Download the latest AZ-104 dumps and ensure a 100 pass rate

Journey into the vast realms of certification, fortified by the academic lighthouse that is the AZ-104 dumps. As diverse as the constellation in the night sky, the AZ-104 dumps bring forth an illustrious set of practice questions, guiding your path through the celestial knowledge maze. Whether the mesmerizing tales from PDFs pull you into their orbit, or the VCE format\’s dynamic simulations transport you to another galaxy, the AZ-104 dumps promise a cosmic experience. A celestial guide, the AZ-104 dumps decode nebulous concepts, ensuring you sail smoothly through the astral challenges. With stars in our eyes, we proudly proclaim our 100% Pass Guarantee.

[Just In] Propel your success with the free AZ-104 PDF and Exam Questions, guaranteeing a 100% pass rate

Question 1:

HOTSPOT

You create an Azure file sync group named Sync 1 and perform the following actions:

1.

Add share as the cloud endpoint for Sync1.

2.

Add data1 as a server endpoint for Sync1.

3.

Register Server1 and Server2 to Sync1.

For each of the following statements, select Yes if the statement is true Otherwise, select No. NOTE Each correct selection is worth one point.

Hot Area:

Correct Answer:


Question 2:

You have an Azure subscription that contains a storage account named account1.

You plan to upload the disk files of a virtual machine to account1 from your on-premises network. The on-premises network uses a public IP address space of 131.107.1.0/24.

You plan to use the disk files to provision an Azure virtual machine named VM1. VM1 will be attached to a virtual network named VNet1. VNet1 uses an IP address space of 192.168.0.0/24.

You need to configure account1 to meet the following requirements:

1.

Ensure that you can upload the disk files to account1.

2.

Ensure that you can attach the disks to VM1.

3.

Prevent all other access to account1.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A. From the Firewalls and virtual networks blade of account1, add the 131.107.1.0/24 IP address range.

B. From the Firewalls and virtual networks blade of account1, select Selected networks.

C. From the Firewalls and virtual networks blade of acount1, add VNet1.

D. From the Firewalls and virtual networks blade of account1, select Allow trusted Microsoft services to access this storage account.

E. From the Service endpoints blade of VNet1, add a service endpoint.

Correct Answer: AB

By default, storage accounts accept connections from clients on any network. To limit access to selected networks, you must first change the default action. Azure portal

1.

Navigate to the storage account you want to secure.

2.

Click on the settings menu called Firewalls and virtual networks.

3.

To deny access by default, choose to allow access from \’Selected networks\’. To allow traffic from all networks, choose to allow access from \’All networks\’.

4.

Click Save to apply your changes.

Grant access from a Virtual Network

Storage accounts can be configured to allow access only from specific Azure Virtual Networks. By enabling a Service Endpoint for Azure Storage within the Virtual Network, traffic is ensured an optimal route to the Azure Storage service. The

identities of the virtual network and the subnet are also transmitted with each request.

Reference:

https://docs.microsoft.com/en-us/azure/storage/common/storage-network-security


Question 3:

HOTSPOT

You have an Azure subscription that contains an Azure Storage account.

You plan to copy an on-premises virtual machine image to a container named vmimages.

You need to create the container for the planned image.

Which command should you run? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

Correct Answer:

Box 1: make

Here the purpose is to \’create a container”. So the correct command would be azcopy make.

Box 2: blob

The requirement is for storing that image, it\’s not used to build AKS. So blob is correct option.

Reference:

https://adamtheautomator.com/azcopy-copy-files/


Question 4:

You have an Active Directory forest named contoso.com.

You install and configure Azure AD Connect to use password hash synchronization as the single sign-on (SSO) method. Staging mode is enabled.

You review the synchronization results and discover that the Synchronization Service Manager does not display any sync jobs.

You need to ensure that the synchronization completes successfully.

What should you do?

A. From Synchronization Service Manager, run a full import.

B. Run Azure AD Connect and set the SSO method to Pass-through Authentication.

C. From Azure PowerShell, run Start-AdSyncSyncCycle -PolicyType Initial.

D. Run Azure AD Connect and disable staging mode.

Correct Answer: D

Staging mode must be disabled. If the Azure AD Connect server is in staging mode, password hash synchronization is temporarily disabled.

References:

https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnectsync- troubleshoot-password-hash-synchronization#no-passwords-are-synchronized-troubleshoot-by- using-the-troubleshooting-task


Question 5:

You have an Azure subscription that contains the resources shown in the following table.

You need to assign Workspace1 a role to allow read, write, and delete operations for the data stored in the containers of storage1. Which role should you assign?

A. Storage Account Contributor

B. Contributor

C. Storage Blob Data Contributor

D. Reader and Data Access

Correct Answer: C

Storage Blob Data Contributor Read, write, and delete Azure Storage containers and blobs. https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#storage-blob-data-contributor


Question 6:

HOTSPOT

You have an Azure web app named App1 that has two deployment slots named Production and Staging. Each slot has the unique settings shown in the following table.

You perform a slot swap.

What are the configurations of the Production slot after the swap? To answer, select the appropriate options in the answer area.

NOTE: Each correction is worth one point.

Hot Area:

Correct Answer:

Which settings are swapped? When you clone configuration from another deployment slot, the cloned configuration is editable. Some configuration elements follow the content across a swap (not slot specific), whereas other configuration elements stay in the same slot after a swap (slot specific). The following lists show the settings that change when you swap slots. Box 1 : On Settings that are swapped: General settings, such as framework version, 32/64-bit, web sockets App settings (can be configured to stick to a slot) Connection strings (can be configured to stick to a slot) Handler mappings Public certificates WebJobs content Hybrid connections * Virtual network integration * Service endpoints * Azure Content Delivery Network * Features marked with an asterisk (*) are planned to be unswapped. So web sockets settings will be swapped. So Production will have web sockets settings from “Off” to “On” after the swap slot. Box 2: App1-prod.contoso.com Settings that aren\’t swapped: Publishing endpoints Custom domain names Non-public certificates and TLS/SSL settings Scale settings WebJobs schedulers IP restrictions Always On Diagnostic settings Cross-origin resource sharing (CORS) So Custom domain names will not be swapped. So Production will have Custom domain names of its own after the swap slot.

Reference: https://docs.microsoft.com/en-us/azure/app-service/deploy-staging-slots#what-happens-during-a- swap


Question 7:

Your on-premises network contains a VPN gateway.

You have an Azure subscription that contains the resources shown in the following table.

You need to ensure that all the traffic from VM1 to storage1 travels across the Microsoft backbone network. What should you configure?

A. Azure AD Application Proxy

B. service endpoints

C. a network security group (NSG)

D. Azure Firewall

Correct Answer: B


Question 8:

Your company deploys several virtual machines on-premises and to Azure. ExpressRoute is being deployed and configured for on-premises to Azure connectivity. Several virtual machines exhibit network connectivity issues. You need to

analyze the network traffic to identify whether packets are being allowed or denied to the virtual machines.

Solution: Use Azure Traffic Analytics in Azure Network Watcher to analyze the network traffic.

Does this meet the goal?

A. Yes

B. No

Correct Answer: B

Reference: https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-ip-flow-verify-overview


Question 9:

HOTSPOT

You manage two Azure subscriptions named Subscription1 and Subscription2. Subscription1 has the following virtual networks:

The virtual networks contain the following subnets:

Subscription2 contains the following virtual network:

*

Name: VNETA

*

Address space: 10.10.128.0/17

*

Location: Canada Central VNETA contains the following subnets:

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Hot Area:

Correct Answer:

Box 1: Yes

With VNet-to-VNet you can connect Virtual Networks in Azure across Different regions.

Box 2: Yes

Azure supports the following types of peering:

1.

Virtual network peering: Connect virtual networks within the same Azure region.

2.

Global virtual network peering: Connecting virtual networks across Azure regions.

Box 3: Yes

References: https://azure.microsoft.com/en-us/blog/vnet-to-vnet-connecting-virtual-networks-in-azure-across-different-regions/ https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-manage-peering#requirements-and-constraints


Question 10:

You have an Azure DNS zone named adatum.com. You need to delegate a subdomain named research.adatum.com to a different DNS server in Azure. What should you do?

A. Create an PTR record named research in the adatum.com zone.

B. Create an NS record named research in the adatum.com zone.

C. Modify the SOA record of adatum.com.

D. Create an A record named “.research in the adatum.com zone.

Correct Answer: B

You need to create a name server (NS) record for the zone. References: https://docs.microsoft.com/en-us/azure/dns/delegate-subdomain


Question 11:

You have an Azure virtual machine named VM1.

The network interface for VM1 is configured as shown in the exhibit. (Click the Exhibit tab.)

You deploy a web server on VM1, and then created a secure website that is accessible by using the HTTPS protocol. VM1 is used as a web server only.

You need to ensure that users can connect to the website from the internet.

What should you do?

A. Modify the action of Rule1.

B. Change the priority of Rule6 to 100.

C. For Rule4, change the protocol from UDP to Any.

D. For Rule5, change the Action to Allow and change the priority to 401.

Correct Answer: D


Question 12:

HOTSPOT

You have an Azure subscription.

You deploy a virtual machine scale set that is configure as shown in the following exhibit.

Use the drop-down menus to select the answer choice that answers each questions based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Hot Area:

Correct Answer:


Question 13:

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while

others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You deploy an Azure Kubernetes Service (AKS) cluster named AKS1.

You need to deploy a YAML file to AKS1.

Solution: From Azure Cloud Shell, you run az aks.

Does this meet the goal?

A. Yes

B. No

Correct Answer: B

Reference: https://docs.microsoft.com/en-us/azure/aks/kubernetes-walkthrough


Question 14:

DRAG DROP

You have an availability set named AS1 that contains three virtual machines named VM1, VM2, and VM3.

You attempt to reconfigure VM1 to use a larger size. The operation fails and you receive an allocation failure message.

You need to ensure that the resize operation succeeds. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Select and Place:

Correct Answer:

Action 1: Stop VM1, VM2 and VM3 If the VM you wish to resize is part of an availability set, then you must stop all VMs in the availability set before changing the size of any VM in the availability set. The reason all VMs in the availability set must be stopped before performing the resize operation to a size that requires different hardware is that all running VMs in the availability set must be using the same physical hardware cluster. Therefore, if a change of physical hardware cluster is required to change the VM size then all VMs must be first stopped and then restarted one-by-one to a different physical hardware clusters. Action 2: Resize VM1 Action 3: Start VM1, VM2, and VM3

References: https://azure.microsoft.com/es-es/blog/resize-virtual-machines/


Question 15:

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while

others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You are the global administrator for an Azure Active Directory (Azure AD) tenant that has several subscriptions.

You need to create a report that lists all the resources for the tenant.

Solution: You run the New-AzureADUserAppRoleAssignment Windows PowerShell cmdlet.

Does this meet the goal?

A. Yes

B. No

Correct Answer: A

The New-AzureADUserAppRoleAssignment cmdlet assigns a user to an application role in Azure Active Directory (AD). Use it for the application report.

Reference:

https://docs.microsoft.com/en-us/powershell/module/azuread/new-azureaduserapproleassignment? view=azureadps-2.0