AZ-104 sample questions

5 questions from the AZ-104 question set, which has 479 in total. Try each one before opening the answer.

Question 1 Single answer Datum Corporation
Case study Datum CorporationOverview

Datum Corporation is a consulting firm that has a main office in Montreal and branch offices in Seattle and New York.

Azure Environment

Datum has an Azure subscription that contains three resource groups named RG1. RG2, and RG3. The subscription contains the storage accounts shown in the following table.

The subscription .contains the virtual machines shown in the following table.

The subscription has an Azure container registry that contains the images shown in the following table.

The subscription contains the resources shown in the following table.

The subscription contains an Azure key vault named Vaultl.

Vault! contains the certificates shown in the following table.

Vaultl contains the keys shown in the following table.

Microsoft Entra Environment

Datum has a Microsoft Entra tenant named adatum.com that is linked to the Azure subscription and contains the users shown in the following table.

The lenant contains the groups shown in the following table.

The adatum.com tenant has a custom security attribute named Attribute1.

Planned Changes

Datum plans to implement the following changes:

• Configure a data collection rule {DCR) named DCR1 to collect only system events that have an event ID of 4648 from VM2 and VM4.

• In storage1, create a new container named cont2 that has the following access policies:

o Three stored access policies named Stored 1, Stored2, and Stored3 o A legal hold for immutable blob storage

• Whenever possible, use directories to organize storage account content.

• Grant User1 the permissions required to link Zone1 to VNet1.

• Assign Attribute1 to supported adatum.com resources.

• In storage2, create an encryption scope named Scope"1.

• Deploy new containers by using Image1 or Image2.

Technical Requirements

Datum must meet the following technical requirements:

• UseTLSforWebApp1.

• Follow the principle of least privilege.

• Grant permissions at the required scope only.

• Ensure that Scope1 is used to encrypt storage services.

• Use Azure Backup to back up cont1 and share1 as frequently as possible.

• Whenever possible, use Azure Disk Encryption and a key encryption key (KEK) to encrypt the virtual machines.

You implement the planned changes for Scope1.

You need to ensure that Scope1 meets the technical requirements.

What can you encrypt by using Scope1?

  1. containers and blobs in storage2 only

  2. containers and blobs in storage1 and storage2

  3. containers, blobs, and file shares in storage2 only

  4. containers, blobs, and file shares in storage1 and storage2

  5. containers, blobs, file shares, queues, and tables in storage2 only

Show answer

Answer: E

Explanation

In Microsoft Azure, encryption scopes are a StorageV2 (general-purpose v2) storage account feature that allows fine-grained control over encryption settings for data stored within a single account. According to Microsoft Azure Storage documentation, an encryption scope defines a specific encryption context that can be applied at the container or blob level and is supported in non-hierarchical namespace storage accounts (those without Data Lake Gen2 enabled).

In the given scenario:

storage1 has Hierarchical namespace = Yes (Data Lake Storage Gen2 enabled).

storage2 has Hierarchical namespace = No.

The plan was to create an encryption scope named Scope1 in storage2.

The technical requirement specifies that Scope1 must be used to encrypt storage services.

According to the Azure Administrator documentation on encryption scopes:

“Encryption scopes are supported for block blobs, append blobs, page blobs, Azure Files, queues, and tables in standard StorageV2 accounts. Encryption scopes are not supported in hierarchical namespace (Data Lake Gen2) enabled accounts.”

This means that Scope1—created in storage2, which does not have hierarchical namespace—can encrypt all blob data (containers and blobs) as well as file shares, queues, and tables.

However, storage1 cannot use encryption scopes because hierarchical namespace storage accounts (ADLS Gen2) manage encryption at the account level and do not support per-scope encryption.

Therefore, only storage2 can apply Scope1, and it can encrypt containers, blobs, file shares, queues, and tables.

Question 2 Hotspot Datum Corporation

You need to implement the planned changes for User1.

Which roles should you assign to User1, and for which resources? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Exhibit
Show answer
Answer
Question 3 Ordering Contoso Ltd (Consulting Company)
Case study Contoso Ltd (Consulting Company)General Overview

Contoso, Ltd. is a consulting company that has a main office in Montreal and branch offices in Seattle and New York.

EnvironmentExisting Environment

Contoso has an Azure subscription named Sub1 that is linked to an Azure Active Directory (Azure AD) tenant. The network contains an on-premises Active Directory domain that syncs to the Azure AD tenant.

The Azure AD tenant contains the users shown in the following table.

You need to configure the alerts for VM1 and VM2 to meet the technical requirements.

Which three actions should you perform in sequence? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.

Exhibit
  1. Configure the Diagnostic settings.

  2. Collect Windows performance counters from the Log analytics agents.

  3. Create an alert rule.

  4. Create an Azure SQL database.

  5. Create a Log Analytics workspace.

Show answer

Correct order: C, D, E

Question 4 Multiple answer Humongous Insurance
Case study Humongous InsuranceExisting Environment

Huongous Insurance is an insurance company that has three offices in Miami, Tokoyo, and Bankok. Each has 5000 users.

Active Directory Environment

Humongous Insurance has a single-domain Active Directory forest named humongousinsurance.com. The functional level of the forest is Windows Server 2012.

You recently provisioned an Azure Active Directory (Azure AD) tenant.

Network Infrastructure

Each office has a local data center that contains all the servers for that office. Each office has a dedicated connection to the Internet.

Each office has several link load balancers that provide access to the servers.

Active Directory Issue

Several users in humongousinsurance.com have UPNs that contain special characters.

You suspect that some of the characters are unsupported in Azure AD.

Licensing Issue

You attempt to assign a license in Azure to several users and receive the following error message: "Licenses not assigned. License agreement failed for one user."

You verify that the Azure subscription has the available licenses.

RequirementsPlanned Changes

Humongous Insurance plans to open a new office in Paris. The Paris office will contain 1,000 users who will be hired during the next 12 months. All the resources used by the Paris office users will be hosted in Azure.

Planned Azure AD Infrastructure

The on-premises Active Directory domain will be synchronized to Azure AD.

All client computers in the Paris office will be joined to an Azure AD domain.

Planned Azure Networking Infrastructure

You plan to create the following networking resources in a resource group named All_Resources:

Default Azure system routes that will be the only routes used to route traffic

A virtual network named Paris-VNet that will contain two subnets named Subnet1 and Subnet2

A virtual network named ClientResources-VNet that will contain one subnet named ClientSubnet

A virtual network named AllOffices-VNet that will contain two subnets named Subnet3 and Subnet4

You plan to enable peering between Paris-VNet and AllOffices-VNet. You will enable the Use remote gateways setting for the Paris-VNet peerings.

You plan to create a private DNS zone named humongousinsurance.local and set the registration network to the ClientResources-VNet virtual network.

Planned Azure Computer Infrastructure

Each subnet will contain several virtual machines that will run either Windows Server 2012 R2, Windows Server 2016, or Red Hat Linux.

Department Requirements

Humongous Insurance identifies the following requirements for the company's departments:

Web administrators will deploy Azure web apps for the marketing department. Each web app will be added to a separate resource group. The initial configuration of the web apps will be identical. The web administrators have permission to deploy web apps to resource groups.

During the testing phase, auditors in the finance department must be able to review all Azure costs from the past week.

Authentication Requirements

Users in the Miami office must use Azure Active Directory Seamless Single Sign-on (Azure AD Seamless SSO) when accessing resources in Azure.

You need to prepare the environment to meet the authentication requirements.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

  1. Allow inbound TCP port 8080 to the domain controllers in the Miami office.

  2. Add http://autogon.microsoftazuread-sso.com to the intranet zone of each client computer in the Miamioffice.

  3. Join the client computers in the Miami office to Azure AD.

  4. Install the Active Directory Federation Services (AD FS) role on a domain controller in the Miami office.

  5. Install Azure AD Connect on a server in the Miami office and enable Pass-through Authentication.

Show answer

Answer: B, E

Explanation

Microsoft Entra Seamless Single Sign-On, combined here with Pass-through Authentication, requires two coordinated steps. First, Microsoft Entra Connect must be installed with Pass-through Authentication and Seamless SSO enabled; this creates the AZUREADSSOACC computer account in on-premises AD and publishes the Kerberos service used for silent, ticket-based sign-in (option E). Second, because Seamless SSO relies on the browser silently negotiating Kerberos against the special endpoint https://autologon.microsoftazuread-sso.com, that URL must be added to each domain-joined client's Local Intranet zone (typically via Group Policy) so browsers treat it as trusted and automatically attempt Kerberos authentication instead of prompting the user (option B). Joining computers to Microsoft Entra ID (option C) is a separate feature (Microsoft Entra joined devices) not required for Seamless SSO with hybrid AD-joined machines. Port 8080 (option A) and AD FS (option D) are unrelated to this PTA + Seamless SSO combination, which avoids federation infrastructure entirely. B and E are correct and unchanged.

Official Reference

Microsoft Entra Seamless SSO – Quick start — https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-sso-quick-start

Question 5 Drag and drop Mix Questions
Case study Mix QuestionsAZ-104 Mix Questions IN THIS CASE STUDY

This section contains standalone questions (no shared case-study scenario) covering all five AZ-104 exam domains: identity and governance, storage, compute, networking, and monitoring/backup. Every question has been independently verified against current Microsoft Learn documentation.

You have an Azure subscription that contains the storage accounts shown in the following table.

You plan to use AzCopy to copy a blob from contained directly to share. You need to identify which authentication method to use when you use AzCopy.

What should you identify for each account? To answer, drag the appropriate authentication methods to the correct accounts. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Exhibit
Show answer
Answer

Back to AZ-104 formats and access options →