You have an Azure subscription.
You plan to deploy the Azure container instances shown in the following table.
Which instances can you deploy to a container group?
A. Instance1 only
B. Instance2 only
C. Instance1 and Instance2 only
D. Instance3 and Instance4 only
Show Answer
Correct Answer: D
Explanation: A container group implies multiple containers deployed together. Azure Container Instances supports multi-container groups only for Linux containers; Windows container groups are limited to a single container. Therefore, only the Linux instances (Instance3 and Instance4) can be deployed to a container group.
Question 169
You have an Azure subscription that contains the resources shown in the following table.
All the resources connect to a virtual network named VNet1.
You plan to deploy an Azure Bastion host named Bastion1 to VNet1.
Which resources can be protected by using Bastion1?
A. VM1 only
B. contoso.com only
C. App1 and contoso.com only
D. VM1 and contoso.com only
E. VM1, App1, and contoso.com
Show Answer
Correct Answer: A
Explanation: Azure Bastion provides secure RDP/SSH connectivity for virtual machines deployed in a virtual network. It is used to access and protect VMs from exposing RDP/SSH ports publicly. It does not provide access protection for Azure App Service web apps or Azure AD Domain Services/domain resources such as contoso.com.
Question 170
You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. VNet1 is in a resource group named RG1.
Subscription1 has a user named User1. User1 has the following roles:
• Reader
• Security Admin
• Security Reader
You need to ensure that User1 can assign the Reader role for VNet1 to other users.
What should you do?
A. Assign User1 the Network Contributor role for VNet1.
B. Remove User1 from the Security Reader role for Subscription1. Assign User1 the Contributor role for RG1.
C. Assign User1 the Owner role for VNet1.
D. Assign User1 the Network Contributor role for RG1.
Show Answer
Correct Answer: C
Explanation: To assign Azure RBAC roles (such as the Reader role) on a resource, a user must have the Microsoft.Authorization/roleAssignments/write permission, which is included in the Owner and User Access Administrator roles. Among the provided options, only assigning the Owner role for VNet1 grants the required ability to assign RBAC roles on that virtual network. Network Contributor and Contributor cannot manage role assignments, and removing Security Reader is irrelevant.
Question 171
You have five Azure virtual machines that run Windows Server 2016. The virtual machines are configured as web servers.
You have an Azure load balancer named LB1 that provides load balancing services for the virtual machines.
You need to ensure that visitors are serviced by the same web server for each request.
What should you configure?
A. Session persistence to None
B. a health probe
C. Session persistence to Client IP and protocol
D. Idle Time-out (minutes) to 20
Show Answer
Correct Answer: C
Explanation: Configure the Azure Load Balancer session persistence (load distribution mode) to 'Client IP and protocol' so requests from the same client are consistently directed to the same backend VM (session affinity). A health probe only determines backend availability, idle timeout controls TCP connection timeout, and 'None' disables session persistence.
Question 172
You deploy Azure virtual machines to three Azure regions
Each region contains a virtual network. Each virtual network contains multiple subnets peered in a full mesh topology.
Each subnet contains a network security group (NSG) that has defined rules.
A user reports that he cannot use port 33000 to connect from a virtual machine in one region to a virtual machine in another region.
Which two options can you use to diagnose the issue? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. Azure Virtual Network Manager
B. IP flow verify
C. Azure Monitor Network Insights
D. Connection troubleshoot
E. elective security rules
Show Answer
Correct Answer: B, D
Explanation: IP flow verify (Azure Network Watcher) checks whether NSG or other network rules allow or deny traffic for a specific flow to or from a VM, making it ideal for diagnosing whether port 33000 is blocked. Connection troubleshoot (Azure Network Watcher) tests end-to-end connectivity between two endpoints and identifies where connectivity fails, including NSG-related issues. Azure Monitor Network Insights is primarily for monitoring and visualization rather than direct flow troubleshooting, Azure Virtual Network Manager is for management, and effective security rules show the resulting rules but do not provide complete end-to-end diagnostics.
Question 173
You have an Azure subscription that contains a virtual network named VNet1.
VNet1 uses two ExpressRoute circuits that connect to two separate on-premises datacenters.
You need to create a dashboard to display detailed metrics and a visual representation of the network topology.
What should you use?
A. Azure Monitor Network Insights
B. a Data Collection Rule (DCR)
C. Azure Virtual Network Watcher
D. Log Analytics
Show Answer
Correct Answer: A
Explanation: Azure Monitor Network Insights provides prebuilt dashboards with detailed metrics and a visual network topology for networking resources, including ExpressRoute. It is designed to monitor ExpressRoute circuits, gateways, peerings, availability, throughput, packet drops, and topology. A Data Collection Rule only configures data collection, Log Analytics is for querying collected data, and Network Watcher focuses on network diagnostics and troubleshooting rather than the dedicated insights dashboard requested.
Question 174
HOTSPOT
-
You have an Azure subscription that contains the storage accounts shown in the following table.
You need to identify which storage accounts support lifecycle management, and which storage accounts support moving data to the Archive access tier.
Which storage accounts should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Lifecycle management: storage1, storage2, and storage3
The Archive access tier: storage2 only
Explanation: Lifecycle management is supported for general-purpose v2, Blob Storage, and BlockBlobStorage accounts. Archive tier requires supported redundancy; RA-GRS supports Archive, while GZRS and ZRS do not.
Question 175
You have an Azure subscription. The subscription contains a storage account named storage1 that has the lifecycle management rules shown in the following table.
On June 1, you store a blob named File1 in the Hot access tier of storage1.
What is the state of File1 on June 7?
A. stored in the Cool access tier
B. stored in the Archive access tier
C. stored in the Hot access tier
D. deleted
Show Answer
Correct Answer: D
Explanation: The lifecycle policy evaluates applicable actions based on the blob's age. When multiple actions apply to the same blob, Azure Blob Storage applies the least expensive action. Delete takes precedence over tiering actions (Archive, then Cool). By June 7, the blob meets the deletion condition, so it is deleted rather than moved to another tier.
Question 176
HOTSPOT
-
You have an Azure subscription that contains the users shown in the following table.
The groups are configured as shown in the following table.
You have a resource group named RG1 as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
Yes
Explanation: Security groups can be nested for Azure RBAC inheritance in this scenario; Microsoft 365 groups cannot be added as members of security groups; a Microsoft 365 group can be assigned the Owner RBAC role if it is role-assignable.
Question 177
You have an Azure subscription named Subscription1.
You have 5 TB of data that you need to transfer to Subscription1.
You plan to use an Azure Import/Export job.
What can you use as the destination of the imported data?
A. Azure Blob Storage
B. Azure Data Lake Store
C. Azure SQL Database
D. a virtual machine
Show Answer
Correct Answer: A
Explanation: Azure Import/Export supports importing data by shipping disks into Azure Blob Storage and Azure Files. Among the provided options, only Azure Blob Storage is a supported import destination. Azure Data Lake Store, Azure SQL Database, and Azure virtual machines are not direct Azure Import/Export import destinations.
$19
Get all 555 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.