Microsoft Azure Administrator (AZ-104日本語版) - AZ-104日本語 Free Exam Questions

QUESTION NO: 1
Sub1 という名前の Azure サブスクリプションがあり、そこには次の表に示すリソースが含まれています。
Sub1には以下のアラートルールが含まれています。
* 名前: アラート1
* 対象範囲: Sub1 内のすべてのリソース グループ
o 将来のリソースをすべて含める
* 条件: すべての管理業務
* アクション: アクション1
Sub1には、以下のアラート処理ルールが含まれています。
* 名前: ルール1
* 範囲: サブ1
* ルールタイプ: 通知を抑制
* ルールを適用する:特定の時間に
o スタン:2022年8月10日
終了日:2022年8月13日
以下の各記述について、正しい場合は「はい」を選択してください。そうでない場合は「いいえ」を選択してください。
注:正解ごとに1ポイントが加算されます。

展示する

展示する
Correct Answer:

Explanation:
Detailed Explanation
An alert processing rule configured to ' Suppress notifications ' only stops the associated action group(s) from firing - it does not prevent the underlying alert condition from being evaluated and fired, so Alert1 still appears as a fired alert in the Azure portal on August 11, 2022, even though it falls within the suppression window; statement 1 is Yes. On August 12, 2022, the resource-group creation (an administrative operation matching Alert1 ' s condition) still fires the alert, but because this date falls within Rule1 ' s suppression window (August 10-13, 2022), the Action1 email notification is suppressed - statement 2 is No. Adding a tag to RG1 on August 15, 2022 is also an administrative operation matching Alert1 ' s broad condition and scope, and August 15 falls entirely outside the August 10-13 suppression window, so the alert fires and Action1 ' s email is sent normally - statement 3 is Yes. This matches the source document ' s answer key.
Official Reference
Alert processing rules - Suppress notifications behavior - https://learn.microsoft.com/en-us/azure/azure- monitor/alerts/alerts-processing-rules
QUESTION NO: 2
Windows Server2016を実行するAzure仮想マシンが5つあります。仮想マシンはWebサーバーとして構成されています。
仮想マシンに負荷分散サービスを提供するLB1という名前のAzureロードバランサーがあります。
リクエストごとに、訪問者に同じWebサーバーがサービスを提供するようにする必要があります。
何を設定する必要がありますか?

Correct Answer: B Vote an answer
Explanation: Only visible for Actual4test members. You can sign-up / login (it's free).
QUESTION NO: 3
お客様はAzureサブスクリプションとMicrosoft Entra ID P1ライセンスをお持ちです。
以下の操作を実行する必要があります。
* すべてのユーザーに対してセルフサービスパスワードリセット(SSPR)を有効にする。
SSPRへの登録時に、ユーザーに4つの質問に回答してもらうようにする。
どの2つの設定を使用すべきですか?回答するには、回答欄で適切な設定を選択してください。
注:正解ごとに1ポイントが加算されます。

展示する
Correct Answer:

Explanation:
Detailed Explanation
SSPR configuration in Microsoft Entra ID is split across two blades: Properties, where the ' Self service password reset enabled ' control is set to None, Selected, or All - selecting All is required to enable SSPR for every user in the tenant; and Authentication methods (the registration/methods blade), where each authentication method is enabled and, specifically for the Security questions method, an admin sets ' Number of questions required to register ' (3-5, so 4 is valid) and a separate ' Number of questions required to reset ' .
Administrator Policy governs admin-specific SSPR behavior (not standard users), and Audit logs/Usage & insights are reporting-only views with no configurable settings. Therefore the two settings to modify are Properties and Authentication methods.
Official Reference
Enable self-service password reset - https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial- enable-sspr
QUESTION NO: 4
あなたは5台の仮想マシンを仮想ネットワークサブネットにデプロイする予定です。
各仮想マシンには、パブリックIPアドレスとプライベートIPアドレスが割り当てられます。
各仮想マシンには、同じ受信および送信セキュリティルールが必要です。
必要なネットワークインターフェースとネットワークセキュリティグループの最小数はいくつですか?回答するには、回答欄で適切なオプションを選択してください。
注:正解ごとに1ポイントが加算されます。

展示する
Correct Answer:

