P.S. Free & New AZ-104 dumps are available on Google Drive shared by TestPDF: https://drive.google.com/open?id=12o8bqYwKl30eKi_4W6eNXNakJ2T7cOoj
With a vast knowledge in the field, TestPDF is always striving hard to provide actual, authentic Microsoft Exam Questions so that the candidates can pass their Microsoft Azure Administrator Exam (AZ-104) exam in less time. TestPDF tries hard to provide the best Microsoft AZ-104 dumps to reduce your chances of failure in the Microsoft Azure Administrator Exam (AZ-104) exam. TestPDF provides an exam scenario with its Microsoft AZ-104 practice test (desktop and web-based) so the preparation of the Microsoft Azure Administrator Exam (AZ-104) exam questions becomes quite easier.
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Deploy and manage Azure compute resources | 20–25% | - Manage containerized workloads
|
| Topic 2: Monitor and maintain Azure resources | 10–15% | - Monitor resources and performance
|
| Topic 3: Implement and manage storage | 15–20% | - Configure access to storage
|
| Topic 4: Manage Azure identities and governance | 20–25% | - Manage Azure subscriptions and governance
|
| Topic 5: Implement and manage virtual networking | 15–20% | - Secure network access
|
>> Valid AZ-104 Test Objectives <<
Solutions is one of the top platforms that has been helping Microsoft AZ-104 exam candidates for many years. Over this long time period countless candidates have passed their dream AZ-104 exam. They all got help from Exams. The Microsoft AZ-104 questions are designed by experience and qualified AZ-104 expert. They work together and strive hard to design and maintain the top standard of TestPDF AZ-104 Questions. So you rest assured that the Microsoft AZ-104 questions you will not only ace your Microsoft Azure Administrator Exam certification exam preparation but also be ready to perform well in the final AZ-104 exam.
NEW QUESTION # 219
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your company registers a domain name of contoso.com.
You create an Azure DNS zone named contoso.com, and then you add an A record to the zone for a host named www that has an IP address of 131.107.1.10.
You discover that Internet hosts are unable to resolve www.contoso.com to the 131.107.1.10 IP address.
You need to resolve the name resolution issue.
Solution: You create a PTR record for www in the contoso.com zone.
Does this meet the goal?
Answer: B
Explanation:
Modify the Name Server (NS) record.
A NS record would be created automatically and you cannot modify it (but you can add to it to support co-hosting domains). You can add additional name servers to this NS record set, to support co-hosting domains with more than one DNS provider. You can also modify the TTL and metadata for this record set. However, you cannot remove or modify the pre-populated Azure DNS name servers.
Reference:
https://docs.microsoft.com/en-us/azure/dns/dns-delegate-domain-azure-dns
NEW QUESTION # 220
You have five Azure virtual machines that run Windows Server 2016. The virtual machines are configured as web servers.
You have an Azure load balancer named LB1 that provides load balancing services for the virtual machines.
You need to ensure that visitors are serviced by the same web server for each request.
What should you configure?
Answer: A
Explanation:
Detailed Explanation
Azure Load Balancer ' s default distribution mode is a 5-tuple (source IP, source port, destination IP, destination port, protocol) hash, which can send successive requests from the same client to different backend VMs because source port changes between connections. To pin a given visitor to the same backend VM (session affinity/stickiness), you configure the load-balancing rule ' s Session persistence setting to ' Client IP ' (2-tuple) or ' Client IP and Protocol ' (3-tuple), which removes port from the hash so all traffic from the same client IP lands on the same backend instance. Floating IP (Direct Server Return) is used for scenarios like SQL Always On, not client affinity; Idle Timeout only controls how long idle TCP connections stay open; Protocol/UDP is irrelevant to affinity for a web workload. Therefore D is correct.
Official Reference
Load Balancer distribution modes - https://learn.microsoft.com/en-us/azure/load-balancer/load-balancer- distribution-mode
NEW QUESTION # 221
You have an Azure subscription that contains a storage account named storageacct1234 and two users named User1 and User2.
You assign User1 the roles shown in the following exhibit.
Which two actions can User1 perform? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
Exhibit
Answer: B,E
Explanation:
Detailed Explanation
Storage Blob Data Contributor is a data-plane role granting read, write, and delete access specifically to blob data, which directly enables uploading blob data (B) and viewing/reading blob data (D). It grants no access to Azure Files data (file shares require separate SMB/file data-plane roles), so option A is incorrect. Assigning roles to another user (C) requires Microsoft.Authorization/roleAssignments/write, present only in roles like Owner or User Access Administrator - neither Reader nor Storage Blob Data Contributor grants it.
Modifying the storage account firewall (E) is a management-plane write operation on networkAcls, which Reader (read-only) cannot perform and Storage Blob Data Contributor (data-plane only) also does not grant.
Thus only B and D are achievable.
Official Reference
Assign an Azure role for access to blob data - https://learn.microsoft.com/en-us/azure/storage/blobs/assign- azure-role-data-access
NEW QUESTION # 222
You have an Azure subscription that contains the virtual networks shown in the following table.
Name
IP address space
Location
Subnet
Peered with
VNet1
10.10.0.0/16
East US
Subnet11, Subnet12
VNet2
VNet2
172.16.0.0/16
West US
Subnet2
VNet1
VNet3
192.168.0.0/16
East US
Subnet3
None
The subscription contains the virtual machines shown in the following table.
Name
IP address
Connected to
VM11
10.10.1.10
Subnet11
VM12
10.10.2.10
Subnet12
VM2
172.16.1.10
Subnet2
VM3
192.168.1.10
Subnet3
You create the route tables shown in the following table.
Name
Associated with
RT1
Subnet11
RT2
Subnet2
RT3
Subnet3
The route tables include the routes shown in the following table.
Name
In route table
Destination
Next hop type
Next hop address
Route1
RT1
192.168.0.0/16
Virtual appliance
192.168.1.10
Route2
RT2
10.10.1.0/24
None
Not applicable
Route3
RT3
10.10.0.0/16
Virtual appliance
10.10.2.10
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
No, No, No
Although VNet1 and VNet2 are peered, routing must be valid in both directions for ping to succeed. Azure virtual network peering enables private connectivity between peered virtual networks, and Azure adds virtual network peering system routes when peering is configured. However, user-defined routes override system routes when they conflict, and Azure selects routes by longest prefix match before applying route-source priority.
VM11 can send traffic toward VM2 through the VNet1-to-VNet2 peering route, but VM2's return traffic to VM11 matches Route2 in RT2: destination 10.10.1.0/24, next hop type None. Microsoft defines None as dropping traffic rather than forwarding it, so the ping fails. VM2 also cannot initiate a successful ping to VM11 for the same reason: its outbound traffic to 10.10.1.10 is dropped by Route2. VM3 cannot ping VM12 because VNet3 is not peered with VNet1, and Route3 points to a virtual appliance IP in a network without direct connectivity. Microsoft specifies that a virtual appliance next hop IP requires direct connectivity, otherwise the UDR configuration is invalid. Study Guide reference: AZ-104 Configure and manage virtual networking , routing, route tables, and virtual network peering.
NEW QUESTION # 223
You need to configure a new Azure App Service app named WebApp1. The solution must meet the following requirements:
* WebApp1 must be able to verify a custom domain name of app.contoso.com.
* WebApp1 must be able to automatically scale up to eight instances.
* Costs and administrative effort must be minimized.
Which pricing plan should you choose, and which type of record should you use to verify the domain? To answer, select the appropriate options in the answer area.
NOTE: Each correct answer is worth one point.
Answer:
Explanation:
NEW QUESTION # 224
......
Are you tired of the lives of ordinary light? Do you want to change yourself? Don't mention it, our TestPDF is at your service anytime. Microsoft AZ-104 certification test is very popular in the IT field. A majority of people want to have the Microsoft AZ-104 certification. Trough Microsoft AZ-104 test, you will have a better and easier life. IT talent is always respectable. TestPDF will give you the opportunity to pass Microsoft AZ-104 Exam. TestPDF Microsoft AZ-104 exam dumps fit in with our need. High quality certification training materials is very useful. 100% guarantee to pass Microsoft AZ-104 exam.
New AZ-104 Test Labs: https://www.testpdf.com/AZ-104-exam-braindumps.html
What's more, part of that TestPDF AZ-104 dumps now are free: https://drive.google.com/open?id=12o8bqYwKl30eKi_4W6eNXNakJ2T7cOoj