ExamGecko
Home Home / Microsoft / AZ-600

Microsoft AZ-600 Practice Test - Questions Answers, Page 3

Question list
Search
Search

List of questions

Search

Related questions



Topic 2, Northwind Traders Case study This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided. To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study. At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section. To start the case study To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Qbutton to return to the question. Overview A company named Northwind Traders has a main office and a datacenter. All development occurs at the main office. Existing Environment Identity Environment The network contains an Active Directory forest named northwind.com. The forest and an Azure Active Directory (Azure AD) tenant named northwind.onmicrosoft.com are integrated by using Active Directory Federation Service (AD FS). All Azure subscriptions use the northwind.onmicrosoft.com Azure AD tenant. Northwind Traders uses an Enterprise Agreement (EA) subscription. All operators are global administrators in northwind.onmicrosoft.com. Azure Stack Hub Environment Northwind Traders has the following five Azure Stack Hub integrated systems: One integrated system that connects to an internet-facing network and has the following configurations: - The region name is int1. - The operators do not have access to the user subscriptions. - The integrated system is used for customer and partner applications. - The partners and customers of NorthWind Traders use guest user accounts to access various user resources. Two integrated systems that connect to a private network, are accessed only from inside the company, and have the following configurations: - The integrated systems are dedicated to research and development. - One integrated system has a region name of priv1, and the other has a region name of priv2. - The integrated systems are used for various data rendering, AI workloads, inference, and data visualization. Two integrated systems that are dedicated to application development and have the following configurations: - The integrated systems are disconnected from the Internet. The workloads in the user subscriptions have Internet access. - One integrated system has a region name of dev1, and the other has a region name of dev2. - Both regions are used only by developers at Northwind Traders. The external domain name of all the integrated systems is northwind.com. All the integrated systems have Azure App Service and the Azure Kubernetes Service (AKS) engine deployed. The computer of the operator in each region has all the prerequisite software installed for managing Azure Stack Hub. Current Problems You identify the following issues in the current environment: The priv2 region recently experienced a catastrophic failure. The developers report high chargeback costs for the dev1 region. The int1 region runs a high number of Windows virtual machines that use pay-as-you-use images. The Northwind Traders partners and customers report that use of the guest user accounts is too complex. Users in the priv1 region recently deployed NCas_v4 virtual machines for various AI workload. The users discover that the virtual machines do not use GPUs. Requirements Planned Changes Northwind Traders plans to implement the following changes: Remove all guest user accounts. Change the DNS forwarder of the priv1 region. Change the billing model and registration name of the int1 region. After the catastrophic failure, restore the priv2 region to its original state. Provide each partner with its own dedicated user subscription that will use its own dedicated Azure AD tenant. Technical Requirements Northwind Traders identifies the following technical requirements: Minimize hardware and software costs. Standardize all datacenter workloads on Azure Stack Hub. In the priv1 region, implement a disaster recovery plan for App Service. Whenever possible, implement solutions by using the minimum amount of administrative effort. In the dev2 region, update the AKS Base Ubuntu image to the latest version in Azure Stack Hub Marketplace. Whenever possible, implement solutions by using built-in tools, features, and services without acquiring additional third-party tools. For the users’ virtual machines and the associated resources in the dev1 and dev2 regions, implement a business continuity and disaster recovery plan that includes an automated failback process. If changes to the Azure Stack Hub infrastructure cause workload downtime outside of planned maintenance windows, notify all users in the region where the downtime occurred and schedule a maintenance window.








You have a multitenant Azure Stack Hub integrated system for a Cloud Solution Provider (CSP). The integrated system is used by several customers. You hire a new support technician to help manage the integrated system.

You need to configure access for the support technician. The solution must meet the following requirements:

The technician must be prevented from accessing customer resources.

The technician must be able to monitor the status of infrastructure backups.

The technician must be able to create and manage plans, offers, and quotas.

Which built-in role should you assign to the support technician?

A.
Reader
A.
Reader
Answers
B.
Owner
B.
Owner
Answers
C.
Use Access Administrator
C.
Use Access Administrator
Answers
D.
Contributor
D.
Contributor
Answers
E.
Backup Operator
E.
Backup Operator
Answers
Suggested answer: D

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-manage-permissions?view=azs-2008

You have an Azure Stack Hub integrated system.

You perform infrastructure backups twice daily.

User workloads are protected by using Azure Site Recovery.

The architect of the user workloads is planning a business continuity disaster recovery (BCDR) strategy. You need to recommend to the architect which resources to include in the BCDR strategy.

Which two resources should you recommend? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.
Azure Key Vault secrets
A.
Azure Key Vault secrets
Answers
B.
plans, quotas, and offers
B.
plans, quotas, and offers
Answers
C.
role-based access control (RBAC) permissions and roles
C.
role-based access control (RBAC) permissions and roles
Answers
D.
user subscriptions
D.
user subscriptions
Answers
E.
Azure Resource Manager templates for resources used by Azure Stack Hub virtual machines
E.
Azure Resource Manager templates for resources used by Azure Stack Hub virtual machines
Answers
F.
Azure Site Recovery workloads
F.
Azure Site Recovery workloads
Answers
Suggested answer: E, F

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/architecture/hybrid/azure-stack-vm-dr

You have an Azure Stack Hub integrated system that was recently moved to a new datacenter and powered on. You need to verify whether the infrastructure components are fully operational.

