DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft AZ-104 Practice Questions & Answers 2026 Part2 | Microsoft Azure Administrator

Are you preparing for the Microsoft AZ-104 certification exam? SPOTO offers the Microsoft AZ-104 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
Your company has serval departments. Each department has a number of virtual machines (VMs).The company has an Azure subscription that contains a resource group named RG1.All VMs are located in RG1.You want to associate each VM with its respective department.What should you do?
A. Create Azure Management Groups for each department
B. Create a resource group for each department
C. Assign tags to the virtual machines
D. Modify the settings of the virtual machines
View answer
Correct Answer: C

View The Updated AZ-104 Exam Questions

SPOTO Provides 100% Real AZ-104 Exam Questions for You to Pass Your AZ-104 Exam!

Question #2
You have an Azure subscription named Subscription1 that contains virtual network named VNet1. VNet1 is in a resource group named RG1.A user named User1 has the following roles for Subscription1: ReaderSecurity Admin Security ReaderYou need to ensure that User1 can assign the Reader role for VNet1 to other users. What should you do?
A. Remove User1 from the Security Reader and Reader roles for Subscription1
B. Assign User1 the Contributor role for VNet1
C. Assign User1 the Owner role for VNet1
D. Assign User1 the Network Contributor role for RG1
View answer
Correct Answer: C
Question #3
You discover that VM3 does NOT meet the technical requirements. You need to verify whether the issue relates to the NSGs. What should you use?
A. Diagram in VNet1
B. the security recommendations in Azure Advisor
C. Diagnostic settings in Azure Monitor
D. Diagnose and solve problems in Traffic Manager Profiles
E. IP flow verify in Azure Network Watcher
View answer
Correct Answer: E
Question #4
You have an Azure subscription that contains a resource group named TestRG. You use TestRG to validate an Azure deployment.TestRG contains the following resources:You need to delete TestRG. What should you do first?
A. Modify the backup configurations of VM1 and modify the resource lock type of VNET1
B. Remove the resource lock from VNET1 and delete all data in Vault1
C. Turn off VM1 and remove the resource lock from VNET1
D. Turn off VM1 and delete all data in Vault1
View answer
Correct Answer: B
Question #5
Your company has an Azure Active Directory (Azure AD) tenant that is configured for hybrid coexistence with the on-premises Active Directory domain.The on-premise virtual environment consists of virtual machines (VMs) running on Windows Server 2012 R2 Hyper-V host servers.You have created some PowerShell scripts to automate the configuration of newly created VMs. You plan to create several new VMs.You need a solution that ensures the scripts are run on the new VMs. Which of the following is the best solution?
A. Configure a SetupComplete
B. Configure a Group Policy Object (GPO) to run the scripts as logon scripts
C. Configure a Group Policy Object (GPO) to run the scripts as startup scripts
D. Place the scripts in a new virtual hard disk (VHD)
View answer
Correct Answer: A
Question #6
You have an Azure subscription that contains the resources shown in the following table.You need to assign User1 the Storage File Data SMB Share Contributor role for share1. What should you do first?
A. Enable identity-based data access for the file shares in storage1
B. Modify the security profile for the file shares in storage1
C. Select Default to Microsoft Entra authorization in the Azure portal for storage1
D. Configure Access control (IAM) for share1
View answer
Correct Answer: A
Question #7
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft Entra tenant named Adatum and an Azure Subscription named Subscription1. Adatum contains a group named Developers. Subscription1 contains a resource group named Dev.You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group. Solution: On Dev, you assign the Logic App Contributor role to the Developers group.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #8
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft Entra tenant named contoso.com.You have a CSV file that contains the names and email addresses of 500 external users. You need to create a guest user account in contoso.com for each of the 500 external users. Solution: From Microsoft Entra ID in the Azure portal, you use the Bulk create user operation. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #9
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has adistinctive result. Establish if the solution satisfies the requirements.Your company has an Azure Active Directory (Azure AD) subscription.You want to implement an Azure AD conditional access policy.The policy must be configured to require members of the Global Administrators group to use Multi-Factor Authentication andan Azure AD-joined device when they connect to Azure AD from untrusted locations.Solution: You access the multi-factor authentication page to alter the user settings.Does the solution meet the goal?
A. es
B. o
View answer
Correct Answer: B
Question #10
You have an Azure subscription that contains multiple virtual machines in the West US Azure region.You need to use Traffic Analytics in Azure Network Watcher to monitor virtual machine traffic.Which two resources should you create? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. a Data Collection Rule (OCR) in Azure Monitor
B. a Log Analytics workspace
C. an Azure Monitor workbook
D. a storage account
E. a Microsoft Sentinel workspace
View answer
Correct Answer: BD
Question #11
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft Entra tenant named contoso.com.You have a CSV file that contains the names and email addresses of 500 external users. You need to create a guest user account in contoso.com for each of the 500 external users. Solution: You create a PowerShell script that runs the New-MgUser cmdlet for each user.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #12
You have an Azure subscription named Subscription1 that contains virtual network named VNet1. VNet1 is in a resource group named RG1.A user named User1 has the following roles for Subscription1: ReaderSecurity Admin Security ReaderYou need to ensure that User1 can assign the Reader role for VNet1 to other users. What should you do?
A. Remove User1 from the Security Reader and Reader roles for Subscription1
B. Assign User1 the Contributor role for VNet1
C. Assign User1 the Owner role for VNet1
D. Assign User1 the Network Contributor role for RG1
View answer
Correct Answer: C
Question #13
You have an Azure subscription that contains eight virtual machines and the resources shown in the following table. You need to configure access for VNEI1. The solution must meet the following requirements: * The virtual machines connected to VNET1 must be able to communicate with the virtual machines connected to VNET2 by using the Microsoft backbone. * The virtual machines connected to VNETl must be able to access storage1. Storage2, and Microsoft Entra ID by using the Microsoft backbone. What is the minimum number of service endpoints you should add to VNET1?
A. A1
B. B2
C. C3
D. D5
View answer
Correct Answer: C
Question #14
Your company’s Azure subscription includes Azure virtual machines (VMs) that run Windows Server 2016. One of the VMs is backed up every day using Azure Backup Instant Restore.When the VM becomes infected with data encrypting ransomware, you decide to recover the VM’s files. Which of the following is TRUE in this scenario?
A. You can only recover the files to the infected VM
B. You can recover the files to any VM within the company’s subscription
C. You can only recover the files to a new VM
D. You will not be able to recover the files
View answer
Correct Answer: B
Question #15
You have an Azure subscription named Subscription1 that contains an Azure Log Analytics workspace named Workspace1.You need to view the error events from a table named Event.Which query should you run in Workspace1?
A. select * from Event where EventType == "error"
B. Event | search "error"
C. Event | where EventType is "error"
D. Get-Event Event | where {$_
View answer
Correct Answer: B
Question #16
You have an Azure subscription that contains a user named User1.You need to ensure that User1 can deploy virtual machines and manage virtual networks. The solution must use the principle of least privilege.Which role-based access control (RBAC) role should you assign to User1?
A. Owner
B. Virtual Machine Contributor
C. Contributor
D. Virtual Machine Administrator Login
View answer
Correct Answer: C
Question #17
You have an Azure Subscription that contains the virtual networks Shown in the following table. All the virtual networks are peered. Each virtual network contains nine virtual machines. You need to configure secure RDP corrections to the virtual machines by using Azure Boston. Whit is the minimum number of Bastion nests required? According to theMicrosoft documentation, Azure Bastion is a service that provides more secure and seamless RDP and SSH access to virtual machines without any exposure through public IP addresses. You can provision the service directly in your local or peered virtual network to get support for all the VMs within it. In your scenario, you have three virtual networks that are peered with each other. This means that they can communicate with each other as if they were in the same virtual network. Therefore, you can deploy one Bastion host in any of the virtual networks and use it to connect to all the virtual machines in the peered virtual networks. You don't need to deploy a separate Bastion host for each virtual network or each virtual machine. For more information about how to deploy and use Azure Bastion, seeTutorial: Deploy Bastion using specified settings: Azure portal.
A. 1
B. 3
C. 9
D. 10
View answer
Correct Answer: B
Question #18
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.Your company’s Azure subscription includes two Azure networks named VirtualNetworkA and VirtualNetworkB.VirtualNetworkA includes a VPN gateway that is configured to make use of static routing. Also, a site-to-site VPN connection exists between your company’s on-premises network and VirtualNetworkA.You have configured a point-to-site VPN connection to VirtualNetworkA from a workstation running Windows10. After configuring virtual network peering between VirtualNetworkA and VirtualNetworkB, you confirm that you are able to access VirtualNetworkB from the company’s on-premises network. However, you find that you cannot establish a connection to VirtualNetworkB from the Windows 10 workstation.You have to make sure that a connection to VirtualNetworkB can be established from the Windows 10 workstation.Solution: You download and re-install the VPN client configuration package on the Windows 10 workstation. Does the solution meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #19
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Azure virtual machine named VM1 that runs Windows Server 2016.You need to create an alert in Azure when more than two error events are logged to the System event log on VM1 within an hour.Solution: You create an Azure Log Analytics workspace and configure the data settings. You install the Microsoft Monitoring Agent on VM1. You create an alert in Azure Monitor and specify the Log Analytics workspace as the source.Does this meet the goal?
A. o
B. es
View answer
Correct Answer: B
Question #20
You are the global administrator for an Azure Active Directory (Azure AD) tenant named adatum.com.You need to enable two-step verification for Azure users.What should you do?
A. nable Azure AD Privileged Identity Management
B. nstall and configure Azure AD Connect
C. reate an Azure AD conditional access policy
D. onfigure a playbook in Azure Security Center
View answer
Correct Answer: C
Question #21
You have an Azure subscription that contains an Azure virtual machine named VM1. VM1 runs a financial reporting app named App1 that does not support multiple active instances. At the end of each month, CPU usage for VM1 peaks when App1 runs. You need to create a scheduled runbook to increase the processor performance of VM1 at the end of each month. What task should you include in the runbook? To create a scheduled runbook to increase the processor performance of VM1 at the end of each month, you need to modify the VM size property of VM1. This will allow you to scale up the VM to a larger size that has more CPU cores and memory. You can use Azure Automation to create a PowerShell runbook that changes the VM size using the Set-AzVM cmdlet. You can then schedule the runbook to run at the end of each month using the Azure portal or Azure PowerShell.For more information, seeHow to resize a virtual machine in Azure using Azure Automation1.
A. Add the Azure Performance Diagnostics agent to VM1
B. Modify the VM size property of VM1
C. Add VM1 to a scale set
D. Increase the vCPU quota for the subscription
E. Add a Desired State Configuration (DSC) extension to VM1
View answer
Correct Answer: E
Question #22
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.Your company has a Microsoft SQL Server Always On availability group configured on their Azure virtual machines (VMs).You need to configure an Azure internal load balancer as a listener for the availability group. Solution: You enable Floating IP.Does the solution meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #23
You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. VNet1 is in a resource group named RG1.Subscription1 has a user named User1. User1 has the following roles: ReaderSecurity Admin Security ReaderYou need to ensure that User1 can assign the Reader role for VNet1 to other users. What should you do?
A. Remove User1 from the Security Reader role for Subscription1
B. Assign User1 the User Access Administrator role for VNet1
C. Remove User1 from the Security Reader and Reader roles for Subscription1
D. Assign User1 the Contributor role for VNet1
View answer
Correct Answer: B
Question #24
You have an Azure subscription that contains 10 virtual machines, a key vault named Vault1, and a network security group (NSG) named NSG1. All the resources are deployed to the East US Azure region.The virtual machines are protected by using NSG1. NSG1 is configured to block all outbound traffic to the internet.You need to ensure that the virtual machines can access Vault1. The solution must use the principle of least privilege and minimize administrative effort.What should you configure as the destination of the outbound security rule for NSG1?
A. an application security group
B. a service tag
C. an IP address range
View answer
Correct Answer: B
Question #25
You have the Azure virtual machines shown in the following table.You have a Recovery Services vault that protects VM1 and VM2.You need to protect VM3 and VM4 by using Recovery Services.What should you do first?
A. Create a new Recovery Services vault
B. Configure the extensions for VM3 and VM4
C. Create a storage account
D. Create a new backup policy
View answer
Correct Answer: B
Question #26
Your company has serval departments. Each department has a number of virtual machines (VMs).The company has an Azure subscription that contains a resource group named RG1.All VMs are located in RG1.You want to associate each VM with its respective department.What should you do?
