AZ 104 Renewal Exam
Questions and Ansẉers with
rationales 2026\2027 update
This Exam contains:
Guarantee passing score
Questions and Ansẉers
format set of multiple-choice
Expert-Verified rationales
Verified ẉith trusted textbooks
,───────────────────────────────────────────────────────
─
You need to grant a user temporary access to perform virtual
machine restarts for 8 hours. Which feature should you use?
A) Azure Policy
B) Azure Role-Based Access Control (RBAC)
C) Microsoft Entra Privileged Identity Management (PIM)
D) Azure Blueprints
Answer: C
Rationale: Privileged Identity Management (PIM) provides time-based
and approval-based role activation for Microsoft Entra ID and Azure
resources, perfect for granting temporary access.
You have an Azure subscription that contains a storage account.
You need to ensure that data in the storage account is retained for 7
years. What should you configure?
A) Azure Storage Object Replication
B) Azure Blob Storage Lifecycle Management
C) Azure Resource Manager Locks
D) Azure Storage Immutable Blobs with a Time-Based Retention
Policy
Answer: D
Rationale: Immutable blobs with a time-based retention policy
(WORM - Write Once, Read Many) ensure that data cannot be
modified or deleted for a specified duration, fulfilling compliance
requirements.
You need to deploy a virtual machine scale set that automatically
adjusts the number of VM instances based on CPU utilization. Which
feature should you configure?
A) Azure Load Balancer rules
B) Azure Virtual Machine Scale Set Autoscale rules
C) Azure Application Gateway autoscaling
D) Azure Monitor Log Analytics alerts
Answer: B
, Rationale: Virtual Machine Scale Sets (VMSS) have built-in
autoscaling capabilities that can be configured with rules based on
metrics like CPU percentage to dynamically scale in or out.
You need to assign a user the ability to manage virtual machines in
a resource group, but prevent them from managing the resource
group itself. Which RBAC role should you assign?
A) Owner
B) Contributor
C) Virtual Machine Contributor
D) User Access Administrator
Answer: C
Rationale: The "Virtual Machine Contributor" role allows users to
manage virtual machines, but does not grant access to the virtual
network or storage account they are connected to, nor does it allow
managing the resource group itself.
You create a new Azure virtual machine named VM1. You need to
ensure that you can connect to VM1 using RDP from your on-
premises network. What should you create?
A) A Network Security Group (NSG) inbound security rule that allows
port 3389
B) An Azure Load Balancer NAT rule
C) A Virtual Network Gateway
D) An Application Gateway
Answer: A
Rationale: RDP uses port 3389. To allow inbound RDP traffic to a
VM, you must configure a Network Security Group (NSG) inbound
security rule to permit traffic on port 3389.
You have an Azure subscription named Subscription1. You need to
ensure that all resources deployed to Subscription1 are deployed to
the West US region. What should you use?
A) Azure Resource Manager templates
B) Azure Policy
C) Azure Management Groups
D) Azure Active Directory
Questions and Ansẉers with
rationales 2026\2027 update
This Exam contains:
Guarantee passing score
Questions and Ansẉers
format set of multiple-choice
Expert-Verified rationales
Verified ẉith trusted textbooks
,───────────────────────────────────────────────────────
─
You need to grant a user temporary access to perform virtual
machine restarts for 8 hours. Which feature should you use?
A) Azure Policy
B) Azure Role-Based Access Control (RBAC)
C) Microsoft Entra Privileged Identity Management (PIM)
D) Azure Blueprints
Answer: C
Rationale: Privileged Identity Management (PIM) provides time-based
and approval-based role activation for Microsoft Entra ID and Azure
resources, perfect for granting temporary access.
You have an Azure subscription that contains a storage account.
You need to ensure that data in the storage account is retained for 7
years. What should you configure?
A) Azure Storage Object Replication
B) Azure Blob Storage Lifecycle Management
C) Azure Resource Manager Locks
D) Azure Storage Immutable Blobs with a Time-Based Retention
Policy
Answer: D
Rationale: Immutable blobs with a time-based retention policy
(WORM - Write Once, Read Many) ensure that data cannot be
modified or deleted for a specified duration, fulfilling compliance
requirements.
You need to deploy a virtual machine scale set that automatically
adjusts the number of VM instances based on CPU utilization. Which
feature should you configure?
A) Azure Load Balancer rules
B) Azure Virtual Machine Scale Set Autoscale rules
C) Azure Application Gateway autoscaling
D) Azure Monitor Log Analytics alerts
Answer: B
, Rationale: Virtual Machine Scale Sets (VMSS) have built-in
autoscaling capabilities that can be configured with rules based on
metrics like CPU percentage to dynamically scale in or out.
You need to assign a user the ability to manage virtual machines in
a resource group, but prevent them from managing the resource
group itself. Which RBAC role should you assign?
A) Owner
B) Contributor
C) Virtual Machine Contributor
D) User Access Administrator
Answer: C
Rationale: The "Virtual Machine Contributor" role allows users to
manage virtual machines, but does not grant access to the virtual
network or storage account they are connected to, nor does it allow
managing the resource group itself.
You create a new Azure virtual machine named VM1. You need to
ensure that you can connect to VM1 using RDP from your on-
premises network. What should you create?
A) A Network Security Group (NSG) inbound security rule that allows
port 3389
B) An Azure Load Balancer NAT rule
C) A Virtual Network Gateway
D) An Application Gateway
Answer: A
Rationale: RDP uses port 3389. To allow inbound RDP traffic to a
VM, you must configure a Network Security Group (NSG) inbound
security rule to permit traffic on port 3389.
You have an Azure subscription named Subscription1. You need to
ensure that all resources deployed to Subscription1 are deployed to
the West US region. What should you use?
A) Azure Resource Manager templates
B) Azure Policy
C) Azure Management Groups
D) Azure Active Directory