AZ-140 Exam Question 61
Drag and Drop Question
You have an Azure subscription that contains the storage accounts shown in the following table.

You have a custom generalized Windows 10 image.
You plan to deploy an Azure Virtual Desktop host pool that will use the custom image and FSLogix profile containers.
You need to recommend which storage accounts to use for the custom image and the profile containers. The solution must meet the following requirements:
- Minimize costs to store the image.
- Maximize performance of the profile containers.
Which account should you recommend for each type of content? To answer, drag the appropriate accounts to the correct content type. Each account may be used once, more than once, or not at all. You many need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

You have an Azure subscription that contains the storage accounts shown in the following table.

You have a custom generalized Windows 10 image.
You plan to deploy an Azure Virtual Desktop host pool that will use the custom image and FSLogix profile containers.
You need to recommend which storage accounts to use for the custom image and the profile containers. The solution must meet the following requirements:
- Minimize costs to store the image.
- Maximize performance of the profile containers.
Which account should you recommend for each type of content? To answer, drag the appropriate accounts to the correct content type. Each account may be used once, more than once, or not at all. You many need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

AZ-140 Exam Question 62
You have an Azure Virtual Desktop deployment that contains a host pool named Pool1. Pool1 contains two session hosts named Host1 and Host2.
You need to enable screen capture protection for the deployment.
What should you do?
You need to enable screen capture protection for the deployment.
What should you do?
AZ-140 Exam Question 63
You have an Azure Virtual Desktop deployment that contains a pooled host pool named Pool1.
Pool1 contains five session hosts.
You plan to deploy two apps named App1 and App2. The solution must meet the following requirements:
- All the session hosts must contain both apps.
- All users must connect to a full desktop session.
- Only users in the sales department must be able to use App1.
- Only users in the research department must be able to use App2.
You need to ensure that the users in each department can see only their assigned app when they connect to Pool1.
What should you use?
Pool1 contains five session hosts.
You plan to deploy two apps named App1 and App2. The solution must meet the following requirements:
- All the session hosts must contain both apps.
- All users must connect to a full desktop session.
- Only users in the sales department must be able to use App1.
- Only users in the research department must be able to use App2.
You need to ensure that the users in each department can see only their assigned app when they connect to Pool1.
What should you use?
AZ-140 Exam Question 64
Case Study 2 - Litware, Inc
Overview
Litware, Inc. is a pharmaceutical company that has a main office in Boston, United States, and a remote office in Chennai, India.
Existing Environment. Identity Environment
The network contains an on-premises Active Directory domain named litware.com that syncs to an Azure Active Directory (Azure AD) tenant named litware.com.
The Azure AD tenant contains the users shown in the following table.

All users are registered for Azure Multi-Factor Authentication (MFA).
Existing Environment. Cloud Services
Litware has a Microsoft 365 E5 subscription associated to the Azure AD tenant. All users are assigned Microsoft 365 Enterprise E5 licenses.
Litware has an Azure subscription associated to the Azure AD tenant. The subscription contains the resources shown in the following table.

Litware uses custom virtual machine images and custom scripts to automatically provision Azure virtual machines and join the virtual machines to the on-premises Active Directory domain.
Network and DNS
The offices connect to each other by using a WAN link. Each office connects directly to the internet.
All DNS queries for internet hosts are resolved by using DNS servers in the Boston office, which point to root servers on the internet. The Chennai office has caching-only DNS servers that forward queries to the DNS servers in the Boston office.
Requirements. Planned Changes
Litware plans to implement the following changes:
Deploy Azure Virtual Desktop environments to the East US Azure region for the users in the

Boston office and to the South India Azure region for the users in the Chennai office.
Implement FSLogix profile containers.

Optimize the custom virtual machine images for the Azure Virtual Desktop session hosts.

Use PowerShell to automate the addition of virtual machines to the Azure Virtual Desktop host

pools.
Requirements. Performance Requirements
Litware identifies the following performance requirements:
Minimize network latency of the Azure Virtual Desktop connections from the Boston and

Chennai offices.
Minimize latency of the Azure Virtual Desktop host authentication in each Azure region.

Minimize how long it takes to sign in to the Azure Virtual Desktop session hosts.

Requirements. Authentication Requirements
Litware identifies the following authentication requirements:
Enforce Azure MFA when accessing Azure Virtual Desktop apps.

Force users to reauthenticate if their Azure Virtual Desktop session lasts more than eight hours.

Requirements. Security Requirements
Litware identifies the following security requirements:
Explicitly allow traffic between the Azure Virtual Desktop session hosts and Microsoft 365.

Explicitly allow traffic between the Azure Virtual Desktop session hosts and the Azure Virtual

Desktop infrastructure.
Use built-in groups for delegation.

