It is impossible to pass Microsoft AZ-102 exam without any help in the short term. Come to us soon and find the most advanced, correct and guaranteed AZ-102 Exam Questions and Answers. You will get a surprising result by our AZ-102 Braindumps.

Free AZ-102 Demo Online For Microsoft Certifitcation:

NEW QUESTION 1
You create an Azure subscription that is associated to a basic Azure Active Directory (Azure AD) tenant. You need to receive an email notification when any user activates an administrative role. What should you do?

  • A. Purchase Azure AD Premium 92 and configure Azure AD Privileged Identity Management,
  • B. Purchase Enterprise Mobility + Security E3 and configure conditional access policies.
  • C. Purchase Enterprise Mobility + Security E5 and create a custom alert rule in Azure Security Center.
  • D. Purchase Azure AD Premium PI and enable Azure AD Identity Protectio

Answer: A

Explanation: When key events occur in Azure AD Privileged Identity Management (PIM), email notifications are sent. For example, PIM sends emails for the following events:
When a privileged role activation is pending approval When a privileged role activation request is completed When a privileged role is activated
When a privileged role is assigned When Azure AD PIM is enabled References:
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pimemail- notifications

NEW QUESTION 2
You need to prepare the environment to meet the authentication requirements.
Which two actions should you perform? Each correct answer presents part of the solution. NOTE Each correct selection is worth one point.

  • A. Azure Active Directory (AD) Identity Protection and an Azure policy
  • B. a Recovery Services vault and a backup policy
  • C. an Azure Key Vault and an access policy
  • D. an Azure Storage account and an access policy

Answer: BD

Explanation: D: Seamless SSO works with any method of cloud authentication - Password Hash Synchronization or Pass-through Authentication, and can be enabled via Azure AD Connect.
B: You can gradually roll out Seamless SSO to your users. You start by adding the following Azure AD URL to all or selected users' Intranet zone settings by using Group Policy in Active Directory: https://autologon.microsoftazuread-sso.com
Incorrect Answers:
A: Seamless SSO needs the user's device to be domain-joined, but doesn't need for the device to be Azure AD Joined.
C: Azure AD connect does not port 8080. It uses port 443.
E: Seamless SSO is not applicable to Active Directory Federation Services (ADFS).
Scenario: Users in the Miami office must use Azure Active Directory Seamless Single Sign-on (Azure AD Seamless SSO) when accessing resources in Azure.
Planned Azure AD Infrastructure include: The on-premises Active Directory domain will be synchronized to Azure AD.
References: https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directoryaadconnect-sso-quick-start

NEW QUESTION 3
HOT SPOT
You have peering configured as shown in the following exhibit.
AZ-102 dumps exhibit
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
AZ-102 dumps exhibit

    Answer:

    Explanation: Box 1: vNET6 only
    Box 2: Modify the address space
    The virtual networks you peer must have non-overlapping IP address spaces.
    References: https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-managepeering#requirements-and-constraints

    NEW QUESTION 4
    You plan to automate the deployment of a virtual machine scale set that uses the Windows Server 2021 Datacenter image.
    You need to ensure that when the scale set virtual machines are provisioned, they have web server components installed.
    Which two actions should you perform? Each correct answer presents part of the solution. NOTE Each correct selection is worth one point.

    • A. Modify the extensionProfile section of the Azure Resource Manager template.
    • B. Create a new virtual machine scale set in the Azure portal.
    • C. Create an Azure policy.
    • D. Create an automation account.
    • E. Upload a configuration scrip

    Answer: AB

    Explanation: Virtual Machine Scale Sets can be used with the Azure Desired State Configuration (DSC) extension handler. Virtual machine scale sets provide a way to deploy and manage large numbers of virtual machines, and can elastically scale in and out in response to load. DSC is used to configure the VMs as they come online so they are running the production software.
    References: https://docs.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machinescale- sets-dsc

