[Jan 21, 2022] Free Azure Solutions Architect Expert AZ-303 Official Cert Guide PDF Download [Q108-Q124]

Share

[Jan 21, 2022] Free Azure Solutions Architect Expert AZ-303 Official Cert Guide PDF Download

Microsoft AZ-303 Official Cert Guide PDF


Microsoft AZ-303: Prerequisites

This certification exam has no official prerequisites. However, the learners must understand its objectives. They also need to possess advanced knowledge and expertise in IT operations, including networking, business continuity, data platform, virtualization, security, budgeting, identity, disaster recovery, and governance. They should also have competence in managing the decision-making processes and identifying how they affect the overall designed solutions. The candidates should also possess the expert-level expertise in Azure administration as well as DevOps processes and Azure development.

 

NEW QUESTION 108
Your company has a virtualization environment that contains the virtualization hosts shown in the following table.

The virtual machines are configured as shown in the following table.

All the virtual machines use basic disks. VM1 is protected by using BitLocker Drive Encryption (BitLocker).
You plan to migrate the virtual machines to Azure by using Azure Site Recovery.
You need to identify which virtual machines can be migrated.
Which virtual machines should you identify for each server? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Incorrect Answers:
VM1 cannot be migrates as it has BitLocker enabled.
VM2 cannot be migrates as the OS disk on VM2 is larger than 2TB.
VMC cannot be migrates as the Data disk on VMC is larger than 4TB.
References:
https://docs.microsoft.com/en-us/azure/site-recovery/hyper-v-azure-support-matrix#azure-vm-requirements

 

NEW QUESTION 109
You have an Azure subscription that contains the resources shown in the following table.

Subnet1 is on VNET1. VM1 connects to Subnet1.
You plan to create a virtual network gateway on VNET1.
You need to prepare the environment for the planned virtual network gateway.
What should you do?

  • A. Modify the address space used by VNET1.
  • B. Modify the address space used by Subnet1.
  • C. Create a local network gateway.
  • D. Delete Subnet1.
  • E. Create a subnet named GatewaySubnet on VNET1.

Answer: A

Explanation:
Section: [none]

 

NEW QUESTION 110
HOTSPOT
You have an Azure Active Directory (Azure AD) tenant named contoso.com. The tenant contains the users shown in the following table.

The tenant contains computers that run Windows 10. The computers are configured as shown in the following table.

You enable Enterprise State Roaming in contoso.com for Group1 and GroupA.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Answer:

Explanation:

Section: [none]
Explanation:
Enterprise State Roaming provides users with a unified experience across their Windows devices and reduces the time needed for configuring a new device.
Box 1: Yes
Box 2: No
Box 3: Yes
Reference:
https://docs.microsoft.com/en-us/azure//////active-directory/devices/enterprise-state-roaming-overview

 

NEW QUESTION 111
You have virtual machines (VMs) that run a mission-critical application.
You need to ensure that the VMs never experience down time.
What should you recommend? To answer, drag the appropriate solutions to the correct scenarios. Each solution may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

References:
https://docs.microsoft.com/en-us/azure/virtual-machines/windows/tutorial-create-vmss
https://docs.microsoft.com/en-us/azure/virtual-machines/windows/tutorial-availability-sets

 

NEW QUESTION 112
Your company hosts multiple websites by using Azure virtual machine scale sets (VMSS) that run Internet Information Server (IIS).
All network communications must be secured by using end to end Secure Socket Layer (SSL) encryption. User sessions must be routed to the same server by using cookie-based session affinity.
The image shown depicts the network traffic flow for the websites to the VMSS.

Use the drop-down menus to select the answer choice that answers each question.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Azure Application Gateway
You can create an application gateway with URL path-based redirection using Azure PowerShell.
Box 2: Path-based redirection and Websockets
Reference:
https://docs.microsoft.com/bs-latn-ba/azure//application-gateway/tutorial-url-redirect-powershell

 

NEW QUESTION 113
You have an on-premises server that runs Windows Server 2019 and hosts a web app named App1.
You have an Azure subscription named Subscription1.
You plan to migrate App1 to Subsciption1 by using Azure Migrate.
To which type of Azure service will App1 be migrated, and what should you provide during the migration? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/learn/modules/migrate-app-service-migration-assistant/6-exercise-migration

 

NEW QUESTION 114
You have an Azure subscription that contains 20 virtual machines. The virtual machines require authenticated access to several Azure resources.
You need to ensure that the virtual machines can authenticate by using Azure Active Directory (Azure AD).
Solution: You configure the Identity settings for each virtual machine.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

 

NEW QUESTION 115
You have two Azure SQL Database managed instances in different Azure regions.
You plan to configure the managed instances in an instance failover group.
What should you configure before you can add the managed instances to the instance failover group?

  • A. Azure Private Link that has endpoints on two virtual networks
  • B. a Site-to-Site VPN between the virtual networks that contain the instances
  • C. an internal Azure Load Balancer instance that has managed instance endpoints in a backend pool
  • D. an Azure Application Gateway that has managed instance endpoints in a backend pool

Answer: B

Explanation:
Section: [none]
Explanation:
For two managed instances to participate in a failover group, there must be either ExpressRoute or a gateway configured between the virtual networks of the two managed instances to allow network communication.
You create the two VPN gateways and connect them.
1. Create the gateway for the virtual network of your primary managed instance using the Azure portal.
2. Create the gateway for the virtual network of your secondary managed instance using the Azure portal.
3. Create a bidirectional connection between the two gateways of the two virtual networks.
Reference:
https://docs.microsoft.com/en-us/azure/azure-sql/managed-instance/failover-group-add-instance-tutorial?
tabs=azure-portal#4---create-a-primary-gateway
Question Set 1

 

NEW QUESTION 116
You have the following Azure Active Directory (Azure AD) tenants:
* Contoso.onmicrosoft.com: Linked to a Microsoft 365 tenant and syncs to an Active Directory forest named contoso.com by using password hash synchronization
* Contosoazure.onmicrosoft.com: Linked to an Azure subscription named Subscription1 You need to ensure that you can assign the users in contoso.com access to the resources in Subscription1.
What should you do?

  • A. Create an Azure management group that contains Subscription1.
  • B. Deploy a second Azure AD Connect server and sync contoso.com to contosoazure.onmicrosoft.com.
  • C. Create guest accounts for all the contoso.com users in contosoazure.onmicrosoft.com.
  • D. Configure the existing Azure AD Connect server to sync contoso.com to contosoazure.onmicrosoft.com.

Answer: B

Explanation:
Section: [none]
Explanation:
Azure AD Connect allows you to quickly onboard to Azure AD and Office 365.
In this topology, one Azure AD Connect sync server is connected to each Azure AD tenant. The Azure AD Connect sync servers must be configured for filtering so that each has a mutually exclusive set of objects to operate on. You can, for example, scope each server to a particular domain or organizational unit.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies

 

NEW QUESTION 117
You have an Azure key vault named KV1.
You need to ensure that applications can use KV1 to provision certificates automatically from an external certification authority (CA).
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Obtain the root CA certificate.
  • B. From KV1, create a certificate issuer resource.
  • C. From KV1, create a private key,
  • D. Obtain the CA account credentials.
  • E. From KV1, create a certificate signing request (CSR).

Answer: A,E

Explanation:
Explanation
C: Obtain the root CA certificate (step 4 in the picture below)
D: From KV1, create a certificate signing request (CSR) (step 2 in the picture below) Note:
Creating a certificate with a CA not partnered with Key Vault
This method allows working with other CAs than Key Vault's partnered providers, meaning your organization can work with a CA of its choice.

