Azure Administrator (AZ-104) Practice Exam
Practice questions for the Microsoft Azure Administrator (AZ-104) certification: Microsoft Entra users, groups, licenses, external users and SSPR; Azure RBAC, Azure Policy, resource locks, tags, subscriptions, management groups and cost management; storage security, SAS, redundancy, replication, blob tiers and lifecycle, and Azure Files; ARM templates and Bicep, virtual machines, disks, availability, scale sets, containers and App Service; virtual networks, peering, routing, NSGs and ASGs, Azure Bastion, private endpoints, Azure DNS and load balancing; and Azure Monitor, Network Watcher, Azure Backup and Azure Site Recovery. Every question includes a written explanation.
100 questions · 12 free preview
Studying more than one? All Microsoft Azure exams for $29 · every exam for $79
Free sample questions
- Sample · question 1 · Elevate Global Administrator access
The Global Administrator at Beacon Hill Nursing can manage Microsoft Entra ID but cannot see several Azure subscriptions created by another team. She needs temporary access to manage role assignments in all subscriptions and management groups in the tenant. What should she do?
- A.Assign herself the Billing Administrator role
- B.Turn on Access management for Azure resources in the Microsoft Entra ID properties to elevate her accesscorrect
- C.Create a new management group and move the subscriptions into it
- D.Invite herself as a guest user to each subscription
Why: Enabling Access management for Azure resources elevates a Global Administrator to the User Access Administrator role at root scope, allowing her to view and assign access to all subscriptions and management groups; it should be turned off after use. Billing roles do not grant RBAC permissions, and she cannot move subscriptions she has no access to. Guest invitations apply to users from other tenants.
Open this question on its own page → - Sample · question 2 · Registering a resource provider
A deployment of an Azure Container Apps environment to a new subscription at Fallowfield Studios fails with an error stating that the subscription is not registered to use the Microsoft.App namespace. What should you do?
- A.Register the Microsoft.App resource provider in the subscriptioncorrect
- B.Assign the Reader role at the subscription scope
- C.Move the subscription to a different management group
- D.Remove all resource locks from the subscription
Why: Resource types are offered by resource providers, which must be registered in a subscription before their resources can be deployed there. Registering Microsoft.App resolves the error. The Reader role grants no deployment rights, and management groups and locks are unrelated to provider registration.
Open this question on its own page → - Sample · question 3 · Static website hosting in Storage
Marigold Bakery wants to host a small static marketing site made of HTML, CSS, and image files directly from Azure Storage without deploying a web server. What should you configure?
- A.An Azure file share with anonymous SMB access
- B.A lifecycle management rule for the Hot tier
- C.Static website hosting on a general-purpose v2 account, then upload the files to the $web containercorrect
- D.A page blob mounted as a virtual hard disk
Why: Static website hosting serves content from a special container named $web through a web endpoint for the storage account. File shares serve SMB or NFS clients rather than browsers, lifecycle rules manage tiering, and page blobs are designed for disk-like random access.
Open this question on its own page → - Sample · question 4 · Secure transfer required setting
A security review at Ardent Logistics finds that some legacy scripts access a storage account over HTTP. The account must reject all requests that do not use HTTPS. Which storage account setting should you enable?
- A.Allow Blob anonymous access
- B.Hierarchical namespace
- C.Large file shares
- D.Secure transfer requiredcorrect
Why: When Secure transfer required is enabled, the storage account rejects REST requests made over HTTP and SMB connections without encryption. Anonymous access controls unauthenticated reads, hierarchical namespace enables Data Lake Storage features, and large file shares raise file share capacity limits.
Open this question on its own page → - Sample · question 5 · Spot VMs for interruptible workloads
Quillan Research runs a large batch rendering job that can tolerate interruptions and restart from checkpoints. The team wants to reduce compute costs by using unused Azure capacity, accepting that VMs may be evicted. Which option should you use?
- A.Azure Spot Virtual Machinescorrect
- B.Reserved VM instances for one year
- C.Dedicated hosts
- D.VMs in a proximity placement group
Why: Azure Spot VMs use spare capacity at a significant discount and can be evicted when Azure needs the capacity back, which suits interruptible batch jobs. Reservations require a term commitment for steady workloads, dedicated hosts provide physical server isolation, and proximity placement groups reduce latency between VMs.
Open this question on its own page → - Sample · question 6 · Proximity placement groups
A trading application at Kestwick Capital runs on several VMs that exchange large amounts of data and require the lowest possible network latency between them within a region. What should you use?
- A.Availability zones with one VM per zone
- B.A proximity placement groupcorrect
- C.Azure Site Recovery
- D.A NAT gateway
Why: A proximity placement group keeps Azure compute resources physically close to each other, minimizing network latency. Spreading VMs across availability zones increases resilience but also increases latency. Site Recovery provides disaster recovery, and a NAT gateway handles outbound internet connectivity.
Open this question on its own page → - Sample · question 7 · App Service Always On
A web app at Pinehurst Library that runs in the Basic tier of App Service responds slowly to the first request after long idle periods because the app is unloaded. What should you enable?
- A.Deployment slots
- B.ARR affinity
- C.Always Oncorrect
- D.HTTPS Only
Why: Always On keeps the app loaded by sending regular requests, preventing it from being unloaded after inactivity, and it is available in the Basic tier and above. Deployment slots support staged deployments, ARR affinity keeps clients on the same instance, and HTTPS Only redirects HTTP traffic.
