AZ 104 EXAM 2025 WITH CORRECT
ANSWERS (GRADE A+)
You need to define a custom domain name for Azure AD to support the planned infrastructure. Which domain
I I I I I I I I I I I I I I I I I I
name should you use? I I I I
A. ad.humongousinsurance.com
I I
B. humongousinsurance.onmicrosoft.com
I I
C. humongousinsurance.local
I I
D. humongousinsurance.com - correct answers Answer: D
I I I I I I
Every Azure AD directory comes with an initial domain name in the form of domainname.onmicrosoft.com.
I I I I I I I I I I I I I I
The initial domain name cannot be changed of deleted, but you can add your corporate domain name to AAD as
I I I I I I I I I I I I I I I I I I I I
well. Adding custom domain names to Azure AD allows you to assign user names in the directory that are
I I I I I I I I I I I I I I I I I I I
familiar to your users, such as '.' instead of 'alice@domain name.onmicrosoft.com'.
I I I I I I I I I I
,You need to prepare the environment to meet the authentication requirements. Which two actions should
I I I I I I I I I I I I I I I
you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one
I I I I I I I I I I I I I I I I I
point. I
A. Allow inbound TCP port 8080 to the domain controllers in the Miami office.
I I I I I I I I I I I I I I
B. Add http://autogon.microsoftazuread-sso.com to the intranet zone of each client computer in the Miami
I I I I I I I I I I I I I I
office. I
C. Join the client computers in the Miami office to Azure AD.
I I I I I I I I I I I I
D. Install the Active Di - correct answers Answer: BE
I I I I I I I I I
B: You can gradually roll out Seamless SSO to your users. You start by adding the following Azure AD URL to all or
I I I I I I I I I I I I I I I I I I I I I I I
selected users' Intranet zone settings by using Group Policy in Active Directory:
I I I I I I I I I I I I
https://autologon.microsoftazuread-sso.com I
E: Seamless SSO works with any method of cloud authentication - Password Hash Synchronization or Pass-
I I I I I I I I I I I I I I I
through Authentication, and can be enabled via Azure AD Connect. I I I I I I I I I
Scenario: Licensing Issue I I I
1. You attempt to assign a license in Azure to several users and receive the following error message: "Licenses
I I I I I I I I I I I I I I I I I I I
not assigned. License agreement failed for one user."
I I I I I I I I
2. You verify that the Azure subscription has the available licenses.
I I I I I I I I I I
You need to resolve the licensing issue before you attempt to assign the license again. What should you do?
I I I I I I I I I I I I I I I I I I I
A. From the Groups blade, invite the user accounts to a new group.
I I I I I I I I I I I I I
B. From the Profile blade, modify the usage location.
I I I I I I I I I
C. - correct answers Answer: B
I I I I I
,Explanation: Some Microsoft services aren't available in all locations because of local laws and regulations. I I I I I I I I I I I I I I I
Before you can assign a license to a user, you must specify the Usage location property for the user. You can
I I I I I I I I I I I I I I I I I I I I I
specify the location under the User > Profile > Settings section in the Azure portal.
I I I I I I I I I I I I I I
You have an azure subscription named Subscription that contains the resource groups shown in the following
I I I I I I I I I I I I I I I I
table. I
RG1 - East Asia I I I
RG2 - East US I I I
In RG1, you create a virtual machine named VM1 in the East Asia location. You plan to create a virtual network
I I I I I I I I I I I I I I I I I I I I I
named VNET1. You need to create VNET, and then connect VM1 to VNET1. What are two possible ways to
I I I I I I I I I I I I I I I I I I I
achieve this goal? Each correct answer presents a complete a solution. NOTE: Each correct selection is worth
I I I I I I I I I I I I I I I I I
one point. I I
A. Create VNET1 in RG - correct answers Answer: AC
I I I I I I I I I
A network interface can exist in the same, or different resource group, than the virtual machine you attach it to,
I I I I I I I I I I I I I I I I I I I I
or the virtual network you connect it to. The virtual machine you attach a network interface to and the virtual
I I I I I I I I I I I I I I I I I I I I
network you connect it to must exist in the same location, also referred to as a region. Note, Resource groups
I I I I I I I I I I I I I I I I I I I I
can span multiple Regions, but VNets only can hold resources (VMs, Network Adapters) that exists in the same
I I I I I I I I I I I I I I I I I I
region. So in this scenario, you need to create VNET1 in any RG and set location as East Asia.
I I I I I I I I I I I I I I I I I I
You have an Azure subscription that contains a storage account named account1. You plan to upload the disk
I I I I I I I I I I I I I I I I I I
files of a virtual machine to account1 from your on-premises network. The on-premises network uses a public
I I I I I I I I I I I I I I I I I
IP address space of 131.107.1.0/24. You plan to use the disk files to provision an Azure virtual machine named
I I I I I I I I I I I I I I I I I I I
VM1. VM1 will be attached to a virtual network named VNet1. VNet1 uses an IP address space of
I I I I I I I I I I I I I I I I I I
192.168.0.0/24. You need to configure account1 to meet the following requirement - correct answers Answer: I I I I I I I I I I I I I I
AB
I
By default, storage accounts accept connections from clients on any network. To limit access to selected
I I I I I I I I I I I I I I I I
networks, you must first change the default action. Azure portal I I I I I I I I I I
1. Navigate to the storage account you want to secure. 2. Click on the settings menu called Firewalls and virtual
I I I I I I I I I I I I I I I I I I I I
networks. I
, 3. To deny access by default, choose to allow access from 'Selected networks'. To allow traffic from all
I I I I I I I I I I I I I I I I I I
networks, choose to allow access from 'All networks'. I I I I I I I I
4. Click Save to apply your changes. Grant access from a Virtual Network Storage accounts can be configured to
I I I I I I I I I I I I I I I I I I I
allow access only from specific Azure Virtual Networks. By enabling a Service Endpoint for Azure Storage within
I I I I I I I I I I I I I I I I
the Virtual Network, traffic is ensured an optimal route to the Azure Storage service. The identities of the
I I I I I I I I I I I I I I I I I I I
virtual network and the subnet are also transmitted with each request.
I I I I I I I I I I
You have an Azure Active Directory (Azure AD) tenant named contosocloud.onmicrosoft.com. Your company
I I I I I I I I I I I I I
has a public DNS zone for contoso.com. You add contoso.com as a custom domain name to Azure AD. You need
I I I I I I I I I I I I I I I I I I I I
to ensure that Azure can verify the domain name. Which type of DNS record should you create?
I I I I I I I I I I I I I I I I I
A. PTR I I
B. MX I I
C. NSEC3I I
D. RRSIG - correct answers Answer: B
I I I I I I
TXT or MX : Correct You can use either a TXT or MX record to verify the custom domain in the Azure AD. MX
I I I I I I I I I I I I I I I I I I I I I I I I
records can serve the purpose of TXT records Questions & Answers PDF P-56 www.dumpskey.com
I I I I I I I I I I I I I I
SRV : Incorrect SRV records are used by various services to specify server locations. When specifying an SRV
I I I I I I I I I I I I I I I I I I
record in Azure DNS I I I I
DNSKEY : Incorrect Choice This will verify that the records are originating from an authorized sender. NSEC :
I I I I I I I I I I I I I I I I I I
Incorrect Choice This is Part of DNSSEC. This is used for explicit denial-of-existence of a DNS record. It is used to
I I I I I I I I I I I I I I I I I I I I I
prove a name does not exist. I I I I I
You have an Azure virtual machine named VM1. Azure collects events from VM1. You are creating an alert rule
I I I I I I I I I I I I I I I I I I I
in Azure Monitor to notify an administrator when an error is logged in the System event log of VM1. You need to
I I I I I I I I I I I I I I I I I I I I I I
specify which resource type to monitor. What should you specify? I I I I I I I I I
A. metric alert
I I I
B. Azure Log Analytics workspace
I I I I I
C. virtual machine
I I I
D. virtual machine extension - correct answers Answer: B
I I I I I I I I
ANSWERS (GRADE A+)
You need to define a custom domain name for Azure AD to support the planned infrastructure. Which domain
I I I I I I I I I I I I I I I I I I
name should you use? I I I I
A. ad.humongousinsurance.com
I I
B. humongousinsurance.onmicrosoft.com
I I
C. humongousinsurance.local
I I
D. humongousinsurance.com - correct answers Answer: D
I I I I I I
Every Azure AD directory comes with an initial domain name in the form of domainname.onmicrosoft.com.
I I I I I I I I I I I I I I
The initial domain name cannot be changed of deleted, but you can add your corporate domain name to AAD as
I I I I I I I I I I I I I I I I I I I I
well. Adding custom domain names to Azure AD allows you to assign user names in the directory that are
I I I I I I I I I I I I I I I I I I I
familiar to your users, such as '.' instead of 'alice@domain name.onmicrosoft.com'.
I I I I I I I I I I
,You need to prepare the environment to meet the authentication requirements. Which two actions should
I I I I I I I I I I I I I I I
you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one
I I I I I I I I I I I I I I I I I
point. I
A. Allow inbound TCP port 8080 to the domain controllers in the Miami office.
I I I I I I I I I I I I I I
B. Add http://autogon.microsoftazuread-sso.com to the intranet zone of each client computer in the Miami
I I I I I I I I I I I I I I
office. I
C. Join the client computers in the Miami office to Azure AD.
I I I I I I I I I I I I
D. Install the Active Di - correct answers Answer: BE
I I I I I I I I I
B: You can gradually roll out Seamless SSO to your users. You start by adding the following Azure AD URL to all or
I I I I I I I I I I I I I I I I I I I I I I I
selected users' Intranet zone settings by using Group Policy in Active Directory:
I I I I I I I I I I I I
https://autologon.microsoftazuread-sso.com I
E: Seamless SSO works with any method of cloud authentication - Password Hash Synchronization or Pass-
I I I I I I I I I I I I I I I
through Authentication, and can be enabled via Azure AD Connect. I I I I I I I I I
Scenario: Licensing Issue I I I
1. You attempt to assign a license in Azure to several users and receive the following error message: "Licenses
I I I I I I I I I I I I I I I I I I I
not assigned. License agreement failed for one user."
I I I I I I I I
2. You verify that the Azure subscription has the available licenses.
I I I I I I I I I I
You need to resolve the licensing issue before you attempt to assign the license again. What should you do?
I I I I I I I I I I I I I I I I I I I
A. From the Groups blade, invite the user accounts to a new group.
I I I I I I I I I I I I I
B. From the Profile blade, modify the usage location.
I I I I I I I I I
C. - correct answers Answer: B
I I I I I
,Explanation: Some Microsoft services aren't available in all locations because of local laws and regulations. I I I I I I I I I I I I I I I
Before you can assign a license to a user, you must specify the Usage location property for the user. You can
I I I I I I I I I I I I I I I I I I I I I
specify the location under the User > Profile > Settings section in the Azure portal.
I I I I I I I I I I I I I I
You have an azure subscription named Subscription that contains the resource groups shown in the following
I I I I I I I I I I I I I I I I
table. I
RG1 - East Asia I I I
RG2 - East US I I I
In RG1, you create a virtual machine named VM1 in the East Asia location. You plan to create a virtual network
I I I I I I I I I I I I I I I I I I I I I
named VNET1. You need to create VNET, and then connect VM1 to VNET1. What are two possible ways to
I I I I I I I I I I I I I I I I I I I
achieve this goal? Each correct answer presents a complete a solution. NOTE: Each correct selection is worth
I I I I I I I I I I I I I I I I I
one point. I I
A. Create VNET1 in RG - correct answers Answer: AC
I I I I I I I I I
A network interface can exist in the same, or different resource group, than the virtual machine you attach it to,
I I I I I I I I I I I I I I I I I I I I
or the virtual network you connect it to. The virtual machine you attach a network interface to and the virtual
I I I I I I I I I I I I I I I I I I I I
network you connect it to must exist in the same location, also referred to as a region. Note, Resource groups
I I I I I I I I I I I I I I I I I I I I
can span multiple Regions, but VNets only can hold resources (VMs, Network Adapters) that exists in the same
I I I I I I I I I I I I I I I I I I
region. So in this scenario, you need to create VNET1 in any RG and set location as East Asia.
I I I I I I I I I I I I I I I I I I
You have an Azure subscription that contains a storage account named account1. You plan to upload the disk
I I I I I I I I I I I I I I I I I I
files of a virtual machine to account1 from your on-premises network. The on-premises network uses a public
I I I I I I I I I I I I I I I I I
IP address space of 131.107.1.0/24. You plan to use the disk files to provision an Azure virtual machine named
I I I I I I I I I I I I I I I I I I I
VM1. VM1 will be attached to a virtual network named VNet1. VNet1 uses an IP address space of
I I I I I I I I I I I I I I I I I I
192.168.0.0/24. You need to configure account1 to meet the following requirement - correct answers Answer: I I I I I I I I I I I I I I
AB
I
By default, storage accounts accept connections from clients on any network. To limit access to selected
I I I I I I I I I I I I I I I I
networks, you must first change the default action. Azure portal I I I I I I I I I I
1. Navigate to the storage account you want to secure. 2. Click on the settings menu called Firewalls and virtual
I I I I I I I I I I I I I I I I I I I I
networks. I
, 3. To deny access by default, choose to allow access from 'Selected networks'. To allow traffic from all
I I I I I I I I I I I I I I I I I I
networks, choose to allow access from 'All networks'. I I I I I I I I
4. Click Save to apply your changes. Grant access from a Virtual Network Storage accounts can be configured to
I I I I I I I I I I I I I I I I I I I
allow access only from specific Azure Virtual Networks. By enabling a Service Endpoint for Azure Storage within
I I I I I I I I I I I I I I I I
the Virtual Network, traffic is ensured an optimal route to the Azure Storage service. The identities of the
I I I I I I I I I I I I I I I I I I I
virtual network and the subnet are also transmitted with each request.
I I I I I I I I I I
You have an Azure Active Directory (Azure AD) tenant named contosocloud.onmicrosoft.com. Your company
I I I I I I I I I I I I I
has a public DNS zone for contoso.com. You add contoso.com as a custom domain name to Azure AD. You need
I I I I I I I I I I I I I I I I I I I I
to ensure that Azure can verify the domain name. Which type of DNS record should you create?
I I I I I I I I I I I I I I I I I
A. PTR I I
B. MX I I
C. NSEC3I I
D. RRSIG - correct answers Answer: B
I I I I I I
TXT or MX : Correct You can use either a TXT or MX record to verify the custom domain in the Azure AD. MX
I I I I I I I I I I I I I I I I I I I I I I I I
records can serve the purpose of TXT records Questions & Answers PDF P-56 www.dumpskey.com
I I I I I I I I I I I I I I
SRV : Incorrect SRV records are used by various services to specify server locations. When specifying an SRV
I I I I I I I I I I I I I I I I I I
record in Azure DNS I I I I
DNSKEY : Incorrect Choice This will verify that the records are originating from an authorized sender. NSEC :
I I I I I I I I I I I I I I I I I I
Incorrect Choice This is Part of DNSSEC. This is used for explicit denial-of-existence of a DNS record. It is used to
I I I I I I I I I I I I I I I I I I I I I
prove a name does not exist. I I I I I
You have an Azure virtual machine named VM1. Azure collects events from VM1. You are creating an alert rule
I I I I I I I I I I I I I I I I I I I
in Azure Monitor to notify an administrator when an error is logged in the System event log of VM1. You need to
I I I I I I I I I I I I I I I I I I I I I I
specify which resource type to monitor. What should you specify? I I I I I I I I I
A. metric alert
I I I
B. Azure Log Analytics workspace
I I I I I
C. virtual machine
I I I
D. virtual machine extension - correct answers Answer: B
I I I I I I I I