Microsoft

AZ-140 Free Practice Questions — Page 7

Question 64

You have an Azure subscription that contains an Azure Virtual Desktop host pool. The host pool uses FSLogix profile containers. You need to create a configuration file to prevent specific folders from syncing to the FSLogix profile containers when a user signs out. How should you name the file?

A. profile.xml
B. redirections.xml
C. fslogix.config
D. folders.json
Show Answer
Correct Answer: B
Explanation:
FSLogix uses a file named redirections.xml to define folder and file exclusions for profile containers. It specifies which folders should not be included in the profile container during sign-out, preventing them from syncing.

Question 65

HOTSPOT - You have an Azure subscription that contains a user named User1 and an Azure Virtual Desktop host pool named Pool1. Pool1 contains the session hosts shown in the following table. You have the devices shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for AZ-140 question 65 Illustration for AZ-140 question 65 Illustration for AZ-140 question 65
Show Answer
Correct Answer: Yes Yes No
Explanation:
Watermarking is enabled on both session hosts. Azure Virtual Desktop watermarking is supported through the web client (including on Windows and macOS), but not through the legacy Remote Desktop Connection client (mstsc).

Question 66

HOTSPOT - You have an Azure Virtual Desktop deployment. Users connect to session hosts by using devices enrolled in Microsoft Intune. You need to create a Conditional Access policy named Policy to meet the following requirements: • Require multifactor authentication (MFA) • Require that the devices be marked as compliant. Which settings of Policy1 should you configure for each requirement? To answer, select the appropriate options in the answer area NOTE: Each correct selection is worth one point.

Illustration for AZ-140 question 66
Show Answer
Correct Answer: Require MFA: Grant Require that the devices be marked as compliant: Grant
Explanation:
In Microsoft Entra Conditional Access, both 'Require multifactor authentication' and 'Require device to be marked as compliant' are configured as Grant controls within the policy.

Question 67

You have an Azure subscription that contains two users named User1 and User2 and the Microsoft Entra groups shown in the following table. You have an Azure Virtual Desktop host pool named Pool1 that contains two session hosts named Host1 and Host2. The session hosts use FSLogix user profiles. Host1 contains the local groups shown in the following table. Host2 contains the local groups shown in the following table. User1 connects to Pool and modifies his desktop. User1 reports that when he reconnects to Pool, the desktop modifications fail to appear. You need to ensure that User1 sees the modified desktop when he connects to Pool. The solution must minimize the impact on other user profiles. What should you do?

A. Add User1 to both FSLogix Profile Include list groups.
B. Remove Group2 from both FSLogix Profile Exclude list groups.
C. Remove User1 from Group3.
D. Remove Group3 from Group2.
Show Answer
Correct Answer: C
Explanation:
FSLogix profiles apply to users in the Include group unless they are also members of an Exclude group, with exclusion taking precedence. The scenario asks to restore profile persistence only for User1 while minimizing impact on other users. Removing User1 from the excluded group (Group3) affects only that user. Removing Group2 from the exclude list or changing nested group membership would affect additional users, and adding the user to the Include list would not override exclusion.

Question 68

HOTSPOT - Case study - This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided. To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study. At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section. To start the case study - To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question. Overview - Litware, Inc. is a pharmaceutical company that has a main office in Boston, United States, and a remote office in Chennai, India. Existing Environment. Identity Environment The network contains an on-premises Active Directory domain named litware.com that syncs to a Microsoft Entra tenant named litware.com. The Microsoft Entra tenant contains the users shown in the following table. All users are registered for Azure Multi-Factor Authentication (MFA). Existing Environment. Cloud Services Litware has a Microsoft 365 E5 subscription associated to the Microsoft Entra tenant. All users are assigned Microsoft 365 Enterprise E5 licenses. Litware has an Azure subscription associated to the Microsoft Entra tenant. The subscription contains the resources shown in the following table. Litware uses custom virtual machine images and custom scripts to automatically provision Azure virtual machines and join the virtual machines to the on-premises Active Directory domain. Existing Environment. Network and DNS The offices connect to each other by using a WAN link. Each office connects directly to the internet. All DNS queries for internet hosts are resolved by using DNS servers in the Boston office, which point to root servers on the internet. The Chennai office has caching-only DNS servers that forward queries to the DNS servers in the Boston office. Requirements. Planned Changes - Litware plans to implement the following changes: • Deploy Azure Virtual Desktop environments to the East US Azure region for the users in the Boston office and to the South India Azure region for the users in the Chennai office. • Implement FSLogix profile containers. • Optimize the custom virtual machine images for the Azure Virtual Desktop session hosts. • Use PowerShell to automate the addition of virtual machines to the Azure Virtual Desktop host pools. Requirements. Performance Requirements Litware identifies the following performance requirements: • Minimize network latency of the Azure Virtual Desktop connections from the Boston and Chennai offices. • Minimize latency of the Azure Virtual Desktop host authentication in each Azure region. • Minimize how long it takes to sign in to the Azure Virtual Desktop session hosts. Requirements. Authentication Requirements Litware identifies the following authentication requirements: • Enforce Azure MFA when accessing Azure Virtual Desktop apps. • Force users to reauthenticate if their Azure Virtual Desktop session lasts more than eight hours. Requirements. Security Requirements Litware identifies the following security requirements: • Explicitly allow traffic between the Azure Virtual Desktop session hosts and Microsoft 365. • Explicitly allow traffic between the Azure Virtual Desktop session hosts and the Azure Virtual Desktop infrastructure. • Use built-in groups for delegation. • Delegate the management of app groups to Admin2, including the ability to publish app groups to users and user groups. • Grant Admin1 permissions to manage workspaces, including listing which apps are assigned to the app groups. • Minimize administrative effort to manage network security. • Use the principle of least privilege. Requirements. Deployment Requirements Litware identifies the following deployment requirements: • Use PowerShell to generate the token used to add the virtual machines as session hosts to an Azure Virtual Desktop host pool. • Minimize how long it takes to provision the Azure Virtual Desktop session hosts based on the custom virtual machine images. • Whenever possible, preinstall agents and apps in the custom virtual machine images. User Profile Requirements - Litware identifies the following user profile requirements: • In storage1, store user profiles for the Boston office users. • Ensure that the user profiles for the Boston office users replicate synchronously between two Azure regions. • Ensure that Admin1 uses a local profile only when signing in to the Azure Virtual Desktop session hosts. You need to configure a conditional access policy to meet the authentication requirements. What should you include in the policy configuration? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for AZ-140 question 68 Illustration for AZ-140 question 68 Illustration for AZ-140 question 68
Show Answer
Correct Answer: Target resources: Azure Virtual Desktop Session controls: Sign-in frequency
Explanation:
Apply the Conditional Access policy to the Azure Virtual Desktop cloud app to enforce MFA for AVD access. Use the Sign-in frequency session control and set it to 8 hours to require reauthentication after sessions exceed eight hours.

Question 69

DRAG DROP - You have an Azure Virtual Desktop deployment that contains a host pool named Pool1. You have an MSI installer package named App1. You need to create an MSIX image of App1 and make the image available to Pool1 by using MSIX app attach. Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Illustration for AZ-140 question 69
Show Answer
Correct Answer: Use the MSIX Packaging Tool to convert App1 into an MSIX package. Run msixmgr.exe to convert the MSIX package into a VHDX file. Store the VHDX file in Azure Files. Add the MSIX package to a host pool.
Explanation:
For MSIX app attach, first create an MSIX package, then create the VHDX container using msixmgr, place the VHDX on a network share such as Azure Files, and finally register the package with the Azure Virtual Desktop host pool.

Question 71

HOTSPOT - You have an Azure Virtual Desktop deployment that contains a host pool named Pool1. Pool1 contains five session hosts joined to an Active Directory Domain Services (AD DS) domain. You plan to use the Azure portal to add additional session hosts and specify a custom configuration. Which type of custom configuration should you use, and where should you store the custom configuration? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for AZ-140 question 71
Show Answer
Correct Answer: Bicep file Azure Blob Storage
Explanation:
Azure Virtual Desktop custom configuration for adding session hosts via the Azure portal uses an Azure Resource Manager deployment template, which can be authored as a Bicep file. Store the template in Azure Blob Storage so it can be accessed during deployment.

Question 72

You have an Azure subscription that contains the storage accounts shown in the following table. You deploy Azure Virtual Desktop. All the session hosts in the deployment are joined to Active Directory. You need to implement FSLogix profile containers. Which storage accounts can you use to store the profile containers?

A. storage1 only
B. storage4 only
C. storage1 and storage4 only
D. storage2, storage3, and storage4 only
E. storage1, storage2, storage3, and storage4
Show Answer
Correct Answer: C
Explanation:
FSLogix profile containers require an SMB file share. Azure Files in both standard and premium storage accounts supports SMB and can host FSLogix profile containers. Blob storage (block blobs or page blobs) cannot be used as an SMB-backed FSLogix profile container location. Therefore, the valid storage accounts are the standard Azure Files account and the premium Azure Files account only.

Question 73

HOTSPOT - Your on-premises network contains an Active Directory Domain Services (AD DS) domain named corp.contoso.com. You have an Azure subscription named Sub1. You have a Microsoft Entra tenant that syncs with corp.contoso.com. You plan to deploy Azure Virtual Desktop to Sub1 and configure FSLogix user profiles. You need to provision an Azure Storage account for the user profiles. The solution must maximize resiliency To what should you set Redundancy and Premium account type? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for AZ-140 question 73
Show Answer
Correct Answer: Redundancy: Zone-redundant storage (ZRS) Premium account type: File shares
Explanation:
FSLogix profile containers on Azure Virtual Desktop are supported on Azure Files Premium (SSD). Premium Azure Files supports LRS or ZRS, not GRS. To maximize resiliency for Premium Azure Files, choose ZRS, which replicates across availability zones within the region.

Question 74

You have an Azure Virtual Desktop deployment that contains a host pool named Pool1. Pool1 contains session hosts that are joined to a Microsoft Entra Domain Services managed domain. The domain contains a user named User1. You configure AADDC Computers GPO as shown in the following table. You configure AADDC Users GPO as shown in the following table. How long after connecting to a session host will User1 be disconnected?

A. 2 hours
B. 3 hours
C. 6 hours
D. 8 hours
Show Answer
Correct Answer: A
Explanation:
Azure Virtual Desktop session time limits are enforced through Computer Configuration Group Policy settings on the session host. User Configuration session limit settings do not apply to Remote Desktop session host behavior in this scenario. Therefore, the effective disconnect limit is the Computer Configuration value of 2 hours.

$19

Get all 320 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.