AZ-140 Exam Question 71
You add several languages to a base image and utilize that image for deploying the Session Hosts. Users log in but don't have an option to add additional languages. Which of the following steps would you take?
AZ-140 Exam Question 72
Drag and Drop Question
You have an Azure subscription that contains a Bicep file named AVD.bicep.
You plan to use AVD.bicep to deploy Azure Virtual Desktop.
Which commands should you run in sequence? To answer, drag the appropriate commands to the correct order. Each command may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

You have an Azure subscription that contains a Bicep file named AVD.bicep.
You plan to use AVD.bicep to deploy Azure Virtual Desktop.
Which commands should you run in sequence? To answer, drag the appropriate commands to the correct order. Each command may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

AZ-140 Exam Question 73
Case Study 2 - Litware, Inc
Overview
Litware, Inc. is a pharmaceutical company that has a main office in Boston, United States, and a remote office in Chennai, India.
Existing Environment. Identity Environment
The network contains an on-premises Active Directory domain named litware.com that syncs to an Azure Active Directory (Azure AD) tenant named litware.com.
The Azure AD tenant contains the users shown in the following table.

All users are registered for Azure Multi-Factor Authentication (MFA).
Existing Environment. Cloud Services
Litware has a Microsoft 365 E5 subscription associated to the Azure AD tenant. All users are assigned Microsoft 365 Enterprise E5 licenses.
Litware has an Azure subscription associated to the Azure AD tenant. The subscription contains the resources shown in the following table.

Litware uses custom virtual machine images and custom scripts to automatically provision Azure virtual machines and join the virtual machines to the on-premises Active Directory domain.
Network and DNS
The offices connect to each other by using a WAN link. Each office connects directly to the internet.
All DNS queries for internet hosts are resolved by using DNS servers in the Boston office, which point to root servers on the internet. The Chennai office has caching-only DNS servers that forward queries to the DNS servers in the Boston office.
Requirements. Planned Changes
Litware plans to implement the following changes:
Deploy Azure Virtual Desktop environments to the East US Azure region for the users in the

Boston office and to the South India Azure region for the users in the Chennai office.
Implement FSLogix profile containers.

Optimize the custom virtual machine images for the Azure Virtual Desktop session hosts.

Use PowerShell to automate the addition of virtual machines to the Azure Virtual Desktop host

pools.
Requirements. Performance Requirements
Litware identifies the following performance requirements:
Minimize network latency of the Azure Virtual Desktop connections from the Boston and

Chennai offices.
Minimize latency of the Azure Virtual Desktop host authentication in each Azure region.

Minimize how long it takes to sign in to the Azure Virtual Desktop session hosts.

Requirements. Authentication Requirements
Litware identifies the following authentication requirements:
Enforce Azure MFA when accessing Azure Virtual Desktop apps.

Force users to reauthenticate if their Azure Virtual Desktop session lasts more than eight hours.

Requirements. Security Requirements
Litware identifies the following security requirements:
Explicitly allow traffic between the Azure Virtual Desktop session hosts and Microsoft 365.

Explicitly allow traffic between the Azure Virtual Desktop session hosts and the Azure Virtual

Desktop infrastructure.
Use built-in groups for delegation.

Delegate the management of app groups to Admin2, including the ability to publish app groups

to users and user groups.
Grant Admin1 permissions to manage workspaces, including listing which apps are assigned to

the app groups.
Minimize administrative effort to manage network security.

Use the principle of least privilege.

Requirements. Deployment Requirements
Litware identifies the following deployment requirements:
Use PowerShell to generate the token used to add the virtual machines as session hosts to a

Azure Virtual Desktop host pool.
Minimize how long it takes to provision the Azure Virtual Desktop session hosts based on the

custom virtual machine images.
Whenever possible, preinstall agents and apps in the custom virtual machine images.

User Profile Requirements
Litware identifies the following user profile requirements:
* In storage1, store user profiles for the Boston office users.
* Ensure that the user profiles for the Boston office users replicate synchronously between two Azure regions.
* Ensure that Admin1 uses a local profile only when signing in to the Azure Virtual Desktop session hosts.
You need to modify the custom virtual machine images to meet the deployment requirements.
What should you install?
Overview
Litware, Inc. is a pharmaceutical company that has a main office in Boston, United States, and a remote office in Chennai, India.
Existing Environment. Identity Environment
The network contains an on-premises Active Directory domain named litware.com that syncs to an Azure Active Directory (Azure AD) tenant named litware.com.
The Azure AD tenant contains the users shown in the following table.

All users are registered for Azure Multi-Factor Authentication (MFA).
Existing Environment. Cloud Services
Litware has a Microsoft 365 E5 subscription associated to the Azure AD tenant. All users are assigned Microsoft 365 Enterprise E5 licenses.
Litware has an Azure subscription associated to the Azure AD tenant. The subscription contains the resources shown in the following table.

Litware uses custom virtual machine images and custom scripts to automatically provision Azure virtual machines and join the virtual machines to the on-premises Active Directory domain.
Network and DNS
The offices connect to each other by using a WAN link. Each office connects directly to the internet.
All DNS queries for internet hosts are resolved by using DNS servers in the Boston office, which point to root servers on the internet. The Chennai office has caching-only DNS servers that forward queries to the DNS servers in the Boston office.
Requirements. Planned Changes
Litware plans to implement the following changes:
Deploy Azure Virtual Desktop environments to the East US Azure region for the users in the

Boston office and to the South India Azure region for the users in the Chennai office.
Implement FSLogix profile containers.

Optimize the custom virtual machine images for the Azure Virtual Desktop session hosts.

Use PowerShell to automate the addition of virtual machines to the Azure Virtual Desktop host

pools.
Requirements. Performance Requirements
Litware identifies the following performance requirements:
Minimize network latency of the Azure Virtual Desktop connections from the Boston and

Chennai offices.
Minimize latency of the Azure Virtual Desktop host authentication in each Azure region.

Minimize how long it takes to sign in to the Azure Virtual Desktop session hosts.

Requirements. Authentication Requirements
Litware identifies the following authentication requirements:
Enforce Azure MFA when accessing Azure Virtual Desktop apps.

Force users to reauthenticate if their Azure Virtual Desktop session lasts more than eight hours.

Requirements. Security Requirements
Litware identifies the following security requirements:
Explicitly allow traffic between the Azure Virtual Desktop session hosts and Microsoft 365.

Explicitly allow traffic between the Azure Virtual Desktop session hosts and the Azure Virtual

Desktop infrastructure.
Use built-in groups for delegation.

Delegate the management of app groups to Admin2, including the ability to publish app groups

to users and user groups.
Grant Admin1 permissions to manage workspaces, including listing which apps are assigned to

the app groups.
Minimize administrative effort to manage network security.

Use the principle of least privilege.

Requirements. Deployment Requirements
Litware identifies the following deployment requirements:
Use PowerShell to generate the token used to add the virtual machines as session hosts to a

Azure Virtual Desktop host pool.
Minimize how long it takes to provision the Azure Virtual Desktop session hosts based on the

custom virtual machine images.
Whenever possible, preinstall agents and apps in the custom virtual machine images.

User Profile Requirements
Litware identifies the following user profile requirements:
* In storage1, store user profiles for the Boston office users.
* Ensure that the user profiles for the Boston office users replicate synchronously between two Azure regions.
* Ensure that Admin1 uses a local profile only when signing in to the Azure Virtual Desktop session hosts.
You need to modify the custom virtual machine images to meet the deployment requirements.
What should you install?
AZ-140 Exam Question 74
You have the devices shown in the following table.

You plan to deploy Azure Virtual Desktop for client access to remote virtualized apps.
Which devices support the Remote Desktop client?

You plan to deploy Azure Virtual Desktop for client access to remote virtualized apps.
Which devices support the Remote Desktop client?
AZ-140 Exam Question 75
Case Study 3 - Northwind Traders
Overview
Northwind Traders is a manufacturing company based in New York City.
Existing Environment
Identity Environment
The on-premises network contains an Active Directory Domain Services (AD DS) domain named northwindtraders.com.
Northwind Traders has a Microsoft Entra tenant and a Microsoft Entra Domain Services managed domain. The northwindtraders.com domain syncs with the Microsoft Entra tenant.
Virtual Machines
The company has an on-premises Hyper-V virtual machine named VM1 that has the following configurations:
- Generation: 1
- Disk size: 2 TB
- Disk format: VHDX
- Disk type: Dynamically expanding
Cloud Services
Northwind Traders has a Microsoft 365 E5 subscription. The subscription contains 500 users that are assigned Microsoft 365 E5 licenses.
The company has an Azure subscription that contains the resources shown in the following table.

