AZ-900
ow much does a Developer level support for Azure cost? $29 per month $1,000 per month $100 per month $0 per month
$29 per month
Which feature within Azure alerts you to service issues that happen in Azure itself, not specifically related to your own resources? Azure Monitor Azure Service Health Azure Portal Dashboard Azure Security Center
Azure Service Health
Which tool within Azure is comprised of : Azure Status, Service Health and Resource Health? Azure Dashboard Azure Monitor Azure Advisor Azure Service Health
Azure Service Health
A customer is planning on creating several Azure Free Accounts. Can a customer have an allowance of a maximum of 10 Azure Free Accounts? Yes No
No
What is the Azure SLA for two or more Virtual Machines in an Availability Set? 0.9995 99.99% 1 0.999
0.9995
What is the service level agreement for two or more Azure Virtual Machines that have been manually placed into different Availability Zones in the same region? 0.9995 0.999 1 0.9999
0.9999
How many regions does Azure have in Brazil? 2 zero 4 1
1
How many free VMs are included per month on the Azure free account in the first 12 months? zero 3 1 2
2
What does it mean if a service is in General Availability (GA) mode? You have to apply to get selected in order to use that service The service is generally available for use, and Microsoft will provide support for it Anyone can use the service but it must not be for production use Anyone can use the service for any reason
Anyone can use the service for any reason
This question requires that you evaluate the underlined text to determine if it is correct.Authorization is the process of verifying a user's credentials. Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct. Authentication Federation No change is needed Ticketing
Authentication
A company has deployed their solutions on to Microsoft Azure.They have users that connect to Azure AD via the Internet.They have the requirement that if users try to login from an anonymous IP address, they are then prompted to change their password.Which of the following should the company consider for this requirement? Azure AD Connect Health Azure Advanced Threat Protection (ATP) Azure AD Identity Protection Azure AD Privileged Identity Management
Azure AD Identity Protection Explanation:- Azure AD Identity Protection because Identity this is a tool that allows organizations to accomplish three key tasks:Automate the detection and remediation of identity-based risks.Investigate risks using data in the portal.Export risk detection data to third-party utilities for further analysis.Identity Protection uses the learnings Microsoft has acquired from their position in organizations with Azure AD, the consumer space with Microsoft Accounts, and in gaming with Xbox to protect your users. Microsoft analyses 6.5 trillion signals per day to identify and protect customers from threats.The signals generated by and fed to Identity Protection, can be further fed into tools like Conditional Access to make access decisions, or fed back to a security information and event management (SIEM) tool for further investigation based on your organization's enforced policies.
A team of developers at your company plans to deploy, and then remove, 50 customized virtual machines each week. Thirty of the virtual machines run Windows Server 2016 and 20 of the virtual machines run Ubuntu Linux. You need to recommend which Azure service will minimize the administrative effort required to deploy and remove the virtual machines. What should you recommend? Azure Reserved Virtual Machines (VM) Instances Azure virtual machine scale sets Azure DevTest Labs Microsoft Managed Desktop
Azure DevTest Labs
You are working on understanding all the key terms when it comes to International standards, data privacy and data protection policies. Which of the following pertains to the following?"A dedicated public cloud for federal and state agencies in the United States" Azure Government GDPR NIST ISO
Azure Government Explanation:- Azure Government is correct because Azure Government delivers a dedicated cloud enabling only US government agencies and their partners to transform mission-critical workloads to the cloud. In order to provide you with the highest level of security and compliance, Azure Government uses physically isolated data-centers and networks.For more information, please visit:https://docs.microsoft.com/en-us/azure/azure-government/documentation-government-welcomeNIST is incorrect because NIST, National Institute of Standards and Technology (is a physical sciences laboratory, and a non-regulatory agency of the United States Department of Commerce. Its mission is to promote innovation and industrial competitiveness. NIST's activities are organized into laboratory programs that include nanoscale science and technology, engineering, information technology, neutron research, material measurement, and physical measurement.
A company is planning on setting up a solution within Microsoft Azure.The solution would have the following key requirement:- Provide a cloud service that makes it easy, fast, and cost-effective to analyse massive amounts of data.Which of the following would be best suited for this requirement? Azure Content Delivery Network Azure SQL Datawarehouse Azure HD Insight Azure Load Balancer
Azure HD Insight Explanation:- Azure HD Insight because Azure HD Insight is a managed, full-spectrum, open-source analytics service in the cloud for enterprises. You can use open-source frameworks such as Hadoop, Apache Spark, Apache Hive, LLAP, Apache Kafka, Apache Storm, R, and more.
A company has a number of resources hosted in Azure. They want to push all the events from the various resources into a centralized repository so that the events could be correlated later on. Which of the following service would you use for this requirement? Azure Analysis Services Azure Event Hubs Azure Advisor Azure Log Analytics
Azure Log Analytics
Which Azure service should you use to correlate events from multiple resources into a centralized repository? Azure Analysis Services Azure Log Analytics Azure Event Hubs Azure Monitor
Azure Log Analytics
Your company plans to deploy several million sensors that will upload data to Azure.You need to identify which Azure resources must be created to support the planned solution. Which two Azure resources should you identify? Each correct answer presents part of the solution. Azure Data Lake Azure Notification Hubs Azure Queue storage Azure File Storage Azure IoT Hub
Azure Queue storage Azure IoT Hub
A company needs to store 2TB of data that will be infrequently used.The data needs to be accessed via PowerBI.Choose 2 of the following options the company should consider as cost-effective data storage solutions to fulfill this need. Azure Data Lake Azure Synapse Analytics Azure CosmosDB Azure PostgreSQL Azure SQL Databases
Azure Synapse Analytics Explanation:- Azure Synapse Analytics is a limitless analytics service that brings together enterprise data warehousing and Big Data analytics. It gives you the freedom to query data on your terms, using either serverless on-demand or provisioned resources—at scale. Azure Synapse brings these two worlds together with a unified experience to ingest, prepare, manage, and serve data for immediate BI and machine learning needsFor more information, please reference:https://docs.microsoft.com/en-us/azure/sql-data-warehouse/sql-data-warehouse-overview-what-isAzure Data Lake is a highly scalable public cloud service that allows developers, scientists, business professionals and other Microsoft customers to gain insight from large, complex data sets. As with most data lake offerings, the service is composed of two parts: data storage and data analytics.For more information, please reference:https://docs.microsoft.com/en-us/azure/data-lake-store/data-lake-store-overview
Your company plans to purchase Azure.The company's support policy states that the Azure environment must provide an option to access support engineers by phone or email.You need to recommend which support plan meets the support policy requirement.Solution: Recommend a Standard support plan.Does this meet the goal? Incorrect Correct
Correct Explanation:- The Standard plan comes with phone and email support.
A company is planning on deploying an Azure Windows Server 2016 virtual machine. Could the virtual machine be used to encrypt all traffic from the virtual machine itself to a host on the Internet? Correct Incorrect
Correct Explanation:- You can install roles such as the Remote Access Server for VPN to ensure traffic is encrypted when it flows out of the server.An example in the Microsoft documentation is given via the below URL
You plan to deploy several Azure virtual machines.You need to ensure that the services running on the virtual machines are available if a single data center fails. Solution: You deploy the virtual machines to two or more regions.Does this meet the goal? Correct Incorrect
Incorrect
Your company has just set up an Azure subscription and an Azure tenant. They want to use recommendations given by the Azure Advisor tool. If your company starts implementing the recommendations given by the Azure Advisor tool, would the company's security score decrease? Incorrect Correct
Incorrect Explanation:- If you improve the security stance of your resources, your security score will increase.
For tax optimization, which type of expense is preferable? CapEx OpEx
OpEx
What type of documents does the Microsoft Service Trust Portal provide? A tool that helps you manage your compliance to various standards Specific recommendations about your usage of Azure and ways you can improve A list of standards that Microsoft follows, pen test results, security assessments, white papers, faqs, and other documents that can be used to show Microsoft's compliance efforts Documentation on the individual Azure services and solutions
A list of standards that Microsoft follows, pen test results, security assessments, white papers, faqs, and other documents that can be used to show Microsoft's compliance efforts
ou have a resource group named RG1. You plan to create virtual networks and app services in RG1.You need to prevent the creation of virtual machines only in RG1.What should you use? A tag A lock An Azure policy An Azure role
A lock
One of the benefits of the cloud is agility. What does that mean in the context of the cloud? Ability to develop and deploy rapidly, sometimes daily code deployments The ability to recover from a big region-wide failure in a short amount of time Ability of a system to grow it's capacity easily when it reaches full capacity Ability to spin up new resources within minutes
Ability to spin up new resources within minutes
Whom amongst the following can use the services offered as part of "Azure Germany"? Only users located in Germany Only Enterprises in Germany All customers who intend to do business in Europe Only Enterprises and users located in Germany
All customers who intend to do business in Europe
What is one way to increase the security of a traditional user id and password system? All of These Require users to change their passwords more frequently. Require longer and more complex passwords. Do not allow users to log into an application except using a company registered device. Use multi-factor authentication which requires an additional device (something you have) to verify identity.
All of These
If you have an Azure free account, with a $200 credit for the first month, what happens when you reach the $200 limit? All services are stopped and you must decide whether you want to convert to a paid account or not. You cannot create any more resources until you add more credits to the account. Your account is automatically closed. Your credit card is automatically billed.
All services are stopped and you must decide whether you want to convert to a paid account or not.
What benefit does a Content Delivery Network (CDN) provide its users? Allows you to store data that can be retrieved later in an extremely fast and inexpensive manner For a small fee, Azure will take over management of your virtual machine, perform OS updates and ensure it's running well Allows you to keep temporarily session information on the web visitor such as their login ID or their name Allows you to reduce the traffic coming into a web server for static, unchanging files such as images, videos and PDFs
Allows you to reduce the traffic coming into a web server for static, unchanging files such as images, videos and PDFs
A company has deployed their solutions on to Azure. They have users that connect to Azure AD via the Internet. They have the requirement that if users try to login from an anonymous IP address, they are then prompted to change their password. Which of the following should the company consider for this requirement? Azure AD Identity Protection Azure Advanced Threat Protection (ATP) Azure AD Connect Health Azure AD Privileged Identity Management
Azure AD Identity Protection Explanation:- You have to create a policy in Azure AD Identity Protection.For more information on Azure AD Identity protection, please visit the below URL https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/overview
To what should an application connect to retrieve security tokens? an Azure Storage account Azure Active Directory (Azure AD) An Azure key vault A certificate store
Azure Active Directory (Azure AD)
A company needs to store 2TB of data that will be infrequently used. The data needs to be accessed via PowerBI. Which of the following would you consider as a cost-effective data storage layer for this requirement? Choose 2 answers from the options given below Azure PostgreSQL Azure CosmosDB Azure SQL Databases Azure Data Lake Azure SQL Datawarehouse
Azure Data Lake Azure SQL Datawarehouse
You have a virtual machine named VM1 that runs Windows Server 2016. VM1 is in the East US Azure region.Which Azure service should you use from the Azure portal to view service failure notifications that can affect the availability of VM1? Azure Advisor Azure Service Fabric Azure Monitor Azure virtual machines
Azure Monitor
A company needs to create a set of resources within Microsoft Azure.For IT Administrators, there is a requirement in which they may only create resources in a certain region.Which of the following can help achieve this? Azure Policies Azure Tags Azure Locks Azure Resource Groups
Azure Policies Explanation:- Azure Policies because Azure Policies is really governance validation that your organization can achieve its goals through effective and efficient use of IT. It meets this need by creating clarity between business goals and IT projects.Does your company experience a significant number of IT issues that never seem to get resolved? Good IT governance involves planning your initiatives and setting priorities on a strategic level to help manage and prevent issues. This strategic need is where Azure Policy comes in.Azure Policy is a service in Azure that you use to create, assign, and manage policies. These policies enforce different rules and effects over your resources, so those resources stay compliant with your corporate standards and service level agreements. Azure Policy meets this need by evaluating your resources for non-compliance with assigned policies. All data stored by Azure Policy is encrypted at rest.For example, you can have a policy to allow only a certain SKU size of virtual machines in your environment. Once this policy is implemented, new and existing resources are evaluated for compliance. With the right type of policy, existing resources can be brought into compliance. This would also apply to the IT administrator in the question who can only create resources in a certain region.A policy assignment is a policy definition that has been assigned to take place within a specific scope. This scope could range from a management group to a resource group. The term scope refers to all the resource groups, subscriptions, or management groups that the policy definition is assigned to. Policy assignments are inherited by all child resources. This design means that a policy applied to a resource group is also applied to resources in that resource group. However, you can exclude a subscope from the policy assignment.For example, at the subscription scope, you can assign a policy that prevents the creation of networking resources. You could exclude a resource group in that subscription that is intended for networking infrastructure. You then grant access to this networking resource group to users that you trust with creating networking resources.In another example, you might want to assign a resource type allow list policy at the management group level. And then assign a more permissive policy (allowing more resource types) on a child management group or even directly on subscriptions. However, this example wouldn't work because policy is an explicit deny system. Instead, you need to exclude the child management group or subscription from the management group-level policy assignment. Then, assign the more permissive policy on the child management group or subscription level. If any policy results in a resource getting denied, then the only way to allow the resource is to modify the denying policy.
