AZ-104 Renewal Exam Prep: 200 Practice
Questions with Answers and Rationales
Covering Identity, Compute, Networking,
Storage, Monitoring, and Governance for
Microsoft Azure Administrator Certification
AZ-104 Practice Question Set
Identity and Access Management (Microsoft
Entra ID)
1. Which Azure service provides centralized
identity management for Azure resources?
A. Azure Monitor
B. Microsoft Entra ID (Azure AD)
C. Azure Policy
D. Azure Security Center
☑VERIFIED ANSWER: B
,Rationale: Microsoft Entra ID (formerly Azure
AD) is the identity and access management
service for Azure resources.
2. You need to grant a colleague the ability to
manage virtual machines in a resource group
without giving access to the subscription.
Which role should you assign?
A. Owner
B. Contributor
C. Virtual Machine Contributor
D. Reader
☑VERIFIED ANSWER: C
Rationale: The Virtual Machine Contributor role
allows management of VMs without granting
full subscription access.
3. What is the primary purpose of Azure Role-
Based Access Control (RBAC)?
A. Monitor cost usage
,B. Grant least-privilege access to resources
C. Encrypt data at rest
D. Route network traffic
☑VERIFIED ANSWER: B
Rationale: RBAC assigns roles with specific
permissions to enforce the principle of least
privilege.
4. Which feature of Azure AD allows you to
enforce multi-factor authentication (MFA)?
A. Conditional Access
B. Privileged Identity Management
C. Access Reviews
D. Azure AD Identity Protection
☑VERIFIED ANSWER: A
Rationale: Conditional Access policies enforce
MFA and other access conditions.
5. You need to allow users to log in to Azure
using their on-premises Active Directory
, credentials. Which service should you use?
A. Azure AD Connect
B. Azure AD B2C
C. Azure AD Identity Protection
D. Azure Key Vault
☑VERIFIED ANSWER: A
Rationale: Azure AD Connect synchronizes on-
premises AD with Azure AD.
6. You want to allow an app to read secrets
from Key Vault without using a username or
password. Which method should you use?
A. Managed Identity
B. Service Principal with username/password
C. Shared Access Signature
D. OAuth 1.0
☑VERIFIED ANSWER: A
Rationale: Managed Identity provides secure
Questions with Answers and Rationales
Covering Identity, Compute, Networking,
Storage, Monitoring, and Governance for
Microsoft Azure Administrator Certification
AZ-104 Practice Question Set
Identity and Access Management (Microsoft
Entra ID)
1. Which Azure service provides centralized
identity management for Azure resources?
A. Azure Monitor
B. Microsoft Entra ID (Azure AD)
C. Azure Policy
D. Azure Security Center
☑VERIFIED ANSWER: B
,Rationale: Microsoft Entra ID (formerly Azure
AD) is the identity and access management
service for Azure resources.
2. You need to grant a colleague the ability to
manage virtual machines in a resource group
without giving access to the subscription.
Which role should you assign?
A. Owner
B. Contributor
C. Virtual Machine Contributor
D. Reader
☑VERIFIED ANSWER: C
Rationale: The Virtual Machine Contributor role
allows management of VMs without granting
full subscription access.
3. What is the primary purpose of Azure Role-
Based Access Control (RBAC)?
A. Monitor cost usage
,B. Grant least-privilege access to resources
C. Encrypt data at rest
D. Route network traffic
☑VERIFIED ANSWER: B
Rationale: RBAC assigns roles with specific
permissions to enforce the principle of least
privilege.
4. Which feature of Azure AD allows you to
enforce multi-factor authentication (MFA)?
A. Conditional Access
B. Privileged Identity Management
C. Access Reviews
D. Azure AD Identity Protection
☑VERIFIED ANSWER: A
Rationale: Conditional Access policies enforce
MFA and other access conditions.
5. You need to allow users to log in to Azure
using their on-premises Active Directory
, credentials. Which service should you use?
A. Azure AD Connect
B. Azure AD B2C
C. Azure AD Identity Protection
D. Azure Key Vault
☑VERIFIED ANSWER: A
Rationale: Azure AD Connect synchronizes on-
premises AD with Azure AD.
6. You want to allow an app to read secrets
from Key Vault without using a username or
password. Which method should you use?
A. Managed Identity
B. Service Principal with username/password
C. Shared Access Signature
D. OAuth 1.0
☑VERIFIED ANSWER: A
Rationale: Managed Identity provides secure