The latest Microsoft Azure AZ-101 exam Practice Questions and Answers

We share the latest effective Microsoft Azure AZ-101 exam dumps online Practice test to improve your skills! You can also choose AZ-101 PDF or AZ-101 YouTube to learn! Get the full AZ-101 dumps: https://www.pass4itsure.com/AZ-101.html (Q&As: 102 ) to pass the exam easily!

[PDF] Free Microsoft Azure AZ-101 pdf dumps download from Google Drive: https://drive.google.com/open?id=1SYcAiZoKz-5sVRgXjbtmNUS0sl8HRAZY

[PDF] Free Full Microsoft pdf dumps download from Google Drive: https://drive.google.com/open?id=1gdQrKIsiLyDEsZ24FxsyukNPYmpSUDDO

Exam AZ-101: Microsoft Azure Integration and Security: https://www.microsoft.com/en-us/learning/exam-az-101.aspx

  • Evaluate and perform server migration to Azure (15-20%)
  • Implement and manage application services (20-25%)
  • Implement advanced virtual networking (30-35%)
  • Secure identities (25-30%)

Latest effective Microsoft Azure AZ-101 Exam Practice Tests

QUESTION 1
You need to create a function app named corp7509086nl that supports sticky sessions. The solution must minimize the
Azure-related costs of the App Service plan. What should you do from the Azure portal?
A. Check the answer in explanation.
Correct Answer: A
See explanation below.
Step 1:
Select the New button found on the upper left-hand corner of the Azure portal, then select Compute > Function App.
Step 2:
Use the function app settings as listed below.
App name: corp7509086n1
Hosting plan: Azure App Service plan
(need this for the sticky sessions)
Pricing tier of the the App Service plan: Shared compute: Free
Step 3:
Select Create to provision and deploy the function app.
References:
https://docs.microsoft.com/en-us/azure/azure-functions/functions-create-function-app-portal

QUESTION 2
You have an Azure subscription.
You enable multi-factor authentication for all users.
Some users report that the email applications on their mobile device cannot co browser and from Microsoft Outlook
2016 on their computer.
You need to ensure that the users can use the email applications on their mobile device.
What should you instruct the users to do?
The users can access Exchange Online by using a web
A. Enable self-service password reset.
B. Create an app password.
C. Reset the Azure Active Directory (Azure AD) password.
D. Reinstall the Microsoft Authenticator app.
Correct Answer: A
References: https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-howitworks

QUESTION 3
You are the global administrator for an Azure Active Directory (Azure AD) tenet named adatum.com.
You need to enable two-step verification for Azure users.
What should you do?
A. Create a sign-in risk policy in Azure AD Identity Protection
B. Enable Azure AD Privileged Identity Management.
C. Create and configure the Identity Hub.
D. Configure a security policy in Azure Security Center.
Correct Answer: A
With Azure Active Directory Identity Protection, you can:
require users to register for multi-factor authentication
handle risky sign-ins and compromised users References: https://docs.microsoft.com/en-us/azure/active-
directory/identity-protection/flows

QUESTION 4
You have an Azure virtual network named VNet1 that contains a subnet named Subnet1. Subnet1 contains three Azure
virtual machines. Each virtual machine has a public IP address.
The virtual machines host several applications that are accessible over port 443 to user on the Internet.
Your on-premises network has a site-to-site VPN connection to VNet1.
You discover that the virtual machines can be accessed by using the Remote Desktop Protocol (RDP) from the Internet
and from the on-premises network.
You need to prevent RDP access to the virtual machines from the Internet, unless the RDP connection is established
from the on-premises network. The solution must ensure that all the applications can still be accesses by the Internet
users.
What should you do?
A. Modify the address space of the local network gateway.
B. Remove the public IP addresses from the virtual machines.
C. Modify the address space of Subnet1.
D. Create a deny rule in a network security group (NSG) that is linked to Subnet1.
Correct Answer: D

QUESTION 5
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
You have an Azure Active Directory (Azure AD) tenant named Adatum and an Azure Subscription named Subscription1.
Adatum contains a group named Developers. Subscription1 contains a resource group named Dev.
You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group.
Solution: On Subscription1, you assign the DevTest Labs User role to the Developers group.
Does this meet the goal?
A.
B. Yes
C. No
Correct Answer: B
DevTest Labs User role only lets you connect, start, restart, and shutdown virtual machines in your Azure DevTest
Labs.
You would need the Logic App Contributor role.
References:
https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles
https://docs.microsoft.com/en-us/azure/logic-apps/logic-apps-securing-a-logic-app

QUESTION 6
You need to create a web app named corp7509086n2 that can be scaled horizontally. The solution must use the lowest
possible pricing tier for the App Service plan. What should you do from the Azure portal?
A. Check the answer in explanation.
Correct Answer: A
See explanation below.
Step 1:
In the Azure Portal, click Create a resource > Web + Mobile > Web App.
Step 2:
Use the Webb app settings as listed below.
Web App name: corp7509086n2
Hosting plan: Azure App Service plan
Pricing tier of the Pricing Tier: Standard
Change your hosting plan to Standard, you can\\’t setup auto-scaling below standard tier.
Step 3:
Select Create to provision and deploy the Web app.
References:
https://docs.microsoft.com/en-us/azure/app-service/environment/app-service-web-how-to-create-a-web-app-in-an-ase
https://azure.microsoft.com/en-us/pricing/details/app-service/plans/

QUESTION 7
You have a public load balancer that balancer ports 80 and 443 across three virtual machines.
You need to direct all the Remote Desktop protocol (RDP) to VM3 only.
What should you configure?
A. an inbound NAT rule
B. a load public balancing rule
C. a new public load balancer for VM3
D. a new IP configuration
Correct Answer: A
To port forward traffic to a specific port on specific VMs use an inbound network address translation (NAT) rule.

QUESTION 8
You create an Azure subscription that is associated to a basic Azure Active Directory (Azure AD) tenant. You need to
receive an email notification when any user activates an administrative role. What should you do?
A. Purchase Azure AD Premium 92 and configure Azure AD Privileged Identity Management,
B. Purchase Enterprise Mobility + Security E3 and configure conditional access policies.
C. Purchase Enterprise Mobility + Security E5 and create a custom alert rule in Azure Security Center.
D. Purchase Azure AD Premium PI and enable Azure AD Identity Protection.
Correct Answer: A
When key events occur in Azure AD Privileged Identity Management (PIM), email notifications are sent. For example,
PIM sends emails for the following events:
When a privileged role activation is pending approval
When a privileged role activation request is completed
When a privileged role is activated
When a privileged role is assigned
When Azure AD PIM is enabled
References:
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-email-notifications

QUESTION 9
You are configuring Azure Active Directory (AD) Privileged Identity Management.
You need to provide a user named Admm1 with read access to a resource group named RG1 for only one month.
The user role must be assigned immediately.
What should you do?
A. Assign an active role.
B. Assign an eligible role.
C. Assign a permanently active role.
D. Create a custom role and a conditional access policy.
Correct Answer: B
Azure AD Privileged Identity Management introduces the concept of an eligible admin. Eligible admins should be users
that need privileged access now and then, but not all-day, every day. The role is inactive until the user needs access,
then
they complete an activation process and become an active admin for a predetermined amount of time.
References:
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure

QUESTION 10
From the MFA Server blade, you open the Block/unblock users blade as shown in the exhibit.pass4itsure az-101 exam question q10What caused AlexW to be blocked?
A. An administrator manually blocked the user.
B. The user reports a fraud alert when prompted for additional authentication.
C. The user account password expired.
D. The user entered an incorrect PIN four times within 10 minutes.
Correct Answer: B


QUESTION 11
You have a Microsoft SQL Server Always On availability group on Azure virtual machines. You need to configure an
Azure internal load balancer as a listener for the availability group. What should you do?
A. Enable Floating IP.
B. Set Session persistence to Client IP and protocol.
C. Set Session persistence to Client IP.
D. Create an HTTP health probe on port 1433.
Correct Answer: A


QUESTION 12
You have an Azure subscription that contains a policy-based virtual network gateway named GW1 and a virtual network
named VNet1. You need to ensure that you can configure a point-to-site connection from VNet1 to an on-premises
computer. Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Reset GW1.
B. Add a service endpoint to VNet1.
C. Add a connection to GW1.
D. Add a public IP address space to VNet1.
E. Delete GWL
F. Create a route-based virtual network gateway.
Correct Answer: EF
E: Policy-based VPN devices use the combinations of prefixes from both networks to define how traffic is
encrypted/decrypted through IPsec tunnels. It is typically built on firewall devices that perform packet filtering. IPsec
tunnel encryption and decryption are added to the packet filtering and processing engine.
F: A VPN gateway is used when creating a VPN connection to your on-premises network.
Route-based VPN devices use any-to-any (wildcard) traffic selectors, and let routing/forwarding tables direct traffic to
different IPsec tunnels. It is typically built on router platforms where each IPsec tunnel is modeled as a network interface
or VTI (virtual tunnel interface).


QUESTION 13
You plan to move services from your on-premises network to Azure.
You identify several virtual machines that you believe can be hosted in Azure. The virtual machines are shown in the
following table.pass4itsure az-101 exam question q13Which two virtual machines can you access by using Azure migrate? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. Sea-CA0l
B. Hou-NW01
C. NYC-FS01
D. Sea-DC01
E. BOS-DB01
Correct Answer: CE

We offer more ways to make it easier for everyone to learn, and YouTube is the best tool in the video.Follow channels: https://www.youtube.com/channel/UCTP5RClZrtMxtRkSvIag0DQ/videos get more useful exam content.

Latest Microsoft Azure AZ-101 YouTube videos:

Microsoft Certified: Azure Administrator Associate Azure Administrators implement, monitor, and maintain Microsoft Azure solutions, including major services related to compute, storage, network, and security.

Share 13 of the latest Microsoft Azure AZ-101 dumps Practice tests for free to help you improve your skills. AZ-101 PDF download Online! Get the full AZ-101 dumps: https://www.pass4itsure.com/AZ-101.html (Q&As: 102 ). Easily pass the exam!

[PDF] Free Microsoft Azure AZ-101 pdf dumps download from Google Drive: https://drive.google.com/open?id=1SYcAiZoKz-5sVRgXjbtmNUS0sl8HRAZY

[PDF] Free Full Microsoft pdf dumps download from Google Drive: https://drive.google.com/open?id=1gdQrKIsiLyDEsZ24FxsyukNPYmpSUDDO

Pass4itsure Promo Code 15% Off

pass4itsure az-101 coupon

related: https://www.certificationvce.com/new-discount-cisco-300-560-dumps-npdev-pdf/