AZ-104

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/331

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

332 Terms

1
New cards

This type of group in Azure is used to secure resources and add users, groups, devices as members ...

Security groups

2
New cards

This type of group in azure is used for shared mailboxes, calendars, SharePoint collections, and other 365 resources...

365 group

3
New cards

Dynamic user or dynamic devices require what type of license?

Azure AD premium P1

4
New cards

This group type has assignment set automatically based on attributes such as department, job title, account attributes, devices, Etc...

Dynamic group

5
New cards

what are the three azure AD device joint types?

Registered, joined, hybrid joined

6
New cards

This azure AD join type allows multiple devices and operating systems (PC, MAC, iOS, Android) to be added to azure AD. The device can be user or org-owned...

Azure registered

7
New cards

This azure AD join type is an org owned device added to azure ad , possibly authenticating to your on prem AD. The only devices that can join this way are Windows 10 /11 devices...

Azure joined

8
New cards

This Azure AD join type is an org device added to azure AD as well as an on Prem AD. The device can authenticate to azure or AD, either or. Older Windows versions such as 7 and 8 .1 can be joined this way...

Azure Hybrid joined

9
New cards

Self service password reset (SSPR) is available for what Azure AD license?

Premium P1

10
New cards

An Azure subscription will only be associated with one and only one....

Entra ID Tenant

11
New cards

Enter ID tenant can be associated with more than one...

Azure subscription

12
New cards

Privileged identity management and identity protection is included with what azure subscription type?

Premium P1

13
New cards

This helps control both access to an app and the access an app has to other resources...

Application identity

14
New cards

True or false: Application identities can be used for both an app inside or outside Azure....

True

15
New cards

In order to use application identities, the app must be....

Registered within an Entra ID tenant.

16
New cards

For app identity with Entra ID, authentication relies on the use of a...

Secret or certificate

17
New cards

(In Entra ID) To register an app you'll be creating for an Entra ID tenant, go to....

App registrations

18
New cards

(In Entra ID) To register an app within an tenant that someone else has developed, go to...

Enterprise applications

19
New cards

(Yes or no) Can I go back to view an apps authentication secret within Entra ID?

No.

20
New cards

(True or False) an app registration account type can be changed after it's created within an Entra ID tenant....

True

21
New cards

These types of identities are similar to Application identities, but there for Azure Resources only...

Managed identities

22
New cards

With managed identities, the authentication is managed by the...

Azure platform

23
New cards

This type of managed identity is assigned for a single resource and exists as long as the resource does ...

System assigned managed identity

24
New cards

This type of managed identity can be used by one or more azure resources...

User assigned managed identity

25
New cards

This type of group simplifies assignment of an Entra ID roles, RBAC roles and licensing...

Security groups

26
New cards

This type of group simplifies administration of collaborative spaces for users projects teams in 365...

Microsoft 365 groups

27
New cards

This simplifies the assignment of Entra ID permissions to objects...

Administrative units

28
New cards

This kind of administrative unit can limit global administrators to specific Entra ID objects...

Restricted administrative unit

29
New cards

Looking at assignments for an administrative unit, you see the scope of an assignment for a particular user reads "directory" and not "This Resource". What does that mean?

The user was inherited to this administrative unit at the tenant level.

30
New cards

What can be used to prevent users from inheriting an newly created administrative unit?

Make it a restrictive administrative unit.

31
New cards

(True or false) I can make an administrative unit restrictive whenever I want...

False

32
New cards

An Entra ID roles, this Is the object we are granting access to something...

Security principal

33
New cards

In Entra id roles, these are the permissions being granted...

Role definition

34
New cards

In Entra ID roles, this is where the role is applied...(Tenant, administrative unit, app)

Scope

35
New cards

When is signing administrative units, best practice is to assign them by using...

Security groups

36
New cards

When creating a custom RBAC Roll in azure, If you don't need to explicitly deny all permissions for a role, what does the "notactions" list do?

Subtract granular permissions within approved actions that you've already specified

37
New cards

What Entra tool is used to sync active directory to an Entra ID tenant?

Entra connect

38
New cards

What are the two types of Entra connect sync service tools?

connect sync and cloud sync

39
New cards

What Entra syncing tool allows cloud based configuration and a lightweight agent installation which replaces the legacy on prem syncing tool?

Entra Connect cloud sync

40
New cards

Entra connect is applying what type of identity?

Hybrid identity

41
New cards

What traditional AD features are not available in Entra ID?

Domain join, group policy, LDAP, Kerberos, Etc.

42
New cards

What Entra ID service allows you to run legacy applications in the cloud that require legacy authentication methods that are available natively within Entra ID?

Entra domain services

43
New cards

Entra domain services provides legacy active directory functionality by using what?

managed domain

44
New cards

A managed domain resides where?

Virtual network within azure

45
New cards

What are the three types of Entra external identities?

B2B Collaboration, B2B direct connect , B2C

46
New cards

This type of external identity allows you to invite users from other identity providers (Google, Facebook, Etc) where they need access to resources within your tenant...

B2B collaboration

47
New cards

This type of external identity provides a mutual connection between two Entra ID tenants, where a guest identity is not required...

B2B Direct connect

48
New cards

This type of external identity provides identity services for your application where end users can log in...

B2C

49
New cards

B2B collaboration allows external identities to be used by creating what within your Entra ID tenant?

Guest identity

50
New cards

Currently, B2B direct connect can already be used for what type of resource?

Shared Microsoft Teams channel

51
New cards

This Entra ID service helps organizations automate identity and access management...

