What's more, part of that PracticeTorrent AZ-104 dumps now are free: https://drive.google.com/open?id=1BwSZIJDkndI9VAYcJsUsmSnk2phueuc3
To save resources of our customers, we offer real Microsoft Azure Administrator Exam (AZ-104) exam questions that are enough to master for AZ-104 certification exam. Our Microsoft AZ-104 Exam Dumps are designed by experienced industry professionals and are regularly updated to reflect the latest changes in the Building Microsoft Azure Administrator Exam (AZ-104) exam content.
| Section | Weight | Objectives |
|---|---|---|
| Manage Azure identities and governance | 15-20% | - Manage Microsoft Entra ID objects and roles - Manage subscriptions and governance - Manage Azure policy and RBAC |
| Configure and manage virtual networking | 25-30% | - Configure virtual networks - Configure load balancing and traffic routing - Configure network security |
| Monitor and maintain Azure resources | 10-15% | - Troubleshoot resources - Monitor resources using Azure Monitor - Implement backup and recovery |
| Deploy and manage Azure compute resources | 20-25% | - Manage containers in Azure - Configure and manage virtual machines - Configure App Services |
| Implement and manage storage | 15-20% | - Configure Azure Storage accounts - Manage data in Azure Storage - Configure Azure Files and Blob storage |
>> AZ-104 Original Questions <<
We offer you free update for one year after purchasing, that is to say, in the following year, you will get the updated version for AZ-104 learning materials for free. And our system will immediately send the latest version to your email address automatically once they update. What’s more, the AZ-104 Learning Materials are high quality, and it will ensure you to pass the exam successfully. Pass guarantee and money back guarantee if you can’t pass the exam.
NEW QUESTION # 452
You plan to use Azure Network Watcher to perform the following tasks:
Task1: Identify a security rule that prevents a network packet from reaching an Azure virtual machine Task2: Validate outbound connectivity from an Azure virtual machine to an external host Which feature should you use for each task? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Task 1: IP flow verify
The IP flow verify capability enables you to specify a source and destination IPv4 address, port, protocol (TCP or UDP), and traffic direction (inbound or outbound). IP flow verify then tests the communication and informs you if the connection succeeds or fails. If the connection fails, IP flow verify tells you which security rule allowed or denied the communication, so that you can resolve the problem.
Task 2: Connection troubleshoot
The connection troubleshoot capability enables you to test a connection between a VM and another VM, an FQDN, a URI, or an IPv4 address. The test returns similar information returned when using the connection monitor capability, but tests the connection at a point in time, rather than monitoring it over time.
Reference:
https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-monitoring-overview
https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-ip-flow-verify-overview
https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-connectivity-overview
NEW QUESTION # 453
You have an Azure virtual machine named VM1 that connects to a virtual network named VNet1. VM1 has the following configurations:
* Subnet: 10.0.0.0/24
* Availability set: AVSet
* Network security group (NSG): None
* Private IP address: 10.0.0.4 (dynamic)
* Public IP address: 40.90.219.6 (dynamic)
You deploy a standard, Internet-facing load balancer named slb1.
You need to configure slb1 to allow connectivity to VM1.
Which changes should you apply to VM1 as you configure slb1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Box 1: Remove the public IP address from VM1
If the Public IP on VM1 is set to Dynamic, that means it is a Public IP with Basic SKU because Public IPs with Standard SKU have Static assignments by default, that cannot be changed. We cannot associate Basic SKUs IPs with Standard SKUs LBs. One cannot create a backend SLB pool if the VM to be associated has a Public IP. For Private IP it doesn't matter weather it is dynamic or static, still we can add the such VM into the SLB backend pool.
Box 2: Create and configure an NSG
Standard Load Balancer is built on the zero trust network security model at its core. Standard Load Balancer secure by default and is part of your virtual network. The virtual network is a private and isolated network.
This means Standard Load Balancers and Standard Public IP addresses are closed to inbound flows unless opened by Network Security Groups. NSGs are used to explicitly permit allowed traffic. If you do not have an NSG on a subnet or NIC of your virtual machine resource, traffic is not allowed to reach this resource. To learn more about NSGs and how to apply them for your scenario, see Network Security Groups. Basic Load Balancer is open to the internet by default.
Reference:
https://docs.microsoft.com/en-us/azure/load-balancer/quickstart-load-balancer-standard-public-portal
https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-overview
NEW QUESTION # 454
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an app named App1 that is installed on two Azure virtual machines named VM1 and VM2. Connections to App1 are managed by using an Azure Load Balancer.
The effective network security configurations for VM2 are shown in the following exhibit.
You discover that connections to App1 from 131.107.100.50 over TCP port 443 fail. You verify that the Load Balancer rules are configured correctly.
You need to ensure that connections to App1 can be established successfully from 131.107.100.50 over TCP port 443.
Solution: You create an inbound security rule that allows any traffic from the AzuteLoadBalancer source and has a cost of 150.
Does this meet the goal?
Answer: B
NEW QUESTION # 455
You have Azure subscriptions named Subscription1 and Subscription2.
Subscription1 has following resource groups:
RG1 includes a web app named App1 in the West Europe location.
Subscription2 contains the following resource groups:
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/azure-resource-manager/management/move-limitations/app-service-move-limitations
NEW QUESTION # 456
You have an Azure subscription that contains the resources shown in the following table.
VM1 and VM2 run a website that is configured as shown in the following table.
LB1 is configured to balance requests to VM1 and VM2.
You configure a health probe as shown in the exhibit. (Click the Exhibit tab.)
You need to ensure that the health probe functions correctly.
What should you do?
Answer: A
NEW QUESTION # 457
......
From your first contact with our AZ-104 practice guide, you can enjoy our excellent service. Before you purchase AZ-104 exam questions, you can consult our online customer service. Even if you choose to use our trial version of our AZ-104 Study Materials first, we will not give you any differential treatment. As long as you have questions on the AZ-104 learning guide, we will give you the professional suggestions.
Training AZ-104 For Exam: https://www.practicetorrent.com/AZ-104-practice-exam-torrent.html
P.S. Free & New AZ-104 dumps are available on Google Drive shared by PracticeTorrent: https://drive.google.com/open?id=1BwSZIJDkndI9VAYcJsUsmSnk2phueuc3