Pass Microsoft AZ-104 in Just 3 Days – Stress-Free, No Study Needed!
Have questions? Contact us directly on WhatsApp for quick support!
You have an Azure subscription that contains the resources shown in the following table.

You need to ensure that data transfers between storage1 and VM1 do NOT traverse the internet
What should you configure for storage1?
- A. data protection
- B. a private endpoint
- C. Public network access in the Firewalls and virtual networks settings
- D. a shared access signature (SAS)
HOTSPOT
–
You have a Microsoft Entra tenant that is linked to the subscriptions shown in the following table.

You have the resource groups shown in the following table.

You assign roles to users as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.


Your on-premises network contains a VPN gateway.
You have an Azure subscription that contains the resources shown in the following table.

You need to ensure that all the traffic from VM1 to storage1 travels across the Microsoft backbone network.
What should you configure?
- A. a network security group (NSG)
- B. private endpoints
- C. Microsoft Entra Application Proxy
- D. Azure Virtual WAN
You have a Microsoft Entra tenant.
You plan to perform a bulk import of users.
You need to ensure that imported user objects are added automatically as the members of a specific group based on each user’s department. The solution must minimize administrative effort.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
- A. Create groups that use the Assigned membership type.
- B. Create an Azure Resource Manager (ARM) template.
- C. Create groups that use the Dynamic User membership type.
- D. Write a PowerShell script that parses an import file.
- E. Create an XML file that contains user information and the appropriate attributes.
- F. Create a CSV file that contains user information and the appropriate attributes.
You have an Azure subscription that contains a storage account named storage1.
You need to ensure that the access keys for storage1 rotate automatically.
What should you configure?
- A. a backup vault
- B. redundancy for storage1
- C. lifecycle management for storage1
- D. an Azure key vault
- E. a Recovery Services vault
You have an Azure subscription that contains the Microsoft Entra identities shown in the following table.

You need to enable self-service password reset (SSPR).
For which identities can you enable SSPR in the Azure portal?
- A. User1 only
- B. Group1 only
- C. User1 and Group1 only
- D. Group1 and Group2 only
- E. User1, Group1, and Group2
DRAG DROP –
You have a Microsoft Entra tenant.
You need to ensure that when a new Microsoft 365 group is created, the group name is automatically formatted as follows:
![]()
Which three actions should you perform in sequence in the Microsoft Entra admin center? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.


HOTSPOT
–
You have a Microsoft Entra tenant that contains the users shown in the following table.

The tenant contains the groups shown in the following table.

Which users and groups can be deleted? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


HOTSPOT
–
You have an Azure subscription that contains the resources shown in the following table.

You plan to use an Azure key vault to provide a secret to app1.
What should you create for app1 to access the key vault, and from which key vault can the secret be used? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.


You have a Microsoft Entra tenant named contoso.com.
You collaborate with an external partner named fabrikam.com.
You plan to invite users in fabrikam.com to the contoso.com tenant.
You need to ensure that invitations can be sent only to fabrikam.com users.
What should you do in the Microsoft Entra admin center?
- A. From Cross-tenant access settings, configure the Tenant restrictions settings.
- B. From Cross-tenant access settings, configure the Microsoft cloud settings.
- C. From External collaboration settings, configure the Guest user access restrictions settings.
- D. From External collaboration settings, configure the Collaboration restrictions settings.
You create the Azure policies shown in the following table:

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:


Box 1: No –
Virtual networks are not allowed at the root and is inherited. Deny overrides allowed.
Box 2: Yes –
Virtual Machines can be created on a Management Group provided the user has the required RBAC permissions.
Box 3: Yes –
Subscriptions can be moved between Management Groups provided the user has the required RBAC permissions.
Reference:
https://docs.microsoft.com/en-us/azure/governance/management-groups/overview https://docs.microsoft.com/en-us/azure/governance/management-groups/manage#moving-management-groups-and-subscriptions