Which is the best way to clear Microsoft AZ-104 exam in first attempt? The answer is: Valid Microsoft AZ-104 exam dumps! Passing the Microsoft AZ-104 exam has never been so easy. With the support of the exam dump provided by https://www.pass4itsure.com/az-104.html (Updated: Sep 21, 2020), you can easily pass the exam.

Valid Microsoft AZ-104 Exam Video

Practice test | Microsoft Role-based AZ-104 Exam Questions Answers

QUESTION 1
You download an Azure Resource Manager template based on an existing virtual machine. The template will be used to
deploy 100 virtual machines. You need to modify the template to reference an administrative password. You must
prevent the password from being stored in plain text.
What should you create to store the password?
A. Azure Active Directory (AD) Identity Protection and an Azure policy
B. a Recovery Services vault and a backup policy
C. an Azure Key Vault and an access policy
D. an Azure Storage account and an access policy
Correct Answer: C
You can use a template that allows you to deploy a simple Windows VM by retrieving the password that is stored in a
Key Vault. Therefore the password is never put in plain text in the template parameter file. References:
https://azure.microsoft.com/en-us/resources/templates/101-vm-secure-password/


QUESTION 2
You have five Azure virtual machines that run Windows Server 2016. The virtual machines are configured as web
servers.
You have an Azure load balancer named LB1 that provides load balancing services for the virtual machines.
You need to ensure that visitors are serviced by the same web server for each request.
What should you configure?
A. Floating IP (direct server return) to Enabled
B. Idle Time-out (minutes) to 20
C. Protocol to UDP
D. Session persistence to Client IP and Protocol
Correct Answer: D
With Sticky Sessions when a client starts a session on one of your web servers, session stays on that specific server.
To configure An Azure Load-Balancer For Sticky Sessions set Session persistence to Client IP. On the following image
you can see sticky session configuration:

gailemartinenaite az-104 exam questions-q2

Reference: https://cloudopszone.com/configure-azure-load-balancer-for-sticky-sessions/

QUESTION 3
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it.
As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains the following resources:
*
A virtual network that has a subnet named Subnet1
*
Two network security groups (NSGs) named NSG-VM1 and NSG-Subnet1
*
A virtual machine named VM1 that has the required Windows Server configurations to allow Remote Desktop
connections NSG-Subnet1 has the default inbound security rules only. NSG-VM1 has the default inbound security rules
and the
following custom inbound security rule:
*
Priority: 100
*
Source: Any
* Source port range: *
* Destination: *
*
Destination port range: 3389
*
Protocol: UDP
*
Action: Allow
VM1 connects to Subnet1. NSG1-VM1 is associated to the network interface of VM1. NSG-Subnet1 is associated to
Subnet1.
You need to be able to establish Remote Desktop connections from the internet to VM1. Solution: You add an inbound
security rule to NSG-Subnet1 that allows connections from the Internet source to the VirtualNetwork destination for port
range 3389 and uses the UDP protocol.
Does this meet the goal?
A.
Yes
B.
No
Correct Answer: B

QUESTION 4
You have an Azure Storage account named storage1.
You plan to use AzCopy to copy data to storage1.
You need to identify the storage services in storage1 to which you can copy the data.
What should you identify?
A. blob, file, table, and queue
B. blob and file only
C. file and table only
D. file only
E. blob, table, and queue only
Correct Answer: B
AzCopy is a command-line utility that you can use to copy blobs or files to or from a storage account.
Incorrect Answers:
A, C, E: AzCopy does not support table and queue storage services.
D: AzCopy supports file storage services, as well as blob storage services.
Reference: https://docs.microsoft.com/en-us/azure/storage/common/storage-use-azcopy-v10

QUESTION 5
You need to resolve the licensing issue before you attempt to assign the license again. What should you do?
A. From the Groups blade, invite the user accounts to a new group.
B. From the Profile blade, modify the usage location.
C. From the Directory role blade, modify the directory role.
Correct Answer: A


QUESTION 6
You need to identify the storage requirements for Contoso. For each of the following statements, select Yes if the
statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Hot Area:

gailemartinenaite az-104 exam questions-q6

Correct Answer:

gailemartinenaite az-104 exam questions-q6-2

Box 1: Yes Contoso is moving the existing product blueprint files to Azure Blob storage. Use unmanaged standard
storage for the hard disks of the virtual machines. We use Page Blobs for these. Box 2: No Box 3: No


QUESTION 7
You have an Azure subscription named Subscription1 that contains the resources shown in the following table.

gailemartinenaite az-104 exam questions-q7

You plan to configure Azure Backup reports for Vault1. You are configuring the Diagnostics settings for the
AzureBackupReports log. Which storage accounts and which Log Analytics workspaces can you use for the Azure
Backup reports of
Vault1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

gailemartinenaite az-104 exam questions-q7-2

Box 1: storage3 only
Vault1 and storage3 are both in West Europe.
Box 2: Analytics3
Vault1 and Analytics3 are both in West Europe.
References:
https://docs.microsoft.com/en-us/azure/backup/backup-azure-configure-reports

QUESTION 8
You need to prepare the environment to meet the authentication requirements. Which two actions should you perform?
Each correct answer presents part of the solution. NOTE Each correct selection is worth one point.
A. Azure Active Directory (AD) Identity Protection and an Azure policy
B. a Recovery Services vault and a backup policy
C. an Azure Key Vault and an access policy
D. an Azure Storage account and an access policy
Correct Answer: BD
D: Seamless SSO works with any method of cloud authentication – Password Hash Synchronization or Pass-through
Authentication, and can be enabled via Azure AD Connect.
B: You can gradually roll out Seamless SSO to your users. You start by adding the following Azure AD URL to all or
selected users\\’ Intranet zone settings by using Group Policy in Active Directory: https://autologon.microsoftazureadsso.com Incorrect Answers:
A: Seamless SSO needs the user\\’s device to be domain-joined, but doesn\\’t need for the device to be Azure AD
Joined.
C: Azure AD connect does not port 8080. It uses port 443.
E: Seamless SSO is not applicable to Active Directory Federation Services (ADFS). Scenario: Users in the Miami office
must use Azure Active Directory Seamless Single Sign-on (Azure AD Seamless SSO) when accessing resources in
Azure.
Planned Azure AD Infrastructure include: The on-premises Active Directory domain will be synchronized to Azure AD.
References: https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso-quickstart

QUESTION 9
You have an Azure virtual machine named VM1 that runs Windows Server 2019.
You save VM1 as a template named Template1 to the Azure Resource Manager library.
You plan to deploy a virtual machine named VM2 from Template1.
What can you configure during the deployment of VM2?
A. operating system
B. administrator username
C. virtual machine size
D. resource group
Correct Answer: B
When deploying a virtual machine from a template, you must specify:
1.
the Resource Group name and location for the VM
2.
the administrator username and password
3.
an unique DNS name for the public IP
Reference: https://docs.microsoft.com/en-us/azure/virtual-machines/windows/ps-template

QUESTION 10
You create an Azure VM named VM1 that runs Windows Server 2019. VM1 is configured as shown in the exhibit. (Click
the Exhibit button.)

gailemartinenaite az-104 exam questions-q10

You need to enable Desired State Configuration for VM1. What should you do first?
A. Configure a DNS name for VM1.
B. Start VM1.
C. Connect to VM1.
D. Capture a snapshot of VM1.
Correct Answer: B
Status is Stopped (Deallocated).
The DSC extension for Windows requires that the target virtual machine is able to communicate with Azure.
The VM needs to be started.
References:
https://docs.microsoft.com/en-us/azure/virtual-machines/extensions/dsc-windows

QUESTION 11
You have an Azure subscription named Subscription1 that contains the resources shown in the following table.