Explanation:
Detailed Explanation
Each virtual machine requires exactly one NIC to carry both its private IP address and an associated public IP address (a NIC IP configuration supports one private and one public IP simultaneously), so five VMs require a minimum of five NICs - you cannot share a NIC across VMs. Because all five VMs require identical inbound and outbound security rules, a single NSG is sufficient: that one NSG can be associated with either the subnet or all five NICs, and its rule set applies uniformly to every attached resource. There is no requirement to create a separate NSG per VM when the rule sets are identical, so the minimum is 1, not 5.
Official Reference
Network security groups overview - https://learn.microsoft.com/en-us/azure/virtual-network/network- security-groups-overview
QUESTION NO: 5
ストレージアカウント「storage1」を含むAzureサブスクリプションがあります。storage1アカウントには「container!」という名前のコンテナが含まれています。container1へのアクセスを構成する必要があります。ソリューションは以下の要件を満たす必要があります。
* 読み取りアクセスのみを許可する
* HTTPとHTTPSの両方のプロトコルを許可する。
コンテナ内のすべてのコンテンツにアクセス権限を適用する
何を使うべきでしょうか?

Correct Answer: A Vote an answer
Explanation: Only visible for Actual4test members. You can sign-up / login (it's free).
QUESTION NO: 6
storage1 という名前の Azure ストレージ アカウントがあり、その中に container 1 と container2 という名前の 2 つのコンテナがあります。両方のコンテナで Blob バージョン管理が有効になっています。
重要なブロブのスナップショットを定期的に取得します。
次のライフサイクル管理ポリシーを作成します。
以下の各記述について、記述が正しい場合は「はい」を選択してください。そうでない場合は「いいえ」を選択してください。
注:正解ごとに1ポイントが加算されます。

展示する

展示する
Correct Answer:

Explanation:
CORRECTED ANSWER: Statement 1: No. Statement 2: No. Statement 3: Yes.
Detailed Explanation
The policy ' s actions are nested under the ' version ' key, not ' snapshot ' ; a lifecycle rule ' s action set applies only to the blob category it is defined under, so this rule governs blob VERSIONS and does not affect SNAPSHOTS at all - statement 1 is corrected from Yes to No, since snapshots are unaffected by a version- scoped rule. Statement 2 is No because the rule ' s prefixMatch filter is ' container1/ ' , restricting scope to blobs whose path begins with container1; blobs in container2 are excluded entirely, so no tiering occurs there regardless of age. Statement 3 is corrected from No to Yes: Microsoft Learn documents that daysAfterLastTierChangeGreaterThan exists specifically ' to prevent [rehydrated blobs] from being moved back to the archive tier ' too soon after rehydration - after the configured 7-day minimum holding period elapses (and the 30-day creation threshold is met), the policy will automatically re-archive a rehydrated version. The source document ' s original key (Yes/No/No) is corrected on statements 1 and 3.
Official Reference
Optimize costs by automating Blob Storage access tiers - daysAfterLastTierChangeGreaterThan -
https://learn.microsoft.com/en-us/azure/storage/blobs/lifecycle-management-policy-configure
QUESTION NO: 7
お客様は、以下の図に示すストレージアカウントを含むAzureサブスクリプションをお持ちです。
図に示された情報に基づいて、各記述を完成させる選択肢をドロップダウンメニューを使用して選択してください。
注:正解ごとに1ポイントが加算されます。

展示する

展示する
Correct Answer:

Explanation:
Detailed Explanation
Azure Storage enforces a hard limit of 5 stored access policies per container; with Policy1 and Policy2 already defined, only 3 more can be created. For container-level immutability (WORM), Azure Storage supports exactly two policy types per container at once - one time-based retention policy and one legal hold
- and they can coexist. Since container1 already has a time-based retention policy, only one more immutability policy (a legal hold) can be added, giving a maximum of 1 additional. These are hard platform limits, not permissions issues, and both dropdown values shown in the exhibit (3 and 1) are already highlighted and match the documented limits, so no correction is required.
Official Reference
Define a stored access policy / Configure immutability policies for containers - https://learn.microsoft.com
/en-us/azure/storage/blobs/immutable-policy-configure-container-scope
QUESTION NO: 8
storage1という名前のAzureストレージアカウントをお持ちです。
Azure App Service 上に app1 という名前のアプリと、Azure コンテナー インスタンスで実行される App2 という名前のアプリがあります。それぞれのアプリはマネージド ID を使用しています。
App1とApp2が今後30日間、storage1からBLOBを読み取ることができるようにする必要があります。
各アプリについて、storage1でどのような設定を行うべきですか?

