Microsoft

AZ-140 Free Practice Questions — Page 7

Question 53

DRAG DROP - You have an Azure subscription that contains a Bicep file named AVD.bicep. You plan to use AVD.bicep to deploy Azure Virtual Desktop. Which commands should you run in sequence? To answer, drag the appropriate commands to the correct order. Each command may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for AZ-140 question 53
Show Answer
Correct Answer: Step 1: az bicep install Step 2: az group create Step 3: az deployment group create
Explanation:
Install the Bicep CLI, create the target resource group, then deploy the existing Bicep file to the resource group using a group deployment. Building or publishing the Bicep file is not required for direct deployment.

Question 54

You have an Azure Virtual Desktop deployment. You plan to deploy the host pools shown in the following table. For which host pools can you configure a load-balancing algorithm?

A. Pool1 and Pool3 only
B. Pool1 and Pool4 only
C. Pool2 and Pool3 only
D. Pool1, Pool2, and Pool3 only
E. Pool1, Pool2, Pool3, and Pool4
Show Answer
Correct Answer: B
Explanation:
In Azure Virtual Desktop, load-balancing algorithms (Breadth-first or Depth-first) can be configured only for **pooled** host pools. **Personal** host pools have a 1:1 user-to-session-host mapping, so load balancing does not apply. Based on the table, Pool1 and Pool4 are pooled host pools; therefore, only those support a load-balancing algorithm.

Question 55

DRAG DROP - Your on-premises network contains an Active Directory domain that syncs with Azure AD. You have an Azure Virtual Desktop host pool that contains three session hosts. All the session hosts are joined to Azure AD. You plan to implement FSLogix profile containers to meet the following requirements: • The profile containers must be stored on low-latency SSD drives. • The solution must support Server Message Block (SMB) authentication. You need to configure an Azure Storage account to prepare for the FSLogix profile containers. Which actions should you perform in sequence? To answer, drag the appropriate actions to the correct order. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for AZ-140 question 55
Show Answer
Correct Answer: Step 1: Create a Premium file shares storage account Step 2: Enable Azure AD Kerberos authentication Step 3: Create a file share
Explanation:
FSLogix profile containers require SMB-based Azure Files. Premium file shares provide low-latency SSD storage. Azure AD Kerberos must be enabled to support SMB authentication for Azure AD–joined session hosts, and finally a file share is created to store the profile containers.

Question 56

HOTSPOT - You have a Microsoft Entra hybrid tenant that contains the users shown in the following table. You have an Azure Virtual Desktop deployment that contains the host pools shown in the following table. Which users can sign in to the session hosts of each pool? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for AZ-140 question 56 Illustration for AZ-140 question 56 Illustration for AZ-140 question 56
Show Answer
Correct Answer: Pool1: User2 only Pool2: User1, User2, and User3
Explanation:
Pool1 session hosts are joined to on‑premises Active Directory, so only users that are synchronized from on‑prem AD can authenticate; this applies only to User2. Pool2 session hosts are joined to Microsoft Entra ID, which allows sign‑in by cloud‑only members, synced members, and Entra guest users when assigned to the host pool, so all three users can sign in.

Question 57

You have an Azure subscription that contains an Azure Virtual Desktop host pool. The host pool uses FSLogix profile containers. You need to create a configuration file to prevent specific folders from syncing to the FSLogix profile containers when a user signs out. How should you name the file?

A. profile.xml
B. redirections.xml
C. fslogix.config
D. folders.json
Show Answer
Correct Answer: B
Explanation:
FSLogix uses a file named redirections.xml to define folder exclusions so that specific directories are not included in the profile container during sign-out. This XML file controls folder redirection and exclusion behavior for FSLogix profile containers.

Question 58

HOTSPOT - You have an Azure subscription that contains a user named User1 and an Azure Virtual Desktop host pool named Pool1. Pool1 contains the session hosts shown in the following table. You have the devices shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for AZ-140 question 58 Illustration for AZ-140 question 58 Illustration for AZ-140 question 58
Show Answer
Correct Answer: Yes Yes No
Explanation:
Azure Virtual Desktop watermarking works only with supported clients. Web browsers on Windows and macOS support watermarking, so connections to Host1 from Device1 (Windows 11) and to Host2 from Device2 (macOS) via a browser are protected. The Remote Desktop Connection client (mstsc.exe) does not support watermarking, so that connection is not protected.

Question 59

HOTSPOT - You have an Azure Virtual Desktop deployment. Users connect to session hosts by using devices enrolled in Microsoft Intune. You need to create a Conditional Access policy named Policy to meet the following requirements: • Require multifactor authentication (MFA) • Require that the devices be marked as compliant. Which settings of Policy1 should you configure for each requirement? To answer, select the appropriate options in the answer area NOTE: Each correct selection is worth one point.

Illustration for AZ-140 question 59
Show Answer
Correct Answer: Require MFA: Grant Require that the devices be marked as compliant: Grant
Explanation:
In Azure Conditional Access, both MFA and device compliance are enforced in the Grant controls, where you require multifactor authentication and require device to be marked as compliant.

Question 60

You have an Azure subscription that contains two users named User1 and User2 and the Microsoft Entra groups shown in the following table. You have an Azure Virtual Desktop host pool named Pool1 that contains two session hosts named Host1 and Host2. The session hosts use FSLogix user profiles. Host1 contains the local groups shown in the following table. Host2 contains the local groups shown in the following table. User1 connects to Pool and modifies his desktop. User1 reports that when he reconnects to Pool, the desktop modifications fail to appear. You need to ensure that User1 sees the modified desktop when he connects to Pool. The solution must minimize the impact on other user profiles. What should you do?

A. Add User1 to both FSLogix Profile Include list groups.
B. Remove Group2 from both FSLogix Profile Exclude list groups.
C. Remove User1 from Group3.
D. Remove Group3 from Group2.
Show Answer
Correct Answer: C
Explanation:
User1’s desktop changes are not persisting because FSLogix is excluding his profile based on group membership. To ensure only User1 is affected and to minimize impact on other users, remove User1 from the group that causes the FSLogix profile exclusion (Group3). This enables profile persistence for User1 without changing group-based behavior for other users.

Question 61

HOTSPOT - Case study - This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided. To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study. At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section. To start the case study - To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question. Overview - Litware, Inc. is a pharmaceutical company that has a main office in Boston, United States, and a remote office in Chennai, India. Existing Environment. Identity Environment The network contains an on-premises Active Directory domain named litware.com that syncs to a Microsoft Entra tenant named litware.com. The Microsoft Entra tenant contains the users shown in the following table. All users are registered for Azure Multi-Factor Authentication (MFA). Existing Environment. Cloud Services Litware has a Microsoft 365 E5 subscription associated to the Microsoft Entra tenant. All users are assigned Microsoft 365 Enterprise E5 licenses. Litware has an Azure subscription associated to the Microsoft Entra tenant. The subscription contains the resources shown in the following table. Litware uses custom virtual machine images and custom scripts to automatically provision Azure virtual machines and join the virtual machines to the on-premises Active Directory domain. Existing Environment. Network and DNS The offices connect to each other by using a WAN link. Each office connects directly to the internet. All DNS queries for internet hosts are resolved by using DNS servers in the Boston office, which point to root servers on the internet. The Chennai office has caching-only DNS servers that forward queries to the DNS servers in the Boston office. Requirements. Planned Changes - Litware plans to implement the following changes: • Deploy Azure Virtual Desktop environments to the East US Azure region for the users in the Boston office and to the South India Azure region for the users in the Chennai office. • Implement FSLogix profile containers. • Optimize the custom virtual machine images for the Azure Virtual Desktop session hosts. • Use PowerShell to automate the addition of virtual machines to the Azure Virtual Desktop host pools. Requirements. Performance Requirements Litware identifies the following performance requirements: • Minimize network latency of the Azure Virtual Desktop connections from the Boston and Chennai offices. • Minimize latency of the Azure Virtual Desktop host authentication in each Azure region. • Minimize how long it takes to sign in to the Azure Virtual Desktop session hosts. Requirements. Authentication Requirements Litware identifies the following authentication requirements: • Enforce Azure MFA when accessing Azure Virtual Desktop apps. • Force users to reauthenticate if their Azure Virtual Desktop session lasts more than eight hours. Requirements. Security Requirements Litware identifies the following security requirements: • Explicitly allow traffic between the Azure Virtual Desktop session hosts and Microsoft 365. • Explicitly allow traffic between the Azure Virtual Desktop session hosts and the Azure Virtual Desktop infrastructure. • Use built-in groups for delegation. • Delegate the management of app groups to Admin2, including the ability to publish app groups to users and user groups. • Grant Admin1 permissions to manage workspaces, including listing which apps are assigned to the app groups. • Minimize administrative effort to manage network security. • Use the principle of least privilege. Requirements. Deployment Requirements Litware identifies the following deployment requirements: • Use PowerShell to generate the token used to add the virtual machines as session hosts to an Azure Virtual Desktop host pool. • Minimize how long it takes to provision the Azure Virtual Desktop session hosts based on the custom virtual machine images. • Whenever possible, preinstall agents and apps in the custom virtual machine images. User Profile Requirements - Litware identifies the following user profile requirements: • In storage1, store user profiles for the Boston office users. • Ensure that the user profiles for the Boston office users replicate synchronously between two Azure regions. • Ensure that Admin1 uses a local profile only when signing in to the Azure Virtual Desktop session hosts. You need to configure a conditional access policy to meet the authentication requirements. What should you include in the policy configuration? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for AZ-140 question 61 Illustration for AZ-140 question 61 Illustration for AZ-140 question 61
Show Answer
Correct Answer: Target resources: Azure Virtual Desktop Session controls: Sign-in frequency
Explanation:
Selecting Azure Virtual Desktop ensures the policy applies to AVD access. Configuring a sign-in frequency enforces reauthentication after a defined period (eight hours), meeting the MFA and session duration requirements.

Question 62

DRAG DROP - You have an Azure Virtual Desktop deployment that contains a host pool named Pool1. You have an MSI installer package named App1. You need to create an MSIX image of App1 and make the image available to Pool1 by using MSIX app attach. Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Illustration for AZ-140 question 62
Show Answer
Correct Answer: Use the MSIX Packaging Tool to convert App1 into an MSIX package. Run msixmgr.exe to convert the MSIX package into a VHDX file. Store the VHDX file in Azure Files. Add the MSIX package to a host pool.
Explanation:
For MSIX app attach in Azure Virtual Desktop, you first create an MSIX package from the MSI. The MSIX package is then converted into a VHDX using msixmgr.exe. The resulting VHDX must be stored on a network share such as Azure Files, and finally the MSIX app attach package is added and assigned to the host pool.

$19

Get all 321 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.