AZ-900

Pataasin ang iyong marka sa homework at exams ngayon gamit ang Quizwiz!

At which OSI layer does ExpressRoute operate? A. Layer 2 B. Layer 3 C. Layer 5 D. Layer 7

B Layer 3

Your network contains an Active Directory forest. The forest contains 5,000 user accounts.Your company plans to migrate all network resources to Azure and to decommission the on-premises data center.You need to recommend a solution to minimize the impact on users after the planned migration.What should you recommend? A. Implement Azure Multi-Factor Authentication (MFA) B. Sync all the Active Directory user accounts to Azure Active Directory (Azure AD) C. Instruct all users to change their password D. Create a guest user account in Azure Active Directory (Azure AD) for each user

B. Sync all the Active Directory user accounts to Azure Active Directory (Azure AD)

You have an Azure virtual machine named VM1.You plan to encrypt VM1 by using Azure Disk Encryption.Which Azure resource must you create first? A. an Azure Storage account B. an Azure Key Vault C. an Azure Information Protection policy D. an Encryption key

B. an Azure Key Vault

What is the function of a Site-to-Site VPN? A. provides a secure connection between a computer on a public network and the corporate network B. provides a dedicated private connection to Azure that does NOT travel over the internet C. provides a connection from an on-premises VPN device to an Azure VPN gateway

C

The company would like to develop a cloud solution by making use of Azure Government. Azure Government can only be used by certain types of clients to develop cloud solutions. Which of the following are the types of customers that can make use of Azure Government in this situation? Answer by dragging the correct option from the list to the answer area. - A governement contractor from any country - A government entity from any country - A European government contractor - A European government entity - A US government contractor - A US government entity

- A US government contractor - A US government entity

______ is the process of verifying a user's credentials. - Authentication - authorization

- Authentication

You can enable just in time (JIT) VM access by using ___ -Azure BAstion -Azure Firewall -Azure Front Door -Azure Security center - Microsoft Defender

- Microsoft Defender

_________ can calculate cost savings fue to reduced electricity consumption as a result og migrating on premises Microsoft SQL servers to Azure -Azure Migrate: Server Assessment tool -The Azure total cost of ownershio (TCO) calculator -The Database Migration Assistant -The pricing calculator in Azure

-The Azure total cost of ownershio (TCO) calculator The Azure Total Cost of Ownership(TCO) Calculator is used to estimate the cost savings you can achieve by migrating your application workloads to Microsoft

Yes or No? 1. Each Azure subscription can contain multiple account administrators. 2. Each Azure subscription can be managed by using a Microsoft account only. 3. An Azure resource group contains multiple Azure subscriptions

1. No 2. No 3. No

What kind of a model are those (IaaS, SaaS, PaaS) 1. Azure App Service 2. Azure virtual machines 3. Microsoft Dynamics 365

1. PaaS 2.IaaS 3.SaaS

Yes or No? 1.Azure Pay-as-you-Go pricing is an example of CapEx 2. Paying electricity for your datacenter is an example of OpEx 3.Deploying your own datacenter is an example of CapEx

1.No 2.Yes 3.yes

Work area 1. No required capital expenditure 2.Provides control over security 3.Provides a choice to use on-premises or cloud-based resources Cloud models -Hybrid -Private -Public

1.Public 2.Private 3.Hybrid

1. Provides a cloud-based Enterprise Data Warehouse 2. Uses past trainings to provide predictions that have high availability 3. Provides serverless computing functionalities 4. Processes data from millions of sensros Azure Services - Azure ML - Azure Synapse Analytics - Azure ioT Hubs - Azure Functions

1.Synapse analytics 2. ML 3. Functions 4. IoT Hubs

Yes or No 1. Azure powershell modules can be installed on macOS 2. Azure Cloud Shell can be accessed from a web browser on a Linuz Computer 3.Azure portal can only be accessed from a Windows device

1.Yes 2.Yes 3.No

Which Azure service should you use to store certificates? A. Azure Security Center B. an Azure Storage account C. Azure Key Vault D. Azure Information Protection

C. Azure Key Vault

What should you use to evaluate whether your company's Azure environment meets regulatory requirements? A. Azure Service Health B. Azure Knowledge Center C. Azure Security Center D. Azure Advisor

C. Azure Security Center

You have an on-premises application that sends email notifications automatically based on a rule.You plan to migrate the application to Azure.You need to recommend a serverless computing solution for the application.What should you include in the recommendation? A. a web app B. a server image in Azure Marketplace C. a logic app D. an API app

C. a logic app Azure Logic Apps is a cloud service that helps you schedule, automate, and orchestrate tasks, business processes, and workflows when you need to integrate apps, data, systems, and services across enterprises or organizations. Logic Apps simplifies how you design and build scalable solutions for app integration, data integration, system integration, enterprise application integration (EAI), and business-to-business (B2B) communication, whether in the cloud, on premises, or both.

Your company plans to migrate all its data and resources to Azure.The company's migration plan states that only Platform as a Service (PaaS) solutions must be used in Azure.You need to deploy an Azure environment that meets the company's migration plan.What should you create? A. Azure virtual machines, Azure SQL databases, and Azure Storage accounts. B. an Azure App Service and Azure virtual machines that have Microsoft SQL Server installed. C. an Azure App Service and Azure SQL databases. D. Azure storage accounts and web server in Azure virtual machines.

C. an Azure App Service and Azure SQL databases.

Your company plans to deploy several custom applications to Azure. The applications will provide invoicing services to the customers of the company. Each application will have several prerequisite applications and services installed. You need to recommend a cloud deployment solution for all the applications. What should you recommend? A. Software as a Service (SaaS) B. Platform as a Service (PaaS) C. Infrastructure as a Service (laaS)

C.IaaS custom app in first-line tells that it can,t be SaaS. Multiple installations in last line of the question tells that its can't be PaaS. In pAAS , u dont install stuff, only application files and data are to be given in Paas. option left IaaS

When you are implementing a SaaS you are responsible for -configuring high availability -defining scalability rules -installing the SaaS solution -Configuring the SaaS solution

Configuring

You plan to deploy a service to Azure virtual machines.You need to ensure that the service will be available if a datacenter fails.What should you use as part of the virtual machine deployment? A. availability sets B. proximity placement groups C. host groups D. availability zones

D. availability zones

_______ enables Azure resources to be deployes close to users -Elasticity -Geo-distribution -High availability -Scalability

Geo-dist

Arrange the storage account redundancy options from the least redundant to the most redundant. To answer, move all options from the list of options to the answer area and arrange them in the correct order.Select and Place: -Zone redundant storage -geo redundant storage -Locally redundant storage

Local-Zone-Geo

You need to view a list of planned maintenance events that can affect the availability of an Azure subscription.Which blade should you use from the Azure portal? To answer, select the appropriate blade in the answer area.Hot Area:

Menu

_________ is highly secure IoT solution that includes a microcontroller unit MCU and customized Linux operating system - Azure Arc - Azure IoT Central - Azure Hub - Azure Sphere

Microsoft's Azure Sphere hardware and service designed to better secure Internet of Things (IoT) devices.

yes or no? 1. If you have Azure resources deployed to every region, you can implement availability zones in all the regions 2.Only virtual machines that run Windows server can be created in availability zones 3. Availability zones are used to replicate data and applications to multiple regions

NO-NO-NO 1-Not every region has multiple Availability Zone. Some regions may have only one Availability Zone. 2-One can run both Linux and Windows virtual machines created in the availability zone. 3-Availability zones are used to replicate data and applications in the same region.

Your company is planning to migrate all their virtual machines to an Azure pay-as-you-go subscription. The virtual machines are currently hosted on the Hyper-V hosts in a data center.You are required make sure that the intended Azure solution uses the correct expenditure model.Solution: You should recommend the use of the scalable expenditure model.Does the solution meet the goal?

NO. Because we have two expenditure models. One is Cap-Ex, another is Op-Ex. So Scalable Expenditure is not the right answer.

Reserved VM is OpEx? A.Yes B. no

No

We can join android devices to Azure AD? A.Yes B. no

No

You are tasked with deploying Azure virtual machines for your company. You need to make use of the appropriate cloud deployment solution. Solution: You should make use of Software as a Service (SaaS). Does the solution meet the goal?

No

You are tasked with deploying a critical LOB application, which will be installed on a virtual machine, to Azure.You are informed that the application deployment strategy should allow for a guaranteed availability of 99.99 percent. You need to make sure that the strategy requires as little virtual machines and availability zones as possible. Solution: You include one virtual machine and two availability zones in your strategy.Does the solution meet the goal?

No

Your company plans to migrate all its data and resources to Azure.The company's migration plan states that only Platform as a Service (PaaS) solutions must be used in Azure.You need to deploy an Azure environment that meets the company migration plan. Solution: You create an Azure App Service and Azure Storage accounts. Does this meet the goal? A. Yes B. No

No

An Azure administrator plans to run a PowerShell script that creates Azure resources.You need to recommend which computer configuration to use to run the script.Solution: Run the script from a computer that runs Linux and has the Azure CLI tools installed.Does this meet the goal? A. Yes B. No

No, A PowerShell script is a file that contains PowerShell cmdlets and code. A PowerShell script needs to be run in PowerShell.PowerShell can now be installed on Linux. However, the question states that the computer has Azure CLI tools, not PowerShell installed. Therefore, this solution does not meet the goal.

You are required to deploy an Artificial Intelligence (AI) solution in Azure. You want to make sure that you are able to build, test, and deploy predictive analytics for the solution. Solution: You should make use of Azure Cosmos DB. Does the solution meet the goal?

No, Azure Cosmos DB is a fully managed NoSQL database for modern app development.

Your company is planning to migrate all their virtual machines to an Azure pay-as-you-go subscription. The virtual machines are currently hosted on the Hyper-V hosts in a data center.You are required make sure that the intended Azure solution uses the correct expenditure model.Solution: You should recommend the use of the elastic expenditure model.Does the solution meet the goal?

No, Elasticity is not an expenditure model rather is one of the characteristics of could computing.

Yes or no? 1. You can create Group Polices in Azure Active Directory? 2. You can join Windows 10 devices to Azure Active Directory 3. You can join Android deviced ti Azure Active Directory

No, Yes, No

On which layer is DDos protection applied? -Application layer -Network layer -Perimeter layer

Perimeter

Azure distributed denial of service (DDoS) protection is an example of protection that is implemented at the _____ - application layer - compute layer - networking layer - perimeter layer

Perimeter layer

An availability Zone in Azure has physically separate locations - Across two continents - Within a single Azure region - Within multiple Azure regions -Within a single Azure datacenter

Within a single Azure region

We can join windows devices to AD? A.Yes B. no

YEs

Yes or No? -You can use Availability Zones in Azure to protect Azure VM from a datacenter failure -You can use Availability Zones in Azure to protect Azure VM from a regionfailure -You can use Availability Zones in Azure to protect Azure managed disks from a datacenter failure

YEs-No-YES

An Azure administrator plans to run a PowerShell script that creates Azure resources.You need to recommend which computer configuration to use to run the script.Solution: Run the script from a computer that runs Chrome OS and uses Azure Cloud Shell.Does this meet the goal? A. Yes B. No

Yes

You have an Azure environment. You need to create a new Azure virtual machine from a tablet that runs the Android operating system.Solution: You use PowerShell in Azure Cloud Shell.Does this meet the goal? A. Yes B. No

Yes

You have an Azure environment. You need to create a new Azure virtual machine from a tablet that runs the Android operating system.Solution: You use the Azure portal.Does this meet the goal? A. Yes B. No

Yes

You plan to deploy several Azure virtual machines.You need to ensure that the services running on the virtual machines are available if a single data center fails.Solution: You deploy the virtual machines to two or more availability zones.Does this meet the goal? A. Yes B. No

Yes

1. Azure Security Center can montor Azure resources and on premises resources 2. All Azure Security Center featues are free 3. From Azure Security Center you can download Regulatory Complience Report

Yes No Yes

You sign in to the Azure portal and create a resource group named RG1.From Azure documentation, you have the following command that creates a virtual machine named VM1. az vm create --resource-group RG1 --name VM1 --image UbuntuLTS --generate-ssh-keys You need to create VM1 in Subscription1 by using the command. Solution: From the Azure portal, launch Azure Cloud Shell and select PowerShell. Run the command in Cloud Shell.Does this meet the goal? A. Yes B. No

Yes The command can be run in the Azure Cloud Shell. Although this question says you select PowerShell rather than Bash, the Az commands will work inPowerShell.

Yes or no? - From Azure Service Health, an administrator can view the health of all the services in an Azure environment - From Azure Service Health, an administrator can create a rule to be alerted if service fails - From Azure Service Health, an administrator can prevent service failure

Yes yes no

You need to purchase a third-party virtual security appliance that you will deploy to an Azure subscription.What should you use? A. Azure subscriptions B. Microsoft Defender for Cloud C. Azure Marketplace D. Microsoft Store

c

Which cloud computing benefit provides continuous user access to a cloud-based application with minimal downtime? A. agility B. scalability C. elasticity D. high availability

d

Application Insights is a feature of - Azure Advisor - Azure Application Gateway - Azure Arc - Azure monitor

monitor

- Authorization to access Azure resources can be provided only to AD users - Identities stored in Azure Active directory, third party cloud services and on prem AD can be used to access Azure resources -Azure has built in authentication and authorization services that provide secure access to Azure resources

no yes yes

-Azure China is operated by MS -Azure Government is operated by ms -Azure Government is available only to US govnerment agiencies and their parnters

no yes yes

1. Azure Firewall will encrypt all the network traffic sent from Azure to the internet 2. A network security group NSG will encrypt all the network traffic sent from azure to the Internet 3. Azure VM that run Windows Server 2016 can encrypt network traffic sent to the Internet

no, no, no

Azure distributed denial of service DDoS protection is an example of protection that is implemented at the -application layer -compute layer -networking layer -perimeter layer

perimeter

You have an Azure environment that contains 10 web apps. To which URL should you connect to manage all the Azure resources? To answer, select the appropriate options in the answer area. https:// __________ . ________.com -admin -portal - www azure azurewebsites microsoft

portal.azure.com

Azure China -is operated by Microsoft -has feature parity with Azure Global -services can be accessed from china only -is a distinct separate instance of MS azure

s a distinct separate instance of Microsoft Azure

You are required to deploy an Artificial Intelligence (AI) solution in Azure. You want to make sure that you are able to build, test, and deploy predictive analytics for the solution. Solution: You should make use of Azure Machine Learning Studio. Does the solution meet the goal?

yes

Your Azure environment contains multiple Azure virtual machines.You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP.Solution: You modify an Azure firewall.Does this meet the goal? A. Yes B. No

yes

-You can use Azure Policy to apply tags to resources -You can add multiple tags to the same resource -An Azure resource inherits tags from the resource group to which the resource is deployed

yes, yes, no

-Azure Active Directory (Azure AD) can be used to manage access to on-prem applications -Azure Active Directory (Azure AD) provides single sign on -iOS devices can be registred in Azure Active Directory (Azure AD)

yes, yes, yes

-Azure resource can have multiple delete locks -Azure resource inherits locks from its resource groups -if an Azure resource has a read only lock you can add a delete lock to the resource

yes, yes, yes

-The Microsoft Service Trust Portal can be accessed by using a MS cloud services account -Compliance Manager can be used to track your companys regulatory compliance activities related to ms cloud services -My Library feature can be used to save MS service Trust Portal documents and resources in a single location

yes, yes, yes

1. You can configure the Azure AD activity logs to appear in Azure Monitor 2. From Azure Monitor you can monitor resources across multiple Azure subscriptions 2. From Azure Monitor you can create alerts

yes, yes, yes

When you are implementing a SaaS solution, you are responsible for: -configuring high availability -defining scalability rules -installing the Saas Solution -configuring the Saas solution

configuring the SaaS solution. Everything else is managed by the cloud provider.

Autoscaling is an example of -agility -elasticity -geo-dist -predictability

elasticity

An Azure web app that queries an on-premises Microsoft SQL server is an example of ____ cloud -Hybrid -multi-vendor -private -public

hybrid

Your company intends to subscribe to an Azure support plan.The support plan must allow for new support requests to be opened.Which of the following are support plans that will allow this? - Basic - Developer - Standard - Professional Direct - Premium

- Basic - Developer - Standard - Professional Direct

An organization that hosts it infrastructure ________ no longer requires a data center -in a private cloud -in a hybrid cloud -in the public cloud -on a Hyper-V host

- In the public cloud A private cloud is hosted in your datacenter. Public cloud is hosted externally

Data that is stored in the Archive access tier of an Azure storage account - can be accessed at any time by using azcopy.exe. - can only be read by using Azure Backup - Must be restored before the data can be accessed - Must be rehydrated before the data can be accessed

- Must be rehydrated before the data can be accessed

You have several VM in Azure Sub. you create a new subscr. - The VM cannot be moved to the new subscription - The VM can be moved to the new subscription - The VM can be moved to the new subscription only if they are all in the same resource group - The VM can be moved to the new subscription only if they run Windows Server 2019

- The VM can be moved to the new subscription

You plan to deploy 20 VM to an Azure environment. To ensure that a VM named VM1 cannot connect to another virtual machine, VM1 must - be deployed to a separate virtual network - run a different operating system than the other virtual machines - be deployed to a separate resource group - have two network interfaces

- be deployed to a separate virtual network

Azure Policy initiative definition is a - collection of policy definitions - collection of Azure Policy definition assignemnts - group of Azure Blueprints definitions - group of role based access control role assignments

- collection of policy definitions

Azure Site Recovery provides _________ for virtual machines - fault tolerance - disaster recovery - elasticity - high availability

- disaster recovery

When planning to migrate a public webside to Azure, you must plan to - deploy a VPN - pay monthly usage costs - pay to transfer all the webside data to Azure - reduce the number of connections to the website

- pay monthly usage costs

Azure Blob storage is: -data storage for queuing and reliably delivering message between applicaions -file share that can be mapped as network drive -key/attribute store for non relational structured data - storage service optimized for very large objects, such as video files and bitmaps

- storage service optimized for very large objects, such as video files and bitmaps

You have several virtual machines in an Azure subscription You create a new subscription. - the virtual machines cannot be moved to the new subscription - the virtual machines can be moved to the new subscription - the virtual machines can be moved to the new subscription only if they are all in the same resource group - the virtual machines can be moved to the new subscription only if they run Windows Server 2016

- the virtual machines can be moved to the new subscription You can move a VM and its associated resources to a different subscription by using the Azure portal.

When you need to delegate permissions to several Azure VM simultaneously you must deploy Azure VM - to the same Azure region - by using the same Azure Resource Manager template - to the same resource group - to the same availability zone

- to the same resource group

An Availability Zone in Azure has physically separate locations - across two countires - within a single Azure region - within multiple Azure regions -within a single Azure datacenter

- within a single Azure region Availability Zones is a high-availability offering that protects your applications and data from datacenter failures. Availability Zones are unique physical locations within an Azure region

____ enables users to authenticate to multiple applications by using SSO -Application security groups in Azure -Azure Active Directory -Azure key Vault -Azure Security center

-Azure Active Directory

___________ a common platform for deplaying objects to a cloud infrastructure and for implementing consistency across Azure environment -Azure policies provide -Resource groups provide -Azure Resource Manager templates provide -Management groups provide

-Azure Resource Manager templates provide ARM is just a template for deployment , policy/policies are just the rules that you can create and apply -you cannot use a rule to deploy - you use a common platform-ARM

An Azure container instance is an example of an Azure -Compute service -identity service - networking service - Storage service

-Compute service

Azure Site Recovery provides _________ for virtual machines -Fault tolerence -Disaster recovery -Elasticity -High availability

-Disaster recovery

You plan to extend your company's network to Azure.The network contains a VPN appliance that uses an IP address of 131.107.200.1.You need to create an Azure resource that defines the VPN appliance in Azure.Which Azure resource should you create? -NAT gateways _Application gateways -Local network gateways -Virtual network gateways -On-premisis Data gateways -Azure Data Box gateways -Azure Stack Edge / Data Box gateways -Web Application Firewall policies

-Local network gateways

The ___ explains what data MS processes, how MS processes the data and the purpose of processing -MS Online Services Privacy Statement -MS Product Teams -MS Online Service Level Agreement -Online Subscription Agreement for MS Azure

-MS Online Services Privacy Statement

[_] provide organizations with the ability to manage the compliance of Azure resources across multiple subscriptions. -Resource groups -Management groups -Azure policies Azure app service plans

-Management groups

You can view your company's regulatory compliance report from... -Azure advisor -Azure Analyisis services -Azure monitor -Microsoft Defender

