AZ-101 Exam - Microsoft Azure Integration and Security

certleader.com

Act now and download your AZ-101 Braindumps today! Do not waste time for the worthless AZ-101 Dumps tutorials. Download AZ-101 Dumps Questions with real questions and answers and begin to learn AZ-101 Exam Questions with a classic professional.

Free demo questions for Microsoft AZ-101 Exam Dumps Below:

NEW QUESTION 1
You plan to connect a virtual network named VNET1017 to your on-premises network by using both an Azure ExpressRoute and a site-to-site VPN connection.
You need to prepare the Azure environment for the planned deployment. The solution must maximize the IP address space available to Azure virtual machines.
What should you do from the Azure portal before you create the ExpressRoute are the VPN gateway?

    Answer:

    Explanation: We need to create a Gateway subnet Step 1:
    Go to More Services > Virtual Networks Step 2:
    Then click on the VNET1017, and click on subnets. Then click on gateway subnet.
    Step 3:
    In the next window define the subnet for the gateway and click OK
    AZ-101 dumps exhibit
    It is recommended to use /28 or /27 for gateway subnet.
    As we want to maximize the IP address space we should use /27. References:
    https://blogs.technet.microsoft.com/canitpro/2021/06/28/step-by-step-configuring-a-site-to-site-vpn- gateway-between-azure-and-on-premise/

    NEW QUESTION 2
    Your marketing team creates a new website that you must load balance for 99.99
    percent availability.
    You need to deploy and configure a solution for both machines in the Web-AS availability set to load balance the website over HTTP. The solution must use the load balancer your resource group.
    What should you do from the Azure portal?

      Answer:

      Explanation: To distribute traffic to the VMs in the availability set, a back-end address pool contains the IP addresses of the virtual NICs that are connected to the load balancer. Create the back-end address pool to include the VMs in the availability set.
      Step 1:
      Select All resources on the left menu, and then select LoadBalancer from the resource list. Step 2:
      Under Settings, select Backend pools, and then select Add. Step 3:
      On the Add a backend pool page, select the Web-AS availability set, and then select OK:
      AZ-101 dumps exhibit
      References:
      https://docs.microsoft.com/en-us/azure/load-balancer/quickstart-create-basic-load-balancer-portal

      NEW QUESTION 3
      You have a public load balancer that balancer ports 80 and 443 across three virtual machines.
      You need to direct all the Remote Desktop protocol (RDP) to VM3 only. What should you configure?

      • A. an inbound NAT rule
      • B. a load public balancing rule
      • C. a new public load balancer for VM3
      • D. a new IP configuration

      Answer: A

      Explanation: To port forward traffic to a specific port on specific VMs use an inbound network address translation (NAT) rule.
      Incorrect Answers:
      B: Load-balancing rule to distribute traffic that arrives at frontend to backend pool instances. References:
      https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-overview

      NEW QUESTION 4
      You have an Azure App Service plan that hosts an Azure App Service named App1. You configure one production slot and four staging slots for App1.
      You need to allocate 10 percent of the traffic to each staging slot and 60 percent of the traffic to the production slot.
      What should you add to Appl1?

      • A. slots to the Testing in production blade
      • B. a performance test
      • C. a WebJob
      • D. templates to the Automation script blade

      Answer: A

      Explanation: Besides swapping, deployment slots offer another killer feature: testing in production. Just like the name suggests, using this, you can actually test in production. This means that you can route a specific percentage of user traffic to one or more of your deployment slots.
      Example:
      AZ-101 dumps exhibit
      References:
      https://stackify.com/azure-deployment-slots/

      NEW QUESTION 5
      You need to create a function app named corp7509086nl that supports sticky sessions. The solution must minimize the Azure-related costs of the App Service plan.
      What should you do from the Azure portal?