A company has just setup an Azure subscription and an Azure tenant. They want to start deploying resources on the Azure platform. They want to implement a way to deploy the resources so that they would be located closest to the users accessing those resources. Which of the following could be used for this requirement? Azure Resource Groups Azure Regions Availability Zones Azure Resource Manager
Azure Regions Explanation:- You can make use of Azure Regions and deploy the resources to the region that is closest to the user.The Microsoft documentation mentions the following::
A company needs to deploy several virtual machines. Each of these virtual machines will have the same set of permissions. To minimize the administrative overhead, in which would you deploy the Azure Virtual Machines? Azure Virtual Machine Scale sets Azure Tags Azure Policies Azure Resource Groups
Azure Resource Groups Explanation:- When you deploy a resource to a resource group which has a set of permissions defined, the resource will inherit the permissions assigned to the resource group. An example is shown below. An example is shown below where a resource group has a permission defined. For more information on role-based access control, please visit the below URL https://docs.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal
A company is planning on deploying resources to Azure. Which of the following in Azure provides a common platform for deploying objects to the Azure Cloud Infrastructure and also allows implementing consistency across the environment? Azure Management Groups Azure Resource Manager Azure Policies Azure Resource Groups
Azure Resource Manager
A company is planning on deploying resources to Microsoft Azure.Which of the following in Azure provides a common platform for deploying objects to the Azure Cloud Infrastructure and also allows implementing consistency across the environment? Azure Resource Manager Azure Management Groups Azure Resource Groups Azure policies
Azure Resource Manager Explanation:- Azure Resource Manager because Azure Resource Manager is the deployment and management service for Azure. It provides a management layer that enables you to create, update, and delete resources in your Azure subscription. You use management features, like access control, locks, and tags, to secure and organize your resources after deployment.The benefits of using Resource Manager include:Manage your infrastructure through declarative templates rather than scripts.Deploy, manage, and monitor all the resources for your solution as a group, rather than handling these resources individually.Redeploy your solution throughout the development lifecycle and have confidence your resources are deployed in a consistent state.Define the dependencies between resources so they're deployed in the correct order.Apply access control to all services in your resource group because Role-Based Access Control (RBAC) is natively integrated into the management platform.Apply tags to resources to logically organize all the resources in your subscription.Clarify your organization's billing by viewing costs for a group of resources sharing the same tag.
This question requires that you evaluate the underlined text to determine if it is correct. Azure policies provide a common platform for deploying objects to a cloud infrastructure and for implementing consistency across the Azure environment. Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct. Management groups provide Resource groups provide Azure Resource Manager provides No change is needed
Azure Resource Manager provides
A company has a requirement to deploy 10 different types of Azure resources for several departments. All of the resources types and configurations are the same. Which of the following could be used to automate the deployment of the resources? Azure API Management service Management groups Azure Resource Manager templates Virtual machine scale sets
Azure Resource Manager templates
You plan to store 20 TB of data in Azure. The data will be accessed infrequently and visualized by using Microsoft Power BI.You need to recommend a storage solution for the data. Which two solutions should you recommend? Azure SQL Data Warehouse Azure Database for PostgreSQL Azure SQL Database Azure Data Lake Azure Cosmos DB
Azure SQL Data Warehouse
A company is planning on setting up a solution in Azure. The solution would have the following key requirement Provide a data store that can be used to store and perform analytics on petabytes of data Which of the following would be best suited for this requirement? Azure Content Delivery Network Azure HD Insight Azure Load Balancer Azure SQL Datawarehouse
Azure SQL Datawarehouse
A company is planning on setting up a solution in Azure. The solution would have the following key requirement: - Provide a solution to host and manage a group of identical Virtual Machines Which of the following would be best suited for this requirement? Azure Data Lake Analytics Azure App Service Azure Virtual Network Azure Virtual Machine Scale Sets
Azure Virtual Machine Scale Sets
A company wants to implement an IoT solution service available in Microsoft Azure.Which of the following would meet the below requirement?"Monitor and control billions of Internet of Things (IoT) assets". IoT Edge IoT Central IoT Hub Azure Time Series Insights
IoT Hub
This question requires that you evaluate the underlined text to determine if it is correct. Resource groups provide organizations with the ability to manage the compliance of Azure resources across multiple subscriptions. Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct. Azure policies Management groups Azure App Service plans No change is needed
Azure policies
