Simulation AZ-102 Dumps 2021

Your success in AZ-102 Study Guides is our sole target and we develop all our AZ-102 Braindumps in a way that facilitates the attainment of this target. Not only is our AZ-102 Exam Questions and Answers material the best you can find, it is also the most detailed and the most updated. AZ-102 Exam Dumps for Microsoft AZ-102 are written to the highest standards of technical accuracy.

Free demo questions for Microsoft AZ-102 Exam Dumps Below:

NEW QUESTION 1
You need to meet the user requirement for Admin1. What should you do?

  • A. From the Subscriptions blade, select the subscription, and then modify the Properties.
  • B. From the Subscriptions blade, select the subscription, and then modify the Access control (IAM) settings.
  • C. From the Azure Active Directory blade, modify the Properties.
  • D. From the Azure Active Directory blade, modify the Group

Answer: A

Explanation: Change the Service administrator for an Azure subscription Sign in to Account Center as the Account administrator. Select a subscription.
On the right side, select Edit subscription details.
Scenario: Designate a new user named Admin1 as the service administrator of the Azure subscription.
References: https://docs.microsoft.com/en-us/azure/billing/billing-add-change-azure-subscriptionadministrator

NEW QUESTION 2
You have 100 Azure subscriptions. All the subscriptions are associated to the same Azure Active Directory (Azure AD) tenant named contoso.com.
You are a global administrator.
You plan to create a report that lists all the resources across all the subscriptions. You need to ensure that you can view all the resources in all the subscriptions. What should you do?

  • A. From the Azure portal, modify the profile settings of your account.
  • B. From Windows PowerShell, run the Add-AzureADAdministrativeUnitMember cmdlet.
  • C. From Windows PowerShell, run the New-AzureADUserAppRoleAssignment cmdlet.
  • D. From the Azure portal, modify the properties of the Azure AD tenan

Answer: C

Explanation: The New-AzureADUserAppRoleAssignment cmdlet assigns a user to an application role in Azure Active Directory (AD). Use it for the application report.
References: https://docs.microsoft.com/en-us/powershell/module/azuread/newazureaduserapproleassignment? view=azureadps-2.0

NEW QUESTION 3
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure web app named Appl. App1 runs in an Azure App Service plan named Plan1. Plan1 is associated to the Free pricing tier.
You discover that App1 stops each day after running continuously for 60 minutes. You need to ensure that App1 can run continuously for the entire day.
Solution: You change the pricing tier of Plan1 to Basic. Does this meet the goal?

  • A. Yes
  • B. No

Answer: A

Explanation: The Free Tier provides 60 CPU minutes / day. This explains why App1 is stops. The Basic tier has no such cap.
References:
https://azure.microsoft.com/en-us/pricing/details/app-service/windows/

NEW QUESTION 4
You have an Azure subscription that contains a virtual network named VNet1. VNet 1 has two subnets named Subnet1 and Subnet2. VNet1 is in the West Europe Azure region.
The subscription contains the virtual machines in the following table.
AZ-102 dumps exhibit
You need to deploy an application gateway named AppGW1 to VNet1. What should you do first?

  • A. Add a service endpoint.
  • B. Add a virtual network.
  • C. Move VM3 to Subnet1.
  • D. Stop VM1 and VM2.

Answer: D

Explanation: If you have an existing virtual network, either select an existing empty subnet or create a new subnet in your existing virtual network solely for use by the application gateway.
Verify that you have a working virtual network with a valid subnet. Make sure that no virtual machines or cloud deployments are using the subnet. The application gateway must be by itself in a virtual network subnet.
References:
https://social.msdn.microsoft.com/Forums/azure/en-US/b09367f9-5d01-4cda-9127- b7a506a0a151/cant-create-application-gateway?forum=WAVirtualMachinesVirtualNetwork https://docs.microsoft.com/en-us/azure/application-gateway/application-gateway-create-gateway

NEW QUESTION 5
You have an Azure App Service plan that hosts an Azure App Service named App1.
You configure one production slot and four staging slots for App1.
You need to allocate 10 percent of the traffic to each staging slot and 60 percent of the traffic to the production slot.
What should you add to Appl1?

  • A. slots to the Testing in production blade
  • B. a performance test
  • C. a WebJob
  • D. templates to the Automation script blade

Answer: A

Explanation: Besides swapping, deployment slots offer another killer feature: testing in production. Just like the name suggests, using this, you can actually test in production. This means that you can route a specific percentage of user traffic to one or more of your deployment slots.
Example:
AZ-102 dumps exhibit
References:
https://stackify.com/azure-deployment-slots/

NEW QUESTION 6
You have two Azure virtual networks named VNet1 and VNet2. VNet1 contains an Azure virtual
machine named VM1. VNet2 contains an Azure virtual machine named VM2. VM1 hosts a frontend application that connects to VM2 to retrieve data. Users report that the frontend application is slower than usual.
You need to view the average round-trip time (RTT) of the packets from VM1 to VM2. Which Azure Network Watcher feature should you use?

  • A. NSG flow logs
  • B. Connection troubleshoot
  • C. IP flow verify
  • D. Connection monitor

Answer: D

Explanation: The Connection Monitor feature in Azure Network Watcher is now generally available in all public regions. Connection Monitor provides you RTT values on a per-minute granularity. You can monitor a direct TCP connection from a virtual machine to a virtual machine, FQDN, URI, or IPv4 address. References:
https://azure.microsoft.com/en-us/updates/general-availability-azure-network-watcher-connectionmonitor- in-all-public-regions/

NEW QUESTION 7
You have an Azure virtual network named VNet1 that contains a subnet named Subnet1. Subnet1 contains three Azure virtual machines. Each virtual machine has a public IP address.
The virtual machines host several applications that are accessible over port 443 to user on the Internet.
Your on-premises network has a site-to-site VPN connection to VNet1.
You discover that the virtual machines can be accessed by using the Remote Desktop Protocol (RDP) from the Internet and from the on-premises network.
You need to prevent RDP access to the virtual machines from the Internet, unless the RDP connection is established from the on-premises network. The solution must ensure that all the applications can still be accesses by the Internet users.
What should you do?

  • A. Modify the address space of the local network gateway.
  • B. Remove the public IP addresses from the virtual machines.
  • C. Modify the address space of Subnet1.
  • D. Create a deny rule in a network security group (NSG) that is linked to Subnet1.

Answer: D

Explanation: You can filter network traffic to and from Azure resources in an Azure virtual network with a network security group. A network security group contains security rules that allow or deny inbound network traffic to, or outbound network traffic from, several types of Azure resources.
References:
https://docs.microsoft.com/en-us/azure/virtual-network/security-overview

NEW QUESTION 8
You plan to grant the member of a new Azure AD group named crop 75099086 the right to delegate administrative access to any resource in the resource group named 7509086.
You need to create the Azure AD group and then to assign the correct to e to the group. The solution must use the principle of least privilege and minimize the number of role assignments.
What should you do from the Azure portal?

    Answer:

    Explanation: Step 1:
    Click Resource groups from the menu of services to access the Resource Groups blade
    AZ-102 dumps exhibit
    Step 2:
    Click Add (+) to create a new resource group. The Create Resource Group blade appears. Enter corp7509086 as the Resource group name, and click the Create button.
    AZ-102 dumps exhibit
    Step 3: Select Create.
    Your group is created and ready for you to add members. Now we need to assign a role to this resource group scope. Step 4:
    Choose the newly created Resource group, and Access control (IAM) to see the current list of role assignments at the resource group scope. Click +Add to open the Add permissions pane.
    AZ-102 dumps exhibit
    Step 5:
    In the Role drop-down list, select a role Delegate administration, and select Assign access to: resource group corp7509086
    AZ-102 dumps exhibit
    References:
    https://docs.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal https://www.juniper.net/documentation/en_US/vsrx/topics/task/multi-task/security-vsrx-azuremarketplace- resource-group.html

    Case Study: 11
    Mix Questions Set E (Security Identities)

    NEW QUESTION 9
    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these Questions will not appear in the review screen.
    You have an Azure subscription named Subscription1. Subscription1 contains a resource group named RG1. RG1 contains resources that were deployed by using templates.
    You need to view the date and time when the resources were created in RG1.
    Solution: From the Subscriptions blade, you select the subscription, and then click Resource providers.
    Does this meet the goal?

    • A. Yes
    • B. No

    Answer: B

    NEW QUESTION 10
    Your company has an Azure subscription named Subscription1.
    The company also has two on-premises servers named Server1 and Server2 that run Windows Server 2021. Server1 is configured as a DNS server that has a primary DNS zone named adatum.com. Adatum.com contains 1,000 DNS records.
    You manage Server1 and Subscription1 from Server2. Server2 has the following tools installed: The DNS Manager console
    Azure PowerShell Azure CLI 2.0
    You need to move the adatum.com zone to Subscription1. The solution must minimize administrative effort.
    What should you use?

    • A. Azure PowerShell
    • B. Azure CLI
    • C. the Azure portal
    • D. the DNS Manager console

    Answer: B

    Explanation: Azure DNS supports importing and exporting zone files by using the Azure command-line interface (CLI). Zone file import is not currently supported via Azure PowerShell or the Azure portal. References: https://docs.microsoft.com/en-us/azure/dns/dns-import-export

    NEW QUESTION 11
    You have an Azure Active Directory (Azure AD) tenant named contosocloud.onmicrosoft.com. Your company has a public DNS zone for contoso.com.
    You add contoso.com as a custom domain name to Azure AD. You need to ensure that Azure can verify the domain name.
    Which type of DNS record should you create?

    • A. RRSIG
    • B. PTR
    • C. DNSKEY
    • D. TXT

    Answer: D

    Explanation: Create the TXT record. App Services uses this record only at configuration time to verify that you own the custom domain. You can delete this TXT record after your custom domain is validated and configured in App Service.
    References: https://docs.microsoft.com/en-us/azure/dns/dns-web-sites-custom-domain

    NEW QUESTION 12
    You create an Azure Storage account named contosostorage. You plan to create a file share named data.
    Users need to map a drive to the data file share from home computers that run Windows 10. Which port should be open between the home computers and the data file share?

    • A. 80
    • B. 443
    • C. 445
    • D. 3389

    Answer: C

    Explanation: Ensure port 445 is open: The SMB protocol requires TCP port 445 to be open; connections will fail if port 445 is blocked.
    References: https://docs.microsoft.com/en-us/azure/storage/files/storage-how-to-use-files-windows

    NEW QUESTION 13
    You have an Azure subscription that contains 10 virtual machines.
    You need to ensure that you receive an email message when any virtual machines are powered off, restarted, or deallocated.
    What is the minimum number of rules and action groups that you require?

    • A. three rules and three action groups
    • B. one rule and one action group
    • C. three rules and one action group
    • D. one rule and three action groups

    Answer: C

    Explanation: An action group is a collection of notification preferences defined by the user. Azure Monitor and Service
    Health alerts are configured to use a specific action group when the alert is triggered. Various alerts may use the same action group or different action groups depending on the user's requirements. References: https://docs.microsoft.com/en-us/azure/monitoring-and-diagnostics/monitoring-actiongroups

    NEW QUESTION 14
    Note: This Questions is part of a series of Questions that present the same scenario. Each questions in the series contains a unique solution that might meet the stated goals. Some questions sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a questions in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You have an Azure virtual machine named VM1. VM1 was deployed by using a custom Azure Resource Manager template named ARM1.json.
    You receive a notification that VM1 will be affected by maintenance. You need to move VM1 to a different host immediately.
    Solution: From the Overview blade, you move the virtual machine to a different resource group. Does this meet the goal?

    • A. Yes
    • B. No

    Answer: B

    Explanation: You should redeploy the VM.
    References: https://docs.microsoft.com/en-us/azure/virtual-machines/windows/redeploy-to-newnode

    NEW QUESTION 15
    HOT SPOT
    You have an Azure Active Directory (Azure AD) tenant that contains three global administrators named Admin1, Admin2, and Admin3.
    The tenant is associated to an Azure subscription. Access control for the subscription is configured as shown in the Access control exhibit. (Click the Exhibit tab.)
    AZ-102 dumps exhibit
    You sign in to the Azure portal as Admin1 and configure the tenant as shown in the Tenant exhibit. (Click the Exhibit tab.)
    AZ-102 dumps exhibit
    For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
    AZ-102 dumps exhibit

      Answer:

      Explanation: AZ-102 dumps exhibit

      NEW QUESTION 16
      You have an Azure subscription that contains the resources in the following table.
      AZ-102 dumps exhibit
      To which subnets can you apply NSG1?

      • A. the subnets on VNet2 only
      • B. the subnets on VNet1 only
      • C. the subnets on VNet2 and VNet3 only
      • D. the subnets on VNet1, VNet2, and VNet3
      • E. the subnets on VNet3 only

      Answer: E

      Explanation: All Azure resources are created in an Azure region and subscription. A resource can only be created in a virtual network that exists in the same region and subscription as the resource.
      References: https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-vnet-plandesign- arm

      NEW QUESTION 17
      You have a public load balancer that balancer ports 80 and 443 across three virtual machines. You need to direct all the Remote Desktop protocol (RDP) to VM3 only.
      What should you configure?

      • A. an inbound NAT rule
      • B. a load public balancing rule
      • C. a new public load balancer for VM3
      • D. a new IP configuration

      Answer: A

      Explanation: To port forward traffic to a specific port on specific VMs use an inbound network address translation (NAT) rule.
      Incorrect Answers:
      B: Load-balancing rule to distribute traffic that arrives at frontend to backend pool instances. References:
      https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-overview

      NEW QUESTION 18
      You need to prepare the environment to meet the authentication requirements.
      Which two actions should you perform? Each correct answer presents part of the solution. NOTE Each correct selection is worth one point.

      • A. Azure Active Directory (AD) Identity Protection and an Azure policy
      • B. a Recovery Services vault and a backup policy
      • C. an Azure Key Vault and an access policy
      • D. an Azure Storage account and an access policy

      Answer: BD

      Explanation: D: Seamless SSO works with any method of cloud authentication - Password Hash Synchronization or Pass-through Authentication, and can be enabled via Azure AD Connect.
      B: You can gradually roll out Seamless SSO to your users. You start by adding the following Azure AD URL to all or selected users' Intranet zone settings by using Group Policy in Active Directory: https://autologon.microsoftazuread-sso.com
      Incorrect Answers:
      A: Seamless SSO needs the user's device to be domain-joined, but doesn't need for the device to be Azure AD Joined.
      C: Azure AD connect does not port 8080. It uses port 443.
      E: Seamless SSO is not applicable to Active Directory Federation Services (ADFS).
      Scenario: Users in the Miami office must use Azure Active Directory Seamless Single Sign-on (Azure AD Seamless SSO) when accessing resources in Azure.
      Planned Azure AD Infrastructure include: The on-premises Active Directory domain will be synchronized to Azure AD.
      References: https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directoryaadconnect-sso-quick-start

      Recommend!! Get the Full AZ-102 dumps in VCE and PDF From 2passeasy, Welcome to Download: https://www.2passeasy.com/dumps/AZ-102/ (New 195 Q&As Version)