D084 Cloud Platform exam with precise
detailed Solutions
Windows 10 can be added to Azure AD as a device to be managed, enabling BYOD or
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
corporate cloud only deployments with - Correct answer ✔Azure AD Join |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
is a feature of Azure AD which allows administrators to control
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
access to cloud applications through additional checks such as user location, the
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
device the user is accessing the cloud app from, and more. - Correct answer ✔Conditional
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Access
Virtual machine scale sets (VMSS), can scale up to _______________. You need to
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
ensure that you create the VMSS configured for large scale sets if you intend to go
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
above 100 instances. There are several other limits to consider too. Using a
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
custom image, you can only create up to 300 instances. To scale above 100
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
instances, you must use the Standard SKU of the Azure Load Balancer or the Azure
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
App Gateway. - Correct answer ✔1,000 instances
|||||| |||||| |||||| |||||| |||||| ||||||
A company is creating guidelines for dictating which users can access their environment
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
and when. |||||| ||||||
Which role or roles can invite guest users into an Azure AD tenant by default? - Correct answer
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
✔Administrators and users
|||||| |||||| ||||||
Which type of Azure AD object should be used to manage delegation of permissions
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
within an Azure AD administrative unit? - Correct answer ✔A built-in role
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
,A software development company needs to update three Microsoft Azure AD groups to
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
meet new security requirements.
|||||| |||||| ||||||
Which tool can be used to update the groups? - Correct answer ✔Azure CLI
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Three new users need to be invited to a company's Azure AD tenant.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Which piece of information should be specified for each new guest account? - Correct answer
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
✔Email address ||||||
A company identifies a set of Azure security permissions required for a new IT group
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
that manages virtual machines.
|||||| |||||| ||||||
What should be created to apply the security permissions to the group? - Correct answer
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
✔Custom role ||||||
What determines the effective permissions when assigning multiple roles to a user? - Correct
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
answer ✔A more permissive role at a resource-level scope grants the user additional
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
permissions.
An administrator is assigning an Azure role to an Azure user and receives the following
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
error: "No more role assignments can be created."
|||||| |||||| |||||| |||||| |||||| |||||| ||||||
What should be configured to resolve the issue? - Correct answer ✔Add users to groups and
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
assign roles to the groups. There is a limit of 2,000 role assignments per subscription.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Changing the approach |||||| ||||||
addresses the issue |||||| ||||||
Azure AD users manage Azure resources based on a built-in role assignment. Their
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
privileges need to be adjusted by removing a subset of permissions.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
, How should the new security permissions be created with the least amount of work? - Correct
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
answer ✔Clone an existing role and modify it |||||| |||||| |||||| |||||| |||||| |||||| ||||||
What should be used to enforce standardized tagging rules to Azure resources? - Correct
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
answer ✔Azure Policy |||||| ||||||
A company has three virtual machines that are categorized by environment purpose,
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
such as development, test, or production. The virtual machines are grouped by different
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
business areas in the management group hierarchy, not by environment purpose.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
What can be implemented to identify the environment purpose for the virtual machines? -
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Correct answer ✔Tags |||||| ||||||
28
A company has three business areas that are consuming Azure resources. The
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
business areas are using several Enterprise Agreement (EA) subscriptions.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
What should be used to grant a user access to the EA subscriptions through a single
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
role assignment? - Correct answer ✔Management groups
|||||| |||||| |||||| |||||| |||||| ||||||
A company has a single subscription for Azure resources shared between different
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
business units. The company intends to assign tags to identify the Azure-related costs
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
that should be charged back to each business unit.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Which level should be used to assign the tags? - Correct answer ✔Resource
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
A virtual machine hosted in Azure is backed up by using Azure Backup.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Where are the backup policies associated with the virtual machine stored? - Correct answer
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
✔Recovery Services Vault |||||| ||||||
detailed Solutions
Windows 10 can be added to Azure AD as a device to be managed, enabling BYOD or
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
corporate cloud only deployments with - Correct answer ✔Azure AD Join |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
is a feature of Azure AD which allows administrators to control
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
access to cloud applications through additional checks such as user location, the
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
device the user is accessing the cloud app from, and more. - Correct answer ✔Conditional
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Access
Virtual machine scale sets (VMSS), can scale up to _______________. You need to
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
ensure that you create the VMSS configured for large scale sets if you intend to go
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
above 100 instances. There are several other limits to consider too. Using a
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
custom image, you can only create up to 300 instances. To scale above 100
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
instances, you must use the Standard SKU of the Azure Load Balancer or the Azure
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
App Gateway. - Correct answer ✔1,000 instances
|||||| |||||| |||||| |||||| |||||| ||||||
A company is creating guidelines for dictating which users can access their environment
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
and when. |||||| ||||||
Which role or roles can invite guest users into an Azure AD tenant by default? - Correct answer
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
✔Administrators and users
|||||| |||||| ||||||
Which type of Azure AD object should be used to manage delegation of permissions
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
within an Azure AD administrative unit? - Correct answer ✔A built-in role
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
,A software development company needs to update three Microsoft Azure AD groups to
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
meet new security requirements.
|||||| |||||| ||||||
Which tool can be used to update the groups? - Correct answer ✔Azure CLI
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Three new users need to be invited to a company's Azure AD tenant.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Which piece of information should be specified for each new guest account? - Correct answer
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
✔Email address ||||||
A company identifies a set of Azure security permissions required for a new IT group
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
that manages virtual machines.
|||||| |||||| ||||||
What should be created to apply the security permissions to the group? - Correct answer
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
✔Custom role ||||||
What determines the effective permissions when assigning multiple roles to a user? - Correct
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
answer ✔A more permissive role at a resource-level scope grants the user additional
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
permissions.
An administrator is assigning an Azure role to an Azure user and receives the following
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
error: "No more role assignments can be created."
|||||| |||||| |||||| |||||| |||||| |||||| ||||||
What should be configured to resolve the issue? - Correct answer ✔Add users to groups and
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
assign roles to the groups. There is a limit of 2,000 role assignments per subscription.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Changing the approach |||||| ||||||
addresses the issue |||||| ||||||
Azure AD users manage Azure resources based on a built-in role assignment. Their
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
privileges need to be adjusted by removing a subset of permissions.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
, How should the new security permissions be created with the least amount of work? - Correct
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
answer ✔Clone an existing role and modify it |||||| |||||| |||||| |||||| |||||| |||||| ||||||
What should be used to enforce standardized tagging rules to Azure resources? - Correct
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
answer ✔Azure Policy |||||| ||||||
A company has three virtual machines that are categorized by environment purpose,
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
such as development, test, or production. The virtual machines are grouped by different
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
business areas in the management group hierarchy, not by environment purpose.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
What can be implemented to identify the environment purpose for the virtual machines? -
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Correct answer ✔Tags |||||| ||||||
28
A company has three business areas that are consuming Azure resources. The
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
business areas are using several Enterprise Agreement (EA) subscriptions.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
What should be used to grant a user access to the EA subscriptions through a single
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
role assignment? - Correct answer ✔Management groups
|||||| |||||| |||||| |||||| |||||| ||||||
A company has a single subscription for Azure resources shared between different
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
business units. The company intends to assign tags to identify the Azure-related costs
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
that should be charged back to each business unit.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Which level should be used to assign the tags? - Correct answer ✔Resource
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
A virtual machine hosted in Azure is backed up by using Azure Backup.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Where are the backup policies associated with the virtual machine stored? - Correct answer
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
✔Recovery Services Vault |||||| ||||||