[Recommend sharing] Best Microsoft AZ-104 dumps pdf to help you out in your exam

Where can I get Microsoft AZ-104 dumps in 2021? Recommend a valid latest Pass4itsure Microsoft AZ-104 dumps pdf (Pass4itsure with a total of 450 practice questions)! The blog post will guide you to prepare and pass your AZ-104 exam with ease. Will also share some AZ-104 pdf, AZ-104 exam video (AZ-104 practice test) for free, which is very helpful for the real exam. Please stay tuned.

Best Microsoft AZ-104 dumps pdf free download

[Latest pdf] Microsoft AZ-104 dumps pdf from google drive https://drive.google.com/file/d/1PC2qT8gU1VjZW1v8jzBwfh-7EQfZyv80/view?usp=sharing

Features provided by Pass4itsure Microsoft AZ-104 dumps:

Pass4itsure-Features

Pass4itsure AZ-104 exam dumps pdf will guide you to the bright future.

Microsoft Role-based AZ-104 exam questions shares for free

Practicing mock tests increases your chances of passing the exam to 100%.

QUESTION 1
You have an Azure virtual machine named VM1.
The network interface for VM1 is configured as shown in the exhibit. (Click the Exhibit tab.)

az-104 exam questions-q1

You deploy a web server on VM1, and then create a secure website that is accessible by using the HTTPS protocol.
VM1 is used as a web server only.
You need to ensure that users can connect to the website from the internet. What should you do?
A. Create a new inbound rule that allows TCP protocol 443 and configure the protocol to have a priority of 501.
B. For Rule5, change the Action to Allow and change the priority to 401.
C. Delete Rule1.
D. Modify the protocol of Rule4.
Correct Answer: B
Rule 2 is blocking HTTPS access (port 443) and has a priority of 500. Changing Rule 5 (ports 50-5000) and giving it a
lower priority number will allow access on port 443. Note: Rules are processed in priority order, with lower numbers
processed before higher numbers, because lower numbers have higher priority. Once traffic matches a rule, processing
stops.
References: https://docs.microsoft.com/en-us/azure/virtual-network/security-overview

QUESTION 2
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it.
As a result, these questions will not appear in the review screen. You have an Azure Active Directory (Azure AD) tenant
named Adatum and an Azure subscription named Subscription1. Adam contains a group named Developers.
Subscription1 contains a resource group named Dev.
You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group.
Solution: On Dev, you assign the Logic App Contributor role to the Developers group.
Does this meet the goal?
A. Yes
B. No
Correct Answer: A
The Logic App Contributor role lets you manage the logic app, but not access them. It provides access to view, edit, and
update a logic app.
References:
https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles
https://docs.microsoft.com/en-us/azure/logic-apps/logic-apps-securing-a-logic-app

QUESTION 3
DRAG DROP
You are configuring serverless computing in Azure.
You need to receive an email message whenever a resource is created in or deleted from a resource group.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions
to the answer area and arrange them in the correct order.
Select and Place:

az-104 exam questions-q3

References: https://docs.microsoft.com/en-us/azure/event-grid/monitor-virtual-machine-changes-event-grid-logic-app
Action 1: Create an Azure Logic App

az-104 exam questions-q3-2

az-104 exam questions-q3-3

az-104 exam questions-q3-4

References: https://docs.microsoft.com/en-us/azure/event-grid/monitor-virtual-machine-changes-event-grid-logic-app

QUESTION 4
You have an Azure resource manager template that will be used to deploy 10 Azure Web Apps. You have to ensure to
deploy the pre-requisites before the deployment of the template. You have to minimize the costs associated with the
implementation. Which of the following would you deploy as pre-requisites?
A. An Azure Load Balancer
B. An Application Gateway
C. 10 Azure App Service Plans
D. One App Service Plan
Correct Answer: D
In-App Service (Web Apps, API Apps, or Mobile Apps), an app always runs in an App Service plan. An App Service plan
defines a set of computing resources for a web app to run.
One App Service Plan: Correct Choice
For an Azure Web App, you need to have an Azure App Service Plan in place. You can associate multiple Azure Web
Apps with the same App Service Plan. Hence to save on costs, you can just have one Azure App Service Plan in place.
An Azure Load Balancer: Incorrect Choice
An Azure load balancer is a Layer-4 (TCP, UDP) load balancer that provides high availability by distributing incoming
traffic among healthy VMs. A load balancer health probe monitors a given port on each VM and only distributes traffic to
an
operational VM An Application Gateway: Incorrect Choice
Azure Application Gateway is a web traffic load balancer that enables you to manage traffic to your web applications.
Traditional load balancers operate at the transport layer (OSI layer 4 – TCP and UDP) and route traffic based on source
IP
address and port, to a destination IP address and port.
10 Azure App Service Plans: Incorrect Choice
For an Azure Web App, you need to have an Azure App Service Plan in place. You can associate multiple Azure Web
Apps with the same App Service Plan. Hence to save on costs, you can just have one Azure App Service Plan in place.
So
there is no need for 10 App Service Plans.
Reference:
https://docs.microsoft.com/en-us/azure/app-service/overview-hosting-plans https://docs.microsoft.com/enus/azure/virtual-machines/windows/tutorial-load-balancer https://docs.microsoft.com/en-us/azure/applicationgateway/overview

