QUESTIONS AND CORRECT
ANSWERS /LATEST 2023/2024 NEW
UPDATE AZ-104 RENEWAL EXAM
QUESTIONS AND CORRECT
ANSWERS GRADED A+
1. You have an Azure subscription that contains the following users in an Azure AD
tenant named contoso.onmicrosoft.com:
Name Role_ Scope
User1.............Global admin........Azure Active Directory
User2............Global admin.........Azure Active Directory
User3..............User admin..............Azure Subscription
User4..................Owner...................Azure Subscription
2. User1 creates a new Azure AD tenant named external.contoso.onmicrosoft.com. You need
to create new user accounts in external.contoso.onmicrosoft.com.
Solution: You instruct User2 to create the user
accounts. Does that meet the goal?
A. Yes
B. No
No
Explanation:
, 3. User1 created the new tenant, so User1 is the Global Administrator of the new
Tenant and only the Global Administrator can add users to a Tenant. User2 is a
Global Administrator of contoso.onmicrosoft.com but not
external.contoso.onmicrosoft.com.
(Slide) You have an Azure subscription that contains the following users in an Azure AD tenant
named contoso.onmicrosoft.com:
Name Role_ Scope
User1.............Global admin........Azure Active Directory
User2............Global admin.........Azure Active Directory
User3..............User admin..............Azure Subscription
User4..................Owner...................Azure Subscription
4. User1 creates a new Azure AD tenant named external.contoso.onmicrosoft.com. You need
to create new user accounts in external.contoso.onmicrosoft.com.
Solution: You instruct User3 to create the user
accounts. Does that meet the goal?
No
Explanation:
Only user administrator or global admin of external.contoso.onmicrosoft.com can
add users
You have an Azure subscription that contains the following users in an Azure AD tenant named
contoso.onmicrosoft.com:
Name Role_ Scope
User1.............Global admin........Azure Active Directory
User2............Global admin.........Azure Active Directory
User3..............User admin..............Azure Subscription
User4..................Owner...................Azure Subscription
User1 creates a new Azure AD tenant named external.contoso.onmicrosoft.com. You need to
create new user accounts in external.contoso.onmicrosoft.com.
,Solution: You instruct User3 to create the user
accounts. Does that meet the goal?
A. Yes
B. No
No
Explanation:
User 3 is a User Administrator in contoso.micorosft.com not in
external.contoso.onmicrosoft.com.
(Slide) HOTSPOT
You have an Azure subscription named Subscription1 that contains a resource group named
RG1. In RG1, you create an internal load balancer named LB1 and a public load balancer named
LB2. You need to ensure that an administrator named Admin1 can manage LB1 and LB2. The
solution must follow the principle of least privilege. Which role should you assign to Admin1 for
each task?
To add backend pool to LB1:
A. Contributor on LB1
B. Network Contributor on LB1
C. Network Contributor on RG1
D. Owner on LB1
To add a health probe to LB2:
A. Contributor on LB2
B. Network Contributor on LB2
C. Network Contributor on RG1
D. Owner on LB2
, C. Network contributor on RG1
Explanation:
*A load balancer (LB) is a Layer-4 (TCP, UDP) load balancer that provides high availability
by distributing incoming traffic among healthy VMs
(Slide) You have an Azure subscription that contains an Azure Active Directory tenant named
contoso.com and an Azure Kubernetes Service (AKS) cluster named AKS1. An administrator
reports that she is unable to grant access to AKS1 to the users in contoso.com. You need to
ensure that access to AKS1 can be granted to the contoso.com users.
What should you do first?
A. From contoso.com, modify the Organization relationships settings.
B. From contoso.com, create an OAuth 2.0 authorization endpoint.
C. Recreate AKS1.
D. From AKS1, create a namespace.
B. From contoso.com, create an OAuth 2.0 authorization endpoint.
(Slide) You have a Microsoft 365 tenant and an Azure Active Directory (Azure AD) tenant
named contoso.com. You plan to grant three users named User1, User2, and User3 access to a
temporary Microsoft SharePoint document library named Library1. You need to create groups
for the users. The solution must ensure that the groups are deleted automatically after 180
days. Which TWO groups should you create?
A. a Microsoft 365 group that uses the Assigned membership type
B. a Security group that uses the Assigned membership type
C. a Microsoft 365 group that uses the Dynamic User membership type