You have an Azure Virtual Desktop deployment that contains a host pool named Pool1.
Pool1 contains a session host named Host1 that is Azure AD-joined.
You need to verify whether a Windows license is assigned to Host1.
What should you do?
A. From the Azure Active Directory admin center, view the product licenses.
B. From VM1, run the Get-WindowsDeveloperLicense cmdlet.
C. From the Azure portal, view the properties of Host1.
D. From Azure Cloud Shell, run the Get-AzVm cmdlet.
Show Answer
Correct Answer: D
Explanation: For Azure Virtual Desktop session hosts, Windows licensing (including AVD Windows client licensing or Hybrid Use Benefit) is reflected in the VM object's LicenseType property. Running Get-AzVM from Azure Cloud Shell allows you to view this property directly and verify whether a Windows license is assigned. The Azure portal VM properties do not reliably display this licensing detail, and Azure AD license views or local cmdlets are not applicable.
Question 151
HOTSPOT -
You have an Azure subscription that contains the storage accounts shown in the following table.
The subscription contains the vaults shown in the following table.
The subscription contains the Azure Virtual Desktop host pools shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
No
Explanation: FSLogix profiles are Azure Files backups and must use a Recovery Services vault in the same region.
Pool1 uses share1 in West US, but Vault1 is in East US → not supported.
Pool2 uses share2 in West US and Vault2 is a Recovery Services vault in West US → supported.
Session host P3-0 is a VM and cannot be backed up to a Backup vault; VMs require a Recovery Services vault.
Question 152
DRAG DROP
-
You have an Azure Virtual Desktop deployment and the Azure Storage accounts shown in the following table.
You plan to create FSLogix profile containers and store the containers in the storage accounts.
You need to identify which storage accounts support the FSLogix profile containers, and then order the accounts from highest to lowest redundancy.
Which three storage accounts should you identify in sequence? To answer, move the appropriate accounts from the list of accounts to the answer area and arrange them in the correct order.
Show Answer
Correct Answer: storage1
storage5
storage2
Explanation: FSLogix profile containers require Azure Files, supported by StorageV2 (standard) and Azure Files Premium; Blob-only accounts are not supported.
Redundancy ranking: GRS (replicates to paired region) > ZRS (replicates across zones in a region) > LRS (replicates within a single datacenter).
Question 153
HOTSPOT
-
You have an Azure Virtual Desktop deployment that has just-in-time (JIT) VM access enabled.
You need to request access to a session host by using JIT VM access.
Which three virtual machine settings can you use to request access? To answer, select the appropriate settings in the answer area.
NOTE: Each selection is worth one point.
Show Answer
Correct Answer: Connect
Microsoft Defender for Cloud
Configuration
Explanation: JIT VM access requests can be made from the VM Connect page, from Microsoft Defender for Cloud where JIT is managed, and from the VM Configuration blade where JIT access is enabled and requested.
Question 154
HOTSPOT
-
You have an Azure Virtual Desktop host pool that contains 20 Windows 11 session hosts.
You create a Windows Defender Application Control (WDAC) policy named Policy1.xml.
You need to deploy Policy1.xml to the session hosts.
How should you prepare the policy, and to where should you copy the policy? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Convert Policy1.xml to its binary form.
C:\Windows\System32\CodeIntegrity\CiPolicies\Active
Explanation: WDAC policies must be converted from XML to a compiled binary (.cip) format before deployment. Active WDAC policies are applied by copying the binary policy file to the CodeIntegrity\CiPolicies\Active directory on each session host.
Question 155
You have an Azure Virtual Desktop deployment that contains a host pool named Pool1. Pool1 contains two session hosts named Host1 and Host2.
You need to enable screen capture protection for the deployment.
What should you do?
A. Configure a Group Policy setting on Host1 and Host2.
B. From RDP Properties for Pool1, disable Clipboard redirection.
C. Install an Azure virtual machine extension on Host1 and Host2.
D. From RDP Properties for Pool1, disable encoding of redirected video.
Show Answer
Correct Answer: A
Explanation: Screen capture protection in Azure Virtual Desktop is enabled on the session hosts by configuring the Screen Capture Protection policy via Group Policy (local GPO, domain GPO, or Intune-delivered policy). It is not controlled by RDP properties like clipboard or video encoding, and there is no Azure VM extension specifically for this feature.
Question 156
Case study -
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study -
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview -
Contoso, Ltd. is a law firm that has a main office in Montreal and branch offices in Paris and Seattle. The Seattle branch office opened recently.
Contoso has an Azure subscription and uses Microsoft 365.
Existing Infrastructure. Active Directory
The network contains an on-premises Active Directory domain named contoso.com and an Azure Active Directory (Azure AD) tenant. One of the domain controllers runs as an Azure virtual machine and connects to a virtual network named VNET1. All internal name resolution is provided by DNS server that run on the domain controllers.
The on-premises Active Directory domain contains the organizational units (OUs) shown in the following table.
The on-premises Active Directory domain contains the users shown in the following table.
The Azure AD tenant contains the cloud-only users shown in the following table.
Existing Infrastructure. Network Infrastructure
All the Azure virtual networks are peered. The on-premises network connects to the virtual networks.
A virtual network named VNET4 was recently created are peered to the other virtual networks. VNET4 does NOT contain any AVD virtual machines.
All servers run Windows Server 2019. All laptops and desktop computers run Windows 10 Enterprise.
Since users often work on confidential documents, all the users use their computer as a client for connecting to Remote Desktop Services (RDS).
In the West US Azure region, you have the storage accounts shown in the following table.
Existing Infrastructure. Remote Desktop Infrastructure
Contoso has a Remote Desktop infrastructure shown in the following table.
Requirements. Planned Changes -
Contoso plans to implement the following changes:
• Implement FSLogix profile containers for the Paris offices.
• Deploy an Azure Virtual Desktop host pool named Pool4.
• Migrate the RDS deployment in the Seattle office to Azure Virtual Desktop in the West US Azure region.
Requirements. Pool4 Configuration
Pool4 will have the following settings:
• Host pool type: Pooled
• Max session limit: 7
• Load balancing algorithm: Depth-first
• Images: Windows 10 Enterprise multi-session
• Virtual machine size: Standard D2s v3
• Name prefix: Pool4
• Number of VMs: 5
• Virtual network: VNET4
Requirements. Technical Requirements
Contoso identifies the following technical requirements:
• Before migrating the RDS deployment in the Seattle office, obtain the recommended deployment configuration based on the current RDS utilization.
• For the Azure Virtual Desktop deployment in the Montreal office, disable audio output in the device redirection settings.
• For the Azure Virtual Desktop deployment in the Seattle office, store the FSLogix profile containers in Azure Storage.
• Enable Operator2 to modify the RDP Properties of the Azure Virtual Desktop deployment in the Montreal office.
• From a server named Server1, convert the user profile disks to the FSLogix profile containers.
• Ensure that the Pool1 virtual machines only run during business hours.
• Use the principle of least privilege.
You need to configure the virtual machines that have the Pool1 prefix. The solution must meet the technical requirements.
What should you use?
A. an Azure Virtual Desktop automation task
B. Access control (IAM)
C. Service Health in Azure Monitor
D. Azure Automation
Show Answer
Correct Answer: D
Explanation: The requirement is to ensure that the Pool1 virtual machines run only during business hours. Azure Automation can use schedules and runbooks to automatically start and stop virtual machines based on time, meeting this requirement. It supports least-privilege access via managed identities and RBAC and is the recommended approach for VM lifecycle automation. The other options do not provide VM start/stop scheduling capabilities.
Question 157
HOTSPOT
-
Case study
-
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study
-
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview
-
Litware, Inc. is a pharmaceutical company that has a main office in Boston, United States, and a remote office in Chennai, India.
Existing Environment. Identity Environment
The network contains an on-premises Active Directory domain named litware.com that syncs to an Azure Active Directory (Azure AD) tenant named litware.com.
The Azure AD tenant contains the users shown in the following table.
All users are registered for Azure Multi-Factor Authentication (MFA).
Existing Environment. Cloud Services
Litware has a Microsoft 365 E5 subscription associated to the Azure AD tenant. All users are assigned Microsoft 365 Enterprise E5 licenses.
Litware has an Azure subscription associated to the Azure AD tenant. The subscription contains the resources shown in the following table.
Litware uses custom virtual machine images and custom scripts to automatically provision Azure virtual machines and join the virtual machines to the on-premises Active Directory domain.
Existing Environment. Network and DNS
The offices connect to each other by using a WAN link. Each office connects directly to the internet.
All DNS queries for internet hosts are resolved by using DNS servers in the Boston office, which point to root servers on the internet. The Chennai office has caching-only DNS servers that forward queries to the DNS servers in the Boston office.
