AZ-104 Exam Question 1

You have an Azure subscription that contains the virtual machines shown in the following table.

VM1 and VM2 use public IP addresses. From Windows Server 2019 on VM1 and VM2, you allow inbound Remote Desktop connections.
Subnet1 and Subnet2 are in a virtual network named VNET1.
The subscription contains two network security groups (NSGs) named NSG1 and NSG2. NSG1 uses only the default rules.
NSG2 uses the default and the following custom incoming rule:
* Priority: 100
* Name: Rule1
* Port: 3389
* Protocol: TCP
* Source: Any
* Destination: Any
* Action: Allow
NSG1 connects to Subnet1. NSG2 connects to the network interface of VM2.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.

AZ-104 Exam Question 2

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You manage a virtual network named VNet1 that is hosted in the West US Azure region.
VNet1 hosts two virtual machines named VM1 and VM2 that run Windows Server.
You need to inspect all the network traffic from VM1 to VM2 for a period of three hours.
Solution: From Azure Network Watcher, you create a connection monitor.
Does this meet the goal?
  • AZ-104 Exam Question 3

    You are planning to deploy an Ubuntu Server virtual machine to your company's Azure subscription.
    You are required to implement a custom deployment that includes adding a particular trusted root certification authority (CA).
    Which of the following should you use to create the virtual machine?
  • AZ-104 Exam Question 4

    You have the Azure virtual machines shown in the following table.

    VNET1, VNET2, and VNET3 are peered.
    VM4 has a DNS server that is authoritative for a zone named Contoso.com and contains the records shown in the following table.

    VNET1 and VNET2 are linked to an Azure private DNS zone named Contoso.com that contains the records shown in the following table.

    The virtual networks are configured to use the DNS servers shown in the following table.

    For each of the following statements, select Yes if the statement is true. Otherwise, select No.
    NOTE: Each correct selection is worth one point.

    AZ-104 Exam Question 5

    DRAG DROP
    You have an on-premises network that you plan to connect to Azure by using a site-so-site VPN.
    In Azure, you have an Azure virtual network named VNet1 that uses an address space of 10.0.0.0/16 VNet1 contains a subnet named Subnet1 that uses an address space of 10.0.0.0/24.
    You need to create a site-to-site VPN to Azure.
    Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
    NOTE: More than one order of answer choice is correct. You will receive credit for any of the correct orders you select.
    Select and Place: