AZ - 900 MSL: Practice Assessment Flashcards

1
Q

What are two characteristics of a consumption-based model? Each correct answer presents a complete solution.

[ ] high capital expenditures
[ ] no upfront costs
[ ] requires the purchase and management of the physical infrastructure
[ ] the ability to stop paying for resources that are no longer needed

A

[/] no upfront costs

[/] the ability to stop paying for resources that are no longer needed

In a consumption-based model, you do not pay for anything until you start using resources, and you only pay for what you use. If you stop using a resource, you stop paying for it. High expenditures are usually associated with the purchase of the physical infrastructure, which is not needed in a consumption-based model.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which two characteristics are common advantages of cloud computing? Each correct answer presents a complete solution.

[ ] elimination of horizontal scaling
[ ] geo-distribution
[ ] high availability
[ ] physical access to servers

A

[/] geo-distribution
[/] high availability

Cloud-based apps can provide a continuous user experience with no apparent downtime, even when things go wrong. You can deploy apps and data to regional datacenters around the globe, thereby ensuring that your customers always have the best performance in their region. Apps in cloud computing can scale vertically and horizontally. In a public cloud model, you do not get physical access to servers, as they are managed by the cloud provider.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Select the answer that correctly completes the sentence.

[Answer choice] refers to upfront costs incurred one time, such as hardware purchases.

A. A consumption-based model

B. Capital expenditures

C. Elasticity

D. Operational expenditures

A

B. Capital expenditures

Capital expenditures are one-time expenses that can be deducted over time. Operational expenditures are billed as you use services and a do not have upfront costs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which cloud deployment model are you using if you have servers physically located at your organization’s on-site datacenter, and you migrate a few of the servers to the cloud?

A. hybrid cloud

B. private cloud

C. public cloud

A

A. hybrid cloud

A hybrid cloud is a computing environment that combines a public cloud and a private cloud by allowing data and applications to be shared between them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Select the answer that correctly completes the sentence.

Increasing compute capacity for an app by adding RAM or CPUs to a virtual machine is called [answer choice].

A. disaster recovery

B. high availability

C. horizontal scaling

D. vertical scaling

A

D. vertical scaling

You scale vertically to increase compute capacity by adding RAM or CPUs to a virtual machine. Scaling horizontally increases compute capacity by adding instances of resources, such as adding virtual machines to the configuration. Disaster recovery keeps data and other assets safe in the event of a disaster. High availability minimizes downtime when things go wrong.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Select the answer that correctly completes the sentence.

Deploying and configuring cloud-based resources quickly as business requirements change is called [answer choice].

A. agility

B. elasticity

C. high availability

D. scalability

A

A. agility

Agility means that you can deploy and configure cloud-based resources quickly as app requirements change. Scalability means that you can add RAM, CPU, or entire virtual machines to a configuration. Elasticity means that you can configure cloud-based apps to take advantage of autoscaling, so apps always have the resources they need. High availability means that cloud-based apps can provide a continuous user experience with no apparent downtime, even when things go wrong.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

In which two deployment models are customers responsible for managing operating systems that host applications? Each correct answer presents a complete solution.

[ ] infrastructure as a service (IaaS)

[ ] on-premises

[ ] platform as a service (PaaS)

[ ] software as a service (SaaS)

A

[/] infrastructure as a service (IaaS)

[/] on-premises

Operating systems are managed by customers when using IaaS or an on-premises deployments. The operating systems are not accessible in PaaS and SaaS deployments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

In a platform as a service (PaaS) model, which two components are the responsibility of the cloud service provider? Each correct answer presents a complete solution.

[ ] information and data

[ ] operating system

[ ] physical network

[ ] user access

A

[/] operating system

[/] physical network

In PaaS, the cloud provider is responsible for the operating system, physical datacenter, physical hosts, and physical network. In PaaS, the customer is responsible for accounts and identities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which type of cloud service model is typically licensed through a monthly or annual subscription?

Select only one answer.

A. Infrastructure as a service (IaaS)

B. platform as a service (PaaS)

C. software as a service (SaaS)

A

C. software as a service (SaaS)

SaaS is software that is centrally hosted and managed for you and your users or customers. Usually, one version of the application is used for all customers, and it is licensed through a monthly or annual subscription. PaaS and IaaS use a consumption-based model, so you only pay for what you use.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the customer responsible for in a software as a service (SaaS) model?

Select only one answer.

A. data and access

B. storage

C. runtime

D. virtual machines

A

A. data and access

SaaS allows you to pay to use an existing application on hardware managed by a third party. You supply data and configure access. Customers are only responsible for storage in a private cloud. Customers are responsible for virtual machines and runtime in IaaS and the private cloud.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Your organization is building a custom application.

You need to focus on application development rather than configuration and management of servers.

Which cloud service model should you use?

Select only one answer.

A. infrastructure as a service (IaaS)

B. platform as a service (PaaS)

C. software as a service (SaaS)

A

B. platform as a service (PaaS)

With PaaS, users can focus on application development because the cloud provider handles all the platform management. In SaaS, the cloud provider manages all aspects of the application environment, such as virtual machines, networking resources, data storage, and applications. IaaS is the closest service model to managing physical servers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which cloud service model is used by Microsoft Office 365?

Select only one answer.

A. infrastructure as a service (IaaS)

B. platform as a service (PaaS)

C. software as a service (SaaS)

A

C. software as a service (SaaS)

SaaS allows users to connect to and use cloud-based apps over the internet. Common examples are email, calendaring, and Office tools, such as Office 365.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which cloud service model is used by Azure SQL Database?

