AZ-104試験無料問題集「Microsoft Azure Administrator 認定」
You have an Azure subscription that uses Azure Container Instances.
You have a computer that has Azure Command-Line Interface (CLI) and Docker installed.
You create a container image named image1.
You need to provision a new Azure container registry and add image1 to the registry.
Which command should you run for each requirement? To answer, select the options in the answer area NOTE: Each correct answer is worth one point.

Exhibit
You have a computer that has Azure Command-Line Interface (CLI) and Docker installed.
You create a container image named image1.
You need to provision a new Azure container registry and add image1 to the registry.
Which command should you run for each requirement? To answer, select the options in the answer area NOTE: Each correct answer is worth one point.

Exhibit
正解:

Explanation:
Detailed Explanation
' az acr create ' is the Azure CLI command that provisions a new Azure Container Registry resource; ' az acr build ' builds and pushes an image inside ACR Tasks rather than creating the registry, ' az container create ' provisions an ACI container group (not a registry), and ' docker create ' only creates a local container instance.
Once the registry exists and the local image is tagged with the registry ' s login server, ' docker push ' uploads (adds) the locally built image1 to the registry over the Docker Registry HTTP API; ' docker pull ' retrieves images instead of uploading them, and ' az acr create ' / ' az container create ' do not push local Docker images. This matches the documented CLI/Docker workflow for provisioning ACR and publishing an image.
Official Reference
Push and pull a container image to an Azure container registry - https://learn.microsoft.com/en-us/azure
/container-registry/container-registry-get-started-docker-cli
You have two Azure Resource Manager (ARM) templates named Template1 and Template2.
Deployments of Template1 currently fail because a virtual machine extension in Template1 depends on a resource referenced in Template2.
You need to ensure that Template1 and Template2 deploy together as a single transaction, and that if either deployment fails, the overall deployment fails. Both templates must remain separate and reusable.
What should you do?
Deployments of Template1 currently fail because a virtual machine extension in Template1 depends on a resource referenced in Template2.
You need to ensure that Template1 and Template2 deploy together as a single transaction, and that if either deployment fails, the overall deployment fails. Both templates must remain separate and reusable.
What should you do?
正解:C
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
You download an Azure Resource Manager template based on an existing virtual machine. The template will be used to deploy 100 virtual machines.
You need to modify the template to reference an administrative password. You must prevent the password from being stored in plain text.
What should you create to store the password?
You need to modify the template to reference an administrative password. You must prevent the password from being stored in plain text.
What should you create to store the password?
正解:A
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
You have a Microsoft Entra tenant that contains the groups shown in the following table.
The tenant contains the users shown in the following table.
Which users and groups can you delete? To answer, select the appropriate options in the answer area.
NOTE Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit
The tenant contains the users shown in the following table.
Which users and groups can you delete? To answer, select the appropriate options in the answer area.
NOTE Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit
正解:

Explanation:
Detailed Explanation
A user or group that currently carries an active license cannot be deleted without first removing that license, because deletion would immediately revoke the license from every dependent account. User1 and User3 each have a license assigned directly to them, so neither is deletable. User2 has no direct license, but is a member of Group1, which itself has an assigned license (i.e., is a group-based licensing source) - membership in a licensed group means User2 is effectively licensed too, so User2 is also not deletable. Only User4, which has neither a direct license nor membership in any licensed group, is safe to delete. For groups, the deciding factor is whether the group itself is the one holding the assigned license (deleting it would strip that license from its members): Group1 and Group3 both show ' Has an assigned license: Yes ' and cannot be deleted, while Group2 and Group4 show ' No ' and can be safely deleted regardless of their membership.
Official Reference
Group-based licensing in Microsoft Entra ID - https://learn.microsoft.com/en-us/entra/identity/users
/licensing-groups-assign
You have an Azure subscription that contains the virtual networks shown in the following table.
The subscription contains the virtual machines shown in the following table.
Each virtual machine contains only a private IP address.
You create an Azure bastion for VNet1 as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit

Exhibit
The subscription contains the virtual machines shown in the following table.
Each virtual machine contains only a private IP address.
You create an Azure bastion for VNet1 as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit

Exhibit
正解:

Explanation:
Detailed Explanation
Native client support (which allows mstsc.exe or the CLI/SSH client to connect through Bastion) is a Standard SKU-only feature; Basic SKU Bastion supports only the browser-based, in-portal HTML5 session, so mstsc.exe cannot be used against VM1 (No). Bastion supports connecting to VMs in regionally-peered virtual networks, and VNet1 (hosting Bastion1) is directly peered with VNet2, so the Azure portal ' s browser- based SSH session can reach VM2 (Yes). VNet peering is not transitive: VNet1 is peered only with VNet2, not with VNet3, so there is no network path from Bastion1 to VM3 even though VNet2 and VNet3 are peered with each other (No). All three statements match the source key.
Official Reference
Azure Bastion - Native client support and VNet peering connectivity - https://learn.microsoft.com/en-us
/azure/bastion/native-client
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure virtual machine named VM1. VM1 was deployed by using a custom Azure Resource Manager template named ARM1.json.
You receive a notification that VM1 will be affected by maintenance.
You need to move VM1 to a different host immediately.
Solution: From the Redeploy blade, you click Redeploy.
Does this meet the goal?
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure virtual machine named VM1. VM1 was deployed by using a custom Azure Resource Manager template named ARM1.json.
You receive a notification that VM1 will be affected by maintenance.
You need to move VM1 to a different host immediately.
Solution: From the Redeploy blade, you click Redeploy.
Does this meet the goal?
正解:B
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource groups.
Another administrator plans to create several network security groups (NSGs) in the subscription.
You need to ensure that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks.
Solution: You configure a custom policy definition, and then you assign the Azure policy to the subscription.
Does this meet the goal?
Another administrator plans to create several network security groups (NSGs) in the subscription.
You need to ensure that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks.
Solution: You configure a custom policy definition, and then you assign the Azure policy to the subscription.
Does this meet the goal?
正解:B
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
You have an Azure subscription that contains an Azure Storage account named storage1 and the users shown in the following table.
You plan to monitor storage1 and to configure email notifications for the signals shown in the following table.
You need to identify the minimum number of alert rules and action groups required for the planned monitoring.
How many alert rules and action groups should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit
You plan to monitor storage1 and to configure email notifications for the signals shown in the following table.
You need to identify the minimum number of alert rules and action groups required for the planned monitoring.
How many alert rules and action groups should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit
正解:

Explanation:
Detailed Explanation
Metric alert rules and Activity Log alert rules are structurally different alert types and cannot be combined into a single rule, and even within the same type, a single alert rule fires all of its actions for the same recipient set -- so each of the four signals (Ingress, Egress, Delete storage account, Restore blob ranges), having distinct type/recipient combinations, requires its own alert rule: 4 alert rules minimum. Action groups, however, can be reused across multiple alert rules whenever the recipient set is identical: Ingress and Restore blob ranges share the exact same recipients (User1 and User3 only) and can share one action group; Egress (User1 only) needs a second distinct action group; Delete storage account (User1, User2, User3) needs a third.
This yields 3 distinct action groups minimum, matching the source key.
Official Reference
Action groups in Azure Monitor - https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/action-groups
