ExamGecko
Home Home / Microsoft / AZ-720

Microsoft AZ-720 Practice Test - Questions Answers, Page 6

Question list
Search
Search

List of questions

Search

Related questions











A company has an ExpressRoute gateway between their on-premises site and Azure. The ExpressRoute gateway is on a virtual network named VNet1. The company enables FastPath on the gateway. You associate a network security group (NSG) with all of the subnets.

Users report issues connecting to VM1 from the on-premises environment. VM1 is on a virtual network named VNet2. Virtual network peering is enabled between VNet1 and VNet2. You create a flow log named FlowLog1 and enable it on the NSG associated with the gateway subnet.

You discover that FlowLog1 is not reporting outbound flow traffic.

You need to resolve the issue with FlowLog1.

What should you do?

A.
Enable FlowLog1 in a network security group associated with the subnet of VM1.
A.
Enable FlowLog1 in a network security group associated with the subnet of VM1.
Answers
B.
Configure the FlowTimeoutInMinutes property on VNet2 to a non-null value.
B.
Configure the FlowTimeoutInMinutes property on VNet2 to a non-null value.
Answers
C.
Configure the FlowTimeoutInMinutes property on VNet1 to a non-null value.
C.
Configure the FlowTimeoutInMinutes property on VNet1 to a non-null value.
Answers
D.
Configure FlowLog1 for version 2.
D.
Configure FlowLog1 for version 2.
Answers
Suggested answer: A

Explanation:

According to 2, when FastPath is enabled on an ExpressRoute gateway, network traffic between your on-premises network and your virtual network bypasses the gateway and goes directly to virtual machines in the virtual network. Therefore, if you want to capture outbound flow traffic from VM1, you need to enable flow logging on an NSG associated with the subnet of VM1.

A company has an ExpressRoute gateway between their on-premises site and Azure. The ExpressRoute gateway is on a virtual network named VNet1. The company enables FastPath on the gateway. You associate a network security group (NSG) with all of the subnets.

Users report issues connecting to VM1 from the on-premises environment. VM1 is on a virtual network named VNet2. Virtual network peering is enabled between VNet1 and VNet2. You create a flow log named FlowLog1 and enable it on the NSG associated with the gateway subnet.

You discover that FlowLog1 is not reporting outbound flow traffic.

You need to resolve the issue with FlowLog1.

What should you do?

A.
Create the storage account for FlowLog1 as a premium block blob.
A.
Create the storage account for FlowLog1 as a premium block blob.
Answers
B.
Create the storage account for FlowLog1 as a premium page blob.
B.
Create the storage account for FlowLog1 as a premium page blob.
Answers
C.
Enable FlowLog1 in a network security group associated with the subnet of VM1.
C.
Enable FlowLog1 in a network security group associated with the subnet of VM1.
Answers
D.
Configure the FlowTimeoutInMinutes property on VNet1 to a non-null value.
D.
Configure the FlowTimeoutInMinutes property on VNet1 to a non-null value.
Answers
Suggested answer: C

Explanation:

when FastPath is enabled on an ExpressRoute gateway, network traffic between your on-premises network and your virtual network bypasses the gateway and goes directly to virtual machines in the virtual network. Therefore, if you want to capture outbound flow traffic from VM1, you need to enable flow logging on an NSG associated with the subnet of VM1.

A company has an Azure Active Directory (Azure AD) tenant. The company provisions an Azure Active Directory Domain Services (Azure AD DS) instance. Users report that they are unable to sign into Azure AD DS after being provisioned from Azure AD.

You verify the user accounts exist in Azure AD DS.

You need to resolve the issue.

What should you do?

A.
Delete the Azure application named AzureActiveDirectoryDomainControllerServices and then enable Azure AD DS again.
A.
Delete the Azure application named AzureActiveDirectoryDomainControllerServices and then enable Azure AD DS again.
Answers
B.
Deploy Azure AD Connect.
B.
Deploy Azure AD Connect.
Answers
C.
Delete the Azure application named Azure AD Domain Services Sync and then enable Azure AD DS again.
C.
Delete the Azure application named Azure AD Domain Services Sync and then enable Azure AD DS again.
Answers
D.
Instruct the users to change their password in Azure AD.
D.
Instruct the users to change their password in Azure AD.
Answers
Suggested answer: B

Explanation:


A company has users in Azure Active Directory (Azure AD). The company enables the users to use Azure AD multi-factor authentication (MFA). A user named User1 reports they receive the following error while setting up additional security verification settings for MFA:

Sorry! We can't process your request. Your session is invalid or expired. There was an error processing your request because your session is invalid or expired. Please try again. You need to help the user complete the MFA setup.

What should you do?

A.
From the Microsoft 365 Admin portal, clear the Block this user from signing in option for the user.
A.
From the Microsoft 365 Admin portal, clear the Block this user from signing in option for the user.
Answers
B.
Instruct the user to complete the setup process within 10 minutes.
B.
Instruct the user to complete the setup process within 10 minutes.
Answers
C.
Instruct the user to enter the correct verification code.
C.
Instruct the user to enter the correct verification code.
Answers
D.
Instruct the user to clear their web browser cache.
D.
Instruct the user to clear their web browser cache.
Answers
E.
From the Azure AD portal, reset the user's password.
E.
From the Azure AD portal, reset the user's password.
Answers
Suggested answer: B

Explanation:


A company has an Azure Active Directory (Azure AD) tenant. The company deploys Azure AD Connect to synchronize objects from their Active Directory Domain Services (AD DS) domain. You observe that AD DS objects are not synchronizing to Azure AD.

You need to verify that the staging mode is enabled.

What should you do?

A.
Review the history for the Azure AD Connect sync scheduled task.
A.
Review the history for the Azure AD Connect sync scheduled task.
Answers
B.
Run this PowerShell cmdlet: Get-ADSyncScheduler
B.
Run this PowerShell cmdlet: Get-ADSyncScheduler
Answers
C.
Review the triggers for the Azure AD Connect sync scheduled task.
C.
Review the triggers for the Azure AD Connect sync scheduled task.
Answers
D.
Run this PowerShell cmdlet: Get-ADSyncConnetorRunStatus
D.
Run this PowerShell cmdlet: Get-ADSyncConnetorRunStatus
Answers
Suggested answer: B

Explanation:

Azure AD Connect has a staging mode feature that allows you to install multiple sync servers for high availability or disaster recovery purposes. When staging mode is enabled on a sync server, it doesn’t export any changes to Azure AD or your on-premises AD DS environment.

To verify that staging mode is enabled on a sync server, you can run the Get-ADSyncScheduler PowerShell cmdlet and check the value of StagingModeEnabled property. If it is True, then staging mode is enabled and no synchronization will occur.

A company has on-premises application server that runs in System Center Virtual Machine Manager (SCVMM). The company configures Azure Site Recovery.

An administrator at the company reports that they receive an error message. The error message indicates that there are replication issues. You need to troubleshoot the issue.

Which log should you review?

A.
Network Security Group flow log
A.
Network Security Group flow log
Answers
B.
Azure Monitor log
B.
Azure Monitor log
Answers
C.
Network Watcher diagnostic log
C.
Network Watcher diagnostic log
Answers
D.
SCVMM debug log
D.
SCVMM debug log
Answers
Suggested answer: D

Explanation:

when you use Azure Site Recovery to replicate on-premises VMs that run in SCVMM, you need to check the SCVMM debug log for any errors or warnings related to replication. The SCVMM debug log is located at % SYSTEMDRIVE%\ProgramData\VMMLogs\SCVMM.debugtrace.log on the SCVMM server.

A company uses Azure Site Recovery (ASR) for a VMware environment that includes the following virtual machines (VMs):

The company reports that they are unable to configure all of the servers for replication.

You need to evaluate the servers and server roles to determine which servers can be protected.

Which server can you protect by using ASR?

