Microsoft AZ-104 Practice Test 1

AZ-104 Practice Test 1

Microsoft Azure Administrator AZ-104 practice test

1 / 80

Your organization has the following Azure hierarchy:

  • Management group: Corp
    • Subscription: Production
      • Resource group: RG-App
        • VM: VM01
  • Subscription: Development

An administrator must be able to start, stop, and restart virtual machines in Production, but must not be able to:

  • Modify VM configuration
  • Delete VMs
  • Access resources in Development
  • Manage resources other than VMs

You want to use a built-in Azure role and assign it at the highest possible scope while satisfying the requirements.

Which action should you take?

2 / 80

Which Azure Active Directory (Microsoft Entra ID) object type represents a non-human identity used by an application to authenticate and access resources?

3 / 80

Which Azure RBAC role grants full access to manage all resources within a scope, but does NOT allow granting access to others?

4 / 80

Which Azure RBAC role allows a user to manage access to Azure resources, without granting the ability to manage the resources themselves?

5 / 80

Which Azure governance feature allows an organization to enforce rules across resources, such as requiring all storage accounts to use encryption, and can audit or deny non-compliant resources?

6 / 80

Which Azure governance feature allows resources to be organized under a hierarchy above the subscription level, enabling consistent policy and RBAC assignment across multiple subscriptions?

7 / 80

An administrator wants to prevent a critical production resource from being accidentally deleted, even by users who have Contributor access. Which feature should be used?

8 / 80

Which type of resource lock prevents any configuration changes to a resource, while still allowing it to be deleted?

9 / 80

Which Azure feature allows an administrator to apply metadata, such as 'Environment: Production' or 'CostCenter: 1234', to resources for organization and cost tracking purposes?

10 / 80

Which Microsoft Entra ID feature requires a user to provide a second form of verification, such as a code from an authenticator app, in addition to their password?

11 / 80

Which Microsoft Entra ID feature allows an administrator to require MFA only when a sign-in is deemed risky, based on signals such as an unfamiliar location?

12 / 80

Which Microsoft Entra ID capability allows an administrator to provide just-in-time, time-bound access to a privileged role, such as Global Administrator, rather than a standing assignment?

13 / 80

An administrator needs to create hundreds of new user accounts in Microsoft Entra ID at once, based on a spreadsheet of employee data. Which approach is most efficient?

14 / 80

Which Microsoft Entra ID group membership type automatically adds or removes members based on defined rules, such as all users in a specific department?

15 / 80

Which Azure feature allows a company to delegate administrative permissions over a specific subset of users, such as those in a particular regional office, without granting tenant-wide administrative access?

16 / 80

Which Azure cost management feature allows an administrator to set a spending threshold and receive an alert when actual or forecasted spending approaches or exceeds that threshold?

17 / 80

Which Azure Cost Management tool provides recommendations for reducing costs, such as identifying underutilized virtual machines that could be resized or shut down?

18 / 80

Which Azure subscription-level concept determines the billing boundary and acts as a container for resource groups and resources?

19 / 80

Which Azure RBAC concept determines the level, such as management group, subscription, resource group, or individual resource, at which a role assignment applies?

20 / 80

An administrator wants to grant a contractor temporary access to a specific resource group for 30 days, with access automatically expiring afterward. Which Azure Entra ID feature is most appropriate?

21 / 80

Which term describes the recommended security practice of granting a user only the minimum level of Azure RBAC permissions necessary to perform their specific job function?

22 / 80

Which Azure Storage account replication option provides the lowest cost, replicating data three times within a single data center in the primary region?

23 / 80

Which Azure Blob Storage access tier offers the lowest storage cost but the highest cost and latency for retrieving data, suited for compliance archives rarely accessed?

24 / 80

An administrator wants to move an infrequently accessed blob from the Hot tier to a lower-cost tier automatically after 30 days without access, and to the Archive tier after 90 days. Which feature should be used?

25 / 80

Which Azure Storage security feature generates a time-limited, permission-scoped URL that grants temporary access to a specific blob or container without sharing the storage account key?

26 / 80

Which Azure Storage feature protects blobs and containers from accidental deletion by retaining deleted items for a configurable retention period, allowing recovery?

27 / 80

Which Azure Storage feature prevents blob data from being modified or deleted for a specified period, or indefinitely, supporting regulatory compliance (WORM) requirements?

28 / 80

An organization needs a storage account that must remain accessible for read operations even if the primary Azure region experiences a complete outage. Which replication option is most appropriate?

29 / 80

Which Azure Files feature allows a managed file share to be mounted using the standard SMB protocol on both Windows and Linux clients, similar to an on-premises file server?

30 / 80

Which Azure Storage networking feature allows a storage account to be accessed privately from within a virtual network, using a private IP address rather than traversing the public internet?

31 / 80

An administrator needs to copy a large volume of on-premises data (many terabytes) to Azure Blob Storage, but the organization's internet bandwidth would make an online transfer take several weeks. Which Azure service is most appropriate?

32 / 80

Which Azure Files feature allows an on-premises Windows Server to cache frequently accessed files locally while the full file set is stored in an Azure file share, synchronizing changes in both directions?

33 / 80

Which Azure Storage account setting, when enabled, would prevent any public (anonymous) read access to blob data, even if an individual container's access level is configured to allow it?

34 / 80

An administrator wants to regenerate a storage account's access keys without causing downtime for applications currently using the account. Which practice supports this?

35 / 80

Which Azure Blob Storage capability allows an application to read and write to specific byte ranges within very large files, supporting scenarios like streaming video?

36 / 80

Which Azure resource defines the compute size, such as vCPU count and memory, available to a virtual machine, such as Standard_D2s_v5?

37 / 80

Which Azure feature groups two or more virtual machines to protect against a single hardware failure or planned maintenance event within a data center, by spreading them across different fault and update domains?

38 / 80

Which Azure feature provides resilience against an entire data center outage within a region, by allowing resources to be deployed across physically separate facilities within that region?

39 / 80

Which Azure feature automatically increases or decreases the number of virtual machine instances in a group based on demand, such as CPU utilization?

40 / 80

Which Azure VM disk type provides the operating system files for a virtual machine and is automatically deleted when certain deallocation actions are taken, unless configured otherwise?

41 / 80

Which Azure VM disk type provides high-performance, non-persistent local storage that is lost when the VM is stopped/deallocated or moved to different host hardware?

42 / 80

Which Azure feature allows an administrator to install and configure additional software or run custom scripts on a VM automatically after deployment, such as installing a monitoring agent?

43 / 80

Which Azure App Service feature allows an administrator to test a new version of a web application in a separate environment before swapping it into production with zero downtime?

44 / 80

Which Azure App Service feature defines the underlying compute resources (such as pricing tier and scale) shared by one or more web apps?

45 / 80

Which Azure container service is most appropriate for running a single, simple containerized task without needing to manage an orchestrator or cluster?

46 / 80

Which Azure resource deployment approach uses a declarative JSON (or Bicep) file to define the desired state of infrastructure, allowing consistent, repeatable deployments?

47 / 80

Which ARM template concept allows the same template to be reused with different values, such as a VM size or region, without modifying the template itself?

48 / 80

Which ARM template concept explicitly defines that one resource must be created before another, such as a virtual network needing to exist before a VM's network interface can be created?

49 / 80

An administrator wants to redeploy the same ARM template repeatedly, with the deployment automatically creating any missing resources and updating any that have changed, without duplicating existing correctly configured resources. Which deployment characteristic supports this?

50 / 80

Which Azure Kubernetes Service (AKS) concept represents a group of underlying virtual machines that run containerized application workloads?

51 / 80

Which Azure service allows a developer to run individual pieces of code in response to an event, such as an HTTP request or a message arriving in a queue, without provisioning or managing servers?

52 / 80

Which Azure App Service hosting plan tier is specifically designed to allow multiple apps from different customers to run in complete isolation on dedicated infrastructure?

53 / 80

An administrator needs to move a running virtual machine to a different Azure region. Which general approach is required, since VMs cannot be directly moved across regions?

54 / 80

Which Azure VM feature allows an administrator to capture a reusable template of a configured VM, including its OS and installed applications, for quickly deploying multiple identical VMs?

55 / 80

Which Azure Virtual Machine pricing option allows a customer to bid on unused Azure compute capacity at a significant discount, with the trade-off that the VM can be evicted with little notice when Azure needs the capacity back?

56 / 80

Which Azure networking resource filters inbound and outbound traffic to and from resources within a subnet or on a specific network interface, based on rules for source, destination, port, and protocol?

57 / 80

Which Azure networking feature allows two virtual networks, even in different regions, to communicate directly using private IP addresses, without traffic passing over the public internet?

58 / 80

Which Azure networking resource distributes incoming network traffic across multiple virtual machines to improve availability and performance, operating at the transport layer (Layer 4)?

59 / 80

Which Azure networking resource operates at the application layer (Layer 7) and can make routing decisions based on URL path, in addition to providing web application firewall (WAF) capabilities?

60 / 80

Which Azure networking resource establishes an encrypted, site-to-site connection between an on-premises network and an Azure virtual network over the public internet?

61 / 80

Which Azure networking service provides a dedicated, private connection between an on-premises network and Azure, bypassing the public internet entirely for improved reliability and lower latency?

62 / 80

Which Azure DNS record type maps a domain name directly to an IPv4 address?

63 / 80

Which Azure DNS record type maps a domain name to another domain name, commonly used to point a custom subdomain to an Azure service's default domain name?

64 / 80

Which Azure networking resource allows an administrator to override the default system routes within a virtual network, such as directing traffic through a network virtual appliance for inspection?

65 / 80

Which Azure networking resource provides a fully managed, cloud-native network security service that centrally filters traffic across multiple virtual networks and subscriptions, using threat intelligence?

66 / 80

An administrator has two NSG rules with the same priority number applying to the same traffic. What happens in this scenario?

67 / 80

Which NSG rule characteristic determines that, when multiple rules could apply to the same traffic, the rule with the lowest priority number takes precedence?

68 / 80

An administrator wants to test whether a specific NSG rule is blocking traffic to a VM, without changing the actual rule configuration. Which Azure tool is most appropriate?

69 / 80

Which Azure Network Watcher tool visually traces the actual path network traffic takes between a source and destination, helping diagnose routing or connectivity issues across multiple hops?

70 / 80

Which Azure service collects and analyzes telemetry, such as metrics and logs, from Azure resources, on-premises environments, and applications, providing a unified monitoring platform?

71 / 80

Which Azure Monitor data store is optimized for storing and querying structured and unstructured log data, using the Kusto Query Language (KQL)?

72 / 80

Which Azure Monitor component defines the specific condition, such as CPU usage exceeding 90% for 5 minutes, that should trigger a notification or automated action?

73 / 80

Which Azure Monitor component defines the specific notification or automated response, such as sending an email or triggering an Azure Function, that occurs when an alert rule's condition is met?

74 / 80

Which Azure service backs up virtual machines, databases, and files, allowing an administrator to restore them in the event of accidental deletion, corruption, or a ransomware attack?

75 / 80

Which Azure service replicates virtual machines to a secondary region, enabling failover and business continuity in the event of a regional disaster, distinct from routine data backup?

76 / 80

Which Azure service allows an administrator to schedule and manage the deployment of operating system updates across multiple Azure and on-premises (via Arc) virtual machines?

77 / 80

Which Azure Monitor visualization tool allows an administrator to combine multiple queries, text, and visualizations into a single, interactive, shareable report?

78 / 80

Which Azure service provides current information about the health of the Azure platform itself, such as ongoing outages or planned maintenance affecting specific services and regions?

79 / 80

An administrator notices a virtual machine's CPU has been consistently near 100% for the past week, and wants a proactive recommendation on whether to resize it. Which Azure service is most appropriate?

80 / 80

Which Azure Monitor concept represents a lightweight, numeric time-series data point, such as CPU percentage sampled every minute, distinct from richer log data?

Your score is

The average score is 95%

0%