Microsoft

AZ-900 Free Practice Questions — Page 12

Question 113

What is used to grant permission to Azure Virtual Desktop resources?

A. tags
B. role-based access control (RBAC) roles
C. resource groups
D. application security groups
Show Answer
Correct Answer: B
Explanation:
Azure Virtual Desktop uses Azure role-based access control (Azure RBAC) to control access to Azure Virtual Desktop resources. Built-in RBAC roles are assigned to users and administrators to grant the permissions needed to perform specific tasks. Tags, resource groups, and application security groups do not grant permissions. Sources: https://learn.microsoft.com/en-us/azure/virtual-desktop/rbac

Question 114

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Hot Area:

Illustration for AZ-900 question 114
Show Answer
Correct Answer: No No Yes
Explanation:
SSO does not require Microsoft Authenticator. Authentication verifies identity; authorization determines access level. Conditional Access evaluates sign-in signals (such as user, device, location, risk) to allow or block access.

Question 115

HOTSPOT - Select the answer that correctly completes the sentence. Hot Area:

Illustration for AZ-900 question 115
Show Answer
Correct Answer: storage service optimized for very large objects, such as video files and bitmaps.
Explanation:
Azure Blob Storage is designed for storing massive amounts of unstructured object data (blobs), including images, videos, backups, and documents.

Question 116

DRAG DROP - Match the Azure services benefits to the correct descriptions. Instructions: To answer, drag the appropriate benefit from the column on the left to its description on the right. Each benefit may be used once, more than once, or not at all. NOTE: Each correct match is worth one point. Select and Place:

Illustration for AZ-900 question 116
Show Answer
Correct Answer: Microsoft Sentinel Microsoft Defender for Cloud Azure Key Vault
Explanation:
Microsoft Sentinel provides SIEM functionality. Microsoft Defender for Cloud displays Secure Score. Azure Key Vault securely stores secrets such as passwords for Azure Function apps.

Question 117

What is the function of a Site-to-Site VPN?

A. provides a secure connection between a computer on a public network and the corporate network
B. provides a dedicated private connection to Azure that does NOT travel over the internet
C. provides a connection from an on-premises VPN device to an Azure VPN gateway
Show Answer
Correct Answer: C
Explanation:
A Site-to-Site VPN connects an on-premises network (via a VPN device) to an Azure virtual network through an Azure VPN Gateway using IPsec/IKE. Option A describes a Point-to-Site VPN for individual client computers, and option B describes Azure ExpressRoute, which is a private dedicated connection that does not traverse the public internet.

Question 118

HOTSPOT - Select the answer that correctly completes the sentence. Hot Area:

Illustration for AZ-900 question 118
Show Answer
Correct Answer: contains one or more data centers that are connected by using a low-latency network.
Explanation:
An Azure region is a set of one or more datacenters within a geographic area connected through a low-latency network. The other statements are incorrect.

Question 119

HOTSPOT - For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Hot Area:

Illustration for AZ-900 question 119
Show Answer
Correct Answer: Yes No Yes
Explanation:
For Azure fundamentals, cloud services are typically managed through the Azure portal or other online management interfaces. Internet connectivity is expected, a dedicated management app is not required, and any modern web browser can be used.

Question 120

HOTSPOT - Select the answer that correctly completes the sentence. Hot Area:

Illustration for AZ-900 question 120
Show Answer
Correct Answer: Azure Monitor
Explanation:
Application Insights is a feature of Azure Monitor that provides application performance monitoring (APM), telemetry, logging, and diagnostics.

Question 121

DRAG DROP - Arrange the storage account redundancy options from the least redundant to the most redundant. To answer, move all options from the list of options to the answer area and arrange them in the correct order. Select and Place:

Illustration for AZ-900 question 121
Show Answer
Correct Answer: Locally-redundant storage (LRS) Zone-redundant storage (ZRS) Geo-redundant storage (GRS)
Explanation:
LRS replicates within a single datacenter, ZRS replicates across availability zones in a region, and GRS adds replication to a secondary geographic region, providing the highest redundancy.

Question 122

HOTSPOT - Select the answer that correctly completes the sentence. Hot Area:

Illustration for AZ-900 question 122
Show Answer
Correct Answer: compute service.
Explanation:
Azure Container Instances is part of Azure Compute. It runs containerized applications on demand, so it is classified as a compute service rather than identity, networking, or storage.

$19

Get all 427 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.