-azure-subscriptions/ https://azure.microsoft.com/en-us/blog/organizing-subscriptions-and-resource-groups-within-the-enterprise/
QUESTION 22
HOTSPOT
You can use the azure file sync agent to sync on-premises data to an azure________________
Select the answer that correctly completes the sentence.
Correct Answer:
Explanation
Explanation/Reference:
You can use the Azure File Sync agent to sync on-premises data to an Azure file share.
QUESTION 23
In which type of cloud model are all the hardware resources owned by a third-party and shared between multiple tenants?
A.
private
B.
hybrid
C.
public
Correct Answer: C
Explanation
Explanation/Reference:
Public Cloud: Hardware resources are owned and managed by a third-party cloud provider (e.g., Microsoft Azure).- Resources are shared between multiple tenants.- Services are accessed over the Internet, typically with pay-as-you-go pricing. Incorrect Options: Private Cloud: Resources are dedicated to a single organization.-Hardware is not shared between multiple tenants. Hybrid Cloud: Combines private and public cloud resources.-Not fully shared, third-party-owned hardware. References (Microsoft Learn): Public, private, and hybrid cloud models overview https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/strategy/plan-cloud-models
QUESTION 24
How many copies of data are maintained by an Azure Storage account that uses georedundant storage (GRS)?
A.
3
B.
4
C.
6
D.
9
Correct Answer: C
QUESTION 25
You have a virtual machine named VM1 that runs Windows Server 2016. VM1 is in the East US Azure region.
Which Azure service should you use from the Azure portal to view service failure notifications that can affect the availability of VM1?
A.
Azure Service Fabric
B.
Azure Monitor
C.
Azure virtual machines
D.
Azure Advisor
Correct Answer: B
Explanation
Explanation/Reference:
Azure Monitor includes the Azure Service Health feature, which provides personalized dashboards for viewing service failure notifications, planned maintenance, and health advisories that can affect the availability of resources like VM1. Azure Advisor provides best practice recommendations but does not provide real-time service failure notifications. Azure Service Fabric is for deploying and managing microservices, not for monitoring platform health. Azure virtual machines is a resource management blade, not a service for platform failure notifications. References: Microsoft Learn: (https://learn.microsoft.com/en-us/azure/service-health/service-health-overview) "Azure Service Health provides personalized alerts and guidance when Azure service issues like outages or maintenance affect your resources."-Microsoft Learn: (https://learn.microsoft.com/en-us/azure/azure-monitor/overview) "Azure Monitor collects, analyzes, and acts on telemetry from your cloud and on-premises environments. It integrates Azure Service Health to notify you of platform incidents and planned maintenance."
QUESTION 26
HOTSPOT
To complete the sentence, select the appropriate option in the answer area.
Correct Answer:
Explanation
Explanation/Reference:
An organization that hosts its infrastructure in the public cloud no longer requires a data center.
QUESTION 27
What can you use to identify underutilized or unused Azure virtual machines?
A.
Azure Advisor
B.
Azure Cost Management + Billing
C.
Azure reservations
D.
Azure Policy
Correct Answer: A
Explanation
Explanation/Reference:
Azure Advisor provides personalized recommendations to optimize Azure resources. For virtual machines, it identifies underutilized or unused VMs and recommends actions such as resizing, stopping, or deleting them to reduce costs.-Helps improve cost efficiency and resource utilization. Incorrect Options: Azure Cost Management + Billing: Focuses on analyzing costs, budgeting, and spending trends.- Does not specifically identify underutilized or unused VMs.-Azure Reservations: Used to pre-purchase capacity for cost savings.- Does not provide insights on VM utilization.-Azure Policy: Enforces compliance and governance rules.- Does not automatically identify underutilized or unused VMs. References (Microsoft Learn): Azure Advisor overview https://learn.microsoft.com/en-us/azure/advisor/advisor-overview Optimize and manage costs for Azure VMs using Azure Advisor https://learn.microsoft.com/en-us/azure/advisor/advisor-cost-recommendations References: https://docs.microsoft.com/en-us/azure/advisor/advisor-overview
QUESTION 28
HOTSPOT
Select the answer that correctly completes the sentence.
Correct Answer:
Explanation
Explanation/Reference:
Box: contains one or more data centers that are connected by using a low-latency network.
An azure region contains one or more data centers that are connected by using a low-latency network.
Each Azure region features datacenters deployed within a latency-defined perimeter. They're connected through a dedicated regional low-latency network. This design ensures that Azure services within any region offer the best possible performance and security. References: https://docs.microsoft.com/en-us/azure/availability-zones/az-overview
QUESTION 29
Your network contains an Active Directory forest. The forest contains 5,000 user accounts.
