AZ-104 practice questions
Microsoft · AZ-104 · 200 questions
Original practice questions for the Microsoft Certified: Azure Administrator Associate (AZ-104) exam, covering Azure identities and governance (Entra ID, RBAC, subscriptions, policy), storage (accounts, access tiers, redundancy, Azure Files and Blob), compute (virtual machines, availability sets and zones, scale sets, App Service, containers), virtual networking (VNets, peering, NSGs, load balancing, name resolution) and monitoring and maintenance (Azure Monitor, alerts, Backup and Site Recovery) — framed inside a regional airline running departure-control systems, crew scheduling, maintenance telemetry and airport-lounge services across several hub regions.
This course contains the use of artificial intelligence.
About the AZ-104 exam
- Time allowed
- 1 hour 40 minutes
- Passing score
- 700 (Microsoft states "a score of 700 or greater is required to pass"; exact scale, e.g. 1-1000, is not stated on the fetched page)
- Languages
- English, Chinese (Simplified), Korean, Japanese, French, Spanish, German, Portuguese (Brazil), Chinese (Traditional), Italian
- Format
- Proctored exam; may include interactive components. Assessed on 5 skill areas: Manage Azure identities and governance (20-25%), Implement and manage storage (15-20%), Deploy and manage Azure compute resources (20-25%), Implement and manage virtual networking (15-20%), Monitor and maintain Azure resources (10-15%)
Schedule this exam The certification this earns
Exam details published by the vendor, checked 28 August 2026. Vendors change fees and formats without notice — confirm on the vendor's own page before you book.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Browse by Domain
Study specific topics at your own pace.
Manage Azure identities and governance · 40 questions
- Cascade Regional Airlines is onboarding 40 new gate agents at once ahead of a schedule expansion. The identity admin has a CSV with each agent's display name, user principal name, and department, and wants to create all the accounts in Microsoft Entra ID without opening the portal 40 times. Which approach should the admin use?
- A maintenance-records application at Cascade Regional Airlines needs a small team of mechanics and one external auditor from a certified inspection firm to co-edit a shared document library and receive a group mailbox for coordination emails. Which type of group best fits this need?
- Cascade Regional Airlines reorganizes its workforce so that every employee's department attribute in Microsoft Entra ID is kept accurate by HR. The identity admin wants a group of all Flight Operations employees to update itself automatically as people transfer in and out, without anyone manually adding or removing members. What should the admin configure?
- A service desk lead at Cascade Regional Airlines is designing self-service password reset (SSPR) for outstation employees so they can regain access to their accounts without calling the help desk after hours. Before enabling SSPR, what must the lead configure so users actually have a way to verify their identity during a reset?
- Cascade Regional Airlines runs a hybrid identity environment where employee accounts are synchronized from on-premises Active Directory to Microsoft Entra ID using Microsoft Entra Connect. The compliance officer wants an employee's self-service password reset in the cloud to also update their on-premises AD password, so a single password works everywhere. What must be enabled for this to work?
- Cascade Regional Airlines has a regional IT team responsible only for the accounts and devices at its three outstation offices, and must not be able to touch HQ or maintenance-base resources. The identity admin wants to delegate a limited set of administrative permissions scoped strictly to the outstation users and groups. What Microsoft Entra ID feature should the admin use?
- Cascade Regional Airlines just purchased Microsoft 365 E3 licenses for 200 new flight-planning staff. Rather than assigning a license to each user account individually, the identity admin wants new hires to automatically receive the correct license the moment they're added to the Flight Planning security group. Which licensing approach accomplishes this?
- Cascade Regional Airlines wants to require multi-factor authentication for all sign-ins to its crew-scheduling app using a conditional access policy, and also wants risk-based sign-in policies that automatically challenge users when Microsoft detects unusual sign-in behavior. Which Microsoft Entra ID licensing tier is the minimum needed to build these conditional access and risk-based policies?
- A contractor from an external staffing agency needs temporary access to Cascade Regional Airlines' shared maintenance-scheduling document library for a six-week engagement, but should never receive a company email mailbox or a full employee identity. What is the appropriate way to grant this access in Microsoft Entra ID?
- Cascade Regional Airlines equips its check-in kiosks with company-owned tablets that must be automatically enrolled in mobile device management and fully controlled by IT, with no personal Microsoft account ever touching them. Which Microsoft Entra device state matches this scenario?
- Cascade Regional Airlines' HQ desktops have been domain-joined to on-premises Active Directory for years, and the identity admin now wants those same machines to also register with Microsoft Entra ID so users can access cloud apps with conditional access enforced, without a disruptive re-image of every machine. What device join type describes the end state?
- During a bulk import of 60 new ramp-agent accounts, Cascade Regional Airlines' identity admin uploads a CSV to the Microsoft Entra ID bulk create tool, but the job reports that 5 rows failed while 55 succeeded. What should the admin do to identify exactly what went wrong with those 5 rows?
- Cascade Regional Airlines wants a Microsoft Entra ID group that automatically contains every corporate laptop enrolled through the company's device management program, so a security baseline policy can target exactly those machines without anyone manually adding devices. What should the identity admin configure?
- Cascade Regional Airlines' service desk lead is configuring self-service password reset policy and wants to require that a user register at least two different authentication methods, and that both methods be used together when performing a reset, for stronger assurance. Where is this requirement configured?
- Cascade Regional Airlines' compliance officer discovers that an administrative unit scoped to the outstation offices was assigned the Helpdesk Administrator role to a regional technician, but the technician is still able to reset the password of a HQ pilot's account, which should be out of scope. What is the most likely explanation for this scope violation?
- Cascade Regional Airlines wants every guest user invited from the external staffing agency to automatically land in a single review group so the compliance team can periodically audit all external access in one place, without anyone manually remembering to add each new guest. What should the identity admin configure?
- Cascade Regional Airlines assigns a Microsoft 365 E3 license to its Ground Operations security group using group-based licensing, but the identity admin notices the group has run out of available licenses in the pool, so several new members show a licensing error instead of receiving the license. What is the most appropriate way to resolve this?
- Cascade Regional Airlines' crew-scheduling application requires that only devices enrolled and marked compliant through device management can sign in, and the identity admin wants a conditional access policy to enforce this. Which Microsoft Entra ID device state must a device be in for a compliance status to exist and be evaluated by that policy?
- Cascade Regional Airlines' identity admin needs Privileged Identity Management to require just-in-time activation, approval workflows, and time-bound elevation for administrative roles, rather than granting those roles as permanent, always-on assignments. Which Microsoft Entra ID licensing tier is required to use Privileged Identity Management?
- Cascade Regional Airlines' cloud administrator is auditing external access and finds that the tenant's external collaboration settings allow any employee to invite guests from any domain with no restrictions, which the compliance officer considers too permissive for an airline handling sensitive maintenance data. What should the administrator do to tighten this while still allowing legitimate B2B collaboration?
- Cascade Regional Airlines' cloud administrator assigns the Contributor role to the maintenance-records support team at the resource group scope that holds their virtual machines and storage account. A new storage account is then created in a different resource group in the same subscription. What can the maintenance-records team do with the new storage account?
- Support engineers on Cascade Regional Airlines' crew-scheduling application need to restart the app's underlying App Service and read its diagnostic logs, but the built-in Contributor role also lets them delete the resource, and the built-in Reader role cannot perform the restart. What should the subscription owner do to give the engineers exactly the access they need?
- A FinOps analyst at Cascade Regional Airlines needs to stop virtual machines from ever being created with unapproved SKUs at the outstation offices, before the deployment can complete. Which Azure Policy effect accomplishes this?
- A compliance officer at Cascade Regional Airlines must apply a consistent bundle of about fifteen related governance policies, covering tagging, allowed regions, and allowed VM SKUs, to every current and future outstation-office subscription. What is the most efficient way to do this?
- Cascade Regional Airlines' cloud administrator holds the Owner role on the maintenance-records resource group and applies a CanNotDelete resource lock to protect its production database from accidental removal. Later, the same administrator attempts to delete the entire resource group. What happens?
- Cascade Regional Airlines is reorganizing its management group hierarchy and moves the Kiosk-Ops subscription out of the Corporate management group and into the Outstations management group, which carries stricter Azure Policy assignments. What is the immediate effect on resources in the Kiosk-Ops subscription?
- A FinOps analyst at Cascade Regional Airlines configures a monthly Cost Management budget with an alert set to fire at 90% of the cap for the crew-scheduling subscription, notifying stakeholders by email as spend approaches the limit. If actual spend exceeds the budget, what happens to further resource deployments in that subscription?
- A helpdesk technician at Cascade Regional Airlines needs the ability to reset passwords for user accounts belonging to the airport kiosk fleet support staff in Microsoft Entra ID. Which type of role should the cloud administrator assign?
- A compliance officer at Cascade Regional Airlines wants every resource created at outstation offices to be tagged with the correct cost-center value automatically, rather than relying on staff to remember and finance correcting mistakes after the fact. What should the compliance officer configure?
- Cascade Regional Airlines' subscription owner assigns an Azure Policy with the DeployIfNotExists effect requiring diagnostic settings on all maintenance-records storage accounts. Storage accounts created before the assignment now show as non-compliant. Without recreating them, how can the owner bring the existing accounts into compliance?
- At Cascade Regional Airlines, a cloud administrator is assigned the Reader role at the management group level and separately assigned the Contributor role directly at the maintenance-records resource group beneath that management group. What is the administrator's effective permission on resources inside the maintenance-records resource group?
- A FinOps analyst at Cascade Regional Airlines moves several virtual machines from the Kiosk-Pilot resource group into the Kiosk-Prod resource group within the same subscription. What should the analyst expect regarding any RBAC role assignments that were scoped directly to Kiosk-Pilot?
- A compliance officer at Cascade Regional Airlines applies a ReadOnly resource lock to the crew-scheduling production App Service to preserve its configuration during an audit. A developer who holds the Contributor role then attempts to restart the App Service. What happens?
- A cloud administrator at Cascade Regional Airlines wants visibility into which outstation-office virtual machines are running on unapproved SKUs before deciding whether to fully enforce an approved-SKU standard, without disrupting any current operations. Which Azure Policy effect fits this goal?
- Cascade Regional Airlines' management group hierarchy has a single root management group, Cascade-Root, containing all current subscriptions for HQ, Outstations, and Kiosk-Ops. The subscription owner wants one "require approved regions" Azure Policy enforced across every current subscription and any subscription added in the future, using a single assignment. Where should the policy be assigned?
- A FinOps analyst at Cascade Regional Airlines has been asked to grant other engineers appropriate RBAC roles on the crew-scheduling resource group, but the analyst has no need to create, modify, or delete the resources themselves. Which built-in Azure role best matches this responsibility?
- A compliance officer at Cascade Regional Airlines applies a CanNotDelete resource lock at the subscription level covering the entire Outstations subscription. Can a resource group owner within that subscription, who holds the Owner role on just their own resource group, delete that resource group?
- Cascade Regional Airlines' cloud administrator wants a single Azure Policy initiative definition for "allowed locations," but HQ should only permit resources in one region while a separate outstation-office subscription should only permit resources in a different region. How can the administrator achieve this using one initiative definition?
- A subscription owner at Cascade Regional Airlines wants to track spending specifically for the maintenance-records resource group, separately from the rest of the spend happening elsewhere in the same subscription. How should the owner set this up in Cost Management?
- Cascade Regional Airlines' compliance officer wants the Kiosk-Ops subscription to inherit governance from both the Outstations management group and the Finance management group at the same time, and attempts to place Kiosk-Ops as a child of both. Is this possible in Azure's management group hierarchy?
Implement and manage storage · 40 questions
- Cascade Regional Airlines is provisioning a new storage account to hold high-throughput telemetry blobs streamed continuously from aircraft health-monitoring sensors during taxi and takeoff, where consistent low-latency writes matter more than cost? Which storage account configuration best fits this workload?
- A records-retention officer at Cascade Regional Airlines is planning where to archive ten years of decommissioned crew scheduling logs that must remain durable but will almost certainly never be read again? Which access tier minimizes ongoing storage cost for this scenario?
- An IT administrator at Cascade Regional Airlines discovers that maintenance photo blobs tiered to Archive six months ago now need to be reviewed urgently by an FAA auditor within the hour? What must happen before those specific blobs can be read?
- Cascade Regional Airlines stores flight-data recorder exports in a storage account and wants automatic cost optimization: files untouched for 30 days should move to Cool, and files untouched for 180 days should move to Archive, without any manual intervention? Which feature should the cloud team configure?
- A ground operations analyst needs to know which redundancy option keeps Cascade Regional Airlines' kiosk log data available for read access even during a regional outage that takes down the primary Azure region entirely? Which option should the analyst choose?
