You have an Azure subscription that contains a user named User1. You need to ensure
that User1 can deploy virtual machines and manage virtual networks. The solution
must use the principle of least privilege. Which role-based access control (RBAC) role
should you assign to User1?
A. Owner
B. Virtual Machine Contributor
C. Contributor
D. Virtual Machine Administrator Login
Give this one a try later!
C. Contributor
You create an Azure Storage account named contosostorage. You plan to create a
file share named data. Users need to map a drive to the data file share from home
computers that run Windows 10. Which outbound port should you open between the
home computers and the data file share?
,A. 80
B. 443
C. 445
D. 3389
Give this one a try later!
C. 445
You create an Azure Storage account. You plan to add 10 blob containers to the
storage account. For one of the containers, you need to use a different key to encrypt
data at rest. What should you do before you create the container?
A. Generate a shared access signature (SAS).
B. Modify the minimum TLS version.
C. Rotate the access keys.
D. Create an encryption scope.
Give this one a try later!
D. Create an encryption scope.
You have 15 Azure subscriptions. You have an Azure Active Directory (Azure AD)
tenant that contains a security group named Group1. You plan to purchase additional
Azure subscription. You need to ensure that Group1 can manage role assignments for
the existing subscriptions and the planned subscriptions. The solution must meet the
following requirements: ✑ Use the principle of least privilege. ✑ Minimize
administrative effort. What should you do?
A. Assign Group1 the Owner role for the root management group.
B. Assign Group1 the User Access Administrator role for the root management group.
C. Create a new management group and assign Group1 the User Access Administrator
role for the group.
D. Create a new management group and assign Group1 the Owner role for the group.
,Give this one a try later!
B. Assign Group1 the User Access Administrator role for the root
management group.
You have three offices and an Azure subscription that contains an Azure Active
Directory (Azure AD) tenant. You need to grant user management permissions to a
local administrator in each office. What should you use?
A. Azure AD roles
B. administrative units
C. access packages in Azure AD entitlement management
D. Azure roles
Give this one a try later!
B. administrative units
You are configuring Azure Active Directory (Azure AD) authentication for an Azure
Storage account named storage1. You need to ensure that the members of a group
named Group1 can upload files by using the Azure portal. The solution must use the
principle of least privilege. Which two roles should you configure for storage1? Each
correct answer presents part of the solution. NOTE: Each correct selection is worth
one point.
A. Storage Account Contributor
B. Storage Blob Data Contributor
C. Reader
D. Contributor
E. Storage Blob Data Reader
Give this one a try later!
, B. Storage Blob Data Contributor
C. Reader
You have an Azure App Services web app named App1. You plan to deploy App1 by
using Web Deploy. You need to ensure that the developers of App1 can use their
Azure AD credentials to deploy content to App1. The solution must use the principle
of least privilege. What should you do?
A. Assign the Owner role to the developers
B. Configure app-level credentials for FTPS
C. Assign the Website Contributor role to the developers
D. Configure user-level credentials for FTPS
Give this one a try later!
B. Configure app-level credentials for FTPS
You have an on-premises server that contains a folder named D:\Folder1. You need to
copy the contents of D:\Folder1 to the public container in an Azure Storage account
named contosodata. Which command should you run?
A. https://contosodata.blob.core.windows.net/public
B. azcopy sync D:\folder1 https://contosodata.blob.core.windows.net/public --
snapshot
C. azcopy copy D:\folder1 https://contosodata.blob.core.windows.net/public --
recursive
D. az storage blob copy start-batch D:\Folder1
https://contosodata.blob.core.windows.net/public
Give this one a try later!
that User1 can deploy virtual machines and manage virtual networks. The solution
must use the principle of least privilege. Which role-based access control (RBAC) role
should you assign to User1?
A. Owner
B. Virtual Machine Contributor
C. Contributor
D. Virtual Machine Administrator Login
Give this one a try later!
C. Contributor
You create an Azure Storage account named contosostorage. You plan to create a
file share named data. Users need to map a drive to the data file share from home
computers that run Windows 10. Which outbound port should you open between the
home computers and the data file share?
,A. 80
B. 443
C. 445
D. 3389
Give this one a try later!
C. 445
You create an Azure Storage account. You plan to add 10 blob containers to the
storage account. For one of the containers, you need to use a different key to encrypt
data at rest. What should you do before you create the container?
A. Generate a shared access signature (SAS).
B. Modify the minimum TLS version.
C. Rotate the access keys.
D. Create an encryption scope.
Give this one a try later!
D. Create an encryption scope.
You have 15 Azure subscriptions. You have an Azure Active Directory (Azure AD)
tenant that contains a security group named Group1. You plan to purchase additional
Azure subscription. You need to ensure that Group1 can manage role assignments for
the existing subscriptions and the planned subscriptions. The solution must meet the
following requirements: ✑ Use the principle of least privilege. ✑ Minimize
administrative effort. What should you do?
A. Assign Group1 the Owner role for the root management group.
B. Assign Group1 the User Access Administrator role for the root management group.
C. Create a new management group and assign Group1 the User Access Administrator
role for the group.
D. Create a new management group and assign Group1 the Owner role for the group.
,Give this one a try later!
B. Assign Group1 the User Access Administrator role for the root
management group.
You have three offices and an Azure subscription that contains an Azure Active
Directory (Azure AD) tenant. You need to grant user management permissions to a
local administrator in each office. What should you use?
A. Azure AD roles
B. administrative units
C. access packages in Azure AD entitlement management
D. Azure roles
Give this one a try later!
B. administrative units
You are configuring Azure Active Directory (Azure AD) authentication for an Azure
Storage account named storage1. You need to ensure that the members of a group
named Group1 can upload files by using the Azure portal. The solution must use the
principle of least privilege. Which two roles should you configure for storage1? Each
correct answer presents part of the solution. NOTE: Each correct selection is worth
one point.
A. Storage Account Contributor
B. Storage Blob Data Contributor
C. Reader
D. Contributor
E. Storage Blob Data Reader
Give this one a try later!
, B. Storage Blob Data Contributor
C. Reader
You have an Azure App Services web app named App1. You plan to deploy App1 by
using Web Deploy. You need to ensure that the developers of App1 can use their
Azure AD credentials to deploy content to App1. The solution must use the principle
of least privilege. What should you do?
A. Assign the Owner role to the developers
B. Configure app-level credentials for FTPS
C. Assign the Website Contributor role to the developers
D. Configure user-level credentials for FTPS
Give this one a try later!
B. Configure app-level credentials for FTPS
You have an on-premises server that contains a folder named D:\Folder1. You need to
copy the contents of D:\Folder1 to the public container in an Azure Storage account
named contosodata. Which command should you run?
A. https://contosodata.blob.core.windows.net/public
B. azcopy sync D:\folder1 https://contosodata.blob.core.windows.net/public --
snapshot
C. azcopy copy D:\folder1 https://contosodata.blob.core.windows.net/public --
recursive
D. az storage blob copy start-batch D:\Folder1
https://contosodata.blob.core.windows.net/public
Give this one a try later!