Case study -
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study -
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview -
Northwind Traders is a manufacturing company based in New York City.
Existing Environment -
Identity Environment -
The on-premises network contains an Active Directory Domain Services (AD DS) domain named northwindtraders.com.
Northwind Traders has a Microsoft Entra tenant and a Microsoft Entra Domain Services managed domain. The northwindtraders.com domain syncs with the Microsoft Entra tenant.
Virtual Machines -
The company has an on-premises Hyper-V virtual machine named VM1 that has the following configurations:
• Generation: 1
• Disk size: 2 TB
• Disk format: VHDX
• Disk type: Dynamically expanding
Cloud Services -
Northwind Traders has a Microsoft 365 E5 subscription. The subscription contains 500 users that are assigned Microsoft 365 E5 licenses.
The company has an Azure subscription that contains the resources shown in the following table.
Both subscriptions are linked to the Microsoft Entra tenant.
Requirements -
Planned Changes -
Northwind Traders identifies the following planned changes:
• Deploy an Azure Virtual Desktop host pool that will contain 10 session hosts joined to the Microsoft Entra Domain Services managed domain.
• Configure VM1 as the source image for the Azure Virtual Desktop deployment and upload the image to Azure.
• The Azure Virtual Desktop deployment will provide access to a custom app named App1.
Performance Requirements -
Northwind Traders identifies the following performance requirements:
• Each Azure Virtual Desktop session host must support 15 user sessions.
• Each new user session must be assigned to a single session host until the maximum session limit is reached for that host.
Application Requirements -
Northwind Traders identifies the following application requirements:
• Microsoft OneDrive must launch when users connect to a RemoteApp session in Azure Virtual Desktop.
• App1 requires a desktop resolution of 1280 x 1024.
• Administrative effort must be minimized.
Disaster Recovery Requirements -
Northwind Traders identifies the following disaster recovery requirements for the Azure Virtual Desktop deployment:
• Minimize outages if an Azure region fails.
• Minimize the recovery time objective (RTO).
• Minimize administrative effort in the event of a failover.
Security Requirements -
Northwind Traders identifies the following security requirements:
• When users sign in to the Azure Virtual Desktop deployment by using the Azure Virtual Desktop client, they must authenticate by using their Microsoft Entra username and password only.
• When users sign in to the Azure Virtual Desktop deployment by using a web browser, they must authenticate by using the Microsoft Authenticator app.
• All the Azure Virtual Desktop session hosts deployed by using the VM1 source image must be onboarded to Microsoft Defender for Endpoint.
• The client version and operating system used to connect to the session hosts must be logged.
• The solution must follow the principle of least privilege.
Networking Requirements -
The Azure Virtual Desktop session hosts must be able to access the resources on the on-premises network.
User Profile Requirements -
Northwind Traders identifies the following user profile requirements:
• Users must be able to access share1 by using their Microsoft Entra account.
• Azure Virtual Desktop user profiles must be managed by using FSLogix.
• All user profiles must be stored in share1.
What should you configure to meet the networking requirements?
A. a Site-to-Site (S2S) VPN connection
B. an on-premises data gateway
C. the Networking settings for the host pool
D. a Point-to-Site (P2S) VPN connection
Show Answer
Correct Answer: A
Explanation: Azure Virtual Desktop session hosts need private network connectivity to on-premises resources. A Site-to-Site VPN connects the Azure virtual network hosting the session hosts to the on-premises network, enabling continuous connectivity. A Point-to-Site VPN is for individual clients, an on-premises data gateway is for specific Azure service access rather than general network connectivity, and host pool networking settings do not provide hybrid connectivity.
Question 34
Case study -
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study -
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview -
Northwind Traders is a manufacturing company based in New York City.
Existing Environment -
Identity Environment -
The on-premises network contains an Active Directory Domain Services (AD DS) domain named northwindtraders.com.
Northwind Traders has a Microsoft Entra tenant and a Microsoft Entra Domain Services managed domain. The northwindtraders.com domain syncs with the Microsoft Entra tenant.
Virtual Machines -
The company has an on-premises Hyper-V virtual machine named VM1 that has the following configurations:
• Generation: 1
• Disk size: 2 TB
• Disk format: VHDX
• Disk type: Dynamically expanding
Cloud Services -
Northwind Traders has a Microsoft 365 E5 subscription. The subscription contains 500 users that are assigned Microsoft 365 E5 licenses.