    NEW QUESTION 5
    HOT SPOT
    You have an Azure subscription named Subscription1.
    You have a virtualization environment that contains the virtualization servers in the following table.
    AZ-102 dumps exhibit
    The virtual machines are configured as shown in the following table.
    AZ-102 dumps exhibit
    All the virtual machines use basic disks. VM1 is protected by using BitLocker Drive Encryption (BitLocker).
    You plan to use Azure Site Recovery to migrate the virtual machines to Azure.
    Which virtual machines can you migrate? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
    AZ-102 dumps exhibit

      Answer:

      Explanation: Box 1: VM3
      Not VM1 as Bitlocker is not supported. BitLocker must be disabled before you enable replication for a VM.
      Not VM2 as maximum Operating system disk size for a generation VM is 2,048 GB. Box 2: VMA and VMB only
      Not VMC as the max data disk size is 4,095 GB References:
      https://docs.microsoft.com/en-us/azure/site-recovery/hyper-v-azure-support-matrix https://docs.microsoft.com/en-us/azure/site-recovery/vmware-physical-azure-supportmatrix# azure-vm-requirements

      NEW QUESTION 6
      Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
      After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
      You have an Azure subscription named Subscription1. Subscription1 contains a resource group named RG1. RG1 contains resources that were deployed by using templates.
      You need to view the date and time when the resources were created in RG1. Solution: From the RG1 blade, you click Automation script.
      Does this meet the goal?

      • A. Yes
      • B. No

      Answer: B

      NEW QUESTION 7
      You discover that VM3 does NOT meet the technical requirements. You need to verify whether the issue relates to the NSGs.
      What should you use?

      • A. Diagram in VNet1
      • B. the security recommendations in Azure Advisor
      • C. Diagnostic settings in Azure Monitor
      • D. Diagnose and solve problems in Traffic Manager Profiles
      • E. IP flow verify in Azure Network Watcher

      Answer: E

      Explanation: Scenario: Contoso must meet technical requirements including:
      Ensure that VM3 can establish outbound connections over TCP port 8080 to the applications servers in the Montreal office.
      IP flow verify checks if a packet is allowed or denied to or from a virtual machine. The information consists of direction, protocol, local IP, remote IP, local port, and remote port. If the packet is denied by a security group, the name of the rule that denied the packet is returned. While any source or destination IP can be chosen, IP flow verify helps administrators quickly diagnose connectivity issues from or to the internet and from or to the on-premises environment.
      References:
      https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-ip-flow-verify-overview

      NEW QUESTION 8
      Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
      After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
      You have an Azure Active Directory (Azure AD) tenant named Adatum and an Azure Subscription named Subscription1. Adatum contains a group named Developers. Subscription1 contains a resource group named Dev.
      You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group.
      Solution: On Subscription1, you assign the Logic App Operator role to the Developers group. Does this meet the goal?

      • A. Yes
      • B. No

      Answer: B

      Explanation: The Logic App Operator role only lets you read, enable and disable logic app. With it you can view the logic app and run history, and enable/disable. Cannot edit or update the definition.
      You would need the Logic App Contributor role. References:
      https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles https://docs.microsoft.com/en-us/azure/logic-apps/logic-apps-securing-a-logic-app

      NEW QUESTION 9
      You have two Azure Active Directory (Azure AD) tenants named contoso.com and fabrikam.com. You have a Microsoft account that you use to sign in to both tenants.
      You need to configure the default sign-in tenant for the Azure portal. What should you do?

      • A. From the Azure portal, configure the portal settings.
      • B. From the Azure portal, change the directory.
      • C. From Azure Cloud Shell, run Set-AzureRmContext.
      • D. From Azure Cloud Shell, run Set-AzureRmSubscriptio

      Answer: B

      Explanation: Change the subscription directory in the Azure portal.
      The classic portal feature Edit Directory, that allows you to associate an existing subscription to your Azure Active Directory (AAD), is now available in Azure portal. It used to be available only to Service Admins with Microsoft accounts, but now it's available to users with AAD accounts as well.
      To get started:
      Go to Subscriptions. Select a subscription. Select Change directory. Incorrect Answers:
      C: The Set-AzureRmContext cmdlet sets authentication information for cmdlets that you run in the current session. The context includes tenant, subscription, and environment information. References: https://azure.microsoft.com/en-us/updates/edit-directory-now-in-new-portal/

      NEW QUESTION 10
      Another administrator reports that she is unable to configure a web app named corplod7509086n3 to prevent all connections from an IP address of 11.0.0.11.
      You need to modify corplod7509086n3 to successfully prevent the connections from the IP address. The solution must minimize Azure-related costs.
      What should you do from the Azure portal?