展示する
Correct Answer:

Explanation:
Detailed Explanation
For App1, the Azure-recommended, credential-less way to grant a web app ' s managed identity read access to blob data is via Access control (IAM), assigning the built-in Storage Blob Data Reader role to the identity ' s service principal - this avoids managing keys and can be scoped/revoked at any time, satisfying the 30-day window by removing the assignment later. For App2 running in Container Instances, direct Azure AD
/managed-identity based data-plane access to Storage requires custom in-container code to request and present a token, which is not the standard configuration path; the practical approach is to configure a Shared Access Signature scoped to Read on the container/blobs with an explicit 30-day expiry, handed to App2. Access keys grant unscoped full account access (not least privilege) and Advanced security only enables Defender for Storage threat detection, not access grants.
Official Reference
Authorize access to blob data with managed identities for Azure resources - https://learn.microsoft.com/en- us/azure/storage/common/storage-auth-aad-msi
QUESTION NO: 9
財務部門の監査担当者には、どの刃を使うように指示すべきでしょうか?

Correct Answer: B Vote an answer
Explanation: Only visible for Actual4test members. You can sign-up / login (it's free).
QUESTION NO: 10
RG1 という名前のリソース グループを含む Azure サブスクリプションをお持ちです。
リソースをデプロイするために、template1 という名前の Azure Resource Manager (ARM) テンプレートを使用する予定です。ソリューションは、以下の要件を満たす必要があります。
RG1に新しいリソースをデプロイします。
RG1では、テンプレートで指定されていないリソースを削除します。
コマンドをどのように完了すればよいですか?

展示する
Correct Answer:

Explanation:
Detailed Explanation
The -ResourceGroupName parameter specifies which resource group the deployment targets (RG1), satisfying the requirement to deploy new resources into RG1 - the -Name, -QueryString, and -Tag parameters are unrelated to targeting a resource group. The -Mode parameter controls how ARM reconciles existing resources: Incremental (the default) only adds or updates resources defined in the template and leaves all other pre-existing resources in the resource group untouched, while Complete mode deletes any resource in the target resource group that is not defined in the template, in addition to deploying what is defined. Since the requirement explicitly demands deleting resources in RG1 that aren ' t specified in the template, -Mode Complete is required; Incremental (the default, and visually highlighted in the exhibit ' s dropdown) would fail that requirement, and ' All ' is not a valid value for -Mode.
Official Reference
Azure Resource Manager deployment modes - https://learn.microsoft.com/en-us/azure/azure-resource- manager/templates/deployment-modes
QUESTION NO: 11
注:この問題は、同じシナリオを提示する一連の問題の一部です。このシリーズの各問題には、提示された目標を満たす可能性のある独自の解答が含まれています。問題セットによっては、複数の正解がある場合もあれば、正解がない場合もあります。
このセクションの質問に回答すると、後から戻って回答することはできません。そのため、これらの質問は復習画面には表示されません。
お客様にはcontoso.comという名前のMicrosoft Entraテナントがあります。
500人の外部ユーザーの名前とメールアドレスが記載されたCSVファイルがあります。
500人の外部ユーザーそれぞれについて、contoso.comにゲストユーザーアカウントを作成する必要があります。
解決策:Azure ポータルの Microsoft Entra ID から、「ユーザーの一括招待」操作を使用します。
これは目標を達成していると言えるでしょうか?

Correct Answer: B Vote an answer
Explanation: Only visible for Actual4test members. You can sign-up / login (it's free).
QUESTION NO: 12
Azure サブスクリプションには、Workspace 1 と Workspace? という名前の 2 つの Log Analytics ワークスペースと、Windows Server を実行する 100 台の仮想マシンが含まれています。
仮想マシンからパフォーマンスデータとイベントを収集する必要があります。ソリューションは以下の要件を満たす必要があります。
* ログは Workspace! と Workspace? に送信する必要があります。
* すべてのWindowsイベントをキャプチャする必要があります
* すべてのセキュリティイベントを記録する必要があります。
各仮想マシンには何をインストールし、設定すべきでしょうか?

Correct Answer: A Vote an answer
Explanation: Only visible for Actual4test members. You can sign-up / login (it's free).

QUALITY AND VALUE

Actual4test Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.

Tested and Approved

We are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.

Easy to Pass

If you prepare for the exams using our Actual4test testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.

Try Before Buy

Actual4test offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.