AZ-104 sample questions with answers

10 free AZ-104 sample questions across the exam's domains, each with its answer and an explanation. No account needed.

AZ-104 sample questions

Microsoft Certified: Azure Administrator Associate, Microsoft.

  1. Question 1

    Domain: Manage Azure identities and governance

    You assign a policy with the DeployIfNotExists effect that installs a monitoring extension. You plan to create a remediation task for existing virtual machines.

    What does the policy assignment need so that the remediation task can deploy resources?

    1. A resource lock on the assignment scope
    2. An exemption recorded for each existing virtual machine in scope
    3. A managed identity with the required role assignments
    4. The enforcement mode set to Disabled
    Show the answer

    Answer: C. A managed identity with the required role assignments

    Remediation for DeployIfNotExists and Modify runs under the assignment's managed identity, which must hold roles that permit the deployment. Setting enforcement mode to Disabled stops the effect from being enforced, which is the opposite of what remediation needs.

    Checked against: https://learn.microsoft.com/en-us/azure/governance/policy/how-to/remediate-resources

  2. Question 2

    Domain: Manage Azure identities and governance

    What licensing is required to use dynamic membership groups in Microsoft Entra ID?

    1. No additional license, because dynamic groups are included in Microsoft Entra ID Free
    2. Microsoft Entra ID P1 (or a higher license) for each user in dynamic groups
    3. Microsoft Entra ID P2 only, because P1 does not include dynamic membership
    4. A Microsoft Entra Workload ID license for the tenant
    Show the answer

    Answer: B. Microsoft Entra ID P1 (or a higher license) for each user in dynamic groups

    Dynamic membership requires Microsoft Entra ID P1 (P2 includes P1) for each unique user who is a member of one or more dynamic groups. It is not part of the Free edition, and saying P2 is exclusively required is wrong because P1 already provides the feature.

    Checked against: https://learn.microsoft.com/en-us/entra/identity/users/groups-dynamic-membership

  3. Question 3

    Domain: Manage Azure identities and governance

    Every resource must have a CostCenter tag. When the tag is missing it should be added automatically with a default value, and existing non-compliant resources should be fixed with a remediation task.

    Which Azure Policy effect should the definition use?

    1. Append
    2. Audit
    3. Deny
    4. Modify
    Show the answer

    Answer: D. Modify

    Modify adds, replaces or removes tags on new resources and can remediate existing resources through a remediation task using a managed identity. Append can add fields to a request but cannot remediate existing resources, and Microsoft recommends Modify for tag management.

    Checked against: https://learn.microsoft.com/en-us/azure/governance/policy/concepts/effect-modify

  4. Question 4

    Domain: Implement and manage storage

    On a general-purpose v2 account using LRS, a lifecycle management rule has filters {"blobTypes":["blockBlob"],"prefixMatch":["logs/"]} and actions baseBlob: tierToCool daysAfterModificationGreaterThan 30, tierToArchive daysAfterModificationGreaterThan 90, delete daysAfterModificationGreaterThan 365.

    What happens to the block blob logs/app1.log, last modified 200 days ago, when the policy next runs?

    1. It is moved to the archive tier
    2. It is moved to the cool tier
    3. It is deleted
    4. Nothing, because the rule applies only to new blobs
    Show the answer

    Answer: A. It is moved to the archive tier

    At 200 days since modification both the cool (30) and archive (90) conditions are met, and lifecycle management applies the least expensive applicable tier, which is archive; the 365-day delete condition is not yet met. Existing blobs are evaluated, so the rule does not apply only to new blobs.

    Checked against: https://learn.microsoft.com/en-us/azure/storage/blobs/lifecycle-management-overview

  5. Question 5

    Domain: Implement and manage storage

    Azure Files is configured for on-premises AD DS authentication. The Finance group must be able to read, write and delete files in share finance, but must not be able to change NTFS permissions.

    Which share-level role should you assign to the group?

    1. Storage File Data SMB Share Elevated Contributor
    2. Storage File Data SMB Share Reader
    3. Storage File Data SMB Share Contributor
    4. Storage Account Contributor
    Show the answer

    Answer: C. Storage File Data SMB Share Contributor

    Storage File Data SMB Share Contributor allows read, write and delete access over SMB. Elevated Contributor adds the ability to modify Windows ACLs (NTFS permissions), which the requirement forbids; Storage Account Contributor is a control-plane role that does not grant SMB data access.

