Microsoft Certified: Azure Administrator Associate practice questions

240 free questions with answers and explanations.

Practice test
  1. 51.A company is implementing Azure Site Recovery to protect their Azure virtual machines (VMs) by replicating them to a different Azure region. They need to ensure that the replicated VMs are powered off in the target region until a failover is initiated, to avoid unnecessary compute costs. Which setting should be configured in the replication policy or VM replication settings to achieve this?Monitor and maintain Azure resources
  2. 52.A company has a complex on-premises Active Directory environment with two separate forests, ForestA and ForestB. Both forests contain user accounts that need to be synchronized to a single Azure AD tenant. Users in ForestA should authenticate using Pass-through Authentication (PTA), while users in ForestB should use Password Hash Synchronization (PHS). Which Azure AD Connect deployment topology supports this requirement?Implement and manage hybrid identities
  3. 53.A company is using Azure AD Connect to synchronize user accounts. They recently renamed an Organizational Unit (OU) in their on-premises Active Directory where several synchronized user accounts reside. After the rename, users in that OU are reporting issues accessing Azure AD resources, and some appear to be duplicated or missing. What is the most likely reason for these issues?Implement and manage hybrid identities
  4. 54.A company wants to implement Azure Site Recovery for their on-premises physical servers to Azure. They need to ensure that the initial replication data is transferred efficiently without consuming excessive internet bandwidth. Which method is most suitable for transferring large amounts of initial replication data for physical servers?Monitor and maintain Azure resources
  5. 55.A company is implementing Azure Site Recovery (ASR) to protect their on-premises VMware virtual machines to Azure. They have configured the replication policy and installed the Mobility service on the source VMs. During the initial replication, they notice that the data transfer is significantly impacting their WAN bandwidth. They need to minimize the WAN bandwidth consumption during the initial replication phase without compromising the RTO/RPO for ongoing replication. Which method should they use for initial replication?Monitor and maintain Azure resources
  6. 56.A company is using Azure AD Connect to synchronize users from an on-premises Active Directory. They want to monitor the health of their synchronization service, including synchronization errors, agent health, and last synchronization cycle status. Which Azure AD feature should they use for this purpose?Implement and manage hybrid identities
  7. 57.A company is implementing an Azure Site Recovery solution for their on-premises VMware virtual machines to Azure. They need to ensure that the network configuration for the replicated virtual machines in Azure matches their on-premises network as closely as possible, including IP addresses and DNS settings, during a failover. Which Site Recovery component is primarily responsible for configuring the network settings of the failed-over VMs?Monitor and maintain Azure resources
  8. 58.A company is migrating from an on-premises Active Directory Federation Services (AD FS) deployment to a managed authentication method in Azure AD. They want to ensure a smooth transition with minimal user impact and retain the ability to validate user credentials against their on-premises Active Directory. Which authentication method should they choose for the migration?Implement and manage hybrid identities
  9. 59.A company is setting up Azure Backup for several Azure virtual machines. They need to ensure that backups are taken daily and retained for 30 days. Which configuration within the backup policy defines how long the daily backup recovery points are stored?Monitor and maintain Azure resources
  10. 60.A security auditor requires a company to retain all Azure Activity Log data for a period of 1 year for compliance purposes. The data needs to be stored in a cost-effective manner and be accessible for future auditing queries. Which destination should be configured in the Diagnostic Settings for the Activity Log?Monitor and maintain Azure resources
  11. 61.A company uses Azure Active Directory (Azure AD) to manage its user identities. They have a new project requiring external consultants to access specific Azure resources for a limited time. These consultants do not have existing Azure AD accounts within the company's tenant. Which feature should be used to provide these consultants with access?Manage Azure identities and governance
  12. 62.A global organization uses Azure AD to manage its user accounts. Due to compliance requirements, all user accounts created for contractors must be automatically disabled after their contract ends. The contracts typically last for 6 months. You need to implement a solution that ensures these contractor accounts are automatically disabled after 180 days from their creation date without manual intervention. How should you configure these user accounts?Manage Azure identities and governance
  13. 63.A company uses Azure Active Directory (Azure AD) to manage user identities. A new project requires a group of external contractors to access specific Azure resources. These contractors do not have existing Azure AD accounts and should not be added to the company's internal user directory. You need to create a mechanism for these contractors to authenticate and access the resources securely. Which of the following Azure AD features should you use?Manage Azure identities and governance
  14. 64.A developer is creating an Azure Function App that needs to securely access secrets stored in an Azure Key Vault. The Function App should authenticate to the Key Vault without requiring any hardcoded credentials or secrets in its code or configuration. Which identity solution should the developer implement for the Function App?Manage Azure identities and governance
  15. 65.A company is setting up a new Azure subscription for a development team. The team lead needs to be able to create and manage all Azure resources within this subscription, including virtual machines, storage accounts, and networks. However, they should not be able to manage access permissions (RBAC) for other users. Which built-in Azure role should be assigned to the team lead at the subscription scope?Manage Azure identities and governance
  16. 66.A company uses Azure Active Directory (Azure AD) with several applications registered. They want to ensure that users accessing a specific sensitive application from an untrusted network location are prompted for multi-factor authentication (MFA), even if they have previously satisfied MFA for other applications in the same session. What should you configure?Manage Azure identities and governance
  17. 67.A financial services company uses Azure Active Directory (Azure AD) to manage access to its applications. Due to strict regulatory requirements, they must ensure that all users accessing highly sensitive applications are prompted for multi-factor authentication (MFA) every time, regardless of their location or device. Other, less sensitive applications should only require MFA if accessed from an unknown location or device. Which Azure AD Conditional Access policy configuration should be implemented to meet these requirements?Manage Azure identities and governance
  18. 68.A company is implementing Azure AD Connect to synchronize on-premises Active Directory users to Azure AD. They need to ensure that only specific organizational units (OUs) are synchronized to Azure AD to limit the number of cloud identities. Which configuration option in Azure AD Connect should be used to achieve this?Manage Azure identities and governance
  19. 69.A company uses Azure Active Directory (Azure AD) to manage its user accounts. They need to implement a solution that allows external vendors to self-register for access to a specific application hosted in Azure. The vendors should be able to use their existing social media accounts (e.g., Google, Microsoft) or create a local account within the Azure AD tenant. What Azure AD feature should you configure?Manage Azure identities and governance
  20. 70.A global company uses Azure Active Directory (Azure AD) and has implemented a strict naming convention for all Azure resources. They want to ensure that all new resource groups created adhere to the pattern 'rg-[department]-[environment]-[projectname]'. If a resource group is created that does not follow this pattern, it should be automatically deleted. Which Azure Policy effect should the company use to achieve this?Manage Azure identities and governance
  21. 71.A security auditor needs read-only access to all resources within a specific Azure subscription to review configurations, but must not be able to modify or deploy any resources. The auditor also needs to view all Azure AD user and group properties. Which two built-in roles, when combined, would grant the minimum necessary permissions?Manage Azure identities and governance
  22. 72.A developer needs to deploy an Azure Function App that requires access to a Storage Account. The Function App should authenticate to the Storage Account without using hardcoded credentials or secrets. Which Azure AD feature should the developer configure for the Function App?Manage Azure identities and governance
  23. 73.A company has a multi-subscription Azure environment managed under a single management group. They want to ensure that all new virtual machines deployed in any subscription within this management group automatically have a specific Azure Monitor Log Analytics workspace configured for diagnostic logging. What is the most efficient way to achieve this consistent configuration across all future deployments?Manage Azure identities and governance
  24. 74.A company has several Azure subscriptions, and they want to ensure consistent naming conventions for all resource groups across these subscriptions. Specifically, all resource groups must start with the prefix 'rg-' followed by the environment name (e.g., 'prod', 'dev', 'test') and then a descriptive name. Any attempt to create a resource group that does not follow this convention should be blocked. Which Azure feature should be implemented?Manage Azure identities and governance
  25. 75.A company is implementing a new Azure subscription for a development team. The team lead needs to be able to create, modify, and delete all resources within the subscription, including virtual machines, storage accounts, and networking components. However, the team lead should NOT be able to manage access to resources (i.e., assign or remove roles) or manage billing. Which built-in Azure role should be assigned to the team lead?Manage Azure identities and governance
  26. 76.A company recently acquired another business. Both companies use separate on-premises Active Directory forests. The acquired company's users need to access resources in the acquiring company's Azure Active Directory (Azure AD) tenant. The acquiring company wants to consolidate identity management into a single Azure AD tenant while keeping both on-premises Active Directory forests operational for their respective domains. Which Azure AD Connect configuration supports this scenario?Manage Azure identities and governance
  27. 77.A client has an Azure subscription and several resource groups. They want to ensure that all resources deployed into a specific resource group named 'ProdAppRG' are automatically tagged with 'Environment: Production' and 'CostCenter: 12345'. This tagging should be mandatory and applied without manual intervention. Which Azure feature should the client use?Manage Azure identities and governance
  28. 78.A company is restructuring its Azure environment. They have a single Azure subscription, 'DevSubscription', which is currently under a management group named 'Development'. They need to move 'DevSubscription' to a new management group named 'Production' to align with new organizational policies. Which role at the root scope (/) is required for a user to perform this subscription move?Manage Azure identities and governance
  29. 79.A company is migrating its legacy applications to Azure. These applications currently rely on traditional LDAP and Kerberos authentication against an on-premises Active Directory Domain Services (AD DS) environment. The company wants to move these applications to Azure IaaS VMs and ensure they can authenticate against a managed domain service in Azure without requiring a domain controller to be deployed and managed by the company. Which Azure AD feature should be implemented?Manage Azure identities and governance
  30. 80.A company uses Azure Active Directory (Azure AD) to manage its user identities. Due to a recent internal audit, they need to ensure that all users who have not logged in for more than 90 days are automatically disabled within Azure AD. Which Azure AD feature should the administrator configure to meet this requirement?Manage Azure identities and governance
  31. 81.A company wants to implement a multi-factor authentication (MFA) policy that applies to all users accessing financial applications, but only when they are outside the corporate network. Users accessing these applications from within the corporate network should not be prompted for MFA. Which Azure AD feature is best suited for this scenario?Manage Azure identities and governance
  32. 82.A developer needs to deploy an Azure Function App that requires access to an Azure Key Vault to retrieve secrets. The Function App should authenticate to Key Vault without storing any credentials in its code or configuration files. Which method should the developer use to achieve this secure authentication?Manage Azure identities and governance
  33. 83.A company wants to ensure that all newly created Azure storage accounts within a specific subscription automatically have encryption at rest configured with customer-managed keys (CMK) from an Azure Key Vault. If a storage account is created without CMK, it should be flagged as non-compliant, and the deployment should be allowed to proceed. What Azure Policy effect should be used?Manage Azure identities and governance
  34. 84.A company wants to ensure that all virtual machines (VMs) deployed in a specific Azure subscription are automatically configured with a particular network security group (NSG). This NSG must be applied to every new VM's network interface upon creation. Which Azure Policy effect should be used to achieve this automatic configuration?Manage Azure identities and governance
  35. 85.A developer is building an Azure Function App that needs to securely access data stored in an Azure SQL Database. The Function App should authenticate to the SQL Database without storing any credentials (like connection strings with username/password) in its code or configuration files. The solution must follow the principle of least privilege. What is the most secure and recommended method for the Function App to authenticate to the Azure SQL Database?Manage Azure identities and governance
  36. 86.A security auditor needs read-only access to review all resources, configurations, and logs across a specific Azure subscription. The auditor should not be able to make any changes. Additionally, the auditor needs to view user and group properties within Azure Active Directory. Which combination of built-in Azure roles should be assigned?Manage Azure identities and governance
  37. 87.A global organization has multiple Azure subscriptions structured under a top-level Management Group. They want to enforce a policy that automatically deploys a specific Azure Monitor Log Analytics workspace to any new resource group created within these subscriptions if one doesn't already exist. Which Azure Policy effect should be used to achieve this?Manage Azure identities and governance
  38. 88.A client is migrating their on-premises services to Azure. They have several legacy applications that require LDAP authentication and integration with their existing on-premises Active Directory Domain Services (AD DS). The client wants to avoid deploying and managing domain controllers in Azure IaaS VMs. Which Azure service should be recommended to facilitate this migration while meeting the authentication requirements?Manage Azure identities and governance
