1. A company is monitoring their Azure web applications using Application Insights. They have configured an alert rule to trigger when the average response time of a specific web application exceeds 2 seconds for a continuous period of 5 minutes. They want to ensure that when this alert triggers, a specific Azure Function is automatically executed to perform a diagnostic action. Which Azure Monitor feature should be configured to integrate the alert with the Azure Function?
Monitor and maintain Azure resources
A.Action Group
B.Log Analytics Query
C.Metric Explorer
D.Diagnostic Settings
Show answerAnswer
A. Action Group
Action Groups are collections of notification preferences and actions that can be triggered by an Azure Monitor alert. They allow you to define various actions, including sending emails, SMS, pushing to an ITSM tool, or calling an Azure Function, which directly addresses the requirement.
2. A global company uses Azure Front Door to manage traffic to their web applications hosted in multiple Azure regions. They need to ensure that if one of their primary application regions becomes unavailable, traffic is automatically routed to a healthy secondary region without manual intervention. Which Azure Front Door routing method should they configure?
Monitor and maintain Azure resources
A.Weighted
B.Latency
C.Priority
D.Session Affinity
Show answerAnswer
C. Priority
The Priority routing method in Azure Front Door allows you to assign priorities to backend pools. If the highest priority backend pool becomes unhealthy, traffic automatically fails over to the next available priority pool.
3. A global enterprise uses Azure Site Recovery (ASR) to protect several critical Azure Virtual Machines (VMs) across different regions. They want to ensure that in the event of a regional outage, the failover process is automated, orchestrated, and can be tested without impacting the production environment. Which ASR feature should they configure?
Monitor and maintain Azure resources
A.Recovery plan
B.Replication policy
C.Failover readiness checks
D.Site Recovery Vault
Show answerAnswer
A. Recovery plan
An Azure Site Recovery recovery plan allows you to orchestrate the failover of multiple VMs in a specific order, automate actions, and test the failover process without disrupting the primary environment. This directly addresses the need for automated, orchestrated, and testable failover for critical multi-VM applications.
4. A company is planning to deploy Azure AD Connect. They have an existing on-premises Active Directory forest and want to ensure that user accounts created in Azure AD (cloud-only users) can also be authenticated against their on-premises Active Directory resources. Which Azure AD Connect feature or configuration is required to achieve this bi-directional authentication capability?
Implement and manage hybrid identities
A.Seamless single sign-on
B.Pass-through authentication
C.Password writeback
D.Password hash synchronization
Show answerAnswer
C. Password writeback
Password writeback is the Azure AD Connect feature that allows password changes made in Azure AD by cloud-only users to be written back to the on-premises Active Directory. This enables cloud-only users to authenticate against on-premises resources with their Azure AD password.
5. A company has configured Azure AD Connect to synchronize identities from their on-premises Active Directory. They observe that user sign-in attempts to Azure AD-integrated applications are sometimes slow, and they want a tool to monitor the health of their synchronization service and identify potential performance bottlenecks or errors. Which Azure service should they use?
Implement and manage hybrid identities
A.Azure AD Connect Health
B.Azure Security Center
C.Azure Network Watcher
D.Azure Monitor
Show answerAnswer
A. Azure AD Connect Health
Azure AD Connect Health is specifically designed to monitor your on-premises identity infrastructure, including Azure AD Connect synchronization services, AD FS, and Active Directory Domain Services. It provides reports on synchronization errors, agent status, and performance metrics.
6. A company is planning to implement Azure AD Connect to synchronize identities from their on-premises Active Directory to Azure Active Directory. They have a strict security policy that prohibits inbound connections from Azure to their on-premises network. Which authentication method should they choose to ensure that users can authenticate against their on-premises Active Directory without allowing inbound connections from Azure?
Implement and manage hybrid identities
A.Password hash synchronization (PHS)
B.Cloud authentication with Azure AD
C.Federation with Azure AD (AD FS)
D.Pass-through authentication (PTA)
Show answerAnswer
D. Pass-through authentication (PTA)
Pass-through authentication (PTA) is the correct choice because it allows users to authenticate against their on-premises Active Directory without requiring inbound connections from Azure. It uses lightweight agents installed on-premises to handle authentication requests.
