Exam Name Free Online practice test Free PDF Dumps Premium Exam Dumps
Microsoft Azure Administrator (AZ-103) (retiring August 31, 2020) Free AZ-103 practice test (Online) Free AZ-103 PDF Dumps (Download) pass4itsure AZ-103 Exam Dumps (Premium)
Microsoft Azure Administrator (AZ-104) Free AZ-104 practice test (Online) Free AZ-104 PDF Dumps (Download) pass4itsure AZ-104 Exam Dumps (Premium)
Planning and Administering Microsoft Azure for SAP Workloads (AZ-120) Free AZ-120 practice test (Online) Free AZ-120 PDF Dumps (Download) pass4itsure AZ-120 Exam Dumps (Premium)
Developing Solutions for Microsoft Azure (AZ-203) (retiring August 31, 2020) Free AZ-203 practice test (Online) Free AZ-203 PDF Dumps (Download) pass4itsure AZ-203 Exam Dumps (Premium)
Developing Solutions for Microsoft Azure (AZ-204) Free AZ-204 practice test (Online) Free AZ-204 PDF Dumps (Download) pass4itsure AZ-204 Exam Dumps (Premium)
Microsoft Azure IoT Developer (AZ-220) Free AZ-220 practice test (Online) Free AZ-220 PDF Dumps (Download) pass4itsure AZ-220 Exam Dumps (Premium)
Microsoft Azure Architect Technologies (AZ-300) Free AZ-300 practice test (Online) Free AZ-300 PDF Dumps (Download) pass4itsure AZ-300 Exam Dumps (Premium)
Microsoft Azure Architect Design (AZ-301) Free AZ-301 practice test (Online) Free AZ-301 PDF Dumps (Download) pass4itsure AZ-301 Exam Dumps (Premium)
Microsoft Azure Architect Technologies Exam (AZ-303) Free AZ-303 practice test (Online) Free AZ-303 PDF Dumps (Download) pass4itsure AZ-303 Exam Dumps (Premium)
Microsoft Azure Architect Design Exam (AZ-304) Free AZ-304 practice test (Online) Free AZ-304 PDF Dumps (Download) pass4itsure AZ-304 Exam Dumps (Premium)
Microsoft Azure DevOps Solutions (AZ-400) Free AZ-400 practice test (Online) Free AZ-400 PDF Dumps (Download) pass4itsure AZ-400 Exam Dumps (Premium)
Microsoft Azure Security Technologies (AZ-500) Free AZ-500 practice test (Online) Free AZ-500 PDF Dumps (Download) pass4itsure AZ-500 Exam Dumps (Premium)
Microsoft Azure Fundamentals (AZ-900) Free AZ-900 practice test (Online) Free AZ-900 PDF Dumps (Download) pass4itsure AZ-900 Exam Dumps (Premium)
Developing Microsoft Azure and Web Services (70-487) Free 70-487 practice test (Online) Free 70-487 PDF Dumps (Download) pass4itsure 70-487 Exam Dumps (Premium)
Configuring and Operating a Hybrid Cloud with Microsoft Azure Stack (70-537) Free 70-537 practice test (Online) Free 70-537 PDF Dumps (Download) pass4itsure 70-537 Exam Dumps (Premium)

We share the latest effective Microsoft Azure AZ-102 exam dumps online Practice test to improve your skills! You can also choose AZ-102 PDF! Get the full AZ-102 dumps: https://www.pass4itsure.com/az-102.html (Q&As: 192) to pass the exam easily!

[PDF] Free Microsoft Azure AZ-102 pdf dumps download from Google Drive: https://drive.google.com/open?id=1IaunHjVrLlJaBzAWqMOh0jXxNpE53bAH

[PDF] Free Full Microsoft pdf dumps download from Google Drive: https://drive.google.com/open?id=1gdQrKIsiLyDEsZ24FxsyukNPYmpSUDDO

Exam AZ-102: Microsoft Azure Administrator Certification Transition: https://www.microsoft.com/en-us/learning/exam-az-102.aspx

  • Manage Azure subscriptions and resources (5-10%)
  • Implement and manage storage (5-10%)
  • Configure and manage virtual networks (15-20%)
  • Manage identities (15-20%)
  • Evaluate and perform server migration to Azure (15-20%)
  • Implement and manage application services (5-10%)
  • Implement advanced virtual networking (5-10%)
  • Secure identities (5-10%)

Latest effective Microsoft Azure AZ-102 Exam Practice Tests

QUESTION 1
You have an Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com that contains 100 user
accounts.
You purchase 10 Azure AD Premium P2 licenses for the tenant.
You need to ensure that 10 users can use all the Azure AD Premium features.
What should you do?
A. From the Groups blade of each user, invite the users to a group.
B. From the Licenses blade of Azure AD, assign a license.
C. From the Directory role blade of each user, modify the directory role.
D. From the Azure AD domain, add an enterprise application.
Correct Answer: B
To assign a license, under Azure Active Directory > Licenses > All Products, select one or more products, and then
select Assign on the command bar. References: https://docs.microsoft.com/en-us/azure/active-
directory/fundamentals/license-users-groups

QUESTION 2
From the MFA Server blade, you open the Block/unblock users blade as shown in the exhibit.pass4itsure az-102 exam question q2

What caused AlexW to be blocked?
A. An administrator manually blocked the user.
B. The user reports a fraud alert when prompted for additional authentication.
C. The user account password expired.
D. The user entered an incorrect PIN four times within 10 minutes.
Correct Answer: B

QUESTION 3
DRAG DROP
You have an on-premises file server named Server1 that runs Windows Server 2016.
You have an Azure subscription that contains an Azure file share.
You deploy an Azure File Sync Storage Sync Service, and you create a sync group.
You need to synchronize files from Server1 to Azure.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions
to the answer area and arrange them in the correct order.
Select and Place:pass4itsure az-102 exam question q3Correct Answer: pass4itsure az-102 exam question q3-1Explanation:
Step 1: Install the Azure File Sync agent on Server1
The Azure File Sync agent is a downloadable package that enables Windows Server to be synced with an Azure file
share
Step 2: Register Server1.
Register Windows Server with Storage Sync Service
Registering your Windows Server with a Storage Sync Service establishes a trust relationship between your server (or
cluster) and the Storage Sync Service.
Step 3: Add a server endpoint
Create a sync group and a cloud endpoint.
A sync group defines the sync topology for a set of files. Endpoints within a sync group are kept in sync with each other.
A sync group must contain one cloud endpoint, which represents an Azure file share and one or more server endpoints.
A server endpoint represents a path on registered server.
References: https://docs.microsoft.com/en-us/azure/storage/files/storage-sync-files-deployment-guide

QUESTION 4
You download an Azure Resource Manager template based on an existing virtual machine. The template will be used to
deploy 100 virtual machines.
You need to modify the template to reference an administrative password. You must prevent the password from being
stored in plain text.
What should you create to store the password?
A. Azure Active Directory (AD) Identity Protection and an Azure policy
B. a Recovery Services vault and a backup policy
C. an Azure Key Vault and an access policy
D. an Azure Storage account and an access policy
Correct Answer: C
You can use a template that allows you to deploy a simple Windows VM by retrieving the password that is stored in a
Key Vault. Therefore, the password is never put in plain text in the template parameter file. References:
https://azure.microsoft.com/en-us/resources/templates/101-vm-secure-password/

QUESTION 5
DRAG DROP
You have an Azure Linux virtual machine that is protected by Azure Backup.
One week ago, two files were deleted from the virtual machine.
You need to restore the deleted files to an on-premises computer as quickly as possible.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to
the answer area and arrange them in the correct order.
Select and Place:pass4itsure az-102 exam question q5Correct Answer: pass4itsure az-102 exam question q5-1Explanation:
To restore files or folders from the recovery point, go to the virtual machine and choose the desired recovery point.
Step 0. In the virtual machine\\’s menu, click Backup to open the Backup dashboard.
Step 1. In the Backup dashboard menu, click File Recovery.
Step 2. From the Select recovery point drop-down menu, select the recovery point that holds the files you want. By
default, the latest recovery point is already selected.
Step 3: To download the software used to copy files from the recovery point, click Download Executable (for Windows
Azure VM) or Download Script (for Linux Azure VM, a python script is generated).
Step 4: Copy the files by using AzCopy
AzCopy is a command-line utility designed for copying data to/from Microsoft Azure Blob, File, and Table storage, using
simple commands designed for optimal performance. You can copy data between a file system and a storage account,
or
between storage accounts.
References: https://docs.microsoft.com/en-us/azure/backup/backup-azure-restore-files-from-vm
https://docs.microsoft.com/en-us/azure/storage/common/storage-use-azcopy

QUESTION 6
You have an Azure DNS zone named adatum.com. You need to delegate a subdomain named research.adatum.com to
a different DNS server in Azure. What should you do?
A. Create an PTR record named research in the adatum.com zone.
B. Create an NS record named research in the adatum.com zone.
C. Modify the SOA record of adatum.com.
D. Create an A record named “.research in the adatum.com zone.
Correct Answer: D
Configure A records for the domains and sub domains.
References: http://www.stefanjohansson.org/2012/12/how-to-configure-custom-dns-names-for-multiple-subdomain-
based-azure-web-sites/

QUESTION 7
You have an Azure subscription named Subscnption1 that contains an Azure virtual machine named VM1.
VM1 is in a resource group named RG1.
VM1 runs services that will be used to deploy resources to RG1.
You need to ensure that a service running on VM1 can manage the resources in RG1 by using the identity of VM1.
What should you do fit
A. From the Azure portal modify the Access control (1AM) settings of VM1.
B. From the Azure portal, modify the Policies settings of RG1.
C. From the Azure portal, modify the value of the Managed Service Identity option for VM1.
D. From the Azure portal, modify the Access control (IAM) settings of RG1.
Correct Answer: C
A managed identity from Azure Active Directory allows your app to easily access other AAD-protected resources such
as Azure Key Vault. The identity is managed by the Azure platform and does not require you to provision or rotate any
secrets.
User assigned managed identities can be used on Virtual Machines and Virtual Machine Scale Sets.
References: https://docs.microsoft.com/en-us/azure/app-service/app-service-managed-service-identity

QUESTION 8
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource
groups.
Another administrator plans to create several network security groups (NSGs) in the subscription.
You need to ensure that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks.
Solution: You create a resource lock, and then you assign the lock to the subscription.
Does this meet the goal?
A. Yes
B. No
Correct Answer: B
How can I freeze or lock my production/critical Azure resources from accidental deletion? There is way to do this with
both ASM and ARM resources using Azure resource lock. References: https://blogs.msdn.microsoft.com/azureedu/2016
/04/27/using-azure-resource-manager-policy-and-azure-lock-to-control-your-azure-resources/

