- 1
You need to ensure that a user can manage virtual machines in a specific resource group but cannot modify any other resources in the subscription. What should you do?
Show answer
Answer: C
Virtual Machine Contributor scoped to the resource group gives exactly the permissions needed — manage VMs in that group only. Subscription-level Contributor is too broad. Owner is too permissive (includes role assignment). Global Administrator is an Azure AD role, not an Azure RBAC role.
- 2 Select all that apply
Which TWO of the following are required when creating a new Azure virtual network? (Select two.)
Show answer
Answer: B, D
Every virtual network requires an address space (e.g. 10.0.0.0/16) and at least one subnet. NSGs, VPN gateways, and public IPs are optional and can be added later as needed.
- 3
A company has a storage account containing sensitive financial data. They need to ensure that all data written to this account is automatically encrypted at rest. What should they configure?
Show answer
Answer: A
Azure Storage Service Encryption (SSE) encrypts all data at rest by default using Microsoft-managed keys. No action is required to enable it. You can optionally switch to customer-managed keys via Key Vault for greater control, but the default already meets the requirement. HTTPS-only protects data in transit, not at rest.
- 4
You need to allow traffic from the internet to reach a web server running on an Azure VM on port 443. The VM is in a subnet with a network security group attached. What should you create?
Show answer
Answer: D
NSGs filter traffic using security rules. An inbound rule allowing TCP 443 from the internet (source: Internet or Any) permits HTTPS traffic to reach the VM. A user-defined route changes routing behaviour. A service endpoint secures access to PaaS services. Application security groups help group VMs logically within NSG rules but don't create the allow rule themselves.
- 5
Azure RBAC role assignments are inherited from parent scopes. A role assigned at the subscription level applies to all resource groups and resources within that subscription.
Show answer
Answer: A
RBAC uses scope inheritance. A role assigned at a management group flows down to subscriptions, then to resource groups, then to individual resources. This is why you should assign roles at the narrowest scope necessary — assigning Contributor at the subscription level gives access to every resource group and resource in it.
- 6
You have a Linux VM in Azure that is running out of disk space on its OS disk. You need to increase the disk size with minimal downtime. What should you do?
Show answer
Answer: B
To resize an OS disk, you must first stop (deallocate) the VM. Then you can increase the disk size through the portal, CLI, or PowerShell. After restarting, you may need to expand the partition within the OS. You cannot shrink a disk — only increase it. The temporary disk is ephemeral and not suitable for persistent data.
- 7 Select all that apply
Which THREE of the following can be configured as sources or destinations in a network security group rule? (Select three.)
Show answer
Answer: A, C, E
NSG rules support IP addresses/CIDR ranges, application security groups (logical groupings of VMs), and service tags (predefined labels like Internet, AzureLoadBalancer, VirtualNetwork). Azure AD groups and subscription IDs cannot be used in NSG rules — RBAC and NSGs are separate systems.
- 8
An administrator needs to run a script that creates 50 Azure resources. The script should be idempotent — running it multiple times should produce the same result. Which approach is most appropriate?
Show answer
Answer: C
ARM templates and Bicep are declarative and idempotent by design — you define the desired state and Azure ensures it matches, whether you run the deployment once or ten times. Imperative CLI or PowerShell scripts would need custom logic to check for existing resources before creating them. The portal is manual and not repeatable.
- 9
You need to copy a large number of files from an on-premises file server to Azure Blob Storage. The files total 2 TB and you need the transfer to be as fast as possible. Which tool should you use?
Show answer
Answer: B
AzCopy is a command-line tool optimised for high-performance bulk transfers to and from Azure Storage. It supports parallel transfers, resumable copies, and can saturate your network bandwidth. Storage Explorer uses AzCopy under the hood but adds GUI overhead. Portal upload is impractical for 2 TB. File Sync is designed for ongoing synchronisation, not one-time bulk migration.
- 10
A storage account needs to be accessible only from VMs within a specific virtual network. All other access, including from the internet, must be blocked. What should you configure?
Show answer
Answer: D
The storage account firewall lets you restrict access to specific virtual networks via service endpoints or private endpoints, and set the default action to Deny. This blocks all access except from the allowed networks. SAS tokens can restrict by IP but don't block the public endpoint entirely. HTTPS-only and Azure AD authentication don't control network access.
- 11 Put these in order
Place the following steps in the correct order to configure Azure AD Multi-Factor Authentication for a group of users.
Show answer
Correct order
- C Verify that users are registered for MFA methods in their security info
- A Create a Conditional Access policy targeting the user group
- D Set the policy to require multi-factor authentication as a grant control
- B Test by signing in as a member of the group and completing the MFA prompt
First ensure users have registered MFA methods (otherwise they'll be locked out). Then create the Conditional Access policy, configure it to require MFA as a grant control, and finally test with a member of the targeted group.
- 12
You need to monitor the CPU usage of all VMs in a resource group and receive an email when any VM exceeds 90% CPU for more than 5 minutes. What should you use?
Show answer
Answer: A
Azure Monitor alert rules let you set metric-based conditions (e.g. CPU > 90% for 5 minutes) scoped to a resource group, and trigger actions like sending email via an action group. Advisor gives recommendations, not real-time alerts. Service Health tracks Azure platform issues. Activity log alerts trigger on management operations (create, delete), not performance metrics.
- 13 Select all that apply
Which TWO of the following are valid Azure Blob Storage access tiers? (Select two.)
Show answer
Answer: B, D
Azure Blob Storage has three access tiers: Hot (frequent access, higher storage cost, lower access cost), Cool (infrequent access, lower storage cost, higher access cost), and Archive (rare access, lowest storage cost, highest retrieval cost and latency). "Standard" and "Premium" describe performance tiers of the storage account, not blob access tiers. "Warm" is not an Azure tier.
- 14
An Azure network security group can be associated with a virtual network.
Show answer
Answer: B
NSGs can be associated with subnets or individual network interfaces — not with the virtual network itself. To apply an NSG to all traffic in a VNet, you must associate it with each subnet within that VNet.
- 15
You manage a web application running on Azure App Service. You need to configure the app to automatically scale from 2 to 10 instances when the average CPU usage exceeds 70%. What should you configure?
Show answer
Answer: C
Scale out (horizontal scaling) adds more instances of your app. An autoscale rule on the App Service plan triggers this based on metrics like CPU usage. Scale up (vertical scaling) increases the size of each instance but doesn't add more. Load Balancer and Traffic Manager distribute traffic but don't control instance count.
- 16
You need to give a third-party application temporary read access to a specific container in Azure Blob Storage. The access should expire after 24 hours and should not require sharing the storage account keys. What should you use?
Show answer
Answer: A
A SAS token provides time-limited, scoped access to specific resources without exposing the account keys. You can restrict it to a single container, set it to read-only, and set a 24-hour expiry. Sharing account keys gives full access. Azure AD roles and managed identities are better for long-term access from trusted applications, not temporary third-party access.
- 17
You are troubleshooting connectivity between two VMs in different Azure virtual networks. The VMs cannot communicate. What is the most likely missing configuration?
Show answer
Answer: D
By default, Azure virtual networks are isolated — VMs in different VNets cannot communicate. Virtual network peering connects two VNets and allows traffic to flow between them. Public IPs would allow internet communication but not private VNet-to-VNet traffic. NSG rules could block traffic, but without peering there is no path for traffic at all. Different Azure AD tenants don't prevent network connectivity.
- 18 Select all that apply
Which TWO of the following tasks require the Owner role and cannot be performed with the Contributor role? (Select two.)
Show answer
Answer: A, D
The key difference between Owner and Contributor is that Owner can manage access (assign RBAC roles) and manage policy, while Contributor cannot. Both roles can create, modify, and delete resources like VMs, resource groups, and ARM deployments.
- 19
You need to ensure that no one in your organisation can create virtual machines larger than Standard_D4s_v3 in a specific subscription. What should you use?
Show answer
Answer: B
Azure Policy enforces rules across resources — you can create a policy that restricts allowed VM sizes to specific SKUs. This prevents anyone from deploying non-compliant VMs, regardless of their RBAC role. RBAC controls who can do what, but cannot restrict which SKU sizes are used. Advisor makes recommendations but doesn't enforce them.
- 20 Put these in order
Place the following steps in the correct order to configure a site-to-site VPN connection between an on-premises network and an Azure virtual network.
Show answer
Correct order
- D Create a gateway subnet in the Azure virtual network
- B Create the virtual network gateway in Azure
- A Create the VPN connection and provide the shared key
- C Verify the connection status shows as Connected
First create a dedicated gateway subnet (must be named GatewaySubnet) in the VNet. Then create the virtual network gateway, which deploys into that subnet (this takes 20-45 minutes). Then create the connection resource linking the Azure gateway to the on-premises local network gateway using a shared key. Finally verify the connection status.