1 | Page
AZ-104: MICROSOFT AZURE
ADMINISTRATOR ASSOCIATE
PRACTICE EXAM – 40 QUESTIONS WITH
VERIFIED ANSWERS & COMPLETE
RATIONALES
## SECTION 1: IDENTITY & GOVERNANCE
**1. Which Azure service is used to manage users, groups, and
application identities in the cloud?**
A. Azure Policy
B. Microsoft Entra ID
C. Azure RBAC
D. Azure Advisor
**Correct answer:** Microsoft Entra ID
**Rationale:** Microsoft Entra ID (formerly Azure Active
Directory) is Microsoft's cloud-based identity and access
management service. It handles authentication, user/group
management, and application identities. Azure Policy enforces
rules on resources, RBAC controls access to resources, and
Azure Advisor provides recommendations.
,2 | Page
---
**2. A company wants to ensure that all new storage accounts
are deployed only in the "East US" region. Which Azure service
should be used?**
A. Azure RBAC
B. Network Security Group
C. Azure Policy
D. Resource Lock
**Correct answer:** Azure Policy
**Rationale:** Azure Policy is used to enforce organizational
standards and assess compliance at scale. A policy can restrict
the allowed locations for resource deployment. RBAC controls
who can do things, NSGs filter network traffic, and Resource
Locks prevent accidental deletion or modification.
---
**3. Which role provides full access to manage all Azure
resources but cannot grant access to others?**
A. Owner
, 3 | Page
B. Contributor
C. Reader
D. User Access Administrator
**Correct answer:** Contributor
**Rationale:** The Contributor role can create and manage all
types of Azure resources but cannot grant access to others.
Owner can manage everything including access. Reader can
only view. User Access Administrator can manage user access
only.
---
**4. What is the maximum number of custom roles you can
create in a single Microsoft Entra tenant?**
A. 100
B. 500
C. 2,000
D. 5,000
**Correct answer:** 5,000
AZ-104: MICROSOFT AZURE
ADMINISTRATOR ASSOCIATE
PRACTICE EXAM – 40 QUESTIONS WITH
VERIFIED ANSWERS & COMPLETE
RATIONALES
## SECTION 1: IDENTITY & GOVERNANCE
**1. Which Azure service is used to manage users, groups, and
application identities in the cloud?**
A. Azure Policy
B. Microsoft Entra ID
C. Azure RBAC
D. Azure Advisor
**Correct answer:** Microsoft Entra ID
**Rationale:** Microsoft Entra ID (formerly Azure Active
Directory) is Microsoft's cloud-based identity and access
management service. It handles authentication, user/group
management, and application identities. Azure Policy enforces
rules on resources, RBAC controls access to resources, and
Azure Advisor provides recommendations.
,2 | Page
---
**2. A company wants to ensure that all new storage accounts
are deployed only in the "East US" region. Which Azure service
should be used?**
A. Azure RBAC
B. Network Security Group
C. Azure Policy
D. Resource Lock
**Correct answer:** Azure Policy
**Rationale:** Azure Policy is used to enforce organizational
standards and assess compliance at scale. A policy can restrict
the allowed locations for resource deployment. RBAC controls
who can do things, NSGs filter network traffic, and Resource
Locks prevent accidental deletion or modification.
---
**3. Which role provides full access to manage all Azure
resources but cannot grant access to others?**
A. Owner
, 3 | Page
B. Contributor
C. Reader
D. User Access Administrator
**Correct answer:** Contributor
**Rationale:** The Contributor role can create and manage all
types of Azure resources but cannot grant access to others.
Owner can manage everything including access. Reader can
only view. User Access Administrator can manage user access
only.
---
**4. What is the maximum number of custom roles you can
create in a single Microsoft Entra tenant?**
A. 100
B. 500
C. 2,000
D. 5,000
**Correct answer:** 5,000