HOTSPOT
-
You have an Azure AD tenant.
You need to modify the Default user role permissions settings for the tenant. The solution must meet the following requirements:
• Standard users must be prevented from creating new service principals.
• Standard users must only be able to use PowerShell or Microsoft Graph to manage their own Azure resources.
Which two settings should you modify? To answer, select the appropriate settings in the answer area.
NOTE: Each correct answer is worth one point.
Show Answer
Correct Answer: Users can register applications → Set to No
Restrict access to Azure AD administration portal → Set to Yes
Explanation: Disabling application registration prevents standard users from creating app registrations and service principals. Restricting access to the Azure AD administration portal ensures standard users cannot manage resources through the portal and must use PowerShell or Microsoft Graph for permitted, scoped operations.
Question 120
You have an Azure subscription that contains the resources shown in the following table.
You need to assign Workspace1 a role to allow read, write, and delete operations for the data stored in the containers of storage1.
Which role should you assign?
A. Storage Account Contributor
B. Contributor
C. Storage Blob Data Contributor
D. Reader and Data Access
Show Answer
Correct Answer: C
Explanation: The requirement is to allow read, write, and delete operations on the data stored within blob containers, not to manage the storage account itself. The **Storage Blob Data Contributor** role grants data-plane permissions to read, write, and delete blob containers and blobs without granting broader management access. Other roles are either too broad (Contributor, Storage Account Contributor) or do not allow write/delete (Reader and Data Access).
Question 122
HOTSPOT
-
You have an Azure subscription that contains a storage account named storage1.
You need to configure a shared access signature (SAS) to ensure that users can only download blobs securely by name.
Which two settings should you configure? To answer, select the appropriate settings in the answer area.
NOTE: Each correct answer is worth one point.
Explanation: Object limits the SAS to a specific blob (access by name). Read permits secure downloading without allowing listing, modification, or deletion.
Question 123
HOTSPOT
-
You have an Azure subscription that contains the vaults shown in the following table.
You create a storage account that contains the resources shown in the following table.
To which vault can you back up cont1 and share1? To answer, select the appropriate options in the answer area.
NOTE: Each correct answer is worth one point.
Show Answer
Correct Answer: cont1:
Backup1 only
share1:
Recovery1 only
Explanation: Azure Blob containers are backed up using an Azure Backup vault. Azure File Shares are backed up using a Recovery Services vault; they aren’t backed up to Backup vaults in this context.
Question 124
You have an Azure subscription. The subscription contains virtual machines that connect to a virtual network named VNet1.
You plan to configure Azure Monitor for VM Insights.
You need to ensure that all the virtual machines only communicate with Azure Monitor through VNet1.
What should you create first?
A. a data collection rule (DCR)
B. a Log Analytics workspace
C. an Azure Monitor Private Link Scope (AMPLS)
D. a private endpoint
Show Answer
Correct Answer: C
Explanation: To force Azure Monitor traffic to stay on a private network, you must use Azure Monitor Private Link. The first resource to create is an Azure Monitor Private Link Scope (AMPLS), which defines the boundary of Azure Monitor resources (such as Log Analytics and VM Insights) that will be accessed privately. Private endpoints, Log Analytics workspaces, and data collection rules are then associated afterward. An AMPLS can be created without any connected resources, making it the correct first step.
Question 125
You have an Azure virtual machine named VM1 and an Azure key vault named Vault1.
On VM1, you plan to configure Azure Disk Encryption to use a key encryption key (KEK).
You need to prepare Vault1 for Azure Disk Encryption.
Which two actions should you perform on Vault1? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Select Azure Virtual machines for deployment.
B. Create a new key.
C. Create a new secret.
D. Configure a key rotation policy.
E. Select Azure Disk Encryption for volume encryption.
Show Answer
Correct Answer: B, E
Explanation: To use Azure Disk Encryption with a key encryption key (KEK), the key vault must contain a cryptographic key and be explicitly enabled for disk encryption access. You must create a new key in the vault to serve as the KEK, and you must enable the key vault setting **Azure Disk Encryption for volume encryption** so the Azure platform can access the key during VM disk encryption and boot. Other options (such as secrets, key rotation, or VM deployment access) are not required to prepare the vault specifically for Azure Disk Encryption with a KEK.
Question 126
HOTSPOT -
You have an Azure subscription that contains a virtual machine named VM1.
To VM1, you plan to add a 1-TB data disk that meets the following requirements:
• Provides data resiliency in the event of a datacenter outage.
• Provides the lowest latency and the highest performance.
• Ensures that no data loss occurs if a host fails.
You need to recommend which type of storage and host caching to configure for the new data disk.
Explanation: ZRS provides resiliency across availability zones, protecting data during a datacenter outage. Premium SSDs deliver the lowest latency and highest performance. Read-only host caching improves read performance while avoiding write caching, which could risk data loss if the host fails.
Question 127
You have five Azure virtual machines that run Windows Server 2016. The virtual machines are configured as web servers.
You have an Azure load balancer named LB1 that provides load balancing services for the virtual machines.
You need to ensure that visitors are serviced by the same web server for each request.
What should you configure?
A. Floating IP (direct server return) to Disabled
B. Idle Time-out (minutes) to 20
C. a health probe
D. Session persistence to Client IP
Show Answer
Correct Answer: D
Explanation: The requirement is to ensure that a client is consistently sent to the same backend virtual machine for each request (sticky sessions). In Azure Load Balancer, this behavior is achieved by configuring Session persistence. Setting session persistence to Client IP ensures that all requests from the same client IP address are directed to the same web server. Other options like floating IP, idle timeout, or health probes do not provide session affinity.
Question 128
You have five Azure virtual machines that run Windows Server 2016. The virtual machines are configured as web servers.
You have an Azure load balancer named LB1 that provides load balancing services for the virtual machines.
You need to ensure that visitors are serviced by the same web server for each request.
What should you configure?
A. Session persistence to Client IP
B. Idle Time-out (minutes) to 20
C. Session persistence to None
D. Protocol to UDP
Show Answer
Correct Answer: A
Explanation: To ensure that each visitor is consistently sent to the same backend web server on every request, Azure Load Balancer must use session persistence (also called source affinity). Configuring session persistence to Client IP ensures that all requests coming from the same client IP address are directed to the same virtual machine. The other options do not provide request stickiness: idle timeout only controls connection duration, session persistence set to None disables affinity, and UDP is unrelated to web session persistence.
Question 129
You have five Azure virtual machines that run Windows Server 2016. The virtual machines are configured as web servers.
You have an Azure load balancer named LB1 that provides load balancing services for the virtual machines.
You need to ensure that visitors are serviced by the same web server for each request.
What should you configure?
A. Session persistence to Client IP and protocol
B. Idle Time-out (minutes) to 20
C. Session persistence to None
D. Floating IP (direct server return) to Enabled
Show Answer
Correct Answer: A
Explanation: The requirement is to ensure session affinity (sticky sessions) so that each visitor is consistently routed to the same backend VM. In Azure Load Balancer, this is achieved by configuring Session persistence to Client IP and protocol. This setting hashes the client IP and protocol to always select the same backend server. Idle timeout, no persistence, or floating IP do not provide per-client session stickiness.
$19
Get all 558 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.