        Answer:

        Explanation: Step 1:
        Select the New button found on the upper left-hand corner of the Azure portal, then select Compute > Function App.
        Step 2:
        Use the function app settings as listed below. App name: corp7509086n1
        Hosting plan: Azure App Service plan
        (need this for the sticky sessions)
        Pricing tier of the the App Service plan: Shared compute: Free Step 3:
        Select Create to provision and deploy the function app. References:
        https://docs.microsoft.com/en-us/azure/azure-functions/functions-create-function-app-portal

        NEW QUESTION 6
        You plan to grant the member of a new Azure AD group named crop 75099086 the right to delegate administrative access to any resource in the resource group named 7509086.
        You need to create the Azure AD group and then to assign the correct to e to the group. The solution must use the principle of least privilege and minimize the number of role assignments.
        What should you do from the Azure portal?

          Answer:

          Explanation: Step 1:
          Click Resource groups from the menu of services to access the Resource Groups blade
          AZ-101 dumps exhibit
          Step 2:
          Click Add (+) to create a new resource group. The Create Resource Group blade appears. Enter corp7509086 as the Resource group name, and click the Create button.
          AZ-101 dumps exhibit
          Step 3:
          Select Create.
          Your group is created and ready for you to add members. Now we need to assign a role to this resource group scope. Step 4:
          Choose the newly created Resource group, and Access control (IAM) to see the current list of role assignments at the resource group scope. Click +Add to open the Add permissions pane.
          AZ-101 dumps exhibit
          Step 5:
          In the Role drop-down list, select a role Delegate administration, and select Assign access to: resource group corp7509086
          AZ-101 dumps exhibit
          References:
          https://docs.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal https://www.juniper.net/documentation/en_US/vsrx/topics/task/multi-task/security-vsrx-azure- marketplace-resource-group.html

          Case Study: 8
          Mix Questions Set E (Security Identities)

          NEW QUESTION 7
          Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
          After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
          You have an Azure web app named Appl. App1 runs in an Azure App Service plan named Plan1. Plan1 is associated to the Free pricing tier.
          You discover that App1 stops each day after running continuously for 60 minutes. You need to ensure that App1 can run continuously for the entire day.
          Solution: You change the pricing tier of Plan1 to Basic. Does this meet the goal?

          • A. Yes
          • B. No

          Answer: A

          Explanation: The Free Tier provides 60 CPU minutes / day. This explains why App1 is stops. The Basic tier has no such cap.
          References:
          https://azure.microsoft.com/en-us/pricing/details/app-service/windows/

          NEW QUESTION 8
          DRAG DROP
          You are developing an Azure web app named WebApp1. WebApp1 uses an Azure App Service plan named Plan1 that uses the B1 pricing tier.
          You need to configure WebApp1 to add additional instances of the app when CPU usage exceeds 70 percent for 10 minutes.
          Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
          AZ-101 dumps exhibit

            Answer:

            Explanation: Box 1: From the Scale out (App Service Plan) settings blade, change the pricing tier The B1 pricing tier only allows for 1 core. We must choose another pricing tier.
            Box 2: From the Scale out (App Service Plan) settings blade, enable autoscale
            Log in to the Azure portal at http://portal.azure.com
            Navigate to the App Service you would like to autoscale.
            Select Scale out (App Service plan) from the menu
            Click on Enable autoscale. This activates the editor for scaling rules.
            AZ-101 dumps exhibit
            Box 3: From the Scale mode to Scale based on metric, add a rule, and set the instance limits.
            Click on Add a rule. This shows a form where you can create a rule and specify details of the scaling. References:
            https://azure.microsoft.com/en-us/pricing/details/app-service/windows/ https://blogs.msdn.microsoft.com/hsirtl/2021/07/03/autoscaling-azure-web-apps/

            NEW QUESTION 9
            HOTSPOT
            You have an Azure subscription named Subscription1 that contains the resources in the following table.
            AZ-101 dumps exhibit
            VM1 and VM2 run the websites in the following table.
            AZ-101 dumps exhibit
            AppGW1 has the backend pools in the following table.
            AZ-101 dumps exhibit
            DNS resolves site1.contoso.com, site2.contoso.com, and site3.contoso.com to the IP address of
            AppGW1.
            AppGW1 has the listeners in the following table.
            AZ-101 dumps exhibit
            AppGW1 has the rules in the following table.
            AZ-101 dumps exhibit
            For each of the following statements, select Yes if the statement is true. Otherwise, select No.
            NOTE: Each correct selection is worth one point.
            AZ-101 dumps exhibit

              Answer:

              Explanation: Vm1 is in Pool1. Rule2 applies to Pool1, Listener 2, and site2.contoso.com

              NEW QUESTION 10
              You need to deploy an Azure load balancer named Ib 1015 to your Azure subscription. The solution must meet the following requirements:
              -Support the load balancing of IP traffic from the Internet to Azure virtual machines connected to VNET1016 subnet0.
              -Prov.de 4 Service level Agreement (SWJ of 99.99 percent ability for the Azure virtual machines.
              -Minimize Azure-related costs.
              What should you do from the Azure portal?
              To complete this task, you do NOT need to wait for the deployment to complete. Once the deployment start in Azure, you can move to the next task.

                Answer:

                Explanation: Step 1:
                On the top left-hand side of the screen, click Create a resource > Networking > Load Balancer. Step 2:
                In the Create a load balancer page enter these values for the load balancer: myLoadBalancer - for the name of the load balancer.
                Internal - for the type of the load balancer. Basic - for SKU version.
                Microsoft guarantees that apps running in a customer subscription will be available 99.99% of the time.
                VNET1016subnet0 - for subnet that you choose from the list of existing subnets.
                Step 3: Accept the default values for the other settings and click Create to create the load balancer.

                NEW QUESTION 11
                HOTSPOT
                You have an Azure web app named WebApp1 that runs in an Azure App Service plan named ASP1. ASP1 is based on the D1 pricing tier.
                You need to ensure that WebApp1 can be accessed only from computers on your on-premises network. The solution must minimize costs.
                What should you configure? To answer, select the appropriate options in the answer are a.
                NOTE: Each correct selection is worth one point.
                AZ-101 dumps exhibit

                  Answer:

                  Explanation: Box 1: B1
                  B1 (Basic) would minimize cost compared P1v2 (premium) and S1 (standard). Box 2: Cross Origin Resource Sharing (CORS)
                  Once you set the CORS rules for the service, then a properly authenticated request made against the service from a different domain will be evaluated to determine whether it is allowed according to the
                  rules you have specified.
                  Note: CORS (Cross Origin Resource Sharing) is an HTTP feature that enables a web application running under one domain to access resources in another domain. In order to reduce the possibility of cross-site scripting attacks, all modern web browsers implement a security restriction known as same-origin policy. This prevents a web page from calling APIs in a different domain. CORS provides a secure way to allow one origin (the origin domain) to call APIs in another origin.
                  References:
                  https://azure.microsoft.com/en-us/pricing/details/app-service/windows/ https://docs.microsoft.com/en-us/azure/cdn/cdn-cors

                  NEW QUESTION 12
                  DRAG DROP
                  You have an Azure subscription that contains the following resources:
                  • a virtual network named VNet1
                  • a replication policy named ReplPolicy1
                  • a Recovery Services vault named Vault1
                  • an Azure Storage account named Storage1
                  You have an Amazon Web Services (AWS) EC2 virtual machine named VM1 that runs Windows Server
                  You need to migrate VM1 to VNet1 by using Azure Site Recovery.
                  Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
                  AZ-101 dumps exhibit

                    Answer:

                    Explanation: Step 1: Deploy an EC2 virtual machine as a configuration server Prepare source include:
                    Use an EC2 instance that's running Windows Server 2012 R2 to create a configuration server and register it with your recovery vault.
                    Configure the proxy on the EC2 instance VM you're using as the configuration server so that it can access the service URLs.
                    Step 2: Install Azure Site Recovery Unified Setup.
                    Download Microsoft Azure Site Recovery Unified Setup. You can download it to your local machine and then copy it to the VM you're using as the configuration server.
                    Step 3: Enable replication for VM1.
                    Enable replication for each VM that you want to migrate. When replication is enabled, Site Recovery automatically installs the Mobility service.
                    References:
                    https://docs.microsoft.com/en-us/azure/site-recovery/migrate-tutorial-aws-azure

                    NEW QUESTION 13
                    Note: This question is part of a series of questions that present the same scenario
                    goals. Some question sets might have more than one correct solution, while others ion in the series contains a unique solution that might meet the stated not have a correct solution.
                    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
                    You have an Azure web app named Appl. App1 runs in an Azure App Service plan named Plan1. Plan1 is associated to the Free pricing tier.
                    You discover that App1 stops each day after running continuously for 60 minutes. You need to ensure that App1 can run continuously for the entire day.
                    Solution: You add a triggered WebJob to App1. Does this meet the goal?

                    • A. Yes
                    • B. No

                    Answer: B

                    Explanation: You need to change to Basic pricing Tier.
                    Note: The Free Tier provides 60 CPU minutes / day. This explains why App1 is stops. The Basic tier has no such cap.
                    References:
                    https://azure.microsoft.com/en-us/pricing/details/app-service/windows/

                    NEW QUESTION 14
                    You have an on-premises network that contains a Hyper-V host named Host1. Host1 runs Windows Server 2021 and hosts 10 virtual machines that run Windows Server 2021.
                    You plan to replicate the virtual machines to Azure by using Azure Site Recovery. You create a Recovery Services vault named ASR1 and a Hyper-V site named
                    Site1.
                    You need to add Host1 to ASR1. What should you do?

                    • A. Download the installation file for the Azure Site Recovery Provide
                    • B. Download the vault registration key.Install the Azure Site Recovery Provider on Host1 and register the server.
                    • C. Download the installation file for the Azure Site Recovery Provide
                    • D. Download the storage account key.Install the Azure Site Recovery Provider on Host1 and register the server.
                    • E. Download the installation file for the Azure Site Recovery Provide
                    • F. Download the vault registration key.Install the Azure Site Recovery Provider on each virtual machine and register the virtual machines.
                    • G. Download the installation file for the Azure Site Recovery Provide
                    • H. Download the storage account key.Install the Azure Site Recovery Provider on each virtual machine and register the virtual machines.

                    Answer: A

                    Explanation: Download the Vault registration key. You need this when you install the Provider. The key is valid for five days after you generate it.
                    Install the Provider on each VMM server. You don't need to explicitly install anything on Hyper-V hosts.
                    Incorrect Answers:
                    B, D: Use the Vault Registration Key, not the storage account key. References:
                    https://docs.microsoft.com/en-us/azure/site-recovery/migrate-tutorial-on-premises-azure

                    NEW QUESTION 15
                    You need to prevent remote users from publishing via FTP to a function app named FunctionApplod7509087fa. Remote users must be able to publish via FTPS. What should you do from the Azure portal?

                      Answer:

                      Explanation: Step 1:
                      Locate and select the function app FunctionApplod7509087fa.
                      Step 2:
                      Select Application Settings > FTP Access, change FTP access to FTPS Only, and click Save.
                      AZ-101 dumps exhibit
                      References:
                      https://blogs.msdn.microsoft.com/appserviceteam/2021/05/08/web-apps-making-changes-to-ftp- deployments/

                      NEW QUESTION 16
                      You plan to deploy a site-to-site VPN connection from on-premises network to your
                      Azure environment. The VPN connection will be established to the VNET01-USEA2 virtual network.
                      You need to create the required resources in Azure for the planned site-to-site VPN. The solution must minimize costs.
                      What should you do from the Azure portal?
                      NOTE: This task may a very long time to complete. You do NOT need to wait for the deployment to complete this task successfully.

                        Answer:

                        Explanation: We create a VPN gateway. Step 1:
                        On the left side of the portal page, click + and type 'Virtual Network Gateway' in search. In Results, locate and click Virtual network gateway.
                        Step 2:
                        At the bottom of the 'Virtual network gateway' page, click Create. This opens the Create virtual network gateway page.
                        Step 3:
                        On the Create virtual network gateway page, specify the values for your virtual network gateway. Gateway type: Select VPN. VPN gateways use the virtual network gateway type VPN.
                        Virtual network: Choose the existing virtual network VNET01-USEA2
                        Gateway subnet address range: You will only see this setting if you did not previously create a gateway subnet for your virtual network.
                        Step 4:
                        Select the default values for the other setting, and click create.
                        AZ-101 dumps exhibit
                        The settings are validated and you'll see the "Deploying Virtual network gateway" tile on the dashboard. Creating a gateway can take up to 45 minutes.
                        Note: This task may take a very long time to complete. You do NOT need to wait for the deployment to complete this task successfully.
                        References:
                        https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-site-to-site-resource-manager-portal

                        Case Study: 4 Contoso Case Study
                        Overview
                        Contoso, Ltd. is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York.
                        The Montreal office has 2,000 employees. The Seattle office has 1,000 employees. The New York office has 200 employees.
                        All the resources used by Contoso are hosted on-premises.
                        Contoso creates a new Azure subscription. The Azure Active Directory (Azure AD) tenant uses a domain named contoso.onmicrosoft.com. The tenant uses the P1 pricing tier.
                        Existing Environment
                        The network contains an Active Directory forest named contoso.com. All domain controllers are configured as DNS servers and host the contoso.com DNS zone.
                        Contoso has finance, human resources, sales, research, and information technology departments. Each department has an organizational unit (OU) that contains all the accounts of that respective department. All the user accounts have the department attribute set to their respective department. New users are added frequently.
                        Contoso.com contains a user named User1.
                        All the offices connect by using private links.
                        Contoso has data centers in the Montreal and Seattle offices. Each data center has a firewall that can be configured as a VPN device.
                        All infrastructure servers are virtualized. The virtualization environment contains the servers in the following table.
                        AZ-101 dumps exhibit
                        Contoso uses two web applications named App1 and App2. Each instance on each web application requires 1GB of memory.
                        The Azure subscription contains the resources in the following table.
                        AZ-101 dumps exhibit
                        The network security team implements several network security groups (NSGs).
                        Planned Changes
                        Contoso plans to implement the following changes:
                        • Deploy Azure ExpressRoute to the Montreal office.
                        • Migrate the virtual machines hosted on Server1 and Server2 to Azure.
                        • Synchronize on-premises Active Directory to Azure Active Directory (Azure AD).
                        • Migrate App1 and App2 to two Azure web apps named webApp1 and WebApp2.
                        Technical requirements
                        Contoso must meet the following technical requirements:
                        • Ensure that WebApp1 can adjust the number of instances automatically based on the load and can scale up to five instance*.
                        • Ensure that VM3 can establish outbound connections over TCP port 8080 to the applications servers in the Montreal office.
                        • Ensure that routing information is exchanged automatically between Azure and the routers in the Montreal office.
                        • Enable Azure Multi-Factor Authentication (MFA) for the users in the finance department only.
                        • Ensure that webapp2.azurewebsites.net can be accessed by using the name app2.contoso.com.
                        • Connect the New Your office to VNet1 over the Internet by using an encrypted connection.
                        • Create a workflow to send an email message when the settings of VM4 are
                        modified.
                        • Cre3te a custom Azure role named Role1 that is based on the Reader role.
                        • Minimize costs whenever possible.

                        NEW QUESTION 17
                        You need to recommend a solution to automate the configuration for the finance department users. The solution must meet the technical requirements.
                        What should you include in the recommended?

                        • A. Azure AP B2C
                        • B. Azure AD Identity Protection
                        • C. an Azure logic app and the Microsoft Identity Management (MIM) client
                        • D. dynamic groups and conditional access policies

                        Answer: D

                        Explanation: Scenario: Ensure Azure Multi-Factor Authentication (MFA) for the users in the finance department only.
                        The recommendation is to use conditional access policies that can then be targeted to groups of users, specific applications, or other conditions.
                        References:
                        https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-userstates

                        P.S. Easily pass AZ-101 Exam with 67 Q&As Certleader Dumps & pdf Version, Welcome to Download the Newest Certleader AZ-101 Dumps: https://www.certleader.com/AZ-101-dumps.html (67 New Questions)