Delegate the management of app groups to Admin2, including the ability to publish app groups

to users and user groups.
Grant Admin1 permissions to manage workspaces, including listing which apps are assigned to

the app groups.
Minimize administrative effort to manage network security.

Use the principle of least privilege.

Requirements. Deployment Requirements
Litware identifies the following deployment requirements:
Use PowerShell to generate the token used to add the virtual machines as session hosts to a

Azure Virtual Desktop host pool.
Minimize how long it takes to provision the Azure Virtual Desktop session hosts based on the

custom virtual machine images.
Whenever possible, preinstall agents and apps in the custom virtual machine images.

User Profile Requirements
Litware identifies the following user profile requirements:
* In storage1, store user profiles for the Boston office users.
* Ensure that the user profiles for the Boston office users replicate synchronously between two Azure regions.
* Ensure that Admin1 uses a local profile only when signing in to the Azure Virtual Desktop session hosts.
You need to configure the user settings of Admin1 to meet the user profile requirements.
What should you do?
Overview
Litware, Inc. is a pharmaceutical company that has a main office in Boston, United States, and a remote office in Chennai, India.
Existing Environment. Identity Environment
The network contains an on-premises Active Directory domain named litware.com that syncs to an Azure Active Directory (Azure AD) tenant named litware.com.
The Azure AD tenant contains the users shown in the following table.

All users are registered for Azure Multi-Factor Authentication (MFA).
Existing Environment. Cloud Services
Litware has a Microsoft 365 E5 subscription associated to the Azure AD tenant. All users are assigned Microsoft 365 Enterprise E5 licenses.
Litware has an Azure subscription associated to the Azure AD tenant. The subscription contains the resources shown in the following table.

Litware uses custom virtual machine images and custom scripts to automatically provision Azure virtual machines and join the virtual machines to the on-premises Active Directory domain.
Network and DNS
The offices connect to each other by using a WAN link. Each office connects directly to the internet.
All DNS queries for internet hosts are resolved by using DNS servers in the Boston office, which point to root servers on the internet. The Chennai office has caching-only DNS servers that forward queries to the DNS servers in the Boston office.
Requirements. Planned Changes
Litware plans to implement the following changes:
Deploy Azure Virtual Desktop environments to the East US Azure region for the users in the

Boston office and to the South India Azure region for the users in the Chennai office.
Implement FSLogix profile containers.

Optimize the custom virtual machine images for the Azure Virtual Desktop session hosts.

Use PowerShell to automate the addition of virtual machines to the Azure Virtual Desktop host

pools.
Requirements. Performance Requirements
Litware identifies the following performance requirements:
Minimize network latency of the Azure Virtual Desktop connections from the Boston and

Chennai offices.
Minimize latency of the Azure Virtual Desktop host authentication in each Azure region.

Minimize how long it takes to sign in to the Azure Virtual Desktop session hosts.

Requirements. Authentication Requirements
Litware identifies the following authentication requirements:
Enforce Azure MFA when accessing Azure Virtual Desktop apps.

Force users to reauthenticate if their Azure Virtual Desktop session lasts more than eight hours.

Requirements. Security Requirements
Litware identifies the following security requirements:
Explicitly allow traffic between the Azure Virtual Desktop session hosts and Microsoft 365.

Explicitly allow traffic between the Azure Virtual Desktop session hosts and the Azure Virtual

Desktop infrastructure.
Use built-in groups for delegation.

Delegate the management of app groups to Admin2, including the ability to publish app groups

to users and user groups.
Grant Admin1 permissions to manage workspaces, including listing which apps are assigned to

the app groups.
Minimize administrative effort to manage network security.

Use the principle of least privilege.

Requirements. Deployment Requirements
Litware identifies the following deployment requirements:
Use PowerShell to generate the token used to add the virtual machines as session hosts to a

Azure Virtual Desktop host pool.
Minimize how long it takes to provision the Azure Virtual Desktop session hosts based on the

custom virtual machine images.
Whenever possible, preinstall agents and apps in the custom virtual machine images.

User Profile Requirements
Litware identifies the following user profile requirements:
* In storage1, store user profiles for the Boston office users.
* Ensure that the user profiles for the Boston office users replicate synchronously between two Azure regions.
* Ensure that Admin1 uses a local profile only when signing in to the Azure Virtual Desktop session hosts.
You need to configure the user settings of Admin1 to meet the user profile requirements.
What should you do?
AZ-140 Exam Question 65
You have been assigned the Workspace Contributor role for managing an Azure Virtual Desktop workspace but you don't have access to information about various applications in the workspace.
Which of the following role is required to get access?
Which of the following role is required to get access?

