Microsoft Azure Administrator - AZ-104무료 덤프문제 풀어보기
You have an Azure App Service web app named appl. You configure autoscaling as shown in following exhibit.
You configure the autoscale rule criteria as shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
After CPU usage has reached 80 percent for 15 minutes, \[2 instances\] will be running.
# Once the first scale-out instance is created, the minimum time before an additional instance is created will be \[5 minutes\].![] (media/image281.jpeg){width= " 7.0in " height= " 2.335902230971129in " }

Exhibit

Exhibit

Exhibit
You configure the autoscale rule criteria as shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
After CPU usage has reached 80 percent for 15 minutes, \[2 instances\] will be running.
# Once the first scale-out instance is created, the minimum time before an additional instance is created will be \[5 minutes\].![] (media/image281.jpeg){width= " 7.0in " height= " 2.335902230971129in " }

Exhibit

Exhibit

Exhibit
정답:

Explanation:
Detailed Explanation
Starting from the default of 1 instance, the 10-minute Duration window for the scale-out rule is first satisfied at the 10-minute mark, triggering one scale-out action (1 - > 2 instances) followed by a 5-minute cool-down.
Duration (10) plus cool-down (5) equals exactly 15 minutes, meaning the earliest possible moment a second scale-out could fire is precisely at the 15-minute mark -- so at exactly 15 minutes, only the first scale-out has definitively completed, giving 2 running instances. The second statement asks for the Cool down value directly from the exhibit, which is 5 minutes: this is the minimum time that must elapse after a scale-out before another scale action can occur. Both selections match the source key.
Official Reference
Autoscale - cooldown and duration settings - https://learn.microsoft.com/en-us/azure/azure-monitor
/autoscale/autoscale-understanding-settings
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You need to ensure that an Azure Active Directory (Azure AD) user named Admin1 is assigned the required role to enable Traffic Analytics for an Azure subscription.
Solution: You assign the Traffic Manager Contributor role at the subscription level to Admin1
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You need to ensure that an Azure Active Directory (Azure AD) user named Admin1 is assigned the required role to enable Traffic Analytics for an Azure subscription.
Solution: You assign the Traffic Manager Contributor role at the subscription level to Admin1
정답: B
설명: (Fast2test 회원만 볼 수 있음)
You have an Azure subscription that contains a storage account named storage1. The subscription is linked to a Microsoft Entra tenant named contoso.com that syncs with an on-premises Active Directory domain. The domain contains the security principals shown in the following table.
In the Microsoft Entra tenant you create a user named User2.
The storage1 account contains a file share named share! and has the following configurations.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point

Exhibit

Exhibit
In the Microsoft Entra tenant you create a user named User2.
The storage1 account contains a file share named share! and has the following configurations.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point

Exhibit

Exhibit
정답:

Explanation:
Detailed Explanation
Azure RBAC role assignments (IAM) can only target objects that exist in Microsoft Entra ID with a resolvable object ID - users, groups, service principals, or managed identities. User1 is a hybrid identity synchronized into Microsoft Entra ID, so Azure Files data-plane roles (Storage File Data SMB Share Contributor/Reader/Elevated Contributor) can be assigned to it - statement 1 is Yes. Computer1 is a plain on- premises AD DS ' Computer ' object; Microsoft Entra Connect does not synchronize generic AD computer accounts as assignable directory principals, so no matching Entra ID object exists to select in IAM, and the role assignment cannot be created - statement 2 is No. User2 is a normal (cloud-only) Entra ID user object, and RBAC assignment only requires a valid directory object - it does not validate whether the user also has an on-premises AD twin for actual Kerberos authentication - so the assignment itself can be created - statement 3 is Yes.
Official Reference
Azure Files identity-based authentication over SMB for AD DS - https://learn.microsoft.com/en-us/azure
/storage/files/storage-files-identity-auth-active-directory-enable
You have an Azure subscription that contains the resources shown in the following table.
You plan to use an Azure key vault to provide a secret to appl.
What should you create for app1 to access the key vault, and from which key vault can the secret be used? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit
You plan to use an Azure key vault to provide a secret to appl.
What should you create for app1 to access the key vault, and from which key vault can the secret be used? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit
정답:

Explanation:
CORRECTED ANSWER: Create a: Managed identity. Use the secret from: Vault1, Vault2, or Vault3 (any of the three key vaults, since RBAC-based Key Vault access via a managed identity has no region or resource- group affinity requirement).
Detailed Explanation
The Azure-recommended, credential-less way for app1 (a Container App) to retrieve a secret is to enable a managed identity and grant it an appropriate Key Vault access role (e.g., Key Vault Secrets User) via Azure RBAC or an access policy - avoiding stored credentials entirely; a service principal would require managing a client secret/certificate, a private endpoint secures network access to a vault but isn ' t itself an identity for app1, and a user account is not applicable to an application workload. Azure Key Vault RBAC role assignments and REST/API access work over HTTPS regardless of the caller ' s region or resource group, so app1 ' s managed identity can be granted access to Vault1, Vault2, or Vault3 equally - none of the vaults ' differing resource groups (RG1 vs RG2) or regions (East US vs West US) restrict this cross-boundary RBAC access, so all three vaults are usable, not only Vault1.
Official Reference
Access Azure Key Vault from Azure Container Apps using a managed identity - https://learn.microsoft.com
/en-us/azure/container-apps/managed-identity
You have an Azure subscription.
Your company has three external partners. You plan to deploy 10 virtual machines that will be used by the partners.
You need to ensure that you can track the partners ' use of the virtual machines by using Microsoft Cost Management. The solution must minimize administrative effort.
What should you do first?
Your company has three external partners. You plan to deploy 10 virtual machines that will be used by the partners.
You need to ensure that you can track the partners ' use of the virtual machines by using Microsoft Cost Management. The solution must minimize administrative effort.
What should you do first?
정답: D
설명: (Fast2test 회원만 볼 수 있음)
You have an Azure subscription that contains a storage account named storage1. The storage 1 account contains a container named containet1.
You create a blob lifecycle rule named rule1.
You need to configure rule1 to automatically move blobs that were NOT updated for 45 days Irom container!
to the Cool access tier.
How should you complete the rule? To answer, select Ihe appropriate options in the answer area.
NOTE: Each correct answer is worth one point.

Exhibit
You create a blob lifecycle rule named rule1.
You need to configure rule1 to automatically move blobs that were NOT updated for 45 days Irom container!
to the Cool access tier.
How should you complete the rule? To answer, select Ihe appropriate options in the answer area.
NOTE: Each correct answer is worth one point.

Exhibit
정답:

Explanation:
Detailed Explanation
A blob lifecycle management rule ' s tierToCool action can be triggered by one of three time-based conditions: daysAfterCreationGreaterThan (time since the blob was first created, regardless of later edits), daysAfterLastAccessTimeGreaterThan (time since the blob was last read - only usable if last-access-time tracking is separately enabled on the account), or daysAfterModificationGreaterThan (time since the blob ' s content was last written/updated). " Blobs that were NOT updated for 45 days " specifically describes modification recency, not creation age or read access, so the correct condition is daysAfterModificationGreaterThan, set to 45. For the blob type filter, Azure Blob lifecycle management tiering actions (tierToCool, tierToArchive) apply only to block blobs - page blobs and append blobs are not eligible for automatic tier transitions through lifecycle policy - so the filter should be set to Blockblob (with the existing prefixMatch of " container1 " already scoping the rule to that container).
Official Reference
Optimize costs with blob lifecycle management - https://learn.microsoft.com/en-us/azure/storage/blobs
/lifecycle-management-overview
You have an Azure subscription that is linked to an Azure AD tenant. The tenant contains two users named User1 and User2. The subscription contains the resources shown in the following table.
The subscription contains the alert rules shown in the following table.
The users perform the following actions:
* User1 creates a new virtual disk and attaches the disk to VM1.
* User2 creates a new resource tag and assigns the tag to RG1 and VM1.
Which alert rules are triggered by each user? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit
The subscription contains the alert rules shown in the following table.
The users perform the following actions:
* User1 creates a new virtual disk and attaches the disk to VM1.
* User2 creates a new resource tag and assigns the tag to RG1 and VM1.
Which alert rules are triggered by each user? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit
정답:

Explanation:
CORRECTED ANSWER: User1: Alert1 and Alert2 are triggered. User2: Alert1 and Alert2 are triggered.
Detailed Explanation
An activity log alert scoped to a resource group fires for administrative operations on any resource whose resourceId falls under that resource group - not just operations on the resource group object itself (Microsoft
' s own documentation gives ' a VM in a production resource group is deleted ' as a canonical resource-group- scoped example). Attaching a new disk to VM1 is logged as a write operation on VM1 ' s resourceId, which lies within RG1, so it matches both Alert1 (scope RG1) and Alert2 (scope VM1) - the alerts are independent rules that both evaluate and can co-fire on the same event; Tagging RG1 directly matches Alert1, and tagging VM1 matches both Alert1 (VM1 is inside RG1) and Alert2 (direct scope match), so User2 also triggers both alerts.
Official Reference
Create, view, and manage activity log alerts - https://learn.microsoft.com/en-us/azure/azure-monitor/alerts
/activity-log-alerts
You have an Azure subscription that contains the virtual networks shown in the following table.
The subscription contains the virtual machines shown in the following table.
The subscription contains the Azure App Service web apps shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit

Exhibit
The subscription contains the virtual machines shown in the following table.
The subscription contains the Azure App Service web apps shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit

Exhibit
정답:

Explanation:
CORRECTED ANSWER: Statement 1: Yes. Statement 2: No. Statement 3: Yes.
Detailed Explanation
Microsoft Learn ' s App Service VNet integration documentation states that an app integrated with a virtual network can reach ' resources in virtual networks peered to the virtual network your app is integrated with...
[with] no extra configuration needed. ' WebApp1 is integrated with VNet1, which is peered with VNet2, so WebApp1 can reach VM2 in VNet2 - statement 1 is corrected from No to Yes. Regional VNet Integration governs only the app ' s outbound traffic into the VNet; it does not route inbound client requests to the app through that VNet or subject them to the integration subnet ' s NSG, so NSG1 (attached to Subnet1) does not control inbound traffic to WebApp1 - statement 2 is No. WebApp2 (Isolated tier / App Service Environment) is deployed directly inside Subnet2, making it a true network member of VNet2; since VNet2 is peered with VNet1 (where VM1 resides), WebApp2 can reach VM1 across the peering - statement 3 is Yes.
The source document ' s original key for statement 1 is corrected here based on current Microsoft documentation.
Official Reference
Integrate your app with an Azure virtual network - peered network reachability - https://learn.microsoft.
com/en-us/azure/app-service/overview-vnet-integration
You have an Azure Storage account named storage1 that has the Blob service properties shown in the following exhibit.
On Janurary1, you add blobs to storage1 as shown in the following table.
You perform the actions shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit

Exhibit
On Janurary1, you add blobs to storage1 as shown in the following table.
You perform the actions shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit

Exhibit
정답:

Explanation:
Detailed Explanation
The Hot access tier has no minimum storage duration requirement, so deleting File1 only 4 days after upload incurs no early deletion charge. The Cool tier carries a 30-day minimum storage duration; moving a blob out of Cool -- to any other tier, including Archive -- before that minimum elapses is billed as an early deletion of the Cool-tier data. File2 was moved to Archive only 14 days after upload, well inside the 30-day window, so an early deletion fee for Cool applies. The Archive tier carries a 180-day minimum storage duration, and rehydrating a blob (moving it out of Archive) before that period elapses is likewise treated as an early deletion of the Archive-tier data. File3 was rehydrated on April 5, roughly 95 days after its January 1 upload -- well under 180 days -- so an early deletion fee for Archive applies.
Official Reference
Blob storage access tiers - early deletion fee - https://learn.microsoft.com/en-us/azure/storage/blobs/access- tiers-overview
You have an Azure Kubernetes Service (AKS) cluster named AKS1.
You need to configure cluster autoscaler for AKS1.
Which two tools should you use? Each correct answer presents a complete solution, NOTE: Each correct selection is worth one point
You need to configure cluster autoscaler for AKS1.
Which two tools should you use? Each correct answer presents a complete solution, NOTE: Each correct selection is worth one point
정답: A,E
설명: (Fast2test 회원만 볼 수 있음)