    Checked against: https://learn.microsoft.com/en-us/azure/storage/files/storage-files-identity-assign-share-level-permissions

  6. Question 6

    Domain: Deploy and manage Azure compute resources

    You must enable encryption at host on the existing VM vm-sql01 in a subscription where the feature has never been used.

    Which steps are required?

    1. Register EncryptionAtHost for Microsoft.Compute, deallocate the VM, then enable it
    2. Enable Azure Disk Encryption first, then enable encryption at host while the VM runs
    3. Create a disk encryption set, then enable encryption at host without stopping the VM
    4. Convert the VM's disks to Ultra Disks, then enable encryption at host
    Show the answer

    Answer: A. Register EncryptionAtHost for Microsoft.Compute, deallocate the VM, then enable it

    Encryption at host must be registered for the subscription (feature EncryptionAtHost in Microsoft.Compute), and existing VMs must be deallocated before it can be enabled. Azure Disk Encryption is a separate technology that actually blocks encryption at host on that VM.

    Checked against: https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-host-based-encryption-portal

  7. Question 7

    Domain: Deploy and manage Azure compute resources

    A VM had Azure Disk Encryption enabled last year; it was later disabled. The security team now wants encryption at host on this VM.

    What is the outcome?

    1. It can be enabled once the VM is deallocated and started on a new host
    2. It can be enabled after the OS disk is resized to a larger size
    3. It can be enabled, but it then covers only the data disks and not the OS disk
    4. It can't be enabled on a VM that has, or ever had, Azure Disk Encryption
    Show the answer

    Answer: D. It can't be enabled on a VM that has, or ever had, Azure Disk Encryption

    Encryption at host can't be enabled on VMs or scale sets that currently have or ever had Azure Disk Encryption enabled; a new VM is needed. Deallocating the VM is required for enabling encryption at host in general, but it does not remove this restriction.

    Checked against: https://learn.microsoft.com/en-us/azure/virtual-machines/disks-enable-host-based-encryption-portal

  8. Question 8

    Domain: Implement and manage virtual networking

    An NSG has these inbound rules: priority 200, Deny, source Internet, TCP 3389; priority 300, Allow, source 203.0.113.5, TCP 3389.

    What happens to an RDP connection from 203.0.113.5?

    1. It is allowed, because a specific source address overrides a service tag
    2. It is denied, because the priority 200 rule matches first
    3. It is allowed, because Allow rules are evaluated before Deny rules
    4. It is denied only if the default DenyAllInBound rule is enabled
    Show the answer

    Answer: B. It is denied, because the priority 200 rule matches first

    Rules are processed in priority order, lowest number first, and processing stops at the first match; the Internet tag includes 203.0.113.5, so the Deny at 200 applies. Specificity doesn't matter, only priority, so the Allow rule would need a number lower than 200.

    Checked against: https://learn.microsoft.com/en-us/azure/virtual-network/network-security-groups-overview

  9. Question 9

    Domain: Implement and manage virtual networking

    You enable the Microsoft.Sql service endpoint on subnet snet-app and add a virtual network rule on an Azure SQL logical server.

    Which statement is true?

    1. The server receives a private IP address from snet-app
    2. On-premises clients connected by VPN automatically use the service endpoint
    3. The server's public endpoint is removed from DNS
    4. Traffic uses the Azure backbone, but the server keeps its public endpoint
    Show the answer

    Answer: D. Traffic uses the Azure backbone, but the server keeps its public endpoint

    Service endpoints extend the subnet's identity to the service over the Azure backbone, but the service keeps its public IP address. Receiving a private IP address from the VNet is what a private endpoint does.

    Checked against: https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-service-endpoints-overview

  10. Question 10

    Domain: Monitor and maintain Azure resources

    In Metrics Explorer, the Percentage CPU chart for a virtual machine scale set shows a single averaged line. You need to see which instance is running hot.

    What should you do?

    1. Change the aggregation from Avg to Count
    2. Apply splitting on the VM instance dimension
    3. Add a filter for Percentage CPU greater than 80
    4. Change the time granularity to 1 day
    Show the answer

    Answer: B. Apply splitting on the VM instance dimension

    Splitting a metric by a dimension draws a separate line for each dimension value, such as each scale set instance. Changing the aggregation to Count only counts the samples, and still produces a single line.

    Checked against: https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/metrics-charts

More practice

A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.

AZ-104 course and practice exam: Microsoft Azure Administrator: the exam guide, with the format, cost, pass mark and domains from the vendor.