Implementing Microsoft Azure Infrastructure Solutions
Question No: 11 DRAG DROP
You plan to deploy an application by using three Azure virtual machines (VMs). The application has a web-based component that uses TCP port 443 and a custom component that uses UDP port 2020.
The application must be available during planned and unplanned Azure maintenance events. Incoming client requests must be distributed across the three VMs. Clients must be connected to a VM only if both application components are running.
You need to configure the VM environment.
For each requirement, what should you implement? To answer, drag the appropriate configuration type to the correct target. Each configuration type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Box 1: availability set.
Box 2: backend pool.
Question No: 12 HOTSPOT
You manage a public-facing web application which allows authenticated users to upload and download large files. On the initial public page there is a promotional video.
You plan to give users access to the site content and promotional video.
In the table below, identify the access method that should be used for the anonymous and authenticated parts of the application. Make only one selection in each column.
References: https://azure.microsoft.com/en-in/documentation/articles/storage-dotnet- shared-access-signature-part-1/
Question No: 13
Your company network includes an On-Premises Windows Active Directory (AD) that has a DNS domain named contoso.local and an email domain named contoso.com. You plan to migrate from On-Premises Exchange to Office 365.
You configure DirSync and set all Azure Active Directory (Azure AD) usernames as
You need to ensure that each user is able to log on by using the email domain as the username.
Which two actions should you perform? Each correct answer presents part of the solution.
Verify the email domain in Azure AD domains.
Run the Set-MsolUserPrincipalName -UserPrincipalName
%firstname.lastname@example.org -NewUserPrincipalName %username
%@contoso.com Power Shell cmdlet.
Edit the ProxyAddress attribute on the On-Premises Windows AD user account.
Verify the Windows AD DNS domain in Azure AD domains.
Update the On-Premises Windows AD user account UPN to match the email address.
Answer: A,B Explanation:
If you have already set up Active Directory synchronization, the user’s UPN may not match the user’s on-premises UPN defined in Active Directory. To fix this, rename the user’s UPN using the Set-MsolUserPrincipalName cmdlet in the Microsoft Azure Active Directory Module for Windows PowerShell.
The email domain (Contoso.com) needs to be verified in Office 365.
Question No: 14 DRAG DROP
You are an administrator for an Azure subscription that is used by your company.
You have an Azure Web App that contains static content accessed by users. You plan to deliver content based on geographic location. The solution must allow clients to connect to a URL that ends in your corporate domain name of adatum.com. You must use the information provided by the portal for your on-premises modifications.
You need to implement the components in Azure to support the above requirements.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Question No: 15
You are designing an Azure Web App that will use one worker role. The Web App does not use SQL Database.
You have the following requirements:
*Maximize throughput and system resource availability
*Minimize downtime during scaling
You need to recommend an approach for scaling the application. Which approach should you recommend?
Increase the role instance size.
Set up horizontal partitioning.
Increase the number of role instances.
Set up vertical partitioning.
Answer: C Explanation:
On the Scale page of the Azure Management Portal, you can manually scale your application or you can set parameters to automatically scale it. You can scale applications that are running Web Roles, Worker Roles, or Virtual Machines. To scale an application that is running instances of Web Roles or Worker Roles, you add or remove role instances to accommodate the work load.
References: http://azure.microsoft.com/en-gb/documentation/articles/cloud-services-how- to-scale/
Question No: 16
You administer an Azure SQL Database that runs in the S0 service tier. The database stored mission-critical data.
You must meet the following requirements:
-> minimize costs associated with hosting the database in Azure
-> minimize downtime in the event of an outage
-> protect the database from unplanned events
What should you do?
Implement a secondary database in the paired region.
Ensure that a secondary databases are online and readable at all times.
Create a continuously replicated copy.
Use backups in a geo-redundant Azure storage (GRS) location.
Answer: D Explanation:
Question No: 17
You are the administrator for your company’s Azure subscription.
Company policy dictates that you must deploy new Azure Resource Manager (ARM) templates using Azure Command-Line Interface (CLI). Parameters are included in a file called azuredeploy.parameters.json and do not contain any password information. All JSON files are located in the root of drive E.
You need to ensure that password parameters are passed to the command.
Which two commands are possible ways to achieve this goal? Each correct answer presents a complete solution.
Add the appropriate password parameters to the azuredeploy.parameters.json file and then run the following CLI command:azure group create -n 鈥淎RMBasic鈥?-l 鈥淲est US鈥?-f 鈥渆:\azuredeploy.json鈥?-e 鈥渆:\azuredeploy.parameters.json鈥?/p>
Run the following CLI command. Do not add additional switches:azure group create -n 鈥淎RMBasic鈥?-l 鈥淲est US鈥?-f 鈥渆:\azuredeploy.json鈥?-e 鈥渆:\azuredeploy.parameters.json鈥?/p>
Run the following CLI command. Add a switch to include password parameters:azure group create -n 鈥淎RMBasic鈥?-l 鈥淲est US鈥?-f 鈥渆:\azuredeploy.json鈥?/p>
Run the following CLI command. Add switches to include all parameters:azure group create -n 鈥淎RMBasic鈥?-l 鈥淲est US鈥?-f 鈥渆:\azuredeploy.json鈥?/p>
Question No: 18 DRAG DROP
You manage an Azure Web Site in Standard mode at the following address: contoso.azurewebsites.net.
Your company has a new domain for the site that needs to be accessible by Secure Socket
Layer (SSL) encryption.
You need to be able to add a custom domain to the Azure Web Site and assign an SSL certificate.
Which three steps should you perform next in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
More than one order of answer choices may be correct. You will receive credit for any of the correct orders you select
First create a CNAME record, then to add the domain name as a custom domain and last add the SNI SSL binding. The advantage of using a CNAME record and a SNI SSL binding is that it does not matter if the IP address of the website changes.
Question No: 19
You are an administrator of an Azure subscription for your company.
Management asks you to configure Azure permissions for a user in your Azure Active Directory (Azure AD). The user must be able to perform all actions on the virtual machines (VMs). The user must not be allowed to create and manage availability sets for the Vms.
You need to implement the required permissions with the least administrative effort. How should you assign permissions?
Use Windows PowerShell to assign the Classic Virtual Machine Contributor role to the user.
Use Windows PowerShell to create a custom role from the Virtual Machine Contributor role and then use NotActions to customize the role permissions.
Implement a custom role through the Azure Portal and customize the role by adding the appropriate permissions.
Assign the Virtual Machine Contributor role to the user.
Answer: A Explanation:
Question No: 20
You have an Azure subscription that contains a storage account named STOR1 and a container name CONTAINER1.
You need to monitor read access for the blobs inside CONTAINER1. The monitoring data must be retained for 10 days.
What should you do?
Run the Set-AzureStorageServiceMetricsProperty cmdlet.
Run the New-AzureStorageBlobSASToken cmdlet.
Run the Set-AzureStorageServiceLoggingProperty cmdlet.
Edit the blob properties of CONTAINER1.
Answer: C Explanation:
|Lowest Price Guarantee||Yes||No||No|
|Free VCE Simulator||Yes||No||No|