DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Conquer the AZ-104 Exam with Free Microsoft Azure Administrator Practice Questions

Exam NameMicrosoft Certified - Azure Administrator Associate
Exam CodeAZ-104
Exam Price$165 (USD)
Duration120 mins
Number of Questions40-60
Passing Score700 / 1000
Books / TrainingAZ-104T00-A: Microsoft Azure Administrator

Your key to AZ-104 exam success is here! Access our free Microsoft Azure Administrator practice questions and answers. Navigate through an extensive practice test and exam questions dump for ultimate preparation.

Take other online exams

Question #1
You need to configure an Azure web app named contoso.azurewebsites.net to host www.contoso.com. What should you do first?
A. reate a CNAME record named asuid that contains the domain verification ID
B. reate a TXT record named www
C. reate A records named www
D. reate a TXT record named asuid that contains the domain verification ID
View answer
Correct Answer: A
Question #2
You have an Azure subscription that contains a virtual network named VNet1. VNet1 uses two ExpressRoute circuits that connect to two separate on-premises datacenters. You need to create a dashboard to display detailed metrics and a visual representation of the network topology. What should you use?
A. zure Monitor Network Insights
B. Data Collection Rule (DCR)
C. og Analytics
D. zure Virtual Network Watcher
View answer
Correct Answer: A
Question #3
You have an Azure subscription that contains 10 virtual machines, a key vault named Vault1, and a network security group (NSG) named NSG1. All the resources are deployed to the East US Azure region. The virtual machines are protected by using NSG1. NSG1 is configured to block all outbound traffic to the internet. You need to ensure that the virtual machines can access Vault1. The solution must use the principle of least privilege and minimize administrative effort What should you configure as the destination of the outbound security rule for NSG1?
A. n application security group
B. service tag
C. n IP address range
View answer
Correct Answer: B
Question #4
You have an Azure DNS zone named adatum.com. You need to delegate a subdomain named research.adatum.com to a different DNS server in Azure. What should you do?
A. Modify the SOA record of adatum
B. Create an A record named *
C. Create an PTR record named research in the adatum
D. Create an NS record named research in the adatum
View answer
Correct Answer: D
Question #5
You have five Azure virtual machines that run Windows Server 2016. The virtual machines are configured as web servers. You have an Azure load balancer named LB1 that provides load balancing services for the virtual machines. You need to ensure that visitors are serviced by the same web server for each request. What should you configure?
A. loating IP (direct server return) to Disabled
B. dle Time-out (minutes) to 20
C. rotocol to UDP
D. ession persistence to Client IP
View answer
Correct Answer: D
Question #6
You have an Azure subscription that contains a storage account named account1.You plan to upload the disk files of a virtual machine to account1 from your on-premises network. The on- premises network uses a public IP address space of 131.107.1.0/24. You plan to use the disk files to provision an Azure virtual machine named VM1. VM1 will be attached to a virtual network named VNet1. VNet1 uses an IP address space of 192.168.0.0/24. You need to configure account1 to meet the following requirements: Ensure that you can upload the disk files to account1. Ensure that you can attach the disks to VM1. Prevent all other access to account1. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
A. rom the Firewalls and virtual networks blade of account1, select Selected networks
B. rom the Firewalls and virtual networks blade of account1, select Allow trusted Microsoft services to access this storage account
C. rom the Firewalls and virtual networks blade of account1, add the 131
D. rom the Firewalls and virtual networks blade of account1, add VNet1
E. rom the Service endpoints blade of VNet1, add a service endpoint
View answer
Correct Answer: AC
Question #7
You have two subscriptions named Subscription1 and Subscription2. Each subscription is associated to a different Azure AD tenant. Subscription1 contains a virtual network named VNet1. VNet1 contains an Azure virtual machine named VM1 and has an IP address space of 10.0.0.0/16. Subscription2 contains a virtual network named VNet2. VNet2 contains an Azure virtual machine named VM2 and has an IP address space of 10.10.0.0/24. You need to connect VNet1 to VNet2. What should you do first?
A. ove VM1 to Subscription2
B. ove VNet1 to Subscription2
C. odify the IP address space of VNet2
D. rovision virtual network gateways
View answer
Correct Answer: D
Question #8
You sign up for Azure AD Premium P2. You need to add a user named admin1@contoso.com as an administrator on all the computers that will be joined to the Azure AD domain. What should you configure in Azure AD?
A. ser settings from the Users blade
B. evice settings from the Devices blade
C. eneral settings from the Groups blade
D. roviders from the MFA Server blade
View answer
Correct Answer: B
Question #9
You deploy Azure virtual machines to three Azure regions. Each region contains a virtual network. Each virtual network contains multiple subnets peered in a full mesh topology. Each subnet contains a network security group (NSG)that has defined rules. A user reports that he cannot use port 33000 to connect from a virtual machine in one region to a virtual machine in another region. Which two options can you use to diagnose the issue? Each correct answer presents a complete solution. NOTE:Each correct selection is worth one point.
A. zure Monitor Network Insights
B. P flow verify
C. ffective security rules
D. onnection troubleshoot
E. zure Virtual Network Manager
View answer
Correct Answer: B
Question #10
You have an Azure subscription that contains 20 virtual machines, a network security group (NSG) named NSG1, and two virtual networks named VNET1 and VNET2 that are peered. You plan to deploy an Azure Bastion Basic SKU host named Bastion1 to VNET1. You need to configure NSG1 to allow inbound access to the virtual machines via Bastion1. Which port should you configure for the inbound security rule?
A. 2
B. 43
C. 89
D. 080
View answer
Correct Answer: B

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number: