[2026] Easy To Download AZ-104 Actual Exam Dumps Resources [Q72-Q96]

Share

[2026] Easy To Download AZ-104 Actual Exam Dumps Resources

Uplift Your AZ-104 Exam Marks With The Help of AZ-104 Dumps


Microsoft AZ-104 Certification Exam consists of 40-60 multiple-choice questions that must be completed within 150 minutes. AZ-104 exam fee is $165, and the certification is valid for two years. AZ-104 exam is available in English, Japanese, Korean, and Simplified Chinese. Microsoft offers official training courses and study materials to help candidates prepare for the exam. Microsoft Azure Administrator certification exam is rigorous and requires a thorough understanding of Azure services, but it is a valuable investment in the career of professionals who want to work with cloud services and Azure technologies.


Final Thoughts

If you want to achieve a high score after taking the Microsoft AZ-104 exam, you need to know a lot about it and learn all its topics. This guide and the hints for your preparation will make a significant difference during your preparation process. So, follow them to succeed, and good luck!


Microsoft AZ-104 exam, also known as the Microsoft Azure Administrator exam, is designed to test an individual's knowledge and skills in managing and monitoring Microsoft Azure services. AZ-104 exam is intended for individuals who are responsible for implementing, managing, and monitoring Azure resources and services.

 

NEW QUESTION # 72
You have an Azure subscription that contains the resources shown in the following table:

You assign a policy to RG6 as shown in the following table:

To RG6, you apply the tag: RGroup: RG6.
You deploy a virtual network named VNET2 to RG6.
Which tags apply to VNET1 and VNET2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/azure-resource-manager/management/tag-policies


NEW QUESTION # 73
Question: 153
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription named Subscription1. Subscription1 contains a resource group named RG1. RG1 contains resources that were deployed by using templates.
You need to view the date and time when the resources were created in RG1.
Solution: From the RG1 blade, you click Automation script.
Does this meet the goal?

  • A. No
  • B. Yes

Answer: A

Explanation:
From the RG1 blade, click Deployments. You see a history of deployment for the resource group.
Reference:
https://docs.microsoft.com/en-us/azure/azure-resource-manager/templates/template-tutorial-create-first-template?tabs=azure-powershell Through activity logs, you can determine:
* what operations were taken on the resources in your subscription
* who started the operation
* when the operation occurred
* the status of the operation
* the values of other properties that might help you research the operation
1. On the Azure portal menu, select Monitor, or search for and select Monitor from any page

2. Select Activity Log.

3. You see a summary of recent operations. A default set of filters is applied to the operations. Notice the information on the summary includes who started the action and when it happened.

https://docs.microsoft.com/en-us/azure/azure-resource-manager/management/view-activity-logs


NEW QUESTION # 74
You have an Azure virtual machine named VM1.
The network interface for VM1 is configured as shown in the exhibit. (Click the Exhibit tab.) You deploy a web server on VM1, and then create a secure website that is accessible by using the HTTPS protocol. VM1 is used as a web server only.
You need to ensure that users can connect to the website from the internet.
What should you do?

  • A. Create a new inbound rule that allows TCP protocol 443 and configure the protocol to have a priority of
    501.
  • B. Delete Rule1.
  • C. Modify the protocol of Rule4.
  • D. For Rule5, change the Action to Allow and change the priority to 401.

Answer: D

Explanation:
Explanation
Rule 2 is blocking HTTPS access (port 443) and has a priority of 500.
Changing Rule 5 (ports 50-5000) and giving it a lower priority number will allow access on port 443.
Note: Rules are processed in priority order, with lower numbers processed before higher numbers, because lower numbers have higher priority. Once traffic matches a rule, processing stops.
References:
https://docs.microsoft.com/en-us/azure/virtual-network/security-overview


NEW QUESTION # 75
You have an Azure web app named WebApp1 that runs in an Azure App Service plan named ASP1. ASP1 is based on the D1 pricing tier.
You need to ensure that WebApp1 can be accessed only from computers on your on-premises network. The solution must minimize costs.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://azure.microsoft.com/en-us/pricing/details/app-service/windows/
https://docs.microsoft.com/en-us/azure/cdn/cdn-cors


NEW QUESTION # 76
You have two Azure virtual machines named VM1 and VM2. VM1 has a single data disk named Disk1. You need to attach Disk1 to VM2. The solution must minimize downtime for both virtual machines.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

1 - Stop VM1.
2 - Detach Disk1 from VM1.
3 - Start VM1.
4 - Attach Disk1 to VM2
Reference:
https://docs.microsoft.com/en-us/azure/virtual-machines/windows/detach-disk
https://docs.microsoft.com/en-us/azure/lab-services/devtest-lab-attach-detach-data-disk


NEW QUESTION # 77
You plan to deploy 20 Azure virtual machines by using an Azure Resource Manager template. The virtual machines will run the latest version of Windows Server 2016 Datacenter by using an Azure Marketplace image.
You need to complete the storageProfile section of the template.
How should you complete the storageProfile section? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/rest/api/compute/virtualmachines/createorupdate


NEW QUESTION # 78
You have an Azure subscription,
You have an on-premises virtual machine named VM1, The settings for VM" are shown in the exhibit. (Click the Exhibit tab.) You need to ensure that you can use the disks attached to VM' as a template for Azure virtual machines, What should you modify on VM1?

  • A. Integration Services
  • B. the memory
  • C. the processor
    (C. the hard drive
    D, the network adapters

Answer: B


NEW QUESTION # 79
You create a Recovery Services vault backup policy named Policy1 as shown in the following exhibit:


Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: 10 years
The yearly backup point occurs to 1 March and its retention period is 10 years.
Box 2: 36 months
The monthly backup point occurs on the 1st of every month and its retention period is 36 months.


NEW QUESTION # 80
You need to identify the storage requirements for Contoso.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Yes
Contoso is moving the existing product blueprint files to Azure Blob storage.
Use unmanaged standard storage for the hard disks of the virtual machines. We use Page Blobs for these.
Box 2: No


NEW QUESTION # 81
You have an Azure subscription that contains the following storage account:

You need 10 create a request to Microsoft Support to perform a live migration of storage1 to Zone Redundant Storage (ZRS) replication. How should you modify storage1 before the Live migration?

  • A. Disable Advanced threat protection
  • B. Set the replication to Locally-redundant storage (IRS)
  • C. Set the access tier to Hot
  • D. Remove the lock

Answer: B


NEW QUESTION # 82
You have a pay-as-you-go Azure subscription that contains the virtual machines shown in the following table.

You create the budget shown in the following exhibit.

The AG1 action group contains a user named [email protected] only.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Box 1: VM1 and VM2 continues to run
When the budget thresholds you've created are exceeded, only notifications are triggered. None of your resources are affected and your consumption isn't stopped. You can use budgets to compare and track spending as you analyze costs.
Box 2: one email notification will be sent each month
Budget alerts for Resource Group RG1, which include VM1, but not VM2.VM1 consumes 20 Euro/day. The
50% ,500 Euro limit, will be reached in 25 days, and an email will be sent.
The 70% and 100% alert conditions will not be reached within a month, and they don't trigger email actions anyway.
References:
https://docs.microsoft.com/en-gb/azure/cost-management-billing/costs/tutorial-acm-create-budgets
https://docs.microsoft.com/en-us/azure/cost-management-billing/costs/cost-mgt-alerts-monitor-usage-spending


NEW QUESTION # 83
You have the Azure management groups shown in the following table.

You add Azure subscriptions to the management groups as shown in the following table.

You create the Azure policies shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/governance/management-groups/overview
https://docs.microsoft.com/en-us/azure/governance/management-groups/manage#moving-management-groups-and-subscriptions


NEW QUESTION # 84
You have an Azure subscription named Subscription1 that contains the resources shown in the following table.

You plan to configure Azure Backup reports for Vault1.
You are configuring the Diagnostics settings for the AzureBackupReports log.
Which storage accounts and which Log Analytics workspaces can you use for the Azure Backup reports of Vault1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Storage accounts: # storage3 only
Log Analytics workspaces: # Analytics3 only
In Azure, Backup Reports use Azure Monitor diagnostic settings to export data from a Recovery Services vault (RSV) to either:
A storage account, or
A Log Analytics workspace.
However, region alignment is a mandatory requirement for both targets. The diagnostic destination (Storage or Log Analytics) must be in the same Azure region as the Recovery Services vault.
1## Recovery Services Vault Location:
From the given table:
Vault1 # Location: West Europe
Therefore, both the storage account and Log Analytics workspace must also be in West Europe.
2## Eligible Storage Accounts:
From the listed resources:
storage1: East US # # (Different region)
storage2: West US # # (Different region)
storage3: West Europe # # (Same region as Vault1)
## Valid Storage Account: storage3 only
3## Eligible Log Analytics Workspaces:
From the listed resources:
Analytics1: East US # # (Different region)
Analytics2: West US # # (Different region)
Analytics3: West Europe # # (Same region as Vault1)
## Valid Log Analytics Workspace: Analytics3 only
4## Microsoft Official Documentation Extract (Azure Administrator Study Guide - Implement and Manage Storage, and Azure Docs):
"For Backup Reports, the destination Log Analytics workspace or storage account must be in the same Azure region as the Recovery Services vault.
Cross-region configuration is not supported for diagnostic settings of Azure Backup vaults." (Reference: Azure Backup documentation - Configure reports for Azure Backup; Azure Monitor Diagnostic Settings Overview) This ensures that diagnostic data generated by the vault is securely and efficiently stored within the same geographic boundary, maintaining compliance and reducing latency.


NEW QUESTION # 85
You have a registered DNS domain named contoso.com.
You create a public Azure DNS zone named contoso.com.
You need to ensure that records created in the contoso.com zone are resolvable from the internet.
What should you do?

  • A. Create the SOA record in contoso.com.
  • B. Create NS records in contoso.com.
  • C. Modify the NS records in the DNS domain registrar.
  • D. Modify the SOA record in the DNS domain registrar.

Answer: C

Explanation:
Delegate the domain
Once the DNS zone gets created and you have the name servers, you'll need to update the parent domain with the Azure DNS name servers. Each registrar has its own DNS management tools to change the name server records for a domain.
In the registrar's DNS management page, edit the NS records and replace the NS records with the Azure DNS name servers.
When you delegate a domain to Azure DNS, you must use the name servers that Azure DNS provides. Use all four name servers, regardless of the name of your domain. Domain delegation doesn't require a name server to use the same top-level domain as your domain.
https://docs.microsoft.com/en-us/azure/dns/dns-delegate-domain-azure-dns


NEW QUESTION # 86
You have an Azure subscription that is linked to an Azure AD tenant. The tenant contains two users named User1 and User2. The subscription contains the resources shown in the following table.

The subscription contains the alert rules shown in the following table.

The users perform the following actions:
* User1 creates a new virtual disk and attaches the disk to VM1.
* User2 creates a new resource tag and assigns the tag to RG1 and VM1.
Which alert rules are triggered by each user? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

In this case, you have two alert rules: Alert1 and Alert2. Alert1 has a scope of RG1, which means it applies to all the resources in the resource group named RG1. Alert1 has a condition of All Administrative operations, which means it triggers when any administrative operation is performed on the resources in RG1. An administrative operation is any operation that changes the configuration or state of a resource, such as creating, deleting, updating, or restarting.
Alert2 has a scope of VM1, which means it applies only to the virtual machine named VM1. Alert2 also has a condition of All Administrative operations, which means it triggers when any administrative operation is performed on VM1.
Now, let's see which alert rules are triggered by each user.
User1 creates a new virtual disk and attaches the disk to VM1. This is an administrative operation on VM1, so it triggers Alert2. However, it does not trigger Alert1, because the new disk is not part of RG1. Therefore, the correct answer for User1 is C. Only Alert2 is triggered.
User2 creates a new resource tag and assigns the tag to RG1 and VM1. This is also an administrative operation on both RG1 and VM1, so it triggers both Alert1 and Alert2. Therefore, the correct answer for User2 is D. Alert1 and Alert2 are triggered.


NEW QUESTION # 87
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription named Subscription1 that contains the resources shown in the following table.

