ExamGecko
Home / Microsoft / AZ-720 / List of questions
Ask Question

Microsoft AZ-720 Practice Test - Questions Answers, Page 6

Add to Whishlist

List of questions

Question 51

Report Export Collapse

A company has an ExpressRoute gateway between their on-premises site and Azure. The ExpressRoute gateway is on a virtual network named VNet1. The company enables FastPath on the gateway. You associate a network security group (NSG) with all of the subnets.

Users report issues connecting to VM1 from the on-premises environment. VM1 is on a virtual network named VNet2. Virtual network peering is enabled between VNet1 and VNet2. You create a flow log named FlowLog1 and enable it on the NSG associated with the gateway subnet.

You discover that FlowLog1 is not reporting outbound flow traffic.

You need to resolve the issue with FlowLog1.

What should you do?

Enable FlowLog1 in a network security group associated with the subnet of VM1.
Enable FlowLog1 in a network security group associated with the subnet of VM1.
Configure the FlowTimeoutInMinutes property on VNet2 to a non-null value.
Configure the FlowTimeoutInMinutes property on VNet2 to a non-null value.
Configure the FlowTimeoutInMinutes property on VNet1 to a non-null value.
Configure the FlowTimeoutInMinutes property on VNet1 to a non-null value.
Configure FlowLog1 for version 2.
Configure FlowLog1 for version 2.
Suggested answer: A
Explanation:

According to 2, when FastPath is enabled on an ExpressRoute gateway, network traffic between your on-premises network and your virtual network bypasses the gateway and goes directly to virtual machines in the virtual network. Therefore, if you want to capture outbound flow traffic from VM1, you need to enable flow logging on an NSG associated with the subnet of VM1.

asked 02/10/2024
Stergios Gaidatzis
45 questions

Question 52

Report Export Collapse

A company has an ExpressRoute gateway between their on-premises site and Azure. The ExpressRoute gateway is on a virtual network named VNet1. The company enables FastPath on the gateway. You associate a network security group (NSG) with all of the subnets.

Users report issues connecting to VM1 from the on-premises environment. VM1 is on a virtual network named VNet2. Virtual network peering is enabled between VNet1 and VNet2. You create a flow log named FlowLog1 and enable it on the NSG associated with the gateway subnet.

You discover that FlowLog1 is not reporting outbound flow traffic.

You need to resolve the issue with FlowLog1.

What should you do?

Create the storage account for FlowLog1 as a premium block blob.
Create the storage account for FlowLog1 as a premium block blob.
Create the storage account for FlowLog1 as a premium page blob.
Create the storage account for FlowLog1 as a premium page blob.
Enable FlowLog1 in a network security group associated with the subnet of VM1.
Enable FlowLog1 in a network security group associated with the subnet of VM1.
Configure the FlowTimeoutInMinutes property on VNet1 to a non-null value.
Configure the FlowTimeoutInMinutes property on VNet1 to a non-null value.
Suggested answer: C
Explanation:

when FastPath is enabled on an ExpressRoute gateway, network traffic between your on-premises network and your virtual network bypasses the gateway and goes directly to virtual machines in the virtual network. Therefore, if you want to capture outbound flow traffic from VM1, you need to enable flow logging on an NSG associated with the subnet of VM1.

asked 02/10/2024
Alejandro Ramirez Cuesta
39 questions

Question 53

Report Export Collapse

A company has an Azure Active Directory (Azure AD) tenant. The company provisions an Azure Active Directory Domain Services (Azure AD DS) instance. Users report that they are unable to sign into Azure AD DS after being provisioned from Azure AD.

You verify the user accounts exist in Azure AD DS.

You need to resolve the issue.

What should you do?