gailemartinenaite az-104 exam questions-q11

You plan to use Vault1 for the backup of as many virtual machines as possible. Which virtual machines can be backed
up to Vault1?
A. VM1, VM3, VMA, and VMC only
B. VM1 and VM3 only
C. VM1, VM2, VM3, VMA, VMB, and VMC
D. VM1 only
E. VM3 and VMC only
Correct Answer: A
To create a vault to protect virtual machines, the vault must be in the same region as the virtual machines. If you have
virtual machines in several regions, create a Recovery Services vault in each region.
References:
https://docs.microsoft.com/bs-cyrl-ba/azure/backup/backup-create-rs-vault


QUESTION 12
You plan to deploy five virtual machines to a virtual network subnet. Each virtual machine will have a public IP address
and a private IP address. Each virtual machine requires the same inbound and outbound security rules. What is the
minimum number of network interfaces and network security groups that you require? To answer, select the appropriate
options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

gailemartinenaite az-104 exam questions-q12

Correct Answer:

gailemartinenaite az-104 exam questions-q12-2

Box 1: 10
One public and one private network interface for each of the five VMs.
Box 2: 1
You can associate zero, or one, network security group to each virtual network subnet and network interface in a virtual
machine. The same network security group can be associated to as many subnets and network interfaces as you
choose.
References:
https://docs.microsoft.com/en-us/azure/virtual-network/security-overview

QUESTION 13
You have an Azure subscription that contains a policy-based virtual network gateway named GW1 and a virtual network
named VNet1.
You need to ensure that you can configure a point-to-site connection from an on-premises computer to VNet1.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Add a service endpoint to VNet1
B. Reset GW1
C. Create a route-based virtual network gateway
D. Add a connection to GW1
E. Delete GW1
F. Add a public IP address space to VNet1
Correct Answer: CE
C: A VPN gateway is used when creating a VPN connection to your on-premises network.
Route-based VPN devices use any-to-any (wildcard) traffic selectors, and let routing/forwarding tables direct traffic to
different IPsec tunnels. It is typically built on router platforms where each IPsec tunnel is modeled as a network interface
or
VTI (virtual tunnel interface).
E: Policy-based VPN devices use the combinations of prefixes from both networks to define how traffic is
encrypted/decrypted through IPsec tunnels. It is typically built on firewall devices that perform packet filtering. IPsec
tunnel encryption
and decryption are added to the packet filtering and processing engine.
Incorrect Answers:
F: Point-to-Site connections do not require a VPN device or a public-facing IP address.
Reference: https://docs.microsoft.com/en-us/azure/vpn-gateway/create-routebased-vpn-gateway-portal
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-connect-multiple-policybased-rm-ps

Easy Microsoft Role-based AZ-104 PDF Dumps

[100% free, pdf] Microsoft AZ-104 PDF Dumps https://drive.google.com/file/d/1w0GeagWT7EPYsRrvS-_EEBRZKO31HUeR/view?usp=sharing

Pass4itsure Give Top Quality Microsoft AZ-104 Exam Dumps

Pass4itsure has created AZ-104 preparation materials for all busy planning IT professionals who cannot prepare for the Microsoft AZ-104 exam pdf dumps. Pass4itsure solves your problems related to Microsoft AZ-104 exam.

Pass4itsure Features

Discount Offer of 12% by Pass4itsure

Latest discount code “2020PASS” – Pass4itsure.

Pass4itsure discount code 2020

Microsoft AZ-104 Pertinent Questions Answers PDF Free Share: https://drive.google.com/file/d/1w0GeagWT7EPYsRrvS-_EEBRZKO31HUeR/view?usp=sharing

Full Microsoft Series Exam Dumps Free Share: https://www.exampass.net/?s=Microsoft

P.S.

It is highly recommended Pass4itsure AZ-104 dumps PDF study for the AZ-104 exam https://www.pass4itsure.com/az-104.html Have the best AZ-104 exam dumps to prepare for the exam, including PDF files and point-to-point question answers.