Your company plans to migrate all network resources to Azure and to decommission the on-premises data center.
You need to recommend a solution to minimize the impact on users after the planned migration.
What should you recommend?
A.
Implement Azure Multi-Factor Authentication (MFA)
B.
Sync all the Active Directory user accounts to Azure Active Directory (Azure AD)
C.
Instruct all users to change their password
D.
Create a guest user account in Azure Active Directory (Azure AD) for each user
Correct Answer: B
Explanation
Explanation/Reference:
To migrate to Azure and decommission the on-premises data center, you would need to create the 5,000 user accounts in Azure Active Directory. The easy way to do this is to sync all the Active Directory user accounts to Azure Active Directory (Azure AD). You can even sync their passwords to further minimize the impact on users. The tool you would use to sync the accounts is Azure AD Connect. The Azure Active Directory Connect synchronization services (Azure AD Connect sync) is a main component of Azure AD Connect. It takes care of all the operations that are related to synchronize identity data between your on-premises environment and Azure AD.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
You can create custom azure roles to control access to resources.Yes
QUESTION 31
Your company is planning a deployment using Azure Database for PostgreSQL. The deployment should meet the following requirements:
1. Up to 10 TB storage 2. Azure Premium Storage 3. Point-in-time-restore for up to 35 days
You need to select the appropriate deployment and pricing tier to meet these requirements and minimize costs.
What should you select?
A.
Azure Database for PostgreSQL Single Server Memory Optimized tier
B.
Azure Database for PostgreSQL Hyperscale (Citus)
C.
Azure Database for PostgreSQL Single Server General Purpose tier
D.
Azure Database for PostgreSQL Single Server Basic tier
Correct Answer: C
Explanation
Explanation/Reference:
1. Storage: Supports up to 16 TiB, sufficient for 10 TB. 2. Premium Storage: Uses Premium SSD/v2. 3. PITR: Supports backup retention up to 35 days.-Minimizes costs compared to Memory Optimized and Hyperscale (Citus) tiers.
1. Azure Database for PostgreSQL Single Server Memory Optimized tier: Meets technical requirements (storage, Premium SSD, 35-day PITR). Fails the cost requirement: more expensive than General Purpose, so not optimal for minimizing costs. 2. Azure Database for PostgreSQL Single Server Basic tier: Storage limitation: Maximum 1 TB, far below 10 TB requirement. Storage type: Standard storage, does not meet Premium SSD requirement. PITR limitation: Only 7 days, insufficient for the required 35 days.-Conclusion: Fails all three technical requirements. 3. Azure Database for PostgreSQL Hyperscale (Citus)): Meets storage and PITR requirements. Cost: Designed for distributed workloads, significantly more expensive than General Purpose. Overkill for single-server deployment; fails the "minimize costs" objective.
References (Microsoft Learn): Flexible Server compute tiers https://learn.microsoft.com/en-us/azure/postgresql/flexible-server/concepts-compute Flexible Server storage limits https://learn.microsoft.com/en-us/azure/postgresql/flexible-server/concepts-limits Flexible Server storage concepts https://learn.microsoft.com/en-us/azure/postgresql/flexible-server/concepts-storage
QUESTION 32
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Box 1: Yes Azure advisor provides personalized recommendations. Advisor is a personalized cloud consultant that helps you follow best practices to optimize your Azure deployments. It analyzes your resource configuration and usage telemetry and then recommends solutions that can help you improve the cost effectiveness, performance, Reliability (formerly called High availability), and security of your Azure resources.
Box 2: Yes Advisor provides recommendations for Application Gateway, App Services, availability sets, Azure Cache, Azure Data Factory, Azure Database for MySQL, Azure Database for PostgreSQL, Azure Database for MariaDB, Azure ExpressRoute, Azure Cosmos DB, Azure public IP addresses, Azure Synapse Analytics, SQL servers, storage accounts, Traffic Manager profiles, and virtual machines.
Box 3: Yes The Advisor dashboard displays personalized recommendations for all your subscriptions. You can apply filters to display recommendations for specific subscriptions and resource types.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Box 1: Yes Most services go to private preview then public preview before being released to general availability. The private preview is only available to certain Azure customers for evaluation purposes. The public preview is available to all Azure customers.
Box 2: No Azure services in public preview can be managed using the regular management tools: Azure Portal, Azure CLI and PowerShell.
Box 3: No Services in private or public preview are usually offered at reduced costs. However, the costs increase, not decrease when the services are released to general availability.
QUESTION 34
What can you use to automatically send an alert if an administrator stops an Azure virtual machine?
A.
Azure Advisor
B.
Azure Service Health
C.
Azure Monitor
D.
Azure Network Watcher
Correct Answer: C
Explanation
Explanation/Reference:
Azure Monitor can create Activity Log alerts on administrative actions. For example, when an administrator stops a VM (deallocate action), Azure Monitor can detect it and send an email, SMS, or trigger other automated actions.-This allows proactive monitoring of critical resources. Incorrect options: Azure Advisor: Provides recommendations for cost, performance, security, and reliability. Does not send real-time alerts for VM actions. Azure Service Health: Notifies about Azure service outages or planned maintenance. Does not alert on administrator actions. Azure Network Watcher: Monitors network connectivity and traffic. Does not track VM power state changes. References (Microsoft Learn): Create Activity Log alerts in Azure Monitor https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/alerts-activity-log Azure Advisor overview https://learn.microsoft.com/en-us/azure/advisor/advisor-overview Azure Service Health overview https://learn.microsoft.com/en-us/azure/service-health/service-health-overview Azure Network Watcher overview https://learn.microsoft.com/en-us/azure/network-watcher/network-watcher-monitoring-overview
QUESTION 35
HOTSPOT
You plan to extend your company's network to Azure.
The network contains a VPN appliance that uses an IP address of 131.107.700.1.
You need to create an Azure resource that defines the VPN appliance In Azure.
Which Azure resource should you create? To answer, select the appropriate resource in the answer area.
Correct Answer:
Explanation
Explanation/Reference:
A Local Network Gateway is an object in Azure that represents your on-premise VPN device. A Virtual Network Gateway is the VPN object at the Azure end of the VPN. A 'connection' is what connects the Local Network Gateway an the Virtual Network Gateway to bring up the VPN.
The local network gateway typically refers to your on-premises location. You give the site a name by which Azure can refer to it, then specify the IP address of the on-premises VPN device to which you will create a connection. You also specify the IP address prefixes that will be routed through the VPN gateway to the VPN device. The address prefixes you specify are the prefixes located on your on-premises network. If your on-premises network changes or you need to change the public IP address for the VPN device, you can easily update the values later.
If a resource group named RG1 has a delete lock, ______________________ can delete RG1.
Select the answer that correctly completes the sentence.
Correct Answer:
QUESTION 38
HOTSPOT
Autoscaling is an example of: _______________
Select the answer that correctly completes the sentence.
Correct Answer:
Explanation
Explanation/Reference:
An Azure virtual machine scale set can automatically increase or decrease the number of VM instances that run your application. This automated and elastic behavior reduces the management overhead to monitor and optimize the performance of your application.
Also: Azure elasticity as a service is referred to a cloud service that enables in automatically scaling Azure hosted resources in par with the demand and configured parameters. It provides Azure Administrators with the ability to auto scale Azure infrastructure and resources as and when needed.
You have a set of Azure policies. You need to group related policies together.
What should you use?
A.
exemptions
B.
metadata
C.
parameters
D.
initiatives
Correct Answer: D
QUESTION 40
This question requires that you evaluate the underlined text to determine if it is correct.
An Azure region contains one or more data centers that are connected by using a low-latency network.
Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct.
A.
No change is needed
B.
Is found in each country where Microsoft has a subsidiary office
C.
Can be found in every country in Europe and the Americas only
D.
Contains one or more data centers that are connected by using a high-latency network
Correct Answer: A
Explanation
Explanation/Reference:
A region is a set of data centres deployed within a latency-defined perimeter and connected through a dedicated regional low-latency network. Microsoft Azure currently has 55 regions worldwide. Regions are divided into Availability Zones. Availability Zones are physically separate locations within an Azure region. Each Availability Zone is made up of one or more datacenters equipped with independent power, cooling, and networking.
Your company implements ________________________________ to automatically add a watermark to microsoft word documents that contain credit card information
To complete the sentence, select the appropriate option in the answer area.
Correct Answer:
QUESTION 42
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your company plans to migrate all its data and resources to Azure.
The company's migration plan states that only Platform as a Service (PaaS) solutions must be used in Azure.
You need to deploy an Azure environment that supports the planned migration.
Solution: You create an Azure App Service and Azure Storage accounts.
Does this meet the goal?
A.
Yes
B.
No
Correct Answer: A
Explanation
Explanation/Reference:
Azure App Service is a PaaS web-hosting service that runs applications without managing virtual machines or operating systems. Azure Storage is also a PaaS service that provides fully managed storage services.