7. A company has successfully deployed Azure AD Connect with Pass-through Authentication (PTA) to synchronize identities. They want to ensure high availability for the authentication service in case one of the PTA agents becomes unavailable. What is the minimum recommended number of Pass-through Authentication agents that should be deployed in the on-premises environment to achieve high availability?
Implement and manage hybrid identities
A.Three agents
B.Four agents
C.One agent
D.Two agents
Show answerAnswer
D. Two agents
For high availability with Pass-through Authentication, it is recommended to deploy at least two authentication agents. This ensures that if one agent becomes unavailable, the other can continue to process authentication requests, preventing service disruption.
8. An administrator is configuring Azure Monitor to collect performance data from several Azure Virtual Machines (VMs) running a critical application. They need to visualize CPU utilization, memory usage, and disk I/O for each VM over the last 24 hours in a single, customizable view within the Azure portal. Which Azure Monitor feature should the administrator use?
Monitor and maintain Azure resources
A.Log Analytics workspace
B.Service Health
C.Azure Monitor workbook
D.Activity log
Show answerAnswer
C. Azure Monitor workbook
Azure Monitor workbooks provide a flexible canvas for data analysis and the creation of rich visual reports. They can combine text, analytics queries, Azure Metrics, and parameters into interactive reports, making them ideal for visualizing multiple performance metrics from various VMs in a single, customizable view.
9. A company has implemented Azure AD Connect with Pass-through Authentication (PTA). Users are reporting intermittent authentication failures to cloud applications. You check the Azure AD Connect Health portal and see that one of the PTA agents is showing an 'Inactive' status. What is the most immediate action you should take to resolve the issue for the affected agent?
Implement and manage hybrid identities
A.Restart the Azure AD Connect synchronization service on the main server.
B.Verify the service account permissions for the PTA agent.
C.Check the network connectivity from the server hosting the inactive PTA agent to Azure AD.
D.Reinstall the PTA agent on the affected server.
Show answerAnswer
C. Check the network connectivity from the server hosting the inactive PTA agent to Azure AD.
An 'Inactive' status for a PTA agent most commonly indicates a loss of connectivity to Azure AD. The most immediate and logical step is to check the network connection from that server to ensure it can reach Azure AD endpoints.
10. A company has several Azure virtual machines running critical line-of-business applications. They need a solution that provides automated backup of these VMs with a daily backup policy and ensures that they can restore any individual disk from a VM without having to restore the entire VM. Which Azure Backup feature should be utilized?
Monitor and maintain Azure resources
A.Azure VM Backup with Instant Restore
B.Azure VM Backup with Granular Disk Restore
C.Azure Backup for Files and Folders
D.Azure VM Backup with Disk Exclusion
Show answerAnswer
B. Azure VM Backup with Granular Disk Restore
Azure VM Backup allows for granular disk restore, meaning you can restore individual disks from a VM backup without needing to restore the entire virtual machine, which directly meets the requirement.
11. A small business uses Azure Backup to protect a critical file share hosted on an Azure Files storage account. They want to ensure that if the storage account is accidentally deleted, they can still recover the file share data. Which feature of Azure Backup for Azure Files provides this protection against accidental deletion of the source storage account?
Monitor and maintain Azure resources
A.Retention Lock
B.Cross-Region Restore
C.Separate Recovery Services vault
D.Soft Delete for Azure Files
Show answerAnswer
C. Separate Recovery Services vault
When you back up an Azure file share, the recovery points are stored in a Recovery Services vault. If the source storage account is accidentally deleted, the backup data in the separate Recovery Services vault remains intact and can be used to restore the file share to a new (or existing) storage account.
12. A company is configuring Azure AD Connect for an existing Active Directory forest. They need to ensure that user password changes made on-premises are immediately reflected in Azure Active Directory for cloud applications. Which feature of Azure AD Connect must be implemented to achieve this goal?
