Topic 6: Misc. Questions

You have an Azure subscription that contains the resources in the following table.


In Azure, you create a private DNS zone named adatum.com, add virtual network link to VNet2, and enable auto registration.
The adatum.com zone is configured as shown in the following exhibit.


For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point


You have an Azure subscription. You need to receive an email alert when a resource lock is removed from any resource in the subscription What should you use to create an activity log alert in Azure Monitor?

A. a resource, a condition, and an action group

B. a resource, a condition, and a Microsoft 365 group

C. a Log Analytics workspace, a resource, and an action group

D. a data collection endpoint, an application security group, and a resource group

A.   a resource, a condition, and an action group

You have an Azure subscription that contains two peered virtual networks named VNet1 and VNet2. VNet1 has a VPN gateway that uses static routing.
The on-premises network has a VPN connection that uses the VPN gateway of VNet1.
You need to configure access for users on the on-premises network to connect to a virtual machine on VNet2. The solution must minimize costs.
Which type of connectivity should you use?

A. Azure Firewall with a private IP address

B. ExpressRoute circuits to VNet2

C. service chaining and user-defined routes (UDRs)

D. Azure Application Gateway

D.   Azure Application Gateway

You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource groups.
Another administrator plans to create several network security groups (NSGs) in the subscription..
You need to ensure that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks..
Solution: You configure a custom policy definition, and then you assign the Azure policy to the subscription..
Does this meet the goal?.

A. Yes

B. No

A.   Yes

You have a Microsoft Entra tenant that contains the users shown in the following table.

The tenant contains the groups shown in the following table.

Self-service password reset (SSPR) needs to be configured for the tenant.
Which users can configure SSPR, and for which group can SSPR be enabled? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


You have an Azure subscription that contains the resource groups shown in the following table.



RG1 contains the resources shown in the following table.



VM1 is running and connects to NIC1 and Disk1. NIC1 connects to VNET1.
RG2 contains a public IP address named IP2 that is in the East US location. IP2 is not assigned to a virtual machine.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.


You have two Azure subscriptions named Sub1 and Sub2 that contain the virtual networks shown in the following table.
You need to ensure that VM1 and VM2 can communicate. The solution must minimize costs and administrative effort. What should you use?

A. an Azure VPN gateway

B. Azure Route Server

C. a user-defined route (UDR)

D. network peering

E. a network virtual appliance (NVA)

D.   network peering

You have an Azure Storage account named storage1.
You need to enable a user named User1 to list and regenerate storage account keys for storage1.
Solution: You assign the Storage Account Contributor role to User1.
Does this meet the goal?

A. Yes

B. No

B.   No

You have an Azure subscription that contains the resources shown in the following table.


LB1 is configured as shown in the following table.


You plan to create new inbound NAT rules that meet the following requirements:
Provide Remote Desktop access to VM2 from the internet by using port 3389.

A. A frontend IP address

B. A health probe

C. A load balancing rule

D. A backend pool

A.   A frontend IP address

You have an Azure Storage account named storage1.
You need to enable a user named User1 to list and regenerate storage account keys for storage1.
Solution: You assign the Storage Account Encryption Scope Contributor Role to User1. Does this meet the goal?

A. Yes

B. No

B.   No

Page 9 out of 45 Pages