Share the latest Microsoft Azure dumps https://www.pass4itsure.com/az-103.html ,13 Exam Practice topics and test your strength. Pass4itsure offers complete Microsoft Azure az-103 exam questions and answers. If you want to pass the exam easily, you can choose Pass4itsure. If you are interested in hobbies. We shared the latest az-103 PDF you can download online!
Download Microsoft Azure az-103 PDF Online
[PDF] Free Microsoft az-103 pdf dumps download from Google Drive: https://drive.google.com/open?id=1IfQGWiZqutQ6oU0sqyAZtQUJ3dcm2GgE
[PDF] Free Full Microsoft pdf dumps download from Google Drive: https://drive.google.com/open?id=1gdQrKIsiLyDEsZ24FxsyukNPYmpSUDDO
Valid information provided by Microsoft officials
AZ-103 Microsoft Azure Administrator: https://www.microsoft.com/en-us/learning/exam-az-103.aspx
Starting on May 1, 2019, you only need to pass Exam AZ-103 to earn this certification. This new exam combines the skills covered in AZ-100 and AZ-101 (which retired on May 1, 2019), with the majority of the new exam coming from AZ-100.
Candidates for this exam are Azure Administrators who manage cloud services that span storage, security, networking, and compute cloud capabilities. Candidates have a deep understanding of each service across the full IT lifecycle, and take requests for infrastructure services, applications, and environments. They make recommendations on services to use for optimal performance and scale, as well as provision, size, monitor, and adjust resources as appropriate.
Candidates for this exam should have proficiency in using PowerShell, the Command Line Interface, Azure Portal, ARM templates, operating systems, virtualization, cloud infrastructure, storage structures, and networking
Manage Azure subscriptions and resources (15-20%)
- Manage Azure subscriptions
- Analyze resource utilization and consumption
- Manage resource groups
- Managed role based access control (RBAC)
Implement and manage storage (15-20%)
- Create and configure storage accounts
- Import and export data to Azure
- Configure Azure files
- Implement Azure backup
Deploy and manage virtual machines (VMs) (15-20%)
- Create and configure a VM for Windows and Linux
- Automate deployment of VMs
- Manage Azure VM
- Manage VM backups
Configure and manage virtual networks (30-35%)
- Create connectivity between virtual networks
- Implement and manage virtual networking
- Configure name resolution
- Create and configure a Network Security Group (NSG)
- Implement Azure load balancer
- Monitor and troubleshoot virtual networking
- Integrate on premises network with Azure virtual network
Manage identities (15-20%)
- Manage Azure Active Directory (AD)
- Manage Azure AD objects (users, groups, and devices)
- Implement and manage hybrid identities
- Implement multi-factor authentication (MFA)
Latest effective Microsoft az-103 Exam Practice Tests
QUESTION 1
You have an Azure Active Directory (Azure AD) tenant named Tenant1 and an Azure subscription named You enable
Azure AD Privileged Identity Management.
You need to secure the members of the Lab Creator role. The solution must ensure that the lab creators request access
when they create labs.
What should you do first?
A. From Azure AD Privileged Identity Management, edit the role settings for Lab Creator.
B. From Subscription1 edit the members of the Lab Creator role.
C. From Azure AD Identity Protection, creates a user risk policy.
D. From Azure AD Privileged Identity Management, discover the Azure resources of Conscription.
Correct Answer: A
As a Privileged Role Administrator you can: Enable approval for specific roles Specify approver users and/or groups to
approve requests View request and approval history for all privileged roles
References: https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure
QUESTION 2
You need to resolve the Active Directory issue. What should you do?
A. From Active Directory Users and Computers, select the user accounts, and then modify the User Principal Name
value.