QUESTION 9
Another administrator reports that she is unable to configure a web app named corplod7509086n3 to prevent all
connections from an IP address of 11.0.0.11. You need to modify corplod7509086n3 to successfully prevent the
connections from the IP address. The solution must minimize Azure-related costs.
What should you do from the Azure portal?
A. Check the answer in explanantion.
Correct Answer: A
See explanation below.
Step 1:
Find and select application corplod7509086n3:
1.
In the Azure portal, on the left navigation panel, click Azure Active Directory.
2.
In the Azure Active Directory blade, click Enterprise applications.
Step 2:
To add an IP restriction rule to your app, use the menu to open Network>IP Restrictions and click on Configure IP
Restrictionspass4itsure az-102 exam question q9Step 3:
Click Add rule
You can click on [+] Add to add a new IP restriction rule. Once you add a rule, it will become effective immediately. pass4itsure az-102 exam question q9-1Step 4:
Add name, IP address of 11.0.0.11, select Deny, and click Add Rule pass4itsure az-102 exam question q9-2

References: https://docs.microsoft.com/en-us/azure/app-service/app-service-ip-restrictions

QUESTION 10
You need to prevent remote users from publishing via FTP to a function app named FunctionApplod7509087fa. Remote
users must be able to publish via FTPS. What should you do from the Azure portal?
A. Check the answer in explanantion.
Correct Answer: A
See explanation below.
Step 1:
Locate and select the function app FunctionApplod7509087fa.
Step 2:
Select Application Settings > FTP Access, change FTP access to FTPS Only, and click Save.pass4itsure az-102 exam question q10References: https://blogs.msdn.microsoft.com/appserviceteam/2018/05/08/web-apps-making-changes-to-ftp-
deployments/

QUESTION 11
DRAG DROP
You have an Azure subscription that is used by four departments in your company. The subscription contains 10
resource groups. Each department uses resources in several resource groups.
You need to send a report to the finance department. The report must detail the costs for each department. Which three
actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer
area and arrange them in the correct order.
Select and Place:pass4itsure az-102 exam question q11Correct Answer: pass4itsure az-102 exam question q11-1Explanation:
Box 1: Assign a tag to each resource.
You apply tags to your Azure resources giving metadata to logically organize them into a taxonomy. After you apply
tags, you can retrieve all the resources in your subscription with that tag name and value. Each resource or resource
group
can have a maximum of 15 tag name/value pairs. Tags applied to the resource group are not inherited by the resources
in that resource group.
Box 2: From the Cost analysis blade, filter the view by tag
After you get your services running, regularly check how much they\\’re costing you. You can see the current spend and
burn rate in Azure portal.
1.
Visit the Subscriptions blade in Azure portal and select a subscription.
2.
You should see the cost breakdown and burn rate in the popup blade.
3.
Click Cost analysis in the list to the left to see the cost breakdown by resource. Wait 24 hours after you add a service for
the data to populate.
4.
You can filter by different properties like tags, resource group, and timespan. Click Apply to confirm the filters and
Download if you want to export the view to a Comma-Separated Values (.csv) file.
Box 3: Download the usage report
References: https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-group-using-tags
https://docs.microsoft.com/en-us/azure/billing/billing-getting-started

QUESTION 12
You have 100 Azure subscriptions. All the subscriptions are associated to the same Azure Active Directory (Azure AD)
tenant named contoso.com.
You are a global administrator.
You plan to create a report that lists all the resources across all the subscriptions.
You need to ensure that you can view all the resources in all the subscriptions.
What should you do?
A. From the Azure portal, modify the profile settings of your account.
B. From Windows PowerShell, run the Add-AzureADAdministrativeUnitMember cmdlet.
C. From Windows PowerShell, run the New-AzureADUserAppRoleAssignment cmdlet.
D. From the Azure portal, modify the properties of the Azure AD tenant.
Correct Answer: C
The New-AzureADUserAppRoleAssignment cmdlet assigns a user to an application role in Azure Active Directory (AD).
Use it for the application report. References: https://docs.microsoft.com/en-us/powershell/module/azuread/new-
azureaduserapproleassignment?view=azureadps-2.0

QUESTION 13
You configure Azure AD Connect for Azure Active Directory Seamless Single Sign-On (Azure AD Seamless SSO) for an
on-premises network. Users report that when they attempt to access myapps.microsoft.com, they are prompted
multiple
times to sign in and are forced to use an account name that ends with onmicrosoft.com.
You discover that there is a UPN mismatch between Azure AD and the on-premises Active Directory. You need to
ensure that the users can use single-sign on (SSO) to access Azure resources.
What should you do first?
A. From the on-premises network, deploy Active Directory Federation Services (AD FS).
B. From Azure AD, add and verify a custom domain name.
C. From the on-premises network, request a new certificate that contains the Active Directory domain name.
D. From the server that runs Azure AD Connect, modify the filtering options.
Correct Answer: B
Azure AD Connect lists the UPN suffixes that are defined for the domains and tries to match them with a custom domain
in Azure AD. Then it helps you with the appropriate action that needs to be taken. The Azure AD sign-in page lists the
UPN suffixes that are defined for on-premises Active Directory and displays the corresponding status against each
suffix. The status values can be one of the following:
State: Verified
Azure AD Connect found a matching verified domain in Azure AD. All users for this domain can sign in by using their on-
premises credentials.
State: Not verified
Azure AD Connect found a matching custom domain in Azure AD, but it isn\\’t verified. The UPN suffix of the users of
this domain will be changed to the default .onmicrosoft.com suffix after synchronization if the domain isn\\’t verified.
Action Required: Verify the custom domain in Azure AD.
References: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-user-signin

Microsoft Certified: Azure Administrator Associate Azure Administrators implement, monitor, and maintain Microsoft Azure solutions, including major services related to compute, storage, network, and security.

Share 13 of the latest Microsoft Azure AZ-102 dumps Practice tests for free to help you improve your skills. AZ-102 PDF download Online! Get the full AZ-102 dumps: https://www.pass4itsure.com/az-102.html (Q&As: 192). Easily pass the exam!

[PDF] Free Microsoft Azure AZ-102 pdf dumps download from Google Drive: https://drive.google.com/open?id=1IaunHjVrLlJaBzAWqMOh0jXxNpE53bAH

[PDF] Free Full Microsoft pdf dumps download from Google Drive: https://drive.google.com/open?id=1gdQrKIsiLyDEsZ24FxsyukNPYmpSUDDO

Pass4itsure Promo Code 15% Off

pass4itsure AZ-102 coupon

related: https://www.certificationvce.com/first-hand-microsoft-070-341-dump-exam/

We share the latest effective Microsoft Azure AZ-101 exam dumps online Practice test to improve your skills! You can also choose AZ-101 PDF! Get the full AZ-101 dumps: https://www.pass4itsure.com/az-101.html (Q&As: 102 ) to pass the exam easily!

[PDF] Free Microsoft Azure AZ-101 pdf dumps download from Google Drive: https://drive.google.com/open?id=1SYcAiZoKz-5sVRgXjbtmNUS0sl8HRAZY

[PDF] Free Full Microsoft pdf dumps download from Google Drive: https://drive.google.com/open?id=1gdQrKIsiLyDEsZ24FxsyukNPYmpSUDDO

Exam AZ-101: Microsoft Azure Integration and Security: https://www.microsoft.com/en-us/learning/exam-az-101.aspx

  • Evaluate and perform server migration to Azure (15-20%)
  • Implement and manage application services (20-25%)
  • Implement advanced virtual networking (30-35%)
  • Secure identities (25-30%)

Latest effective Microsoft Azure AZ-101 Exam Practice Tests

QUESTION 1
You need to create a function app named corp7509086nl that supports sticky sessions. The solution must minimize the
Azure-related costs of the App Service plan. What should you do from the Azure portal?
A. Check the answer in explanation.
Correct Answer: A
See explanation below.
Step 1:
Select the New button found on the upper left-hand corner of the Azure portal, then select Compute > Function App.
Step 2:
Use the function app settings as listed below.
App name: corp7509086n1
Hosting plan: Azure App Service plan
(need this for the sticky sessions)
Pricing tier of the the App Service plan: Shared compute: Free
Step 3:
Select Create to provision and deploy the function app.
References:
https://docs.microsoft.com/en-us/azure/azure-functions/functions-create-function-app-portal

QUESTION 2
You have an Azure subscription.
You enable multi-factor authentication for all users.
Some users report that the email applications on their mobile device cannot co browser and from Microsoft Outlook
2016 on their computer.
You need to ensure that the users can use the email applications on their mobile device.
What should you instruct the users to do?
The users can access Exchange Online by using a web
A. Enable self-service password reset.
B. Create an app password.
C. Reset the Azure Active Directory (Azure AD) password.
D. Reinstall the Microsoft Authenticator app.
Correct Answer: A
References: https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-howitworks

QUESTION 3
You are the global administrator for an Azure Active Directory (Azure AD) tenet named adatum.com.
You need to enable two-step verification for Azure users.
What should you do?
A. Create a sign-in risk policy in Azure AD Identity Protection
B. Enable Azure AD Privileged Identity Management.
C. Create and configure the Identity Hub.
D. Configure a security policy in Azure Security Center.
Correct Answer: A
With Azure Active Directory Identity Protection, you can:
require users to register for multi-factor authentication
handle risky sign-ins and compromised users References: https://docs.microsoft.com/en-us/azure/active-
directory/identity-protection/flows

QUESTION 4
You have an Azure virtual network named VNet1 that contains a subnet named Subnet1. Subnet1 contains three Azure
virtual machines. Each virtual machine has a public IP address.
The virtual machines host several applications that are accessible over port 443 to user on the Internet.
Your on-premises network has a site-to-site VPN connection to VNet1.
You discover that the virtual machines can be accessed by using the Remote Desktop Protocol (RDP) from the Internet
and from the on-premises network.
You need to prevent RDP access to the virtual machines from the Internet, unless the RDP connection is established
from the on-premises network. The solution must ensure that all the applications can still be accesses by the Internet
users.
What should you do?
A. Modify the address space of the local network gateway.
B. Remove the public IP addresses from the virtual machines.
C. Modify the address space of Subnet1.
D. Create a deny rule in a network security group (NSG) that is linked to Subnet1.
Correct Answer: D

