Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure Storage account named storage1.
You need to enable a user named User1 to list and regenerate storage account keys for storage1.
Solution: You assign the Reader and Data Access role to User1.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: The Reader and Data Access role provides read access to storage account metadata and data-plane access information but does not grant permission to regenerate storage account access keys. Listing and regenerating storage account keys requires a role that includes the Microsoft.Storage/storageAccounts/listKeys/action and regenerateKey/action permissions, such as the Storage Account Key Operator Service Role (or a broader role like Owner/Contributor).
Question 52
HOTSPOT
-
Your network contains an on-premises Active Directory Domain Services (AD DS) domain.
The domain contains the identities shown in the following table.
You have an Azure subscription that contains a storage account named storage1. The file shares in storage1 have an identity source of AD DS and Default share-level permissions set to Enable permissions for all authenticated users and groups.
You create an Azure Files share named share1 that has the roles shown in the following table.
You have a Microsoft Entra tenant that contains a cloud-only user named User3.
You use Microsoft Entra Connect to sync OU1 from the AD DS domain to the Microsoft Entra tenant.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
No
Explanation: Azure Files share-level RBAC is evaluated using Microsoft Entra identities. Only OU1 is synchronized, so User2 and Group1 are synced, but User1 (in OU2) is not. A synced group cannot grant Azure access to a user that has no corresponding synced Entra identity. User2 has the Reader role directly. User3 is cloud-only and has no assigned share role; the default share-level setting only applies to the configured identity source (AD DS authenticated identities), not to an unrelated cloud-only user.
Question 53
You have an Azure subscription that contains the resources shown in the following table.
You need to ensure that data transfers between storage1 and VM1 do NOT traverse the internet
What should you configure for storage1?
A. data protection
B. a private endpoint
C. Public network access in the Firewalls and virtual networks settings
D. a shared access signature (SAS)
Show Answer
Correct Answer: B
Explanation: A private endpoint assigns the storage account a private IP address within the virtual network, so traffic between the VM and the storage account stays on the Azure private network/Microsoft backbone and does not traverse the public internet. Data protection, public network access settings, and SAS tokens do not provide private network connectivity.
Question 54
You have an Azure subscription named Subscription1 that contains the resources shown in the following table.
You create virtual machines in Subscription1 as shown in the following table.
You plan to use Vault1 for the backup of as many virtual machines as possible.
Which virtual machines can be backed up to Vault1?
A. VM1 only
B. VM3 and VMC only
C. VM1, VM2, VM3, VMA, VMB, and VMC
D. VM1, VM3, VMA, and VMC only
E. VM1 and VM3 only
Show Answer
Correct Answer: D
Explanation: A Recovery Services vault must be in the same Azure region as the virtual machines it protects, but it can be in a different resource group. Therefore, all VMs in the same region as Vault1 can be backed up regardless of resource group, while VMs in other regions cannot.
Question 55
You have an Azure subscription that contains an Azure container registry named ContReg1.
You enable the Admin user for ContReg1.
Which username can you use to sign in to ContReg1?
A. root
B. admin
C. administrator
D. ContReg1
Show Answer
Correct Answer: D
Explanation: When the Azure Container Registry admin user is enabled, the username used for basic authentication is the registry name itself, and the password is one of the admin access keys. Therefore, for a registry named ContReg1, the username is ContReg1.
Question 56
HOTSPOT
-
You have an Azure subscription that contains the virtual networks shown in the following table.
The subscription contains the virtual machines shown in the following table.
The subscription contains the Azure App Service web apps shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
Yes
Explanation: VNet Integration enables outbound access from WebApp1 to resources in its integrated VNet and peered VNets. NSGs on the integration subnet do not control inbound traffic to the App Service itself. An Isolated-tier app in an App Service Environment is deployed into the VNet, so it can communicate with resources in a peered VNet unless blocked by network rules.
Question 57
HOTSPOT -
You have a Microsoft Entra tenant that contains the groups shown in the following table.
The tenant contains the users shown in the following table.
Which users and groups can you delete? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Users: User1, User2, User3, and User4
Groups: Group2 and Group4
Explanation: Deleting a user is allowed regardless of direct or inherited license assignment; the license is reclaimed. Groups with active license assignments cannot be deleted until the licenses are removed. Therefore, only the groups without assigned licenses (Group2 and Group4) can be deleted.
Question 58
HOTSPOT -
You have an Azure Storage account named contoso2024 that contains the resources shown in the following table.
You have users that have permissions for contoso2024 as shown in the following table.
The contoso2024 account is configured as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
No
No
Explanation: Reader and Storage Account Contributor are management-plane roles and do not grant data access. Reading blob/file data requires appropriate Storage Data roles (or another valid data authorization). Shared Key access is disabled, so possessing an access key cannot be used to access the data.
Question 59
You have an Azure subscription that contains the virtual networks shown in the following table.
You need to ensure that all the traffic between VNet1 and VNet2 traverses the Microsoft backbone network.
What should you configure?
A. a private endpoint
B. peering
C. Express Route
D. a route table
Show Answer
Correct Answer: B
Explanation: Virtual network peering (including global VNet peering across regions) routes traffic between Azure virtual networks over the Microsoft backbone network. Private endpoints provide private access to Azure PaaS services, ExpressRoute connects on-premises networks to Azure, and route tables influence routing but do not by themselves provide private VNet-to-VNet connectivity over the Microsoft backbone.
Question 60
Your on-premises network contains a VPN gateway.
You have an Azure subscription that contains the resources shown in the following table.
You need to ensure that all the traffic from VM1 to storage1 travels across the Microsoft backbone network.
What should you configure?
A. Azure Application Gateway
B. service endpoints
C. a network security group (NSG)
D. Azure Peering Service
Show Answer
Correct Answer: B
Explanation: Service endpoints extend the VNet identity to supported Azure services such as Azure Storage and ensure traffic from the VM to the storage account remains on the Microsoft backbone network instead of traversing the public internet. Application Gateway is for HTTP load balancing, NSGs filter traffic, and Azure Peering Service optimizes connectivity from ISP networks to Microsoft edge rather than VM-to-storage traffic within Azure.
$19
Get all 555 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.