You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. VNet1 is in a resource group named RG1.
Subscription1 has a user named User1. User1 has the following roles:
• Reader
• Security Admin
• Security Reader
You need to ensure that User1 can assign the Reader role for VNet1 to other users.
What should you do?
A. Remove User1 from the Security Reader role for Subscript on 1. Assign User1 the Contributor role for RG1.
B. Assign User1 the Owner role for VNet1.
C. Remove User1 from the Security Reader and Reader roles for Subscription1. Assign User1 the Contributor role for Subscription 1.
D. Assign User1 the Contributor role for VNet1.
Show Answer
Correct Answer: B
Explanation: To assign Azure RBAC roles, a user needs the Microsoft.Authorization/roleAssignments/write permission, which is included in the Owner role (and User Access Administrator), but not in Contributor, Reader, Security Reader, or Security Admin. Assigning the Owner role scoped to VNet1 gives User1 permission to assign the Reader role for that resource without granting ownership beyond that scope.
Question 159
You have an Azure subscription that has the public IP addresses shown in the following table.
You plan to deploy an Instance of Azure Firewall Premium named FW1.
Which IP addresses can you use?
A. IP2 only
B. IP1 and IP2 only
C. IP1, IP2, and IP5 only
D. IP1, IP2, IP4, and IP5 only
Show Answer
Correct Answer: B
Explanation: Azure Firewall Premium requires Standard SKU, static public IPv4 addresses. It does not support Basic SKU, dynamic public IPs, or IPv6 public IP addresses. Therefore, only IP1 and IP2 are eligible.
Question 160
HOTSPOT
-
You have an Azure subscription that contains a user named User1 and the resources shown in the following table.
NSG1 is associated to networkinterface1.
User1 has role assignments for NSG1 as shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
Yes
Explanation: Storage Account Contributor at the resource group scope can create and manage storage accounts in that resource group. Contributor on the NSG allows managing NSG rules, but does not grant permission to modify the network interface's DNS settings. Therefore the user can add inbound security rules to the associated NSG but cannot change NIC DNS settings.
Question 161
You have an Azure subscription.
You need to receive an email alert when a resource lock is removed from any resource in the subscription.
What should you use to create an activity log alert in Azure Monitor?
A. a resource, a condition, and an action group
B. a resource, a condition, and a Microsoft 365 group
C. a Log Analytics workspace, a resource, and an action group
D. a data collection endpoint, an application security group, and a resource group
Show Answer
Correct Answer: A
Explanation: An Azure Monitor activity log alert rule is created by specifying the scope (resource or subscription), the activity log condition (such as administrative operation 'Delete lock' or resource lock removal), and an action group to send notifications such as email. Microsoft 365 groups, Log Analytics workspaces, data collection endpoints, and application security groups are not required components for creating an activity log alert rule.
Question 162
You have an Azure subscription that contains 10 virtual machines and the resources shown in the following table.
You need to ensure that Bastion1 can support 100 concurrent SSH users. The solution must minimize administrative effort.
What should you do first?
A. Resize the subnet of Bastion1
B. Configure host scaling.
C. Create a network security group (NSG)
D. Upgrade Bastion1 to the Standard SKU
Show Answer
Correct Answer: D
Explanation: Upgrade Azure Bastion to the Standard SKU first. Host scaling, which is required to increase capacity beyond the Basic SKU, is only available with the Standard SKU. A Standard Bastion can then be scaled out with additional instances to support around 100 concurrent SSH sessions. Resizing the AzureBastionSubnet may be necessary only if the existing subnet is too small for the desired scale, but enabling the required SKU is the first prerequisite. Creating an NSG is unrelated, and host scaling cannot be configured on the Basic SKU.
Question 163
You have an Azure subscription named Subscription1.
You have 5 TB of data that you need to transfer to Subscription1.
You plan to use an Azure Import/Export job.
What can you use as the destination of the imported data?
A. an Azure Cosmos DB database
B. Azure Data Lake Store
C. Azure Blob storage
D. Azure Data Factory
Show Answer
Correct Answer: C
Explanation: Azure Import/Export supports importing data into Azure Blob storage (and Azure Files), not Azure Cosmos DB, Azure Data Lake Store, or Azure Data Factory. Therefore, the valid destination from the options is Azure Blob storage.
Question 164
HOTSPOT
-
You have an Azure subscription that contains a storage account named storage1. The storage1 account contains a container named container1.
You create a blob lifecycle rule named rule1.
You need to configure rule1 to automatically move blobs that were NOT updated for 45 days from contained to the Cool access tier.
How should you complete the rule? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: The requirement is based on blobs not being updated, so use the modification time condition. Moving to the Cool tier is supported for block blobs in lifecycle management.
Question 165
You have an Azure subscription that contains a virtual machine named VM1 and an Azure function named App1.
You need to create an alert rule that will run App1 if VM1 stops.
What should you create for the alert rule?
A. an application security group
B. a security group that has dynamic device membership
C. an action group
D. an application group
Show Answer
Correct Answer: C
Explanation: Azure Monitor alert rules use action groups to define what happens when an alert is triggered. An action group can invoke an Azure Function, so to run App1 when VM1 stops, you create an action group and associate it with the alert rule.
Question 166
You have an Azure subscription that contains a storage account named storage1 in the North Europe Azure region.
You need to ensure that when blob data is added to storage1, a secondary copy is created in the East US region. The solution must minimize administrative effort.
What should you configure?
A. operational backup
B. object replication
C. geo-redundant storage (GRS)
D. a lifecycle management rule
Show Answer
Correct Answer: B
Explanation: Object replication is the only option that allows you to replicate blob data to a specifically chosen Azure region such as East US. Geo-redundant storage (GRS) automatically replicates to the storage account's paired region, which for North Europe is not East US, so it does not meet the stated requirement. Operational backup and lifecycle management do not provide cross-region blob replication.
Question 167
You have an Azure subscription that contains two Log Analytics workspaces named Workspace1 and Workspace2 and 100 virtual machines that run Windows Server.
You need to collect performance data and events from the virtual machines. The solution must meet the following requirements:
• Logs must be sent to Workspace1 and Workspace 2.
• All Windows events must be captured.
• All security events must be captured.
What should you install and configure on each virtual machine?
A. the Azure Monitor agent
B. the Windows Azure diagnostics extension (WAD)
C. the Windows VM agent
Show Answer
Correct Answer: A
Explanation: The Azure Monitor agent (AMA) is the supported agent for collecting performance counters and Windows event logs, including security events, and can be configured through Data Collection Rules to send data to multiple Log Analytics workspaces. The Windows Azure Diagnostics extension primarily sends diagnostics to Azure Storage and is not the appropriate solution for this requirement. The Windows VM agent enables VM extensions but does not itself collect and forward monitoring data.
$19
Get all 555 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.