Implement and manage hybrid identities
A.Password hash synchronization
B.Password writeback
C.Azure AD Connect Health
D.Seamless single sign-on
Show answerAnswer
A. Password hash synchronization
Password hash synchronization (PHS) is the feature that synchronizes a hash of a user's password from on-premises Active Directory to Azure AD, allowing immediate reflection of password changes in the cloud.
13. A company is using Azure Monitor to collect logs and metrics from various Azure resources. They have configured an alert rule that triggers when CPU utilization on a specific VM exceeds 90% for 5 minutes. When the alert triggers, they need to automatically send an email to the operations team, post a message to a Microsoft Teams channel, and trigger an Azure Function to perform automated remediation. Which Azure Monitor component should be configured to achieve these automated actions?
Monitor and maintain Azure resources
A.Metric alert rule
B.Diagnostic settings
C.Log Analytics workspace
D.Action group
Show answerAnswer
D. Action group
An Action Group in Azure Monitor is a collection of notification preferences and actions that can be triggered by an Azure alert. It allows you to define multiple actions (email, Teams, Azure Function, etc.) to be executed when a specific alert condition is met, centralizing the response to alerts.
14. A company is implementing Azure Site Recovery (ASR) for an on-premises application server running Windows Server. The server hosts several critical applications and requires application-consistent recovery points to ensure data integrity during failover. Which component is responsible for creating application-consistent snapshots for Windows machines protected by ASR?
Monitor and maintain Azure resources
A.Azure Recovery Services Vault
B.Azure Site Recovery Process Server
C.Volume Shadow Copy Service (VSS)
D.Azure Site Recovery Configuration Server
Show answerAnswer
C. Volume Shadow Copy Service (VSS)
For Windows machines, the Volume Shadow Copy Service (VSS) is leveraged by Azure Site Recovery's Mobility Service to create application-consistent snapshots, ensuring that in-flight data is committed to disk before the snapshot is taken.
15. A company is utilizing Azure AD Connect to synchronize users from an on-premises Active Directory to Azure AD. They have configured Password Hash Synchronization (PHS). Recently, some users reported issues with accessing cloud applications, specifically that their password changes made on-premises are not being recognized in Azure AD. You need to identify the most likely cause of this issue.
Implement and manage hybrid identities
A.The user's UPN suffix does not match a verified custom domain in Azure AD.
B.The Password Hash Synchronization feature is disabled in Azure AD Connect.
C.The Azure AD Connect server is not running on a domain controller.
D.The Azure AD Connect Health agent is not installed on the synchronization server.
Show answerAnswer
B. The Password Hash Synchronization feature is disabled in Azure AD Connect.
If Password Hash Synchronization is enabled but password changes are not being recognized, the most direct cause would be that the PHS feature itself has been disabled or is not functioning correctly within Azure AD Connect.
16. A company is migrating from a legacy on-premises application that uses LDAP authentication to a modern cloud-based application that integrates with Azure AD. They need to ensure that user accounts and passwords are synchronized to Azure AD. However, they have a strict security policy prohibiting any on-premises passwords from leaving their network in any form, including hashes. Which authentication method, if any, could support this requirement while enabling cloud application access?
Implement and manage hybrid identities
A.None of the above
B.Federation with AD FS
C.Pass-through Authentication (PTA)
D.Password Hash Synchronization (PHS)
Show answerAnswer
A. None of the above
If a strict policy prohibits *any* form of on-premises passwords (including hashes) from leaving the network, then neither PHS nor PTA can be used, as PHS sends hashes to Azure AD and PTA requires agents to forward password validation requests through the internet to Azure AD. Federation (AD FS) keeps passwords on-premises but still involves sending security tokens to Azure AD for authentication, which might be deemed a 'form' of authentication information leaving the network, depending on the interpretation of 'any form'. If the policy is absolutely airtight against *any* on-premises password-derived information (even validation requests or tokens) leaving the network, then hybrid identity might not be fully achievable for on-premises accounts, or cloud-only accounts would be required.
17. A company is migrating several on-premises SQL Server databases to Azure SQL Database. They need to implement a solution to continuously monitor the performance of these databases, specifically focusing on deadlocks and long-running queries, and provide detailed insights for performance tuning. Which Azure Monitor feature, specifically designed for database insights, should they use?
Monitor and maintain Azure resources
A.Azure Monitor Metrics Explorer
B.Azure Monitor SQL Insights (preview)
C.Azure Monitor Activity Log
D.Azure Monitor Workbooks
Show answerAnswer
B. Azure Monitor SQL Insights (preview)
Azure Monitor SQL Insights (currently in preview but a key feature for this use case) provides a comprehensive, out-of-the-box monitoring solution specifically for Azure SQL Databases, Managed Instances, and SQL Servers on VMs, offering deep insights into performance metrics like deadlocks and query execution.
18. A global company has multiple Active Directory forests in different geographical locations. They plan to consolidate identity management using Azure AD. They need to ensure that user identities from all forests are synchronized to a single Azure AD tenant. Which Azure AD Connect deployment topology is most suitable for this scenario?
Implement and manage hybrid identities
A.Multiple forests, single Azure AD tenant
B.Multiple forests, multiple Azure AD tenants
C.Single forest, single Azure AD tenant
D.Single forest, multiple Azure AD tenants
Show answerAnswer
A. Multiple forests, single Azure AD tenant
The 'Multiple forests, single Azure AD tenant' topology is designed for scenarios where an organization has several Active Directory forests and wants to synchronize all user identities into one centralized Azure AD tenant for management.
19. A company is using Azure Monitor to collect logs from various Azure resources. They need to create an alert rule that triggers when the average CPU utilization of any virtual machine within a specific resource group exceeds 90% for a continuous period of 5 minutes. The alert should notify administrators via email. Which type of signal logic should be used for this alert rule?
Monitor and maintain Azure resources
A.Log Search
B.Application Insights
C.Activity Log
D.Metric
Show answerAnswer
D. Metric
CPU utilization is a performance counter collected as a metric. Azure Monitor metric alerts are designed to evaluate numeric values collected over time, which directly applies to monitoring CPU usage.
20. A company is implementing Azure AD Connect and plans to use Pass-through Authentication (PTA). They need to deploy PTA agents in a highly available configuration to ensure continuous authentication services. Which measure should they take to meet this requirement?
Implement and manage hybrid identities
A.Install the PTA agent on a domain controller in each forest.
B.Configure a load balancer in front of the PTA agents.
C.Install the PTA agent on the same server as Azure AD Connect.
D.Deploy multiple PTA agents on separate servers.
Show answerAnswer
D. Deploy multiple PTA agents on separate servers.
For high availability with Pass-through Authentication, you must deploy multiple PTA agents on separate servers. Azure AD automatically distributes authentication requests among the available agents.
21. A company has a complex on-premises Active Directory environment with multiple forests and uses a full mesh trust topology. They plan to implement Azure AD Connect to synchronize users to a single Azure AD tenant. They need to ensure that users are represented as a single identity in Azure AD, even if their account and resource objects reside in different forests. Which Azure AD Connect feature is crucial for achieving this object consolidation?
Implement and manage hybrid identities
A.Password hash synchronization
B.Attribute filtering
C.Join rules
D.Organizational unit (OU) filtering
Show answerAnswer
C. Join rules
In multi-forest scenarios, especially with account-resource forests or full mesh trusts, 'join rules' (part of synchronization rules) are crucial. They define how objects from different forests that represent the same real-world entity are identified and combined into a single metaverse object, which then synchronizes to Azure AD as a single identity.
22. A company uses Azure AD Connect to synchronize users from an on-premises Active Directory domain. They want to prevent a specific Organizational Unit (OU) containing service accounts from being synchronized to Azure AD. How can they achieve this using Azure AD Connect?
Implement and manage hybrid identities
A.Move the OU to a separate, unsynchronized forest.
B.Implement a custom synchronization rule to block the OU.
C.Exclude the OU in the Azure AD Connect wizard during configuration.
D.Configure attribute filtering in Azure AD Connect.
