A company needs to improve the security of its Windows Server VMs in Azure, what should they implement?
AJust-in-Time VM Access
BAzure Backup
CApplication Insights
DAzure Load Balancer
Explanation
Just-in-Time VM Access restricts access to VMs, enhancing security, while the other options focus on backup, monitoring, and traffic distribution.
Q12
You are configuring a site-to-site VPN connection between an Azure virtual network and an on-premises network. What happens if the local network gateway is misconfigured?
AAzure cannot reach the on-premises network
BData transfer speeds increase
CAll traffic is automatically encrypted
DVPN connection remains unaffected
Explanation
If the local network gateway is misconfigured, Azure will not be able to reach the on-premises network; the other options are incorrect consequences of misconfiguration.
Q13
Which service can you use to monitor Azure AD logins?
AAzure Monitor
BAzure Security Center
CAzure Active Directory
DAzure Sentinel
Explanation
Azure Sentinel allows advanced monitoring including AD logins; others focus on different aspects.
Q14
A company needs to provide temporary VPN access to contractors. What Azure service should they use?
AAzure Point-to-Site VPN
BAzure ExpressRoute
CAzure VNet Peering
DAzure Site-to-Site VPN
Explanation
Point-to-Site VPN is designed for individual access; others serve different network configurations.
Q15
You are configuring hybrid backups. What happens if you select 'Azure Backup' instead of 'Azure Site Recovery'?
AOnly VM backups are created.
BData is not replicated.
CDisaster recovery services are disabled.
DFile-level recovery is enabled.
Explanation
Choosing Azure Backup means no DR services, only backups; others misrepresent the function.
Q16
Which service simplifies the integration of on-premises identities with Azure AD?
AAzure AD Connect
BAzure Active Directory
CMicrosoft Intune
DAzure ExpressRoute
Explanation
Azure AD Connect is designed to sync identities between on-premises Active Directory and Azure AD; others provide different functionalities.
Q17
You are configuring a virtual network gateway for Site-to-Site VPN. What happens if the local network gateway IP address configuration is incorrect?
AVPN establishes successfully.
BConnection fails to establish.
CData is encrypted but not routed.
DAll traffic is blocked externally.
Explanation
Connection fails when local gateway IP is incorrect; all other options misrepresent capability or outcomes.
Q18
A company needs to transfer large files to Azure Blob Storage. What should they prioritize configuring for high throughput?
ABlob tiering
BAzure Data Box
CStorage replication
DAccess policies
Explanation
Azure Data Box is specifically designed for large transfers; the others focus on different aspects of storage management.
Q19
Which service enables seamless connectivity between on-premises and Azure-hosted applications?
AAzure ExpressRoute
BAzure Blob Storage
CAzure Backup
DAzure DevOps
Explanation
Azure ExpressRoute provides dedicated private connections, while others don’t focus on connectivity.
Q20
A company needs to implement role-based access control in Azure. What should they do?
ACreate a Network Security Group
BUse Azure Active Directory
CDeploy a Web Application Firewall
DEnable Azure Monitor
Explanation
Azure Active Directory supports role-based access control, while others serve different purposes.