AZ-104 Renewal Exam Questions and Answers
2022 All Answers Available
1. You have an Azure subscription. You need to ensure that when an administrator attempts
to delete any resource in resource group RG1, the operation is blocked. What should you
configure?
A. An Azure Policy assignment that denies delete operations
B. A CanNotDelete resource lock on RG1
C. A ReadOnly resource lock on RG1
D. An RBAC role assignment that denies delete permissions
Correct Answer: B
Rationale: A CanNotDelete resource lock allows read and modify operations but blocks
deletion. ReadOnly locks block both modification and deletion. Resource locks are governance
mechanisms that operate directly at the resource or resource group level, independent of policy
evaluation.
2. You need to create an Azure Policy that ensures all newly created storage accounts use
Standard_LRS redundancy. What type of policy definition should you use?
A. An Audit effect built-in policy
B. A Deny effect custom policy using a not condition
C. An Append effect custom policy
D. A DeployIfNotExists effect custom policy
Correct Answer: B
Rationale: To block non-compliant resource configurations, you need a Deny effect. Policy
definitions can use not to invert logic, such as "if not Standard_LRS, then deny." Audit only
records violations, Append only adds properties, and DeployIfNotExists is used to automatically
deploy related resources.
3. You need to move an Azure subscription from its current management group to another
management group. Which of the following is correct?
A. You can move the subscription, and inherited policies are immediately updated
B. You cannot move a subscription to a different management group
,C. You must delete all resource locks on the subscription before moving
D. After moving, RBAC role assignments are reset
Correct Answer: A
Rationale: Subscriptions can be moved between management groups. After the move, the
subscription inherits policies and RBAC assignments from the new management group while
losing inheritance from the old one. RBAC role assignments are not reset, though effective
permissions may change due to inheritance.
4. You have a Microsoft Entra ID tenant. You need to invite an external partner user so they
can access specific resources in the Azure portal. What user type should this user have?
A. Member
B. Guest
C. External Member
D. Service Principal
Correct Answer: B
Rationale: External collaboration users are created through B2B invitations and appear as
user type "Guest" in Microsoft Entra ID. Guest users can be granted access to Azure resources
through RBAC.
5. You need to configure self-service password reset (SSPR) for Azure administrators. Which of
the following is a requirement for SSPR?
A. Users must have a Microsoft 365 license
B. Users must register at least one authentication method
C. Users must have multi-factor authentication (MFA) enabled
D. Users must be global administrators
Correct Answer: B
Rationale: The prerequisite for using SSPR is that users have registered at least one available
authentication method (such as Authenticator app, SMS, email, or security questions). MFA is
not a hard prerequisite for SSPR, though the two are often used together.
6. You need to assign a built-in RBAC role that allows a user to manage virtual machines but
prohibits assigning roles. Which role should you use?
,A. Owner
B. Contributor
C. Virtual Machine Contributor
D. User Access Administrator
Correct Answer: C
Rationale: The Virtual Machine Contributor role allows managing virtual machines but
cannot manage RBAC role assignments. Contributor can manage all resources but not access
permissions; Owner can manage access permissions; User Access Administrator specifically
manages access permissions.
7. You assigned a policy at the subscription level. The policy's effect is "Deny." You create a
resource in resource group RG1, and that resource type is blocked by the policy. What
happens?
A. Resource creation is denied
B. Resource creation succeeds but is marked as non-compliant
C. Resource creation succeeds but is automatically deleted
D. Resource creation is denied and requires administrator approval
Correct Answer: A
Rationale: The Deny effect is evaluated at resource deployment time. If the resource does
not meet the policy conditions, the deployment request fails directly. Subscription-level policies
are inherited by all resource groups and resources.
8. You need to view a specific user's effective permissions on a particular resource group.
What should you use?
A. Azure Policy compliance report
B. The "Check access" feature in the resource group's Access control (IAM) blade
C. Microsoft Entra ID audit logs
D. Azure Advisor recommendations
Correct Answer: B
Rationale: The "Check access" feature displays the effective RBAC permissions for a user or
principal at a specific scope (subscription, resource group, or resource), including directly
assigned and inherited permissions.
, 9. You need to ensure that when a new virtual network is created, a "CostCenter" tag is
automatically added. What should you use?
A. A Deny policy
B. An Append policy
C. A Modify policy
D. An Audit policy
Correct Answer: C
Rationale: The Modify effect allows adding, updating, or removing tags when a resource is
created or updated. Append can only add values and cannot modify or remove. Modify policies
typically require a managed identity to perform remediation tasks.
10. You have a Microsoft Entra ID tenant containing 100 users. You need to create a dynamic
group containing all users whose department is "IT." What membership type should you use?
A. Assigned
B. Dynamic User
C. Dynamic Device
D. Microsoft 365
Correct Answer: B
Rationale: Dynamic User membership automatically adds or removes members based on
user attributes such as department. Assigned requires manual member management. Dynamic
Device is based on device attributes.
11. You need to grant an application that needs to run automation scripts access to Azure
resources. Which of the following is the most secure approach?
A. Create a user account and assign a password
B. Use a service principal and assign an RBAC role
C. Use a managed identity
D. Store administrator credentials in Key Vault
Correct Answer: C
Rationale: Managed identities are automatically managed identities for Azure resources
2022 All Answers Available
1. You have an Azure subscription. You need to ensure that when an administrator attempts
to delete any resource in resource group RG1, the operation is blocked. What should you
configure?
A. An Azure Policy assignment that denies delete operations
B. A CanNotDelete resource lock on RG1
C. A ReadOnly resource lock on RG1
D. An RBAC role assignment that denies delete permissions
Correct Answer: B
Rationale: A CanNotDelete resource lock allows read and modify operations but blocks
deletion. ReadOnly locks block both modification and deletion. Resource locks are governance
mechanisms that operate directly at the resource or resource group level, independent of policy
evaluation.
2. You need to create an Azure Policy that ensures all newly created storage accounts use
Standard_LRS redundancy. What type of policy definition should you use?
A. An Audit effect built-in policy
B. A Deny effect custom policy using a not condition
C. An Append effect custom policy
D. A DeployIfNotExists effect custom policy
Correct Answer: B
Rationale: To block non-compliant resource configurations, you need a Deny effect. Policy
definitions can use not to invert logic, such as "if not Standard_LRS, then deny." Audit only
records violations, Append only adds properties, and DeployIfNotExists is used to automatically
deploy related resources.
3. You need to move an Azure subscription from its current management group to another
management group. Which of the following is correct?
A. You can move the subscription, and inherited policies are immediately updated
B. You cannot move a subscription to a different management group
,C. You must delete all resource locks on the subscription before moving
D. After moving, RBAC role assignments are reset
Correct Answer: A
Rationale: Subscriptions can be moved between management groups. After the move, the
subscription inherits policies and RBAC assignments from the new management group while
losing inheritance from the old one. RBAC role assignments are not reset, though effective
permissions may change due to inheritance.
4. You have a Microsoft Entra ID tenant. You need to invite an external partner user so they
can access specific resources in the Azure portal. What user type should this user have?
A. Member
B. Guest
C. External Member
D. Service Principal
Correct Answer: B
Rationale: External collaboration users are created through B2B invitations and appear as
user type "Guest" in Microsoft Entra ID. Guest users can be granted access to Azure resources
through RBAC.
5. You need to configure self-service password reset (SSPR) for Azure administrators. Which of
the following is a requirement for SSPR?
A. Users must have a Microsoft 365 license
B. Users must register at least one authentication method
C. Users must have multi-factor authentication (MFA) enabled
D. Users must be global administrators
Correct Answer: B
Rationale: The prerequisite for using SSPR is that users have registered at least one available
authentication method (such as Authenticator app, SMS, email, or security questions). MFA is
not a hard prerequisite for SSPR, though the two are often used together.
6. You need to assign a built-in RBAC role that allows a user to manage virtual machines but
prohibits assigning roles. Which role should you use?
,A. Owner
B. Contributor
C. Virtual Machine Contributor
D. User Access Administrator
Correct Answer: C
Rationale: The Virtual Machine Contributor role allows managing virtual machines but
cannot manage RBAC role assignments. Contributor can manage all resources but not access
permissions; Owner can manage access permissions; User Access Administrator specifically
manages access permissions.
7. You assigned a policy at the subscription level. The policy's effect is "Deny." You create a
resource in resource group RG1, and that resource type is blocked by the policy. What
happens?
A. Resource creation is denied
B. Resource creation succeeds but is marked as non-compliant
C. Resource creation succeeds but is automatically deleted
D. Resource creation is denied and requires administrator approval
Correct Answer: A
Rationale: The Deny effect is evaluated at resource deployment time. If the resource does
not meet the policy conditions, the deployment request fails directly. Subscription-level policies
are inherited by all resource groups and resources.
8. You need to view a specific user's effective permissions on a particular resource group.
What should you use?
A. Azure Policy compliance report
B. The "Check access" feature in the resource group's Access control (IAM) blade
C. Microsoft Entra ID audit logs
D. Azure Advisor recommendations
Correct Answer: B
Rationale: The "Check access" feature displays the effective RBAC permissions for a user or
principal at a specific scope (subscription, resource group, or resource), including directly
assigned and inherited permissions.
, 9. You need to ensure that when a new virtual network is created, a "CostCenter" tag is
automatically added. What should you use?
A. A Deny policy
B. An Append policy
C. A Modify policy
D. An Audit policy
Correct Answer: C
Rationale: The Modify effect allows adding, updating, or removing tags when a resource is
created or updated. Append can only add values and cannot modify or remove. Modify policies
typically require a managed identity to perform remediation tasks.
10. You have a Microsoft Entra ID tenant containing 100 users. You need to create a dynamic
group containing all users whose department is "IT." What membership type should you use?
A. Assigned
B. Dynamic User
C. Dynamic Device
D. Microsoft 365
Correct Answer: B
Rationale: Dynamic User membership automatically adds or removes members based on
user attributes such as department. Assigned requires manual member management. Dynamic
Device is based on device attributes.
11. You need to grant an application that needs to run automation scripts access to Azure
resources. Which of the following is the most secure approach?
A. Create a user account and assign a password
B. Use a service principal and assign an RBAC role
C. Use a managed identity
D. Store administrator credentials in Key Vault
Correct Answer: C
Rationale: Managed identities are automatically managed identities for Azure resources