2026 New AZ-102 Exam Dumps with PDF and VCE Free: https://www.2passeasy.com/dumps/AZ-102/

Act now and download your AZ-102 Braindumps today! Do not waste time for the worthless AZ-102 Exam Questions and Answers tutorials. Download AZ-102 Exam Questions and Answers with real questions and answers and begin to learn AZ-102 Exam Questions and Answers with a classic professional.

Free AZ-102 Demo Online For Microsoft Certifitcation:

NEW QUESTION 1
You plan to connect a virtual network named VNET1017 to your on-premises network by using both an Azure ExpressRoute and a site-to-site VPN connection.
You need to prepare the Azure environment for the planned deployment. The solution must maximize the IP address space available to Azure virtual machines.
What should you do from the Azure portal before you create the ExpressRoute are the VPN gateway?

    Answer:

    Explanation: We need to create a Gateway subnet Step 1:
    Go to More Services > Virtual Networks Step 2:
    Then click on the VNET1017, and click on subnets. Then click on gateway subnet.
    Step 3:
    In the next window define the subnet for the gateway and click OK
    AZ-102 dumps exhibit
    It is recommended to use /28 or /27 for gateway subnet.
    As we want to maximize the IP address space we should use /27. References:
    https://blogs.technet.microsoft.com/canitpro/2021/06/28/step-by-step-configuring-a-site-to-sitevpn- gateway-between-azure-and-on-premise/

    NEW QUESTION 2
    You are troubleshooting a performance issue for an Azure Application Gateway. You need to compare the total requests to the failed requests during the past six hours. What should you use?

    • A. Metrics in Application Gateway
    • B. Diagnostics logs in Application Gateway
    • C. NSG flow logs in Azure Network Watcher
    • D. Connection monitor in Azure Network Watcher

    Answer: A

    Explanation: Application Gateway currently has seven metrics to view performance counters.
    Metrics are a feature for certain Azure resources where you can view performance counters in the portal. For Application Gateway, the following metrics are available: Total Requests
    Failed Requests Current Connections Healthy Host Count Response Status Throughput Unhealthy Host count
    You can filter on a per backend pool basis to show healthy/unhealthy hosts in a specific backend pool References: https://docs.microsoft.com/en-us/azure/application-gateway/applicationgatewaydiagnostics# Metrics

    NEW QUESTION 3
    You have an Azure subscription that contains the resources in the following table.
    AZ-102 dumps exhibit
    Store1 contains a file share named Data. Data contains 5,000 files.
    You need to synchronize the files in Data to an on-premises server named Server1.
    Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

    • A. Download an automation script.
    • B. Create a container instance.
    • C. Create a sync group.
    • D. Register Server1.
    • E. Install the Azure File Sync agent on Server1.

    Answer: CDE

    Explanation: Step 1 (E): Install the Azure File Sync agent on Server1
    The Azure File Sync agent is a downloadable package that enables Windows Server to be synced with an Azure file share
    Step 2 (D): Register Server1.
    Register Windows Server with Storage Sync Service
    Registering your Windows Server with a Storage Sync Service establishes a trust relationship between your server (or cluster) and the Storage Sync Service.
    Step 3 (C): Create a sync group and a cloud endpoint.
    A sync group defines the sync topology for a set of files. Endpoints within a sync group are kept in sync with each other. A sync group must contain one cloud endpoint, which represents an Azure file share and one or more server endpoints. A server endpoint represents a path on registered server. References: https://docs.microsoft.com/en-us/azure/storage/files/storage-sync-files-deploymentguide

    NEW QUESTION 4
    Another administrator reports that she is unable to configure a web app named corplod7509086n3 to prevent all connections from an IP address of 11.0.0.11.
    You need to modify corplod7509086n3 to successfully prevent the connections from the IP address. The solution must minimize Azure-related costs.
    What should you do from the Azure portal?

      Answer:

      Explanation: Step 1:
      Find and select application corplod7509086n3:
      1. In the Azure portal, on the left navigation panel, click Azure Active Directory.
      2. In the Azure Active Directory blade, click Enterprise applications. Step 2:
      To add an IP restriction rule to your app, use the menu to open Network>IP Restrictions and click on Configure IP Restrictions
      AZ-102 dumps exhibit
      Step 3:
      Click Add rule
      You can click on [+] Add to add a new IP restriction rule. Once you add a rule, it will become effective immediately.
      AZ-102 dumps exhibit
      Step 4:
      Add name, IP address of 11.0.0.11, select Deny, and click Add Rule
      AZ-102 dumps exhibit
      References:
      https://docs.microsoft.com/en-us/azure/app-service/app-service-ip-restrictions

      NEW QUESTION 5
      You plan to deploy an application getaway named appgw1015 to load balance IP traffic to the Azure virtual machines connected to subnet0.
      You need to configure a virtual network named VNET1015 to support the planned application gateway.
      What should you do from the Azure portal?

        Answer:

        Explanation: Step 1:
        Click Networking, Virtual Network, and select VNET1015. Step 2:
        Click Subnets, and Click +Add on the VNET1015 - Subnets pane that appears. Step 3:
        On the Subnets page, click +Gateway subnet at the top to open the Add subnet page.
        AZ-102 dumps exhibit
        Step 4:
        Locate subnet0 and add it. References:
        https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-site-to-site-resourcemanager- portal

        NEW QUESTION 6
        You need to prepare the environment to meet the authentication requirements.
        Which two actions should you perform? Each correct answer presents part of the solution. NOTE Each correct selection is worth one point.

        • A. Azure Active Directory (AD) Identity Protection and an Azure policy
        • B. a Recovery Services vault and a backup policy
        • C. an Azure Key Vault and an access policy
        • D. an Azure Storage account and an access policy

        Answer: BD

        Explanation: D: Seamless SSO works with any method of cloud authentication - Password Hash Synchronization or Pass-through Authentication, and can be enabled via Azure AD Connect.
        B: You can gradually roll out Seamless SSO to your users. You start by adding the following Azure AD URL to all or selected users' Intranet zone settings by using Group Policy in Active Directory: https://autologon.microsoftazuread-sso.com
        Incorrect Answers:
        A: Seamless SSO needs the user's device to be domain-joined, but doesn't need for the device to be Azure AD Joined.
        C: Azure AD connect does not port 8080. It uses port 443.
        E: Seamless SSO is not applicable to Active Directory Federation Services (ADFS).
        Scenario: Users in the Miami office must use Azure Active Directory Seamless Single Sign-on (Azure AD Seamless SSO) when accessing resources in Azure.
        Planned Azure AD Infrastructure include: The on-premises Active Directory domain will be synchronized to Azure AD.
        References: https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directoryaadconnect-sso-quick-start

        NEW QUESTION 7
        DRAG DROP
        You need to prepare the New York office infrastructure for the migration of the on-premises virtual machines to Azure.
        Which four actions you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
        AZ-102 dumps exhibit

          Answer:

          Explanation: Box 1:
          From the Azure portal, download the OVF file.
          In the vCenter Server, import the Collector appliance as a virtual machine using the Deploy OVF Template wizard.
          In vSphere Client console, click File > Deploy OVF Template.
          In the Deploy OVF Template Wizard > Source, specify the location for the .ovf file. Box 2: From VM1, connect to the collector virtual machine
          After you've created the Collector virtual machine, connect to it and run the Collector. Box 3: From the ASRV1 blade in the Azure portal, select a protection goal.
          Box 4: From VM1, register the configuration server. Register the configuration server in the vault
          Scenario: The Azure infrastructure and the on-premises infrastructure and the on-premises infrastructure must be prepared for the migration of the VMware virtual machines to Azure. References:
          Migrate Your Virtual Machines to Microsoft Azure, Includes guidance for optional data migration, Proof of Concept guide, September 2021 https://azuremigrate.blob.core.windows.net/publicpreview/Azure%20Migrate%20-
          %20Preview%20User%20Guide.pdf

          NEW QUESTION 8
          You create an Azure subscription that is associated to a basic Azure Active Directory (Azure AD) tenant. You need to receive an email notification when any user activates an administrative role. What should you do?

          • A. Purchase Azure AD Premium 92 and configure Azure AD Privileged Identity Management,
          • B. Purchase Enterprise Mobility + Security E3 and configure conditional access policies.
          • C. Purchase Enterprise Mobility + Security E5 and create a custom alert rule in Azure Security Center.
          • D. Purchase Azure AD Premium PI and enable Azure AD Identity Protectio

          Answer: A

          Explanation: When key events occur in Azure AD Privileged Identity Management (PIM), email notifications are sent. For example, PIM sends emails for the following events:
          When a privileged role activation is pending approval When a privileged role activation request is completed When a privileged role is activated
          When a privileged role is assigned When Azure AD PIM is enabled References:
          https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pimemail- notifications

          NEW QUESTION 9
          You need to recommend a solution to automate the configuration for the finance department users. The solution must meet the technical requirements.
          What should you include in the recommended?

          • A. Azure AP B2C
          • B. Azure AD Identity Protection
          • C. an Azure logic app and the Microsoft Identity Management (MIM) client
          • D. dynamic groups and conditional access policies

          Answer: D

          Explanation: Scenario: Ensure Azure Multi-Factor Authentication (MFA) for the users in the finance department only.
          The recommendation is to use conditional access policies that can then be targeted to groups of users, specific applications, or other conditions.
          References:
          https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-userstates

          NEW QUESTION 10
          You have a public load balancer that balancer ports 80 and 443 across three virtual machines. You need to direct all the Remote Desktop protocol (RDP) to VM3 only.
          What should you configure?

          • A. an inbound NAT rule
          • B. a load public balancing rule
          • C. a new public load balancer for VM3
          • D. a new IP configuration

          Answer: A

          Explanation: To port forward traffic to a specific port on specific VMs use an inbound network address translation (NAT) rule.
          Incorrect Answers:
          B: Load-balancing rule to distribute traffic that arrives at frontend to backend pool instances. References:
          https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-overview

          NEW QUESTION 11
          Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
          After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
          You manage a virtual network named VNet1 that is hosted in the West US Azure region. VNet1 hosts two virtual machines named VM1 and VM2 that run Windows Server.
          You need to inspect all the network traffic from VM1 to VM2 for a period of three hours. Solution: From Azure Monitor, you create a metric on Network In and Network Out. Does this meet the goal?

          • A. Yes
          • B. No

          Answer: B

          Explanation: You should use Azure Network Watcher. References:
          https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-monitoring-overview Case Study: 5

          Mix Questions Set B (Implement advanced networking)

          NEW QUESTION 12
          You have an Azure Service Bus.
          You need to implement a Service Bus queue that guarantees first in first-out (FIFO) delivery of messages.
          What should you do?

          • A. Set the Lock Duration setting to 10 seconds.
          • B. Enable duplicate detection.
          • C. Set the Max Size setting of the queue to 5 GB.
          • D. Enable partitioning.
          • E. Enable session

          Answer: E

          Explanation: Through the use of messaging sessions you can guarantee ordering of messages, that is first-in-firstout (FIFO) delivery of messages.
          References:
          https://docs.microsoft.com/en-us/azure/service-bus-messaging/service-bus-azure-and-service-busqueues- compared-contrasted

          NEW QUESTION 13
          You have an on-premises network that contains a Hyper-V host named Host1. Host1 runs Windows Server 2021 and hosts 10 virtual machines that run Windows Server 2021.
          You plan to replicate the virtual machines to Azure by using Azure Site Recovery. You create a Recovery Services vault named ASR1 and a Hyper-V site named Site1. You need to add Host1 to ASR1.
          What should you do?

          • A. Download the installation file for the Azure Site Recovery Provide
          • B. Download the vault registration key.Install the Azure Site Recovery Provider on Host1 and register the server.
          • C. Download the installation file for the Azure Site Recovery Provide
          • D. Download the storage account key.Install the Azure Site Recovery Provider on Host1 and register the server.
          • E. Download the installation file for the Azure Site Recovery Provide
          • F. Download the vault registration key.Install the Azure Site Recovery Provider on each virtual machine and register the virtual machines.
          • G. Download the installation file for the Azure Site Recovery Provide
          • H. Download the storage account key.Install the Azure Site Recovery Provider on each virtual machine and register the virtual machine

          Answer: A

          Explanation: Download the Vault registration key. You need this when you install the Provider. The key is valid for five days after you generate it.
          Install the Provider on each VMM server. You don't need to explicitly install anything on Hyper-V hosts.
          Incorrect Answers:
          B, D: Use the Vault Registration Key, not the storage account key. References:
          https://docs.microsoft.com/en-us/azure/site-recovery/migrate-tutorial-on-premises-azure

          NEW QUESTION 14
          You plan to automate the deployment of a virtual machine scale set that uses the Windows Server 2021 Datacenter image.
          You need to ensure that when the scale set virtual machines are provisioned, they have web server components installed.
          Which two actions should you perform? Each correct answer presents part of the solution. NOTE Each correct selection is worth one point.

          • A. Modify the extensionProfile section of the Azure Resource Manager template.
          • B. Create a new virtual machine scale set in the Azure portal.
          • C. Create an Azure policy.
          • D. Create an automation account.
          • E. Upload a configuration scrip

          Answer: AB

          Explanation: Virtual Machine Scale Sets can be used with the Azure Desired State Configuration (DSC) extension handler. Virtual machine scale sets provide a way to deploy and manage large numbers of virtual machines, and can elastically scale in and out in response to load. DSC is used to configure the VMs as they come online so they are running the production software.
          References: https://docs.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machinescale- sets-dsc

          NEW QUESTION 15
          You have an Azure Active Directory (Azure AD) domain that contains 5,000 user accounts. You create a new user account named AdminUser1.
          You need to assign the User administrator administrative role to AdminUser1. What should you do from the user account properties?

          • A. From the Directory role blade, modify the directory role.
          • B. From the Groups blade, invite the user account to a new group.
          • C. From the Licenses blade, assign a new licens

          Answer: A

          Explanation: Assign a role to a user
          Sign in to the Azure portal with an account that's a global admin or privileged role admin for the directory.
          Select Azure Active Directory, select Users, and then select a specific user from the list.
          For the selected user, select Directory role, select Add role, and then pick the appropriate admin roles from the Directory roles list, such as Conditional access administrator.
          Press Select to save.
          References: https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/activedirectory-users-assign-role-azure-portal

          NEW QUESTION 16
          HOT SPOT
          You have an Azure subscription named Subscription1. Subscription1 contains the virtual networks in the following table.
          AZ-102 dumps exhibit
          Subscription1 contains the virtual machines in the following table:
          AZ-102 dumps exhibit
          The firewalls on all the virtual machines are configured to allow all ICMP traffic. You add the peerings in the following table.
          AZ-102 dumps exhibit
          For each of the following statements, select Yest if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
          AZ-102 dumps exhibit

            Answer:

            Explanation: Box 1: Yes
            Vnet1 and Vnet3 are peers. Box 2: Yes
            Vnet2 and Vnet3 are peers. Box 3: No
            Peering connections are non-transitive.
            References: https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/hybridnetworking/ hub-spoke

            NEW QUESTION 17
            You need to define a custom domain name for Azure AD to support the planned infrastructure. Which domain name should you use?

            • A. ad.humongousinsurance.com
            • B. humongousinsurance.onmicrosoft.com
            • C. humongousinsurance.local
            • D. humongousinsurance.com

            Answer: D

            Explanation: Every Azure AD directory comes with an initial domain name in the form of domainname.onmicrosoft.com. The initial domain name cannot be changed or deleted, but you can add your corporate domain name to Azure AD as well. For example, your organization probably has other domain names used to do business and users who sign in using your corporate domain name. Adding custom domain names to Azure AD allows you to assign user names in the directory that are familiar to your users, such as ‘alice@contoso.com.’ instead of 'alice@domain name.onmicrosoft.com'.
            Scenario:
            Network Infrastructure: Each office has a local data center that contains all the servers for that office. Each office has a dedicated connection to the Internet.
            Humongous Insurance has a single-domain Active Directory forest named humongousinsurance.com Planned Azure AD Infrastructure: The on-premises Active Directory domain will be synchronized to Azure AD.
            References: https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/add-customdomain

            Recommend!! Get the Full AZ-102 dumps in VCE and PDF From Dumpscollection, Welcome to Download: http://www.dumpscollection.net/dumps/AZ-102/ (New 195 Q&As Version)