You have an Azure subscription named Subscription1 that contains two Azure virtual networks named VNet1 and VNet2. VNet1 contains a VPN gateway named
VPNGW1 that uses static routing. There is a site-to-site VPN connection between your on-premises network and VNet1.
On a computer named Client1 that runs Windows 10, you configure a point-to-site VPN connection to VNet1.
You configure virtual network peering between VNet1 and VNet2. You verify that you can connect to VNet2 from the on-premises network. Client1 is unable to connect to VNet2.
You need to ensure that you can connect Client1 to VNet2.
What should you do?
A. Select Use the remote virtual network's gateway or Route Server on VNet1 to VNet2 peering.
B. Select Use the remote virtual network s gateway or Route Server on VNet2 to VNet1 peering.
C. Download and re-install the VPN client configuration package on Client1.
D. Enable BGP on VPNGW1.
Show Answer
Correct Answer: C
Explanation: The point-to-site VPN client package contains the routes that the Windows VPN client installs. After adding virtual network peering or otherwise changing the network topology so that additional address spaces (such as VNet2) should be reachable through the VPN gateway, Windows point-to-site clients must download and reinstall the VPN client configuration package to receive the updated routes. The existing peering already allows on-premises connectivity, so the missing step for the P2S client is refreshing its configuration.
Question 233
HOTSPOT -
You have the role assignment file shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: User3 is
User1 and User4
Explanation: User3 is the only user explicitly assigned the Owner role at the VM1 resource scope. User1 inherits Owner from the subscription. For RG1, User1 (subscription Owner) and User4 (RG1 Contributor) can create virtual machines; User2 is limited to RG2 and User3 is scoped only to VM1.
Question 234
HOTSPOT -
You have an Azure subscription that contains the resources shown in the following table.
You plan to create a data collection rule named DCR1 in Azure Monitor.
Which resources can you set as data sources in DCR1, and which resources can you set as destinations in DCR1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: Data sources: VM1 only
Destinations: Workspace1 only
Explanation: A data collection rule uses Azure Monitor Agent to collect data from supported compute resources such as virtual machines. In the context of this exam, the supported destination is a Log Analytics workspace.
Question 236
You plan to deploy route-based Site-to-Site VPN connections between several on-premises locations and an Azure virtual network.
Which tunneling protocol should you use?
A. IKEv1
B. PPTP
C. IKEv2
D. L2TP
Show Answer
Correct Answer: C
Explanation: Route-based Azure Site-to-Site VPN gateways use IKEv2/IPsec. Policy-based VPN gateways use IKEv1. PPTP and L2TP are not the tunneling protocols used for Azure route-based Site-to-Site VPN connections.
Question 237
HOTSPOT -
You have two Azure subscriptions named Sub1 and Sub2. Sub1 is in a management group named MG1. Sub2 is in a management group named MG2.
You have the resource groups shown in the following table.
You have the virtual machines shown in the following table.
You assign roles to users as shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: No
No
No
Explanation: User1 lacks the Virtual Machine User Login role on VM1/Sub1. User2 has only VM User Login on Sub1, so cannot manage VM1 disks. On VM3, Virtual Machine Contributor at MG2 allows VM management and disks, but not disk snapshots as required by the statement.
Question 238
HOTSPOT -
You have an Azure App Service plan named ASP1.
CPU usage for ASP1 is shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: four times
scaled up
Explanation: The chart indicates a 6-hour aggregation interval (24/6 = 4 calculations per day). The maximum CPU frequently reaches 100%, indicating the plan is CPU-constrained during peak load, so increasing the compute capacity (scale up) best addresses CPU saturation.
Question 239
HOTSPOT -
You have an Azure App Service app named WebApp1 that contains two folders named Folder1 and Folder2.
You need to configure a daily backup of WebApp1. The solution must ensure that Folder2 is excluded from the backup.
What should you create first, and what should you use to exclude Folder2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: First create: An Azure Storage account
To exclude Folder2: A _backup.filter file
Explanation: Azure App Service custom backups are stored in an Azure Storage account. To exclude specific folders or files from App Service backups, create a _backup.filter file in the app's wwwroot directory listing the paths to exclude.
Question 240
HOTSPOT -
You have the following custom role-based access control (RBAC) role.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: No
Yes
Yes
Explanation: The role denies Microsoft.Authorization/*/Write, so it cannot create role assignments. It allows Microsoft.Compute/virtualMachines/*, enabling VM creation/management. It allows Microsoft.Network/networkInterfaces/*, which includes configuring NIC settings such as assigning a static private IP.
Question 241
You create an Azure Storage account.
You plan to add 10 blob containers to the storage account.
For one of the containers, you need to use a different key to encrypt data at rest.
What should you do before you create the container?
A. Generate a shared access signature (SAS).
B. Modify the minimum TLS version.
C. Rotate the access keys.
D. Create an encryption scope.
Show Answer
Correct Answer: D
Explanation: Encryption scopes let you use a different encryption key for specific blob containers or individual blobs within the same storage account. You must create the encryption scope before creating/configuring the container to use it. SAS, TLS version, and access key rotation do not control encryption at rest.
Question 242
You are configuring Azure Active Directory (Azure AD) authentication for an Azure Storage account named storage1.
You need to ensure that the members of a group named Group1 can upload files by using the Azure portal. The solution must use the principle of least privilege.
Which two roles should you configure for storage1? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Storage Account Contributor
B. Storage Blob Data Contributor
C. Reader
D. Contributor
E. Storage Blob Data Reader
Show Answer
Correct Answer: B, C
Explanation: To upload blob data via the Azure portal using Microsoft Entra ID (Azure AD), users need a data-plane role that permits writes (Storage Blob Data Contributor) and a management-plane role that lets them browse to the storage account in the Azure portal (Reader). Storage Account Contributor grants unnecessary management permissions, Contributor is overly broad, and Storage Blob Data Reader cannot upload data.
$19
Get all 555 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.