Mall Academy AZ-104 Azure Administrator Practice Exam #4 Flashcards
Conditional access is a feature of Azure AD which allows administrators to control access to cloud applications through additional checks such as user location, the device the user is accessing the cloud app from, and more.
A. True
B. False
A. True
Explanation:
Conditional access is a feature of Azure AD which allows administrators to control access to cloud applications through additional checks such as user location, the device the user is accessing the cloud app from, and more.
A resource group template is a JSON file that allows you to declaratively describe a set of resources. These resources can then be added to a new or existing resource group. For example, a template can contain the configuration necessary to create two API App instances, a Mobile App instance, and a Document DB instance.
A. True
B. False
A. True
Explanation:
A resource group template is a JSON file that allows you to declaratively describe a set of resources. These resources can then be added to a new or existing resource group. For example, a template can contain the configuration necessary to create two API App instances, a Mobile App instance, and a Document DB instance.
Alternatively, virtual networks can be connected using a VNet-to-VNet VPN connection.
A. False
B. True
B. True
Explanation:
Alternatively, virtual networks can be connected using a VNet-to-VNet VPN connection.
You have the Azure virtual machines shown in the following table.
You have a Recovery Services vault that protects VM1 and VM2.
You need to protect VM3 and VM4 by using Recovery Services.
What should you do first?
A. Create a new backup policy
B. Create a storage account
C. Create a new Recovery Services vault
D. Configure the extensions for VM3 and VM4
C. Create a new Recovery Services vault
Explanation:
A Recovery Services vault is a storage entity in Azure that houses data.
The data is typically copies of data, or configuration information for virtual machines(VMs), workloads, servers, or workstations.
You can use Recovery Services vaults to hold backup data for various Azure Services.
References: https://docs.microsoft.com/en-us/azure/site-recovery/azure-to-azure-tutorial-enable-replication
Downstream Windows clients can be managed through Azure AD using Azure AD hybrid join.
A. False
B. True
B. True
Explanation:
Downstream Windows clients can be managed through Azure AD using Azure AD hybrid join.
You have an Azure subscription named Subscription1.
You have 5 TB of data that you need to transfer to Subscription1.
You plan to use an Azure Import/Export job.
What can you use as the destination of the imported data?
A. The Azure File Sync Storage Sync Service
B. Azure Data Lake Store
C. Azure Blob Storage
D. A virtual machine
C. Azure Blob Storage
Explanation:
Azure Import/Export service is used to securely import large amounts of data to Azure Blob storage and Azure Files by shipping disk drives to an Azure datacenter.
The maximum size of an Azure Files Resource of a file share is 5 TB.
Reference: https://docs.microsoft.com/en-us/azure/storage/common/storage-import-export-service
Storage accounts must specify a replication mode. The options are locally redundant,
zone-redundant, geo-redundant, read-access geo-redundant storage, geo zoneredundant,
and read-access geo zone-redundant.
A. FALSE
B. True
B. True
Explanation:
Storage accounts must specify a replication mode. The options are locally redundant,
zone-redundant, geo-redundant, read-access geo-redundant storage, geo zoneredundant,
and read-access geo zone-redundant.
A template allows you to configure multiple resources simultaneously and use variables/parameters/functions to create dependencies between resources.
A. False
B. True
A. True
Explanation:
A template allows you to configure multiple resources simultaneously and use variables/parameters/functions to create dependencies between resources.
Azure Log Analytics can consolidate machine data from on-premises and cloud-based workloads and this data is indexed and categorized for quick searching. Data can be collected only from Windows machines.
A. False
B. True
A. False
Explanation:
Azure Log Analytics can consolidate machine data from on-premises and cloud-based workloads and this data is indexed and categorized for quick searching. Data can be collected from both Windows and Linux machines.
Both global VNet peering and VNet-to-VNet VPN connections route traffic between Azure regions , not _____________________.
A. over private networks
B. over the public internet
C. over the Microsoft backbone network
B. over the public internet
Explanation:
Both global VNet peering and VNet-to-VNet VPN connections route traffic between Azure regions over the Microsoft backbone network, not the public Internet.
Azure AD supports hybrid identity scenarios with _________________.
A. Azure AD Identity Protection
B. Azure Express Route
C. Azure AD Connect
C. Azure AD Connect
Explanation:
Azure AD supports hybrid identity scenarios with Azure AD Connect.
Self-service password reset can be combined with the password writeback features of Azure AD Connect to allow users to reset their passwords from the cloud while adhering to on-premises password standards.