A. reate Azure Management Groups for each department
B. reate a resource group for each department
C. ssign tags to the virtual machines
D. odify the settings of the virtual machines
View answer
Correct Answer: C
Question #27
You have an Azure subscription named Subscription1 that contains virtual network named VNet1. VNet1 is in a resource group named RG1.User named User1 has the following roles for Subscription1: ReaderSecurity Admin Security ReaderYou need to ensure that User1 can assign the Reader role for VNet1 to other users. What should you do?
A. Remove User1 from the Security Reader and Reader roles for Subscription1
B. Remove User1 from the Security Reader role for Subscription1
C. Assign User1 the Network Contributor role for VNet1
D. Assign User1 the User Access Administrator role for VNet1
View answer
Correct Answer: D
Question #28
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish ifthe solution satisfies the requirements.Your company has an Azure Active Directory (Azure AD) subscription.You want to implement an Azure AD conditional access policy.The policy must be configured to require members of the Global Administrators group to use Multi-Factor Authentication and an Azure AD-joined device when theyconnect to Azure AD from untrusted locations.Solution: You access the multi-factor authentication page to alter the user settings.Does the solution meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #29
You have an Azure subscription named Subscription1 that contains virtual network named VNet1. VNet1 is in a resource group named RG1.A user named User1 has the following roles for Subscription1: ReaderSecurity Admin Security ReaderYou need to ensure that User1 can assign the Reader role for VNet1 to other users. What should you do?
A. Remove User1 from the Security Reader and Reader roles for Subscription1
B. Assign User1 the Contributor role for VNet1
C. Assign User1 the Owner role for VNet1
D. Assign User1 the Network Contributor role for RG1
View answer
Correct Answer: C
Question #30
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You need to ensure that a Microsoft Entra user named Admin1 is assigned the required role to enable Traffic Analytics for an Azure subscription.Solution: You assign the Traffic Manager Contributor role at the subscription level to Admin1. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #31
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft Entra tenant named contoso.com.You have a CSV file that contains the names and email addresses of 500 external users. You need to create a guest user account in contoso.com for each of the 500 external users. Solution: You create a PowerShell script that runs the New-MgUser cmdlet for each user.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #32
You have an Azure subscription that contains the resources shown in the following table.You need to assign Workspace1 a role to allow read, write, and delete operations for the data stored in the containers of storage1.Which role should you assign?
A. Storage Account Contributor
B. Contributor
C. Storage Blob Data Contributor
D. Reader and Data Access
View answer
Correct Answer: C
Question #33
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.Your company's Azure solution makes use of Multi-Factor Authentication for when users are not in the office. The Per Authentication option has been configured as the usage model.After the acquisition of a smaller business and the addition of the new staff to Azure Active Directory (Azure AD) obtains a different company and adding the new employees to Azure Active Directory (Azure AD), you are informed that these employees should also make use of Multi-Factor Authentication.To achieve this, the Per Enabled User setting must be set for the usage model.Solution: You reconfigure the existing usage model via the Azure CLI.Does the solution meet the goal?
A. es
B. o
View answer
Correct Answer: B
Question #34
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has adistinctive result. Establish if the solution satisfies the requirements.Your company has an Azure Active Directory (Azure AD) subscription.You want to implement an Azure AD conditional access policy.The policy must be configured to require members of the Global Administrators group to use Multi-Factor Authentication andan Azure AD-joined device when they connect to Azure AD from untrusted locations.Solution: You access the Azure portal to alter the session control of the Azure AD conditional access policy.Does the solution meet the goal?
A. es
B. o
View answer
Correct Answer: B
Question #35
You need to recommend a solution to automate the configuration for the finance department users. The solution must meetthe technical requirements.What should you include in the recommendation?
A. zure AD B2C
B. ynamic groups and conditional access policies
C. zure AD Identity Protection
D. n Azure logic app and the Microsoft Identity Management (MIM) client
View answer
Correct Answer: B
Question #36
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish ifthe solution satisfies the requirements.Your company makes use of Multi-Factor Authentication for when users are not in the office. The Per Authentication option has been configured as the usagemodel.After the acquisition of a smaller business and the addition of the new staff to Azure Active Directory (Azure AD) obtains a different company and adding the newemployees to Azure Active Directory (Azure AD), you are informed that these employees should also make use of Multi-Factor Authentication.To achieve this, the Per Enabled User setting must be set for the usage model.Solution: You reconfigure the existing usage model via the Azure portal.Does the solution meet the goal?
A. Yes
B. No
View answer
Correct Answer: B

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us