Both services are managed by Microsoft and do not require infrastructure management. Since no IaaS services (such as virtual machines) are used, the solution complies with the PaaS-only policy.
Incorrect solutions would include: Azure Virtual Machines Self-managed databases Custom operating systems
All of these would violate the PaaS-only requirement.
REFERENCES (Microsoft Learn):
Azure App Service overview https://learn.microsoft.com/en-us/azure/app-service/overview
PaaS definition and examples https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/strategy/cloud-service-models
IaaS vs PaaS vs SaaS (comparison guide) https://learn.microsoft.com/en-us/azure/architecture/framework/technology-choices/compute-decision-tree
QUESTION 43
Your company plans 10 migrate all its data and resources to Azure.
The company's migration plan states that only Platform as a Service (PaaS) solutions must be used in Azure
You need to deploy an Azure environment that meets the company's migration plan
What should you create?
A.
an Azure App Service and Azure SQL databases
B.
Azure storage accounts and web server in Azure virtual machines
C.
Azure virtual machines. Azure SQL databases, and Azure Storage accounts
D.
an Azure App Service and Azure virtual machines that have Microsoft SQL Server installed
Correct Answer: A
Explanation
Explanation/Reference:
Azure App Service and Azure SQL databases are examples of Azure PaaS solutions. Therefore, this solution does meet the goal. **Azure App Service** is a PaaS offering for hosting web apps without managing the VM or OS. **Azure SQL Database** is a fully managed PaaS database service. This combination satisfies the requirement to use only PaaS solutions.
Incorrect Options: 1. Azure storage accounts and web server in Azure virtual machines: Using a VM for the web server is **IaaS**, not PaaS. 2. Azure virtual machines, Azure SQL databases, and Azure Storage accounts: Virtual machines are **IaaS**, violating the migration plan requirement. 3. Azure App Service and Azure virtual machines with SQL Server installed: Using a VM for SQL Server is **IaaS**, which is not allowed per the plan.
What should you use to track the costs of Azure resources?
A.
Tags
B.
usage and quotas
C.
Azure Quickstart templates
D.
budgets
Correct Answer: D
Explanation
Explanation/Reference:
Azure Budgets allows you to monitor and track costs for Azure resources and subscriptions.
You can set a budget for a specific scope (subscription, resource group, or management group) and receive alerts when spending approaches or exceeds the budgeted amount. This is the recommended way to track and control Azure costs over time. Incorrect Options: Tags: Help organize and categorize Azure resources, but do not track costs directly. Usage and quotas: Provide information about resource usage limits and consumption but do not provide cost tracking or alerts. Azure Quickstart templates: Used to deploy resources quickly in Azure; they do not track costs. References: https://learn.microsoft.com/en-us/azure/cost-management-billing/costs/tutorial-acm-create-budgets https://learn.microsoft.com/en-us/azure/cost-management-billing/costs/cost-analysis-overview
QUESTION 45
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Box 1: No Authorization to access azure resources can be provided only to azure active directory users. No Authorization to access Azure resources can be provided by other identity providers by using federation. A commonly used example of this is to federate your on-premises Active Directory environment with Azure AD and use this federation for authentication and authorization.
Box 2: Yes As described above, third-party cloud services and on-premises Active Directory can be used to access Azure resources. This is known as 'federation'. Federation is a collection of domains that have established trust. The level of trust may vary, but typically includes authentication and almost always includes authorization. A typical federation might include a number of organizations that have established trust for shared access to a set of resources.
Box 3: Yes Azure Active Directory (Azure AD) is a centralized identity provider in the cloud. This is the primary built-in authentication and authorization service to provide secure access to Azure resources.
You need to identify which blades in the Azure portal must be used to perform the following tasks:
1. View security recommendations. 2. Monitor the health of Azure services. 3. Browse available virtual machine images.
Which blade should you identify for each task? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Box 1: Azure Monitor is used to monitor the health of Azure services. Azure Monitor maximizes the availability and performance of your applications and services by delivering a comprehensive solution for collecting, analyzing, and acting on telemetry from your cloud and on-premises environments. It helps you understand how your applications are performing and proactively identifies issues affecting them and the resources they depend on.
Box 2: You can browse available virtual machine images in the Azure Marketplace. Azure Marketplace provides access and information on solutions and services available from Microsoft and their partners. Customers can discover, try, or buy cloud software solutions built on or for Azure. The catalog of 8,000+ listings provides Azure building blocks, such as Virtual Machines (VMs), APIs, Azure apps, Solution Templates and managed applications, SaaS apps, containers, and consulting services.
Box 3. Azure Advisor displays security recommendations. Azure Advisor provides you with a consistent, consolidated view of recommendations for all your Azure resources. It integrates with Azure Security Center to bring you security recommendations. You can get security recommendations from the Security tab on the Advisor dashboard.
Security Center helps you prevent, detect, and respond to threats with increased visibility into and control over the security of your Azure resources. It periodically analyzes the security state of your Azure resources. When Security Center identifies potential security vulnerabilities, it creates recommendations. The recommendations guide you through the process of configuring the controls you need.
Your company has an Azure environment that contains resources in several regions.
A company policy states that administrators must only be allowed to create additional Azure resources in a region in the country where their office is located.
You need to create the Azure resource that must be used to meet the policy requirement.
What should you create?
A.
a read-only lock
B.
an Azure policy
C.
a management group
D.
a reservation
Correct Answer: B
Explanation
Explanation/Reference:
Azure policies can be used to define requirements for resource properties during deployment and for already existing resources. Azure Policy controls properties such as the types or locations of resources.
Azure Policy is a service in Azure that you use to create, assign, and manage policies. These policies enforce different rules and effects over your resources, so those resources stay compliant with your corporate standards and service level agreements. Azure Policy meets this need by evaluating your resources for non-compliance with assigned policies. All data stored by Azure Policy is encrypted at rest.
Azure Policy offers several built-in policies that are available by default. In this question, we would use the `Allowed Locations' policy to define the locations where resources can be deployed.
The company plans to implement an Azure environment.
You need to ensure that each department can use a different payment option for the Azure services it consumes.
What should you create for each department?
A.
a reservation
B.
a subscription
C.
a resource group
D.
a container instance
Correct Answer: B
Explanation
Explanation/Reference:
There are different payment options in Azure including pay-as-you-go (PAYG), Enterprise Agreement (EA), and Microsoft Customer Agreement (MCA) accounts.
Your Azure costs are `per subscription'. You are charged monthly for all resources in a subscription. Therefore, to use different payment options per department, you will need to create a separate subscription per department. You can create multiple subscriptions in a single Azure Active Directory tenant.
Incorrect Answers: A: A reservation is where you commit to a resource (for example a virtual machine) for one or three years. This gives you a discounted price on the resource for the reservation period. Reservations do not provide a way to use different payment options per department. C: A resource group is a logical container for Azure resources. You can view the total cost of all the resources in a resource group. However, resource groups do not provide a way to use different payment options per department. D: A container instance is an Azure resource used to run an application. Container instances do not provide a way to use different payment options per department.
In which Azure support plans can you open a new support request?
A.
Premier and Professional Direct only
B.
Premier, Professional Direct, and Standard only
C.
Premier, Professional Direct, Standard, and Developer only
D.
Premier, Professional Direct, Standard, Developer, and Basic
Correct Answer: D
Explanation
Explanation/Reference:
All Azure support plans allow you to open a support request. The difference between plans is the type of support, response times, and access to support engineers. - Basic: Limited support, includes billing and subscription support.- Developer: Technical support during business hours.- Standard: 24x7 support for production workloads. Professional Direct: 24x7 support with faster response times and access to ProDirect delivery manager. Premier: Enterprise-level support with prioritized response and dedicated support resources. Reasons why other answers are incorrect: Limiting to only Premier and Professional Direct, or Standard and Developer, is incorrect because even the Basic and Developer plans can open support requests, though with different response times and severity levels.
Your company plans to migrate all its network resources to Azure.
You need to start the planning process by exploring Azure.
What should you create first?
A.
a subscription
B.
a resource group
C.
a virtual network
D.
a management group
Correct Answer: A
Explanation
Explanation/Reference:
The first thing you create in Azure is a subscription. You can think of an Azure subscription as an `Azure account'. You get billed per subscription. A subscription is an agreement with Microsoft to use one or more Microsoft cloud platforms or services, for which charges accrue based on either a per-user license fee or on cloud-based resource consumption.
Microsoft's Software as a Service (SaaS)-based cloud offerings (Office 365, Intune/EMS, and Dynamics 365) charge per-user license fees. Microsoft's Platform as a Service (PaaS) and Infrastructure as a Service (IaaS) cloud offerings (Azure) charge based on cloud resource consumption.
