✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Manage Azure identities and governance
A company has a Microsoft Entra ID tenant with 5,000 users. The IT team wants to delegate password reset and basic user management permissions for only the 200 users in the Marketing department to a departmental helpdesk group, without granting them any permissions over other users in the tenant. What should the administrator configure?
Administrative units let you scope a Microsoft Entra role such as Helpdesk Administrator to a defined subset of users or groups, restricting management capability to only the Marketing users.
Question 2 of 12 · Implement and manage storage
A company runs a mission-critical application that must remain available if an entire datacenter within the primary region fails, and must also allow read access to data from a secondary region if the primary region becomes completely unavailable. Which storage redundancy option BEST meets these requirements?
RA-GZRS combines zone-redundant storage within the primary region (protecting against datacenter/zone failure) with geo-replication to a secondary region and read access (RA) to that secondary region during an outage — the only option satisfying both requirements.
Question 3 of 12 · Deploy and manage Azure compute resources
A company runs a two-tier web application on two Azure VMs. The finance team requires the solution to meet a 99.99% uptime SLA in the event of a datacenter-level failure. Which configuration meets this requirement?
Two or more VMs deployed across different Availability Zones and running in the same zone-redundant configuration are covered by Microsoft's 99.99% SLA, since zones are physically separate datacenters with independent power, cooling, and networking.
Question 4 of 12 · Implement and manage virtual networking
VNet-A is peered with VNet-B, and VNet-B is peered with VNet-C. VNet-A is NOT peered with VNet-C. A VM in VNet-A needs to communicate directly with a VM in VNet-C using private IP addresses. What should you do?
Azure VNet peering is non-transitive by design. Even though A-B and B-C are peered, A and C have no relationship unless a direct peering is explicitly created between them.
Question 5 of 12 · Monitor and maintain Azure resources
A company requires an RPO of under 5 minutes and an RTO of under 15 minutes for its production VMs in the event of a regional outage. Which solution BEST meets this requirement?
Azure Site Recovery continuously replicates VM disk changes to a secondary region, achieving an RPO as low as 30 seconds to a few minutes, and allows failover within minutes to meet the 15-minute RTO.
Question 6 of 12 · Manage Azure identities and governance
An organization must ensure that every resource group created in any subscription automatically includes a 'CostCenter' tag, and that resource group creation is blocked if the tag is missing. Which Azure governance feature should be used?
Azure Policy with a deny effect evaluates resource creation requests and blocks non-compliant ones, making it the correct tool to enforce mandatory tagging.
Question 7 of 12 · Implement and manage storage
A media company stores raw video footage that is accessed frequently for editing during the first 30 days after upload, rarely accessed afterward, and must be retained for compliance after one year with access latency of several hours being acceptable. Which lifecycle management tier progression BEST meets these requirements?
Hot tier is optimized for frequent access during the active editing period, Cool tier reduces storage cost for infrequently accessed data after 30 days, and Archive tier offers the lowest cost for long-term compliance retention where hours-long rehydration latency is acceptable.
Question 8 of 12 · Deploy and manage Azure compute resources
A development team needs to run a single containerized batch job that executes for about 3 minutes, requires no orchestration, has no persistent state, and should be billed only for the seconds it actually runs. Which Azure service is the BEST fit?
ACI is designed for running single, standalone containers with no orchestration overhead, billed per second of vCPU/memory consumption — ideal for short-lived, stateless batch jobs.
Question 9 of 12 · Implement and manage virtual networking
You create an Azure Private DNS zone named contoso.internal and add an A record for a VM. VMs in VNet1 still cannot resolve contoso.internal names, even though they use the default Azure-provided DNS. What is the most likely cause?
A Private DNS zone only resolves names for VNets that have an explicit virtual network link created (either with or without auto-registration). Without the link, the zone is invisible to VMs in that VNet.
Question 10 of 12 · Monitor and maintain Azure resources
A VM in Azure cannot reach a specific external website. You need to test the actual network path and pinpoint whether an NSG rule, user-defined route, or other configuration is blocking the connection. Which Network Watcher tool should you use?
Connection Troubleshoot performs an actual connection test to a destination and reports hop-by-hop results, identifying whether NSGs, user-defined routes, or other configuration issues are blocking traffic.
Question 11 of 12 · Manage Azure identities and governance
An administrator assigns an Azure Policy definition with a 'DeployIfNotExists' effect to enable diagnostic settings on all storage accounts in a subscription. After assignment, 40 pre-existing storage accounts remain non-compliant. What must the administrator do to bring these existing resources into compliance?
DeployIfNotExists and Modify effects only apply automatically to new or updated resources going forward; a remediation task must be created and run to apply the deployment action to existing non-compliant resources.
Question 12 of 12 · Implement and manage storage
An administrator needs to grant a third-party application temporary write access to a specific blob container for 24 hours, without exposing the storage account key and without granting access to other containers in the account. Which mechanism should be used?
A Service SAS can be scoped to a single container, granted specific permissions (such as write), and given a defined expiry time, meeting the requirement without exposing the account key or granting broader access.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.
The exam fee is approximately $165 and varies by region — confirm current pricing with the certification vendor before you book.
What topics are on the exam?
It covers 5 domains: Manage Azure identities and governance (20-25%), Implement and manage storage (15-20%), Deploy and manage Azure compute resources (20-25%), Implement and manage virtual networking (15-20%), Monitor and maintain Azure resources (10-15%). The full course has a dedicated chapter, lab and practice-test coverage for each.
Is this practice test really free?
Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.
Will this prepare me for the real exam?
The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.