Microsoft Certified: Azure Administrator Associate practice questions

240 free questions with answers and explanations.

Practice test
  1. 1.A global company uses Azure Front Door to manage traffic to their web applications hosted in multiple Azure regions. They need to ensure that if one of their primary application regions becomes unavailable, traffic is automatically routed to a healthy secondary region without manual intervention. Which Azure Front Door routing method should they configure?Monitor and maintain Azure resources
  2. 2.A company is monitoring their Azure web applications using Application Insights. They have configured an alert rule to trigger when the average response time of a specific web application exceeds 2 seconds for a continuous period of 5 minutes. They want to ensure that when this alert triggers, a specific Azure Function is automatically executed to perform a diagnostic action. Which Azure Monitor feature should be configured to integrate the alert with the Azure Function?Monitor and maintain Azure resources
  3. 3.A global enterprise uses Azure Site Recovery (ASR) to protect several critical Azure Virtual Machines (VMs) across different regions. They want to ensure that in the event of a regional outage, the failover process is automated, orchestrated, and can be tested without impacting the production environment. Which ASR feature should they configure?Monitor and maintain Azure resources
  4. 4.A company is planning to deploy Azure AD Connect. They have an existing on-premises Active Directory forest and want to ensure that user accounts created in Azure AD (cloud-only users) can also be authenticated against their on-premises Active Directory resources. Which Azure AD Connect feature or configuration is required to achieve this bi-directional authentication capability?Implement and manage hybrid identities
  5. 5.A company has configured Azure AD Connect to synchronize identities from their on-premises Active Directory. They observe that user sign-in attempts to Azure AD-integrated applications are sometimes slow, and they want a tool to monitor the health of their synchronization service and identify potential performance bottlenecks or errors. Which Azure service should they use?Implement and manage hybrid identities
  6. 6.A company is planning to implement Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure Active Directory. They have a strict security policy that prohibits inbound connections from Azure to their on-premises network. Which authentication method should they choose to ensure that users can authenticate against their on-premises Active Directory without allowing inbound connections from Azure?Implement and manage hybrid identities
  7. 7.A company has successfully deployed Azure AD Connect with Pass-through Authentication (PTA) to synchronize identities. They want to ensure high availability for the authentication service in case one of the PTA agents becomes unavailable. What is the minimum recommended number of Pass-through Authentication agents that should be deployed in the on-premises environment to achieve high availability?Implement and manage hybrid identities
  8. 8.An administrator is configuring Azure Monitor to collect performance data from several Azure Virtual Machines (VMs) running a critical application. They need to visualize CPU utilization, memory usage, and disk I/O for each VM over the last 24 hours in a single, customizable view within the Azure portal. Which Azure Monitor feature should the administrator use?Monitor and maintain Azure resources
  9. 9.A company has implemented Azure AD Connect with Pass-through Authentication (PTA). Users are reporting intermittent authentication failures to cloud applications. You check the Azure AD Connect Health portal and see that one of the PTA agents is showing an 'Inactive' status. What is the most immediate action you should take to resolve the issue for the affected agent?Implement and manage hybrid identities
  10. 10.A company has several Azure virtual machines running critical line-of-business applications. They need a solution that provides automated backup of these VMs with a daily backup policy and ensures that they can restore any individual disk from a VM without having to restore the entire VM. Which Azure Backup feature should be utilized?Monitor and maintain Azure resources
  11. 11.A small business uses Azure Backup to protect a critical file share hosted on an Azure Files storage account. They want to ensure that if the storage account is accidentally deleted, they can still recover the file share data. Which feature of Azure Backup for Azure Files provides this protection against accidental deletion of the source storage account?Monitor and maintain Azure resources
  12. 12.A company is configuring Azure AD Connect for an existing Active Directory forest. They need to ensure that user password changes made on-premises are immediately reflected in Azure Active Directory for cloud applications. Which feature of Azure AD Connect must be implemented to achieve this goal?Implement and manage hybrid identities
  13. 13.A company is using Azure Monitor to collect logs and metrics from various Azure resources. They have configured an alert rule that triggers when CPU utilization on a specific VM exceeds 90% for 5 minutes. When the alert triggers, they need to automatically send an email to the operations team, post a message to a Microsoft Teams channel, and trigger an Azure Function to perform automated remediation. Which Azure Monitor component should be configured to achieve these automated actions?Monitor and maintain Azure resources
  14. 14.A company is implementing Azure Site Recovery (ASR) for an on-premises application server running Windows Server. The server hosts several critical applications and requires application-consistent recovery points to ensure data integrity during failover. Which component is responsible for creating application-consistent snapshots for Windows machines protected by ASR?Monitor and maintain Azure resources
  15. 15.A company is utilizing Azure AD Connect to synchronize users from an on-premises Active Directory to Azure AD. They have configured Password Hash Synchronization (PHS). Recently, some users reported issues with accessing cloud applications, specifically that their password changes made on-premises are not being recognized in Azure AD. You need to identify the most likely cause of this issue.Implement and manage hybrid identities
  16. 16.A company is migrating from a legacy on-premises application that uses LDAP authentication to a modern cloud-based application that integrates with Azure AD. They need to ensure that user accounts and passwords are synchronized to Azure AD. However, they have a strict security policy prohibiting any on-premises passwords from leaving their network in any form, including hashes. Which authentication method, if any, could support this requirement while enabling cloud application access?Implement and manage hybrid identities
  17. 17.A company is migrating several on-premises SQL Server databases to Azure SQL Database. They need to implement a solution to continuously monitor the performance of these databases, specifically focusing on deadlocks and long-running queries, and provide detailed insights for performance tuning. Which Azure Monitor feature, specifically designed for database insights, should they use?Monitor and maintain Azure resources
  18. 18.A global company has multiple Active Directory forests in different geographical locations. They plan to consolidate identity management using Azure AD. They need to ensure that user identities from all forests are synchronized to a single Azure AD tenant. Which Azure AD Connect deployment topology is most suitable for this scenario?Implement and manage hybrid identities
  19. 19.A developer is building a new application that will run on Azure Kubernetes Service (AKS). They need to ensure that all application logs are centralized for analysis and troubleshooting. The logs should be retained for 90 days and be easily queryable using KQL. Which Azure service should they integrate with AKS to meet these requirements?Monitor and maintain Azure resources
  20. 20.A company is using Azure Monitor to collect logs from various Azure resources. They need to create an alert rule that triggers when the average CPU utilization of any virtual machine within a specific resource group exceeds 90% for a continuous period of 5 minutes. The alert should notify administrators via email. Which type of signal logic should be used for this alert rule?Monitor and maintain Azure resources
  21. 21.A company is implementing Azure AD Connect and plans to use Pass-through Authentication (PTA). They need to deploy PTA agents in a highly available configuration to ensure continuous authentication services. Which measure should they take to meet this requirement?Implement and manage hybrid identities
  22. 22.A company has a complex on-premises Active Directory environment with multiple forests and uses a full mesh trust topology. They plan to implement Azure AD Connect to synchronize users to a single Azure AD tenant. They need to ensure that users are represented as a single identity in Azure AD, even if their account and resource objects reside in different forests. Which Azure AD Connect feature is crucial for achieving this object consolidation?Implement and manage hybrid identities
  23. 23.A company uses Azure AD Connect to synchronize users from an on-premises Active Directory domain. They want to prevent a specific Organizational Unit (OU) containing service accounts from being synchronized to Azure AD. How can they achieve this using Azure AD Connect?Implement and manage hybrid identities
  24. 24.A company is configuring Azure AD Connect. They have users with on-premises UPNs ending in '.local' (e.g., user@contoso.local) and want these users to sign in to Azure AD with a routable UPN (e.g., user@contoso.com). They have already added 'contoso.com' as a custom domain in Azure AD. Which step is necessary in Azure AD Connect to achieve this desired UPN suffix for cloud sign-ins?Implement and manage hybrid identities