The company has an Azure subscription that contains the resources shown in the following table.
Both subscriptions are linked to the Microsoft Entra tenant.
Requirements -
Planned Changes -
Northwind Traders identifies the following planned changes:
• Deploy an Azure Virtual Desktop host pool that will contain 10 session hosts joined to the Microsoft Entra Domain Services managed domain.
• Configure VM1 as the source image for the Azure Virtual Desktop deployment and upload the image to Azure.
• The Azure Virtual Desktop deployment will provide access to a custom app named App1.
Performance Requirements -
Northwind Traders identifies the following performance requirements:
• Each Azure Virtual Desktop session host must support 15 user sessions.
• Each new user session must be assigned to a single session host until the maximum session limit is reached for that host.
Application Requirements -
Northwind Traders identifies the following application requirements:
• Microsoft OneDrive must launch when users connect to a RemoteApp session in Azure Virtual Desktop.
• App1 requires a desktop resolution of 1280 x 1024.
• Administrative effort must be minimized.
Disaster Recovery Requirements -
Northwind Traders identifies the following disaster recovery requirements for the Azure Virtual Desktop deployment:
• Minimize outages if an Azure region fails.
• Minimize the recovery time objective (RTO).
• Minimize administrative effort in the event of a failover.
Security Requirements -
Northwind Traders identifies the following security requirements:
• When users sign in to the Azure Virtual Desktop deployment by using the Azure Virtual Desktop client, they must authenticate by using their Microsoft Entra username and password only.
• When users sign in to the Azure Virtual Desktop deployment by using a web browser, they must authenticate by using the Microsoft Authenticator app.
• All the Azure Virtual Desktop session hosts deployed by using the VM1 source image must be onboarded to Microsoft Defender for Endpoint.
• The client version and operating system used to connect to the session hosts must be logged.
• The solution must follow the principle of least privilege.
Networking Requirements -
The Azure Virtual Desktop session hosts must be able to access the resources on the on-premises network.
User Profile Requirements -
Northwind Traders identifies the following user profile requirements:
• Users must be able to access share1 by using their Microsoft Entra account.
• Azure Virtual Desktop user profiles must be managed by using FSLogix.
• All user profiles must be stored in share1.
You need to prepare the disk on VM1 for use with the Azure Virtual Desktop deployment.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Convert the disk format to VHD.
B. Compact the disk.
C. Convert the disk type to Differencing.
D. Convert the disk type to Fixed size.
E. Merge the disk.
Show Answer
Correct Answer: A, D
Explanation: To use an on-premises Hyper-V VM as the source image for Azure Virtual Desktop, the virtual hard disk must be in the VHD format because Azure does not support uploading VHDX images. In addition, Azure requires the uploaded VHD to be a fixed-size disk, not a dynamically expanding disk. Therefore, convert the disk from VHDX to VHD and from dynamically expanding to fixed size.
Question 35
You have a Microsoft 365 E5 subscription.
You have an Azure subscription.
You plan to deploy the Azure Virtual Desktop host pools shown in the following table.
What is the maximum number of users that can connect simultaneously to the Azure Virtual Desktop deployment?
A. 15
B. 23
C. 45
D. 60
Show Answer
Correct Answer: D
Explanation: The maximum simultaneous users is the sum of the capacities of all host pools. For pooled host pools, capacity equals the number of session hosts multiplied by the configured maximum sessions per host. For the personal host pool, each personal session host supports one user. Using the given values: Pool 1 = 5 × 6 = 30 users, Pool 2 = 3 × 5 = 15 users, Pool 3 = 15 personal hosts = 15 users. Total = 30 + 15 + 15 = 60 simultaneous users.
Question 36
You have an Azure subscription that contains an Azure Virtual Desktop deployment, a standard Azure Firewall instance named FW1, and the virtual networks shown in the following table.
You need to configure VNet2 to route all outbound traffic via FW1. The solution must minimize the impact on the Azure Virtual Desktop deployment.
What should you do first?
