getcertified4sure.com

AZ-100 Exam

Microsoft AZ-100 Braindumps 2021




Master the AZ-100 Exam Questions content and be ready for exam day success quickly with this AZ-100 Braindumps. We guarantee it!We make it a reality and give you real AZ-100 Braindumps in our Microsoft AZ-100 braindumps. Latest 100% VALID AZ-100 Free Practice Questions at below page. You can use our Microsoft AZ-100 braindumps and pass your exam.

Online Microsoft AZ-100 free dumps demo Below:

NEW QUESTION 1
You plan to back up an Azure virtual machine named VM1.
You discover that the Backup Pre-Check status displays a status of Warning. What is a possible cause of the Warning status?

  • A. VM1 does not have the latest version of WaAppAgent.exe installed.
  • B. VM1 has an unmanaged disk.
  • C. VM1 is stopped.
  • D. A Recovery Services vault is unavailable.

Answer: A

Explanation: The Warning state indicates one or more issues in VM’s configuration that might lead to backup failures and provides recommended steps to ensure successful backups. Not having the latest VM Agent installed, for example, can cause backups to fail intermittently and falls in this class of issues.
References:
https://azure.microsoft.com/en-us/blog/azure-vm-backup-pre-checks/

NEW QUESTION 2
You have an Azure subscription that contains the resources in the following table.
AZ-100 dumps exhibit
Store1 contains a file share named Data. Data contains 5,000 files.
You need to synchronize the files in Data to an on-premises server named Server1.
Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • A. Download an automation script.
  • B. Create a container instance.
  • C. Create a sync group.
  • D. Register Server1.
  • E. Install the Azure File Sync agent on Server1.

Answer: CDE

Explanation: Step 1 (E): Install the Azure File Sync agent on Server1
The Azure File Sync agent is a downloadable package that enables Windows Server to be synced with an Azure file share
Step 2 (D): Register Server1.
Register Windows Server with Storage Sync Service
Registering your Windows Server with a Storage Sync Service establishes a trust relationship between your server (or cluster) and the Storage Sync Service.
Step 3 (C): Create a sync group and a cloud endpoint.
A sync group defines the sync topology for a set of files. Endpoints within a sync group are kept in sync with each other. A sync group must contain one cloud endpoint, which represents an Azure file share and one or more server endpoints. A server endpoint represents a path on registered server.
References: https://docs.microsoft.com/en-us/azure/storage/files/storage-sync-files-deployment-guide

NEW QUESTION 3
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription named Subscription1. Subscription1 contains a resource group named RG1. RG1 contains resources that were deployed by using templates.
You need to view the date and time when the resources were created in RG1. Solution: From the RG1 blade, you click Automation script.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

NEW QUESTION 4
You need to recommend an identify solution that meets the technical requirements. What should you recommend?

  • A. federated single-on (SSO) and Active Directory Federation Services (AD FS)
  • B. password hash synchronization and single sign-on (SSO)
  • C. cloud-only user accounts
  • D. Pass-through Authentication and single sign-on (SSO)

Answer: A

Explanation: Active Directory Federation Services is a feature and web service in the Windows Server Operating System that allows sharing of identity information outside a company’s network.
Scenario: Technical Requirements include:
Prevent user passwords or hashes of passwords from being stored in Azure. References: https://www.sherweb.com/blog/active-directory-federation-services/

Topic 3, Mix Questions

NEW QUESTION 5
Click to expand each objective. To connect to the Azure portal, type https://portal.azure.com in the browser address bar.
AZ-100 dumps exhibit
AZ-100 dumps exhibit
AZ-100 dumps exhibit
AZ-100 dumps exhibit
AZ-100 dumps exhibit
AZ-100 dumps exhibit
When you are finished performing all the tasks, click the ‘Next’ button.
Note that you cannot return to the lab once you click the ‘Next’ button. Scoring occur in the background while you complete the rest of the exam.
Overview
The following section of the exam is a lab. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design. Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn’t matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to
ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
To start the lab
You may start the lab by clicking the Next button.
You plan to deploy several Azure virtual machines and to connect them to a virtual network named VNET1007.
You need to ensure that future virtual machines in VNET1007 can register their name in an internal DNS zone named corp7523690.com. The zone must NOT be hosted on a virtual machine.
What should you do from Azure Cloud Shell?
To complete this task, start Azure Cloud Shell and select PowerShell(Linux). Click Show Advanced Settings, and then enter corp7523690n1 in the Storage account text box and File1 in the File share text box. Click Create storage, and then complete the task.

    Answer:

    Explanation: Step 1: New-AzureRMResourceGroup -name MyResourceGroup
    Before you create the DNS zone, create a resource group to contain the DNS zone.
    Step 2: New-AzureRmDnsZone -Name corp7523690.com -ResourceGroupName MyResourceGroup A DNS zone is created by using the New-AzureRmDnsZone cmdlet. This creates a DNS zone called
    corp7523690.com in the resource group called MyResourceGroup.
    References: https://docs.microsoft.com/en-us/azure/dns/dns-getstarted-powershell

    NEW QUESTION 6
    Click to expand each objective. To connect to the Azure portal, type https://portal.azure.com in the browser address bar.
    AZ-100 dumps exhibit
    AZ-100 dumps exhibit
    AZ-100 dumps exhibit
    When you are finished performing all the tasks, click the ‘Next’ button.
    Note that you cannot return to the lab once you click the ‘Next’ button. Scoring occur in the background while you complete the rest of the exam.
    Overview
    The following section of the exam is a lab. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design.
    Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn’t matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
    Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
    Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
    To start the lab
    You may start the lab by clicking the Next button.
    You plan to store media files in the rg1lod7523691n1 storage account.
    You need to configure the storage account to store the media files. The solution must ensure that only users who have access keys can download the media files and that the files are accessible only over HTTPS.
    What should you do from Azure portal?

      Answer:

      Explanation: We should create an Azure file share.
      Step 1: In the Azure portal, select All services. In the list of resources, type Storage Accounts. As you begin typing, the list filters based on your input. Select Storage Accounts.
      On the Storage Accounts window that appears.
      Step 2: Locate the rg1lod7523691n1 storage account.
      Step 3: On the storage account page, in the Services section, select Files.
      AZ-100 dumps exhibit
      Step 4: On the menu at the top of the File service page, click + File share. The New file share page drops down.
      Step 5: In Name type myshare. Click OK to create the Azure file share.
      References: https://docs.microsoft.com/en-us/azure/storage/files/storage-how-to-use-files-portal

      NEW QUESTION 7
      You have an Azure Active Directory (Azure AD) tenant named contosocloud.onmicrosoft.com. Your company has a public DNS zone for contoso.com.
      You add contoso.com as a custom domain name to Azure AD. You need to ensure that Azure can verify the domain name. Which type of DNS record should you create?

      • A. RRSIG
      • B. PTR
      • C. DNSKEY
      • D. TXT

      Answer: D

      Explanation: Create the TXT record. App Services uses this record only at configuration time to verify that you own the custom domain. You can delete this TXT record after your custom domain is validated and configured in App Service.
      References: https://docs.microsoft.com/en-us/azure/dns/dns-web-sites-custom-domain

      NEW QUESTION 8
      You need to meet the user requirement for Admin1. What should you do?

      • A. From the Subscriptions blade, select the subscription, and then modify the Properties.
      • B. From the Subscriptions blade, select the subscription, and then modify the Access control (IAM) settings.
      • C. From the Azure Active Directory blade, modify the Properties.
      • D. From the Azure Active Directory blade, modify the Groups.

