• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 42 pages
Exam (elaborations)

AZ-104 ACTUAL EXAM 2026/2027 | Questions & Verified Answers | Pass Your Microsoft Azure Administrator Exam | Pass Guaranteed - A+ Graded

Document preview thumbnail
Preview 4 out of 42 pages

Pass the AZ-104 Microsoft Azure Administrator exam with verified questions and answers for 2026/2027. This A+ Graded resource covers all five core exam domains: Manage Azure identities and governance (20-25%), Implement and manage storage (15-20%), Deploy and manage Azure compute resources (20-25%), Implement and manage virtual networking (15-20%), and Monitor and maintain Azure resources (10-15%) . Each question includes detailed rationales to strengthen understanding of key concepts like Microsoft Entra ID, RBAC scopes, Azure Policy, storage redundancy (LRS/GRS/ZRS), ARM and Bicep templates, VNet peering, and Azure Monitor alerts . With our Pass Guarantee, you have the definitive tool to pass on your first attempt. Download your complete AZ-104 exam guide instantly!

Content preview

AZ-104 Questions & Answers 2026|2027
Microsoft Azure Administrator Certification Exam Preparation
Pass For Your Exam | Complete 140-Question Test Bank with Verified Answers

Aligned with 2026-2027 Microsoft Azure Administrator Certification Exam Objectives and Current Azure Service Capabilities

7 Sections | 140 Questions | Cognitive Mix: 30% Recall, 50% Application, 20% Analysis

Independent Study Resource - This exam preparation resource is intended for educational and study purposes to support candidates
preparing for the AZ-104 Microsoft Azure Administrator certification exam. Content is aligned with current Microsoft Azure service
capabilities and official exam objectives. Verify all content with current Microsoft Learn documentation and official Microsoft study
materials. This resource is not affiliated with, endorsed by, or sponsored by Microsoft Corporation.



Section and Question Range Mapping
Secti
Topic Questions Count
on

1 Manage Azure Identities and Governance Q1-Q22 22

2 Implement and Manage Storage Q23-Q42 20

3 Deploy and Manage Azure Compute Resources Q43-Q64 22

4 Implement and Manage Virtual Networking Q65-Q88 24

5 Secure and Monitor Azure Resources Q89-Q108 20

6 Implement Backup, Recovery, and Cost Management Q109-Q124 16

7 Automate, Optimize, and Troubleshoot Azure Operations Q125-Q140 16

TOTAL 140



Section 1: Section 1: Manage Azure Identities and Governance (Microsoft Entra ID,
RBAC, Subscriptions, Azure Policy, & Resource Locks)


Q1: You need to grant a user the ability to manage virtual machines in a specific resource group, but prevent
them from managing networking or storage resources in the same group. Which approach should you use?
A. Assign the Contributor role at the subscription scope.
B. Assign the Virtual Machine Contributor role at the resource group scope. [CORRECT]
C. Assign the Owner role at the resource group scope.
D. Create an Azure Policy assignment denying the creation of non-VM resources.
Correct Answer: B
Rationale: Virtual Machine Contributor is a built-in role that allows management of VMs but not other resources; assigning at
resource group scope limits permissions to that group. Option A (Contributor at subscription) grants too much access, violating
least privilege. Option C (Owner) also allows role assignment changes - excessive. Option D (Azure Policy) controls resource
creation but does not manage RBAC permissions on existing resources. NCLEX-AZ tip: RBAC controls access; Policy
controls compliance. Always apply least privilege.


AZ-104 Microsoft Azure Administrator Exam Test Bank | Page 1

,AZ-104 EXAM 2026|2027 - 140 QUESTION TEST BANK




Q2: A company wants to allow a guest user from a partner organization to access an Azure subscription for a
90-day project. Which action should you perform first?
A. Create a new Microsoft Entra ID tenant for the guest.
B. Invite the guest user via B2B collaboration in Microsoft Entra ID. [CORRECT]
C. Create a service principal for the guest.
D. Assign the guest user a subscription Owner role.
Correct Answer: B
Rationale: Microsoft Entra B2B collaboration allows inviting external guest users to your tenant. The guest uses their own
identity (from their home tenant or social account). Option A is unnecessary - guests keep their home identity. Option C
(service principal) is for applications, not users. Option D (Owner) violates least privilege. After invitation, you assign
appropriate RBAC roles. AZ tip: B2B guest invitations are free (up to limits) and the recommended pattern for partner access.

