Azure Dumps
-

Microsoft AZ-301 Exam Actual Questions (P. 10)

The questions for AZ-301 were last updated at July 24, 2021.
  • Viewing page 10 out of 47 pages.
  • Viewing questions 46-50 out of 234 questions
Question #35 Topic 2

Your network contains an Active Directory domain named contoso.com that is federated to an Azure Active Directory (Azure AD) tenant. The on-premises domain contains a VPN server named Server1 that runs Windows Server 2016.
You have a single on-premises location that uses an address space of 172.16.0.0/16.
You need to implement two-factor authentication for users who establish VPN connections to Server1.
What should you include in the implementation?

  • A. In Azure AD, create a conditional access policy and a trusted named location
  • B. Install and configure Azure MFA Server on-premises
  • C. Configure an Active Directory Federation Services (AD FS) server on-premises
  • D. In Azure AD, configure the authentication methods. From the multi-factor authentication (MFA) service settings, create a trusted IP range
Reveal Solution Hide Solution 44

Correct Answer: B
You need to download, install and configure the MFA Server.
References:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfaserver-deploy

Question #36 Topic 2

HOTSPOT -
You configure the Diagnostics settings for an Azure SQL database as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Hot Area:

Reveal Solution Hide Solution 13

Correct Answer:

Question #37 Topic 2

Note: This question is part of series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your company has an on-premises Active Directory Domain Services (AD DS) domain and an established Azure Active Directory (Azure AD) environment.
Your company would like users to be automatically signed in to cloud apps when they are on their corporate desktops that are connected to the corporate network.
You need to enable single sign-on (SSO) for company users.
Solution: Install and configure an Azure AD Connect server to use password hash synchronization and select the Enable single sign-on option.
Does the solution meet the goal?

  • A. Yes
  • B. No
Reveal Solution Hide Solution 12

Correct Answer: A

Question #38 Topic 2

You have an Azure subscription that contains a custom application named Application1. Application1 was developed by an external company named Fabrikam,
Ltd. Developers at Fabrikam were assigned role-based access control (RBAC) permissions to the Application1 components. All users are licensed for the
Microsoft 365 E5 plan.
You need to recommend a solution to verify whether the Fabrikam developers still require permissions to Application1. The solution must meet the following requirements:
✑ To the manager of the developers, send a monthly email message that lists the access permissions to Application1.
✑ If the manager does not verify an access permission, automatically revoke that permission.
✑ Minimize development effort.
What should you recommend?

  • A. In Azure Active Directory (AD) Privileged Identity Management, create a custom role assignment for the Application1 resources
  • B. Create an Azure Automation runbook that runs the Get-AzureADUserAppRoleAssignment cmdlet
  • C. Create an Azure Automation runbook that runs the Get-AzureRmRoleAssignment cmdlet
  • D. In Azure Active Directory (Azure AD), create an access review of Application1
Reveal Solution Hide Solution 16

Correct Answer: D

Question #39 Topic 2

Note: This question is part of series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your company has an on-premises Active Directory Domain Services (AD DS) domain and an established Azure Active Directory (Azure AD) environment.
Your company would like users to be automatically signed in to cloud apps when they are on their corporate desktops that are connected to the corporate network.
You need to enable single sign-on (SSO) for company users.
Solution: Install and configure an Azure AD Connect server to use pass-through authentication and select the Enable single sign-on option.
Does the solution meet the goal?

  • A. Yes
  • B. No
Reveal Solution Hide Solution 8

Correct Answer: A


SaveCancel