      Answer: A

      Explanation: Change the Service administrator for an Azure subscription
      Sign in to Account Center as the Account administrator.
      Select a subscription.
      On the right side, select Edit subscription details.
      Scenario: Designate a new user named Admin1 as the service administrator of the Azure subscription. References:
      https://docs.microsoft.com/en-us/azure/billing/billing-add-change-azure-subscription-administrator

      NEW QUESTION 9
      You have a virtual network named VNet1 that has the configuration shown in the following exhibit.
      AZ-100 dumps exhibit
      Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
      NOTE: Each correct selection is worth one point.
      AZ-100 dumps exhibit

        Answer:

        Explanation: Box 1: add a subnet
        Your IaaS virtual machines (VMs) and PaaS role instances in a virtual network automatically receive a private IP address from a range that you specify, based on the subnet they are connected to. We need to add the 192.168.1.0/24 subnet.
        Box 2: add a network interface
        The 10.2.1.0/24 network exists. We need to add a network interface. References:
        https://docs.microsoft.com/en-us/azure/virtual-network/virtual-networks-static-private-ip-arm-pportal

        NEW QUESTION 10
        You have an on-premises file server named Server1 that runs Windows Server 2021. You have an Azure subscription that contains an Azure file share.
        You deploy an Azure File Sync Storage Sync Service, and you create a sync group. You need to synchronize files from Server1 to Azure.
        Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
        AZ-100 dumps exhibit

          Answer:

          Explanation: Step 1: Install the Azure File Sync agent on Server1
          The Azure File Sync agent is a downloadable package that enables Windows Server to be synced with an Azure file share
          Step 2: Register Server1.
          Register Windows Server with Storage Sync Service
          Registering your Windows Server with a Storage Sync Service establishes a trust relationship between your server (or cluster) and the Storage Sync Service.
          Step 3: Add a server endpoint
          Create a sync group and a cloud endpoint.
          A sync group defines the sync topology for a set of files. Endpoints within a sync group are kept in sync with each other. A sync group must contain one cloud endpoint, which represents an Azure file share and one or more server endpoints. A server endpoint represents a path on registered server.
          References: https://docs.microsoft.com/en-us/azure/storage/files/storage-sync-files-deployment-guide

          NEW QUESTION 11
          You have an Azure subscription named Subscrption1 that is associated to an Azure Active Directory (Azure AD) tenant named AAD1.
          Subscription1 contains the objects in the following table:
          AZ-100 dumps exhibit
          You plan to create a single backup policy for Vault1. To answer, select the appropriate options in the answer area.
          NOTE: Each correct selection is worth one point.
          AZ-100 dumps exhibit

            Answer:

            Explanation: Box 1: RG1 only Box 2: 99 years
            With the latest update to Azure Backup, customers can retain their data for up to 99 years in Azure.
            Note: A backup policy defines a matrix of when the data snapshots are taken, and how long those snapshots are retained.
            The backup policy interface looks like this:
            AZ-100 dumps exhibit
            References:
            https://docs.microsoft.com/en-us/azure/backup/backup-azure-vms-first-look-arm#defining-a-backup-policy
            https://blogs.microsoft.com/firehose/2015/02/16/february-update-to-azure-backup-includes-data-retention-up-to-

            NEW QUESTION 12
            Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
            After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
            Your company registers a domain name of contoso.com.
            You create an Azure DNS zone named contoso.com, and then you add an A record to the zone for a host named www that has an IP address of 131.107.1.10.
            You discover that Internet hosts are unable to resolve www.contoso.com to the 131.107.1.10 IP address.
            You need to resolve the name resolution issue.
            Solution: You create a PTR record for www in the contoso.com zone. Does this meet the goal?

            • A. Yes
            • B. No

            Answer: B

            Explanation: Modify the Name Server (NS) record.
            References: https://docs.microsoft.com/en-us/azure/dns/dns-delegate-domain-azure-dns

            NEW QUESTION 13
            You have an Azure Linux virtual machine that is protected by Azure Backup. One week ago, two files were deleted from the virtual machine.
            You need to restore the deleted files to an on-premises computer as quickly as possible.
            Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
            AZ-100 dumps exhibit

              Answer:

              Explanation: To restore files or folders from the recovery point, go to the virtual machine and choose the desired recovery point.
              Step 0. In the virtual machine's menu, click Backup to open the Backup dashboard. Step 1. In the Backup dashboard menu, click File Recovery.
              Step 2. From the Select recovery point drop-down menu, select the recovery point that holds the files you want. By default, the latest recovery point is already selected.
              Step 3: To download the software used to copy files from the recovery point, click Download Executable (for Windows Azure VM) or Download Script (for Linux Azure VM, a python script is generated).
              Step 4: Copy the files by using AzCopy
              AzCopy is a command-line utility designed for copying data to/from Microsoft Azure Blob, File, and Table storage, using simple commands designed for optimal performance. You can copy data between a file system and a storage account, or between storage accounts.
              References:
              https://docs.microsoft.com/en-us/azure/backup/backup-azure-restore-files-from-vm https://docs.microsoft.com/en-us/azure/storage/common/storage-use-azcopy

              NEW QUESTION 14
              You have an Azure subscription named Subscription1. Subscription1 contains the resources in the following table.
              AZ-100 dumps exhibit
              VNet1 is in RG1. VNet2 is in RG2. There is no connectivity between VNet1 and Vnet2.
              An administrator named Admin1 creates an Azure virtual machine named VM1 in RG1. VM1 uses a disk named Disk1 and connects to VNet1. Admin1 then installs a custom application in VM1.
              You need to move the custom application to Vnet2. The solution must minimize administrative effort. Which two actions should you perform? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
              AZ-100 dumps exhibit

                Answer:

                Explanation: You can move a VM and its associated resources to another resource group using the portal. References: https://docs.microsoft.com/en-us/azure/virtual-machines/windows/move-vm

                NEW QUESTION 15
                You sign up for Azure Active Directory (Azure AD) Premium.
                You need to add a user named admin1@contoso.com as an administrator on all the computers that will be joined to the Azure AD domain.
                What should you configure in Azure AD?

                • A. Device settings from the Devices blade.
                • B. General settings from the Groups blade.
                • C. User settings from the Users blade.
                • D. Providers from the MFA Server blade.

                Answer: C

                Explanation: When you connect a Windows device with Azure AD using an Azure AD join, Azure AD adds the following
                security principles to the local administrators group on the device: The Azure AD global administrator role
                The Azure AD device administrator role The user performing the Azure AD join
                In the Azure portal, you can manage the device administrator role on the Devices page. To open the Devices page:
                1. Sign in to your Azure portal as a global administrator or device administrator.
                2. On the left navbar, click Azure Active Directory.
                3. In the Manage section, click Devices.
                4. On the Devices page, click Device settings.
                5. To modify the device administrator role, configure Additional local administrators on Azure AD joined devices.
                References: https://docs.microsoft.com/en-us/azure/active-directory/devices/assign-local-admin

                NEW QUESTION 16
                You need to prepare the environment to meet the authentication requirements.
                Which two actions should you perform? Each correct answer presents part of the solution.
                NOTE Each correct selection is worth one point.

                • A. Azure Active Directory (AD) Identity Protection and an Azure policy
                • B. a Recovery Services vault and a backup policy
                • C. an Azure Key Vault and an access policy
                • D. an Azure Storage account and an access policy

                Answer: BD

                Explanation: D: Seamless SSO works with any method of cloud authentication - Password Hash Synchronization or Pass-through Authentication, and can be enabled via Azure AD Connect.
                B: You can gradually roll out Seamless SSO to your users. You start by adding the following Azure AD URL to all or selected users' Intranet zone settings by using Group Policy in Active Directory: https://autologon.microsoftazuread-sso.com

                Topic 2, Contoso Ltd
                Overview
                Contoso, Ltd. is a manufacturing company that has offices worldwide. Contoso works with partner organizations to bring products to market.
                Contoso products are manufactured by using blueprint files that the company authors and maintains.
                Existing Environment
                Currently, Contoso uses multiple types of servers for business operations, including the following:
                File servers
                Domain controllers
                Microsoft SQL Server servers
                Your network contains an Active Directory forest named contoso.com. All servers and client computers are joined to Active Directory.
                You have a public-facing application named App1. App1 is comprised of the following three tiers:
                A SQL database
                A web front end
                A processing middle tier
                Each tier is comprised of five virtual machines. Users access the web front end by using HTTPS only.
                Requirements Planned Changes
                Contoso plans to implement the following changes to the infrastructure: Move all the tiers of App1 to Azure.
                Move the existing product blueprint files to Azure Blob storage.
                Create a hybrid directory to support an upcoming Microsoft Office 365 migration project.
                Technical Requirements
                Contoso must meet the following technical requirements:
                Move all the virtual machines for App1 to Azure.
                Minimize the number of open ports between the App1 tiers.
                Ensure that all the virtual machines for App1 are protected by backups.
                Copy the blueprint files to Azure over the Internet.
                Ensure that the blueprint files are stored in the archive storage tier.
                Ensure that partner access to the blueprint files is secured and temporary.
                Prevent user passwords or hashes of passwords from being stored in Azure.
                Use unmanaged standard storage for the hard disks of the virtual machines.
                Ensure that when users join devices to Azure Active Directory (Azure AD), the users use a mobile phone to verify their identity.
                Minimize administrative effort whenever possible.
                User Requirements
                Contoso identifies the following requirements for users:
                Ensure that only users who are part of a group named Pilot can join devices to Azure AD. Designate a new user named Admin1 as the service administrator of the Azure subscription. Ensure that a new user named User3 can create network objects for the Azure subscription.

                NEW QUESTION 17
                Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
                After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
                You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource groups.
                Another administrator plans to create several network security groups (NSGs) in the subscription.
                You need to ensure that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks.
                Solution: You configure a custom policy definition, and then you assign the policy to the subscription.
                Does this meet the goal?

                • A. Yes
                • B. No

                Answer: A

                Explanation: Resource policy definition used by Azure Policy enables you to establish conventions for resources in your organization by describing when the policy is enforced and what effect to take. By defining conventions, you can control costs and more easily manage your resources.
                References: https://docs.microsoft.com/en-us/azure/azure-policy/policy-definition

                NEW QUESTION 18
                You have 100 Azure subscriptions. All the subscriptions are associated to the same Azure Active Directory (Azure AD) tenant named contoso.com.
                You are a global administrator.
                You plan to create a report that lists all the resources across all the subscriptions. You need to ensure that you can view all the resources in all the subscriptions.
                What should you do?

                • A. From the Azure portal, modify the profile settings of your account.
                • B. From Windows PowerShell, run the Add-AzureADAdministrativeUnitMember cmdlet.
                • C. From Windows PowerShell, run the New-AzureADUserAppRoleAssignment cmdlet.
                • D. From the Azure portal, modify the properties of the Azure AD tenant.

                Answer: C

                Explanation: The New-AzureADUserAppRoleAssignment cmdlet assigns a user to an application role in Azure Active Directory (AD). Use it for the application report.
                References:
                https://docs.microsoft.com/en-us/powershell/module/azuread/new-azureaduserapproleassignment?view=azuread

                NEW QUESTION 19
                You have peering configured as shown in the following exhibit.
                AZ-100 dumps exhibit
                Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
                NOTE: Each correct selection is worth one point.
                AZ-100 dumps exhibit

                  Answer:

                  Explanation: Box 1: vNET6 only
                  Box 2: Modify the address space
                  The virtual networks you peer must have non-overlapping IP address spaces. References:
                  https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-manage-peering#requirements-and-cons

                  NEW QUESTION 20
                  Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
                  After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
                  You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource groups.
                  Another administrator plans to create several network security groups (NSGs) in the subscription.
                  You need to ensure that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks.
                  Solution: You assign a built-in policy definition to the subscription. Does this meet the goal?

                  • A. Yes
                  • B. No

                  Answer: B

                  P.S. Easily pass AZ-100 Exam with 106 Q&As prep-labs.com Dumps & pdf Version, Welcome to Download the Newest prep-labs.com AZ-100 Dumps: https://www.prep-labs.com/dumps/AZ-100/ (106 New Questions)