Entra ID governance

52
New cards

This Entra ID governance product enables organizations to manage identity and access lifecycle at scale and automate access request workflows, assignments, reviews, and expiration..

Entitlement management

53
New cards

This Entra ID governance product provides the ability to control, manage, and monitor privileges that people have to crucial resources within a tenant...

Privileged identity management

54
New cards

This Entra ID governance product provides the ability to efficiently manage permissions and provide scheduled checks to make sure only the right users have continued access and no one had more access than they really need ...

Access reviews

55
New cards

This Entra ID governance product automates the management of an Entra ID user based on 3 lifecycle processes..

Lifecycle workflows

56
New cards

What are the three life cycle processes within identity governance?

Joiner, Mover, Leaver

57
New cards

This Entra ID governance product presents users with relevant disclaimers for legal or compliance requirements....

Terms of use

58
New cards

To use Entra ID governance, you will need at least what kind of licensing?

Premium 1

59
New cards

Within Entra ID governance, in order to use Entitlement Management, Privileged Identity Management, and Access Reviews, you will need what kind of licensing?

Premium 2

60
New cards

Within Entra id governance, In order to use the extended features of access reviews and lifecycle workflows, you will need what kind of licensing?

ID governance

61
New cards

With entitlement management in Entra ID, a grouping of resources to be provided for a specific role/purpose is called...

Access package

62
New cards

With entitlement management in entra ID, this is used to organize and manage resources and access packages...

A collection

63
New cards

To use Entra ID entitlement management, you need to have at least what kind of license?

Premium P2

64
New cards

Thor entitlement management, access packages are created where?

Entra ID Admin Portal

65
New cards

With entitlement management user access is managed through where?

myaccess.Microsoft.com

66
New cards

Which administrative roles allow granular permissions to entitlement management?

Access package manager, catalog owner, and others

67
New cards

This Entra ID feature helps organizations detect, investigate, and remediate identity based risks...

Entra ID protection

68
New cards

Why is it recommended not to use Entra ID protection...

Conditional access policies provide more granular options

69
New cards

In azure, what are the two types of public IP addressing?

Basic and standard

70
New cards

Main difference between basic and standard public IP addressing in azure?

Basic allows all incoming traffic, whereas standard only allows what a firewall permits (if present)

71
New cards

What are the three ways Microsoft assigns a public IP address?

From a pool, a public IP prefix, or a custom IP address prefix (aka) BYOIP

72
New cards

What are the three types of outbound connectivity for azure virtual networks?

VM default, VM public IP, public load balancer SNAT, NAT Gateway

73
New cards

Do you have to configure a public IP for a virtual machine in azure?

No, a public IP is already assigned to a VM by default

74
New cards

A group of IP address prefixes that are used to point to Microsoft services for a source / destination...

Service tags

75
New cards

Similar to service tags, this is a way to group vms together for use as source or destination, without the need to manually add IP addresses...

App security groups

76
New cards

Service tags and app security groups are examples of....

Augmented security groups

77
New cards

Once in application security group is created, how do you configure it to a specific virtual machine ?

Going to the NIC settings of the VM

78
New cards

If there is an issue with an Azure VM, what options do you have to recover the machine from a possibly failed state?

Redeploy/reapply

79
New cards

When redeploying in Azure VM, what happens to the data on a temporary drive?

It's lost

80
New cards

Where in your azure subscription can you find your current limits on resources?

Usage and quotas

81
New cards

If you shut down a VM within your Azure subscription, does it still add to your total quota for that resource?

Yes.

82
New cards

What are the three types of disks for VM storage in Azure?

OS , Data, and Temp disk

83
New cards

With Azure VM storage, the OS and data disks are managed by what?

Blog storage - VHDs

84
New cards

Can you manually install an OS for an azure VM?

No.

85
New cards

Can you upload your own VHDS and create an azure VM from that ?

Yes.

86
New cards

True or false: you can add , detach, or resize data disks without downtime...

True

87
New cards

To avoid breaking anything within your azure VM, watch feature can you use to create a current backup before starting your changes?

Snapshot

88
New cards

How can you create a snapshot of an azure VM?

Going directly to the OS disk and selecting create snapshot above.

89
New cards

An Azure VM can have multiple NICs, but they must reside within the same...

Virtual network

90
New cards

This is the configuration of private IPV4/V6 addresses and any associated public IP addresses of a NIC...

IP config

91
New cards

True or false: A NIC can only have 1 ipconfig.....

False

92
New cards

True or false: you cannot change the virtual network of a VM once it's created.

True

93
New cards

Without actually connecting to the virtual machine, where can you Set a static IP address for the vNIC of this virutal machine?

Setting the IP config assignment to static from the IP configuration page on the associated vNIC.

94
New cards

What tool can you use to deploy a VM environment across multiple machines to create redundancy(avoiding having to redeploy this environment manually every time)?

VM images

95
New cards

In some cases, before creating a VM image, the source machine must be cleared of user/machine specific information. What is this action called?

Generalize

96
New cards

In some cases, when creating AVM, you would like to keep specific user/machine information from the source machine. What is this action called?

Specialize

97
New cards

For Azure VMs, What are the two types of images you can create?

Managed image or compute gallery image.

98
New cards

This type of Azure VM image allows you to create version history, expiry time, and deploy images within different regions...

compute image gallery

99
New cards

This azure tool allows you to execute scripts on VMs during or after employment...

Custom script extension

100
New cards

This azure VM tool enables you to define a desired state of your virtual machine and maintain this state, enforcing Microsoft's version of desired state configuration - DSC...

Automation state configuration