You have an Azure subscription. The subscription contains two virtual machines that host an SAP workload.
You need to protect the workload by using Azure Site Recovery. The solution must meet the following requirements:
• Support shared application-consistent recovery points.
• Support shared crash-consistent recovery points.
• Minimize administrative effort.
What should you create?
A. an Azure Automation runbook
B. a replication group
C. an Azure shared disk
D. an Azure Automation workflow
Show Answer
Correct Answer: B
Explanation: Create a replication group. Azure Site Recovery replication groups let multiple VMs be included in a multi-VM consistency group, so they can share application-consistent and crash-consistent recovery points. This provides coordinated recovery with less administrative effort than managing the VMs independently.
Question 42
DRAG DROP
You have an SAP Fiori single sign-on (SSO)-enabled subscription.
You have an Azure subscription that is linked to a Microsoft Entra tenant named contoso.com.
You need to configure SSO authentication between SAP Fiori and contoso.com.
Which five actions should you perform in sequence in the Microsoft Entra admin center? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Show Answer
Correct Answer: 1. Add an enterprise application from the gallery.
2. Select SAML as the SSO method.
3. Upload the metadata file and provide the sign-in URL.
4. Update the user claims.
5. Download the federation metadata file.
Explanation: Configure SAP Fiori as a SAML enterprise application, then set its service-provider details and claims. Download the Microsoft Entra federation metadata after those settings are configured.
Question 43
HOTSPOT
You have an Azure subscription that contains an Azure NetApp Files account named account1 and an SAP HANA deployment.
In account1, you create a capacity pool named pool1 that has the following configurations:
• Quality of Service (QoS) type: Auto
• Service level: Premium
• Size: 4 TB
In account1, you create a volume named volume1 that has the following configurations:
• Network features: Standard
• Protocol: Dual-protocol
• Quota: 500 GB
You need configure pool1 and volume1 to support an application volume group for the HANA deployment.
What should you modify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: For pool1: QoS type
For volume1: Protocol
Explanation: An SAP HANA application volume group requires a manual-QoS capacity pool and NFS volumes. Change pool1 from Auto to Manual QoS and volume1 from dual-protocol to NFS.
Question 44
You have an SAP production landscape in Azure. The landscape is hosted on 50 virtual machines that run SUSE Enterprise Linux (SLES). The virtual machines are billed by using pay-as-you-go rates.
You need to minimize operating system costs for the virtual machines.
What should you use?
A. capacity reservations
B. Azure Hybrid Benefit
C. reserved instances
D. spot pricing
Show Answer
Correct Answer: B
Explanation: Azure Hybrid Benefit for Linux lets you use eligible SUSE subscriptions for SLES VMs, replacing the pay-as-you-go OS software charge. Reserved instances reduce compute costs, not specifically OS costs.
Sources:
https://learn.microsoft.com/en-us/azure/virtual-machines/linux/azure-hybrid-benefit-linux?tabs=ahbNewPortal%2CahbExistingPortal%2Clicenseazcli%2Crhelpaygreqs%2CrhelAzcliByosConv%2Cpaygclisingle%2Crhelpaygconversion%2Crhelcompliance
Question 45
You have an SAP workload on an Azure virtual machine.
You have a built-in role-based access control (RBAC) role definition in the JSON format.
You plan to change the built-in role definition to a custom role definition.
Which property value in the built-in role definition must you change?
A. assignableScopes
B. notActions
C. roleName
D. actions
Show Answer
Correct Answer: C
Explanation: Change `roleName` to a unique name for the custom role. The `actions` and `notActions` values define its permissions and only need changing if you want different permissions.
Question 46
HOTSPOT
You have an Azure subscription. The subscription contains two virtual machines named SQL1 and SQL2 that host a Microsoft SQL Server 2019 Always On availability group named AOG1.
You plan to deploy an SAP NetWeaver system that will have a database tier hosted on AOG1.
You need to encrypt the Azure virtual machine disks and the SQL Server database. The solution must meet the following requirements:
• The operating system disk, data disk, and the temporary disk of the virtual machines must be encrypted.
• SQL Server encryption keys must be stored on-premises.
Which type of encryption should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct select ion is worth one point.
Show Answer
Correct Answer: For the virtual machine disks: Encryption at host
For the SQL Server database: Transparent Data Encryption (TDE)
Explanation: Encryption at host covers the OS, data, and temporary disks. TDE encrypts the SQL Server database; its protecting key can be managed in an on-premises key store through Extensible Key Management.
Question 47
You have an Azure subscription that contains a virtual machine named VM1. VM1 runs SUSE Linux Enterprise Server (SLES) and hosts an SAP workload.
You deploy Azure Monitor for SAP solutions.
You need to configure the Linux OS provider. The solution must ensure that you can collect monitoring data by using the Prometheus endpoint on VM1.
Which firewall port should you open on VM1?
A. 22
B. 80
C. 443
D. 9100
Show Answer
Correct Answer: D
Explanation: The Linux OS provider collects metrics through the Prometheus Node Exporter endpoint, which listens on TCP port 9100 by default. Open port 9100 on VM1.
Question 48
DRAG DROP
You have two Azure subscriptions as shown in the following table.
You plan to configure the following Azure policies:
• Policy1: Enforces resource tags to every resource in both subscriptions.
• Policy2: Enables Microsoft Defender for Servers for all existing and future production workloads.
You need to identify the scope level to assign each policy. The solution must minimize administrative effort.
At which scope level should you assign each policy? To answer, drag the appropriate scope levels to the correct policies. Each scope level may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Policy1: Tenant Root management group
Policy2: MG1
Explanation: The root management group covers both subscriptions with one assignment. MG1 covers the production subscription and future workloads added under that group.
Question 49
HOTSPOT
You have an Azure subscription.
You plan to deploy SAP HANA to Azure virtual machines by using Azure Center for SAP solutions. The virtual machines will use customized resource names.
You need to use the Azure command-line interface (CLI) to deploy the solution.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: The SAP virtual instance command creates the solution, and the JSON configuration file supplies the deployment settings, including customized resource names.
Question 50
HOTSPOT
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
Yes
Explanation: The extension stores performance data in Azure Storage. The Set-AzVMAEMExtension cmdlet is used to enable it on Windows Server, but not on SUSE Linux Enterprise Server.
$19
Get all 299 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.