Which tool within Azure helps you to track your compliance with various international standards and government laws? Service Trust Portal Microsoft Privacy Statement Compliance Manager Azure Government Services
Compliance Manager
Deploying Azure App Services applications consists of what two components? Pick two. Database scripts Configuration Packaged code Managing operating system updates
Configuration Packaged code
A company wants to create multiple data stores in Microsoft Azure.They want to have storage layers that can be used to store data that is infrequently used.Which of the following storage tiers for Azure BLOB storage would be suitable for this type of requirement?Choose 2 answers from the options given below. Cool storage Hot storage Archive storage Premium storage
Cool storage Explanation:- Cool Storage & D. Archive Storage are correct because Azure storage offers different access tiers, which allow you to store blob object data in the most cost-effective manner. The available access tiers include:Hot - Optimized for storing data that is accessed frequently.Cool - Optimized for storing data that is infrequently accessed and stored for at least 30 days.Archive - Optimized for storing data that is rarely accessed and stored for at least 180 days with flexible latency requirements (on the order of hours).For more information, please visit:https://docs.microsoft.com/en-us/azure/storage/blobs/storage-blob-storage-tiers
A company plans on purchasing a Microsoft Azure Support plan.Below is a key requirement for the support plan:- Provide an option to contact Microsoft support engineers by phone or email 24/7.A recommendation is made to purchase the Standard Support plan.Would this recommendation fulfil the requirement? Correct Incorrect
Correct
A company wants to host a set of tables in Microsoft Azure.They want absolutely zero administration of the underlying infrastructure and low latency access to data.You recommend using the SQL Database service.Would this meet the requirement? Incorrect Correct
Correct
Correct or Incorrect: you can create your own policies if built-in Azure Policy is not sufficient to your needs Correct Incorrect
Correct
A company wants to implement an IoT solution service available in Microsoft Azure.Which of the following would meet the below requirement?"Provides a fully managed SaaS (software-as-a-service) solution that makes it easy to connect, monitor and manage IoT assets at scale". IoT Hub IoT Edge IoT Central Azure Time Series Insights
IoT Central
Your company is planning on using Azure AD for authentication to the resources defined in Azure.Does Azure AD have built-in capabilities for securing authentication and authorization to resources? Correct Incorrect
Correct Explanation:- Azure Active Directory (Azure AD) is Microsoft's cloud-based identity and access management service, which helps your employees sign in and access resources such as Microsoft Office 365, the Azure portal, and thousands of other SaaS applications with built-in capabilities for securing both authentication and authorization.For more information, please visit:https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-whatis
A company wants to try out some services which are being offered by Microsoft Azure in Public Preview.Does Microsoft provide a separate Azure portal for trying out the services in Public Preview? Correct Incorrect
Correct Explanation:- Microsoft Azure offers preview features to you for evaluation purposes. A preview may include preview, beta, or other pre-release features, services, software, or regions. Previews are subject to reduced or different service terms, as set forth in your service agreement and the preview supplemental terms -https://azure.microsoft.com/en-us/support/legal/preview-supplemental-terms/ . Previews are made available to you on the condition that you agree to these terms of use, which supplement your agreement governing the use of Azure.So If you want to test public preview features you would go to for preview.portal.azure.comIf you want to implement the public preview solution, you'd use portal.azure.comFor more information, please visit:https://azure.microsoft.com/en-us/support/legal/preview-supplemental-terms/
A company is planning on hosting a set of resources in Azure. They want to protect their resources against DDoS attacks and also get real time attack metrics. Which of the following should the company opt for? DDoS Protection Basic DDoS Protection Isolated DDoS Protection Standard DDoS Protection Premium
DDoS Protection Standard Explanation:- This is mentioned in the Microsoft Documentation. Since this is clearly mentioned in the documentation, all other options are incorrect For more information on Azure IoT Hub, please visit the below URLhttps://docs.microsoft.com/en-us/azure/virtual-network/ddos-protection-overview
Which of the following is not a feature of Azure Functions? Can possibly cost you nothing as there is a generous free tier Can trigger the function based off of Azure events such as a new file being saved to a storage account blob container Designed for backend batch applications that are continuously running Can edit the code right in the Azure Portal using a code editor
Designed for backend batch applications that are continuously running
What is Guaranteed in an Azure Service Level Agreement (SLA)? Performance Bandwidth Feature availability Uptime
Feature availability
You are working on understanding all the key terms when it comes to International Standards, data privacy and data protection policies.Which of the following choices pertains to the following?"An organization that defines international standards across all industries" GDPR NIST Azure Government ISO
ISO Explanation:- ISO is the correct answer because ISO, International Organization for Standardization, is an organization defines international standards across all industries.