  39. 89.A security administrator needs to grant a new auditor read-only access to all resources and their configurations within a specific Azure subscription. The auditor also needs to view Azure Active Directory (Azure AD) user and group properties for auditing purposes. Which combination of Azure built-in roles should be assigned?Manage Azure identities and governance
  40. 90.A developer is building an Azure Function App that needs to securely access secrets stored in an Azure Key Vault. The Function App should authenticate to Key Vault without requiring secrets or connection strings in its code or configuration. What authentication method should the developer implement?Manage Azure identities and governance
  41. 91.A global organization uses Azure Active Directory (Azure AD) with multiple custom applications registered. They need to ensure that users are prompted for multi-factor authentication (MFA) only when they access these custom applications from outside the corporate network, but not when accessing from within the corporate network. Which Azure AD feature should be configured?Manage Azure identities and governance
  42. 92.A company has several Azure subscriptions organized under a Management Group. They want to ensure that a specific set of Azure Policies and RBAC assignments are consistently applied to all current and future subscriptions within this Management Group. Which Azure governance feature provides a way to package these artifacts and deploy them repeatedly?Manage Azure identities and governance
  43. 93.A company uses Azure Active Directory (Azure AD) to manage its user accounts. They have a global directory with thousands of users. Due to a recent organizational change, several user accounts need to have their 'Department' attribute updated to a new value. This change affects approximately 500 users. What is the most efficient method to perform this bulk update?Manage Azure identities and governance
  44. 94.A global company has multiple Azure subscriptions organized under a management group. They want to ensure that all virtual machines (VMs) deployed in a specific subscription, regardless of who deploys them, automatically have a specific custom tag named 'CostCenter' with a default value of 'Unknown' if the tag is not explicitly provided during deployment. What Azure feature should you use?Manage Azure identities and governance
  45. 95.A company recently acquired another business. They need to integrate the acquired company's on-premises Active Directory users into their existing Azure AD tenant. The acquired company's Active Directory has a different domain name and uses a separate forest. Which Azure AD Connect topology should be implemented to synchronize users from both forests into a single Azure AD tenant?Manage Azure identities and governance
  46. 96.A manufacturing company has multiple Azure subscriptions organized under a management group. They want to ensure a consistent configuration of Azure Key Vaults across all subscriptions within this management group, specifically enforcing a minimum key length for all newly created keys. Additionally, they need to prevent the deletion of any Key Vaults once deployed. Which two Azure governance features should they combine to meet these requirements?Manage Azure identities and governance
  47. 97.A large enterprise uses Azure Active Directory (Azure AD) to manage thousands of user accounts. Due to a recent internal reorganization, many users have had their department and cost center information changed. An administrator needs to efficiently update these attributes for a large number of users in Azure AD. Which method is the most efficient for performing this bulk update?Manage Azure identities and governance
  48. 98.A company has several Azure subscriptions, and they want to ensure that all resources deployed within these subscriptions are tagged with 'CostCenter' and 'Environment'. These tags are crucial for cost management and resource organization. They need a solution that automatically adds these tags if they are missing or updates them if they have incorrect values, without preventing resource deployment. Which Azure Policy effect should they use?Manage Azure identities and governance
  49. 99.An organization has several Azure subscriptions and uses a management group hierarchy. They want to ensure that all new resource groups created within a specific management group automatically inherit a set of tags for cost allocation purposes. Which Azure governance feature should be used to achieve this?Manage Azure identities and governance
  50. 100.A global company has multiple Azure subscriptions organized under a management group named 'Corporate'. They need to ensure that all virtual machines across these subscriptions are deployed with a specific set of security extensions and diagnostic settings. Furthermore, they want to standardize the deployment of network security groups (NSGs) for all new subnets. This standardization should be applied consistently and automatically across all present and future subscriptions within the 'Corporate' management group. Which Azure service is best suited for this comprehensive, multi-resource and multi-subscription standardization?Manage Azure identities and governance