Microsoft
AZ-104
Microsoft Azure Administrator Exam
Up to Date products, reliable and verified.
Questions and Answers in PDF Format.
For More Information – Visit link below:
Web: www.examkill.com/
Version product
Visit us at: https://examkill.com/az-104
, Latest Version: 57.1
Question: 1
You implement the planned changes for Scope1.
You need to ensure that Scope1 meets the technical requirements.
What can you encrypt by using Scope1?
A. containers and blobs in storage2 only
B. containers and blobs in storage1 and storage2
C. containers, blobs, and file shares in storage2 only
D. containers, blobs, and file shares in storage1 and storage2
E. containers, blobs, file shares, queues, and tables in storage2 only
Answer: A
Explanation:
Azure Storage encryption scopes are a Blob-service feature only: Microsoft Learn's "Encryption
scopes for Blob storage" states a scope lets you manage encryption with a key scoped to a
container or an individual blob. Scopes cannot be applied to Azure Files, Queue storage, or Table
storage, and a scope is also a property of the single storage account in which it is created –
Scope1 was created in storage2, so it can never protect storage1 resources. This rules out every
option that mentions file shares, queues, tables, or storage1. Option A is therefore the only
technically valid choice: Scope1 can encrypt containers and blobs in storage2 only. (E) is
outdated/incorrect – it describes account-level default (Microsoft-managed or customer-
managed key) encryption, which does cover all data services, not a named encryption scope.
Administrators should distinguish "storage account encryption" (covers Blobs, Files, Queues,
Tables) from "encryption scope" (Blob-only, granular per-container/blob). To restrict Scope1's
applicability further, set it as the container's default scope and optionally prevent overriding it
at upload time.
Official Reference
Encryption scopes for Blob storage — https://learn.microsoft.com/en-
us/azure/storage/blobs/encryption-scope-overview
Question: 2
HOTSPOT
You need to implement the planned changes for User1.
Which roles should you assign to User1, and for which resources? To answer, select the
appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Visit us at: https://examkill.com/az-104
AZ-104
Microsoft Azure Administrator Exam
Up to Date products, reliable and verified.
Questions and Answers in PDF Format.
For More Information – Visit link below:
Web: www.examkill.com/
Version product
Visit us at: https://examkill.com/az-104
, Latest Version: 57.1
Question: 1
You implement the planned changes for Scope1.
You need to ensure that Scope1 meets the technical requirements.
What can you encrypt by using Scope1?
A. containers and blobs in storage2 only
B. containers and blobs in storage1 and storage2
C. containers, blobs, and file shares in storage2 only
D. containers, blobs, and file shares in storage1 and storage2
E. containers, blobs, file shares, queues, and tables in storage2 only
Answer: A
Explanation:
Azure Storage encryption scopes are a Blob-service feature only: Microsoft Learn's "Encryption
scopes for Blob storage" states a scope lets you manage encryption with a key scoped to a
container or an individual blob. Scopes cannot be applied to Azure Files, Queue storage, or Table
storage, and a scope is also a property of the single storage account in which it is created –
Scope1 was created in storage2, so it can never protect storage1 resources. This rules out every
option that mentions file shares, queues, tables, or storage1. Option A is therefore the only
technically valid choice: Scope1 can encrypt containers and blobs in storage2 only. (E) is
outdated/incorrect – it describes account-level default (Microsoft-managed or customer-
managed key) encryption, which does cover all data services, not a named encryption scope.
Administrators should distinguish "storage account encryption" (covers Blobs, Files, Queues,
Tables) from "encryption scope" (Blob-only, granular per-container/blob). To restrict Scope1's
applicability further, set it as the container's default scope and optionally prevent overriding it
at upload time.
Official Reference
Encryption scopes for Blob storage — https://learn.microsoft.com/en-
us/azure/storage/blobs/encryption-scope-overview
Question: 2
HOTSPOT
You need to implement the planned changes for User1.
Which roles should you assign to User1, and for which resources? To answer, select the
appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Visit us at: https://examkill.com/az-104