Microsoft AZ-102 Exam Questions and Answers 2021

Want to know AZ-102 Study Guides features? Want to lear more about AZ-102 Dumps Questions experience? Study AZ-102 Dumps. Gat a success with an absolute guarantee to pass Microsoft AZ-102 (Microsoft Azure Administrator Certification Transition) test on your first attempt.

Also have AZ-102 free dumps questions for you:

NEW QUESTION 1
HOT SPOT
You have an Azure subscription named Subscription1. Subscription1 contains the virtual machines in the following table.
AZ-102 dumps exhibit
Subscription1 contains a virtual network named VNet1 that has the subnets in the following table.
AZ-102 dumps exhibit
VM3 has a network adapter named NIC3. IP forwarding is enabled on NIC3. Routing is enabled on VM3.
You create a route table named RT1. RT1 is associated to Subnet1 and Subnet2 and contains the routes in the following table.
AZ-102 dumps exhibit
You apply RT1 to Subnet1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
AZ-102 dumps exhibit

    Answer:

    Explanation: Box 1: Yes
    Traffic from VM1 and VM2 can reach VM3 thanks to the routing table, and as IP forwarding is enabled on VM3, traffic from VM3 can reach VM1.
    Box 2: No
    VM3, which has IP forwarding, must be turned on, in order for traffic from VM2 to reach VM1. Box 3: Yes
    The traffic from VM1 will reach VM3, which thanks to IP forwarding, will send the traffic to VM2. References: https://www.quora.com/What-is-IP-forwarding

    NEW QUESTION 2
    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals.
    Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to these questions will not appear m the review screen.
    You manage a virtual network named VNetl1 that is hosted in the West US Azure region. VNetl1 hosts two virtual machines named VM1 and VM2 that run Windows Server. You need to inspect all the network traffic from VM1 to VM2 for a period of three hours. Solution: From Azure Network Watcher, you create a packet capture.
    Does this meet the goal?

    • A. Yes
    • B. No

    Answer: A

    Explanation: Azure Network Watcher provides tools to monitor, diagnose, view metrics, and enable or disable logs for resources in an Azure virtual network.
    Capture packets to and from a VM
    Advanced filtering options and fine-tuned controls, such as the ability to set time and size limitations, provide versatility. The capture can be stored in Azure Storage, on the VM's disk, or both. You can then analyze the capture file using several standard network capture analysis tools.
    Network Watcher variable packet capture allows you to create packet capture sessions to track traffic to and from a virtual machine. Packet capture helps to diagnose network anomalies both reactively and proactivity.
    References:
    https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-monitoring-overview

    NEW QUESTION 3
    HOT SPOT
    You plan to create an Azure Storage account in the Azure region of East US 2. You need to create a storage account that meets the following requirements: Replicates synchronously
    Remains available if a single data center in the region fails
    How should you configure the storage account? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.
    AZ-102 dumps exhibit

      Answer:

      Explanation: Box 1: Zone-redundant storage (ZRS)
      Zone-redundant storage (ZRS) replicates your data synchronously across three storage clusters in a single region.
      LRS would not remain available if a data center in the region fails GRS and RA GRS use asynchronous replication.
      Box 2: StorageV2 (general purpose V2) ZRS only support GPv2.
      References:
      https://docs.microsoft.com/en-us/azure/storage/common/storage-redundancy https://docs.microsoft.com/en-us/azure/storage/common/storage-redundancy-zrs

      NEW QUESTION 4
      DRAG DROP
      Your network is configured as shown in the following exhibit.
      AZ-102 dumps exhibit
      The firewalls are configured as shown in the following table.
      AZ-102 dumps exhibit
      Prod1 contains a vCenter server.
      You install an Azure Migrate Collector on Test1. You need to discover the virtual machines.
      Which TCP port should be allowed on each firewall? To answer, drag the appropriate ports to the correct firewalls. Each port may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
      NOTE: Each correct selection is worth one point.
      AZ-102 dumps exhibit

        Answer:

        Explanation: FW1: Outbound 443
        Collector communicates with Azure Migrate service over SSL 443. FW2: Outbound 443
        The Collector must be able to communicate with the vCenter Server. By default, it connects to vCenter on 443.
        Note: The collector communicates as summarized in the following diagram.
        AZ-102 dumps exhibit
        References:
        https://docs.microsoft.com/en-us/azure/migrate/concepts-collector

        NEW QUESTION 5
        You have two Azure virtual networks named VNet1 and VNet2. VNet1 contains an Azure virtual
        machine named VM1. VNet2 contains an Azure virtual machine named VM2. VM1 hosts a frontend application that connects to VM2 to retrieve data. Users report that the frontend application is slower than usual.
        You need to view the average round-trip time (RTT) of the packets from VM1 to VM2. Which Azure Network Watcher feature should you use?

        • A. NSG flow logs
        • B. Connection troubleshoot
        • C. IP flow verify
        • D. Connection monitor

        Answer: D

        Explanation: The Connection Monitor feature in Azure Network Watcher is now generally available in all public regions. Connection Monitor provides you RTT values on a per-minute granularity. You can monitor a direct TCP connection from a virtual machine to a virtual machine, FQDN, URI, or IPv4 address. References:
        https://azure.microsoft.com/en-us/updates/general-availability-azure-network-watcher-connectionmonitor- in-all-public-regions/

        NEW QUESTION 6
        Which blade should you instruct the finance department auditors to use?

        • A. invoices
        • B. partner information
        • C. cost analysis
        • D. External services

        Answer: A

        NEW QUESTION 7
        HOT SPOT
        You have an Azure web app named WebApp1 that runs in an Azure App Service plan named ASP1. ASP1 is based on the D1 pricing tier.
        You need to ensure that WebApp1 can be accessed only from computers on your on-premises network. The solution must minimize costs.
        What should you configure? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
        AZ-102 dumps exhibit

          Answer:

          Explanation: Box 1: B1
          B1 (Basic) would minimize cost compared P1v2 (premium) and S1 (standard). Box 2: Cross Origin Resource Sharing (CORS)
          Once you set the CORS rules for the service, then a properly authenticated request made against the service from a different domain will be evaluated to determine whether it is allowed according to the rules you have specified.
          Note: CORS (Cross Origin Resource Sharing) is an HTTP feature that enables a web application running under one domain to access resources in another domain. In order to reduce the possibility of cross-site scripting attacks, all modern web browsers implement a security restriction known as
          same-origin policy. This prevents a web page from calling APIs in a different domain. CORS provides a secure way to allow one origin (the origin domain) to call APIs in another origin.
          References:
          https://azure.microsoft.com/en-us/pricing/details/app-service/windows/ https://docs.microsoft.com/en-us/azure/cdn/cdn-cors

          NEW QUESTION 8
          You have an Azure subscription that contains a policy-based virtual network gateway named GW1 and a virtual network named VNet1. You need to ensure that you can configure a point-to-site connection from VNet1 to an on-premises computer. Which two actions should you perform? Each correct answer presents part of the solution.
          NOTE: Each correct selection is worth one point.

          • A. Reset GW1.
          • B. Add a service endpoint to VNet1.
          • C. Add a connection to GW1.
          • D. Add a public IP address space to VNet1.
          • E. Delete GWL
          • F. Create a route-based virtual network gatewa

          Answer: EF

          Explanation: E: Policy-based VPN devices use the combinations of prefixes from both networks to define how traffic is encrypted/decrypted through IPsec tunnels. It is typically built on firewall devices that perform packet filtering. IPsec tunnel encryption and decryption are added to the packet filtering and processing engine.
          F: A VPN gateway is used when creating a VPN connection to your on-premises network.
          Route-based VPN devices use any-to-any (wildcard) traffic selectors, and let routing/forwarding tables direct traffic to different IPsec tunnels. It is typically built on router platforms where each IPsec tunnel is modeled as a network interface or VTI (virtual tunnel interface).
          Incorrect Answers:
          D: Point-to-Site connections do not require a VPN device or a public-facing IP address. References:
          https://docs.microsoft.com/en-us/azure/vpn-gateway/create-routebased-vpn-gateway-portal https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-connect-multiple-policybasedrm- ps

          Case Study: 10
          Lab 2 Overview
          This is a lab or performance-based testing (PBT) section.
          The following section of the exam is a lab. In this section, you will perform a set of tasks m a live environment. While most liable to you as it would be m a live environment, some functionality (e g, copy and paste, ability to having sites) will not be possible by design.
          Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn't matter how you accomplish the lab9s0 and all other sections of the exam in the time provided.
          Please note that once you submit your work by clicking the Next button within a lab. you will NOT be able to return to the tab.
          AZ-102 dumps exhibit
          AZ-102 dumps exhibit
          AZ-102 dumps exhibit
          To connect to Azure portal, type https://portal.azure.com in te browser address bar.

          NEW QUESTION 9
          You need to deploy an Azure load balancer named Ib 1015 to your Azure subscription. The solution must meet the following requirements:
          -Support the load balancing of IP traffic from the Internet to Azure virtual machines connected to VNET1016 subnet0.
          -Prov.de 4 Service level Agreement (SWJ of 99.99 percent ability for the Azure virtual machines.
          -Minimize Azure-related costs.
          What should you do from the Azure portal?
          To complete this task, you do NOT need to wait for the deployment to complete. Once the deployment start in Azure, you can move to the next task.

            Answer:

            Explanation: Step 1:
            On the top left-hand side of the screen, click Create a resource > Networking > Load Balancer. Step 2:
            In the Create a load balancer page enter these values for the load balancer: myLoadBalancer - for the name of the load balancer.
            Internal - for the type of the load balancer. Basic - for SKU version.
            Microsoft guarantees that apps running in a customer subscription will be available 99.99% of the time.
            VNET1016subnet0 - for subnet that you choose from the list of existing subnets.
            Step 3: Accept the default values for the other settings and click Create to create the load balancer.

            NEW QUESTION 10
            You have an Azure Service Bus.
            You need to implement a Service Bus queue that guarantees first in first-out (FIFO) delivery of messages.
            What should you do?

            • A. Set the Lock Duration setting to 10 seconds.
            • B. Enable duplicate detection.
            • C. Set the Max Size setting of the queue to 5 GB.
            • D. Enable partitioning.
            • E. Enable session

            Answer: E

            Explanation: Through the use of messaging sessions you can guarantee ordering of messages, that is first-in-firstout (FIFO) delivery of messages.
            References:
            https://docs.microsoft.com/en-us/azure/service-bus-messaging/service-bus-azure-and-service-busqueues- compared-contrasted

            NEW QUESTION 11
            HOT SPOT
            You have an Azure subscription named Subscrption1 that is associated to an Azure Active Directory (Azure AD) tenant named AAD1.
            Subscription1 contains the objects in the following table:
            AZ-102 dumps exhibit
            You plan to create a single backup policy for Vault1. To answer, select the appropriate options in the answer area.
            NOTE: Each correct selection is worth one point.
            AZ-102 dumps exhibit

              Answer:

              Explanation: Box 1: RG1 only Box 2: 99 years
              With the latest update to Azure Backup, customers can retain their data for up to 99 years in Azure. Note: A backup policy defines a matrix of when the data snapshots are taken, and how long those snapshots are retained.
              The backup policy interface looks like this:
              AZ-102 dumps exhibit
              References: https://docs.microsoft.com/en-us/azure/backup/backup-azure-vms-first-lookarm# defining-a-backup-policy
              https://blogs.microsoft.com/firehose/2015/02/16/february-update-to-azure-backup-includes-dataretention- up-to-99-years-offline-backup-and-more/

              NEW QUESTION 12
              SIMULATION
              Click to expand each objective. To connect to the Azure portal, type https://portal.azure.com in the browser address bar.
              AZ-102 dumps exhibit
              AZ-102 dumps exhibit
              AZ-102 dumps exhibit
              When you are finished performing all the tasks, click the ‘Next’ button.
              Note that you cannot return to the lab once you click the ‘Next’ button. Scoring occur in the background while you complete the rest of the exam.
              Overview
              The following section of the exam is a lab. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design. Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn’t matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
              Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
              Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
              To start the lab
              You may start the lab by clicking the Next button.
              You plan to configure VM1 to be accessible from the Internet.
              You need to add a public IP address to the network interface used by VM1. What should you do from Azure portal?

                Answer:

                Explanation: You can add private and public IP addresses to an Azure network interface by completing the steps that follow.
                Step 1: In Azure portal, click More services > type virtual machines in the filter box, and then click Virtual machines.
                Step 2: In the Virtual machines pane, click the VM you want to add IP addresses to. Click Network interfaces in the virtual machine pane that appears, and then select the network interface you want to add the IP addresses to. In the example shown in the following picture, the NIC named myNIC from the VM named myVM is selected:
                AZ-102 dumps exhibit
                Step 3: In the pane that appears for the NIC you selected, click IP configurations. Step 4: Click Create public IP address.
                AZ-102 dumps exhibit
                Step 5: In the Create public IP address pane that appears, enter a Name, select an IP address assignment type, a Subscription, a Resource group, and a Location, then click Create, as shown in the following picture:
                References: https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-multiple-ipaddresses- portal

                NEW QUESTION 13
                HOT SPOT
                You need to recommend a solution for App1. The solution must meet the technical requirements. What should you include in the recommendation? To answer, select the appropriate options in the answer area.
                NOTE: Each correct selection is worth one point.
                AZ-102 dumps exhibit

                  Answer:

                  Explanation: This reference architecture shows how to deploy VMs and a virtual network configured for an N-tier application, using SQL Server on Windows for the data tier.
                  AZ-102 dumps exhibit
                  Scenario: You have a public-facing application named App1. App1 is comprised of the following three tiers:
                  A SQL database A web front end
                  A processing middle tier
                  Each tier is comprised of five virtual machines. Users access the web front end by using HTTPS only. Technical requirements include:
                  Move all the virtual machines for App1 to Azure. Minimize the number of open ports between the App1 tiers.
                  References: https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/n-tier/n-tier-sql-server

                  NEW QUESTION 14
                  HOT SPOT
                  You need to provision the resources in Azure to support the virtual machine that will be migrated from the New York office.
                  What should you include in the solution? To answer, select the appropriate options in the answer
                  area.
                  NOTE: Each correct selection is worth one point.
                  AZ-102 dumps exhibit

                    Answer:

                    Explanation: AZ-102 dumps exhibit
                    Box 1: 10.20.0.0/16
                    Scenario: The New York office an IP address of 10.0.0.0/16. The Los Angeles office uses an IP address space of 10.10.0.0/16.
                    Box 2: Storage (general purpose v1)
                    Scenario: The New York office has a virtual machine named VM1 that has the vSphere console installed.

                    NEW QUESTION 15
                    HOT SPOT
                    You have an Azure Active Directory (Azure AD) tenant.
                    You need to create a conditional access policy that requires all users to use multi-factor authentication when they access the Azure portal.
                    Which three settings should you configure? To answer, select the appropriate settings in the answer area.
                    AZ-102 dumps exhibit

                      Answer:

                      Explanation: Box 1: Assignments, Users and Groups
                      When you configure the sign-in risk policy, you need to set:
                      The users and groups the policy applies to: Select Individuals and Groups
                      AZ-102 dumps exhibit
                      Box 2:
                      When you configure the sign-in risk policy, you need to set the type of access you want to be enforced.
                      AZ-102 dumps exhibit
                      Box 3:
                      When you configure the sign-in risk policy, you need to set:
                      The type of access you want to be enforced when your sign-in risk level has been met:
                      AZ-102 dumps exhibit
                      References:
                      https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-user-risk-policy

                      NEW QUESTION 16
                      You have an Azure App Service plan that hosts an Azure App Service named App1.
                      You configure one production slot and four staging slots for App1.
                      You need to allocate 10 percent of the traffic to each staging slot and 60 percent of the traffic to the production slot.
                      What should you add to Appl1?

                      • A. slots to the Testing in production blade
                      • B. a performance test
                      • C. a WebJob
                      • D. templates to the Automation script blade

                      Answer: A

                      Explanation: Besides swapping, deployment slots offer another killer feature: testing in production. Just like the name suggests, using this, you can actually test in production. This means that you can route a specific percentage of user traffic to one or more of your deployment slots.
                      Example:
                      AZ-102 dumps exhibit
                      References:
                      https://stackify.com/azure-deployment-slots/

                      NEW QUESTION 17
                      You have an Azure subscription named Subscription1. Subscription1 contains a virtual machine named VM1.
                      You have a computer named Computer1 that runs Windows 10. Computer1 is connected to the Internet.
                      You add a network interface named Interface1 to VM1 as shown in the exhibit (Click the Exhibit button.)
                      AZ-102 dumps exhibit
                      From Computer1, you attempt to connect to VM1 by using Remote Desktop, but the connection fails. You need to establish a Remote Desktop connection to VM1.
                      What should you do first?

                      • A. Start VM1.
                      • B. Attach a network interface.
                      • C. Delete the DenyAllOutBound outbound port rule.
                      • D. Delete the DenyAllInBound inbound port rul

                      Answer: A

                      Explanation: Incorrect Answers:
                      B: The network interface has already been added to VM. C: The Outbound rules are fine.
                      D: The inbound rules are fine. Port 3389 is used for Remote Desktop.
                      Note: Rules are processed in priority order, with lower numbers processed before higher numbers, because lower numbers have higher priority. Once traffic matches a rule, processing stops. As a result, any rules that exist with lower priorities (higher numbers) that have the same attributes as rules with higher priorities are not processed.
                      References: https://docs.microsoft.com/en-us/azure/virtual-network/security-overview

                      NEW QUESTION 18
                      SIMULATION
                      Click to expand each objective. To connect to the Azure portal, type https://portal.azure.com in the browser address bar.
                      AZ-102 dumps exhibit
                      AZ-102 dumps exhibit
                      AZ-102 dumps exhibit
                      AZ-102 dumps exhibit
                      AZ-102 dumps exhibit
                      AZ-102 dumps exhibit
                      When you are finished performing all the tasks, click the ‘Next’ button.
                      Note that you cannot return to the lab once you click the ‘Next’ button. Scoring occur in the background while you complete the rest of the exam.
                      Overview
                      The following section of the exam is a lab. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design. Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn’t matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.
                      Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.
                      Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.
                      To start the lab
                      You may start the lab by clicking the Next button.
                      You plan to create several virtual machines in different availability zones, and then to configure the virtual machines for load balanced connections from the Internet.
                      You need to create an IP address resource named ip1006 to support the planned load balancing solution. The solution must minimize costs.
                      What should you do from the Azure portal?

                        Answer:

                        Explanation: We should create a public IP address.
                        At the top, left corner of the portal, select + Create a resource.
                        Enter public ip address in the Search the Marketplace box. When Public IP address appears in the search results, select it.
                        Under Public IP address, select Create.
                        Enter, or select values for the following settings, under Create public IP address, then select Create: Name: ip1006
                        SKU: Basic SKU IP Version: IPv6
                        IP address assignment: Dynamic Subscription: Select appropriate Resource group: Select appropriate
                        References: https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-public-ipaddress

                        P.S. Easily pass AZ-102 Exam with 195 Q&As Surepassexam Dumps & pdf Version, Welcome to Download the Newest Surepassexam AZ-102 Dumps: https://www.surepassexam.com/AZ-102-exam-dumps.html (195 New Questions)