Free AZ-104 Practice Exam: Microsoft Azure Administrator
Try 50 free Microsoft Azure Administrator (AZ-104) questions with diagrams, Bicep, configuration exhibits, and explained answers from our refreshed practice bank.
Practise with 50 questions from the reviewed AZ-104 v2 bank, including seven diagram questions, Bicep, diagnostic output, and configuration tables. These are original IT Mastery practice questions, not official Microsoft questions, copied live-exam content, or exam dumps.
Start Question 1 · Questions 26–50 · Review your attempt
How to use this free exam
- Write down each answer before opening its explanation. There are 45 single-answer questions and five Select TWO questions.
- For a timed attempt, set your own 100-minute timer. This page does not run a timer, record your answers, or calculate a score.
- Award one point per correct question, for a total out of 50. For Select TWO, both choices must match with no extra choice. Mark correct guesses for review too.
- Read the explanation after answering. Identify the evidence that makes the strongest alternative fail—not just the wording of the correct choice.
Use Open full-size diagram when labels need more space, or open its Text description. Wide tables scroll horizontally. Code blocks offer Wrap lines and Copy code; keep the stated assumptions in mind when reading illustrative commands.
The set covers the five domains in the current AZ-104 blueprint . Microsoft provides 100 minutes for the exam but does not guarantee a fixed question count or item-type mix. This public set uses our practice-bank allocation; it does not reproduce a live Microsoft exam. Microsoft certification details .
Practice-set coverage
| Domain | Official range | Questions in this set |
|---|---|---|
| Manage Azure Identities and Governance | 20–25% | 12 |
| Implement and Manage Storage | 15–20% | 10 |
| Deploy and Manage Azure Compute Resources | 20–25% | 12 |
| Implement and Manage Virtual Networking | 15–20% | 9 |
| Monitor and Maintain Azure Resources | 10–15% | 7 |
Practice questions
Questions 1-25
Question 1
Topic: Identities and Governance
A partner’s Microsoft Entra B2B guest account has already redeemed its invitation. The partner now uses a different email identity and cannot access the original identity. You must let the partner redeem with the new email while preserving the guest’s object ID, group memberships, and application assignments.
What should you do?
Options:
A. Delete the guest, invite the new email, and recreate its assignments.
B. Reset redemption status, enter the new email, and resend the invitation.
C. Update the contact email, revoke sessions, and resend the invitation.
D. Change the guest UPN, revoke sessions, and resend the invitation.
Best answer: B
Explanation: Microsoft Entra B2B invitation redemption associates an external identity with an existing guest object. Resetting the guest’s redemption status clears that association and permits a new invitation to be redeemed with a different email identity. The guest’s object ID, group memberships, and application assignments are retained.
Changing contact information or the guest UPN does not replace the external identity established during redemption. Revoking sessions invalidates existing tokens but does not reset the identity association. Deleting and recreating the guest produces a different object ID and requires access to be reassigned.
- Updating contact email changes profile information but does not reset the external identity used during invitation redemption.
- Changing the UPN changes a directory attribute but does not associate the guest with the partner’s new external identity.
- Recreating the guest creates a new object ID, so existing memberships and application assignments are not preserved automatically.
Question 2
Topic: Compute
A Windows Server Azure VM uses a nonshared managed data disk containing one NTFS volume, F:. An administrator expands the disk from 256 GiB to 512 GiB. The application using F: must remain online.
Observed status:
15:03 Azure disk update: Succeeded
15:05 Guest disk 2 capacity: 256 GiB
15:05 F: partition size: 256 GiB
15:05 Supported maximum size: 256 GiB
The guest measurements were collected before any storage rescan. Which action should the administrator take next?
Options:
A. Detach and reattach disk 2, then extend F: after reconnection.
B. Restart Windows, then extend F: after the disk capacity refreshes.
C. Rescan storage in Windows, then extend F: into the unallocated space.
D. Extend F: to 512 GiB, then rescan storage in Windows.
Best answer: C
Explanation: Managed disk capacity and guest volume capacity are separate layers. The successful Azure update shows that the managed disk is now 512 GiB, while the guest output still reflects the geometry cached before a rescan. Windows must first rescan its storage devices so that disk 2 shows the additional unallocated space. The administrator can then extend the NTFS partition through Disk Management or Resize-Partition while the VM and application remain online.
Extending the partition before the rescan cannot use capacity that Windows has not detected, and restarting or detaching the disk would cause an unnecessary interruption.
- Restart Windows may refresh disk geometry, but it interrupts the application and is unnecessary for this supported online expansion.
- Extend before rescan fails because Windows still reports 256 GiB as the maximum supported partition size.
- Detach and reattach can force rediscovery, but it interrupts disk access despite the successful online Azure resize.
Question 3
Topic: Monitoring and Recovery
An administrator expects Windows performance counters and selected event logs from vm-app01 in ws-ops.
Observed at 09:40:
| Component | Status |
|---|---|
dcr-guest | Sources and data flow to ws-ops saved at 09:00 |
| Azure Monitor Agent | Provisioning succeeded at 09:05 |
| Workspace queries | No guest records since 09:05 |
| DCR associations | None for vm-app01 |
Which action should the administrator take to begin the guest collection defined by dcr-guest?
Options:
A. Associate
dcr-guestwithvm-app01.B. Reinstall AMA and configure
ws-opsdirectly in the extension.C. Enable VM Insights for
vm-app01usingws-ops.D. Add a VM diagnostic setting that sends guest data to
ws-ops.
Best answer: A
Explanation: Azure Monitor Agent performs guest collection, but a data collection rule defines what to collect, how to process it, and where to send it. A data collection rule association applies that configuration to a monitored resource. Here, the agent is healthy, and dcr-guest already has the required sources, data flow, and workspace destination. The missing association means the agent has no applicable instruction to collect those sources.
Creating the association starts collection prospectively; it does not reconstruct telemetry from before the association existed. Installing the agent alone is therefore insufficient.
- Reinstalling AMA does not apply the existing DCR, and the extension already reports successful provisioning.
- Using diagnostic settings collects supported platform telemetry rather than AMA-based guest performance counters and event logs.
- Enabling VM Insights can deploy separate monitoring configuration but does not apply the sources defined in the existing DCR.
Question 4
Topic: Storage
All application instances authenticate to an Azure storage account with key1; key2 is unused. Configuration deployment rolls through instances asynchronously, and a dashboard confirms when every instance has loaded a configuration and authenticated successfully.
You must regenerate both keys without failed requests. At completion, every instance must use the regenerated key2. Which procedure should you follow?
Options:
A. Regenerate
key2; start its deployment; regeneratekey1; confirm every instance useskey2.B. Regenerate
key1; start its deployment; confirm every instance uses it; regeneratekey2.C. Deploy current
key2; confirm every instance uses it; regeneratekey1; regeneratekey2.D. Regenerate
key2; start its deployment; confirm every instance uses it; regeneratekey1.
Best answer: D
Explanation: Regenerating a storage account key immediately invalidates its previous value. Safe rotation therefore begins with the unused key. After regenerating key2, deploy its new value and wait until the dashboard confirms that every instance is successfully using it. Only then can key1 be regenerated without interrupting clients. This sequence also reaches the required end state: both keys have been regenerated, and clients use the new key2.
The critical prerequisite is confirming migration away from the active key before invalidating that key.
- Deploying the current
key2works temporarily, but regenerating it afterward invalidates the value clients are using. - Regenerating
key1before confirming the rolling deployment can interrupt instances that still usekey1. - Regenerating
key1first immediately invalidates the credential initially used by every instance.
Question 5
Topic: Storage
A blob-to-blob AzCopy transfer used SAS authorization for both storage accounts. The original SAS tokens expired at 14:00, and replacement tokens are available.
Job evidence at 14:05:
Job status: CompletedWithErrors
Transfers completed: 11,420
Transfers failed: 580
Last error: 403 AuthenticationFailed
Job-plan files: retained on AdminVM
Connectivity tests from AdminVM to both blob endpoints on TCP 443 now succeed. Which action should complete the remaining transfers while preserving the job’s progress?
Options:
A. Resume the job from another computer using the original SAS tokens
B. Resume the job on AdminVM with only the destination SAS token
C. Resume the job on AdminVM with both replacement SAS tokens
D. Restart the copy on AdminVM with both replacement SAS tokens
Best answer: C
Explanation: AzCopy resumability depends on the retained job-plan files, valid authorization, and connectivity to the required endpoints. The job plan on AdminVM records which transfers completed and which failed, so resuming the existing job avoids starting a new transfer operation. However, job plans do not retain SAS tokens. Because both the source and destination were authorized by SAS and both original tokens expired, replacement tokens for both sides must be provided when the job is resumed. The successful TCP 443 tests show that AdminVM currently has the required endpoint connectivity.
Restarting the copy creates a new job instead of using the recorded progress from the incomplete job.
- Restarting creates a new job and does not use the retained plan to target the failed transfers.
- Supplying only the destination SAS leaves the source without the required current authorization.
- Using the original SAS tokens fails because they have expired, regardless of which computer initiates the resume.
Question 6
Topic: Compute
An administrator reviews four virtual machines in the same availability set.
| VM | Fault domain | Update domain |
|---|---|---|
| VM1 | FD0 | UD0 |
| VM2 | FD1 | UD1 |
| VM3 | FD0 | UD1 |
| VM4 | FD1 | UD0 |
A hardware failure affects FD0. Separately, planned maintenance restarts UD0. Which interpretation correctly identifies the VMs that may be unavailable during each event?
Options:
A. Hardware: VM1 and VM3; maintenance: VM1 and VM4
B. Hardware: VM1 only; maintenance: VM1 and VM4
C. Hardware: VM1 and VM3; maintenance: VM1 only
D. Hardware: VM1 and VM4; maintenance: VM1 and VM3
Best answer: A
Explanation: Fault domains group VMs that share exposure to underlying hardware, power, or network failures. A failure affecting FD0 can therefore make VM1 and VM3 unavailable, regardless of their update domains. Update domains group VMs that Azure may restart together during planned maintenance. Maintenance affecting UD0 can therefore make VM1 and VM4 unavailable, regardless of their fault domains.
The two domain types are independent coordinates: fault-domain distribution limits correlated hardware failures, while update-domain distribution limits simultaneous maintenance restarts.
- Swapping the VM groups incorrectly treats update domains as hardware boundaries and fault domains as maintenance boundaries.
- Limiting the hardware failure to VM1 ignores that VM3 also resides in FD0.
- Limiting maintenance to VM1 ignores that VM4 also resides in UD0.
Question 7
Topic: Monitoring and Recovery
A Log Analytics workspace receives one Perf row per CPU sample. An analyst needs one row for each VM and each 10-minute interval, showing average and peak CPU usage.
Computeridentifies the VM.TimeGeneratedis the sample time.CounterValueis the sampled percentage.- In KQL,
summarizeemits one row per unique combination of itsbyexpressions, andbin()groups values into fixed buckets.
Perf
| where TimeGenerated >= ago(2h)
| where ObjectName == "Processor" and CounterName == "% Processor Time" and InstanceName == "_Total"
| <aggregation-line>
Which line should replace <aggregation-line>?
Options:
A.
summarize AvgCPU = avg(CounterValue), PeakCPU = max(CounterValue) by Computer, bin(CounterValue, 10)B.
summarize AvgCPU = avg(CounterValue), PeakCPU = max(CounterValue) by Computer, bin(TimeGenerated, 10m)C.
summarize AvgCPU = avg(CounterValue), PeakCPU = max(CounterValue) by Computer, bin(TimeGenerated, 1h)D.
summarize AvgCPU = avg(CounterValue), PeakCPU = max(CounterValue) by CounterName, bin(TimeGenerated, 10m)
Best answer: B
Explanation: KQL’s summarize operator calculates each aggregate for every unique combination of the expressions following by. Including Computer keeps samples from different VMs separate. Applying bin(TimeGenerated, 10m) rounds sample times into fixed 10-minute buckets. Within each VM and time bucket, avg(CounterValue) calculates average CPU usage and max(CounterValue) calculates peak CPU usage.
Both the resource identifier and the requested time bucket must be grouping expressions.
- Using a one-hour time bin produces hourly summaries rather than the required 10-minute intervals.
- Grouping by
CounterNamecombines samples from different VMs because that field is fixed by the filter. - Binning
CounterValuegroups CPU percentages into value ranges instead of grouping samples by time.
Question 8
Topic: Storage
An Azure storage account has blob versioning and blob soft delete enabled. A user overwrote reports/summary.csv, and the current blob contains incorrect data. The desired content is available as a previous version with a known version ID. The blob was not deleted, and no snapshots exist.
Which action should an administrator take to make the desired content current while preserving version history?
Options:
A. Restore the base blob from a timestamp-matched snapshot.
B. Copy the desired version to the base blob URL.
C. Delete the current version to expose the desired version.
D. Undelete the base blob to restore the desired version.
Best answer: B
Explanation: Blob versioning preserves previous blob states as independently addressable versions. To restore desired content, use the previous version as the copy source and the base blob URL as the destination. Because versioning remains enabled, the copy creates another version that becomes current while retaining the existing version history.
Soft delete addresses deleted blobs or versions, not an ordinary overwrite when the required previous version remains available. Snapshots are separate read-only point-in-time copies and cannot be used when none were created. The key is to promote the existing version through a copy operation rather than treating the overwrite as a deletion.
- Deleting the base blob leaves no current version and retains its previous versions; it does not automatically promote the desired one.
- Undelete is inappropriate because the base blob was overwritten rather than deleted.
- Snapshot restoration is unavailable because no snapshot exists, even if a matching timestamp is known.
Question 9
Topic: Storage
A storage account uses AD DS identity-based SMB access. The FinanceEditors group is synchronized to Microsoft Entra ID. Members must create, edit, and delete files only in the Quarterly directory of the reports share. They must not change permissions, and other users’ access must remain unchanged.
Apply least privilege at the narrowest relevant scopes. Select TWO actions.
Options:
A. Grant
FinanceEditorsModify onQuarterlyand its child items.B. Assign the Azure Contributor role at the share scope.
C. Assign Storage File Data SMB Share Reader at the share scope.
D. Grant
FinanceEditorsFull Control onQuarterlyand its child items.E. Assign Storage File Data SMB Share Contributor at the share scope.
Correct answers: A and E
Explanation: Identity-based SMB access to Azure Files requires authorization at two levels. An applicable Azure role assignment grants access to the file share, while Windows directory and file ACLs control access within that share. Storage File Data SMB Share Contributor permits read, write, and delete operations. An inherited Modify ACL on Quarterly permits the required file operations while limiting access to the intended directory and withholding permission-management rights.
Both authorization layers must permit an operation. Full Control would work functionally but would unnecessarily allow members to change ACLs.
- The SMB Share Reader role permits reading but does not authorize creating, editing, or deleting files.
- The Azure Contributor role manages resources through the management plane but does not grant SMB data access.
- Full Control includes changing permissions and ownership, exceeding the group’s stated responsibilities.
Question 10
Topic: Compute
An App Service app on a supported multitenant plan must connect to two Azure virtual machines by their private IP addresses. The app must remain publicly reachable for inbound requests. The VNet is in the app’s region, and an unused subnet can be dedicated to App Service.
Which configuration should the administrator use?
Options:
A. Use a
Microsoft.Webservice endpoint from the virtual machines’ subnet.B. Use a virtual network access restriction for the virtual machines’ subnet.
C. Use an App Service private endpoint through a dedicated endpoint subnet.
D. Use regional VNet integration with a subnet delegated to
Microsoft.Web/serverFarms.
Best answer: D
Explanation: Regional VNet integration provides outbound connectivity from a multitenant App Service app to resources in a virtual network. It uses a dedicated subnet delegated to Microsoft.Web/serverFarms. This integration does not replace the app’s inbound endpoint, so the app can remain publicly reachable.
A private endpoint gives clients private inbound access to the app. Service endpoints and App Service access restrictions also affect traffic directed toward the app rather than connections initiated by it. The deciding factor is the required traffic direction: from the app to the virtual machines.
- A private endpoint provides a private inbound address for the app; it does not route app-originated traffic to the virtual machines.
- A
Microsoft.Webservice endpoint supports subnet-based access to App Service, not outbound VNet connectivity from the app. - A virtual network access restriction filters inbound requests to the app and does not establish an outbound route.
Question 11
Topic: Virtual Networking
An administrator creates an Azure subnet with defaultOutboundAccess set to false and deploys a VM to it.
- The VM has no public IP address.
- An NSG permits outbound TCP 443.
- A route for
0.0.0.0/0uses next hopInternet. - No NAT gateway, load balancer outbound rule, firewall, or proxy is configured.
Which explanation of the VM’s expected HTTPS connectivity to an external vendor server on the public internet outside Azure is supported?
Options:
A. HTTPS succeeds; the NSG rule supplies outbound source NAT.
B. HTTPS succeeds; private-subnet mode restricts inbound traffic only.
C. HTTPS succeeds; the Internet route supplies outbound source NAT.
D. HTTPS fails; no configured component supplies outbound source NAT.
Best answer: D
Explanation: Setting defaultOutboundAccess to false removes Azure’s default outbound connectivity for the subnet. The route selects the Internet next hop, and the NSG permits TCP 443, but neither translates the VM’s private source address. Reaching the specified external vendor server requires an explicit egress method that provides source NAT, such as a NAT gateway or an applicable load balancer outbound rule. Because none is configured, this HTTPS connection fails. Routing and security permissions alone do not provide outbound address translation.
- Internet route selects the next hop but does not provide source NAT.
- NSG allow rule permits matching traffic but performs no address translation.
- Inbound-only effect misstates the setting, which specifically disables default outbound access.
Question 12
Topic: Storage
A storage account supports lifecycle management and the Cool tier. In container telemetry, only block blobs under virtual directory audit/ must be moved to Cool after more than 30 days since modification and deleted after more than 365 days since modification.
For this interface, prefixMatch is case-sensitive, begins with the container name, and has no leading slash. Replace the placeholders in this policy definition:
{
"filters": {
"blobTypes": ["<blob-type>"],
"prefixMatch": ["<prefix>"]
},
"actions": {
"baseBlob": {
"tierToCool": {"<age-field>": 30},
"delete": {"<age-field>": 365}
}
}
}
Which replacements meet the requirements?
Options:
A. Use
blockBlob,telemetry/audit/, anddaysAfterModificationGreaterThan.B. Use
blockBlob,telemetry/, anddaysAfterModificationGreaterThan.C. Use
blockBlob,telemetry/audit/, anddaysAfterLastAccessTimeGreaterThan.D. Use
blockBlob,/telemetry/audit/, anddaysAfterModificationGreaterThan.
Best answer: A
Explanation: A lifecycle rule combines filters that select objects with actions and age conditions applied to those objects. blockBlob limits the rule to block blobs. Because the prefix begins with the container name and has no leading slash, telemetry/audit/ selects the required virtual directory. The trailing slash preserves the intended directory boundary.
Both actions must use daysAfterModificationGreaterThan: tierToCool evaluates the 30-day modification age, while delete evaluates the 365-day modification age. These conditions mean more than the stated number of elapsed days, not execution at an exact timestamp. A last-access condition would measure a different form of object age.
- Using
telemetry/includes block blobs outside the requiredaudit/virtual directory. - Using last-access age does not implement the stated time-since-modification requirement.
- Starting the prefix with
/does not match the interface’s container-relative prefix format.
Question 13
Topic: Compute
An administrator is deploying an Azure VM using a size that supports encryption at host. The security requirement is to encrypt at rest all disk data residing on the compute host, including temporary disks and OS/data disk caches. Customer-managed keys are not required.
Which configuration should the administrator select?
Options:
A. Enable Azure Disk Encryption within the guest operating system.
B. Enable encryption at host with platform-managed keys.
C. Associate the managed disks with a disk encryption set.
D. Use server-side encryption with platform-managed keys on the disks.
Best answer: B
Explanation: Encryption at host is designed to protect VM disk data that resides on the Azure compute host. It encrypts temporary disks and OS/data disk caches at rest, addressing the stated host-resident data requirement. Platform-managed keys can be used because customer-managed keys are not required.
Azure Disk Encryption operates within the guest through BitLocker or dm-crypt. Managed-disk server-side encryption protects data in the storage service, while a disk encryption set supplies an identity for customer-managed disk keys. Neither mechanism alone addresses all host-resident caches and temporary-disk data. The required protection boundary therefore determines the encryption choice.
- Disk encryption set supports customer-managed keys for managed disks but does not itself encrypt host caches or temporary disks.
- Azure Disk Encryption encrypts through the guest operating system rather than applying host-level encryption.
- Server-side encryption protects managed-disk data in Azure Storage but does not cover all data residing on the compute host.
Question 14
Topic: Compute
A company has the following App Service topology:
Scroll sideways if needed. Open full-size diagram in a new tab
Text description
In one West Europe resource group, ASP-Prod hosts OrdersApp and PayrollApp and changes from two to four instances. ASP-Test hosts PortalApp and remains at one instance.
An administrator manually scales ASP-Prod from two instances to four. Per-app scaling is disabled, and ASP-Test remains at one instance.
Which outcome correctly describes the available capacity and App Service plan compute charges?
Options:
A. OrdersApp alone uses four instances; only ASP-Prod’s compute charge increases.
B. All three apps share four instances; only ASP-Prod’s compute charge increases.
C. OrdersApp and PayrollApp share four instances; both plans’ compute charges increase.
D. OrdersApp and PayrollApp share four instances; only ASP-Prod’s compute charge increases.
Best answer: D
Explanation: App Service compute capacity and billing operate at the App Service plan level. With per-app scaling disabled, all applications hosted by a plan share its allocated instances. Because ASP-Prod hosts OrdersApp and PayrollApp, scaling that plan from two instances to four expands the shared capacity available to both applications.
PortalApp remains on ASP-Test and does not use ASP-Prod’s instances, even though both plans are in the same resource group and region. The additional instances increase ASP-Prod’s compute charge, while ASP-Test’s capacity and charge remain unchanged. Resource-group placement does not create a shared compute or billing boundary.
- App-only scaling incorrectly treats plan scale-out as specific to OrdersApp; PayrollApp uses the same plan instances.
- Both plans billed confuses resource-group containment with billing; ASP-Test’s instance count did not change.
- Resource-group sharing treats the resource group as the compute boundary; PortalApp is hosted by a separate plan.
Question 15
Topic: Virtual Networking
An Azure Standard Load Balancer marks VM1 unhealthy. VM1 belongs to the backend pool. All evidence was collected during the same five-minute interval after the latest deployment.
Probe: HTTP 10.20.1.4:8080/health
Backend health: Unhealthy for four probe intervals
IP flow verify, 168.63.129.16 -> 10.20.1.4:8080: Allow
Listener: 127.0.0.1:8080
curl http://127.0.0.1:8080/health: HTTP 200
curl http://10.20.1.4:8080/health: Connection refused
Which diagnosis is best supported?
Options:
A. The probe targets port 8080 while the application listens on port 8443.
B. The
/healthendpoint returns a non-success status to the HTTP probe.C. The application listener is bound only to loopback instead of the backend IP.
D. The backend NSG blocks probe traffic from the AzureLoadBalancer service tag.
Best answer: C
Explanation: An Azure Load Balancer health probe connects to the backend’s private IP and configured port, not to its loopback address. The listener output shows that the application is bound only to 127.0.0.1:8080. Consequently, the local loopback request succeeds, while a request to 10.20.1.4:8080 is refused before HTTP can return a status.
The IP flow verification also shows that the NSG permits traffic from the Azure health-probe source. Binding the application to 0.0.0.0:8080 or the VM’s private IP would make the listener reachable by the probe. A successful loopback test alone does not prove that a backend service is reachable through its NIC.
- NSG blocking conflicts with the allow result for the probe source, destination, protocol, and port.
- Unsuccessful health response conflicts with the observed HTTP 200 response from the configured path.
- Port mismatch conflicts with the listener evidence showing that the application uses port 8080, although only on loopback.
Question 16
Topic: Identities and Governance
Jordan has two Azure role assignments that apply to storage account sa1. No deny assignments apply.
Role assigned at resource group rg1:
{
"permissions": [{
"actions": ["Microsoft.Storage/storageAccounts/*"],
"notActions": ["Microsoft.Storage/storageAccounts/listKeys/action"],
"dataActions": ["Microsoft.Storage/storageAccounts/blobServices/containers/blobs/*"],
"notDataActions": ["Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete"]
}]
}
A second role assigned directly to sa1 explicitly grants the excluded listKeys/action Action and blob delete DataAction.
Which statement describes Jordan’s effective access to sa1?
Options:
A. Jordan cannot list account keys but can delete blobs in
sa1.B. Jordan can neither list account keys nor delete blobs in
sa1.C. Jordan can list account keys and delete blobs in
sa1.D. Jordan can list account keys but cannot delete blobs in
sa1.
Best answer: C
Explanation: Azure RBAC applies NotActions and NotDataActions within their own role definition, then combines permissions granted by all applicable role assignments. In the resource-group role, the Actions wildcard includes listKeys/action, but NotActions removes that management-plane operation. Similarly, the DataActions wildcard includes blob deletion, but NotDataActions removes that data-plane operation.
The role assigned directly to sa1 independently grants both excluded operations. Because its scope applies and no deny assignment exists, Jordan can perform both operations. NotActions and NotDataActions are permission subtractions, not global denials that override other roles.
- Keys remain excluded incorrectly treats NotActions as overriding the separate role’s management-plane grant.
- Deletion remains excluded incorrectly treats NotDataActions as overriding the separate role’s data-plane grant.
- Neither operation allowed treats both subtraction arrays as deny assignments rather than limits on one role.
Question 17
Topic: Storage
A VM uses its managed identity to upload a blob through a storage account’s public endpoint. The VM subnet has a Microsoft.Storage service endpoint and is on the account’s network allowlist. The identity’s only assignment is Contributor at the storage account scope.
Blob service logging was enabled 30 minutes before this test. The request produced:
Time: 10:14:22
Operation: PutBlob
Authentication: OAuth
Status: 403
Status text: AuthorizationPermissionMismatch
Which action should the administrator take?
Options:
A. Assign Storage Account Contributor at the storage account scope.
B. Add the VM subnet to the storage account network allowlist.
C. Assign Storage Blob Data Contributor at the container scope.
D. Acquire a new OAuth token for the Azure Storage audience.
Best answer: C
Explanation: Storage network rules determine whether a request can reach the service, authentication establishes the caller’s identity, and authorization determines permitted data operations. The same-time log shows that Azure Storage accepted OAuth authentication but rejected PutBlob with AuthorizationPermissionMismatch. The Contributor role grants management-plane permissions but does not grant blob data-plane access through Microsoft Entra authentication. Assigning Storage Blob Data Contributor at the container or a parent scope supplies the required data action.
A network rejection or invalid token would produce different evidence, so changing connectivity or token acquisition does not address the observed authorization failure.
- Adding the subnet is unnecessary because it is already allowed and the service recorded an authorization-specific failure.
- Storage Account Contributor provides storage management permissions, not OAuth-based blob data permissions.
- Requesting another token does not resolve missing RBAC data actions after OAuth authentication succeeded.
Question 18
Topic: Identities and Governance
Azure Advisor recommends resizing a continuously running Standard_D8s_v5 VM to Standard_D4s_v5 because CPU utilization is low. The workload requires at least 4 vCPUs and 28 GiB of memory.
Planning assumptions: 730 hours monthly, pay-as-you-go rates, and no commitment discounts.
| VM size | vCPUs | Memory | Hourly rate |
|---|---|---|---|
| D8s_v5 | 8 | 32 GiB | $0.40 |
| D4s_v5 | 4 | 16 GiB | $0.20 |
| E4s_v5 | 4 | 32 GiB | $0.28 |
| E8s_v5 | 8 | 64 GiB | $0.48 |
Which action best reduces cost while satisfying the workload requirements?
Options:
A. Resize to E4s_v5, saving $87.60 per month.
B. Retain D8s_v5, saving $0.00 per month.
C. Resize to D4s_v5, saving $146.00 per month.
D. Resize to E8s_v5, increasing cost by $58.40 per month.
Best answer: A
Explanation: Azure Advisor cost recommendations should be validated against workload requirements before implementation. Although D4s_v5 provides the required 4 vCPUs, its 16 GiB of memory is below the 28 GiB minimum. E4s_v5 provides 4 vCPUs and 32 GiB while supporting continuous operation.
The current monthly cost is $0.40 x 730 = $292.00. E4s_v5 costs $0.28 x 730 = $204.40, producing monthly savings of $87.60. Retaining D8s_v5 satisfies the requirements but misses a supported rightsizing opportunity.
- D4s_v5 resize calculates the savings correctly but fails the workload’s minimum memory requirement.
- Retaining D8s_v5 preserves sufficient capacity but overlooks a less expensive size that meets both requirements.
- E8s_v5 resize adds unnecessary capacity and increases monthly cost rather than reducing it.
Question 19
Topic: Virtual Networking
A VM has a public IP and NSGs associated with both its subnet and network interface. Routing is correctly configured. A client at 198.51.100.25 starts a new TCP 443 connection.
| NSG scope | Direction | Priority | Rule |
|---|---|---|---|
| Subnet | Inbound | 200 | Allow TCP 443 from Internet |
| Network interface | Inbound | 300 | Deny TCP 443 from Any |
The administrator must retain both NSGs and existing rules but may add one rule. Which change allows this client connection?
Options:
A. Add an inbound NIC allow for the client at priority 250.
B. Add an inbound subnet allow for the client at priority 150.
C. Add an outbound NIC allow for the client at priority 250.
D. Add an inbound NIC allow for the client at priority 350.
Best answer: A
Explanation: When NSGs are associated with both a subnet and a network interface, a new inbound flow must be allowed by both NSGs. The subnet NSG already permits TCP 443, but the network-interface NSG denies it. Adding a source-specific allow at priority 250 to the network-interface NSG causes that rule to be evaluated before the priority-300 deny because lower priority numbers are processed first.
NSG priorities are evaluated independently within each NSG; rules in separate NSGs do not compete by priority. Once the inbound connection is permitted, NSG statefulness allows its response traffic.
- A subnet rule cannot overcome the independent deny applied by the network-interface NSG.
- An outbound rule does not permit the initial inbound connection through the network-interface NSG.
- A priority-350 allow is not reached because the matching priority-300 deny is evaluated first.
Question 20
Topic: Identities and Governance
A policy assignment is intended to ensure every storage account has a diagnostic setting. acct-old existed before the assignment. Activity Log collection was active throughout the test.
Observed results:
09:40 Compliance scan: acct-old = NonCompliant
10:00 Create acct-new: Succeeded
10:08 Policy-triggered deployment for acct-new: Succeeded
10:09 Diagnostic setting on acct-new: Succeeded
11:00 acct-old: setting absent; no deployment recorded
Which interpretation and action are supported by this evidence?
Options:
A.
modifyis active; submit an update to the existing account.B.
denyis active; recreate the existing account under the assignment.C.
auditIfNotExistsis active; rerun compliance evaluation for the existing account.D.
deployIfNotExistsis active; start remediation for the existing account.
Best answer: D
Explanation: The policy-triggered deployment for the newly created account demonstrates the deployIfNotExists effect. This effect checks for a related configuration after a matching resource is created or updated and can deploy that configuration using the policy assignment’s managed identity. A compliance scan evaluates existing resources but does not automatically deploy missing configuration to them. Existing noncompliant resources require a remediation task.
The successful deployment for acct-new also shows that the assignment can perform the deployment. The absence of a deployment for acct-old is meaningful because Activity Log collection covered the entire test period.
auditIfNotExistsrecords noncompliance but would not produce the successful policy-triggered deployment shown for the new account.modifychanges supported resource properties during processing or remediation rather than creating the observed child-resource deployment.denywould reject a matching request instead of allowing creation and deploying the missing setting afterward.
Question 21
Topic: Storage
An organization stores operational files in an Azure storage account. The data must remain available if one availability zone in the primary region fails and must be recoverable after a complete primary-region outage. Read access to the secondary region before failover is not required.
Which redundancy configuration should an administrator select?
Options:
A. Geo-redundant storage (GRS)
B. Geo-zone-redundant storage (GZRS)
C. Zone-redundant storage (ZRS)
D. Locally redundant storage (LRS)
Best answer: B
Explanation: Geo-zone-redundant storage (GZRS) combines two protections required here. It synchronously replicates data across availability zones in the primary region, allowing continued availability during a zone failure. It also asynchronously replicates data to a secondary region for recovery from a regional outage. Because direct read access to the secondary copy before failover is unnecessary, read-access GZRS is not required.
The key distinction is that GRS provides geographic replication but does not distribute the primary-region copies across availability zones.
- LRS keeps copies within one physical location and does not provide zone or regional failure protection.
- ZRS protects against a primary-region zone failure but does not replicate data to another region.
- GRS provides a secondary-region copy, but its primary-region copies are locally redundant rather than zone-redundant.
Question 22
Topic: Monitoring and Recovery
VM1 is protected by Recovery Services vault RSV1. Application corruption began after a deployment at 02:00.
- 01:00 recovery point: last known-good state
- 03:00 recovery point: created after the corruption
The administrator must keep VM1 unchanged and provision a bootable copy in one restore operation. The target resource group and isolated subnet are in the same subscription and region.
Which restore configuration should the administrator use?
Options:
A. Use 03:00 with
Create new, targetingtest-rgand the isolated subnet.B. Use 01:00 with
Create new, targetingtest-rgand the isolated subnet.C. Use 01:00 with
Restore disks, targeting a storage account for later VM deployment.D. Use 01:00 with
Replace existing, retaining VM1’s current resource group and network.
Best answer: B
Explanation: A recovery point restores the VM state captured at that time, so the 01:00 point is required because it predates the corruption. The Create new restore configuration provisions a separate VM and allows the administrator to specify its name, resource group, virtual network, and subnet while leaving the protected source VM unchanged.
Replace existing restores disks to the original VM rather than creating an isolated copy. Restore disks recovers the disks and deployment artifacts but requires a separate VM deployment afterward. The required combination is therefore the last known-good recovery point and a new-VM restore.
- The 03:00 recovery point contains the post-deployment corrupted state.
Replace existingmodifies the protected VM instead of preserving it unchanged.Restore disksdoes not directly provision the required bootable VM in one restore operation.
Question 23
Topic: Identities and Governance
Sam has one Azure RBAC Reader role assignment scoped to MG-Apps. No other role assignments apply. The hierarchy is shown below.
Scroll sideways if needed. Open full-size diagram in a new tab
Text description
The tenant root contains MG-Corporate and MG-Sandbox. MG-Corporate contains Sub-Shared and MG-Apps. Sub-Shared contains RG-Network and vnet-hub. MG-Apps contains Sub-Prod with RG-Data and stprod, plus Sub-Test with RG-Test and vm-test. MG-Sandbox contains Sub-Lab with RG-Lab and vm-lab.
Which statements accurately describe the inherited scope? Select TWO.
Options:
A. Sam does not inherit Reader on
vm-testbecauseSub-Testis separate fromSub-Prod.B. Sam inherits Reader on
vnet-hubbecauseMG-Corporatecontains both branches.C. Sam does not inherit Reader on
vm-lab, which belongs toMG-Sandbox.D. Sam inherits Reader on
MG-Corporatebecause it contains the assignment scope.E. Sam inherits Reader on
stprodthroughSub-ProdandRG-Data.
Correct answers: C and E
Explanation: Azure RBAC role assignments apply at the assigned scope and flow downward to every descendant scope. The assignment at MG-Apps therefore applies to its child subscriptions, their resource groups, and their resources, including stprod and vm-test.
Inheritance does not flow upward to MG-Corporate or sideways into another branch through a common parent. Consequently, resources under Sub-Shared and MG-Sandbox are outside this assignment’s scope. Separate subscriptions still inherit the role when both are descendants of the assigned management group.
- The common parent does not extend the assignment sideways to
vnet-hubunderSub-Shared. - A role assigned at
MG-Appsdoes not propagate upward to its parent,MG-Corporate. Sub-Testis a separate subscription, but it remains a descendant ofMG-Apps.
Question 24
Topic: Storage
An administrator must configure asynchronous object replication for block blobs. Both GPv2 accounts and their containers are eligible for object replication. The required direction is shown below; all displayed account features are currently disabled.
Scroll sideways if needed. Open full-size diagram in a new tab
Text description
The orders container is inside the source account srcacct and replicates asynchronously to the orders-copy container inside destination account dstacct. Versioning and change feed are disabled on both accounts.
Which account-level feature configuration must the administrator apply before creating the replication policy?
Options:
A. Enable change feed on
srcacct; enable versioning and soft delete ondstacct.B. Enable versioning and soft delete on
srcacct; enable versioning ondstacct.C. Enable versioning on
srcacct; enable versioning and change feed ondstacct.D. Enable versioning and change feed on
srcacct; enable versioning ondstacct.
Best answer: D
Explanation: Azure Blob Storage object replication uses the source account’s change feed to identify block blob creations and updates that must be copied. Blob versioning is required on both the source and destination accounts. Therefore, srcacct needs change feed and versioning, while dstacct needs versioning. Blob soft delete provides recovery from deletion or overwrite but does not replace either prerequisite.
The replication direction determines which account must have change feed enabled.
- Enabling change feed on the destination tracks destination changes, not the source changes that initiate replication.
- Enabling source change feed without source versioning leaves a required source feature disabled.
- Enabling source soft delete instead of change feed does not provide the change records used by replication.
Question 25
Topic: Virtual Networking
An administrator has three Azure virtual networks. Each diagram line represents active reciprocal peering with virtual network access enabled. No gateways, network virtual appliances, user-defined routes, or blocking security rules exist.
Scroll sideways if needed. Open full-size diagram in a new tab
Text description
VNet A uses address space 10.10.0.0/16 and has reciprocal peering with VNet B. VNet B uses 10.20.0.0/16 and also has reciprocal peering with VNet C, which uses 10.30.0.0/16. No direct peering connects VNet A and VNet C.
Which statements correctly describe workload reachability? Select TWO.
Options:
A. A C workload can reach 10.10.4.4 by transiting VNet B.
B. An A workload can reach 10.30.6.4 by transiting VNet B.
C. An A workload cannot reach 10.30.6.4 by using only the shown peerings.
D. An A workload can reach 10.20.5.4 through the direct A-B peering.
E. A B workload cannot reach 10.10.4.4 because it lies outside B’s address space.
Correct answers: C and D
Explanation: Azure VNet peering provides direct connectivity between the address spaces of the two peered networks. Therefore, workloads in VNet A can reach VNet B, and workloads in VNet B can reach both A and C.
Peering is nontransitive. The A-B and B-C peerings do not create an A-C route through VNet B. Transit would require an additional routing mechanism, such as an appropriately configured network virtual appliance or gateway. A destination being outside the source VNet’s address space is normal for peered traffic; the direct peering supplies the route to that remote address space.
- A-to-C transit incorrectly treats VNet B as a router between its two peering relationships.
- C-to-A transit makes the same nontransitive-peering error in the opposite direction.
- Outside the local range does not prevent access when direct peering provides a route to the remote address space.
Questions 26-50
Question 26
Topic: Identities and Governance
An administrator with the Owner role deploys one Standard_D4s_v5 VM in West Europe. The subscription is Active, and the deployment fails during validation.
Evidence collected immediately after the failure:
Code: OperationNotAllowed
Target: vm-app-03
Message: Standard DSv5 Family vCPUs quota exceeded
Region: westeurope
Current usage: 20
Current limit: 20
Additional required: 4
The VM must remain in West Europe and use the same size family. Which action should the administrator take?
Options:
A. Assign Contributor at the subscription scope and retry the deployment.
B. Request reactivation of the subscription and retry the deployment.
C. Request a DSv5 family vCPU quota of at least 24.
D. Reserve regional capacity for four additional DSv5 family vCPUs.
Best answer: C
Explanation: Azure applies regional vCPU quotas at both total and VM-family levels. The evidence specifically identifies the West Europe Standard DSv5 family quota: all 20 allowed vCPUs are already used, and the deployment needs 4 more. The required family quota is therefore at least 24. A quota increase request addresses this subscription-level limit while preserving the required region and VM family.
A capacity reservation addresses availability of compute capacity, not the documented quota limit. Authorization and subscription-state changes are also unsupported by the evidence because the administrator is an Owner and the subscription is Active.
- Capacity reservation does not increase the subscription’s regional VM-family vCPU quota.
- Additional role assignment is unnecessary because Owner already provides deployment permissions at subscription scope.
- Subscription reactivation is inapplicable because the supplied status is Active.
Question 27
Topic: Compute
An administrator must map the apex name contoso.com to the App Service app web-prod.azurewebsites.net. App Service displays inbound IP address 20.50.10.8 and a custom domain verification ID. Existing MX records for contoso.com must remain.
Which DNS record set should the administrator create?
Options:
A. Create
CNAME www -> web-prod.azurewebsites.netandTXT asuid.www -> <verification-id>.B. Create
A @ -> 20.50.10.8andTXT asuid.www -> <verification-id>.C. Create
CNAME @ -> web-prod.azurewebsites.netandTXT asuid -> <verification-id>.D. Create
A @ -> 20.50.10.8andTXT asuid -> <verification-id>.
Best answer: D
Explanation: An App Service apex-domain mapping uses an A record that points the zone apex (@) to the app’s inbound IP address. A TXT record named asuid contains the app’s custom domain verification ID and proves ownership of the apex domain. Adding these records does not require removing existing MX records.
A conventional CNAME cannot be used at the zone apex because it would conflict with other required apex records. For a subdomain such as www.contoso.com, the corresponding records would instead use www and asuid.www. The verification record’s name must match the domain being mapped.
- An apex CNAME conflicts with other apex records, including the existing mail configuration.
- A TXT record at
asuid.wwwverifieswww.contoso.com, not the requested apex domain. - Records for
wwwwould map the subdomain rather thancontoso.comitself.
Question 28
Topic: Virtual Networking
A hub VNet uses address spaces 10.20.0.0/16 and 10.21.0.0/16. It connects to an on-premises network using 10.30.0.0/16.
A new spoke VNet will be peered with the hub and requires one /23 subnet and two /24 subnets. All connected address spaces and subnets must be nonoverlapping. Which address plan should the administrator use?
Options:
A.
10.21.128.0/17; subnets10.21.128.0/23,10.21.130.0/24, and10.21.131.0/24B.
10.22.0.0/16; subnets10.22.0.0/23,10.22.2.0/24, and10.22.3.0/24C.
10.30.128.0/17; subnets10.30.128.0/23,10.30.130.0/24, and10.30.131.0/24D.
10.22.0.0/16; subnets10.22.0.0/23,10.22.1.0/24, and10.22.2.0/24
Best answer: B
Explanation: Connected networks require unique address spaces so that routing can identify the correct destination. The 10.22.0.0/16 range does not overlap either hub prefix or the on-premises 10.30.0.0/16 range. Within that VNet, 10.22.0.0/23 covers addresses from 10.22.0.0 through 10.22.1.255. The two /24 subnets begin at 10.22.2.0 and 10.22.3.0, so neither intersects the /23 or each other.
A valid VNet prefix alone is insufficient; every subnet must also be contained within the VNet and remain distinct.
- The
10.21.128.0/17range is contained within the hub’s existing10.21.0.0/16address space. - The
10.30.128.0/17range overlaps the connected on-premises10.30.0.0/16network. - The
10.22.1.0/24subnet overlaps the second half of the10.22.0.0/23subnet.
Question 29
Topic: Compute
An Azure App Service app runs on a plan that supports deployment slots. An administrator must release a new build with these requirements:
- Validate it against a staging backend before it receives production traffic.
- Promote the exact tested content without deploying it again.
- Keep each slot’s
BACKEND_URLvalue attached to that slot.
Which actions should the administrator take? Select TWO.
Options:
A. Leave
BACKEND_URLswappable, perform the swap, and correct both values afterward.B. Create a staging slot, deploy the release there, and test its slot-specific hostname.
C. Configure
BACKEND_URLas a deployment slot setting, then swap after validation.D. Route 5% of production requests to staging and validate with live traffic.
E. After staging validation, deploy the same package separately to the production slot.
Correct answers: B and C
Explanation: A deployment slot provides an independent hostname where a release can be deployed and tested without changing production routing. After validation, swapping staging with production places the tested content behind the production hostname, avoiding a separate deployment.
Settings marked as deployment slot settings are sticky: their values remain associated with their respective slots during a swap. Marking BACKEND_URL this way preserves the production backend value in production and the staging backend value in staging. Traffic routing to staging would instead expose the unvalidated release to some production requests.
- Routing a production percentage to staging is a canary release and violates the requirement to validate before production traffic arrives.
- Deploying separately to production does not promote the exact slot deployment that was validated.
- Correcting backend values after a swap allows the settings to move and may expose the application to the wrong backend.
Question 30
Topic: Virtual Networking
A spoke VNet is peered with a hub VNet containing an NVA. IP forwarding is enabled on the NVA, and the peering permits forwarded traffic.
Settings record:
| Setting | Value |
|---|---|
| Source subnet | AppSubnet (10.1.2.0/24) |
| Target prefix | 172.20.0.0/16 |
| Required next hop | NVA |
| NVA private IP | 10.0.1.4 |
| Other destination paths | Remain unchanged |
| Current route-table association | None |
Which route-table configuration meets the requirement?
Options:
A. Add
172.20.0.0/16through virtual appliance10.0.1.4, then associate the table withAppSubnet.B. Add
172.20.0.0/16through the virtual network gateway, then associate the table withAppSubnet.C. Add
0.0.0.0/0through virtual appliance10.0.1.4, then associate the table withAppSubnet.D. Add
172.20.0.0/16through virtual appliance10.0.1.4, then associate the table withGatewaySubnet.
Best answer: A
Explanation: A user-defined route affects traffic from the subnet associated with its route table. To steer only traffic destined for 172.20.0.0/16, the route must use that exact prefix and specify Virtual appliance with the NVA’s private IP. Associating the table with AppSubnet makes the route effective for the required source.
A default route could change paths for other destinations. A virtual network gateway is a different next-hop type and does not identify the NVA. Associating the table with GatewaySubnet would not apply the route to traffic originating from AppSubnet.
- Default route:
0.0.0.0/0could redirect additional destinations, violating the requirement to preserve their existing paths. - Gateway next hop: A virtual network gateway does not direct packets to the specified NVA address.
- Wrong association: Associating the table with
GatewaySubnetdoes not apply its routes toAppSubnettraffic.
Question 31
Topic: Monitoring and Recovery
An Azure VM named app01 is replicated from East US to West US by Azure Site Recovery. An administrator must validate guest access and connectivity to a sanitized database while app01 remains online and replication continues. Test resources must not reach production.
Topology:
Scroll sideways if needed. Open full-size diagram in a new tab
Text description
The production VM app01 sends application traffic to prod-db and replicates through Azure Site Recovery. RecoveryVNet is peered with ProdVNet. TestVNet has no peering or routes to other virtual networks and contains the validation VM, Azure Bastion, and a sanitized test-db copy. Bastion reaches the test VM, which reaches test-db.
Which sequence should the administrator use?
Options:
A. Run Test failover to
TestVNet, validate through Bastion andtest-db, then run Cleanup test failover.B. Run Failover to
TestVNet, validate through Bastion andtest-db, then commit and reprotect.C. Run Test failover with no network, validate startup through Boot diagnostics, then run Cleanup test failover.
D. Run Test failover to
RecoveryVNet, validate through peering andprod-db, then run Cleanup test failover.
Best answer: A
Explanation: Azure Site Recovery test failover creates a recovery VM from a selected recovery point without stopping the source VM or ongoing replication. The selected network determines the test VM’s connectivity. TestVNet is isolated from production but provides both required validation paths: Bastion to the test VM and the test VM to the sanitized test-db copy. After validation, Cleanup test failover removes the temporary resources while normal protection continues.
An actual failover changes the recovery state, while a test VM without networking cannot validate guest access or application connectivity. The required pattern is test failover, isolated validation, and cleanup.
- Using
RecoveryVNetviolates isolation because its peering provides connectivity to the production network and database. - Running an actual failover enters the disaster-recovery workflow instead of preserving uninterrupted production replication.
- Selecting no network permits startup inspection but prevents Bastion access and connectivity testing against
test-db.
Question 32
Topic: Virtual Networking
An application on appvm accesses https://stdata.blob.core.windows.net. Public network access must remain disabled.
appvmuses Azure-provided DNS.- Routing and NSGs permit traffic to
10.20.1.4. - The application has the required blob data permissions.
- The storage firewall allows the App subnet.
- The private endpoint connection is approved.
Scroll sideways if needed. Open full-size diagram in a new tab
Text description
App VNet contains appvm using Azure-provided DNS and is peered with Endpoint VNet, which contains the approved private endpoint at 10.20.1.4. The private DNS zone is linked only to Endpoint VNet, maps stdata to the private endpoint, and the endpoint connects to the blob service.
What is the expected access result, and what should the administrator do?
Options:
A. The request fails after public resolution; link the private DNS zone to App VNet.
B. The request succeeds privately because peering extends the existing private DNS zone link.
C. The request succeeds publicly because the App subnet is allowed by the storage firewall.
D. The request fails because peering cannot reach private endpoints; deploy one in App VNet.
Best answer: A
Explanation: A private DNS zone link applies only to the linked virtual network; VNet peering does not extend that DNS relationship. Therefore, appvm does not use the zone’s record for 10.20.1.4 and instead resolves the storage hostname through public DNS. Because public network access is disabled, the storage service rejects that public path even though its firewall contains an App subnet rule.
The approved private endpoint is reachable across the peering because routing and NSGs permit it. Linking the private DNS zone to App VNet enables the storage hostname to resolve to the endpoint’s private IP. Storage firewall network rules do not govern traffic entering through an approved private endpoint.
- The subnet firewall rule cannot override disabled public network access, so it does not admit a publicly resolved request.
- Private endpoints can be reached across peered VNets when routing and security controls permit the traffic.
- VNet peering provides network connectivity but does not make a private DNS zone link transitive.
Question 33
Topic: Virtual Networking
An organization owns contoso.com, registered with a third-party registrar. An Azure public DNS zone for contoso.com displays four assigned Azure nameservers. The organization wants Azure DNS to host the entire zone and resolve app.contoso.com to the application’s fixed public IPv4 address.
Which configuration meets the requirement?
Options:
A. Keep the current delegation, add the Azure nameservers to the zone’s apex NS set, then create an
appA record.B. Delegate the domain to all four Azure nameservers, then create an
appA record in the registrar’s hosted DNS zone.C. Delegate the domain to all four Azure nameservers, then create an
appA record in the Azure zone.D. Delegate the domain to all four Azure nameservers, then create an
appCNAME record containing the public IPv4 address.
Best answer: C
Explanation: Creating an Azure public DNS zone does not automatically make Azure authoritative for the domain. The registrar must delegate contoso.com through the parent zone to all nameservers assigned to the Azure DNS zone. After delegation, records must be created in that Azure zone. Because the application has a fixed IPv4 address, an A record named app produces the required app.contoso.com mapping.
A CNAME instead targets another DNS name, not an IP address, and records left with the former DNS host are not authoritative after delegation changes.
- Adding Azure nameservers only inside the Azure zone does not update the parent-zone delegation controlled through the registrar.
- A CNAME record cannot contain an IPv4 address as its target; it must reference another DNS name.
- A record at the registrar’s DNS host is not authoritative after the domain is delegated to Azure DNS.
Question 34
Topic: Compute
An operator must deploy this Bicep file:
targetScope = 'subscription'
param deploymentLocation string
param resourceGroupName string
param vmName string
resource appRg 'Microsoft.Resources/resourceGroups@2022-09-01' = {
name: resourceGroupName
location: deploymentLocation
}
module compute './compute.bicep' = {
name: 'compute'
scope: appRg
params: {
location: deploymentLocation
vmName: vmName
}
}
The current command is:
az deployment group create \
--resource-group rg-tools \
--template-file main.bicep \
--parameters deploymentLocation=eastus resourceGroupName=rg-app
The operator’s custom role contains all required deployment and resource actions but is assigned only at rg-tools. The intended rg-app group does not exist. Subscription deployments require az deployment sub create, a deployment metadata location, and values for parameters without defaults.
Which change will successfully deploy the file?
Options:
A. Precreate
rg-appand assign the role there; useaz deployment sub createwith--location eastusand all three parameters.B. Assign the role at subscription scope; use
az deployment sub createwith--location eastusand all three parameters.C. Assign the role at subscription scope; use
az deployment group createforrg-toolsand supply all three parameters.D. Assign the role at subscription scope; use
az deployment sub createwith--location eastusand the two existing parameters.
Best answer: B
Explanation: The file declares targetScope = 'subscription', so it must be submitted through a subscription-scope deployment command. The command also needs a location for the deployment record and explicit values for all three parameters because none has a default. Authorization must cover the subscription deployment and the resources created beneath it. Assigning the custom role at subscription scope allows its permissions to inherit into rg-app and the module’s resources.
The module’s scope: appRg expression also creates the necessary dependency on the resource group. An explicit dependsOn modification is unnecessary. A resource-group deployment command cannot deploy a subscription-scoped file.
- Resource-group assignment does not authorize creation of the subscription-scope deployment, even if the target resource group is created first.
- Group deployment command is incompatible with the file’s declared subscription target scope.
- Missing VM parameter causes parameter validation to fail because
vmNamehas no default value.
Question 35
Topic: Storage
An administrator must create an Azure blob container for public product images. Anonymous users must be able to read a blob when given its URL, but they must not be able to list the container’s blobs.
Which configuration meets the requirement?
Options:
A. Enable account-level anonymous access; set container access to Private
B. Enable account-level anonymous access; set container access to Blob
C. Disable account-level anonymous access; set container access to Blob
D. Enable account-level anonymous access; set container access to Container
Best answer: B
Explanation: Azure Storage controls anonymous blob access at both the storage-account and container levels. The account’s anonymous-access setting must permit the feature. The container must then use the Blob access level, which allows anonymous clients to read individual blobs by URL but does not allow them to enumerate the container. The Container access level also permits anonymous listing, while Private prevents all anonymous access.
Both levels must therefore be configured consistently; enabling anonymous access at the account alone does not make a container public.
- Container access permits anonymous users to list blobs, exceeding the stated requirement.
- Account access disabled overrides the container setting and blocks anonymous blob access.
- Private container requires authorization for both blob reads and container listing.
Question 36
Topic: Monitoring and Recovery
A maintenance window is scheduled for several Azure VMs from 22:00 to 23:00. Their alerts must continue to be evaluated and recorded, but notifications must be suppressed during that hour. The shared action group must continue notifying for other resources.
Which configuration should an administrator use?
Options:
A. Create a scheduled suppression rule scoped to the entire subscription
B. Apply an action group with no receivers to the affected VMs
C. Disable the affected VMs’ alert rules for the maintenance window
D. Create a scheduled suppression rule scoped to the affected VMs
Best answer: D
Explanation: An Azure Monitor alert processing rule changes how actions are handled after an alert condition is evaluated. A suppression rule can target specific resources and operate only during a configured schedule. Therefore, the alerts can still fire and remain available for review while their notifications are suppressed during maintenance. Scoping the rule to the affected VMs prevents interruption of notifications for other resources using the shared action group.
Disabling alert rules stops their evaluation, while applying another action group does not replace or suppress existing action groups.
- Subscription-wide suppression would also suppress notifications for unrelated resources during the maintenance window.
- Disabling the alert rules would prevent alert evaluation rather than suppress only their actions.
- Applying an empty action group would not prevent existing action groups from running.
Question 37
Topic: Identities and Governance
A Microsoft Entra group containing standard member users is enabled for self-service password reset (SSPR). Microsoft Authenticator, SMS, and security questions are available. Security questions require users to register five questions and answer three during a reset.
The organization requires users with insufficient reset information to receive a registration prompt at sign-in. Each password reset must require two authentication methods.
Which settings should an administrator configure? Select TWO.
Options:
A. Set SSPR sign-in registration requirement to Yes.
B. Set required security-question answers to two.
C. Set the SSPR reset-method requirement to two.
D. Set security questions to Enabled in authentication methods policy.
E. Set the Authenticator registration campaign to Enabled.
Correct answers: A and C
Explanation: SSPR registration and reset verification are controlled by separate SSPR settings. Enabling the sign-in registration requirement prompts eligible users who lack sufficient reset information. Setting the number of methods required to reset to two enforces two authentication methods during each reset.
Authentication-method availability does not require every available method to be registered. Security questions also remain an SSPR configuration: answering the configured set of questions counts as one authentication method, not several methods. An Authenticator registration campaign encourages Authenticator enrollment but does not replace the SSPR registration requirement.
- An Authenticator registration campaign targets Authenticator enrollment rather than overall SSPR registration sufficiency.
- Security questions are managed in SSPR settings, not in the authentication methods policy.
- Changing the number of security-question answers adjusts one method’s challenge, not the number of reset methods.
Question 38
Topic: Compute
An Azure Container App currently uses single revision mode. Administrators want to deploy a new image and send 10% of requests from the app’s default FQDN to the new revision while 90% remain on the healthy current revision. The current revision must remain available for a rapid rollback without another deployment. Which configuration should the administrator use?
Options:
A. Use multiple revision mode, size the new revision to 10% of total replicas, and scale it to zero if needed.
B. Use multiple revision mode, label the new revision as canary for 10% of requests, and relabel the old revision if needed.
C. Use multiple revision mode, keep both revisions active, assign 90/10 traffic weights, and restore the old revision to 100% if needed.
D. Use single revision mode, keep both revisions active, assign 90/10 traffic weights, and reactivate the old revision if needed.
Best answer: C
Explanation: Azure Container Apps must use multiple revision mode to split ingress traffic between active revisions. Before deploying the changed image, switch to multiple revision mode so the current revision remains active. After the new revision is ready, assign 10% of default-FQDN traffic to it and retain 90% on the current revision. If problems occur, assign 100% back to the old revision without redeploying. Replica settings control capacity and scaling rather than traffic percentages, while revision labels provide revision-specific URLs rather than weighted routing for users of the default FQDN.
- Single revision mode does not support keeping two revisions active for weighted ingress traffic.
- Replica counts affect capacity and autoscaling, not the percentage of requests routed to a revision.
- Revision labels provide dedicated URLs; moving a label does not split traffic sent to the default FQDN.
Question 39
Topic: Storage
An Azure storage account has file-share soft delete enabled with a 14-day retention period. The contracts share was deleted 6 days ago. An administrator then created an empty share in the same account named contracts. No backup exists.
What should the administrator do to recover the original data?
Options:
A. Delete the current
contracts, then wait until day 15 to undelete the earlier version.B. Delete the current
contracts, then undelete the earliercontractsversion.C. Keep the current
contracts, then undelete the earlier version ascontracts-restored.D. Keep the current
contracts, then undelete the earlier version into another account.
Best answer: B
Explanation: A soft-deleted Azure file share can be recovered during its configured retention period. Recovery restores the share in its original storage account with its original name, including associated snapshots. Because an active share already uses contracts, that naming conflict must be removed first. After deleting the empty replacement, the administrator can select and undelete the earlier deleted version.
Once the 14-day retention period expires, the original share is permanently deleted and cannot be recovered through soft delete.
- Restoring as
contracts-restoredis unsupported because soft-delete recovery does not assign a different share name. - Restoring into another account is unsupported because undelete operates within the original storage account.
- Waiting until day 15 allows the retention period to expire, permanently removing the recoverable version.
Question 40
Topic: Identities and Governance
A cloud-only Microsoft Entra member account was disabled before an employee’s leave and accidentally deleted 12 days ago. The UPN has not been reused. An application requires the user’s original object ID, and the returning employee must be able to sign in.
What should an administrator do?
Options:
A. Restore the deleted user, then set Account enabled to Yes.
B. Restore the deleted user, then reset the user’s password.
C. Create a member with the same UPN, then enable the account.
D. Restore the deleted user, then reassign the user’s license.
Best answer: A
Explanation: Microsoft Entra ID retains a deleted user for 30 days, during which an administrator can restore the same directory object and preserve its object ID. Because this user was disabled before deletion, restoration alone does not meet the sign-in requirement. The administrator must also change the Account enabled property to Yes.
Creating another account with the same UPN produces a different object ID. Password resets and license assignments address credentials and service access, respectively, but neither enables a disabled account.
- Password reset changes the credential but does not enable a disabled user account.
- Same UPN does not preserve identity because a newly created user receives a new object ID.
- License reassignment grants service entitlements but does not change the account’s enabled state.
Question 41
Topic: Compute
An Azure Container Instances group fails before its container starts. The group uses contoso.azurecr.io/apps/api:v3 and a user-assigned managed identity referenced for registry authentication.
Configuration:
- Registry mode: RBAC Registry + ABAC Repository Permissions
- Identity assignment:
AcrPullat registry scope, added one day earlier - Registry diagnostics: enabled 30 minutes before deployment
Evidence:
11:55 Authorized client confirms apps/api:v3 exists
12:04 ACI event: Image pull failed: 401 Unauthorized
12:04 Registry log: manifest request reached endpoint; status 401
12:06 VNet test: registry DNS and TCP 443 succeeded
Which change should the administrator make?
Options:
A. Add a NAT gateway to the container group’s delegated subnet.
B. Assign the built-in Reader role at registry scope to the identity.
C. Push
v3again aslatestand update the image reference.D. Assign Container Registry Repository Reader for
apps/apito the identity.
Best answer: D
Explanation: The registry uses RBAC Registry + ABAC Repository Permissions mode. In this mode, repository roles authorize image operations, while legacy roles such as AcrPull are not honored. The identity therefore reaches the registry but cannot read the requested repository, producing the recorded 401 response. Assigning Container Registry Repository Reader with access to apps/api provides the required pull permission.
The successful request arrival and TCP test rule out a basic egress failure, while the authorized manifest check confirms that the requested image exists.
- Built-in Reader can permit pulls in RBAC Registry Permissions mode, but it does not provide repository data access in the configured ABAC mode.
- NAT gateway does not address the authorization failure because the manifest request already reached the registry endpoint.
- Retagging the image does not resolve the 401 response, and the requested
v3manifest was confirmed to exist.
Question 42
Topic: Monitoring and Recovery
An administrator must configure backup for two Azure workloads:
- An Azure virtual machine using Azure VM Backup
- Blob data using vaulted Azure Blob Backup
The administrator can deploy multiple vaults. Which vault configuration is supported?
Options:
A. Assign the VM to a Recovery Services vault and the blobs to a Backup vault.
B. Assign both the VM and the blobs to a Recovery Services vault.
C. Assign both the VM and the blobs to a Backup vault.
D. Assign the VM to a Backup vault and the blobs to a Recovery Services vault.
Best answer: A
Explanation: Azure backup vault selection depends on the workload and backup capability. Azure VM Backup is managed through a Recovery Services vault. Vaulted Azure Blob Backup is managed through a Backup vault. Because the requirements include both capabilities, the administrator must deploy the corresponding vault type for each workload. A vault’s resource type identifies supported backup management capabilities, but it does not by itself establish where every protected byte is stored.
- Reversing the assignments fails because neither vault type supports the workload assigned to it.
- Using only a Recovery Services vault fails because it does not support vaulted Azure Blob Backup.
- Using only a Backup vault fails because it does not support Azure VM Backup.
Question 43
Topic: Identities and Governance
A subscription-level Azure Policy assignment requires a costCenter tag. An approved exception allows one resource group to remain untagged because no alternative control exists. Governance requires owner and reason metadata, automatic expiration, and an Exempt compliance state. The assignment must remain enforced elsewhere.
Which configuration meets these requirements?
Options:
A. Create a resource-group policy exemption categorized as Waiver, with metadata and
expiresOn; report resources as Exempt.B. Create a resource-group Waiver exemption, with the end date only in metadata; report resources as Exempt.
C. Add the resource group to the assignment’s
notScopes, with exception details in metadata; omit resources from evaluation.D. Create a resource-group policy exemption categorized as Mitigated, with metadata and
expiresOn; report resources as Exempt.
Best answer: A
Explanation: An Azure Policy exemption is appropriate when a documented exception must remain visible in compliance reporting. The exemption references the assignment, can include ownership and justification metadata, and uses expiresOn to stop honoring the exception after the approved period. The Waiver category applies because noncompliance is being accepted rather than addressed through another method.
An assignment exclusion using notScopes removes the resource group from evaluation, so it does not provide the requested Exempt state. The Mitigated category instead indicates that the policy’s intent is satisfied through an alternative method. A date stored only in metadata documents the deadline but does not implement automatic expiration.
- Assignment exclusion removes the resource group from policy evaluation instead of displaying its resources as Exempt.
- Mitigated exemption misclassifies the exception because no alternative method satisfies the policy’s intent.
- Metadata-only date records the deadline but does not make the exemption expire automatically.
Question 44
Topic: Compute
A web VM must use the available private address 10.20.1.10. Internet clients must reach it only through an existing Standard Load Balancer whose frontend, rule, probe, NSG rules, and webPool are ready.
The Bicep module uses null for no public IP association and [] for no backend pool membership.
param accessMode string
param fixedIp string = ''
var useFixedIp = !empty(fixedIp)
resource nic 'Microsoft.Network/networkInterfaces@2024-05-01' = {
name: 'web-nic'
location: resourceGroup().location
properties: {
ipConfigurations: [{
name: 'ipconfig1'
properties: {
subnet: { id: subnet.id }
privateIPAllocationMethod: useFixedIp ? 'Static' : 'Dynamic'
privateIPAddress: useFixedIp ? fixedIp : null
publicIPAddress: accessMode == 'direct' ? { id: vmPip.id } : null
loadBalancerBackendAddressPools: accessMode == 'balanced' ? [{ id: webPool.id }] : []
}
}]
}
}
Which parameter values meet the requirements?
Options:
A.
accessMode = 'direct';fixedIp = '10.20.1.10'B.
accessMode = 'balanced';fixedIp = '10.20.1.10'C.
accessMode = 'balanced';fixedIp = ''D.
accessMode = 'isolated';fixedIp = '10.20.1.10'
Best answer: B
Explanation: A nonempty fixedIp makes useFixedIp true, so the NIC receives a static private address. The balanced access mode omits publicIPAddress while adding the IP configuration to the load balancer’s webPool. The existing load-balancing rule and frontend can therefore provide the required Internet access without attaching a public IP directly to the VM’s NIC.
The direct mode attaches the VM public IP, while isolated creates neither public nor load-balanced access. An empty fixedIp selects dynamic private addressing.
