Microsoft Certified: Azure Administrator Associate practice questions
240 free questions with answers and explanations.
- 101.A developer needs to create an Azure Function App that securely accesses secrets stored in an Azure Key Vault. The Function App should authenticate to Key Vault without storing any credentials in its code or configuration files. What is the most secure and recommended method for the Function App to authenticate to the Key Vault?Manage Azure identities and governance
- 102.A multinational corporation has several Azure subscriptions organized under a top-level management group. They want to ensure that all virtual networks (VNets) deployed across these subscriptions automatically have DDoS Protection Standard enabled. Additionally, they need to prevent users from accidentally deleting critical networking resources like virtual networks and public IP addresses. Which combination of Azure features should be implemented?Manage Azure identities and governance
- 103.A company policy requires that all Azure resources deployed into a specific subscription must be tagged with 'Department' and 'CostCenter'. If these tags are missing, the resource creation should be prevented. Which Azure governance feature should be implemented to enforce this policy?Manage Azure identities and governance
- 104.A company is implementing a new Azure subscription for a project. They need to ensure that no resources within this subscription can be accidentally deleted or modified by any user, including subscription owners, for a critical production environment. Which Azure feature should be configured to prevent such accidental actions?Manage Azure identities and governance
- 105.A company uses Azure AD and has implemented a strict naming convention for all Azure resources. They want to ensure that all new resource groups created within a specific subscription (Subscription A) automatically adhere to this naming convention, which requires resource group names to start with 'rg-prod-' for production environments. Any attempt to create a resource group that violates this rule should be blocked. Which Azure feature should you use to enforce this naming convention at the time of creation?Manage Azure identities and governance
- 106.A large enterprise has a complex Azure AD environment with thousands of user accounts. They need to update a specific custom attribute, 'EmployeeID', for a group of 500 users. Performing this manually is time-consuming and error-prone. Which method is the most efficient way to achieve this bulk update?Manage Azure identities and governance
- 107.A security auditor needs read-only access to all resources within a specific Azure subscription. They should be able to view all resource configurations, logs, and security settings, but must not be able to make any changes or manage user access. Which built-in Azure role should be assigned to the security auditor at the subscription scope?Manage Azure identities and governance
- 108.A developer is building an Azure Function App that needs to securely retrieve secrets from Azure Key Vault without embedding credentials in the application code. The Function App will be deployed to an App Service Plan. Which identity solution should the developer implement?Manage Azure identities and governance
- 109.A company wants to ensure that all Azure resources deployed within a specific subscription are tagged with 'CostCenter' and 'Environment'. If a resource is deployed without these tags, it should be automatically assigned a default value for 'CostCenter' and 'Environment'. Which Azure Policy effect should be used?Manage Azure identities and governance
- 110.A company uses Azure Active Directory (Azure AD) to manage its user accounts. They recently acquired another business, and both companies use separate on-premises Active Directory forests. The goal is to synchronize user accounts from both on-premises forests into a single Azure AD tenant. What is the recommended Azure AD Connect deployment topology for this scenario?Manage Azure identities and governance
- 111.A company wants to ensure that all Azure virtual machines (VMs) deployed in a specific subscription (Subscription-Prod) are configured with a minimum of 8 GB of RAM and are located in the 'East US 2' region. Any VM deployment that does not meet these criteria should be prevented. Which Azure governance feature should be used to enforce these rules?Manage Azure identities and governance
- 112.A company is implementing a new naming convention for all Azure resources. They want to ensure that all new Virtual Machines (VMs) deployed into a specific subscription have a name that starts with 'vm-'. If a VM is deployed with a different naming pattern, the deployment should fail. Which Azure governance feature should be used to enforce this naming convention?Manage Azure identities and governance
- 113.A company has an Azure subscription and uses Azure Active Directory (Azure AD). An administrator needs to create a new custom role definition for a security auditor. This role should allow the auditor to view all security-related settings and logs across all resource groups within the subscription, but explicitly prevent them from making any changes. The auditor should also be able to review Azure AD sign-in and audit logs. Which built-in role should be used as a starting point for the custom role, and which additional permissions are needed for Azure AD logs?Manage Azure identities and governance
- 114.A company wants to delegate the ability to create new user accounts in Azure Active Directory to their Human Resources (HR) department. The HR team should only be able to create standard user accounts and assign basic user properties, but not manage administrative roles or modify existing users. Which Azure AD built-in role should be assigned to the HR team?Manage Azure identities and governance
- 115.A company wants to transfer an existing Azure subscription from one management group to another. Which of the following conditions must be met to successfully move the subscription?Manage Azure identities and governance
- 116.A company is consolidating its Azure subscriptions. They have two subscriptions, 'Dev' and 'Test', which currently reside under different Management Groups. They need to move the 'Dev' subscription to the same Management Group as 'Test' to apply a consistent set of policies. What is the prerequisite for moving an Azure subscription between Management Groups?Manage Azure identities and governance
- 117.A global organization uses Azure Active Directory (Azure AD) to manage its user accounts. Due to compliance requirements, all user accounts must have their licenses automatically assigned based on their department, and these licenses should be removed if a user leaves a specific department. Which Azure AD feature can automate this process?Manage Azure identities and governance
- 118.A global consulting firm uses Azure Active Directory (Azure AD) to manage its user identities. They have a new project requiring collaboration with external partners who use their own organizational identities. The firm needs to grant these external partners access to specific applications and data within their Azure AD tenant, but without creating full user accounts for them. Which Azure AD feature should the firm utilize to achieve this?Manage Azure identities and governance
- 119.A global company has a single Azure Active Directory (Azure AD) tenant. Due to a recent internal re-organization, certain users from the 'Sales' department need to be moved to the 'Marketing' department. This move involves updating their user attributes, specifically their `department` and `jobTitle`. The company wants to ensure that these attribute changes are applied consistently and that the users retain their existing access to applications relevant to their new department. What is the most efficient way to achieve this in Azure AD?Manage Azure identities and governance
- 120.A company is implementing a new Azure subscription for a development team. The team lead needs to be able to create, modify, and delete all resources within a specific resource group, but should NOT be able to modify access permissions (RBAC) for that resource group. Which built-in Azure RBAC role is most appropriate for the team lead?Manage Azure identities and governance
- 121.A security administrator needs to ensure that all administrative users in Azure Active Directory (Azure AD) who have highly privileged roles, such as Global Administrator or User Access Administrator, are required to use multi-factor authentication (MFA) every time they sign in, regardless of their location or device. This measure should also prevent them from using legacy authentication protocols. Which Azure AD feature is best suited to enforce these stringent security requirements?Manage Azure identities and governance
- 122.A global company uses Azure Active Directory (Azure AD) to manage its user identities. Due to a recent internal audit, the security team has mandated that all guest user accounts must be reviewed and approved every 30 days to maintain access to critical applications. Which Azure AD feature should be implemented to meet this requirement with minimal administrative overhead?Manage Azure identities and governance
- 123.A security administrator needs to ensure that only users accessing Azure resources from corporate-managed devices can access specific sensitive applications. Users from unmanaged devices should be blocked. All users are managed in Azure Active Directory. Which Azure AD feature should be configured to meet this requirement?Manage Azure identities and governance
- 124.A company wants to ensure that all Azure virtual machines (VMs) deployed in a specific subscription have a particular tag, 'Owner', populated with the name of the deploying user. If the 'Owner' tag is missing or has an incorrect value, the policy should automatically correct it during deployment. Which Azure Policy effect should the company use?Manage Azure identities and governance
- 125.A global organization has multiple Azure subscriptions structured under a top-level Management Group. They need to ensure that all virtual machines deployed across these subscriptions are automatically configured with specific diagnostic settings, including sending logs to a central Log Analytics workspace. This configuration should be applied consistently and automatically to any new or existing VM. Which Azure feature should be used?Manage Azure identities and governance
- 126.A company has an Azure subscription and wants to delegate the ability to create new resource groups to a specific group of users, but these users should not be able to manage any resources within those resource groups or delete existing resource groups. Which custom role definition should be created to meet these requirements?Manage Azure identities and governance
- 127.A global manufacturing company uses Azure AD and has multiple custom applications registered. They need to ensure that users from a specific department can only access one of these custom applications from devices that are marked as 'compliant' by Microsoft Intune. All other users should have unrestricted access to this application. Which Azure AD feature should be configured?Manage Azure identities and governance
- 128.A company is restructuring its Azure environment. They have a single Azure subscription, 'DevTestSubscription', which is currently under the 'Development' management group. All production workloads must reside in subscriptions under the 'Production' management group. You need to move 'DevTestSubscription' from the 'Development' management group to the 'Production' management group. What is the prerequisite for moving a subscription between management groups?Manage Azure identities and governance
- 129.A company wants to delegate the ability to reset passwords for standard user accounts in Azure Active Directory to their help desk team. The help desk team should NOT be able to modify any other user properties, create new users, or manage administrative accounts. Which built-in Azure AD role should be assigned to the help desk team?Manage Azure identities and governance
- 130.A company is restructuring its Azure environment. They need to move an existing Azure subscription, named 'Development-Subscription', from its current Management Group 'Dev-MG' to a new Management Group 'Prod-MG'. Which role is required at the 'Development-Subscription' scope to perform this move?Manage Azure identities and governance
- 131.A security administrator needs to grant a new auditor read-only access to all resources and their configurations across multiple Azure subscriptions within a specific Management Group. The auditor should not be able to view user sign-in logs or audit logs within Azure Active Directory. Which role assignment strategy should the administrator use?Manage Azure identities and governance
- 132.A company is migrating its on-premises applications to Azure. These applications currently use Active Directory Domain Services (AD DS) for authentication. The company wants to lift and shift these applications without modifying their authentication code. Which Azure service should they use?Manage Azure identities and governance
- 133.A company is restructuring its Azure environment. They have an existing Azure subscription named 'DevTest' that currently resides under a management group named 'Development'. They need to move the 'DevTest' subscription to another management group named 'Production' to align with new organizational guidelines. What is the minimum Azure RBAC role required on the *destination* management group ('Production') for an administrator to successfully perform this move?Manage Azure identities and governance
- 134.A global company uses Azure Active Directory (Azure AD) and has several business-critical applications. They want to ensure that users accessing these applications from untrusted locations (e.g., outside corporate network, high-risk countries) are prompted for multi-factor authentication (MFA), even if they have previously satisfied MFA within the same session. Which Azure AD feature and configuration combination should be used?Manage Azure identities and governance
- 135.A company uses Azure Active Directory (Azure AD) to manage its user accounts. They have a new requirement to ensure that all user accounts are automatically removed from all groups and their licenses are revoked when their employee status changes to 'Terminated' in the HR system. This process must be automated and efficient. Which Azure AD feature is best suited for this task?Manage Azure identities and governance
- 136.A company uses Azure Active Directory (Azure AD) and has several business-critical applications registered in its tenant. They want to implement a security measure that requires users to re-authenticate with multi-factor authentication (MFA) every 30 days when accessing these specific applications, regardless of their location or device, to reduce the risk of credential compromise. What Azure AD feature should be configured to achieve this?Manage Azure identities and governance
- 137.A company is implementing a new Azure subscription. They want to delegate the ability to create new user accounts in Azure Active Directory (Azure AD) to a specific group of help desk technicians. These technicians should only be able to create standard user accounts and reset passwords for non-administrative users. They must not be able to manage other administrative roles or delete existing users. Which built-in Azure AD role should be assigned to the help desk technicians?Manage Azure identities and governance
- 138.An administrator needs to create a new Azure AD user account for a contractor. The contractor requires temporary access to specific Azure resources for a period of 3 months. After this period, the account should automatically be disabled. Which setting should the administrator configure when creating the new user account in Azure AD?Manage Azure identities and governance
- 139.A company is implementing a new Azure subscription for a project. They need to ensure that all virtual machines deployed in this subscription are automatically configured with a specific custom DNS server IP address. Additionally, this configuration should be immutable for all existing and newly deployed VMs. Which combination of Azure governance features should be used?Manage Azure identities and governance
- 140.A company wants to synchronize user accounts from their on-premises Active Directory to Azure Active Directory. They have multiple distinct forests in their on-premises environment, and all users from these forests need to exist in a single Azure AD tenant. Which Azure AD Connect topology supports this requirement?Manage Azure identities and governance
- 141.A company is deploying a new Azure Virtual Machine (VM) that will run a specialized high-performance computing (HPC) workload. This workload requires extremely low latency access to a large amount of temporary storage that is directly attached to the VM and guarantees high throughput. Which Azure disk type is most suitable for this requirement?Deploy and manage Azure compute resources
- 142.A company is migrating a legacy application to Azure App Service. The application relies on specific environment variables that are set during startup. Additionally, the application needs to connect to an Azure SQL Database using a connection string that contains sensitive credentials. You need to configure the App Service to manage these settings securely and efficiently.Deploy and manage Azure compute resources
- 143.A company is migrating a legacy batch processing application to Azure. The application consists of several independent executables that run for varying durations (from minutes to hours) and require specific CPU and memory allocations. The company wants to minimize infrastructure management and only pay for the compute resources consumed during execution. Which Azure compute service is the most suitable for this scenario?Deploy and manage Azure compute resources
- 144.You need to update the operating system and installed applications on 50 Azure virtual machines (VMs) that are part of a Virtual Machine Scale Set (VMSS). The update process must be automated, minimize downtime, and allow for a gradual rollout to monitor for issues before applying to all instances.Deploy and manage Azure compute resources
- 145.A development team needs to deploy a containerized application to Azure. The application is stateless, has intermittent traffic, and does not require persistent storage or complex orchestration. The team prioritizes rapid deployment and minimal management overhead.Deploy and manage Azure compute resources
- 146.A solutions architect is designing a highly available and scalable web application on Azure. The application uses Azure Virtual Machine Scale Sets (VMSS) for its web servers and requires a Layer 7 load balancing solution with URL-based routing to direct traffic to different backend pools based on the request path. Which Azure service should the architect recommend?Deploy and manage Azure compute resources
- 147.An Azure Virtual Machine (VM) running a critical application is experiencing intermittent performance issues. You suspect that the VM's disk I/O operations are bottlenecking the application. You need to identify the current disk performance metrics, specifically the Read Operations Per Second (IOPS) and Write Operations Per Second (IOPS) for the OS disk and data disks. Which Azure monitoring tool should you use to gather this information?Deploy and manage Azure compute resources
- 148.You are tasked with deploying an Azure virtual machine (VM) that runs a custom application. The application requires specific network security group (NSG) rules and the installation of a custom agent after the VM is provisioned. You need to automate the VM deployment and post-deployment configuration efficiently.Deploy and manage Azure compute resources
- 149.A company is deploying a new multi-tier application to Azure. The application consists of a web front-end, a business logic tier, and a database tier. The business logic tier runs on several Azure virtual machines (VMs) that need to communicate with each other and with the database, but should not be directly accessible from the internet. You need to design the network connectivity for the business logic tier.Deploy and manage Azure compute resources
- 150.A company is deploying a new web application to Azure App Service. The application needs to connect to an Azure SQL Database instance using a private endpoint. The security team insists that all outbound connections from the App Service to the database must be routed through the virtual network to ensure network isolation and security. Which App Service networking feature should you configure?Deploy and manage Azure compute resources