Get up-to-date Real Exam Questions for AZ-720 UPDATED [2022]
Pass Microsoft AZ-720 Exam in First Attempt Guaranteed
NEW QUESTION 20
A company migrates an on-premises Windows virtual machine (VM) to Azure. An administrator enables backups for the VM by using the Azure portal.
The company reports that the Azure VM backup job is failing.
You need to troubleshoot the issue.
Solution: Configure the retention range for the current VM backup policy.
Does the solution meet the goal?
- A. No
- B. Yes
Answer: B
NEW QUESTION 21
A company uses Azure Site Recovery (ASR) to replicate and recover Azure virtual machines (VM) between Azure regions.
An administrator receives the following warning from ASR about a VM that uses P10 disks: Data change rate beyond supported limits You add OS Disk Write Bytes/Sec and Data Disk Write Bytes/Sec to the list of metrics for monitoring. You discover that the VM consistently has a data churn of greater than 8 MB/s but less than 10 MB/s.
You need to resolve the issue.
What should you do?
- A. Create a network service endpoint in a virtual network.
- B. Upgrade the target storage disk.
- C. Uninstall the Volume Shadow Copy Service (VSS) Provider service.
- D. Use AzCopy to upload data to a cache storage account.
Answer: B
NEW QUESTION 22
A company has an Azure Active Directory (Azure AD) tenant. You are assigned the Owner role-based access control (RBAC) role of an Azure resource group named RG1.
An administrator grants a user named User1 the Contributor RBAC role for RG1. User1 receives an authorization error when attempting to create a Cosmos DB account in RG1.
The administrator verifies that they can create a Cosmos DB account in RG1.
You need to troubleshoot the issue.
What should you do?
Answer:
Explanation:
NEW QUESTION 23
A company has virtual machines (VMs) in the following Azure regions:
* West Central US
* Australia East
The company uses ExpressRoute private peering to provide connectivity to VMs hosted on each region and
on-premises services.
The company implements global VNet peering between a VNet in each region. After configuring VNet
peering, VM traffic attempts to use ExpressRoute private peering.
You need to ensure that traffic uses global VNet peering instead of ExpressRoute private peering. The solution
must preserve existing on-premises connectivity to Azure VNets.
What should you do?
- A. Disable the ExpressRoute peering connections for one of the regions.
- B. Add a user-defined route to the subnets route table.
- C. Add a second VNet to the virtual machines and configure VNet peering between the VNets.
- D. Add a filter to the on-premises routers.
Answer: D
NEW QUESTION 24
A company uses Azure AD Connect. The company plans to implement self-service password reset (SSPR).
An administrator receives an error that password writeback cloud not be enabled during the Azure AD Connect configuration. The administrator observes the following event log error:
Error getting auth token
You need to resolve the issue.
Solution: Restart the Azure AD Connect service.
Does the solution meet the goal?
- A. No
- B. Yes
Answer: A
NEW QUESTION 25
A company plans to use an Azure PaaS service by using Azure Private Link service. The azure Private Link
service and an endpoint have been configured.
The company reports that the endpoint is unable to connect to the service.
You need to resolve the connectivity issue.
What should you do?
- A. Disable the service network policies.
- B. Approve the connection state.
- C. Disable the endpoint network policies.
- D. Validate the VPN device.
Answer: A
NEW QUESTION 26
A company configures an Azure site-to-site VPN between an on-premises network and an Azure virtual network.
The company reports that after completing the configuration, the VPN connection cannot be established.
You need to troubleshoot the connection issue.
What should you do first?
- A. Identify the shared key by running this PowerShell cmdlet: Get-AzVirtualNetworkGatewayConnectionSharedKey.
- B. Verify the AzureRoot.cer file exists.
- C. Verify the AzureClient.pfx file exists.
- D. Identify the shared key by running this PowerShell cmdlet: Get-AzVirtualNetworkGatewayConnectionVpnDeviceConfigScript.
Answer: D
NEW QUESTION 27
A company uses Azure AD Connect. The company plans to implement self-service password reset (SSPR).
An administrator receives an error that password writeback cloud not be enabled during the Azure AD
Connect configuration. The administrator observes the following event log error:
Error getting auth token
You need to resolve the issue.
Solution: Restart the Azure AD Connect service.
Does the solution meet the goal?