Both subscriptions are linked to the Microsoft Entra tenant.
Requirements
Planned Changes
Northwind Traders identifies the following planned changes:
- Deploy an Azure Virtual Desktop host pool that will contain 10 session hosts joined to the Microsoft Entra Domain Services managed domain.
- Configure VM1 as the source image for the Azure Virtual Desktop deployment and upload the image to Azure.
- The Azure Virtual Desktop deployment will provide access to a custom app named App1.
Performance Requirements
Northwind Traders identifies the following performance requirements:
- Each Azure Virtual Desktop session host must support 15 user sessions.
- Each new user session must be assigned to a single session host until the maximum session limit is reached for that host.
Application Requirements
Northwind Traders identifies the following application requirements:
- Microsoft OneDrive must launch when users connect to a RemoteApp session in Azure Virtual Desktop.
- App1 requires a desktop resolution of 1280 x 1024.
- Administrative effort must be minimized.
Disaster Recovery Requirements
Northwind Traders identifies the following disaster recovery requirements for the Azure Virtual Desktop deployment:
- Minimize outages if an Azure region fails.
- Minimize the recovery time objective (RTO).
- Minimize administrative effort in the event of a failover.
Security Requirements
Northwind Traders identifies the following security requirements:
- When users sign in to the Azure Virtual Desktop deployment by using the Azure Virtual Desktop client, they must authenticate by using their Microsoft Entra username and password only.
- When users sign in to the Azure Virtual Desktop deployment by using a web browser, they must authenticate by using the Microsoft Authenticator app.
- All the Azure Virtual Desktop session hosts deployed by using the VM1 source image must be onboarded to Microsoft Defender for Endpoint.
- The client version and operating system used to connect to the session hosts must be logged.
- The solution must follow the principle of least privilege.
Networking Requirements
The Azure Virtual Desktop session hosts must be able to access the resources on the on- premises network.
User Profile Requirements
Northwind Traders identifies the following user profile requirements:
- Users must be able to access share1 by using their Microsoft Entra account.
- Azure Virtual Desktop user profiles must be managed by using FSLogix.
- All user profiles must be stored in share1.
What should you do to ensure that the session hosts meet the application requirements for App1?
Overview
Northwind Traders is a manufacturing company based in New York City.
Existing Environment
Identity Environment
The on-premises network contains an Active Directory Domain Services (AD DS) domain named northwindtraders.com.
Northwind Traders has a Microsoft Entra tenant and a Microsoft Entra Domain Services managed domain. The northwindtraders.com domain syncs with the Microsoft Entra tenant.
Virtual Machines
The company has an on-premises Hyper-V virtual machine named VM1 that has the following configurations:
- Generation: 1
- Disk size: 2 TB
- Disk format: VHDX
- Disk type: Dynamically expanding
Cloud Services
Northwind Traders has a Microsoft 365 E5 subscription. The subscription contains 500 users that are assigned Microsoft 365 E5 licenses.
The company has an Azure subscription that contains the resources shown in the following table.

Both subscriptions are linked to the Microsoft Entra tenant.
Requirements
Planned Changes
Northwind Traders identifies the following planned changes:
- Deploy an Azure Virtual Desktop host pool that will contain 10 session hosts joined to the Microsoft Entra Domain Services managed domain.
- Configure VM1 as the source image for the Azure Virtual Desktop deployment and upload the image to Azure.
- The Azure Virtual Desktop deployment will provide access to a custom app named App1.
Performance Requirements
Northwind Traders identifies the following performance requirements:
- Each Azure Virtual Desktop session host must support 15 user sessions.
- Each new user session must be assigned to a single session host until the maximum session limit is reached for that host.
Application Requirements
Northwind Traders identifies the following application requirements:
- Microsoft OneDrive must launch when users connect to a RemoteApp session in Azure Virtual Desktop.
- App1 requires a desktop resolution of 1280 x 1024.
- Administrative effort must be minimized.
Disaster Recovery Requirements
Northwind Traders identifies the following disaster recovery requirements for the Azure Virtual Desktop deployment:
- Minimize outages if an Azure region fails.
- Minimize the recovery time objective (RTO).
- Minimize administrative effort in the event of a failover.
Security Requirements
Northwind Traders identifies the following security requirements:
- When users sign in to the Azure Virtual Desktop deployment by using the Azure Virtual Desktop client, they must authenticate by using their Microsoft Entra username and password only.
- When users sign in to the Azure Virtual Desktop deployment by using a web browser, they must authenticate by using the Microsoft Authenticator app.
- All the Azure Virtual Desktop session hosts deployed by using the VM1 source image must be onboarded to Microsoft Defender for Endpoint.
- The client version and operating system used to connect to the session hosts must be logged.
- The solution must follow the principle of least privilege.
Networking Requirements
The Azure Virtual Desktop session hosts must be able to access the resources on the on- premises network.
User Profile Requirements
Northwind Traders identifies the following user profile requirements:
- Users must be able to access share1 by using their Microsoft Entra account.
- Azure Virtual Desktop user profiles must be managed by using FSLogix.
- All user profiles must be stored in share1.
What should you do to ensure that the session hosts meet the application requirements for App1?

