Microsoft Certified: Azure Administrator Associate practice questions

240 free questions with answers and explanations.

Practice test
  1. 201.An administrator needs to configure an Azure storage account to allow specific Azure virtual machines (VMs) located in a particular virtual network to access its blob containers, while blocking all other network traffic. The solution must be implemented with the least administrative effort and without exposing the storage account to the public internet. Which network access configuration should be applied?Implement and manage storage
  2. 202.A manufacturing company uses Azure File Sync to synchronize files between an on-premises Windows Server and an Azure file share. They report that changes made to files directly in the Azure file share are not immediately synchronizing back to the on-premises server. Changes made on-premises synchronize quickly. What is the most likely reason for this behavior?Implement and manage storage
  3. 203.A developer needs to create a new Azure storage account that will host a static website. The website content is expected to grow over time, and the developer wants to ensure that the storage account can scale to accommodate petabytes of data with high throughput. Which type of storage account should be created?Implement and manage storage
  4. 204.A company is hosting a public-facing web application on Azure Virtual Machines (VMs) and wants to distribute incoming web traffic across multiple instances for high availability and performance. They also need to implement SSL offloading and a Web Application Firewall (WAF) to protect against common web vulnerabilities. The solution must provide Layer 7 load balancing.Implement and manage virtual networking
  5. 205.A company is migrating its on-premises DNS infrastructure to Azure DNS. They have several public-facing websites and applications that currently use an external registrar. The company wants to host their public DNS zones in Azure DNS to manage them centrally with other Azure resources. What is the first step to host an existing public DNS domain, example.com, in Azure DNS?Implement and manage virtual networking
  6. 206.A network administrator needs to improve the security posture of an Azure Virtual Network (VNet) by ensuring that all outbound internet traffic from a specific subnet is inspected and filtered by a centralized firewall. The VNet contains multiple subnets, and only one of them requires this specific outbound filtering.Implement and manage virtual networking
  7. 207.A company has an Azure Virtual Network (VNet) in the West US 2 region and needs to deploy a highly available network virtual appliance (NVA) for advanced firewall and routing capabilities. The NVA must be deployed in an active-passive configuration to ensure high availability and automatic failover. Which Azure Load Balancer SKU supports this scenario?Implement and manage virtual networking
  8. 208.A company plans to deploy a highly available web application across multiple Azure regions. The application needs to ensure optimal routing to the closest available endpoint based on user location and maintain session affinity for specific users during their session. Which Azure networking service should you implement?Implement and manage virtual networking
  9. 209.A company is deploying a new application that consists of several stateless web servers. These web servers need to be scaled automatically based on demand and must be accessible from the internet. To ensure high availability and efficient distribution of incoming HTTP traffic, an Azure Application Gateway is configured. The backend pool of the Application Gateway needs to dynamically include new web server instances as they scale out. Which type of backend pool target should be used for the Application Gateway?Implement and manage virtual networking
  10. 210.A security auditor has identified that an Azure Virtual Network (VNet) named 'VNetHR' contains highly sensitive data. The auditor recommends restricting outbound Internet access from 'VNetHR' to only specific fully qualified domain names (FQDNs) for security updates and antivirus definitions, while blocking all other outbound Internet traffic. All internal VNet communication should remain unrestricted. Which Azure networking service should be implemented to enforce this granular outbound FQDN-based filtering?Implement and manage virtual networking
  11. 211.A company is deploying a new application in Azure that requires direct, private connectivity between Azure virtual networks (VNets) located in different regions. The application must have high throughput and low latency communication between the VNets. You need to recommend a solution that meets these requirements.Implement and manage virtual networking
  12. 212.A company is deploying a new web application on Azure and requires a highly available and scalable solution to distribute incoming HTTP/HTTPS traffic across multiple backend servers. The solution must also provide SSL offloading capabilities and integrate with Azure Web Application Firewall (WAF) for enhanced security. Which Azure networking service should be implemented?Implement and manage virtual networking
  13. 213.A company is deploying a new application that consists of several virtual machines (VMs) in an Azure Virtual Network (VNet). The application requires that all inbound internet traffic be distributed evenly across these VMs. Additionally, the application needs to be accessible via a public IP address and support TCP and UDP protocols. Which Azure networking service should you implement?Implement and manage virtual networking
  14. 214.A technician needs to connect an on-premises network to an Azure Virtual Network (VNet) securely over the public internet. The connection must use standard, industry-proven tunneling protocols, and the on-premises network has a VPN device capable of IPsec IKEv1 and IKEv2. Which Azure networking component should they use?Implement and manage virtual networking
  15. 215.An organization requires that all inbound traffic to a specific web application hosted on Azure Virtual Machines must first pass through a Web Application Firewall (WAF) to protect against common web vulnerabilities. The WAF must be integrated with a Layer 7 load balancer that provides SSL termination. The solution needs to be deployed regionally within a single Azure region. Which Azure networking service combines WAF capabilities with Layer 7 load balancing and SSL termination?Implement and manage virtual networking
  16. 216.A company is expanding its Azure footprint and needs to connect a new Azure Virtual Network (VNet) in the West US region to an existing VNet in the East US region. Both VNets have overlapping IP address spaces. Which networking solution should you implement to enable communication between resources in these VNets?Implement and manage virtual networking
  17. 217.A network administrator is designing an Azure Virtual Network (VNet) for a new application. The VNet will contain several subnets, and each subnet needs to have its own dedicated Network Security Group (NSG) to control traffic flow. The administrator wants to ensure that a specific NSG is always applied to a particular subnet, even if new VMs are added or removed from that subnet. How should the NSG be associated?Implement and manage virtual networking
  18. 218.A company is expanding its Azure environment and needs to ensure that virtual machines (VMs) in a newly created virtual network (VNet) can resolve DNS queries for both public internet resources and private Azure DNS zones. The VNet is named 'VNetProd' and has a subnet 'SubnetProd'. Which DNS configuration is required for 'VNetProd'?Implement and manage virtual networking
  19. 219.A client is deploying a new critical application in Azure that requires dedicated, private connectivity from their on-premises data center to an Azure Virtual Network. This connection must offer consistent low latency and high bandwidth, bypassing the public internet entirely. They currently have no existing ExpressRoute circuits.Implement and manage virtual networking
  20. 220.A company is deploying an internal web application on Azure Virtual Machines (VMs). The application needs to be accessible only from within the corporate network, which is connected to Azure via a Site-to-Site VPN. You must ensure that the public IP address of the web application is not discoverable from the internet and that all traffic remains within Azure's private network.Implement and manage virtual networking
  21. 221.A company has an existing Azure Virtual Network (VNet) named 'VNetHub' in a hub-spoke topology. A new spoke VNet, 'VNetSpoke01', needs to be connected to 'VNetHub' for seamless communication between resources in both VNets. This connection must be low-latency and high-bandwidth, and all traffic between the VNets should remain within the Microsoft backbone network. How should these two VNets be connected?Implement and manage virtual networking
  22. 222.A company is deploying a critical application in Azure across multiple virtual machines (VMs) within a single virtual network. To ensure high availability and distribute incoming traffic efficiently among these VMs, a Layer 4 load balancer is required. The load balancer must support both internal and internet-facing endpoints. Which Azure networking service should be used?Implement and manage virtual networking
  23. 223.A company is migrating its on-premises web application to Azure. The application's backend database is hosted on an Azure SQL Database. The security team requires that the Azure SQL Database be accessible only from the application's virtual machines (VMs) within a specific subnet, and no traffic should traverse the public internet. Which Azure networking feature should you implement to meet this requirement?Implement and manage virtual networking
  24. 224.A developer is creating a new application that will store small, frequently updated configuration files and metadata. The application needs to retrieve data quickly with low latency and support simple queries based on key-value pairs. Which Azure storage service is most suitable for this scenario?Implement and manage storage
  25. 225.A client has an existing Azure Virtual Network (VNet) named 'VNetHub' (10.1.0.0/16) in the 'West US' region, which contains an Azure Firewall. They are deploying a new VNet named 'VNetSpoke' (10.2.0.0/16) in the same region. All traffic originating from 'VNetSpoke' destined for the internet or other VNets must pass through the Azure Firewall in 'VNetHub'. Which two Azure networking configurations are required to achieve this?Implement and manage virtual networking
  26. 226.A company is migrating its on-premises file servers to Azure File Shares. The company requires that users authenticate to the Azure File Shares using their existing Active Directory (AD) domain credentials, and that permissions are managed using standard NTFS ACLs. Which authentication method should be configured for the Azure File Share?Implement and manage storage
  27. 227.An administrator needs to configure an Azure storage account to ensure that all data is accessed exclusively from specific virtual networks within Azure. No public internet access to the storage account should be allowed. Which networking feature should be implemented?Implement and manage storage
  28. 228.A company has two Azure Virtual Networks (VNets), 'VNetA' and 'VNetB', located in different Azure regions. 'VNetA' is in 'West US 2' and 'VNetB' is in 'East US'. They need to enable direct and private communication between virtual machines (VMs) in 'VNetA' and 'VNetB'. Which networking feature should you implement?Implement and manage virtual networking
  29. 229.A technician is configuring a new Azure Virtual Network (VNet) named 'VNetDev'. This VNet contains a subnet named 'AppSubnet' (10.0.1.0/24) where development application VMs will reside. The VMs in 'AppSubnet' need to access a shared file server VM in another subnet, 'FileSubnet' (10.0.2.0/24), within the same VNet. Additionally, all outbound internet traffic from 'AppSubnet' must be routed through an Azure Firewall located in 'FirewallSubnet' (10.0.0.0/24). Which combination of Azure networking features should the technician implement?Implement and manage virtual networking
  30. 230.A client has an Azure Virtual Network (VNet) named 'VNetProd' in the 'East US' region. They need to establish a secure, site-to-site VPN connection between 'VNetProd' and their on-premises data center. The on-premises VPN device supports IKEv2 and BGP. Which Azure networking gateway type should you create to facilitate this connection?Implement and manage virtual networking
  31. 231.A company is deploying a highly sensitive application on Azure Virtual Machines (VMs). The security team requires that all network traffic to and from these VMs be logged for auditing and security analysis. You need to implement a solution to capture and store this network traffic. Which Azure networking feature should you configure?Implement and manage virtual networking
  32. 232.A company is designing a highly available and scalable web application in Azure. The application will be hosted on multiple Azure Virtual Machines (VMs) and needs to distribute HTTP and HTTPS traffic based on URL path. Additionally, the application requires Web Application Firewall (WAF) capabilities to protect against common web vulnerabilities. Which Azure networking service should be used to meet these requirements?Implement and manage virtual networking
  33. 233.A company is deploying a new application that will use a custom domain name, 'app.contoso.com'. The application is hosted on an Azure App Service. You need to configure DNS resolution for this custom domain name to point to the Azure App Service. Which type of record should you create in Azure DNS?Implement and manage virtual networking
  34. 234.A pilot project involves deploying a web application with a single Azure Virtual Machine (VM) in a new Azure Virtual Network (VNet). The application needs to be accessible from the internet over HTTPS (port 443). Which is the MINIMUM number of Network Security Groups (NSGs) that must be configured to secure this VM, while allowing the required inbound traffic?Implement and manage virtual networking
  35. 235.A company is hosting a web application in Azure that serves global customers. The application stores user-generated content (images, videos) in Azure Blob Storage. To ensure high availability and disaster recovery across geographical regions, while also allowing read-only access to the secondary region, which redundancy option should be configured for the storage account?Implement and manage storage
  36. 236.An organization is deploying a geo-distributed application across multiple Azure regions. The application requires high availability and low latency for users worldwide. You need to ensure that user requests are routed to the closest healthy endpoint. Which Azure service is best suited for this requirement?Implement and manage virtual networking
  37. 237.A company is planning to deploy a new application that will store highly sensitive customer data in Azure Blob Storage. The company's security policy dictates that all data must be encrypted at rest using encryption keys that are managed and controlled solely by the company. You need to recommend a solution that meets this requirement.Implement and manage storage
  38. 238.A company is deploying a new web application on Azure. The application has a public-facing frontend and an internal API backend. Both are hosted on Azure Virtual Machines (VMs) within the same virtual network. The frontend VMs need to communicate with the API backend VMs. The API backend VMs must not be directly accessible from the internet. You need to implement a solution that distributes traffic to the API backend VMs and ensures they are not internet-facing. Which Azure networking component should you use for the API backend?Implement and manage virtual networking
  39. 239.A financial institution needs to store audit logs in Azure Blob Storage. These logs must be retained for a minimum of seven years and cannot be modified or deleted during this period, even by administrators. After seven years, the logs can be deleted. Which Azure Blob Storage feature should be used to meet these requirements?Implement and manage storage
  40. 240.A media company stores large video files in Azure Blob Storage. These files are accessed frequently for the first 30 days after upload, then rarely accessed for the next 90 days, and finally, almost never accessed but must be retained for archival purposes. You need to optimize storage costs while ensuring data availability for each access pattern. Which storage tiering strategy should you implement?Implement and manage storage