2024 Latest AZ-720 DUMPS Q&As with Explanations Verified & Correct Answers
AZ-720 dumps Exam Material with 121 Questions
NEW QUESTION # 71
A company has an Azure Active Directory (Azure AD) tenant. The company deploys Azure AD Connect to
synchronize users from an Active Directory Domain Services (AD DS).
The synchronization of a user object is failing.
You need to troubleshoot the failing synchronization by using a built-in Azure AD Connect troubleshooting
task.
Which two pieces of information should you collect before you start troubleshooting?
- A. Object globally unique identifier
- B. Object distinguished name
- C. Azure AD connector name
- D. Object common name
- E. AD connector name
Answer: A,C
NEW QUESTION # 72
A company uses Azure Site Recovery (ASR) for a VMware environment that includes the following virtual machines (VMs):
The company reports that they are unable to configure all of the servers for replication.
You need to evaluate the servers and server roles to determine which servers can be protected.
Which server can you protect by using ASR?
- A. VM4
- B. VM1
- C. VM3
- D. VM2
Answer: C
NEW QUESTION # 73
A company has an ExpressRoute gateway between their on-premises site and Azure. The ExpressRoute
gateway is on a virtual network named VNet1. The company enables FastPath on the gateway. You associate a
network security group (NSG) with all of the subnets.
Users report issues connecting to VM1 from the on-premises environment. VM1 is on a virtual network named
VNet2. Virtual network peering is enabled between VNet1 and VNet2.
You create a flow log named FlowLog1 and enable it on the NSG associated with the gateway subnet.
You discover that FlowLog1 is not reporting outbound flow traffic.
You need to resolve the issue with FlowLog1.
What should you do?
- A. Configure the FlowTimeoutInMinutes property on VNet2 to a non-null value.
- B. Configure the FlowTimeoutInMinutes property on VNet1 to a non-null value.
- C. Enable FlowLog1 in a network security group associated with the subnet of VM1.
- D. Configure FlowLog1 for version 2.
Answer: A
NEW QUESTION # 74
A company enables just-in-time (JIT) virtual machine (VM) access in Azure.
An administrator observes a list of VMs on the Unsupported tab of the JIT VM access page in the Microsoft Defender for Cloud portal.
You need to determine why some VMs are not supported for JIT VM access.
What should you conclude?
- A. The VMs were provisioned by using a classic deployment.
- B. The administrator does not have the SecurityReader role.
- C. The administrator is using the Microsoft Defender for Cloud free tier.
- D. The administrator does not have permissions to request JIT access to the VMs.
Answer: A
Explanation:
JIT VM access is only supported for VMs that are deployed using the Azure Resource Manager (ARM) deployment model. VMs that are provisioned using the classic deployment model are not compatible with JIT VM access and will be displayed under the Unsupported tab of the JIT VM access page in the Microsoft Defender for Cloud portal.
NEW QUESTION # 75
A company uses an Azure Virtual Network (VNet) gateway named VNetGW1. VNetGW1 connects to a partner site by using a site-to-site VPN connection with dynamic routing.
The company observes that the VPN disconnects from time to time.
You need to troubleshoot the cause for the disconnections.
What should you verify?
- A. The partner's VPN device and VNetGW1 are configured using the same shared key.
- B. The partner's VPN device is enabled for Perfect forward secrecy.
- C. The partner's VPN device and VNetGW1 are configured with the same virtual network address space.
- D. The IP address of the local network gateway matches the partner's VPN device.
Answer: D
NEW QUESTION # 76
A customer has an Azure Virtual Network named VNet1 that contains an internal standard SKU load balancer
named LB1. The backend pool for LB1 includes the following virtual machines: VM1, VM2.
The customer configures a rule named Rul1 to load balance incoming HTTPS requests for VM1 and VM2.
Rule1 is associated with an HTTPS health probe. The path for the probe is set to /.
