Microsoft AZ-303 Exam Dumps [2022] Practice Valid Exam Dumps Question
AZ-303 Dumps - Grab Out For [NEW-2022] Microsoft Exam
Azure Infrastructure Implementation and Monitoring: 50-55%
- Storage Accounts Implementation – The potential candidates should have competence in managing access keys as well as implementing Azure storage replication and Azure storage account failover. The topic also covers Shared Access Signatures, access policies, and Azure Active Directory authentication for storage. You must also demonstrate the knowledge of how to configure blob storage, Azure Files, and network access for the storage account;
- Azure Active Directory Implementation – The applicants should demonstrate the skills in managing and implementing guest accounts, self-service password reset, multiple directories, and Conditional Access. They also need competence in adding custom domains and configuring Azure Active Directory Identity Protection. Additionally, they need the skills in configuring fraud alerts, bypass options, user accounts for MFA, verification methods, and Trusted IPs;
- Implementation of Virtual Machines for Linux and Windows – It is important to know how to configure Azure Disk Encryption, High Availability, and storage for Virtual Machines. You also need the skills in configuring and deploying scale sets and choosing virtual machine sizes;
- Automation of Configuration and Deployment of Resources – This subsection requires competence in managing template libraries, creating and implementing automation run-books, and deploying from templates. The examinees also need the expertise in configuring virtual disk templates, measuring the location of the latest resources, and modifying the Azure Resource Manager template;
NEW QUESTION 38
Your company has the groups shown in the following table.
The company has an Azure subscription that contains an Azure Active Directory (Azure AD) tenant named contoso.com.
An administrator named Admin1 attempts to enable Enterprise State Roaming for all the users in the Managers group.
Admin1 reports that the options for Enterprise State Roaming are unavailable from Azure AD.
You verify that Admin1 is assigned the Global administrator role.
You need to ensure that Admin1 can enable Enterprise State Roaming.
What should you do?
- A. Enforce Azure Multi-Factor Authentication (MFA) for Admin1.
- B. Assign an Azure AD Privileged Identity Management (PIM) role to Admin1.
- C. Purchase an Azure AD Premium P1 license for each user in the Managers group.
- D. Purchase an Azure Rights Management (Azure RMS) license for each user in the Managers group.
Answer: C
Explanation:
Explanation
Enterprise State Roaming is available to any organization with an Azure AD Premium or Enterprise Mobility
+ Security (EMS) license.
References:
https://docs.microsoft.com/bs-latn-ba/azure/active-directory/devices/enterprise-state-roaming-enable
NEW QUESTION 39
You have an Azure subscription that contains a resource group named RG1. RG1 contains multiple resources.
You need to trigger an alert when the resources in RG1 consume $1,000 USD.
What should you do?
- A. From RG1, create an event subscription.
- B. From Cost Management + Billing, add a cloud connector.
- C. From Cost Management + Billing, create a budget.
- D. From the subscription, create an event subscription.
Answer: C
Explanation:
Explanation
Explanation:
Create budgets to manage costs and create alerts that automatically notify you are your stakeholders of spending anomalies and overspending.
To set it up, go to the Azure Portal, select 'Cost Management + Billing' -> 'Cost Management' -> 'Go to Cost Management'.
Note: Cost alerts are automatically generated based when Azure resources are consumed. Alerts show all active cost management and billing alerts together in one place. When your consumption reaches a given threshold, alerts are generated by Cost Management. There are three types of cost alerts: budget alerts, credit alerts, and department spending quota alerts.
Reference:
https://docs.microsoft.com/en-us/azure/cost-management-billing/manage/getting-started
NEW QUESTION 40
You have an Azure key vault named KV1.
You need to ensure that applications can use KV1 to provision certificates automatically from an external certification authority (CA).
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
- A. Obtain the root CA certificate.
- B. From KV1, create a certificate issuer resource.
- C. From KV1, create a private key,
- D. Obtain the CA account credentials.
- E. From KV1, create a certificate signing request (CSR).
Answer: A,E
Explanation:
C: Obtain the root CA certificate (step 4 in the picture below)
D: From KV1, create a certificate signing request (CSR) (step 2 in the picture below) Note:
Creating a certificate with a CA not partnered with Key Vault
This method allows working with other CAs than Key Vault's partnered providers, meaning your organization can work with a CA of its choice.
The following step descriptions correspond to the green lettered steps in the preceding diagram.
In the diagram above, your application is creating a certificate, which internally begins by creating a key in your key vault.
Key Vault returns to your application a Certificate Signing Request (CSR).
Your application passes the CSR to your chosen CA.
