You have an Azure subscription that contains a Standard SKU Azure container registry named ContReg1.
You need to ensure that ContReg1 supports geo-replication.
What should you do first for ContReg1?
A. Enable Admin user.
B. Add a scope map.
C. Add an automation task.
D. Create a cache rule.
E. Upgrade the SKU.
Show Answer
Correct Answer: E
Explanation: Geo-replication for Azure Container Registry is supported only in the Premium SKU. Since ContReg1 is currently using the Standard SKU, the first required action is to upgrade the registry to the Premium SKU before geo-replication can be enabled.
Question 27
You have an Azure subscription that contains the storage accounts shown in the following table.
Which storage account can be converted to zone-redundant storage (ZRS) replication?
A. storage1 only
B. storage2 only
C. storage3 only
D. storage2 and storage3
E. storage1, storage2, and storage3
Show Answer
Correct Answer: A
Explanation: Only storage1 can be converted to ZRS. Azure supports direct conversion to ZRS only from LRS on general-purpose v2 (and some premium) storage accounts. Accounts using RA-GRS cannot be converted directly to ZRS, and BlobStorage accounts do not support conversion to ZRS. Since storage1 uses LRS on a supported account type, it is the only valid choice.
Question 28
You have a Microsoft Entra tenant configured as shown in the following exhibit.
The tenant contains the identities shown in the following table.
You purchase a Microsoft Fabric license.
To which identities can you assign the license?
A. User1 only
B. User1 and Group1 only
C. User1 and Group2 only
D. User1, Group1, and Group2
Show Answer
Correct Answer: A
Explanation: In Microsoft Entra ID Free, licenses can only be assigned directly to individual users. Group-based licensing (assigning licenses to security groups or Microsoft 365 groups) requires Microsoft Entra ID P1 or higher. Since the tenant is in Free mode, only User1 can be assigned the Microsoft Fabric license, not Group1 or Group2.
Question 30
You have an Azure subscription that contains a storage account named storage1. The storage1 account contains blob data.
You need to assign a role to a user named User1 to ensure that the user can access the blob data in storage1. The role assignment must support conditions.
Which two roles can you assign to User1? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. Owner
B. Storage Account Contributor
C. Storage Account Backup Contributor
D. Storage Blob Data Contributor
E. Storage Blob Data Owner
F. Storage Blob Delegator
Show Answer
Correct Answer: D, E
Explanation: To access blob data using Azure RBAC with support for role assignment conditions, you must use data-plane roles. Storage Blob Data Contributor allows read, write, and delete access to blob data and supports conditions. Storage Blob Data Owner provides full blob data access, including managing access permissions, and also supports conditions. Management-plane roles like Owner or Storage Account Contributor do not grant direct blob data access via RBAC.
Question 31
You have an Azure subscription that contains the Microsoft Entra identities shown in the following table.
You need to enable self-service password reset (SSPR).
For which identities can you enable SSPR in the Azure portal?
A. User1 only
B. Group1 only
C. User1 and Group1 only
D. Group1 and Group2 only
E. User1, Group1, and Group2
Show Answer
Correct Answer: C
Explanation: In the Azure portal, self-service password reset can be enabled for all users or for selected users by choosing a security group. Individual user accounts are valid SSPR targets (as users), and security groups can be used to scope SSPR. Microsoft 365 groups aren’t supported directly for SSPR scoping. Therefore, SSPR can be enabled for User1 and Group1, but not Group2.
Question 32
You have an Azure subscription that contains a storage account named storage1.
You need to ensure that the access keys for storage1 rotate automatically.
What should you configure?
A. a backup vault
B. redundancy for storage1
C. lifecycle management for storage1
D. an Azure key vault
E. a Recovery Services vault
Show Answer
Correct Answer: D
Explanation: Automatic rotation of Azure Storage account access keys is achieved by integrating the storage account with Azure Key Vault. Key Vault supports storage account key management and provides built-in key rotation policies and automation, which none of the other options offer.
Question 34
You have an Azure subscription that contains two peered virtual networks named VNet1 and VNet2.
You have a Network Virtual Appliance (NVA) named NetVA1.
You need to ensure that the traffic from VNet1 to VNet2 is inspected by using NetVA1.
What should you use?
A. a local network gateway
B. a route table that has custom routes
C. a service endpoint
D. IP address reservations
Show Answer
Correct Answer: B
Explanation: To force traffic between peered virtual networks through a Network Virtual Appliance (NVA), you must use user-defined routes (UDRs) in a route table. By associating a route table with custom routes that point traffic destined for the other VNet to the NVA’s IP address, all inter-VNet traffic is redirected through NetVA1 for inspection. Other options do not control traffic flow within peered VNets.
Question 35
You plan to deploy several Azure virtual machines that will run Windows Server 2022 in a virtual machine scale set by using an Azure Resource Manager template.
You need to ensure that NGINX is available on all the virtual machines after they are deployed.
What should you use?
A. Azure Custom Script Extension
B. Deployment Center in Azure App Service
C. Microsoft Entra Application Proxy
D. the Publish-AzVMDscConfiguration cmdlet
Show Answer
Correct Answer: A
Explanation: To ensure NGINX is installed on all Windows Server 2022 VMs in a virtual machine scale set deployed via an ARM template, you should use the Azure Custom Script Extension. It allows you to run post-deployment scripts on each VM instance to install and configure software such as NGINX. Deployment Center applies to App Service, Microsoft Entra Application Proxy is unrelated, and Publish-AzVMDscConfiguration only publishes DSC configurations to Azure Automation rather than applying them directly during VM deployment.
Question 36
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure Storage account named storage1.
You need to enable a user named User1 to list and regenerate storage account keys for storage1.
Solution: You assign the Storage Account Key Operator Service Role to User1.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: A
Explanation: The Storage Account Key Operator Service Role explicitly allows listing and regenerating storage account access keys. Assigning this role to User1 meets the requirement to manage keys for storage1.
Question 37
HOTSPOT -
You have an Azure container registry named contoso2023 as shown in the following exhibit.
You need to enable contoso2023 to use a dedicated data endpoint.
Which two settings should you configure for contoso2023? To answer, select the appropriate settings in the answer area.
NOTE: Each correct answer is worth one point.
Show Answer
Correct Answer: Overview
Networking
Explanation: Dedicated data endpoints are available only in the Premium SKU, which is changed from the Overview blade. The dedicated data endpoint itself is enabled under Networking > Public access.
$19
Get all 558 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.