Q3: You need to delete a resource group named 'prod-rg' that contains production resources, but a junior
admin has applied a CanNotDelete lock. What is the correct sequence of actions?
A. Force delete with the --force flag in Azure CLI.
B. Remove the CanNotDelete lock, then delete the resource group. [CORRECT]
C. Move the resources to another resource group, then delete.
D. Change the lock to ReadOnly, then delete.
Correct Answer: B
Rationale: A CanNotDelete lock prevents deletion of the resource group and its child resources. You must remove the lock
before deletion. There is no --force flag override for locks (Option A). Moving resources (Option C) is unnecessary and would
still require the lock removed if applied to children. A ReadOnly lock (Option D) does not allow deletion either - locks must be
removed first. AZ tip: CanNotDelete locks apply to all resources in the group, inherited by children.

Q4: An administrator wants to enforce that all resources in a subscription must be deployed only to the 'East
US' and 'West Europe' regions. Which Azure feature should they use?
A. RBAC role assignment.
B. Azure Policy with the 'Allowed Locations' built-in definition. [CORRECT]
C. Resource lock.
D. Management group hierarchy.
Correct Answer: B
Rationale: Azure Policy enforces compliance rules on resources. The built-in 'Allowed Locations' policy definition restricts
which regions resources can be deployed to. RBAC (Option A) controls access, not locations. Resource locks (Option C)
prevent deletion or modification, not deployment location. Management groups (Option D) organize subscriptions but do not
enforce location rules. AZ tip: Policy = compliance/governance; RBAC = access control; Locks = protection from changes.

Q5: You have a custom RBAC role that needs to be updated to include additional permissions for managing
Azure Key Vault. Which method should you use?
A. Modify the role in the Azure portal directly.
B. Export the role definition to JSON, modify the 'Actions' array, then update using az role definition update.
[CORRECT]
C. Delete and recreate the role definition.
D. Use Azure Policy to add the permissions.
Correct Answer: B
Rationale: Custom roles are typically edited by exporting the JSON definition, modifying the actions, then updating with
CLI/PowerShell or REST. While the portal allows some editing, JSON export/update is the standard and most reliable method.
Option C is unnecessary - custom roles can be updated. Option D (Policy) does not modify RBAC permissions. AZ tip:
Custom role JSON includes 'Actions', 'NotActions', 'DataActions', 'AssignableScopes'.


AZ-104 Microsoft Azure Administrator Exam Test Bank | Page 2

,AZ-104 EXAM 2026|2027 - 140 QUESTION TEST BANK




Q6: A user reports they cannot reset their password through self-service password reset (SSPR) even though
SSPR is enabled. Which of the following is the most likely cause?
A. The user is not assigned an Azure AD Premium P2 license.
B. The user is not included in the SSPR group selected for password reset. [CORRECT]
C. The user does not have an Azure subscription.
D. The user has MFA configured.
Correct Answer: B
Rationale: SSPR can be configured for 'All users' or 'Selected' users (group-based). If 'Selected' is configured, only members
of that group can use SSPR. SSPR requires Premium P1 (Option A is incorrect - P2 is not required). Subscription (Option C) is
not required for SSPR. MFA (Option D) is actually used during SSPR for verification. AZ tip: SSPR verification methods
require at least one to be configured by the user before reset is allowed.

Q7: You need to apply a tag named 'Department' with value 'Finance' to all existing and future storage
accounts in a subscription. What is the most efficient way to enforce this?
A. Use Azure Policy with the 'Append' effect on storage accounts.
B. Use Azure Policy with 'Modify' effect and a remediation task. [CORRECT]
C. Manually tag each storage account.
D. Use RBAC role assignments.
Correct Answer: B
Rationale: Azure Policy 'Modify' effect adds or replaces tags on resources during creation and can be remediated against
existing resources using a remediation task. 'Append' (Option A) only adds tags during creation and does not affect existing
resources - and only works for non-existent tags. Manual tagging (Option C) is inefficient and not enforced. RBAC (Option D)
does not manage tags. AZ tip: Modify effect supports remediation tasks for existing resources.

Q8: Your organization has 50 Azure subscriptions and wants to apply governance policies across all of them
centrally. What should you create?
A. A management group hierarchy with all subscriptions underneath. [CORRECT]
B. A custom RBAC role at each subscription.
C. A storage account for centralized logging.
D. A single resource group spanning all subscriptions.
Correct Answer: A
Rationale: Management groups allow centralized management of multiple subscriptions. Policies and RBAC applied at the
management group level are inherited by all child subscriptions. Custom RBAC at each subscription (Option B) is repetitive
and not centralized. A storage account (Option C) does not provide governance. Resource groups cannot span subscriptions
(Option D). AZ tip: Management group hierarchy supports up to 6 levels deep, with policies inherited by all children.

Q9: A user has been granted the Reader role at the subscription scope and the Contributor role at a resource
group scope within that subscription. What is the effective permission the user has on resources in that
resource group?
A. Reader only (most restrictive wins).
B. Contributor (most permissive at the lower scope wins). [CORRECT]
C. No access (denied due to conflict).
D. Owner (highest level combined).
Correct Answer: B
Rationale: Azure RBAC is additive - the user gets the union of all assignments. The more specific Contributor role at the
resource group scope grants more permissions than Reader at the subscription level. There is no conflict (Option C). The user
does not get Owner (Option D) - that role would need explicit assignment. AZ tip: RBAC is additive; explicit deny (deny
assignment) overrides all allow assignments.


AZ-104 Microsoft Azure Administrator Exam Test Bank | Page 3

, AZ-104 EXAM 2026|2027 - 140 QUESTION TEST BANK




Q10: You need to ensure that a resource group can be modified but not deleted. Which type of lock should you
apply?
A. ReadOnly.
B. CanNotDelete. [CORRECT]
C. No lock needed - RBAC is sufficient.
D. Apply an Azure Policy.
Correct Answer: B
Rationale: CanNotDelete (Delete) lock allows read and modify operations but prevents deletion. ReadOnly (Option A)
prevents both modification and deletion. RBAC (Option C) does not prevent deletion if the user has Contributor or Owner.
Azure Policy (Option D) is for compliance, not deletion protection. AZ tip: Locks apply regardless of RBAC role - even
Owners cannot delete a locked resource without first removing the lock.

Q11: You have created a custom RBAC role definition and need to assign it to a user for a single resource (one
specific storage account). What scope should you use?
A. Subscription scope.
B. Resource group scope.
C. Resource scope (the storage account itself). [CORRECT]
D. Management group scope.
Correct Answer: C
Rationale: For least privilege, assign at the specific resource scope. Assigning at higher scopes (subscription, resource group,
or management group) grants permissions across more resources than necessary. AZ tip: Scope follows inheritance -
subscription > resource group > resource. Always assign at the narrowest needed scope.

Q12: A company wants to enforce that all VMs created in their subscription have a specific tag (CostCenter)
with a value. Which Azure Policy effect should they use?
A. Deny - block creation of VMs without the tag.
B. Audit - log non-compliance but allow creation.
C. DeployIfNotExists - automatically deploy the tag.
D. All of the above are valid depending on the desired enforcement level. [CORRECT]
Correct Answer: D
Rationale: Azure Policy effects include Deny (block), Audit (log only), and DeployIfNotExists (auto-remediate), among
others. The choice depends on the desired level of enforcement. Deny is strictest; Audit is informational; DeployIfNotExists is
automated remediation. AZ tip: Common effects: Deny, Audit, Append, Modify, DeployIfNotExists, Disabled.

Q13: You need to view the effective permissions a user has on a specific storage account. Which tool should
you use?
A. Azure Advisor.
B. 'Check access' (IAM) feature in the Azure portal. [CORRECT]
C. Azure Monitor.
D. Azure Policy compliance view.
Correct Answer: B
Rationale: The 'Check access' feature in IAM (Access Control) blade allows you to check effective permissions for a user,
group, or service principal on a specific resource. Azure Advisor (Option A) provides best-practice recommendations. Azure
Monitor (Option C) is for monitoring metrics/logs. Azure Policy compliance (Option D) shows policy compliance, not RBAC
permissions. AZ tip: 'Check access' shows direct + inherited role assignments.




AZ-104 Microsoft Azure Administrator Exam Test Bank | Page 4

Document information

Uploaded on
September 29, 2026
Number of pages
42
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$20.50

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NURSEEXAMITY
3.4
(110)
Sold
597
Followers
275
Items
6880
Last sold
18 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions