Microsoft

AZ-120 Free Practice Questions — Page 5

Question 41

You have an Azure subscription. The subscription contains two virtual machines that host an SAP workload. You need to protect the workload by using Azure Site Recovery. The solution must meet the following requirements: • Support shared application-consistent recovery points. • Support shared crash-consistent recovery points. • Minimize administrative effort. What should you create?

A. an Azure Automation runbook
B. a replication group
C. an Azure shared disk
D. an Azure Automation workflow
Show Answer
Correct Answer: B
Explanation:
Create a replication group. Azure Site Recovery replication groups let multiple VMs be included in a multi-VM consistency group, so they can share application-consistent and crash-consistent recovery points. This provides coordinated recovery with less administrative effort than managing the VMs independently.

Question 42

DRAG DROP You have an SAP Fiori single sign-on (SSO)-enabled subscription. You have an Azure subscription that is linked to a Microsoft Entra tenant named contoso.com. You need to configure SSO authentication between SAP Fiori and contoso.com. Which five actions should you perform in sequence in the Microsoft Entra admin center? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Illustration for AZ-120 question 42
Show Answer
Correct Answer: 1. Add an enterprise application from the gallery. 2. Select SAML as the SSO method. 3. Upload the metadata file and provide the sign-in URL. 4. Update the user claims. 5. Download the federation metadata file.
Explanation:
Configure SAP Fiori as a SAML enterprise application, then set its service-provider details and claims. Download the Microsoft Entra federation metadata after those settings are configured.

Question 43

HOTSPOT You have an Azure subscription that contains an Azure NetApp Files account named account1 and an SAP HANA deployment. In account1, you create a capacity pool named pool1 that has the following configurations: • Quality of Service (QoS) type: Auto • Service level: Premium • Size: 4 TB In account1, you create a volume named volume1 that has the following configurations: • Network features: Standard • Protocol: Dual-protocol • Quota: 500 GB You need configure pool1 and volume1 to support an application volume group for the HANA deployment. What should you modify? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for AZ-120 question 43
Show Answer
Correct Answer: For pool1: QoS type For volume1: Protocol
Explanation:
An SAP HANA application volume group requires a manual-QoS capacity pool and NFS volumes. Change pool1 from Auto to Manual QoS and volume1 from dual-protocol to NFS.

Question 44

You have an SAP production landscape in Azure. The landscape is hosted on 50 virtual machines that run SUSE Enterprise Linux (SLES). The virtual machines are billed by using pay-as-you-go rates. You need to minimize operating system costs for the virtual machines. What should you use?

A. capacity reservations
B. Azure Hybrid Benefit
C. reserved instances
D. spot pricing
Show Answer
Correct Answer: B
Explanation:
Azure Hybrid Benefit for Linux lets you use eligible SUSE subscriptions for SLES VMs, replacing the pay-as-you-go OS software charge. Reserved instances reduce compute costs, not specifically OS costs. Sources: https://learn.microsoft.com/en-us/azure/virtual-machines/linux/azure-hybrid-benefit-linux?tabs=ahbNewPortal%2CahbExistingPortal%2Clicenseazcli%2Crhelpaygreqs%2CrhelAzcliByosConv%2Cpaygclisingle%2Crhelpaygconversion%2Crhelcompliance

Question 45

You have an SAP workload on an Azure virtual machine. You have a built-in role-based access control (RBAC) role definition in the JSON format. You plan to change the built-in role definition to a custom role definition. Which property value in the built-in role definition must you change?

A. assignableScopes
B. notActions
C. roleName
D. actions
Show Answer
Correct Answer: C
Explanation:
Change `roleName` to a unique name for the custom role. The `actions` and `notActions` values define its permissions and only need changing if you want different permissions.

Question 46

HOTSPOT You have an Azure subscription. The subscription contains two virtual machines named SQL1 and SQL2 that host a Microsoft SQL Server 2019 Always On availability group named AOG1. You plan to deploy an SAP NetWeaver system that will have a database tier hosted on AOG1. You need to encrypt the Azure virtual machine disks and the SQL Server database. The solution must meet the following requirements: • The operating system disk, data disk, and the temporary disk of the virtual machines must be encrypted. • SQL Server encryption keys must be stored on-premises. Which type of encryption should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct select ion is worth one point.

Illustration for AZ-120 question 46
Show Answer
Correct Answer: For the virtual machine disks: Encryption at host For the SQL Server database: Transparent Data Encryption (TDE)
Explanation:
Encryption at host covers the OS, data, and temporary disks. TDE encrypts the SQL Server database; its protecting key can be managed in an on-premises key store through Extensible Key Management.

Question 47

You have an Azure subscription that contains a virtual machine named VM1. VM1 runs SUSE Linux Enterprise Server (SLES) and hosts an SAP workload. You deploy Azure Monitor for SAP solutions. You need to configure the Linux OS provider. The solution must ensure that you can collect monitoring data by using the Prometheus endpoint on VM1. Which firewall port should you open on VM1?

A. 22
B. 80
C. 443
D. 9100
Show Answer
Correct Answer: D
Explanation:
The Linux OS provider collects metrics through the Prometheus Node Exporter endpoint, which listens on TCP port 9100 by default. Open port 9100 on VM1.

Question 48

DRAG DROP You have two Azure subscriptions as shown in the following table. You plan to configure the following Azure policies: • Policy1: Enforces resource tags to every resource in both subscriptions. • Policy2: Enables Microsoft Defender for Servers for all existing and future production workloads. You need to identify the scope level to assign each policy. The solution must minimize administrative effort. At which scope level should you assign each policy? To answer, drag the appropriate scope levels to the correct policies. Each scope level may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for AZ-120 question 48 Illustration for AZ-120 question 48
Show Answer
Correct Answer: Policy1: Tenant Root management group Policy2: MG1
Explanation:
The root management group covers both subscriptions with one assignment. MG1 covers the production subscription and future workloads added under that group.

Question 49

HOTSPOT You have an Azure subscription. You plan to deploy SAP HANA to Azure virtual machines by using Azure Center for SAP solutions. The virtual machines will use customized resource names. You need to use the Azure command-line interface (CLI) to deploy the solution. How should you complete the command? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for AZ-120 question 49
Show Answer
Correct Answer: az workloads **sap-virtual-instance** create -g $resourceGroupName -n $resourceName --configuration ./payload.**json**
Explanation:
The SAP virtual instance command creates the solution, and the JSON configuration file supplies the deployment settings, including customized resource names.

Question 50

HOTSPOT For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for AZ-120 question 50
Show Answer
Correct Answer: Yes No Yes
Explanation:
The extension stores performance data in Azure Storage. The Set-AzVMAEMExtension cmdlet is used to enable it on Windows Server, but not on SUSE Linux Enterprise Server.

$19

Get all 299 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.