AZ 104 RENEWAL EXAM UPDATED ACTUAL
QUESTIONS AND CORRECT ANSWERS
◉ You need to prepare the environment to meet the authentication
requirements. Which two actions should you perform? Each correct
answer presents part of the solution. NOTE: Each correct selection is
worth one point.
A. Allow inbound TCP port 8080 to the domain controllers in the
Miami office.
B. Add http://autogon.microsoftazuread-sso.com to the intranet
zone of each client computer in the Miami office.
C. Join the client computers in the Miami office to Azure AD.
D. Install the Active Directory Federation Services (AD FS) role on a
domain controller in the Miami Questions & Answers PDF P-16
www.dumpskey.com office.
E. Install Azure AD Connect on a server in the Miami office and
enable Pass-through Authentication..
Answer: Answer: BE
,B: You can gradually roll out Seamless SSO to your users. You start by
adding the following Azure AD URL to all or selected users' Intranet
zone settings by using Group Policy in Active Directory:
https://autologon.microsoftazuread-sso.com
E: Seamless SSO works with any method of cloud authentication -
Password Hash Synchronization or Pass-through Authentication,
and can be enabled via Azure AD Connect.
◉ Scenario: Licensing Issue
1. You attempt to assign a license in Azure to several users and
receive the following error message: "Licenses not assigned. License
agreement failed for one user."
2. You verify that the Azure subscription has the available licenses.
You need to resolve the licensing issue before you attempt to assign
the license again. What should you do?
A. From the Groups blade, invite the user accounts to a new group.
B. From the Profile blade, modify the usage location.
C. From the Directory role blade, modify the directory role..
Answer: Answer: B
,Explanation: Some Microsoft services aren't available in all locations
because of local laws and regulations. Before you can assign a
license to a user, you must specify the Usage location property for
the user. You can specify the location under the User > Profile >
Settings section in the Azure portal.
◉ You have an azure subscription named Subscription that contains
the resource groups shown in the following table.
RG1 - East Asia
RG2 - East US
In RG1, you create a virtual machine named VM1 in the East Asia
location. You plan to create a virtual network named VNET1. You
need to create VNET, and then connect VM1 to VNET1. What are two
possible ways to achieve this goal? Each correct answer presents a
complete a solution. NOTE: Each correct selection is worth one
point.
A. Create VNET1 in RG2, and then set East Asia as the location.
B. Create VNET1 in a new resource group in the West US location,
and then set West US as the location.
C. Create VNET1 in RG1, and then set East Asia as the location
D. Create VNET1 in RG1, and then set East US as the location.
E. Create VNET1 in RG2, and then set East US as the location..
, Answer: Answer: AC
A network interface can exist in the same, or different resource
group, than the virtual machine you attach it to, or the virtual
network you connect it to. The virtual machine you attach a network
interface to and the virtual network you connect it to must exist in
the same location, also referred to as a region. Note, Resource
groups can span multiple Regions, but VNets only can hold resources
(VMs, Network Adapters) that exists in the same region. So in this
scenario, you need to create VNET1 in any RG and set location as
East Asia.
◉ You have an Azure subscription that contains a storage account
named account1. You plan to upload the disk files of a virtual
machine to account1 from your on-premises network. The on-
premises network uses a public IP address space of 131.107.1.0/24.
You plan to use the disk files to provision an Azure virtual machine
named VM1. VM1 will be attached to a virtual network named
VNet1. VNet1 uses an IP address space of 192.168.0.0/24. You need
to configure account1 to meet the following requirements: Ensure
that you can upload the disk files to account1. Ensure that you can
attach the disks to VM1. Prevent all other access to account1. Which
two actions should you perform? Each correct selection presents
part of the solution. NOTE: Each correct selection is worth one point.
A. From the Firewalls and virtual networks blade of account1, add
the 131.107.1.0/24 IP address range.
QUESTIONS AND CORRECT ANSWERS
◉ You need to prepare the environment to meet the authentication
requirements. Which two actions should you perform? Each correct
answer presents part of the solution. NOTE: Each correct selection is
worth one point.
A. Allow inbound TCP port 8080 to the domain controllers in the
Miami office.
B. Add http://autogon.microsoftazuread-sso.com to the intranet
zone of each client computer in the Miami office.
C. Join the client computers in the Miami office to Azure AD.
D. Install the Active Directory Federation Services (AD FS) role on a
domain controller in the Miami Questions & Answers PDF P-16
www.dumpskey.com office.
E. Install Azure AD Connect on a server in the Miami office and
enable Pass-through Authentication..
Answer: Answer: BE
,B: You can gradually roll out Seamless SSO to your users. You start by
adding the following Azure AD URL to all or selected users' Intranet
zone settings by using Group Policy in Active Directory:
https://autologon.microsoftazuread-sso.com
E: Seamless SSO works with any method of cloud authentication -
Password Hash Synchronization or Pass-through Authentication,
and can be enabled via Azure AD Connect.
◉ Scenario: Licensing Issue
1. You attempt to assign a license in Azure to several users and
receive the following error message: "Licenses not assigned. License
agreement failed for one user."
2. You verify that the Azure subscription has the available licenses.
You need to resolve the licensing issue before you attempt to assign
the license again. What should you do?
A. From the Groups blade, invite the user accounts to a new group.
B. From the Profile blade, modify the usage location.
C. From the Directory role blade, modify the directory role..
Answer: Answer: B
,Explanation: Some Microsoft services aren't available in all locations
because of local laws and regulations. Before you can assign a
license to a user, you must specify the Usage location property for
the user. You can specify the location under the User > Profile >
Settings section in the Azure portal.
◉ You have an azure subscription named Subscription that contains
the resource groups shown in the following table.
RG1 - East Asia
RG2 - East US
In RG1, you create a virtual machine named VM1 in the East Asia
location. You plan to create a virtual network named VNET1. You
need to create VNET, and then connect VM1 to VNET1. What are two
possible ways to achieve this goal? Each correct answer presents a
complete a solution. NOTE: Each correct selection is worth one
point.
A. Create VNET1 in RG2, and then set East Asia as the location.
B. Create VNET1 in a new resource group in the West US location,
and then set West US as the location.
C. Create VNET1 in RG1, and then set East Asia as the location
D. Create VNET1 in RG1, and then set East US as the location.
E. Create VNET1 in RG2, and then set East US as the location..
, Answer: Answer: AC
A network interface can exist in the same, or different resource
group, than the virtual machine you attach it to, or the virtual
network you connect it to. The virtual machine you attach a network
interface to and the virtual network you connect it to must exist in
the same location, also referred to as a region. Note, Resource
groups can span multiple Regions, but VNets only can hold resources
(VMs, Network Adapters) that exists in the same region. So in this
scenario, you need to create VNET1 in any RG and set location as
East Asia.
◉ You have an Azure subscription that contains a storage account
named account1. You plan to upload the disk files of a virtual
machine to account1 from your on-premises network. The on-
premises network uses a public IP address space of 131.107.1.0/24.
You plan to use the disk files to provision an Azure virtual machine
named VM1. VM1 will be attached to a virtual network named
VNet1. VNet1 uses an IP address space of 192.168.0.0/24. You need
to configure account1 to meet the following requirements: Ensure
that you can upload the disk files to account1. Ensure that you can
attach the disks to VM1. Prevent all other access to account1. Which
two actions should you perform? Each correct selection presents
part of the solution. NOTE: Each correct selection is worth one point.
A. From the Firewalls and virtual networks blade of account1, add
the 131.107.1.0/24 IP address range.