        Answer:

        Explanation: Step 1:
        Find and select application corplod7509086n3:
        1. In the Azure portal, on the left navigation panel, click Azure Active Directory.
        2. In the Azure Active Directory blade, click Enterprise applications. Step 2:
        To add an IP restriction rule to your app, use the menu to open Network>IP Restrictions and click on Configure IP Restrictions
        AZ-102 dumps exhibit
        Step 3:
        Click Add rule
        You can click on [+] Add to add a new IP restriction rule. Once you add a rule, it will become effective immediately.
        AZ-102 dumps exhibit
        Step 4:
        Add name, IP address of 11.0.0.11, select Deny, and click Add Rule
        AZ-102 dumps exhibit
        References:
        https://docs.microsoft.com/en-us/azure/app-service/app-service-ip-restrictions

        NEW QUESTION 11
        You have an Azure subscription that contains an Azure file share.
        You have an on-premises server named Server1 that runs Windows Server 2021. You plan to set up Azure File Sync between Server1 and the Azure file share. You need to prepare the subscription for the planned Azure File Sync.
        Which two actions should you perform in the Azure subscription? To answer, drag the appropriate actions to the correct targets. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
        AZ-102 dumps exhibit

          Answer:

          Explanation: First action: Create a Storage Sync Service
          The deployment of Azure File Sync starts with placing a Storage Sync Service resource into a resource group of your selected subscription.
          Second action: Run Server Registration
          Registering your Windows Server with a Storage Sync Service establishes a trust relationship between your server (or cluster) and the Storage Sync Service. A server can only be registered to one Storage Sync Service and can sync with other servers and Azure file shares associated with the same Storage Sync Service.
          The Server Registration UI should open automatically after installation of the Azure File Sync agent.
          AZ-102 dumps exhibit

          NEW QUESTION 12
          HOT SPOT
          You have an Azure subscription named Subscription1. Subscription1 contains the resources in the following table.
          AZ-102 dumps exhibit
          VNet1 is in RG1. VNet2 is in RG2. There is no connectivity between VNet1 and Vnet2.
          An administrator named Admin1 creates an Azure virtual machine named VM1 in RG1. VM1 uses a disk named Disk1 and connects to VNet1. Admin1 then installs a custom application in VM1.
          You need to move the custom application to Vnet2. The solution must minimize administrative effort.
          Which two actions should you perform? To answer, select the appropriate options in the answer area.
          NOTE: Each correct selection is worth one point.
          AZ-102 dumps exhibit

            Answer:

            Explanation: You can move a VM and its associated resources to another resource group using the portal. References: https://docs.microsoft.com/en-us/azure/virtual-machines/windows/move-vm

            NEW QUESTION 13
            Which blade should you instruct the finance department auditors to use?

            • A. Cost analysis
            • B. Usage + quotas
            • C. External services
            • D. Payment methods

            Answer: B

            Explanation: Subscription costs are based on usage. Microsoft Azure limits are also called quotas.
            Scenario: During the testing phase, auditors in the finance department must be able to review all Azure costs from the past week.
            Incorrect Answers:
            C: External services are published by third party software vendors in the Azure marketplace. References: https://docs.microsoft.com/en-us/azure/azure-subscription-service-limits

            NEW QUESTION 14
            HOT SPOT
            You plan to create a new Azure Active Directory (Azure AD) role.
            You need to ensure that the new role can view all the resources in the Azure subscription and issue support requests to Microsoft. The solution must use the principle of least privilege.
            How should you complete the JSON definition? To answer, select the appropriate options in the answer area.
            NOTE: Each correct selection is worth one point.
            AZ-102 dumps exhibit