- Direct mode attaches
vmPipand does not enroll the NIC inwebPool, bypassing the required load-balanced path. - Empty fixed address joins
webPoolbut selects dynamic allocation, so10.20.1.10is not retained. - Isolated mode assigns the static address but provides no load balancer backend membership or public ingress path.
Question 45
Topic: Compute
An administrator deploys the resources shown below using a single Bicep file. Arrows show all deployment dependencies and point from each prerequisite to the resource that depends on it.
Scroll sideways if needed. Open full-size diagram in a new tab
Text description
The virtual network and network security group are prerequisites for the subnet. The subnet and public IP are prerequisites for the network interface. The network interface is a prerequisite for the virtual machine.
During deployment:
- The virtual network and network security group have deployed successfully.
- The public IP is still deploying.
- The subnet, network interface, and virtual machine have not started deploying.
Which statement correctly describes what Azure Resource Manager can deploy next?
Options:
A. The network interface can start while the public IP continues deploying.
B. The subnet must wait for the public IP to finish before it can start.
C. The subnet can start while the public IP continues deploying.
D. The virtual machine can start while the public IP continues deploying.
Best answer: C
Explanation: Azure Resource Manager starts a resource when its deployment prerequisites have completed. In Bicep, resource references can create implicit dependencies, and dependsOn declares explicit dependencies. Both kinds constrain deployment order.
The subnet can start because its virtual network and network security group are ready. The public IP is on an independent branch and can continue deploying at the same time. The network interface must wait for both the subnet and the public IP. The virtual machine must then wait for the network interface. Independent branches can progress in parallel; an unfinished resource does not block resources that do not depend on it.
- Starting the network interface is premature: both its subnet and public IP prerequisites are unfinished.
- Starting the virtual machine is premature: its network interface prerequisite has not deployed.
- Waiting for the public IP before starting the subnet adds a dependency that the deployment does not contain.
Question 46
Topic: Monitoring and Recovery
An Azure VM cannot connect to an internal application at 10.20.4.15 on TCP port 443. An administrator needs an on-demand test that reports whether the destination is reachable and identifies latency or a failing hop along the path. Which Azure Network Watcher diagnostic tool should the administrator use?
Options:
A. Run Packet capture on the source VM.
B. Run Connection troubleshoot from the source VM.
C. Run Next hop for the source VM.
D. Run IP flow verify for the source VM.
Best answer: B
Explanation: Connection troubleshoot tests point-in-time connectivity from a supported Azure source to a specified destination and port. It reports whether the connection succeeds and can identify latency, hops, and detected path issues. This directly matches the need to diagnose end-to-end connectivity.
IP flow verify evaluates whether an NSG permits or denies a specific flow. Next hop identifies the route selected for a destination. Packet capture records network traffic for detailed protocol analysis. Those tools can investigate parts of a connectivity problem, but they do not directly provide the requested point-in-time path result.
- IP flow verify evaluates the applicable NSG decision rather than end-to-end reachability and path latency.
- Next hop reports the selected routing next hop but does not test whether the connection succeeds.
- Packet capture records packets for analysis rather than directly reporting connectivity status and failing hops.
Question 47
Topic: Virtual Networking
An organization selects the dedicated Azure Bastion deployment option. Administrators must use native SSH clients, with the lowest paid SKU that supports this requirement. The 10.20.4.0/26 range is reserved and contains no resources.
| Field | Proposed value |
|---|---|
| SKU | Basic |
| Subnet | AzureBastionSubnet, 10.20.4.0/27 |
| Public IP | Standard, Static |
| Native client support | Enabled |
Which focused configuration change makes the deployment valid?
Options:
A. Configure
/26with Basic and retain the Standard static public IP.B. Configure
/26with Standard and use a Standard dynamic public IP.C. Configure
/27with Standard and retain the Standard static public IP.D. Configure
/26with Standard and retain the Standard static public IP.
Best answer: D
Explanation: A dedicated Azure Bastion deployment requires a subnet named AzureBastionSubnet with a prefix of /26 or larger for a new deployment, plus a Standard static public IP. Native client connectivity requires the Standard SKU or higher and must be enabled. The proposed record already has the correct subnet name, public IP properties, and native client setting, but Basic does not support native clients and /27 is too small. Using the reserved /26 range and Standard SKU resolves both mismatches while selecting the lowest qualifying SKU.
The Developer deployment option has different subnet and public IP requirements, so those dedicated-deployment rules should not be applied to it.
- Retaining Basic leaves native SSH client connectivity unsupported even after enlarging the subnet.
- Retaining
/27leaves the dedicated Bastion subnet smaller than the required/26minimum. - Changing to dynamic allocation conflicts with the requirement for a Standard static public IP.
Question 48
Topic: Identities and Governance
An Azure subscription has a monthly budget of $10,000 with these alert conditions:
- Actual cost exceeds 80%
- Forecasted cost exceeds 100%
The current actual cost is $7,500, and the forecasted monthly cost is $10,800. No automation is configured for the budget.
Which outcome should the administrator expect?
Options:
A. Only the forecasted-cost condition is met; resources are stopped.
B. Only the actual-cost condition is met; resources continue running.
C. Only the forecasted-cost condition is met; resources continue running.
D. Both budget alert conditions are met; resources continue running.
Best answer: C
Explanation: Budget conditions evaluate actual and forecasted spending independently. The actual cost is $7,500 divided by $10,000, or 75%, which is below the 80% actual-cost threshold. The forecasted cost is $10,800 divided by $10,000, or 108%, which exceeds the 100% forecast threshold. Therefore, the forecasted-cost condition is met, but the actual-cost condition is not.
Azure budgets provide notifications based on configured thresholds. They do not inherently cap spending, stop resources, or prevent additional deployment. Those enforcement actions require separately configured automation.
- Treating both conditions as met incorrectly counts the 108% forecast toward actual spending, which remains at 75%.
- Treating only the actual condition as met reverses the two percentage comparisons.
- Expecting resources to stop attributes enforcement to the budget even though no automation is configured.
Question 49
Topic: Identities and Governance
A company needs a group for its Research department. The group must provide a shared mailbox, shared calendar, and SharePoint team site. Users must be added or removed automatically when their Microsoft Entra department attribute changes. The tenant has the required licenses for dynamic membership.
Which group configuration should an administrator create?
Options:
A. Security group with dynamic user membership
B. Security group with assigned membership
C. Microsoft 365 group with dynamic user membership
D. Microsoft 365 group with assigned membership
Best answer: C
Explanation: Microsoft 365 groups provide collaboration resources such as a shared mailbox, calendar, and SharePoint team site. Dynamic user membership uses a rule based on user attributes, so membership can be reevaluated automatically when the department value changes. An assigned membership model would require administrators or group owners to maintain membership manually.
A dynamic security group can automate access-control membership, but it does not provide the required Microsoft 365 collaboration resources.
- Assigned Microsoft 365 membership provides the collaboration resources but does not automatically follow department attribute changes.
- Dynamic security membership automates membership but does not create the required mailbox, calendar, and SharePoint site.
- Assigned security membership provides neither automatic attribute-based membership nor the requested collaboration resources.
Question 50
Topic: Identities and Governance
A resource group has a CanNotDelete lock. A storage operator has Contributor on the resource group and Storage Blob Data Contributor on a storage account in that group. The operator can modify the account and delete blobs but cannot delete the account.
A governance administrator changes the resource group’s lock to ReadOnly. All role assignments remain unchanged. Which result should the operator expect?
Options:
A. Cannot delete blobs; cannot modify or delete the storage account
B. Delete blobs and modify or delete the storage account
C. Delete blobs and modify the storage account; cannot delete the account
D. Delete blobs; cannot modify or delete the storage account
Best answer: D
Explanation: A resource lock applied to a resource group is inherited by resources within that group. Changing the lock from CanNotDelete to ReadOnly expands management-plane protection: Azure Resource Manager operations cannot modify or delete the storage account.
Resource locks do not independently change data-plane authorization. Blob deletion is a data operation authorized by Storage Blob Data Contributor, so the operator retains that capability. The key distinction is between management-plane protection from the inherited lock and data-plane access granted through Azure RBAC.
- Blocking blob deletion incorrectly treats a resource lock as a data-plane access control.
- Allowing account modification applies CanNotDelete behavior instead of the changed ReadOnly behavior.
- Allowing account deletion ignores that the resource-group lock is inherited by the storage account.
Review your attempt
The questions are mixed across domains. Use each question’s topic label to record your result, including questions you answered correctly by guessing.
| Topic label | Correct | Missed or guessed question numbers |
|---|---|---|
| Identities and Governance | ___ / 12 | ___ |
| Storage | ___ / 10 | ___ |
| Compute | ___ / 12 | ___ |
| Virtual Networking | ___ / 9 | ___ |
| Monitoring and Recovery | ___ / 7 | ___ |
Your raw total is a practice result. It does not convert to Microsoft’s scaled exam score or predict a pass. Repeating these same questions immediately can measure answer memory more than understanding.
| What caused the miss? | Next step |
|---|---|
| An unfamiliar service, role, or setting | Compare it with the closest alternative in the cheat sheet . |
| A missed arrow, scope, rule priority, or traffic direction | Work through the scenario guide and explain the deciding evidence. |
| A command or deployment assumption | Review the relevant Microsoft documentation and practise the operation in a safe lab. |
| Gaps across several domains | Use the study plan to choose focused sessions before another mixed attempt. |
Report a question issue
Email a question report with the question number, the issue, and a supporting Microsoft reference if available. You can also write to support@masteryexamprep.com . For account or paid-access issues, use support .
Continue in the web app
Use IT Mastery for interactive AZ-104 practice with mixed sets, timed mocks, topic drills, explanations, and progress tracking.