Precise AZ-100 Braindumps 2019

★ Pass on Your First TRY ★ 100% Money Back Guarantee ★ Realistic Practice Exam Questions

Free Instant Download NEW AZ-100 Exam Dumps (PDF & VCE):
Available on: https://www.certleader.com/AZ-100-dumps.html


AZ-100 Product Description:
Exam Number/Code: AZ-100 vce
Exam name: Microsoft Azure Infrastructure and Deployment
n questions with full explanations
Certification: Microsoft Certification
Last updated on Global synchronizing

Instant Access to Free VCE Files: Microsoft AZ-100 Microsoft Azure Infrastructure and Deployment

AZ-100 examcollection

Act now and download your AZ-100 Free Practice Questions today! Do not waste time for the worthless AZ-100 Dumps Questions tutorials. Download AZ-100 Study Guides with real questions and answers and begin to learn AZ-100 Exam Questions with a classic professional.

Also have AZ-100 free dumps questions for you:

NEW QUESTION 1
You plan to back up an Azure virtual machine named VM1.
You discover that the Backup Pre-Check status displays a status of Warning. What is a possible cause of the Warning status?

  • A. VM1 does not have the latest version of WaAppAgent.exe installed.
  • B. VM1 has an unmanaged disk.
  • C. VM1 is stopped.
  • D. A Recovery Services vault is unavailable.

Answer: A

Explanation: The Warning state indicates one or more issues in VM’s configuration that might lead to backup failures and provides recommended steps to ensure successful backups. Not having the latest VM Agent installed, for example, can cause backups to fail intermittently and falls in this class of issues.
References:
https://azure.microsoft.com/en-us/blog/azure-vm-backup-pre-checks/

NEW QUESTION 2
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure virtual machine named VM1. VM1 was deployed by using a custom Azure Resource Manager template named ARM1.json.
You receive a notification that VM1 will be affected by maintenance. You need to move VM1 to a different host immediately.
Solution: From the Redeploy blade, you click Redeploy. Does this meet the goal?

  • A. Yes
  • B. No

Answer: A

Explanation: When you redeploy a VM, it moves the VM to a new node within the Azure infrastructure and then powers it back on, retaining all your configuration options and associated resources.
References: https://docs.microsoft.com/en-us/azure/virtual-machines/windows/redeploy-to-new-node

NEW QUESTION 3
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource groups.
Another administrator plans to create several network security groups (NSGs) in the subscription.
You need to ensure that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks.
Solution: You create a resource lock, and then you assign the lock to the subscription. Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

Explanation: How can I freeze or lock my production/critical Azure resources from accidental deletion? There is way to do this with both ASM and ARM resources using Azure resource lock.
References:
https://blogs.msdn.microsoft.com/azureedu/2016/04/27/using-azure-resource-manager-policy-and-azure-lock-to

NEW QUESTION 4
You need to meet the user requirement for Admin1. What should you do?

  • A. From the Subscriptions blade, select the subscription, and then modify the Properties.
  • B. From the Subscriptions blade, select the subscription, and then modify the Access control (IAM) settings.
  • C. From the Azure Active Directory blade, modify the Properties.
  • D. From the Azure Active Directory blade, modify the Groups.

Answer: A

Explanation: Change the Service administrator for an Azure subscription
Sign in to Account Center as the Account administrator.
Select a subscription.
On the right side, select Edit subscription details.
Scenario: Designate a new user named Admin1 as the service administrator of the Azure subscription. References:
https://docs.microsoft.com/en-us/azure/billing/billing-add-change-azure-subscription-administrator

NEW QUESTION 5
You have an Azure subscription named Subscription1. Subscription1 contains a virtual machine named VM1. You have a computer named Computer1 that runs Windows 10. Computer1 is connected to the Internet.
You add a network interface named Interface1 to VM1 as shown in the exhibit (Click the Exhibit button.)
AZ-100 dumps exhibit
From Computer1, you attempt to connect to VM1 by using Remote Desktop, but the connection fails. You need to establish a Remote Desktop connection to VM1.
What should you do first?

  • A. Start VM1.
  • B. Attach a network interface.
  • C. Delete the DenyAllOutBound outbound port rule.
  • D. Delete the DenyAllInBound inbound port rule.

Answer: A

NEW QUESTION 6
Overview
The following section of the exam is a lab. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design.
Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn’t matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
To start the lab
You may start the lab by clicking the Next button. You plan to host several secured websites on Web01.
You need to allow HTTPS over TCP port 443 to Web01 and to prevent HTTP over TCP port 80 to Web01. What should you do from the Azure portal?

    Answer:

    Explanation: You can filter network traffic to and from Azure resources in an Azure virtual network with a network security group. A network security group contains security rules that allow or deny inbound network traffic to, or outbound network traffic from, several types of Azure resources.
    A network security group contains security rules that allow or deny inbound network traffic to, or outbound network traffic from, several types of Azure resources.
    Step A: Create a network security group
    A1. Search for and select the resource group for the VM, choose Add, then search for and select Network security group.
    A2. Select Create.
    AZ-100 dumps exhibit
    The Create network security group window opens. A3. Create a network security group
    Enter a name for your network security group.
    Select or create a resource group, then select a location. A4. Select Create to create the network security group.
    Step B: Create an inbound security rule to allows HTTPS over TCP port 443 B1. Select your new network security group.
    B2. Select Inbound security rules, then select Add. B3. Add inbound rule
    B4. Select Advanced.
    From the drop-down menu, select HTTPS.
    You can also verify by clicking Custom and selecting TCP port, and 443. B5. Select Add to create the rule.
    Repeat step B2-B5 to deny TCP port 80
    B6. Select Inbound security rules, then select Add. B7. Add inbound rule
    B8. Select Advanced.
    Clicking Custom and selecting TCP port, and 80. B9. Select Deny.
    Step C: Associate your network security group with a subnet
    Your final step is to associate your network security group with a subnet or a specific network interface. C1. In the Search resources, services, and docs box at the top of the portal, begin typing Web01. When the
    Web01 VM appears in the search results, select it.
    C2. Under SETTINGS, select Networking. Select Configure the application security groups, select the Security Group you created in Step A, and then select Save, as shown in the following picture:
    AZ-100 dumps exhibit
    References:
    https://docs.microsoft.com/en-us/azure/virtual-network/tutorial-filter-network-traffic

    NEW QUESTION 7
    You have an Azure subscription named Subscription1. Subscription1 contains a virtual machine named VM1. You install and configure a web server and a DNS server on VM1.
    VM1 has the effective network security rules shown in the following exhibit.
    AZ-100 dumps exhibit
    Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
    NOTE: Each correct selection is worth one point.
    AZ-100 dumps exhibit

      Answer:

      Explanation: AZ-100 dumps exhibit

      NEW QUESTION 8
      Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
      After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
      You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource groups.
      Another administrator plans to create several network security groups (NSGs) in the subscription.
      You need to ensure that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks.
      Solution: You configure a custom policy definition, and then you assign the policy to the subscription.
      Does this meet the goal?

      • A. Yes
      • B. No

      Answer: A

      Explanation: Resource policy definition used by Azure Policy enables you to establish conventions for resources in your organization by describing when the policy is enforced and what effect to take. By defining conventions, you can control costs and more easily manage your resources.
      References: https://docs.microsoft.com/en-us/azure/azure-policy/policy-definition

      NEW QUESTION 9
      You need to resolve the licensing issue before you attempt to assign the license again. What should you do?

      • A. From the Groups blade, invite the user accounts to a new group.
      • B. From the Profile blade, modify the usage location.
      • C. From the Directory role blade, modify the directory role.

      Answer: B

      Explanation: License cannot be assigned to a user without a usage location specified. Scenario: Licensing Issue
      You attempt to assign a license in Azure to several users and receive the following error message: "Licenses not assigned. License agreement failed for one user."
      You verify that the Azure subscription has the available licenses.

      NEW QUESTION 10
      Which blade should you instruct the finance department auditors to use?

      • A. Partner information
      • B. Overview
      • C. Payment methods
      • D. Invoices

      Answer: D

      Explanation: You can opt in and configure additional recipients to receive your Azure invoice in an email. This feature may not be available for certain subscriptions such as support offers, Enterprise Agreements, or Azure in Open.
      Select your subscription from the Subscriptions page. Opt-in for each subscription you own. Click Invoices then Email my invoice.
      Click Opt in and accept the terms.
      Scenario: During the testing phase, auditors in the finance department must be able to review all Azure costs from the past week.
      References: https://docs.microsoft.com/en-us/azure/billing/billing-download-azure-invoice-daily-usage-date

      NEW QUESTION 11
      You have an Azure subscription named Subscription1. Subscription1 contains the virtual networks in the following table.
      AZ-100 dumps exhibit
      Subscription1 contains the virtual machines in the following table:
      AZ-100 dumps exhibit
      The firewalls on all the virtual machines are configured to allow all ICMP traffic. You add the peerings in the following table.
      AZ-100 dumps exhibit
      For each of the following statements, select Yest if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
      AZ-100 dumps exhibit

        Answer:

        Explanation: Box 1: Yes
        Vnet1 and Vnet3 are peers. Box 2: Yes
        Vnet2 and Vnet3 are peers. Box 3: No
        Peering connections are non-transitive.
        References:
        https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/hybrid-networking/hub-spoke

        NEW QUESTION 12
        You need to recommend an identify solution that meets the technical requirements. What should you recommend?

        • A. federated single-on (SSO) and Active Directory Federation Services (AD FS)
        • B. password hash synchronization and single sign-on (SSO)
        • C. cloud-only user accounts
        • D. Pass-through Authentication and single sign-on (SSO)

        Answer: A

        Explanation: Active Directory Federation Services is a feature and web service in the Windows Server Operating System that allows sharing of identity information outside a company’s network.
        Scenario: Technical Requirements include:
        Prevent user passwords or hashes of passwords from being stored in Azure. References: https://www.sherweb.com/blog/active-directory-federation-services/

        Topic 3, Mix Questions

        NEW QUESTION 13
        Your network contains an Active Directory domain named adatum.com and an Azure Active Directory (Azure AD) tenant named adatum.onmicrosoft.com.
        Adatum.com contains the user accounts in the following table.
        AZ-100 dumps exhibit
        Adatum.onmicrosoft.com contains the user accounts in the following table.
        AZ-100 dumps exhibit
        You need to implement Azure AD Connect. The solution must follow the principle of least privilege.
        Which user accounts should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
        AZ-100 dumps exhibit

          Answer:

          Explanation: Box 1: User5
          In Express settings, the installation wizard asks for the following: AD DS Enterprise Administrator credentials
          Azure AD Global Administrator credentials
          The AD DS Enterprise Admin account is used to configure your on-premises Active Directory. These credentials are only used during the installation and are not used after the installation has completed. The Enterprise Admin, not the Domain Admin should make sure the permissions in Active Directory can be set in all domains.
          Box 2: UserA
          Azure AD Global Admin credentials credentials are only used during the installation and are not used after the installation has completed. It is used to create the Azure AD Connector account used for synchronizing changes to Azure AD. The account also enables sync as a feature in Azure AD.
          References:
          https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-accounts-permissio

          NEW QUESTION 14
          You have an Active Directory forest named contoso.com.
          You install and configure Azure AD Connect to use password hash synchronization as the single sign-on (SSO) method. Staging mode is enabled.
          You review the synchronization results and discover that the Synchronization Service Manager does not display any sync jobs.
          You need to ensure that the synchronization completes successfully. What should you do?

          • A. From Synchronization Service Manager, run a full import.
          • B. Run Azure AD Connect and set the SSO method to Pass-through Authentication.
          • C. From Azure PowerShell, run Start-AdSyncSyncCycle -PolicyType Initial.
          • D. Run Azure AD Connect and disable staging mode.

          Answer: D

          Explanation: Staging mode must be disabled. If the Azure AD Connect server is in staging mode, password hash synchronization is temporarily disabled.
          References:
          https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnectsync-troubleshoot-p

          NEW QUESTION 15
          You have a Recovery Service vault that you use to test backups. The test backups contain two protected virtual machines.
          You need to delete the Recovery Services vault. What should you do first?

          • A. From the Recovery Service vault, stop the backup of each backup item.
          • B. From the Recovery Service vault, delete the backup data.
          • C. Modify the disaster recovery properties of each virtual machine.
          • D. Modify the locks of each virtual machine.

          Answer: A

          Explanation: You can't delete a Recovery Services vault if it is registered to a server and holds backup data. If you try to delete a vault, but can't, the vault is still configured to receive backup data.
          Remove vault dependencies and delete vault
          In the vault dashboard menu, scroll down to the Protected Items section, and click Backup Items. In this menu, you can stop and delete Azure File Servers, SQL Servers in Azure VM, and Azure virtual machines.
          AZ-100 dumps exhibit
          References: https://docs.microsoft.com/en-us/azure/backup/backup-azure-delete-vault

          NEW QUESTION 16
          You have an Azure Active Directory (Azure AD) tenant named adatum.com. Adatum.com contains the groups in the following table.
          AZ-100 dumps exhibit
          You create two user accounts that are configured as shown in the following table.
          AZ-100 dumps exhibit
          To which groups do User1 and User2 belong? To answer. select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
          AZ-100 dumps exhibit

            Answer:

            Explanation: Box 1: Group 1 only First rule applies
            Box 2: Group1 and Group2 only Both membership rules apply.
            References: https://docs.microsoft.com/en-us/sccm/core/clients/manage/collections/create-collections

            P.S. Certleader now are offering 100% pass ensure AZ-100 dumps! All AZ-100 exam questions have been updated with correct answers: https://www.certleader.com/AZ-100-dumps.html (106 New Questions)