Microsoft AZ-101 Dumps Questions 2019

AZ-101 Royal Pack Testengine pdf

100% Actual & Verified — 100% PASS

Unlimited access to the world's largest Dumps library! Try it Free Today!

https://www.exambible.com/AZ-101-exam/

Product Description:
Exam Number/Code: AZ-101
Exam name: Microsoft Azure Integration and Security
n questions with full explanations
Certification: Microsoft Certification
Last updated on Global synchronizing

Free Certification Real IT AZ-101 Exam pdf Collection

Exam Code: AZ-101 (AZ-101 Exam Questions), Exam Name: Microsoft Azure Integration and Security, Certification Provider: Microsoft Certifitcation, Free Today! Guaranteed Training- Pass AZ-101 Exam.

Also have AZ-101 free dumps questions for you:

NEW QUESTION 1
You are the global administrator for an Azure Active Directory (Azure AD) tenant named adatum.com. From the Azure Active Directory blade, you assign the Conditional Access Administrator role to a user You need to ensure that Admin1 has just-in-time access as a conditional access administrator.
What should you do next?

  • A. Enable Azure AD Multi-Factor Authentication (MFA).
  • B. Set Admin1 as Eligible for the Privileged Role Administrator role.
  • C. Admin1 as Eligible for the Conditional Access Administrator role.
  • D. Enable Azure AD Identity Protection.

Answer: A

Explanation: Require MFA for admins is a baseline policy that requires MFA for the following directory roles:
Global administrator 
SharePoint administrator 
Exchange administrator 
Conditional access administrator 
Security administrator References:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/baseline-protection

NEW QUESTION 2
You have an Azure subscription named Subscnption1 that contains an Azure virtual machine named VM1. VM1 is in a resource group named RG1.
VM1 runs services that will be used to deploy resources to RG1.
You need to ensure that a service running on VM1 can manage the resources in RG1 by using the identity of VM1. What should you do fit -

  • A. From the Azure portal modify the Access control (1AM) settings of VM1.
  • B. From the Azure portal, modify the Policies settings of RG1.
  • C. From the Azure portal, modify the value of the Managed Service Identity option for VM1.
  • D. From the Azure portal, modify the Access control (IAM) settings of RG1.

Answer: C

Explanation: A managed identity from Azure Active Directory allows your app to easily access other AAD-protected resources such as Azure Key Vault. The identity is managed by the Azure platform and does not require you to provision or rotate any secrets.
User assigned managed identities can be used on Virtual Machines and Virtual Machine Scale Sets. References:
https://docs.microsoft.com/en-us/azure/app-service/app-service-managed-service-identity

NEW QUESTION 3
Your company recently hired a user named janet-7509087@ExamUsers.com.
You need to ensure that janet-7509087@ ExamUsers.com can connect to load balancer named Web-LAB. The solution must ensure that janet-7509087@ ExamUsers.com can modify the backend pools.
What should you do from the Azure portal?

    Answer:

    Explanation: Step 1:
    In the navigation list, choose Load Balancer.
    AZ-101 dumps exhibit
    Step 2:
    Locate the load balancer named Web-ALB, and click the Access icon. Step3:
    In the Users blade, click Roles. In the Roles blade, click Add to add permissions for the user Janet- 7509087@ExamUsers.com.
    Step 4:
    Add permission to modify backend pools References:
    https://docs.microsoft.com/en-us/azure/azure-stack/azure-stack-manage-permissions

    NEW QUESTION 4
    You need to add a deployment slot named staging to an Azure web app named
    corplod@lab.LabInstance.Idn4. The solution must meet the following requirements:
    When new code is deployed to staging, the code must be swapped automatically to the production slot. Azure-related costs must be minimized.
    What should you do from the Azure portal?

      Answer:

      Explanation: Step 1:
      Locate and open the corplod@lab.LabInstance.Idn4 web app.
      1. In the Azure portal, on the left navigation panel, click Azure Active Directory.
      2. In the Azure Active Directory blade, click Enterprise applications.
      Step 2:
      Open your app's resource blade and Choose the Deployment slots option, then click Add Slot.
      AZ-101 dumps exhibit
      Step 3:
      In the Add a slot blade, give the slot a name, and select whether to clone app configuration from another existing deployment slot. Click the check mark to continue.
      The first time you add a slot, you only have two choices: clone configuration from the default slot in production or not at all.
      References:
      https://docs.microsoft.com/en-us/azure/app-service/web-sites-staged-publishing

      NEW QUESTION 5
      You recently deployed a web app named homepagelod7509087.
      You need to back up the code used for the web app and to store the code in the homepagelod7509Q87 storage account. The solution must ensure that a new backup is created daily.
      What should you do from the Azure portal?

        Answer:

        Explanation: Step 1:
        Locate and select the web app homepagelod7509087, select Backups. The Backups page is displayed.
        AZ-101 dumps exhibit
        Step 2:
        In the Backup page, Click Configure. Step 3:
        In the Backup Configuration page, click Storage: Not configured to configure a storage account.
        AZ-101 dumps exhibit
        Step 4:
        Choose your backup destination by selecting a Storage Account and Container. Select the homepagelod7509087 storage account.
        Step 5:
        In the Backup Configuration page that is still left open, select Scheduled backup On, and configure daily backups.
        AZ-101 dumps exhibit
        Step 6:
        In the Backup Configuration page, click Save. Step 7:
        In the Backups page, click Backup. References:
        https://docs.microsoft.com/en-us/azure/app-service/web-sites-backup

        NEW QUESTION 6
        You have an Azure subscription.
        You enable multi-factor authentication for all users.
        Some users report that the email applications on their mobile device cannot co browser and from Microsoft Outlook 2016 on their computer.
        You need to ensure that the users can use the email applications on their mobile device. What should you instruct the users to do?
        The users can access Exchange Online by using a web

        • A. Enable self-service password reset.
        • B. Create an app password.
        • C. Reset the Azure Active Directory (Azure AD) password.
        • D. Reinstall the Microsoft Authenticator app.

        Answer: A

        Explanation: References:
        https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-howitworks

        NEW QUESTION 7
        Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
        After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
        You have an Azure Active Directory (Azure AD) tenant named Adatum and an Azure Subscription named Subscription1. Adatum contains a group named Developers. Subscription1 contains a resource group named Dev.
        You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group.
        Solution: On Subscription1, you assign the Logic App Operator role to the Developers group. Does this meet the goal?

        • A. Yes
        • B. No

        Answer: B

        Explanation: The Logic App Operator role only lets you read, enable and disable logic app. With it you can view the logic app and run history, and enable/disable. Cannot edit or update the definition.
        You would need the Logic App Contributor role. References:
        https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles https://docs.microsoft.com/en-us/azure/logic-apps/logic-apps-securing-a-logic-app

        NEW QUESTION 8
        You have an on-premises network that contains a Hyper-V host named Host1. Host1 runs Windows Server 2016 and hosts 10 virtual machines that run Windows Server 2016.
        You plan to replicate the virtual machines to Azure by using Azure Site Recovery. You create a Recovery Services vault named ASR1 and a Hyper-V site named
        Site1.
        You need to add Host1 to ASR1. What should you do?

        • A. Download the installation file for the Azure Site Recovery Provide
        • B. Download the vault registration key.Install the Azure Site Recovery Provider on Host1 and register the server.
        • C. Download the installation file for the Azure Site Recovery Provide
        • D. Download the storage account key.Install the Azure Site Recovery Provider on Host1 and register the server.
        • E. Download the installation file for the Azure Site Recovery Provide
        • F. Download the vault registration key.Install the Azure Site Recovery Provider on each virtual machine and register the virtual machines.
        • G. Download the installation file for the Azure Site Recovery Provide
        • H. Download the storage account key.Install the Azure Site Recovery Provider on each virtual machine and register the virtual machines.

        Answer: A

        Explanation: Download the Vault registration key. You need this when you install the Provider. The key is valid for five days after you generate it.
        Install the Provider on each VMM server. You don't need to explicitly install anything on Hyper-V hosts.
        Incorrect Answers:
        B, D: Use the Vault Registration Key, not the storage account key. References:
        https://docs.microsoft.com/en-us/azure/site-recovery/migrate-tutorial-on-premises-azure

        NEW QUESTION 9
        You are building a custom Azure function app to connect to Azure Event Grid.
        You need to ensure that resources are allocated dynamically to the function app. Billing must be based on the executions of the app.
        What should you configure when you create the function app?

        • A. the Windows operating system and the Consumption plan hosting plan
        • B. the Windows operating system and the App Service plan hosting plan
        • C. the Docker container and an App Service plan that uses the Bl1 pricing tier
        • D. the Docker container and an App Service plan that uses the SI pricing

        Answer: A

        Explanation: Azure Functions runs in two different modes: Consumption plan and Azure App Service plan. The Consumption plan automatically allocates compute power when your code is running. Your app is scaled out when needed to handle load, and scaled down when code is not running.
        Incorrect Answers:
        B: When you run in an App Service plan, you must manage the scaling of your function app. References:
        https://docs.microsoft.com/en-us/azure/azure-functions/functions-create-first-azure-function

        NEW QUESTION 10
        You plan to grant the member of a new Azure AD group named crop 75099086 the right to delegate administrative access to any resource in the resource group named 7509086.
        You need to create the Azure AD group and then to assign the correct to e to the group. The solution must use the principle of least privilege and minimize the number of role assignments.
        What should you do from the Azure portal?

          Answer:

          Explanation: Step 1:
          Click Resource groups from the menu of services to access the Resource Groups blade
          AZ-101 dumps exhibit
          Step 2:
          Click Add (+) to create a new resource group. The Create Resource Group blade appears. Enter corp7509086 as the Resource group name, and click the Create button.
          AZ-101 dumps exhibit
          Step 3:
          Select Create.
          Your group is created and ready for you to add members. Now we need to assign a role to this resource group scope. Step 4:
          Choose the newly created Resource group, and Access control (IAM) to see the current list of role assignments at the resource group scope. Click +Add to open the Add permissions pane.
          AZ-101 dumps exhibit
          Step 5:
          In the Role drop-down list, select a role Delegate administration, and select Assign access to: resource group corp7509086
          AZ-101 dumps exhibit
          References:
          https://docs.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal https://www.juniper.net/documentation/en_US/vsrx/topics/task/multi-task/security-vsrx-azure- marketplace-resource-group.html

          Case Study: 8
          Mix Questions Set E (Security Identities)

          NEW QUESTION 11
          You need to prevent remote users from publishing via FTP to a function app named FunctionApplod7509087fa. Remote users must be able to publish via FTPS. What should you do from the Azure portal?

            Answer:

            Explanation: Step 1:
            Locate and select the function app FunctionApplod7509087fa.
            Step 2:
            Select Application Settings > FTP Access, change FTP access to FTPS Only, and click Save.
            AZ-101 dumps exhibit
            References:
            https://blogs.msdn.microsoft.com/appserviceteam/2018/05/08/web-apps-making-changes-to-ftp- deployments/

            NEW QUESTION 12
            HOTSPOT
            You have an on-premises data center and an Azure subscription. The data center contains two VPN devices. The subscription contains an Azure virtual network named VNet1. VNet1 contains a gateway subnet.
            You need to create a site-to-site VPN. The solution must ensure that is a single instance of an Azure VPN gateway fails, or a single on-premises VPN device fails, the failure will not cause an interruption that is longer than two minutes.
            What is the minimum number of public IP addresses, virtual network gateways, and local network gateways required in Azure? To answer, select the appropriate options in the answer area.
            NOTE: Each correct selection is worth one point.
            AZ-101 dumps exhibit

              Answer:

              Explanation: Box 1: 4
              Two public IP addresses in the on-premises data center, and two public IP addresses in the VNET. The most reliable option is to combine the active-active gateways on both your network and Azure, as shown in the diagram below.
              AZ-101 dumps exhibit
              Box 2: 2
              Every Azure VPN gateway consists of two instances in an active-standby configuration. For any planned maintenance or unplanned disruption that happens to the active instance, the standby instance would take over (failover) automatically, and resume the S2S VPN or VNet-to-VNet connections.
              Box 3: 2
              Dual-redundancy: active-active VPN gateways for both Azure and on-premises networks References:
              https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-highlyavailable

              NEW QUESTION 13
              DRAG DROP
              You have an Azure subscription that contains an Azure Service Bus named Bus1.
              Your company plans to deploy two Azure web apps named App1 and App2. The web apps will create messages that have the following requirements:
              Each message created by App1 must be consumed by only a single consumer
              Each message created by App2 will be consumed by multiple consumers.
              Which resource should you create for each web app? To answer, drag the appropriate resources to the correct web apps. Each resource may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
              NOTE: Each correct selection is worth one point.
              AZ-101 dumps exhibit

                Answer:

                Explanation: AZ-101 dumps exhibit

                NEW QUESTION 14
                HOTSPOT
                You need to prepare the environment to implement the planned changes for Server2.
                What should you do? To answer, select the appropriate options in the answer area.
                NOTE: Each correct selection is worth one point.
                AZ-101 dumps exhibit

                  Answer:

                  Explanation: Box 1: Create a Recovery Services vault
                  Create a Recovery Services vault on the Azure Portal. Box 2: Install the Azure Site Recovery Provider
                  Azure Site Recovery can be used to manage migration of on-premises machines to Azure. Scenario: Migrate the virtual machines hosted on Server1 and Server2 to Azure.
                  Server2 has the Hyper-V host role. References:
                  https://docs.microsoft.com/en-us/azure/site-recovery/migrate-tutorial-on-premises-azure

                  Case Study: 5
                  Mix Questions Set C (Evaluate and perform server migration to Azure)

                  NEW QUESTION 15
                  You discover that VM3 does NOT meet the technical requirements. You need to verify whether the issue relates to the NSGs.
                  What should you use?

                  • A. Diagram in VNet1
                  • B. the security recommendations in Azure Advisor
                  • C. Diagnostic settings in Azure Monitor
                  • D. Diagnose and solve problems in Traffic Manager Profiles
                  • E. IP flow verify in Azure Network Watcher

                  Answer: E

                  Explanation: Scenario: Contoso must meet technical requirements including:
                  Ensure that VM3 can establish outbound connections over TCP port 8080 to the applications servers in the Montreal office.
                  IP flow verify checks if a packet is allowed or denied to or from a virtual machine. The information consists of direction, protocol, local IP, remote IP, local port, and remote port. If the packet is denied by a security group, the name of the rule that denied the packet is returned. While any source or destination IP can be chosen, IP flow verify helps administrators quickly diagnose connectivity issues from or to the internet and from or to the on-premises environment.
                  References:
                  https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-ip-flow-verify-overview

                  NEW QUESTION 16
                  You have an azure subscription that contain a virtual named VNet1. VNet1. contains four subnets named Gatesway, perimeter, NVA, and production.
                  The NVA contain two network virtual appliance (NVAs) that will network traffic inspection between the perimeter subnet and the production subnet.
                  You need o implement an Azure load balancer for the NVAs. The solution must meet the following requirements:
                  The NVAs must run in an active-active configuration that uses automatic failover.
                  The NVA must load balance traffic to two services on the Production subnet. The services have different IP addresses
                  Which three actions should you perform? Each correct answer presents parts of the solution.
                  NOTE: Each correct selection is worth one point.

                  • A. Add two load balancing rules that have HA Ports enabled and Floating IP disabled.
                  • B. Deploy a standard load balancer.
                  • C. Add a frontend IP configuration, two backend pools, and a health prob.
                  • D. Add a frontend IP configuration, a backend pool, and a health probe.
                  • E. Add two load balancing rules that have HA Ports and Floating IP enabled.
                  • F. Deploy a basic load balancer.

                  Answer: BCE

                  Explanation: A standard load balancer is required for the HA ports.
                  -Two backend pools are needed as there are two services with different IP addresses.
                  -Floating IP rule is used where backend ports are reused. Incorrect Answers:
                  F: HA Ports are not available for the basic load balancer. References:
                  https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-standard-overview https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-multivip-overview

                  NEW QUESTION 17
                  Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals.
                  Some question sets might have more than one correct solution, while others might not have a correct solution.
                  After you answer a question in this section, you will NOT be able to return to these questions will not appear m the review screen.
                  You manage a virtual network named VNetl1 that is hosted in the West US Azure region.
                  VNetl1 hosts two virtual machines named VM1 and VM2 that run Windows Server. You need to inspect all the network traffic from VM1 to VM2 for a period of three hours.
                  Solution: From Azure Network Watcher, you create a packet capture. Does this meet the goal?

                  • A. Yes
                  • B. No

                  Answer: A

                  Explanation: Azure Network Watcher provides tools to monitor, diagnose, view metrics, and enable or disable logs for resources in an Azure virtual network.
                  Capture packets to and from a VM
                  Advanced filtering options and fine-tuned controls, such as the ability to set time and size limitations, provide versatility. The capture can be stored in Azure Storage, on the VM's disk, or both. You can then analyze the capture file using several standard network capture analysis tools.
                  Network Watcher variable packet capture allows you to create packet capture sessions to track traffic to and from a virtual machine. Packet capture helps to diagnose network anomalies both reactively and proactivity.
                  References:
                  https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-monitoring-overview

                  Recommend!! Get the Full AZ-101 dumps in VCE and PDF From Surepassexam, Welcome to Download: https://www.surepassexam.com/AZ-101-exam-dumps.html (New 67 Q&As Version)