- Cascade Regional Airlines' compliance team requires that crew document scans survive the simultaneous loss of an entire Azure datacenter within the primary region, but a full cross-region failover is not required for this particular workload? Which redundancy option satisfies this requirement at the lowest cost?
- During a scheduled disaster-recovery test, Cascade Regional Airlines' cloud team wants to validate that a storage account configured with GRS can actually be made writable in the secondary region if the primary region were to fail permanently? What must the team initiate to make the secondary region primary?
- A DevOps engineer configuring backups for Cascade Regional Airlines' maintenance photo archive account needs the cheapest redundancy level that still protects against the loss of a single disk or server rack inside one datacenter? Which option meets that minimum bar?
- A compliance auditor asks Cascade Regional Airlines to prove that safety-incident report blobs cannot be modified or deleted, even accidentally by an administrator with full account access, for a mandatory five-year retention period? Which blob storage feature enforces this?
- An engineer accidentally overwrites a maintenance photo blob with a corrupted upload at Cascade Regional Airlines, and the storage account has blob versioning enabled? What is the correct way to recover the pre-corruption image?
- Cascade Regional Airlines wants a safety net so that if a support technician mistakenly deletes a crew document scan container, the deleted contents can be recovered within a defined window without needing versioning or a separate backup job? Which feature should be enabled?
- Legal counsel at Cascade Regional Airlines places a hold on a set of incident-investigation blobs pending litigation, requiring that they cannot be deleted or altered by anyone, with no expiration date, until legal explicitly releases the hold? Which immutability feature fits this open-ended requirement?
- A security architect reviewing Cascade Regional Airlines' storage design notes that flight-data recorder exports are encrypted at rest, but compliance now requires the airline itself to control and be able to revoke the encryption keys, rather than relying on keys Microsoft generates and manages? Which configuration satisfies this?
- Cascade Regional Airlines' network team wants a maintenance-records storage account reachable only from the airline's virtual network and from a short list of on-premises office IP ranges, with all other public internet traffic denied by default? Which storage account feature should be configured first?
- After locking down a storage account's firewall to deny all public network access, Cascade Regional Airlines' team notices that Azure Monitor diagnostic logs can no longer be written to the account, breaking an audit pipeline that a Microsoft-hosted service depends on? Which firewall setting should the team review?
- Cascade Regional Airlines locked down the network security group on the booking-tier subnet to deny all outbound traffic except to a handful of approved destinations, then discovered that VMs in that subnet can still reach a maintenance-records storage account whose public network access is left fully open. The network team wants a single control that governs whether the storage account itself accepts that traffic, independent of any subnet's NSG rules. What should they configure?
- Cascade Regional Airlines' finance team asks why last month's storage bill spiked after a batch of aircraft inspection photos, tiered to Cool for months, was suddenly accessed heavily by a new analytics job? What most directly explains this cost increase?
- A data analyst at Cascade Regional Airlines is deciding between the Cool and Cold access tiers for a set of quarterly maintenance summary reports expected to be accessed a handful of times per year but never truly abandoned? Which factor most directly distinguishes when Cold is preferable to Cool for this data?
- Cascade Regional Airlines' cloud team is choosing a storage account kind for a new workload that needs both blob storage for maintenance photos and table storage for structured inspection metadata, all under one account with the modern feature set including access tiers and lifecycle management? Which account kind should they choose?
- Cascade Regional Airlines' security team wants blobs newly uploaded to a maintenance-records container to be encrypted using a customer-managed key from the moment they are written, without requiring any application code changes on the upload path? Which statement about this requirement is accurate?
- Cascade Regional Airlines is bringing in an outside avionics inspection vendor to review photos of a recent landing-gear-door inspection stored in a single Blob container. Security wants the access credential tied to a specific Microsoft Entra ID identity rather than the storage account key, so it can be revoked by removing a role assignment instead of rotating keys. Which credential should IT issue to the vendor?
- Cascade's crew-records team stores scanned licensing and medical documents in a container named crew-doc-scans, separate from the flight-ops-logs container in the same storage account. A payroll auditor needs temporary read access to crew-doc-scans only, and must never be able to touch flight-ops-logs. Which SAS type satisfies this?
- A dispatch coordinator at Cascade needs to send a one-time download link for a single day's flight-release PDF to an outstation manager who will grab the file within the hour. The coordinator is about to generate a SAS token for the blob. What expiry setting best fits this task?
- An outstation office issued several SAS tokens against the same container to a rotating cast of ground-handling contractors over the past month. Security now wants the ability to instantly invalidate every one of those already-issued tokens at once, without rotating the storage account keys that other production apps depend on. What should have been used when the tokens were created?
- Cascade's central IT team wants to rotate the storage account access keys every quarter as a security best practice, but several internal applications are currently authenticated using key1. What rotation approach avoids an outage for those applications?
- A ground-handling contractor at an outstation needs to upload a batch of ramp-inspection photos into one virtual folder in a Blob container for a single afternoon. An IT technician suggests just giving the contractor the storage account access key since it's quick to hand over. Why is that the wrong call?
- Cascade is standing up a new flight-data ingestion service on Linux virtual machines at the hub, and the team needs the servers to mount an Azure file share using POSIX-style file permissions and Linux-native file locking, similar to how the existing Windows maintenance workstations mount their share over SMB. Which protocol should this new share use?
- Cascade's IT team is setting up an Azure file share to hold scanned aircraft maintenance logs that are only opened a handful of times per year, but whenever someone does need one, it must open instantly with no rehydration delay. Which share tier best fits this pattern?
- Cascade's crew-scheduling office wants each crew member's Azure Files SMB share access to be controlled by that individual's own domain credentials, with per-user, NTFS-style permissions on specific folders — not one shared secret handed to the whole team. What should IT enable on the storage account?
- Cascade wants a Windows file server at each outstation to keep local copies of shared operations documents in sync with a master copy in Azure and with the servers at every other outstation, so a document edited at one location eventually appears everywhere. What Azure File Sync construct ties all of these locations together?
- An outstation server in Cascade's Azure File Sync deployment only has 500 GB of local disk, but the cloud file share it's paired with holds several terabytes of historical documents. IT still wants every file to appear browsable in the local folder, without needing to expand the server's disk. What Azure File Sync feature accomplishes this?
- A new hire configuring Azure File Sync at Cascade is confused about which piece is which after a support ticket mentions both a 'server endpoint' and a 'cloud endpoint' inside the same sync group. Which statement correctly distinguishes the two?
- Cascade's IT team is migrating years of aircraft maintenance photo archives — several million files — from an aging on-premises NAS into Azure Blob storage overnight, and the job needs to resume automatically if the connection drops partway through. Which tool is purpose-built for this kind of high-throughput, resumable bulk transfer?
- A Cascade support engineer occasionally needs to browse a handful of Blob containers, spot-check whether a specific maintenance photo uploaded correctly, and adjust a container's public access level, all without writing a script. Which tool fits this ad hoc, visual task best?
- An outstation with only a slow, metered satellite internet link needs to move roughly 60 TB of historical aircraft maintenance video into Azure Blob storage as a one-time bulk transfer. Uploading over that link would take weeks and blow through the data cap. What Azure offering is designed for exactly this situation?
- Cascade's HQ storage account holds the crew-doc-scans container, and a regional office in another Azure region needs its own read-only copy of that container's contents kept continuously and automatically up to date, without triggering a full failover of the entire storage account. What feature should be configured?
- Before rolling out a schema change, a Cascade developer needs to copy a snapshot of one container's blobs from the Production storage account into a Staging storage account for testing — a one-off task, and the developer already has a command-line tool installed and is comfortable scripting it. What's the most direct way to accomplish the copy?
- A vendor's contract with Cascade Regional Airlines ended, so an administrator deleted the stored access policy that several outstanding SAS URLs referenced, and those URLs stopped working immediately. The URLs carried no expiry of their own — they took their permissions and expiry from the policy. Two weeks later a scripted container deployment re-creates a stored access policy on the same container using the same policy identifier. What happens to the vendor's old SAS URLs?
- Cascade's automation team is building a script that needs one single credential granting read and write access across both the Blob service and the File service in a storage account, rather than being scoped to one container or one service. Which SAS type is designed to span multiple storage services in a single token?
- Shortly after Cascade's central IT rotated a storage account's access keys, several outstation applications using recently issued service SAS tokens for a container suddenly began receiving authorization failures, while everything else kept working. What's the most likely cause, and what fixes it going forward?
Deploy and manage Azure compute resources · 60 questions
- Cascade Regional Airlines runs its crew-scheduling application on a General Purpose Azure VM. During the summer peak, the operations team wants to resize the VM to a larger size in the same series, but Azure reports the target size isn't available on the hardware cluster currently hosting the VM. What must happen for the resize to succeed?
- The maintenance-records database at Cascade Regional Airlines needs consistently sub-millisecond disk latency and independently configurable IOPS and throughput, separate from the disk's capacity. A junior engineer suggests attaching an Ultra Disk to the VM. What must also be true for that plan to work?
- Cascade Regional Airlines runs two crew-scheduling VMs that must keep serving dispatchers even if a single server rack loses power or a host reboots for maintenance inside the same Azure datacenter. Which deployment option is the correct fit for this specific failure scope?
- Before applying a risky patch to the managed OS disk of the maintenance-records VM, an engineer at Cascade Regional Airlines wants a quick point-in-time copy of the disk's current state that can be used to create a new disk and roll back if the patch goes wrong. What should the engineer create?
- Cascade Regional Airlines has fully configured a Windows VM for its crew-scheduling application and wants to capture it as a reusable image to deploy multiple fresh, identical instances at other regional hubs, each with its own computer name and security identifiers. What must the engineer do to the source VM before capturing the image?
- Cascade Regional Airlines wants to distribute its approved maintenance-records VM image to engineering teams in three separate subscriptions and two Azure regions, keep multiple versions available, and control who can use each version. A single managed image resource in one subscription can't do all of this. What should the airline use instead?
- After a new Windows VM for the maintenance-records app finishes provisioning at Cascade Regional Airlines, an engineer needs it to automatically download a configuration package and run an installer, without connecting over RDP to do it by hand. Which Azure feature is designed for running this kind of post-deployment script directly against the VM?
- An engineer at Cascade Regional Airlines is deploying a Linux VM to monitor seasonal booking-load spikes and wants it to install a monitoring agent and write a configuration file automatically the very first time it boots, using a standard, cloud-platform-agnostic method rather than an Azure-specific tool. Which approach fits this requirement?
- A dispatcher at a Cascade Regional Airlines regional hub shuts down a rarely-used reporting VM from inside the Windows guest OS instead of using the Azure portal's Stop button, then wonders why the compute charges keep appearing on the next invoice. Why does Azure keep billing for compute after this shutdown?
- A compliance auditor asks Cascade Regional Airlines to prove that the maintenance-records VM's OS disk is encrypted at rest, and separately asks whether the guest OS volume itself is encrypted from inside the operating system with a customer-managed key exposed to the OS. What is true about these two encryption layers on a managed disk?
- The maintenance-records VM's OS disk is nearly full from accumulated log files, and an engineer at Cascade Regional Airlines increases the managed disk's size from 128 GiB to 256 GiB through the Azure portal while the VM is still running. After the resize operation reports success, why does the OS still show the original, smaller volume size?
- Cascade Regional Airlines is choosing a VM series for its crew-scheduling database, which keeps a large working set of upcoming rosters cached in RAM and is far more sensitive to available memory than to raw CPU core count. Which category of VM series should the team favor for this workload?
- During disaster-recovery planning, a Cascade Regional Airlines architect reads that the airline's primary Azure region is paired with a specific secondary region, and asks what benefit that Microsoft-defined pairing itself actually provides, apart from whatever the airline configures on its own. What does the region-pair relationship provide?
- A bad configuration change corrupted the maintenance-records VM three days ago, and the airline has nightly Azure Backup recovery points stored in a Recovery Services vault. The team wants to keep the VM's existing resource ID and networking exactly as they are, but swap its disks back to the state from before the corruption. Which restore approach fits that goal?
- Cascade Regional Airlines keeps adding VMs to a single availability set to handle a growing booking-load monitoring fleet, well past the number of fault domains that availability set offers. What happens to the resiliency benefit as the VM count grows beyond the number of available fault domains?
- Cascade Regional Airlines attaches a data disk to a VM that only holds an infrequently-accessed archive of last season's booking-load reports, read a handful of times a month, where minimizing disk cost matters far more than IOPS or latency. Which managed disk type best fits this specific workload?
- A dispatcher accidentally deleted a single configuration file from the maintenance-records VM this morning. The VM itself is healthy and running fine, and Cascade Regional Airlines just needs that one file back from last night's Azure Backup recovery point, without disrupting the running VM or its other data. What is the appropriate restore approach?
- Cascade Regional Airlines wants the crew-scheduling application to survive the complete loss of one entire physical Azure datacenter within its primary region, not just a rack, while still keeping the app's VMs inside that same region for low-latency access to regional storage. What should the team deploy the VMs across?
- Six months after deploying a Linux VM for booking-load monitoring with a cloud-init configuration at first boot, an engineer at Cascade Regional Airlines now needs to push an updated script to that already-running VM to reconfigure the monitoring agent. Why is reapplying the original cloud-init configuration not the right tool for this later, on-demand change?
- To cut costs during the airline's slow off-season, Cascade Regional Airlines properly deallocates a seasonal booking-load-testing VM through the Azure portal rather than shutting it down from inside the guest OS. The finance team is then surprised to see any charge at all for that VM the following month. What is the correct explanation for the remaining charge?
- Cascade Regional Airlines is redesigning the scale set behind its public booking site. The platform team wants to mix General Purpose and Memory Optimized VM sizes in the same scale set and spread instances across multiple availability zones for resilience. Which Virtual Machine Scale Set orchestration mode should they choose?
- An overnight batch job at Cascade Regional Airlines pulls flight-manifest files from a storage queue and processes them on a Virtual Machine Scale Set. The queue backs up heavily right after the last redeye departs, then empties by morning. Which autoscale configuration best matches processing capacity to the workload?
- A support engineer notices that whenever Cascade Regional Airlines' booking-site scale set scales in during a traffic dip, the newest instance is always the one removed — even when an older instance is closer to becoming unhealthy. The team wants the newest instances protected so recently deployed code gets time to prove itself before being torn down. Which scale-in policy should they configure?
- Cascade Regional Airlines wants to stage a new booking-site build in a separate deployment slot, warm it up, then swap it into production with zero downtime. Their App Service plan is currently on the Free tier. What is the minimum tier change required to unlock deployment slots?
- The booking site's App Service is hosted on a Standard S1 plan with a single instance. During a holiday sale, response times degrade because the app is running out of memory processing large itinerary exports, even though CPU usage stays low and only one or two users trigger exports at a time. What is the most appropriate first response?
- A release engineer swaps a newly tested staging slot into production for Cascade Regional Airlines' booking site. Immediately after the swap, the first wave of live users hits slow response times because the app has to finish its startup initialization under real traffic. What App Service feature should the engineer use before the next release to avoid this cold-start delay during swap?
- Cascade Regional Airlines wants to bind a free App Service Managed Certificate to the apex domain cascaderegional.com for the booking site, but the binding keeps failing domain validation. The DNS zone currently has only an A record pointing the apex at the App Service's inbound IP, with no other verification records. What is the most likely reason the App Service Managed Certificate cannot be issued for the apex domain?
- Cascade Regional Airlines' internal crew-scheduling web app runs on a Basic App Service plan and is used sporadically throughout the day. Staff complain that the first request after a period of inactivity takes much longer than normal to load. Which App Service configuration setting most directly addresses this specific complaint?
- A developer at Cascade Regional Airlines needs to run a short-lived container that regenerates a single daily gate-assignment report, then exits. There is no need for orchestration, scaling, or service discovery between multiple services. Which compute option is the simplest fit for this workload?
- Cascade Regional Airlines runs its nightly flight-data reconciliation job in an Azure Container Instances container group. The job should run exactly once per night, and if it fails, the operations team wants to investigate the failure rather than have the platform silently retry it. Which container group restart policy should be configured?
- A container running in Azure Container Instances processes uploaded baggage-tag images for Cascade Regional Airlines and needs those images to persist even after the container instance is deleted and recreated. Which storage approach should be used?
- Cascade Regional Airlines' baggage-tracking service is made up of several small containerized microservices that need to scale independently based on load, communicate with each other, and support rolling updates with minimal manual orchestration effort from the small platform team. Which compute service best fits this requirement without taking on full Kubernetes cluster management?
- Cascade Regional Airlines expects a predictable but sharp spike in booking-site traffic every year during the holiday fare sale, driven by sustained high CPU usage across the web tier. Which autoscale configuration lets the scale set add instances automatically once CPU usage crosses a defined threshold, without requiring an operator to intervene?
- After Cascade Regional Airlines pushes a new VM image to its booking-site scale set, all instances are replaced simultaneously and the site experiences a brief full outage during the rollout. Which scale set upgrade policy is most likely currently configured, and which change would eliminate the simultaneous-replacement behavior?
- Cascade Regional Airlines is deploying a stateless web tier for its flight-status API behind an Azure Load Balancer, where every instance must run the exact same VM image and configuration, and the team wants the platform to manage large-scale identical deployments with minimal per-instance customization. Which Virtual Machine Scale Set orchestration mode fits this requirement?
- The booking site's App Service is on a Standard S2 plan running two instances. During a flash sale, thousands of concurrent users push CPU usage to its ceiling across all instances simultaneously, even though per-request memory usage stays modest. What is the most appropriate first response to relieve the CPU pressure?
- Cascade Regional Airlines wants to swap a staging slot into production for the booking site, but the team wants a chance to run smoke tests against production settings and connection strings applied to the staging slot before traffic actually switches over, with the ability to cancel if something looks wrong. Which App Service feature supports this?
- Cascade Regional Airlines binds a TLS certificate to www.cascaderegional.com on their App Service, but requests to book.cascaderegional.com, a second custom domain on the same app, still show a certificate warning because the browser receives the wrong certificate for that hostname. What is the most likely cause?
- A newly added baggage-tracking microservice at Cascade Regional Airlines receives bursts of requests only when flights are actively boarding, and sits completely idle overnight and between flights. The team wants to avoid paying for idle compute during those quiet periods while still scaling out automatically during boarding bursts. Which compute option best supports scaling down to zero instances during idle periods?
- An architect at Cascade Regional Airlines is documenting the scale-in behavior of the booking site's Virtual Machine Scale Set, which has not had any explicit scale-in policy configured. Which statement correctly describes the behavior that applies by default when the scale set removes instances?
- Cascade Regional Airlines is standing up a new outstation network in Bozeman. The platform engineer wants the same ARM template to deploy either a /24 or /26 VNet address space depending on which airport it lands in, without editing the template body for each site. Which template section should hold that address space value?
- Cascade Regional Airlines deploys the same ARM template to three environments: development, staging, and the production outstation network. Rather than editing the template or typing a long list of inline values on every deployment command, the team wants each environment's input values stored separately and version-controlled alongside the template. What should they use?
