AZ-204 Sample Questions

AZ-204 Sample Questions & Answers

Compute solutions, from containers to App Service and Functions, carry the most weight, alongside connecting to APIM and event- or message-based services, developing against Cosmos DB and Blob Storage, authentication, and monitoring with Application Insights.

Launch the full AZ-204 simulator →

Showing 10 of 20 free samples.

  1. Question 1

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

    You are developing an application that processes Azure Blob storage events.

    Your application has the following requirements:

    Process transaction logs asynchronously for changes that occur to the blobs and the blob metadata. .
    Process changes in the order in which they occurred. .
    Retain changes for compliance reasons.

    Solution: You use Azure Event Grid with a subscriber Azure Function app.

    Does the solution meet the goal?

    Show answer & explanation

    Correct answer: A

    Azure Event Grid can trigger Azure Functions when blob storage events occur, providing a serverless and event-driven architecture. This integration allows automatic processing of uploaded files without polling or manual intervention.

  2. Question 2

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

    After you answer a question in this section, you will NOT be able to return to it.
    As a result, these questions will not appear in the review screen.

    You are developing a web app named mywebappl. Mywebappl uses the address myapp1.azurewebsites.net. You protect mywebappl by implementing an Azure Web Application Firewall (WAF). The traffic to mywebappl is routed through an Azure Application Gateway instance that is also used by other web apps.

    You want to secure all traffic to mywebappl by using SSL.

    Solution: You open the Azure Application Gateway’s HTTP setting and set the Override backend path option to mywebapp1.azurewebsites.net. You then add an authentication certificate for mywebappl .azurewebsites.net.

    Does this meet the goal?

    Show answer & explanation

    Correct answer: B

    Explanation:
    In case of end to end SSL, trusted Azure services such as Azure App service web apps do not require whitelisting the backends in the application gateway. Therefore, there is no need to add any authentication certificates. -- Reference:
    https://docs.microsoft.com/en-us/azure/application-gateway/application-gateway-web-app-overview

  3. Question 3

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

    You are developing a solution for a public facing API.

    The API back end is hosted in an Azure App Service instance.

    You have implemented a RESTful service for the API back end.

    You must configure back-end authentication for the API Management service instance.

    Solution: You configure Client cert gateway credentials for the HTTP(s) endpoint.

    Does the solution meet the goal?

    Show answer & explanation

    Correct answer: B

    Explanation:
    The API back end is hosted in an Azure App Service instance. It is an Azure resource and not an HTTP(s) endpoint. -- Reference:
    https://docs.microsoft.com/en-us/rest/api/apimanagement/apimanagementrest/azure-api-management-rest-api-backend-entity

  4. Question 4

    You are developing a web app that uses Azure Active Directory (Azure AD) for authentication.

    You want to configure the web app to use multifactor authentication.

    What should you do?

    Show answer & explanation

    Correct answer: C

    Explanation:
    MFA is enabled by conditional access policy. It is the most flexible means to enable two-step verification for your users. Enabling using conditional access policy only works for Azure MFA in the cloud and is a premium feature of Azure AD.
    Reference:
    https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-getstarted

  5. Question 5

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

    You are configuring a web app that delivers streaming video to users.

    The application makes use of continuous integration and deployment.

    You need to ensure that the application is highly available and that the users’ streaming experience is constant. You also want to configure the application to store data in a geographic location that is nearest to the user.

    Solution: You include the use of Azure Redis Cache in your design.

    Does the solution meet the goal?

    Show answer & explanation

    Correct answer: B

    The solution does not satisfy the requirements for streaming video delivery. Content Delivery Network is essential for streaming video to provide global reach, reduce latency, and handle traffic spikes effectively.

  6. Question 6

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

    You are developing a mobile app that uses an Azure SQL Database named Weyland.

    The database contains a table names Customers that has a field named email_address.

    You want to implement dynamic data masking to hide the data in the email_address field.

    Solution: You run the Set-AzSqlDatabaseDataMaskingRule
    -DatabaseName "Weyland" -SchemaName "dbo"
    -TableName "Customers" -ColumnName "email_address"
    -MaskingFunction "email" Powershell cmdlet

    Does the solution meet the goal?

    Show answer & explanation

    Correct answer: A

    PowerShell Set-AzSqlDatabaseDataMaskingRule cmdlet allows you to configure dynamic data masking rules for Azure SQL Database. This approach provides programmatic control over masking policies and can be integrated into automation scripts for consistent security configurations.

  7. Question 7

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

    Your company has an Azure Active Directory (Azure AD) environment. Users occasionally connect to Azure AD via the Internet.

    You need to ensure that users who connect to Azure AD via the internet using an unidentified IP address, are automatically instructed to change their passwords.

    Solution: You configure the use of Azure AD Identity Protection.

    Does the solution meet the goal?

    Show answer & explanation

    Correct answer: A

    Azure AD Identity Protection sign-in risk policies automatically evaluate the risk level of each sign-in attempt and can require additional verification or block access based on configured risk thresholds, providing adaptive authentication security.

  8. Question 8

    You manage an Azure SQL database that allows for Azure AD authentication.

    You need to make sure that database developers can connect to the SQL database via Microsoft SQL Server Management Studio (SSMS). You also need to make sure the developers use their on-premises Active Directory account for authentication. Your strategy should allow for authentication prompts to be kept to a minimum.

    Which of the following should you implement?

    Show answer & explanation

    Correct answer: C

    Explanation:
    Azure AD can be the initial Azure AD managed domain. Azure AD can also be an on-premises Active Directory Domain Services that is federated with the Azure AD.
    Using an Azure AD identity to connect using SSMS or SSDT The following procedures show you how to connect to a SQL database with an Azure AD identity using SQL Server Management Studio or SQL Server Database Tools.
    Active Directory integrated authentication Use this method if you are logged in to Windows using your Azure Active Directory credentials from a federated domain. 1. Start Management Studio or Data Tools and in the Connect to Server (or Connect to Database Engine) dialog box, in the Authentication box, select Active Directory - Integrated. No password is needed or can be entered because your existing credentials will be presented for the connection. 2. Select the Options button, and on the Connection Properties page, in the Connect to database box, type the name of the user database you want to connect to. (The AD domain name or tenant ID” option is only supported for Universal with MFA connection options, otherwise it is greyed out.) -- Reference: httpsT/githuLcom/MjcrosoftDocs/azure-docs/blob/master/articles/sql-database/sql-database-aad-authentication-configure.md

  9. Question 9

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

    Your company has an azure subscription that includes a storage account, a resource group, a blob container and a file share.

    A fellow administrator named Jon Ross used an Azure Resource Manager template to deploy a virtual machine and an Azure Storage account.

    You need to identify the Azure Resource Manager template the Jon Ross used.

    Solution: You access the Resource Group blade.

    Does the solution meet the goal?

    Show answer & explanation

    Correct answer: A

    Explanation:
    View template from deployment history • Go to the resource group for your new resource group. Notice that the portal shows the result of the last deployment. Select this link.Resource group • You see a history of deployments for the group. In your case, the portal probably lists only one deployment. Select this deployment.Last deployment • The portal displays a summary of the deployment. The summary includes the status of the deployment and its operations and the values that you provided for parameters. To see the template that you used for the deployment, select View template.View deployment summary -- Reference:
    https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-manager-export-template

  10. Question 10

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

    You are developing a web app named mywebappl. Mywebappl uses the address myapp1.azurewebsites.net. You protect mywebappl by implementing an Azure Web Application Firewall (WAF). The traffic to mywebappl is routed through an Azure Application Gateway instance that is also used by other web apps.

    You want to secure all traffic to mywebappl by using SSL.

    Solution: You open the Azure Application Gateway’s HTTP setting and set the Override backend path option to mywebapp1.azurewebsites.net. You then enable the Use for App service option.

    Does this meet the goal?

    Show answer & explanation

    Correct answer: A

    Explanation:
    The ability to specify a host override is defined in the HTTP settings and can be applied to any back-end pool during rule creation.
    The ability to derive the host name from the IP or FQDN of the back-end pool members. HTTP settings also provide an option to dynamically pick the host name from a back-end pool member's FQDN if configured with the option to derive host name from an individual back-end pool member.
    SSL termination and end to end SSL with multi-tenant services.
    In case of end to end SSL, trusted Azure services such as Azure App service web apps do not require whitelisting the backends in the application gateway. Therefore, there is no need to add any authentication certificates. -- Reference:
    https://docs.microsoft.com/en-us/azure/application-gateway/application-gateway-web-app-overview

Ready for the real thing?

The full AZ-204 simulator has every exam-style question, timed mode, and instant scoring.

Go to the AZ-204 simulator →