Requirements. Planned Changes
-
Litware plans to implement the following changes:
• Deploy Azure Virtual Desktop environments to the East US Azure region for the users in the Boston office and to the South India Azure region for the users in the Chennai office.
• Implement FSLogix profile containers.
• Optimize the custom virtual machine images for the Azure Virtual Desktop session hosts.
• Use PowerShell to automate the addition of virtual machines to the Azure Virtual Desktop host pools.
Requirements. Performance Requirements
Litware identifies the following performance requirements:
• Minimize network latency of the Azure Virtual Desktop connections from the Boston and Chennai offices.
• Minimize latency of the Azure Virtual Desktop host authentication in each Azure region.
• Minimize how long it takes to sign in to the Azure Virtual Desktop session hosts.
Requirements. Authentication Requirements
Litware identifies the following authentication requirements:
• Enforce Azure MFA when accessing Azure Virtual Desktop apps.
• Force users to reauthenticate if their Azure Virtual Desktop session lasts more than eight hours.
Requirements. Security Requirements
Litware identifies the following security requirements:
• Explicitly allow traffic between the Azure Virtual Desktop session hosts and Microsoft 365.
• Explicitly allow traffic between the Azure Virtual Desktop session hosts and the Azure Virtual Desktop infrastructure.
• Use built-in groups for delegation.
• Delegate the management of app groups to Admin2, including the ability to publish app groups to users and user groups.
• Grant Admin1 permissions to manage workspaces, including listing which apps are assigned to the app groups.
• Minimize administrative effort to manage network security.
• Use the principle of least privilege.
Requirements. Deployment Requirements
Litware identifies the following deployment requirements:
• Use PowerShell to generate the token used to add the virtual machines as session hosts to an Azure Virtual Desktop host pool.
• Minimize how long it takes to provision the Azure Virtual Desktop session hosts based on the custom virtual machine images.
• Whenever possible, preinstall agents and apps in the custom virtual machine images.
User Profile Requirements
-
Litware identifies the following user profile requirements:
• In storage1, store user profiles for the Boston office users.
• Ensure that the user profiles for the Boston office users replicate synchronously between two Azure regions.
• Ensure that Admin1 uses a local profile only when signing in to the Azure Virtual Desktop session hosts.
You need to configure a conditional access policy to meet the authentication requirements.
What should you include in the policy configuration? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Set Cloud apps or actions to include:
Windows Virtual Desktop
Set Session controls to include:
Sign-in frequency
Explanation: Azure Virtual Desktop is the cloud app used to control access to AVD resources. Configuring a sign-in frequency session control enforces reauthentication after a defined period (eight hours), satisfying the authentication requirements. MFA enforcement is applied through Conditional Access to the Windows Virtual Desktop app.
Question 158
You have an Azure AD tenant that contains a resource group named RG1. RG1 contains the resources shown in the following table.
Your on-premises network has an IP address range of 192.168.10.0/24. Users on Host1 can successfully connect to the resources on the network.
You add a new on-premises network that has an IP address range of 192.168.11.0/24 and contains a subnet. The subnet contains an application server named App1.
Users report that Host1 cannot connect to App1.
You need to ensure that the users on Host1 can access App1.
What should you modify?
A. the Connections settings of VPNGW1
B. the Subnets setting of VNet1
C. the Configuration settings of LNGW1
D. the DNS server settings of VNet1
E. the RDP Properties of the host pool
Show Answer
Correct Answer: C
Explanation: The local network gateway (LNGW1) defines the on‑premises address spaces that Azure routes to over the site‑to‑site VPN. After adding a new on‑premises network (192.168.11.0/24), LNGW1 must be updated to include this new address range; otherwise, traffic from Azure/Host1 will not be routed to App1.
Question 159
HOTSPOT
-
You have an Azure Virtual Desktop deployment that contains two Azure AD-joined session hosts named Host1 and Host2.
FSLogix Profile Containers and Office Containers have different locations and are used for both session hosts.
You have an Azure AD tenant that contains the users shown in the following table.
Host1 contains the local groups shown in the following table.
Host2 contains the local groups shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
No
Yes
Explanation: FSLogix rules apply per host and per container, with Exclude taking priority over Include.
1) On Host1, User1 is in Group3, which is in the ODFC Exclude list, so no Office Container is used.
2) Office settings roam only with the Office Container; User2 does not have an applicable Office Container across both hosts, so changes on Host1 do not apply to Host2.
3) Desktop shortcuts roam with the Profile Container; User3 is included for profiles on both hosts, so the shortcut appears on Host2.
$19
Get all 321 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.