New Year Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Microsoft AZ-303 Microsoft Azure Architect Technologies Exam Practice Test

Demo: 22 questions
Total 218 questions

Microsoft Azure Architect Technologies Questions and Answers

Question 1

You migrate WebApp1 to Azure.

You need toconfigure the AKS cluster to enable WebApp1 to access KV1. The solution must meet the authentication and authorization requirements.

What should you do?

Options:

A.

Configure Azure role-based access control (Azure R8AQ for KubernetesAuthorization.

B.

Configure a pod-managed identity.

C.

Implement pod security policies.

D.

Implement the Secrets Store CSl Driver.

Question 2

You need to deploy resources to RG1 by using the existing ARM templates. The solution must meet the deployment requirements.

What should you modify in the templates, and which cmdlet should you run to deploy the resources?

Options:

Question 3

You need to ensure that you can implement Azure AD Seamless SSO for Fabrikam. The solution must meet the following requirements:

  • Support the planned changes.
  • Meet the authentication and authorization requirements.

What should you do?

Options:

A.

Create a new Azure AD tenant namedfabrikam.com

B.

From the Fabrikam forest, configure an additional UPN suffix ofLitware.com.

C.

From the Fabrikam forest, configure all users to have a UPN suffixofLitware.com.

D.

From theLitware.comtenant, add a custom domain named fabrikam com.

Question 4

You need to ensure that the virtual machine disks are encrypted. The solution must meet the security requirements.

Which three actions should you perform in Sub1 in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Options:

Question 5

You need to configure Azure AD Seamless SSO for Fabrikam. The solution must meet the authentication and authorization requirements.

What should you install first?

Options:

A.

the Azure AD Connect provisioning agent on SERVER1

B.

the Azure AD Connect provisioning agent on DC1

C.

Azure AD Connect in staging mode on SERVER1

D.

an Azure AD Connect primary server on SERVER1

Question 6

You migrate WebApp1 to Azure.

You need to implementa traffic filtering solution for WebApp1. The solution must meet the security requirements.

What should you do?

Options:

A.

Configure the Threat intelligence settings for FW1.

B.

Deploy an Azure Application Gateway to VNet1.

C.

Deploy Azure Bastion to VNet1

D.

Configure an inbound rule on FW1.

Question 7

You plan to migrate WebApp1 to Azure.

You need to implement the AKS cluster that will host WebApp1. The solution must meet thedeployment requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE:Each correct selection is worth one point.

Options:

Question 8

You create and publish the BP1 blueprint.

You need to ensure that you can use BP1 to configure permissions for RG1. The solution must meet the authentication and authorization requirements.

What should you do?

Options:

A.

Add a read-only resource lock to Sub1.

B.

Assign an Azure role-based access control (Azure RBAC) role to Sub1.

C.

Assign an Azure role-based access control (Azure RBAC) role to BP1.

D.

Select the Read Only blueprint lock mode for the BP1 assignment.

Question 9

You need to recommend a solution to provide KV1 with access to the on-premises network of Litware. The solution must meet the security requirements.

What should you include in the recommendation? To answer, select the appropriate options in the answer area.

NOTE:Each correct selection is worth one point.

Options:

Question 10

You need to ensure that the NoSQL data is encrypted. The solution must meet the security requirements.

What should you do first?

Options:

A.

Upgrade storage2 to StorageV2 (general purpose v2).

B.

Create a new general-purpose v2 storage account.

C.

Create a new Azure Blob storage account.

D.

Modify the Encryption settings of storage2.

Question 11

You need to move the blueprint files to Azure.

What should you do?

Options:

A.

Generate a shared access signature (SAS). Map a drive, and then copy the files by using File Explorer.

B.

Use the Azure Import/Export service.

C.

Generate an access key. Map a drive, and then copy the files by using File Explorer.

D.

Use Azure Storage Explorer to copy the files.

Question 12

You have an Azure Active Directory (Azure AD) tenant.

You need to create a conditional access policy that requires all users to use multi-factorauthentication when they access the Azure portal.

Which three settings should you configure? To answer, select the appropriate settings to the answer area.

NOTE:Each correct selection is worth one point.

Options:

Question 13

You have an Azuresubscription named Sub1 that has a subscription ID of 12ab3cd4-5e67-8901-f234-g5hi67jkl8m9.

In Sub1, you create an Azure Storage account named storage1 and a table named Table1.

Which URI should you use to access Table1?

Options:

A.

https://storage.core.windons. net/12ab3cd4-5e67-8901-f234-g5hi67jkl8m9/storagel/table1

B.

https://sub1.core.windows.net/storagel/table1

C.

https://table1.table.core.windows.net/storage1

D.

https://storagel.table.core.windows.net/table1

Question 14

Youhave an Azure SQL database named DB1.

You plan to create the following four tables in DB1 by using the following code.

You need to identify which table must be created last.

What should you identify? To answer, select the appropriate options inthe answer area.

NOTE:Each correct selection is worth one point.

Options:

A.

Table1

B.

Table2

C.

Table3

D.

Table4

Question 15

ON NO: 3HOTSPOT

You have an Azure subscription that contains the resources shown in the following table.

You need to recommend an authorization mechanism for controlling access to blob1. The solution must ensure that access to blob1 can beconfigured without affecting the other resources in storage1.

What should you recommend? To answer, select the appropriate options in the answer area.

Options:

Question 16

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer aquestion in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure subscription.

You have an on-premises file server named Server1 that runs Windows Server 2019.

Youmanage Server1 by using Windows Admin Center.

You need to ensure that if Server1 fails, you can recover Server1 files from Azure.

Solution: You register Windows Admin Center in Azure and configure Azure Backup.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 17

Subnet1 contains a virtual appliance named VM1 that operates as a router.

You create a routing table namedRT1.

You need to route all inbound traffic to VNet1 through VM1.

How should you configure RT1? To answer, select the appropriate options in the answer area.

You have an Azure subscription that contains a virtual network named VNet1. VNet1 uses an IP address space of 10.0.0.0/16 and contains the subnets in the following table.

Options:

Question 18

You have an Azure subscription that contains the resources shown in the following table.

A certificate named Certificate! isstored in Vault1

You need to grant VM1 and VM2 access to Certificate1 by using the same security principal.

What should you do?

Options:

A.

Create an Azure Active Directory (Azure AD) user. Create an access policy for Vaultl. Assign the access policy to the user.Configure a user-assigned managed identity forVMl andVM2.

B.

Create a managed identity. Assign the Key Vault Reader role-based access control (RBAC) role for Vault 1 to the managed identity. Configure a system-assigned managed identity for VM1 and VM2.

C.

Create an Azure Active Directory (Azure AD) user. Assign the Key Vault Reader role-based access control (RBAC) role for Vaultl to the user. Configure a user-assigned managed identity for VM1 and VM2.

D.

Create a managed identity. Add the Vault1access policy to the managed identity. Configure a user-assigned managed identity for VM1 and VM2.

Question 19

You create a new Azure subscription. You create a resource group named RG1. In RG1. you create the resources shown in the following table.

You need to configure anencrypted tunnel between your on-premises network and VNET1.

Which two additional resources should you create in Azure? Each correct answer presents part of the solution.

Options:

A.

a point-to-site configuration

B.

a local network gateway

C.

a VNet-to-VNet connection

D.

a VPN gateway

E.

a site-to-site connection

Question 20

You have an Azure subscription.

You create a custom role in Azure by using the following Azure Resource Manager template.

You assign the role to a user namedUser1.

Which action can User1 perform?

Options:

A.

Delete virtual machines.

B.

Create resource groups.

C.

Create virtual machines.

D.

Create support requests

Question 21

You have Azure virtual machines that have Update Management enabled. The virtual machinesare configured as shown in the following table.

You need to ensure that all critical and security updates are applied to each virtual machine every month. What is the minimum number of update deployments you should create?

Options:

A.

4

B.

6

C.

1

D.

2

Question 22

You have an Azure Active Directory (Azure AD) tenant linked to an Azure subscription. The tenant contains a group named Admins.

You need toprevent users, except for the members of Admins, from using the Azure portal and Azure PowerShell to access the subscription.

What should you do?

Options:

A.

From Azure AD, configure the User settings.

B.

From the Azure subscription, assign an Azure policy.

C.

From Azure AD, create a conditional access policy.

D.

From the Azure subscription, configure Access control (IAM).

Demo: 22 questions
Total 218 questions