AZ 104 Study Set 1 Exam Questions with
complete answers 2023/2024
You can download published audit reports and other compliance-related information
related to Microsoft's cloud service from here - Answer-Service Trust Portal
Which Azure service allows you to configure fine-grained access management for Azure
resources, enabling you to grant users only the rights they need to perform their jobs? -
Answer-RBAC
Which Azure service allows you to create, assign, and, manage policies to enforce
different rules and effects over your resources and stay compliant with your corporate
standards and service-level agreements (SLAs)? - Answer-Azure Policy
Which of the following services provides up-to-date status information about the health
of Azure services? - Answer-Azure Service Health
It organizes resources into named resource groups that let you deploy, update, or
delete all of the resources together. - Answer-Azure Resource Manager
These are small applications that allow you to configure and automate tasks on Azure
VMs after initial deployment. They can be run with the Azure CLI, PowerShell, Azure
Resource Manager templates, and the Azure portal. - Answer-Azure VM Extensions
These are a logical feature used to ensure that a group of related VMs are deployed so
that they aren't all subject to a single point of failure and not all upgraded at the same
time during a host operating system upgrade in the datacenter. VMs should perform an
identical set of functionalities and have the same software installed. - Answer-
Availability Set
Microsoft offers a -------- external connectivity service level agreement (SLA) for
multiple-instance VMs deployed in an availability set. That means that for the SLA to
apply, there must be at least two instances of the VM deployed within an availability set.
- Answer-99.95%
is a logical group of hardware in Azure that shares a common power source and
network switch. You can think of it as a rack within an on-premises datacenter. ****are
also defined for managed disks attached to VMs. - Answer-Fault Domain
is a logical group of hardware that can undergo maintenance or be rebooted at the
same time. Azure will automatically place availability sets into THESE to minimize the
impact when the Azure platform introduces host operating system change - Answer-
update domains
, replicates workloads from a primary site to a secondary location. If an outage happens
at your primary site, you can fail over to a secondary location. This failover allows users
to continue to access your applications without interruption. You can then fail back to
the primary location once it's up and running again - Answer-Azure Site Recovery
Suppose you want to run a network appliance on a virtual machine. Which workload
option should you choose. These are designed to have a high CPU-to-memory ratio.
Suitable for medium traffic web servers, network appliances, batch processes, and
application servers. - Answer-Compute Optimizes
Here, an agent is installed on on-premises servers that authenticate against the on-
premises Active Directory. When an Azure AD user account tries to authenticate,
password authentication is handled on-premises through these servers and Active
Directory - Answer-Azure AD pass-through authentication
Here, the authentication process is performed by an on-premises Active Directory
Federation Services (AD FS) server that validates users' passwords. Use this
authentication method if you want advanced measures like smart card-based
authentication for users. - Answer-Federated authentication
Here, the user's password is hashed twice and synchronized between the on-premises
Active Directory and Azure AD. Users have the same credentials to access resources
and applications both on-premises and in the cloud. - Answer-Azure AD password hash
synchronization
This feature helps you configure risk-based conditional access to protect applications
from identity risks. You can also use privileged identity management, which lets you
monitor and put detailed restrictions on administrators. - Answer-Azure Active Directory
Premium P2
lets you add virtual machines to a domain without needing domain controllers. Your
internal staff users can access virtual machines by using their company Azure AD
credentials. ****Use this service to reduce the complexity of migrating on-premises
applications to Azure. - Answer-Azure AD DS
This allows you to invite external users to your tenant so that your staff can collaborate
with them. - Answer-AD B2B
You use it to add on-premises applications to your instance of Azure AD. you create
secure remote access for your on-premises applications. - Answer-AD Application
Proxy
The scratch image is an empty container image that doesn't create a filesystem layer.
This image assumes that the application you're going to run can directly use the host
OS kernel. - Answer-base image
complete answers 2023/2024
You can download published audit reports and other compliance-related information
related to Microsoft's cloud service from here - Answer-Service Trust Portal
Which Azure service allows you to configure fine-grained access management for Azure
resources, enabling you to grant users only the rights they need to perform their jobs? -
Answer-RBAC
Which Azure service allows you to create, assign, and, manage policies to enforce
different rules and effects over your resources and stay compliant with your corporate
standards and service-level agreements (SLAs)? - Answer-Azure Policy
Which of the following services provides up-to-date status information about the health
of Azure services? - Answer-Azure Service Health
It organizes resources into named resource groups that let you deploy, update, or
delete all of the resources together. - Answer-Azure Resource Manager
These are small applications that allow you to configure and automate tasks on Azure
VMs after initial deployment. They can be run with the Azure CLI, PowerShell, Azure
Resource Manager templates, and the Azure portal. - Answer-Azure VM Extensions
These are a logical feature used to ensure that a group of related VMs are deployed so
that they aren't all subject to a single point of failure and not all upgraded at the same
time during a host operating system upgrade in the datacenter. VMs should perform an
identical set of functionalities and have the same software installed. - Answer-
Availability Set
Microsoft offers a -------- external connectivity service level agreement (SLA) for
multiple-instance VMs deployed in an availability set. That means that for the SLA to
apply, there must be at least two instances of the VM deployed within an availability set.
- Answer-99.95%
is a logical group of hardware in Azure that shares a common power source and
network switch. You can think of it as a rack within an on-premises datacenter. ****are
also defined for managed disks attached to VMs. - Answer-Fault Domain
is a logical group of hardware that can undergo maintenance or be rebooted at the
same time. Azure will automatically place availability sets into THESE to minimize the
impact when the Azure platform introduces host operating system change - Answer-
update domains
, replicates workloads from a primary site to a secondary location. If an outage happens
at your primary site, you can fail over to a secondary location. This failover allows users
to continue to access your applications without interruption. You can then fail back to
the primary location once it's up and running again - Answer-Azure Site Recovery
Suppose you want to run a network appliance on a virtual machine. Which workload
option should you choose. These are designed to have a high CPU-to-memory ratio.
Suitable for medium traffic web servers, network appliances, batch processes, and
application servers. - Answer-Compute Optimizes
Here, an agent is installed on on-premises servers that authenticate against the on-
premises Active Directory. When an Azure AD user account tries to authenticate,
password authentication is handled on-premises through these servers and Active
Directory - Answer-Azure AD pass-through authentication
Here, the authentication process is performed by an on-premises Active Directory
Federation Services (AD FS) server that validates users' passwords. Use this
authentication method if you want advanced measures like smart card-based
authentication for users. - Answer-Federated authentication
Here, the user's password is hashed twice and synchronized between the on-premises
Active Directory and Azure AD. Users have the same credentials to access resources
and applications both on-premises and in the cloud. - Answer-Azure AD password hash
synchronization
This feature helps you configure risk-based conditional access to protect applications
from identity risks. You can also use privileged identity management, which lets you
monitor and put detailed restrictions on administrators. - Answer-Azure Active Directory
Premium P2
lets you add virtual machines to a domain without needing domain controllers. Your
internal staff users can access virtual machines by using their company Azure AD
credentials. ****Use this service to reduce the complexity of migrating on-premises
applications to Azure. - Answer-Azure AD DS
This allows you to invite external users to your tenant so that your staff can collaborate
with them. - Answer-AD B2B
You use it to add on-premises applications to your instance of Azure AD. you create
secure remote access for your on-premises applications. - Answer-AD Application
Proxy
The scratch image is an empty container image that doesn't create a filesystem layer.
This image assumes that the application you're going to run can directly use the host
OS kernel. - Answer-base image