A.
VM1
A.
VM1
Answers
B.
VM2
B.
VM2
Answers
C.
VM3
C.
VM3
Answers
D.
VM4
D.
VM4
Answers
Suggested answer: A

Explanation:

Azure Site Recovery supports replicating VMware VMs that meet certain requirements for operating system version, disk type and size, network adapter type and configuration, and so on. Based on the table of VMs and their properties, only VM1 meets all the requirements for replication

A company uses Azure Site Recovery (ASR) to replicate and recover Azure virtual machines (VM) between Azure regions. An administrator receives the following warning from ASR about a VM that uses P10 disks: Data change rate beyond supported limits You add OS Disk Write Bytes/Sec and Data Disk Write Bytes/Sec to the list of metrics for monitoring. You discover that the VM consistently has a data churn of greater than 8 MB/s but less than 10 MB/s.

You need to resolve the issue.

What should you do?

A.
Uninstall the Volume Shadow Copy Service (VSS) Provider service.
A.
Uninstall the Volume Shadow Copy Service (VSS) Provider service.
Answers
B.
Use AzCopy to upload data to a cache storage account.
B.
Use AzCopy to upload data to a cache storage account.
Answers
C.
Create a network service endpoint in a virtual network.
C.
Create a network service endpoint in a virtual network.
Answers
D.
Upgrade the target storage disk.
D.
Upgrade the target storage disk.
Answers
Suggested answer: D

Explanation:

Azure Site Recovery has limits on data change rates depending on the type of disk used for replication. If a VM has a data change rate higher than the supported limit for its disk type, it can cause replication issues or errors. To resolve this issue, you can upgrade the target storage disk to a higher tier that supports higher data change rates.

A company migrates an on-premises Windows virtual machine (VM) to Azure. An administrator enables backups for the VM by using the Azure portal. The company reports that the Azure VM backup job is failing.

You need to troubleshoot the issue.

What should you do?

A.
Create a new manual backup in Backup center.
A.
Create a new manual backup in Backup center.
Answers
B.
Run chkdsk on the VM.
B.
Run chkdsk on the VM.
Answers
C.
Configure the retention range of the current backup policy for the VM.
C.
Configure the retention range of the current backup policy for the VM.
Answers
D.
Install the VM guest agent with administrative permissions.
D.
Install the VM guest agent with administrative permissions.
Answers
E.
Enable replication and create a recovery plan for the backup vault.
E.
Enable replication and create a recovery plan for the backup vault.
Answers
Suggested answer: D

Explanation:

According to Microsoft Azure’s troubleshooting documentation, one of the steps to troubleshoot backup failures on Azure virtual machines is to check the Azure VM Guest Agent service health. You should ensure that the Azure VM Guest Agent service is started and up-to-date 1. On a Windows VM, you can navigate to services.msc and ensure that the Windows Azure VM Guest Agent service is up and running. Also, ensure that the latest version is installed 2

A company enables just-in-time (JIT) virtual machine (VM) access in Azure.

An administrator observes a list of VMs on the Unsupported tab of the JIT VM access page in the Microsoft Defender for Cloud portal. You need to determine why some VMs are not supported for JIT VM access.

What should you conclude?

A.
The administrator is using the Microsoft Defender for Cloud free tier.
A.
The administrator is using the Microsoft Defender for Cloud free tier.
Answers
B.
The VMs were provisioned by using a classic deployment.
B.
The VMs were provisioned by using a classic deployment.
Answers
C.
The VMs were recently provisioned by using an Azure Resource Manager deployment.
C.
The VMs were recently provisioned by using an Azure Resource Manager deployment.
Answers
D.
The administrator does not have the SecurityReader role.
D.
The administrator does not have the SecurityReader role.
Answers
Suggested answer: B

Explanation:

The Unsupported tab on the Just-in-Time VM access page in the Microsoft Defender for Cloud portal indicates that the VMs were provisioned by using a classic deployment Classic deployments were used in Azure before the deployment model was updated to Azure Resource Manager, which is now the preferred model for deploying and managing resources in Azure.

Total 119 questions
Go to page: of 12