Question 1
What Azure service provides detailed reporting and monitoring for establishing recovery plans for VMs?
Correct Answer:
Azure Site Recovery
Explanation:
Azure Site Recovery is the service specifically designed to provide detailed reporting and monitoring for establishing recovery plans for virtual machines (VMs). It focuses on business continuity and disaster recovery, allowing administrators to set up replication for their VMs, automate the failover process, and ensure that applications can be restored in the event of a failure. The service monitors the health of your VMs and provides insights into their status, which can help in crafting recovery strategies and ensuring minimal downtime. In contrast, while Azure Advisor offers best practices and recommendations for improving Azure resources, it doesn't focus solely on recovery planning. Azure Security Center primarily focuses on providing security recommendations and threat protection for Azure resources, which is different from recovery planning. Azure Monitor is intended for collecting and analyzing performance metrics and logs from Azure resources, but it doesn't offer the same level of focused planning and execution for disaster recovery that Azure Site Recovery does.
Question 2
How can you monitor the status and performance of multiple Azure Virtual Machines?
Correct Answer:
Azure Monitor with metrics and logs
Explanation:
Using Azure Monitor with metrics and logs is the best way to monitor the status and performance of multiple Azure Virtual Machines. Azure Monitor provides a comprehensive set of tools to collect, analyze, and act on telemetry data from your cloud and on-premises environments. It offers both metrics, which are numerical values that represent data over time (like CPU usage, memory utilization, etc.), and logs, which provide detailed records of events that occur within the virtual machines. Through Azure Monitor, you can set up alerts based on specific conditions, create dashboards to visualize the performance data, and utilize insights to optimize the performance of your virtual machines. This centralized monitoring effectively enables administrators to quickly identify issues and make data-driven decisions to maintain performance and availability across all monitored Azure resources. While other options have their significance, they serve different purposes. For instance, Service Fabric health monitoring is specific to applications running on Azure Service Fabric, Network Watcher focuses on network performance and diagnostics, and Azure Security Center alerts primarily deal with security-related events and threats rather than overall performance monitoring. Thus, Azure Monitor stands out as the most holistic and applicable solution for monitoring multiple Azure Virtual Machines.
Question 3
What action is permitted when a ReadOnly lock is applied to a resource group in Azure?
Correct Answer:
Generate an automation script for the resource group
Explanation:
When a ReadOnly lock is applied to a resource group in Azure, tasks that only involve reading information about the resources are permitted, while modifications or deletions are restricted. Generating an automation script for the resource group falls within the permitted actions as it does not alter the state of the resources. The automation script primarily retrieves information about the current configuration and deployments in the resource group. In contrast, options involving modifications or actions that change resource states, such as uploading a blob to the storage account or starting a virtual machine, would be disallowed under a ReadOnly lock. Additionally, viewing sensitive information like storage account keys is generally not permitted in a ReadOnly context due to the potential security implications. Thus, generating an automation script represents the only action that aligns with the constraints imposed by a ReadOnly lock.
Question 4
What configuration should be made to ensure automatic key rotation for Azure Storage account access keys?
Correct Answer:
Enable key rotation policies in Azure Key Vault
Explanation:
To ensure automatic key rotation for Azure Storage account access keys, enabling key rotation policies in Azure Key Vault is the most appropriate configuration. Azure Key Vault provides a secure way to manage secrets, including cryptographic keys, and offers built-in capabilities for automatic key rotation. When key rotation policies are enabled, Key Vault can automatically rotate keys based on specified schedules, allowing for enhanced security by minimizing the risk of key compromise and ensuring that access keys are regularly updated without requiring manual intervention. This not only improves security but also reduces the operational burden on administrators, as they do not have to perform regular manual updates of keys. Storing keys in Azure Active Directory is not a feature meant for key rotation; instead, it is used for managing identities and their access rights. Manually generating a new key pair every month does not automate the process and can lead to increased workload and higher chances of human error. Utilizing Azure Automation runbooks for rotation could achieve key rotation but would require additional setup and management compared to the built-in key rotation policies of Azure Key Vault. Hence, enabling key rotation policies in Azure Key Vault is the most efficient and automated approach.
Question 5
What is the restriction of the Azure policy shown in the exhibit?
Correct Answer:
Limit creation of Azure SQL servers to a specific resource group
Explanation:
The restriction of the Azure policy is to limit the creation of Azure SQL servers to a specific resource group. This means that the policy enforces governance rules so that Azure SQL servers can only be deployed within the designated resource group identified in the policy definition. Consequently, any attempt to create Azure SQL servers outside of this specified resource group would be denied, ensuring that resource management and compliance are maintained according to organizational policies. This type of configuration is useful in scenarios where organizations want to control costs, manage resources efficiently, or adhere to specific security requirements within Azure. By enforcing such a restriction, administrators can maintain tighter control over where and how resources are deployed, leading to better resource organization and management.
Question 1
Exam overview

About this Exam

The Microsoft Azure Administrator Associate certification, earned by passing the AZ-104 exam, validates your expertise in managing cloud services. It is designed for IT professionals who have subject matter expertise in implementing, managing, and monitoring an organization’s Microsoft Azure environment. This comprehensive certification covers crucial areas like virtual networks, storage, compute, identity, security, and governance. Whether you are an aspiring cloud professional or looking to formalize your existing skills, this credential demonstrates your ability to effectively manage diverse Azure services throughout their full IT lifecycle.

More details

Additional Information

What the Course Entails and Exam Details

To master this exam, you must become proficient across five heavily-weighted domains that outline the core responsibilities of an Azure Administrator.

Manage Azure identities and governance (20–25%): This section focuses on essential identity management using Azure Entra ID (formerly Azure Active Directory). You'll learn to manage users, groups, and licenses, configure self-service password reset, and handle hybrid identities. Crucial governance aspects like Role-Based Access Control (RBAC), subscription management, setting up budgets and alerts, applying Azure policies, and resource tagging are all covered here.

Implement and manage storage (15–20%): You will master configuring and managing Azure storage accounts, including managing data within different access tiers (hot, cool, archive), securing storage accounts with shared access signatures and firewall rules, and understanding data lifecycle management. Skills in managing Azure files, Azure Blob storage, and storage replication options are key to this domain.

Deploy and manage Azure compute resources (20–25%): This is where you learn to deploy and manage Virtual Machines (VMs). Key skills include configuring VMs for high availability and scalability (using scale sets), automating deployment with Infrastructure as Code (ARM templates or Bicep), and understanding how to deploy and manage container solutions like Azure Container Instances and basic Azure Kubernetes Service (AKS). Mastering Azure App Service configuration is also crucial for web application deployment.

Configure and manage virtual networking (15–20%): A robust understanding of Azure virtual networks is essential. This domain covers creating and configuring Virtual Networks (VNets) and subnets, implementing network security groups (NSGs) for traffic control, managing public and private IP addresses, configuring Azure DNS, and setting up connectivity solutions like VNet peering, VPN gateways, and ExpressRoute. Basic understanding of load balancers is also relevant.

Monitor and maintain Azure resources (10–15%): This domain tests your ability to ensure the health, performance, and recoverability of your Azure environment. You will become familiar with Azure Monitor, including using metrics and logs (Log Analytics and KQL queries) to gain insights and configure diagnostic settings and critical alert rules. This section also covers vital backup and disaster recovery processes using Azure Backup and Azure Site Recovery to protect VMs, storage, and other resources.

 

 

What to Expect in the Final Exam

The AZ-104 exam is a comprehensive assessment that demands both theoretical knowledge and practical hands-on application. It is generally a computer-based, proctored exam. You can expect 40–60 questions within a 120-minute time limit for the exam content itself. The question formats are diverse, including single and multi-select multiple choice, drag-and-drop, interactive hot area questions, sequence-ordering scenarios, and in-depth case studies where you must make decisions based on complex requirements. While not present in every exam instance, you should be prepared for potential performance-based lab scenarios where you must perform actual tasks within the Azure Portal. The passing score is a scaled 700 out of 1000. It is a closed-book exam, so external resources are not permitted during the test.

 

 

How to Study and Exam Centers

Preparation for the AZ-104 exam requires a strategic mix of focused study and dedicated practical experience. Start with the free official Microsoft Learn learning path which offers extensive modules and hands-on labs directly tailored to each exam objective. Complement this by thoroughly reading official Azure documentation to gain in-depth understanding.

Crucially, hands-on practice is absolutely essential. Spend significant time in the Azure Portal (utilizing free accounts or subscription credits) explicitly performing tasks in all five domains – creating VNets, deploying VMs, configuring storage, managing identities, and setting up monitoring. This cements your knowledge.

Furthermore, integrating high-quality practice exams is a key strategy to succeed, mirroring the intent behind this guide's title. Use reputable practice test platforms that simulate the real exam environment with diverse question types. Analyze your results, focus your study on weak areas, and use practice exams to improve your time management skills. Consider online courses, study groups, and flashcards for reinforced learning. Setting an exam date and creating a realistic study schedule will keep you motivated and on track.

When you are ready, you must register for and take the exam through Pearson VUE, Microsoft’s authorized exam provider. You have two primary options:

Online Proctored Exam: This flexible option allows you to take the exam from the comfort and privacy of your home or office, as long as you meet specific hardware, software, and environment requirements, and are proctored remotely.

Physical Testing Center: You can choose to take the exam in person at a physical Pearson VUE authorized test center. You can use Pearson VUE’s test center locator during the exam scheduling process to find convenient locations near you. Register online through your Microsoft Certification profile to schedule and pay for your exam. Good luck!

 

 

Job Opportunities from the Course

Earning the Microsoft Azure Administrator Associate certification opens doors to numerous exciting career opportunities in the burgeoning cloud computing landscape. This highly respected credential validates your practical skills and positions you as a valuable asset to organizations leveraging Azure. Potential job roles and career paths include:

  • Azure Administrator
  • Cloud Systems Administrator
  • Cloud Engineer
  • DevOps Engineer (often with an Azure focus)
  • Solutions Architect (as an expert-level path)
  • Cloud Security Engineer
  • Network Engineer (Azure Specialization)
  • System Engineer (incorporating Azure skills)
  • IT Operations Manager (overseeing cloud environments)
Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions