AZ-102 Exam - Microsoft Azure Administrator Certification Transition

certleader.com

Proper study guides for AZ-102 Microsoft Azure Administrator Certification Transition certified begins with AZ-102 Exam Questions preparation products which designed to deliver the AZ-102 Dumps by making you pass the AZ-102 test at your first time. Try the free AZ-102 Dumps right now.

Microsoft AZ-102 Free Dumps Questions Online, Read and Test Now.

NEW QUESTION 1
You have an Active Directory forest named contoso.com.
You install and configure Azure AD Connect to use password hash synchronization as the single signon (SSO) method. Staging mode is enabled.
You review the synchronization results and discover that the Synchronization Service Manager does not display any sync jobs.
You need to ensure that the synchronization completes successfully. What should you do?

  • A. From Synchronization Service Manager, run a full import.
  • B. Run Azure AD Connect and set the SSO method to Pass-through Authentication.
  • C. From Azure PowerShell, run Start-AdSyncSyncCycle -PolicyType Initial.
  • D. Run Azure AD Connect and disable staging mode.

Answer: D

Explanation: Staging mode must be disabled. If the Azure AD Connect server is in staging mode, password hash synchronization is temporarily disabled.
References: https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directoryaadconnectsync-troubleshoot-password-hash-synchronization#no-passwords-are-synchronizedtroubleshoot-by-using-the-troubleshooting-task

NEW QUESTION 2
DRAG DROP
You have an on-premises network that includes a Microsoft SQL Server instance named SQL1. You create an Azure Logic App named App1.
You need to ensure that App1 can query a database on SQL1.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
AZ-102 dumps exhibit

    Answer:

    Explanation: To access data sources on premises from your logic apps, you can create a data gateway resource in Azure so that your logic apps can use the on-premises connectors.
    Box 1: From an on-premises computer, install an on-premises data gateway.
    Before you can connect to on-premises data sources from Azure Logic Apps, download and install the on-premises data gateway on a local computer.
    Box 2: From the Azure portal, create an on-premises data gateway Create Azure resource for gateway
    After you install the gateway on a local computer, you can then create an Azure resource for your gateway. This step also associates your gateway resource with your Azure subscription.
    Sign in to the Azure portal. Make sure you use the same Azure work or school email address used to install the gateway.
    On the main Azure menu, select Create a resource > Integration > On-premises data gateway.
    AZ-102 dumps exhibit
    On the Create connection gateway page, provide this information for your gateway resource.
    To add the gateway resource to your Azure dashboard, select Pin to dashboard. When you're done, choose Create.
    Box 3: From the Logic Apps Designer in the Azure portal, add a connector
    After you create your gateway resource and associate your Azure subscription with this resource, you can now create a connection between your logic app and your on-premises data source by using the gateway.
    In the Azure portal, create or open your logic app in the Logic App Designer. Add a connector that supports on-premises connections, for example, SQL Server. Set up your connection.
    References:
    https://docs.microsoft.com/en-us/azure/logic-apps/logic-apps-gateway-connection

    NEW QUESTION 3
    SIMULATION
    Click to expand each objective. To connect to the Azure portal, type https://portal.azure.com in the browser address bar.
    AZ-102 dumps exhibit
    AZ-102 dumps exhibit
    AZ-102 dumps exhibit
    When you are finished performing all the tasks, click the ‘Next’ button.
    Note that you cannot return to the lab once you click the ‘Next’ button. Scoring occur in the background while you complete the rest of the exam.
    Overview
    The following section of the exam is a lab. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design. Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn’t matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
    Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
    Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
    To start the lab
    You may start the lab by clicking the Next button.
    Another administrator attempts to establish connectivity between two virtual networks named VNET1 and VNET2.
    The administrator reports that connections across the virtual networks fail.
    You need to ensure that network connections can be established successfully between VNET1 and VNET2 as quickly as possible.
    What should you do from the Azure portal?

      Answer:

      Explanation: You can connect one VNet to another VNet using either a Virtual network peering, or an Azure VPN Gateway.
      To create a virtual network gateway
      Step1 : In the portal, on the left side, click +Create a resource and type 'virtual network gateway' in search. Locate Virtual network gateway in the search return and click the entry. On the Virtual network gateway page, click Create at the bottom of the page to open the Create virtual network gateway page.
      Step 2: On the Create virtual network gateway page, fill in the values for your virtual network gateway.
      AZ-102 dumps exhibit
      AZ-102 dumps exhibit
      Name: Name your gateway. This is not the same as naming a gateway subnet. It's the name of the gateway object you are creating.
      Gateway type: Select VPN. VPN gateways use the virtual network gateway type VPN.
      Virtual network: Choose the virtual network to which you want to add this gateway. Click Virtual network to open the 'Choose a virtual network' page. Select the VNet. If you don't see your VNet, make sure the Location field is pointing to the region in which your virtual network is located. Gateway subnet address range: You will only see this setting if you did not previously create a gateway subnet for your virtual network. If you previously created a valid gateway subnet, this setting will not appear.
      Step 4: Select Create New to create a Gateway subnet.
      AZ-102 dumps exhibit
      Step 5: Click Create to begin creating the VPN gateway. The settings are validated and you'll see the "Deploying Virtual network gateway" tile on the dashboard. Creating a gateway can take up to 45 minutes. You may need to refresh your portal page to see the completed status.
      References: https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-vnet-vnetresource-manager-portal?

      NEW QUESTION 4
      You have two subscriptions named Subscription1 and Subscription2. Each subscription is associated to a different Azure AD tenant.
      Subscription1 contains a virtual network named VNet1.VNet1 contains an Azure virtual machine named VM1 and has an IP address space of 10.0.0.0/16.
      Subscription2 contains a virtual network named VNet2. VNet2 contains an Azure virtual machine named VM2 and has an IP address space of 10.10.0.0/24.
      You need to connect VNet1 to VNet2. What should you do first?

      • A. Move VNet1 to Subscription2.
      • B. Modify the IP address space of VNet2.
      • C. Provision virtual network gateways.
      • D. Move VM1 to Subscription2.

      Answer: C

      Explanation: The virtual networks can be in the same or different regions, and from the same or different subscriptions. When connecting VNets from different subscriptions, the subscriptions do not need to
      be associated with the same Active Directory tenant.
      Configuring a VNet-to-VNet connection is a good way to easily connect VNets. Connecting a virtual network to another virtual network using the VNet-to-VNet connection type (VNet2VNet) is similar to creating a Site-to-Site IPsec connection to an on-premises location. Both connectivity types use a VPN gateway to provide a secure tunnel using IPsec/IKE, and both function the same way when communicating.
      The local network gateway for each VNet treats the other VNet as a local site. This lets you specify additional address space for the local network gateway in order to route traffic.
      References: https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-vnet-vnetresource- manager-portal

      NEW QUESTION 5
      You sign up for Azure Active Directory (Azure AD) Premium.
      You need to add a user named admin1@contoso.com as an administrator on all the computers that will be joined to the Azure AD domain.
      What should you configure in Azure AD?

      • A. Device settings from the Devices blade.
      • B. General settings from the Groups blade.
      • C. User settings from the Users blade.
      • D. Providers from the MFA Server blade.

      Answer: C

      Explanation: When you connect a Windows device with Azure AD using an Azure AD join, Azure AD adds the following security principles to the local administrators group on the device:
      The Azure AD global administrator role The Azure AD device administrator role
      The user performing the Azure AD join In the Azure portal, you can manage the device administrator role on the Devices page. To open the Devices
      page: 1. Sign in to your Azure portal as a global administrator or device administrator.
      2. On the left navbar, click Azure Active Directory.
      3. In the Manage section, click Devices.
      4. On the Devices page, click Device settings.
      5. To modify the device administrator role, configure Additional local administrators on Azure AD joined
      devices.
      References: https://docs.microsoft.com/en-us/azure/active-directory/devices/assign-local-admin

      NEW QUESTION 6
      You need to recommend an identify solution that meets the technical requirements. What should you recommend?

      • A. federated single-on (SSO) and Active Directory Federation Services (AD FS)
      • B. password hash synchronization and single sign-on (SSO)
      • C. cloud-only user accounts
      • D. Pass-through Authentication and single sign-on (SSO)

      Answer: A

      Explanation: Active Directory Federation Services is a feature and web service in the Windows Server Operating System that allows sharing of identity information outside a company’s network.
      Scenario: Technical Requirements include:
      Prevent user passwords or hashes of passwords from being stored in Azure.
      References: https://www.sherweb.com/blog/active-directory-federation-services/

      NEW QUESTION 7
      You are the global administrator for an Azure Active Directory (Azure AD) tenant named adatum.com. From the Azure Active Directory blade, you assign the Conditional Access Administrator role to a user You need to ensure that Admin1 has just-in-time access as a conditional access administrator.
      What should you do next?

      • A. Enable Azure AD Multi-Factor Authentication (MFA).
      • B. Set Admin1 as Eligible for the Privileged Role Administrator role.
      • C. Admin1 as Eligible for the Conditional Access Administrator role.
      • D. Enable Azure AD Identity Protectio

      Answer: A

      Explanation: Require MFA for admins is a baseline policy that requires MFA for the following directory roles: Global administrator
      SharePoint administrator Exchange administrator Conditional access administrator Security administrator References:
      https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/baseline-protection

      NEW QUESTION 8
      You need to define a custom domain name for Azure AD to support the planned infrastructure. Which domain name should you use?

      • A. ad.humongousinsurance.com
      • B. humongousinsurance.onmicrosoft.com
      • C. humongousinsurance.local
      • D. humongousinsurance.com

      Answer: D

      Explanation: Every Azure AD directory comes with an initial domain name in the form of domainname.onmicrosoft.com. The initial domain name cannot be changed or deleted, but you can add your corporate domain name to Azure AD as well. For example, your organization probably has other domain names used to do business and users who sign in using your corporate domain name. Adding custom domain names to Azure AD allows you to assign user names in the directory that are familiar to your users, such as ‘alice@contoso.com.’ instead of 'alice@domain name.onmicrosoft.com'.
      Scenario:
      Network Infrastructure: Each office has a local data center that contains all the servers for that office. Each office has a dedicated connection to the Internet.
      Humongous Insurance has a single-domain Active Directory forest named humongousinsurance.com Planned Azure AD Infrastructure: The on-premises Active Directory domain will be synchronized to Azure AD.
      References: https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/add-customdomain

      NEW QUESTION 9
      You have an Azure virtual network named VNet1 that contains a subnet named Subnet1. Subnet1 contains three Azure virtual machines. Each virtual machine has a public IP address.
      The virtual machines host several applications that are accessible over port 443 to user on the Internet.
      Your on-premises network has a site-to-site VPN connection to VNet1.
      You discover that the virtual machines can be accessed by using the Remote Desktop Protocol (RDP) from the Internet and from the on-premises network.
      You need to prevent RDP access to the virtual machines from the Internet, unless the RDP connection is established from the on-premises network. The solution must ensure that all the applications can still be accesses by the Internet users.
      What should you do?

      • A. Modify the address space of the local network gateway.
      • B. Remove the public IP addresses from the virtual machines.
      • C. Modify the address space of Subnet1.
      • D. Create a deny rule in a network security group (NSG) that is linked to Subnet1.

      Answer: D

      Explanation: You can filter network traffic to and from Azure resources in an Azure virtual network with a network security group. A network security group contains security rules that allow or deny inbound network traffic to, or outbound network traffic from, several types of Azure resources.
      References:
      https://docs.microsoft.com/en-us/azure/virtual-network/security-overview

      NEW QUESTION 10
      SIMULATION
      Click to expand each objective. To connect to the Azure portal, type https://portal.azure.com in the browser address bar.
      AZ-102 dumps exhibit
      AZ-102 dumps exhibit
      AZ-102 dumps exhibit
      AZ-102 dumps exhibit
      AZ-102 dumps exhibit
      AZ-102 dumps exhibit
      When you are finished performing all the tasks, click the ‘Next’ button.
      Note that you cannot return to the lab once you click the ‘Next’ button. Scoring occur in the background while you complete the rest of the exam.
      Overview
      The following section of the exam is a lab. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design. Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn’t matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
      Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
      Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
      To start the lab
      You may start the lab by clicking the Next button.
      You plan to move backup files and documents from an on-premises Windows file server to Azure Storage. The backup files will be stored as blobs.
      You need to create a storage account named corpdata7523690n2. The solution must meet the following requirements:
      Ensure that the documents are accessible via drive mappings from Azure virtual machines that run Windows Server 2021.
      Provide the highest possible redundancy for the documents. Minimize storage access costs.
      What should you do from the Azure portal?

        Answer:

        Explanation: Step 1: In the Azure portal, click All services. In the list of resources, type Storage Accounts. As you begin typing, the list filters based on your input. Select Storage Accounts.
        Step 2: On the Storage Accounts window that appears, choose Add. Step 3: Select the subscription in which to create the storage account.
        Step 4: Under the Resource group field, select Create New. Create a new Resource
        AZ-102 dumps exhibit
        Step 5: Enter a name for your storage account: corpdata7523690n2
        Step 6: For Account kind select: General-purpose v2 accounts (recommended for most scenarios) General-purpose v2 accounts is recommended for most scenarios. . General-purpose v2 accounts deliver the lowest per-gigabyte capacity prices for Azure Storage, as well as industry-competitive transaction prices.
        Step 7: For replication select: Read-access geo-redundant storage (RA-GRS)
        Read-access geo-redundant storage (RA-GRS) maximizes availability for your storage account. RA-GRS provides read-only access to the data in the secondary location, in addition to geo-replication across
        two regions.
        References:
        https://docs.microsoft.com/en-us/azure/storage/common/storage-quickstart-create-account https://docs.microsoft.com/en-us/azure/storage/common/storage-account-overview

        NEW QUESTION 11
        You have a virtual network named VNet1 as shown in the exhibit.
        AZ-102 dumps exhibit
        No devices are connected to VNet1.
        You plan to peer VNet1 to another virtual network named Vnet2 in the same region. VNet2 has an address space of 10.2.0.0/16.
        You need to create the peering. What should you do first?

        • A. Modify the address space of VNet1.
        • B. Configure a service endpoint on VNet2
        • C. Add a gateway subnet to VNet1.
        • D. Create a subnet on VNet1 and VNet2.

        Answer: A

        Explanation: The virtual networks you peer must have non-overlapping IP address spaces. References:
        https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-managepeering# requirements-and-constraints

        NEW QUESTION 12
        You need to prepare the environment to meet the authentication requirements.
        Which two actions should you perform? Each correct answer presents part of the solution. NOTE Each correct selection is worth one point.

        • A. Azure Active Directory (AD) Identity Protection and an Azure policy
        • B. a Recovery Services vault and a backup policy
        • C. an Azure Key Vault and an access policy
        • D. an Azure Storage account and an access policy

        Answer: BD

        Explanation: D: Seamless SSO works with any method of cloud authentication - Password Hash Synchronization or Pass-through Authentication, and can be enabled via Azure AD Connect.
        B: You can gradually roll out Seamless SSO to your users. You start by adding the following Azure AD URL to all or selected users' Intranet zone settings by using Group Policy in Active Directory: https://autologon.microsoftazuread-sso.com
        Incorrect Answers:
        A: Seamless SSO needs the user's device to be domain-joined, but doesn't need for the device to be Azure AD Joined.
        C: Azure AD connect does not port 8080. It uses port 443.
        E: Seamless SSO is not applicable to Active Directory Federation Services (ADFS).
        Scenario: Users in the Miami office must use Azure Active Directory Seamless Single Sign-on (Azure AD Seamless SSO) when accessing resources in Azure.
        Planned Azure AD Infrastructure include: The on-premises Active Directory domain will be synchronized to Azure AD.
        References: https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directoryaadconnect-sso-quick-start

        NEW QUESTION 13
        You have the Azure virtual machines shown in the following table.
        AZ-102 dumps exhibit
        You have a Recovery Services vault that protects VM1 and VM2. You need to protect VM3 and VM4 by using Recovery Services. What should you do first?

        • A. Configure the extensions for VM3 and VM4.
        • B. Create a new Recovery Services vault.
        • C. Create a storage account.
        • D. Create a new backup polic

        Answer: B

        Explanation: A Recovery Services vault is a storage entity in Azure that houses dat
        A. The data is typically copies of
        data, or configuration information for virtual machines (VMs), workloads, servers, or workstations. You can use Recovery Services vaults to hold backup data for various Azure services
        References: https://docs.microsoft.com/en-us/azure/site-recovery/azure-to-azure-tutorial-enablereplication

        NEW QUESTION 14
        HOT SPOT
        You create an Azure web app named WebApp1. WebApp1 has the autoscale settings shown in the following exhibit.
        AZ-102 dumps exhibit
        AZ-102 dumps exhibit
        The scale out and scale in rules are configured to have a duration of 10 minutes and a cool down time of five minutes.
        Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
        NOTE: Each correct selection is worth one point.
        AZ-102 dumps exhibit

          Answer:

          Explanation: AZ-102 dumps exhibit

          NEW QUESTION 15
          You need to implement a backup solution for App1 after the application is moved. What should you create first?

          • A. a recovery plan
          • B. an Azure Backup Server
          • C. a backup policy
          • D. a Recovery Services vault

          Answer: D

          Explanation: A Recovery Services vault is a logical container that stores the backup data for each protected resource, such as Azure VMs. When the backup job for a protected resource runs, it creates a recovery point inside the Recovery Services vault.
          Scenario:
          There are three application tiers, each with five virtual machines.
          Move all the virtual machines for App1 to Azure.
          Ensure that all the virtual machines for App1 are protected by backups.
          References: https://docs.microsoft.com/en-us/azure/backup/quick-backup-vm-portal

          NEW QUESTION 16
          SIMULATION
          Click to expand each objective. To connect to the Azure portal, type https://portal.azure.com in the browser address bar.
          AZ-102 dumps exhibit
          AZ-102 dumps exhibit
          AZ-102 dumps exhibit
          AZ-102 dumps exhibit
          AZ-102 dumps exhibit
          AZ-102 dumps exhibit
          When you are finished performing all the tasks, click the ‘Next’ button.
          Note that you cannot return to the lab once you click the ‘Next’ button. Scoring occur in the background while you complete the rest of the exam.
          Overview
          The following section of the exam is a lab. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design. Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn’t matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
          Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
          Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
          To start the lab
          You may start the lab by clicking the Next button.
          You plan to create 100 Azure virtual machines on each of the following three virtual networks: VNET1005a
          VNET1005b VNET1005c
          All the network traffic between the three virtual networks will be routed through VNET1005a. You need to create the virtual networks, and then to ensure that all the Azure virtual machines can connect to other virtual machines by using their private IP address. The solution must NOT require any virtual network gateways and must minimize costs.
          What should you do from the Azure portal before you configure IP routing?

            Answer:

            Explanation: Step 1: Click Create a resource in the portal.
            Step 2: Enter Virtual network in the Search the Marketplace box at the top of the New pane that appears. Click Virtual network when it appears in the search results.
            Step 3: Select Classic in the Select a deployment model box in the Virtual Network pane that appears, then click Create.
            Step 4: Enter the following values on the Create virtual network (classic) pane and then click Create: Name: VNET1005a
            Address space: 10.0.0.0/16 Subnet name: subnet0 Resource group: Create new
            Subnet address range: 10.0.0.0/24
            Subscription and location: Select your subscription and location.
            Step 5: Repeat steps 3-5 for VNET1005b (10.1.0.0/16, 10.1.0.0/24), and for VNET1005c 10.2.0.0/16, 10.2.0.0/24).
            References: https://docs.microsoft.com/en-us/azure/virtual-network/create-virtual-network-classic

            NEW QUESTION 17
            You have an Azure subscription that contains the resources in the following table.
            AZ-102 dumps exhibit
            Store1 contains a file share named Data. Data contains 5,000 files.
            You need to synchronize the files in Data to an on-premises server named Server1.
            Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

            • A. Download an automation script.
            • B. Create a container instance.
            • C. Create a sync group.
            • D. Register Server1.
            • E. Install the Azure File Sync agent on Server1.

            Answer: CDE

            Explanation: Step 1 (E): Install the Azure File Sync agent on Server1
            The Azure File Sync agent is a downloadable package that enables Windows Server to be synced with an Azure file share
            Step 2 (D): Register Server1.
            Register Windows Server with Storage Sync Service
            Registering your Windows Server with a Storage Sync Service establishes a trust relationship between your server (or cluster) and the Storage Sync Service.
            Step 3 (C): Create a sync group and a cloud endpoint.
            A sync group defines the sync topology for a set of files. Endpoints within a sync group are kept in sync with each other. A sync group must contain one cloud endpoint, which represents an Azure file share and one or more server endpoints. A server endpoint represents a path on registered server. References: https://docs.microsoft.com/en-us/azure/storage/files/storage-sync-files-deploymentguide

            100% Valid and Newest Version AZ-102 Questions & Answers shared by Certleader, Get Full Dumps HERE: https://www.certleader.com/AZ-102-dumps.html (New 195 Q&As)