AZ-103 Premium Bundle

AZ-103 Premium Bundle

Microsoft Azure Administrator Certification Exam

4.5 
(46620 ratings)
0 QuestionsPractice Tests
0 PDFPrint version
November 21, 2024Last update

Microsoft AZ-103 Free Practice Questions

It is impossible to pass Microsoft AZ-103 exam without any help in the short term. Come to us soon and find the most advanced, correct and guaranteed . You will get a surprising result by our .

Online AZ-103 free questions and answers of New Version:

NEW QUESTION 1
Your company registers a domain name of contoso.com.
You create an Azure DNS named contoso.com and then you add an A record to the zone for a host named www that has an IP address of 131.107.1.10.
You discover that Internet hosts are unable to resolve www.contoso.com to the 131.107.1.10 IP address.
You need to resolve the name resolution issue.
Solution: You modify the name server at the domain registrar. Does this meet the goal?

  • A. No
  • B. Yes

Answer: A

Explanation: Modify the Name Server (NS) record.
References: https://docs.microsoft.com/en-us/azure/dns/dns-delegate-domain-azure-dns

NEW QUESTION 2
You plan to deploy a site-to-site VPN connection from on-premises network to your Azure environment. The VPN connection will be established to the VNET01-USEA2 virtual network.
You need to create the required resources in Azure for the planned site-to-site VPN. The solution must minimize costs.
What should you do from the Azure portal?
NOTE: This task may a very long time to complete. You do NOT need to wait for the deployment to complete this task successfully.

    Answer:

    Explanation: We create a VPN gateway. Step 1:
    On the left side of the portal page, click + and type 'Virtual Network Gateway' in search. In Results, locate and click Virtual network gateway.
    Step 2:
    At the bottom of the 'Virtual network gateway' page, click Create. This opens the Create virtual network gateway page.
    Step 3:
    On the Create virtual network gateway page, specify the values for your virtual network gateway. Gateway type: Select VPN. VPN gateways use the virtual network gateway type VPN.
    Virtual network: Choose the existing virtual network VNET01-USEA2
    Gateway subnet address range: You will only see this setting if you did not previously create a gateway subnet for your virtual network.
    Step 4:
    Select the default values for the other setting, and click create.
    AZ-103 dumps exhibit
    The settings are validated and you'll see the "Deploying Virtual network gateway" tile on the dashboard. Creating a gateway can take up to 45 minutes.
    Note: This task may take a very long time to complete. You do NOT need to wait for the deployment to complete this task successfully.
    References:
    https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-site-to-site-resource- manager-portal

    Case Study: 5
    Humongous Insurance
    Overview
    Existing Environment
    Active Directory Environment
    Humongous Insurance has a single-domain Active Directory forest named humongousinsurance.com. The functional level of the forest is Windows Server 2012.
    You recently provisioned an Azure Active Directory (Azure AD) tenant.
    Network Infrastructure
    Each office has a local data center that contains all the servers for that office. Each office has a dedicated connection to the Internet.
    Each office has several link load balancers that provide access to the servers.
    Active Directory Issue
    Several users in humongousinsurance.com have UPNs that contain special characters. You suspect that some of the characters are unsupported in Azure AD.
    Licensing Issue
    You attempt to assign a license in Azure to several users and receive the following error message:
    "Licenses not assigned. License agreement failed for one user." You verify that the Azure subscription has the available licenses. Requirements
    Planned Changes
    Humongous Insurance plans to open a new office in Paris. The Paris office will contain 1,000 users who will be hired during the next 12 months. All the resources used by the Paris office users will be hosted in Azure.
    Planned Azure AD Infrastructure
    The on-premises Active Directory domain will be synchronized to Azure AD. All client computers in the Paris office will be joined to an Azure AD domain. Planned Azure Networking Infrastructure
    You plan to create the following networking resources in a resource group named All_Resources:
     Default Azure system routes that will be the only routes used to route traffic
     A virtual network named Paris-VNet that will contain two subnets named Subnet1 and Subnet2
     A virtual network named ClientResources-VNet that will contain one subnet named ClientSubnet
     A virtual network named AllOffices-VNet that will contain two subnets named Subnet3 and Subnet4
    You plan to enable peering between Paris-VNet and AllOffices-VNet. You will enable the Use remote
    gateways setting for the Paris-VNet peerings.
    You plan to create a private DNS zone named humongousinsurance.local and set the registration network to the ClientResources-VNet virtual network.
    Planned Azure Computer Infrastructure
    Each subnet will contain several virtual machines that will run either Windows Server 2012 R2, Windows Server 2021, or Red Hat Linux.
    Department Requirements
    Humongous Insurance identifies the following requirements for the company's departments:
     Web administrators will deploy Azure web apps for the marketing department. Each web app will be added to a separate resource group. The initial configuration of the web apps will be identical. The web administrators have permission to deploy web apps to resource groups.
     During the testing phase, auditors in the finance department must be able to review all Azure costs from the past week.
    Authentication Requirements
    Users in the Miami office must use Azure Active Directory Seamless Single Sign-on (Azure AD Seamless SSO) when accessing resources in Azure.

    NEW QUESTION 3
    HOTSPOT
    You have an Azure virtual network named VNet1 that connects to your on-premises network by using a site-to-site VPN. VMet1 contains one subnet named Subnet1.
    Subnet1 is associated to a network security group (NSG) named NSG1. Subnet1 contains a basic
    internal load balancer named ILB1. ILB1 has three Azure virtual machines in the backend pool.
    You need to collect data about the IP addresses that connects to ILB1. You must be able to run interactive queries from the Azure portal against the collected data.
    What should you do? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.
    AZ-103 dumps exhibit

      Answer:

      Explanation: Box 1: An Azure Log Analytics workspace
      In the Azure portal you can set up a Log Analytics workspace, which is a unique Log Analytics environment with its own data repository, data sources, and solutions
      Box 2: ILB1
      References:
      https://docs.microsoft.com/en-us/azure/log-analytics/log-analytics-quick-create-workspace https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-standard-diagnostics

      NEW QUESTION 4
      HOTSPOT
      You have an Azure web app named App1 that has two deployment slots named Production and Staging. Each slot has the unique settings shown in the following table.
      AZ-103 dumps exhibit
      You perform a slot swap.
      What are the configurations of the Production slot after the swap? To answer, select the appropriate options in the answer area.
      NOTE: Each correction is worth one point.
      AZ-103 dumps exhibit

        Answer:

        Explanation: Swapping the slots means the destination slot website URL will run source slot code with destination slot settings.

        NEW QUESTION 5
        You recently deployed a web app named homepagelod7509087.
        You need to back up the code used for the web app and to store the code in the homepagelod7509Q87 storage account. The solution must ensure that a new backup is created daily.
        What should you do from the Azure portal?

          Answer:

          Explanation: Step 1:
          Locate and select the web app homepagelod7509087, select Backups. The Backups page is displayed.
          AZ-103 dumps exhibit
          Step 2:
          In the Backup page, Click Configure. Step 3:
          In the Backup Configuration page, click Storage: Not configured to configure a storage account.
          AZ-103 dumps exhibit
          Step 4:
          Choose your backup destination by selecting a Storage Account and Container. Select the homepagelod7509087 storage account.
          Step 5:
          In the Backup Configuration page that is still left open, select Scheduled backup On, and configure daily backups.
          AZ-103 dumps exhibit
          Step 6:
          In the Backup Configuration page, click Save. Step 7:
          In the Backups page, click Backup. References:
          https://docs.microsoft.com/en-us/azure/app-service/web-sites-backup

          NEW QUESTION 6
          Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
          After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
          You have an Azure Active Directory (Azure AD) tenant named Adatum and an Azure Subscription named Subscription1. Adatum contains a group named Developers. Subscription1 contains a resource group named Dev.
          You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group.
          Solution: On Subscription1, you assign the DevTest Labs User role to the Developers group. Does this meet the goal?

          • A. No
          • B. Yes

          Answer: A

          Explanation: DevTest Labs User role only lets you connect, start, restart, and shutdown virtual machines in your Azure DevTest Labs.
          You would need the Logic App Contributor role. References:
          https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles https://docs.microsoft.com/en-us/azure/logic-apps/logic-apps-securing-a-logic-app

          NEW QUESTION 7
          You have an Azure subscription named Subscription1.
          You have 5 TB of data that you need to transfer to Subscription1. You plan to use an Azure Import/Export job.
          What can you use as the destination of the imported data?

          • A. A virtual machine
          • B. Azure Data Factory
          • C. The Azure File Sync Storage Sync Service
          • D. An Azure Cosmos DB database
          • E. Azure File Storage
          • F. Azure SQL Database

          Answer: E

          Explanation: Azure Import/Export service is used to securely import large amounts of data to Azure Blob storage and Azure Files by shipping disk drives to an Azure datacenter.
          References:
          https://docs.microsoft.com/en-us/azure/storage/common/storage-import-export-service

          NEW QUESTION 8
          You have an Azure subscription that contains three virtual networks named VNet1, VNet2, VNet3.
          VNet2
          contains a virtual appliance named VM2 that operates as a router.
          You are configuring the virtual networks in a hub and spoke topology that uses VNet2 as the hub network.
          You plan to configure peering between VNet1 and VNet2 and between VNet2 and VNet3. You need to provide connectivity between VNet1 and VNet3 through VNet2.
          Which two configurations should you perform? Each correct answer presents part of the solution.
          NOTE: Each correct selection is worth one point.

          • A. On the peering connections, use remote gateways.
          • B. Create a route filter.
          • C. Create route tables and assign the table to subnets.
          • D. On the peering connections, allow gateway transit.
          • E. On the peering connections, allow forwarded traffic.

          Answer: AD

          Explanation: Allow gateway transit: Check this box if you have a virtual network gateway attached to this virtual network and want to allow traffic from the peered virtual network to flow through the gateway.
          The peered virtual network must have the Use remote gateways checkbox checked when setting up the peering from the other virtual network to this virtual network.
          References:
          https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-manage- peering#requirements-and-constraints

          NEW QUESTION 9
          HOTSPOT
          You have an Azure subscription named Subscrption1 that is associated to an Azure Active Directory (Azure AD) tenant named AAD1.
          Subscription1 contains the objects in the following table:
          AZ-103 dumps exhibit
          You plan to create a single backup policy for Vault1. To answer, select the appropriate options in the answer area.
          NOTE: Each correct selection is worth one point.
          AZ-103 dumps exhibit

            Answer:

            Explanation: Box 1: RG1 only Box 2: 99 years
            With the latest update to Azure Backup, customers can retain their data for up to 99 years in Azure. Note: A backup policy defines a matrix of when the data snapshots are taken, and how long those snapshots are retained.
            The backup policy interface looks like this:
            AZ-103 dumps exhibit
            References: https://docs.microsoft.com/en-us/azure/backup/backup-azure-vms-first-look-arm#defining-a-backup-policy
            https://blogs.microsoft.com/firehose/2015/02/16/february-update-to-azure-backup-includes-data-retention-up-to-99-years-offline-backup-and-more/

            NEW QUESTION 10
            HOTSPOT
            You have an Azure subscription named Subscription1 that contains the resources in the following table.
            AZ-103 dumps exhibit
            VM1 and VM2 run the websites in the following table.
            AZ-103 dumps exhibit
            AppGW1 has the backend pools in the following table.
            AZ-103 dumps exhibit
            DNS resolves site1.contoso.com, site2.contoso.com, and site3.contoso.com to the IP address of AppGW1.
            AppGW1 has the listeners in the following table.
            AZ-103 dumps exhibit
            AppGW1 has the rules in the following table.
            AZ-103 dumps exhibit
            For each of the following statements, select Yes if the statement is true. Otherwise, select No.
            NOTE: Each correct selection is worth one point.
            AZ-103 dumps exhibit

              Answer:

              Explanation: Vm1 is in Pool1. Rule2 applies to Pool1, Listener 2, and site2.contoso.com

              NEW QUESTION 11
              You have an Azure subscription that contains a policy-based virtual network gateway named GW1 and a virtual network named VNet1. You need to ensure that you can configure a point-to-site connection from VNet1 to an on-premises computer. Which two actions should you perform? Each correct answer presents part of the solution.
              NOTE: Each correct selection is worth one point.

              • A. Create a route-based virtual network gateway.
              • B. Delete GWL
              • C. Add a public IP address space to VNet1.
              • D. Add a connection to GW1.
              • E. Reset GW1.
              • F. Add a service endpoint to VNet1.

              Answer: AB

              Explanation: E: Policy-based VPN devices use the combinations of prefixes from both networks to define how traffic is encrypted/decrypted through IPsec tunnels. It is typically built on firewall devices that perform packet filtering. IPsec tunnel encryption and decryption are added to the packet filtering and processing engine.
              F: A VPN gateway is used when creating a VPN connection to your on-premises network.
              Route-based VPN devices use any-to-any (wildcard) traffic selectors, and let routing/forwarding tables direct traffic to different IPsec tunnels. It is typically built on router platforms where each IPsec tunnel is modeled as a network interface or VTI (virtual tunnel interface).
              Incorrect Answers:
              D: Point-to-Site connections do not require a VPN device or a public-facing IP address. References:
              https://docs.microsoft.com/en-us/azure/vpn-gateway/create-routebased-vpn-gateway-portal https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-connect-multiple-policybased-rm- ps

              NEW QUESTION 12
              HOTSPOT
              You have an Azure subscription1 that contains the resource shown in the following table.
              AZ-103 dumps exhibit
              The status of VM1 is Running.
              You assign an Azure policy as shown in the exhibit. (Click the Exhibit tab.) You assign the policy by using the following parameters.
              AZ-103 dumps exhibit
              For each of the following statements, select YES if the statements is true. Otherwise, select No. Note: Each correct selection is worth one point.
              AZ-103 dumps exhibit

                Answer:

                Explanation: AZ-103 dumps exhibit

                NEW QUESTION 13
                Your company has an Azure subscription named Subscription1.
                The company also has two on-premises servers named Server1 and Server2 that run Windows Server 2021. Server1 is configured as a DNS server that has a primary DNS zone named adatum.com. Adatum.com contains 1,000 DNS records.
                You manage Server1 and Subscription1 from Server2. Server2 has the following tools installed:
                 The DNS Manager console
                 Azure PowerShell
                 Azure CLI 2.0
                You need to move the adatum.com zone to Subscription1. The solution must minimize administrative effort.
                What should you use?

                • A. the DNS Manager console
                • B. the Azure portal
                • C. Azure PowerShell
                • D. Azure CLI

                Answer: D

                Explanation: Azure DNS supports importing and exporting zone files by using the Azure command-line interface (CLI). Zone file import is not currently supported via Azure PowerShell or the Azure portal. References: https://docs.microsoft.com/en-us/azure/dns/dns-import-export

                NEW QUESTION 14
                Overview
                The following section of the exam is a lab. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design.
                Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn’t matter how you accomplish the task, if you successfully perform it, you will earn credit for that task. Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
                Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
                To start the lab
                You may start the lab by clicking the Next button.
                You plan to host several secured websites on Web01.
                You need to allow HTTPS over TCP port 443 to Web01 and to prevent HTTP over TCP port 80 to Web01.
                What should you do from the Azure portal?

                  Answer:

                  Explanation: Answer:
                  See explanation below.
                  You can filter network traffic to and from Azure resources in an Azure virtual network with a network security group. A network security group contains security rules that allow or deny inbound network traffic to, or outbound network traffic from, several types of Azure resources.
                  A network security group contains security rules that allow or deny inbound network traffic to, or outbound network traffic from, several types of Azure resources.
                  Step A: Create a network security group
                  A1. Search for and select the resource group for the VM, choose Add, then search for and select Network security group.
                  A2. Select Create.
                  AZ-103 dumps exhibit
                  The Create network security group window opens. A3. Create a network security group
                  Enter a name for your network security group.
                  Select or create a resource group, then select a location. A4. Select Create to create the network security group.
                  Step B: Create an inbound security rule to allows HTTPS over TCP port 443 B1. Select your new network security group.
                  B2. Select Inbound security rules, then select Add. B3. Add inbound rule
                  B4. Select Advanced.
                  From the drop-down menu, select HTTPS.
                  You can also verify by clicking Custom and selecting TCP port, and 443. B5. Select Add to create the rule.
                  Repeat step B2-B5 to deny TCP port 80
                  B6. Select Inbound security rules, then select Add. B7. Add inbound rule
                  B8. Select Advanced.
                  Clicking Custom and selecting TCP port, and 80. B9. Select Deny.
                  Step C: Associate your network security group with a subnet
                  Your final step is to associate your network security group with a subnet or a specific network interface.
                  C1. In the Search resources, services, and docs box at the top of the portal, begin typing Web01. When the Web01 VM appears in the search results, select it.
                  C2. Under SETTINGS, select Networking. Select Configure the application security groups, select the Security Group you created in Step A, and then select Save, as shown in the following picture:
                  AZ-103 dumps exhibit
                  References:
                  https://docs.microsoft.com/en-us/azure/virtual-network/tutorial-filter-network-traffic

                  NEW QUESTION 15
                  HOTSPOT
                  You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. You add the users in the following table.
                  AZ-103 dumps exhibit
                  Which user can perform each configuration? To answer, select the appropriate options in the answer area.
                  NOTE: Each correct selection is worth one point.
                  AZ-103 dumps exhibit

                    Answer:

                    Explanation: Box 1: User1 and User3 only.
                    The Owner Role lets you manage everything, including access to resources.
                    The Network Contributor role lets you manage networks, but not access to them. Box 2: User1 and User2 only
                    The Security Admin role: In Security Center only: Can view security policies, view security states, edit security policies, view alerts and recommendations, dismiss alerts and recommendations.
                    References:
                    https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles

                    NEW QUESTION 16
                    You have an Azure subscription that contains a virtual machine named VM1. VM1 hosts a line-of- business application that is available 24 hours a day. VM1 has one network interface and one managed disk. VM1 uses the D4s v3 size.
                    You plan to make the following changes to VM1:
                     Change the size to D8s v3.
                     Add a 500-GB managed disk.
                     Add the Puppet Agent extension.
                     Attach an additional network interface. Which change will cause downtime for VM1?

                    • A. Change the size to D8s v3.
                    • B. Add the Puppet Agent extension.
                    • C. Attach an additional network interface.
                    • D. Add a 500-GB managed disk.

                    Answer: A

                    Explanation: While resizing the VM it must be in a stopped state.
                    References: https://azure.microsoft.com/en-us/blog/resize-virtual-machines/

                    NEW QUESTION 17
                    You deploy an Azure Application Gateway.
                    You need to ensure that all the traffic requesting https://adatum.com/internal resources is directed to an internal server pool and all the traffic requesting https://adatum.com/external resources is directed to an external server pool.
                    What should you configure on the Application Gateway?

                    • A. SSL termination
                    • B. basic routing
                    • C. multi-site listeners
                    • D. URL path-based routing

                    Answer: D

                    NEW QUESTION 18
                    You have an Azure subscription.
                    You enable multi-factor authentication for all users.
                    Some users report that the email applications on their mobile device cannot co browser and from Microsoft Outlook 2021 on their computer.
                    You need to ensure that the users can use the email applications on their mobile device. What should you instruct the users to do?
                    The users can access Exchange Online by using a web

                    • A. Reset the Azure Active Directory (Azure AD) password.
                    • B. Reinstall the Microsoft Authenticator app.
                    • C. Create an app password.
                    • D. Enable self-service password reset.

                    Answer: D

                    Explanation: References:
                    https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-howitworks

                    P.S. Certshared now are offering 100% pass ensure AZ-103 dumps! All AZ-103 exam questions have been updated with correct answers: https://www.certshared.com/exam/AZ-103/ (303 New Questions)


                    START AZ-103 EXAM