QUESTION 5
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
You have an Azure Active Directory (Azure AD) tenant named Adatum and an Azure Subscription named Subscription1.
Adatum contains a group named Developers. Subscription1 contains a resource group named Dev.
You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group.
Solution: On Subscription1, you assign the DevTest Labs User role to the Developers group.
Does this meet the goal?
A.
B. Yes
C. No
Correct Answer: B
DevTest Labs User role only lets you connect, start, restart, and shutdown virtual machines in your Azure DevTest
Labs.
You would need the Logic App Contributor role.
References:
https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles
https://docs.microsoft.com/en-us/azure/logic-apps/logic-apps-securing-a-logic-app

QUESTION 6
You need to create a web app named corp7509086n2 that can be scaled horizontally. The solution must use the lowest
possible pricing tier for the App Service plan. What should you do from the Azure portal?
A. Check the answer in explanation.
Correct Answer: A
See explanation below.
Step 1:
In the Azure Portal, click Create a resource > Web + Mobile > Web App.
Step 2:
Use the Webb app settings as listed below.
Web App name: corp7509086n2
Hosting plan: Azure App Service plan
Pricing tier of the Pricing Tier: Standard
Change your hosting plan to Standard, you can\\’t setup auto-scaling below standard tier.
Step 3:
Select Create to provision and deploy the Web app.
References:
https://docs.microsoft.com/en-us/azure/app-service/environment/app-service-web-how-to-create-a-web-app-in-an-ase
https://azure.microsoft.com/en-us/pricing/details/app-service/plans/

QUESTION 7
You have a public load balancer that balancer ports 80 and 443 across three virtual machines.
You need to direct all the Remote Desktop protocol (RDP) to VM3 only.
What should you configure?
A. an inbound NAT rule
B. a load public balancing rule
C. a new public load balancer for VM3
D. a new IP configuration
Correct Answer: A
To port forward traffic to a specific port on specific VMs use an inbound network address translation (NAT) rule.

QUESTION 8
You create an Azure subscription that is associated to a basic Azure Active Directory (Azure AD) tenant. You need to
receive an email notification when any user activates an administrative role. What should you do?
A. Purchase Azure AD Premium 92 and configure Azure AD Privileged Identity Management,
B. Purchase Enterprise Mobility + Security E3 and configure conditional access policies.
C. Purchase Enterprise Mobility + Security E5 and create a custom alert rule in Azure Security Center.
D. Purchase Azure AD Premium PI and enable Azure AD Identity Protection.
Correct Answer: A
When key events occur in Azure AD Privileged Identity Management (PIM), email notifications are sent. For example,
PIM sends emails for the following events:
When a privileged role activation is pending approval
When a privileged role activation request is completed
When a privileged role is activated
When a privileged role is assigned
When Azure AD PIM is enabled
References:
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-email-notifications

QUESTION 9
You are configuring Azure Active Directory (AD) Privileged Identity Management.
You need to provide a user named Admm1 with read access to a resource group named RG1 for only one month.
The user role must be assigned immediately.
What should you do?
A. Assign an active role.
B. Assign an eligible role.
C. Assign a permanently active role.
D. Create a custom role and a conditional access policy.
Correct Answer: B
Azure AD Privileged Identity Management introduces the concept of an eligible admin. Eligible admins should be users
that need privileged access now and then, but not all-day, every day. The role is inactive until the user needs access,
then
they complete an activation process and become an active admin for a predetermined amount of time.
References:
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure

QUESTION 10
From the MFA Server blade, you open the Block/unblock users blade as shown in the exhibit.pass4itsure az-101 exam question q10What caused AlexW to be blocked?
A. An administrator manually blocked the user.
B. The user reports a fraud alert when prompted for additional authentication.
C. The user account password expired.
D. The user entered an incorrect PIN four times within 10 minutes.
Correct Answer: B

QUESTION 11
You have a Microsoft SQL Server Always On availability group on Azure virtual machines. You need to configure an
Azure internal load balancer as a listener for the availability group. What should you do?
A. Enable Floating IP.
B. Set Session persistence to Client IP and protocol.
C. Set Session persistence to Client IP.
D. Create an HTTP health probe on port 1433.
Correct Answer: A

QUESTION 12
You have an Azure subscription that contains a policy-based virtual network gateway named GW1 and a virtual network
named VNet1. You need to ensure that you can configure a point-to-site connection from VNet1 to an on-premises
computer. Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Reset GW1.
B. Add a service endpoint to VNet1.
C. Add a connection to GW1.
D. Add a public IP address space to VNet1.
E. Delete GWL
F. Create a route-based virtual network gateway.
Correct Answer: EF
E: Policy-based VPN devices use the combinations of prefixes from both networks to define how traffic is
encrypted/decrypted through IPsec tunnels. It is typically built on firewall devices that perform packet filtering. IPsec
tunnel encryption and decryption are added to the packet filtering and processing engine.
F: A VPN gateway is used when creating a VPN connection to your on-premises network.
Route-based VPN devices use any-to-any (wildcard) traffic selectors, and let routing/forwarding tables direct traffic to
different IPsec tunnels. It is typically built on router platforms where each IPsec tunnel is modeled as a network interface
or VTI (virtual tunnel interface).

QUESTION 13
You plan to move services from your on-premises network to Azure.
You identify several virtual machines that you believe can be hosted in Azure. The virtual machines are shown in the
following table.pass4itsure az-101 exam question q13Which two virtual machines can you access by using Azure migrate? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. Sea-CA0l
B. Hou-NW01
C. NYC-FS01
D. Sea-DC01
E. BOS-DB01
Correct Answer: CE

Microsoft Certified: Azure Administrator Associate Azure Administrators implement, monitor, and maintain Microsoft Azure solutions, including major services related to compute, storage, network, and security.

Share 13 of the latest Microsoft Azure AZ-101 dumps Practice tests for free to help you improve your skills. AZ-101 PDF download Online! Get the full AZ-101 dumps: https://www.pass4itsure.com/az-101.html (Q&As: 102 ). Easily pass the exam!

[PDF] Free Microsoft Azure AZ-101 pdf dumps download from Google Drive: https://drive.google.com/open?id=1SYcAiZoKz-5sVRgXjbtmNUS0sl8HRAZY

[PDF] Free Full Microsoft pdf dumps download from Google Drive: https://drive.google.com/open?id=1gdQrKIsiLyDEsZ24FxsyukNPYmpSUDDO

Pass4itsure Promo Code 15% Off

pass4itsure az-101 coupon

related: https://www.certificationvce.com/new-discount-cisco-300-560-dumps-npdev-pdf/

2017 Pass4itsure best quality Microsoft Azure 70-774 dumps exam video questions in the latest pdf version, pass Perform Cloud Data Science with Azure Machine Learning (beta). At the time of writing this summary of the Pass4itsure https://www.pass4itsure.com/70-774.html dumps on Microsoft Azure HDInsight exam, it is still in Beta as it was just recently published.

Exam Code: 70-774
Exam Name: Perform Cloud Data Science with Azure Machine Learning (beta)
Updated: Aug 25, 2017
Q&As: 102

[Latest Microsoft 70-774 Dumps Certification Vce From Google Drive]: https://drive.google.com/open?id=0BwxjZr-ZDwwWZTFRbi1ZeVRzdDQ

[Latest Cisco 400-201 Dumps Certification Vce From Google Drive]: https://drive.google.com/open?id=0BwxjZr-ZDwwWV2ZxQlJ2OGxkaXc

Here is a high level list of the skills and objectives measured on this Microsoft 70-774 dumps exam:

Administer and Provision HDInsight Clusters

  • Deploy HDInsight clusters
  • Deploy and secure multi-user HDInsight clusters
  • Ingest data for batch and interactive processing
  • Configure HDInsight clusters
  • Manage and debug HDInsight jobs

 70-774 dumps

Pass4itsure Microsoft 70-774 Dumps Training Program Online Here:

QUESTION 19.A project manager has finished the project. He knows that the project scope has been completed and
is within cost and time objectives set by management. Management, however, says that the project is a
failure, because the original schedule was for 27 weeks and the project was completed in 33 weeks.
If the project baseline was 33 weeks, the project is a success because:
A. It only had six weeks of changes.
B. It was completed within the baseline.
C. There were so few changes.
D. There was good communication control.
70-774 exam Answer: B
QUESTION 20.Your company has just presented its new five-year strategic plan. You have received a new product
request from a customer that is in line with the previous five-year strategic plan, but it does not meet the
objectives of the new plan. The product description seems to have a valid business driver and to be a
straightforward development effort.
As project manager, what is the BEST course of action?
A. Do a benefit cost analysis of the project and submit it for management approval.
B. Submit the new product request to the PMO for review and approval before proceeding.
C. Inform the customer of the change in corporate direction and ask him/her to take another look at the
project.
D. Request a project charter from management and begin a WBS.
Answer: B
QUESTION 21.The performing organization is trying to decide whether to split the contracts department and assign
procurement responsibilities to departments directly responsible for the projects.
A procurement professional might not want this split to occur because they would lose ___________ in a
decentralized contracting environment.
A. Standardized company project management practices
B. Loyalty to the project
C. Experience
D. Access to others with similar expertise
70-774 dumps Answer: D
QUESTION 22
Medial home states that:
A. A partnership between primary care providers (PCPs), patients and their families to deliver
comprehensive care over the long-term in a variety of settings.
B. A proprietorship of primary care providers (PCPs), patients and their families to deliver comprehensive
care over the long-term in their own variety of settings.
C. A partnership between primary care providers (PCPs), patients and their families that do not deliver
comprehensive care over the long-term in a variety of settings.
D. A partnership between primary care providers (PCPs), patients and their families to deliver
comprehensive care just foe a short period of time in a variety of settings.
Correct Answer: A
QUESTION 23
Which of the following are the four aspects that all the businesses are required to produce financial
statements at least annually?
A. Balance sheet, statement of operations, statement of changes in equity, statement of expense
B. Journals, statement of operations, statement of changes in equity, statement of expense
C. Balance sheet, statement of operations, statement of changes in equity, statement of cash flow
D. Balance sheet, statement of operations, statement of controlled liabilities, statement of expense
70-774 pdf Correct Answer: C
QUESTION 24
Balance sheet is majorly composed of:
A. heading, body and notes
B. heading, preliminary side bullets and notes
C. footers, body and notes
D. heading, body and footers
Correct Answer: A
QUESTION 25
At the top of the balance sheet there is a three-line heading that includes name of the organization, name
ff statement and
A. One date
B. Two dates
C. Three dates
D. none of the above
70-774 vce Correct Answer: B
QUESTION 26
A major difference between the balance sheet of an investor-owned and a non-profit health care
organization is in the section.
A. owners’ asset
B. owners’ liability
C. owners’ equity
D. owners’ expense
Correct Answer: C
QUESTION 27
Two dates are often shown so that the reader can compare two successive periods, this is called:
A. comparative net assets
B. comparative balance sheet
C. comparative income statement
D. comparative cash flows
70-774 exam Correct Answer: B
QUESTION 28
The resources that the organization owns, typically recorded at their original costs are called assets.
A. True
B. False
Correct Answer: A
QUESTION 29
The financial obligations of the organization are known as:
A. comparative net assets
B. liabilities
C. expenses
D. none of the above
70-774 dumps Correct Answer: B
QUESTION 30
Net assets are:
A. The difference between an organization’s assets and liabilities
B. The difference between an owner’s assets and liabilities
C. The difference between a shareholder’s assets and expenses
D. The difference between a stakeholder’s assets and expenses
Correct Answer: A
QUESTION 31
In investor-owned organizations, the accounting equation is:
A. Assets are equal to the sum of liabilities and owner’s equity
B. Assets are equal to the sum of liabilities and shareholder’s equity
C. Assets are equal to the sum of liabilities and proprietor’s equity
D. Assets are equal to the sum of liabilities and net assets
70-774 pdf Correct Answer: B
QUESTION 32
If assets are equal to the sum of liabilities and net assets in an accounting equation then this equation is
feasible for:
A. Investor-owned organizations
B. Profit-based organizations
C. Non-profit based organizations
D. None of the above
Correct Answer: C
QUESTION 33
Which of the following is NOT included in current assets?
A. Cash and cash equivalents
B. short-term investments
C. patient accounts receivables
D. long-term investments
70-774 vce Correct Answer: D
QUESTION 34
A measure of how quickly an asset can be converted into cash is called:
A. Cash conversion
B. Asset conversion
C. Liquidity
D. Equity
Correct Answer: C
QUESTION 35
Cash (or cash equivalents) is the most liquid asset on the balance sheet.
A. True
B. False
70-774 exam Correct Answer: A
QUESTION 36
By subtracting contractual allowances and charity care discounts from gross patient accounts receivables,
what remains is:
A. Patients accounts payable
B. Patients accounts receivable
C. Patients accounts bill
D. Patients cash income
Correct Answer: B
QUESTION 37
Health care organizations also present an estimate of how much of their patient accounts receivables they
likely will not be able to collect, this estimate is called:
A. Allowance for collectables
B. Expense for collectables
C. Allowance for uncollectables
D. Expense for uncollectables
70-774 dumps Correct Answer: C
QUESTION 38
Supplies refer to small-dollar items that will be used up or fully consumed within more than two years.
A. True
B. False
Correct Answer: B

To study for this Microsoft 70-774 dumps exam, you’ll need to rely mostly on the Azure HDInsight documentation, as well as the documentation for any other services and technologies listed in the exam objectives. To get more information about Microsoft 70-774 dumps go here: https://www.pass4itsure.com/70-774.html

 

Download SC-400 Dumps 2024

Successfully prepare for the Microsoft SC-400 exam and have difficulties? Don’t worry, you can prepare by downloading SC-400 dumps 2024 right study resources.

Download SC-400 dumps 2024 https://www.pass4itsure.com/sc-400.html from Pass4itSure (PDF, VCE, and its new premium plan, All 4000+ Exam PDF&VCE dumps, One Package, from $199.79!) You can choose from three options to ensure a smooth SC-400 exam preparation.

In addition, the new SC-400 dumps come with free Microsoft SC-400 exam questions for you to practice in advance.

New SC-400 Dumps Free Practice Questions Online (1-15)

From: Pass4itSure
Number of issues: 15/237
Relevant certification: Microsoft

Question 1:

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You are configuring a file policy in Microsoft Cloud App Security.

You need to configure the policy to apply to all files. Alerts must be sent to every file owner who is affected by the policy. The policy must scan for credit card numbers, and alerts must be sent to the Microsoft Teams site of the affected department.

Solution: You use the Data Classification service inspection method and send alerts to Microsoft Power Automate.

Does this meet the goal?

A. Yes

B. No

Correct Answer: B

The proposed solution involves using the Data Classification service inspection method and sending alerts to Microsoft Power Automate. While this approach is partially correct in that the Data Classification service can be used to scan for sensitive information such as credit card numbers in files, the solution does not directly address the requirement to send alerts to every file owner and to the Microsoft Teams site of the affected department.

Microsoft Cloud App Security policies can be configured to send alerts when files containing sensitive information are detected. However, the integration with Microsoft Teams for alerting purposes is not directly facilitated through Microsoft Power Automate within the scope of configuring a file policy in Microsoft Cloud App Security alone. The communication to Microsoft Teams and file owners would typically involve additional configuration outside the direct settings of a file policy in Microsoft Cloud App Security.

To meet the goal of alerting every file owner and the Microsoft Teams site of the affected department directly, you would need to ensure that the alerting mechanism specifically includes these targets. While Microsoft Power Automate can be used to automate workflows and could potentially be part of a solution to route alerts appropriately, simply sending alerts to Power Automate does not guarantee that alerts will reach both the file owners and the specific Microsoft Teams site without the proper workflow configuration in Power Automate that specifically targets these recipients.

Question 2:

You have a Microsoft 365 tenant that uses Microsoft Office 365 Message Encryption (OME).

You need to ensure that any emails containing attachments sent to [email protected] are encrypted automatically by using OME.

What should you do?

A. From the Exchange admin center, create a new sharing policy.

B. From the Microsoft 365 security center, create a Safe Attachments policy.

C. From the Exchange admin center, create a mail flow rule.

D. From the Microsoft 365 compliance center, configure an auto-apply retention label policy.

Correct Answer: C

You can create mail flow rules to help protect email messages you send and receive. You can set up rules to encrypt any outgoing email messages and remove encryption from encrypted messages coming from inside your organization or from replies to encrypted messages sent from your organization.

Reference: https://docs.microsoft.com/en-us/microsoft-365/compliance/define-mail-flow-rules-to-encrypt-email?view=o365-worldwide

Question 3:

HOTSPOT

You have a Microsoft 365 E5 subscription.

You receive the data loss prevention (DLP) alert shown in the following exhibit.

Microsoft SC-400 Exam Question 3

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

Hot Area:

Microsoft SC-400 Exam Question 3-2

Correct Answer:

Microsoft SC-400 Exam Question 3-2

Explanation:

Box 1: sent to a manager for approval

Actions taken: GenerateAlert

User overrode policy: Yes

Manager approved

Box 2: overrode Rule1

Rule1 was overridden.

Note: Policy Details:

Policy1

Rule1

Note 2: User Override support

Here are some fine points to understand about using a policy tip to override a rule:

The option to override is per rule, and it overrides all of the actions in the rule (except sending a notification, which can’t be overridden).

Reference:

https://learn.microsoft.com/en-us/microsoft-365/compliance/use-notifications-and-policy-tips

Question 4:

You have a Microsoft 365 E5 subscription that contains a trainable classifier named Trainable1. You plan to create the items shown in the following table.

Microsoft SC-400 Exam Question 4

Which items can use Trainable1?

A. Label2 only

B. Label1 and Label2 only

C. Label1 and Policy1 only

D. Label2, Policy1, and DLP1 only

Correct Answer: C

Explanation:

A Microsoft Purview trainable classifier is a tool you can train to recognize various types of content by giving it samples to look at. Once trained, you can use it to identify items for application of Office sensitivity labels, Communications

compliance policies, and retention label policies.

Once published your classifier will be available as a condition in Office auto-labeling with sensitivity labels, auto-apply retention label policy based on a condition, and in Communication compliance.

Reference:

https://learn.microsoft.com/en-us/microsoft-365/compliance/classifier-get-started-with

Question 5:

You plan to implement sensitivity labels for Microsoft Teams.

You need to ensure that you can view and apply sensitivity labels to new Microsoft Teams sites.

What should you do first?

A. Run the Set-apposite cmdlet.

B. Configure the EnableMTPLabels Azure Active Directory (Azure AD) setting.

C. Create a new sensitivity label scoped to Groups and sites.

D. Run the Execute-AzureAdLabelSync cmdtet.

Correct Answer: C

Explanation: Before you can view and apply sensitivity labels to new Microsoft Teams sites, you first need to create a new sensitivity label and scope it to Groups and sites. This allows the label to be used within Microsoft Teams, SharePoint sites, and Office 365 groups. By doing so, you can classify and protect your organization’s data based on the level of sensitivity.

After creating and configuring the sensitivity labels appropriately in the Microsoft 365 compliance center or the Microsoft 365 security center, these labels can then be applied to Teams, sites, and groups as needed.

The other options listed do not directly relate to the initial setup required for applying sensitivity labels to new Microsoft Teams sites:

A. The Set-SPOSite cmdlet is used to configure settings for SharePoint Online sites and is not directly related to the initial setup of sensitivity labels for Teams.

B. Configuring the EnableMTPLabels Azure Active Directory (Azure AD) setting is not a recognized configuration step for enabling sensitivity labels in Microsoft Teams.

D. There is no cmdlet named Execute-AzureAdLabelSync. The synchronization of labels between Azure Information Protection and Office 365 is automatic and does not require manual execution of a cmdlet like this.

Question 6:

You have a Microsoft 365 E5 subscription that contains a data loss prevention (DLP) policy named DLP1.

DLP1 has a rule that triggers numerous alerts.

You need to reduce the number of alert notifications that are generated. The solution must maintain the sensitivity of DLP1.

What should you do?

A. Change the mode of DLP1 to Test without notifications.

B. Modify the rule and increase the instance count.

C. Modify the rule and configure an alert threshold.

D. Modify the rule and set the priority to the highest value.

Correct Answer: C

To reduce the number of alert notifications generated by the Data Loss Prevention (DLP) policy named DLP1, while maintaining its sensitivity, the best approach is to modify the rule and configure an alert threshold.

Option C: Modify the rule and configure an alert threshold.

Explanation:

Configuring an alert threshold allows you to specify a minimum number of incidents that must occur before an alert is generated. This approach reduces the volume of notifications by filtering out isolated incidents or false positives, focusing on patterns or repeated actions that could indicate a more significant risk. It maintains the sensitivity of DLP1 by not altering the conditions under which data is considered sensitive but rather adjusting the response to detected incidents.
Other Options:

A. Change the mode of DLP1 to Test without notifications. This would essentially stop all notifications, which might reduce the overload but at the cost of missing potentially critical alerts. It does not maintain the operational sensitivity of DLP1 as it stops alerting altogether.


B. Modify the rule and increase the instance count. Increasing the instance count means a policy violation must occur more times before an alert is triggered. This option is similar to configuring an alert threshold and could be a viable approach but is less specific than configuring a threshold for alert notifications.


D. Modify the rule and set the priority to the highest value. Changing the priority of a rule affects the order in which it is evaluated relative to other rules but does not directly impact the number of alerts generated. This option does not address the problem of reducing alert notifications.
Therefore, Option C is the most suitable solution as it directly targets the issue of reducing unnecessary alert notifications while ensuring that the DLP policy remains effective in identifying and responding to significant incidents.

Reference: https://learn.microsoft.com/en-us/microsoft-365/compliance/alert-policies?view=o365-worldwide

Question 7:

You have a Microsoft 365 E5 subscription.

You need to export the details of a retention label. The export must include the following information:

? Is record

? Is regulatory? Disposition type What should you do?

A. From the Microsoft Purview compliance portal, export Compliance Manager assessment actions.

B. From the Microsoft Purview compliance portal export a file plan.

C. From the Microsoft Purview compliance portal, export a disposition review.

D. From PowerShell, run the Export-ActivityExplorerData cmdlet.

E. From PowerShell, run the Get-RetentionEvent cmdlet.

Correct Answer: B

Explanation:

A file plan is a detailed inventory of the record categories or types that a company creates or receives, the location where these records are stored, and the retention periods and disposition actions for each category.

In the context of Microsoft 365, exporting a file plan from the Purview compliance portal allows you to get detailed information about retention labels, including whether the label marks content as a record, whether it is regulatory (meets specific regulatory requirements) and the disposition type (how the content is managed at the end of its retention period).
Other Options:

A. From the Microsoft Purview compliance portal, export Compliance Manager assessment actions. This option is focused on exporting actions related to compliance assessments rather than details specific to retention labels.

C. From the Microsoft Purview compliance portal, export a disposition review. This would export information related to the review process for content that has reached the end of its retention period, not the specific details of the retention labels themselves.

D. From PowerShell, run the Export-ActivityExplorerData cmdlet. This cmdlet is used to export user and admin activities from Activity Explorer, not details of retention labels.

E. From PowerShell, run the Get-RetentionEvent cmdlet. This cmdlet does not exist in the context of Microsoft 365’s compliance features. Even if it did, the description does not align with exporting detailed information about retention labels.

Therefore, Option B is the correct action to take to achieve the goal of exporting detailed information about a retention label, including its record status, regulatory status, and disposition type.

Question 8:

You are creating a data loss prevention (DLP) policy that will apply to all available locations. You configure an advanced DLP rule in the policy. Which type of condition can you use in the rule?

A. Keywords

B. Content search query

C. Sensitive info type

D. Sensitive label

Correct Answer: C

Explanation:

Sensitive info types are predefined or custom definitions that are used to identify sensitive items like financial, medical, or personal information within content. DLP policies utilize these types to detect and protect sensitive information across different locations such as Exchange Online, SharePoint Online, and OneDrive for Business. Configuring a DLP rule to trigger based on the presence of sensitive info types allows for precise control over the handling of specific types of sensitive data.
Other Options:

A. Keywords: While keywords can be a part of a DLP policy condition, they are typically used in combination with other conditions rather than being the primary or sole condition for an advanced DLP rule. Keywords alone might not provide the specificity and accuracy needed for comprehensive DLP enforcement but are still useful in broader content detection scenarios.

B. Content search query: This option is not directly used as a condition in DLP policies. Content search queries are more commonly associated with the search and investigation features within Microsoft 365 compliance solutions, rather than as conditions for DLP rules.

D. Sensitive label: Sensitive labels are used within Microsoft 365 to classify and protect content based on its sensitivity. While they are a crucial part of information protection, they serve a different purpose from the conditions used in DLP rules.

However, it’s worth noting that DLP policies can be configured to act based on the presence or absence of such labels, making this also a valid condition for a DLP rule, especially in scenarios where the policy needs to differentiate between protected and unprotected content.

Given the context of the question emphasizing an advanced DLP rule and the specific types of conditions that can be used, the Sensitive info type (Option C) is the most fitting answer because it directly relates to the types of data that DLP policies are designed to detect and protect.

However, it’s important to understand that in practical applications, DLP rules can be configured to utilize a combination of conditions, including sensitive info types and sensitive labels, to effectively protect sensitive information.

Question 9:

HOTSPOT

You have a Microsoft 365 tenant named contoso.com that contains two users named User1 and User2. The tenant uses Microsoft Office 365 Message Encryption (OME).

User1 plans to send emails that contain attachments as shown in the following table.

Microsoft SC-400 Exam Question 9

User2 plans to send emails that contain attachments as shown in the following table.

Microsoft SC-400 Exam Question 9-2

For which emails will the attachments be protected? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Hot Area:

Microsoft SC-400 Exam Question 9-3

Correct Answer:

Microsoft SC-400 Exam Question 9-4

Question 10:

You have a Microsoft 365 E5 tenant that contains a user named User1.

You need to identify the type and number of holds placed on the mailbox of User1.

What should you do first?

A. From the Microsoft 365 compliance center, create an eDiscovery case.

B. From Exchange Online PowerShell, run the Get-Mailbox cmdlet.

C. From the Microsoft 365 compliance center, run a content search.

D. From Exchange Online PowerShell, run the Get-HoldCompliancePolicy cmdlet.

Correct Answer: D

Explanation:

The Get-Mailbox cmdlet in Exchange Online PowerShell can be used to view the properties of a user’s mailbox, including information about any holds that are placed on the mailbox. To specifically identify the types and numbers of holds, you would use this cmdlet along with additional parameters or pipelining to filter or extract details about litigation holds, retention policies, or eDiscovery holds applied to the mailbox. For instance, you might use Get-Mailbox -Identity User1 | Format-List hold to list all properties related to holds for User1’s mailbox.

Other Options:

A. From the Microsoft 365 compliance center, create an eDiscovery case. While creating an eDiscovery case can be part of a process to search and hold content, it’s not the first step you would take just to identify existing holds on a mailbox. This option is more about taking action based on content rather than auditing or reporting existing conditions.

C. From the Microsoft 365 compliance center, run a content search. Running a content search is useful for finding specific items across Microsoft 365 services based on search criteria. However, it doesn’t directly provide information about the holds on a particular mailbox.

D. From Exchange Online PowerShell, run the Get-HoldCompliancePolicy cmdlet. This cmdlet does not exist. The intention might be to use cmdlets that can retrieve information about compliance policies affecting the mailbox, such as Get-LitigationHold or Get-MailboxSearch (for eDiscovery holds), but the specific cmdlet mentioned is incorrect.

Given the goal is to identify the types and numbers of holds on a mailbox, Option D with the correct cmdlet (Get-Mailbox) provides the most straightforward and effective path to obtaining this information. However, the explanation clarifies the intent and corrects the cmdlet usage for achieving the task.

Reference: https://docs.microsoft.com/en-us/microsoft-365/compliance/identify-a-hold-on-an-exchange-online-mailbox?view=o365-worldwide

Question 11:

You are creating an advanced data loss prevention (DLP) rule in a DLP policy named Policy 1 that will have all locations selected. Which two conditions can you use in the rule? Each correct answer presents a complete solution. (Choose two.)

NOTE: Each correct selection is worth one point.

A. Content contains

B. Content is shared from Microsoft 365

C. Document size equals or is greater than

D. Attachment\’s file extension is

E. Document property is

Correct Answer: AE

Explanation of Other Options:

B. Content is shared from Microsoft 365

While DLP policies can restrict the sharing of sensitive information outside the organization, the condition “content is shared from Microsoft 365” is not typically listed as a specific condition in DLP rule configuration. DLP policies focus more on the sensitivity of the content rather than the act of sharing itself.

C. Document size equals or is greater than

This condition is not typically a part of DLP rule configurations. DLP policies are more concerned with the sensitivity of the content rather than the size of a document. The size of a document might be relevant in other contexts, such as email delivery or storage policies, but not directly for DLP.
D. Attachment’s file extension is

While restricting or monitoring specific file types can be an aspect of data protection, this condition is not typically used directly in DLP rule configurations within Microsoft 365. DLP policies usually focus on the content within files rather than the file types or extensions themselves.


Therefore, Options A (Content contains) and E (Document property is) are the correct choices for conditions that can be used in an advanced DLP rule in a policy named Policy 1 that covers all locations. These conditions allow for precise targeting of sensitive information based on its content or metadata properties.

Question 12:

HOTSPOT

You have a Microsoft 365 E5 tenant.

You create sensitivity labels as shown in the Sensitivity Labels exhibit.

Microsoft SC-400 Exam Question 12

The Confidential/External sensitivity label is configured to encrypt files and emails when applied to content. The sensitivity labels are published as shown in the Published exhibit.

Microsoft SC-400 Exam Question 12-2

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Hot Area:

Microsoft SC-400 Exam Question 12-3

Correct Answer:

Microsoft SC-400 Exam Question 12-4

Question 13:

HOTSPOT

You have a data loss prevention (DLP) policy that has the advanced DLP rules shown in the following table.

Microsoft SC-400 Exam Question 13

You need to identify which rules will apply when content matches multiple advanced DLP rules.

Which rules should you identify? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

Microsoft SC-400 Exam Question 13-2

Correct Answer:

Microsoft SC-400 Exam Question 13-3

Reference: https://docs.microsoft.com/en-us/microsoft-365/compliance/data-loss-prevention-policies?view=o365-worldwide

Question 14:

HOTSPOT

You have a Microsoft 365 E5 tenant that contains the users shown in the following table.

Microsoft SC-400 Exam Question 14

You have a retention policy that has the following configurations:

1.Name: Policy1

2.Retain items for a specific period: 5 years

3.Locations to apply the policy: Exchange email, SharePoint sites

You place a Preservation Lock on Policy1.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Hot Area:

Microsoft SC-400 Exam Question 14-2

Correct Answer:

Microsoft SC-400 Exam Question 14-3

When a retention policy is locked:

1.No one, including the global admin, can disable the policy or delete it

2. Locations can be added but not removed

3. You can extend the retention period but not decrease it

Reference: https://docs.microsoft.com/en-us/microsoft-365/compliance/retention-preservation-lock?view=o365-worldwide

Question 15:

HOTSPOT

You are implementing Microsoft Office 365 Message Encryption (OME) for a Microsoft 365 tenant named contoso.com.

You need to meet the following requirements:

1. All emails to a domain named fabrikam.com must be encrypted automatically.

2. Encrypted emails must expire seven days after they are sent.

What should you configure for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Hot Area:

Correct Answer:

Microsoft SC-400 Exam Question 15-2

More Microsoft 365 Exam Questions…

Now that we’ve shared the online practice questions, let’s talk about other learning resources!

Here you can find various forms of SC-400 (Administering Information Protection and Compliance in Microsoft 365) learning resources.

SC-400 (Administering Information Protection and Compliance in Microsoft 365) Learning Resource Integration (2024)

With a link for your convenience. Save time.

Document Format:

Book Format:

  1. Microsoft Information Protection Administrator SC-400 Certification Guide: Advance your Microsoft Security & Compliance services knowledge and pass the SC-400 exam with confidence
  2. Microsoft SC-400: Exclusive Exam Preparation: Information Protection Administrator – LATEST EXAM QUESTIONS & EXPLANATION (Microsoft Certifications Exams Preparation Books – NEW & EXCLUSIVE)

(For reference only)

Of course, there are many other exam study resources that you are welcome to add.

Perhaps, you still have doubts about the exam.

Question Of The Most Concern: Microsoft SC-400 Exam

What knowledge is the best thing to know to study for the Microsoft SC-400 exam?

The following knowledge points are required:
Microsoft 365 applications
Microsoft Online Exchange
Microsoft SharePoint
Microsoft OneDrive
Microsoft Teams
PowerShell

What will happen to the SC-400 exam “Microsoft 365 Defender portal” in late April 2024?

Yes, the Microsoft 365 Defender portal will change to the Microsoft Defender portal.

Where can I find free Microsoft SC-400 dumps and questions 2024?

Here, Certificationvce. Or you can find more on Microsoft-technet.com.

Well, it’s time for you to study hard.

Final sentence:

With SC-400 dumps 2024, you can improve your understanding and proficiency in the Administering Information Protection and Compliance in Microsoft 365 exam and be better prepared to ensure a top-notch score in the exam.

Download SC-400 Dumps 2024 https://www.pass4itsure.com/sc-400.html PDF, VCE, and its new premium plan, All 4000+ Exam PDF&VCE dumps, One Package, from $199.79! Prepare for the exam with ease.

Exam Name Free Online practice test Free PDF Dumps Premium Exam Dumps
Designing and Implementing an Azure AI Solution (AI-100) Free AI-100 practice test (Online) Free AI-100 PDF Dumps (Download) pass4itsure AI-100 Exam Dumps (Premium)
Analyzing Data with Microsoft Power BI (DA-100) Free DA-100 practice test (Online) Free DA-100 PDF Dumps (Download) pass4itsure DA-100 Exam Dumps (Premium)
Designing and Implementing a Data Science Solution on Azure (DP-100) Free DP-100 practice test (Online) Free DP-100 PDF Dumps (Download) pass4itsure DP-100 Exam Dumps (Premium)
Implementing an Azure Data Solution (DP-200) Free DP-200 practice test (Online) Free DP-200 PDF Dumps (Download) pass4itsure DP-200 Exam Dumps (Premium)
Designing an Azure Data Solution (DP-201) Free DP-201 practice test (Online) Free DP-201 PDF Dumps (Download) pass4itsure DP-201 Exam Dumps (Premium)
Administering Relational Databases on Microsoft Azure (DP-300) Free DP-300 practice test (Online) Free DP-300 PDF Dumps (Download) pass4itsure DP-300 Exam Dumps (Premium)
Microsoft Azure Data Fundamentals (DP-900) Free DP-900 practice test (Online) Free DP-900 PDF Dumps (Download) pass4itsure DP-900 Exam Dumps (Premium)
Querying Data with Transact-SQL (70-761) Free 70-761 practice test (Online) Free 70-761 PDF Dumps (Download) pass4itsure 70-761 Exam Dumps (Premium)
Developing SQL Databases (70-762) Free 70-762 practice test (Online) Free 70-762 PDF Dumps (Download) pass4itsure 70-762 Exam Dumps (Premium)
Administering a SQL Database Infrastructure (70-764) Free 70-764 practice test (Online) Free 70-764 PDF Dumps (Download) pass4itsure 70-764 Exam Dumps (Premium)
Provisioning SQL Databases (70-765) Free 70-765 practice test (Online) Free 70-765 PDF Dumps (Download) pass4itsure 70-765 Exam Dumps (Premium)
Implementing a Data Warehouse Using SQL (70-767) Free 70-767 practice test (Online) Free 70-767 PDF Dumps (Download) pass4itsure 70-767 Exam Dumps (Premium)
Developing SQL Data Models (70-768) Free 70-768 practice test (Online) Free 70-768 PDF Dumps (Download) pass4itsure 70-768 Exam Dumps (Premium)
Analyzing and Visualizing Data with Microsoft Power BI (70-778) Free 70-778 practice test (Online) Free 70-778 PDF Dumps (Download) pass4itsure 70-778 Exam Dumps (Premium)
Analyzing and Visualizing Data with Microsoft Excel (70-779) Free 70-779 practice test (Online) Free 70-779 PDF Dumps (Download) pass4itsure 70-779 Exam Dumps (Premium)
 latest AZ-900 dumps 2023

The AZ-900 exam is a stepping stone to success in the Microsoft industry. To help you prepare for the AZ-900 exam, we offer a plan: Try the Microsoft AZ-900 dumps of the Pass4itSure update and succeed on the AZ-900 exam with the actual AZ-900 exam questions.

Saving the Microsoft Azure Fundamentals exam? The latest AZ-900 dumps online download: https://www.pass4itsure.com/az-900.html to pass this exam smoothly.

Related to AZ-900

You need to understand which exams it is related to and where it is headed, as shown below.

AZ-900 Exam Development Roadmap

The AZ-900 exam is too difficult, how to save it?

AZ-900 is only an introductory exam for other advanced Microsoft certifications, but it’s not a small challenge. You need thorough preparation to pass.

Back to business, how to save your AZ-900 exam? Use Pass4itSure AZ-900 dumps, use Pass4itSure AZ-900 dumps, use Pass4itSure AZ-900 dumps. Say important things three times.

Pass4itSure: A reliable platform

Pass4itSure adheres to the principles of honesty, truthfulness, and trustworthiness, and provides you with real-time updated AZ-900 dumps exam preparation resources at a moderate price to help you complete the exam.

Latest-2023 Microsoft AZ-900 real questions (free share)

Question 1:

You have a virtual machine named VM1 that runs Windows Server 2016. VM1 is in the East US Azure region.

Which Azure service should you use from the Azure portal to view service failure notifications that can affect the availability of VM1?

A. Azure Service Fabric

B. Azure Monitor

C. Azure virtual machines

D. Azure Advisor

Correct Answer: C

In the Azure virtual machines page in the Azure portal, there is a named Maintenance Status. This column will display service issues that could affect your virtual machine. A service failure is rare but host server maintenance that could affect your virtual machines is more common.

Azure periodically updates its platform to improve the reliability, performance, and security of the host infrastructure for virtual machines. The purpose of these updates ranges from patching software components in the hosting environment to upgrading networking components or decommissioning hardware.

References: https://docs.microsoft.com/en-us/azure/virtual-machines/maintenance-and-updates


Question 2:

Fill in the blank (______________________) in Azure Firewall enables users on the internet to access a server on a virtual network.

Correct Answer: Network Address Translation(NAT) rules


Question 3:

DRAG DROP

Match the Azure service to the correct description.

Instructions: To answer, drag the appropriate Azure service from the column on the left to its description on the right. Each service may be used once, more than once, or not at all.

NOTE: Each correct match is worth one point.

Select and Place:

az-900 test questions 3

Correct Answer:

az-900 test questions 3-2

Explanation:

Box 1: Azure SQL Database

SQL Server is a relational database service. Azure SQL Database is a managed SQL Server Database in Azure. The SQL Server is managed by Microsoft; you just have access to the database.

Box 2: Azure SQL Synapse Analytics

Azure SQL Synapse Analytics (previously called Data Warehouse) is a cloud-based Platform-as-a-Service (PaaS) offering from Microsoft. It is a large-scale, distributed, MPP (massively parallel processing) relational database technology in the same class of competitors as Amazon Redshift or Snowflake.

Azure SQL Synapse Analytics is an important component of the Modern Data Warehouse multi-platform architecture.

Because Azure SQL Synapse Analytics is an MPP system with a shared-nothing architecture across distributions, it is meant for large-scale analytical workloads which can take advantage of parallelism.

Box 3: Azure Data Lake Analytics

You can process big data jobs in seconds with Azure Data Lake Analytics.

You can process petabytes of data for diverse workload categories such as querying, ETL, analytics, machine learning, machine translation, image processing, and sentiment analysis by leveraging existing libraries written in .NET languages, R or Python.

Box 4: Azure HDInsight.

Apache Hadoop was the original open-source framework for distributed processing and analysis of big data sets on clusters. The Hadoop ecosystem includes related software and utilities, including Apache Hive, Apache HBase, Spark, Kafka, and many others.

Azure HDInsight is a fully managed, full-spectrum, open-source analytics service in the cloud for enterprises.

The Apache Hadoop cluster type in Azure HDInsight allows you to use HDFS, YARN resource management, and a simple MapReduce programming model to process and analyze batch data in parallel.

Reference:

https://azure.microsoft.com/en-us/services/sql-database/

https://docs.microsoft.com/en-us/azure/sql-data-warehouse/sql-data-warehouse-overview-what-is

https://docs.microsoft.com/bs-latn-ba/azure/hdinsight/hadoop/apache-hadoop-introduction

https://www.blue-granite.com/blog/is-azure-sql-data-warehouse-a-good-fit-updated

https://azure.microsoft.com/en-gb/services/data-lake-analytics/


Question 4:

You have a resource group named RG1.

You plan to create virtual networks and app services in RG1.

You need to prevent the creation of virtual machines only in RG1.

What should you use?

A. a lock

B. an Azure role

C. a tag

D. an Azure policy

Correct Answer: D

Azure policies can be used to define requirements for resource properties during deployment and for already existing resources. Azure Policy controls properties such as the types or locations of resources.

Azure Policy is a service in Azure that you use to create, assign, and manage policies. These policies enforce different rules and effects over your resources, so those resources stay compliant with your corporate standards and service level agreements.

In this question, we would create an Azure policy assigned to the resource group that denies the creation of virtual machines in the resource group.

You could place a read-only lock on the resource group. However, that would prevent the creation of any resources in the resource group, not virtual machines only. Therefore, an Azure Policy is a better solution.

References:

https://docs.microsoft.com/en-us/azure/governance/policy/overview


Question 5:

Your network contains an Active Directory forest. The forest contains 5,000 user accounts.

Your company plans to migrate all network resources to Azure and to decommission the on-premises data center.

You need to recommend a solution to minimize the impact on users after the planned migration.

What should you recommend?

A. Implement Azure Multi-Factor Authentication (MFA)

B. Sync all the Active Directory user accounts to Azure Active Directory (Azure AD)

C. Instruct all users to change their password

D. Create a guest user account in Azure Active Directory (Azure AD) for each user

Correct Answer: B

To migrate to Azure and decommission the on-premises data center, you would need to create the 5,000 user accounts in Azure Active Directory. The easy way to do this is to sync all the Active Directory user accounts to Azure Active

Directory (Azure AD). You can even sync their passwords to further minimize the impact on users.

The tool you would use to sync the accounts is Azure AD Connect. The Azure Active Directory Connect synchronization services (Azure AD Connect sync) are a main component of Azure AD Connect.

It takes care of all the operations that are related to synchronizing identity data between your on-premises environment and Azure AD.

References:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-whatis


Question 6:

Fill in the blank Azure distributed denial of service (DDoS) protection is an example of a protection that is implemented at the (_______________).

Correct Answer: networking layer


Question 7:

HOTSPOT

Select the answer that correctly completes the sentence.

Hot Area:

az-900 test questions 7

Correct Answer:

az-900 test questions 7-2

Explanation:

Box: within a single Azure region

Azure availability zones are physically separate locations within each Azure region that are tolerant to local failures.

Reference:

https://docs.microsoft.com/en-us/azure/availability-zones/az-overview


Question 8:

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear on the review screen.

Your company deploys several virtual machines on-premises and to Azure. ExpressRoute is being deployed and configured for on-premises to Azure connectivity.

Several virtual machines exhibit network connectivity issues.

You need to analyze the network traffic to identify whether packets are being allowed or denied to the virtual machines.

Solution: Use Azure Traffic Analytics in Azure Network Watcher to analyze the network traffic.

Does this meet the goal?

A. Yes

B. No

Correct Answer: B

Instead use Azure Network Watcher IP Flow Verify, which allows you to detect traffic filtering issues at a VM level.

Note: IP flow verification checks if a packet is allowed or denied to or from a virtual machine. The information consists of direction, protocol, local IP, remote IP, local port, and a remote port. If the packet is denied by a security group, the name of the rule that denied the packet is returned.

While any source or destination IP can be chosen, IP flow verification helps administrators quickly diagnose connectivity issues from or to the internet and from or to the on-premises environment.

Reference:

https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-ip-flow-verify-overview


Question 9:

HOTSPOT

Select the answer that correctly completes the sentence.

Hot Area:

az-900 test questions 9

Correct Answer:

az-900 test questions 9-2

Question 10:

HOTSPOT

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Hot Area:

az-900 test questions 10

Correct Answer:

az-900 test questions 10-2

Box 1: Yes

You can send Azure AD activity logs to Azure Monitor logs to enable rich visualizations, monitoring, and alerting on the connected data.

All data collected by Azure Monitor fits into one of two fundamental types, metrics, and logs (including Azure AD activity logs). Activity logs record when resources are created or modified. Metrics tell you how the resource is performing and the resources that it\’s consuming.

Box 2: Yes

Azure Monitor can consolidate log entries from multiple Azure resources, subscriptions, and tenants into one location for analysis together.

Box 3: Yes

You can create alerts in Azure Monitor.

Alerts in Azure Monitor proactively notify you of critical conditions and potentially attempt to take corrective action. Alert rules based on metrics provide near real-time alerting based on numeric values, while rules based on logs allow for complex logic across data from multiple sources.

References:

https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/concept-activity-logs-azure-monitor

https://docs.microsoft.com/en-us/azure/azure-monitor/overview


Question 11:

DRAG DROP

Match the Azure services to the appropriate descriptions.

To answer, drag the appropriate service from the column on the left to its description on the right. Each service may be used once, more than once, or not at all.

NOTE: Each correct match is worth one point.

Select and Place:

az-900 test questions 11

Correct Answer:

az-900 test questions 11-2

Explanation: Box 1: ExpressRoute ExpressRoute lets you extend your on-premises networks into the Microsoft Cloud over a private connection with the help of a connectivity provider. With ExpressRoute, you can establish connections to Microsoft cloud services, such as Microsoft Azure and Microsoft 365.

Box 2: Virtual network peering enables you to seamlessly connect two or more Virtual Networks in Azure. The virtual networks appear as one for connectivity purposes. The traffic between virtual machines in peered virtual networks uses the Microsoft backbone infrastructure.

Box 3: VPN gateway VPN gateways provide secure connectivity between multiple sites, such as on-premises data centers, Google Cloud Virtual Private Cloud (VPC) networks, and Google Cloud VMware Engine private clouds. Traffic is encrypted because the VPN connections traverse the internet.

Reference: https://docs.microsoft.com/en-us/azure/expressroute/expressroute-introduction https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-peering-overview https://cloud.google.com/vmware-engine/docs/concepts-vpn-gateways


Question 12:

Your company plans 10 migrate all its data and resources to Azure.

The company\’s migration plan states that only Platform as a Service (PaaS) solutions must be used in Azure

You need to deploy an Azure environment that meets the company\’s migration plan

What should you create?

A. an Azure App Service and Azure SQL databases

B. Azure storage accounts and web server in Azure virtual machines

C. Azure virtual machines. Azure SQL databases, and Azure Storage accounts

D. an Azure App Service and Azure virtual machines that have Microsoft SQL Server installed

Correct Answer: A

Azure App Service and Azure SQL databases are examples of Azure PaaS solutions. Therefore, this solution does meet the goal.


Question 13:

What is the longest term you can purchase for Azure Reserved VM Instances?

A. three years

B. four years

C. one year

D. five years

Correct Answer: A


Question 14:

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

Your company is planning to migrate all its virtual machines to an Azure pay-as-you-go subscription. The virtual machines are currently hosted on the Hyper-V hosts in a data center.

You are required to make sure that the intended Azure solution uses the correct expenditure model.

Solution: You should recommend the use of the elastic expenditure model.

Does the solution meet the goal?

A. Yes

B. No

Correct Answer: B


Question 15:

You have an Azure Sentinel workspace.

You need to automate responses to threats detected by Azure Sentinel.

What should you use?

A. adaptive network hardening in Azure Security Center

B. Azure Service Health

C. Azure Monitor workbooks

D. adaptive application controls in Azure Security Center

Correct Answer: C


The above practice questions contain 15 questions for the exam for final preparation. This is not enough and it is recommended that you download the Pass4itSure AZ-900 dumps https://www.pass4itsure.com/az-900.html (there are 604 questions).

Final words:

How do I pass the Microsoft Azure Fundamentals AZ-900 exam? The most effective thing to do is: Download the latest AZ-900 dumps (Pass4itSure) to practice exam questions.

The best online resource to prepare for the Microsoft AZ-204 exam: Pass4itsure full az-204 dumps (Total Questions: 185 Q&A AZ-204 Dumps). The latest AZ-204 exam dumps can help you pass your first exam!

Free share Microsoft AZ-204 online resource

Microsoft AZ-204 exam resource

Exam AZ-204: Developing Solutions for Microsoft Azure
Part of the requirements for: Microsoft Certified: Azure Developer Associate

New 2021 Microsoft AZ-204 dumps pdf from google drive (Update Questions)

Welcome to download [free questions] Microsoft AZ-204 dumps pdf https://drive.google.com/file/d/1PBmVGWtrAhMduQfsEj4Pa797K8CyB1U1/view?usp=sharing

The following are the new 2021 Microsoft AZ-204 exam practice questions(q1-q13), covering real exam answers and questions! You can test yourself!

QUESTION 1
DRAG DROP
You plan to create a Docker image that runs as ASP.NET Core application named ContosoApp. You have a setup script
named setupScript.ps1 and a series of application files including ContosoApp.dll.
You need to create a Dockerfile document that meets the following requirements:
Call setupScript.ps1 when the container is built.
Run ContosoApp.dll when the container starts.
The Docker document must be created in the same folder where ContosoApp.dll and setupScript.ps1 are stored.
Which four commands should you use to develop the solution? To answer, move the appropriate commands from the
list of commands to the answer area and arrange them in the correct order.
Select and Place:

az-204 exam questions-q1

Correct Answer:

az-204 exam questions-q1-2

Step 1: WORKDIR /apps/ContosoApp
Step 2: COPY ./The Docker document must be created in the same folder where ContosoApp.dll and setupScript.ps1
are stored.
Step 3: EXPOSE ./ContosApp/ /app/ContosoApp
Step 4: CMD powershell ./setupScript.ps1
ENTRYPOINT [“dotnet”, “ContosoApp.dll”]
You need to create a Dockerfile document that meets the following requirements:
Call setupScript.ps1 when the container is built.
Run ContosoApp.dll when the container starts.
References:
https://docs.microsoft.com/en-us/azure/app-service/containers/tutorial-custom-docker-image

QUESTION 2
You are developing a software solution for an autonomous transportation system. The solution uses large data sets and
Azure Batch processing to simulate navigation sets for entire fleets of vehicles.
You need to create compute nodes for the solution on Azure Batch.
What should you do?
A. In the Azure portal, add a Job to a Batch account.
B. In a .NET method, call the method: BatchClient.PoolOperations.CreateJob
C. In Python, implement the class: JobAddParameter
D. In Azure CLI, run the command: az batch pool create
E. In a .NET method, call the method: BatchClient.pool operations.CreatePool
F. In Python, implement the class: TaskAddParameter
G. In the Azure CLI, run the command: az batch account create
Correct Answer: B
A Batch job is a logical grouping of one or more tasks. A job includes settings common to the tasks, such as priority and
the pool to run tasks on. The app uses BatchClient.JobOperations.CreateJob method to create a job on your pool.
Note:
Step 1: Create a pool of compute nodes. When you create a pool, you specify the number of compute nodes for the
pool, their size, and the operating system. When each task in your job runs, it\\’s assigned to execute on one of the
nodes in
your pool.
Step 2: Create a job. A job manages a collection of tasks. You associate each job to a specific pool where that job\\’s
tasks will run.
Step 3: Add tasks to the job. Each task runs the application or script that you uploaded to process the data files it
downloads from your Storage account. As each task completes, it can upload its output to Azure Storage.
Incorrect Answers:
C, F: To create a Batch pool in Python, the app uses the PoolAddParameter class to set the number of nodes, VM size,
and a pool configuration.
E: BatchClient.PoolOperations does not have a CreateJob method.
References: https://docs.microsoft.com/en-us/azure/batch/quick-run-dotnet https://docs.microsoft.com/enus/azure/batch/quick-run-python

QUESTION 3
You are developing an internal website for employees to view sensitive data. The website uses Azure Active Directory
(AAD) for authentication.
You need to implement multifactor authentication for the website.
What should you do? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Upgrade to Azure AD Premium.
B. In Azure AD conditional access, enable the baseline policy.
C. In Azure AD, create a new conditional access policy.
D. In Azure AD, enable application proxy.
E. Configure the website to use Azure AD B2C.
Correct Answer: AC
A: Multi-Factor Authentication comes as part of the following offerings:
Azure Active Directory Premium licenses – Full featured use of Azure Multi-Factor Authentication Service (Cloud) or
Azure Multi-Factor Authentication Server (On-premises).
Multi-Factor Authentication for Office 365
Azure Active Directory Global Administrators
C: MFA Enabled by conditional access policy. It is the most flexible means to enable two-step verification for your users.
Enabling using conditional access policy only works for Azure MFA in the cloud and is a premium feature of Azure AD.
References: https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-getstarted

QUESTION 4
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear on the review screen.
You are developing an Azure Service application that processes queue data when it receives a message from a mobile
application. Messages may not be sent to the service consistently.
You have the following requirements:
Queue size must not grow larger than 80 gigabytes (GB).
Use first-in-first-out (FIFO) ordering of messages.
Minimize Azure costs.
You need to implement the messaging solution.
Solution: Use the .Net API to add a message to an Azure Storage Queue from the mobile application. Create an Azure
VM that is triggered by Azure Storage Queue events.
Does the solution meet the goal?
A. Yes
B. No
Correct Answer: B
Don\\’t use a VM, instead create an Azure Function App that uses an Azure Service Bus Queue trigger.
Reference: https://docs.microsoft.com/en-us/azure/azure-functions/functions-create-storage-queue-triggered-function

QUESTION 5
You develop a website. You plan to host the website in Azure. You expect the website to experience high traffic
volumes after it is published.
You must ensure that the website remains available and responsive while minimizing cost.
You need to deploy the website.
What should you do?
A. Deploy the website to a virtual machine. Configure the virtual machine to automatically scale when the CPU load is
high.
B. Deploy the website to an App Service that uses the Shared service tier. Configure the App service plan to
automatically scale when the CPU load is high.
C. Deploy the website to an App Service that uses the Standard service tier. Configure the App service plan to
automatically scale when the CPU load is high.
D. Deploy the website to a virtual machine. Configure a Scale Set to increase the virtual machine instance count when
the CPU load is high.
Correct Answer: C
Windows Azure Web Sites (WAWS) offers 3 modes: Standard, Free, and Shared.
Standard mode carries an enterprise-grade SLA (Service Level Agreement) of 99.9% monthly, even for sites with just
one instance.
Standard mode runs on dedicated instances, making it different from the other ways to buy Windows Azure Web Sites.
Incorrect Answers:
B: Shared and Free modes do not offer the scaling flexibility of Standard, and they have some important limits.
Shared mode, just as the name states, also uses shared Compute resources, and also has a CPU limit. So, while
neither Free nor Shared is likely to be the best choice for your production environment due to these limits.

QUESTION 6
DRAG DROP
You are deploying an Azure Kubernetes Services (AKS) cluster that will use multiple containers
You need to create the cluster and verify that the services for the containers are configured correctly and available.
Which four commands should you use to develop the solution? To answer, move the appropriate command segments
from the list of command segments to the answer area and arrange them in the correct order.

az-204 exam questions-q6

QUESTION 7
You are writing code to create and run an Azure Batch job.
You have created a pool of compute nodes.
You need to choose the right class and its method to submit a batch job to the Batch service.
Which method should you use?
A. JobOperations.EnableJobAsync(String, IEnumerable,CancellationToken)
B. JobOperations.CreateJob()
C. CloudJob.Enable(IEnumerable)
D. JobOperations.EnableJob(String, IEnumerable)
E. CloudJob.CommitAsync(IEnumerable, CancellationToken)
Correct Answer: E
A Batch job is a logical grouping of one or more tasks. A job includes settings common to the tasks, such as priority and
the pool to run tasks on. The app uses BatchClient.JobOperations.CreateJob method to create a job on your pool.
The Commit method submits the job to the Batch service. Initially, the job has no tasks.
{
CloudJob job = batchClient.JobOperations.CreateJob();
job.Id = JobId;
job.PoolInformation = new PoolInformation { PoolId = PoolId };
job.Commit();
}

References:
https://docs.microsoft.com/en-us/azure/batch/quick-run-dotnet

QUESTION 8
Your company is developing an Azure API.
You need to implement authentication for the Azure API. You have the following requirements:
All API calls must be secure.
Callers to the API must not send credentials to the API.
Which authentication mechanism should you use?
A. Basic
B. Anonymous
C. Managed identity
D. Client certificate
Correct Answer: C
Use the authentication-managed-identity policy to authenticate with a backend service using the managed identity of the
API Management service. This policy essentially uses the managed identity to obtain an access token from Azure Active
Directory for accessing the specified resource. After successfully obtaining the token, the policy will set the value of the
token in the Authorization header using the Bearer scheme.
Reference: https://docs.microsoft.com/bs-cyrl-ba/azure/api-management/api-management-authentication-policies

QUESTION 9
DRAG DROP
You are developing an application to use Azure Blob storage. You have configured Azure Blob storage to include
change feeds.
A copy of your storage account must be created in another region. Data must be copied from the current storage
account to the new storage account directly between the storage servers.
You need to create a copy of the storage account in another region and copy the data.
In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area
and arrange them in the correct order.
Select and Place:

az-204 exam questions-q9

Move data to the new storage account.
Delete the resources in the source region.
Note: You must enable the change feed on your storage account to begin capturing and recording changes. You can
enable and disable changes by using Azure Resource Manager templates on Portal or Powershell.
Reference:
https://docs.microsoft.com/en-us/azure/storage/common/storage-account-move
https://docs.microsoft.com/en-us/azure/storage/blobs/storage-blob-change-feed

QUESTION 10
HOTSPOT
You are developing a back-end Azure App Service that scales based on the number of messages contained in a
Service Bus queue.
A rule already exists to scale up the App Service when the average queue length of unprocessed and valid queue
messages is greater than 1000.
You need to add a new rule that will continuously scale down the App Service as long as the scale up condition is not
met.
How should you configure the Scale rule? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

az-204 exam questions-q10

Correct Answer:

az-204 exam questions-q10-2

Box 1: Service bus queue
You are developing a back-end Azure App Service that scales based on the number of messages contained in a
Service Bus queue.
Box 2: ActiveMessage Count
ActiveMessageCount: Messages in the queue or subscription that are in the active state and ready for delivery.
Box 3: Count
Box 4: Less than or equal to
You need to add a new rule that will continuously scale down the App Service as long as the scale up condition is not
met.
Box 5: Decrease count by


QUESTION 11
HOTSPOT
You are developing a ticket reservation system for an airline.
The storage solution for the application must meet the following requirements:
Ensure at least 99.99% availability and provide low latency.
Accept reservations event when localized network outages or other unforeseen failures occur.
Process reservations in the exact sequence as reservations are submitted to minimize overbooking or selling the same
seat to multiple travelers.
Allow simultaneous and out-of-order reservations with a maximum five-second tolerance window.
You provision a resource group named airlineResourceGroup in the Azure South-Central US region.
You need to provision a SQL SPI Cosmos DB account to support the app.
How should you complete the Azure CLI commands? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area

az-204 exam questions-q11

az-204 exam questions-q11-2

Box 1: BoundedStaleness
Bounded staleness: The reads are guaranteed to honor the consistent-prefix guarantee. The reads might lag behind
writes by at most “K” versions (that is, “updates”) of an item or by “T” time interval. In other words, when you choose
bounded staleness, the “staleness” can be configured in two ways:
The number of versions (K) of the item
The time interval (T) by which the reads might lag behind the writes
Incorrect Answers:
Strong
Strong consistency offers a linearizability guarantee. Linearizability refers to serving requests concurrently. The reads
are guaranteed to return the most recent committed version of an item. A client never sees an uncommitted or partial
write.
Users are always guaranteed to read the latest committed write.
Box 2: –enable-automatic-failover true\
For multi-region Cosmos accounts that are configured with a single-write region, enable automatic-failover by using
Azure CLI or Azure portal. After you enable automatic failover, whenever there is a regional disaster, Cosmos DB will
automatically failover your account.

QUESTION 12
HOTSPOT
You are building a traffic monitoring system that monitors traffic along six highways. The system produces time series
analysis-based reports for each highway. Data from traffic sensors are stored in Azure Event Hub.
Traffic data is consumed by four departments. Each department has an Azure Web App that displays the time-seriesbased reports and contains a WebJob that processes the incoming data from Event Hub. All Web Apps run on App
Service
Plans with three instances.
Data throughout must be maximized. Latency must be minimized.
You need to implement the Azure Event Hub.
Which settings should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

az-204 exam questions-q12

Correct Answer:

az-204 exam questions-q12-2

Box 1: 6
The number of partitions is specified at creation and must be between 2 and 32.
There are 6 highways.
Box 2: Highway
References:
https://docs.microsoft.com/en-us/azure/event-hubs/event-hubs-features

QUESTION 13
HOTSPOT
You need to secure the Shipping Function app.
How should you configure the app? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

az-204 exam questions-q13

Correct Answer:

az-204 exam questions-q13-2

Scenario: Shipping Function app: Implement secure function endpoints by using app-level security and include Azure
Active Directory (Azure AD). Box 1: Function Box 2: JSON based Token (JWT) Azure AD uses JSON based tokens
(JWTs) that contain claims Box 3: HTTP How a web app delegates sign-in to Azure AD and obtains a token User
authentication happens via the browser. The OpenID protocol uses standard HTTP protocol messages. References:
https://docs.microsoft.com/en-us/azure/active-directory/develop/authentication-scenarios

Why choosing Pass4itsure exam dumps!

why pass4itsure exam dumps

Latest Pass4itsure candidates pass feedback

Latest Pass4itsure candidates pass feedback

Pass4itsure Microsoft dumps discount code 2021 free share

Share the Pass4itsure Microsoft dumps discount code “Microsoft”. Pass4itsure value your money and gives you a 15% discount on the purchase of a complete AZ-204 exam preparation product set practice test software, PDF Q&A. 

The last sentence:

This blog shares the latest Microsoft AZ-204 exam questions, and answers! Microsoft AZ-204 pdf, Microsoft AZ-204 exam video! Get full Pass4itsure 100% pass & stable Microsoft AZ-204 dumps!

ps.