  25. 25.A financial services company uses Azure to host critical applications. They need to ensure that database backups are immutable for a period of 7 years to meet regulatory compliance. They are currently using Azure Backup for their Azure SQL Databases. Which Azure Backup feature should they enable to meet this requirement?Monitor and maintain Azure resources
  26. 26.A company is using Azure AD Connect to synchronize user identities from their on-premises Active Directory. They need to ensure that the userPrincipalName (UPN) used for signing into Azure AD matches the user's primary email address, which is stored in the 'mail' attribute in on-premises AD. The default UPN suffix in on-premises AD is 'internal.local', but their verified custom domain in Azure AD is 'contoso.com'. Which action should they take in Azure AD Connect to achieve this?Implement and manage hybrid identities
  27. 27.A company has implemented Azure AD Connect with Pass-through Authentication (PTA). They want to ensure high availability for their authentication service. What is the minimum number of Pass-through Authentication agents that should be deployed in their on-premises environment to achieve this goal?Implement and manage hybrid identities
  28. 28.A company has implemented Azure AD Connect and is synchronizing user accounts. They recently renamed an organizational unit (OU) in their on-premises Active Directory. After the next synchronization cycle, they notice that users from the renamed OU are no longer visible in Azure AD. What is the most likely reason for this issue?Implement and manage hybrid identities
  29. 29.A company is planning to implement Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure Active Directory. They require that authentication requests for cloud resources are always handled by the on-premises Active Directory domain controllers, even if a user's password hash is synchronized to Azure AD. Which authentication method should be configured in Azure AD Connect to meet this requirement?Implement and manage hybrid identities
  30. 30.A company is using Azure Monitor to gain insights into the performance and availability of their critical web application. They need to visualize aggregated performance metrics, such as average response time and request rate, for the past 24 hours in a graphical format. Which Azure Monitor tool is specifically designed for interactive charting and analysis of numerical time-series data?Monitor and maintain Azure resources
  31. 31.A company is preparing to deploy Azure AD Connect. Their on-premises Active Directory environment consists of multiple separate forests, each with its own UPN suffix and distinct user populations. They need to synchronize users from all forests into a single Azure AD tenant. What is the recommended Azure AD Connect topology for this scenario?Implement and manage hybrid identities
  32. 32.A global manufacturing company uses Azure resources across multiple regions. They want to centralize the monitoring of all their Azure resource health and service issues. Which Azure service provides a personalized view of the health of Azure services and regions they are using, along with notifications about outages and planned maintenance?Monitor and maintain Azure resources
  33. 33.A company uses Azure AD Connect with federation (AD FS) for hybrid identity. They want to monitor the health and performance of their AD FS infrastructure and ensure that users can authenticate successfully. Which Azure AD Connect component should they use for this purpose?Implement and manage hybrid identities
  34. 34.A financial services company needs to audit all management operations performed on their Azure SQL Databases, such as database creation, deletion, and permission changes. They also need to retain these audit logs for at least one year for compliance purposes. Which Azure Monitor feature should be configured to capture and retain these specific types of logs?Monitor and maintain Azure resources
  35. 35.A company is using Azure Site Recovery (ASR) to protect their on-premises physical servers to Azure. They need to ensure that the recovery point objective (RPO) for their critical applications is no more than 15 minutes. Which ASR replication policy setting directly influences the achievable RPO?Monitor and maintain Azure resources
  36. 36.A company is implementing Azure Site Recovery (ASR) to protect their on-premises Hyper-V virtual machines to Azure. They need to ensure that the initial replication of large virtual machines (VMs) is performed efficiently without consuming significant internet bandwidth. Which method should they use for the initial replication?Monitor and maintain Azure resources
  37. 37.A company is planning to migrate from an on-premises Active Directory Federation Services (AD FS) deployment to Pass-through Authentication (PTA) for their hybrid identity solution. They need to ensure a smooth transition with minimal downtime for users. Which of the following is a key step to prepare for this migration?Implement and manage hybrid identities
  38. 38.A company is planning to implement Azure AD Connect to synchronize users from their on-premises Active Directory to Azure AD. They want to ensure that user passwords are never stored in the cloud in plain text and that users can authenticate against their on-premises Active Directory domain controllers directly when accessing cloud resources. Which authentication method should they choose for Azure AD Connect?Implement and manage hybrid identities
  39. 39.A company uses Azure Monitor to collect performance metrics from their Azure virtual machines. They need to visualize trends in CPU utilization over the last 30 days and compare it against the average CPU utilization of a specific VM scale set. Which Azure Monitor feature should they use?Monitor and maintain Azure resources
  40. 40.A company is implementing Azure AD Connect and wants to ensure that all user objects synchronized from their on-premises Active Directory to Azure AD have a unique and immutable identifier. Which attribute is automatically used by Azure AD Connect for this purpose, assuming default configuration?Implement and manage hybrid identities
  41. 41.A company requires all Azure Virtual Machines (VMs) to have their operating system disks encrypted at rest. They are using Azure Backup to protect these VMs. To ensure that the restored VMs also have their OS disks encrypted, what additional component must be backed up along with the VM?Monitor and maintain Azure resources
  42. 42.A company is using Azure Monitor to track the health and performance of their application hosted on Azure App Services. They need to receive an immediate email notification if the HTTP response time of their web application exceeds 2 seconds for a sustained period of 5 minutes. Which Azure Monitor component should be configured to achieve this?Monitor and maintain Azure resources
  43. 43.A company is implementing Azure AD Connect for the first time. They have an existing on-premises Active Directory with multiple child domains and want to ensure that all user objects from all domains are synchronized to Azure AD. Which synchronization scope should they select during the Azure AD Connect configuration?Implement and manage hybrid identities
  44. 44.A company has several Azure virtual machines spread across different resource groups and subscriptions. They need to analyze performance trends, identify bottlenecks, and create custom dashboards that combine metrics and logs from these diverse sources. Which Azure Monitor component is best suited for collecting, aggregating, and providing a powerful query language for such varied data?Monitor and maintain Azure resources
  45. 45.A company is using Azure Backup for their Azure virtual machines. They have a strict compliance requirement to ensure that all backup data is stored in a geo-redundant manner, meaning it must be replicated to a secondary Azure region at a significant distance from the primary region. They also want to use the most cost-effective storage option that meets this redundancy requirement. Which storage redundancy option should they choose for their Recovery Services vault?Monitor and maintain Azure resources
  46. 46.A company has implemented Azure AD Connect with Password Hash Synchronization (PHS). They have a requirement that users must be able to change their on-premises Active Directory password from the Azure AD self-service password reset (SSPR) portal. Which Azure AD Connect feature must be enabled to allow this functionality?Implement and manage hybrid identities
  47. 47.A company is using Azure AD Connect to synchronize user accounts. They notice that some users are experiencing issues with their sign-in names (User Principal Names - UPNs) in Azure AD not matching their desired format. They want to ensure that all synchronized users have UPNs in Azure AD that match the format 'user@company.com', even if their on-premises UPN suffix is different (e.g., 'user@internal.local'). Which component of Azure AD Connect should they configure to achieve this?Implement and manage hybrid identities
  48. 48.A company is using Azure Backup to protect their critical Azure virtual machines. They discover that a VM's operating system disk needs to be restored to a previous state, but they want to keep the existing data disks and configuration. Which restore option should they choose to achieve this specific outcome?Monitor and maintain Azure resources
  49. 49.A company is using Azure AD Connect with Password Hash Synchronization (PHS) enabled. They have an on-premises security policy that requires users to change their passwords every 90 days. Users are complaining that their Azure AD passwords are not expiring, even though they change them on-premises. What is the most likely cause for this discrepancy?Implement and manage hybrid identities
  50. 50.A client has several critical Azure Virtual Machines (VMs) that host a multi-tier application. They need to configure Azure Backup for these VMs and implement a retention policy that keeps daily backups for 30 days, weekly backups for 12 weeks, and monthly backups for 24 months. Which type of backup policy in Azure Backup allows for this specific retention configuration?Monitor and maintain Azure resources