A. FALSE
B. TRUE
B. TRUE
Explanation:
Self-service password reset can be combined with the password writeback features of Azure AD Connect to allow users to reset their passwords from the cloud while adhering to on-premises password standards.
DNS zones in Azure DNS must be delegated from the parent domain. This is achieved
by setting up appropriate NS records in the parent domain, pointing to the name
servers assigned by Azure DNS.
A. False
B. True
B. True
Explanation:
DNS zones in Azure DNS must be delegated from the parent domain. This is achieved
by setting up appropriate NS records in the parent domain, pointing to the name
servers assigned by Azure DNS.
ExpressRoute provides Microsoft Peering (connectivity to Azure PaaS endpoints, and other Microsoft services) or Private Peering (connectivity to Azure virtual networks). The former uses Internet address and the latter uses Intranet addresses. Azure Public Peering, for Azure PaaS services only, is deprecated for new ExpressRoute circuits.
A. False
B. True
B. True
Explanation:
ExpressRoute provides Microsoft Peering (connectivity to Azure PaaS endpoints, and other Microsoft services) or Private Peering (connectivity to Azure virtual networks). The former uses Internet address and the latter uses Intranet addresses. Azure Public Peering, for Azure PaaS services only, is deprecated for new ExpressRoute circuits.
To achieve a VPN connection or enable MFA we should set up appropriate NS records in the parent domain, pointing to the name servers assigned by Azure DNS.
A. True
B. False
B. False
Explanation:
If it’s to achieve a VPN connection or enable MFA, then this is False. But if it’s to enable a custom domain to be used by Azure DNS, its True.
A template can simplify orchestration because you only need to deploy the template to deploy all of your resources.
A. False
B. True
B. True
Explanation:
A template can simplify orchestration because you only need to deploy the template to deploy all of your resources.
ExpressRoute circuits provide different levels of bandwidth, from 50Mbps to 10Gbps. They don’t provide redundant connections.
A. False
B. True
A. False
Explanation:
ExpressRoute circuits provide different levels of bandwidth, from 50Mbps to 10Gbps. They also provide redundant connections.
Blob storage supports …… types of blobs, and …… access tiers.
A. 1
B. 3
C. 4
D. 2
B. 3
Explanation:
Blob storage supports three types of blobs (block, page and append blobs), and three access tiers (hot, cool, and archive).
Each network security group includes a list of default rules, which can be overridden using user-defined rules. Rules are applied in priority order (processing stops at the first rule matching the traffic in question).
A. True
B. False
A. True
Explanation:
Each Network Security Groups includes a list of default rules, which can be overridden using user-defined rules. Rules are applied in priority order (processing stops at the first rule matching the traffic in question).
A VPN gateway can be shared by peered VNets. The peering connections must enable the settings to Use Remote Gateway (on the peering towards the gateway) and Allow Gateway Transit (on the peering from the gateway).
A. True
B. False
A. True
Explanation:
A VPN gateway can be shared by peered VNets. The peering connections must enable the settings to Use Remote Gateway (on the peering towards the gateway) and Allow Gateway Transit (on the peering from the gateway).
Many advanced features of Azure AD require Azure AD Premium P1 or Azure AD Premium P2 licenses. When considering Azure AD features, administrators need to be aware of the licensing boundaries.
A. True
B. False
A. True
Explanation:
Many advanced features of Azure AD require Azure AD Premium P1 or Azure AD Premium P2 licenses. When considering Azure AD features, administrators need to be aware of the licensing boundaries.
Using VNet peering to provide access to a central VNet containing shared services, such as Active Directory domain controllers, is known as _________________.
A. Service Queue
B. Service Chaining
C. Service Hub
D. Service List
B. Service Chaining
Explanation:
Using VNet peering to provide access to a central VNet containing shared services, such as Active Directory domain controllers, is known as service chaining.
Windows 10 can be added to Azure AD as a device to be managed, enabling BYOD or corporate cloud only deployments with Azure AD Join.
A. True
B. False
A. True
Explanation:
Windows 10 can be added to Azure AD as a device to be managed, enabling BYOD or corporate cloud only deployments with Azure AD Join.
The Premium tier
A. Magnetic Disks and Supports all services
B. Solid state disks and is only used for unmanaged VM disks
B. Solid state disks and is only used for unmanaged VM disks
Explanation:
The Standard performance tier uses magnetic disks and supports all services. The Premium tier uses solid-state disks and is only used for unmanaged VM disks.