- A change-control reviewer at Cascade Regional Airlines asks the platform team to re-run last week's ARM template deployment against the same resource group, unchanged, to confirm it is safe to include in the standard build runbook. After the re-run, the resource group contains the same resources it did before, with no duplicates and no errors. What property of the template deployment does this behavior demonstrate?
- A Cascade Regional Airlines engineer redeploys the outstation network template to an existing resource group without setting a deployment mode. The resource group already contains a diagnostic storage account that was created manually and is not listed in the template. What happens to that storage account when the deployment runs?
- Two weeks after a successful outstation build, a Cascade Regional Airlines engineer reuses the original ARM template to redeploy the same resource group in Complete mode, intending only to refresh the network security group rules. After the deployment finishes, the on-call team reports that a load balancer added by a different team last week, and never added to the template, is gone. What is the most likely explanation?
- A Cascade Regional Airlines engineer authors a new outstation deployment in Bicep instead of raw ARM JSON. When the deployment is submitted to Azure Resource Manager, what actually happens to the Bicep file before the resources are created?
- A Cascade Regional Airlines engineer maintaining a growing library of ARM JSON templates for outstation builds complains that the templates are verbose and hard to read, with heavy nesting and repeated syntax for simple resource declarations. A teammate suggests migrating the authoring to Bicep. What is the main reason Bicep was created to address this complaint?
- Cascade Regional Airlines wants to define its standard outstation virtual network pattern once in Bicep and reuse it across every new airport deployment, rather than copying the same resource block into every template. Which Bicep feature is built for exactly this kind of reuse?
- An engineer runs an ARM template deployment command against Cascade Regional Airlines' outstation subscription without specifying a management group or subscription-level scope flag, targeting an existing resource group by name. At what scope does this deployment run?
- Cascade Regional Airlines' platform team wants a single ARM template to both create a new resource group for an upcoming outstation and assign a subscription-wide policy, in one deployment. Since creating a resource group is not something that can be declared from inside another resource group's deployment, what deployment scope must this template target?
- Cascade Regional Airlines has grown to operate four Azure subscriptions, one per region, and wants a single template deployment to assign the same tagging policy to all four at once rather than repeating the assignment in each subscription individually. Which deployment scope is built for applying a template's effect across multiple subscriptions in one operation?
- Before writing a new ARM template from scratch for a resource group that was built manually through the portal, a Cascade Regional Airlines engineer wants a quick starting point that reflects what is currently deployed. Which built-in capability produces an ARM template based on the resource group's existing resources?
- A Cascade Regional Airlines engineer exports a template from an existing outstation resource group and, before reusing it, redeploys the exported template unmodified against a brand-new resource group to see what happens. The deployment fails on several resources. What is a known limitation of exported templates that most likely explains this?
- A compliance auditor asks Cascade Regional Airlines' platform team to show every ARM template deployment made against a specific outstation resource group over the past quarter, including which template and parameter values were used each time. Where in Azure should the team look first to answer this without needing external logging?
- An ARM template deployment for a new outstation fails partway through, with several resources created successfully and one resource reporting an error. Cascade Regional Airlines' engineer needs to identify exactly which resource failed and why. Where should they look to get that specific, per-resource error detail?
- A Cascade Regional Airlines engineer needs to quickly spin up a single test virtual machine for an afternoon proof-of-concept, with no expectation of repeating the build or handing it to another team. Which approach best fits this one-off, exploratory task?
- A Cascade Regional Airlines engineer writes an Azure CLI script that issues a sequence of az commands to create a virtual network, then a subnet, then a virtual machine, one command after another. Compared to an equivalent ARM or Bicep template deploying the same resources, what is a key difference in how this CLI script behaves?
- Cascade Regional Airlines runs a quarterly disaster-recovery rehearsal that rebuilds an entire outstation's network and compute footprint in a secondary region, and the rebuild must match the production footprint precisely every time. Why is an ARM or Bicep template the best-suited approach for this recurring rebuild, compared to manually recreating resources through the portal each quarter?
- Cascade Regional Airlines requires every production change to go through a scheduled change-control window, and reviewers want to see exactly what an ARM template deployment will add, modify, or delete in the outstation resource group before the window opens and the deployment is actually approved to run. Which capability lets the team preview those effects without making any changes yet?
- After an ARM template deployment creates a new public IP address for an outstation's gateway, a downstream automation script needs that IP address's resource ID to configure DNS immediately afterward, without a separate lookup call. Which template section should return that value so it is available right after the deployment finishes?
Implement and manage virtual networking · 40 questions
- Cascade Regional Airlines' network architects are provisioning a new Azure VNet for the crew-scheduling tier. The airline's on-premises data center already uses 10.10.0.0/16, and the VNet will connect to it over ExpressRoute. Which address space should the architects choose for the new VNet to avoid a routing conflict?
- The kiosk team at Cascade Regional Airlines requests a /28 subnet for the airport check-in kiosks. How many usable host IP addresses will that subnet actually provide once Azure's reserved addresses are accounted for?
- A Cascade Regional Airlines engineer configures an NSG for the public booking subnet with two inbound custom rules: priority 100 named 'Deny-All' and priority 200 named 'Allow-HTTPS'. The engineer created the Allow-HTTPS rule first and added the Deny-All rule afterward, but HTTPS traffic to the subnet is now blocked. Why?
- Cascade Regional Airlines just created a network security group for the crew-scheduling subnet without adding any custom rules yet. A VM in a different subnet of the same virtual network needs to reach a VM in the crew-scheduling subnet. Will that traffic be allowed?
- The kiosk subnet at Cascade Regional Airlines only needs to send data out to the booking API over HTTPS; the kiosks should never be able to initiate any other outbound connection. Where should this restriction be configured?
- Cascade Regional Airlines applies a network security group to both the outstation-office subnet and the network interface of a specific VM within that subnet. For inbound traffic reaching that VM, in what order are the two NSGs evaluated?
- Cascade Regional Airlines wants an NSG rule that allows the reservations-app VMs to reach the payment-processing VMs on port 443, without hardcoding IP addresses since those VMs are added and removed as the fleet autoscales. What should the rule use as its source and destination?
- Cascade Regional Airlines peers VNet A (headquarters) with VNet B (an outstation office), and separately peers VNet B with VNet C (a maintenance depot). No peering exists directly between VNet A and VNet C. Can a VM in VNet A reach a VM in VNet C by routing through VNet B?
- Cascade Regional Airlines has an ExpressRoute gateway deployed in the headquarters VNet and wants the outstation-office VNet, which is peered to headquarters, to reach on-premises resources through that same gateway instead of deploying a second ExpressRoute gateway. What must be configured to allow this?
- Cascade Regional Airlines wants to peer its headquarters VNet in East US with a new VNet in West Europe that will support the outstation office there. What is required for this cross-region peering to succeed?
- Cascade Regional Airlines needs a public IP for its booking-tier load balancer that is zone-redundant and denies all inbound traffic by default unless an NSG explicitly allows it. Which SKU should they choose, and why?
- The outstation office's on-premises firewall references its Azure VPN gateway's public IP address by its exact numeric value, so that address must never change. Which public IP allocation method must be assigned to the gateway?
- VMs in the crew-scheduling subnet at Cascade Regional Airlines need a stable, predictable outbound public IP address for connecting to a third-party scheduling API, but the subnet must not expose any inbound public endpoint. What should be attached to the subnet to meet this need?
- Cascade Regional Airlines wants to connect its new outstation office's on-premises router to its Azure VNet over an encrypted tunnel across the public internet, without provisioning any dedicated private circuit. Which connection type should they configure?
- A Cascade Regional Airlines network engineer is traveling and needs to connect a single laptop directly to the crew-scheduling VNet from a hotel network, without any on-premises VPN hardware available. Which connection type fits this need?
- Cascade Regional Airlines' compliance team requires that traffic between the headquarters data center and Azure never traverse the public internet under any circumstances. Which connectivity option meets this requirement?
- Cascade Regional Airlines wants VMs in the booking-tier subnet to reach an Azure Storage account using a private IP address from the VNet's own address space, with the storage account fully removed from public exposure. What should they implement?
- Cascade Regional Airlines wants to restrict an Azure SQL Database's firewall so it only accepts connections originating from the crew-scheduling subnet, while traffic still travels over the Azure backbone to the database's existing public endpoint, with no new network interface or private IP address required. Which feature satisfies this?
- Cascade Regional Airlines needs a subnet for the maintenance depot with room for at least 100 usable host addresses, sized as efficiently as possible once Azure's reserved addresses are taken into account. Which CIDR prefix should they use?
- Cascade Regional Airlines' VNet is 10.30.0.0/16. The team has already created 10.30.0.0/24 for the public booking tier and 10.30.1.0/24 for crew-scheduling. Which of the following ranges can be safely used for a new airport-kiosk subnet without overlapping either existing subnet?
- Cascade Regional Airlines is rebuilding its public booking site behind an Azure Load Balancer that fronts identical web farms in the Denver and Boise regions, and the network team wants the load balancer's frontend to keep working even if an entire availability zone in a region goes down. Which load balancer SKU must they choose to get zone-redundant frontend IP configurations?
- An engineer at Cascade Regional Airlines needs temporary RDP access to troubleshoot one specific backend virtual machine behind a Standard Load Balancer, without disturbing the load-balancing rule that spreads HTTPS booking traffic across the whole backend pool. Which load balancer feature should map a distinct frontend port straight to RDP on that single VM?
- Gate-agent kiosks at Cascade Regional Airlines' Seattle hub intermittently freeze because the Standard Load Balancer keeps sending traffic to a backend VM that crashed hours ago and never came back online. Which load balancer component should the network team configure so unhealthy instances are automatically pulled out of rotation?
- During a fare-sale spike, Cascade Regional Airlines notices that shopping-cart state built up on one backend web server is being lost mid-checkout because a customer's follow-up requests keep landing on a different VM behind the Standard Load Balancer. Which load balancer setting should route all of that customer's requests back to the same backend instance for the duration of the session?
- Cascade Regional Airlines wants a single Application Gateway to send requests for /booking to its web-farm backend pool and requests for /api to its internal reservations API backend pool, all behind one public IP and hostname. Which Application Gateway feature accomplishes this split?
- Cascade Regional Airlines wants to publish both its public booking site (booking.cascaderegional.com) and a separate partner portal (partners.cascaderegional.com) through the same Application Gateway public IP, with each hostname routed to its own backend pool. Which Application Gateway feature makes this possible?
- After enabling the WAF policy on Cascade Regional Airlines' Application Gateway in Prevention mode, the security team notices legitimate booking submissions from a partner travel agency are being blocked, and they need to understand what's triggering the block before re-enabling strict enforcement. What should they do first?
- Cascade Regional Airlines' internal reservations API only needs to be reachable from clients inside its own VNet, and the platform team wants Layer 7 path-based routing and a WAF applied to that internal traffic without exposing anything to the public internet. Which service fits this requirement?
- Cascade Regional Airlines wants to give global customers a single hostname for its booking site that accelerates HTTPS traffic at the network edge, applies a WAF close to the user, and can fail over between regional backends, rather than simply resolving a DNS name to whichever region is currently healthy. Which service best fits this need?
- Cascade Regional Airlines runs its booking site primarily out of its East US region, with a fully provisioned but idle standby deployment in West US 2 meant only to take over if East US becomes completely unavailable. Which Traffic Manager routing method should route all traffic to East US under normal conditions and only shift to West US 2 during an outage?
- Cascade Regional Airlines' flight-status lookup service is deployed in both the US and Europe, and the goal is simply to send each customer to whichever deployment gives them the fastest response based on network latency, with no preference for one region over the other. Which Traffic Manager routing method fits this goal?
- Cascade Regional Airlines just created a public Azure DNS zone for cascaderegional.com to host its booking site's records, but external resolvers still aren't finding any of the new records when customers try to reach the site. What step is still missing?
- Cascade Regional Airlines wants its bare root domain, cascaderegional.com (with no subdomain), to resolve directly to its Azure Front Door endpoint, but Front Door only exposes a DNS name rather than a static IP, and DNS standards prohibit a CNAME record at the zone apex. Which Azure DNS record type solves this?
- Cascade Regional Airlines' internal reservations API, running in one VNet, needs to resolve the private endpoint name of a database service that lives in a peered VNet, using a private DNS zone that already contains the correct record. What must be configured on the private DNS zone for the API's VNet to actually query and resolve that name?
- Cascade Regional Airlines' crew-scheduling application scales a pool of worker VMs up and down constantly inside its own VNet, and the platform team wants each new VM to automatically get a resolvable DNS A record in the linked private DNS zone the moment it's created, without any manual record entry. Which private DNS zone setting achieves this?