You can also use a trial subscription, but the subscription expires after a specific amount of time or consumption charges. You can convert a trial subscription to a paid subscription. Organizations can have multiple subscriptions for Microsoft's cloud offerings.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Availability zones expand the level of control you have to maintain the availability of the applications and data on your VMs. Availability Zones are unique physical locations within an Azure region. Each zone is made up of one or more datacenters equipped with independent power, cooling, and networking. To ensure resiliency, there are a minimum of three separate zones in all enabled regions. The physical separation of Availability Zones within a region protects applications and data from datacenter failures. With Availability Zones, Azure offers industry best 99.99% VM uptime SLA. By architecting your solutions to use replicated VMs in zones, you can protect your applications and data from the loss of a datacenter. If one zone is compromised, then replicated apps and data are instantly available in another zone.
You can use availability zones in azure to protect azure virtual machines from a datacenter failure. Yes You can use availability zones in azure to protect azure virtual machines from a region failure. No You can use availability zones in azure to protect azure managed disks from a datacenter failure. Yes
Which two features or services can be integrated with Azure Monitor? Each correct answer presents part of the solution.
NOTE: Each correct answer is worth one point.
A.
Azure status
B.
Application Insights
C.
Azure Advisor
D.
Log Analytics
E.
Azure Service Health
Correct Answer: BD
Explanation
Explanation/Reference:
Application Insights: An application performance monitoring service that collects telemetry and integrates with Azure Monitor to provide insights into application health, performance, and usage. Log Analytics: A service that collects and analyzes log data from Azure resources and integrates with Azure Monitor for advanced query and alerting capabilities.
Incorrect Options:
Azure Status: Provides the current health of Azure services globally; it does not integrate directly with Azure Monitor. Azure Service Health: Provides notifications and guidance about Azure service issues; while it complements Azure Monitor, it is not a data integration point for monitoring. Azure Advisor: Provides recommendations for cost, performance, and security optimization; it does not provide telemetry data to Azure Monitor.
Match the cloud computing benefits to the correct descriptions.
To answer, drag the appropriate benefit from the column on the left to its description on the right. Each benefit may be used once, more than once, or not at all.
You plan to deploy a service to Azure virtual machines.
You need to ensure that the service will be available if a datacenter fails.
What should you use as part of the virtual machine deployment?
A.
availability sets
B.
proximity placement groups
C.
host groups
D.
availability zones
Correct Answer: D
Explanation
Explanation/Reference:
Azure availability zones are physically separate locations within each Azure region that are tolerant to local failures. Failures can range from software and hardware failures to events such as earthquakes, floods, and fires. Tolerance to failures is achieved because of redundancy and logical isolation of Azure services. To ensure resiliency, a minimum of three separate availability zones are present in all availability zone-enabled regions.
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You plan to deploy several Azure virtual machines.
You need to ensure that the services running on the virtual machines are available if a single data center fails.
Solution: You deploy the virtual machines to two or more resource groups.
Does this meet the goal?
A.
Yes
B.
No
Correct Answer: B
Explanation
Explanation/Reference:
A resource group is a logical container for Azure resources. When you create a resource group, you specify which location to create the resource group in. However, when you create a virtual machine and place it in the resource group, the virtual machine can still be in a different location (different datacenter). Therefore, creating multiple resource groups, even if they are in separate datacenters does not ensure that the services running on the virtual machines are available if a single data center fails.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
You must install Azure Cloud Shell on your computer before you can use it. No
QUESTION 57
DRAG DROP
You need to complete the defense-in-depth strategy used in a datacenter.
What should you do? To answer, drag the appropriate layers to the correct positions in the model. Each layer may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Defence in depth layers (from bottom to top): Data - In almost all cases attackers are after data. - Data can be in database, stored on disk inside VMs, on a SaaS application such as Office 365 or in cloud storage. - Those storing and controlling access to data to ensures that it's properly secured - Often regulatory requirements dictates controls & processes - to ensure confidentiality, integrity, and availability. Application - Ensure applications are secure and free of vulnerabilities. - Store sensitive application secrets in a secure storage medium. - Make security a design requirement for all application development. - Integrate security into the application development life cycle. Compute - Secure access to virtual machines. - Implement endpoint protection and keep systems patched and current. - Malware, unpatched systems, and improperly secured systems open your environment to attacks. Networking - Limit communication between resources. - Deny by default. - Allow only what is required - Restrict inbound internet access and limit outbound, where appropriate. - Implement secure connectivity to on-premises networks. Perimeter - Use distributed denial of service (DDoS) protection to filter large-scale attacks before they can cause a denial of service for end users. - Use perimeter firewalls to identify and alert on malicious attacks against your network. Identity and access - Control access to infrastructure and change control. - Access granted is only what is needed - Use single sign-on and multi-factor authentication. - Audit events and changes. Physical security - Building security & controlling access to computing hardware. - First line of defense.
This question requires that you evaluate the underlined text to determine if it is correct.
