AZ-140 Exam Question 76

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure Virtual Desktop host pool that contains five session hosts. The session hosts run Windows 10 Enterprise multi-session.
You need to prevent users from accessing the internet from Azure Virtual Desktop sessions. The session hosts must be allowed to access all the required Microsoft services.
Solution: You configure the RDP Properties of the host pool.
Does this meet the goal?
  • AZ-140 Exam Question 77

    Case Study 2 - Litware, Inc
    Overview
    Litware, Inc. is a pharmaceutical company that has a main office in Boston, United States, and a remote office in Chennai, India.
    Existing Environment. Identity Environment
    The network contains an on-premises Active Directory domain named litware.com that syncs to an Azure Active Directory (Azure AD) tenant named litware.com.
    The Azure AD tenant contains the users shown in the following table.

    All users are registered for Azure Multi-Factor Authentication (MFA).
    Existing Environment. Cloud Services
    Litware has a Microsoft 365 E5 subscription associated to the Azure AD tenant. All users are assigned Microsoft 365 Enterprise E5 licenses.
    Litware has an Azure subscription associated to the Azure AD tenant. The subscription contains the resources shown in the following table.

    Litware uses custom virtual machine images and custom scripts to automatically provision Azure virtual machines and join the virtual machines to the on-premises Active Directory domain.
    Network and DNS
    The offices connect to each other by using a WAN link. Each office connects directly to the internet.
    All DNS queries for internet hosts are resolved by using DNS servers in the Boston office, which point to root servers on the internet. The Chennai office has caching-only DNS servers that forward queries to the DNS servers in the Boston office.
    Requirements. Planned Changes
    Litware plans to implement the following changes:
    Deploy Azure Virtual Desktop environments to the East US Azure region for the users in the

    Boston office and to the South India Azure region for the users in the Chennai office.
    Implement FSLogix profile containers.

    Optimize the custom virtual machine images for the Azure Virtual Desktop session hosts.

    Use PowerShell to automate the addition of virtual machines to the Azure Virtual Desktop host

    pools.
    Requirements. Performance Requirements
    Litware identifies the following performance requirements:
    Minimize network latency of the Azure Virtual Desktop connections from the Boston and

    Chennai offices.
    Minimize latency of the Azure Virtual Desktop host authentication in each Azure region.

    Minimize how long it takes to sign in to the Azure Virtual Desktop session hosts.

    Requirements. Authentication Requirements
    Litware identifies the following authentication requirements:
    Enforce Azure MFA when accessing Azure Virtual Desktop apps.

    Force users to reauthenticate if their Azure Virtual Desktop session lasts more than eight hours.

    Requirements. Security Requirements
    Litware identifies the following security requirements:
    Explicitly allow traffic between the Azure Virtual Desktop session hosts and Microsoft 365.

    Explicitly allow traffic between the Azure Virtual Desktop session hosts and the Azure Virtual

    Desktop infrastructure.
    Use built-in groups for delegation.

    Delegate the management of app groups to Admin2, including the ability to publish app groups

    to users and user groups.
    Grant Admin1 permissions to manage workspaces, including listing which apps are assigned to

    the app groups.
    Minimize administrative effort to manage network security.

    Use the principle of least privilege.

    Requirements. Deployment Requirements
    Litware identifies the following deployment requirements:
    Use PowerShell to generate the token used to add the virtual machines as session hosts to a

    Azure Virtual Desktop host pool.
    Minimize how long it takes to provision the Azure Virtual Desktop session hosts based on the

    custom virtual machine images.
    Whenever possible, preinstall agents and apps in the custom virtual machine images.

    User Profile Requirements
    Litware identifies the following user profile requirements:
    * In storage1, store user profiles for the Boston office users.
    * Ensure that the user profiles for the Boston office users replicate synchronously between two Azure regions.
    * Ensure that Admin1 uses a local profile only when signing in to the Azure Virtual Desktop session hosts.
    Which two roles should you assign to Admin2 to meet the security requirements? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.
  • AZ-140 Exam Question 78

    Hotspot Question
    You have an Azure Virtual Desktop deployment that contains Windows 11 session hosts.
    You have an MSIX package named App1.
    You need to use app attach to deploy an MSIX image based on App1. The solution must optimize performance.
    Which command should you run, and which image format should you use? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    AZ-140 Exam Question 79

    Hotspot Question
    You have an Azure subscription that contains an Azure Virtual Desktop deployment. The subscription contains the virtual networks shown in the following table.

    You have virtual network peering configured as shown in the following table.

    The deployment contains the session hosts shown in the following table.

    Windows Defender Firewall is configured on each session host to allow all network traffic between the session hosts.
    For each of the following statements, select Yes if the statement is true. Otherwise, select No.
    NOTE: Each correct selection is worth one point.

    AZ-140 Exam Question 80

    Hotspot Question
    You have an Azure Virtual Desktop deployment.
    You are configuring the outbound firewall settings for the host pool.
    Which outbound URL and outbound port should you configure to ensure that the host machines maintain Windows activation? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.