Best Quality AZ-101 Exam Questions and Answers 2019

Your success in AZ-101 Exam Questions and Answers is our sole target and we develop all our AZ-101 Exam Questions and Answers in a way that facilitates the attainment of this target. Not only is our AZ-101 Dumps material the best you can find, it is also the most detailed and the most updated. AZ-101 Exam Questions and Answers for Microsoft AZ-101 are written to the highest standards of technical accuracy.

Free demo questions for Microsoft AZ-101 Exam Dumps Below:

NEW QUESTION 1
You have an Azure subscription.
You enable multi-factor authentication for all users.
Some users report that the email applications on their mobile device cannot co browser and from Microsoft Outlook 2016 on their computer.
You need to ensure that the users can use the email applications on their mobile device. What should you instruct the users to do?
The users can access Exchange Online by using a web

  • A. Enable self-service password reset.
  • B. Create an app password.
  • C. Reset the Azure Active Directory (Azure AD) password.
  • D. Reinstall the Microsoft Authenticator app.

Answer: A

Explanation: References:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-howitworks

NEW QUESTION 2
HOTSPOT
You have an Azure Active Directory (Azure AD) tenant that contains three global administrators named Admin1, Admin2, and Admin3.
The tenant is associated to an Azure subscription. Access control for the subscription is configured as shown in the Access control exhibit. (Click the Exhibit tab.)
AZ-101 dumps exhibit
You sign in to the Azure portal as Admin1 and configure the tenant as shown in the Tenant exhibit. (Click the Exhibit tab.)
AZ-101 dumps exhibit
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
AZ-101 dumps exhibit

    Answer:

    Explanation: AZ-101 dumps exhibit

    NEW QUESTION 3
    HOTSPOT
    You have an Azure web app named WebApp1.
    You need to provide developers with a copy of WebApp1 that they can modify without affecting the production WebApp1. When the developers finish testing their changes, you must be able to switch the current line version of WebApp1 to the new version.
    Which command should you run prepare the environment? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.
    AZ-101 dumps exhibit

      Answer:

      Explanation: Box 1: New-AzureRmWebAppSlot
      The New-AzureRmWebAppSlot cmdlet creates an Azure Web App Slot in a given a resource group that uses the specified App Service plan and data center.
      Box 2: -SourceWebApp References:
      https://docs.microsoft.com/en-us/powershell/module/azurerm.websites/new-azurermwebappslot

      NEW QUESTION 4
      HOTSPOT
      You have an Azure web app named WebApp1 that runs in an Azure App Service plan named ASP1. ASP1 is based on the D1 pricing tier.
      You need to ensure that WebApp1 can be accessed only from computers on your on-premises network. The solution must minimize costs.
      What should you configure? To answer, select the appropriate options in the answer are a.
      NOTE: Each correct selection is worth one point.
      AZ-101 dumps exhibit

        Answer:

        Explanation: Box 1: B1
        B1 (Basic) would minimize cost compared P1v2 (premium) and S1 (standard). Box 2: Cross Origin Resource Sharing (CORS)
        Once you set the CORS rules for the service, then a properly authenticated request made against the service from a different domain will be evaluated to determine whether it is allowed according to the
        rules you have specified.
        Note: CORS (Cross Origin Resource Sharing) is an HTTP feature that enables a web application running under one domain to access resources in another domain. In order to reduce the possibility of cross-site scripting attacks, all modern web browsers implement a security restriction known as same-origin policy. This prevents a web page from calling APIs in a different domain. CORS provides a secure way to allow one origin (the origin domain) to call APIs in another origin.
        References:
        https://azure.microsoft.com/en-us/pricing/details/app-service/windows/ https://docs.microsoft.com/en-us/azure/cdn/cdn-cors

        NEW QUESTION 5
        HOTSPOT
        You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. You add the users in the following table.
        AZ-101 dumps exhibit
        Which user can perform each configuration? To answer, select the appropriate options in the answer area.
        NOTE: Each correct selection is worth one point.
        AZ-101 dumps exhibit

          Answer:

          Explanation: Box 1: User1 and User3 only.
          The Owner Role lets you manage everything, including access to resources.
          The Network Contributor role lets you manage networks, but not access to them. Box 2: User1 and User2 only
          The Security Admin role: In Security Center only: Can view security policies, view security states, edit security policies, view alerts and recommendations, dismiss alerts and recommendations.
          References:
          https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles

          NEW QUESTION 6
          You need to add a deployment slot named staging to an Azure web app named
          corplod@lab.LabInstance.Idn4. The solution must meet the following requirements:
          When new code is deployed to staging, the code must be swapped automatically to the production slot. Azure-related costs must be minimized.
          What should you do from the Azure portal?

            Answer:

            Explanation: Step 1:
            Locate and open the corplod@lab.LabInstance.Idn4 web app.
            1. In the Azure portal, on the left navigation panel, click Azure Active Directory.
            2. In the Azure Active Directory blade, click Enterprise applications.
            Step 2:
            Open your app's resource blade and Choose the Deployment slots option, then click Add Slot.
            AZ-101 dumps exhibit
            Step 3:
            In the Add a slot blade, give the slot a name, and select whether to clone app configuration from another existing deployment slot. Click the check mark to continue.
            The first time you add a slot, you only have two choices: clone configuration from the default slot in production or not at all.
            References:
            https://docs.microsoft.com/en-us/azure/app-service/web-sites-staged-publishing

            NEW QUESTION 7
            You plan to grant the member of a new Azure AD group named crop 75099086 the right to delegate administrative access to any resource in the resource group named 7509086.
            You need to create the Azure AD group and then to assign the correct to e to the group. The solution must use the principle of least privilege and minimize the number of role assignments.
            What should you do from the Azure portal?

              Answer:

              Explanation: Step 1:
              Click Resource groups from the menu of services to access the Resource Groups blade
              AZ-101 dumps exhibit
              Step 2:
              Click Add (+) to create a new resource group. The Create Resource Group blade appears. Enter corp7509086 as the Resource group name, and click the Create button.
              AZ-101 dumps exhibit
              Step 3:
              Select Create.
              Your group is created and ready for you to add members. Now we need to assign a role to this resource group scope. Step 4:
              Choose the newly created Resource group, and Access control (IAM) to see the current list of role assignments at the resource group scope. Click +Add to open the Add permissions pane.
              AZ-101 dumps exhibit
              Step 5:
              In the Role drop-down list, select a role Delegate administration, and select Assign access to: resource group corp7509086
              AZ-101 dumps exhibit
              References:
              https://docs.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal https://www.juniper.net/documentation/en_US/vsrx/topics/task/multi-task/security-vsrx-azure- marketplace-resource-group.html

              Case Study: 8
              Mix Questions Set E (Security Identities)

              NEW QUESTION 8
              HOTSPOT
              You have an on-premises data center and an Azure subscription. The data center contains two VPN devices. The subscription contains an Azure virtual network named VNet1. VNet1 contains a gateway subnet.
              You need to create a site-to-site VPN. The solution must ensure that is a single instance of an Azure VPN gateway fails, or a single on-premises VPN device fails, the failure will not cause an interruption that is longer than two minutes.
              What is the minimum number of public IP addresses, virtual network gateways, and local network gateways required in Azure? To answer, select the appropriate options in the answer area.
              NOTE: Each correct selection is worth one point.
              AZ-101 dumps exhibit

                Answer:

                Explanation: Box 1: 4
                Two public IP addresses in the on-premises data center, and two public IP addresses in the VNET. The most reliable option is to combine the active-active gateways on both your network and Azure, as shown in the diagram below.
                AZ-101 dumps exhibit
                Box 2: 2
                Every Azure VPN gateway consists of two instances in an active-standby configuration. For any planned maintenance or unplanned disruption that happens to the active instance, the standby instance would take over (failover) automatically, and resume the S2S VPN or VNet-to-VNet connections.
                Box 3: 2
                Dual-redundancy: active-active VPN gateways for both Azure and on-premises networks References:
                https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-highlyavailable

                NEW QUESTION 9
                Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
                After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
                You have an Azure Active Directory (Azure AD) tenant named Adatum and an Azure Subscription named Subscription1. Adatum contains a group named Developers. Subscription1 contains a resource group named Dev.
                You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group.
                Solution: On Subscription1, you assign the DevTest Labs User role to the Developers group. Does this meet the goal?

                • A. Yes
                • B. No

                Answer: B

                Explanation: DevTest Labs User role only lets you connect, start, restart, and shutdown virtual machines in your Azure DevTest Labs.
                You would need the Logic App Contributor role. References:
                https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles https://docs.microsoft.com/en-us/azure/logic-apps/logic-apps-securing-a-logic-app

                NEW QUESTION 10
                Your marketing team creates a new website that you must load balance for 99.99
                percent availability.
                You need to deploy and configure a solution for both machines in the Web-AS availability set to load balance the website over HTTP. The solution must use the load balancer your resource group.
                What should you do from the Azure portal?

                  Answer:

                  Explanation: To distribute traffic to the VMs in the availability set, a back-end address pool contains the IP addresses of the virtual NICs that are connected to the load balancer. Create the back-end address pool to include the VMs in the availability set.
                  Step 1:
                  Select All resources on the left menu, and then select LoadBalancer from the resource list. Step 2:
                  Under Settings, select Backend pools, and then select Add. Step 3:
                  On the Add a backend pool page, select the Web-AS availability set, and then select OK:
                  AZ-101 dumps exhibit
                  References:
                  https://docs.microsoft.com/en-us/azure/load-balancer/quickstart-create-basic-load-balancer-portal

                  NEW QUESTION 11
                  You plan to deploy a site-to-site VPN connection from on-premises network to your
                  Azure environment. The VPN connection will be established to the VNET01-USEA2 virtual network.
                  You need to create the required resources in Azure for the planned site-to-site VPN. The solution must minimize costs.
                  What should you do from the Azure portal?
                  NOTE: This task may a very long time to complete. You do NOT need to wait for the deployment to complete this task successfully.

                    Answer:

                    Explanation: We create a VPN gateway. Step 1:
                    On the left side of the portal page, click + and type 'Virtual Network Gateway' in search. In Results, locate and click Virtual network gateway.
                    Step 2:
                    At the bottom of the 'Virtual network gateway' page, click Create. This opens the Create virtual network gateway page.
                    Step 3:
                    On the Create virtual network gateway page, specify the values for your virtual network gateway. Gateway type: Select VPN. VPN gateways use the virtual network gateway type VPN.
                    Virtual network: Choose the existing virtual network VNET01-USEA2
                    Gateway subnet address range: You will only see this setting if you did not previously create a gateway subnet for your virtual network.
                    Step 4:
                    Select the default values for the other setting, and click create.
                    AZ-101 dumps exhibit
                    The settings are validated and you'll see the "Deploying Virtual network gateway" tile on the dashboard. Creating a gateway can take up to 45 minutes.
                    Note: This task may take a very long time to complete. You do NOT need to wait for the deployment to complete this task successfully.
                    References:
                    https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-site-to-site-resource-manager-portal

                    Case Study: 4 Contoso Case Study
                    Overview
                    Contoso, Ltd. is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York.
                    The Montreal office has 2,000 employees. The Seattle office has 1,000 employees. The New York office has 200 employees.
                    All the resources used by Contoso are hosted on-premises.
                    Contoso creates a new Azure subscription. The Azure Active Directory (Azure AD) tenant uses a domain named contoso.onmicrosoft.com. The tenant uses the P1 pricing tier.
                    Existing Environment
                    The network contains an Active Directory forest named contoso.com. All domain controllers are configured as DNS servers and host the contoso.com DNS zone.
                    Contoso has finance, human resources, sales, research, and information technology departments. Each department has an organizational unit (OU) that contains all the accounts of that respective department. All the user accounts have the department attribute set to their respective department. New users are added frequently.
                    Contoso.com contains a user named User1.
                    All the offices connect by using private links.
                    Contoso has data centers in the Montreal and Seattle offices. Each data center has a firewall that can be configured as a VPN device.
                    All infrastructure servers are virtualized. The virtualization environment contains the servers in the following table.
                    AZ-101 dumps exhibit
                    Contoso uses two web applications named App1 and App2. Each instance on each web application requires 1GB of memory.
                    The Azure subscription contains the resources in the following table.
                    AZ-101 dumps exhibit
                    The network security team implements several network security groups (NSGs).
                    Planned Changes
                    Contoso plans to implement the following changes:
                    • Deploy Azure ExpressRoute to the Montreal office.
                    • Migrate the virtual machines hosted on Server1 and Server2 to Azure.
                    • Synchronize on-premises Active Directory to Azure Active Directory (Azure AD).
                    • Migrate App1 and App2 to two Azure web apps named webApp1 and WebApp2.
                    Technical requirements
                    Contoso must meet the following technical requirements:
                    • Ensure that WebApp1 can adjust the number of instances automatically based on the load and can scale up to five instance*.
                    • Ensure that VM3 can establish outbound connections over TCP port 8080 to the applications servers in the Montreal office.
                    • Ensure that routing information is exchanged automatically between Azure and the routers in the Montreal office.
                    • Enable Azure Multi-Factor Authentication (MFA) for the users in the finance department only.
                    • Ensure that webapp2.azurewebsites.net can be accessed by using the name app2.contoso.com.
                    • Connect the New Your office to VNet1 over the Internet by using an encrypted connection.
                    • Create a workflow to send an email message when the settings of VM4 are
                    modified.
                    • Cre3te a custom Azure role named Role1 that is based on the Reader role.
                    • Minimize costs whenever possible.

                    NEW QUESTION 12
                    You have an Azure subscription named Subscription1 and two Azure Active Directory (Azure AD) tenants named Tenant1 and Tenant2.
                    Subscnption1 is associated to Tenant1 Multi-factor authentication (MFA) is enabled for all the users in Tenant1.
                    You need to enable MFA for the users in Tenant2. The solution must maintain MFA forTenant1. What should you do first?

                    • A. Transfer the administration of Subscription1 to a global administrator of Tenants.
                    • B. Configure the MFA Server setting in Tenant1.
                    • C. Create and link a subscription to Tenant2.
                    • D. Change the directory for Subscription1.

                    Answer: C

                    NEW QUESTION 13
                    Note: This question is part of a series of questions that present the same scenario
                    goals. Some question sets might have more than one correct solution, while others ion in the series contains a unique solution that might meet the stated not have a correct solution.
                    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
                    You have an Azure web app named Appl. App1 runs in an Azure App Service plan named Plan1. Plan1 is associated to the Free pricing tier.
                    You discover that App1 stops each day after running continuously for 60 minutes. You need to ensure that App1 can run continuously for the entire day.
                    Solution: You add a triggered WebJob to App1. Does this meet the goal?

                    • A. Yes
                    • B. No

                    Answer: B

                    Explanation: You need to change to Basic pricing Tier.
                    Note: The Free Tier provides 60 CPU minutes / day. This explains why App1 is stops. The Basic tier has no such cap.
                    References:
                    https://azure.microsoft.com/en-us/pricing/details/app-service/windows/

                    NEW QUESTION 14
                    A web developer creates a web application that you plan to deploy as an Azure web app.
                    Users must enter credentials to access the web application.
                    You create a new web app named WebAppl1 and deploy the web application to WebApp1.
                    You need to disable anonymous access to WebApp1. What should you configure?

                    • A. Advanced Tools
                    • B. Authentication/ Authorization
                    • C. Access control (IAM)
                    • D. Deployment credentials

                    Answer: B

                    Explanation: Anonymous access is an authentication method. It allows users to establish an anonymous connection.
                    References:
                    https://docs.microsoft.com/en-us/biztalk/core/guidelines-for-resolving-iis-permissions-problems

                    NEW QUESTION 15
                    DRAG DROP
                    You have an Azure subscription that contains the following resources:
                    • a virtual network named VNet1
                    • a replication policy named ReplPolicy1
                    • a Recovery Services vault named Vault1
                    • an Azure Storage account named Storage1
                    You have an Amazon Web Services (AWS) EC2 virtual machine named VM1 that runs Windows Server
                    You need to migrate VM1 to VNet1 by using Azure Site Recovery.
                    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
                    AZ-101 dumps exhibit

                      Answer:

                      Explanation: Step 1: Deploy an EC2 virtual machine as a configuration server Prepare source include:
                      Use an EC2 instance that's running Windows Server 2012 R2 to create a configuration server and register it with your recovery vault.
                      Configure the proxy on the EC2 instance VM you're using as the configuration server so that it can access the service URLs.
                      Step 2: Install Azure Site Recovery Unified Setup.
                      Download Microsoft Azure Site Recovery Unified Setup. You can download it to your local machine and then copy it to the VM you're using as the configuration server.
                      Step 3: Enable replication for VM1.
                      Enable replication for each VM that you want to migrate. When replication is enabled, Site Recovery automatically installs the Mobility service.
                      References:
                      https://docs.microsoft.com/en-us/azure/site-recovery/migrate-tutorial-aws-azure

                      NEW QUESTION 16
                      You have a public load balancer that balancer ports 80 and 443 across three virtual machines.
                      You need to direct all the Remote Desktop protocol (RDP) to VM3 only. What should you configure?

                      • A. an inbound NAT rule
                      • B. a load public balancing rule
                      • C. a new public load balancer for VM3
                      • D. a new IP configuration

                      Answer: A

                      Explanation: To port forward traffic to a specific port on specific VMs use an inbound network address translation (NAT) rule.
                      Incorrect Answers:
                      B: Load-balancing rule to distribute traffic that arrives at frontend to backend pool instances. References:
                      https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-overview

                      Recommend!! Get the Full AZ-101 dumps in VCE and PDF From 2passeasy, Welcome to Download: https://www.2passeasy.com/dumps/AZ-101/ (New 67 Q&As Version)