Your company implements Azure policies to automatically add a watermark to Microsoft Word documents that contain credit card information.
Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct.
A.
No change is needed.
B.
DDoS protection
C.
Azure Information Protection
D.
Azure Active Directory (Azure AD) Identity Protection
Correct Answer: C
Explanation
Explanation/Reference:
Azure Information Protection is used to automatically add a watermark to Microsoft Word documents that contain credit card information.
You use Azure Information Protection labels to apply classification to documents and emails. When you do this, the classification is identifiable regardless of where the data is stored or with whom it's shared. The labels can include visual markings such as a header, footer, or watermark.
Labels can be applied automatically by administrators who define rules and conditions, manually by users, or a combination where users are given recommendations. In this question, we would configure a label to be automatically applied to Microsoft Word documents that contain credit card information. The label would then add the watermark to the documents.
Match the Azure service to the correct definition.
Instructions: To answer, drag the appropriate Azure service from the column on the left to its description on the right. Each service may be used once, more than once, or not at all.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Box 1: Azure Functions provides the platform for serverless code. Azure Functions is a serverless compute service that lets you run event-triggered code without having to explicitly provision or manage infrastructure.
Box 2: Azure Databricks is a big analysis service for machine learning. Azure Databricks is an Apache Spark-based analytics platform. The platform consists of several components including 'MLib'. Mlib is a Machine Learning library consisting of common learning algorithms and utilities, including classification, regression, clustering, collaborative filtering, dimensionality reduction, as well as underlying optimization primitives.
Box 3: Azure Application Insights detects and diagnoses anomalies in web apps. Application Insights, a feature of Azure Monitor, is an extensible Application Performance Management (APM) service for developers and DevOps professionals. Use it to monitor your live applications. It will automatically detect performance anomalies, and includes powerful analytics tools to help you diagnose issues and to understand what users actually do with your app.
Box 4: Azure App Service hosts web apps. Azure App Service is an HTTP-based service for hosting web applications, REST APIs, and mobile back ends. You can develop in your favorite language, be it .NET, .NET Core, Java, Ruby, Node.js, PHP, or Python. Applications run and scale with ease on both Windows and Linux-based environments.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Box 1: No Adding more ram to a virtual machine is an example of horizontal scaling. No Horizontal scaling refers to adding more instances, or removing instances, of resources used by a workload. For example, extending an application from one compute instance to five compute instances. The Microsoft Azure cloud supports automatic horizontal scaling for compute instances, called virtual machines (VMs).
Horizontal scaling is flexible in a cloud situation because you can use it to run a large number of VMs to handle load. In contrast, scaling up and down, or vertical scaling, keeps the same number of resource instances constant but gives them more capacity in terms of memory, CPU speed, disk space, and network.
Box 2: No
Box 3: Yes Autoscale scales in and out, or horizontally. Scaling horizontally is an increase or decrease of the number of resource instances.
Select the answer that correctly completes the sentence.
Correct Answer:
QUESTION 63
This question requires that you evaluate the underlined text to determine if it is correct.
Data that is stored in the Archive access tier of an Azure Storage account can be accessed at any time by using azcopy.exe.
Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct.
A.
No change is needed.
B.
can only be read by using Azure Backup
C.
must be restored before the data can be accessed
D.
must be rehydrated before the data can be accessed
Correct Answer: D
Explanation
Explanation/Reference:
Corrected Statement: Data that is stored in the Archive access tier of an Azure Storage account (must be rehydrated before the data can be accessed).
Reasoning: The **Archive access tier** in Azure Storage is intended for long-term, infrequently accessed data. Data in the Archive tier is **offline** and must be **rehydrated** to an online tier (Hot or Cool) before it can be read or accessed. Other options: "No change is needed" Incorrect. Data cannot be accessed immediately; it must be rehydrated first. "Can only be read by using Azure Backup" Incorrect. Azure Backup is a separate service; Archive data can be restored via any supported storage access method after rehydration. "Must be restored before the data can be accessed" Partially correct but vague; the technical term is **rehydration**.
References: Microsoft Learn: (https://learn.microsoft.com/en-us/azure/storage/blobs/storage-blob-storage-tiers#archive) "Data in the Archive tier is offline and cannot be read or modified. To access the data, you must first rehydrate it to the Hot or Cool tier." Microsoft Learn: (https://learn.microsoft.com/en-us/azure/storage/blobs/storage-blob-rehydration-overview) "Rehydration is the process of moving data from the Archive tier to an online tier so it can be accessed or read."
QUESTION 64
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation
Explanation/Reference:
Azure pay-as-you-go pricing is an example of capex. No
QUESTION 65
HOTSPOT
To complete the sentence, select the appropriate option in the answer area.