QUESTION 5
You need to use Azure Automation State Configuration to manage the ongoing consistency of a virtual machine
configurations.
Which five actions should you perform in sequence? To answer, move the appropriate action from the list of actions to
the answer area and arrange them in the correct order. NOTE: More than one order of answer choices is correct. You
will
receive credit for any of the correct orders you select.
Select and Place:

az-104 exam questions-q5

Step 1: Upload a configuration to the Azure Automation State Configuration. Import the configuration into the Automation
account. Step 2: Compile a configuration into a node configuration. A DSC configuration defining that state must be
compiled into one or more node configurations (MOF document), and placed on the Automation DSC Pull Server. Step
3: Onboard the virtual machines to Azure Automation State Configuration. Onboard the Azure VM for management with
Azure Automation State Configuration Step 4: Assign the node configuration Step 5: Check the compliance status of the
node Each time Azure Automation State Configuration performs a consistency check on a managed node, the node
sends a status report back to the pull server. You can view these reports on the
page for that node.
On the blade for an individual report, you can see the following status information for the corresponding consistency
check:
The report states – whether the node is “Compliant”, the configuration “Failed”, or the node is “Not Compliant”
References:
https://docs.microsoft.com/en-us/azure/automation/automation-dsc-getting-started

QUESTION 6
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it.
As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource
groups.
Another administrator plans to create several network security groups (NSGs) in the subscription. You need to ensure
that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks.
Solution: You create a resource lock, and then you assign the lock to the subscription.
Does this meet the goal?
A. Yes
B. No
Correct Answer: B
How can I freeze or lock my production/critical Azure resources from accidental deletion? There is a way to do this with
both ASM and ARM resources using Azure resource lock.
References:
https://blogs.msdn.microsoft.com/azureedu/2016/04/27/using-azure-resource-manager-policy-and-azure-lock-to-controlyour-azure-resources/

QUESTION 7
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it.
As a result, these questions will not appear in the review screen.
You deploy an Azure Kubernetes Service (AKS) cluster named AKS1.
You need to deploy a YAML file to AKS1.
Solution: From Azure Cloud Shell, you run az aks.
Does this meet the goal?
A. Yes
B. No
Correct Answer: A
Installing Azure CLI doesn\\’t mean that Azure Kubernates client is installed. So before running kubectl client command,
you have install kubectl, the Kubernetes command-line client. First need to run az aks install-cli to install Kubernetes
CLI,
which is kubectl Reference:
https://docs.microsoft.com/en-us/cli/azure/aks?view=azure-cli-latest

QUESTION 8
You have an Azure subscription that includes data in following locations:

az-104 exam questions-q8

You plan to export data by using Azure import/export job named Export1. You need to identify the data that can be
exported by using Export1. Which data should you identify?
A. DB1
B. Table1
C. container1
D. Share1
Correct Answer: C
Azure Import/Export service is used to securely import large amounts of data to Azure Blob storage. Only the Blob
service is supported with the Export job feature

az-104 exam questions-q8-2

References: https://docs.microsoft.com/en-us/azure/storage/common/storage-import-export-requirements

QUESTION 9
You have an Azure App Service plan named AdatumASP1 that uses the P2v2 pricing tier. AdatumASP1 hosts Ml Azure
web app named adatumwebapp1. You need to delegate the management of adatumwebapp1 to a group named Devs.
Devs must be able to perform the following tasks:
1.
Add deployment slots.
2.
View the configuration of AdatumASP1.
3.
Modify the role assignment for adatumwebapp1. Which role should you assign to the Devs group?
A. Owner
B. Contributor
C. Web Plan Contributor
D. Website Contributor
Correct Answer: A
Owner : Correct Choice
The Owner role lets you manage everything, including access to resources.
Contributor : Incorrect Choice
With contributor role you can Add deployment slots and View the configuration of App service plan but you can\\’t Modify
the role assignment. For this you need User Access Administrator or Owner role. So this is incorrect.
Web Plan Contributor : Incorrect Choice
The Web Plan Contributor role lets you manage the web plans for websites, but not access to them.
So this option is incorrect.
Website Contributor : Incorrect Choice
The Website Contributor role lets you manage websites (not web plans), but not access to them. So this is incorrect
option.
Note:
As per least privilege principle it is not advisable to provide owner role to any group, rather you should create custom
RBAC role with custom policy and use that role for this operation. However as this option is not available here so only
option
to go with owner role.
References:
https://docs.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal
https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles

QUESTION 10
HOTSPOT
You have an Azure Active Directory (Azure AD) tenant. You need to create a conditional access policy that requires all
users to use multi-factor authentication when they access the Azure portal.
Which three settings should you configure? To answer, select the appropriate settings in the answer area.
Hot Area:

az-104 exam questions-q10

Correct Answer

az-104 exam questions-q10-2

Box 1: Assignments, Users and Groups
When you configure the sign-in risk policy, you need to set:
The users and groups the policy applies to: Select Individuals and Groups

az-104 exam questions-q10-3

Box 3:
When you configure the sign-in risk policy, you need to set:
The type of access you want to be enforced when your sign-in risk level has been met:

az-104 exam questions-q10-3

References: https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-user-risk-policy


QUESTION 11
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it.
As a result, these questions will not appear in the review screen. You have an Azure virtual machine named VM1. VM1
was deployed by using a custom Azure Resource Manager template named ARM1.json.
You receive a notification that VM1 will be affected by maintenance.
You need to move VM1 to a different host immediately.
Solution: Solution: From the Overview blade, you move the virtual machine to a different subscription.
Does this meet the goal?
A. Yes
B. No
Correct Answer: B
You would need to Redeploy the VM.
References:
https://docs.microsoft.com/en-us/azure/virtual-machines/windows/redeploy-to-new-node

QUESTION 12
HOTSPOT
You have an Azure Storage account named storage1 that uses Azure Blob storage and Azure File storage.
You need to use AzCopy to copy data to the blob storage and file storage in storage1.
Which authentication method should you use for each type of storage? To answer, select the appropriate options in the
answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

az-104 exam questions-q12

You can provide authorization credentials by using Azure Active Directory (AD), or by using a Shared Access Signature
(SAS) token.
Box 1:
Both Azure Active Directory (AD) and Shared Access Signature (SAS) token are supported for Blob storage.
Box 2:
Only Shared Access Signature (SAS) token is supported for File storage.
Reference:
https://docs.microsoft.com/en-us/azure/storage/common/storage-use-azcopy-v10

QUESTION 13
You have a hybrid infrastructure that contains an Azure Active Directory (Azure AD) tenant named
contoso.onmicrosoft.com. The tenant contains the users shown in the following table.

az-104 exam questions-q13

You plan to share a cloud resource to the All Users group. You need to ensure that User1, User2, User3, and User4 can
connect successfully to the cloud resource.
What should you do first?
A. Create a user account of the member type for User4.
B. Create a user account of the member type for User3.
C. Modify the Directory-wide Groups settings.
D. Modify the External collaboration settings.
Correct Answer: C
Ensure that “Enable an \\’All Users\\’ group in the directory” policy is set to “Yes” in your Azure Active Directory (AD)
settings in order to enable the “All Users” group for centralized access administration. This group represents the entire
collection of Active Directory users, including guests and external users, that you can use to make the access
permissions easier to manage within your directory.
Incorrect Answers:
A, B: User3 and User4 are guests already.
Note: By default, all users and guests in your directory can invite guests even if they\\’re not assigned to an admin role.
External collaboration settings let you turn guest invitations on or off for different types of users in your organization.
You
can also delegate invitations to individual users by assigning roles that allow them to invite guests.
References: https://www.cloudconformity.com/knowledge-base/azure/ActiveDirectory/enable-all-users-group.html

Pass4itsure Microsoft dumps discount code 2021

Pass4itsure value your money and give you a 15% discount on the purchase of a complete AZ-104 exam preparation product set practice test software, PDF Q&A. Share the Pass4itsure Microsoft dumps discount code “Microsoft”.

Pass4itsure Microsoft dumps discount code 2021

The last sentence:

Keep learning! Here are the Microsoft AZ-104 exam questions, Microsoft AZ-104 exam video, AZ-104 pdf that Pass4itsure shares for free. Select Pass4itsure AZ-104 dumps help you pass the exam. Get the full Microsoft AZ-104 dumps pdf, easily!