Download AZ-101 Exam Questions and Answers 2019

We offers AZ-101 Study Guides. "Microsoft Azure Integration and Security", also known as AZ-101 exam, is a Microsoft Certification. This set of posts, Passing the AZ-101 exam with AZ-101 Free Practice Questions, will help you answer those questions. The AZ-101 Free Practice Questions covers all the knowledge points of the real exam. 100% real AZ-101 Exam Questions and Answers and revised by experts!

Online Microsoft AZ-101 free dumps demo Below:

NEW QUESTION 1
You have an Azure Active Directory (Azure AD) tenant named Tenant1 and an Azure subscription named You enable Azure AD Privileged Identity Management.
You need to secure the members of the Lab Creator role. The solution must ensure that the lab creators request access when they create labs.
What should you do first?

  • A. From Azure AD Privileged Identity Management, edit the role settings for Lab Creator.
  • B. From Subscription1 edit the members of the Lab Creator role.
  • C. From Azure AD Identity Protection, creates a user risk policy.
  • D. From Azure AD Privileged Identity Management, discover the Azure resources of Conscription.

Answer: A

Explanation: As a Privileged Role Administrator you can:
Enable approval for specific roles
Specify approver users and/or groups to approve requests
View request and approval history for all privileged roles References:
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure

NEW QUESTION 2
You plan to move services from your on-premises network to Azure.
You identify several virtual machines that you believe can be hosted in Azure. The virtual machines are shown in the following table.
AZ-101 dumps exhibit
Which two virtual machines can you access by using Azure migrate? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  • A. Sea-CA0l
  • B. Hou-NW01
  • C. NYC-FS01
  • D. Sea-DC01
  • E. BOS-DB01

Answer: CE

NEW QUESTION 3
HOTSPOT
Your company has offices in New York and Los Angeles.
You have an Azure subscription that contains an Azure virtual network named VNet1. Each office has a site-to-site VPN connection to VNet1.
Each network uses the address spaces shown in the following table.
AZ-101 dumps exhibit
You need to ensure that all Internet-bound traffic from VNet1 is routed through the New York office.
What should you do? To answer, select the appropriate options in the answer are a.
NOTE: Each correct selection is worth one point.
AZ-101 dumps exhibit

    Answer:

    Explanation: Incorrect Answers:
    Not: New-AzureRmVirtualNetworkGatewayConnection
    This command creates the Site-to-Site VPN connection between the virtual network gateway and the on-prem VPN device. We already have Site-to-Site VPN connections.
    Box 2: 192.168.0.0/20
    Specify the VNET1 address. References:
    https://docs.microsoft.com/en-us/powershell/module/azurerm.network/set- azurermvirtualnetworkgatewaydefaultsite

    NEW QUESTION 4
    You are building a custom Azure function app to connect to Azure Event Grid.
    You need to ensure that resources are allocated dynamically to the function app. Billing must be based on the executions of the app.
    What should you configure when you create the function app?

    • A. the Windows operating system and the Consumption plan hosting plan
    • B. the Windows operating system and the App Service plan hosting plan
    • C. the Docker container and an App Service plan that uses the Bl1 pricing tier
    • D. the Docker container and an App Service plan that uses the SI pricing

    Answer: A

    Explanation: Azure Functions runs in two different modes: Consumption plan and Azure App Service plan. The Consumption plan automatically allocates compute power when your code is running. Your app is scaled out when needed to handle load, and scaled down when code is not running.
    Incorrect Answers:
    B: When you run in an App Service plan, you must manage the scaling of your function app. References:
    https://docs.microsoft.com/en-us/azure/azure-functions/functions-create-first-azure-function

    NEW QUESTION 5
    You have an Azure subscription named Subscnption1 that contains an Azure virtual machine named VM1. VM1 is in a resource group named RG1.
    VM1 runs services that will be used to deploy resources to RG1.
    You need to ensure that a service running on VM1 can manage the resources in RG1 by using the identity of VM1. What should you do fit -

    • A. From the Azure portal modify the Access control (1AM) settings of VM1.
    • B. From the Azure portal, modify the Policies settings of RG1.
    • C. From the Azure portal, modify the value of the Managed Service Identity option for VM1.
    • D. From the Azure portal, modify the Access control (IAM) settings of RG1.

    Answer: C

    Explanation: A managed identity from Azure Active Directory allows your app to easily access other AAD-protected resources such as Azure Key Vault. The identity is managed by the Azure platform and does not require you to provision or rotate any secrets.
    User assigned managed identities can be used on Virtual Machines and Virtual Machine Scale Sets. References:
    https://docs.microsoft.com/en-us/azure/app-service/app-service-managed-service-identity

    NEW QUESTION 6
    HOTSPOT
    You need to prepare the environment to implement the planned changes for Server2.
    What should you do? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.
    AZ-101 dumps exhibit

      Answer:

      Explanation: Box 1: Create a Recovery Services vault
      Create a Recovery Services vault on the Azure Portal. Box 2: Install the Azure Site Recovery Provider
      Azure Site Recovery can be used to manage migration of on-premises machines to Azure. Scenario: Migrate the virtual machines hosted on Server1 and Server2 to Azure.
      Server2 has the Hyper-V host role. References:
      https://docs.microsoft.com/en-us/azure/site-recovery/migrate-tutorial-on-premises-azure

      Case Study: 5
      Mix Questions Set C (Evaluate and perform server migration to Azure)

      NEW QUESTION 7
      DRAG DROP
      You create an Azure Migrate project named TestMig in a resource group named test-migration.
      You need to discover which on-premises virtual machines to assess for migration. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
      AZ-101 dumps exhibit

        Answer:

        Explanation: Step 1: Download the OVA file for the collection appliance
        Azure Migrate uses an on-premises VM called the collector appliance, to discover information about your on-premises machines. To create the appliance, you download a setup file in Open Virtualization Appliance (.ova) format, and import it as a VM on your on-premises vCenter Server.
        Step 2: Create a migration group in the project
        For the purposes of assessment, you gather the discovered VMs into groups. For example, you might group VMs that run the same application. For more precise grouping, you can use dependency visualization to view dependencies of a specific machine, or for all machines in a group and refine the
        group.
        Step 3: Create an assessment in the project
        After a group is defined, you create an assessment for it. References:
        https://docs.microsoft.com/en-us/azure/migrate/migrate-overview

        Case Study: 6
        Mix Questions Set D (Implement advanced networking)

        NEW QUESTION 8
        You have an Azure Service Bus.
        You need to implement a Service Bus queue that guarantees first in first-out (FIFO) delivery of messages.
        What should you do?

        • A. Set the Lock Duration setting to 10 seconds.
        • B. Enable duplicate detection.
        • C. Set the Max Size setting of the queue to 5 GB.
        • D. Enable partitioning.
        • E. Enable sessions.

        Answer: E

        Explanation: Through the use of messaging sessions you can guarantee ordering of messages, that is first-in-first- out (FIFO) delivery of messages.
        References:
        https://docs.microsoft.com/en-us/azure/service-bus-messaging/service-bus-azure-and-service-bus- queues-compared-contrasted

        NEW QUESTION 9
        You have an Azure subscription that contains a virtual network named VNet1. VNet 1 has two subnets named Subnet1 and Subnet2. VNet1 is in the West Europe Azure region.
        The subscription contains the virtual machines in the following table.
        AZ-101 dumps exhibit
        You need to deploy an application gateway named AppGW1 to VNet1. What should you do first?

        • A. Add a service endpoint.
        • B. Add a virtual network.
        • C. Move VM3 to Subnet1.
        • D. Stop VM1 and VM2.

        Answer: D

        Explanation: If you have an existing virtual network, either select an existing empty subnet or create a new subnet in your existing virtual network solely for use by the application gateway.
        Verify that you have a working virtual network with a valid subnet. Make sure that no virtual machines or cloud deployments are using the subnet. The application gateway must be by itself in a virtual network subnet.
        References:
        https://social.msdn.microsoft.com/Forums/azure/en-US/b09367f9-5d01-4cda-9127- b7a506a0a151/cant-create-application-gateway?forum=WAVirtualMachinesVirtualNetwork https://docs.microsoft.com/en-us/azure/application-gateway/application-gateway-create-gateway

        NEW QUESTION 10
        Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
        After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
        You have an Azure Active Directory (Azure AD) tenant named Adatum and an Azure Subscription named Subscription1. Adatum contains a group named Developers. Subscription1 contains a resource group named Dev.
        You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group.
        Solution: On Subscription1, you assign the Logic App Operator role to the Developers group. Does this meet the goal?

        • A. Yes
        • B. No

        Answer: B

        Explanation: The Logic App Operator role only lets you read, enable and disable logic app. With it you can view the logic app and run history, and enable/disable. Cannot edit or update the definition.
        You would need the Logic App Contributor role. References:
        https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles https://docs.microsoft.com/en-us/azure/logic-apps/logic-apps-securing-a-logic-app

        NEW QUESTION 11
        You have an Azure subscription.
        You enable multi-factor authentication for all users.
        Some users report that the email applications on their mobile device cannot co browser and from Microsoft Outlook 2016 on their computer.
        You need to ensure that the users can use the email applications on their mobile device. What should you instruct the users to do?
        The users can access Exchange Online by using a web

        • A. Enable self-service password reset.
        • B. Create an app password.
        • C. Reset the Azure Active Directory (Azure AD) password.
        • D. Reinstall the Microsoft Authenticator app.

        Answer: A

        Explanation: References:
        https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-howitworks

        NEW QUESTION 12
        You are the global administrator for an Azure Active Directory (Azure AD) tenant named adatum.com. From the Azure Active Directory blade, you assign the Conditional Access Administrator role to a user You need to ensure that Admin1 has just-in-time access as a conditional access administrator.
        What should you do next?

        • A. Enable Azure AD Multi-Factor Authentication (MFA).
        • B. Set Admin1 as Eligible for the Privileged Role Administrator role.
        • C. Admin1 as Eligible for the Conditional Access Administrator role.
        • D. Enable Azure AD Identity Protection.

        Answer: A

        Explanation: Require MFA for admins is a baseline policy that requires MFA for the following directory roles:
        Global administrator 
        SharePoint administrator 
        Exchange administrator 
        Conditional access administrator 
        Security administrator References:
        https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/baseline-protection

        NEW QUESTION 13
        You plan to support many connections to your company's automatically uses up to five instances when CPU utilization on the instances exceeds 70 percent for 10 minutes. When CPU utilization decreases, the solution must automatically reduce the number of instances.
        What should you do from the Azure portal?

          Answer:

          Explanation: Step 1:
          Locate the Homepage App Service plan Step 2:
          below.
          Click Add a rule, and enter the appropriate fields, such as below, and the click Add. Time aggregation: average
          Metric Name: Percentage CPU Operator: Greater than Threshold 70
          Duration: 10 minutes Operation: Increase count by Instance count: 4
          AZ-101 dumps exhibit
          Step 3:
          We must add a scale in rule as well. Click Add a rule, and enter the appropriate fields, such as below, then click Add.
          Operator: Less than Threshold 70
          Duration: 10 minutes Operation: Decrease count by Instance count: 4
          References:
          https://docs.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machine-scale-sets- autoscale-portal
          https://docs.microsoft.com/en-us/azure/monitoring-and-diagnostics/insights-autoscale-best-practices

          NEW QUESTION 14
          From the MFA Server blade, you open the Block/unblock users blade as shown in the exhibit.
          AZ-101 dumps exhibit
          What caused AlexW to be blocked?

          • A. An administrator manually blocked the user.
          • B. The user reports a fraud alert when prompted for additional authentication.
          • C. The user account password expired.
          • D. The user entered an incorrect PIN four times within 10 minutes.

          Answer: B

          NEW QUESTION 15
          Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
          After you answer
          a question in this section, you will NOT be able to return to it As a result, these questions will not appear in the review screen.
          You have an Azure Active Directory (Azure AD) tenant named Adatum and an Azure Subscript contains a resource group named Dev.
          d Subscription1. Adatum contains a group named Developers. Subscription!
          You need to provide the Developers group with the ability to create Azure logic apps in the; Dev, resource group.
          Solution: On Dev, you assign the Logic App Contributor role to the Developers group.
          Does this meet the goal?

          • A. Yes
          • B. No

          Answer: A

          Explanation: The Logic App Contributor role lets you manage logic app, but not access to them. It provides access to view, edit, and update a logic app.
          References:
          https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles https://docs.microsoft.com/en-us/azure/logic-apps/logic-apps-securing-a-logic-app

          NEW QUESTION 16
          Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
          After you answer a question in this section, you will NOT be able to return to it As a result these questions will not appear in the review screen.
          You have an Azure wet) app named Appl. App1 runs in an Azure App Service plan named Plan1. Plan1 is associated to the Free pricing tier.
          You discover that App1 stops each day after running continuously for 60 minutes. You need to ensure that App1 can run continuously for the entire day.
          Solution: You change the pricing tier of Plan1 to Shared. Does this meet the goal?

          • A. Yes
          • B. No

          Answer: B

          Explanation: You should switch to the Basic Tier.
          The Free Tier provides 60 CPU minutes / day. This explains why App1 is stops. The Shared Tier provides 240 CPU minutes / day. The Basic tier has no such cap.
          References:
          https://azure.microsoft.com/en-us/pricing/details/app-service/windows/

          P.S. Surepassexam now are offering 100% pass ensure AZ-101 dumps! All AZ-101 exam questions have been updated with correct answers: https://www.surepassexam.com/AZ-101-exam-dumps.html (67 New Questions)