00:15:00

Microsoft Azure Administrator Associate Practice Test (AZ-104)

Use the form below to configure your Microsoft Azure Administrator Associate Practice Test (AZ-104). The practice test can be configured to only include certain exam objectives and domains. You can choose between 5-100 questions and set a time limit.

Logo for Microsoft Azure Administrator Associate AZ-104
Questions
Number of questions in the practice test
Free users are limited to 20 questions, upgrade to unlimited
Seconds Per Question
Determines how long you have to finish the practice test
Exam Objectives
Which exam objectives should be included in the practice test

Microsoft Azure Administrator Associate AZ-104 Information

As a candidate for this certification, you should have subject matter expertise in implementing, managing, and monitoring an organization’s Azure environment, including:

  • Virtual networks
  • Storage
  • Compute
  • Identity
  • Security
  • Governance

As an Azure administrator, you often serve as part of a larger team dedicated to implementing an organization's cloud infrastructure. You also coordinate with other roles to deliver Azure networking, security, database, application development, and DevOps solutions.

You should be familiar with:

  • Operating systems
  • Networking
  • Servers
  • Virtualization

In addition, you should have experience with:

  • PowerShell
  • Azure CLI
  • The Azure portal
  • Azure Resource Manager templates
  • Microsoft Entra ID

Skills measured

  • Manage Azure identities and governance
  • Implement and manage storage
  • Deploy and manage Azure compute resources
  • Implement and manage virtual networking
  • Monitor and maintain Azure resources

Free Microsoft Azure Administrator Associate AZ-104 Practice Test

Press start when you are ready, or press Change to modify any settings for the practice test.

  • Questions: 15
  • Time: Unlimited
  • Included Topics:
    Manage Azure identities and governance
    Implement and manage storage
    Deploy and manage Azure compute resources
    Configure and manage virtual networking
    Monitor and maintain Azure resources
Question 1 of 15

An organization wants to automatically assign licenses to users based on their department membership. Which Azure Entra ID feature should they use?

  • Multi-factor authentication

  • Group-based licensing

  • Device management policies

  • Conditional Access Policies

Question 2 of 15

A company wants to assign permissions to users for accessing data in a storage account without sharing account keys. Which method should they use to achieve this?

  • Integrate the storage account with Azure Active Directory

  • Use connection strings in application code

  • Distribute the storage account access keys to users

  • Use Shared Access Signatures

Question 3 of 15

In Azure, roles cannot be assigned at the subscription level to manage access to all resources within the subscription.

  • False

  • True

Question 4 of 15

Azure Entra ID, (Formerly Azure Active Directory) allows the creation of security groups that can have other groups as members.

  • False

  • True

Question 5 of 15

An Azure administrator needs to provide a contractor with the ability to manage all resources within a specific resource group but prevent them from altering access permissions. Which role assignment should the administrator use to meet this requirement?

  • Assign the Contributor role to the contractor at the resource group level

  • Assign the Reader role to the contractor at the resource group level

  • Assign the Contributor role to the contractor at the subscription level

  • Assign the Owner role to the contractor at the resource group level

Question 6 of 15

An organization stores large volumes of data in Azure Blob Storage that is rarely accessed but must be retained for compliance reasons. Retrieval times of up to several hours are acceptable when the data is required. As an Azure administrator tasked with minimizing storage costs, which storage access tier should you configure for this data?

  • Hot

  • Cool

  • Archive

  • Premium

Question 7 of 15

You want to back up several Azure virtual machines using the Azure Backup service. Which action should you perform first to begin configuring the backups?

  • Configure a backup policy in Azure Backup

  • Register the virtual machines with Azure Backup

  • Enable Azure Site Recovery for the virtual machines

  • Create a Recovery Services vault

Question 8 of 15

You need to establish a private connection from your Azure virtual network to an Azure PaaS service without exposing traffic to the public internet. Which Azure feature should you configure?

  • Public Load Balancer

  • Private Endpoint

  • Network Security Group

  • VPN Gateway

Question 9 of 15

An administrator needs to verify if TCP port 443 is accessible from an Azure virtual machine to an on-premises server and obtain ongoing insights into the connection's health. Which Azure tool should they use?

  • Traffic Analytics

  • Network Watcher Connection Monitor

  • Network Watcher IP Flow Verify

  • NSG Flow Logs

Question 10 of 15

An organization wants its users to access Azure Blob storage using their corporate credentials. Users should be able to read and write blobs but must not be able to delete any blobs. How can you configure the storage account to meet these requirements?

  • Enable identity-based access on the storage account.

  • Assign the 'Storage Blob Data Contributor' role to the users.

  • Create a custom role with read and write permissions and assign it to the users.

  • Assign the 'Storage Blob Data Reader' role to the users.

Question 11 of 15

As an Azure administrator, you need to provide temporary access to a blob storage container to a third-party vendor for one week. You also want the ability to revoke this access if necessary without regenerating the storage account keys or impacting other services. What should you do to meet these requirements?

  • Generate a shared access signature with an expiry time of one week and share it with the vendor.

  • Provide the access keys of the storage account to the vendor.

  • Create a shared access signature associated with a stored access policy on the container, and provide it to the vendor.

  • Add the vendor as a contributor to the storage container.

Question 12 of 15

Your company is deploying a new cloud-based application that requires licenses for a large number of employees. You want to ensure that when users join or leave the company, the license management process is efficient and requires minimal administrative effort. What should you configure to achieve this?

  • Enable self-service licensing for users.

  • Assign licenses to individual users manually.

  • Utilize group-based licensing.

  • Use administrative units for license distribution.

Question 13 of 15

You are an Azure administrator for a company that runs a critical application on an Azure Virtual Machine (VM) named VM1. The application requires additional storage space to store log files. You need to add a data disk to VM1 without causing any downtime. What should you do?

  • Stop VM1, attach a new data disk, and then start VM1.

  • Attach an empty managed data disk to VM1 from the Azure portal.

  • Redeploy VM1 with a larger OS disk size.

  • Deallocate VM1, add a data disk using Azure PowerShell, and then allocate VM1.

Question 14 of 15

You are an Azure administrator for Contoso Ltd. You have a virtual machine named VM1 in Resource Group A. You need to move VM1 to Resource Group B within the same subscription. When you attempt to move VM1 using the Azure portal, the operation fails with an error message. You have confirmed that both resource groups are in the same region and that you have the necessary permissions. What should you do to successfully move VM1 to Resource Group B?

  • Add your user account as an owner of Resource Group B

  • Remove any resource locks from VM1 and its associated resources

  • Change the location of VM1 to match Resource Group B

  • Deallocate VM1 before attempting the move

Question 15 of 15

You are an Azure administrator responsible for configuring backups for your company's virtual machines. The company requires that critical VMs have backups that allow recovery of daily data for the past month, with minimal impact on system performance during business hours. What should you do to meet these requirements?

  • Create a new backup policy with weekly backups, retaining backups for the past month

  • Create a new backup policy that schedules backups outside business hours, with retention set to 30 days

  • Use the default backup policy without changes

  • Modify the existing backup policy to increase retention to 90 days and schedule backups during peak hours