The following step descriptions correspond to the green lettered steps in the preceding diagram.
* In the diagram above, your application is creating a certificate, which internally begins by creating a key in your key vault.
* Key Vault returns to your application a Certificate Signing Request (CSR).
* Your application passes the CSR to your chosen CA.
* Your chosen CA responds with an X509 Certificate.
* Your application completes the new certificate creation with a merger of the X509 Certificate from your CA.
Reference:
https://docs.microsoft.com/en-us/azure/key-vault/certificates/certificate-scenarios

 

NEW QUESTION 118
You have an Azure subscription that contains two virtual networks named VNet1 and VNet2. Virtual machines connect to the virtual networks.
The virtual networks have the address spaces and the subnets configured as shown in the following table.

You need to add the address space of 10.33.0.0/16 to VNet1. The solution must ensure that the hosts on VNet1 and VNet2 can communicate.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation:
Step 1: Remove peering between Vnet1 and VNet2.
You can't add address ranges to, or delete address ranges from a virtual network's address space once a virtual network is peered with another virtual network. To add or remove address ranges, delete the peering, add or remove the address ranges, then re-create the peering.
Step 2: Add the 10.44.0.0/16 address space to VNet1.
Step 3: Recreate peering between VNet1 and VNet2
References:
https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-manage-peering

 

NEW QUESTION 119
HOTSPOT
Your organization has developed and deployed several Azure App Service Web and API applications. The applications use Azure SQL Database to store and retrieve data. Several departments have the following requests to support the applications:

You need to recommend the appropriate Azure service for each department request.
What should you recommend? To answer, configure the appropriate options in the dialog box in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Answer:

Explanation:

Section: [none]
Explanation/Reference:
https://docs.microsoft.com/en-us/azure/sql-database/transparent-data-encryption-azure-sql

 

NEW QUESTION 120
HOTSPOT
Your company runs several Windows and Linux virtual machines (VMs).
You must design a solution that implements data privacy, compliance, and data sovereignty for all storage uses in Azure. You plan to secure all Azure storage accounts by using Role-Based Access Controls (RBAC) and Azure Active Directory (Azure AD).
You need to secure the data used by the VMs.
Which solution should you use? To answer, select the appropriate solutions in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Answer:

Explanation:

Section: [none]
Explanation/Reference:
References:
https://docs.microsoft.com/en-us/azure/security/security-storage-overview

 

NEW QUESTION 121
You network contains an Active Directory domain that is synced to Azure Active Directory (Azure AD) as shown in the following exhibit.

You have a user account configured as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: No
Password writeback is disabled.
Note: Having a cloud-based password reset utility is great but most companies still have an on-premises directory where their users exist. How does Microsoft support keeping traditional on-premises Active Directory (AD) in sync with password changes in the cloud? Password writeback is a feature enabled with Azure AD Connect that allows password changes in the cloud to be written back to an existing on-premises directory in real time.
Box 2: No
Box 3: Yes
Yes, there is an Edit link for Location Info.
References:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-writeback

 

NEW QUESTION 122
Your network contains an on-premises Active Directory and an Azure Active Directory (Azure AD) tenant.
You deploy Azure AD Connect and configure pass-through authentication?
Your Azure subscription contains several web apps that are accessed from the Internet.
You plan to enable Azure Multi-Factor Authentication (MFA) for the Azure tenant.
You need to recommend a solution to prevent users from being prompted for Azure MFA when they access the web apps from the on-premises network.
What should you include in the recommendation?

  • A. trusted IPs
  • B. an Azure ExpressRoute circuit
  • C. a site-to-site VPN between the on-premises network and Azure
  • D. an Azure policy

Answer: A

Explanation:
The Trusted IPs feature of Azure Multi-Factor Authentication is used by administrators of a managed or federated tenant. The feature bypasses two-step verification for users who sign in from the company intranet. The feature is available with the full version of Azure Multi-Factor Authentication, and not the free version for administrators.
References:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings#trusted-ips

 

NEW QUESTION 123
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure Active Directory (Azure AD) tenant named contoso.com.
A user named Admin1 attempts to create an access review from the Azure Active Directory admin center and discovers that the Access reviews settings are unavailable. Admin1 discovers that all the other Identity Governance settings are available.
Admin1 is assigned the User administrator, Compliance administrator, and Security administrator roles.
You need to ensure that Admin1 can create access reviews in contoso.com.
Solution: You create an access package.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

Explanation:
Section: [none]
Explanation:
You do not use access packages for Identity Governance. Instead use Azure AD Privileged Identity Management.
Note: PIM essentially helps you manage the who, what, when, where, and why for resources that you care about. Key features of PIM include:
Conduct access reviews to ensure users still need roles
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure
https://docs.microsoft.com/en-us/azure/active-directory/governance/entitlement-management-overview

 

NEW QUESTION 124
......


Microsoft AZ-303 Exam Syllabus Topics:

TopicDetails

Implement and Monitor an Azure Infrastructure (50-55%)

Implement cloud infrastructure monitoring- monitor security
- monitor performance
- monitor health and availability
- monitor cost
- configure advanced logging-initiate automated responses by using Action Groups
- configure and manage advanced alerts
Implement storage accounts- select storage account options based on a use case- configure Azure Files andAzure Blobstorage
- configure network access to the storage account
- implement Shared Access Signatures and access policies- implement Azure AD authentication for storage
- manage access keys
- implement Azure storage replication
- implement Azure storage account failover
Implement VMs for Windows and Linux- configure High Availability
- configure storage for VMs
- select virtual machine size
- implement Azure Dedicated Hosts
- deploy and configure scale sets
- configure Azure Disk Encryption
Automate deployment and configuration of resources- save a deployment as an Azure Resource Manager template- modify Azure Resource Manager template
- evaluate location of new resources
- configure aVHDtemplate
- deploy from a template
- managean imagelibrary
- create and execute an automation runbook
Implement virtual networking- implement VNet to VNet connections
- implement VNet peering
Implement Azure Active Directory- add custom domains
- configure Azure AD Identity Protection
- implement self-service password reset
- implement Conditional Access including MFA
- configure fraud alerts
- configure verification methods
- implement and manage guest accounts
- manage multiple directories
Implement and manage hybrid identities- install and configure Azure AD Connect
- identity synchronization options
- configure and manage password sync and password writeback
- configure single sign-on
-configure Azure AD Connect cloud sync
- use Azure AD Connect Health

Implement Management and Security Solutions (25-30%)

Manage workloads in Azure- migrate workloads using Azure Migrate
- implement Azure Backup forAzure workloads
- implement disaster recovery- implement AzureAutomationUpdate Management
Implement load balancing and network security- implement Azure Load Balancer
- implement anAzure Application Gateway
- implement Web Application Firewall
- implement Azure Firewall
- implement Azure Firewall Manager
- implement Azure Front Door
- implement Azure Traffic Manager
- implement Network Security Groups and Application Security Groups
- implement Bastion
Implement and manage Azure governance solutions- create and manage hierarchical structure that contains management groups, subscriptions and resource groups
- assign RBAC roles
- create a custom RBAC role
- configure access to Azure resources by assigning roles
- configure management access to Azure
- interpret effective permissions
- set up and perform an access review
- implement and configure Azure Policy
- implement and configure Azure Blueprints
Manage security for applications- implement and configure Key Vault
- implement and configure Managed Identities
- register and manage applications in Azure AD

Implement Solutions for Apps (10-15%)

Implement an application infrastructure- create and configure Azure App Service
- create an App Service Web App for Containers
- create and configure an App Service plan
- configure App Service- configure networking for App Service
- create and manage deployment slots
- implement Logic Apps
- implement Azure Functions
Implement container-based applications- create a container image
- configure Azure Kubernetes Service
- publish and automate imagemanagement by using the Azure Container Registry-deploya solution on an Azure Container Instance

 

Free AZ-303 Exam Dumps to Improve Exam Score: https://passguide.validtorrent.com/AZ-303-valid-exam-torrent.html