Microsoft

AZ-104 Practice Test: 10 Original Questions

Ten administrator scenarios across the AZ-104 skill areas: identities and governance, storage, compute, virtual networking, and monitoring. Each asks for the option that meets the requirement with the least privilege or effort, and each answer links to the Microsoft Learn page it rests on.

These questions were written for CertBlaze from the official Microsoft Azure Administrator exam guide, with AI assistance. They are not taken from the real exam, an exam dump or any other question bank. Each answer names the official page it is based on; if you spot a mistake, please tell us.

What this set covers

  • Manage Azure identities and governance: 2 questions
  • Implement and manage storage: 3 questions
  • Deploy and manage Azure compute resources: 2 questions
  • Implement and manage virtual networking: 2 questions
  • Monitor and maintain Azure resources: 1 question

Question 1

Manage Azure identities and governance

A support team must be able to view and restart the virtual machines in resource group RG-App, but must not be able to delete them or change any other resources. You must follow the principle of least privilege. What should you do?

A. Assign the Contributor role at the RG-App scope.
B. Create a custom role with Microsoft.Compute/virtualMachines/read and Microsoft.Compute/virtualMachines/restart/action, and assign it at the RG-App scope.
C. Assign the Virtual Machine Contributor role at the subscription scope.
D. Assign the Reader role at the RG-App scope.
Show Answer
Correct Answer: B
Explanation:
A custom role lets you grant exactly the read and restart actions, and assigning it at the resource group limits it to RG-App. Contributor (A) can change and delete everything in the group. Virtual Machine Contributor (C) can delete VMs and the subscription scope is too broad. Reader (D) cannot restart anything.
Source: Azure custom roles (Microsoft Learn)

Question 2

Manage Azure identities and governance

Finance requires every new resource group in the subscription to have a CostCenter tag. Deployments without the tag must fail. What should you configure?

A. An Azure Policy assignment that requires the CostCenter tag on resource groups, with the deny effect
B. A CanNotDelete lock on the subscription
C. A custom RBAC role that includes Microsoft.Resources/tags/write
D. An Azure Advisor alert for untagged resources
Show Answer
Correct Answer: A
Explanation:
Azure Policy can require a tag and deny any resource group created without it; built-in policy definitions exist for this. A lock (B) does not inspect tags. An RBAC role (C) grants permissions but cannot require values. Advisor (D) does not block deployments.
Source: Assign policy definitions for tag compliance (Microsoft Learn)

Question 3

Implement and manage storage

An application must still be able to read data from a storage account if the primary region becomes unavailable, without waiting for anyone to start a failover. Which redundancy option should you choose?

A. Locally redundant storage (LRS)
B. Zone-redundant storage (ZRS)
C. Read-access geo-redundant storage (RA-GRS)
D. Geo-redundant storage (GRS)
Show Answer
Correct Answer: C
Explanation:
RA-GRS copies data to a secondary region and gives read access to that copy at all times, so reads continue while the primary is down. GRS (D) also replicates to a secondary region, but the secondary is readable only after a failover. LRS (A) and ZRS (B) keep all copies in the primary region.
Source: Azure Storage redundancy (Microsoft Learn)

Question 4

Implement and manage storage

An external partner must upload files to one blob container for the next 24 hours. You must not share the storage account keys or make the container public. What should you provide?

A. The storage account access key
B. The Storage Account Contributor role for the partner's account
C. Anonymous public access on the container
D. A shared access signature (SAS) scoped to the container with write and create permissions that expires in 24 hours
Show Answer
Correct Answer: D
Explanation:
A SAS grants limited, time-bound access to specific storage resources without exposing the account key. The account key (A) gives full control of the whole account. Public access (C) lets anyone read the container. Storage Account Contributor (B) manages the account itself and is far broader than uploading to one container.
Source: Grant limited access with shared access signatures (Microsoft Learn)

Question 5

Implement and manage storage

Blobs that have not been modified for 90 days should move to the Cool tier, and blobs older than 365 days should be deleted. You want the least administrative effort. What should you use?

A. A lifecycle management policy on the storage account
B. An Azure Automation runbook that runs every night
C. A scheduled AzCopy job on a virtual machine
D. Blob soft delete with a 365-day retention period
Show Answer
Correct Answer: A
Explanation:
Lifecycle management policies are rules on the storage account that tier and delete blobs by age, run by the platform with no code. A runbook (B) or AzCopy job (C) works but adds scripts and infrastructure to maintain. Soft delete (D) protects deleted blobs; it does not tier or delete anything.
Source: Azure Blob Storage lifecycle management overview (Microsoft Learn)

Question 6

Deploy and manage Azure compute resources

Two VMs run an application that must stay available if a whole datacenter in the region fails, with the highest VM availability SLA. How should you deploy them?

A. In an availability set with two fault domains
B. As one VM on Premium SSD storage plus one stopped standby VM
C. In two different availability zones
D. In a proximity placement group
Show Answer
Correct Answer: C
Explanation:
VMs in two or more availability zones are in separate datacenters and carry the highest VM SLA. An availability set (A) spreads VMs across racks inside one datacenter, so it does not survive a datacenter outage. A single running VM (B) is a single point of failure, and a proximity placement group (D) puts VMs closer together, not further apart.
Source: Availability options for Azure Virtual Machines (Microsoft Learn)

Question 7

Deploy and manage Azure compute resources

A web tier must add instances automatically when average CPU goes above 70% and remove them when the load drops. What should you deploy?

A. Virtual machines in an availability set
B. An Azure Load Balancer with health probes
C. A Virtual Machine Scale Set with an autoscale rule based on CPU
D. One larger VM size
Show Answer
Correct Answer: C
Explanation:
Virtual Machine Scale Sets can scale the number of instances in and out with autoscale rules on metrics such as CPU. An availability set (A) has a fixed number of VMs. A load balancer (B) spreads traffic but does not create instances. A bigger VM (D) is a manual scale-up.
Source: Overview of autoscale with Azure Virtual Machine Scale Sets (Microsoft Learn)

Question 8

Implement and manage virtual networking

VMs in the Web subnet must accept HTTPS from the internet, and RDP from the internet must be blocked. The VMs have public IP addresses. What is the simplest configuration?

A. Associate a network security group with the Web subnet that has an inbound rule allowing TCP 443 from Internet and no rule allowing TCP 3389.
B. Create a user-defined route that sends port 3389 to None.
C. Enable Azure DDoS Protection on the virtual network.
D. Add a service endpoint for Microsoft.Web to the subnet.
Show Answer
Correct Answer: A
Explanation:
A network security group filters traffic by rules; allowing 443 from the Internet service tag lets HTTPS in, and the default DenyAllInbound rule blocks RDP because nothing allows it. Route tables (B) route by destination prefix, not by port. DDoS Protection (C) mitigates attacks but does not filter RDP. Service endpoints (D) secure access to Azure services, not inbound traffic.
Source: Network security groups (Microsoft Learn)

Question 9

Implement and manage virtual networking

VNet1 in West Europe and VNet2 in East US must communicate over private IP addresses with low latency. You want no gateways to deploy or manage. What should you configure?

A. Global virtual network peering between VNet1 and VNet2
B. A site-to-site VPN between two VPN gateways
C. An ExpressRoute circuit
D. Service endpoints on both virtual networks
Show Answer
Correct Answer: A
Explanation:
Global VNet peering connects virtual networks in different regions over the Microsoft backbone using private IPs, with no gateways. A VPN (B) needs gateways and adds encryption overhead. ExpressRoute (C) connects on-premises networks to Azure. Service endpoints (D) connect a subnet to Azure PaaS services, not to another VNet.
Source: Virtual network peering (Microsoft Learn)

Question 10

Monitor and maintain Azure resources

You want an email when the CPU of a production VM stays above 85% for 15 minutes. What should you create?

A. A Log Analytics workspace with no alert
B. An Azure Advisor recommendation digest
C. An activity log alert on the VM
D. An Azure Monitor metric alert rule on Percentage CPU with an action group that sends email
Show Answer
Correct Answer: D
Explanation:
A metric alert evaluates a platform metric such as Percentage CPU over a time window and calls an action group, which sends the email. A workspace alone (A) stores data but alerts nobody. Activity log alerts (C) fire on control-plane events such as a VM being stopped, not on metric values. Advisor digests (B) summarize recommendations.
Source: Types of Azure Monitor alerts (Microsoft Learn)