-Microsoft Defender

1. Windows 10 2. Ubuntu 3. MacOS Mojave You need to identify which Azure management tools can be used for each computer. What should you identify for each computer. Answer Area: - Azure CLI and the Azure portal - Azure Portal and AzurePowershell -The Azure CLI and Azure PowerShell -The Azure CLI, the Azure portal and Azure Powershell

-The Azure CLI, the Azure portal and Azure Powershell for all of them Azure CLI can be installed everywhere https://docs.microsoft.com/en-us/cli/azure/install-azure-cli?view=azure-cli-latest Azure portal can be accessed everywhere (using a browser) And Azure powershell can be run on every system https://docs.microsoft.com/en-us/powershell/azure/install-az-ps?view=azps-3.1.0

An Azure region ____ -contains one or more data centers that are connected by using a low latency network - is found in each country where Microsoft has office - can be fount in every country in Eu and US only - Contains one or more data centers that are connected using high-latency network

-contains one or more data centers that are connected by using a low latency network

An azure region -contains one or more data centers that are connected by using a low latency network -is found in each country where Microsoft has a ssubsidary office - can be found in every country in EU and US -Contains one or more data centers that are connected by using a high latancy work

-contains one or more data centers that are connected by using a low latency network

1. Provide operating system virtualization 2. Provide portable environment for virtualized applications 3. Used to build deploy and scale web apps 4. Provide a platform from serverless code Services - Azure Functions - Azure App Service - Azure VM - Azure Container Instance

1- VM 2-Container instance 3. App service 4.Function

1. Describes which personal data is collected, how the data is used and what the data is for 2.A legal agreement that details the obligations between MS and a customer regarding the processing and security of customer data and personal data 3.Defines the data processing and security terms for inline services, including the disclosure of processed data and the transfer, retention and deletion of data -Data protection Addendum -MS Privacy statement -Online Service teams

1-MS Privacy statement 2-Online Service teams 3-Data protection Addendum

1. Provides a digital online assistant that provides speech support 2.Uses past trainings to provide predictions that have high probability 3.Provides serverless computing functionalities 4.Processes data from millions of sensors Answers: -Azure Machine Learning -Azure IoT Hub Azure Bot Services -Azure Functions

1. Azure Bot Services 2.Azure ML 3. functions 4.IoT Hub

1. A managed relational cloud database service 2. A cloud based service that leverages massively parallal processing to quickly run complex queries across petabytes of data in a relational database 3.Can run massively parallel data transformation and processing programs across petabytes of data 4.An open source framework for the disributed processing ans analysis of big data clusters Answer options - Azure HDInsights - Azure Data Lake Analytics - Azure SQL Synapse anaytics - Azure Database

1. Azure Database 2. SQL synapse 3. Data lake analytics 4.HDInsights

Answer area 1. A cloud service that remains available after a failure occurs 2.A cloud service that can be recovered after a failure occurs 3.A cloud service that performs quickly when demand increases 4.A cloud service that can be accessed quickly from the internet Answer options - Disaster recovery - Fault tolerance - Low latency -Dynamic scalability

1. Fault tolerance 2. Disaster recovery 3.Dynamic scalability 4.Low latency

1. Executes code 2. Is always stateful 3. Runs only in the cloud Statements: -Azure functions - Azure Logic Apps

1. Functions 2. Functions 3.Logic Apps

1. A managed service that provides bidirectional communication between IoT devices and Azure 2. A fully managed SaaS to connect, monitor and manage IoT devices at scale 3. A software and hardware solution that provides communication and security features for IoT devices Services -Azure Sphere -IoT Central -IoT Hub

1. IoT Hub 2.IoT Central 3.Azure sphere

You need to identify which blades in the Azure portal must be used to perform the following tasks:✑ View security recommendations.✑ Monitor the health of Azure services.✑ Browse available virtual machine images.Which blade should you identify for each task? To answer, select the appropriate options in the answer area. 1.Monitor health of Azure services -Monitor -Subsrciption -Marketplace -Advisor 2.Browse available virtual machine images -Monitor -Subsrciption -Marketplace -Advisor 3. View security recommendations -Monitor -Subsrciption -Marketplace -Advisor

1. Monitor 2. Marketplace 3. Advisor

Yes or No? -Azure subscription can have multiple account administrators -Azure subscription can be manages using Microsoft account only - An Azure resource group can contain multiple Azure subscriptions

1. No 2. No - You need an Azure Active Directory account to manage a subscription, not a Microsoft account. An account is created in the Azure Active Directory when you create the subscription. Further accounts can be created in the Azure Active Directory to manage the subscription 3. No. Resource groups are logical containers for Azure resources. However, resource groups do not contain subscriptions. Subscriptions contain resource groups.

Yes or No? 1. Availability zones can be implemented in all Azure regions 2. Only VM that run in Windows Server can be created in availability zones 3. Availability zones are used to replicate data an applications to multiple regions

1. No 2. No 3. No

Yes or no? 1. North america is represented by a single Azure resource 2. Every Azure region has multiple datacenters 3. Data transfers between Azure services located in different azure regions are always free

1. No 2. No 3. No

Yes or No? 1. All Azure resources deployed to a resource group must use the same Azure region 2. If you assign a tag to a resource group, all the Azure resources in that resource group are aasigned to the same tag 3. If you assign permission for a user to manage a resource group the user can manage al the Azure resources in that resource group

1. No 2. No 3.Yes

Yes or No? 1.Azure Files is an example of IaaS 2.A DNS server that runs on an Azure virtual machine is an example of PaaS 3.Microsoft Intune is an example of SaaS

1. No 2. No 3.Yes

Yes or No? 1. You must have physical servers to use cloud computing 2. You must have internet connectivity to use cloud computing 3.the costs to increase cloud computing capacity are less then the costs to increase the computing capacity of an on-premises datacenter

1. No 2. Yes 3. Yes

Yes or No? 1.Azure virtual networks deployed to the same Azure region are connected by default 2.Each Azure VN in a single resource group must have a unique name 3.The Azure VN address space must be unique within a subscribtion

1. No 2. Yes 3. Yes

For each of the following statements, select Yes if the statement is true. Otherwise, select No.NOTE: Each correct selection is worth one point. 1. Paas solution that hosts web apps in Azure provides full control of the operating systems that host applications 2. Paas solution that hosts we apps in Azure provides the ability to scale the platform automatically 3. Paas solution that hosts we apps in Azure provides professinal development services to contunuously add features to custom applications

1. No, PasS wont give you full control like IaaS 2. Yes 3.Yes, it is referring to azure devops which u can use with PaaS

1. 2. Idendity & access 3. 4. Network 5. Compute 6. 7. Data Fill inn: -Perimeter -Application -Physical security

1. Physical Security 3. Perimeter 6. Application

1. Restrict which virtual machine types can be created in a subscription 2. Identify Azure resources that are associated with specific cost centers. 3. Deploy a complete Azure application environment including resources configuration and role assignments Features - Azure Blueprints - Azure Policy - Azure resource locks - Azure tags

1. Polocy 2.tags 3. Blueprint

1. A fully managed data warehouse that has integral security at every level of scale at no extra cost 2. A globally distributed databse that supports NoSQL 3. Managed Apache Hadoop clusters in the cloud that enable you to process massive amounts of data Services - Azure Cosmos DB - Azure HDInsights - Azure Synapse Analytics

1. Synapse 2. Cosmos 3. HDInsihts

Yes or No? 1.Azure provides flexibility beetween capital expenditure (CapEx) and operational expenditure (CapEx) 2.If you create two Azure vitrual machines that use the B2S size. each virtual machines that use the B2S size, each virtual machine will always generate the same monthly cost 3. When an Azure Virtual machine is stopped, you continute to pay storage costs associated to the virtual machines

1. Yes 2. No 3. Yes

Yes or No 1. Cloud computing provides elastic scalability 2.Customers can minimize capital expenditure by using public cloud 3.Cloud computing leverages virtualization to provide services to multiple customers simlutaneously

1. Yes 2. Yes 3.Yes

Yes or No? 1. A single Microsoft account can be used to manage multiple Azure subscriptions. 2. Two Azure subscriptions can be merged into a single subscription. 3. A company can use resources from multiple subscriptions

1. Yes 2.No 3.Yes

1. When using an Azure ExpressToute connection, inbound data traffic from an on-premises network to Azure is always free 2. Outbound data traffic from Azure to an on-premises network is always free 3. Data traffic from Azure services within the same region is always free

1. Yes. You already use and pay ExpressRoute. They just ask if inbound data is free of charge, which it is. 2. No. Outbound data is not free of charge. 3. Yes. Within same region is free.

Yes or No? 1. A Windows Virtual Desktop session host can run Windows 10 only 2. A Windows Virtual Desktop host pool that includes 20 session hosts supports a maximum of 20 simultaneous user connections 3. Windows Virtual Desktop supports desktop and app virtualization

1. no 2. no 3.yes

1. With a consumption-based plan you pay fixed rate for all data sent to or from virtual machines hosted in the cloud. 2. With consumption based plan you reduce overall cost by paying only for extra capacity when it is required. 3. Serverless computing is an example of consumption-based plan

1. no 2. yes 3. yes

1. The ability to use the same credentials to access multiple resources and applications from different providers 2. The process of identifying the access level of a user or service 3. Requires several elements to identify a user or a service - authorization -MFA -signle sign on SSO

1. sso 2.authorization 3.MFA

1. From the Azure portal, you can distinguish between services that are generally available and services that are in public preview 2.After an Azure service becomes generally available, the service is no longer updated with new features 3. When you create Azure resources for a service in public preview, you must recreate the resources once the service becomes generally available

1. yes 2. No 3. No

1. An integrated solution for the deployment of code 2. A tool that provide guidance and recommendations to improve an Azure environment 3. A simplified tool to build intelligent AI applications 4. Monitors web applications Answer options -Azure Advisor -Azure Cognitive Services -Azure Application Insights -Azure DevOps

1.DevOps 2. Advisor 3.Cognitive Services 4. Application Insights

What kind of a model are those (IaaS, SaaS, PaaS) 1. a cloud based file server 2. a cloud based accounting system 3. a cloud based service for custom apps

1.IaaS 2.SaaS 3.PaaS

Yes or No? 1. A company can extend an internal network by adding its own physical servers to the public cloud 2. A private cloud must be disconnected from the internet 3.Part of hybrid cloud is the public cloud

1.No 2.No 2.Yes

Yes or No? 1.You can create a resource group inside another resource group 2. An Azure virtual machine can be in muiltiple resource group 3. A resource group can contain resources from multiple Azure regions

1.No 2.No 3.Yes

Yes or No? 1.A company can extend a private cloud by adding its own physical servers to the public cloud 2.To build a hybrid cloud, you must deploy resources to the public cloud 3.A private cloud must be disconnected from the internet

1.No 2.Yes 3.No

1.Microsoft SQL Server 2019 installed on an Azure Virtual machine is an example of Paas 2. Azure SQL DB is an example of Paas 3.Azure Cosmos DB is an example of Saas

1.No 2.Yes 3.No its a PaaS

1.A PaaS solution provides full control of operating systems that host applications 2.A PaaS solution provides additional memory to apps by changing pricing tiers 3.A PaaS solution can automatically scale the number of instances

1.No 2.Yes 3.Yes

Yes or No? 1.Paas solution that hosts web apps in Azure provides full control of the operating systems that host applications 2. Paas solution that hosts web apps in Azure can be provided with additional memory by changing the pricing tier 3.Paas solution that hosts web apps in Azure

1.No 2.Yes 3.Yes

Yes or No? 1.With SaaS, you must apply software updates 2.With Iaas you must install the software you want to use 3.Azure Backup is an example of PaaS

1.No 2.Yes 3.Yes

Yes or No? 1.Building a data center infrastructure is an example of OpEx 2.Monthly salaries for technical personell are an example of OpEx 3.Leasing software is an example of OpEx

1.No, Building a data center infrastructure is capital expenditure, not operation expenditure. 2.Yes 3.Yes

Drag Drop Answers 1.Resources can be provisioned dynamically to meet changing demands 2.Applications and data can be deployes to multiple regions 3. Application ca be developed, tested and launched rapidly Benefits -Agility -Geo-distribution -Scalability

1.Scalability 2.Geo-dist 3.Agility

1. Increase the compute capacity of apps in the cloud 2.Provide a continuous user experience with no aparent downtime 3. Ensure that users always have the best experience by deploying apps to all the regions where there are users Benefits -Diasaster recovery - Geo- distribution - High availabilty -Scalabilty

1.Scalability 2.High-availability 3.Geo

1.Azure Active Directory (Azure AD) requires the implementation of domain controllers on Azure virtual machines 2.Azure Active Directory (Azure AD) provides authentication services for resources hosted in Azure an MS 365 3.Each user account in Azure AD can be assigned only one license

1.no 2.yes 3.no

Yes or No? 1. To achieve a hybbrid cloud model, a company must always migrate from a private cloud model 2.A company can extend the capacity of its internal network by using the public cloud 3.In a public cloud model, only guest users at your company can access the resources in the cloud

1.no 2.yes 3.no

Yes or no 1. To implement a hybrid cloud model, a company must have an internal network 2.A company can extend the coputing resources of its internal network by using a hybrid cloud 3.In a public cloud model, only guest users at your company can access the resources in cloud

1.yes 2.yes 3.no

What does a customer provide in a software as a service (SaaS) model? A. application data B. data storage C. compute resources D. application software

A

Which Azure service should you use to collect events from multiple resources into a centralized repository? A. Azure Event Hubs B. Azure Analysis Services C. Azure Monitor D. Azure Stream Analytics

A

Which cloud computing model includes on-premises and cloud-based resources? A. hybrid B. public C. private

A

You plan to deploy several Azure virtual machines.You need to ensure that the services running on the virtual machines are available if a single data center fails.Solution: You deploy the virtual machines to two or more regions.Does this meet the goal? A. Yes B. No

A

An Azure administrator plans to run a PowerShell script that creates Azure resources.You need to recommend which computer configuration to use to run the script. Solution: Run the script from a computer that runs Windows 10 and has the Azure PowerShell module installed.Does this meet the goal?

A 🗳️A PowerShell script is a file that contains PowerShell cmdlets and code. A PowerShell script needs to be run in PowerShell.

Your Azure environment contains multiple Azure virtual machines.You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP.Solution: You modify a network security group (NSG).Does this meet the goal? A. Yes B. No

A 🗳️A network security group works like a firewall. You can attach a network security group to a virtual network and/or individual subnets within the virtual network.

Your company plans to deploy several web servers and several database servers to Azure.You need to recommend an Azure solution to limit the types of connections from the web servers to the database servers.What should you include in the recommendation? A. network security groups (NSGs) B. Azure Service Bus C. a local network gateway D. a route filter

A 🗳️A network security group works like a firewall. You can attach a network security group to a virtual network and/or individual subnets within the virtual network.

What can you use to identify underutilized or unused Azure virtual machines? A. Azure Advisor B. Azure Cost Management + Billing C. Azure reservations D. Azure Policy

A 🗳️Azure Advisor helps you optimize and reduce your overall Azure spend by identifying idle and underutilized resources. You can get cost recommendations from the Cost tab on the Advisor dashboard.

Your company plans to automate the deployment of servers to Azure.Your manager is concerned that you may expose administrative credentials during the deployment.You need to recommend an Azure solution that encrypts the administrative credentials during the deployment.What should you include in the recommendation? A. Azure Key Vault B. Azure Information Protection C. Azure Security Center D. Azure Multi-Factor Authentication (MFA)

A 🗳️Azure Key Vault is a secure store for storage various types of sensitive information. In this question, we would store the administrative credentials in the Key Vault.

You have an Azure subscription named Subscription1. You sign in to the Azure portal and create a resource group named RG1.From Azure documentation, you have the following command that creates a virtual machine named VM1. az vm create --resource-group RG1 --name VM1 --image UbuntuLTS --generate-ssh-keys You need to create VM1 in Subscription1 by using the command.Solution: From a computer that runs Windows 10, install Azure CLI. From a command prompt, sign in to Azure and then run the command.Does this meet the goal? A. Yes B. No

A 🗳️The command can be run from PowerShell or the command prompt if you have the Azure CLI installed.

You have an Azure subscription named Subscription1. You sign in to the Azure portal and create a resource group named RG1.From Azure documentation, you have the following command that creates a virtual machine named VM1. az vm create --resource-group RG1 --name VM1 --image UbuntuLTS --generate-ssh-keysYou need to create VM1 in Subscription1 by using the command.Solution: From the Azure portal, launch Azure Cloud Shell and select Bash. Run the command in Cloud Shell.Does this meet the goal? A. Yes B. No

A 🗳️The command can be run in the Azure Cloud Shell.

Which service provides network traffic filtering across multiple Azure subscriptions and virtual networks? A. Azure Firewall B. an application security group C. Azure DDoS protection D. a network security group (NSG)

A 🗳️You can restrict traffic to multiple virtual networks in multiple subscriptions with a single Azure firewall.

You plan to store 20 TB of data in Azure. The data will be accessed infrequently and visualized by using Microsoft Power BI.You need to recommend a storage solution for the data.Which two solutions should you recommend? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point. A. Azure Data Lake B. Azure Cosmos DB C. Azure Azure Synapse Analytics D. Azure SQL Database E. Azure Database for PostgreSQL

A, C

What are two benefits of cloud computing? Each correct answer presents a complete solution. A. enables the rapid provisioning of resources B. has increased administrative complexity C. has the same configuration options as on-premises D. shifts capital expenditures (CAPEX) to operating expenditures (OPEX)

A, D

You plan to deploy several Azure virtual machines.You need to ensure that the services running on the virtual machines remain available if a single data center fails.What are two possible solutions? Each correct answer presents a complete solution. A. Deploy the virtual machines to two or more availability zones. B. Deploy the virtual machines to two or more resource groups. C. Deploy the virtual machines to a scale set. D. Deploy the virtual machines to two or more regions.

A, D

A support engineer plans to perform several Azure management tasks by using the Azure CLI.You install the CLI on a computer.You need to tell the support engineer which tools to use to run the CLI.Which two tools should you instruct the support engineer to use? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point. A. Command Prompt B. Azure Resource Explorer C. Windows PowerShell D. Windows Defender Firewall E. Network and Sharing Center

A. AC 🗳️For Windows the Azure CLI is installed via an MSI, which gives you access to the CLI through the Windows Command Prompt (CMD) or PowerShell.References:

Which Azure service provides a set of version control tools to manage code? A. Azure Repos B. Azure DevTest Labs C. Azure Storage D. Azure Cosmos DB

A. Azure Repos

You need to collect and automatically analyze security events from Azure Active Directory (Azure AD).What should you use? A. Azure Sentinel B. Azure Synapse Analytics C. Azure AD Connect D. Azure Key Vault

A. Azure Sentinel Microsoft Azure Sentinel is a scalable, cloud-native, security information event management (SIEM) and security orchestration automated response (SOAR) solution.

You plan to create an Azure virtual machine.You need to identify which storage service must be used to store the unmanaged data disks of the virtual machine.What should you identify? A. Conteiner B. Tables C. File shares D. Queues

A. Container Azure containers are the backbone of the virtual disks platform for Azure IaaS

Which of the following should be done FIRST when establishing a new data protection program that must comply with applicable data privacy regulations? A. Create an inventory of systems where personal data is stored. B. Encrypt all personal data stored on systems and networks. C. Evaluate privacy technologies required for data protection. D. Update disciplinary processes to address privacy violations.

A. Create an inventory of systems where personal data is stored.

You plan to migrate all the servers to Azure.You need to recommend a solution to ensure that some of the servers are available if a single Azure data center goes offline for an extended period.What should you include in the recommendation? A. fault tolerance B. elasticity C. scalability D. low latency

A. Fault tolerance it is the ability of a system to continue to function in the event of a failure of some of its components.

