LATEST AZURE ADMINISTRATOR (AZ-104)
EXAM BANK | COMPLETE EXAM BANK
WITH CORRECT ANSWERS AND
RATIONALES. A+ GRADED
1. An Azure administrator needs to grant a user
group the ability to create virtual machines but not to
delete or modify networking resources. Which built-in
RBAC role meets this requirement?
A) Contributor
B) Owner
C) Virtual Machine Contributor
D) Network Contributor
Correct answer: C
Rationale: Virtual Machine Contributor allows
creation and management of VMs but does not allow
access to the virtual network or storage account.
2. A company has multiple Azure subscriptions. The
administrator wants to apply a policy that restricts
VM sizes to specific SKUs across all subscriptions.
What is the most efficient way to enforce this?
,A) Assign an Azure Policy to each subscription
individually
B) Create a management group, place all
subscriptions under it, and assign the policy to the
management group
C) Use Azure RBAC with a custom role
D) Use Azure Blueprints for each subscription
Correct answer: B
Rationale: Management groups allow hierarchical
policy inheritance. A single policy assignment at the
management group level applies to all child
subscriptions.
3. An administrator needs to ensure that storage
accounts can only be created in the East US and
West Europe regions. Which Azure service should be
used?
A) Azure RBAC
B) Azure Policy (Allowed locations policy)
C) Azure Blueprints
D) Azure Resource Graph
Correct answer: B
,Rationale: Azure Policy has built-in "Allowed
locations" policy to restrict which regions resources
can be deployed in.
4. A user reports that they cannot start a stopped VM.
The administrator checks and finds the VM is in the
East US region. What could be the issue?
A) The VM has a policy applied that denies start
B) The user does not have the Virtual Machine
Contributor role
C) The Azure subscription is past due
D) The East US region is experiencing an outage
Correct answer: B
Rationale: The most common reason is insufficient
RBAC permissions. The user must have at least
Virtual Machine Contributor or Contributor role to
start a VM.
5. Which Azure AD feature allows users to reset their
own passwords without administrator intervention
(when properly configured)?
A) Azure AD Privileged Identity Management (PIM)
B) Azure AD Identity Protection
C) Azure AD Self-Service Password Reset (SSPR)
, D) Azure AD Conditional Access
Correct answer: C
Rationale: SSPR allows users to reset their
passwords after verifying authentication methods
(phone, email, security questions).
6. An administrator needs to back up an Azure file
share (SMB) to another region for disaster recovery.
Which Azure service should be used?
A) Azure Backup (support for Azure Files)
B) Azure Site Recovery
C) Azure File Sync
D) Storage Account replication (GRS)
Correct answer: A
Rationale: Azure Backup provides backup and
recovery for Azure Files (snapshots and vault
backup). GRS replicates data but does not provide
point-in-time recovery.
7. A company has an Azure Storage account with
hierarchical namespace enabled (ADLS Gen2). Which
access control model can be used at the file and
directory level?
A) RBAC only
EXAM BANK | COMPLETE EXAM BANK
WITH CORRECT ANSWERS AND
RATIONALES. A+ GRADED
1. An Azure administrator needs to grant a user
group the ability to create virtual machines but not to
delete or modify networking resources. Which built-in
RBAC role meets this requirement?
A) Contributor
B) Owner
C) Virtual Machine Contributor
D) Network Contributor
Correct answer: C
Rationale: Virtual Machine Contributor allows
creation and management of VMs but does not allow
access to the virtual network or storage account.
2. A company has multiple Azure subscriptions. The
administrator wants to apply a policy that restricts
VM sizes to specific SKUs across all subscriptions.
What is the most efficient way to enforce this?
,A) Assign an Azure Policy to each subscription
individually
B) Create a management group, place all
subscriptions under it, and assign the policy to the
management group
C) Use Azure RBAC with a custom role
D) Use Azure Blueprints for each subscription
Correct answer: B
Rationale: Management groups allow hierarchical
policy inheritance. A single policy assignment at the
management group level applies to all child
subscriptions.
3. An administrator needs to ensure that storage
accounts can only be created in the East US and
West Europe regions. Which Azure service should be
used?
A) Azure RBAC
B) Azure Policy (Allowed locations policy)
C) Azure Blueprints
D) Azure Resource Graph
Correct answer: B
,Rationale: Azure Policy has built-in "Allowed
locations" policy to restrict which regions resources
can be deployed in.
4. A user reports that they cannot start a stopped VM.
The administrator checks and finds the VM is in the
East US region. What could be the issue?
A) The VM has a policy applied that denies start
B) The user does not have the Virtual Machine
Contributor role
C) The Azure subscription is past due
D) The East US region is experiencing an outage
Correct answer: B
Rationale: The most common reason is insufficient
RBAC permissions. The user must have at least
Virtual Machine Contributor or Contributor role to
start a VM.
5. Which Azure AD feature allows users to reset their
own passwords without administrator intervention
(when properly configured)?
A) Azure AD Privileged Identity Management (PIM)
B) Azure AD Identity Protection
C) Azure AD Self-Service Password Reset (SSPR)
, D) Azure AD Conditional Access
Correct answer: C
Rationale: SSPR allows users to reset their
passwords after verifying authentication methods
(phone, email, security questions).
6. An administrator needs to back up an Azure file
share (SMB) to another region for disaster recovery.
Which Azure service should be used?
A) Azure Backup (support for Azure Files)
B) Azure Site Recovery
C) Azure File Sync
D) Storage Account replication (GRS)
Correct answer: A
Rationale: Azure Backup provides backup and
recovery for Azure Files (snapshots and vault
backup). GRS replicates data but does not provide
point-in-time recovery.
7. A company has an Azure Storage account with
hierarchical namespace enabled (ADLS Gen2). Which
access control model can be used at the file and
directory level?
A) RBAC only