00:15:00

Microsoft Azure Administrator Associate Practice Test (AZ-104)

Use the form below to configure your Microsoft Azure Administrator Associate Practice Test (AZ-104). The practice test can be configured to only include certain exam objectives and domains. You can choose between 5-100 questions and set a time limit.

Logo for Microsoft Azure Administrator Associate AZ-104
Questions
Number of questions in the practice test
Free users are limited to 20 questions, upgrade to unlimited
Seconds Per Question
Determines how long you have to finish the practice test
Exam Objectives
Which exam objectives should be included in the practice test

Microsoft Azure Administrator Associate AZ-104 Information

As a candidate for this certification, you should have subject matter expertise in implementing, managing, and monitoring an organization’s Azure environment, including:

  • Virtual networks
  • Storage
  • Compute
  • Identity
  • Security
  • Governance

As an Azure administrator, you often serve as part of a larger team dedicated to implementing an organization's cloud infrastructure. You also coordinate with other roles to deliver Azure networking, security, database, application development, and DevOps solutions.

You should be familiar with:

  • Operating systems
  • Networking
  • Servers
  • Virtualization

In addition, you should have experience with:

  • PowerShell
  • Azure CLI
  • The Azure portal
  • Azure Resource Manager templates
  • Microsoft Entra ID

Skills measured

  • Manage Azure identities and governance
  • Implement and manage storage
  • Deploy and manage Azure compute resources
  • Implement and manage virtual networking
  • Monitor and maintain Azure resources

Free Microsoft Azure Administrator Associate AZ-104 Practice Test

Press start when you are ready, or press Change to modify any settings for the practice test.

  • Questions: 15
  • Time: Unlimited
  • Included Topics:
    Manage Azure identities and governance
    Implement and manage storage
    Deploy and manage Azure compute resources
    Configure and manage virtual networking
    Monitor and maintain Azure resources
Question 1 of 15

You are an Azure administrator for your organization. You need to ensure that devices running Windows 10 are automatically registered in Azure Entra ID when users sign in with their corporate credentials. Which device identity feature should you configure?

  • You selected this option

    Configure Hybrid Azure AD Join

  • You selected this option

    Configure Windows Hello for Business

  • You selected this option

    Configure Azure Entra ID Join

  • You selected this option

    Configure Azure Entra ID registered devices

Question 2 of 15

When setting up backups for an Azure App Service, which destination is used to store the backup data?

  • You selected this option

    Local storage on the App Service

  • You selected this option

    A connected GitHub repository

  • You selected this option

    An Azure SQL Database

  • You selected this option

    An Azure Blob Storage account

Question 3 of 15

You are an Azure administrator for a company. There is a virtual machine named VM1 that hosts a web application that must be accessible from the internet over port 80. The company's security policy states that virtual machines should not be assigned public addresses directly. What should you implement to meet these requirements?

  • You selected this option

    Assign a public address to the virtual network subnet containing VM1

  • You selected this option

    Set up an Azure Load Balancer to forward port 80 to VM1

  • You selected this option

    Configure an Azure Virtual Network NAT gateway

  • You selected this option

    Enable Azure Traffic Manager to route traffic to VM1

Question 4 of 15

You are an Azure Administrator for Contoso Ltd. A user named John Doe has recently changed his last name to Smith after getting married. You need to update his username and email address in Azure Entra ID to reflect his new name, while ensuring he retains access to all existing resources and group memberships. Which action should you take to accomplish this?

  • You selected this option

    Remove John Doe from all groups, create a new account for John Smith, and reassign group memberships.

  • You selected this option

    Delete John Doe's user account and create a new account for John Smith with the updated information.

  • You selected this option

    Edit John Doe's user properties in Azure Entra ID to change his name, username, and email address.

  • You selected this option

    Use the Azure AD Connect tool to synchronize changes from on-premises Active Directory.

Question 5 of 15

When creating an Azure Storage account, which configuration setting enhances security by requiring encryption for data in transit?

  • You selected this option

    Enabling Secure Transfer Required

  • You selected this option

    Configuring Shared Access Signature Tokens

  • You selected this option

    Enabling Soft Delete

  • You selected this option

    Setting Access Tier to Cool

Question 6 of 15

An organization requires control over the encryption keys used to encrypt data in their Azure Storage account. Which configuration should you implement?

  • You selected this option

    Disable storage encryption to manage encryption externally.

  • You selected this option

    Implement Advanced Threat Protection on the storage account.

  • You selected this option

    Enable storage encryption with customer-managed keys stored in Azure Key Vault.

  • You selected this option

    Enable storage encryption with Microsoft-managed keys.

Question 7 of 15

A company wants each department to receive its own invoice for Azure services consumed. What is the best way to achieve this?

  • You selected this option

    Use Azure Cost Management to allocate costs per department

  • You selected this option

    Create separate resource groups for each department

  • You selected this option

    Create separate subscriptions for each department

  • You selected this option

    Assign resource tags to categorize each department's resources

Question 8 of 15

You are tasked with implementing disaster recovery for virtual machines in Azure by replicating them to a secondary region. Before initiating replication, which resource must be created to facilitate this process?

  • You selected this option

    A Recovery Services vault

  • You selected this option

    A Network Security Group

  • You selected this option

    An Azure Storage account

  • You selected this option

    A Load Balancer

Question 9 of 15

You are an Azure administrator for your organization. You need to create a group in Azure Entra ID that can be used to assign licenses to users. Which type of group should you create?

  • You selected this option

    Create an Administrative unit

  • You selected this option

    Create a Distribution list

  • You selected this option

    Create a Security group

  • You selected this option

    Create an Office 365 group

Question 10 of 15

As an Azure Administrator, you need to diagnose connectivity issues between two virtual machines, VM1 and VM2, within the same virtual network. To troubleshoot the problem, you want to gather low-level network data between these VMs. Which Azure tool should you use to accomplish this task?

  • You selected this option

    Azure Network Watcher Packet Capture

  • You selected this option

    Azure Network Security Group

  • You selected this option

    Azure Traffic Analytics

  • You selected this option

    Azure Monitor Logs

Question 11 of 15

You need to provide a group of users with read access to data stored in an Azure Storage account using their existing credentials. Which action should you take to achieve this?

  • You selected this option

    Generate a storage account access key and share it with the users.

  • You selected this option

    Create a Shared Access Signature (SAS) token and distribute it to the users.

  • You selected this option

    Enable the 'Allow Blob public access' setting on the storage account.

  • You selected this option

    Assign the 'Storage Blob Data Reader' role to the users at the storage account level.

Question 12 of 15

Initiating an unplanned failover to a secondary region using Azure Site Recovery requires the primary site to be online.

  • You selected this option

    True

  • You selected this option

    False

Question 13 of 15

You are an Azure administrator responsible for monitoring several web applications hosted in Azure. Your organization requires that when the average page load time of any web application exceeds 2 seconds over a 10-minute period, an email notification is sent to the development team. The solution should be cost-effective and require minimal effort to maintain. Which monitoring solution should you implement?

  • You selected this option

    Install a third-party monitoring tool to track page load times and send notifications.

  • You selected this option

    Enable Application Insights for the web apps and configure an alert based on the page load time.

  • You selected this option

    Enable Azure Monitor metrics for the web apps and create an alert rule based on CPU utilization.

  • You selected this option

    Deploy a Function App to monitor the web apps and send emails when thresholds are breached.

Question 14 of 15

You manage virtual machines (VMs) in Azure that reside within a private virtual network and are not accessible from the internet. Administrators need to connect to these VMs remotely for maintenance purposes. You need to provide secure, seamless remote connectivity to these VMs without exposing them to the internet or requiring a virtual private network connection.

What should you implement?

  • You selected this option

    Assign public addresses to the VMs and restrict access using Network Security Groups (NSGs)

  • You selected this option

    Set up a site-to-site connection for administrators to access the VMs

  • You selected this option

    Deploy an Azure Bastion host in the virtual network

  • You selected this option

    Implement Azure Firewall to permit remote management traffic

Question 15 of 15

You are an Azure administrator managing resources for the finance department within a resource group. The finance team needs the ability to modify the resources, but you need to prevent accidental deletion of these resources. What should you do?

  • You selected this option

    Apply a ReadOnly lock to all resources.

  • You selected this option

    Apply a ReadOnly lock at the resource group level.

  • You selected this option

    Apply a Delete lock at the resource group level.

  • You selected this option

    Remove delete permissions from the finance team.