One of the benefits of Azure SQL Data Warehouse is that high availability is built into the platform.Instructions: Review the underlined text. If it makes the statement correct, select `No change is needed`. If the statement is incorrect, select the answer choice that makes the statement correct. A. No change is needed B. automatic scaling C. data compression D. versioning

A. No change is needed

Your company has an on-premises network that contains multiple servers.The company plans to reduce the following administrative responsibilities :✑ Backing up application data ✑ Replacing failed server hardware ✑ Managing physical server security ✑ Updating server operating systems ✑ Managing permissions to shared documentsThe company plans to migrate servers to Azure virtual machines. You need to identify which administrative responsibilities will be eliminated after the planned migration. Which two responsibilities should you identify? Each correct answer presents a complete solution. A. Replacing failed server hardware B. Backing up application data C. Managing physical server security D. Updating server operating systems E. Managing permissions to shared documents

A. Replacing failed server hardware C. Managing physical server security

Your developers have created 10 web applications that must be host on Azure. You need to determine which Azure web tier plan to host the web apps. The web tier plan must meet the following requirements: ✑ The web apps will use custom domains. ✑ The web apps each require 10 GB of storage. ✑ The web apps must each run in dedicated compute instances .✑ Load balancing between instances must be included. ✑ Costs must be minimized. Which web tier plan should you use? A. Standard B. Basic C. Free D. Shared

A. Standard

Your developers have created a portal web app for users in the Miami branch office. The web app will be publicly accessible and used by the Miami users to retrieve customer and product information. The web app is currently running in an on-premises test environment. You plan to host the web app on Azure. You need to determine which Azure web tier plan to host the web app. The web tier plan must meet the following requirements: ✑ The website will use the miami.weyland.com URL. ✑ The website will be deployed to two instances. ✑ SSL support must be included. ✑ The website requires 12 GB of storage. ✑ Costs must be minimized. Which web tier plan should you use? A. Standard B. Basic C. Free D. Shared

A. Standard

You have an Azure subscription and 100 Windows 10 devices.You need to ensure that only users whose devices have the latest security patches installed can access Azure Active Directory (Azure AD)-integrated applications.What should you implement? A. a conditional access policy B. Azure Bastion C. Azure Firewall D. Azure Policy

A. a conditional access policy

You plan to deploy several Azure virtual machines.You need to control the ports that devices on the Internet can use to access the virtual machines.What should you use? A. a network security group (NSG) B. an Azure Active Directory (Azure AD) role C. an Azure Active Directory group D. an Azure key vault

A. a network security group (NSG)

Your company plans to start using Azure and will migrate all its network resources to Azure.You need to start the planning process by exploring Azure.What should you create first? A. a subscription B. a resource group C. a virtual network D. a management group

A. a subscription

You have an Azure environment that contains multiple Azure virtual machines.You plan to implement a solution that enables the client computers on your on-premises network to communicate to the Azure virtual machines.You need to recommend which Azure resources must be created for the planned solution.Which two Azure resources should you include in the recommendation? Each correct answer presents part of the solution. A. a virtual network gateway B. a load balancer C. an application gateway D. a virtual network E. a gateway subnet

A. a virtual network gateway E. a gateway subnet To implement a solution that enables the client computers on your on-premises network to communicate to the Azure virtual machines, you need to configure aVPN (Virtual Private Network) to connect the on-premises network to the Azure virtual network.The Azure VPN device is known as a Virtual Network Gateway. The virtual network gateway needs to be located in a dedicated subnet in the Azure virtual network. This dedicated subnet is known as a gateway subnet and must be named 'GatewaySubnet'.

The company has several departments. All the Azure resources used by each department will be managed by a department administrator. What are two possible techniques to segment Azure for the departments? Each correct answer presents a complete solution. A. multiple subscriptions B. multiple Azure Active Directory (Azure AD) directories C. multiple regions D. multiple resource groups

A. multiple subscriptions D. multiple resource groups An Azure subscription is a container for Azure Resources, it is also a boundary for resources and billing. To enable each department administrator to manage the Azure resources you would need seperated subscription per department. You can then assign each department administrator as an administrator for the subscription to enable them to manage all resources in that subscription.Reference:

You have 1,000 virtual machines hosted on the Hyper-V hosts in a data center.You plan to migrate all the virtual machines to an Azure pay-as-you-go subscription.You need to identify which expenditure model to use for the planned Azure solution.Which expenditure model should you identify? A. operational B. elastic C. capital D. scalable

A. operational CapEx is what you pay upfront, on prem, for servers, racks, cooling, security, the Datacenter itself. OpEx is what you pay to keep your infrastructure operational, like IT staff. In this case, when you move to the Cloud, what you identify in this case is the OpEx or Operational model.

To which cloud models can you deploy physical servers? A. private cloud and hybrid cloud only B. private cloud only C. private cloud, hybrid cloud and public cloud D. hybrid cloud only

A. private cloud and hybrid cloud only

Your company plans to deploy several million sensors that will upload data to Azure.You need to identify which Azure resources must be created to support the planned solution.Which two Azure resources should you identify? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point. A. Azure Data Lake B. Azure Queue storage C. Azure File Storage D. Azure IoT Hub E. Azure Notification Hubs

AD

Which node in the Azure portal should you use to assign a user the Reader role for a resource group? To answer, select the node in the answer area. - Overview - Activity log - Access Control - Tags -Resource visualiser -Events

Access control

You plan to use Azure to host two apps named App1 and App2. The apps must meet the following requirements: ✑ You must be able to modify the code of App1. ✑ Administrative effort to manage the operating system of App1 must be minimized. ✑ App2 must run interactively with the operating system of the server. Which type of cloud service should you use for each app?

App1: PaaS App: IaaS

To what should an application connect to retrieve security tokens? A. an Azure Storage account B. Azure Active Directory (Azure AD) C. a certificate store D. an Azure key vault

Azure Active Directory (Azure AD)

From ___ you can view which user turned off a specific virtual machine during the last 14 days. Azure Access Control IAM Azure event Hubs Azure Activity Log Azure Service Health

Azure Activity Log

You plan to migrate a web application to Azure. The web application is accessed by external users. You need to recommend a cloud deployment solution to minimize the amount of administrative effort used to manage the web application. What should you include in the recommendation? A. Software as a Service (SaaS) B. Platform as a Service (PaaS) C. Infrastructure as a Service (IaaS) D. Database as a Service (DaaS)

Azure App Service is a platform-as-a-service (PaaS) offering that lets you create web and mobile apps for any platform or device and connect to data anywhere, in the cloud or on-premises. App Service includes the web and mobile capabilities that were previously delivered separately as Azure Websites and Azure Mobile Services.

You plan to implement an Azure database solution.You need to implement a database solution that meets the following requirements: ✑ Can add data concurrently from multiple regions ✑ Can store JSON documentsWhich database service should you deploy? -Azure Cosmos DB -Azure Database for MySQL Servers -Azure Database for MariaDB serves -SQL Data Warehouses -Azure cache for Redis -Data Facory -Virtual clusters -Elastic Job agents - Sql databases -Azure Database for PostgreSQL servers -SQL servers -Azure Database Migration Services -SQL Server stretch databases -SQL elastic pools -Managed databases -Sql manages instances

Azure Cosmos DB Azure Cosmos DB is Microsoft's globally distributed, multi-model database service. With a click of a button, Cosmos DB enables you to elastically and independently scale throughput and storage across any number of Azure regions worldwide.Azure Cosmos DB is a great way to store unstructured and JSON data. Combined with Azure Functions, Cosmos DB makes storing data quick and easy with much less code than required for storing data in a relational database.

You have an Azure environment that contains 10 virtual networks and 100 virtual machines.You need to limit the amount of inbound traffic to all the Azure virtual networks.What should you create? A. one application security group (ASG) B. 10 virtual network gateways C. 10 Azure ExpressRoute circuits D. one Azure firewall

Azure Firewall NSG just block or open a port, Azure Firewall can "limit the amount of traffic", because it's a stateful firewall. So the answer is Azure Firewall

You need to purchase a third-party virtual security appliance that you will deploy to an Azure subscription.What should you use? A. Azure subscriptions B. Azure Security Center C. Azure Marketplace D. Microsoft Store

Azure Marketplace

You have a resource group named RG1.You need to prevent the creation of virtual machines in RG1. The solution must ensure that other objects can be created in RG1.What should you use? A. a lock B. an Azure role C. a tag D. an Azure policy

Azure Policy enforces compliance to new and already existing resources.

What is the most severe failure from which an Azure Availability Zone can be used to protect access to Azure service? A. a physical server failure B. an Azure region failure C. a storage failure D. an Azure data center failure

Azure data center

Which cloud deployment solution is used for Azure virtual machines and Azure SQL databases? To answer, select the appropriate options in the answer area. Azure virtual machines: -IaaS -PaaS -SaaS Azure SQL Databases -IaaS -PaaS -SaaS

Azure virtual machines: -IaaS Azure SQL Databases -PaaS

Which service provides serverless computing in Azure? A. Azure Virtual Machines B. Azure Functions C. Azure storage account D. Azure dedicated hosts

B

Your company has an Azure subscription that contains resources in several regions.You need to ensure that administrators can only create resources in those regions.What should you use? A. a read-only lock B. an Azure policy C. a management group D. a reservation

B

You have a virtual machine named VM1 that runs Windows Server 2016. VM1 is in the East US Azure region.Which Azure service should you use from the Azure portal to view service failure notifications that can affect the availability of VM1? A. Azure Service Fabric B. Azure Monitor C. Azure virtual machines D. Azure Advisor

B Azure Monitor

Your Azure environment contains multiple Azure virtual machines.You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP.Solution: You modify an Azure Traffic Manager profile.Does this meet the goal? A. Yes B. No

B 🗳️Azure Traffic Manager is a DNS-based load balancing solution. It is not used to ensure that a virtual machine named VM1 is accessible from the Internet over

Your Azure environment contains multiple Azure virtual machines.You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP.Solution: You modify a DDoS protection plan.Does this meet the goal? A. Yes B. No

B 🗳️DDoS is a form of attack on a network resource. A DDoS protection plan is used to protect against DDoS attacks; it does not provide connectivity to a virtual machine.

A team of developers at your company plans to deploy, and then remove, 50 virtual machines each week. All the virtual machines are configured by using AzureResource Manager templates.You need to recommend which Azure service will minimize the administrative effort required to deploy and remove the virtual machines.What should you recommend? A. Azure Reserved Virtual Machine (VM) Instances B. Azure DevTest Labs C. Azure virtual machine scale sets D. Azure Virtual Desktop

B 🗳️DevTest Labs creates labs consisting of pre-configured bases or Azure Resource Manager templates.By using DevTest Labs, you can test the latest versions of your applications by doing the following tasks:✑ Quickly provision Windows and Linux environments by using reusable templates and artifacts.✑ Easily integrate your deployment pipeline with DevTest Labs to provision on-demand environments.✑ Scale up your load testing by provisioning multiple test agents and create pre-provisioned environments for training and demos.

You have an Azure environment. You need to create a new Azure virtual machine from a tablet that runs the Android operating system.Solution: You use the PowerApps portal.Does this meet the goal? A. Yes B. No

B 🗳️PowerApps lets you quickly build business applications with little or no code. It is not used to create Azure virtual machines. Therefore, this solution does not meet the goal.

An Azure administrator plans to run a PowerShell script that creates Azure resources.You need to recommend which computer configuration to use to run the script.Which three computers can run the script? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point. A. a computer that runs macOS and has PowerShell Core 6.0 installed. B. a computer that runs Windows 10 and has the Azure PowerShell module installed. C. a computer that runs Linux and has the Azure PowerShell module installed. D. a computer that runs Linux and has the Azure CLI tools installed. E. a computer that runs Chrome OS and uses Azure Cloud Shell.

B, C, E A: wrong, you need Azure Powershell Module, Powershell only isn't enoght B: correct, you have Powershell and the module to create Azure resources C: correct, you have Powershell and the module to create Azure resources D: wrong, with Azure CLI you don't execute Powershell script E: correct, from a browser you can connect to Azure Portal and execute Azure Powershell comdlet

You plan to provision Infrastructure as a Service (IaaS) resources in Azure. Which resource is an example of IaaS? A. an Azure web app B. an Azure virtual machine C. an Azure logic app D. an Azure SQL database

B.

Your company plans to deploy an Artificial Intelligence (AI) solution in Azure.What should the company use to build, test, and deploy predictive analytics solutions? A. Azure Logic Apps B. Azure Machine Learning Designer C. Azure Batch D. Azure Cosmos DB

B. Azure Machine Learning Designer

You need to be notified when Microsoft plans to perform maintenance that can affect the resources deployed to an Azure subscription.What should you use? A. Azure Monitor B. Azure Service Health C. Azure Advisor D. Microsoft Trust Center

B. Azure Service Health provides a personalized view of the health of the Azure services and regions you're using. This is the best place to look for service impacting communications about outages, planned maintenance activities, and other health advisories because the authenticated Service Health experience knows which services and resources you currently use.

You manage a local Active Directory Domain Services environment. Your company purchases an Enterprise E1 license for all users.You need to implement self-service password reset. You want to achieve this goal while minimizing costs. A. Upgrade your subscription to Azure AD Premium P2. B. Deploy Azure AD Connect. C. Deploy Azure Information Protection. D. Upgrade your subscription to Azure AD Premium P1

B. Deploy Azure AD Connect.

You have an accounting application named App1 that uses a legacy database. You plan to move App1 to the cloud. Which service model should you use? A. platform as a service (PaaS) B. infrastructure as a service (IaaS) C. software as a service (SaaS)

B. IaaS

Resource groups provide organizations with the ability to manage the compliance of Azure resources across multiple subscriptions.Instructions: Review the underlined text. If it makes the statement correct, select `No change is needed`. If the statement is incorrect, select the answer choice that makes the statement correct. A. No change is needed B. Management groups C. Azure policies D. Azure App Service plans

B. Management groups

Your Azure environment contains multiple Azure virtual machines.You need to ensure that a virtual machine named VM1 is accessible from the Internet over HTTP.What are two possible solutions? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point. A. Modify an Azure Traffic Manager profile B. Modify a network security group (NSG) C. Modify a DDoS protection plan D. Modify an Azure firewall

B. Modify a network security group (NSG) Most Voted D. Modify an Azure firewall

Your company's developers intend to deploy a large number of custom virtual machines on a weekly basis. They will also be removing these virtual machines during the same week it was deployed. Sixty percent of the virtual machines have Windows Server 2016 installed, while the other forty percent has Ubuntu Linux installed. You are required to make sure that the administrative effort, needed for this process, is reduced by employing a suitable Azure service. Solution: You recommend the use of Azure Reserved Virtual Machines (VM) Instances. Does the solution meet the goal?

B. No, Azure DevTest Labs enable you to quickly create environments using reusable templates and artifacts.

Your company has datacenters in Los Angeles and New York. The company has a Microsoft Azure subscription. You are configuring the two datacenters as geo-clustered sites for site resiliency. You need to recommend an Azure storage redundancy option.You have the following data storage requirements: ✑ Data must be stored on multiple nodes. ✑ Data must be stored on nodes in separate geographic locations. ✑ Data can be read from the secondary location as well as from the primary location. Which of the following Azure stored redundancy options should you recommend? A. Geo-redundant storage B. Read-only geo-redundant storage C. Zone-redundant storage D. Locally redundant storage

B. Read-only geo-redundant storage

Which term represents the ability to increase the computing capacity of a virtual machine by adding memory or CPUs? A. agility B. vertical scaling C. horizontal scaling D. elasticity

B. Vertical scaling Vertical scaling, also known as scale up and scale down, means increasing or decreasing virtual machine (VM) sizes in response to a workload.

Your company plans to move several servers to Azure.The company's compliance policy states that a server named FinServer must be on a separate network segment.You are evaluating which Azure services can be used to meet the compliance policy requirements.Which Azure solution should you recommend? A. a resource group for FinServer and another resource group for all the other servers B. a virtual network for FinServer and another virtual network for all the other servers C. a VPN for FinServer and a virtual network gateway for each other server D. one resource group for all the servers and a resource lock for FinServer

B. a virtual network for FinServer and another virtual network for all the other servers

Your company has an Azure subscription that contains resources in several regions.You need to create the Azure resource that must be used to meet the policy requirement.What should you create? A. a read-only lock B. an Azure policy C. a management group D. a reservation

B. an Azure policy

What can Azure Information Protection encrypt? A. network traffic B. documents and email messages C. an Azure Storage account D. an Azure SQL database

B. documents and email messages

You have an Azure web app.You need to manage the settings of the web app from an iPhone.What are two Azure management tools that you can use? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point. A. Azure CLI B. the Azure portal C. Azure Cloud Shell D. Windows PowerShell E. Azure Storage Explorer

B. the Azure portal C. Azure Cloud Shell The Azure portal is the web-based portal for managing Azure. Being web-based, you can use the Azure portal on an iPhone.Azure Cloud Shell is a web-based command line for managing Azure. You access the Azure Cloud Shell from the Azure portal. Being web-based, you can use theAzure Cloud Shell on an iPhone.

You plan to deploy several Azure virtual machines.You need to ensure that the services running on the virtual machines are available if a single data center fails.Solution: You deploy the virtual machines to a scale set.Does this meet the goal? A. Yes B. No

B.No, Scale set does not garanti availability if a DataCenter fails.

Your company's Azure subscription includes a Basic support plan. They would like to request an assessment of an Azure environment's design from Microsoft. This is, however, not supported by the existing plan. You want to make sure that the company subscribes to a support plan that allows this functionality, while keeping expenses to a minimum. Solution: You recommend that the company subscribes to the Professional Direct support plan. Does the solution meet the goal? A.yes B.no

B.no

Your company has virtual machines (VMs) hosted in Microsoft Azure. The VMs are located in a single Azure virtual network named VNet1.The company has users that work remotely. The remote workers require access to the VMs on VNet1. You need to provide access for the remote workers. What should you do? A. Configure a Site-to-Site (S2S) VPN. B. Configure a VNet-toVNet VPN. C. Configure a Point-to-Site (P2S) VPN. D. Configure DirectAccess on a Windows Server 2012 server VM. E. Configure a Multi-Site VPN

C. A Point-to-Site (P2S) VPN gateway connection lets you create a secure connection to your virtual network from an individual client computer.P2S VPN is also a useful solution to use instead of S2S VPN when you have only a few clients that need to connect to a VNet.

A team of developers at your company plans to deploy, and then remove, 50 customized virtual machines each week. Thirty of the virtual machines run WindowsServer 2016 and 20 of the virtual machines run Ubuntu Linux.You need to recommend which Azure service will minimize the administrative effort required to deploy and remove the virtual machines.What should you recommend? A. Azure Reserved Virtual Machines (VM) Instances B. Azure virtual machine scale sets C. Azure DevTest Labs D. Microsoft Managed Desktop

C. Azure DevTest Labs

Your company implements ______ to automatically add a watermark to Microsoft Word documents that contain credit card information. A. Azure policies B. DDoS protection C. Azure Information Protection D. Azure Active Directory (Azure AD) Identity Protection

C. Azure Information Protection

What can you use to automatically send an alert if an administrator stops an Azure virtual machine? A. Azure Advisor B. Azure Service Health C. Azure Monitor D. Azure Network Watcher

C. Azure Monitor

You have an Azure Sentinel workspace.You need to automate responses to threats detected by Azure Sentinel.What should you use? A. adaptive network hardening in Azure Security Center B. Azure Service Health C. Azure Monitor workbooks D. adaptive application controls in Azure Security Center

C. Azure monitor workbooks Once you have connected your data sources to Microsoft Sentinel, you can visualize and monitor the data using the Microsoft Sentinel adoption of Azure Monitor Workbooks, which provides versatility in creating custom dashboards.

What should you use to evaluate whether your company's Azure environment meets regulatory requirements? A. the Knowledge Center website B. the Advisor blade from the Azure portal C. Compliance Manager from the Service Trust Portal D. the Solutions blade from the Azure portal

C. Compliance Manager from the Service Trust Portal

You have an Azure virtual network named VNET1 in a resource group named RG1. You assign an Azure policy specifying that virtual networks are not an allowed resource type in RG1. VNET1 A. s deleted automatically B. Is moved automatically to another resource group C. Continues to function normally D. Is now a read-only object

C. Continues to function normally

You plan to map a network drive from several computers that run Windows 10 to Azure Storage. You need to create a storage solution in Azure for the planned mapped drive.What should you create? A. an Azure SQL database B. a virtual machine data disk C. a File service in a storage account D. a Blob service in a storage account

C. a File service in a storage account

Which two types of customers are eligible to use Azure Government to develop a cloud solution? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point. A. a Canadian government contractor B. a European government contractor C. a United States government entity D. a United States government contractor E. a European government entity

C. a United States government entity D. a United States government contractor

You have an Azure subscription.Where will you find details on the personal data collected by Microsoft, how Microsoft uses the data, and what the data is used for? A. the Data Protection Addendum B. the Microsoft Online Services Terms C. the Microsoft Privacy Statement D. Azure Security Center

C. the Microsoft Privacy Statement

What is a feature of an Azure virtual network? A. resource cost analysis B. packet inspection C. geo-redundancy D. isolation and segmentation

D

You need to identify the type of failure for which an Azure Availability Zone can be used to protect access to Azure services.What should you identify? A. a physical server failure B. an Azure region failure C. a storage failure D. an Azure data center failure

D

You plan to migrate several servers from an on-premises network to Azure.What is an advantage of using a public cloud service for the servers over an on-premises network? A. The public cloud is owned by the public, NOT a private corporation B. The public cloud is a crowd-sourcing solution that provides corporations with the ability to enhance the cloud C. All public cloud resources can be freely accessed by every member of the public D. The public cloud is a shared entity whereby multiple corporations each use a portion of the resources in the clou

D

You need to manage containers.Which two services can you use? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point. A. Azure Virtual Desktop B. Azure virtual machines C. Azure Functions D. Azure Container Instances E. Azure Kubernetes Service (AKS)

D. Azure Container Instances E. Azure Kubernetes Service (AKS)

You attempt to create several managed Microsoft SQL Server instances in an Azure environment and receive a message that you must increase your Azure subscription limits. What should you do to increase the limits? A. Create a service health alert B. Upgrade your support plan C. Modify an Azure policy D. Create a new support request

D. Create a new support request. any Azure resource have quote limits. The purpose of the quota limits is to help you control your Azure costs. However, it is common to require an increase to the default quota.You can request a quota limit increase by opening a support request.

What is the first stage in the Microsoft Cloud Adoption Framework for Azure? A. Adopt the cloud. B. Make a plan. C. Ready your organization. D. Define your strategy.

D. Define strategy SPRAGM:Strategy - Plan - Ready - Adopt - Govern - Manage

You have an on-premises network that contains 100 servers. You need to recommend a solution that provides additional resources to your users. The solution must minimize capital and operational expenditure costs. What should you include in the recommendation? A. a complete migration to the public cloud B. an additional data center C. a private cloud D. a hybrid cloud

D. Hybrid With a hybrid cloud, you can continue to use the on-premises servers while adding new servers in the public cloud (Azure for example). Adding new servers inAzure minimizes the capital expenditure costs as you are not paying for new servers as you would if you deployed new server on-premises.

This question requires that you evaluate the underlined text to determine if it is correct.Azure Germany can be used by legal residents of Germany only.Instructions: Review the underlined text. If it makes the statement correct, select `No change is needed`. If the statement is incorrect, select the answer choice that makes the statement correct. A. no change is needed B. only enterprises that are registered in Germany C. only enterprises that purchase their azure licenses from a partner based in Germany D. any user or enterprise that requires its data to reside in Germany Show Suggested Answer

D. any user or enterprise that requires its data to reside in Germany

What are two characteristics of the public cloud? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point. A. dedicated hardware B. unsecured connections C. limited storage D. metered pricing E. self-service management

D. metered pricing E. self-service management

This question requires that you evaluate the underlined text to determine if it is correct.Azure {Key Vault} is used to store secrets for Azure Active Directory (Azure AD) user accounts.Instructions: Review the underlined text. If it makes the statement correct, select `No change is needed`. If the statement is incorrect, select the answer choice that makes the statement correct. A. No change is needed B. Azure Active Directory (Azure AD) administrative accounts C. Personally Identifiable Information (PII) D. server applications

D. server applications Key Vault is designed to store configuration secrets for server apps. It's not intended for storing data belonging to your app's users, and it shouldn't be used in the client-side part of an app.

This question requires that you evaluate the underlined text to determine if it is correct. From (Azure Cloud Shell), you can track your company's regulatory standards and regulations, such as ISO 27001. A. No change is needed. B. the Microsoft Cloud Partner Portal C. Compliance Manager D. the Trust Cente

D. the Trust Center

Your company plans to migrate all on-premises data to Azure.You need to identify whether Azure complies with the company's regional requirements.What should you use? A. the Knowledge Center B. Azure Marketplace C. the MyApps portal D. the Trust Center

D. the Trust Center Hide Answer

You can review audit reports and compiance related info for Azure services from -Ms Defender for cloud -ms defender for Identity admin center -ms 365 compliance center -ms service trust portal

Defender for Cloud

Your company hosts an accounting application named App1 that is used by all the customers of the company. App1 has low usage during the first three weeks of each month and very high usage during the last week of each month.Which benefit of Azure Cloud Services supports cost management for this type of usage pattern? A. high availability B. high latency C. elasticity D. load balancing

Elasticity in this case is the ability to provide additional compute resource when needed and reduce the compute resource when not needed to reduce costs.Autoscaling is an example of elasticity.

You can use Azure Sync agent to sync on premises data to an Azure____ -blob container -Data Lake Storage container - file share - queue

File share

An Azure web app that queries an on premises Microsoft SQL server is an example of a _________ cloud -hybrid -multi-vendor -private -public

Hybrid because Azure is already a public cloud example and it queries an on premise SQL server . So (public + private = hybrid)

You plan to implement several security services for an Azure environment. You need to identify which Azure services must be used to meet the following security requirements: ✑ Monitor threats by using sensors ✑ Enforce Azure Multi-Factor Authentication (MFA) based on a conditionWhich Azure service should you identify for each requirement? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point. -Azure Monitor -Azure Security Center -Azure Active Directory Identity protection -Azure Advances Threat Protection

Monitor: -Azure Advances Threat Protection Enforce Azure Multi-Factor Authentication (MFA) :-Azure Active Directory Identity protection

The company's migration plan states that only Platform as a Service (PaaS) solutions must be used in Azure.You need to deploy an Azure environment that meets the company migration plan.Solution: You create Azure virtual machines, Azure SQL databases, and Azure Storage accounts.Does this meet the goal? A. Yes B. No

No

We can create policy group using Azure AD? A.Yes B. no

No

You are tasked with deploying Azure virtual machines for your company.You need to make use of the appropriate cloud deployment solution.Solution: You should make use of Platform as a Service (PaaS).Does the solution meet the goal?

No

You are tasked with deploying a critical LOB application, which will be installed on a virtual machine, to Azure. You are informed that the application deployment strategy should allow for a guaranteed availability of 99.99 percent. You need to make sure that the strategy requires as little virtual machines and availability zones as possible. Solution: You include two virtual machines and one availability zone in your strategy. Does the solution meet the goal?

No

You have been informed by your superiors of the company's intentions to automate server deployment to Azure. There is, however, some concern that administrative credentials could be uncovered during this process. You are required to make sure that during the deployment, the administrative credentials are encrypted using a suitable Azure solution. Solution: You recommend the use of Azure Information Protection. Does the solution meet the goal?

No

Your company plans to migrate all its data and resources to Azure.The company's migration plan states that only Platform as a Service (PaaS) solutions must be used in Azure.You need to deploy an Azure environment that meets the company migration plan.Solution: You create an Azure App Service and Azure virtual machines that have Microsoft SQL Server installed.Does this meet the goal? A. Yes B. No

No

Your company has an Azure Active Directory (Azure AD) environment. Users occasionally connect to Azure AD via the Internet. You have been tasked with making sure that users who connect to Azure AD via the internet from an unidentified IP address, are automatically encouraged to change passwords.Solution: You configure the use of Azure AD Privileged Identity Management.Does the solution meet the goal?

No Privileged Identity Management provides time-based and approval-based role activation to mitigate the risks of excessive, unnecessary, or misused access permissions on resources that you care about

Yes or No? 1.Azure subscription can be associated to multiple Azure Active Directory 2. You cab change the Azure Active Directory tentant to which an Azure subscribtion is associated 3. Then Azure subsriction expired the associated Azure Active Directory tentant is deletet automatically

No Yes No

Yes or No - The archive access tier is set at the storage account level - The Hot access tier is recomennded for data that is accessed and modified frequently - The cool access tier is recommended for long term backups

No Yes Yes

Yes or no -Azure resources can ony access other resources in the same resource group -If you delete a resource group all the resources will be deleted - A resource group can contain resources from multiple Azure regoins

No Yes Yes

An Azure administrator plans to run a PowerShell script that creates Azure resources.You need to recommend which computer configuration to use to run the script.Solution: Run the script from a computer that runs macOS and has PowerShell Core 6.0 installed.Does this meet the goal? A. Yes B. No

No The computer has PowerShell Core 6.0, but it doesn't have the Azure CLI installed. There is no mention of that in the question. You need Azure PowerShell module in addition to PowerShell to run Azure commands, such as New-AzVM. Therefore, the answer should be B, No.

You plan to deploy several Azure virtual machines.You need to ensure that the services running on the virtual machines are available if a single data center fails.Solution: You deploy the virtual machines to two or more scale sets.Does this meet the goal? A. Yes B. No

No, An availability set is a logical grouping of VMs within a datacenter. You will have to use availability zones. Hence B answer

Your company's developers intend to deploy a large number of custom virtual machines on a weekly basis. They will also be removing these virtual machines during the same week it was deployed. Sixty percent of the virtual machines have Windows Server 2016 installed, while the other forty percent has Ubuntu Linux installed.You are required to make sure that the administrative effort, needed for this process, is reduced by employing a suitable Azure service.Solution: You recommend the use of Microsoft Managed Desktop.Does the solution meet the goal?

No, DevTest Labs are perfect for this scenario while they want to create 50 VMs they also want to DECOMISSION them in a very short period of time. that spells completely: test environment.

Your company's infrastructure includes a number of business units that each need a large number of various Azure resources for everyday operation. The resources required by each business unit are identical. You are required to sanction a strategy to create Azure resources automatically.Solution: You recommend that management groups be included in the strategy. Does the solution meet the goal?

No, It should be ARM template.

You have been informed by your superiors of the company's intentions to automate server deployment to Azure. There is, however, some concern that administrative credentials could be uncovered during this process.You are required to make sure that during the deployment, the administrative credentials are encrypted using a suitable Azure solution.Solution: You recommend the use of Azure Multi-Factor Authentication (MFA).Does the solution meet the goal?

No, MFA adds an aditional layer to the authentication process, but it doesn't keep your credential safe

Your company's Active Directory forest includes thousands of user accounts. You have been informed that all network resources will be migrated to Azure. Thereafter, the on-premises data center will be retired. You are required to employ a strategy that reduces the effect on users, once the planned migration has been completed.Solution: You plan to require Azure Multi-Factor Authentication (MFA).Does the solution meet the goal?

No, The best way to resolve this issue would be to sync all the Active Directory user accounts to Azure Active Directory (Azure AD).

You are planning a strategy to deploy numerous web servers and database servers to Azure.This strategy should allow for connection types between the web servers and database servers to be controlled. Solution: You include a local network gateway in your strategy.Does the solution meet the goal?

No, The local network gateway is a specific object that represents your on-premises location (the site) for routing purpose.

You are planning to migrate a company to Azure. Each of the company's numerous divisions will have an administrator in place to manage the Azure resources used by their respective division. You want to make sure that the Azure deployment you employ allows for Azure to be segmented for the divisions, while keeping administrative effort to a minimum. Solution: You plan to make use of several Azure Active Directory (Azure AD) directories. Does the solution meet the goal?

No, Why in the world a company will create SEVERAL AADs when it can create a single AAD and organize its divisions right there?

Yes or no? 1.Azure Advisor provides recommendations on how to improve the security of an Azure Active Directory environment 2.Azure Advisor provides recommendations on how to reduce the cost of running Azure virtual machines 3.Azure Advisor provides recommendations on how to configure the network setting on Azure VM

No, Yes, No

-Trust Center is part of the Azure Security Center -Trust Center can only be accessed by users that have an Azure subscription -Trust Center provides information about the Azure compliance offerings

No, no yes

You need to ensure that the services running on the virtual machines are available if a single data center fails.Solution: You deploy the virtual machines to two or more resource groups.Does this meet the goal? A. Yes B. No

No, when you create a virtual machine and place it in the resource group, the virtual machine can still be in a different location (different datacenter).Therefore, creating multiple resource groups, even if they are in separate datacenters does not ensure that the services running on the virtual machines are available if a single data center fails.

Your company's infrastructure includes a number of business units that each need a large number of various Azure resources for everyday operation. The resources required by each business unit are identical. You are required to sanction a strategy to create Azure resources automatically. Solution: You recommend that the Azure API Management service be included in the strategy.Does the solution meet the goal?

No. Azure API Management Service i( APIM ) is a way to create and manage customer APIs for existing backend services. The Question is asking about a way to create Azure resources automatically ( on the fly ). ARM (Azure Resource Manager) is a tool that automates the deployments on the AZ cloud.

A Microsoft SQL Server Database that is hosted in the cloud an had software updates managed by Azure is an example of - disaster recovery as a service(DRaaS) - IaaS - PaaS - SaaS

PaaS

A Microsoft SQL Server db that is hosted in the cloud and has software updated managed by Azure is an example of -disaster recovery as a service DRaaS -IaaS -PaaS -SaaS

PaaS

Azure Cosmos DB is an example of _____ offering -PaaS -IaaS -Serverkess -SaaS

PaaS

In which type of cloud model are all the hardware resources owned by a third-party and shared between multiple tenants? A. private B. hybrid C. public

Public

1. Provides the platform for serverless code 2. A big data analysis service for ML 2. Detects and diagnoses anomalies in web apps 4. Hosts web apps 1.Databricks 2.Functions 3.App Service 4. Application Insights

Serverless ---> Functions big data analysis ---> databricks anomalies ---> Insights Host ---> App Service

Your company plans to migrate all its data and resources to Azure. The company's migration plan states that only Platform as a Service (PaaS) solutions must be used in Azure. You need to deploy an Azure environment that meets the company migration plan. Solution: You create an Azure App Service and Azure SQL databases. Does this meet the goal?

Yes

Your company's Active Directory forest includes thousands of user accounts. You have been informed that all network resources will be migrated to Azure. Thereafter, the on-premises data center will be retired. You are required to employ a strategy that reduces the effect on users, once the planned migration has been completed. Solution: You plan to sync all the Active Directory user accounts to Azure Active Directory (Azure AD). Does the solution meet the goal?

Yes

Your company's developers intend to deploy a large number of custom virtual machines on a weekly basis. They will also be removing these virtual machines during the same week it was deployed. Sixty percent of the virtual machines have Windows Server 2016 installed, while the other forty percent has Ubuntu Linux installed.You are required to make sure that the administrative effort, needed for this process, is reduced by employing a suitable Azure service.Solution: You recommend the use of Azure DevTest Labs.Does the solution meet the goal?

Yes

Your company's infrastructure includes a number of business units that each need a large number of various Azure resources for everyday operation. The resources required by each business unit are identical .You are required to sanction a strategy to create Azure resources automatically. Solution: You recommend that the Azure Resource Manager templates be included in the strategy.Does the solution meet the goal?

Yes

Your company has an Azure Active Directory (Azure AD) environment. Users occasionally connect to Azure AD via the Internet.You have been tasked with making sure that users who connect to Azure AD via the internet from an unidentified IP address, are automatically encouraged to change passwords.Solution: You configure the use of Azure AD Identity Protection.Does the solution meet the goal?

Yes Identity Protection identifies risks of many types, including: Anonymous IP address use Atypical travel Malware linked IP address Unfamiliar sign-in properties Leaked credentials Password spray

You are tasked with deploying a critical LOB application, which will be installed on a virtual machine, to Azure.You are informed that the application deployment strategy should allow for a guaranteed availability of 99.99 percent. You need to make sure that the strategy requires as little virtual machines and availability zones as possible. Solution: You include two virtual machines and two availability zones in your strategy. Does the solution meet the goal?

Yes, For all Virtual Machines that have two or more instances deployed across two or more Availability Zones in the same Azure region, we guarantee you will have Virtual Machine Connectivity to at least one instance at least 99.99% of the time.

Your company is planning to migrate all their virtual machines to an Azure pay-as-you-go subscription. The virtual machines are currently hosted on the Hyper-V hosts in a data center. You are required make sure that the intended Azure solution uses the correct expenditure model. Solution: You should recommend the use of the operational expenditure model. Does the solution meet the goal?

Yes, Operating expenditures are ongoing costs of doing business. Consuming cloud services in a pay-as-you-go model could qualify as an operating expenditure.

You have an Azure subscription named Subscription1. You sign in to the Azure portal and create a resource group named RG1.From Azure documentation, you have the following command that creates a virtual machine named VM1. az vm create --resource-group RG1 --name VM1 --image UbuntuLTS --generate-ssh-keys You need to create VM1 in Subscription1 by using the command. Solution: From a computer that runs Windows 10, install Azure CLI. From PowerShell, sign in to Azure and then run the command.Does this meet the goal? A. Yes B. No

Yes, The command can be run from PowerShell or the command prompt if you have the Azure CLI installed.

Yes or no? -Data that is stored in Azure Storage account automatically has at least three copies - All data that is copied to an Azure Storage account is backed up automatically to another data center - An Azure Storage account can contain up to 2 TB og data and upt to million files

Yes, There are different replication options available with a storage account. The 'minimum' replication option is Locally Redundant Storage (LRS). With LRS, data is replicated synchronously three times within the primary region. No, Data is not backed up automatically to another Azure Data Center although it can be depending on the replication option configured for the account. LocallyRedundant Storage (LRS) is the default which maintains three copies of the data in the data center. No, The limits are much higher than that. The current storage limit is 2 PB for US and Europe, and 500 TB for all other regions (including the UK) with no limit on the number of files

You are tasked with deploying Azure virtual machines for your company.You need to make use of the appropriate cloud deployment solution.Solution: You should make use of Infrastructure as a Service (IaaS).Does the solution meet the goal?

Yes, Virtual Machines and Azure storage accounts is IaaS

You have an Azure environment. You need to create a new Azure virtual machine from a tablet that runs the Android operating system. Solution: You use Bash in Azure Cloud Shell.Does this meet the goal? A. Yes B. No

Yes, With Azure Cloud Shell, you can create virtual machines using Bash or PowerShell.

1.You can create custom Azure roles to control access to resources 2. A user account can be assigned to multiple Azure roles 3. A resource group can have Owner role assigned to multiple users

Yes, Yes, No

Yes or No? 1. You can use Cost Management to view costs associated to management groups 2. You can use Cost Management to view costs associated to resource groups 3.You can use Cost Management to view the usage of virtual machines

Yes, Yes, Yes

You are planning a strategy to deploy numerous web servers and database servers to Azure. This strategy should allow for connection types between the web servers and database servers to be controlled.Solution: You include network security groups (NSGs) in your strategy. Does the solution meet the goal?

Yes, You can use an Azure network security group to filter network traffic to and from Azure resources in an Azure virtual network. A network security group contains security rules that allow or deny inbound network traffic to, or outbound network traffic from, several types of Azure resources. For each rule, you can specify source and destination, port, and protocol.

1. You can associate a network security group (NSG) to a virtual network subnet 2. You can associate a network security group (NSG) to a virtual network 3.You can associate a network security group (NSG) to a virtual network interface

Yes, no yes

Yes or No? 1. Azure Monitor can monitor the performance of on premises computers 2. Azure Monitor can send alerts to Azure Active Directory security groups 3. Azure Monitor can trigger alerts based on data in an Azure Log analytics workspace

Yes, no yes

Yes or No -To use Azure AD credentials to sign into a computer that runs Windows 10, the computer must be joined to AD -Users in Azure AD are organized by using resource groups -Azure Active Directory groups support dynamic membership rules

Yes, no, yes

You plan to deploy a critical line-of-business application to Azure.The application will run on an Azure virtual machine.You need to recommend a deployment solution for the application. The solution must provide a guaranteed availability of 99.99 percent.What is the minimum number of virtual machines and the minimum number of availability zones you should recommend for the deployment? To answer, select the appropriate options in the answer area.

You need a minimum of two virtual machines with each one located in a different availability zone.

You have 50 virtual machines hosted on-premises and 50 virtual machines hosted in Azure. The on-premises virtual machines and the Azure virtual machines connect to each other.Which type of cloud model is this? A. hybrid B. private C. public

a.hybrid

Yes or No - Azure Advisor can generate a list of Azure VM that are protected by azure backup - If you implement the securty recommendations provided by Azure Advisor, your companys secure score will decrease - To maintain Microsoft support you must implement the security recommendations provided by Azure Advisor within 30 days

no no no 1. Azure Advisor can generate a list of VM's "NOT" protected by backup -> NO 2. You are aiming for an overall score of 100%, Score INCREASE when implementing recommendations -> NO 3. Microsoft Support is not dependant on recommendations beeing implemented -> NO

1. to implement an azure MFA solution you must sync on premises identities to the cloud 2. Two valid methods for azure MFA are picture id and passport nr 3. azure MFA can be required for administrative and non administrative accounts

no, no, yes

1. You can create Group Policies in Azure AD 2. You can join Windows 10 devices to Azure AD 3. You can join android devices to Azure AD

no, yes no

1. Identities stored in an on-premises Active Directory can be syncronized to Azure AD 2. Identities stored in Azure Active Directory, third party cloud services, and on-premises Active directory can be used to access Azure resources 3. Azure has built in authentication services that provide secure access to Azure resources

yes, yes, yes


Kaugnay na mga set ng pag-aaral

Transcription, Translation & Differentiation

View Set

Creating and Using Thesis Statements - Quiz

View Set

Kappa Alpha Psi - Cumulative Test - 1

View Set