It is more faster and easier to pass the AZ-301 Exam Dumps by using AZ-301 Braindumps. Immediate access to the AZ-301 Dumps Questions and find the same core area AZ-301 Dumps Questions with professionally verified answers, then PASS your exam with a high score now.
Microsoft AZ-301 Free Dumps Questions Online, Read and Test Now.
NEW QUESTION 1
You have an on-premises network that uses on IP address space of 172.16.0.0/16 You plan to deploy 25 virtual machines to a new azure subscription.
You identity the following technical requirements.
All Azure virtual machines must be placed on the same subnet subnet1.
All the Azure virtual machines must be able to communicate with all on premises severs.
The servers must be able to communicate between the on-premises network and Azure by using a site to site VPN.
You need to recommend a subnet design that meets the technical requirements.
What should you include in the recommendation? To answer, drag the appropriate network addresses to the correct subnet. Each network address may be used once, more than once or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation: 
NEW QUESTION 2
You have an Azure subscription that contains a custom application named Application was developed by an external company named fabric, Ltd. Developers at Fabrikam were assigned role-based access control (RBAV) permissions to the Application components. All users are licensed for the Microsoft 365 E5 plan.
You need to recommends a solution to verify whether the Faricak developers still require permissions to Application1. The solution must the following requirements.
* To the manager of the developers, send a monthly email message that lists the access permissions to Application1.
* If the manager does not verify access permission, automatically revoke that permission.
* Minimize development effort. What should you recommend?
- A. Create an Azure Automation runbook that the Get-AureADUSAppRoleAssigmety cmdlet.
- B. In azure Active directory (Azure AD) create an access review of application1.
- C. In Azure Active Directory (AD) privileged identity Managed, create a custom roles assignment for the Application 1 resources.
- D. Create an Azure Automation runbook that runs the get-AzureRaRolesAssigned cmdlet.
Answer: A
NEW QUESTION 3
You need to recommend a solution for configuring the Azure Multi-Factor Authentication (MFA) settings. What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Answer:
Explanation: References:
https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-sign-in-risk-policy https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-mfa-policy
NEW QUESTION 4
You need to deploy resources to host a stateless web app in an Azure subscription. The solution must meet the following requirements:
• Provide access to the full .NET framework.
• Provide redundancy if an Azure region fails.
• Grant administrators access to the operating system to install custom application dependencies.
Solution: You deploy an Azure virtual machine to two Azure regions, and you deploy an Azure Application Gateway.
Does this meet the goal?
- A. Yes
- B. No
Answer: B
NEW QUESTION 5
Your company has 300 virtual machines hosted in a VMWare environment. The virtual machines vary in size and have various utilization levels.
You plan to move all the virtual machines to Azure.
You need to recommend how many and what size Azure virtual machines will be required to move the current workloads to Azure. The solution must minimize administrative effort.
What should you use to make the recommendation?
- A. Azure Cost Management
- B. Azure Migrate
- C. Azure pricing calculator
- D. Azure Advisor recommendations
Answer: A
NEW QUESTION 6
You are designing a container solution in azure that will include two containers. One container will host a web API that will be available to the public. The other container will perform health monitoring of the web API and will remain private. The two containers will be deployed together as a group.
You need to recommend a compute service for the containers. The solution must minimize costs and maintenance over head.
What should you include in the recommendation?
- A. Azure container instances
- B. Azure container Service
- C. Azure kubernetes service (aks)
- D. Azure service fabric
Answer: A
Explanation: References:
https://docs.microsoft.com/en-us/azure/container-instances/container-instances-container-groups
NEW QUESTION 7
You have an on-premises Active Directory forest and an Azure Active Directory (Azure AD) tenant. All Azure AD users are assigned a Premium P1 license.
You deploy Azure AD Connect.
Which two features are available in this environment that can reduce operational overhead for your company’s help desk? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
- A. Azure AD Privileged Identity Management policies
- B. access reviews
- C. self-service password reset
- D. Microsoft Cloud App Security Conditional Access App Control
- E. password writeback
Answer: CE
NEW QUESTION 8
You manage a single-domain, on-premises Active Directory for named contoso.com. The forest functional level is window Server 2021.
You have several on-premises applications that depend on Active Directory. You plan to migrate the applications to Azure.
You need to recommend an identity solution for the appkcatkms. The solution mufl meet the following requirements:
• Eliminate the need for hybrid network connectivity
• Minimize management overhead for Active Directory. What should you recommend?
- A. In Azure, deploy additional domain controllers for the contoso.com domain
- B. In Azure, deploy an additional child domain to the contoso.com forest.
- C. Implement Azure Active Directory Domain Services (Azure AD DS).
- D. Implement a new Acuve Directory forest in Azure.
Answer: A
NEW QUESTION 9
You have an Azure environment that contains the Azure subscription and the virtual networks shown in the following table.
You need to recommend a virtual network peering solution to ensure that the resources connected to any other virtual network. The solution must minimize administrative effort.
Which virtual network peering topology should you recommend? To answer, select the appropriate topology in the answer area.
NOTE: Each correct selection is worth one point,
Answer:
Explanation: 
NEW QUESTION 10
You have five .NET Core applications that run on 10 Azure virtual machines in the same subscription.
You need to recommend a solution to ensure that the applications can authenticate by using the same Azure Active Directory (Azure AD) identity. The solution must meet the following requirements:
Ensure that the applications can authenticate only when running on the 10 virtual machines.
Minimize administrative effort.
What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Answer:
Explanation: 
NEW QUESTION 11
What should you include in the identity management strategy to support the planned changes?
- A. Move all the domain controllers from corp.fabrikam.com to virtual networks in Azure.
- B. Deploy domain controllers for corp.fabrikam.com to virtual networks in Azure.
- C. Deploy a new Azure AD tenant for the authentication of new R&D projects.
- D. Deploy domain controllers for the rd.fabrikam.com forest to virtual networks in Azure.
Answer: B
Explanation: Directory synchronization between Azure Active Directory (Azure AD) and corp.fabrikam.com must not be affected by a link failure between Azure and the on-premises network. (This requires domain controllers in Azure)
Users on the on-premises network must be able to authenticate to corp.fabrikam.com if an Internet link fails. (This requires domain controllers on-premises)
Topic 2, Mix Questions
NEW QUESTION 12
You are planning to deploy an application by using the Azure Kubermets Services (AKS)> the application will reedy on having access to an encryption key that will be used to ... transmit files
What should you use to provides the encryption key AKS security?
- A. secrets
- B. Azure Storage Service Encryption
- C. a Kubernetes deployment YAML file
- D. ConfigureMap
Answer: C
NEW QUESTION 13
Your company has 20 web APIs that were developed in-house.
The company is developing 10 web apps that will use the web APIs. The web apps and the APIs are registered in the company’s Azure Active Directory (Azure AD) tenant. The web APIs are published by using Azure API Management.
You need to recommend a solution to block unauthorized requests originating from the web apps from reaching the web APIs. The solution must meet the following requirements:
Use Azure AD-generated claims.
Minimize configuration and management effort.
What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Answer:
Explanation: 
NEW QUESTION 14
You are designing a software as a service (SaaS) application that will enable Azure Active Directory (Azure AD) users to create and publish surveys. The SaaS application will have a front-end web app and a back-end web API. The web app will rely on the web API to handle updates to customer surveys.
You need to design an authorization flow for the SaaS application. The solution must meet the following requirements:
To access the back-end web API, the web app must authenticate by using OAuth 2 bearer tokens.
The web app must authenticate by using the identities of individual users.
What should you include in the solution? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Answer:
Explanation: References:
https://docs.microsoft.com/lb-lu/azure/architecture/multitenant-identity/web-api https://docs.microsoft.com/en-us/azure/active-directory/develop/quickstart-v1-dotnet-webapi
NEW QUESTION 15
You need to recommend a notification solution for the IT Support distribution group. What should you include in the recommendation?
- A. Azure Network Watcher
- B. an action group
- C. a SendGrid account with advanced reporting
- D. Azure AD Connect Health
Answer: D
Explanation: References:
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-operations
NEW QUESTION 16
You store web access logs data in Azure Blob storage. You plan to generate monthly reports from the access logs.
You need to recommend an automated process to upload the data to Azure SQL Database every month. What should you include in the recommendation?
- A. Microsoft SQL Server Migration Assistant (SSMA)
- B. Azure Data Factory
- C. Data Migration Assistant
- D. AzCopy
Answer: C
NEW QUESTION 17
You have standard Load balancer configured to support three virtual machines on the same subnet. You need to recommend a solution to notify administrators when the load balancer fails.
Which metrics should you recommend using to test the load balancer? To answer, drag the appropriate metrics to the correct conditions. Each metric may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOT: Each correct selection is worth one point.
Answer:
Explanation: 
P.S. Easily pass AZ-301 Exam with 108 Q&As 2passeasy Dumps & pdf Version, Welcome to Download the Newest 2passeasy AZ-301 Dumps: https://www.2passeasy.com/dumps/AZ-301/ (108 New Questions)