Open this question on its own page → - Sample · question 8 · Regional service tags in NSG rules
VMs in the snet-data subnet at Lowther Mining must be allowed outbound access only to Azure Storage in the East US region, and the rule must adapt automatically when Microsoft changes the service's IP ranges. What should you use as the destination in the outbound NSG rule?
- A.An application security group containing the storage account
- B.The public IP address of the storage account
- C.The VirtualNetwork service tag
- D.The Storage.EastUS service tagcorrect
Why: Service tags represent groups of IP prefixes for Azure services and are maintained by Microsoft, and regional tags such as Storage.EastUS limit the scope to one region. ASGs contain VM network interfaces, not PaaS services. A single public IP address is not stable or complete for a service, and VirtualNetwork covers your own address space.
Open this question on its own page → - Sample · question 9 · NAT gateway for predictable outbound IP
VMs at Hartfield Legal have no public IP addresses and are placed in the snet-batch subnet. A partner requires all outbound internet connections from these VMs to come from a single, predictable public IP address that it can add to an allow list. What should you configure?
- A.An internal load balancer with a private frontend IP
- B.A private endpoint on snet-batch
- C.A service endpoint for Microsoft.Web on snet-batch
- D.A NAT gateway with a static public IP address associated with snet-batchcorrect
Why: A NAT gateway associated with a subnet provides outbound internet connectivity for its VMs by translating their traffic to the NAT gateway's public IP addresses or prefixes, giving the partner a fixed source address. An internal load balancer has no public address. Private and service endpoints provide access to Azure services and do not give outbound internet traffic a fixed public IP.
Open this question on its own page → - Sample · question 10 · Azure DNS alias record at apex
Wexford Gardens hosts its website behind a public IP address in Azure and uses Azure DNS for the zone wexfordgardens.example. The team wants the zone apex record to follow the public IP resource automatically if its address changes and to avoid dangling records if the IP is deleted. What should you create?
- A.A CNAME record at the zone apex
- B.An alias A record at the zone apex that references the public IP resourcecorrect
- C.A TXT record containing the IP address
- D.A private DNS zone linked to the website's virtual network
Why: Alias records in Azure DNS reference an Azure resource such as a public IP address, update automatically when its address changes, and prevent dangling records when the resource is deleted. CNAME records are not allowed at the zone apex. TXT records do not resolve addresses, and private zones do not serve internet clients.
Open this question on its own page → - Sample · question 11 · Metric alerts with dynamic thresholds
Response times for an application at Corbin Freight follow a weekly pattern, making static alert thresholds noisy. You want a metric alert that learns historical behavior and flags deviations automatically. What should you configure?
- A.A log search alert with a fixed threshold
- B.An activity log alert for administrative operations
- C.A metric alert rule that uses dynamic thresholdscorrect
- D.A Service Health alert
Why: Dynamic thresholds use machine learning on a metric's history, including seasonal patterns, to calculate expected ranges and alert on deviations. A fixed threshold is exactly what causes the noise. Activity log alerts track control-plane events, and Service Health alerts cover Azure platform incidents.
Open this question on its own page → - Sample · question 12 · Service Health alerts
Administrators at Ferrisdale Hotels want to be emailed when an Azure service incident or planned maintenance affects the services and regions they use. What should you create?
- A.A Service Health alert with an action groupcorrect
- B.An Azure Advisor recommendation digest
- C.A Connection monitor test
- D.A budget alert in Cost Management
Why: Service Health alerts notify you, through action groups, about service issues, planned maintenance, and health advisories that affect your subscriptions' services and regions. Advisor digests summarize recommendations, Connection monitor tests your own network paths, and budget alerts track spending.
Open this question on its own page →
Like the sample?
Other practice exams
- AnthropicClaude Certified Architect — Foundations100 questions · $19
- CompTIACompTIA Security+ (SY0-701)100 questions · $19
- ISC2CISSP100 questions · $19
- DatabricksDatabricks Data Engineer Associate100 questions · $19
- DatabricksDatabricks Data Engineer Professional100 questions · $19
- Google CloudGoogle Cloud Associate Cloud Engineer100 questions · $19
- Google CloudGoogle Cloud Professional Cloud Architect100 questions · $19
- Google CloudGoogle Cloud Professional Data Engineer100 questions · $19
- HashiCorpTerraform Associate (004)100 questions · $19
- Microsoft Power BI & FabricPower BI Data Analyst (PL-300)100 questions · $19
- Microsoft Power BI & FabricFabric Analytics Engineer (DP-600)100 questions · $19
- SnowflakeSnowPro Core (COF-C03)250 questions · $19
- SnowflakeSnowPro Advanced: Data Engineer100 questions · $19
- SnowflakeSnowPro Advanced: Architect100 questions · $19
- AWSAWS Cloud Practitioner (CLF-C02)100 questions · $19
- AWSAWS Solutions Architect Associate (SAA-C03)100 questions · $19
- AWSAWS AI Practitioner (AIF-C01)100 questions · $19
- Microsoft AzureAzure Fundamentals (AZ-900)100 questions · $19
- Microsoft AzureAzure AI Fundamentals (AI-901)100 questions · $19
- Microsoft AzureAzure Solutions Architect Expert (AZ-305)100 questions · $19