B. Run idfix.exe, and then use the Edit action.
C. From Active Directory Domains and Trusts, modify the list of UPN suffixes.
D. From Azure AD Connect, modify the outbound synchronization rule.
Correct Answer: B
IdFix is used to perform discovery and remediation of identity objects and their attributes in an on- premises Active
Directory environment in preparation for migration to Azure Active Directory. IdFix is intended for the Active Directory
administrators responsible for directory synchronization with Azure Active Directory.
Scenario: Active Directory Issue
Several users in humongousinsurance.com have UPNs that contain special characters. You suspect that some of the
characters are unsupported in Azure AD.
References: https://www.microsoft.com/en-us/download/details.aspx?id=36832
QUESTION 3
You deploy an Azure Application Gateway.
You need to ensure that all the traffic requesting https://adatum.com/internal resources is directed to an internal server
pool and all the traffic requesting https://adatum.com/external resources is directed to an external server pool.
What should you configure on the Application Gateway?
A. URL path-based routing
B. multi-site listeners
C. basic routing D. SSL termination
Correct Answer: A
QUESTION 4
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
You have an Azure Active Directory (Azure AD) tenant named Adatum and an Azure Subscription named Subscription1.
Adatum contains a group named Developers. Subscription1 contains a resource group named Dev.
You need to provide the Developers group with the ability to create Azure logic apps in the Dev resource group.
Solution: On Subscription1, you assign the DevTest Labs User role to the Developers group.
Does this meet the goal?
A. Yes
B. No
Correct Answer: B
DevTest Labs User role only lets you connect, start, restart, and shutdown virtual machines in your Azure DevTest
Labs. You would need the Logic App Contributor role.
References: https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles
https://docs.microsoft.com/en-us/azure/logic-apps/logic-apps-securing-a-logic-app
QUESTION 5
You are planning the move of App1 to Azure.
You create a network security group (NSG).
You need to recommend a solution to provide users with access to App1.
What should you recommend?
A. Create an outgoing security rule for port 443 from the Internet. Associate the NSG to all the subnets.
B. Create an incoming security rule for port 443 from the Internet. Associate the NSG to all the subnets.
C. Create an incoming security rule for port 443 from the Internet. Associate the NSG to the subnet that contains the
web servers.
D. Create an outgoing security rule for port 443 from the Internet. Associate the NSG to the subnet that contains the
web servers.
Correct Answer: C
As App1 is public-facing we need an incoming security rule, related to the access of the web servers. Scenario: You
have a public-facing application named App1. App1 is comprised of the following three tiers: a SQL database, a web
front end, and a processing middle tier. Each tier is comprised of five virtual machines. Users access the web front end
by using HTTPS only.
QUESTION 6
You have an azure subscription named Subscription that contains the resource groups shown in the following table.
In RG1, you create a virtual machine named VM1 in the East Asia location.
You plan to create a virtual network named VNET1.
You need to create VNET, and then connect VM1 to VNET1.
What are two possible ways to achieve this goal? Each correct answer presents a complete a solution.
NOTE: Each correct selection is worth one point.
A. Create VNET1 in RG2, and then set East Asia as the location.
B. Create VNET1 in a new resource group in the West US location, and then set West US as the location.
C. Create VNET1 in RG1, and then set East Asia as the location
D. Create VNET1 in RG1, and then set East US as the location.
E. Create VNET1 in RG2, and then set East US as the location.
Correct Answer: AC
QUESTION 7
Note This question is part of a series of questions that present the same seer Some question sets might have more than
one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
You manage a virtual network named VNet1 that is hosted in the West US Azure region.
VNet1 hosts two virtual machines named VM1 and VM2 that run Windows Server. You need to inspect all the network
traffic from VM1 to VM2 for a period of three hours.
Solution: From Performance Monitor, you create a Data Collector Set (DCS) Does this meet the goal?
A. Yes
B. No
Correct Answer: B
You should use Azure Network Watcher.
References: https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-monitoring-overview
QUESTION 8
You have an Azure virtual network named VNet1 that contains a subnet named Subnet1. Subnet1 contains three Azure
virtual machines. Each virtual machine has a public IP address.
The virtual machines host several applications that are accessible over port 443 to user on the Internet.
Your on-premises network has a site-to-site VPN connection to VNet1.
You discover that the virtual machines can be accessed by using the Remote Desktop Protocol (RDP) from the Internet
and from the on-premises network.
You need to prevent RDP access to the virtual machines from the Internet, unless the RDP connection is established
from the on-premises network. The solution must ensure that all the applications can still be accesses by the Internet
users.
What should you do?
A. Modify the address space of the local network gateway.
B. Remove the public IP addresses from the virtual machines.
C. Modify the address space of Subnet1.
D. Create a deny rule in a network security group (NSG) that is linked to Subnet1.
Correct Answer: D
You can filter network traffic to and from Azure resources in an Azure virtual network with a network security group. A
network security group contains security rules that allow or deny inbound network traffic to, or outbound network traffic
from, several types of Azure resources.
References: https://docs.microsoft.com/en-us/azure/virtual-network/security-overview
QUESTION 9
Click to expand each objective. To connect to the Azure portal, type https://portal.azure.com in the browser address
bar.
When you are finished performing all the tasks, click the `Next\\’ button. Note that you cannot return to the lab once you
click the `Next\\’ button. Scoring occur in the background while you complete the rest of the exam.
Overview
The following section of the exam is a lab. In this section, you will perform a set of tasks in a live environment. While
most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste,
ability
to navigate to external websites) will not be possible by design. Scoring is based on the outcome of performing the tasks
stated in the lab. In other words, it doesn\\’t matter how you accomplish the task, if you successfully perform it, you will
earn credit for that task.
Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as
much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you
are
able to complete the lab(s) and all other sections of the exam in the time provided.
Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to
the lab.
To start the lab
You may start the lab by clicking the Next button.
Another administrator attempts to establish connectivity between two virtual networks named VNET1 and VNET2.
The administrator reports that connections across the virtual networks fail. You need to ensure that network connections
can be established successfully between VNET1 and VNET2 as quickly as possible.
What should you do from the Azure portal?
A. Answer: See solution below.
Correct Answer: A
You can connect one VNet to another VNet using either a Virtual network peering, or an Azure VPN Gateway.
To create a virtual network gateway
Step1 : In the portal, on the left side, click +Create a resource and type \\’virtual network gateway\\’ in search. Locate
Virtual network gateway in the search return and click the entry. On the Virtual network gateway page, click Create at
the
bottom of the page to open the Create virtual network gateway page.
Step 2: On the Create virtual network gateway page, fill in the values for your virtual network gateway.
Name: Name your gateway. This is not the same as naming a gateway subnet. It\\’s the name of the gateway object you
are creating.
Gateway type: Select VPN. VPN gateways use the virtual network gateway type VPN. Virtual network: Choose the
virtual network to which you want to add this gateway. Click Virtual network to open the \\’Choose a virtual network\\’
page.
Select the VNet. If you don\\’t see your VNet, make sure the Location field is pointing to the region in which your virtual
network is located. Gateway subnet address range: You will only see this setting if you did not previously create a
gateway
subnet for your virtual network. If you previously created a valid gateway subnet, this setting will not appear.
Step 4: Select Create New to create a Gateway subnet.
Step 5: Click Create to begin creating the VPN gateway. The settings are validated and you\\’ll see the “Deploying
Virtual network gateway” tile on the dashboard. Creating a gateway can take up to 45 minutes. You may need to refresh
your portal page to see the completed status.
References: https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-vnet-vnet- resource-manager-portal?
QUESTION 10
You have an Azure DNS zone named adatum.com. You need to delegate a subdomain named research.adatum.com to
a different DNS server in Azure. What should you do?
A. Create an PTR record named research in the adatum.com zone.
B. Create an NS record named research in the adatum.com zone.
C. Modify the SOA record of adatum.com.
D. Create an A record named “.research in the adatum.com zone.
Correct Answer: D
Configure A records for the domains and sub domains.