- A. No
- B. Yes
Answer: A
NEW QUESTION 28
A company uses an Azure Virtual Network (VNet) gateway named VNetGW1. VNetGW1 connects to a partner site by using a site-to-site VPN connection with dynamic routing.
The company observes that the VPN disconnects from time to time.
You need to troubleshoot the cause for the disconnections.
What should you verify?
- A. The partner's VPN device and VNetGW1 are configured using the same shared key.
- B. The partner's VPN device and VNetGW1 are configured with the same virtual network address space.
- C. The IP address of the local network gateway matches the partner's VPN device.
- D. The partner's VPN device is enabled for Perfect forward secrecy.
Answer: B
NEW QUESTION 29
A company uses an Azure blob container.
The IT department has a service-level agreement (SLA) that requests on average cannot exceed 20 milliseconds.
You need to implement a log analytics query to generate the SLA report.
How should you complete the query?
Answer:
Explanation:
NEW QUESTION 30
A company is deploying Azure Bastion to provide secure clientless access to its Azure VMs. The company configures a network security group named NSG1.
During deployment, the following error displays: Network security group NSG1 does not have necessary rules for Azure Bastion Subnet AzureBastionSubnet.
You need to fix the inbound rules for NSG1.
How should you complete the configuration?
Answer:
Explanation:
NEW QUESTION 31
A company implements Windows and Linux VMs in an Azure Virtual Network. The company plans to apply
routing changes to the virtual network.
You need to determine the impact of these changes on network latency affecting applications that use TCP and
UDP traffic. The solution must provide the highest level of accuracy.
Which tools should you use?
Answer:
Explanation:
NEW QUESTION 32
A company uses an Azure VPN gateway with an IP address of 203.0.113.20.
Users report that the VPN connection frequently drops.
You need to determine when each connection failure occurred.
How should you complete the Azure Monitor query?
Answer:
Explanation:
NEW QUESTION 33
A company enables just-in-time (JIT) virtual machine (VM) access in Azure.
An administrator observes a list of VMs on the Unsupported tab of the JIT VM access page in the Microsoft
Defender for Cloud portal.
You need to determine why some VMs are not supported for JIT VM access.
What should you conclude?
- A. The VMs were provisioned by using a classic deployment.
- B. The VMs were recently provisioned by using an Azure Resource Manager deployment.
- C. The administrator is using the Microsoft Defender for Cloud free tier.
- D. The administrator does not have the SecurityReader role.
Answer: A
NEW QUESTION 34
A company uses Azure Active Directory (Azure AD) with Azure role-based access control (RBAC) for access to resources.
Some users report that they are unable to grant RBAC roles to other users.
You need to troubleshoot the issue.
How should you complete the Azure Monitor query?
Answer:
Explanation:
NEW QUESTION 35
A company has an Azure tenant. The company deploys an Azure firewall named FW1 to control access from
an on-premises datacenter to an Azure virtual machine named VM1.
The company troubleshoots ICMP connectivity from the on-premises datacenter to VM1. You are unable to
ping VM1 from an on-premises server.
You need to determine if ICMP connectivity to VM1 is allow on FW1.
What should you do?
- A. Use the ping command targeting the IP address of VM1 and review the command's response.
- B. Use the ping command targeting the IP address of VM1 and review the Infrastructure rules log of FW1.
- C. Use the ping command targeting the fully qualified domain name of VM1 and review the command's response.
- D. Use the ping command targeting the IP address of VM1 and review the Network rules log of FW1.
Answer: A
NEW QUESTION 36
A company deploys Azure Traffic Manager load balancing for an Azure App Service solution.
Load balancing performance is showing a degraded status after deployment, and new HTTPS probes are failing to reach the Traffic Manager endpoints.
You need to troubleshoot the probe failure.
How should you complete the PowerShell script?
Answer:
Explanation:
NEW QUESTION 37
A company migrates an on-premises Windows virtual machine (VM) to Azure. An administrator enables backups for the VM by using the Azure portal.
The company reports that the Azure VM backup job is failing.
You need to troubleshoot the issue.
Solution: Install the VM guest agent by using administrative permissions.
Does the solution meet the goal?
- A. No
- B. Yes
Answer: A
NEW QUESTION 38
......
Microsoft AZ-720 Study Guide Archives : https://www.braindumpsit.com/AZ-720_real-exam.html
Pass AZ-720 Exam Latest Practice Questions: https://drive.google.com/open?id=1nPM05v_PWCnpmvCxRwXTXquIoqbHEDoo