              Answer:

              Explanation: Box 1: "*/read",
              */read lets you view everything, but not make any changes. Box 2: " Microsoft.Support/*"
              The action Microsoft.Support/* enables creating and management of support tickets. References:
              https://docs.microsoft.com/en-us/azure/role-based-access-control/tutorial-custom-role-powershell https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles

              NEW QUESTION 15
              HOT SPOT
              You have an Azure subscription named Subscrption1 that is associated to an Azure Active Directory (Azure AD) tenant named AAD1.
              Subscription1 contains the objects in the following table:
              AZ-102 dumps exhibit
              You plan to create a single backup policy for Vault1. To answer, select the appropriate options in the answer area.
              NOTE: Each correct selection is worth one point.
              AZ-102 dumps exhibit

                Answer:

                Explanation: Box 1: RG1 only Box 2: 99 years
                With the latest update to Azure Backup, customers can retain their data for up to 99 years in Azure. Note: A backup policy defines a matrix of when the data snapshots are taken, and how long those snapshots are retained.
                The backup policy interface looks like this:
                AZ-102 dumps exhibit
                References: https://docs.microsoft.com/en-us/azure/backup/backup-azure-vms-first-lookarm# defining-a-backup-policy
                https://blogs.microsoft.com/firehose/2015/02/16/february-update-to-azure-backup-includes-dataretention- up-to-99-years-offline-backup-and-more/

                NEW QUESTION 16
                From the MFA Server blade, you open the Block/unblock users blade as shown in the exhibit.
                AZ-102 dumps exhibit
                What caused AlexW to be blocked?

                • A. An administrator manually blocked the user.
                • B. The user reports a fraud alert when prompted for additional authentication.
                • C. The user account password expired.
                • D. The user entered an incorrect PIN four times within 10 minute

                Answer: B

                NEW QUESTION 17
                You create a new replication policy in Azure for the physical servers. You successfully complete the following actions:
                Create and configure a Recovery Services vault.
                Ensure Internet connectivity.
                Ensure that the required URLs are reachable.
                Ensure that the host server requirements are met.
                Ensure that the servers marked for replication comply with the requirements of the Azure virtual machines.
                You need to replicate the on-premises servers to Azure.
                Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
                NOTE: More than one order of answer choices is correct. You will receive credit for any of the correct orders you select.
                AZ-102 dumps exhibit

                  Answer:

                  Explanation: Step 2: Deploy the OVF template Set up the source environment.
                  Download the OVF template for the configuration server, and import the template in VMware.
                  Note: Open Virtualization Format (OVF) template is an industry standard software distribution model for virtual machine templates. Starting January 2021, configuration server for the VMware to Azure scenario will be available to all our customers as an OVF template.
                  Step 3: Associate the configuration server to the replication policy Associate the replication policy with your on-premises configuration server. Step 4: Enable replication
                  References:
                  https://docs.microsoft.com/en-us/azure/site-recovery/vmware-azure-set-up-replication

                  NEW QUESTION 18
                  You need to prevent remote users from publishing via FTP to a function app named FunctionApplod7509087fa. Remote users must be able to publish via FTPS. What should you do from the Azure portal?

                    Answer:

                    Explanation: Step 1:
                    Locate and select the function app FunctionApplod7509087fa. Step 2:
                    Select Application Settings > FTP Access, change FTP access to FTPS Only, and click Save.
                    AZ-102 dumps exhibit
                    References:
                    https://blogs.msdn.microsoft.com/appserviceteam/2021/05/08/web-apps-making-changes-to-ftpdeployments/

                    P.S. Easily pass AZ-102 Exam with 195 Q&As Certleader Dumps & pdf Version, Welcome to Download the Newest Certleader AZ-102 Dumps: https://www.certleader.com/AZ-102-dumps.html (195 New Questions)