AZ-104 PDF Dumps-2026-Microsoft AZ-104 Exam Dumps(597-607)
Questions and Answers PDF
Vendor: Microsoft
Exam Code: AZ-104
Exam Name: Microsoft Azure Administrator
New Updated Questions from Braindump2go (Updated in April/2026)
Visit Braindump2go and Download Full Version AZ-104 Exam Dumps
QUESTION 597
You have a subnet named Subnet1 that contains Azure virtual machines. A network security group (NSG) named NSG1 is associated to Subnet1. NSG1 only contains the default rules. You need to create a rule in NSG1 to prevent the hosts on Subnet1 form connecting to the Azure portal. The hosts must be able to connect to other internet hosts.
To what should you set Destination in the rule?
A. Application security group
B. IP Addresses
C. Service Tag
D. Any
Answer: C
Explanation:
You can use service tags to achieve network isolation and protect your Azure resources from the general Internet while accessing Azure services that have public endpoints. Create inbound/outbound network security group rules to deny traffic to/from Internet and allow traffic to/from AzureCloud or other available service tags of specific Azure services.
You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. VNet1 is in a resource group named RG1.
Subscription1 has a user named User1. User1 has the following roles:
- Reader
- Security Admin
- Security Reader
You need to ensure that User1 can assign the Reader role for VNet1 to other users. What should you do?
A. Remove User1 from the Security Reader role for Subscription1. Assign User1 the Contributor role for RG1.
B. Assign User1 the User Access Administrator role for VNet1.
C. Remove User1 from the Security Reader and Reader roles for Subscription1.
D. Assign User1 the Contributor role for VNet1.
Answer: B
Explanation:
Has full access to all resources including the right to delegate access to others.
Note:
There are several versions of this question in the exam. The question has two possible correct answers:
- Assign User1 the User Access Administrator role for VNet1.
- Assign User1 the Owner role for VNet1.
Other incorrect answer options you may see on the exam include the following:
- Assign User1 the Contributor role for VNet1.
- Remove User1 from the Security Reader and Reader roles for Subscription1. Assign User1 the Contributor role for Subscription1.
- Remove User1 from the Security Reader role for Subscription1. Assign User1 the Contributor role for RG1. Reference: https://docs.microsoft.com/en-us/azure/role-based-access-control/overview
QUESTION 600
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure Active Directory (Azure AD) tenant named contoso.com. You have a CSV file that contains the names and email addresses of 500 external users. You need to create a guest user account in contoso.com for each of the 500 external users.
Solution: From Azure AD in the Azure portal, you use the Bulk invite users operation. Does this meet the goal?
A. Yes
B. No
Answer: B
Explanation:
This implies that the required fields (Email and Redirection URL)are missing from the .csv file. Here are the csv field pre-requisites that are needed for bulk upload of external users: https://learn.microsoft.com/en-us/azure/active-directory/external-identities/tutorial-bulk-invite#prerequisites
QUESTION 601
You have an Azure AD tenant named adatum.com that contains the groups shown in the following table.
Questions and Answers PDF
Adatum.com contains the users shown in the following table.
You assign the Azure Active Directory Premium Plan 2 license to Group1 and User4. Which users are assigned the Azure Active Directory Premium Plan 2 license?
A. User4 only
B. User1 and User4 only
C. User1, User2, and User4 only
D. User1, User2, User3, and User4
Answer: B
Explanation:
https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/licensing-group-advanced Under Limitations and known issues: "Group-based licensing currently does not support groups that contain other groups (nested groups). If you apply a license to a nested group, only the immediate first-level user members of the group have the licenses applied."
QUESTION 602
Hotspot Question
You have an Azure subscription that contains the users shown in the following table.
The groups are configured as shown in the following table.
You have a resource group named RG1 as shown in the following exhibit.
Questions and Answers PDF
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Box 1: No
Role-assignable groups are designed to help prevent potential breaches by having the following restrictions: Group nesting isn't supported. A group can't be added as a member of a role-assignable group.
Box 2: No
M365 groups cant be added to membership of another group.
Box 3: Yes
The statement is not complete but if it states to assign the role to Group3 directly it is possible. https://learn.microsoft.com/en-us/azure/active-directory/roles/groups-concept#restrictions-for-role-assignable-groups
QUESTION 603
Your on-premises network contains a VPN gateway. You have an Azure subscription that contains the resources shown in the following table.
Questions and Answers PDF
You need to ensure that all the traffic from VM1 to storage1 travels across the Microsoft backbone network. What should you configure?
A. Azure Application Gateway
B. private endpoints
C. a network security group (NSG)
D. Azure Virtual WAN
Answer: B
Explanation:
You can use private endpoints for your Azure Storage accounts to allow clients on a virtual network (VNet) to securely access data over a Private Link. The private endpoint uses a separate IP address from the VNet address space for each storage account service. Network traffic between the clients on the VNet and the storage account traverses over the VNet and a private link on the Microsoft backbone network, eliminating exposure from the public internet. Link: https://learn.microsoft.com/en-us/azure/storage/common/storage-private-endpoints
QUESTION 604
Hotspot Question
You have an Azure subscription that contains a user named User1 and the resources shown in the following table.
NSG1 is associated to networkinterface1. User1 has role assignments for NSG1 as shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Answer:
Questions and Answers PDF
Explanation:
Box 1: Yes
User1 can create a storage account in RG1, since User1 has Storage Account Contribute Role inherited from Resource Group.
Box 2: No
User1 can view all resources, but does not allow to make any changes. https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#reader
Box 3: Yes
User1 can create an inbound security rule to filter inbound traffic to networkinterface1, since User1 has Contributor role for NSG1.
QUESTION 605
Hotspot Question
You have three Azure subscriptions named Sub1, Sub2, and Sub3 that are linked to an Azure AD tenant. The tenant contains a user named User1, a security group named Group1, and a management group named MG1. User is a member of Group1.
Sub1 and Sub2 are members of MG1. Sub1 contains a resource group named RG1. RG1 contains five Azure functions. You create the following role assignments for MG1:
- Group1: Reader
- User1: User Access Administrator
You assign User the Virtual Machine Contributor role for Sub1 and Sub2. For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Questions and Answers PDF
Box 1: Yes
GROUP1 Reader access, provides access to view all items, except secrets. https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#reader
Box 2: Yes
To Assign OWNER role, you need to either Owner role or User Administrator Access Role. https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal-subscriptionadmin#prerequisites
Box 3: No
Neither User Access Admin Role nor the Reader Role allows to create new resources. https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-steps
QUESTION 606
Hotspot Question
You have an Azure subscription. The subscription contains a storage account named storage1 that has the lifecycle management rules shown in the following table.
On June 1, you store two blobs in storage1 as shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Answer:
Explanation:
On June 6, File1 will be in archive because File1 is in container 1, and rule 1 applies 3 days after june 1.
Questions and Answers PDF
On June 1, File2 will still be in Hot tier because File2 is in container2, Rule3 and Rule4 havent hit yet. On June 16, File2 will be deleted because Rule3 applies 10 days after June 1.
QUESTION 607
Drag and Drop Question
You have an Azure subscription that contains a virtual machine named VM1. You need to back up VM1. The solution must ensure that backups are stored across three availability zones in the primary region.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
You have an Azure subscription named Subscription1. You have 5 TB of data that you need to transfer to Subscription1. You plan to use an Azure Import/Export job. What can you use as the destination of the imported data?
A. an Azure Cosmos DB database
B. Azure File Storage
C. Azure SQL Database
D. a virtual machine
Answer: B
Explanation:
Azure Import/Export service is used to securely import large amounts of data to Azure Blob storage and Azure Files by shipping disk drives to an Azure datacenter.
The maximum size of an Azure Files Resource of a file share is 5 TB.
Note:
There are several versions of this question in the exam. The question has two correct answers:
1. Azure File Storage
2. Azure Blob Storage
The question can have other incorrect answer options, including the following: