AZ-102 Exam Questions - Online Test


AZ-102 Premium VCE File

Learn More 100% Pass Guarantee - Dumps Verified - Instant Download
150 Lectures, 20 Hours

certleader.com

AZ-102 Dumps Questions are updated and AZ-102 Exam Dumps are verified by experts. Once you have completely prepared with our AZ-102 Exam Dumps you will be ready for the real AZ-102 exam without a problem. We have AZ-102 Exam Questions and Answers. PASSED AZ-102 Braindumps First attempt! Here What I Did.

Free demo questions for Microsoft AZ-102 Exam Dumps Below:

NEW QUESTION 1
You have an Azure Active Directory (Azure AD) tenant.
All administrators must enter a verification code to access the Azure portal.
You need to ensure that the administrators can access the Azure portal only from your on-premises network. What should you configure?

  • A. the multi-factor authentication service settings
  • B. an Azure AD Identity Protection user risk policy
  • C. the default for all the roles in Azure AD Privileged Identity Management
  • D. an Azure AD Identity Protection sign-in risk policy

Answer: A

NEW QUESTION 2
HOT SPOT
You plan to use Azure Network Watcher to perform the following tasks:
Task1: Identify a security rule that prevents a network packet from reaching an Azure virtual machine.
Task2: Validate outbound connectivity from an Azure virtual machine to an external host.
Which feature should you use for each task? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
AZ-102 dumps exhibit

    Answer:

    Explanation: Task 1: IP flow verify
    IP flow verify checks if a packet is allowed or denied to or from a virtual machine. The information consists of direction, protocol, local IP, remote IP, local port, and remote port. If the packet is denied by a security group, the name of the rule that denied the packet is returned. While any source or destination IP can be chosen, IP flow verify helps administrators quickly diagnose connectivity issues from or to the internet and from or to the on-premises environment.
    Task 2:
    With the addition of Connection Troubleshoot, Network Watcher will see an incremental increase in its capabilities and ways for you to utilize it in your day to day operations. You can now, for example, check connectivity between source (VM) and destination (VM, URI, FQDN, IP Address). References:
    https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-ip-flow-verify-overview https://azure.microsoft.com/en-us/blog/network-watcher-connection-troubleshoot-now-generallyavailable/

    NEW QUESTION 3
    SIMULATION
    Click to expand each objective. To connect to the Azure portal, type https://portal.azure.com in the browser address bar.
    AZ-102 dumps exhibit
    AZ-102 dumps exhibit
    AZ-102 dumps exhibit
    When you are finished performing all the tasks, click the ‘Next’ button.
    Note that you cannot return to the lab once you click the ‘Next’ button. Scoring occur in the background while you complete the rest of the exam.
    Overview
    The following section of the exam is a lab. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design. Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn’t matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
    Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
    Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
    To start the lab
    You may start the lab by clicking the Next button.
    Another administrator attempts to establish connectivity between two virtual networks named VNET1 and VNET2.
    The administrator reports that connections across the virtual networks fail.
    You need to ensure that network connections can be established successfully between VNET1 and VNET2 as quickly as possible.
    What should you do from the Azure portal?

      Answer:

      Explanation: You can connect one VNet to another VNet using either a Virtual network peering, or an Azure VPN Gateway.
      To create a virtual network gateway
      Step1 : In the portal, on the left side, click +Create a resource and type 'virtual network gateway' in search. Locate Virtual network gateway in the search return and click the entry. On the Virtual network gateway page, click Create at the bottom of the page to open the Create virtual network gateway page.
      Step 2: On the Create virtual network gateway page, fill in the values for your virtual network gateway.
      AZ-102 dumps exhibit
      AZ-102 dumps exhibit
      Name: Name your gateway. This is not the same as naming a gateway subnet. It's the name of the gateway object you are creating.
      Gateway type: Select VPN. VPN gateways use the virtual network gateway type VPN.
      Virtual network: Choose the virtual network to which you want to add this gateway. Click Virtual network to open the 'Choose a virtual network' page. Select the VNet. If you don't see your VNet, make sure the Location field is pointing to the region in which your virtual network is located. Gateway subnet address range: You will only see this setting if you did not previously create a gateway subnet for your virtual network. If you previously created a valid gateway subnet, this setting will not appear.
      Step 4: Select Create New to create a Gateway subnet.
      AZ-102 dumps exhibit
      Step 5: Click Create to begin creating the VPN gateway. The settings are validated and you'll see the "Deploying Virtual network gateway" tile on the dashboard. Creating a gateway can take up to 45 minutes. You may need to refresh your portal page to see the completed status.
      References: https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-vnet-vnetresource-manager-portal?

      NEW QUESTION 4
      You are the global administrator for an Azure Active Directory (Azure AD) tenant named adatum.com.
      You need to enable two-step verification for Azure users. What should you do?

      • A. Configure a playbook in Azure AD conditional access policy.
      • B. Create an Azure AD conditional access policy.
      • C. Create and configure the Identify Hub.
      • D. Install and configure Azure AD Connec

      Answer: B

      Explanation: References:
      https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings

      NEW QUESTION 5
      DRAG DROP
      You need to prepare the environment to ensure that the web administrators can deploy the web apps as quickly as possible.
      Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
      AZ-102 dumps exhibit

        Answer:

        Explanation:
        Step 1:
        First you create a storage account using the Azure portal.
        Step 2:
        Select Automation options at the bottom of the screen. The portal shows the template on the Template tab.
        Deploy: Deploy the Azure storage account to Azure. Step 3:
        Share the template.
        Scenario: Web administrators will deploy Azure web apps for the marketing department. Each web app will be added to a separate resource group. The initial configuration of the web apps will be identical. The web administrators have permission to deploy web apps to resource groups.
        References: https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-managerquickstart-create-templates-use-the-portal

        NEW QUESTION 6
        A web developer creates a web application that you plan to deploy as an Azure web app. Users must enter credentials to access the web application.
        You create a new web app named WebAppl1 and deploy the web application to WebApp1. You need to disable anonymous access to WebApp1.
        What should you configure?

        • A. Advanced Tools
        • B. Authentication/ Authorization
        • C. Access control (IAM)
        • D. Deployment credentials

        Answer: B

        Explanation: Anonymous access is an authentication method. It allows users to establish an anonymous connection.
        References:
        https://docs.microsoft.com/en-us/biztalk/core/guidelines-for-resolving-iis-permissions-problems

        NEW QUESTION 7
        You need to prevent remote users from publishing via FTP to a function app named FunctionApplod7509087fa. Remote users must be able to publish via FTPS. What should you do from the Azure portal?

          Answer:

          Explanation: Step 1:
          Locate and select the function app FunctionApplod7509087fa. Step 2:
          Select Application Settings > FTP Access, change FTP access to FTPS Only, and click Save.
          AZ-102 dumps exhibit
          References:
          https://blogs.msdn.microsoft.com/appserviceteam/2021/05/08/web-apps-making-changes-to-ftpdeployments/

          NEW QUESTION 8
          Note: This questions is part of a series of questions that present the same scenario. Each questions in the series contains a unique solution that might meet the stated goals. Some questions sets might have more than one correct solution, while others might not have a correct solution. After you answer a questions in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
          You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource groups.
          Another administrator plans to create several network security groups (NSGs) in the subscription. You need to ensure that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks.
          Solution: You assign a built-in policy definition to the subscription. Does this meet the goal?

          • A. Yes
          • B. No

          Answer: B

          NEW QUESTION 9
          You have an Azure Service Bus.
          You need to implement a Service Bus queue that guarantees first in first-out (FIFO) delivery of messages.
          What should you do?

          • A. Set the Lock Duration setting to 10 seconds.
          • B. Enable duplicate detection.
          • C. Set the Max Size setting of the queue to 5 GB.
          • D. Enable partitioning.
          • E. Enable session

          Answer: E

          Explanation: Through the use of messaging sessions you can guarantee ordering of messages, that is first-in-firstout (FIFO) delivery of messages.
          References:
          https://docs.microsoft.com/en-us/azure/service-bus-messaging/service-bus-azure-and-service-busqueues- compared-contrasted

          NEW QUESTION 10
          HOT SPOT
          You have an Azure Storage accounts as shown in the following exhibit.
          AZ-102 dumps exhibit
          Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
          NOTE: Each correct selection is worth one point.
          AZ-102 dumps exhibit

            Answer:

            Explanation: Box 1: storageaccount1 and storageaccount2 only Box 2: All the storage accounts
            Note: The three different storage account options are: General-purpose v2 (GPv2) accounts, Generalpurpose v1 (GPv1) accounts, and Blob storage accounts.
            General-purpose v2 (GPv2) accounts are storage accounts that support all of the latest features for blobs, files, queues, and tables.
            Blob storage accounts support all the same block blob features as GPv2, but are limited to supporting only block blobs.
            General-purpose v1 (GPv1) accounts provide access to all Azure Storage services, but may not have the latest features or the lowest per gigabyte pricing.
            References: https://docs.microsoft.com/en-us/azure/storage/common/storage-account-options

            NEW QUESTION 11
            You need to resolve the Active Directory issue. What should you do?

            • A. From Active Directory Users and Computers, select the user accounts, and then modify the User PrincipalName value.
            • B. Run idfix.exe, and then use the Edit action.
            • C. From Active Directory Domains and Trusts, modify the list of UPN suffixes.
            • D. From Azure AD Connect, modify the outbound synchronization rul

            Answer: B

            Explanation: IdFix is used to perform discovery and remediation of identity objects and their attributes in an onpremises Active Directory environment in preparation for migration to Azure Active Directory. IdFix is
            intended for the Active Directory administrators responsible for directory synchronization with Azure Active Directory.
            Scenario: Active Directory Issue
            Several users in humongousinsurance.com have UPNs that contain special characters. You suspect that some of the characters are unsupported in Azure AD.
            References: https://www.microsoft.com/en-us/download/details.aspx?id=36832

            NEW QUESTION 12
            You are the global administrator for an Azure Active Directory (Azure AD) tenet named adatum.com. You need to enable two-step verification for Azure users.
            What should you do?

            • A. Create a sign-in risk policy in Azure AD Identity Protection
            • B. Enable Azure AD Privileged Identity Management.
            • C. Create and configure the Identity Hub.
            • D. Configure a security policy in Azure Security Cente

            Answer: A

            Explanation: With Azure Active Directory Identity Protection, you can: require users to register for multi-factor authentication handle risky sign-ins and compromised users
            References:
            https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/flows

            NEW QUESTION 13
            Your company registers a domain name of contoso.com.
            You create an Azure DNS named contoso.com and then you add an A record to the zone for a host named www that has an IP address of 131.107.1.10.
            You discover that Internet hosts are unable to resolve www.contoso.com to the 131.107.1.10 IP address.
            You need to resolve the name resolution issue.
            Solution: You modify the name servers at the domain registrar. Does this meet the goal?

            • A. Yes
            • B. No

            Answer: A

            Explanation: Before you can delegate your DNS zone to Azure DNS, you need to know the name servers for your zone. The NS record set contains the names of the Azure DNS name servers assigned to the zone. References:
            https://docs.microsoft.com/en-us/azure/dns/dns-delegate-domain-azure-dns

            NEW QUESTION 14
            Your company registers a domain name of contoso.com.
            You create an Azure DNS named contoso.com and then you add an A record to the zone for a host named www that has an IP address of 131.107.1.10.
            You discover that Internet hosts are unable to resolve www.contoso.com to the 131.107.1.10 IP address.
            You need to resolve the name resolution issue.
            Solution: You add an NS record to the contoso.com zone. Does this meet the goal?

            • A. Yes
            • B. No

            Answer: A

            Explanation: Before you can delegate your DNS zone to Azure DNS, you need to know the name servers for your
            zone. The NS record set contains the names of the Azure DNS name servers assigned to the zone. References: https://docs.microsoft.com/en-us/azure/dns/dns-delegate-domain-azure-dns

            NEW QUESTION 15
            You discover that VM3 does NOT meet the technical requirements. You need to verify whether the issue relates to the NSGs.
            What should you use?

            • A. Diagram in VNet1
            • B. the security recommendations in Azure Advisor
            • C. Diagnostic settings in Azure Monitor
            • D. Diagnose and solve problems in Traffic Manager Profiles
            • E. IP flow verify in Azure Network Watcher

            Answer: E

            Explanation: Scenario: Contoso must meet technical requirements including:
            Ensure that VM3 can establish outbound connections over TCP port 8080 to the applications servers in the Montreal office.
            IP flow verify checks if a packet is allowed or denied to or from a virtual machine. The information consists of direction, protocol, local IP, remote IP, local port, and remote port. If the packet is denied by a security group, the name of the rule that denied the packet is returned. While any source or destination IP can be chosen, IP flow verify helps administrators quickly diagnose connectivity issues from or to the internet and from or to the on-premises environment.
            References:
            https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-ip-flow-verify-overview

            NEW QUESTION 16
            You are troubleshooting a performance issue for an Azure Application Gateway. You need to compare the total requests to the failed requests during the past six hours. What should you use?

            • A. Metrics in Application Gateway
            • B. Diagnostics logs in Application Gateway
            • C. NSG flow logs in Azure Network Watcher
            • D. Connection monitor in Azure Network Watcher

            Answer: A

            Explanation: Application Gateway currently has seven metrics to view performance counters.
            Metrics are a feature for certain Azure resources where you can view performance counters in the portal. For Application Gateway, the following metrics are available: Total Requests
            Failed Requests Current Connections Healthy Host Count Response Status Throughput Unhealthy Host count
            You can filter on a per backend pool basis to show healthy/unhealthy hosts in a specific backend pool References: https://docs.microsoft.com/en-us/azure/application-gateway/applicationgatewaydiagnostics# Metrics

            100% Valid and Newest Version AZ-102 Questions & Answers shared by Surepassexam, Get Full Dumps HERE: https://www.surepassexam.com/AZ-102-exam-dumps.html (New 195 Q&As)