Which three actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.
Run the Start-AzureStack cmdlet
A.
Run the Start-AzureStack cmdlet
Answers
B.
Run the Test-AzureStack cmdlet
B.
Run the Test-AzureStack cmdlet
Answers
C.
Connect to the privileged endpoint (PEP)
C.
Connect to the privileged endpoint (PEP)
Answers
D.
Connect to the administrator portal
D.
Connect to the administrator portal
Answers
E.
Run the Get-AzureStackStampInformation cmdlet
E.
Run the Get-AzureStackStampInformation cmdlet
Answers
Suggested answer: A, B, C

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-diagnostic-test?view=azs-2008

You and a Microsoft Support Engineer are troubleshooting an Azure Stack Hub integrated system.

The security team at your company requires an audit trail whenever management actions are performed on the integrated system. You unlock the privileged endpoint (PEP) and perform several troubleshooting tasks that resolve the issue. Which cmdlet should you run next?

A.
Invoke-AzureStackOnDemandLog
A.
Invoke-AzureStackOnDemandLog
Answers
B.
Close-PrivilegedEndpoint
B.
Close-PrivilegedEndpoint
Answers
C.
Get-AzureStackLog
C.
Get-AzureStackLog
Answers
D.
Exit-PSSession
D.
Exit-PSSession
Answers
Suggested answer: B

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-privileged-endpoint?view=azs-2008

You have an Azure Stack Hub integrated system.

A scale unit node has a hardware failure.

You replace the physical server based on the field replacement unit (FRU) documentation of the OEM hardware vendor. You need to reintroduce the node to the scale unit.

Which PowerShell cmdlet should you run?

A.
Enable-AzsScaleUnitNode
A.
Enable-AzsScaleUnitNode
Answers
B.
Repair-AzsScaleUnitNode
B.
Repair-AzsScaleUnitNode
Answers
C.
Start-AzsScaleUnitNode
C.
Start-AzsScaleUnitNode
Answers
D.
Restart-AzsInfrastructureRole
D.
Restart-AzsInfrastructureRole
Answers
E.
Add-AzsScaleUnitNode
E.
Add-AzsScaleUnitNode
Answers
Suggested answer: B

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-node-actions?view=azs-2008&tabs=az1#repair

Which three components are required to configure an Azure Stack Hub infrastructure backup? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

A.
an SMB file share in the trusted network perimeter
A.
an SMB file share in the trusted network perimeter
Answers
B.
credentials that have write access to storage
B.
credentials that have write access to storage
Answers
C.
an Azure Blob storage account
C.
an Azure Blob storage account
Answers
D.
an encryption certificate
D.
an encryption certificate
Answers
E.
an SMB file share in Azure
E.
an SMB file share in Azure
Answers
Suggested answer: A, B, D

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-backup-reference?view=azs-2008

You have an Azure Stack Hub integrated system and an offer to which users can subscribe.

You need to prevent users and operators from creating new user subscriptions based on the offer without affecting the existing user subscriptions. What should you do?

A.
Change the offer state to Private.
A.
Change the offer state to Private.
Answers
B.
Change the offer state to Decommissioned.
B.
Change the offer state to Decommissioned.
Answers
C.
Change the offer state to Public.
C.
Change the offer state to Public.
Answers
D.
Delete the offer and create a new private offer.
D.
Delete the offer and create a new private offer.
Answers
Suggested answer: B

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-create-offer?view=azs-2008

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure Stack Hub integrated system that connects to the Internet. The integrated system uses an Enterprise Agreement (EA) for licensing. You are creating an Azure Resource Manager template to generate a marketplace item for a virtual machine that runs Windows Server 2019 Datacenter and a custom application. You need to ensure that Windows Server is licensed by using the bring-your-own-license model.

Solution: You add licenseType: None to the Azure Resource Manager template.

Does this meet the goal?

A.
Yes
A.
Yes
Answers
B.
No
B.
No
Answers
Suggested answer: B

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-windows-server-faq?view=azs-2008&tabs=az1%2Caz2

You plan to deploy an Azure Stack Hub integrated system that will connect to the internet.

You are planning the network design. You plan the address space for the public VIP network and the private network. Which three additional networks are required for the Azure Stack Hub deployment? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

A.
a switch infrastructure network
A.
a switch infrastructure network
Answers
B.
a DNS network
B.
a DNS network
Answers
C.
a storage network
C.
a storage network
Answers
D.
a hypervisor network
D.
a hypervisor network
Answers
E.
a BMC network
E.
a BMC network
Answers
F.
an infrastructure network
F.
an infrastructure network
Answers
Suggested answer: A, E, F

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-network?view=azs-2008

You have an Azure Stack Hub integrated system.

You need to give a new operator access to the privileged endpoint (PEP) as soon as possible.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.
Run the New-CloudAdminUser cmdlet.
A.
Run the New-CloudAdminUser cmdlet.
Answers
B.
Run the New-AzureADUser cmdlet.
B.
Run the New-AzureADUser cmdlet.
Answers
C.
Connect to the PEP.
C.
Connect to the PEP.
Answers
D.
Connect to and unlock the PEP.
D.
Connect to and unlock the PEP.
Answers
E.
Connect to the administrator management endpoint.
E.
Connect to the administrator management endpoint.
Answers
Suggested answer: A, C

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-privileged-endpoint?view=azs-2008

Total 179 questions
Go to page: of 18