Delete the Azure application named AzureActiveDirectoryDomainControllerServices and then enable Azure AD DS again.
Delete the Azure application named AzureActiveDirectoryDomainControllerServices and then enable Azure AD DS again.
Deploy Azure AD Connect.
Deploy Azure AD Connect.
Delete the Azure application named Azure AD Domain Services Sync and then enable Azure AD DS again.
Delete the Azure application named Azure AD Domain Services Sync and then enable Azure AD DS again.
Instruct the users to change their password in Azure AD.
Instruct the users to change their password in Azure AD.
Suggested answer: B
Explanation:


asked 02/10/2024
loveneel kataria
35 questions

Question 54

Report Export Collapse

A company has users in Azure Active Directory (Azure AD). The company enables the users to use Azure AD multi-factor authentication (MFA). A user named User1 reports they receive the following error while setting up additional security verification settings for MFA:

Sorry! We can't process your request. Your session is invalid or expired. There was an error processing your request because your session is invalid or expired. Please try again. You need to help the user complete the MFA setup.

What should you do?

From the Microsoft 365 Admin portal, clear the Block this user from signing in option for the user.
From the Microsoft 365 Admin portal, clear the Block this user from signing in option for the user.
Instruct the user to complete the setup process within 10 minutes.
Instruct the user to complete the setup process within 10 minutes.
Instruct the user to enter the correct verification code.
Instruct the user to enter the correct verification code.
Instruct the user to clear their web browser cache.
Instruct the user to clear their web browser cache.
From the Azure AD portal, reset the user's password.
From the Azure AD portal, reset the user's password.
Suggested answer: B
Explanation:


asked 02/10/2024
Duane Joyce
41 questions

Question 55

Report Export Collapse

A company has an Azure Active Directory (Azure AD) tenant. The company deploys Azure AD Connect to synchronize objects from their Active Directory Domain Services (AD DS) domain. You observe that AD DS objects are not synchronizing to Azure AD.

You need to verify that the staging mode is enabled.

What should you do?

Review the history for the Azure AD Connect sync scheduled task.
Review the history for the Azure AD Connect sync scheduled task.
Run this PowerShell cmdlet: Get-ADSyncScheduler
Run this PowerShell cmdlet: Get-ADSyncScheduler
Review the triggers for the Azure AD Connect sync scheduled task.
Review the triggers for the Azure AD Connect sync scheduled task.
Run this PowerShell cmdlet: Get-ADSyncConnetorRunStatus
Run this PowerShell cmdlet: Get-ADSyncConnetorRunStatus
Suggested answer: B
Explanation:

Azure AD Connect has a staging mode feature that allows you to install multiple sync servers for high availability or disaster recovery purposes. When staging mode is enabled on a sync server, it doesn’t export any changes to Azure AD or your on-premises AD DS environment.

To verify that staging mode is enabled on a sync server, you can run the Get-ADSyncScheduler PowerShell cmdlet and check the value of StagingModeEnabled property. If it is True, then staging mode is enabled and no synchronization will occur.

asked 02/10/2024
Channa Leang
46 questions

Question 56

Report Export Collapse

A company has on-premises application server that runs in System Center Virtual Machine Manager (SCVMM). The company configures Azure Site Recovery.

An administrator at the company reports that they receive an error message. The error message indicates that there are replication issues. You need to troubleshoot the issue.

Which log should you review?

Network Security Group flow log
Network Security Group flow log
Azure Monitor log
Azure Monitor log
Network Watcher diagnostic log
Network Watcher diagnostic log
SCVMM debug log
SCVMM debug log
Suggested answer: D
Explanation:

when you use Azure Site Recovery to replicate on-premises VMs that run in SCVMM, you need to check the SCVMM debug log for any errors or warnings related to replication. The SCVMM debug log is located at % SYSTEMDRIVE%\ProgramData\VMMLogs\SCVMM.debugtrace.log on the SCVMM server.

asked 02/10/2024
David Clark
46 questions

Question 57

Report Export Collapse

A company uses Azure Site Recovery (ASR) for a VMware environment that includes the following virtual machines (VMs):

Microsoft AZ-720 image Question 33 88135 10022024015601000000

The company reports that they are unable to configure all of the servers for replication.

You need to evaluate the servers and server roles to determine which servers can be protected.

Which server can you protect by using ASR?

