What is used to grant permission to Azure Virtual Desktop resources?
A. tags
B. role-based access control (RBAC) roles
C. resource groups
D. application security groups
Show Answer
Correct Answer: B
Explanation: Azure Virtual Desktop uses Azure role-based access control (RBAC) to grant and manage permissions to its resources. Built-in and custom RBAC roles define what users and administrators can access and perform. Tags, resource groups, and application security groups do not grant permissions.
Question 127
HOTSPOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: Single sign-on (SSO) requires Microsoft Authenticator: No
Authentication establishes access level: No
Conditional Access uses sign-in signals to allow or deny access: Yes
Explanation: SSO does not require Microsoft Authenticator; it uses one set of credentials across apps. Authentication verifies identity, while authorization determines access level. Conditional Access evaluates sign-in signals (user, device, location, risk) to allow, deny, or challenge access.
Question 128
HOTSPOT -
Select the answer that correctly completes the sentence.
Hot Area:
Show Answer
Correct Answer: storage service optimized for very large objects, such as video files and bitmaps.
Explanation: Azure Blob Storage is designed to store unstructured data (blobs), especially large binary objects like images, videos, backups, and other large files, not queues, file shares, or key-value data.
Question 129
DRAG DROP -
Match the Azure services benefits to the correct descriptions.
Instructions: To answer, drag the appropriate benefit from the column on the left to its description on the right. Each benefit may be used once, more than once, or not at all.
NOTE: Each correct match is worth one point.
Select and Place:
Show Answer
Correct Answer: Provide SIEM functionality:
Microsoft Sentinel
Display the secure score for an Azure subscription:
Microsoft Defender for Cloud
Store passwords for use by Azure Function applications:
Azure Key Vault
Explanation: Microsoft Sentinel is Azure’s cloud-native SIEM solution. Microsoft Defender for Cloud shows the secure score for subscriptions. Azure Key Vault securely stores secrets, keys, and passwords used by Azure services such as Azure Functions.
Question 130
What is the function of a Site-to-Site VPN?
A. provides a secure connection between a computer on a public network and the corporate network
B. provides a dedicated private connection to Azure that does NOT travel over the internet
C. provides a connection from an on-premises VPN device to an Azure VPN gateway
Show Answer
Correct Answer: C
Explanation: A Site-to-Site VPN connects an entire on-premises network to an Azure virtual network using VPN devices and an Azure VPN gateway. Option A describes a Point-to-Site VPN for individual clients, and option B describes ExpressRoute, which is a private connection that does not use the public internet.
Question 131
HOTSPOT -
Select the answer that correctly completes the sentence.
Hot Area:
Show Answer
Correct Answer: contains one or more data centers that are connected by using a low-latency network.
Explanation: An Azure region is defined as a geographical area that contains one or more datacenters interconnected through a dedicated low-latency network to provide high performance and reliability.
Question 132
HOTSPOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: Yes
No
Yes
Explanation: Cloud services are typically managed through provider portals or APIs, which require network connectivity. A separate management app is not mandatory because management is usually done via web portals or CLI tools. Cloud services can be managed from any modern web browser, such as through the Azure portal.
Question 133
HOTSPOT -
Select the answer that correctly completes the sentence.
Hot Area:
Show Answer
Correct Answer: Azure Monitor
Explanation: Application Insights is an Application Performance Management (APM) feature that is part of Azure Monitor, used to collect telemetry, metrics, logs, and performance data for applications.
Question 134
DRAG DROP -
Arrange the storage account redundancy options from the least redundant to the most redundant. To answer, move all options from the list of options to the answer area and arrange them in the correct order.
Select and Place:
Explanation: LRS replicates data within a single datacenter, ZRS replicates across availability zones in a region, and GRS adds replication to a secondary geographic region, providing the highest redundancy.
Question 135
HOTSPOT -
Select the answer that correctly completes the sentence.
Hot Area:
Show Answer
Correct Answer: compute service.
Explanation: Azure Container Instances run containerized applications and provide CPU and memory resources. They are part of Azure Compute services, not storage, networking, or identity.
$19
Get all 428 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.