Select only one answer.

A. infrastructure as a service (IaaS)

B. platform as a service (PaaS)

C. software as a service (SaaS)

A

B. platform as a service (PaaS)

Azure SQL Database is a PaaS database engine.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which type of cloud service are virtual networks?

Select only one answer.

A. infrastructure as a service (IaaS)

B. platform as a service (PaaS)

C. software as a service (SaaS)

A

A. infrastructure as a service (IaaS)

IaaS helps you reduce the cost and complexity of maintaining a physical server and its datacenter infrastructure. Virtual networks are part of the IaaS cloud service.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which two factors affect Azure costs? Each correct answer presents a complete solution.

Select all answers that apply.

[ ] availability zone selection

[ ] date and time of use

[ ] resource location

[ ] resource usage

A

[/] resource location

[/] resource usage

Usage meters, such as CPU time, disk size, and write operations, are used to calculate your bill for an Azure resource. Deleting or deallocating a resource means that you will no longer be billed for it. Different regions can have different associated prices. Resources cost the same no matter the time of day or the day of the week.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which two scenarios are common billing use cases for resource tags? Each correct answer presents a complete solution.

Select all answers that apply.

[ ] associating costs with different environments

[ ] categorizing costs by department

[ ] identifying lower cost regions

[ ] resizing underutilized virtual machines

A

[/] associating costs with different environments

[/] categorizing costs by department

You can use tags to categorize costs by department, such as human resources, marketing, or finance, or by environment, such as test or production. Resizing underutilized virtual machines is a good cost saving measure and provisioning resources in lower cost regions is a good practice, but resource tags do not help with this.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

You plan to build a new solution in Azure that will use platform as a service (PaaS) products.

What should you use to estimate the monthly costs?

Select only one answer.

A. Azure Advisor

B. Azure Cost Management

C. Azure Pricing calculator

D. Total Cost of Ownership (TOC) Calculator

A

C. Azure Pricing calculator

The Azure Pricing calculator allows you to estimate and configure according to your specific requirements. You will then receive a consolidated estimated price and a detailed breakdown of the costs associated with each resource you added to your solution.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which two features are available by using Azure Cost Management + Billing? Each correct answer presents a complete solution.

Select all answers that apply.

[ ] Create and manage budgets.

[ ] Estimate the total cost of ownership before resources are deployed.

[ ] Generate historical reports and forecast future usage.

[ ] Provide discounted prices when you pay in advance.

A

[/] Create and manage budgets.
[/] Generate historical reports and forecast future usage.

Azure Cost Management allows you to create and manage cost and usage budgets by monitoring resource demand trends, consumption rates, and cost patterns. It also allows you to use historical data to generate reports and forecast future usage and expenditures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

You need to associate the costs of resources to different groups within an organization without changing the location of the resources.

What should you use?

Select only one answer.

A. administrative units

B. resource groups

C. resource tags

D. subscriptions

A

C. resource tags

Resource tags can be used to group billing data and categorize costs by runtime environment, such as billing usage for virtual machines running in a production environment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What can you use to restrict the deployment of a virtual machine to a specific location?

Select only one answer.

A. Azure AD

B. Azure Policy

C. resource groups

D. resource locks

A

B. Azure Policy

Azure Policy can help to create a policy for allowed regions, which enables you to restrict the deployment of virtual machines to a specific location.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What can you use to ensure that a development team can only create virtual machines of a certain size?

Select only one answer.

A. Azure Blueprints

B. Azure Policy

C. Cloud Adoption Framework

D. Conditional Access

A

B. Azure Policy

Azure Policy enables you to define both individual policies and groups of related policies called initiatives. Azure Policy evaluates your resources and highlights resources that are not compliant with the policies you created. Azure Policy can also prevent noncompliant resources from being created.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What can you use to define the resources you want to provision in a declarative JSON format?

Select only one answer.

A. Azure CLI

B. Azure PowerShell

C. Azure Repos

D. Azure Resource Manager (ARM) templates

A

D. Azure Resource Manager (ARM) templates

By using ARM templates, you can describe the resources you want to use in a declarative JSON format.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Which management layer accepts requests from any Azure tool or API and enables you to create, update, and delete resources in an Azure account?

Select only one answer.

A. Azure CLI

B. Azure management groups

C. Azure Resource Manager (ARM)

D. Azure Sphere

A

C. Azure Resource Manager (ARM)

ARM is the deployment and management service for Azure. It provides a management layer that enables you to create, update, and delete resources in an Azure account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What should you use to access Azure Cloud Shell?

Select only one answer.

A. a web browser

B. Azure Resource Manager (ARM)

C. Microsoft Visual Studio Code

D. the command-line on a local computer

A

A. a web browser

Cloud Shell is an interactive, browser-accessible shell for managing Azure resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What can you use to manage servers across cloud platforms and on-premises environments?

Select only one answer.

A. Azure Arc

B. Azure CLI

C. Azure Monitor

D. Azure PowerShell

A

A. Azure Arc

Azure Arc simplifies governance and management by delivering a consistent multi-cloud and on-premises management platform.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

You need to review the root cause analysis (RCA) report for a service outage that occurred last week.

Where should you look for the report?

Select only one answer.

A. Azure Advisor

B. Azure Monitor

C. Azure Service Health

D. Log Analytics

A

C. Azure Service Health

After an outage, Service Health provides official incident reports called root cause analysis (RCA), which you can share with stakeholders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

You need to be notified when there are new recommendations for reducing Azure costs.

Which tool should you use?

Select only one answer.

A. Azure Advisor

B. Azure Monitor

C. Azure Service Health

D. Log Analytics

A

A. Azure Advisor

Azure Advisor evaluates Azure resources and makes recommendations to help improve reliability, security, and performance, achieve operational excellence, and reduce costs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What should you proactively review and act on to avoid service interruptions, such as service retirements and breaking changes?

Select only one answer.

A. application insights

B. Azure Monitor

C. health advisories

D. service issues

A

C. health advisories

Health advisories are issues that require that you take proactive action to avoid service interruptions, such as service retirements and breaking changes. Service issues are problems such as outages that require immediate actions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What can you use to get notification about an outage in a specific Azure region?

Select only one answer.

A. Azure Advisor

B. Azure Monitor

C. Azure Security Center

D. Azure Service Health

A

D. Azure Service Health

Service Health notifies you of Azure-related service issues, such as region-wide downtime.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What can you apply to an Azure virtual machine to ensure that users cannot change or delete the resource?

Select only one answer.

A. a lock

B. a tag

C. a user-assigned managed identity

D. Conditional Access

A

A. a lock

Incorrect: A user-assigned managed identity –– Adding an identity will not add the ability to change or delete the resource.

Correct: A lock –– A resource lock will meet both requirements.

Incorrect: A tag –– A tag will not meet the requirements.

Incorrect: Conditional Access –– Conditional Access will not meet the requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Which feature in the Microsoft Purview governance portal should you use to manage access to data sources and datasets?

Select only one answer.

A. Data Catalog

B. Data Estate Insights

C. Data Policy

D. Data Sharing

A

C. Data Policy

Incorrect: Data Catalog –– This enables data discovery.

Incorrect: Data Sharing –– This shares data within and between organizations.

Incorrect: Data Estate Insights –– This accesses data estate health.

Correct: Data Policy –– This governs access to data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Select the answer that correctly completes the sentence.

In a region pair, a region is paired with another region in the same [answer choice].

Select only one answer.

A. availability zone

B. datacenter

C. geography

D. resource group

A

C. geography

Each Azure region is always paired with another region within the same geography, such as US, Europe, or Asia, at least 300 miles away.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What is an Azure Storage account named storage001 an example of?

Select only one answer.

A. a resource

B. a resource group

C. a resource manager

D. a subscription

A

A. a resource

A resource is a manageable item that is available through Azure. Virtual machines, storage accounts, web apps, databases, and virtual networks are examples of resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Which Azure component allows you to replicate resources across a geography to ensure business continuity during a natural disaster at the primary site?

Select only one answer.

A. availability sets

B. availability zones

C. Azure Virtual Machine Scale Sets

D. region pairs

A

D. region pairs

Region pairs allow the replication of Azure resources across geographies to help ensure that a secondary region is available in case of any disaster at the primary region.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Which resource can you use to manage access, policies, and compliance across multiple subscriptions?

Select only one answer.

A. administrative units

B. management groups

C. resource groups

A

B. management groups

Management groups can be used in environments that have multiple subscriptions to streamline the application of governance conditions.

Resource groups can be used to organize Azure resources.

Administrative units are used to delegate the administration of Azure AD resources, such as users and groups.

Accounts are used to provide access to resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Select the answer that correctly completes the sentence.

[Answer choice] is the deployment and management service for Azure.

Select only one answer.

A. Azure AD

B. Azure API Management

C. Azure Monitor

D. Azure Resource Manager (ARM)

A

D. Azure Resource Manager (ARM)

ARM is the deployment and management service for Azure. It provides a management layer that enables you to create, update, and delete resources in an Azure subscription. You use management features, such as access control, resource locks, and resource tags, to secure and organize resources after deployment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Which Azure compute service can you use to deploy and manage a set of identical virtual machines?

Select only one answer.

A. availability sets

B. availability zones

C. Azure Container Instances

D. Azure Virtual Machine Scale Set

A

D. Azure Virtual Machine Scale Set

Virtual Machine Scale Sets are an Azure compute resource that you can use to deploy and manage and scale a set of identical virtual machines.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

What can you use to execute code in a serverless environment?

Select only one answer.

A. Azure Container Instances

B. Azure Functions

C. Azure Logic Apps

D. Azure Virtual Desktop

A

B. Azure Functions

Azure Functions allows you to run code as a service without having to manage the underlying platform or infrastructure. Azure Logic Apps is similar to Azure Functions, but uses predefined workflows instead of developing your own code.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Which scenario is a use case for a VPN gateway?

Select only one answer.

A. communicating between Azure resources

B. connecting an on-premises datacenter to an Azure virtual network

C. filtering outbound network traffic

D. partitioning a virtual network’s address space

A

B. connecting an on-premises datacenter to an Azure virtual network

A VPN gateway is a type of virtual network gateway. Azure VPN Gateway instances are deployed to a dedicated subnet of a virtual network. You can use them to connect on-premises datacenters to virtual networks through a Site-to-Site (S2S) VPN connection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

You need to allow resources on two different Azure virtual networks to communicate with each other.

What should you configure?

Select only one answer.

A. a network security group (NSG)

B. a point-to-site VPN

C. peering

D. service endpoints

A

C. peering

You can link virtual networks together by using virtual network peering. Peering enables resources in each virtual network to communicate with each other.

41
Q

What can you use to connect Azure resources, such as Azure SQL databases, to an Azure virtual network?

Select only one answer.

A. ExpressRoute

B. network security groups (NSGs)

C. peering

D. service endpoints

A

D. service endpoints

Service endpoints are used to expose Azure services to a virtual network, providing communication between the two. ExpressRoute is used to connect an on-premises network to Azure. NSGs allow you to configure inbound and outbound rules for virtual networks and virtual machines. Peering allows you to connect virtual networks together.

42
Q

Which two services can you use to establish network connectivity between an on-premises network and Azure resources? Each correct answer presents a complete solution.

Select all answers that apply.

[ ] Azure Bastion

[ ] Azure Firewall

[ ] Azure VPN Gateway

[ ] ExpressRoute

A

[/] Azure VPN Gateway

[/] ExpressRoute

ExpressRoute connections and Azure VPN Gateway are two services that you can use to connect an on-premises network to Azure. Bastion provides a web interface to remotely administer Azure virtual machines by using SSH/RDP. Azure Firewall is a stateful firewall service used to protect virtual networks.

43
Q

What can you use to provide Mac and Android users with access to a Windows environment that will run Windows-based applications?

Select only one answer.

A. Azure Container Instances

B. Azure Functions

C. Azure Logic Apps

D. Azure Virtual Desktop

A

D. Azure Virtual Desktop

Azure Virtual Desktop is a desktop and application virtualization service that runs in the cloud. It enables your users to use a cloud-hosted version of Windows from any location. Azure Virtual Desktop works across devices such as Windows, Mac, iOS, Android, and Linux. It works with apps that you can use to access Remote Desktops and apps. You can also use most modern browsers to access Azure Virtual Desktop-hosted experiences.

44
Q

What are two services that allow you to run applications in containers? Each correct answer presents a complete solution.

Select all answers that apply.

[ ] Azure Container Instances

[ ] Azure Functions

[ ] Azure Logic Apps

[ ] Azure Kubernetes Service (AKS)

A

[/] Azure Container Instances
[/] Azure Kubernetes Service (AKS)

Containers are a virtualization environment. Much like running multiple virtual machines on a single physical host, you can run multiple containers on a single physical or virtual host. Unlike virtual machines, you do not manage the operating system for a container.

45
Q

Which storage service should you use to store thousands of files containing text and images?

Select only one answer.

A. Azure Blob storage

B. Azure Disk Storage

C. Azure Queue Storage

D. Azure Table storage

A

A. Azure Blob storage

Azure Blob storage is an object storage solution that you can use to store massive amounts of unstructured data, such as text or binary data.

46
Q

Which two scenarios are common use cases for Azure Blob storage? Each correct answer presents a complete solution.

Select all answers that apply.

[ ] hosting ASPX files for a website

[ ] mounting a file storage share to be accessed as a virtual drive on multiple virtual machines

[ ] serving images or documents directly to a browser

[ ] storing data for backup and restore

A

[/] serving images or documents directly to a browser

[/] storing data for backup and restore

Low storage costs and unlimited file formats make blob storage a good location to store backups and archives. Blob storage can be reached from anywhere by using an internet connection. Azure Disk Storage provides disks for Azure virtual machines. Azure Files supports mounting file storage shares.

47
Q

Which Azure Blob storage service tier has the highest storage costs and the fastest access times for reading and writing data?

Select only one answer.

A. Archive

B. Cool

C. Hot

A

C. Hot

The Hot tier is optimized for storing data that is accessed frequently. The Cool access tier has a slightly lower availability SLA and higher access costs compared to hot data, which are acceptable trade-offs for lower storage costs. Archive storage stores data offline and offers the lowest storage costs, but also the highest costs to rehydrate and access data.

48
Q

Which Azure Storage service should you use to store unstructured files, such as images, that will be served on webpages?

Select only one answer.

A. Azure Blob storage

B. Azure Disk Storage

C. Azure Queue Storage

D. Azure Table storage

A

A. Azure Blob storage

Azure Blob storage is an object storage solution that you can use to store massive amounts of unstructured data, such as text or binary data.

49
Q

What can you use to allow a user to manage all the resources in a resource group?

Select only one answer.

A. Azure Key Vault

B. Azure role-based access control (RBAC)

C. resource locks

D. resource tags

A

B. Azure role-based access control (RBAC)

Azure RBAC allows you to assign a set of permissions to a user or group. Resource tags are used to locate and act on resources associated with specific workloads, environments, business units, and owners. Resource locks prevent the accidental change or deletion of a resource. Key Vault is a centralized cloud service for storing an application secrets in a single, central location.

50
Q

To which object or level is an Azure role-based access control (RBAC) role applied?

Select only one answer.

A. policy

B. resource lock

C. resource tag

D. scope

A

D. scope

An Azure RBAC role is applied to a scope, which is a resource or set of resources that the access applies to. Resource locks prevent the accidental change or deletion of a resource. Resource tags are used to locate and act on resources associated with specific workloads, environments, business units, and owners. Policies enforce different rules across resource configurations so that the configurations stay compliant with corporate standards.

51
Q

Which two attributes are characteristics of the private cloud deployment model? Each correct answer presents a complete solution.

Select all answers that apply.

[ ] Applications can be provisioned and deprovisioned quickly.

[ ] Hardware must be purchased.

[ ] Organizations only pay for what they use.

[ ] The company has complete control over physical resources and security.

A

[/] Hardware must be purchased.
[/] The company has complete control over physical resources and security.

In a private cloud, hardware must be purchased for start up and maintenance. In a private cloud, organizations control resources and security. Quick provisioning is a characteristic of the public cloud deployment model. Paying only for what is used is a characteristic of the public cloud deployment model.

52
Q

What are two basic services provided by all cloud providers? Each correct answer presents a complete solution.

Select all answers that apply.

[ ] application development

[ ] colocation

[ ] compute

[ ] storage

A

[/] compute

[/] storage

All cloud providers provide compute and storage services. Colocation is when a business rents space in a shared physical datacenter. Application development is the responsibility of the customer and is typically done either in-house or through a third party.

53
Q

What are two characteristics of the public cloud deployment model? Each correct answer presents a complete solution.

Select all answers that apply.

[ ] Computing resources are used exclusively by users from one organization.

[ ] Hardware is physically located in an organization’s on-site datacenter.

[ ] Servers and storage are owned and operated by a third-party cloud service provider.

[ ] Services are offered over the internet and are available to anyone who wants to purchase them.

A

[/] Servers and storage are owned and operated by a third-party cloud service provider.

[/] Services are offered over the internet and are available to anyone who wants to purchase them.

In a public cloud, services are offered over the internet and are available to anyone who wants to purchase them. A private cloud is limited to a single organization. Cloud resources, such as servers and storage, are owned and operated by a third-party cloud service provider and delivered over the internet. A private cloud consists of computing resources used exclusively by users from one business or organization.

54
Q

Select the answer that correctly completes the sentence.

Increasing compute capacity for an app by adding instances of resources such as virtual machines is called [answer choice].

Select only one answer.

A. disaster recovery

B. high availability

C. horizontal scaling

D. vertical scaling

A

C. horizontal scaling

Scaling horizontally increases compute capacity by adding instances of resources, such as adding virtual machines to the configuration. You scale vertically by adding RAM or CPUs to a virtual machine. Disaster recovery keeps data and other assets safe in the event of a disaster. High availability minimizes downtime when things go wrong.

55
Q

What is high availability in a public cloud environment dependent on?

Select only one answer.

A. capital expenditures

B. cloud-based backup retention limits

C. the service-level agreement (SLA) that you choose

D. the vertical scalability of an app

A

C. the service-level agreement (SLA) that you choose

Different services have different SLAs. Sometimes different tiers of the same service will offer different SLAs, which can increase or decrease the promised availability.

56
Q

Select the answer that correctly completes the sentence.

In cloud computing, [answer choice] allows you to deploy applications to regional datacenters around the world.

Select only one answer.

A. disaster recovery

B. elasticity

C. geo-location

D. high availability

A

C. geo-location

You can deploy apps and data to regional datacenters around the globe, thereby ensuring that your customers always have the best performance in their region. This is referred to as geo-distribution.

57
Q

In which cloud service model is the customer responsible for managing the operating system?

Select only one answer.

A. Infrastructure as a service (IaaS)

B. platform as a service (PaaS)

C. software as a service (SaaS)

A

A. Infrastructure as a service (IaaS)

IaaS consists of virtual machines and networking provided by the cloud provider. The customer is responsible for the OS and applications. The cloud provider is responsible for the OS in PaaS and SaaS.

58
Q

What uses the infrastructure as a service (IaaS) cloud service model?

Select only one answer.

A. Azure App Services

B. Azure Cosmos DB

C. Azure virtual machines

D. Microsoft Office 365

A

C. Azure virtual machines

Azure Virtual Machines is an IaaS offering. The customer is responsible for the configuration of the virtual machine as well as all operating system configurations. Azure App Services and Azure Cosmos DB are PaaS offerings. Microsoft Office 365 is a SaaS offering.

59
Q

Which two Azure resources can make use of availability zones? Each correct answer presents a complete solution.

Select all answers that apply.

[ ] Azure SQL databases

[ ] Azure subscriptions

[ ] resource groups

[ ] virtual machines

A

[/] Azure SQL databases
[/] virtual machines

Availability zones are primarily for virtual machines, managed disks, load balancers, and SQL databases.

60
Q

Which Azure resource is a software emulation of a physical computer that includes a virtual processor, memory, storage, and networking resources?

Select only one answer.

A. a container

B. a function

C. a virtual machine

D. an App Service

A

C. a virtual machine

Virtual machines are software emulations of physical computers. They include a virtual processor, memory, storage, and networking resources. Virtual machines host an operating system, and you can install and run software just like on a physical computer.

61
Q

Which storage service offers fully managed file shares in the cloud that are accessible by using Server Message Block (SMB) protocol?

Select only one answer.

A. Azure Disk Storage

B. Azure Files

C. Azure Queue Storage

D. Azure Table storage

A

B. Azure Files

Azure Files offers fully managed file shares in the cloud with shares that are accessible by using Server Message Block (SMB) protocol. Mounting Azure file shares is just like connecting to shares on a local network.

62
Q

What enables a user to sign in one time and use that credential to access multiple resources and applications from different providers?

Select only one answer.

A. Conditional Access

B. device management

C. multi-factor authentication (MFA)

D. single sign-on (SSO)

A

D. single sign-on (SSO)

SSO enables a user to sign in one time and use that credential to access multiple resources and applications from different providers. MFA is a process whereby a user is prompted during the sign-in process for an additional form of identification. Conditional Access is a tool that Azure AD uses to allow or deny access to resources based on identity signals. Azure AD supports the registration of devices.

63
Q

What can you use to ensure that a user can only access applications from compliant devices?

Select only one answer.

A. Conditional Access

B. hybrid identity

C. multi-factor authentication (MFA)

D. single sign-on (SSO)

A

A. Conditional Access

Conditional Access is a tool that Azure AD uses to allow or deny access to resources based on identity signals, such as the device being used. SSO enables a user to sign in one time and use that credential to access multiple resources and applications from different providers. MFA is a process whereby a user is prompted during the sign-in process for an additional form of identification. Hybrid identity solutions create a common user identity for authentication and authorization to all resources, regardless of location.

64
Q

Which type of strategy uses a series of mechanisms to slow the advancement of an attack that aims to gain unauthorized access to data?

Select only one answer.

A. defense in depth

B. distributed denial-of-service (DDoS)

C. least privileged access

D. perimeter

A

A. defense in depth

A defense in depth strategy uses a series of mechanisms to slow the advancement of an attack that aims to gain unauthorized access to data. The principle of least privilege means restricting access to information to only the level that users need to perform their work. A DDoS attack attempts to overwhelm and exhaust an application’s resources. The perimeter layer is about protecting an organization’s resources from network-based attacks.

65
Q

What Azure AD feature can you use to configure security authentication that requires users to use their mobile phone to sign in?

Select only one answer.

A. Azure Information Protection (AIP)

B. Microsoft Defender for Cloud

C. Microsoft Entra Verified ID

D. multi-factor authentication (MFA)

A

D. multi-factor authentication (MFA)

MFA is the concept of requiring something more than only a password to sign in to an application. You can use the mobile phone to receive a phone call, text, or a code to get authenticated.

66
Q

What can you use to sync identities from an on-premises Active Directory Domain Services (AD DS) domain to Azure AD?

Select only one answer.

A. Azure AD Connect

B. Azure Key Vault

C. Azure Resource Manager (ARM)

D. Conditional Access

A

A. Azure AD Connect

Azure AD Connect syncs user identities from an on-premises Active Directory Domain Services (AD DS) domain to Azure AD. Azure AD Connect allows you to use features such as single sign-on (SSO), MFA, and self-service password reset (SSPR) in both systems. SSPR prevents users from using known compromised passwords.

67
Q

What can you use to ensure that users authenticate by using multi-factor authentication (MFA) when they attempt to sign in from a specific location?

Select only one answer.

A. administrative units

B. Azure role-based access control (RBAC)

C. Conditional Access

D. single sign-on (SSO)

A

C. Conditional Access

Conditional Access can use signals to determine information about authentication attempts, and then determine whether to block access or require additional verifications, such as MFA.

68
Q

You have an Azure virtual machine that is accessed only between 9:00 and 17:00 each day.

What should you do to minimize costs but preserve the associated hard disks and data?

Select only one answer.

A. Deallocate the virtual machine.

B. Delete the virtual machine.

C. Implement Privileged Identity Management.

D. Resize the virtual machine.

A

A. Deallocate the virtual machine

If you have virtual machine workloads that are used only during certain periods, but you run them every hour of every day, then you are wasting money. These virtual machines are great candidates to deallocate when not in use and start back when required to save compute costs while the virtual machines are deallocated.

69
Q

What can be applied to a resource to prevent accidental deletion?

Select only one answer.

A. a resource lock

B. a resource tag

C. a policy

D. an Azure Reservation

A

A. a resource lock

A resource lock prevents resources from being accidentally deleted or changed. Resource tags offer the custom grouping of resources. Policies enforce different rules across all resource configurations so that the configurations stay compliant with corporate standards. An initiative is a way of grouping related policies together.

70
Q

You need to recommend a solution for Azure virtual machine deployments. The solution must enforce company standards on the virtual machines.

What should you include in the recommendation?

Select only one answer.

A. Azure Blueprints

B. Azure Cost Management

C. Azure Lock

D. Azure Policy

A

D. Azure Policy

Azure policies will allow you to enforce company standards on new virtual machines when combined with Azure VM Image Builder and Azure Compute Gallery. By using Azure Policy and role-based access control (RBAC) assignments, enterprises can enforce standards on Azure resources. But on virtual machines, these mechanisms only affect the control plane or the route to the virtual machine.

71
Q

You need to ensure that multi-factor authentication (MFA) is enabled on accounts with write permissions in an Azure subscription.

What should you implement?

Select only one answer.

A. Azure Policy

B. resource locks

C. resource tags

D. Cloud Adoption Framework

A

A. Azure Policy

Azure Policy is a service in Azure that enables you to create, assign, and manage policies that control or audit resources.

72
Q

Which two actions can be performed by using the graphical user interface (GUI) in the Azure portal? Each correct answer presents a complete solution.

Select all answers that apply.

[ ] Change the availability zone of a virtual machine.

[ ] Create new resources.

[ ] Repeatedly set up one or more resources and ensure that all the [ ] dependencies are created in the proper order.

[ ] Review a graphical view of all the services you are using.

A

[/] Create new resources.
[/] Review a graphical view of all the services you are using.

The Azure portal provides a GUI to view all the services you are using, create new services, configure your services, and view reports.

73
Q

What can you use to create resources in Azure and includes a validation step to ensure all resources are created in a specific order based on dependencies, in parallel and idempotent?

Select only one answer.

A. Azure CLI

B. Azure PowerShell

C. Azure Resource Manager (ARM) templates

D. Azure REST API

A

C. Azure Resource Manager (ARM) templates

ARM templates define an application’s infrastructure requirements for a repeatable deployment that is done in a consistent manner. A validation step ensures that all resources can be created in the proper order based on dependencies, in parallel and idempotent.

74
Q

Which two tools can you use to create a new Azure virtual machine from a mobile device that runs Android? Each correct answer presents complete solution.

Select all answers that apply.

[ ] PowerShell in Azure Cloud Shell

[ ] Remote Desktop

[ ] SSH

[ ] the Azure portal

A

[/] PowerShell in Azure Cloud Shell
[/] the Azure portal

The Azure portal can run on devices that have the Android operating system installed. The browser can be any type, such as Internet Explorer 11, Chrome, Firefox, or Safari (all the latest versions). When you visit the portal, you will see Cloud Shell. Users can then access Bash and PowerShell from within Cloud Shell. You can use Bash and PowerShell to create Azure virtual machines.

75
Q

What provides recommendations to reduce the cost of Azure resources?

Select only one answer.

A. Azure Advisor

B. Azure Dashboard

C. Azure Service Health

D. Microsoft Defender for Cloud

A

A. Azure Advisor

76
Q

You have a team of Linux administrators that need to manage the resources in Azure. The team wants to use the Bash shell to perform the administration.

What should you recommend?

Select only one answer.

A. Azure Blueprint

B. Azure CLI

C. Azure Powershell

D. Azure Resource Manager (ARM) template

A

B. Azure CLI

Azure CLI allows you to use the Bash shell to perform administrative tasks. Bash is used in Linux environments, so a Linux administrator will probably be more comfortable performing command-line administration from Azure CLI.

77
Q

Which Azure service can generate an alert if virtual machine utilization is over 80% for five minutes?

Select only one answer.

A. Azure Advisor

B. Azure Monitor

C. Azure Policy

D. Azure Service Health

A

B. Azure Monitor

Azure Monitor is a platform for collecting, analyzing, visualizing, and alerting based on metrics. Azure Monitor can log data from an entire Azure and on-premises environment.

78
Q

Select the answer that correctly completes the sentence.

[Answer choice] is the logical container used to combine and organize Azure resources.

Select only one answer.

A. a management group

B. a resource group

C. Azure Resource Manager (ARM)

D. an Azure region

A

B. a resource group

Resources are combined into resource groups, which act as a logical container into which Azure resources like web apps, databases, and storage accounts, are deployed and managed.

79
Q

Which two services are provided by Azure AD? Each correct answer presents a complete solution.

Select all answers that apply.

[ ] authentication

[ ] data encryption

[ ] name resolution

[ ] single sign-on (SSO)

A

[/] authentication
[/] single sign-on (SSO)

Azure AD provides services for verifying identity and access to applications and resources. SSO enables you to remember a single username and password to access multiple applications and is available in Azure AD.

80
Q

What Azure AD feature can you use to ensure that users can only access Microsoft Office 365 applications from approved client applications?

Select only one answer.

A. Azure role-based access control (RBAC)

B. Conditional Access

C. multi-factor authentication (MFA)

D. single sign-on (SSO)

A

B. Conditional Access

Conditional Access allows administrators to control, allow, or deny access to resources based on certain signals. You can require that access to certain applications only be allowed if the users are using an approved client application. MFA is a process whereby a user is prompted during the sign-in process for an additional form of identification. Examples include a code on their mobile phone or a fingerprint scan.

81
Q

Which Azure service evaluates Azure resources and makes recommendations to help improve reliability, security, performance, and cost reduction?

Select only one answer.

A. Azure Advisor

B. Azure Monitor

C. Azure Service Health

D. Log Analytics

A

A. Azure Advisor

Azure Advisor evaluates Azure resources and makes recommendations to help improve reliability, security, and performance, achieve operational excellence, and reduce costs.

82
Q

Select the answer that correctly completes the sentence.

An example of [answer choice] is automatically scaling an application to ensure that the application has the resources needed to meet customer demands.

Select only one answer.

A. agility

B. elasticity

C. geo-distribution

D. high availability

A

B. elasticity

Elasticity refers to the ability to scale resources as needed, such as during business hours, to ensure that an application can keep up with demand, and then reducing the available resources during off-peak hours. Agility refers to the ability to deploy new applications and services quickly. High availability refers to the ability to ensure that a service or application remains available in the event of a failure. Geo-distribution makes a service or application available in multiple geographic locations that are typically close to your users.

83
Q

Select the answer that correctly completes the sentence.

Increasing the capacity of an application by adding additional virtual machine is called [answer choice].

Select only one answer.

A. agility

B. high availability

C. horizontal scaling

D. vertical scaling

A

C. horizontal scaling

84
Q

Your organization plans to deploy several production virtual machines that will have consistent resource usage throughout the year.

What can you use to minimize the costs of the virtual machines without reducing the functionality of the virtual machines?

Select only one answer.

A. Azure Monitor alerts

B. Azure Reservations

C. spending limits

A

B. Azure Reservations

Azure Reservations offers discounted prices on certain Azure services. Azure Reservations can save you up to 72 percent compared to pay-as-you-go prices. To receive a discount, you can reserve services and resources by paying in advance.Spending limits can suspend a subscription when the spend limit is reached.

85
Q

What can you use to automatically detect performance anomalies for web apps?

Select only one answer.

A. Azure Advisor

B. Azure Application Insights

C. Azure Cognitive Services

D. Azure DevOps

A

B. Azure Application Insights

B. Azure Application Insights

86
Q

Which two components are created in an Azure subscription? Each correct answer presents a complete solution.

Select all answers that apply.

[ ] Azure AD user accounts

[ ] management groups

[ ] resource groups

[ ] resources

A

[/] resource groups

[/] resources

Resources can only be associated with a single subscription. Subscriptions may be grouped into management groups. An account may be associated with multiple subscriptions.

87
Q

Which Azure Blob storage tier stores data offline and offers the lowest storage costs and the highest costs to access data?

Select only one answer.

A. Archive

B. Cool

C. Hot

A

A. Archive

The Archive storage tier stores data offline and offers the lowest storage costs, but also the highest costs to rehydrate and access data. The Hot storage tier is optimized for storing data that is accessed frequently. Data in the Cool access tier can tolerate slightly lower availability, but still requires high durability, retrieval latency, and throughput characteristics similar to hot data.

88
Q

Which two protocols are used to access Azure file shares? Each correct answer presents a complete solution.

Select all answers that apply.

[ ] HTTP

[ ] FTP

[ ] Network File System (NFS)

[ ] Server Message Block (SMB)

A

[/] Network File System (NFS)

[/] Server Message Block (SMB)

Azure Files offers fully managed file shares in the cloud that are accessible via industry-standard SMB and NFS protocols.

89
Q

What is the purpose of defense in depth?

Select only one answer.

A. to enable you to locate and act on resources that are associated with specific workloads, environments, business units, and owners

B. to evaluate resources and make recommendations to help improve reliability and performance

C. to manage policies that control or audit resources so that the configurations stay compliant with corporate standards

D. to use several layers of protection to prevent information from being accessed by unauthorized users

A

D. to use several layers of protection to prevent information from being accessed by unauthorized users

The objective of defense in depth is to use several layers of protection to prevent information from being accessed or stolen by unauthorized users.

90
Q

Why is cloud computing often less expensive than on-premises datacenters? Each correct answer presents a complete solution.

Select only one answer.

A. Cloud service offerings have limited functionality.

B. Network bandwidth is free.

C. Services are only offered in a single geographic location.

D. You are only billed for what you use.

A

D. You are only billed for what you use.

Renting compute and storage services and being billed for only what you use often lowers operating expenses. Depending on the service and the type of network bandwidth, charges can be incurred. Cloud service offerings often provide functionality that can be difficult or cost-prohibitive to deploy on-premises, especially for smaller organizations. Major cloud providers offer services around the world. Making it easy and relatively inexpensive to deploy services close to where your users reside.

91
Q

What can you use to ensure that new and existing Azure resources stay in compliance with corporate standards?

Select only one answer.

A. Azure Advisor

B. Azure Policy

C. resource locks

D. resource tags

A

B. Azure Policy

Azure Policy is a service in Azure that enables you to create, assign, and manage policies that control or audit resources. These policies enforce different rules across all resource configurations so that the configurations stay compliant with corporate standards.

92
Q

You need to create a custom solution that uses thresholds to trigger autoscaling functionality to scale an app up or down to meet user demand.

What should you include in the solution?

Select only one answer.

A. Application insights

B. Azure Advisor

C. Azure Monitor

D. Azure Service Health

A

C. Azure Monitor

Azure Monitor is a platform that collects metric and logging data, such as CPU percentages. The data can be used to trigger autoscaling

93
Q

What can you use to find information about planned maintenance for Azure services that are critical to your organization?

Select only one answer.

A. Azure Advisor

B. Azure Monitor

C. Azure Service Health

D. Log Analytics

A

C. Azure Service Health

You can drill down to the affected services, regions, and details to show how an event will affect you and what you must do. Most of these events occur without any impact to you and will not be shown. In a rare case that a reboot is required, Service Health allows you to choose when to perform the maintenance to minimize the downtime

94
Q

Select the answer that correctly completes the sentence.

[Answer choice] are physically separate datacenters within an Azure region.

Select only one answer.

A. Availability zones

B. Geographies

C. Region pairs

D. Resource groups

A

A. Availability zones

Availability zones are physically separate datacenters within an Azure region. Each availability zone is made up of one or more datacenters equipped with independent power, cooling, and networking.

95
Q

For which resource does Azure generate separate billing reports and invoices by default?

Select only one answer.

A. accounts

B. management groups

C. resource groups

D. subscriptions

A

D. subscriptions

Azure generates separate billing reports and invoices for each subscription so that you can organize and manage costs. Resource groups can be used to group costs, but you will not receive a separate invoice for each resource group. Management groups are used to efficiently manage access, policies, and compliance for subscriptions. You can set up billing profiles to roll up subscriptions into invoice sections, but this requires customization.

96
Q

You need to compare the costs of running an application in an on-premises datacenter with the costs of running the application in Azure.

What should you use to assist you?

Select only one answer.

A. Azure Advisor

B. Azure Cost Management

C. Azure Pricing calculator

D. Total Cost of Ownership (TCO) Calculator

A

D. Total Cost of Ownership (TCO) Calculator

The TCO Calculator helps you estimate the cost savings over time of operating a solution in Azure compared to operating in an on-premises datacenter.

97
Q

What is an advantage of cloud computing compared to on-premises deployments?

Select only one answer.

A. You can scale more quickly.

B. You can work from multiple workstations.

C. You have full access in case of internet outage.

D. You own your CPUs.

A

A. You can scale more quickly.

Cloud computing allows you to scale more quickly. Owning your own CPUs and having full access in the event of an internet outage are not features of cloud computing. Working from multiple workstations is not specific to cloud computing compared to an on-premises deployment.

98
Q

What are cloud-based backup services, data replication, and geo-distribution features of?

Select only one answer.

A. a cost reduction plan

B. a disaster recovery plan

C. a hybrid cloud deployment

D. an elastic application configuration

A

B. a disaster recovery plan

Disaster recovery uses services, such as cloud-based backup, data replication, and geo-distribution, to keep data and code safe in the event of a disaster.