- Staff at Cascade Regional Airlines' on-premises office in Missoula report they cannot resolve the private-link name of an Azure storage account's private endpoint, and the query instead returns the storage account's public IP address. The privatelink DNS zone in Azure is correctly configured and linked to the VNet. What is most likely missing?
- An engineer at Cascade Regional Airlines suspects a network security group rule is silently blocking traffic from the crew-scheduling app VM to the backend database VM on port 1433, but nothing in the application logs confirms it. Which Network Watcher tool directly tests whether a specific flow between two VMs is allowed or denied, and by which rule?
- Packets from Cascade Regional Airlines' internal API VM destined for the on-premises reservations database are silently failing to arrive, and the network team suspects a misconfigured user-defined route is sending traffic somewhere other than the VPN gateway. Which Network Watcher tool identifies the actual next hop a packet takes toward a given destination?
- A virtual machine in Cascade Regional Airlines' baggage-tracking subnet has both a subnet-level NSG and a NIC-level NSG applied, and the security team is troubleshooting unexpected blocked traffic but isn't sure which combined set of rules is actually being enforced on that VM. Which Network Watcher tool shows the full, merged rule set actually applied to the VM?
- Cascade Regional Airlines' compliance team needs a historical, queryable record of every allowed and denied connection through the NSGs protecting the booking VNet, to support an upcoming security audit. Which Network Watcher feature should be enabled to capture this?
Monitor and maintain Azure resources · 20 questions
- At Cascade Regional Airlines, a ramp operations dashboard needs to show live CPU and memory trends for the gate-check-in VMs at Denver with only a few minutes of delay, refreshed continuously through the shift. Which Azure Monitor data store is purpose-built for this kind of lightweight, near-real-time numerical trend?
- Cascade Regional Airlines runs 40 web and application servers supporting the booking site across two regions. The operations team wants to run a single Kusto query that correlates failed sign-ins across every one of those servers at once. What should the servers be configured to send their logs to?
- An engineer at Cascade Regional Airlines is onboarding new reservation servers to Azure Monitor Agent and needs to define exactly which Windows event log channels and performance counters get collected, and which Log Analytics workspace they are sent to. Which object should the engineer create to define this?
- During a compliance audit, Cascade Regional Airlines' security team tries to query sign-in log records from 120 days ago in their Log Analytics workspace and gets no results, even though the servers were sending data the whole time. The workspace was never customized. What is the most likely explanation?
- The booking-site VMs at Cascade Regional Airlines need to page the on-call engineer whenever CPU utilization stays above 85% for 10 minutes. The team wants this evaluated against the numeric performance counter itself, with no custom query written. Which Azure Monitor alert type fits?
- Security analysts at Cascade Regional Airlines want to be notified whenever more than 20 failed login attempts against the crew-scheduling portal occur from the same IP address within 5 minutes. This requires filtering, grouping, and counting structured sign-in records. Which Azure Monitor alert type should they configure?
- Cascade Regional Airlines wants an immediate notification any time someone deletes a resource group in the subscription, so leadership can be alerted quickly if it happens outside a planned maintenance window. An engineer configures a metric alert on the subscription scope, but it never fires when a test resource group is deleted. What is the most likely reason, and what should be configured instead?
- When a critical alert fires against the booking-site infrastructure at Cascade Regional Airlines, the on-call runbook requires that an email go to the ops distribution list, a text message go to the on-call engineer's phone, and a ticket be automatically created in the ITSM system, all from the same alert. Which Azure Monitor object bundles these three notification actions together?
- Cascade Regional Airlines is patching the reservation database cluster during a planned 2-hour maintenance window and expects a burst of expected CPU and connectivity alerts during that time. The team does not want to disable or edit each of the dozens of existing alert rules, but does want notifications suppressed only for that window and only for that resource group. What should they configure?
- Cascade Regional Airlines' booking site sees normal traffic swings between weekdays and weekends, and again during holiday travel peaks, making any single fixed CPU threshold either too noisy on busy days or too insensitive on quiet ones. Which metric alert configuration adapts the threshold automatically to these learned patterns?
- An auditor investigating a data-loss incident at Cascade Regional Airlines asks which storage account blobs were deleted and by whom last Tuesday. The engineer checks the subscription's activity log and finds no matching entries, even though the storage account itself was never modified. What is the correct explanation?
- Cascade Regional Airlines needs resource-level logs from its API Management gateway to land simultaneously in a Log Analytics workspace for querying, an event hub for a third-party SIEM to consume, and a storage account for long-term archival. Which single Azure Monitor mechanism configures all three destinations for that resource?
- Leadership at Cascade Regional Airlines wants a single interactive report that combines a CPU trend chart from metrics, a table of recent failed deployments from logs, and a written summary, refreshed on demand and shareable as a saved view. Which Azure Monitor feature is designed for this kind of combined, interactive report?
- An engineer at Cascade Regional Airlines enables VM insights on the crew-scheduling application's VMs, expecting to see a dependency map showing which processes talk to which other machines. The performance charts appear, but the dependency map stays empty. What is the most likely missing piece?
- Cascade Regional Airlines wants nightly backups of its crew-scheduling VMs retained for 30 days, with a separate weekly backup retained for a full year for audit purposes. Where is this schedule and retention behavior defined once the VMs are enrolled in a Recovery Services vault?
- Cascade Regional Airlines needs to back up both its crew-scheduling Windows VMs and a set of Azure Database for PostgreSQL flexible servers holding flight-schedule data. The VM backups are already working through a Recovery Services vault. Where should the PostgreSQL backups be configured instead?
- The gate operations team at Cascade Regional Airlines stores shared flight-manifest documents on an Azure file share and wants scheduled, application-consistent backups with the ability to restore individual files without restoring the whole share. Which Azure Backup capability should they use?
- A reservation-database VM at Cascade Regional Airlines was corrupted by a bad configuration change. The team wants to keep the original VM running untouched for forensic review while standing up a fully working replacement from last night's recovery point under a different name. Which Azure Backup restore option fits?
- Cascade Regional Airlines wants its booking-site VMs in the primary region to be continuously kept in sync with standby VMs in a secondary region, so that a regional outage causes only minutes of data loss rather than requiring a restore from last night's backup. Which Azure service provides this kind of ongoing, near-continuous replication between regions?
- During a scheduled DR rehearsal, Cascade Regional Airlines wants to prove that its replicated booking-site VMs can start up correctly in the secondary region, without interrupting the live production site still running in the primary region or affecting ongoing replication. Which Azure Site Recovery operation should they run?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by the exam vendor.