Your chosen CA responds with an X509 Certificate.
Your application completes the new certificate creation with a merger of the X509 Certificate from your CA.
Reference:
https://docs.microsoft.com/en-us/azure/key-vault/certificates/certificate-scenarios
NEW QUESTION 41
You have an Azure Container Registry and an Azure container instance.
You pull an image from the registry, and then update the local copy of the image.
You need to ensure that the updated image can be deployed to the container instance. The solution must ensure that you can deploy the updated image or the previous version of the image.
What should you do?
- A. Run the az image copy command and specify the tag parameter. Run the az aks update command and specify the attach-acr parameter.
- B. Run the docker image push command and specify the tag parameter.
- C. Run the kubect1 apply command and specify the dry-run parameter.
Answer: A
NEW QUESTION 42
You have a hierarchy of management groups and Azure subscriptions as shown in the following table.
You create the Azure resources shown in the following table.
You assign roles to users as shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point
Answer:
Explanation:
Explanation:
Box 1: Yes
You have assigned the role, so you can remove it.
Box 2: Yes
Contributor role: Grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC.
Box 3: No
Reference:
https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#contributor
NEW QUESTION 43
You have an Azure virtual machine named VM1 and an Azure Active Directory (Azure AD) tenant named adatum.com.
D18912E1457D5D1DDCBD40AB3BF70D5D
VM1 has the following settings:
* IP address: 10.10.0.10
* System-assigned managed identity: On
You need to create a script that will run from within VM1 to retrieve the authentication token of VM1.
Which address should you use in the script?
- A. 10.10.0.10
- B. vm1.adatum.com.onmicrosoft.com
- C. vm1.adatum.com
- D. 169.254.169.254
Answer: D
Explanation:
Your code that's running on the VM can request a token from the Azure Instance Metadata Service identity endpoint, accessible only from within the VM: http://169.254.169.254/metadata/identity/oauth2/token Reference:
https://docs.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/overview
NEW QUESTION 44
DRAG DROP
You need to prepare the environment to ensure that the web administrators can deploy the web apps as quickly as possible.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:
Answer:
Explanation:
Section: [none]
Explanation:
Step 1:
First you create a storage account using the Azure portal.
Step 2:
Select Automation options at the bottom of the screen. The portal shows the template on the Template tab.
Add the storage account to the library.
Step 3:
Share the template.
Scenario: Web administrators will deploy Azure web apps for the marketing department. Each web app will be added to a separate resource group. The initial configuration of the web apps will be identical. The web administrators have permission to deploy web apps to resource groups.
References:
https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-manager-quickstart-create- templates-use-the-portal
NEW QUESTION 45
You have an on-premises virtual machine named VM1 configured as shown in the following exhibit.
VM is started.
You need to create a new virtual machine image in Azure from VM1.
Which three actions should you perform before you create the new image? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
- A. Convert the disk type to VHD
- B. Remove the Backup (volume shadow copy) integration service
- C. Run Add-AzureRmVhd and specify a blob service container as the destination
- D. Reduce the amount of memory to 16 GB
- E. Run Add-AzureRmVhd and specify a file share as the destination
- F. Generalize VM1
Answer: A,C,F
NEW QUESTION 46
You are developing an Azure Web App. You configure TLS mutual authentication for the web app.
You need to validate the client certificate in the web app. To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION 47
You have an Azure subscription that contains the resource groups shown in the following table.
You create an Azure Resource Manager template named Template1 as shown in the following exhibit.
From the Azure portal, you deploy Template1 four times by using the settings shown in the following table.
What is the result of the deployment? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION 48
You have 10 Azure virtual machines on a subnet named Subnet1. Subnet1 is on a virtual network named VNet1.
You plan to deploy a public Azure Standard Load Balancer named LB1 to the same Azure region as the 10 virtual machines.
You need to ensure that traffic from all the virtual machines to the internet flows through LB1. The solution must prevent the virtual machines from being accessible on the internet.
Which three actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
- A. Add an outbound rule to LB1.
- B. Add an inbound rule to LB1.
- C. Associate a network security group (NSG) to Subnet1.
- D. Add the network interfaces of the virtual machines to the backend pool of LB1.
- E. Add health probes to LB1.
- F. Associate a user-defined route to Subnet1.
Answer: A,D,E
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/load-balancer/tutorial-load-balancer-standard-manage-portal2
NEW QUESTION 49
Your company has an Azure Container Registry named Registry1.
You have an Azure virtual machine named Server1 that runs Windows Server 2019.
From Server1, you create a container image named image1.
You need to add image1 to Registry1.
Which command should you run on Server1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
An Azure container registry stores and manages private Docker container images, similar to the way Docker Hub stores public Docker images. You can use the Docker command-line interface (Docker CLI) for login, push, pull, and other operations on your container registry.
Reference:
https://docs.microsoft.com/en-us/azure/container-registry/container-registry-get-started-docker-cli
https://docs.docker.com/engine/reference/commandline/push/
NEW QUESTION 50
You have an Azure subscription that contains a resource group named RG1.
You have a group named Group1 that is assigned the Contributor role for RG1.
You need to enhance security for the virtual machines in RG1 to meet the following requirements:
* Prevent Group1 from assigning external IP addresses to the virtual machines.
* Ensure that Group1 can establish an RDP connection to the virtual machines through a shared external IP address.
What should you use to meet each requirement? To answer, select the appropriate options in the answer are a. NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://blog.nillsf.com/index.php/2019/11/02/using-azure-policy-to-deny-public-ips-on-specific-vnets/
https://azure.microsoft.com/en-us/services/azure-bastion/
NEW QUESTION 51
You need to recommend an identity solution that meets the technical requirements.
What should you recommend?
- A. cloud-only user accounts
- B. Pass-thorough Authentication and single sign-on (SSO)
- C. federated single sign-on (SSO) and Active Directory Federation Services (AD FS)
- D. password hash synchronization and single sign-on (SSO)
Answer: B
Explanation:
With Pass-through Authentication the on-premises passwords are never stored in the cloud in any form.
Scenario:
* Prevent user passwords or hashes of passwords from being stored in Azure.
* Ensure that when users join devices to Azure Active Directory (Azure AD), the users use a mobile phone to verify their identity.
* Minimize administrative effort whenever possible.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta Implement Solutions for Apps Question Set 1
NEW QUESTION 52
You have an Azure subscription that contains a resource group named RG1.
You have a group named Group1 that is assigned the Contributor role for RG1.
You need to enhance security for the virtual machines in RG1 to meet the following requirements:
* Prevent Group1 from assigning external IP addresses to the virtual machines.
* Ensure that Group1 can establish an RDP connection to the virtual machines through a shared external IP address.
What should you use to meet each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION 53
You have an Azure Storage account named storage1 that is accessed by several applications.
An administrator manually rotates the access keys for storage1.
After the rotation, the applications fail to access the storage account.
A developer manually modifies the applications to resolve the issue.
You need to implement a solution to rotate the access keys automatically. The solution must minimize the need to update the applications once the solution is implemented.
What should you include in the solution?
- A. an Azure AD enterprise application
- B. Azure Key Vault
- C. an Azure Desired State Configuration (DSC) extension
- D. Azure Logic Apps
Answer: B
Explanation:
Section: [none]
Explanation:
Microsoft recommends that you use Azure Key Vault to manage your access keys, and that you regularly rotate and regenerate your keys. Using Azure Key Vault makes it easy to rotate your keys without interruption to your applications. You can also manually rotate your keys.
Reference:
https://docs.microsoft.com/en-us/azure/storage/common/storage-account-keys-manage
NEW QUESTION 54
HOTSPOT
You are creating an app that uses Event Grid to connect with other services. Your app's event data will be sent to a serverless function that checks compliance. This function is maintained by your company.
You write a new event subscription at the scope of your resource. The event must be invalidated after a specific period of time.
You need to configure Event Grid to ensure security.
What should you implement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:
Answer:
Explanation:
Section: [none]
Explanation/Reference:
References:
https://docs.microsoft.com/en-us/azure/event-grid/security-authentication
NEW QUESTION 55
Your company has a virtualization environment that contains the virtualization hosts shown in the following table.
The virtual machines are configured as shown in the following table.
All the virtual machines use basic disks. VM1 is protected by using BitLocker Drive Encryption (BitLocker).
You plan to migrate the virtual machines to Azure by using Azure Site Recovery.
You need to identify which virtual machines can be migrated.
Which virtual machines should you identify for each server? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
NEW QUESTION 56
You have an Azure subscription that contains the resources shown in the following table.
Subnet1 is on VNET1. VM1 connects to Subnet1.
You plan to create a virtual network gateway on VNET1.
You need to prepare the environment for the planned virtual network gateway.
What are two ways to achieve this goal? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
- A. Modify the address space used by VNET1.
- B. Modify the address space used by Subnet1.
- C. Create a local network gateway.
- D. Delete Subnet1.
- E. Create a subnet named GatewaySubnet on VNET1.
Answer: A,D
Explanation:
Section: [none]
NEW QUESTION 57 
Subnet1 contains a virtual appliance named VM1 that operates as a router.
You create a routing table named RT1.
You need to route all inbound traffic to VNet1 through VM1.
How should you configure RT1? To answer, select the appropriate options in the answer area.
You have an Azure subscription that contains a virtual network named VNet1. VNet1 uses an IP address space of 10.0.0.0/16 and contains the subnets in the following table.
1. 10.0.1.0/24: Address space of sbbnet 1 as routing should be made through vm1.
2. Virtual Network: Next hop needs to be made for virtual network.
3. Gateway Subnet: Should be made through vnet gateway and that used gateway subnet only.
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-networks-udr-overview
Answer:
Explanation:
NEW QUESTION 58
Note: This question is part of series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure Active Directory (Azure AD) tenant named contoso.com.
A user named Admin1 attempts to create an access review from the Azure Active Directory admin center and discovers that the Access reviews settings are unavailable. Admin1 discovers that all the other Identity Governance settings are available.
Admin1 is assigned the User administrator, Compliance administrator, and Security administrator roles.
You need to ensure that Admin1 can create access reviews in contoso.com.
Solution: You assign the Service administrator role to Admin1.
Does this meet the goal?
- A. Yes
- B. No
Answer: B
Explanation:
Instead use Azure AD Privileged Identity Management.
Note: PIM essentially helps you manage the who, what, when, where, and why for resources that you care about. Key features of PIM include:
* Conduct access reviews to ensure users still need roles
References:
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure
NEW QUESTION 59
Note: This question is part of series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory forest named fabrikam.com. The forest contains two child domains named corp.fabrikam.com and research.fabrikam.com.
You have an Azure subscription that contains an Azure Active Directory (Azure AD) tenant named contoso.com.
You install Azure AD Connect and sync all the on-premises user accounts to the Azure AD tenant. You implement seamless single sign-on (SSO).
You plan to change the source of authority for all the user accounts in research.fabrikam.com to Azure AD.
You need to prevent research.fabrikam.com from resyncing to Azure AD.
Solution: You use the Synchronization Service Manager.
Does this meet the goal?
- A. Yes
- B. No
Answer: B
Explanation:
Section: [none]
Explanation:
Instead you should customize the default synchronization rule.
Note: The Synchronization Service Manager UI is used to configure more advanced aspects of the sync engine and to see the operational aspects of the service.
References:
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-create-custom-sync-rule
NEW QUESTION 60
You have 10 Azure virtual machines on a subnet named Subnet1. Subnet1 is on a virtual network named VNet1.
You plan to deploy a public Azure Standard Load Balancer named LB1 to the same Azure region as the 10 virtual machines.
You need to ensure that traffic from all the virtual machines to the internet flows through LB1. The solution must prevent the virtual machines from being accessible on the internet.
Which three actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
- A. Add an outbound rule to LB1.
- B. Add an inbound rule to LB1.
- C. Associate a network security group (NSG) to Subnet1.
- D. Add the network interfaces of the virtual machines to the backend pool of LB1.
- E. Add health probes to LB1.
- F. Associate a user-defined route to Subnet1.
Answer: A,D,E
Explanation:
Section: [none]
Explanation:
A: To allow the Load Balancer to monitor the status of your app, you use a health probe. The health probe dynamically adds or removes VMs from the Load Balancer rotation based on their response to health checks.
B: To distribute traffic to the VMs, a backend address pool contains the IP addresses of the virtual (NICs) connected to the Load Balancer.
D: A Load Balancer rule is used to define how traffic is distributed to the VMs. Only outbound traffic is allowed.
Reference: https://docs.microsoft.com/en-us/azure/load-balancer/tutorial-load-balancer-standard-manage- portal
NEW QUESTION 61
You play to deploy an Azure virtual machine named VM1 by using an Azure Resource Manager template.
You need to complete the template.
What should you include in the template? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:

References:
https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-manager-tutorial-create-templates-with-dependent-resources
NEW QUESTION 62
You have SQL Server on an Azure virtual machine named SQL1.
You need to automate the backup of the databases on SQL1 by using Automated Backup v2 for the virtual machines. The backups must meet the following requirements:
* Meet a recovery point objective (RPO) of 15 minutes.
* Retain the backups for 30 days.
* Encrypt the backups at rest.
What should you provision as part of the backup solution?
- A. Azure Key Vault
- B. an Azure Storage account
- C. Elastic Database jobs
- D. a Recovery Services vault
Answer: A
NEW QUESTION 63
......
AZ-303 Exam Dumps PDF Guaranteed Success with Accurate & Updated Questions: https://www.vcetorrent.com/AZ-303-valid-vce-torrent.html