VM1
VM1
VM2
VM2
VM3
VM3
VM4
VM4
Suggested answer: A
Explanation:

Azure Site Recovery supports replicating VMware VMs that meet certain requirements for operating system version, disk type and size, network adapter type and configuration, and so on. Based on the table of VMs and their properties, only VM1 meets all the requirements for replication

asked 02/10/2024
Adam Beke
42 questions

Question 58

Report Export Collapse

A company uses Azure Site Recovery (ASR) to replicate and recover Azure virtual machines (VM) between Azure regions. An administrator receives the following warning from ASR about a VM that uses P10 disks: Data change rate beyond supported limits You add OS Disk Write Bytes/Sec and Data Disk Write Bytes/Sec to the list of metrics for monitoring. You discover that the VM consistently has a data churn of greater than 8 MB/s but less than 10 MB/s.

You need to resolve the issue.

What should you do?

Uninstall the Volume Shadow Copy Service (VSS) Provider service.
Uninstall the Volume Shadow Copy Service (VSS) Provider service.
Use AzCopy to upload data to a cache storage account.
Use AzCopy to upload data to a cache storage account.
Create a network service endpoint in a virtual network.
Create a network service endpoint in a virtual network.
Upgrade the target storage disk.
Upgrade the target storage disk.
Suggested answer: D
Explanation:

Azure Site Recovery has limits on data change rates depending on the type of disk used for replication. If a VM has a data change rate higher than the supported limit for its disk type, it can cause replication issues or errors. To resolve this issue, you can upgrade the target storage disk to a higher tier that supports higher data change rates.

asked 02/10/2024
Nipunika Jayasundara
42 questions

Question 59

Report Export Collapse

A company migrates an on-premises Windows virtual machine (VM) to Azure. An administrator enables backups for the VM by using the Azure portal. The company reports that the Azure VM backup job is failing.

You need to troubleshoot the issue.

What should you do?

Create a new manual backup in Backup center.
Create a new manual backup in Backup center.
Run chkdsk on the VM.
Run chkdsk on the VM.
Configure the retention range of the current backup policy for the VM.
Configure the retention range of the current backup policy for the VM.
Install the VM guest agent with administrative permissions.
Install the VM guest agent with administrative permissions.
Enable replication and create a recovery plan for the backup vault.
Enable replication and create a recovery plan for the backup vault.
Suggested answer: D
Explanation:

According to Microsoft Azure’s troubleshooting documentation, one of the steps to troubleshoot backup failures on Azure virtual machines is to check the Azure VM Guest Agent service health. You should ensure that the Azure VM Guest Agent service is started and up-to-date 1. On a Windows VM, you can navigate to services.msc and ensure that the Windows Azure VM Guest Agent service is up and running. Also, ensure that the latest version is installed 2

asked 02/10/2024
Sharos Ramcharan
28 questions

Question 60

Report Export Collapse

A company enables just-in-time (JIT) virtual machine (VM) access in Azure.

An administrator observes a list of VMs on the Unsupported tab of the JIT VM access page in the Microsoft Defender for Cloud portal. You need to determine why some VMs are not supported for JIT VM access.

What should you conclude?

The administrator is using the Microsoft Defender for Cloud free tier.
The administrator is using the Microsoft Defender for Cloud free tier.
The VMs were provisioned by using a classic deployment.
The VMs were provisioned by using a classic deployment.
The VMs were recently provisioned by using an Azure Resource Manager deployment.
The VMs were recently provisioned by using an Azure Resource Manager deployment.
The administrator does not have the SecurityReader role.
The administrator does not have the SecurityReader role.
Suggested answer: B
Explanation:

The Unsupported tab on the Just-in-Time VM access page in the Microsoft Defender for Cloud portal indicates that the VMs were provisioned by using a classic deployment Classic deployments were used in Azure before the deployment model was updated to Azure Resource Manager, which is now the preferred model for deploying and managing resources in Azure.

asked 02/10/2024
Richard lavery
43 questions
Total 119 questions
Go to page: of 12
Search

Related questions