Show answerAnswer
C. Exclude the OU in the Azure AD Connect wizard during configuration.
During the initial configuration or by running the Azure AD Connect wizard again, you can specify which Organizational Units (OUs) from your on-premises Active Directory should be synchronized to Azure AD. This provides a straightforward way to exclude specific OUs.
23. A company is configuring Azure AD Connect. They have users with on-premises UPNs ending in '.local' (e.g., user@contoso.local) and want these users to sign in to Azure AD with a routable UPN (e.g., user@contoso.com). They have already added 'contoso.com' as a custom domain in Azure AD. Which step is necessary in Azure AD Connect to achieve this desired UPN suffix for cloud sign-ins?
Implement and manage hybrid identities
A.Configure Pass-through Authentication for all users.
B.Modify the inbound synchronization rule for the UPN attribute.
C.Enable Password Writeback in Azure AD Connect.
D.Add 'contoso.com' as an alternate UPN suffix in on-premises Active Directory.
Show answerAnswer
D. Add 'contoso.com' as an alternate UPN suffix in on-premises Active Directory.
For users to sign in with a routable UPN (like user@contoso.com) that differs from their on-premises non-routable UPN (user@contoso.local), the routable suffix must be added as an alternate UPN suffix in the on-premises Active Directory. Azure AD Connect can then synchronize this alternate UPN, or you can configure it to replace the '.local' suffix with '.com' during synchronization.
24. A financial services company uses Azure to host critical applications. They need to ensure that database backups are immutable for a period of 7 years to meet regulatory compliance. They are currently using Azure Backup for their Azure SQL Databases. Which Azure Backup feature should they enable to meet this requirement?
Monitor and maintain Azure resources
A.Backup Immutability
B.Long-Term Retention (LTR)
C.Cross Region Restore
D.Soft Delete
Show answerAnswer
A. Backup Immutability
Backup Immutability in Azure Backup prevents backups from being deleted or modified for a specified duration, which directly addresses the regulatory requirement for immutable backups.
25. A company is using Azure AD Connect to synchronize user identities from their on-premises Active Directory. They need to ensure that the userPrincipalName (UPN) used for signing into Azure AD matches the user's primary email address, which is stored in the 'mail' attribute in on-premises AD. The default UPN suffix in on-premises AD is 'internal.local', but their verified custom domain in Azure AD is 'contoso.com'. Which action should they take in Azure AD Connect to achieve this?
Implement and manage hybrid identities
A.Configure a custom synchronization rule to map 'mail' to 'userPrincipalName'.
B.Add 'contoso.com' as an alternative UPN suffix in on-premises Active Directory.
C.Disable UPN suffix validation in Azure AD.
D.Enable Password Hash Synchronization.
Show answerAnswer
A. Configure a custom synchronization rule to map 'mail' to 'userPrincipalName'.
To ensure the UPN in Azure AD matches the 'mail' attribute and uses the 'contoso.com' suffix, a custom synchronization rule is required. This rule would take the value from the 'mail' attribute (e.g., user@contoso.com) and map it to the 'userPrincipalName' attribute for Azure AD provisioning.
Azure Monitor Action Groups are reusable sets of notification preferences and actions that can be triggered by any Azure Monitor alert, enabling automated responses.
Can include email, SMS, push notifications, webhooks, ITSM, runbooks, Azure Functions.
Used across various alert types (metric, log, activity log).
An Azure Front Door routing method that directs all traffic to the primary (highest priority) healthy backend pool. If the primary becomes unhealthy, traffic automatically fails over to the next highest priority healthy backend pool.
Ideal for active/passive or active/standby disaster recovery scenarios.
Provides automatic failover based on backend health probes.
An Azure Site Recovery feature that orchestrates and automates the failover of multiple virtual machines, allowing for controlled and testable disaster recovery.
An Azure AD Connect feature that allows password changes made in Azure AD (e.g., by cloud-only users or self-service password reset) to be synchronized back to the on-premises Active Directory.
Crucial for enabling cloud-only users to authenticate against on-premises resources.
Supports self-service password reset (SSPR) for hybrid users.
Requires specific permissions for the Azure AD Connect service account in on-premises AD.