The network adapters of VM1 and VM2 are associated with a network security named NSG1 that contains the
following rules:
You connect to https://VM1 and https://VM2 from VNet1. Attempts to connect using the front-end IP address
of LB1 are failing.
You need to resolve the issue.
What should you do?
- A. Add an NSG1 rule with the source set to VirtualNetwork.
- B. Add an NSG1 rule with the source set to AzureLoadBalancer.
- C. Change the health probe associated with Rule1 to use HTTP.
- D. Change the health probe associated with Rule1 to use TCP.
Answer: C
NEW QUESTION # 77
A company implements Azure Firewall and deploys an Azure Firewall policy.
The policy incudes multiple application and network rules for the company's infrastructure. After deployment, an application is not accessible from on-premises computers.
You need to enable diagnostic logging for the following settings:
AzureFirewallApplicationRule
AzureFirewallNetworkRule
AzureFirewallDnsProxy
How should you complete the PowerShell cmdlet?
Answer:
Explanation:
NEW QUESTION # 78
A company uses an Azure Virtual Network (VNet) gateway named VNetGW1. VNetGW1 connects to a
partner site by using a site-to-site VPN connection with dynamic routing.
The company observes that the VPN disconnects from time to time.
You need to troubleshoot the cause for the disconnections.
What should you verify?
- A. The partner's VPN device is configured for one VPN tunnel per subnet pair.
- B. The public IP address of the partner's VPN device is configured in the local network gateway address
space on VNetGW1. - C. The partner's VPN device and VNetGW1 are configured using the same shared key.
- D. The partner's VPN device and VNetGW1 are configured with the same virtual network address space.
Answer: C
NEW QUESTION # 79
A company connects an on-premises network to an Azure virtual network by using ExpressRoute.
The ExpressRoute connection is experiencing higher than normal latency.
You need to confirm the traffic flow.
How should you complete the PowerShell command?
Answer:
Explanation:
NEW QUESTION # 80
A company implements Windows and Linux VMs in an Azure Virtual Network. The company plans to apply routing changes to the virtual network.
You need to determine the impact of these changes on network latency affecting applications that use TCP and UDP traffic. The solution must provide the highest level of accuracy.
Which tools should you use?
Answer:
Explanation:
NEW QUESTION # 81
A company has an Azure environment that uses one virtual network.
The company restructures the environment to use two different virtual networks. Virtual machines in one
network cannot communicate with virtual machines in the other virtual network.
You need to re-establish a connection between virtual machines in the two networks.
How should you configure the networks?
Answer:
Explanation:
NEW QUESTION # 82
You need to resolve the connectivity issue with the on-premises database named CosmosDB1.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 83
A company creates an Azure resource group named RG1. RG1 has an Azure SQL Database logical server named sqlsvr1 that hosts the following resources:
An administrator grants a user named User1 the Reader RBAC role in RG1. The administrator grants User2 the Contributor role in sqlsvr1.
User1 reports that they can connect to SQLDB1 from the IP address 155.127.95.212. User1 cannot connect to SQLDB2. User2 can connect to both SQLDB1 and SQLDB2 from the IP address 121.19.27.18. Both users can successfully connect to SQLDB1 and SQLDB2 from VM1.
You are helping the administrator troubleshoot the issue. You run the following PowerShell command:
Get-AzSqlServerFirewallRule -ResourceGroupName 'RG1' -ServerName 'sqlsvr1' The following output displays:
You need to identify the cause for the reported issue and resolve User1's issues. The solution must satisfy the principle of least privilege.
What should you do?
Answer:
Explanation:
NEW QUESTION # 84
A company migrates existing Ubuntu Linux servers from their on-premises vSphere infrastructure to Azure.
The virtual machines (VMs) are experiencing a low network throughput of 20 Mbps. The VMs are expected to sustain 300 Mbps.
You need to ensure that the VMs are compatible with Azure.
Which change should you make?
- A. Install a kernel name that ends with -azure.
- B. Increase the TCP buffers and window size kernel parameters.
- C. Redeploy the VM with Accelerated Networking enabled.
- D. Configure the network interfaces to 1000 Mbps/full duplex.
Answer: D
NEW QUESTION # 85
A company named Contoso connects its on-premises resources to Azure by using ExpressRoute.
An administrator reports that the circuit is in a failed state.
You need to resolve the issue.
How should you complete the PowerShell commands?
Answer:
Explanation:
NEW QUESTION # 86
A company uses Azure AD Connect. The company plans to implement self-service password reset (SSPR).
An administrator receives an error that password writeback could not be enabled during the Azure AD
Connect configuration. The administrator observes the following event log error:
Error getting auth token
You need to resolve the issue.
What should you do?
- A. Configure Azure AD Connect using a global administrator account with a password that is less than 256 characters.
- B. Disable password writeback and then enable password writeback using the Azure AD Connect configuration.
- C. Restart the Azure AD Connect service.
- D. Configure Azure AD Connect using a global administrator account that is not federated.
Answer: A
NEW QUESTION # 87
A company has users in Azure Active Directory (Azure AD). The company enables the users to use Azure AD multi-factor authentication (MFA).
A user named User1 reports they receive the following error while setting up additional security verification settings for MFA:
Sorry! We can't process your request. Your session is invalid or expired. There was an error processing your request because your session is invalid or expired. Please try again.
You need to help the user complete the MFA setup.
What should you do?
- A. From the Microsoft 365 Admin portal, clear the Block this user from signing in option for the user.
- B. Instruct the user to clear their web browser cache.
- C. Instruct the user to enter the correct verification code.
- D. Instruct the user to complete the setup process within 10 minutes.
- E. From the Azure AD portal, reset the user's password.
Answer: E
NEW QUESTION # 88
You manage an Azure subscription that contains the following resources:
An on-premises environment is connected to VNet1 by using ERGW1.
An on-premises environment is connected to VNet1 by using ERGW1.
An administrator measures network latency for on-premises traffic that targets VM1 and VM2 by using the front-end IP address of the load balancer. The administrator enables ExpressRoute FastPath on ERGW1 and observes that the latency has not changed.
You need to resolve the issue that is preventing the network latency improvements offered by ExpressRoute FastPath from taking effect.
What should you do?
- A. Redeploy the load balancer as a Standard SKU.
- B. Resize VM1 and VM2.
- C. Enable accelerated networking on VM1 and VM2
- D. Change the SKU for the ExpressRoute gateway.
Answer: A
Explanation:
To resolve the issue that is preventing the network latency improvements offered by ExpressRoute FastPath from taking effect, you should redeploy the load balancer as a Standard SKU. ExpressRoute FastPath is only supported on Standard Load Balancer SKUs. So the correct answer is A. Redeploy the load balancer as a Standard SKU.
NEW QUESTION # 89
A company uses Azure AD Connect. The company plans to implement self-service password reset (SSPR).
An administrator receives an error that password writeback cloud not be enabled during the Azure AD Connect configuration. The administrator observes the following event log error:
Error getting auth token
You need to resolve the issue.
Solution: Disable password writeback and then enable password writeback.
Does the solution meet the goal?
- A. No
- B. Yes
Answer: A
Explanation:
The solution of disabling and re-enabling password writeback may not meet the goal of resolving the issue. According to 1, there are other steps that you should try before disabling and re-enabling password writeback, such as:
Confirm network connectivity
Restart the Azure AD Connect Sync service
Install the latest Azure AD Connect release
Troubleshoot password writeback
If none of these steps work, then you can try to disable and re-enable password writeback as a last resort.
NEW QUESTION # 90
......
Share Latest AZ-720 DUMP Questions and Answers: https://www.pass4guide.com/AZ-720-exam-guide-torrent.html
AZ-720 Questions and Answers Guarantee you Oass the Test Easily: https://drive.google.com/open?id=1rIn0kPGPX_YBHSR8uKZPBPJJVJSnadq0