References: http://www.stefanjohansson.org/2012/12/how-to-configure-custom-dns-names-for- multiple-subdomain-
based-azure-web-sites/
QUESTION 11
You have an Azure subscription that contains a virtual machine named VM1. VM1 hosts a line-of- business application
that is available 24 hours a day. VM1 has one network interface and one managed disk. VM1 uses the D4s v3 size.
You plan to make the following changes to VM1:
Change the size to D8s v3.
Add a 500-GB managed disk.
Add the Puppet Agent extension.
Attach an additional network interface.
Which change will cause downtime for VM1?
A. Add a 500-GB managed disk.
B. Attach an additional network interface.
C. Add the Puppet Agent extension.
D. Change the size to D8s v3.
Correct Answer: D
While resizing the VM it must be in a stopped state.
References: https://azure.microsoft.com/en-us/blog/resize-virtual-machines/
QUESTION 12
You have an Azure subscription named Subscnption1 that contains an Azure virtual machine named VM1. VM1 is in a
resource group named RG1.
VM1 runs services that will be used to deploy resources to RG1.
You need to ensure that a service running on VM1 can manage the resources in RG1 by using the identity of VM1.
What should you do fit
A. From the Azure portal modify the Access control (1AM) settings of VM1.
B. From the Azure portal, modify the Policies settings of RG1.
C. From the Azure portal, modify the value of the Managed Service Identity option for VM1.
D. From the Azure portal, modify the Access control (IAM) settings of RG1.
Correct Answer: C
A managed identity from Azure Active Directory allows your app to easily access other AAD-protected resources such
as Azure Key Vault. The identity is managed by the Azure platform and does not require you to provision or rotate any
secrets.
User assigned managed identities can be used on Virtual Machines and Virtual Machine Scale Sets.
References:
https://docs.microsoft.com/en-us/azure/app-service/app-service-managed-service-identity
QUESTION 13
Overview
The following section of the exam is a lab. In this section, you will perform a set of tasks in a live environment. While
most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste,
ability
to navigate to external websites) will not be possible by design.
Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn\\’t matter how you
accomplish the task, if you successfully perform it, you will earn credit for that task. Labs are not timed separately, and
this
exam may have more than one lab that you must complete. You can use as much time as you would like to complete
each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all
other
sections of the exam in the time provided.
Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to
the lab.
To start the lab
You may start the lab by clicking the Next button.
You plan to connect several virtual machines to the VNET01-USEA2 virtual network. In the Web-RGlod8095859
resource group, you need to create a virtual machine that uses the Standard_B2ms size named Web01 that runs
Windows
Server 2016. Web01 must be added to an availability set.
What should you do from the Azure portal?
A. Answer: See explanation below.
Correct Answer: A
Step 1. Choose Create a resource in the upper left-hand corner of the Azure portal.
Step 2. In the Basics tab, under Project details, make sure the correct subscription is selected and then choose Web-
RGlod8095859 resource group
Step 3. Under Instance details type/select: Virtual machine name: Web01 Image: Windows Server 2016 Size:
Standard_B2ms size Leave the other defaults.
Step 4. Finish the Wizard
13 Microsoft Azure az-103 Exam Practice questions and answers have let you know your strength, if you are only interested then please pay attention to us! If you would like to pass the exam, please select our recommended https://www.pass4itsure.com/az-103.html dumps. In this article we have created PDF and YouTube for everyone to learn from.
Like friends please add to favorites! We update all year round! Share more effective and up-to-date exam dumps for free!
Pass4itsure Promo Code 15% Off
Why Choose Pass4itsure?
Pass4itsure is the best provider of IT learning materials and the right choice for you to prepare for Microsoft az-103 exam.
Other brands started earlier, but the price is relatively expensive and the questions are not the newest. Pass4itsure provide the latest
real questions and answers with lowest prices, help you pass az-103 exam easily at first try.