A company is planning on setting up a Microsoft Azure Free Account.Does the Standard Support plan come along with the Microsoft Azure Free Account? Incorrect Correct
Incorrect
An Azure administrator plans to run a PowerShell script that creates Azure resources.You need to recommend which computer configuration to use to run the script. Solution: Run the script from a computer that runs Chrome OS and uses Azure Cloud Shell.Does this meet the goal? Incorrect Correct
Incorrect
A company wants to setup users within their Microsoft Azure Account.They have segregated their users into groups.They now want to ensure they set the right permissions for users and administrators accordingly.They need to manage the permissions effectively.You recommend using Azure Management Groups.Does this recommendation meet the requirement? Incorrect Correct
Incorrect Explanation:- Azure Management Groups refers to the tasks and processes required to maintain your business applications and the resources that support them. Azure has many services and tools that work together to provide complete management. These services aren't only for resources in Azure, but also in other clouds and on-premises. Understanding the different tools and how they work together is the first step in designing a complete management environment.
A company wants to setup users in within their Microsoft Azure Account.They have segregated their users into groups.They now want to ensure they set the right permissions for users and administrators accordingly.They need to manage the permissions effectively.You recommend using Azure Policies.Does this recommendation meet the requirement? Correct Incorrect
Incorrect Explanation:- Azure Policy is a service in Azure that you use to create, assign, and manage policies. These policies enforce different rules and effects over your resources, so those resources stay compliant with your corporate standards and service level agreements. Azure Policy meets this need by evaluating your resources for non-compliance with assigned policies. All data stored by Azure Policy is encrypted at rest.
An IT administrator for a company has been given a powershell script.This powershell script will be used to create several Virtual Machines in Azure.You have to provide a machine to the IT administrator for running the powershell script.You decide to provide a Linux machine which has the Azure CLI tools installed.Would this solution fit the requirement? Correct Incorrect
Incorrect Explanation:- Azure PowerShell is basically an extension of Windows PowerShell. It lets Windows PowerShell users control Azure's robust functionality. From the command line, Azure PowerShell programmers use preset scripts called cmdlets to perform complex tasks like provisioning virtual machines (VMs) or creating cloud services.For more information, please visit:https://docs.microsoft.com/en-us/powershell/azure/get-started-azureps?view=azps-3.1.0
A company wants to make use of a Microsoft Azure service in private preview.Are Azure services in private preview available to all customers? Incorrect Correct
Incorrect Explanation:- The private preview is only available to certain Azure customers for evaluation purposes. The public preview is available to all Azure customers. ... Azure features that have been successfully evaluated and tested will typically be released to customers as part of the generally available product integrated into Azure.
A company currently has the following unused resources as part of their subscription- 10 user accounts in Azure AD- 5 user groups in Azure AD- 10 public IP address- 10 network InterfacesThey want to reduce the costs for resources hosted in AzureThey decide to remove the network interfaces from Azure ADWould this fulfil the requirement? Incorrect Correct
Incorrect Explanation:- There is no price for network interfaces, so this would not help reduce the cost.
Which of the following category does Azure Kubernetes come under? Infrastructure as a service Platform as a service Software as a service Hardware as a service
Infrastructure as a service Explanation:- Azure Kubernetes comes under the "Infrastructure as a service" category.The Microsoft documentation mentions the following:
company has a VPN device that will be used as Site-to-Site connection from Microsoft Azure to their on-premise location.Which of the following would be used to represent the VPN device? Application Gateway DNS Zone Virtual Network gateway Local Network Gateway
Local Network Gateway
A company wants to host a set of tables in Azure. They want absolutely zero administration of the underlying infrastructure and low latency access to data. You recommend using the Azure App service. Would this suit the requirement? Yes No
No
A company wants to host a set of tables in Azure. They want absolutely zero administration of the underlying infrastructure and low latency access to data. You recommend using the SQL Database service Would this suit the requirement? Yes No
No
An IT administrator for a company has been given a powershell script. This powershell script will be used to create several Virtual Machines in Azure. You have to provide a machine to the IT administrator for running the powershell script. You decide to provide a Linux machine which has the Azure CLI tools installed. Would this solution fit the requirement? No Yes
No
A company wants to setup users in their Azure Account. They have segregated their users into groups. They now want to ensure they set the right permissions for users and administrators accordingly. They need to manage the permissions effectively. You recommend using Azure Management Groups. Does this recommendation meet the requirement? No Yes
No Explanation:- Azure management groups are used for organizing resources in Azure. The Microsoft documentation mentions the following on Azure management groups.For more information on Azure Management Groups, please visit the below URL https://docs.microsoft.com/en-us/azure/governance/management-groups/
A company wants to setup users in their Azure Account. They have segregated their users into groups. They now want to ensure they set the right permissions for users and administrators accordingly. They need to manage the permissions effectively. You recommend using Azure Policies. Does this recommendation meet the requirement? Yes No
No Explanation:- Azure policies are used from more of a governance aspect. The Microsoft documentation mentions these policies. For more information on Azure policies, please visit the below URL https://docs.microsoft.com/en-us/azure/governance/policy/overview
A company has a set of resources deployed to Azure. They want to make use of the Azure Advisor tool. Would the Azure Advisor tool give recommendations on how to improve the security of the Azure AD environment? No Yes
No Explanation:- The snapshot from the Microsoft documentation shows the interrelation between Azure Advisor and Azure Security Center. Azure Security can give you recommendations on how to secure your resources in Azure. Azure AD is already a secure platform. You should instead focus on how to secure sign-ins that occur using Azure AD. For more information on Azure AD security recommendations, please visit the below URL https://docs.microsoft.com/en-us/azure/advisor/advisor-security-recommendations
This question requires that you evaluate the underlined text to determine if it is correct. Azure Key Vault is used to store secrets for Azure Active Directory (Azure AD) user accounts.Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct. Azure Active Directory (Azure AD) administrative accounts No change is needed Personally Identifiable Information (PII) server applications
No change is needed
This question requires that you evaluate the underlined text to determine if it is correct. One of the benefits of Azure SQL Data Warehouse is that high availability is built into the platform. Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct. Automatic scaling Data compression No change is needed Versioning
No change is needed
This question requires that you evaluate the underlined text to determine if it is correct. You have an Azure virtual network named VNET1 in a resource group named RG1. You assign an Azure policy specifying that virtual networks are not an allowed resource type in RG1. VNET1 is deleted automatically. Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct. No change is needed is now a read-only object is moved automatically to another resource group continues to function normally
No change is needed
This question requires that you evaluate the underlined text to determine if it is correct. You have an application that is comprised of an Azure web app that has a Service Level Agreement (SLA) of 99.95 percent and an Azure SQL database that has an SLA of 99.99 percent.The composite SLA for the application is the product of both SLAs, which equals 99.94 percent. Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct. The highest SLA associated to the application, which is 99.99 percent No change is needed The lowest SLA associated to the application, which is 99.95 percent The difference between the two SLAs, which is 0.05 percent
No change is needed
You have an Azure environment that contains 10 virtual networks and 100 virtual machines. You need to limit the amount of inbound traffic to all the Azure virtual networks. What should you create? 10 Azure ExpressRoute circuits One Azure firewall One network security group (NSG) 10 virtual network gateways
One Azure firewall
A company is planning on moving some of their on-premise resources to Azure. They have to provide a business justification for moving to Azure. They have to classify expenses as part of the business justification. Which category would the following expense come under?"Cooling expenses" Operating Expenditure Capital Expenditure Secondary Expenditure Primary Expenditure
Operating Expenditure Explanation:- This expense comes under the operating expense category.The Microsoft documentation gives examples of operating expenses
What are the two ways you can get support if you are on a Standard support plan? Choose two. Whatsapp Phone call Email Skype message In Person Chat
Phone call Email
A company is planning on using the Azure Content Delivery Service. Which of the following is the right category to which the Azure Content Delivery service belongs to? Software as a service(SaaS) Function as a Service(FaaS) Infrastructure as a service (IaaS) Platform as a service (Paas)
Platform as a service (Paas)
Which of the following scenarios would Azure Policy be a recommended method for enforcement? Prevent certain Azure Virtual Machine instance types from being used in a resource group Allow only one specific roles of users to have access to a resource group Require a virtual machine to always update to the latest security patches Add an additional prompt when creating a resource without a specific tag to ask the user if they are really sure they want to continue?
Prevent certain Azure Virtual Machine instance types from being used in a resource group
What should you use to evaluate whether your company's Azure environment meets regulatory requirements? Compliance Manager from the Security Trust Portal The Advisor blade from the Azure portal The Security Center blade from the Azure portal The Knowledge Center website
The Security Center blade from the Azure portal
A company has just deployed a Virtual Machine named demovm to Azure. The overview of the Virtual Machine is shown below. The company needs to know if the underlying infrastructure in Azure hosting the Virtual Machine has any issues? Where could they view such issues? The Virtual Machine blad Azure AD Azure Monitor Azure Advisor
The Virtual Machine blad Explanation:- You can see for any service health issues for the infrastructure of the Virtual Machine in the VM blade itself. Just go to Resource health as shown below
This question requires that you evaluate the underlined text to determine if it is correct. If a resource group named RG1 has a delete lock, only a member of the global administrators group can delete RG1. Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct. The delete lock must be removed before an administrator An Azure tag must be added before an administrator No change is needed An Azure policy must be modified before an administrator
The delete lock must be removed before an administrator
What is a benefit of economies of scale? Big companies don't need to make a profit on the first product they sell you, because they will make a profit on the second The more you buy of something, the cheaper it is for you Big companies don't need to make a profit on every sale Prices of cloud servers and services are always going down. It'll be cheaper next year than it is this year.
The more you buy of something, the cheaper it is for you
Your organization has implemented an Azure Policy that restricts the type of Virtual Machine instances you can use. How can you create a VM that is blocked by policy? Use an account that has Contributor or above permissions to the resource group The only way is to remove the policy, create the resource and add the policy back Subscription Owners (Administrators) can create resources regardless of what the policy restricts
The only way is to remove the policy, create the resource and add the policy back
What is the concept of Availability? A system must have 100% uptime to be considered available A system that can scale up and scale down depending on customer demand A system that has a single point of failure The percentage of time a system responds properly to requests, expressed as a percentage over time
The percentage of time a system responds properly to requests, expressed as a percentage over time
A company is planning on migrating their public web site to Azure. Which of the following do they need to consider when it comes to hosting their public web site on Azure? They would need to reduce the number of connections to the web site They would need to pay for the user data transfer onto the site They would have to consider paying a monthly cost for the solution They would need to deploy a Virtual Private connection from their on-premise site to Azure
They would have to consider paying a monthly cost for the solution
Which of the following elements is considered part of the "perimeter" layer of security? Separate servers into distinct subnets by role Use a firewall Keep operating systems up to date with patches Locks on the data center doors
Use a firewall
A company is planning on hosting their resources in Azure. The senior management wants to know what the capital expenditure (CapEx) and operational expenditure (OpEx) that would be incurred when moving to Azure. Does Azure provide flexibility when it comes to capital expenditure (CapEx) and operational expenditure (OpEx)? No Yes
Yes
A company is planning on setting up an Azure account and spinning up resources in the purchased subscription. When it comes to the Service Level Agreement, does Microsoft ensure an SLA of 99.9% uptime for paid Azure services? Yes No
Yes
A company is planning on using their Azure Free Account for hosting production-based resources. Does the Azure Free Account allow you to host production-based resources? Yes No
Yes
An IT administrator for a company has been given a powershell script. This powershell script will be used to create several Virtual Machines in Azure. You have to provide a machine to the IT administrator for running the powershell script. You decide to provide a ChromeOS based machine and use Azure Cloud Shell. Would this solution fit the requirement? - Yes - No
Yes
A company has a virtual machine defined as demovm. This Virtual Machine was created with the standard settings. An application is installed on demovm. It now needs to be ensured that the application can be accessed over the Internet via HTTP. You make modifications to the Azure firewall Would this solution fit the requirement? Yes No
Yes Explanation:- To open a port in the Windows Firewall: Select the name of your virtual machine in the Microsoft Azure portal.Click the Connect button in the toolbar.A Remote Desktop Connection to the virtual machine is downloaded to your local directory.Open the Remote Desktop Connection with the username and password that you entered when you created the virtual machine.In the Server Manager, select the Local Server.In the Properties section, click the link next to the Windows Firewall property.
Why is Azure App Services considered Platform as a Service? Azure App Services is not PaaS, it's Software as a Service. You are responsible for keeping the operating system up to date with the latest patches You can decide on what type of virtual machine it runs - A-series, or D-series, or even H-series You give Azure the code and configuration, and you have no access to the underlying hardware
You give Azure the code and configuration, and you have no access to the underlying hardware
How do you get access to services in Private Preview mode? You must agree to a terms of use first. You must apply to use them. They are available in the marketplace. You simply use them. You cannot use private preview services.
You must apply to use them.
You have an Azure environment that contains multiple Azure virtual machines. You plan to implement a solution that enables the client computers on your on-premises network to communicate to the Azure virtual machines.You need to recommend which Azure resources must be created for the planned solution. Which two Azure resources should you include in the recommendation? Each correct answer presents part of the solution. a gateway subnet a load balancer a virtual network gateway an application gateway a virtual network
a gateway subnet a virtual network
Your company needs to deploy and manage several Azure Web apps using the Azure App service resource. Which of the following URL would you use to manage the Azure Web Apps? https://portal.azurewebsites.net https://portal.azurewebsites.com https://portal.microsoft.com https://portal.azure.com
https://portal.azure.com