VM1 connects to a virtual network named VNET2 by using a network interface named NIC1.
You need to create a new network interface named NIC2 for VM1.
Solution: You create NIC2 in RG1 and West US.
Does this meet the goal?

  • A. Yes
  • B. NO

Answer: A

Explanation:
The virtual machine you attach a network interface to and the virtual network you connect it to must exist in the same location, here West US, also referred to as a region.
Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-network-interface


NEW QUESTION # 88
You have an Azure subscription that contains an Azure virtual machine named VM1. VM1 runs a financial reporting app named App1 that does not support multiple active instances.
At the end of each month, CPU usage for VM1 peaks when App1 runs.
You need to create a scheduled runbook to increase the processor performance of VM1 at the end of each month.
What task should you include in the runbook?

  • A. Add a Desired State Configuration (DSC) extension to VM1.
  • B. Add VM1 to a scale set.
  • C. Modify the VM size property of VM1.
  • D. Add the Azure Performance Diagnostics agent to VM1.
  • E. Increase the vCPU quota for the subscription.

Answer: A

Explanation:
Explanation/Reference:
https://docs.microsoft.com/en-us/azure/automation/automation-quickstart-dsc-configuration


NEW QUESTION # 89
You have an Azure subscription named Sub1.
You plan to deploy a multi-tiered application that will contain the tiers shown in the following table.

You need to recommend a networking solution to meet the following requirements:
* Ensure that communication between the web servers and the business logic tier spreads equally across the virtual machines.
* Protect the web servers from SQL injection attacks.
Which Azure resource should you recommend for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Box 1: an internal load balancer
Azure Internal Load Balancer (ILB) provides network load balancing between virtual machines that reside inside a cloud service or a virtual network with a regional scope.
Box 2: an application gateway that uses the WAF tier
Azure Web Application Firewall (WAF) on Azure Application Gateway provides centralized protection of your web applications from common exploits and vulnerabilities. Web applications are increasingly targeted by malicious attacks that exploit commonly known vulnerabilities.
References:
https://docs.microsoft.com/en-us/azure/web-application-firewall/ag/ag-overview


NEW QUESTION # 90
You have an Azure subscription that contains the resources in the following table.

You install the Web Server server role (IIS) on VM1 and VM2, and then and VM1 and VM2 to LB1.

Answer:

Explanation:

Explanation


NEW QUESTION # 91
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains the virtual machines shown in the following table.
You deploy a load balancer that has the following configurations:
*Name: LB1
*Type: Internal
*SKU: Standard
*Virtual network: VNET1
You need to ensure that you can add VM1 and VM2 to the backend pool of LB1.
Solution: You create two Standard public IP addresses and associate a Standard SKU public IP address to the network interface of each virtual machine.
Does this meet the goal?

  • A. No
  • B. Yes

Answer: A

Explanation:
This question tests understanding of Azure Load Balancer SKU compatibility and backend pool configuration requirements.
# Scenario Summary
You have:
VM1 and VM2 in the same VNet (VNET1)
A Load Balancer (LB1) configured as:
Type: Internal
SKU: Standard
You need to ensure that VM1 and VM2 can be added to LB1's backend pool.
The proposed solution:
"You create two Standard public IP addresses and associate a Standard SKU public IP address to the network interface of each virtual machine."
# Understanding Azure Load Balancer Requirements
1. Backend pool requirements for a Standard Load Balancer:
All VMs must be in the same virtual network as the load balancer.
Each VM's NIC must be configured with a Standard SKU IP configuration (private or public).
The Load Balancer SKU must match the SKU of the IP addresses associated with the VM network interfaces.
2. Internal Load Balancer behavior:
An Internal Load Balancer (ILB) distributes traffic within a virtual network using private IP addresses, not public IPs.
Therefore, the backend VMs do not need public IPs - and adding them does not affect backend pool membership.
3. SKU alignment rule (Microsoft Docs):
"You can only attach virtual machines or instances that use Standard IP configurations to a Standard Load Balancer. Basic and Standard SKUs are not interchangeable." However:
A public IP is only required for inbound Internet access or outbound NAT, not for internal load balancing.
For an Internal Standard Load Balancer, backend pool members require Standard SKU NIC configurations, not public IPs.
# Why the Proposed Solution Fails
The solution suggests creating two Standard public IPs and assigning them to the VMs' NICs.
This does not enable VM1 and VM2 to join the backend pool of an internal load balancer, because:
The load balancer type is internal, meaning it routes private traffic within the virtual network, not via public IPs.
Backend pool membership depends on the NIC's private IP configuration, not its public IP.
Adding public IPs only exposes VMs to the Internet and does not influence load balancer backend eligibility.
Thus, this action is unnecessary and does not meet the goal.
# Correct Solution (for reference)
To meet the goal:
Ensure VM1 and VM2 have NICs configured with Standard SKU private IPs.
Ensure both VMs are in VNet1, the same virtual network as LB1.
No need to assign public IPs to internal backend VMs.
You could also ensure:
az network nic ip-config update \
--name ipconfig1 \
--nic-name VM1-nic \
--resource-group RG1 \
--private-ip-address-version IPv4 \
--sku Standard
# Final Verified Answer:
B). No
# Microsoft Azure Documentation (Exam-Verified Extracts)
Azure Load Balancer SKU Comparison:
"Internal Load Balancer uses private IP addresses. Public IPs are not required or used for internal balancing." Backend Pool Membership:
"Virtual machines in the backend pool must be in the same virtual network as the load balancer and use matching Standard SKU IP configurations." Public vs Internal Load Balancer:
"For internal load balancers, only private frontends and backend configurations are supported."
# Final Verified Answer: B. No
Assigning Standard public IPs to VMs does not affect internal load balancer backend connectivity. Backend membership depends on private IP configurations in the same VNet and matching SKU, not public IPs.


NEW QUESTION # 92
You have an Azure subscription that contains the Azure virtual machines shown in the following table.

You configure the network interfaces of the virtual machines to use the settings shown in the following table

From the settings of VNET1, you configure the DNS servers shown in the following exhibit.

The virtual machines can successfully connect to the DNS server that has an IP address of 192.168.10.15 and the DNS server that has an IP address of 193.77.134.10.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Answer:

Explanation:


NEW QUESTION # 93
You have an Azure subscription that contains the virtual networks shown in the following table.
The subscription contains the private DNS zones shown in the following table.
You add virtual network links to the private DNS zones as shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/dns/private-dns-virtual-network-links
https://docs.microsoft.com/en-us/azure/dns/private-dns-autoregistration


NEW QUESTION # 94
You have an Azure subscription.
You create the following file named Deploy.json.

You connect to the subscription and run the following commands.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 95
You recently created a new Azure subscription that contains a user named Admin1.
Admin1 attempts to deploy an Azure Marketplace resource by using an Azure Resource Manager template. Admin1 deploys the template by using Azure PowerShell and receives the following error message: "User failed validation to purchase resources. Error message: "Legal terms have not been accepted for this item on this subscription. To accept legal terms, please go to the Azure portal (http:// go.microsoft.com/fwlink/?LinkId=534873) and configure programmatic deployment for the Marketplace item or create it there for the first time." You need to ensure that Admin1 can deploy the Marketplace resource successfully.
What should you do?

  • A. From the Azure portal, assign the Billing administrator role to Admin1
  • B. From Azure PowerShell, run the Set-AzApiManagementSubscription cmdlet
  • C. From Azure PowerShell, run the Set-AzMarketplaceTerms cmdlet
  • D. From the Azure portal, register the Microsoft.Marketplace resource provider

Answer: C

Explanation:
Set-AzMarketplaceTerms - "Accept or reject terms for a given publisher id(Publisher), offer id(Product) and plan id(Name). Please use Get-AzMarketplaceTerms to get the agreement terms."
https://docs.microsoft.com/en-us/powershell/module/az.marketplaceordering/set- azmarketplaceterms?view=azps-8.3.0


NEW QUESTION # 96
......

Use Microsoft AZ-104 Dumps To Succeed Instantly in AZ-104 Exam: https://examcollection.dumpsactual.com/AZ-104-actualtests-dumps.html