Actual AZ-102 Exam Questions 2019

AZ-102 Royal Pack Testengine pdf

100% Actual & Verified — 100% PASS

Unlimited access to the world's largest Dumps library! Try it Free Today!

https://www.exambible.com/AZ-102-exam/

Product Description:
Exam Number/Code: AZ-102
Exam name: Microsoft Azure Administrator Certification Transition
n questions with full explanations
Certification: Microsoft Certification
Last updated on Global synchronizing

Free Certification Real IT AZ-102 Exam pdf Collection

Proper study guides for AZ-102 Microsoft Azure Administrator Certification Transition certified begins with AZ-102 Braindumps preparation products which designed to deliver the AZ-102 Exam Questions and Answers by making you pass the AZ-102 test at your first time. Try the free AZ-102 Dumps right now.

Check AZ-102 free dumps before getting the full version:

NEW QUESTION 1
Note: This questions is part of a series of questions that present the same scenario. Each questions in the series contains a unique solution that might meet the stated goals. Some questions sets might have more than one correct solution, while others might not have a correct solution. After you answer a questions in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource groups.
Another administrator plans to create several network security groups (NSGs) in the subscription. You need to ensure that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks.
Solution: You assign a built-in policy definition to the subscription. Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

NEW QUESTION 2
SIMULATION
Click to expand each objective. To connect to the Azure portal, type https://portal.azure.com in the browser address bar.
AZ-102 dumps exhibit
AZ-102 dumps exhibit
AZ-102 dumps exhibit
When you are finished performing all the tasks, click the ‘Next’ button.
Note that you cannot return to the lab once you click the ‘Next’ button. Scoring occur in the background while you complete the rest of the exam.
Overview
The following section of the exam is a lab. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design. Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn’t matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
To start the lab
You may start the lab by clicking the Next button.
Another administrator attempts to establish connectivity between two virtual networks named VNET1 and VNET2.
The administrator reports that connections across the virtual networks fail.
You need to ensure that network connections can be established successfully between VNET1 and VNET2 as quickly as possible.
What should you do from the Azure portal?

    Answer:

    Explanation: You can connect one VNet to another VNet using either a Virtual network peering, or an Azure VPN Gateway.
    To create a virtual network gateway
    Step1 : In the portal, on the left side, click +Create a resource and type 'virtual network gateway' in search. Locate Virtual network gateway in the search return and click the entry. On the Virtual network gateway page, click Create at the bottom of the page to open the Create virtual network gateway page.
    Step 2: On the Create virtual network gateway page, fill in the values for your virtual network gateway.
    AZ-102 dumps exhibit
    AZ-102 dumps exhibit
    Name: Name your gateway. This is not the same as naming a gateway subnet. It's the name of the gateway object you are creating.
    Gateway type: Select VPN. VPN gateways use the virtual network gateway type VPN.
    Virtual network: Choose the virtual network to which you want to add this gateway. Click Virtual network to open the 'Choose a virtual network' page. Select the VNet. If you don't see your VNet, make sure the Location field is pointing to the region in which your virtual network is located. Gateway subnet address range: You will only see this setting if you did not previously create a gateway subnet for your virtual network. If you previously created a valid gateway subnet, this setting will not appear.
    Step 4: Select Create New to create a Gateway subnet.
    AZ-102 dumps exhibit
    Step 5: Click Create to begin creating the VPN gateway. The settings are validated and you'll see the "Deploying Virtual network gateway" tile on the dashboard. Creating a gateway can take up to 45 minutes. You may need to refresh your portal page to see the completed status.
    References: https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-vnet-vnetresource-manager-portal?

    NEW QUESTION 3
    SIMULATION
    Click to expand each objective. To connect to the Azure portal, type https://portal.azure.com in the browser address bar.
    AZ-102 dumps exhibit
    AZ-102 dumps exhibit
    AZ-102 dumps exhibit
    When you are finished performing all the tasks, click the ‘Next’ button.
    Note that you cannot return to the lab once you click the ‘Next’ button. Scoring occur in the background while you complete the rest of the exam.
    Overview
    The following section of the exam is a lab. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design.
    Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn’t matter how you accomplish the task, if you successfully perform it, you will earn credit for that task. Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
    Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
    To start the lab
    You may start the lab by clicking the Next button.
    You plan to store media files in the rg1lod7523691n1 storage account.
    You need to configure the storage account to store the media files. The solution must ensure that only users who have access keys can download the media files and that the files are accessible only over HTTPS.
    What should you do from Azure portal?

      Answer:

      Explanation: We should create an Azure file share.
      Step 1: In the Azure portal, select All services. In the list of resources, type Storage Accounts. As you begin typing, the list filters based on your input. Select Storage Accounts.
      On the Storage Accounts window that appears.
      Step 2: Locate the rg1lod7523691n1 storage account.
      Step 3: On the storage account page, in the Services section, select Files.
      AZ-102 dumps exhibit
      Step 4: On the menu at the top of the File service page, click + File share. The New file share page drops down.
      Step 5: In Name type myshare. Click OK to create the Azure file share.
      References: https://docs.microsoft.com/en-us/azure/storage/files/storage-how-to-use-files-portal

      NEW QUESTION 4
      HOT SPOT
      You plan to create a new Azure Active Directory (Azure AD) role.
      You need to ensure that the new role can view all the resources in the Azure subscription and issue support requests to Microsoft. The solution must use the principle of least privilege.
      How should you complete the JSON definition? To answer, select the appropriate options in the answer area.
      NOTE: Each correct selection is worth one point.
      AZ-102 dumps exhibit

        Answer:

        Explanation: Box 1: "*/read",
        */read lets you view everything, but not make any changes. Box 2: " Microsoft.Support/*"
        The action Microsoft.Support/* enables creating and management of support tickets. References:
        https://docs.microsoft.com/en-us/azure/role-based-access-control/tutorial-custom-role-powershell https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles

        NEW QUESTION 5
        You have an Azure DNS zone named adatum.com. You need to delegate a subdomain named research.adatum.com to a different DNS server in Azure. What should you do?

        • A. Create an PTR record named research in the adatum.com zone.
        • B. Create an NS record named research in the adatum.com zone.
        • C. Modify the SOA record of adatum.com.
        • D. Create an A record named “.research in the adatum.com zon

        Answer: D

        Explanation: Configure A records for the domains and sub domains.
        References: http://www.stefanjohansson.org/2012/12/how-to-configure-custom-dns-names-formultiple- subdomain-based-azure-web-sites/

        NEW QUESTION 6
        You have an Azure subscription that contains 10 virtual machines.
        You need to ensure that you receive an email message when any virtual machines are powered off, restarted, or deallocated.
        What is the minimum number of rules and action groups that you require?

        • A. three rules and three action groups
        • B. one rule and one action group
        • C. three rules and one action group
        • D. one rule and three action groups

        Answer: C

        Explanation: An action group is a collection of notification preferences defined by the user. Azure Monitor and Service
        Health alerts are configured to use a specific action group when the alert is triggered. Various alerts may use the same action group or different action groups depending on the user's requirements. References: https://docs.microsoft.com/en-us/azure/monitoring-and-diagnostics/monitoring-actiongroups

        NEW QUESTION 7
        You need to define a custom domain name for Azure AD to support the planned infrastructure. Which domain name should you use?

        • A. ad.humongousinsurance.com
        • B. humongousinsurance.onmicrosoft.com
        • C. humongousinsurance.local
        • D. humongousinsurance.com

        Answer: D

        Explanation: Every Azure AD directory comes with an initial domain name in the form of domainname.onmicrosoft.com. The initial domain name cannot be changed or deleted, but you can add your corporate domain name to Azure AD as well. For example, your organization probably has other domain names used to do business and users who sign in using your corporate domain name. Adding custom domain names to Azure AD allows you to assign user names in the directory that are familiar to your users, such as ‘alice@contoso.com.’ instead of 'alice@domain name.onmicrosoft.com'.
        Scenario:
        Network Infrastructure: Each office has a local data center that contains all the servers for that office. Each office has a dedicated connection to the Internet.
        Humongous Insurance has a single-domain Active Directory forest named humongousinsurance.com Planned Azure AD Infrastructure: The on-premises Active Directory domain will be synchronized to Azure AD.
        References: https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/add-customdomain

        NEW QUESTION 8
        You have an Azure subscription that contains the resources in the following table.
        AZ-102 dumps exhibit
        To which subnets can you apply NSG1?

        • A. the subnets on VNet2 only
        • B. the subnets on VNet1 only
        • C. the subnets on VNet2 and VNet3 only
        • D. the subnets on VNet1, VNet2, and VNet3
        • E. the subnets on VNet3 only

        Answer: E

        Explanation: All Azure resources are created in an Azure region and subscription. A resource can only be created in a virtual network that exists in the same region and subscription as the resource.
        References: https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-vnet-plandesign- arm

        NEW QUESTION 9
        HOT SPOT
        You need to implement App2 to meet the application? To answer, select the appropriate options in the answer area.
        NOTE: Each correct selection is worth one point.
        AZ-102 dumps exhibit

          Answer:

          Explanation: Box 1: Standard
          Not Shared: A Shared plan does not support Always on. Box 2: Always on
          If your function app is on the Consumption plan, there can be up to a 10-minute delay in processing new blobs if a function app has gone idle. To avoid this cold-start delay, you can switch to an App Service plan with Always On enabled, or use a different trigger type.
          Scenario: A newly developed API must be implemented as an Azure function named App2. App2 will use a blob storage trigger. App2 must process new blobs immediately.
          App2 must be able to connect directly to the private IP addresses of the Azure virtual machines. App2 will be deployed directly to an Azure virtual network.
          The cost of App1 and App2 must be minimized. References:
          https://docs.microsoft.com/en-us/azure/azure-functions/functions-bindings-storage-blob https://azure.microsoft.com/en-us/pricing/details/app-service/plans/

          Case Study: 13 Mix Questions Set F

          NEW QUESTION 10
          You have a public load balancer that balancer ports 80 and 443 across three virtual machines. You need to direct all the Remote Desktop protocol (RDP) to VM3 only.
          What should you configure?

          • A. an inbound NAT rule
          • B. a load public balancing rule
          • C. a new public load balancer for VM3
          • D. a new IP configuration

          Answer: A

          Explanation: To port forward traffic to a specific port on specific VMs use an inbound network address translation (NAT) rule.
          Incorrect Answers:
          B: Load-balancing rule to distribute traffic that arrives at frontend to backend pool instances. References:
          https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-overview

          NEW QUESTION 11
          You have an Azure Active Directory (Azure AD) domain that contains 5,000 user accounts. You create a new user account named AdminUser1.
          You need to assign the User administrator administrative role to AdminUser1. What should you do from the user account properties?

          • A. From the Directory role blade, modify the directory role.
          • B. From the Groups blade, invite the user account to a new group.
          • C. From the Licenses blade, assign a new licens

          Answer: A

          Explanation: Assign a role to a user
          Sign in to the Azure portal with an account that's a global admin or privileged role admin for the directory.
          Select Azure Active Directory, select Users, and then select a specific user from the list.
          For the selected user, select Directory role, select Add role, and then pick the appropriate admin roles from the Directory roles list, such as Conditional access administrator.
          Press Select to save.
          References: https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/activedirectory-users-assign-role-azure-portal

          NEW QUESTION 12
          You need to prevent remote users from publishing via FTP to a function app named FunctionApplod7509087fa. Remote users must be able to publish via FTPS. What should you do from the Azure portal?

            Answer:

            Explanation: Step 1:
            Locate and select the function app FunctionApplod7509087fa. Step 2:
            Select Application Settings > FTP Access, change FTP access to FTPS Only, and click Save.
            AZ-102 dumps exhibit
            References:
            https://blogs.msdn.microsoft.com/appserviceteam/2018/05/08/web-apps-making-changes-to-ftpdeployments/

            NEW QUESTION 13
            You have an Azure subscription named Subscription1 and two Azure Active Directory (Azure AD) tenants named Tenant1 and Tenant2.
            Subscnption1 is associated to Tenant1 Multi-factor authentication (MFA) is enabled for all the users in Tenant1.
            You need to enable MFA for the users in Tenant2. The solution must maintain MFA forTenant1. What should you do first?

            • A. Transfer the administration of Subscription1 to a global administrator of Tenants.
            • B. Configure the MFA Server setting in Tenant1.
            • C. Create and link a subscription to Tenant2.
            • D. Change the directory for Subscription1.

            Answer: C

            Explanation: Case Study: 12
            ADatum Corporation Overview
            A Datum Corporation is a financial company that has two main offices in New York and Los Angeles. A Datum has a subsidiary named Fabrikam, Inc. that shares the Los Angeles office.
            A Datum is conducting an initial deployment of Azure services to host new line-of-business applications and is preparing to migrate its existing on-premises workloads to Azure.
            A Datum uses Microsoft Exchange Online for email. On-Premises Environment
            The on-premises workloads run on virtual machines hosted in a VMware vSphere 6 infrastructure. All the virtual machines are members of an Active Directory forest named adatum.com and run Windows Server 2016.
            The New York office an IP address of 10.0.0.0/16. The Los Angeles office uses an IP address space of 10.10.0.0/16.
            The offices connect by using a VPN provided by an ISP. Each office has one Azure ExpressRoute circuit that provides access to Azure services and Microsoft Online Services. Routing is implemented by using Microsoft peering.
            The New York office has a virtual machine named VM1 that has the vSphere console installed. Azure Environment
            You provision the Azure infrastructure by using the Azure portal. The infrastructure contains the resources shown in the following table.
            AZ-102 dumps exhibit
            AG1 has two backend pools named Pool11 and Pool12. AG2 has two backend pools named Pool21 and Pool22.
            Planned Changes
            ADatum plans to migrate the virtual machines from the New York office to the East US Azure region by using Azure Site Recovery.
            Infrastructure Requirements
            ADatum identifies the following infrastructure requirements:
            ? A new web app named App1 that will access third-parties for credit card processing must be deployed.
            ? A newly developed API must be implemented as an Azure function named App2. App2 will use a blob storage trigger. App2 must process new blobs immediately.
            ? The Azure infrastructure and the on-premises infrastructure and the on-premises infrastructure must be prepared for the migration of the VMware virtual machines to Azure.
            ? The sizes of the Azure virtual machines that will be used to migrate the on-premises workloads must be identified.
            ? All migrated and newly deployed Azure virtual machines must be joined to the adatum.com domain.
            ? AG1 must load balance incoming traffic in the following manner:
            1. http://corporate.adatum.com/video/* will be load balanced across Pool11.
            2. http://corporate.adatum.com/images/* will be load balanced across Pool12.
            ? AG2 must load balance incoming traffic in the following manner:
            1. http://www.adatum.com will be load balanced across Pool21.
            2. http://www.fabrikam.com will be load balanced across Pool22.
            ? ER1 must route traffic between the New York office and the platform as a service (PaaS) services in the East US Azure region, as long as ER1 is available.
            ? ER2 must route traffic between the Los Angeles office and the PaaS sevices in the West US region, as long as ER2 is available.
            ? ER1 and ER2 must be configured to fail over automatically. Application Requirements
            App2 must be able to connect directly to the private IP addresses of the Azure virtual machines. App2 will be deployed directly to an Azure virtual network.
            Inbound and outbound communications to App1 must be controlled by using NSGs. Pricing Requirements
            ADatum identifies the following pricing requirements:
            ? The cost of App1 and App2 must be minimized.
            ? The transactional charges of Azure Storage account must be minimized.

            NEW QUESTION 14
            You are planning the move of App1 to Azure. You create a network security group (NSG).
            You need to recommend a solution to provide users with access to App1. What should you recommend?

            • A. Create an outgoing security rule for port 443 from the Interne
            • B. Associate the NSG to all the subnets.
            • C. Create an incoming security rule for port 443 from the Interne
            • D. Associate the NSG to all the subnets.
            • E. Create an incoming security rule for port 443 from the Interne
            • F. Associate the NSG to the subnet thatcontains the web servers.
            • G. Create an outgoing security rule for port 443 from the Interne
            • H. Associate the NSG to the subnet thatcontains the web server

            Answer: C

            Explanation: As App1 is public-facing we need an incoming security rule, related to the access of the web servers. Scenario: You have a public-facing application named App1. App1 is comprised of the following three tiers: a SQL database, a web front end, and a processing middle tier.
            Each tier is comprised of five virtual machines. Users access the web front end by using HTTPS only.

            NEW QUESTION 15
            HOT SPOT
            You have an Azure web app named WebApp1 that runs in an Azure App Service plan named ASP1. ASP1 is based on the D1 pricing tier.
            You need to ensure that WebApp1 can be accessed only from computers on your on-premises network. The solution must minimize costs.
            What should you configure? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
            AZ-102 dumps exhibit

              Answer:

              Explanation: Box 1: B1
              B1 (Basic) would minimize cost compared P1v2 (premium) and S1 (standard). Box 2: Cross Origin Resource Sharing (CORS)
              Once you set the CORS rules for the service, then a properly authenticated request made against the service from a different domain will be evaluated to determine whether it is allowed according to the rules you have specified.
              Note: CORS (Cross Origin Resource Sharing) is an HTTP feature that enables a web application running under one domain to access resources in another domain. In order to reduce the possibility of cross-site scripting attacks, all modern web browsers implement a security restriction known as
              same-origin policy. This prevents a web page from calling APIs in a different domain. CORS provides a secure way to allow one origin (the origin domain) to call APIs in another origin.
              References:
              https://azure.microsoft.com/en-us/pricing/details/app-service/windows/ https://docs.microsoft.com/en-us/azure/cdn/cdn-cors

              NEW QUESTION 16
              HOT SPOT
              You purchase a new Azure subscription named Subscription1.
              You create a virtual machine named VM1 in Subscription1. VM1 is not protected by Azure Backup. You need to protect VM1 by using Azure Backup. Backups must be created at 01:00 and stored for 30 days.
              What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
              AZ-102 dumps exhibit

                Answer:

                Explanation: Box 1: A Recovery Services vault
                A Recovery Services vault is an entity that stores all the backups and recovery points you create over time.
                Box 2: A backup policy
                What happens when I change my backup policy?
                When a new policy is applied, schedule and retention of the new policy is followed. References:
                https://docs.microsoft.com/en-us/azure/backup/backup-configure-vault https://docs.microsoft.com/en-us/azure/backup/backup-azure-backup-faq

                NEW QUESTION 17
                You have an Azure subscription that contains an Azure file share.
                You have an on-premises server named Server1 that runs Windows Server 2016. You plan to set up Azure File Sync between Server1 and the Azure file share. You need to prepare the subscription for the planned Azure File Sync.
                Which two actions should you perform in the Azure subscription? To answer, drag the appropriate actions to the correct targets. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
                AZ-102 dumps exhibit

                  Answer:

                  Explanation: First action: Create a Storage Sync Service
                  The deployment of Azure File Sync starts with placing a Storage Sync Service resource into a resource group of your selected subscription.
                  Second action: Run Server Registration
                  Registering your Windows Server with a Storage Sync Service establishes a trust relationship between your server (or cluster) and the Storage Sync Service. A server can only be registered to one Storage Sync Service and can sync with other servers and Azure file shares associated with the same Storage Sync Service.
                  The Server Registration UI should open automatically after installation of the Azure File Sync agent.
                  AZ-102 dumps exhibit

                  P.S. Easily pass AZ-102 Exam with 195 Q&As Certleader Dumps & pdf Version, Welcome to Download the Newest Certleader AZ-102 Dumps: https://www.certleader.com/AZ-102-dumps.html (195 New Questions)