Which resources can be used as a source for a Network security group inbound security rule?
A. Service Tags only
B. IP Addresses, Service tags and Application security groups
C. Application security groups only
D. IP Addresses only
Show Answer
Correct Answer: B
Explanation: Azure Network Security Group inbound security rules support source values as IP addresses (or CIDR ranges), Service Tags, and Application Security Groups. These options are available for defining the source in inbound rules.
Question 188
Who can use the Azure Total Cost of Ownership (TCO) calculator?
A. billing readers for an Azure subscription only
B. owners for an Azure subscription only
C. anyone
D. all users who have an account in Azure Active Directory (Azure AD) that is linked to an Azure subscription only
Show Answer
Correct Answer: C
Explanation: The Azure Total Cost of Ownership (TCO) Calculator is a publicly accessible web-based tool for estimating the cost of migrating workloads to Azure. It does not require Azure subscription ownership or specific Azure AD permissions, so anyone can use it.
Question 189
HOTSPOT -
To complete the sentence, select the appropriate option in the answer area.
Hot Area:
Show Answer
Correct Answer: automatically respond to threats.
Explanation: Azure Sentinel playbooks use Azure Logic Apps to automate and orchestrate responses to alerts and incidents.
Question 190
Your company has an Azure subscription that contains resources in several regions.
You need to create the Azure resource that must be used to meet the policy requirement.
What should you create?
A. a read-only lock
B. an Azure policy
C. a management group
D. a reservation
Show Answer
Correct Answer: B
Explanation: The only Azure resource/service designed to implement and enforce governance policy requirements across Azure resources is Azure Policy. A read-only lock prevents modification or deletion, a management group organizes subscriptions and provides scope for governance but is not itself the policy mechanism, and a reservation is a pricing discount construct.
Sources:
https://learn.microsoft.com/en-us/answers/questions/5536554/his-policy-maintains-a-set-of-best-available-regio
Question 191
You have an Azure virtual machine named VM1.
You plan to encrypt VM1 by using Azure Disk Encryption.
Which Azure resource must you create first?
A. an Azure Storage account
B. an Azure Key Vault
C. an Azure Information Protection policy
D. an Encryption key
Show Answer
Correct Answer: B
Explanation: Azure Disk Encryption requires an Azure Key Vault to securely store and manage the disk encryption keys and secrets (or key encryption keys) used by BitLocker/DM-Crypt. The VM already exists, so its managed disks/storage are already provisioned. An Azure Information Protection policy is unrelated, and while encryption keys can be customer-managed, the prerequisite Azure resource to create is the Key Vault.
Question 192
HOTSPOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: Yes
Yes
Yes
Explanation: Azure AD can manage access to on-premises applications via Application Proxy, provides single sign-on (SSO), and supports registration of iOS devices (registered, not Azure AD joined).
Question 193
HOTSPOT -
To complete the sentence, select the appropriate option in the answer area.
Hot Area:
Explanation: Inbound internet access to a server in an Azure virtual network is enabled using Azure Firewall DNAT (Destination NAT) rules, which translate incoming public traffic to the private server.
Question 194
HOTSPOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: No
Yes
No
Explanation: Archive tier is set at the blob level, not the storage account level. Hot tier is for frequently accessed and modified data. Long-term backups are better suited to the Archive tier; Cool is for infrequently accessed data with shorter retention.
Question 195
HOTSPOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: Yes
Yes
Yes
Explanation: Azure Cost Management supports cost analysis at management group and resource group scopes, and can report resource usage (including virtual machines) over historical periods such as the last three months.
Question 196
What is the first stage in the Microsoft Cloud Adoption Framework for Azure?
A. Adopt the cloud.
B. Make a plan.
C. Ready your organization.
D. Define your strategy.
Show Answer
Correct Answer: D
Explanation: The Microsoft Cloud Adoption Framework for Azure follows the lifecycle: Strategy, Plan, Ready, Adopt, Govern, and Manage. Therefore, the first stage is to define your strategy.
$19
Get all 427 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.