You have an Azure subscription and 100 Windows 10 devices.
You need to ensure that only users whose devices have the latest security patches installed can access Azure Active Directory (Azure AD)-integrated applications.
What should you implement?
A. a conditional access policy
B. Azure Bastion
C. Azure Firewall
D. Azure Policy
Show Answer
Correct Answer: A
Explanation: Use an Azure AD (Microsoft Entra ID) Conditional Access policy that requires the device to be marked as compliant. Device compliance, typically evaluated by Microsoft Intune, can enforce that Windows 10 devices have the latest required security updates before users are granted access to Azure AD-integrated applications. Azure Bastion provides secure VM access, Azure Firewall filters network traffic, and Azure Policy governs Azure resource configuration rather than user sign-in conditions.
Sources:
https://learn.microsoft.com/en-sg/answers/questions/412521/need-to-migrate-applications-to-azure-ad
Question 209
DRAG DROP -
Match the Azure service to the appropriate description.
To answer, drag the appropriate service from the column on the left to its description on the right. Each service may be used once, more than once, or not at all.
NOTE: Each correct match is worth one point.
Select and Place:
Show Answer
Correct Answer: Azure Synapse Analytics
Azure Cosmos DB
Azure HDInsight
Explanation: Synapse Analytics is the fully managed data warehouse service. Cosmos DB is the globally distributed NoSQL database. HDInsight provides managed Apache Hadoop clusters for big data processing.
Question 210
HOTSPOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: Yes
No
Yes
Explanation: Azure Files is categorized under Azure infrastructure/storage services in Azure Fundamentals context. A DNS server running on an Azure VM is IaaS, not PaaS. Microsoft Intune is SaaS.
Question 211
HOTSPOT -
To complete the sentence, select the appropriate option in the answer area.
Hot Area:
Show Answer
Correct Answer: Microsoft Online Services Privacy Statement
Explanation: The privacy statement describes what data Microsoft processes, how it processes that data, and the purposes for processing. Product Terms, SLAs, and subscription agreements cover licensing, service commitments, and contractual terms rather than privacy practices.
Question 212
HOTSPOT -
You plan to extend your company's network to Azure.
The network contains a VPN appliance that uses an IP address of 131.107.200.1.
You need to create an Azure resource that defines the VPN appliance in Azure.
Which Azure resource should you create? To answer, select the appropriate resource in the answer area.
Hot Area:
Show Answer
Correct Answer: Local network gateway
Explanation: A Local Network Gateway is the Azure resource that represents the on-premises VPN device by storing its public IP address and on-premises address prefixes. A Virtual Network Gateway is the Azure VPN endpoint, not the definition of the on-premises appliance.
Question 214
DRAG DROP -
Match the Azure Services service to the correct descriptions.
Instructions: To answer, drag the appropriate service from the column on the left to its description on the right. Each service may be used once, more than once, or not at all.
NOTE: Each correct match is worth one point.
Select and Place:
Show Answer
Correct Answer: Analyze security log files from Azure virtual machines → Azure Sentinel
Display the secure score for an Azure subscription → Azure Security Center
Store passwords for use by Azure Function applications → Azure Key Vault
Explanation: Azure Sentinel is the SIEM/SOAR service for analyzing security logs. Azure Security Center (now Microsoft Defender for Cloud) provides Secure Score. Azure Key Vault securely stores secrets such as passwords used by Azure Functions.
Question 215
HOTSPOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Show Answer
Correct Answer: No
Yes
Yes
Explanation: Microsoft Sentinel stores ingested data in an Azure Monitor Log Analytics workspace, not directly in Azure Storage. It supports automated remediation through playbooks (Logic Apps). It can collect Windows Defender Firewall logs from Azure virtual machines via supported data collection.
Question 216
Your company has an Azure subscription that contains the following unused resources:
✑ 20 user accounts in Azure Active Directory (Azure AD)
✑ Five groups in Azure AD
✑ 10 public IP addresses
✑ 10 network interfaces
You need to reduce the Azure costs for the company.
Which unused resources should you remove?
A. the network interfaces
B. the public IP addresses
C. the groups
D. the user accounts
Show Answer
Correct Answer: B
Explanation: Unused public IP addresses can incur Azure charges, so deleting them reduces costs. Azure AD users and groups do not incur per-object charges in this context, and unused network interfaces by themselves are not billed resources.
Question 217
Your company has datacenters in Los Angeles and New York. The company has a Microsoft Azure subscription.
You are configuring the two datacenters as geo-clustered sites for site resiliency.
You need to recommend an Azure storage redundancy option.
You have the following data storage requirements:
✑ Data must be stored on multiple nodes.
✑ Data must be stored on nodes in separate geographic locations.
✑ Data can be read from the secondary location as well as from the primary location
Which of the following Azure stored redundancy options should you recommend?
A. Geo-redundant storage
B. Read-only geo-redundant storage
C. Zone-redundant storage
D. Locally redundant storage
Show Answer
Correct Answer: B
Explanation: The requirements are: replication across multiple nodes, replication to a separate geographic region, and the ability to read from the secondary location without failover. Standard geo-redundant storage (GRS) replicates to a secondary region but does not provide read access to the secondary endpoint unless a failover occurs. Read-access geo-redundant storage (RA-GRS) provides continuous read access to the secondary region. Although the option is labeled 'Read-only geo-redundant storage', it is referring to RA-GRS/read-access geo-redundant storage. Zone-redundant storage (ZRS) is limited to availability zones within one region, and locally redundant storage (LRS) stays within a single datacenter.
Question 218
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company's Active Directory forest includes thousands of user accounts.
You have been informed that all network resources will be migrated to Azure. Thereafter, the on-premises data center will be retired.
You are required to employ a strategy that reduces the effect on users, once the planned migration has been completed.
Solution: You plan to sync all the Active Directory user accounts to Azure Active Directory (Azure AD).
Does the solution meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: A
Explanation: Synchronizing on-premises Active Directory user accounts to Azure Active Directory before migrating resources preserves user identities, passwords (with appropriate sync), and group memberships, minimizing disruption during the migration. This is the standard approach for reducing user impact during a transition to Azure identities.
$19
Get all 427 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.