Correct Answer:
Explanation
Explanation/Reference:
One of the benefits of zure sql data warehouse is that high availability is built into the platform
QUESTION 66
What is used to grant permission to Azure Virtual Desktop resources?
A.
tags
B.
role-based access control (RBAC) roles
C.
resource groups
D.
application security groups
Correct Answer: B
Explanation
Explanation/Reference:
RBAC roles: Role-Based Access Control (RBAC) in Azure is used to grant users, groups, or applications specific permissions to Azure resources. For Azure Virtual Desktop, you assign RBAC roles to control access to host pools, application groups, and workspaces. This ensures that only authorized users can manage or access resources. Incorrect Answers: Tags: Tags are used for organizing resources and tracking costs; they do not grant access permissions. Resource groups: Resource groups are containers for Azure resources; they do not control permissions themselves, although you can assign RBAC roles at the resource group level. Application security groups: These are used to group virtual machines for network security purposes, not for granting access permissions. https://learn.microsoft.com/en-us/azure/role-based-access-control/overview https://learn.microsoft.com/en-us/azure/virtual-desktop/manage-rbac
This question requires that you evaluate the underlined text to determine if it is correct.
You deploy an Azure resource. The resource becomes unavailable for an extended period due to a service outage. Microsoft will automatically refund your bank account.
Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct.
A.
No change is needed.
B.
automatically migrate the resource to another subscription
C.
automatically credit your account
D.
send you a coupon code that you can redeem for Azure credits
Correct Answer: C
Explanation
Explanation/Reference:
If the SLA for an Azure service is not met, you receive credits for that service and that service only. The credits are deducted from your monthly bill for that service. If you stopped using the service where the SLA was not met, your account would remain in credit for that service. The credits would not be applied to any other services that you may be using.
Service Credits apply only to fees paid for the particular Service, Service Resource, or Service tier for which a Service Level has not been met. In cases where Service Levels apply to individual Service Resources or to separate Service tiers, Service Credits apply only to fees paid for the affected Service Resource or Service tier, as applicable. The Service Credits awarded in any billing month for a particular Service or Service Resource will not, under any circumstance, exceed your monthly service fees for that Service or Service Resource, as applicable, in the billing month.
From __________________ you can view which user turned off a specific virtual machine during the last 14 days.
To complete the sentence, select the appropriate option in the answer area.
Correct Answer:
QUESTION 69
Your company plans to deploy several custom applications to Azure.
The applications will provide invoicing services to the customers of the company.
Each application will have several prerequisite applications and services installed.
You need to recommend a cloud deployment solution for all the applications.
What should you recommend?
A.
Software as a Service (SaaS)
B.
Platform as a Service (PaaS)
C.
Infrastructure as a Service (laaS)
Correct Answer: C
Explanation
Explanation/Reference:
Infrastructure as a service (IaaS) is an instant computing infrastructure, provisioned and managed over the internet. The IaaS service provider manages the infrastructure, while you purchase, install, configure, and manage your own software
Incorrect Answers: A: Software as a service (SaaS) allows users to connect to and use cloud-based apps over the Internet. Common examples are email, calendaring, and office tools. In this scenario, you need to run your own apps, and therefore require an infrastructure.
B:Platform as a service (PaaS) is a complete development and deployment environment in the cloud. PaaS includes infrastructure--servers, storage, and networking--but also middleware, development tools, business intelligence (BI) services, database management systems, and more. PaaS is designed to support the complete web application lifecycle: building, testing, deploying, managing, and updating.
You need to be notified when Microsoft plans to perform maintenance that can affect the resources deployed to an Azure subscription.
What should you use?
A.
Azure Monitor
B.
Azure Service Health
C.
Azure Advisor
D.
Microsoft Trust Center
Correct Answer: B
Explanation
Explanation/Reference:
Azure Service Health provides a personalized view of the health of the Azure services and regions you're using. This is the best place to look for service impacting communications about outages, planned maintenance activities, and other health advisories because the authenticated Service Health experience knows which services and resources you currently use.
The cool access tier is optimized ________________________
Select the answer that correctly completes the sentence.
Correct Answer:
Explanation
Explanation/Reference:
Box: for data that is accessed infrequently and stored for at least 30 days Cool tier - An online tier optimized for storing data that is infrequently accessed or modified. Data in the cool tier should be stored for a minimum of 30 days. The cool tier has lower storage costs and higher access costs compared to the hot tier.
Incorrect: * for data that is accessed rarely, is stored for at least 180 days, ..