A. Upgrade FW1 to the Premium SKU.
B. Deploy Azure NAT Gateway to VNet1.
C. For FW1, enable DNS Proxy.
D. Deploy Azure Route Server to VNet2.
Show Answer
Correct Answer: C
Explanation: To force outbound traffic from Azure Virtual Desktop session hosts through Azure Firewall with minimal impact, Azure Firewall should have DNS Proxy enabled before redirecting traffic. This helps ensure consistent DNS resolution and supports FQDN-based firewall rules required by Azure Virtual Desktop. The other options (Premium SKU, NAT Gateway, Route Server) are not the prerequisite for this scenario. Routing itself is typically completed later with peering and a UDR.
Sources:
https://learn.microsoft.com/en-us/azure/firewall/protect-azure-virtual-desktop?toc=%2Fazure%2Fvirtual-desktop%2Ftoc.json&bc=%2Fazure%2Fvirtual-desktop%2Fbreadcrumb%2Ftoc.json
Question 37
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains a virtual network named VNet1, a storage account named storage1, and five Azure Virtual Desktop session hosts. VNet1 and storage1 are in the East US Azure region. The session hosts are connected to VNet1.
In storage1, you create an Azure Files share named share1.
You need to ensure that the session hosts connect to share1 by using the Microsoft backbone network.
Solution: You add a private endpoint to storage1.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: A
Explanation: Adding a private endpoint to the storage account allows Azure Files traffic from resources in the virtual network to reach the storage account over a private IP using the Microsoft backbone network. Since the session hosts are connected to the same virtual network, they can access the file share privately, meeting the stated goal.
Question 38
You have an Azure subscription that contains an Azure Virtual Desktop host pool named Pool1. All the session hosts in Pool1 are Microsoft Entra joined.
Users connect to Pool1 by using macOS devices.
You need to ensure that remote users can authenticate to RemoteApp sessions by using their Microsoft Entra credentials.
Which RDP property should you configure?
A. targetisaadjoined:i:1
B. enablerdsaadauth:i:1
C. authentication level:i:1
D. promptcredentialonce:i:0
Show Answer
Correct Answer: A
Explanation: For Azure Virtual Desktop with Microsoft Entra joined session hosts accessed from macOS clients, the required custom RDP property is `targetisaadjoined:i:1`. This enables Microsoft Entra authentication for non-Windows clients connecting to Entra-joined session hosts. Although `enablerdsaadauth` is the newer property, Microsoft Learn guidance for macOS access to Entra-joined Azure Virtual Desktop session hosts specifies `targetisaadjoined:i:1` in this scenario.
Sources:
https://learn.microsoft.com/en-us/azure/virtual-desktop/azure-ad-joined-session-hosts
https://learn.microsoft.com/en-us/answers/questions/5819096/unable-to-access-azure-virtual-desktop-using-rdp
Question 39
You have an Azure Virtual Desktop deployment that contains the resources shown in the following table.
You need to ensure that users can connect to a session host in the deallocated state.
On which resources can you enable Start VM on Connect?
A. Workspace1 only
B. Azure virtual machines
C. P1-0 and P1-1
D. Pool1 only
Show Answer
Correct Answer: D
Explanation: Start VM on Connect is enabled at the Azure Virtual Desktop host pool level. When enabled on a host pool, users connecting to a deallocated session host in that pool can trigger the VM to start automatically. It is not configured on the workspace, individual application groups, or directly on the virtual machines.
Question 40
Case study -
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study -
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview -
Northwind Traders is a manufacturing company based in New York City.
Existing Environment -
Identity Environment -
The on-premises network contains an Active Directory Domain Services (AD DS) domain named northwindtraders.com.
Northwind Traders has a Microsoft Entra tenant and a Microsoft Entra Domain Services managed domain. The northwindtraders.com domain syncs with the Microsoft Entra tenant.
Virtual Machines -
The company has an on-premises Hyper-V virtual machine named VM1 that has the following configurations:
• Generation: 1
• Disk size: 2 TB
• Disk format: VHDX
• Disk type: Dynamically expanding
Cloud Services -
Northwind Traders has a Microsoft 365 E5 subscription. The subscription contains 500 users that are assigned Microsoft 365 E5 licenses.
The company has an Azure subscription that contains the resources shown in the following table.
Both subscriptions are linked to the Microsoft Entra tenant.
Requirements -
Planned Changes -
Northwind Traders identifies the following planned changes:
• Deploy an Azure Virtual Desktop host pool that will contain 10 session hosts joined to the Microsoft Entra Domain Services managed domain.
• Configure VM1 as the source image for the Azure Virtual Desktop deployment and upload the image to Azure.
• The Azure Virtual Desktop deployment will provide access to a custom app named App1.
Performance Requirements -
Northwind Traders identifies the following performance requirements:
• Each Azure Virtual Desktop session host must support 15 user sessions.
• Each new user session must be assigned to a single session host until the maximum session limit is reached for that host.
Application Requirements -
Northwind Traders identifies the following application requirements:
• Microsoft OneDrive must launch when users connect to a RemoteApp session in Azure Virtual Desktop.
• App1 requires a desktop resolution of 1280 x 1024.
• Administrative effort must be minimized.
Disaster Recovery Requirements -
Northwind Traders identifies the following disaster recovery requirements for the Azure Virtual Desktop deployment:
• Minimize outages if an Azure region fails.
• Minimize the recovery time objective (RTO).
• Minimize administrative effort in the event of a failover.
Security Requirements -
Northwind Traders identifies the following security requirements:
• When users sign in to the Azure Virtual Desktop deployment by using the Azure Virtual Desktop client, they must authenticate by using their Microsoft Entra username and password only.
• When users sign in to the Azure Virtual Desktop deployment by using a web browser, they must authenticate by using the Microsoft Authenticator app.
• All the Azure Virtual Desktop session hosts deployed by using the VM1 source image must be onboarded to Microsoft Defender for Endpoint.
• The client version and operating system used to connect to the session hosts must be logged.
• The solution must follow the principle of least privilege.
Networking Requirements -
The Azure Virtual Desktop session hosts must be able to access the resources on the on-premises network.
User Profile Requirements -
Northwind Traders identifies the following user profile requirements:
• Users must be able to access share1 by using their Microsoft Entra account.
• Azure Virtual Desktop user profiles must be managed by using FSLogix.
• All user profiles must be stored in share1.
Which monitoring solution should you configure to meet the security requirements?
A. Azure Virtual Desktop Insights
B. Application Insights
C. VM insights
D. Azure Monitor activity log insights
Show Answer
Correct Answer: A
Explanation: Azure Virtual Desktop Insights provides monitoring and connection analytics for Azure Virtual Desktop, including client details such as client version and operating system used to connect to session hosts. This directly satisfies the requirement to log the client version and operating system. Application Insights monitors applications, VM insights focuses on VM performance, and Azure Monitor activity log insights tracks Azure control-plane operations rather than AVD client connection details.
Question 41
HOTSPOT
-
You have an Azure subscription that contains an Azure Virtual Desktop deployment. All the session hosts in the deployment are joined to Active Directory.
You plan to implement Quality of Service (QoS) for the deployment by using Group Policy
You need to configure a QoS policy that will tag Remote Desktop Services (RDS) traffic for Expedited Forwarding (EF).
Which DSCP value should you specify, and which executable should you tag? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: Expedited Forwarding (EF) uses DSCP value 46. For Azure Virtual Desktop/RDS QoS Group Policy, the RDP traffic is tagged by creating the policy for svchost.exe hosting the Remote Desktop Services components.
Question 42
You have an on-premises Windows device named Device1.
You have an Azure Virtual Desktop host pool named Pool1 that contains Windows 11 session hosts.
You create an application group named AppGrp1. You have an app named App1. App1 is added to AppGrp1 and published as a RemoteApp.
You need to ensure that when a user on Device1 connects to App1, Microsoft OneDrive launches.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Add an assignment to AppGrp1.
B. For Device1, configure the HKLM\Software\Microsoft\Windows\CurrentVersion\Run\OneDrive registry key.
C. For the session hosts, configure the HKLM\Software\Microsoft\Windows\CurrentVersion\Run\OneDrive registry key.
D. For Pool1, configure the Advanced settings in RDP Properties.
E. For Device1, configure the Enable enhanced shell experience for RemoteApp Group Policy setting.
F. For the session hosts, configure the Enable enhanced shell experience for RemoteApp Group Policy setting.
Show Answer
Correct Answer: C, F
Explanation: To have OneDrive launch with an Azure Virtual Desktop RemoteApp session, configure the OneDrive Run registry key on the session hosts and enable the Enhanced shell experience for RemoteApp Group Policy on the session hosts. The enhanced shell experience enables processing of Run/RunOnce keys in RemoteApp sessions, allowing OneDrive to start. Configuring the client device is not sufficient, and assigning the app group is unrelated to OneDrive startup.
$19
Get all 320 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.