You need to identify which storage account to use for the flow logging of IP traffic from VM5. The solution must meet the retention requirements.
Which storage account should you identify?
A. storage1
B. storage2
C. storage3
D. storage4
Show Answer
Correct Answer: B
Explanation: NSG flow log retention is supported only when logs are stored in a General Purpose v2 (GPv2) storage account. Among the options, storage2 is the only GPv2 account that meets the retention requirement, making it the correct choice.
Question 233
You need to ensure that you can grant Group4 Azure RBAC read only permissions to all the Azure file shares.
What should you do?
A. On storage2, enable identity-based access for the file shares.
B. Recreate storage2 and set Hierarchical namespace to Enabled.
C. On storage1 and storage4, change the Account kind type to StorageV2 (general purpose v2).
D. Create a shared access signature (SAS) for storage1, storage2, and storage4.
Show Answer
Correct Answer: A
Explanation: To grant Group4 read-only access using Azure RBAC to Azure file shares, the storage account must support identity-based authentication for Azure Files. Azure RBAC for file shares works only when identity-based access (Azure AD DS or AD DS integration) is enabled. Storage2 is the only account where this is not enabled, so you must enable identity-based access there. Other options are unrelated: hierarchical namespace is for Data Lake Gen2, changing account kind is unnecessary here, and SAS tokens are not RBAC-based.
Question 234
HOTSPOT -
You implement the planned changes for NSG1 and NSG2.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: Yes
Yes
No
Explanation: NSG1 has inbound rules only, so VM1 outbound RDP to VM2 is allowed.
NSG2 has outbound rules; ICMP from VM2 to VM3 is allowed (no deny).
NSG2 explicitly denies outbound RDP from VM2, so RDP to VM3 is blocked.
Question 235
You have an Azure Active Directory (Azure AD) tenant that is linked to 10 Azure subscriptions.
You need to centrally monitor user activity across all the subscriptions.
What should you use?
A. Azure Application Insights Profiler
B. access reviews
C. Activity log filters
D. a Log Analytics workspace
Show Answer
Correct Answer: D
Explanation: To centrally monitor user activity across multiple Azure subscriptions, you need a single aggregation point for logs. A Log Analytics workspace can collect Azure Activity Logs from all subscriptions in the tenant, enabling centralized querying, dashboards, and alerts using KQL. The other options do not provide cross-subscription, centralized monitoring of user activity.
Question 236
You have an Azure subscription named Subscription1 that contains two Azure virtual networks named VNet1 and VNet2. VNet1 contains a VPN gateway named
VPNGW1 that uses static routing. There is a site-to-site VPN connection between your on-premises network and VNet1.
On a computer named Client1 that runs Windows 10, you configure a point-to-site VPN connection to VNet1.
You configure virtual network peering between VNet1 and VNet2. You verify that you can connect to VNet2 from the on-premises network. Client1 is unable to connect to VNet2.
You need to ensure that you can connect Client1 to VNet2.
What should you do?
A. Select Use the remote virtual network's gateway or Route Server on VNet1 to VNet2 peering.
B. Select Use the remote virtual network s gateway or Route Server on VNet2 to VNet1 peering.
C. Download and re-install the VPN client configuration package on Client1.
D. Enable BGP on VPNGW1.
Show Answer
Correct Answer: C
Explanation: Point-to-site VPN clients download a client configuration package that contains the address spaces and routes reachable through the VPN gateway. When the network topology changes—such as adding VNet peering so that VNet1 can reach VNet2—the existing P2S client does not automatically learn the new routes. Re-downloading and reinstalling the VPN client configuration updates the route table on Client1, allowing it to reach VNet2.
Question 237
HOTSPOT -
You have the role assignment file shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: User1 and User3 are
User1 and User4
Explanation: VM1 has an Owner role assigned directly to User3, and User1 is Owner at the subscription scope, which is inherited by VM1.
In RG1, User1 (subscription Owner) and User4 (Contributor on RG1) both have permissions to create virtual machines.
Question 238
HOTSPOT -
You have an Azure subscription that contains the resources shown in the following table.
You plan to create a data collection rule named DCR1 in Azure Monitor.
Which resources can you set as data sources in DCR1, and which resources can you set as destinations in DCR1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: Data sources: VM1 only
Destinations: Workspace1 only
Explanation: A data collection rule (DCR) primarily works with the Azure Monitor Agent, which is installed on compute resources such as virtual machines. Storage accounts, SQL databases, and Log Analytics workspaces are not valid data sources for a DCR. For destinations, DCRs send collected data to a Log Analytics workspace; other listed resources are not valid destinations in this scenario.
Question 240
You plan to deploy route-based Site-to-Site VPN connections between several on-premises locations and an Azure virtual network.
Which tunneling protocol should you use?
A. IKEv1
B. PPTP
C. IKEv2
D. L2TP
Show Answer
Correct Answer: C
Explanation: Azure route-based Site-to-Site VPN gateways require IPsec with IKEv2. IKEv2 supports route-based VPNs, multiple site connections, and modern security features. PPTP and L2TP are not used for Azure S2S VPNs, and IKEv1 is primarily associated with policy-based VPNs.
Question 241
HOTSPOT -
You have two Azure subscriptions named Sub1 and Sub2. Sub1 is in a management group named MG1. Sub2 is in a management group named MG2.
You have the resource groups shown in the following table.
You have the virtual machines shown in the following table.
You assign roles to users as shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: No
No
No
Explanation: 1) User1 has Virtual Machine Contributor at MG1 (covers Sub1) but no Virtual Machine User Login on Sub1/VM1, so sign-in isn’t allowed.
2) User2 has only Virtual Machine User Login on Sub1; this allows login but not disk or snapshot management.
3) User2 has Virtual Machine Contributor on MG2 (covers VM3), but that role allows disk management only; snapshot management requires snapshot-specific permissions.
Question 242
HOTSPOT -
You have an Azure App Service plan named ASP1.
CPU usage for ASP1 is shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: four times
scaled up
Explanation: The chart shows a 6-hour time granularity (Last 30 days – Automatic: 6 hours), so the average CPU is calculated 24 ÷ 6 = 4 times per day. The maximum CPU frequently reaches 100%, indicating CPU saturation; to optimize CPU usage and reduce throttling, the App Service plan needs more CPU resources, which is achieved by scaling up.
$19
Get all 558 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.