An Azure AD Connect feature that validates users' passwords directly against their on-premises Active Directory without storing passwords in Azure AD, using lightweight agents.
Provides a simple password validation for users against on-premises AD.
Requires no inbound firewall ports to the on-premises network.
Uses lightweight agents installed on-premises to process authentication requests.
To ensure continuous authentication service with Azure AD Pass-through Authentication, multiple authentication agents should be deployed on-premises to provide redundancy.
Minimum of two agents for high availability.
Agents are stateless and can be added/removed easily.
Azure AD automatically load-balances requests across available agents.
A flexible canvas in Azure Monitor for creating interactive and customizable visual reports that combine various data sources like metrics, logs, and text.
When an Azure AD Pass-through Authentication agent is unable to communicate with Azure AD, resulting in it being marked as 'Inactive' in Azure AD Connect Health.
Commonly caused by network connectivity issues (firewall, proxy, DNS).
Can also be due to the agent service being stopped or unhealthy.
Requires investigation of the server hosting the agent.
A capability of Azure Backup for virtual machines that allows users to restore individual disks or even specific files and folders from a VM backup, without needing to recover the entire virtual machine.
Reduces recovery time and resource consumption compared to full VM restore.
Azure Backup stores recovery points in a Recovery Services vault, isolating them from the source data, thus protecting against accidental deletion of the source resource.
Recovery Services vaults are independent resources.
Backup data persists even if the original resource is deleted.
Crucial for protecting against catastrophic data loss due to source deletion.
A method of hybrid identity that synchronizes a cryptographic hash of a user's password from on-premises Active Directory to Azure AD, enabling cloud authentication.
Simplest method for hybrid identity password synchronization.
Provides a form of cloud authentication.
Enables immediate reflection of on-premises password changes in Azure AD.
A collection of notification preferences and automated actions that Azure Monitor alerts can trigger, allowing for a centralized response to incidents.
A technology included in Microsoft Windows that allows backup applications to create consistent snapshots of computer files or volumes, even while they are in use, typically used for application-consistent backups and replication.
Ensures data integrity for applications by coordinating with them.
Used by Azure Site Recovery and Azure Backup for Windows VMs.
Creates a 'point-in-time' copy of data, including open files and in-memory data.
A security policy that prohibits any form of on-premises password information, including hashes or validation requests, from leaving the on-premises network.
Challenges standard hybrid identity authentication methods.
A comprehensive, unified monitoring solution within Azure Monitor for Azure SQL Database, Azure SQL Managed Instance, and SQL Server on Azure Virtual Machines, offering deep performance insights.
Provides pre-built dashboards for SQL performance.
Monitors deadlocks, expensive queries, wait statistics, etc.
Leverages Azure Monitor Logs for data collection and analysis.
A deployment configuration where Azure AD Connect synchronizes identities from multiple on-premises Active Directory forests into a single Azure Active Directory tenant.
Supports various multi-forest scenarios (e.g., full mesh, account-resource).
Requires careful planning for object consolidation and attribute flow.
Facilitates centralized identity management in Azure AD for complex on-premises environments.
Synchronization rules within Azure AD Connect that define how objects from different connected directories (e.g., multiple AD forests) are matched and combined into a single object in the metaverse.
Essential for object consolidation in multi-forest environments.
Uses attributes (e.g., mail, employeeID) to match objects.
Helps create a single, unified identity in Azure AD from disparate sources.
A feature in Azure Backup that makes backed-up data unchangeable and undeletable for a specified retention period, even by administrators, to meet regulatory and compliance requirements.
Prevents accidental or malicious deletion/modification of backups.
Configured at the Recovery Services vault level.
Essential for compliance standards requiring data retention integrity.
Configuring Azure AD Connect synchronization rules to use a specific on-premises attribute (e.g., 'mail') as the source for the userPrincipalName (UPN) in Azure AD.
Crucial when on-premises UPNs do not match desired Azure AD UPNs or primary email addresses.
Requires creating or modifying synchronization rules in the Synchronization Rules Editor.
Ensures consistent sign-in experience and proper identity representation in Azure AD.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.